Data protection

1. Basic principles of data processing

The protection of your personal data is of particular importance to us. We therefore process your data exclusively on the basis of the legal provisions (GDPR). In this privacy policy, we inform you about the most important aspects of data processing within the framework of our website.

This privacy policy informs you about the nature, scope, and purpose of the processing of personal data within our online services and the associated websites, functions, and content (hereinafter collectively referred to as "online services" or "website"). This privacy policy applies regardless of the domains, systems, platforms, and devices (e.g., desktop or mobile) used to access the online services.

2. Collection, processing & use of personal data

Regarding the terminology used (e.g. “personal data” or its “processing”), we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

The personal data processed within the scope of this online service includes usage data (e.g., the websites of our online service visited, interest in our products) and content data (e.g., entries in the contact form).

The term "user" encompasses all categories of individuals affected by data processing. These include our business partners, customers, prospective customers, and other visitors to our website.

We process your personal data only in compliance with the applicable data protection regulations. This means that your data will only be processed if there is a legal basis for doing so. Specifically, this applies when data processing is necessary or legally required for the provision of our contractual services (e.g., processing inquiries) and online services, when you have given your consent, or when it is based on our legitimate interests (i.e., our interest in the analysis, optimization, and economic operation and security of our online services; Art. 6 para. 1 lit. f GDPR), particularly for audience measurement, creating profiles for advertising and marketing purposes, collecting access data, and using third-party services.

Legal basis:
We refer to the following legal bases:

  • Legal basis for consent: Art. 6 para. 1 lit. a. and Art. 7 GDPR
  • Legal basis for processing data to fulfill our services and implement contractual measures: Art. 6 para. 1 lit. b GDPR,
  • The legal basis for processing data to fulfill our legal obligations is Article 6(1)(c) GDPR.
  • The legal basis for processing to protect our legitimate interests is Art. 6 para. 1 lit. f. GDPR.

3. Safety measures

We implement organizational, contractual and technical security measures in accordance with the state of the art to ensure compliance with data protection laws and to protect the data we process against accidental or intentional manipulation, loss, destruction or access by unauthorized persons.

The security measures include, in particular, the encrypted transmission of data between your browser and our server.

4. Disclosure of data to third parties & third-party providers

Your data will only be shared with third parties within the framework of legal requirements. We only share your data with third parties if this is necessary, for example, for contractual purposes (Art. 6 para. 1 lit. b) GDPR) or based on our legitimate interests (Art. 6 para. 1 lit. f) GDPR) in the efficient and effective operation of our business.

If we use subcontractors to provide our services, we will take appropriate legal precautions as well as corresponding technical and organizational measures to ensure the protection of your personal data in accordance with the relevant legal regulations.

If this privacy policy uses content, tools, or other resources from third-party providers whose registered office is located in a third country, it must be assumed that data will be transferred to the third-party providers' countries of domicile. Third countries are understood to be countries where the GDPR is not directly applicable law, i.e., generally countries outside the EU or the European Economic Area. Data is transferred to third countries only if an adequate level of data protection exists, if the user has given their consent, or if there is another legal basis for doing so.

5. Performance of contractual services

We process inventory data (e.g. your name and address, your contact details), contract data (e.g. services used, names of contact persons, payment information) to fulfill our contractual obligations and services (Art. 6 para. 1 lit. b. GDPR).

We process usage data (e.g., the pages visited on our website, interest in our products) for the continuous optimization of our offerings and content data (e.g., entries in the contact form) for processing inquiries.

6. Making contact

When you contact us via contact form or email, your information will be processed for the purpose of handling and processing your contact request (Art. 6 para. 1 lit. b) GDPR).

Your information may be stored in our Customer Relationship Management System ("CRM System") or a comparable system for managing inquiries.

7. Collection of access data & log files

Based on our legitimate interests (Art. 6 para. 1 lit. f. GDPR), we collect data about every access to the server on which this website is located (so-called server log files). Access data includes the name of the accessed web page, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, your operating system, referrer URL (the previously visited page, if our website was accessed via a link), and your IP address.

Log file information is stored for a maximum of three months for security reasons (e.g., to investigate misuse or fraud) and then deleted.

Data that needs to be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.

8. Cookies & Audience Measurement

Cookies are pieces of information that are transferred from our web server or third-party web servers to your web browser and stored there for later retrieval. Cookies can be small files or other types of information storage.

We use "session cookies," which are only stored for the duration of your current visit to our website. A session cookie contains a randomly generated, unique identification number, a so-called session ID. It also contains information about its origin and storage duration. These cookies cannot store any other data. Session cookies are deleted when you end your use of our website, for example, by closing your browser.

You will be informed about the use of cookies for pseudonymous audience measurement within the framework of this privacy policy.

Opt-out:
If you do not want cookies to be stored on your computer, please disable the corresponding option in your browser's system settings. Stored cookies can be deleted in your browser's system settings. Disabling cookies may limit the functionality of our website.

You can object to the use of cookies for audience measurement and advertising purposes via the Network Advertising Initiative's opt-out page ( http://optout.networkadvertising.org/ ) and additionally the US website ( http://www.aboutads.info/choices ) or the European website ( http://www.youronlinechoices.com/uk/your-ad-choices/ ).

9. Google Analytics

Based on our legitimate interests (interest in the analysis, optimization and economic operation of our website, Art. 6 para. 1 lit. f GDPR), we use Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google uses cookies. The information generated by the cookie about your use of our website is generally transmitted to and stored on a Google server in the USA.

Compliance with European data protection law:
Google is certified under the Privacy Shield agreement and thereby guarantees compliance with European data protection law ( https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active ).

How Google Analytics works:
Google will use this information on our behalf to evaluate your use of our website, to compile reports on your activity within this online service, and to provide us with other services relating to website activity and internet usage. Pseudonymous user profiles may be created from the processed data.

Anonymization of your data:
We use Google Analytics only with IP anonymization enabled. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will your full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by your browser will not be merged with other Google data.

Opt-out:
You can prevent the storage of cookies by adjusting your browser settings accordingly; you can also prevent Google from collecting and processing data generated by the cookie and related to your use of our website by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de .

Further information:
Further information on data usage by Google, settings and opt-out options can be found on Google's websites: https://www.google.com/intl/de/policies/privacy/partners ("How Google uses data when you use our partners' sites or apps"), http://www.google.com/policies/technologies/ads ("How Google uses data for advertising"), http://www.google.de/settings/ads ("Manage the information Google uses to show you ads").

10th Newsletter

The following information explains the content of our newsletter, the registration, distribution, and statistical evaluation procedures, as well as your rights to object. By subscribing to our newsletter, you agree to receive it and to the procedures described.

Newsletter content:
We only send newsletters, emails, and other electronic notifications containing promotional information (hereinafter "newsletters") with your consent or where legally permitted. If the content of the newsletter is specifically described during the registration process, this description is decisive for your consent. Otherwise, our newsletters contain information about our products, offers, promotions, and our company.

Double opt-in and logging:
Subscription to our newsletter uses a double opt-in process: After registering, you will receive an email asking you to confirm your subscription. This confirmation is necessary to prevent third parties from subscribing using your email address. Newsletter subscriptions are logged to document the registration process in accordance with legal requirements. This includes recording the time of registration and confirmation, as well as the IP address. Changes to your data stored with the email service provider are also logged.

Login details :
To subscribe to our newsletter, simply provide your email address. Optionally, we ask for your name so we can address you personally in our newsletter.

Statistical surveys and analyses:
Our newsletters contain a so-called "web beacon," a pixel-sized file that is retrieved from the email service provider's server when the newsletter is opened. During this retrieval, technical information such as browser and system details, as well as your IP address and the time of retrieval, are collected. This information is used to technically improve our services based on technical data, target groups, and your reading behavior, including retrieval locations (determined using the IP address) and access times. Statistical analysis also includes determining whether you open our newsletter, when it was opened, and which links were clicked. This information can be associated with you for technical reasons. However, neither we nor the email service provider intend to monitor you. Rather, the analyses help us understand our users' reading habits and tailor our content accordingly, or send different content based on their interests.

The use of the shipping service provider, the performance of statistical surveys and analyses, and the logging of the registration process are based on our legitimate interests (Art. 6 para. 1 lit. f GDPR). Our interest lies in the use of a user-friendly and secure newsletter system that serves both our business interests and meets your expectations.

Cancellation/Revocation:
You can unsubscribe from our newsletter at any time / revoke your consent. This will simultaneously revoke your consent to its distribution by the email service provider and the statistical analyses. A separate revocation of the distribution by the email service provider or the statistical analysis is unfortunately not possible. You will find a link to unsubscribe at the end of each newsletter. If you have subscribed to the newsletter and have unsubscribed, your personal data will be deleted.

11. Integration of third-party services and content

It is possible that third-party content (e.g., maps from Google Maps, fonts, etc.) may be integrated into our website. This requires that the providers of this content ("third-party providers") receive your IP address. Without the IP address, the content cannot be sent to your browser. Your IP address is therefore necessary for displaying the content.

We strive to use only content from providers who use your IP address solely for delivering the content.

Third-party providers may use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. These pixel tags allow for the analysis of information such as visitor traffic on the pages of this website. The pseudonymized information can be stored in cookies on your device and may include, among other things, technical information about your browser and operating system, referring websites, visit time, and other details about your use of our online services, as well as be combined with such information from other sources.

Below you will find an overview of third-party providers, their content, a link to their respective privacy policies (containing further information on the processing of your data) and, in some cases already mentioned here, options to object ("opt-out"):

12. Your rights

Right to information:
You have the right to request, free of charge, information about the personal data we store about you.

Right to rectification, erasure, data portability & restriction of processing:
Of course, you have the right to rectification of inaccurate data, restriction of processing, and erasure of your personal data. Where applicable, you can also exercise your right to data portability.

Right to appeal:
If you believe that we are processing your data unlawfully, you have the right to lodge a complaint with the competent supervisory authority. In Austria, this is the Data Protection Authority.

Right to object:
You can object to the future processing of your personal data at any time in accordance with legal requirements. In particular, you can object to processing for direct marketing purposes.

13. Deletion of data

Your data stored with us will be deleted as soon as it is no longer required for its intended purpose and there are no legal retention obligations preventing its deletion.

14. Changes to the Privacy Policy

We reserve the right to amend our privacy policy to reflect changes in the law or modifications to the service or data processing. However, this only applies to statements regarding data processing. If your consent is required or if parts of the privacy policy contain provisions relating to your contractual relationship with us, changes will only be made with your consent.

However, this only applies to statements regarding data processing. If your consent is required or if parts of the privacy policy contain provisions relating to the contractual relationship with you, changes will only be made with your consent.

We ask you to regularly review the content of our privacy policy.

15. Responsible Person & Contact

The responsible body within the meaning of data protection law is:

Wooden curling stone - Wimmer KG woodturning workshop
Oberndorf 7
4793 St. Roman, Austria

Telephone: +43 7716 6324
Email: office@holzeisstock.at

As of November 2018