DSVGO

Table of Contents

Introduction and Overview

Scope of Application

Legal Basis

Contact Details of the Data Controller

Data Retention

Your Rights under the General Data Protection Regulation (GDPR)

Data Transfers to Third Countries

Security of Data Processing

Communication

Data Processing Agreement (DPA)

Cookies

Web Hosting

Definitions

Introduction and Overview

We have prepared this Privacy Policy (version: June 2026) to explain, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national laws, which personal data (“personal data”) we process as the data controller, which data may be processed in the future, and what lawful rights you have in relation to your personal data. This also applies to personal data processed on our behalf by appointed data processors (e.g. hosting providers).

For the sake of readability, terms referring to individuals apply equally to all genders.

In short: this Privacy Policy provides comprehensive information about how we collect, process and protect your personal data.

Privacy policies often contain technical language and legal terminology. Our aim is to present the most important information in a clear, transparent and easy-to-understand manner. Wherever it improves clarity, technical terms are explained in plain language and links to additional information are provided.

We want you to understand that we only process personal data in the course of our business activities where there is an appropriate legal basis for doing so, as required by the GDPR and applicable legislation.

If you have any questions after reading this Privacy Policy, please contact the data controller listed below or in our Legal Notice. You may also follow the provided links for further information from third-party sources. Our contact details can also be found in the Legal Notice.

Scope of Application

This Privacy Policy applies to all personal data processed by us in the course of our business activities, as well as to all personal data processed on our behalf by appointed data processors.

For the purposes of this Privacy Policy, “personal data” means any information relating to an identified or identifiable natural person within the meaning of Article 4(1) of the General Data Protection Regulation (GDPR), including, for example, a person’s name, email address or postal address.

The processing of personal data enables us to provide, manage and invoice our products and services, whether online or offline.

This Privacy Policy applies to:

all other situations in which personal data is collected and processed as part of our business activities.

all websites operated by us;

all online services and digital platforms we provide;

communication by email, telephone and through social media; and

  • all online presences, including websites, operated by us;
  • email communications with customers, prospective clients and other business contacts;

In short: this Privacy Policy applies to all areas of our business in which personal data is systematically collected and processed through the channels described above. If we establish a legal relationship with you outside the scope of these channels, we will provide you with additional privacy information where required.

Legal Basis

In this Privacy Policy, we provide transparent information about the legal principles and statutory provisions that form the basis for our processing of personal data.

With regard to European Union law, we rely on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, commonly referred to as the General Data Protection Regulation (GDPR).

The full text of the GDPR is available on the official EUR-Lex website:
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

We process your personal data only where at least one of the following legal bases applies:

  • Consent (Article 6(1)(a) GDPR): We process your personal data where you have given your consent for a specific purpose. For example, this applies to the information you submit through a contact form.
  • Performance of a Contract (Article 6(1)(b) GDPR): We process your personal data where this is necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract. For example, we require certain personal information before concluding a contract with you.
  • Legal Obligation (Article 6(1)(c) GDPR): We process your personal data where this is necessary to comply with a legal obligation. For example, we are legally required to retain invoices for accounting and tax purposes, which generally contain personal data.
  • Legitimate Interests (Article 6(1)(f) GDPR): We process your personal data where this is necessary for the purposes of our legitimate interests, provided that these interests are not overridden by your fundamental rights and freedoms. For example, we process certain data to ensure the secure, reliable and efficient operation of our website.

In addition to the GDPR, national data protection laws also apply. In Austria, this is the Austrian Data Protection Act (Datenschutzgesetz – DSG), which supplements the GDPR and contains specific provisions governing the protection of personal data.

Contact Details of the Data Controller

If you have any questions regarding data protection or the processing of personal data, please contact the data controller using the details provided below:

Michael Preschl
Michael-Walz-Gasse 20
5020 Salzburg
E-Mail: management@michael-preschl.at
Telefon: +43 660 767 23 13
Impressum: https://test.michael-preschl.at/imprint

Data Retention

As a general principle, we retain personal data only for as long as necessary to provide our services and fulfil the purposes for which the data was collected. Once the purpose for processing no longer applies, we will delete the relevant personal data without undue delay.

In certain cases, however, we are legally required to retain specific data even after the original purpose has ceased to exist, for example to comply with accounting, tax or other statutory record-keeping obligations.

If you request the deletion of your personal data or withdraw your consent to its processing, we will erase the data as soon as reasonably possible, provided that no legal obligation requires us to retain it.


Your Rights under the General Data Protection Regulation (GDPR)

In accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), we inform you of the following rights to ensure fair and transparent processing of your personal data:

  • Right of Access (Article 15 GDPR): You have the right to obtain confirmation as to whether we process your personal data. Where this is the case, you have the right to receive a copy of your personal data and information about the purposes of the processing, the categories of data concerned, the recipients, the retention period, your rights and, where applicable, the source of the data.
  • Right to Rectification (Article 16 GDPR): You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data.
  • Right to Erasure (Article 17 GDPR): You have the right to request the deletion of your personal data (“right to be forgotten”) where the legal requirements are met.
  • Right to Restriction of Processing (Article 18 GDPR): You have the right to request the restriction of the processing of your personal data. In such cases, we may continue to store the data but will not process it further except as permitted by law.
  • Right to Data Portability (Article 20 GDPR): You have the right to receive your personal data in a structured, commonly used and machine-readable format and, where technically feasible, to have those data transmitted to another controller.
  • Right to Object (Article 21 GDPR): You have the right to object to the processing of your personal data where the legal requirements are met. If your personal data is processed for direct marketing purposes, you may object to such processing at any time.
  • Rights Relating to Automated Decision-Making (Article 22 GDPR): Under certain circumstances, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
  • Right to Lodge a Complaint (Article 77 GDPR): If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent data protection supervisory authority at any time.

If you believe that the processing of your personal data violates applicable data protection law, or that your rights under data protection legislation have otherwise been infringed, you have the right to lodge a complaint with the competent supervisory authority.

In Austria, the competent supervisory authority is:

Austrian Data Protection Authority (Datenschutzbehörde – DSB)

Barichgasse 40–42
1030 Vienna
Austria
Phone: +43 1 52 152-0
mail: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/

Data Transfers to Third Countries

We transfer or process personal data in countries outside the European Union or the European Economic Area only where you have consented to such processing, where the transfer is required by law or necessary for the performance of a contract, and only to the extent permitted under applicable data protection law.

Where personal data is processed exclusively within the European Union or the European Economic Area, as is the case with our web hosting services, no transfer to third countries takes place.

Security of Data Processing

To protect personal data, we have implemented appropriate technical and organisational measures. Where possible, we encrypt or pseudonymise personal data.

These measures are intended to reduce the risk of unauthorised access and to make it as difficult as reasonably possible for third parties to identify individuals from the data processed by us.

TLS Encryption (HTTPS)

To ensure the secure transmission of data over the Internet, we use HTTPS (Hypertext Transfer Protocol Secure). HTTPS encrypts all data transmitted between your browser and our web server, preventing unauthorised third parties from intercepting or accessing the information during transmission.

By implementing HTTPS, we provide an additional layer of security and support the principle of data protection by design in accordance with Article 25(1) of the General Data Protection Regulation (GDPR).

You can recognise a secure connection by the padlock icon displayed in your browser’s address bar and by the use of https:// at the beginning of our website address instead of http://.


Communication

Data Subjects: Individuals who contact us by telephone, email or via our online contact forms.

Personal Data Processed: This may include your name, telephone number, email address and any information you provide through contact forms or other communications.

Purpose of Processing: To respond to enquiries, communicate with customers, business partners and other contacts, and to manage business-related correspondence.

Retention Period: Personal data is retained for as long as necessary to process your enquiry, fulfil contractual or business purposes, and comply with applicable legal retention obligations.

Legal Bases:

Article 6(1)(f) GDPR – Legitimate Interests

Article 6(1)(a) GDPR – Consent

Article 6(1)(b) GDPR – Performance of a Contract or Pre-contractual Measures

If you contact us by telephone, email or through our online contact forms, we may process your personal data. The information you provide will be used to respond to your enquiry, manage our communication with you and, where applicable, carry out any related contractual or business activities.

Your personal data will be retained only for as long as necessary to fulfil these purposes or for as long as required by applicable legal retention obligations.

  • Telephone
    If you contact us by telephone, we may process personal data such as your name, telephone number and any information you provide during the conversation in order to respond to your enquiry. Your personal data will be deleted once the matter has been concluded, provided that no statutory retention obligations apply.
  • Email
    If you communicate with us by email, your personal data will be processed and stored on our email systems for the purpose of handling your enquiry and any related business activities. Your personal data will be deleted once the matter has been concluded, provided that no statutory retention obligations apply.
  • Online Contact Forms
    If you contact us via one of our online contact forms, the information you submit will be processed and stored on our web server and, where necessary, forwarded to the appropriate email address within our organisation for the purpose of handling your enquiry. Your personal data will be deleted once the matter has been concluded, provided that no statutory retention obligations apply.

Data Processing Agreement (DPA)

Like most businesses, we rely on the services of carefully selected third-party providers to support our operations. Where these service providers process personal data on our behalf, they act as data processors within the meaning of Article 28 of the General Data Protection Regulation (GDPR).

We enter into a Data Processing Agreement (DPA) with each processor where required by law. These agreements ensure that personal data is processed solely on our documented instructions and in full compliance with the GDPR.


Cookies

Data Subjects: Visitors to this website

Purpose of Processing: Depends on the specific cookie used.

Personal Data Processed: Depends on the individual cookie.

Retention Period: Varies depending on the cookie and may range from a few hours to several years.

Legal Bases:

  • Article 6(1)(a) GDPR – Consent
  • Article 6(1)(f) GDPR – Legitimate Interests

Cookies are small text files that are stored on your device by your web browser. Each cookie contains a name and a value and is used to store certain information, such as your language preferences or personal website settings.

Cookies generally fall into four categories:

  • Essential cookies
  • Functional cookies
  • Performance and analytics cookies
  • Advertising and marketing cookies

The cookies used on this website depend on the services and technologies implemented.

Managing Cookies

You decide whether and how cookies are used on your device. Regardless of which website or service sets a cookie, you can delete, block or restrict cookies at any time through your browser settings. Please note that disabling certain cookies may affect the functionality of this website.

Legal Basis

The use of strictly necessary cookies is based on our legitimate interest pursuant to Article 6(1)(f) GDPR in ensuring the secure and technically correct operation of our website.

Any cookies that are not strictly necessary will only be used with your prior consent in accordance with Article 6(1)(a) GDPR.


Web Hosting

Data Subjects: Visitors to this website

Purpose of Processing: Provision of reliable web hosting and the secure operation of the website.

Personal Data Processed: IP address, date and time of access, browser type and version, operating system, requested pages, referrer URL, hostname of the accessing device and other technical connection data.

Retention Period: Generally up to two weeks.

Legal Basis: Article 6(1)(f) GDPR – Legitimate Interests

Whenever you visit our website, certain technical information is automatically collected and stored. In order to display the website, your browser must communicate with a web server on which the website is hosted.

During this process, our web server typically records information including the full URL of the requested page, browser type and version, operating system, referrer URL, hostname and IP address of the accessing device, as well as the date and time of the request. This information is stored in server log files.

Server log files are generally retained for up to two weeks before being automatically deleted. We do not disclose this information to third parties. However, we cannot exclude the possibility that it may be accessed by competent authorities where required by law.

The processing of this data is based on our legitimate interest pursuant to Article 6(1)(f) GDPR in providing a secure, stable and reliable website.


World4You

Our website is hosted by World4You Internet Services GmbH, Hafenstraße 35, 4020 Linz, Austria.

Further information about how World4You processes personal data can be found in its Privacy Policy:

https://www.world4you.com/de/unternehmen/datenschutzerklaerung.html

In accordance with Article 28 GDPR, we have concluded a Data Processing Agreement (DPA) with World4You. This agreement is required by law because World4You processes personal data on our behalf. It ensures that World4You processes such data solely on our documented instructions and in compliance with the requirements of the GDPR.


Definitions

Data Processor (Article 4 GDPR)

data processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the data controller. Examples include web hosting providers, cloud service providers, accountants and email marketing service providers.

Data Controller (Article 4 GDPR)

data controller is the natural or legal person, public authority, agency or other body that determines, alone or jointly with others, the purposes and means of processing personal data.

For the purposes of this Privacy Policy, we are the data controller responsible for the processing of your personal data.


© All texts are protected by copyright.

Based on the Privacy Policy Generator by AdSimple, adapted and supplemented for this website.