Privacy Policy - Kalk & Kegel
KALK&KEGEL
MAGAZINE FOR FOOD. DRINKS. MADNESS.

Privacy Policy

Privacy Policy, as of July 2019.

This Privacy Policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “Data”) within our online service and its associated websites, features, and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the “online service”). With regard to the terms used, such as “processing” or “controller,” we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

General Information

The entity responsible for the collection, processing, and use of personal data as defined by the Data Protection Act, as well as for the content, is

KALK&KEGEL MPP Medien GmbH
Wenisbucher Straße 114, 8044 Graz

Contact:
Michael Pöcheim-Pech
Phone: +43 (0) 660 631 67 74
Email: info@kalkundkegel.com

Types of data processed:

  • Master data (e.g., names, addresses)
  • Contact information (e.g., email, phone numbers)
  • Content data (e.g., text entries, photographs, videos)
  • Usage data (e.g., websites visited, content interests, access times)
  • Meta/communication data (e.g., device information, IP addresses)

Categories of Data Subjects

Visitors and users of the online service (hereinafter, we collectively refer to these individuals as “users”).

Purpose of the Processing

  • To provide the online service, its features, and its content.
  • Responding to contact requests and communicating with users.
  • Safety measures.
  • Reach Measurement/Marketing

Relevant Legal Bases

In accordance with Article 13 of the GDPR, we are providing you with the legal bases for our data processing activities. If the legal basis is not specified in the Privacy Policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing to fulfill our services, carry out contractual obligations, and respond to inquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfill our legal obligations is Article 6(1)(c) of the GDPR, and the legal basis for processing to protect our legitimate interests is Article 6(1)(f) of the GDPR. In the event that the vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.

Safety Measures

In accordance with Article 32 of the GDPR, and taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and maintaining its separation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the erasure of data, and a response to data breaches. Furthermore, we take the protection of personal data into account from the very beginning of the development and selection of hardware, software, and procedures, in accordance with the principle of data protection through technology design and privacy-friendly default settings (Art. 25 GDPR).

Cooperation with Data Processors and Third Parties

If, in the course of our data processing, we disclose data to other individuals or companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, this is done only on the basis of a legal authorization (e.g., if the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Article 6(1)(b) of the GDPR), you have given your consent, a legal obligation requires it, or based on our legitimate interests (e.g., when using agents, web hosts, etc.).

If we engage third parties to process data on the basis of a so-called “data processing agreement,” this is done in accordance with Article 28 of the GDPR.

Transfers to Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in connection with the use of third-party services, disclosure, or transfer of data to third parties, this occurs only if it is necessary to fulfill our (pre)contractual obligations, based on your consent, due to a legal obligation, or based on our legitimate interests. Subject to statutory or contractual permissions, we process data in a third country—or have it processed there—only if the specific requirements of Articles 44 et seq. of the GDPR are met. This means that processing takes place, for example, on the basis of specific safeguards, such as an officially recognized determination that a country provides a level of data protection equivalent to that of the EU (e.g., for the U.S. through the “Privacy Shield”) or compliance with officially recognized specific contractual obligations (so-called “Standard Contractual Clauses”).

Cookies and the Right to Object to Direct Marketing

“Cookies” are small files that are stored on users’ computers. Various types of information can be stored in cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to a website. Temporary cookies—also known as “session cookies” or “transient cookies”—are cookies that are deleted after a user leaves an online service and closes their browser. Such a cookie can, for example, store the contents of a shopping cart in an online store or a login status. Cookies that remain stored even after the browser is closed are referred to as “permanent” or “persistent.” For example, a user’s login status may be stored so that it remains active when the user returns to the site several days later. Such cookies may also store users’ interests, which are used for audience measurement or marketing purposes. “Third-party cookies” are cookies provided by parties other than the controller operating the online service (in contrast, when only the controller’s own cookies are used, they are referred to as “first-party cookies”).

We may use temporary and permanent cookies, and we provide information about this in our Privacy Policy.

If users do not want cookies to be stored on their computers, they are asked to disable the corresponding option in their browser’s settings. Stored cookies can be deleted in the browser’s settings. Disabling cookies may result in limited functionality of this website.

Deletion of Data

The data we process will be deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated in this Privacy Policy, the data we store will be deleted as soon as it is no longer necessary for its intended purpose and there are no legal retention requirements preventing its deletion. If the data is not erased because it is required for other legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for any other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

In accordance with Austrian law, records must be retained for 7 years pursuant to § 132(1) of the Federal Tax Code (BAO) (accounting records, receipts/invoices, accounts, supporting documents, business papers, statements of income and expenses, etc.), for 22 years in connection with real estate, and for 10 years for documents related to electronically provided services, telecommunications, radio, and television services provided to non-business customers in EU member states for which the Mini One-Stop Shop (MOSS) is utilized.

Business-Related Processing

In addition, we process

  • Contract details (e.g., subject matter of the contract, term, customer category).
  • Payment information (e.g., bank account information, payment history)

from our customers, prospective customers, and business partners for the purpose of providing contractual services, customer support, marketing, advertising, and market research.

Agency Services

We process our customers’ data as part of our contractual services, which include conceptual and strategic consulting, campaign planning, software and design development and consulting or maintenance, campaign and process implementation and management, server administration, data analysis and consulting services, and training services.

In this context, we process master data (e.g., customer master data such as names or addresses), contact data (e.g., email addresses, phone numbers), content data (e.g., text entries, photographs, videos), contract data (e.g., subject matter of the contract, term), payment data (e.g., bank account information, payment history), usage and metadata (e.g., in the context of evaluating and measuring the success of marketing measures). As a general rule, we do not process special categories of personal data, unless they are part of commissioned processing. Data subjects include our customers, prospective customers, and their customers, users, website visitors, or employees, as well as third parties. The purpose of the processing is to provide contractual services, billing, and our customer service. The legal bases for processing are derived from Article 6(1)(b) of the GDPR (contractual services) and Article 6(1)(f) of the GDPR (analysis, statistics, optimization, and security measures). We process data that is necessary for the establishment and fulfillment of contractual services and indicate that the provision of such data is required. Disclosure to third parties occurs only if it is necessary within the scope of a contract. When processing data provided to us as part of a contract, we act in accordance with the client’s instructions and the legal requirements for data processing on behalf of a client pursuant to Article 28 of the GDPR, and we process the data for no other purposes than those specified in the contract.

We delete the data after the statutory warranty periods and comparable obligations have expired. The necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, the data is deleted upon their expiration (6 years, pursuant to Section 257(1) of the German Commercial Code (HGB), 10 years, pursuant to Section 147(1) of the German Fiscal Code (AO)). In the case of data disclosed to us by the client in connection with an engagement, we delete the data in accordance with the terms of the engagement, generally upon completion of the engagement.

Administration, Financial Accounting, Office Organization, Contact Management

We process data in connection with administrative tasks, the organization of our operations, financial accounting, and compliance with legal obligations, such as archiving. In doing so, we process the same data that we process in connection with the provision of our contractual services. The legal bases for processing are Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR. This processing affects customers, prospective customers, business partners, and website visitors. The purpose and our interest in the processing lie in administration, financial accounting, office organization, and data archiving—that is, tasks that serve to maintain our business operations, fulfill our responsibilities, and provide our services. The deletion of data relating to contractual services and contractual communication is in accordance with the information provided regarding these processing activities.

In this context, we disclose or transfer data to tax authorities, advisors (such as tax advisors or auditors), as well as other fee-collecting agencies and payment service providers.

In addition, based on our business interests, we store information about suppliers, event organizers, and other business partners—for example, for the purpose of contacting them at a later date. We generally store this data, which is primarily company-related, on a permanent basis.

Newsletter

If you would like to subscribe to the newsletter offered on the website, we need your email address as well as information that allows us to verify that you are the owner of the provided email address and that you consent to receiving the newsletter. In addition to your email address, we also collect other data that allows us to personalize or categorize your areas of interest.

To ensure that newsletters are sent only with the recipient’s consent, we use the so-called double opt-in procedure. As part of this process, potential recipients can be added to a mailing list. Users then receive a confirmation email giving them the opportunity to confirm their subscription in a legally compliant manner. Only once confirmation is received is the email address actively added to the mailing list. We use this data exclusively to send the requested information and offers.

We use Newsletter2Go as our newsletter software. Your data is transmitted to Newsletter2Go GmbH in this process. Newsletter2Go is prohibited from selling your data or using it for any purpose other than sending newsletters. Newsletter2Go is a German, certified provider that was selected in accordance with the requirements of the General Data Protection Regulation and the Federal Data Protection Act.

For more information, click here: Information for newsletter subscribers at NL2GO

You may revoke your consent to the storage of your data and email address, as well as their use for sending the newsletter, at any time—for example, by clicking the “Unsubscribe” link in the newsletter. Until you revoke your consent to receive our newsletter, this personal data will be stored for the purpose of sending newsletters (for direct marketing via email). After you unsubscribe from the newsletter, your data will be completely deleted for this purpose within 2 weeks.

The legal basis for storing data for our newsletter is the user’s consent. (Article 6(1)(a) (Consent) of the GDPR). Data protection measures are subject to ongoing technical updates; for this reason, we ask that you review our Privacy Policy at regular intervals to stay informed about our data protection practices. For more information, see NL2GO’s Privacy Policy.

Newsletter2Go GmbH’s mail servers have dedicated IP addresses. As a result, they—like the entire Newsletter2Go service—are subject exclusively to German data protection law. Newsletter2Go handles your recipients’ personal data with the utmost care. Resale or similar practices are strictly prohibited. For more information, see the Terms and Conditions.

DATA TRANSMISSION
By subscribing to our newsletter, you consent to the transmission of your data via an SSL-secured connection. No data will be transmitted unless you subscribe to the newsletter. Newsletter2Go allows us to analyze newsletter open and usage data.

Hosting and Email Delivery

The hosting services we use are intended to provide the following services: infrastructure and platform services, computing capacity, storage space, and database services, email delivery, security services, and technical maintenance services, which we utilize for the purpose of operating this online offering.

In this context, we—or our hosting provider—process inventory data, contact data, content data, contract data, usage data, meta and communication data from customers, prospective customers, and visitors to this online service based on our legitimate interests in providing this online service efficiently and securely in accordance with Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).

Collection of Access Data and Log Files

We, or rather our hosting provider, collect data regarding every access to the server on which this service is located (so-called server log files) based on our legitimate interests within the meaning of Article 6(1)(f) of the GDPR. The access data includes the name of the webpage accessed, the file, the date and time of access, the amount of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), IP address, and the requesting provider.

For security reasons (e.g., to investigate cases of misuse or fraud), log file information is stored for a maximum of 7 days and then deleted. Data that must be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.

Google Analytics

Based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic operation of our online service within the meaning of Article 6(1)(f) of the GDPR), we use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies. The information generated by the cookie regarding users’ use of the online service is generally transmitted to a Google server in the United States and stored there.

Google is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection law (Information on the Privacy Shield).

Google will use this information on our behalf to evaluate how users use our online service, to compile reports on activity within this online service, and to provide us with other services related to the use of this online service and Internet usage. In doing so, pseudonymous user profiles may be created from the processed data.

We use Google Analytics only with IP anonymization enabled. This means that Google truncates users’ IP addresses within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and truncated there.

The IP address transmitted by the user’s browser is not combined with other data held by Google. Users can prevent cookies from being stored by adjusting their browser settings accordingly; Users can also prevent Google from collecting the data generated by the cookie and related to their use of the online service, as well as from processing this data, by downloading and installing the browser plugin available at the following link: Browser Plugin.

For more information about Google’s use of data, as well as options for adjusting settings and opting out, please refer to Google’s Privacy Policy and the settings for Google ads.

Users’ personal data is deleted or anonymized after 14 months.

Facebook Pixel

We use the so-called Facebook Pixel on our site. This is a service and product of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, hereinafter referred to simply as “Facebook.” This service is used to analyze, evaluate, and track user behavior. In addition, the data and capabilities available to us allow us to place targeted advertisements via Facebook and Instagram. When a page on which the Facebook Pixel is installed is accessed, this information is transmitted to Facebook and, if the user is logged into Facebook at the same time, is associated with that user. This information is not directly accessible to the website operators, and they cannot draw any conclusions about individual users. Facebook is also obligated to comply with applicable standards and data protection regulations, as it is headquartered in the U.S. and is bound by the U.S.-EU Privacy Shield framework. If you wish to prevent Facebook from collecting and storing data about you and your behavior on our website, please follow this link and adjust your settings accordingly.

Social Media Presence

We maintain an online presence on social networks and platforms in order to communicate with customers, prospective customers, and users who are active there and to inform them about our services. When accessing these networks and platforms, the terms and conditions and data processing policies of their respective operators apply.

Unless otherwise specified in our Privacy Policy, we process users’ data when they communicate with us on social networks and platforms, such as by posting comments on our online presence or sending us messages.

Integration of Third-Party Services and Content

Within our online offering, we rely on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) to incorporate content or services from third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter collectively referred to as “Content”).

This always requires that the third-party providers of this content collect users’ IP addresses, since they would not be able to send the content to users’ browsers without the IP address. The IP address is therefore necessary for displaying this content. We make every effort to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These “pixel tags” allow information—such as visitor traffic on the pages of this website—to be analyzed. This pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, time of visit, and other details regarding the use of our online service, as well as being linked to such information from other sources.

0
0
Bestellung
Der Warenkorb ist leer.zurück zum Shop