Privacy Policy
(Datenschutz English)
Privacy Policy:
Introduction: This privacy policy (version 24.05.2025-113002165) explains how we, as data controllers, process your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and national laws. Our goal is to be transparent and easy to understand, avoiding overly technical language. If you have questions, contact us using the details in the "Contact Information of the Data Controller" section.
Scope of Application
This policy applies to all personal data we process within our company and by our commissioned processors. This includes data from:
-
Online presences (websites, online shops)
-
Social media profiles and email communication
-
Mobile apps for smartphones and other devices
"Personal data" refers to information like your name, email address, and mailing address (Art. 4 No. 1 GDPR).
Legal Basis for Processing Data
We process your data only when at least one of these conditions applies:
-
Consent (Article 6(1)(a) GDPR): You have given us explicit permission for a specific purpose (e.g., submitting a contact form).
-
Contract (Article 6(1)(b) GDPR): It's necessary to fulfill a contract or pre-contractual obligations with you (e.g., for a purchase).
-
Legal obligation (Article 6(1)(c) GDPR): We are legally required to process the data (e.g., retaining invoices for accounting).
-
Legitimate interests (Article 6(1)(f) GDPR): Processing is necessary for our legitimate interests that don't override your fundamental rights (e.g., secure and economic website operation).
In addition to EU law, national laws like Austria's Data Protection Act (DSG) and Germany's Federal Data Protection Act (BDSG) also apply.
Contact Information of the Data Controller
For any data protection questions, please contact: Constantin Michael Mittendrein Stattegger Straße 147, 8046 Graz Email: Constantin.3DS@gmail.com Phone: +43 669 19692323
Storage Duration
We store personal data only as long as necessary to provide our services and products. Data is deleted once the purpose for processing no longer exists, unless legal obligations require longer retention (e.g., for accounting). If you request deletion or withdraw consent, we will delete data as quickly as possible, subject to legal retention periods.
Your Rights Under the GDPR
As a data subject, you have the following rights:
-
Right to Information (Article 15 GDPR): Obtain confirmation if your data is processed, receive a copy, and learn details like processing purposes, data categories, recipients, storage duration, and data origin.
-
Right to Rectification (Article 16 GDPR): Have inaccurate data corrected.
-
Right to Erasure ("Right to be Forgotten") (Article 17 GDPR): Request the deletion of your data.
-
Right to Restriction of Processing (Article 18 GDPR): Limit our processing of your data to storage only.
-
Right to Data Portability (Article 20 GDPR): Receive your data in a commonly used format.
-
Right to Object (Article 21 GDPR): Object to processing based on public interest or legitimate interests; for direct marketing or profiling, you can object at any time.
-
Right not to be subject to automated individual decision-making (Article 22 GDPR): Under certain conditions.
-
Right to Lodge a Complaint (Article 77 GDPR): File a complaint with a supervisory authority if you believe your rights have been violated.
Austrian Supervisory Authority: Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Phone: +43 1 52 152-0, Email: dsb@dsb.gv.at, Website: https://www.dsb.gv.at
Data Transfers to Third Countries
We transfer data outside the EU ("third countries") only with your consent or if another legal basis exists (e.g., legal requirement, contract fulfillment). For transfers to the U.S., an adequate level of protection is generally only recognized if the U.S. company actively participates in the EU-U.S. Data Privacy Framework. Be aware that U.S. governmental authorities may access data, and collected data might be linked with other services of the same provider. We prioritize EU server locations where possible.
Data Processing Security
We use technical and organizational measures to protect personal data, including encryption and pseudonymization. We adhere to "data protection by design and by default" (Article 25 GDPR). Our website uses TLS encryption with HTTPS (visible by the padlock symbol and "https://" in the address bar) to ensure secure data transmission.
Communication
When you contact us via phone, email, or online forms, personal data (e.g., phone number, name, email address, form input) may be processed to handle your request. This data is stored for the duration of the business case and in accordance with legal requirements.
-
Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(b) GDPR (Contract), Art. 6(1)(f) GDPR (Legitimate Interest).
Cookies
Our website uses HTTP cookies to store user-specific data.
-
What are cookies? Small text files stored by your browser to remember preferences (e.g., language, session info). There are first-party and third-party cookies.
-
Types: Essential (for core functionality), Functional (user behavior/site performance), Preference (user settings), Marketing (personalized advertising).
-
Storage Duration: Varies from hours to years; you can delete them manually in your browser settings.
-
Legal Basis: Storing non-essential cookies requires consent (Art. 6(1)(a) GDPR). Essential cookies may be stored under legitimate interests (Art. 6(1)(f) GDPR).
Explanation of Key Terms
-
Processor (Art. 4 GDPR): A person/entity processing data on behalf of the controller (e.g., hosting providers).
-
Consent (Art. 4 GDPR): Freely given, specific, informed, unambiguous agreement to data processing.
-
Personal Data (Art. 4 GDPR): Any information relating to an identified or identifiable person (e.g., name, email, IP address). Includes special categories like health or biometric data.
-
Profiling (Art. 4 GDPR): Automated processing of personal data to evaluate aspects of a person (e.g., behavior, preferences) for purposes like advertising or credit checks.
-
Controller (Art. 4 GDPR): The person/entity determining the purposes and means of processing personal data (in our case, us).
-
Processing (Art. 4 GDPR): Any operation performed on personal data, including collection, storage, use, disclosure, erasure.
Final Note
We aim to inform you transparently about our data processing practices and the tools we use. We've tried to explain complex legal and technical terms in simple language, with further explanations provided. If you have any remaining questions, please contact us or the responsible authority.