PRIVACY POLICY
Collection and Use of Data

Personal data refers to any information that can be used to identify a specific person. This includes, for example, your name, address, email address, or phone number.

Collection of Personal Data When Using Our Website

When you use our website for informational purposes only—meaning you do not register or provide us with any other information—we collect only the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display the website to you and to ensure stability and security:

  • IP address
  • Date and time of the request
  • Time zone difference from Greenwich Mean Time (GMT)
  • Specific page requested
  • Access status/HTTP status code
  • Amount of data transmitted
  • Website from which the request originates
  • Browser type
  • Operating system and its interface
  • Language and version of the browser software

The legal basis for storing this data is Article 6(1)(f) of the GDPR.

 

Collection of Personal Data During Registration

We offer you the opportunity to register on our website by providing personal data. Depending on the type of contract entered into, we store the following information:

  • First and last name
  • Address
  • Billing address
  • Email address
  • Phone number

During the registration process, you will be asked to confirm that you have read and agree to our Privacy Policy by checking the corresponding box. By doing so, you consent to the use of your personal data for the following purposes:

  • Processing orders
  • Sending direct marketing materials, such as emails, package inserts, or postal offers and vouchers
  • Sending review requests
  • Sending our newsletter 

The legal basis for processing your data is your consent under Article 6(1)(a) of the GDPR. If the registration is necessary for fulfilling a contract or carrying out pre-contractual measures with you, Article 6(1)(b) of the GDPR also applies.

 

Name and Contact Information of the Data Controller 

The entity responsible for managing personal data is:

VINOBLE COSMETICS GmbH
8441 Fresing 17a | Austria
Managing Director: Luise Köfer

E-Mail: [email protected]

Contact Information of the Data Protection Officer

You can contact our Data Protection Officer at:
E-Mail:  [email protected]

 

Purposes of Processing Personal Data

 
We store your data solely for the following purposes:

To process orders (including payment processing and, if necessary, credit checks), to send advertising on our behalf, and to provide customer service.

We store and process your personal data at our central company headquarters.

Your personal data will only be transferred to third parties if it is necessary for contract execution, billing, or debt collection purposes (e.g., shipping companies or payment service providers), or if you have explicitly given your consent.

The legal basis for the transfer of data to third parties for contract execution or billing purposes is Article 6(1)(b) GDPR. For disclosures required by law, the legal basis is Article 6(1)(c) GDPR.


Duration of Data Storage

We store your data for as long as it is required for the respective purpose while balancing your legitimate interests. If specific data processed for contract execution is subject to tax retention obligations, it will be stored for 7 or 30 years. During this period, data processing will be restricted after two years, meaning the data will only be used to fulfill legal obligations. The retention period begins at the end of the calendar year in which the order was placed or the contract was fulfilled.

Disclosure of Personal Data to Third Parties

We may share your personal data in accordance with legal requirements with the following companies or categories of recipients:

(1)    Tax Authorities, Auditors, and Other Authorities

External service providers and professional advisors such as lawyers, auditors, accountants, credit agencies for credit checks, debt collection agencies, postal/shipping service providers, payment providers such as PayPal (Europe) S.à r.l. et Cie, S.C.A, 22-24 Boulevard Royal, L-2449 Luxembourg; Klarna AB (publ), Sveavägen 46, 111 34 Stockholm, Schweden.

(2)    E-Commerce & Content Management System Magento

Our website uses the content management system Magento, an e-commerce platform provided by Adobe Inc. (formerly Magento Inc.), 345 Park Avenue, San Jose, CA 95110-2704, USA. Magento is used for the administration and presentation of our online shop content.

The hosting infrastructure is provided by CLOUDWAYS, a platform operated by DigitalOcean LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA. The servers are located in Frankfurt am Main, Germany. Accordingly, the storage and processing of data take place within the European Union.

When you visit our website, various cookies are set. These enable essential security functions (e.g., access to secured areas of the website or order processing in the online shop) and are therefore technically necessary for website usage. As a result, they cannot be disabled. Additionally, cookies that improve website comfort and usability are set. Since these are functional cookies, consent is requested. No data is transferred to Magento or third parties.

The legal basis for transferring data to third parties for contract execution or billing purposes is Article 6(1)(b) GDPR, while the legal basis for legally mandated disclosures is Article 6(1)(c) GDPR.

 

Your Rights

To exercise your rights, you can use the contact option provided at https://www.vinoble-cosmetics.at/kontakt or contact us at [email protected].

You have the following rights:

1. Revocation of Consent

You can revoke your consent to the processing of personal data at any time with future effect. For this, you can use the contact options provided above (https://www.vinoble-cosmetics.at/kontakt).

2. Other Rights

You also have the following rights with respect to your personal data:

  • Right to access
  • Right to rectification
  • Right to erasure or restriction of processing
  • Right to object to processing
  • Right to data portability 

Additionally, you have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data by us.

The competent data protection supervisory authority for Austria is:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna

 

Contact Form

When you send us inquiries via the contact form, we will use your data solely for processing your request. Your data will not be used for advertising purposes or shared with third parties.

The legal basis for processing the data transmitted via the contact form or in the course of sending an email is Article 6(1)(f) GDPR. If the contact is intended to conclude a contract, the additional legal basis for processing is Article 6(1)(b) GDPR.

The data you enter in the contact form will be stored by us until you request deletion, revoke your consent for storage, or the purpose for storing the data no longer applies.

 

Cookies

In order to make the visit to our online offering attractive and to enable the use of certain features, we use cookies. These are small text files that your web browser receives when you visit our pages and stores on your computer. Some of the cookies are automatically deleted after closing the browser. Other cookies remain on your computer and allow us to recognize you or your device on your next visit to our website.

This site uses the following types of cookies, the scope and functionality of which are explained below:

a) Session Cookies:

These are automatically deleted when you close your browser. Specifically, these are session cookies that store a session ID, which allows the various requests of your browser to be assigned to the same session. This enables your device to be recognized when you return to our website. Session cookies are deleted when you log out or close the browser.

b) Persistent Cookies:

These are automatically deleted after a specified duration, which can vary depending on the cookie. You can delete cookies at any time in your browser’s security settings.

You can influence the use of cookies by changing your browser settings. Most browsers offer an option to restrict or block the saving of cookies. Each browser manages cookie settings individually. You can find the relevant instructions in the help menu of your browser.

The links to manage cookies in your browser settings are as follows:

·        Internet Explorer: http://windows.microsoft.com/de-DE/windows-vista/Block-or-allow-cookies

·        Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen

·        Chrome: http://support.google.com/chrome/bin/answer.py?hl=de&hlrm=en&answer=95647

·        Safari: https://support.apple.com/kb/ph21411?locale=de_DE

Please note that disabling cookies may limit the functionality of the website. The legal basis for the use of cookies is Article 6(1)(f) GDPR.


Google Tag Manager

We use the Google Tag Manager service on our website. This service is provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Tag Manager allows marketers to manage website tags through an interface. A tag is a marker or identifier applied to a dataset. The Tag Manager itself—which implements the tags—operates without the use of cookies and does not collect any personal data. 

Tags deployed via Google Tag Manager may trigger the collection of data, but this data is only passed on to the respective target systems. Google Tag Manager does not access or store this data. It solely facilitates the activation of other tags, which in turn may collect data under their own responsibility. Information about these third-party services can be found in the relevant sections of this privacy policy. Google Tag Manager does not use this data for its own purposes. 

If you have disabled cookies—either via browser settings or consent management—this setting will be respected for all tracking tags implemented through Google Tag Manager. The tool does not modify your cookie preferences. 

In some cases, Google may ask for your permission to share certain product data (e.g., account information) with other Google products to enable specific features, such as simplifying the addition of new AdWords conversion tracking tags. In addition, Google developers may occasionally review aggregated product usage information to further optimize the product. However, Google will not share such data with other Google products without your explicit consent.

 For more information, please refer to Google’s Terms of Service and Google’s Privacy Policy for this product.

 

Use of Google Analytics

Our website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies," which are text files stored on your computer, to analyze your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. In the event that IP anonymization is activated on this website, however, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide further services related to website usage and internet usage to the website operator.

The IP address transmitted by your browser within the framework of Google Analytics will not be merged with other data from Google.

You can prevent the storage of cookies by adjusting your browser software accordingly. However, we point out that in this case, you may not be able to use all features of this website to their full extent. Additionally, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link:

http://tools.google.com/dlpage/gaoptout?hl=de.

This website uses Google Analytics with the "_anonymizeIp()" extension. This ensures that IP addresses are shortened and further processing is done in a way that prevents personal identification. In cases where data collected about you has a personal reference, this will be immediately excluded, and the personal data will be deleted.

We use Google Analytics to analyze and regularly improve the use of our website. The statistics obtained help us improve our offerings and make them more interesting for you as a user. In exceptional cases where personal data is transferred to the USA, Google has self-certified under the EU-US Privacy Shield:

https://www.privacyshield.gov/EU-US-Framework.

Third-party information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. Google Analytics Terms: http://www.google.com/analytics/terms/de.html, Privacy Overview: http://www.google.com/intl/de/analytics/learn/privacy.html, and Privacy Policy: http://www.google.de/intl/de/policies/privacy.

 

Google Analytics Remarketing

Our websites use the features of Google Analytics Remarketing in conjunction with the cross-device capabilities of Google Ads and Google DoubleClick. These services are provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

This functionality allows the advertising audiences created with Google Analytics Remarketing to be linked to the cross-device functions of Google Ads and Google DoubleClick. In this way, interest-based, personalized advertising messages—adapted to your previous usage and browsing behavior on one device (e.g., a smartphone)—can also be displayed on another of your devices (e.g., tablet or desktop).

If you have given the appropriate consent, Google will link your web and app browsing history with your Google account. This allows personalized advertising messages to be shown across any device on which you are signed in with your Google account.

To support this feature, Google Analytics collects Google-authenticated user IDs, which are temporarily linked with our Google Analytics data in order to define and create audiences for cross-device advertising.

You can permanently opt out of cross-device remarketing/targeting by disabling personalized advertising in your Google account settings: https://www.google.com/settings/ads/onweb

The aggregation of data in your Google account takes place exclusively based on your consent, which you may give or revoke at Google (Art. 6 para. 1 lit. a GDPR). For data collection processes that are not merged into your Google account (e.g., if you do not have a Google account or have objected to such merging), the data is processed on the basis of Art. 6 para. 1 lit. f GDPR. The legitimate interest arises from our need as website operators to conduct anonymized analysis of website visitors for advertising purposes.

Further information and Google’s privacy policy can be found at: https://www.google.com/policies/technologies/ads/

 

Google Ads and Google Conversion Tracking

This website uses Google Ads, an online advertising platform provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

As part of Google Ads, we use conversion tracking. When you click on an ad served by Google, a cookie is set for conversion tracking. Cookies are small text files that your internet browser stores on your device. These cookies expire after 30 days and are not used to personally identify users. If a user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to the corresponding page.

Each Google Ads customer receives a different cookie. These cookies cannot be tracked across the websites of different Ads customers. The information collected using the conversion cookie is used to generate conversion statistics for Ads customers who have opted in to conversion tracking. Customers receive information such as the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that can personally identify users.

If you do not wish to participate in tracking, you can opt out by disabling the Google Conversion Tracking cookie in your browser settings. You will then not be included in the conversion tracking statistics.

The storage of “conversion cookies” is based on Art. 6 para. 1 lit. f GDPR. As the website operator, we have a legitimate interest in analyzing user behavior in order to optimize both our website and our advertising.

You can find more information about Google Ads and Google Conversion Tracking in Google's privacy policy: https://www.google.de/policies/privacy/

You can configure your browser to notify you when cookies are being set, to allow cookies on a case-by-case basis, to refuse the acceptance of cookies in certain cases or in general, and to automatically delete cookies when the browser is closed. Please note that disabling cookies may limit the functionality of this website.


Right to Object

You can object to the collection and storage of data for the purpose of usage analysis at any time with effect for the future by notifying us of your objection, e.g., by email to: [email protected].

The legal basis for the use of analysis tools is Article 6(1)(f) of the GDPR.

 

Social Media Links

On our website, we provide links to social media platforms Facebook, Instagram, LinkedIn, and TikTok using their respective icons. These are hyperlinks, and no data transmission occurs through them. If you click on the link, you will be directly redirected to our respective social media presence. Data will only be transmitted to the respective social media service if you are logged into your user account with the respective platform. In this case, the social media platform may obtain information about which content you have viewed on our website.

We are solely responsible for the social media services linked to on our website:

For Facebook and its website, the responsible party is Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA;

For Instagram and its website, the responsible party is Instagram, LLC, 1601 Willow Rd., Menlo Park, CA 94025, USA;

For LinkedIn and its website, the responsible party is LinkedIn Corporation, 1000 W Maude Ave, Sunnyvale, CA 94085, USA;

For TikTok and its website, the responsible party is TikTok Inc., 5800 Bristol Parkway, Culver City, CA 90230, USA;

For further information about the purpose and extent of data collection, processing, and use by the respective social media platform, please refer to their privacy policies.

 

Newsletter

(1) With your consent, you can subscribe to our newsletter, through which we inform you about our current offers. The promoted goods and services are specified in the consent form.

(2) We use the double opt-in method for newsletter subscription. This means that after registering, we send an email to the provided email address asking for confirmation that you wish to receive the newsletter. If you do not confirm your subscription, your information will be blocked and automatically deleted after one month. We also store the IP addresses and timestamps of the registration and confirmation. This process aims to verify your subscription and to clarify any potential misuse of your personal data.

(3) The only mandatory information for the newsletter subscription is your email address. Additional, marked data is optional and used to personalize communication. After confirmation, we store your email address to send the newsletter. The legal basis is Article 6(1)(a) of the GDPR.

(4) You can withdraw your consent to receive the newsletter at any time and unsubscribe. You can do so by clicking the link provided in every newsletter email, by emailing us at [email protected], or by contacting us via the details provided in the imprint.

When you subscribe to our newsletter, the data you provide, including your email address, is transferred, stored, and processed by MailChimp. This allows us to send you regular updates, offers, and information.

MailChimp offers extensive analytics regarding how the newsletters are opened and used. These analyses are grouped and are not used for individual evaluation.

The data stored at MailChimp is deleted once you unsubscribe from the newsletter. This does not affect data stored for other purposes.

MailChimp has its own privacy policies and practices, which may differ from ours. For more information on MailChimp’s privacy practices, please visit: MailChimp Privacy. If you have any questions regarding the data collected by MailChimp or want to exercise your rights concerning this data, please contact The Rocket Science Group, LLC directly.

 

Facebook Remarketing/ Retargeting

(1) On our website, we use Facebook's "Custom Audiences" for retargeting/remarketing, a service provided by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook"). This service uses tracking or remarketing pixels, which are pixel image files that allow log file analysis. The pixels allow the service provider to see when and how many users have accessed the pixel, or whether and when an email was opened or a website visited.

(2) With this service, users of the website may see interest-based advertisements ("Facebook Ads") on Facebook or other websites using the same procedure. Our goal is to display advertisements that are of interest to you, to make our website more interesting for you. When you visit our website, a direct connection to Facebook's servers is established through the pixel. This enables Facebook to identify you via your browser ID, as this can be linked to your user account. We have no control over the scope and further use of the data collected through Facebook’s use of this tool and inform you based on our knowledge: Through the integration of Facebook Custom Audiences, Facebook receives information that you have accessed the respective page on our website or clicked on one of our advertisements. If you are registered with a Facebook service, Facebook can associate this visit with your account. Even if you are not registered or logged in to Facebook, there is a possibility that Facebook will learn and store your IP address and other identifying features.

(3) You can disable the "Facebook Custom Audiences" feature for logged-in users at https://www.facebook.com/settings/?tab=ads#_.

(4) The legal basis for processing your data is Article 6(1)(f) of the GDPR. Further information on data processing by Facebook can be found at: https://www.facebook.com/about/privacy/.  

Right to Object
If you do not wish to receive targeted advertising generated by the respective targeting service, you can object to the use of retargeting technology on our website by sending us a message at [email protected].

 

Klarna

In order to offer you payment via Klarna, your personal data (contact and delivery details) may be transferred to Klarna. This is necessary for Klarna to check your eligibility to use the payment method. Personal data transmitted to Klarna will be processed in accordance with Klarna's privacy policies.


Data Security

We have implemented various security measures to protect your personal data. Our servers and databases are protected by both physical and technical measures.

For data collection and transmission on our website, we use the standard SSL encryption technology. Personal data transmitted during the ordering process is encrypted using SSL, identifiable by the lock symbol in the browser and the "https://" prefix in the address bar.

With encrypted communication, your payment data transmitted to us cannot be read by third parties. However, 100% data security cannot be guaranteed when communicating via email.

 

Changes to This Privacy Policy

This privacy policy may be changed by us at any time. All changes will be posted on this website and will automatically become effective 30 days after their publication. We will inform you of any significant changes to this privacy policy via email.

Status: February 13, 2023