Legal Notice & Legal Notice
Responsible party
Stefan Beck
Brandnerhus Projekt GmbH
Taverneweg 4
6832 Sulz
Email: office@brandnerhus.at
VAT ID: ATU75537215
Privacy Policy
This Privacy Policy explains to you the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) on our website and the associated websites, and in relation to features and content, as well as external online presences, such as our social media profile (hereinafter jointly referred to as the “online offering”). With regard to the terms used, such as “processing” or “data controller”, we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Types of data processed:
– Inventory data (e.g., names, addresses).
– Contact data (e.g., email address, phone numbers).
– Content data (e.g., text inputs, photographs, videos).
– Usage data (e.g., websites visited, interest in content, times of access).
– Meta/communication data (e.g., device information, IP addresses).
Purpose of the processing:
– To provide the online offering, its features and content.
– To respond to contact requests and communicate with users.
– Security measures.
– Reach measurement/marketing
Terms used
“Personal data” means all information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); a natural person is regarded as identifiable if he or she can be directly or indirectly identified – especially by means of association with an identifier such as a name – with an identification number, with location data, with an online identifier (e.g., a cookie), or with one or several special features reflecting the physical, physiological, genetic, psychological, economic, cultural, or social identity of that natural person. “Processing” means any operation carried out with or without the aid of automated procedures, or any such series of operations in connection with personal data. The term is broad and covers virtually every aspect of dealing with data. “Controller” refers to the natural or legal person, public authority, institution, or other body that alone or jointly with others determines the purposes and means of the processing of personal data.
Relevant legal basis
In accordance with Art. 13 GDPR, we inform you of the legal bases for the data processing we carry out. If the legal basis is not mentioned in the Privacy Policy, the following applies: the legal basis for obtaining consent is Art. 6 (1) (a) and Art. 7 GDPR, the legal basis for processing to fulfil our services and execute contractual measures, as well as for replying to enquiries, is Art. 6 (1) (b) GDPR, the legal basis for processing to fulfil our legal obligations is Art. 6 (1) (c) GDPR, and the legal basis for processing to protect our legitimate interests is Art. 6 (1)(f) GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) (d) GDPR applies as the legal basis.
Working together with processors and third parties
If we disclose data to other persons and companies (processors or third parties) within the scope of our processing, transmit the data to them, or otherwise grant them access to the data, this shall only take place on the basis of some legal permission (e.g., if transmission of the data to third parties, such as payment service providers, in accordance with Art. 6 (1) (b) GDPR is required to fulfil a contract), you have consented, a legal obligation provides for this, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.). If we commission third parties with the processing of data on the basis of a so-called “data processing contract”, this is done on the basis of Art. 28 GDPR.
Transfers to third-party countries
If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of the use of third-party services or data disclosure or transfer to third parties, this will only take place to fulfil our (pre)contractual obligations, on the basis of your consent, in the basis of a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or have the data processed in a third country only if the particular requirements of Article 44 ff. GDPR are met. This means, for example, that the processing is carried out on the basis of special guarantees, such as the officially recognised determination of a data protection level equivalent to that of the EU (e.g., through the “Privacy Shield” for the USA) or compliance with officially recognised special contractual obligations (so-called “standard contractual clauses”).
Making contact
When contacting us (for example, by contact form, email, telephone or via social media), the user’s details are processed in order to handle and transact the contact enquiry in accordance with Art. 6 (1) (b) GDPR. User information can be stored in a customer relationship management system (“CRM system”) or comparable enquiry organisation system. We delete enquiries if they are no longer required. We review whether they are required every two years; the legal archiving obligations also apply.
Google Analytics
Based on our legitimate interests (i.e., interest in the analysis, optimisation, and economical operation of our online offering within the meaning of Art. 6 (1)(f) GDPR), we use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies. The information generated by the cookie about the user’s use of the online offering is generally transmitted to and stored on a Google server in the USA. Google is certified under the Privacy Shield agreement, thereby offering a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). Google will use this information on our behalf to analyse the use of our online offering by users, compile reports on activities within this online offering, and provide us with other services related to the use of this online offering and the Internet. Pseudonymous usage profiles of users may be created from the data processed. We only use Google Analytics with IP anonymisation enabled. This means that users’ IP addresses are truncated by Google within EU member states or other countries party to the Agreement on the European Economic Area. Only in exceptional cases are IP addresses transferred to a Google server in the USA and truncated there. The IP address sent by your browser will not be associated with other data held by Google. Users may prevent the storage of cookies by selecting the appropriate settings in their browser; users can also prevent Google from collecting the data generated by cookies regarding their use of the website, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en. Further information on Google’s use of data, as well as settings and means of objection, can be found in Google’s Privacy Policy (https://policies.google.com/technologies/ads) and in the settings for the display of advertisements by Google (https://adssettings.google.com/authenticated). Users’ personal data will be deleted or anonymised after 14 months.
Google Fonts
We integrate the fonts (“Google Fonts”) of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, opt-out: https://adssettings.google.com/authenticated.
Google Maps
We integrate maps from the service “Google Maps” from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The processed data may include, in particular, IP addresses and location data of the users, though these are not collected without the users’ consent (as a rule, within the framework of the settings of their mobile devices). The data may be processed in the USA. Privacy Policy: https://www.google.com/policies/privacy/, opt-out: https://adssettings.google.com/authenticated.