privacy policy

Notes:

A privacy policy can only be created if all tools and applications used in the course of data processing (for marketing purposes), i.e. all categories of personal data and their use, are known. The following sample declaration therefore represents a framework that must be supplemented in the individual points depending on the processing. Source reference: This model declaration was drawn up in particular with reference to the data protection law forms manual2 (Koreng/Lachenmann) und dem WEKA-Werk Praxiswissen Datenschutz, Loseblattausgabe, erstellt.

To find out which cookies, plugins or other applications are active on your website, it is advisable to use various tools (cookie viewer or similar) to check whether cookies are stored - if this is the case, you should contact the website designer and obtain the relevant information. Some of the most common tools and plugins are included in this sample privacy policy.

No liability can be assumed for the completeness and correctness of this privacy policy in the event of unreflected use, especially since it must always be evaluated and adapted on the basis of the actual functions of a website or the data processing of a company. This sample can therefore only provide a guideline on how to create a legally correct privacy policy for your own website.

PRIVACY POLICY

Diese Website wird betrieben von der AUSZEIT St. Lambrecht GmbH (FN: 540296 d), in der Folge „wir“, „uns“ und „AUSZEIT – Rehazentrum St. Lambrecht GmbH“, mit Sitz in Hauptstraße 38 – 40, A-8813 St. Lambrecht Steiermark | Austria. In dieser Datenschutzerklärung wird von uns als Verantwortlichem nach Art. 4 Abs. 7 DSGVO beschrieben, welche Daten wir bei Ihrem Besuch auf unserer Website erheben und zu welchem Zweck wir diese verarbeiten. Zudem informieren wir Sie darüber, wie wir allgemein Daten unserer Kunden, Lieferanten und Interessenten verarbeiten und erläutern abschließend, welche Rechte und Sicherheiten wir im Zuge der Datenverarbeitung bieten. Alle relevanten Kontaktdaten entnehmen Sie bitte Punkt 11. dieser Datenschutzerklärung.

Since the protection of your personal data is of particular concern to us, we strictly adhere to the legal requirements of the DSG and the DSGVO when collecting and processing your personal data.

Below we inform you in detail about the scope and purpose of our data processing and your rights as a data subject. Therefore, please read our privacy policy carefully before you continue to use our website and, if necessary, give your consent to data processing. 

  1. Personal data

It is generally possible to use our website without providing personal data. However, different regulations may apply to the use of individual services, which we will inform you of separately.

Apart from the cookies described in detail below, we therefore only collect and store the data that you yourself provide to us by entering it in our input masks or actively interacting with our website in any other way.

Personal data is all information that relates to an identified or identifiable natural person. This includes, for example, your name, your address, your telephone number or your date of birth, but also your IP address or geolocation data that can be used to identify you.

  1. Use of cookies
  1. If you only use our website for information purposes, i.e. if you do not register for a service or otherwise provide us with information - for example via a contact form - we only collect the (personal) data that your browser transmits to our server. If you wish to visit our website, we collect the data listed below, which is technically necessary for us to display the website to you and to ensure its stability and security in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR:
  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request
  • Access status / http status code
  • Amount of data transferred in each case
  • Website from which the request comes
  • Browser used
  • Operating system and its interface
  • Language and version of the browser software

However, this data is not processed beyond the purpose of displaying our website.

  1. In addition to the aforementioned data, first and third-party cookies are stored on your computer when you use our website; these are small text files that are stored on your hard disk in the browser you are using. The place that sets a cookie (this is done either by us or an explicitly named third party) receives certain information as a result.

We need these cookies on the one hand to recognize you as a user of the website and on the other hand to be able to track the use of our services. Finally, we may use cookies for marketing purposes in order to analyze your usage behavior and to send you targeted advertising if necessary. 

  1. A basic distinction can be made between first party cookies, third party cookies and third party requests.
  • First Party Cookies

First party cookies are stored in your browser by us or our website itself in order to offer you the best possible user experience. These are functional cookies in particular, such as shopping cart cookies. We may also use cookies to identify you for subsequent visits if you have an account with us - otherwise you will have to log in each time you visit.

  • Third Party Cookies

Third-party cookies are stored in your browser by a third-party provider. These are usually tracking or marketing tools which, on the one hand, evaluate your user behaviour and, on the other hand, enable the third-party provider to recognize you on other websites you visit. Retarget marketing, for example, is generally based on the function of such cookies.

  • Third Party Requests

Third party requests are all requests that you as a site user make to third parties via our site - for example, if you interact with social network plugins or use the services of a payment provider. In this case, no cookies are stored in your browser, but it cannot be ruled out that personal data will be sent to this third-party provider as a result of the interaction. For this reason, we also inform you in detail in our privacy policy about the tools and applications we use.

  1. In order to provide you with comprehensive information about the cookies we use, we have designed a cookie banner in accordance with the ECJ case law of 01.10.2019, C-673/17 (Planet 49) and other relevant decisions, which is displayed when you first visit our website. This cookie banner shows all cookies used, including their function, storage duration and origin. Only if you consent to the use of some or all cookies will they be stored by us; an exception to this may be technically essential cookies, without whose use our website could not be displayed correctly.
  1. You can change your browser settings at any time, for example to refuse to accept third-party cookies or all cookies. In this case, however, we must point out that you may no longer be able to use all the functions of our website.
  1. Collection and processing of personal data
  1. Website

Personal data that goes beyond the information stored by cookies is only processed by us as part of the operation of our website if you provide it to us voluntarily, for example when you register with us, enter into a contractual relationship with us or otherwise contact us. This relates exclusively to contact details and information on the matters with which you contact us.

We only use the personal data you provide to the extent that this is necessary to fulfill the respective purpose of the processing (e.g. registration, sending newsletters, processing an order, sending information material and advertising, processing a competition, answering a question, providing access to certain information) and this is permitted by law (in particular pursuant to Art. 6 or Art. 9 GDPR). in accordance with Art. 6 or Art. 9 GDPR) (e.g. the sending of advertising and information material to existing customers in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR).

The purpose of processing your data is the operation of our website and the targeted provision of company-specific information, including the presentation of our range of goods and services (marketing).

Any further use of your data will only take place if you have given your express prior consent, if we need your data to fulfill a contract concluded with you or if we are obliged to retain it due to a legal provision. You can revoke any consent you have given at any time for the future, as explained in detail below.

[borlabs-cookie type=“btn-cookie-preference“ title=“Datenschutzeinstellungen“/]

  1. Contract processing, marketing and more

In general, we use personal data of our customers, suppliers and other contractual and cooperation partners, e.g. contact persons, their contact details and marketing-relevant information, for the purpose of contract processing and within the scope of statutory retention obligations (e.g. accounting), and also for legitimate interests, such as for marketing and customer care purposes.

We also collect personal data from interested parties (e.g. contact persons, their contact details and marketing-relevant information) in the course of our acquisition and sales activities. We are always on the lookout for potential contractual partners on the Internet, at trade fairs and at other events and maintain a marketing database for this purpose in order to enable targeted advertising for our products and services. We carry out all of the measures listed here in our legitimate interest for marketing purposes in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR in conjunction with recital 47 for a period of three years from the end of a contractual relationship (customers & suppliers) or our first (unsuccessful) contact (interested parties), unless the data subject has given their express consent beyond this.

If we do not collect personal data for marketing purposes from the data subject themselves, we will also inform the data subject of where we have collected their data in accordance with Art. 14 GDPR when they first contact us.

  1. Application management

We collect data from applicants for job offers open with us for the purpose of initiating a possible employment relationship Art. 6 para. 1 sentence 1 lit. b GDPR or, if necessary, on the basis of explicit consent for evidence purposes.

  1. Storage duration

We generally store data that you have provided to us exclusively for customer support or for marketing and information purposes for a period of three years after our last contact. However, if you so wish, we will also delete your data before this period expires, provided there is no legal obstacle to this.

In the event of contract initiation or conclusion, we process your personal data after complete contract processing until the expiry of the guarantee, warranty, limitation and statutory retention periods applicable to us, and beyond that until the end of any legal disputes in which the data is required as evidence.

We will only store data that you may send us as part of an application process for a period of 6 months without separate consent.

If storage is required by law, we will comply with the period standardized there. If we process your personal data for purposes other than those described in this privacy policy, for example for legitimate interest, we will inform you separately before processing begins.

  1. Data transmission
  1. General

Your data will not be transferred to third parties unless we are legally obliged to do so, the transfer of data is necessary for the execution of a contractual relationship concluded between us or you have previously expressly consented to the transfer of your data.

External processors or other cooperation partners will only receive your data if this is necessary for the execution of the contract, if we have a legitimate interest in it, which we always disclose separately in the event of an incident, or if this is necessary due to special standards, with your consent.

Your personal data will not be sold or otherwise marketed by us to third parties. If our contractual partners or processors are based in a third country, i.e. a country outside the European Economic Area (EEA), we will inform you of the consequences of this circumstance in the description of the offer.

If one of our processors comes into contact with your personal data, we ensure that they comply with the provisions of the data protection laws in the same way as we do.

  1. Data transfer to the USA?

We occasionally offer some services in the course of which data is or may be transferred to the USA. However, in order to use these services, it is necessary - unless there is another justification, such as the fulfillment of contractual obligations - that you consent to the use of your data collected via these services, including in the USA (Art. 49 para. 1 lit. a GDPR).

We collect this consent - depending on the service - via our cookie banner or separately by means of a corresponding declaration of consent directly before using a service offered.

Your consent is required because, according to recent decisions by authorities and courts and the case law of the ECJ, the USA is not considered to have an adequate level of data protection when processing personal data (C-311/18, Schrems II). These official and court decisions are particularly critical of the fact that access by US authorities (FISA 0702) is not comprehensively restricted by law, does not require approval by an independent authority and there are no relevant legal remedies available to those affected in the event of such interventions.

Apart from the contracts concluded with US service providers, we have no direct influence on the access of US authorities to personal data that is transferred to service providers in the USA when using these services. Even if we assume that our service providers take the necessary steps to guarantee the promised level of protection in accordance with the contractual agreements concluded with us, access by US authorities to data processed in the USA is nevertheless conceivable.

We therefore request your consent to the processing of data in the USA before using such services. We will point out separately for each service or application that there is a possibility of data transfer to the USA.

  1. Newsletter

You have the option of subscribing to our free newsletter. With this newsletter you will receive all the latest news and information about our company as well as customized advertising at regular intervals. To receive our newsletter, you need a valid e-mail address.

We check the e-mail address you have entered in our registration form to see whether you actually wish to receive newsletters. This is done by sending you an e-mail to the e-mail address you have provided, which you can confirm by clicking on a link provided. After confirming the e-mail, you are registered for our newsletter. (double opt-in)

We store your IP address and the date and time of your registration when you first subscribe to the newsletter. This is done for security reasons in case a third party misuses your e-mail address and subscribes to our newsletter without your knowledge. We do not collect and process any other data for the newsletter subscription; the data is used exclusively for the newsletter subscription.

Unless you object to this, we may transfer your data to companies affiliated with our company for the purpose of analysis and for the transmission of information for advertising purposes. Within the group of companies, your data that you have provided to us to receive the newsletter will be compared with data that may be collected by us elsewhere (e.g. when purchasing a product or booking a service).

Your newsletter registration data will not be passed on to third parties who are not part of the group of companies. You can unsubscribe from our newsletter at any time; you will find the details for unsubscribing in the confirmation email and in each individual newsletter.

  1. Tools and applications used
  1. We use Google Analytics, a web analytics service provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. This service uses cookies, the functionality of which has already been explained in detail above. The information generated by these cookies about your use of this website is generally transmitted to a Google server and stored there.

Google uses this information on our behalf to evaluate your use of our website, to compile reports on website activity and to provide other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

You can prevent the storage of the cookies required by Google Analytics by setting your browser software accordingly, although this may mean that you will not be able to use all the functions of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) as well as its transmission and processing by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de

If you would like further information on the type, scope and purpose of the data collected by Google, we recommend that you read their privacy policy. https://support.google.com/analytics/answer/6004245?hl=de

Google also processes your data in the USA. Before you give your consent to the storage of cookies through the use of Google Analytics, please read the relevant information in our privacy policy.

  1. We also use the services of Google Maps on our website. This enables us to show you interactive maps directly on our website and allows you to conveniently use the map function to find our location and make your journey easier.

When you visit our website, Google receives the information that you have accessed the corresponding subsite of our website and the personal data listed under 2. This takes place regardless of whether you are logged in via a Google account or not. If you are logged in to Google, your data will be assigned directly to your account. If you do not wish this to happen, you must log out of Google before using this service. Google uses your data for the purposes of advertising, market research and needs-based website design. You have the right to object to the use of your data in this regard, which you must address directly to Google.

Further information on the purpose and scope of data collection can be found in Google's privacy policy, which can be found at http://www.google.de/intl/de/policies/privacy. Google also processes your data in the USA. Before you give your consent to the storage of cookies through the use of Google Analytics, please read the relevant information in our privacy policy.

  1. We also provide links to other websites on our website for information purposes only. These websites are not under our control and are therefore not subject to the provisions of this privacy policy. However, if you activate a link, it is possible that the operator of this website will collect data about you and process it in accordance with its privacy policy, which may differ from ours. Please always inform yourself about the current data protection regulations on the websites we link to.
  1. Our website also offers the option of interacting with various social networks via plugins. These are
  • Facebook, betrieben von der Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland
  • Youtube, operated by Youtube LLC, 901 Cherry Avenue, San Bruno, CA 94066 USA
  • Instagram, betrieben von der Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland

If you click on a plugin of one of these social networks, it is activated and a connection to the respective server of this network is established as described above.

If you activate these plugins, you consent to the use of your data collected via these plugins in the USA.

Wir haben keinen Einfluss auf den Umfang und Inhalt der Daten, die durch den Klick auf das Plugin an den jeweiligen Betreiber dieses sozialen Netzwerks übermittelt werden bzw. welche in weiterer Folge dem Zugriff durch US-Behörden unterliegen können.

If you want to find out about the type, scope and purpose of the data collected by the operators of these social networks, we recommend that you read the data protection provisions of the respective social network.

Subject to your consent, our website uses a pixel or first party cookie provided by Teads to optimize our advertising campaigns. This Teads tracking technology collects information about the URL address, the type of end device, the browser and operating system you are currently using and your IP address. For more information, please read the Teads privacy policy. Please also note that you have the right to obtain information about the personal data Teads has stored about you and to request that your personal data be corrected, deleted or transferred. You may also have the right to object to certain processing or to request that Teads restricts such processing. You can exercise these rights by contacting Teads at dpo@teads.com.

  1. Joint responsibilities pursuant to Art. 26 GDPR
  1. Facebook - Fan page

We operate a Facebook fan page at https://www.facebook.com/AuszeitGesundheitszentrum. The purpose of this fan page is to share information about our company's activities, to implement marketing measures and to provide a further communication channel with us.

In this context, we are "joint controllers" with Facebook, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, which provides us with this service. In principle, Facebook allows you to select in your settings which personal data is shared with us. If you do not want this, we will receive all information regarding the use of our fan page and personal data about visitors in anonymized form.

For this purpose, we have concluded a so-called Art. 26 GDPR agreement with Facebook, in which the mutual rights and obligations of us and Facebook are regulated. This can be found at https://www.facebook.com/-legal/EU_data_transfer-_addendum/update. In this context, we also ask you to read Facebook's privacy policy, which you can find at https://www.facebook.com/policy.php finden.

In the Art. 26 GDPR agreement concluded by us, Facebook undertakes to be the first point of contact for data subjects regarding the processing of In-sights data and to fulfill the associated obligations and tasks.

You can therefore assert your data subject rights both against us in accordance with point 10 of this privacy policy and against Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

  1. Instagram - Profile

We operate an Instagram profile at https://www.instagram.com/auszeit_st.lambrecht/. We want to use this profile to implement marketing measures, draw attention to our products and services and create another communication channel with our customers.

In this context, we are also "joint controllers" with Instagram, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, which provides us with this service. In principle, Instagram allows you to select in your settings which personal data is shared with us. If you do not want this, we will receive all information regarding the use of our fan page and personal data about visitors in anonymized form.

For this purpose, we have concluded a so-called Art. 26 GDPR agreement with Instagram, in which the mutual rights and obligations of us and Instagram are regulated. This can be found at https://www.facebook.com/-legal/EU_data_transfer-_addendum/update. In this context, we also ask you to read Instagram's privacy policy, which you can find at https://help.instagram.com/519522125107875 finden.

In the Art. 26 GDPR agreement concluded by us, Instagram undertakes to be the first point of contact for data subjects regarding the processing of In-sights data and to fulfill the associated obligations and tasks.

You can therefore assert your data subject rights both against us in accordance with point 10 of this privacy policy and against Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

  1. Security

We use numerous technical and organizational security measures to protect your data against manipulation, loss, destruction and access by third parties. Our security measures are constantly being improved in line with technological developments on the Internet. Should you require more detailed information on the type and scope of the technical and organizational measures we have taken, please do not hesitate to contact us in writing at any time.

  1. Your rights

In accordance with the General Data Protection Regulation and the Data Protection Act, you are entitled to the following rights and legal remedies as a data subject of our data processing:

  • Right to information (Art. 15 GDPR)

As the data subject of the data processing described above and other data processing, you have the right to request information about whether and, if so, which personal data about you is being processed. For your own protection - so that no unauthorized person receives information about your data - we will verify your identity in a suitable form before providing information.

  • Right to rectification (Art. 16) and erasure (Art. 17 GDPR)

You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you or - taking into account the purposes of the data processing - the completion of incomplete personal data and the erasure of your data, provided that the criteria of Art. 17 GDPR are met.

  • Right to restriction of processing (Art. 18 GDPR)

Under the legal requirements, you have the right to restrict the processing of all personal data collected. This data will only be processed with your individual consent or for the assertion and enforcement of legal claims after the request for restriction.

  • Right to data portability (Art. 20 GDPR)

You may request the unhindered and unrestricted transfer of personal data that you have provided to us to you or a third party.

  • Right to object (Art. 21 GDPR)

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is necessary for the purposes of our legitimate interests or those of a third party. Your data will no longer be processed after objection, unless there are compelling legitimate grounds for processing that outweigh your interests, rights and freedoms or the processing serves to assert, exercise or defend legal claims. You can object to data processing for the purpose of direct advertising at any time with effect for the future.

  • Revocation of consent

If you have separately given your consent to the processing of your data, you can withdraw this at any time. Such a revocation affects the permissibility of processing your personal data after you have given it to us.

If you take a measure to enforce your above-mentioned rights under the GDPR, AUSZEIT - Rehazentrum St. Lambrecht GmbH must respond to the requested measure or comply with the request immediately, but at the latest within one month of receipt of your request.

We will respond to all reasonable requests within the legal framework free of charge and as promptly as possible.

The data protection authority is responsible for applications concerning violations of the right to information, violations of the right to confidentiality, rectification or erasure. Their contact details are as follows:

Austrian Data Protection Authority

Barichgasse 40-42

1030 Wien

dsb@dsb.gv.at

  1. Contact information / contact person
  1. Contact information of the person responsible
  1. Contact information of the contact person for data protection matters

11. Competitions

Personal data must be provided in order to participate in the competition. The participant assures that the personal details provided by him/her, in particular first name, surname, address, email address and telephone number, are true and correct.

The organizer points out that all personal data of the participant will neither be passed on to third parties nor made available to them for use without consent. An exception to this is the company Österreichische Post AG commissioned to carry out the mailing, which must collect, store and use the data for the purpose of carrying out the mailing.

The data collected in connection with the competition will be deleted at the end of the competition, unless statutory retention periods prevent this.

The privacy policy and further information can be found at Datenschutzerklärung (bmk.gv.at) aufgerufen werden.

Status: January 2023