Personal data (usually referred to just as “data” below) will only be processed by me to the extent necessary and for the purpose of providing a functional and user-friendly website, including its contents, and the services offered there.

Per Art. 4 No. 1 of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as the “GDPR”), “processing” refers to any operation or set of operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction performed on personal data, whether by automated means or not.

The following privacy policy is intended to inform you in particular about the type, scope, purpose, duration, and legal basis for the processing of such data either under my own control or in conjunction with others. I also inform you below about the third-party components I use to optimize this website and improve the user experience which may result in said third parties also processing data they collect and control.

This privacy policy is structured as follows:

I. Information about me as controllers of your data
II. The rights of users and data subjects
III. Information about the data processing

I. Information about me as controllers of your data

The party responsible for this website (the “controller”) for purposes of data protection law is:

Simona Ledl
Apothekerhofstr 7
Salzburg 5020
Austria

Send email

II. The rights of users and data subjects

With regard to the data processing to be described in more detail below, users and data subjects have the right

  • to confirmation of whether data concerning them is being processed, information about the data being processed, further information about the nature of the data processing, and copies of the data (cf. also Art. 15 GDPR);
  • to correct or complete incorrect or incomplete data (cf. also Art. 16 GDPR);
  • to the immediate deletion of data concerning them (cf. also Art. 17 DSGVO), or, alternatively, if further processing is necessary as stipulated in Art. 17 Para. 3 GDPR, to restrict said processing per Art. 18 GDPR;
  • to receive copies of the data concerning them and/or provided by them and to have the same transmitted to other providers/controllers (cf. also Art. 20 GDPR);
  • to file complaints with the supervisory authority if they believe that data concerning them is being processed by the controller in breach of data protection provisions (see also Art. 77 GDPR).

In addition, the controller is obliged to inform all recipients to whom it discloses data of any such corrections, deletions, or restrictions placed on processing the same per Art. 16, 17 Para. 1, 18 GDPR. However, this obligation does not apply if such notification is impossible or involves a disproportionate effort. Nevertheless, users have a right to information about these recipients.

Likewise, under Art. 21 GDPR, users and data subjects have the right to object to the controller’s future processing of their data pursuant to Art. 6 Para. 1 lit. f) GDPR. In particular, an objection to data processing for the purpose of direct advertising is permissible.

III. Information about the data processing

Your data processed when using this website will be deleted or blocked as soon as the purpose for its storage ceases to apply, provided the deletion of the same is not in breach of any statutory storage obligations or unless otherwise stipulated below.

Server data

For technical reasons, the following data sent by your internet browser to me or to my server provider will be collected, especially to ensure a secure and stable website: These server log files record the type and version of your browser, operating system, the website from which you came (referrer URL), the webpages on this site visited, the date and time of your visit, as well as the IP address from which you visited this site.

The data thus collected will be temporarily stored, but not in association with any other of your data.

The basis for this storage is Art. 6 Para. 1 lit. f) GDPR. My legitimate interest lies in the improvement, stability, functionality, and security of this website.

The data will be deleted within no more than seven days, unless continued storage is required for evidentiary purposes. In which case, all or part of the data will be excluded from deletion until the investigation of the relevant incident is finally resolved.

Encryption through SSL / TLS

For security reasons, my website uses SSL or TLS encryption. This ensures that transmitted data is protected and cannot be read by third parties. You can recognize successful encryption by the fact that the protocol name in the status bar of the browser changes from “http://” to “https://” and that a closed lock symbol is visible there.

System and information security

I secure my website and my other systems through technical and organizational measures against loss, destruction, access, modification or dissemination of the stored data by unauthorized persons. Despite controls, however, complete protection against all dangers is not possible. The connection to the Internet and the resulting technical possibilities alone mean that no guarantee can be given that content and the flow of information will not be viewed and recorded by third parties.

Cookies

a) Session cookies

I use cookies on this website. Cookies are small text files or other storage technologies stored on your computer by your browser. These cookies process certain specific information about you, such as your browser, location data, or IP address.

This processing makes this website more user-friendly, efficient, and secure, allowing me, for example, to display this website in different languages or to offer a shopping cart function. You can find information about the cookies I use in the Cookie Policy.

The legal basis for such processing is Art. 6 Para. 1 lit. b) GDPR, insofar as these cookies are used to collect data to initiate or process contractual relationships.

If the processing does not serve to initiate or process a contract, my legitimate interest lies in improving the functionality of this website. The legal basis is then Art. 6 Para. 1 lit. f) GDPR.

When you close your browser, these session cookies are deleted.

b) Third-party cookies

If necessary, this website may also use cookies from companies with whom I cooperate for the purpose of advertising, analyzing, or improving the features of this website.

Please refer to the following information for details, in particular for the legal basis and purpose of such third-party collection and processing of data collected through cookies.

c) Disabling cookies

You can refuse the use of cookies by changing the settings on your browser. Likewise, you can use the browser to delete cookies that have already been stored. However, the steps and measures required vary, depending on the browser you use. If you have any questions, please use the help function or consult the documentation for your browser or contact its maker for support. Browser settings cannot prevent so-called flash cookies from being set. Instead, you will need to change the setting of your Flash player. The steps and measures required for this also depend on the Flash player you are using. If you have any questions, please use the help function or consult the documentation for your Flash player or contact its maker for support.

If you prevent or restrict the installation of cookies, not all of the functions on this site may be fully usable.

Order processing

The data you submit when ordering goods and/or services from me will have to be processed in order to fulfill your order. Please note that orders cannot be processed without providing this data.

The legal basis for this processing is Art. 6 Para. 1 lit. b) GDPR.

After your order has been completed, your personal data will be deleted, but only after the retention periods required by tax and commercial law.

In order to process your order, I will share your data with the shipping company responsible for delivery to the extent required to deliver your order and/or with the payment service provider to the extent required to process your payment.

The legal basis for the transfer of this data is Art. 6 Para. 1 lit. b) GDPR.

Contact

If you contact me via email or the contact form, the data you provide will be used for the purpose of processing your request. I must have this data in order to process and answer your inquiry; otherwise we will not be able to answer it in full or at all.

The legal basis for this data processing is Art. 6 Para. 1 lit. b) GDPR.

Your data will be deleted once I have fully answered your inquiry and there is no further legal obligation to store your data, such as if an order or contract resulted therefrom.

User posts, comments, and ratings

I offer you the opportunity to post questions, answers, opinions, and ratings on this website, hereinafter referred to jointly as “posts.” If you make use of this opportunity, I will process and publish your post, the date and time you submitted it, and any pseudonym you may have used.

The legal basis for this is Art. 6 Para. 1 lit. a) GDPR. You may revoke your prior consent under Art. 7 Para. 3 GDPR with future effect. All you have to do is inform me that you are revoking your consent.

In addition, I will also process your IP address and email address. The IP address is processed because I might have a legitimate interest in taking or supporting further action if your post infringes the rights of third parties and/or is otherwise unlawful.

In this case, the legal basis is Art. 6 Para. 1 lit. f) GDPR. My legitimate interest lies in any legal defense I may have to mount.

Mailerlite

To send my (heART&mind) newsletter, I use the services of MailerLite Limited, a company registered in Ireland with its registered office at 38 Mount Street Upper, Dublin 2, D02 PR89 Ireland

If you subscribe to my e-mail newsletter and wish to read it regularly, you must register with a valid e-mail address and thus consent to the processing of your personal data by me. Please refer to the declaration of consent on the newsletter registration form.

Before sending the newsletter, you must expressly confirm to me as part of the so-called double opt-in procedure that I should activate the email newsletter service for you. I do this to prevent third-party email addresses from being used for registrations. You will receive a confirmation and authorization e-mail from me asking you to click on the link contained in this e-mail to confirm that you wish to receive my newsletter. If you do not confirm, your personal data will be deleted within 90 days.

In connection with the registration, in addition to the e-mail address, the time of registration, the time of confirmation, the IP address and the consent text are stored and I use the e-mail address exclusively for the delivery of the newsletter unless you have expressly consented to any other use.

This data is stored on the servers of MailerLite Limited.

Small, “invisible” files (beacons) that are sent with the newsletter can be used for various evaluations to improve my offers. The IP address, browser and time of retrieval and opening of the newsletter and the click behavior on links contained in the newsletter are recorded and statistically evaluated.

Mailerlite has undertaken to comply with the GDPR guidelines. You can find more information on this at: https://www.mailerlite.com/gdpr-compliance and in their privacy policy: https://www.mailerlite.com/legal/privacy-policy

The newsletter is sent on the basis of the recipient’s consent in accordance with Art. 6 para. 1 lit. a GDPR.

The analysis of the opening and click rates is based on my legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR. My interest is to create the most suitable offers for my users and to achieve and continuously optimize this by analyzing user behavior.

Google Web Fonts

Google Web Fonts are used in the integration of the newsletter registration from Mailerlite. Mailerlite has undertaken to comply with the GDPR guidelines. You can find more information on this at: https://www.mailerlite.com/gdpr-compliance and in their privacy policy: https://www.mailerlite.com/legal/privacy-policy

YouTube

My website uses YouTube functions. When you visit my site, a connection to the YouTube servers is established. This tells the YouTube server which of my pages you have visited. If you are logged into your YouTube account, you give YouTube the opportunity to associate your user behavior directly with your personal YouTube profile. You can prevent this by logging out of your YouTube account.

I have no knowledge of further processing or the duration of storage.

The operator of the service is Google LLC, D/B/A YouTube, 901 Cherry Ave, San Bruno, CA 94066, USA.

I would like to point out that there is a possibility that data may be transferred to the USA and processed by US authorities. According to the current legal situation, the USA is considered an unsafe third country with an inadequate level of data protection.

There is currently no adequacy decision pursuant to Art. 45 GDPR.

However, Google has undertaken to comply with the standard contractual clauses for the transfer of personal data to third countries in accordance with Directive 2016/679 (Standard Contractual Clauses – SCC).

You can find more information on the standard contractual clauses at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_de and at: https://policies.google.com/privacy/frameworks?hl=de

You can find further information on the handling of user data by YouTube in YouTube’s privacy policy at: https://www.google.de/intl/de/policies/privacy

The legal basis for this data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR.

Facebook

To advertise my products and services as well as to communicate with interested parties or customers, I have a presence on the Facebook platform.

On this social media platform, I am jointly responsible with Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland.

I have defined the joint responsibility in an agreement regarding the respective obligations within the meaning of the GDPR. This agreement, which sets out the reciprocal obligations, is available at the following link:

https://www.facebook.com/legal/terms/page_controller_addendum

The legal basis for the processing of the resulting and subsequently disclosed personal data is Art. 6 para. 1 lit. f GDPR. My legitimate interest lies in the analysis, communication, sales, and promotion of my products and services.

The legal basis may also be your consent per Art. 6 para. 1 lit. a GDPR granted to the platform operator. Per Art. 7 para. 3 GDPR, you may revoke this consent with the platform operator at any time with future effect.

When accessing my online presence on the Facebook platform, Facebook Ireland Ltd. as the operator of the platform in the EU will process your data (e.g. personal information, IP address, etc.).

This data of the user is used for statistical information on the use of my company presence on Facebook. Facebook Ireland Ltd. uses this data for market research and advertising purposes as well as for the creation of user profiles. Based on these profiles, Facebook Ireland Ltd. can provide advertising both within and outside of Facebook based on your interests. If you are logged into Facebook at the time you access this site, Facebook Ireland Ltd. will also link this data to your user account.

If you contact me via Facebook, the personal data your provide at that time will be used to process the request. I will delete this data once I have completely responded to your query, unless there are legal obligations to retain the data, such as for subsequent fulfillment of contracts.

Facebook Ireland Ltd. might also set cookies when processing your data.

If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. Cookies that have already been saved can be deleted at any time. The instructions to do this depend on the browser and system being used. For Flash cookies, the processing cannot be prevented by the settings in your browser, but instead by making the appropriate settings in your Flash player. If you prevent or restrict the installation of cookies, not all of the functions of Facebook may be fully usable.

Details on the processing activities, their suppression, and the deletion of the data processed by Facebook can be found in its privacy policy:

https://www.facebook.com/privacy/explanation

It cannot be excluded that the processing by Facebook Ireland Ltd. will also take place in the United States by Facebook Inc., 1601 Willow Road, Menlo Park, California 94025.

Instagram

To advertise my products and services as well as to communicate with interested parties or customers, I have a presence on the Instagram platform.

On this social media platform, I am jointly responsible with Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland.

The data protection officer of Instagram can be reached via this contact form:

https://www.facebook.com/help/contact/540977946302970

I have defined the joint responsibility in an agreement regarding the respective obligations within the meaning of the GDPR. This agreement, which sets out the reciprocal obligations, is available at the following link:

https://www.facebook.com/legal/terms/page_controller_addendum

The legal basis for the processing of the resulting and subsequently disclosed personal data is Art. 6 para. 1 lit. f GDPR. My legitimate interest lies in the analysis, communication, sales, and promotion of my products and services.

The legal basis may also be your consent per Art. 6 para. 1 lit. a GDPR granted to the platform operator. Per Art. 7 para. 3 GDPR, you may revoke this consent with the platform operator at any time with future effect.

When accessing this online presence on the Instagram platform, Facebook Ireland Ltd. as the operator of the platform in the EU will process your data (e.g. personal information, IP address, etc.).

This data of the user is used for statistical information on the use of my company presence on Instagram. Facebook Ireland Ltd. uses this data for market research and advertising purposes as well as for the creation of user profiles. Based on these profiles, Facebook Ireland Ltd. can provide advertising both within and outside of Instagram based on your interests. If you are logged into Instagram at the time you access this site, Facebook Ireland Ltd. will also link this data to your user account.

If you contact me via Instagram, the personal data your provide at that time will be used to process the request. I will delete this data once I have completely responded to your query, unless there are legal obligations to retain the data, such as for subsequent fulfillment of contracts.

Facebook Ireland Ltd. might also set cookies when processing your data.

If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. Cookies that have already been saved can be deleted at any time. The instructions to do this depend on the browser and system being used. For Flash cookies, the processing cannot be prevented by the settings in your browser, but instead by making the appropriate settings in your Flash player. If you prevent or restrict the installation of cookies, not all of the functions of Instagram may be fully usable.

Details on the processing activities, their suppression, and the deletion of the data processed by Instagram can be found in its privacy policy:

https://privacycenter.instagram.com/policy/

It cannot be excluded that the processing by Facebook Ireland Ltd. will also take place in the United States by Facebook Inc., 1601 Willow Road, Menlo Park, California 94025.

WhatsApp

I also use the services of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, a subsidiary of Meta Platforms Inc (hereinafter “WhatsApp”) for modern communication and to be able to get in touch with my customers and interested parties as quickly as possible

When you send me a request via WhatsApp, you automatically send me your telephone number and the message itself and I process this data with the help of my processor WhatsApp.

I would like to point out that there is a possibility that data may be transferred to the USA and processed by US authorities. According to the current legal situation, the USA is considered an unsafe third country with an inadequate level of data protection.

To find out what data is collected, processed or used when you use the WhatsApp application, please refer to WhatsApp’s privacy policy, which is available at the following address: https://www.whatsapp.com/legal/privacy-policy

There is currently no adequacy decision pursuant to Art. 45 GDPR.

However, WhatsApp has undertaken to comply with the standard contractual clauses for the transfer of personal data to third countries in accordance with Directive 2016/679 (Standard Contractual Clauses – SCC).

You can find more information on the Standard Contractual Clauses at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_de

Please note further information at https://www.whatsapp.com/legal/

The legal basis for the use and provision of Whatsapp is my legitimate interest pursuant to Art. 6 para. 1 lit.f GDPR.

The legal basis for the processing of your request is so-called pre-contractual measures in accordance with Art. 6 para. 1 lit. b. GDPR.

Social media links via graphics

I also integrate the following social media sites into this website. The integration takes place via a linked graphic of the respective site. The use of these graphics stored on my own servers prevents the automatic connection to the servers of these networks for their display. Only by clicking on the corresponding graphic will you be forwarded to the service of the respective social network.

Once you click, that network may record information about you and your visit to this site. It cannot be ruled out that such data will be processed in the United States.

Initially, this data includes such things as your IP address, the date and time of your visit, and the page visited. If you are logged into your user account on that network, however, the network operator might assign the information collected about your visit to this site to your personal account. If you interact by clicking Like, Share, etc., this information can be stored your personal user account and possibly posted on the respective network. To prevent this, you need to log out of your social media account before clicking on the graphic. The various social media networks also offer settings that you can configure accordingly.

The following social networks are integrated into this site by linked graphics:

Facebook

Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, a subsidiary of Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA.

Privacy Policy: https://www.facebook.com/policy.php

Instagram

Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, a subsidiary of Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA.

Privacy Policy: https://privacycenter.instagram.com/policy/

Last updated in March 2024