Privacy Policy

Introduction

In this privacy policy, we want to tell you what types of your personal data (we'll call it "data" for short) we process, why we do it, and how much. This policy covers all the ways we handle personal data, whether it's when we provide our services, or specifically on our websites, mobile apps, and other online spots like our social media pages (we'll call all of this our "online offering").

The terms we use aren't gender-specific.

As of: December 21, 2020

Contents

Responsible Party

Overview of Processing

This next section gives you a quick summary of the types of data we process, why we process it, and who it relates to.

What Kind of Data We Process

  • Basic information (like names, addresses).
  • Content data (like what you type into online forms).
  • Contact details (like your email and phone numbers).
  • Meta/communication data (like device info and IP addresses).
  • Usage data (like websites you visit, what content you're interested in, and when you access things).
  • Contract data (like what the contract is about, how long it lasts, and your customer type).
  • Payment data (like bank details, invoices, and your payment history).

Special categories of data

  • Health data (Art. 9 Para. 1 GDPR).

Types of people involved

  • Business and contract partners.
  • Interested parties.
  • Communication partners.
  • Customers.
  • Users (e.g., website visitors, people using our online services).

What we use your data for

  • Providing our online services and making them user-friendly.
  • Conversion tracking (measuring how effective our marketing efforts are).
  • Office and organizational processes.
  • Direct marketing (e.g., by email or post).
  • Contact requests and communication.
  • Profiling (creating user profiles).
  • Remarketing.
  • Reach measurement (e.g., access statistics, recognizing returning visitors).
  • Security measures.
  • Tracking (for example, profiling based on interests or behavior, and using cookies).
  • Providing our services as agreed in contracts and offering customer support.
  • Handling and answering your questions.

Applicable Legal Bases

Below, we'll explain the legal grounds from the General Data Protection Regulation (GDPR) that we use to process your personal data. Please remember that in addition to the GDPR rules, national data protection laws in your or our country of residence might also apply. If there are more specific legal bases for certain situations, we'll mention them in the privacy policy.

  • Consent (Art. 6 Para. 1 S. 1 lit. a. GDPR) – This is when the person concerned has given their permission for us to process their personal data for one or more specific purposes.
  • Fulfilling contracts and pre-contractual requests (Art. 6 Para. 1 S. 1 lit. b. GDPR) – We process data when it's necessary to fulfill a contract with the person concerned, or to take steps they've requested before we enter into a contract.
  • Legal Obligation (Art. 6 Para. 1 S. 1 lit. c. GDPR) – We process data when it's necessary to comply with a legal obligation that applies to us.
  • Legitimate Interests (Art. 6 Para. 1 S. 1 lit. f. GDPR) – We process data when it's necessary for our legitimate interests or those of a third party, unless these interests are outweighed by the fundamental rights and freedoms of the person concerned, especially when their personal data needs protection.

National Data Protection Regulations in Austria: On top of the GDPR, Austria has its own national data protection rules. This mainly includes the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act – DSG). This Act has special rules about things like your right to access, correct, or delete your data, how special categories of personal data are handled, processing for other purposes, data transfers, and automated decision-making in specific cases.

Security Measures

We take appropriate technical and organizational steps, as required by law, to ensure a level of protection that matches the risk. We consider the latest technology, implementation costs, and the nature, scope, context, and purposes of our data processing, as well as the varying likelihood and severity of threats to people's rights and freedoms.

These measures specifically include keeping your data confidential, intact, and available by controlling both physical and electronic access to it, as well as how it's accessed, entered, shared, kept available, and separated. We've also set up procedures to make sure you can exercise your data rights, that data can be deleted, and that we can respond to any data threats. What's more, we consider personal data protection right from the start when we're developing or choosing hardware, software, and processes, following the principle of privacy by design and using privacy-friendly default settings.

IP Address Shortening: If we can, or if we don't need to store your IP address, we'll shorten it or have it shortened for you. When we shorten an IP address, also known as 'IP masking,' we delete the last part (the last two numbers). (Just so you know, an IP address is a unique ID given to your internet connection by your online provider.) The main reason for shortening it is to make it much harder, or even impossible, to identify someone using their IP address.

SSL Encryption (https): To keep your data safe when you send it through our online service, we use SSL encryption. You'll know a connection is encrypted if you see 'https://' in your browser's address bar.

How We Use Cookies

Cookies are small text files that websites or domains store on your computer through your browser. Their main job is to remember information about you during or after your visit to an online service. This could be things like your language settings on a website, your login status, items in your shopping cart, or where you stopped watching a video. When we talk about cookies, we also include other technologies that do the same job (for example, when user information is saved using anonymous online identifiers, also called 'user IDs').

Here are the different types of cookies and what they do:

  • Temporary Cookies (also known as session cookies): These cookies are deleted as soon as you leave a website and close your browser.
  • Permanent Cookies: Permanent cookies stick around even after you close your browser. This means things like your login status can be saved, or your favorite content can show up right away when you visit a website again. These cookies can also store your interests, which helps with things like audience measurement or marketing.
  • First-Party Cookies: These are the cookies we set ourselves.
  • Third-Party Cookies: These cookies are mainly used by advertisers (other companies) to process user information.
  • Necessary (also known as essential or strictly required) Cookies: Some cookies are absolutely essential for a website to work properly (for example, to remember your logins or other things you've entered, or for security reasons).
  • Statistics, Marketing, and Personalization Cookies: We also typically use cookies for audience measurement and to save a user's interests or behavior (like what content they view or features they use) on different web pages to create a user profile. These profiles help us show users content that might interest them. This whole process is called 'tracking,' which means keeping an eye on users' potential interests. If we use cookies or tracking technologies, we'll let you know separately in our privacy policy or when we ask for your consent.

Notes on Legal Bases: The legal reason we process your personal data using cookies depends on whether we ask for your permission. If we do, and you agree to use cookies, then your consent is the legal basis for processing your data. Otherwise, the data processed with cookies will be handled based on our legitimate interests (like running and improving our online service efficiently) or if using cookies is necessary to meet our contractual obligations.

Storage Duration: Unless we tell you exactly how long permanent cookies will be stored (for example, during a cookie opt-in), please assume they might stick around for up to two years.

General Information on Revocation and Objection (Opt-Out): Depending on whether we process your data based on your consent or legal permission, you can always withdraw your consent or object to your data being processed by cookie technologies (we call this 'opting out'). You can start by doing this through your browser settings, for example, by turning off cookies (though this might limit how well our online service works). If you want to object to cookies being used for online marketing, especially for tracking, you can also do so through various services on websites like https://optout.aboutads.info and https://www.youronlinechoices.com/. You might also find more opt-out info in the details about the service providers and cookies we use.

Processing of Cookie Data Based on Consent: We use a system to manage cookie consent. This system helps us get your permission for using cookies (and the processing and providers mentioned in the system), and it also lets you manage and withdraw your consent. We save your consent declaration so we don't have to ask you again and can prove we got your permission, as required by law. This consent can be stored on our server and/or in a cookie (called an opt-in cookie, or similar tech) so we can link it to you or your device. Unless specific details are given by cookie management service providers, here's what you should know: Your consent might be stored for up to two years. During this time, a pseudonymous user ID is created and saved along with when you gave consent, details about what you consented to (like which categories of cookies and/or service providers), and information about your browser, system, and device.

  • Types of data processed: Usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • People affected: Users (e.g., website visitors, users of online services).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Services and service providers used:

  • BorlabsCookie: Cookie consent management; Service provider: Borlabs; Website: https://de.borlabs.io/borlabs-cookie/; An individual user ID, language, types of consent, and the time they were given are stored on the server side and in the cookie on the user's device.

Commercial and Business Services

We handle data from our contract and business partners, like customers and potential clients (we'll call them 'contract partners' for short), for contractual and similar legal matters, related activities, and when we communicate with them (even before a contract), for example, to answer their questions.

We process this data to meet our contractual duties, protect our rights, handle related administrative tasks, and for our business operations. We only share contract partners' data with third parties when allowed by law, if it's needed for the reasons mentioned above, to meet legal requirements, or if the individuals involved give their consent (for example, with telecommunications, transport, and other support services, subcontractors, banks, tax and legal advisors, payment service providers, or tax authorities). We'll let contract partners know about any other ways we process their data, like for marketing, within this privacy policy.

We'll let our contract partners know what data is needed for the purposes mentioned above either before or during data collection. This might be in online forms, through special markings (like colors) or symbols (like asterisks), or by telling them in person.

We delete data once legal warranty and similar obligations expire, which is usually after 4 years. However, if the data is stored in a customer account, we might keep it longer if required for legal archiving reasons (like for tax purposes, which is typically 10 years). Any data shared with us by a contract partner for an order will be deleted according to that order's terms, generally after the order is finished.

When we use third-party providers or platforms for our services, the terms and conditions and privacy policies of those providers or platforms apply to the relationship between users and the providers.

Shop and E-commerce: We process our customers' data to help them choose, buy, or order products, goods, and related services, and to handle payment and delivery. If an order requires it, we use service providers like postal, freight, and shipping companies to deliver or fulfill it for our customers. For payments, we work with banks and payment service providers. The necessary details are clearly marked during the order or purchase process and include what's needed for delivery, provision, billing, and contact information for any follow-up.

Restaurant Services: We process information from our visitors and prospective clients (we'll just call them 'visitors') to provide ordered food and drinks, and to deliver and bill for other services and provisions.

When we're working for you, we might need to process special categories of data under Art. 9 para. 1 GDPR, especially health information. We do this to protect our visitors' health (for example, if they tell us about allergies), and otherwise, only with their consent.

We might share or send customer data to service providers involved in our services, authorities, billing centers, and for IT, office, or similar services. This happens if it's necessary to fulfill a contract, legally required, if customers have given their consent, or if it's based on our legitimate interests.

  • Types of data processed: Inventory data (e.g., names, addresses), payment data (e.g., bank details, invoices, payment history), contact data (e.g., email, phone numbers), contract data (e.g., contract subject, term, customer category), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • Special categories of personal data: Health data (Art. 9 para. 1 GDPR).
  • People affected: Prospective clients, business and contract partners, customers.
  • Purposes of processing: Providing contractual services and customer service, handling contact inquiries and communication, office and organizational procedures, managing and responding to inquiries, security measures.
  • Legal bases: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), Legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Providing Our Online Offering and Web Hosting

To make sure our online services are safe and run smoothly, we use one or more web hosting providers. Our online content is accessed from their servers (or servers they manage). For this, we might use their infrastructure and platform services, computing power, storage and database services, as well as security and technical maintenance.

When we provide hosting, the data we process can include all user information from our online services that comes up during use and communication. This typically includes your IP address, which is needed to deliver online content to browsers, and anything you type into our online services or on websites.

Email Sending and Hosting: Our web hosting services also cover sending, receiving, and storing emails. For this, we process recipient and sender addresses, other email-related info (like involved providers), and the content of the emails themselves. This data might also be used to detect spam. Please remember that emails on the internet are generally not sent encrypted. While emails are usually encrypted during transit, they aren't encrypted on the sending and receiving servers (unless end-to-end encryption is used). So, we can't take responsibility for the email transmission path between the sender and our server.

Collection of Access Data and Log Files: We (or our web hosting provider) collect data every time someone accesses the server, which we call server log files. These log files can include the address and name of the websites and files accessed, the date and time, the amount of data transferred, a message about successful access, browser type and version, the user's operating system, the referrer URL (the page visited before), and usually IP addresses and the requesting provider.

Server log files can be used for security, like preventing server overload (especially from malicious attacks, known as DDoS attacks), and also to make sure our servers are running smoothly and are stable.

  • Types of data processed: Content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • People affected: Users (e.g., website visitors, users of online services).
  • Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. GDPR).

Getting in Touch

When you get in touch with us (e.g., via contact form, email, phone, or social media), we process the information you provide, but only as much as needed to answer your inquiries and any requested actions.

We answer contact inquiries related to contractual or pre-contractual relationships to fulfill our contractual obligations or to respond to (pre-)contractual requests. Otherwise, we do it based on our legitimate interest in answering your questions.

  • Types of Data Processed: Inventory data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., entries in online forms).
  • Affected Persons: Communication partners.
  • Purposes of Processing: Contact inquiries and communication.
  • Legal Basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b. GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. GDPR).

Newsletter and Electronic Notifications

We only send out newsletters, emails, and other electronic notifications (which we'll call 'newsletters' from now on) if you've given us your consent or if it's legally allowed. If the content of a newsletter is specifically described when you sign up, that description is what counts for your consent. Otherwise, our newsletters will just have information about our services and us.

To sign up for our newsletters, usually all you need to do is provide your email address. However, we might ask for your name, so we can address you personally in the newsletter, or for other details if they're needed for the newsletter's purpose.

Double Opt-In Process: Signing up for our newsletter generally uses a 'double opt-in' process. This means that after you sign up, you'll get an email asking you to confirm your registration. This confirmation is important so that no one can sign up using someone else's email address. We log all newsletter registrations to prove that the sign-up process meets legal requirements. This includes saving the registration and confirmation times, as well as your IP address. Any changes to your data stored with the mailing service provider are also logged.

Deletion and Restriction of Processing: We might keep unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, just so we can prove that consent was given previously. The processing of this data is limited to the purpose of potentially defending against claims. You can request individual deletion at any time, provided you also confirm that consent was previously given. If we're obliged to permanently respect objections, we reserve the right to store the email address solely for this purpose in a blocklist.

We log the registration process based on our legitimate interests to prove that it ran smoothly. If we use a service provider to send emails, we do this based on our legitimate interests in having an efficient and secure mailing system.

Notes on Legal Basis: We send out newsletters based on the recipient's consent, or if consent isn't needed, based on our legitimate interests in direct marketing, as long as it's legally allowed (for example, for advertising to existing customers). If we use a service provider to send emails, we do this based on our legitimate interests. The registration process is recorded based on our legitimate interests to prove that it was carried out according to the law.

Content: Information about us, our services, promotions, and offers.

Analysis and Performance Measurement: Our newsletters include a 'web beacon,' which is a tiny, pixel-sized file. When you open the newsletter, this file is retrieved from our server, or from the server of our mailing service provider if we use one. During this retrieval, we first collect technical info like details about your browser and system, your IP address, and the time of access.

We use this information to technically improve our newsletter based on technical data, or to understand our target audience and their reading habits by looking at their access locations (which can be determined using IP addresses) or access times. This analysis also checks if newsletters are opened, when they're opened, and which links are clicked. While this information can technically be linked to individual newsletter recipients, neither we nor our mailing service provider (if used) aim to track individual users. Instead, these evaluations help us understand our users' reading habits and tailor our content to them, or send different content based on what our users are interested in.

Unless users give explicit consent, we evaluate our newsletters and measure their performance based on our legitimate interests. This is to ensure we use a user-friendly and secure newsletter system that serves both our business interests and meets user expectations.

Unfortunately, you can't opt out of performance measurement separately. In that case, you'd have to cancel your entire newsletter subscription or object to receiving it.

  • Types of Data Processed: Inventory data (e.g., names, addresses), contact data (e.g., email, phone numbers), meta-/communication data (e.g., device information, IP addresses), usage data (e.g., visited websites, interest in content, access times).
  • Affected Persons: Communication partners.
  • Purposes of Processing: Direct marketing (e.g., via email or postal mail).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
  • Option to Object (Opt-Out): You can unsubscribe from our newsletter at any time, meaning you can withdraw your consent or object to receiving further communications. You'll find a link to unsubscribe at the end of every newsletter, or you can use one of the contact options listed above, preferably email.

Web Analytics, Monitoring, and Optimization

Web analysis (also known as 'reach measurement') helps us evaluate the visitor traffic on our online offerings. It can include things like visitor behavior, interests, or demographic info such as age or gender, all as pseudonymized values. With reach analysis, we can figure out, for example, when our online offerings, their features, or content are used most often or are inviting for reuse. We can also understand which areas need optimizing.

Besides web analysis, we might also use testing methods to, for example, test and optimize different versions of our online offerings or their components.

For these purposes, we might create user profiles and store them in a file (called a 'cookie') or use similar methods for the same goal. This info can include things like content you've viewed, websites you've visited and elements you've used there, and technical details like your browser, computer system, and usage times. If users have agreed to the collection of their location data, this might also be processed, depending on the provider.

We also store users' IP addresses. However, we use an IP masking procedure (which means pseudonymizing by shortening the IP address) to protect users. Generally, for web analysis, A/B testing, and optimization, we don't store clear user data (like email addresses or names), but rather pseudonyms. This means that neither we nor the providers of the software we use know the actual identity of the users, only the information stored in their profiles for the purposes of the respective procedures.

Notes on Legal Basis: If we ask for your permission to use third-party services, then your consent is what allows us to process your data. Otherwise, we process your data based on our legitimate interests (meaning we want to provide efficient, cost-effective, and user-friendly services). Also, don't forget to check out the info on how we use cookies in this privacy policy.

  • People affected: Users (e.g., website visitors, users of online services).
  • Why We Process Data: Measuring reach (like website traffic stats and recognizing returning visitors), tracking (for example, creating profiles based on your interests/behavior, and using cookies), measuring conversions (checking how effective our marketing efforts are), and profiling (creating user profiles).
  • Security Measures: IP masking (making your IP address anonymous).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Services and service providers used:

  • Matomo (without cookies): Matomo is a privacy-friendly web analytics tool that doesn't use cookies. Instead, it recognizes returning users with something called a "digital fingerprint," which is stored anonymously and changes every 24 hours. This "digital fingerprint" captures how users move around our online services by combining anonymized IP addresses with your browser settings, making it impossible to identify individual users. Service Provider: Web analytics / reach measurement (self-hosted); Website: https://matomo.org/.

Our Presence on Social Networks (Social Media)

We have a presence on social media and we process user data there to chat with active users or share information about us.

Just so you know, your data might be processed outside the European Union. This could mean some risks for you, like it might be harder to enforce your rights.

Also, data on social networks is usually processed for market research and advertising. For instance, they might create user profiles based on your behavior and interests. These profiles can then be used to show you ads, both on and off the networks, that are likely to match your interests. Typically, cookies are stored on your computer for these purposes, holding info about your behavior and interests. Plus, your user profiles might store data regardless of the devices you use (especially if you're a member of those platforms and logged in).

For all the details on how data is processed and how you can opt-out, please check the privacy policies and info provided by the network operators.

If you have questions or want to exercise your data rights, it's usually best to contact the providers directly. Only they have access to your data and can take action or give you info. But if you still need a hand, feel free to reach out to us.

Facebook: We, along with Facebook Ireland Ltd., are responsible for collecting (but not further processing) data from people who visit our Facebook page (our "Fanpage"). This includes info about the content you view or interact with, or actions you take (check out "Things you and others do and provide" in Facebook's Data Policy: https://www.facebook.com/policy), as well as details about the devices you use (like IP addresses, operating system, browser type, language settings, cookie data; see "Device Information" in Facebook's Data Policy: https://www.facebook.com/policy). As explained in Facebook's Data Policy under "How do we use this information?", Facebook also collects and uses info to provide "Page Insights" analytics services to page operators. This helps us understand how people interact with our pages and related content. We've made a special agreement with Facebook ("Information on Page Insights," https://www.facebook.com/legal/terms/page_controller_addendum). This agreement outlines the security measures Facebook must follow and states that Facebook will handle your data subject rights (meaning you can send info or deletion requests directly to Facebook, for example). Your rights (especially regarding information, deletion, objection, and complaining to the relevant supervisory authority) aren't limited by these agreements with Facebook. You can find more details in the "Information on Page Insights" (https://www.facebook.com/legal/terms/information_about_page_insights_data).

  • Types of Data Processed: Master data (like names, addresses), contact info (like email, phone numbers), content data (like what you type into online forms), usage data (like websites you visit, content you're interested in, access times), and meta/communication data (like device info, IP addresses).
  • People affected: Users (e.g., website visitors, users of online services).
  • Why We Process Data: Contact requests and communication, tracking (for example, creating profiles based on your interests/behavior, and using cookies), remarketing, and measuring reach (like website traffic stats and recognizing returning visitors).
  • Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. GDPR).

Services and service providers used:

Plugins, Embedded Functions, and Content

We include functional and content elements in our online services that come from the servers of their respective providers (we'll call them "third-party providers" from now on). These could be things like graphics, videos, social media buttons, or posts (which we'll collectively refer to as "content").

To include this content, third-party providers always need to process your IP address, because they can't send the content to your browser without it. So, your IP address is essential for showing you this content or these features. We try our best to only use content from providers who use your IP address just to deliver the content. Third-party providers might also use "pixel tags" (which are invisible graphics, also known as "web beacons") for statistics or marketing. These "pixel tags" can help them analyze things like visitor traffic on our website pages. The anonymous info can also be stored in cookies on your device. This might include technical details about your browser and operating system, referring websites, visit times, and other info about how you use our online services, and it can also be linked with info from other sources.

Notes on Legal Basis: If we ask for your permission to use third-party services, then your consent is what allows us to process your data. Otherwise, we process your data based on our legitimate interests (meaning we want to provide efficient, cost-effective, and user-friendly services). Also, don't forget to check out the info on how we use cookies in this privacy policy.

  • Types of data processed: Usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • People affected: Users (e.g., website visitors, users of online services).
  • Why We Process Data: Providing our online services and making them user-friendly.

Deleting Your Data

We delete the data we process according to legal requirements as soon as you withdraw your consent or if other permissions expire (for example, if the reason for processing the data is no longer valid, or if it's not needed for that purpose anymore).

If data isn't deleted because it's needed for other legal purposes, we'll limit its processing to just those reasons. This means the data will be blocked and not used for anything else. For example, this applies to data that we have to keep for commercial or tax reasons, or if storing it is necessary to assert, exercise, or defend legal claims, or to protect the rights of another person or company.

You can also find more info on deleting personal data in the specific privacy notices within this policy.

Changes and Updates to the Privacy Policy

Please make sure to regularly check our privacy policy for updates. We'll update the policy whenever changes in our data processing make it necessary. We'll let you know if any changes require you to do something (like give consent) or if a special notification is needed.

If we list addresses and contact info for companies and organizations in this privacy policy, please remember that these might change over time. So, it's a good idea to double-check the details before reaching out.

Your Rights as a Data Subject

Under the GDPR, you have several rights as a data subject, especially those outlined in Articles 15 to 21:

  • Right to object: You have the right to object at any time, for reasons related to your specific situation, to the processing of your personal data that's based on Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on these rules. If your personal data is processed for direct marketing, you can object to this processing at any time. This also covers profiling related to direct marketing.
  • Right to withdraw consent: You can withdraw any consent you've given at any time.
  • Right to Information: You have the right to ask for confirmation on whether your data is being processed, and to get information about this data, as well as more details and a copy of the data, all according to legal requirements.
  • Right to Correction: In line with legal requirements, you have the right to ask for your data to be completed or for any incorrect data about you to be corrected.
  • Right to Erasure and Restriction of Processing: Following legal requirements, you have the right to ask for your data to be deleted immediately, or alternatively, to request a restriction on how your data is processed, also in line with legal requirements.
  • Right to Data Portability: You have the right to get your data that you've provided to us in a structured, common, and machine-readable format, as per legal requirements, or to ask for it to be transferred to another controller.
  • Complaint to a Supervisory Authority: You also have the right, as per legal requirements, to file a complaint with a supervisory authority, especially in the Member State of your usual residence, your workplace, or where the alleged violation happened, if you think that the processing of your personal data goes against the GDPR.

Definitions

Here, you'll get an overview of the terms used in this privacy policy. Many of these terms are taken from the law and are mainly defined in Article 4 of the GDPR. While the legal definitions are binding, the explanations below are mostly for your understanding. The terms are listed alphabetically.

  • IP Masking: "IP masking" is a method where the last octet (that's the last two numbers) of an IP address is deleted. This means the IP address can no longer uniquely identify a person. So, IP masking is a tool for pseudonymizing processing procedures, especially in online marketing.
  • Conversion Measurement: Conversion measurement (sometimes called "visit action evaluation") is a process that helps us figure out how effective our marketing campaigns are. Typically, a cookie is stored on users' devices on the websites where the marketing happens, and then it's retrieved again on the target website. This way, for example, we can see if the ads we placed on other websites were successful.
  • Personal Data: "Personal data" refers to any information about an identified or identifiable natural person (who we'll call the "data subject"). An identifiable natural person is someone who can be identified, directly or indirectly, especially by linking them to an identifier like a name, an ID number, location data, an online identifier (like a cookie), or one or more specific traits that reveal their physical, physiological, genetic, mental, economic, cultural, or social identity.
  • Profiling: "Profiling" refers to any automated processing of personal data that uses this data to analyze, evaluate, or predict certain personal aspects about a natural person. (Depending on the type of profiling, this can include information about age, gender, location and movement data, how they interact with websites and their content, shopping habits, or social interactions with others.) For example, it might predict their interests in certain content or products, their clicking behavior on a website, or their location. Cookies and web beacons are often used for profiling.
  • Reach Measurement: Reach measurement (also known as web analytics) helps us understand the flow of visitors to an online service. It can cover things like visitor behavior or their interest in specific information, like website content. With reach analysis, website owners can, for example, see when visitors come to their site and what content they're interested in. This helps them better adapt the website's content to their visitors' needs. For reach analysis, we often use pseudonymous cookies and web beacons to recognize returning visitors and get more accurate insights into how our online service is being used.
  • Remarketing: "Remarketing" or "retargeting" is when we note, for advertising purposes, which products a user showed interest in on a website. This helps us remind them about those products on other websites, like through ads.
  • Tracking: "Tracking" is when we can follow users' behavior across different online services. Usually, information about their behavior and interests related to the online services they use is stored in cookies or on the servers of tracking technology providers (this is what we call profiling). This information can then be used, for example, to show users ads that are likely to match what they're interested in.
  • Controller: A "controller" is the natural or legal person, public authority, agency, or other body that, alone or with others, decides why and how personal data is processed.
  • Processing: "Processing" means any operation or set of operations performed on personal data, whether or not using automated methods. This term is really broad and covers pretty much any way you handle data, like collecting, evaluating, storing, transmitting, or deleting it.

Dear Guests, from Monday, July 6, 2026, through Saturday, September 5, our kitchen will be open until 10:30 p.m.!

Favicon Gmoakeller 1030 Vienna
Privacy Overview

This website uses cookies to give you the best possible user experience. Cookies are stored in your browser and help us, for example, to recognize you as a returning visitor when you come back to our website later. They also help us understand which pages are most interesting to our visitors. For more details on the information we collect from our website visitors, please check out our Privacy Policy.