Privacy policy

1) Introduction and Contact Details of the Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data refers to all data with which you can be personally identified.

1.2 The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is BSC Webdesign OG, Sankt-Johann-Gasse 1-5/1/17, 1050 Vienna, Austria, Tel.: +436801461414, E-Mail: paul.stellnberger@bscwebdesign.com. The controller for the processing of personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

2) Data Collection when Visiting our Website

2.1 When using our website for purely informational purposes, i.e., if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to our page server (so-called “server log files”). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time of access
  • Amount of data sent in bytes
  • Source/referral from which you accessed the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form)

Processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to subsequently check the server log files if there are concrete indications of unlawful use.

2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string “https://” and the padlock symbol in your browser's address bar.

3) Hosting & Content Delivery Network

3.1 Amazon Web Services

For hosting our website and displaying page content, we use the system of the following provider: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA

All data collected on our website is processed on the provider's servers.
We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties. 

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

3.2 Wix

For hosting our website and displaying page content, we use the system of the following provider: Wix HQ, 6350671, Nemal Tel Aviv St 40, Tel Aviv-Yafo, Israel

Data is also transferred to: Wix Inc., 500 Terry A. Francois Boulevard, San Francisco, California 94158, USA

All data collected on our website is processed on the provider's servers.
We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

When data is transferred to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

3.3 Google Cloud CDN

We use a Content Delivery Network from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

This service enables us to deliver large media files such as graphics, page content, or scripts faster via a network of regionally distributed servers. Processing is carried out to protect our legitimate interest in improving the stability and functionality of our website in accordance with Art. 6 para. 1 lit. f GDPR.

Data may also be transferred to: Google LLC, USA

We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

4) Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies, which are small text files stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called “session cookies”), while others remain on your device for a longer period and enable the storage of page settings (so-called “persistent cookies”). In the latter case, you can find the storage duration in the overview of your web browser's cookie settings.

If personal data is also processed by individual cookies used by us, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of the contract, in accordance with Art. 6 para. 1 lit. a GDPR in the case of granted consent, or in accordance with Art. 6 para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the website visit.

You can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them, or exclude the acceptance of cookies for certain cases or generally.

Please note that if cookies are not accepted, the functionality of our website may be limited.

5) Contact

5.1 Calendly

For providing an online appointment booking function, we use the services of the following provider: Calendly, LLC, BB&T Tower, 271 17th St NW, Atlanta, GA 30363, USA

For the purpose of appointment scheduling, first and last name as well as email address (and, if applicable, phone number, if a phone appointment is desired) are collected in accordance with Art. 6 para. 1 lit. b GDPR and transmitted to the provider and stored there for appointment organization in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in effective customer management and efficient appointment administration.

After the appointment has taken place or after the agreed appointment period has expired, your data will be deleted by the provider.

We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

5.2 When contacting us (e.g., via contact form or email), personal data is collected. Which data is collected when using a contact form is evident from the respective contact form. This data is stored and used exclusively for the purpose of answering your inquiry or for contacting you and the associated technical administration.

The legal basis for processing this data is our legitimate interest in responding to your inquiry in accordance with Art. 6 para. 1 lit. f GDPR. If your contact aims at concluding a contract, an additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted after your inquiry has been finally processed. This is the case when it can be inferred from the circumstances that the matter concerned has been conclusively clarified and provided that no legal retention obligations prevent deletion.

6) Retargeting/Remarketing and Conversion Tracking

Microsoft Advertising Universal Event Tracking

This website uses conversion tracking technology from the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA

For the use of Universal Event Tracking, a tag is placed on every page of our website that interacts with the conversion cookie set by Microsoft. This interaction makes user behavior on our website traceable and sends the collected information to Microsoft. The purpose of this is that certain predefined goals, such as purchases or leads, can be statistically recorded and evaluated to make the alignment and content of our offers more relevant to interests. The tags never serve to personally identify users.

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology will not take place during your visit to the site.

You can revoke your granted consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the “Cookie Consent Tool” provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

7) Page Functionalities

7.1 Google Sign-In

On our website we provide a single sign-on function of the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

In addition to the transmission of data to the above-mentioned provider location, data may also be transmitted to Google LLC, USA

If you have an account with the provider, you can use this account data to create a user account or to register on our website.

When you visit this site, a direct connection can be established between your browser and the provider's servers via this login function, even if you do not have an account with the provider or are not logged into one. The provider then receives the information that you have visited our site. The information collected in this way (possibly including your IP address) is transmitted directly from your browser to a server of the provider and stored there. However, the information is not used to identify you personally and is not passed on to third parties.

These data processing operations are carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in a user-friendly and interactive design of our online presence.

If you click the login button to register with the provider on our website using your account data, the provider will transmit the general and publicly accessible information stored in your account (user ID, name, address, e-mail address, age and gender) to us exclusively on the basis of your express consent in accordance with Art. 6 para. 1 lit. a GDPR.

We store and use the data transmitted by the provider to set up a user account with the necessary data (title, first name, surname, address data, country, e-mail address, date of birth), provided that you have released this data to the provider. Conversely, based on your consent, data (e.g. information about your surfing or purchasing behavior) may be transferred from us to your account with the provider.

The consent given can be revoked at any time with effect for the future.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

Further information on Google's data protection can be found here: https://business.safety.google/intl/de/privacy/

7.2 Google reCAPTCHA

On this website, we use the CAPTCHA service of the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

Data may also be transferred to: Google LLC, USA. For the visual design of the CAPTCHA window, the provider uses "Google Fonts", i.e., fonts loaded from the internet by Google. No further information beyond that already transferred to Google via the reCAPTCHA functionality is processed here.

The service checks whether an entry is made by a natural person or abusively by machine and automated processing, and blocks spam, DDoS attacks, and similar automated malicious access. To ensure that an action is performed by a human and not by an automated bot, the provider collects the IP address of the device used, identification data of the browser and operating system type used, as well as the date and duration of the visit, and transmits this for evaluation to the provider's servers. Cookies, i.e., small text files stored in the browser of the end device, may be used here.

If the processing described above is based on cookies, these will only be set if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your granted consent at any time with effect for the future by deactivating this service in the “Cookie Consent Tool” provided on the website.

If the processing described above is carried out without the use of cookies, the legal basis is our legitimate interest in establishing individual responsibility on the internet and preventing misuse and spam in accordance with Art. 6 para. 1 lit. f GDPR.

We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

Further information on Google's data protection provisions can be found here: https://business.safety.google/intl/de/privacy/

7.3 Google Photos

This website uses the image service “Google Photos” from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: “Google”) for embedding and displaying images.

Google Photos itself does not store or read any information on user devices. Nor does the service perform any independent data analyses.

However, when image files are loaded from the Google network, your IP address is transmitted to Google and may be stored there. A transmission to servers of Google LLC in the USA is also possible.

This processing will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, image files will not be loaded via Google Photos.

You can revoke your granted consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the “Cookie Consent Tool” provided on the website. We have concluded a data processing agreement with Google, obliging Google to protect the data of our website visitors and not to pass it on to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

8) Tools and Miscellaneous

Cookie Consent Tool

This website uses a so-called “Cookie Consent Tool” to obtain effective user consents for cookies requiring consent and cookie-based applications. The “Cookie Consent Tool” is displayed to users as an interactive user interface when they visit the page, allowing them to grant consent for certain cookies and/or cookie-based applications by checking a box. Through the use of this tool, all cookies/services requiring consent are only loaded if the respective user grants the corresponding consents by checking a box. This ensures that such cookies are only set on the user's respective device if consent has been granted.

The tool sets technically necessary cookies to store your cookie preferences. Personal user data is generally not processed here.

If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning, or logging cookie settings, this is done in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in a legally compliant, user-specific, and user-friendly consent management for cookies and thus in a legally compliant design of our website.

A further legal basis for processing is also Art. 6 para. 1 lit. c GDPR. As controllers, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user's consent.

Where necessary, we have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further information on the operator and the setting options of the Cookie Consent Tool can be found directly in the corresponding user interface on our website.

9) Rights of the Data Subject

9.1 The applicable data protection law grants you the following data subject rights (rights of access and intervention) vis-à-vis the controller regarding the processing of your personal data, with reference to the stated legal basis for the respective exercise conditions:

  • Right of access in accordance with Art. 15 GDPR;
  • Right to rectification in accordance with Art. 16 GDPR;
  • Right to erasure in accordance with Art. 17 GDPR;
  • Right to restriction of processing in accordance with Art. 18 GDPR;
  • Right to notification in accordance with Art. 19 GDPR;
  • Right to data portability in accordance with Art. 20 GDPR;
  • Right to withdraw granted consents in accordance with Art. 7 para. 3 GDPR;
  • Right to lodge a complaint in accordance with Art. 77 GDPR.

9.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST WITHIN THE FRAMEWORK OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

10) Duration of Storage of Personal Data

The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing, and – if applicable – additionally by the respective statutory retention period (e.g., commercial and tax law retention periods).

When personal data is processed based on explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the data concerned will be stored until you revoke your consent.

If statutory retention periods exist for data processed within the scope of legal or quasi-legal obligations based on Art. 6 para. 1 lit. b GDPR, these data are routinely deleted after the retention periods expire, provided they are no longer required for contract fulfillment or initiation and/or we no longer have a legitimate interest in further storage.

When processing personal data based on Art. 6 para. 1 lit. f GDPR, these data are stored until you exercise your right to object under Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.

When processing personal data for direct marketing purposes based on Art. 6 para. 1 lit. f GDPR, these data are stored until you exercise your right to object under Art. 21 para. 2 GDPR.

Unless otherwise stated in the other information of this declaration regarding specific processing situations, stored personal data will otherwise be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.