Privacy Policy
1. Personal Data
Sylvia Wallinger, e.U., collects, processes and uses your personal data only with your consent or on the basis of an engagement for the purposes agreed with you, or where another legal basis exists in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”) or the Austrian Data Protection Act (“DSG”), and in compliance with applicable data protection and civil law provisions.
Only personal data required for the provision and administration of our services, or data that you have voluntarily provided to us, will be collected.
Personal data means any information relating to an identified or identifiable individual, such as name, address, email address, telephone number, date of birth, age, gender, or social security number. This may also include special categories of personal data, such as health data.
2. Access, Rectification and Erasure
As a client, and subject to applicable duties of confidentiality, you have the right at any time to obtain information about your stored personal data, its source and recipients, and the purposes for which it is processed. You also have the right to rectification, data portability, objection, restriction of processing, and the erasure of data that is inaccurate or has been processed unlawfully.
If your personal data changes, we kindly ask you to inform us accordingly.
You have the right to withdraw your consent to the processing of your personal data at any time where processing is based on your consent.
If you believe that our processing of your personal data infringes applicable data protection law or that your data protection rights have otherwise been violated, you have the right to lodge a complaint with the competent supervisory authority. In Austria, the competent authority is the Austrian Data Protection Authority (Datenschutzbehörde).
3. Data Security
Your personal data is protected through appropriate organisational and technical measures. These measures are designed in particular to protect against unauthorised, unlawful or accidental access, processing, loss, use, or manipulation.
Despite our efforts to maintain an appropriately high standard of care and security, it cannot be completely ruled out that information you provide to us via the internet may be accessed or used by third parties.
Please therefore note that we cannot accept liability for the disclosure of information resulting from transmission errors for which we are not responsible and/or from unauthorised access by third parties, such as attacks on email accounts or telephone systems.
4. Use of Data
We will not process the data provided to us for purposes other than those covered by our engagement, your consent, or another legal basis in accordance with the GDPR and the Austrian Data Protection Act.
This does not apply to the use of anonymised data for statistical purposes.
5. Disclosure of Data to Third Parties
Your data will only be disclosed to third parties with your prior consent.
6. Notification of Personal Data Breaches
We endeavour to ensure that personal data breaches are identified at an early stage and, where required, reported without undue delay to you and/or the competent supervisory authority, taking into account the categories of personal data affected.
7. Data Retention
We will not retain personal data for longer than is necessary to fulfil our contractual or statutory obligations and to establish, exercise, or defend against potential legal claims.
8. Cookies
This website uses “cookies” to make our services more user-friendly, effective, and secure.
A cookie is a small text file transmitted by our web server to the browser’s cookie storage on your device. Cookies enable our website to recognise your browser when a connection is established between our web server and your browser.
Cookies may help us determine the frequency with which our website is used and the number of visitors to our website. The content of the cookies we use is limited to an identification number that does not directly identify the user. The primary purpose of a cookie is to recognise visitors to the website.
The following type of cookie is used on this website:
Session Cookies
Session cookies are temporary cookies that remain in your browser’s cookie storage until you leave our website and are automatically deleted at the end of your visit.
9. Server Log Files
For the purposes of optimising this website in terms of system performance, usability, and the provision of useful information about our services, the website provider automatically collects and stores information in server log files that your browser automatically transmits.
This information may include your Internet Protocol address (IP address), browser and language settings, operating system, internet service provider, and the date and time of access.
This data is not combined with other sources of personal data. We reserve the right to review this data retrospectively if we become aware of specific indications of unlawful use.
Hosting and Technical Processing
This website is operated on behalf of the controller named above by Rothirsch Tech. GmbH (brand “Tagfalter”), Austraße 15, 6200 Jenbach, Austria, acting as a data processor. The processing is governed by a data processing agreement pursuant to Article 28 GDPR.
Where Your Data Is Stored
The website and associated email services are operated on dedicated infrastructure located in Tyrol, Austria.
Additional backup copies are stored with Infomaniak Network SA in Geneva, Switzerland. The European Commission has adopted an adequacy decision for Switzerland.
No US-based hyperscale cloud provider is used.
Server Log Data
When you access this website, technical information transmitted by your browser is automatically recorded in server logs. This includes your IP address, the date and time of access, the requested URL, the amount of data transferred, as well as your browser type and operating system.
This processing is carried out for the purposes of secure operation, troubleshooting, and protection against attacks on the basis of our legitimate interests pursuant to Article 6(1)(f) GDPR.
The logs are automatically deleted after a short period of time.
Sub-processors
Specialised service providers are used for certain technical functions:
- Content Delivery Network (CDN): for the efficient delivery of static content such as images and scripts.
- Domain Name System (DNS): to ensure that the domain can be reached via the internet.
The complete and current list of sub-processors forms part of the data processing agreement and is available upon request.
Map Display (OpenStreetMap)
A map provided by OpenStreetMap is embedded on the Contact page. When this page is opened, your browser loads the map directly from servers operated for the OpenStreetMap service and, in doing so, transmits your IP address.
This processing is carried out for the purpose of displaying the practice location on the basis of our legitimate interests pursuant to Article 6(1)(f) GDPR.
The map is loaded exclusively on the Contact page.
Technical and Organisational Measures
Measures implemented to protect personal data include access controls, encrypted data transmission (TLS), regular backups stored in two countries—Austria (Tyrol) and Switzerland—as well as ongoing security monitoring.
This section is provided and centrally maintained by Tagfalter (Rothirsch Tech. GmbH), the operator of the technical infrastructure.