Privacy Policy

Privacy Policy

In this privacy policy we inform you about the processing of your personal data.

If you want to change your privacy settings (grant consent or revoke your previously granted consent), click here to change your settings.

Responsible

Bäckerei – Konditorei – Cafe Gandl, Gesellschaft m.b.H. & Co KG, Im Stöckl 84, 5360 St. Wolfgang im Salzkammergut, AT, gandl@speed.at, +43 (6138) 2294

Hosting

Host Europe GmbH

Our website is hosted by our processor Host Europe, Host Europe GmbH, Hansestrasse 111, 51149 Köln, Germany.

Connection data are processed to provide and to deliver the website. Data are not stored beyond access for the mere purpose of delivery and provision of the website.

The legal basis of processing is the legitimate interest (absolute technical necessity to provide and to deliver the “website” service which you have explicitly requested by visiting the website according to Article 6 (1) (f) GDPR.

Connection data and other personal data are also processed in connection with various other functions or services in order to operate the website. Detailed information is provided in this Data Privacy Statement and in the individual functions or services.

Server Log Files

Connection data are processed to monitor the technical function and to increase the reliability of our webhost. The duration of processing is limited to 7 days.

The legal basis of processing is the legitimate interest (absolute technical necessity of a server log file as fundamental data basis for failure analysis and for security measures in connection with the “website” service which you have explicitly requested by visiting the website) according to Art. 6 (1) (f) GDPR.

Web Fonts

Font Awesome

We process connection data and browser data in cooperation with our processor Fontawesome, Fonticons, Inc., 6 Porter Road, Apartment 3R, Cambridge, MA 02140, USA, in order to provide the fonts which the web browser needs to display the website. This data is processed only for the time needed to select and transfer the fonts.

The legal basis of processing is the legitimate interest (absolute technical necessity to provide and to deliver the “website” service which you have explicitly requested by visiting the website according to Article 6 (1) (f) GDPR.

Any further independent processing of data by Fontawesome is carried out by Fontawesome as sole controller. Detailed information is provided in the Data privacy policy of Fontawesome.

Embeddings

Google Maps

If you have given your consent, we will process your personal data in cooperation with Google Maps, Google LLC, Amphitheatre Parkway, Mountain View, CA 94043, USA, as joint controllers for the purpose of showing interactive maps on our website.

We will enable the service to collect connection data, data of your web browser, and to place an advertising cookie. The placing of advertising cookies allows Google to create an individual user-ID for each user. These personal data can be used for unambiguous identification and are then processed via the advertising network operated by Google.

Any further independent processing of data by Google is carried out by Google as sole controller. Detailed information is provided in the Data privacy policy of Google.

If you do not give your consent, we are simple not able to provide the Google Maps service to you. You can withdraw your consent by changing the settings at Privacy policy.

The legal basis of processing is your consent according to Article 6 (1) (a) GDPR.

The Google group transfers your personal data to the USA. The legal basis for data transfer to the USA is your consent in accordance with Art. 49 Para. 1 a in conjunction with Art. 6 Para. 1 a GDPR. Before you gave your consent, you were informed that the USA does not have a data protection level that complies with EU standards. In particular, US intelligence agencies can access your data without being informed about it and without you being able to take legal action against it. For this reason, the European Court of Justice ruled in a judgment that the previous adequacy decision (Privacy Shield) was invalid.

Web Shop

You can buy products directly via our webshop. If you do so, the data you provide and the data of the products you have selected will be processed by the controller in order to provide you with an offer, for the conclusion of the contract, for the performance of the contract and for the fulfillment of post-contractual obligations prior to the conclusion of the contract based on the pre-contractual relationship initiated by you and, after conclusion of the contract, based on the contract according to Art. 6 (1) (b) GDPR.

If you use an already existing customer account to buy our products or have created a customer account to buy the products, your personal data will be processed until you delete your customer account.

When customers buy our products via a guest checkout, their personal data will be processed until the legal retention periods have expired.

Your data are processed for the purpose of direct marketing in a manner compatible with the purpose of performing the contract in forms not requiring consent, such as addressed advertising materials sent by post, until you object.

You have no legal or contractual obligation to provide personal data. However, the provision of data is necessary for the conclusion of the contract. If you do not provide such data, a contract cannot be concluded.

Shopping carts of non-registered users will be deleted after 14 days, at the latest. User accounts of registered users are active until the account is deleted by the user. Contract data are processed until the limitation period of potential post-contractual obligations has expired.

Payments are processed via:

Service: PayPal
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxenburg

Service: Stripe
Provider: Stripe,Inc. 185 Berry Street, Suite 550, San Francisco, CA 94107, USA

Right to object

You have the right to object to processing if your personal data is processed based on legitimate interests.

We will then cease the processing carried out on this basis, unless there are compelling and legitimate reasons for us to do so.

You have the right to object to the processing of your personal data for the purpose of direct marketing. In this case, we will cease the processing of your personal data for the purpose of direct mail.

The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Withdrawal

You have the right to withdraw your consent at any time by changing the settings at Privacy settings.

If you have given your consent to receipt of advertising by email, you may withdraw your consent by clicking the unsubscribe link. In this case, we will cease the processing operations, unless there is any other legal basis.

The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Right to data subject

You have the right to access to, rectification, erasure and restriction of processing of personal data.

You have also the right to data portability if the processing of your personal data is based on your consent or on a contract concluded with you.

You have also the right to lodge a complaint with the supervisory authority. If you need more information on the supervisory authorities in the European Union, go to here.

Contact with us

If you contact us using the form on the website or by e-mail, the data you provide will be stored by us for a maximum of six months in order to process the request and in the event of follow-up questions. We do not pass on this data without your consent. Please note that emails may be transmitted unencrypted if your mail server does not support encryption. It cannot be ruled out that data may then be misused.