Privacy Policy

The controller within the meaning of data protection laws, in particular the EU General Data Protection Regulation (GDPR), is

Brucker Getränkezentrum GmbH
Brandstetterstraße 2, 8600 Bruck/Mur
E-Mail: office@exaktvodka.com
Telefon: +43386255588

Your rights as a data subject

You can exercise the following rights at any time using the contact details provided for our data protection officer:

  • Information about your data stored by us and its processing (Art. 15 GDPR),
  • Correction of incorrect personal data (Art. 16 GDPR),
  • Deletion of your data stored by us (Art. 17 GDPR),
  • Restriction of data processing if we are not yet allowed to delete your data due to legal obligations (Art. 18 GDPR),
  • Objection to the processing of your data by us (Art. 21 GDPR) and
    Data portability, provided you have consented to the data processing or have concluded a contract with us (Art. 20 GDPR).
  • If you have given us your consent, you can revoke it at any time with effect for the future.


You can contact the supervisory authority responsible for us at any time with a complaint: https://www.dsb.gv.at/

Cookies

Like many other websites, we also use so-called “cookies”. Cookies are small text files that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit our website.

You can delete individual cookies or the entire cookie inventory. You will also receive information and instructions on how to delete these cookies or block their storage in advance. Depending on your browser provider, you will find the necessary information under the following links:

Storage duration and cookies used:

If you allow us to use cookies through your browser settings or consent, the following cookies may be used on our websites:

Technically necessary cookies

Nature and purpose of the processing:

We use cookies to make our website more user-friendly. Some elements of our website require that the accessing browser can be identified even after a page change.

The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary for the browser to be recognized even after a page change.

We need cookies for the following applications:

Cookie policy
Spam protection


Legal basis and legitimate interest:

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in a user-friendly design of our website.


Recipients:

Recipients of the data may be technical service providers who act as processors for the operation and maintenance of our website.


Provision is mandatory or required:

The provision of the aforementioned personal data is neither required by law nor by contract. However, without this data, the service and functionality of our website cannot be guaranteed. In addition, individual services may not be available or may be restricted.


Objection

Please read the information on your right to object under Art. 21 GDPR below.

Technically not necessary cookies

We also use cookies in order to better tailor the offer on our website to the interests of our visitors or to generally improve it on the basis of statistical evaluations. To find out which providers use cookies, please refer to the information below on the display, tracking, remarketing and web analysis technologies used.


Legal basis:

The legal basis for this processing is your consent, Art. 6 para. 1 lit. a GDPR.

Recipients:
Recipients of the data may be technical service providers who act as processors for the operation and maintenance of our website.

For further recipients, please refer to the information below on the display, tracking, remarketing and web analysis technologies used.

Third country transfer:
Please refer to the lists of the individual display, tracking, remarketing and web analysis providers for more information.

Provision prescribed or required:
Of course, you can also view our website without cookies. Web browsers are regularly set to accept cookies. In general, you can deactivate the use of cookies at any time via your browser settings (see Revocation of consent).

Please note that individual functions of our website may not work if you have deactivated the use of cookies.

Withdrawal of consent:
You can withdraw your consent at any time via our cookie consent tool.

Profiling:
To what extent we analyze the behavior of website visitors with pseudonymized user profiles, please refer to the information below on the display, tracking, remarketing and web analysis technologies used.

Provision of chargeable services

Nature and purpose of the processing:

For the provision of chargeable services, we request additional data, such as payment details, in order to process your order.

Legal basis:
The processing of the data required for the conclusion of the contract is based on Art. 6 para. 1 lit. b GDPR.

Recipients:
Recipients of the data may be processors.

Storage period:
We store this data in our systems until the statutory retention periods have expired. These are generally 6 or 10 years for reasons of proper accounting and tax law requirements.

Provision mandatory or required:
The provision of your personal data is voluntary. Without the provision of your personal data, we cannot grant you access to the content and services we offer.

Contact form

Nature and purpose of the processing:

The data you enter will be stored for the purpose of individual communication with you. This requires you to provide a valid e-mail address and your name. This is used to assign the request and subsequently answer it. The provision of further data is optional.

Legal basis:
The data entered in the contact form is processed on the basis of a legitimate interest (Art. 6 para. 1 lit. f GDPR).

By providing the contact form, we would like to make it easy for you to contact us. The information you provide will be stored for the purpose of processing your request and for possible follow-up questions.

If you contact us to request a quote, the data entered in the contact form will be processed to carry out pre-contractual measures (Art. 6 para. 1 lit. b GDPR).

Recipients:
Recipients of the data may be processors.

Storage period:
data will be deleted no later than 6 months after the request has been processed.

If there is a contractual relationship, we are subject to the statutory retention periods according to the German Commercial Code (HGB) and delete your data after these periods have expired.

Provision mandatory or required:
The provision of your personal data is voluntary. However, we can only process your request if you provide us with your name, e-mail address and the reason for the request.

Borlabs Cookie

This website uses Borlabs Cookie, which sets a technically necessary cookie (borlabs-cookie) to store your cookie consent.

Borlabs Cookie does not process any personal data.

The borlabs cookie stores the consent you gave when you entered the website. If you wish to revoke this consent, simply delete the cookie in your browser. When you re-enter/reload the website, you will be asked for your cookie consent again.

Use of WPML

We use the plugin WPML (WordPress Multilingual Plugin) to be able to offer our website in several languages. The provider is OnTheGoSystems Limited, 22/F 3 Lockhart Road, Wanchai, Hong Kong.

WPML sets a cookie (e.g. _icl_current_language) to save your selected language for the duration of your visit. This cookie does not contain any personal data and is only stored locally in your browser. No data is transmitted to the provider.

The processing is based on our legitimate interest in making our content accessible in multiple languages (Art. 6 para. 1 lit. f GDPR).

Further information can be found in the WPML privacy policy.

Use of WooCommerce

To operate our online store, we use the open source store system WooCommerce, which is integrated as a plugin into the WordPress content management system. WooCommerce runs on our own server and is operated by us. All store functions are handled via WooCommerce: Product presentation, shopping cart, order process, customer account and the management of orders and customer data.

1. order processing

When you place an order in our online store, the necessary personal data is collected and processed. The processing is necessary for the execution of the purchase contract with you.

Data collected: First name, surname or company name, billing address, optional delivery address, e-mail address, telephone number and the selected payment data (will be forwarded directly to the payment service provider, see section “Payment service provider”).

Purpose of processing: Identification of the customer, processing and fulfillment of the order, correspondence, invoicing and assertion of or defense against liability claims.

Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of a contract)

Storage period: The order data will be stored until the expiry of the statutory retention obligations. Due to tax and company law regulations (in particular UGB and BAO), this period is generally 7 years.

2. customer account

You have the option of creating a personal customer account on our website. Registration is voluntary and not mandatory for placing an order. A customer account makes future orders easier, as your address and order details are saved.

Data collected during registration: e-mail address (mandatory field), password (stored in encrypted form), first and last name, billing address and optionally a different delivery address. Companies can also enter their VAT number.

Purpose of processing: Provision of a personal user account, simplification of future ordering processes, access to past orders and management of your stored address data.

Legal basis: Art. 6 para. 1 lit. b GDPR (contractual relationship or pre-contractual measures) and Art. 6 para. 1 lit. a GDPR (consent through voluntary registration)

Storage period: Your account data will be stored for as long as the customer account exists. You can have your account deleted at any time. After deletion, data that must continue to be stored due to statutory retention obligations (e.g. invoice data) will be stored in accordance with the statutory periods.

3. technical data and cookies

WooCommerce sets technically necessary cookies for the functionality of the store (e.g. shopping cart cookie, session cookie). These cookies are absolutely necessary for the operation of the store and cannot be deactivated without impairing the basic functions of the store.

In addition, the following technical data is automatically recorded in server log files: IP address, browser information and the default language setting. This data is used exclusively for technical error analysis and is deleted after 30 days.

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in the secure and stable operation of the online store)

4. data transfer to third countries

WooCommerce runs on our own server operated in the EU. Regular data transfer to Automattic Inc (USA) does not take place as part of normal store operation.

If individual WooCommerce extensions or WordPress services should establish a connection to servers of Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA, Automattic is certified under the EU-US Data Privacy Framework, so that an adequate level of data protection is guaranteed (Art. 45 GDPR).

Privacy policy WooCommerce/Automattic: https://automattic.com/privacy/

Payment service provider

We use external payment service providers to process payments in our online store. The personal data required to process the respective payment (e.g. name, address, email address, payment data) is transmitted to the selected provider. This data is processed on the basis of Art. 6 para. 1 lit. b GDPR (contract fulfillment), as the processing is necessary to process your order and thus to fulfill the purchase contract.

The respective provider is responsible for the security and data protection of the respective payment processing. For more information, please refer to the linked data protection declarations of the providers.

1. paypal

If you choose the PayPal payment method, the data required for payment processing (in particular first and last name, delivery address, e-mail address, telephone number, the amount to be paid and your IP address) will be transmitted to the payment service provider so that you can authorize the payment to PayPal. A PayPal account is required to use PayPal.

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of contract)

Third country transfer: PayPal may transfer data to PayPal Inc. (USA). PayPal is certified under the EU-US Data Privacy Framework, so that an adequate level of data protection is guaranteed (Art. 45 GDPR).

Privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

2. credit card payment

Credit card payments in our store are technically processed via the payment service provider PayPal. The card data required to process the payment (e.g. cardholder, card number, expiration date, verification number) is transmitted directly to PayPal in encrypted form and processed there. We ourselves do not receive or store any complete credit card data.

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of contract)

Privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

3. google pay

If you select the Google Pay payment method, the payment is technically processed via the payment service provider PayPal. Google Pay allows you to make payments via your Android device or your browser without passing on your full card details to the merchant. The actual payment processing is carried out by PayPal.

Provider (payment processing): PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

Provider (wallet service): Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of contract)

Third country transfer: Google Ireland Limited may transfer data to Google LLC (USA). Google is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).

Privacy policy PayPal: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

Google Pay privacy policy: https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=de

4 Apple Pay

If you select the Apple Pay payment method, the payment is technically processed via the payment service provider PayPal. Apple Pay allows you to make payments via your Apple devices (iPhone, iPad, Mac) without passing on your full card details to the merchant. The actual payment processing is carried out by PayPal.

Provider (payment processing): PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

Provider (wallet service): Apple Distribution International Ltd, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland

Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of contract)

Privacy policy PayPal: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

Apple Pay privacy policy: https://www.apple.com/legal/privacy/de-ww/

5. amazon pay

If you select the Amazon Pay payment method, the data required for payment processing (in particular name, delivery address, payment information) will be transmitted to Amazon. Amazon Pay allows you to use the payment and address details stored in your Amazon account without having to enter them again. An Amazon account is required to use Amazon Pay.

Provider: Amazon Payments Europe S.C.A., 38 avenue John F. Kennedy, L-1855 Luxembourg

Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of contract)

Third country transfer: Amazon Payments Europe S.C.A. may transfer data to Amazon.com, Inc (USA). Amazon is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).

Privacy policy: https://pay.amazon.eu/help/201751600

Insofar as the aforementioned payment service providers transfer data to the USA or other third countries, this is done – unless otherwise stated – on the basis of adequacy decisions of the EU Commission pursuant to Art. 45 GDPR (in particular EU-US Data Privacy Framework) or on the basis of standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR.

Use of CleanTalk anti-spam check

We use the “CleanTalk” service, which protects the website from spam. It is used on the basis of our legitimate interests within the meaning of Article 6(1)(f) of the General Data Protection Regulation (GDPR).

For security reasons and to protect against spam, your data is processed in the CleanTalk Cloud Service and stored in log files for a maximum of 45 days. At the end of this period, this data will be completely deleted. CleanTalk may use information about the spam activity of IP or email addresses to provide adequate anti-spam protection to all websites connected to its service.

Further information on the collection and use of data by CleanTalk can be found in the data protection information of CleanTalk Inc: https://cleantalk.org/publicoffer#privacy

Use of Mailpoet

We use the WordPress plugin Mailpoet for our email marketing. The use is based on our legitimate interests within the meaning of Art. 6 para. 1 lit. f) General Data Protection Regulation (GDPR). Once you have given your consent, personal data will be processed for the purpose of sending electronic direct advertising (e.g. sending newsletters) until you withdraw your consent.

To send newsletters, we use the service provider Mailpoet, Aut O’Mattic A8C Ireland Ltd, Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland.

Further information on the collection and use of data can be found in Mailpoet’s privacy policy: https://automattic.com/privacy/?utm_medium=automattic_referred&utm_source=mpcom_footer


Revocation of consent

If the processing of personal data is based on our legitimate interest, you have the right to object to this at any time, particularly in the case of electronic direct marketing. If you exercise your right to object, no personal data will be processed for the purpose of email marketing.

Your data will be discontinued on the basis of this legal basis, unless there are compelling legitimate grounds for processing on our part. The lawfulness of data processing up to the point of objection is not affected by the objection. In the case of consent to electronic advertising, you can also withdraw your consent by clicking on the unsubscribe link. Processing will then cease unless there is another legal basis.

Use of script libraries (Google Webfonts)

In order to display our content correctly and graphically appealing across browsers, we use “Google Web Fonts” from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter “Google”) to display fonts on this website.

You can find more information about Google Web Fonts at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://www.google.com/policies/privacy/.

Use of Google Analytics

If you have given your consent, this website uses Google Analytics, a web analysis service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (hereinafter: “Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. However, due to the activation of IP anonymization on these websites, your IP address will be shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Further information on terms of use and data protection can be found at https://www.google.com/analytics/terms/de.html and at https://policies.google.com/?hl=de.

Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator.

The data sent by us and linked to cookies, user identifiers (e.g. user ID) or advertising IDs are automatically deleted after 14 months. Data that has reached the end of its retention period is automatically deleted once a month.


Withdrawal of consent:

You can prevent tracking by Google Analytics on our website by clicking here:

An opt-out cookie will be installed on your device. This will prevent Google Analytics from collecting data for this website and for this browser in the future as long as the cookie remains installed in your browser.

You can also prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all the functions of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available under the following link: Browser Add On to deactivate Google Analytics.

Embedded YouTube videos

We embed YouTube videos on our website. The operator of the corresponding plugins is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA (hereinafter referred to as “YouTube”). YouTube, LLC is a subsidiary of Google LLC, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA (hereinafter “Google”). When you visit a page with the YouTube plugin, a connection to YouTube servers is established. YouTube is informed which pages you visit. If you are logged into your YouTube account, YouTube can assign your surfing behavior to you personally. You can prevent this by logging out of your YouTube account beforehand.

When a YouTube video is started, the provider uses cookies that collect information about user behavior.

Further information on the purpose and scope of data collection and its processing by YouTube can be found in the provider’s privacy policy, where you will also find further information on your rights in this regard and setting options to protect your privacy (https://policies.google.com/privacy).

Revocation of consent:
The provider does not currently offer the option of a simple opt-out or blocking of data transmission. If you wish to prevent your activities on our website from being tracked, please revoke your consent for the corresponding cookie category or all technically unnecessary cookies and data transmissions in the cookie consent tool. In this case, however, you may not be able to use our website or may only be able to use it to a limited extent.

Use of Google Maps

We use Google Maps on this website. Google Maps is operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter “Google”). This allows us to show you interactive maps directly on the website and enables you to use the map function conveniently.

You can find more information about data processing by Google in the Google privacy policy: https://policies.google.com/privacy. You can also change your personal data protection settings there in the data protection center.

Detailed instructions on managing your own data in connection with Google products can be found here: https://www.dataliberation.org

When you visit the website, Google receives information that you have accessed the corresponding subpage of our website. This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data will be assigned directly to your account.

If you do not wish to be associated with your Google profile, you must log out of Google before activating the button. Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its websites. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right.

Revocation of consent:
The provider does not currently offer the option of a simple opt-out or blocking of data transmission. If you wish to prevent your activities on our website from being tracked, please revoke your consent for the corresponding cookie category or all technically unnecessary cookies and data transmissions in the cookie consent tool. In this case, however, you may not be able to use our website or may only be able to use it to a limited extent.

Use of social media plugins

aronda Social (News-Feed)


We use the aronda Social widget from aronda digital GmbH, St. Peter Hauptstraße 208/1, 8042 Graz, Austria, to display a bundled news feed from several social media channels on our website. This currently includes content from Facebook, Instagram and YouTube in particular.

Functions and content from these third-party providers are integrated via the widget. aronda Social retrieves content and data directly from the platforms Meta Platforms Ireland Limited (for Facebook and Instagram) and Google Ireland Limited (for YouTube) and displays them on our website. To the best of our current knowledge, aronda Social does not set any cookies that directly collect, process or store personal data. However, personal data – such as IP addresses or browser information – may be transferred to aronda digital, Meta or Google under certain circumstances for technical reasons.


If you click on a post or link within the integrated news feed, you will be redirected to the corresponding platform. Meta or Google may process personal data, in particular information about the website from which you accessed the respective platform. We have no influence on the type, scope and purpose of data processing by these third-party providers.


The operation and data processing on the respective platforms are governed by their own privacy policies. In the case of Facebook and Instagram, there may be joint responsibility with Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, in accordance with Art. 26 GDPR.


The integration takes place on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the attractive, uniform presentation of current social media content and in increasing the visibility of and interaction with our online presences.


Further information on data collection and use can be found in the privacy policy of the respective provider:

You can see the full range of functions of the widget at https://www.aronda.at/datenschutzrichtlinie/.

If you do not want Meta or Google to link your visit to our website with your respective user account, we recommend that you log out of your Facebook, Instagram or YouTube account before accessing the links from the widget.

SSL encryption

To protect the security of your data during transmission, we use state-of-the-art encryption methods (e.g. SSL) via HTTPS.

Information about your right to object in accordance with Art. 21 GDPR

Individual right of objection

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (f) of Article 6(1) GDPR (data processing on the basis of a balancing of interests); this also applies to profiling based on this provision within the meaning of Article 4(4) GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.

Recipient of an objection:

Brucker Getränkezentrum GmbH
Brandstetterstraße 2, 8600 Bruck/Mur
E-Mail: office@exaktvodka.com
Phone: +43386255588

Changes to our privacy policy

We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. The new privacy policy will then apply to your next visit.

Questions about the data protection regulations

If you have any questions about data protection, please send us an e-mail or contact the person responsible for data protection in our organization directly:

Brucker Getränkezentrum GmbH
Brandstetterstraße 2, 8600 Bruck/Mur
E-Mail: office@exaktvodka.com
Phone: +43386255588

The privacy policy was created with the help of activeMind AG the experts for external data protection officers (version #2020-09-30).

0