SCHRATTENTHAL CASTLE

Schrattenthal 1
A-2073 Schrattenthal / NÖ

Privacy statement

This data protection declaration clarifies the type, scope and purpose of the processing of personal data (hereinafter referred to as “data”) within our online offering and the associated websites, functions and content as well as external online presences, such as our social media profile (hereinafter referred to collectively as “online offering”). With regard to the terms used, such as “processing” or “person responsible”, we refer to the definitions in Art. 4 of the Data Protection Basic Regulation (DSGVO).

Responsible
DI Andrea Schubert
Schrattenthal Castle
A-2073 Schrattenthal, Lower Austria
Phone +43 (0)699 102 88 072

info@schloss-schrattenthal.at
Imprint: https://www.schloss-schrattenthal.at/impressum Types of data processed

Types of data processed:
– Inventory data (e.g., names, addresses).
– Contact data (e.g., e-mail, telephone numbers).
– Content data (e.g., text input, photographs, videos).
– Usage data (e.g., websites visited, interest in content, access times).
– Meta/communication data (e.g., device information, IP addresses).

Categories of data subjects
Visitors and users of the online offer (hereinafter referred to collectively as “users”).

Purpose of processing
– Provision of the online offer, its functions and contents.
– Answering contact requests and communicating with users.
– Security measures.
– Range measurement/Marketing

Terms used
“personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier (e.g. a cookie) or to one or more specific characteristics which express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, is regarded as identifiable.

“processing” means any operation carried out with or without the aid of automated processes, or set of operations, involving personal data. The term is broad and covers practically every handling of data.

“Pseudonymisation” means the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the provision of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.

“Profiling” means any automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to the work performance, economic situation, health, personal preferences, interests, reliability, conduct, whereabouts or movements of that natural person.

The “controller” is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.

“processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Applicable legal bases
In accordance with Art. 13 DSGVO, we inform you of the legal basis of our data processing. If the legal basis is not mentioned in the data protection declaration, the following applies: The legal basis for obtaining consent is Art. 6 para. 1 lit. a and Art. 7 DSGVO, the legal basis for processing in order to fulfil our services and carry out contractual measures as well as answer inquiries is Art. 6 para. 1 lit. b DSGVO, the legal basis for processing in order to fulfil our legal obligations is Art. 6 para. 1 lit. c DSGVO, and the legal basis for processing in order to safeguard our legitimate interests is Art. 6 para. 1 lit. f DSGVO. Art. 6 para. 1 lit. d DSGVO serves as the legal basis in the event that vital interests of the data subject or another natural person necessitate the processing of personal data.

Security measures
In accordance with Art. 32 of the DSGVO, we shall take into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different agreements between the parties.