Zuletzt aktualisiert: März 2026
Datenschutz
We take the protection of your personal data very seriously. This privacy policy informs you about how we collect, process, and use your data in accordance with the General Data Protection Regulation (GDPR / DSGVO) and the Austrian Data Protection Act (DSG).
1. Controller
The controller responsible for data processing on this website is:
van Gold GmbH
Rasumofskygasse 10/6, 1030 Wien, Osterreich
Email: info@vangold.at
Phone: +43 1 234 56 78
2. Data Protection Officer
If you have any questions regarding data protection, you can reach our data protection officer at:
Email: datenschutz@vangold.at
3. Types of Data Collected
3.1 Personal Data
When you create an account or place an order, we collect the following personal data:
- Name (first name, last name)
- Email address
- Billing and shipping address
- Phone number (optional)
3.2 Order Data
When you place an order, we additionally process:
- Order details (products, quantities, prices)
- Payment information (bank transfer reference)
- Shipping and delivery information
- Order history
3.3 Usage Data
When you visit our website, our servers automatically collect technical data:
- IP address (anonymized)
- Browser type and version
- Operating system
- Referring URL
- Date and time of access
- Pages visited
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR): Processing of your data is necessary for the fulfillment of our contractual obligations, including processing orders, managing deliveries, and handling payments.
- Legal obligation (Art. 6(1)(c) GDPR): We are required to retain certain data under Austrian commercial and tax law (UGB, BAO), including invoices and transaction records, for up to 7 years.
- Legitimate interests (Art. 6(1)(f) GDPR): We process usage data to ensure the security and functionality of our website, to prevent fraud, and to improve our services.
- Consent (Art. 6(1)(a) GDPR): Where you have given explicit consent, for example for our newsletter or non-essential cookies. You may withdraw consent at any time.
5. Data Retention
We retain your personal data only as long as necessary:
- Account data: retained for the duration of your account and deleted upon request, subject to legal retention obligations.
- Order and invoice data: 7 years (Austrian commercial and tax law, UGB Section 212, BAO Section 132).
- Server logs: 30 days, then automatically deleted.
- Newsletter subscription: until you unsubscribe.
6. Cookies and Tracking
6.1 Essential Cookies
We use strictly necessary cookies to enable core website functionality, such as session management, shopping cart persistence, and security features. These cookies do not require your consent.
6.2 Analytics Cookies
With your consent, we may use analytics tools to understand how visitors interact with our website. This data is collected anonymously and is used solely to improve our services. You can manage your cookie preferences at any time through our cookie settings.
7. Third-Party Services
We share personal data with the following third parties only as necessary:
- Payment processing: Bank transfer data is processed through the SEPA banking system. We do not store your bank account details on our servers.
- Shipping providers: We share your name, delivery address, and phone number with our insured shipping partners for order delivery.
- Hosting: Our website is hosted on servers within the European Union. All data remains within the EU/EEA.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): You may request information about the personal data we hold about you.
- Right to rectification (Art. 16): You may request the correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): You may request the deletion of your data, subject to legal retention requirements.
- Right to restriction (Art. 18): You may request that we restrict the processing of your data under certain conditions.
- Right to data portability (Art. 20): You may request your data in a structured, machine-readable format.
- Right to object (Art. 21): You may object to the processing of your data based on legitimate interests.
To exercise any of these rights, please contact us at datenschutz@vangold.at. We will respond to your request within 30 days.
9. Right to Lodge a Complaint
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Austrian Data Protection Authority:
Osterreichische Datenschutzbehorde (DSB)
Barichgasse 40-42, 1030 Wien
Website: www.dsb.gv.at
Email: dsb@dsb.gv.at