Privacy Policy
& Legal Notice

We would like to inform you below about the processing of your personal data in connection with your visit to our website.

Legal Notice

Privacy Policy

Introduction and Overview

We have prepared this Privacy Policy (Version 08/10/2022-122080263) to explain to you, in accordance with the provisions ofthe General Data Protection Regulation (EU) 2016/679and applicable national laws, which personal data (referred to as “data” for short) we, as the data controller—and the data processors we engage (e.g., service providers)—process, will process in the future, and what legal rights you have. The terms used are gender-neutral.
In short:We provide you with comprehensive information about the data we process about you.

Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, is intended to explain the most important points to you as simply and transparently as possible. Where it promotes transparency, technicalterms areexplained in a reader-friendly manner, links to further information are provided, andgraphicsare used. We use clear and simple language to explain that, in the course of our business activities, we process personal data only when there is a corresponding legal basis for doing so. This certainly isn’t possible if we provide explanations that are as brief, unclear, and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps you’ll discover a piece of information or two that you weren’t aware of before.
If you still have questions, please contact the responsible party listed below or in the legal notice, follow the provided links, and review additional information on third-party websites. You can, of course, also find our contact information in the legal notice.

Scope of Application

This Privacy Policy applies to all personal data processed by us within the company and to all personal data processed by companies we have commissioned (data processors). By “personal data,” we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address, and mailing address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this Privacy Policy includes:

  • All online platforms (websites, online stores) that we operate
  • Social Media Presence and Email Communication
  • Mobile apps for smartphones and other devices

In short:This Privacy Policy applies to all areas within the company where personal data is processed in a structured manner through the channels mentioned. Should we enter into a legal relationship with you outside of these channels, we will inform you separately if necessary.

Legal Basis

In the following Privacy Policy, we provide you with transparent information about the legal principles and regulations—that is, the legal bases under the General Data Protection Regulation—that allow us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, athttps://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.

We process your data only if at least one of the following conditions applies:

  1. Consent(Article 6(1)(a) of the GDPR): You have given us your consent to process data for a specific purpose. An example would be storing the data you entered in a contact form.
  2. Contract(Article 6(1)(b) of the GDPR): We process your data to fulfill a contract or pre-contractual obligations with you. For example, when we enter into a purchase agreement with you, we need certain personal information in advance.
  3. Legal Obligation(Article 6(1)(c) of the GDPR): We process your data when we are subject to a legal obligation. For example, we are legally required to retain invoices for accounting purposes. These typically contain personal data.
  4. Legitimate Interests(Article 6(1)(f) of the GDPR): In cases where legitimate interests exist that do not infringe upon your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website securely and cost-effectively. This processing therefore constitutes a legitimate interest.

Other conditions, such as the collection of data in the public interest, the exercise of official authority, and the protection of vital interests, generally do not apply to us. However, should such a legal basis be applicable, it will be indicated in the appropriate section.

In addition to the EU regulation, national laws also apply:

  • InAustria, this is the Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data (Data Protection Act), orDSG for short.
  • InGermany, theFederal Data Protection Act(BDSG) applies.

If any additional regional or national laws apply, we will provide you with information about them in the following sections.

Contact Information for the Data Controller

If you have any questions regarding data protection or the processing of personal data, please find the contact information for the responsible person or department below:

Gruber Röschitz Wein GmbH
3743 Röschitz

7 Roggendorfer Street

Email:office@gruber-roeschitz.at
Phone: +43 2984 27 65

Retention period

It is our general policy to retain personal data only for as long as is strictly necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer exists. In some cases, we are legally required to retain certain data even after the original purpose has ceased to exist, for example, for accounting purposes.

If you wish to have your data deleted or wish to revoke your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.

We will provide you with information below regarding the specific duration of each data processing activity, provided we have further information on the matter.

Rights Under the General Data Protection Regulation

In accordance with Articles 13 and 14 of the GDPR, we are informing you of the following rights to which you are entitled to ensure that your data is processed in a fair and transparent manner:

  • Under Article 15 of the GDPR, you have the right to know whether we process any of your data. If so, you have the right to receive a copy of the data and to obtain the following information:
    • the purpose for which we process the data;
    • the categories—that is, the types of data—that are processed;
    • who receives this data, and if the data is transferred to third countries, how security can be guaranteed;
    • how long the data is stored;
    • the existence of the right to rectification, erasure, or restriction of processing, and the right to object to processing;
    • that you can file a complaint with a supervisory authority (links to these authorities are provided below);
    • the source of the data, if we did not collect it from you;
    • whether profiling is carried out—that is, whether data is automatically analyzed to create a personal profile of you.
  • Under Article 16 of the GDPR, you have the right to have your data corrected, which means that we must correct any data if you find any errors.
  • Under Article 17 of the GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the erasure of your data.
  • Under Article 18 of the GDPR, you have the right to restrict processing, which means that we may only store the data but may not continue to use it.
  • Under Article 20 of the GDPR, you have the right to data portability, which means that, upon request, we will provide you with your data in a commonly used format.
  • Under Article 21 of the GDPR, you have the right to object, the exercise of which will result in a change to how your data is processed.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then review as soon as possible whether we can legally comply with this objection.
    • If your data is used for direct marketing purposes, you may object to this type of data processing at any time. After that, we may no longer use your data for direct marketing.
    • If data is used for profiling, you may object to this type of data processing at any time. We may no longer use your data for profiling after that.
  • Under certain circumstances, pursuant to Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing (such as profiling).
  • Under Article 77 of the GDPR, you have the right to lodge a complaint. This means that you may file a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.

In short:You have rights—don’t hesitate to contact the responsible party listed above!

If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you may file a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found athttps://www.dsb.gv.at/. In Germany, there is a data protection commissioner for each federal state. For more information, you can contact theFederal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:

Austrian Data Protection Authority

Director: Mag. Dr. Andrea Jelinek
Address: Barichgasse
40-42, 1030 Vienna
Phone: +43
1 52 152-0
Email:
dsb@dsb.gv.at
Website:
https://www.dsb.gv.at/

Cookies

Cookies Summary
👥 Data Subjects: Visitors to the website
🤝 Purpose: Depends on the specific cookie. You can find more details below or from the software provider that sets the cookie.
📓 Data Processed: Depends on the specific cookie used. More details can be found below or from the software provider that sets the cookie.
📅 Retention period: Depends on the specific cookie; may vary from hours to years
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What are cookies?

Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used, so that you can better understand the following privacy policy.

Whenever you browse the Internet, you use a browser. Some well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

One thing is undeniable: Cookies are really useful little helpers. Almost all websites use cookies. More specifically, they are HTTP cookies, since there are other types of cookies for different applications. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically placed in the cookie folder—essentially the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data about you, such as your language or personal page settings. When you visit our site again, your browser sends this “user-specific” information back to our site. Thanks to cookies, our website knows who you are and provides you with the settings you are accustomed to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

The following diagram illustrates a possible interaction between a web browser—such as Chrome—and a web server. In this scenario, the web browser requests a website and receives a cookie from the server, which the browser then reuses the next time it requests a different page.

 

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans, or other “malware.” Cookies also cannot access information on your computer.

Here's an example of what cookie data might look like:

Name:_ga
Value:GA1.2.1326744211.152122080263-9
Purpose:To distinguish between website visitors
Expiration date:After 2 years

A browser should be able to support these minimum sizes:

  • At least 4,096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3,000 cookies in total

What types of cookies are there?

The specific cookies we use depend on the services we utilize and are explained in the following sections of this Privacy Policy. At this point, we would like to briefly discuss the different types of HTTP cookies.

There are four types of cookies:

Essential Cookies
These cookiesare necessary to ensure the website’s basic functionality. For example, these cookies are needed when a user adds a product to the shopping cart, then continues browsing other pages, and proceeds to checkout later. These cookies ensure that the shopping cart is not cleared, even if the user closes their browser window.

Functional Cookies
These cookies collect information about user behavior and whether the user receives any error messages. These cookies are also used to measure the website's loading time and performance across different browsers.

Targeted Cookies
These cookies improve the user experience. For example, they store locations, font sizes, or form data that you have entered.

Advertising Cookies
These cookies are also called targeting cookies. They are used to deliver personalized ads to users. This can be very convenient, but it can also be very annoying.

Usually, when you visit a website for the first time, you'll be asked which of these types of cookies you want to allow. And, of course, this decision is also stored in a cookie.

If you'd like to learn more about cookies and don't mind reading technical documentation, we recommendhttps://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments titled “HTTP State Management Mechanism.”

Purpose of Processing via Cookies

The purpose ultimately depends on the specific cookie. You can find more details below or by contacting the manufacturer of the software that sets the cookie.

What data is processed?

Cookies are small tools that help with many different tasks. Unfortunately, it is not possible to generalize about what data is stored in cookies, but we will inform you about the data that is processed or stored in this Privacy Policy.

Cookie Retention Periods

The storage period depends on the specific cookie and is explained in more detail below. Some cookies are deleted after less than an hour, while others may remain stored on a computer for several years.

You also have control over how long cookies are stored. You can manually delete all cookies at any time through your browser (see also “Right to Object” below). Furthermore, cookies that are based on your consent will be deleted no later than when you revoke your consent, although the lawfulness of their storage up to that point remains unaffected.

Right to Object – How Can I Delete Cookies?

You decide for yourself how and whether you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable, or allow only some cookies. For example, you can block third-party cookies but allow all other cookies.

If you want to see which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find these options in your browser settings:

Chrome: Delete, Enable, and Manage Cookies in Chrome

Safari: Managing Cookies and Website Data with Safari

Firefox: Clear cookies to remove data that websites have stored on your computer

Internet Explorer: Deleting and Managing Cookies

Microsoft Edge: Deleting and Managing Cookies

If you do not want to accept cookies at all, you can configure your browser to notify you whenever a cookie is about to be set. This allows you to decide whether to allow each individual cookie or not. The procedure varies depending on the browser. The best approach is to search for instructions on Google using the search terms “delete cookies Chrome” or “disable cookies Chrome” if you’re using the Chrome browser.

Legal Basis

The so-called “Cookie Directives” have been in effect since 2009. They stipulate that the storage of cookies requires yourconsent(Article 6(1)(a) of the GDPR). However, reactions to these directives still vary widely among EU countries. In Austria, however, this directive was implemented in Section 96(3) of the Telecommunications Act (TKG). In Germany, the Cookie Directive was not transposed into national law. Instead, this directive was largely implemented in Section 15(3) of the Telemedia Act (TMG).

For strictly necessary cookies, even in the absence of consent, there arelegitimate interests(Article 6(1)(f) of the GDPR), which are, in most cases, of an economic nature. We want to provide visitors to the website with a pleasant user experience, and certain cookies are often absolutely necessary to achieve this.

Unless strictly necessary cookies are used, this will only occur with your consent. The legal basis for this is Article 6(1)(a) of the GDPR.

The following sections provide more detailed information about the use of cookies, to the extent that the software used employs cookies.

Communication

Communication Summary
👥 Who This Applies To: Anyone who communicates with us by phone, email, or online form
📓 Data Processed: e.g., phone number, name, email address, form data entered. You can find more details under the respective contact method
🤝 Purpose: Handling communication with customers, business partners, etc.
📅 Retention period: For the duration of the business transaction and as required by law
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)

If you contact us and communicate with us by phone, email, or through the online form, we may process your personal data.

The data is processed for the purpose of handling and addressing your inquiry and the related business transaction. The data is stored for that period of time or as long as required by law.

Affected Individuals

All individuals who contact us through the communication channels we provide are affected by the events mentioned.

Phone

When you call us, the call data is stored in pseudonymized form on the respective device and with the telecommunications provider used. In addition, data such as your name and phone number may subsequently be sent via email and stored for the purpose of responding to your inquiry. The data is deleted as soon as the business transaction is complete and legal requirements permit.

Email

When you communicate with us via email, data may be stored on the respective device (computer, laptop, smartphone, etc.) and on the email server. The data will be deleted as soon as the business matter has been resolved and legal requirements permit.

Online Forms

When you communicate with us via the online form, data is stored on our web server and, if necessary, forwarded to one of our email addresses. The data is deleted as soon as the business transaction is complete and legal requirements permit.

Legal Basis

The processing of data is based on the following legal grounds:

  • Art. 6(1)(a) of the GDPR (Consent): You give us your consent to store your data and to use it for purposes related to the business transaction;
  • Art. 6(1)(b) of the GDPR (Contract): It is necessary for the performance of a contract with you or a processor, such as a telephone service provider, or we need to process the data for pre-contractual activities, such as preparing a quote;
  • Art. 6(1)(f) of the GDPR (Legitimate Interests): We aim to handle customer inquiries and business communications in a professional manner. To do so, certain technical systems—such as email programs, Exchange servers, and mobile network providers—are necessary to ensure efficient communication.
Website Builder Systems: Introduction

Website Builder Systems Privacy Policy Summary
👥 Data Subjects: Visitors to the website
🤝 Purpose: To optimize our services at
📓 Data Processed: Data such as technical usage information (e.g., browser activity, clickstream activity, session heatmaps), as well as contact information, IP address, or your geographic location. More details can be found further down in this Privacy Policy and in the privacy policies of the providers.
📅 Retention period: Depends on the provider
⚖️ Legal basis: Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(a) GDPR (consent)

What are website builders?

We use a website builder for our website. Website builders are a specific type of content management system (CMS). With a website builder, website operators can create a website very easily and without any programming knowledge. In many cases, web hosting providers also offer website builders. When using a website builder, your personal data may be collected, stored, and processed. In this privacy notice, we provide you with general information about data processing by website builders. For more detailed information, please refer to the provider’s privacy policy.

Why do we use website builders for our website?

The biggest advantage of a modular system is its ease of use. We want to provide you with a clear, simple, and well-organized website that we can easily manage and maintain ourselves—without any outside help. Modular systems now offer many helpful features that we can use even without any programming knowledge. This allows us to design our website according to our preferences and ensure that you have an informative and enjoyable experience while visiting our site.

What data is stored by a modular system?

Exactly what data is stored naturally depends on the website builder system used. Each provider processes and collects different types of data from website visitors. However, technical usage information—such as operating system, browser, screen resolution, language and keyboard settings, hosting provider, and the date of your website visit—is typically collected. In addition, tracking data (e.g., browser activity, clickstream activity, session heatmaps, etc.) may also be processed. Furthermore, personal data may be collected and stored. This typically includes contact information such as your email address, phone number (if you provided it), IP address, and geographic location data. You can find details on exactly what data is stored in the provider’s privacy policy.

How long and where is the data stored?

We provide information below regarding the duration of data processing in connection with the website builder system used, to the extent that we have further information on this matter. You can find detailed information on this in the provider’s privacy policy. In general, we process personal data only for as long as is strictly necessary to provide our services and products. The provider may store your data according to its own policies, over which we have no control.

Right to Object

You always have the right to access, correct, and delete your personal data. If you have any questions, you can also contact the administrators of the website builder system used at any time. You can find their contact information either in our Privacy Policy or on the provider’s website.

You can delete, disable, or manage cookies that providers use for their features in your browser. The process varies depending on which browser you use. Please note, however, that this may prevent some features from working as usual.

Legal Basis

We have a legitimate interest in using a website builder system to optimize our online service and present it to you in an efficient and user-friendly manner. The legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we will only use the website builder if you have given your consent.

To the extent that the processing of data is not strictly necessary for the operation of the website, the data will be processed only on the basis of your consent. This applies in particular to tracking activities. The legal basis in this regard is Article 6(1)(a) of the GDPR.

In this Privacy Policy, we have provided you with the most important general information regarding data processing. If you would like more detailed information on this topic, you can find additional details—where available—in the following section or in the provider’s privacy policy.

Social Media Introduction

Social Media Privacy Policy Summary
👥 Data Subjects: Visitors to the website
🤝 Purpose: Presentation and optimization of our services, communication with visitors, prospective customers, etc., advertising for
📓 Data Processed: Data such as phone numbers, email addresses, contact information, user behavior data, information about your device, and your IP address.
You can find more details about this on the respective social media platform.
📅 Retention period: Depends on the social media platforms used
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is social media?

In addition to our website, we are also active on various social media platforms. In this context, user data may be processed so that we can specifically target users who are interested in us through social networks. Furthermore, elements of a social media platform may be embedded directly into our website. This is the case, for example, when you click on a “social button” on our website and are redirected directly to our social media presence. The term “social media” refers to websites and apps that allow registered members to create content, share content publicly or within specific groups, and connect with other members.

Why do we use social media?

For years, social media platforms have been the place where people communicate and connect online. Through our social media presence, we can introduce our products and services to potential customers. The social media elements embedded on our website help you quickly and easily access our social media content.

The data stored and processed through your use of a social media channel is primarily intended to enable web analytics. The goal of these analytics is to develop more precise and personalized marketing and advertising strategies. Depending on your behavior on a social media platform, the analyzed data can be used to draw relevant conclusions about your interests and create so-called user profiles. This also enables the platforms to present you with tailored advertisements. In most cases, cookies are placed in your browser for this purpose to store data about your usage behavior.

We generally assume that we remain the data controller under data protection law, even when we use the services of a social media platform. However, the European Court of Justice has ruled that, in certain cases, the operator of the social media platform may be jointly responsible with us within the meaning of Article 26 of the GDPR. Where this is the case, we will make a separate note of it and operate on the basis of a relevant agreement. The key provisions of the agreement are then set forth below for the platform in question.

Please note that when you use social media platforms or our embedded features, your data may also be processed outside the European Union, as many social media channels—such as Facebook or Twitter—are U.S. companies. As a result, you may no longer be able to exercise or enforce your rights regarding your personal data as easily.

What data is processed?

Exactly which data is stored and processed depends on the specific social media platform provider. However, it usually includes data such as phone numbers, email addresses, information you enter into a contact form, user data—such as which buttons you click, whom you “like” or follow, and when you visited which pages—as well as information about your device and your IP address. Most of this data is stored in cookies. Especially if you have your own profile on the social media platform you’re visiting and are logged in, data can be linked to your profile.

All data collected through a social media platform is also stored on the providers' servers. Consequently, only the providers have access to the data and can provide you with the relevant information or make changes.

If you want to know exactly what data social media providers store and process, and how you can object to that data processing, you should carefully read the company’s privacy policy. If you have questions about data storage and processing or wish to exercise your rights in this regard, we recommend that you contact the provider directly.

Duration of Data Processing

We provide information below regarding the duration of data processing, to the extent that we have further details on this matter. For example, the social media platform Facebook stores data until it is no longer needed for its own purposes. However, customer data that is matched with your own user data is deleted within two days. In general, we process personal data only for as long as is strictly necessary to provide our services and products. If required by law—as is the case with accounting, for example—this retention period may be extended.

Right to Object

You also have the right and the option to withdraw your consent to the use of cookies or third-party providers, such as embedded social media elements, at any time. You can do this either through our cookie management tool or through other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

Since social media tools may use cookies, we also recommend that you review our general privacy policy regarding cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective tools.

Legal Basis

If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for data processing(Art. 6(1)(a) GDPR). In general, if consent has been given, your data is also stored and processed based on our legitimate interest(Art. 6(1)(f) GDPR)in maintaining prompt and effective communication with you or other customers and business partners. However, we only use these tools to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.

You can find information about specific social media platforms—if available—in the following sections.

Instagram Privacy Policy

Instagram Privacy Policy Summary
👥 Data Subjects: Visitors to the website
🤝 Purpose: To optimize our services at
📓 Data Processed: Data such as user behavior data, information about your device, and your IP address.
You can find more details below in the Privacy Policy.
📅 Retention period: until Instagram no longer needs the data for its purposes
⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is Instagram?

We have integrated Instagram features into our website. Instagram is a social media platform operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA. Instagram has been a subsidiary of Meta Platforms Inc. since 2012 and is one of the Facebook products. The integration of Instagram content on our website is called “embedding.” This allows us to display content such as buttons, photos, or videos from Instagram directly on our website. When you visit pages on our website that have an Instagram feature integrated, data is transmitted to Instagram, where it is stored and processed. Instagram uses the same systems and technologies as Facebook. Your data is therefore processed across all Facebook companies.

In the following, we’d like to give you a more detailed look at why Instagram collects data, what types of data it collects, and how you can largely control how that data is processed. Since Instagram is owned by Meta Platforms Inc., we draw our information from both the Instagram Privacy Policy and the Meta Privacy Policy itself.

Instagram is one of the most popular social media networks worldwide. Instagram combines the benefits of a blog with those of audiovisual platforms like YouTube or Vimeo. On “Insta” (as many users colloquially call the platform), you can upload photos and short videos, edit them with various filters, and share them on other social networks. And if you don’t want to be active yourself, you can simply follow other interesting users.

Why do we use Instagram on our website?

Instagram is the social media platform that has really taken off in recent years. And, of course, we’ve responded to this boom as well. We want you to feel as comfortable as possible on our website. That’s why presenting our content in a variety of ways is a given for us. Thanks to the embedded Instagram features, we can enrich our content with helpful, funny, or exciting posts from the world of Instagram. Since Instagram is a subsidiary of Facebook, the data collected can also help us deliver personalized ads on Facebook. This ensures that our ads reach only people who are genuinely interested in our products or services.

Instagram also uses the collected data for measurement and analysis purposes. We receive aggregated statistics, which give us more insight into your preferences and interests. It’s important to note that these reports do not identify you personally.

What data does Instagram store?

When you visit one of our pages that incorporates Instagram features (such as Instagram images or plug-ins), your browser automatically connects to Instagram’s servers. In the process, data is sent to Instagram, where it is stored and processed—regardless of whether you have an Instagram account or not. This includes information about our website, your computer, purchases you’ve made, ads you see, and how you use our services. Additionally, the date and time of your interaction with Instagram are stored. If you have an Instagram account or are logged in, Instagram stores significantly more data about you.

Facebook distinguishes between customer data and event data. We assume that this is also the case with Instagram. Examples of customer data include name, address, phone number, and IP address. This customer data will only be transmitted to Instagram after it has been “hashed.” Hashing refers to the process of converting a data record into a string of characters. This allows contact information to be encrypted. In addition, the “event data” mentioned above is also transmitted. By “event data,” Facebook—and consequently Instagram—means data about your user behavior. Contact information may also be combined with event data. The collected contact information is matched against the data Instagram already has about you.

The collected data is transmitted to Facebook via small text files (cookies), which are usually stored in your browser. The amount of data stored varies depending on the Instagram features you use and whether you have an Instagram account yourself.

We assume that data processing on Instagram works the same way as it does on Facebook. This means that if you have an Instagram account or have visitedwww.instagram.com, Instagram has set at least one cookie. If that is the case, your browser sends information to Instagram via the cookie as soon as you interact with an Instagram feature. This data is deleted or anonymized no later than 90 days after it has been processed. Although we have thoroughly examined Instagram’s data processing practices, we cannot say with complete certainty exactly what data Instagram collects and stores.

Below, we’ll show you the cookies that are set in your browser at a minimum when you click on an Instagram feature (such as a button or an Instagram image). For the purposes of this test, we’re assuming that you don’t have an Instagram account. If you’re logged into Instagram, significantly more cookies will, of course, be set in your browser.

These cookies were used in our test:

Name: csrftoken
Value: “”
Purpose: Thiscookie is most likely set for security reasons to prevent forged requests. However, we were unable to determine the exact purpose.
Expiration date:after one year

Name: mid
Value: “”
Purpose: Instagramsets this cookie to optimize its services and offerings both on and off Instagram. The cookie assigns a unique user ID.
Expiration date:at the end of the session

Name:fbsr_122080263124024
Value: Notspecified
Purpose: Thiscookie stores the login request for users of the Instagram app.
Expiration date:
At the end of the session

Name:rur
Value: ATN
Purpose: Thisis an Instagram cookie that ensures functionality on Instagram.
Expiration date:At the end of the session

Name: urlgen
Wert: “{”194.96.75.33”: 1901}:1iEtYv:Y833k2_UjKvXgYe122080263”
Verwendungszweck: Dieses Cookie dient den Marketingzwecken von Instagram.
Ablaufdatum: nach Ende der Sitzung

Note:We cannot claim that this list is exhaustive. Which cookies are set in each individual case depends on the embedded features and your use of Instagram.

How long and where is the data stored?

Instagram shares the information it receives with other Facebook companies, external partners, and the people you connect with around the world. Data processing is conducted in accordance with Instagram’s privacy policy. For security and other reasons, your data is stored on Facebook servers located around the world. Most of these servers are located in the United States.

How can I delete my data or prevent it from being stored?

Under the General Data Protection Regulation, you have the right to access, transfer, correct, and delete your data. You can manage your data in your Instagram settings. If you want to completely delete your data from Instagram, you must permanently delete your Instagram account.

Here's how to delete your Instagram account:

First, open the Instagram app. On your profile page, scroll down and tap "Help Center." This will take you to the company's website. On the website, click "Manage Your Account" and then "Delete Your Account."

If you permanently delete your account, Instagram will delete posts such as your photos and status updates. Information that other people have shared about you is not part of your account and will therefore not be deleted.

As mentioned above, Instagram primarily stores your data using cookies. You can manage, disable, or delete these cookies in your browser. The process varies slightly depending on your browser. Under the “Cookies” section, you’ll find links to the instructions for the most popular browsers.

You can also generally configure your browser so that you are always notified when a cookie is about to be set. Then you can decide on a case-by-case basis whether you want to allow the cookie or not.

Legal Basis

If you have consented to the processing and storage of your data through embedded social media elements, this consent serves as the legal basis for data processing(Art. 6(1)(a) GDPR). In general, your data is also stored and processed based on our legitimate interest(Art. 6(1)(f) GDPR)in maintaining prompt and effective communication with you or other customers and business partners. However, we only use the embedded social media elements to the extent that you have given your consent. Most social media platforms also set cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie policy of the respective service provider.

Instagram and Facebook process data in the United States, among other places. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.

Facebook uses standard contractual clauses approved by the European Commission (Art. 46, paras. 2 and 3 of the GDPR) as the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, the United States) or for data transfers to those countries. These clauses require Facebook to comply with EU data protection standards when processing relevant data even outside the EU. These clauses are based on an implementing decision by the European Commission. You can find the decision and the clauses here, among other places:https://germany.representation.ec.europa.eu/index_de.

We have tried to provide you with the most important information about how Instagram processes data. Athttps://help.instagram.com/519522125107875
you can learn more about Instagram's privacy policy.

All texts are protected by copyright.

Source: Created using AdSimple'sPrivacy Policy Generator

If you have any questions or concerns, please contact us:

Gruber Röschitz Wein GmbH
Roggendorfer Straße 7
3743 Röschitz
office@gruber-roeschitz.at

Shopping Cart
Your shopping cart is emptyBack to the store