Legal
Privacy Policy
Information about the collection, processing, and use of personal data within the scope of our website and our inquiry forms.
Only the German version of this text is legally binding.
This translation is provided for convenience. Only the German original is legally binding.
Data Controller
Florian SkodicWaltendorfer-Hauptstraße 84/3
8010 Graz
Österreich
Email: florianskodic@skodic.com
Phone: +43 664 2847579
Data Collection and Processing
When using our website, technically necessary data (e.g., IP address, browser type, time of access) is temporarily processed to enable the page view. For inquiry forms, we collect name, company (optional), email address, phone number (optional), product details, and any file attachments to process your request and provide you with an offer.
Legal Basis for Processing
Personal data is processed on the basis of Art. 6 Para. 1 lit. b GDPR (contract fulfillment or pre-contractual measures) and Art. 6 Para. 1 lit. f GDPR (legitimate interest in answering inquiries and operating the website), unless another legal basis is specified. In the case of consent, processing is based on Art. 6 Para. 1 lit. a GDPR.
Purpose of Processing
The data is used exclusively to process your inquiry, create an offer, communicate with you, and, if necessary, for order processing. Data is only passed on to third parties if this is necessary for contract fulfillment or for legal reasons.
Recipients and Disclosure
Recipients of personal data may include internal employees, commissioned processors (e.g., hosting providers, email services), and external partners for order execution (e.g., shipping service providers, partner print shops), provided this is necessary to provide the service. Data is not passed on for advertising purposes.
Storage Period
Personal data is only stored for as long as necessary for the stated purposes or as required by statutory retention obligations. After these periods, the data is deleted or anonymized.
Your Rights
You have the right to information about stored data, its correction, deletion, restriction of processing, and data portability. Furthermore, you can object to processing based on Art. 6 Para. 1 lit. f GDPR at any time. To exercise your rights or if you have questions about data protection, please contact the controller named above.
Right of Complaint
You have the right to lodge a complaint with the responsible Austrian data protection authority: Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at.
Cookies and Consent
We use technically necessary cookies based on our legitimate interest in the secure operation of the website (Art. 6 Para. 1 lit. f GDPR). We use cookies and services for statistics (analytics) and marketing exclusively after your explicit consent (Art. 6 Para. 1 lit. a GDPR, § 165 Para. 3 TKG 2021). Without your consent, no such cookies are set and no data is processed for these purposes.
We store your selection for verification in your browser (local storage and a first-party cookie) along with the time and version of the consent. The storage period is a maximum of six months, after which we will ask again. You can change or revoke your consent at any time without giving reasons via the "Cookie Settings" link in the footer; the legality of processing carried out until revocation remains unaffected.
Services and Processors Used
We use the following service providers with whom – where required – data processing agreements in accordance with Art. 28 GDPR exist:
- Lovable (Hosting and Application Operation) – Operation and provision of this website including application logic. Connection data (IP address, time, requested page, browser) are processed in server logs.
- Cloudflare – Content Delivery Network, DNS, and protection against attacks. Technical connection data is processed for the secure and performant delivery of the site.
- Supabase – Database, authentication, and file storage. Inquiry data, uploaded print files, offer and invoice data, as well as access data for the internal area are stored here (Server location EU).
- Stripe (Stripe Payments Europe Ltd., Ireland) – payment service provider for online payments. This integration is currently disabled: as long as voucher sales and online payment are not activated, no Stripe script or Stripe iFrame is loaded on any page of this website and no data is transmitted to Stripe. Only after express activation would the Stripe payment window be loaded on the "Vouchers" and "Pay Invoice" pages and payment and card data, amount, reference, email address, IP address and technical fraud-prevention data be processed (Art. 6 Para. 1 lit. b and lit. f GDPR). Card data would be entered directly with Stripe; we do not receive it. Stripe privacy policy: stripe.com/at/privacy.
- Server and error logs of the hosting provider – technically necessary for secure and error-free operation: page path, time, browser/device type, and truncated IP address are processed in server logs and error reports. Legal basis: Art. 6 Para. 1 lit. f GDPR. Storage period usually 30 days. This processing cannot be opted out of, as no page view is possible without it.
- Optional reach measurement (Statistics) – the evaluation of page views by our hosting provider's (Lovable) analysis script and by Google Analytics 4 (provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) is purely optional and is only loaded if you agree in the cookie banner under the "Statistics" category (Art. 6 Para. 1 lit. a GDPR, § 165 Para. 3 TKG 2021). Google Analytics uses cookies and processes usage data (e.g. pages visited, dwell time, approximate location, device); your IP address is truncated/anonymized. Transfer to the USA cannot be ruled out; Google is certified under the EU-US Data Privacy Framework. Without consent, the scripts are blocked and no analysis data is transmitted. No marketing cookies are set and no profile-building evaluation across websites is carried out. You can revoke your consent at any time via "Cookie Settings" in the footer.
- Resend – Sending of confirmation, offer, and notification emails via our sender domain. Email address, content, and delivery status are processed.
- Google Workspace / Gmail (Google Ireland Ltd.) – Reception and processing of your email correspondence.
- Fonts – all fonts are delivered locally from our own server. No connection to Google Fonts and no transmission of your IP address to third parties takes place.
- Technical error log of our hosting provider – if a technical error occurs on the website, an error report (error message, page path, browser/device type, time) is logged within the scope of hosting. No additional external monitoring service is used.
- Partner print shops and shipping service providers – to execute the order, we transmit print data as well as delivery and contact data to the respective commissioned production or shipping partner.
Payment Processing
Online payments via this website are currently disabled: value vouchers cannot be purchased and invoices cannot be paid online, and no data is transmitted to a payment service provider. Offers and invoices are settled by bank transfer outside this website; for this we store the reference (offer/invoice number), amount, status, time and billing data. Legal bases are Art. 6 Para. 1 lit. b GDPR (contract fulfilment) and Art. 6 Para. 1 lit. c GDPR (tax retention obligation, § 132 BAO – 7 years). As soon as online payment is expressly activated, we will update this policy accordingly.
Voucher Purchase and Voucher Recipient
When purchasing a voucher, we process your name, email address, the voucher amount, the generated voucher code, status, and remaining value as well as – if provided by you – the name, email address, and personal message of the recipient. We use this data exclusively to deliver the voucher, to be able to redeem it later, and to document the payment (Art. 6 Para. 1 lit. b GDPR). You provide the details of the recipient voluntarily; please inform this person about it.
For the storage period, we distinguish between:
- Redemption data of the voucher (voucher code, issue date, nominal value, remaining value, status): until the end of redeemability of 30 years, as the voucher is valid for this long.
- Tax-relevant transaction data (amount, payment reference, document data): 7 years according to § 132 BAO (Art. 6 Para. 1 lit. c GDPR).
- Email address and personal message of the recipient as well as your contact details: only as long as delivery, verification, and possible claims require this – usually 3 years after delivery or after full redemption.
- Thereafter, these personal details are deleted or anonymized; the voucher record itself remains redeemable without personal reference.
Customer Account and Loyalty Program
You can create a customer account for the loyalty program. Email address, a password chosen by you (stored exclusively as a cryptographic hash), times of registration, email confirmation, and logins, as well as your point balance with the associated bookings (invoice reference, creditable invoice amount excluding shipping and third-party costs, credited and redeemed points, cancellation bookings, and expiration bookings) are processed. Authentication takes place via Supabase. Legal basis is Art. 6 Para. 1 lit. b GDPR (implementation of the loyalty program you requested), for bookings with invoice reference additionally Art. 6 Para. 1 lit. c GDPR (tax retention obligation).
The booking data serves exclusively to manage your point account: crediting points for paid invoices, reversing for cancellations, credits, or refunds, expiration of unredeemed points 36 months after credit, verification of redemptions (points are personal and non-transferable), and processing of a possible discontinuation of the program. Automated decision-making or profiling does not take place, nor is there use for third-party advertising. The full rules can be found here:
Terms and Conditions of the Loyalty Program
You can have your customer account deleted at any time by email; unredeemed points will expire. We delete account data no later than 24 months after the last login, booking data with invoice reference after the expiry of the statutory retention period (7 years, § 132 BAO).
Uploaded Print Files and Deletion Periods
Files uploaded via the inquiry form are stored in a private, non-publicly accessible storage area. Access is restricted to us after login; downloads take place via time-limited links.
- Print files from inquiries without order: deletion no later than 6 months after the last correspondence.
- Print files from placed orders: retention 24 months after delivery (reprint possibility), then deletion.
- Inquiry data (form fields, contact data): deletion 3 years after completion of the correspondence, provided there is no statutory retention obligation.
- Invoices, offers, and payment documents: 7 years according to § 132 BAO.
- Email delivery logs: maximum 12 months.
- Server log files: usually 30 days.
- Cookie consents: maximum 6 months, after which a new inquiry occurs.
Upon request, we will delete your print files early at any time – a short email is sufficient.
Data Security
We use technical and organizational measures to protect your data from loss, misuse, or unauthorized access. Despite all care, absolute security on the Internet cannot be guaranteed.
Data Transfer to Third Countries
Data transfer to third countries outside the European Economic Area (EEA) only takes place if this is necessary for the provision of the service and suitable guarantees according to Art. 44 ff. GDPR are in place (e.g., adequacy decision of the EU Commission or standard contractual clauses).
Questions about the processing of your data or wish to delete your print files? Contact us at any time – we process requests within the statutory deadlines.
Get in touch