Data Protection Regulation
We are pleased about your interest in our online shop. The protection of your personal data is of particular importance to us. We therefore process your data exclusively based on legal regulations (GDPR, Austrian TKG 2003). In this privacy policy, we provide you with very detailed information about all aspects of data processing in connection with our website and how we handle your data.
The following principles apply to the processing of personal data by us:
- Lawfulness, fairness, and transparency;
- Purpose limitation: Data is only used by us for specific, clear, and lawful purposes;
- Data minimization: We do not process more data than is necessary to achieve the purposes required for our contractual relationship;
- Accuracy: We strive to keep your stored data as accurate and up-to-date as possible. If you notice that the data we process about you is incorrect or outdated, please inform us. We will correct it immediately and, if requested, provide brief confirmation;
- Storage limitation: We aim to pseudonymize your stored data in our processing as much as possible and/or delete data when there are no longer any legal or contractual retention obligations (archiving or storage requirements);
- Integrity and confidentiality: We adhere to the organizational and technical security measures required by the GDPR;
- Accountability, both to you and to the competent supervisory authorities (see Appendix, Section 7, at the end of this privacy policy) regarding the use and processing of your personal data.
1. The processing of your data by us is carried out for the following purposes:
1.1 Contact with us
If you contact us via a form on the website or by email, the data you provide will be stored by us for six months for the purpose of processing your inquiry and in case of follow-up questions. We will not share this data without your explicit consent.
1.2 Access data and hosting
You can visit our websites without providing any personal information. Each time a webpage is accessed, the web server automatically saves a so-called server log file, which contains, for example, the name of the requested file, your IP address, date and time of access, amount of data transferred, and the requesting provider (access data) and documents the access.
This access data is evaluated exclusively to ensure trouble-free operation of the site and to improve our services. This serves to protect our legitimate interests, which prevail in the context of a balancing of interests, in the correct presentation of our offer in accordance with Art. 6(1)(f) GDPR. All access data is deleted no later than seven days after the end of your visit to the site.
1.3 Data storage
The data you provide is necessary for the performance of a contract or for carrying out pre-contractual measures. Without this data, we cannot conclude the contract with you. Data will not be transferred to third parties, except for the transfer of credit card data to the processing banks/payment service providers for the purpose of debiting the purchase price, to our transport or shipping companies for the delivery of goods, and, to some extent, to our tax advisor (as a data processor) to fulfill our tax obligations.
We collect personal data when you voluntarily provide it to us in the context of your order or when contacting us (e.g., via contact form or email). Mandatory fields are marked as such because, in these cases, the data is essential for contract processing or for handling your contact request, and you cannot submit the order or contact request without providing it. The data collected can be seen from the respective input forms. We use the data you provide in accordance with Art. 6(1)(b) GDPR for contract processing and handling your inquiries.
If you have given your consent pursuant to Art. 6(1)(a) GDPR by choosing to open a customer account, we will use your data for the purpose of opening the customer account. Opening a customer account is not required for your purchase if you use the offered payment option via PayPal Express.
The deletion of your customer account is possible at any time and can be done either by sending a message to the contact option listed in Section 6 or via a designated function in the customer account. After deletion of your customer account, your data will be restricted for further processing and deleted after the expiry of tax and commercial retention periods, unless you have expressly consented to further use of your data or we reserve the right to use your data beyond this, which is legally permitted and about which we inform you in this statement.
Data stored with us will be deleted if the purchase process is aborted.
In the case of a contract conclusion and complete contract fulfillment, all data from the contractual relationship will initially be stored until the expiry of the tax retention period (7 years).
The data, including name, address, purchased goods, and purchase date, will also be stored until the expiry of product liability (10 years). Data processing is based on the legal provisions of § 96(3) Austrian TKG and Art. 6(1)(a) (consent) and/or (b) (necessary for contract fulfillment) GDPR.
1.4 Data transfer
For contract fulfillment pursuant to Art. 6(1)(b) GDPR, we transfer your data to the shipping company entrusted with the delivery, as far as this is necessary for the delivery of ordered goods. Depending on which payment service provider you select during the order process, we transfer the payment data collected for this purpose to the credit institution entrusted with the payment and, if applicable, to payment service providers commissioned by us or to the selected payment service. In some cases, the selected payment service providers also collect this data themselves if you create an account with them. In this case, you must log in to the payment service provider with your access data during the order process. The privacy policy of the respective payment service provider applies in this regard.
For order and contract processing, we also use an external inventory management system. The data transfer or processing in this regard is based on a data processing agreement.
The same applies to the data transfer to our wholesalers in cases where they handle the shipping for us (drop shipping).
2. Technical-organizational aspects of the use of your data
2.1 Cookies
Our website uses so-called cookies, provided you have given your consent pursuant to Art. 6(1)(a) GDPR. These are small text files that are stored on your device with the help of the browser. They do not cause any harm.
We use cookies to make our offer attractive and to enable the use of certain functions, to display suitable products, or for market research. Some of the cookies we use are deleted after the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies).
If you do not want this, you can set up your browser to inform you about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for specific cases or in general. If cookies are not accepted, the functionality of our website may be restricted.
Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browsers under the following links:
Microsoft Edge™ - https://support.microsoft.com/en-us/help/4027947/microsoft-edge-delete-cookies
Safari™ - https://support.apple.com/en-us/guide/safari/sfri11471/12.0/mac/10.14
Chrome™ - https://support.google.com/chrome/answer/95647?hl=en&hlrm=en
Firefox™ - https://support.mozilla.org/en-US/products/firefox/protect-your-privacy/cookies
Opera™ - https://help.opera.com/en/latest/web-preferences/#cookies
2.2 Use of Google (Universal) Analytics for web analysis
Our website uses functions of the web analysis service Google Analytics, Google Universal Analytics - integrated into the Shopware plugin Google Services. We have concluded a corresponding data processing agreement with the provider.
This web analysis service is provided by Google Ireland Limited, a company registered and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland.
Google (Universal) Analytics uses methods that enable an analysis of your use of the website, such as cookies. The automatically collected information about your use of this website is usually transferred to a Google server in the USA and stored there. By activating IP anonymization on this website, the IP address is shortened or pseudonymized before transmission within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area. This allows only rough localization.
Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The anonymized IP address transmitted by your browser as part of Google Analytics is generally not merged with other Google data. After the purpose has been fulfilled and the use of Google Analytics by us has ended, the data collected in this context will be deleted.
The relationship with the web analysis provider is based on an adequacy decision of the European Commission. To the extent that information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here: https://www.privacyshield.gov/list. Based on an agreement between the USA and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.
Our aim in the sense of the GDPR (legitimate interest) is to improve our offer and our website. Data processing is based on the legal provisions of § 96(3) Austrian TKG and Art. 6(1)(a) (consent) and/or (f) (legitimate interest) GDPR.
You can revoke your consent at any time with effect for the future by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en. This prevents the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google.
3. Newsletter and your right to object
You have the option to subscribe to our newsletter via our website. For this, we need your email address and your declaration that you agree to receive the newsletter. Based on your consent pursuant to Art. 6(1)(a) GDPR, we will then send our newsletter to your email address.
You can cancel the newsletter subscription at any time. Please send your cancellation to the following email address: shop@phoenix-der-lebenskraft.at.
You can also perform an automatic cancellation on the newsletter page.
The revocation of the newsletter subscription does not affect the lawfulness of the processing carried out based on the consent until the revocation.
We will then immediately delete your data in connection with the newsletter distribution, unless you have expressly consented to further use of your data or we reserve the right to use your data beyond this, which is legally permitted and about which we inform you in this statement.
4. Postal advertising and your right to object
In addition, we reserve the right to use your first and last name and your postal address for our own advertising purposes, e.g., to send interesting offers and information about our products by letter post. This serves to protect our legitimate interests, which prevail in the context of a balancing of interests, in addressing our customers with advertising in accordance with Art. 6(1)(f) GDPR.
The advertising mailings may be provided in the context of processing on our behalf by a service provider to whom we would transfer your data for this purpose.
You can object to the storage and use of your data for these purposes at any time by sending a message to the contact option described below.
5. Your general data protection rights
As a data subject, you have the following rights:
- Pursuant to Art. 15 GDPR, the right to request information about your personal data processed by us to the extent specified therein;
- Pursuant to Art. 16 GDPR, the right to request the immediate correction of incorrect or incomplete personal data stored by us;
- Pursuant to Art. 17 GDPR, the right to request the deletion of your personal data stored by us, unless further processing is necessary
- to exercise the right to freedom of expression and information;
- to fulfill a legal obligation;
- for reasons of public interest; or
- for the establishment, exercise, or defense of legal claims;
- Pursuant to Art. 18 GDPR, the right to request the restriction of the processing of your personal data, insofar as
- the accuracy of the data is disputed by you;
- the processing is unlawful, but you refuse its deletion;
- we no longer need the data, but you need it for the establishment, exercise, or defense of legal claims; or
- you have objected to the processing pursuant to Art. 21 GDPR;
- Pursuant to Art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format or to request its transfer to another controller;
- Pursuant to Art. 77 GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace as the delivery address, or alternatively, our company headquarters. As a service, we provide all contact details for Germany and Austria in the appendix at the end of this privacy policy.
5.1 Right to object (or for Austria, synonymously: right to revoke)
Insofar as we process personal data as explained above to protect our legitimate interests, which prevail in the context of a balancing of interests, you can object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you can exercise this right at any time as described above. If the processing is carried out for other purposes, you have a right to object only if there are reasons arising from your particular situation.
After exercising your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims.
This does not apply if the processing is carried out for direct marketing purposes. In that case, we will no longer process your personal data for this purpose.
For questions regarding the collection, processing, or use of your personal data, for information, correction, restriction, or deletion of data, as well as revocation of consents given or objection to a specific use of data, please contact us directly using the contact details below.
You can reach us at the following contact details:
Responsible for data processing is
Ing. Andreas Staudinger
Managing Director
Phoenix der Lebenskraft e.U.
Quellengasse 28
A-2435 Wienerherberg, Austria
Phone: +43 660 3002341
Email: shop@phoenix-der-lebenskraft.at
6. Updating this privacy policy
We reserve the right to adapt this privacy policy as needed to technical developments and legal changes or in connection with the introduction of new services or products. Such an update would be indicated by specifying the new date under "Status" below.
Status: current as of June 1, 2020
7. Appendix: Competent supervisory authorities for Germany and Austria
You have the right to lodge a complaint at any time with the data protection supervisory authority responsible for your usual place of residence or workplace as the delivery address, or alternatively, for our company headquarters. As a service, we provide all contact details for Germany and Austria below.
7.1. For customers with residence/delivery address in Germany:
Germany – entire federal territory:
The Federal Commissioner for Data Protection and Freedom of Information
Address: Husarenstraße 30, D-53117 Bonn
Phone: 0228 997799 - 0
Fax: 0228 997799 - 550
Email: poststelle@bfdi.bund.de
Website: http://www.datenschutz.bund.de
Baden-Württemberg:
The State Commissioner for Data Protection Baden-Württemberg
Address: Postfach 10 29 32, 70025 Stuttgart
Königstraße 10a, 70182 Stuttgart
Phone: 0711 615541 - 0
Fax: 0711 615541 - 15
Email: poststelle@lfd.bwl.de
Website: http://www.baden-wuerttemberg.datenschutz.de
Bayern:
State Office for Data Protection Supervision
Address: Postfach 606, 91511 Ansbach
Promenade 27 (Schloss), 91522 Ansbach
Phone: 0981 53 - 1300
Fax: 0981 53 - 5300
Email: poststelle@lda.bayern.de
Website: http://www.lda.bayern.de
Berlin:
Berlin Commissioner for Data Protection and Freedom of Information
Address: Friedrichstr. 219, 10969 Berlin
Phone: 030 13889 - 0
Fax: 030 215 - 5050
Email: mailbox@datenschutz-berlin.de
Website: http://www.datenschutz-berlin.de
Brandenburg:
The State Commissioner for Data Protection and Access to Files (LDA Bbg)
Address: Stahnsdorfer Damm 77, 14532 Kleinmachnow
Phone: 033203 356 - 0
Fax: 033203 356 - 49
Email: Poststelle@LDA.Brandenburg.de
Website: http://www.lda.brandenburg.de
Bremen:
The State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen
Address: Postfach 10 03 80, 27503 Bremerhaven
Arndtstr. 1, 27570 Bremerhaven
Phone: 0421 361 - 2010
Fax: 0421 361 - 18495
Email: office@datenschutz.bremen.de
Website: http://www.datenschutz-bremen.de
Hamburg:
The Hamburg Commissioner for Data Protection and Freedom of Information
Address: Kurt-Schumacher-Allee 4, 20097 Hamburg
Phone: 040 42854 - 4040
Fax: 040 42854 - 4000
Email: mailbox@datenschutz.hamburg.de
Website: http://www.datenschutz.hamburg.de
Hessen:
The Hessian Data Protection Commissioner
Address: Gustav-Stresemann-Ring 1, 65189 Wiesbaden
Postfach 31 63, 65021 Wiesbaden
Phone: 0611 14080
Fax: 0611 1408 - 900
Email: poststelle@datenschutz.hessen.de
Website: http://www.datenschutz.hessen.de
Mecklenburg-Vorpommern:
The State Commissioner for Data Protection and Freedom of Information Mecklenburg-Vorpommern
Address: Lennéstr. 1, 19053 Schwerin
Phone: 0385 59494 - 0
Fax: 0385 59494 - 58
Email: datenschutz@mvnet.de
Website: http://www.lfd.m-v.de
Niedersachsen:
The State Commissioner for Data Protection Niedersachsen
Address: Prinzenstraße 5, 30159 Hannover
Phone: 0511 120 - 4500
Fax: 0511 120 - 4599
Email: poststelle@lfd.niedersachsen.de
Website: http://www.lfd.niedersachsen.de
Nordrhein-Westfalen:
The State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Address: Kavalleriestraße 2-4, 40213 Düsseldorf
Phone: 0211 38424 - 0
Fax: 0211 38424 - 10
Email: poststelle@ldi.nrw.de
Website: http://www.ldi.nrw.de
Rheinland-Pfalz:
The State Commissioner for Data Protection Rhineland-Palatinate
Address: Hintere Bleiche 34, 55116 Mainz
Postfach 30 40, 55020 Mainz
Phone: 06131 208 - 2449
Fax: 06131 208 - 2497
Email: poststelle@datenschutz.rlp.de
Website: http://www.datenschutz.rlp.de
Saarland:
Independent Data Protection Center Saarland
State Commissioner for Data Protection and Freedom of Information
Address: Fritz-Dobisch-Straße 12, 66111 Saarbrücken
Phone: 0681 94781 - 0
Fax: 0681 94781 - 29
Email: poststelle@datenschutz.saarland.de
Website: http://www.datenschutz.saarland.de
Sachsen:
The Saxon Data Protection Commissioner
Address: Devrientstr. 1, 01067 Dresden
Phone: 0351 493 - 5401
Fax: 0351 493 - 5490
Email: saechsdsb@slt.sachsen.de
Website: http://www.datenschutz.sachsen.de
Sachsen-Anhalt:
State Commissioner for Data Protection Saxony-Anhalt
Address: Postfach 19 47, 39009 Magdeburg
Leiterstraße 9, 39104 Magdeburg
Phone: 0391 81803 - 0
Fax: 0391 81803 - 33
Email: poststelle@lfd.sachsen-anhalt.de
Website: http://www.datenschutz.sachsen-anhalt.de
Schleswig-Holstein:
Independent State Center for Data Protection Schleswig-Holstein
Address: Postfach 71 16, 24171 Kiel
Holstenstraße 98, 24103 Kiel
Phone: 0431 988 - 1200
Fax: 0431 988 - 1223
Email: mail@datenschutzzentrum.de
Website: http://www.datenschutzzentrum.de
Thüringen:
The Thuringian State Commissioner for Data Protection (TLFD)
Address: Postfach 90 04 55, 99107 Erfurt
Häßlerstr. 8, 99096 Erfurt
Phone: 0361 3771 - 900
Fax: 0361 3771 - 904
Email: poststelle@datenschutz.thueringen.de
Website: http://www.thueringen.de/datenschutz
7.2. For customers with residence/delivery address in Austria:
Austrian Data Protection Authority
Address: Barichgasse 40-42, 1030 Vienna
Phone: +43 1 521 52-25 69
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/
Direct download of the complaint form of the Austrian Data Protection Authority at the link:
https://www.dsb.gv.at/documents/22758/844171/Beschwerde_an_die_Datenschutzbeh%C3%B6rde_PJ_%C2%A7_44_45_DSG.pdf/d426ca8e-3c2a-4d46-9a44-c108ea80c037
(All contact details are subject to changes by the respective authority.)
Privacy policy created with the support of the Trusted Shops legal text generator in cooperation with FÖHLISCH Rechtsanwälte.