Legal
Privacy Policy
This English version is provided for your convenience. The German version is legally binding.
Controller
The controller for data processing within the meaning of the General Data Protection Regulation (GDPR) is Natascha Schenk (Diamonds in Glass), Copacabana 38/Tür 30, 8401 Kalsdorf bei Graz, Austria, email: office@diamondsinglass.com. For questions about data protection you can reach us at the same address.
Principles
We process personal data only insofar as this is necessary for the provision of our website and services or you have given your consent. We pass on data only where a legal basis exists and require corresponding data processing agreements from all service providers.
Processed data and purposes
Master data (name, address), contract data (orders, order history), account data upon registration, contact data for enquiries, payment data and technical usage data (e.g. IP address, browser type, time of access). The purposes are the processing of orders and customer service, the provision and security of the website, legal obligations and, with consent, newsletters and reach measurement.
Legal bases
Performance of a contract and pre-contractual measures (Art. 6 (1) (b) GDPR), legal obligations such as tax retention periods (point (c)), legitimate interests in security, fraud prevention and improvement of our offering (point (f)) and your consent, for example for newsletters and non-essential cookies (point (a)).
Hosting and delivery (Cloudflare)
The delivery of the website and protective functions are provided via Cloudflare, Inc. In doing so, technical access data such as IP address and request data are processed in order to provide the website securely and stably (Art. 6 (1) (f) GDPR).
Shop, checkout, customer account and payment (Shopify)
Our shop, the ordering process, customer accounts and payment processing are provided via Shopify (Shopify International Limited). Shopify processes order, account and payment data as a processor. Payments are processed via the payment service providers offered in the checkout, which process the payment data under their own responsibility.
Newsletter and email (Klaviyo)
We use Klaviyo (Klaviyo, Inc.) to send our newsletter. Registration takes place via the double opt-in procedure; you can revoke your consent at any time via the unsubscribe link in every email or by sending us a message. We process your email address, the time of registration and open and click data in order to design relevant content (Art. 6 (1) (a) GDPR).
Product reviews (Judge.me)
Customer reviews are collected and displayed via Judge.me. When you submit a review, we process the data you provide (name, rating, text and optionally images) in order to publish the review (Art. 6 (1) (a) and (f) GDPR).
Consultation appointments (Cal.com)
We use Cal.com for booking personal video consultations. The data you provide in the booking form is processed to organise the appointment (Art. 6 (1) (b) GDPR).
Contact
If you contact us via the contact form or by email, we process your details to handle the enquiry and any follow-up questions (Art. 6 (1) (b) and (f) GDPR).
Cookies and consent
We use technically necessary cookies for the operation of the website and, only with your consent, cookies and services for analysis and personalisation. You can adjust or revoke your consent at any time via the cookie settings in the footer.
Reach measurement and marketing
We do not use third-party analytics or advertising services such as Google Analytics, Google Ads or tracking pixels of social networks. The only script requiring consent is Klaviyo's onsite tracking, which we load exclusively after your express consent (Art. 6 (1) (a) GDPR). You can revoke this consent for the future at any time via the cookie settings. Without consent no such processing takes place.
Recipients and transfers to third countries
Some of the service providers mentioned also process data outside the EU, in particular in the USA. Transfers take place on the basis of appropriate safeguards, such as the EU Commission's standard contractual clauses or certification under the EU-US Data Privacy Framework.
Retention period
We store personal data only for as long as is necessary for the stated purposes. Statutory retention periods apply to invoice and contract data (in Austria generally seven years). After that, the data is deleted or anonymised.
Your rights
You have the right to access, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing and to revoke consent given at any time with effect for the future. A message to the address given above is sufficient to exercise these rights.
You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40 bis 42, 1030 Vienna, dsb.gv.at.
Data security and changes
We take technical and organisational measures to protect your data, including encrypted transmission (TLS). This privacy policy will be adapted if changes to our processing require it.