This privacy policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) within our online services and the associated websites, functions, and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as “online services”). Regarding the terminology used, such as “processing” or “controller,” we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Who we are
Foodies is a private and independent food community for foodies and gourmets, by foodies. The project is currently in its initial phase and will be further improved and optimized.
Responsible: Ing. Eric Hallwachs 1070 Wien, Österreich
What personal data we collect and why we collect it
Types of data processed:
- Inventory data (e.g., names, usernames, addresses)
- Contact details (e.g., email, phone numbers)
- Content data (e.g., text entries, blog posts, contributions to discussion groups and forums, photographs, images, videos)
- Usage data (e.g., websites visited, interest in content, access times)
- Metadata/communication data (e.g., device information, IP addresses)
Purpose of processing
- Provision of the online service, its functions and content
- Responding to contact requests and communicating with users
- Security measures
- Reach measurement/marketing
Terminology used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data. “Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person. “Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements; “Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; “Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller;
Relevant legal bases
In accordance with Article 13 of the GDPR, we inform you of the legal bases for our data processing. Unless otherwise stated in the privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing data to fulfill our services and implement contractual measures, as well as to respond to inquiries, is Article 6(1)(b) of the GDPR; the legal basis for processing data to comply with our legal obligations is Article 6(1)(c) of the GDPR; and the legal basis for processing data to protect our legitimate interests is Article 6(1)(f) of the GDPR. In the event that processing personal data is necessary to protect the vital interests of the data subject or another natural person, Article 6(1)(d) of the GDPR serves as the legal basis.
Security measures
In accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access to, input of, disclosure of, and ensuring the availability and separation of the data. Furthermore, we have established procedures that guarantee the exercise of data subject rights, the erasure of data, and responses to data breaches. We also consider the protection of personal data during the development and selection of hardware, software, and processes, in accordance with the principles of data protection by design and by default (Article 25 GDPR). SSL/TLS encryption: This website uses SSL encryption for security reasons and to protect the transmission of all web content. You can recognize an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the padlock icon in your browser’s address bar. When SSL encryption is enabled, the data you transmit to us cannot be intercepted by third parties.
Cooperation with processors and third parties
If, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transmit it to them, or otherwise grant them access to the data, this is done only on the basis of a legal permission (e.g., if the transfer of data to third parties is necessary for the performance of a contract pursuant to Art. 6 para. 1 lit. b GDPR), if you have given your consent, if a legal obligation requires it, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.). If we commission third parties to process data on the basis of a so-called “data processing agreement,” this is done on the basis of Art. 28 GDPR.
Comments
When visitors leave comments on the website, we collect the data shown in the comments form, as well as the visitor’s IP address and browser user agent string to help spam detection. An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you are a registered user and upload photos to this website, you should avoid uploading photos with embedded EXIF GPS location data. Visitors to this website could download photos stored here and extract their location information.
Cookies
When you leave a comment on our website, you may opt-in to saving your name, email address, and website in cookies. This is for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year. If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser. When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for one year. If you select “Remember Me,” your login will persist for two weeks. Logging out of your account will remove the login cookies. If you edit or publish an article, an additional cookie will be saved in your browser. This cookie contains no personal data and only references the post ID of the article you just edited. The cookie expires after one day.
Embedded content from other websites
Articles on this website may include embedded content (e.g., videos, images, articles, aggregated content from user blogs, etc.). Embedded content from other websites behaves exactly as if the visitor had visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking services, and monitor your interaction with this embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
How long we store your data
When you post a comment, it, along with its metadata, is stored indefinitely. This allows us to automatically recognize and approve follow-up comments instead of holding them in a moderation queue. For users who register on our website, we also store the personal information they provide in their user profiles. All users can view, edit, or delete their personal information at any time (except for their username, which cannot be changed). Website administrators can also view and edit this information. If you publish your own content (e.g., a recipe) on our website, we store it until you delete the post or the respective uploads (e.g., photos, videos, etc.). Deleted content cannot be recovered. Registered users can delete their posts and uploads themselves.
What rights you have over your data
If you have an account or blog on this website, or if you have left comments, you can request an export of your personal data from us, including all data you have provided. You can also request the deletion of all personal data we hold about you. This does not include data we are required to retain for administrative, legal, or security purposes.
Where we send your data
Visitor comments and activity updates in the “Activity Feed” may be checked by an automated spam detection service, see section “Akismet Anti-Spam Check”.
Hosting
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, security services, and technical maintenance services, which we use for the purpose of operating this online service. In doing so, we, or our hosting provider, process inventory data, contact data, content data, usage data, meta and communication data of users, prospective customers, and visitors to this online service based on our legitimate interests in the efficient and secure provision of this online service pursuant to Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).
Collection of access data and log files
We, or rather our hosting provider, collect data about every access to the server on which this service is located (so-called server log files) based on our legitimate interests within the meaning of Art. 6 para. 1 lit. f GDPR. Access data includes the name of the accessed website, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address, and the requesting provider. Log file information is stored for a maximum of 7 days for security reasons (e.g., to investigate misuse or fraud) and then deleted. Data whose further retention is required for evidentiary purposes is exempt from deletion until the final resolution of the respective incident.
Registration function
Users can optionally create a user account. During registration, users will be informed of the required mandatory information. The data entered during registration will be used for the purpose of using the service. Users may be informed by email about service- or registration-related information, such as changes to the scope of services or technical issues. If users have terminated their user account, their data relating to the user account will be deleted, unless its retention is necessary for commercial or tax law reasons in accordance with Art. 6 Para. 1 lit. c GDPR. It is the users’ responsibility to back up their data before the end of the contract if they have terminated their account. We are entitled to irretrievably delete all user data stored during the period of use of the service. When using our registration and login functions, as well as the user account, we store the IP address and the time of the respective user action. This storage is based on our legitimate interests, as well as the user’s interest in protection against misuse and other unauthorized use. We do not generally share this data with third parties, unless it is necessary for pursuing our claims or we are legally obligated to do so pursuant to Art. 6 para. 1 lit. c GDPR. IP addresses are anonymized or deleted no later than 7 days after collection.
Contact
When you contact us (e.g., via contact form, email, telephone, or social media), the information you provide will be processed in accordance with Article 6(1)(b) GDPR for the purpose of handling your inquiry. Your information may be stored in a customer relationship management system (“CRM system”) or similar inquiry management system. We delete inquiries when they are no longer needed. We review the necessity of retaining inquiries every two years; statutory archiving obligations also apply.
Akismet Anti-Spam Check
Our website uses the “Akismet” service, provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. This service is used based on our legitimate interests pursuant to Art. 6 para. 1 lit. f) GDPR. Akismet helps distinguish comments from real people from spam comments. For this purpose, all comment data is sent to a server in the USA, where it is analyzed and stored for comparison purposes for four days. If a comment is classified as spam, the data is stored beyond this period. This data includes the entered name, email address, IP address, comment content, referrer, information about the browser and operating system used, and the time of entry. Further information on the collection and use of data by Akismet can be found in Automattic’s privacy policy: https://automattic.com/privacy/. Users are welcome to use pseudonyms or refrain from entering their name or email address. You can completely prevent the transmission of data by not using our commenting system. That would be a shame, but unfortunately we see no other equally effective alternatives.
Retrieving profile pictures from Gravatar
We use the Gravatar service provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA, within our online services, and particularly in our blog. Gravatar is a service where users can register and upload profile pictures and their email addresses. When users with the same email address post articles or comments on other online platforms (especially blogs), their profile pictures can be displayed alongside their posts or comments. For this purpose, the email address provided by the user is transmitted to Gravatar in encrypted form to check whether a profile is associated with it. This is the sole purpose of transmitting the email address, and it is not used for any other purpose and is subsequently deleted. The use of Gravatar is based on our legitimate interests within the meaning of Art. 6 Para. 1 lit. f) GDPR, as Gravatar allows us to offer authors of articles and comments the opportunity to personalize their posts with a profile picture. By displaying images, Gravatar learns users’ IP addresses, as this is necessary for communication between a browser and an online service. Further information on the collection and use of data by Gravatar can be found in Automattic’s privacy policy: https://automattic.com/privacy/. If users do not want a profile picture associated with their email address on Gravatar to appear in the comments, they should use an email address that is not registered with Gravatar when commenting. We would also like to point out that it is possible to use an anonymous email address or no email address at all if users do not wish their email address to be transmitted to Gravatar. Users can completely prevent the transmission of data by not using our commenting system.
Google Analytics
Based on our legitimate interests (i.e., our interest in analyzing, optimizing, and operating our online services economically, in accordance with Article 6(1)(f) of the GDPR), we use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies. The information generated by the cookie about users’ use of the online services is generally transmitted to and stored on a Google server in the USA. Google is certified under the Privacy Shield Framework and thus guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). Google will use this information on our behalf to evaluate users’ use of our online services, to compile reports on activity within these online services, and to provide us with other services relating to the use of these online services and internet usage. Pseudonymous user profiles may be created from the processed data. We use Google Analytics only with IP anonymization enabled. This means that Google will shorten the IP address of users within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by the user’s browser will not be merged with other Google data. Users can prevent the storage of cookies by adjusting their browser settings; users can also prevent Google from collecting and processing data generated by the cookie and related to their use of the website by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de. Further information on Google’s data usage, settings, and opt-out options can be found in Google’s Privacy Policy (https://policies.google.com/technologies/ads) and in the settings for Google ad personalization (https://adssettings.google.com/authenticated). Users’ personal data will be deleted or anonymized after 14 months.
Online presence on social media
We maintain online presences within social networks and platforms to communicate with customers, prospects, and users active there and to inform them about our services. When accessing these networks and platforms, the terms and conditions and data processing policies of their respective operators apply. Unless otherwise stated in our privacy policy, we process user data when users communicate with us within these social networks and platforms, for example, by posting on our online presences or sending us messages.
Integration of third-party services and content
Within our online services, we use content or service offerings from third-party providers based on our legitimate interests (i.e., our interest in the analysis, optimization, and economic operation of our online services within the meaning of Art. 6 para. 1 lit. f GDPR) to integrate their content and services, such as videos or fonts (hereinafter referred to collectively as “Content”). This always requires that the third-party providers of this Content are aware of the users’ IP addresses, as they could not send the Content to their browsers without the IP address. The IP address is therefore necessary for displaying this Content. We strive to use only Content from providers who use the IP address solely for delivering the Content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These pixel tags allow information such as visitor traffic on the pages of this website to be evaluated. The pseudonymous information can also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, time of visit and other information about the use of our online service, as well as be combined with such information from other sources.
This privacy policy is currently valid and was last updated in June 2024.
Due to the ongoing development of our online services or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current privacy policy can be accessed and printed from the website at any time.
Erstellt mit Datenschutz-Generator.de von RA Dr. Thomas Schwenke sowie der WordPress Datenschutzerklärung von Automattic