top of page

Privacy Policy

1. Data protection at a glance

General Information


The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to any data with which you could be personally identified. Detailed information on data protection can be found in our privacy policy listed below this text.

​

Data Collection on This Website


Who is responsible for data collection on this website?
The data processing on this website is carried out by the website owner. You can find their contact details in the section “Information on the Responsible Party” in this privacy policy.

​

How do we collect your data?


Some data is collected when you provide it to us. This could be, for example, data you enter in a contact form.

Other data is collected automatically or with your consent when you visit the website. This data is primarily technical (e.g., internet browser, operating system, or the time the page was accessed). It is collected automatically as soon as you access the site.

​

What Do We Use Your Data For?


Some of the data is collected to ensure the website functions properly. Other data may be used to analyze user behavior.

​

What Rights Do You Have Regarding Your Data?


You have the right to obtain, at any time and free of charge, information about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to the processing of your data, you may revoke this consent at any time for the future. You also have the right to request the restriction of processing your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the relevant supervisory authority.

You can contact us at any time with further questions about data protection.

​

Analysis Tools and Third-Party Tools


When you visit this website, your browsing behavior may be statistically evaluated. This is done primarily with so-called analytics programs.

You can find detailed information about these analytics programs in the full privacy policy below.

2. Hosting and Content Delivery Networks (CDN)

External Hosting

​

This website is hosted by an external service provider (host). The personal data collected on this website is stored on the host’s servers. This may include IP addresses, contact requests, metadata and communication data, contract data, contact details, names, website access logs, and other data generated via the website.

​

The host is used for the purpose of fulfilling contracts with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of providing our online services securely, quickly, and efficiently through a professional provider (Art. 6 para. 1 lit. f GDPR).

​

Our host will process your data only to the extent necessary to fulfill its service obligations and in accordance with our instructions regarding this data.

​

We use the following host:

​

Wix.com, Inc

3. General Information and Mandatory Disclosures

Privacy

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.

When you use this website, various personal data are collected. Personal data refers to data that can be used to personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

Please note that data transmission over the internet (e.g., when communicating via email) may have security vulnerabilities. Complete protection of your data from access by third parties is not possible.


Note on the Responsible Party

The responsible party for data processing on this website is:

 
Villa Schlosser
Via Lungolago 5
37018 Malcesine VR

C.F. SCHSFO76T43B709H
 
info@villaschlosser.com



The responsible party is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Period

Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you request deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, deletion will occur after those reasons no longer apply.

Note on Data Transfer to the USA

Our website includes tools from companies based in the United States. When these tools are active, your personal data may be transferred to the US servers of the respective companies. We would like to point out that the USA is not considered a safe third country under EU data protection law. US companies are required to hand over personal data to security authorities without allowing you as the data subject to take legal action against this. Therefore, it cannot be ruled out that US authorities (e.g., intelligence services) may process, evaluate, and permanently store your data on US servers for surveillance purposes. We have no influence over these processing activities.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You may revoke your consent at any time. The legality of the data processing carried out before the revocation remains unaffected by the revocation.

Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS FOR PROCESSING CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING AT ANY TIME; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS ASSOCIATED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).


Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of a breach of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. The right to lodge a complaint is without prejudice to other administrative or judicial remedies.

Right to Data Portability

You have the right to receive the data that we process automatically based on your consent or in fulfillment of a contract, in a commonly used, machine-readable format, and to have it transmitted to another controller, where technically feasible.

SSL or TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the website operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser’s address line changes from "http://" to "https://" and by the lock icon in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.


Right to Information, Deletion, and Correction

Within the framework of the applicable legal provisions, you have the right to receive information free of charge at any time about your stored personal data, its origin and recipient, and the purpose of the data processing. You also have the right to request correction or deletion of this data. You can contact us at any time regarding this and other questions about personal data.

Right to Restriction of Processing

You have the right to request the restriction of processing of your personal data. You can contact us at any time regarding this right. The right to restrict processing applies in the following cases:

  • If you contest the accuracy of your personal data stored by us, we usually need time to verify this. During the verification period, you have the right to request the restriction of processing of your personal data.

  • If the processing of your personal data was/is unlawful, you may request restriction of data processing instead of deletion.

  • If we no longer need your personal data, but you need it to assert, exercise, or defend legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.

  • If you have filed an objection under Art. 21 Para. 1 GDPR, a balance must be struck between your interests and ours. Until it is determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

​
If you have restricted the processing of your personal data, such data – apart from being stored – may only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.

4. Data collection on this website

Cookies

​

Our website uses so-called “cookies.” Cookies are small text files that do not harm your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are deleted automatically after you leave the site. Persistent cookies remain on your device until you delete them yourself or they are automatically removed by your web browser.

​

In some cases, third-party cookies may also be stored on your device when you visit our website. These cookies enable us or you to make use of certain third-party services (e.g., cookies for processing payment services).

​

Cookies serve different functions. Many cookies are technically necessary, because certain website features would not work without them (e.g., the shopping-cart function or video display). Other cookies are used to analyse user behaviour or to display advertising.

​

Cookies that are required to carry out electronic communication (necessary cookies), to provide specific functions you request (functional cookies, e.g., for the shopping cart), or to optimise the website (e.g., cookies that measure web audience) are stored on the basis of Art. 6 (1) (f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing cookies to ensure the technically flawless and optimised provision of its services. Where consent to store cookies has been requested, the relevant cookies are stored solely on the basis of that consent (Art. 6 (1) (a) GDPR); consent can be revoked at any time.

​

You can configure your browser so that you are informed about the setting of cookies, allow cookies only in individual cases, exclude the acceptance of cookies for specific cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

​

If cookies are used by third-party companies or for analytics purposes, we will inform you separately within this privacy policy and, where necessary, ask for your consent.

​

Contact Form

​

If you send us enquiries via the contact form, the information you provide—including the contact details you enter—will be stored by us for the purpose of processing the enquiry and for follow-up questions. We will not pass on this data without your consent.

​

These data are processed on the basis of Art. 6 (1) (b) GDPR if your enquiry is related to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in efficiently handling enquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) if it has been requested.

​

The data you enter in the contact form remain with us until you ask us to delete them, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your enquiry has been processed). Mandatory statutory provisions—especially retention periods—remain unaffected.

​

Enquiries by E-mail, Telephone or Fax

​

If you contact us by e-mail, phone, or fax, your enquiry, including all personal data resulting from it (name, enquiry), will be stored and processed by us for the purpose of handling your request. We do not pass on these data without your consent.

​

These data are processed on the basis of Art. 6 (1) (b) GDPR if your request is related to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in efficiently handling the enquiries sent to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) if it has been requested.

​

The data you send us via contact enquiries remain with us until you ask us to delete them, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., once your request has been resolved). Mandatory statutory provisions—especially legal retention periods—remain unaffected.

5. Analysis and advertising tools

Google Tag Manager

​

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool that allows us to integrate tracking or analytics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies, or carry out any independent analyses. It only facilitates the management and deployment of the tools integrated through it. However, Google Tag Manager does collect your IP address, which may also be transferred to Google's parent company in the United States.

The use of Google Tag Manager is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the quick and easy integration and management of various tools on their website. If appropriate consent has been requested, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR; consent can be revoked at any time.

​

Google Analytics

​

This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data such as page views, time spent on the site, operating systems used, and the user’s origin. These data may be compiled by Google into a profile associated with the respective user or their device.

Google Analytics uses technologies that make it possible to recognize the user for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to a Google server in the USA and stored there.

​

The use of this analytics tool is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both the website and its advertising. If consent has been requested (e.g., consent to store cookies), the processing is based exclusively on Art. 6(1)(a) GDPR; the consent can be revoked at any time.

Data transfer to the USA is based on the EU Commission’s Standard Contractual Clauses. Details can be found here:
https://privacy.google.com/businesses/controllerterms/mccs/

 

Browser Plugin

​

You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link:
https://tools.google.com/dlpage/gaoptout?hl=en

 

Further information on how Google Analytics handles user data can be found in Google’s privacy policy:
https://support.google.com/analytics/answer/6004245?hl=en

 

Storage Period

​

User- and event-level data stored by Google that are linked to cookies, user IDs (e.g., User ID), or advertising IDs (e.g., DoubleClick cookies, Android advertising ID) are anonymized or deleted after 14 months. Details can be found here:
https://support.google.com/analytics/answer/7667196?hl=en

6. Newsletter

Newsletter Data


If you would like to receive the newsletter offered on this website, we require your email address and information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No other data is collected, or it is collected only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.

​

The processing of the data entered in the newsletter subscription form is based solely on your consent (Art. 6(1)(a) GDPR). You may revoke your consent to the storage of your data, email address, and their use for sending the newsletter at any time, for example via the "Unsubscribe" link in the newsletter. The lawfulness of any data processing that has already taken place remains unaffected by the revocation.

​

The data you provide for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe and will be deleted from the newsletter distribution list after you unsubscribe or once the purpose no longer applies. We reserve the right to remove or block email addresses from our newsletter mailing list at our discretion within the scope of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

​

After you have unsubscribed from the newsletter mailing list, your email address may be stored in a blacklist either by us or by the newsletter service provider to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest pursuant to Art. 6(1)(f) GDPR). Storage in the blacklist is not time-limited. You may object to the storage if your interests outweigh our legitimate interests.

7. Links to external sites

Our website includes links that lead to external sites, such as navigation features provided by Google Maps, social networks, and other third-party websites. It may also include embedded features where data is processed by third-party providers. For all information regarding data processing and cookie usage on these linked sites, please refer to the respective site owners' privacy policies.

bottom of page