Privacy Policy

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Florian Reimann

Hirschstettner Straße 61/1/58

1220 Vienna

Email: info@vergilis-life.com

Telephone: +43 676 6157495

1) Data collection when visiting our website

When you use our website for purely informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files" ).

When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time of access
  • Amount of data sent in bytes
  • Source/referrer from which you accessed this page
  • Browser used
  • Operating system used
  • IP address used (possibly in anonymized form)

The processing is carried out in accordance with Article 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be disclosed or used for any other purpose. However, we reserve the right to subsequently review the server log files should there be concrete indications of unlawful use.

2) Cookies

To make your visit to our website more attractive and to enable the use of certain functions, we use so-called cookies on various pages . These are small text files that are stored on your device.

  • Some of the cookies we use are deleted after the end of the browser session, i.e., after you close your browser ( session cookies ).
  • Other cookies remain on your device and allow us to recognize your browser on your next visit ( persistent cookies ).

Insofar as personal data is processed through individual cookies used by us, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR for the performance of a contract , in accordance with Art. 6 para. 1 lit. a GDPR in the case of consent given , or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly, effective design of the website visit.

Cookie settings

You can configure your browser to notify you when cookies are set and decide individually whether to accept them, or to exclude the acceptance of cookies in certain cases or in general.

Important: If you do not accept cookies, the functionality of our website may be limited.

Managing cookie settings is described in the help menus of the respective browsers. Here are the links to the most common browsers:

 

3) Contact and hosting

Contact

When you contact us (e.g., via contact form or email), personal data is collected. The data collected via a contact form is indicated on the form itself. This data is stored and used solely for the purpose of responding to your inquiry , contacting you, and for the associated technical administration.

The legal basis for processing this data is Article 6(1)(b) GDPR (necessary for the performance of pre-contractual measures). Your data will be deleted 3 years after your request has been fully processed.

Hosting (Shopify)

We use the system of the following provider to host our website and display the page content:

Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (“Shopify”).

Data will also be transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada.

All data collected through this website is processed on the provider's servers. We have concluded a data processing agreement with the provider . For data transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

4) Data processing for contract fulfillment

Personal data is collected and processed in accordance with Article 6(1)(b) GDPR when you provide it to us for the performance of a contract. The specific data collected is evident from the respective order form. We store and use the data you provide for the purpose of fulfilling the contract. After complete contract fulfillment or deletion of your customer account, your data will be deleted in accordance with tax and commercial law retention periods (currently 7 years) .

5) Data processing 7 for order processing

5.1 Data transfer

Insofar as necessary for the performance of the contract for delivery and payment purposes, the personal data we collect will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR .

5.2 Use of special service providers for order processing and fulfillment

To fulfill our contractual obligations to our customers, we work with external shipping partners .

Transfer of personal data to shipping service providers

DPD Direct Parcel Distribution Austria GmbH (Arbeitergasse 46, Leopoldsdorf 2333, Austria)

  • Purpose: Delivery of the goods.
  • Legal basis:
    • Article 6 paragraph 1 letter a GDPR (consent): Disclosure of your email address and/or telephone number for the purpose of coordinating a delivery date or delivery notification, provided that you have given your express consent during the ordering process.
    • Article 6 paragraph 1 letter b GDPR (contract performance): Disclosure of the recipient's name and delivery address.
  • Revocation: Consent can be revoked at any time with effect for the future by contacting the data controller or the provider.

5.3 Use of payment service providers (Payment Services)

Amazon Pay

  • Provider: Amazon Payments Europe sca, 38 avenue JF Kennedy, L-1855 Luxembourg.
  • Processing: When selecting a prepayment payment method (e.g. credit card payment), your payment data provided during the ordering process, as well as information about the content of your order, will be transmitted to Amazon Pay in accordance with Art. 6 Para. 1 lit. b GDPR , exclusively for the purpose of payment processing.

Apple Pay

  • Provider: Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.
  • Processing: When you select "Apple Pay," payment processing is handled via the Apple Pay function on your device. The information is transmitted to Apple in encrypted form, encrypted again there, and then forwarded to the payment service provider of your payment card stored with Apple Pay for payment processing.
  • Legal basis: Article 6 paragraph 1 letter b GDPR (payment processing).
  • Additionally: Apple stores anonymized transaction data to improve the service (no personal information).

Apple Pay privacy information: https://support.apple.com/de-de/HT203027

Google Pay

  • Provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ( “Google” ).
  • Processing: If you select "Google Pay," payment processing is handled via the Google Pay application on your mobile device. The information provided during the order process is transmitted to Google, which sends your stored payment data, in the form of a unique transaction number, to the initiating website.
  • Legal basis:

PayPal

  • Provider: PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg.
  • Processing (prepayment): If you select a prepayment payment method, your payment details and information about the order content will be transmitted to PayPal for payment processing in accordance with Art. 6 para. 1 lit. b GDPR .
  • Processing (prepayment by provider): When selecting a payment method where we provide services in advance (e.g. purchase on account), certain personal data will also be transmitted to PayPal for credit checks .
    • Legal basis for credit check: Article 6 paragraph 1 letter f GDPR (safeguarding our legitimate interest in assessing creditworthiness).

    • Right to object: You can object to this data processing at any time.

Shopify Payments

  • Provider: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.
  • Processing: When selecting a prepayment payment method, your payment details and information about the order content will be transmitted to Shopify Payments in accordance with Art. 6 para. 1 lit. b GDPR , exclusively for the purpose of payment processing.

Klarna: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden.

  • Processing: If you choose a Klarna payment method, we transfer your data (name, address, DOB, email, phone, order details) to Klarna.
  • Credit Check: For "Pay Later" or "Financing," Klarna performs a credit check based on our legitimate interest (Art. 6 (1) lit. f GDPR).
  • Privacy Policy: https://www.klarna.com/intl/privacy-policy/

6. Use of your data for direct marketing

6.1 Registration for our email newsletter

Required information: Only your email address.

Legal basis: Article 6 paragraph 1 letter a GDPR (your consent ).

Logging: Your IP address, as well as the date and time of registration, are stored in order to be able to trace any possible misuse.

Unsubscribe: You can unsubscribe from the newsletter at any time via the link included in the newsletter or by sending us a corresponding message . After unsubscribing, your email address will be deleted immediately.

6.2 Sending the email newsletter to existing customers

Legal basis: Article 6 paragraph 1 letter f GDPR and Section 174 TKG (our legitimate interest in personalized direct marketing for similar goods or services ).

Right to object: You can object to the use of your email address for this advertising purpose at any time with effect for the future.

6.3 MailChimp

Provider: The Rocket Science Group, LLC d/b/a MailChimp, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.

Transfer: Your data will be transferred to MailChimp for the purpose of sending the newsletter in accordance with Art. 6 para. 1 lit. f GDPR (legitimate interest in effective newsletter marketing).

Tracking (only with consent): With your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, MailChimp carries out a statistical evaluation of success (open rates, clicks) using web beacons.

Revocation: Consent to newsletter tracking can be revoked at any time.

Data transfer to the USA: The provider has joined the EU-US Data Privacy Framework (adequacy decision of the EU Commission).

7) Web analytics

7.1 Google Analytics 4

Provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ( “Google” ).

Function: Web analytics service for analyzing your website usage.

Data processing: Google Analytics 4 uses cookies by default and collects information, including your IP address, which is shortened to prevent direct personal identification.

Legal basis: All processing, in particular the setting of cookies, only takes place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR .

Storage period: The data will be stored for a period of two months and then deleted.

Revocation: You can revoke your consent at any time with effect for the future via the "Cookie Consent Tool" provided on the website .

Data transfer to the USA: The provider has joined the EU-US Data Privacy Framework (adequacy decision).

Special functions:

Demographic characteristics: Creation of statistics on age, gender and interests (data cannot be attributed to any specific person).

Google Signals: Enables cross-device reporting if you have enabled personalized advertising and linked your devices to your Google account (only with consent).

UserIDs: Enables cross-device analysis of activities if you have set up an account on the website and log in on different devices (only with consent).

7.2 Google Ads Remarketing

Provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

Function: Retargeting technology to display interest-based advertising based on the pages you have visited.

Data processing: Google sets a cookie that uses a pseudonymous cookie ID. Further processing only takes place if you have consented to linking your browsing history with your Google account.

Legal basis: Article 6 paragraph 1 letter a GDPR (your explicit consent ). Retargeting technology will not be used without your consent.

Revocation: You can revoke your consent at any time via the "Cookie-Consent-Tool" .

Data transfer to the USA: The provider has joined the EU-US Data Privacy Framework (adequacy decision).

7.3 Google Ads Conversion Tracking

Provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ( “Google” ).

Function: Online advertising program for measuring the success of advertising campaigns.

Data processing: This function is used exclusively without cookies . Instead, your browser's local storage is used to save an ID assigned by Google.

Purpose: To generate conversion statistics to determine how many users clicked on an ad and were redirected to a page with conversion tracking.

Legal basis: Article 6 paragraph 1 letter f GDPR (our legitimate interest in the statistical evaluation of the success of our advertising campaigns).

Data transfer to the USA: The provider has joined the EU-US Data Privacy Framework (adequacy decision).

8) Tools

8.1 Consent Tool (Cookie Consent)

Function: Interactive user interface for obtaining valid user consent (opt-in) for cookies and applications that require consent. The tool ensures that these are only loaded if you have given your consent.

Data processing: This tool uses technically necessary cookies to store your cookie preferences . Insofar as personal data (such as the IP address) is processed in this context:

    • Article 6 paragraph 1 letter f GDPR (our legitimate interest in legally compliant consent management).

    • Article 6 paragraph 1 letter c GDPR (legal obligation to make the use of technically unnecessary cookies dependent on consent).

    • Legal basis:

9) Rights of the data subject ✅

Current data protection law grants you comprehensive rights as a data subject vis-à-vis the data controller.

  • Right

    Description

    Right of access (Art. 15 GDPR)

    Right to information about your personal data processed by us, the purposes of processing, storage period, categories of recipients, etc.

    Right to rectification (Art. 16 GDPR)

    Right to immediate rectification of inaccurate and/or completion of incomplete data.

    Right to erasure (Art. 17 GDPR)

    Right to erasure of your data if the conditions are met (this does not apply, for example, if processing is necessary for the establishment, exercise, or defense of legal claims).

    Right to restriction of processing (Art. 18 GDPR)

    Right to request the restriction of processing, for example while the accuracy of your data is being verified or you object to its deletion.

    Right to information (Art. 19 GDPR)

    Right to be informed about the recipients to whom rectification, erasure or restriction of processing has been communicated.

    Right to data portability (Art. 20 GDPR)

    You have the right to receive the data you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller.

    Right to withdraw consent (Art. 7 para. 3 GDPR)

    Right to revoke previously granted consent to data processing at any time with effect for the future.

    Right to lodge a complaint (Art. 77 GDPR)

    Right to lodge a complaint with a supervisory authority if you believe that the processing of your data violates the GDPR (in Austria: Data Protection Authority ).

    9.2 Right to object 🛑
  • If your personal data is processed based on our overriding legitimate interest , you have the right to object to this processing at any time with effect for the future . Further processing remains reserved if there are compelling legitimate grounds for the continued processing.

10) Duration of storage of personal data

The duration of the storage of personal data depends on the respective legal basis, the processing purpose and the applicable statutory retention periods.

Consent (Art. 6 para. 1 lit. a GDPR): Storage until consent is withdrawn .

Contractual performance (Art. 6 para. 1 lit. b GDPR) and legal obligations: Routine deletion after the expiry of the statutory retention periods (e.g. commercial and tax law periods), provided that there is no longer a need for contract performance or a legitimate interest in further storage.

Direct marketing (Art. 6 para. 1 lit. f GDPR): Storage until the right to object is exercised (Art. 21 para. 2 GDPR).

In general: Stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or processed.