Imprint

Service Provider
ALab.Studio
DI Antonio Labuhar, BSc
Gablenzgasse 33/1
1150 Vienna
Austria

UID: ATU77624028

Contact Information
Phone: +43 660 1612755
Email:

Social Media and Other Online Presences
This imprint also applies to the following social media profiles and online platforms:

– Instagram ↗︎
– YouTube ↗︎

Links to External Websites
The content of external websites to which we directly or indirectly refer is beyond our control, and we do not take ownership of such content. We do not accept any responsibility for any damages or disadvantages arising from the use of the information accessible on the linked websites.

Copyrights and Trademarks
All content presented on this website, including texts, photographs, graphics, trademarks, and service marks, is protected by applicable intellectual property laws (copyrights, trademark rights). Use, reproduction, etc., are subject to our rights or the rights of the respective copyright or trademark holders.

Image Sources and Copyright Notices
All image rights are owned by us, unless explicitly stated otherwise with a different copyright holder.

DATA-PRIVACY

With the following privacy policy, we aim to inform you about the types of your personal data (hereinafter also referred to as “data”), the purposes for which it is processed, and the extent of such processing. This privacy policy applies to all personal data processing activities we carry out, both as part of providing our services and, in particular, on our websites, mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as “online offering”).

The terms used are gender-neutral.

Effective Date: December 1st, 2024

Overview of Processing

The following overview summarizes the types of data processed, the purposes of the processing, and the categories of affected individuals.

Types of Data Processed:

  • Master data
  • Payment data
  • Contact data
  • Content data
  • Contract data
  • Usage data
  • Meta, communication, and procedural data

Categories of Affected Individuals:

  • Customers
  • Prospective customers
  • Users
  • Business and contractual partners

Purposes of Processing:

  • Provision of contractual services and customer support
  • Responding to inquiries and communication
  • Security measures
  • Office and organizational procedures
  • Administration and response to requests
  • Feedback collection
  • Marketing
  • User-related profiling
  • Provision and user-friendliness of our online offering
  • Information technology infrastructure
 

Legal Bases

The following provides an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations in your or our country of residence may apply. If more specific legal bases are relevant in individual cases, we will inform you in this privacy policy.

  • Contract performance and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR): Processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract.
  • Legal obligation (Art. 6(1)(1)(c) GDPR): Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(1)(f) GDPR): Processing is necessary for the purposes of legitimate interests pursued by the controller or a third party unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject that require the protection of personal data.

In addition to the GDPR’s data protection regulations, national regulations apply in Austria, notably the Federal Act on the Protection of Natural Persons regarding the Processing of Personal Data (Data Protection Act – DSG). The DSG includes specific provisions on the right to information, rectification or deletion, processing of special categories of personal data, processing for other purposes, transfers, and automated individual decision-making.

Security Measures

We implement appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.

These measures include ensuring the confidentiality, integrity, and availability of data by controlling both physical and electronic access to the data and access, input, transmission, securing availability, and separation of data. Additionally, we have established procedures to uphold data subject rights, delete data, and respond to data threats. Furthermore, we consider the protection of personal data during the development or selection of hardware, software, and procedures according to the principles of data protection by design and by default.

  • TLS Encryption (HTTPS): To protect the data transmitted through our online offering, we use TLS encryption. You can recognize such encrypted connections by the “https://” prefix in your browser’s address bar.

Data Processing in Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or processing occurs as part of using third-party services or disclosing or transferring data to other persons, entities, or companies, it will only be carried out in compliance with legal requirements.

Subject to express consent or required contractual or legal transfers, we process or allow data to be processed only in third countries with a recognized data protection level, contractual obligation through so-called EU Commission standard protection clauses, certifications, or binding internal data protection regulations (Art. 44–49 GDPR). More information is available on the EU Commission’s website: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en.

Data Deletion

The data we process will be deleted in accordance with legal requirements as soon as the consents permitted for processing are withdrawn or other permissions cease to apply (e.g., if the purpose of processing no longer applies or the data is no longer required for the purpose). If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted to these purposes. This means the data will be locked and not processed for other purposes. For instance, this applies to data required to be retained for commercial or tax law reasons or data needed to establish, exercise, or defend legal claims or to protect the rights of another natural or legal person.

Our privacy notices may also contain additional information about the retention and deletion of data for specific processing activities.

Use of Cookies

Cookies are small text files or other markers stored on devices to save and retrieve information from the devices. For example, they can store login statuses, shopping cart contents in an online store, accessed content, or used features of an online offering. Cookies can also be used for various purposes, such as ensuring the functionality, security, and convenience of online offerings or analyzing visitor flows.

Consent Notices: We use cookies in accordance with legal requirements. Therefore, we obtain prior consent from users unless legally not required. Consent is not necessary, particularly if storing and retrieving information (including cookies) is essential to provide a telemedia service (our online offering) explicitly requested by users. Revocable consent is clearly communicated to users and contains information on cookie usage.

Legal Basis for Cookies: The legal basis for processing users’ personal data using cookies depends on whether we ask for user consent. If users consent, the legal basis is their declared consent. Otherwise, data processed using cookies is based on our legitimate interests (e.g., for a business operation of our online offering and its usability improvement) or, if required, to fulfill contractual obligations.

Cookie Types and Duration

  • Temporary Cookies (Session Cookies): Deleted no later than when a user leaves the online offering and closes their device (e.g., browser or mobile application).
  • Permanent Cookies: Remain stored even after closing the device. For example, login statuses or preferred content can be displayed directly when revisiting a website. Unless otherwise specified, cookies should be assumed permanent, with a storage duration of up to two years.

Opt-Out Information: Users can revoke their given consent anytime and object to processing under the GDPR’s provisions (Art. 21 GDPR). Users can object via their browser settings, e.g., by disabling cookie use (although this may limit functionality). Objections to cookies for online marketing purposes can also be made at https://optout.aboutads.info and https://www.youronlinechoices.com.

Cookie Management Tool:

  • Complianz: Cookie consent management; Service provider: Locally hosted on our server, no data sharing with third parties.
 

WooCommerce

Functional

Usage

Sharing data

This data is not shared with third parties.

Functional

Name
Expiration
session
Function
Store items in shopping cart
Name
Expiration
session
Function
Store items in shopping cart
Name
Expiration
1 day
Function
Store items in shopping cart
Name
Expiration
session
Function
Store performed actions on the website

WordPress

Functional

Usage

We use WordPress for website development. Read more

Sharing data

This data is not shared with third parties.

Functional

Name
Expiration
session
Function
Store browser details
Name
Expiration
persistent
Function
Store user preferences
Name
Expiration
1 year
Function
Store user preferences
Name
Expiration
persistent
Function
Store logged in users

Complianz

Functional

Usage

Sharing data

This data is not shared with third parties. For more information, please read the Complianz Privacy Statement.

Functional

Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store accepted cookie policy ID
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store if the cookie banner has been dismissed

Stripe

Functional

Usage

Sharing data

This data is not shared with third parties.

Functional

Name
Expiration
1 year
Function
Provide fraud prevention

Google Fonts

Marketing

Usage

We use Google Fonts for display of webfonts. Read more

Sharing data

For more information, please read the Google Fonts Privacy Statement.

Marketing

Name
Expiration
expires immediately
Function
Read user IP address

Google reCAPTCHA

Marketing

Usage

We use Google reCAPTCHA for spam prevention. Read more

Sharing data

For more information, please read the Google reCAPTCHA Privacy Statement.

Marketing

Name
Expiration
session
Function
Read and filter requests from bots
Name
Expiration
session
Function
Read and filter requests from bots
Name
Expiration
persistent
Function
Read and filter requests from bots

Google Maps

Marketing

Usage

We use Google Maps for maps display. Read more

Sharing data

For more information, please read the Google Maps Privacy Statement.

Marketing

Name
Expiration
expires immediately
Function
Read user IP address

Vimeo

Statistics

Usage

We use Vimeo for video display. Read more

Sharing data

For more information, please read the Vimeo Privacy Statement.

Statistics

Name
Expiration
10 minutes
Function
Store and track audience reach
Name
Expiration
2 years
Function
Store the user’s usage history

YouTube

Marketing

Usage

We use YouTube for video display. Read more

Sharing data

For more information, please read the YouTube Privacy Statement.

Marketing

Name
Expiration
session
Function
Store location data
Name
Expiration
6 months
Function
Provide ad delivery or retargeting
Name
Expiration
session
Function
Store and track interaction
Name
Expiration
8 months
Function
Store user preferences

Miscellaneous

Purpose pending investigation

Usage

Sharing data

Sharing of data is pending investigation

Purpose pending investigation

Name
elementor
Expiration
Function
Name
acf
Expiration
Function
Name
e_globals
Expiration
Function
Name
wc_fragments_e937e944335f14fc681b28f890f1688a
Expiration
Function
Name
wc_cart_created
Expiration
Function
Name
sbjs_migrations
Expiration
Function
Name
sbjs_first_add
Expiration
Function
Name
sbjs_current
Expiration
Function
Name
sbjs_first
Expiration
Function
Name
sbjs_session
Expiration
Function
Name
wf_loginalerted_2063a94191f4c9a6db7e4992e83a22866f83cbec20839da628554b0252398211
Expiration
Function
Name
wfwaf-authcookie-a3f6109a1f488e459c567de8f2f4ccb7
Expiration
Function

Business Services

We process data of our contractual and business partners, e.g., customers and prospective customers (collectively referred to as “contractual partners”), within the context of contractual or comparable legal relationships, as well as associated measures and communication with these partners (including pre-contractual communication), such as responding to inquiries.

We process this data to fulfill our contractual obligations. This includes delivering agreed-upon services, addressing warranty claims, and resolving performance issues. Additionally, we process data to protect our rights, handle related administrative tasks, and organize our business operations. We also process data based on our legitimate interests in proper and efficient business management and implementing security measures to protect our contractual partners and business operations from misuse, risks to data, confidential information, and rights. This may include working with telecommunication, transportation, subcontractor services, banks, tax and legal advisors, payment service providers, or financial authorities. In compliance with applicable laws, we share contractual partners’ data with third parties only when necessary for the aforementioned purposes or to meet legal obligations. Further processing, such as for marketing purposes, will be communicated in this privacy policy.

We inform contractual partners about the required data for these purposes during or before data collection, e.g., through online forms, specific markings (e.g., colors, symbols, or asterisks), or in-person communication.

We delete data after the expiration of statutory warranty or similar obligations, generally after four years, unless the data is stored in a customer account or retained for legal archiving purposes. Statutory retention periods for tax-related documents, business records, inventories, opening balances, annual financial statements, operating instructions, and other organizational documents range from six to ten years. Retention periods start at the end of the calendar year in which the last entry, document creation, or related record was made.

If third-party providers or platforms are used for our services, their terms and privacy policies will apply to interactions between users and those providers or platforms.

Data Types Processed:

  • Personal Data: Names, addresses
  • Payment Data: Bank details, invoices, payment history
  • Contact Information: Email, phone numbers
  • Contractual Data: Contract subject, duration, customer categories
  • Usage Data: Websites visited, content interest, access times
  • Meta-, Communication, and Procedural Data: IP addresses, timestamps, identifiers, consent status

Affected Individuals: Customers, prospective customers, business, and contractual partners
Processing Purposes: Fulfilling contractual obligations, customer service, security measures, responding to inquiries, administrative tasks
Legal Bases:

  • Contractual Performance: Art. 6(1)(b) GDPR
  • Legal Obligations: Art. 6(1)(c) GDPR
  • Legitimate Interests: Art. 6(1)(f) GDPR

 

Additional Processing Details:

Online Shops and E-Commerce:
We process customer data to facilitate the selection, purchase, and order of products, services, and their payment and delivery. Where required, we work with service providers like shipping companies and payment processors. Necessary details for order processing include delivery and contact information.

Legal Basis: Art. 6(1)(b) GDPR


Online Offerings and Web Hosting

We process user data to provide online services, including IP addresses necessary to deliver content and functionality to user browsers or devices.

Data Types Processed: Usage data, meta/communication data (IP addresses, timestamps, identifiers), content data (e.g., online form entries).
Affected Individuals: Website visitors, online service users.
Purpose: Providing online offerings and user experience, IT infrastructure, and security measures.
Legal Basis: Art. 6(1)(f) GDPR

Details:

  • Hosting Services: Use of third-party servers for hosting.
  • Access Logs: Logfiles include requested resources, dates, IPs, browser types, and system information. Data retention: max. 30 days unless required longer for investigations.


Social Media Presence

We maintain online profiles on social networks to communicate with users and share information. User data may be processed outside the EU, posing risks like reduced enforceability of rights. Social platforms often process user data for analytics and advertising.

Data Types: Contact details, usage, and meta/communication data.
Purpose: Communication, feedback, marketing.
Legal Basis: Art. 6(1)(f) GDPR


Embedded Plugins and Content

We integrate third-party plugins (e.g., videos, maps). This requires third parties to process users’ IP addresses. Cookies may also be used for analytics or marketing.

Data Types: Usage data, communication/meta data, contact details, content data.
Purpose: Content delivery, user profiles, marketing.
Legal Basis: Art. 6(1)(f) GDPR

For detailed opt-out options, see respective providers’ policies.