Data protection information of Hochzeitsatelier Irvalda e.U./ Hochzeitsatelier Irvalda, as of: 13.04.2020

Since May 25, 2018, the uniform requirements of the EU General Data Protection Regulation (GDPR). In the following data protection information, we inform you about the processing of personal data carried out by Hochzeitsatelier Irvalda e.U. in accordance with the GDPR and the Data Protection Act(DSG). Please read our data protection information carefully. If you have any questions or comments about our data protection information, please contact us athallo@irvalda.com1. Name and contact details of the controller This data protection information applies to data processing by Hochtzeitsatelier Irvalda e.U. – Hochzeitsatelier Irvalda Müglendergasse 6/3 1170 Vienna Austria kontakt@irvalda.com Owner: Iryna Domann Website:www.irvalda.com2. Purposes of data processing, legal bases and legitimate interests pursued by the controller or a third party and categories of recipients2.1 Accessing our websites/applications

2.1.1. Log-Files Every time you access websites/applications, information is sent to the server of our website/application through the respective Internet browser of your respective device and temporarily stored in log files. The data records stored in this way contain the following data, which are stored until they are automatically deleted: date and time of retrieval, name of the page accessed, IP address of the requesting device, referrer URL (origin URL from which you came to our website), the amount of data transferred, loading time, as well as product and version information of the browser used and the name of your access provider. The legal basis for processing the IP address is Article 6 paragraph 1 letter f) GDPR. Our legitimate interest arises from the

  • Ensuring a smooth connection setup,
  • To ensure convenient use of our website/application,
  • Evaluation of system security and stability.

It is not possible to draw any direct conclusions about your identity from the information and we will not do so. The data is stored and automatically deleted once the aforementioned purposes have been achieved. The standard periods for deletion are based on the criterion of necessity. 2.1.2. Cookies, Tracking, Social-Media-Plugins We use cookies, tracking tools, targeting processes and social media plug-ins for our website/application. The exact processes involved and how your data is used for this purpose are explained in detail below. 2.1.3. Geo-Lokalisation If you have agreed to geolocalization in your browser, operating system or other settings on your device, we use this function to offer you individual services based on your current location (e.g. the location of the nearest branch). We process your location data processed in this way exclusively for this function. If you stop using this function, the data will be deleted. 2.2.Establishment, execution and/or termination of a contract

2.2.1. Datenverarbeitung bei Vertragsabschluss If you register with one of our websites/applications and conclude a contract with us, we process the data required for the conclusion, performance or termination of a contract with you. This includes

  • First name, last name
  • Billing and delivery address
  • E-mail address
  • Invoice and payment data
  • Date of birth
  • Wedding date
  • Phone number

The legal basis for this is Article 6 Paragraph 1 Letter b) GDPR, i.e. you provide us with the data on the basis of the respective contractual relationship (e.g. management of your customer account, processing a purchase contract) between you and us. In addition, we are obliged to process your email address in the event of a purchase via our websites/applications due to legal requirements in the General Civil Code (ABGB) to send an electronic order confirmation (Article 6 Paragraph 1 Letter c) GDPR). Unless we use your data for advertising purposes (see 3.3 below), we store the data collected for contract processing until the statutory or possible contractual warranty and guarantee rights expire. After this period has expired, we retain the information required by company and tax law for the legally specified periods of time. During this period, the data will only be processed again in the event of an audit by the tax authorities. In order to process a purchase contract via our websites/applications, the following data processing is also required: In order to process a purchase contract via our websites/applications, the following data processing is also required: Your payment details will be passed on to payment service providers commissioned by us, who will process the payment(s). We pass on information about your delivery address to logistics companies and shipping partners commissioned by us. To ensure that the goods are delivered according to your wishes, we will send your email address and, if applicable, telephone number to the logistics company and/or shipping partner commissioned by us who will take care of the delivery. They will contact you if necessary prior to delivery to coordinate the details of the delivery with you. The respective data will only be transmitted for the respective purposes and will be deleted again after delivery has taken place. 2.2.2. Nutzung von Daten zu Zwecken der Betrugsprävention The data you provide when placing an order may be used to check whether an atypical ordering process has taken place (e.g. simultaneous ordering of a large number of goods to the same address using different customer accounts). In principle, we have a legitimate interest in carrying out such a check. The legal basis for processing is Art. 6(1)(f) GDPR. 2.2.3. Übermittlung von Daten an Transportdienstleister For the purpose of delivering ordered goods, we work with logistics service providers/transport companies and/or shipping partners: The following data may be transmitted to them for the purpose of delivering the ordered goods or to announce them: first name, last name, postal address, telephone number and, if applicable, email address. The legal basis for the processing is Art. 6 paragraph 1 letter b) GDPR. 2.3. Datenverarbeitung zu Werbezwecken

2.3.1. Postalische Werbung Wir haben grundsätzlich ein berechtigtes Interesse daran, Ihre Daten zu Marketingzwecken zu nutzen. Wir erheben die folgenden Daten zu eigenen Marketingzwecken sowie zu Marketingzwecken Dritter: Vorname, Nachname, Postadresse, Geburtsjahr. Die genannten Daten können hierfür auch an Dritte übermittelt werden. Wir sind außerdem dazu berechtigt, den genannten Daten weitere über Sie unter Einhaltung der gesetzlichen Vorgaben erhobene personenbezogene Daten zu eigenen Marketingzwecken sowie zu Marketingzwecken Dritter hinzu zu speichern. Ziel ist es, Ihnen allein an Ihren tatsächlichen oder vermeintlichen Bedürfnissen orientierte Werbung zukommen zu lassen und Sie entsprechend nicht mit unnützer Werbung zu belästigen. Eine Übermittlung der hinzugespeicherten Daten an Dritte erfolgt nicht. Außerdem pseudonymisiert der Verantwortliche über Sie erhobene personenbezogene Daten zum Zweck der Nutzung der pseudonymisierten Daten für eigene Marketingzwecke sowie für Marketingzwecke Dritter (Werbetreibende). Die pseudonymisierten Daten können auch dazu genutzt werden, um Sie individualisiert online zu bewerben, wobei die Aussteuerung der Werbung durch einen Dienstleister / Agentur erfolgen kann. Rechtsgrundlage für die Nutzung personenbezogener Daten zu Marketingzwecken ist Art. 6 Absatz 1 Buchstabe f) DSGVO. Hinweis auf das Widerspruchsrecht Sie können der Nutzung Ihrer personenbezogenen Daten zu vorgenannten Werbezwecken jederzeit kostenfrei mit Wirkung für die Zukunft unter hallo@irvalda.com widersprechen. Soweit Sie Widerspruch einlegen werden Ihre Daten für die weitere werbliche Datenverarbeitung gesperrt. Wir weisen darauf hin, dass es in Ausnahmefällen auch noch nach Eingang Ihres Widerspruchs vorübergehend noch zu einem Versand von Werbematerial kommen kann. Dies ist technisch durch die nötige Vorlaufzeit im Rahmen der Selektion bedingt und bedeutet nicht, dass wir Ihren Widerspruch nicht umgesetzt haben. 2.3.2. Newsletter Auf unseren Websites/ Applikationen bieten wir Ihnen die Möglichkeit, sich für unsere Newsletter anzumelden. Um sicher gehen zu können, dass bei der Eingabe der Emailadresse keine Fehler unterlaufen sind, setzen wir das sog. Double-Opt-In-Verfahren (DOI-Verfahren) ein: Nachdem Sie Ihre Email-Adresse in das Anmeldefeld eingegeben haben, übersenden wir Ihnen einen Bestätigungslink an die angegebene Adresse. Erst wenn Sie diesen Bestätigungslink anklicken, wird Ihre Email-Adresse in unseren Verteiler zum Versand unserer Newsletter aufgenommen. Rechtsgrundlage für diese Datenverarbeitung ist Artikel 6 Absatz 1 Buchstabe a) DSGVO. Hinweis Widerrufsrecht Sie können Ihre Einwilligung jederzeit mit Wirkung für die Zukunft durch eine Mitteilung an unter hallo@irvalda.com oder die Abmeldemöglichkeit am Ende eines jeden Newsletters widerrufen. 2.3.3. Produktempfehlungen per E-Mail Als Bestandskunde unseres Onlineshops erhalten Sie regelmäßig Produktempfehlungen von uns per E-Mail. Diese Produktempfehlungen erhalten Sie von uns unabhängig davon, ob Sie einen Newsletter abonniert haben. Hierbei verwenden wir die von Ihnen im Rahmen des Kaufs angegebene E-Mailadresse zur Bewerbung von eigenen Waren und / oder Dienstleistungen, die denjenigen ähneln, die Sie bei uns aufgrund einer bereits getätigten Bestellung erworben haben. Rechtsgrundlage für diese Datenverarbeitung ist Art. 6 Abs. 1 Buchstabe f) DSGVO. Hinweis Widerspruchsrecht Sie können unseren Produktempfehlungen jederzeit mit Wirkung für die Zukunft durch eine Mitteilung an hallo@irvalda.com oder am Ende einer jeden Produktempfehlungs-EMail widersprechen, ohne dass hierfür andere als die Übermittlungskosten nach den Basistarifen entstehen. 2.3.4. Gewinnspiele If you register for competitions organized by us, we will use the data you provide during registration for the purpose of implementing the participation contract, in particular for notifying you of prizes and, if applicable, for advertising our offers and/or offers from our competition partners. Detailed information can be found in the respective conditions of participation for each competition. The legal basis for this data processing is Article 6(1)(a) GDPR, Article 6(1)(b) GDPR and Article 6(1)(f) GDPR. 2.4. Onlineauftritt und Webseitenoptimierung

2.4.1. Cookies Allgemeine Information We use cookies on various pages to make visiting our website attractive and to enable the use of certain functions as well as to statistically record the use of our website. Cookies are small text files that your browser automatically creates and that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit our website. Cookies do not cause any damage to your end device and do not contain any viruses, Trojans or other malware. Information is stored in the cookie that results in each case in connection with the specific end device used. However, this does not mean that we gain direct knowledge of your identity. Most of the cookies we use are deleted again at the end of the browser session (so-called session cookies). These enable us, for example, to offer you the cross-page shopping cart display, in which you can see how many items are currently in your shopping cart and what your current purchase value is. Other cookies remain on your computer and enable us to recognize your computer on your next visit (so-called persistent or cross-session cookies). These cookies in particular serve to make our website more user-friendly, effective and secure. Thanks to these files, it is possible, for example, to display information on the site that is specifically tailored to your interests. If you have a customer account and are logged in or have activated the „stay logged in“ function, the information stored in cookies is assigned to a pseudonymized cookie ID. Of course, you can configure your browser so that it does not store our cookies on your hard disk. The help function in the menu bar of most web browsers explains how you can prevent your browser from accepting new cookies, how you can have your browser notify you when you receive a new cookie or how you can delete all cookies already received and block all further cookies. Please proceed as follows: In Internet Explorer, select „Internet Options“ from the „Tools“ menu. Click on the „Privacy“ tab. You can now make the security settings for the Internet zone. Here you can set whether and which cookies should be accepted or rejected. Confirm your settings with „OK“. In Firefox: Select „Settings“ in the „Extras“ menu. Click on „Privacy“. In the drop-down menu, select the entry „Create according to user-defined settings“. You can now set whether cookies should be accepted, how long you want to keep these cookies and add exceptions to which websites you always or never want to allow cookies to be used. Confirm your settings with „OK“. In Google Chrome: Click on the Chrome menu in the browser toolbar. Now select „Settings“. Click on „Show advanced settings“. Under „Privacy“, click on „Content settings“. You can make the following settings for cookies under „Cookies“: Delete cookies Block cookies by default Delete cookies and website data by default after closing the browser Allow exceptions for cookies from certain websites or domains   You can deactivate the collection and storage of data in this browser at any time with effect for the future here. However, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. If these cookies and/or the information they contain are personal data, the legal basis for data processing is Art. 6(1)(f) GDPR. Our interest in optimizing our website is to be regarded as legitimate within the meaning of the aforementioned provision. 2.4.2. Google Analytics We use Google Analytics, a web analysis service of Google Inc. („Google“), for the purpose of designing and continuously optimizing our pages in line with requirements on the basis of Article 6 (1) (f) GDPR. Google Analytics uses „cookies“, which are text files placed on your computer, to help the website analyze how users use the site. In this context, pseudonymized user profiles are created and cookies are used. The information generated by the cookie about your use of this website such as

  • browser type/version, – operating system used, – referrer URL (the previously visited page), – host name of the accessing computer (IP address), – time of the server request

Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de. As an alternative to the browser add-on, especially for browsers on mobile devices, you can also prevent Google Analytics from collecting data by clicking on this link. An opt-out cookie will be set to prevent the future collection of your data when you visit this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again. Further information on data protection in connection with Google Analytics can be found on the Google Analytics website. 2.4.3. Werbepartner/ Third-Party-Cookies We work together with advertising partners to make the online offer on our site even more interesting for you. For this purpose, cookies are also set by our advertising partners when you visit our site (so-called third-party cookies). Information about your user behavior and your interests when you visit our website is also stored in the cookies of our advertising partners using pseudonyms. In some cases, information is also collected that was found on other websites before you visited our site. This information is used to show you interest-based advertisements from our advertising partners. No personal data is stored and no user profiles are merged with personal data about you. You can prevent our advertising partners from displaying interest-based advertising by selecting the appropriate cookie settings in your browser (see also 2.4.1 reference above). 2.4.4. Google Adwords Our website uses the Google AdWords service. Google AdWords is an online advertising program from Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA („Google“). On the one hand, we use the remarketing function within the Google AdWords service. With the remarketing function, we can present users of our website with advertisements based on their interests on other websites within the Google display network (on Google itself, so-called „Google ads“ or on other websites). For this purpose, the interaction of users on our website is analyzed, e.g. which offers the user was interested in, in order to be able to display targeted advertising to users on other sites even after they have visited our website. For this purpose, Google stores a number in the browsers of users who visit certain Google services or websites in the Google Display Network. This number, known as a „cookie“, is used to record the visits of these users. This number is used to uniquely identify a web browser on a specific computer and not to identify a person; personal data is not stored. The legal basis for this data processing is Article 6(1)(f) GDPR. You can deactivate the use of cookies by Google by following the link below and downloading and installing the plug-in provided there: www.google.com/settings/ads/plugin. You can find more information about Google Remarketing and Google’s privacy policy at: www.google.com/privacy/ads/. 2.4.5. Social-Media-Plug-Ins We use social plug-ins from the social networks Facebook, Google+ and Twitter on our website on the basis of Article 6(1)(f) GDPR in order to make our company better known. The underlying advertising purpose is to be regarded as a legitimate interest within the meaning of the GDPR. Responsibility for data protection-compliant operation must be guaranteed by the respective provider. The purpose and scope of the data collection and the further processing and use of the data by the respective provider as well as your rights in this regard and setting options to protect your privacy can be found in the respective data protection information of the provider, which we link to below. You can prevent social networks from assigning the information collected about you to your user account with the respective social network during your visit by logging out of the social network pages beforehand and deleting cookies that have been set. If you do not want social networks to assign the data collected via our website directly to your profile, you must log out of the relevant social networks before visiting our website. You can also completely prevent the plugins from loading with add-ons for your browser, e.g. with the script blocker „NoScript“, which can be found at: http://noscript.net. 2.4.6. Facebook, Google+ und YouTube Social plugins from Facebook and Google (Google+ and YouTube) are used on this website. These are offers from the US companies Facebook and Google Inc (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA („Google„)). When you visit a page that contains such a plugin, your browser establishes a connection to Facebook or Google and the content is loaded from these pages. Your visit to this website may therefore be tracked by Facebook and Google, even if you do not actively use the social plugin function. If you have an account with Facebook or Google, you can use such a social plugin and share information with your friends. OTTO has no influence on the content of the plugins and the transmission of information. Facebook and Google provide detailed information on the scope, type, purpose and further processing of your data on their websites. Here you will also find further information on your rights and setting options to protect your privacy. Data protection information from Facebook: https://www.facebook.com/about/privacy. Data protection information from Google: http: //www.google.com/intl/de/policies/privacy . 2.4.7. Pinterest Plugins of the social network Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA („Pinterest“) are integrated on this website. You can recognize the Pinterest plugin by the „Pin it button“ on our site. If you click on the Pinterest „Pin it button“ while you are logged into your Pinterest account, you can link the content of our pages to your Pinterest profile. This allows Pinterest to associate your visit to our pages with your user account. We would like to point out that we have no knowledge of the content of the transmitted data or its use by Pinterest. Further information can be found in Pinterest’s privacy policy: http://about.pinterest.com/de/privacy. 2.4.8. Instagram Plugins of the social network Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA („Instagram„) are also integrated on this website. You can recognize the Instagram plugin by the „Instagram button“ on our site. If you click on the „Instagram button“ while you are logged into your Instagram account, you can link the content of our pages to your Instagram profile. This allows Instagram to associate your visit to our pages with your user account. We would like to point out that we have no knowledge of the content of the transmitted data or its use by Instagram. Further information can be found in Instagram’s privacy policy: http: //instagram.com/about/legal/privacy/ . 2.5. Kundenkonto/ Nutzerkonto In order to provide you with the greatest possible convenience, we offer you the permanent storage of your personal data in a password-protected customer account/user account. The creation of the customer account is basically voluntary and is based on your consent within the meaning of Article 6 (1) (b) GDPR. Once you have set up a customer account, you do not need to enter your data again. You can also view the data stored about you in your customer account at any time and change some of it. Only if you wish to place orders via our website/application is it necessary to open a customer account to process the contract. The legal basis for data processing in this case is (additionally) Art. 6 (1) (a) GDPR. In addition to the data requested when placing an order, you must enter a password of your choice to set up a customer account. This is used together with your e-mail address to access your customer account. Please treat your personal access data confidentially and in particular do not make it accessible to unauthorized third parties. Please note that you will automatically remain logged in even after leaving our website, unless you actively log out. You have the option of deleting your customer account at any time. Please note, however, that this does not mean that the data visible in your customer account will be deleted once you have placed an order with us. Your data will be deleted automatically after expiry of the retention obligations under commercial and tax law that apply to us. The legal basis for this data processing is Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. 2.6. Contact us You have the option of contacting us in several ways. By e-mail, by telephone, by chat or by post. When you contact us, we use the personal data that you voluntarily provide to us in this context solely for the purpose of contacting you and processing your request. The legal basis for this data processing is Art. 6(1)(a), Art. 6(1)(b), Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. 2.7. Kundenbewertungen/ Kommentare When users leave comments or other contributions on www.irvalda.com, their IP addresses are stored on the basis of our legitimate interests within the meaning of Art. 6 para. 1 letter f). GDPR for 7 days. This is done for our security in case someone leaves illegal content in comments and posts (insults, prohibited political propaganda, etc.). Users can subscribe to comments with their consent in accordance with Art. 6 (1) (a) GDPR and unsubscribe from ongoing comment subscriptions at any time. For the purposes of proving the user’s consent, we store the time of registration together with the user’s IP address and delete this information when users unsubscribe from the subscription. 2.8. Sonstige Inhalte von Nutzern You have the opportunity to publish your own content on www.irvalda.com in various places (e.g. product reviews, comments, etc.). If you post a comment, a recommendation or a rating on products, brands and styles, we process the personal data that you voluntarily enter as part of the comment or rating. The legal basis for this data processing is Art. 6(1)(a), Art. 6(1)(b) and Art. 6(1)(f) GDPR. In addition, our terms of use apply to the settings of your own content, which you can access here. 2.9. Zahlungen We process your payment information for the purpose of payment processing, e.g. when you purchase or use a product and/or service via www.irvalda.com. Depending on the payment method, we may forward your payment information to third parties (e.g. to your credit card provider in the case of credit card payments). The legal basis for this data processing is Art. 6(1)(a), Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR. 2.9.1 PayPal When paying via PayPal, your payment data will be forwarded to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter „PayPal“) as part of the payment processing. PayPal reserves the right to use address data, among other things, to calculate the score values for the payment methods credit card via PayPal. Further data protection information, including information on the credit agencies used, can be found in PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full3. Your rights

3.1. Überblick In addition to the right to withdraw your consent given to us, you have the following additional rights if the respective legal requirements are met:

  • the right to information about your personal data stored by us (Art. 15 GDPR), in particular you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the origin of your data if it has not been collected directly from you;
  • the right to rectification of incorrect data or completion of correct data (Art. 16 GDPR),
  • the right to erasure of your data stored by us (Art. 17 GDPR), provided that no statutory or contractual retention periods or other statutory obligations or rights to further storage are to be complied with by us,
  • the right to restrict the processing of your data (Art. 18 GDPR) if the accuracy of the data is disputed by you, the processing is unlawful but you refuse to delete it; the controller no longer needs the data, but you need it to assert, exercise or defend legal claims or you have lodged an objection to the processing in accordance with Art. 21 GDPR,
  • the Right to data portability pursuant to Art. 20 GDPR i.e. the right to receive selected data stored by us about you in a commonly used, machine-readable format or to request that it be transmitted to another controller
  • the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.

3.2. Widerspruchsrecht Under the conditions of Art. 21 (1) GDPR, data processing may be objected to on grounds relating to the particular situation of the data subject. The above general right to object applies to all processing purposes described in this data protection information that are processed on the basis of Article 6(1)(f) GDPR. In contrast to the specific right to object to data processing for advertising purposes, we are only obliged under the GDPR to implement such a general objection if you give us reasons of overriding importance (e.g. a possible danger to life or health). 3.3. Widerrufsrechts Insofar as we process data on the basis of your consent, you have the right to withdraw your consent at any time. The revocation of consent does not have the consequence that the data processing carried out on the basis of the consent up to the time of revocation becomes ineffective.