1. Introduction
Backflexexpel ("we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website backflexexpel.world and use our services.
We comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Austrian Data Protection Act (Datenschutzgesetz - DSG), and other applicable data protection laws.
2. Data Controller
The data controller responsible for your personal data is:
Backflexexpel
Salbergweg 6
8940 Liezen
Austria
Email: infocenter@backflexexpel.world
3. Personal Data We Collect
We may collect the following categories of personal data:
3.1 Information You Provide
- Contact Information: Name, email address, phone number (optional)
- Order Information: Details provided when placing an order
- Communication Data: Messages and correspondence with us
3.2 Automatically Collected Information
- Technical Data: IP address, browser type, operating system, device information
- Usage Data: Pages visited, time spent on pages, navigation patterns
- Cookie Data: Information collected through cookies and similar technologies
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
- Consent (Art. 6(1)(a)): Where you have given explicit consent for specific processing activities
- Contract Performance (Art. 6(1)(b)): Processing necessary to fulfill our contractual obligations to you
- Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate business interests, provided these do not override your rights
5. Purposes of Processing
We use your personal data for the following purposes:
- Processing and fulfilling your orders
- Communicating with you about your orders and inquiries
- Providing customer support
- Improving our website and services
- Sending marketing communications (with your consent)
- Complying with legal obligations
- Preventing fraud and ensuring website security
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Order Data: Retained for 7 years to comply with Austrian tax and commercial law requirements
- Marketing Consent: Until you withdraw consent or unsubscribe
- Website Analytics: Aggregated and anonymized after 26 months
- Customer Inquiries: Retained for 3 years after resolution
7. Data Sharing and Transfers
We may share your personal data with:
- Service Providers: Payment processors, shipping companies, and IT service providers who assist in our operations
- Advertising and Analytics Providers: Where you have given consent (e.g. marketing or analytics cookies), providers such as Google may process limited data for ad measurement, conversion tracking, or remarketing in line with their terms and our Cookie Policy
- Legal Authorities: When required by law or to protect our legal rights
We do not sell your personal data in the sense of disclosure for monetary or other valuable consideration to unrelated third parties for their own marketing.
If we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Request correction of inaccurate data
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18): Request limitation of processing
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to Object (Art. 21(1)): Object to processing based on legitimate interests, on grounds relating to your particular situation
- Right to Object to Direct Marketing (Art. 21(2)): Where we process data for direct marketing, you may object at any time; we will then stop processing for that purpose
- Right to Withdraw Consent (Art. 7): Withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal
You also have the right to lodge a complaint with a supervisory authority (in Austria: the Austrian Data Protection Authority).
To exercise these rights, contact us at infocenter@backflexexpel.world. We will respond without undue delay and in any event within one month (Art. 12 GDPR); that period may be extended by two further months where necessary, in which case we will inform you.
8a. Automated Decision-Making and Profiling
We do not use automated decision-making, including profiling, which produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. If this changes, we will inform you and describe the logic and consequences.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- SSL/TLS encryption for data transmission
- Secure data storage with access controls
- Regular security assessments
- Employee training on data protection
10. Cookies
Our website uses cookies and similar technologies. For detailed information about our cookie practices, please see our Cookie Policy.
11. Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated revision date. We encourage you to review this policy regularly.
13. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Vienna, Austria
Website: dsb.gv.at