Privacy Policy

In the following section, you will find information regarding the handling of your personal data, which is collected while you browse the website and use the services we offer. In order to provide you with all the functions and services of our website, it is necessary for us to collect and process personal data about you. The processing of your personal data may include any type of operation, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. The processing of your personal data is always carried out in accordance with the principles of lawfulness and fairness, taking into account all applicable regulations and in accordance with EU Regulation 679/2016 (GDPR) of the European Parliament and of the Council. We will explain to you which data we collect, why this is necessary, and what rights you have regarding your data.

Data Controller Responsibility
The responsibility for the processing of personal data on this website lies with Santerhof, Pustertaler Straße 40 - I-39037 Mühlbach (BZ), VAT No. IT03289110219.
Should you have any questions, you may contact us at any time.
Tel.: +39 345 4063937
E-Mail: info@weingutsanter.com
Internet: www.weingutsanter.com

Purpose of Data Processing
The Data Controller processes data:

  • to fulfill legal obligations
  • to fulfill contractual obligations
  • to provide the information and services you have requested
  • to review system efficiency
  • to conduct marketing activities, such as sending commercial information, advertising material, and market research
  • to protect liabilities (e.g., payments)
  • to determine customer satisfaction regarding the quality of products and services

Method of Data Processing
Your personal data will be processed manually, electronically, but mainly with automated means and processes tailored to the respective purposes. This primarily involves the use of databases and electronic platforms managed by us or by third parties. Every type of data processing guarantees the security and confidentiality of the data.

When connecting to the website, the IT systems and software procedures automatically and indirectly manage and/or acquire a series of general data and information. The following data may be collected:

  • browser types and versions used
  • the operating system used
  • the website from which an accessing system reaches our website (so-called referrers)
  • the sub-websites accessed via an accessing system on our website
  • the date and time of access
  • an Internet Protocol address (IP address)
  • other similar data and information

This general data and information are stored in the server's databases and log files to ensure a stable and secure experience for you. The legal basis is Art. 6 of the GDPR.
This anonymously collected data and information is therefore analyzed statistically on the one hand, and with the aim of increasing data protection and data security on the other hand, in order to ultimately ensure an optimal level of protection for the personal data we process.

Data Retention
In order to comply with the law, the Data Controller has set different retention periods for personal data depending on the individual purposes:

  • For the management of and response to your inquiries regarding products and initiatives, your personal data will be kept for as long as is necessary to process your request.
  • For the management of activities related to your use of the website, your personal data will be kept for as long as is necessary to provide the service you have requested.
  • For the management and execution of statutory obligations (regarding accounting, administration, taxation, etc.), your personal data will be kept for as long as necessary for this purpose.
  • For the management of disputes and possible legal proceedings, your personal data will be kept for as long as is strictly necessary to pursue these purposes, and in any case not longer than the applicable statute of limitations.

Partnership with Third-Party Providers
When we work with third-party providers, they are contractually obliged to use the same data protection/security standards, and we ensure that these are adhered to. Such third parties, acting as Data Processors, guarantee that they will not store the data received from us and will not use it for any other purposes.
Under such agreements, users' email addresses are transmitted to the third-party provider using cryptographic mechanisms (e.g., hashing). The traceability of the email address is therefore prevented.
We may need to transfer your data to service providers in non-European countries (EEA). The EEA consists of the countries of the European Union plus Switzerland, Iceland, Liechtenstein, and Norway, which are considered to be countries with equivalent laws regarding data protection and privacy. This type of data transfer can occur if our servers (i.e., where we store data) or our suppliers and service providers are located outside the EEA. In the event that we transfer your information to a country outside the European Economic Area (EEA), we will ensure that the information is properly protected.

Dissemination of Data
The personal data processed by us is generally not subject to public disclosure. In certain cases, data is transmitted to the following recipients:

  • Subcontractors for technical checks, payments, identity and delivery services, analytics providers, or credit insurance agencies.
  • Public administration and authorities, where required by law.
  • Credit institutions with which we have business relationships for the management of receivables/liabilities and for financial intermediation.
  • Any natural or legal, public and/or private persons (legal, administrative, and tax advisory offices, courts, chambers of commerce, etc.) if the forwarding of the data proves necessary or appropriate for the exercise of our business.

SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us, we use SSL/TLS encryption. You can recognize such an encrypted connection by the fact that the address line of the browser begins with "https://" and by the lock symbol in your browser line. If SSL/TLS encryption is activated, the data you transfer to us cannot be read by third parties.

Encrypted Payment Processing
If, after the conclusion of a fee-based contract, there is an obligation to provide us with your payment data, for example your account number, this data is required for payment processing. Payment transactions via common means of payment (Visa/MasterCard, direct debit) are carried out via an encrypted SSL/TLS connection.

Contact Form
Should you choose to send an inquiry via the contact form, the provision of certain personal data is necessary to meet your requirements. This is also why the respective fields of the form are marked with an asterisk or otherwise indicated as mandatory data. The provision of further personal and sensitive data is entirely up to you. Failure to provide, or incomplete provision of, the personal data marked with an asterisk or otherwise indicated as mandatory will result in the requested performance or service not being able to be carried out. By submitting the form, you agree to the data processing. Your data will be processed for the management and answering of your questions and will not be stored longer than necessary for the respective processing purposes.

Use of Cookies
To improve the use of our website, we use cookies. Cookies are text information that is stored on a computer via the browser when visiting a website. This storage serves to recognize a session. You can delete stored cookies at any time via your web browser or adjust the settings so that no cookies are stored. Under certain circumstances, it may then happen that not all of our services and functions of our website are available. You can find further information on this in our Cookie Policy.

Profiling
Profiling is any form of automated processing of personal data consisting of the use of personal data to evaluate, analyze, and predict certain personal aspects relating to a natural person. We have entered into agreements with third-party providers for this type of marketing.

User Rights
The rights listed above can be asserted by the data subject or a person authorized by them by sending a request to the Data Controller via registered letter or e-mail. The user has the right to receive a copy of the personal data in our possession. The response will be provided within the legally prescribed period.
In certain cases, we may store some information for legal purposes (suspected fraud, breach of general terms and conditions). If you believe that your rights have been violated, you also have the right to file a complaint with the competent data protection supervisory authority or to take legal action.

We summarize the rights of the data subject again as follows:

  • Right to Confirmation: Each data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning them is being processed. If a data subject wishes to avail themselves of this right of confirmation, they may contact us at any time.
  • Right of Access: Each data subject shall have the right to obtain free information about their personal data stored at any time. The information includes the following:
    • the purposes of the processing
    • the categories of personal data concerned
    • the recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organizations. If the data is transferred to a third country, the data subject also has the right to be informed of the appropriate safeguards relating to the transfer.
    • the envisaged period for which the personal data will be stored
    • the existence of the right to lodge a complaint with a supervisory authority
    • where the personal data is not collected from the data subject: any available information as to its source
    • the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.
  • Right to Rectification: Each data subject shall have the right to obtain without undue delay the rectification of inaccurate personal data concerning them.
  • Right to Erasure (Right to be forgotten): Each data subject shall have the right to obtain from the controller the erasure of personal data concerning them without undue delay, provided that one of the following grounds applies, as long as the processing is not necessary:
    • The personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed.
    • The data subject withdraws consent on which the processing is based according to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, and where there is no other legal ground for the processing.
    • The data subject objects to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing.
    • The personal data has been unlawfully processed.
    • The personal data must be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject.
    • The personal data has been collected in relation to the offer of information society services referred to in Art. 8(1) GDPR – Protection of minors.
  • Right to Restriction of Processing: Each data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:
    • The accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data.
    • The processing is unlawful, and the data subject opposes the erasure of the personal data and requests the restriction of their use instead.
    • The controller no longer needs the personal data for the purposes of the processing, but it is required by the data subject for the establishment, exercise, or defense of legal claims.
    • The data subject has objected to processing pursuant to Art. 21(1) GDPR pending the verification of whether the legitimate grounds of the controller override those of the data subject.
  • Right to Data Portability: Each data subject shall have the right to receive the personal data concerning them, which was provided to a controller, in a structured, commonly used, and machine-readable format. They shall also have the right to transmit those data to another controller without hindrance from the controller to which the personal data has been provided.
    Furthermore, in exercising their right to data portability pursuant to Art. 20(1) GDPR, the data subject shall have the right to have personal data transmitted directly from one controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.
  • Right to Object: Each data subject shall have the right to object, on grounds relating to their particular situation, at any time, to the processing of personal data concerning them. This also applies to profiling based on these provisions.
    We shall no longer process the personal data in the event of an objection, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.
    If we process personal data for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning them for such marketing. This also applies to profiling to the extent that it is related to such direct marketing.
  • Automated Individual Decision-Making, Including Profiling: Each data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them, or similarly significantly affects them, as long as the decision is not necessary for entering into, or the performance of, a contract between the data subject and a data controller. If the decision is necessary for entering into, or the performance of, a contract, or if it is based on the data subject's explicit consent, we shall implement suitable measures to safeguard the data subject's rights and freedoms.
  • Right to Withdraw Data Protection Consent: Each data subject shall have the right to withdraw their consent to the processing of their personal data at any time.

Location of Processing of Your Personal Data
Your personal data is mainly processed on our premises as well as in the departments where the Data Controllers are located. The contractually agreed service is provided exclusively in a member state of the European Union or in a state party to the Agreement on the European Economic Area. Any relocation of the service or sub-tasks thereof to a third country requires the prior consent of the client and may only take place if the special requirements of Art. 44 et seq. of the GDPR are met (e.g., adequacy decision of the Commission, standard EU data protection clauses, approved codes of conduct).

For further information, please contact us at the addresses provided in the "Imprint" section.

leaf icon