Data Controller (Provider):
Company Name: Nobileaty GmbH
Address: Josef-Fritsch-Weg 5/518, 1020 Vienna, Austria
Phone: +43-664-99253100
E-mail: office@nobileaty.com
Data Protection Contact:
Name: Walter Leor Phillips
E-mail Address: office@nobileaty.com
1. General Information
This Privacy Policy explains how we process personal data when you use our webshop https://nobileaty.com. We comply with the provisions of the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the E-Commerce Act (ECG).
2. Data Processing Purposes and Legal Basis
2.1 Order processing
We process name, address, e-mail, phone number, billing and shipping data, as well as payment details to fulfil your order.
Legal basis: GDPR Art. 6 (1) b (contract performance).
2.2 Customer account / registration
Registration is voluntary and free of charge. Users must provide accurate and complete data.
Legal basis: GDPR Art. 6 (1) b.
2.3 Newsletter subscription
We use the double opt-in procedure. The data (e-mail, name) is transmitted to our newsletter provider (MailerLite – servers in Germany and Netherlands).
Legal basis: GDPR Art. 6 (1) a (consent).
2.4 Web analytics and cookies
- Essential cookies: always active, required for website operation.
- Analytics/marketing cookies: only active after explicit consent via cookie banner.
Legal basis: GDPR Art. 6 (1) a and f.
2.5 Security and server logs
We store IP addresses and access data for technical security reasons and to prevent misuse. Data is automatically deleted after a maximum of 3 months.
3. Data Sharing with Third Parties
Personal data is only shared to the extent necessary:
- Shipping providers (delivery of goods)
- Payment providers (bank, credit card processors)
- Newsletter providers
- Accounting/tax advisors (legal obligation)
- IT and hosting providers
All partners process the data in compliance with GDPR.
4. Data Retention Period
- Order data: 7 years (due to legal obligations)
- Shipping data: until fulfilment of the order
- Newsletter data: until withdrawal of consent (unsubscription)
- Server logs: up to 3 months
5. Data Subject Rights
You have the following rights:
- Access to personal data
- Rectification
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability
- Objection to processing
- Right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at)
6. Security Measures
We implement technical and organizational security measures to protect your personal data against unauthorized access, loss, or theft.
7. Embedded Content and Social Media
Embedded services (e.g. YouTube, Google Maps) are only loaded after consent. When activating such services, your IP address and usage data may be transferred to third-party providers.
Social media integrations may process data if you are logged in to those platforms. We have no influence on these processes.
8. Hosting
Our website is hosted by an external provider. The hosting provider processes connection data (IP address, server logs) based on a data processing agreement and GDPR compliance.
Vienna, 21 August, 2025