Privacy Policy

Datenschutzerklärung

In this privacy policy we inform you about the processing of your personal data.

If you want to change your privacy settings (grant consent or revoke your previously granted consent), click here to change your settings.

Responsible

Reinhart Mlineritsch, Dornberggasse 17, A-5020 Salzburg, Österreich, photography@drei.at, +4369910866605

Hosting

Dienst: Drei Webhosting
Anbieter: Hutchison Drei Austria GmbH

Brünner Straße 52, A – 1210 Wien, Wien

Datenschutzerklärung: Link zur Datenschutzerklärung

Web Fonts

Analysis Services

WP Statistics

We use the local analysis software WP-Statistics, WordPress to process your data for the purpose of troubleshooting, failure analysis and statistical analysis and to identify measures for the sophistication of our website.

This service is a local analysis tool so that no personal data are transferred to the service provider or to third parties. Furthermore, your personal data are anonymized immediately after such data were collected. Personal data are therefore not stored beyond initial processing.

The legal basis of processing is the absolute technical necessity to provide and deliver the “website” service which you have explicitly requested according to § 165 (3) Telecommunications Act by visiting the website.

Right to object

You have the right to object to processing if your personal data is processed based on legitimate interests.

We will then cease the processing carried out on this basis, unless there are compelling and legitimate reasons for us to do so.

You have the right to object to the processing of your personal data for the purpose of direct marketing. In this case, we will cease the processing of your personal data for the purpose of direct mail.

The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Withdrawal

You have the right to withdraw your consent at any time by changing the settings at Privacy settings.

If you have given your consent to receipt of advertising by email, you may withdraw your consent by clicking the unsubscribe link. In this case, we will cease the processing operations, unless there is any other legal basis.

The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Right to data subject

You have the right to access to, rectification, erasure and restriction of processing of personal data.

You have also the right to data portability if the processing of your personal data is based on your consent or on a contract concluded with you.

You have also the right to lodge a complaint with the supervisory authority. If you need more information on the supervisory authorities in the European Union, go to here.

Web Application Firewall (NinjaFirewall)

1. Description and Scope of Data Processing
We use the free security software NinjaFirewall on our website. This is a Web Application Firewall (WAF) that is loaded before the actual WordPress installation. The plugin analyzes incoming data traffic (HTTP/HTTPS requests) in real-time before it reaches the web server to detect malicious code and cyberattacks.
To best protect your privacy, we have enabled IP anonymization within the plugin. The IP address of the accessing device is shortened and thereby anonymized (e.g., by masking the last block of digits) before it is saved in any security logs. In addition, the time of the access, the URL called up, and purely technical details of the request (e.g., user-agent) are processed.
 
2. Purpose of Data Processing
The processing of this data is carried out strictly for security purposes. NinjaFirewall detects and blocks known attack patterns (such as SQL injections, cross-site scripting, and malware injections) as well as unauthorized bot access. This protects our system against hacking, data manipulation, and server overload.
 
3. Legal Basis for Data Processing
The data is processed based on our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in maintaining the operational security of our website, defending against cyber risks, and protecting the data processed on our platform from unauthorized access. By anonymizing the IP addresses immediately, the data privacy requirements for data minimization are particularly respected.
 
4. Storage Period and Data Deletion
The analysis of the data takes place in real-time directly on our local server within the European Union. Regular traffic data is not stored permanently. Data regarding blocked or suspicious requests is documented exclusively in an anonymized form in a local security log file and automatically overwritten or deleted after a short period (usually a few days). No personal data is transmitted to the developer of the plugin or any other third parties.

Protection Against Brute-Force Attacks (Limit Login Attempts Reloaded)

1. Description and Scope of Data Processing
We use the security plugin Limit Login Attempts Reloaded on our website. When an attempt is made to log into the administrative area of our website, the plugin collects and stores the following data:
    • The IP address of the accessing device
    • The timestamp of the login attempt
    • The username entered

2. Purpose of Data Processing
The processing of this data is carried out strictly for security purposes. The plugin counts failed login attempts and temporarily blocks the user’s IP address after a specified number of incorrect attempts. This prevents automated attacks (known as brute-force attacks) and unauthorized access to our website’s backend, ensuring the integrity and stability of our online presence.
 
3. Legal Basis for Data Processing
The data is processed based on our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in ensuring IT security, defending against cyberattacks, and maintaining the secure operation of our website.
 
4. Storage Period and Data Deletion
The collected IP addresses are processed locally on our server. IP addresses that do not trigger a block are deleted immediately. IP addresses that have been blocked due to excessive failed attempts are kept only for the duration of the lockout (usually a few hours to days) and are automatically deleted thereafter. No data is shared with third parties.

Website Performance Optimization (WP Fastest Cache)

1. Description and Scope of Data Processing
We use the performance plugin WP Fastest Cache on our website. This plugin optimizes the loading speed of our pages by utilizing “caching”. It converts dynamically generated WordPress content into static HTML files and stores them temporarily on our web server. When the website is accessed again, this data does not need to be recompiled and can be loaded immediately. Furthermore, technical scripts (such as CSS and HTML files) are compressed and optimized. The plugin does not collect or store any personal data from website visitors.
 
2. Purpose of Data Processing
The purpose of utilizing this tool is the technical optimization of our website. Fast loading times significantly improve the user experience for our visitors and lower the resource load on our server infrastructure during periods of high traffic.
 
3. Legal Basis for Data Processing
The plugin is used based on our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in the technically error-free provision, optimization, and stability of our online services.
 
4. Storage Period and Data Deletion
The cached files are stored exclusively on our local web server within the European Union. They do not contain any personal information and are automatically deleted and regenerated whenever the website is updated (e.g., when publishing new content) or after predefined time intervals. No data is shared with third parties.

Object and Database Caching (Redis Cache)

1. Description and Scope of Data Processing
We use Redis (often via a WordPress object cache plugin) on our website to optimize database performance. Redis is an in-memory data structure store that caches frequently requested database queries and objects directly in the server’s RAM. When a user visits our website, data can be retrieved significantly faster because the system does not need to query the main database repeatedly. Redis does not collect, track, or permanently store any personal data of website visitors.
 
2. Purpose of Data Processing
The purpose of using Redis is to improve the loading speed and responsiveness of our website. Efficient database caching reduces server load and ensures a stable, fast user experience even during peak traffic periods.
 
3. Legal Basis for Data Processing
The data processing is based on our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in ensuring the technical optimization, performance, stability, and security of our online services.
 
4. Storage Period and Data Deletion
The cached data is stored exclusively in the volatile memory (RAM) of our local web server or the server environment provided by our hosting company within the European Union. The cache is temporary and is automatically cleared, updated, or overwritten as website content changes. No data is transmitted to third parties.

Local Integration of Google Web Fonts

1. Description and Scope of Data Processing
To ensure a consistent and visually appealing presentation of our website, we use web fonts provided by Google. To protect your privacy, these fonts are hosted locally on our own web server. When you access a page, your browser loads the required fonts directly from our server into your browser cache to display text and fonts correctly. As a result, no connection to Google servers is established, and no data (such as your IP address) is transmitted to Google.
 
2. Purpose of Data Processing
The purpose of hosting these fonts locally is to provide a visually optimal, secure, and privacy-compliant display of our website content across all user devices.
 
3. Legal Basis for Data Processing
The data processing is based on our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in the secure and reliable technical presentation of our website without compromising the data privacy of our visitors.
 
4. Storage Period and Data Deletion
Since the fonts are stored locally on our server and loaded from there by your browser, no personal data or traffic logs are processed or saved by any third-party font provider.