Privacy Policy
Introduction
With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to simply as "data") we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Effective date: 8 September 2026
Controller
Jakob Lehner
Ferihumerstraße 46
4040 Linz
Austria
Email address: jakoblehnerphotography@gmail.com
Phone: +43 699 10328145
Legal notice: /impressum
Overview of processing
The following overview summarizes the types of data processed and the purposes of their processing.
Types of data processed
- Master data (e.g. names, addresses)
- Content data (e.g. entries in online forms)
- Contact details (e.g. email, telephone numbers)
- Meta/communications data (e.g. device information, IP addresses)
- Usage data (e.g. websites visited, interest in content, access times)
- Contract data (e.g. subject matter, duration, customer category)
- Payment data (e.g. bank details, invoices, payment history)
Categories of data subjects
- Employees (e.g. staff, applicants, former employees)
- Business and contractual partners
- Prospective customers
- Communication partners
- Customers
- Users (e.g. website visitors, users of online services)
- Sweepstakes and competition participants
Purposes of processing
- Provision of our online offering and user-friendliness
- Conversion measurement (measuring the effectiveness of marketing activities)
- Office and organizational procedures
- Direct marketing (e.g. by email or post)
- Conducting sweepstakes and competitions
- Audience segmentation
- Marketing
- Contact requests and communication
- Reach measurement (e.g. access statistics, recognition of returning visitors)
- Security measures
- Provision of contractual services and customer service
Applicable legal bases
Below is an overview of the legal bases under the GDPR on which we process personal data:
- Consent (Art. 6(1), first sentence, lit. a GDPR) - The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual requests (Art. 6(1), first sentence, lit. b GDPR) - Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps prior to entering into a contract.
- Legal obligation (Art. 6(1), first sentence, lit. c GDPR) - Processing is necessary for compliance with a legal obligation.
- Legitimate interests (Art. 6(1), first sentence, lit. f GDPR) - Processing is necessary to safeguard the legitimate interests of the controller or a third party.
National data protection regulations in Austria: In addition to the data protection regulations of the General Data Protection Regulation, national data protection regulations apply in Austria. These include, in particular, the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act – DSG).
Security measures
In accordance with legal requirements, taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data. Furthermore, we have established procedures to ensure the exercise of data subjects’ rights, the deletion of data and responses to threats to data security.
Transfer of personal data
In the course of processing personal data, data may be transferred to or disclosed to other bodies, companies, legally independent organizational units or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content embedded in a website.
In such cases, we comply with legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data to protect it.
Deletion of data
Data processed by us is deleted in accordance with legal requirements as soon as the consent permitting its processing is withdrawn or other permissions cease to apply (e.g. if the purpose of processing this data no longer applies or the data is no longer necessary for that purpose).
If the data is not deleted because it is required for other legally permissible purposes, its processing is restricted to those purposes. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
Use of cookies
Cookies are small text files or other stored records that store information on devices and read information from them. For example, they may store the login status in a user account, the contents of a shopping cart in an online shop, content accessed or features used in an online offering.
Information on consent: We use cookies in accordance with legal provisions. We therefore obtain users’ prior consent unless consent is not required by law.
Storage duration: With regard to storage duration, a distinction is made between temporary cookies (session cookies) and permanent cookies. Temporary cookies are deleted at the latest after a user has left an online offering and closed their device. Permanent cookies remain stored even after the device has been closed.
Provision of the online offering and web hosting
To provide our online offering securely and efficiently, we use the services of one or more web hosting providers whose servers (or servers managed by them) make the online offering available.
Data processed in connection with the provision of hosting may include all information relating to users of our online offering that arises in the course of use and communication. This regularly includes the IP address, which is necessary to deliver the contents of online offerings to browsers, and all entries made within our online offering or on websites.
Contact and inquiry management
When you contact us (e.g. via contact form, email, telephone or social media), as well as in the context of existing user and business relationships, the information provided by those making inquiries is processed insofar as this is necessary to respond to contact requests and any requested actions.
Responding to contact requests and managing contact and inquiry data in the context of contractual or pre-contractual relationships is carried out to fulfill our contractual obligations or to respond to (pre-)contractual requests, and otherwise on the basis of our legitimate interests in responding to inquiries and maintaining user or business relationships.
Presence on social networks (social media)
We maintain online presences within social networks and platforms in order to communicate with customers, interested parties and users who are active there and to inform them about our services.
Please note that user data may be processed outside the European Union. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights.
Furthermore, user data is generally processed for market research and advertising purposes. For example, usage profiles can be created from users’ behavior and resulting interests. These profiles can in turn be used, for example, to place advertisements inside and outside the platforms that are presumed to match users’ interests.
Embedded videos (Vimeo)
Videos from the provider Vimeo are embedded on this website. When a page with an embedded video is accessed, a connection to Vimeo servers is established and your IP address is transmitted.
The videos are embedded with Do Not Track mode (dnt=1) enabled. This limits tracking by the Vimeo player. For more information, see the Vimeo privacy policy.
Rights of data subjects
As a data subject, you have various rights under the GDPR:
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed.
- Right to rectification: You have the right to request the correction of inaccurate data concerning you.
- Right to erasure ("right to be forgotten"): You have the right to request the deletion of data concerning you.
- Right to restriction of processing: You have the right to request the restriction of processing.
- Right to data portability: You have the right to receive data concerning you and to have it transferred to others.
- Right to object: You have the right to object at any time to the processing of data concerning you.
- Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority.
Changes and updates to the privacy policy
We ask you to check the contents of our privacy policy regularly. We update the privacy policy whenever changes to the data processing we carry out make this necessary.
Definitions of terms
This section provides an overview of the terms used in this privacy policy. The definitions are primarily based on Art. 4 GDPR.