Privacy Policy
Introduction
VD Aesthetic OG (“VD Aesthetic”, “we”, “us”, “our”) protects your personal data and respects your privacy. This privacy policy explains which data we process when you use our website, for what purposes and on what legal basis – in accordance with the GDPR and applicable Austrian data protection regulations.
This policy applies to the VD Aesthetic OG website and to personal data processed in the course of website use or via linked contact and booking channels.
Controller and Contact
The controller responsible for data processing is VD Aesthetic OG (General Partnership). Registered office/business address: Hoher Markt 4/2/1F, 1010 Vienna, Austria. Commercial register court: Commercial Court of Vienna. Company registration number (FN): 665421k. Business purpose: Beauty – cosmetics.
For data protection inquiries, please contact dorina@vdaesthetic.at or valentina@vdaesthetic.at, or by phone at +43 650 262 6722 or +43 664 515 6268.
Personal data we process
Server and device data (website access): When visiting the website, technical data may be processed (e.g. IP address, date/time, accessed page, referrer URL, browser/OS, device information). This data is required to deliver the website, ensure IT security and perform error analysis.
Cookie and consent data: We store your cookie preference (e.g. consent/rejection, timestamp) so that your selection is respected on subsequent visits.
Contact and booking data via external channels: If you request or book an appointment via linked services (e.g. online booking, WhatsApp), the data you enter there (e.g. name, contact details, appointment request, message) is processed by the respective provider. We may receive the data required for appointment handling and communication.
No user accounts: We do not offer user accounts or logins on the website. We do not carry out automated individual decision-making or profiling for advertising purposes based on website usage.
Purposes and legal bases
We process personal data for the following purposes:
Provision of the website and IT security: Technically necessary processing (e.g. server logs, attack prevention, stability). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and functional operation) and, where applicable, Art. 6(1)(c) GDPR (legal obligations, e.g. evidence/security).
Cookie consent and necessary cookies: Storage of your cookie selection and technical functions. Legal basis: Art. 6(1)(c) GDPR (compliance) and Art. 6(1)(f) GDPR (legitimate interest in user-friendly preference storage). For consent-required cookies: Art. 6(1)(a) GDPR in conjunction with Section 165 TKG 2021 (Austria).
Traffic analysis (only with consent): If you consent via the cookie banner, we process usage data to analyse website traffic and improve the website. Legal basis: Art. 6(1)(a) GDPR (consent). You may withdraw your consent at any time by deleting cookies in your browser and resetting your selection in the banner.
Appointment and contact handling: Communication, appointment scheduling, follow-up questions and organisational handling. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures/contract) and Art. 6(1)(f) GDPR (efficient communication). Any additional information you voluntarily provide is processed within the scope of your request.
Cookies, consent and traffic analysis
A cookie banner appears on your first visit. There you can accept or reject non-essential cookies (e.g. traffic analysis). Without consent, we do not set analytics cookies.
Necessary cookies: These are required for basic functions (e.g. saving your cookie preference).
Traffic analysis (only with consent): If enabled, we collect statistical usage data to optimise content and usability. We do not use this data to profile you for advertising purposes.
You can delete or block cookies at any time via your browser settings. This may restrict website functionality.
Third-party services and external links
We use or link to third-party services that may process personal data under their own responsibility. If you use these services or click external links, their respective privacy policies apply:
Online appointment booking (Treatwell): When following the online booking link, you are redirected to an external booking service. Data entered there (e.g. name, contact details, appointment request) is processed by the provider. We may receive booking information required for appointment handling.
WhatsApp: When booking or contacting us via WhatsApp, WhatsApp processes your communication and metadata. Message content is used to handle your request.
Social media (Instagram, Facebook, YouTube): Our website links to social media profiles. Clicking these links may transmit data to the respective platform operator.
Maps/navigation (e.g. Google Maps link): When accessing map or navigation links, the provider processes technical data (e.g. IP address) to provide the map function.
Web hosting/IT service providers: We use service providers (e.g. hosting, technical support) as processors for operating and maintaining the website. They may have access to technical data (e.g. server logs) within the scope of their services.
We do not sell personal data and do not share it for advertising purposes. Data is only disclosed where necessary for contract performance, where you have consented, where there is a legal obligation, or where there is an overriding legitimate interest.
Google Maps embedding
A map from Google Maps is embedded on the website. When accessing the page containing the map, data (e.g. IP address, technical device/browser data, possibly location data if enabled) is transmitted to Google and processed there.
Further information on Google technologies and partner websites can be found here: Google – Partner Websites.
Data retention
We store personal data only for as long as necessary for the respective purposes:
Server logs: generally retained for a short period to ensure technical operation and to prevent/analyse security incidents; subsequently deleted or anonymised in accordance with the hosting/security concept.
Cookie consent: retained as long as necessary to document and technically implement your selection; details depend on your browser storage and our banner settings.
Appointments and communication: retained as long as necessary for appointment handling, follow-up and documentation; beyond that only in case of statutory retention obligations or for the assertion/defence of legal claims.
Traffic analysis: only with consent and in accordance with the deletion/retention settings of the analytics tool, or until consent is withdrawn (where technically possible).
Your rights under the GDPR
You have the following rights in particular:
Right of access: information about whether and which data we process about you.
Right to rectification: correction of inaccurate or completion of incomplete data.
Right to erasure: deletion where the legal requirements are met (e.g. purpose no longer applies, withdrawal, unlawful processing).
Right to restriction: restriction of processing in certain cases.
Right to data portability: receipt of the data you have provided in a commonly used format (where applicable).
Right to object: objection to processing based on legitimate interests.
Withdrawal of consent: at any time with effect for the future (e.g. analytics cookies).
To exercise your rights, please contact us using the details provided in the section Controller and Contact. We may request appropriate proof of identity.
Right to lodge a complaint: You may lodge a complaint with a supervisory authority. The competent authority in Austria is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, email: dsb@dsb.gv.at.
Data security
We implement appropriate technical and organisational measures to protect data against loss, misuse and unauthorised access (e.g. HTTPS encryption, access restrictions, system updates).
Despite all measures, data transmission over the internet cannot be completely risk-free. We continuously review and improve our security measures.
Changes to this privacy policy
We may update this privacy policy if processes, services used or legal requirements change. The current version is always available on the website.
In the event of significant changes, we will inform you appropriately (e.g. via a notice on the website). The version date stated below is authoritative.
Contact information
VD Aesthetic OG, Hoher Markt 4/2/1F, 1010 Vienna, Austria
Email: dorina@vdaesthetic.at | valentina@vdaesthetic.at
Phone: +43 650 262 6722 | +43 664 515 6268
Further legal information can be found in the Imprint.