Privacy Policy


Privacy Policy of BOLTENSTERN GmbH
for www.fabnora.com

Effective as of: May 2026


1. Data Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

BOLTENSTERN GmbH
Schliessmanngasse 15
1130 Vienna
Austria

Commercial Court Vienna
FN 430979 v
VAT ID: ATU69498803

E-Mail: marie@boltenstern.com


2. General Information on Data Processing

Protecting your personal data is very important to us. We process your personal data exclusively in accordance with the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act (TKG).

This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data when using our online shop at www.fabnora.com.


3. Collection of Personal Data

We collect personal data when you:

  • visit our website,

  • place an order,

  • create a customer account,

  • subscribe to our newsletter,

  • contact us,

  • use our website technically.

The following data may in particular be processed:

  • Name

  • Billing and shipping address

  • E-mail address

  • Telephone number

  • Payment information

  • Order information

  • IP address

  • Browser and device information

  • Website usage data


4. Purposes and Legal Bases of Processing

We process personal data only to the extent necessary and on the basis of the following legal grounds pursuant to Art. 6 GDPR:

Contract Performance (Art. 6 para. 1 lit. b GDPR)

For:

  • processing orders,

  • payment processing,

  • delivery of products,

  • customer communication,

  • administration of customer accounts.

Legal Obligations (Art. 6 para. 1 lit. c GDPR)

For:

  • compliance with tax and commercial retention obligations,

  • fraud prevention,

  • compliance with legal obligations.

Legitimate Interests (Art. 6 para. 1 lit. f GDPR)

For:

  • technical provision and security of the website,

  • improvement of our services,

  • prevention of misuse and fraud,

  • responding to customer inquiries.

Consent (Art. 6 para. 1 lit. a GDPR)

For:

  • sending newsletters,

  • storing non-essential cookies,

  • voluntary marketing measures.

Any consent granted may be withdrawn at any time with future effect.


5. Customer Account

Customers may create a customer account in order to manage orders more conveniently and facilitate future purchases.

Processing is carried out on the basis of contract performance pursuant to Art. 6 para. 1 lit. b GDPR.

Customers may request deletion of their customer account at any time.


6. Newsletter

If you subscribe to our newsletter, we process your email address in order to send information about our products, collections and offers.

We use Klaviyo Inc., USA, as our newsletter service provider.

Subscription takes place using the double opt-in procedure.

Legal basis:
Art. 6 para. 1 lit. a GDPR.

You may withdraw your consent at any time via the unsubscribe link in the newsletter or by contacting marie@boltenstern.com.


7. Payment Providers

For payment processing, we cooperate with external payment service providers. Depending on the selected payment method, payment data is transmitted directly to the respective provider.

The following providers may in particular be used:

  • Shopify Payments

  • PayPal

  • Klarna

  • Revolut (for USDC/cryptocurrency payments)

Processing is carried out for the performance of the contract pursuant to Art. 6 para. 1 lit. b GDPR.

The respective payment providers are responsible for their own data processing activities and privacy policies.


8. Hosting and Shop System

Our online shop is operated via Shopify Inc.

Shopify processes personal data in connection with the provision and technical administration of the online shop.

Further information:
https://www.shopify.com/legal/privacy

This may involve data transfers to third countries, particularly the United States and Canada. Shopify uses appropriate safeguards pursuant to Art. 46 GDPR, in particular the European Commission’s Standard Contractual Clauses.


9. Cookies and Similar Technologies

Our website uses cookies and similar technologies that are necessary for the operation of the website.

In addition, further cookies for analytics, convenience or marketing purposes may be used subject to your explicit consent.

You may adjust or withdraw your cookie preferences at any time via the cookie banner.


10. Storage Period

We store personal data only for as long as necessary:

  • for contract performance,

  • due to statutory retention obligations,

  • or to safeguard legitimate interests.

Tax and commercial law retention periods may require storage for up to seven years or longer.


11. Disclosure of Personal Data

Personal data is disclosed exclusively:

  • to shipping service providers,

  • payment providers,

  • IT and hosting providers,

  • newsletter service providers,

  • where necessary for contract performance,

  • or where we are legally obliged to do so.

No further disclosure takes place without your explicit consent.


12. International Data Transfers

When using certain service providers, personal data may be transferred to countries outside the European Union.

Where required, such transfers are carried out exclusively on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular Standard Contractual Clauses of the European Commission.


13. Rights of Data Subjects

You have the right at any time to:

  • obtain information about your stored data,

  • request correction of inaccurate data,

  • request deletion of your data,

  • request restriction of processing,

  • receive your data in a portable format,

  • object to processing,

  • withdraw previously granted consent.

To exercise your rights, please contact:
marie@boltenstern.com


14. Right to Lodge a Complaint

If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with the competent supervisory authority.

In Austria:

Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria

https://www.dsb.gv.at


15. Data Security

We implement appropriate technical and organisational security measures to protect personal data against loss, manipulation, unauthorised access or unlawful processing.


16. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy where necessary due to legal, technical or business developments.

The current version published on our website shall apply.

Net Orders Checkout

Item Price Qty Total
Subtotal € 0
Shipping
Total

Shipping Address

Shipping Methods