Privacy Policy
Privacy Policy of BOLTENSTERN GmbH
for www.fabnora.com
Effective as of: May 2026
1. Data Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
BOLTENSTERN GmbH
Schliessmanngasse 15
1130 Vienna
Austria
Commercial Court Vienna
FN 430979 v
VAT ID: ATU69498803
E-Mail: marie@boltenstern.com
2. General Information on Data Processing
Protecting your personal data is very important to us. We process your personal data exclusively in accordance with the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act (TKG).
This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data when using our online shop at www.fabnora.com.
3. Collection of Personal Data
We collect personal data when you:
-
visit our website,
-
place an order,
-
create a customer account,
-
subscribe to our newsletter,
-
contact us,
-
use our website technically.
The following data may in particular be processed:
-
Name
-
Billing and shipping address
-
E-mail address
-
Telephone number
-
Payment information
-
Order information
-
IP address
-
Browser and device information
-
Website usage data
4. Purposes and Legal Bases of Processing
We process personal data only to the extent necessary and on the basis of the following legal grounds pursuant to Art. 6 GDPR:
Contract Performance (Art. 6 para. 1 lit. b GDPR)
For:
-
processing orders,
-
payment processing,
-
delivery of products,
-
customer communication,
-
administration of customer accounts.
Legal Obligations (Art. 6 para. 1 lit. c GDPR)
For:
-
compliance with tax and commercial retention obligations,
-
fraud prevention,
-
compliance with legal obligations.
Legitimate Interests (Art. 6 para. 1 lit. f GDPR)
For:
-
technical provision and security of the website,
-
improvement of our services,
-
prevention of misuse and fraud,
-
responding to customer inquiries.
Consent (Art. 6 para. 1 lit. a GDPR)
For:
-
sending newsletters,
-
storing non-essential cookies,
-
voluntary marketing measures.
Any consent granted may be withdrawn at any time with future effect.
5. Customer Account
Customers may create a customer account in order to manage orders more conveniently and facilitate future purchases.
Processing is carried out on the basis of contract performance pursuant to Art. 6 para. 1 lit. b GDPR.
Customers may request deletion of their customer account at any time.
6. Newsletter
If you subscribe to our newsletter, we process your email address in order to send information about our products, collections and offers.
We use Klaviyo Inc., USA, as our newsletter service provider.
Subscription takes place using the double opt-in procedure.
Legal basis:
Art. 6 para. 1 lit. a GDPR.
You may withdraw your consent at any time via the unsubscribe link in the newsletter or by contacting marie@boltenstern.com.
7. Payment Providers
For payment processing, we cooperate with external payment service providers. Depending on the selected payment method, payment data is transmitted directly to the respective provider.
The following providers may in particular be used:
-
Shopify Payments
-
PayPal
-
Klarna
-
Revolut (for USDC/cryptocurrency payments)
Processing is carried out for the performance of the contract pursuant to Art. 6 para. 1 lit. b GDPR.
The respective payment providers are responsible for their own data processing activities and privacy policies.
8. Hosting and Shop System
Our online shop is operated via Shopify Inc.
Shopify processes personal data in connection with the provision and technical administration of the online shop.
Further information:
https://www.shopify.com/legal/privacy
This may involve data transfers to third countries, particularly the United States and Canada. Shopify uses appropriate safeguards pursuant to Art. 46 GDPR, in particular the European Commission’s Standard Contractual Clauses.
9. Cookies and Similar Technologies
Our website uses cookies and similar technologies that are necessary for the operation of the website.
In addition, further cookies for analytics, convenience or marketing purposes may be used subject to your explicit consent.
You may adjust or withdraw your cookie preferences at any time via the cookie banner.
10. Storage Period
We store personal data only for as long as necessary:
-
for contract performance,
-
due to statutory retention obligations,
-
or to safeguard legitimate interests.
Tax and commercial law retention periods may require storage for up to seven years or longer.
11. Disclosure of Personal Data
Personal data is disclosed exclusively:
-
to shipping service providers,
-
payment providers,
-
IT and hosting providers,
-
newsletter service providers,
-
where necessary for contract performance,
-
or where we are legally obliged to do so.
No further disclosure takes place without your explicit consent.
12. International Data Transfers
When using certain service providers, personal data may be transferred to countries outside the European Union.
Where required, such transfers are carried out exclusively on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular Standard Contractual Clauses of the European Commission.
13. Rights of Data Subjects
You have the right at any time to:
-
obtain information about your stored data,
-
request correction of inaccurate data,
-
request deletion of your data,
-
request restriction of processing,
-
receive your data in a portable format,
-
object to processing,
-
withdraw previously granted consent.
To exercise your rights, please contact:
marie@boltenstern.com
14. Right to Lodge a Complaint
If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with the competent supervisory authority.
In Austria:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria
15. Data Security
We implement appropriate technical and organisational security measures to protect personal data against loss, manipulation, unauthorised access or unlawful processing.
16. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy where necessary due to legal, technical or business developments.
The current version published on our website shall apply.