The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information on data protection can be found in our privacy policy listed below.
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Information on the Data Controller" in this privacy policy.
How do we collect your data?
Your data is collected partly because you provide it to us. This may, for example, include data that you enter into a contact form.
Other data is collected automatically or with your consent when you visit the website by our IT systems. This is mainly technical data (e.g. internet browser, operating system or time of page request). The collection of this data takes place automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected in order to ensure error-free provision of the website and to protect it against abuse.
What rights do you have regarding your data?
You have the right to obtain information free of charge at any time about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
The data controller responsible for the processing of personal data on this website is:
Erseni LtdThe data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
We operate our website on our own servers, hosted by the following infrastructure provider:
Infrastructure provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland
We have full control over the servers and the data stored on them. The infrastructure provider only supplies the hardware and the network connection.
When you visit our website, information is automatically saved on our servers in server log files, which your browser transmits to us.
Details on the infrastructure provider's privacy policy: https://www.hetzner.com/legal/privacy-policy/
A data processing agreement pursuant to Art. 28 GDPR exists with the infrastructure provider.
The use of the server infrastructure is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in a reliable and secure provision of our website.
Our web server automatically saves information in so-called server log files, which your browser automatically transmits to us. These are:
This data is not merged with other data sources.
Server log files are stored for a maximum of 14 days and then automatically deleted, unless a specific security incident requires longer retention.
The collection of this data is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the technically error-free presentation and optimisation of our website – for this purpose, the server log files must be collected.
Our website exclusively uses technically necessary cookies (in particular a session cookie and a CSRF protection cookie). These cookies are required for the operation of the website and enable basic functions.
The session cookie is automatically deleted when you close your browser. It is used exclusively to maintain your session and does not contain any personal data.
The storage of this cookie is based on Art. 6 (1) (f) GDPR and § 25 (2) (2) TDDDG. We have a legitimate interest in the technically error-free provision of our website.
You can set your browser to inform you about the setting of cookies or to generally reject cookies. If cookies are disabled, the functionality of this website may be limited.
This website uses the web analytics service Matomo, which we host ourselves on our own infrastructure at matomo.erseni.net. No data is passed on to third parties.
We evaluate the use of this website statistically in order to design it according to demand and to improve it continuously.
The analysis is cookieless. No cookies are set and no cross-device recognition takes place. Consent via a cookie banner is therefore not required.
Art. 6 (1) (f) GDPR. Our legitimate interest lies in designing and optimising our offering according to demand.
The anonymised usage data is stored on our Matomo server for as long as it is needed for statistical evaluation. An automatic deletion period is currently not configured.
You can object to the analysis at any time by enabling the Do Not Track setting in your browser or by contacting us at hallo@nadine-nissen.at.
For the delivery of all transactional emails (order confirmations, newsletter confirmations, login mails) we use the SMTP service of our mail provider Strato AG.
Strato AG, Pascalstraße 10, 10587 Berlin, Germany
The use of the mail delivery service is based on our legitimate interest in reliable email delivery (Art. 6 (1) (f) GDPR) and on the performance of a contract for transactional mails (Art. 6 (1) (b) GDPR). Processing takes place entirely within the European Union; no transfer to a third country occurs.
A data processing agreement pursuant to Art. 28 GDPR exists with Strato AG.
For more information on Strato's data processing: https://www.strato.de/datenschutz/
If you send us enquiries via the contact form or by email, your details, including the contact data you provide, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent.
The processing of this data is based on Art. 6 (1) (b) GDPR, insofar as your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of enquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) if this was requested.
The data you have transmitted will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for the data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
A transfer of personal data to third countries outside the European Union only takes place if an adequacy decision of the European Commission exists or if appropriate safeguards under Art. 46 GDPR (in particular EU Standard Contractual Clauses, Binding Corporate Rules) are in place.
Where third-country recipients are certified under the EU-US Data Privacy Framework, transfers to the United States are additionally based on the adequacy decision of the EU Commission of 10 July 2023.
Specific recipients and the corresponding level of protection are listed in the following sections on individual services.
For the processing of purchases (cookbooks, subscriptions) we use the payment service provider Stripe.
Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland
During a purchase the following data is transmitted to Stripe:
Processing is carried out for the performance of a contract (Art. 6 (1) (b) GDPR) and to fulfil statutory retention obligations (Art. 6 (1) (c) GDPR).
Stripe Payments Europe Ltd. (Ireland) is our direct contractual partner. Stripe additionally processes certain data via its parent company Stripe, Inc. (San Francisco, USA). This transfer to a third country takes place on the basis of the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and additionally on the basis of the EU-US Data Privacy Framework, to which Stripe is certified (Art. 45 GDPR).
A data processing agreement pursuant to Art. 28 GDPR exists with Stripe.
On our side we store Stripe IDs and order data for as long as the customer account or subscription exists, but at least for the statutory retention periods (10 years pursuant to § 132 BAO / § 147 AO).
More information on Stripe's data processing: https://stripe.com/de/privacy
When you buy a cookbook or take out a subscription, we create a personal account for you, which you can use to manage your purchased content and your subscription.
Login is passwordless via a magic link that we send you by email. We do not store a password. The magic link is single-use and expires after 24 hours.
Processing is carried out for the performance of a contract (Art. 6 (1) (b) GDPR) and, with respect to the protection of the member area, on the basis of our legitimate interest (Art. 6 (1) (f) GDPR).
Account data is stored as long as your account exists. You may have your account deleted at any time (see section "Your Rights"). Upon account deletion, pseudonymised order data remains for accounting purposes for the statutory retention period (10 years).
Every time you buy a cookbook or take out a subscription, we store the following data in our database:
Processing is carried out for the performance of a contract (Art. 6 (1) (b) GDPR) and to fulfil statutory retention obligations (Art. 6 (1) (c) GDPR).
Order data is subject to statutory tax and commercial retention obligations. We store it for at least 10 years after the end of the contract (§ 132 BAO, § 147 AO, § 14b UStG). After expiry it is automatically deleted. Pseudonymisation takes place upon customer account deletion, where the accounting obligation allows it.
If you subscribe to our newsletter, we collect the following data:
We store the IP address and timestamp in order to be able to prove the consent within the meaning of Art. 7 (1) GDPR (obligation of accountability). After 12 months from confirmation the IP address is anonymised; the fact of the consent itself remains on record.
Registration takes place in a so-called double opt-in procedure. After entering your email address you receive a confirmation email with a link. Only after clicking the link is your address added to the distribution list. If no confirmation takes place within 30 days, your registration data (including IP address) is automatically deleted.
We use your email address exclusively to send the newsletter with texts on travel, culinary topics and hotel portraits. No data is passed on to third parties.
Processing is based on your consent (Art. 6 (1) (a) GDPR). You can revoke this consent at any time by unsubscribing via the unsubscribe link in any newsletter email or by contacting us at hallo@nadine-nissen.at. The legality of the processing carried out until the revocation remains unaffected.
Your data is stored as long as you are subscribed to the newsletter. After unsubscribing we keep the fact of the unsubscription and the consent previously given for a maximum of 12 months in order to be able to prove that the registration was made with consent. After that, all personal data is deleted.
We do not use tracking pixels, counting pixels or personalised tracking links in our newsletters. Open rates and click rates are not collected. Links in the newsletters lead directly to the destination without any individual identifier.
This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Our offering is not specifically targeted at the United Kingdom market. We do not actively promote our content in UK media, do not use GBP pricing and do not address a UK-specific audience. Because some of our content is available in English or offered through international platforms such as Etsy, use by individuals based in the UK is nevertheless possible.
If you have your habitual residence in the United Kingdom, we process your data on the basis of the EU GDPR and, where applicable, the UK GDPR. Your rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent) remain fully preserved and can be exercised via the contact address listed above.
You may additionally lodge a complaint with the competent UK supervisory authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk. As we have not currently appointed a representative in the United Kingdom under Art. 27 UK GDPR, communication is handled directly with us via hallo@nadine-nissen.at. Should the focus of our offering shift towards the United Kingdom, we will appoint a UK representative and update this notice accordingly.
You have the following rights regarding personal data concerning you:
You have the right to obtain information free of charge at any time about the personal data stored about you, its origin and recipients, and the purpose of the data processing.
You have the right to request the correction of inaccurate personal data.
You have the right to request the deletion of your personal data, unless statutory retention obligations conflict with this. Order data is subject to a 10-year retention period (§ 132 BAO / § 147 AO) and is pseudonymised upon account deletion.
You have the right under certain circumstances to request the restriction of the processing of your personal data.
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR. You may also object at any time, without giving reasons, to the processing of your data for direct marketing purposes (in particular newsletter).
Insofar as you have given us consent, you can revoke it at any time with effect for the future. The legality of the processing carried out until the revocation remains unaffected.
Logged-in members can trigger data export, profile editing and account deletion themselves via the member area under "Account". Alternatively, contact us informally by email at hallo@nadine-nissen.at. We will respond to your request within 30 days (Art. 12 (3) GDPR).
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. Particularly competent authorities are:
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.
Interviews, Reportagen und Porträts aus dem Journal, direkt in dein Postfach.