Journal Über mich Zusammenarbeit Kontakt
  • Journal
  • Über mich
  • Zusammenarbeit
  • Kontakt
  • Privacy | Nadine Nissen

    Privacy at a Glance

    General Notes

    The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information on data protection can be found in our privacy policy listed below.

    Data Collection on This Website

    Who is responsible for data collection on this website?

    Data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Information on the Data Controller" in this privacy policy.

    How do we collect your data?

    Your data is collected partly because you provide it to us. This may, for example, include data that you enter into a contact form.

    Other data is collected automatically or with your consent when you visit the website by our IT systems. This is mainly technical data (e.g. internet browser, operating system or time of page request). The collection of this data takes place automatically as soon as you enter this website.

    What do we use your data for?

    Some of the data is collected in order to ensure error-free provision of the website and to protect it against abuse.

    What rights do you have regarding your data?

    You have the right to obtain information free of charge at any time about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

    Data Controller

    The data controller responsible for the processing of personal data on this website is:

    Erseni Ltd
    Archiepiskopou Makariou III 59
    6017 Larnaca
    Cyprus
    Phone: +43 664 1031985
    Email: hallo@nadine-nissen.at

    The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

    Hosting

    We operate our website on our own servers, hosted by the following infrastructure provider:

    Hetzner Online GmbH

    Infrastructure provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland

    We have full control over the servers and the data stored on them. The infrastructure provider only supplies the hardware and the network connection.

    When you visit our website, information is automatically saved on our servers in server log files, which your browser transmits to us.

    Details on the infrastructure provider's privacy policy: https://www.hetzner.com/legal/privacy-policy/

    A data processing agreement pursuant to Art. 28 GDPR exists with the infrastructure provider.

    The use of the server infrastructure is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in a reliable and secure provision of our website.

    Server Log Files

    Our web server automatically saves information in so-called server log files, which your browser automatically transmits to us. These are:

    • Browser type and version
    • Operating system used
    • Referrer URL
    • Hostname of the accessing computer
    • Time of the server request
    • IP address (stored for a maximum of 14 days for abuse prevention on the basis of Art. 6 (1) (f) GDPR)

    This data is not merged with other data sources.

    Server log files are stored for a maximum of 14 days and then automatically deleted, unless a specific security incident requires longer retention.

    The collection of this data is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the technically error-free presentation and optimisation of our website – for this purpose, the server log files must be collected.

    Cookies

    Our website exclusively uses technically necessary cookies (in particular a session cookie and a CSRF protection cookie). These cookies are required for the operation of the website and enable basic functions.

    Session Cookie

    The session cookie is automatically deleted when you close your browser. It is used exclusively to maintain your session and does not contain any personal data.

    The storage of this cookie is based on Art. 6 (1) (f) GDPR and § 25 (2) (2) TDDDG. We have a legitimate interest in the technically error-free provision of our website.

    You can set your browser to inform you about the setting of cookies or to generally reject cookies. If cookies are disabled, the functionality of this website may be limited.

    Web Analytics with Matomo

    This website uses the web analytics service Matomo, which we host ourselves on our own infrastructure at matomo.erseni.net. No data is passed on to third parties.

    Purpose

    We evaluate the use of this website statistically in order to design it according to demand and to improve it continuously.

    Processed Data

    • pages visited and the time of the visit
    • the previously visited page, if transmitted
    • browser type, operating system and screen size
    • IP address, which is truncated and thereby anonymised before processing

    Cookies

    The analysis is cookieless. No cookies are set and no cross-device recognition takes place. Consent via a cookie banner is therefore not required.

    Legal Basis

    Art. 6 (1) (f) GDPR. Our legitimate interest lies in designing and optimising our offering according to demand.

    Retention Period

    The anonymised usage data is stored on our Matomo server for as long as it is needed for statistical evaluation. An automatic deletion period is currently not configured.

    Objection

    You can object to the analysis at any time by enabling the Do Not Track setting in your browser or by contacting us at hallo@nadine-nissen.at.

    Email Delivery via Strato

    For the delivery of all transactional emails (order confirmations, newsletter confirmations, login mails) we use the SMTP service of our mail provider Strato AG.

    Provider

    Strato AG, Pascalstraße 10, 10587 Berlin, Germany

    Processed Data

    • Recipient email address
    • Email content
    • Time of delivery
    • Technical metadata (mail headers, delivery status)

    Legal Basis

    The use of the mail delivery service is based on our legitimate interest in reliable email delivery (Art. 6 (1) (f) GDPR) and on the performance of a contract for transactional mails (Art. 6 (1) (b) GDPR). Processing takes place entirely within the European Union; no transfer to a third country occurs.

    Data Processing Agreement

    A data processing agreement pursuant to Art. 28 GDPR exists with Strato AG.

    For more information on Strato's data processing: https://www.strato.de/datenschutz/

    Contact Requests

    If you send us enquiries via the contact form or by email, your details, including the contact data you provide, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent.

    The processing of this data is based on Art. 6 (1) (b) GDPR, insofar as your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of enquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) if this was requested.

    The data you have transmitted will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for the data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.

    Transfers to Third Countries

    A transfer of personal data to third countries outside the European Union only takes place if an adequacy decision of the European Commission exists or if appropriate safeguards under Art. 46 GDPR (in particular EU Standard Contractual Clauses, Binding Corporate Rules) are in place.

    Where third-country recipients are certified under the EU-US Data Privacy Framework, transfers to the United States are additionally based on the adequacy decision of the EU Commission of 10 July 2023.

    Specific recipients and the corresponding level of protection are listed in the following sections on individual services.

    Payment Processing via Stripe

    For the processing of purchases (cookbooks, subscriptions) we use the payment service provider Stripe.

    Provider

    Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland

    Processed Data

    During a purchase the following data is transmitted to Stripe:

    • Email address (if you are signed in, the account email is sent to Stripe so you do not have to enter it again in the payment process)
    • Name, billing address and country (entered directly in the Stripe checkout, not on our side)
    • Payment data (credit card, SEPA, Apple Pay, Google Pay - entered directly in the Stripe checkout, not on our side)
    • Stripe customer ID, Stripe subscription ID, Stripe payment intent ID (used to link payments and subscriptions to your account on our side)
    • Amount, currency, timestamp, Stripe-owned fraud-prevention metadata (e.g. IP address, browser fingerprint - collected directly by Stripe)

    Legal Basis

    Processing is carried out for the performance of a contract (Art. 6 (1) (b) GDPR) and to fulfil statutory retention obligations (Art. 6 (1) (c) GDPR).

    Transfers to Third Countries

    Stripe Payments Europe Ltd. (Ireland) is our direct contractual partner. Stripe additionally processes certain data via its parent company Stripe, Inc. (San Francisco, USA). This transfer to a third country takes place on the basis of the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and additionally on the basis of the EU-US Data Privacy Framework, to which Stripe is certified (Art. 45 GDPR).

    Data Processing Agreement

    A data processing agreement pursuant to Art. 28 GDPR exists with Stripe.

    Retention Period

    On our side we store Stripe IDs and order data for as long as the customer account or subscription exists, but at least for the statutory retention periods (10 years pursuant to § 132 BAO / § 147 AO).

    More information on Stripe's data processing: https://stripe.com/de/privacy

    Member Area and Login

    When you buy a cookbook or take out a subscription, we create a personal account for you, which you can use to manage your purchased content and your subscription.

    Stored Data

    • Email address (login)
    • Account status (active, signed out, deleted)
    • Role and permissions
    • Time of account creation and last login
    • Link to your Stripe customer ID (for billing and subscription management)
    • List of cookbooks you have purchased (in your personal library)

    Passwordless Login

    Login is passwordless via a magic link that we send you by email. We do not store a password. The magic link is single-use and expires after 24 hours.

    Legal Basis

    Processing is carried out for the performance of a contract (Art. 6 (1) (b) GDPR) and, with respect to the protection of the member area, on the basis of our legitimate interest (Art. 6 (1) (f) GDPR).

    Retention Period

    Account data is stored as long as your account exists. You may have your account deleted at any time (see section "Your Rights"). Upon account deletion, pseudonymised order data remains for accounting purposes for the statutory retention period (10 years).

    Purchases and Subscription

    Every time you buy a cookbook or take out a subscription, we store the following data in our database:

    • Link to your account
    • Cookbook purchased or subscription concluded
    • Price paid
    • Status (paid, pending, refunded, cancelled)
    • Timestamps of the order, payment and any refund
    • Stripe checkout session ID, Stripe payment intent ID and Stripe subscription ID

    Legal Basis

    Processing is carried out for the performance of a contract (Art. 6 (1) (b) GDPR) and to fulfil statutory retention obligations (Art. 6 (1) (c) GDPR).

    Retention Period

    Order data is subject to statutory tax and commercial retention obligations. We store it for at least 10 years after the end of the contract (§ 132 BAO, § 147 AO, § 14b UStG). After expiry it is automatically deleted. Pseudonymisation takes place upon customer account deletion, where the accounting obligation allows it.

    Newsletter

    If you subscribe to our newsletter, we collect the following data:

    • Email address (required)
    • Time of registration and of confirmation
    • IP address at the time of registration (stored to prove consent)

    We store the IP address and timestamp in order to be able to prove the consent within the meaning of Art. 7 (1) GDPR (obligation of accountability). After 12 months from confirmation the IP address is anonymised; the fact of the consent itself remains on record.

    Double Opt-In

    Registration takes place in a so-called double opt-in procedure. After entering your email address you receive a confirmation email with a link. Only after clicking the link is your address added to the distribution list. If no confirmation takes place within 30 days, your registration data (including IP address) is automatically deleted.

    Purpose

    We use your email address exclusively to send the newsletter with texts on travel, culinary topics and hotel portraits. No data is passed on to third parties.

    Legal Basis and Revocation

    Processing is based on your consent (Art. 6 (1) (a) GDPR). You can revoke this consent at any time by unsubscribing via the unsubscribe link in any newsletter email or by contacting us at hallo@nadine-nissen.at. The legality of the processing carried out until the revocation remains unaffected.

    Retention Period

    Your data is stored as long as you are subscribed to the newsletter. After unsubscribing we keep the fact of the unsubscription and the consent previously given for a maximum of 12 months in order to be able to prove that the registration was made with consent. After that, all personal data is deleted.

    No Tracking

    We do not use tracking pixels, counting pixels or personalised tracking links in our newsletters. Open rates and click rates are not collected. Links in the newsletters lead directly to the destination without any individual identifier.

    SSL/TLS Encryption

    This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

    If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

    Information for Users in the United Kingdom

    Our offering is not specifically targeted at the United Kingdom market. We do not actively promote our content in UK media, do not use GBP pricing and do not address a UK-specific audience. Because some of our content is available in English or offered through international platforms such as Etsy, use by individuals based in the UK is nevertheless possible.

    If you have your habitual residence in the United Kingdom, we process your data on the basis of the EU GDPR and, where applicable, the UK GDPR. Your rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent) remain fully preserved and can be exercised via the contact address listed above.

    You may additionally lodge a complaint with the competent UK supervisory authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk. As we have not currently appointed a representative in the United Kingdom under Art. 27 UK GDPR, communication is handled directly with us via hallo@nadine-nissen.at. Should the focus of our offering shift towards the United Kingdom, we will appoint a UK representative and update this notice accordingly.

    Your Rights

    You have the following rights regarding personal data concerning you:

    Right of Access (Art. 15 GDPR)

    You have the right to obtain information free of charge at any time about the personal data stored about you, its origin and recipients, and the purpose of the data processing.

    Right to Rectification (Art. 16 GDPR)

    You have the right to request the correction of inaccurate personal data.

    Right to Erasure (Art. 17 GDPR)

    You have the right to request the deletion of your personal data, unless statutory retention obligations conflict with this. Order data is subject to a 10-year retention period (§ 132 BAO / § 147 AO) and is pseudonymised upon account deletion.

    Right to Restriction of Processing (Art. 18 GDPR)

    You have the right under certain circumstances to request the restriction of the processing of your personal data.

    Right to Data Portability (Art. 20 GDPR)

    You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.

    Right to Object (Art. 21 GDPR)

    You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR. You may also object at any time, without giving reasons, to the processing of your data for direct marketing purposes (in particular newsletter).

    Revocation of Granted Consents (Art. 7 (3) GDPR)

    Insofar as you have given us consent, you can revoke it at any time with effect for the future. The legality of the processing carried out until the revocation remains unaffected.

    How to Exercise Your Rights

    Logged-in members can trigger data export, profile editing and account deletion themselves via the member area under "Account". Alternatively, contact us informally by email at hallo@nadine-nissen.at. We will respond to your request within 30 days (Art. 12 (3) GDPR).

    Right to Lodge a Complaint (Art. 77 GDPR)

    You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. Particularly competent authorities are:

    • Austria (residence): Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at
    • Germany (residence): the data protection authority of your federal state
    • Cyprus (seat of the controller): Office of the Commissioner for Personal Data Protection, 1 Iasonos Street, 1082 Nicosia, commissioner@dataprotection.gov.cy

    Automated Decision-Making

    Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.

    Neue Texte direkt erhalten

    Interviews, Reportagen und Porträts aus dem Journal, direkt in dein Postfach.

    Ja, ich möchte regelmäßig den Newsletter Texte von Nadine mit Reise- und Kulinarik-Texten per E-Mail erhalten. Den Widerruf finde ich in jeder Mail. Hinweise zum Datenschutz unter Datenschutz.
    Anmelden
    Cookbooks | Newsletter | Media Kit | Imprint | Privacy | Terms Nadine Nissen · Journal für Kulinarik, Reisen und Gastlichkeit