data protection
Reliability begins when things are clearly defined.
1. Scope
The protection of your personal data is important to us. This privacy notice explains the nature, scope, and purpose of the processing of personal data by Unfolding Human (e) Potential Eva Gold GmbH, FN 659228, Kirchberggasse 10/2nd floor/13, 1070 Vienna (hereinafter "we" or "Eva Gold").
2. Responsible party
The following entity is responsible for processing the personal data described below:
Unfolding Human (e) Potential Eva Gold GmbH
Attn: Ms. Eva Gold
Kirchberggasse 10/2nd floor/13
1070 Vienna
Austria
3. Purposes of data processing
Eva Gold processes and uses your personal data for the following purposes:
Contract fulfillment
Personal data provided by you in the context of concluding a contract is used for processing or is necessary and required for the conclusion of a contractual relationship and is therefore processed on the basis of legal authorizations in fulfillment of the contract.
Processing your personal data for marketing purposes (in particular, sending information for advertising purposes by fax, letter, email, or text message).
Newsletter Personal data provided by you when registering for the Eva Gold newsletter will be used exclusively for sending the newsletter by email, unless you give us your separate consent for further use.
4. Website, member area
In connection with the website www.eva-gold.com operated by Eva Gold, personal data is processed for the following purposes:
- To make our website available to you and to further improve and develop it;
- To be able to generate usage statistics;
- Detect, prevent, and investigate attacks on our website;
- to respond to your inquiries;
- provide a members' area;
During your visit to the website, the following data and information will be collected:
- Date and time of access to a page on our site
- Your IP address, name, and version of your web browser;
- the website (URL) you visited before accessing our website;
- Cookies;
During your visit to the member area, the following data and information will be collected:
- First name, last name;
- Email address;
- Display name and password;
5. Online store
If you would like to use your online customer account for the first time, you must register by providing your contact details:
- First name, last name;
- Email address;
- Display name and password;
The following data processing is required to process a purchase contract via our online store:
- First name, last name, display name;
- Billing and delivery address;
- Email address;
- Phone number (optional);
- Ordering information (optional);
- Invoice and payment data;
You can change your data via your online customer account or in writing at organisation@eva-gold.com after providing sufficient identification.
This data processing is based on Art. 6 (1) (b) GDPR and serves the purpose of contract performance.
When you use your online customer account, we store the data necessary for fulfilling the contract, including payment method details. We also store the voluntary data you provide for the duration of your use of the online customer account, unless you delete it beforehand. All information can be changed at any time in the password-protected customer area or under our contact details.
The legal basis for this is Article 6(1)(b) GDPR, i.e., you provide us with the data on the basis of the respective contractual relationship (e.g., management of your online customer account, processing of a purchase contract) between you and us. In order to process your email address in the event of a purchase via our websites/applications, we are also obliged by legal requirements in the Austrian General Civil Code (ABGB) to send an electronic order confirmation ("confirmation of receipt") (Article 6(1)(c) GDPR).
Insofar as we do not use your data for advertising purposes (see 3.3.), we store the data collected for contract processing until the expiry of the statutory or possible contractual warranty and guarantee rights. After this period has expired, we will retain the information required by commercial and tax law relating to the contractual relationship for the periods specified by law. During this period, the data will only be processed again in the event of an audit by the tax authorities.
6. Use of cookies
We use cookies on our website and web shop to make our offering more user-friendly, effective, and secure. A cookie is a small text file that we transfer via our web server to the cookie file of your browser on your computer's hard drive. This enables our website to recognize you as a user when a connection is established between our web server and your browser. Cookies help us to determine the frequency of use and the number of users of our website. The content of the cookies we use is limited to an identification number that no longer allows any personal reference to the user. The main purpose of a cookie is to recognize visitors to the website.
Two types of cookies are used:
Session cookies: These are temporary cookies that remain in your browser's cookie file until you leave our website and are automatically deleted at the end of your visit.
Persistent cookies: For better user-friendliness, cookies remain stored on your device and allow us to recognize your browser the next time you visit.
Cookies that are necessary for the electronic communication process or to provide certain functions you have requested (e.g., shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. If other cookies (e.g., cookies for analyzing your surfing behavior) are stored, these are treated separately in these cookie settings.
You can view or adjust your cookie settings at any time at www.eva-gold.com/datenschutz.
Note: Disabling cookies may limit the functionality of this website.
7. Payment service providers
During payment processing, the service provider may forward your data to a credit agency to check your credit rating. Please refer to the general terms and conditions and privacy policy of the respective payment service provider (https://stripe.com/at/privacy).
The following data is collected by the payment service provider Stripe, LLC:
The payment service provider Stripe is used to process payments.
- Name of the cardholder;
- Email address;
- Customer number;
- Order number;
- Bank details;
- Credit card details;
- Credit card validity period;
- Credit card verification code (CVC);
8. Analysis tools and third-party tools
When you visit this website, your surfing behavior may be statistically evaluated. This is primarily done using so-called analysis programs.
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or statistics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It is used solely for the management and display of the tools integrated through it. However, Google Tag Manager does collect your IP address, which may also be transferred to Google's parent company in the United States.
The use of Google Tag Manager is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the quick and uncomplicated integration and management of various tools on its website. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables website operators to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, length of stay, operating systems used, and the origin of the user. This data is summarized in a user ID and assigned to the respective end device of the website visitor.
Furthermore, we can use Google Analytics to record your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modeling approaches to supplement the collected data sets and employs machine learning technologies in data analysis.
Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there.
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.
Browser plugin
You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
For more information on how Google Analytics handles user data, please refer to Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Google Signals
We use Google Signals. When you visit our website, Google Analytics collects information such as your location, search history, YouTube history, and demographic data (visitor data). This data can be used for personalized advertising with the help of Google Signals. If you have a Google account, Google Signal links the visitor data to your Google account and uses it for personalized advertising messages. The data is also used to create anonymous statistics on the user behavior of our users.
Google Analytics e-commerce measurement
This website uses the "e-commerce measurement" function of Google Analytics. With the help of e-commerce measurement, the website operator can analyze the purchasing behavior of website visitors in order to improve their online marketing campaigns. This involves collecting information such as orders placed, average order values, shipping costs, and the time from viewing to purchasing a product. This data can be summarized by Google under a transaction ID that is assigned to the respective user or their device.
Hotjar
This website uses Hotjar. The provider is Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe (website: https://www.hotjar.com).
Hotjar is a tool for analyzing your user behavior on this website. With Hotjar, we can record your mouse and scroll movements and clicks, among other things. Hotjar can also determine how long you have remained with the mouse pointer on a specific spot. Hotjar uses this information to create so-called heat maps, which can be used to determine which areas of the website are preferred by website visitors.
Furthermore, we can determine how long you stayed on a page and when you left it. We can also determine at which point you canceled your entries in a contact form (so-called conversion funnels).
In addition, Hotjar can be used to obtain direct feedback from website visitors. This function serves to improve the website operator's web offerings.
Hotjar uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting).
If consent has been obtained, the use of the service is based exclusively on Art. 6 (1) (a) GDPR and § 25 TTDSG. Consent can be revoked at any time. If consent has not been obtained, the use of this service is based on Art. 6 (1) lit. f GDPR; the website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.
Deactivating Hotjar
If you would like to deactivate data collection by Hotjar, click on the following link and follow the instructions there: https://www.hotjar.com/policies/do-not-track/
Please note that Hotjar must be deactivated separately for each browser and each device. For more information about Hotjar and the data it collects, please refer to Hotjar's privacy policy at the following link: https://www.hotjar.com/privacy
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program from Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites when the user enters specific search terms in Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on user data available to Google (e.g., location data and interests) (target group targeting). As website operators, we can evaluate this data quantitatively, for example by analyzing which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs/.
Google Ads Remarketing
This website uses the functions of Google Ads Remarketing. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With Google Ads Remarketing, we can assign people who interact with our online offering to specific target groups in order to then display interest-based advertising to them in the Google advertising network (remarketing or retargeting).
Furthermore, the advertising target groups created with Google Ads Remarketing can be linked to Google's cross-device functions. This allows interest-based, personalized advertising messages that have been tailored to you based on your previous usage and browsing behavior on one device (e.g., cell phone) to also be displayed on another of your devices (e.g., tablet or PC).
If you have a Google account, you can opt out of personalized advertising at the following link: https://www.google.com/settings/ads/onweb/.
Use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Consent can be revoked at any time.
Further information and the privacy policy can be found in Google's privacy policy at: https://policies.google.com/technologies/ads?hl=de.
Target group formation with customer matching
We use Google Ads Remarketing customer matching, among other things, to form target groups. In doing so, we transfer certain customer data (e.g., email addresses) from our customer lists to Google. If the customers in question are Google users and are logged into their Google account, they will be shown relevant advertising messages within the Google network (e.g., on YouTube, Gmail, or in the search engine).
Google Conversion Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google Conversion Tracking, Google and we can recognize whether the user has performed certain actions. For example, we can evaluate which buttons on our website are clicked how often and which products are viewed or purchased particularly frequently. This information is used to create conversion statistics. We learn the total number of users who clicked on our ads and what actions they took. We do not receive any information that allows us to personally identify the user. Google itself uses cookies or similar recognition technologies for identification.
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Consent can be revoked at any time.
For more information about Google Conversion Tracking, please refer to Google's privacy policy: https://policies.google.com/privacy?hl=de.
Meta Pixel (formerly Facebook Pixel)
This website uses Facebook/Meta visitor action pixels to measure conversions. This service is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the data collected is also transferred to the US and other third countries.
This allows the behavior of website visitors to be tracked after they have been redirected to the provider's website by clicking on a Facebook advertisement. This allows the effectiveness of Facebook advertisements to be evaluated for statistical and market research purposes and future advertising measures to be optimized.
The data collected is anonymous to us as the operator of this website; we cannot draw any conclusions about the identity of users. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with the Facebook Data Use Policy (https://de-de.facebook.com/about/privacy/). This enables Facebook to place advertisements on Facebook pages and outside of Facebook. As the website operator, we have no influence on this use of the data.
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Consent can be revoked at any time.
We use the enhanced matching function within Meta Pixel.
Enhanced matching allows us to transfer various types of data (e.g., place of residence, state, postal code, hashed email addresses, names, gender, date of birth, or telephone number) about our customers and prospects that we collect via our website to Meta (Facebook). By activating this feature, we can tailor our advertising campaigns on Facebook even more precisely to people who are interested in our offers. In addition, advanced matching improves the attribution of website conversions and expands custom audiences.
Insofar as personal data is collected on our website using the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of data and its transfer to Facebook. The processing by Facebook after the transfer is not part of the joint responsibility. The obligations incumbent upon us jointly have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for the secure implementation of the tool on our website in accordance with data protection laws. Facebook is responsible for the data security of Facebook products. You can assert your rights as a data subject (e.g., requests for information) regarding the data processed by Facebook directly with Facebook. If you assert your rights as a data subject with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
You can find further information on protecting your privacy in Facebook's privacy policy: https://de-de.facebook.com/about/privacy/.
You can also disable the "Custom Audiences" remarketing feature in the ad settings section at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this, you must be logged in to Facebook.
If you do not have a Facebook account, you can disable usage-based advertising from Facebook on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.
Facebook Conversion API
We have integrated Facebook Conversion API into this website. This service is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the data collected is also transferred to the USA and other third countries. Facebook Conversion API enables us to track website visitors' interactions with our website and pass this information on to Facebook in order to improve advertising performance on Facebook.
In particular, the time of the visit, the website visited, your IP address and user agent, and, if applicable, other specific data (e.g., products purchased, shopping cart value, and currency) are recorded. A complete overview of the data that can be collected can be found here: https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Consent can be revoked at any time.
Insofar as personal data is collected on our website using the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Article 26 GDPR). Joint responsibility is limited exclusively to the collection of data and its transfer to Facebook. The processing by Facebook after the transfer is not part of the joint responsibility. The obligations incumbent upon us jointly have been set out in a joint processing agreement. The wording of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for the secure implementation of the tool on our website in accordance with data protection laws. Facebook is responsible for the data security of Facebook products. You can assert your rights as a data subject (e.g., requests for information) regarding the data processed by Facebook directly with Facebook. If you assert your rights as a data subject with us, we are obliged to forward them to Facebook. The transfer of data to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
You can find further information on the protection of your privacy in Facebook's privacy policy: https://de-de.facebook.com/about/privacy/.
Facebook Custom Audiences
We use Facebook Custom Audiences. This service is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
When you visit or use our websites and apps, take advantage of our free or paid offers, transmit data to us, or interact with our company's Facebook content, we collect your personal data. If you give us your consent to use Facebook Custom Audiences, we will transmit this data to Facebook, which Facebook can then use to display relevant advertising to you. Furthermore, your data can be used to define target groups (lookalike audiences). Facebook processes this data as our processor. Details can be found in Facebook's terms of use: https://www.facebook.com/legal/terms/customaudience.
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here: https://www.facebook.com/legal/terms/customaudience and https://www.facebook.com/legal/terms/dataprocessing.
9. Video conferencing
Audio and video conferences
We use online conference tools, among other things, to communicate with our customers. The specific tools we use are listed below. If you communicate with us via video or audio conference over the Internet, your personal data will be collected and processed by us and the provider of the respective conference tool.
The conference tools collect all data that you provide/use to use the tools (email address and/or your phone number). The conference tools also process the duration of the conference, the start and end (time) of participation in the conference, the number of participants, and other "context information" related to the communication process (metadata).
Furthermore, the provider of the tool processes all technical data necessary for handling online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.
If content is exchanged, uploaded, or otherwise made available within the tool, it will also be stored on the tool provider's servers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared while using the service.
Please note that we do not have full control over the data processing operations of the tools used. Our options are largely determined by the corporate policy of the respective provider. For further information on data processing by the conference tools, please refer to the privacy policies of the respective tools, which we have listed below this text.
Purpose and legal basis
The conference tools are used to communicate with prospective or existing contractual partners or to offer certain services to our customers (Art. 6 (1) (b) GDPR). Furthermore, the use of the tools serves to generally simplify and accelerate communication with us or our company (legitimate interest within the meaning of Art. 6 (1) (f) GDPR). If consent has been requested, the use of the relevant tools is based on this consent; consent can be revoked at any time with effect for the future.
Storage period
The data collected directly by us via the video and conference tools will be deleted from our systems as soon as you request us to delete it, revoke your consent to its storage, or the purpose for data storage no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal retention periods remain unaffected.
We have no influence on the storage period of your data, which is stored by the operators of the conference tools for their own purposes. For details, please contact the operators of the conference tools directly.
Conference tools used
We use the following conference tools:
Zoom
We use Zoom. This service is provided by Zoom Communications Inc., San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. Details on data processing can be found in Zoom's privacy policy: https://zoom.us/de-de/privacy.html.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://zoom.us/de-de/privacy.html.
Microsoft Teams
We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please refer to the Microsoft Teams privacy policy: https://privacy.microsoft.com/de-de/privacystatement.
10. Vimeo
This website uses plugins from the video portal Vimeo. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.
When you visit one of our pages equipped with a Vimeo video, a connection to the Vimeo servers is established. This tells the Vimeo server which of our pages you have visited. Vimeo also obtains your IP address. This also applies if you are not logged in to Vimeo or do not have a Vimeo account. The information collected by Vimeo is transmitted to the Vimeo server in the USA.
If you are logged into your Vimeo account, you enable Vimeo to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your Vimeo account.
Vimeo uses cookies or similar recognition technologies (e.g., device fingerprinting) to recognize website visitors.
Vimeo is used in the interest of an appealing presentation of our online offerings. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission and, according to Vimeo, on "legitimate business interests." Details can be found here: https://vimeo.com/privacy.
Further information on the handling of user data can be found in Vimeo's privacy policy at: https://vimeo.com/privacy.
11. Hosting
We host the content of our website with the following provider:
Hetzner
The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (hereinafter referred to as Hetzner). For details, please refer to Hetzner's privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz.
The use of Hetzner is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in ensuring that our website is as reliable as possible. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
order processing We have concluded an order processing agreement (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed in accordance with our instructions and in compliance with the GDPR.
12. Legal basis
Eva Gold processes personal data for the fulfillment of a contract or pre-contractual measures, or on the basis of legal obligations or with your prior consent. By giving your consent, you confirm that you are at least 16 years of age or that you have the consent of your legal representative.
13. Duration of storage
We will delete your data after termination and processing of your contract or after expiry of the statutory warranty, guarantee, limitation, and statutory retention periods, unless you give us separate consent for further processing and use of this personal data.
14. Disclosure
We will not disclose your data to third parties without your express consent, a legal basis, or if it is necessary for the fulfillment of contractual relationships.
15. Your rights
You have the right to: a) check whether and what personal data we have stored about you and to receive copies of this data; b) request the correction, supplementation, or deletion of your personal data; c) restrict processing; d) object to the processing of your personal data under certain circumstances or revoke your previously given consent to processing; e) request data portability, f) know the identity of third parties to whom data is transferred, and f) lodge a complaint with the data protection authority.
16. Contact
If you have any questions or comments about data protection or our website, or if you would like information about the personal data we have stored about you, please contact us at
If you discover that the personal data stored about you is incorrect, we will correct your data as soon as possible upon notification.