Privacy Policy
Last updated: 7 September 2026
Thank you for your interest in the information on our website!
With this Privacy Policy, we would like to inform all persons who use this website about the nature, scope and purposes of the processing of personal data. In this context, personal data means any information by which you, as a user of our website, can be personally identified (in theory, possibly indirectly or by linking various data), including your IP address. Information stored in cookies is generally not personal data, or only in exceptional cases; however, it is covered by a special rule that makes the permissibility of using cookies—depending on their purpose—largely dependent on the users’ active consent.
In a general section of this Privacy Policy, we provide you with information on data protection that generally applies to our processing of data, including data collection on our website. In particular, you will be informed, as a data subject, about the rights to which you are entitled.
We endeavour to provide this information in gender-neutral language. Where individual wording does not yet reflect this, we note that this information applies to all people of every gender.
The terms used in our Privacy Policy and our data protection practices are based on the provisions of the EU General Data Protection Regulation (“GDPR”) as well as other relevant national legal provisions.
Controller within the meaning of the GDPR
ASTORplast GmbH
Company register number: 70154v
Traunuferstraße 110a
4052 Ansfelden
Austria
E: info@astorplast.at
T: +43 7229 513 34
F: +43 7229 513 34-11
Data collection on our website
Your personal data is collected, on the one hand, when you expressly provide it to us; on the other hand, data—especially technical data—is collected automatically when you visit our website. Some of this data is collected to ensure the website functions without errors. Other data may be used for analysis purposes. In principle, however, you can use our website without having to provide any personal information.
Technologies on our website
Cookies and Local Storage
We use cookies on our website to make our online presence more user-friendly and functional. Some cookies remain stored on your device.
Cookies are small data packets that are exchanged between your browser and the/our web server when you visit our website. They do not cause any damage and serve only to recognise website visitors. Cookies can only store information that is provided by your browser, i.e. information that you have entered into the browser yourself or that is available on the website. Cookies cannot execute code and cannot be used to access your device.
The next time you access our website using the same device, the information stored in cookies may subsequently be sent back either to us (“first-party cookie”) or to a web application of the third-party provider to which the cookie belongs (“third-party cookie”). Based on the stored and returned information, the respective web application recognises that you have already accessed and visited the website using the browser on your device.
Cookies contain the following information:
- Cookie name
- Name of the server from which the cookie originally originates
- Cookie ID number
- A date on which the cookie is automatically deleted
Depending on their purpose and function, we divide cookies into the following categories:
- Technically necessary cookies to ensure the technical operation and basic functions of our website. This type of cookie is used, for example, to retain your settings while you navigate the website; or to ensure that important information is retained throughout the session (e.g. login, shopping cart).
- Statistics cookies to understand how visitors interact with our website by collecting and analysing information only anonymously. This provides us with valuable insights to optimise both the website and our products and services.
- Marketing cookies to carry out targeted advertising activities for users on our website.
- Unclassified cookies are cookies that we are currently trying to classify together with providers of individual cookies.
Depending on the storage period, we also distinguish between session cookies and persistent cookies. Session cookies store information that is used during your current browser session. These cookies are automatically deleted when you close the browser. No information remains on your device. Persistent cookies store information between two visits to the website. Based on this information, you are recognised as a returning visitor on your next visit and the website responds accordingly. The lifespan of a persistent cookie is determined by the provider of the cookie.
The legal basis for the use of technically necessary cookies is our legitimate interest in the technically flawless operation and smooth functionality of our website. Our website cannot function properly without these cookies. The use of statistics and marketing cookies requires your consent. You can withdraw your consent to the use of cookies at any time with effect for the future. Consent is voluntary. If it is not given, there will be no disadvantages. Further information about the cookies we actually use (in particular their purpose and storage period) can be found in this Privacy Policy and in the information about the cookies we use in our cookie banner.
You can also set your internet browser so that the storage of cookies on your device is generally prevented, or so that you are asked each time whether you agree to the setting of cookies. You can delete cookies that have already been set at any time. You can find out how this works in detail in your browser’s help function.
Please note that generally disabling cookies may lead to functional restrictions on our website.
We also use so-called Local Storage functions (also referred to as “local storage”) on our website. In this process, data is stored locally in your browser cache and—unless you clear the cache or it is session storage—can continue to exist and be read even after the browser is closed.
Third parties cannot access the data stored in Local Storage. Where specific plugins or tools use Local Storage functions, this is described in the respective plugin or tool.
If you do not want plugins or tools to use Local Storage functions, you can control this in the settings of your respective browser. Please note that this may result in functional restrictions.
To manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and related consents, we use the consent tool “Real Cookie Banner”. Details on how “Real Cookie Banner” works can be found at https://devowl.io/de/rcb/datenverarbeitung/.
The legal bases for processing personal data in this context are Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the related consents.
Providing the personal data is neither contractually required nor necessary for entering into a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we cannot manage your consents.
External hosting
Category: General processing activity
Purpose: technical provision, operation and delivery of the website
Data types: technical data and usage data
Data subjects: visitors to the online offering
Recipients: hosting service providers and technical infrastructure partners
Technologies: server and network infrastructure
Legal basis: legitimate interest (provision & operation)
Our website is operated by an external hosting provider. When the website is accessed, various technical data is processed that is required for operation, security and delivery of the content. This generally includes information that the browser transmits automatically. The processed data may include:
- IP address
- Date and time of access
- Pages or files accessed
- Amount of data transferred
- Messages about successful or failed retrievals
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing device
The hosting provider processes this data to ensure the technical operation of the website, detect attacks or misuse, remedy disruptions and provide a stable connection. Processing is carried out exclusively on our behalf. The legal basis for processing is our legitimate interest in the secure, reliable and efficient operation of our website.
Contact
Our website offers various ways to contact us, for example via contact forms or provided email addresses. In the course of contacting us, the personal data provided is processed exclusively to handle and respond to the respective enquiry. Processing is carried out insofar as it is necessary to take pre-contractual steps or to perform a contract, or on the basis of legitimate interests, for example to maintain customer relationships or to document processes.
Providing certain data may be necessary in order to process an enquiry in full. Without this information, the enquiry may not be processed, or may only be processed to a limited extent.
Personal data from contact enquiries may also be stored in a customer or prospect database on the basis of legitimate interests in order to optimise communication and support. Use for marketing purposes takes place only if separate consent has been given for this or a legitimate interest exists and there are no overriding interests of the data subject worthy of protection.
Personal data from contact enquiries is stored only for as long as this is necessary to process and handle the enquiry or as long as statutory retention obligations exist. After the enquiry has been finally processed and any statutory periods have expired, the data is deleted or anonymised. As a rule, deletion takes place no later than three years without further contact, provided that no longer statutory or contractual retention obligations apply.
Further information on the handling of personal data can be found in the website’s Privacy Policy.
Server log files
Category: General processing activity
Purpose: technical security, stability and error analysis
Data types: technical connection data and access data
Data subjects: visitors to the online offering
Recipients: hosting providers or technical service providers
Technologies: server logs
Legal basis: legitimate interest (technical operation & security)
When you access our website, so-called server log files are automatically created. These log files contain the following data that the browser transmits automatically:
- IP address
- Date and time of access
- File or page accessed
- Amount of data transferred
- Message about successful retrieval
- Browser type and version used
- Operating system used
- Referrer URL (previously visited page)
- Hostname of the accessing device
This data is processed to ensure the functionality, security and stability of our website, in particular to prevent or trace attacks (e.g. DDoS attacks), for error analysis and for the technical provision of the website. The legal basis for this is legitimate interest in the secure and error-free provision of the website.
The log file data is automatically deleted after a technically customary period—at the latest after 12 weeks—once it is no longer required for the stated purposes. Longer storage may occur in individual cases if data is needed for evidentiary purposes (e.g. to clarify security-relevant incidents). This data is not merged with other data sources.
SSL encryption
For your visit to our website, we use the widely used SSL method (Secure Socket Layer) in conjunction with the highest level of encryption supported by your browser. You can recognise whether an individual page of our website is transmitted in encrypted form by the closed key or padlock symbol in your browser’s status bar. The use of this method is based on our legitimate interest in using appropriate encryption technologies.
We also use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorised access by third parties. Our security measures are continuously improved in line with technological developments and kept up to date with the state of the art.
Webcare
Provider: DataReporter GmbH, Zeileisstraße 6, 4600 Wels, Austria
Purpose: consent management
Category: technically required
Recipients: EU, AT
Processed data: IP address, consent data
Data subjects: users
Technology: JavaScript call, cookies, Swarmcrawler
Legal basis: legitimate interest, consent (Swarmcrawler for evaluating search results)
Website: https://www.datareporter.eu/
Further information: https://www.datareporter.eu/company/info
We use the Webcare tool on our website for consent management. Webcare records and stores the decision of the respective users of our website. Our consent banner ensures that statistical and marketing technologies such as cookies or external tools are only set or started once the user has given explicit consent to their use.
For this purpose, we store information on the extent to which the user has confirmed the use of cookies. The user’s decision can be revoked at any time by accessing the cookie settings and managing the consent declaration. Existing cookies are deleted after consent is withdrawn. A cookie is also set to store the information about the user’s consent status, which is referenced in the cookie details. In addition, when this service is accessed, the IP address of the respective user is transmitted to DataReporter servers. The IP address is neither stored nor linked to any other user data; it is used solely for the correct execution of the service.
With the help of Webcare, our website is regularly examined for technologies relevant under data protection law. This examination is carried out only for those users who have expressly given consent (for statistical or marketing purposes). Users’ search results are evaluated by Webcare in anonymised form and only in relation to technologies, and are used to fulfil our information obligations. To start the Swarmcrawler technology, a request is sent to our servers and, for the purpose of data transmission, the user’s IP address is transmitted. Servers are selected that are geographically close to the respective user’s location. It can be assumed that for users within the EU, a server located within the EU will also be selected. The user’s IP address is not retained and is removed immediately after the end of the communication.
General information on data protection
The following provisions apply in principle not only to data collection on our website, but also generally to other processing of personal data.
Personal data
Personal data is information that can be individually attributed to you. Examples include your address, your name, and your postal address, email address or telephone number. Information such as the number of users who visit a website is not personal data because it does not allow attribution to an individual person.
Legal bases for the processing of personal data
Unless more specific information is provided in this Privacy Policy (e.g. regarding the technologies used), we may process your personal data on the basis of the following legal bases:
- Consent pursuant to Art. 6(1)(a) GDPR – the data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual measures pursuant to Art. 6(1)(b) GDPR – processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation pursuant to Art. 6(1)(c) GDPR – processing is necessary for compliance with a legal obligation.
- Protection of vital interests pursuant to Art. 6(1)(d) GDPR – processing is necessary to protect the vital interests of the data subject or of another natural person.
- Legitimate interests pursuant to Art. 6(1)(f) GDPR – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
Please note that, in addition to the GDPR provisions, national data protection regulations may apply in your and/or our country of residence.
Transfer of personal data
Your personal data will not be transferred to third parties for purposes other than those listed in this Privacy Policy.
We only pass on your personal data to third parties if:
- you have given your explicit consent pursuant to Art. 6(1)(a) GDPR,
- the disclosure is necessary pursuant to Art. 6(1)(f) GDPR to safeguard legitimate interests and to assert, exercise or defend legal claims, and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data,
- there is a legal obligation for the disclosure pursuant to Art. 6(1)(c) GDPR, and this is legally permissible, and/or
- it is necessary pursuant to Art. 6(1)(b) GDPR for the handling of contractual relationships with you.
Cooperation with processors
We carefully select our service providers who process personal data on our behalf. If we commission third parties to process personal data on the basis of a data processing agreement, this is done in accordance with Art. 28 GDPR.
Transfer to third countries
If we process data in a third country, or if this occurs in the context of using third-party services or disclosing or transferring data to other persons or companies, this is done only on the basis of the legal bases for data disclosure presented above.
Subject to explicit consent or contractual necessity, we process—or have data processed—in accordance with Art. 44–49 GDPR only in third countries with a level of data protection recognised as adequate, or on the basis of specific safeguards, such as a contractual obligation through so-called standard contractual clauses of the EU Commission, the existence of certifications, or binding internal data protection rules.
Data transfer to the USA
We would like to expressly point out that on 10 July 2023, the EU Commission adopted an adequacy decision under Art. 45(1) GDPR for the EU–US Data Privacy Framework. Accordingly, organisations/companies (as data importers) in the USA that are registered in a public list as part of the Data Privacy Framework self-certification provide an adequate level of protection for data transfers. Whether the specific service provider is already certified can be found here: https://www.dataprivacyframework.gov/s/participant-search
The Data Privacy Framework constitutes a valid legal basis for the transfer of personal data to the USA. It creates binding safeguards to meet all requirements of the CJEU; for example, access by US intelligence services to EU data is limited to what is necessary and proportionate, and a court has been established to review data protection, to which individuals in the EU also have access.
If a data transfer by us to the USA takes place at all, or if we use a service provider based in the USA, we explicitly refer to this in this Privacy Policy (see in particular the description of the technologies on our website).
It should be noted that, despite significant improvements, the Data Privacy Framework applies only partially and only to data transfers to those data importers in the USA that appear in the public list of certified organisations/companies.
What can the transfer of personal data to the USA mean for you as a user, and what risks exist in this context?
Risks for you as a user, insofar as data importers in the USA are concerned that do not fall under the Data Privacy Framework, include in any case the powers of US intelligence services and the legal situation in the USA, which, in the view of the CJEU, no longer ensures an adequate level of data protection. This includes, among other things, the following points:
- Section 702 of the Foreign Intelligence Surveillance Act (FISA) does not provide for restrictions on intelligence surveillance measures and does not provide guarantees for non-US citizens.
- Presidential Policy Directive 28 (PPD-28) does not provide data subjects with effective legal remedies against measures by US authorities and does not provide limits to ensure proportionate measures.
- the ombudsperson provided for in the Privacy Shield does not have sufficient independence from the executive; it cannot issue binding orders to the intelligence services.
Legally compliant transfer of data to the USA on the basis of the standard contractual clauses for data importers that do not fall under the Data Privacy Framework?
In June 2021, the European Commission adopted new standard contractual clauses (Standard Contractual Clauses, SCC) with Decision 2021/914/EU. These create a new legal basis for data transfers where the level of data protection is not the same as in the EU.
Legally compliant transfer of data to the USA on the basis of consent?
If data is transferred to a service provider based in the USA that does not fall under the Data Privacy Framework and this data transfer is based on explicit consent, we will explicitly inform you of this in this Privacy Policy, in particular in the description of the technologies used on our website.
What measures do we take to ensure that data transfers to the USA are legally compliant?
Where US providers offer the option, we choose to process data on EU servers. This should technically ensure that the data remains within the European Union and that access by US authorities is not possible.
Storage period in general
If no explicit storage period is specified when data is collected (e.g. as part of a consent declaration), we are obliged under Art. 5(1)(e) GDPR to delete personal data as soon as the purpose of its processing no longer applies. In this context, we would like to point out that statutory retention obligations to which we are subject constitute a legitimate purpose for the further processing of the personal data covered by them.
As a rule, we store and retain data in personal form until the end of a business relationship or until the expiry of applicable guarantee, warranty or limitation periods, and beyond that until the conclusion of any legal disputes in which the data is required as evidence, or in any case until the end of the third year after the last contact with a business partner.
Storage period in particular
In the description of individual technologies on our website, you will find specific information on the storage period of data. In our cookie table, you will be informed about the storage period of individual cookies. In addition, you always have the option of asking us directly about the specific storage period of data. To do so, please use the contact details provided in this Privacy Policy.
Rights of data subjects
Data subjects have the right:
- (i) pursuant to Art. 15 GDPR, to request information about your personal data processed by us. In particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, as well as the existence of automated decision-making including profiling and, where applicable, meaningful information about its details;
- (ii) pursuant to Art. 16 GDPR, to request without undue delay the rectification of inaccurate personal data stored by us or the completion of your personal data;
- (iii) pursuant to Art. 17 GDPR, under certain circumstances to request the erasure of your personal data stored by us, unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims;
- (iv) pursuant to Art. 18 GDPR, to request the (temporary) restriction of processing of your personal data insofar as the accuracy of the data is contested by you, the processing is unlawful but you oppose erasure, we no longer need the data but you require it for the establishment, exercise or defence of legal claims, or you have objected to processing pursuant to Art. 21 GDPR;
- (v) pursuant to Art. 20 GDPR, to receive from us the personal data that you have provided to us in a structured, commonly used and machine-readable format, or to request its direct transfer to another controller; however, this covers only those personal data that we process by automated means on the basis of your consent or on the basis of a contract;
- (vi) pursuant to Art. 21 GDPR, if your personal data is processed on the basis of our legitimate interest, to object to the processing of your personal data insofar as there are grounds for doing so arising from your particular situation, or if the objection is directed against direct marketing. In the latter case, you have a general right to object, which we will implement without requiring you to state a particular situation;
- (vii) pursuant to Art. 7(3) GDPR to withdraw your consent once given at any time vis-à-vis us. This means that we may no longer continue the data processing based on this consent in the future. Among other things, you have the option to withdraw your consent to the use of cookies on our website with effect for the future by accessing our Cookie settings;
- (viii) pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority regarding the unlawful processing of your data by us. As a rule, you can contact the supervisory authority of your habitual residence or place of work, or of our company’s registered office.
The competent supervisory authority for ASTORplast GmbH is:
Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna, Austria
Tel.: +43 1 52 152-0, dsb@dsb.gv.at
Exercising data subject rights
You decide how your personal data is used. If you therefore wish to exercise any of the above rights vis-à-vis us, you are welcome to contact us by email at info@astorplast.at, by post, or by telephone.
Please support us in specifying your request by answering questions from our responsible staff member regarding the specific processing of your personal data. If there are justified doubts about your identity, we may request a copy of an ID document.
If you have any questions about data protection, you can reach us at info@astorplast.at or via the other contact details provided in this Privacy Policy.
Ansfelden, 7 September 2026
