Note:

Below you will first find a brief, simplified overview of our data protection practices.
The full, legally binding version of the Privacy Policy follows below

Summary of the Privacy Policy

We take the protection of your data very seriously. Here is an overview of the key points:

  1. Who is responsible?
    Karl Fröschl Event GmbH, Maria-Pachleitner-Str. 18/15, 8053 Graz, office@froeschlracing.com

  2. What data do we process?

    • Contact details (e.g. name, email address, telephone number)

    • Contract and payment details for orders

    • Usage data (e.g. pages visited, IP address, cookies)

    • Data relating to events (e.g. live timing results)

  3. Why do we process this data?

    • To process orders and contracts

    • To communicate with you

    • For the security and operation of our website

    • For analytics and advertising (only with your consent)

    • For live timing at events

  4. Who receives the data?

    • Technical service providers (e.g. web hosts, payment providers such as PayPal/Stripe)

    • Analytics and marketing services (e.g. Google, Meta)

    • Public authorities, where we are legally obliged to do so

  5. How long do we store the data?

    • Contract and payment data: up to 7–10 years (legal obligations)

    • Usage and marketing data: for as short a period as possible, usually a few months

    • Livetiming data: permanently with our partner Speedhive (no subsequent deletion possible)

  6. Your rights

    • Access, rectification, erasure

    • Restriction of processing or objection to processing

    • Withdrawal of consent

    • Data portability

    • Right to lodge a complaint with the data protection authority

  7. Cookies & Tracking

    • Essential cookies: for the operation of the website

    • Statistical and marketing cookies: only with your consent (which can be withdrawn at any time)

Privacy Policy

Introduction

This privacy policy explains what personal data we process, for what purposes, and to what extent. It applies to all services we provide, our websites, mobile services and external online presences such as social media profiles (hereinafter collectively referred to as the “online offering”). The terms used are to be understood as gender-neutral..

Responsible persons

Karl Fröschl Event GmbH
Inhaber: Karl Fröschl
Maria-Pachleitner-Str. 18/15
8053 Graz
E-Mail: office@froeschlracing.com

Overview of processing operations

The following overview sets out the types of data processed, the purposes of processing and the people affected.

Types of data processed

  • Personal details (e.g. name, address)

  • Content data (e.g. entries in online forms)

  • Contact details (e.g. email address, telephone number)

  • Usage data (e.g. websites visited, interest in content, access times)

  • Location data (e.g. device GPS data)

  • Payment data (e.g. bank details, invoices, payment history)

Categories of people affected

  • Customers

  • Users (e.g. website visitors, users of online services)

Purposes of processing

  • Assessment of creditworthiness (only in the case of relevant contractual relationships)

  • Provision and optimisation of the online service

  • Analysis of website visits and usage patterns (anonymised where possible)

  • Office and organisational processes

  • Cross-device tracking (only for marketing purposes and anonymised where possible)

  • Reach measurement (e.g. access statistics, recognition of returning visitors)

  • Security measures

  • Provision of contractual services and customer service

  • Management and response to enquiries

Automated decisions

  • Bonitätsauskunft (Credit reference elevant enquiries; based on a credit check).

Legal basis for processing

  • Consent (Article 6(1)(a) GDPR): You have given your consent to specific processing activities.

  • Performance of a contract / pre-contractual measures (Art. 6(1)(b) GDPR): Data processing for the performance of contracts or enquiries.

  • Legal obligation (Art. 6(1)(c) GDPR): Processing to comply with legal obligations.

  • Legitimate interests (Art. 6(1)(f) GDPR): Safeguarding legitimate interests, provided that no overriding interests or fundamental rights of the data subject are infringed.
    Note: In addition to the GDPR, national data protection regulations of your country of residence or our country of incorporation may apply. Specific legal bases for certain processing operations are explained separately in the relevant sections.

Security measures

We implement technical and organisational measures to ensure the confidentiality, integrity and availability of your data. These include:

  • Control of physical and electronic access to data

  • Control of data input, access, disclosure, backup and segregation

  • Procedures for exercising data subjects’ rights, data erasure and responding to data breaches

  • Data protection by design and privacy-friendly default settings

SSL encryption (https)
All data transmitted via our website is encrypted using SSL (as indicated by the prefix https:// in your browser’s address bar).

Transfer and disclosure of personal data

Personal data may be disclosed to Service providers, payment institutions or providers of integrated services be transmitted. We enter into data processing agreements (Article 28 of the GDPR) with all recipients.

Data processing in third countries

Subject to your expressed consent or where transfers are required by contract or law, data will only be processed in third countries if:

  • there is an adequate level of data protection,

  • there are binding EU standard contractual clauses,

  • certification is in place, or

  • internal data protection policies are strictly adhered to (Articles 44–49 of the GDPR).

Data processing in third countries

Subject to your expressed consent or where transfers are required by contract or law, data will only be processed in third countries if:

  • there is an adequate level of data protection,

  • there are binding EU standard contractual clauses,

  • certification is in place, or

  • internal data protection policies are strictly adhered to (Articles 44–49 of the GDPR).

Use of cookies

Cookies are small text files or other storage mechanisms that are stored on end devices and read information from them. They are used, for example, to Login status in a user account, to store the contents of your shopping cart, the content you have viewed or the features you have used on our website. Cookies may also be used for various purposes, in particular to ensure functionality, security and user-friendliness, and to compile anonymised analyses of visitor traffic.

Information regarding consent
We use cookies in accordance with the relevant legal requirements. We therefore obtain prior consent from users, unless this is not required by law. In particular, consent is not required if the storage or retrieval of information is strictly necessary in order to provide users with the telemedia service they have expressly requested.
Consent is revocable, is clearly communicated and contains information about the use of cookies.

Legal basis under data protection law
The processing of personal data using cookies takes place either:

  • based on your explicit consent (Article 6(1)(a) of the GDPR), or

  • based on our legitimate interests (e.g. operation, functionality and improvement of the usability of the online service) or to fulfil contractual obligations, where cookies are required.

Purposes of cookies

  • Functionality of the website

  • Safety and comfort

  • Audience measurement, analysis of user behaviour (anonymised where possible)

  • Marketing (only with consent)

How long cookies are stored

  • Temporary cookies (session cookies): are deleted as soon as the user leaves the website and closes the browser.

  • Persistent cookies: remain stored even after the device is turned off, for example to display your login status or preferred content again. Unless otherwise stated, the maximum retention period is two years.

Withdrawal and objection (opt-out)
Depending on the legal basis, you may at any time:

  • withdraw consent, or

  • object to the processing of your data by cookies (opt-out).

Implementation guidelines:

  • Browser settings: e.g. disabling cookies (Please note: the online service may be subject to limited functionality)

  • Marketing tracking: Opt out via services such as: https://optout.aboutads.info

Processing of cookie data on the basis of consent
We use a Cookie Consent Management Procedure, which ensures the following functions:

  • Obtaining and managing user consent

  • Right to cancel at any time

  • Recording of consent to record-keeping in accordance with the GDPR

  • Storage on the server and/or in an opt-in cookie (pseudonymised, with device assignment)

  • Duration of storage: up to two years

  • The following information is also stored: the time of consent, Categories of cookies used and service providers, browser, system and device

Commercial and business services

We process data relating to our contractual and business partners (e.g. customers, prospective customers) in connection with:

  • contractual or similar legal relationships

  • Communication and responding to enquiries

  • Administration and business organisation

Data sharing

  • Data will only be disclosed to third parties where this is necessary for the purposes set out above, to comply with legal obligations or with the consent of the data subjects..

  • Possible recipients: telecommunications service providers, transport and support services, subcontractors, banks, tax and legal advisers, payment service providers or public authorities.

  • Any further processing for marketing purposes will be clearly communicated to the contracting parties.

Data storage and deletion

  • Data is deleted once the statutory retention periods have expired: generally after 4 years, in Kundenkonten bis zu 10 Jahre but up to 10 years for customer accounts for tax or legal reasons.

  • Data from third-party orders is deleted in accordance with the terms of the contract once the order has been completed.

Third-party providers/platforms

Where third-party providers or platforms are used, the terms and conditionsand privacy policies of those providers also apply.

Economic analysis and market research

We analyse data from a business perspective in order to identify market trends, customer preferences and user behaviour. The individuals concerned may include contractual partners, prospective customers, customers and users of the online service. Markttendenzen, Kundenwünsche und Nutzerverhalten zu erkennen. Betroffene Personen können Vertragspartner, Interessenten, Kunden und Nutzer des Onlineangebots sein.

The analyses are for internal use only. Where possible, data is processed in a pseudonymised or anonymised form. Profile information relating to registered users may be taken into account, but will not be disclosed to third parties without consent.

Shop and e-commerce

We process customer data to facilitate the selection, ordering, payment and delivery of products or services. To this end, we engage service providers such as postal, freight or delivery companies where necessary. Payment transactions are processed via banks or payment service providers.

Types of data processed:

  • Personal details (e.g. name, address)

  • Payment details (e.g. bank details, invoices, payment history)

  • Contact details (e.g. email address, telephone number)

  • Contract details (e.g. subject matter of the contract, term, customer category)

  • Usage data (e.g. websites visited, interest in content, access times)

  • Meta/communication data (e.g. device information, IP address)

People affected: Prospective clients, business and contractual partners, customers

Purposes of processing:

  • Provision of contractual services and customer service

  • Management and response to enquiries

  • Office and organisational procedures

  • Security measures

  • Evaluation of the visitor campaign

  • Marketing (interest-based, behaviour-based)

  • Profiling / Creation of user profiles

Legal basis:

  • Performance of a contract and pre-contractual measures (Article 6(1)(b) of the GDPR)

  • Legal obligation (Article 6(1)(c) of the GDPR)

  • Legitimate interests (Article 6(1)(f) of the GDPR)

payment service provider

We use banks and other payment service providers to ensure secure and efficient payment processing.

Data processed: Name, address, bank details, contract details, payment information. This data is processed and stored directly by the payment service providers. We only receive confirmation of payment (whether successful or not).

Disclosures to credit reference agencies are carried out solely for the purposes of identity and credit checks, where required by law.

Services and providers used:

Provision of the online service and web hosting

We use web hosting providers for infrastructure, computing power, storage, database services, security and maintenance services.

Data processed: IP address, data entered on the website, communication data.

Email delivery and hosting

When sending, receiving and storing emails, we process sender and recipient addresses as well as metadata (e.g. involved providers, spam detection). Emails are generally transmitted unencrypted over the internet, end-to-end encryption is only used where explicitly offered.

Collection of access data and log files

Server log files record, among other things: pages accessed, date and time, data volume, browser type and version, operating system, referrer URL and IP address.

Purposes:

  • Security (e.g. protection against DDoS attacks)

  • Server stability and utilisation analysis

Types of data processed: Content data, usage data, meta/communication data

People affected: Users of the online service

Legal basis: Legitimate interests (Article 6(1)(f) of the GDPR)

Getting in touch

When you contact us (e.g. via the contact form, email, telephone or social media), the information provided by the enquirer will be processed to the extent necessary to respond to the enquiry or to carry out the requested actions. verarbeitet, soweit dies zur Beantwortung der Anfrage oder zur Durchführung angefragter Maßnahmen erforderlich ist.

Enquiries are dealt with within the context of contractual or pre-contractual relationships in order to fulfil our obligations, or on the basis of our legitimate interestswhich consist of responding to enquiries efficiently and appropriately.

Types of data processed:

  • Personal details (e.g. name, address)

  • Contact details (e.g. email address, telephone number)

  • Content data (e.g. form entries)

  • Usage data (e.g. websites visited, interest in content, access times)

  • Meta/communication data (e.g. device information, IP address)

People affected: Communication partners, prospective clients
Purposes of processing: Beantwortung von Kontaktanfragen, Kommunikation, Verwaltung von Anfragen
Legal basis: Performance of a contract and pre-contractual measures (Article 6(1)(b) of the GDPR), legitimate interests (Article 6(1)(f) of the GDPR)

Services used: Contact form, email communication, social media channels

Web analytics, monitoring and optimisation

Web analytics (reach measurement) is used to analyse visitor traffic and identify usage patterns, interests and demographic data (e.g. age, gender) in pseudonymous form. This enables us to optimise our online offering, carry out A/B testing and make targeted adjustments.

For these purposes user profiles may be created and cookies or similar technologies may be used. Data includes, for example, content viewed, features used, technical details (browser, device, access times) and, optionally, location data.

IP addresses are processed in a pseudonymised form (IP masking). verarbeitet. Es werden No plain text data, such as email addresses or names, is stored. The software providers cannot identify the users.

Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR) or legitimate interests (Article 6(1), first sentence, point (f) of the GDPR)

Types of data processed: Usage data, metadata/communication data, and, where applicable, location data
People affected: Users of the online service
Purposes of processing: Audience measurement, tracking, campaign performance analysis, profiling
Safety measures: IP-Masking
Service provider: Google Analytics, Google Tag Manager (including data processing agreements and standard contractual clauses)

Onlinemarketing

Personal data is processed for marketing purposes, e.g. for advertisements, user profiles, remarketing, audience targeting and conversion tracking. Data is stored in pseudonymised form; plain text data is only processed if users give their explicit consent or if social networks carry out the linking.

Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR) or legitimate interests (Article 6(1), first sentence, point (f) of the GDPR)

Types of data processed: Usage data, metadata/communication data, location data
People affected: Users, prospective customers
Purposes of processing: Tracking, profiling, remarketing, conversion tracking, reach measurement, cross-device tracking
Safety measures: IP-Masking
Options to opt out:

Service provider: Facebook-Pixel (Meta Platforms Ireland Limited), Google Ad Manager (Google LLC)

Social media presence

We maintain social media profiles to facilitate communication, provide information and carry out marketing activities. User data may be processed outside the EU, which may affect the enforcement of users’ rights.

Data may be used for market research and targeted advertising, for example through the use of cookies and user profiles. We only receive aggregated information; individual user data remains with the provider.

Types of data processed: Inventory data, contact details, content data, usage data, metadata/communication data
People affected: Social media users, website visitors
Purposes of processing: Communication, tracking, remarketing, audience measurement
Legal basis: Legitimate interests (Article 6(1)(f) of the GDPR)

Service provider: Instagram, Facebook Pages (Meta Platforms Ireland Limited, including joint controller agreements and standard contractual clauses)

Plugins, embedded functions and content

We incorporate third-party content and features (e.g. graphics, videos, social media buttons) into our online platform. This content is provided by the third-party providers’ servers. The user’s IP address is required to display the content. Third-party providers may also use pixel tags (web beacons) to analyse visitor behaviour or for marketing purposes.

The pseudonymised data may be stored in cookies and linked to further information from other sources.

Legal basis:

  • Consent (Article 6(1)(a) of the GDPR)

  • Legitimate interests (Article 6(1)(f) of the GDPR)

  • Performance of a contract and pre-contractual enquiries (Article 6(1)(b) of the GDPR)

Types of data processed: Usage data, metadata/communication data, location data, content data, inventory data, contact details
People affected: Users, communication partners
Purposes of processing: Provision of the online service, customer service, contact enquiries, tracking, marketing, profiling, security measures, administration and responding to enquiries

Services used: reCAPTCHA (Google Ireland Limited) – to distinguish between humans and bots in online forms. Data: IP address, device information, browser, mouse and keyboard inputs, cookies, location data.

Deletion of data

Personal data is regularly deletedPersonal data is regularly deleted as soon as consent is withdrawn or other authorisations cease to apply. Data required for legally permissible purposes (e.g. retention for tax or commercial law purposes, legal defence) is blocked and used only for these purposes.

Changes and updates to the privacy policy

We update our privacy policy on a regular basis. Any changes that require action on your part (e.g. consent) will be communicated separately.

Rights of data subjects

Under the GDPR, you have the following rights in particular:

  • Right to object: Objection to processing on the basis of legitimate interests or direct marketing, including profiling.

  • Right to withdraw consent: Consent may be withdrawn at any time.

  • Right of access: Confirmation and information regarding processed data.

  • Right to rectification: Completion or correction of incorrect data.

  • Right to erasure and restriction: Erasure or restriction of the processing of personal data.

  • Right to data portability: Provision of the data in a structured, commonly used format.

  • Right to appeal: Lodging a complaint with the relevant supervisory authority.

Definitions of terms

The terms used in this privacy policy correspond to the definitions set out in Article 4 of the GDPR and are explained here for clarity (e.g. tracking, profiling, cross-device tracking, IP masking, remarketing, audience targeting, live timing)

Live timing at events

During events, lap times are automatically recorded and published via Livetiming. The following information is displayed: start number, name, number of laps completed and best lap time.

The data is stored permanently by the provider Speedhive can be viewed by anyone. It is not currently possible to delete the data at a later date.

If you wish, a username may be displayed instead of your real name; please notify us in writing before the event. schriftlich vor der Veranstaltung angegeben werden.

Shopping Basket