Privacy Policy

PRIVACY POLICY (ART 13 DSGVO)

The protection of your personal data is of high value to us. In this privacy policy we inform you how we process personal data on our website (www.wienerphilharmoniker.at), our online shop and our social media channels. When processing your personal data, we always comply with all applicable legal regulations, in particular the EU Data Protection Regulation ("GDPR"), the Austrian Data Protection Act ("DSG") and the Austria Telecommunications Act 2003 ("TKG") in the respective current version.

1. CONTROLLER AND CONTACT

Controller for the processing of your personal data is:

          Wiener Philharmoniker (Association - Verein)
          Kärntner Ring 12, A-1010 Vienna
          +43 1 505 6525
          info@wienerphilharmoniker.at

No data protection officer has been designated as there is no legal requirement.

2. PURPOSES OF PROCESSING AND LEGAL GROUNDS

2.1 Provision of our website and website security

We process personal data to offer our goods and services on our website. When accessing our website your browser automatically transmits your IP-Address, as well as other information about your system (e.g. your operating system, browser version, date and time of the visit, URL, Referrer-URL or referring site). This data is necessary to deliver the contents of our website to your device and to ensure that they are displayed correctly. This connection data is monitored by our server with automatic protocols (logs) to prevent malicious access or other attacks.

We process this data based on our legitimate interests to provide and secure our website services (Art 6 (1) lit f GDPR).

Our webhosting is operated by: Amazon Web Services. Additionally, we use the service Sentry for error analysis.

2.2 Communication and contact forms (including requests for school events)

You can contact us using the available contact forms or by contacting us directly via mail. We will process the data you provided to answer your requests (name, email, topic, message content) and provide our services (Art 6 (1) lit b GDPR). Some fields in our contact forms may be marked as mandatory fields. You are not obliged to provide this data. However, without this information we may not be able to process your request or provide our services.

2.3 Account and user profile

To use our online shop or to subscribe to our newsletters you need a user account. We process the data provided by you (title and form of address, name, email, password, address, phone number) to provide you our services and to contact you for further inquiries also by telephone (Art 6 (1) lit b GDPR).

2.4 Online shop & ticket sales

When using our online shop, we process the data provided by you (name, contact data, address, bank and invoice details) to fulfill our (pre-)contractual obligations with you (Art 6 (1) lit b GDPR). Invoice data is stored for at least seven years due to legal obligations. You may view your order history in your user profile.

Some fields in our contact forms may be marked as mandatory fields. You are not obliged to provide this data. However, without this information we may not be able to process your request or provide our services.

For the performance of our contractual obligations with you, your personal data may be transmitted to third parties (payment services: Qenta PaymentWirecard, SIX Payment; shipping: Gramola; ticket system: JetTicket).

2.5 Google ReCaptcha

This website uses ReCAPTCHA to prevent spam and abuse through automated requests. ReCAPTCHA is a Google service and processes data about current website behaviour. The assigned risk score is used to determine whether additional authentication methods should be deployed (e.g. picture recognition tests). We process your personal data within our legitimate interests to prevent misuse of our contact forms. Further information on ReCATPCHA can be found at https://developers.google.com/recaptcha.

2.6 Newsletter

You can subscribe to our newsletters to receive regular updates from us (Art 6 (1) lit a GDPR). For the purpose of providing our newsletter we process the data your provided in your registration, as well as general data on the popularity and use of our newsletter. You may unsubscribe at any time using the respective link in each newsletter or by contacting us directly. A withdrawal of consent does not affect the lawfulness of the processing prior to the withdrawal.

Our newsletter service provider: Mailchimp

2.7 Waiting list for subscriptions

When you register for our subscription waiting list we process the personal data you provide (name, address, telephone number, email, number of seats, desired frequency, desired price) for the performance of our (pre-)contractual obligations (Art 6 (1) lit b GDPR). Please note that you must renew your registration regularly, otherwise your data will be deleted (currently after one year).

2.8 Applications (orchestra or summer academy)

If you apply to us, we process the data you provide (name, date and place of birth, citizenship, contact information (address, email, telephone), education, resume, photo, proof of studies, links to video applications) to carry out the application process and select the best candidates. The processing is based on our (pre-)contractual obligations (Art 6 (1) lit b GDPR). You are not obliged to provide your personal data. Without this data, however, it is not possible for us to conduct the application process with you.

We process your data for the duration of the application process. Additionally, we may retain data as far as legal claims can be raised against us (i.e. in Austria at least for 7 months after declining an application due to possible claims under the GlBG).

In addition, your data may be stored when you give your consent (e.g. to hold your application for future consideration).

2.9 Website analytics

We use Google Analytics, a service provided by Google Ireland Limited, register number: 368047, Gordon House, Barrow Street, Dublin 4, Ireland, to better understand how our website is used and which contents we should further develop. This analysis tool uses cookies to record standard logging information and visitor behavior on our website in an aggregated form. Google Analytics creates aggregated usage statistics including the following factors in particular: number and duration of page impressions of each sub-page, geographical distribution of users, used end devices (PC/mobile), language, operating system, service provider, monitor resolution (on mobile devices). For more information about how Google Analytics works and the information we can collect and analyze, please visit: https://support.google.com/analytics/answer/1012034?hl=en&ref_topic=6157800

The cookies used by Google Analytics are only set once you give your consent. To deactivate Google Analytics you may also use the following link: https://tools.google.com/dlpage/gaoptout/

Further information on Google’s terms of use and Google’s privacy policy can be found at the following link: https://www.google.com/analytics/terms/gb.html

2.10 Embedded content (streaming on our website)

With your consent, we use third party services to provide you a multi-media experience on our website. When you activate such plug-ins, your device connects to the servers of the respective plugin-provider and transmits data necessary to provide the content (your IP address, the current web page, cookies of the plug-in provider, device and browser settings). If you do not agree with the transfer of your data, please do not activating the plug-ins.

YouTube (videos): The website of the external media network YouTube is operated exclusively by Google Ireland Limited, register number: 368047, Gordon House, Barrow Street, Dublin 4, Ireland. You can find more information about data protection at Google under the following link: https://policies.google.com/privacy

Vimeo (videos): The website of the external media network Vimeo is operated exclusively by Vimeo Inc., 555 West 18th Street, New York 10011, USA. For more information on data protection at Vimeo, please click on the following link: https://vimeo.com/privacy

Idagio (music): The website of the external media network Idagio is operated exclusively by IDAGIO GmbH, Tempelhofer Ufer 17, 10963 Berlin, Germany. For more information on data protection at Idagio, please follow this link: https://about.idagio.com/privacy

2.11 Social media channels

In addition to this website, we operate the following social media channels:

Facebook    
Operator of the social media channel: Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland  
Privacy policy of the operator: https://www.facebook.com/privacy/explanation, https://www.facebook.com/legal/terms/page_controller_addendum, https://www.facebook.com/ViennaPhilharmonic
Our channel: https://www.facebook.com/ViennaPhilharmonic

Instagram
Operator of the social media channel: Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland
Privacy policy of the operator: https://de-de.facebook.com/help/instagram/155833707900388
Our channel: https://www.instagram.com/viennaphilharmonic

Twitter
Operator of the social media channel: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07 IRELAND
Privacy policy of the operator: https://twitter.com/de/privacy
Our channel: https://twitter.com/Vienna_Phil

Regarding the operation of the individual social media channels we may act as joint controllers together with the respective operator of the platform where this operator is not acting as sole controller. However, we do not have full access to the data processing by the platform operator. Therefore, we recommend reading our privacy policy together with the privacy policy of each platform to get a comprehensive overview.

For the operation of our social media channels we may process:

  • your personal data, e.g. cookies, when you interact with our social media channels (however, please note, that some data may be collected even if you are not logged in) and
  • interaction data, e.g. if you communicate with us via our social media channels through posts, comments, personal messages or contact forms.

When interacting with our social media channels we may have access to your publicly visible data (e.g. name and profile picture when you make a public comment on our page). Please review your profile settings to check which data is publicly available and to change which data can be shared by the platform. For more information please read the privacy policies of the respective social media platform.

In addition, we receive anonymous statistics from the social media operators about the use and popularity of our social media pages. The following information are processed:

  • Total number of followers (i.e. person following our channel)
  • Reach: number of people who see a specific post; number of interactions with a specific post; this enables us to review which topics are of great interest to our community
  • Demographic data of users: age, gender, place of residence, language.
  • Ad performance: How many people were reached by a post or paid ad? How many people have interacted with it?

2.12 Cookies

This website uses cookies. Cookies are small text files which are temporarily stored on your device when you visit our website and store certain information. Cookies cannot access, read or change other data stored on your device. Without cookies you may not be able to use some of the services we provide on our website (e.g. our online shop).

The following table provides an overview of the cookies used on our website:

csrftoken
Provider and purpose: Content Management System (CMS)
Category: Necessary
Retention: 1 year

vuid
Provider and purpose: Vimeo, Inc t display videos
Category: Necessary
Retention: 1 year
To prevent the cookie from being set, follow the instructions here https://vimeo.com/cookie_policy

Google Analytics (_ga, _gid, _gat_UA-)
Used to create usage statistics of our website and control repeated requests. This helps us understand how often, from which countries and with which devises our website is accessed and allows us to further optimize for these audiences. Cookies can distinguish individual users by means of a randomly generated ID to prevent multiple counts. 
Category: Analytics & optimization
Retention: 1 minute (_gat), 1 day (_gid), 1 year (_ga)

APISID, _Secure-SSID, _Secure-3PSID, SID, SSID, SIDCC, __Secure-3PAPISID, APISID, __Secure-HSID, SAPISID, HSID, __Secure-3PSIDCC, 1P_JAR, NID, CONSENT, SEARCH_SAMESITE, ANID 
Provider and purpose: Google ReCAPTCHA to prevent spam and abuse through automated requests.
Category: Necessary
Retention: 2 Jahre

shop_token 
Provider and purpose: Online shop: required for shop login, stores user token identify unique user (e.g. retaining your shopping basket)
Category: Necessary
Retention: 3 years

shop_token_refresh
Provider and purpose: Online shop: required for shop login, stores user token identify unique user (e.g. retaining your shopping basket)
Category: Necessary
Retention: 3 hours

3. GENERAL RETENTION PERIODS

We only store personal data within the statutory retention periods or insofar as there are justified interests in further processing (e.g. for the exercise and defense of legal claims). Communication data will be processed until your inquiry is completed or as long as (pre-)contractual obligations apply. For the storage period of cookies please refer to the cookie section of this privacy policy. You may also delete cookies in your browser settings at any time.

4. RECIPIENTS

Our service providers may process your personal data on our behalf in order to provide our services (esp. IT service providers, marketing agencies, newsletter services, banks and payment services, printing and shipping services). The specific recipients of individual processing purposes are listed above.

For recipients in third countries (Google, Amazon, Mailchimp) we use appropriate guarantees in form of standard contractual clauses to ensure an adequate level of data protection. I certain cases, after separate information, your data will also be transmitted on the basis of your explicit consent (Art 49 (1) lit a GDPR), or insofar as the transmission is necessary for the performance of the contract (Art 49 (1) lit b GDPR).

This website uses Google ReCaptcha, and, in case you have given your consent, Google Analytics. Both services are provided by Google Ireland Limited, register number: 368047, Gordon House, Barrow Street, Dublin 4, Ireland (Google). Google Analytics is a web analytics service and uses cookies to help the Website analyze how users use the site. The information generated by the cookie about your use of our Website (including your IP address and the URLs of the accessed pages) will be transmitted to and stored by Google on servers in the United States. We do not store any of your personal data collected in connection with Google Analytics. For more information please visit https://www.google.com/analytics/terms/gb.html and https://www.google.com/analytics/terms/dpa/dataprocessingamendment_20160909.html.

5. YOUR RIGHTS

Within the statutory provisions you have the following rights concerning the processing of your personal data (Art 15 to 21 GDPR):

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to object to a processing based on legitimate interests
  • Right to data portability for data provided by you, as well as
  • Right to withdraw a data protection consent (e.g. for our newsletters) – a withdrawal of consent does not affect the lawfulness of processing before the withdrawal

Furthermore, you may change the use of cookies in your browser settings or via https://tools.google.com/dlpage/gaoptout/ or https://www.youronlinechoices.com.

We do not process your personal data for the purpose of making decisions that are based solely on automated processing, including profiling, which produce legal effects on you or may similarly significantly affect you (Art 22 GDPR).

Additionally, you have the right to file a complaint with the competent supervisory authority, e.g. if you believe that we have violated your privacy rights or have not adequately enforced your data subject rights. In Austria: Austrian Data Protection Authority, Barichgasse 40-42, A-1030 Vienna, https://www.data-protection-authority.gv.at/

6. LINKS TO OTHER WEBSITES AND UPDATES TO THIS POLICY

This website may contain hyperlinks to websites controlled by third parties (e.g. websites or our partners or our social media channels). We are not responsible for and do not endorse or accept any responsibility over the contents or use of these websites. We are not responsible for the privacy policies or practices of other websites. We encourage you to review the privacy policies of those sites so you can understand how they collect, use, and share your information.

In the event of changes to the legal or technical framework, we will update this privacy policy to provide you with an up-to-date and complete picture of our processing. We recommend to regularly review the privacy policy to be informed about the current status.

Last updated: September 2020