VigneteRey
VigneteRey Austrian Alpine Corridors
Home / Legal Documentation / Privacy Policy

Statutory Disclosure

Privacy policy governing personal data and visitor rights

This Privacy Policy describes how VigneteRey (“we”, “us”, “our”), operating from Kärntner Straße 12, 1010 Wien, Austria, collects, processes, and protects personal data obtained from visitors using our website (vigneterey.it.com). We are committed to processing all personal data in full compliance with the European Union General Data Protection Regulation (Regulation (EU) 2016/679 – GDPR) and the Austrian Data Protection Act (Datenschutzgesetz – DSG).

Regulatory Baseline

Jurisdiction:
Republic of Austria / EU
Framework:
EU GDPR (2016/679) & DSG
Current Freshness:
September 2026
Supervisory Authority:
DSB Wien (Barichgasse)
Article 13 Compliance

Data controller identity and contact information

Direct inquiries, access requests, and revocation notices are processed by our dedicated privacy coordinator stationed at our Vienna administrative office.

Official Entity Address

VigneteRey Editorial Desk

Kärntner Straße 12

1010 Wien

Österreich

Office Hours

Monday – Friday: 08:30 – 17:30

Direct Communications

General Information

info@vigneterey.it.com

Dedicated Privacy Desk

privacy@vigneterey.it.com

Telephone Verification

+43 1 512 8490

Operational Scope: If you have questions regarding the processing of your personal data or wish to exercise your statutory data protection rights, please contact our designated data protection coordinator at the email address listed above. Formal requests receive initial written acknowledgment within three business days.
Data Inventory

Categories of personal data collected

We collect personal data only when strictly necessary to deliver, secure, and improve our informational website. We do not engage in automated individual decision-making, behavioral profiling, or unauthorized background aggregation.

LOG-01

Server Log Files

Network communication telemetry generated on every request: IP address (anonymized at subnet level where technically feasible), date and time of request, UTC timestamp, client browser version, host operating system, referring URL header, and HTTP status codes for requested alpine corridor guides.

MSG-02

Contact Communications

User-initiated transmissions submitted via editorial inquiries or route feedback: Full name, sender email address, inquiry classification (such as mountain pass status or vignette clarification), and any personal circumstances voluntarily noted in the communication payload.

MET-03

Technical Analytics Data

Pseudonymized telemetry and session performance records collected via essential load-monitoring mechanisms and consented analytical metrics. Used strictly to ensure server availability under peak seasonal transit traffic on Austrian highway corridors.

Legal Foundation

Legal bases for data processing under GDPR

Under Article 6 of Regulation (EU) 2016/679, any processing of personal data requires an explicitly recognized legal ground. We process personal data exclusively under the following statutory provisions:

Article 6(1)(f) GDPR

Legitimate Interests

Processing technical server logs and network packets to preserve server stability, prevent distributed denial-of-service (DDoS) intrusions, perform security forensic analysis, and safeguard the editorial infrastructure that serves alpine travelers.

Article 6(1)(b) GDPR

Contractual & Pre-contractual

Handling incoming visitor communications and field reports to formulate accurate replies, fulfill direct user requests for navigation clarification, and deliver customized route itinerary information requested by the user.

Article 6(1)(a) GDPR

Explicit Consent

Storing optional analytical metrics, performance cookies, or route preference markers. Consent is collected affirmatively via our dedicated cookie configuration panel and may be modified or revoked at any time with future effect.

Operational control and data processing standards for Austrian alpine road transit
Data protection oversight – Austrian transit network infrastructure
Processing Boundaries

Purposes of data processing

Personal data collected through this website is processed strictly for legitimate operational, informative, and technical maintenance purposes:

  • System Reliability and Network Defense:

    Ensuring continuous technical accessibility, dynamic server load balancing during extreme winter travel surges, and automated protection against malicious traffic spikes.

  • Editorial Assistance and Inquiries:

    Answering direct motorist inquiries, evaluating submitted field reports regarding road closures or high-pass weather restrictions, and updating route manuals.

  • Aggregated Content Optimization:

    Analyzing aggregated, non-identifying traffic patterns to identify high-demand Austrian transit corridors (such as the Tauern Autobahn or Arlberg corridor) and enhance navigational clarity.

  • Statutory Legal Obligations:

    Complying with statutory preservation mandates, official regulatory disclosures, and authorized legal disclosures under applicable Austrian federal legislation.

Retention Ledger

Data retention schedules and disposal

We retain personal data only for the duration necessary to fulfill the specific operational purposes for which it was gathered, observing strict time-bound purge protocols:

14–30 Days

Server Access & Security Logs

Raw web server records are retained for security auditing. Following this window, records are either purged or stripped of IP identifying fragments, unless held under active forensic inquiry.

12 Months

Direct Correspondence

Email exchanges, navigation clarifications, and route inquiries submitted through our contact channels are archived for up to twelve months to accommodate follow-up questions, then permanently deleted.

Session Rule

Analytical Metrics

Performance and technical analytics tokens expire strictly in alignment with schedules defined in our dedicated Cookie Policy, retaining no long-term identifier beyond user session termination.

Infrastructure Integrity

Third-party service providers and international data transfers

We do not sell, trade, or commercially lease personal data to external third parties. We utilize trusted technical service providers (such as web hosting facilities, content delivery networks, and email delivery platforms) bound by strict Data Processing Agreements (DPAs) in compliance with Article 28 GDPR.

All primary website hosting infrastructure resides within the European Union. In the event that any secondary technical transmission involves processing outside the European Economic Area (EEA), such transfers rely on European Commission Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection.

Transmission Defense

Security measures and transmission protocols

We implement state-of-the-art technical and organizational security measures to protect your personal data against accidental loss, unauthorized access, destruction, or alteration. All web traffic between your browser and our servers is encrypted using Secure Sockets Layer / Transport Layer Security (TLS/HTTPS).

Internal access to personal correspondence is restricted strictly to authorized editorial and administrative personnel who have signed confidentiality commitments and received training on Austrian and European data protection standards.

Chapter III GDPR

Statutory data subject rights under European law

Under Chapter III of the GDPR, visitors retain clear, enforceable entitlements concerning their personal records. Review your statutory rights below:

Right of Access (Article 15 GDPR)

You hold the right to obtain confirmation as to whether personal data concerning you is processed by VigneteRey. Where processing occurs, you may request access to that data along with details regarding processing purposes, categories of data involved, anticipated retention windows, and recipients.

Right to Rectification (Article 16 GDPR)

You have the right to request the immediate correction of inaccurate personal data concerning you, as well as the completion of any incomplete records maintained within our editorial files.

Right to Erasure / “Right to be Forgotten” (Article 17 GDPR)

You are entitled to request the deletion of your personal data when it is no longer necessary for the purposes for which it was gathered, when consent has been withdrawn and no alternative legal basis exists, or when processing was unlawful.

Right to Restriction of Processing (Article 18 GDPR)

You have the right to demand the restriction of data processing if the accuracy of data is contested by you, if the processing is unlawful yet you oppose deletion, or while verification of a legitimate interest objection is pending.

Right to Data Portability (Article 20 GDPR)

You may request to receive personal data you provided to us in a structured, commonly used, and machine-readable format, and have that information transmitted directly to another controller where technically feasible.

Right to Object (Article 21 GDPR)

You may object at any time to the processing of personal data concerning you which is based on Article 6(1)(f) GDPR (legitimate interests). We will discontinue processing unless compelling legitimate grounds overriding your interests, rights, and freedoms are demonstrated.

Supervisory Recourse

Right to Lodge a Formal Complaint

If you consider that the processing of personal data violates data protection legislation, you hold the right to lodge a complaint with the competent supervisory authority:

Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42, 1030 Wien, Österreich • dsb@dsb.gv.at

Editorial Integrity

Need clarification on data handling or corridor guidelines?

Our privacy desk responds directly to Austrian road travelers and data subjects regarding transit documentation, site analytics, and statutory requests.