Statutory Disclosure
Privacy policy governing personal data and visitor rights
This Privacy Policy describes how VigneteRey (“we”, “us”, “our”), operating from Kärntner Straße 12, 1010 Wien, Austria, collects, processes, and protects personal data obtained from visitors using our website (vigneterey.it.com). We are committed to processing all personal data in full compliance with the European Union General Data Protection Regulation (Regulation (EU) 2016/679 – GDPR) and the Austrian Data Protection Act (Datenschutzgesetz – DSG).
Regulatory Baseline
- Jurisdiction:
- Republic of Austria / EU
- Framework:
- EU GDPR (2016/679) & DSG
- Current Freshness:
- September 2026
- Supervisory Authority:
- DSB Wien (Barichgasse)
Data controller identity and contact information
Direct inquiries, access requests, and revocation notices are processed by our dedicated privacy coordinator stationed at our Vienna administrative office.
Official Entity Address
VigneteRey Editorial Desk
Kärntner Straße 12
1010 Wien
Österreich
Office Hours
Monday – Friday: 08:30 – 17:30
Direct Communications
General Information
Dedicated Privacy Desk
Telephone Verification
+43 1 512 8490
Categories of personal data collected
We collect personal data only when strictly necessary to deliver, secure, and improve our informational website. We do not engage in automated individual decision-making, behavioral profiling, or unauthorized background aggregation.
Server Log Files
Network communication telemetry generated on every request: IP address (anonymized at subnet level where technically feasible), date and time of request, UTC timestamp, client browser version, host operating system, referring URL header, and HTTP status codes for requested alpine corridor guides.
Contact Communications
User-initiated transmissions submitted via editorial inquiries or route feedback: Full name, sender email address, inquiry classification (such as mountain pass status or vignette clarification), and any personal circumstances voluntarily noted in the communication payload.
Technical Analytics Data
Pseudonymized telemetry and session performance records collected via essential load-monitoring mechanisms and consented analytical metrics. Used strictly to ensure server availability under peak seasonal transit traffic on Austrian highway corridors.
Legal bases for data processing under GDPR
Under Article 6 of Regulation (EU) 2016/679, any processing of personal data requires an explicitly recognized legal ground. We process personal data exclusively under the following statutory provisions:
Legitimate Interests
Processing technical server logs and network packets to preserve server stability, prevent distributed denial-of-service (DDoS) intrusions, perform security forensic analysis, and safeguard the editorial infrastructure that serves alpine travelers.
Contractual & Pre-contractual
Handling incoming visitor communications and field reports to formulate accurate replies, fulfill direct user requests for navigation clarification, and deliver customized route itinerary information requested by the user.
Explicit Consent
Storing optional analytical metrics, performance cookies, or route preference markers. Consent is collected affirmatively via our dedicated cookie configuration panel and may be modified or revoked at any time with future effect.
Purposes of data processing
Personal data collected through this website is processed strictly for legitimate operational, informative, and technical maintenance purposes:
-
System Reliability and Network Defense:
Ensuring continuous technical accessibility, dynamic server load balancing during extreme winter travel surges, and automated protection against malicious traffic spikes.
-
Editorial Assistance and Inquiries:
Answering direct motorist inquiries, evaluating submitted field reports regarding road closures or high-pass weather restrictions, and updating route manuals.
-
Aggregated Content Optimization:
Analyzing aggregated, non-identifying traffic patterns to identify high-demand Austrian transit corridors (such as the Tauern Autobahn or Arlberg corridor) and enhance navigational clarity.
-
Statutory Legal Obligations:
Complying with statutory preservation mandates, official regulatory disclosures, and authorized legal disclosures under applicable Austrian federal legislation.
Data retention schedules and disposal
We retain personal data only for the duration necessary to fulfill the specific operational purposes for which it was gathered, observing strict time-bound purge protocols:
Server Access & Security Logs
Raw web server records are retained for security auditing. Following this window, records are either purged or stripped of IP identifying fragments, unless held under active forensic inquiry.
Direct Correspondence
Email exchanges, navigation clarifications, and route inquiries submitted through our contact channels are archived for up to twelve months to accommodate follow-up questions, then permanently deleted.
Analytical Metrics
Performance and technical analytics tokens expire strictly in alignment with schedules defined in our dedicated Cookie Policy, retaining no long-term identifier beyond user session termination.
Third-party service providers and international data transfers
We do not sell, trade, or commercially lease personal data to external third parties. We utilize trusted technical service providers (such as web hosting facilities, content delivery networks, and email delivery platforms) bound by strict Data Processing Agreements (DPAs) in compliance with Article 28 GDPR.
All primary website hosting infrastructure resides within the European Union. In the event that any secondary technical transmission involves processing outside the European Economic Area (EEA), such transfers rely on European Commission Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection.
Security measures and transmission protocols
We implement state-of-the-art technical and organizational security measures to protect your personal data against accidental loss, unauthorized access, destruction, or alteration. All web traffic between your browser and our servers is encrypted using Secure Sockets Layer / Transport Layer Security (TLS/HTTPS).
Internal access to personal correspondence is restricted strictly to authorized editorial and administrative personnel who have signed confidentiality commitments and received training on Austrian and European data protection standards.
Statutory data subject rights under European law
Under Chapter III of the GDPR, visitors retain clear, enforceable entitlements concerning their personal records. Review your statutory rights below:
Right of Access (Article 15 GDPR)
You hold the right to obtain confirmation as to whether personal data concerning you is processed by VigneteRey. Where processing occurs, you may request access to that data along with details regarding processing purposes, categories of data involved, anticipated retention windows, and recipients.
Right to Rectification (Article 16 GDPR)
You have the right to request the immediate correction of inaccurate personal data concerning you, as well as the completion of any incomplete records maintained within our editorial files.
Right to Erasure / “Right to be Forgotten” (Article 17 GDPR)
You are entitled to request the deletion of your personal data when it is no longer necessary for the purposes for which it was gathered, when consent has been withdrawn and no alternative legal basis exists, or when processing was unlawful.
Right to Restriction of Processing (Article 18 GDPR)
You have the right to demand the restriction of data processing if the accuracy of data is contested by you, if the processing is unlawful yet you oppose deletion, or while verification of a legitimate interest objection is pending.
Right to Data Portability (Article 20 GDPR)
You may request to receive personal data you provided to us in a structured, commonly used, and machine-readable format, and have that information transmitted directly to another controller where technically feasible.
Right to Object (Article 21 GDPR)
You may object at any time to the processing of personal data concerning you which is based on Article 6(1)(f) GDPR (legitimate interests). We will discontinue processing unless compelling legitimate grounds overriding your interests, rights, and freedoms are demonstrated.
Right to Lodge a Formal Complaint
If you consider that the processing of personal data violates data protection legislation, you hold the right to lodge a complaint with the competent supervisory authority:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42, 1030 Wien, Österreich • dsb@dsb.gv.at
Editorial Integrity
Need clarification on data handling or corridor guidelines?
Our privacy desk responds directly to Austrian road travelers and data subjects regarding transit documentation, site analytics, and statutory requests.