Privacy Policy
The protection of your personal data is important to us. This Privacy Policy explains how Shenion Capital Advisory GmbH processes personal data when you visit this website or contact us.
We process personal data in accordance with the EU General Data Protection Regulation, the Austrian Data Protection Act, the Austrian Telecommunications Act 2021 and other applicable legal requirements.
1. Controller
The controller responsible for processing personal data through this website is:
Shenion Capital Advisory GmbH
Obere Theninger Straße 10
4062 Kirchberg-Thening
Austria
2. Scope of this Privacy Policy
This Privacy Policy applies to the processing of personal data in connection with:
- visits to this website;
- communication by email or telephone;
- technically necessary website operation;
- links to external websites and social-media profiles.
The website does not currently offer user accounts, online purchases, newsletter registration or a website contact form.
3. Website access and server log files
When you access this website, technical information may automatically be transmitted by your browser and recorded in server log files.
This information may include:
- IP address;
- date and time of access;
- requested page or file;
- amount of data transferred;
- referring website;
- browser type and version;
- operating system;
- device information;
- access status or error codes.
Purposes
This data is processed to:
- deliver the website;
- maintain the security and stability of the website;
- identify and resolve technical problems;
- prevent misuse and cyberattacks;
- investigate security incidents.
Legal basis
Processing is based on our legitimate interest in operating a secure, stable and functional website pursuant to Article 6(1)(f) GDPR.
Retention
Server log data is retained only for as long as required for technical operation, security monitoring and the investigation of incidents. It is then deleted or anonymised unless further retention is required to establish, exercise or defend legal claims.
The precise technical retention period depends on the configuration of our hosting provider.
4. Hosting and technical service providers
We use external hosting and technical service providers to operate and maintain this website.
These providers may process technical website data, including IP addresses and server log information, on our behalf. They act as processors pursuant to Article 28 GDPR where applicable and may process data only in accordance with our instructions and contractual obligations.
Recipients may include:
- website-hosting providers;
- website-maintenance and IT-support providers;
- security and backup service providers;
- professional advisers where legally necessary.
We disclose personal data only where this is necessary for the relevant purpose, legally required or otherwise permitted under applicable data-protection law.
5. Contact by email or telephone
When you contact us by email or telephone, we process the information you provide.
This may include:
- name;
- company and position;
- email address;
- telephone number;
- content of your enquiry;
- related correspondence and documents;
- information necessary to evaluate or respond to your enquiry.
Purposes
We process this information to:
- respond to your enquiry;
- communicate with you;
- assess a potential engagement or business relationship;
- prepare, negotiate or perform a contract;
- maintain appropriate business records;
- establish, exercise or defend legal claims.
Legal bases
Depending on the nature of the enquiry, processing is based on:
- steps taken at your request before entering into a contract or performance of a contract pursuant to Article 6(1)(b) GDPR;
- our legitimate interest in responding to business communications and managing professional relationships pursuant to Article 6(1)(f) GDPR;
- compliance with legal obligations pursuant to Article 6(1)(c) GDPR;
- your consent pursuant to Article 6(1)(a) GDPR where consent is specifically requested.
Retention
We retain enquiries and related correspondence for as long as necessary to respond and manage the relevant business relationship.
Information may be retained for longer where required by statutory retention obligations or where necessary for the establishment, exercise or defence of legal claims.
6. Cookies and similar technologies
Cookies are small files or pieces of information stored on or accessed from your device.
This website is intended to use only cookies or comparable storage technologies that are technically necessary for:
- delivering website content;
- maintaining website security;
- storing essential technical settings;
- ensuring the correct operation of WordPress and the website interface.
Technically necessary cookies may be used without consent where they are required to provide a service expressly requested by the visitor.
At the time of publication of this Privacy Policy, we do not intentionally use analytics, advertising, profiling or cross-website tracking cookies.
Should we introduce non-essential cookies or tracking technologies in the future, they will not be activated before the required consent has been obtained. This Privacy Policy and any consent-management mechanism will then be updated accordingly.
You may configure your browser to reject or delete cookies. Disabling technically necessary cookies may affect the operation of the website.
7. Fonts and website assets
Fonts, icons, images and other website assets should, where reasonably possible, be hosted locally on our website infrastructure.
Where content is loaded from an external provider, technical data such as your IP address may be transmitted to that provider. Any such external integration must be assessed separately and, where required, described in this Privacy Policy and activated only after the necessary consent has been obtained.
8. External links and LinkedIn
This website contains links to external websites, including our LinkedIn company profile.
When you follow an external link, the operator of the destination website processes data under its own responsibility and in accordance with its own privacy policy. We do not control data processing carried out by external website operators.
A simple link does not itself transmit personal data to the external provider before you click it, provided that no external plugin, feed or embedded content is loaded on the Shenion website.
9. International data transfers
Where a service provider processes personal data outside the European Economic Area, we ensure that an appropriate transfer mechanism is available where required.
This may include:
- an adequacy decision adopted by the European Commission;
- standard contractual clauses;
- supplementary technical and organisational safeguards;
- another legally recognised transfer mechanism.
Information regarding relevant safeguards may be requested using the contact details provided above.
10. Data security
We implement appropriate technical and organisational measures to protect personal data against:
- unauthorised access;
- unlawful processing;
- accidental loss;
- destruction;
- alteration;
- unauthorised disclosure.
These measures are reviewed and adapted where appropriate. Nevertheless, no transmission or storage system can guarantee absolute security.
11. No automated decision-making
We do not use personal data collected through this website for automated decision-making, including profiling, that produces legal effects or similarly significantly affects website visitors.
12. Your rights
Subject to the conditions under applicable law, you have the right to:
- obtain confirmation as to whether we process your personal data;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data;
- request restriction of processing;
- receive data you provided in a structured, commonly used and machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time with effect for the future;
- lodge a complaint with a data-protection supervisory authority.
Where processing is based on our legitimate interests, you may object to such processing on grounds relating to your particular situation. We will then cease processing unless compelling legitimate grounds override your interests, rights and freedoms, or processing is required for legal claims.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
13. Complaints
You have the right to lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority.
The Austrian supervisory authority is:
Austrian Data Protection Authority
Österreichische Datenschutzbehörde
Further information and complaint procedures are available through the authority’s official website.
We encourage you to contact us first so that we have an opportunity to address your concerns.
14. Changes to this Privacy Policy
We may update this Privacy Policy when:
- the website or its functionality changes;
- new service providers or technologies are introduced;
- legal or regulatory requirements change;
- our data-processing activities change.
The current version will always be published on this website. The date of the latest update is stated at the top of the page.
