Privacy Policy
1. Data Controller
The controller responsible for processing personal data in connection with Innsbruck Lokal is:
Innsbruck Marketing GmbH
Colingasse 5a
6020 Innsbruck
Austria
Phone: +43 (0) 512 56 15 00
Email: office@innsbruckmarketing.at
Data protection inquiries and requests for access, rectification, erasure or restriction of processing may be directed to these contact details.
2. General Principles and Legal Bases
When using Innsbruck Lokal, personal data is processed insofar as this is necessary for the technical provision of the platform, the management of merchant accounts, the presentation and management of shops and offers, and the functions described below.
Depending on the purpose, processing is carried out in particular on the following legal bases:
- Art. 6(1)(a) GDPR, where consent has been given;
- Art. 6(1)(b) GDPR, insofar as processing is necessary for the performance of a contract or for taking steps at the request of the data subject prior to entering into a contract;
- Art. 6(1)(c) GDPR, insofar as a legal obligation exists;
- Art. 6(1)(f) GDPR, insofar as processing is necessary for the purposes of the legitimate interests pursued by Innsbruck Marketing GmbH or third parties and these interests are not overridden by the interests or rights of the data subject.
Where information is stored on or accessed from a user’s device, Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) also applies. Storage or access that is not strictly necessary takes place only with prior consent.
As a general rule, personal data is stored only for as long as necessary for the respective purpose. Statutory retention obligations and permissible further storage for the establishment, exercise or defence of legal claims remain unaffected.
Recipients
Insofar as necessary for the respective processing activities described, personal data may be transferred in particular to the following recipients or categories of recipients:
- Hosting and IT service providers;
- Email service providers;
- Providers of AI services;
- Providers of mapping and geocoding services;
- Other technical service providers.
Where service providers process personal data on behalf of Innsbruck Marketing GmbH, they are engaged as processors in accordance with applicable legal requirements.
Where personal data is processed outside the European Economic Area, this takes place only in accordance with Art. 44 et seq. GDPR.
3. Hosting and Technical Provision
The technical maintenance and provision of Innsbruck Lokal have been entrusted to:
Medienweide.com, Jonas Weidemann
Guerickestraße 12
10587 Berlin
Germany
Medienweide uses ALL-INKL.COM – Neue Medien Münnich as a sub-processor for its server and data centre infrastructure. The servers are located in Germany.
Innsbruck Lokal does not use a separate backup location outside the technical safeguards provided by the hosting provider.
Data transmission between the browser and the platform is encrypted using HTTPS/TLS.
4. Server Log Files
When Innsbruck Lokal is accessed, technically necessary connection and access data is processed. This may include in particular:
- IP address;
- Time of access;
- Page or resource accessed;
- Browser and device information;
- Referrer;
- Technical status and error information.
Processing serves to ensure the secure and uninterrupted operation of the platform, analyse errors, and detect and prevent attacks or misuse.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, stable and technically proper operation of the platform.
Technical log data is stored only for as long as necessary for these purposes. Longer storage may take place where necessary to investigate a security incident or to establish, exercise or defend legal claims.
5. Technically Necessary Storage and Privacy Settings
Innsbruck Lokal uses technically necessary cookies and comparable storage technologies insofar as they are required in particular for:
- Login and session management;
- Security functions;
- Storing privacy settings;
- Functions explicitly requested by the user.
The selection regarding the loading of external content is stored locally in the browser so that it can be taken into account during subsequent page visits.
Storage, access or external content that is not strictly necessary is activated only after the corresponding consent has been given.
Consent that has been given may be withdrawn at any time via the website’s privacy settings with effect for the future.
6. Merchant Accounts and Registration
Merchants can create a user account to manage one or more shops or business locations and offers on Innsbruck Lokal.
During registration and account management, the necessary master data, contact data, access data and security data are processed in particular.
Processing serves in particular the following purposes:
- Setting up and managing the merchant account;
- Authentication;
- Protection against unauthorised access;
- Use of merchant functions;
- Communication in connection with the account.
Where the data subject is personally a contracting party, processing is carried out on the basis of Art. 6(1)(b) GDPR. Where contact persons or employees of a company are concerned, processing is carried out on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in the performance and management of the contractual relationship with the respective company.
During registration, the Terms of Use must be expressly accepted. For documentation purposes, the time, language, edition or version, and the references to the Terms of Use and Privacy Policy applicable at that time are stored in particular.
7. Shops, Offers and Other Platform Content
Logged-in merchants can create, edit and manage shops and offers.
In this context, the following data is processed in particular:
- Shop and company names;
- Descriptions and other content;
- Business contact details;
- Location and address data;
- Opening hours;
- Categories and services offered;
- Websites and social media links;
- Images, logos and other media files;
- Information about offers and events;
- Assignment and editing information.
The information intended for publication is displayed publicly on Innsbruck Lokal after it has been saved. There is currently no prior editorial approval by Innsbruck Marketing GmbH.
Processing serves to provide and manage the respective shop or offer listing.
Where the data is necessary for the performance of the contractual relationship with the data subject, processing is based on Art. 6(1)(b) GDPR. Where business contact details or other personal information relating to third parties form part of a listing, processing is carried out on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in providing and operating a platform that showcases Innsbruck’s retail and hospitality businesses.
8. Images, Logos and Other Media Files
Merchants can upload images, logos and other media files.
The respective file and any technical metadata it may contain are processed and assigned to the user account or the relevant shop or offer.
The files are stored on the hosting infrastructure of Innsbruck Lokal and, where intended by the merchant, displayed publicly.
Processing is carried out in accordance with the legal basis applicable to the respective content pursuant to Section 7.
The merchant’s responsibility for the content they provide and the necessary rights is governed by the Terms of Use.
9. AI-Assisted Website Analysis and Translation – Mistral AI
To assist merchants in creating and translating shop and offer content, Innsbruck Lokal uses services provided by:
Mistral AI
15 rue des Halles
75001 Paris
France
The AI functions are triggered exclusively and deliberately by logged-in merchants. No content is transmitted to Mistral merely by visiting Innsbruck Lokal.
Website Analysis
A merchant can enter the URL of a publicly accessible website and generate suggestions for a shop listing from its content.
For this purpose, the Innsbruck Lokal server retrieves the homepage and no more than three selected subpages from the same domain. Before transmission to Mistral, the content is technically extracted, cleaned and shortened.
The information transmitted may include publicly accessible website and company information such as texts, contact details, opening hours, addresses, social media links, and image and logo URLs.
Image files, PDF files, archives, audio files and video files are not transmitted to Mistral.
The source of the data is the publicly accessible website specified by the merchant.
The results generated by Mistral are displayed to the merchant as suggestions. The merchant decides which suggestions to accept and can subsequently edit them.
AI Translation
Merchants can submit shop and offer texts to Mistral to create an English-language version. This function is also triggered deliberately, and the result is provided solely as an editable translation suggestion.
Data Protection at Mistral
Innsbruck Lokal uses a paid Mistral account held by Innsbruck Marketing GmbH.
The use of API data to train Mistral models is disabled. Labs or Preview models are not used.
Zero Data Retention is enabled for the API service used. Inputs and outputs are therefore processed only insofar as necessary to generate the respective response and are not subsequently stored by Mistral.
Where Mistral uses sub-processors outside the European Economic Area or processing takes place outside the European Economic Area, the legal requirements of Art. 44 et seq. GDPR are complied with.
Where the transmitted data relates to the merchant personally and is necessary for the performance of the contractual relationship, processing is carried out on the basis of Art. 6(1)(b) GDPR. Where publicly accessible business contact details or other personal information relating to third parties are processed, processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in the efficient and user-friendly creation and maintenance of shop and offer information.
Merchants should not transmit confidential personal data or personal data that is not necessary for the respective purpose via the AI functions.
10. Matomo
A self-hosted Matomo instance is used for the statistical analysis of Innsbruck Lokal.
Matomo is operated on the server infrastructure used for Innsbruck Lokal in Germany. Analysis data is not transferred to the Matomo Cloud.
Matomo processes information about page views as well as technical browser and device information in particular. The IP address is anonymised for statistical analysis.
Matomo is configured so that no Matomo tracking cookies are set. The visitor log and visitor profile functions are disabled. Supported Do Not Track signals from the browser are respected.
Matomo is activated only after you have given your consent.
Processing is carried out on the basis of Art. 6(1)(a) GDPR in conjunction with Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021).
You can withdraw your consent at any time via the privacy settings of Innsbruck Lokal with effect for the future.
Detailed page-view data is stored for 361 days, or 362 days in leap years. Aggregated report data is subsequently stored permanently for statistical comparisons and overall analyses.
11. Internal Statistics for Shops and Offers
In addition to Matomo, Innsbruck Lokal maintains its own statistics on views and certain interactions with shops and offers. These statistics are separate from Matomo.
Only the respective shop or offer, the type of event and the calendar day are stored. The events recorded include, in particular, views and clicks on telephone numbers, email addresses, websites, maps or directions.
In particular, these statistics do not store IP addresses or IP hashes, cookies, visitor identifiers, referrers, browser or device information, user agents or exact times.
It is therefore not possible to identify individual or returning visitors using these statistics.
Merchants receive statistical analyses relating to their own shops and offers. Administrators can access cross-platform analyses.
Technical server log files and Matomo are separate systems.
12. System and Transactional Emails – Brevo
Innsbruck Lokal uses the Brevo service for technically and organisationally necessary emails.
The provider is:
Sendinblue GmbH
Köpenicker Straße 126
10179 Berlin
Germany
Brevo is currently used in particular to send system and transactional messages, such as:
- Notifications relating to registration or account management;
- Password and security messages;
- Notifications relating to shops and offers;
- Notifications regarding the closure of a user account.
Innsbruck Lokal does not currently offer a newsletter.
In connection with sending emails, recipient data, contact data, message data, sending information and delivery information are processed in particular.
Processing is carried out on the basis of Art. 6(1)(b) GDPR insofar as the message is necessary for the performance of the contractual relationship. Security and administrative messages may additionally be based on Art. 6(1)(f) GDPR.
13. Map Functions in the Public Area
Innsbruck Lokal uses a locally integrated map library to display shops and other locations.
External map material is loaded only when the user activates the “Load map data” function. The following map sources are used:
- OpenStreetMap;
- basemap.at or the map data provided for this purpose via the infrastructure of the City of Vienna.
When external map tiles are loaded, the IP address of the accessing device, together with the necessary browser and connection information, is transmitted to the respective map server for technical reasons.
Processing takes place following prior consent on the basis of Art. 6(1)(a) GDPR in conjunction with Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021).
The selected preference is stored locally in the browser and can be withdrawn via the website’s privacy settings or by deleting the corresponding website data.
Location Function
Certain map functions allow users to use their current location.
Access takes place only following a corresponding action by the user and the necessary location permission in the browser or operating system.
The determined location is used for the respective map function and is not permanently stored on the servers of Innsbruck Lokal.
14. Google Maps in the Merchant Area and External Route Links
The Google Maps JavaScript API, including a geocoding function, is used in the protected merchant and administration area.
The provider for users in the European Economic Area is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
This function enables merchants to search for an address when creating or editing a shop and convert it into a standardised postal address and geographical coordinates.
The Google function is loaded exclusively in the protected merchant or administration area and in connection with the address function used by the merchant.
When this function is used, the following data in particular is transmitted to Google:
- The address entered;
- The IP address;
- Technically necessary device and connection data.
Where the data subject is personally a contracting party, processing is carried out on the basis of Art. 6(1)(b) GDPR. Where data relating to company contact persons is concerned, processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in the standardised collection of shop addresses and geographical coordinates for map display.
Where the technical integration additionally requires the storage of information on the user’s device or corresponding access that is subject to consent under Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021), this takes place only after prior consent.
Google may also process personal data outside the European Economic Area. Such transfers take place only in accordance with the requirements of Art. 44 et seq. GDPR.
Google Maps maps are not embedded on the publicly accessible platform. Google Maps is accessed there only via external location or route links. The Google service is opened only when such a link is clicked.
15. Reporting Unlawful Content
Persons who consider content on Innsbruck Lokal to be unlawful can report it via the publicly accessible “Report content” reporting channel.
The following information in particular is processed:
- The content concerned, its URL or a unique identification of the content;
- The reasons for the report;
- The name and email address of the person submitting the report;
- Confirmation that the information provided is accurate and complete to the best of the reporting person’s knowledge;
- A reference number, processing status and internal notes relating to the handling of the report.
The report is stored as an internal case. The responsible editorial team is notified of new reports and can review and process them. Technical safeguards are used to protect against abusive or duplicate reports. No IP addresses, browser identifiers or additional cookies are stored for the reporting form in this process.
Processing serves to receive, review, document and handle reports of potentially unlawful content and to ensure that the measures taken can be traced.
The legal basis is Art. 6(1)(f) GDPR. IMG’s legitimate interest lies in being able to review reports of potential legal violations, respond to them where necessary and document the handling of such reports.
As a general rule, the data is deleted three years after the respective report has been closed, unless a statutory obligation or the establishment, exercise or defence of legal claims requires longer storage.
16. Account Closure and Deletion
Merchants can request the closure of their user account themselves in the protected area. This requires entering their current password and providing explicit confirmation.
After the account has been closed:
- Access is blocked immediately;
- Active sessions are terminated;
- Associated shops and offers are set to “Draft” and are no longer publicly visible;
- IMG and the merchant are informed of the closure and the scheduled deletion date.
The account can subsequently be restored by an administrator for a period of 30 days. Merchants cannot restore their accounts themselves.
After this period has expired, the following in particular are deleted as part of a daily deletion process:
- The user account;
- The shops and offers belonging to the merchant, including language versions;
- The media uploaded by the merchant via their user account.
Files that are used in a shop but were uploaded by another user are not automatically deleted as a result.
Temporary storage during the 30-day period serves to ensure the orderly completion of the account closure and to allow an accidental closure to be reversed by an administrator.
Statutory data protection rights, in particular a request for erasure pursuant to Art. 17 GDPR, remain unaffected by this technical account closure function.
17. Rights of Data Subjects
Subject to the applicable statutory requirements, data subjects have the following rights in particular:
- Access to the personal data being processed pursuant to Art. 15 GDPR;
- Rectification of inaccurate data or completion of incomplete data pursuant to Art. 16 GDPR;
- Erasure pursuant to Art. 17 GDPR;
- Restriction of processing pursuant to Art. 18 GDPR;
- Data portability pursuant to Art. 20 GDPR, where the relevant requirements are met;
- Objection to processing based on Art. 6(1)(e) or (f) GDPR pursuant to Art. 21 GDPR;
- Withdrawal of consent at any time with effect for the future.
Right to Object under Art. 21 GDPR
Where IMG processes personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation.
Following an objection, IMG will no longer process the personal data concerned unless IMG can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.
Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Requests may be directed to the contact details provided in Section 1. Where necessary to process a request, Innsbruck Marketing GmbH may require appropriate information to verify the identity of the person making the request.
Data subjects also have the right to lodge a complaint with a data protection supervisory authority.
For Austria:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Austria
Email: dsb@dsb.gv.at
18. No Automated Decision-Making
Innsbruck Lokal does not use the systems described for decisions based solely on automated processing that produce legal effects concerning a person or similarly significantly affect them.
In particular, the AI functions used do not automatically decide whether shops or offers are published or rejected.
The AI or statistical functions described do not carry out profiling of visitors.
19. Changes to This Privacy Policy
Innsbruck Marketing GmbH may amend this Privacy Policy if the functions used, service providers or legal requirements change.
The version published on innsbruck-lokal.at at the respective time applies. Where new or modified processing requires consent by law, such consent will be obtained separately.
Last updated: 16 September 2026