• No silicones!
  • No animal testing!
  • Vegan!
  • No sulfates!
  • No parabens!

privacy policy

In this privacy policy, we inform you about the processing of your personal data. If you wish to change your privacy settings (grant consent or revoke consent already given), click here to change your settings.

Responsible party

Roland Markus, Roland Markus e.U., Aigen 20, 4911 Tumeltsham, Austria, info@timelessbeautysecrets.at, 069910107007

Hosting

Cloudways: Service: Cloudways Provider: Cloudways Ltd., 52 Springvale, Pope Pius XII Street, Mosta MST2653, Malta Server location: Frankfurt

Security services

On this website, we use the services of security providers such as captcha services to prevent non-human and automated entries.

Our website uses the service 'Turnstile Captcha' from Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Turnstile Captcha serves to protect our website from automated access, so-called bots, and helps us ensure the security of our user data. This service is technically necessary to ensure the proper functioning and protection of our website.

When using Turnstile Captcha, certain information, such as your IP address, browser and device information, as well as information about your interaction with the captcha, is transmitted to and processed by Cloudflare. The processing of this data is necessary to ensure the proper operation and security of our website. No data is collected or processed in a way that would allow linking to individual user profiles. The legal basis for processing your data is Art. 6 para. 1 lit. f GDPR (legitimate interest in the security of our website and protection against automated access) as well as Art. 6 para. 1 lit. b GDPR (technically necessary processing for contract fulfillment). Cloudflare is a certified participant in the Privacy Shield agreement and thus ensures the European level of data protection. Further information on data protection at Cloudflare can be found at: https://www.cloudflare.com/de-de/privacypolicy/

Web fonts

Font Awesome

We process with our processor Fontawesome, Fonticons, Inc., 6 Porter Road, Apartment 3R, Cambridge, MA 02140, USA, connection data and browser data for the purpose of providing the fonts required by the web browser to display the website. This data is processed only for the duration necessary to select and transmit the fonts. The legal basis for data processing is legitimate interest (absolute technical necessity for the provision and delivery of the service 'website' expressly requested by your call) according to Art. 6 para. 1 lit. f GDPR. Insofar as Fontawesome carries out further independent processing of the data, Fontawesome is solely responsible for this. Details can be found in the Privacy Policy by Fontawesome.

Embeddings

YouTube

In the event that you give your consent, we process your personal data together with the service Youtube, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland as joint controllers for the purpose of playing videos on our website. We enable the service to collect connection data, collect data from your web browser, and place an advertising cookie. By placing advertising cookies, Google is able to calculate an individual user ID for each user. These personal data suitable for unique identification are then processed within the advertising network operated by Google. The Google Group transfers your personal data to the USA. The legal basis for the data transfer to the USA is your consent pursuant to Art. 49 para. 1 lit. a in conjunction with Art. 6 para. 1 lit. a GDPR in conjunction with §25 TTDSG. You were already informed before giving your consent that the USA does not have a level of data protection equivalent to EU standards. In particular, US intelligence agencies can access your data without informing you and without you having any legal recourse. For this reason, the European Court of Justice declared the previous adequacy decision (Privacy Shield) invalid in a ruling. If Google carries out further independent processing of the data, particularly within the framework of Google's advertising network, Google is solely responsible for this. You can find details in the Privacy Policy from Google. The only consequence of not giving consent is that the YouTube service will not be made available to you. You can revoke any consent already given by changing the privacy settings . The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR.

Google Maps

In the event that you give your consent, we process your personal data together with the service Google Maps, Google LLC, Amphitheatre Parkway, Mountain View, CA 94043, USA, as joint controllers for the purpose of displaying interactive maps on our website. We enable the service to collect connection data, collect data from your web browser, and place an advertising cookie. By placing advertising cookies, Google is able to calculate an individual user ID for each user. These personal data suitable for unique identification are then processed within the advertising network operated by Google. If Google carries out further independent processing of the data, particularly within the framework of Google's advertising network, Google is solely responsible for this. You can find details in the Privacy Policy from Google. The only consequence of not giving consent is that the Google Maps service will not be made available to you. You can revoke any consent already given by changing the privacy settings change. The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR. The Google Group transfers your personal data to the USA. The legal basis for the transfer of data to the USA is your consent pursuant to Art. 49 para. 1 lit. a in conjunction with Art. 6 para. 1 lit. a GDPR in connection with §25 TTDSG. You were already informed before giving your consent that the USA does not have a level of data protection equivalent to EU standards. In particular, US intelligence agencies may access your data without informing you and without you being able to take legal action against it. For this reason, the European Court of Justice declared the previous adequacy decision (Privacy Shield) invalid in a ruling.

Instagram

In the event that you give your consent, we process your personal data together with the service Instagram, Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, as joint controllers of your personal data for the purpose of providing Instagram services on our website. We enable the service to collect connection data, collect data from your web browser, and place advertising cookies. By placing advertising cookies, Facebook is able to calculate an individual user ID for each user. These personal data suitable for unique identification are then processed as part of the advertising network operated by Facebook. The Facebook Group transfers your personal data to the USA. The legal basis for the transfer of data to the USA is your consent pursuant to Art. 49 para. 1 lit. a in conjunction with Art. 6 para. 1 lit. a GDPR in connection with §25 TTDSG. You were already informed before giving your consent that the USA does not have a level of data protection equivalent to EU standards. In particular, US intelligence agencies may access your data without informing you and without you being able to take legal action against it. For this reason, the European Court of Justice declared the previous adequacy decision (Privacy Shield) invalid in a ruling. Insofar as Facebook carries out further independent processing of the data, particularly within the framework of Facebook's advertising network, Facebook is solely responsible for this. You can find details in the Privacy Policy from Facebook. Failure to give consent will only result in Facebook's services not being made available to you. You can revoke any consent already given by privacy settings . The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR.

Facebook

In the event that you give your consent, we process your personal data together with the service Facebook, Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, as joint controllers of your personal data for the purpose of providing Facebook services (e.g. Facebook Like Button, Facebook Like Box) on our website. We enable the service to collect connection data, collect data from your web browser, and place advertising cookies. By placing advertising cookies, Facebook is able to calculate an individual user ID for each user. These personal data suitable for unique identification are then processed as part of the advertising network operated by Facebook. The Facebook Group transfers your personal data to the USA. The legal basis for the transfer of data to the USA is your consent pursuant to Art. 49 para. 1 lit. a in conjunction with Art. 6 para. 1 lit. a GDPR in connection with §25 TTDSG. You were already informed before giving your consent that the USA does not have a level of data protection equivalent to EU standards. In particular, US intelligence agencies may access your data without informing you and without you being able to take legal action against it. For this reason, the European Court of Justice declared the previous adequacy decision (Privacy Shield) invalid in a ruling. Insofar as Facebook carries out further independent processing of the data, particularly within the framework of Facebook's advertising network, Facebook is solely responsible for this. You can find details in the Privacy Policy from Facebook. Failure to give consent will only result in Facebook's services not being made available to you. You can revoke any consent already given by privacy settings . The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR.

Webshop

We offer you the opportunity to purchase products directly through our webshop. As part of the webshop, the data you enter as well as data about the products you have selected are processed by the controller for the purpose of preparing an offer, concluding a contract, fulfilling the contract, and fulfilling any post-contractual obligations prior to the conclusion of the contract on the basis of the pre-contractual relationship initiated by you and after the conclusion of the contract on the basis of the contract pursuant to Art. 6 para. 1 lit. b GDPR. If the purchase of our products is made via an already existing customer account or a customer account has been created for the processing of the purchase, your personal data will be processed until your customer account is deleted. For customers who have purchased our products via a guest profile, your personal data will be processed until the statutory retention periods expire. Further processing of your data for the purpose of direct marketing in non-consent-requiring forms such as addressed postal advertising will be carried out for the purpose of fulfilling the contract until you object. There is no legal or contractual obligation to provide personal data. However, provision is required for the conclusion of the contract. Failure to provide data will result in no contract being concluded. Shopping carts of unregistered users will be deleted after a maximum of 14 days. The user accounts of registered users will remain until the account is deleted by the user. Contract data will be processed until the expiration of possible post-contractual obligations.

Payments are processed with:

Service: PayPal Operator: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg Service: Stripe Operator: Stripe, Inc. 185 Berry Street, Suite 550, San Francisco, CA 94107, USA

Analytics services

Matomo

We process your personal data with the data processor Matomo, InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand for the purpose of error analysis and statistical evaluation of our website. We enable the service to collect connection data, data from your web browser and data about the content accessed, as well as to run analytics software and store data on your device. The service anonymizes the collected data immediately after collection and provides us with the anonymized data in the form of statistics for evaluation. We use these statistics for troubleshooting and further development of our website. The data on your device is stored for up to two years. The legal basis for data processing is the legitimate interest (absolute technical necessity for the provision and delivery of the service “website” expressly requested by you by your call) pursuant to Art. 6 para. 1 lit. f GDPR. The legal basis for the transfer to New Zealand is the implementing decision of the EU Commission 2013/65/EU.

Targeting / Profiling / Advertising

Facebook Pixel

In the event that you give your consent, we process your personal data together with the service Facebook Pixel, Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland as joint controllers of your personal data for the purpose of displaying personalized advertising and measuring our advertising success. Not granting consent has no direct impact on the functionality of the website, however, if consent is not given, we are unable to display personalized advertising on your devices. You can revoke consent already given by privacy settings changing it. We enable the service to collect connection data, data from your web browser, and data about the content accessed. In addition, we enable the service to execute tracking and recognition software as well as to store data on your device. With the tracking and recognition software, the service is then able to enrich its advertising network and recognize you when you visit third-party websites or display personalized advertising. We also use the collected data to measure our advertising success. The data on your device is stored for up to two years. The legal basis for data processing is your consent according to Art. 6 para. 1 lit. a GDPR. The Facebook group transfers your personal data to the USA. The legal basis for data transfer to the USA is your consent according to Art. 49 para. 1 lit. a in conjunction with Art. 6 para. 1 lit. a GDPR in connection with §25 TTDSG. You were already informed before giving your consent that the USA does not have a level of data protection equivalent to EU standards. In particular, US intelligence agencies can access your data without informing you and without you being able to take legal action against it. For this reason, the European Court of Justice declared the previous adequacy decision (Privacy Shield) invalid in a ruling.

Right to object

If the processing of your personal data is based on legitimate interest, you have the right to object to this processing. If there are no compelling legitimate grounds for processing on our part, the processing of your data on this legal basis will be discontinued. You also have the right to object to the processing of your personal data for direct marketing purposes. In the event of an objection, your personal data will no longer be processed for direct marketing purposes. The lawfulness of the data processed up to the objection is not affected by the objection.

Right of withdrawal

You have the right to withdraw consent already given at any time by privacy settings changing it. In the case of consent to receive electronic advertising, you can withdraw your consent by clicking on the unsubscribe link. In this case, processing will be discontinued unless there is another legal basis. The lawfulness of the data processed up to the withdrawal is not affected by the withdrawal.

Data subject rights

You also have the right to access, rectification, erasure, and restriction of the processing of personal data. If the legal basis for processing your personal data is your consent or a contract concluded with you, you also have the right to data portability. Furthermore, you have the right to lodge a complaint with the supervisory authority. More information about supervisory authorities in the European Union can be found here.

Privacy Policy for Tiktok

TikTok Pixel

When visiting this website, personal data is processed. Categories of data processed: data about the use of the website as well as the logging of clicks on individual elements. Purpose of processing: analysis of usage behavior, analysis of the effectiveness of online marketing measures, and selection of online advertising on other platforms, which is automatically selected using real-time bidding based on usage behavior. The legal basis for processing: your consent according to Art. 6 (1) a GDPR. Data is transferred to: the independent controller TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (https://www.tiktok.com). The legal basis for the data transfer to TikTok Technology Limited is your consent according to Art. 6 (1) a GDPR. This may also involve the transfer of personal data to a country outside the European Union. The transfer of data is based on your consent pursuant to Art. 6 para 1 lit a in conjunction with Art. 49 para 1 lit a GDPR. For email contact with the data protection officer of TikTok Technology LimitedFor email contact with the data protection officer of TikTok Technology Limited: For email contact with the data protection officer of TikTok Technology LimitedFor email contact with the data protection officer of TikTok Technology Limited:
https://www.tiktok.com/legal/report/DPO. For email contact with the data protection officer of TikTok Technology Limited:
https://www.tiktok.com/legal/privacy-policy-eea?lang=de. Duration of processing: is variable and ends when the purpose of processing ceases.

en_USEnglish