Legal

Privacy Policy

This policy explains what personal data we process, for what purposes, on what legal basis – and what rights you have.

Introduction and overview

We have written this privacy policy (version 28 July 2026) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Austrian Data Protection Act (DSG), what personal data we process, how we process it, the legal bases on which we rely, and the rights you have.

The protection of your personal data is important to us. We process data only on a valid legal basis, in a transparent, fair and secure manner, and we limit processing to what is necessary for the respective purpose. As some matters are inherently technical, a glossary of the most important terms is provided at the end of this policy.

Scope

This privacy policy applies to all personal data processed by us on this website and on any related subdomains, and – to the extent described – to data processed when you contact us by email, phone or post. It does not apply to other websites or services of third parties that we merely link to.

Controller

The controller within the meaning of the GDPR is:

Weingut Mantlerhof GmbH & Co KG, Hauptstraße 50, 3494 Gedersdorf, Austria

Phone: +43 (0)2735 8248 · Email: weingut@mantlerhof.com

Commercial register number: FN 663337x · Commercial register court: Landesgericht Krems an der Donau

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data. For data protection enquiries you can reach us at any time at weingut@mantlerhof.com.

Legal bases for processing

We process personal data only on a valid legal basis under Art. 6(1) GDPR:

  • Consent (Art. 6(1)(a)) – where you have given us permission for a specific purpose. You may withdraw consent at any time with effect for the future.
  • Contract / pre-contractual steps (Art. 6(1)(b)) – where processing is needed to perform a contract with you or to take steps at your request before entering into one, e.g. to handle an order in our online shop.
  • Legal obligation (Art. 6(1)(c)) – where the law requires us to process or retain data, in particular tax and commercial record-keeping obligations.
  • Legitimate interest (Art. 6(1)(f)) – where processing serves a legitimate interest, e.g. the secure, stable and efficient operation of this website, and your interests do not override it.

How we collect your data

We receive personal data in two ways: (1) data you actively provide to us – for example when you write to us or place an order in the online shop; and (2) data collected automatically and for technical reasons when you visit the website – in particular server log data and information stored on or read from your device by technically necessary cookies.

Where information is stored on or read from your device, § 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) additionally applies. The national law supplementing the GDPR in Austria is the Data Protection Act (DSG).

Purposes of processing and data minimisation

We process personal data only for clearly defined purposes: providing and securing this website, handling orders and enquiries, and fulfilling our legal obligations. We follow the principle of data minimisation – we collect only the data we actually need, we do not sell your data, and we do not use it for purposes incompatible with those stated here.

Web hosting

This website is hosted on servers located within the European Union. Our hosting provider processes the data needed to deliver the site (see Server log files) as our processor under a data-processing agreement pursuant to Art. 28 GDPR. Legal basis: our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). As the servers are located in the EU, no third-country transfer occurs through hosting.

Hosting provider: Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany; server location Falkenstein (Germany), within the EU/EEA.

Server log files

On each request the server automatically processes: IP address, date and time, the requested page/file, the HTTP status code, the volume of data transferred, the referrer URL, and browser type, version and operating system. This data is used solely for secure, error-free operation and abuse defence (Art. 6(1)(f) GDPR), is not merged with other data sources, and is deleted or anonymised after 7 to 14 days.

Cookies

Cookies are small text files that a website stores on your device via your browser. They can be “session cookies” (deleted when you close the browser) or “persistent cookies”, and they can be set by us (“first-party”) or by third parties (“third-party”).

This website uses technically necessary cookies required for its secure operation – in particular to manage your shopping cart. To obtain, manage and document your consent to non-essential cookies, we use the consent-management tool CookieShield; you can call up and change your cookie settings at any time via the “Cookies” link in the footer (§ 165(3) TKG 2021; Art. 6(1)(a) GDPR). Disabling necessary cookies may limit the functionality of the website.

When you complete the ordering process, you are redirected to the secure checkout page of our shop provider, Shopify. Cookies set there are subject to Shopify’s responsibility (see “Online shop and order processing”).

Web analytics (PostHog)

To improve what we offer, we use the analytics tool PostHog. It records which pages are opened, how long a visit lasts and which features are used — for example opening a wine description or adding an item to the basket. This involves a pseudonymous identifier, technical connection data and details about your browser, operating system and approximate region. We do not combine this data with other sources and do not use it to identify you personally.

PostHog is only loaded after your explicit consent. The legal basis is Art. 6(1)(a) GDPR in conjunction with § 165(3) of the Austrian Telecommunications Act 2021. Without consent the analytics script is not executed and no corresponding cookies are set or read. You can withdraw your consent at any time, with effect for the future, via the “Cookies” link in the footer.

We use PostHog's European instance; analytics data is processed on servers within the EU. The provider is PostHog, Inc., 2261 Market Street, San Francisco, CA 94114, USA, acting as our processor under Art. 28 GDPR. Where access from the United States occurs, it is based on Standard Contractual Clauses pursuant to Art. 46 GDPR. The analytics script is served from our own domain.

Fonts and third-party content

All fonts used on this website are self-hosted and delivered from our own EU server; no external font service (such as Google Fonts) is loaded. On the vast majority of pages, merely loading them therefore transmits no personal data to third parties. The exceptions are the contact page with its embedded map (see “Map service (Mapbox)”) and — only after your consent — web analytics.

Map service (Mapbox)

Our contact page embeds an interactive map provided by Mapbox so that you can locate us and plan a route. When you open that page, your browser loads the map directly from Mapbox servers. This transmits your IP address along with technical details about your browser, device and the map section displayed; without this transmission the map cannot be rendered.

The legal basis is our legitimate interest in providing clear directions (Art. 6(1)(f) GDPR). The provider is Mapbox, Inc., 740 15th Street NW, 5th Floor, Washington, DC 20005, USA. The transfer to the United States is based on Standard Contractual Clauses pursuant to Art. 46 GDPR. Details on Mapbox's processing are available at www.mapbox.com/legal/privacy.

If you wish to avoid this transmission, simply do not open the contact page: our address, telephone number and e-mail address are also listed in the imprint and in the footer of every page.

Contacting us

If you contact us by email or phone, we process your name, contact details and message in order to handle the enquiry. Legal basis: Art. 6(1)(b) GDPR where it concerns the initiation or performance of a contract, otherwise our legitimate interest in answering your enquiry (Art. 6(1)(f) GDPR). We delete this data once the enquiry has been fully handled, unless statutory retention obligations apply.

Withdrawal via our online form

On our “Withdraw from contract” page we provide consumers with a statutory withdrawal function (§ 13a FAGG). If you use the form, we process the data you provide – name, address, email address, order number, order or delivery date, and optional details on items and a message – in order to handle your withdrawal and confirm its receipt. Legal bases are Art. 6(1)(c) GDPR (compliance with our legal obligation) and Art. 6(1)(b) GDPR (reversal of the contract).

To send the statutorily required acknowledgement of receipt and the internal notification, we use the email service Amazon SES (Amazon Web Services). The provider is Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855 Luxembourg); sending takes place via the EU region (Frankfurt). Amazon Web Services processes the sending data as our processor pursuant to Art. 28 GDPR. Where processing by Amazon Web Services, Inc. (USA) takes place, it relies on the EU-US Data Privacy Framework and on Standard Contractual Clauses.

Online shop and order processing

Our online shop is operated via the Shopify platform. The provider is Shopify International Limited (2nd Floor, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland); depending on the processing, Shopify Inc. (151 O’Connor Street, Ground floor, Ottawa, Ontario, K2P 2L8, Canada) is also involved. Shopify provides the technical infrastructure of the shop and processes personal data as our processor under a data-processing agreement pursuant to Art. 28 GDPR.

When you visit the shop, fill your cart and place an order, Shopify processes the data required for this – in particular the order, billing and delivery data you provide (name, address, email address, phone number), the items ordered, and technical connection data. The order is completed (checkout) on a Shopify-hosted, TLS-encrypted page.

Legal bases are Art. 6(1)(b) GDPR (performance of the purchase contract), Art. 6(1)(c) GDPR (statutory retention obligations, see “Storage duration”) and Art. 6(1)(f) GDPR (secure and efficient shop operation and fraud prevention). Canada benefits from an adequacy decision of the European Commission; where processing takes place in the USA, it relies on the EU-US Data Privacy Framework and on Standard Contractual Clauses (see “Transfers to third countries”).

Shopify’s privacy policy is available at www.shopify.com/legal/privacy.

Payment processing

To pay for your order, the necessary payment and billing data is transmitted to the respective chosen payment provider. Payment is processed within the checkout provided by Shopify. Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (provision of secure and efficient payment methods).

Depending on the chosen payment method, the payment provider may process the data partly as our processor and partly as an independent controller – for example for fraud prevention and to meet its own regulatory obligations. We only pass on the data required to process the respective payment.

Ordering and customer account

If you place an order or create a customer account, we process the data required for the contract: name, billing and delivery address, email address, phone number, order and payment data and – in the case of an account – encrypted credentials. Legal bases are Art. 6(1)(b) GDPR (contract), Art. 6(1)(c) GDPR (statutory retention of invoices and business records for up to seven years under the BAO/UGB) and Art. 6(1)(f) GDPR (fraud prevention).

We share order data with the shipping or logistics company we commission, to the extent necessary for delivery (Art. 6(1)(b) GDPR). Account data is deleted once you close your account, unless retention obligations apply.

Content management system and admin area

This website runs on the content management system Payload CMS, hosted on our EU infrastructure. For authorised editors and administrators we process account data (name, email address, role), encrypted credentials, session and log data, and timestamps of changes – for user management, login, security and traceability. Legal bases are Art. 6(1)(b), (c) and (f) GDPR. This processing affects only CMS users, not ordinary visitors to the website.

Recipients and processors

We pass data to third parties only where necessary to run the website and the online shop, to meet legal obligations or to protect legitimate interests. Recipients may include: our hosting/infrastructure provider, the Shopify shop platform, the email-sending service Amazon SES (Amazon Web Services), payment providers, the shipping and logistics companies we commission, and authorities where legally required. We conclude data-processing agreements pursuant to Art. 28 GDPR with processors, ensuring instruction-bound, confidential processing and adequate technical and organisational measures.

In addition, the map service Mapbox (only when the contact page is opened) and — solely after your consent — the analytics service PostHog.

Transfers to third countries

We transfer personal data to countries outside the EU/EEA only with appropriate safeguards: on the basis of an adequacy decision (e.g. for Canada or under the EU-US Data Privacy Framework), on the basis of Standard Contractual Clauses (Art. 46 GDPR) or another safeguard under Chapter V GDPR. Such a transfer may occur in particular in connection with the operation of our online shop via Shopify (Canada/USA) and when sending emails via Amazon Web Services (USA). You can request a copy of the relevant safeguards from us.

A transfer to the United States may additionally occur when the contact page is opened (Mapbox) and — after your consent — in the context of web analytics (PostHog); both are safeguarded by Standard Contractual Clauses.

Storage duration

We store personal data only for as long as necessary for the respective purpose. Where statutory retention periods apply – for example up to seven years for tax and commercial records under the Federal Fiscal Code (BAO) and the Business Code (UGB) – we retain the relevant data for that period and restrict further processing. Server log data is deleted after 7 to 14 days, unless a specific security incident requires longer retention. Once the purpose ceases and no retention obligation applies, the data is deleted or anonymised.

Security of processing

We use appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access, alteration or disclosure – including access controls, role and rights concepts, encryption, secure passwords, logging and regular updates (Art. 32 GDPR). This website is transmitted over an encrypted HTTPS/TLS connection, recognisable by the lock symbol and “https://” in your browser’s address bar. Despite all care, transmission over the internet can have security gaps; complete protection against access by third parties is not possible.

Your rights as a data subject

Under the GDPR you have extensive rights. We respond to requests without undue delay and at the latest within one month.

  • Right of access (Art. 15) – you may ask whether and which data we process about you, and request a copy together with information on purposes, recipients, storage periods and the origin of the data.
  • Right to rectification (Art. 16) – you may have inaccurate data corrected and incomplete data completed.
  • Right to erasure (Art. 17) – you may request deletion of your data where there is no legal reason for continued processing.
  • Right to restriction of processing (Art. 18) – you may request that we limit processing, e.g. while the accuracy of data is verified.
  • Right to data portability (Art. 20) – for data you provided on the basis of consent or contract, you may request transmission in a structured, commonly used and machine-readable format.
  • Right to object (Art. 21) – on grounds relating to your particular situation, you may object at any time to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7(3)) – where processing is based on consent, you may withdraw it at any time with effect for the future; the lawfulness of prior processing is unaffected.
  • No automated decision-making (Art. 22) – you have the right not to be subject to a decision based solely on automated processing. We do not carry out such processing.

Right to lodge a complaint

If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with the supervisory authority. In Austria this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna · Phone +43 1 52 152-0 · Email dsb@dsb.gv.at · Web www.dsb.gv.at. You may also contact the supervisory authority of your EU country of residence.

Children's data

This website is not directed at children and we do not knowingly process the personal data of children. If we become aware that a child has provided data without the consent of a parent or guardian, we will delete it.

Changes to this privacy policy

We may update this policy as legal requirements, our processing activities or technical features change. The version published at the time of your visit applies. Last updated: 28 July 2026.

Questions about data protection

If you have any questions about this privacy policy or about how we process your personal data, please contact us at weingut@mantlerhof.com. We are happy to help.

Glossary of terms used

We have tried to keep this policy easy to read. To help, here are plain-language explanations of the key terms:

  • Personal data: any information relating to an identified or identifiable natural person – e.g. name, email address, IP address or location data.
  • Processing: any operation performed on personal data – collecting, storing, using, transmitting, erasing, etc.
  • Controller: the person or organisation that decides why and how personal data is processed (here: us).
  • Processor: a service provider that processes data on the controller’s behalf and on its instructions (e.g. our hosting provider or Shopify).
  • Data subject: the person whose data is processed – e.g. a visitor to this website.
  • Consent: a freely given, specific, informed and unambiguous indication of your agreement to a specific processing; it can be withdrawn at any time.
  • Third country: a country outside the EU/EEA.
  • Supervisory authority: the body monitoring compliance with data protection law – in Austria, the Data Protection Authority.