Document Owner: FAB L’Style
Last Updated: August 2026
Version: 1.0
1. Purpose and Scope
1.1 Purpose
The purpose of this Data Protection Policy is to establish a clear framework for the processing of personal data by FAB L’Style KG (“the Company”, “we”, “us”, or “our”). This policy ensures that the Company complies with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the Austrian Data Protection Act (Datenschutzgesetz 2018 – DSG).
1.2 Scope
This policy applies to:
- All employees, contractors, and third-party service providers who process personal data on behalf of the Company.
- All personal data processed by the Company, regardless of the medium (electronic, paper, or otherwise).
- All data processing activities carried out in connection with the Company’s operations, including but not limited to:
- Website operations (https://fablstyle.com)
- Customer and client relations
- Marketing and communications
- Human resources management
- Supplier and vendor management
2. Definitions
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person (“data subject”). |
| Processing | Any operation performed on personal data, including collection, storage, use, disclosure, and deletion. |
| Data Controller | The entity that determines the purposes and means of processing personal data. FAB L’Style KG is the Data Controller. |
| Data Processor | The entity that processes personal data on behalf of the Controller. |
| Data Subject | The identified or identifiable natural person whose personal data is processed. |
| Supervisory Authority | The Austrian Data Protection Authority (Österreichische Datenschutzbehörde – DSB). |
3. Data Protection Principles
The Company adheres to the following data protection principles set out in Article 5 GDPR:
| Principle | Our Commitment |
|---|---|
| Lawfulness, Fairness, and Transparency | We process personal data lawfully, fairly, and in a transparent manner. Data subjects are informed about how their data is used through our Privacy Policy. |
| Purpose Limitation | We collect personal data for specified, explicit, and legitimate purposes and do not process it further in a manner incompatible with those purposes. |
| Data Minimisation | We collect only the personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. |
| Accuracy | We take reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date. |
| Storage Limitation | We retain personal data only for as long as necessary for the purposes for which it is processed. |
| Integrity and Confidentiality (Security) | We process personal data in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage. |
| Accountability | We are responsible for, and able to demonstrate, compliance with these principles. |
4. Lawful Bases for Processing
Under Article 6 GDPR, we rely on the following lawful bases for processing personal data:
| Lawful Basis | Application |
|---|---|
| Consent (Art. 6(1)(a)) | Where the data subject has given clear, informed, and unambiguous consent for a specific purpose (e.g., marketing communications, non-essential cookies). |
| Contract (Art. 6(1)(b)) | Where processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract. |
| Legal Obligation (Art. 6(1)(c)) | Where processing is necessary for compliance with a legal obligation to which the Company is subject (e.g., tax and accounting records). |
| Legitimate Interests (Art. 6(1)(f)) | Where processing is necessary for the purposes of the legitimate interests pursued by the Company or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject (e.g., spam prevention, website security, direct marketing to existing customers). |
5. Data Subject Rights
The Company respects and facilitates the exercise of all data subject rights under the GDPR. Data subjects have the right to:
| Right | Description | GDPR Article |
|---|---|---|
| Right of Access | To obtain confirmation as to whether personal data concerning them is being processed, and access to that data. | Art. 15 |
| Right to Rectification | To obtain the rectification of inaccurate personal data. | Art. 16 |
| Right to Erasure (“Right to be Forgotten”) | To obtain the deletion of personal data under certain circumstances. | Art. 17 |
| Right to Restriction of Processing | To obtain restriction of processing under certain circumstances. | Art. 18 |
| Right to Data Portability | To receive personal data in a structured, commonly used, and machine-readable format and have it transmitted to another controller. | Art. 20 |
| Right to Object | To object, on grounds relating to their particular situation, to processing based on legitimate interests. | Art. 21 |
| Right to Withdraw Consent | To withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. | Art. 7(3) |
| Right to Lodge a Complaint | To lodge a complaint with a supervisory authority (in Austria, the Datenschutzbehörde). | Art. 77 |
Procedure for Handling Data Subject Requests:
- All requests must be directed to the Data Protection Officer (DPO) or the designated contact person.
- Requests must be acknowledged within 5 working days.
- The request must be responded to within one month of receipt.
- The response must be provided in a clear, plain, and accessible format.
- The request is free of charge unless the request is manifestly unfounded, excessive, or repetitive.
6. Data Security
6.1 Technical and Organisational Measures (TOMs)
The Company implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These include:
- Access Controls: Role-based access restrictions to personal data.
- Encryption: Encryption of data in transit (SSL/TLS) and at rest where appropriate.
- Authentication: Strong password policies and multi-factor authentication for critical systems.
- Backup and Recovery: Regular backups and disaster recovery procedures.
- Monitoring and Logging: Audit trails and monitoring of access to personal data.
- Staff Training: Regular data protection and security awareness training for all employees.
6.2 Data Protection by Design and by Default
The Company integrates data protection principles into the design of new systems, processes, and services (Article 25 GDPR). This includes:
- Implementing privacy-friendly default settings.
- Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
- Minimising the collection and retention of personal data.
7. Data Breach Management
7.1 Definition
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
7.2 Breach Response Procedure
| Step | Action | Responsible Party | Timeline |
|---|---|---|---|
| 1. Identification | Identify and contain the breach. | IT/Security Team | Immediately |
| 2. Assessment | Assess the nature, scope, and potential impact of the breach. | DPO / Data Protection Team | Within 24 hours |
| 3. Notification to Supervisory Authority | Notify the Austrian Data Protection Authority (Datenschutzbehörde) without undue delay and, where feasible, not later than 72 hoursafter becoming aware of the breach (unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons). | DPO | Within 72 hours |
| 4. Communication to Data Subjects | Communicate the breach to affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms. | DPO / Communications Team | As soon as reasonably possible |
| 5. Documentation | Document all facts relating to the breach, its effects, and the remedial action taken. | DPO | Ongoing |
| 6. Review and Improvement | Review the breach and implement measures to prevent recurrence. | Data Protection Team | Within 30 days of resolution |
7.3 Breach Log
All personal data breaches must be documented in a central breach log, regardless of whether they are reported to the supervisory authority.
8. Data Retention and Disposal
8.1 Retention Principles
- Personal data shall be retained only for as long as necessary for the purposes for which it was collected.
- Retention periods are determined based on legal, regulatory, and operational requirements.
- When data is no longer needed, it shall be securely deleted or anonymised.
8.2 Retention Schedule (Summary)
| Data Category | Retention Period |
|---|---|
| Comments and metadata | Indefinitely (to automatically recognise and approve follow-up comments) |
| User account information | For as long as the account remains active |
| Contact form submissions | Reasonable period to respond to enquiries and for record-keeping |
| Cookie consent preferences | Up to 12 months |
| Analytics data | In accordance with the retention policies of the analytics provider |
| Employee records | Duration of employment + statutory retention periods (e.g., 7 years for tax records) |
| Customer/Client records | Duration of the business relationship + statutory retention periods |
8.3 Secure Disposal
- Electronic Data: Deletion using secure deletion software or physical destruction of storage media.
- Paper Records: Shredding or incineration.
9. Data Processing Agreements (DPAs)
9.1 Requirement
Where the Company engages a third-party Data Processor, a written Data Processing Agreement (DPA) must be in place prior to any processing activity, as required by Article 28 GDPR.
9.2 Content of DPA
The DPA must include, at a minimum:
- The subject matter and duration of the processing.
- The nature and purpose of the processing.
- The type of personal data and categories of data subjects.
- The obligations and rights of the Controller.
- The Processor’s obligations regarding security, sub-processing, data subject rights, and breach notification.
9.3 Sub-Processing
The Processor must not engage another Processor (sub-processor) without prior specific or general written authorisation from the Company. Where general authorisation is given, the Processor shall inform the Company of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Company the opportunity to object.
10. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Data Protection Officer (DPO) / Data Protection Lead | • Monitoring compliance with the GDPR and this policy • Advising on Data Protection Impact Assessments (DPIAs) • Serving as the point of contact for the supervisory authority and data subjects • Managing data breach notifications and data subject requests |
| All Employees | • Complying with this policy and data protection principles • Reporting any suspected data breaches immediately • Attending mandatory data protection training • Ensuring personal data is handled securely and confidentially |
| IT / Security Team | • Implementing and maintaining technical security measures • Responding to security incidents and breaches • Managing access controls and system audits |
| Management | • Ensuring adequate resources for data protection compliance • Approving high-risk processing activities • Fostering a culture of data protection awareness |
11. Training and Awareness
11.1 Mandatory Training
All employees and contractors who process personal data must complete mandatory data protection training:
- Initial Training: Within the first month of employment or engagement.
- Refresher Training: Annually thereafter.
11.2 Training Content
Training covers:
- The principles of data protection.
- The rights of data subjects.
- The Company’s policies and procedures.
- How to identify and respond to data breaches.
- Security best practices.
11.3 Record Keeping
Training attendance and completion records shall be maintained.
12. Monitoring, Audits, and Compliance
12.1 Internal Audits
The Company shall conduct regular internal audits of its data processing activities to ensure compliance with this policy and applicable laws.
12.2 Review of this Policy
This Data Protection Policy shall be reviewed at least annually or whenever there is a significant change in the Company’s processing activities, legal requirements, or regulatory guidance.
12.3 Non-Compliance
Failure to comply with this policy may result in disciplinary action, up to and including termination of employment or contract, and may expose the individual and the Company to legal liability and regulatory fines.
13. Contact Information
For any questions, concerns, or requests regarding this Data Protection Policy or data protection matters generally, please contact:
FAB L’Style
Wimmergasse 24/2-3
1050 Vienna, Austria
Email: office@fablstyle.com
Phone: +43 664 3404183
Commercial Register: FN 466 975 d (Handelsgericht Wien)
Data Protection Officer (DPO) Contact:
Email: dpo@fablstyle.com (Note: If this email is not yet active, please use office@fablstyle.comand mark the subject as “FAO: Data Protection Officer”.)
Supervisory Authority (Austria)
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna, Austria
Website: https://www.dsb.gv.at
Email: dsb@dsb.gv.at
14. Document Control
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | August 2026 | FAB L’Style KG | Initial version |