Data Protection Policy

Document Owner: FAB L’Style
Last Updated: August 2026
Version: 1.0

1. Purpose and Scope

1.1 Purpose

The purpose of this Data Protection Policy is to establish a clear framework for the processing of personal data by FAB L’Style KG (“the Company”, “we”, “us”, or “our”). This policy ensures that the Company complies with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the Austrian Data Protection Act (Datenschutzgesetz 2018 – DSG).

1.2 Scope

This policy applies to:

  • All employees, contractors, and third-party service providers who process personal data on behalf of the Company.
  • All personal data processed by the Company, regardless of the medium (electronic, paper, or otherwise).
  • All data processing activities carried out in connection with the Company’s operations, including but not limited to:
    • Website operations (https://fablstyle.com)
    • Customer and client relations
    • Marketing and communications
    • Human resources management
    • Supplier and vendor management

2. Definitions

TermDefinition
Personal DataAny information relating to an identified or identifiable natural person (“data subject”).
ProcessingAny operation performed on personal data, including collection, storage, use, disclosure, and deletion.
Data ControllerThe entity that determines the purposes and means of processing personal data. FAB L’Style KG is the Data Controller.
Data ProcessorThe entity that processes personal data on behalf of the Controller.
Data SubjectThe identified or identifiable natural person whose personal data is processed.
Supervisory AuthorityThe Austrian Data Protection Authority (Österreichische Datenschutzbehörde – DSB).

3. Data Protection Principles

The Company adheres to the following data protection principles set out in Article 5 GDPR:

PrincipleOur Commitment
Lawfulness, Fairness, and TransparencyWe process personal data lawfully, fairly, and in a transparent manner. Data subjects are informed about how their data is used through our Privacy Policy.
Purpose LimitationWe collect personal data for specified, explicit, and legitimate purposes and do not process it further in a manner incompatible with those purposes.
Data MinimisationWe collect only the personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
AccuracyWe take reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date.
Storage LimitationWe retain personal data only for as long as necessary for the purposes for which it is processed.
Integrity and Confidentiality (Security)We process personal data in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
AccountabilityWe are responsible for, and able to demonstrate, compliance with these principles.

4. Lawful Bases for Processing

Under Article 6 GDPR, we rely on the following lawful bases for processing personal data:

Lawful BasisApplication
Consent (Art. 6(1)(a))Where the data subject has given clear, informed, and unambiguous consent for a specific purpose (e.g., marketing communications, non-essential cookies).
Contract (Art. 6(1)(b))Where processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract.
Legal Obligation (Art. 6(1)(c))Where processing is necessary for compliance with a legal obligation to which the Company is subject (e.g., tax and accounting records).
Legitimate Interests (Art. 6(1)(f))Where processing is necessary for the purposes of the legitimate interests pursued by the Company or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject (e.g., spam prevention, website security, direct marketing to existing customers).

5. Data Subject Rights

The Company respects and facilitates the exercise of all data subject rights under the GDPR. Data subjects have the right to:

RightDescriptionGDPR Article
Right of AccessTo obtain confirmation as to whether personal data concerning them is being processed, and access to that data.Art. 15
Right to RectificationTo obtain the rectification of inaccurate personal data.Art. 16
Right to Erasure (“Right to be Forgotten”)To obtain the deletion of personal data under certain circumstances.Art. 17
Right to Restriction of ProcessingTo obtain restriction of processing under certain circumstances.Art. 18
Right to Data PortabilityTo receive personal data in a structured, commonly used, and machine-readable format and have it transmitted to another controller.Art. 20
Right to ObjectTo object, on grounds relating to their particular situation, to processing based on legitimate interests.Art. 21
Right to Withdraw ConsentTo withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.Art. 7(3)
Right to Lodge a ComplaintTo lodge a complaint with a supervisory authority (in Austria, the Datenschutzbehörde).Art. 77

Procedure for Handling Data Subject Requests:

  1. All requests must be directed to the Data Protection Officer (DPO) or the designated contact person.
  2. Requests must be acknowledged within 5 working days.
  3. The request must be responded to within one month of receipt.
  4. The response must be provided in a clear, plain, and accessible format.
  5. The request is free of charge unless the request is manifestly unfounded, excessive, or repetitive.

6. Data Security

6.1 Technical and Organisational Measures (TOMs)

The Company implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These include:

  • Access Controls: Role-based access restrictions to personal data.
  • Encryption: Encryption of data in transit (SSL/TLS) and at rest where appropriate.
  • Authentication: Strong password policies and multi-factor authentication for critical systems.
  • Backup and Recovery: Regular backups and disaster recovery procedures.
  • Monitoring and Logging: Audit trails and monitoring of access to personal data.
  • Staff Training: Regular data protection and security awareness training for all employees.
6.2 Data Protection by Design and by Default

The Company integrates data protection principles into the design of new systems, processes, and services (Article 25 GDPR). This includes:

  • Implementing privacy-friendly default settings.
  • Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
  • Minimising the collection and retention of personal data.

7. Data Breach Management

7.1 Definition

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

7.2 Breach Response Procedure
StepActionResponsible PartyTimeline
1. IdentificationIdentify and contain the breach.IT/Security TeamImmediately
2. AssessmentAssess the nature, scope, and potential impact of the breach.DPO / Data Protection TeamWithin 24 hours
3. Notification to Supervisory AuthorityNotify the Austrian Data Protection Authority (Datenschutzbehörde) without undue delay and, where feasible, not later than 72 hoursafter becoming aware of the breach (unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons).DPOWithin 72 hours
4. Communication to Data SubjectsCommunicate the breach to affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.DPO / Communications TeamAs soon as reasonably possible
5. DocumentationDocument all facts relating to the breach, its effects, and the remedial action taken.DPOOngoing
6. Review and ImprovementReview the breach and implement measures to prevent recurrence.Data Protection TeamWithin 30 days of resolution
7.3 Breach Log

All personal data breaches must be documented in a central breach log, regardless of whether they are reported to the supervisory authority.

8. Data Retention and Disposal

8.1 Retention Principles
  • Personal data shall be retained only for as long as necessary for the purposes for which it was collected.
  • Retention periods are determined based on legal, regulatory, and operational requirements.
  • When data is no longer needed, it shall be securely deleted or anonymised.
8.2 Retention Schedule (Summary)
Data CategoryRetention Period
Comments and metadataIndefinitely (to automatically recognise and approve follow-up comments)
User account informationFor as long as the account remains active
Contact form submissionsReasonable period to respond to enquiries and for record-keeping
Cookie consent preferencesUp to 12 months
Analytics dataIn accordance with the retention policies of the analytics provider
Employee recordsDuration of employment + statutory retention periods (e.g., 7 years for tax records)
Customer/Client recordsDuration of the business relationship + statutory retention periods
8.3 Secure Disposal
  • Electronic Data: Deletion using secure deletion software or physical destruction of storage media.
  • Paper Records: Shredding or incineration.

9. Data Processing Agreements (DPAs)

9.1 Requirement

Where the Company engages a third-party Data Processor, a written Data Processing Agreement (DPA) must be in place prior to any processing activity, as required by Article 28 GDPR.

9.2 Content of DPA

The DPA must include, at a minimum:

  • The subject matter and duration of the processing.
  • The nature and purpose of the processing.
  • The type of personal data and categories of data subjects.
  • The obligations and rights of the Controller.
  • The Processor’s obligations regarding security, sub-processing, data subject rights, and breach notification.
9.3 Sub-Processing

The Processor must not engage another Processor (sub-processor) without prior specific or general written authorisation from the Company. Where general authorisation is given, the Processor shall inform the Company of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Company the opportunity to object.

10. Roles and Responsibilities

RoleResponsibility
Data Protection Officer (DPO) / Data Protection Lead• Monitoring compliance with the GDPR and this policy
• Advising on Data Protection Impact Assessments (DPIAs)
• Serving as the point of contact for the supervisory authority and data subjects
• Managing data breach notifications and data subject requests
All Employees• Complying with this policy and data protection principles
• Reporting any suspected data breaches immediately
• Attending mandatory data protection training
• Ensuring personal data is handled securely and confidentially
IT / Security Team• Implementing and maintaining technical security measures
• Responding to security incidents and breaches
• Managing access controls and system audits
Management• Ensuring adequate resources for data protection compliance
• Approving high-risk processing activities
• Fostering a culture of data protection awareness

11. Training and Awareness

11.1 Mandatory Training

All employees and contractors who process personal data must complete mandatory data protection training:

  • Initial Training: Within the first month of employment or engagement.
  • Refresher Training: Annually thereafter.
11.2 Training Content

Training covers:

  • The principles of data protection.
  • The rights of data subjects.
  • The Company’s policies and procedures.
  • How to identify and respond to data breaches.
  • Security best practices.
11.3 Record Keeping

Training attendance and completion records shall be maintained.

12. Monitoring, Audits, and Compliance

12.1 Internal Audits

The Company shall conduct regular internal audits of its data processing activities to ensure compliance with this policy and applicable laws.

12.2 Review of this Policy

This Data Protection Policy shall be reviewed at least annually or whenever there is a significant change in the Company’s processing activities, legal requirements, or regulatory guidance.

12.3 Non-Compliance

Failure to comply with this policy may result in disciplinary action, up to and including termination of employment or contract, and may expose the individual and the Company to legal liability and regulatory fines.

13. Contact Information

For any questions, concerns, or requests regarding this Data Protection Policy or data protection matters generally, please contact:

FAB L’Style
Wimmergasse 24/2-3
1050 Vienna, Austria
Email: office@fablstyle.com
Phone: +43 664 3404183
Commercial Register: FN 466 975 d (Handelsgericht Wien)

Data Protection Officer (DPO) Contact:
Email: dpo@fablstyle.com (Note: If this email is not yet active, please use office@fablstyle.comand mark the subject as “FAO: Data Protection Officer”.)

Supervisory Authority (Austria)

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna, Austria
Website: https://www.dsb.gv.at
Email: dsb@dsb.gv.at

14. Document Control

VersionDateAuthorChanges
1.0August 2026FAB L’Style KGInitial version

Translate »