Privacy Policy

This policy explains which personal data is processed when you use https://www.pedalia.at, for what purposes, on what legal basis, and what rights you have.

Last updated: 01.09.2026

1. Controller

1.1. The controller within the meaning of the General Data Protection Regulation (GDPR) is the media owner and service provider named in the Imprint. The email address given there is also the contact address for all data protection matters.

1.2. No data protection officer has been appointed, as the conditions of Art. 37 GDPR are not met.

2. What data we process

Account and registration

2.1. On registration we process your name, email address and password. The password is stored solely as a cryptographic hash and is not readable by us. We also store the time your email address was confirmed, the time of your last login, and the IP address used for it.

2.2. For commercial accounts we additionally process the company name, address, contact details, VAT number and the information submitted during verification.

Listings

2.3. Content you publish yourself — in particular descriptions, prices, images, condition details and location information — is publicly accessible by design. Please do not publish anything you do not want to be public, and obscure third parties' personal data in images.

2.4. Price changes to a listing are recorded. That record is necessary in order to comply with statutory requirements on announcing price reductions.

Messages

2.5. Messages you send to other users via the platform are stored so that they can be delivered and read by the people involved. They may be examined in order to investigate abuse reports and to comply with legal obligations.

Payments

2.6. For paid subscriptions taken out by commercial providers we use an external payment service provider. Complete payment card details are processed exclusively there and never reach us. We receive only the information needed to perform the contract, in particular payment status, card brand, the last four digits and the billing data.

Server logs

2.7. When the site is accessed, the IP address, time, address requested, volume of data transferred, status code, referrer and browser identifier are processed for technical reasons. This data is necessary for operating the service, diagnosing faults and defending against attacks.

Protection against misuse

2.8. To defend the login and registration forms against automated access we use a bot detection service. To limit request frequency we also evaluate the IP address and browser identifier.

3. Purposes and legal bases

3.1. Providing the user account, publishing listings, delivering messages and administering subscriptions: performance of the user contract pursuant to Art. 6(1)(b) GDPR.

3.2. Operating, securing and stabilising the platform, defending against misuse and fraud, and pursuing breaches of our terms: legitimate interest pursuant to Art. 6(1)(f) GDPR in a functioning and secure service.

3.3. Compliance with legal obligations, in particular commercial and tax retention duties and the obligations under Regulation (EU) 2022/2065: Art. 6(1)(c) GDPR.

3.4. Audience measurement using analytics services: solely on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 165 TKG 2021. Without consent these services are not loaded and set no cookies.

3.5. Sending emails in the course of your use of the service, for example to confirm your email address, reset your password or notify you of status changes: Art. 6(1)(b) GDPR.

4. Recipients and processors

4.1. We disclose personal data only where this is necessary to provide the service, where you have consented, or where we are legally obliged to. Contracts under Art. 28 GDPR are in place with all processors.

Hosting and server operation

4.2. The platform is operated with Hetzner Online GmbH, Industriestrasse 25, 91710 Gunzenhausen, Germany; the servers are located in data centres within the European Union. Email is sent via the same provider's infrastructure; no additional mail delivery service is used.

Payment processing

4.3. We use Stripe to administer subscriptions. The contracting party within the European Union is Stripe Payments Europe Ltd., established in Ireland. Processing by the US parent company cannot be excluded; such transfers are based on the EU-US Data Privacy Framework and additionally on standard contractual clauses.

Bot detection

4.4. We use Google reCAPTCHA to protect the login and registration forms. The provider for users in the European Economic Area is Google Ireland Limited. IP address, browser identifier and interaction data are transmitted to Google; transfer to the USA cannot be excluded and is based on the EU-US Data Privacy Framework.

Audience measurement

4.5. Only with your consent do we use Google Analytics. The provider for users in the European Economic Area is Google Ireland Limited. The IP address is processed in truncated form. Without consent the service is not loaded; consent once given can be withdrawn at any time via the cookie settings.

Authorities and legal proceedings

4.6. Disclosure to courts, authorities or legal representatives takes place only where we are legally obliged to do so or where it is necessary to establish, exercise or defend legal claims.

5. Retention

5.1. We store personal data only for as long as is necessary for the relevant purposes or as required by statutory retention obligations. Because that necessity depends on the purpose, the criteria determining the period are set out below.

5.2. Account and profile data is stored for the duration of the user relationship. After it ends, the data is erased or its processing restricted, unless a retention obligation or a need to defend legal claims requires otherwise.

5.3. Listings are removed from public view when they are deactivated, expire or are deleted. Records may be kept beyond that point for evidentiary purposes, in particular to handle notices and complaints under Regulation (EU) 2022/2065.

5.4. Messages are stored for as long as they are needed for communication between the people involved and for investigating any abuse reports.

5.5. Invoice and payment data is subject to commercial and tax retention obligations, in particular under § 212 UGB and § 132 BAO, and is retained for seven years.

5.6. Server logs are stored only for as long as is necessary for operation, fault diagnosis and security, and are then deleted or anonymised.

6. Your rights

6.1. Under the GDPR you have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object (Art. 21).

6.2. Where processing is based on consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal is unaffected.

6.3. To exercise these rights, an informal message to the email address given in the Imprint is sufficient. Requests to delete your account are accepted by that route and handled within the statutory period of one month. We may ask for additional information where this is necessary to establish your identity.

6.4. Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna.

7. Cookies and similar technologies

7.1. Strictly necessary cookies are required for the site to work. These include in particular the session cookie for logged-in users, cookies securing forms, and the cookie storing your cookie choices. They are set without consent on the basis of § 165(3) TKG 2021.

7.2. All other cookies, in particular those used for audience measurement, are set only after your express consent. The service concerned is not loaded without consent.

7.3. You can change or withdraw your choices at any time via the “Cookie settings” link at the foot of the page. You can also delete cookies in your browser or restrict their storage generally; the site may not work fully as a result.

8. Whether providing data is required

8.1. Providing your data is neither legally nor contractually required. However, without the information requested at registration we cannot maintain a user account, and without the information a listing requires it cannot be published.

8.2. No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Decisions to remove or restrict content are not taken on a solely automated basis.

9. Data about bicycle businesses that we did not collect from them

9.1. We prepare a Pedalia shop profile for bicycle businesses in Austria before we contact them. That data is therefore not collected from the business itself — the paragraphs below are the information required by Art. 14 GDPR.

9.2. The data processed is: the company name, address, phone number, email address, website and logo of the business, a contact person published on its website, and details of the bikes offered there (title, description, price, images and technical data).

9.3. The source is exclusively the publicly accessible website of the business concerned, together with publicly accessible business directories and map services. We collect no data from non-public sources and no special categories of personal data.

9.4. The purpose is to prepare a dealer profile and to contact the business about it. The legal basis is our legitimate interest in assembling a complete Austrian bicycle marketplace and in approaching potential partner businesses (Art. 6(1)(f) GDPR). Once a business claims its profile, we rely on performance of a contract for any further processing (Art. 6(1)(b) GDPR).

9.5. Until it is claimed, none of it is publicly visible: neither the prepared profile nor the prepared listings appear on the marketplace, in search, or in search engines. Nothing becomes visible until the business has claimed its profile and published it itself.

9.6. We do not pass this data on to third parties. If a business is never contacted, or does not respond, we delete the prepared data after 24 months at the latest.

9.7. Any business may object to this processing at any time (Art. 21 GDPR) and request deletion — through the link in our invitation email, with no account and no reason required, or informally by email to us. We then delete the prepared listings, the prepared profile and the underlying data. The only thing retained is the email address, and solely for the purpose of not writing to that business again.

10. Changes to this policy

10.1. We update this privacy policy when our processing changes or when an update becomes legally necessary. The version published on this page is the one that applies.