| Website | montenegroclimbingguidebook.com |
| Effective date | 28.09.2026 |
This Privacy Policy explains how personal data is collected, used, and protected when you visit montenegroclimbingguidebook.com (the “Website”) or place an order through it. It is written in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Austrian Data Protection Act (Datenschutzgesetz, “DSG”).
1. Controller
The controller responsible for the processing of personal data on this Website is:
Valentin Sattek
Marktstraße 10 Top 1
9584 Finkenstein am Faaker See, Austria
Email: valentin.sattek@gmail.com
Phone: +43 664 1356311
2. General information
We process personal data only where there is a legal basis for doing so, and only to the extent necessary for the purpose concerned. “Personal data” means any information relating to an identified or identifiable natural person. This policy describes each processing activity, its purpose, and its legal basis under Article 6 GDPR.
3. Web hosting and server log files
Our Website is hosted externally by a third-party service provider acting as a data processor. The provider of these hosting services is Hostinger Operations, UAB, Švitrigailos g. 34, Vilnius, LT-03230, Lithuania.
Personal data collected on this Website is stored on secure infrastructure. The physical data centre used for our Website is located in Frankfurt am Main, Germany. Hostinger maintains strict technical and organisational security measures to safeguard this data in alignment with the General Data Protection Regulation (GDPR).
When you access the Website, the hosting infrastructure automatically records technical information in server log files, including your IP address, the date and time of access, the page requested, the referring URL, and information about your browser and operating system.
Purpose: ensuring a stable, secure, and correctly functioning website.
Legal basis: our legitimate interest in the secure and efficient operation of the Website (Art. 6(1)(f) GDPR).
Hostinger acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
4. Cookies
This Website uses only cookies that are technically necessary for its operation — for example, to maintain your shopping cart and session during the ordering process. These cookies do not require consent (Art. 6(1)(f) GDPR).
We do not use analytics, tracking, advertising, or social-media cookies.
Payment providers (Stripe, PayPal) may set their own cookies during checkout; see Section 6.
5. Placing an order (WooCommerce)
When you place an order, we process the data you enter, including your first and last name, billing and shipping address, email address and — where provided — telephone number, together with the details of the products ordered and the order total.
Purpose: processing and fulfilling your order, arranging shipping, handling any return or withdrawal, and meeting our statutory obligations.
Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR); and compliance with legal obligations, in particular retention duties under tax and commercial law (Art. 6(1)(c) GDPR).
The order function is provided by the WooCommerce plugin, which stores this data within the Website’s own database on the hosting infrastructure described in Section 3.
6. Payment processing
Depending on the payment method you choose, your payment data is processed by the relevant payment service provider. We do not store full credit card details ourselves.
Credit / debit card, Apple Pay, Google Pay (Stripe): processed by Stripe Payments Europe, Ltd., One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland, and, where applicable, Stripe, Inc. (United States). Stripe’s own privacy notice is available at stripe.com/privacy.
PayPal: processed by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. PayPal’s own privacy statement is available on paypal.com.
Bank transfer / prepayment (Vorkasse): your name, order reference, and the fact of payment are processed by us and our bank in order to reconcile the incoming payment.
Purpose: processing your payment.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); and our legitimate interest in secure payment and fraud prevention (Art. 6(1)(f) GDPR).
Stripe and PayPal act as independent controllers for parts of this processing; their own privacy notices apply in addition to this one. Data may be transferred to the United States (see Section 11).
7. Contact form
If you use the contact form on the Website, we process the name, email address, and message you provide.
Purpose: receiving and answering your enquiry.
Legal basis: our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR); and, where your enquiry concerns a contract or its initiation, performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
The contact form is provided by the SureForms plugin and stores submissions within the Website’s own database; a notification email is sent to us. Enquiry data is kept only for as long as needed to deal with your request and any follow-up, after which it is deleted, unless statutory retention periods apply.
8. Product reviews
Reviews can be submitted only by customers who have purchased the product. If you submit a review, we process the name you provide and the content of the review, which is then published on the relevant product page.
Purpose: displaying genuine customer reviews.
Legal basis: your consent, given by submitting the review (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.
9. Website security (Wordfence)
We use the Wordfence security plugin on our Website, operated by Defiant, Inc., 800 5th Ave, Suite 4100, Seattle, WA 98104, USA (“Defiant”). Wordfence protects our Website against cyberattacks, malware, and unauthorised access (for example brute-force attacks).
To detect and defend against threats, the plugin processes technical data of Website visitors. On each page request it records, among other things, your IP address, the date and time of access, the URL requested, the user agent (browser and operating system), and any error messages. To verify user permissions and identify attackers, Wordfence also sets technically necessary cookies.
Suspicious IP addresses and attack data are transmitted to Defiant’s global security network (Threat Defense Feed) in order to update its firewall database and to protect our Website and others pre-emptively.
Legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in ensuring IT security and stability and in defending against malicious access to our online presence.
The data collected is transferred to Defiant’s servers in the United States and processed there; the safeguards applied are set out in Section 11. Further information can be found in Defiant’s privacy policy at wordfence.com/privacy-policy.
In addition, data transmitted between your browser and the Website is encrypted in transit using current TLS/SSL standards.
10. Caching and performance (LiteSpeed)
The Website uses the LiteSpeed Cache plugin to improve loading times. Caching is performed on the hosting infrastructure described in Section 3; no external content delivery network is used.
11. Transfers to third countries
Some of the providers named above are established in, or transfer data to, the United States. Such transfers take place on the basis of appropriate safeguards under Chapter V GDPR. The safeguards applied to each provider are set out below.
Stripe — data transfer and safeguards. While Stripe’s European entity handles EU data initially, data may be transferred to Stripe, Inc. in the United States. Stripe, Inc. is certified under the EU–U.S. Data Privacy Framework (DPF), which establishes a recognised adequate level of data protection under the GDPR. Stripe is also certified as a PCI Service Provider Level 1, enforcing advanced physical and electronic data encryption.
PayPal — data transfer and safeguards. For cross-border data flows or infrastructure sharing outside the European Economic Area (EEA), including to PayPal, Inc. in the United States, PayPal relies on EU-approved Binding Corporate Rules (BCRs). These rules legally obligate all PayPal corporate entities to adhere to strict GDPR-equivalent privacy standards regardless of their geographic location.
Wordfence — data transfer and safeguards. For data transfers to the United States, we rely on the standard Data Processing Addendum (DPA) provided by Defiant, Inc., which incorporates the EU Standard Contractual Clauses to ensure an adequate level of data protection. Wordfence Free processes only the minimum data required to protect the Website infrastructure.
12. Recipients
Personal data is disclosed only where necessary: to the processors and providers named above (hosting, payment, security); to the shipping service provider for the delivery of your order (Österreichische Post AG); to our tax advisor and the tax authorities within the scope of our statutory obligations; and where we are otherwise legally required to do so.
13. Retention
We retain personal data only for as long as necessary for the purposes described, or as required by law. Data relating to orders, invoices, and payments is retained for the statutory period under Austrian tax and commercial law (as a rule seven years pursuant to § 132 of the Federal Fiscal Code, and longer in certain cases). Contact enquiries and other data are deleted once they are no longer needed.
14. Your rights
Under the GDPR, you have the right to:
- request access to your personal data (Art. 15);
- request rectification of inaccurate data (Art. 16);
- request erasure (Art. 17);
- request restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21); and
- withdraw any consent you have given, with effect for the future (Art. 7(3)).
To exercise these rights, please contact us using the details in Section 1.
15. Right to lodge a complaint
If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with the Austrian supervisory authority:
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
Website: dsb.gv.at
16. Obligation to provide data
For the conclusion and performance of a purchase contract, you must provide the data required for the order and delivery; without it, we cannot process your order. Providing data via the contact form is voluntary.
17. No automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
18. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to the Website or to legal requirements. The current version is always available on the Website.