Privacy Policy
Authorised representative
Alyssandra Singh (stage name)
Sandra Singh, BSc.
Sternwartestrasse 10/24
1180 Vienna
Austria
office@alyssandra-singh.com
Privacy Policy
1Controller
- 1.1
The controller responsible for data processing on this website is:
- 1.2
Sandra Singh, BSc. (stage name: Alyssandra Singh) – Sternwartestraße 10/24, 1180 Vienna, Austria
- 1.3
E-mail: office@alyssandra-singh.com
2Data Protection Officer
- 2.1
A data protection officer has not been appointed. The requirements of Art. 37 GDPR are not met:
- 2.2
Fewer than 250 employees
- 2.3
No large-scale processing of special categories of personal data (Art. 9 GDPR)
- 2.4
No regular and systematic large-scale monitoring of data subjects
3Fundamental Right to Data Protection
- 3.1
Every person has the fundamental right to the protection of personal data. This right is guaranteed by § 1 of the Austrian Data Protection Act (DSG, BGBl I No. 165/1999 as amended) as well as by the General Data Protection Regulation (GDPR, EU 2016/679). We treat personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
4Server Log Files
When you visit our website, information of a general nature is automatically collected. This data is stored in server log files. The following data is collected:
- 4.1
IP address (anonymised where technically possible)
- 4.2
Date and time of access
- 4.3
URL of the page requested
- 4.4
User agent (browser type and version, operating system)
- 4.5
Referrer URL (the previously visited page)
- 4.6
HTTP status code (success or error of the access)
- 4.7
Storage location: tmp/error.log (locally on the server)
- 4.8
Purpose: Ensuring IT security, defence against cyber attacks, analysis of server errors, maintaining the functionality of the website.
- 4.9
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in IT security and the error-free operation of the website).
- 4.10
Legitimate interest: The processing is necessary to safeguard our legitimate interest in ensuring the security and stability of our website.
- 4.11
Storage period: Server log files are stored for a maximum of 30 days and automatically deleted after this period has expired.
- 4.12
Recipients/categories of recipients: Hosting provider (processor) – server operation, storage of log files
5Cookies
- 5.1
General Information
- 5.1.1
Our website uses cookies. Cookies are small text files that are stored on your device when you visit our website. They make it possible to store certain information for a specific period of time and serve to make the website functional and user-friendly.
- 5.2
Cookies Used
- 5.2
We use the following cookies:
- 5.2.1
XID – Session identification (assignment of the server session, ensuring the functionality of the website) – lifetime: 100 days – technically necessary: yes – legal basis: Art. 6 (1) lit. f GDPR in conjunction with § 165 (3) TKG 2021
- 5.2.2
lang – Storage of the language setting (DE/EN) for displaying the website – lifetime: session – technically necessary: yes – legal basis: Art. 6 (1) lit. f GDPR in conjunction with § 165 (3) TKG 2021
- 5.2.3
darkmode – Storage of the UI setting (dark mode/light mode) – lifetime: session – technically necessary: yes – legal basis: Art. 6 (1) lit. f GDPR in conjunction with § 165 (3) TKG 2021
- 5.2.4
rtab – Storage of the tab status for the user interface – lifetime: session – technically necessary: yes – legal basis: Art. 6 (1) lit. f GDPR in conjunction with § 165 (3) TKG 2021
- 5.3
Legal Bases
- 5.3.1
Technically necessary cookies (Art. 6 (1) lit. f GDPR in conjunction with § 165 (3) TKG 2021): The cookies mentioned are required for the operation of our website. They serve to ensure the basic functionality of the website and therefore do not require consent. The legal basis is our legitimate interest in providing a functional and user-friendly website.
- 5.3.2
Non-technically necessary cookies: We currently do not use any cookies that are not technically necessary. Should this change, we will obtain your prior consent in accordance with § 165 TKG 2021 before such cookies are set.
- 5.4
Browser Settings
- 5.4.1
You can prevent or restrict the storage of cookies in your browser settings. Please note that in this case, not all functions of the website may be fully usable. You can also delete cookies at any time in your browser settings.
6Contact Form
When you use our contact form, we collect the following personal data:
- 6.1
Name – your full name
- 6.2
E-mail – your e-mail address
- 6.3
Message – the content of your message
- 6.4
Purpose: Processing of your contact enquiry.
- 6.5
Legal basis: Art. 6 (1) lit. b GDPR (processing for the performance of pre-contractual measures, in particular to respond to your enquiry).
- 6.6
Storage period: The data is stored until your enquiry has been fully processed and then deleted, unless there is a statutory retention obligation.
- 6.7
Recipients/categories of recipients: Sandra Singh, BSc. (controller – processing of the contact enquiry); e-mail service provider (processor – e-mail delivery).
7WhatsApp Contact
On our website you will find a link to contact us via WhatsApp (api.whatsapp.com).
- 7.1
Purpose: Provision of an alternative communication channel.
- 7.2
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in providing additional contact options).
- 7.3
Data flow: When you click on the WhatsApp link, your browser is redirected to the WhatsApp platform. In doing so, personal data (in particular IP address, user agent, referrer URL) may be transmitted to the operator.
- 7.4
Third-country transfer: When the WhatsApp page is accessed, personal data may be transmitted to Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) and, where applicable, to Meta Platforms, Inc. (1 Hacker Way, Menlo Park, CA 94025, USA). The USA is considered a third country without an adequacy decision of the European Commission for the entire country. However, Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework (DPF). The adequacy decision of the European Commission on the EU-US Data Privacy Framework (decision of 10.07.2023, C(2023) 4745 final) ensures an adequate level of protection in accordance with Art. 45 GDPR.
- 7.5
Recipients/categories of recipients: Meta Platforms Ireland Limited (joint controller, Art. 26 GDPR – communication via WhatsApp – EU/Ireland); Meta Platforms, Inc. (recipient within the scope of the DPF – technical provision – USA, DPF-certified).
- 7.6
Further information on WhatsApp data protection: https://www.whatsapp.com/privacy
8External Links
Our website contains links to external websites of third parties. We have no influence over the content and data protection practices of these external pages. The respective provider or operator of the pages is always responsible for the content of linked pages.
- 8.1
The following external links are available on our website:
- 8.2
IMDb profile – operator: Amazon.com, Inc. (USA) – third country: USA
- 8.3
Note: When you click on these links, personal data (in particular your IP address) may be transmitted to the operator of the linked page. Please inform yourself about data protection on the respective pages.
9Your Rights
Within the framework of the applicable statutory provisions, you have the following rights regarding your personal data at any time:
- 9.1
Right of Access (Art. 15 GDPR)
- 9.1.1
You have the right to obtain confirmation as to whether the data in question is being processed and to obtain access to this data as well as further information and a copy of the data in accordance with Art. 15 GDPR.
- 9.2
Right to Rectification (Art. 16 GDPR)
- 9.2.1
You have the right to obtain the completion of data concerning you or the rectification of inaccurate data concerning you.
- 9.3
Right to Erasure (Art. 17 GDPR)
- 9.3.1
You have the right to obtain the erasure of data concerning you under the conditions of Art. 17 GDPR. In particular, a right to erasure exists if:
- 9.3.2
The data is no longer necessary for the purposes for which it was collected or otherwise processed
- 9.3.3
You have withdrawn your consent and there is no other legal basis for the processing
- 9.3.4
You object to the processing and there are no overriding legitimate grounds for the processing
- 9.3.5
The data has been processed unlawfully
- 9.3.6
The erasure is necessary to comply with a legal obligation
- 9.4
Right to Restriction of Processing (Art. 18 GDPR)
- 9.4.1
You have the right to obtain the restriction of processing of data concerning you if one of the conditions of Art. 18 GDPR is met. This is in particular the case when:
- 9.4.2
You contest the accuracy of the data, for a period enabling the controller to verify the accuracy
- 9.4.3
The processing is unlawful and you oppose the erasure and instead request the restriction of use
- 9.4.4
The controller no longer needs the data, but you need them for the establishment, exercise or defence of legal claims
- 9.4.5
You have objected to the processing and it is not yet clear whether the legitimate grounds of the controller override your grounds
- 9.5
Right to Data Portability (Art. 20 GDPR)
- 9.5.1
You have the right to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, provided that the processing is based on consent or a contract and is carried out by automated means.
- 9.6
Right to Object (Art. 21 GDPR)
- 9.6.1
You have the right to object at any time to the processing of data concerning you that is based on Art. 6 (1) lit. e or f GDPR. This also applies to profiling based on these provisions. In the event of an objection, we will no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
10Right to Lodge a Complaint with the Data Protection Authority
You have the right to lodge a complaint with the Austrian Data Protection Authority (DSB) if you believe that the processing of your personal data violates the GDPR:
- 10.1
Datenschutzbehörde (DSB) – Barichgasse 40-42, 1030 Vienna, Austria
- 10.2
Phone: +43 1 52 152-0
- 10.3
E-mail: dsb@dsb.gv.at
- 10.4
Website: https://www.dsb.gv.at/
11Obligation to Provide Data
- 11.1
The provision of personal data is neither required by law nor by contract. However, without providing your data, our contact form cannot be made available and your enquiry cannot be processed. Data processing for server log files takes place automatically when you visit the website and does not require any active data entry on your part.
12Automated Decision-Making / Profiling
- 12.1
We do not carry out automated decision-making including profiling within the meaning of Art. 22 GDPR. A purely automated decision that produces legal effects concerning you or similarly significantly affects you does not take place.
13Right to Withdraw Consent
- 13.1
Insofar as the processing of your personal data is based on consent (Art. 6 (1) lit. a GDPR), you have the right to withdraw this consent at any time in accordance with Art. 7 (3) GDPR. The withdrawal of consent does not affect the lawfulness of the data processing carried out on the basis of the consent up to the withdrawal. You can declare the withdrawal informally (e.g. by e-mail to office@alyssandra-singh.com).
14Right to Compensation
- 14.1
In accordance with Art. 82 GDPR and § 30 DSG, you are entitled to compensation if you have suffered material or non-material damage as a result of processing of your personal data that violates data protection regulations. The right to compensation exists regardless of whether the processing was based on negligence or intent.
15Currency and Amendments of this Privacy Policy
- 15.1
This privacy policy is currently valid and has the status July 2026.
- 15.2
We reserve the right to adapt this privacy policy so that it always complies with the current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. The new privacy policy will then apply on your next visit.


