Privacy
This privacy notice sets out the nature, scope and purpose of the processing of personal data in connection with this website, together with the rights of data subjects under Articles 13 and 14 GDPR.
Controller
The controller within the meaning of Article 4(7) GDPR is:
Mycelium Movement
Mandlgasse 5/2
1120 Wien
Österreich
E-Mail: office@mycelium-movement.com
Enquiries concerning data protection should be addressed as above. There is no obligation to appoint a data protection officer under Article 37 GDPR.
Cookies, audience measurement and third-party content
This website uses no cookies and employs no analytics, tracking or advertising services. No profiling takes place.
Fonts are served exclusively from the operator’s own server; no connection to external font services is established. Video content is likewise self-hosted. Third-party content, such as YouTube or Vimeo, is not embedded.
Provision of the website and server log files
The website is hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, under its Cloudflare Pages service.
On each access, technically necessary access data is processed, in particular the IP address, the date and time of access, the resource requested, the volume of data transferred, the referrer and details of the browser and operating system.
This processing serves the technical provision of the website, operational security and the prevention of abusive access. The legal basis is Article 6(1)(f) GDPR; the legitimate interest lies in the secure and uninterrupted operation of the website.
A data processing agreement pursuant to Article 28 GDPR is in place with the provider. Insofar as data is transferred to the United States, such transfer is based on the European Commission’s Standard Contractual Clauses and on the provider’s certification under the EU-U.S. Data Privacy Framework.
Contact form
The data entered in the booking form is processed, namely name, email address, the type of performance selected and the content of the message.
Technical transmission is handled by the service Web3Forms, which receives the entries and forwards them by email. Processing on servers outside the European Economic Area cannot be excluded; such transfer is based on the European Commission’s Standard Contractual Clauses.
The data is processed solely in order to deal with the enquiry and to prepare an offer. The legal basis is Article 6(1)(b) GDPR for steps taken prior to entering into a contract, and otherwise Article 6(1)(f) GDPR.
Provision of the data is voluntary. Without a name, email address and message the enquiry cannot be processed.
Contact by email
Where contact is made by email, the sender’s address and the content of the message are processed for the purpose of dealing with the matter. The legal basis is Article 6(1)(b) GDPR and otherwise Article 6(1)(f) GDPR.
Inbound mail is handled via Cloudflare Email Routing. Incoming messages are received by the provider and forwarded to the controller’s mailbox.
Local storage in the browser
A single entry with the key mm-lang is stored in the browser’s local storage, recording the language version selected.
The entry contains no personal data and is transmitted neither to the controller nor to third parties. It serves solely to give effect to the user’s own selection and may be deleted at any time via the browser settings.
References to social networks
The footer of the website links to profiles on Instagram and Facebook. These are plain hyperlinks; no social plugins or embedded content are used.
No data is transmitted to the operators of those networks unless the respective link is actively followed. From that point their privacy terms apply; the controller has no influence over the processing carried out there.
Retention periods
Server log files are automatically deleted or anonymised by the hosting provider after a short period.
Enquiries received through the contact form or by email are deleted once they have been conclusively dealt with, unless statutory retention obligations require otherwise. Where a booking results, the seven-year retention period under § 132 of the Austrian Federal Fiscal Code (BAO) applies in particular.
Rights of data subjects
Data subjects have the right of access under Article 15 GDPR, to rectification under Article 16 GDPR, to erasure under Article 17 GDPR, to restriction of processing under Article 18 GDPR and to data portability under Article 20 GDPR.
Processing based on Article 6(1)(f) GDPR may be objected to at any time pursuant to Article 21 GDPR. Any consent given may be withdrawn at any time with future effect; the lawfulness of processing carried out prior to withdrawal remains unaffected.
An informal notification to the controller is sufficient to exercise these rights.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their residence, place of work or the place of the alleged infringement. The competent authority in Austria is:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40–42, 1030 Vienna, Austria
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at
Amendments to this privacy notice
This privacy notice will be amended where changes to the technology employed or to the legal position so require. The version published here from time to time is the one that applies.
Last updated: August 2026