Data Protection 

Protection of your personal data is highly important for us. Therefore, we process them only in accordance with the relevant regulations (DSGVO, TKG 2003). The goal of this statement is to define the nature of collection and processing of data.

On behalf of Bomboncito, Zita Szabo-Herkelyis responsible for data processing. If you have any questions related to collecting, processing or use of your personal data, please contact us in writing:

Zita Szabo-Herkely, Bergheimer Straße 23. 5020, Salzburg,

Data collection and processing

We collect and process specific personal data during the course of orders, subscription to newsletter or visiting our website. The nature, scope and goal of data processing will be described below.


As a part of the order we process the data given by you: surname, last name, e-mail address, street, postal code, city, phone number, username and password.

In addition, in case of payment by credit card / PayPal, type of credit card, credit card number, credit card expiration date, and the cvv number indicated in the back of the credit card shall be disclosed. Your data will be transferred via internet through SSL (minimum 128 bit) encrypted.

Any information disclosed by you will be used only to process the order and for performance of the contract concluded between you and us. The legal title of the data processing is Point b) of Section (1) of Article 6. of DS-GVO. After performance of the contract and payment of the purchase price you data will be archived and deleted after the expiry of sustention period according to tax and commercial regulations, or the expiry of deadlines according to the product liabilities act, except is you gave your consent to further use of your data. If an order is interrupted before entering into a contract, the data will be deleted.

Your personal data may be disclosed to third parties or published otherwise if it is required for performance of the contract or invoicing, or if you gave your prior consent. As a part of processing an order, the enlisted service providers (for example couriers, logistics companies, payment service providers) will receive the data required for processing the order. In case of statutory provision, request from an authority or official inspection, we are obliged by law to disclose the proper data with the authorities.


If you subscribe to our newsletter, and you're your consent (Point a) of Section (1) of Article 6 of GDPR) we process your name and e-mail address for the purpose of sending newsletters. Your personal data will be stored until you describe from our newsletter or you revoke your consent.

You may revoke your consent or describe from our newsletter by sending a message to our address

Visiting our website / using of "cookies"

During your visit on our website, we collect technically required personal data (name of downloaded file, date and time of retrieval, data quantity handed over, notification of successful retrieval, type and version of browser, user's operating system , reference URL and requesting service provider).

Such data cannot be associated to certain individuals, and they will not be connected to data from other data sources.

Please note, that we use "cookies" during your visit on our website. These are small files or other forms of storing information, which are forwarded from our web server or the web server of a third party to the user's browser and stored there for retrieval purposes later. Cookies used during the visit of our website serve only to simplify the order procedure (i.e. storing the items in the cart) and support several functions of our website. Cookies used by us will be deleted from the hard drive (session "cookies"). Collection of such data is under Section (3) of Article 96 of TGK.

We also use "cookies" as a part of Google Analytics web analyzation service for statistical analysis of the usage of our website (please see below). Collection of such data is under Point f) of Section (1) of Article 6 of DS-GVO.

If you gave your consent earlier in accordance with Section (1) of Article 6, we use "cookies" from third parties during your visit on our website to collect and evaluate user's behaviour.

You may give your consent to using "cookies" through a banner which explains the nature and extent of "cookies" and provides you the option to accept or reject the usage of such "cookies". These "cookies" will not be used prior to your consent. Missing to accept "cookies" may limit several functions of our website.

Using Google Analytics

We use Google Analytics, a web analytics service provided by Google LLC (1600 Amphitheatre Parkway Mountain View, CA 94043, USA) ("Google"). As part of Google Analytics, the "cookies" are configured in the computer to statistically evaluate the usage of our website. We entered into a contract with Google for data processing of orders.

The information produced by "cookies" in connection with usage of the website (including the IP address) will be anonymized before stored in Google's servers, therefore the cannot be associated with the computer. In only exceptional cases will the full IP address send to a Google service provider and be shortened there. Google uses such information to evaluate the usage of the website, prepare reports from web activities of web operators, and other services related to usage of the website and internet usage in general. Information provided by Google Analytics as a part of Google Analytics service will not be merged with other Google information. For further information from processing the data of the users of Google Analytics, please read the data protection principles of Google:

You can prevent collection of data generated by "cookies" and the data in connection with usage of the website, and also the processing of data anonymized by Google by downloading and installing a browser plug-in available at the following link Do not forget, by using it, you may limit several functions of our website.

Social media plugins

We use Facebook and Instagram web plugins operated by Facebook Inc., a 1601 S. California Ave, a Palo Alto, a CA 94304, USA, For this purpose, we use a two-step process, in which you may give your consent according to Point a) of Section (1) of Article 6 of GDPR to the data processing by the operator of the social media network. The data will be forwarded only to the operator of the social media network, if the users click on one of the displayed icons, and therefore they agree to forward the data to the operator of the social media network. Only the approval will establish the connection between the browser and the specific social network.

The social network will receive information from visits to our website through the plug-in. If you are logged in to Facebook and Instagram, your visit can be associated with your social network account. The network's operator can store any interaction with the plug-in.

Information related to the usage of data collected by each social network is available on the website of Facebook and Instagram under "Data Protection" or "Privacy".

Data Security

Your contractual data will be forwarded through the internet using SSL encryption. Our website and other systems are secured by technical and organisational measures against loss, corruption, access, modification or publication of the data by unauthorised personnel.

Your rights

You have a right to information related to your personal data, and for legal remedy or for termination or limitation of processing. In addition to that, you may file a complaint against the processing and have the right to forward your data in a structured, type written, readable form. For any of the mentioned rights, please contact the person responsible.

Legal remedy

You have the right to file a complaint to the competent authority. In case of Austria, this is the data protection authority, Wickenburggasse 8, 1080 Vienna, phone: +43 1 52 152-0, E-mail:, Web: