We have drafted this privacy policy (version 11/12/2024-112919974) to explain to you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (hereinafter referred to as “data”) we, as the controller, and the processors commissioned by us (e.g., providers) – process, will process in the future, and what legal options you have. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal terminology. This privacy policy, on the other hand, is intended to describe the most important things as simply and transparently as possible. Insofar as it promotes transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics are used. We thus inform you in clear and simple language that we only process personal data in the course of our business activities if there is a corresponding legal basis for doing so. This is certainly not possible if you provide explanations that are as concise, unclear, and legally technical as possible, as is often the standard on the Internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is some information here that you did not know before.
If you still have questions, please contact the responsible body listed below or in the legal notice, follow the links provided, and view further information on third-party websites. You will also find our contact details in the legal notice.
This privacy policy applies to all personal data processed by us within the company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person’s name, email address, and postal address. The processing of personal data ensures that we can offer and bill our services and products, whether online or offline. The scope of this privacy policy covers:
In short: The privacy policy applies to all areas in which personal data is processed in a structured manner within the company via the channels mentioned. If we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.
In the following privacy policy, we provide you with transparent information about the legal principles and regulations, i.e., the legal basis of the General Data Protection Regulation, which enable us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can, of course, read this EU General Data Protection Regulation online at EUR-Lex, the gateway to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/? uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
Other conditions, such as the performance of tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests, do not generally apply to us. If such a legal basis should nevertheless be relevant, it will be indicated at the appropriate place.
In addition to the EU regulation, national laws also apply:
If other regional or national laws apply, we will inform you about them in the following sections.
If you have any questions about data protection or the processing of personal data, you will find the contact details of the controller in accordance with Article 4(7) of the EU General Data Protection Regulation (GDPR) below:
Panacool GmbH
GF Jakob Hraschan
Finkensteiner Straße 5
9585 Gödersdorf
Austria
Email: office@panacool.com
Phone: +43 4257 93080
Legal notice: https://panacool.com/impressum/
It is our general policy to store personal data only for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.
If you wish to have your data deleted or revoke your consent to data processing, the data will be deleted as quickly as possible and insofar as there is no obligation to store it.
We will inform you about the specific duration of the respective data processing below, provided we have further information on this.
In accordance with Articles 13 and 14 of the GDPR, we inform you of the following rights to which you are entitled in order to ensure fair and transparent data processing:
In short: You have rights – don’t hesitate to contact the responsible body listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. In Austria, this is the data protection authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
We have implemented both technical and organizational measures to protect personal data. Where possible, we encrypt or pseudonymize personal data. In this way, we make it as difficult as possible for third parties to derive personal information from our data.
Article 25 of the GDPR refers to “data protection through technology design and data protection-friendly default settings,” meaning that security must always be considered and appropriate measures taken for both software (e.g., forms) and hardware (e.g., access to the server room). In the following, we will discuss specific measures where necessary.
TLS, encryption, and https sound very technical, and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data over the Internet in a way that is secure against eavesdropping.
This means that the entire transmission of all data from your browser to our web server is secure—no one can “listen in.”
This means that we have introduced an additional layer of security and comply with data protection through technology design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data.
You can recognize the use of this data transmission security by the small lock symbol in the upper left corner of the browser, to the left of the Internet address (e.g., examplepage.com) and the use of the https (instead of http) scheme as part of our Internet address.
If you would like to know more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links to further information.
Communication Summary
👥 Affected persons: Anyone who communicates with us by phone, email, or online form
📓 Processed data: e.g., phone number, name, email address, form data entered. You can find more details on this under the respective contact type
🤝 Purpose: Handling communication with customers, business partners, etc.
📅 Storage period: Duration of the business case and legal requirements
⚖️ Legal basis: Art. 6 (1) (a) GDPR (consent), Art. 6 (1) (b) GDPR (contract), Art. 6 (1) (f) GDPR (legitimate interests)
When you contact us and communicate with us by phone, email, or online form, personal data may be processed.
The data is processed for the purpose of handling and processing your inquiry and the associated business transaction. The data is stored for as long as necessary or as required by law.
The above-mentioned processes affect everyone who contacts us via the communication channels we provide.
When you call us, the call data is stored in pseudonymized form on the respective end device and by the telecommunications provider used. In addition, data such as your name and telephone number may be sent by email and stored for the purpose of responding to your inquiry. The data will be deleted as soon as the business transaction has been completed and legal requirements permit.
If you communicate with us by email, data may be stored on the respective end device (computer, laptop, smartphone, etc.) and data may be stored on the email server. The data will be deleted as soon as the business transaction has been completed and legal requirements allow.
If you communicate with us using an online form, data will be stored on our web server and, if necessary, forwarded to one of our email addresses. The data will be deleted as soon as the business transaction has been completed and legal requirements allow.
The processing of data is based on the following legal basis:
Cookies Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Depends on the respective cookie. More details can be found below or from the manufacturer of the software that sets the cookie.
📓 Processed data: Depends on the cookie used. More details can be found below or from the manufacturer of the software that sets the cookie.
📅 Storage period: depends on the respective cookie, can vary from hours to years
⚖️ Legal basis: Art. 6 (1) (a) GDPR (consent), Art. 6 (1) (f) GDPR (legitimate interests)
Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used so that you can better understand the following privacy policy.
Whenever you surf the Internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: cookies are really useful little helpers. Almost all websites use cookies. More specifically, they are HTTP cookies, as there are also other cookies for other areas of application. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically stored in the cookie folder, which is essentially the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data about you, such as your language or personal page settings. When you visit our site again, your browser transmits the “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are used to. In some browsers, each cookie has its own file, while in others, such as Firefox, all cookies are stored in a single file.
The following graphic shows a possible interaction between a web browser such as Chrome and the web server. The web browser requests a website and receives a cookie back from the server, which the browser reuses when another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans, or other “malware.” Cookies also cannot access information on your PC.
Cookie data may look like this, for example:
Name: _ga
Value: GA1.2.1326744211.152112919974-9
Purpose: Distinguishing website visitors
Expiration date: After 2 years
A browser should be able to support these minimum sizes:
The question of which cookies we use in particular depends on the services used and is clarified in the following sections of the privacy policy. At this point, we would like to briefly discuss the different types of HTTP cookies.
There are four types of cookies:
Essential cookies
These cookies are necessary to ensure the basic functionality of the website. For example, these cookies are needed when a user adds a product to their shopping cart, then continues to browse other pages and only proceeds to checkout later. These cookies ensure that the shopping cart is not deleted even if the user closes their browser window.
Functional cookies
These cookies collect information about user behavior and whether the user receives any error messages. These cookies are also used to measure the loading time and behavior of the website in different browsers.
Targeted cookies
These cookies ensure better user-friendliness. For example, entered locations, font sizes, or form data are stored.
Advertising cookies
These cookies are also called targeting cookies. They are used to deliver personalized advertising to the user. This can be very practical, but also very annoying.
Usually, when you visit a website for the first time, you are asked which of these cookie types you want to allow. And, of course, this decision is also stored in a cookie.
If you would like to know more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments from the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism.”
The purpose ultimately depends on the respective cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalize what data is stored in cookies, but we will inform you about the processed or stored data in the following privacy policy.
The storage period depends on the respective cookie and is specified in more detail below. Some cookies are deleted after less than an hour, while others can remain stored on a computer for several years.
You also have control over the storage period. You can manually delete all cookies at any time via your browser (see also “Right to object” below). Furthermore, cookies that are based on consent will be deleted at the latest after you revoke your consent, whereby the legality of the storage remains unaffected until then.
You decide for yourself how and whether you want to use cookies. Regardless of which service or website the cookies originate from, you always have the option to delete, deactivate, or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.
If you want to find out which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find this in your browser settings:
Chrome: Delete, enable, and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Delete cookies to remove data that websites have stored on your computer
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete and manage cookies
If you do not want cookies at all, you can set your browser to always inform you when a cookie is about to be set. This allows you to decide whether or not to allow each individual cookie. The procedure varies depending on the browser. The best way to find the instructions is to search Google using the search term “delete cookies Chrome” or “disable cookies Chrome” in the case of a Chrome browser.
The so-called “cookie guidelines” have been in place since 2009. These stipulate that the storage of cookies requires your consent (Article 6(1)(a) GDPR). However, there are still very different responses to these guidelines within EU countries. In Austria, however, this directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the cookie guidelines were not implemented as national law. Instead, this directive was largely implemented in Section 15 (3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.
For cookies that are absolutely necessary, even if no consent has been given, there are legitimate interests (Article 6(1)(f) GDPR), which in most cases are of an economic nature. We want to provide visitors to the website with a pleasant user experience, and certain cookies are often absolutely necessary for this.
If cookies that are not absolutely necessary are used, this will only happen with your consent. The legal basis for this is Article 6(1)(a) GDPR.
The following sections provide more detailed information about the use of cookies, if the software used employs cookies.
Customer data Summary
👥 Data subjects: Customers or business and contractual partners
🤝 Purpose: Provision of contractually or pre-contractually agreed services, including associated communication
📓 Processed data: Name, address, contact details, email address, telephone number, payment information (such as invoices and bank details), contract data (such as the term and subject matter of the contract), IP address, order data
📅 Storage period: The data will be deleted as soon as it is no longer required for the fulfillment of our business purposes and there is no legal obligation to retain it.
⚖️ Legal basis: Legitimate interest (Art. 6 (1) (f) GDPR), contract (Art. 6 (1) (b) GDPR)
In order to offer our services and contractual services, we also process data from our customers and business partners. This data always includes personal data. Customer data refers to all information that is processed on the basis of a contractual or pre-contractual cooperation in order to be able to provide the services offered. Customer data is therefore all the information we collect and process about our customers.
There are many reasons why we collect and process customer data. The most important one is that we simply need various data to provide our services. Sometimes your email address is sufficient, but if you purchase a product or service, we also need data such as your name, address, bank details, or contract details. We also use the data for marketing and sales optimization so that we can improve our overall service to our customers. Another important point is our customer service, which is always very important to us. We want you to be able to contact us at any time with questions about our offers, and for this we need at least your email address.
At this point, we can only provide a general overview of the data that is stored. This always depends on the services you purchase from us. In some cases, you only provide us with your email address so that we can contact you or answer your questions, for example. In other cases, you purchase a product or service from us, and we need significantly more information, such as your contact details, payment details, and contract details.
Here is a list of possible data that we receive from you and process:
As soon as we no longer need the customer data to fulfill our contractual obligations and our purposes, and the data is also not necessary for possible warranty and liability obligations, we delete the corresponding customer data. This is the case, for example, when a business contract ends. After that, the limitation period is usually 3 years, although longer periods are possible in individual cases. We also comply with the statutory retention obligations. Your customer data will certainly not be passed on to third parties unless you have given your explicit consent.
The legal basis for the processing of your data is Art. 6 (1) (a) GDPR (consent), Art. 6 (1) (b) GDPR (contract or pre-contractual measures) , Art. 6 (1) (f) GDPR (legitimate interests) and, in special cases (e.g., medical services), Art. 9 (2) (a) GDPR (processing of special categories).
In the case of the protection of vital interests, data processing is carried out in accordance with Art. 9(2)(c) GDPR. For the purposes of healthcare, occupational medicine, medical diagnostics, care or treatment in the health or social sector, or for the management of systems and services in the health or social sector, the processing of personal data is carried out in accordance with Art. 9(2)(h) GDPR. If you voluntarily provide special categories of data, processing is carried out on the basis of Art. 9 (2) (a) GDPR.
Web hosting Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Professional hosting of the website and securing its operation
📓 Processed data: IP address, time of website visit, browser used, and other data. More details can be found below or from the respective web hosting provider.
📅 Storage period: Depends on the respective provider, but usually 2 weeks
⚖️ Legal basis: Art. 6 (1) (f) GDPR (legitimate interests)
When you visit websites today, certain information—including personal data—is automatically generated and stored, as is the case on this website. This data should be processed as sparingly as possible and only when justified. By website, we mean all web pages on a domain, i.e., everything from the home page to the very last subpage (like this one).
If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We refer to these as browsers or web browsers for short.
To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why it is usually handled by professional providers. These providers offer web hosting and thus ensure reliable and error-free storage of website data. That’s a lot of technical terms, but please stay with us, it gets even better!
When the browser on your computer (desktop, laptop, tablet, or smartphone) establishes a connection and during the transfer of data to and from the web server, personal data may be processed. On the one hand, your computer stores data, and on the other hand, the web server must also store data for a period of time to ensure proper operation.
A picture is worth a thousand words, so the following graphic illustrates the interaction between the browser, the internet, and the hosting provider.
The purposes of data processing are:
Even while you are visiting our website right now, our web server, which is the computer on which this website is stored, usually automatically stores data such as
As a rule, the above-mentioned data is stored for two weeks and then automatically deleted. We do not pass on this data, but cannot rule out the possibility that this data may be viewed by authorities in the event of illegal behavior.
In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass on your data without your consent!
The legality of the processing of personal data in the context of web hosting is based on Art. 6 (1) lit. f GDPR (protection of legitimate interests), because the use of professional hosting by a provider is necessary in order to present the company on the Internet in a secure and user-friendly manner and to be able to pursue attacks and claims arising from this, if necessary.
As a rule, there is a contract between us and the hosting provider for order processing in accordance with Art. 28 f. GDPR, which ensures compliance with data protection and guarantees data security.
We always strive to make our privacy policy as clear and understandable as possible. However, this is not always easy, especially when it comes to technical and legal issues. It often makes sense to use legal terms (such as personal data) or certain technical terms (such as cookies, IP address). However, we do not want to use these without explanation. Below you will find an alphabetical list of important terms used that we may not have covered sufficiently in the previous privacy policy. If these terms are taken from the GDPR and are definitions, we will also cite the GDPR texts here and add our own explanations where necessary.
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the following definitions apply:
“Processor” means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data that we process from you. In addition to the controllers, there may also be so-called processors. This includes any company or person who processes personal data on our behalf. Processors can therefore include service providers such as tax advisors, hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Consent” of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
Explanation: On websites, such consent is usually given via a cookie consent tool. You are probably familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree to or consent to data processing. In most cases, you can also make individual settings and thus decide for yourself which data processing you allow and which you do not. If you do not give your consent, no personal data about you may be processed. In principle, consent can of course also be given in writing, i.e., not via a tool.
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term
“health data” means personal data related to the physical or mental health of a natural person, including the provision of health services, and which reveal information about their health status;
Explanation: Health data therefore includes all stored information relating to your own health. This is often data that is also recorded in a patient file. This includes, for example, which medications you use, X-ray images, your entire medical history, and, as a rule, your vaccination status.
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the following definitions shall apply:
“personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Explanation: Personal data is therefore any data that can identify you as a person. This usually includes data such as:
According to the European Court of Justice (ECJ), your IP address is also considered personal data. IT experts can use your IP address to determine at least the approximate location of your device and, subsequently, you as the connection owner. Therefore, storing an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called “special categories” of personal data that are particularly sensitive. These include:
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the following definitions apply:
“profiling” means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements;
Explanation: Profiling involves gathering various pieces of information about a person in order to learn more about that person. In the web sector, profiling is often used for advertising purposes or for credit checks. Web and advertising analysis programs, for example, collect data about your behavior and interests on a website. This results in a specific user profile that can be used to target advertising to a specific audience.
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the following definitions apply:
“controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Explanation: In our case, we are responsible for the processing of your personal data and are therefore the “controller.” If we pass on collected data to other service providers for processing, they are “processors.” For this purpose, a “processing agreement (PA)” must be signed.
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
Note: When we refer to processing in our privacy policy, we mean any type of data processing. As mentioned above in the original GDPR declaration, this includes not only the collection but also the storage and processing of data.
Congratulations! If you are reading these lines, you have really “fought your way through” our entire privacy policy, or at least scrolled down to this point. As you can see from the scope of our privacy policy, we take the protection of your personal data very seriously.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, we want to not only tell you what data is processed, but also explain the reasons for using various software programs. Privacy policies usually sound very technical and legal. However, since most of you are not web developers or lawyers, we wanted to take a different approach linguistically and explain the facts in simple and clear language. Of course, this is not always possible due to the nature of the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions about data protection on our website, please do not hesitate to contact us or the responsible authority. We hope you enjoy your visit and look forward to welcoming you back to our website soon.
All texts are protected by copyright.
Source: Created with the Data Protection Generator from AdSimple
Our customers appreciate not only the technology, but above all the exceptional all-round service provided by Panacool. As a true one-stop shop, we accompany you from the initial consultation and room inspection through ordering, installation, and training to one month of free marketing support for your quick promotion. Thanks to remote maintenance and rapid response times, we ensure smooth operations at all times. A particular highlight is our showroom and test center in Villach, where interested parties can experience our products live.
Sehr freundliche und kompetente Kundenberatung. Das schöne Design samt einer „einfachen Bedienung“ hat uns überzeugt. Sehr positiv auch der exklusive medizinische Hintergrund von Panacool und die kostenlose Ärzte-Hotline, da immer wieder Fragen auftreten. Großartigen Gesundheits-Effekt bere...
Mehr lesen
„Waren von Probeanwendung begeistert, da hier gegenüber anderen Anbietern „keine Luftbewegungen“ in der Kabine zu verspüren waren, was den Komfort nicht nur wesentlich erhöhte und man daher gerne weitere Anwendungen durchführt“. Beratung sehr freundlich und kompetent!
In einer Analyse mehrere Anbieter hat Panacool am besten abgeschnitten. Da Panacool als einziger Anbieter auch ein Show- und Testcenter aufweist, konnte hier eine praktische Anwendung zur vollsten Zufriedenheit durchgeführt werden. Rundum-Beratung top. Wichtig war uns auch der medizinische Hintergr...
Mehr lesen

The demand for cold and oxygen applications is growing rapidly. Investing today gives you a decisive advantage—whether in the fitness and health sector, physiotherapy, or the wellness industry.
With Panacool, part of Panaceo International GmbH, you can rely on TÜV-certified quality, state-of-the-art technology, and an established partner network. Our dual-chamber system has been proven to reach a genuine -110 °C – safely, comfortably, and with an eye to the future.
Benefit from comprehensive service: personal consultation, training for your team, your own medical hotline, and fast support via remote maintenance. In our showroom in Villach, you can experience the effects of our systems live and see for yourself.
Let’s work together to make your vision a reality. We look forward to your inquiry and will contact you promptly to discuss your individual options.

Panacool GmbH
Finkensteiner Straße 5
9585 Gödersdorf