Data Privacy Policy
Thank you for visiting our website. In this Policy, we would like to inform you about how we handle your data in accordance with Art. 13 of the General Data Protection Regulation (GDPR).
Controller
The Controller for the data processing operations described below is the office named in the imprint.
USAGE Data
When you visit our website, our web server temporarily evaluates usage data for statistical purposes in order to improve the quality of our website. This data consists of the following data categories:
- the name and address of the requested content,
- the date and time of the query,
- of the transferred data volume,
- the access status (content transferred, content not found),
- the description of the used web browser and operating system,
- the referral link, which indicates from which page you reached ours,
- the IP address of the requesting computer, which is shortened in such a way that a personal reference can no longer be established.
The aforementioned protocol data is only evaluated anonymously.
Data Security
In order to protect your data from unwanted access as comprehensively as possible, we take technical and organisational measures. We use an encryption process on our websites. Your data is transferred from your computer to our server and vice versa via the internet using TLS encryption. You can usually recognise this by the fact that the lock symbol in the status bar of your browser is closed and the address line begins with https://.
Necessary Cookies
On our website, we use cookies which are necessary in order for the site to function.
Cookies are small text files that can be placed on your computer or mobile device by websites that you visit. A distinction is made between session cookies, which are deleted as soon as you close your browser, and permanent cookies, which are stored beyond the individual session.
We do not use these necessary cookies for analysis, tracking or advertising purposes.
In some cases, these cookies only contain information on certain settings and cannot be linked to a person. They may also be necessary to enable user guidance, security and implementation of the site.
The legal basis for using these cookies is our legitimate interest according to Art. 6 (1) (f) GDPR.
You can set your browser to inform you about the placement of cookies. This is in order to make the use of cookies transparent for you.
You can also delete cookies or prevent the setting of new cookies at any time by using the appropriate browser settings.
Please note that if you delete certain cookies, our web pages may not be displayed correctly and some functions may no longer be available.
Provider | Adequate level of data protection | Revocation of consent |
---|---|---|
Borelabs | Processing only within EU/EEA | If you wish to withdraw your consent, please click on the Consent Manager (always displayed at the bottom left of the pages) and make the appropriate setting via our banner. |
DECLARATION OF CONSENT
We use a consent management platform (consent or cookie banner) on our websites. The processing in connection with the use of the consent management platform as well as the logging of the settings you have made is carried out on the basis of Art. 6 (1) sentence 1 lit. f DSGVO, in our legitimate interest to play out our content according to your preferences and to be able to prove the consent(s) you have given. The settings you have made, the consent you have given with them and parts of your usage data are stored in a cookie. This means that the cookie is retained for subsequent page requests and your consent can still be traced. You can find more information on this under the section “Required cookies”.
The provider of the consent management platform works for us as a strictly instruction-bound service provider (order processor). An order processing contract in accordance with Art. 28 DSGVO has been agreed.
GOOGLE ANALYTICS
We use the web analysis tool “Google Analytics”. Google Analytics creates user profiles based on pseudonyms. For this purpose, permanent cookies are stored on your end device and read by us. In this way, we are able to recognize returning visitors and count them as such.
As part of the Google Analytics service, Google Ireland Limited supports us as a processor in accordance with Art. 28 GDPR. Data processing may also be carried out by Google outside the EU or the EEA (in particular in the USA). With regard to Google, no adequate level of data protection can be assumed due to processing in the USA. There is a risk that authorities may access the data for security and surveillance purposes without you being informed or having the right to appeal. Please bear this in mind if you decide to give your consent to our use of Google Analytics.
Data processing is based on your consent, provided that you have given your consent via our banner. The transfer to a third country takes place on the basis of Art. 49 para. 1 lit. a GDPR.
You can withdraw your consent at any time. Please make the appropriate settings via our banner.
Provider | Adequate level of data protection | Revocation of consent |
---|---|---|
Processing also possible outside the EU/EEA. No adequate level of data protection. The transfer takes place on the basis of Art. 49 para. 1 lit. a GDPR. | If you wish to withdraw your consent, please click on the Consent Manager (always displayed at the bottom left of the pages) and make the appropriate setting via our banner. |
Contact form
You may contact us via our contact form. In order to use our contact form, we will require you to provide the data marked as mandatory.
The legal basis for this processing is Art. 6 (1) (f) GDPR, being our legitimate interest to respond to your request.
Your data will only be used to process your request. We delete your data if they are no longer required and there are no legal obligations to retain them.
Where the processing of your data is based on legitimate interest in accordance with Art. 6 (1) (f) GDPR, you have the right to object to that processing at any time. To do so, please use the email address provided in the imprint.
Embedded videos
On our websites, we embed videos that are not hosted on our servers. In order to ensure that accessing our websites containing embedded videos does not automatically lead to the download of third-party content, we only show locally hosted preview images of the videos as a first step. As a result, the third-party provider does not receive any information.
Only after you click on the preview image, is content from the third-party provider downloaded. This provides the third party with information that you have accessed our site and with the usage data technically required for this purpose. Furthermore, the third party provider is then able to implement tracking technologies. We have no influence on the further data processing by the third-party provider. By clicking on the preview image, you give us your consent to download content from the third-party provider.
The embedding is based on your consent if you have given your consent by clicking on the preview image. Please note that the embedding of many videos leads to your data being processed outside the EU or EEA. In some countries, there is a risk that authorities may access the data for security and surveillance purposes without informing you or allowing you to take legal action. Where we use providers in third countries without an adequate level of protection and you give your consent, the transfer to this third country is based on Art. 49 (1) (a) GDPR.
Provider | Adequate level of data protection | Revocation of consent |
---|---|---|
Google (YouTube) | No adequate level of data protection. The data is transmitted on the basis of Art. 49 (1) (a) GDPR. | If you click on a preview image, the content of the third-party provider is immediately downloaded. To avoid this downloading on other sites, please do not click on the preview image. |
Storage period
Unless otherwise specified, we will delete your personal data if they are no longer required for the relevant processing purposes and no legal retention obligations oppose deletion.
Data Processors
We transfer your data to service providers who support us in the operation of our websites and related processes. These service providers are usually data processors within the meaning of Art. 28 GDPR. Our service providers are strictly bound by contracts and our instructions.
Any processors who may not have been previously disclosed are listed below. If data is transferred outside the EU or the EEA, we will also provide information on the adequate level of data protection.
Service Provider / Processor | Purpose | Adequate level of data protection |
---|---|---|
Mittwald | Webhosting and Support | Processing only within EU/EEA |
Your rights as a data subject
When processing your personal data, the GDPR grants you certain rights as a data subject:
Right of access by the data subject (Art. 15 GDPR)
You have the right to obtain confirmation as to whether personal data concerning you are being processed; if this is the case, you have the right to be informed of this personal data and to receive the information specified in Art. 15 GDPR.
Right to rectification (Art. 16 GDPR)
You have the right to rectification of inaccurate personal data concerning you and, taking into account the purposes of the processing, the right to have incomplete personal data completed, including by means of providing a supplementary statement without delay.
Right to erasure (Art. 17 GDPR)
You have the right to obtain the erasure of personal data concerning you without undue delay if one of the reasons listed in Art. 17 GDPR applies.
Right to restriction of processing (Art. 18 GDPR)
You have the right to request the restriction of processing if one of the conditions listed in Art. 18 GDPR is met, e.g. if you have objected to the processing, for the duration of our examination.
Right to data portability (Art. 20 GDPR)
In certain cases, which are listed in detail in Art. 20 GDPR, you have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format, or to request that this data be transferred to a third party.
Right to withdraw consent (Art. 7 GDPR)
If the processing of data is based on your consent, you are entitled to withdraw your consent to the use of your personal data at any time in accordance with Art. 7 (3) GDPR. Please note that the withdrawal is only effective for the future. Processing that took place before the withdrawal is not affected.
Right to object (Art. 21 GDPR)
If data is collected on the basis of Art. 6 (1) 1 f GDPR (data processing for the purpose of our legitimate interests) or on the basis of Art. 6 (1) 1 e GDPR (data processing for the purpose of protecting public interests or in the exercise of official authority), you have the right to object to the processing at any time for reasons arising from your particular situation. We will then no longer process the personal data unless there are compelling legitimate grounds for the processing which override your interests, rights and freedoms or if data is still needed for the establishment, exercise or defence of legal claims.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
According to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your data violates data protection regulations. This right may be asserted in particular with a supervisory authority in the Member State of your habitual residence, your place of work or the place of the suspected infringement.
Asserting your rights
Unless otherwise described above, please contact us to assert your rights. You will find our contact details in our imprint.
Contact details of the data protection officer
Our data protection officer is available to provide further information on data protection.
David Havelka
Tel: +43 1 587 05 15-16