The German version of this page is legally binding. This translation is provided for convenience only.
Introduction and Overview
We have drafted this Privacy Policy (version 11/11/2022-122317514) to explain to you, according to the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (short: data) we as the responsible party – and the processors commissioned by us (e.g., providers) – process, will process in the future, and what lawful options you have. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This Privacy Policy aims to describe the most important things to you as simply and transparently as possible. Where it aids transparency, technical terms are explained in a reader-friendly manner, links to further information are provided and graphics are used. We inform you in clear and simple language that we only process personal data within the scope of our business activities when there is a corresponding legal basis. This is certainly not possible if one provides the briefest, unclear, and legally-technical explanations, as is often standard on the internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is one or another piece of information that you did not know yet.
If questions remain, we kindly ask you to contact the responsible office mentioned below or in the imprint, follow the available links, and view further information on third-party sites. Our contact details can also be found in the imprint.
Scope of Application
This Privacy Policy applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information in the sense of Art. 4 No. 1 GDPR, such as a person’s name, email address, and postal address. The processing of personal data ensures that we can offer and bill for our services and products, whether online or offline. The scope of this Privacy Policy includes:
- all online presences (websites, online shops) that we operate
- social media presences and email communication
- mobile apps for smartphones and other devices
In short: The Privacy Policy applies to all areas where personal data is structured and processed in the company via the mentioned channels. Should we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.
Legal Basis
In the following Privacy Policy, we provide you with transparent information about the legal principles and regulations, i.e., the legal basis of the General Data Protection Regulation, which enable us to process personal data.
Regarding EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the access to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679 read.
We only process your data if at least one of the following conditions applies:
- Consent (Article 6 paragraph 1 lit. a GDPR): You have given us your consent to process data for a specific purpose. An example would be storing the data you entered in a contact form.
- Contract (Article 6 paragraph 1 lit. b GDPR): To fulfil a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase contract with you, we need personal information in advance.
- Legal obligation (Article 6 paragraph 1 lit. c GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally required to keep invoices for accounting purposes. These usually contain personal data.
- Legitimate interests (Article 6 paragraph 1 lit. f GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data to operate our website securely and economically efficiently. This processing is therefore a legitimate interest.
Other conditions such as the performance of tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests, generally do not occur with us. If such a legal basis should be applicable, it will be indicated at the appropriate place.
In addition to the EU regulation, national laws also apply:
- In Austria this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), abbreviated DSG.
- In Germany the Federal Data Protection Actapplies, abbreviated BDSG.
If further regional or national laws apply, we will inform you in the following sections.
Contact details of the responsible person
If you have questions about data protection or the processing of personal data, you will find the contact details of the responsible person or entity below:
Katharina Alber
Larch 3a, 6071 Aldrans, Austria
Austria
Authorized representative: Katharina Alber
E-Mail: piano@boogiekathi.com
Phone: +43 676 960 8543
Imprint: https://www.boogiekathi.com/impressum
Storage duration
It is a general criterion for us that we only store personal data for as long as it is absolutely necessary to provide our services and products. This means that we delete personal data as soon as the reason for data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased, for example for accounting purposes.
If you wish to have your data deleted or revoke your consent to data processing, the data will be deleted as quickly as possible, provided there is no obligation to store it.
We will inform you about the specific duration of the respective data processing further below, if we have further information on this.
Rights according to the General Data Protection Regulation
According to Articles 13, 14 GDPR, we inform you about the following rights you have, so that data processing is fair and transparent:
- According to Article 15 GDPR, you have the right to know whether we process data about you. If this is the case, you have the right to receive a copy of the data and to know the following information:
- for what purpose we carry out the processing;
- the categories, i.e., the types of data that are processed;
- who receives this data and if the data is transferred to third countries, how security can be guaranteed;
- how long the data is stored;
- the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
- that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
- the source of the data if we did not collect it from you;
- whether profiling is carried out, i.e., whether data is automatically evaluated to create a personal profile of you.
- According to Article 16 GDPR, you have the right to rectification of data, which means we must correct data if you find errors.
- According to Article 17 GDPR, you have the right to erasure (‘right to be forgotten’), which means you may request the deletion of your data.
- According to Article 18 GDPR, you have the right to restriction of processing, which means we may only store the data but not use it further.
- According to Article 20 GDPR, you have the right to data portability, which means we will provide you with your data in a common format upon request.
- According to Article 21 GDPR, you have the right to object, which, once enforced, results in a change in processing.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then promptly assess whether we can legally comply with this objection.
- If data is used for direct marketing, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
- If data is used for profiling, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
- According to Article 22 GDPR, you may have the right not to be subject to a decision based solely on automated processing (such as profiling).
- According to Article 77 GDPR, you have the right to lodge a complaint. This means you can contact the data protection authority at any time if you believe that the processing of personal data violates the GDPR.
In short: You have rights – don’t hesitate to contact the responsible office listed above!
If you believe that the processing of your data violates data protection law or your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. For Austria, this is the data protection authority, whose website you can find at https://www.dsb.gv.at/ In Germany, each federal state has a data protection officer. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) For our company, the following local data protection authority is responsible:
Austrian Data Protection Authority
Head: Mag. Dr. Andrea Jelinek
Address: Barichgasse 40-42, 1030 Vienna
Phone number: +43 1 52 152-0
Email address:
dsb@dsb.gv.at
Website:
https://www.dsb.gv.at/
Data transfer to third countries
We only transfer or process data to countries outside the EU (third countries) if you consent to this processing, it is legally required, or contractually necessary, and in any case only to the extent that it is generally permitted. Your consent is, in most cases, the primary reason we process data in third countries. The processing of personal data in third countries such as the USA, where many software manufacturers offer services and have their server locations, can mean that personal data is processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. Data processing by US services (such as Google Analytics) may result in data not being processed and stored anonymously. Furthermore, US authorities may have access to individual data. Additionally, it may happen that collected data is linked with data from other services of the same provider, if you have a corresponding user account. Whenever possible, we try to use server locations within the EU, if offered.
We inform you in the relevant sections of this privacy policy in more detail about data transfer to third countries, if applicable.
Security of data processing
To protect personal data, we have implemented both technical and organisational measures. Where possible, we encrypt or pseudonymise personal data. This makes it as difficult as possible, within our means, for third parties to infer personal information from our data.
Article 25 of the GDPR refers to “data protection by design and by default” meaning that both software (e.g., forms) and hardware (e.g., access to the server room) always consider security and implement appropriate measures. Below, we will discuss specific measures if necessary.
TLS encryption with https
TLS, encryption, and https sound very technical, and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to securely transmit data over the internet.
This means that the entire transmission of all data from your browser to our web server is secured – no one can “listen in”.
With this, we have introduced an additional layer of security and fulfil data protection by design (Article 25 paragraph 1 GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data.
You can recognise the use of this data transmission security by the small padlock symbol at the top left of the browser, to the left of the internet address (e.g., examplepage.de) and the use of the https scheme (instead of http) as part of our internet address.
If you want to know more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find good links to further information.
Communication
|
Communication summary – Affected parties: Everyone who communicates with us via phone, email, or online form |
When you contact us and communicate via phone, email, or online form, personal data may be processed.
The data is processed for handling and processing your inquiry and the related business transaction. The data is stored for as long as necessary or as required by law.
Affected individuals
All individuals who seek contact with us through the communication channels we provide are affected by the mentioned processes.
Phone
When you call us, the call data is pseudonymised and stored on the respective device and by the telecommunications provider used. Additionally, data such as name and phone number may be sent via email and stored for responding to inquiries. The data is deleted once the business case is concluded and legal requirements allow.
When you communicate with us via email, data may be stored on the respective device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data is deleted once the business case is concluded and legal requirements allow.
Online forms
When you communicate with us using an online form, data is stored on our web server and may be forwarded to one of our email addresses. The data is deleted once the business case is concluded and legal requirements allow.
Legal bases
The processing of data is based on the following legal bases:
- Art. 6 para. 1 lit. a GDPR (Consent): You give us consent to store your data and use it further for purposes related to the business case;
- Art. 6 para. 1 lit. b GDPR (Contract): It is necessary for the performance of a contract with you or a processor such as the telephone provider, or we need to process the data for pre-contractual activities, such as preparing an offer;
- Art. 6 para. 1 lit. f GDPR (Legitimate Interests): We aim to conduct customer inquiries and business communication in a professional manner. Certain technical facilities such as email programs, exchange servers, and mobile operators are necessary to conduct communication efficiently.
Data Processing Agreement (DPA)
In this section, we would like to explain what a Data Processing Agreement is and why it is needed. Because the term “Data Processing Agreement” can be quite a tongue-twister, we will often use the acronym DPA here in the text. Like most companies, we do not work alone but also use the services of other companies or individuals. By involving various companies or service providers, we may pass on personal data for processing. These partners then act as processors, with whom we conclude a contract, the so-called Data Processing Agreement (DPA). The most important thing for you to know is that the processing of your personal data is carried out exclusively according to our instructions and must be regulated by the DPA.
Who are processors?
We are responsible as a company and website owner for all data we process from you. In addition to the responsible parties, there may also be so-called processors. This includes any company or person who processes personal data on our behalf. More precisely and according to the GDPR definition: any natural or legal person, authority, institution, or other body that processes personal data on our behalf is considered a processor. Processors can therefore be service providers such as hosting or cloud providers, payment or newsletter providers, or large companies like Google or Microsoft.
For better understanding of the terminology, here is an overview of the three roles in the GDPR:
Data subject (You as a customer or interested party) – Controller (we as the company and client) – Processor (Service providers such as web hosts or cloud providers)
Content of a data processing agreement
As mentioned above, we have concluded a DPA with our partners who act as processors. It primarily states that the processor processes the data to be processed exclusively in accordance with the GDPR. The contract must be concluded in writing, although electronic contract conclusion is also considered “in writing” in this context. Only on the basis of the contract does the processing of personal data take place. The contract must include the following:
- Commitment to us as the controller
- Duties and rights of the controller
- Categories of data subjects
- Type of personal data
- Nature and purpose of data processing
- Subject matter and duration of data processing
- Place of data processing
Furthermore, the contract contains all the duties of the processor. The most important duties are:
- Ensuring data security measures
- taking possible technical and organizational measures to protect the rights of the data subject
- maintaining a data processing register
- cooperating with the data protection supervisory authority upon request
- conducting a risk analysis regarding the received personal data
- Sub-processors may only be engaged with the written consent of the controller
You can see what such a DPA looks like, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html Here a sample contract is presented.
Cookies
|
Cookies Summary – Data subjects: Visitors to the website |
What are cookies?
Our website uses HTTP cookies to store user-specific data.
Below we explain what cookies are and why they are used, so you can better understand the following privacy policy.
Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing is undeniable: cookies are really useful little helpers. Almost all websites use cookies. More specifically, they are HTTP cookies, as there are also other cookies for different applications. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, essentially the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data from you, such as language or personal site settings. When you revisit our site, your browser sends the “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are accustomed to. In some browsers, each cookie has its own file, while in others like Firefox, all cookies are stored in a single file.
The following graphic shows a possible interaction between a web browser like Chrome and the web server. The web browser requests a website and receives a cookie from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, trojans, or other “malware.” Cookies also cannot access information on your PC.
This is what cookie data can look like:
Name: _ga
Value: GA1.2.1326744211.152122317514-9
Purpose: Distinguishing website visitors
Expiration date: after 2 years
These minimum sizes should be supported by a browser:
- At least 4096 bytes per cookie
- At least 50 cookies per domain
- At least 3000 cookies in total
What types of cookies are there?
The question of which cookies we specifically use depends on the services used and is clarified in the following sections of the privacy policy. At this point, we would like to briefly discuss the different types of HTTP cookies.
Four types of cookies can be distinguished:
Essential cookies
These cookies are necessary to ensure basic functions of the website. For example, these cookies are needed when a user places a product in the shopping cart, then continues browsing on other pages, and only later proceeds to checkout. These cookies prevent the shopping cart from being deleted, even if the user closes their browser window.
Functional cookies
These cookies collect information about user behaviour and whether the user receives any error messages. Additionally, these cookies measure the loading time and behaviour of the website on different browsers.
Targeted cookies
These cookies ensure better user-friendliness. For example, entered locations, font sizes, or form data are stored.
Advertising cookies
These cookies are also called targeting cookies. They are used to deliver individually tailored advertising to the user. This can be very practical, but also very annoying.
Typically, when you first visit a website, you are asked which of these types of cookies you would like to allow. And of course, this decision is also stored in a cookie.
If you want to know more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265the Request for Comments by the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism.”
Purpose of processing via cookies
The purpose ultimately depends on the respective cookie. You can find more details below or from the manufacturer of the software that sets the cookie.
What data is processed?
Cookies are little helpers for a variety of tasks. Unfortunately, it is not possible to generalize which data is stored in cookies, but we will inform you about the processed or stored data within the framework of the following privacy policy.
Storage duration of cookies
The storage duration depends on the respective cookie and is specified further below. Some cookies are deleted in less than an hour, while others can remain stored on a computer for several years.
You also have control over the storage duration. You can manually delete all cookies at any time via your browser (see also below “Right to object”). Furthermore, cookies based on consent are deleted at the latest after you withdraw your consent, whereby the legality of the storage remains unaffected until then.
Right to object – how can I delete cookies?
You decide whether and how you want to use cookies. Regardless of which service or website the cookies originate from, you always have the option to delete, deactivate, or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.
If you want to find out which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find this in your browser settings:
Chrome: Delete, enable, and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Delete cookies to remove data that websites have placed on your computer
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete and manage cookies
If you generally do not want to have cookies, you can set your browser to always inform you when a cookie is to be set. This way, you can decide for each individual cookie whether you want to allow it or not. The procedure varies depending on the browser. It’s best to search for the instructions on Google with the search term “delete cookies Chrome” or “disable cookies Chrome” in the case of a Chrome browser.
Legal basis
Since 2009, there have been the so-called “Cookie Directives”. These state that the storage of cookies requires your consent (Article 6 (1) lit. a GDPR). However, there are still very different reactions to these directives within EU countries. In Austria, this directive was implemented in § 96 (3) of the Telecommunications Act (TKG). In Germany, the cookie directives were not implemented as national law. Instead, this directive was largely implemented in § 15 (3) of the Telemedia Act (TMG).
For strictly necessary cookies, even if no consent is present, there are legitimate interests (Article 6 (1) lit. f GDPR), which are mostly of an economic nature. We want to provide visitors to the website with a pleasant user experience, and certain cookies are often absolutely necessary for this.
Insofar as non-essential cookies are used, this only happens with your consent. The legal basis is Art. 6 (1) lit. a GDPR.
In the following sections, you will be informed in more detail about the use of cookies, provided that the software used employs cookies.
Web hosting introduction
|
Web hosting summary – Affected parties: Visitors to the website |
What is web hosting?
When you visit websites nowadays, certain information – including personal data – is automatically created and stored, as is the case on this website. These data should be processed as sparingly as possible and only with justification. By website, we mean the entirety of all web pages on a domain, i.e., everything from the homepage to the very last subpage (like this one). By domain, we mean, for example, beispiel.de or musterbeispiel.com.
If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We simply call them browsers or web browsers.
To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and demanding task, which is why it is usually taken over by professional providers. These providers offer web hosting and ensure reliable and error-free storage of website data. A whole lot of technical terms, but please stay with us, it gets better!
When the browser on your computer (desktop, laptop, tablet, or smartphone) connects and during data transmission to and from the web server, personal data may be processed. On one hand, your computer stores data, and on the other hand, the web server must also store data for a while to ensure proper operation.
A picture is worth a thousand words, so the following graphic illustrates the interaction between the browser, the internet, and the hosting provider.
Why do we process personal data?
The purposes of data processing are:
- Professional hosting of the website and securing its operation
- to maintain operational and IT security
- Anonymous evaluation of access behaviour to improve our offer and possibly for law enforcement or claims enforcement
Which data are processed?
Even while you are visiting our website right now, our web server, which is the computer where this website is stored, usually automatically saves data such as
- the complete internet address (URL) of the accessed webpage
- Browser and browser version (e.g., Chrome 87)
- the operating system used (e.g., Windows 10)
- the address (URL) of the previously visited page (Referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen/)
- the hostname and IP address of the device from which access is made (e.g., COMPUTERNAME and 194.23.43.121)
- Date and time
- in files called web server log files
How long are data stored?
As a rule, the above-mentioned data are stored for two weeks and then automatically deleted. We do not pass on these data, but we cannot exclude the possibility that these data may be viewed by authorities in the event of unlawful behaviour.
In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass on your data without consent!
Legal basis
The legality of processing personal data in the context of web hosting is derived from Art. 6 para. 1 lit. f GDPR (Protection of legitimate interests), as the use of professional hosting by a provider is necessary to present the company securely and user-friendly on the internet and to possibly pursue attacks and claims arising from it.
There is usually a contract for commissioned data processing in accordance with Art. 28 et seq. GDPR between us and the hosting provider, which ensures compliance with data protection and guarantees data security.
Web Hosting Provider External Privacy Policy
Below you will find the contact details of our external hosting provider, where you can learn more about data processing in addition to the information above:
easyname GmbH
Canettistraße 5/10, A-1100 Vienna
You can learn more about data processing at this provider in the Privacy Policy.
Web Analytics Introduction
|
Web Analytics Privacy Policy Summary – Affected parties: Visitors to the website |
What is Web Analytics?
We use software on our website to evaluate the behaviour of website visitors, known as web analytics or web analysis. Data is collected, which the respective analytics tool provider (also called a tracking tool) stores, manages, and processes. With the help of the data, analyses of user behaviour on our website are created and made available to us as website operators. Additionally, most tools offer various testing options. For example, we can test which offers or content are most popular with our visitors. To do this, we show you two different offers for a limited period. After the test (known as an A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analytics procedures, user profiles can also be created and the data can be stored in cookies.
Why do we conduct web analytics?
With our website, we have a clear goal in mind: we want to deliver the best web offering on the market for our industry. To achieve this goal, we want to offer the best and most interesting content and ensure that you feel completely comfortable on our website. With the help of web analysis tools, we can take a closer look at the behaviour of our website visitors and then improve our web offering for you and us accordingly. For example, we can determine the average age of our visitors, where they come from, when our website is most visited, or which content or products are particularly popular. All this information helps us to optimize the website and thus tailor it perfectly to your needs, interests, and wishes.
What data is processed?
Which data is stored exactly depends, of course, on the analysis tools used. But generally, for example, it is stored which content you view on our website, which buttons or links you click on, when you access a page, which browser you use, with which device (PC, tablet, smartphone, etc.) you visit the website or which computer system you use. If you have agreed that location data may also be collected, this can also be processed by the web analytics tool provider.
Additionally, your IP address will also be stored. According to the General Data Protection Regulation (GDPR), IP addresses are considered personal data. However, your IP address is usually stored in a pseudonymised form (i.e., in an unrecognisable and shortened form). For the purpose of testing, web analysis, and web optimisation, no direct data such as your name, age, address, or email address is stored. All these data, if collected, are stored in a pseudonymised manner. This means you cannot be identified as a person.
The following example schematically shows how Google Analytics works as an example of client-based web tracking with JavaScript code.
How long the respective data is stored always depends on the provider. Some cookies store data only for a few minutes or until you leave the website, while other cookies can store data for several years.
Duration of data processing
We inform you about the duration of data processing further below, provided we have more information on this. Generally, we process personal data only as long as it is absolutely necessary for providing our services and products. If it is legally required, as in the case of accounting, this storage period may also be exceeded.
Right to object
You also have the right and the opportunity to revoke your consent to the use of cookies or third-party providers at any time. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating, or deleting cookies in your browser.
Legal basis
The use of web analytics requires your consent, which we have obtained with our cookie popup. This consent constitutes, according to Art. 6 para. 1 lit. a GDPR (Consent) the legal basis for the processing of personal data, as may occur with the collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors to technically and economically improve our offering. With the help of web analytics, we can identify website errors, detect attacks, and improve profitability. The legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests). We only use the tools insofar as you have given consent.
Since cookies are used with web analytics tools, we also recommend reading our general privacy policy on cookies. To find out exactly what data of yours is stored and processed, you should read the privacy policies of the respective tools.
Information on specific web analytics tools, if available, can be found in the following sections.
Google Analytics Privacy Policy
|
Google Analytics Privacy Policy Summary – Affected parties: Website visitors |
What is Google Analytics?
We use the analysis tracking tool Google Analytics (GA) from the American company Google Inc. For the European region, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. For example, if you click on a link, this action is stored in a cookie and sent to Google Analytics. With the reports we receive from Google Analytics, we can better tailor our website and service to your needs. Below, we will take a closer look at the tracking tool and inform you about which data is stored and how you can prevent this.
Google Analytics is a tracking tool used for analysing the traffic on our website. For Google Analytics to work, a tracking code is embedded in the code of our website. When you visit our website, this code records various actions you perform on our site. Once you leave our website, this data is sent to the Google Analytics servers and stored there.
Google processes the data and we receive reports about your user behaviour. These reports can include, among others:
- Audience reports: Through audience reports, we get to know our users better and understand more precisely who is interested in our service.
- Ad reports: Ad reports allow us to analyse and improve our online advertising more easily.
- Acquisition reports: Acquisition reports provide us with helpful information on how we can attract more people to our service.
- Behaviour reports: Here we learn how you interact with our website. We can track the path you take on our site and which links you click on.
- Conversion reports: A conversion is an action you take in response to a marketing message, such as becoming a buyer or newsletter subscriber from a mere website visitor. These reports help us understand how our marketing efforts are received by you. This way, we aim to increase our conversion rate.
- Real-time reports: Here we can immediately see what is happening on our website. For example, we can see how many users are currently reading this text.
Why do we use Google Analytics on our website?
Our goal with this website is clear: We want to offer you the best possible service. The statistics and data from Google Analytics help us achieve this goal.
The statistically evaluated data gives us a clear picture of the strengths and weaknesses of our website. On one hand, we can optimise our site so that it is more easily found by interested people on Google. On the other hand, the data helps us understand you as a visitor better. We know very precisely what we need to improve on our website to offer you the best possible service. The data also helps us conduct our advertising and marketing measures more individually and cost-effectively. After all, it only makes sense to show our products and services to people who are interested in them.
What data is stored by Google Analytics?
Google Analytics creates a random, unique ID using a tracking code, which is linked to your browser cookie. This way, Google Analytics recognises you as a new user. When you visit our site again, you are recognised as a ‘returning’ user. All collected data is stored together with this user ID. This is what makes it possible to evaluate pseudonymous user profiles in the first place.
To be able to analyse our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For each newly created property, the Google Analytics 4 property is standard by default. Alternatively, you can also create the Universal Analytics property. Depending on the property used, data is stored for different lengths of time.
Your interactions on our website are measured through identifiers such as cookies and app instance IDs. Interactions are all types of actions you perform on our website. If you also use other Google systems (such as a Google account), data generated by Google Analytics can be linked with third-party cookies. Google does not share Google Analytics data unless we, as the website operator, authorise it. Exceptions may occur if required by law.
The following cookies are used by Google Analytics:
Name: _ga
Value: 2.1326744211.152122317514-5
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. It is primarily used to distinguish website visitors.
Expiration date: after 2 years
Name: _gid
Value: 2.1687193234.152122317514-1
Purpose:This cookie is also used to distinguish website visitors.
Expiration date: after 24 hours
Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose: Used to throttle request rate. If Google Analytics is provided via Google Tag Manager, this cookie is named _dc_gtm_ <property-id>.
Expiration date: after 1 minute
Name: AMP_TOKEN
Value: no information
Purpose: The cookie contains a token that can be used to retrieve a user ID from the AMP Client ID service. Other possible values indicate an opt-out, a request, or an error.
Expiration date: after 30 seconds to one year
Name: __utma
Value: 1564498958.1564498958.1564498958.1
Purpose: This cookie can track your behaviour on the website and measure performance. The cookie is updated each time information is sent to Google Analytics.
Expiration date: after 2 years
Name: __utmt
Value: 1
Purpose: The cookie is used like _gat_gtag_UA_<property-id> to throttle the request rate.
Expiration date: after 10 minutes
Name: __utmb
Value: 3.10.1564498958
Purpose: This cookie is used to determine new sessions. It is updated every time new data or information is sent to Google Analytics.
Expiration date: after 30 minutes
Name: __utmc
Value: 167421564
Purpose: This cookie is used to establish new sessions for returning visitors. It is a session cookie and is only stored until you close the browser.
Expiration date: Upon closing the browser
Name: __utmz
Value: m|utmccn=(referral)|utmcmd=referral|utmcct=/
Purpose: The cookie is used to identify the source of traffic to our website. This means the cookie stores where you came from to reach our website. This could be another page or an advertisement.
Expiration date: after 6 months
Name: __utmv
Value: no information
Purpose: The cookie is used to store custom user data. It is always updated when information is sent to Google Analytics.
Expiration date: after 2 years
Note:This list cannot claim to be complete, as Google frequently changes their choice of cookies.
Here we provide you with an overview of the most important data collected with Google Analytics:
Heatmaps: Google creates so-called heatmaps. Heatmaps show exactly which areas you click on. This way, we get information on where you are “travelling” on our site.
Session duration: Google refers to the session duration as the time you spend on our site without leaving it. If you have been inactive for 20 minutes, the session ends automatically.
Bounce rate (English: Bounce rate): A bounce occurs when you view only one page on our website and then leave our website again.
Account creation: When you create an account or make a purchase on our website, Google Analytics collects this data.
IP address: The IP address is only displayed in a shortened form so that no unique assignment is possible.
Location: The IP address can be used to determine the country and your approximate location. This process is also known as IP geolocation.
Technical information: Technical information includes, among other things, your browser type, your internet provider, or your screen resolution.
Source of origin: Google Analytics, and of course we, are also interested in which website or advertisement you came to our site from.
Further data includes contact details, any reviews, media playback (e.g., if you play a video via our site), sharing content via social media, or adding to your favourites. This list is not exhaustive and serves only as a general orientation of data storage by Google Analytics.
How long and where is the data stored?
Google has its servers distributed all over the world. Most servers are located in America, and consequently, your data is usually stored on American servers. Here you can read exactly where the Google data centres are located: https://www.google.com/about/datacenters/locations/?hl=de
Your data is distributed across various physical data carriers. This has the advantage that the data can be accessed more quickly and is better protected against manipulation. In every Google data centre, there are appropriate emergency programs for your data. For example, if the hardware at Google fails or natural disasters paralyse servers, the risk of service interruption at Google remains low.
The retention period of the data depends on the properties used. When using the newer Google Analytics 4 properties, the retention period of your user data is fixed at 14 months. For other so-called event data, we have the option to choose a retention period of 2 months or 14 months.
For Universal Analytics properties, Google Analytics has a standardised retention period of your user data set at 26 months. Then your user data is deleted. However, we have the option to choose the retention period of usage data ourselves. We have five options available for this:
- Deletion after 14 months
- Deletion after 26 months
- Deletion after 38 months
- Deletion after 50 months
- No automatic deletion
Additionally, there is also the option that data is only deleted if you no longer visit our website within the period we have chosen. In this case, the retention period is reset each time you visit our website again within the specified period.
When the specified period has expired, the data is deleted once a month. This retention period applies to your data linked to cookies, user recognition, and advertising IDs (e.g., cookies from the DoubleClick domain). Reporting results are based on aggregated data and are stored independently of user data. Aggregated data is a merging of individual data into a larger unit.
How can I delete my data or prevent data storage?
Under the data protection law of the European Union, you have the right to access your data, update it, delete it, or restrict its processing. By using the browser add-on to disable Google Analytics JavaScript (ga.js, analytics.js, dc.js), you prevent Google Analytics from using your data. You can download and install the browser add-on at https://tools.google.com/dlpage/gaoptout?hl=de Please note that this add-on only disables data collection by Google Analytics.
If you want to generally disable, delete, or manage cookies, you will find the relevant links to the instructions for the most popular browsers under the section “Cookies”.
Legal basis
The use of Google Analytics requires your consent, which we have obtained with our cookie popup. This consent constitutes, according to Art. 6 para. 1 lit. a GDPR (Consent) the legal basis for the processing of personal data, as may occur with the collection by web analytics tools.
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors to improve our offering technically and economically. With the help of Google Analytics, we can identify website errors, detect attacks, and improve profitability. The legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests). Nevertheless, we only use Google Analytics if you have given consent.
Google processes your data, among other places, in the USA. We point out that, according to the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. This can entail various risks for the legality and security of data processing.
As a basis for data processing with recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, particularly in the USA) or a data transfer there, Google uses so-called Standard Contractual Clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when transferred and stored in third countries (such as the USA). Through these clauses, Google commits to maintaining the European data protection level when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
We hope we have provided you with the most important information about Google Analytics data processing. If you want to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/de/ and https://support.google.com/analytics/answer/6004245?hl=de.
Data Processing Agreement (DPA) Google Analytics
In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have concluded a Data Processing Agreement (DPA) with Google. You can read what a DPA is exactly and what must be included in a DPA in our general section “Data Processing Agreement (DPA)”.
This contract is legally required because Google processes personal data on our behalf. It clarifies that Google may only process data they receive from us according to our instructions and must comply with the GDPR. You can find the link to the data processing terms at https://business.safety.google/intl/de/adsprocessorterms/
Google Analytics reports on demographic characteristics and interests
We have enabled advertising reporting features in Google Analytics. The demographic and interest reports include information about age, gender, and interests. This allows us to get a better understanding of our users without being able to assign this data to individual people. Learn more about the advertising features at https://support.google.com/analytics/answer/3450482?hl=de_AT&utm_id=ad.
You can manage the use of your Google account activities and information under ‘Ads Settings’ at https://adssettings.google.com/authenticated by unchecking the box.
Google Analytics in consent mode
Depending on your consent, personal data about you is processed by Google Analytics in the so-called consent mode. You can choose whether to agree to Google Analytics cookies or not. This also determines which data Google Analytics is allowed to process about you. These collected data are mainly used to conduct measurements about user behaviour on the website, deliver targeted advertising, and provide us with web analysis reports. Generally, you consent to data processing by Google via a cookie consent tool. If you do not consent to data processing, only aggregated data will be collected and processed. This means data cannot be assigned to individual users, and no user profile of you is created. You can also agree to statistical measurement only. In this case, no personal data is processed and therefore not used for advertising or advertising success measurement.
Google Analytics IP anonymisation
We have implemented IP address anonymisation on this website for Google Analytics. This function was developed by Google to ensure that this website complies with applicable data protection regulations and recommendations of local data protection authorities when they prohibit the storage of full IP addresses. Anonymisation or masking of the IP occurs as soon as the IP addresses arrive in the Google Analytics data collection network and before any storage or processing of the data takes place.
Find more information about IP anonymisation at https://support.google.com/analytics/answer/2763052?hl=de.
Google Site Kit Privacy Policy
|
Google Site Kit Privacy Policy Summary – Affected parties: Visitors to the website |
What is Google Site Kit?
We have integrated the WordPress plugin Google Site Kit from the American company Google Inc. into our website. For the European region, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. With Google Site Kit, we can quickly and easily view statistics from various Google products, such as Google Analytics, directly in our WordPress dashboard. The tool or the tools integrated into Google Site Kit also collect personal data from you. In this privacy policy, we explain why we use Google Site Kit, how long and where data is stored, and which other privacy texts are relevant for you in this context.
Google Site Kit is a plugin for the WordPress content management system. With this plugin, we can view important website analysis statistics directly in our dashboard. These are statistics collected by other Google products, primarily Google Analytics. In addition to Google Analytics, services like Google Search Console, Page Speed Insight, Google AdSense, Google Optimize, and Google Tag Manager can also be linked with Google Site Kit.
Why do we use Google Site Kit on our website?
As a service provider, it is our duty to offer you the best possible experience on our website. You should feel comfortable on our site and quickly and easily find exactly what you’re looking for. Statistical evaluations help us get to know you better and tailor our offerings to your needs and interests. For these evaluations, we use various Google tools. Site Kit greatly facilitates this work because we can view and analyze the statistics of Google products directly in the dashboard. We no longer need to log in separately for each tool. Site Kit thus always provides a good overview of the most important analysis data.
What data is stored by Google Site Kit?
If you have actively consented to tracking tools in the cookie notice (also called script or banner), Google products like Google Analytics set cookies and data about you, such as your user behavior, is sent to Google, stored, and processed there. This also includes personal data such as your IP address.
For more detailed information on the individual services, we have dedicated sections in this privacy policy. For example, take a look at our privacy policy on Google Analytics. Here we go into great detail about the data collected. You will learn how long Google Analytics stores, manages, and processes data, which cookies may be used, and how you can prevent data storage. We also have separate privacy policies with comprehensive information for other Google services such as Google Tag Manager or Google AdSense.
Below we show you example Google Analytics cookies that can be set in your browser if you have generally consented to data processing by Google. Please note that these cookies are just a selection:
Name: _ga
Value:2.1326744211.152122317514-2
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. It is generally used to distinguish website visitors.
Expiration date: after 2 years
Name: _gid
Value:2.1687193234.152122317514-7
Purpose: This cookie is also used to distinguish website visitors.
Expiration date: after 24 hours
Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose: This cookie is used to reduce the request rate.
Expiration date: after 1 minute
How long and where is the data stored?
Google stores collected data on its own servers, which are distributed worldwide. Most servers are located in the United States, so it is quite possible that your data is also stored there. On https://www.google.com/about/datacenters/locations/?hl=de you can see exactly where the company provides servers.
Data collected by Google Analytics is retained for 26 months by default. After that, your user data is deleted. The retention period applies to all data linked with cookies, user identification, and advertising IDs.
How can I delete my data or prevent data storage?
You always have the right to access your data, have it deleted, corrected, or restricted. Additionally, you can also disable, delete, or manage cookies in your browser at any time.
If you wish to generally disable, delete, or manage cookies, you will find the relevant links to the instructions for the most popular browsers under the section “Cookies”.
Legal basis
The use of Google Site Kit requires your consent, which we have obtained through our cookie popup. This consent constitutes the legal basis for the processing of personal data, as may occur with the collection by web analytics tools, according to Art. 6 para. 1 lit. a GDPR (Consent) .
In addition to consent, we have a legitimate interest in analysing the behaviour of website visitors to improve our offer technically and economically. With the help of Google Site Kit, we can identify website errors, detect attacks, and improve profitability. The legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests). We only use Google Site Kit if you have given consent.
Google processes data from you, among other places, in the USA. We point out that, according to the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. This can involve various risks for the legality and security of data processing.
As a basis for data processing with recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, particularly in the USA) or a data transfer there, Google uses so-called Standard Contractual Clauses (= Art. 46 para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are template contracts provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when transferred to and stored in third countries (such as the USA). Through these clauses, Google commits to maintaining the European data protection level when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/
To learn more about data processing by Google, we recommend Google’s comprehensive privacy policies at https://policies.google.com/privacy?hl=de.
Messenger & Communication Introduction
|
Messenger & Communication Privacy Policy Summary – Affected parties: Visitors to the website |
What are messenger & communication functions?
We offer various options on our website (such as messenger and chat functions, online or contact forms, email, phone) to communicate with us. Your data will also be processed and stored as necessary to respond to your inquiry and our subsequent actions.
In addition to classic communication methods such as email, contact forms, or phone, we also use chats and messengers. The most commonly used messenger function currently is WhatsApp, but there are, of course, many different providers offering messenger functions specifically for websites. If content is end-to-end encrypted, this is indicated in the individual data protection texts or in the privacy policy of the respective provider. End-to-end encryption simply means that the content of a message is not visible even to the provider. However, information about your device, location settings, and other technical data can still be processed and stored.
Why do we use messenger & communication functions?
Communication options with you are of great importance to us. After all, we want to talk to you and answer any questions about our service as best as possible. Well-functioning communication is an important part of our service. With the practical messenger & communication functions, you can always choose the one you prefer. In exceptional cases, however, it may happen that we cannot answer certain questions via chat or messenger. This is the case when it comes to internal contractual matters, for example. Here we recommend other communication options such as email or phone.
We generally assume that we remain responsible under data protection law, even when we use the services of a social media platform. However, the European Court of Justice has decided that in certain cases, the operator of the social media platform can be jointly responsible with us in the sense of Art. 26 GDPR. If this is the case, we will point it out separately and work on the basis of a related agreement. The essence of the agreement is reproduced further down with the affected platform.
Please note that when using our embedded elements, your data may also be processed outside the European Union, as many providers, such as Facebook Messenger or WhatsApp, are American companies. As a result, you may find it more difficult to assert or enforce your rights regarding your personal data.
What data is processed?
The exact data stored and processed depends on the respective provider of the messenger & communication functions. Generally, it involves data such as name, address, phone number, email address, and content data like all the information you enter into a contact form. Information about your device and the IP address is usually also stored. Data collected via a messenger & communication function is also stored on the providers’ servers.
If you want to know exactly what data is stored and processed by the respective providers and how you can object to data processing, you should carefully read the company’s respective privacy policy.
How long is data stored?
How long the data is processed and stored primarily depends on the tools we use. Further down, you will find more information about the data processing of each tool. The providers’ privacy policies usually specify exactly which data is stored and processed and for how long. Generally, personal data is only processed for as long as it is necessary to provide our services. If data is stored in cookies, the storage duration can vary greatly. The data may be deleted immediately after leaving a website, but it can also be stored for several years. Therefore, you should examine each cookie in detail if you want to know more about data storage. Most of the time, you will also find insightful information about individual cookies in the providers’ privacy policies.
Right to object
You also have the right and the opportunity to revoke your consent to the use of cookies or third-party providers at any time. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection by cookies by managing, disabling, or deleting cookies in your browser. For further information, please refer to the section on consent.
Since cookies may be used for messenger & communication functions, we also recommend our general privacy policy on cookies. To find out exactly which data of yours is stored and processed, you should read the privacy policies of the respective tools.
Legal basis
If you have consented to the processing and storage of your data through integrated messenger & communication functions, this consent serves as the legal basis for data processing (Art. 6 para. 1 lit. a GDPR). We process your request and manage your data within the framework of contractual or pre-contractual relationships to fulfil our pre-contractual and contractual obligations or to respond to inquiries. The basis for this is Art. 6 para. 1 sentence 1 lit. b GDPR. Generally, your data is also stored and processed based on our legitimate interest (Art. 6 para. 1 lit. f GDPR) in fast and good communication with you or other customers and business partners.
Facebook Messenger Privacy Policy
We use the communication tool Facebook Messenger on our website. The service provider is the American company Meta Platforms Inc. For the European region, the company Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) is responsible.
Facebook processes your data, among other places, in the USA. We point out that, according to the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. This may involve various risks for the legality and security of data processing.
As the basis for data processing with recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway, particularly in the USA) or a data transfer there, Facebook uses so-called Standard Contractual Clauses (= Art. 46. para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when it is transferred to and stored in third countries (such as the USA). Through these clauses, Facebook commits to maintaining the European data protection level when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses, among others, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can find the Facebook data processing terms, which correspond to the Standard Contractual Clauses, at https://www.facebook.com/legal/terms/dataprocessing.
Learn more about the data processed through the use of Facebook in the Privacy Policy at https://www.facebook.com/about/privacy.
Data Processing Agreement (DPA) Facebook Messenger
In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have concluded a Data Processing Agreement (DPA) with Facebook. What exactly a DPA is and what must be included in a DPA can be read in our general section “Data Processing Agreement (DPA)”.
This contract is legally required because Facebook processes personal data on our behalf. It clarifies that Facebook may only process data they receive from us according to our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) at https://www.facebook.com/legal/terms/dataprocessing.
WhatsApp Privacy Policy
We use the instant messaging service WhatsApp on our website. The service provider is the American company WhatsApp Inc., a subsidiary of Meta Platforms Inc. For the European region, the company responsible is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
WhatsApp processes data from you, among other places, in the USA. We point out that, according to the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. This can involve various risks for the legality and security of data processing.
As the basis for data processing with recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway, particularly in the USA) or a data transfer there, WhatsApp uses so-called Standard Contractual Clauses (= Art. 46. para. 2 and 3 GDPR). Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data also complies with European data protection standards when it is transferred to and stored in third countries (such as the USA). Through these clauses, WhatsApp commits to maintaining the European data protection level when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses, among others, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
Information on data transfer with WhatsApp, which corresponds to the Standard Contractual Clauses, can be found at https://www.whatsapp.com/legal/business-data-transfer-addendum-20210927
Learn more about the data processed through the use of WhatsApp in the Privacy Policy at https://www.whatsapp.com/privacy
Chatbots Introduction
|
Chatbots Privacy Policy Summary – Affected: Visitors to the website |
What are chatbots?
You can also communicate with us via chatbots or similar chat functions. A chat offers the opportunity to write or speak with very little delay. A chatbot is software that tries to answer your question and may inform you about news. By using these communication tools, your personal data can also be processed and stored.
Why do we use chatbots?
Communication options with you are important to us. After all, we want to talk to you and answer any questions about our service as best as possible. Well-functioning communication is an important part of our service. Chatbots have the great advantage that we can automatically answer frequently asked questions with the help of this software. This saves us time and you still receive detailed and helpful answers. If the chatbot cannot help further, you of course always have the option to contact us personally.
Please note that when using our embedded elements, your data may also be processed outside the European Union, as many providers are American companies. As a result, you may not be able to assert or enforce your rights regarding your personal data as easily.
What data is processed?
It may happen that you also use the chat services on other websites/platforms. In this case, your user ID is also stored on the servers of this website. We can also be informed about which user used the chat at what time. The contents are also stored. Which data is exactly stored depends on the respective service. However, it usually involves contact data such as email address or phone number, IP address, and various usage data.
If you have consented to the use of the chat function, this consent along with any possible registration will also be stored or logged. We do this so that we can provide proof of registration or consent if legally required.
The provider of a chat platform can also know when you are chatting and receives technical information about the device you are using. What information is exactly stored and processed also depends on your PC settings. In many cases, data about your approximate location can be collected. This is done on the one hand to optimize the chat services and on the other hand to ensure more security. Furthermore, the information can also be used to implement personalized advertising and marketing measures.
If you have consented to a chatbot sending you messages, you can of course deactivate this activation at any time. The chatbot also serves as a help and shows you how to unsubscribe from this function. All your related data will then be deleted from the recipient directory.
We use the above-mentioned data to address you personally via chat, to answer your questions and inquiries, or to send you possible content. Additionally, we can also fundamentally improve our chat services with it.
How long is data stored?
How long the data is processed and stored primarily depends on the tools we use. Further down, you will learn more about the data processing of each tool. The providers’ privacy policies usually specify exactly which data is stored and processed and for how long. In general, personal data is only processed as long as it is necessary to provide our services. If data is stored in cookies, the storage duration varies greatly. The data can be deleted immediately after leaving a website, but it can also be stored for several years. Therefore, you should look at each individual cookie in detail if you want to know more about data storage. Most of the time, you will also find insightful information about individual cookies in the providers’ privacy policies.
Right to object
You also have the right and the opportunity to revoke your consent to the use of cookies or third-party providers at any time. This can be done either through our cookie management tool or through other opt-out functions. For example, you can also prevent data collection through cookies by managing, disabling, or deleting cookies in your browser.
Since cookies can be used in chat services, we also recommend our general privacy policy on cookies. To find out exactly what data of yours is stored and processed, you should read the privacy policies of the respective tools.
Legal basis
We ask for your permission via a pop-up window to process your data within the framework of chat services. If you consent, this consent also serves as the legal basis (Art. 6 para. 1 lit. a GDPR) for data processing. In addition, we process your inquiries and manage your data within the framework of contractual or pre-contractual relationships to fulfil our pre-contractual and contractual obligations or to respond to inquiries. The basis for this is Art. 6 para. 1 sentence 1 lit. b. GDPR. In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6 para. 1 lit. f GDPR) in fast and good communication with you or other customers and business partners. We only use the tools if you have given consent.
Online Marketing Introduction
|
Online Marketing Privacy Policy Summary – Affected parties: Visitors to the website |
What is online marketing?
Online marketing refers to all measures carried out online to achieve marketing goals such as increasing brand awareness or completing a business transaction. Furthermore, our online marketing measures aim to draw people’s attention to our website. To showcase our offerings to many interested people, we engage in online marketing. This usually involves online advertising, content marketing, or search engine optimisation. To use online marketing efficiently and purposefully, personal data is also stored and processed. The data helps us to show our content only to those who are genuinely interested and also allows us to measure the advertising success of our online marketing measures.
Why do we use online marketing tools?
We want to show our website to everyone interested in our offerings. We are aware that this is not possible without consciously set measures. That’s why we do online marketing. There are various tools that make our work on online marketing measures easier and also constantly provide improvement suggestions through data. This allows us to target our campaigns more precisely to our audience. The purpose of these online marketing tools is ultimately to optimise our offerings.
What data is processed?
For our online marketing to work and the success of the measures to be measured, user profiles are created and data is stored, for example, in cookies (these are small text files). With the help of this data, we can not only place advertising in the traditional sense but also display our content directly on our website in the way you prefer. There are various third-party tools that offer these functions and accordingly also collect and store data from you. For example, the named cookies store which pages you have visited on our website, how long you viewed these pages, which links or buttons you click, or from which website you came to us. Additionally, technical information can also be stored. For instance, your IP address, which browser you use, from which device you visit our website, or the time when you accessed our website and when you left it again. If you have consented to us determining your location, we can also store and process this.
Your IP address is stored in a pseudonymised form (i.e., shortened). Unique data that directly identifies you as a person, such as name, address, or email address, is also stored in a pseudonymised form within the advertising and online marketing procedures. We cannot identify you as a person; we only have the pseudonymised, stored information in the user profiles.
The cookies may also be used, analysed, and utilised for advertising purposes on other websites that work with the same advertising tools. The data can then also be stored on the servers of the advertising tool providers.
In exceptional cases, unique data (names, email address, etc.) may be stored in the user profiles. This storage occurs, for example, if you are a member of a social media channel that we use for our online marketing measures and the network connects previously received data with the user profile.
For all advertising tools we use that store data about you on their servers, we only ever receive aggregated information and never data that makes you identifiable as an individual. The data merely shows how well the advertising measures worked. For example, we can see which measures prompted you or other users to visit our website and purchase a service or product. Based on the analyses, we can improve our advertising offer in the future and tailor it even more precisely to the needs and wishes of interested individuals.
Duration of data processing
We will inform you about the duration of data processing further below, if we have more information on this. In general, we process personal data only as long as it is absolutely necessary for the provision of our services and products. Data stored in cookies is stored for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may be stored in your browser for several years. You will usually find precise information about the individual cookies used by the provider in the respective privacy policies of the individual providers.
Right to object
You also have the right and the opportunity to withdraw your consent to the use of cookies or third-party providers at any time. This can be done either via our cookie management tool or through other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser. The lawfulness of the processing up to the point of withdrawal remains unaffected.
Since online marketing tools generally use cookies, we also recommend our general privacy policy on cookies. To find out exactly what data about you is stored and processed, you should read the privacy policies of the respective tools.
Legal basis
If you have consented to the use of third-party providers, the legal basis for the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (Consent) this consent forms the legal basis for the processing of personal data, as may occur when collected by online marketing tools.
We also have a legitimate interest in measuring online marketing measures in an anonymised form in order to optimise our offer and measures using the data obtained. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests). However, we only use the tools if you have given your consent.
Information on specific online marketing tools is provided – if available – in the following sections.
Explanation of terms used
We always strive to make our privacy policy as clear and understandable as possible. However, this is not always easy, especially with technical and legal topics. It often makes sense to use legal terms (such as personal data) or certain technical expressions (such as cookies, IP address). However, we do not want to use these without explanation. Below you will find an alphabetical list of important terms used, which we may not have sufficiently addressed in the previous privacy policy. If these terms are taken from the GDPR and are definitions, we will also include the GDPR texts here and, if necessary, add our own explanations.
Processor
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“Processor” a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data we process from you. In addition to the controllers, there may also be so-called processors. This includes any company or person that processes personal data on our behalf. Processors can therefore include service providers such as tax advisors, as well as hosting or cloud providers, payment or newsletter providers, or large companies like Google or Microsoft.
Concerned supervisory authority
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“concerned supervisory authority” a supervisory authority which is concerned by the processing of personal data becausea)
the controller or processor is established on the territory of the Member State of that supervisory authority,
b)
this processing substantially affects or is likely to affect data subjects with residence in the Member State of that supervisory authority, or
c)
a complaint has been lodged with that supervisory authority;
Explanation: In Germany, each federal state has its own data protection supervisory authority. So if your company headquarters (main establishment) is in Germany, the respective supervisory authority of the federal state is your contact point. In Austria, there is only one Data Protection Authority for the entire country.
Biometric data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“biometric data” personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;
Explanation: These are biological characteristics described by biometric data from which personal data can be obtained using technical procedures. These include DNA, fingerprints, the geometry of various body parts, height, but also handwriting or the sound of a voice.
Filing system
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“filing system” any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis;
Explanation: Any organised storage of data on a computer’s data carrier is referred to as a “filing system”. If we store your name and email address on a server for our newsletter, then this data is in a so-called “filing system”. The main tasks of a “filing system” include the quick search and retrieval of specific data and, of course, the secure storage of the data.
Consent
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“consent” any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them;
Explanation: Usually, on websites, such consent is obtained through a cookie consent tool. You probably know this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree to data processing or consent to it. You can often make individual settings and decide for yourself which data processing you allow and which you do not. If you do not consent, no personal data about you may be processed. Of course, consent can also be given in writing, not just through a tool.
Personal data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“personal data”
all information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Explanation: Personal data is therefore all data that can identify you as a person. These are usually data such as:
- Name
- Address
- Email address
- Postal address
- Telephone number
- Date of birth
- Identification numbers such as social security number, tax identification number, identity card number or matriculation number
- Bank data such as account number, credit information, account balances, etc.
According to the European Court of Justice (ECJ), your IP address is also considered personal data. IT experts can use your IP address to determine at least the approximate location of your device and subsequently identify you as the subscriber. Therefore, storing an IP address also requires a legal basis under the GDPR. There are also so-called “special categories” of personal data, which are particularly worthy of protection. These include:
- racial and ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership
- genetic data such as data obtained from blood or saliva samples
- biometric data (these are information about physical, physiological or behavioural characteristics that can identify a person).
Health data - Data concerning sexual orientation or sex life
Profiling
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“profiling” any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning the natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
Explanation: Profiling involves gathering various information about a person to learn more about them. In the web sector, profiling is often used for advertising purposes or credit checks. Web or advertising analysis programs, for example, collect data about your behaviour and interests on a website. This results in a specific user profile, which can be used to target advertising to a specific audience.
Controller
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term means:
“controller” the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its nomination may be provided for by Union law or the law of the Member States;
Explanation: In our case, we are responsible for processing your personal data and are therefore the ‘controller’. If we pass on collected data to other service providers for processing, they are ‘processors’. A ‘Data Processing Agreement (DPA)’ must be signed for this purpose.
Closing words
Congratulations! If you are reading these lines, you have really ‘fought’ your way through our entire privacy policy or at least scrolled down to this point. As you can see from the extent of our privacy policy, we take the protection of your personal data very seriously.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, we not only want to inform you about which data is processed, but also to explain the reasons for using various software programs. Privacy policies usually sound very technical and legal. However, since most of you are neither web developers nor lawyers, we wanted to take a different linguistic approach and explain the facts in simple and clear language. Of course, this is not always possible due to the nature of the topic. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions about data protection on our website, please do not hesitate to contact us or the responsible body. We wish you a pleasant time and hope to welcome you back to our website soon.
All texts are copyright protected.
Source: Created with the Privacy Policy Generator by AdSimple