Privacy Policy
Notes:
A privacy policy can only be prepared once all tools and applications used in the course of data processing (for marketing purposes), and thus all categories of personal data and their use, are known. The following sample declaration therefore provides a framework that must be supplemented in the individual points depending on the processing activities. Source note: This sample declaration was prepared in particular with reference to the Form Manual on Data Protection Law² (Koreng/Lachenmann) and the WEKA publication Practical Knowledge of Data Protection, loose-leaf edition.
To find out which cookies, plugins or other applications are active on your webpage, it is advisable to use various tools (such as a cookie viewer or similar) to check whether cookies are being stored. If this is the case, the website designer should be consulted and the relevant information obtained. Some of the most common tools and plugins are included in this sample privacy policy.
No liability can be accepted for the completeness and accuracy of this privacy policy in the event of its unreviewed use, especially as it must always be assessed and adapted based on the actual functions of a website and the data processing activities of a company. This template can therefore only serve as a guide for creating a legally compliant privacy policy for your own homepage.
PRIVACY POLICY
This website is operated by Condeli GmbH, hereinafter referred to as “we”, “us” and “Condeli GmbH”, with its registered office at Gewerbepark 1, 4193 Reichenthal | Austria. In this privacy policy, we, as the controller pursuant to Art. 4 para. 7 GDPR, describe which data we collect when you visit our website and for what purpose we process it. We also inform you about how we generally process data of our customers, suppliers and interested parties and finally explain which rights and safeguards we provide in the course of data processing. Please refer to section 11 of this privacy policy for all relevant contact details.
As the protection of your personal data is of particular concern to us, we strictly comply with the legal requirements of the DSG and the GDPR when collecting and processing your personal data.
Below, we inform you in detail about the scope and purpose of our data processing, as well as your rights as a data subject. Please read our privacy policy carefully before continuing to use our website and, where applicable, giving your consent to data processing.
- Personal Data
In principle, it is possible to use our website without providing personal data. However, different provisions may apply to the use of individual services, which we will inform you of separately.
Therefore, apart from the cookies described in detail below where applicable, we generally only collect and store the data that you provide to us yourself by entering it into our input forms or by otherwise actively interacting with our website.
Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, address, telephone number or date of birth, as well as your IP address or geolocation data that allows conclusions to be drawn about you.
- Use of Cookies
- If you use our website for informational purposes only, meaning that you do not register for a service or otherwise provide us with information — for example via a contact form — we only collect the personal data that your browser transmits to our server. Therefore, if you wish to visit our website, we collect the data listed below, which is technically necessary for us to display the website to you and to ensure its stability and security pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR:
- IP-Address
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request
- Access status / HTTP status code
- Amount of data transferred in each case
- Website from which the request originates
- Browser used
- Operating system and its interface
- Language and version of the browser software
However, this data is not processed beyond the purpose of displaying our website.
- In addition to the data mentioned above, first- and third-party cookies are stored on your computer when you use our website; these are small text files that are stored on your hard drive and assigned to the browser you are using. The party that sets a cookie (either us or an explicitly named third party) thereby receives certain information.
We need these cookies, on the one hand, to recognise you as a user of the website and, on the other hand, to be able to track the use of our services. Finally, we may use cookies for marketing purposes in order to analyse your usage behaviour and, where applicable, provide you with targeted advertising.
- A basic distinction can be made between first-party cookies, third-party cookies and third-party requests.
- First-party cookies
First-party cookies are stored in your browser by us or by our website itself in order to provide you with the best possible user experience. These are, in particular, functional cookies, such as shopping cart cookies. We may also use cookies to identify you on subsequent visits if you have an account with us – otherwise, you would have to log in again each time you visit.
- Third-party cookies
Third-party cookies are stored in your browser by a third-party provider. These are usually tracking or marketing tools that, on the one hand, evaluate your user behaviour and, on the other hand, enable the third-party provider to recognise you on other websites you visit. Retargeting marketing, for example, is generally based on the function of such cookies.
- Third-party requests
Third-party requests are all requests that you, as a website user, make to third parties via our website – for example, when you interact with social network plugins or use the services of a payment provider. In this case, no cookies are stored in your browser, but it cannot be ruled out that personal data may be sent to this third-party provider as a result of the interaction. For this reason, we also provide you with detailed information in our privacy policy about the tools & applications we use.
- To provide you with comprehensive information about the cookies we use, we have designed a cookie banner in accordance with the case law of the ECJ of 01/10/2019, C-673/17 (Planet 49), as well as other relevant decisions, which is displayed to you when you first visit our website. This cookie banner shows all cookies used, including their function, storage duration and origin. Cookies will only be stored by us if you consent to the use of some or all cookies; an exception may apply to technically strictly necessary cookies, without which our website could not be displayed correctly.
- You may change your browser settings at any time, for example to reject third-party cookies or all cookies. In this case, however, we must point out that you may no longer be able to use all functions of our website.
- Collection and Processing of Personal Data
- Website
Personal data beyond the information stored by cookies is processed by us in the course of operating our website only if you voluntarily provide it to us, for example when you register with us, enter into a contractual relationship with us or otherwise contact us. This consists exclusively of contact details and information relating to the matters with which you approach us.
We use the personal data you provide only to the extent necessary for fulfilling the respective purpose of processing (e.g. registration, sending newsletters, processing an order, sending information material and advertising, carrying out a prize draw, answering a question, enabling access to certain information) and insofar as this is permitted by law (in particular pursuant to Art. 6 or Art. 9 GDPR), e.g. sending advertising and information material to existing customers pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR.
The purpose of processing your data is to operate our website and to provide targeted company-specific information, including the presentation of our range of goods and services (marketing).
Any further use of your data will only take place to the extent that you have previously given your explicit consent, we require your data to fulfil a contract concluded with you, or we are obliged to retain it due to a statutory provision. Any consent given may be withdrawn at any time with future effect, as explained in detail below.
- Contract processing, marketing and more
In general, we use personal data of our customers, suppliers and other contractual and cooperation partners, e.g. contact persons, their contact details and marketing-relevant information, for the purpose of contract processing and within the scope of statutory retention obligations (e.g. accounting), and beyond that also on the basis of legitimate interest, for example for marketing and customer support purposes.
In addition, we collect personal data of interested parties (e.g. contact persons, their contact details and marketing-relevant information) in the course of our acquisition and sales activities. We are constantly searching for potential contractual partners on the internet, at trade fairs and at other events and, for this purpose, maintain a marketing database in order to enable targeted advertising for our products and services. We carry out all of the measures listed here on the basis of our legitimate interest for marketing purposes pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR in conjunction with Recital 47 for a period of three years from the end of a contractual relationship (customers & suppliers) or from our first unsuccessful contact (interested parties), unless the data subject has given explicit consent beyond this period.
If we do not collect personal data for marketing purposes directly from the data subject, we also inform the data subject, pursuant to Art. 14 GDPR, at the time of first contact, where we obtained their data.
- Application Management
We collect data from applicants for job vacancies at our company for the purpose of initiating a possible employment relationship pursuant to Art. 6 para. 1 sentence 1 lit. b GDPR, or, where applicable, on the basis of explicit consent for record-keeping purposes.
- Storage Period
Data that you have provided to us exclusively for customer support or for marketing and information purposes will generally be stored until three years after our last contact. However, if you so request, we will delete your data before this period expires, provided there is no legal obstacle to doing so.
In the event of contract initiation or conclusion, we process your personal data after full completion of the contract until the expiry of the guarantee, warranty, limitation and statutory retention periods applicable to us, and beyond that until the conclusion of any legal disputes in which the data is required as evidence.
Data that you may provide to us as part of an application process will be retained for a period of only 6 months without separate consent.
If storage is legally required, we comply with the period stipulated therein. If we process your personal data beyond the purposes set out in this privacy policy — for example on the basis of legitimate interest — we will inform you separately before commencing such processing.
- Data Transmission
- General
In principle, your data will not be transmitted to third parties unless we are legally obliged to do so, the disclosure of data is necessary for the performance of a contractual relationship concluded between us, or you have previously expressly consented to the disclosure of your data.
External processors or other cooperation partners will only receive your data to the extent that this is necessary for contract processing, we have a legitimate interest in doing so, which we will always disclose separately in the relevant case, or where this is required due to special legal provisions, with your consent.
Your personal data will not be sold or otherwise marketed by us to third parties. If our contractual partners or processors are based in a third country, i.e. a country outside the European Economic Area (EEA), we will inform you about the consequences of this circumstance in the description of the offer.
If one of our processors comes into contact with your personal data, we ensure that they comply with the provisions of data protection laws in the same way as we do.
- Data transfer to the USA?
We occasionally offer certain services in the course of which data transfer to the USA takes place or may take place. In order to use these services — unless another legal basis exists, such as the fulfilment of contractual obligations — it is therefore necessary that you consent, where applicable, to the use of your data collected via these services, including in the USA (Art. 49 para. 1 lit. a GDPR).
We obtain this consent — depending on the service — via our cookie banner or separately through a corresponding declaration of consent directly before using an offered service.
Your consent is required because, according to the most recent decisions by authorities and courts as well as the case law of the ECJ, the USA is not deemed to provide an adequate level of data protection for the processing of personal data (C-311/18, Schrems II). These decisions by authorities and courts particularly highlight that access by US authorities (FISA 702) is not comprehensively restricted by law, does not require approval by an independent body, and that no relevant legal remedies are available to data subjects in the event of such interference.
Apart from the contracts concluded with US service providers, we have no direct influence on access by US authorities to personal data transferred to service providers in the USA when using these services. Even though we assume that our service providers take the necessary steps in accordance with the contractual agreements concluded with us to ensure the promised level of protection, access by US authorities to data processed in the USA is nevertheless conceivable.
We therefore ask for your consent to the processing of data in the USA before using such services. For each service or application, we will separately indicate that data transfer to the USA may occur.
- Newsletter
You have the option to subscribe to our free newsletter. With this newsletter, you will receive all the latest news and information about our company as well as tailored advertising at regular intervals. In order to receive our newsletter, you need a valid email address.
We check the email address entered by you in our registration form to verify whether you actually wish to receive newsletters. This is done by sending an email to the email address provided by you, the receipt of which you can confirm by clicking on a link provided. Once the email has been confirmed, you are subscribed to our newsletter. (Double opt-in)
Upon initial registration for the newsletter, we store your IP address, the date and the time of your registration. This is done for security reasons in the event that a third party misuses your email address and subscribes to our newsletter without your knowledge. We do not collect or process any further data for the newsletter subscription; the data is used exclusively for receiving the newsletter.
Unless you object, we may transfer your data to companies affiliated with our company under corporate law for the purpose of analysis and for sending information for advertising purposes. Within the corporate group, the data you have provided to us for receiving the newsletter will be compared with data that we may collect from you elsewhere (e.g. when purchasing goods or booking a service).
Your data provided for newsletter registration will not be passed on to third parties that do not belong to the corporate group. You may unsubscribe from our newsletter at any time; details on how to unsubscribe can be found in the confirmation email and in each individual newsletter.
- Tools and Applications Used
- We use Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. This service uses cookies, the functionality of which has already been explained in detail above. The information generated by these cookies about your use of this website is usually transmitted to a Google server and stored there.
On our behalf, Google uses this information to evaluate your use of our website, to compile reports on website activity and to provide the website operator with other services related to website use and internet use. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.
You can prevent the storage of cookies required by Google Analytics by selecting the appropriate settings in your browser software; however, this may mean that you will not be able to use all functions of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address), as well as its transmission to and processing by Google, by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de
If you would like further information about the type, scope and purpose of the data collected by Google, we recommend that you read their privacy policy. https://support.google.com/analytics/answer/6004245?hl=de
Google also processes your data in the USA. Before giving your consent to the storage of cookies through the use of Google Analytics, please read the relevant information in our privacy policy.
- On our website, we also use the services of Google Maps. This allows us to display interactive maps directly on our website and enables you to conveniently use the map function to find our location and facilitate your journey.
By visiting our website, Google receives the information that you have accessed the corresponding subpage of our website, as well as the personal data listed under section 2. This takes place regardless of whether you are logged into a Google account or not. If you are logged into Google, your data will be assigned directly to your account. If you do not want this, you must log out of Google before using this service. Google uses your data for advertising, market research and needs-based website design purposes. You have the right to object to this use of your data, which you must exercise directly with Google.
Further information on the purpose and scope of data collection can be found in Google’s privacy policy, available at http://www.google.com/intl/en/policies/privacy. Google also processes your data in the USA. Before giving your consent to the storage of cookies through the use of Google Analytics, please read the relevant information in our privacy policy.
- We also provide links to other websites on our website; this is done for informational purposes only. These websites are not under our control and are therefore not covered by the provisions of this privacy policy. However, if you activate a link, it is possible that the operator of that website may collect data about you and process it in accordance with its own privacy policy, which may differ from ours. Please always also inform yourself about the current privacy policies on the websites linked by us.
- On our website, it is also possible to interact with various social networks via plugins. These are:
- Facebook, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
- YouTube, operated by YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA
- Instagram, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
If you click on a plugin of one of these social networks, it will be activated and, as described above, a connection will be established to the respective server of that network.
If you activate these plugins, you consent, where applicable, to the use of your data collected via these plugins, including in the USA.
We have no influence over the scope and content of the data transmitted to the respective operator of this social network by clicking on the plugin, or over which data may subsequently be subject to access by US authorities.
If you would like to inform yourself about the type, scope and purpose of the data collected by the operators of these social networks, we recommend that you read the privacy policies of the respective social network.
- Security
We use numerous technical and organisational security measures to protect your data against manipulation, loss, destruction and access by third parties. Our security measures are continuously improved in line with technological developments on the internet. If you require further information on the type and scope of the technical and organisational measures we have taken, we are happy to respond to written enquiries in this regard at any time.
- Your Rights
Pursuant to the General Data Protection Regulation and the Data Protection Act, you, as a data subject affected by our data processing, have the following rights and legal remedies:
- Right of access (Art. 15 GDPR)
As a data subject affected by the data processing described above and any other data processing, you have the right to request information as to whether personal data concerning you is being processed and, if so, which personal data is being processed. For your own protection — to ensure that no unauthorised person receives information about your data — we will verify your identity in an appropriate manner before providing any information.
- Right to rectification (Art. 16) and erasure (Art. 17 GDPR)
You have the right to request without undue delay the rectification of inaccurate personal data concerning you or — taking into account the purposes of the data processing — the completion of incomplete personal data, as well as the erasure of your data, provided that the criteria set out in Art. 17 GDPR are met.
- Right to restriction of processing (Art. 18 GDPR)
Under the statutory conditions, you have the right to restrict the processing of all personal data collected. From the time the restriction request is submitted, this data will only be processed with your individual consent or for the establishment and enforcement of legal claims.
- Right to data portability (Art. 20 GDPR)
You may request the unrestricted and unimpeded transmission of personal data that you have provided to us to you or to a third party.
- Right to object (Art. 21 GDPR)
You may object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is necessary for the purposes of our legitimate interests or those of a third party. After an objection, your data will no longer be processed unless there are compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You may object at any time to data processing for the purpose of direct advertising with future effect.
- Withdrawal of Consent
If you have separately given consent to the processing of your data, you may withdraw this consent at any time. Such withdrawal affects the lawfulness of the processing of your personal data after you have communicated it to us.
If you take any action to exercise your rights under the GDPR listed above, Condeli GmbH shall respond to the requested action or comply with the request without undue delay, but no later than within one month of receipt of your request.
We will respond to all reasonable requests within the statutory framework free of charge and as promptly as possible.
The Data Protection Authority is responsible for applications concerning violations of the right of access, violations of the rights to confidentiality, rectification or erasure. Its contact details are:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Wien
- Contact Information / Contact Person
- Contact Information of the Controller
- Contact Information of the Contact Person for Data Protection Matters
Last updated: January 2023