Newsletter privacy policy

When you register for our newsletter, you submit the above personal data and give us the right to contact you by e-mail.We use the data stored when you register for the newsletter exclusively for our newsletter and do not pass it on.
If you unsubscribe from the newsletter – you will find the link to do so at the bottom of every newsletter – we will delete all data stored when you subscribed to the newsletter.

MailChimp order data processing contract

We have concluded a contract with MailChimp for commissioned data processing (Data Processing Addendum).This contract serves to secure your personal data and ensures that MailChimp complies with the applicable data protection regulations and does not pass on your personal data to third parties.
You can find more information about this contract at http://mailchimp.com/legal/forms/data-processing-addendum/.

Embedded social media elements Privacy policy

We embed elements of social media services on our website to display images, videos and texts.
When you visit pages that display these elements, data is transferred from your browser to the respective social media service and stored there. We have no access to this data.
The following links will take you to the pages of the respective social media services where it is explained how they handle your data:

Privacy Policy

We have written this privacy policy (version 19.02.2020-221116668) to explain to you, in accordance with the requirements of the Datenschutz-Grundverordnung (EU) 2016/679

what information we collect, how we use data and what choices you have as a visitor to this website.

Unfortunately, it is in the nature of things that these explanations sound very technical, but we have tried to describe the most important things as simply and clearly as possible when creating them.

Automatic data storage

When you visit websites nowadays, certain information is automatically created and stored, including on this website.
When you visit our website as you are doing now, our web server (computer on which this website is stored) automatically saves data such as

  • the address (URL) of the website accessed
    browser and browser version
    the operating system used
    the address (URL) of the previously visited page (referrer URL)
    the host name and IP address of the device from which access is made
    date and time

     

    in files (web server log files).

As a rule, web server log files are stored for two weeks and then automatically deleted. We do not pass this data on, but we cannot rule out the possibility that this data may be viewed in the event of unlawful behavior.

Cookies

[borlabs-cookie type=”btn-cookie-preference” title=”Cookie Einstellungen ändern”/]
Our website uses HTTP cookies to store user-specific data.
Below we explain what cookies are and why they are used so that you can better understand the following privacy policy.

What exactly are cookies?

Whenever you surf the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

One thing cannot be denied: Cookies are really useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are also other cookies for other areas of application. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically stored in the cookie folder, the “brain” of your browser, so to speak. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser transmits the “user-related” information back to our site.Thanks to cookies, our website knows who you are and offers you the settings you are used to.In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our website, third-party cookies are created by partner websites (e.g. Google Analytics).Each cookie must be evaluated individually, as each cookie stores different data.The expiry time of a cookie also varies from a few minutes to a few years.Cookies are not software programs and do not contain viruses, Trojans or other “malware”.Cookies also cannot access information on your PC.

This is what cookie data can look like, for example:

Name: _ga
Value: GA1.2.1326744211.152221116668-6
Purpose: Differentiation of website visitors
Expiration date: after 2 years

A browser should be able to support these minimum sizes:

  • At least 4096 bytes per cookie
    At least 50 cookies per domain
    At least 3000 cookies in total

What types of cookies are there?

The question of which cookies we use in particular depends on the services used and is clarified in the following sections of the privacy policy. At this point, we would like to briefly explain the different types of HTTP cookies.

There are 4 types of cookies:

Essential cookies
These cookies are necessary to ensure basic website functions. For example, these cookies are needed when a user places a product in the shopping cart, then continues surfing on other pages and later goes to the checkout. These cookies ensure that the shopping cart is not deleted even if the user closes the browser window.

Purposeful cookies
These cookies collect information about user behavior and whether the user receives any error messages. These cookies are also used to measure the loading time and the behavior of the website in different browsers.

Targeted cookies
These cookies ensure better user-friendliness. For example, entered locations, font sizes or form data are saved.

Advertising cookies
These cookies are also called targeting cookies.They are used to deliver customized advertising to the user. This can be very practical, but also very annoying.
When you visit a website for the first time, you are usually asked which of these types of cookie you would like to allow. And of course this decision is also saved in a cookie.

How can I delete cookies?

You decide how and whether you want to use cookies.Regardless of which service or website the cookies come from, you always have the option of deleting, deactivating or only partially allowing cookies.For example, you can block third-party cookies but allow all other cookies.
If you want to find out which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:

Chrome: Delete, enable and manage cookies in Chromen

Safari:Manage cookies and website data with Safari

Firefox: Delete cookies to remove data that websites have stored on your computer

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete and manage cookies

If you do not want any cookies, you can set up your browser so that it always informs you when a cookie is to be set. You can then decide for each individual cookie whether or not to allow it. The procedure differs depending on the browser. It is best to search for the instructions in Google using the search term “delete cookies Chrome” or “deactivate cookies Chrome” in the case of a Chrome browser.

What about my data protection?

The so-called “cookie guidelines” have been in place since 2009. These state that the storage of cookies requires your consent. However, there are still very different reactions to these directives within the EU countries. In Austria, however, this directive has been implemented in Section 96 (3) of the Telecommunications Act (TKG).

If you would like to know more about cookies and are not afraid of technical documentation, we recommend https://tools.ietf.org/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism”.

Storage of personal data

Personal data that you transmit to us electronically on this website, such as your name, e-mail address, address or other personal details when submitting a form or comments on the blog, will be used by us together with the time and IP address only for the purpose stated in each case, stored securely and not passed on to third parties.

We therefore only use your personal data to communicate with those visitors who expressly request contact and to process the services and products offered on this website.We do not pass on your personal data without your consent, but we cannot rule out the possibility of this data being viewed in the event of unlawful behavior.

If you send us personal data by e-mail – i.e. outside of this website – we cannot guarantee the secure transmission and protection of your data. We recommend that you never send confidential data unencrypted by e-mail.

Rights under the General Data Protection Regulation

According to the provisions of the GDPR and theAustrian Data Protection Act (DSG) Datenschutzgesetzes (DSG)

, you have the following rights:
Right to rectification (Article 16 GDPR)
Right to erasure (“right to be forgotten”) (Article 17 GDPR)
Right to restriction of processing (Article 18 GDPR)
Right to notification – notification obligation in connection with the rectification or erasure of personal data or the restriction of processing (Article 19 GDPR)
Right to data portability (Article 20 GDPR)
Right to object (Article 21 GDPR)
Right not to be subject to a decision based solely on automated processing, including profiling (Article 22 GDPR)

If you believe that the processing of your data violates data protection law or your data protection claims have otherwise been violated in any way, you can complain to the supervisory authority, which in Austria is the data protection authority, whose website you can find at https://www.dsb.gv.at/.

Evaluation of visitor behavior

In the following privacy policy, we inform you whether and how we analyze data from your visit to this website. The evaluation of the collected data is generally anonymous and we cannot draw any conclusions about your person from your behavior on this website.

You can find out more about how to object to this evaluation of visit data in the following privacy policy.

TLS encryption with https

We use https to transmit data tap-proof on the Internet (data protection through technology design Article 25 (1) GDPR): Artikel 25 Absatz 1 DSGVO). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the Internet, we can ensure the protection of confidential data. You can recognize the use of this data transmission security by the small lock symbol at the top left of the browser and the use of the https scheme (instead of http) as part of our Internet address.

Google Fonts privacy policy

We use Google Fonts on our website.These are the “Google Fonts” of Google Inc (1600 Amphitheatre Parkway Mountain View, CA 94043, USA).

You do not need to log in or enter a password to use Google fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are completely separate from all other Google services.If you have a Google account, you do not need to worry that your Google account data will be transmitted to Google while using Google Fonts. Google records the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We will take a closer look at exactly how the data is stored.

What are Google Fonts?

Google Fonts (formerly Google Web Fonts) is a directory of over 800 fonts that Google LLC makes available to its users free of charge.

Many of these fonts are published under the SIL Open Font License, while others are published under the Apache License. Both are free software licenses.

Why do we use Google Fonts on our website?

With Google Fonts, we can use fonts on our own website without having to upload them to our own server. Google Fonts is an important component in keeping the quality of our website high. All Google fonts are automatically optimized for the web and this saves data volume and is a great advantage, especially for use on mobile devices.When you visit our site, the low file size ensures a fast loading time.Furthermore, Google Fonts are secure web fonts.Different image synthesis systems (rendering) in different browsers, operating systems and mobile devices can lead to errors.Such errors can sometimes visually distort texts or entire websites.Thanks to the fast Content Delivery Network (CDN), there are no cross-platform problems with Google Fonts.Google Fonts supports all common browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We use Google Fonts so that we can present our entire online service as beautifully and uniformly as possible.

What data is stored by Google?

When you visit our website, fonts are loaded from a Google server. This external request transmits data to Google’s servers, allowing Google to recognize that you (or your IP address) visited our website. The Google Fonts API is designed to limit the usage, storage, and collection of end-user data to what is necessary for proper font delivery. By the way, API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software domain.

Google Fonts securely stores CSS and font requests on Google servers, ensuring protection. Using the collected usage data, Google can determine how well individual fonts are received. These results are published on internal analytics platforms, such as Google Analytics. Additionally, Google uses data from its own web crawler to identify which websites utilize Google Fonts. This data is published in the BigQuery database of Google Fonts. Businesses and developers use the Google BigQuery web service to analyze and manage large datasets.

It’s important to note that every Google Fonts request automatically transmits information such as language settings, IP address, browser version, browser screen resolution, and browser name to Google’s servers. Whether this data is also stored remains unclear and is not explicitly communicated by Google.

How long and where is the data stored?

Requests for CSS assets are stored by Google for one day on their servers, which are primarily located outside the EU. This allows us to use fonts via a Google stylesheet. A stylesheet is a template that makes it quick and easy to adjust the design or font of a website.

Font files are stored by Google for one year. Google aims to improve website loading times overall with this approach. When millions of websites refer to the same fonts, they are cached after the first visit and will load instantly on all other subsequently visited websites. Occasionally, Google updates font files to reduce file size, expand language support, or improve the design.

How can I delete my data or prevent data storage?

The data stored by Google for one day or one year cannot simply be deleted. These data are automatically transmitted to Google when the site is accessed. To have this data deleted early, you need to contact Google Support at https://support.google.com/?hl=de&tid=221116668 . You can only prevent this data storage by not visiting our website.

Unlike other web fonts, Google allows us unrestricted access to all fonts. This means we have unlimited access to a wide variety of fonts, enabling us to optimize the design of our website. For more information about Google Fonts and other questions, visit https://developers.google.com/fonts/faq?tid=221116668. While Google addresses some data protection issues there, detailed information on data storage is not included. Obtaining precise information from Google about the data stored is relatively challenging.

You can also read about the data Google collects in general and how it is used at https://www.google.com/intl/de/policies/privacy/ .

MailChimp Privacy Policy

Like many other websites, we also use the services of the newsletter company MailChimp on our website. The operator of MailChimp is The Rocket Science Group, LLC, located at 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA. MailChimp allows us to easily send you interesting updates via newsletters. With MailChimp, there’s no need for installations, and we can still benefit from a variety of highly useful features. Below, we provide more details about this email marketing service and inform you about the key aspects related to data protection.

What is MailChimp?

MailChimp is a cloud-based newsletter management service. “Cloud-based” means we do not need to install MailChimp on our own computer or server. Instead, we access the service via an IT infrastructure that is available online, hosted on an external server. This type of software usage is also known as SaaS (Software as a Service).

MailChimp offers a wide range of email types for us to choose from. Depending on the goals of our newsletter, we can execute single campaigns, regular campaigns, autoresponders (automated emails), A/B tests, RSS campaigns (sent at predefined times and frequencies), and follow-up campaigns.

Why do we use MailChimp on our website?

We use a newsletter service to stay in touch with you. We want to keep you informed about updates and share any attractive offers currently available in our program. For our marketing efforts, we are always looking for the simplest and most effective solutions, which is why we chose MailChimp as our newsletter management service.

MailChimp is easy to use while offering a wide range of helpful features. This allows us to create appealing and engaging newsletters in a short amount of time. Thanks to the provided design templates, we can customize each newsletter to suit our needs. With its “responsive design,” our content is displayed clearly and beautifully on your smartphone or other mobile devices.

Features like A/B testing and comprehensive analytics quickly show us how our newsletters are received. This enables us to respond if necessary and improve our offerings or services.

Another advantage is MailChimp’s “cloud system.” The data is not stored or processed directly on our servers. Instead, we can retrieve it from external servers, saving storage space and significantly reducing maintenance efforts.

What data does MailChimp store?

The Rocket Science Group LLC (MailChimp) operates online platforms that allow us to communicate with you (provided you have subscribed to our newsletter). If you subscribe to our newsletter via our website, you confirm your subscription by email, thereby joining a MailChimp email list. To verify your subscription to this “list provider,” MailChimp stores the date of subscription and your IP address. Additionally, MailChimp collects your email address, name, physical address, and demographic information such as language or location.

This information is used to send you emails and enable certain MailChimp features (e.g., newsletter analysis).

MailChimp also shares information with third parties to provide better services. Some data is shared with advertising partners to better understand customer interests and preferences, enabling more relevant content and targeted advertising.

Through “web beacons” (small graphics embedded in HTML emails), MailChimp can determine whether an email was delivered, opened, or if links were clicked. All of this information is stored on MailChimp servers. This allows us to generate statistical reports and see how well our newsletters resonate with you. In turn, we can tailor our content more effectively to your needs and improve our services.

MailChimp may also use this data to enhance its own services. For example, this could involve technical optimization of email delivery or identifying the recipients’ location (country).

The following cookies may be set by MailChimp. This is not an exhaustive list but rather a selection of examples:

  1. Name: AVESTA_ENVIRONMENT
    Value: Prod
    Purpose: This cookie is essential for providing MailChimp services. It is always set when a user subscribes to a newsletter mailing list.
    Expiration: At the end of the session
  2. Name: ak_bmsc
    Value: F1766FA98C9BB9DE4A39F70A9E5EEAB55F6517348A7000001221116668-3
    Purpose: This cookie helps distinguish between humans and bots. It enables the creation of secure reports on website usage.
    Expiration: After 2 hours
  3. Name: bm_sv
    Value: A5A322305B4401C2451FC22FFF547486~FEsKGvX8eovCwTeFTzb8//I3ak2Au…
    Purpose: This cookie originates from MasterPass Digital Wallet (a MasterCard service) and is used to provide visitors with secure and simple virtual payment transactions. It anonymously identifies users on the website.
    Expiration: After 2 hours
  4. Name: _abck
    Value: 8D545C8CCA4C3A50579014C449B045221116668-9
    Purpose: No detailed information about the purpose of this cookie is available.
    Expiration: After 1 year

Additional Notes on MailChimp’s Use of Cookies:
Sometimes, users open our newsletter via a provided link to ensure proper display. This may be necessary if the email program doesn’t display the newsletter correctly. In such cases, the newsletter is displayed via a MailChimp-hosted website.

MailChimp also uses cookies on its own websites to store data in your browser. These cookies may involve the processing of personal data by MailChimp and its partners (e.g., Google Analytics). This data collection is the responsibility of MailChimp, and we have no control over it.

For detailed information about the cookies used by MailChimp, you can refer to the MailChimp Cookie Statement. It provides a thorough explanation of how and why the company uses cookies.

How Long and Where Are Data Stored?

Since MailChimp is an American company, all collected data is stored on servers located in the United States.

In general, the data remains permanently stored on MailChimp’s servers until a deletion request is made by you. If you request the deletion of your data from us, we will permanently remove all your personal information and anonymize it in MailChimp reports. Alternatively, you can directly request MailChimp to delete your data. In this case, MailChimp will remove all your information and notify us of the deletion. Upon receiving this notification, we have 30 days to remove your contact from all associated integrations.

How Can I Delete My Data or Prevent Its Storage?

You can withdraw your consent to receive our newsletter at any time by clicking the unsubscribe link located at the bottom of the email. After unsubscribing, your data will be deleted from MailChimp.

If you access a MailChimp-hosted website via a link in our newsletter and cookies are set in your browser, you can delete or disable these cookies at any time.

The process for disabling or deleting cookies depends on your browser. Below are guides for managing cookies in different browsers:

If you want to block cookies altogether, you can configure your browser to notify you whenever a cookie is set. This allows you to decide individually whether to allow or deny each cookie.

MailChimp is an active participant in the EU-U.S. Privacy Shield Framework, which ensures the proper and secure transfer of personal data. For more information, visit Privacy Shield.

To learn more about MailChimp’s use of cookies, visit MailChimp Cookie Policy, and for detailed information on their privacy practices, visit MailChimp Privacy Policy.

YouTube Privacy Policy

We have embedded YouTube videos on our website to provide you with interesting video content directly on our site. YouTube is a video platform operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA, and has been a subsidiary of Google LLC since 2006. When you visit a page on our website that includes a YouTube video, your browser automatically connects to YouTube or Google servers. Depending on your settings, various data may be transferred. Google is responsible for all data processing, and Google’s privacy policy applies.

Below, we explain in more detail which data is processed, why we embed YouTube videos, and how you can manage or delete your data.

What is YouTube?

YouTube is a platform where users can watch, rate, comment on, and upload videos for free. Over the years, YouTube has become one of the most important social media channels worldwide. To display videos on our website, YouTube provides an embed code that we integrate into our site.

Why Do We Use YouTube Videos on Our Website?

YouTube is the most popular video platform with the highest-quality content. We aim to provide you with the best possible user experience on our website, and interesting videos are a part of that. By embedding videos, we complement our texts and images with additional helpful content.

Additionally, embedded videos make our website easier to find on Google’s search engine. If we run Google Ads campaigns, Google can also use the collected data to display our ads to people who are genuinely interested in our offerings.

What Data Does YouTube Store?

When you visit one of our pages with an embedded YouTube video, YouTube sets at least one cookie that saves your IP address and our URL.

If you are logged into your YouTube account, YouTube can associate your interactions on our website with your profile using cookies. Data collected may include:

  • Session duration
  • Bounce rate
  • Approximate location
  • Technical information such as browser type, screen resolution, or your internet provider
  • Interaction details such as ratings, sharing content via social media, or adding videos to your YouTube favorites

If you are not logged into a Google or YouTube account, Google stores data using a unique identifier linked to your device, browser, or app. For example, your preferred language setting is preserved. However, fewer interaction data points are stored since fewer cookies are set.

Below, we list cookies that were set during a test in the browser. The list includes cookies set without a logged-in YouTube account and those set with an account logged in. This list is not exhaustive as user data depends on interactions with YouTube.

 

Cookies Set Without a YouTube Account Logged In:

  1. Name: YSC
    Value: b9-CV6ojI5Y221116668-1
    Purpose: Registers a unique ID to track video viewing statistics.
    Expiration: End of session
  2. Name: PREF
    Value: f1=50000000
    Purpose: Registers a unique ID to compile statistics about how YouTube videos are used on the website.
    Expiration: 8 months
  3. Name: GPS
    Value: 1
    Purpose: Registers a unique ID on mobile devices to track GPS location.
    Expiration: 30 minutes
  4. Name: VISITOR_INFO1_LIVE
    Value: 95Chz8bagyU
    Purpose: Attempts to estimate the user’s bandwidth on pages with embedded YouTube videos.
    Expiration: 8 months

Cookies Set When Logged Into a YouTube Account:

  1. Name: APISID
    Value: zILlvClZSkqGsSwI/AU1aZI6HY7221116668-
    Purpose: Used to create a profile based on user interests for personalized advertising.
    Expiration: 2 years
  2. Name: CONSENT
    Value: YES+AT.de+20150628-20-0
    Purpose: Stores user consent status for various Google services. Also enhances security by protecting user data from unauthorized access.
    Expiration: 19 years
  3. Name: HSID
    Value: AcRwpgUik9Dveht0I
    Purpose: Helps create a profile of user interests to deliver personalized ads.
    Expiration: 2 years
  4. Name: LOGIN_INFO
    Value: AFmmF2swRQIhALl6aL…
    Purpose: Stores information about login credentials.
    Expiration: 2 years
  5. Name: SAPISID
    Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
    Purpose: Uniquely identifies the user’s browser and device to create a profile of interests.
    Expiration: 2 years
  6. Name: SID
    Value: oQfNKjAsI221116668-
    Purpose: Stores the user’s Google account ID and the last login time in a digitally signed and encrypted format.
    Expiration: 2 years
  7. Name: SIDCC
    Value: AN0-TYuqub2JOcDTyL
    Purpose: Stores information about how the website is used and any advertisements viewed before visiting the site.
    Expiration: 3 months

These cookies support various functionalities, such as user authentication, personalization of ads, and analytics for video performance. For further details, please refer to Google’s Privacy Policy and YouTube’s cookie policy.

Data Retention and Storage at YouTube

The data collected by YouTube and Google is stored on Google’s servers, most of which are located in the United States. Google distributes the data across various data centers to optimize load times and protect the data from manipulation. A detailed overview of Google’s data centers can be found at Google Datacenter Locations. https://www.google.com/about/datacenters/inside/locations/?hl=de 

Data is stored for varying lengths of time, depending on the type of data:

  • Data stored in your Google Account, such as items in “My Activity,” photos, or documents, remains stored until you delete it.
  • Data linked to your device, browser, or app can be deleted, even if you are not logged into a Google account.
  • Other data is either automatically deleted after a certain period or stored for a longer duration, depending on the type and purpose of the data.

Deleting Data and Preventing Data Storage

There are several options to delete or prevent the storage of your data:

  1. Manual Deletion in Google Account:
    You can manually delete data from your Google Account at any time. Google also offers an automatic deletion option for location and activity data, where you can choose whether these data are deleted after 3 or 18 months.
  2. Disabling or Deleting Cookies:
    Regardless of whether you have a Google account, you can delete or disable cookies in your browser. The instructions for managing cookies in various browsers are:
  3. Cookie Notifications:
    You can set up your browser to notify you whenever a cookie is set. This allows you to decide whether to accept each individual cookie.

More Information and Privacy Policy

Since YouTube is a subsidiary of Google, both services share a common privacy policy. For more information on how your data is handled, please refer to the Google Privacy Policy. 

VG Wort Privacy Policy

Cookies and Access Statistics Reporting

We use “session cookies” from VG Wort, Munich, to measure access to texts in order to determine the likelihood of copying. Session cookies are small pieces of information stored in the visitor’s computer memory by the provider. A session cookie contains a randomly generated unique identification number, known as a session ID. It also includes information about its origin and the storage duration. Session cookies cannot store any other data. These measurements are carried out by Kantar Germany GmbH using the Scalable Central Measurement Method (SZM). They help determine the likelihood of copying individual texts for the purpose of compensating authors and publishers for their legal claims. We do not collect personal data through cookies.

Many of our pages are equipped with JavaScript calls that report the access data to the VG Wort collecting society. This allows our authors to participate in the VG Wort distributions, ensuring the legal compensation for the use of copyrighted works under Section 53 of the Copyright Act (UrhG).

You can use our services even without cookies. Most browsers are set to accept cookies automatically. However, you can disable cookie storage or configure your browser to notify you whenever cookies are sent.

Privacy Policy for Using the Scalable Central Measurement Method

Our website and mobile web offerings use the “Scalable Central Measurement Method” (SZM) from Kantar Germany GmbH to determine statistical values for measuring the likelihood of copying texts.

Anonymous measurement values are collected. The access measurement either uses a session cookie or a signature created from various automatically transmitted information from your browser to recognize computer systems. IP addresses are processed only in anonymized form.

The procedure was developed with data protection in mind. The sole purpose of this method is to determine the likelihood of copying individual texts.

At no time will individual users be identified. Your identity remains fully protected. You will not receive any advertising through this system.

 

Privacy Policy of the VG-Wort Plugin

Definitions

The terms used below are derived from Article 4 of the General Data Protection Regulation (GDPR): Datenschutz-Grundverordnung (DSGVO).

Name and Address of the Data Controller

The data controller in the sense of the GDPR and other national data protection laws of the member states, as well as other data protection regulations, is the provider of this plugin, as indicated in the imprint.

General Information on Data Processing

Scope of Processing Personal Data

We process personal data of our users only to the extent necessary to provide a functional plugin. The processing of personal data typically occurs only with the consent of the user. An exception applies in cases where obtaining prior consent is not possible for factual reasons and where the processing of data is permitted by legal provisions.

Legal Basis for Processing Personal Data

If we collect personal data for processing, the legal basis for such processing is Article 6(1)(a) of the EU General Data Protection Regulation (GDPR) for consent: EU-Datenschutzgrundverordnung (DSGVO)

For processing personal data necessary for the performance of a contract to which the affected person is a party, the legal basis is Article 6(1)(b) GDPR. This also applies to processing operations required to carry out pre-contractual measures.

If the processing of personal data is necessary to fulfill a legal obligation to which our company is subject, the legal basis is Article 6(1)(c) GDPR.

In cases where vital interests of the affected person or another individual make the processing of personal data necessary, the legal basis is Article 6(1)(d) GDPR.

If processing is necessary for the protection of legitimate interests of our company or a third party, and if the interests, fundamental rights, and freedoms of the data subject do not override the first-mentioned interest, the legal basis for processing is Article 6(1)(f) GDPR.

Data Deletion and Retention Period

Personal data of the affected person will be deleted or blocked once the purpose of storage no longer applies. Storage may continue if required by European or national legislators in union regulations, laws, or other provisions to which the data controller is subject. Data will also be blocked or deleted when the prescribed storage period stipulated by the aforementioned norms expires, unless continued storage is necessary for contract fulfillment or contractual purposes.

Data Transmission

Data transmission to our server over the internet is conducted via HTTPS and TLS protocols in an encrypted manner. Unencrypted transmission is not possible from our server. Data is encrypted by our plugin or your web browser, then transmitted and finally decrypted by our server.

Provision of the Plugin

Description and Scope of Data Processing

The plugin does not send any data to the manufacturer without the user’s consent. Data that can be sent to the manufacturer is listed below. The plugin does not create or collect any usage data.

Check Function for Counting Tokens

Description and Scope of Data Processing

You have the option to have the counting tokens integrated into your website by the plugin checked by us. This can be done via the “Check” link found at several places in the plugin. When you click on this check link, the following data is sent to our server:

  • Access through your web browser:
    • Information about the web browser type and version used,
    • The user’s operating system,
    • The user’s IP address,
    • Date and time of access,
    • The website from which the user’s system reached our server.
  • Data contained in the check link:
    • The public counting token,
    • The link to the website (WordPress page) where the counting token should be located.

The data sent by your access through a web browser is only stored in the log files of our system if an error occurs during the corresponding page request. This does not affect the user’s IP address or any other data that would allow the data to be assigned to a specific user.

The data contained in the check link is used by our server to verify whether the public counting token is present on the WordPress page specified in the link.

The user’s IP address is temporarily stored only to determine how often the user uses the check function within a given time interval.

These data are not stored together with other personal data of the user.

Legal Basis for Data Processing

The legal basis for the temporary storage of the data is Art. 6 (1)(f) or (a) GDPR.

Purpose of Data Processing

The temporary storage of the user’s IP address by the server is necessary to enable the delivery of the requested webpage to the user’s computer. To do this, the user’s IP address must remain stored for the duration of the session.

The temporary storage of the data in the check link is required to carry out the check.

The user’s IP address is temporarily stored only to protect our check function from misuse (excessive use).

Storage Duration

The data will be deleted as soon as they are no longer necessary for the purpose for which they were collected. In the case of data collected for the provision of the check function for counting tokens, this will occur once the session is over. There is no permanent storage.

The user’s IP address is stored for a maximum of one day for the protection of our system.

Right to Object and Erasure

The storage of data in log files in the event of an error is essential for the operation of the check function for counting tokens. Therefore, users do not have the right to object.

The storage of the user’s IP address is essential for the protection of our system. Therefore, users do not have the right to object.

The user can activate or deactivate the use of the check function for counting tokens through a checkbox in the “Privacy” section/menu. By default, this checkbox is deactivated.

 

Rights of the Data Subject

If your personal data is processed, you are considered a data subject under the GDPR, and you have the following rights with respect to the data controller:

Right to Access

You have the right to obtain confirmation from the controller as to whether your personal data is being processed. If processing occurs, you may request information about the following:

  • The purposes of processing your personal data.
  • The categories of personal data being processed.
  • The recipients or categories of recipients to whom your personal data has been disclosed or will be disclosed.
  • The planned duration of storage for your personal data or, if not possible, the criteria used to determine the storage duration.
  • The existence of the right to rectification, erasure, restriction of processing, or objection to processing.
  • The right to lodge a complaint with a supervisory authority.
  • Any available information about the origin of the data if the personal data was not obtained from you.
  • The existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the scope and intended consequences of such processing.

You also have the right to request information on whether your personal data is transferred to a third country or international organization and to be informed about the appropriate safeguards according to Article 46 of the GDPR related to such transfers.

Right to Rectification

You have the right to request rectification and/or completion of your personal data if it is inaccurate or incomplete. The controller must make the correction without undue delay.

Right to Restriction of Processing

You may request the restriction of processing your personal data under the following circumstances:

  • If you dispute the accuracy of your personal data for a period that allows the controller to verify the accuracy of the data.
  • If the processing is unlawful and you oppose the erasure of personal data and instead request a restriction on its use.
  • If the controller no longer needs the personal data for processing purposes but you need it for the establishment, exercise, or defense of legal claims.
  • If you have objected to processing under Article 21(1) of the GDPR and it has not yet been determined whether the controller’s legitimate grounds override your reasons.

When processing is restricted, your personal data may only be processed with your consent or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another person or for reasons of important public interest in the Union or a Member State.

You will be informed before the restriction on processing is lifted.

Right to Erasure

Obligation to Delete:

You may request the controller to erase your personal data without undue delay, and the controller is obligated to comply, provided that one of the following reasons applies:

  • The personal data is no longer necessary for the purposes for which it was collected or processed.
  • You withdraw your consent on which the processing is based (Article 6(1)(a) or Article 9(2)(a) of the GDPR), and there is no other legal basis for processing.
  • You object to the processing under Article 21(1) of the GDPR and there are no overriding legitimate grounds for processing, or you object to processing under Article 21(2) of the GDPR.
  • The personal data has been unlawfully processed.
  • The erasure of personal data is necessary to comply with a legal obligation under Union or Member State law.
  • The personal data was collected in relation to the offer of information society services according to Article 8(1) of the GDPR.

Notification to Third Parties:

If the controller has made the personal data public and is required to delete it according to Article 17(1) of the GDPR, they must take appropriate measures, including technical measures, to inform other controllers who are processing your data that you have requested the deletion of all links to or copies of your personal data.

Exceptions:

The right to erasure does not apply if processing is necessary for:

  • The exercise of the right to freedom of expression and information.
  • Compliance with a legal obligation that requires processing under Union or Member State law.
  • Public health interests under Article 9(2)(h) and (i) and Article 9(3) of the GDPR.
  • Archiving purposes in the public interest, scientific or historical research, or statistical purposes under Article 89(1) of the GDPR, provided that the right to erasure is likely to seriously impair the achievement of these processing objectives.
  • The establishment, exercise, or defense of legal claims.

Right to Notification

If you have requested the rectification, erasure, or restriction of processing, the controller must inform all recipients to whom your personal data has been disclosed of the rectification, erasure, or restriction, unless it proves impossible or would involve a disproportionate effort.

You have the right to be informed of these recipients.

Right to Data Portability

You have the right to receive your personal data that you have provided to the controller in a structured, commonly used, and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that:

  • The processing is based on consent according to Article 6(1)(a) or Article 9(2)(a) of the GDPR, or on a contract according to Article 6(1)(b) of the GDPR.
  • The processing is carried out by automated means.

In exercising this right, you also have the right to have your personal data transmitted directly from one controller to another, where technically feasible, without affecting the rights and freedoms of others.

The right to data portability does not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Right to Object

You have the right to object at any time to the processing of your personal data based on Article 6(1)(e) or (f) of the GDPR, including profiling based on these provisions. The controller will no longer process your personal data unless they can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims.

If your personal data is being processed for direct marketing purposes, you have the right to object to the processing of your data for such purposes, including profiling to the extent that it is related to direct marketing.

If you object to the processing for direct marketing purposes, your personal data will no longer be processed for those purposes.

You may exercise your right to object in relation to the use of information society services, even if automated processes are involved, regardless of Directive 2002/58/EC.

Right to Withdraw Consent

You have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before the withdrawal.

Automated Decision-Making, including Profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless:

  • The decision is necessary for entering into or performance of a contract between you and the controller.
  • It is authorized by Union or Member State law, which provides appropriate safeguards for your rights and freedoms.
  • It is based on your explicit consent.

Such decisions must not be based on special categories of personal data unless explicit consent is given or specific legal provisions apply to protect your rights.

The controller must take appropriate measures to safeguard your rights, including at least the right to obtain human intervention, express your point of view, and contest the decision.

Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your residence, place of work, or the place of the alleged infringement, if you believe that the processing of your personal data infringes the GDPR.

The supervisory authority will inform the complainant about the progress and outcome of the complaint, including the possibility of a judicial remedy under Article 78 of the GDPR.

 

 

Source: Created with the Datenschutz Generator von firmenwebseiten.at in Cooperation with elektroautos.co.at