GDPR

Privacy Policy Table of Contents Introduction and Overview Scope of Application Legal Grounds Contact Details of the Data Controller Storage Duration Rights under the General Data Protection Regulation Security of Data Processing Communication Cookies Web Hosting Introduction Security & Anti-Spam Explanation of Terms Used Closing Remarks Introduction and Overview We have written this privacy policy (version 21.11.2025-113081820) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as data controllers – and the processors commissioned by us (e.g., providers) – process, will process in the future, and what legal options you have. The terms used are to be understood as gender-neutral. In short: We inform you comprehensively about the data we process about you. Privacy policies usually sound very technical and use specialized legal terms. This privacy policy, on the other hand, is intended to describe the most important things to you as simply and transparently as possible. To the extent that it promotes transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics are used. We thereby inform you in clear and simple language that we only process personal data within the framework of our business activities if there is a corresponding legal basis. This is certainly not possible if one provides explanations that are as brief, unclear, and legally technical as possible, as is often standard on the internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is a piece of information or two that you did not know yet. If questions nevertheless remain, we would like to ask you to contact the responsible office named below or in the legal notice (Impressum), follow the available links, and view further information on third-party sites. You can, of course, also find our contact details in the legal notice. Scope of Application This privacy policy applies to all personal data processed within the company by us and to all personal data processed by companies commissioned by us (data processors). By personal data, we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person’s name, email address, and postal address. The processing of personal data ensures that we can offer and bill our services and products, whether online or offline. The scope of application of this privacy policy includes:

all online presences (websites, online shops) that we operate social media presences and email communication mobile apps for smartphones and other devices In short: The privacy policy applies to all areas in which personal data is structured and processed within the company via the channels mentioned. Should we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.

Legal Grounds In the following privacy policy, we provide you with transparent information regarding the legal principles and regulations, i.e., the legal grounds of the General Data Protection Regulation, which allow us to process personal data. As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the access to EU law, at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32016R0679. We only process your data if at least one of the following conditions applies:

Consent (Article 6 paragraph 1 lit. a GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of data you entered into a contact form. Contract (Article 6 paragraph 1 lit. b GDPR): We process your data in order to fulfill a contract or pre-contractual obligations with you. For example, if we conclude a purchase contract with you, we require personal information in advance. Legal Obligation (Article 6 paragraph 1 lit. c GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally required to keep invoices for accounting purposes. These usually contain personal data. Legitimate Interests (Article 6 paragraph 1 lit. f GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website safely and economically. This processing is therefore a legitimate interest. Other conditions such as the performance of tasks in the public interest and the exercise of official authority, as well as the protection of vital interests, do not usually occur with us. Should such a legal basis nevertheless be relevant, it will be indicated at the corresponding point. In addition to the EU regulation, national laws also apply:

In Austria, this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), or DSG for short. In Germany, the Federal Data Protection Act applies, BDSG for short. If other regional or national laws apply, we will inform you about them in the following sections.

Contact Details of the Data Controller If you have any questions regarding data protection or the processing of personal data, you can find the contact details of the controller in accordance with Article 4 Paragraph 7 of the EU General Data Protection Regulation (GDPR) below: Florian Svetanic-Weigel Gmein 14 4084 St. Agatha Email: office@replug-unmute.com Legal Notice: www.replug-unmute.com/impressum

Storage Duration It is a general criterion for us that we only store personal data for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for the data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for bookkeeping purposes. Should you wish to have your data deleted or revoke your consent to data processing, the data will be deleted as quickly as possible and to the extent that there is no obligation to store it. We will inform you about the specific duration of the respective data processing further below, provided we have further information on this.

Rights under the General Data Protection Regulation In accordance with Articles 13, 14 GDPR, we inform you about the following rights to which you are entitled to ensure fair and transparent data processing:

According to Article 15 GDPR, you have a right of access as to whether we process your data. If this is the case, you have the right to receive a copy of the data and to find out the following information: the purpose for which we carry out the processing; the categories, i.e., the types of data being processed; who receives this data and, if the data is transmitted to third countries, how security can be guaranteed; how long the data will be stored; the existence of the right to rectification, erasure, or restriction of processing and the right to object to processing; that you can lodge a complaint with a supervisory authority (links to these authorities can be found below); the origin of the data if we did not collect it from you; whether profiling is carried out, i.e., whether data is automatically evaluated to arrive at a personal profile of you. According to Article 16 GDPR, you have a right to rectification of data, which means that we must correct data if you find errors. According to Article 17 GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the deletion of your data. According to Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but no longer use it. According to Article 20 GDPR, you have the right to data portability, which means that we will provide you with your data in a common format upon request. According to Article 21 GDPR, you have a right to object, which leads to a change in processing once enforced. If the processing of your data is based on Article 6 para. 1 lit. e (public interest, exercise of official authority) or Article 6 para. 1 lit. f (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally comply with this objection. If data is used for direct marketing, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing. If data is used for profiling, you can object to this type of data processing at any time. We may then no longer use your data for profiling. Under certain circumstances, according to Article 22 GDPR, you have the right not to be subject to a decision based solely on automated processing (for example, profiling). According to Article 77 GDPR, you have the right to lodge a complaint. This means you can complain to the data protection authority at any time if you believe that the processing of personal data violates the GDPR. In short: You have rights – do not hesitate to contact the responsible office listed above! If you believe that the processing of your data violates data protection law or your data protection claims have been violated in any other way, you can complain to the supervisory authority. For Austria, this is the Data Protection Authority (Datenschutzbehörde), whose website you can find at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For more detailed information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde) Head: Dr. Matthias Schmidl Address: Barichgasse 40-42, 1030 Wien Phone No.: +43 1 52 152-0 Email address: dsb@dsb.gv.at Website: https://www.dsb.gv.at/ Security of Data Processing To protect personal data, we have implemented both technical and organizational measures. Wherever possible, we encrypt or pseudonymize personal data. In doing so, we make it as difficult as possible within our capabilities for third parties to infer personal information from our data. Art. 25 GDPR speaks here of “data protection by design and by default” and means that security must always be kept in mind and appropriate measures taken, both for software (e.g., forms) and hardware (e.g., access to the server room). Below we will go into concrete measures, if necessary.

Communication Communication Summary 👥 Data subjects: Everyone who communicates with us via phone, email, or online form 📓 Processed data: e.g., phone number, name, email address, form data entered. You can find more details in the respective contact method used 🤝 Purpose: Handling communication with customers, business partners, etc. 📅 Storage duration: Duration of the business matter and statutory requirements ⚖️ Legal grounds: Art. 6 para. 1 lit. a GDPR (Consent), Art. 6 para. 1 lit. b GDPR (Contract), Art. 6 para. 1 lit. f GDPR (Legitimate interests) When you contact us and communicate via phone, email, or online form, personal data may be processed. The data is processed for the execution and handling of your question and the associated business transaction. The data is stored for just as long or as long as required by law.

Data Subjects All those who seek contact with us via the communication channels provided by us are affected by the aforementioned processes.

Telephone When you call us, call data is stored in pseudonymized form on the respective end device and with the telecommunications provider used. In addition, data such as name and phone number can subsequently be sent via email and stored to answer inquiries. The data will be deleted as soon as the business matter has ended and legal requirements permit.

Email When you communicate with us via email, data may be stored on the respective end device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data will be deleted as soon as the business matter has ended and legal requirements permit.

Online Forms When you communicate with us using an online form, data is stored on our web server and may be forwarded to one of our email addresses. The data will be deleted as soon as the business matter has ended and legal requirements permit.

Legal Grounds The processing of data is based on the following legal grounds:

Art. 6 para. 1 lit. a GDPR (Consent): You give us consent to store your data and use it further for purposes relevant to the business matter; Art. 6 para. 1 lit. b GDPR (Contract): There is a necessity for the fulfillment of a contract with you or a data processor such as the telephone provider, or we must process the data for pre-contractual activities, such as the preparation of an offer; Art. 6 para. 1 lit. f GDPR (Legitimate interests): We want to conduct customer inquiries and business communication in a professional framework. For this purpose, certain technical facilities such as email programs, Exchange servers, and mobile network operators are necessary to operate communication efficiently. Cookies Cookies Summary 👥 Data subjects: Website visitors 🤝 Purpose: Dependent on the respective cookie. You can find more details further below or from the manufacturer of the software that sets the cookie. 📓 Processed data: Dependent on the respective cookie used. You can find more details further below or from the manufacturer of the software that sets the cookie. 📅 Storage duration: Dependent on the respective cookie, can vary from hours to years ⚖️ Legal grounds: Art. 6 para. 1 lit. a GDPR (Consent), Art. 6 para. 1 lit. f GDPR (Legitimate interests) What are Cookies? Our website uses HTTP cookies to store user-specific data. In the following, we explain what cookies are and why they are used so that you can better understand the following privacy policy. Whenever you surf the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies. One thing cannot be denied: Cookies are truly useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are also other cookies for other areas of application. HTTP cookies are small files that are stored by our website on your computer. These cookie files are automatically placed in the cookie folder, practically the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified. Cookies store certain user data about you, such as language or personal page settings. When you visit our site again, your browser transmits the “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are used to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file. The following graphic shows a possible interaction between a web browser like Chrome and the web server. The web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans, or other “malware”. Cookies also cannot access information on your PC. This is what cookie data can look like, for example: Name: _ga Value: GA1.2.1326744211.152113081820-9 Purpose of use: Differentiation of website visitors Expiration date: after 2 years A browser should be able to support these minimum sizes:

At least 4096 bytes per cookie At least 50 cookies per domain At least 3000 cookies in total What Types of Cookies are There? The question of which specific cookies we use depends on the services used and will be clarified in the following sections of the privacy policy. At this point, we would like to briefly discuss the different types of HTTP cookies. One can distinguish between 4 types of cookies: Essential Cookies These cookies are necessary to ensure basic functions of the website. For example, these cookies are needed when a user puts a product into the shopping cart, then continues surfing on other pages, and only goes to the checkout later. These cookies ensure that the shopping cart is not deleted, even if the user closes their browser window. Functional Cookies These cookies collect information about user behavior and whether the user gets any error messages. Furthermore, these cookies are also used to measure the loading time and behavior of the website with different browsers. Performance-oriented Cookies These cookies ensure better user-friendliness. For example, entered locations, font sizes, or form data are stored. Advertising Cookies These cookies are also called targeting cookies. They serve to deliver individually tailored advertising to the user. This can be very practical, but also very annoying. Usually, when you visit a website for the first time, you are asked which of these cookie types you want to allow. And of course, this decision is also stored in a cookie. If you want to know more about cookies and do not shy away from technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism”.

Purpose of Processing via Cookies The purpose is ultimately dependent on the respective cookie. You can find more details further below or from the manufacturer of the software that sets the cookie.

What Data is Processed? Cookies are small assistants for many different tasks. Unfortunately, it is not possible to generalize what data is stored in cookies, but we will inform you about the processed or stored data within the framework of the following privacy policy.

Storage Duration of Cookies The storage duration depends on the respective cookie and is specified further below. Some cookies are deleted after less than an hour, while others can remain stored on a computer for several years. You also have an influence on the storage duration yourself. You can manually delete all cookies at any time via your browser (see also “Right to object” below). Furthermore, cookies based on consent will be deleted at the latest after you revoke your consent, whereby the lawfulness of the storage up to that point remains unaffected.

Right to Object – How Can I Delete Cookies? You decide yourself how and if you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, deactivate, or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies. If you want to find out which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings: Chrome: Delete, allow and manage cookies in Chrome Safari: Manage cookies and website data in Safari Firefox: Clear cookies and site data in Firefox Internet Explorer: Delete and manage cookies Microsoft Edge: Delete and manage cookies If you fundamentally do not want any cookies, you can set up your browser so that it always informs you when a cookie is to be set. This way, you can decide for each individual cookie whether you allow the cookie or not. The procedure varies depending on the browser. It is best to search for instructions in Google with the search term “delete cookies Chrome” or “deactivate cookies Chrome” in the case of a Chrome browser.

Legal Basis Since 2009, there have been so-called “Cookie Guidelines”. They state that storing cookies requires your consent (Article 6 para. 1 lit. a GDPR). Within the EU countries, however, there are still very different reactions to these guidelines. In Austria, however, this guideline was implemented in § 165 para. 3 of the Telecommunications Act (2021). In Germany, the cookie guidelines were not implemented as national law. Instead, this guideline was largely implemented in § 15 para. 3 of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024. For absolutely necessary cookies, even if no consent is given, there are legitimate interests (Article 6 para. 1 lit. f GDPR), which are in most cases of an economic nature. We want to provide visitors to the website with a pleasant user experience, and certain cookies are often absolutely necessary for this. Insofar as cookies that are not absolutely necessary are used, this only happens in the event of your consent. The legal basis in this respect is Art. 6 para. 1 lit. a GDPR. In the following sections, you will be informed more precisely about the use of cookies, provided that the software used uses cookies.

Web Hosting Introduction Web Hosting Summary 👥 Data subjects: Website visitors 🤝 Purpose: Professional hosting of the website and securing operations 📓 Processed data: IP address, time of website visit, browser used, and other data. You can find more details further below or from the respective web hosting provider used. 📅 Storage duration: Dependent on the respective provider, but usually 2 weeks ⚖️ Legal grounds: Art. 6 para. 1 lit. f GDPR (Legitimate interests) What is Web Hosting? When you visit websites nowadays, certain information – including personal data – is automatically created and stored, as is the case on this website. This data should be processed as sparingly as possible and only with justification. By website, by the way, we mean the entirety of all web pages on a domain, i.e., everything from the home page to the very last subpage (like this one). By domain, we mean for example example.de or template-example.com. If you want to view a website on a computer, tablet, or smartphone, you use a program for this called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We call them browser or web browser for short. To display the website, the browser must connect to another computer where the code of the website is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why this is usually handled by professional providers. These offer web hosting and thus ensure reliable and error-free storage of website data. A whole bunch of technical terms, but please bear with us, it gets even better! When the browser establishes a connection on your computer (desktop, laptop, tablet, or smartphone) and during data transmission to and from the web server, personal data may be processed. On the one hand, your computer stores data, and on the other hand, the web server must also store data for a period of time to ensure proper operation. A picture is worth a thousand words, so the following graphic illustrates the interaction between the browser, the internet, and the hosting provider.

Why Do We Process Personal Data? The purposes of data processing are:

Professional hosting of the website and securing operations To maintain operational and IT security Anonymous evaluation of access behavior to improve our offer and, if necessary, for criminal prosecution or enforcement of claims What Data is Processed? Even while you are visiting our website right now, our web server, which is the computer on which this web page is stored, usually automatically stores data such as

the complete internet address (URL) of the accessed web page browser and browser version (e.g., Chrome 87) the operating system used (e.g., Windows 10) the address (URL) of the previously visited page (referrer URL) (e.g., https://www.examplesource.de/whereicamefrom/) the host name and IP address of the device from which access is made (e.g., COMPUTERNAME and 194.23.43.121) date and time in files called web server log files. How Long is Data Stored? As a rule, the data mentioned above is stored for two weeks and then automatically deleted. We do not pass this data on, but we cannot rule out the possibility that this data may be viewed by authorities in the event of illegal behavior. In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass your data on without consent!

Legal Basis The lawfulness of processing personal data within the framework of web hosting results from Art. 6 para. 1 lit. f GDPR (protection of legitimate interests), because the use of professional hosting with a provider is necessary to present the company securely and user-friendly on the internet and to be able to track attacks and claims resulting from this if necessary. There is usually a contract for data processing in accordance with Art. 28 f. GDPR between us and the hosting provider, which ensures compliance with data protection and guarantees data security.

External Web Hosting Provider Privacy Policy Below you will find the contact details of our external hosting provider, where you can learn more about data processing in addition to the information above: helloly GmbH Rainerstrasse 25 4020 Linz Austria You can learn more about data processing at this provider in their privacy policy.

Security & Anti-Spam Security & Anti-Spam Privacy Policy Summary 👥 Data subjects: Website visitors 🤝 Purpose: Cyber security 📓 Processed data: Data such as your IP address, name, or technical data such as browser version You can find more details further below and in the individual data protection texts. 📅 Storage duration: Most data is stored until it is no longer required to fulfill the service ⚖️ Legal grounds: Art. 6 para. 1 lit. a GDPR (Consent), Art. 6 para. 1 lit. f GDPR (Legitimate interests) What is Security & Anti-Spam Software? With so-called security & anti-spam software, you and we can protect ourselves from various spam or phishing emails and possible other cyber attacks. Spam refers to promotional emails from mass mailings that were not requested. Such emails are also called electronic junk and can also cause costs. Phishing emails, on the other hand, are messages aimed at building trust through fake messages or websites in order to obtain personal data. Anti-spam software usually protects against unwanted spam messages or malicious emails that could introduce viruses into our system. We also use general firewall and security systems that protect our computers from unwanted network attacks.

Why Do We Use Security & Anti-Spam Software? We attach particularly great importance to security on our website. After all, it is not just about our security, but above all about yours. Unfortunately, cyber threats have already become part of everyday life in the world of IT and the internet. Hackers often try to steal personal data from an IT system with the help of a cyber attack. Therefore, a good defense system is absolutely necessary. A security system monitors all incoming and outgoing connections to our network or computer. To achieve even greater security against cyber attacks, we use other external security services in addition to the standardized security systems on our computer. Unauthorized data traffic is thereby better prevented, and we protect ourselves from cybercrime.

What Data is Processed by Security & Anti-Spam Software? Which data exactly is collected and stored naturally depends on the respective service. However, we always endeavor to only use programs that collect data very sparingly or only store data that is necessary for the fulfillment of the offered service. In principle, the service can store data such as name, address, IP address, email address, and technical data such as browser type or browser version. Performance and log data can also be collected in order to recognize possible incoming threats in good time. This data is processed within the scope of the services and in compliance with applicable laws. This also includes the GDPR for US providers (via standard contractual clauses). In some cases, these security services also work together with third-party providers who can store and/or process data under instruction and in accordance with data protection guidelines and other security measures. Data storage usually takes place via cookies.

Storage Duration We will inform you about the duration of data processing further below, provided we have further information on this. For example, security programs store data until you or we revoke data storage. In general, personal data is only stored for as long as is absolutely necessary for the provision of the services. In many cases, we unfortunately lack precise information from the providers regarding the duration of storage.

 

Right to Object You also have the right and opportunity at any time to revoke your consent to the use of cookies or third-party providers of security software. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating, or deleting cookies in your browser. Since cookies can also be used with such security services, we recommend our general privacy policy regarding cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.

 

Legal Basis We deploy security services mainly based on our legitimate interests (Art. 6 para. 1 lit. f GDPR) in having a good security system against various cyberattacks. Certain processing operations, in particular the use of cookies and the use of security functions, require your consent. If you have consented to your data being processed and stored by integrated security services, this consent serves as the legal basis for data processing (Art. 6 para. 1 lit. a GDPR). Most of the services we use set cookies in your browser to store data. Therefore, we recommend that you read our data protection text about cookies carefully and view the privacy policy or cookie guidelines of the respective service provider. Information on specific tools can be found – if available – in the following sections.

 

Explanation of Terms Used We always endeavor to write our privacy policy as clearly and comprehensibly as possible. However, this is not always easy, particularly with technical and legal topics. It often makes sense to use legal terms (such as personal data) or certain technical expressions (such as cookies, IP address). However, we do not want to use these without explanation. Below you will find an alphabetical list of important terms used, which we may not have addressed sufficiently in the privacy policy so far. If these terms have been taken from the GDPR and are definitions, we will also state the GDPR texts here and add our own explanations if necessary.

Processor Definition according to Article 4 of the GDPR For the purposes of this Regulation, the term:

“processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; Explanation: As a company and website owner, we are responsible for all data we process from you. In addition to the controllers, there can also be so-called processors. This includes every company or person that processes personal data on our behalf. Consequently, in addition to service providers such as tax advisors, processors can also include hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.

Consent Definition according to Article 4 of the GDPR For the purposes of this Regulation, the term:

 

“consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her; Explanation: On websites, such consent is usually given via a cookie consent tool. You are probably familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree or consent to data processing. Most of the time, you can also make individual settings and thus decide for yourself which data processing you allow and which you do not. If you do not consent, no personal data may be processed from you. In principle, consent can of course also be given in writing, i.e., not via a tool.

 

Recipient Definition according to Article 4 of the GDPR For the purposes of this Regulation, the term:

recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing; Explanation: Any person and any company that receives personal data is considered a recipient. Thus, we and our processors are also so-called recipients. Only public authorities that have an inquiry mandate are not considered recipients.

 

Personal Data Definition according to Article 4 of the GDPR For the purposes of this Regulation, the term:

 

“personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; Explanation: Personal data is therefore all data that can identify you as a person. This usually includes data such as:

 

Name Address Email address Postal address Telephone number Date of birth Identification numbers such as social security number, tax identification number, ID card number, or matriculation number Bank details such as account number, credit information, account balances, and much more. According to the European Court of Justice (ECJ), your IP address is also considered personal data. Based on your IP address, IT experts can determine at least the approximate location of your device and subsequently identify you as the line holder. Therefore, storing an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called “special categories” of personal data, which are particularly worthy of protection. These include:

 

racial and ethnic origin political opinions religious or philosophical beliefs trade union membership genetic data, such as data taken from blood or saliva samples biometric data (this is information on psychological, physical, or behavioral characteristics that can identify a person) health data data concerning sexual orientation or sex life Profiling Definition according to Article 4 of the GDPR For the purposes of this Regulation, the term:

“profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements; Explanation: In profiling, various pieces of information about a person are gathered in order to learn more about this person. In the web sector, profiling is frequently used for advertising purposes or for credit checks. Web or advertising analysis programs, for example, collect data about your behavior and interests on a website. This results in a specific user profile, with the help of which advertising can be displayed target-specifically to a target group.

 

Controller Definition according to Article 4 of the GDPR For the purposes of this Regulation, the term:

“controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law; Explanation: In our case, we are responsible for processing your personal data and are consequently the “controller”. If we pass on collected data to other service providers for processing, these are “processors”. For this purpose, a “Data Processing Agreement (DPA)” must be signed.

Processing Definition according to Article 4 of the GDPR For the purposes of this Regulation, the term:

“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; Note: When we speak of processing in our privacy policy, we mean any kind of data processing. As mentioned above in the original GDPR explanation, this includes not only the collection but also the storage and handling of data.

Closing Remarks Congratulations! If you are reading these lines, you have truly “fought” your way through our entire privacy policy or at least scrolled down to this point. As you can see from the scope of our privacy policy, we take the protection of your personal data anything but lightly. It is important to us to inform you about the processing of personal data to the best of our knowledge and belief. In doing so, we not only want to tell you which data is processed, but also bring you closer to the motives for using various software programs. Usually, privacy policies sound very technical and legal. Since most of you are neither web developers nor lawyers, we wanted to take a different approach linguistically as well and explain the matter in simple and clear language. Of course, this is not always possible due to the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy. If you have any questions regarding data protection on our website, please do not hesitate to contact us or the responsible office. We wish you a wonderful time and hope to welcome you back to our website soon. All texts are protected by copyright. Source: Privacy policy created with the Privacy Policy Generator for Austria by AdSimple