Data Privacy Statement

1. Name and Address of the Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection regulations is:

HF Data Datenverarbeitungsges.m.b.H
Schönbrunner Straße 231
1120 Vienna
Austria
Tel.: +43 / 1 / 981 16-0
E-Mail: office[at]hfdata.at
Website: www.firmenbuchgrundbuch.at

2. Name and Address of the Data Protection Officer

The Data Protection Officer of the controller is:

Dr. Georg Hittmair
Schönbrunner Straße 231
1120 Vienna
Austria
E-Mail: datenschutz[at]compass.at

3. General Information on Data Processing

As we provide our services as a clearing office for the Austrian Land Register [Grundbuch] and Business Register [Firmenbuch] on behalf of the Federal Ministry of Justice, enquiries relating to data protection law concerning the core of our activities are forwarded to the Federal Ministry of Justice pursuant to Article 28 GDPR. We as the processor are not authorised to take action ourselves.

3.1 Scope of Processing of Personal Data

As a matter of principle, we collect and use our users' personal data only to the extent that this is necessary for providing an operable website and our contents and services. As a rule, the personal data of our users is collected and used only upon the user's prior consent. An exception applies where the user's consent cannot be obtained in advance for factual reasons and the processing of the data is permitted by statutory provisions.

3.2 Legal basis for the processing of personal data

Where we obtain the consent of the data subject for processing operations involving personal data, Article 6(1)(a) of the EU General Data Protection Regulation (GDPR) constitutes the legal basis.

When processing personal data that is necessary for the performance of a contract to which the data subject is party, Article 6(1)(b) GDPR constitutes the legal basis. This also applies to processing activities which are necessary to implement pre-contractual measures.

Where processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Article 6(1)(c) GDPR constitutes the legal basis.

In cases where vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) GDPR constitutes the legal basis. If processing is necessary to protect a legitimate interest of our company or a third party and the interests, fundamental rights and fundamental freedoms of the data subject do not override the former interest, Article 6(1)(f) GDPR constitutes the legal basis for data processing.

3.3 Erasure of data; Storage period

The personal data of the person concerned will be deleted or blocked as soon as the purpose of storage ceases to apply. Furthermore, data may be stored if this has been provided for by the European or national legislator in EU regulations, laws or other provisions to which the controller is subject. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfilment of a contract.

3.4 Scope of Data Processing

HF Data Datenverarbeitungsges.m.b.H acts as a clearing office for the Land Register and the Business Register on behalf of the Federal Ministry of Justice (See also https://www.justiz.gv.at/service/verrechnungsstellen.795.de.html)).

The service is provided under a service licence, which was awarded in a public procurement procedure. In terms of data protection law we thus act as the Federal Ministry's processor. When the contract was awarded, HF Data Datenverarbeitungsges.m.b.H was put under an obligation to log accesses to the databases of the Republic of Austria.

In order to enhance the findability of Land Register and Business Register information, Business Register and cadastre data provided under the Austrian Act on Re-use of Public Sector Information [Informationsweiterverwendungsgesetz/IWG] for further processing is also processed for index-linking.

4. Collection of data as part of HF-Data's activities (Information acc. to Article 14 GDPR)

4.1 Legal basis for the processing of personal data

The activities of HF Data Datenverarbeitungsges.m.b.H are thus primarily subject to Article 6(1)(b) and (c) GDPR. Processing is required for fulfilling a contract to which the data subject is a party, or to carry out pre-contractual measures; moreover, there is a legal obligation to process data where services are used.

4.2 Purpose of Data Processing

Personal data is processed in the course of a business relationship with customers where a trade is practised, including systematic recording of all transactions concerning income and expenses.

HF Data Datenverarbeitungsges.m.b.H holds the following trade licence for providing its services: Services in automated data processing and information technology as defined in Section 103(1)(a) No. 2 of the Austrian Trade Code [Gewerbeordnung/GewO] of 1973. The purpose of data processing as defined in Article 5(1)(b) GDPR is therefore to support the provision of services expressly permitted by law under the Trade Code.

4.3 Source of Personal Data

HF Data sources personal data from public registers; i.e. the Business Register, the Trade Register or the Register of Associations.

4.4 Categories of Personal Data

All data categories from the underlying public registers are stored. Data may include the following: internal ID, name, title, gender, date of birth, contact details, official ID (e.g. ZVR [Central Register of Associations] number).

4.5 Categories of Recipients

There is a data transfer to third parties, if this is necessary for the execution of the contract. In principle, the recipients of the data are only the users of HF Data services.

4.6 Retention Period

We store data permanently because historical data is also of great value to us and our customers. For example, Compass books from the interwar period were used as a key source for dealing with restitution issues. We have digitised all data gathered in 150 years of publishing and offer this historical data as a separate product.

4.7 Right to Object and Erasure

Article 14 GDPR provides for duties to provide information where personal data was not collected from the data subject; paragraph 5 of that Article, however, provides for exceptions to those information duties. Two of the exceptions apply to us: Paragraphs 1 to 4 (= duty to provide information) do not apply if and to the extent that

(b) provision of such information proves to be impossible or would require disproportionate efforts;
(c) obtaining or disclosure of data is expressly regulated by EU or Member State legislation to which the controller is subject and which provides for appropriate measures to protect the data subject's legitimate interests.

Almost all data of Compass products originate from freely accessible public databases. Reuse of such data is regulated in Directive 2013/37/EU and by the Austrian Act on Re-use of Public Sector Information. All of the said legislation contains a reference to data protection provisions and therefore falls under letter (c). Moreover, informing millions of data subjects would require disproportionate efforts. That is why we make such information available to the public, as is also provided for in the last sentence of Article 14(5)(b) GDPR.

5. Provision of the Website and Creation of Log Files

5.1 Description and Scope of Data Processing

Each time our website is visited, our system will automatically collect data and information from the computer system of the calling computer.

The following data will be collected:

  1. Information about the browser type and version used
  2. The user's operating system
  3. The user's IP address
  4. Date and time of access
  5. Websites from which the user's system accesses our website
  6. Websites accessed by the user's system via our website
  7. The user's request

Such data will be stored in the log files of our system as well. Such data will not be stored together with other personal data of the user.

5.2 Legal Basis for Data Processing

The legal basis for temporary storage of data and log files is Article 6(1)(f) GDPR.

5.3 Purpose of Data Processing

Temporary storage of the IP address by the system is necessary for delivering the website to the user's computer. For that purpose, the user's IP address must remain stored for the duration of the session.

Log files are stored to ensure the website's functionality. In addition, such data helps us to optimise the website and to ensure the security of our IT systems.

No data will be analysed for marketing purposes in this connection. The said purposes also constitute our legitimate interest in data processing as defined in Article 6(1)(f) GDPR.

5.4 Storage period

The data will be erased once it is no longer necessary for achieving the purpose for which it was collected.

  • Website provision: The data will be erased when the relevant session has ended.
  • Storage in log files: The data will be erased after a maximum of three (3) months.
    • Storage after that period is possible. In that case the IP addresses of the users will be deleted or masked so that the calling client can no longer be identified.

5.5 Right to Object and Erasure

Collection of data for provision of the website and storage of data in log files is absolutely necessary for operation of the website. Consequently, users have no right to object.

6. Use of cookies; Local storage

6.1 Description and extent of data processing

Our website uses cookies to make our internet presence more user-friendly and functional. Some cookies will remain stored on your terminal device.

Cookies are small data packages which are exchanged between your browser and the/our web server when you visit our website. They cause no harm and merely serve the purpose of recognising visitors of the website. Cookies may only store information provided by your browser, i.e. information you have entered into the browser yourself or which is available on the website. Cookies cannot execute a code and cannot be used to access your terminal device.

When you visit our website again using the same terminal device, the information stored in cookies may subsequently either be sent back to us ("first-party cookie") or to a web application of the third-party providers to which the cookie belongs ("third-party cookie"). By means of the stored and returned information the relevant web application will recognise that you have previously retrieved and visited the website via the browser of your terminal device.

Cookies contain the following information:

  • Cookie name
  • Name of the server from which the cookie originally came
  • Cookie ID number
  • A date on which the cookie is automatically deleted

Depending on their designated purpose and function cookies are categorised as follows:

  • Strictly necessary cookies to ensure technical operation and the essential features of our website. These cookies are used, for example, to maintain your settings while you navigate the website, or to ensure that important information is maintained throughout the session (e.g. login, shopping basket)
  • Statistics cookies that help us understand how visitors interact with our website; such information is collected and analysed anonymously only. This gives us valuable insight to be able to help us optimise both the website and our products and services
  • Marketing cookies to target visitors on our website with highly specific ads.
  • Non-classified cookies are cookies which we are currently trying to classify together with providers of individual cookies

In addition, depending on the storage period cookies are categorised into session cookies and persistent cookies. Session cookies store information which is used during your current browser session. These cookies will be deleted automatically once you close your browser. No information will remain stored on your terminal device. Persistent cookies store information between two visits to the website. As a result of such information you will be recognised as a recurring visitor at your next visit and the website will respond accordingly. The duration of a persistent cookie is defined by the cookie provider.

6.2 Legal basis for data processing

The legal basis for using strictly necessary cookies is our legitimate interest in technically sound operation and smooth functionality of our website in line with Article 6(1)(f) GDPR.

Without these cookies our website cannot function properly. Use of statistics cookies or marketing cookies requires your consent pursuant to Article 6(1)(a) GDPR.

6.3 Right to object and erasure

  • You may withdraw your consent to the use of cookies pursuant to Article 7(3) GDPR at any time with effect for the future. Consent is voluntary. If you do not consent, no disadvantages will occur. Further information on the cookies we actually use (in particular on their purpose and duration) is contained in this data privacy statement and in the information on cookies used by us in our cookie banner.
  • In addition, you may adjust your browser settings to generally prevent cookies from being stored on your terminal device or to be asked for permission to place cookies. Cookies that have been placed can be deleted at any time. For information on how this works please use your browser's help function.
  • Please note that if you disable cookies in general, the functions on our website may be compromised.
  • Our website also uses so-called local storage functions (also referred to as "local storage"). This means that data is stored locally in the cache of your browser, which continues to exist and may be read out even after the browser is closed, unless you delete the cache or in the case of session storage.
  • Third parties cannot access data stored in local storage. Where special plugins or tools use the local storage function, they will contain a description thereof.
  • If you do not want plugins or tools to use local storage functions, you can adjust your browser settings accordingly. Please note that this may lead to functional limitations.

7. WebCare – Consent Management (DataReporter)

To manage your cookie consents and to fulfil our statutory information obligations, we use WebCare by Datareporter GmbH, Zeileisstraße 6, 4600 Wels, Austria.

When you first visit our website, a cookie banner is displayed through which you can grant or refuse your consent to various cookie categories. Your consent decision is stored in a cookie so that you do not have to make this decision again on your next visit. WebCare does not store personal data such as names or email addresses — only your consent decision and an anonymous session identifier.

Data processing takes place on servers in Europe (Germany). No data is transferred to third countries. A data processing agreement pursuant to Article 28 GDPR has been concluded between us and Datareporter GmbH.

You may withdraw or adjust your consent at any time via the cookie banner (accessible again via the privacy link in the footer).

Legal basis: Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR (obligation to demonstrate consent) as well as Article 6(1)(f) GDPR (legitimate interest in the legally compliant management of consents).

Privacy policy DataReporter: https://www.datareporter.eu

8. Sentry (Error Detection and System Monitoring)

We use Sentry, a service provided by Functional Software, Inc., 45 Fremont Street, San Francisco, CA 94105, USA, to detect and diagnose technical errors on our website. Sentry automatically captures error messages, load times and technical diagnostic data (e.g. browser type, operating system, URL accessed at the time of an error, anonymised IP address). Personal data from form inputs is not captured.

The data collected is used exclusively for technical quality assurance and error resolution. It is not used for advertising purposes.

Data processing takes place on servers within the EU (Germany). No transfer to third countries takes place. A data processing agreement pursuant to Article 28 GDPR has been concluded between us and Sentry.

Legal basis: Article 6(1)(f) GDPR (legitimate interest in the stable and error-free operation of our website).

Privacy policy Sentry: https://sentry.io/privacy/

9. Contact form and email contact

9.1 Description and extent of data processing

Our website provides a contact form which may be used to contact us electronically.

If a user makes use of that option, the data entered into the input form will be transmitted to us and stored. This data includes the contact details provided (e.g. name, email address) as well as the content and message data, for the purpose of processing the enquiry and in the event of follow-up questions.

In addition, the following data is stored at the time the message is sent:

  1. The user's IP address
  2. Date and time of submission

Alternatively, you may contact us via the email address provided. In that case the user's personal data transmitted by email will be stored. In this context no data will be passed on to third parties. Data will be used exclusively for processing the conversation.

9.2 Legal basis for data processing

The legal basis for data processing is Article 6(1)(a) GDPR, provided that the user has given his/her consent.

The legal basis for processing data transmitted in the course of sending an email is Article 6(1)(f) GDPR. If the purpose of the email contact is to conclude a contract, Article 6(1)(b) GDPR is an additional legal basis for processing.

9.3 Purpose of data processing

Personal data from the input form will be processed by us only to process your enquiry. If you contact us by email, this also constitutes the necessary legitimate interest in data processing. Other personal data processed during the sending process is used to prevent misuse of the contact form and to ensure the security of our IT systems.

9.4 Storage period

The data will be erased once it is no longer necessary for achieving the purpose for which it was collected. For personal data from the contact form input fields and data sent by email, this is the case when the respective conversation with the user has ended. The conversation is considered ended when the circumstances indicate that the matter in question has been conclusively resolved. The additional personal data collected during the submission process is erased no later than seven days.

9.5 Right to object and erasure

The user may withdraw his/her consent to the processing of personal data at any time. If the user contacts us by email, s/he may object to storage of his/her personal data at any time. In that case the conversation cannot be continued.

You may withdraw your consent and object to storage at any time by sending an email to datenschutz@compass.at. In that case all personal data stored during our contact will be erased.

10. User login and account registration

10.1 SSO login

To access the password-protected area of our website, we operate a Single Sign-On (SSO) system on our own servers. No login data is transferred to third parties.

The following data is processed during login:

  1. User identifier
  2. Password (stored encrypted, never in plain text)
  3. Session token
  4. Date and time of login

Legal basis: Article 6(1)(b) GDPR (performance of contract) and Article 6(1)(f) GDPR (legitimate interest in a secure authentication procedure).

Retention period: Session data is automatically deleted after logout or upon expiry of the session. Account master data is stored for the duration of the business relationship.

10.2 Account registration

Access to extended query services (account) can be requested by submitting an account registration application.

The following personal data is collected as part of this application:

  1. Name
  2. Email address
  3. Completed registration form (file upload, PDF)
  4. Official photo ID (file upload)
  5. Proof of residence (file upload)
  6. Optional: Professional ID for WiEReG access (notary ID, ADVM code or WT code)

Upon submission of the application, IP address and timestamp are also stored.

The uploaded documents (ID, proof of residence) contain particularly sensitive personal data and are used exclusively for identity verification in the context of account activation.

Legal basis: Article 6(1)(b) GDPR (performance of pre-contractual measures at the request of the data subject and performance of contract following account activation).

Retention period: Account master data (name, email) is stored for the duration of the business relationship. Invoice-relevant data is retained for 7 years in accordance with statutory retention obligations (§ 132 of the Austrian Federal Fiscal Code, BAO). Uploaded identity documents are deleted after the verification process is complete.

Right to object and erasure: The provision of the stated data is mandatory for opening an account. Requests for data deletion or account closure can be directed to datenschutz@compass.at.

11. E-commerce

11.1 Extent of processing personal data

We offer a platform for concluding purchase and service contracts. In order to provide the same, the following personal data is processed:

  1. Email
  2. First and last name
  3. Company
  4. Address
  5. Products
  6. IP address for VAT calculation

11.2 Payment processing (Mollie)

For payment processing, we use the service Mollie provided by Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. During payment, your payment data is transmitted directly to Mollie and processed there. We receive from Mollie only a payment confirmation, but no complete payment data (e.g. no complete card numbers).

Mollie is certified in accordance with the PCI-DSS standard. Processing takes place on servers within the EU/EEA. No data is transferred to third countries.

A data processing agreement pursuant to Article 28 GDPR has been concluded between us and Mollie.

Legal basis: Article 6(1)(b) GDPR (performance of contract).

Privacy policy Mollie: https://www.mollie.com/de/privacy

11.3 Legal basis for the processing of personal data

The legal basis for processing personal data is Article 6(1)(b) GDPR.

11.4 Purpose of data processing

Storage of the data is necessary for you to be able to buy our products and for us to issue an invoice.

11.5 Storage period

Data will generally be erased once the purpose for which it was collected has been achieved. We are under a statutory obligation to retain invoices for seven (7) years (§ 132 of the Austrian Federal Fiscal Code, BAO).

11.6 Right to object and erasure

Collection and storage of data is absolutely necessary when purchasing our products. Consequently, users have no right to object.

12. Friendly Captcha (Spam Protection)

To protect our forms from spam and automated misuse, we use Friendly Captcha by Friendly Captcha GmbH, Am Anger 3–5, 82237 Wörthsee, Germany. Friendly Captcha is active on all forms on this website.

Friendly Captcha analyses browser and network connection characteristics in the background (e.g. anonymised IP address, browser fingerprint) without requiring you to solve images or perform manual inputs.

In the course of providing the service, data may be transferred to sub-processors in the USA. Appropriate safeguards pursuant to Article 46(2)(c) GDPR (standard contractual clauses) have been agreed. A data processing agreement pursuant to Article 28 GDPR has been concluded between us and Friendly Captcha GmbH.

Legal basis: Article 6(1)(f) GDPR (legitimate interest in the security of our forms and protection against abusive use).

Privacy policy Friendly Captcha: https://friendlycaptcha.com/legal/privacy-end-users/

13. Web analysis by Matomo

13.1 Extent of processing personal data

We use Matomo, an open-source software for analysing user behaviour, on our website. Matomo is operated on our own servers; data is not passed on to third parties.

Matomo behaves differently depending on your consent decision in the cookie banner:

With consent (statistics cookies accepted): Matomo sets a cookie to recognise returning visitors. The following data is stored:

  1. Two bytes of the IP address of the accessing system (the IP address is truncated before storage so that it cannot be traced back to individual persons)
  2. The accessed webpage
  3. The website from which the user reached the accessed webpage (referrer)
  4. The sub-pages accessed from the accessed webpage
  5. Time spent on the webpage
  6. Frequency of access to the webpage

Without consent (cookieless tracking): Without consent to statistics cookies, Matomo is operated in cookieless mode. No cookies are set and no cross-device recognition is performed. Analysis takes place exclusively on an aggregated, fully anonymised basis.

13.2 Matomo Tag Manager

We use the Matomo Tag Manager for the central management of our analytics and marketing tags. The Tag Manager itself does not collect personal data; data collection is carried out by the services integrated via the Tag Manager, which are described separately in this data privacy statement. The Matomo Tag Manager is operated on our own servers.

13.3 Legal basis for data processing

For tracking with cookies, Article 6(1)(a) GDPR applies (your consent via the cookie banner, category "Statistics").

For cookieless tracking without consent, Article 6(1)(f) GDPR applies (legitimate interest in the analysis and optimisation of our online offering). Since no cookies are set and no personal data in the sense of individual attribution is processed, consent is not required for this.

13.4 Storage period

The data is deleted as soon as it is no longer needed for our recording purposes.

13.5 Right to object and erasure

You can prevent tracking by Matomo with cookies by not accepting the "Statistics" category in the cookie banner or by withdrawing your consent at any time via the cookie banner.

Alternatively, you can set an opt-out cookie to prevent future tracking: https://analytics.compass.at/index.php?module=CoreAdminHome&action=optOut&language=de

Further information on the privacy settings of the Matomo software can be found at: https://matomo.org/docs/privacy/

14. Google Ads Conversion Tracking

We use Google Ads Conversion Tracking by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure the success of our Google advertising campaigns.

Conversion tracking takes place exclusively upon consent having been granted (category "Marketing" in the cookie banner). The transmission of conversion data to Google takes place server-side via the Matomo Conversion Export Plugin. Client-side, only a Google tag (gtag.js) is integrated for Consent Mode signalling; without marketing consent, no conversion data is transmitted to Google.

In the event of a conversion (e.g. completed order following a click on a Google ad), the following data is transmitted to Google: conversion event, timestamp and — where available — the Google Click ID (GCLID). No complete IP addresses are transmitted to Google.

In the course of this service, data may be transferred to the USA. Google Ireland Limited is listed in the EU-US Data Privacy Framework: https://www.dataprivacyframework.gov/list

The legal basis is your consent pursuant to Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by adjusting your settings in our cookie banner.

Further information on data protection at Google can be found at: https://policies.google.com/privacy

Google advertising settings: https://adssettings.google.com/authenticated

15. Microsoft Advertising Conversion Tracking

Our website uses a conversion tracking service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA, to measure the success of our Microsoft Advertising campaigns (formerly Bing Ads).

Conversion tracking takes place exclusively upon consent having been granted (category "Marketing" in the cookie banner). The transmission of conversion data to Microsoft takes place server-side via the Matomo Conversion Export Plugin. No client-side Microsoft tracking cookies are set. Without marketing consent, no conversion data is transmitted to Microsoft.

In the event of a conversion, the following data is transmitted to Microsoft: conversion event and timestamp. No complete IP addresses and no personal identification data are transmitted.

In the course of this service, data is transferred to the USA. Microsoft is listed in the EU-US Data Privacy Framework: https://www.dataprivacyframework.gov/s/participant-search/participantdetail?id=a2zt0000000KzNaAAK&status=Active

Any data transfers are also made on the basis of EU standard contractual clauses pursuant to Article 46(2)(c) GDPR: https://about.ads.microsoft.com/de-de/ressourcen/richtlinien/microsoft-advertising-vertrag

Legal basis: Article 6(1)(a) GDPR (your consent via the cookie banner, category "Marketing").

Privacy policy Microsoft: https://privacy.microsoft.com/de-de/privacystatement

Further information on Microsoft Advertising: https://help.ads.microsoft.com/#apex/3/de/53056/2

16. MapToolkit (Map Display)

For the display of interactive maps (e.g. to show company locations), we use MapToolkit by Toursprung GmbH, Lederergasse 23, 4020 Linz, Austria.

When a map is loaded, your browser establishes a connection to MapToolkit's servers, transmitting your IP address and information about the map region accessed. MapToolkit processes this data exclusively to deliver the map content.

Processing takes place on servers within the EU. A data processing agreement pursuant to Article 28 GDPR has been concluded between us and Toursprung GmbH.

Legal basis: Article 6(1)(f) GDPR (legitimate interest in the user-friendly display of location information).

Privacy policy MapToolkit: https://www.maptoolkit.com/de/privacy

17. Rights of the data subject

Where your personal data is processed, you are a data subject as defined in the GDPR and you have the following rights vis-à-vis the controller:

17.1 Right of access

You may ask the controller to confirm whether personal data concerning you is processed by us. If such processing takes place, you may request the following information from the controller:

  1. the purposes for which the personal data is processed;
  2. the categories of personal data that are processed;
  3. the recipients or categories of recipients to whom the personal data concerning you has been or will be disclosed;
  4. the planned retention period for the personal data concerning you or, if specific information on this is not possible, the criteria used to determine the retention period;
  5. the existence of a right to rectification or erasure of personal data concerning you, a right to restriction of processing by the controller or a right to object to such processing;
  6. the existence of a right to lodge a complaint with a supervisory authority;
  7. all available information about the origin of the data, where the personal data is not collected from the data subject;
  8. the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) GDPR and — at least in those cases — meaningful information about the logic involved and the significance and envisaged consequences of such processing for the data subject.

You have the right to request information about whether the personal data concerning you is transferred to a third country or to an international organisation. In this context, you may request to be informed about the appropriate safeguards pursuant to Article 46 GDPR in connection with the transfer.

This right of access may be restricted to the extent that it is likely to render impossible or seriously impair the achievement of the research or statistical purposes, and the restriction is necessary for the fulfilment of the research or statistical purposes.

17.2 Right to rectification

You have a right to rectification and/or completion of data vis-à-vis the controller if the processed personal data concerning you is incorrect or incomplete.

The controller must rectify the data immediately.

Your right to rectification may be restricted to the extent that it is likely to render impossible or seriously impair the achievement of the research or statistical purposes, and the restriction is necessary for the fulfilment of the research or statistical purposes.

17.3 Right to restriction of processing

You may request restriction of processing of personal data concerning you under the following conditions:

  1. if you contest the accuracy of the personal data concerning you for a period enabling the controller to verify the accuracy of the personal data;
  2. the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
  3. the controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims; or
  4. if you have objected to processing pursuant to Article 21(1) GDPR and it has not yet been determined whether the controller's legitimate reasons override your reasons.

Where processing of personal data concerning you has been restricted, such data may — with the exception of storage — only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

Where restriction of processing has been imposed under the above conditions, you will be informed by the controller before the restriction is lifted.

Your right to restriction of processing may be restricted to the extent that it is likely to render impossible or seriously impair the achievement of the research or statistical purposes, and the restriction is necessary for the fulfilment of the research or statistical purposes.

17.4 Right to erasure

12.4.1 Erasure obligation

You may request that the controller erase the personal data concerning you without delay, and the controller is obliged to erase this data without delay where one of the following grounds applies:

  1. The personal data concerning you is no longer necessary in relation to the purposes for which it was collected or otherwise processed.
  2. You withdraw your consent on which the processing was based pursuant to Article 6(1)(a) or Article 9(2)(a) GDPR, and there is no other legal basis for the processing.
  3. You object to the processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21(2) GDPR.
  4. The personal data concerning you has been unlawfully processed.
  5. The erasure of personal data concerning you is necessary for compliance with a legal obligation under Union or Member State law to which the controller is subject.
  6. The personal data concerning you was collected in relation to the offer of information society services referred to in Article 8(1) GDPR.

12.4.2 Information to third parties

Where the controller has made the personal data concerning you public and is obliged pursuant to Article 17(1) GDPR to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you as the data subject have requested the erasure of any links to, or copy or replication of, that personal data.

12.4.3 Exceptions

The right to erasure does not apply to the extent that processing is necessary

  1. for exercising the right of freedom of expression and information;
  2. for compliance with a legal obligation which requires processing under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. for reasons of public interest in the area of public health pursuant to Article 9(2)(h) and (i) as well as Article 9(3) GDPR;
  4. for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Article 89(1) GDPR, to the extent that the right referred to in section a) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
  5. for the establishment, exercise or defence of legal claims.

17.5 Right to be notified

If you have exercised your right to rectification, erasure, or restriction of processing vis-à-vis the controller, the controller must notify all recipients to whom personal data concerning you has been disclosed of such rectification or erasure of data or restriction of processing, unless this proves impossible or involves disproportionate efforts. You have a right vis-à-vis the controller to be informed about those recipients.

17.6 Right to data portability

You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to which the personal data has been provided, where

  1. the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR or on a contract pursuant to Article 6(1)(b) GDPR; and
  2. the processing is carried out by automated means.

In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another controller, where technically feasible. The rights and freedoms of other persons must not be adversely affected by this.

The right to data portability does not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

17.7 Right to object

You have the right, on grounds relating to your particular situation, to object to the processing of personal data concerning you on the basis of Article 6(1)(e) or (f) GDPR at any time; this shall also apply to profiling that is based on those provisions.

The controller shall no longer process the personal data concerning you unless the controller demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims.

Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing; this includes profiling to the extent that it is related to such direct marketing. Where you object to processing for direct marketing purposes, the personal data concerning you shall no longer be processed for such purposes. You have the possibility, in the context of the use of information society services — notwithstanding Directive 2002/58/EC — to exercise your right to object by automated means using technical specifications.

You also have the right to object, on grounds relating to your particular situation, to processing of personal data concerning you for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) GDPR. Your right to object may be restricted to the extent that it is likely to render impossible or seriously impair the achievement of the research or statistical purposes, and the restriction is necessary for the fulfilment of the research or statistical purposes.

17.8 Right to withdraw your consent given under data protection law

You may withdraw your consent given under data protection law at any time. The lawfulness of processing done up to the time of withdrawal shall not be affected by withdrawing consent.

17.9 Automated individual decision-making including profiling

You have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision

  1. is necessary for entering into, or performance of, a contract between you and the controller,
  2. is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
  3. is based on your explicit consent.

However, these decisions must not be based on special categories of personal data referred to in Article 9(1) GDPR, unless Article 9(2)(a) or (g) GDPR applies and appropriate measures have been taken to safeguard the rights and freedoms and your legitimate interests.

With regard to the cases referred to in (1) and (3), the controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your own point of view and to contest the decision.

17.10 Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress or outcome of the complaint, including the option of a judicial remedy as defined in Article 78 GDPR.

Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42
1030 Vienna
E-Mail: dsb@dsb.gv.at
Website: www.dsb.gv.at

18. Changes to this data privacy statement

We reserve the right to adapt this data privacy statement in order to always comply with current legal requirements or to implement changes to our services in the data privacy statement, e.g. when introducing new services.

The new data privacy statement will then apply when you visit us again.