We have prepared this Privacy Policy (Version 02/28/2023-122427432) to inform you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (referred to as “data” for short) we, as the data controller—and the data processors we engage (e.g., service providers)—process, will process in the future, and
what legal options are available to you. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, is designed to explain the most important points to you as simply and transparently as possible. Wherever it promotes transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics are used. We use clear and simple language to inform you that, in the course of our business activities at
, we process personal data only when there is a corresponding legal basis for doing so. This certainly isn’t possible if we provide explanations that are as brief, vague, and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps you’ll discover a piece of information or two that you weren’t aware of before.
If you still have questions, please contact the responsible party listed below or in the legal notice, follow the links provided, and review additional information on third-party websites. You can, of course, also find our contact information in the legal notice.
This Privacy Policy applies to all personal data processed by our company and to all personal data processed by companies we have contracted (data processors). By “personal data,” we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address, and mailing address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this privacy policy includes:
In short: This Privacy Policy applies to all areas in which personal data is processed in a structured manner within the company through the channels listed above. Should we enter into a legal relationship with you outside of these channels, we will inform you separately if necessary.
In the following Privacy Policy, we provide you with transparent information about the legal principles and regulations—that is, the legal bases under the General Data Protection Regulation—that allow us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.
We process your data only if at least one of the following conditions applies:
Other conditions, such as the collection of data in the public interest, the exercise of official authority, and the protection of vital interests, generally do not apply to us. However, should such a legal basis be relevant, it will be indicated in the appropriate section.
In addition to the EU regulation, national laws also apply:
If any additional regional or national laws apply, we will provide you with information about them in the following sections.
If you have any questions regarding data protection or the processing of personal data, please find the contact information for the responsible person or department below:
Email: info@ceraflex.at
It is our general policy to retain personal data only for as long as is strictly necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer exists. In some cases, we are legally required to retain certain data even after the original purpose has ceased to exist, for example, for accounting purposes.
If you wish to have your data deleted or wish to revoke your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.
We will provide you with information below regarding the specific duration of each data processing activity, provided we have further details on this matter.
In accordance with Articles 13 and 14 of the GDPR, we are informing you of the following rights to which you are entitled to ensure that your data is processed in a fair and transparent manner:
In short: You have rights—don’t hesitate to contact the responsible party listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you can lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/ . In Germany, there is a data protection officer for each federal state. For more information, you can contact the You can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) . The following local data protection authority is responsible for our company:
Director: Mag . Dr. Andrea Jelinek
Address: Barichgasse 40-42, 1030 Vienna
Phone number: +43 1 52 152-0
Email address:
dsb@dsb.gv.at
Website:
https://www.dsb.gv.at/
|
Web Hosting Summary
👥 Data Subjects: Visitors to the website 🤝 Purpose: Professional hosting of the website and ensuring its operation 📓 Data Processed: IP address, time of website visit, browser used, and other data. You can find more details below or from the respective web hosting provider. 📅 Retention period: Depends on the respective provider, but generally 2 weeks ⚖️ Legal basis: Art. 6(1)(f) GDPR (Legitimate Interests) |
When you visit websites these days, certain information—including personal data—is automatically generated and stored, and this is also the case on this website. This data should be processed as sparingly as possible and only for a valid reason. By the way, by “website” we mean the entirety of all web pages on a domain—that is, everything from the home page to the very last subpage (like this one). By “domain,” we mean, for example, example.de or sampleexample.com.
If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You’re probably familiar with the names of some web browsers: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We refer to them simply as browsers or web browsers.
To display a website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why it’s usually handled by professional providers. They offer web hosting and ensure that website data is stored reliably and without errors. That’s a lot of technical terms, but please stick with it—it gets even better!
When your browser on your computer (desktop, laptop, tablet, or smartphone) establishes a connection, and during the transmission of data to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a certain period of time to ensure proper operation.
A picture is worth a thousand words, so the following diagram illustrates the interaction between the browser, the Internet, and the hosting provider.
The purposes of data processing are:
Even as you are visiting our website right now, our web server—the computer on which this website is hosted—typically automatically stores data such as
As a general rule, the data listed above is stored for two weeks and then automatically deleted. We do not share this data with third parties; however, we cannot rule out the possibility that government authorities may access this data in the event of unlawful conduct.
In short: Your visit is logged by our provider (the company that hosts our website on special computers [servers]), but we will not share your information without your consent!
The lawfulness of processing personal data in the context of web hosting is based on Article 6(1)(f) of the GDPR (protection of legitimate interests), as the use of professional hosting services from a provider is necessary to present the company on the Internet in a secure and user-friendly manner and, if necessary, to investigate any attacks or claims arising therefrom.
We generally have a contract with the hosting provider for data processing in accordance with Article 28 et seq. of the GDPR, which ensures compliance with data protection regulations and guarantees data security.
We always strive to make our privacy policy as clear and understandable as possible. However, this isn’t always easy, especially when it comes to technical and legal topics. It often makes sense to use legal terms (such as “personal data”) or certain technical terms (such as “cookies” or “IP address”). However, we do not want to use these terms without explanation. Below you will find an alphabetical list of important terms used in this policy that we may not have addressed in sufficient detail in the previous version of the privacy policy . If these terms are taken from the GDPR and are definitions, we will also cite the relevant GDPR text here and, where appropriate, add our own explanations.
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Processor” means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data we process from you. In addition to the data controllers, there may also be so-called data processors. This includes any company or individual that processes personal data on our behalf. Consequently, data processors may include not only service providers such as tax advisors, but also hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Consent” of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, expressed in the form of a statement or other unambiguous affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her;
Explanation: On websites, this type of consent is typically obtained through a cookie consent tool. You’re probably familiar with this. Whenever you visit a website for the first time, you’re usually asked via a banner whether you agree to or consent to data processing. In most cases, you can also configure individual settings and thus decide for yourself which data processing you allow and which you do not. If you do not give your consent, no personal data about you may be processed. In principle, , consent can of course also be given in writing—that is, not via a tool.
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term “” means:
“personal data” any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person, ;
Explanation: Personal data is any information that can be used to identify you as an individual. This typically includes information such as:
According to the European Court of Justice (ECJ), your IP address is also considered personal data. IT experts can use your IP address to determine at least the approximate location of your device and, subsequently, identify you as the account holder. Therefore, storing an IP address also requires a legal basis under the GDPR. There are also so-called “special categories” of personal data that require special protection. These include:
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Profiling” means any form of automated processing of personal data that consists of using such personal data to evaluate certain personal aspects relating to a natural person, in particular to evaluate aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements of that natural person;
Explanation: Profiling involves gathering various pieces of information about a person in order to learn more about that person. On the web, profiling is often used for advertising purposes or for credit checks. Web and advertising analytics programs, for example, collect data about your behavior and interests on a website. This results in a specific user profile that can be used to deliver targeted ads to a specific audience.
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Controller” means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data; if the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its designation may be provided for under Union law or the law of the Member States;
Explanation: In our case, we are responsible for the processing of your personal data and are therefore the “data controller.” If we transfer collected data to other service providers for processing, they are “data processors.” A “Data Processing Agreement (DPA)” must be signed for this purpose.
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Processing” any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution, or any other form of disclosure; the alignment or combination; the restriction, erasure, or destruction;
Note: When we refer to “processing” in our Privacy Policy, we mean any type of data processing. As mentioned above in the original GDPR statement, this includes not only the collection but also the storage and processing of data.
Congratulations! If you’re reading this, you’ve really “battled” your way through our entire Privacy Policy—or at least scrolled down to this point. As you can see from the length of our Privacy Policy, we take the protection of your personal data very seriously.
It is important to us to inform you, to the best of our knowledge and belief, about the processing of personal data. In doing so, we want not only to tell you what data is processed, but also to explain the reasons for using various software programs. Privacy policies usually sound very technical and legal. However, since most of you are not web developers or lawyers, we wanted to take a different approach linguistically and explain the facts in simple and clear language. Of course, this is not always possible
given the nature of the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions regarding data protection on our website, please do not hesitate to contact us or the data controller. We hope you continue to enjoy your visit and look forward to welcoming you back to our website soon.
All texts are protected by copyright.
Source: Created using the AdSimple Privacy Policy Generator
Matomo
This website uses the open-source web analytics service Matomo.
With the help of Matomo, we are able to collect and analyze data about how visitors use our website. This allows us, among other things, to determine when specific pages were viewed and which region the visitors are from. We also collect various log files (e.g., IP address, referrer, browsers, and operating systems used) and can track whether our website visitors perform certain actions (e.g., clicks, purchases, etc.).
The use of this analytics tool is based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of Section of the TTDSG. Consent may be revoked at any time.
Cookie-Free Analytics
We have configured Matomo so that it does not store cookies in your browser.
Hosting
We host Matomo exclusively on our own servers, so all analytics data remains with us and is not shared with anyone else.
Sie haben die Möglichkeit zu verhindern, dass von Ihnen hier getätigte Aktionen analysiert und verknüpft werden. Dies wird Ihre Privatsphäre schützen, aber wird auch den Besitzer daran hindern, aus Ihren Aktionen zu lernen und die Bedienbarkeit für Sie und andere Benutzer zu verbessern.