Privacy Statement
Data Protection Advisor
Andreas Leibetseder
This Privacy Statement informs you about how we process personal data (hereinafter “data”) collected on our online platforms and through our associated webpages, and describes the scope and purpose of these activities. The terms “Processing” and “Controller” are used within the meaning of Art. 4 of the General Data Protection Regulation (GDPR).
Controller
Sclable Business Solutions GmbH
Marc-Aurel-Straße 10-12 / 10
1010 Vienna, Austria
Phone: +43 1 348 9088
General information
Types of processed data
- Contact details (e.g. e-mail, phone numbers)
- Usage data (e.g. interest in content, access times)
- Meta / communication data (e.g. device information, IP addresses)
Data subject categories
Visitors and users of the online offer (data subjects are hereinafter referred to as “users”).
Purpose of processing
- Providing the online offer, its functions and its content
- Responding to contact inquiries and communicating with users
- Security measures
- Audience/reach measurement
Contacting
When contactin us (for example, by e-mail, telephone or via social media), the information provided by the user to handle the contact inquiry is processed in accordance with Art. 6 (1) (b) of the GDPR. User information can be stored in a Customer Relationship Management System (“CRM System”) or similar inquiry organization system. This data will not be shared without your prior consent. The inquiries that are no longer necessary are deleted. We check the necessity every two years. The statutory archiving obligations also apply.
Collection of access data and log files
For the purposes of our legitimate interests, in accordance with Art. 6 (1) (f) of the GDPR, we collect data every time the server on which the service is located, is accessed (so-called server log files). The access data includes the name of the website accessed, the data file accessed and the date and time of access, the quantity of data transferred, notification of successful retrieval, browser type and version, the user’s operating system, the referrer URL (the page previously visited), the user’s IP address and the requesting service provider.
Log file information is retained for security reasons (e.g. to detect abuse or fraud) for a maximum of 6 months before being deleted. Data that is to be retained as evidence shall be excluded from deletion until the relevant case has been finalized.
Cookies and similar technologies
We use cookies and similar technologies to store information on your device and to access information already stored there. You can change or withdraw your consent at any time, with effect for the future, under Manage preferences.
Statistics cookies
We use cookies to measure the performance of our website:
- How do visitors use our website?
- On which areas/pages do users spend the most time?
- How often are the pages visited?
- Are the videos on our website being watched?
Our website uses the Matomo analytics tool to collect and store data to improve the website based on statistics. Matomo uses cookies, text files that are stored on your computer and allow an analysis of your use of the website. For this purpose, the usage information associated with the cookie is transmitted to our server and stored for up to 90 days. This function can be deactivated in the browser at any time. Your IP address is anonymized. A transfer to third parties does not take place.
Marketing cookies
We use LinkedIn Insight Tag to track website conversions, build targeted professional audiences, and provide aggregated demographic insights about our website visitors. It matches your visit to our website with your LinkedIn profile (if you are a member) to show you relevant advertisements on LinkedIn. Following data is collected: IP address (truncated and/or hashed), device properties, browser type, timestamp, page views, and referrer URL. Data is encrypted, sent to LinkedIn, and anonymized or deleted within 90 days. For the audience-insights part of this processing, we and LinkedIn Ireland act as joint controllers within the meaning of Art. 26 GDPR.
Video content
We use Ignite Video, a European video hosting platform, to stream video content on our website. By integrating this solution, we ensure that you can watch our videos in compliance with data protection regulations and without any cookie tracking. The IP address is automatically transmitted upon requesting video content. Ignite does not store or process the IP address in any way. The European Union is the primary location where the collected data is processed. If the data is also processed in other countries, you will be informed separately. Cookie Policy of the Data Processor: https://ignite.video/en/privacy.
Third-Country Data Transfers
With the LinkedIn Insight Tag, one tool integrated into our website transfers personal data to a country outside the European Economic Area (EEA). The following data may be transferred to the United States: IP address (truncated and/or hashed), device properties, browser type, timestamp, page views, and referrer URL.
To safeguard your data in accordance with the requirements of Chapter V GDPR, we rely on the following transfer mechanisms:
- EU-U.S. Data Privacy Framework (Art. 45 GDPR): LinkedIn Corporation is certified under the EU-U.S. Data Privacy Framework. The transfer therefore takes place on the basis of the European Commission’s adequacy decision. Certification obliges the recipient to comply with the principles of the Framework. Should this adequacy decision be suspended, repealed, or annulled, we will transfer data on the basis of the European Commission’s Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
- Supplementary safeguards: In addition, we apply technical and organisational measures where available, including truncation and/or hashing of IP addresses, transport encryption (TLS), and the use of pseudonymous tracking identifiers.
- Your consent (Art. 6(1)(a) GDPR): The transfer only takes place if you have consented to the Marketing category. You can withdraw your consent at any time with effect for the future.
Your rights
You are entitled to exercise your right to disclosure, rectification, deletion, limitation, data transferability, revocation and objection.
If you feel that your data has been processed in an unlawful manner or your right to data protection has been violated in any way, you can file a complaint with the regulating authorities. In Austria, this is the Datenschutzbehörde [Data Protection Authority].
Datenschutzbehörde [Data Protection Authority]:
Wickenburggasse 8
1080 Vienna, Austria
Phone: +43 1 52 152-0