
Preamble
With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to briefly as “data”) we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offering”).
The terms used are not gender-specific.
Last updated: 14 July 2026
Controller
AV-Professional GmbH City Park Vienna Brunner Straße 63/23 1230 Vienna, Austria
Contact: Bashir Altawil
Authorized representatives: David Knapp, Ing. Rainer Strzygowski
Email address: datenschutz@avpro.at
Phone: 0043 1 252 10 0
Legal notice (Impressum): https://www.avpro.at/impressum
Data Protection Officer Contact
AV-Professional GmbH City Park Vienna Brunner Straße 63/23 1230 Vienna, Austria
Contact: Bashir Altawil b.altawil@avpro.at
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
Inventory data. Employee data. Payment data. Location data. Contact data. Content data. Contract data. Usage data. Meta, communication and procedural data. Social data. Applicant data. Image and/or video recordings. Audio recordings. Log data. Performance and behavioral data. Working time data. Creditworthiness data. Salary data.
Special Categories of Data
Health data. Religious or philosophical beliefs. Trade union membership.
Categories of Data Subjects
Customers and clients. Employees. Prospective customers. Communication partners. Users. Applicants. Business and contractual partners. Persons depicted. Third parties. Customers.
Purposes of Processing
Provision of contractual services and fulfillment of contractual obligations. Communication. Security measures. Direct marketing. Reach measurement. Office and organizational procedures. Remarketing. Organizational and administrative procedures. Application procedures. Feedback. Marketing. Profiles with user-related information. Provision of our online offering and user-friendliness. Assessment of creditworthiness and credit rating. Establishment and execution of employment relationships. Information technology infrastructure. Public relations and information purposes. Financial and payment management. Public relations. Sales promotion. Business processes and administrative procedures. Artificial Intelligence (AI).
Automated Decisions in Individual Cases
Credit rating inquiry.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or registered office. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
Consent (Art. 6 (1) sentence 1 lit. a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
Performance of a contract and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
Legal obligation (Art. 6 (1) sentence 1 lit. c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject which require protection of personal data.
Application procedure as a pre-contractual or contractual relationship (Art. 6 (1) sentence 1 lit. b) GDPR) – Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR are requested as part of the application process, their processing is carried out in accordance with Art. 9(2) lit. b, lit. c or lit. h GDPR.
Processing of special categories of personal data relating to healthcare, occupation and social security (Art. 9(2) lit. h) GDPR) – Processing is necessary for the purposes of preventive or occupational medicine.
National data protection regulations in Austria: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Austria. These include, in particular, the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act – DSG).
Relevant legal bases under Swiss data protection law: If you are located in Switzerland, we process your data on the basis of the Federal Act on Data Protection (“Swiss DPA”).
Security Measures
In accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to it, its input, transfer, the safeguarding of its availability, and its separation. We have also established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data breaches. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and through privacy-friendly default settings.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. If a website is secured with an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL.
Transfer of Personal Data
In the course of our processing of personal data, it may occur that such data is transferred to or disclosed to other entities, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content embedded in a website. In such cases, we comply with the legal requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.
Data transfer within the organization: We may transfer personal data to other departments or units within our organization or grant them access to it. Insofar as the data transfer is for administrative purposes, it is based on our legitimate business and economic interests, or is carried out insofar as it is necessary for the fulfillment of our contractual obligations, or where the consent of the data subject or a legal permission exists.
International Data Transfers
Data processing in third countries: Insofar as we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), this is always done in compliance with legal requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a safe legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the EU Commission.
Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with legal provisions as soon as the underlying consent is revoked or there are no further legal grounds for the processing.
Further notes on processing operations, procedures and services:
Retention and deletion of data: The following general periods apply under Austrian law for retention and archiving:
10 years – retention period for books and records, annual financial statements, inventories, accounting documents and invoices (Federal Fiscal Code BAO §132, Commercial Code UGB §§190–212).
6 years – other business documents: commercial or business letters received and sent, as well as other tax-relevant documents (BAO §132, UGB §§190–212).
3 years – data for processing warranty and damage claims, based on the regular statutory limitation period (§§ 1478, 1480 of the Austrian Civil Code).
Rights of Data Subjects
As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1) lit. e or f GDPR.
Right to withdraw consent: You have the right to withdraw any consent given at any time.
Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to request information about this data as well as further information and a copy of the data in accordance with legal requirements.
Right to rectification: You have the right, in accordance with legal requirements, to request the completion of data concerning you or the correction of inaccurate data concerning you.
Right to erasure and restriction of processing: You have the right, in accordance with legal requirements, to request that data concerning you be deleted without delay, or alternatively to request a restriction of the processing of the data.
Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with legal requirements, in a structured, commonly used and machine-readable format, or to request its transfer to another controller.
Right to lodge a complaint with a supervisory authority: In accordance with legal requirements, you also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of personal data concerning you violates the GDPR.
Business Services
We process data of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as “contractual partners”), within the framework of contractual and comparable legal relationships as well as related measures, and with regard to communication with contractual partners (or pre-contractually), such as responding to inquiries.
We delete the data after the expiry of statutory warranty and comparable obligations, i.e. generally after four years, unless the data is stored in a customer account or must be retained for legal archiving reasons (e.g. for tax purposes, generally ten years).
Types of data processed: Inventory data; payment data; contact data; contract data; usage data; meta, communication and procedural data; employee data.
Data subjects: Customers and clients; prospective customers; business and contractual partners; employees.
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR); legal obligation (Art. 6(1) sentence 1 lit. c) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Online shop, order forms, e-commerce and delivery: We process the data of our customers to enable them to select, purchase or order the selected products as well as their payment and delivery; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR).
WooCommerce: For processing orders in our online rental shop (rental store and clearance store), we use WooCommerce, an e-commerce plugin for WordPress. In the course of use, order, payment and contact data required for contract fulfillment and customer management is processed. Data processing takes place on our own server, hosted by Hetzner; no data is transferred to the plugin developer during regular operation; Service provider: Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA (plugin development); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR); Website: https://woocommerce.com; Privacy Policy: https://automattic.com/privacy/.
Event management: We process the data of participants in events offered or organized by us in order to enable their participation and use of the associated services; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR).
Film and television production: We process the data of our customers and clients in order to enable the planning, production and distribution of film and television content as well as related services; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR), legal obligation (Art. 6(1) sentence 1 lit. c) GDPR), legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Rental services: We process the data of our renters and prospective renters in accordance with the underlying rental agreement; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR).
Technical services: We process the data of our customers and clients in order to enable them to select, purchase or commission the selected services as well as their payment and provision; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR).
Business Processes and Procedures
Personal data of customers and clients is processed within the framework of contractual and comparable legal relationships and pre-contractual measures. This data processing supports and facilitates business operations in areas such as customer management, sales, payment processing, accounting and project management.
Types of data processed: Inventory data; payment data; contact data; content data; contract data; usage data; meta, communication and procedural data; log data; employee data.
Data subjects: Customers and clients; prospective customers; communication partners; business and contractual partners; customers; third parties; users; employees.
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); legal obligation (Art. 6(1) sentence 1 lit. c) GDPR).
Further notes on processing operations, procedures and services:
Customer management and CRM: Procedures within the framework of customer management and customer relationship management (e.g. customer acquisition, customer retention, customer communication, complaint management, data management and analysis); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR), legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Sales: Procedures for the planning, execution and monitoring of measures for the marketing and sale of products or services; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR), legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Accounting and payment processing: Procedures for the recording, processing and monitoring of business transactions in the area of accounts payable and receivable; Legal bases: Performance of a contract (Art. 6(1) sentence 1 lit. b) GDPR), legal obligation (Art. 6(1) sentence 1 lit. c) GDPR), legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Marketing, advertising and sales promotion: Procedures within the framework of marketing, advertising and sales promotion (e.g. market analysis, development of marketing strategies, planning and implementation of advertising campaigns, online marketing); Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Public relations: Procedures within the framework of public relations (e.g. development and implementation of communication strategies, maintaining media contacts, crisis communication); Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Use of Online Platforms for Offering and Sales Purposes
We offer our services on online platforms operated by other service providers. In this context, the privacy notices of the respective platforms apply in addition to our own privacy notices.
Types of data processed: Inventory data; payment data; contact data; contract data; usage data; meta, communication and procedural data.
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
eBay: Online marketplace for e-commerce; Service provider: eBay Marketplaces GmbH, Helvetiastrasse 15/17, 3005 Bern, Switzerland; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); Website: https://www.ebay.de/; Privacy Policy: https://www.ebay.de/help/policies/member-behavior-policies/datenschutzerklrung?id=4260.
Providers and Services Used in the Course of Business Operations
In the course of our business operations, and in compliance with legal requirements, we use additional services, platforms, interfaces or plug-ins from third-party providers.
Types of data processed: Inventory data; payment data; contact data; content data; contract data.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Asana: Project management – organization and management of teams, groups, workflows, projects and processes; Service provider: Asana, Inc, 1550 Bryant Street, Suite 200, San Francisco, CA 94103, USA; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); Website: https://asana.com; Privacy Policy: https://asana.com/terms#privacy-policy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Microsoft Teams: Audio and video conferencing, chat, file sharing, integration with Office 365 applications; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); Website: https://www.microsoft.com/en-ie/microsoft-teams/; Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Payment Procedures
Within the framework of contractual and other legal relationships, we offer data subjects efficient and secure payment options and, in addition to banks and credit institutions, use further service providers for this purpose (collectively “payment service providers”).
Types of data processed: Inventory data; payment data; contract data; usage data; meta, communication and procedural data.
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
American Express: Payment services; Service provider: American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany; Website: https://www.americanexpress.com/; Privacy Policy: https://www.americanexpress.com/en-us/legal/online-privacy-statement.html.
Mastercard: Payment services; Service provider: Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium; Website: https://www.mastercard.com; Privacy Policy: https://www.mastercard.com/global/en/vision/corp-responsibility/privacy.html.
PayPal: Payment services; Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Website: https://www.paypal.com; Privacy Policy: https://www.paypal.com/webapps/mpp/ua/privacy-full.
Visa: Payment services; Service provider: Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, UK; Website: https://www.visa.co.uk; Privacy Policy: https://www.visa.co.uk/legal/global-privacy-notice.html.
Credit Check
Insofar as we provide advance performance or assume comparable economic risks, we reserve the right to obtain an identity and credit report from service providers specializing in this field (credit reporting agencies).
Types of data processed: Inventory data; payment data; contact data; contract data; creditworthiness data.
Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Automated decisions in individual cases: Credit rating inquiry.
Further notes on processing operations, procedures and services:
AKV EUROPA – Alpenländischer Kreditorenverband: Credit reporting agency; Service provider: AKV EUROPA, Schleifmühlgasse 2, 1041 Vienna, Austria; Website: https://www.akv.at/; Privacy Policy: https://www.akv.at/impressum.
KSV1870 – Kreditschutzverband von 1870: Credit reporting agency; Service provider: KSV1870 Holding AG, Wagenseilgasse 7, A-1120 Vienna, Austria; Website: https://www.ksv.at/; Privacy Policy: https://www.ksv.at/datenschutzerklaerung.
Provision of the Online Offering and Web Hosting
We process user data in order to provide our online services to them.
Types of data processed: Usage data; meta, communication and procedural data; log data; content data.
Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure; security measures.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Provision of the online offering on rented storage space: For the provision of our online offering, we use storage space, computing capacity and software that we rent from a corresponding server provider; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Collection of access data and log files: Access to our online offering is logged in the form of server log files. Log file information is stored for a maximum of 30 days and then deleted or anonymized; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Email sending and hosting: The web hosting services we use also include the sending, receiving and storage of emails; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Content Delivery Network: We use a Content Delivery Network (CDN) to deliver the content of our online offering more quickly and securely; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Hetzner: Services in the field of providing information technology infrastructure; Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Website: https://www.hetzner.com; Privacy Policy: https://www.hetzner.com/legal/privacy-policy/; Data Processing Agreement: https://docs.hetzner.com/general/general-terms-and-conditions/data-privacy-faq/.
Microsoft Azure: Services in the field of providing information technology infrastructure; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Website: https://azure.microsoft.com; Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
gstatic.com: Content Delivery Network (CDN); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Privacy Policy: https://policies.google.com/privacy.
W3 Total Cache: WordPress performance and caching plugin used to optimize load times through browser caching, page caching, database caching and optional CDN integration. In the course of caching operations, technical usage data (including IP addresses, accessed URLs, browser information) is processed in server logs. W3 Total Cache itself does not transmit any personal data to the plugin developer. Processing takes place exclusively on our server and, where applicable, via connected CDN services; Service provider: Newfold Digital, Inc. (BoldGrid), 5335 Gate Pkwy, Jacksonville, FL 32256, USA; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); Website: https://www.boldgrid.com/w3-total-cache/; Privacy Policy: https://www.newfold.com/privacy-center. Basis for third-country transfers (if CDN services are integrated): EU/EEA – Standard Contractual Clauses; please review the privacy policy of the respective CDN provider used.
Use of Cookies
“Cookies” are understood to be functions that store information on users’ devices and read information from them. Cookies may serve various purposes, such as the functionality, security and convenience of online offerings, as well as the analysis of visitor flows. We use cookies in accordance with legal requirements. Where necessary, we obtain the prior consent of users.
Storage period:
Temporary cookies (session cookies): These are deleted at the latest after a user has left the online offering and closed their device.
Permanent cookies: These remain stored even after the device is closed. The storage period can be up to two years.
General information on withdrawal and objection (opt-out): Users can withdraw any consent given at any time and can also object to the processing in accordance with legal requirements, including via their browser’s privacy settings.
Types of data processed: Meta, communication and procedural data; usage data.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); consent (Art. 6(1) sentence 1 lit. a) GDPR).
Further notes on processing operations, procedures and services:
Processing of cookie data based on consent: We use a consent management solution to obtain users’ consent for the use of cookies. The consent is stored for up to two years; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR).
Cookie opt-out: In the footer of our website you will find a link through which you can change your cookie settings and withdraw any consent given.
Borlabs Cookie: Consent management platform for obtaining, documenting and managing users’ consent for the use of cookies and comparable technologies, as well as for enabling the withdrawal of consent given. As part of this process, a cookie is set on first visit to our website that stores the user’s consent status (opt-in or opt-out per category), a pseudonymous user identifier, and the timestamp of consent. This data is processed exclusively on our server and is not shared with third parties. The Borlabs cookie is stored on the user’s device for a maximum of 12 months; Service provider: borlabs GmbH, Rödingsmarkt 20, 20459 Hamburg, Germany; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR), legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); Website: https://borlabs.io; Privacy Policy: https://borlabs.io/en/privacy-policy/. Since processing takes place exclusively on our own servers in the EU, no third-country transfer occurs.
Contact and Inquiry Management
When contacting us, as well as within the framework of existing user and business relationships, the information provided by the inquiring parties is processed insofar as this is necessary to respond to the contact inquiries and any requested measures.
Types of data processed: Inventory data; contact data; content data; usage data; meta, communication and procedural data.
Data subjects: Communication partners.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR).
Further notes on processing operations, procedures and services:
Contact form: When contacting us via our contact form, email, or other means of communication, we process the personal data transmitted to us in order to respond to and process the respective request; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR), legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Communication via Messenger
We use messenger services for the purpose of communication. In the case of end-to-end encryption of content, we note that the content of communications is encrypted end-to-end and cannot be viewed even by the messenger service providers themselves.
Types of data processed: Contact data; content data; usage data; meta, communication and procedural data.
Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Apple iMessage: Sending and receiving text messages, voice messages and video calls; Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Website: https://www.apple.com/; Privacy Policy: https://www.apple.com/legal/privacy/.
Instagram: Sending messages via the social network Instagram; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.instagram.com; Privacy Policy: https://privacycenter.instagram.com/policy/.
Facebook Messenger: Sending and receiving text messages, making voice and video calls; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Microsoft Teams: Chat, audio and video conferencing, file sharing; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Website: https://www.microsoft.com/en-ie/microsoft-365; Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Artificial Intelligence (AI)
We use Artificial Intelligence (AI), whereby personal data is processed. Our AI systems are used in strict compliance with legal requirements. In doing so, we adhere in particular to the principles of lawfulness, transparency, fairness, human oversight, purpose limitation, data minimization, integrity and confidentiality.
Types of data processed: Content data; usage data.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
ChatGPT: AI-based service for processing natural language; Service provider: OpenAI Ireland Ltd, 117-126 Sheriff Street Upper, D01 YC43 Dublin 1, Ireland; Website: https://openai.com/product; Privacy Policy: https://openai.com/policies/eu-privacy-policy.
DALL-E: Generation of images from text descriptions; Service provider: OpenAI, 3180 18th St, San Francisco, CA 94110, USA; Website: https://openai.com/product; Privacy Policy: https://openai.com/policies/privacy-policy.
DeepL: Translation of texts into various languages; Service provider: DeepL SE, Maarweg 165, 50825 Cologne, Germany; Website: https://www.deepl.com; Privacy Policy: https://www.deepl.com/privacy.
Microsoft Copilot: Creation and editing of texts, tables and presentations with AI assistance; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Website: https://www.microsoft.com/en-us/microsoft-copilot/organizations; Privacy Policy: https://www.microsoft.com/en-us/privacy/privacystatement; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Midjourney: Creation of AI-generated images based on text input; Service provider: Midjourney, Inc., 795 Folsom Street, 1st Floor, San Francisco, CA 94107, USA; Website: https://www.midjourney.com/; Privacy Policy: https://docs.midjourney.com/docs/privacy-policy.
Video Conferences, Online Meetings, Webinars and Screen Sharing
We use platforms and applications from other providers (hereinafter “conferencing platforms”) for the purpose of conducting video and audio conferences, webinars and other types of video and audio meetings.
Types of data processed: Inventory data; contact data; content data; usage data; image and/or video recordings; audio recordings; log data.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Cisco WebEx: Conferencing and communication software; Service provider: Webex Communications Deutschland GmbH, Hansaallee 249, c/o Cisco Systems GmbH, 40549 Düsseldorf, Germany; Website: https://www.webex.com; Privacy Policy: https://www.cisco.com/c/en/us/about/legal/privacy-full.html; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF).
Microsoft Teams: Audio and video conferencing, chat, file sharing, optional recording; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Website: https://www.microsoft.com/en-ie/microsoft-teams/; Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
TeamViewer: Conferencing and communication software; Service provider: TeamViewer GmbH, Jahnstr. 30, 73037 Göppingen, Germany; Website: https://www.teamviewer.com; Privacy Policy: https://www.teamviewer.com/en/legal/privacy-and-cookies/.
Zoom: Video conferencing, online meetings, webinars, screen sharing, optional recording; Service provider: Zoom Video Communications, Inc., 55 Almaden Blvd., Suite 600, San Jose, CA 95113, USA; Website: https://zoom.us; Privacy Policy: https://explore.zoom.us/en/privacy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Cloud Services
We use software services accessible via the internet (cloud services) for the storage and management of content.
Types of data processed: Inventory data; contact data; content data; usage data; image and/or video recordings.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Adobe Creative Cloud: Cloud storage and cloud-based application software, including for photo editing, video editing and graphic design; Service provider: Adobe Systems Software Ireland, 4-6, Riverwalk Drive, Citywest Business Campus, Dublin 24, Ireland; Website: https://www.adobe.com/creativecloud.html; Privacy Policy: https://www.adobe.com/privacy.html; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Apple iCloud: Cloud storage service; Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Website: https://www.apple.com/; Privacy Policy: https://www.apple.com/legal/privacy/.
Microsoft Cloud Services: Cloud storage, cloud infrastructure services and cloud-based application software; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Website: https://microsoft.com; Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Newsletter and Electronic Notifications
We send newsletters, emails and other electronic notifications (hereinafter “newsletters”) exclusively with the consent of the recipients or on the basis of a legal permission.
Content: Company news, product updates, rental news, expert knowledge, industry insights, our services, promotions and offers.
Types of data processed: Inventory data; contact data; meta, communication and procedural data; usage data.
Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Opt-out option: You can cancel your subscription to our newsletter at any time. A cancellation link can be found at the end of every newsletter, or you can use one of the contact options listed above.
Further notes on processing operations, procedures and services:
Measurement of open and click rates: The newsletters contain a so-called web beacon for measuring open and click rates. This measurement is based on user consent; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR).
Mailjet: Email sending and automation services; Service provider: Mailjet SAS, 13-13 bis, rue de l’Aubrac, 75012 Paris, France; Website: https://www.mailjet.com; Privacy Policy: https://www.mailjet.com/privacy-policy/.
Web Analytics, Monitoring and Optimization
Web analytics serves to evaluate the visitor flows of our online offering and may include behavior, interests, or demographic information about visitors as pseudonymous values. With the help of reach analysis, we can determine at what times our online offering or its functions are used most frequently, or invite reuse.
Types of data processed: Usage data; meta, communication and procedural data.
Security measures: IP masking (pseudonymization of the IP address).
Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Google Analytics: We use Google Analytics to measure and analyze the use of our online offering based on a pseudonymous user identification number. Google Analytics does not log or store individual IP addresses for EU users. Event data is stored for a period of 2 months, and user-level data for a period of 14 months; upon expiry of the respective period, the data is automatically deleted; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com/about/analytics/; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses; Opt-out option: https://tools.google.com/dlpage/gaoptout.
Google Site Kit: WordPress plugin for the central integration and management of Google services on the website (including Google Analytics, Google Search Console). Site Kit establishes connections to the respective Google services and transmits usage data to Google. Data protection processing is governed by the terms of the respective integrated Google services. Data collection by Google Analytics can be prevented via the opt-out plugin; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR), legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); Website: https://sitekit.withgoogle.com/; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses; Opt-out option: https://tools.google.com/dlpage/gaoptout.
Google Search Console: We use Google Search Console to analyze the visibility of our online offering in Google Search, as well as to monitor and optimize the technical performance of our website. Google Search Console collects data on search queries through which users found our website (search terms, clicks, impressions, average position), as well as technical information on indexing and crawling activity by Google. Personal data of individual users is provided to us by Google in aggregated and anonymized form; identification of individual users is not possible for us. Use of Google Search Console requires verification of website ownership with Google; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR) — the legitimate interest lies in optimizing the discoverability and technical quality of our online offering; Website: https://search.google.com/search-console/; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms).
Matomo: Software for web analytics and reach measurement. Data collected through the use of Matomo is processed by us only and is not shared with third parties. Cookies are stored for a maximum period of 13 months; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR).
Google Tag Manager: We use Google Tag Manager, a management system that allows website tags to be implemented and managed via an interface. Google Tag Manager itself does not create cookies and does not process personal data; it triggers other tags (e.g. the Google Ads conversion tag), which may process data in turn; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); Website: https://marketingplatform.google.com/about/tag-manager/; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
Google Ads Conversion Tracking (gtag.js): We use the Google Ads conversion tag to measure the effectiveness of our Google Ads campaigns. A cookie is set when a user visits our website or reaches a defined target page, allowing us to determine whether a user arrived at our website via one of our ads and completed a desired action (conversion); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); Website: https://ads.google.com; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses; Opt-out option: https://myadcenter.google.com/personalizationoff.
Meta Pixel: We use the Meta Pixel, an analytics and remarketing tool provided by Meta Platforms. The Meta Pixel enables tracking of user activity after a click on a Meta advertisement (Facebook/Instagram) and the creation of audiences for future advertising campaigns (remarketing); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); Website: https://www.facebook.com/business/tools/meta-pixel; Privacy Policy: https://www.facebook.com/privacy/policy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
LinkedIn Insight Tag: We use the LinkedIn Insight Tag, an analytics and remarketing tool provided by LinkedIn. The Insight Tag enables conversion tracking, retargeting of website visitors, and additional insights into how LinkedIn members interact with our website; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); Website: https://business.linkedin.com/marketing-solutions/insight-tag; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses; Opt-out option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Digital Badges
Digital badges (also known as open badges) are digital certificates that verify the skills, achievements and interests of individuals or organizations. When badges are issued individually for specific individuals, the metadata stored in the badges regarding the skills, achievements and interests of the relevant individuals is processed.
Types of data processed: Inventory data; content data; usage data.
Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Presence on Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.
Types of data processed: Contact data; content data; usage data; inventory data; meta, communication and procedural data.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Instagram: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.instagram.com; Privacy Policy: https://privacycenter.instagram.com/policy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF).
Facebook Pages: Profiles within the social network Facebook – We are jointly responsible with Meta Platforms Ireland Limited for the collection of data from visitors to our Facebook page; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
LinkedIn: Social network – We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection of visitor data used to create the page insights for our LinkedIn profiles; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses; Opt-out option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Threads: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.threads.net/; Privacy Policy: https://help.instagram.com/515230437301944.
Vimeo: Social network and video platform; Service provider: Vimeo Inc., Attention: Legal Department, 555 West 18th Street, New York, New York 10011, USA; Website: https://vimeo.com; Privacy Policy: https://vimeo.com/privacy.
YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF); Opt-out option: https://myadcenter.google.com/personalizationoff.
Xing: Social network; Service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; Website: https://www.xing.com/; Privacy Policy: https://privacy.xing.com/en/privacy-policy.
Plug-ins and Embedded Functions and Content
We embed functional and content elements in our online offering that are sourced from the servers of their respective providers.
Types of data processed: Usage data; meta, communication and procedural data; location data.
Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Google Fonts (loaded from Google servers): Loading of fonts for the purpose of technically secure, maintenance-free and efficient use; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://fonts.google.com/; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF).
Google Maps: Integration of maps from the “Google Maps” service; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal bases: Consent (Art. 6(1) sentence 1 lit. a) GDPR); Website: https://mapsplatform.google.com/; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF).
Font Awesome (loaded from the provider’s server): Loading of fonts and icons; Service provider: Fonticons, Inc., 6 Porter Road Apartment 3R, Cambridge, MA 02140, USA; Website: https://fontawesome.com/; Privacy Policy: https://fontawesome.com/privacy.
Management, Organization and Auxiliary Tools
We use services, platforms and software from other providers for the purposes of organization, administration, planning and the provision of our services.
Types of data processed: Content data; usage data; meta, communication and procedural data; inventory data; contact data.
Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Asana: Project management; Service provider: Asana, Inc, 1550 Bryant Street, Suite 200, San Francisco, CA 94103, USA; Website: https://asana.com; Privacy Policy: https://asana.com/terms#privacy-policy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
calendly: Online appointment scheduling and management; Service provider: Calendly LLC., 271 17th St NW, Ste 1000, Atlanta, Georgia 30363, USA; Website: https://calendly.com; Privacy Policy: https://calendly.com/privacy; Basis for third-country transfers: EU/EEA – Standard Contractual Clauses.
Mentimeter: Creation of presentations and meetings with real-time feedback; Service provider: Mentimeter AB, Alströmergatan 22, SE-112 47 Stockholm, Sweden; Website: https://www.mentimeter.com; Privacy Policy: https://www.mentimeter.com/trust/legal/privacy-policy.
Trello: Project management tool; Service provider: Atlassian Pty Ltd, 350 Bush Street, Floor 13, San Francisco, CA 94104, USA; Website: https://trello.com/; Privacy Policy: https://trello.com/privacy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
WeTransfer: Transfer of files over the internet; Service provider: WeTransfer BV, Oostelijke Handelskade 751, Amsterdam 1019 BW, Netherlands; Website: https://wetransfer.com; Privacy Policy: https://wetransfer.com/legal/privacy.
Processing of Data in the Context of Employment Relationships
Within the framework of employment relationships, personal data is processed with the aim of effectively establishing, carrying out and terminating such relationships.
Types of data processed: Employee data; payment data; contract data; inventory data; contact data; content data; social data; log data; performance and behavioral data; working time data; salary data; image and/or video recordings; usage data; meta, communication and procedural data.
Special categories of personal data: Health data; religious or philosophical beliefs; trade union membership.
Data subjects: Employees.
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR); legal obligation (Art. 6(1) sentence 1 lit. c) GDPR); legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR); processing of special categories of personal data relating to healthcare, occupation and social security (Art. 9(2) lit. h) GDPR).
Further notes on processing operations, procedures and services:
Working time recording: Procedures for recording employees’ working hours include both manual and automated methods; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1) sentence 1 lit. b) GDPR), legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Video surveillance: Employee surveillance serves the security of the company, the protection of property, and the safety of employees. Recorded video data is deleted after a maximum of 96 hours, unless there is a specific suspected case; Legal bases: Legitimate interests (Art. 6(1) sentence 1 lit. f) GDPR).
Deletion of employee data (Austrian law): Employee data is deleted when it is no longer required for the purpose for which it was collected. The following retention periods apply: Data relating to wage tax and levy obligations (§ 132(1) BAO): 7 years. Social security: 7 years under the Commercial Code (UGB). Vacation entitlements: 2 years from the end of the vacation year. Records of workplace accidents (§ 16 ASchG): at least 5 years. Entitlement to issuance of a certificate of employment: 30 years.
Application Process
The application process requires applicants to provide us with the data necessary for their assessment and selection. Where available, applicants can submit their applications via our online form.
Deletion of data: Applicant data is deleted if an application is unsuccessful or withdrawn. Deletion takes place no later than after a period of six months.
Inclusion in an applicant pool: Inclusion in an applicant pool is based on consent. Duration of data retention in the applicant pool: 12 months.
Types of data processed: Inventory data; contact data; content data; applicant data.
Legal bases: Application procedure as a pre-contractual or contractual relationship (Art. 6(1) sentence 1 lit. b) GDPR).
Changes and Updates
We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary.
Supervisory authority responsible for us:
Austrian Data Protection Authority +43 1 52 152-0 dsb@dsb.gv.at
Definitions
Employees: Persons who are in an employment relationship, whether as staff, employees, or in similar positions.
Inventory data: Essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar assignments.
Credit rating inquiry: Automated decisions are based on automatic data processing without human involvement. Such automated decisions are only permissible under Art. 22 GDPR if data subjects consent, if they are necessary for the performance of a contract, or if national laws permit such decisions.
Content data: Information generated in the course of the creation, editing and publication of content of all kinds.
Contact data: Essential information that enables communication with individuals or organizations. This includes, among other things, telephone numbers, postal addresses and email addresses.
Artificial Intelligence (AI): The purpose of processing data through Artificial Intelligence includes the automated analysis and processing of user data in order to recognize patterns, make predictions, and improve the efficiency and quality of our services.
Meta, communication and procedural data: Categories that contain information about the manner in which data is processed, transmitted and managed.
Usage data: Information that records how users interact with digital products, services or platforms.
Personal data: All information relating to an identified or identifiable natural person.
Profiles with user-related information: Any type of automated processing of personal data that consists of using such personal data to analyze, evaluate or predict certain personal aspects.
Log data: Information about events or activities logged in a system or network.
Reach measurement: Web analytics for evaluating the visitor flows of an online offering.
Remarketing: For advertising purposes, a record is kept of which products a user has shown interest in, in order to remind them of this on other websites.
Location data: Information about the geographically determinable position of a device or a person.
Controller: The natural or legal person, authority, institution or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processing: Any operation carried out in connection with personal data, whether or not by automated means.
Contract data: Specific information relating to the formalization of an agreement between two or more parties.
Payment data: All information required for the execution of payment transactions between buyers and sellers.