Schutz. Ihrer. Daten.

— Datenschutz? Wir nehmen Datenschutz ernst! Alles, was Sie über den Schutz Ihrer Daten wissen müssen, finden Sie hier.

Privacy Policy

Introduction and overview

We have prepared this privacy policy (version 10.02.2022) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as the controller - and the processors (e.g. providers) commissioned by us - process, will process in the future and what lawful options you have. The terms used are to be understood as gender-neutral. We provide you with comprehensive information about the data we process about you. The protection of your personal data is of particular concern to us. We therefore process your data exclusively on the basis of the statutory provisions (GDPR, TKG 2003). In this data protection information, we inform you about the most important aspects of data processing on our website.

Area of application

This privacy policy applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and bill our services and products, whether online or offline. The scope of this privacy policy includes

  • all online presences (websites, online stores) that we operate
  • Social media presence and e-mail communication
  • Mobile apps for smartphones and other devices

The privacy policy applies to all areas in which personal data is processed in the company in a structured manner via the channels mentioned. If we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.

Legal basis

In the following privacy policy, we provide you with transparent information on the legal principles and regulations, i.e. the legal basis of the General Data Protection Regulation, which enable us to process personal data.

As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can of course read this EU General Data Protection Regulation online at EUR-Lex, the access point to EU law, at https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=celex32016R0679.

We only process your data if at least one of the following conditions applies:

  • Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
  • Contract (Article 6(1)(b) GDPR): In order to fulfill a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase contract with you, we need personal information in advance.
  • Legal obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for accounting purposes. These usually contain personal data.
  • Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and efficiently. This processing is therefore a legitimate interest.

Other conditions such as recording in the public interest, the exercise of official authority and the protection of vital interests do not generally apply to us. If such a legal basis is relevant, it will be indicated at the appropriate point.

In addition to the EU regulation, national laws also apply:

  • In Austria, this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), or DSG for short.
  • In Germany, the Federal Data Protection Act (BDSG) applies.

If other regional or national laws apply, we will inform you of this in the following sections.

Contact details of the person responsible

If you have any questions about data protection, you will find the contact details of the person or body responsible below:
PaiperOne GmbH
Gabriele Bolek-Fügl
Lindengasse 56, 1070 Vienna, Austria
E-mail: office@paiper.one

Imprint: https://www.paiper.one/impressum/

Contact details of the data protection officer

Below you will find the contact details of the data protection officers:
Lindengasse 56, 1070 Vienna, Austria
E-mail: office@paiper.one

Storage duration

It is a general criterion for us that we only store personal data for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for the data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.

If you wish your data to be deleted or revoke your consent to data processing, the data will be deleted as quickly as possible and insofar as there is no obligation to store it.

We will inform you below about the specific duration of the respective data processing.

Rights under the General Data Protection Regulation

According to Article 13 GDPR, you have the following rights to ensure fair and transparent processing of data

  • According to Article 15 GDPR, you have a right to information as to whether we process your data. If this is the case, you have the right to receive a copy of the data and the following information:
    the purpose for which we carry out the processing;
    • the categories, i.e. the types of data that are processed;
    • who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
    • how long the data will be stored;
    • the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
    • that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
    • the origin of the data if we have not collected it from you;
    • whether profiling is carried out, i.e. whether data is automatically analyzed in order to create a personal profile of you.
  • According to Article 16 GDPR, you have a right to rectification of data, which means that we must correct data if you find errors.
  • According to Article 17 GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you may request the erasure of your data.
  • According to Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it any further.
  • According to Article 19 GDPR, you have the right to data portability, which means that we will provide you with your data in a commonly used format upon request.
  • According to Article 21 GDPR, you have the right to object, which will result in a change in the processing after enforcement.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally comply with this objection.
    • If data is used for direct marketing purposes, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
    • If data is used for profiling purposes, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
  • Under Article 22 GDPR, you may have the right not to be subject to a decision based solely on automated processing (e.g. profiling).

If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. For Austria, this is the data protection authority, whose website you can find at https://www.dsb.gv.at/ find. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:

Austria Data Protection Authority
Head: Dr. Andrea Jelinek
Address: Barichgasse 40-42, 1030 Vienna
Telephone no.: +43 1 52 152-0
E-mail address: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/

Data transfer to third countries

We only transfer or process data to countries outside the EU (third countries) if you consent to this processing, if this is required by law or contract and in any case only to the extent that this is generally permitted. In most cases, your consent is the most important reason for us to process data in third countries. The processing of personal data in third countries such as the USA, where many software manufacturers offer services and have their server locations, may mean that personal data is processed and stored in unexpected ways.

We expressly point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. Data processing by US services (such as Google Analytics) may result in data not being processed and stored anonymously. Furthermore, US government authorities may be able to access individual data. In addition, data collected may be linked to data from other services of the same provider if you have a corresponding user account. Where possible, we try to use server locations within the EU if this is offered.

We will inform you in more detail about data transfer to third countries, if applicable, in the appropriate sections of this privacy policy.

Security of data processing

In order to protect personal data, we have implemented both technical and organizational measures. Where possible, we encrypt or pseudonymize personal data. In this way, we make it as difficult as possible for third parties to infer personal information from our data.

Art. 25 GDPR speaks here of "data protection by design and by default" and thus means that both software (e.g. forms) and hardware (e.g. access to the server room) should always be designed with security in mind and appropriate measures should be taken. If necessary, we will discuss specific measures below.

TLS encryption with https

We use HTTPS (the Hypertext Transfer Protocol Secure stands for "secure hypertext transfer protocol") to transmit data tap-proof on the Internet.

This means that the complete transmission of all data from your browser to our web server is secured - nobody can "eavesdrop". We have thus introduced an additional layer of security and fulfill data protection through technology design (Article 25 (1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the Internet, we can ensure the protection of confidential data. You can recognize the use of this data transmission security by the small lock symbol at the top left of the browser, to the left of the Internet address (e.g. examplepage.com) and the use of the https scheme (instead of http) as part of our Internet address.

If you want to know more about encryption, we recommend a Google search for "Hypertext Transfer Protocol Secure wiki" to get good links to further information.

HubSpot

We use HubSpot, a digital marketing tool, on our website. The service provider is the American company HubSpot, Inc, 25 First St 2nd Floor Cambridge, MA, USA. The company also has a registered office in Ireland at 1 Sir John Rogerson's Quay, Dublin 2, Ireland.

HubSpot also processes your data in the USA, among other places. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. This may entail various risks for the legality and security of data processing.

HubSpot uses so-called standard contractual clauses (= Art. 46. para. 2 and 3 GDPR) as the basis for data processing with recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or data transfer to these countries. Standard Contractual Clauses (SCCs) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to and stored in third countries (such as the USA). Through these clauses, HubSpot undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Data Processing Agreement, which corresponds to the standard contractual clauses, can be found at https://legal.hubspot.com/dpa.

You can find out more about the data processed through the use of HubSpot in the Privacy Policy on https://legal.hubspot.com/de/privacy-policy.

Data processing agreement (DPA) HubSpot

We have concluded a data processing agreement (DPA) with HubSpot in accordance with Article 28 of the General Data Protection Regulation (GDPR). You can find out exactly what a DPA is and, above all, what must be included in a DPA in our general section "Data processing agreement (DPA)".

This contract is required by law because HubSpot processes personal data on our behalf. It clarifies that HubSpot may only process data that it receives from us in accordance with our instructions and must comply with the GDPR. You can find the link to the data processing agreement (DPA) at https://legal.hubspot.com/dpa.

LinkedIn Insight Tag

We use the conversion tracking tool LinkedIn Insight Tag on our website. The service provider is the American company LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. LinkedIn Ireland Unlimited (Wilton Place, Dublin 2, Ireland) is responsible for data protection aspects in the European Economic Area (EEA), the EU and Switzerland.

LinkedIn also processes your data in the USA, among other places. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. This may entail various risks for the legality and security of data processing.

LinkedIn uses so-called standard contractual clauses (= Art. 46. para. 2 and 3 GDPR) as the basis for data processing with recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or data transfer to these countries. Standard Contractual Clauses (SCCs) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to and stored in third countries (such as the USA). Through these clauses, LinkedIn undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

You can find more information on the standard contractual clauses at LinkedIn at https://de.linkedin.com/legal/l/dpa or https://www.linkedin.com/legal/l/eu-sccs

You can find out more about LinkedIn Insight Tag at https://www.linkedin.com/help/linkedin/answer/a427660. You can also find out more about the data processed through the use of LinkedIn Insight Tag in the privacy policy on https://de.linkedin.com/legal/privacy-policy

Your rights

In principle, you have the rights to information, correction, deletion, restriction, data portability, revocation and objection. If you believe that the processing of your data violates data protection law or your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. In Austria, this is the data protection authority.

Phone: +43 677 61935707
E-mail: office@paiper.one

Cookie Directive (EU) | paiper.one

We love our cookies

EN