Privacy Statement
PRIVACY STATEMENT / INFORMATION OBLIGATION
It is particularly important to us to protect your data, which is why we comply with the applicable data protection regulations, in particular the GDPR and the DSG, when processing your personal data (e.g. master data).
Below you will find more detailed information about the data processing we carry out:
1. Responsible
U-Grow Gmbh
Kolpingstrasse 8, 4600 Wels
office@u-grow.com
Owner: Ing. Korayem Razik, MBA
As we are not legally obliged to do so, we have not appointed a data protection officer/notified the data protection authority.
2. rights of data subjects/right of objection and revocation/right of appeal
2.1. You have the following rights vis-à-vis us with regard to the personal data concerning you:
- Right of access (Art 15 GDPR),
- Right to rectification (Art 16 GDPR) or erasure (Art 17 GDPR)
- Restriction of processing (Art 18 GDPR),
- Right to data portability (Art 20 GDPR),
- Right to object to processing (Art 21 GDPR).
Right to object: If the processing of your personal data is based on a balancing of interests (Art. 6 para. 1 lit. f GDPR: legitimate interests), you have the right to object to the processing at any time for reasons arising from your particular situation. When exercising your right to object, we ask you to explain your reasons why we should not process your personal data as we have done. We will examine the situation and either discontinue or adapt the data processing or show you our compelling reasons worthy of protection and continue the data processing. We will also continue the data processing if it serves the assertion, exercise or defense of legal claims.
You can object to data processing for the purposes of direct advertising and data analysis at any time. In this case, we will stop processing the data.
Right of withdrawal: If you have given us your consent to process your personal data, you can also withdraw your consent at any time. Your revocation does not affect the legality of the data processing carried out until the revocation.
To exercise these rights, you must inform us in person, by telephone or in writing:
U-Grow Gmbh
Kolpingstrasse 8, 4600 Wels
office@u-grow.com
+43 664 4701812
Owner: Ing. Korayem Razik, MBA
Please note that we can only provide you with information if you can identify yourself.
2.2. If you are of the opinion that the data processing violates applicable data protection law or that we violate your data protection claims, you also have the right to lodge a complaint with the supervisory authority in the member state of your place of residence, your place of work or the place of the alleged violation.
If you wish to lodge your complaint with the supervisory authority in Austria, please address it to:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
3. Information about the processing of your personal data
3.1. Website visit
- Purpose: If our website is only used for information purposes (no registration and no transmission of other information), personal data is collected which is transmitted from your browser to our server. This is technically necessary in order to display our website to you and to ensure the stability and security of the website.
- Legal basis: legitimate interest (Art. 6 para. 1 lit. f GDPR), § 96 para. 3 TKG 2003
- The following data is processed: IP address, date and time of the request, time zone difference to GMT, content of the request (specific page), access status/HTTP status code, amount of data transferred in each case, requesting website, browser, operating system and interface, language and version of the browser software.
- Storage duration: As long as you use our website.
- Recipients/recipient categories: Processor
3.2. Electronic contact requests via the website
- Purpose: Processing of contact requests via email or the website contact form.
- Legal basis: Performance of a contract, necessary for the implementation of pre-contractual measures (Art. 6 para. 1 lit. b GDPR), legitimate interest (Art. 6 para. 1 lit. f GDPR), § 96 para. 3 TKG 2003.
- The following data is processed: Master data, content data of the request.
- Storage period: Until the request is answered. If statutory retention obligations exist, processing will be restricted until then.
- Recipients/recipient categories: Processor
3.3. Cookies/web analysis service
- Purpose: Improvement of the range of services, website and direct advertising.
- Legal basis: Consent (Article 6(1)(a) GDPR), legitimate interest, in particular to improve our own services for the benefit of users (Article 6(1)(f) GDPR), explicit consent (Article 49(1)(a) GDPR), necessary for the purposes of the legitimate interests pursued by the data subject (Article 49(1)(c) GDPR)
- Recipients/recipient categories: Company of the analysis service/service provider
Heading #1 | Heading #2 | Heading #3 |
---|---|---|
Simple content | Simple content | Simple content |
3.3.1 Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”), if you are a resident of the European Union, the European Economic Area and Switzerland, Google Ireland Limited (registration number: 368047), Gordon House, Barrow Street, Dublin 4, Ireland. This service uses “cookies” to analyze the use of the website.
We use the analysis of user behavior to optimize both our website and our advertising. We have activated the IP anonymization function on this website. This means that your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. A transfer of the collected information to a third country without an adequate level of security cannot be ruled out.
With your express consent to the processing of cookies, you also consent to the possible processing of your data in the USA.
The information may also be passed on to Google’s contractual partners. You can find more information on the handling of user data in Google’s privacy policy: https://www.google.de/intl/de/policies/privacy/.
Storage period: see cookie list
Contract data processing: We have concluded a contract with Google for contract data processing.
3.3.2 Facebook-Pixel
We use “Facebook Pixel” from Facebook Inc, 1 Hacker Way, Menlo Park, CA 94025, USA, or for residents of the European Union, the European Economic Area and Switzerland, Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”).
When you visit our pages, a direct connection is established between your browser and the Facebook server via the Facebook pixel. Facebook receives the information that you have visited our site with your IP address. This allows Facebook to associate your visit to our pages with your user account. We can use the information obtained in this way to display Facebook ads or for tracking functions. The data collected is anonymous to us as the operator. A transfer of the collected information to a third country without an adequate level of security cannot be ruled out.
Storage duration: see cookie list
Further information on this can be found in Facebook’s privacy policy at https://www.facebook.com/about/privacy/
If you do not wish data to be collected via Custom Audience, you can deactivate it here https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen You must first log in to Facebook. If you do not have a Facebook account, you can suppress usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance:: https://www.youronlinechoices.com/ie/your-ad-choices
3.4. Social Media
In addition to our website, we also maintain presences on social networks, in particular Facebook, Instagram, LinkedIn and YouTube, to increase awareness of our company and for marketing purposes. When you visit one of our presences, personal data may be transmitted to the operator of the social network. In addition, the operator may link your profile to ours if you are logged into the respective network.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR), legitimate interest (Art. 6 para. 1 lit. f GDPR), explicit consent (Art. 49 para. 1 lit. a GDPR).
Recipients/recipient categories: Processor
Details on the specific data collection and processing by the respective operator can be found in the following links:
Facebook: https://de-de.facebook.com/about/privacy/
Instagram: https://help.instagram.com/155833707900388
LinkedIn: https://www.linkedin.com/legal/privacy-policy?_l=de_DE
Youtube: https://www.youtube.com/static?gl=DE&template=terms&hl=de und https://policies.google.com/privacy.
A transfer of the collected information to a third country without an adequate level of security cannot be ruled out.
3.5. Message service
For the purpose of operating a message service on this website, which is used to respond to inquiries, the user name and message content you provide are collected as data and stored for the course of the chat.
In addition to the IP address, information about the time the message was created is also stored.
Legal basis: Consent (Art 6 para 1 lit a GDPR), legitimate interest, in particular to improve our own services for the benefit of users (Art 6 para 1 lit f GDPR), § 96 para 3 TKG 2003, express consent (Art 49 para 1 lit a GDPR).
A transfer of the collected information to a third country without an adequate level of security cannot be ruled out.
Details on the specific data collection and processing by the respective operator can be found in the following links
Calendly: https://calendly.com/pages/privacy
Chatra: https://chatra.com/terms-of-service/
3.6. Live chat system
Purpose: We use the Zoom video conferencing tool from the American software company Zoom Video Communications for our website. The company is headquartered in San Jose, California, 55 Almaden Boulevard, 6th Floor, CA 95113. With the “Zoom Meetings” service, we can easily hold an online video conference with customers, business partners, clients and employees without installing any software. This makes it very easy for us to get in touch digitally, discuss various topics, send text messages or even make phone calls. Zoom can also be used to share the screen, exchange files and use a whiteboard.
Zoom automatically saves technical data from your browser or your IP address. If you enter data such as your name, your user name, your e-mail address or your telephone number, this data will be stored by Zoom. Content that you upload while using Zoom is also stored. This includes, for example, files or chat logs. A transfer of the collected information to a third country without an adequate level of security cannot be ruled out.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR), legitimate interest, in particular to improve our own services for the benefit of users (Art. 6 para. 1 lit. f GDPR), express consent (Art. 49 para. 1 lit. a GDPR).
Storage period: The data collected is stored for as long as is necessary to provide the services or for our own purposes. The data will only be stored for longer if this is required for legal reasons.
3.7. reCAPTCHA
On this website, we use the reCAPTCHA function of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). This function is primarily used to differentiate whether an entry is made by a natural person or abusively by machine and automated processing. reCATPCHA serves the security of our website and subsequently also your security. The service includes the sending of the IP address and any other data required by Google for the reCAPTCHA service to Google and is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in determining individual responsibility on the Internet and avoiding abuse and spam. When using Google reCAPTCHA, personal data may also be transmitted to the servers of Google LLC. in the USA without an adequate level of security.
Further information on Google reCAPTCHA and Google’s privacy policy can be found at: https://www.google.com/intl/de/policies/privacy/
3.8. E-commerce store, customer management, accounting, logistics and bookkeeping
§ Purpose: Processing of personal data in the context of any business relationship with customers and suppliers as part of a business activity, including systematic recording of all business transactions relating to income and expenditure.
§ Legal basis: Consent (Art 6 para 1 lit a GDPR), performance of a contract, necessary for the implementation of pre-contractual measures (Art 6 para 1 lit b GDPR), compliance with a legal obligation (Art 6 para 1 lit c GDPR), legitimate interest, in particular defense, exercise and assertion of legal claims (Art 6 para 1 lit f GDPR), explicit consent (Art 9 para 2 lit a GDPR), § Section 96 (3) TKG 2003, express consent (Art 49 (1) (a) GDPR), performance of a contract, necessary for the implementation of pre-contractual measures (Art 49 (1) (b) GDPR), necessary for the performance of an interest of the data subject (Art 49 (1) (c) GDPR), assertion, exercise and defense of legal claims (Art 49 (1) (e) GDPR).
§ The following data is processed for the e-commerce store via our website Master data, nationality, date of birth, passport number.
§ Storage period: Until the end of the business relationship or until the expiry of the guarantee, warranty, limitation and statutory retention periods applicable to the client (in particular BAO); in addition, until the end of any legal disputes in which the data is required as evidence.
§ Recipients/recipient categories: Tax office, courts and authorities, suppliers, debt collection agencies for debt recovery, banks involved in payment to the data subject or to third parties, legal representatives, chartered accountants, payroll accountants, hotels/accommodation, airlines.
The provision of your personal data is necessary for the fulfillment of the contract or the implementation of pre-contractual measures. Without this data, we cannot conclude a contract with you.
3.8.1 Payment methods
3.8.1.1 PayPal
PayPal is an online payment service provider. Payments are processed via so-called PayPal accounts, which are virtual private or business accounts. PayPal also offers the option of processing virtual payments via credit cards if a user does not have a PayPal account. A PayPal account is managed via an e-mail address, which is why there is no classic account number. PayPal makes it possible to initiate online payments to third parties or to receive payments. PayPal also acts as a trustee and offers buyer protection services.
The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR), fulfillment of a contract, necessary for the implementation of pre-contractual measures (Art. 6 para. 1 lit. b GDPR).
Further information on the online payment service provider can be found here: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
3.8.1.2 Klarna
The use of the payment methods invoice, installment purchase and direct debit requires a positive credit check. In this respect, we forward your data to Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm Sweden, for the purpose of address and credit checks as part of the purchase initiation and processing of the purchase contract.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR), fulfillment of a contract, necessary for the implementation of pre-contractual measures (Art. 6 para. 1 lit. b GDPR).
Further information on the payment provider can be found here: https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/privacy.
3.9. Customer care and marketing for own purposes
§ Purpose: Processing of own or purchased customer and prospective customer data for the initiation of business relating to our own range of products or services and for the implementation of advertising measures and newsletter distribution; customer relationship management.
§ Legal basis: Consent (Art 6 para 1 lit a GDPR), performance of a contract, necessary for the implementation of pre-contractual measures (Art 6 para 1 lit b GDPR), compliance with a legal obligation (Art 6 para 1 lit c GDPR), legitimate interest, in particular defense, exercise and assertion of legal claims (Art 6 para 1 lit f GDPR), explicit consent (Art 49 para 1 lit a GDPR).
§ The following data is processed for sending the newsletter via our website Master data
§ Storage period: The data may be stored until the end of the third year after the last contact with the client, unless longer contractual or statutory retention periods exist. When sending newsletters until revocation.
§ Recipients/recipient categories: Company of the analysis service/service provider
3.9.1 MailChimp
We use the services of the newsletter company MailChimp on our website. MailChimp is operated by The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USA. MailChimp makes it very easy for us to send you interesting news by newsletter and stay in contact with you.
Sometimes it may happen that you open our newsletter via a specified link for better presentation. This is the case, for example, if your e-mail program does not work or the newsletter is not displayed correctly. The newsletter will then be displayed via a MailChimp website.
Details about the specific data collection and processing by the operator can be found in the following link:https://mailchimp.com/legal/cookies/.
MailChimp is an American company and all data collected is stored on American servers with an inadequate level of security.
In principle, the data remains permanently stored on Mailchimp’s servers and is only deleted if you request this. You can have your contact deleted by us. This will permanently remove all your personal data for us and anonymize you in the Mailchimp reports.
3.10. Applicant management
§ Purpose: Use and record-keeping of personal data provided by applicants, if this data was provided by the data subject.
§ Legal basis: Consent (Art 6 para 1 lit a GDPR), explicit consent (Art 9 para 2 lit a GDPR) as well as assertion, exercise and defense of legal claims (Art 9 para 2 lit f GDPR) and legitimate interest (Art 10 GDPR in conjunction with § 4 para 3 Z 2 DSG).
§ Storage period: Applicant data will be deleted immediately after the advertised position has been filled or after expiry of the claim period under the Equal Treatment Act (7 months), unless consent has been given to keep records. Unsolicited applications will be kept on file for the intended purpose until revoked by the person concerned.
§ Recipients/recipient categories: Applicant data will not be passed on.
4. information on data transfers to third countries or international organizations
Note on data processing in the USA:
According to the case law of the ECJ (judgment of 16.07.2020, Ref: C-311/18 (“Schrems II”), there is not a sufficient level of security in the USA. There may be government surveillance measures in the USA for which no legal protection against these measures can be claimed.
5. Amendment of this privacy policy
We reserve the right to amend this Privacy Policy at any time in compliance with the applicable data protection regulations.
Current status: September 2020