Privacy statement

Responsibility

Primas CONSULTING GmbH
Management
Dr. Günter Rattay
Mag. Anton Lorenz

primas@primas.at
UID: ATU 41678902
Company register: 148557t at Kreisgericht Korneuburg
Head quarter
Börseplatz 6/28
A-1010 Vienna
Tel.: +43-1-533 23 34
Fax: +43-1-533 23 34-99
No data protection officer has been appointed, as this is not required by law.

Privacy Policy

We have written this privacy policy (version 17.02.2021-111643845) to provide you with information in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 as well as to explain what information we collect, how we use data and what choices you have as a visitor to this website.

Privacy policies usually sound very technical. However, this version should describe the most important things as simply and clearly as possible. Moreover, technical terms are explained in a reader-friendly manner whenever possible. We would also like to convey that we only collect and use information via this website if there is a corresponding legal basis for it. This is certainly not possible if you give very brief technical explanations, as are often standard on the Internet when it comes to data protection. We hope you find the following explanations interesting and informative. Maybe you will also find some information that you did not know yet.
Should you still have questions, we kindly ask you to follow the existing links to see further information on third-party websites, or to simply write us an email. You can find our contact information in our website’s imprint.

Cookies

Our website uses HTTP-cookies to store user-specific data.
For your better understanding of the following Privacy Policy statement, we will explain to you below what cookies are and why they are in use.

What exactly are cookies?

Every time you surf the internet, you use a browser. Common browsers are for example Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text-files in your browser. These files are called cookies.

What should not be dismissed, is that cookies are very useful little helpers. Nearly all websites use cookies. More accurately speaking these are HTTP-cookies, since there are also different cookies for other uses. http-cookies are small files which our website stores on your computer. These cookie files are automatically put into the cookie-folder, which is like the “brain” of your browser. A cookie consists of a name and a value. Moreover, to define a cookie, one or multiple attributes must be specified.

Cookies save certain parts of your user data, such as e.g. language or personal page settings. When you re-open our website, your browser submits these “user specific” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are familiar to. In some browsers every cookie has its own file, in others such as Firefox, all cookies are stored in one single file.

There are both first-party cookies and third-party coookies. First-party cookies are created directly by our site, while third-party cookies are created by partner-websites (e.g. Google Analytics). Every cookie is individual, since every cookie stores different data. The expiration time of a cookie also varies – it can be a few minutes, or up to a few years. Cookies are no software-programs and contain no computer viruses, trojans or any other malware. Cookies also cannot access your PC’s information.

This is an example of how cookie-files can look:

name: _ga
value: GA1.2.1326744211.152111643845-9
purpose: differentiation between website visitors
expiration date: after 2 years

A browser should support these minimum sizes:

  • at least 4096 bytes per cookie
  • at least 50 cookies per domain
  • at least 3000 cookies in total

Which types of cookies are there?

What exact cookies we use, depends on the used services. We will explain this in the following sections of the Privacy Policy statement. Firstly, we will briefly focus on the different types of HTTP-cookies.

There are 4 different types of cookies:

Essential Cookies
These cookies are necessary to ensure the basic function of a website. They are needed when a user for example puts a product into their shopping cart, then continues surfing on different websites and comes back later in order to proceed to the checkout. Even when the user closed their window priorly, these cookies ensure that the shopping cart does not get deleted.

Purposive Cookies
These cookies collect info about the user behaviour and record if the user potentially receives any error messages. Furthermore, these cookies record the website’s loading time as well as its behaviour within different browsers.

Target-orientated Cookies
These cookies care for an improved user-friendliness. Thus, information such as previously entered locations, fonts or data in forms stay saved.

Advertising Cookies
These cookies are also known as targeting-Cookies. They serve the purpose of delivering individually adapted advertisements to the user. This can be very practical, but also rather annoying.

Upon your first visit to a website you are usually asked which of these cookie-types you want to accept. Furthermore, this decision will of course also be saved in a cookie.

How can I delete cookies?

You yourself take the decision if and how you want to use cookies. Thus, no matter what service or website cookies are from, you always have the option to delete, deactivate or only partially allow them. Therefore, you can for example block cookies of third parties but allow any other cookies.

If you want change or delete cookie-settings and would like to determine which cookies have been saved to your browser, you can find this info in your browser-settings:

Chrome: Clear, enable and manage cookies in Chrome

Safari: Manage cookies and website data in Safari

Firefox: Clear cookies and site data in Firefox

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete cookies in Microsoft Edge

If you generally do not want to allow any cookies at all, you can set up your browser in a way, to notify you whenever a potential cookie is about to be set. This gives you the opportunity to manually decide to either permit or deny the placement of every single cookie. The settings for this differ from browser to browser. Therefore, it might be best for you to search for the instructions in Google. If you are using Chrome, you could for example put the search phrase “delete cookies Chrome” or “deactivate cookies Chrome” into Google.

How is my data protected?

There is a “cookie policy” that has been in place since 2009. It states that the storage of cookies requires the user’s consent. However, among the countries of the EU, these guidelines are often met with mixed reactions. In Austria the guidelines have been implemented in § 96 section 3 of the Telecommunications Act (TKG).

If you want to learn more about cookies and do not mind technical documentation, we recommend https://tools.ietf.org/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism”.

Storage of Personal Data

Any personal data you electronically submit to us on this website, such as your name, email address, home address or other personal information you provide via the transmission of a form or via any comments to the blog, are solely used for the specified purpose and get stored securely along with the respective submission times and IP-address. These data do not get passed on to third parties.

Therefore, we use personal data for the communication with only those users, who have explicitly requested being contacted, as well as for the execution of the services and products offered on this website. We do not pass your personal data to others without your approval, but we cannot exclude the possibility this data will be looked at in case of illegal conduct.

If you send us personal data via email – and thus not via this website – we cannot guarantee any safe transmission or protection of your data. We recommend you, to never send confidential data via email.

Business-related processing

On our platform, possibilities are made available to make inquiries or orders. Among these areas are contact enquiries, the online shop, the newsletter and seminar registration.

During this process the entered data will be processed. This data includes:

  • Name/s (title, first name, last name)
  • Email address(es)
  • Company
  • Contact details (street, postcode, city, country, telephone number, fax number)
  • Notes relevant to the area (number of course places, comments, notes)

In addition, the following data will also be stored by us for the purpose of processing the contract:

  • Customer contract data (for example, contract object, validity period, customer category)
  • Payment transactions / order data
  • Other remarks

The data provided by you is necessary for the fulfilment of the contract or for the execution of pre-contractual measures. We cannot conclude a contract with you without this data. A data transfer to third parties does not take place, with the exception of the transfer of credit card data / bank data to the processing bank institutes / payment service providers for the purpose of debiting the purchase price, to the transport company / shipping company commissioned by us to deliver the goods and to our tax consultant to fulfill our tax obligations.

All accounting-relevant data will be stored for 7 years in accordance with the legal obligation pursuant to Art. 6c DSGVO and for as long as there are legal obligations for this. Data to support organizational processing (e.g. protocols) will be stored for 7 years in accordance with Art. 6f DSGVO, analogous to the accounting documents, due to a justified interest. All other data will be stored for a maximum of 10 years.

In cases where there is a legitimate interest in longer storage, we reserve the right to retain data for the duration of the statutory limitation period of 30 years. A justified interest exists in particular if the storage of the data is necessary to defend against claims which expire after a period of 30 years. The same applies to possible own claims which become statute-barred within the 30-year limitation period (e.g. claims for damages for hidden defects, statutory enrichment claims…).

After expiry of this period, the data will be deleted or anonymized to the extent that a personal conclusion is no longer possible.

The data name, address, purchased goods and date of purchase are stored beyond that going up to the expiration of the product liability (10 years).  Data processing is carried out on the basis of the legal provisions of § 96 Para. 3 TKG and Art. 6 Para. 1 lit a (consent) and/or lit b (necessary for the fulfilment of the contract) of the DSGVO.

Rights in accordance with the General Data Protection Regulation

You are granted the following rights in accordance with the provisions of the GDPR (General Data Protection Regulation) and the Austrian Data Protection Act (DSG):

  • right to rectification (article 16 GDPR)
  • right to erasure (“right to be forgotten“) (article 17 GDPR)
  • right to restrict processing (article 18 GDPR)
  • righ to notification – notification obligation regarding rectification or erasure of personal data or restriction of processing (article 19 GDPR)
  • right to data portability (article 20 GDPR)
  • Right to object (article 21 GDPR)
  • right not to be subject to a decision based solely on automated processing – including profiling – (article 22 GDPR)

If you think that the processing of your data violates the data protection law, or that your data protection rights have been infringed in any other way, you can lodge a complaint with your respective regulatory authority. For Austria this is the data protection authority, whose website you can access at https://www.data-protection-authority.gv.at/.

Evaluation of Visitor Behaviour

In the following Privacy Policy, we will inform you on if and how we evaluate the data of your visit to this website. The evaluation is generally made anonymously, and we cannot link to you personally based on your behaviour on this website.

You can find out more about how to disagree with the evaluation of visitor data, in the Privacy Policy below.

TLS encryption with https

We use https to transfer information on the internet in a tap-proof manner (data protection through technology design Article 25 Section 1 GDPR). With the use of TLS (Transport Layer Security), which is an encryption protocol for safe data transfer on the internet, we can ensure the protection of confidential information. You can recognise the use of this safeguarding tool by the little lock-symbol, which is situated in your browser’s top left corner, as well as by the use of the letters https (instead of http) as a part of our web address.

Google Analytics Privacy Policy

We use the tracking and analysis tool Google Analytics (GA) of the US-American company Google LLC (1600 Amphitheatre Parkway Mountain View, CA 94043, USA). Google Analytics collects data on your actions on our website. Whenever you click a link for example, this action is saved in a cookie and transferred to Google Analytics. With the help of reports which we receive from Google Analytics, we can adapt our website and our services better to your wishes. In the following, we will explain the tracking tool in more detail, and most of all, we will inform you what data is saved and how you can prevent this.

What is Google Analytics?

Google Analytics is a tracking tool with the purpose of conducting data traffic analysis of our website. For Google Analytics to work, there is a tracking code integrated to our website. Upon your visit to our website, this code records various actions you perform on your website. As soon as you leave our website, this data is sent to the Google Analytics server, where it is stored.

Google processes this data and we then receive reports on your user behaviour. These reports can be one of the following:

  • Target audience reports: With the help of target audience reports we can get to know our users better and can therefore better understand who is interested in our service.
  • Advertising reports: Through advertising reports we can analyse our online advertising better and hence improve it.
  • Acquisition reports: Acquisition reports provide us helpful information on how we can get more people enthusiastic about our service.
  • Behaviour reports: With these reports, we can find out how you interact with our website. By the means of behaviour reports, we can understand what path you go on our website and what links you click.
  • Conversion reports: A conversion is the process of leading you to carry out a desired action due to a marketing message. An example of this would be transforming you from a mere website visitor into a buyer or a newsletter subscriber. Hence, with the help of these reports we can see in more detail, if our marketing measures are successful with you. Our aim is to increase our conversion rate.
  • Real time reports: With the help of these reports we can see in real time, what happens on our website. It makes us for example see, we can see how many users are reading this text right now.

Why do we use Google Analytics on our website?

The objective of our website is clear: We want to offer you the best possible service. Google Analytics’ statistics and data help us with reaching this goal.

Statistically evaluated data give us a clear picture of the strengths and weaknesses of our website. On the one hand, we can optimise our page in a way, that makes it easier to be found by interested people on Google. On the other hand, the data helps us to get a better understanding of you as our visitor. Therefore, we can very accurately find out what we must improve on our website, in order to offer you the best possible service. The analysis of that data also enables us to carry out our advertising and marketing measures in a more individual and more cost-effective way. After all, it only makes sense to show our products and services exclusively to people who are interested in them.

What data gets stored by Google Analytics?

With the aid of a tracking code, Google Analytics creates a random, unique ID which is connected to your browser cookie. That way, Google Analytics recognises you as a new user. The next time you visit our site, you will be recognised as a “recurring” user. All data that is collected gets saved together with this very user ID. Only this is how it is made possible for us to evaluate and analyse pseudonymous user profiles.

Your interactions on our website are measures by tags such as cookies and app instance IDs. Interactions are all kinds of actions that you perform on our website. If you are also using other Google systems (such as a Google Account), data generated by Google Analytics can be linked with third-party cookies. Google does not pass on any Google Analytics data, unless we as the website owners authorise it. In case it is required by law, exceptions can occur.

The following cookies are used by Google Analytics:

Name: _ga
Value:2.1326744211.152111643845-5
Purpose: By deafault, analytics.js uses the cookie _ga, to save the user ID. It generally serves the purpose of differenciating between website visitors.
Expiration date: After 2 years

Name: _gid
Value:2.1687193234.152111643845-1
Purpose: This cookie also serves the purpose of differentiating between website users
Expiration date: After 24 hours

Name: _gat_gtag_UA_
Value: 1
Verwendungszweck: It is used for decreasing the demand rate. If Google Analytics is provided via Google Tag Manager, this cookie gets the name _dc_gtm_ .
Expiration date: After 1 minute

Name: AMP_TOKEN
Value: No information
Purpose: This cookie has a token which is used to retrieve the user ID by the AMP Client ID Service. Other possible values suggest a logoff, a request or an error.
Expiration date: After 30 seconds up to one year

Name: __utma
Value:1564498958.1564498958.1564498958.1
Purpose: With this cookie your behaviour on the website can be tracked and the site performance can be measured. The cookie is updated every time the information is sent to Google Analytics.
Expiration date: After 2 years

Name: __utmt
Value: 1
Purpose: Just like _gat_gtag_UA_ this cookie is used for keeping the requirement rate in check.
Expiration date: Afer 10 minutes

Name: __utmb
Value:3.10.1564498958
Purpose: This cookie is used to determine new sessions. It is updated every time new data or information gets sent to Google Analytics.
Expiration date: After 30 minutes

Name: __utmc
Value: 167421564
Purpose: This cookie is used to determine new sessions for recurring visitors. It is therefore a session cookie, and only stays saved until you close the browser again.
Expiration date: After closing the browser

Name: __utmz
Value: m|utmccn=(referral)|utmcmd=referral|utmcct=/
Purpose: This cookie is used to identify the source of our website’s visitor number. This means, that the cookie saves information on where you came to our website from. This could be another site or an advertisement.
Expiration date: After 6 months

Name: __utmv
Value: No information
Purpose: The cookie is used to store custom user data. It gets updated whenever information is sent to Google Analytics.
Expiration date: After 2 years

Note: This list is by no means exhaustive, since Google are repeatedly changing the use of their cookies.

Below we will give you an overview of the most important data that can be evaluated by Google Analytics:

Heatmaps: Google creates so-called Heatmaps an. These Heatmaps make it possible to see the exact areas you click on, so we can get information on what routes you make on our website.

Session duration: Google calls the time you spend on our website without leaving it session duration. Whenever you are inactive for 20 minutes, the session ends automatically.

Bounce rate If you only look at one page of our website and then leave our website again, it is called a bounce.

Account creation: If you create an account or make an order on our website, Google Analytics collects this data.

IP-Address: The IP address is only shown in a shortened form, to make it impossible to clearly allocate it.

Location: Your approximate location and the country you are in can be defined by the IP address. This process is called IP location determination.

Technical information: Information about your browser type, your internet provider and your screen resolution are called technical information.

Source: Both, Google Analytics as well as ourselves, are interested what website or what advertisement led you to our site.

Further possibly stored data includes contact data, potential reviews, playing media (e.g. when you play a video on our site), sharing of contents via social media or adding our site to your favourites. This list is not exhaustive and only serves as general guidance on Google Analytics’ data retention.

How long and where is the data saved?

Google has servers across the globe. Most of them are in America and therefore your data is mainly saved on American servers. Here you can read detailed information on where Google’s data centres are located: https://www.google.com/about/datacenters/inside/locations/?hl=en

Your data is allocated to various physical data mediums. This has the advantage of allowing to retrieve the data faster, and of protecting it better from manipulation. Every Google data centre has respective emergency programs for your data. Hence, in case of a hardware failure at Google or a server error due to natural disasters, the risk for a service interruption stays relatively low.

Google Analytics has a 26 months standardised period of retaining your user data. After this time, your user data is deleted. However, we have the possibility to choose the retention period of user data ourselves. There are the following five options:

  • Deletion after 14 months
  • Deletion after 26 months
  • Deletion after 38 months
  • Deletion after 50 months
  • No automatical deletion

As soon as the chosen period is expired, the data is deleted once a month. This retention period applies to any of your data which is linked to cookies, user identification and advertisement IDs (e.g. cookies of the DoubleClick domain). Any report results are based on aggregated information and are stored independently of any user data. Aggregated information is a merge of individual data into a single and bigger unit.

How can I delete my data or prevent data retention?

Under the provisions of the European Union’s data protection law, you have the right to obtain information on your data and to update, delete or restrict it. With the help of a browser add on that can deactivate Google Analytics’ JavaScript (ga.js, analytics.js, dc.js), you can prevent Google Analytics from using your data. You can download this add on at https://tools.google.com/dlpage/gaoptout?hl=en-GB. Please consider that this add on can only deactivate any data collection by Google Analytics.

Should you generally want to deactivate, delete or manage all cookies (independently of Google Analytics), you can use one of the guides that are available for any browser:

Chrome: Clear, enable and manage cookies in Chrome

Safari: Manage cookies and website data in Safari

Firefox: Clear cookies and site data in Firefox

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete cookies in Microsoft Edge

Google Analytics is an active participant of the EU-U.S. Privacy Shield Framework, which regulates correct and save transfer of personal data.
You can find more information on this at https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&tid=111643845. We hope we were able to make you more familiar with the most important information on Google Analytics’ data processing. If you want to learn more about the tracking service, we recommend both of the following links: https://marketingplatform.google.com/about/analytics/terms/gb/ and https://support.google.com/analytics/answer/6004245?hl=en.

Newsletter Privacy Policy

When you subscribe to our Newsletter you submit your personal data and give us the right to contact you via email. We use the data that is stored for the registration for the Newsletter exclusively for our Newsletter and do not pass them on.

If you unsubscribe from the newsletter – for which you can find a link in the bottom of every newsletter – we will delete all data that was saved when you registered for the newsletter.

YouTube Privacy Policy

We have integrated YouTube videos to our website. Therefore, we can show you interesting videos directly on our site. YouTube is a video portal, which has been a subsidiary company of Google LLC since 2006. The video portal is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page on our website that contains an embedded YouTube video, your browser automatically connects to the servers of YouTube or Google. Thereby, certain data are transferred (depending on the settings). Google is responsible for YouTube’s data processing and therefore Google’s data protection applies.

In the following we will explain in more detail which data is processed, why we have integrated YouTube videos and how you can manage or clear your data.

What is YouTube?

On YouTube, users can watch, rate, comment or upload videos for free. Over the past few years, YouTube has become one of the most important social media channels worldwide. For us to be able to display videos on our website, YouTube provides a code snippet that we have integrated to our website.

Why do we use YouTube videos on our website?

YouTube is the video platform with the most visitors and best content. We strive to offer you the best possible user experience on our website, which of course includes interesting videos. With the help of our embedded videos, we can provide you other helpful content in addition to our texts and images. Additionally, embedded videos make it easier for our website to be found on the Google search engine. Moreover, if we place ads via Google Ads, Google only shows these ads to people who are interested in our offers, thanks to the collected data.

What data is stored by YouTube?

As soon as you visit one of our pages with an integrated YouTube, YouTube places at least one cookie that stores your IP address and our URL. If you are logged into your YouTube account, by using cookies YouTube can usually associate your interactions on our website with your profile. This includes data such as session duration, bounce rate, approximate location, technical information such as browser type, screen resolution or your Internet provider. Additional data can include contact details, potential ratings, shared content via social media or YouTube videos you added to your favourites.

If you are not logged in to a Google or YouTube account, Google stores data with a unique identifier linked to your device, browser or app. Thereby, e.g. your preferred language setting is maintained. However, many interaction data cannot be saved since less cookies are set.

In the following list we show you cookies that were placed in the browser during a test. On the one hand, we show cookies that were set without being logged into a YouTube account. On the other hand, we show you what cookies were placed while being logged in. We do not claim for this list to be exhaustive, as user data always depend on how you interact with YouTube.

Name: YSC
Value: b9-CV6ojI5Y111643845-1
Purpose: This cookie registers a unique ID to store statistics of the video that was viewed.
Expiry date: after end of session

Name: PREF
Value: f1=50000000
Purpose: This cookie also registers your unique ID. Google receives statistics via PREF on how you use YouTube videos on our website.
Expiry date: after 8 months

Name: GPS
Value: 1
Purpose: This cookie registers your unique ID on mobile devices to track GPS locations.
Expiry date: after 30 minutes

Name: VISITOR_INFO1_LIVE
Value: 95Chz8bagyU
Purpose: This cookie tries to estimate the user’s internet bandwith on our sites (that have built-in YouTube videos).
Expiry date: after 8 months

Further cookies that are placed when you are logged into your YouTube account:

Name: APISID
Value: zILlvClZSkqGsSwI/AU1aZI6HY7111643845-
Purpose: This cookie is used to create a profile on your interests. This data is then used for personalised advertisements.
Expiry date: after 2 years

Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: The cookie stores the status of a user’s consent to the use of various Google services. CONSENT also provides safety measures to protect users from unauthorised attacks.
Expiry date: after 19 years

Name: HSID
Value: AcRwpgUik9Dveht0I
Purpose: This cookie is used to create a profile on your interests. This data helps to display customised ads.
Expiry date: after 2 years

Name: LOGIN_INFO
Value: AFmmF2swRQIhALl6aL…
Purpose: This cookie stores information on your login data.
Expiry date: after 2 years

Name: SAPISID
Value: 7oaPxoG-pZsJuuF5/AnUdDUIsJ9iJz2vdM
Purpose: This cookie identifies your browser and device. It is used to create a profile on your interests.
Expiry date: after 2 years

Name: SID
Value: oQfNKjAsI111643845-
Purpose: This cookie stores your Google Account ID and your last login time, in a digitally signed and encrypted form.
Expiry date: after 2 years

Name: SIDCC
Value: AN0-TYuqub2JOcDTyL
Purpose: This cookie stores information on how you use the website and on what advertisements you may have seen before visiting our website.
Expiry date: after 3 months

How long and where is the data stored?

The data YouTube receive and process on you are stored on Google’s servers. Most of these servers are in America. At https://www.google.com/about/datacenters/inside/locations/?hl=en you can see where Google’s data centres are located. Your data is distributed across the servers. Therefore, the data can be retrieved quicker and is better protected against manipulation.

Google stores collected data for different periods of time. You can delete some data anytime, while other data are automatically deleted after a certain time, and still other data are stored by Google for a long time. Some data (such as elements on “My activity”, photos, documents or products) that are saved in your Google account are stored until you delete them. Moreover, you can delete some data associated with your device, browser, or app, even if you are not signed into a Google Account.

How can I delete my data or prevent data retention?

Generally, you can delete data manually in your Google account. Furthermore, in 2019 an automatic deletion of location and activity data was introduced. Depending on what you decide on, it deletes stored information either after 3 or 18 months.

Regardless of whether you have a Google account or not, you can set your browser to delete or deactivate cookies placed by Google. These settings vary depending on the browser you use. The following instructions will show how to manage cookies in your browser:

Chrome: Clear, enable and manage cookies in Chrome

Safari: Manage cookies and website data in Safari

Firefox: Clear cookies and site data in Firefox

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete cookies in Microsoft Edge

If you generally do not want to allow any cookies, you can set your browser to always notify you when a cookie is about to be set. This will enable you to decide to either allow or permit each individual cookie. Since YouTube is a subsidiary company of Google, Google’s privacy statement applies to both. If you want to learn more about how your data is handled, we recommend the privacy policy at https://policies.google.com/privacy?hl=en.

Google reCAPTCHA Privacy Policy

Our primary goal is to provide you an experience on our website that is as secure and protected as possible. To do this, we use Google reCAPTCHA from Google Inc. (1600 Amphitheater Parkway Mountain View, CA 94043, USA). With reCAPTCHA we can determine whether you are a real person from flesh and bones, and not a robot or a spam software. By spam we mean any electronically undesirable information we receive involuntarily. Classic CAPTCHAS usually needed you to solve text or picture puzzles to check. But thanks to Google’s reCAPTCHA you usually do have to do such puzzles. Most of the times it is enough to simply tick a box and confirm you are not a bot. With the new Invisible reCAPTCHA version you don’t even have to tick a box. In this privacy policy you will find out how exactly this works, and what data is used for it.

What is reCAPTCHA?

reCAPTCHA is a free captcha service from Google that protects websites from spam software and misuse by non-human visitors. This service is used the most when you fill out forms on the Internet. A captcha service is a type of automatic Turing-test that is designed to ensure specific actions on the Internet are done by human beings and not bots. During the classic Turing-test (named after computer scientist Alan Turing), a person differentiates between bot and human. With Captchas, a computer or software program does the same. Classic captchas function with small tasks that are easy to solve for humans but provide considerable difficulties to machines. With reCAPTCHA, you no longer must actively solve puzzles. The tool uses modern risk techniques to distinguish people from bots. The only thing you must do there, is to tick the text field “I am not a robot”. However, with Invisible reCAPTCHA even that is no longer necessary. reCAPTCHA, integrates a JavaScript element into the source text, after which the tool then runs in the background and analyses your user behaviour. The software calculates a so-called captcha score from your user actions. Google uses this score to calculate the likelihood of you being a human, before entering the captcha. reCAPTCHA and Captchas in general are used every time bots could manipulate or misuse certain actions (such as registrations, surveys, etc.).

Why do we use reCAPTCHA on our website?

We only want to welcome people from flesh and bones on our side and want bots or spam software of all kinds to stay away. Therefore, we are doing everything we can to stay protected and to offer you the highest possible user friendliness. For this reason, we use Google reCAPTCHA from Google. Thus, we can be pretty sure that we will remain a “bot-free” website. Using reCAPTCHA, data is transmitted to Google to determine whether you genuinely are human. reCAPTCHA thus ensures our website’s and subsequently your security. Without reCAPTCHA it could e.g. happen that a bot would register as many email addresses as possible when registering, in order to subsequently “spam” forums or blogs with unwanted advertising content. With reCAPTCHA we can avoid such bot attacks.

What data is stored by reCAPTCHA?

reCAPTCHA collects personal user data to determine whether the actions on our website are made by people. Thus, IP addresses and other data Google needs for its reCAPTCHA service, may be sent to Google. Within member states of the European Economic Area, IP addresses are almost always compressed before the data makes its way to a server in the USA.
Moreover, your IP address will not be combined with any other of Google’s data, unless you are logged into your Google account while using reCAPTCHA. Firstly, the reCAPTCHA algorithm checks whether Google cookies from other Google services (YouTube, Gmail, etc.) have already been placed in your browser. Then reCAPTCHA sets an additional cookie in your browser and takes a snapshot of your browser window.

The following list of collected browser and user data is not exhaustive. Rather, it provides examples of data, which to our knowledge, is processed by Google.

  • Referrer URL (the address of the page the visitor has come from)
  • IP-address (z.B. 256.123.123.1)
  • Information on the operating system (the software that enables the operation of your computers. Popular operating systems are Windows, Mac OS X or Linux)
  • Cookies (small text files that save data in your browser)
  • Mouse and keyboard behaviour (every action you take with your mouse or keyboard is stored)
  • Date and language settings (the language and date you have set on your PC is saved)
  • All Javascript objects (JavaScript is a programming language that allows websites to adapt to the user. JavaScript objects can collect all kinds of data under one name)
  • Screen resolution (shows how many pixels the image display consists of)

Google may use and analyse this data even before you click on the “I am not a robot” checkmark. In the Invisible reCAPTCHA version, there is no need to even tick at all, as the entire recognition process runs in the background. Moreover, Google have not given details on what information and how much data they retain.

The following cookies are used by reCAPTCHA: With the following list we are referring to Google’s reCAPTCHA demo version at https://www.google.com/recaptcha/api2/demo.
For tracking purposes, all these cookies require a unique identifier. Here is a list of cookies that Google reCAPTCHA has set in the demo version:

Name: IDE
Value: WqTUmlnmv_qXyi_DGNPLESKnRNrpgXoy1K-pAZtAkMbHI-111643845-8
Purpose:This cookie is set by DoubleClick (which is owned by Google) to register and report a user’s interactions with advertisements. With it, ad effectiveness can be measured, and appropriate optimisation measures can be taken. IDE is stored in browsers under the domain doubleclick.net.
Expiry date: after one year

Name: 1P_JAR
Value: 2019-5-14-12
Purpose: This cookie collects website usage statistics and measures conversions. A conversion e.g. takes place, when a user becomes a buyer. The cookie is also used to display relevant adverts to users. Furthermore, the cookie can prevent a user from seeing the same ad more than once.
Expiry date: after one month

Name: ANID
Value: U7j1v3dZa1116438450xgZFmiqWppRWKOr
Purpose:We could not find out much about this cookie. In Google’s privacy statement, the cookie is mentioned in connection with “advertising cookies” such as “DSID”, “FLC”, “AID” and “TAID”. ANID is stored under the domain google.com.
Expiry date: after 9 months

Name: CONSENT
Value: YES+AT.de+20150628-20-0
Purpose: This cookie stores the status of a user’s consent to the use of various Google services. CONSENT also serves to prevent fraudulent logins and to protect user data from unauthorised attacks.
Expiry date: after 19 years

Name: NID
Value: 0WmuWqy111643845zILzqV_nmt3sDXwPeM5Q
Purpose: Google uses NID to customise advertisements to your Google searches. With the help of cookies, Google “remembers” your most frequently entered search queries or your previous ad interactions. Thus, you always receive advertisements tailored to you. The cookie contains a unique ID to collect users’ personal settings for advertising purposes.
Expiry date: after 6 months

Name: DV
Value: gEAABBCjJMXcI0dSAAAANbqc111643845-4
Purpose: This cookie is set when you tick the “I am not a robot” checkmark. Google Analytics uses the cookie personalised advertising. DV collects anonymous information and is also used to distinct between users.
Expiry date: after 10 minutes

Note: We do not claim for this list to be extensive, as Google often change the choice of their cookies.

How long and where are the data stored?

Due to the integration of reCAPTCHA, your data will be transferred to the Google server. Google have not disclosed where exactly this data is stored, despite repeated inquiries. But even without confirmation from Google, it can be assumed that data such as mouse interaction, length of stay on a website or language settings are stored on the European or American Google servers. The IP address that your browser transmits to Google does generally not get merged with other Google data from the company’s other services.
However, the data will be merged if you are logged in to your Google account while using the reCAPTCHA plug-in. Google’s diverging privacy policy applies for this.

How can I delete my data or prevent data storage?

If you want to prevent any data about you and your behaviour to be transmitted to Google, you must fully log out of Google and delete all Google cookies before visiting our website or use the reCAPTCHA software. Generally, the data is automatically sent to Google as soon as you visit our website. To delete this data, you must contact Google Support at https://support.google.com/?hl=en-GB&tid=111643845.

If you use our website, you agree that Google LLC and its representatives automatically collect, edit and use data.

You can find out more about reCAPTCHA on Google’s Developers page at https://developers.google.com/recaptcha/. While Google do give more detail on the technical development of reCAPTCHA there, they have not disclosed precise information about data retention and data protection. A good, basic overview of the use of data however, can be found in the company’s internal privacy policy at https://policies.google.com/privacy?hl=en-GB.

WooCommerce Privacy Policy

We have integrated the open-source shop system WooCommerce to our website as a plugin. This WooCommerce plugin is based on the content management system WordPress, which is a subsidiary company of Automattic Inc. (60 29th Street #343, San Francisco, CA 94110, USA). Through the implemented functions, data are stored and sent to Automattic Inc where they are processed. In this privacy policy we want to inform you on what data this is, how the network uses this data and how you can manage or prevent data retention.

What is WooCommerce?

WooCommerce is an online shop system that has been part of the WordPress directory since 2011 and was specially developed for WordPress websites. It is a customisable, open source eCommerce platform that is based on WordPress. It has been integrated into our website as a WordPress plugin.

Why do we use WooCommerce on our website?

We use this practical online shop system, to be able to offer you our physical or digital products or services in the best possible way on our website. The aim is to give you easy and easy access to our offer, so that you can quickly and easily navigate to the products you want. With WooCommerce we have found a good plugin that meets our requirements for an online shop.

What data is stored by WooCommerce?

Information that you actively enter to a text field in our online shop can be collected and stored by WooCommerce or Automattic. Hence, if you register with us or order a product, Automattic may collect, process and save this data. In addition to email address, name or address, this can also be your credit card or billing information. Subsequently, Automattic can also use this information for their own marketing campaigns.

There is also evidence that Automattic automatically collects information on you in so-called server log files:

  • IP-address
  • Browser information
  • Pre-set language settings
  • Date and time of the web access

Moreover, WooCommerce sets cookies in your browser and uses technologies such as pixel tags (web beacons), to for example clearly identify you as a user and to be able to offer interest-based advertising. WooCommerce uses several different cookies, which are placed depending on the user action. This means that if you for example add a product to the shopping cart, a cookie is set so that the product remains in the shopping cart when you leave our website and come back later.

Below we want to show you an example list of possible cookies that may be set by WooCommerce:

Name: woocommerce_items_in_cart
Value: 1
Purpose:This cookie helps WooCommerce to determine when the contents of the shopping cart change.
Expiry date: after end of session

Name: woocommerce_cart_hash
Value: 447c84f810834056ab37cfe5ed27f204111643845-7
Purpose:This cookie is also used to recognise and save the changes in your shopping cart.
Expiry date: after end of session

Name: wp_woocommerce_session_d9e29d251cf8a108a6482d9fe2ef34b6
Value: 1146%7C%7C1589034207%7C%7C95f8053ce0cea135bbce671043e740111643845-4aa
Purpose:This cookie contains a unique identifier for you to allow the shopping cart data to be found in the database.
Expiry date: after 2 days

How long and where is the data stored?

Unless there is a legal obligation to keep data for a longer period, WooCommerce will delete your data if it is no longer needed for the purposes it was saved for. Server log files for example, the technical data for your browser and your IP address will be deleted after about 30 days. This is how long Automattic use the data to analyse the traffic on their own websites (for example all WordPress websites) and to fix possible problems. The data is stored on Automattic’s American servers.

How can I delete my data and prevent data retention?

You have the right to access your personal data anytime, as well as to object to it being used and processed. You can also lodge a complaint with a state supervisory authority anytime.

You can also manage, delete or deactivate cookies individually in your browser. However, please note that deactivated or deleted cookies may have a negative impact on the functions of our WooCommerce online shop. Depending on the browser you use, managing cookies differs slightly. Below you will find links to the instructions for the most common browsers:

Chrome: Clear, enable and manage cookies in Chrome

Safari: Manage cookies and website data in Safari

Firefox: Clear cookies and site data in Firefox

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete cookies in Microsoft Edge

Automattic is an active participant in the EU-U.S. Privacy Shield Framework, which regulates the correct and secure transfer of personal data. More information can be found at https://www.privacyshield.gov/participant?id=a2zt0000000CbqcAAC.
You can find more details on the privacy policy, as well as on which data is collected by WooCommerce in what way at https://automattic.com/privacy/ . Moreover, you can find general information on WooCommerce at https://woocommerce.com/.

Sofortüberweisung Privacy Policy

On our website we offer the payment method “Sofortüberweisung” from Sofort GmbH for cashless payment. Sofort GmbH has been part of the Swedish company Klarna since 2014, but is based in Germany, Theresienhöhe 12, 80339 Munich.

If you choose this payment method, your personal data will also be transmitted to Sofort GmbH or Klarna, where it will be stored and processed. In this privacy policy we will give you an overview of Sofort GmbH’s data processing.

What is “Sofortüberweisung”?

Sofortüberweisung is an online payment system that enables you to place an order via online banking. The payment is processed by Sofort GmbH, while we immediately receive information about your payment. Anyone who has an active online banking account with a PIN and TAN can use this method. Only a few banks do not yet support this payment option.

Why do we use “Sofortüberweisung” on our website?

It is our goal to offer you the best possible service with our website and our integrated online shop. Next to the overall experience of the website and offers, this also includes smooth, fast, and secure payment processing of your orders. To ensure this, we use “Sofortüberweisung” as a payment system.

What data is stored by “Sofortüberweisung”?

If you make an immediate transfer via the Sofort/Klarna service, data such as your name, account number, sort code, payment reference, amount and date are stored on the company’s servers. We then also receive this information via the payment confirmation.

As part of the check for sufficient account coverage, Sofort GmbH reviews whether your account balance and overdraft can cover the payment amount. In some cases, it is also reviewed whether any instant transfers have been successfully carried out within the last 30 days. Furthermore, a shortened (“hashed”) form of your user identification (such as your signatory or contract number) as well as your IP address will be stored. For SEPA transfers your BIC and IBAN will also be stored.

According to Sofort GmbH, no other personal data (such as account balances, sales data, transaction limits, account lists, mobile phone numbers, authentication certificates, security codes or PIN/TAN) are collected, stored or passed on to third parties.

Sofortüberweisung also uses cookies to make our service more user-friendly. When you order a product, you will be redirected to the Sofort or Klarna website. After successful payment you will be redirected to our thank-you page. There, the following three cookies are placed:

Name: SOFUEB
Value: e8cipp378mdscn9e17kajlfhv7111643845-5
Purpose: This cookie stores your session ID.
Expiry date: after ending the browser session

Name: User[user_cookie_rules] Value: 1
Purpose: This cookie stores the status of your consent to the use of cookies.
Expiry date: after 10 years

Name: _ga
Value: GA1.2.69759879.1589470706
Purpose: Analytics.js uses the _ga cookie by default to store your user ID. Hence, it basically serves to differentiate between website visitors. It is a Google Analytics cookie.
Expiry date: after 2 years

Note: We do not claim for this cookie list to be exhaustive. Moreover, it is always possible that Sofortüberweisung may also use other cookies.

How long and where are the data stored?

All gathered data are stored within the legal storage obligations. This obligation can last between three and ten years.

Klarna/Sofort GmbH try to only save data within the EU or the European Economic Area (EEA). If data is transferred outside the EU/EEA, data protection must comply with the GDPR. Also, the country the data is transferred to must be subject to the EU’s adequacy decision or have the US Privacy Shield certificate.

How can I delete my data or prevent data retention?

You can withdraw your consent for Klarna to process your personal data at any time. You also always have the right for information, rectification and deletion of your personal data. For this, you can simply email the company’s data protection team at privacy@klarna.co.uk.

In your browser, you can manage, delete, or deactivate Sofortüberweisung’s possible cookies. The settings vary a bit depending on what browser you use. The following instructions will show you how to manage cookies in the most common browsers:

Chrome: Clear, enable and manage cookies in Chrome

Safari: Manage cookies and website data in Safari

Firefox: Clear cookies and site data in Firefox

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete cookies in Microsoft Edge

If you want to know more about Sofort GMmbH’s data processing, we recommend the privacy policy at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/en_gb/privacy.

Stripe Privacy Policy

On our website we use a payment tool by Stripe, an American technology company and online payment service. Stripe Payments Europe (Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland) is responsible for customers within the EU. Therefore, if you choose Stripe as your payment method, your payment will be processed via Stripe Payments. Hence, the data required for the payment process is forwarded to Stripe where it is then stored. In this privacy policy we will give you an overview of Stripe’s data processing and retention. Moreover, we will explain why we use Stripe on our website.

What is Stripe?

The technology company Stripe offers payment solutions for online payments. Stripe enables us to accept credit and debit card payments in our webshop while it handles the entire payment process. A major advantage of Stripe is that you never have to leave our website or shop during the payment process. Moreover, payments are processed very quickly via Stripe.

Why do we use Stripe on our website?

We of course want to offer the best possible service with both our website and our integrated online shop. After all, we would like you to feel comfortable on our site and take advantage of our offers. We know that your time is valuable and therefore, payment processing in particular must work quickly and smoothly. In addition to our other payment providers, with Stripe we have found a partner that guarantees secure and fast payment processing.

What data are stored by Stripe?

If you choose Stripe as your payment method, your personal data (transaction data) will be transmitted to Stripe where it will be stored. These data include the payment method (i.e. credit card, debit card or account number), bank sort code, currency, as well as the amount and the payment date. During a transaction, your name, email address, billing or shipping address and sometimes your transaction history may also be transmitted. These data are necessary for authentication. Furthermore, Stripe may also collect relevant data for the purpose of fraud prevention, financial reporting and for providing its services in full. These data may include your name, address, telephone number as well as your country in addition to technical data about your device (such as your IP address).

Stripe does not sell any of your data to independent third parties, such as marketing agencies or other companies that have nothing to do with Stripe. However, data may be forwarded to internal departments, a limited number of Stripe’s external partners or for legal compliance reasons. What is more, Stripe uses cookies to collect data. Here is a selection of cookies that Stripe may set during the payment process:

Name: m
Value: edd716e9-d28b-46f7-8a55-e05f1779e84e040456111643845-5
Purpose: This cookie appears when you select your payment method. It saves and recognises whether you are accessing our website via a PC, tablet or smartphone.
Expiry date: after 2 years

Name: __stripe_mid
Value: fc30f52c-b006-4722-af61-a7419a5b8819875de9111643845-1
Purpose: This cookie is required for carrying out credit card transactions. For this purpose, the cookie stores your session ID.
Expiry date: after one year

Name: __stripe_sid
Value: 6fee719a-c67c-4ed2-b583-6a9a50895b122753fe
Purpose: This cookie also stores your ID. Stripe uses it for the payment process on our website.
Expiry date: after end of the session

How long and where are the data stored?

Generally, personal data are stored for the duration of the provided service. This means that the data will be stored until we terminate our cooperation with Stripe. However, in order to meet legal and official obligations, Stripe may also store personal data for longer than the duration of the provided service. Furthermore, since Stripe is a global company, your data may be stored in any of the countries Stripe offers its services in. Therefore, your data may be stored outside your country, such as in the USA for example.

How can I delete my data or prevent data retention?

Stripe is still a participant of the EU-U.S. Privacy Shield Framework which regulated correct and secure transfer of personal data until July 16, 2020. However, since the European Court of Justice declared the agreement to be invalid, the company no longer relies on this agreement, but still acts according to the principles of Privacy Shield.

You always reserve the right to information, correction and deletion of your personal data. Should you have any questions, you can contact the Stripe team at https://support.stripe.com/contact/email.

You can delete, deactivate or manage cookies in your browser that Stripe uses for its functions. This works differently depending on which browser you are using. Please note, however, that if you do so the payment process may no longer work. The following instructions will show you how to manage cookies in your browser:

Chrome: Clear, enable and manage cookies in Chrome

Safari: Manage cookies and website data in Safari

Firefox: Clear cookies and site data in Firefox

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete cookies in Microsoft Edge

We have now given you a general overview of Stripe’s data processing and retention. If you want more information, Stripe’s detailed privacy policy at https://stripe.com/at/privacy is a good source.

Newsletter

Unser Newsletter informiert über Trends und Erfahrungen zu den Themen Management, Projektmanagement, Organisationsentwicklung, Führung und agile Transformation. Es erwarteten Sie Tipps, Best Practice Beispiele, Kundenstorys, u.v.m.

Der Newsletter wird in unregelmäßigen Intervallen ca. 1  Mal pro Monat ausgesendet.
Das Newsletter-Abo kann jederzeit wieder storniert werden.