Política de privacidad
Preámbulo
Con la siguiente política de privacidad queremos informarte sobre qué tipos de datos personales (en adelante, también abreviados como «datos») tratamos, con qué fines y en qué medida. La presente declaración de protección de datos se aplica a todos los tratamientos de datos personales que llevamos a cabo, tanto en el marco de la prestación de nuestros servicios como, en particular, en nuestros sitios web, en aplicaciones móviles y en presencias en línea externas, como nuestros perfiles en redes sociales (en adelante, conjuntamente, «servicios en línea»).
Los términos utilizados no tienen connotación de género.
Última actualización: 30 de junio de 2026
Aviso: la presente política de privacidad se aplica exclusivamente al uso de nuestro sitio web www.sobbatical.com y abarca el tratamiento de datos personales relacionado con las actividades del sitio web, por ejemplo, al utilizar nuestro formulario de contacto o al suscribirte a nuestra newsletter. Para cualquier tratamiento de datos personales dentro de la aplicación Sobbatical (p. ej., durante el registro, la creación de un perfil o la solicitud a un proyecto) se aplica una política de privacidad independiente, disponible directamente en la aplicación.
Aviso: esta traducción al español se ofrece únicamente a título informativo. En caso de discrepancia o conflicto, prevalecerá la versión alemana.
Responsable del tratamiento
Sobbatical Impact Travel e.U.
Propietario: Axel Menzel
Märzstraße 88/16
1150 Viena
Austria
Dirección de correo electrónico: [email protected]
Bases jurídicas aplicables
Bases jurídicas aplicables según el RGPD: A continuación encontrarás un resumen de las bases jurídicas del RGPD sobre las que fundamentamos el tratamiento de datos personales. Ten en cuenta que, además de las disposiciones del RGPD, pueden aplicarse disposiciones nacionales de protección de datos de tu país o del nuestro. Si, además, en casos concretos son aplicables bases jurídicas más específicas, te informaremos de ellas en la presente declaración de protección de datos.
Consentimiento (art. 6, apdo. 1, letra a, RGPD) – El interesado ha dado su consentimiento para el tratamiento de sus datos personales para uno o varios fines específicos.
Ejecución de un contrato y solicitudes precontractuales (art. 6, apdo. 1, letra b, RGPD) – El tratamiento es necesario para la ejecución de un contrato en el que el interesado es parte o para la aplicación de medidas precontractuales adoptadas a petición suya.
Cumplimiento de una obligación legal (art. 6, apdo. 1, letra c, RGPD) – El tratamiento es necesario para el cumplimiento de una obligación legal a la que está sujeto el responsable del tratamiento.
Intereses legítimos (art. 6, apdo. 1, letra f, RGPD) – El tratamiento es necesario para los fines de los intereses legítimos perseguidos por el responsable del tratamiento o por un tercero, siempre que sobre dichos intereses no prevalezcan los intereses o los derechos y libertades fundamentales del interesado que requieran la protección de datos personales.
Disposiciones nacionales de protección de datos en Austria: Además de las disposiciones del RGPD, en Austria se aplican normativas nacionales de protección de datos. Se trata, en particular, de la Ley federal de protección de las personas físicas en lo que respecta al tratamiento de datos personales (Ley de protección de datos – DSG). Dicha ley contiene, en particular, disposiciones especiales sobre el derecho de acceso, rectificación o supresión, el tratamiento de categorías especiales de datos personales, el tratamiento con otros fines y la comunicación y la toma de decisiones automatizada en casos individuales.
Referencia a la aplicabilidad del RGPD y de la LPD suiza: La presente información sobre protección de datos tiene por objeto informar tanto conforme a la Ley federal suiza de protección de datos (LPD suiza) como al Reglamento General de Protección de Datos (RGPD). Por ello, te rogamos que tengas en cuenta que, debido a un ámbito de aplicación territorial más amplio y a una mejor comprensión, se han utilizado los términos del RGPD. En concreto, en lugar de los términos de la LPD suiza «tratamiento» de «datos personales» e «interés preponderante», se emplean los términos del RGPD «tratamiento» de «datos personales» e «interés legítimo». No obstante, el significado jurídico de los términos sigue determinándose por la LPD suiza en el marco de su aplicación.
Resumen de las operaciones de tratamiento
La siguiente tabla resume los tipos de datos tratados, los fines para los que se tratan y los interesados afectados.
Categorías de datos tratados
-
Datos de inventario. Datos de pago. Datos de contacto. Datos de contenido. Datos contractuales. Datos de uso. Metadatos, datos de comunicación y de proceso.
Categorías de interesados
-
Clientes.
Empleados.
Clientes potenciales.
Interlocutores de comunicación.
Usuarios.
Socios comerciales y contractuales.
Personas representadas.
Fines del tratamiento
-
Prestación de servicios contractuales y atención al cliente.
Solicitudes de contacto y comunicación.
Medidas de seguridad.
Marketing directo.
Análisis web.
Segmentación (targeting).
Procedimientos administrativos y de organización.
Gestión y respuesta a consultas.
Comentarios y opiniones.
Marketing.
Perfiles con información relativa a los usuarios.
Prestación de nuestros servicios en línea y usabilidad.
Infraestructura informática.
Comunicación de datos personales
En el marco de nuestro tratamiento de datos personales, puede ocurrir que los datos se transfieran a otros lugares, empresas o personas, o que se les comuniquen. Entre los destinatarios de estos datos pueden encontrarse, por ejemplo, prestadores de servicios encargados de tareas informáticas o proveedores de servicios y contenidos integrados en un sitio web. En tales casos se respetan los requisitos legales y, en particular, se celebran con los destinatarios de tus datos los contratos o acuerdos correspondientes destinados a proteger tus datos.
Transferencias internacionales de datos
Si tratamos datos en un tercer país (es decir, fuera de la Unión Europea (UE) o del Espacio Económico Europeo (EEE)) o el tratamiento se produce en el marco del uso de servicios de terceros o de la divulgación o transferencia de datos a otras personas, organismos o empresas, ello solo se lleva a cabo conforme a los requisitos legales.
Sin perjuicio del consentimiento expreso o de una transferencia exigida por contrato o por ley, solo tratamos o hacemos tratar los datos en terceros países con un nivel de protección de datos reconocido, sobre la base de garantías particulares, como una obligación contractual mediante las denominadas cláusulas tipo de protección de datos de la Comisión Europea, o cuando certificaciones o normas internas vinculantes de protección de datos justifiquen el tratamiento (art. 44 a 49 RGPD; página informativa de la Comisión Europea: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en).
Comunicación de datos personales al extranjero: Conforme a la Ley suiza de protección de datos (LPD), solo comunicamos datos personales al extranjero cuando se garantiza un nivel de protección adecuado para las personas afectadas (art. 15 LPD suiza). Si el Consejo Federal no constata la existencia de un nivel de protección adecuado, aplicamos medidas de seguridad alternativas. Estas medidas pueden incluir acuerdos internacionales, garantías específicas, cláusulas de protección de datos en los contratos, cláusulas tipo aprobadas por el Comisionado Federal de Protección de Datos y Transparencia (PFPDT) o normas internas de protección de datos previamente reconocidas por el PFPDT o por una autoridad competente de otro país.
En virtud del art. 16 LPD suiza, pueden admitirse excepciones a la comunicación de datos al extranjero si se cumplen determinadas condiciones, en particular el consentimiento de la persona afectada, la ejecución de un contrato, un interés público, la protección de la vida o la integridad física, datos hechos públicos o datos procedentes de un registro previsto por la ley. Dichas comunicaciones respetan siempre los requisitos legales.
Supresión de datos
The data processed by us will be erased in accordance with the statutory provisions as soon as their processing is revoked or other permissions no longer apply (e.g. if the purpose of processing this data no longer applies or they are not required for the purpose). If the data is not deleted because they are required for other and legally permissible purposes, their processing is limited to these purposes. This means that the data will be restricted and not processed for other purposes. This applies, for example, to data that must be stored for commercial or tax reasons or for which storage is necessary to assert, exercise or defend legal claims or to protect the rights of another natural or legal person. In the context of our information on data processing, we may provide users with further information on the deletion and retention of data that is specific to the respective processing operation.
Derechos de los interesados
Rights of the Data Subjects under the GDPR: As data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
-
Right to Object: You have the right, on grounds arising from your particular situation, to object at any time to the processing of your personal data which is based on letter (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions. Where personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of the personal data concerning you for the purpose of such marketing, which includes profiling to the extent that it is related to such direct marketing.
-
Right of withdrawal for consents: You have the right to revoke consents at any time.
-
Right of access: You have the right to request confirmation as to whether the data in question will be processed and to be informed of this data and to receive further information and a copy of the data in accordance with the provisions of the law.
-
Right to rectification: You have the right, in accordance with the law, to request the completion of the data concerning you or the rectification of the incorrect data concerning you.
-
Right to Erasure and Right to Restriction of Processing: In accordance with the statutory provisions, you have the right to demand that the relevant data be erased immediately or, alternatively, to demand that the processing of the data be restricted in accordance with the statutory provisions.
-
Right to data portability: You have the right to receive data concerning you which you have provided to us in a structured, common and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
-
Complaint to the supervisory authority: In accordance with the law and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State where you habitually reside, the supervisory authority of your place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Rights of the data subjects under the Swiss DPA:
You have the following rights as an affected individual in accordance with the provisions of the Swiss DSG:
-
Right to information: You have the right to request confirmation as to whether data concerning you is being processed and to receive the information necessary for you to assert your rights under this law and to ensure transparent data processing (Art. 25 to 27 Swiss DSG).
-
Right to data disclosure or transfer: You have the right to request the disclosure of your personal data that you have provided to us in a commonly used electronic format (Art. 28 to 29 Swiss DSG).
-
Right to file a complaint: You have the right to file a complaint to protect your personality rights (Art. 32 para. 2 to para. 4 Swiss DSG).
-
Right to rectification: You have the right, in accordance with Art. 32 Swiss DSG, to request the rectification of inaccurate data concerning you. If it is not possible to determine the accuracy or inaccuracy of the data, you have the right to attach a statement of disagreement (Art. 32 para. 1 and 3 Swiss DSG).
-
Right to prohibition of processing: You have the right to request a prohibition or restriction of the processing of the data (Art. 32 para. 2 lit a. Swiss DSG).
-
Right to prohibition of disclosure to third parties: You have the right to request that a specific disclosure of data concerning you to third parties be prohibited (Art. 32 para. 2 lit b. Swiss DSG).
-
Right to deletion, destruction: You have the right to request the immediate deletion and destruction of data concerning you, or alternatively (Art. 32 para. 2 lit c. Swiss DSG).
-
Right to withdraw consent: You have the right to withdraw your consent with effect for the future.
Uso de cookies
Cookies are small text files or other data records that store information on end devices and read information from the end devices. For example, to store the login status in a user account, the contents of a shopping cart in an e-shop, the contents accessed or the functions used. Cookies can also be used for various purposes, e.g. for purposes of functionality, security and convenience of online offers as well as the creation of analyses of visitor flows.
Information on consent: We use cookies in accordance with the statutory provisions. Therefore, we obtain prior consent from users, except when it is not required by law. In particular, consent is not required if the storage and reading of information, including cookies, is strictly necessary in order to provide an information society service explicitly requested by the subscriber or user. Essential cookies usually include cookies with functions related to the display and operability of the onlineservice, load balancing, security, storage of users' preferences and choices or similar purposes related to the provision of the main and secondary functions of the onlineservice requested by users. The revocable consent will be clearly communicated to the user and will contain the information on the respective cookie use.
Information on legal bases under data protection law: The legal basis under data protection law on which we process users' personal data with the use of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is their declared consent. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g. in a business operation of our online services and improvement of its usability) or, if this is done in the context of the fulfillment of our contractual obligations, if the use of cookies is necessary to fulfill our contractual obligations. For which purposes the cookies are processed by us, we do clarify in the course of this privacy policy or in the context of our consent and processing procedures.
Retention period: With regard to the retention period, a distinction is drawn between the following types of cookies:
-
Temporary cookies (also known as "session cookies"): Temporary cookies are deleted at the latest after a user has left an online service and closed his or her end device (i.e. browser or mobile application).
-
Permanent cookies: Permanent cookies remain stored even after the terminal device is closed. For example, the login status can be saved, or preferred content can be displayed directly when the user visits a website again. Likewise, user data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information about the type and storage duration of cookies (e.g., as part of obtaining consent), users should assume that cookies are permanent and that the storage period can be up to two years.
General notes on revocation and objection (so-called "Opt-Out"): Users can revoke the consents they have given at any time and object to the processing in accordance with legal requirements. Users can restrict the use of cookies in their browser settings, among other options (although this may also limit the functionality of our online offering). A objection to the use of cookies for online marketing purposes can also be made through the websites
https://optout.aboutads.info and https://www.youronlinechoices.com/.
-
Processed data types: Usage data (e.g. websites visited, interest in content, access times).
-
Data subjects: Users (e.g. website visitors, users of online services).
-
Purposes of Processing: Provision of our online services and usability.
-
Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act); Consent (Article 6(1)(a) GDPR; Article 31(1) Swiss Data Protection Act).
Further information on processing methods, procedures and services used:
-
Processing Cookie Data on the Basis of Consent: We use a cookie management solution in which users' consent to the use of cookies, or the procedures and providers mentioned in the cookie management solution, can be obtained, managed and revoked by the users. The declaration of consent is stored so that it does not have to be retrieved again and the consent can be proven in accordance with the legal obligation. Storage can take place server-sided and/or in a cookie (so-called opt-out cookie or with the aid of comparable technologies) in order to be able to assign the consent to a user or and/or his/her device. Subject to individual details of the providers of cookie management services, the following information applies: The duration of the storage of the consent can be up to two years. In this case, a pseudonymous user identifier is formed and stored with the date/time of consent, information on the scope of the consent (e.g. which categories of cookies and/or service providers) as well as the browser, system and used end device; Legal Basis: Consent (Article 6(1)(a) GDPR; Article 31(1) Swiss Data Protection Act).
-
Cookie-Opt-Out: In the footer of our website you will find a link that allows you to change your cookie settings as well as revoke corresponding consents; Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
Servicios para empresas
We process data of our contractual and business partners, e.g. customers and interested parties (collectively referred to as "contractual partners") within the context of contractual and comparable legal relationships as well as associated actions and communication with the contractual partners or pre-contractually, e.g. to answer inquiries.
We process this data in order to fulfill our contractual obligations. These include, in particular, the obligations to provide the agreed services, any update obligations and remedies in the event of warranty and other service disruptions. In addition, we process the data to protect our rights and for the purpose of administrative tasks associated with these obligations and company organization. Furthermore, we process the data on the basis of our legitimate interests in proper and economical business management as well as security measures to protect our contractual partners and our business operations from misuse, endangerment of their data, secrets, information and rights (e.g. for the involvement of telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the framework of applicable law, we only disclose the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners will be informed about further forms of processing, e.g. for marketing purposes, within the scope of this privacy policy.
Which data are necessary for the aforementioned purposes, we inform the contracting partners before or in the context of the data collection, e.g. in online forms by special marking (e.g. colors), and/or symbols (e.g. asterisks or the like), or personally.
We delete the data after expiry of statutory warranty and comparable obligations, i.e. in principle after expiry of 4 years, unless the data is stored in a customer account or must be kept for legal reasons of archiving. The statutory retention period for documents relevant under tax law as well as for commercial books, inventories, opening balance sheets, annual financial statements, the instructions required to understand these documents and other organizational documents and accounting records is ten years and for received commercial and business letters and reproductions of sent commercial and business letters six years. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, the opening balance sheet, the annual financial statements or the management report was prepared, the commercial or business letter was received or sent, or the accounting document was created, furthermore the record was made or the other documents were created.
If we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms shall apply in the relationship between the users and the providers.
-
Processed data types: Inventory data (e.g. names, addresses); Payment Data (e.g. bank details, invoices, payment history); Contact data (e.g. e-mail, telephone numbers); Contract data (e.g. contract object, duration, customer category).
-
Data subjects: Prospective customers; Business and contractual partners.
-
Purposes of Processing: Provision of contractual services and customer support; Contact requests and communication; Office and organisational procedures; Managing and responding to inquiries.
-
Legal Basis: Performance of a contract and prior requests (Article 6(1)(1)(b) GDPR; Article 31(1) and 2(b) Swiss Data Protection Act); Compliance with a legal obligation (Article 6(1)(1)(c) GDPR; Article 31(1) Swiss Data Protection Act); Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
Further information on processing methods, procedures and services used:
-
Travel-related Services: We process the data of our customers and interested parties (uniformly referred to as "customers") in accordance with the underlying contractual relationship. Furthermore, we may process information on the characteristics and circumstances of persons or items belonging to them if this is necessary within the framework of the contractual relationship. These can be, for example, information on personal circumstances, mobile assets and financial situation. As part of our assignment it may be necessary for us to process special categories of data within the meaning of Artcile 9(1) GDPR; Article 5(c)Swiss Data Protection Act, in particular information on the health of a person. The processing takes place in order to protect the health interests of the customers and otherwise only with the consent of the customers. If necessary for the fulfilment of the contract or required by law, or agreed to by customers or on the basis of our legitimate interests, we disclose or transmit the customer's data, for example to the service providers involved in the fulfilment of the travel services; Legal Basis: Performance of a contract and prior requests (Article 6(1)(1)(b) GDPR; Article 31(1) and 2(b) Swiss Data Protection Act).
Proveedores y servicios utilizados en el marco de la actividad
As part of our business activities, we use additional services, platforms, interfaces or plug-ins from third-party providers (in short, "services") in compliance with legal requirements. Their use is based on our interests in the proper, legal and economic management of our business operations and internal organization.
-
Processed data types: Inventory data (e.g. names, addresses); Payment Data (e.g. bank details, invoices, payment history); Contact data (e.g. e-mail, telephone numbers); Content data (e.g. text input, photographs, videos); Contract data (e.g. contract object, duration, customer category).
-
Data subjects: Customers; Prospective customers; Users (e.g. website visitors, users of online services); Business and contractual partners.
-
Purposes of Processing: Provision of contractual services and customer support; Office and organisational procedures.
-
Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act); Performance of a contract and prior requests (Article 6(1)(1)(b) GDPR; Article 31(1) and 2(b) Swiss Data Protection Act).
Further information on processing methods, procedures and services used:
-
Email marketing and newsletter distribution, management of subscribers and campaign analytics; Service provider: UAB "MailerLite", J. Basanavičiaus 15, LT-03108 Vilnius, Lithuania; Legal Basis: Consent (Article 6(1)(1)(a) GDPR) and Legitimate Interests (Article 6(1)(1)(f) GDPR); Website: https://www.mailerlite.com; Privacy Policy: https://www.mailerlite.com/legal/privacy-policy; Data Processing Agreement: https://www.mailerlite.com/legal/data-processing-agreement. Data is processed on servers within the European Union (ISO 27001-certified data centre); no transfer to third countries.
Prestación de servicios en línea y alojamiento web
We process user data in order to be able to provide them with our online services. For this purpose, we process the IP address of the user, which is necessary to transmit the content and functions of our online services to the user's browser or terminal device.
-
Processed data types: Usage data (e.g. websites visited, interest in content, access times); Meta, communication and process data (e.g. IP addresses, time information, identification numbers, consent status).
-
Data subjects: Users (e.g. website visitors, users of online services).
-
Purposes of Processing: Provision of our online services and usability; Information technology infrastructure (Operation and provision of information systems and technical devices, such as computers, servers, etc.).); Security measures.
-
Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
Further information on processing methods, procedures and services used:
-
Provision of online offer on rented hosting space: For the provision of our online services, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a "web hoster"); Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
-
Collection of Access Data and Log Files: The access to our online services is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, data volumes transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a general rule, IP addresses and the requesting provider. The server log files can be used for security purposes, e.g. to avoid overloading the servers (especially in the case of abusive attacks, so-called DDoS attacks) and to ensure the stability and optimal load balancing of the servers; Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act); Retention period: Log file information is stored for a maximum period of 30 days and then deleted or anonymized. Data, the further storage of which is necessary for evidence purposes, are excluded from deletion until the respective incident has been finally clarified.
-
Google Cloud Storage: Cloud storage, cloud infrastructure services and cloud-based application software; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act); Website: https://cloud.google.com/; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum; Standard Contractual Clauses (Safeguarding the level of data protection when processing data in third countries): https://cloud.google.com/terms/eu-model-contract-clause; Further Information: https://cloud.google.com/privacy.
Blogs y medios de publicación
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data will only be processed for the purposes of the publication medium to the extent necessary for its presentation and communication between authors and readers or for security reasons. For the rest, we refer to the information on the processing of visitors to our publication medium within the scope of this privacy policy.
-
Processed data types: Inventory data (e.g. names, addresses); Contact data (e.g. e-mail, telephone numbers); Content data (e.g. text input, photographs, videos); Usage data (e.g. websites visited, interest in content, access times); Meta, communication and process data (e.g. IP addresses, time information, identification numbers, consent status).
-
Data subjects: Users (e.g. website visitors, users of online services).
-
Purposes of Processing: Provision of contractual services and customer support; Feedback (e.g. collecting feedback via online form); Provision of our online services and usability.
-
Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
Gestión de contactos y consultas
When contacting us (e.g. via mail, contact form, e-mail, telephone or via social media) as well as in the context of existing user and business relationships, the information of the inquiring persons is processed to the extent necessary to respond to the contact requests and any requested measures.
-
Processed data types: Contact data (e.g. e-mail, telephone numbers); Content data (e.g. text input, photographs, videos); Usage data (e.g. websites visited, interest in content, access times); Meta, communication and process data (e.g. IP addresses, time information, identification numbers, consent status).
-
Data subjects: Communication partner (Recipients of e-mails, letters, etc.).
-
Purposes of Processing: Contact requests and communication; Managing and responding to inquiries; Feedback (e.g. collecting feedback via online form); Provision of our online services and usability.
-
Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act); Performance of a contract and prior requests (Article 6(1)(1)(b) GDPR; Article 31(1) and 2(b) Swiss Data Protection Act).
Further information on processing methods, procedures and services used:
-
Contact form: When users contact us via our contact form, e-mail or other communication channels, we process the data provided to us in this context to process the communicated request; Legal Basis: Performance of a contract and prior requests (Article 6(1)(1)(b) GDPR; Article 31(1) and 2(b) Swiss Data Protection Act), Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
Videoconferencias, reuniones en línea, seminarios web y uso compartido de pantalla
We use platforms and applications of other providers (hereinafter referred to as "Conference Platforms") for the purpose of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as "Conference"). When using the Conference Platforms and their services, we comply with the legal requirements.
Data processed by Conference Platforms: In the course of participation in a Conference, the Data of the participants listed below are processed. The scope of the processing depends, on the one hand, on which data is requested in the context of a specific Conference (e.g., provision of access data or clear names) and which optional information is provided by the participants. In addition to processing for the purpose of conducting the conference, participants' Data may also be processed by the Conference Platforms for security purposes or service optimization. The processed Date includes personal information (first name, last name), contact information (e-mail address, telephone number), access data (access codes or passwords), profile pictures, information on professional position/function, the IP address of the internet access, information on the participants' end devices, their operating system, the browser and its technical and linguistic settings, information on the content-related communication processes, i.e. entries in chats and audio and video data, as well as the use of other available functions (e.g. surveys). The content of communications is encrypted to the extent technically provided by the conference providers. If participants are registered as users with the Conference Platforms, then further data may be processed in accordance with the agreement with the respective Conference Provider.
Logging and recording: If text entries, participation results (e.g. from surveys) as well as video or audio recordings are recorded, this will be transparently communicated to the participants in advance and they will be asked - if necessary - for their consent.
Data protection measures of the participants: Please refer to the data privacy information of the Conference Platforms for details on the processing of your data and select the optimum security and data privacy settings for you within the framework of the settings of the conference platforms. Furthermore, please ensure data and privacy protection in the background of your recording for the duration of a Conference (e.g., by notifying roommates, locking doors, and using the background masking function, if technically possible). Links to the conference rooms as well as access data, should not be passed on to unauthorized third parties.
Notes on legal bases: Insofar as, in addition to the Conference Platforms, we also process users' data and ask users for their consent to use contents from the Conferences or certain functions (e.g. consent to a recording of Conferences), the legal basis of the processing is this consent. Furthermore, our processing may be necessary for the fulfillment of our contractual obligations (e.g. in participant lists, in the case of reprocessing of Conference results, etc.). Otherwise, user data is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.
-
Processed data types: Inventory data (e.g. names, addresses); Contact data (e.g. e-mail, telephone numbers); Content data (e.g. text input, photographs, videos); Usage data (e.g. websites visited, interest in content, access times); Meta, communication and process data (e.g. IP addresses, time information, identification numbers, consent status).
-
Data subjects: Communication partner (Recipients of e-mails, letters, etc.); Users (e.g. website visitors, users of online services); Persons depicted.
-
Purposes of Processing: Provision of contractual services and customer support; Contact requests and communication; Office and organisational procedures.
-
Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
Further information on processing methods, procedures and services used:
-
Google Hangouts / Meet: Conference and communication software; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act); Website: https://hangouts.google.com/; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum; Standard Contractual Clauses (Safeguarding the level of data protection when processing data in third countries): https://cloud.google.com/terms/eu-model-contract-clause.
Servicios en la nube
Utilizamos servicios de software accesibles a través de Internet (los denominados «servicios en la nube», también conocidos como «Software as a Service»), prestados en los servidores de sus proveedores, para el almacenamiento y la gestión de contenidos (p. ej., almacenamiento y gestión de documentos, intercambio de documentos, contenidos e información con determinados destinatarios o publicación de contenidos e información).
En este marco, pueden tratarse y almacenarse datos personales en los servidores del proveedor, en la medida en que dichos datos formen parte de procesos de comunicación con nosotros o sean tratados por nosotros conforme a la presente política de privacidad. Estos datos pueden incluir, en particular, datos maestros y de contacto de los interesados, datos sobre procesos, contratos y otras operaciones y sus contenidos. Los proveedores de servicios en la nube también tratan datos de uso y metadatos con fines de seguridad y optimización del servicio.
Si utilizamos servicios en la nube para poner documentos y contenidos a disposición de otros usuarios o de sitios web de acceso público, formularios, etc., los proveedores pueden almacenar cookies en los dispositivos de los usuarios con fines de análisis web o para recordar sus preferencias.
Tipos de datos tratados: datos de inventario (p. ej., nombres, direcciones); datos de contacto (p. ej., correo electrónico, números de teléfono); datos de contenido (p. ej., entradas de texto, fotografías, vídeos); datos de uso (p. ej., sitios web visitados, interés en contenidos, horas de acceso); metadatos, datos de comunicación y de proceso (p. ej., direcciones IP, información horaria, números de identificación, estado del consentimiento).
Interesados: clientes; empleados (p. ej., trabajadores, candidatos); clientes potenciales; interlocutores de comunicación (destinatarios de correos, cartas, etc.); usuarios (p. ej., visitantes del sitio, usuarios de servicios en línea).
Fines del tratamiento: procedimientos administrativos y de organización; infraestructura informática (operación y provisión de sistemas de información y dispositivos técnicos, como ordenadores, servidores, etc.).
Base jurídica: intereses legítimos (art. 6, apdo. 1, letra f, RGPD; art. 31, apdo. 1 y 2, LPD suiza).
Información adicional sobre los métodos, procedimientos y servicios utilizados:
Google Cloud Storage: almacenamiento en la nube, servicios de infraestructura en la nube y software de aplicación basado en la nube; Proveedor: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublín 2, Irlanda; Base jurídica: intereses legítimos (art. 6, apdo. 1, letra f, RGPD; art. 31, apdo. 1 y 2, LPD suiza); Sitio web: https://cloud.google.com/; Política de privacidad: https://policies.google.com/privacy; Contrato de encargo del tratamiento: https://cloud.google.com/terms/data-processing-addendum; Cláusulas contractuales tipo (garantía del nivel de protección de datos al tratar datos en terceros países): https://cloud.google.com/terms/eu-model-contract-clause; Información adicional: https://cloud.google.com/privacy.
Google Workspace: almacenamiento en la nube, servicios de infraestructura en la nube y software de aplicación basado en la nube; Proveedor: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublín 2, Irlanda; Base jurídica: intereses legítimos (art. 6, apdo. 1, letra f, RGPD; art. 31, apdo. 1 y 2, LPD suiza); Sitio web: https://workspace.google.com/; Política de privacidad: https://policies.google.com/privacy; Contrato de encargo del tratamiento: https://cloud.google.com/terms/data-processing-addendum; Cláusulas contractuales tipo (garantía del nivel de protección de datos al tratar datos en terceros países): https://cloud.google.com/terms/eu-model-contract-clause; Información adicional: https://cloud.google.com/privacy.
Comunicación comercial por correo electrónico, correo postal, fax o teléfono
We process personal data for the purposes of promotional communication, which may be carried out via various channels, such as e-mail, telephone, post or fax, in accordance with the legal requirements.
The recipients have the right to withdraw their consent at any time or to object to the advertising communication at any time.
After revocation or objection, we store the data required to prove the past authorization to contact or send up to three years from the end of the year of revocation or objection on the basis of our legitimate interests. The processing of this data is limited to the purpose of a possible defense against claims. Based on the legitimate interest to permanently observe the revocation, respectively objection of the users, we further store the data necessary to avoid a renewed contact (e.g. depending on the communication channel, the e-mail address, telephone number, name).
-
Processed data types: Inventory data (e.g. names, addresses); Contact data (e.g. e-mail, telephone numbers).
-
Data subjects: Communication partner (Recipients of e-mails, letters, etc.).
-
Purposes of Processing: Direct marketing (e.g. by e-mail or postal).
-
Legal Basis: Consent (Article 6(1)(a) GDPR; Article 31(1) Swiss Data Protection Act); Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
Web Analysis, Monitoring and Optimization
Web analysis is used to evaluate the visitor traffic on our website and may include the behaviour, interests or demographic information of users, such as age or gender, as pseudonymous values. With the help of web analysis we can e.g. recognize, at which time our online services or their functions or contents are most frequently used or requested for repeatedly, as well as which areas require optimization.
In addition to web analysis, we can also use test procedures, e.g. to test and optimize different versions of our online services or their components.
Unless otherwise stated below, profiles, i.e. data aggregated for a usage process, can be created for these purposes and information can be stored in a browser or in a terminal device and read from it. The information collected includes, in particular, websites visited and elements used there as well as technical information such as the browser used, the computer system used and information on usage times. If users have agreed to the collection of their location data from us or from the providers of the services we use, location data may also be processed.
Unless otherwise stated below, profiles, that is data summarized for a usage process or user, may be created for these purposes and stored in a browser or terminal device (so-called "cookies") or similar processes may be used for the same purpose. The information collected includes, in particular, websites visited and elements used there as well as technical information such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data or profiles to us or to the providers of the services we use, these may also be processed, depending on the provider.
The IP addresses of the users are also stored. However, we use any existing IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect the user. In general, within the framework of web analysis, A/B testing and optimisation, no user data (such as e-mail addresses or names) is stored, but pseudonyms. This means that we, as well as the providers of the software used, do not know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.
-
Processed data types: Usage data (e.g. websites visited, interest in content, access times); Meta, communication and process data (e.g. IP addresses, time information, identification numbers, consent status).
-
Data subjects: Users (e.g. website visitors, users of online services).
-
Purposes of Processing: Web Analytics (e.g. access statistics, recognition of returning visitors); Profiles with user-related information (Creating user profiles); Targeting (e.g. profiling based on interests and behaviour, use of cookies); Provision of our online services and usability.
-
Security measures: IP Masking (Pseudonymization of the IP address).
-
Legal Basis: Consent (Article 6(1)(a) GDPR; Article 31(1) Swiss Data Protection Act).
Further information on processing methods, procedures and services used:
-
Google Analytics: We use Google Analytics to perform measurement and analysis of the use of our online services by users based on a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It is used to assign analysis information to an end device in order to recognize which content users have accessed within one or various usage processes, which search terms they have used, have accessed again or have interacted with our online services. Likewise, the time of use and its duration are stored, as well as the sources of users referring to our online services and technical aspects of their end devices and browsers. In the process, pseudonymous profiles of users are created with information from the use of various devices, and cookies may be used. In Analytics, higher level geographic location data is provided by collecting the following metadata based on IP search: "city" (and the derived latitude and longitude of the city), "continent", "country", "region", "subcontinent" (and the ID-based equivalents). To ensure the protection of user data in the EU, Google receives and processes all user data via domains and servers within the EU. The IP address of users is not logged and is shortened by the last two digits by default. The shortening of the IP address takes place on EU servers for EU users. In addition, all sensitive data collected from users in the EU is deleted before it is collected via EU domains and servers; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Article 6(1)(a) GDPR; Article 31(1) Swiss Data Protection Act); Website: https://marketingplatform.google.com/intl/en/about/analytics/; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Standard Contractual Clauses (Safeguarding the level of data protection when processing data in third countries): https://business.safety.google/adsprocessorterms; Opt-Out: Opt-Out-Plugin: https://tools.google.com/dlpage/gaoptout?hl=en, Settings for the Display of Advertisements: https://adssettings.google.com/authenticated; Further Information: https://privacy.google.com/businesses/adsservices (Types of processing and data processed).
Perfiles en redes sociales (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.
We would like to point out that user data may be processed outside the European Union. This may entail risks for users, e.g. by making it more difficult to enforce users' rights.
In addition, user data is usually processed within social networks for market research and advertising purposes. For example, user profiles can be created on the basis of user behaviour and the associated interests of users. The user profiles can then be used, for example, to place advertisements within and outside the networks which are presumed to correspond to the interests of the users. For these purposes, cookies are usually stored on the user's computer, in which the user's usage behaviour and interests are stored. Furthermore, data can be stored in the user profiles independently of the devices used by the users (especially if the users are members of the respective networks or will become members later on).
For a detailed description of the respective processing operations and the opt-out options, please refer to the respective data protection declarations and information provided by the providers of the respective networks.
Also in the case of requests for information and the exercise of rights of data subjects, we point out that these can be most effectively pursued with the providers. Only the providers have access to the data of the users and can directly take appropriate measures and provide information. If you still need help, please do not hesitate to contact us.
-
Processed data types: Contact data (e.g. e-mail, telephone numbers); Content data (e.g. text input, photographs, videos); Usage data (e.g. websites visited, interest in content, access times); Meta, communication and process data (e.g. IP addresses, time information, identification numbers, consent status).
-
Data subjects: Users (e.g. website visitors, users of online services).
-
Purposes of Processing: Contact requests and communication; Feedback (e.g. collecting feedback via online form); Marketing.
-
Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
Further information on processing methods, procedures and services used:
-
Instagram: Social network; Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act); Website: https://www.instagram.com; Privacy Policy: https://instagram.com/about/legal/privacy.
-
Facebook: Social network; Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR); Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy.
-
LinkedIn: Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland; Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Data Processing Agreement: https://legal.linkedin.com/dpa; Standard Contractual Clauses (Safeguarding the level of data protection when processing data in third countries): https://legal.linkedin.com/dpa; Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Plugins and embedded functions and content
Within our online services, we integrate functional and content elements that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may, for example, be graphics, videos or city maps (hereinafter uniformly referred to as "Content").
The integration always presupposes that the third-party providers of this content process the IP address of the user, since they could not send the content to their browser without the IP address. The IP address is therefore required for the presentation of these contents or functions. We strive to use only those contents, whose respective offerers use the IP address only for the distribution of the contents. Third parties may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may include technical information about the browser and operating system, referring websites, visit times and other information about the use of our website, as well as may be linked to such information from other sources.
-
Processed data types: Usage data (e.g. websites visited, interest in content, access times); Meta, communication and process data (e.g. IP addresses, time information, identification numbers, consent status).
-
Data subjects: Users (e.g. website visitors, users of online services).
-
Purposes of Processing: Provision of our online services and usability.
-
Legal Basis: Legitimate Interests (Article 6(1)(1)(f) GDPR; Article 31(1) and (2) Swiss Data Protection Act).
We kindly ask you to inform yourself regularly about the contents of our data protection declaration. We will adjust the privacy policy as changes in our data processing practices make this necessary. We will inform you as soon as the changes require your cooperation (e.g. consent) or other individual notification.
If we provide addresses and contact information of companies and organizations in this privacy policy, we ask you to note that addresses may change over time and to verify the information before contacting us.
Supervisory authority competent for us:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Austria
E-Mail: [email protected]
