Table of contents
- Which of your data do we collect, for which purposes and on which legal basis do we process it?
- Additional embedded services and contents of third parties
- Is your data transmitted to third parties?
- Retention period
- Your Rights under Data Protection Law
- Data security
1. General, Scope IXOLIT GmbH / IXOPAY GmbH
1.1. It is of utmost importance for us to protect your personal data. We therefore comply with the applicable data protection provisions, in particular the General Data Protection Regulation ("GDPR"), the Austrian Data Protection Act ("DSG") and the Telecommunications Act ("TKG") concerning the protection, lawful processing and confidentiality of personal data as well as data security.
1.2.a. Controller of the processing on the Websites www.ixolit.com, www.ixo.care, www.ixocreate.com, www.ixoplan.com is IXOLIT GmbH, Mariahilfer Straße 77-79, 1060 Vienna, FN 213107v, Commercial Court Vienna ("IXOLIT").
1.2.b. Controller of the processing on the Website www.ixopay.com is IXOPAY GmbH, Mariahilfer Straße 77-79, 1060 Vienna, FN 451099g, Commercial Court Vienna ("IXOPAY").
In accordance with this distinction, the terms "we", "us" and "our" refer either to IXOLIT or IXOPAY, depending on which of the above-mentioned Websites you use.
2. Which of your data do we collect, for which purposes and on which legal basis do we process it?
2.1. Contacting us
When you fill out the contact form or the qualification form on our Website or establish contact with us via e-mail or through other electronic channels (such as social media platforms), we process the data you voluntarily provided us with in the aforementioned media (name, e-mail address, nature of the enquiry respectively the subject of your message and the content of your message, as well as other fields in the aforementioned forms on our Website).
We process the data provided within the course of contacting us solely for processing your enquiry, to get in contact with you if desired and to provide you with the requested information. This data processing is therefore necessary for the fulfilment of our (pre)contractual obligations.
2.2. Server log files
We collect and process the following data when you visit our Website and use our Online Services, that is – technically speaking – when you access the respective server containing the specifically requested service (so called server log files): name of the accessed Website, file (e.g. html, JPG, PNG), date and time of access, transmitted quantity of data, server status codes, processing time, browser and client type alongside the version, your operating system, referrer URL (the previously visited Website or external site), IP-address and the requesting provider, reverse DNS; if you contact us via the Contact Form, we also process connection data regarding source and target (network discovery or address, port numbers, protocol, e-mail address, e-mail subject, connecting server, protocol details, reputation data for spam filters, reverse DNS, obvious labelling, connected servers), authentication details and technical e-mail meta information.
This data is generated automatically through our servers when you use our Website and is necessary so that we can provide you with our Online Services. We therefore process server log files solely to be able to operate our Website and the connected services, to distribute web server requests in our server pool, for detection and rectification of errors as well as for security reasons (e.g. for clarification of abusive and fraudulent activities), for a maximum duration of 15 days. Thus, this data processing activity is necessary to ensure our legitimate interests in operating an error-free and secure Website.
2.3. Usage data
Based on your consent to Reporting Cookies, we collect and process the following data about your use and interaction with our Website: IP-address of your device, the used internet browser, the browser language, your operating system, the requested files from our Website, your settings regarding Java, screen resolution, colour depth, your click behaviour on the Website (time of access, clicks) as well as the internet site from which you visit us (referrer URL). You can withdraw your consent at any time via the "Cookie Settings" or through your browser settings (see point 3.4 below) with effect for the future and free of charge.
This data is collected through the Reporting Cookie "Google Analytics" (see point 3.5 below). We use this usage data for (i) web analysis, (ii) improvements of our Online Services and our Website, (iii) increasing usability. Your consent is not necessary for the use of the Online Presence.
On the basis of your consent (obtained through double opt-in process; after registration you receive an e-mail for confirmation of your registration) we process the personal data that you provided us with voluntarily in the course of the registration for the newsletter (your e-mail address and potentially your name) (i) for sending you e-mail newsletters about our current projects, marketing and product information as well as (ii) for measuring your reading habits of our newsletter and (iii) to transmit your provided data within our group, namely to IXOLIT GmbH, FN 213107v and IXOPAY GmbH, FN 451099g (each Mariahilfer Straße 77-79, 1060 Vienna), which can send you e-mail newsletters for the same purposes as well.
Reading habits: Within our newsletters we use a mechanism to determine whether our newsletter is opened, when it is opened and what links are clicked. The sole purpose of these statistical evaluations is to assess your reading habits and to adjust the contents to them. No data is passed on to third parties.
You can withdraw your consent to the receipt of our newsletter at any time (e.g. via e-mail to firstname.lastname@example.org or through the unsubscribe link in our e-mail newsletters) with effect for the future and free of charge. After receipt of your withdrawal we, and all other the Group Members, will stop sending further e-mail newsletters immediately and erase your personal data from the mailing list.
2.5. Registration and User Account
When you are registered on our Website and have a user account for the use of our Online Services, we process the following personal data: title, name, company, e-mail address, address, telephone number, IP address, VAT number as well as your access data.
We process the data of your user account solely for operating your account, the provision of our Online Services as well as for the billing of our services. This data processing is therefore necessary for the fulfilment of our (pre)contractual obligations.
3.1. Cookies are files that are transmitted from our web server to your web browser and are stored on your device for later retrieval. Through such cookies, our Website can store important data to provide you with our services and to make the use of our Website more comfortable for you.
3.2. Most of the cookies that are used by us are so called "session cookies" that are stored on your device for the time of your current visit of our Website, only. This temporary cookies make a conformable use of our Website possible for you (e.g. through adaptation of user settings for the sorting of references and choice of language according to your needs). Session cookies are just valid for the duration of your specific visit of our Website and are subsequently erased automatically. Moreover, we also use "persistent cookies" that stay on your device and are not erased automatically when you close your browser. You can, of course, erase these cookies yourself at any time. With persistent cookies we especially pursue the purpose to improve your user experience by customising the Website to your personal needs and thus to optimise the loading time accordingly.
3.3.a) Google Tag Manager: Our Website uses the "Google Tag Manager". This service is strictly necessary to implement and manage the Google Analysis and Marketing services into our Website according to your Cookie Settings. Google Tag Manager does not use or set cookies.
3.3.b) Referrer ID: Our Website uses a "ReferrerID Cookie" for the duration of the session if you visit links on websites of our business partners that refer to our Website, for the purpose of statistical evaluations regarding the website from which you were referred to our Website. By means of this cookie we do not process personal data (§ 96 (3) TKG) and do not use "hidden identifiers" or other similar devices. Third parties cannot access the collected anonymous information.
3.4. Cookie Settings
You can accept or reject individual or all types of cookies that are not strictly necessary easily via our tool "Cookie Settings". Thereunder, we also inform you on the types of cookies we use on this Website.
Please also note: Most internet browsers accept cookies by default. You can adjust your internet browser settings so that cookies are only placed with your explicit consent, are generally rejected or stored cookies are removed. In order to do so, please follow the instructions provided by your respective internet browser’s producer:
- Explorer: https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies
- Chrome: https://support.google.com/chrome/answer/95647?hl=en
- Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
- Safari: https://support.apple.com/en-gb/guide/safari/sfri11471/mac
- Opera: https://help.opera.com/en/latest/web-preferences/#cookies
3.5. Cookies for which consent is required
Provided that you have given consent to Reporting Cookies, we use Universal Analytics, a web analysis service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google") on our Website. The information generated through the Universal Analytics Cookie about the use of the Website are usually transmitted to the servers of Google in the United States of America and stored there. Google commits under current data processing agreements to maintain a mechanism that facilitates transfers of personal data outside of the EU as required by the GDPR.
Google will use this information on our behalf to evaluate the usage of our Website by the users, to assemble reports about the activities on our Website and to deliver to us further services connected to the use of the Website. In doing so, pseudonymised user profiles of users can be generated from the processed data. Google will also potentially transmit the data to third parties if legally required or third parties process the data on behalf of Google.
If you have not given your consent, we use Universal Analytics only with activated IP Anonymization. This means that IP addresses are shortened by Google as soon as data is received by the Google Analytics Collection Network, before any storage or processing takes place. To our knowledge, the IP address transmitted from your browser is not merged with other data of Google.
You can prevent the general use of Google Analytics by downloading and installing the browser plug-in available through the following link: https://tools.google.com/dlpage/gaoptout. You can find out more information about the data usage through Google, setting and objection possibilities on the websites of Google: https://policies.google.com/technologies/partner-sites
We use the online marketing service "Google Ads" (formerly: "Google Adwords"). Google Ads is considered as profiling. Through the information collected, we can access statistics and particularly find out the total number of users that have clicked on our advertisements or that were forwarded to a Website of our Online Presence through a Google search or through the Google Display Network.
On our behalf, Google Ads furthermore uses advertising functions of Google's Universal Analytics service to place advertisements to target groups provided by Google on the basis of the consents given to Google by the individual users.
You can object to these processing activities by using the Opt-out service provided by Google: https://adssettings.google.com/authenticated. Please find more general information about data use for marketing purposes by Google through the data protection notice of Google under https://policies.google.com/privacy
Provided that you have given consent to Marketing Cookies, we use the Conversion Tracker of the Google Ads service. In this case every Google Ads client (and therefore also us) receives a different so called "Conversion-Cookie", allowing us to obtain information to assess the advertisement efficiency across our Websites and on websites of our marketing- & advertising partners. For further information of Google regarding Conversion-Tracking please see https://support.google.com/google-ads/answer/1722022
4. Additional embedded services and contents of third parties
Within our Online Services, we use further services and contents of third party providers to incorporate their contents and services on the basis of our legitimate interests in the provision, optimisation and economical operation of our Online Services. This requires that the third parties providing said content receive the IP address of the user, as otherwise they are not able to send the requested contents to the right browser. The IP address is therefore necessary for the display of these contents and the use of the embedded services.
Specifically, we use the following services and contents of third parties in our Online Services:
5. Is your data transmitted to third parties?
5.1. To the extent necessary, we provide your personal data to the following service providers (acting as “processors”) outside IXOLIT Group that support us in the performance of our Online Services:
- IT-service providers and/or providers of data hosting solutions or similar services;
- Other service providers, providers of tools and software solutions that support us with the performance of our services as well and operate on our behalf (including providers of marketing tools, marketing agencies, communication service providers).
All our processors have been contractually bound to process your data only on our behalf and on the basis of our instructions so that we can provide you with our Online Services.
5.2. Processing of your data in a third country outside the European Union (EU), respectively the European Economic Area (EEA) or when using services of third parties is only carried out where it is necessary for the performance of our (pre)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of legitimate interests. We have implemented suitable and appropriate guarantees to develop a way of transmission of your data to the respective third country compliant with data protection (e.g. by concluding so-called "EU-Standard Contractual Clauses"). Upon your request we can transmit a copy of those suitable guarantees to you, provided that we process or let your data be processed in third countries.
6. Retention period
6.1. We store your personal data just as long as necessary for the purposes for which they are processed. Beyond that, we are potentially obligated to store your data for longer in accordance to legal retention periods.
6.2. Specifically, we store your data in connection with the establishment of contact with us in accordance with legal retention periods (inter alia § 212 BAO, §132 UGB) for a time period of usually seven years.
6.3. Server log files are stored for a maximum time period of 15 days and are erased subsequently.
6.4. We store your usage data for the time period stated in Cookie Settings, "Report Cookies", but at the latest until you withdraw your consent (eg. by disabling cookies).
6.5. If you are no client of us and have registered for our newsletter only, we store your data until you withdraw your consent.
6.6. We store data in connection with your registration and your user account until the end of your client relationship with us, or respectively beyond that until the expiry of the respective legal retention periods (usually for a time period of seven years, see above).
6.7. Apart from that, we store your personal data for a time period beyond the above-mentioned, as long as legal claims out of the relationship between you and us are enforceable and only if such litigation becomes apparent, or respectively until the definitive settlement of an incident or court proceedings. Such processing is based on legitimate interests for the establishment, exercise or defence of legal claims.
7. Your Rights under applicable Data Protection Law
7.1. You have the right to access your personal data that is being processed by us (Art 15 GDPR). Apart from that, you have the right to rectification of inaccurate or incomplete data (Art 16 GDPR). You have a right to erasure if (i) your personal data is no longer necessary for the purposes for which we have collected it, (ii) you withdraw your consent and there is no other legal basis for processing by us (cf. Section 3), (iii) you object to the processing and there are no overriding legitimate grounds for the processing (except in the case of processing for direct marketing purposes), (iv) your personal data has been unlawfully processed or (v) for compliance with our legal obligations (Art 17 GDPR)be. Additionally, you have the right to restriction of processing (Art 18 GDPR) as well as the right to data portability concerning the data you have provided us with (Art 20 GDPR).
7.2. We may process your data on the basis of legitimate interests (cf Sections 2.2) in which case you have the right to object. In the case you object to the processing, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing of this data which override your interests, rights and freedoms (weighing of interests) or for the establishment, exercise or defence of legal claims.
In particular, you may object at any time to the processing of your data for the purposes of direct marketing of the IXOLIT Group. In the case of such an objection, we will no longer process your personal data for these purposes (no weighing of interests).
7.3. Additionally, you have the right to withdraw your consent at any time with effect for the future.
7.4. Finally, you have the right to lodge a complaint with the responsible supervisory authority (Art 77 GDPR).
7.5. If you have questions relating to this or to make use of your data subject rights, please feel free to contact us at:
IXOLIT GmbH / IXOPAY GmbH
Mariahilfer Straße 77-79, 1060 Wien
8. Data security
We comply with appropriate technical and organisational security measures pursuant to Art 32 GDPR to, considering the risks, guarantee an appropriate data protection level, especially to protect your personal data against accidental or unlawful destruction, alteration or against loss and against unauthorised disclosure or unauthorised access.
Version: 26. Aug 2020