Hello, and thank you for your interest in our website. Purely for reasons of better readability, the following explanations do not use male, female and diverse language forms simultaneously. All references to persons apply to all genders: m/f/x. Alongside these and other matters, we also take your rights to privacy, data protection and informational self-determination very seriously. We would therefore like to inform you of the following:
Who are we?
We are think modular - digital solutions GmbH, Ebendorferstraße 3/14, 1010 Vienna, Austria, telephone: +43 01 9974355, info@think-modular.com, represented by our managing directors Christian Zange and Gerald Henzinger.
Our data protection officer is heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, datenschutz@heydata.eu.
What happens when you use the website purely for informational purposes?
If you use our website purely for informational purposes — that is, if you neither register as a user nor otherwise transmit information to us — we collect the following data from you: IP address, date and time of the request, time zone difference from Greenwich Mean Time (GMT), content of the request (the specific page), access status / HTTP status code, the respective amount of data transferred, the website from which the request originates, browser, operating system and its interface, and the language and version of the browser software. We receive this data via cookies and directly from your browser.
The purpose of this processing is to provide our website and to carry out statistical analysis.
The legal basis for this is Article 6(1)(1)(f) GDPR, according to which the processing of personal data is permitted even without the consent of the data subject where the processing is necessary to safeguard the legitimate interests of the controller or of a third party, provided that the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data do not override those interests, in particular where the data subject is a child. The purposes referred to in paragraph 2 are in our commercial interest. Insofar as we use cookies, we refer you — in particular with regard to the maximum storage period — to our explanations under "How do we use cookies on this website?".
There is no legal obligation to process this data.
What happens when you use our contact field?
If you communicate with us via our contact field, we collect the data that you enter there.
Only you know the reasons for contacting us; our response to it describes the purpose of our processing.
Insofar as it concerns a specific obligation — whether in connection with the initiation, performance or termination of that obligation — the legal basis for the processing is Article 6(1)(b) GDPR, because in that case the communication is necessary for the initiation, performance and termination of the obligation. We always store this personal data until the end of the contractual relationship between us. In this case, we also process your data in order to fulfil legal obligations to which we are subject. The legal basis is Article 6(1)(1)(c) GDPR, §§ 131, 132 of the Federal Fiscal Code (Bundesabgabenordnung), § 212 of the Austrian Commercial Code (UGB). We may therefore be obliged to:
retain data relating to you that arises from books and records within the meaning of §§ 131, 132 of the Federal Fiscal Code for seven years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6(1)(1)(c) GDPR in conjunction with § 132 BAO);
retain data relating to you that arises from books, inventories, opening balance sheets, annual financial statements including management reports, consolidated financial statements including consolidated management reports, business letters received, copies of business letters sent, and vouchers for entries in the books we are required to keep pursuant to § 190 UGB, for seven years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6(1)(1)(c) GDPR in conjunction with § 212 UGB).
In all other cases, the legal basis is Article 6(1)(1)(f) GDPR, according to which the processing of personal data is permitted even without the consent of the data subject where the processing is necessary to safeguard the legitimate interests of the controller or of a third party, provided that the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data do not override those interests, in particular where the data subject is a child. Communication outside of an obligation is in our mutual interest, as we need to review your request. We store your data until the purpose arising from the legitimate interest has been fulfilled and until any retention obligations within the meaning of Article 6(1)(1)(c) GDPR that may arise no longer exist.
Unless express reference is made to Article 6(1)(1)(c) GDPR, there is no legal obligation to process the data.
What happens when you register for and use the internal area?
If you register for the internal area, we collect the data that you provide during the registration process. For details, we refer you to our Customer Privacy Policy.
Where and how do we maintain company pages on social networks (social media)?
We currently maintain company pages on the following social networks:
We have no influence over the data collected and the data processing operations, nor are we aware of the full extent of the data collection, the purposes of the processing, or the storage periods. We also have no information about the deletion of the collected data by the respective provider.
When you select our company pages, it is possible that the respective provider stores the data collected about you as usage profiles and uses this data for the purposes of advertising, market research and/or the needs-based design of its website. You have the right to object to the creation of these user profiles, and to exercise this right you must contact the respective provider.
Further information on the purpose and scope of the data collection and its processing by the respective provider can be found in the privacy policies of these providers set out below. There you will also find further information on your rights in this regard and on the settings available to protect your privacy.
Insofar as you maintain a profile with these social networks yourself, the legal basis is your consent within the meaning of Article 6(1)(1)(a) GDPR, which you have granted to the respective provider of the social network. In all other cases, the legal basis is Article 6(1)(1)(f) GDPR, according to which your data may be processed insofar as this is necessary to safeguard our legitimate interests or the interests of a third party, provided that your interests or fundamental rights and freedoms requiring the protection of personal data do not override those interests, in particular where the data subject is a child. We have a commercial interest in linking to our company pages, whereby you click on the links independently and voluntarily. In all other respects, the providers of the respective social networks are responsible, and for details we refer you to paragraph 7.
Additional information:
Facebook Inc., 1601 S. California Avenue, Palo Alto, CA 94304, USA. If and insofar as we analyse visitor interactions with our company page, we are jointly responsible with Facebook under data protection law in this respect, pursuant to Article 26 GDPR. The relevant agreement can be found here: https://www.facebook.com/legal/terms/page_controller_addendum. If and insofar as we instruct Facebook to process data for us beyond this, we are the controller within the meaning of Article 28 GDPR. The relevant agreement can be found here: https://www.facebook.com/legal/terms/dataprocessing. Palo Alto, California 94304, USA; http://www.facebook.com/policy.php. The data processing operations are also not precluded by the fact that the data may be processed by Facebook outside the European Union, because Facebook is listed under the Privacy Shield Framework, so that in this respect Article 45 GDPR in conjunction with the Commission Implementing Decision (EU) 2016/1250 of 12 July 2016 justifies the use of this provider. A privacy policy of the provider can be found here: https://www.facebook.com/policy.php.
Twitter, Inc., 1355 Market St, Suite 900, San Francisco, California 94103, USA. If and insofar as we analyse visitor interactions with our company page, we are jointly responsible with Twitter under data protection law in this respect, pursuant to Article 26 GDPR. The relevant agreement can be found here: https://gdpr.twitter.com/en/controller-to-controller-transfers.html. If and insofar as we instruct Twitter to process data for us beyond this, we are the controller within the meaning of Article 28 GDPR. The relevant agreement can be found here: https://gdpr.twitter.com/en/dpa.html. The data processing operations are also not precluded by the fact that the data may be processed by Twitter outside the European Union, because Twitter is listed under the Privacy Shield Framework, so that in this respect Article 45 GDPR in conjunction with the Commission Implementing Decision (EU) 2016/1250 of 12 July 2016 justifies the use of this provider. A privacy policy of the provider can be found here: https://twitter.com/privacy.
Xing AG, Dammtorstraße 30, 20354 Hamburg, Germany. A privacy policy of the provider can be found here: http://www.xing.com/privacy.
LinkedIn Corporation, 2029 Stierlin Court, Mountain View, California 94043, USA; http://www.linkedin.com/legal/privacy-policy. If and insofar as we analyse visitor interactions with our company page, we are jointly responsible with LinkedIn under data protection law in this respect, pursuant to Article 26 GDPR. The relevant agreement can be found here: https://legal.linkedin.com/pages-joint-controller-addendum. If and insofar as we instruct LinkedIn to process data for us beyond this, we are the controller within the meaning of Article 28 GDPR. The relevant agreement can be found here: https://legal.linkedin.com/dpa/DE. The data processing operations are also not precluded by the fact that the data may be processed by LinkedIn outside the European Union, because LinkedIn is listed under the Privacy Shield Framework, so that in this respect Article 45 GDPR in conjunction with the Commission Implementing Decision (EU) 2016/1250 of 12 July 2016 justifies the use of this provider. A privacy policy of the provider can be found here: https://www.linkedin.com/legal/privacy-policy.
(7) Unless express reference is made to Article 6(1)(1)(c) GDPR, there is no legal obligation to process the data.
How do we use YouTube videos?
We have embedded YouTube videos into our online offering that are stored on http://www.YouTube.com and can be played directly from our website. These are all embedded in "enhanced privacy mode", which means that no data about you as a user is transmitted to YouTube if you do not play the videos. Only when you play the videos is the data referred to in paragraph 2 transmitted. We have no influence over this data transmission.
By visiting the website, YouTube receives the information that you have accessed the relevant subpage of our website. In addition, the data referred to in paragraph 3 is transmitted. This happens regardless of whether YouTube provides a user account through which you are logged in, or whether no user account exists. If you are logged in to Google, your data is assigned directly to your account. If you do not wish your data to be associated with your YouTube profile, you must log out before activating the button. YouTube stores your data as usage profiles and uses it for the purposes of advertising, market research and/or the needs-based design of its website. Such an analysis is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and to exercise this right you must contact YouTube.
Further information on the purpose and scope of the data collection and its processing by YouTube can be found in the privacy policy. There you will also find further information on your rights and the settings available to protect your privacy: https://www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
We also maintain a company page with this provider. If you interact with this company page, it is possible that the provider processes your data as described in paragraphs 2 and 3.
The legal basis is your consent within the meaning of Article 6(1)(1)(a) GDPR, which you have granted via our cookie banner and which you can revoke, in particular, by deactivating it in the cookie banner. Upon revocation, we delete the data immediately. Without revocation, at the latest after 14 months.
The legal basis for the processing that takes place to obtain consent is Article 6(1)(1)(c) GDPR. Under this provision, we may process your data where this is necessary to fulfil a legal obligation to which we are subject. The legal obligation to which we are subject arises from Article 7(1) GDPR and Article 5(1) GDPR respectively. According to these provisions, we are legally obliged to document the obtaining of consent. This is only possible if we collect your data for evidentiary purposes. We store the data for as long as this is necessary for evidentiary purposes. If you confirm your consent, the retention period ends only after you revoke your consent, plus the time until any civil-law claims become time-barred, i.e. generally on 31 December of the third calendar year following the year in which you revoked your consent.
Unless express reference is made to Article 6(1)(1)(c) GDPR, there is no legal obligation to process the data.
Tracking with Matomo
On our website we use Matomo (formerly "PIWIK"). This is open-source software that allows us to analyse the use of our website. In doing so, your IP address, the website(s) of our online presence that you visit, the website from which you switched to our online presence (referrer URL), the length of time you spend on our website, and the frequency with which you access one of our websites are processed.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the analysis and optimisation of our website.
However, we use Matomo with the anonymisation function "Automatically Anonymize Visitor IPs". This anonymisation function shortens your IP address by two bytes, so that it is impossible to attribute it to you or to the internet connection you use.
In addition, you have the option to stop the analysis of your usage behaviour by way of a so-called opt-out.
We have configured Matomo so that no additional cookies are necessary.
How do we use cookies on this website?
Furthermore, cookies are stored on your computer when you use the website. Cookies are small text files that are stored on your hard drive, assigned to the browser you are using, and through which certain information flows to the entity that sets the cookie (in this case, us). Cookies cannot execute programs or transmit viruses to your computer. They serve to make the internet offering as a whole more user-friendly and effective.
We use transient cookies. Transient cookies are automatically deleted when the user closes the browser. These include, in particular, session cookies. These store a so-called session ID, which allows various requests from the visitor's browser to be assigned to the shared session. This enables the visitor's computer to be recognised when the visitor returns to your website. The legal basis for this is Article 6(1)(1)(f) GDPR, according to which the processing of personal data is permitted even without the consent of the data subject where the processing is necessary to safeguard the legitimate interests of the controller or of a third party, provided that the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data do not override those interests, in particular where the data subject is a child. The purposes referred to in paragraph 2 are in our commercial interest. Insofar as we use cookies, we refer you — in particular with regard to the maximum storage period — to the explanation for the respective cookie.
We use persistent cookies. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. The legal basis is your consent within the meaning of Article 6(1)(1)(a) GDPR, which you have granted via our cookie banner and which you can revoke, in particular, by deactivating it in the cookie banner. Upon revocation, we delete the data immediately. Without revocation, at the latest after 14 months.
The legal basis for the processing required under paragraph 3 to obtain consent is Article 6(1)(1)(c) GDPR. Under this provision, we may process your data where this is necessary to fulfil a legal obligation to which we are subject. The legal obligation to which we are subject arises from Article 7(1) GDPR and Article 5(1) GDPR respectively. According to these provisions, we are legally obliged to document the obtaining of consent. This is only possible if we collect your data for evidentiary purposes. We store the data for as long as this is necessary for evidentiary purposes. If you confirm your consent, the retention period ends only after you revoke your consent, plus the time until any civil-law claims become time-barred, i.e. generally on 31 December of the third calendar year following the year in which you revoked your consent.
Unless express reference is made to Article 6(1)(1)(c) GDPR, there is no legal obligation to process the data.
Do we ensure adequate data security?
We maintain up-to-date technical measures to ensure data security, in particular to protect your personal data against risks during data transmission and against being accessed by third parties. These are adapted in each case in line with the current state of the art.
What rights do you have?
You have a number of rights. You have the right to obtain information about the personal data processed about you, as well as the right to rectification or erasure, to restriction of processing, to object to the processing, and to data portability. You also have the option of lodging a complaint about us with the supervisory authority responsible for us. We would politely point out that these rights may be subject to conditions, on the fulfilment of which we will insist.