Data protection declaration in accordance with Art. 13, 14 GDPR – fulfilment of information obligations
Thank you for visiting our website. We place great emphasis on safeguarding your data within our organization and provide you with comprehensive details regarding our data processing procedures.
Our privacy policy provides you with insights into data processing within Wertheim Vertriebsgesellschaft m.b.H. and when using the Wertheim Vertriebsgesellschaft m.b.H website. The legal basis for this processing is the General Data Protection Regulation (hereinafter “GDPR”) and the Austrian Data Protection Act (“DSG”).
1 Responsible for data processing
The controller pursuant to Art. 4 para. 7 GDPR is
Wertheim Vertriebsgesellschaft m.b.H.
Danfoss Street 6
2353 Guntramsdorf
Tel: +43 (0)2236 320 350 – 0
Fax: +43 (0)2236 320 350 – 21
E-mail: office@wertheim.at
The company has appointed Mrs. Birgit von Maurnböck as external data protection officer. She can be contacted at bvm@meineberater.at.
2 Data processing in the business environment
2.1 Data processing in accordance with Art. 13 GDPR
We process data that is transmitted to us by various people, for example while registering a customer account, as part of an application and generally when concluding contracts.
2.2 Data processing in accordance with Art. 14 GDPR
In addition, we process personal data that is not provided by the data subject themselves. This is the case, for example, when managing directors provide us with the names and contact details of their employees during collaboration on projects or business relationships.
2.3 Affected persons
We process the following data from interested parties: Company, name of contact person and professional contact and address data.
The following data is processed from customers (companies): Company, name of contact persons, professional address and contact data, bank details and contract data.
We process the following data from suppliers and sales partners: Company, names of contact persons, professional address data and contact details, bank details, contract data.
We process and publish the names of authors in connection with those works (photos or videos) that were created by them.
2.4 Legal basis
The legal basis for data processing is:
– consent (e.g. use of analysis tools on the website) pursuant to Art. 6 para. 1 lit. a GDPR
– the initiation and fulfillment of the contract pursuant to Art. 6 para. 1 lit. b GDPR
– legal obligations (e.g. statutory retention and documentation obligations, publication obligations under copyright law) pursuant to Art. 6 para. 1 lit. c GDPR,
– legitimate interests of our company (e.g. use of software) pursuant to Art. 6 para. 1 lit. f GDPR
We will inform you separately about the legal basis and the purpose of the processing for each data processing operation described below.
2.5 Forwarding of data
Your personal data will be passed on for the purpose of fulfilling the contract in accordance with Art. 6 para. 1 lit. b GDPR in order to provide you with our services.
– Transfer within the Group: The personal data we collect is transferred to the holding company within the Group where necessary. This happens because the holding company provides IT services for us, among other things. The transfer takes place on the basis of internally concluded contracts.
– Disclosure to processors: We work with processors and transfer personal data to them in order to provide our services efficiently. These include companies that handle contract fulfillment, payments, account management and IT services, for example.
– Other disclosure: We reserve the right to disclose personal data to authorities or lawyers, for example, if this is required by law or in the context of a legal dispute.
2.6 Storage/deletion of data
– Contractual retention obligations: After termination of a contractual relationship or after the end of contractually agreed periods, we delete or anonymize your data, provided that this does not conflict with any statutory retention periods.
– Withdrawal of consent: If you withdraw your consent to the processing of your personal data, we will delete or anonymize your data unless there is another legal basis for the processing.
– Statutory retention obligations: To comply with statutory retention periods (e.g. based on tax laws – or accounting regulations), we are obliged to continue to store personal data for a period specified by law even after the end of the contract or revocation of consent. After these periods have expired, we will delete or anonymize your data.
2.7 Contact us
If you contact us by email, telephone, contact form or via social media, we store the data you provide to respond to your inquiries. Once processing is complete, we delete the data or restrict its processing in accordance with applicable statutory retention obligations.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
2.8 Applicants
– General: If you send us your application documents, we will process your personal data contained therein for the purpose of personnel selection and recruitment. In the event of a rejection, we will delete your documents 7 months after sending the rejection to you.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract initiation and fulfillment)
If we wish to keep you on record for the purpose of contacting you at a later date, we will approach you with a separate request for your consent. If you explicitly give us this consent, we will store your application documents. If there is no further opportunity to fill a position with us within one year, we will delete all your applicant data one year after you have given us your consent.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
– Application platforms: We use various online application platforms to recruit employees for our company. People who are interested in working for our company have the opportunity to apply directly via a form provided by the operator of the application platform. Applicants decide for themselves which data they make available in the course of using such an online portal. They also have the option of uploading application documents. Personal data entered and documents uploaded will be forwarded to us by the operator of the applicant portal. Both the application platform and we as a company are responsible for processing this data as the controller within the meaning of the GDPR. Please note the data protection declarations of the respective portal operators.
Legal basis: Art. 6 para. 1 lit. b (contract initiation and fulfillment)
2.9 Author
We are legally obliged to state the names of the authors of image data (photos or videos) each time they are published. As soon as the use of this image data is discontinued, this personal data is automatically deleted.
3 Registration and login on our website
You have the option to register on our website. To do this, we require login data consisting of your e-mail address or username and a password of your choice, which you can reset at any time if you forget it. The following data is mandatory when registering: First name, last name, address, e-mail address and username. You can edit the data you have entered at any time in the account settings. We generate a customer number that is also linked to your customer account. You can log in to our website at any time using your login data. With your customer account, you can set up and save vault configurations.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract initiation and fulfillment)
4 Social media presence
We operate the following social media channels: LinkedIn and YouTube. When you visit our social media presence, personal data, including the IP address of the respective provider, is processed and cookies are used for data collection. Please refer to the privacy policy of the respective service to find out exactly what information is transmitted. There you will also find information about contact options and ways to restrict the processing of this data.
We would also like to point out that you use the respective services and their functions on your own responsibility. This applies in particular to the use of interactive functions (e.g. sharing, commenting or rating).
The providers of the social media services have supplied us with corresponding agreements – in most cases these are agreements on joint responsibility for data processing. The use of social media is based on our legitimate business interests.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
5 Informational use of the website
When using the website for information purposes only, we only collect the personal data that your browser transmits to our server (server log files). If you wish to view our website, we collect at most the data that is technically necessary for us to display our website to you and to ensure stability and security:
• IP address
• Date and time of the request
• Time zone difference to Coordinated Universal Time (UTC)
• Content of the request (specific page)
• Access status/HTTP status code
• Website from which the request comes
• Browser
• Operating system and its interface
• Language and version of the browser software
This data is not merged with personal data sources. We reserve the right to check this data retrospectively if we become aware of specific indications of unlawful use and – if there has been a hacking attack – to pass the data on to the law enforcement authorities. The data will not be passed on to third parties beyond this.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
6 Cookies
Cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard disk assigned to the browser you are using and through which certain information flows to the place that sets the cookie (in this case by us or third-party providers). Cookies cannot execute programs or transmit viruses to your computer.
The cookie allows you to be recognized when you visit the website without having to re-enter data that you have already entered.
The information contained in the cookies is used, for example, to determine whether you are logged in or what data you have already entered, or to recognize you as a user when a connection is established between our web server and your browser.
We distinguish between technical cookies that are used exclusively to ensure the operation of a website and other cookies that are set by us or third-party providers for the purposes of statistical analysis, tracking or advertising/marketing.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest; for technical cookies), Art. 6 para. 1 lit. a GDPR (consent; for all other cookies)
7 Data processing for services provided by Automattic
Our website uses the services of WordPress.com, a content management platform provided by Automattic Inc, 60 29th Street 343, San Francisco, 94110 California, USA.
Aut O’Mattic A8C Ireland Ltd, Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland, is responsible for the European region.
Further information can be found in the privacy policy of Automattic Inc. at https://automattic.com/de/privacy/.
7.1 WordPress Static Files
By using WordPress, so-called “static files” are used. These files contain static content such as images, CSS files and JavaScript files that are required to display the website. The use of WordPress static files enables efficient provision of website content and improves loading times for visitors to our website. These static files are stored on our own servers or, if necessary, on an external content delivery network (CDN). A CDN can be used to optimize the delivery of static files by storing them on servers in different locations worldwide. When using WordPress Static Files, no personal data is collected or processed unless you actively provide such data via forms or other interactions on the website.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
7.2 WooCommerce
We have integrated the WooCommerce open source store system on our website.
The implemented functions send, store and process data to Automattic Inc. We use WooCommerce to offer you a user-friendly and secure shopping experience. WooCommerce provides the technical basis for our online store, manages your orders and integrates secure payment services. It also enables the creation and management of customer accounts, which stores order history and delivery addresses. WooCommerce helps us to personalize and improve your shopping experience by analysing purchasing behaviour and generating reports. When you register with us or order a product, Automattic can collect, process and store this data. In addition to your e-mail address, name or address, this may also include credit card or billing information. Automattic may subsequently use this information for its own marketing campaigns.
WooCommerce uses a number of different cookies that are set depending on the user action. This means, for example, that when you place a product in the shopping cart, a cookie is set so that the product remains in the shopping cart when you leave our website and return at a later time. Unless there is a legal obligation to store data for a longer period of time, WooCommerce deletes the data when it is no longer needed for the purposes for which it was stored.
Further information can be found in the privacy policy of Automattic Inc. at https://automattic.com/de/privacy/ and general information about WooCommerce at https://woocommerce.com/.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
8 Calendly
We have integrated the appointment scheduling tool ‘Calendly’, provided by Calendly, LLC, 271 17th St NW, Atlanta, GA 30363, USA, on our website. By using Calendly, you can conveniently make appointments with us online by entering your name, email address and the date and time of the appointment.
Further information can be found in Calendly’s privacy policy at: https://calendly.com/de/privacy.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
9 Cloudflare (CDN)
Our website uses a so-called “Content Delivery Network” (CDN) from Cloudflare, Inc, 101 Townsend Street, San Francisco, 94107 California, USA.
With the CDN service, website content such as web videos or other large media can be provided quickly and securely. Proxy servers store the files locally and thus improve the access speed when downloading. Using the Cloudflare CDN helps us to optimize the loading speed of our website.
The CDN service processes the IP address of the website visitor. The IP address is automatically deleted from Cloudflare’s logs.
Further information can be found in Cloudflare’s privacy policy: https://www.cloudflare.com/security-policy.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
10 Cloudinary
Our website uses Cloudinary, a service provided by Cloudinary Inc, 3400 Central Expressway, Suite 110, Santa Clara, 95051 California, USA.
This service is used to optimize the provision of images and videos. Cloudinary enables us to efficiently store and manage media files and make them available on our website. This contributes to an improved loading time and user experience. When media files are retrieved via Cloudinary, technical data such as your IP address, browser type, operating system, the previously visited website, the date and time of access and the requested file are automatically transmitted to Cloudinary. This data is processed by Cloudinary for the delivery and optimization of the media files. The data is processed for the purpose of providing media files quickly and efficiently and to improve the performance of our website.
Further information can be found in Cloudinary’s privacy policy at https://cloudinary.com/privacy.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
11 Data processing for Google services
We use the services of Google Ireland Limited (“Google”), a company incorporated and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland, on our website.
Further information can be found in Google’s privacy policy at https://policies.google.com/privacy?hl=de.
11.1 Google Analytics
On our website we use Google Analytics, a tool that helps us to understand how our website is used. With Google Analytics, we can see how many people visit our site and how long they stay.
This website uses the function “Activation of IP anonymization” (i.e. Google Analytics has been extended by the code “gat._anonymizeIp();” to ensure an anonymized collection of IP addresses (so-called IP masking)). As a result, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
Google uses the information collected to analyse your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage.
Your IP address, which is transmitted from your browser to Google Analytics, will not be merged with other Google data. However, Google may pass this information on to third parties if this is required by law or if third parties process this data on behalf of Google.
You can prevent cookies from being stored on your computer by making the appropriate settings in your browser. Please note, however, that in this case you may not be able to use all the functions of our website to their full extent.
Further information on terms of use and data protection can be found at https://www.google.com/analytics/terms/de.html or at https://support.google.com/analytics/answer/6004245?hl=de.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
11.2 Google Maps
We use the Google Maps service on this website. This allows us to show you interactive maps directly on the website and enables you to use the map function conveniently. When you visit the website, Google receives the information that you have accessed the corresponding subpage of our website. In addition, the data already mentioned under “Informational use of the website” is transmitted. This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data will be assigned directly to your account. If you do not wish your data to be associated with your Google profile, you must log out before activating the button. Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right.
The integration of Google Maps leads to the reloading of other Google services on our website, in particular Google Static and Google Fonts.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
11.2 Google Tag Manager
We use the Google Tag Manager on our website, which enables us to integrate and manage website tags such as tracking codes or conversion pixels. This collects data on the website and forwards it to associated analysis tools, which store and analyse this data. Although the Google Tag Manager collects data (e.g. IP address), it does not store it and has no access to it. It merely acts as an interface between the website and the analysis software.
You can find more detailed information here: https://www.google.com/intl/de/tagmanager/faq.html.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
12 Hotjar
We use Hotjar, an analytics tool provided by Hotjar Ltd, Dragonara Business Centre 5th Floor, Dragonara Road, Paceville St Julian’s, STJ 3141, Malta, to analyse user behaviour on our website and improve usability. Hotjar enables us to better understand the behaviour of our users on our website by recording activities such as mouse clicks, mouse movements and scrolling behaviour. This information helps us to adapt our website to the needs of our visitors and make it more user-friendly.
Hotjar uses cookies and other technologies to collect data about the behaviour of our users and their end devices, in particular the IP address of the device (in anonymized form), screen size, device type (unique device identifiers), browser information, geographical location (country only) and preferred language for displaying our website. The information is neither used by Hotjar nor by us to identify individual users or merged with other data about individual users.
Further information can be found in Hotjar’s privacy policy at https://www.hotjar.com/legal/policies/privacy.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
13 Matomo
We have integrated the web analysis service Matomo from the provider InnoCraft Limited, 7 Waterloo Quay, PO625, 6140 Wellington, New Zealand on our website for the statistical analysis of user behavior and for optimization and marketing purposes.
The following data is processed: Browser type, browser version, operating system, country of origin, date and time of the server request, number of visits, time spent on the website and the external links you click on. The IP address is anonymized before it is saved. Pseudonymized user profiles can be created and evaluated from this data. The data collected is processed on our servers and is not passed on to third parties.
The information generated in the pseudonymous user profile is not used to personally identify the website visitor and is not merged with personal data about the bearer of the pseudonym.
For more information, please refer to Matomo’s privacy policy at https://matomo.org/privacy-policy.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
14 SourceBuster JS
We use the open source software Sourcebuster.js on our website, which is provided by the developer community and is not operated by a specific provider. The software is integrated on our website to analyse the origin and traffic data of visitors.
Our website uses Sourcebuster.js, a JavaScript plugin, to analyse the origin and traffic of our website visitors. Sourcebuster.js helps us to collect and analyse information about the source of visitors (e.g. search engine, referral website, campaign). This data is used to evaluate the success of our marketing measures and to improve the user experience on our website. Sourcebuster.js collects information such as the referrer URL, the search engine used, the search terms entered and the campaign name (if applicable). This data is processed anonymously and does not allow any conclusions to be drawn about your person.
As this service is hosted locally on the web server, no data is transferred to third parties.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
15 Storepoint
Our website uses the Storepoint service, provided by Storepoint, Inc, 862 Richmond Street W, Toronto, ON M6J 1C9, Canada, to display interactive maps and location information. Storepoint enables us to provide you with a user-friendly map that allows you to easily find [e.g. our locations, stores or other relevant places].
When you use the Storepoint cards, technical data such as your IP address, browser type, operating system, the previously visited website, the date and time of access and location information (if enabled) may be automatically transmitted to Storepoint. This data is processed by Storepoint in order to provide and optimize the map functionality.
The integration of Storepoint leads to the reloading of Storepoint icons on our website.
For more information, please refer to Storepoint’s privacy policy at https://storepoint.co/privacy.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
16 Usercentrics (Cookiebot)
We use the Usercentrics Cookiebot consent banner from Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, to obtain data protection-compliant consent for the use of cookies and services requiring consent on our website.
The consent banner records and stores the selection of cookies and services requiring consent of the respective user of our website. The explicit consent of the website visitor ensures that statistical, functional and marketing cookies and services requiring consent are only then set.
The consent tool records, logs and stores the website visitor’s settings for the duration of the session. Cookiebot collects, transmits and stores certain user information (including the IP address) so that the selected settings can be clearly assigned to the respective website visitor.
For more information, please refer to the privacy policy of Usercentrics https://usercentrics.com/de/datenschutzerklaerung/ and Usercentrics Cookiebot https://www.cookiebot.com/de/privacy-policy/.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
17 Your rights
You have the following rights towards us about your personal data:
• Right to information, correction and deletion
• Right to restriction of processing
• Right to object to the processing
• Right to data portability
• Right to lodge a complaint with the Austrian data protection authority
Barichgasse 40 – 42, 1030 Vienna, Telephone: +43 1 52 152-0
E-mail: dsb@dsb.gv.at
If you are of the opinion that we have violated Austrian or European data protection law in the processing of your data and thereby infringed your rights, please contact us so that we can clarify any questions you may have.
Please send your inquiries and concerns by e-mail to office@wertheim.at or contact us using the contact details provided.
18 Changes to this privacy policy
We reserve the right to make changes to our privacy policy from time to time. We will publish all changes to the privacy policy on this page. Please refer to the latest version of our privacy policy in this regard.