I. Scope and legal basis
The protection of your personal data is of particular concern to me. I therefore process your data exclusively on the basis of the legal provisions (DSGVO, TKG 2003). In this data protection information I inform you about the most important aspects of data processing within the framework of my website.
The legal basis for data protection can be found in the Federal Data Protection Act (BDSG) and the Telemedia Act (TMG).
Relevant legal basis
II. This is me “Responsible Provider”
The address of my website is https://www.tipatclick.com
You can reach me under the following contact details:
Mag.Komm. Ulrike Huemer, E-Mail firstname.lastname@example.org, Tel.: +43 662 254648-01
Contact with and to me
If you contact me via a form on this website or via email, my Facebook channel, my XING profile or my Twitter account, the data you provide will be stored for six months for the purpose of processing your enquiry and in case of follow-up questions. I will not pass on this data without your consent.
III. Your rights
In principle, you have the rights to information, correction, deletion, restriction, data transferability, revocation and objection. If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you can complain to the supervisory authority. In Austria, this is the data protection authority.
Revocation, changes, corrections and updates
Every user has the right, upon request and free of charge, to obtain information about the personal data stored about him or her. In addition, users have the right to correct incorrect data, block and delete their personal data, insofar as this does not conflict with any legal obligation to retain data.
IV. Handling of personal data
Personenbezogene Daten sind Informationen, mit deren Hilfe eine Person bestimmbar ist, also Angaben, die zurück zu einer Person verfolgt werden können. Dazu gehören der Name, die Emailadresse oder die Telefonnummer. Aber auch Daten über Vorlieben, Hobbies, Mitgliedschaften oder welche Webseiten von jemandem angesehen wurden zählen zu personenbezogenen Daten.
„Personenbezogene Daten“ sind alle Informationen, die sich auf eine identifizierte oder identifizierbare natürliche Person (im Folgenden „betroffene Person“) beziehen; als identifizierbar wird eine natürliche Person angesehen, die direkt oder indirekt, insbesondere mittels Zuordnung zu einer Kennung wie einem Namen, zu einer Kennnummer, zu Standortdaten, zu einer Online-Kennung (z.B. Cookie) oder zu einem oder mehreren besonderen Merkmalen identifiziert werden kann, die Ausdruck der physischen, physiologischen, genetischen, psychischen, wirtschaftlichen, kulturellen oder sozialen Identität dieser natürlichen Person sind.
Personenbezogene Daten werden von mir nur dann erhoben, genutzt und weiter gegeben, wenn dies gesetzlich erlaubt ist oder Nutzer in die Datenerhebung einwilligen.
IV.I. Directory of procedures
Types of data processed
– Contact data (e.g., e-mail, name,…).
– Content data (e.g., text entries, photographs, videos).
– Usage data (e.g., web pages visited, interest in content, access times).
– Meta/communication data (e.g., device information, IP addresses).
Purpose of the processing
– Provision of the online offer, its functions and contents.
– Responding to contact requests and communicating with users.
– Security measures.
– Reach measurement for self-marketing.
– Customer care and marketing for own purposes.
“Processing” means any operation or set of operations which is performed upon personal data, whether or not by automatic means. The term is broad and covers virtually any handling of data.
IV.I.I Meta and communication data
Access Data / Server logfiles
The provider (or his web space provider) collects data on every access to the offer (so-called server log files). The access data includes:
Name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider.
The log data used is only used for statistical evaluations for the purpose of the operation, security and optimisation of the offer. However, as the provider, I reserve the right to subsequently check the log data if there is a justified suspicion of unlawful use due to concrete indications.
The hosting services used by me serve to provide the following services: Infrastructure and platform services, computing capacity, storage space and database services, security services and technical maintenance services, which are used for the purpose of operating this online offer.
In doing so, I, or the hosting provider, process inventory data, contact data, content data, contract data, usage data, meta data and communication data of customers, interested parties and visitors of this online offer on the basis of my legitimate interests in an efficient and secure provision of this online offer pursuant to Art. 6 para. 1 lit. f DSGVO in conjunction with Art. 28 DSGVO (conclusion of a contract). Art. 28 DSGVO (conclusion of order processing contract).
This website uses so-called cookies. These are small text files that are stored on your end device with the help of the browser. They do not cause any harm.
If you do not wish this, you can set up your browser so that it informs you about the setting of cookies and you only allow this in individual cases.
If you disable cookies, the functionality of this website may be limited. You can manage many online ad cookies from companies via the US site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/uk/your-ad-choices/.
Integration of third-party services and content
It may happen that third-party content, such as videos from YouTube, maps from Google Maps, RSS feeds or graphics from other websites, are integrated within this online offer. This always assumes that the providers of this content (hereinafter referred to as “third-party providers”) are aware of the IP address of the user. Without the IP address, they could not send the content to the browser of the respective user. The IP address is therefore necessary for the presentation of this content. I have no influence on whether third-party providers store the IP address, e.g. for statistical purposes.
Web-Analyse mit Google Analytics
My website uses functions of the web analysis service Google Analytics. The provider is Google Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Cookies are used for this purpose, which enable an analysis of the use of the website by your users. The information thus generated is transferred to the provider’s server and stored there.
You can prevent this by setting your browser so that no cookies are stored (see Cookies).
I have concluded a corresponding contract for commissioned data processing with the provider.
Your IP address is recorded, but pseudonymised immediately [e.g. by deleting the last 8 bits]. This means that only a rough localisation is possible.
The data processing is carried out on the basis of the legal provisions of § 96 para 3 TKG as well as Art 6 para 1 lit a (consent) and/or f (legitimate interest) of the DSGVO.
My concern in terms of the DSGVO (legitimate interest) is the improvement of my offer and this website. Since the privacy of my users is important to me, the user data is pseudonymised.
Your user data will be stored for a period of 26 months. I do not release your user data for use by Google’s sales team.
Revocation of data processing by Google
You can revoke the processing of your data by installing a plugin in your browser that disables data processing by Google Analytics https://tools.google.com/dlpage/gaoptout?hl=de.
Users may also prevent the collection of data generated by the cookie and relating to their use of the website (including their IP address) by Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
For more information on Google’s use of data for advertising purposes, settings and opt-out options, please visit Google’s websites: https://www.google.com/intl/de/policies/privacy/partners/ (“Google’s use of data when you use my partners’ websites or apps”),http://www.google.com/policies/technologies/ads (“Use of data for advertising purposes”),http://www.google.de/settings/ads (“Manage the information Google uses to show you ads”) and http://www.google.com/ads/preferences/ (“Determine what ads Google shows you”).
As an alternative to the browser add-on or within browsers on mobile devices, please click this link to prevent the collection by Google Analytics within this website in the future. This will place an opt-out cookie on your device. If you delete your cookies, you must click this link again.
You have the possibility to subscribe to a newsletter via my website. For this I need your e-mail address and your declaration that you agree to receive the newsletter.
In order to address you in a targeted manner, I also collect and process information voluntarily given about your first name.
This data is only used for sending the newsletter and will not be passed on to third parties.
When you register for the newsletter, your IP address and the date of registration are stored. This storage serves solely as proof in the event that a third party misuses an email address and registers to receive the newsletter without the knowledge of the authorised person.
As soon as you have registered for my newsletter, I will send you a confirmation email with a link to confirm your registration (“Double Opt In”).
You can cancel your subscription to the newsletter at any time. Your data will be deleted immediately in connection with the newsletter dispatch in this way.
The dispatch of the newsletter and the associated performance measurement is based on the consent of the recipients in accordance with Art. 6 Para. 1 lit. a, Art. 7 DSGVO in conjunction with § 107 Para. 2 TKG or on the basis of the legal permission in accordance with § 107 Para. 2 and 3 TKG.
You can revoke your consent to the storage of data, the email address and its use for sending the newsletter at any time. Please enter your cancellation in my unsubscribe form. You can also send your objection informally as a message to the contact options above.
Newsletter – dispatch service provider
The newsletter is sent using the dispatch service provider “MailChimp”, a newsletter dispatch platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA.
The dispatch service provider may use the recipients’ data in pseudonymous form, i.e. without attribution to a user, to optimise or improve its own services, e.g. to technically optimise the dispatch and presentation of the newsletter or for statistical purposes. However, the dispatch service provider does not use the data of my newsletter recipients to write to them itself or to pass on data to third parties.
Newsletter – performance measurement
The newsletters contain a so-called “web beacon”, i.e. a pixel-sized file that is retrieved from my server when the newsletter is opened, or if I use a dispatch service provider, from their server. In the course of this retrieval, technical information, such as information on the browser and your system, as well as your IP address and the time of the retrieval are collected.
This information is used for the technical improvement of the services on the basis of the technical data or the target groups and their reading behaviour on the basis of their retrieval locations (which can be determined with the help of the IP address) or the access times. Statistical surveys also include determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither my intention nor, if used, that of the dispatch service provider to observe individual users. The analyses serve much more to recognise the reading habits of my users and to adapt my content to them or to send different content according to the interests of my users.
IV.II. Cooperation with processors and third parties
If, in the course of processing data, I disclose data to other persons and companies (order processors or third parties), transmit it to them or otherwise grant them access to the data, this will only be done on the basis of a legal permission (e.g. if a transmission of the data to third parties, such as to payment service providers, is necessary for the performance of the contract pursuant to Art. 6 (1) lit. b DSGVO), you have consented, a legal obligation provides for this or on the basis of my legitimate interests (e.g. when using agents, web hosts, etc.).
If third parties are commissioned with the processing of data on the basis of a so-called “order processing contract”, this is done on the basis of Art. 28 DSGVO.
Transfers to third countries
If data is processed in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if this is done in the context of using third-party services or disclosing, or transferring data to third parties, this is only done if it is done to fulfil my (pre-)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of my legitimate interests. Subject to legal or contractual permissions, data will only be processed or allowed to be processed in a third country if the special requirements of Art. 44 ff. DSGVO are met. This means that the processing is carried out, for example, on the basis of special guarantees, such as the officially recognised determination of a level of data protection corresponding to that of the EU (e.g. for the USA through the “Privacy Shield”) or compliance with officially recognised special contractual obligations (so-called “standard contractual clauses”).
Use of Facebook Social Plugins
On the basis of my legitimate interests (i.e. interest in the analysis, optimisation and economic operation of my online offer within the meaning of Art. 6 para. 1 lit. f. DSGVO), I use social plugins (“Plugins”) of the social network facebook.com, which is operated by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). The plugins can display interaction elements or content (e.g. videos, graphics or text contributions) and are recognisable by one of the Facebook logos (white “f” on a blue tile, the terms “Like”, “Like” or a “thumbs up” sign) or are marked with the addition “Facebook Social Plugin”. The list and appearance of Facebook social plugins can be viewed here: https://developers.facebook.com/docs/plugins/.
Facebook is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
When a user calls up a function of this online offer that contains such a plugin, his or her device establishes a direct connection with Facebook’s servers. The content of the plugin is transmitted by Facebook directly to the user’s device and integrated into the online offer by the latter. In the process, user profiles can be created from the processed data. I therefore have no influence on the scope of the data that Facebook collects with the help of this plugin and therefore inform users according to my level of knowledge.
By integrating the plugins, Facebook receives the information that a user has accessed the corresponding page of the online offer. If the user is logged in to Facebook, Facebook can assign the visit to his or her Facebook account. If users interact with the plugins, for example by clicking the Like button or posting a comment, the corresponding information is transmitted from their device directly to Facebook and stored there. If a user is not a member of Facebook, there is still the possibility that Facebook will find out and store his or her IP address. According to Facebook, only an anonymised IP address is stored in Germany.
The purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as the related rights and setting options for protecting the privacy of the users, can be found in the data protection information of Facebook: https://www.facebook.com/about/privacy/.
If a user is a Facebook member and does not want Facebook to collect data about him or her via this online offer and link it to his or her membership data stored with Facebook, he or she must log out of Facebook and delete his or her cookies before using my online offer. Further settings and objections to the use of data for advertising purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. The settings are platform-independent, i.e. they are applied to all devices, such as desktop computers or mobile devices.
Right of revocation
You have the right to revoke consent granted in accordance with Art. 7 (3) DSGVO with effect for the future.
Right of objection
You may object to the future processing of data relating to you in accordance with Art. 21 DSGVO at any time. The objection can be made in particular against the processing for purposes of direct advertising.
IV.III. Right to data portability
Users have the right to receive personal data concerning them, which has been provided to me as the provider, in a structured, common and machine-readable format. Furthermore, they have the right to transfer this data to another controller to whom the personal data has been provided, provided that
• (I) the processing is based on consent pursuant to Art. 6 para. 1 lit. a DSGVO or Art. 9 para. 2 lit. a DSGVO or on a contract pursuant to Art. 6 para. 1 lit. b DSGVO and
• the processing is carried out with the aid of automated procedures. In exercising this right, you also have the right to have the personal data concerning you transferred directly from one controller to another controller, insofar as this is technically feasible. This must not affect the freedoms and rights of other persons.
The right to data portability does not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.