Privacy Statement

1. General Information

1.1 Controller

secinto GmbH
Poststraße 3
8530 Deutschlandsberg
Austria
datenschutz@secinto.com
+43 660 7724524

1.2 Scope of Processing

We process the personal data of our users only to the extent necessary to provide a functional website as well as our content and services. The processing of our users’ personal data is generally carried out only with the user’s consent. An exception applies in cases where obtaining prior consent is not possible for factual reasons and the processing of the data is permitted by law.

1.3 Legal Basis

Where we obtain the consent of the data subject for processing personal data, Art. 6(1)(a) GDPR serves as the legal basis.

When the processing of personal data is necessary for the performance of a contract to which the data subject is a party, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations necessary to take steps prior to entering into a contract.

Where processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis.

If processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, and such interests are not overridden by the interests, fundamental rights, and freedoms of the data subject, Art. 6(1)(f) GDPR serves as the legal basis.

1.4 Data Deletion and Storage Duration

Personal data of the data subject shall be erased or blocked as soon as the purpose of storage no longer applies. Storage may also take place if this is provided for by European or national legislators in EU regulations, laws, or other provisions to which the controller is subject. Data shall also be blocked or deleted if a storage period prescribed by the aforementioned regulations expires, unless further storage is required for the conclusion or performance of a contract.

2. Website

2.1 Scope of Data Processing

Our website processes the following data transmitted from your computer in order to deliver the content you request (e.g. texts, images, downloadable files, etc.) to your device. We also process these data for the detection and prosecution of abuse. Storage in log files ensures the functionality of the website, helps us optimize the site, and ensures the security of our IT systems. Data are not analyzed for marketing purposes.

Processed data:

  • Browser type and version used

  • User’s operating system

  • User’s Internet service provider

  • User’s IP address

  • Date and time of access

  • Websites from which the user’s system accessed our website

  • Websites accessed by the user’s system through our website

2.2 Legal Basis

The temporary storage of data and log files is based on Art. 6(1)(f) GDPR.

2.3 Purpose of Processing

The temporary storage of the IP address is necessary to enable the delivery of the website to the user’s computer. For this purpose, the user’s IP address must remain stored for the duration of the session.

Log file storage ensures the website’s functionality, enables optimization, and secures our IT systems. Data are not evaluated for marketing purposes.

These purposes also constitute our legitimate interest in data processing pursuant to Art. 6(1)(f) GDPR.

2.4 Duration of Storage

Data are deleted once they are no longer necessary to achieve the purpose for which they were collected. For data collected to provide the website, this is the case when the session ends.

For data stored in log files, deletion occurs after no more than seven days. Longer storage is possible, in which case IP addresses are deleted or anonymized so they can no longer be attributed to a specific client.

2.5 Right to Object and Removal

The collection of data for the provision of the website and their storage in log files is essential for the operation of the site. Consequently, the user has no right to object.

3. Use of Cookies

3.1 Scope of Data Processing

Our website uses cookies. Cookies are text files stored in or by the Internet browser on the user’s computer system. When a user visits a website, a cookie may be stored on their operating system containing a unique string of characters that enables the browser to be identified upon returning to the site.

We use cookies to make our website more user-friendly. Certain elements of our site require that the browser be recognized even after a page change.

We also use cookies that allow an analysis of users’ browsing behavior.

To manage cookies and similar technologies (e.g. tracking pixels, web beacons) and related consents, we use the consent tool “Complianz.” Details on how “Complianz” functions can be found via the corresponding link on our website.

The legal bases for processing personal data in this context are Art. 6(1)(c) and Art. 6(1)(f) GDPR. Our legitimate interest lies in managing the cookies, similar technologies, and associated consents.

Providing personal data is neither legally nor contractually required, nor necessary for the conclusion of a contract. However, if you do not provide the data, we cannot manage your consents.

3.2 Legal Basis

The legal basis for processing personal data using cookies is Art. 6(1)(f) GDPR.
For technically necessary cookies, the same provision applies.
For analytical cookies, processing is based on the user’s consent under Art. 6(1)(a) GDPR.

3.3 Purpose of Processing

Technically necessary cookies make it easier for users to navigate and use the website. Some features cannot function without cookies, as they require the browser to be recognized after a page change. Data collected through necessary cookies are not used to create user profiles.

Analytical cookies help us improve the quality of our website and content by providing insights into how the site is used. These purposes also constitute our legitimate interest under Art. 6(1)(f) GDPR.

3.4 Duration of Storage and Right to Object

Cookies are stored on the user’s computer and transmitted to our site from there. You therefore have full control over cookie use. By changing your browser settings, you can deactivate or restrict cookie transmission. Stored cookies can be deleted at any time, including automatically. If cookies are disabled, some website functions may no longer be fully available.

4. Web Analytics

4.1 Scope of Processing

This website uses Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). The use includes the “Universal Analytics” mode, which allows data, sessions, and interactions across multiple devices to be assigned to a pseudonymous user ID, enabling cross-device analysis of user activities.

Google Analytics uses cookies to analyze your use of the website. The information generated by the cookie is generally transmitted to and stored on a Google server in the USA.

If IP anonymization is activated, your IP address will first be shortened by Google within member states of the EU or other EEA states. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. The IP address transmitted by your browser within Google Analytics is not merged with other Google data.

4.2 Legal Basis

The legal basis for processing personal data of users is Art. 6(1)(f) GDPR.

4.3 Purpose of Processing

Google processes the information on behalf of the website operator to evaluate the use of the website, compile reports on website activity, and provide other services related to website and Internet usage.

The processing enables us to analyze user behavior and improve our website and user experience. These purposes also represent our legitimate interest in processing under Art. 6(1)(f) GDPR and § 15(3) TMG.

IP anonymization adequately protects users’ interests in safeguarding their personal data.

4.4 Duration of Storage

Sessions and campaigns end after a certain time. By default, sessions end after 30 minutes of inactivity, and campaigns after six months; the maximum limit is two years. For details, see Google’s Terms of Use and Privacy Policy.

4.5 Right to Object

You can prevent cookies from being stored by adjusting your browser settings. However, this may limit website functionality. You can also prevent data collection (including your IP address) and processing by Google by installing the browser add-on for deactivation (“anonymizeIP”). Opt-out cookies prevent future tracking on this website and must be set on all devices you use.
Click here to disable Google Analytics: [Deactivate Google Analytics]

5. Business Transactions

The privacy policy applicable to regular business operations can be downloaded via the following link:
Privacy Policy – Business Transaction.

6. NEWSLETTER AND MARKETING EMAILS

6.1 Description and Scope of Data Processing

Our website offers the option to subscribe to our newsletter and receive
marketing information. When using our services (particularly the Security Check),
we may contact you with relevant information about cybersecurity topics,
product updates, and offers.

The following data is processed:
– Email address
– First and last name (if provided)
– Company (if provided)
– Time of registration/usage
– IP address at the time of registration

For sending newsletters, we use Brevo (Sendinblue GmbH, Köpenicker Str. 126,
10179 Berlin). The data is stored on Brevo servers. Brevo is GDPR certified.

6.2 Legal Basis

The legal basis for processing data after newsletter subscription by the user
is Art. 6 Para. 1 lit. a GDPR, provided the user has given consent.

The legal basis for sending marketing information to existing customers and
users of our services is Art. 6 Para. 1 lit. f GDPR (legitimate interest).
Our legitimate interest lies in informing our customers about security-relevant
developments and our services.

6.3 Purpose of Data Processing

The collection of the email address serves to deliver the newsletter and
marketing information. The collection of other personal data serves to prevent
misuse of the services or the email address used, as well as to personalize
communication.

6.4 Storage Duration

The data will be deleted as soon as it is no longer necessary for achieving
the purpose of its collection. The user’s email address will therefore be
stored as long as the newsletter subscription or customer relationship is active.

Other personal data will generally be deleted after a period of three years,
unless there is a legal obligation to retain it.

6.5 Right to Object and Withdrawal

The subscription to the newsletter or marketing emails can be cancelled by
the affected user at any time. For this purpose, there is a corresponding link
in every newsletter and marketing email.

You can also object to the processing of your data for marketing purposes at
any time by emailing datenschutz@secinto.com.

7. Rights of Data Subjects

7.1 Right of Access

You have the right to obtain confirmation from the controller as to whether personal data concerning you are being processed and, if so, access to the following information:

  • Purposes of processing

  • Categories of personal data

  • Recipients or categories of recipients

  • Planned storage duration or criteria for determining it

  • Existence of rights to rectification, erasure, restriction, or objection

  • Existence of a right to lodge a complaint with a supervisory authority

  • Source of the data, if not collected from you

  • Existence of automated decision-making, including profiling, and meaningful information about the logic involved and possible consequences

You also have the right to be informed whether your personal data are transferred to a third country or international organization and, if so, about appropriate safeguards under Art. 46 GDPR.

7.2 Right to Rectification

You have the right to obtain rectification of inaccurate or completion of incomplete personal data concerning you without undue delay.
Where data are processed for research or statistical purposes, this right may be limited if it would seriously impair the achievement of those purposes.

7.3 Right to Restriction of Processing

You may request restriction of processing under the following conditions:

  • You contest the accuracy of the data for a period enabling verification;

  • Processing is unlawful, but you oppose erasure and request restriction instead;

  • The controller no longer needs the data but you require them for legal claims; or

  • You have objected under Art. 21(1) GDPR and the balance of interests is pending.

If processing is restricted, such data may—except for storage—only be processed with your consent, for legal claims, to protect another person’s rights, or for reasons of public interest.

7.4 Right to Erasure (“Right to be Forgotten”)

You may request immediate erasure of personal data concerning you where one of the following applies:

  1. The data are no longer necessary for the purposes collected;

  2. You withdraw consent and no other legal basis applies;

  3. You object under Art. 21 GDPR and there are no overriding legitimate grounds;

  4. The data were unlawfully processed;

  5. Erasure is required for compliance with a legal obligation; or

  6. The data were collected in relation to services offered directly to a child under Art. 8(1) GDPR.

If the controller has made such data public, they must take reasonable steps—including technical measures—to inform other controllers processing the data that you have requested deletion of all links or copies.

Exceptions: The right to erasure does not apply where processing is necessary

  • for exercising freedom of expression or information;

  • for compliance with a legal obligation or task in the public interest;

  • for public health reasons;

  • for archiving, research, or statistical purposes, if erasure would seriously impair the objectives; or

  • for the establishment, exercise, or defense of legal claims.

7.5 Right to Notification

If you have exercised your right to rectification, erasure, or restriction, the controller must notify all recipients to whom personal data have been disclosed, unless this proves impossible or involves disproportionate effort. You have the right to be informed of those recipients.

7.6 Right to Data Portability

You have the right to receive personal data you provided to the controller in a structured, commonly used, and machine-readable format, and to transmit those data to another controller without hindrance, where processing is based on consent or contract and carried out by automated means.

You may also request direct transfer between controllers where technically feasible, provided the rights of others are not adversely affected. This right does not apply to processing necessary for tasks in the public interest or the exercise of official authority.

7.7 Right to Object

You have the right, on grounds relating to your particular situation, to object at any time to processing based on Art. 6(1)(e) or (f) GDPR.

The controller will no longer process the data unless compelling legitimate grounds override your interests or the processing serves legal claims.

If your data are processed for direct marketing, you may object at any time; your data will then no longer be processed for such purposes.

You may exercise this right via automated procedures using technical specifications (e.g. through browser or app settings).

7.8 Right to Withdraw Consent

You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

7.9 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority—particularly in your country of residence, place of work, or the location of the alleged infringement—if you consider that the processing of personal data concerning you infringes the GDPR.
The supervisory authority shall inform you of the progress and outcome of your complaint, including the possibility of judicial remedy under Art. 78 GDPR.

Contact

E-mail: office@checkfix.io

Phone: +43 660 77 24 524

secinto

secinto GmbH

Poststraße 3

8530 Deutschlandsberg

Austria

E-mail: office@checkfix.com

*Studie KPMG zur Cybersecurity in Österreich 2023