Updated June 2022
We take the protection of your personal data very seriously and process it in accordance with the applicable legal provisions.
The following notes provide a clear overview of how we process your personal data when you visit our website, https://kundenkonto.ims-austria.com, (the " Website). This Policy is addressed to (i) our customers, suppliers and other business contacts who are natural persons and, where we deal with legal entities, (ii) their employees, members and other representatives (hereinafter together as "business contact", "data subject" or "you").
Controller regarding the data processing on this Website is IMS Austria GmbH, with registered office at Industriestrasse 3, 4565 Inzersdorf, Austria, registered under number: FN 168192 t, telephone number +43 1 / 72550-0, and email address email@example.com (in the following also "we", "us", "our").
On the one hand, your personal data are collected when you communicate them to us. This can be data that you enter in a contact form, for example.
On the other hand, data, including personal data, are automatically collected by our computer systems when you visit our Website. This is mainly technical data (e.g. Internet browser, operating system or time of page consultation).
|User account management||Performance of a contract or pre-contractual measures (Art 6 1b GDPR)|
|Analysis of your needs||Performance of a contract or pre-contractual measures (Art 6 1b GDPR)|
|Online chat and online contact form||Performance of a contract or pre-contractual measures (Art 6 1b GDPR)|
|Customer and claim management||Legitimate interest of the data controller (Art 6 1f GDPR)|
|Direct marketing (by email and SMS).||Consent (Art 6 1a GDPR) (or legitimate interest in the case of active customers (Art 6 1f GDPR))|
|Monitoring the quality and continuous improvement of our products and services, including through the use of advanced data analysis technologies||Legitimate interest of the data controller (Art 6 1f GDPR)|
|Monitoring of our activities (reporting)||Legitimate interest of the data controller (Art 6 1f GDPR)|
|Response to your possible requests to exercise your rights in relation to your personal data (see section on your rights)||Compliance with a legal obligation to which the data controller is subject (Art 6 1c GDPR)|
|Audit of the company in the event of an asset transfer project, asset purchase, merger, etc.||Legitimate interest of the data controller (Art 6 1f GDPR)|
|Session cookies||Legitimate interest of the data controller (Art 6 1f GDPR)|
|Third-party cookies, analytics cookies||Consent (see below) (Art 6 1a GDPR)|
We process the following categories of data: first and last name, email address, company, JAC number associated with the company, position, customer need.
You may also visit our Website without actively providing us with information about you. In this case we collect certain data that your browser transmits to our website server (i.e. log files).
We process the following categories of data through our log files: browser type and version, operating system used, referring URL, host name of the accessing computer, date and time of server query, IP address.
The processing of these log files is necessary for us to maintain the functionality, stability and security of our Website. We may also process them for the purpose of forensic investigations in the case of a security incident or in order to generate user statistics. For statistical purposes your IP-address is used in anonymized form only.
Legal basis: Art 6 1f GDPR – legitimate interest in maintaining functionality, stability and security of our Website.
In accordance with applicable law, you may any time exercise your rights of access, rectification, deletion, portability, limitation of the personal data we process or objection to the processing, as well as the right to withdraw your consent where applicable.
You have the right to object at any time to direct marketing and profiling to the extent that it is related to such direct marketing.
Furthermore, you have the right to file a complaint with the competent supervisory authority. In Austria, this authority is the "Österreichische Datenschutzbehörde", all contacts and other details of which are available on the website https://www.dsb.gv.at/.
You can contact us at any time to exercise your rights by contacting to our data protection officer whose contact details are set out below.
For processing that requires your consent, we will seek your consent. You may withdraw your consent at any time. To do so, you can contact our data protection officer. The withdrawal of consent does not affect the legitimacy of the processing carried out prior to the withdrawal.
If your personal data are processed for the purpose of direct marketing, you have the right to object at any time to their processing; this also applies to profiling, insofar as it is related to such direct marketing. If you object, your personal data will no longer be used for marketing purposes.
You have the right to complaint to a competent supervisory authority, in particular in the country of your habitual residence, your place of work or the place of the alleged infringement.
You have the right to request that personal data which you have provided to us and that we process automatically on the basis of your consent or in performance of a contract be transmitted to you or to a third party in a customary, machine-readable format.
Within the framework of the applicable legal provisions, you have the right to access your personal data at any time and to correct, or delete such personal data.
You have the right to request the limitation of the processing of your personal data under the circumstance described in Art 18 GDPR.
We do not process your personal data for the purpose of taking decisions based solely on automated processing, including profiling, which produce legal effects concerning you (Art 22 GDPR).
The information required to contact us or to subscribe to our newsletter is mandatory information, as indicated in the corresponding area of the Website (e.g. an online form). Without this mandatory information, we cannot allow you to use the corresponding features or it will take longer to process your request.
Some of these recipients may be located in countries outside the EEA for which an adequate level of data protection has not yet been established by the EU Commission. In particular, this includes our affiliated companies. It should be noted that the level of data protection in such countries may not be the same as within the EEA. Also, subject to local laws and regulations data may be accessible to local authorities or courts.
However, where personal data is transferred to such third countries, we implement appropriate safeguards to ensure that your rights are protected in accordance with the GDPR. This includes the conclusion of the EU Commission's standard contractual clauses for the transfer of personal data (Art 46(2) c GDPR). Further details on the implemented safeguards as well as copies of the respective agreements are available on request at firstname.lastname@example.org.
Google Services: In order to provide a modern website and multi-media content, we use services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google may transfer data to recipients in the USA. The European Court of Justice has found that the USA does not have an adequate level of data protection.
With your explicit consent, data may be transferred to a third country (Art 49 1a GDPR). There is a risk that your data may be subject to access by US authorities for control and monitoring purposes and that no effective legal remedies are available against this. Before we set cookies and transfer your data to these companies, we will ask you for your explicit consent and provide you with detailed information about the corresponding data processing (in particular the purposes, data categories and storage period). You can withdraw your consent at any time with effect for the future.
We keep your personal data for the time necessary to fulfill the purposes mentioned above, plus the applicable statutory retention periods and/or statute of limitations for the establishment, exercise or defense of legal claims ("Legal limitation"). For certain claims the statutory limitation period may be up to 30 years. Any retention period based on statute of limitations will be expanded by up to eight weeks to account for postal delay. After these periods, we will delete your personal data.
Once the operational purposes mentioned above have been fulfilled, the personal data is archived until the end of applicable statutory retention period and/or statute of limitations, if any, and then deleted. Access to the data is therefore restricted so that the personal data is not accessible in an active database.
|Purpose of the processing||Storage time in operational database||Archiving|
|Management of requests for quotations for products or services, including responses to the customer's diagnosis, management of deliveries and after-sales service (purpose: analysis of your needs)||5 years from the last activity||5 to 10 years|
|Invoicing||3 years||7 years after the end of the respective business year|
|Online chat and online contact form||Subject to request (quotation, claim, data subject rights)||Subject to request (quotation, claim, data subject rights)|
|Customer and claim management||Duration of the contractual relationship||Legal limitation|
|Use of the user account / user account management||Duration of the contractual relationship and up to 3 years from the last activity||n/a|
|Monitoring the quality and continuous improvement of our products and services, including through the use of advanced data analysis technologies||Duration of the contractual relationship||n/a|
|Monitoring of our activities (reporting)||Duration of the contractual relationship||Legal limitation|
|Response to your possible requests to exercise your rights in relation to your personal data (see section on your rights)||For the duration of handling your request or complaint||Legal limitation|
|Audit of the company in the event of an asset transfer project, asset purchase, merger, etc.||Completion of the project||Legal limitation|
|Direct marketing (by email and SMS).||3 years from the last activity; or, where processing is based on your consent, until the withdrawal of your consent||N/A|
|Cookies/targeted advertising/advertising profiling||Please refer to the table in point 9 below||N/A|
We would like to draw your attention to the fact that data transmission over the Internet (e.g. communication by email) may have security breaches. A complete protection of data against third party intrusion is not possible. IMS Austria GmbH implements state-of-the-art security measures within the framework of a duty of care.
This Website uses SSL or TLS encryption for security purposes and to protect the transmission of confidential content, such as orders or requests that you send to us as the operator of the Website. You can recognize an encrypted connection by the fact that the browser address bar changes from "http://" to "https://" and by the padlock symbol in your browser address bar.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
We have appointed a data protection officer, with the following contact details: email@example.com .
In order to better understand how our Website is used and what content we should further develop, we use "Google Analytics" to compile anonymous usage statistics. This analysis tool uses (third-party) cookies to collect standard logging information as well as visitor behavior on our Website in aggregated form. Aggregate analyses will be performed, in particular, on the following factors: Number and duration of page views of the individual (sub-)pages, geographical location of accesses, end devices used by visitors (Web/mobile), language, operating system, service provider and screen resolution (on mobile devices).
This service is provided by Google. If you activate Google Analytics you thereby explicitly consent (Art 49 1a GDPR) to the data transfer of your IP address to Google (including Google entities in the USA). Regarding the risks associated with such transfer to the USA please see above point 5
|1. Necessary cookies|
|__cfduid||Identification of reliable web traffic||1 year|
|NSC_#||Web traffic distribution to optimize response time||1 day|
|PHPSESSID||Retention of user settings||Duration of the session|
|TawkWindowName||Functionality of the Website dialog box||Duration of the session|
|Hl||Identification of the Website||1 year|
|SS||Functionality of the Website dialog box||Duration of the session|
|_ga||Registration of a unique identifier to generate statistical data on the use of the Website||2 years|
|_gat||Cookie from Google Analytics to decrease the rate of queries||1 day|
|_gid||Recording of a unique identifier to generate statistics on the visit of the Website||1 day|
|_hjid||Unique session identifier for statistical purposes||1 year|
|collect||Sends device and visitor behavior data to Google Analytics. Tracks the visitor across devices and marketing channels||Duration of the session|
|TawkConnectionTime||Visitor recognition to optimize the operation of the dialog box||Duration of the session|
|tawkUUID||Analysis of the interaction between the user and the Website chat||6 months|
|__tawkuuid||Visitor identification via login information to provide online help via messaging.||6 months|
|_hjIncludedInSample||Determination of the need to record or not the user's navigation in a space dedicated to statistics||Duration of the session|
|r/collect||Sending data about the visitor's device and behavior to Google Analytics. Tracking the visitor on other devices and marketing channels.||Duration of the session|
By clicking on the "OK"-button in the Website's cookie banner you agree to the use of the above listed optional cookies on our Website. Your consent can be withdrawn (for all or individual cookies) at any time with effect for the future.
Our Website uses plugins from the YouTube service. The plugins are operated by Google. The plugins are deactivated by default. If you activate them by clicking on the "Activate YouTube plugin" button, you thereby consent to the transfer of cookie, device and browsing data to Google. If you are logged into your YouTube account, YouTube may be able to assign your surfing behaviour to your YouTube account. You can prevent this by logging out of your YouTube account before clicking on the plugin/video. If you do not have a YouTube account, YouTube may nevertheless receive and store your IP address and information about the browser and operating system you are using after activating the plugin or the video.
In addition, YouTube may store various cookies on your device, e.g. if a YouTube video is clicked on.
In connection with the above-mentioned processing your personal data may – subject to your explicit consent (Art 49 1a GDPR) - be transferred to Google entities in the USA. Regarding the risks associated with such transfer to the USA please see above point 5.
You can find more information about the processing of user data in the YouTube Policy at: https://policies.google.com/privacy?hl=en.
Our website uses the Google Maps mapping service via an API to display geographical information in a user-friendly way. The provider is Google.
Google Maps is deactivated by default. If you activate it by clicking on the map, you thereby explicitly consent (Art 49 1a GDPR) to the data transfer of your IP address to Google (including Google entities in the USA). Regarding the risks associated with such transfer to the USA please see above point 5.
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on our Websites. The provider is Google.
The purpose of reCAPTCHA is to check whether the data entered on our Websites (e.g. in a contact form) is made by a person or by an automated program (protection against misuse). For this purpose, reCAPTCHA analyzes the behavior of the user on the basis of various characteristics (e.g. IP address, length of stay on the Website or mouse movements made by the user). This analysis starts automatically as soon as the visitor enters the Website. The data collected during the analysis may be transferred to Google entities in the USA. Regarding the risks associated with such transfer to the USA please see above point 5.