The following information is a concise, understandable, and transparent summary of the information contained in the Privacy Policy regarding the data controller, the purpose and nature of the processing of personal data, and your rights in connection with such processing, in the form required to comply with the GDPR information obligation. Details concerning the type of processing and the entities involved in this process can be found in the indicated policy.
Who is the data controller?
The controller of personal data (hereinafter referred to as the Controller) is AVS Europe GmbH, operating at the following address: Hebbelplatz 5, AT-1100 Vienna, with VAT ID: ATU 41157902 and company registration number (FN): 98180 h.
How can you contact the data controller?
The Controller can be contacted in one of the following ways:
Postal address – AVS Europe GesmbH, Hebbelplatz 5, 1100 Vienna
Email address: europe@avs-europe.com
Telephone: +43 1 604 5858
Has the Controller appointed a Data Protection Officer for personal data?
The Controller has appointed a Data Protection Officer, Mr. Stefan Eisert.
The Data Protection Officer can be contacted:
by email at: datenschutz@avs-europe.com
by telephone at: +43 1 604 5858
or in writing at: Hebbelplatz 5, 1100 Vienna
The Data Protection Officer may be contacted in all matters related to the processing of personal data.
Where do we obtain personal data from and what are its sources?
The data comes from the following source:
from the data subjects
What scope of personal data do we process?
The website processes ordinary personal data voluntarily provided by the persons to whom it relates (e.g. first and last name, login, email address, telephone number, IP address, etc.).
The detailed scope of the processed data can be found in the Privacy Policy.
What are the purposes of our data processing?
Personal data voluntarily provided by the user is processed for one of the following purposes:
Provision of electronic services;
Communication by the Controller with users in matters related to the website and data protection;
Safeguarding the Controller’s legitimate interest.
What are the legal bases for data processing?
The Controller collects and processes user data on the basis of:
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
Article 6(1)(a)
the data subject has given consent to the processing of their personal data for one or more specific purposes
Article 6(1)(b)
processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract
Article 6(1)(f)
processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party
What legitimate interest is pursued by the Controller?
For the possible establishment, exercise, or defence of claims, the legal basis for processing is our legitimate interest (Article 6(1)(f) GDPR), consisting, among other things, in the protection of our rights;
For the evaluation of planned marketing campaigns.
For what period do we process personal data?
As a rule, the indicated personal data is stored only for the period of providing the service within the website operated by the Controller.
In exceptional situations, this period may be extended in order to safeguard the Controller’s legitimate interest. In such a case, the Controller stores the indicated data from the moment the user requests its deletion, but no longer than for a period of 3 years in the event of a breach or suspected breach of the website terms by the data subject.
Who is the recipient of personal data?
As a rule, the sole recipient of the data is the Controller.
However, data processing may be entrusted to other entities providing services to the Controller for the maintenance of the website’s operation.
These entities include, among others:
Hosting companies providing hosting or related services to the Controller
Is your personal data transferred outside the European Union?
Personal data is not transferred outside the European Union or to third countries, unless publication occurs as a result of an individual action by the user (e.g. posting a comment or entry), which will make the data accessible to every visitor to the website.
Will personal data be used as the basis for automated decision-making?
Personal data is not used for automated decision-making (profiling).
What rights do you have in connection with the processing of personal data?
Right of access to personal data.
Users have the right to access their personal data, exercised upon request submitted to the Controller.
Right to rectification of personal data.
Users have the right to request from the Controller the immediate rectification of incorrect personal data and/or completion of incomplete personal data, exercised upon request submitted to the Controller.
Right to erasure of personal data.
Users have the right to request from the Controller the immediate erasure of personal data, exercised upon request submitted to the Controller.
Right to restriction of processing of personal data.
Users have the right to restrict the processing of personal data in the cases indicated in Article 18 GDPR, e.g. when contesting the accuracy of personal data, exercised upon request submitted to the Controller.
Right to data portability.
Users have the right to receive from the Controller personal data concerning the user in a structured, commonly used, machine-readable format, upon request submitted to the Controller.
Right to object to the processing of personal data.
Users have the right to object to the processing of their personal data in the cases indicated in Article 21 GDPR, exercised upon request submitted to the Controller.
Right to lodge a complaint.
Users have the right to lodge a complaint with the supervisory authority responsible for personal data protection.
Privacy Policy
The following Privacy Policy sets out the rules for storing and accessing data on users’ devices used when using the website for the electronic provision of services by the Controller, as well as the rules for collecting and processing users’ personal data, which they have provided personally and voluntarily using the tools available on the website.
§1. Definitions
Website – the website of AVS Europe GmbH at https://www.avs-europe.com
External website – websites of partners, service providers, or service recipients cooperating with the Controller
Website/Data Controller – the website administrator and data controller (hereinafter referred to as the Controller) is the company ‘AVS Europe GmbH’, with address: Hebbelplatz 5, 1100 Vienna, with VAT ID: ATU 41157902 and company registration number (FN): 98180 h.
User – a natural person for whom the Controller provides services electronically via the website.
Device – an electronic device with software through which the user accesses the website
Cookies – text data collected in the form of files placed on the user’s device
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
Personal data – information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as first and last name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person
Processing – any operation or set of operations which is performed on personal data or on sets of personal data, whether by automated or non-automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
Restriction of processing – the marking of stored personal data with the aim of limiting its future processing
Profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements
Consent – any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which, by a statement or by a clear affirmative action, they signify agreement to the processing of personal data relating to them
Personal data breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored, or otherwise processed
Pseudonymisation – the processing of personal data in such a manner that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures preventing attribution to an identified or identifiable natural person
Anonymisation – an irreversible data processing process that destroys/overwrites ‘personal data’ and makes it impossible to identify a specific data set or assign it to a specific user or natural person.
§2. Data Protection Officer
The Controller has appointed a Data Protection Officer. The DPO can be contacted by email at datenschutz@avs-europe.com, by telephone at +43 1 604 5858, or in writing at Hebbelplatz 5, 1100 Vienna.
The Data Protection Officer may be contacted in all matters related to the processing of personal data.
§3. Types of cookies
Internal cookies – files placed and read on the user’s device by the ICT system of the website
External cookies – files placed and read on the user’s device by ICT systems of external websites. Scripts of external websites that may place cookies on users’ devices have been knowingly placed on the website through scripts and services made available and installed on the website
Session cookies – files placed and read by the website on the user’s device during one session of a given device. After the session ends, the files are deleted from the user’s device.
Persistent cookies – files placed and read by the website on the user’s device until they are manually deleted. The files are not automatically deleted after the end of the device session, unless the user’s device configuration is set to delete cookies after the end of the device session.
§4. Data storage security
Mechanisms for storing and reading cookies – mechanisms for storing, reading, and exchanging data between cookies stored on the user’s device and the website are implemented by built-in web browser mechanisms and do not allow other data to be downloaded from the user’s device or data from other websites visited by the user, including personal or confidential information. The transfer of viruses, trojans, and other worms to the user’s device is also practically impossible.
Internal cookies – cookies used by the Controller are safe for users’ devices and do not contain scripts, content, or information that could threaten the security of personal data or the security of the device used by the user.
External cookies – the Controller takes all possible measures to verify and select website partners in terms of user security. For cooperation, the Controller selects well-known, large partners with global public trust. However, the Controller does not have full control over the content of cookies originating from external partners. The Controller is not responsible for the security of cookie files, their content, or their lawful use by scripts installed on the website originating from external websites, to the extent permitted by law. A list of partners can be found in the further part of the Privacy Policy.
Cookie control
The user may independently change the settings for storing, deleting, and accessing the data of stored cookies on any website at any time.
Information on how to disable cookies in the most common computer browsers can be found on the websites of the respective providers.
The user may delete all previously stored cookies at any time using the tools available on the user’s device through which the user uses the website services.
Threats on the part of the user – the Controller uses all possible technical measures to ensure the security of the data stored in cookies. However, it should be noted that ensuring the security of this data depends on both parties, including the user’s activity. The Controller is not responsible for the interception of such data, impersonation of the user’s session, or their removal as a result of the user’s intentional or unintentional actions, viruses, trojans, or other spyware that may have infected the user’s device. In order to protect themselves against these threats, users should follow the rules for safe use of the Internet.
Storage of personal data – the Controller ensures that it makes every effort to ensure that the processed personal data voluntarily entered by users is secure, access to it is limited, and it is processed in accordance with its purpose and the purposes of processing. The Controller also ensures that it makes every effort to protect the stored data against loss by applying appropriate physical and organizational safeguards.
§5. Purposes for which cookies are used
Optimization and facilitation of access to the website
Personalization of the website for users
Keeping statistics (users, number of visits, types of devices, connection, etc.)
§6. Purposes of processing personal data
Personal data voluntarily provided by the user is processed for one of the following purposes:
Provision of electronic services;
Communication by the Controller with users in matters related to the website and data protection;
Safeguarding the Controller’s legitimate interest.
Anonymous and automatically collected user data is processed for one of the following purposes:
Keeping statistics
Safeguarding the Controller’s legitimate interest.
§7. Types of collected data
The website collects data about users. Part of the data is collected automatically and anonymously, and part of the data consists of personal data voluntarily provided by the user when subscribing to individual services offered on the website.
Automatically collected anonymous data:
IP address
Browser type
Screen resolution
Approximate location
Opened subpages of the website
Time spent on the relevant subpage of the website
Type of operating system
Address of the previous subpage
Referrer address
Browser language
Internet connection speed
Internet service provider
Data collected during registration:
First and last name
Email address
Telephone numbers
Part of the data (without identification data) may be stored in cookies. Part of the data (without identification data) may be transferred to the provider of statistical services.
§8. Access to personal data by third parties
As a rule, the sole recipient of personal data provided by users is the Controller. Data collected as part of the provided services is not transferred or resold to third parties.
Access to data (usually on the basis of a data processing agreement) may be granted to entities responsible for maintaining the infrastructure and services necessary to operate the website, i.e.:
Hosting companies providing hosting or related services to the Controller
Hosting services to which the processing of personal data is entrusted:
For the operation of the website, the Controller uses the services of an external hosting provider: KOSCHIER IT-Outsourcing GmbH, with registered office at Lemböckgasse 61/1/23, 1230 Vienna, Austria.