Privacy & GDPR
This is a convenience translation. The legally binding version is the German original.
Privacy Policy in accordance with the General Data Protection Regulation (GDPR) of C1.IT Solutions GmbH – May 2018.
Statement
C1.IT solutions declares to its customers, suppliers and others that it complies with and has implemented the European General Data Protection Regulation, GDPR for short. It protects personal data by means of suitable, state-of-the-art technologies and measures that are subject to a defined process. This process is continuously documented, monitored and reviewed.
Subcontractors and agents of C1.IT solutions who, in the course of business, may likewise gain access to personal data are not only chosen and selected in accordance with the GDPR, but are also explicitly instructed to provide corresponding GDPR declarations and to comply with them.
The implementation of and compliance with the GDPR expressly does not replace other statutory provisions or guidelines that C1.IT solutions is obliged to observe.
C1.IT Solutions GmbH / DI Claus Reinprecht – Vienna, May 2018
Scope of this Privacy Policy
This policy applies to all personal data that is and has been collected, stored and processed. This data arises on the one hand through enquiries about products, project requests and other contacts, and on the other hand when this data is stored with consent for the purpose of placing an order.
In general this concerns the names of managing directors and contact persons and therefore comprises only name, telephone numbers, email addresses and, where applicable, address data, should the persons also be business partners in the sense of invoicing and offers. If, in the latter case, the persons are customers, the details of the SEPA direct debit – that is, the bank account details – are also stored where a SEPA direct debit mandate has been consented to. For European foreign customers the VAT identification number is additionally stored, which may occasionally also apply to domestic customers (depending on project turnover).
The same principles apply to legal entities.
Should natural persons register for the newsletter distribution list via the C1.IT solutions website or by other means, they give their consent by registering that this data (name and email address) may be stored and processed.
For customers of VoIP and mobile services, the CDR data is stored and processed for the legally defined period at a secure location that can only be accessed by authorised persons with special access rights. This CDR data is transmitted and made available in electronically encrypted form by downstream providers (Drei and/or kapper/mediainvent).
For cloud products as well as for mail and web hosting products we provide storage space and therefore bear no responsibility for its use and processing. In accordance with the product specifications we protect the storage space by the technical measures contained therein (data redundancy, encryption, backup and security) and access technologies.
Use of data
The data described above is generated, stored and processed for the purpose of establishing, managing and conducting business relationships. This use and processing of data takes place in the performance of an order or contract whose parties are customers or suppliers – in short, business partners – or in order to carry out pre-contractual measures undertaken in response to enquiries from these business partners (Art. 6(1)(b) GDPR). This may, for example, be in the context of an offer, a project, invoicing or a personalised mailing. Further data is used for internal administrative purposes, including in fulfilment of legal and tax obligations (Art. 6(1)(f) GDPR).
In general, personal data is not passed on unless it is necessary for supplementary services such as transport and freight, where products and services have to be delivered. For this point, the person in any case explicitly consents to this measure by placing the order.
All suppliers and partners of C1.IT solutions are based in the European Union and are themselves obliged to comply with the GDPR and to provide corresponding declarations.
Data security and protection
C1.IT solutions has taken suitable and appropriate, state-of-the-art measures to protect the data against loss, theft or other unlawful use (including unauthorised access). These measures are documented and continuously subjected to review.
Controller under the GDPR
The controller within the meaning of the GDPR is C1.IT Solutions GmbH, Vienna, Austria. Questions, suggestions and complaints in connection with the use of data by and through C1.IT solutions can be addressed to support@ebox.at or via the other means of contact and will be answered and dealt with within an appropriate processing period.
Right to object to processing
Data subjects have the option of getting in touch via the support email address support@ebox.at or via the other means such as telephone and fax in order to exercise all rights to which they are entitled under the GDPR; these include the right of access (Art. 15), the right to rectification (Art. 16), the right to erasure (Art. 17), the right to restriction of processing (Art. 18), the right to data portability (Art. 20) and, in general, the right to object to data processing (Art. 21).
General contact details
C1.IT Solutions GmbH
Stolzenthalergasse 14
A-1080 Vienna
Tel. +43 1 30600 · Fax +43 1 30600-9
Mail: info@c1-it.com · Support: support@ebox.at
As at: 24.5.2018, Claus Reinprecht
GDPR and .AT Domains
For the registration, renewal and administration of .at domains, certain personal data – in particular of domain holders (registrants) as well as of administrative and technical contacts – must be transmitted to and stored by the Austrian registry nic.at GmbH. This processing is necessary for the performance of the domain registration contract (Art. 6(1)(b) GDPR).
As the registry, nic.at GmbH is an independent controller for the processing of this registration data. The data protection provisions and registration policies of nic.at therefore additionally apply.
Since the GDPR came into force, personal data of domain holders is no longer published generally in the public WHOIS query. Disclosure takes place only in legally prescribed cases or upon demonstration of a legitimate interest following appropriate review.
As an accredited .at registrar, we transmit only the data necessary for the registration and proper operation of the domain.