Privacy policy
General information on data processing
This privacy policy explains the nature, scope and purpose of the processing of personal and usage data (hereinafter referred to as ‘data’) in the course of our online offer and the associated websites, functions and content as well as external online presences, such as our social media profile (hereinafter collectively referred to as ‘online offer’). In addition, this statement also provides information on the handling of personal data that applies in the context of general contact with us and in particular applications for jobs in our company. We process your data exclusively on the basis of the statutory provisions (GDPR, TKG 2003).
Explanation of terms
Personal data & usage data
The provisions of the GDPR apply to the processing of personal data of natural persons. By definition, ‘personal data’ is any information relating to an identified or identifiable natural person (‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. When using our service, we may ask you to provide certain personally identifiable information that we use to contact or identify you (‘personal data’). Personally Identifiable Information may include (but is not limited to) the following data
- Email address
- First name and surname
- telephone number
- Address, state, province, postcode, city
- Cookies and usage data
We may also collect data about the manner in which our Service is accessed or used (‘Usage Data’). This Usage Data may include your computer's Internet Protocol address (IP address), browser type, browser version, the pages you visit within our Service, the time and date of your visit, the total time spent on those pages, unique device identifiers and other diagnostic data.
Processing
The GDPR defines the term ‘processing’ as any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Controller and processor
‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law. ‘Processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Consent
Consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Pseudonymisation
Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
Legal basis for the processing of personal data
We process personal data in accordance with the GDPR on the following legal basis:
- Legal basis for obtaining consent (Art. 6 para. 1 lit. a and Art. 7 GDPR)
- Processing of data to fulfil our services, to implement contractual measures and to respond to enquiries (Art. 6 para. 1 lit. b GDPR)
- Processing of data to fulfil our legal obligations (e.g. obligations under labour law or tax law) (Art. 6 para. 1 lit. c GDPR)
- The processing of data to protect our legitimate interests (Art. 6 para. 1 lit. f GDPR)
- The processing of personal data in the event that vital interests of the data subject or another natural person make this necessary (Art. 6 para. 1 lit. d GDPR).
Collection and use of data
We collect various types of data for a number of purposes in order to improve the service we provide to you, in particular to
- Provide and maintain our Service to you;
- Notify you of changes to our Service;
- enable you to participate in the interactive parts of our Service when you request it;
- Provide customer support services;
- collect analytics and other valuable data so that we can improve our Service;
- monitor the use of our Service;
- identify, prevent and address technical issues;
Rights of access and cancellation
You have the right to request information from us at any time about the data we have stored about you, as well as its origin, recipients or categories of recipients to whom this data is passed on and the purpose of storage. You also have the right to object to the processing or use of your personal data for the purposes of advertising or market and opinion research as well as address trading and commercial data processing. You can also object to the collection, processing or use of your personal data at any time if an examination shows that your legitimate interest outweighs the interest of the controller in the collection, processing or use due to your particular personal situation. This does not apply if a legal provision authorises or obliges the collection, processing or use. Furthermore, you have the right to revoke your previously given consent to the collection, processing and use of your personal data at any time with effect for the future. Green Medical Medizintechnik will provide you with all information or explanations on data protection on request. (see Contact). Please also contact Green Medical Medizintechnik if you wish to exercise your right of objection or cancellation in accordance with the AGBG. See also greenmedical.at/shop/agb.
Data security
Your personal data is transmitted over the Internet in encrypted form using SSL and 128-bit encryption. We use technical and organisational measures to secure our website and other systems against loss, destruction, access, modification or dissemination of your data by unauthorised persons. Access to your user account is only possible after entering your personal password. You should always treat your access information confidentially and close the browser window when you have finished communicating with us, especially if you share your computer with others.
Security measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as the access, input, disclosure, safeguarding of availability and separation of the data. We have also set up procedures to ensure that data subjects' rights are exercised, data is deleted and we respond to data threats. Furthermore, we take the protection of personal data into account as early as the development and selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and data protection-friendly default settings.
Collection of personal data when browsing our website
When using the website for information purposes only, i.e. if you do not log in to use the website, register or otherwise provide us with information, we do not collect any personal data, with the exception of the data that your browser transmits to enable you to visit the website. These are IP address; date and time of the request; time zone difference to Greenwich Mean Time (GMT); content of the request (specific page); access status/HTTP status code, the amount of data transferred in each case; website from which the request comes; browser; operating system and its interface; language and version of the browser software.
Collection, processing and use of personal data
We collect personal data (individual details about personal or factual circumstances of a specific or identifiable natural person) only to the extent provided by you. Your personal data is processed and used to fulfil and process your order and to deal with your enquiries. Once the contract has been fully processed, all personal data will initially be stored in accordance with tax and commercial retention periods and then deleted after this period has expired, unless you have consented to further processing and use.
Use of functions on our website
In addition to the purely informational use of our website, we offer various services that you can use if you are interested. To do so, you generally have to provide additional personal data that we use to provide the respective service. If additional voluntary information is possible, this is labelled accordingly. When you contact us by e-mail, your e-mail address and, if you provide it, your name and telephone number will be stored by us in order to contact you and answer or process and clarify your questions and concerns.
Disclosure of personal data
Your data will not be passed on to third parties without your express consent. The only exceptions to this are our service partners (payment service providers, shipping service providers, web shop(s) service providers, accounting and administration service providers, etc.), which we require to process the contractual relationship. In these cases, we strictly observe the provisions of the Federal Data Protection Act. Your data will also be passed on to the tax consultancy firm representing us in order to fulfil our legal (commercial and tax) obligations. Furthermore, your data may be forwarded to the law firms representing us or service providers commissioned with the collection of payments (‘debt collection agencies’), for example.
Purchase/user account
If you wish to use the functions of our user account, you must register by entering your user name/name, your e-mail address and a password of your choice. If you wish to make purchases in our online shop, you must provide further information required for the processing of contracts. These mandatory details are marked separately. Further details are voluntary. As part of the guest or user account, we store the data required to fulfil the contract for any order, in particular your delivery addresses. We forward your payment information directly to our billing service provider / payment service provider (PSP); this information does not remain in our systems. We also store the voluntary data you provide for the duration of your user account, unless you delete it beforehand. You can manage and change all details in the protected user account area.
Payment data
Your payment details are encrypted and transmitted over the Internet during the ordering process. Due to a special integration into the ordering process, we do not have access to your payment data at any time and are therefore not the processor of this data. This data is processed exclusively by these payment service providers (PSP) or service providers:
Amazon Pay: Your payment at greenmedical.at/shop is processed via your existing Amazon account (Amazon Check Out). Contact: Amazon Payments Europe s.c.a., 38 avenue J.F. Kennedy, L-1855 Luxembourg. Data protection officer can be contacted at eu-privacy@amazon.lu.
Klarna: Klarna enables purchase on account. You will therefore receive an invoice from Klarna and must transfer the outstanding amount to the bank details shown on the Klarna invoice. Contact: Sveavägen 46, 111 34 Stockholm, Sweden. Data protection officer can be reached at inkorg@klarna.se
PayPal: Your payment at greenmedical.at/shop will be processed via your existing PayPal account (PayPal Check Out) if you have selected the PayPal payment method.
Google Adwords and conversion measurement
We use the online marketing process Google ‘AdWords’ to place adverts in the Google advertising network (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who are presumed to be interested in the adverts. This allows us to display adverts for and within our online offering in a more targeted manner in order to present users only with adverts that potentially match their interests. If, for example, a user is shown adverts for products that they were interested in on other online offers, this is referred to as ‘remarketing’. For these purposes, when our and other websites on which the Google advertising network is active are accessed, a code from Google is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also known as ‘web beacons’) are integrated into the website. With their help, an individual cookie, i.e. a small file, is stored on the user's device (comparable technologies can also be used instead of cookies). This file records which websites the user has visited, which content they are interested in and which offers the user has clicked on, as well as technical information about the browser and operating system, referring websites, visiting time and other information about the use of the online offer. We also receive an individual ‘conversion cookie’. The information collected with the help of the cookie is used by Google to create conversion statistics for us. However, we only receive the anonymous total number of users who clicked on our advert and were redirected to a page with a conversion tracking tag. However, we do not receive any information with which users can be personally identified. User data is processed pseudonymously within the Google advertising network. This means that Google does not store and process the user's name or email address, for example, but processes the relevant data in relation to cookies within pseudonymised user profiles. This means that, from Google's perspective, the adverts are not managed and displayed for a specifically identified person, but for the cookie owner, regardless of who this cookie owner is. This does not apply if a user has expressly allowed Google to process the data without this pseudonymisation. The information collected about users is transmitted to Google and stored on Google's servers in the USA. Further information on the use of data by Google (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), setting and objection options, can be found in Google's privacy policy (https://policies.google.com/technologies/ads) and in the settings for the display of advertisements by Google(https://adssettings.google.com/authenticated).
Google Tag Manager
We use Google Tag Manager to manage website tags. A tag is a JavaScript snippet that is used to send information from a website to third parties, particularly in the context of web tracking. The Google Tag Manager tool itself does not collect any personal data. The tool triggers other tags, which in turn may collect data (e.g. the Google Analytics tag). Google Tag Manager does not access this data. If a deactivation has been made at domain or cookie level, this remains in place for all tracking tags that are implemented with Google Tag Manager. This makes it easier to effectively implement your objections to tracking procedures.
Social media plugins
We currently use the following social media plug-ins: Facebook, Twitter, Instagram, Pinterest. We use the so-called 2-click solution. This means that when you visit our website, no personal data is initially passed on to the providers of these plug-ins. You can recognise the provider of the plug-in by the marking on the greyed-out box using the initial letter. Personal data will only be transmitted if you click on one of the plug-ins: By activating the plug-in, data is automatically transmitted to the respective plug-in provider and stored there (for US providers in the USA). We have no influence on the data collected and data processing operations, nor are we aware of the full extent of the data collection, the purposes and the storage periods. As the plug-in provider collects data via cookies in particular, we recommend that you delete all cookies via your browser's security settings before clicking on the greyed-out box. When you activate a plug-in, the plug-in provider receives the information that you have accessed the corresponding sub-page of our website. In addition, the above-mentioned data is transmitted, whereby in the case of Facebook, according to the respective providers in Germany, only an anonymised IP is collected. This takes place regardless of whether you have an account with this plug-in provider and are logged in there. If you are logged in with the plug-in provider, this data is directly assigned to your account. If you click the activated button and, for example, link the page, the plug-in provider also saves this information in your user account and shares this publicly with your contacts. If you do not wish to be associated with your profile with the plug-in provider, you must log out before activating the button. The plug-in provider stores this data as a user profile and uses it for the purposes of advertising, market research and/or customising its website. Such an evaluation is carried out in particular (even for users who are not logged in) to display customised advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact the respective plug-in provider to exercise this right. Further information on the purpose and scope of data collection and its processing by the plug-in provider can be found in the data protection declarations of these providers provided below. There you will also find further information on your rights in this regard and setting options to protect your privacy. Addresses of the respective providers and URL with their data protection notices:
- Facebook Inc, 1601 S California Ave, Palo Alto, California 94304, USA; facebook./policy.php; further information on data collection: facebook/help
- Twitter, Inc, 1355 Market St, Suite 900, San Francisco, California 94103, USA; https://twitter.com/privacy.
- Instagram, Inc, 181 South Park Street, Suite 2, San Francisco, CA 94107, USA, iinstagram/help.
- WhatsApp, 1601 Willow Road, Menlo Park, California 94025, USA, https://www.whatsapp.com/legal.
Facebook pixel, custom audiences and Facebook conversion
Within our online offer, the so-called ‘Facebook pixel’ of the social network Facebook, which is operated by Facebook Inc, 1601 S California Ave, Palo Alto, California 94304, USA, or if you are resident in the EU, Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (‘Facebook’), is used. With the help of the Facebook pixel, Facebook is able to determine the visitors of our online offer as a target group for the display of adverts (so-called ‘Facebook ads’). Accordingly, we use the Facebook pixel to display the Facebook ads placed by us only to those Facebook users who have also shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited) that we transmit to Facebook (so-called ‘custom audiences’). With the help of the Facebook pixel, we also want to ensure that our Facebook ads correspond to the potential interest of users and are not annoying. With the help of the Facebook pixel, we can also track the effectiveness of Facebook adverts for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook advert (so-called ‘conversion’). Facebook processes the data in accordance with Facebook's data usage policy. Accordingly, general information on the display of Facebook ads can be found in Facebook's data usage policy: facebook.com/policy. Specific information and details about the Facebook pixel and how it works can be found in Facebook's help section: facebook.com/business/help. You can object to the collection by the Facebook pixel and use of your data to display Facebook ads. To set which types of adverts are displayed to you within Facebook, you can go to the page set up by Facebook and follow the instructions there on the settings for usage-based advertising: https://www.facebook.com/settings?tab=ads. The settings are platform-independent, i.e. they are adopted for all devices, such as desktop computers or mobile devices. You can also object to the use of cookies for reach measurement and advertising purposes via the deactivation page of the network advertising initiative http://optout.networkadvertising.org and additionally the US website(http://www.aboutads.info/choices) or the European website .
Server log files
We automatically collect and store information in so-called server log files, which your browser automatically transmits to us when you access our website. These are
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server enquiry They are mainly used for quality assurance of our services.
This data cannot be assigned to specific persons. This data is not merged with other data sources. We reserve the right to check this data retrospectively if we become aware of specific indications of unlawful use.
Cookies and right to object to direct advertising
‘Cookies‘ are small files that are stored on users’ computers. Different information can be stored within the cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. Temporary cookies, or ‘session cookies’ or ‘transient cookies’, are cookies that are deleted after a user leaves an online service and closes their browser. The content of a shopping basket in an online shop or a login status, for example, can be stored in such a cookie. ‘Permanent’ or “persistent” cookies are cookies that remain stored even after the browser is closed. For example, the login status can be saved if the user visits the website after several days. The interests of users can also be stored in such a cookie and used for reach measurement or marketing purposes. ‘Third-party cookies’ are cookies that are offered by providers other than the controller who operates the online service (otherwise, if they are only their cookies, they are referred to as “first-party cookies”). We may use temporary and permanent cookies and clarify this in our privacy policy. If users do not want cookies to be stored on their computer, they are asked to deactivate the corresponding option in the system settings of their browser. Saved cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this online offer. A general objection to the use of cookies used for online marketing purposes can be declared for a large number of services, especially in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be achieved by switching them off in the browser settings. Please note that you may then not be able to use all the functions of this website.
Information, correction, blocking and deletion of data
You have the right to free information about your stored data as well as the right to correction, deletion or blocking at any time. Please contact us if you wish. You will find the contact details under Contact.
Deletion of the data
Unless expressly stated in this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and the deletion does not conflict with any statutory retention requirements. If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons. According to legal requirements in Germany, data is stored in particular for 10 years in accordance with §§ 147 para. 1 AO, 257 para. 1 no. 1 and 4, para. 4 HGB (books, records, management reports, accounting vouchers, commercial books, documents relevant for taxation, etc.) and 6 years in accordance with § 257 para. 1 no. 2 and 3, para. 4 HGB (commercial letters). According to legal requirements in Austria, the retention period is 7 years in accordance with Section 132 (1) BAO (accounting documents, receipts/invoices, accounts, receipts, business papers, statement of income and expenses, etc.), 22 years in connection with real estate and 10 years for documents in connection with electronically provided services, telecommunications, radio and television services provided to non-entrepreneurs in EU member states and for which the Mini-One-Stop-Shop (MOSS) is used. In the event of deletion by us, data will be made unrecognisable and unrecoverable from our systems using an irreversible pseudonymisation process.
Making contact
When contacting us (e.g. by contact form, email, telephone or via social media), the user's details are processed in order to process the contact enquiry and handle it. The user's details may be stored and processed in a customer relationship management system (‘CRM system’) or a comparable organisation tool / ERP system. We delete all contact/enquiries if they are no longer required. We review the necessity at regular intervals. Furthermore, the statutory archiving obligations apply.
Gender-neutral wording
Please note that this privacy policy uses the usual masculine form for personal nouns and pronouns to make it easier to read. However, this does not imply any discrimination against the female gender, but should be understood as gender-neutral in the sense of linguistic simplification.
Muster & Co GmbH
Stubenring 11
AT - 1160 Vienna
Commercial court: Landesgericht Wien
UID: ATU12345678
E-mail: info@musterundco.at
Status 01.01.2024