1. Overview
If we welcome you as a customer or business partner, please read from point 3.
If you visit our website, please read from point 2.
2. What data do we process when you visit our website?
Welcome to the website www.elferspot.com! Please get a picture of how we process your personal data when you visit our website (Art 13, Art 14 GDPR; § 165 Abs 3 TKG).
When visiting our website, the following data may be processed:
- Browser type,
- operating system,
- country,
- date,
- Time and duration of access,
- IP address1 and pages visited on our website including entry and exit pages,
- Contact page on website,
- e-mail address,
- payment data,
- telephone number,
- Postal address,
- data in the course of registration
The processing of this data is necessary to manage the security of the operation of the website and to ensure the functionality of the website from a technical point of view. The collection of this data is partly carried out via technical cookies. These technical cookies are only used to the extent necessary (§ 165 Abs 3 TKG). The processing of this data is justified by our legitimate interest in operating our website (Art 6 para 1 lit f GDPR).
In order to operate our website, it may be necessary for us to disclose your information to the following recipients:
Recipient of the data | Purpose of data processing | Legal basis of data processing | Registered office | Basis for transfer to a third country |
Hetzner Online GmbH | Website hosting | Predominant legitimate interests (Art 6 para 1 lit f GDPR) Order processing contract according to Art 28 GDPR | Germany | Within the EEA |
BunnyWay d.o.o. | Website hosting | Predominant legitimate interests (Art 6 para 1 lit f GDPR) Order processing contract according to Art 28 GDPR | Slovenia | Within the EEA |
atomproductions – advertising agency – Photography Thomas Altendorfer | Website- Administration | Predominant legitimate interests (Art 6 para 1 lit f GDPR) Order processing contract according to Art 28 GDPR | Austria | Within the EEA |
PayPal | Payment service provider | Contractual necessity (Art 6 para 1 lit b GDPR) | USA | Listed according to the EU-US Data Privacy Framework |
Stripe, Inc | Payment service provider | Contractual necessity (Art 6 para 1 lit b GDPR) | USA | Listed according to the EU-US Data Privacy Framework |
Intuit Ireland Software Limited Privacy policy of Mailchimp | Newsletter mailing | Consent (Art 6 para 1 lit a GDPR) | Irland | Listed according to the EU-US Data Privacy Framework |
LOGSTA Germany GmbH | Fulfillment provider Shipping service provider | Contractual necessity (Art 6 para 1 lit b GDPR) | Germany | Within the EEA |
Alphabet Inc Google Analytics, Google Ads To the privacy policy of Google: Privacy Policy – Privacy & Terms – Google | Statistical analysis | Consent (Art 6 para 1 lit a GDPR) | USA | Listed according to the EU-US Data Privacy Framework Consent according to Art 49 (1) lit a GDPR |
Meta Platforms, Inc. Instagram Inc For Facebook/Instagram privacy policy, see: | Social media application | Consent (Art 6 para 1 lit a GDPR) | Ireland USA | Listed according to the EU-US Data Privacy Framework Consent according to Art 49 (1) lit a GDPR |
Meta Platforms, Inc. Facebook Inc To the privacy policy of Facebook/Instragram,see: | Social media application | Consent (Art 6 para 1 lit a GDPR) | Ireland USA | Listed according to the EU-US Data Privacy Framework Consent according to Art 49 (1) lit a GDPR |
YouTube For Google’s privacy policy, see: Privacy Policy – Privacy Policy & Terms of Use – Google | Video online platform | Consent (Art 6 para 1 lit a GDPR) | USA | Listed according to the EU-US Data Privacy Framework Consent according to Art 49 (1) lit a GDPR |
X Corp. To the privacy policy of X, see: Privacy (x.com) | Social media application | Consent (Art 6 para 1 lit a GDPR) | USA | Listed according to the EU-US Data Privacy Framework Consent according to Art 49 (1) lit a GDPR |
Pinterest Inc. Pinterest’s privacy policy | Social media application | Consent (Art 6 para 1 lit a GDPR) | Irland | Listed according to the EU-US Data Privacy Framework Consent according to Art 49 (1) lit a GDPR |
2.1 Overview of the “technical” cookies used
The above data is stored via so-called “cookies“2. Cookies are text files that are stored on your computer and allow an analysis of the use of the website. They are used for recognition and storage of temporary data of the homepage visitor. In principle, we only use cookies to the extent necessary to communicate with you via the homepage.
These technical cookies are activated as soon as you visit our website.
The following cookies are used on our platform based on our predominantly legitimate interest (Art 6 para 1 lit f GDPR):
Cookie name | Purpose of the cookie | Duration of storage | Country of domicile of the recipient |
_greaptcha | This cookie is used to distinguish between humans and bots. | persistent | USA |
_GRECAPTCHA www.google.com | This cookie is used to distinguish between humans and bots. | 179 days | USA |
Rc::a; rc::c | This cookie is used to distinguish between humans and bots. | persistent | USA |
Rc::b | This cookie is used to distinguish between humans and bots. | session | USA |
Rc::d-# | This cookie is used to distinguish between humans and bots. | persistent | USA |
CONSENT Youtube.com | Used to determine whether the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for compliance with the GDPR website. | 5949 days | USA |
Test_cookie (Doubleclick.net) | Used to determine whether the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for compliance with the GDPR website. | 1 day | USA |
Wc_cart_hash_# | Used for the purpose of a secure transaction. | persistent | USA |
Wc_fragments _# | Used for the purpose of a secure transaction. | persistent | USA |
Wp-wpml_current_language | Used to determine the appropriate language. | 1 day | USA |
2.2 Overview of the “advertising cookies” used
In addition to the “technical cookies” described above, we also use so-called advertising cookies (including “statistical cookies”). These advertising cookies allow us to better understand and evaluate your interests. With the help of the advertising cookies, we can merge your “surfing behavior” across the boundaries of our website with data from other websites. In this way, we would like to be in a position to better understand the interests of our homepage visitors and to be able to address them in a more targeted manner.
We respect that not every visitor of the website wants this. Therefore, we process your data in the course of advertising cookies only if you consent (Art 6 para 1 lit a GDPR). You can revoke this consent at any time, whereby the data processing carried out until the time of revocation remains justified.
Currently, the following advertising cookies are used:
Cookie name | Purpose | Duration of storage | Name and location of the recipient | Purpose of the transfer to the recipient |
_ga (Google) | Statistical purposes | 6 months | USA | Registers a unique ID that is used to generate statistical data about who uses the website again. |
_gat (Google) | Statistical purposes | 1 day | USA | Used by Google Analytics to limit the request rate |
_gid (Google) | Statistical purposes | 1 day | USA | Registers a unique ID that is used to generate statistical data about who uses the website again. |
_pk_ses# | Statistical purposes | 1 day | Germany | Used by Piwik Analytics Platform to track visitor’s page views during the session. |
Collect (Google) | Statistical purposes | session | USA | Used to send data to Google Analytics about the visitor’s device and behavior. send. Captures the visitor across devices and marketing channels. |
_fbp fr (Facebook) | Marketing purposes | 3 months | USA | Used by Facebook to offer customized product advertising to the visitor. |
Tr (Facebook) | Marketing purposes | session | USA | Used by Facebook to offer customized product advertising to the visitor. |
IDE (doublehlick.net) | Marketing purposes | 1 year | USA | Used by Google DoubleClick to register and report the user’s actions on the website after viewing or clicking on an advertisement of the provider, with the purpose of measuring the effectiveness of advertising and displaying targeted advertising to the user. |
Ads/ga-audiences (Google) | Marketing purposes | session | USA | Used by GooglAds. |
VISTOR_INFO1_Live (youtube.com) | Marketing purposes | 179 days | USA | Tries to estimate user bandwidth on pages with integrated Youtube videos. |
YSC (youtube.com) | Marketing purposes | session | USA | Registers a unique ID to keep statistics of the videos. |
YT.innertube::nextID | Marketing purposes | persistent | USA | Registers a unique ID to keep statistics of the videos from Youtube that the user has watched |
YT.innertube::requests | Marketing purposes | persistent | USA | Registers a unique ID to keep statistics of the videos from Youtube that the user has watched |
Yt-remote-cast-available | Marketing purposes | session | USA | Saves the user settings when retrieving a Youtube video integrated on other web pages |
Yt-remote-cast-installed | Marketing purposes | session | USA | Saves the user settings when retrieving a Youtube video integrated on other web pages |
Yt-remote-connected-devices | Marketing purposes | persistent | USA | Saves the user settings when retrieving a Youtube video integrated on other web pages |
Yt-remote-device-id | Marketing purposes | persistent | USA | Saves the user settings when retrieving a Youtube video integrated on other web pages |
Yt-remote-fast-check-period | Marketing purposes | session | USA | Saves the user settings when retrieving a Youtube video integrated on other web pages |
Yt-remote-session-app | Marketing purposes | session | USA | Saves the user settings when retrieving a Youtube video integrated on other web pages |
Yt-remote-session-name | Marketing purposes | session | USA | Saves the user settings when retrieving a Youtube video integrated on other web pages |
3. For what purposes do we process your data if you are a customer of ours or have a business relationship with us?
In the course of our business relationship with patients and business partners, we process data on the basis of contractual (processing of the contractual relationship with you, pre-contractual obligations, billing for services, dispatch of documents, communication for the processing of the contract) and legal obligations (legally required storage within the meaning of § 132 BAO); (Art 6 para 1 lit b and c GDPR) as well as on the basis of our legitimate interests or on the basis of legitimate interests of third parties (Art 6 para 1 lit f GDPR), namely:
- for the purpose of internal administration and management of your business case to the extent necessary (e.g.: Processing your business case, forwarding your business case to various departments, filing, archiving purposes, correspondence with you);
- Disclosure of data in the course of corporate transactions (e.g. due diligence);
- Delivery of packages;
- For the purpose of direct marketing (e.g.: Mailing, e-mailing, satisfaction surveys, congratulatory letters, statistical evaluations);
We would like to inform you explicitly that you can object to the processing of your data for the purpose of direct marketing.
- Assertion and defense of legal claims
in each case to the extent necessary. The processing of your data serves the initiation, maintenance and settlement of our business relations. If you do not provide us with this data, we will unfortunately not be able to process your business case.
In addition, the transfer of personal data to our processors (within the meaning of Art. 4 Z 8 GDPR) may take place. These processors are listed under point 4.
If applicable, we process your data based on your voluntary, explicit consent (Art 6 para 1 lit a GDPR).
4. How long will your data be stored?
We will only store your data for as long as is necessary for the purposes for which we collected your data. In this context, statutory retention obligations must be taken into account (for example, for reasons of tax law, contracts and other documents from our contractual relationship must generally be retained for a period of seven years (§ 132 BAO)). In justified individual cases, such as for the assertion and defense of legal claims, we may also store your data for up to 30 years after termination of the business relationship.
We store data from interested parties for up to one year from the time the interested party last contacted us.
5. Who may receive your data?
In the course of our business relationship, it may be necessary for us to transmit your data to the following recipients:
Recipient | Purpose | Legal basis | Registered office (country) | Basis for transfer to a third country |
Shipping service provider | Settlement of the legal transaction | Contract fulfillment (Art 6 para 1 lit b GDPR) | In general Austria | Within the EEA |
Buyer (from the dealer’s point of view) | Settlement of the legal transaction | Contract fulfillment (Art 6 para 1 lit b GDPR) | Within the EEA | Within the EEA |
Dealer (from the buyer’s point of view) | Settlement of the legal transaction | Contract fulfillment (Art 6 para 1 lit b GDPR) | Within the EEA | Within the EEA |
Newsletter-Provider (Mailchimp) | Newsletter dispatch | Consent (Art 6 para 1 lit a GDPR) | USA | Standard data protection clauses according to Art 46 (2) lit c GDPR Consent according to Art 49 (1) lit a GDPR |
Chartered accountant and tax consultant | Tax consulting and auditing | Contractual obligation (Art 6 para 1 lit b GDPR) | Austria | Within the EEA |
Banks | Payment processing | Contractual obligation (Art 6 para 1 lit b GDPR) | Within the EEA | Within the EEA |
Lawyers | Pursuit and defense of legal claims | Contractual obligation (Art 6 para 1 lit b GDPR) Predominant legitimate interests (Art 6 para 1 lit f GDPR) | Austria | Within the EEA |
Courts, authorities, online arbitration board | Law Enforcement | Predominant legitimate interests (Art 6 para 1 lit f GDPR) | In general Austria | Within the EEA |
6. Collection of data from other sources (Art 14 GDPR)
In the course of a business relationship or the initiation thereof, it is naturally necessary to conduct research on the business partner. This is done exclusively to the extent necessary for this purpose. In this context, data may be retrieved and processed from the following sources:
Source | Purpose | Legal basis | Data categories |
KSV Credit Protection Association | Check creditworthiness | Predominant legitimate interests (Art 6 para 1 lit f GDPR) | Any entries in the credit record |
7. Does automated decision-making or profiling take place (Art. 13 para. 2 lit f GDPR)?
No automated decision-making or profiling takes place in our company.
8. What rights do you have with regard to data processing?
We would like to inform you that if you meet the legal requirements for this:
- Have the right to request information about which of your data is processed by us (see in detail Art 15 GDPR).
- Have the right to request that inaccurate or incomplete data concerning you be corrected or completed (see in detail Art 16 GDPR).
- Have the right to erasure of your data (see in detail Art 17 GDPR).
- Have the right to object to processing of your data that is necessary to protect our legitimate interests or those of a third party. This applies in particular with regard to the processing of your data for advertising purposes.
- Have the right to receive the transfer of the data you have provided in a structured, common and machine-readable format.
If we process your data on the basis of your consent, you have the right to revoke this consent at any time by e-mail. This does not affect the lawfulness of the data processing carried out up to this point (Art 7 (3) GDPR).
9. What are your rights of appeal?
If, contrary to expectations, there is a violation of your right to lawful processing of your data, please contact us by mail or e-mail. We will make every effort to process your concerns promptly. However, you also have the right to lodge a complaint with the supervisory authority for data protection matters responsible for you.
The address of the Austrian data protection authority is:
Österreichische Datenschutzbehörde
Barichgasse 40-42,
1030 Wien
10. How can you contact us?
If you have any further questions about the processing of your data, please feel free to contact our data protection coordinator using the contact details below.
11. Responsible
Responsible person in the sense of Art 4 Z 7 GDPR is:
Elferspot Media GmbH
Hauptstraße 6, 3rd floor, 4040 Linz, Austria
info@elferspot.com
1 An IP address is a number that is assigned to a device. Devices can communicate over the Internet using this IP address. Each IP address contains information about the Internet service provider used and the physical location of the device used. In this way, information about the user of the device can be obtained.
2 You may refuse the use of cookies by selecting the appropriate settings on your browser. However, we would like to point out that in this case you may not be able to use all functions of this homepage to their full extent.