Introduction

With the following Privacy Policy, we would like to inform you about the types of personal data we process, the purposes for which we process such data, and the extent to which such processing takes place. Personal data is hereinafter also referred to simply as “data”. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (collectively referred to as the “Online Services”).
The terms used are not gender-specific. Last updated: 28 October 2020

Table of Contents

  • Introduction

  • Controller

  • Overview of Data Processing

  • Applicable Legal Bases

  • Security Measures

  • Transfer and Disclosure of Personal Data

  • Data Processing in Third Countries

  • Use of Cookies

  • Provision of the Online Services and Web Hosting

  • Contact

  • Newsletter and Electronic Notifications

  • Plugins and Embedded Functions and Content

  • Deletion of Data

  • Changes and Updates to the Privacy Policy

  • Rights of Data Subjects

  • Definitions

Controller

Additive Manufacturing Austria (AM Austria) e.V.

Association for the Promotion of Additive Manufacturing

Mollardgasse 85a/2/64-69, A-1060 Vienna, Austria

Email: initiative(at)am-austria.com

Phone: +43 (0)1 9346612 200

Legal Notice: https://www.am-austria.com/impressum

Overview of Data Processing

The following overview summarises the types of data processed, the purposes for which they are processed, and the categories of data subjects concerned.

Die nachfolgende Übersicht fasst die Arten der verarbeiteten Daten und die Zwecke ihrer Verarbeitung zusammen und verweist auf die betroffenen Personen.

Types of Data Processed

  • Master data (e.g. names, addresses)

  • Content data (e.g. text entries, photographs, videos)

  • Contact data (e.g. email addresses, telephone numbers)

  • Meta and communication data (e.g. device information, IP addresses)

  • Usage data (e.g. websites visited, interest in content, access times)

  • Location data (data indicating the location of an end user's device)

Categories of Data Subjects

  • Communication partners

  • Users (e.g. website visitors, users of online services)

Purposes of Processing

  • Provision of our Online Services and user-friendliness

  • Notification of members (e.g. by email or post)

  • Contact requests and communication

  • Reach measurement (e.g. access statistics, recognition of returning visitors)

  • Tracking (e.g. use of cookies)

  • Server monitoring and error detection

Applicable Legal Bases

In the following, we inform you about the legal bases under the General Data Protection Regulation (GDPR) on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may also apply in your country of residence or our country of establishment. If more specific legal bases apply in individual cases, we will inform you of these in this Privacy Policy.

  • Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.

  • Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.

  • Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National Data Protection Regulations in Austria

In addition to the data protection provisions of the General Data Protection Regulation, national data protection regulations apply in Austria. In particular, this includes the Federal Act on the Protection of Natural Persons in the Processing of Personal Data (Data Protection Act – DSG).

The Data Protection Act contains, among other things, specific provisions concerning the right of access, the right to rectification or erasure, the processing of special categories of personal data, processing for other purposes, the transfer of data and automated decision-making in individual cases.

Security Measures

In accordance with legal requirements and taking into account the state of the art, the costs of implementation, the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to the data itself, its entry, disclosure, availability and separation.

We have also established procedures to ensure the exercise of data subject rights, the deletion of data and appropriate responses to threats to data. Furthermore, we take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and data protection-friendly default settings.

SSL Encryption (HTTPS)

To protect data transmitted via our Online Services, we use SSL encryption. You can recognise encrypted connections by the prefix https:// in your browser's address bar.

Transfer and Disclosure of Personal Data

As part of our processing of personal data, data may be transferred to or disclosed to other entities, companies, legally independent organisational units or individuals. Recipients of such data may include, for example, payment service providers in connection with payment transactions, service providers commissioned with IT-related tasks, or providers of services and content integrated into a website.

In such cases, we comply with the applicable legal requirements and, in particular, enter into appropriate agreements with recipients of your data to protect your personal data.

Data Processing in Third Countries

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other persons, entities or companies, this will only take place in accordance with the applicable legal requirements.

Unless expressly consented to by you or required for contractual or legal reasons, we only process or have data processed in third countries where an adequate level of data protection is recognised, where contractual obligations have been established through the European Commission's Standard Contractual Clauses, where certifications exist, or where binding internal data protection regulations apply (Art. 44–49 GDPR).

Information provided by the European Commission:
https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en

Use of Cookies

Cookies are text files containing data from visited websites or domains that are stored by a browser on the user's computer. A cookie primarily serves to store information about a user during or after their visit to an Online Service.

The information stored may include, for example, language settings on a website, login status or the point at which a video was watched. The term “cookies” also includes other technologies that perform the same functions as cookies, for example when user information is stored using pseudonymous online identifiers, also known as “user IDs”.

The following types and functions of cookies are distinguished:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest when a user leaves an Online Service and closes their browser.

  • Persistent cookies: Persistent cookies remain stored even after the browser has been closed. They may, for example, be used to save login status or display preferred content directly when a user visits a website again. Persistent cookies may also store users' interests, which can be used for reach measurement or marketing purposes.

  • First-party cookies: First-party cookies are set directly by us.

  • Third-party cookies: Third-party cookies are primarily set by external services used to process user information.

  • Necessary cookies (also known as essential or strictly necessary cookies): Certain cookies are essential for the operation of a website, for example to store logins or other user inputs or for security purposes.

  • Statistics and personalisation cookies: Cookies are also generally used for reach measurement and where a user's interests or behaviour (e.g. viewing specific content or using certain functions) are stored in a user profile on individual websites. Such profiles may be used to display content that corresponds to users' potential interests. This process is also referred to as “tracking”, i.e. tracking users' potential interests. Where we use cookies or tracking technologies, we will inform you separately in this Privacy Policy or as part of obtaining your consent.

Information on Legal Bases

The legal basis on which we process your personal data using cookies depends on whether we ask you for consent. If this is the case and you consent to the use of cookies, your consent constitutes the legal basis for processing your data.

Otherwise, data processed using cookies is processed on the basis of our legitimate interests (e.g. our interest in the economically efficient operation and improvement of our Online Services) or, where the use of cookies is necessary to fulfil our contractual obligations, on that basis.

Storage Period

Unless we provide you with explicit information about the storage period of persistent cookies (e.g. as part of a cookie opt-in), please assume that cookies may be stored for up to two years.

General Information on Withdrawal and Objection (Opt-Out)

Depending on whether processing is based on consent or a legal authorisation, you have the right to withdraw your consent at any time or to object to the processing of your data through cookie technologies (collectively referred to as “opt-out”).

You can initially exercise your objection through your browser settings, for example by disabling the use of cookies. Please note that this may restrict the functionality of our Online Services.

Processing of Cookie Data Based on Consent

Before we process or have data processed through the use of cookies, we ask users for consent, which can be withdrawn at any time. Before consent has been given, only cookies that are strictly necessary for the operation of our Online Services may be used.

Cookie Settings / Opt-Out Option

Types of data processed: Usage data (e.g. websites visited, interest in content, access times), meta and communication data (e.g. device information, IP addresses).

Data subjects: Users (e.g. website visitors, users of online services).

Legal bases: Consent (Art. 6(1)(a) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

This website uses the “CookieYes” tool provided by Mozilor Limited, 3 Warren Yard, Wolverton Mill, Milton Keynes, England, MK12 5NW, United Kingdom (“CookieYes”) to obtain valid user consent for cookies and cookie-based applications that require consent.

By integrating corresponding JavaScript code, the tool displays a banner to users when they access the website, allowing them to provide consent for certain cookies and/or cookie-based applications. The tool blocks the setting of all cookies requiring consent until the respective user has provided the appropriate consent. This ensures that such cookies are only placed on the user's device if consent has been given.

In order for CookieYes to uniquely associate page views with individual users and to record, individually assign and store the user's consent settings for the duration of a session, the cookie consent tool collects certain user information, including the IP address, when the website is accessed and transmits this information to CookieYes servers, where it is stored.

Provision of the Online Services and Web Hosting

In order to provide our Online Services securely and efficiently, we use the services of one or more web hosting providers whose servers (or servers managed by them) are used to make the Online Services available. For these purposes, we may use infrastructure and platform services, computing capacity, storage and database services, as well as security and technical maintenance services.

The data processed as part of the provision of hosting services may include all information relating to users of our Online Services that arises during use and communication. This regularly includes the IP address, which is necessary to deliver the content of Online Services to browsers, as well as all information entered within our Online Services or on websites.

Collection of Access Data and Log Files

We or our web hosting provider collect data each time the server is accessed (so-called server log files). Server log files may include the address and name of the websites and files accessed, the date and time of access, the amount of data transferred, notification of successful access, browser type and version, the user's operating system, the referrer URL (the previously visited page), and generally the IP address and requesting provider.

Server log files may be used for security purposes, for example to prevent server overload, particularly in the event of abusive attacks such as Distributed Denial-of-Service (DDoS) attacks. They may also be used to ensure server capacity and stability.

Types of data processed: Content data (e.g. text entries, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta and communication data (e.g. device information, IP addresses).

Data subjects: Users (e.g. website visitors).

Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors), tracking (e.g. use of cookies), analysis of visitor actions, server monitoring and error detection.

Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).

Services and Service Providers Used

Squarespace: Squarespace provides software as a service for creating and hosting websites.

Service provider: Squarespace, Inc., 8 Clarkson St, New York, NY 10014, USA
Website: https://www.squarespace.com
Privacy Policy: https://www.squarespace.com/privacy

Contact

When contacting us (e.g. via contact form, email, telephone or social media), the information provided by the person making the enquiry is processed to the extent necessary to respond to the enquiry and take any requested action.

Responding to enquiries in the context of contractual or pre-contractual relationships is carried out to fulfil our contractual obligations or to respond to (pre-)contractual enquiries. In other cases, processing is based on our legitimate interest in responding to enquiries.

Types of data processed: Master data (e.g. names, addresses), contact data (e.g. email addresses, telephone numbers), content data (e.g. text entries, photographs, videos).

Data subjects: Communication partners.

Purposes of processing: Contact enquiries and communication.

Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

Newsletter and Electronic Notifications

We only send newsletters, emails and other electronic notifications (hereinafter referred to as “Newsletters”) with the consent of the recipients or where permitted by law. If the content of a Newsletter is specifically described as part of the registration process, this description is relevant to the user's consent. Otherwise, our Newsletters contain information about our services and our organisation.

Deletion and Restriction of Processing

We may retain unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove that consent was previously given. Processing of this data is restricted to the purpose of potentially defending against legal claims.

An individual request for deletion is possible at any time, provided that the previous existence of consent is confirmed at the same time. Where we are legally required to permanently respect objections, we reserve the right to store the email address solely for this purpose on a blocklist.

The logging of the registration process is based on our legitimate interests for the purpose of demonstrating that the registration process was carried out correctly. If we commission a service provider to send emails, this is based on our legitimate interests in an efficient and secure email distribution system.

Information on Legal Bases

Newsletters are sent on the basis of the recipients' consent or, where consent is not required, on the basis of our legitimate interests in notifying our members, provided and to the extent permitted by law.

If we commission a service provider to send emails, this is based on our legitimate interests. The registration process is recorded on the basis of our legitimate interests in order to demonstrate that it was carried out in accordance with the law.

Content

Information about us, our services, activities and offers.

Types of data processed: Master data (e.g. names, addresses), contact data (e.g. email addresses, telephone numbers), meta and communication data (e.g. device information, IP addresses), usage data (e.g. websites visited, interest in content, access times).

Data subjects: Communication partners.

Purposes of processing: Member notifications (e.g. by email or post).

Legal bases: Consent (Art. 6(1)(a) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

Opt-Out Option

You can unsubscribe from our Newsletter at any time, i.e. withdraw your consent or object to further receipt. You will find an unsubscribe link at the end of each Newsletter. Alternatively, you can use one of the contact options listed above, preferably by email.

Services and Service Providers Used

CleverReach: Newsletter platform.

Service provider: CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany
Website: https://www.cleverreach.com/de
Privacy Policy: https://www.cleverreach.com/de/datenschutz/

Plugins and Embedded Functions and Content

We integrate functional and content elements into our Online Services that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos, social media buttons and posts (collectively referred to as “content”).

The integration of such content always requires the third-party providers to process the users' IP addresses, as they would not be able to send the content to users' browsers without the IP address. The IP address is therefore required to display such content or functions.

We endeavour to use only content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes.

Pixel tags can be used to analyse information such as visitor traffic on the pages of this website. Pseudonymous information may also be stored in cookies on users' devices and may include technical information about the browser and operating system, referring websites, time of visit and other information concerning the use of our Online Services. Such information may also be combined with information from other sources.

Information on Legal Bases

If we ask users for their consent to use third-party providers, consent constitutes the legal basis for processing the data. Otherwise, users' data is processed on the basis of our legitimate interests, i.e. our interest in efficient, economical and recipient-friendly services.

In this context, we also refer you to the information on the use of cookies contained in this Privacy Policy.

Types of data processed: Usage data (e.g. websites visited, interest in content, access times), meta and communication data (e.g. device information, IP addresses), location data (data indicating the location of an end user's device).

Data subjects: Users (e.g. website visitors, users of online services).

Purposes of processing: Provision of our Online Services and user-friendliness; contractual services and customer support.

Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).

Services and Service Providers Used

Google Maps: We integrate maps from the “Google Maps” service provided by Google.

The data processed may include, in particular, IP addresses and users' location data. However, such data is not collected without the user's consent, which is generally provided through the settings of their mobile devices.

Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Website: https://cloud.google.com/maps-platform
Privacy Policy: https://policies.google.com/privacy

Opt-out option: Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout?hl=en

Advertising settings: https://adssettings.google.com/authenticated

Deletion of Data

The data processed by us is deleted in accordance with legal requirements as soon as the consent permitting its processing is withdrawn or other permissions cease to apply (e.g. when the purpose of processing the data has ceased to exist or the data is no longer required for that purpose).

If data is not deleted because it is required for other legally permissible purposes, its processing will be restricted to those purposes. In other words, the data will be blocked and not processed for other purposes.

This applies, for example, to data that must be retained for commercial or tax reasons or whose storage is necessary for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person.

Further information concerning the deletion of personal data may also be provided in the individual privacy notices contained in this Privacy Policy.

Changes and Updates to the Privacy Policy

We ask you to regularly review the content of our Privacy Policy. We will amend this Privacy Policy whenever changes to the data processing carried out by us make this necessary.

We will inform you whenever the changes require your cooperation, such as providing consent, or require another form of individual notification.

If we provide addresses and contact information for companies and organisations in this Privacy Policy, please note that such information may change over time. We therefore recommend checking the information before contacting the respective organisation.

Rights of Data Subjects

As a data subject, you have various rights under the GDPR, in particular under Articles 15 to 21 GDPR:

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Art. 6(1)(e) or (f) GDPR, including profiling based on those provisions.

  • Right to withdraw consent: You have the right to withdraw your consent at any time.

  • Right of access: You have the right to obtain confirmation as to whether personal data concerning you is being processed and to obtain access to such data and further information and a copy of the data in accordance with applicable law.

  • Right to rectification: You have the right, in accordance with applicable law, to request the completion of incomplete personal data concerning you or the rectification of inaccurate personal data.

  • Right to erasure and restriction of processing: You have the right, in accordance with applicable law, to request the immediate erasure of personal data concerning you or, alternatively, to request restriction of the processing of such data.

  • Right to data portability: You have the right to receive personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that such data be transmitted to another controller, in accordance with applicable law.

  • Right to lodge a complaint with a supervisory authority: You also have the right, in accordance with applicable law, to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you believe that the processing of your personal data infringes the GDPR.

Supervisory Authority Responsible for Us

Austrian Data Protection Authority (Datenschutzbehörde – DSB)

Barichgasse 40–42
A-1030 Vienna
Austria

Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at

Definitions

This section provides an overview of the terminology used in this Privacy Policy. Many of the terms are taken from the law and are defined, in particular, in Article 4 GDPR. The statutory definitions are legally binding. The explanations below are primarily intended to facilitate understanding. The terms are listed alphabetically.

Personal Data

“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Reach Measurement

Reach measurement (also known as web analytics) is used to analyse visitor traffic to an Online Service and may include analysing visitors' behaviour or interests in relation to specific information, such as website content.

Using reach analysis, website operators can determine, for example, when visitors access their website and which content they are interested in. This enables them to adapt website content more effectively to the needs of their visitors.

Pseudonymous cookies and web beacons are frequently used for reach analysis to recognise returning visitors and obtain more accurate analyses of the use of an Online Service.

Server Monitoring and Error Detection

Server monitoring and error detection are used to ensure the availability and integrity of our Online Services and to use the processed data to technically optimise our Online Services.

The data processed includes performance, capacity utilisation and comparable technical values that provide information about the stability of our Online Services and any irregularities.

In the event of errors or irregularities, individual requests from users of our Online Services may be recorded in order to identify and resolve the source of problems.

Tracking

“Tracking” refers to the ability to monitor users' behaviour across multiple Online Services.

As a general rule, information about users' behaviour and interests in relation to the Online Services they use is stored in cookies or on the servers of providers of tracking technologies (so-called profiling).

This information may subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.

Controller

“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Processing

“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and includes virtually any handling of data, such as collection, analysis, storage, transmission or deletion.