Privacy Policy

 

Privacy Policy pursuant to Articles 13 and 14 GDPR – Compliance with Information Obligations

In this privacy policy, we provide you with detailed information about how we process your data.

This policy applies both to data processing within tyromotion GmbH and to the use of our website. The legal basis for this data processing is the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

1         Data Processing in General

1.1        Data Controller

The data controller pursuant to Art. 4 (7) GDPR is

tyromotion GmbH
Bahnhofgürtel 59

8020 Graz

 

Phone +43 (316) 908 909
Fax +43 (316) 2311 2391 44
Email: office@tyromotion.com

 

1.2        Data Processing Pursuant to Article 13 GDPR

We process data provided to us by the data subject through their own submissions, such as when subscribing to the newsletter, as part of a job application, when registering for PartnerWeb/CustomerPortal, and when concluding contracts.

1.3        Data Processing Pursuant to Article 14 GDPR

In addition, we also process data that is not provided directly by the data subject themselves. This is the case, for example, when management bodies provide us with the names and contact details of their employees in the context of projects or business relationships.

1.4        Data Subjects

The following data is processed from interested parties: company name, name of the contact person, and professional contact and address information.

The following data is processed for clients: company name, names of contact persons, business address and contact information, bank details, and contract data.

We process the following data from suppliers and partner companies (distribution partners): company name, titles and names of contact persons, business address and contact information, bank details, and contract details.

The following data is processed for newsletter recipients: email address, name and nationality.

We publish the names of authors upon request. As soon as the use of the works is discontinued, the personal data is automatically deleted.

1.5        Legal Basis

The legal basis for data processing is:

  • Consent (e.g., when processing your email address for advertising purposes) pursuant to Art. 6 (1) (a) GDPR
  • Pre-contractual and contractual performance pursuant to Art. 6 (1) (b) GDPR
  • Legal obligations (e.g., legally mandated retention and documentation requirements, disclosure obligations under copyright law) pursuant to Article 6 (1) (c) GDPR
  • Legitimate interests of our company (e.g., use of software) pursuant to Art. 6 (1) (f) GDPR

We will inform you separately about the legal basis and the purpose of the processing for each instance of data processing described below.

1.6        Data Transfer

Data is transferred exclusively for the purpose of contract performance pursuant to Art. 6 (1) (b) GDPR in order to provide you with our services.

  • Transfer within the corporate group: The personal data collected is transferred within the corporate group as necessary. This is necessary because different companies within the corporate group provide different services. The transfer is based on internally concluded contracts.
  • Transfer to processors: We collaborate with processors to whom personal data is transferred in order to provide services efficiently. This includes companies that handle tasks such as contract fulfillment, payment processing, account management, the distribution of newsletters, and IT services.
  • Other Disclosures: In certain cases, such as to comply with legal obligations or in the context of a legal dispute, personal data may be disclosed to government authorities or attorneys.

1.7        Retention/Deletion/Anonymization of Data

  • Contractual retention obligations: Upon termination of a contractual relationship or after the expiration of contractually agreed periods, personal data will be deleted or anonymized as soon as no legal retention obligations prevent this.
  • Withdrawal of Consent: If consent to the processing of personal data is withdrawn, the data will be deleted or anonymized, unless there is another legal basis for the processing.
  • Legal retention obligations: The data controller is subject to a wide range of legal retention obligations. Upon expiration of these legally prescribed retention obligations, personal data is automatically deleted. It may happen that personal data must be retained for legal reasons despite the withdrawal of consent or the expiration of contractually agreed terms and is only deleted at a later date (after the respective statutory periods have expired). The following is a list of the EU regulations and austrian laws that the data controller must comply with (without claiming to be exhaustive):
  • Federal Tax Code (Bundesabgabenordnung – BAO)
  • Commercial Code (Unternehmensgesetzbuch – UGB)
  • Trade Regulation Act (Gewerbeordnung 1994 – GewO 1994)
  • General Civil Code (Allgemeines bürgerliches Gesetzbuch – ABGB)
  • Value Added Tax Act (Umsatzsteuergesetz 1994 – UstG 1994)
  • Whistleblower Protection Act (HinweisgeberInnenschutzgestz – HSchG)
  • Data Protection Act (Datenschutzgestz – DSG)
  • General Data Protection Regulation (GDPR)

2         Contact

When you contact us via email, phone, web form, or social media, the data you provide is stored so we can process your inquiries. This may include the following personal data: name, email address, phone number, or address. We will delete the data collected in this context once processing is no longer necessary, or restrict processing if there are legal retention obligations.

Depending on the nature of your inquiry and our area of responsibility, it may be necessary to forward your inquiry to another company within our corporate group for further processing, provided this is necessary to ensure proper handling.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)

3         Visitor Registration

As part of visitor registration, personal data such as name, contact information, and the date and time of the visit are collected. Processing is carried out exclusively for the purposes of identification, access control, ensuring security on the premises, assisting with emergency and evacuation measures, tracking visits, safeguarding trade secrets, and investigating security incidents. The data is stored for 4 weeks and then deleted.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)

4         Application Management

General: When you submit your application documents to us, we process the personal data contained therein for the purpose of personnel selection and job placement.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual and contractual processing)

Deletion: In the event of a rejection, we will delete your documents 7 months after sending the rejection notice to you.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)

Retention: If we wish to keep your information on file to contact you at a later date, we will reach out to you with a separate request for your consent. If you explicitly grant us this consent, we will store your application documents. If no further opportunity to fill a position with us arises within one year of receiving your consent, we will delete all of your application documents.

Legal basis: Art. 6 (1) (a) GDPR (consent)

Application Portal: All applications are processed through our application portal. For more information, please click here.

Application platforms: We use various online application platforms to recruit employees for our company. Individuals interested in working for our company have the option to apply directly via a form provided by the operator of the application platform. Applicants decide for themselves what data they provide when using such an online portal. Personal data entered and documents uploaded are forwarded to us by the operator of the application platform. Both the application platform and we process this data as data controllers within the meaning of the GDPR. Please review the privacy policies of the respective operators of the application platforms.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual and contractual processing)

5         Social Media Presence

We operate social media pages on Instagram, LinkedIn, X (Twitter), Xing, and Facebook. When you visit our social media presence, personal data—including the IP address provided by the respective provider—is processed, and cookies are used for data collection. Please refer to the privacy policy of the respective service to determine exactly what information is transmitted. There you will also find information on how to contact us and how to restrict the processing of this data.

Furthermore, we would like to point out that you use the respective services and their functions at your own risk. This applies in particular to the use of interactive features (such as sharing, commenting, or rating).

The providers of the social media services have provided us with corresponding agreements—in most cases, these are agreements regarding joint responsibility for data processing. The use of social media platforms is based on our legitimate interest.

If we are required to fulfill data subject rights (see 11), you may contact either us or the provider of the respective social media platform.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)

6         Whistleblowing System

We have set up a whistleblowing system (online whistleblowing system) on our website. The whistleblowing system allows you to contact us and report compliance and legal violations without whistleblowers having to fear reprisals. For more information, please click here.

Legal basis: Art. 6 (1) (c) GDPR (legal obligation)

7         Data processing when using our website

7.1        Informational use of the website

When you use the website for informational purposes only, we collect only the personal data that your browser transmits to our server (server log files). When you access our website, we collect the data that is technically necessary for us to display our website to you and to ensure its stability and security:

  • IP address
  • Date and time of the request
  • Time zone difference from Coordinated Universal Time (UTC)
  • Content of the request (specific page)
  • Access status/HTTP status code
  • Website from which the request originates
  • Browser
  • Operating system and its interface
  • Language and version of the browser software

 

This data is not combined with sources of personal data. We reserve the right to review this data retrospectively if we become aware of specific indications of unlawful use, and to forward the data—should there have been a cyberattack—to law enforcement authorities. No further disclosure to third parties takes place.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)

7.2        Cookies

When you visit our website, cookies are stored on your device. Cookies are small text files that are assigned to the browser you are using and stored on your hard drive. They enable us or third-party providers to collect certain information. Cookies cannot execute programs or transmit viruses to your computer.

The information contained in the cookies is used, for example, to determine whether you are logged in, what data you have already entered, or to recognize you as a user when a connection is established between our web server and your browser.

We distinguish between technical cookies, which serve exclusively to ensure the operation of a website, and cookies requiring consent, which are set by us or third-party providers for the purposes of statistical analysis, tracking, or advertising/marketing.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest; for technical cookies), Art. 6 (1) (a) GDPR (consent; for all other cookies)

7.3        Registration and Login to PartnerWeb

You have the option to sign up for PartnerWeb on our website. To do so, we require login credentials consisting of your email address and a password of your choice.

To register for PartnerWeb, please send us an email to marketing@tyromotion.com. We will send you your initial login credentials for PartnerWeb via email. During the registration process, we process the following personal data: title, first and last names, address, email address, and phone number. You may voluntarily provide your company name, mobile phone number, and date of birth. You can edit the information you have provided at any time in your account settings. We generate a partner number that is also linked to your PartnerWeb account. You can log in to our website at any time using your login credentials.

Legal basis: Article 6 (1) (b) of the GDPR (pre-contractual and contractual processing)

7.4        Registration and Login to the Customer Portal

You have the option to log in to the Customer Portal on our website. To do so, we require login credentials consisting of your email address and a password of your choice.

To gain access to the Customer Portal, please register using the form on our website. During the registration process, we process the following personal data: title, first and last names, address, email address, and phone number. You may voluntarily provide your company name, mobile phone number, and date of birth. You can edit the information you have provided at any time in your account settings. We generate a partner number that is also linked to your Customer Portal account. You can log in to our website at any time using your login credentials.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual and contractual processing)

7.5        Newsletter Subscription

You can subscribe to our newsletter by providing us with your first and last name, your nationality, and your email address. You can unsubscribe at any time. To do so, use the unsubscribe link found in every newsletter or send an email to marketing@tyromotion.com .

To ensure that the registration is actually initiated by you, we use the so-called double opt-in procedure. After you sign up, you will receive a confirmation email with a link. Your subscription will only be activated and your address added to the mailing list once you click this confirmation link. This ensures that no one can use your email address without your consent and that you have explicitly agreed to receive the newsletter.

After you unsubscribe, we will no longer use your data to send the newsletter.

If we have no business relationship with you and are not subject to any legal retention obligations, your data will be deleted after you unsubscribe from the newsletter.

Legal basis: Art. 6 (1) (a) GDPR (consent)

8         Borlabs Cookie (Consent Management)

Our website uses the consent management tool “Borlabs Cookie” provided by Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Germany.

The service uses a technically necessary cookie (borlabs-cookie) to store your cookie consent. The consent management tool records and stores the cookie preferences of each user of our website. With the website visitor’s explicit consent, we ensure that statistical and marketing cookies are only set thereafter.

By integrating the Borlabs cookie on our own server, we guarantee that no data is shared with third parties.

For further information, please refer to Borlabs’ privacy policy at: https://de.borlabs.io/datenschutz/.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)

9         Data Processing for Google Services

We use services provided by Google Ireland Limited (“Google”), a company incorporated and operating under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland, on our website.

For more information, please refer to Google’s Privacy Policy at https://policies.google.com/privacy?hl=de.

9.1        Google Fonts

We use Google Fonts on our website. To ensure a consistent and appealing display of fonts and icons, your browser loads the necessary fonts into your browser cache. To do this, the browser you are using must connect to Google Fonts’ servers, which means that Google Fonts becomes aware that our website has been accessed via your IP address.

You can read about what data Google collects and how it is used at https://www.google.com/intl/de/policies/privacy/.

Legal basis: Art. 6 (1) (a) GDPR (consent)

9.2        Google Maps

We use Google Maps on this website. This allows us to display interactive maps directly on the website and enables you to conveniently use the map. When you visit the website, Google receives information that you have accessed the corresponding page of our website. In addition, the data already mentioned under “Informational Use of the Website” is transmitted. This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data is directly associated with your account. If you do not wish for this association with your Google profile, you must log out before activating the button. Google stores your data as usage profiles and uses them for the purposes of advertising, market research, and/or the needs-based design of its website. Such analysis is carried out in particular (even for users who are not logged in) to provide targeted advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, in which case you must contact Google to exercise this right.

Further information on the purpose and scope of data collection and its processing by the plugin provider can be found in the provider’s privacy policy. There you will also find further information on your rights in this regard and settings options for protecting your privacy: http://www.google.de/intl/de/policies/privacy.

Legal basis: Art. 6 (1) (a) GDPR (consent)

9.3        YouTube

We operate a YouTube channel and have embedded YouTube videos on our website that are stored at http://www.YouTube.com. The operator of YouTube is YouTube, LLC, 901 Cherry Ave., San Bruno, 94066 California, USA. YouTube, LLC is a subsidiary of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

We use YouTube videos in enhanced privacy mode. With this setting, YouTube does not store cookies when you visit our website. A connection to YouTube’s servers is only established when you start playing the embedded videos. YouTube uses cookies for data collection and statistical analysis. In doing so, YouTube is informed which pages you visit. If you are logged into YouTube, your data is directly associated with your account. YouTube uses your data for advertising and market research purposes.

The use of this service involves the transfer of personal data to the United States, or such a transfer cannot be ruled out. Google has obtained certification under the Adequacy Decision for the transfer of personal data to the United States. The European Commission has concluded that an adequate level of protection exists for personal data transferred from the EU to a company in the U.S. certified under the EU-U.S. Data Privacy Framework, which is why data transfer is permissible under Art. 45 GDPR.

The integration of YouTube results in the loading of Google services on our website, such as Google DoubleClick, Google APIs, Google Video, Google Photos, Google Static, and Google Fonts.

For more information on data protection at “YouTube,” please refer to the provider’s privacy policy at: https://www.google.de/intl/de/policies/privacy/

Legal basis: Art. 6 (1) (a) GDPR (consent)

9.4        Google AdSense for YouTube

In connection with embedded YouTube videos, Google may display advertisements via the “Google AdSense for YouTube” service. In doing so, Google uses cookies and similar technologies to display personalized advertisements to users and to analyse interaction with the embedded content.

For more information, visit: https://policies.google.com/privacy.

Legal basis: Art. 6 (1) (a) GDPR (consent)

10    Font Awesome

To ensure consistent display of fonts and icons, our website uses so-called web fonts provided by Font Icons, Inc., 307 S Main St, Bentonville, 72712 Arkansas, USA. To ensure a consistent and appealing display of fonts and icons, your browser loads the necessary web fonts into its cache. To do this, the browser you are using must establish a connection to Font Icons’ servers, which results in Font Icons becoming aware that our website has been accessed via your IP address.

If your browser does not support Font Awesome, a standard font from your computer will be used.

For further information on Font Awesome, please visit the following links: https://fontawesome.com/help as well as the privacy policy at https://fontawesome.com/privacy.

Legal basis: Art. 6 (1) (a) GDPR (consent)

11    Your Rights

You have the following rights with respect to the personal data concerning you:

  • Right of access, rectification, and erasure
  • Right to restriction of processing
  • Right to object to processing
  • Right to data portability

 

In addition to the above rights, you have the right to lodge a complaint with a data protection authority; in Austria, this is the Austrian Data Protection Authority:

  • Address: Barichgasse 40–42, 1030 Vienna
  • Phone: +43 1 52 152-0
  • Email: dsb@dsb.gv.at

If you believe that we have violated Austrian or European data protection laws in the processing of your data and thereby infringed upon your rights, we ask that you contact us so that we may address any questions you may have.

Please send your inquiries and concerns via email to office@tyromotion.com or contact us using the contact information provided.

12    Changes to this Privacy Policy

We reserve the right to make changes to our Privacy Policy from time to time. All changes to the Privacy Policy will be published by us on this page. Please refer to the current version of our Privacy Policy in this regard.