Data protection

Prime Law

Preamble

PRIME LAW El-Juaneh Romanek Rechtsanwälte GmbH (hereinafter referred to as "PRIME LAW", "we" or "us") attaches the highest priority to the protection of your personal data. In addition to our professional duty of confidentiality, we comply with all data protection regulations, in particular the EU General Data Protection Regulation (hereinafter referred to as "GDPR").

Personal data is information about natural persons who are identified or identifiable (hereinafter referred to as "data subjects"). Personal data includes, for example, name, address, email address, telephone number, date of birth, age, gender, social security number, video recordings or photos. Sensitive data, such as health data or data in connection with criminal proceedings, may also be included.

We process your personal data for different purposes and on different legal bases, depending on whether you visit our website, are or wish to become our client, business partner or supplier, or whether you apply for a job with us.

We only collect personal data that is required to optimize our website, to provide our legal services, to enter into and process business relationships or transactions through our law firm and to carry out application procedures. Furthermore, data voluntarily provided to us may also be processed for the purposes mentioned.

1. responsible persons

The controller within the meaning of the GDPR is the:

PRIME LAW El-Juaneh Romanek Rechtsanwälte GmbH

Annagasse 5/3/15,

Kleinmariazellerhof, staircase 3, top floor

1010 Vienna

Contact e-mail: office@prime-law.at

2. data protection vis-à-vis website visitors

2.1 Data collection on our website

Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator's contact details in the legal notice of this website.

How do we collect your data?
On the one hand, your data is collected when you provide it to us. This may, for example, be data that you enter in a contact form or when you contact us by e-mail.

Other data is collected automatically by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of page view). This data is collected automatically as soon as you enter our website.

What do we use your data for?
Some of the data is collected in order to ensure the error-free provision of the website. Other data may be used to analyze your user behavior.

What rights do you have regarding your data?
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction, blocking or deletion of this data. You can contact us at any time at the address given in the legal notice if you have any further questions on the subject of data protection. You also have the right to lodge a complaint with the data protection authority.

Analysis tools and third-party tools
When you visit our website, your surfing behavior may be statistically evaluated. This is mainly done using cookies and so-called analysis programs. The analysis of your surfing behavior is usually anonymous; the surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. Detailed information on this can be found in the following privacy policy.

You can object to this analysis. We will inform you about the objection options in this privacy policy.

2.2 General notes and mandatory information

Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We would like to point out that data transmission over the Internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.

Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw your consent at any time. All you need to do is send us an informal email. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to lodge a complaint with the competent supervisory authority
In the event of breaches of data protection law, the data subject has the right to lodge a complaint with the competent supervisory authority. In Austria, this is the data protection authority.

Right to data portability
You have the right to have data which we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.

SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Information, blocking, deletion
You have the right to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction, blocking or deletion of this data at any time within the framework of the applicable legal provisions. You can contact us at any time at the address given in the legal notice if you have further questions on the subject of personal data.

Objection to advertising emails
We hereby object to the use of contact data published as part of our duty to provide a legal notice for the purpose of sending unsolicited advertising and information material. The operators of this website expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.

2.3 Data collection on our website

Cookies
Some of the web pages use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies are used to make our website more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called "session cookies". They are automatically deleted at the end of your visit. Other cookies remain stored on your end device until you delete them. These cookies enable us to recognize your browser on your next visit.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

Cookies that are required to carry out the electronic communication process or to provide certain functions that you have requested (e.g. shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the storage of cookies for the technically error-free and optimized provision of its services. Insofar as other cookies (e.g. cookies to analyze your surfing behavior) are stored, these are treated separately in this privacy policy.

[borlabs-cookie type="btn-cookie-preference" title="View/change cookie preference"/]

Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address*

* Your IP address is recorded but immediately pseudonymized. This means that only a rough localization is possible. It is no longer possible to establish a personal reference.

This data is not merged with other data sources.

The basis for data processing is Art. 6 para. 1 lit. f GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.

Contact form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. We will not pass on this data without your consent.

The data entered in the contact form is therefore processed exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. All you need to do is send us an informal email. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.

We will retain the data you provide on the contact form until you request its deletion, revoke your consent for its storage, or the purpose for its storage no longer pertains (e.g. after fulfilling your request). Mandatory statutory provisions - in particular retention periods - remain unaffected.

Registration on this website
You can register on our website in order to use additional functions on the site. We will only use the data you enter for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise we will refuse your registration.

In the event of important changes, for example to the scope of the offer or technically necessary changes, we will use the e-mail address provided during registration to inform you in this way.

The processing of the data entered during registration is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw your consent at any time. All you need to do is send us an informal email. The legality of the data processing that has already taken place remains unaffected by the revocation.

The data collected during registration will be stored by us for as long as you are registered on our website and will then be deleted. Statutory retention periods remain unaffected.

Registration with Facebook Connect
Instead of registering directly on our website, you can register with Facebook Connect. The provider of this service is Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

If you decide to register with Facebook Connect and click on the "Login with Facebook" / "Connect with Facebook" button, you will be automatically redirected to the Facebook platform. There you can log in with your user data. This will link your Facebook profile with our website or our services. This link gives us access to your data stored on Facebook. These are above all

  • Facebook name
  • Facebook profile and cover picture
  • Facebook cover picture
  • E-mail address stored with Facebook
  • Facebook ID
  • Facebook friends lists
  • Facebook Likes ("Like" information)
  • Birthday
  • Gender
  • Country
  • Language

This data is used to set up, provide and personalize your account.

Further information can be found in the Facebook terms of use and the Facebook privacy policy. You can find these at: https://de-de.facebook.com/about/privacy/ and
https://www.facebook.com/legal/terms/.

Comment function on this website
For the comment function on this page, in addition to your comment, information about the time the comment was created, your e-mail address and, if you are not posting anonymously, the user name you have chosen will be saved.

Storage of the IP address
Our comment function stores the IP addresses of users who write comments. As we do not check comments on our site before they are activated, we need this data in order to be able to take action against the author in the event of legal violations such as insults or propaganda.

Subscribing to comments
As a user of the site, you can subscribe to comments after registering. You will receive a confirmation e-mail to check whether you are the owner of the e-mail address provided. You can unsubscribe from this function at any time via a link in the info mails. In this case, the data entered when subscribing to comments will be deleted; however, if you have transmitted this data to us for other purposes and elsewhere (e.g. newsletter subscription), it will remain with us.

Storage duration of comments
The comments and the associated data (e.g. IP address) are stored and remain on our website until the commented content has been completely deleted or the comments must be deleted for legal reasons (e.g. offensive comments).

Legal basis
Comments are stored on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent at any time. All you need to do is send us an informal email. The legality of the data processing operations already carried out remains unaffected by the revocation.

Sharing content via plugins (Facebook, Google+1, Twitter & Co.)
The content on our pages can be shared on social networks such as Facebook, Twitter or Google+ in compliance with data protection regulations. This page uses the eRecht24 Safe Sharing Tool for this purpose. This tool only establishes direct contact between the networks and users when the user actively clicks on one of these buttons.

This tool does not automatically transfer user data to the operators of these platforms. If the user is logged in to one of the social networks, an information window appears when using the social buttons of Facebook, Google+1, Twitter & Co. in which the user can confirm the text before sending it.

Our users can share the content of this site on social networks in compliance with data protection regulations without complete surfing profiles being created by the network operators.

Facebook plugins (Like & Share button)
Plugins of the social network Facebook, provider Facebook Inc, 1 Hacker Way, Menlo Park, California 94025, USA, are integrated on our pages. You can recognize the Facebook plugins by the Facebook logo or the "Like" button on our site. You can find an overview of the Facebook plugins here: https://developers.facebook.com
/docs/plugins/.

When you visit our pages, a direct connection is established between your browser and the Facebook server via the plugin. Facebook receives the information that you have visited our site with your IP address. If you click on the Facebook "Like" button while you are logged into your Facebook account, you can link the content of our pages to your Facebook profile. This allows Facebook to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Facebook. Further information on this can be found in Facebook's privacy policy at: https://de-de.facebook.com/policy.php.

If you do not want Facebook to be able to associate your visit to our pages with your Facebook user account, please log out of your Facebook user account.

Twitter plugin
Functions of the Twitter service are integrated on our pages. These functions are offered by Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. By using Twitter and the "Re-Tweet" function, the websites you visit are linked to your Twitter account and made known to other users. Data is also transmitted to Twitter in the process. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Twitter. Further information on this can be found in Twitter's privacy policy at: https://twitter.com/privacy.

You can change your data protection settings on Twitter in the account settings at https://twitter.com/account/settings
.

Instagram plugin
Functions of the Instagram service are integrated on our pages. These functions are offered by Instagram Inc, 1601 Willow Road, Menlo Park, CA 94025, USA.

If you are logged into your Instagram account, you can link the content of our pages to your Instagram profile by clicking on the Instagram button. This allows Instagram to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Instagram.

Further information on this can be found in Instagram's privacy policy: https://instagram.com
/about/legal/privacy/.

LinkedIn plugin
Our website uses functions of the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.

Each time one of our pages containing LinkedIn functions is accessed, a connection to LinkedIn servers is established. LinkedIn is informed that you have visited our website with your IP address. If you click on the LinkedIn "Recommend" button and are logged into your LinkedIn account, LinkedIn is able to associate your visit to our website with you and your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by LinkedIn.

Further information on this can be found in LinkedIn's privacy policy at: https://www.linkedin.com/legal/privacy-policy.

XING plugin
Our website uses functions of the XING network. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany.

Each time one of our pages containing XING functions is accessed, a connection to XING servers is established. To the best of our knowledge, no personal data is stored in the process. In particular, no IP addresses are stored or usage behavior evaluated.

Further information on data protection and the XING Share button can be found in XING's privacy policy at: https://www.xing.com/app/share?op=data_protection.

Pinterest plugin
On our website we use social plugins from the social network Pinterest, which is operated by Pinterest Inc., 808 Brannan Street, San Francisco, CA 94103-490, USA ("Pinterest").

When you visit a page that contains such a plugin, your browser establishes a direct connection to the Pinterest servers. The plugin transmits log data to the Pinterest server in the USA. This log data may contain your IP address, the address of the websites visited that also contain Pinterest functions, the type and settings of the browser, the date and time of the request, your use of Pinterest and cookies.

Further information on the purpose, scope and further processing and use of the data by Pinterest as well as your rights and options for protecting your privacy can be found in Pinterest's privacy policy: https://about.pinterest.com
/en/privacy-policy.

2.5 Analysis tools and advertising

Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Google Analytics uses so-called "cookies". These are text files that are stored on your computer and enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there.

Google Analytics cookies are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.

IP anonymization
We have activated the IP anonymization function on this website. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Browser plugin
You can prevent the storage of cookies by selecting the appropriate settings in your browser software; however, please note that if you do this you may not be able to use the full functionality of this website. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at the following link: https://tools.google.com
/dlpage/gaoptout ?hl=en.

Objection to data collection
You can prevent the collection of your data by Google Analytics by setting your preferences accordingly under "Cookies".

You can find more information on how Google Analytics handles user data in Google's privacy policy: https://support.google.com/
analytics/answer/6004245?hl=en
.

Contract data processing
We have concluded a contract data processing agreement with Google and fully implement the strict requirements of the data protection authorities when using Google Analytics.

Demographic characteristics in Google Analytics
This website uses the "demographic characteristics" function of Google Analytics. This allows reports to be created that contain statements about the age, gender and interests of site visitors. This data comes from interest-based advertising from Google and from visitor data from third-party providers. This data cannot be assigned to a specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the section "Objection to data collection".

Google Analytics Remarketing
Our websites use the functions of Google Analytics Remarketing in conjunction with the cross-device functions of Google AdWords and Google DoubleClick. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

This function makes it possible to link the advertising target groups created with Google Analytics Remarketing with the cross-device functions of Google AdWords and Google DoubleClick. In this way, interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one device (e.g. cell phone) can also be displayed on another of your devices (e.g. tablet or PC).

If you have given your consent, Google will link your web and app browsing history to your Google account for this purpose. In this way, the same personalized advertising messages can be displayed on every device on which you sign in with your Google account.

To support this function, Google Analytics collects Google-authenticated user IDs that are temporarily linked to our Google Analytics data in order to define and create target groups for cross-device advertising.

You can permanently object to cross-device remarketing/targeting by deactivating personalized advertising in your Google account; follow this link: https://www.google.com/settings
/ads/onweb/.

The aggregation of the data collected in your Google Account is based exclusively on your consent, which you can give or withdraw from Google (Art. 6 para. 1 lit. a GDPR). For data collection processes that are not merged in your Google account (e.g. because you do not have a Google account or have objected to the merging), the collection of data is based on Art. 6 para. 1 lit. f GDPR. The legitimate interest arises from the fact that the website operator has an interest in the anonymized analysis of website visitors for advertising purposes.

Further information and the data protection provisions can be found in Google's privacy policy at: https://www.google.com/
policies/technologies/ads/
.

Google AdWords and Google Conversion Tracking
This website uses Google AdWords. AdWords is an online advertising program of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ("Google").

As part of Google AdWords, we use what is known as conversion tracking. When you click on an ad placed by Google, a cookie is set for conversion tracking. Cookies are small text files that the Internet browser stores on the user's computer. These cookies lose their validity after 30 days and are not used to personally identify the user. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page.

Each Google AdWords customer receives a different cookie. The cookies cannot be tracked via the websites of AdWords customers. The information collected using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users. If you do not wish to participate in tracking, you can object to this use by easily deactivating the Google Conversion Tracking cookie via your Internet browser under user settings. You will then not be included in the conversion tracking statistics.

The storage of "conversion cookies" takes place on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.

You can find more information about Google AdWords and Google conversion tracking in Google's privacy policy:
https://www.google.de/policies/privacy/.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on our websites. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").

The purpose of reCAPTCHA is to check whether data is entered on our websites (e.g. in a contact form) by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, time spent on the website by the website visitor or mouse movements made by the user). The data collected during the analysis is forwarded to Google.

The reCAPTCHA analyses run completely in the background. Website visitors are not informed that an analysis is taking place.

Data processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its website from abusive automated spying and SPAM.

Further information about Google reCAPTCHA and Google's privacy policy can be found at the following links: https://www.google.com/intl/de/
policies/privacy/
and
https://www.google.com/recaptcha/
intro/android.html
.

Facebook Pixel
Our website uses the visitor action pixel from Facebook, Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook") to measure conversions.

This allows the behavior of site visitors to be tracked after they have been redirected to the provider's website by clicking on a Facebook ad. This allows the effectiveness of Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimized.

The data collected is anonymous to us as the operator of this website; we cannot draw any conclusions about the identity of the user. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with the Facebook Data Usage Policy. This allows Facebook to place advertisements on Facebook pages and outside of Facebook. This use of the data cannot be influenced by us as the site operator.

You can find further information on protecting your privacy in Facebook's data protection information: https://www.facebook.
com/about/privacy/
.

You can also activate the remarketing function "Custom Audiences" in the settings area for advertisements at https://www.facebook.com/ads/
preferences/?entry_product
=ad_settings_screen

deactivate it. You must be logged in to Facebook to do this.

If you do not have a Facebook account, you can deactivate usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance:
http://www.youronlinechoices.com/de/

praferenzmanagement/
.

2.6 Newsletter

Newsletter data
If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.

The data entered in the newsletter registration form is processed exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent to the storage of the data, the e-mail address and its use for sending the newsletter at any time, for example via the "UNSUBSCRIBE" link in the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation.

The data you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g. e-mail addresses for the member area) remain unaffected by this.

MailChimp
This website uses the services of MailChimp to send newsletters. The provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.

MailChimp is a service with which, among other things, the sending of newsletters can be organized and analyzed. If you enter data for the purpose of subscribing to the newsletter (e.g. email address), this data is stored on MailChimp's servers in the USA.

MailChimp is certified in accordance with the "EU-US Privacy Shield". The "Privacy Shield" is an agreement between the European Union (EU) and the USA that is intended to ensure compliance with European data protection standards in the USA.

With the help of MailChimp, we can analyze our newsletter campaigns. When you open an email sent with MailChimp, a file contained in the email (known as a web beacon) connects to MailChimp's servers in the USA. This makes it possible to determine whether a newsletter message has been opened and which links, if any, have been clicked on. Technical information is also collected (e.g. time of access, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of the recipients.

If you do not wish to be analyzed by MailChimp, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. You can also unsubscribe from the newsletter directly on the website.

The data processing takes place on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation.

The data you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted from both our servers and MailChimp's servers after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g. e-mail addresses for the member area) remain unaffected by this.

For more information, please refer to MailChimp's privacy policy at: https://mailchimp.com/legal/terms/.

Conclusion of a data processing agreement
We have concluded a so-called "data processing agreement" with MailChimp, in which we oblige MailChimp to protect our customers' data and not to pass it on to third parties. This agreement can be viewed at the following link: https://mailchimp.com/legal
/forms/data-processing-agreement
/sample-agreement/.

2.7 Plugins and tools

YouTube
Our website uses plugins from the Google-operated YouTube site. The operator of the pages is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA.

When you visit one of our pages equipped with a YouTube plugin, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited.

If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.

The use of YouTube is in the interest of an appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.

Further information on the handling of user data can be found in YouTube's privacy policy at: https://www.google.de/intl/de
/policies/privacy.

Vimeo
Our website uses plugins from the video portal Vimeo. The provider is Vimeo Inc, 555 West 18th Street, New York, New York 10011, USA.

When you visit one of our pages equipped with a Vimeo plugin, a connection to the Vimeo servers is established. This tells the Vimeo server which of our pages you have visited. Vimeo also obtains your IP address. This also applies if you are not logged in to Vimeo or do not have a Vimeo account. The information collected by Vimeo is transmitted to the Vimeo server in the USA.

If you are logged into your Vimeo account, you enable Vimeo to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your Vimeo account.

Further information on the handling of user data can be found in Vimeo's privacy policy at: https://vimeo.com/privacy.

Google Web Fonts
This site uses so-called web fonts provided by Google for the uniform display of fonts. When you access a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.

For this purpose, the browser you are using must connect to Google's servers. As a result, Google becomes aware that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.

If your browser does not support web fonts, a standard font will be used by your computer.

Further information on Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/.

Google Maps
This site uses the Google Maps map service via an API. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

To use the functions of Google Maps, it is necessary to save your IP address. This information is usually transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer.

The use of Google Maps is in the interest of an appealing presentation of our online offers and to make it easy to find the places we have indicated on the website. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.

You can find more information on the handling of user data in Google's privacy policy: https://www.google.de/intl/de
/policies/privacy/.

SoundCloud
Plugins from the social network SoundCloud (SoundCloud Limited, Berners House, 47-48 Berners Street, London W1T 3NF, United Kingdom) may be integrated on our pages. You can recognize the SoundCloud plugins by the SoundCloud logo on the affected pages.

When you visit our website, a direct connection is established between your browser and the SoundCloud server once the plugin has been activated. SoundCloud then receives the information that you have visited our site with your IP address. If you click on the "Like button" or "Share button" while you are logged into your SoundCloud user account, you can link and/or share the content of our pages with your SoundCloud profile. This allows SoundCloud to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by SoundCloud. Further information on this can be found in SoundCloud's privacy policy at: https://soundcloud.com/pages/privacy.

If you do not want SoundCloud to associate your visit to our pages with your SoundCloud user account, please log out of your SoundCloud user account before activating content from the SoundCloud plugin.

Spotify
Functions of the Spotify music service are integrated on our pages. The provider is Spotify AB, Birger Jarlsgatan 61, 113 56 Stockholm, Sweden. You can recognize the Spotify plugins by the green logo on our site. You can find an overview of the Spotify plugins at: https://developer.spotify.com.

This allows a direct connection to be established between your browser and the Spotify server when you visit our website via the plugin. Spotify receives the information that you have visited our site with your IP address. If you click on the Spotify button while you are logged into your Spotify account, you can link the content of our pages to your Spotify profile. This allows Spotify to associate your visit to our website with your user account.

Further information on this can be found in Spotify's privacy policy: https://www.spotify.com
/en/legal/privacy-policy/.

If you do not want Spotify to be able to associate your visit to our pages with your Spotify user account, please log out of your Spotify user account.

3. data protection vis-à-vis clients and their contractual partners

In the case of clients and their contractual partners, personal data is processed to carry out pre-contractual measures and to fulfill the contract (Art. 6 para. 1 lit. b GDPR), e.g. to establish purchase contracts and process the transaction as well as to fulfill legal and professional obligations (Art. 6 para. 1 lit. c GDPR).

The main purpose of processing this data is to carry out and process our legal advice and representation. The processing of this data is only partly required by law, but is necessary for the above-mentioned purposes. If you do not wish to provide us with your data, we will not be able to enter into a client relationship with you.

We would also like to inform you that in the course of our legal representation and support, we regularly obtain factual and case-related information about you from third parties.

We will not process the data provided to us for purposes other than those covered by the mandate agreement or otherwise by a provision in accordance with the GDPR. An exception to this is the use for statistical purposes, provided that the data provided has been anonymized.

In order to realize the above-mentioned purposes, it may be necessary to disclose your data to third parties. These third parties include, for example, the opposing party, substitutes, notaries, experts, courts and other authorities, insurance companies, banks, external service providers such as IT service providers, accountants, tax consultants and the Vienna Bar Association. Your data will only be forwarded in accordance with the provisions of the GDPR, in particular to fulfill the mandate or to fulfill our legal and professional obligations.

We will not retain data for longer than is necessary to fulfill our contractual or legal obligations and to defend against any liability claims. In individual cases, this may be up to 30 years after termination of the mandate.

4. data protection vis-à-vis business partners and suppliers

We process the personal data of business partners and suppliers to carry out pre-contractual measures and to fulfill contractual obligations (Art 6 para 1 lit b GDPR) as well as to fulfill legal obligations (Art 6 para 1 lit c GDPR).

The main purpose of processing your data is to initiate and process our contracts for the purchase of goods and services.

The processing is only partly required by law, but is necessary for the above-mentioned purposes. If this data is not provided or not provided in full, no contract can be concluded with the business partner or supplier or we cannot fulfill our legal obligations.

In order to realize the above-mentioned purposes, it may be necessary to pass on your data to substitutes, external service providers such as IT service providers, accountants, tax consultants, clients, courts and other authorities, opponents and experts.

We will not store data for longer than is necessary to fulfill our contractual or legal obligations and to defend against any liability claims.

5. data protection vis-à-vis applicants

We process the personal data of applicants to carry out pre-contractual measures and, if necessary, to fulfill contractual obligations (Art 6 para 1 lit b GDPR) and to fulfill our legal obligations (Art 6 para 1 lit c GDPR).

The processing of applicant data serves the purpose of handling the application procedure and, if necessary, registration with the social security system.

The processing is only partly required by law, but is necessary for the above-mentioned purposes. If this data is not provided or not provided in full, we will not be able to enter into an employment relationship with the applicant or fulfill our legal obligations.

In order to achieve the intended purposes, it may occasionally be necessary for us to disclose your data to substitutes, external service providers such as IT service providers, tax consultants, courts and authorities, payroll accountants and, if necessary, personnel consultants.

Data of applicants who are not hired will be deleted 6 months after notification of rejection, unless we are expressly requested to keep them on record beyond that. Our internal data protection information applies to employees.

6. data security measures

Your personal data is protected by taking appropriate organizational and technical precautions. These precautions relate in particular to protection against unauthorized, unlawful or accidental access, processing, loss, use and manipulation.

Notwithstanding our efforts to maintain an appropriately high level of due diligence at all times, it cannot be ruled out that information that you disclose to us via the Internet may be viewed and used by other persons.

Please note that we therefore accept no liability whatsoever for the disclosure of information due to errors in data transmission not caused by us and/or unauthorized access by third parties (e.g. hacking of e-mail accounts or telephones, interception of faxes).

7. transfer to third countries

The recipients of your personal data may be located outside the EEA or process your personal data there (e.g. in the case of international projects). The level of data protection in these countries may not be the same as in Austria. However, we only transfer your personal data to countries for which the EU Commission has decided that they have an adequate level of data protection or we take measures to ensure that all recipients have an adequate level of data protection, for which we conclude standard contractual clauses (2010/87/EC and/or 2004/915/EC).

8. information on the rights of the data subject affected by the data processing

As a client or generally as a data subject, you have the right to information about your stored personal data, its origin, recipients and the purpose of the data processing (see Art 15 GDPR), as well as a right to rectification (see Art 16 GDPR), erasure (see Art 17 GDPR), restriction of processing (see Art 18 GDPR), data portability (see Art 20 GDPR) and objection (see Art 21 GDPR) at any time, subject to compliance with the lawyer's duty of confidentiality.

You can assert your rights at any time free of charge. You can contact us at the above e-mail address for this purpose.

If you are of the opinion that the processing of your personal data by us violates the applicable data protection law or your data protection claims have been violated in any other way, you have the option of complaining to the competent supervisory authority (see Art 77 GDPR). In Austria, the data protection authority is responsible for this.

9. profiling

We do not use automated decision-making, including profiling.