Privacy Policy

This privacy policy informs you about the data processing by Untis GmbH. It applies to all processing operations that are connected with our services, in particular:

  • business communication and contractual relationships,
  • the visit and use of the functions of our online presences (e.g., our website(s)),
  • the application procedure,
  • our marketing offers,
  • our presences in social networks,
  • participation in events (digital and analog).

Not covered is the data processing that arises when using our products (Untis, WebUntis, Untis Mobile, Untis Messenger). To that processing, our separate product privacy policy applies.

Click here for the privacy policy for our products (Untis, WebUntis, Untis Mobile, Untis Messenger)

A. Controller and Data Protection Officer

Controller:
Untis GmbH
Belvederegasse 11
2000 Stockerau
Austria

Authorized representatives:
Christian Gruber, Jürgen Pointinger

M:office(at)untis.at
T: +43 2266 62241

You can reach our data protection officer at:
datenschutz(at)untis.at

B. General Information on Data Processing

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects concerned. Details on the respective processing procedures can be found further below.

I. Types of Data Processed

  • Inventory data (e.g., names, addresses)
  • Applicant data (e.g., personal details, postal and contact addresses, the documents belonging to the application and the information contained therein, such as cover letter, CV, certificates as well as further information about the person or qualification communicated by applicants in relation to a specific position or voluntarily)
  • Content data (e.g., text entries, photographs, videos)
  • Contact data (e.g., email, telephone numbers)
  • Meta-/communication data (e.g., device information, IP addresses)
  • Usage data (e.g., websites visited, interest in content, access times)
  • Contract data (e.g., contract subject, term, customer category)
  • Payment data (e.g., bank details, invoices, payment history)

II. Categories of Data Subjects

  • Employees (e.g., salaried staff, applicants, former employees)
  • Applicants
  • Business and contractual partners
  • Interested parties
  • Communication partners
  • Customers
  • Users (e.g., website visitors, users of online services)

III. Purposes of Processing

  • Provision of our online offering and user-friendliness
  • Evaluation of visit actions
  • Application procedure (establishment and any later performance as well as possible later termination of the employment relationship.)
  • Office and organizational procedures
  • Direct marketing (e.g., by email or by post)
  • Feedback (e.g., collecting feedback via online form)
  • Interest-based and behavior-based marketing
  • Contact inquiries and communication
  • Conversion measurement (measurement of the effectiveness of marketing measures)
  • Profiling (creating user profiles)
  • Remarketing
  • Reach measurement (e.g., access statistics, recognition of returning visitors)
  • Security measures
  • Tracking (e.g., interest-/behavior-based profiling, use of cookies)
  • Contractual services and service
  • Administration and response to inquiries

IV. Relevant Legal Bases

Below we share the legal bases of the General Data Protection Regulation (GDPR) on which we process personal data. Detailed explanations can be found in Section C. Please note that in addition to the provisions of the GDPR, national data protection regulations in your and/or our country of residence and domicile may apply.

  • Consent (Art. 6 para. 1 sentence 1 lit. a GDPR) - The data subject has given their consent to the processing of personal data concerning them for a specific purpose or several specific purposes.
  • Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR) - The processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR) - The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) - The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where the interests or fundamental rights and freedoms of the data subject which require protection of personal data override.
  • Application process as a precontractual and/or contractual relationship (Art. 9 para. 1 sentence 1 lit. b GDPR) - Insofar as, in the context of the application procedure, special categories of personal data within the meaning of Art. 9 para. 1 GDPR (e.g., health data, such as severe disability status or ethnic origin) are requested from applicants so that the controller or the data subject can exercise their rights arising from labor law and social security and social protection law and fulfill their obligations in this regard, their processing is carried out pursuant to Art. 9 para. 2 lit. b GDPR; in the case of the protection of vital interests of applicants or other persons pursuant to Art. 9 para. 2 lit. c GDPR; or for purposes of preventive health care or occupational medicine, for the assessment of the employee’s working capacity, for medical diagnosis, for the provision or treatment in the health or social sector or for the management of systems and services in the health or social sector pursuant to Art. 9 para. 2 lit. h GDPR. In the case of voluntary communication based on consent of special categories of data, their processing is based on Art. 9 para. 2 lit. a GDPR.

National data protection regulations in Austria: In addition to the data protection regulations of the General Data Protection Regulation, national regulations on data protection apply in Austria. These include in particular the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act – DSG). The Data Protection Act contains in particular special provisions on the right of access, the right to rectification or erasure, on the processing of special categories of personal data, on processing for other purposes and on transmission as well as on automated decision-making in individual cases.

V. Security Measures

In accordance with statutory provisions, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of processing as well as the varying probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

The measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, transfer, securing of availability and their separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data and responses to threats to the data. We also take into account the protection of personal data already during the development or selection of hardware, software as well as procedures in accordance with the principle of data protection by design and by default.

SSL encryption (https): To protect your data transmitted via our online offering, we use SSL encryption. You can recognize such encrypted connections by the prefix https:// in your browser’s address line.

VI. Disclosure and Transmission of Personal Data

In the context of our processing of personal data, it occurs that the data are transmitted to other bodies, companies, legally independent organizational units or persons or disclosed to them. Recipients of these data can include, for example, payment institutions in the context of payment transactions, service providers commissioned with IT tasks or providers of services and content that are embedded in a website. In such cases we observe the legal requirements and in particular conclude appropriate contracts or agreements with the recipients of your data that serve the protection of your data.

Data transmission within the corporate group: We can transmit personal data to other companies within our corporate group or grant them access to these data. Insofar as this disclosure is for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and economic interests, or it is carried out insofar as it is necessary to fulfill our contractual obligations or if the consent of the data subjects or a statutory permission exists.

Data transmission within the organization: We can transmit personal data to other bodies within our organization or grant them access to these data. Insofar as this disclosure is for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and economic interests, or it is carried out insofar as it is necessary to fulfill our contractual obligations or if the consent of the data subjects or a statutory permission exists.

Details are set out in Section C below.

VII. Data Processing in Third Countries

Insofar as we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA)) or the processing takes place in the context of the use of services of third parties or the disclosure or transmission of data to other persons, bodies or companies, this is carried out only in accordance with the statutory provisions.

Subject to explicit consent or legally or contractually required transmission, we process or allow the data to be processed only in third countries with a recognized level of data protection or on the basis of special guarantees, such as contractual obligations through so-called standard contractual clauses of the EU Commission, the existence of certifications or binding internal data protection regulations (Artt. 44 to 49 GDPR, informational page by the European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en). Details are set out in Section C below.

VIII. Deletion of Data

The data processed by us are deleted in accordance with the statutory provisions as soon as the consents permitting their processing are revoked or other permissions cease to apply (e.g., if the purpose of the processing of these data has ceased to apply or they are not necessary for the purpose).

If the data are not deleted because they are required for other and legally permissible purposes, their processing is restricted to these purposes. That is, the data are blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax reasons or whose storage is necessary for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person.

Further information on the deletion of personal data can be found in the respective processing information.

C. Use of Cookies

“Cookies” are small files that are stored on users’ devices. Different information can be stored by means of cookies. The information can include, e.g., the language settings on a website, the login status, a shopping cart or the point at which a video was watched.

As a rule, cookies are also used when a user’s interests or their behavior (e.g., viewing certain content, using functions, etc.) are stored in a user profile on individual websites. Such profiles serve to display content to users that corresponds to their potential interests. This procedure is also referred to as “tracking,” i.e., tracking the potential interests of users. We also include under the term cookies other technologies that fulfill the same functions (e.g., when information about users is stored on the basis of pseudonymous online identifiers, also referred to as “user IDs”).

Insofar as we use cookies or “tracking” technologies, we will inform you separately in our privacy policy.

Information on legal bases: Which legal basis is used for the use of cookies and comparable technologies (hereinafter also “information”) follows the respective purpose of use. If the storage of information in the end user’s terminal equipment or access to information already stored in the end user’s terminal equipment serves the transmission of a message via a public telecommunications network, or if the storage of information in the end user’s terminal equipment or access to information already stored in the end user’s terminal equipment is absolutely necessary so that we can provide a digital service expressly requested by the user, the use takes place without consent on the basis of a statutory authorization. In all other cases, we use cookies and comparable technologies only on the basis of your consent. Details are set out in Section C.

On which legal basis under data protection law we process your personal data with the help of cookies and comparable technologies depends on whether we ask you for consent. If this is the case and you consent to the use of cookies (see above), the legal basis for the processing of your data is the declared consent. Otherwise, the data processed with the help of cookies are processed on the basis of Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interests are the disruption-free operation of our online offering.

Withdrawal and objection: Regardless of whether the processing is based on consent or legal permission, you have the possibility at any time to withdraw consent given or to object to the processing of your data by cookie technologies.

You can declare your objection using your browser settings, e.g., by deactivating the use of cookies (whereby this can also restrict the functionality of our online offering).

A withdrawal of consent to the use of cookies requiring consent can be exercised at any time with effect for the future via the consent settings. You can find these at the end of this privacy policy.

D. Detailed Explanations of the Individual Processing Operations

I. Commercial and Business Services

We process data of our contractual and business partners, e.g., customers and interested parties (summarized as “contractual partners”) in the context of contractual and comparable legal relationships and associated measures and in the context of communication with the contractual partners (or precontractual), e.g., to answer inquiries.

We process these data to fulfill our contractual obligations, to safeguard our rights and for purposes of the administrative tasks associated with this information and the entrepreneurial organization. We pass on the data of the contractual partners within the applicable law only insofar as this is necessary for the aforementioned purposes or to fulfill legal obligations or with the consent of the contractual partners (e.g., to involved telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Contractual partners are informed about further processing forms, e.g., for marketing purposes, within the framework of this privacy policy.

Which data are necessary for the aforementioned purposes we inform the contractual partners before or in the context of the data collection, e.g., in online forms, by special marking (e.g., colors) or symbols (e.g., asterisks or similar), or personally.

We delete the data after expiry of statutory warranty and comparable obligations, i.e., generally after the expiry of 4 years, unless the data are stored in a customer account. Insofar as statutory retention periods apply, we store the required data until the expiry of the respective period (e.g., for tax purposes generally 10 years, in Germany generally 8 years). Data that were disclosed to us in the context of an assignment by the contractual partner we delete in accordance with the specifications of the assignment, generally after the end of the assignment.

Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between users and the providers.

Offering software and platform services: We process the data of our users, registered and any test users (hereinafter uniformly referred to as “users”), in order to be able to provide them with our contractual services and on the basis of legitimate interests to be able to ensure the security of our offering and to develop it further. The required information is marked as such in the context of the order, purchase or comparable contract conclusion and includes the information required for the provision of services and billing as well as contact information in order to be able to hold any necessary clarifications.

  • Types of data processed: Inventory data (e.g., names, addresses), payment data (e.g., bank details, invoices, payment history), contact data (e.g., email, telephone numbers), contract data (e.g., contract subject, term, customer category).
  • Data subjects: Interested parties, business and contractual partners.
  • Purposes of processing: Contractual services and service, contact inquiries and communication, office and organizational procedures, administration and response to inquiries.
  • Legal bases: Performance of contract and precontractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR), balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: ensuring the security and further development of our offering).

II. Contacting Us

When contacting us (e.g., via contact form, email, telephone or via social media), the information of the inquiring persons is processed insofar as this is necessary to answer the contact inquiries and any requested measures.

The answering of contact inquiries in the context of contractual or precontractual relationships is carried out to fulfill our contractual obligations or to answer (pre)contractual inquiries and otherwise on the basis of legitimate interests in answering the inquiries.

In special cases, such as an overload of our support department, personal data may be passed on within the corporate group. Order processing contracts have been concluded.

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), content data (e.g., text entries, photographs, videos), usage data (e.g., websites visited, interest in content, access times), meta-/communication data (e.g., device information, IP addresses).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact inquiries and communication, administration and response to inquiries.
  • Legal bases: Performance of contract and precontractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: proper handling of contact inquiries that are not based on a precontractual or contractual relationship).

Services and service providers used (processors):

In selected cases, data transfers may occur with locations in the USA. Zendesk and Salesforce are certified under the EU-US Data Privacy Framework (Art. 45 GDPR).

III. Provision of the Online Offering and Web Hosting

The data processed in the context of the provision of the hosting offering can include all information concerning the users of our online offering that arises in the context of use and communication. This regularly includes the IP address, which is necessary to deliver the contents of online offerings to browsers, and all entries made within our online offering or on websites. To provide our online offering we use hosting service providers. Order processing contracts have been concluded.

Collection of access data and log files: We ourselves (or our web hosting provider) collect data on each access to the server (so-called server log files). The server log files can include the address and name of the accessed websites and files, date and time of access, transferred data amounts, message about successful retrieval, browser type including version, the user’s operating system, referrer URL (the previously visited page) and as a rule IP addresses and the requesting provider.

The server log files can be used, on the one hand, for security purposes, e.g., to avoid an overload of the servers (in particular in the event of abusive attacks, so-called DDoS attacks) and, on the other hand, to ensure the utilization of the servers and their stability.

  • Types of data processed: Content data (e.g., text entries, photographs, videos), usage data (e.g., websites visited, interest in content, access times), meta-/communication data (e.g., device information, IP addresses).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Legal bases: Balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: proper and disruption-free display of our online offering).

IV. Applications

The application process requires that applicants provide us with the data necessary for their assessment and selection. Which information is required results from the job description or, in the case of online forms, from the details given there.

As a rule, the required information includes information about the person, such as name, address, a contact option as well as the proofs of the qualifications necessary for a position. On request we are happy to inform additionally which information is required.

If provided, applicants can submit their applications to us using an online form. The data are transmitted to us encrypted according to the state of the art. Applicants can also submit their applications to us via email. We ask you to note, however, that emails are generally not sent encrypted on the Internet. As a rule emails are encrypted during transmission, but not on the servers from which they are sent and received. We can therefore not assume responsibility for the transmission path of the application between the sender and the receipt on our server.

For the purposes of candidate search, submission of applications and selection of applicants, we can, in compliance with the statutory provisions, use applicant management or recruitment software and platforms and services of third parties.

Applicants are welcome to contact us regarding the type of submission of the application or to send us the application by post.

Processing of special categories of data: Insofar as, in the context of the application procedure, special categories of personal data within the meaning of Art. 9 para. 1 GDPR (e.g., health data, such as, e.g., severe disability status or ethnic origin) are requested from applicants so that the controller or the data subject can exercise their rights arising from labor law and social security and social protection law and fulfill their obligations in this regard, their processing is carried out pursuant to Art. 9 para. 2 lit. b GDPR; in the case of the protection of vital interests of applicants or other persons pursuant to Art. 9 para. 2 lit. c GDPR; or for purposes of preventive health care or occupational medicine, for the assessment of the employee’s working capacity, for medical diagnosis, for the provision or treatment in the health or social sector or for the management of systems and services in the health or social sector pursuant to Art. 9 para. 2 lit. h GDPR. In the case of voluntary communication of special categories of data based on consent, their processing is based on Art. 9 para. 2 lit. a GDPR.

Deletion of data: The data provided by applicants can, in the event of a successful application, be further processed by us for the purposes of the employment relationship. Otherwise, if the application for a job offer is not successful, the applicants’ data are deleted. The applicants’ data are also deleted if an application is withdrawn, which applicants are entitled to do at any time. The deletion takes place, subject to a justified revocation by the applicants, at the latest after the expiry of a period of six months, so that we can answer any follow-up questions about the application and fulfill our burden of proof obligations from the provisions on equal treatment of applicants. Invoices for any reimbursement of travel expenses are archived in accordance with the tax law provisions.

Inclusion in an applicant pool: Inclusion in a candidate pool, if offered, is based on consent. Applicants are informed that their consent to inclusion in the talent pool is voluntary, has no influence on the current application procedure and they can withdraw their consent at any time for the future.

Duration of storage of data in the applicant pool in months:

  • Types of data processed: Applicant data (e.g., personal information, postal and contact addresses, the documents belonging to the application and the information contained therein, such as cover letter, CV, certificates as well as further information about the person or qualification communicated by applicants in relation to a specific position or voluntarily).
  • Data subjects: Applicants.
  • Purposes of processing: Application procedure (establishment and any later performance as well as possible later termination of the employment relationship.).
  • Legal bases: Art. 6 para. 1 sentence 1 lit. b GDPR (application procedure as a precontractual and/or contractual relationship), insofar as, in the context of the application procedure, special categories of personal data within the meaning of Art. 9 para. 1 GDPR (e.g., health data, such as severe disability status or ethnic origin) are requested from applicants so that the controller or the data subject can exercise their rights arising from labor law and social security and social protection law and fulfill their obligations in this regard, their processing is carried out pursuant to Art. 9 para. 2 lit. b GDPR. Otherwise, processing is based on the express consent of Art. 9 para. 2 lit. a GDPR, which you can grant in the individual case.

Services and service providers used (processors):

V. Business Communication and Document Management

In the context of general business communication as well as document management, specifically document storage and administration, calendar management, email dispatch, spreadsheets and presentations, exchange of documents, content and information with certain recipients or publication of websites, forms or other content and information as well as chats and participation in audio and video conferences, master data and contact data of users, data on procedures, contracts, other processes and their contents are processed.

For the purpose of implementation we also use technical solutions from specialized providers (“cloud services”), which enable us to process more effectively. These providers also process, in their own responsibility, usage data and metadata.

Insofar as we provide forms or similar documents and content for other users or publicly accessible websites with the help of cloud services, the providers can store cookies on the users’ devices for the purposes of web analysis or to remember user settings (e.g., in the case of media control). Further information on cookies can be found above in this privacy policy.

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), content data (e.g., text entries, photographs, videos), usage data (e.g., websites visited, interest in content, access times), meta-/communication data (e.g., device information, IP addresses).
  • Data subjects: Customers, employees (e.g., salaried staff, applicants, former employees), interested parties, communication partners.
  • Purposes of processing: Office and organizational procedures.
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), performance of contract and precontractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: efficient and secure administrative and collaboration processes).

Services and service providers used (processors):

In selected cases, data transfers may occur with locations in the USA. Microsoft is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).

VI. Newsletter and Broad Communication

We send newsletters, emails and other electronic notifications (hereinafter “newsletter”) only with the consent of the recipients or a statutory permission. Insofar as the contents of the newsletter are specifically described in the context of registration, they are decisive for the users’ consent. Otherwise, our newsletters contain information about our services and us.

To sign up for our newsletters, it is generally sufficient if you provide your email address. However, we may ask you to provide a name, for the purpose of personal addressing in the newsletter, or further information insofar as these are required for the purposes of the newsletter.

Double opt-in procedure: Registration for our newsletter generally takes place in a so-called double opt-in procedure. That is, after registration you receive an email in which you are asked to confirm your registration. This confirmation is necessary so that no one can register with third-party email addresses. The registrations for the newsletter are logged in order to be able to prove the registration process in accordance with legal requirements. This includes the storage of the registration and confirmation time as well as the IP address. Changes to your data stored with the dispatch service provider are also logged.

Deletion and restriction of processing: We can store unsubscribed email addresses for up to three years on the basis of our legitimate interests before we delete them, in order to be able to prove a previously given consent. The processing of these data is restricted to the purpose of a possible defense against claims. An individual deletion request is possible at any time, provided that the former existence of a consent is confirmed at the same time. In the case of obligations to permanently observe objections (in the case of newsletters sent without consent), we reserve the right to store the email address solely for this purpose on a blacklist.

Notes on legal bases: The sending of newsletters is based on the consent of the recipients or, if consent is not required, on our legitimate interests in direct marketing, insofar and to the extent that these are legally permitted, e.g., in the case of advertising to existing customers. The registration procedure is recorded on the basis of our legitimate interests, to prove that it was carried out in accordance with the law.

Success measurement: The newsletters contain a so-called “web beacon,” i.e., a one-pixel file that is retrieved when the newsletter is opened from our server, or, if we use a dispatch service provider, from its server. In the course of this retrieval, technical information is initially collected, such as information about the browser and your system, as well as your IP address and the time of retrieval.

This information is used to technically improve our newsletter based on the technical data or the target groups and their reading behavior based on their retrieval locations (which can be determined with the help of the IP address) or the access times. This analysis also includes determining whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons this information can be assigned to individual newsletter recipients. However, it is neither our intention nor, if used, that of the dispatch service provider to observe individual users. The evaluations serve us rather to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.

The evaluation of the newsletter and the success measurement are based on the consent that you give to receive the newsletter.

A separate withdrawal of the success measurement is unfortunately not possible; in this case the entire newsletter subscription must be canceled or must be objected to.

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), meta-/communication data (e.g., device information, IP addresses), usage data (e.g., websites visited, interest in content, access times).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g., by email or by post).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: promotional communication in the case of a legal authorization, evidence that consent was given (double opt-in procedure)).

Withdrawal and objection option (opt-out): You can cancel receipt of our newsletter at any time, i.e., withdraw your consent or object to further receipt. A link to cancel the newsletter can be found at the end of each newsletter. Alternatively, you can contact one of the contact options given above, preferably email.

Services and service providers used (processors):

  • CleverReach: Email marketing platform; service provider: “CleverReach” — CleverReach GmbH & Co. KG; Schafjückenweg 2, 26180 Rastede; Germany; website: cleverreach.com; privacy policy: https://www.cleverreach.com/en/privacy-policy/

VII. Advertising Communication via Post, Fax or Telephone

We process personal data for the purposes of advertising communication, which can take place via various channels, such as email, telephone, post or fax. In this context we observe the legal requirements and obtain the required consents insofar as the communication is not legally permitted.

The recipients have the right to withdraw consents given at any time or to object to advertising communication at any time.

After withdrawal we can store the data required to prove the consent for up to three years on the basis of our legitimate interests before we delete them. The processing of these data is restricted to the purpose of a possible defense against claims. An individual deletion request is possible at any time, provided that the former existence of a consent is confirmed at the same time.

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g., by email or by post).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: promotional external presentation).

VIII. Online Marketing

We process personal data for the purposes of online marketing, which includes in particular the display of advertising and other content (collectively referred to as “content”) based on potential interests of the users and the measurement of their effectiveness.

For these purposes, so-called usage profiles are created and stored in a file (so-called “cookie”) or similar procedures are used, by means of which the information relevant to the display of the aforementioned content is stored about the user. This information can include, e.g., viewed content, websites visited, online networks used, but also communication partners and technical information, such as the browser used, the computer system used as well as information on usage times. Insofar as users have consented to the collection of their location data, these can also be processed.

The IP addresses of the users are also stored. However, we use IP masking procedures (i.e., pseudonymization by shortening the IP address) to protect the users. In general, in the context of online marketing procedures, no clear data of the users (such as email addresses or names) are stored, but pseudonyms. That is, neither we nor the providers of the online marketing procedures know the actual identity of the users, only the information stored in their profiles.

The information in the profiles are generally stored in the cookies or by means of similar procedures. These cookies can later generally also be read on other websites that use the same online marketing procedure and analyzed for the purposes of displaying content as well as supplemented with further data and stored on the server of the provider of the online marketing procedure.

In exceptional cases clear data can be assigned to the profiles. This is the case if users are, e.g., members of a social network whose online marketing procedure we use and the network links the users’ profiles to the above-mentioned information. We ask you to note that users can make additional agreements with the providers, e.g., by giving consent in the context of registration.

We generally only gain access to aggregated information about the success of our advertisements. However, we can, in the context of so-called conversion measurements, check which of our online marketing procedures have led to a so-called conversion, i.e., e.g., to a contract conclusion with us. Conversion measurement is used solely to analyze the success of our marketing measures.

In this context we also refer you to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g., websites visited, interest in content, access times), meta-/communication data (e.g., device information, IP addresses).
  • Data subjects: Users (e.g., website visitors, users of online services), interested parties.
  • Purposes of processing: Tracking (e.g., interest-/behavior-based profiling, use of cookies), remarketing, evaluation of visit actions, interest-based and behavior-based marketing, profiling (creating user profiles), conversion measurement (measurement of the effectiveness of marketing measures), reach measurement (e.g., access statistics, recognition of returning visitors).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR)

Withdrawal option (opt-out): A withdrawal of consent to the use of cookies requiring consent can be exercised at any time with effect for the future via the consent settings. You can find these at the end of this privacy policy.

Services and service providers used:

IX. Social Media

We maintain online presences within social networks in order to communicate with the users active there or to offer information about us there. We use the services Instagram and LinkedIn.

As the operator of our Instagram page, we are jointly responsible under data protection law with Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Meta”). As the operator of our LinkedIn company page, we are jointly responsible under data protection law with LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (“LinkedIn”).

In connection with the operation of our Instagram page, we use the Page Insights function to receive statistical evaluations of the users of our Instagram page. With the agreement that we have concluded with Meta, Instagram acknowledges the joint responsibility under data protection law with regard to so-called Insights data and assumes essential data protection obligations for the information of data subjects, for data security and for reporting data protection violations. It is also stipulated in the agreement that Facebook is the primary contact in exercising data subject rights (Art. 15–22 GDPR). Because as the provider of the social network, Instagram alone has the immediate access possibilities to the required information and can also immediately take any required measures and provide information. Should our support nevertheless be required, we can be contacted at any time.

The same applies to the operation of our LinkedIn company page. LinkedIn provides us with Page Insights in aggregated form; for the collection and combination of these data we and LinkedIn are jointly responsible. We have accepted the agreement on joint responsibility by using the LinkedIn page. LinkedIn assumes the essential part of the data protection obligations, including the fulfillment of data subject rights pursuant to Art. 15–22 GDPR as well as the reporting and notification obligations in the case of data protection violations. We forward requests on data subject rights immediately to LinkedIn. You can contact us at any time for this.

We point out that users’ data can be processed outside the European Union. This can result in risks for users because, e.g., the enforcement of users’ rights could be made more difficult. Both Meta and LinkedIn are certified under the EU-US Data Privacy Framework (DPF) and additionally base third-country transfers on standard data protection clauses approved by the EU Commission.

Furthermore, users’ data are as a rule processed within social networks for market research and advertising purposes. For example, usage profiles can be created on the basis of users’ usage behavior and the interests that result from this. The usage profiles can in turn be used to place, e.g., advertisements within and outside the networks that presumably correspond to users’ interests. For these purposes cookies are as a rule stored on the users’ computers, in which the usage behavior and the interests of the users are stored. Furthermore, data can also be stored in the usage profiles independently of the devices used by the users (in particular if the users are members of the respective platforms and are logged in there).

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), content data (e.g., text entries, photographs, videos), usage data (e.g., websites visited, interest in content, access times), meta-/communication data (e.g., device information, IP addresses).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Contact inquiries and communication, tracking (e.g., interest-/behavior-based profiling, use of cookies), remarketing, reach measurement (e.g., access statistics, recognition of returning visitors).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: promotional external presentation (processing via the respective profile)).

Services and service providers used:

X. YouTube

We use YouTube videos on our website. YouTube is a company of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: “Google”). The implementation takes place on the basis of your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. Here we use the option of “enhanced privacy mode” provided by YouTube.

When you call up a page that has an embedded video, a connection to the YouTube servers is established and the content is displayed on the website by notifying your browser. YouTube additionally places cookies on your computer.

According to YouTube, in “enhanced privacy mode” your data — in particular which of our websites you have visited as well as device-specific information including the IP address — are only transmitted to the YouTube server in the USA when you watch the video. By clicking on the video you consent to this transmission.

If you are logged in to YouTube at the same time, this information is assigned to your member account at YouTube. You can prevent this by logging out of your member account before visiting our website.

The data are transmitted to servers of Google in the USA. The USA are so-called insecure third countries. This means that in the USA a level of data protection comparable to that in the EU is not guaranteed. Google is DPF-certified. Google additionally bases the transfer to the USA on standard contractual clauses approved by the EU Commission. A copy of the standard contractual clauses can be found here: https://policies.google.com/privacy/frameworks?hl=en.

Further information on data protection in connection with YouTube can be found here: https://policies.google.com/privacy?hl=en.

XI. Untis Conference in Salzburg

Untis GmbH holds an annual event (“Untis Conference”) for partners, users, school principals and administrators as well as government representatives. For the purpose of organizing this event, the processing of personal data of registered participants is necessary. These data are kept for up to 3 years in order to be able to refer, for organizational purposes, to the data of participation of the previous Untis Conference for the respective subsequent Untis Conference.

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), content data (e.g., text entries, photographs, videos), meta-/communication data (e.g., device information, IP addresses).
  • Data subjects: Registered participants.
  • Purposes of processing: Contact inquiries and communication, event organization, marketing communication around the event.
  • Legal bases: Art. 6 para. 1 sentence 1 lit. b GDPR; balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: maintaining contact).

XII. Webinars and online trainings

Untis GmbH offers online trainings (“webinars”) for customers and interested parties in order to give them an overview of available solutions and products that were developed by Untis or integration partners. For the purpose of organizing these webinars, the processing of personal data of registered participants is necessary. In the case of local/regional implementation of the webinar, data required for this are forwarded to the regional Untis sales partner (https://www.untis.at/untis-partner). These data are kept for up to 1 year. A further use of these data for marketing purposes does not take place.

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), meta-/communication data (e.g., device information, IP addresses).
  • Data subjects: Registered participants.
  • Purposes of processing: Contact inquiries and communication around the webinar.
  • Legal bases: Art. 6 para. 1 sentence 1 lit. b GDPR; balancing of interests (Art. 6 para. 1 sentence 1 lit. f GDPR; legitimate interests: extra-contractual communication in the context of the implementation and follow-up of webinars).

Services and service providers used (processors):

E. Rights of Data Subjects

As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Arts. 15 to 18 and 21 GDPR:

  • Right to object: You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you that is carried out on the basis of Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. If personal data concerning you are processed for the purpose of direct advertising, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling insofar as it is connected with such direct advertising.
  • Right to withdraw consent: You have the right to withdraw consents given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you are being processed and to information about these data as well as to further information and a copy of the data in accordance with the legal provisions.
  • Right to rectification: You have the right, in accordance with the legal provisions, to request the completion of data concerning you or the rectification of incorrect data concerning you.
  • Right to erasure and restriction of processing: You have the right, in accordance with the legal provisions, to demand that data concerning you be erased without delay, or alternatively, in accordance with the legal provisions, to demand a restriction of the processing of the data.
  • Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal provisions, or to demand their transmission to another controller.
  • Complaint to supervisory authority: You also have the right, in accordance with the legal provisions, to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you violates the GDPR.

Change and update of the privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes in the data processing we carry out make this necessary. We inform you as soon as the changes require an act of cooperation on your part (e.g., consent) or any other individual notification.

Annex: Definitions

In this section you will receive an overview of the terms used in this privacy policy. Many of the terms are taken from the law and are defined primarily in Art. 4 GDPR. The legal definitions are binding. The following explanations, in contrast, are primarily intended to aid understanding. The terms are sorted alphabetically.

  • Evaluation of visit actions: “Evaluation of visit actions” (English “conversion tracking”) refers to a procedure by which the effectiveness of marketing measures can be determined. For this purpose, as a rule, a cookie is stored on the users’ devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, we can thus track whether the ads we place on other websites were successful).
  • IP masking: “IP masking” is a method in which the last octet, i.e., the last two numbers of an IP address, is deleted so that the IP address can no longer serve to uniquely identify a person. Therefore, IP masking is a means of pseudonymization of processing procedures, in particular in online marketing.
  • Interest-based and behavior-based marketing: One speaks of interest- and/or behavior-based marketing when the potential interests of users in ads and other content are determined as precisely as possible. This is done on the basis of information about their previous behavior (e.g., visiting certain websites and staying on them, purchasing behavior or interaction with other users), which is stored in a so-called profile. For these purposes, cookies are used as a rule.
  • Conversion measurement: Conversion measurement is a procedure by which the effectiveness of marketing measures can be determined. For this purpose, as a rule, a cookie is stored on the users’ devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, we can thus track whether the ads we place on other websites were successful.
  • Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by assignment to an identifier such as a name, to an identification number, to location data, to an online identifier (e.g., cookie) or to one or more special characteristics that are expression of the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiling: “Profiling” means any form of automated processing of personal data consisting of the use of personal data to analyze, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this includes information concerning age, gender, location and movement data, interaction with websites and their content, purchasing behavior, social interactions with other people). For purposes of profiling, cookies and web beacons are frequently used.
  • Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering and can include the behavior or interests of the visitors in certain information, such as website content. With the help of reach analysis, website owners can, e.g., recognize at what time visitors visit their website and which content they are interested in. This allows them, e.g., to better adapt the content of the website to the needs of their visitors. For purposes of reach analysis, pseudonymous cookies and web beacons are frequently used to recognize returning visitors and thus obtain more precise analyses of the use of an online offering.
  • Remarketing: “Remarketing” or “retargeting” refers to when, e.g., for advertising purposes, it is noted which products a user has been interested in on a website in order to remind the user of these products on other websites, e.g., in advertisements.
  • Tracking: “Tracking” refers to when the behavior of users can be traced across several online offerings. As a rule, behavior and interest information regarding the online offerings used is stored in cookies or on servers of the providers of tracking technologies (so-called profiling). This information can subsequently be used, e.g., to display advertisements to users that likely correspond to their interests.
  • Controller: “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: “Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and encompasses practically any handling of data, whether collecting, evaluating, storing, transmitting or erasing.

Last change: 3.9.2026