This privacy statement provides an overview of how your data will be processed by Kotányi.
1. Information in accordance with Article 13 GDPR
The purpose of this privacy statement is to inform you of the purpose, nature and scope of the use of your data, as well as your rights regarding your data.
2. Data controller
3. Purpose of and legal basis for processing
Personal data is processed solely on the legal basis of your consent, an existing contract, legislative provisions or a legitimate interest of Kotányi.
In addition, we only collect personal data that you have provided explicitly and voluntarily; for example, if you apply for a job with us via the career portal, or if you subscribe to our newsletter. We only use this type of information for the corresponding purposes and in accordance with the valid statutory provisions; any further use is only carried out with your consent.
4. Data storage
When you access our website, data is stored temporarily on our server for data security purposes. Each data record comprises:
- The IP address of the end device.
- The time stamp for the access (date, time).
- The name of the file requested.
- The type of device used.
- The name of the browser used.
- The defined browser language.
- The name of the operating system used.
- The amount of data transmitted.
- The access status (file transmitted, file not found, etc.).
- The name of the Internet provider.
- The content of any forms completed.
4.1 Legal basis
The data that are recorded help us to identify the causes of potential technical problems, optimize our Internet presence in technical terms, and guarantee the security of our IT infrastructure.
We have a legitimate interest in storing the data on a temporary basis pursuant to Article 6(1)(f) GDPR. The collection of these data is essential for the operation of our website. Visitors to the website do not therefore have a right to object.
5. Data and information security
Your data is exclusively processed subject to the following technical and organizational measures (Article 32 GDPR):
- Declaration of confidentiality from all staff.
- Multilevel access checks.
- Multilevel user authentication checks.
- Video surveillance.
- Individual authorization concepts.
- Encrypted communication via SSL.
- Secure IT infrastructure.
6. Data transfer
Your data is only shared with third parties for the following purposes:
- Article 6, Paragraph 1(a) GDPR
- Article 6, Paragraph 1(b) GDPR
- Article 6, Paragraph 1(c) GDPR
- Article 6, Paragraph 1(f) GDPR
7. Application procedure
We process your personal data in accordance with the provisions of the European Union General Data Protection Regulation (EU GDPR) to the extent necessary for us to decide whether to establish an employment relationship. The legal basis for the data processing operations is Article 88 GDPR and, where applicable, Article 6(1)(b) GDPR regarding the performance of a contract or steps prior to performance of a contract.
We may also process your personal data if this is necessary for compliance with a legal obligation (Article 6(1)(c) GDPR) or to defend against any legal claims asserted against us. The legal basis for the latter is Article 6(1)(f) GDPR. The legitimate interest may be e.g. an obligation to provide evidence in proceedings under the German General Equal Treatment Act. If you give us express consent to the processing of your personal data for certain purposes, the legality of this processing is based on your consent according to Article 6(1)(a) GDPR. After giving consent, you can revoke it at any time with effect for the future (see Section 12).
If you enter into an employment relationship with us, pursuant to Article 88 GDPR we can continue processing the personal data already received from you for the purposes of that relationship, to the extent that this is necessary for the performance or termination of the relationship or for the exercise or performance of the rights and obligations of the party representing the interests of employees based on a law, a wage agreement or a works or service agreement (collective agreement).
The data released with your consent will be stored in our applicant database so that, if we cannot offer you an appropriate position at the moment, we can inform you at a later date about new career opportunities within Kotányi. Your data will be stored for a period of six months for this purpose. If you expressly agree, the period may be extended to 12 months.
If you send us your application in a hard copy form (i.e. not electronically), we use the service “CVlizer” provided by JoinVision E-Services GmbH, FN271009v, Wehrgasse 28, 1050 Vienna (“JoinVision”) to allow us to process with greater speed.
7.1.1 Contract data processing agreement
Processing is carried out on the basis of a contract data processing agreement concluded between Kotányi and JoinVision pursuant to Article 28 GDPR and related technical and organizational measures.
Cookies are small text files that are stored by websites you visit on the end device you are using, via your browser. These text files can be used to identify you or analyze your behavior.
We do not use any analytical cookies without your explicit consent. You can also adjust your cookie preferences in your web browser settings. Further information can be found in your browser’s Help portal.
We use the following categories of cookies on our pages:
8.1 Functional cookies
8.1.1 Purpose of processing
We use functional cookies to allow you to use our website more easily. They also make our website more secure.
8.1.2 Legal basis
We have a legitimate interest in processing functional cookies. The legal basis is therefore Article 6(1)(f) GDPR.
When you access our website, the cookie “__cfduid” is loaded. This cookie is used by the CloudFlare service to identify trusted Internet traffic, manage load balancing and increase the security of our website. The information that is stored is anonymized and encrypted.
22.214.171.124 Retention time
If you have already interacted with our cookie notice, we will save your decision so that we do not need to display the notice again for a certain period of time. To do so, we set either the “cookie-reject” or the “cookie-consent” cookie to “true”.
126.96.36.199 Retention time
8.2 Analytics cookies
8.2.1 Purpose of processing
We use analytical cookies to improve our Internet presence and (depending on the relevant cookie) for targeted online advertising.
8.2.2 Legal basis
We will only process analytical cookies with your consent. The legal basis is therefore Article 6(1)(a) GDPR.
8.2.3 Facebook Pixel
With your consent, our website uses “Facebook pixel” from Facebook, Inc., 1601 S California Ave, Palo Alto, California 94304, USA or, if you are resident in the EU, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). This allows us to track users’ actions once they have viewed or clicked on a Facebook advert, so we can monitor the effectiveness of Facebook ads for statistics and market research purposes. The data that is collected is anonymized for us; in other words, we cannot see any personal data and we are unable to draw any conclusions about the identity of individual users. Facebook can use this data for its own advertising purposes, in accordance with the Facebook data policy (https://www.facebook.com/about/privacy/). You can allow Facebook and its partners to enable the display of adverts within and outside of Facebook.
188.8.131.52 Contract data processing agreement
Processing is carried out on the basis of an order data processing contract concluded between Kotányi and Google pursuant to Article 28 GDPR and related technical and organizational measures.
184.108.40.206 Google Remarketing, “New Interactions” or “Similar Target Groups”
In order to present you with personalized and appropriate advertising within the Google Display network after you have visited our website, we use the Remarketing functions “Re-engagement” or “Similar audiences” provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). If you grant consent, Google stores cookies on your device in order to analyze your usage behavior. According to Google, no personal data is stored or collated. Google Remarketing achieves this through the use of pseudonymization (among other methods).
You can disable Google device or cookie detection by following this link: http://www.google.com/settings/ads
To deactivate personalized advertising from other advertising networks, you can also use the following service from “Your Online Choices”: http://www.youronlinechoices.com/at/praferenzmanagement
220.127.116.11 Google Analytics
This website uses functions from the Google Analytics web analysis service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). If you provide consent, the service places cookies on your end device for analytical purposes. Generally speaking, the information about your use of this website that is generated by the cookies is sent to a Google server in the USA and stored there.
On our behalf, Google will use this information stored in cookies to evaluate your use of the website to compile reports on website activity and to provide Kotányi with additional services relating to website usage and Internet usage. The IP address forwarded by your browser in connection with Google Analytics is not combined with any other data from Google.
You can also stop Google from collecting the data generated by the cookies and relating to your use of the website (including your IP address), and from processing this data by downloading and installing the plugin that is available from the following link: https://tools.google.com/dlpage/gaoptout?hl=de
You can also check your privacy settings via the following link: https://myaccount.google.com/privacy?pli=1#ads
More detailed information can be found in the Google data protection policies: https://www.google.com/analytics/terms/de.html
18.104.22.168.1 IP — Anonymization
If IP Anonymization is activated by us on this website, Google will firstly remove your IP address within member states of the European Union and in other member states of the Agreement on the European Economic Area. The full IP address will only be sent to a Google server in the USA and removed there in exceptional cases.
22.214.171.124 Google Tag Manager
More detailed information can be found in Google’s data protection policies: https://www.google.com/analytics/tag-manager/use-policy/
This website uses the Hotjar analysis and feedback tool (Hotjar Ltd., http://www.hotjar.com, Level 2, St Julian’s Business Centre, 3, Elia Zammit Street, St Julian’s STJ 1000, Malta, Europe). Hotjar allows us to use targeted analysis to optimize the website. The information generated by the tracking code and cookie are sent to the Hotjar servers in Ireland (EU) and processed there.
This information comprises:
Recorded from: device and browser
- The anonymized IP address of your end device.
- The resolution of your display device.
- The device type and browser information.
- The country from which you are visiting our website.
- The preferred display language for our website.
- Mouse interactions such as position, movement and clicks.
- Keyboard interactions.
- Log data.
Recorded from: Servers
- The time stamp for the access (date, time).
- The current domain.
- The pages visited.
You can opt out of data recording and storage at any time, with effect for the future, at https://www.hotjar.com/legal/compliance/opt-out.
Details about how Hotjar handles your personal data and your rights in this matter can be found in the Hotjar privacy policies: https://www.hotjar.com/legal/policies/privacy
8.3.1 Contract data processing agreement
Processing is carried out on the basis of a contract data processing agreement concluded between Kotányi and Hotjar pursuant to Article 28 GDPR and related technical and organizational measures.
If you want to subscribe to the Kotányi newsletter service, the minimum we require is the email address to which you would like the newsletter to be sent. Other information is used to tailor the newsletter to you, or to facilitate feedback. We use the double opt-in method for newsletter subscriptions. In other words, we will only send you newsletters once you have given us your email address and then confirmed your subscription by clicking on a link in an email that we send you. We do this to ensure that only the genuine user of the email address given can subscribe to the newsletter service. Your confirmation must be received promptly after sending the email, otherwise your subscription and email address will be deleted from our database. Until we receive your confirmation, our newsletter service will not accept any further messages from this email address. You can unsubscribe from our newsletter at any time.
If you wish to unsubscribe, please use the contact details in Section 2 “Data controller” to get in touch with us or cancel your subscription via the link at the bottom of every newsletter. If you receive our newsletter, we collect statistical data to enable us to optimize the service. The newsletter subscription and its use are assigned to each customer within the newsletter software.
9.1 Legal basis
For the circulation of newsletters, we refer to Article 6, Paragraph 1(a, f) GDPR and Article 7 GDPR.
We use the email marketing service of eyepin GmbH (“eyepin”) (https://www.eyepin.com, Billrothstraße 52, 1190 Vienna, Austria) to send out newsletters. The email addresses of our newsletter recipients as well as other data specified as part this information are stored on eyepin servers in Austria. eyepin only processes data in accordance with its privacy statement (https://www.eyepin.com/en/datenschutz). Personal data is not shared with third parties for advertising, marketing or market research purposes.
9.2.1 Contract data processing agreement
Processing is carried out on the basis of a contract data processing agreement concluded between Kotányi and eyepin pursuant to Article 28 GDPR and related technical and organizational measures.
Although links that take you to other websites are selected and checked with the greatest care, we cannot accept any responsibility or liability whatsoever for the content of the linked external websites.
11. Age restriction
We do not process the personal data of children under the age of 14 under any circumstances. If you have not yet reached the minimum age, please refrain from using our services and ask your legal guardian for assistance.
12. Rights of data subjects
The GDPR provides the following rights for data subjects:
- Right of access (Article 15 GDPR).
- Right to rectification (Article 16 GDPR).
- Right to erasure (“Right to be forgotten”) (Article 17 GDPR).
- Right to restriction of processing (Article 18 GDPR).
- Right to data portability (Article 20 GDPR).
- Right to object (Article 21 GDPR).
- Right to withdraw consent (Article 7, Paragraph 3 GDPR).
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR). Austria: Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna
If you have general concerns about data protection or on exercising your rights, please use the contact details in Section 2 “Data controller” to get in touch with us.
As we cannot process any requests from data subjects unless identity checks have been successfully completed beforehand, please present a valid form of official photo identification (passport, ID document).