Privacy Policy
Thank you for visiting the trafficon.eu website. Our work contributes to safety on road, cycling and public transport networks; but the security of your data matters just as much to us. We do our best to keep the data we process to a minimum.
Our security measures
We take appropriate technical and organisational measures (in accordance with Art. 32 GDPR) to ensure a level of security appropriate to the risk.
This is done in accordance with the statutory requirements, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.
These measures include in particular:
- Truncation of the IP address where processing the full IP address is not necessary. This prevents, or at least makes more difficult, the identification of a person.
- TLS encryption (https) to protect the data you transmit via our online services. You can recognise such encrypted connections by the prefix https:// in your browser’s address bar.
Transfer of data
In the course of our processing of personal data, the data may be transmitted to or disclosed to other bodies, companies, legally independent organisational units or persons. In doing so, we comply with the statutory requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data. This processing is always carried out on an existing legal basis. Further and more specific information on the respective recipients and processing operations can be found in the following sections of this privacy policy.
We also transmit data within our group of companies where this is necessary for administrative purposes. This is based on our legitimate business and commercial interests, the need to fulfil contractual obligations, the consent of the data subjects or a legal permission. Further and more specific information on the respective recipients and processing operations can be found in the following sections of this privacy policy.
Data processing in third countries
If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if processing takes place in the context of using third-party services or disclosing or transmitting data to other persons, bodies or companies, this is done only in accordance with the statutory requirements.
Subject to express consent or a transfer required by contract or by law, we process data, or have it processed, only in third countries with a recognised level of data protection, for example as determined by the European Commission by means of an adequacy decision (in accordance with Art. 45 GDPR), on the basis of contractual obligations through so-called standard contractual clauses of the European Commission (in accordance with Art. 46 GDPR), or where certifications or binding corporate rules exist (in accordance with Art. 44 to 49 GDPR, information page of the European Commission.
Information page of the European Commission).
Deletion of data
The data we process is deleted in accordance with the statutory requirements as soon as the consent permitting its processing is withdrawn or other permissions cease to apply (e.g. if the purpose of processing this data no longer applies or the data is not necessary for that purpose).
If the data is not deleted because it is required for other, legally permissible purposes, its processing is restricted to those purposes. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person.
As part of our privacy notices, we may provide users with further information on the deletion and retention of data that applies specifically to the respective processing operations.
Use of cookies
What are cookies?
A cookie is a small text file that a web portal stores on your computer, tablet or smartphone. This allows the portal to “remember” certain entries and settings (e.g. login, language, font size and other display preferences) for a certain period, so that you do not have to enter them again each time you visit or navigate the portal.
What we use cookies for
This website uses cookies for internal functions. The cookie data collected is not personally identifiable.
The data processed by means of cookies is therefore processed on the basis of our legitimate interests (to improve the usability of the website).
Which cookies we use
No cookies are used for website visitors.
Provision of our online services and web hosting
We process user data in order to provide our online services and to improve their usability. For this purpose, we process the user’s IP address, which is necessary to deliver the content and functions of our online services to the user’s browser or device. This processing is based on our legitimate interest (in accordance with Art. 6(1)(f) GDPR).
Logging via “server log files”
Access to our online services is logged in the form of so-called server log files. Only the following technical information is recorded:
shortened IP address, date and time of access, the address requested, HTTP status code and the volume of data transferred.
The server log files serve in particular the security and stability of our online services, for example to detect and fend off abusive access and overloads (e.g. DDoS attacks).
Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidential purposes is exempt from deletion until the incident in question has been finally resolved.
Information on web hosts
To provide our online services, we use storage space, computing capacity and software that we rent or otherwise obtain from server providers (also known as „web hosts“). The web hosting services we use also include sending, receiving and storing emails. For these purposes, the addresses of recipients and senders, other information relating to the sending of emails (e.g. the providers involved) and the content of the respective emails are processed. The aforementioned data may also be processed for the purpose of detecting spam. Please note that emails on the internet are generally not sent in encrypted form. As a rule, emails are encrypted in transit, but (unless so-called end-to-end encryption is used) not on the servers from which they are sent and on which they are received. We therefore cannot accept any responsibility for the transmission path of emails between the sender and their receipt on our server.
Hetzner (Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; https://www.hetzner.com):
Services in the field of providing IT infrastructure and related services (e.g. storage space and/or computing capacity);
Legal basis: legitimate interests (Art. 6(1)(f) GDPR);
Website | Privacy policy | Data processing agreement
Email processing
For processing and sending emails, we use Microsoft 365 from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
Among other things, the form emails sent via our website are processed through Microsoft 365. This includes applications submitted via the application form, which may contain CVs and other application documents, for example. The emails are forwarded to the responsible recipients within our company and are processed and stored via Microsoft 365.
In particular, the email address, the name and the information contained in the respective message and in attachments may be processed.
Legal basis: legitimate interests (Art. 6(1)(f) GDPR) and, where the processing is necessary to take steps at the request of the data subject prior to entering into a contract, Art. 6(1)(b) GDPR.
Contact and enquiry management
When you contact us (e.g. via contact form, email, telephone or social media) and in the context of existing user and business relationships, the details provided by the enquiring persons are processed to the extent necessary to respond to the contact enquiries and any measures requested.
Types of data processed: contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. web pages visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).
Purposes of processing: contact enquiries and communication; managing and responding to enquiries; feedback (e.g. collecting feedback via online form); provision of our online services and usability.
Legal bases: legitimate interests (Art. 6(1)(f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
Application process
The application process requires applicants to provide us with the data necessary for their assessment and selection. The information required is set out in the job description or, in the case of online forms, in the details given there.
In principle, the required information includes personal details such as name, address and contact details, as well as proof of the qualifications needed for a position. On request, we are also happy to tell you what information is required.
Applicants can submit their applications to us via an online form. The data entered in the form and the address of the page from which the form was sent are transmitted to us in encrypted form. To protect the form against spam, a hash of the IP address is stored for one hour. The IP address itself is not stored. Uploaded application documents are deleted from the server immediately after successful transmission and afterwards exist only as part of the application sent to us.
Applicants can also send us their applications by email. Please note, however, that emails on the internet are generally not sent in encrypted form. As a rule, emails are encrypted in transit, but not on the servers from which they are sent and on which they are received. We therefore cannot accept any responsibility for the transmission path of the application between the sender and its receipt on our server. Applicants are welcome to contact us about how to submit their application, or to send it to us by post.
Processing of special categories of data: If sensitive data (within the meaning of Art. 9(1) GDPR) or special categories of personal data (e.g. health data such as severe disability status, or ethnic origin) are requested from applicants during the application process in order to meet obligations under employment or social law, so that the controller or the data subject can exercise the rights arising from employment law and social security and social protection law and fulfil their obligations in this respect, this data is processed on the grounds set out in Art. 9(2) GDPR.
Deletion of data: If an application is successful, the data provided by applicants may be processed further by us for the purposes of the employment relationship. Otherwise, if the application for a position is not successful, the applicants’ data will be deleted. Applicants’ data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time. Subject to a justified revocation by the applicant, deletion takes place after six months at the latest, so that we can answer any follow-up questions about the application and meet our obligations to provide evidence under the regulations on the equal treatment of applicants. Invoices for any reimbursement of travel expenses are archived in accordance with tax regulations.
Inclusion in an applicant pool: Inclusion in an applicant pool, where offered, is based on consent. Applicants are informed that their consent to inclusion in the talent pool is voluntary, has no influence on the ongoing application process and can be withdrawn at any time with effect for the future.
Newsletter
The following information explains the content of our newsletter, the registration, dispatch and statistical analysis procedures, and your rights to object. By subscribing to our newsletter, you agree to receive it and to the procedures described.
Content of the newsletter
We send newsletters, e-mails and other electronic notifications containing promotional information (hereinafter “newsletter”) only with the consent of the recipients or where permitted by law. Where the content of the newsletter is specifically described when signing up, this description is decisive for the users’ consent. Otherwise, our newsletters contain news about our company, our projects, event recommendations and job vacancies.
To subscribe to our newsletters, it is generally sufficient to provide your e-mail address. However, we may ask you to provide a name, so that we can address you personally in the newsletter, or further details if these are required for the purposes of the newsletter.
Double opt-in procedure & logging
Subscription to our newsletter generally takes place using a so-called double opt-in procedure. This means that after signing up you will receive an e-mail asking you to confirm your subscription. This confirmation is necessary so that no one can sign up with someone else’s e-mail address. Newsletter subscriptions are logged so that the subscription process can be proven in accordance with legal requirements. This includes storing the time of subscription and of confirmation as well as the IP address. Changes to your data stored with our mailing service provider (“Brevo”) are also logged.
Use of the mailing service provider “Brevo”
The newsletters are sent using “Brevo”, a newsletter mailing platform of the service provider Brevo GmbH (Köpenicker Straße 126, 10179 Berlin).
Privacy policy | Data processing agreement
The e-mail addresses of our newsletter recipients (and any other data provided when signing up) are stored on Brevo’s servers in Germany and used to send and analyse the newsletters. This is done on our behalf (further information: Data processing agreement).
Sign-up data
To subscribe to the newsletter, it is sufficient to provide your e-mail address. Optionally, we ask you to provide your first name and surname. This information is used solely to personalise the newsletter.
Statistical data collection and analysis
The newsletters contain a so-called “web beacon”, i.e. a pixel-sized file that is retrieved from Brevo’s server when the newsletter is opened. As part of this retrieval, technical information such as information about the browser and your system, as well as your IP address and the time of retrieval, is collected. This information is used to make technical improvements to the services based on the technical data, or to learn about the target groups and their reading behaviour based on where the newsletter is retrieved (which can be determined using the IP address) or on access times.
Statistical data collection also includes determining whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, neither we nor Brevo intend to monitor individual users. Rather, the analyses help us to recognise the reading habits of our users and to adapt our content to them or to send different content according to our users’ interests.
Unsubscribing/withdrawal of consent
You can unsubscribe from our newsletter at any time, i.e. withdraw your consent. This also ends your consent to its dispatch via the mailing service provider and to the statistical analyses. Unfortunately, it is not possible to withdraw consent separately for dispatch via the mailing service provider or for the statistical analysis. You will find a link to unsubscribe at the end of every newsletter. The withdrawal does not affect the lawfulness of the data processing carried out before the withdrawal.
Deletion & restriction of processing
We may store unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove that consent was previously given. The processing of this data is restricted to the purpose of a possible defence against claims. An individual request for deletion is possible at any time, provided that the former existence of consent is confirmed at the same time. Where there are obligations to observe objections permanently, we reserve the right to store the e-mail address in a so-called „blocklist“ solely for this purpose.
Web analysis, monitoring and optimisation
Web analysis (also referred to as „reach measurement“) is used to evaluate the flow of visitors to our online services and may include behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. Reach analysis helps us, for example, to recognise when our online services, or their features or content, are used most frequently or encourage repeat visits. It also shows us which areas need optimisation. The associated data processing is based on our legitimate interest.
Web analysis with “Umami”
To design our website according to need and keep improving it, we use the web analysis tool Umami.
Umami works without cookies. It records only anonymised usage data, for example which pages are visited, how long a page is viewed or from which region it is accessed. Individual visitors cannot be identified.
The collected data is evaluated exclusively in aggregated and anonymised form. No user profiles are created, and the data is not linked to other personal data.
You can object to the collection and analysis of your usage data by Umami at any time:
This deactivates web analysis for your visit.
Presence on social networks
We maintain online presences within social networks and process users’ data in this context in order to communicate with the users active there and to provide information about us. Please note that users’ data may be processed outside the European Union. This may result in risks for users because, for example, it could make it more difficult to enforce their rights.
Furthermore, users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on users’ behaviour and the interests resulting from it. These usage profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to users’ interests. For these purposes, cookies are generally stored on users’ computers, in which their usage behaviour and interests are stored. Furthermore, data can also be stored in the usage profiles independently of the devices used by users (in particular if users are members of the respective platforms and are logged in to them).
For a detailed description of the respective forms of processing and the options to object (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
With regard to requests for information and the assertion of data subject rights, we would also like to point out that these can be asserted directly with the providers. Only the providers have access to users’ data and can take appropriate measures and provide information directly. Should you nevertheless need help, please contact us.
Notes on the service providers used:
Facebook: We are jointly responsible with Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; https://www.facebook.com) for the collection (but not the further processing) of data of visitors to our Facebook page (so-called „fan page“). (Joint controller agreement).
The joint responsibility is limited to the collection of data by, and its transmission to, Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which concerns in particular the transfer of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
The data processed includes information on the types of content users view or interact with, or the actions they take, as well as information about the devices they use (e.g. IP addresses, operating system, browser type, language settings, cookie data; see “Device information” in the Facebook Data Policy).
Facebook also uses information to provide analytics services, so-called „Page Insights“, to page operators so that they can gain insights into how people interact with their pages and with the content associated with them. We have concluded a special agreement with Facebook (Information about Page Insights), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfil data subject rights (i.e. users can, for example, send requests for information or deletion directly to Facebook). The rights of users (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the Information about Page Insights.
LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland); Legal basis: legitimate interests (Art. 6(1)(f) GDPR);
Website | Privacy policy | Data processing agreement | Standard contractual clauses (ensuring the level of data protection for processing in third countries) | Option to object (opt-out).
Twitter (Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland, parent company: Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA) | Legal basis: legitimate interests (Art. 6(1)(f) GDPR);
Website | Privacy policy
Task management
We use third-party providers for the purposes of organising, administering, planning and providing our (pre-)contractual services (Art. 6(1)(b) GDPR) on the basis of our legitimate interest (pursuant to Art. 6(1)(f) GDPR).
When selecting this third-party provider, we comply with the statutory requirements. In this context, personal data may be processed and stored on the third-party providers’ servers. This may concern various data that we process in accordance with this privacy policy (in particular users’ master data and contact details, and data on transactions, contracts, other processes and their contents).
If, in the context of communication or of business or other relationships with us, users are referred to the third-party providers or their software or platforms, the third-party providers may process usage data and metadata for security purposes, for service optimisation or for marketing purposes.
We therefore ask you to observe the privacy notices of our third-party provider.
Asana (Asana, Inc, 1550 Bryant Street, Suite 200, San Francisco, CA 94103, USA; https://asana.com)
Privacy policy | Data processing agreement | Standard contractual clauses (ensuring the level of data protection for processing in third countries)
Business services
We process data (e.g. contact or bank details) of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as „contractual partners“), in the context of contractual and comparable legal relationships and associated measures, and in the context of communication with contractual partners (or pre-contractually), e.g. to answer enquiries.
We process this data in order to fulfil our contractual (Art. 6(1)(b) GDPR) or legal obligations (Art. 6(1)(c) GDPR). In addition, we process the data on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in proper and economically sound business management and in security measures to protect our contractual partners and our business operations against misuse and against threats to their data, secrets, information and rights (e.g. for the involvement of telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisers, payment service providers or tax authorities).
Within the scope of applicable law, we only pass on contractual partners’ data to third parties to the extent that this is necessary for the aforementioned purposes or to fulfil legal obligations. Where we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between users and the providers.
The periods for deleting this data are determined by the duration of the business relationship (initiation and performance up to the termination of a contract), by the statutory retention and documentation obligations under the Austrian Commercial Code (Unternehmensgesetzbuch, UGB) and the Federal Fiscal Code (Bundesabgabenordnung, BAO) (generally seven years), and by ongoing warranty and guarantee periods. In addition, data may be stored until the conclusion of any legal dispute.
Changes and updates to this privacy policy
Please review the content of our privacy policy regularly.
We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.
Where we provide addresses and contact details of companies and organisations in this privacy policy, please note that addresses may change over time, and please check the details before getting in touch.
Your rights as a data subject
As a data subject, you have various rights under the GDPR, arising in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object at any time to processing that we carry out on the basis of legitimate interest. If your data is processed for direct marketing purposes, you may also object to this.
- Right to withdraw consent: If the processing is based on consent, you have the right to withdraw it at any time.
- Right of access: You have the right to request information on whether we process your data and, if so, which data. You also have the right to further information and to a copy of the data in accordance with the statutory requirements.
- Right to rectification: In accordance with the statutory requirements, you have the right to request that your data be completed or that inaccurate data concerning you be corrected.
- Right to erasure: You have the right to request the erasure of your data where this is provided for by law. In accordance with the statutory requirements, you have the right to request that data concerning you be erased without undue delay or, alternatively, in accordance with the statutory requirements, to request that the processing of the data be restricted.
- Right to data portability: Where the processing is based on consent or a contract, you have the right to receive your data in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller.
- Complaint to a supervisory authority: If you believe that the processing of your data infringes data protection law or that your data protection rights have otherwise been violated in any way, you can lodge a complaint with the supervisory authority. In Austria, this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna (dsb@dsb.gv.at).
- Right to restriction: You have the right, under certain conditions, to obtain the restriction of the processing of your data.
Thank you for your attention.