Information requirements according to GDPR
Version: May 2018
“Doka” (Doka GmbH, Josef Umdasch Platz 1, 3300 Amstetten, Austria; responsible party pursuant to GDPR) takes the protection of personal data seriously. That is why Doka processes personal data independently pursuant to the requirements of the applicable legislation, especially pursuant to the Regulation (EU) 2016/679 of the European Parliament and Council dated 27 April 2016 on the protection of natural persons when processing personal data in relation to the free movement of data (“GDPR”).
“Personal data” is all information that relates to an identified or identifiable natural person such as name, address, email address and IP address.
The aim of this statement is to inform the visitor (also referred to hereinafter as “you” or “your”) about the purpose and scope of processing personal data on the following “websites”, whereby the individual websites do not always use all the cookies or applications listed here and also have their own privacy statements:
Your data is generally not sent to third parties (processors) unless we are legally obligated to do so, it is necessary to forward data to meet our contractual obligations or you have expressly consented to your data being forwarded in advance.
If you use our websites solely for information purposes, i.e. if you do not register or transmit information another way, we will only collect personal data that is sent from your browser. If you visit our websites, we will collect the data listed below that is required by us for technical reasons to display the websites and to ensure their stability and security: IP address and IP location, date and time of the query, time zone difference to Greenwich Mean Time (GMT), content of the request (certain page), access status/HTTP status code, transferred data volume, website which the request comes from, operating system and its interface, language and version of the browser software, number, duration and time of visits, search engines and keywords that were used, browser type, screen size and operating system.
We also add links on our websites to other websites; this is only done for information purposes. These websites are not under our control and therefore do not come under the provisions of this privacy statement. If you access a link, it is possible for the operator of these websites to collect data about you and to process this data pursuant to his privacy statement which may differ from our version.
In general, personal data transmitted by your browser and obtained by Doka in purely informational use of our website (logfiles) are retained for a period of 3 months. Beyond this period, logfiles are stored in our systems only for the purpose of investigating irregularities or security incidents.
In general, Doka stores your personal data only for as long as is necessary for the fulfilment of the purpose for which they were obtained. Therefore, in consequence Doka stores your data for the duration of our contractual relationship or provision of goods and services relationship with you. Beyond this period, Doka stores your personal data to fulfil legal obligations for retention of records (e.g. to fulfil the 7-year obligation to retain records in accordance with the applicable stipulations of tax and corporate law). Insofar as necessary, Doka can also retain your data for as long as the period of limitation for potential legal claims against Doka has not expired; for certain claims the statutory period of limitation can be up to 30 years. Personal data are either deleted or anonymised as soon as no reasonable grounds for further storage exist.
In order to answer your queries and fulfil your orders and requests, we will process the following personal data: First name, surname, title, email address, password, date of birth, company, contact, company register number, UID number (tax ID number), telephone number, fax number, delivery address and invoice address, credit card details, account number.
Doka uses the newsletter to provide information on current topics, new developments and offers. If a user wants to receive the newsletter that can be found on the websites, he/she must provide his/her email address and information that allow us to verify whether a user is also the holder of the specified email address or whether the holder of the email address also agrees to receive the newsletter.
A valid email address is required to register for the newsletter. The IP address and login date are stored during the registration process. This procedure is used for security reasons in the event that a third party misuses the email address and registers for the newsletter without the authorised user being aware. Doka uses this data solely to send the requested information.
Your email address and your first name, surname and title are required to register for the newsletter in the online shop.
eworx Network & Internet GmbH (“eworx”, Hanriederstraße 25, 4150 Rohrbach-Berg, Austria; processor within the meaning of GDPR) is responsible for sending this information. If a user registers for the newsletter, the data specified during the registration process will be transferred to eworx and stored there. After registering, the user will receive an email from eworx to confirm the registration by clicking on the link (“double opt-in”). eworx offers options to analyse how newsletters are opened and used. By ordering the newsletter, you are giving your consent for all the data provided to be processed. The consent to store data, the email address and the use thereof for the newsletter can be revoked at any time. It can be revoked via a link in the newsletter or by notifying Doka.
The data entered in the form is stored with Doka for processing queries and in case there are any follow-up questions. By sending the form, you are giving your consent for your data to be recorded and processed electronically.
Doka records the following data when using the contact form: Company/organisation, business segment, company size, employment sector, position, gender, first name/surname, address/postcode/city, country, telephone number, email address, fax number, message, customer number, VAT ID, date, contact, sender, title.
When using the online shop, cookies are also stored on a visitor’s PC to be able to track movements in the online shop, to use the shopping basket and to recognise visitors who visit our website several times.
Our websites use the following types of cookies, the scope and function of which are explained below:
Transient cookies are deleted automatically when you close your browser. These mainly include session cookies. They store what is referred to as a session ID, which can allocate different requests from your browser to the joint session. This allows your computer to be recognised when you return to our websites. These session cookies will be deleted when you log out or close the browser. Session-related cookies must also be approved to be able to use the shopping basket and checkout in the online shop. If a customer generally does not want to or cannot accept any cookies, it is also possible to place an order via email, telephone or fax.
Persistent cookies are automatically deleted after a specified period which may differ depending on the cookie. However, you can delete the cookies yourself at all times in your browser settings. They help to improve user-friendliness (displaying content that is suitable for the location) and can be used to analyse websites (see “Google Analytics”). Integrated plug-ins (see below) also employ cookies to carry out their services.
The following cookies are generally added to the websites:
|Name||Purpose and procedure|
|PHPSESSID||Preserves the user’s preferred settings so that they can be made available automatically if he/she visits the website again; session.|
|country; Selectedcountry||This cookie is used to store information on which country website users visit and which language preference the user has. If the user visits our websites again, the cookie will be read and country-specific data will be output. |
|hideLanguageHintUs||If the doka.com site is visited with an IP address from the USA, the user will not be forwarded to doka.com/us/index via the Locator Service. The user will remain on the international version and receive a notification. The “hideLanguageHintUs” cookie is set if this notification is not displayed or the user has already confirmed the reference to the cookie.|
|Language||The user’s language settings are stored so that the language used is automatically set the next time the website is visited.|
|ISAWPLB||This cookie (ISA Web Publishing Load Balancing) is employed when using numerous web front-end servers in ISA Server TMG. It directs queries to the same server.|
|These are tokens for a secure session.|
|JSESSIONID||A unique number is allocated to the user’s session with this cookie. It is required to ensure that the website works; session.|
|These cookies are used to store your preferred settings on cookies and third party applications.|
Google LLC 1600 Amphitheatre Parkway Mountain View, CA 94043 USA (“Google”)
The following Google cookies are placed on our websites:
“_ga” This cookie is used by Google Analytics to distinguish between website visitors and to track site visits and the duration of the site visits, expiry 2 years;
“_gat” This Google Analytics cookie is used to monitor the requirement rate of the servers and to restrict it, expiry 10 minutes;
“_gid” This cookie is used to distinguish between users, expiry 24 hours.
"_gali" This cookie is used by Enhanced Link Attribution of Google Analytics to improve the accuracy of the users In-Page Analytics report by automatically differentiating between multiple links to the same URL on a single page by using link element IDs.
“_gcl_au” This cookie is used by Google AdSense for experimenting with advertising efficiency on websites that use the company’s services. Expires after 3 months.
By visiting our websites, Google receives information that you have accessed the corresponding subsite of our websites and the personal data listed under 2. This occurs regardless of whether you are logged into a Google account or not. If you are logged into Google, your data will be allocated directly to your account. If you do not want this to happen, you must log out of Google before using this service. Google uses your data for the purposes of advertising, market research and tailored website design. You have a right to object to this use of your data and must contact Google directly about it.
We would also like to point out that Google also processes your data in the USA and is subject to the EU-US Privacy Shield. You can find this at http://www.google.com/intl/en/policies/privacy.
Browser add-on for deactivating Google Analytics: https://tools.google.com/dlpage/gaoptout?hl=en
Google Analytics cookies may also be managed using our general cookie settings.
You can find information on the purpose and scope of data collection in the Google privacy statement at: http://www.google.com/intl/en/policies/privacy.
Hotjar Ltd., Level 2, St Julian’s Business Centre, 3, Elia Zammit Street, St Julian’s STJ 1000, Malta, Europa ("Hotjar")
Revocation of consent:
You can opt out of the saving of a user profile or information on your visit by Hotjar at our website as well as the placement of tracking cookies by Hotjar on other websites if you click on this Opt-Out-Link.
Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA („Facebook“)
Doka uses plug-ins of the social network Facebook. The Facebook plug-ins can be seen in the Facebook logo or the “Like button”. If these websites are visited from Facebook, a direct connection is established between the browser and the Facebook server via the plug-in. This enables Facebook to obtain the information that the websites were visited with the IP address. If the Facebook “Like button” is clicked on while being logged into a Facebook account, content on these websites may be linked to that Facebook profile. This means that Facebook can allocate the visit to websites to the user account. Doka is not informed of the content of the transmitted data and the use thereof by Facebook. Please refer to the Facebook privacy statement for more information on this.
If you do not want Facebook to allocate your visit to these websites to your Facebook user account, please log out of this account.
Bing Universal Event Tracking (UET)
Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (“Microsoft”)
Doka uses the service Bing Universal Event Tracking (UET) of the Microsoft Corporation. The integration of the Bing tag makes it possible to collect and save user interactions on the pages and to thereby direct advertising to certain user groups in a systematic way. Pseudonymized user profiles are created at Microsoft from the collected and saved data. The data are sent to servers in the US and saved there for 180 days. Also the IP address and the Microsoft cookie “MUID“ are saved (with an expiration date of 13 months). The Microsoft cookie contains a GUID (Global Unique Identifier), i.e. an ID that can be assigned to the browser or the user himself (if he is logged into the Microsoft account). You will obtain more Information on the purpose and scope of the data collection in Google’s Data Protection Agreement, which you can find at: https://privacy.microsoft.com/de-de/privacystatement
You can manage and prevent the placement of Microsoft cookies by deactivating the cookies via the browser or the general cookie settings. Microsoft can track the user behaviour through several electronic devices with cross device tracking. As a result, Microsoft can offer personalised advertising. This behaviour can be deactivated at https://choice.microsoft.com/de-de/opt-out.
Facebook visitor action pixels
Doka uses “visitor action pixels” from Facebook on these websites. This enables the behaviour of users to be tracked after they have been forwarded to the websites of the provider by clicking on a Facebook advertisement. This process is used to assess the effectiveness of Facebook advertisements for statistical and market research purposes and can help to enhance future promotional measures. The data collected is anonymous for Doka and does not allow for any conclusions to be drawn about the user’s identity. However, the data from Facebook is stored and processed so that it is possible to connect to the relevant user profile and Facebook can use the data for its own advertising purposes in accordance with the Facebook data policy (https://www.facebook.com/about/privacy). The user makes it possible for Facebook and its partners to place advertisements on and outside of Facebook. Cookies can also be placed on the accessing device for these purposes. The following cookies are set on our websites: “_fpb”, “fr”, “tr”. Facebook uses these cookies to display a series of advertising products.
Revoking consent at Facebook: https://www.facebook.com/ads/website_custom_audiences/
YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA
Doka uses a plug-in from the YouTube website operated by Google to integrate videos. If the user visits a website equipped with a YouTube plug-in by Doka, a connection will be established with the YouTube servers. The YouTube server will be informed of which Doka websites have been visited. If the user is also logged into his/her YouTube account, YouTube will be able to allocate the surfing behaviour directly to the personal user profile.
This allocation can be prevented by signing out of the YouTube account and other YouTube LLC and Google Inc user accounts and by deleting the relevant cookies:
Vimeo LCC, 555 West 18th Street, New York, New York 10011, USA („Vimeo“)
Vimeo.com plug-ins are used on these websites. If users access websites that are equipped with a Vimeo plug-in, a connection will be established with the Vimeo servers and the plug-in displayed. If users are logged into Vimeo as members, Vimeo will allocate this information to the personal user account on this platform. However, this allocation could be prevented by the user logging out from his/her Vimeo user account and deleting the corresponding Vimeo cookies before using the Doka website. Further information on data processing and details on data protection from Vimeo can be found at https://vimeo.com/privacy
However, this allocation cannot be prevented by the user logging out from his/her Vimeo user account and deleting the corresponding Vimeo cookies before using the Doka website: www.vimeo.com
Sketchfab, Inc., Sketchfab HQ, 1123 Broadway #501 (25th St), New York City, NY 10010 US („Sketchfab“)
Doka uses plug-ins from the website sketchfab.com run by Sketchfab, Inc.. If Doka websites are visited by users who are equipped with a Sketchfab plug-in, a connection will be established with the Sketchfab servers which then instructs the user’s browser to display the plug-in on the website. If users are logged into their Sketchfab account, they are enabling the company to allocate their surfing behaviour directly to their personal profile.
This procedure can be prevented by logging out from the Sketchfab account:
whatchado GmbH, Möllwaldplatz 4/39, 1040 Wien, Österreich („Whatchado“)
Doka uses plug-ins on the website whatchado.com run by Whatchado to integrate videos on the websites. Whatchado is operated by whatchado GmbH, Möllwaldplatz 4/39, 1040 Vienna, Austria. If Doka websites are accessed that are equipped with this plug-in, a connection will be established with the Whatchado servers. If users are logged into their Whatchado account, Whatchado will be able to allocate the surfing behaviour directly to the user’s personal profile.
This is prevented by logging out of the user account:
Rocket Science Group, LLC, 512 Means St. Suite 404, Atlanta, GA 30318, USA („Mandrill“)
Doka uses the Mandrill service. This involves the specified contact details such as email address, title, first name and surname as well as the content of an email being transferred to Mandrill and stored there. The service manages data about when emails that were sent by Doka, when they have been read and when the links in them have been opened. The service may also gather data on how often an email has been opened and what IP address, which email client and which operating system it is from. The Rocket Science Group, LLC takes part in the EU-US Privacy Shield framework programme of the US Department of Commerce in relation to the collection, usage and storage of personal data from the Member States of the European Economic Area. You will receive information here on which data The Rocket Science Group, LLC collects, processes and uses as part of the EU-US Privacy Shield framework programme and the purposes for which this is done: https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG. Further information on Mandrill and data protection at Mandrill can be found here: http://mailchimp.com/legal/privacy/
Mandrill’s services are used when it comes to using contact forms at doka.com. If you do not want to use this service, we recommend using an alternative method to contact Doka in relation to the contact details specified on the relevant websites.
MaxMind, Inc. 14 Spring Street, 3rd Floor Waltham, MA 02451 USA („MaxMind“)
GeoLite 2 is used to determine IP addresses to provide you with the correct country version of the online shop immediately. GeoLite 2 data is prepared by MaxMind. You can find more information at: https://www.maxmind.com/en/privacy_policy
Contacting Doka (see below)
Flockler Oy, Rautatienkatu 21 B, 33100 TAMPERE, Finland, Europe ("Flockler")
Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA (“Google”)
Doka uses content from Google Maps of the company Google LLC (“Google”). If the user visits a subpage of www.doka.com on which Google Maps is embedded, data about your behavior when using Google Maps will be transmitted to and processed by Google. Google will process this data as a usage profile to be used for market research or to design Google Maps based on user needs. If you are a Google customer and logged into a Google service, this data will be directly connected to your Google account.
Monotype, 600 Unicorn Park Drive, Woburn, MA 01801, USA ("Monotype")
Doka uses the Web Font Services from Fonts.com. In the Web Font Services from fonts.com no personal data is collected or processed in the context of providing the Web Fonts. Although page views are counted in the context of Web Font Tracking, the IP number from which the page view is made is stored in anonymous form.
Doka points out that the user has rights pursuant to GDPR in relation to the processing of his/her personal data, for example a right to information, data porting, to object and to erasure. In order to assert these rights and address other issues relating to the processing of personal data with Doka, please contact them at: Doka GmbH, Subject matter: Data protection query, Josef Umdasch Platz 1, 3300 Amstetten, Austria.
Please alternatively forward your queries on the subject of data protection to: firstname.lastname@example.org
Users also have a right of appeal to the data protection authority of the Republic of Austria on matters relating to data protection: https://www.dsb.gv.at/
Doka regularly maintains its websites. This may include the statement being adapted. This adaptation is not referred to separately. It is therefore recommended to access this statement on a regular basis.