Data Privacy

Information requirements according to GDPR

Version: April 2019

I. Object of the Statement

“Doka” (Doka GmbH, Josef Umdasch Platz 1, 3300 Amstetten, Austria; responsible party pursuant to GDPR) takes the protection of personal data seriously. That is why Doka processes personal data independently pursuant to the requirements of the applicable legislation, especially pursuant to the Regulation (EU) 2016/679 of the European Parliament and Council dated 27 April 2016 on the protection of natural persons when processing personal data in relation to the free movement of data (“GDPR”).

“Personal data” is all information that relates to an identified or identifiable natural person such as name, address, email address and IP address.

The aim of this statement is to inform the visitor (also referred to hereinafter as “you” or “your”) about the purpose and scope of processing personal data on the following “websites”, whereby the individual websites do not always use all the cookies or applications listed here and also have their own privacy statements:

II. General Processing

Doka processes personal data on its websites based on your consent (use of cookies for analysis and promotional purposes; see below for opt-out; establishing contact via the form or by email, newsletter) and to meet its contractual obligations and in the legitimate interest of ensuring secure shopping (online shop).

Doka is authorised, within the scope of the data protection specifications, to outsource the processing of your personal data in full or in part to external service providers that work for Doka as data processors in accordance with art. 4 section 8 DSGVO. External service providers support is, for example, through the technical operation and support of the websites and apps, data management, the provision and performance of services, marketing and website and app analysis. Doka remains responsible for the protection of the data passed on; the service providers from Doka process your data only according to our instructions. This will be ensured through strict contractual rules, technical and organisational actions and supplemental checks by us.

If you use our websites solely for information purposes, i.e. if you do not register or transmit information another way, we will only collect personal data that is sent from your browser. If you visit our websites, we will collect the data listed below that is required by us for technical reasons to display the websites and to ensure their stability and security: IP address and IP location, date and time of the query, time zone difference to Greenwich Mean Time (GMT), content of the request (certain page), access status/HTTP status code, transferred data volume, website which the request comes from, operating system and its interface, language and version of the browser software, number, duration and time of visits, search engines and keywords that were used, browser type, screen size and operating system.

Please refer to “Use of cookies” on how to use cookies.

We also add links on our websites to other websites; this is only done for information purposes. These websites are not under our control and therefore do not come under the provisions of this privacy statement. If you access a link, it is possible for the operator of these websites to collect data about you and to process this data pursuant to his privacy statement which may differ from our version.

III. Specific Processing

Online Shop

In order to answer your queries and fulfil your orders and requests, we will process the following personal data: First name, surname, title, email address, password, date of birth, company, contact, company register number, UID number (tax ID number), telephone number, fax number, delivery address and invoice address, credit card details, account number.

Please refer to “Use of cookies” below on how to use cookies in the online shop.

Newsletter

Doka uses the newsletter to provide information on current topics, new developments and offers. If a user wants to receive the newsletter that can be found on the websites, he/she must provide his/her email address and information that allow us to verify whether a user is also the holder of the specified email address or whether the holder of the email address also agrees to receive the newsletter.

A valid email address is required to register for the newsletter. The IP address and login date are stored during the registration process. This procedure is used for security reasons in the event that a third party misuses the email address and registers for the newsletter without the authorised user being aware. Doka uses this data solely to send the requested information.

Your email address and your first name, surname and title are required to register for the newsletter in the online shop.

eworx Network & Internet GmbH (“eworx”, Hanriederstraße 25, 4150 Rohrbach-Berg, Austria; processor within the meaning of GDPR) is responsible for sending this information. If a user registers for the newsletter, the data specified during the registration process will be transferred to eworx and stored there. After registering, the user will receive an email from eworx to confirm the registration by clicking on the link (“double opt-in”). eworx offers options to analyse how newsletters are opened and used. By ordering the newsletter, you are giving your consent for all the data provided to be processed. The consent to store data, the email address and the use thereof for the newsletter can be revoked at any time. It can be revoked via a link in the newsletter or by notifying Doka.

Contact form

The data entered in the form is stored with Doka for processing queries and in case there are any follow-up questions. By sending the form, you are giving your consent for your data to be recorded and processed electronically.

Doka records the following data when using the contact form: Company/organisation, business segment, company size, employment sector, position, gender, first name/surname, address/postcode/city, country, telephone number, email address, fax number, message, customer number, VAT ID, date, contact, sender, title.

Use of cookies and applications from third-party providers

Cookies are also stored on the visitor’s access device when using the websites. Cookies are small files that enable specific information relating to the access device (PC, smartphone, etc.) to be stored on said device. On the one hand, they make websites more user-friendly and help the user (e.g. storage of login details) and, on the other hand, they are used to record statistical data on website usage and to analyse this data with the aim of improving the range of services. Users can have an influence over the use of cookies. Most browsers have an option that enables the storage of cookies to be limited or prevented completely. However, it is important to note that the use and especially the ease of use will be restricted without cookies.

When using the online shop, cookies are also stored on a visitor’s PC to be able to track movements in the online shop, to use the shopping basket and to recognise visitors who visit our website several times.

Our websites use the following types of cookies, the scope and function of which are explained below:

Transient cookies:

Transient cookies are deleted automatically when you close your browser. These mainly include session cookies. They store what is referred to as a session ID, which can allocate different requests from your browser to the joint session. This allows your computer to be recognised when you return to our websites. These session cookies will be deleted when you log out or close the browser. Session-related cookies must also be approved to be able to use the shopping basket and checkout in the online shop. If a customer generally does not want to or cannot accept any cookies, it is also possible to place an order via email, telephone or fax.

Persistent cookies:

Persistent cookies are automatically deleted after a specified period which may differ depending on the cookie. However, you can delete the cookies yourself at all times in your browser settings. They help to improve user-friendliness (displaying content that is suitable for the location) and can be used to analyse websites (see “Google Analytics”). Integrated plug-ins (see below) also employ cookies to carry out their services.

The following cookies are generally added to the websites:

NAMEPURPOSE and PROCEDURE
PHPSESSIDPreserves the user’s preferred settings so that they can be made available automatically if he/she visits the website again; session.
countryThis cookie is used to store information on which country website users visit and which language preference the user has. If the user visits our websites again, the cookie will be read and country-specific data will be output.
hideLanguageHintUsIf the doka.com site is visited with an IP address from the USA, the user will not be forwarded to doka.com/us/index via the Locator Service. The user will remain on the international version and receive a notification. The “hideLanguageHintUs” cookie is set if this notification is not displayed or the user has already confirmed the reference to the cookie.
acceptcookieIf users visit Doka websites, a cookie notification will be displayed. If users consent to the use of cookies, the acceptcookie will be set and the reference to the cookie is generally hidden when visiting the website again.
LanguageThe user’s language settings are stored so that the language used is automatically set the next time the website is visited.
ISAWPLBThis cookie (ISA Web Publishing Load Balancing) is employed when using numerous web front-end servers in ISA Server TMG. It directs queries to the same server.
accelertorSecureGUID and cpAcceleratorSecureGUIDA unique number is allocated to the user’s session with this cookie. It is required to ensure that the website works; session.
JSESSIONIDA unique number is allocated to the user’s session with this cookie. It is required to ensure that the website works; session.
hide_cookieoverlay
hide_cookieoverlay_medium
performance-cookies_allowed
performace-cookies_allowed_medium
socialmedia-cookies_allowed
These cookies are used to store your preferred settings on cookies and third party applications.

 

Applications of third-party providers:

Application:
Google-Analytics

Provider:
Google LLC 1600 Amphitheatre Parkway Mountain view, CA 94043 USA ("Google")

Description:
These websites use Google Analytics, a web analysis service of Google Inc. (“Google”). Google Analytics uses cookies, text files, that are stored on a computer and which enable an analysis to be carried out on the use of the websites. The information generated by the cookie on the use of these websites is usually transferred to a Google server in the USA and stored there. If the IP anonymisation is activated on these websites (_gat._anonymizeIp), the Google IP address will be truncated in advance within the EU Member States or in other states party to the Agreement on the European Economic Area. The full IP address will only be transferred to a Google server in the USA and truncated there in exceptional circumstances. Google will use this information on behalf of the operator of these websites to assess website use, to compile reports on website activities and to provide services to the website operator associated with website and Internet use. The IP address sent by the browser as part of Google Analytics is not merged with other Google data. The storage of cookies can be prevented by setting the browser software accordingly; but we would like to point out that it may not be possible to use all functions of these websites in their entirety in this case. The recording of data generated by the cookie and relating to website use (incl. your IP address) in Google and the processing of this data by Google may also be prevented by installing a browser plug-in.

Google offers a deactivation add-on for the most popular browsers, which offers more control over which data from Google is entered onto the websites that are accessed. The add-on informs the JavaScript (ga.js) of Google Analytics that no information will be sent to Google Analytics on the website visit. However, the deactivation add-on for the Google Analytics browser does not prevent information being sent to Doka or other web analysis services that may be employed.

The following Google cookies are placed on our websites:

  • “_ga” This cookie is used by Google Analytics to distinguish between website visitors and to track site visits and the duration of the site visits, expiry 2 years;
  • “_gat” This Google Analytics cookie is used to monitor the requirement rate of the servers and to restrict it, expiry 10 minutes;
  • “_gid” This cookie is used to distinguish between users, expiry 24 hours.
  • "_gali" This cookie is used by Enhanced Link Attribution of Google Analytics to improve the accuracy of the users In-Page Analytics report by automatically differentiating between multiple links to the same URL on a single page by using link element IDs.

By visiting our websites, Google receives information that you have accessed the corresponding subsite of our websites and the personal data listed under 2. This occurs regardless of whether you are logged into a Google account or not. If you are logged into Google, your data will be allocated directly to your account. If you do not want this to happen, you must log out of Google before using this service. Google uses your data for the purposes of advertising, market research and tailored website design. You have a right to object to this use of your data and must contact Google directly about it.

We would also like to point out that Google also processes your data in the USA and is subject to the EU-US Privacy Shield. You can find this at http://www.google.com/intl/en/policies/privacy.

Revoking consent:
Browser add-on for deactivating Google Analytics: https://tools.google.com/dlpage/gaoptout?hl=en

Google Analytics cookies may also be managed using our general cookie settings.

You can find information on the purpose and scope of data collection in the Google privacy statement at: http://www.google.com/intl/en/policies/privacy.

 

Application:
Bing Universal Event Tracking (UET)

Provider:
Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (“Microsoft”)

Description:
Doka uses the service Bing Universal Event Tracking (UET) of the Microsoft Corporation. The integration of the Bing tag makes it possible to collect and save user interactions on the pages and to thereby direct advertising to certain user groups in a systematic way. Pseudonymized used profiles are created at Microsoft from the collected and saved data. The data are sent to servers in the US and saved there for 180 days. Also the IP address and the Microsoft cookie are saved (with an expiration date of 13 months). The Microsoft cookie contains a GUID (Global Unique Identifier), i.e. an ID that can be assigned to the browser of the user himself (if he is logged into the Microsoft account). You will obtain more Information on the purpose and scope of the data collection in Google’s Data Protection Agreement, which you can find at: https://privacy.microsoft.com/de-de/privacystatement

Revocation of consent:
You can manage and prevent the placement of Microsoft cookies by deactivating the cookies via the browser or the general cookie settings. 

Microsoft can track the user behaviour through several electronic devices with cross device tracking. As a result, Microsoft can offer personalised advertising. This behaviour can be deactivated at https://choice.microsoft.com/de-de/opt-out.

 

Application:
Facebook Plug-In

Provider:
Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA („Facebook“)

Description:
Doka uses plug-ins of the social network Facebook. The Facebook plug-ins can be seen in the Facebook logo or the “Like button”. Doka uses plug-ins from the social network Facebook. The Facebook plug-ins can be detected on the Facebook page, on the Facebook logo or "Like Button". If these websites are visited from Facebook, a direct connection is established between the browser and the Facebook server via the plug-in. This enables Facebook to obtain the information that the websites were visited with the IP address. If the Facebook “Like button” is clicked on while being logged into a Facebook account, content on these websites may be linked to that Facebook profile. This means that Facebook can allocate the visit to websites to the user account. Doka is not informed of the content of the transmitted data and the use thereof by Facebook. Please refer to the Facebook privacy statement for more information on this.: https://www.facebook.com/privacy/explanation.

Revoking consent:
If you do not want Facebook to allocate your visit to these websites to your Facebook user account, please log out of this account.
www.facebook.com

 

Application:
Facebook visitor action pixels

Provider:
Facebook

Description:
Doka uses “visitor action pixels” from Facebook on these websites. This enables the behaviour of users to be tracked after they have been forwarded to the websites of the provider by clicking on a Facebook advertisement. This process is used to assess the effectiveness of Facebook advertisements for statistical and market research purposes and can help to enhance future promotional measures. The data collected is anonymous for Doka and does not allow for any conclusions to be drawn about the user’s identity. However, the data from Facebook is stored and processed so that it is possible to connect to the relevant user profile and Facebook can use the data for its own advertising purposes in accordance with the Facebook data policy (https://www.facebook.com/about/privacy). The user makes it possible for Facebook and its partners to place advertisements on and outside of Facebook. A cookie may also be stored on the access device for these purposes.

The following cookie is placed on our websites:
„_fpb“  This cookie is used by Facebook in order to display a series of advertising products. Process 24 hours.

Revoking consent:
Revoking consent at Facebook: https://www.facebook.com/ads/website_custom_audiences/

 

Application:
YouTube Plug-In

Provider:
YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA

 

Description:
Doka uses a plug-in from the YouTube website operated by Google to integrate videos. If the user visits a website equipped with a YouTube plug-in by Doka, a connection will be established with the YouTube servers. The YouTube server will be informed of which Doka websites have been visited. If the user is also logged into his/her YouTube account, YouTube will be able to allocate the surfing behaviour directly to the personal user profile.

Revoking consent:
This allocation can be prevented by signing out of the YouTube account and other YouTube LLC and Google Inc user accounts and by deleting the relevant cookies: www.youtube.com

 

Application:
Vimeo Plug-In

Provider:
Vimeo LCC, 555 West 18th Street, New York, New York 10011, USA („Vimeo“)

Description:
Vimeo.com plug-ins are used on these websites. If users access websites that are equipped with a Vimeo plug-in, a connection will be established with the Vimeo servers and the plug-in displayed. If users are logged into Vimeo as members, Vimeo will allocate this information to the personal user account on this platform. However, this allocation could be prevented by the user logging out from his/her Vimeo user account and deleting the corresponding Vimeo cookies before using the Doka website. Further information on data processing and details on data protection from Vimeo can be found at https://vimeo.com/privacy

Revoking consent:
However, this allocation cannot be prevented by the user logging out from his/her Vimeo user account and deleting the corresponding Vimeo cookies before using the Doka website: www.vimeo.com

 

Application:
Sketchfab Plug-In

Provider:
Sketchfab, Inc., Sketchfab HQ, 1123 Broadway #501 (25th St), New York City, NY 10010 US („Sketchfab“)

Description:
Doka uses plug-ins from the website sketchfab.com run by Sketchfab, Inc.. If Doka websites are visited by users who are equipped with a Sketchfab plug-in, a connection will be established with the Sketchfab servers which then instructs the user’s browser to display the plug-in on the website. If users are logged into their Sketchfab account, they are enabling the company to allocate their surfing behaviour directly to their personal profile.

Revoking consent:
This procedure can be prevented by logging out from the Sketchfab account: www.sketchfab.com

 

Application:
Watchado Plug-In

Provider:
whatchado GmbH, Möllwaldplatz 4/39, 1040 Wien, Österreich („Whatchado“)

Description:
Doka uses plug-ins on the website whatchado.com run by Whatchado to integrate videos on the websites. Whatchado is operated by whatchado GmbH, Möllwaldplatz 4/39, 1040 Vienna, Austria. If Doka websites are accessed that are equipped with this plug-in, a connection will be established with the Whatchado servers. If users are logged into their Whatchado account, Whatchado will be able to allocate the surfing behaviour directly to the user’s personal profile.

Revoking consent:
This is prevented by logging out of the user account: www.whatchado.com

 

Application:
Mandrill

Provider:
Rocket Science Group, LLC, 512 Means St. Suite 404, Atlanta, GA 30318, USA („Mandrill“)

Description:
Doka uses the Mandrill service. This involves the specified contact details such as email address, title, first name and surname as well as the content of an email being transferred to Mandrill and stored there. The service manages data about when emails that were sent by Doka, when they have been read and when the links in them have been opened. The service may also gather data on how often an email has been opened and what IP address, which email client and which operating system it is from. The Rocket Science Group, LLC takes part in the EU-US Privacy Shield framework programme of the US Department of Commerce in relation to the collection, usage and storage of personal data from the Member States of the European Economic Area. You will receive information here on which data The Rocket Science Group, LLC collects, processes and uses as part of the EU-US Privacy Shield framework programme and the purposes for which this is done: https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG. Further information on Mandrill and data protection at Mandrill can be found here: https://mailchimp.com/legal/privacy/

Revoking consent:
Mandrill’s services are used when it comes to using contact forms at doka.com. If you do not want to use this service, we recommend using an alternative method to contact Doka in relation to the contact details specified on the relevant websites.

 

Application:
GeoLite2

Provider:
MaxMind, Inc. 14 Spring Street, 3rd Floor Waltham, MA 02451 USA („MaxMind“)

Description:
GeoLite 2 is used to determine IP addresses to provide you with the correct country version of the online shop immediately. GeoLite 2 data is prepared by MaxMind. You can find more information at: https://www.maxmind.com/en/privacy_policy

Revoking consent:
Contacting Doka (see below)

 

Application:
Walls.io

Provider:
“Die Socialisten” Social Software Development GmbH, Andreasgasse 6, Top 1, 1070 Vienna, Austria, Europe (“Walls.io”)

Description:
Doka uses the services of Walls.io. When this plug-in is called, IP address and session-cookie information are sent to Walls.io, solely on account of technical necessities relating to provision of the service. These data are saved only by Walls.io in Europe and are not made available to third parties. For more information on data processing by Walls.io, see the privacy policy of Walls.io here: https://walls.io/privacy

Revocation of consent:
You can restrict or prevent the execution of Walls.io on our websites by selecting the appropriate settings in your browser. In this case our websites might not be available in full and some content might be missing.

IV. Rights of the persons affected and contact

Doka points out that the user has rights pursuant to GDPR in relation to the processing of his/her personal data, for example a right to information, data porting, to object and to erasure. In order to assert these rights and address other issues relating to the processing of personal data with Doka, please contact them at: Doka GmbH, Subject matter: Data protection query, Josef Umdasch Platz 1, 3300 Amstetten, Austria.

Please alternatively forward your queries on the subject of data protection to: dataprotection@doka.com

Users also have a right of appeal to the data protection authority of the Republic of Austria on matters relating to data protection: https://www.dsb.gv.at/

V. Adapting the privacy statement

Doka regularly maintains its websites. This may include the statement being adapted. This adaptation is not referred to separately. It is therefore recommended to access this statement on a regular basis.