Legal
Privacy
This page describes what actually happens when you read here, write to us, book an appointment, or place an order. In short: no tracking, no advertising cookies, no transfer outside the EU.
This is a translation for convenience. The authoritative version is the German one.
Controller
Ascios GmbH, [street and number missing], 3100 St. Pölten, Austria.kontakt@ascios.eu
No data protection officer has been appointed. The conditions of Art. 37 GDPR are not met: we neither carry out regular large-scale monitoring nor process special categories of personal data on a large scale. Please address data protection requests to the contact above.
This website
Hosting is on European infrastructure with [hosting provider not yet decided]. When a page is requested, the server processes technically necessary connection data: IP address, time, requested address, volume transferred, browser identification. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
[data processing agreement with the host under Art. 28 GDPR not yet concluded - required before going live]
No tracking or marketing cookies are set and no audience measurement takes place. All fonts are served from our own server; no connections to Google Fonts or other third parties are made.
Booking an appointment
If you book an initial call through our form, we process your name, email address, optionally your phone number and company, your enquiry and the chosen time slot, in order to arrange, hold and communicate with you about the call (Art. 6(1)(b) GDPR, pre-contractual measure at your request). To confirm your email address we send you a six-digit one-time code. Providing this data is voluntary, but without it we cannot process your booking.
Abuse protection
To keep our public forms (appointment booking, quote acceptance) from being misused for automated requests or to harass someone else’s mailbox with unsolicited mail, we limit the number of requests per IP address and per mailbox within a short window and per day, require the browser to do a small amount of computational work before sending (proof of work), and check a form field invisible to humans that only automated programs fill in. The legal basis is our legitimate interest in a working, abuse-free service (Art. 6(1)(f) GDPR). For this we temporarily keep the IP address and a cryptographic hash of the email address in a counter; the address itself is not stored for this purpose.
Suppression list for unsolicited mail
If an email address is entered into our appointment form without the person concerned having done so themselves, they can permanently stop further confirmation emails via a link in the email. For this we store only a cryptographic hash of the address, never the address itself - this is also the technical implementation of the right to object under Art. 21 GDPR against this processing. The suppression can be reversed at any time on the same page.
The free self-check
The self-check runs entirely in your browser. Your answers are not transmitted to us and are not stored anywhere on our side. So that an accidental reload does not lose your work, the page keeps them in your browser’s sessionStorage - a store that is cleared when you close the tab. This happens exclusively on your own device. The button at the end of the page clears it at any time.
Enquiries
If you write to us, we process your contact details and the content of your message in order to answer it and to prepare a possible contract (Art. 6(1)(b) GDPR).
Ordering
If you order Ascios Learn or Ascios Assess through our order page, we process the details this requires (company name, VAT identification number, and for larger orders a second contact person) to perform the contract (Art. 6(1)(b) GDPR).
We additionally log the time, IP address and browser identification for each step of the order process - for example confirming the terms and conditions or the service description. This serves to prove that and when an order was validly placed, should that need clarifying in a dispute (Art. 6(1)(f) GDPR, legitimate interest in being able to prove that contracts were concluded).
If you name a second contact person when ordering, we receive their name and contact details from you as the ordering person, not directly from them (Art. 14 GDPR). Only the details needed to communicate about the order are processed.
VAT identification number verification
If you provide a VAT identification number when ordering, we verify it via the official VAT Information Exchange System (VIES) interface of the European Commission, to demonstrate the conditions for a VAT-exempt intra-Community supply (Art. 6(1)(c) GDPR, statutory tax record-keeping duty).
In our products
Survey data is processed pseudonymously by role - real names stay with you. Processing takes place on European infrastructure; free text is analysed by locally operated models. Customer data trains no third-party models. Once the report is released, the raw answers are deleted. No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
Sending mail, delivery log, and our internal admin tool
We use a mail service provider within the EU to send our emails. For every email sent we log the recipient, subject, content and time, and - for an undeliverable message (bounce) - the error returned by the receiving mailbox, which we retrieve automatically via IMAP.
We log every write action our staff perform in our internal admin tool (for example creating a document or recording a payment) with the time, user account, action and the IP address of the access. This serves the traceability of our own bookkeeping and the investigation of security incidents (Art. 6(1)(f) and (c) GDPR).
Recipients of your data
We only pass your data on where necessary to provide our services: to our hosting provider (technical operation of this website), to a mail service provider within the EU (sending emails), to our tax advisor (bookkeeping), and, for a VAT check, to the European Commission (VIES). A data processing agreement under Art. 28 GDPR is or will be in place with every provider that has access to personal data in doing so. No transfer to countries outside the EU and EEA takes place.
Retention periods at a glance
We keep personal data for this long, unless a reason for longer retention applies:
- Appointment bookings without a resulting contract12 months, then automated anonymisation
- Enquiries not linked to a business case12 months, then automated anonymisation
- Business records (invoices, payments, delivery log, audit trail, VAT check evidence)7 years (§ 132 BAO, Austrian tax code)
- Suppression list for unsolicited mailunlimited while active; lifted entries are deleted after 12 months
Your rights
You have the following rights in relation to Ascios GmbH. An informal email is enough.
- AccessArt. 15 GDPR
- RectificationArt. 16 GDPR
- ErasureArt. 17 GDPR
- Restriction of processingArt. 18 GDPR
- Data portabilityArt. 20 GDPR
- ObjectionArt. 21 GDPR
We currently have no processing based on your consent. Should that change, you would have the right at any time to withdraw such consent with effect for the future (Art. 7(3) GDPR).
If you believe that the processing of your data infringes the GDPR, you may lodge a complaint with the supervisory authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria,dsb.gv.at