Introduction and overview
We have written this privacy policy in order to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (referred to below simply as data) we process as controller – together with the processors we commission (e.g. providers) – which data we will process in the future, and what lawful options are available to you. All terms used are to be understood as gender-neutral.
In short: we inform you comprehensively about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, by contrast, is intended to describe the most important points as simply and transparently as possible. Where it aids transparency, technical terms are explained in a reader-friendly way and links to further information are provided. In clear and simple language we thereby explain that, in the course of our business activities, we process personal data only where there is an appropriate legal basis for doing so. That is certainly not possible if one gives the briefest, vaguest and most legalistic explanations, as is often the standard on the internet when it comes to data protection.
If questions nevertheless remain, we would ask you to contact the controller named below or in the legal notice, to follow the links provided and to look at further information on third-party sites. Our contact details can of course also be found in the legal notice.
Scope
This privacy policy applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (processors). By personal data we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data enables us to offer and invoice our services and products, whether online or offline. The scope of this privacy policy covers:
- all online presences (websites, online shops) that we operate
- social media presences and email communication
- mobile apps for smartphones and other devices
In short: the privacy policy applies to all areas in which personal data is processed in a structured manner in the company via the channels named above. Should we enter into legal relationships with you outside these channels, we will inform you separately where appropriate.
Legal bases
In the following privacy policy we provide you with transparent information on the legal principles and provisions – that is, the legal bases of the General Data Protection Regulation – which enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course read this EU General Data Protection Regulation online on EUR-Lex, the gateway to EU law, at eur-lex.europa.eu.
We process your data only if at least one of the following conditions applies:
- Consent (Article 6(1)(a) GDPR): you have given us your consent to process data for a specific purpose. One example would be the storage of the data you entered into a contact form.
- Contract (Article 6(1)(b) GDPR): we process your data in order to perform a contract or pre-contractual obligations with you. If, for example, we conclude a purchase agreement with you, we require personal information in advance.
- Legal obligation (Article 6(1)(c) GDPR): where we are subject to a legal obligation, we process your data. For example, we are required by law to retain invoices for accounting purposes. These generally contain personal data.
- Legitimate interests (Article 6(1)(f) GDPR): in the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we have to process certain data in order to be able to operate our website securely and in an economically efficient manner. Such processing therefore constitutes a legitimate interest.
Further conditions such as the performance of tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests, do not usually arise in our case. Insofar as such a legal basis should nevertheless be relevant, it will be indicated at the appropriate point.
In addition to the EU regulation, national laws also apply:
- In Austria this is the Federal Act concerning the Protection of Personal Data (Datenschutzgesetz), DSG for short.
- In Germany the Federal Data Protection Act (BDSG) applies.
Should further regional or national laws apply, we will inform you about them in the following sections.
Contact details of the controller
Should you have any questions about data protection, you will find the contact details of the responsible person or body below:
Ing. René Eder, BA MSc MBA
Schleiergasse 9/23, 1100 Vienna, Austria
Email: office@redfox.management
Phone: +43 664 148 99 77
Legal notice: https://redfox.management/en/#impressum
Retention period
It is a general criterion for us that we store personal data only for as long as is strictly necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for processing it no longer exists. In some cases we are legally obliged to retain certain data even after the original purpose has ceased to apply, for example for accounting purposes.
Should you wish your data to be deleted or withdraw your consent to data processing, the data will be deleted as quickly as possible and to the extent that no obligation to retain it exists.
We will inform you further below about the specific duration of the respective data processing, provided we have further information on this.
Your rights under the GDPR
Under Article 13 GDPR you have the following rights, in order to ensure fair and transparent processing of data:
- Under Article 15 GDPR you have a right of access as to whether we process data about you. If that is the case, you have the right to receive a copy of the data and to be informed of the following:
- the purpose for which we carry out the processing;
- the categories, that is to say the types of data being processed;
- who receives this data and, where the data is transferred to third countries, how security can be guaranteed;
- how long the data will be stored;
- the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
- that you may lodge a complaint with a supervisory authority (links to these authorities can be found below);
- the origin of the data, if we did not collect it from you;
- whether profiling is carried out, that is to say whether data is evaluated automatically in order to arrive at a personal profile of you.
- Under Article 16 GDPR you have a right to rectification of the data, which means that we must correct data if you find errors.
- Under Article 17 GDPR you have the right to erasure (the "right to be forgotten"), which specifically means that you may request the deletion of your data.
- Under Article 18 GDPR you have the right to restriction of processing, which means that we may only store the data but not use it further.
- Under Article 19 GDPR you have the right to data portability, which means that on request we will make your data available to you in a common format.
- Under Article 21 GDPR you have a right to object, which, once enforced, brings about a change in the processing.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then examine as quickly as possible whether we can legally comply with this objection.
- If data is used to conduct direct marketing, you may object to this type of data processing at any time. We may then no longer use your data for direct marketing.
- If data is used to carry out profiling, you may object to this type of data processing at any time. We may then no longer use your data for profiling.
- Under Article 22 GDPR you may, in certain circumstances, have the right not to be subject to a decision based solely on automated processing (for example profiling).
In short: you have rights – do not hesitate to contact the controller listed above!
If you believe that the processing of your data infringes data protection law, or that your data protection rights have been violated in any other way, you may lodge a complaint with the supervisory authority. For Austria this is the Data Protection Authority, whose website you will find at dsb.gv.at. In Germany there is a data protection commissioner for each federal state. For further information you may contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
Data transfers to third countries
We only transfer or process data in countries outside the EU (third countries) if you consent to this processing, if it is required by law, or if it is contractually necessary – and in every case only to the extent that this is generally permitted. In most cases your consent is the most important reason for us having data processed in third countries. The processing of personal data in third countries such as the USA, where many software manufacturers offer services and have their server locations, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, particular care is required with data transfers to the USA. Data processing by US services may result in data not being processed and stored in anonymised form. Furthermore, US government authorities may under certain circumstances gain access to individual data. In addition, collected data may be linked with data from other services of the same provider, if you have a corresponding user account. Where possible, we seek to use server locations within the EU, provided this is offered.
We will inform you in more detail about data transfers to third countries at the relevant points in this privacy policy, insofar as such transfers apply.
Security of data processing
In order to protect personal data, we have implemented both technical and organisational measures. Wherever possible, we encrypt or pseudonymise personal data. In this way we make it as difficult as we can for third parties to infer personal information from our data.
Art. 25 GDPR speaks here of "data protection by design and by default", meaning that with both software (e.g. forms) and hardware (e.g. access to the server room) one always considers security and takes appropriate measures. Below we go into specific measures, where necessary.
TLS encryption with https
TLS, encryption and https sound very technical, and they are. We use HTTPS (Hypertext Transfer Protocol Secure) in order to transfer data securely over the internet. This means that the entire transfer of all data from your browser to our web server is protected – nobody can "listen in".
We have thereby introduced an additional layer of security and fulfil data protection by design (Article 25(1) GDPR). Through the use of TLS (Transport Layer Security), an encryption protocol for secure data transfer on the internet, we can ensure the protection of confidential data. You can recognise the use of this protection of data transfer by the small padlock symbol at the top left of the browser, to the left of the internet address, and by the use of the https scheme (instead of http) as part of our internet address.
Communication
Communication — summary
- Data subjects
- Everyone who communicates with us by telephone, email or online form
- Data processed
- e.g. telephone number, name, email address, data entered into forms. You will find more details under the respective type of contact
- Purpose
- Handling communication with customers, business partners, etc.
- Retention period
- Duration of the business case and of the statutory provisions
- Legal bases
- Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)
If you contact us and communicate by telephone, email or online form, personal data may be processed.
The data is processed in order to handle and deal with your enquiry and the associated business transaction. The data is stored for the same period, or for as long as the law requires.
Data subjects
Everyone who seeks contact with us via the communication channels we provide is affected by the processes described.
Telephone
If you call us, the call data is stored in pseudonymised form on the respective device and at the telecommunications provider used. In addition, data such as name and telephone number may subsequently be sent by email and stored in order to answer the enquiry. The data is deleted as soon as the business case has been concluded and statutory provisions permit.
If you communicate with us by email, data may be stored on the respective device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data is deleted as soon as the business case has been concluded and statutory provisions permit.
Online forms
If you communicate with us using an online form, data is stored on our web server and may be forwarded to an email address of ours. The data is deleted as soon as the business case has been concluded and statutory provisions permit.
Legal bases
The processing of the data is based on the following legal bases:
- Art. 6(1)(a) GDPR (consent): you give us your consent to store your data and to use it further for purposes relating to the business case;
- Art. 6(1)(b) GDPR (contract): there is a necessity for the performance of a contract with you or with a processor such as the telephone provider, or we have to process the data for pre-contractual activities such as the preparation of an offer;
- Art. 6(1)(f) GDPR (legitimate interests): we wish to handle customer enquiries and business communication in a professional setting. This requires certain technical facilities such as email programs, Exchange servers and mobile network operators in order to be able to conduct communication efficiently.
Web hosting
Web hosting — summary
- Data subjects
- Visitors to the website
- Purpose
- secure, stable and efficient provision of our website
- Data processed
- technical access data such as IP address, address requested, date and time of access, volume of data transferred, browser type and operating system
- Retention period
- access data is generally retained by the provider only for a short time, usually a few days
- Legal basis
- Art. 6(1)(f) GDPR (legitimate interests)
What is web hosting?
When you visit websites nowadays, certain information – including personal data – is automatically created and stored, and this website is no exception. Such data should be processed as sparingly as possible and only with justification. By website, incidentally, we mean the entirety of all web pages on a domain, that is everything from the homepage to the last subpage. By domain we mean redfox.management.
If you want to view a website on your computer, tablet or smartphone, you use a program called a web browser. The web browser first has to establish a connection to another computer on which the data of the website is stored: the web server. Operating a web server is a demanding task, which is why it is generally handled by a professional provider.
Why do we process personal data?
The purposes of the data processing are:
- professional hosting of the website and safeguarding of its operation
- maintaining operational and IT security, in particular defending against automated attacks and abusive access
- evaluation of access behaviour by the provider exclusively in anonymised, aggregated form
What data is processed?
Even while you are visiting our website right now, our web server – the computer on which this website is stored – generally automatically stores data such as:
- the full internet address (URL) of the page requested
- browser and browser version as well as the operating system used
- the IP address of the accessing device
- date and time of access as well as the volume of data transferred
This data arises for technical reasons that cannot be avoided if a website is to be delivered at all. On this website we operate neither analytics tools nor tracking, and we set no cookies for analytics or marketing purposes.
How long and where is the data stored?
The access data described above is processed by the provider in server log files and retained there only for a short time, usually a few days. We ourselves do not evaluate these log files on a personal basis.
Hosting provider: digimagical GmbH
This website is operated on servers of digimagical GmbH, Legstattgasse 4–6/25, 3001 Mauerbach, Austria (company register FN 394558h, Regional Court of St. Pölten, VAT ID ATU67821878). digimagical GmbH acts for us as a processor within the meaning of Art. 28 GDPR; a corresponding data processing agreement is in place.
The provider is established in Austria and processes the access data described above within the European Union. No transfer to third countries takes place as part of the hosting. The company is certified to ISO/IEC 27001:2022, meaning it operates an externally audited information security management system.
Contact: office@digimagical.com, phone +43 720 343 873 100. For abuse reports: abuse@digimagical.com.
Cloudflare (DNS and redirection of former domains)
For the domains red-fox.consulting, reneeder.pro and reneeder.com, DNS management is handled via Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA; for the European area, Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany is responsible. These domains are used solely to direct visitors to redfox.management by way of a permanent redirect (HTTP 301).
If you call up one of these three domains, your request passes through Cloudflare's network before the redirect, and your IP address is processed in doing so. If you call up redfox.management directly, Cloudflare is not involved.
Cloudflare operates a worldwide network of servers. Requests from Europe are usually answered within the EU, although processing in third countries – in particular in the USA – cannot be ruled out. We point out that, in the opinion of the European Court of Justice, particular care is required with data transfers to the USA. As the basis for processing by recipients in third countries, Cloudflare uses what are known as standard contractual clauses (Art. 46(2) and (3) GDPR) – template documents provided by the EU Commission intended to ensure that your data complies with European data protection standards outside the EU as well. You will find the decision and the clauses here: eur-lex.europa.eu
A data processing agreement is in place with Cloudflare. You can find out more about the data processed in Cloudflare's privacy policy at cloudflare.com/privacypolicy.
Legal basis
The legal basis is Art. 6(1)(f) GDPR (legitimate interests). We have a legitimate interest in providing our website securely, stably and in an economically efficient manner. Without the processing of this technical access data, operation of the website would not be possible.
Other services
Other services — summary
- Data subjects
- Visitors to the website
- Purpose
- Improving the user experience
- Data processed
- Which data is processed depends heavily on the services used. In most cases it is the IP address and/or technical data. You will find more details under the respective tools.
- Retention period
- depending on the tools used
- Legal bases
- Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What falls under "other services"?
The category "other services" covers those services that do not fit into any of the categories named above. These are generally various embedded elements that improve our website. As a rule, these functions are obtained from third-party providers and integrated into our website.
What data is processed?
Whenever elements from third-party providers are integrated into our website, your IP address is transmitted to the respective provider and processed there. This is technically necessary, because otherwise the content could not be sent to your browser and consequently could not be displayed. Every provider handles your data differently. We therefore recommend that you read the privacy policies of the respective services carefully. As a matter of principle, we endeavour to use only services that treat the subject of data protection with great care.
Duration of the data processing
We will inform you below about the duration of the data processing, provided we have further information on this. In general we process personal data only for as long as is strictly necessary for the provision of our services and products.
Google Fonts
Google Fonts — summary
- Data subjects
- Visitors to the website
- Purpose
- consistent and error-free display of typefaces across platforms
- Data processed
- data such as IP address as well as CSS and font requests
- Retention period
- font files are stored by Google for one year
- Legal bases
- Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)
What is Google Fonts?
On our website we use Google Fonts, the "Google typefaces" of Google Inc. For the European area, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.
To use Google typefaces you do not have to register or store a password. Nor are any cookies stored in your browser. The files (CSS, typefaces/fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are entirely separate from all other Google services.
Why do we use Google Fonts on our website?
With Google Fonts we can use typefaces on our own website without having to upload them to our own server. All Google typefaces are automatically optimised for the web; this saves data volume and is an advantage particularly on mobile devices. Otherwise, differing rendering systems in various browsers, operating systems and mobile devices can lead to errors that visually distort text or entire web pages.
What data is stored by Google?
When you visit our website, the typefaces are loaded from a Google server. Through this external call, data is transmitted to Google's servers. Google thereby also recognises that you, or your IP address, are visiting our website. The Google Fonts API was developed in order to reduce the use, storage and collection of end-user data to what is necessary for the proper provision of typefaces.
It should nevertheless be borne in mind that with every Google Fonts request, information such as language settings, IP address, browser version, browser screen resolution and browser name is automatically transmitted to Google's servers. Whether this data is also stored cannot be clearly established, nor is it unambiguously communicated by Google.
How long and where is the data stored?
Google stores requests for CSS assets for one day on its servers, which are located primarily outside the EU. The font files are stored by Google for one year. Google's aim in doing so is to improve the loading time of web pages generally.
How can I delete my data or prevent it from being stored?
Data that Google stores for one day or one year cannot simply be deleted. The data is transmitted to Google automatically when the page is called up. In order to have this data deleted early, you must contact Google Support at support.google.com.
Legal basis
If you have consented to the use of Google Fonts, that consent is the legal basis for the corresponding data processing. Under Art. 6(1)(a) GDPR this consent constitutes the legal basis for the processing of personal data as may occur when it is collected by Google Fonts. In addition, we have a legitimate interest in using Google Fonts in order to optimise our online service. The corresponding legal basis for this is Art. 6(1)(f) GDPR (legitimate interests).
Google also processes data about you in the USA, among other places. As the basis for data processing by recipients established in third countries, or for a transfer of data there, Google uses what are known as standard contractual clauses (Art. 46(2) and (3) GDPR). You will find the decision and the corresponding standard contractual clauses here, among other places: eur-lex.europa.eu
You can also read about which data is collected by Google in general, and what this data is used for, at policies.google.com/privacy.
All texts are protected by copyright. Source: created with the privacy policy generator by AdSimple, adapted to the actual operation of this website. This English version is a translation of the legally binding German original; in case of doubt, the German version prevails.