Data privacy

When operating the website www.sustainadiligence.com, Carleo Consult GmbH (hereinafter referred to as “we”) acts as the controller within the meaning of the GDPR.

The protection of your data is of particular concern to us. We therefore process your data exclusively on the basis of the statutory provisions (GDPR, TKG). In this data protection information, we inform you about the most important aspects of data processing on our website.

In principle, you are not obliged to provide us with your personal data. However, the processing of certain personal data is necessary in order to be able to handle business relationships with you and is regulated in accordance with the mandate agreement or any general terms and conditions.

We do not use your data for automated decision-making including profiling within the meaning of Art. 13 para. 2 lit. f and Art. 14 para. 2 lit. g GDPR.

Due to the further development of our website or legal changes, it may become necessary to amend this privacy policy. The version published on our website applies in each case.

Below you will find detailed information on the individual data processing operations.

1. Provision of the website (log files & hosting)

2. Cookies and tracking

3. Newsletter

4. Your rights

5. Links to external pages

6. Data security

7. Contact

1. Provision of the website (log files & hosting)

1.1 Scope of data processing

Each time you visit our website, we automatically collect certain information about your device, including information about your web browser, your IP address, your time zone and some of the cookies installed on your device. When you browse the website, we also collect information about the individual web pages or products you view, which websites or search terms referred you to the website and how you interact with the website.

1.2 Purpose of data processing

The security of customer data is our top priority. We therefore only process a minimum amount of user data, and only as much as is absolutely necessary to maintain the website. Automatically collected information is only used to detect possible cases of abuse and to compile statistical information about the use of the website. This statistical information is not summarized in such a way that it allows conclusions to be drawn about a specific user of the system.

1.3 Legal basis

The legal basis for the temporary storage of data and log files is our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Our legitimate interest in data processing is to achieve the purposes described under point 1.2.

1.4 Storage period

The data is either deleted after the end of the respective session or anonymized or stored in log files. The data is not stored in a form that allows the data subject to be identified.

2. Cookies and tracking

This website does not use cookies.

3. Newsletter

If the option to register for a newsletter is offered on our website, the following applies: the newsletter fulfills the task of informing you about new developments and news. Only the e-mail address is used to send the newsletter. Our newsletter is sent on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR or, if consent is not required (e.g. for existing customers), on the basis of our legitimate interest in direct marketing for similar products or services in accordance with Art. 6 para. 1 lit. f GDPR. You can revoke your consent to the sending of the newsletter at any time and unsubscribe from the newsletter. You can declare your revocation by clicking on the link provided in every newsletter e-mail or by sending a message to the contact details given in the imprint.

4. Your rights

You have the following rights vis-à-vis us with regard to the personal data concerned:

- Right of access,

- Right to rectification or erasure,

- Right to restriction of processing,

- Right to object to processing,

- Right to data portability.

If you believe that the processing of the data violates data protection law, you can lodge a complaint with the supervisory authority. In Austria, this is the data protection authority (https://www.dsb.gv.at). If you have given us your consent to process your data, this can be revoked at any time. Such a revocation affects the permissibility of the processing of your personal data after you have expressed the revocation to us. If the processing of your personal data is based on our legitimate interest, you can object to the processing. When exercising such an objection, we ask you to state the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either discontinue or adapt the data processing or point out to you our compelling legitimate grounds on the basis of which we are entitled to continue the processing.

5. Links to external pages

Our website may contain links to other websites that are not owned or controlled by us. Please be aware that we are not responsible for such other websites or third parties' privacy practices. We encourage you to be aware when you leave our website and read the privacy statements of each website that may collect personal information.

6. Information security

We secure information you provide on computer servers in a controlled, secure environment, protected from unauthorized access, use, or disclosure. We keep reasonable administrative, technical, and physical safeguards to protect against unauthorized access, use, modification, and personal data disclosure in its control and custody.