Privacy
The common good needs trust — and protection for people.
Open infrastructure must never come at the expense of personal rights. We explain what data is processed, why and which rights you have.
- People before data
- Data minimization
- Clear rights
Data protection declaration
As of June 18, 2024. SupraTix GmbH takes the protection of your personal data very seriously. Personal data is all data that can be related to you personally, for example name, address, email address or user behavior.
Personal data may be collected when you visit the website. This data will be processed in compliance with applicable data protection regulations and will not be published or passed on to third parties without authorization.
This data protection declaration informs you about what data is collected when you visit the websites and how this data is used.
This online offer may only be used by children under 16 years of age with the separate consent of their legal guardian. The required form can be requested via datenschutz@supratix.com.
The definitions from Article 4 of the General Data Protection Regulation (GDPR) apply to terms such as personal data or processing.
Person responsible and data protection contact
SupraTix GmbHOstra-Allee 20
01067 Dresden, Germany
Telephone: +49 (0) 351 33948 400
Email: info@supratix.com
If you have any questions about data protection at SupraTix GmbH, Tobias Göcke is available at the address mentioned and by email to datenschutz@supratix.com.
Types of data processed and purposes
The source version names inventory data, contact data, content data, contract data, payment data, metacommunication data and usage data.
- Inventory data: name, username, address, birthday and associated organization.
- Contact details: email address and telephone number.
- Content data: Text entries, programming, imports and uploads such as images, videos or PDFs.
- Contract and payment data: product usage, subject matter of the contract, term, customer category, bank details and payment history.
- Meta and usage data: IP address, account activities, time zone, content type, learning preference, skills, task activities, spatial data, operating system, browser, language and browser software version.
The processing can concern contact inquiries, service provision, contract processing, security, technical operation, communication, organizational procedures, newsletters and the provision of the online offer.
Processors, third parties and third countries
If SupraTix GmbH discloses, transmits or otherwise grants access to data to processors or third parties, this is only done on the basis of legal permission, consent, a legal obligation or legitimate interests.
If third parties are commissioned to process data, this is done on the basis of an order processing contract in accordance with Art. 28 GDPR.
Transfers to third countries outside the European Union or the European Economic Area only take place if this happens to fulfill pre-contractual or contractual obligations, on the basis of consent, on the basis of a legal obligation or on the basis of legitimate interests. The source version also mentions Privacy Shield and standard contractual clauses.
Legal basis and security
The legal basis of the source includes consent according to Art. 6 Paragraph 1 lit. a and Art. 7 GDPR, contract fulfillment and pre-contractual measures according to Art. 6 Paragraph 1 Letter d GDPR.
SupraTix GmbH uses technical and organizational security measures to protect personal data against misuse, loss, destruction and access by unauthorized persons.
Contact, deletion and rights
When you contact us via email or online contact form, the data provided will be saved to answer questions. The data arising in this context will be deleted as soon as storage is no longer necessary, or restricted if there are legal retention requirements.
Data subjects have the legal rights to information, correction, deletion, restriction of processing, objection to processing and data portability. You also have the right to complain to a data protection supervisory authority.
Data will be deleted or its processing restricted in accordance with Articles 17 and 18 GDPR as soon as they are no longer necessary for their intended purpose. Commercial or tax law requirements may require storage for six or ten years.
Newsletter and cookies
Newsletters, emails and other electronic notifications with promotional information will only be sent with the consent of the recipient or legal permission. Registration takes place using the double opt-in procedure and is logged with the registration time, confirmation time and IP address.
Some of the websites use cookies. Some cookies are session cookies and are automatically deleted after the visit. Other cookies remain stored on the device until they are deleted. Browser settings can limit or block cookies; this may limit the functionality of the website.
Named services
- Amazon Web Services
- The source credits Amazon Web Services, Inc. for services such as S3, CloudFront, Lambda, EC2, Application Load Balancer, Elastic Cache, Elastic Transcoder, SNS, and SQS. The basis is legitimate interests and an order processing contract.
- DATEV eG
- The source names DATEV eG for CRM and accounting software. The basis is legitimate interests and an order processing contract.
- Creditreform Boniversum GmbH
- The source names Creditreform Boniversum GmbH, Hammfelddamm 13, 41460 Neuss, for credit checks when concluding contracts and in cases with legitimate interest.
Objection to advertising emails
The use of contact details published as part of the imprint obligation to send advertising and information materials that have not been expressly requested is prohibited. The operators reserve the right to take legal action in the event of unsolicited advertising information, such as spam emails.
OSC-specific addition
This supplement describes public OSC forms, optional PDF uploads, the strategy form and web analytics on the OSC pages.
- OSC public forms
- Contact, participation and strategy requests are processed to process the request. Mandatory fields remain limited to the information required for an initial classification.
- Private inquiry inbox
- Contact and participation inquiries are stored with your contact details, message, selected topic or role, and any PDF attachment. Only authorized staff in the relevant organization can access this inbox. Attachments have no public download link. A reference number identifies the inquiry; submitting interest does not create a membership or payment obligation.
- Optional PDF uploads
- A PDF file can be transmitted voluntarily, up to a maximum of 10 MB. It is only used to check and process the request.
- Protection against repeated submissions
- The contact and participation forms use temporary request counters. Their keys are derived from the network address, organization context and time window using a secret-key hash. The counters contain no contact details, message text or raw IP address and expire after the configured window. They are not added to the inquiry record. Hosting and access logs are separate from these counters.
- Strategy form
- The strategy form on the OSC homepage transmits inquiries via
/store/safe-contact-formular/into the operator's existing contact process. - supra_tracking and web analysis
-
SupraTracking – Reichweiten- und Nutzungsanalyse dieser Website
Diese Website misst mit dem eigenen Dienst SupraTracking, welche Seiten wie lange aufgerufen werden. Die Daten werden ausschließlich auf den Servern dieses Mandanten gespeichert (keine Drittanbieter, keine Werbenetzwerke, kein seitenübergreifendes Tracking).
- Immer (berechtigtes Interest an Reichweitenmessung, Art. 6 Abs. 1 lit. f DSGVO)
- Aufgerufene Seite (ohne Suchparameter), verweisende Seite (ohne Suchparameter), Zeitpunkt, IP-Adresse, Browserkennung, Language, Zeitzone, Bildschirmgröße, Kampagnenparameter (utm_*) sowie – bei Anmeldung – das Nutzerkonto. Solange die Seite sichtbar ist, sendet der Browser alle 30 Sekunden ein Aktivitätssignal. Aus dem Netzwerk kann das besuchende Company (nicht die Person) abgeleitet werden. Klicks auf Links werden gezählt: externe Links führen dazu über eine kurze Weiterleitung auf unserem Server, bei allen anderen Links (interne Seiten, Email, Phone, Downloads) meldet der Browser beim Klick, welcher Link genutzt wurde. Bei angemeldeten Nutzern wird der Klick dem Konto zugeordnet, außer der Browser sendet „Do Not Track“ oder „Global Privacy Control“.
- Nur mit Ihrer Einwilligung (§ 25 Abs. 1 TTDSG, Art. 6 Abs. 1 lit. a DSGVO)
- Verhaltensanalyse: größte Scrolltiefe, aktive Zeit (Tab sichtbar und Eingabe in den letzten 15 Sekunden), Anzahl der Eingaben, Ausstiegsgrund (Seite geschlossen, Link geklickt, Tab gewechselt) und Interaktionen mit Seitenelementen. Gespeichert werden nur diese zusammengefassten Werte – keine Mauskoordinaten, keine Tastatureingaben, keine Forminhalte. Die Einwilligung erteilen oder widerrufen Sie in den Cookie-Einstellungen (Kategorie mit SupraTracking-Verhaltensanalyse) bzw. über die Einwilligungsauswahl der jeweiligen Seite. Sendet Ihr Browser „Do Not Track“ oder „Global Privacy Control“, wird keine Verhaltensanalyse erfasst.
- Aktionen im Frame der Nutzung (Vertrag bzw. berechtigtes Interest)
- Registrierung, Kontaktanfrage, Bestellung sowie Buchung oder Lizenzierung eines Produkts werden als Ereignis erfasst. Ist der Nutzer angemeldet oder einem Kontakt im Kundenbeziehungsmanagement (CRM) zugeordnet, erscheint das Ereignis in dessen Aktivitätsverlauf bzw. im Verlauf des zugehörigen Companys, damit Anfragen und Buchungen betreut werden können. Verhaltensdaten (Scrolltiefe, Interaktionen) werden dort nie eingetragen.
- Zugriff und Rechte
- Auswertungen sehen nur berechtigte Administratoren des Mandanten. Auskunft, Berichtigung, Löschung, Einschränkung und Widerspruch richten Sie an die in dieser Privacyerklärung genannte Stelle; ein Widerruf der Einwilligung wirkt für die Zukunft.