PRIVACY POLICY
ARTICLE 13 GENERAL DATA PROTECTION REGULATION (GDPR)
1 WHICH DATA ARE PROCESSED AND FROM WHICH SOURCES DO THEY COME FROM?
- Your personal details: e.g. name, address, e-mail address, telephone number and gender
- Data about your PhiShop purchases: e.g. customer number, UID number, previous purchases,
- Invoice number, purchase date and time, product, quantity and price
- Data about your payment method: e.g. bank details, used credit card company,...
2 FOR WHAT PURPOSES AND FOR WHAT DURATION ARE DATA PROCESSED?
We may combine Data we or our providers have collected with Data collected by our affiliates to gain a more detailed picture of the needs and interests of our users. Also, your Data (buyers’, followers’ and students’ Data) may be processed to create and execute unified marketing campaigns and analytics thereof for both the Controller and PhiAcademy GmbH, and the analytics pertaining to the Phi brand in a unified manner.
In this way, we can provide better service to our customers as well as keep track of our Masters' activities related to the Phi brand. We process the abovementioned Data on the basis of your consent.
You can withdraw your consent anytime by e-mail to: info@phishop.com
Your Data will be processed until you withdraw consent, after which we will delete your Data immediately i.e., as soon as technically possible after receiving withdrawal.
3 ON WHAT LEGAL BASIS DO WE PROCESS YOUR DATA?
4 WHO RECEIVES YOUR DATA?
Company Name: | Located in: | Safeguards |
DHL Express (Austria) GmbH | Austria | |
Stripe, Inc. | USA | Standard Contractual Clauses |
PayPal (Europe) S.à.r.l. & Cie | Luxembourg | |
Klarna Bank AB | Sweden | |
Falcon.io ApS | Denmark | |
The Rocket Science Group LLC (MailChimp) | USA | Standard Contractual Clauses |
Freshworks Inc. | USA | Standard Contractual Clauses |
banibis GmbH | Austria | |
Craftmaster GmbH | Austria | |
PhiAcademy d.o.o | Serbia | Standard Contractual Clauses |
platform.sh | Germany | |
Vanilla Reply GmbH | Germany | |
Klaviyo, Inc. | USA | |
GMD Solutions | Serbia | |
Viber Rakuten | Luxembourg |
5 COOKIES
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
- “Log files” track actions occurring on the Website or Mobileshop, and collect data including your IP address, browser type, referring/exit pages, and date/time stamps.
- “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Website and use the Mobileshop.
Cookie Name | Purpose | Storage period |
section_data_ids | Facilitates the caching of content in the browser, so pages load faster. | Until the end of the page visit |
PHPSESSID | Your session ID on the server. | 1 hour |
product_data_storage | Saves the configuration for product data related to recently displayed / compared products. | Until the end of the page visit |
recently_compared_product | Stores product IDs of recently compared products. | Until the end of the page visit |
recently_viewed_product_previous | Stores product IDs of previously viewed products for easy navigation. | Until the end of the page visit |
mage-translation-file-version | Facilitates the translation of content into other languages. | Until the end of the page visit |
recently_viewed_product | Stores product IDs of recently viewed products for easy navigation. | Until the end of the page visit |
form_key | Stores randomly generated keys to prevent the use of forged information. | 1 hour |
Pnctest | Tests whether cookies are supported by your browser. | 1 hour |
recently_compared_product_previous | Stores product IDs of previously compared products for easy navigation. | Until the end of the page visit |
mage-cache-storage-section-invalidation | Facilitates the caching of content in the browser, so pages load faster. | Until the end of the page visit |
mage-cache-storage | Facilitates the caching of content in the browser, so pages load faster. | Until the end of the page visit |
mage-messages | Contains information on whether new messages are available in the shop for the visitor / customer. | Until the end of the page visit |
mage-translation-storage | Facilitates the translation of content into other languages. | Until the end of the page visit |
Cookie Name | Purpose | Storage period |
shopgate_analytics_SHOPNUMMER_uuid | Stores anonymous data for the creation of statistics in the retailer area. | 10 years |
SSID | Done through Facebook and Google listed below. | Until you close the app. |
Third Party | Description | Privacy Policy |
Google Analytics | We use Google Analytics to help measure how users interact with our websites. | https://policies.google.com/privacy |
Google Ads | We use Google Ads to deliver targeted advertisements to individuals who visit our websites. | https://policies.google.com/privacy |
We use Facebook Custom Audiences to deliver targeted advertisements to individuals who visit our websites. | https://www.facebook.com/policy.php | |
We use Pinterest Custom Audiences to deliver targeted advertisements to individuals who visit our websites. | https://policy.pinterest.com/en-gb/privacy-policy#section-residents-of-the-eea | |
Snapchat | We use Snapchat Custom Audiences to deliver targeted advertisements to individuals who visit our websites. | https://www.snap.com/en-GB/privacy/privacy-policy |
TikTok | We use TikTok Custom Audiences to deliver targeted advertisements to individuals who visit our websites. | https://www.tiktok.com/legal/privacy-policy?lang=en |
We use LinkedIn Custom Audiences to deliver targeted advertisements to individuals who visit our websites. | https://www.linkedin.com/legal/privacy-policy? | |
PayPal | We use PayPal as one of our payment providers to process your orders and capture payments. | https://www.paypal.com/en/webapps/mpp/ua/privacy-full |
Stripe | We use Stripe as one of our payment providers to process your orders and capture payments. | https://stripe.com/privacy-center/legal |
- If you want to prevent the use of Google Analytics cookies on the website, you can either do this through your browser settings (see point 5.1), or you can install the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout
Google Analytics Cookie | Purpose | Storage period |
_gat | Determined by Google Analytics to identify unique sessions | 30 minutes |
_gid | Determined by Google Analytics to identify unique sessions | 30 minutes |
_ga | Determined by Google Analytics to identify unique sessions | 30 minutes |
Personal data such as the IP address, as well as other information such as device ID, device type and operating system may also be transferred to TikTok to enable optimised targeting of advertising campaigns. TikTok processes this data to identify users of our website and associate their actions with a TikTok user account. TikTok processes this data to display targeted and personalised advertising to its users.
This procedure is used to evaluate the effectiveness of the Pinterest ads for statistical and market research purposes and can help to optimise our advertising measures. Personal data such as the IP address, as well as other information such as the device ID, device type and operating system may also be transferred to Pinterest in order to enable optimised measurement of the advertising campaigns. Because Pinterest is a worldwide service, Pinterest may transfer the personal data of EEA residents to a country outside the EEA. When Pinterest transfers information from the EEA to a country that doesn't provide an adequate level of protection, Pinterest will only do so under appropriate safeguards, such as standard contractual clauses. Pinterest’s Privacy Policy can be accessed here.
For years LinkedIn has relied on overlapping protections under both Standard Contractual Clauses (SCCs) and the Privacy Shield legal frameworks for data transfers. While the ruling by the European Court of Justice of the July 16, 2020 invalidated the use of Privacy Shield, SCCs remain in place and LinkedIn continues to transfer data from the EU, EEA and Switzerland using SCCs. LinkedIn is also monitoring ongoing negotiations between the U.S. Department of Commerce and EU Commission regarding a Privacy Shield replacement. Despite its invalidation as a transfer mechanism, LinkedIn has elected to maintain its Privacy Shield certification from the U.S. Department of Commerce.
Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
6 ARE YOU OBLIGED TO PROVIDE DATA?
7 YOUR RIGHTS IN THE CONTEXT OF THE PROCESSING OF YOUR DATA
- To request information about which of your personal Data we process (Article 15 GDPR);
- To rectify or erase your Data (Article 16 GDPR);
- To restrict the processing of your Data (Article 18 GDPR);
- To withdraw your consent (Article 7 GDPR);
- To object to the processing of your Data (Article 21 GDPR);
- To Data portability (Article 20 GDPR).
8 AUTOMATED DECISION-MAKING
9 WHO CAN YOU CONTACT?
Information on the processing of personal data (Privacy policy to applicants)
Dear applicant! Dear Applicant!
In fulfillment of the information obligations under the General Data Protection Regulation (Articles 13 and 14), we hereby inform you about the processing of your personal data in the context of the application procedure.
Purpose and legal basis of data processing
We process the data provided by you (e.g. from your CV, the submitted references, the application questionnaire, the interview, etc.) for the purpose of the selection procedure on the basis of your consent.
By submitting or transmitting your application documents, you therefore consent to the processing of personal data such as name, title, date of birth, home address, telephone number, e-mail address, education, work experience, salary requirements and those data and images contained in the letter of application, curriculum vitae, references or other documents submitted or transmitted, for the purpose of recording them in an applicant database of our company.
Transmission of data
Your data will be treated with absolute confidentiality during the application process and will not be passed on to third parties under any circumstances without your express consent.
Data will only be passed on during the application process in exceptional cases and with your consent, for example if this is necessary for the preliminary clarification of an intended job promotion. Possible recipients for this are in particular:
- Public Employment Service
- Social Ministry Service
- Austria Wirtschaftsservice GmbH
Duration of data storage
For the purpose of processing the application, the data provided will be stored in our applicant database for the duration of the selection process. In addition, in the event of rejection in accordance with the provisions of the Equal Treatment Act, the necessary data will generally remain stored for a further six months. In the event of legal proceedings, the data relevant to the proceedings will remain stored until the legal conclusion of the proceedings. After the relevant periods have expired, your data will be deleted unless you give us your consent to store it for a longer period of time to keep records for future job placements.
Your rights
You have the following rights under data protection law: information, correction, deletion, restriction, objection. Please contact us regarding these claims.
If you believe that the processing of your data violates data protection law or your data protection rights have been violated in any other way, you have the right to complain to the data protection authority.
You can reach us at the following contact details:
PhiAcademy GmbH - Wiegelestraße 10, 1230 Vienna - 01 375 1618 1618 - contact@phiacademy.at