Privacy Policy - Non-profit | NPO-Academy - USA

Privacy Policy

1. General information

Protecting your personal information is very important to us. We process your personal data exclusively pursuant to applicable law (GDPR, Austrian Data Protection Act (DSG), Austrian Telecommunications Act (TKG) 2003).

We process information about you, so-called personal data - or “data” for short in the following to be able to provide our website and in order to sell our products and provide our services. The term “processing” means any handling of data, such as the collection, storage, use, or deletion of personal data.

In this privacy policy, we inform you about the processing of your personal data and your rights arising from data protection laws.

The data controller responsible for the processing of your personal data is:

NPO-Academy Americas GmbH
Schoepfleuthnergasse 18
1210 Vienna
Austria, Europe

E-mail address: office.us@npo-academy.com
Telephone (USA): +1-202-600-9014

If you have any complaints, questions, or suggestions regarding data protection, please address them to the contact information provided above. We are happy to help!

Personal data or personally identifiable information can be changed by sending an e-mail to us (office.us@npo-academy.com) with your specific change inquiry, and we will verify your request.

 

2. Data processing on our website www.npo-academy.com/us

2.1. General information

As part of our website and online services, we process data that you make available to us (such as when placing an order), logs (for security reasons, our servers log from whom requests were initiated), and cookies (these are small text files that are stored on your device and contain information that allows us to recognize you).

To prevent other providers from placing cookies, you can block so-called “third-party cookies” in your browser. You can find instructions for the most common browsers here:

Firefox: here
Chrome: here
Microsoft Edge: here
Safari: in Apple’s Safari, third-party cookies are blocked by default.

You have the possibility to activate the “do not track” function in your browser settings, to avoid tracking by third-parties.

2.2. Data processing for the operation and security of our website www.npo-academy.com/us (server logs):

Purpose of processing: When you visit our website, the webserver collects usage data (so-called server logs). It is necessary to collect this data, so we can establish a connection to our server and enable the use of the website. This data is also used to ward off and analyze cyber-attacks.

The following server logs are collected: The hostname of the accessing computer together with the date, time of the request, identification data of the browser and the operating system used, as well as the “referrer” URL.

Legal grounds for processing: The processing of your personal data is based on our legitimate interest in ensuring our online services and system security.

In the event of a cyberattack, this server log data will be passed on to a law enforcement agency, and no other data transfer to third parties will take place.

Further information: Server logs are stored for no longer than 4 weeks.

2.3. Data processing for marketing purposes:

2.3.1. Web analytics

We use the following tool to process data about your use of our website to adapt it to your interests in the best possible way.

− Google Analytics, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

The purpose for processing: Google Analytics places cookies to recognize you on your next visit and to be able to generate personalized user statistics on website activity. We have also activated Google’s “anonymize IP” module. With this module, the IP address assigned to you is anonymized by Google within the European Union.

Google Analytics stores the following cookies on your device:

Name Duration Purpose
_ga 2 years Contains a randomly generated user ID. Based on this ID, Google Analytics can recognize returning users on this website and merge the data from previous visits.
_gid 24 hours Contains a randomly generated user ID. Based on this ID, Google Analytics can recognize returning users on this website and merge the data from previous visits.
_gat 1 minute Certain data is only sent to Google Analytics at a maximum of once per minute. The cookie has a lifetime of one minute. As long as it is set, certain data transmissions are prevented.
_gac_xxx 90 days This cookie is set when a user arrives at the website by clicking on a Google advertisement. It contains information about which advertisement was clicked on, so that results such as orders or contact requests can be assigned to the advertisement.
IDE 1 year Contains a randomly generated user ID. Google can recognize the user across different website domains and display personalized advertising using this ID.

 

Legal grounds for processing: The processing of your personal data is based on your consent. If you tick the box “accept all” on our cookie banner, you consent to us processing your data to the extent described here.

Data recipients: The information about your website activity generated by the cookie is usually transferred to a Google server in the US and stored there. The appropriate safeguards for transferring data result from standard contractual clauses under Article 46 GDPR. For more information on standard contractual clauses and appropriate or reasonable safeguards, please visit https://privacy.google.com/businesses/processorterms/…Google acts as a data processor for us and may only use the transmitted data to process the specific orders and is contractually obligated to comply with the legal requirements for data protection.

Further information: You may prevent cookies from being placed by configuring your browser accordingly; however, please note that in this case, your use of certain features or functions on our website may be limited. In addition, you can prevent Google from collecting data generated through cookies and relating to your use of the websites (including your anonymized IP address) and processing of this data by Google by downloading and installing the browser plug-in available from the following link: (https://tools.google.com/dlpage/gaoptout?hl=en).

2.4. Data processing for our social media activities:

We use so-called “social media plugins”. These enable us to show you interactive elements or content (e.g. text posts, graphics, images, and videos) from social media services. Via these plugins, data, including personal data, can be transmitted to the social media service providers and possibly used by them.

When you visit our website, a direct connection between your browser and the server of the social media service provider is only established via the social media plugins if you have consented to the transfer of the data.

We currently use social media plugins from the following services:

− YouTube: We use plugins from the YouTube service on our website. The plugins can display interactive elements or content (e.g. videos, graphics, or text contributions). Via these plugins, data can be sent to YouTube and possibly used by YouTube. Data is only transmitted to YouTube if you have consented to its use.

For further information on YouTube and the exact scope and purpose of data processing, please refer to Google's privacy policy at https://policies.google.com/privacy?hl=en. The responsible party for data processing is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

 

3. Data processing for our newsletter

The purpose for processing: If you sign up for our newsletter, you will regularly receive e-mails with information about us and our offered services. If you no longer wish for us to contact you, that’s not a problem! Simply inform us at office.us@npo-academy.com or use the unsubscribe link in the newsletter.

We process the following personal data: name, e-mail address

Legal grounds for processing: The processing of your personal data is based on your consent.

Recipients of the data: Your data will not be transferred to third parties that pursue their purposes.

Further information: We process your data until you revoke your consent.

 

4. Data processing in the context of business operations:

4.1. Data processing in the context of initiating contact:

The purpose for processing: When you initiate contact with us (e.g. by e-mail, contact form, or telephone), we process the personal data provided by you as part of the contact initiation only to the extent necessary for processing and handling your request.

We process following personal data: prefix, full name, address, zip code, country, e-mail address, phone number, time-zone, if you note it: degree, firm name, department.

Legal grounds for processing: your personal data is processed to conduct actions required to initiate or perform a contractual relationship or to perform a contractual relationship or is based on our legitimate interest, namely for preparing a reply to your request.

We transmit such data to third parties only in the event that such transmission is necessary for responding to your request.

Further information: We process your data for as long as this is necessary to process the request, and for another seven years following our final contact to be able to process your potential follow-up requests.

4.2. General data processing in the context of a customer order:

Purpose of processing: when you place an order with us, we process your data to process the order, answer questions that you ask us regarding your order, and to perform our contractual duties.

We process following personal data: full name, address, zip code, country, e-mail address, phone number, time-zone, if you note it: degree, firm name, department.

Legal basis for the processing: we will process your data to fulfill a contractual relationship or on a legal basis in the context of a business relationship (or to manage it).

Recipients of the data: We transfer data on a case-by-case basis to the following categories of recipients where required to perform our contractual duties, or if such transfer is required by applicable laws:

▪ Banks
▪ Legal representatives
▪ Chartered accountants, auditors, and tax consultants
▪ Courts
▪ Responsible administrative authorities
▪ Collection agencies
▪ External financiers
▪ Contract and business partners
▪ Contract and business partners in the USA
▪ Insurance providers

Further information: we only process your data for as long as is necessary to perform our contractual duties or to comply with applicable laws (for example, following the retention obligations under tax and corporate law). As a rule, we keep data for seven years.

Your data will also be transferred to our contractual and business partners in the United States to conduct seminars in the States. The transfer of this data is necessary to perform our contractual duties when seminars are ordered. Therefore, the legal grounds for the transfer of your data is to fulfill a contract between the person concerned and the responsible party at the request of the person concerned (Art 49 para. 1 lit b GDPR).

4.3. Data processing in the course of our provision of seminar services:

Purpose of the processing: once your user account is activated, we will process your data to be able to provide our services and to perform our contractual obligations.

We process following personal data: full name, address, zip code, country, e-mail address, phone number, time-zone, if you note it: degree, firm name, department.

Legal grounds for the processing: your personal data is processed to fulfill a contractual relationship.

Recipients of the data: We transfer data on a case-by-case basis to the following categories of recipients where required to perform our contractual duties, or if such transfer is required by applicable laws:

▪ Banks
▪ Legal representatives
▪ Chartered accountants, auditors, and tax consultants
▪ Courts
▪ Responsible administrative authorities
▪ Collection agencies
▪ External financiers
▪ Contract and business partners
▪ Contract and business partners in the USA
▪ Insurance providers

Further information: we only process your data for as long as is necessary to perform our contractual duties or to comply with applicable laws (for example, following the retention obligations under tax and corporate law). As a rule, we keep data for seven years.

To conduct seminars in the USA, your data will be transferred to our contractual and business partners in the USA to perform our contractual duties and to process your orders.

The transfer of your data is required to be able to perform our contractual obligations. Therefore, the legal grounds for the transfer of your data is to fulfill a contractual relationship between the person concerned and the responsible party at the request of the person concerned (Art 49 para. 1 lit b GDPR).

4.4. Data processing regarding events:

The purpose for processing: If you register for an event with us, we process your data to process the registration, organize and hold the event, answer questions that you ask us regarding your registration, and to perform our contractual duties.

We process following personal data: full name, address, zip code, country, e-mail address, phone number, time-zone, if you note it: degree, firm name, department.

Legal basis for the processing: we will process your data to be able to perform our contractual duties.

Further information: we only process your data for as long as is necessary to perform our contractual duties or to comply with applicable laws (for example, following the retention obligations under tax and corporate law). As a rule, we keep data for seven years.

 

5. Children

Our website does not provide services or sell products to children under the age of 18. In the event that we become aware that we have collected personal information from any child, we will dispose of that information in accordance with applicable laws and regulations where required. If you are a parent or guardian and you believe that your child under the age of 18 years old has provided us with information without your consent, please contact us at office.us@npo-academy.com and we will take reasonable steps to ensure that such information is deleted from our systems.

 

6. Your rights

6.1. Right to information on your personal data stored by us pursuant to Art. 15 GDPR

You have the right to request information whether we process your personal data. If we do, you have a right to information about the nature of this personal data and additional information related to the processing.

6.2. Right to rectification of incorrect data pursuant to Art. 16 GDPR

If your personal data that we process is not (or no longer) correct or complete, you may request its rectification and, if necessary, ask that it be completed.

6.3. Right to deletion pursuant to Art. 17 GDPR

If the statutory conditions are met, you may request the deletion of your personal data.

6.4. Right to restriction of data pursuant to Art. 18 GDPR

If the statutory conditions are met, you may request the restriction of the processing of your personal data.

6.5. Right to data portability pursuant to Art. 20 GDPR

If the statutory conditions are met, you may request that your data be transmitted to you in a structured, commonly used and machine-readable format.

6.6. Right to object to unreasonable data processing pursuant to Art. 21 GDPR

You may object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that we process based on a legitimate interest pursuant to Art. 6 para. 1(f) GDPR.

6.7. Right to revoke consent

If the processing is based on a declaration of consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of the processing carried out based on the consent before its withdrawal.

6.8. Right to submit a complaint to the data protection authority

If you believe that our processing of your personal data violates existing data protection law, or that your data protection rights were otherwise violated, you have the right to file a complaint with the competent authority (Austrian Data Protection Authority). The address is as follows:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna, Austria
Phone: +43 1 52 152-0
E-mail: dsb@dsb.gv.at

 

7. Further information:

The data that we ask you to provide is required to process the sale of our goods and to provide our services as part of a contractual obligations, to answer a request, or to send our newsletter or other information.

If you do not make the data available, we cannot perform these services.

There is no automated decision-making, including profiling. Should we process your personal data for a purpose other than that for which we collected the data, we will notify you of this fact and inform you of this other purpose.

This policy and your interaction with our website are the primary means by which we provide you with notice and choice regarding its collection and use of your personal information. We may modify this policy at any time. However, if we make changes to this policy, we will notify you either through an e-mail, and/or a prominent notice at our website, or as otherwise required or permitted by law.