Skip to main content
Kohn Consulting
Brands Retail Experience Contact
EN/DE

Legal

Privacy Policy

How we protect your data

This is the privacy policy of Kohn Consulting (hereinafter “we” or “us”). Data protection and data security are important to us. This policy explains which personal data we collect, why we process it and how it is used. You can view, save or print this policy at any time at www.kohn-consulting.at/privacy/.

1. Controller and scope

The controller within the meaning of the GDPR and applicable national data protection laws is:

Andreas Kohn
Zellergasse 3a
2301 Neu-Oberhausen
Austria

Email: andreas@kohn-consulting.at
Website: www.kohn-consulting.at

This privacy policy applies to the Kohn Consulting website at www.kohn-consulting.at (hereinafter the “Website”) and its associated subdomains.

2. Definition of personal data

“Personal data” means any information relating to you as an identified or identifiable natural person (hereinafter “you” or “data subject”), such as name, age, address, email address, IP address or telephone number. An identifiable natural person is one who can be identified directly or indirectly, in particular by reference to an identifier or to one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.

If information cannot be linked to you, or could be linked to you only with disproportionate effort, it is not considered personal data. We process personal data only where a valid legal basis applies.

3. External service providers and hosting

We use an external service provider to host our Website. Personal data may therefore be stored on the hosting provider’s servers. This may include metadata and communication data, IP addresses, Website access data and other information generated when the Website is used.

The legal basis for using the hosting provider is Art 6 para 1 lit f GDPR. Our legitimate interest lies in the reliable, direct and efficient provision of our Website.

Our hosting provider is:

Netlify, Inc.
101 2nd Street
San Francisco, CA 94105
United States

Netlify processes connection and usage data required to deliver and secure the Website. Where personal data is transferred to the United States or other countries outside the EEA, Netlify relies on recognised transfer mechanisms, including the EU-U.S. Data Privacy Framework and the European Commission’s standard contractual clauses.

Further information is available in the Netlify Privacy Statement and Netlify’s GDPR information.

4. Processing of data on our Website

4.1 Provision and use of the Website

When you visit our Website, your browser automatically transmits personal data to the server on which the Website is hosted. This data is stored temporarily.

The data processed may include your IP address, the date and time of access, the name and URL of the requested file, the referrer URL, the browser used, the operating system of your device and the name of your internet service provider.

We process this data to provide a reliable connection and enable secure, convenient use of the Website. The legal basis is our legitimate interest pursuant to Art 6 para 1 lit f GDPR.

Once the data is no longer required to display the Website, it is deleted unless continued storage is required by law. This processing is necessary for the Website to function; there is therefore no right to object to it.

4.2 Contacting us

Our Website provides links that allow you to contact us by email. When you select one of these links, your operating system’s email program may open automatically.

If you contact us, we process at least your name and email address as well as any additional personal data that you provide voluntarily. This may include your address, telephone number or information required to process a specific request.

The purpose of processing is to handle and respond to your request. Personal data provided in this context is not disclosed to third parties unless this is necessary to process the request or required by law.

Where you have expressly consented, processing is based on Art 6 para 1 lit a GDPR. Otherwise, it is based on our legitimate interest in handling enquiries efficiently and effectively pursuant to Art 6 para 1 lit f GDPR.

Once your enquiry has been conclusively processed, we delete the data disclosed in the course of correspondence unless further storage is required by law.

5. Disclosure of data to third parties

Personal data is disclosed to third parties only if at least one of the following circumstances applies:

  • Art 6 para 1 lit a GDPR: you have given your consent to the transfer.
  • Art 6 para 1 lit b GDPR: the transfer is necessary for the performance of a contract with you.
  • Art 6 para 1 lit c GDPR: there is a legal obligation to transfer the data.
  • Art 6 para 1 lit f GDPR: the transfer is necessary to protect legitimate business interests or to assert, exercise or defend legal claims, and there is no reason to assume that your legitimate interests in the non-disclosure of your data override those interests.

Apart from the transfers described in section 3, personal data is not transferred to third parties outside the European Union or the European Economic Area.

6. Cookies and local storage

The Website does not currently set its own cookies and does not use browser local storage for analytics, advertising or profiling. It can therefore be used without a cookie consent banner.

If services that require consent are added in the future, this privacy policy and the consent mechanism will be updated before those services are activated.

7. Tracking and analysis tools

The Website does not currently use web analytics, advertising pixels, cross-site tracking or comparable analysis tools. If such tools are introduced later, this privacy policy will be updated and consent will be obtained where legally required.

8. Hyperlinks

If our Website contains links to third-party websites, we are not responsible for the processing of your data on those websites. Information about such processing can be found in the respective privacy policies. You can recognise an external link by the change in the URL shown in your browser’s address bar.

9. Your rights as a data subject

The General Data Protection Regulation gives you the following rights:

  • Art 15 GDPR, access: You may request confirmation as to whether we process personal data relating to you and obtain information about the purposes, categories, recipients, duration, origin and existence of automated decision-making.
  • Art 16 GDPR, rectification: You may request that inaccurate personal data concerning you be corrected without undue delay and that incomplete data be completed.
  • Art 17 GDPR, erasure: You may request erasure where the data is no longer necessary, consent is withdrawn, you successfully object, processing is unlawful or erasure is legally required. This does not apply where processing remains necessary for freedom of expression and information, legal obligations, public health, archiving or research, or legal claims.
  • Art 18 GDPR, restriction: You may request restriction if you dispute the accuracy of the data, processing is unlawful, we no longer need the data but you require it for legal claims, or you have objected pending verification of overriding grounds.
  • Art 20 GDPR, portability: You may receive personal data you provided to us in a structured, commonly used and machine-readable format and transfer it to another controller where processing is based on consent or a contract and carried out by automated means.
  • Art 7 para 3 GDPR, withdrawal: You may withdraw consent at any time using the contact details above. Processing based on that consent can no longer continue after withdrawal.
  • Art 77 GDPR, complaint: You may lodge a complaint with a supervisory authority. In Austria, the competent authority is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.

10. Your right to object

Where processing of your personal data is based on Art 6 para 1 lit f GDPR, you have the right to object pursuant to Art 21 GDPR on grounds relating to your particular situation. You also have an unconditional right to object to processing for direct marketing purposes.

11. Data security and security measures

We treat your personal data confidentially. We regularly review and improve our technical security measures to maintain a consistently high level of data protection and help prevent the loss or manipulation of processed data.

Data published or disclosed on the internet without encryption can be viewed by third parties. We cannot prevent this or influence third parties who do not observe data protection rules. Any data you provide should therefore also be protected by encryption or other suitable measures where appropriate.

© Kohn Consulting
Home LinkedIn Impressum Privacy Policy