Data protection

Revised November 29, 2022

I. Overview

If we would like to welcome you as a customer, interest or business partner, please read from point III.

If you visit our website, please read from point II.

II. What data do we process when you visit our website?

Welcome to our website! Please get an idea of ​​how we process your personal data when you visit our website (Article 13, Article 14 GDPR; Section 165 Paragraph 3 TKG).

When you visit our website, the following data may be processed:

    • browser type,
    • Operating system,
    • Country,
    • Date,
    • time and duration of access,
    • IP address * and pages visited on our website including entry and exit pages, contact page on website,
    • Contact page on website,
    • Device data: We may store personal data from your device. Such data includes geolocation data, IP address, unique identifiers (e.g. MAC address),
    • Data that you enter via a contact form,
    • Data in the course of sending the newsletter.

The processing of this data is necessary to ensure the security of the operation of the website and to ensure the functionality of the website from a technical point of view. This data is partly collected via technical cookies. These technical cookies are only used to the extent necessary (Section 165 Paragraph 3 TKG). The processing of this data is justified by our legitimate interest in operating our website (Article 6 (1) (f) GDPR).

In order to operate our website, it may be necessary for us to disclose your data to the following recipients:

  • Recipient data: Host Europe Limited
    • Purpose of data processing: website hosting
    • Legal basis for data processing: predominantly legitimate interest
    • (Article 6 Paragraph 1 Letter f GDPR)
    • Place of business: Germany
    • Basis for transfer to a third country**: Within the EU
  • Recipient data: MailChimp, Inc
    • Purpose of data processing: newsletter provider
    • Legal basis for data processing: Consent (Article 6 Paragraph 1 lit a GDPR)
    • Place of business: USA
    • Basis for transfer to third countries: standard data protection clauses in accordance with Art. 46 Para. 2 lit. c GDPR
  • Recipient data: Facebook (Instagram); (Meta, Inc)
    • Purpose of data processing: Social media provider
    • Legal basis for data processing: Consent (Article 6 Paragraph 1 lit a GDPR)
    • Place of business: USA
    • Basis for transfer to a third country: Art 49 Paragraph 1 lit a GDPR
  • Recipient data: Linkedin (Microsoft, Inc)
    • Purpose of data processing: Social media provider
    • Legal basis for data processing: Consent (Article 6 Paragraph 1 lit a GDPR)
    • Place of business: USA
    • Basis for transfer to a third country: Art 49 Paragraph 1 lit a GDPR
  • Recipient data: TikTok
    • Purpose of data processing: Social media provider
    • Legal basis for data processing: Consent (Article 6 Paragraph 1 lit a GDPR)
    • Place of business: China
    • Basis for transfer to a third country: Art 49 Paragraph 1 lit a GDPR
  • Recipient data: Alphabet, Inc (Google Analytics, Google Drive; Gmail)
    • Purpose of data processing: Statistical evaluation of the website and advertising; Document storage and collaborative work; Email provider
    • Legal basis for data processing: consent (Article 6 Paragraph 1 lit a GDPR); legitimate interest according to Art 6 Paragraph 1 lit f GDPR;
    • Place of business: USA
    • Basis for transfer to third countries: standard data protection clauses in accordance with Art. 46 Para. 2 lit. c GDPR

II.1. Overview of the “technical” cookies used

The above data is stored via so-called “cookies***”. Cookies are text files that are stored on your computer and enable the use of the website to be analyzed. They are used to recognize and store temporary data of homepage visitors. We generally only use cookies to the extent necessary to communicate with you via the homepage.

These technical cookies are activated as soon as you visit our homepage.

The following cookies are used on our platform based on our predominantly legitimate interest (Article 6 (1) (f) GDPR):

  • Cookie name:_cf_bm
    • Purpose of the cookie: This cookie is used to distinguish between humans and bots.
    • Duration of storage: 1 day
    • Cookie name: embed/v3/counters.gif
      • Purpose of the cookie: Used to implement forms into the website.
      • Duration of storage: session

      II.2. Overview of the “advertising cookies” used

      In addition to the “technical cookies” described above, we also use so-called advertising cookies (including “statistical cookies”). These advertising cookies make it possible to better understand and evaluate your interests. Using advertising cookies, we can combine your “surfing behavior” with data from other websites across our website. This would enable us to better understand the interests of our homepage visitors and address them more specifically.

      We respect that not every website visitor wants this. Therefore, we only process your data in the context of advertising cookies if you agree to this (Article 6 Paragraph 1 lit a GDPR). You can revoke this consent at any time, although the data processing carried out up to the point of revocation remains justified.

      • Cookie name: _hssc
        • Purpose of the cookie: Statistical purposes
        • Duration of storage: 1 day
        • Recipient's country of residence: USA
        • How it works: Indicates whether the cookie data needs to be updated in the visitor's browser
      • Cookie name: _hssrc
        • Purpose of the cookie: Statistical purposes
        • Duration of storage: session
        • Recipient's country of residence: USA
        • How it works: Used to recognize the visitor's browser when returning to the website.
      • Cookie name: _hstc
        • Purpose of the cookie: Statistical purposes
        • Storage period: 179 days
        • Recipient's country of residence: USA
        • How it works: Sets a unique ID for the session. This allows the website to collect data about visitor behavior for statistical purposes.
      • Name of the cookie: hubspotuk
        • Purpose of the cookie: Statistical purposes
        • Storage period: 179 days
        • Recipient's country of residence: USA
        • How it works: Sets a unique ID for the session. This allows the website to collect data about visitor behavior for statistical purposes.
      • Cookie name: _ptg.gif
        • Purpose of the cookie: advertising purposes
        • Duration of storage: session
        • Recipient's country of residence: USA
      • Cookie name: _ga; (Google) – Google Analytics
        • Purpose of the cookie: Statistical purposes
        • Storage period: 399 days
        • Recipient's country of residence: USA
        • How it works: Registers a unique ID that is used to create statistical data about website usage.
      • Cookie name: _ga_# (Google) – Google Analytics
        • Purpose of the cookie: Statistical purposes
        • Storage period: 399 days
        • Recipient's country of residence: USA
        • How it works: Collects data on how often a visitor is on the website.
      • Cookie name: _gid (Google)
        • Purpose of the cookie: Statistical purposes
        • Duration of storage: 1 day
        • Recipient's country of residence: USA
        • How it works: Registers a unique ID that is used to compile statistical data about visitors' use of the website.
      • Cookie name: _gat (Google)
        • Purpose of the cookie: Statistical purposes
        • Duration of storage: 1 day
        • Recipient's country of residence: USA
        • How it works: Certain data is only sent to Google Analytics a maximum of once per minute. The cookie has a lifespan of one minute. As long as it is set, certain data transfers are prevented.

      III. For what purposes do we process your data if you are a customer or have a business relationship with us?

      As part of our business relationship with customers and business partners, we process data based on contractual (processing of the contractual relationship with you, pre-contractual obligations, billing of services, sending of documents, communication to process the contract) and legal obligations (legally required storage within the meaning of Section 132 BAO ) (Article 6 Paragraph 1 lit b and c GDPR) as well as due to our legitimate interests or due to the legitimate interests of third parties (Article 6 Paragraph 1 lit f GDPR), namely:

        • for the purposes of internal administration and management of your business case to the extent necessary (e.g.: processing your business case, forwarding your business case to various departments, file storage, archiving purposes, correspondence with you);
        • for the purpose of delivering orders;
        • In case of due diligence (assessment by investors);
        • Assertion and defense of legal claims

      each to the extent required. The processing of your data serves to initiate, maintain and process our business relationships. If you do not provide us with this data, we will unfortunately not be able to process your business case.

      If necessary, we process your data based on your voluntary, express consent (Article 6 Paragraph 1 lit a GDPR).

      IV. How long is your data stored?

      We will only store your data for as long as necessary for the purposes for which we collected your data. In this context, legal retention obligations must be taken into account (for example, for tax reasons, contracts and other documents from our contractual relationship must generally be retained for a period of seven years (§ 132 BAO)). In justified individual cases, such as to assert and defend legal claims, we can also store your data for up to 30 years after the end of the business relationship. We store data from interested parties for up to one year from the time the interested party last contacted us.

      V. Who may receive your data?

      As part of our business relationship, it may be necessary for us to transmit your data to the following recipients:

      • Recipient: CP International Logistik GmbH
        • Purpose: Logistics and delivery company
        • Legal basis: legitimate interest
        • Country: Austria
      • Recipient: Insurance companies
        • Purpose: Insuring transport
        • Legal basis: Legal and contractual necessity
        • Country: Austria
      • Recipient: auditors and tax advisors
        • Purpose: tax advice
        • Legal basis: Contractual necessity
        • Country: Austria
        • Basis for transfer to third countries: Within the EEA
      • Recipient: Erste Bank
        • Purpose: payment processing
        • Legal basis: Contractual obligation
        • Country: Within the EEA
        • Basis for transfer to third countries: Within the EEA
      • Recipients: lawyers, courts, dispute resolution
        • Purpose: Pursuing and defending legal claims
        • Legal basis: Predominantly legitimate interests
        • Country: Austria
        • Basis for transfer to third countries: Within the EEA
      • Recipient: Online collaboration tools (Zoom, Microsoft Teams)
        • Purpose: Conducting online meetings
        • Legal basis: Predominantly legitimate interests
        • Country: USA
        • Basis for transfer to third countries: standard data protection clauses in accordance with Art. 46 Para. 2 lit. c GDPR
      • Recipients: Funding agencies
        • Purpose: Proof of financial management
        • Legal basis: Legal and contractual necessity
        • Country: Austria
        • Basis for transfer to third countries: Within the EU
      • Recipient: HubSpot, Inc.
        • Purpose: E-commerce platform; E-commerce
        • Legal basis: Predominantly legitimate interests
        • Country: USA
        • Basis for transfer to third countries: standard data protection clauses in accordance with Art. 46 Para. 2 lit. c GDPR
      • Recipient: Canva Pty Ltd.
        • Purpose: creation of designs, creative performances
        • Legal basis: Predominantly legitimate interests
        • Country: Australia
        • Basis for transfer to third countries: standard data protection clauses in accordance with Art. 46 Para. 2 lit. c GDPR

      VI. Collection of data from other sources (Article 14 GDPR)

      In the course of a business relationship or an initiation into one, it is naturally necessary to carry out research about the business partner. This only occurs to the extent necessary. In this context, data can be accessed and processed from the following sources:

      Our company does not obtain any data from third sources.

      VII. Does automated decision-making or profiling take place (Article 13 (2) (f) GDPR)?

      There is no automated decision-making or profiling in our company.

      VIII. What rights do you have regarding data processing?

      We would like to inform you that, provided the legal requirements are met:

        • You have the right to request information about which of your data is being processed by us (see Art 15 GDPR in detail).
        • You have the right to request the correction or completion of incorrect or incomplete data concerning you (see in detail Art 16 GDPR).
        • You have the right to have your data deleted (see Art 17 GDPR in detail).
        • You have the right to object to the processing of your data that is necessary to protect our legitimate interests or those of a third party (see Art 21 GDPR in detail). This applies in particular to the processing of your data for advertising purposes.
        • Have the right to receive the data you have provided to us in a structured, commonly used and machine-readable format.

      If we process your data based on your consent, you have the right to revoke this consent at any time by email. This does not affect the lawfulness of the data processing that has taken place up to this point (Article 7 Paragraph 3 GDPR).

      IX. What rights of complaint do you have?

      If, contrary to expectations, there is a violation of your right to lawful processing of your data, please contact us by post or email. We will endeavor to address your concerns promptly. However, you also have the right to lodge a complaint with the supervisory authority responsible for data protection matters.

      The address of the Austrian data protection authority is:

      Austrian data protection authority

      Barichgasse 40-42,

      1030 Vienna

      X. How can you contact us?

      If you have any further questions about the processing of your data, please feel free to contact our data protection coordinator using the contact details below.

      XI. responsible

      The person responsible within the meaning of Art 4 Z 7 GDPR is:

      Circularful GmbH

      Leystrasse 50, Top 23

      1200 Vienna

      Austria

      info@matr.eco

      +43 664 533 90 81

      ________________

      * An IP address is a number assigned to a device. This IP address allows devices to communicate over the Internet. Each IP address contains information about the Internet service provider used and the physical location of the device used. In this way, information about the user of the device can be obtained.

      ** “Third country” includes all states except (1) the member states of the European Union and (2) the member states of the European Economic Area, i.e. beyond the EU member states Iceland, Liechtenstein and Norway.

      ***You can prevent the storage of cookies by setting your browser software accordingly. However, we would like to point out that in this case you may not be able to fully use all of the functions of this homepage.

      __________________

      Author of this data protection declaration : Dr. Tobias Tretzmuller, LL.M. ; www.digital-recht.at

      Any use of this data protection declaration, or even parts of it, without the consent of the author constitutes a copyright infringement.

      Didn't find what you were looking for?

      Tell us what type of mattress or furniture you are looking for and we will do our best to find something for you.