Collection and processing of personal data

Data Protection at ista

The protection of your personal data is very important to ista.

ista complies with the legal data protection regulations and does everything to keep your and your customer’s/tenant‘s data confidential. All personal data is collected, processed and used in accordance with the provisions of the General Data Protection Regulation (GDPR) and only for the purposes of contract processing, fulfilment of legal obligations or for safeguarding our own legitimate business interests with regard to the advice and support of the customers as well as the demand-oriented product design.

All service providers of ista dealing with the processing of personal data also comply with the provisions of the GDPR in accordance with Art. 28 GDPR. Compliance is monitored by our data protection officer.

Collection and processing of personal data

Each time a user accesses the ista website and each time a file is accessed, data about that activity is stored in a log file. This data is not related to a person; so ista cannot trace back which user has retrieved what data.

In detail, the following data record is saved for each call:

• Name of the file

• Date and time of access

• Amount of data transferred

• Message whether the call was successful

• Anonymous IP-Address

• If necessary, operating system and browser software on your computer

• As well as the website from which you visited the ista website

Personal user profiles cannot be created.

The above-mentioned data is evaluated for statistical purposes only.

Personal data will only be collected if you give it to ista on your own - for example, when registering for a survey or conducting a contract. A transmission of your data to third parties does not take place, unless ista is legally obliged to do so. Insofar as external service providers come into contact with your personal data, ista has ensured that they comply with the provisions of data protection laws through legal, technical and organizational measures as well as regular checks.

Cookies:

ista uses so-called cookies on the ista website to recognize multiple use of the offer by the same user/internet connection owner. Cookies are small text files that your internet browser stores on your computer. They serve to optimize ista's internet presence and offers. The cookies are usually so-called "session cookies", which are deleted after the end of your visit.

In some cases, however, these cookies provide information in order to automatically recognize you. This recognition is based on the IP address stored in the cookies. The information obtained in this way serves to optimize ista's offers and to make it easier for you to access the ista website.

You may refuse the use of cookies by selecting the appropriate settings in your browser; however, ista points out that in this case you may not be able to use the full functionality of the ista website.

Google Tag Manager

Google Tag Manager is a solution that we can use to manage “website tags” using an interface (allowing us, for example, to incorporate Google Analytics and other Google marketing services into our online offering). The tag manager itself (which implements the tags) does not process any personal data relating to users. With regard to the processing of users' personal data, we refer users to the following information on the Google services. Use policy:  https://www.google.com/intl/de/tagmanager/use-policy.html

Usercentrics

Use of the Usercentrics Consent Management Platform
We use the Usercentrics Consent Management Platform to comply with the statutory provision pursuant to Article 7, para. 1 GDPR. The operator is Usercentrics GmbH, Rosental 4, 80331 Munich. The Usercentrics Consent Management Platform collects Logfile data, user agent (device, browser type, browser language, browser version, resolution) and consent data (consent yes/no, timestamp, data extent, data attributes, ControllerID, ProcessorID, consentID) by means of a Javascript. This JavaScript permits Usercentrics GmbH to inform the user about specific tags and web technologies on our website and to obtain, manage and document the user's consent. The legal basis for data processing is Article 6, para. 1, letter c) GDPR since we are legally obliged to prove consent (pursuant to Article 7, para 1 GDPR). Our aim is to know and implement our users' preferences as well as to document these legally in a secure manner. The data are deleted as soon as they are no longer required for our documentation and there are no legal obligations to retain records.

You can permanently disable the execution of JavaScript at any time by selecting the relevant settings in your browser, which would also prevent Usercentrics from executing JavaScript.

For further details on Usercentrics data protection policy go to: https://usercentrics.com/privacy-policy/

 

You can select your privacy settings here:
 

Web Analytics

Zenloop

Service description

This is a B2B Software-as-a-Service platform. With this service, the user can collect and analyze customer feedback.

 

Processing company

zenloop GmbH

Pappelallee 78-79, 10437 Berlin, Germany

 

Data protection officer of the processing company

Please find below the e-mail address of the data protection officer of the processing company.

dpo@zenloop.com

 

Purposes of data processing

This list shows the purposes for which we collect and process data.

- Surveys

- Analysis

 

Technologies used

This list shows all the technologies used by this service to collect data. Typical technologies are cookies and pixels that are placed in the browser.

- Cookies

 

Collected data

This list contains all (personal) data collected during or via use of the service.

- Device information

- Browser information

- Referrer URL

- e-mail address

- Usage data

- IP address

- Survey responses

 

Legal basis

Below you will find the legal basis required for data processing.

- Art. 6 al. 1 lit. a RGPD

 

Place of processing

This is the main location where the data collected is processed. If the data is also processed in other countries, you will be informed separately.

- European Union

 

 

 

 

Retention period

The retention period is the period during which the data collected is stored for processing. Data must be deleted as soon as it is no longer required for the specified processing purposes.

- Data will be deleted as soon as it is no longer required for processing purposes.

 

Transfer to third countries

This service may transfer the data collected to another country. Please note that this service may transfer data to a country that does not have the required data protection standards. Below is a list of countries to which data may be transferred. To find out more about guarantees, please consult the supplier's privacy policy or contact them directly.

- United States of America

 

Recipients of data

The following lists the recipients of the data collected.

- Salesforce.com Inc.

- zenloop GmbH

- Amazon Web Services, Inc.

- Elasticsearch B.V.

 

Click here to read the data processor's privacy policy

www.zenloop.com/en/legal/privacy

 

 

Qualtrics

Processing company
Qualtrics LLC

333 W. River Park Drive

Provo, UT 84604, United States of America
 

Data processing purposes

This list shows the purposes of data collection and processing.

- Surveys

- Analysis
 

Technologies used

- Cookies and similar technologies
 

Data collected

This list contains all (personal) data collected during or through the use of the service.

- IP address

- Device information

- Browser information

- Referrer URL

- Responses to surveys

- Email address

- Usage data

 

Legal basis

The following is the required legal basis for the processing of data

- Art. 6 para. 1 s. 1 lit. a GDPR


Place of processing

European Union and United States of America
 

Retention period

The retention period is the period of time during which the collected data is stored for processing. The data must be deleted as soon as it is no longer required for the specified processing purposes.

The data is deleted as soon as it is no longer required for processing.

 

Data recipient

- Qualtrics LLC

- Salesforce.com Inc.

- Amazon Web Services, Inc.

- Elasticsearch B.V.
 

Data protection officer of the processing company

Below you will find the e-mail address of the data protection officer of the processing company.

privacy@qualtrics.com  

Sleeknote

Description of Service

This is a notification tool for websites. With this tool websites can provide on-site messages without pop-ups.

 

Processing Company

Sleeknote ApS
Jens Baggesens Vej 90A, 8200 Aarhus, Denmark

 

Data Protection Officer of Processing Company

Below you can find the email address of the data protection officer of the processing company.

mail@sleeknote.com

 

Data Purposes

This list represents the purposes of the data collection and processing.

  • Functionality
  • Analytics

 

Technologies Used

This list represents all technologies this service uses to collect data. Typical technologies are Cookies and Pixels that are placed in the browser.

  • Cookies
  • Log files

 

Data Collected

This list represents all (personal) data that is collected by or through the use of this service.

  • IP Address
  • Browser information
  • Browser language
  • Date and time of visit
  • Message text
  • Statistical information

 

Legal Basis

In the following the required legal basis for the processing of data is listed.

  • Art. 6 para. 1 s. 1 lit. f GDPR

 

Location of Processing

This is the primary location where the collected data is being processed. If the data is also processed in other countries, you are informed separately.

  • European Union

 

Retention Period

The retention period is the time span the collected data is saved for the processing purposes. The data needs to be deleted as soon as it is no longer needed for the stated processing purposes.

  • The data will be deleted as soon as they are no longer needed for the processing purposes

 

Data Recipients

In the following the recipients of the data collected are listed.

  • Sleeknote ApS

 

Click here to read the privacy policy of the data processor

https://sleeknote.com/privacy-policy

Piwik PRO Analytics Suite

We use the analysis software Piwik PRO Analytics Suite (piwikpro.de) to analyse and optimise this website. The data collected with this software can be used to create user profiles under a pseudonym. 

Data processing purposes

This list contains the purposes for which data are collected and processed. Consent is valid only for the purposes specified. The data collected cannot be used or stored for purposes other than those listed below. 

  • Analysis
  • Optimisation

Technologies used

  • Cookies

Data collected

This list contains all (personal) data that are collected during or through the use of the service.

  • Anonymised shortened IP address
  • Usage data
  • User ID
  • Date and time of the visit
  • Referrer URL
  • Websites visited
  • Screen resolution
  • Geographic location
  • User agent
  • Visitor ID

Legal basis

The required legal basis for the processing of data is listed in the following:

  • Art. 6, para. 1 s. 1 lit. a GDPR

Location of processing

  • European Union

Retention period

The retention period is the period of time during which the data collected are stored for processing. The data must be deleted as soon as they are no longer needed for the stated processing purposes. The data are stored for up to 25 months.

Data recipient

  • Piwik PRO Sp. z o.o.
  • Piwik PRO GmbH

Data protection officer of the processing company

Below you will find the email address of the data protection officer of the processing company.

gdpr@piwik.pro

Consent to the collection and storage of data can be withdrawn at any time with immediate future effect.

Click here to read the privacy policy of the data processor https://piwik.pro/privacy-policy/

Click here to withdraw consent on all domains of the data processing company https://piwik.pro/opt-out/

Google Analytics

This is a web analytics service. With this, the user can measure the advertising return on investment "ROI" as well as track user behavior with flash, video, websites and applications.

Processing Company

Google Ireland Limited

Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

Data Purposes

This list represents the purposes of the data collection and processing.

  • Marketing
  • Analytics

Technologies Used

  • Cookies
  • Pixel
  • JavaScript
  • Device fingerprinting

Data Collected

This list represents all (personal) data that is collected by or through the use of this service.

  • Click path
  • Date and time of visit
  • Device information
  • Location information
  • IP address
  • Pages visited
  • Referrer URL
  • Browser information
  • Hostname
  • Browser language
  • Browser type
  • Screen resolution
  • Device operating system
  • Interaction data
  • User behaviour
  • Visited URL

Legal Basis

In the following the required legal basis for the processing of data is listed.

  • Art. 6 para. 1 s. 1 lit. a GDPR

Location of Processing

European Union

Retention Period

The retention period is the time span the collected data is saved for the processing purposes. The data needs to be deleted as soon as it is no longer needed for the stated processing purposes.

The Retention Period depends on the type of the saved data. Each client can choose how long Google Analytics retains data before automatically deleting it.

Data Recipients

  • Google Ireland Limited, Alphabet Inc., Google LLC

Data Protection Officer of Processing Company

Below you can find the email address of the data protection officer of the processing company.

https://support.google.com/policies/contact/general_privacy_form

Transfer to Third Countries

This service may forward the collected data to a different country. Please note that this service might transfer the data to a country without the required data protection standards. If the data is transferred to the USA, there is a risk that your data can be processed by US authorities, for control and surveillance measures, possibly without legal remedies. Below you can find a list of countries to which the data is being transferred. For more information regarding safeguards please refer to the website provider’s privacy policy or contact the website provider directly.

United States of America,Singapore,Chile,Taiwan

Click here to read the privacy policy of the data processor https://policies.google.com/privacy?hl=en

Click here to opt out from this processor across all domains https://tools.google.com/dlpage/gaoptout?hl=de

Click here to read the cookie policy of the data processor https://policies.google.com/technologies/cookies?hl=en

Storage Information

Below you can see the longest potential duration for storage on a device, as set when using the cookie method of storage and if there are any other methods used.

  • Maximum age of cookie storage: 2 years

 

Google Ads

This is an advertising service.

Processing Company

Google Ireland Limited

Google Building Gordon House, 4 Barrow Street, Dublin D04 E5W5, Ireland

Data Purposes

This list represents the purposes of the data collection and processing.

  • Advertisement
  • Analytics
  • Providing Service
  • Statistics

Technologies Used

  • Cookies

Data Collected

This list represents all (personal) data that is collected by or through the use of this service.

  • Ads viewed
  • Cookie ID
  • Date and time of visit
  • Device information
  • Geographic location
  • IP address
  • Search terms
  • Ads shown
  • Client ID
  • Impressions
  • Online identifiers
  • Browser information

Legal Basis

In the following the required legal basis for the processing of data is listed.

  • Art. 6 para. 1 s. 1 lit. a GDPR

Location of Processing

European Union

Retention Period

The retention period is the time span the collected data is saved for the processing purposes. The data needs to be deleted as soon as it is no longer needed for the stated processing purposes.

The data will be deleted as soon as they are no longer needed for the processing purposes. Log data is anonymized after 9 months and cookie information is anonymized after 18 months.

Data Recipients

  • Alphabet Inc., Google LLC, Google Ireland Limited

Data Protection Officer of Processing Company

Below you can find the email address of the data protection officer of the processing company.

https://support.google.com/policies/troubleshooter/7575787?hl=en

Transfer to Third Countries

This service may forward the collected data to a different country. Please note that this service might transfer the data to a country without the required data protection standards. If the data is transferred to the USA, there is a risk that your data can be processed by US authorities, for control and surveillance measures, possibly without legal remedies. Below you can find a list of countries to which the data is being transferred. For more information regarding safeguards please refer to the website provider’s privacy policy or contact the website provider directly.

Chile,Singapore,United States of America,Taiwan

Click here to read the privacy policy of the data processor https://policies.google.com/privacy?hl=en

Click here to opt out from this processor across all domains https://safety.google/privacy/privacy-controls/

Click here to read the cookie policy of the data processor https://policies.google.com/technologies/cookies?hl=en

Storage Information

Below you can see the longest potential duration for storage on a device, as set when using the cookie method of storage and if there are any other methods used.

  • Maximum age of cookie storage: 1 year

Remarketing activities and cookies

This website uses the remarketing or "similar target group" function of Google Inc. (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; „Google“).

This feature allows you to view interest-based ads on Google Display Network web pages. For this purpose, a cookie is stored in your browser when you visit a website. This serves to recognize you as a visitor to the website and to determine visits and usage data.

According to Google's own information, server logs are stored in which parts of the IP address and cookie information are partially deleted after 9 to 18 months. For more information, please visit http://www.google.com/policies/technologies/ads/.

An example of a server log is provided by Google at the following link:

https://policies.google.com/privacy/key-terms?hl=gb#toc-terms-server-logs

There are several ways in which cookies can be deactivated in the browser to exclude your own browser from remarketing.

Google provides the option of downloading a browser plug-in that permanently deactivates these cookies under the following link: https://www.google.com/settings/ads/plugin

You can also make settings in your browser to deactivate the installation of cookies.

If you wish to object to tracking, you can do so by adjusting your browser settings regarding cookie installations. You can find information on this under the following links:

Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences

Internet Explorer: https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies

Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en-GB

Safari: https://support.apple.com/en-gb/HT201265 

Third-party providers may also disable browser cookies. The Network Advertising Initiative (NAI) offers the possibility to implement an opt-out for your own browser. Information can be found on the following page: optout.networkadvertising.org.

This website uses the conversion tracking of "Google-Adwords", a Google service.

When you visit Google pages, Google stores cookies. You can deactivate or leave this storage activated. If the cookie is still activated and you visit certain websites on the website, Google and ista can recognize that you have clicked on an ad placed by ista and have thus been forwarded to an ista page.

The information collected is used by Google to generate statistics for Adwords customers. These statistics include information about the number of users who clicked on ads and were redirected to pages that were tagged with a conversion tracking tag.

You can find Google's privacy policy here: https://policies.google.com/privacy

Rights of data subjects

In accordance with the GDPR, ista takes appropriate measures to provide the data subject with all information and communications relating to processing in a precise, transparent, comprehensible and easily accessible form in clear and simple language. The information shall be transmitted in writing or in any other form, including, where appropriate, electronically.

Since ista processes personal data automatically, ista informs you of the following information in accordance with Art. 13 GDPR:

Anna Cole, ista Energy Solutions Limited, The Officers‘ Mess, Royston Road, Duxford, CB22 4QH, is the person responsible for ista.

The contact details of ista's data protection officer are:

ista Energy Solutions Limited, Data Protection Officer, The Officers‘ Mess, Royston Road, Duxford, CB22 4QH, e-mail: dpo@ista-uk.com

The purpose for which the personal data is to be processed and the legal basis for the processing are as follows: Optimization of customer satisfaction and the website, Art. 6 paragraph 1 f GDPR.

The legitimate interest in this is to be seen in particular in the pseudonymized processing for the optimisation of the website.

Data deletion and duration of storage

The personal data of the data subjects will be deleted or blocked as soon as the purpose of storage ceases to apply. Furthermore, data may be stored if this has been provided for the European or national legislator in EU regulations, laws or other provisions to which the person responsible is subject. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfilment of a contract.

Newsletter

ista offers you the option to subscribe to a newsletter on the ista webpage. From this newsletter you will receive information on ista topics and offers at regular intervals. To receive this newsletter, you need a valid e-mail address. Your entered e-mail address will be checked by ista for accuracy and completeness. Your login data as well as your official IP address, date and time will be stored. This serves as security to prevent your e-mail address from being misused by unauthorized third parties. No other data will be stored by ista. The data collected will only be used for the newsletter dispatch. ista undertakes not to transmit the data collected to other third parties. You have the option of cancelling the newsletter at any time without giving reasons and requesting information from the ista site. The details are marked in each newsletter.

Rights of data subjects

In accordance with the GDPR, ista takes appropriate measures to provide the data subject with all information and communications relating to data processing in a precise, transparent, understandable and easily accessible form in clear and simple language. The information shall be transmitted in writing or in any other form, including, where appropriate, electronically.

Social Media / Social Bookmarks

Social bookmarks from LinkedIn, Twitter and YouTube are integrated on the ista website. Social Bookmarks are internet bookmarks that allow users of such services to collect links and news messages. These are only included on the website as a link to the corresponding services. After clicking on the integrated graphic you will be forwarded to the page of the respective provider, i.e. only then will user information be transferred to the respective provider. For information on the handling of your personal data when using these websites, please refer to the respective data protection regulations of the providers.

Important Notice: This data protection information applies exclusively to ista's internet service offering. The ista website contains links to other websites. Please note that ista is not responsible for the data protection or the content of these other internet services. We recommend all internet users to inform themselves about the respective data protection notices of other internet services when leaving ista's website.

Changes to this data protection information

ista reserves the right to amend this disclosures at any time in compliance with the applicable data protection regulations; current status is May 2018.

If you have any questions regarding the processing or security of your personal data, you can contact ista’s data protection officer directly.