Privacy Notice

Information under Articles 13 and 14 of the General Data Protection Regulation

1. Preamble and provision of privacy information

The protection of personal data is a matter of particular importance to red tax Steuerberatung GmbH. We process personal data exclusively in accordance with the applicable data protection and professional rules, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (Datenschutzgesetz, DSG) and the Austrian Public Accountants and Tax Advisers Act 2017 (Wirtschaftstreuhandberufsgesetz 2017, WTBG 2017). This Privacy Notice explains which personal data we process in the course of our professional activities, business relationships and online presence, the purposes and legal bases of the processing, the parties to whom data may be disclosed, how long data is retained and the rights available to data subjects.

Where personal data is collected directly from a data subject, we generally provide the information required under Article 13 GDPR at the time the data is collected. This information may be provided in several layers. Essential information is provided directly in the relevant collection context; supplementary information may be provided by means of an easily accessible reference to this Privacy Notice.

Where personal data is not collected directly from the data subject, information is provided in accordance with Article 14 GDPR and the exceptions set out in that Article. Further details are provided in section 8. Terms referring to persons apply to all genders.

2. Controller

Controller

red tax Steuerberatung GmbH

Address

Museumstrasse 3b/16, 1070 Vienna, Austria

Commercial Register Number

FN 611698 g

Commercial Register Court

Commercial Court of Vienna

VAT Identification Number

ATU79838712

Telephone

+43 676 9498505

Website

https://www.red-tax.at/

3. Data protection role as a tax advisory firm

red tax Steuerberatung GmbH provides professional services under the WTBG 2017 and the professional rules applicable to public accountants and tax advisers, acting independently and on its own professional responsibility.

When processing personal data in connection with professional services, in particular tax advice, bookkeeping, accounting, payroll services, the preparation of annual financial statements and representation before tax authorities and other bodies, red tax Steuerberatung GmbH generally acts as an independent controller within the meaning of the GDPR.

In individual cases outside the professional activities that must be performed independently, where personal data is processed solely on the documented instructions of a client and the requirements of Article 28 GDPR are met, we may act as a processor. Where necessary, this allocation of roles is governed by a separate agreement. Irrespective of the respective data protection role, red tax Steuerberatung GmbH and the persons working for it are subject to the statutory duty of confidentiality under section 80 WTBG 2017.

  1. Definitions

The following explanations are intended to make this Privacy Notice easier to understand. The statutory definitions, in particular those in Article 4 GDPR, remain authoritative.

Personal data:

Any information relating to an identified or identifiable natural person.

Data subject:

 Any identified or identifiable natural person whose personal data is processed.

Processing:

Any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure or destruction.

Controller:

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing.

Processor:

A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Recipient:

A natural or legal person, public authority, agency or other body to which personal data is disclosed.

Special categories of personal data:

Data within the meaning of Article 9(1) GDPR, in particular data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health and data concerning a person's sex life or sexual orientation.

Data concerning health: 

Personal data relating to the physical or mental health of a natural person which reveals information about that person's health status.

Consent:

Any freely given, specific, informed and unambiguous indication of a data subject's wishes by which the data subject, through a statement or clear affirmative action, signifies agreement to the processing in question.

Client:

A natural or legal person, partnership or other legal entity with whom a contractual or professional engagement exists or is being considered.

Persons connected with a client engagement: 

Natural persons whose personal data is processed in connection with advice, representation or other services provided to a client, including employees, managing directors, shareholders, beneficial owners, relatives, business partners, customers, suppliers and other contact persons.

5. Categories of data subjects

• Clients, former clients and prospective clients;

• managing directors, board members, shareholders, beneficial owners and other officers of clients;

• employees, former employees, job applicants and other personnel of our clients;

• relatives, co-insured persons and dependants;

• customers, suppliers, debtors, creditors and other business partners of our clients;

• contact persons and employees of business partners;

• lawyers, notaries, auditors, banks, insurers and other professional advisers;

• representatives of public authorities and other parties to proceedings;

• suppliers, service providers, job applicants and other business contacts of red tax Steuerberatung GmbH;

• visitors to and users of our website and other persons who communicate with us.

6. Categories of personal data

Depending on the relevant engagement and purpose of processing, we may process the following personal data in particular:

• master and identification data, in particular name, title, date and place of birth, nationality, gender and, where applicable, a photograph;

• address and contact details, in particular residential or business address, telephone number and email address;

• company and business data, in particular company name, legal form, commercial register number, trade licence details, VAT identification number, tax number and other official identification numbers;

• data relating to corporate offices, shareholdings, powers of representation and beneficial ownership;

• identity verification data, in particular identity document details and copies of identity documents;

• social security numbers and social security data;

• bank, payment and account details;

• asset, income and financial data;

• bookkeeping, invoice, supporting-document, balance-sheet and other accounting data;• tax and levy data;

• data relating to claims, liabilities, reminders, enforcement proceedings and other legal relationships;

• contract, service and engagement data;

• personnel, employment, working-time, remuneration and payroll data;

• insurance and pension data;

• correspondence, notes of conversations, documents and other content data;

• data from administrative and court proceedings;

• technical usage and access data relating to the website and IT systems, in particular IP address, time of access, browser and device information and server log data;

• records of consent, withdrawal and objection;

• other personal data lawfully collected or provided in connection with an engagement or business relationship.

7. Special categories of personal data and data relating to offences

In the course of our professional activities, we may process special categories of personal data within the meaning of Article 9 GDPR where this is necessary for the relevant service.

This applies in particular to health data connected with payroll services, for example information concerning sick leave, continued remuneration, disabilities or other matters relevant to employment, social security or tax law. In individual cases, other special categories of personal data may also be processed, such as information revealing trade union membership or religious or philosophical beliefs.

Documents containing special categories of personal data may also be provided or made available to us in connection with tax and social security advice or representation before authorities, courts or other public bodies.

We process such data only where this is necessary for the relevant activity and permitted under Article 9(2) GDPR, in particular for compliance with obligations under employment or social protection law, for the establishment, exercise or defence of legal claims or on the basis of other applicable statutory provisions.

In individual cases, our activities may also involve the processing of personal data relating to acts or omissions punishable by a court or administrative authority, suspected offences, criminal convictions or related security measures. This may arise in particular in connection with financial criminal or administrative penal proceedings, administrative or court proceedings and statutory due diligence obligations, especially those relating to the prevention of money laundering and terrorist financing.

Such data is processed only where permitted under Article 10 GDPR in conjunction with the relevant Austrian legislation, in particular section 4(3) DSG, and where necessary for the relevant activity.

8. Sources of personal data and information under Article 14 GDPR

We obtain personal data in particular:

• directly from the data subject;

• from our clients and their officers, employees or other representatives;

• from former tax advisers or other advisers, where the relevant transfer is lawful;

• from banks, insurers, public authorities, courts or social security institutions;

• through FinanzOnline, the Austrian Business Service Portal, ELDA and other electronic systems provided for by law;

• from public registers and directories, in particular the Austrian Commercial Register, Land Register, Austrian Business Licence Information System and Register of Beneficial Owners;

• from other publicly accessible sources.

Where personal data is not collected directly from the data subject, we generally provide the information required under Article 14 GDPR within a reasonable period and no later than one month after obtaining the data. Where the data is used to communicate with the data subject, the information is provided no later than at the time of the first communication. Where disclosure to another recipient is envisaged, the information is provided no later than at the time of the first disclosure.

The information obligation does not apply to the extent that an exception under Article 14(5) GDPR applies. This may be the case in particular where the data subject already has the information or where personal data must remain confidential pursuant to a statutory duty of professional secrecy, notably under Article 14(5)(d) GDPR in conjunction with section 80 WTBG 2017.

9. Relevant legal bases and purposes of processing

We process personal data only where the relevant processing operation has a legal basis under the GDPR or other applicable legislation. The applicable legal basis is stated below for each specific purpose of processing.

Where special categories of personal data within the meaning of Article 9(1) GDPR are processed, processing takes place only if an additional legal basis under Article 9(2) GDPR applies. Personal data relating to offences or criminal convictions is processed only in compliance with Article 10 GDPR and the supplementary Austrian provisions.

Relevant legislation may also include the DSG, WTBG 2017, Austrian Federal Fiscal Code (Bundesabgabenordnung, BAO), Austrian Commercial Code (Unternehmensgesetzbuch, UGB), Austrian Value Added Tax Act 1994 (Umsatzsteuergesetz 1994, UStG 1994), provisions of employment and social security law and the Austrian Telecommunications Act 2021 (Telekommunikationsgesetz 2021, TKG 2021). The professional duty of confidentiality under section 80 WTBG 2017 is taken into account in all processing operations.

9.1 Initiating and accepting client engagements

We process personal data to deal with enquiries, communicate with prospective clients, prepare proposals, assess whether we can accept an engagement, carry out necessary conflict-of-interest and independence checks and comply with statutory identification and due diligence obligations:

• under Article 6(1)(b) GDPR, where the data subject is the prospective contracting party and processing is necessary to take steps at that person's request before entering into a contract;

• under Article 6(1)(c) GDPR, where statutory identification, verification or documentation obligations apply, for example anti-money-laundering obligations under the WTBG 2017;

• under Article 6(1)(f) GDPR for data relating to officers, contact persons or other persons connected with a prospective client. Our legitimate interest lies in properly assessing, initiating and conducting a business relationship and avoiding conflicts of interest.

9.2 Provision of tax advisory and professional services

We process personal data in particular to provide tax and business advice, represent clients before tax and other authorities, prepare and file tax returns, maintain financial and fixed-asset accounts, prepare annual financial statements and other accounting documents, provide personnel and payroll services, make social security filings, prepare analyses, notifications, declarations and reports and carry out other activities within the scope of the WTBG 2017:

• under Article 6(1)(b) GDPR, where an individual client is the contracting party and processing is necessary for the performance of the contract;

• under Article 6(1)(c) GDPR, where processing is necessary to comply with statutory obligations under tax, company, social security, anti-money-laundering or professional law;

• under Article 6(1)(f) GDPR for personal data relating to a client's officers, employees, customers, suppliers, shareholders or other persons, where processing is necessary for the proper provision of the commissioned professional service. Our legitimate interest lies in the proper and efficient performance of the engagement and the related representation and documentation activities.

9.3 Compliance with anti money laundering obligations

As a professional practice subject to the WTBG 2017, we have statutory obligations to prevent money laundering and terrorist financing. For this purpose, we process in particular identification data, identity document data, information on powers of representation and beneficial ownership and information required to assess the risk of a business relationship.

The legal basis is Article 6(1)(c) GDPR in conjunction with sections 87 et seq WTBG 2017, including the applicable due diligence, verification, documentation and reporting obligations. Where required by law, data may be transferred to the competent authorities and reporting bodies.

9.4 Statutory and professional obligations

Personal data is processed to the extent necessary to comply with statutory obligations to which we are subject as a tax advisory firm. These include, in particular, obligations under the WTBG 2017, BAO, UGB, tax legislation, social security law, employment and payroll tax law and the rules on preventing money laundering and terrorist financing. The legal basis is Article 6(1)(c) GDPR in conjunction with the applicable statutory obligation.

9.5 Practice management documentation and quality assurance

We process personal data to manage and organise our practice, document our activities, carry out internal administration and quality assurance and ensure that our services are provided properly and securely.

Where processing is not already necessary for the performance of a contract or compliance with a statutory obligation, it is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the proper, secure and efficient operation of our practice, the traceability of professional activities, quality assurance and IT and information security.

9.6 Fee billing and receivables management

We process personal data to prepare and send fee invoices, record and monitor payments, issue reminders in respect of outstanding amounts and establish, exercise or defend legal claims.

• Article 6(1)(b) GDPR for contract-related billing to individual clients;

• Article 6(1)(c) GDPR where statutory invoicing, recording or retention obligations apply;

• Article 6(1)(f) GDPR for receivables management and legal enforcement. Our legitimate interest lies in enforcing and securing legitimate fee claims and defending legal claims.

9.7 Communications and contact management

If you contact us by telephone, email or any other means, we process the data you provide in order to handle and respond to your enquiry and for further communications.

• Article 6(1)(b) GDPR where the communication serves to initiate or perform a contract with the data subject;

• Article 6(1)(f) GDPR in other cases. Our legitimate interest lies in efficient, traceable and secure business communications.

9.8 Direct marketing and professional information

We may use the contact details of existing and prospective business partners to provide information about our services, current tax developments, events and other professional matters.

Postal direct marketing may be based on Article 6(1)(f) GDPR where the interests or fundamental rights of the data subject do not prevail. Our legitimate interest lies in maintaining existing and initiating new business relationships and providing information on relevant professional services and developments.

Electronic marketing messages and marketing calls are made only in compliance with the requirements of section 174 TKG 2021, in particular on the basis of the relevant consent or, in the case of electronic mail, where the statutory conditions for lawful communications with existing customers are met. Consent may be withdrawn at any time with effect for the future. The processing of personal data for direct marketing purposes may be objected to at any time.

9.9 Job applications

Where we accept job applications, we process the application data provided for the purpose of conducting the recruitment process.

The legal basis is Article 6(1)(b) GDPR for taking steps prior to entering into a contract. Where data is retained for a limited period after completion of the selection process to document the process and defend against possible legal claims, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in demonstrating that the selection process was lawful and in defending legal claims.

If no employment relationship is established, application documents are generally retained for seven months where this is necessary for the establishment, exercise or defence of possible legal claims and are then deleted. This retention period takes account in particular of the six-month period for asserting claims under the Austrian Equal Treatment Act and an appropriate additional period for potential court proceedings. Data is retained for longer only where a separate legal basis applies, in particular consent to retaining the application on file.

9.10 Changes of purpose

If we intend to further process personal data for a purpose other than the purpose for which it was collected, we provide the data subject, before that further processing, with information on the new purpose and the relevant additional information in accordance with Article 13(3) or Article 14(4) GDPR, unless a statutory exception to the information obligation applies.

10. Provision of personal data

The provision of personal data may be required by law, necessary for entering into or performing a contract, or voluntary. Where data is required to comply with statutory due diligence obligations or properly perform a client engagement, we may be unable to accept or continue the engagement unless the necessary data is provided.

In particular, subject to the statutory requirements of the WTBG 2017, a business relationship may not be established or may have to be terminated if the statutory due diligence obligations towards clients cannot be fulfilled. Where data is provided solely on a voluntary basis, failure to provide it does not result in any disadvantage, except where the relevant service or function cannot technically or practically be provided without that data.

11. Recipients of personal data

Personal data is disclosed or transferred only where necessary for the stated purposes, required by law or otherwise permitted under data protection law. Depending on the relevant engagement, the following recipients or categories of recipients may in particular receive data:

• tax offices and other tax authorities and bodies accessible through FinanzOnline;

• the Austrian Health Insurance Fund and other social security institutions;

• municipalities and other public bodies responsible for levies;

• Statistics Austria;

• courts and administrative authorities;

• the Austrian Financial Intelligence Unit and other statutory reporting bodies;

• the Austrian Chamber of Tax Advisers and Auditors (Kammer der Steuerberater:innen und Wirtschaftsprüfer:innen, KSW) and other competent professional bodies;

• banks, payment service providers, insurers, pension and employee provident funds and other pension institutions;

• lawyers, notaries, auditors and other professional advisers;

• experts and other parties to proceedings;

• recipients designated by the client;

• debt collection agencies or other bodies involved in legal enforcement;

• IT, software, hosting, cloud, telecommunications, archiving, printing, delivery and other technical service providers.

Personal data is not sold.

12. Processors and external service providers

We may use external service providers to provide our services and operate our practice, for example providers of practice management, accounting and payroll software, IT support, cloud and hosting services, document management and archiving, email and communication services, data backup, newsletter distribution, website hosting and website administration.

Where these service providers process personal data on our behalf, they are contractually bound in accordance with Article 28 GDPR. Processors may generally process personal data only on documented instructions and within the agreed scope. Where a service provider acts as an independent controller for its own purposes, data is transferred only on an applicable legal basis.

13. Transfers of data to third countries

Personal data is transferred to countries outside the European Union or the European Economic Area, or to international organisations, only where necessary for the relevant processing operation and where the requirements of Articles 44 et seq GDPR are met.

Depending on the recipient, a transfer may be based in particular on an adequacy decision of the European Commission under Article 45 GDPR, on appropriate safeguards under Article 46 GDPR, especially standard contractual clauses, or, in exceptional cases provided for by law, on Article 49 GDPR. Where standard contractual clauses or other appropriate safeguards are used, we also provide information in the specific context about how a copy of the relevant safeguards may be obtained or where they are available.

Transfers to recipients in the United States may be based on an applicable adequacy decision where the relevant recipient is covered by that decision. Otherwise, another lawful transfer mechanism is used.

14. Retention periods and deletion

We retain personal data only for as long as necessary for the relevant purpose of processing. Data is retained beyond that period only where statutory retention obligations apply or where further retention is necessary, in particular for the establishment, exercise or defence of legal claims.

The specific retention period therefore depends on the nature of the data, the relevant purpose of processing and the applicable statutory retention and limitation periods. In particular, the following periods or deletion criteria apply:

Client and engagement documents: for the duration of the engagement and thereafter for as long as statutory retention obligations, pending proceedings or the establishment, exercise or defence of legal claims require further retention.

Books, records and supporting documents: generally seven years under section 132 BAO and beyond that for as long as they are relevant to pending tax proceedings.

Documents subject to retention under company law: generally seven years under section 212 UGB and beyond that for as long as they are relevant to pending court or administrative proceedings.

Property-related documents within the scope of the UStG 1994: generally 22 years where the special statutory retention period under section 18(10) UStG 1994 applies.

Documents relating to anti-money-laundering due diligence and documentation obligations: generally at least five years in accordance with section 98 WTBG 2017. Data is retained beyond that period only where required by another statutory provision or supported by another legal basis.

Application documents where no employment relationship is established: generally for up to seven months after completion of the recruitment process, in particular to preserve and defend possible claims. Data is retained beyond that period only where a separate legal basis applies.

Enquiries and other communications not followed by a client engagement: for the period required to deal with the relevant enquiry and thereafter only for as long as necessary to establish, exercise or defend legal claims, comply with statutory obligations or on another legal basis.

Records of consent, withdrawal and objection: for as long as the record is necessary for the processing in question or to give effect to a withdrawal or objection; the data is then deleted unless a statutory obligation or another legal basis requires further retention.

Website server logs: only for as long as necessary to ensure technical operation and system security and to detect and analyse technical errors or security incidents. Data is retained beyond that period only where a legal basis applies in the individual case.

Cookies and analytics and marketing data: the retention period depends on the nature and purpose of the relevant cookie or technology, its technical lifetime and the settings of the relevant service. Data is deleted once the applicable retention period expires, unless another legal basis permits further retention.

Newsletter data: until consent is withdrawn or an objection to receipt is made. Records of consent, withdrawals and objections are retained only for as long as necessary to demonstrate the lawfulness of processing or to give effect to the withdrawal or objection.

Personal data is deleted or anonymised when the applicable retention period expires, unless a statutory obligation or another legal basis requires further retention.

15 .Website and technical access data

When you visit our website, technically necessary data may be processed, in particular the IP address, date and time of access, page or file requested, amount of data transferred, browser type and version, operating system, referrer URL, host name of the accessing device and technical error and security information.

This data is processed to provide the website technically, ensure its stability and security and detect and prevent misuse and cyberattacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of our website and IT systems.

16 .Email communications

The “Contact Us” link on our website opens the email application or email service configured on your device. Merely opening it does not transmit the contents of a message to us. If you send us an email, we process the information you provide, in particular your email address, the contents of your message and any attachments, to deal with your enquiry.

Where the contact serves to initiate or perform a contract with you, the legal basis is Article 6(1)(b) GDPR. In other cases, processing is based on Article 6(1)(f) GDPR; our legitimate interest lies in the efficient, traceable and secure handling of business enquiries.

17. Cookies and similar technologies

Our website may use cookies and similar technologies. Strictly necessary cookies may be used where they are required to provide a service expressly requested by the user. Where cookies or similar technologies are not strictly necessary, they are generally used only after prior consent under section 165(3) TKG 2021 in conjunction with Article 6(1)(a) GDPR.

Where personal data is processed on the basis of consent, that consent may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. Consent can be managed and withdrawn through the cookie settings provided on our website.

Where processing is based on Article 6(1)(f) GDPR, the data subject has the right to object under the conditions set out in Article 21 GDPR. Where personal data is processed for direct marketing purposes, an objection may be made at any time without giving reasons.

The storage of cookies may also be restricted or prevented through browser settings. This may limit certain website functions.

18. Web analytics external content newsletters and social media

Where analytics, statistics or marketing services based on cookies or similar technologies are used, they are generally activated only after prior consent. The legal bases are Article 6(1)(a) GDPR and, where applicable, section 165(3) TKG 2021.

The same applies to external content or services such as maps, videos, fonts, appointment-booking systems or directly embedded social media content where activation is not technically necessary. For each service actually used, we provide specific information about the provider, purpose, data or categories of data processed, legal basis, retention period and any transfer to a third country.

Cal.com and online appointment booking. An appointment-booking interface provided by Cal.com is embedded on our website. The provider is Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. After you give consent, your browser connects to Cal.com to load the booking interface. In this process, your IP address, browser and device information, the page visited, referrer URL and time of access may be transmitted to Cal.com; cookies or similar identifiers may also be used. The legal basis for activating the embed is your consent under Article 6(1)(a) GDPR and, where information is stored on or retrieved from your device, section 165(3) TKG 2021. The embed is not loaded without your consent.

If you book an appointment, we process your name, email address, selected appointment and any other information you provide to organise and hold the appointment. Cal.com states that it processes booking information on our behalf as a processor. The legal basis is Article 6(1)(b) GDPR where you are taking steps towards or performing a contract with us yourself; otherwise it is Article 6(1)(f) GDPR (handling business appointment requests). Our retention is governed by the criteria in section 14; Cal.com may generally retain booking information for the lifetime of our account with it. Cal.com states that it processes data in the United States and relies on standard contractual clauses or an applicable adequacy mechanism for transfers from the EEA. Further information: https://cal.com/privacy.

Google Maps. Maps from Google Maps are embedded to display our location. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, provides this Google service to users in the European Economic Area. Only after you give consent is a connection to Google established to load the map. In this process, your IP address, browser and device information, referrer URL and time of access, as well as cookies or similar identifiers, may be processed. Interacting with the map may generate further usage data and, where applicable, location data. The legal basis for activating the embed is your consent under Article 6(1)(a) GDPR and, where information is stored on or retrieved from your device, section 165(3) TKG 2021. The map is not loaded without your consent.

Google may also process data outside the EEA. Details of its processing, retention and international transfers are available at https://policies.google.com/privacy. Use of Google Maps features is also subject to the additional terms at https://maps.google.com/help/terms_maps/.

Where a newsletter is offered, the contact details required for this purpose are processed on the basis of consent under Article 6(1)(a) GDPR and in compliance with section 174 TKG 2021. Consent may be withdrawn at any time with effect for the future. Where a double opt-in procedure is used, evidence of the time and scope of registration may be processed to the extent necessary to demonstrate consent.

Where we operate social media profiles, we process personal data generated there in accordance with the relevant platform and our actual use. Where joint controllership with a platform operator exists within the meaning of Article 26 GDPR, we provide information on the essential terms of the relevant arrangement and the responsibilities of the parties.

19. Use of AI supported applications

Where we use AI-supported applications to assist with internal workflows or the provision of our services and personal data is processed, this is done only in accordance with the applicable data protection and professional requirements and with due regard to our statutory duties of confidentiality.

Before using such an application, we examine in particular the specific purpose, necessity and data minimisation, the respective roles under data protection law, any required agreement under Article 28 GDPR, confidentiality and security guarantees, storage locations and deletion arrangements, any use of input data for the provider's own purposes or for training and any transfers to third countries. Special categories of personal data and data under Article 10 GDPR are processed only where the additional statutory requirements applicable in each case are met.

20. Automated decision making and profiling

As a general rule, we do not make decisions based solely on automated processing, including profiling, within the meaning of Article 22 GDPR that produce legal effects concerning data subjects or similarly significantly affect them. If such procedures are used in future, we will inform data subjects in accordance with the statutory requirements, in particular about the logic involved and the significance and envisaged consequences of the processing.

21 .Security measures

In accordance with Articles 24, 25 and 32 GDPR and taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the relevant risk.

These measures serve in particular to ensure the confidentiality, integrity, availability and resilience of the systems and services used and to restore the availability of personal data rapidly following a physical or technical incident. Data protection principles under Article 25 GDPR are also taken into account when selecting and designing systems, applications and workflows. Depending on the relevant processing operation and the associated risk, our technical and organisational measures include in particular:

• physical and organisational entry, access and authorisation controls;

• user, role and authorisation concepts and appropriate authentication procedures;

• appropriate encryption and transmission protection measures, where required by the nature and sensitivity of the data;

• data backup and recovery measures and measures to ensure the availability of business-critical data and systems;

• technical safeguards against malware, unauthorised access and other IT security risks, together with appropriate updating and maintenance;

• logging, monitoring and organisational review measures where required;

• confidentiality and data protection obligations for persons working for us, together with appropriate awareness measures and training;

• careful selection and data protection review of external service providers and, where required, the conclusion of data processing agreements and assessment of third-country transfers;

• established procedures for detecting, assessing and handling personal data breaches and complying with any notification and communication obligations.

The adequacy of the technical and organisational measures is reviewed regularly, taking account of developments in the state of the art, the systems used and the relevant risks, and adjusted where necessary. We also take account of the special professional duty of confidentiality under section 80 WTBG 2017.

22. Professional duty of confidentiality

As a tax advisory firm, red tax Steuerberatung GmbH is subject to the statutory duties of confidentiality under the WTBG 2017. Under section 80 WTBG 2017, authorised professionals are in particular required to maintain confidentiality concerning matters entrusted to them and personal circumstances and business or trade secrets that become known to them while carrying out an engagement or practising their profession.

Information is disclosed only where there is a statutory obligation or other legal basis for doing so, the client has validly released us from the duty of confidentiality or another statutory exception applies.

23. Rights of data subjects

Subject to the statutory requirements, data subjects have the following rights in particular:

• access under Article 15 GDPR;

• rectification under Article 16 GDPR;

• erasure under Article 17 GDPR. Erasure may be excluded where data must continue to be retained, for example because of statutory retention obligations, or where it is required for the establishment or defence of legal claims;

• restriction of processing under Article 18 GDPR;

• data portability under Article 20 GDPR;

• objection to certain processing under Article 21 GDPR;

• withdrawal of consent under Article 7(3) GDPR with effect for the future.

Where personal data is processed for direct marketing purposes, the data subject may object to such processing at any time without giving reasons.

Restrictions arising from professional law

These rights are not unrestricted. Under section 80(3a) WTBG 2017, a data subject may not rely on the rights under Articles 12 to 22 and Article 34 GDPR or section 1(3) DSG to the extent that this is necessary to protect the authorised professional's right to confidentiality in order to safeguard the client or the rights and freedoms of other persons or to enforce civil-law claims.

Similarly, the information obligation under Article 14 GDPR does not apply in particular where and to the extent that personal data must remain confidential pursuant to a statutory duty of professional secrecy under Article 14(5)(d) GDPR.

Data subject requests are therefore always assessed with due regard to our statutory duties of confidentiality and the rights of our clients and other third parties.

To exercise your rights, please contact office@red-tax.at. Where we have reasonable doubts concerning the identity of the person making the request, we may request additional information necessary to confirm that person's identity in accordance with Article 12(6) GDPR.

24. Withdrawal of consent

Where the processing of your personal data is based on your consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

You may withdraw consent in particular by emailing office@red-tax.at or by using any other contact method specified in this Privacy Notice.

25. Third party content and services

Our website may contain links to third-party websites, platforms or other online services. When you access such an external service, you leave our area of responsibility. The relevant third party's privacy information and other legal terms apply to its processing of personal data.

We generally have no control over the nature, scope and purposes of processing by external providers whose services are merely accessible through a link on our website. We therefore accept no responsibility for the data protection arrangements or content of those external services, unless the relevant processing falls within our own area of responsibility.

26. Right to lodge a complaint

If you consider that the processing of your personal data infringes data protection law, you have the right under Article 77 GDPR to lodge a complaint with a competent data protection supervisory authority.

In Austria, the competent authority is:

Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna, Austria
+43 1 52 152-0
dsb@dsb.gv.at
https://www.dsb.gv.at/

27. Changes to this Privacy Notice

We review this Privacy Notice regularly and update it where our processing activities, the technical systems used or the legal framework change. Changes to this Privacy Notice do not, however, replace any information about a new purpose of processing that must be provided in an individual case under Article 13(3) or Article 14(4) GDPR.

The version currently published on our website applies.

red tax Steuerberatung GmbH

+43 (676) 949 85 05

office@red-tax.at

Museumstraße 3b/16

1070 Wien

Looking for reliable tax advice for your business?

Schedule an initial consultation with us. We will discuss your situation, clarify your needs and explain how we can support your business in Austria and across Europe.

red tax Steuerberatung GmbH

+43 (676) 949 85 05

office@red-tax.at

Museumstraße 3b/16

1070 Wien

Looking for reliable tax advice for your business?

Schedule an initial consultation with us. We will discuss your situation, clarify your needs and explain how we can support your business in Austria and across Europe.

red tax Steuerberatung GmbH

+43 (676) 949 85 05

office@red-tax.at

Museumstraße 3b/16

1070 Wien

Looking for reliable tax advice for your business?

Schedule an initial consultation with us. We will discuss your situation, clarify your needs and explain how we can support your business in Austria and across Europe.