General Data Protection Regulation

Please note: These legal texts have been translated from the original German version with the assistance of AI. Despite careful review, errors or inaccuracies cannot be ruled out. In case of doubt, the German original version shall prevail.

  1. Subject Matter of the Agreement

    1. The subject matter of this engagement is the performance of the following tasks: enabling the use of products and services of the Processor; this particularly concerns the use of the classic business card in digital form, the digital business card, including the associated administration portals, and the manufacture and production of personalised hardware components.
    2. This agreement is to be understood as a supplement to our Privacy Policy and our General Terms and Conditions.
    3. The following types of personal data are processed: ▪ For the use of our services and the portal for managing digital business cards, the following data is processed: profile picture, contact details, order details, contract data, billing data, login access, browser data, device data (fingerprint & operating system), country and federal state ▪ For the use of digital business cards, the following data is processed, whereby it is left to the user to decide which data they wish to provide: profile picture, contact details, social media data ▪ To enable statistics and analyses, the following additional data is collected each time the digital business card is accessed: timestamp, browser data, device data (fingerprint & operating system), country and federal state – IP address is collected when the contact is downloaded.
    4. The following categories of data subjects are subject to processing: customers
    5. The processing is of the following nature: collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of data
  2. Duration of the Agreement

    1. The agreement is concluded for an indefinite period and may be terminated by either party at any time, but no earlier than at the end of the month. The right to extraordinary termination for good cause remains unaffected.
  3. Obligations and Rights of the Processor

    1. The Processor undertakes to process personal data solely on documented instructions from the Controller, including with regard to the transfer of personal data to third countries or international organisations, unless it is legally obliged to do so. In such a case, the Processor shall inform the Controller, unless such notification is prohibited by law.
    2. The Processor legally declares that all persons authorised to process the data have been bound to confidentiality before commencing their activities or are subject to an appropriate statutory duty of confidentiality. In particular, the confidentiality obligation of the persons authorised to process the data shall continue to apply even after the end of their activities and after leaving the Processor.
    3. The Processor legally declares that it has taken all necessary measures to ensure the security of processing in accordance with Article 32 GDPR.
    4. Taking into account the nature of the processing, the Processor shall, where possible, support the Controller by appropriate technical and organisational measures so that the Controller can comply at all times, within the statutory periods, with its obligation to respond to requests for exercising the rights of data subjects set out in Chapter III of the GDPR (e.g. information, access, rectification and erasure, data portability, objection, and automated individual decision-making), and shall provide the Controller with all information necessary for this purpose. If such a request is addressed to the Processor and it is apparent that the applicant mistakenly considers the Processor to be the Controller of the data application operated by it, the Processor shall forward the request to the Controller without delay and inform the applicant accordingly.
    5. Taking into account the nature of the agreement and the information available to it, the Processor shall support the Controller in complying with the obligations set out in Articles 32 to 36 GDPR (e.g. data security measures, notifications of personal data breaches to the supervisory authority, notification of the person affected by a personal data breach, data protection impact assessment, prior consultation).
    6. The Processor shall maintain a record of processing activities for this processing operation in accordance with Article 30 GDPR.
    7. The Controller shall be granted the right, at any time, to inspect and monitor the processing facilities with regard to the processing of the data provided by it, including through third parties appointed by the Controller. The Processor undertakes to provide the Controller with all information necessary to demonstrate compliance with the obligations laid down in this agreement and to enable and contribute to audits, including inspections, conducted by the Controller or another auditor appointed by the Controller.
    8. After the end of this agreement, the Processor shall be obliged, unless there is a legal obligation to retain the data, to destroy all processing results and documents containing data on behalf of the Controller.
    9. The Processor shall notify the Controller without delay of disruptions, breaches by the Processor or by persons employed by it, breaches of data protection provisions or of the stipulations agreed in the engagement, as well as any suspicion of data protection breaches or irregularities in the processing of personal data. The Processor may only carry out notifications under Articles 33 or 34 GDPR on behalf of the Controller following prior instruction from the Controller.
  4. Place of Data Processing

    1. Unless the Controller specifies otherwise, all data processing activities are carried out by default within the European Union or the European Economic Area (EEA).
  5. Sub-Processors

    1. The Processor is not entitled to engage a sub-processor, except for section 5.2 and productions of hardware components, such as the production of NFC or personalised physical business cards, where necessary. Only the strictly necessary customer master data is transmitted to the sub-processor. The sub-processor differs depending on the product and component and can be explained to the Controller upon request. The customer master data is stored by the sub-processor for a maximum of 1 year.
    2. The Controller agrees to the engagement of the following sub-processors subject to a contractual agreement in accordance with Article 28(2)-(4) GDPR:
      Name and AddressSubject Matter of the Engagement
      Akamai Technologies GmbH Att.: Global Data Protection Officer 22 Parkring DE-85748 Garching Provision of cloud servers in accordance with the ISO27001 standard for data processing and storage
      Akamai Technologies GmbH Att.: Global Data Protection Officer 22 Parkring DE-85748 Garching Provision of images, files and documents uploaded by the Controller, in accordance with the ISO27001 standard.
      Laravel Holdings Inc. 60 Broad Street, 24th Floor #1559, New York, New York 10004, United States Reporting and processing of error messages that arise during use.
      Stripe, Inc. now known as Stripe, LLC 354 Oyster Point Boulevard South San Francisco, California, 94080, United States Processing of payment transactions and storage of payment methods, including the storage of bank details for certain payment methods (e.g. SEPA or bank transfer)
    3. Paragraph valid for processed data until the stated cut-off date: The Controller engaged the following sub-processor until the cut-off date of 30 March 2026 subject to a contractual agreement in accordance with Article 28(2)-(4) GDPR:
      Name and AddressSubject Matter of the Engagement
      Google Ireland Ltd. Google Building Gordon House, 4 Barrow St, Grand Canal Dock, Dublin 4, D04 V4X7, Ireland Provision of images, files and documents uploaded by the Controller, in accordance with the ISO27001 standard.
  6. General Retention of Data

    1. All personal data processed during registration and use on/of becard.me and the associated services and products is stored on the Processor's servers for no longer than ten years after the Controller's last activity, provided that no deletion request has been submitted by the Controller (see section 4).
    2. The following data is stored in the respective data centres in accordance with ISO27001 / ISO27017 / ISO27018 / SOC 1/2/3 / PCI DSS:
      Data TypeServer LocationServer Type
      Personal data (name, address, statistics, etc.), STRING/TEXT data for processing (log files, etc.) Frankfurt, Germany Cloud
      PDF and EXCEL documents (invoices, order confirmations, delivery notes, etc.) and images (profile pictures, company logos, etc.) Depending on the server selection of the Controller, data is stored at the nearest locations in: Paris, France Washington, DC, USA Osaka, Japan Cloud
      Safeguards / backupsFrankfurt, Germany Cloud
      API usage reports & error messages that arise during useFrankfurt, Germany Cloud
      Subscriptions, billing settings, payment methods and bank detailsSouth San Francisco, United States Cloud
  7. Safeguarding Processes / Backups

    1. All data is backed up once a day and stored in encrypted form, with a full backup of all data carried out every morning between 02:00 and 05:00. The last seven days are always stored. Backups older than seven days are automatically deleted in full.
  8. Deletion Process

    1. The deletion process takes effect upon the written request of the Controller. If no tax-relevant data has been processed, all data will be deleted within 48 hours on working days (Austria), except for section 8.3.
    2. In the event of an order placed within becard.me and the associated services and products, all data will be deleted in accordance with section 8.1, except for data that must be retained for accounting, tax and customs law purposes pursuant to Section 132(1) BAO and Section 11(2), third subparagraph, UStG. This data expires after 7 years and will subsequently be deleted accordingly.
    3. For technical reasons and due to the exceptionally high effort involved, the deletion process cannot be carried out in backup copies. See the deletion process for backup copies under section 3.1 – in the event of restoring a backup, see section 8.4
    4. When a deletion request is made, an anonymised identification number together with the internal identification number of the Controller is automatically stored on the separate backup server. This is used for the deletion process in backup restorations. The exact procedure is declared in section 5.1. This data record is stored for 8 days.
  9. Deletion Process in Backup Restorations

    1. In the event of a backup restoration, the identification numbers from the "deletion request" database (in accordance with section 8.4) are checked and automatically removed again from the current backup restore. This ensures that no data remains in circulation where a deletion request has already been received.
  10. Technical and Organisational Measures

    1. The Processor shall ensure security in accordance with Article 28(3)(c) and Article 32 GDPR, in particular in conjunction with Article 5(1) and Article 5(2) GDPR. Overall, the measures to be taken are data security measures intended to ensure a level of protection appropriate to the risk with regard to the confidentiality, integrity, availability and resilience of the systems. In doing so, the state of the art, implementation costs, the nature, scope and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons within the meaning of Article 32 GDPR, must be taken into account.
    2. The technical and organisational measures are subject to technical progress and further development. In this respect, the Processor is permitted to implement alternative appropriate measures. The security level of the specified measures must not be reduced. Significant changes must be documented and communicated to the Controller in advance.
    3. The Processor shall, where appropriate and at least annually, carry out a review, assessment and evaluation of the effectiveness of the technical and organisational measures for ensuring the security of processing (Article 32(1)(d) GDPR). The result shall be communicated to the Controller.
  11. Rectification, Restriction and Erasure of Data

    1. The Processor may not rectify, erase or restrict the processing of data processed under this agreement on its own authority, but only on documented instructions from the Controller. If a data subject contacts the Processor directly in this regard, the Processor shall forward the request to the Controller without delay.
    2. To the extent covered by the scope of services, the deletion concept, right to be forgotten, rectification, data portability and access shall be ensured directly by the Processor in accordance with documented instructions from the Controller.
  12. Liability and Compensation

    1. The Controller and Processor shall be liable towards data subjects in accordance with the provisions set out in Article 82 GDPR.
  13. Miscellaneous

    1. Amendments and additions to this agreement, including any assurances given by the Processor, require a written agreement, which may also be made in electronic format (text form), and an express indication that they constitute an amendment or addition to these terms.
    2. If individual provisions of this agreement are invalid or unenforceable, or become invalid or unenforceable after conclusion of the agreement, the validity of the remaining provisions of the agreement shall remain unaffected.
    3. Austrian law applies.
  14. DSG 2000, GDPR, Data Protection Amendment Act 2018

    1. At the time of signing this agreement, the provisions of the DSG 2000 still apply. However, the contracting parties already agree that, upon the entry into force of the General Data Protection Regulation and the Data Protection Amendment Act 2018, the Processor must fully comply with the obligations set out in their provisions.
FAQs

Legal Matters & Data Protection

Here you'll find answers to the most frequently asked questions about data protection, data security, subscriptions, and legal matters at Becard.