Privacy Policy
The legally binding version of this Privacy Policy is the German version. Translations are provided solely for better understanding.
Data Protection Web
Status: 17 June 2024
1. Controller
Name / Company: PowUnity GmbH
Address: Feldstraße 9d, 6020 Innsbruck, Austria
Email: [email protected]
2. Data Protection Officer
Name: Christian Strassl
Address: Feldstraße 9d, 6020 Innsbruck, Austria
Email: [email protected]
3. Types of data processed
- Inventory data (e.g. names, addresses)
- Contact details (e.g. email, phone numbers)
- Content data (e.g. text entries, photos, videos)
- Contract data (e.g. subject matter of the contract, term)
- Payment data (e.g. bank details, payment history)
- Usage data (e.g. websites visited, access times)
- Meta/communication data (e.g., device information, IP addresses)
4. Purpose of processing
- Provision of the online offering and its functions
- Fulfilment of contractual services, service and customer care
- Responding to contact enquiries and communicating with users
- Marketing, advertising and market research
- Safety measures
5. Legal bases for processing
- Consent (Art. 6(1)(a) GDPR)
- Performance of contracts (Art. 6(1)(b) GDPR)
- Fulfilment of legal obligations (Art. 6(1)(c) GDPR)
- Safeguarding legitimate interests (Art. 6(1)(f) GDPR)
6. Safety measures
We implement technical and organizational measures to ensure a level of protection appropriate to the risk. These include:
- Encrypted data transmission
- Physical security of the servers in locked rooms with access control
- Regular updates and security patches
- Access controls and role-based access restrictions
7. Disclosure of Data
Data is only shared within the scope permitted by law or on the basis of consent. This applies, for example, to payment service providers, logistics companies, and service providers who support us in fulfilling our contractual obligations.
8. Data transfers to third countries
Data transfers to third countries only take place if specific safeguards, such as Standard Contractual Clauses or recognized data protection certifications, are in place.
9. Rights of the data subjects
Data subjects have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR)
10. Cookies and Tracking
We use cookies and tracking technologies such as Google Analytics (GA4), Google Tag Manager, Meta Pixel, Adcell, Bing Ads, LinkedIn, and Wicked Reports to analyze user behavior and deliver targeted advertising. Users can prevent the storage of cookies by adjusting the settings in their browser software accordingly. Detailed information can be found in our Cookie Policy.
10.1. Google Analytics We use Google Analytics, a web analytics service provided by Google LLC (“Google”), to analyze the use of our website. Google Analytics uses cookies that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is generally transmitted to a Google server in the USA and stored there.
IP anonymization We have enabled IP anonymization on this website. This means that your IP address is shortened by Google within the member states of the European Union or in other contracting states to the Agreement on the European Economic Area before transmission. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
Data processing We have concluded a data processing agreement with Google and fully implement the strict requirements of the Austrian data protection authorities when using Google Analytics.
User rights You can prevent the storage of cookies by adjusting the settings of your browser software; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available under the following link: tools.google.com/dlpage/gaoptout.
Further information Further information on data protection in connection with Google Analytics can be found in the Google Analytics Help.
10.2. Meta (formerly Facebook) We use the Meta Pixel and other analytics tools from Meta Platforms, Inc. (“Meta”) to measure the effectiveness of our advertising and to deliver targeted advertising. In doing so, data about your use of our website is collected and linked to your Facebook or Instagram account. Meta may use this information to display personalized advertising.
Data transmission The data collected by the pixel is generally transmitted to a Meta server in the USA and stored there. Meta is certified under the EU-US Data Privacy Framework and thus provides a guarantee to comply with European data protection law.
User rights You can prevent the collection of your data by the Meta Pixel by disabling the relevant ad personalization options in the settings of your Facebook account. Further information can be found in Meta’s privacy policy: facebook.com/policy.php.
10.3. Adcell We use Adcell, an affiliate marketing network, to run marketing campaigns and measure the effectiveness of our advertising. Adcell uses cookies to track user activities and deliver targeted advertising.
Data transmission The data collected by Adcell is generally transferred to servers in the EU and stored there. Adcell implements strict data protection policies to ensure the security and protection of the data.
User rights You can prevent Adcell from collecting your data by adjusting the relevant cookie settings in your browser. Further information can be found in the Adcell Privacy Policy.
10.4. Bing Ads We use Bing Ads, an advertising network from Microsoft, to run our marketing campaigns and measure their effectiveness. Bing Ads uses cookies to track user activity and deliver targeted advertising.
Data transfer The data collected by Bing Ads is generally transferred to servers in the USA and stored there. Microsoft is certified under the EU-US Data Privacy Framework and therefore provides a guarantee to comply with European data protection law.
User rights You can prevent Bing Ads from collecting your data by adjusting the relevant cookie settings in your browser. Further information can be found in the Bing Ads Privacy Policy.
10.5. LinkedIn We use LinkedIn, a social network and career network, to run marketing campaigns and measure their effectiveness. LinkedIn uses cookies to track user activity and deliver targeted advertising.
Data transmission The data collected by LinkedIn is generally transferred to servers in the USA and stored there. LinkedIn is certified under the EU-US Data Privacy Framework and thus provides a guarantee to comply with European data protection law.
User rights You can prevent LinkedIn from collecting your data by adjusting the relevant cookie settings in your browser. Further information can be found in the LinkedIn Privacy Policy.
10.6. External media We embed content from external media such as YouTube. These external media may collect personal data and set cookies when you view the relevant content. Further information can be found in the privacy policies of the respective providers:
- YouTube: policies.google.com/privacy
11. Email marketing with Klaviyo
We use Klaviyo, an email marketing platform, to manage and run our email campaigns. If you provide your email address as part of a purchase or a sign-up on our website, it will be stored in Klaviyo. We use Klaviyo to send informative and sales-focused emails.
Data transmission and storage The data is stored on Klaviyo’s servers in the USA. Klaviyo is certified under the EU-US Data Privacy Framework and therefore guarantees compliance with European data protection law.
User rights You can object to receiving these emails at any time by using the unsubscribe link in each email or by contacting us directly.
Further information Further information on data protection in connection with Klaviyo can be found in the Klaviyo Privacy Policy.
12. Data retention
Data is stored for as long as necessary to fulfill the purposes for which it was collected or as required by statutory retention periods. Customer information is retained at least for as long as the customer uses our product or service in order to ensure the best possible customer support.
13. Amendments to the Privacy Policy
We reserve the right to amend this Privacy Policy in order to adapt it to changes in the legal situation or in the event of changes to the service and data processing. Users are requested to regularly inform themselves about the content of the Privacy Policy.
App Privacy Policy
This Privacy Policy applies to the use of the PowUnity app, all related services, and any other possible interactions between PowUnity and its users. It describes how PowUnity collects, uses, and shares information, and explains your options regarding this information.
Status: 11 July 2024
1. Controller Name / Company: PowUnity GmbH
Address: Feldstraße 9d, 6020 Innsbruck, Austria
E-mail: [email protected]
2. Data Protection Officer Name: Christian Strassl
Address: Feldstraße 9d, 6020 Innsbruck, Austria
Email: [email protected]
Required permissions
To use the PowUnity app properly, certain permissions are required on your smartphone to provide you with the best tracking functionality:
- Location:
- Approximate location (cellular-based)
- Precise location (GPS- and cellular-based)
- Note: Location permission is required to display your current position relative to the GPS tracker on the map.
- Camera:
- Capture photos and videos
- Note: This permission is required if you want to scan the QR code to install the GPS tracker or photograph the invoice and the bicycle for a bike passport. You can also enter the ID manually if you prefer.
- Other:
- Push notifications
- Note: This permission is required to notify you directly about events related to our products and services, in particular to alert you in the event of unauthorized movement of your e-bike.
- Vibration control
- Note: This permission is required to send vibration notifications, in particular to alert you in the event of a stolen e-bike.
Data we process and their purpose
We collect information about you when you voluntarily provide it and when you use our products and services. PowUnity processes your profile information, payment information, location data, and activity data as follows:
- Profile information:
- When registering for a PowUnity App account, you provide an email address and a password. This information is mandatory for accessing the PowUnity App. You may also optionally upload a profile picture.
- Purpose: To enable the proper use of the PowUnity app and to personalize your account.
- Legal basis: Consent (Article 6(1)(a) GDPR).
- Retention period: Deleted 1 year after deactivation of the account.
- Payment information:
- Collected when you decide to pay for a PowUnity service.
- Purpose: For processing subscription payments.
- Legal basis: Required for the performance of the contract (Article 6(1)(b) GDPR).
- Retention period: Stored for 7 years in accordance with the Federal Fiscal Code or for as long as legal action is required.
- Location data:
- Collected and stored when using the PowUnity app services. This mainly includes GPS positions from the GPS tracker mounted on your e-bike.
- Purpose: To ensure the functionality of our product and to generate route data.
- Retention period: Stored in our backup system for a maximum of 1 year after termination of the contract.
- Activity data:
- Automatically collected when using the PowUnity app, such as IP address, page visit data, and usage timestamps.
- Purpose: For the optimization and further development of the PowUnity app.
- Legal basis: Legitimate interest (Article 6(1)(f) GDPR).
- Retention period: Deleted 1 year after creation.
Technologies and Services
- Auth0 (Registration):
- Provider: Auth0, Inc., Bellevue, WA, USA.
- Legal basis: Auth0 complies with the GDPR and other relevant data protection regulations by implementing Standard Contractual Clauses (SCCs) and other mechanisms under the EU-US Data Privacy Framework to ensure lawful data flows.
- Auth0 Privacy Policy
- Cisco Jasper Control Center (SIM card management):
- Note: SIM card numbers, when combined with other data in our systems, can be used to identify a specific user or their e-bike.
- Cisco Privacy Policy
- Cloudinary (image storage):
- Provider: Cloudinary Ltd.
- Data protection measures: Cloudinary complies with the GDPR and provides secure storage and processing of images.
- Location: USA.
- Cloudinary Privacy Policy
- Mittwald CM Service GmbH & Co. KG (web hosting):
- Provider: Mittwald CM Service GmbH & Co. KG, Espelkamp, Germany.
- Data protection measures: Mittwald complies with the GDPR and provides secure web hosting services.
- Location: Espelkamp, Germany.
- Mittwald Privacy Policy
- Postmark (Email):
- Provider: Postmark, Wildbit LLC, Chicago, USA.
- Data protection measures: Postmark complies with the GDPR and uses industry-standard security measures to protect your data. Emails and associated data are retained for 45 days before being deleted from the systems. Postmark adheres to the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses (SCCs) to protect the data.
- Storage period: 45 days.
- Location: Chicago, USA.
- Postmark Privacy Policy
- Sentry (Error analysis):
- Provider: Functional Software Inc., San Francisco, CA, USA.
- Legal basis: Sentry complies with the GDPR and other relevant data protection regulations by implementing Standard Contractual Clauses (SCCs) and other mechanisms under the EU-U.S. Data Privacy Framework to ensure lawful data transfers.
- Sentry Privacy Policy
- STASTO (server hosting):
- Provider: STASTO Automation KG, Innsbruck, Austria.
- Data protection measures: STASTO complies with the GDPR and provides secure server hosting services.
- Location: Innsbruck, Austria.
- STASTO Privacy Policy
- Zapier (Integration and automation):
- Provider: Zapier, Inc., San Francisco, USA.
- Data protection measures: Zapier complies with the GDPR and ensures that data processed through its services is encrypted and stored securely. Data is retained for up to 69 days before being deleted. Zapier adheres to the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses (SCCs) to protect data.
- Storage duration: Up to 69 days.
- Location: USA.
- Zapier Privacy Policy
Contract processor
- Chargebee:
- Used for processing subscription payments.
- Provider: Chargebee Inc., Walnut, CA, USA.
- Data protection measures: Chargebee complies with the GDPR and implements robust security measures to protect your data. Chargebee stores information such as your email address, payment details, and billing information until the account is deleted. Chargebee uses Standard Contractual Clauses (SCCs) and other mechanisms under the EU-U.S. Data Privacy Framework to ensure lawful data transfers.
- Retention period: Stored in accordance with statutory requirements and until the account is deleted.
- Chargebee Privacy Policy
Data retention
- Amazon Web Services (AWS):
- We use AWS servers for data storage.
- Location: Frankfurt, Germany.
- Data protection measures: AWS complies with the GDPR and provides robust security measures to protect the data stored on its servers.
- AWS Privacy Policy
Payment service provider
We use external payment service providers to process payments. They are responsible for their data processing practices in accordance with Article 24 GDPR. Further information can be found in their privacy policies:
- American Express: American Express Privacy Policy
- Klarna / Sofortüberweisung: Klarna Privacy Policy
- Mastercard: Mastercard Privacy Policy
- PayPal: PayPal Privacy Policy
- Stripe: Stripe Privacy Policy
- Visa: Visa Privacy Policy
Analysis by Google Firebase
We use Google Firebase to track and analyze app usage, improve performance, and understand user behavior. All collected data is anonymous.
- Provider: Google Ireland Limited, Dublin, Ireland.
- Legal basis: Legitimate interest (Article 6(1)(f) GDPR).
- For more information, please refer to the Firebase Privacy Policy
Rights of data subjects
Under the GDPR, you have the following rights:
- Right of access: You may request access to your personal data.
- Right to rectification: You may request the correction of inaccurate or incomplete data.
- Right to erasure: Under certain conditions, you may request the deletion of your data.
- Right to restriction of processing: Under certain conditions, you may request the restriction of processing.
- Right to data portability: You can request the transfer of your data to another service provider.
- Right to object: You may object to processing based on legitimate interests or for direct marketing purposes.
- Right to lodge a complaint: You may lodge a complaint with a supervisory authority.
Data retention
In accordance with Art. 5(1)(e) GDPR, personal data will be deleted as soon as the purpose of the processing has been fulfilled. Retention periods are determined by statutory requirements or business needs. Unless otherwise stated, data will be processed until the end of the business relationship or until the expiry of statutory periods, including any legal disputes.
Reporting of data protection breaches
In the event of a personal data breach, we will notify affected individuals and the competent supervisory authorities within 72 hours of becoming aware of the breach, as required by the GDPR.
Updates to this Policy
We may update this policy periodically. Any changes will be published on this page, and in the event of material changes, we will provide a clearly visible notice.
For questions or concerns, please contact us at [email protected].
This updated Privacy Policy includes necessary adjustments to reflect the current legal framework and best practices in data protection as of July 2024.
Use of artificial intelligence (AI)
For the efficient and error-reduced capture of incoming orders, supplier invoices, and incoming email correspondence, we use a technical processing system based on artificial intelligence.
In doing so, the contents of orders, incoming invoices and incoming emails (e.g. company name, contact person, business contact details, the content of email correspondence, order and invoice line items, delivery and billing information, payment data) are automatically analyzed and transferred into structured data for our internal ERP and financial accounting systems.
The controller responsible for this processing is PowUnity GmbH, Feldstraße 9d, 6020 Innsbruck, Austria.
The technical implementation is carried out by our affiliated group company STASTO International KG as a processor within the meaning of Art. 28 GDPR. A data processing agreement has been concluded with this company.
As part of the processing, STASTO International KG uses the technical service providers OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA, and Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA, as sub-processors. A contract pursuant to Art. 28 GDPR has been concluded with each of these providers. In the course of use, personal data may be transferred to a third country (USA). The transfer is carried out on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular the Standard Contractual Clauses approved by the EU Commission.
The processing is carried out exclusively for the purpose of the proper execution and handling of contractual relationships with customers and suppliers, as well as for compliance with statutory retention and documentation obligations.
The legal basis for processing is Art. 6 (1) (b) GDPR (performance of a contract), Art. 6 (1) (c) GDPR (compliance with legal obligations, in particular corporate and tax law regulations), as well as Art. 6 (1) (f) GDPR (legitimate interest in efficient and structured business operations).
No automated decision-making within the meaning of Art. 22 GDPR takes place.
Further information on the use of AI