ZTP.digital ZT-GmbH, office at Millennium Tower, Handelskai 94-96, A-1200 Vienna, Austria (“ZTP” or “we”) respects your privacy. This privacy policy applies to the ZTP website.
1. Who is responsible for data processing and whom can I contact?
The controller is:
ZTP.digital ZT-GmbH
Office at Millennium Tower
Handelskai 94-96
A-1200 Vienna, Austria
You can reach us at:
Phone: +43 1 532 46 86-0
Fax: +43 1 532 46 86-20
E-mail: office@cyberbelt.ai
2. Which personal data do we use?
By personal data we mean any information relating to an identified or identifiable natural person. We collect personal data from you yourself, namely when …
2.1. You send us an enquiry via our contact form
When you use our contact form, we may collect the following personal data: name (first and last name), position, company/authority, location, e-mail, phone, as well as any other information you voluntarily provide (e.g. in the “subject” and “message” fields).
Providing your personal data is voluntary. However, if you do not provide certain data (such as your e-mail address), we may not be able to process your enquiry.
2.2. You apply for an open position by e-mail
Providing your personal data is voluntary.
3. Features and links to other websites
For practical reasons or for your information, our website may contain features for which we cooperate with other companies, as well as links to other websites. These features and links may be operated independently of ZTP; separate privacy notices or policies may apply to them. We therefore strongly recommend that you review them when you visit them. Insofar as these features and linked websites are not owned or controlled by ZTP, we are not responsible for their content, use or privacy practices.
4. For what purpose and on what legal basis do we process your personal data?
4.1. Based on a legitimate interest of ZTP (Art. 6 (1)(f) GDPR)
Our overriding legitimate interest is to process the personal data mentioned under point 2.1 in order to handle and respond to your enquiry, complaint or indeed your praise.
4.2. With your consent (Art. 6 (1)(a) GDPR)
We process the personal data mentioned under point 2.2 with your consent. You may withdraw this consent for the future at any time by e-mail to office@cyberbelt.ai. Withdrawal does not affect the lawfulness of the data processing carried out up to the point of withdrawal.
5. Who receives my data?
As a general rule, we do not pass on your data.
6. How long is my personal data stored?
Based on consent: If you have given your consent as part of the application process, we may store the personal data submitted under point 2.2 for six months. As soon as you withdraw your consent for the future, the personal data will be deleted, unless statutory retention obligations exist (e.g. under company law, tax law or the Austrian Federal Fiscal Code) or the data is necessary for the preservation of evidence within the framework of the statutory limitation periods.
Based on legitimate interests: We store the personal data mentioned under point 2.1 only for as long as it is required for the purposes stated under point 4.1. Once our legitimate interest has ceased to exist, the data is routinely deleted, unless its – temporary – further processing is required to fulfil statutory retention obligations or to preserve evidence within the framework of the statutory limitation periods. We may store anonymized data indefinitely.
7. What data protection rights do I have?
Under applicable law you are entitled, among other things:
- to check which personal data we have stored about you and to receive copies of this data,
- to request the rectification, completion or erasure of your personal data that is incorrect or processed unlawfully,
- to require us to restrict the processing of your personal data,
- under certain circumstances, to object to the processing of your personal data or to withdraw consent previously given,
- to request data portability,
- to know the identity of third parties to whom your personal data is transferred, and
- to lodge a complaint with the competent authority. The competent data protection authority for Austria is the Datenschutzbehörde, Wickenburggasse 8, 1080 Vienna.
8. Definition of information security
ZTP defines the term information security as the preservation of:
Responsibility
Management, all employees and other third parties must be aware of their responsibility for maintaining information security, report security incidents and act in accordance with the applicable requirements of the ISMS. Violations of the information security policies have consequences for ZTP employees. All employees receive awareness training on information security; specialists are prepared for their tasks in dedicated training sessions.
Availability
The availability of our data and IT systems is safeguarded in all areas in such a way that the downtime targets defined and agreed for business operations can be met. Adequate business continuity and emergency plans must be in place.
Confidentiality
It must be ensured that information can only be viewed, processed or used by authorized persons, in order to prevent intentional or accidental unauthorized access to ZTP information or systems. ZTP complies with the requirements of the Austrian Data Protection Act and the GDPR, intellectual property law and other laws protecting privacy and information security.
Integrity
The accuracy and completeness of information and processing methods must be ensured and protected. To this end, the deliberate or accidental destruction as well as the unauthorized modification of physical or electronic data must be prevented.
Physical assets
ZTP's employees and their knowledge represent the most significant information asset. Physical assets at ZTP include, among other things, computer hardware, server rooms, networks, cabling, telephone systems and archive systems.
Web fonts
For a consistent presentation of text content, we use web fonts on our website. For data protection reasons, we do not embed them directly from external servers but serve these fonts locally from our own web server. As a result, no requests are made to third-party servers. If your browser does not support web fonts, a standard font from your computer will be used automatically.
Contact form
Our contact form transmits your input to a Vercel Function so that we can receive your enquiry server-side and forward it through the configured e-mail service to the responsible contact address. Processing is limited to handling your enquiry.