Information in accordance with Art. 13 and 14. GDPR
The party responsible for processing your personal data is the company to which you are submitting a report. The company contact details are:
1. Name and contact details of the controller
- AIT Austrian Institute of Technology GmbH (“AIT”): Giefinggasse 4, 1210 Vienna, office@ait.ac.at, +43 50550-0;
- LKR Leichtmetallkompetenzzentrum Ranshofen GmbH (“LKR”): Lamprechtshausenerstraße 61, 5282 Braunau am Inn - Ranshofen, office.lkr@ait.ac.at; +43 50550-6900;
- Nuclear Engineering Seibersdorf GmbH (‘NES’): Forschungszentrum, 2444 Seibersdorf, office@nes.at, +43 50550-2040;
- Seibersdorf Labor GmbH (‘SL’): Forschungszentrum, 2444 Seibersdorf, office@seibersdorf-laboratories.at, +43 50550-2500
- If the incident did not occur at AIT or if the report does not relate to AIT, AIT will act as a processor under data protection law when receiving and processing the report.
2. Contact details of the Data Protection Officer
The Data Protection Officer of AIT, LKR and NES can be reached at: Giefinggasse 4, 1210 Vienna, dpo@ait.ac.at.
The Data Protection Officer of SL can be reached at: Forschungszentrum, 2444 Seibersdorf, datenschutz@seibersdorf-laboratories.at
3. Processed data, purpose and legal basis of the data processing
Whistleblowers can ask questions and submit reports anonymously. Otherwise, your name, your contact details (if provided), information on submitted reports and their handling as well as any correspondence will be processed.
The following information is processed concerning persons named in reports (persons accused of malpractice, witnesses, etc.): Name, contact details, organisational membership, information from reports and correspondence and information on the handling of reports (procedure, measures taken).
The following information is processed concerning persons who handle questions or reports: (User) name, password, organisational membership, steps taken (procedure). The intended purpose of the processing is the handling of voluntarily submitted questions or comments.
Questions and comments can be submitted on topics that are mandatory under the Whistleblower Protection Act. The legal basis for data processing in these cases is the fulfilment of legal obligations and our legitimate interest in being able to prove the fulfilment of legal obligations.
Questions and comments can also be submitted on topics that we also consider important or relevant to our business. In this case, the legal basis for data processing is our legitimate interest in checking and eliminating violations of internal or external requirements and being able to provide corresponding evidence.
3.1 Cookies
The following cookies are set during use of the whistleblowing system:
Name:
JSESSIONID
Purpose:
Maintaining the connection between your computer and the whistleblowing system
Storage period:
Until the end of your connection to the whistleblowing system
4. Categories of recipients
On behalf of the other controllers, ‘AIT’ handles the categorisation and assignment of reports to the correct contact persons as well as ensuring proper processing as data processor. The company selected during submission of the report is legally responsible for the processing of questions/ reports.
The system is technically operated by EQS Group GmbH (www.eqs.bkms-system.com) – this company is not able to access any personal data.
If necessary to protect the rights of those persons impacted by a report, such persons will be informed of the receipt of reports. The identity of the whistleblower will only be disclosed if it is known and if this is absolutely essential for processing of a report.
Other group companies or public authorities are recipients if this is required for the handling of reports.
5. Storage period:
Personal data is anonymized after five years from the completion of a report. The anonymised report will be deleted after eight years from the completion of a report.
6. Obligation to provide data
The provision of personal data is not mandatory and is voluntary.
7. Your rights
You have the right to obtain information about your stored personal data. You also have the right to have the data corrected or erased. In accordance with the specific conditions laid out in the General Data Protection Regulation, you have the right to request a restriction of the processing or transmission of your data. You also have the right to object to the processing of your data.
Please note that your rights may be restricted under the conditions listed in Section 8 (9) of the Whistleblower Protection Act.
If you are of the opinion that the processing of your data violates the provisions of data protection law, you can lodge a complaint with a data protection supervisory authority. In Austria, the Data Protection Authority (www.dsb.gv.at) is responsible for handling complaints.
If you wish to exercise your rights, please contact the responsible controller named in item 1.
8. Additional information
8.1 File attachments
You have the option of uploading attachments to the system. If you wish to submit an anonymous report, please take note: Files may contain hidden personal data that could jeopardise your anonymity. Please remove all such information before uploading a file.
If you are unable to remove this data or are uncertain about how to do so, copy the text of your attachment into your report text or send the printed document anonymously to the address listed in the footer, citing the reference number received at the end of the reporting process.
Additional information on the processing of personal data can be found at:
- AIT and LKR: www.ait.ac.at/en/disclaimer-data-protection
- NES: https://www.nes.at/en/privacy-policy
- SL: https://www.seibersdorf-laboratories.at/en/company-info/data-protection