To the content
PageHeaderDefaultBackground.svg

Privacy statement

The lawful handling of personal data is an important foundation for the day-to-day work of Austrian Power Grid AG (APG, also referred to in the following as “we” and “us”).

The following sections describe how your personal data is processed when you visit our website.

APG shall store and use all data that is transmitted or disclosed via APG webpages in accordance with the applicable legal requirements, in particular the Austrian Data Protection Act (Datenschutzgesetz, DSG) and the General Data Protection Regulation (GDPR). It is neither a contractual nor legal requirement to process the personal data that we process while our website is being used. You are not obliged to provide personal data. However, the non-provision of personal data would mean that our website cannot be used. We do not use your personal data to carry out automated decision-making, including profiling.

APG makes every reasonable effort to make the exchange of this data as secure as is currently technically and procedurally possible, for instance by securely encrypting the data being transmitted. At the same time, users are requested to make their own reasonable efforts to keep their access data for online services confidential.
 

1. Name and address of the controller and method of contacting the data protection officer

Austrian Power Grid AG
Wagramer Straße 19
1220 Wien (IZD-Tower)
Österreich

If you have any questions or you would like to exercise any affected rights, you can contact our data protection officer at datenschutz@apg.at.

 

2. Data processing

2.1 Application management

2.1.1 Subject matter and purpose of processing

APG provides applicants with a facility to make an online application. The personal data that is processed as part of an online application includes:

  • key applicant details (name, title, e-mail address, postal address, telephone number, date of birth, citizenship, candidate ID);
  • CV, in particular details of professional experience and education;
  • cover letter from the applicant;
  • photograph (optional);
  • qualifications, awards and language skills;
  • files and documents (for example certificates) that may be uploaded;
  • details in additional data fields;
  • interview notes from job interviews;
  • result from the PEP (politically exposed person) check; and
  • criminal record extract.

APG processes your personal data for the purpose of corresponding with you and handling your application. In addition, we may process personal data insofar as this is necessary to defend us against legal claims made against us.

2.1.2 Retention period

We process personal data for a period of six months, starting from the day on which the selection process ends. If you consent to us keeping your details on file, APG shall store personal data for a period of up to three years.

2.1.3 Legal basis

The legal basis for processing this personal data is provided by the employment contract, should one be concluded. The legal basis in this case is Article 6(1)(b) GDPR.

If you have consented to us keeping your details on file, the legal basis for the processing of this personal data is provided by your voluntary consent in accordance with Article 6(1)(a) GDPR.

2.1.4 Recipients

We use the services of New Work SE, Strandkai 1, 20457 Hamburg, Germany as the processor for the technical and administrative aspect of processing your data.

 

2.2 Processing activities as part of website operation

2.2.1 Newsletter

2.2.1.1 Subject matter and purpose of processing

The e-mail address you have provided is processed by APG for the purpose of registration and delivery of the APG newsletter. The newsletter shall be transmitted regularly in connection with current topics and events relating to APG.

In addition, we measure the performance of the newsletter by recording the opening and click behaviour. Specifically, the following information is tracked anonymously: time of delivery, time of opening, period of opening, e-mail client used, which link was clicked and the time of the click.

2.2.1.2 Retention period

We process your e-mail address until such time that the consent agreement is revoked by the data subject.

2.2.1.3 Legal basis

We process the personal data on the basis of your consent in accordance with Article 6(1)(a) GDPR.

2.2.1.4 Recipients

We use the services of eworx Network & Internet GmbH, Hanriederstraße 25, 4150 Rohrbach-Berg, Austria for the delivery and analysis of the newsletter.

 

2.2.2 Events

2.2.2.1 Subject matter and purpose of processing

APG processes your personal data for the purposes of event registration and organisation, and for communication purposes (see Newsletter). This includes the holding of online events. The following personal data is processed in relation to this:

  • first name, last name;
  • company;
  • e-mail address;
  • telephone number; and
  • photographs.

2.2.2.2 Retention period

We process your personal data until such time that the consent agreement is revoked by the data subject.

2.2.2.3 Legal basis

We process the personal data on the basis of your consent in accordance with Article 6(1)(a) GDPR.

2.2.2.4 Recipients

We transmit your personal data to the following service providers as part of handling events: eworx Network & Internet GmbH, Hanriederstraße 25, A-4150 Rohrbach-Berg.

 

2.2.3 Log data

2.2.3.1 Purposes of processing

Each time the APG website is requested, the system records information and data from the computer system of the requesting computer. This recording happens automatically. This is necessary so that we can supply our content to the user’s computer. Furthermore, it allows us to ensure the functionality of the website, to optimise it, and to maintain the security of our IT systems.

 

2.2.3.2 Subject matter, purposes, legal basis and retention period

Types of data

Purposes

Legal basis

Period of processing

  • browser type and browser version
  • referrer URL
  • date and time of server request
  • IP address
  • http method and http version

technical transmission of our content

Article 6(1)(f) GDPR in conjunction with Section 165(3) of the Austrian Telecommunications Act 2021 (Telekommunikationsgesetz, TKG 2021)

one year

2.2.3.3 Recipients

APG uses service providers to provide the APG website, for example for handling technical matters. These service providers process your data on our behalf. We use the services of the following processors:

  • hosting provider (Conova Communications GmbH, Karolingerstraße 36a, 5020 Salzburg, Austria); and
  • content management provider (digitalwerk gmbH, Getreidemarkt 1/10, 1060 Vienna, Austria).


2.2.4 Cookies and comparable technologies

In addition, cookies and comparable technologies are used when a visit is made to our website. These temporary files contain, for instance, the information that a user has previously visited one of our webpages. This allows the website to “recognise” that it is the same user and adapt the presentation of content from the website.

Technically necessary cookies are placed automatically when a visit is made to our website so that we can offer you the best possible website experience. When using functional cookies, APG processes your personal data to enable basic website functions and to provide you with the services you have requested. The cookie banner that is displayed enables you to choose whether you would also like to allow additional cookies for analytical and statistical purposes.

The use of cookies can be disabled by users themselves at any time by means of their own browser settings. If they are disabled, however, we are no longer able to guarantee the absence of technical faults when using our website. If you click “Accept all cookie”, you are consenting to the use of all cookies.

Below is a collection of links where you will find detailed information on disabling cookies in popular browsers:

A summary of the cookies used can be found in the table below.

2.2.4.1 Matomo Analytics

To improve the user-friendliness of the website, we use the Matomo open-source web analytics tool that places non-functional cookies.

When using non-functional cookies and subsequently analysing user data, we process personal data so that we can learn about the preferences of our website visitors and better personalise our offering.

Your IP address is recorded as part of this but is immediately pseudonymised through the erasure of the last three digits. This means that only rough geolocation is possible.

You can find the specific purpose, the types of data processed and the retention period for individual cookies in the table below.

We process the personal data on the basis of your consent in accordance with Article 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021. You can revoke your consent at any time without reason in the cookie settings of your browser. Revocation of consent does not affect the lawfulness of consented processing operations that occurred up until the revocation.

To run Matomo, we use the services of Matomo Cloud, operated by ePrivacy Holding GmbH, Große Bleichen 21, 20354 Hamburg, Germany.

2.2.4.2 Youtube-Plugin

YouTube is a service provided by Google LLC and offers Google LLC plugins that allow webpage operators to embed videos. APG uses the YouTube plugin on its APG webpages. 

The following types of data, among others, may be collected when embedding the YouTube plugin provided by Google LLC:

Screen.prototype.availTop, window.screenTop, window.screenLeft, Navigator.prototype.mediaCapabilities, Navigator.prototype.getBattery, window.screenX, window.screenY, window.outerWidth, window.outerHeight, Navigator.prototype.hardwareConcurrency, Navigator.prototype.onLine, Screen.prototype.availWidth, Screen.prototype.availHeight, HTMLCanvasElement.prototype.toDataURL, Intl.DateTimeFormat.prototype.resolvedOptions, window.indexedDB, window.devicePixelRatio, MediaSource.isTypeSupported, WebGLRenderingContext.prototype.getParameter, WebGLRenderingContext.prototype.getExtension, Date.prototype.getTimezoneOffset

Screen.prototype.colorDepth, Navigator.prototype.connection, Navigator.prototype.cookieEnabled, window.innerWidth, URL.createObjectURL, window.innerHeight, Screen.prototype.height, Screen.prototype.width, Navigator.prototype.mimeTypes, PerformanceTiming.prototype.navigationStart, Navigator.prototype.language, HTMLMediaElement.prototype.canPlayType, NavigatorUAData.prototype.brands, Navigator.prototype.plugins, window.matchMedia("prefers-color-scheme"), window.sessionStorage, window.localStorage, Document.cookie setter, Document.cookie getter, Date.prototype.getTime, Navigator.prototype.userAgent, Event.prototype.timeStamp.

In addition, basic data, such as IP address and time stamp, is transmitted.

Information on the cookies used is summarised in the table below.

The aforementioned personal data can be used to create a digital “fingerprint” which means you can be identifiable to Google LLC.

We process the personal data on the basis of your express consent in accordance with Article 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021 in conjunction with Article 49 GDPR.

The embedding of the YouTube plugin means that your personal data shall also be processed by Google LLC which is headquartered in the USA. The USA is not certified by the European Court of Justice as offering an appropriate level of data protection. There is therefore a risk, in particular, of your personal data being accessed by US authorities for control and surveillance purposes, and against which there are no effective means of address. You can revoke your express consent for this at any time without reason.

You can find further information on Google data protection provisions at policies.google.com/technologies.

2.2.4.3 Summary of cookies and other technologies used

The following cookies and other technologies are used on the APG website

Types of data/name of cookie or comparable technology

Provider/recipient of personal data

Legal basis

Purpose of processing

Processing period

Functional cookies or comparable technologies

cookiesAccepted

n/a

legitimate interest as defined under Article 6(1)(f) GDPR in conjunction with Section 165(3) TKG 2021

stores the user’s permission status from the cookie banner

one year

cookiesClosed

n/a

legitimate interest as defined under Article 6(1)(f) GDPR in conjunction with Section 165(3) TKG 2021

stores the user’s permission status from the cookie banner

one year

PHPSESSID

n/a

legitimate interest as defined under Article 6(1)(f) GDPR in conjunction with Section 165(3) TKG 2021

stores the session status in connection with application management

session1

Non-functional cookies or comparable technologies

_pk_ref

Matomo Analytics

consent

records the website from which you are visiting us

six months

_pk_cvar

Matomo Analytics

consent

contains user-defined variables that were set when the page was last viewed

30 minutes

_pk_id

Matomo Analytics

consent

stores a one-off user ID

13 months

_pk_ses

Matomo Analytics

consent

shows a user’s active session

30 minutes

CONSENT

Youtube

consent

stores the permission to embed YouTube videos

two years

VISITOR_INFO1_LIVE

Youtube

consent

stores the user settings when requesting a YouTube video that is integrated on other webpages

one year

YSC

Youtube

consent

session1

yt-remote-connected-devices

Youtube

consent

persistent

yt-remote-device-id

Youtube

consent

persistent

yt.innertube::nextId

Youtube

consent

persistent

yt.innertube::requests

Youtube

consent

persistent

ytidb::LAST_RESULT_ENTRY_KEY

Youtube

consent

persistent

yt-remote-fast-check-period

Youtube

consent

stores video preferences from embedded videos

session1

yt-remote-session-app

Youtube

consent

session1

yt-remote-session-name

Youtube

consent

session1

1 Usually the duration of a session is based on how long you have the browser window open.

2.3 Competitions

The following section outlines how your personal data is processed when you participate in APG GAMIFY event competitions.

APG will store and use all data communicated or disclosed in connection with the participation in GAMIFY event games in compliance with the applicable statutory provisions, in particular the Austrian Data Protection Act (DSG) and the General Data Protection Regulation (GDPR). The processing of personal data is neither contractually nor legally required. You are not obliged to provide your personal data. However, failure to provide personal data would mean that you cannot enter APG GAMIFY games. We do not use your personal data for automated decision-making or profiling.

"GAMIFY" event games are provided by dMAS GmbH which acts as a contractor of Austrian Power Grid AG in this context. The personal data are processed directly by dMAS GmbH and made available to Austrian Power Grid AG.

2.3.1 Object and purpose of processing

APG provides access to the GAMIFY event games. In this context, the following personal data are being processed:

  • First name
  • Surname
  • E-Mail address
  • Date of birth
  • School / Training institution
  • Zip code
  • Country

APG processes your personal data for participation in the competition in the context of the current event, as well as for contacting you for job offers or invitations to other APG events. In addition, we may process personal data if this is necessary to defend against legal claims asserted against us.

2.3.2 Duration of storage

We store the personal data until you revoke your consent, starting on the day you enter your personal data when participating in GAMIFY games.

2.3.3 Legal basis

We base the processing of this personal data on the legal basis of your consent according to Article 6, paragraph 1, item (a) of the GDPR.

If you have consented to the storage of your data, we base the processing of this personal data on the legal basis of your voluntarily given consent in accordance with Article 6, paragraph 1, item (a) of the GDPR.

2.3.4 Recipient

The personal data will not be passed on to any other recipients.

 

 

2.4 Video surveillance

2.4.1 Subject matter and objectives of the data processing

APG operates video surveillance systems on its company premises, offices, and construction sites. This video surveillance is used to investigate criminal offenses, protect visitors and employees, exercise property rights, preserve evidence in the event of damage, prevent vandalism, and protect property and possessions. The personal data used for processing includes

  • video recordings
  • license plates

2.4.2 Duration of storage

The recordings of the video surveillance systems are stored for 30 days.

2.4.3 Legal basis

The legal basis for the video surveillance is the ‘legitimate interests’ clause as stipulated in Article 6, paragraph 1, item (f) of the General Data Protection Regulation (GDPR).

2.4.4 Recipients

The recordings of the video surveillance systems are not passed on to any third party except for civil or criminal proceedings, or similar actions that are conducted or initiated in connection with the processing objectives.

2.5. Appointment booking

2.5.1.  Object and purpose of processing

APG processes your personal data as part of the online appointment booking with MS Bookings for the purpose of organising a guided tour through the control centre. The following data is collected:

  • First name
  • Surname
  • Organisation name
  • e-mail address

2.5.2 Storage period

We process personal data until cancellation, starting on the day you enter your personal data when using MS Bookings.

2.5.3 Legal basis

The legal basis for the collection of data is consent.

2.5.4 Recipients

Microsoft Bookings is part of Microsoft Office 365, which is software from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.

 

3. Rights of data subjects

You have the following rights with regard to the processing of your personal data:

Right to revoke consent

Insofar as we process data concerning you on the basis of your consent (Article 6(1)(a) GDPR), you can revoke your consent at any time. We will no longer process your personal data from the receipt of your revocation. However, revocation of consent does not affect the lawfulness of processing operations that occurred up until the time of revocation.

Right of access

You can request access to the personal data concerning you that is being processed. Upon request, we shall provide you with a copy of the personal data concerning you that is being processed. Please note that access is not granted if this puts at risk trade or business secrets of the controller or a third party.

Right to rectification

If we process data concerning you that is inaccurate or incomplete, you can request that it is rectified or completed.

Right to erasure

You have the right to request that we erase personal data concerning you. We are happy to erase personal data insofar as this is provided for in the GDPR. For instance, personal data shall not be erased if the processing of the data is required to fulfil a legal obligation or to assert, exercise or defend legal claims.

Right to restrict processing

Under certain conditions you can request that we restrict the use of your personal data. This is the case, for instance, if the accuracy of the personal data concerning you is in dispute, specifically for the time needed to check the accuracy.

Right to object

Insofar as your personal data is processed on the basis of legitimate interests (Article 6(1)(f) GDPR), you are entitled to file an objection for reasons arising from your particular situation. In this case we shall no longer process your data unless there are imperative grounds for processing that merit protection which override your interests, rights and freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims.

Right to data portability

If we process personal data provided by you on the basis of your consent or in order to perform a contract, you can request to receive this data or that we transmit it to another controller.

Right to complain

If you believe that the processing of your personal data infringes the GDPR, you are, of course, welcome to contact us at datenschutz@apg.at at any time.
In addition, you are entitled to file a complaint with the Austrian Data Protection Authority.

 

 

To the main navigation