Data Protection Notice of KSV1870 Information GmbH for InfoPasses

Data Protection Notice of KSV1870 Information GmbH for InfoPasses

We are committed to ensuring the responsible and scrupulous handling and protection of your data. The purpose of the data protection notice below is to inform you that your personal data will be processed if you use or order an InfoPass product.

We are issuing the following Data Protection Notice for the Product InfoPasses to confirm that the services provided by KSV1870 Information GmbH are in conformity with the law:

Terms used in the General Data Protection Regulation ('GDPR')

In accordance with the GDPR, the terms are defined as follows:

"personal data": any information relating to an identified or identifiable natural person ('data subjects');

"processing": any operation, whether or not performed by automated means, such as the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure, dissemination, alignment or combination, restriction, erasure or destruction of data;

"controller": the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data;

"recipient": a natural or legal person, public authority, agency, etc., to which the personal data is disclosed, whether a third party or not;

"third party": a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;

"processor": a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

"profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;

"consent" of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Controller's name and contact details:

KSV1870 Information GmbH
Company register number: FN 308571g
Wagenseilgasse 7
1120 Vienna

Under data protection law, KSV1870 Information GmbH is controller of the InfoPass products and responsible for the data processing performed in the process.

1. For what purpose is data processed for InfoPasses?

KSV1870 Information GmbH (hereunder also referred to as "we" and "us") is a company operating as a credit reference agency and in the field of automatic data processing and information technology in accordance with the law. We have business licences in accordance with sec. 151 (list compilers and direct marketing companies), sec. 152 (credit reference agencies), and sec. 153 (services in automatic data processing and information technology) of the Industrial Code ("GewO") and operate a company in these areas.

As a credit reference agency, our general aim is to protect entrepreneurs against financial loss and promote liquidity (creditor protection). For this purpose, we provide credit reports and create score models. As a credit reference agency, we process personal data in order to protect the lending and commercial loan sector against loss of accounts receivable. Information on credit standing, payment track records, and payment issues, any behaviour in breach of contract, research and access to this information is intended to minimise the risk of default for third parties. The data processed and, if need be, disclosed to third parties serves to assess this default risk.

The purpose of processing credit standing data is thus to protect creditors from having to grapple with the loss of receivables, to minimise the risk of loss of receivables, but also to prevent fraud, misuse, and money laundering. The purpose of data processing is also to protect the data subjects themselves from becoming over-indebted or from going on a credit binge. This data processing is necessary for us to be able to carry on the trade of a credit reference agency, and also for third-party companies whose services KSV1870 Information GmbH uses, so that effective creditor protection, effective minimisation of the risk of a loss of receivable and the prevention of fraud, misuse, and money laundering can be ensured and guaranteed.

InfoPasses are tools that enable you, as customer and data subject under data protection law, to present the required documents in concentrated and concise form to the party of your choice.

In connection with the product and/or the database and/or data application, your personal data is processed at your proactive request to use and avail yourself of KSV1870 Information GmbH as a service provider. In the case of InfoPasses, you yourself provide the data and documents on a voluntary basis, and these are then supplemented with appropriate information processed by KSV1870 Information GmbH in its operation as a credit reference agency, summarised, and made available to you as a comprehensive document.

The InfoPass is issued at your request, intended for voluntary presentation to third parties of your choice, and meant to support you in your endeavour.

In total, 4 types of InfoPass products are currently available:

InfoPass for Tenants

This InfoPass is for presentation to prospective landlords by tenants or prospective tenants, making it easier to obtain a tenancy agreement.

InfoPass for Authorities

This InfoPass is for presentation to the authorities in administrative procedures, or it can be used as proof or support in procedures.

InfoPass for Applicants

This InfoPass is for presentation to prospective employers or employment agencies by job applicants, making it easier for them to find employment.

InfoPass for Financers

This InfoPass is for presentation to third parties providing financial support in the form of loans, credit, leasing, or other facilities and is intended to help you obtain financing and facilitate the process.

 

When preparing an InfoPass, data is processed for the purpose of providing services to you as data subject in the field of automatic data processing and information technology (carrying on a trade in accordance with sec. 153 Industrial Code) and thus also for the purpose of supporting you as data subject in accomplishing the relevant objective from the list above.

However, data is also processed for the aforementioned purposes of a credit reference agency in that access to information on credit relations is given to you as data subject and indirectly to third parties when you use the InfoPass product and present it to them. Accordingly, data is also processed for the aforementioned purpose of minimising the risk a loss of receivables, for creditor protection, the prevention of fraud, misuse, and money laundering as well as to protect you from becoming over-indebted.

2. Which personal data categories do we process for the InfoPass product?

  • academic degree (applicants);
  • current employer with from-to date (applicants, financers);
  • address type (e.g. rental, ownership, etc.) (financers);
  • number of children (applicants);
  • number of dependent children (financers);
  • date of ID issue;
  • ID number;
  • specific data from the Business Database and the CommercialCreditRecords (ComCR)
  • specific data obtained from the ConsumerCreditRecords (ConCR)
  • specific data obtained from the waning list (WL);
  • reference letters (applicants);
  • former employer with from-to date (applicants, financers);
  • own funds (financers);
  • marital status (applicants, financers);
  • financing total (financers);
  • financing purpose (financers);
  • company name/names of persons;
  • former address;
  • date of birth;
  • salary expectations in EUR (applicants);
  • sex;
  • land owned (financers);
  • marriage certificate;
  • highest level of education completed (applicants);
  • KSV1870 number;
  • copy of ID;
  • URL of LinkedIn profile (applicants);
  • confirmation of registration (Meldezettel);
  • monthly income (financers);
  • monthly fixed costs (financers);
  • name;
  • personal telephone and fax number, and other information required for addressing on account of modern means of communication;
  • collateral (financers);
  • social insurance statement (applicants, financers);
  • criminal record certificate (applicants);
  • title and form of address;
  • university diplomas (applicants);
  • available-from date (applicants);
  • salary group according to the collective bargaining agreement (applicants);
  • salary group years according to the collective bargaining agreement (applicants);
  • home address;
  • preferred maturity (financers);
  • preferred monthly instalment (financers);
  • URL of XING profile (applicants).

3. Where does the data we process come from?

Notice in accordance with Article 13 GDPR

We collect the data processed for the production of an InfoPass directly from you. For the purpose of contract performance and for the production and transmission of an InfoPass, you yourself as data subject under data protection law make personal data available to us. Therefore, this personal data originates from you.

You provide us with your personal data primarily when submitting a request on our website to order an InfoPass. We may also obtain your personal data from you in the course of a telephone call or e-mail correspondence, provided this is necessary to achieve the aforementioned purposes.

Notice in accordance with Article 14 GDPR

However, in addition to this data, we as a credit reference agency may in some circumstances already be processing personal data about you. We may process any such data that is already available for the purpose of carrying on the trade of a credit reference agency without your consent. For more information and details about which personal data and credit information this applies to or may apply to, please see our special data protection notice issued in our capacity as a credit reference agency (https://www.ksv.at/datenschutzerklaerung-ksv1870-information-gmbh-dsgvo).

In performing our contract and with your consent, we also process some of the data already available in the Business Database and the CommercialCreditRecords (ComCR) of KSV1870 Information GmbH when writing up an InfoPass and use this data in the InfoPass product.

With your express consent, order placement, and release from banking secrecy, we also obtain bank-sourced loan and credit data (specific data from the ConsumerCreditRecords, specific data from the warning lists kept by the banks) from Kreditschutzverband von 1870. Therefore, such data comes from Kreditschutzverband von 1870. We use and process this loan and credit data collected for contract performance of the InfoPass only for such contract performance.

4. Lawful basis of data processing for the InfoPass product

The following provisions of the GDPR thus form the lawful basis for such data processing:

  • Article 6(1)(a) and Article 9(2)(a) GDPR (consent to the processing of personal data);
  • Article 6(1)(b) GDPR (necessary for performance of the contract);
  • Article 6(1)(f) GDPR (overriding interest consisting in achieving the aforementioned purposes).

Once the purpose of the contract has been fulfilled or you withdraw your consent, data processing may continue pursuant to Article 6(1)(b), (c) and/or (f) GDPR (legitimate interest). There is a legitimate interest when compliance with retention periods under statutory, tax, and warranty law needs to be ensured and to defend against any liability claims. In any case, data is also processed in order to have proof of provision in the course of a contractual service and proof of the right to collect and retain the agreed fee.

5. Information on the storage period

We retain your data as long as necessary for performance of the contract and fulfilment of the aforementioned processing purposes. This notwithstanding, the data is also retained as long as required to ensure compliance with retention periods under statutory, tax, and warranty law and to defend against any liability claims. 

6. Potential recipients of the personal data that we process

Data that is transmitted to us by you in connection with the preparation of the InfoPass product for the purpose of contract performance with your consent will not be passed on or transmitted to any third party and therefore not to any third country or international organisation.

However, if personal data available to us – which was not transmitted by you – is used to produce the InfoPass product on your behalf, such data may form part of access reports provided to third parties (in accordance with sec. 152 GewO, credit reference agencies).

However, to achieve the purpose and ensure contract performance, we use the services of the following processors:

  • KSV1870 Holding AG for IT services

7. Transmission of personal data

It may become necessary to forward personal data that we have processed to third parties whose services we use and who we provide with data. Personal data is forwarded exclusively on the basis of the GDPR and, as a rule, within the EU. If actions need to be taken outside the EU in individual cases, your data may be transmitted to recipients outside the EU. We will undertake such transmissions only if a relevant adequacy decision has been issued by the European Commission and/or suitable guarantees have been provided or the transmission requires no approval.

8. Data processing information within the scope of score calculation

The InfoPass (authorities, financers, tenants) also indicates a score, which forms an integral part of this product. For conclusion and performance of the contract, a probability needs to be calculated as well. The likelihood of the future occurrence of events is computed by processing personal information and non-personal information as well as past experience. The calculated result is a score.

These scores are generally calculated based on specific information and/or processed data (variables that are introduced) concerning a data subject. This personal data is also fully disclosed in the data subject access report acc. to Article 15 GDPR. Such a report can be sent to you anytime: https://digitalerantrag.ksv.at/Dip/?request=auskunft-nach-art-15-dsgvo

In ordering the InfoPass (authorities, financers, tenants) you are also authorising the processing of this data.

The documents you provide and the probability calculated for this InfoPass (authorities, financers, tenants) are used exclusively to prepare this InfoPass and will not be fed to any other credit reference agency databases of KSV1870 Information GmbH. Please note that this probability variable provided by KSV1870 Information GmbH will not be transmitted and/or forwarded to any third party.

9. Data security

We take the technical and organisational steps required to protect the personal data we process, especially against unauthorised, illegal, or accidental access by unauthorised persons, data tampering, loss, or destruction. Our security measures are continuously improved to comply with the state of the art.

10. Your rights ("data subject rights")

Withdrawal of your consent

For the InfoPass, personal data is also processed with your consent. You have the right to withdraw this consent. However, any such withdrawal will not affect the lawfulness of any processing performed before the withdrawal.

Please note that your data may still be subject to further processing on the legal grounds of contract performance, the fulfilment of a legal obligation, or the existence of an overriding legitimate interest.

10.1. Right to access in accordance with Article 15 GDPR

Fair and transparent processing of data is important to us. In accordance with Article 15(1) GDPR, you have the right to obtain confirmation as to whether or not personal data is being processed, and you have the right to access such information. This right of access allows you to establish which of your data we store for the purpose of operating as a credit reference agency and list compiler. 

10.2. Right to rectification

Data accuracy is our goal. According to Article 16 GDPR, you have the right to obtain, without undue delay, the rectification of any inaccuracy in your personal data and to request, with due consideration of the purposes of the processing, the completion of incomplete personal data – including by providing a supplementary notice. Proof for this must be provided in writing so as to ensure transparent processing.

10.3. Objection and erasure requests

Furthermore, Article 21 GDPR gives you the right to object to the processing of personal data concerning you based on Article 6(1)(e) or (f) GDPR at any time on grounds relating to your particular situation.

Your objection in accordance with Article 21 GDPR will be assessed individually and dealt with in accordance with the relevant standards.

Furthermore, you have the right to erasure of processed personal data concerning you on the basis of Article 17 GDPR. In the event of erasure requests in accordance with Article 17 GDPR, an assessment is performed in each individual case to establish whether the available data is no longer needed for the purposes it was collected for, and this data is erased where appropriate.

10.4. Restriction of processing

Article 18 GDPR also provides for the right to have processing restricted where one of the following applies:

  • you contest the accuracy of the personal data, for a period enabling us to verify the accuracy of the personal data;
  • the processing is unlawful, and you oppose erasure of the personal data and request the restriction of their use instead;
  • we no longer need the personal data for processing purposes, but you yourself require the data for the establishment, exercise, or defence of legal claims;
  • you have objected to processing pursuant to Article 21(1) GDPR pending the verification whether our legitimate grounds override your grounds.

Where processing has been restricted in accordance with the above, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise, or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a member state.

10.5 Receipt of personal data in a structured, established, and machine-readable form

If your personal data has been processed using an automated procedure and on the basis of your consent or a contract signed with you, you have the right, pursuant to Article 20 GDPR, to receive this processed personal data in a structured, commonly used, and machine-readable format.

10.6. You can address these requests to us

If you wish to exercise your right, please let us know. Our contact details are: KSV1870 Information GmbH, company register no. 308571g, 1120 Vienna, Wagenseilgasse 7.

10.7. Data Protection Authority

If you believe that your data is being processed in breach of data protection law or your rights under data protection law have been otherwise infringed, you also have the right to file a complaint with the Data Protection Authority of the Republic of Austria with the address: 1030 Vienna, Barichgasse 40-42. 

10.8. Data protection officer

You can reach our data protection officer "Putz & Rischka, Rechtsanwälte KG" at ksv1870.datenschutzbeauftragter@ksv.at and by regular mail at Reisnerstraße 12, 1030 Wien.