Legal information

Commitly GmbH Privacy Policy

Personal rights in connection with data protection are important to COMMITLY. Therefore, we place a high value on the confidentiality of your personal information. We have written this policy to explain what information we collect, how we use it and what choices you have.

Please take sufficient time to familiarise yourself with our privacy practices and contact us if you have any questions.

A. Definitions

  1. "We" or "Commitly" is Commitly GmbH, FN 476463 g, Commercial Register Court Wiener Neustadt, with its registered office at Dr. Clemens Pirquet-Strasse 43, 2380 Perchtoldsdorf, (″Commitly″).
  2. "You" or "User" means a natural person who creates a user account with Commitly for the use of the Commitly App as a Consumer and/or makes a request to Commitly to do so.
  3. The "Commitly Website" is the website created by Commitly and used for marketing purposes.
  4. The "Commitly App" is a software application created and offered by Commitly. You can use the Commitly App by accessing the corresponding website (web app).
  5. "Privacy Policy" means this policy which provides you with guidance on what data is collected from you by Commitly and how it is processed. When you create a user account, you will be notified of the Privacy Policy. We reserve the right to amend the above privacy policy at any time in compliance with current legal requirements. You will be notified of any updates by e-mail to your registered e-mail address. This notice will also inform you of your right to object (which you can exercise immediately by deleting your account) and the consequences of objecting. If the updated Privacy Policy is the reason why you no longer wish to use Commitly, you may delete your user account at any time until the update comes into effect. This will terminate the user relationship with Commitly.
  6. "Personal data" means the data of an individual which personally identifies him or her, such as his or her name, e-mail address or telephone number, or any other non-public data in this context.
  7. "Service Providers" means providers of software or remote communications-based services and companies used by Commitly to process payments or provide technical services.
  8. "Anonymous data" is data that is not related to personal data. Anonymous data can no longer identify an individual person.

B. General

  1. Commitly GmbH, FN 476463 g, Commercial Register Court Wiener Neustadt, Dr. Clemens Pirquet-Strasse 43, 2380 Perchtoldsdorf, (″Commitly″) offers you the possibility to unlock data on incoming and outgoing payments from bank and credit card accounts as well as other payment services for viewing and to analyse and evaluate them according to certain criteria, as well as to be informed about movements in your accounts through a notification function.
  2. Commitly collects, uses and processes your personal data exclusively within the framework of the provisions of Austrian data protection law. In the following, we inform you about the type, scope and purpose of the collection and use of personal data. You can access this information at any time on our website Commitly.com.

C. Data protection principles

  1. We undertake to treat all personal data of yours that is forwarded to us in accordance with the applicable Austrian data protection laws. This means in particular that we will not pass them on to third parties. We also undertake to collect, record, store, modify, block or delete personal data protected by the Federal Data Protection Act only for the purpose of lawfully fulfilling our tasks. The data will not be used for purposes other than the legitimate fulfilment of tasks.
  2. Our technical infrastructure reliably prevents unauthorised third parties from viewing and changing the data stored with us (data security and integrity). In doing so, we ensure through the selection of the location of our data centre that European law is adhered to by our service providers.
  3. The data we collect is either provided by you when you use the Commitly app or take advantage of features and services, or is generated during use. User data is always necessary so that the Commitly app can be used as desired.
  4. The data created by you in the course of using the Commitly App and services and/or functions within the Commitly App, in particular via the login (insofar as you select this) and the application, are stored on dedicated servers in the highly secure data centre of Amazon Web Services (AWS) in Frankfurt, but are not used or processed in any other way by the server service provider.

D. Data provided by you

  1. When you register, for example by registering and then logging in, you leave basic data (including information on how you found us on the internet) which is transmitted to us. This data is provided by the registration form and is collected, stored and used exclusively for the use of the Commitly app and its services. Via this login data, we may inform you about changes, additions or new versions of the Commitly app and information provided via the website, as well as, for example, news about the website/app.
  2. Registration for a newsletter can be done either via a login or by registering with an e-mail address. In the case of the e-mail address, no further information is required. However, you are free to provide further information of your own accord when registering for the newsletter. By registering for the newsletter, you as the subscriber expressly agree that the registration confirmation and the newsletter will be sent to the e-mail address provided.
  3. Within the scope of the newsletter subscription as well as within the scope of the registration, we are also entitled to inform you about changes, additions or new versions of the website or the Commitly app and the functions offered via it and information made available via the website as well as e.g. news about the available banks.
  4. As part of and to enable the use of the Commitly App or the provision of the functions set out in the User Agreement, Commitly collects various types of data, some of which is provided by you and some of which is necessary for or arises from the use of the Commitly App and the related provision of services.

E. Use of the Commitly app or services/services

COMMITLY uses analytics services to help us better understand how you use our website and applications. This helps us to develop the COMMITLY experience and gradually improve our communication with you.

  1. In order to improve the quality and security of our service, we store for statistical purposes the data about each access to the pages of the Commitly app that your browser/app transmits whenever you visit the website/use the app. These server logs contain data such as your web request/call for use, your IP address, browser type, browser language, date and time of your request and one or more cookies by which your browser can be uniquely identified, as well as general information, for example when errors occur, and the information from security events (change of password, password recovery, change of e-mail address), as these are necessary for use. The IP address is stored in a shortened form in accordance with data protection regulations.
  2. When you visit our website and as part of the service delivery process, the website sends one or more cookies - small files containing a string of characters - to your computer or other device, which uniquely identifies the browser. We use cookies to improve the quality of the website, including to store user preferences and track user trends, and to measure how you found our website and services on the internet. We may place one or more cookies in your browser when you visit the website or sub-pages. You can set your browser to notify you when a cookie is sent. This opens up the possibility of either accepting or rejecting a cookie. The data we collect and analyse is used to improve services and the website, to personalise the web experience, and to enable easy login when login cookies are set permanently.
  3. We use third-party services to help us assess the effectiveness of the Commitly App and Services and to determine how you use the Commitly App and/or Services. To do this, we may use tracking pixels (web beacons) on the Commitly App pages that the third party providers provide to Commitly for this purpose. The information we collect includes pages visited, navigation patterns and similar data. This statistically collected data enables us to find out which services within the Commitly app are of most interest to users and which offers users prefer to view. Although the provider logs the data coming from our website on our behalf, we have control over how this data can or cannot be used. While the cookie itself does not contain any personal data, if you provide personal data (such as your user ID) when visiting the website and do not delete the cookie from your browser after providing this data, the provider will collect the non-personal data stored in the cookie (such as the number of visits) and store it anonymously.

F. Our services

Registration - User account ("Account")

  1. In order to use our services, you must first register with us on the platform. To do this, you must open an account and enter your email address and a password. You complete the registration by entering your personal data, such as name and first name. We store this data for the duration of the platform contract under assignment to your account.
  2. In order to make the best possible use of the services offered by Commitly, you can add further personal details to your profile information on the platform at any time in the electronic forms provided for your account. We will also store this data for the duration of the platform contract.

Registration to retrieve account data ("bank details")

  1. In order to activate one or more bank, credit card and/or payment service accounts of your company on the platform, we collect and process the following additional personal data: Account number and bank code or IBAN and BIC, user ID / login and PIN or password ("Access Data").
  2. Commitly does not at any time store the access data entered by you for the purpose of the account connection.
  3. Of course, you can remove the linked bank, credit card and/or payment service accounts at any time.

Provision and use of your account data ("synchronisation")

  1. As part of the synchronisation, data on account balances, incoming and outgoing payments of your company ("Transactions") of your bank, credit card and/or payment service accounts activated by you on the Platform will be transmitted to us by the respective account-holding institutions.
  2. These transactions
  • we store during the term of the platform contract existing with you,
  • We use and process the data in order to present it to you in overviews for your information within the framework of planning - including analyses and evaluations - in your password-protected user area on the platform,
  • We use and process your personal data to keep you informed about movements in your activated accounts via notifications.

G. Commissioned data processing

COMMITLY uses third party service providers to provide you with the services of the COMMITLY app. For more information, please refer to our commissioned processing agreement pursuant to Art. 28 DSGVO, which is concluded between the Commitly customer (controller or principal) and Commitly GmbH (processor or contractor).

finAPI GmbH (interface provider)

The provision of the transaction data within the scope of the account information service is carried out by the external interface provider finAPI GmbH ("finAPI"), Ainmillerstraße 11, 80801 Munich, which processes the data under the supervision and exclusively according to the instructions of Commitly. finAPI, as a German company, is bound by German data protection law. The access data to accounts & cards are additionally stored encrypted at finAPI. Commitly has no access to this access data. A corresponding contract on the processing of personal data on behalf has been concluded between finAPI and Commitly.

https://www.finapi.io/

Chargebee (subscription management)

Parts of your personal data (name of your company, first and last name) are used to identify you and your company and to check the payment methods offered. As part of the registration process, your first name and surname are passed on to the service provider ChargeBee (Chargebee Inc., 340 S Lemon Avenue, #1537, Walnut, California 91789, USA). In addition, your payment data such as credit card and bank data (depending on the payment method selected by you) are collected, used and processed for the purpose of payment processing as well as passed on to payment service providers and the credit card company or bank specified by you in each case and used and processed by them. Commitly does not store any credit card data in connection with a transaction at any time.

https://www.chargebee.com/

Braintree Payment (payment processing)

Commitly uses Braintreee Payments ("Braintree") as its payment gateway. Braintree is a service of PayPal (Europe) S.à r.l. et Cie, S.C.A.. Braintree is used exclusively to process payments between Commitly and its users. For this purpose, the credit card data recorded in Chargebee is transmitted to Braintree for further processing.

https://www.braintreepayments.com/at/legal

Intercom (Customer Experience)

We use third party services to help us better understand how you use Commitly. Specifically, we submit some of your information (such as your email address and the date you registered) to Intercom, Inc ("Intercom") and use Intercom when you visit our website or use our product to collect data for analytics purposes. Intercom analyses your use of our website and/or product and tracks the development of our customer relationship so that we can improve our service to you. We also use Intercom as a medium for communication, either by email or in the form of messages within our product(s). We also use Intercom to provide you with a help section.

https://intercom.io/

Mailchimp (Newsletter Management)

When sending our newsletter to registered interested parties and when sending transactional emails to users, we use Mailchimp (a brand of The Rocket Science Group, LLCm, Georgia, USA) as part of commissioned data processing. Mailchimp has been carefully selected by us as a specialised service provider and is regularly audited by us to ensure that your privacy is protected. Mailchimp will only process your personal data on our behalf and on our instructions and may only use your personal data for the purposes specified by us. Compliance with these data protection provisions and the necessary security measures is guaranteed at all times.

https://mailchimp.com

Zendesk (Support Management)

We use the customer support system "Zendesk", from the provider Zendesk, Inc., 989 Market Street #300, San Francisco, CA 94102, USA, in order to be able to process user enquiries more quickly and efficiently (legitimate interest pursuant to Art. 6 Para. 1 lit. f. DSGVO ).

Zendesk only uses the users' data for the technical processing of the requests and does not pass them on to third parties. To use Zendesk, at least a correct email address is required. A pseudonymous use is possible. In the course of processing service requests, it may be necessary to collect further data (name, address). The use of Zendesk is optional and serves to improve and accelerate our customer and user service.

If users do not consent to data collection via and storage in Zendesk's external system, we provide them with alternative means of contact for submitting service requests by email, telephone or post. For more information, users should consult Zendesk's privacy policy: 

https://www.zendesk.de/company/customers-partners/privacy-policy

Hubspot (CRM Management)

This website uses HubSpot. HubSpot is a software solution for the control and realisation of inbound marketing. The saved information is stored on HubSpot servers. It can be used by us to contact visitors to our website and to determine which of our company's services are of interest to them. All information we collect is subject to this privacy policy.

We use all information collected exclusively to optimise our marketing. HubSpot is a software company from the USA with a branch in Ireland. Contact: HubSpot, 2nd Floor 30 North Wall Quay, Dublin 1, Ireland, Phone: +353 1 5187500.

HubSpot is subject to TRUSTe 's Privacy Seal and the U.S. - EU Safe Harbor Framework and the U.S. - Swiss Safe Harbor Framework. For more information, please see HubSpot Legal Stuff (general information about HubSpot and privacy).

https://legal.hubspot.com/de/privacy-policy

H. Use of tracking tools

  1. In order to make visiting the Commitly website and the Commitly app attractive and the use of certain functions more user-friendly, effective and secure, we use so-called cookies on various pages. These are small text files that are stored on your terminal device assigned to the browser you are using and through which certain information flows to the body that sets the cookie (in this case, us). Cookies cannot execute programs or transmit viruses to your end device.
  2. Most of the cookies we use are so-called "session cookies". They are automatically deleted after the end of your visit to our website. In addition, we use cookies that remain stored on your terminal device after the end of your visit to our website until you delete them. These cookies enable us to recognise your browser on your next visit.
  3. You can also set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, however, the functionality of our website may be limited.

Google Analytics

  1. Our website uses Google Analytics, a web analytics service provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
  2. The information generated by the cookie about your use of our website will be transmitted to and stored by Google on servers in the United States. As this website uses Google Analytics with the extension "_anonymizeIp()", your IP address will, however, be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area, so that a direct personal reference can be excluded. Only in exceptional cases will the full IP address be transmitted to a server by Google in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator.
  3. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
  4. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. In addition, you can prevent the collection of the data generated by the cookie and related to your use of the website (incl. your IP address) to Google as well as the processing of this data by Google by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=de.3.
  5. Google Analytics is used in accordance with the conditions agreed with Google by the German data protection authorities. Information of the third party provider: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001.

Google's Terms of Use:

http://www.google.com/analytics/terms/de.html

Google privacy overview:

http://www.google.com/intl/de/analytics/learn/privacy.html

Privacy policy of Google:

http://www.google.de/intl/de/policies/privacy.

Use of Google Remarketing

  1. Our website uses the remarketing function of Google Inc. This function is used to present interest-based advertisements to visitors of the website within the framework of the Google advertising network.
  2. The website visitor's browser stores cookies, i.e. text files that are stored on your computer and enable the visitor to be recognised when they visit websites that belong to Google's advertising network. On these pages can then present the visitor with advertisements that relate to content that the visitor has previously accessed on websites that use Google's remarketing function. According to its own information, Google does not collect any personal data during this process.
  3. If you still do not wish to use Google's remarketing function, you can deactivate it in principle by changing the corresponding settings under

http://www.google.com/settings/ads make.

Alternatively, you can disable the use of cookies for interest-based advertising via the ad network initiative by following the instructions at

http://www.networkadvertising.org/managing/opt_out.asp follow

Further information on Google Remarketing and Google's privacy policy can be found at:

http://www.google.com/privacy/ads/

Google Ad Words

  1. As an AdWords customer, we also use Google Conversion Tracking, an analysis service provided by Google Inc (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). Google Adwords sets a cookie on your computer ("conversion cookie") if you have accessed our website via a Google ad. These cookies lose their validity after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, we and Google will be able to recognise that the user has clicked on the ad and has been redirected to this page . Each Google AdWords customer receives a different cookie. Cookies can therefore not be tracked via the websites of AdWords customers. The information obtained using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. The customers learn the total number of users who clicked on their ad at and were redirected to a page marked with a conversion tracking tag. However, they do not receive any information with which users can be personally identified.
  2. If you do not wish to take part in the tracking procedure , you can also refuse the setting of a cookie required for this - for example, by means of a browser setting that generally deactivates the automatic setting of cookies . However, we would like to point out that in this case you may not be able to use all the functions of this website to their full extent. You can also deactivate cookies for conversion tracking by setting your browser to block cookies from the domain "googleadservices.com". You can find out more about Google's privacy policy at

http://www.google.de/policies/privacy/

Sentry

We use the Sentry service (Sentry, 132 Hawthorne St, San Francisco, CA 94107, USA) to improve the technical stability of our services by monitoring system stability and identifying code errors. Sentry serves these purposes alone and does not evaluate data for advertising purposes. For further information, please refer to Sentry's privacy policy:

https://getsentry.com/privacy/

J. Communication

  1. If you send email messages or other communications to us or enter them directly on the website/Commitly app, we, as a provider, retain such communications in order to process your request, respond to questions and improve the website, products, features/services and services.
  2. Communication within the Commitly app takes place exclusively via an encrypted internet connection and is stored on servers connected to the internet. In addition, e-mails and, if necessary, push messages are sent directly to the end device as part of the communication.

K. Your rights as a user

  1. You have the right at any time to enquire free of charge about the data collected about you. You have the right to revoke your consent to the use of your personal data at any time with effect for the future. To request information or to revoke your consent, please contact Commitly at support@commitly.com. We will then provide the information without delay.
  2. If you so wish, we will, at your request, delete your data stored with us completely in accordance with your instructions. However, this may mean that you can no longer use the website and, where applicable, services and/or functions within the Commitly app. In this case, you are entitled to an extraordinary right of termination for existing contractual relationships without, however, incurring any claims for compensation against Commitly.
  3. However, in the event of the existence of and for the duration of statutory retention obligations as well as within the scope of data backup, we are entitled to continue to store data including backups and logs that have otherwise been ordered to be deleted and to use and process data to the extent necessary to comply with the statutory obligation.

L. Data security

  1. The data storage and processing of data collected within the scope of services or in any other way is carried out on servers on behalf of Commitly. Within the scope of commissioned data processing, Commitly ensures compliance with data protection regulations and the contents of the data protection declaration by means of suitable technical, organisational and contractual measures.
  2. Commitly takes the necessary security measures to protect data from unauthorised access and to prevent the unauthorised modification, disclosure or destruction of data. This includes internal audits of data collection and data storage and processing practices and security measures, as well as physical security measures to protect against unauthorised access to the systems on which personal data is stored.

M. Contact

For information or explanations regarding the use of your data, please contact:

Commitly GmbH

Dr. Clemens Pirquet-Strasse 43
2380 Perchtoldsdorf

E-mail: support@commitly.com

(Status: 28.03.2020)

20200328_Data privacy