Privacy Policy

1. Introduction

Protecting your personal data is extremely important to us. We therefore handle your personal data in accordance with the applicable legal provisions on the protection, lawful handling and confidentiality of personal data, in particular in accordance with the Austrian Data Protection Act (hereinafter referred to as “DPA”) and the General Data Protection Regulation (hereinafter referred to as “GDPR”). The information below explains how we process your personal data when you use our website (www.mezzalite.com) (hereinafter referred to as the “website”) or our web app (“app.mezzalite.com”) (hereinafter referred to as the “app”).

2. Name and contact details of the responsible person

Mezzalite GmbH (hereinafter referred to as “Mezzalite”) is responsible for data processing.
Mezzalite GmbH
Schellinggasse 1/1
A-1010 Vienna, Austria
office@mezzalite.com

3. Data processing

When providing our services, we process the personal data of users of our app as well as users of our website’s online content. The specific data processing activities are outlined below:

3.1. Data processing in connection with the use of the website

The following personal data is automatically processed when you visit our website:
Log data;
IP address;
Type and version of your web browser;
Data about your end device (device ID);
Date and time of access to our website or its subsites;
The website from which you accessed our website (referrer URL).
The purpose of the processing is to provide you with the content and services on our website, to ensure the security of the IT infrastructure used, to carry out marketing and analyses for advertising purposes and to enable you to use our website for information purposes.
The log data is usually stored for 14 days. In the event of a security-relevant incident, the data is stored until the incident is resolved.
The legal basis for the processing of your personal data is our legitimate interest pursuant to Article 6 (1) (f) GDPR. Our legitimate interest consists of making our website user-friendly and constantly improving it, providing you with the content you have accessed, ensuring the security of our IT infrastructure (in particular for the purpose of defending against attacks and detecting, eliminating and documenting faults) and administering the cookie consents that have been granted.
You are not obligated to provide your data, however, if you do not provide it, it is not possible for us to provide you with the content you have accessed.
For more details about cookies, see item 3.8.

3.2. Data processing in connection with the app account

We process the following personal data when you create and use an account as a capital seeker or capital provider:
Name
Address
Contact details
Company details
Project details
Additional uploaded data
The data is passed on to our IT service provider, which is based in the EU. In addition, we pass your data on to capital providers or capital seekers, insofar as you request this.
The personal data will generally be processed by us for the duration of the business relationship and in accordance with the legal requirements (retention obligations). The legal basis for the processing of your personal data is consent pursuant to Article 6 (1) (a) GDPR, the fulfilment of pre-contractual and contractual obligations pursuant to Article 6 (1) (b) GDPR (if an investment is made) and the fulfilment of legal obligations pursuant to Article 6 (1) (c) GDPR (in order to comply with statutory retention obligations).
It is necessary for you to provide us with your data so that we can provide you with the service we provide via our app.

3.3. Data processing of customer data

We process the following personal data of customers:
Name
Address
Contact details
Payment details
The data is processed by our data processing provider, which is based in the EU.
The personal data will generally be processed by us for the duration of the business relationship and in accordance with the legal requirements (retention obligations). The legal basis for the processing of your personal data is the fulfilment of pre-contractual and contractual obligations pursuant to Article 6 (1) (b) GDPR and the fulfilment of legal obligations pursuant to Article 6 (1) (c) GDPR.
You need to provide us with your data so that we can enter into a contractual relationship with you.

3.4. Data processing in connection with the newsletter

We process the following personal data for the purpose of sending you newsletters electronically on a regular basis:
Name
Email address
The data is passed on to our IT service provider, which is based in the EU. The legal basis for the processing of your personal data is your express consent pursuant to Article 6 (1) (a) GDPR. We use a double opt-in procedure for our newsletter subscriptions. Sie geben auf unserer Website Ihren Namen und die E-Mail-Adresse ein und bekommen ein Bestätigungs-E-Mail, um die Anmeldung nochmals zu bestätigen. You enter your name and email address on our website and receive a confirmation email in which you are asked to confirm that you want to subscribe. This is to prevent any unauthorised third party from misusing your email address.
You can cancel your newsletter subscription at any time by sending an email to office@mezzalite.com. You can also unsubscribe from the newsletter by clicking on the link contained in each newsletter. We will process the personal data you provide to us until you withdraw your consent. When you revoke your consent, we will delete this data and this deletion will be irreversible. However, we would like to point out that all processing carried out until revocation remains lawful. You are not obligated to provide your data, however, if you do not provide it, it is not possible for us to provide you with the newsletter.

3.5. Data processing in connection with contact requests

It is possible to contact us directly by email. If you contact us in this way, we will only process the data that you provide to us in the email. The data is passed on to our IT service provider, which is based in the EU.
The purpose of the processing is to make it possible for you to contact us directly via our website or by email. We will only process the data you provide for the purpose of further communication with you. The personal data will not be processed for any other purpose.
The legal basis for the processing of your personal data is our legitimate interest pursuant to Article 6 (1) (f) GDPR and processing for the performance of a contract or for the implementation of pre-contractual measures pursuant to Article 6 (1) (b) GDPR. Our legitimate interest consists of making our website user-friendly, enabling you to contact us easily and transparently, and ensuring that we respond to your requests.

3.6. Data processing in connection with job applications

We process the following personal data when you apply to work with us:
Name
Address
Contact details
Other applicant details
We will not pass your data on to third parties.
The purpose of the data processing is to manage the application process and to register with the relevant authorities in the event that you are hired. We will generally process the personal data for a period of 6 months after completion of the application process. Processing beyond this will only be carried out if you consent to us retaining the records. The legal basis for the processing of your personal data is the fulfilment of pre-contractual obligations pursuant to Article 6 (1) (b) GDPR and the fulfilment of legal obligations pursuant to Article 6 (1) (c) GDPR. The legal basis for retaining the records is your express consent pursuant to Article 6 (1) (a) GDPR. You can revoke your consent to the retention of these records at any time by sending an email to office@mezzalite.com. We will process the personal data you provide to us until you withdraw your consent. When you revoke your consent, we will delete this data and this deletion will be irreversible. However, we would like to point out that all processing carried out until revocation remains lawful. You need to provide us with your data so that we can process your application.

3.7. Data processing in connection with social media plugins

We do not have any integrated social media plugins on our website. The social media buttons that are linked to the social networks (e.g. Instagram, Facebook, LinkedIn) have only been integrated on our website with a link (a link that takes you to the social networks). If you click on one of these links (buttons), you will be redirected to the respective website. Please refer to the data protection policies of the respective providers.

3.8. Data processing in connection with cookies

We use cookies on our website to allow us to provide our services. Cookies are small text files containing information that is stored on your end device when you visit our website. Storing cookies temporarily makes it easier for you to use the website, which is why you will be asked for your consent the first time you visit the website. However, you are not obligated to give this consent and you can use the website without giving your consent – although functionality may be limited in some cases. Cookies that do not require consent (known as strictly necessary cookies), the purpose of which is to enable the transmission of a message via an electronic communications network, as well as cookies that are strictly necessary to provide our services, are processed by us even without your consent. There are two basic types of cookies:

Cookies that do not require consent and cookies that do require consent

Cookies that do not require consent are those cookies without which we cannot provide the applications and functions at all (known as operationally necessary cookies). These cookies are generally only stored until you close your browser. All other cookies are cookies that require consent.

First- und Third-Party-Cookies

First-party cookies are cookies that are set and accessed by us or by our processing providers. Third-party cookies are cookies that are set and accessed by other data controllers. Therefore, the distinction here depends on where a cookie originates from.

Session cookies and persistent cookies

Session cookies are cookies that are automatically deleted when the browser is closed. Persistent cookies are cookies that remain stored on your computer/end device for a certain period of time after you close your browser.
We only use cookies requiring consent if you have previously consented to their processing through our cookie notice (cookie banner). The cookie banner is displayed when you visit our website. There, you can select the cookies you want and consent to their processing.

Our website uses the cookies described below.

You can revoke your consent to the use of cookies at any time without giving reasons here. However, we would like to point out that all processing/data transmission carried out until revocation remains lawful.

3.9. Data Processing in connection with Google Analytics web analytics tools

If you have consented, Google Analytics, a web analytics service of Google Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, will be used on our website. Google Analytics also uses cookies, which make it possible to analyse your use of the website. The information generated by the cookie about your use of our website will be transmitted to and stored by Google on servers in the United States.

IP anonymisation has been implemented on our website (“_anonymizeIp()”). This means that Google will shorten your IP address beforehand within the EU or the EEA (this is known as IP masking). Therefore, the full IP address will not be transmitted to a Google server in the United States. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and truncated there. Google will use this information on our behalf for the purpose of evaluating your use of the website, compiling reports on website activity for us, and providing other services relating to website use and internet usage.

You can prevent the installation of cookies by adjusting your browser settings accordingly (using a browser plugin). However, we would like to point out that in this case you may not be able to use the full functionality of our website. Furthermore, you can prevent the collection and processing of data generated by the cookie and related to your use of the website (including your anonymised IP address) by downloading and installing the browser plugin available at the address below. The current link is: https://tools.google.com/dlpage/gaoptout?hl=en-GB

Information about the third-party provider: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001.

Terms and conditions of use: http://www.google.com/analytics/terms/de.html
Data protection overview: http://www.google.com/intl/de/analytics/learn/privacy.html
Data privacy policy: http://www.google.de/intl/de/policies/privacy

3.10. Data processing in connection with the LinkedIn Insight Tag

If you have consented, the LinkedIn Insight Tag, a service provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, will be used on our website. The LinkedIn Insight Tag sets cookies that enable the collection of the URL, referrer URL, IP address, device and browser properties (user agent), timestamp and data from LinkedIn if you have an active LinkedIn account. You can delete the cookies at any time in your browser settings.
We do not receive any personal data from LinkedIn, only anonymised reports and messages. The cookies expire after 30 or 90 days. LinkedIn deletes the direct identifiers within 7 days in order to pseudonymise the data. The remaining pseudonymised data is then deleted by LinkedIn within 180 days.
You can find further information on data protection at LinkedIn by clicking on the following link:  https://www.linkedin.com/legal/privacy-policy?_l=de_DE

3.11. Data processing in connection with Facebook Pixel

If you have consented, Facebook Pixel, a service of Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, will be used on our website. Facebook Pixel allows us to categorise our website users into target groups and to use targeted advertising via Facebook. We do not receive any personal data from Facebook, we can only place certain advertisements.
You can find further information on data protection at Facebook by clicking on the following link:  https://www.facebook.com/policy.php

3.12. Data processing in connection with Google Adwords

If you have consented, Google AdWords, a service of Google Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, will be used on our website. Google Adwords sets a cookie (conversion tracking) when you access our website via an ad placed on Google. This makes it possible to measure the number of times a target is reached and to carry out conversion tracking.

You can prevent the installation of cookies by adjusting your browser settings accordingly (using a browser plugin). Furthermore, you can prevent the collection and processing of data generated by the cookie and related to your use of the website (including your anonymised IP address) by downloading and installing the browser plugin available at the address below. The current link is: https://www.google.com/settings/ads
Information about the third-party provider: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001.

Terms and conditions of use: http://www.google.com/analytics/terms/de.html
Data protection overview: http://www.google.com/intl/de/analytics/learn/privacy.html
Data privacy policy: http://www.google.de/intl/de/policies/privacy

4. Automated decision-making / profiling

No automated decision-making, including profiling, takes place.

5. Your rights as a data subject

We would also like to inform you of the following rights that you have as a data subject:
Right to be informed by the data controller about the personal data concerning you pursuant to Article 15 GDPR
Right of rectification pursuant to Article 16 GDPR
Right of erasure pursuant to Article 17 GDPR
Right of restriction of processing pursuant to Article 18 GDPR
Right of data portability pursuant to Article 20 GDPR
Right to object to processing pursuant to Article 21 GDPR
Right to withdraw consent pursuant to Article 7 (3) GDPR
Furthermore, you also have the right to lodge a complaint with the competent supervisory authority (in Austria, this is the Austrian Data Protection Authority based in Vienna). With regard to this, please refer to the website of the Austrian Data Protection Authority, which can be accessed via the link www.dsb.gv.at</a. However, if you have any complaints, you can also contact us directly by sending an email to office@mezzalite.com.

6. Revisions of this policy

This privacy policy may need to be updated due to technical developments and new legal requirements. We will inform you about this in advance.
All rights reserved © Mezzalite 2022