Privacy policy under Art. 13 GDPR
Protecting your personal data matters to us. We process it solely on the basis of the applicable law, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021). This statement sets out what data this website processes, for what purpose and for how long.
1. Controller
Nirotech GmbH
Liebensdorf 312
8081 Heiligenkreuz am Waasen
Austria
Telephone: +43 3134 20120
E-mail: office@nirotech.com
Company register number: FN 205197 k
VAT number: ATU51369905
We have not appointed a data protection officer; we are not required by law to do so. Please address all data protection matters to the contact details above.
2. What this website does not do
This website works without the techniques such statements usually have to cover. Specifically:
- No cookies. The website sets no cookies. For the same reason there is no consent dialogue: there is nothing to consent to. Your browser’s local storage and session storage remain untouched as well.
- No audience measurement, no statistics, no tracking. We use neither Google Analytics nor any comparable tool. You are not recognised across visits.
- No content from third-party servers. Fonts, images, stylesheets and scripts are served exclusively from our own server. While you visit this website your browser connects to no third party – not to Google Fonts, not to a map or video service.
- No social media plugins. No buttons from Facebook, Instagram, LinkedIn or any other network, neither active nor behind a second click.
- No disclosure for advertising. We do not sell data and do not pass any on for advertising or profiling.
3. Server log files
Every time a page is requested, the server records the request automatically. The following is stored:
- the IP address of the requesting device,
- the date and time of the request,
- the address requested and the status code returned,
- the volume of data transferred,
- the previously visited page (referrer), where your browser sends it,
- browser and operating system identification (user agent).
This data is technically necessary to deliver the website, to detect faults and to fend off attacks. It is not combined with other sources and is not used to identify individual visitors. The legal basis is our legitimate interest in secure and uninterrupted operation (Art. 6(1)(f) GDPR).
4. Forms on this website
The website offers three forms. All three require your express consent to the processing of your details; without that tick nothing is stored and nothing is sent. Your details are stored in the protected area of the website and additionally sent by e-mail to the responsible department within our company. They are not passed on to third parties.
4.1 Application form
We process: the position you are applying for, salutation, first and last name, date of birth, nationality, address, telephone number, e-mail address and any remarks you choose to add. The purpose is to assess your application and to decide on a possible appointment. The legal basis is the initiation of an employment relationship (Art. 6(1)(b) GDPR) together with section 11(1) DSG; your consent (Art. 6(1)(a) GDPR) applies in addition.
4.2 Staffing enquiry
We process: the qualification you are looking for, company, salutation, first and last name, address, telephone number, e-mail address and your remarks. The purpose is to answer your enquiry and, where applicable, to initiate a contract (Art. 6(1)(b) GDPR).
4.3 Contact form
We process: salutation, first and last name, telephone number, e-mail address, subject and your message. The purpose is to answer your request. The legal basis is our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR), or Art. 6(1)(b) GDPR for business matters.
4.4 Documents you may need to send us
No files can be uploaded through the forms on this website. Documents you send us by another route – attached to an e-mail, by post or in person – are processed as part of your application or enquiry. This applies in particular to your CV, references, proof of training, certificates and photographs.
Where such documents contain information given special protection by Art. 9 GDPR – health data or a disability pass, for instance – we process it only in so far as this is necessary for the recruitment procedure (Art. 9(2)(b) GDPR in conjunction with section 11(2) DSG). We ask you to send such information only where it is relevant to the position.
One note in our own interest: e-mail is not a confidential channel. For particularly sensitive documents we recommend the post or handing them over in person.
4.5 Protection against automated submissions
To keep our forms from being misused for advertising or bulk messages, the website checks every submission. In doing so we process your IP address – but not in clear text: it is reduced to a check value that cannot be reversed, which serves only as a counter and expires by itself after 24 hours at most. We also ask the mail service of your e-mail domain whether it accepts mail at all; your address itself is not transmitted in the process. The legal basis is our legitimate interest in preventing misuse (Art. 6(1)(f) GDPR).
5. Contact by e-mail and telephone
If you write to us or call us, we process your details in order to deal with your request. The legal basis is Art. 6(1)(b) GDPR for contractual matters, otherwise our legitimate interest in replying (Art. 6(1)(f) GDPR).
6. Recipients and processors
Within our company, only those departments that need it for their work have access. Access to the stored submissions is limited to named user accounts.
For operating the website and sending the e-mails we use service providers, in particular our hosting provider and the agency maintaining the website. They are bound by contract under Art. 28 GDPR, process data solely on our instructions and are subject to confidentiality. The servers are located within the European Union. No transfer to third countries takes place.
7. Retention
We store personal data only for as long as it is needed for the relevant purpose, and beyond that for as long as statutory retention obligations apply – under the Austrian Commercial Code (UGB) or the Federal Fiscal Code (BAO), for instance – or for as long as it is needed to assert, exercise or defend legal claims. The data is then deleted.
In detail this means: we keep applications for the duration of the selection procedure and beyond that for as long as claims under the Equal Treatment Act can be brought. Enquiries sent through the contact or staffing form are deleted once your request has been dealt with and no retention obligation stands in the way. Server log files are overwritten automatically after a short period.
If you would like us to keep your application beyond the current procedure for future positions, please tell us expressly. Without such separate consent we do not add you to a candidate pool.
8. Data security
Transmission between your browser and our server is encrypted. Documents that reach us are not stored in the publicly accessible area of the server. Access to submissions requires a login and the corresponding authorisation. We keep our technical and organisational measures in line with the state of the art.
9. Links to other websites
Our pages contain occasional links to websites run by others. We are not responsible for their content or for how they handle your data. As soon as we learn of unlawful content, we remove the link concerned.
10. Your rights
You have the following rights in relation to us:
- Access to whether and which data we process about you (Art. 15 GDPR),
- Rectification of inaccurate data (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Objection to processing based on a legitimate interest (Art. 21 GDPR).
Where you have given us consent, you may withdraw it at any time with effect for the future. This does not affect the lawfulness of the processing carried out up to that point. A message to office@nirotech.com is enough.
If you believe that the processing of your data infringes data protection law, you may lodge a complaint with the supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at.
11. Changes to this statement
We adapt this statement when the processing on this website changes. The version published here is the one that applies.
Last updated: 24 September 2026