Privacy Notice
Scope of the processing of personal data and data controller
ASSETERA GmbH ("the Company") processes personal data exclusively on the basis of the statutory provisions (General Data Protection Regulation - GDPR, Telecommunications Act – TKG 2021) and, as a matter of principle, only insofar as this is necessary for the provision of our services and for the fulfilment of statutory obligations. The respective scope of data processing depends on the specific services to be provided. In addition, the Company processes personal data after prior consent for information and advertising purposes. Personal data are all data which directly or indirectly allow a conclusion to be drawn about your person.
In this privacy notice, we inform you about the most important aspects of data processing within the scope of our website.
The data controller within the meaning of Art. 4(7) GDPR is the Company:
ASSETERA GmbH
Ungargasse 37, 1030 Vienna, Austria
FN 448308 b
Legal bases for the processing of personal data
The data you provide is necessary for the fulfilment of the contract or for the implementation of pre-contractual measures, in alignment with Art. 6(1)(b) and Art. 6(1)(f) GDPR. Without this data, we cannot provide you with any services or enter into a business relationship with you.
Data categories: The data varies depending on the service provision but usually includes at least the following categories: customer data, contractual data, bank data, identification numbers, physical characteristics, ownership characteristics, contractual data with third parties and transactions-related information.
With respect to transactions, your electronic communications with the Company that result, or may result, in transactions (particularly in the receipt, transmission, and execution of orders) will be recorded for regulatory compliance purposes pursuant to Art. 33 of the Austrian Securities Supervision Act 2018 (Wertpapieraufsichtsgesetz 2018 - WAG 2018). Your orders must generally be submitted via ASSETERA Marketplace or, in exceptional cases (e.g. Marketplace disruptions), via a durable medium such as email. Orders by telephone will only be accepted in very limited situations and only where legally compliant recording is guaranteed and you provide your consent for such recordings.
Copies of transaction recordings will be stored by the Company for a period of 5 years, or up to 7 years where required by the national competent authority. You may request copies of those transactions from the Company free of charge during the previously mentioned record retention timeframe.
The Company is also legally obliged to process the personal data of its customers as well as of their beneficial owners and other corporate representatives on the basis of national laws, in particular the Financial Market Money Laundering Act (FM-GwG), which result from EU money laundering regulations as well as regulations against the financing of terrorism. In order to safeguard the effectiveness of the measures implemented, the exercise of data subject rights may, in certain circumstances, be restricted or deferred. This applies in particular to the right to information, data correction, deletion or portability, where compliance with a data subject request would impair or jeopardies the purpose of such measures. The legal basis for such restriction is the performance of a task carried out in the public interest pursuant to Art. 6(1)(e) GDPR and, in particular, Art. 21 FM-GwG.
Your personal data will be processed by the Company in accordance with the due diligence requirements of the FM-GwG for the duration of the current business relationship and deleted after 10 years following the termination of the business relationship in accordance with Art. 21(1)(1) FM-GwG. Personal data processed for other purposes shall be handled in accordance with the retention periods resulting from the respective applicable legal requirements and deleted thereafter.
Disclosure of data
Your personal data may be transmitted to the Company’s service providers (be them IT or others) for the provision, operation, security and maintenance of the Company’s services.
Where IT service providers process personal data on behalf of the Company as processors, the Company enters into corresponding data processing agreements with them in accordance with Art. 28 GDPR. The Company may also use IT service providers acting as processors that are located outside the European Union or the European Economic Area. In such cases, personal data may be processed or stored in a third country.
Where personal data is transferred to or processed in a third country, the Company ensures that the applicable requirements under Chapter V GDPR are complied with. In particular, that such transfers are carried out on the basis of an adequacy decision adopted by the European Commission pursuant to Art. 45 GDPR or, where no such adequacy decision exists, on the basis of appropriate safeguards pursuant to Art. 46 GDPR, including the European Commission’s Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, where applicable.
In addition, where IT service providers qualify as information and communication technology (ICT) third-party service providers under the Digital Operational Resilience Act (DORA), the Company ensures that the relevant contractual arrangements include the required provisions regarding the location of data processing and storage, information security, audit and access rights, incident notification support, subcontracting, business continuity, termination, exit arrangements, and the return or deletion of data, as applicable.
In particular, the Company uses a processor to fulfil its legal due diligence obligations under the FM-GwG. Your data may be transmitted to and processed by SUMSUB TECH LTD, Agiou Andreou 153, 3036 Limassol, Cyprus, for identity verification, customer due diligence and AML screening purposes. SUMSUB processes in particular the following categories of data: customer data, contact information, identity document data, identification data, verification data, biometric or liveness verification data where required, anti-money laundering (AML) screening results, sanctions and politically exposed persons (PEP) screening results, as well as technical data.
In certain cases, it may be necessary for the Company to transmit customer data to issuers of security tokens that the customer has acquired via the ASSETERA Marketplace, to the extent necessary and legally permissible, so that the issuer can fulfil its own legal and regulatory due diligence obligations.
Data may also be disclosed in order to assert, exercise or defend legal claims, insofar as there is no reason to assume that there is an overriding interest worthy of protection in not disclosing the data, as well as if there is a legal obligation to disclose the data and insofar as this is legally permissible and necessary for the processing of contractual relationships with you.
Contacting
On our website, we offer you the opportunity to contact the Company about a request and to leave your contact details (name, e-mail, company) so that you can be contacted directly by one of our experts. We process the data provided in accordance with pre-contractual measures based on your request. The legal basis is the implementation of pre-contractual measures based on your request in accordance with Art. 6(1)(b) GDPR. The data you provide will be stored in accordance with the retention periods resulting from the applicable legal requirements and then deleted.
Marketing communications
You will be asked to provide the Company with your explicit consent for subscribing to marketing communications on the Company website. After having provided your explicit consent, we may use your personal data, including your contact details (such as your e-mail address), to send you marketing communications regarding our products, services, and related updates. These communications may include information about features, offers, and events that may be of interest to you.
You may withdraw your consent at any time by using the unsubscribe link included in each marketing email or by contacting us directly at newsletter@assetera.com. The withdrawal of consent shall not affect the lawfulness of any processing carried out on the basis of consent prior to its withdrawal.
Cookies and web-analysis-tools
This website uses the following cookies: functional cookies.
In order to make it easier for you to access our website and to enable evaluations of visits to our website, we store cookies on your terminal device. These record the IP address of your terminal device and thus your visits to our website. However, this only takes place if you have previously given us your consent in the cookie banner. The legal basis for this is consent in accordance with Art. 6 (1)(a) GDPR.
You can restrict or prevent the setting of cookies. If the use of cookies is restricted, not all functions of this website may be fully usable.
Your rights
With regard to your data processed by the Company, you are generally entitled to the rights of information, correction, deletion, restriction of processing, data portability, revocation of consent and objection to processing. If you believe that the processing of your data violates the data protection law or that your data protection rights have been violated in any other way, you can submit a complaint to us at complaints@assetera.com office-vasp@assetera.comor to the Austrian Data Protection Authority.
