Privacy policy
This privacy policy applies between you, the User of this Website and FutureTrust, the owner and provider of this Website. FutureTrust takes the privacy of your information very seriously. This privacy policy applies to our use of any and all Data collected by us or provided by you in relation to your use of the Website.
Please read this privacy policy carefully.
Definitions and interpretation
- In this privacy policy, the following definitions are used:
Data collectively all information that you submit to EEMA, FutureTrust via the Website. This definition incorporates, where applicable, the definitions provided in the Data Protection Laws; Cookies a small text file placed on your computer by this Website when you visit certain parts of the Website and/or when you use certain features of the Website. Details of the cookies used by this Website are set out in the clause below (Cookies); Data Protection Laws any applicable law relating to the processing of personal Data, including but not limited to the Directive 96/46/EC (Data Protection Directive) or the GDPR, and any national implementing laws, regulations and secondary legislation; GDPR the General Data Protection Regulation (EU) 2016/679; FutureTrust,
we or usFutureTrust, and EEMA, the company responsible for this website, incorporated in Belgium whose registered office is at Rue Washington 40, 1050 Brussels, Belgium; EU Cookie Law the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended by the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011, and Directive 2009/136/EC (Cookie Directive); User or you any third party that accesses the Website and is not either (i) employed by FutureTrust and acting in the course of their employment or (ii) engaged as a consultant or otherwise providing services to FutureTrust and accessing the Website in connection with the provision of such services; and Website any of the Websites hosted in this website, https://www.futuretrust.eu/, and any sub-domains of this site unless expressly excluded by their own terms and conditions. Services the FutureTrust Services and the FutureTrust Pilot Applications:
Further information about personal data processing when using the FutureTrust Services is set out in the Services Schedule.SigS the FutureTrust signature pilot, providing an online service where the user can electronically sign or seal a user-provided document. ValS the FutureTrust validation service pilot, providing an online service where the user can check the validity of an electronic signature, seal, certificate or evidence record. eID the FutureTrust eID service pilot, providing an online service for electronic user identification through the pan-European eID-Broker, which is powered by SkIDentity technology. PresS the FutureTrust preservation service pilot, providing an online service where the user can submit electronic data and later signed documents for long-term preservation. gTSL the FutureTrust global trust services list, providing an online list of Trust Service Providers and trust anchors. eMandate the FutureTrust electronic mandate pilot, in partnership with Multicert (a FutureTrust consortium member). The eMandate pilot allows the user to create and submit electronically-signed mandates to third-party Service Providers. eInvoice the FutureTrust electronic invoices pilot, in partnership with BRZ (a FutureTrust consortium member). Users can submit to the eInvoice pilot electronically-signed invoices, for billable services provided to the Austrian government. eApostille the FutureTrust eApostille pilot, in partnership with PSDA (a FutureTrust consortium member). The eApostille pilot allows users to check the validity of submitted electronic apostilles. eIDAS-Portal the eIDAS-Portal of the German Universities, in partnership with DFN-CERT and ecsec (both FutureTrust consortium members). The eIDAS-Portal provides a smart eID-based system for certificate enrolment, which allows to combine University-specific credentials with eID-based identity verification in order to end up with a completely electronic process for certificate enrolment within the DFN-PKI. - In this privacy policy, unless the context requires a different interpretation:
- the singular includes the plural and vice versa;
- references to sub-clauses, clauses, schedules or appendices are to sub-clauses, clauses, schedules or appendices of this privacy policy;
- a reference to a person includes firms, companies, government entities, trusts and partnerships;
- "including" is understood to mean "including without limitation";
- reference to any statutory provision includes any modification or amendment of it;
- the headings and sub-headings do not form part of this privacy policy.
Scope of this privacy policy
- This privacy policy applies only to the actions of FutureTrust and Users with respect to the Services hosted in this website. It does not extend to any external websites that can be accessed from this website including, but not limited to, any links we may provide to social media websites.
- For purposes of the applicable Data Protection Laws, FutureTrust, represented by EEMA, is the "Data Controller". This means that FutureTrust determines the purposes for which, and the manner in which, your Data is processed. In some of the provided FutureTrust Services, further Data Controllers might be involved. Information about the respective Services can be found at the Services Schedule below.
Data collected
- When using this Website, we may collect the following Data, which includes personal Data, from you:
- name;
- contact Information such as email addresses and telephone numbers;
- IP address (automatically collected);
- web browser type and version (automatically collected);
- a list of URLs starting with a referring site, your activity on this Website, and the site you exit to (automatically collected);
For information about data collected during use of the Services, see the Services Schedule.
How we collect Data
- We collect Data in the following ways:
- data is given to us by you;
- data is received from other sources; and
- data is collected automatically.
Data that is given to us by you
- FutureTrust will collect your Data in a number of ways, for example:
- when you contact us through the Website, by telephone, post, e-mail or through any other means;
- when you use our Websites;
in each case, in accordance with this privacy policy.
Data that is received from third parties
- FutureTrust might receive Data about you from third parties when you use some of the FutureTrust Services. Details about the third parties that may send us Data about you can be found in the Services Schedule.
Data that is collected automatically
- To the extent that you access the Website, we will collect your Data automatically, for example:
- we automatically collect some information about your visit to the Website. This information helps us to make improvements to Website content and navigation, and includes your IP address, the date, times and frequency with which you access the Website and the way you use and interact with its content.
- we will collect your Data automatically via cookies, in line with the cookie settings on your browser. For more information about cookies, and how we use them on the Website, see the section below, headed "Cookies".
Our use of Data
- Any or all of the above Data may be required by us from time to time in order to provide you with the best possible service and experience when using our Website. Specifically, Data may be used by us for the following reasons:
- improvement of our products / services;
- transmission by email of marketing materials that may be of interest to you;
in each case, in accordance with this privacy policy.
- We may use your Data for the above purposes if we deem it necessary to do so for our legitimate interests. If you are not satisfied with this, you have the right to object in certain circumstances (see the section headed "Your rights" below).
- For the delivery of direct marketing to you via e-mail, we'll need your consent, whether via an opt-in or soft-opt-in:
- soft opt-in consent is a specific type of consent which applies when you have previously engaged with us (for example, you contact us to ask us for more details about a particular product/service, and we are marketing similar products/services). Under "soft opt-in" consent, we will take your consent as given unless you opt-out.
- for other types of e-marketing, we are required to obtain your explicit consent; that is, you need to take positive and affirmative action when consenting by, for example, checking a tick box that we'll provide.
- if you are not satisfied about our approach to marketing, you have the right to withdraw consent at any time. To find out how to withdraw your consent, see the section headed "Your rights" below.
Keeping Data secure
- The FutureTrust pilots portal (https://portal.futuretrust.eu) is hosted by ecsec within a secure operation environment similar to the "Secure Cloud Infastructure (SkIDentity)".
Data retention
- The data retention, if any, is according to the privacy statements for the individual FutureTrust Services and FutureTrust Pilot Applications.
Your rights
- You have the following rights in relation to your Data:
- Right to access - the right to request (i) copies of the information we hold about you at any time, or (ii) that we modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this, unless your request is "manifestly unfounded or excessive." Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why.
- Right to correct - the right to have your Data rectified if it is inaccurate or incomplete.
- Right to erase - the right to request that we delete or remove your Data from our systems.
- Right to restrict our use of your Data - the right to "block" us from using your Data or limit the way in which we can use it.
- Right to data portability - the right to request that we move, copy or transfer your Data.
- Right to object - the right to object to our use of your Data including where we use it for our legitimate interests.
- To make enquiries, exercise any of your rights set out above, or withdraw your consent to the processing of your Data (where consent is our legal basis for processing your Data), please contact us via this e-mail address: info@futuretrust.eu.
- If you are not satisfied with the way a complaint you make in relation to your Data is handled by us, you may be able to refer your complaint to the relevant data protection authority as indicated in the individual privacy statement.
- It is important that the Data we hold about you is accurate and current. Please keep us informed if your Data changes during the period for which we hold it.
Transfers outside the European Economic Area
- Data which we collect from you may be stored and processed in and transferred to countries outside of the European Economic Area (EEA). For example, this could occur if our servers are located in a country outside the EEA or one of our Website providers is situated in a country outside the EEA. We also share information with our group companies, some of which are located outside the EEA.
- We will only transfer Data outside the EEA where it is compliant with data protection legislation and the means of transfer provides adequate safeguards in relation to your data, eg by way of data transfer agreement, incorporating the current standard contractual clauses adopted by the European Commission, or by signing up to the EU-US Privacy Shield Framework, in the event that the organisation in receipt of the Data is based in the United States of America.
- To ensure that your Data receives an adequate level of protection, we have put in place appropriate safeguards and procedures with the third parties we share your Data with. This ensures your Data is treated by those third parties in a way that is consistent with the Data Protection Laws. The entity responsible for the personal data protection in Georgia is the "State Inspector´s Service".
Links to other websites
- This Website may, from time to time, provide links to other websites. We have no control over such websites and are not responsible for the content of these websites. This privacy policy does not extend to your use of such websites. You are advised to read the privacy policy or statement of other websites prior to using them.
Cookies
- This Website may place and access certain Cookies on your computer. FutureTrust uses Cookies to improve your experience of using the Website and to improve our range of Websites. FutureTrust has carefully chosen these Cookies and has taken steps to ensure that your privacy is protected and respected at all times.
- All Cookies used by this Website are used in accordance with current UK and EU Cookie Law.
- Before the Website places Cookies on your computer, you will be presented with a message bar requesting your consent to set those Cookies. By giving your consent to the placing of Cookies, you are enabling FutureTrust to provide a better experience and Website to you. You may, if you wish, deny consent to the placing of Cookies; however certain features of the Website may not function fully or as intended.
- This Website may place the following Cookies:
- You can find a list of Cookies that we use in the Cookies Schedule.
- You can choose to enable or disable Cookies in your internet browser. By default, most internet browsers accept Cookies but this can be changed. For further details, please consult the help menu in your internet browser.
- You can choose to delete Cookies at any time; however you may lose any information that enables you to access the Website more quickly and efficiently including, but not limited to, personalisation settings.
- It is recommended that you ensure that your internet browser is up-to-date and that you consult the help and guidance provided by the developer of your internet browser if you are unsure about adjusting your privacy settings.
- For more information generally on cookies, including how to disable them, please refer to aboutcookies.org. You will also find details on how to delete cookies from your computer.
Type of Cookie | Purpose |
Session (Transient) cookies | These cookies are erased when you close your browser, and do not collect information from your computer. They typically store information in the form of a session identification that does not personally identify the user. |
Persistent (Permanent or Stored) cookies | These cookies are stored on your hard drive until they expire (i.e. the are based on a set expiration date) or until you delete them. These cookies are used to collect identifying information about the user, such as Web surfing behavior or user preferences for a specific site. |
General
- You may not transfer any of your rights under this privacy policy to any other person. We may transfer our rights under this privacy policy where we reasonably believe your rights will not be affected.
- If any court or competent authority finds that any provision of this privacy policy (or part of any provision) is invalid, illegal or unenforceable, that provision or part-provision will, to the extent required, be deemed to be deleted, and the validity and enforceability of the other provisions of this privacy policy will not be affected.
- Unless otherwise agreed, no delay, act or omission by a party in exercising any right or remedy will be deemed a waiver of that, or any other, right or remedy.
- This Agreement will be governed by and interpreted according to the law of Belgium. All disputes arising under the Agreement will be subject to the exclusive jurisdiction of the Belgium courts.
Changes to this privacy policy
- FutureTrust reserves the right to change this privacy policy as we may deem necessary from time to time or as may be required by law. Any changes will be immediately posted on the Website and you are deemed to have accepted the terms of the privacy policy on your first use of the Website following the alterations.
You may contact FutureTrust by email at info@futuretrust.eu.
Date
29 July 2019
Cookies
- Below is a list of the cookies that we use. We have tried to ensure this is complete and up to date, but if you think that we have missed a cookie or there is any discrepancy, please let us know.
We use the following cookies:
Description of Cookie | Type | Purpose |
svSession | Permanent | communication between site owner and visitor |
hs | Session | security |
XSRF-TOKEN | Persistent cookie | security |
smSession | Two weeks | identifies logged in site members |
TSxxxxxxxx (where x is replaced with a random series of numbers and letters) | Permanent | security |
TSxxxxxxxx_d (where x is replaced with a random series of numbers and letters) | Permanent | security |
Web Analysis
- This website may use the web analytics service Matomo. Matomo is an open source solution that is operated in the FutureTrust pilots environment. Matomo uses "Cookies" as described above and stores your IP address in a "shortened" and thus pseudonymised form (eg 192.168.yyy.zzz) in order to generate anonymised user profiles that may be used to analyse and optimise the website. Cookies from Matomo remain on your device until you delete them. The data collected in Matomo will not be shared or linked to other data and services. In addition, the storage of Cookies by your web browser can be prevented in principle, but some functions of this website could be limited thereby.
Social Media
- If "Social Media Buttons" are included in this web offer, it is either a static link to a corresponding profile on Twitter, Facebook, LinkedIn etc. or the privacy-friendly "Shariff" solution is used. As a result, these buttons are integrated on the website only as a graphic that contains a link to the website of the button provider. Only by clicking on the graphic you will be forwarded to the services of the respective provider and only then your data will be sent to the respective provider. If you do not click the buttons, there will be no data exchange between your browser and the providers of the social media buttons. Information about the collection and use of your data in the social networks can be found in the respective terms of use of the respective providers. Further information on the privacy-friendly Shariff solution can be found at https://github.com/heiseonline/shariff.
Services
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the SigS to upload an electronic document for electronic signing, we may collect the following personal Data:
- authentication credentials;
- identifying data (name; date of birth; address; unique identifier);
- name of the signatory;
- pseudonym [optional];
- additional data of the qualified trust Service Provider [optional];
- produced electronic signature;
- personal data contained in the uploaded documents;
- The SigS might receive Data about you from the following third parties:
- eID Service;
- Certificate Authority;
- Time Stamping Authority;
- Data collected by and for the use of SigS will only be processed for the purposes of the SigS.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
- The SigS has been configured to operate in a 'stateless' manner. This means that your Data are retained by the Service only during the process of electronic signing. Once the electronically signed document has been retrieved by you, the collected Data concerning you are deleted.
- You have full access to the rights set in clause 15.
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the ValS to upload a signature object for validation, we may collect the following personal Data:
- electronic signature;
- authentication tokens;
- identifying data (name; date of birth; address; unique identifier);
- The ValS might receive Data about you from the following third parties:
- Certificate Authority;
- Time Stamping Authority;
- Data collected by and for the use of ValS will only be processed for the purposes of the ValS.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
in each case, in accordance with this privacy policy.
- The ValS has been configured to retain your Data only during the process of electronic validation. Once the electronic validation has been performed, the collected Data concerning you are deleted.
- You have full access to the rights set in clause 15.
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the eID Service to upload an electronic document for electronic signing, we may collect the following personal Data:
- identification data (name; date of birth; address; unique identifier);
- authentication data;
- The eID Service might receive Data about you from the following third parties:
- Service Providers;
- Identity Providers;
- Data collected by and for the use of eID will only be processed for the purposes of the eID Service.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
- third party eID Providers who provide eID services to you (the User) which require the processing of personal data - to enable third party eID Providers in receipt of any shared data to perform electronic authentication and identification functions using the FutureTrust eID Service;
- third party Service Providers which require the processing of personal data - to enable third party Service Providers in receipt of any shared data to provide access to their services after authentication of you (the User);
in each case, in accordance with this privacy policy.
- The eID Service has been configured to operate in a 'stateless' manner. This means that your Data are retained by the Service only during the process of electronic authentication and identification. Once the electronic identification or authentication has been performed, the collected Data concerning you are deleted.
- You have full access to the rights set in clause 15.
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the PresS to upload an electronic document for preservation, we may collect the following personal Data:
- provided data;
- electronic signatures or seals;
- Data collected by and for the use of PresS will only be processed for the purposes of the PresS.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
in each case, in accordance with this privacy policy.
- The PresS has been configured to operate in a 'stateless' manner. This means that your Data are retained by the Service only during the process of preservation or verification of a preservation. Once the processes have been completed, the collected Data concerning you are deleted.
- You have full access to the rights set in clause 15.
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the gTSL to upload an electronic document for electronic signing, we may collect the following personal Data:
- email address;
- The gTSL might receive Data about you from the following third parties:
- Subscription Providers;
- Data collected by and for the use of gTSL will only be processed for the purposes of the gTSL.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
- third party Subscription Providers who provide subscription services to us which require the processing of personal data - to enable the gTSL to provide notification about changes to interested users;
in each case, in accordance with this privacy policy.
- The gTSL has been configured to operate in a 'stateless' manner. Your email address is retained by the Subscription Provider only for the period that you require notification services from the gTSL and only after your consent.
- You have full access to the rights set in clause 15.
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the eMandate to upload an electronic document for electronic signing, we may collect the following personal Data:
- electronic signature;
- authentication data;
- identifying data (name; date of birth; address; unique identifier);
- The eMandate might receive Data about you from the following third parties:
- Service Provider;
- your Bank;
- Data collected by and for the use of eMandate will only be processed for the purposes of the pilot.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
- the SigS and the PresS Services who provide electronic signing and preservation services - to setup a new eMandate;
- the Service Provider - to setup a new subscription on behalf of you (the User) to one of their Services;
- third party payment providers (your Bank) who process payments made over the Service - to setup a new eMandate after your instruction in order for you (the User) to access one of the services provided by the Service Provider;
in each case, in accordance with this privacy policy.
- The eMandate has been configured to operate without storing any Data concerning you. The participating third parties will maintain your Data only for the purposes of the pilot. After termination of the pilot, the collected Data concerning you are deleted. A possibility to retain the Data concerning you and your access to the subscribed Services should be sought with the participating Service Providers.
- You have full access to the rights set in clause 15.
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the eInvoice to upload an electronic document for electronic signing, we may collect the following personal Data:
- electronic signature;
- identifying data of you (the representative of the company);
- personal data contained in the submitted eInvoice;
- The eInvoice might receive Data about you from the following third parties:
- ValS;
- the Austrian Data Protection Authority;
- Data collected by and for the use of eInvoice will only be processed for the purposes of the eInvoice pilot.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
- the ValS who provides validation services to us which require the processing of personal data - to enable the ValS to validate the electronic signature contained in the submitted eInvoice;
- the Austrian Data Protection Authority who maintains the registration of companies permitted to operate within Austria - to allow you (the representative) and your company access to the Austrian's government portal of electronic services [optional];
in each case, in accordance with this privacy policy.
- The eInvoice will only process your Data for the duration of the pilot. After termination of the pilot, all processed data will be automatically deleted. If you (the User) require continuing access to the Austrian business portal, your registration to the ERsB and ERnP can be maintained after submission of a request to us (see clause 40).
- You have full access to the rights set in clause 15.
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the eApostille to upload an electronic document for electronic signing, we may collect the following personal Data:
- electronic apostille;
- document containing an electronic apostille;
- authentication data;
- The eApostille might receive Data about you from the following third parties:
- eApostille provider;
- eID Service;
- Data collected by and for the use of eApostille will only be processed for the purposes of the pilot.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
- the eID Service, the PresS and the ValS who provide electronic authentication, preservation and validation services to us which require the processing of personal data - to enable us to validate the eApostille and, if you (the User) consent, store it for preservation;
in each case, in accordance with this privacy policy.
- The eApostille has been configured to operate in a 'stateless' manner. This means that your Data are retained by the Service only during the process of validation of the eApostille. Once the eApostille has been validated, the collected Data concerning you are deleted. If you (the User) opt to store the validated document containing the eApostille for preservation, then collected Data concerning you will be retained until the end of the pilot.
- You have full access to the rights set in clause 15.
- In addition to clause 4 of the Privacy Policy, use of this FutureTrust service requires processing of Data by the following groups of people:
- When using the eIDAS-Portal for smart certificate enrolment, we may collect the following personal Data:
- identification and authentication data (name; date of birth; unique identifier, university credential (e.g. username / password), mobile phone number);
- electronic certificate;
- The eIDAS-Portal might receive Data about you from the following third parties:
- DFN-CERT;
- Data collected by and for the use of eIDAS-Portal will only be processed for the purposes of the pilot.
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors - this processing will take place in the course of the pilot for troubleshooting purposes;
- the eID Service who provide electronic authentication and identification services - to enable us to enrol you (the User) for a smart electronic certificate, which may be used for electronic signing, authentication and encryption;
- the DFN - to issue a new smart electronic certificate after your successful enrolment to the Service
in each case, in accordance with this privacy policy.
- The participating Universities as well as DFN-CERT will retain your Data as indicated within its applicable policies.
- You have full access to the rights set in clause 15.
SigS
Data Controllers and Processors
Third party | Role | Purpose |
SigS (ecsec) | Data Controller | To create a signature or seal upon request of the user |
eID Service | Data Processor | To authenticate and identify the user and determine its name and other identity attributes, if necessary |
Certification Authority | Data Processor | To provide the SigS with an electronic certificate, if necessary |
Time Stamping Authority | Data Processor | To provide time stamp tokens for the SigS, if necessary |
Data collected
Data that is received from third parties
Our use of Data
Who we share Data with
Data retention
Your rights
ValS
Data Controllers and Processors
Third party | Role | Purpose |
ValS (ecsec) | Data Controller | to validate a signature, seal, certificate or evidence record on behalf of the user |
Certification Authority | Data Processor | to provide certificate status information |
Time Stamping Authority | Data Processor | To provide time stamp tokens for the ValS, if necessary |
Data collected
Data that is received from third parties
Our use of Data
Who we share Data with
Data retention
Your rights
eID Service
Data Controllers and Processors
Third party | Role | Purpose |
Service Provider (e.g. SigS, ecsec) | Data Controller | to provide a service to the user, which may require authentication or identification |
eID Service (ecsec) | Data Processor | authentication and identification of a user on behalf of a Service Provider |
Data collected
Data that is received from third parties
Our use of Data
Who we share Data with
Data retention
Your rights
PresS
Data Controllers and Processors
Third party | Role | Purpose |
Transaction Service Providers | Data Controller | to deposit electronic documents, possibly with signatures and seals for long term preservation; to request the augmentation of the probative value of an electronic signature or seal; to request the verification of a preserved electronic signature or seal |
PresS (ecsec) | Data Processor | to preserve electronic signatures and seals on behalf of a Transaction Service Provider; to augment the probative value of an electronic signature or seal; to verify a preservation object container |
Time Stamping, Validation or Storage Services | Data Processor | to provide time stamping, validation or storage services for preservation reasons on behalf of the PresS |
Data collected
Our use of Data
Who we share Data with
Data retention
Your rights
gTSL
Data Controllers and Processors
Third party | Role | Purpose |
gTSL | Data Controller | to provide notification services to subscribed users who wish to be notified about changes to the trust service lists |
Subscription Provider | Data Processor | to subscribe you (the User) if you decide you would like to be notified about changes to the trust service lists |
Data collected
Data that is received from third parties
Our use of Data
Who we share Data with
Data retention
Your rights
eMandate
Data Controllers and Processors
Third party | Role | Purpose |
Service Provider | Data Controller | to authenticate you (the User) in order to access the Provider's Services that will require a mandate; to provide a Service to you (the User); |
Payment Provider | Data Controller | to authenticate you (the User) in order to access your bank's online Services; to validate the Service Provider's proposal to setup a new mandate for the desired Service after consent by you (the User) |
eMandate Service | Data Processor | to provide a routing and validation service between the Service Provider and and your bank on behalf of the Service Provider |
SigS, PresS | Data Processor | to provide electronic signing and preservation services when creating a new eMandate on behalf of the Service Provider |
Data collected
Data that is received from third parties
Our use of Data
Who we share Data with
Data retention
Your rights
eInvoice
Data Controllers and Processors
Third party | Role | Purpose |
BRZ | Data Controller | to validate the submitted eInvoices |
ValS | Data Processor | to validate the electronic signature contained within the submitted eInvoices |
BRZ | Data Controller | to register you (the User) under the ERsB and the ERnP registries for companies and their representatives that operate within Austria [optional] |
Austrian Data Protection Authority | Data Processor | to register you (the User) under the ERsB and the ERnP registries for companies and their representatives that operate within Austria on behalf of the BRZ [optional] |
Data collected
Data that is received from third parties
Our use of Data
Who we share Data with
Data retention
Your rights
eApostille
Data Controllers and Processors
Third party | Role | Purpose |
PSDA | Data Controller | to validate a submitted document containing an eApostille; to retrieve a stored document containing an eApostille |
eApostille provider | Data Controller | to provide an eApostille to a document submitted by you (the User) |
ValS, PresS, gTSL, eID Service | Data Processors | to provide authentication, validation and preservation services on behalf of the PSDA |
Data collected
Data that is received from third parties
Our use of Data
Who we share Data with
Data retention
Your rights
eIDAS-Portal
Data Controllers and Processors
Third party | Role | Purpose |
Participating Universities (Ruhr-University Bochum, University of Leipzig and University of Applied Science Coburg) | Data Controller | to provide smart certificate based elctronic services to you (the User) |
eID Service (ecsec) and Certification Authority (DFN-CERT) | Data Processors | to provide electronic identification and certification services within the eIDAS-Portal. |
Data collected
Data that is received from third parties
Our use of Data
Who we share Data with
Data retention
Your rights
Date
Schedules as amended on 11 September 2019