Privacy Policy
Nessus GmbH, Fernkorngasse 10/3/501, 1100 Vienna, Austria, Phone: +43 1 3360006, Email address: datenschutz@nessus.at (“Nessus”, “we”, “us”) considers the protection of your personal data to be an important concern. Your data is not our business model, and we process your data exclusively on the basis of legal provisions, in particular the Data Protection Act as amended (“DSG”), the Telecommunications Act (“TKG”), and the General Data Protection Regulation (“GDPR”).
In this privacy policy, we inform you about the processing of your personal data and your rights within the scope of our offers.
1. SUBJECT AND PURPOSE OF DATA PROCESSING
1.1. CONTACT WITH NESSUS
1.1.1. Processing
When you contact us, we process your personal data (e.g., name, phone number, email address, and the content of your message) to handle this inquiry. We process this data to be able to handle your inquiry (and any follow-up questions) for the purpose of contract fulfillment (including pre-contractual measures) pursuant to Art. 6 (1) (b) GDPR and, if no contractual relationship exists, within the scope of our legitimate interests to answer your inquiry pursuant to Art. 6 (1) (f) GDPR.
1.1.2. Storage Period
We store data only as long as necessary for the respective purposes. Emails for simple contact inquiries are stored in our ticket system for a maximum of 6 months, otherwise 10 years. The long storage period is necessary to protect interests in liability cases of any kind. If you contact us by phone, your phone number is stored in the log files and deleted after 8 weeks. If you send us a letter or a fax, these are scanned and stored in the ticket system. The deletion period for the digital copy and the original coincides with that of email inquiries. Likewise, internal tickets with the same storage period are created through the use of the contact options offered on our website (e.g., standby request, callback).
1.2. BACKUP
1.2.1. Processing
For security reasons, we create backups of all Nessus core systems as a precaution.
We create backups based on our legitimate interests pursuant to Art. 6 (1) (f) GDPR. Our legitimate interests lie in offering a secure IT infrastructure in which the availability, integrity, and confidentiality of the processed data is guaranteed.
1.2.2. Storage Period
For technical reasons within the meaning of § 4 (2) DSG, backups are deleted no later than 6 months after the deletion of the original data.
1.3. OFFER – IF YOU RECEIVE AN OFFER FROM NESSUS
1.3.1. Processing
In order to provide you with an offer, we process, among other things, the following data: first and last name, organization, address, contact information (e.g., email address, phone number). We process this data within the scope of our pre-contractual relationship pursuant to Art. 6 (1) (b) GDPR.
1.3.2. Disclosure
In order to fulfill our pre-contractual obligations to you, we use service providers who, under our order and instructions, may also have access to personal data in order to provide the commissioned IT services.
Furthermore, we transfer your personal data to the following recipients:
- to external third parties to the extent necessary on the basis of our legitimate interests (e.g., auditors, insurance companies in the event of an insurance claim, legal representatives where relevant, etc.);
- to authorities and other public bodies to the extent required by law (e.g., tax authorities, courts, etc.).
1.3.3. Storage Period
We store data only as long as necessary for the respective purposes. If deletion cannot be carried out because the data is required for permissible legal purposes, data processing will be restricted. In this case, the data will be blocked and not processed for other purposes.
1.4. GENERAL DATA – IF YOU CONCLUDE A CONTRACT WITH NESSUS
1.4.1. Processing
If you conclude a contract with us, we will process the following data: last and first name, if applicable organizational data, address, contact options (e.g., email address, phone number), IP address, information about the type of our contractual relationship. Furthermore, the following personal data that you provide to us will be processed: payment data (SEPA direct debit, …), contract commitment, contract term, notice period. The data provided by you is necessary for contract fulfillment or for the implementation of pre-contractual measures. We therefore process your personal data for contract fulfillment on the basis of Art. 6 (1) (b) GDPR. Without this data, we cannot conclude the contract with you.
1.4.2. Disclosure
In order to fulfill our contract with you, we use service providers who, under our order and instructions, may also have access to personal data in order to provide the commissioned IT services.
Furthermore, we transfer your personal data to the following recipients:
- to external third parties to the extent necessary on the basis of our legitimate interests (e.g., auditors, insurance companies in the event of an insurance claim, legal representatives where relevant, etc.);
- to authorities and other public bodies to the extent required by law (e.g., tax authorities, courts, etc.).
Your data will not be disclosed to any other third parties for their own purposes without your consent.
1.4.3. Storage Period
Upon termination of the contract, all billing information from the contractual relationship will be stored until the expiry of the tax retention period (7 years). Your stored payment methods (SEPA mandates, …) will be deleted after 13 months at the latest. Your master data, information about purchased products, email correspondence, and date of purchase will be stored for 10 years to preserve, assert, or defend legal claims.
Furthermore, we also store the data beyond this if necessary, as long as legal claims from the relationship between us and you can be asserted or until the final clarification of a specific incident or legal dispute (maximum 30 years).
1.5. SERVER HOUSING NESSUS – IF YOU PURCHASE RACK SPACE
1.5.1. Processing
The customer has the option to request access authorization for one or more persons to their rack space. In doing so, the following data is processed: first name, last name, signature, hash of a hand vein image (but not the hand vein image itself – reconstruction through the hash is not possible), portrait image for the access card, and a copy of the ID. For billing purposes, the data volume consumed is recorded. Several video cameras are installed in the data center, monitoring all premises and recording movements. Every entry into our data center is logged for security and documentation purposes. We process this personal data to fulfill our contractual obligations pursuant to Art. 6 (1) (b) GDPR and, with regard to video surveillance, on the basis of our legitimate interests pursuant to Art. 6 (1) (f) GDPR to provide a secure server environment. Regarding the hand vein scan, we process the data on the basis of explicit consent pursuant to Art. 9 (2) (a) GDPR.
1.5.2. Disclosure
Data transfer to third parties generally does not take place. However, the customer can request their access logs and those of their employees if there is a legitimate interest. Video recordings of incidents relevant to criminal law are passed on to the competent authorities, involved insurance companies, and the responsible contractual partner.
1.5.3. Storage Period
First name, last name, data volume consumed, portrait image, copy of the ID, and other forms are deleted no later than 3 months after the end of the contract; the signed Nessus house rules and consent declaration after 3 years; and the hash for the fingerprint image or the hand vein image immediately after the end of the contract. Video recordings are deleted after 8 days and access logs after one year. In the event of incidents relevant to criminal law, video recordings may be retained until the allegations have been finally clarified by a legally binding decision. If authorized persons have not authenticated in the data center for more than 12 months, the affected access authorizations will be deleted after appropriate prior notice.
1.6. SERVER HOUSING INTERXION – IF YOU PURCHASE INTERXION RACK SPACE
1.6.1. Processing
The customer has the option to request access authorization for one or more persons to their rack space. In doing so, the following data is processed: first name, last name, and if applicable, a portrait image. For billing purposes, the data volume consumed is recorded.
We process your personal data on the basis of our contractual relationship pursuant to Art. 6 (1) (b) GDPR. Several video cameras are installed in the Nessus cage in the InterXion data center, monitoring the premises and recording movements. Video surveillance is carried out based on our legitimate interests pursuant to Art. 6 (1) (f) GDPR. These interests consist of ensuring a secure server environment. Processing is carried out to enable your physical access to the data center of InterXion Österreich GmbH and to ensure security during the visit.
1.6.2. Disclosure
To provide our services, we regularly use IT service providers who have access to personal data under our order and instructions in order to provide the commissioned IT services.
Furthermore, we transfer your personal data to the following recipients:
- to external third parties to the extent necessary on the basis of our legitimate interests (e.g., auditors, insurance companies in the event of an insurance claim, legal representatives where relevant, etc.);
- to authorities and other public bodies to the extent required by law (e.g., tax authorities, courts, etc.).
Your data will not be disclosed to any other third parties for their own purposes without your consent.
1.6.3. Storage Period
We store data only as long as necessary for the respective purposes. Nessus deletes the first name, last name, data volume consumed, and portrait image no later than 3 months after the end of the contract, and video recordings after 8 days. Longer storage only takes place to the extent necessary to investigate identified attacks on our technical infrastructure and beyond that only until the end of relevant limitation periods, statutory retention periods, or any legal disputes.
1.7. INTERNET PRODUCTS – IF YOU PURCHASE AN INTERNET CONNECTION
1.7.1. Processing
In order for the desired internet connection to be established at the specified location, the following data is processed: first and last name, organization, address, contact information (e.g., email address, phone number). For billing purposes, the data volume consumed is recorded. We process this personal data on the basis of our contractual relationship pursuant to Art. 6 (1) (b) GDPR.
Since a contractual relationship is entered into with the purchase of a product, “General Data” is additionally processed, see above.
1.7.2. Disclosure
For the operation and management of our internet products, we regularly use IT service providers who, under our order and instructions, may also have access to personal data in order to provide the commissioned IT services.
Furthermore, we transfer your personal data to the following recipients:
- to external third parties to the extent necessary on the basis of our legitimate interests (e.g., auditors, insurance companies in the event of an insurance claim, legal representatives where relevant, etc.);
- to authorities and other public bodies to the extent required by law (e.g., tax authorities, courts, etc.).
Your data will not be disclosed to any other third parties for their own purposes without your consent. We do not transfer any data to a third country.
1.7.3. Storage Period
We store data only as long as necessary for the respective purposes. The data is deleted 3 months after the end of the contract. Longer storage only takes place to the extent necessary to investigate identified attacks on our network and beyond that only until the end of relevant limitation periods, statutory retention periods, or any legal disputes.
1.8. TRAFFIC – DATA TRANSMITTED VIA THE NESSUS NETWORK
1.8.1. Processing
We process information on the data transmitted via our network based on our legitimate interests pursuant to Art. 6 (1) (f) GDPR. Our legitimate interests lie in providing effective technical support and in offering secure services to our customers. The processing serves the purpose of being able to offer support services to our customers and as a preventive protective measure, e.g., against DDoS attacks. The contents of the data packets are not monitored.
1.8.2. Storage Period
We store data only as long as necessary for the respective purposes. The data is deleted after 6 hours. Longer storage only takes place to the extent necessary to investigate identified attacks on our network and beyond that only until the end of relevant limitation periods, statutory retention periods, or any legal disputes.
1.9. NEWSLETTER & TIS
To inform you about new Nessus products, Nessus sends newsletters to the email address you provided. You have the option to subscribe to this newsletter and, of course, to unsubscribe at any time.
With our additional mailing list TIS – Technical Information System, we inform our subscribers about planned maintenance work and service interruptions. Of course, you have the option to unsubscribe from this list at any time.
Furthermore, we send important information that is not considered a newsletter, such as details about critical security vulnerabilities, information about necessary service suspensions, changes to terms and conditions, or similar.
1.9.1. Processing
In order to provide you with targeted information, the following data is processed: email address. If you have subscribed to our newsletter or TIS, we process your data on the basis of your explicit consent pursuant to Art. 6 (1) (a) GDPR in conjunction with § 174 TKG. Technical or contractually necessary mailings take place within the scope of our ongoing contractual relationship pursuant to Art. 6 (1) (b) GDPR.
1.9.2. Disclosure
For sending newsletters and TIS, we regularly use IT service providers who, under our order and instructions, may also have access to personal data in order to provide the commissioned IT services.
Furthermore, we transfer your personal data to the following recipients:
- to external third parties to the extent necessary on the basis of our legitimate interests (e.g., auditors, insurance companies in the event of an insurance claim, legal representatives where relevant, etc.);
- to authorities and other public bodies to the extent required by law (e.g., tax authorities, courts, etc.).
Your data will not be disclosed to any other third parties for their own purposes without your consent.
1.9.3. Storage Period
Deletion from the newsletter or TIS takes place after unsubscribing. If you have registered for a newsletter and the receipt of advertising information accordingly and are not a customer of ours, we store your personal data until your revocation and for a maximum of three years from your last contact.
1.10. SATISFACTION SURVEY
Satisfaction surveys are conducted at regular intervals. As a rule, persons who have had contact with Nessus in recent months are contacted by email, provided you have given us your prior consent in accordance with Art. 6 (1) (a) GDPR in conjunction with § 174 TKG, which you can revoke at any time.
1.10.1. Processing
Email address, rating on a scale of 0 – 10, comment (optional)
1.10.2. Disclosure
In order to conduct satisfaction surveys, the service of an operator within the EU is used.
1.10.3. Storage Period
The data will be deleted after 12 months at the latest.
1.11. APPLICATIONS
If you send us an application, we process the following data:
1.11.1. Processing
Depending on what information we receive from applicants, we process at least the full name, contact details (e.g., phone number, email address), CV, and cover letter on the basis of pre-contractual measures pursuant to Art. 6 (1) (b) GDPR.
1.11.2. Storage Period
Data from application processes is deleted 7 months after the end of the application procedure, provided you are not employed by us. Retention takes place to defend against potential claims under the GlBG.
1.12. WEBSITE, COOKIES, AND WEB ANALYSIS
1.12.1. Data Categories
In the course of your visit to our website, we will automatically collect the following personal data about you: date and time of accessing a page on our website; data about your end device (device ID); IP address; name and version of your web browser; session ID.
The collection takes place for support purposes and as a protective measure against possible attacks within the scope of our legitimate interests pursuant to Art. 6 (1) (f) GDPR, which consists of making our website user-friendly and being able to recognize, prevent, and investigate attacks on our website and online services.
To ensure the best possible functionality of our website (e.g., customer area), session cookies are created. On the basis of your explicit consent pursuant to Art. 6 (1) (a) GDPR, the user’s IP data is stored with the help of cookies for the purpose of better usability. After the end of the session, the data stored in the cookies is deleted. Data processing is based on the legal provision of § 165 (3) TKG.
If cookies are not accepted, please change your browser settings accordingly. Note that this may restrict the functionality of the website. If you do not wish this, you can set up your browser so that it informs you about the setting of cookies and you only allow this in individual cases.
When cookies are deactivated, the functionality of our website may be restricted.
1.12.2. Purpose of Data Processing
We process your data in connection with your visit to our website for the following purposes:
- to provide you with our website, including its functions, and to further improve and develop this website;
- to be able to detect, prevent, and investigate attacks on our website and online services.
1.12.3. Disclosure
To provide our website, we use IT service providers who, under our order and instructions, may also have access to personal data in order to provide the commissioned IT services.
Furthermore, we transfer your personal data to the following recipients:
- to external third parties to the extent necessary on the basis of our legitimate interests (e.g., auditors, insurance companies in the event of an insurance claim, legal representatives where relevant, etc.);
- to authorities and other public bodies to the extent required by law (e.g., tax authorities, courts, etc.).
1.12.4. Storage Period
The data is generally deleted after 8 weeks. Longer storage only takes place to the extent necessary to investigate identified attacks on our website and beyond that only until the end of relevant limitation periods, statutory retention periods, or any legal disputes.
1.13. GOOGLE ANALYTICS
This website uses the “Google Analytics” service, which is offered by Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA), to analyze website usage by users. The service uses “cookies” – text files that are stored on your end device. The information collected by the cookies is usually sent to a Google server in the USA and stored there.
IP anonymization is active on this website. The IP address of users is shortened within the member states of the EU and the European Economic Area. This shortening eliminates the personal reference of your IP address. Within the framework of the data processing agreement that the website operators have concluded with Google Inc., the latter uses the information collected to compile an evaluation of website usage and website activity and provides services associated with internet usage.
You have the option to prevent the storage of cookies on your device by making appropriate settings in your browser. There is no guarantee that you will be able to access all functions of this website without restrictions if your browser does not allow cookies.
Furthermore, you can use a browser plugin to prevent the information collected by cookies (including your IP address) from being sent to Google Inc. and used by Google Inc. The following link leads you to the corresponding plugin: https://tools.google.com/dlpage/gaoptout?hl=en
Here you can find further information on data use by Google Inc.: https://support.google.com/analytics/answer/6004245?hl=en
1.14. FORMER SERVER, DOMAIN, AND HOSTING CUSTOMERS
This part of the privacy policy is relevant for those who have sent an email to Nessus in the past and formerly obtained hosting services from Nessus (domain, web space, V/root server, managed services), as the “hosting” partial operation was transferred to easyname by way of universal succession through demerger for acquisition pursuant to §§ 1 (2) (2) in conjunction with 17 SpaltG.
1.14.1. Processing
We continue to process the following data that you provided to us on the occasion of your business relationship with us and in connection with an inquiry in the ticket system: first and last name, name of the organization / company, address, email address, name of the contact person for processing the ticket, content of a ticket/inquiry, for the purpose described in the paragraph after next.
Furthermore, for the purpose mentioned below, we also process the customer number, date of the ticket, the history of the processing of the ticket, comments and other information for solving the inquiry, other details about the ticket that we collected in the ticket system on the occasion of your inquiry or generated automatically.
For the processing of the data, we assert our legitimate interests and those of easyname GmbH pursuant to Art. 6 (1) (f) GDPR, which consist in the fact that the demerger of the “hosting” partial operation requires the transfer of customer data to easyname GmbH as universal successor for the continuation of the partial operation, and this data attributable to the “hosting” partial operation is necessary to be able to maintain and process the contractual relationships with customers, including inquiries made via tickets, unchanged.
We have transferred the “hosting” partial operation to easyname by way of universal succession through demerger for acquisition pursuant to §§ 1 (2) (2) in conjunction with 17 SpaltG. In the course of this, all rights, legal relationships, and assets belonging to and required for the business operation, including existing customer contracts and the customer database, were transferred. easyname GmbH therefore enters into the legal position regarding the contracts and business relationships from the “hosting” partial operation. With the effectiveness of the demerger for acquisition into easyname GmbH through the transfer of this partial operation according to the demerger plan and takeover agreement dated April 27, 2020, as of May 27, 2020, all rights and obligations arising from the contractual relationships with customers as well as all activities in connection with the partial operation were taken over by easyname GmbH.
The purpose of the processing and in particular the transfer of the data is thus the implementation of this demerger for acquisition, namely by transferring all data attributable to this partial operation that is necessary for the continuation of the contractual relationships, but which was in the Nessus ticket system, which was not attributable to the demerged assets. For easyname GmbH, the data is therefore necessary for the continuation of the partial operation transferred by way of universal succession and for the continued fulfillment of the associated contractual relationships as well as the maintenance of business relationships.
1.14.2. Disclosure
In the course of processing, the data will only be transferred to easyname GmbH, FN 402196s, Canettistraße 5/10, 1100 Vienna, as universal successor to the “hosting” partial operation. Information on the type and scope of data processing at the data recipient can be found in the privacy information of easyname GmbH, available at https://www.easyname.at/de/unternehmen/privacy-policy.
1.14.3. Storage Period
The data will be deleted as soon as the transfer of the data attributable to the partial operation is completely and legally concluded, and will be kept by us beyond that only as long as we need the data for the enforcement of and defense against legal claims from the contractual relationship with the customer, and therefore for 3 years pursuant to §§ 1486 and 1489 ABGB.
2. DATA TRANSFERS TO THIRD COUNTRIES
If we process your data in a third country outside the European Union (EU) or the European Economic Area (EEA) or if this happens within the scope of using third-party services, this only takes place if it is necessary to fulfill our (pre)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. We have implemented suitable and appropriate guarantees to design the transfer of your data to the respective third country in compliance with data protection (e.g., conclusion of so-called “standard data protection clauses”). Upon your request, we will provide you with a copy of these suitable guarantees, provided we process your data or have it processed in third countries.
3. DATA SECURITY
We take appropriate technical and organizational security measures to protect your personal data from accidental or unauthorized deletion, alteration, or against loss, theft, and unauthorized inspection, disclosure, reproduction, use, modification, or access. Furthermore, we and our employees are committed to maintaining data secrecy and confidentiality. Likewise, our vicarious agents and representatives who must have access to your personal data to fulfill their professional tasks will receive access and subject themselves to the same obligations to maintain data secrecy and confidentiality.
4. DATA SUBJECT RIGHTS
You have a right to information, rectification, deletion, restriction, portability of your personal data and can revoke your consent at any time or object to the processing.
Attention: If you request the deletion or restriction of data necessary for the contract, this may affect the function of your purchased products!
4.1. RIGHT TO INFORMATION
You have the right to receive confirmation as to whether we are processing personal data concerning you. If this is the case, you can also request the information contained in Article 15 GDPR from us. You have the right to request information as to whether the personal data concerning you is being transferred to a third country or to an international organization. In this context, you can request to be informed about the appropriate guarantees pursuant to Art. 46 GDPR in connection with the transfer.
4.2. RIGHT TO RECTIFICATION
If we process your personal data that is incomplete or incorrect, you can request its rectification or completion from us without delay.
4.3. RIGHT TO DELETION
You can request the deletion of your personal data from us if the data is no longer necessary for the purposes of processing, the processing is based on your consent and you withdraw it, you successfully object to the processing, or we process this data unlawfully. Please note that there may be reasons that prevent immediate deletion, e.g., in the case of legally regulated retention obligations.
If you have asserted the right to rectification, deletion, or restriction of processing against us, we are obliged to notify all recipients to whom the personal data concerning you has been disclosed of this rectification or deletion of the data or restriction of processing, unless this proves impossible or involves a disproportionate effort.
4.4. RIGHT TO RESTRICTION OF PROCESSING
You can request the restriction of the processing of your data from us if
- you contest the accuracy of the data, for a period enabling us to verify the accuracy of the data,
- the processing of the data is unlawful, but you refuse deletion and instead request restriction of data use,
- we no longer need the data for the intended purpose, but you still need this data to assert or defend legal claims, or
- you have objected to the processing of the data and it has not yet been determined whether your interests prevail.
4.5. RIGHT TO DATA PORTABILITY
You can request that we provide you with your data, which you have entrusted to us for storage, in a structured, common, and machine-readable format, provided
- we process this data on the basis of consent granted by you pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR, or on the basis of a contract pursuant to Art. 6 (1) (b) GDPR, and
- this processing is carried out using automated procedures.
In exercising this right, you also have the right to obtain that the personal data concerning you is transmitted directly by us to another controller, insofar as this is technically feasible. The freedoms and rights of other persons must not be adversely affected thereby.
4.6. RIGHT TO OBJECT
You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR.
In this case, we will no longer process the personal data concerning you unless we can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.
4.7. RIGHT TO LODGE A COMPLAINT
If you are of the opinion that we are violating data protection provisions when processing your data, we request that you contact us so that we can clarify any questions. Notwithstanding any other legal remedies, there is a right to lodge a complaint with the national supervisory authority of your place of residence if unlawful processing of personal data is assumed. In Austria, the Data Protection Authority, Barichgasse 40-42, 1030 Vienna, email dsb@dsb.gv.at, phone: +43 1 52 152-0 is responsible.
4.8. ASSERTION OF RIGHTS
If you wish to assert one of the mentioned rights against us, please use our contact options.
4.9. CONFIRMATION OF IDENTITY
To protect your data, rights, your privacy, and as protection against misuse, we grant the right to complete deletion, data information, and disclosure only after prior appointment, in person, and after prior verification of identity. This measure is intended to prevent, for example, persons who have gained abusive access to your account or your email address from receiving additional personal data from you.
In case of doubt, we can therefore request additional information to confirm your identity for all data protection inquiries.
4.10. COSTS FOR REPEATED REQUESTS FOR INFORMATION
Nessus provides a copy of the personal data in the event of requests for information. For each additional copy, a reasonable fee based on administrative costs will be charged.
4.11. SCOPE OF CONSENT
Please inform co-users of your Nessus accounts (e.g., employees or relatives) about the processing and transfer of your data within the scope of your consent. Do not give any consent to us unless the co-users of your account also agree to it.
4.12. RIGHT TO REVOKE THE DATA PROTECTION DECLARATION OF CONSENT
You have the right to revoke any data protection declaration of consent given at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.
5. CONTACT OPTIONS
Nessus GmbH
Fernkorngasse 10/3/501
1100 Vienna (Austria)
Phone: +43 1 3360006
Email: datenschutz@nessus.at
As of: January 2025