Scope of GDPR-Tool at data2.eu

  • Awareness

    Awareness

  • Processing Index with data2.eu

    Processing Index

  • Privacy Statement

    Privacy Statement

  • Processor contracts

    Processor Contracts

  • DPIA / DPO

    DPIA / DPO

  • EU Citizens

    Rights of EU Citizens

English

One of the requirements of the GDPR is to know which personal data you are collecting, processing, sharing in your organisation. To do that you have to create a Processing Index and you could use our GDPR Tool for that.

Processing index with GDPR Tool

Creating a processing index can be a lot of work. Our GDPR Tool will make it easier and faster:

  1. We will help you to set up a Processing Index for all your activities in a structured way
  2. You will get practical examples from the field that you can easily select (can save you a lot of typing) or you can add your own
  3. After you are done, you can download a PDF for your GDPR documentation

One of the requirements of the GDPR is to know which personal data you are collecting, processing, sharing in your organisation. To do that you have to create a Processing Index and you could use our GDPR Tool for that.

Overview

Details

  • Awareness

    1. Awareness

    Principles of GDPR

    • Lawfulness, fairness and transparency
    • Purpose limitation
    • Data minimisation
    • Accuracy
    • Storage limitation
    • Integrity and confidentiality
    • Accountability
  • Processing Index with data2.eu

    2. Processing Index

    We help creating this with many examples.

    • What personal data do you process?
    • Which are the effected persons?
    • How long do you store the data?
    • Who are recipients of your data?
    • How do you protect that data?
  • Privacy Statement

    3. Privacy Statement

    Explain to your visitors, clients:

    • what personal data you process
    • what data you transfer 3rd parties
    • how long you store it
    • how they can contact you
  • Processor contracts

    4. Processor Contracts

    If you transfer data to 3rd parties, you have to make contracts to ensure the processors are also GDPR compliant. Contracts have to include:

    • what personal data you are processing
    • if there are recipients
    • how the processor is compliant
    • what are the technical and organisational measures
  • DPIA / DPO

    5. DPIA / DPO

    Determine the need of:

    • Data Protection Impact Assessment: is there high risk for the freedom and rights of natural persons?
    • Data Protection Officer: Do you process personal data on a large scale? Or sensitive data?
  • EU Citizens

    6. Rights of EU Citizens

    Right to ...

    • be informed
    • get access
    • get the data corrected
    • cancellation ("right to be forgotten")
    • restriction of processing
    • data portability
    • object

Processing index with GDPR Tool

To add or edit your processing activities, recipients, and technical and organisational measures (TOM), you need to have an active subscription to the service.
When your subscription has expired, you can still download the PDFs that you have created.

Data2.eu was founded by Peter Martin and Sigrid Gramlinger in December 2017. They both knew each other from the international Joomla community for some years. Joomla is an award winning Content Management System to create websites and webapplications, developed and supported by a large international community.

When Sigrid and Peter met again at Joomla World Conference 2017 in Rome (Italy), during dinner they were both discussing the GDPR and its consequences for their businesses. Peter had an idea for a Software as a Service (SaaS) and Sigrid was enthusiastic immediatelly. They decided to team up, worked out the idea and developed the Saas in four months time. 

Software as a Service

Companies and organisations have to comply with the GDPR regarding their processing and storing of personal data. One of the things you need to do to comply, the registration of all processing activities and technical and organisational measures, can be quite a hassle. So we offer a service to make it easier for companies to comply with the GDPR. 

Sigrid Gramlinger

Sigrid Gramlinger

Sigrid specialised on Joomla in 2010 after some years of trying different CMS and getting sick of static HTML and CSS. With www.webgras.at she is offering solid websites based on Joomla. She enjoys most to stick to "Just Joomla" with as few extensions as possible and has done already some presentations on that topic at JoomlaDays in Austria, Germany and the Netherlands.

While enjoying the Joomla community on some German JoomlaDays she was always missing a  community in Austria. Therefore since 2014, with some others she initiated the first Joomla User Group in Austria as well as JoomlaDay Austria since 2015.

She is a certified GDPR consultant and lives just outside Vienna (Austria) with her family.

Peter Martin

Peter Martin

Peter loves the freedom and possibilities that open source software gives you as user and the knowledge sharing that you can only find within such open source communities. He has been active in the international Joomla community since 2005: at first as regular forum user, and later as Global Moderator at Joomla forum. In the past he was a member of the Community Leadership Team, Operations Department Coordinator, Board of Directors and Google Summer of Code mentor. In the Netherlands he helps with organizing Joomla Pizza Bugs and Fun events, and the Dutch Joomla Developers group.  

Peter has his own business in the Netherlands, www.db8.nl (founded in 2005) and supports companies and organizations with Joomla implementations, support and custom Joomla extension development. 

He is an enthusiastic Linux user, organizes a Linux Usergroup and lives with his family in Nijmegen (Netherlands). 

Peter Martin & Sigrid Gramlinger-Moser
data2.eu
Galiciestraat 35
6663 NR Lent
Netherlands

Contact:

Telephone: +31 (0) 644214500
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Register entry:

data2.eu is a tradename of Coöperatie data2.eu U.A.
Entry in the Handelsregister (Netherlands)
Registering court: KvK Gelderland-Zuid
Registration number: 71624163

VAT:

VAT Id number: NL858788081B01

Responsible for contents:

Sigrid Gramlinger-Moser
Hans Pettenauer-G. 6/6
A-3400 Klosterneuburg
Austria

and

Peter Martin
Galiciestraat 35
6663 NR Lent
The Netherlands

Dispute resolution

The European Commission provides a platform for online dispute resolution (OS): https://ec.europa.eu/consumers/odr.

Liability for Contents

As service providers, we are liable for own contents of these websites. However, service providers are not obligated to permanently monitor submitted or stored information or to search for evidences that indicate illegal activities.

Legal obligations to removing information or to blocking the use of information remain unchallenged. In this case, liability is only possible at the time of knowledge about a specific violation of law. Illegal contents will be removed immediately at the time we get knowledge of them.

Liability for Links

Our offer includes links to external third party websites. We have no influence on the contents of those websites, therefore we cannot guarantee for those contents. Providers or administrators of linked websites are always responsible for their own contents.

The linked websites had been checked for possible violations of law at the time of the establishment of the link. Illegal contents were not detected at the time of the linking. A permanent monitoring of the contents of linked websites cannot be imposed without reasonable indications that there has been a violation of law. Illegal links will be removed immediately at the time we get knowledge of them.

Copyright

Contents and compilations published on these websites by the providers are subject to Dutch copyright laws. Reproduction, editing, distribution as well as the use of any kind outside the scope of the copyright law require a written permission of the author or originator. Downloads and copies of these websites are permitted for private use only.
The commercial use of our contents without permission of the originator is prohibited.

Copyright laws of third parties are respected as long as the contents on these websites do not originate from the provider. Contributions of third parties on this site are indicated as such. However, if you notice any violations of copyright law, please inform us. Such contents will be removed immediately

1. An overview of data protection 

General

The following gives a simple overview of what happens to your personal information when you visit our website. Personal information is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy found below.

Data collection on our website

Who is responsible for the data collection on this website?

The data collected on this website are processed by the website operator. The operator's contact details can be found in the website's required legal notice.

How do we collect your data?

Some data are collected when you provide it to us. This could, for example, be data you enter on a contact form.

Other data are collected automatically by our IT systems when you visit the website. These data are primarily technical data such as the browser and operating system you are using or when you accessed the page. These data are collected automatically as soon as you enter our website.

What do we use your data for?

Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze how visitors use the site.

What rights do you have regarding your data?

You always have the right to request information about your stored data, its origin, its recipients, and the purpose of its collection at no charge. You also have the right to request that it be corrected, blocked, or deleted. You can contact us at any time using the address given in the legal notice if you have further questions about the issue of privacy and data protection. You may also, of course, file a complaint with the competent regulatory authorities.

Analytics and third-party tools

When visiting our website, statistical analyses may be made of your surfing behavior on our website. This happens primarily using cookies and analytics. The analysis of your surfing behavior is usually anonymous, i.e. we will not be able to identify you from this data. You can object to this analysis or prevent it by using certain tools. Detailed information can be found in the following privacy policy. We will inform you below about how to exercise your options in this regard.

2. General information and mandatory information

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data as confidential and in accordance with the statutory data protection regulations and this privacy policy.

If you use this website, various pieces of personal data will be collected. Personal information is any data with which you could be personally identified. This privacy policy explains what information we collect and what we use it for. It also explains how and for what purpose this happens.

Please note that data transmitted via the internet (e.g. via email communication) may be subject to security breaches. Complete protection of your data from third-party access is not possible.

Notice concerning the party responsible for this website

The party responsible for processing data on this website is:

Peter Martin & Sigrid Gramlinger-Moser
data2.eu
Galiciestraat 35
6663 NR Lent

Telephone: +31 (0) 644214500
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (names, email addresses, etc.).

Revocation of your consent to the processing of your data

Many data processing operations are only possible with your express consent. You may revoke your consent at any time with future effect. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

Right to file complaints with regulatory authorities

If there has been a breach of data protection legislation, the person affected may file a complaint with the competent regulatory authorities: https://autoriteitpersoonsgegevens.nl/

Right to data portability

You have the right to have data which we process based on your consent or in fulfillment of a contract automatically delivered to yourself or to a third party in a standard, machine-readable format. If you require the direct transfer of data to another responsible party, this will only be done to the extent technically feasible.

TLS encryption

This site uses TLS encryption (Formerly known as SSL) for security reasons and for the protection of the transmission of confidential content, such as the inquiries you send to us as the site operator. You can recognize an encrypted connection in your browser's address line when it changes from "http://" to "https://" and the lock icon is displayed in your browser's address bar.

If TLS encryption is activated, and you have checked that the certificate is ours, then the data you transfer to us cannot be read by third parties.

Encrypted payments on this website

If you enter into a contract which requires you to send us your payment information (e.g. account number for direct debits), we will require this data to process your payment.

Payment transactions using common means of payment (Visa/MasterCard, direct debit) are only made via encrypted SSL or TLS connections. You can recognize an encrypted connection in your browser's address line when it changes from "http://" to "https://" and the lock icon in your browser line is visible.

In the case of encrypted communication, and you have checked that the certificate is ours, any payment details you submit to us cannot be read by third parties.

Information, blocking, deletion

As permitted by law, you have the right to be provided at any time with information free of charge about any of your personal data that is stored as well as its origin, the recipient and the purpose for which it has been processed. You also have the right to have this data corrected, blocked or deleted. You can contact us at any time using the address given in our legal notice if you have further questions on the topic of personal data.

Opposition to promotional emails

We hereby expressly prohibit the use of contact data published in the context of website legal notice requirements with regard to sending promotional and informational materials not expressly requested. The website operator reserves the right to take specific legal action if unsolicited advertising material, such as email spam, is received.

3. Data collection on our website

Cookies

Some of our web pages use cookies. Cookies do not harm your computer and do not contain any viruses. Cookies help make our website more user-friendly, efficient, and secure. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called "session cookies." They are automatically deleted after your visit. Other cookies remain in your device's memory until you delete them. These cookies make it possible to recognize your browser when you next visit the site.

You can configure your browser to inform you about the use of cookies so that you can decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions or to always reject them, or to automatically delete cookies when closing your browser. Disabling cookies may limit the functionality of this website.

Cookies which are necessary to allow electronic communications or to provide certain functions you wish to use are stored pursuant to Art. 6 paragraph 1, letter f of GDPR. The website operator has a legitimate interest in the storage of cookies to ensure an optimized service provided free of technical errors. If other cookies (such as those used to analyze your surfing behavior) are also stored, they will be treated separately in this privacy policy.

Server log files

The website provider automatically collects and stores information that your browser automatically transmits to us in "server log files". These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

These data will not be combined with data from other sources.

The basis for data processing is Art. 6 (1) (b) GDPR, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.

Contact and Support form

Should you send us questions via the contact or support form, we will collect the data entered on the form, including the contact details you provide, to answer your question and any follow-up questions. We do not share this information without your permission.

We will, therefore, process any data you enter onto the contact form only with your consent per Art. 6 (1)(a) GDPR. You may revoke your consent at any time. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

We will retain the data you provide on the contact form until you request its deletion, revoke your consent for its storage, or the purpose for its storage no longer pertains (e.g. after fulfilling your request). Any mandatory statutory provisions, especially those regarding mandatory data retention periods, remain unaffected by this provision.

Registration on this website

You can register on our website in order to access additional functions offered here. The input data will only be used for the purpose of using the respective site or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject your registration.

To inform you about important changes such as those within the scope of our site or technical changes, we will use the email address specified during registration.

We will process the data provided during registration only based on your consent per Art. 6 (1)(a) GDPR. You may revoke your consent at any time with future effect. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

We will continue to store the data collected during registration for as long as you remain registered on our website. Statutory retention periods remain unaffected.

Processing of data (customer and contract data)

We collect, process, and use personal data only insofar as it is necessary to establish, or modify legal relationships with us. This is done based on Art. 6 (1) (b) GDPR, which allows the processing of data to fulfill a contract or for measures preliminary to a contract. We collect, process and use your personal data when accessing our website (usage data) only to the extent required to enable you to access our service or to bill you for the same.

Collected customer data shall be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.

Data transmitted when entering into a contract with online service

We transmit personally identifiable data to third parties only to the extent required to fulfill the terms of your contract, for example, to companies entrusted to deliver goods to your location or banks entrusted to process your payments. Your data will not be transmitted for any other purpose unless you have given your explicit permission to do so. Your data will not be disclosed to third parties for advertising purposes without your explicit consent.

The basis for data processing is Art. 6 (1) (b) GDPR, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.

Data transferred when signing up for services and digital content

We transmit personally identifiable data to third parties only to the extent required to fulfill the terms of your contract with us, for example, to banks entrusted to process your payments.

Your data will not be transmitted for any other purpose unless you have given your explicit permission to do so. Your data will not be disclosed to third parties for advertising purposes without your explicit consent.

The basis for data processing is Art. 6 (1) (b) GDPR, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.

4. Analytics and advertising

Google Analytics

This website uses Google Analytics, a web analytics service. It is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Google Analytics uses so-called "cookies". These are text files that are stored on your computer and that allow an analysis of the use of the website by you. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.

Google Analytics cookies are stored based on Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both its website and its advertising.

IP anonymization

We have activated the IP anonymization feature on this website. Your IP address will be shortened by Google within the European Union or other parties to the Agreement on the European Economic Area prior to transmission to the United States. Only in exceptional cases is the full IP address sent to a Google server in the US and shortened there. Google will use this information on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity, and to provide other services regarding website activity and Internet usage for the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with any other data held by Google.

Browser plugin

You can prevent these cookies being stored by selecting the appropriate settings in your browser. However, we wish to point out that doing so may mean you will not be able to enjoy the full functionality of this website. You can also prevent the data generated by cookies about your use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

Objecting to the collection of data

You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this site: Disable Google Analytics.

For more information about how Google Analytics handles user data, see Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=en.

Outsourced data processing

We have entered into an agreement with Google for the outsourcing of our data processing and fully implement the strict requirements of the EU data protection authorities when using Google Analytics.

5. Newsletter

Newsletter data

If you would like to receive our newsletter, we require your name and a valid email address as well as information that allows us to verify that you are the owner of the specified email address and that you agree to receive this newsletter. We store your IP address as technical measure to protect our service. No additional data is collected or is only collected on a voluntary basis. We only use this data to send the requested information and do not pass it on to third parties.

We will, therefore, process any data you enter onto the contact form only with your consent per Art. 6 (1) (a) GDPR. You can revoke consent to the storage of your data and email address as well as their use for sending the newsletter at any time, e.g. through the "unsubscribe" link in the newsletter. The data processed before we receive your request may still be legally processed.

The data provided when registering for the newsletter will be used to distribute the newsletter until you cancel your subscription when said data will be deleted. Data we have stored for other purposes (e.g. email addresses for the members area) remain unaffected.

6. Plugins and tools

YouTube

Our website uses plugins from YouTube, which is operated by Google. The operator of the pages is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.  If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited. If you're logged in to your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account. YouTube is used to help make our website appealing. This constitutes a justified interest pursuant to Art. 6 (1) (f) GDPR. Further information about handling user data, can be found in the data protection declaration of YouTube under https://www.google.de/intl/de/policies/privacy.

7. Payment service providers

Mollie

Our website accepts payments via payment processor Mollie. The payment provider is Mollie B.V., Keizersgracht 313, 1016 EE, Amsterdam, Netherlands.

If you select payment via the payment methods that we currently offer (iDEAL, Bancontact, SOFORT Banking, Overboeking, PayPal, Bitcoin, KBC/CBC Payment Button, Belfius Direct Net), the payment data you provide will be supplied to those payment gateways based on Art. 6 (1) (a) (Consent) and Art. 6 (1) (b) GDPR (Processing for contract purposes). You have the option to revoke your consent at any time with future effect. It does not affect the processing of data previously collected.

PayPal

Our website accepts payments via PayPal. The provider of this service is PayPal (Europe) S.à.r.l & Cie, S.C.A. (22-24 Boulevard Royal, L-2449 Luxembourg.

If you select payment via PayPal, the payment data you provide will be supplied to PayPal based on Art. 6 (1) (a) (Consent) and Art. 6 (1) (b) GDPR (Processing for contract purposes). You have the option to revoke your consent at any time with future effect. It does not affect the processing of data previously collected.

Subcategories

On this page we will inform you about news items that are related to the GDPR, and about our GDPR tool for creating a processing index that is needed to comply with the GDPR.

 

End of Service

Thank you for your interest in this GDPR tool.

We've decided to quit with this service at end of September 2023.
Former customers can download their PDFs until the end of September 2023.