Privacy Policy

Processing (personal) data by the online shop operator (asknet GmbH).

1. General information

asknet GmbH, hereinafter referred to as 'asknet', is a company based in Germany and the expert for academic software needs in the German-speaking region with more than 25 years of experience in the procurement of software in the fields of research and education. asknet offers quick and easy solutions for the licensing, procurement, and management of software in your organization.

This privacy policy describes how asknet handles personal data when you visit the online shops or order a product.

asknet processes e-commerce payment transactions, hereinafter referred to as 'transaction', in the online shops; it operates as a personal data controller to create, verify and execute transactions.

During the transaction, asknet receives customer and payment information from the buyer/end customer and uses fraud prevention services for this purpose and passes on personal data (including payment data) to a payment processor. Personal data of customers is also given to service providers for billing, licensing, delivery and other purposes.

2. Responsible person

Responsible for processing in the sense of data protection law is:

asknet GmbH
Hertzstraße 16a
76187 Karlsruhe

Phone: +49 (0) 721 96458 0
Fax: +49 (0) 721 96458 99
E-Mail: info@asknet.de

You can also contact our data protection team directly by writing to privacy@asknet.com.

Our data protection officer is:

Mr. Markus Strauss
tacticx Consulting GmbH
Walbecker Straße 53
D-47608 Geldern
E-Mail: asknet@extern.tacticx.com

We process your data in strict confidence and only for the purpose we informed you of when collecting the data. Our standards for processing your data are the General Data Protection Regulation (GDPR), the Federal Data Protection Act (FDPA) and the other applicable data protection regulations.

3. Data processing when using our online shop

The personal data you provide to us will be used by us to provide you with the products you have ordered, to process payments, to respond to your enquiries, for registration (if required) and to provide you with additional information, opportunities and features about the products you have ordered. We also use this information to prevent or detect fraud and abuse of our online shops, to customise the features, performance and support of the online shops to our customers' needs, and to perform technical, logistical and other functions or improvements.

3.1 Website visit

Each time you visit our online shops a number of general data and information, including personal data, are collected by our systems. The following data is stored:

  • IP address (if applicable, in anonymised, shortened form)
  • Date and time of the request (timestamp)
  • Request details and destination address (protocol version, HTTP method, referrer, UserAgent string)
  • Name of the retrieved file and amount of data transferred (requested URL incl. query string, size in bytes)
  • Message indicating whether the request was successful (HTTP status code)
  • Website from which the request came
  • Browser type or app used
  • Operating system and its interface
  • Language and version of the browser software

When processing this data, we do not draw any conclusions about your person. There is neither a personal evaluation nor an evaluation of the data for marketing purposes or profiling.

The legal basis for processing the data is Art. 6 (1) lit. f GDPR. The processing of the data is technically mandatory to provide our websites and to ensure the stability and security of our systems. This is also our legitimate interest. There is no possibility to use our websites without such processing of data, i.e. you have no possibility to object.

3.2 Order processing and contract fulfilment

When you shop in our online shop, we process the following personal data from you to process your order:

  • Last name, first name
  • Account ID
  • Address (billing and delivery address)
  • E-mail address
  • Telephone number
  • Customer account
  • Payment data (e.g. credit card number, card verification code, account number, account name, invoice postcode).

Within the scope of what is legally permissible, we pass on your data to the Software Publishers (for licensing purposes) and to our subsidiaries that support us in properly fulfilling the contract. In turn, these companies are obliged to comply with the applicable data protection regulations. In particular, these companies may only process the data to fulfil their tasks on our behalf and only in accordance with our instructions. Data processing in connection with the ordering process is based on Art. 6 (1) lit. b GDPR.

We also pass out your data to the SW Publisher or distributor for licensing purposes.

We collect your address as a basis for tax calculation, transaction processing and support, as well as for statistical purposes. Furthermore, we transmit your address to logistics service providers solely to fulfil your order via our online shop and for statistical purposes. We do not sell your address and contact details in conjunction with other information, combine them with non-transactional records or use them for promotional purposes (unless you have subscribed to our newsletters).

In certain online shops, we give users the option to provide us with account registration information. This information may include but is not limited to name, address, e-mail address and password.

Without your express prior consent, we will only send you product-related announcements of a non-promotional nature (such as announcements related to your purchase of products or subscription renewal information) and only if we deem it necessary.

3.3 Contact

If you contact us by e-mail, fax or telephone, or if you use one of the customer service contact forms provided in the online shops, we will collect any personal data you provide to us in connection with that communication. Unless your request relates to the performance of a contract, the legal basis for processing your request is Art. 6 (1) lit. f GDPR. Our legitimate interest is the processing of your request.

Unless otherwise stated above, the legal basis for all processing activities mentioned in this section is Art. 6 (1) lit. b GDPR and - with regard to processing for the purpose of complying with a legal obligation to which we are subject - Art. 6 (1) lit. c GDPR.

3.4 Preventing fraud and combating money laundering

asknet collects and processes personal data for the following purposes:

  • Validation of the legitimacy of a transaction under applicable anti-money laundering laws through the use of internal tools and external providers (under Art. 6 (1) lit. c GDPR),
  • Confirmation that the intended transaction is not fraudulent in nature through the use of internal tools and external providers (under Art. 6 (1) lit. f GDPR), and
  • Execution of the transaction (under Art. 6 (1) lit. b GDPR).

3.5 Personal data from other sources

We may receive personal data about you from other sources, such as product suppliers or third parties who provide services to us in connection with the website or the online shop. We may aggregate this information with the personal data we collect from you through the Website or Online shop to prevent or detect fraud or misuse of our Website or Online shop, to fulfil your order and to contact you regarding your product order. We do not process this data for marketing purposes.

The legal bases for these processing activities are Art. 6 (1) lit. b GDPR, insofar as the data is necessary for the performance of the contract, and Art. 6 (1) lit. f GDPR for the prevention and detection of fraud and abuse.

In order to prevent late payment, we reserve the right to obtain information about your creditworthiness (for example based on mathematical-statistical processes) from third parties for certain payment methods (for example direct debit and purchase orders) in accordance with Art. 6 (1) lit. f GDPR.

3.6 Data protection for minors

asknet does not knowingly collect information from children under the age of 18. If you are under 18 years of age, please do not submit any personal information through the platform without the consent of your legal guardian. We encourage parents and guardians to monitor their children's Internet use and to help enforce our privacy policy by instructing their children never to provide personal information on our platform without their permission.

If you have reason to believe that a child under the age of 18 has provided asknet with personal information through the platform, please contact privacy@asknet.com, and we will endeavour to delete that information from our databases.

3.7 Law enforcement, disclosure to public authorities and departments

We may disclose your personal data to recipients if such disclosure is necessary to:

  • Comply with applicable laws or comply with subpoenas or warrants served on us (Art. 6 (1) lit. c GDPR),
  • Enforce our terms and conditions (Art. 6 (1) lit. b GDPR),
  • Protect and defend our rights or property or the rights or property of visitors to our online shops and website, our customers, our suppliers or other third parties (Art. 6 (1) lit. f GDPR), or
  • In certain situations, to comply with lawful requests by public authorities to disclose personal data, in particular, to comply with national security or law enforcement regulations (Art. 6 (1) lit. c GDPR).

In the case of tax-exempt orders from certain EU countries your address data may be forwarded to the relevant tax authorities to check whether your value added tax identification number (VAT ID) is correct (Art. 6 (1) lit. c GDPR).

4. External service providers

We transmit your personal data to external service providers who support us in communication as well as in the operation of the website and the online shops and who act on our behalf to provide you with the website, the online shops and the products as well as the associated customer support. Where we use third parties to perform our services, we process personal data in accordance with the provisions of the GDPR, the CCPA and other applicable laws and regulations. Categories of service providers that assist us in providing our services to you include, for example, services to communicate with you via e-mail, process transactions, perform customer authentication, ship products, screen orders for fraudulent activity, provide customer service or fulfilment services to us or services to maintain consistent compliance with applicable laws and regulations. However, external service providers who process data on our behalf do not have the right to use your personal data unless it is necessary to assist us in providing the online shops, related processes and products. Transfers to downstream third parties are subject to the provisions of this Privacy Policy regarding notice and choice and the agreements with our external service providers and the supplier.

We provide analytical data to analytics and tracking technology providers as described under "Cookies and Tracking Technologies".

Third-Party Service/Vendor

Entity Country

Nature of services

Ethoca Inc.

USA, UK, EU, Australia

Fraud Prevention

Verifi, Inc.

USA

Fraud Prevention

Sift Science Inc.

USA, UK

Fraud Prevention

ecovium Holding GmbH

Germany

SDN Screening

Paypal Holdings Inc.

USA

Payment processing

Global Collect Services B.V.

Netherlands

Payment processing

Chase Paymentech, LLC

USA

Payment processing

DG Financial Technology Inc.

Japan

Payment processing

Unzer GmbH

Germany

Payment processing

Avalara, Inc.

USA

Commercial support

Faktoora GmbH

Germany

Invoicing

Kivuto Solutions

Canada

Order processing

VERBI – Software. Consult. Sozialforschung. GmbH

Germany

Order processing

HubSpot, Inc.

USA

Marketing and CRM Services

Amazon Web Services, Inc. (AWS)

Ireland, Germany

Technical Operation

Freshworks Inc.

USA, UK, EU, Australia

Technical Support Services

5. Cookies and tracking technologies

So-called cookies are used in the online shops. These are small text files that are stored on the device with which you access the website.

Our online shop only uses essential cookies that are necessary to ensure the core functionality of the website. The legal basis for the use of essential cookies is Art. 6 (1) lit. f GDPR - a legitimate interest.

You can also determine whether you wish to allow cookies via your browser settings. Please note that deactivating cookies may result in the website's limited or completely disabled functionality.

You can configure the handling of cookies in your browser yourself. By changing the settings in your browser, you can deactivate or restrict the transmission of cookies. You can delete cookies that have already been saved at any time. This can also be done automatically. If cookies are deactivated for our websites, it may no longer be possible to use all functions to their full extent. You can find more information on the websites of your respective browser provider:

6. Newsletters

If you subscribe to any of our newsletters, we store your e-mail address and use this to send the newsletter. Your e-mail address is not made public or disclosed to third parties.

  • Collected data: E-mail address, first name, last name, title, role
  • Purpose of use: Sending of the newsletter requested
  • Storage period: As a general rule, the data is only stored for as long as it is needed to fulfil the purpose. For the newsletter, the data are stored as long as it is expected that a newsletter will be sent and as long as you have not objected to using your data.
  • Legal basis: Art. 6 (1) lit. a GDPR - consent
  • Revocation: You can unsubscribe from our newsletter at any time using a link included in each issue. We will then delete your e-mail address from our distribution list.

7. Data subject rights

If personal data is processed by asknet as the data controller, you as the data subject have, depending on the legal basis and purpose of the processing, certain rights from Chapter III GDPR, in particular the right to information (Art. 15 GDPR), the right to correction (Art. 16 GDPR), the right to deletion (Art. 17 GDPR), the right to restriction of processing (Art. 18 GDPR), the right to data portability (Art. 20 GDPR), the right to object (Art. 21 GDPR). If the processing of personal data is based on your consent, you have the right to revoke your consent under data protection law in accordance with Art. 7 III GDPR.

To exercise your data subject rights about the data processed for the operation of this website, please contact us using the contact details provided in Section 2.

7.1 Right of complaint

You have the right to complain to a data protection supervisory authority. To do so, you can contact the data protection supervisory authority responsible for your place of residence or federal state or the data protection supervisory authority responsible for us.

This is:

The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg)

Address:

Lautenschlagerstraße 20
70173 Stuttgart
GERMANY

Postal address:

PO Box 10 29 32
70025 Stuttgart
GERMANY

Phone: +49 711 6155 41-0
Fax: +49 711 6155 41-15
E-mail: poststelle@lfdi.bwl.de

7.2 Right of objection

If we process your personal data based on our legitimate interests, you have the right to object to such processing on grounds relating to your particular situation. This applies equally to profiling. If we process personal data for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing, to the extent that profiling is involved in connection with such direct marketing.

8. Security

We use commercially reasonable and appropriate physical, technical and organisational measures and procedures to secure and protect your personal data during processing – in particular – collection, transmission and storage. Your personal data is only accessible to authorised employees who are familiar with asknet's privacy policy.

8.1 Automated decision making

With the exception of automated controls to prevent payment fraud and to avoid breaches of government sanctions lists (e.g. OFAC), we do not process your personal data for any other automated decision-making, including profiling, as addressed in Article 22 (1) and (4) GDPR.

9. Data retention

asknet retains personal data for as long as necessary to enable product sales, comply with legal obligations (statutory retention obligations), settle disputes, and enforce our agreements.

In principle, we delete your personal data as soon as it is no longer required for the aforementioned purposes unless temporary storage is still necessary. We store your personal data based on legal obligations to provide proof and to retain records, which result, among other things, from the German Commercial Code and the German Tax Act, under which retention periods of up to ten full years are provided. In addition, we retain your data for the period when claims can be asserted against our company.

Upon your request, we will restrict the processing of your personal data on the basis of applicable law. Once the legal retention periods have expired, the data will be removed from our operational systems.

10. Final provisions

asknet reserves the right to adapt this privacy policy at any time to ensure that it always complies with current legal requirements or to implement changes to the services in the privacy policy, e.g. when new services are introduced or changes are made to the online shops. The new data protection declaration will apply when you access this website again.

 

Version: April 2024