Crisam Logo
  • CRISAM®
    CRISAM®
    • What is CRISAM®?
    • Method
    • Content
    • Continuing education
    • Events
    • Customers
    • Webinars
  • Areas of application
    Areas of application
    • Information Security Management
    • Integrated Risk Management
    • Data protection management
    • Internal Control System & Audit Management
    • Business Continuity Management
    • Project Risk Management
    • CRISAM® Legal Hold Software
    • CRISAM® Compliance powered by Deloitte
    • ESG
    • DORA
    • Compliance Management
    • Tax Compliance Management System
    • Global Internal Audit Standards
    • Legal register
    • Approvals & Disclosures Workflow Software
    • Conflicts of Interest Software
  • Industries
    Industries
    • Automobile
    • Energy
    • Health
    • Manufacturing
    • Finance
    • Trade
    • Real estate & construction industry
    • Broadcasting & Telecommunications
    • Technology
    • Transportation & Logistics
  • CRISAM® Compliance powered by Deloitte
  • More
    More
    • Download Center
    • News
    • CRISAM® Partner
    • CRISAM® Academy
    • Jobs
    • Contact
  • en
    • de
Request
  • Language
    • de
  • CRISAM®
    • What is CRISAM®?
    • Method
    • Content
    • Continuing education
    • Events
    • Customers
    • Webinars
  • Areas of application
    • Information Security Management
    • Integrated Risk Management
    • Data protection management
    • Internal Control System & Audit Management
    • Business Continuity Management
    • Project Risk Management
    • CRISAM® Legal Hold Software
    • CRISAM® Compliance powered by Deloitte
    • ESG
    • DORA
    • Compliance Management
    • Tax Compliance Management System
    • Global Internal Audit Standards
    • Legal register
    • Approvals & Disclosures Workflow Software
    • Conflicts of Interest Software
  • Industries
    • Automobile
    • Energy
    • Health
    • Manufacturing
    • Finance
    • Trade
    • Real estate & construction industry
    • Broadcasting & Telecommunications
    • Technology
    • Transportation & Logistics
  • CRISAM® Compliance powered by Deloitte
  • More
    • Download Center
    • News
    • CRISAM® Partner
    • CRISAM® Academy
    • Jobs
    • Contact
  • Request
CRISAM Newsletter

Groups of data subjects according to DSGVO

Interested party

Interested parties are all those persons who are interested in our product and our other services and who are regularly informed about new ones.

Personal data of interested parties are processed within the scope of the following processing activities for the purposes listed below:

Processing activity
Providing information
Event management
Personal contact

Purpose of processing

To provide information about news, products and services
To plan and organize training and information events of CALPANA
To provide information about news, products and services in the context of a personal conversation

The legal basis for the processing of personal data of interested parties is based on the following legal basis or legitimate interests:

Processing activity
Providing information
Event management
Personal contact

Legal basis / legitimate interest

Consent
Consent
Consent

Within the scope of the processing activity “Provision of Information”, “Event Management” and “Personal Contact”, joint processing of CALPANA Austria and CALPANA Germany may occur. The object of the processing is the management of contacts in order to provide cross-border services accordingly.

The following categories of personal data are processed in the listed processing activities:

Processing activity

Provision of information, personal contact

Event management

Data category

Data for contact management

Contact details for events

Types of data contained therein

data include name, telephone number, e-mail, address, function in the company and additional notes (interest of the interested party – in the product, service or events, for example).

Data include name, telephone number, e-mail, address and possibly billing address.

In the context of the processing activities we carry out, we do not transfer personal data, of the groups of data subjects concerning you, to any recipients or categories of recipients.

We store your personal data as long as this is required by law, is necessary for the purpose or the use in accordance with the legitimate interest of the company requires it. The deletion period listed below follows this storage period.

Data category

Data for contact management
Contact details for events

Storage period

Until revoked.
Until shortly after the end of the event.

Deletion period

Immediately after revocation.
Immediately after storage period.

Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Data for contact management
Contact details for events

Origin

From the person concerned themselves.
From the person concerned themselves.

No automated decision-making, including profiling, is carried out in any of the above-mentioned processing activities.

Customer

Customers are all those persons who request and purchase products and services from us. Personal data of customers are processed within the scope of the following processing activities for the purposes mentioned below:

Processing activity

Order processing
Provision of information
Event management

Purpose of processing

Processing of orders and invoicing of services.
To provide information about products and services.
Planning and organization of events to present the company and its products and services.

The legal basis for the processing of personal data of customers is based on the following legal basis or legitimate interests:

Processing activity

Order processing
Provision of information
Event management

Legal basis / legitimate interest

The respective contract with the customer.
Legitimate interest (maintaining contact).
Consent, legitimate interest (maintaining contact).

In the context of the processing activity “order processing”, joint processing of CALPANA Austria and CALPANA Germany may occur. The purpose of the processing is the management of contacts for the provision of the services to be provided under the joint contracts or agreements.
However, only the contact details (name, email, address and telephone number) are processed.

The following categories of personal data are processed in the listed processing activities:

Processing activity

Order processing, provision of information

Order processing

Event management

Order processing

Data category

Customer master data

Customer properties

Contact details for events

Project data

Types of data contained therein

data include name, address, company register number, VAT ID, e-mail and telephone number.

data include sales, payment history, contact persons and offers.

data include name, telephone number, e-mail, address and possibly billing address.

data include backups of project files.

In the context of the processing activities we carry out, we do not transfer personal data, of the groups of data subjects concerning you, to any recipients or categories of recipients.

We store your personal data as long as this is required by law, is necessary for the purpose or the use in accordance with the legitimate interest of the company requires it. The deletion period listed below follows this storage period.

Data category

Customer master data

 

 

 

 

Customer properties

 

 

 

 

Contact details for events

 

Project data

Storage duration

Austria: As long as the business relationship continues and all receivables have been settled. After that, the processing is restricted and the data is stored for 7 years after the approved annual financial statement (according to BAO).
Germany: As long as the business relationship continues and all receivables have been settled. Thereafter, processing is restricted and the data is stored for 10 years after the approved annual financial statements (in accordance with Section 147 (3) in conjunction with (1) Nos. 1, 4 and 4a AO, Section 14b (1) UStG).

 

Austria: As long as the business relationship continues and all receivables have been settled. After that, the processing is restricted and the data is stored for 7 years after the approved annual financial statement (according to BAO).
Germany: As long as the business relationship continues and all receivables have been settled. Thereafter, processing is restricted and the data is stored for 10 years after the approved annual financial statements (in accordance with Section 147 (3) in conjunction with (1) Nos. 1, 4 and 4a AO, Section 14b (1) UStG).

 

Until shortly after the end of the event or after the termination of the business relationship.

 

Austria: As long as the business relationship continues and all receivables have been settled. Thereafter,
processing is restricted and the data is stored for 7 years after the approved annual financial statements (according to BAO).
Germany: As long as the business relationship continues and all claims have been settled. Thereafter, processing is restricted and the data is stored for 10 years after the approved annual financial statements (in accordance with Section 147 (3) in conjunction with (1) Nos. 1, 4 and 4a AO, Section 14b (1) UStG).

Deletion period

After the storage period within a deletion cycle of one year.

 

 

 

After the storage period within a deletion cycle of one year.

 

 

Immediately after the storage period.

 

Immediately after the storage period.

Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Customer master data
Customer properties
Contact details for events
Project data

Processing activities Automated decision-making, including profiling, carried out.

Origin

From customer contact or prospective customer contact.
From customer contact or prospective customer contact.
From customer contact or prospective customer contact.
From the customer itself.

Supplier

Suppliers are all those persons who transfer or provide goods or services to our company by delivery.
Personal data of suppliers are processed within the scope of the following processing activities for the purposes listed below:

Processing activity

Provision of services

Purpose of processing

Contact person data is processed in the course of providing the service from suppliers.

The legal basis for the processing of personal data of suppliers is based on the following legal basis or legitimate interests:

Processing activity

Provision of services

Legal basis / legitimate interest

The respective contract with the supplier

In the context of the processing activity “provision of services”, joint processing by CALPANA Austria and CALPANA Germany may occur. The purpose of the processing is the management of contacts for the purchase and use of standardized services.
However, only the contact details (name, email, address and telephone number) are processed.

The following categories of personal data are processed in the listed processing activities:

Processing activity

Provision of services

Data category

Supplier contact data

The types of data contained therein

data include name, telephone number, e-mail and address.

In the course of the processing activities carried out by us, we transmit personal data, of the categories of data subjects concerning you, to the following recipients or categories of recipients:

Data type

Bank details, name

Recipient

Bank

EU third country [Y/N]

N

Purpose of the transmission

Execution of the settlement.

We store your personal data as long as this is required by law, is necessary for the purpose or the use in accordance with the legitimate interest of the company requires it. The deletion period listed below follows this storage period.

Data category

Supplier contact data

Storage duration

Austria: As long as the business relationship continues and all liabilities have been settled. After that, processing is restricted and data is stored for 7 years after approved annual financial statements (according to BAO), due to the retention of invoice data.

Germany: As long as the business relationship continues and all liabilities have been settled. After that, processing is restricted and the data is stored for 10 years after the approved annual financial statements (in accordance with § 147 para. 3 in conjunction with para. 1 nos. 1, 4 and 4a AO, § 14b para. 1 UStG), due to the retention of invoice data.

Deletion period

After the storage period within a deletion cycle of one year.

Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Supplier contact data

No automated decision-making, including profiling, is carried out in any of the above processing activities.

Origin

From the supplier himself.

Training participant

Training participants are all those persons who take part in training courses of our company and thereby obtain special or extended qualifications and advanced training in the use of the software or other subject areas. Likewise, customers can also be considered as training participants.

Personal data of training participants are processed within the framework of the following processing activities for the purposes mentioned below:

Processing activity

Implementation of external training courses

Purpose of processing

Conducting external training courses for further training and obtaining further qualifications.

The legal basis for the processing of personal data of training participants is based on the following legal basis or legitimate interests:

Processing activity

Implementation of external training courses

Legal basis / legitimate interest

Contract (service)

The following categories of personal data are processed in the listed processing activities:

Processing activity

Implementation of external training courses

Data category

Training participant data

Types of data contained therein

Data include company name, name, address, status of completed training courses and examinations

In the context of the processing activities we carry out, we do not transfer personal data, of the groups of data subjects concerning you, to any recipients or categories of recipients.

We store your personal data as long as this is required by law, is necessary for the purpose or the use in accordance with the legitimate interest of the company requires it. The deletion period listed below follows this storage period.



Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Training participant data

Origin

From the person concerned.

No automated decision-making, including profiling, is carried out in any of the above-mentioned processing activities.

Data category

Training participant data

Storage duration

Until the termination of the business relationship. Except the tests are kept for a period of 3 years, for traceability and issuance of a certificate if necessary.

Deletion period

Immediately after the storage period.

Applicant

Applicants are all those persons who apply for a vacant position or submit an unsolicited application to the company.
Personal data of applicants are processed for the following purposes as part of the following processing activities:

Processing activity

Applicant management

Purpose of processing

Selection of a suitable person for the vacant position.

The legal basis for the processing of personal data of applicants is based on the following legal basis or legitimate interests:

Processing activity

Applicant management

Legal basis / legitimate interest

Contract (pre-contractual relationship)

The following categories of personal data are processed in the listed processing activities:

Processing activity

Applicant management

Data category

Applicant data

Types of data contained therein

Data include master data (name, address, telephone number, date of birth, gender, ev. religious confession, marital status), professional certificates, application photo, certificates, application letter (are personal data and contents of the applicant indicated, which he / she reveals himself). Among other things, it may contain Art. 9 data (health data, religious confession) or Art. 10 data (criminal convictions).

As part of the processing activities we carry out, we do not transfer personal data relating to you to any recipients or categories of recipients.
We store your personal data for as long as this is required by law, is necessary for the purpose or is required for use in accordance with the legitimate interests of the company. The deletion period listed below follows this storage period.

Data category

Applicant data

Storage duration

Austria: 6 months after the position was filled or rejected (according to GlBG) incl. a buffer period of one month.
Germany: 2 months after cancellation

Deletion period

Immediately after the storage period.

Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Applicant data

Origin

From the applicant or personnel service provider.

No automated decision-making, including profiling, is carried out in any of the above-mentioned processing activities.

 

Website visitors

Website visitors are all those persons who, within a certain measured time, call up our website and thus “visit” it.
Personal data of website visitors are processed within the scope of the following processing activities for the purposes mentioned below:

Processing activity

Processing of contact requests

Purpose of processing

Processing of website form inquiries in order to provide the enquirer with appropriate support.

The legal basis for the processing of personal data of website visitors is based on the following legal basis or legitimate interests:

Processing activity

Processing of contact requests

Legal basis / legitimate interest

Legitimate interest (business processing)

The following categories of personal data are processed in the listed processing activities:

Processing activity

Processing of contact requests

Data category

Contact form

The types of data contained therein

data are the subject and the exact description of the request, name, telephone number and e-mail.

In the context of the processing activities we carry out, we do not transfer personal data, of the groups of data subjects concerning you, to any recipients or categories of recipients.

We store your personal data as long as this is required by law, is necessary for the purpose or the use in accordance with the legitimate interest of the company requires it. The deletion period listed below follows this storage period.

Data category

Contact form

Storage period

The data is stored until the support case is closed or for up to one year thereafter in order to ensure appropriate traceability.

Deletion period

Immediately after the storage period.

Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Contact form

Origin

From the person concerned.

No automated decision-making, including profiling, is carried out in any of the above-mentioned processing activities.

External service provider

External service providers are all those persons who provide services to the company and charge accordingly.
Personal data of external service providers are processed within the scope of the following processing activities for the purposes listed below:

Processing activity

Service provision
Cost allocation

Purpose of processing

Verification of the performance of the external service provider.
Billing for the services of external service providers.

The legal basis for the processing of personal data of external service providers is based on the following legal basis or legitimate interests:

Processing activity

Service provision

Cost allocation

Legal basis / legitimate interest

Contract with the external service provider in each case.

Contract with the external service provider in each case.
Austria: Legal basis (Section 132 BAO)
Germany: Legal basis (Section 147 AO, Section 257 HGB)

The following categories of personal data are processed in the listed processing activities:

Processing activity

Service provision,
Service allocation

Data category

Data from external service providers

The types of data contained therein

data include company name, name, telephone number, bank details, service and payment.

In the course of the processing activities carried out by us, we transmit personal data, of the categories of data subjects concerning you, to the following recipients or categories of recipients:

Data type

Bank details, name, fee

Recipient

Bank

EU third country [Y/N]

N

Purpose of the transmission

Execution of the settlement.

We store your personal data as long as this is required by law, is necessary for the purpose or the use in accordance with the legitimate interest of the company requires it. The deletion period listed below follows this storage period.

Data category

Data from external service providers

Storage duration

Austria: As long as the business relationship continues and all liabilities have been settled. After that, processing is restricted and data is stored for 7 years after approved annual financial statements (according to BAO), due to the retention of invoice data.

Germany: As long as the business relationship continues and all liabilities have been settled. Thereafter, the processing is restricted and the data is stored for 10 years after the approved annual financial statements (§ 147 para. 3 in connection with para. 1 No. 1, 4

Deletion period

Immediately after the storage period.

Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Data from external service providers

Origin

From the external service provider itself.

No automated decision-making, including profiling, is carried out in any of the above-mentioned processing activities.


Third

Third parties are all those persons who do not belong to one of the other categories of data subjects.

Personal data of third parties are processed in the context of the following processing activities for the purposes listed below:

Processing activity

erroneous contact

Purpose of processing

Processing of erroneous contact via e-mail.

The legal basis for the processing of personal data of third parties is based on the following legal basis or legitimate interests:

Processing activity

erroneous contact

Legal basis / legitimate interest

legitimate interest (processing of inquiries)

The following categories of personal data are processed in the listed processing activities:

Processing activity

erroneous contact

Data category

Contact details of the third party

The types of data contained therein

data include name, telephone number and e-mail.

As part of the processing activities we carry out, we do not transfer personal data relating to you to any recipients or categories of recipients.
We store your personal data for as long as this is required by law, is necessary for the purpose or is required for use in accordance with the legitimate interests of the company. The deletion period listed below follows this storage period.

Data category

Contact details of the third party

Storage period

Erroneous e-mails are accepted and stored for as long as they have been processed.

Deletion period

Immediately after the storage period.

Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Contact details of the third party

Origin

by the person concerned himself

No automated decision-making, including profiling, is carried out in any of the above-mentioned processing activities.


Newsletter recipients

Newsletter recipients are all those persons who register to receive the newsletter.
Personal data of newsletter recipients are processed within the scope of the following processing activities for the purposes stated below:

Processing activity

Newsletter

Purpose of processing

Sending information about the product, events, general information about CRISAM®, CALPANA and risk management.

The legal basis for the processing of personal data of newsletter recipients is based on the following legal basis or legitimate interests:

Processing activity

Newsletter

Legal basis / legitimate interest

Consent

The following categories of personal data are processed in the listed processing activities:

Processing activity

Newsletter

Data category

Newsletter form

The data types contained therein

data are title, name and email address.

In the context of the processing activities we carry out, we do not transfer personal data, of the groups of data subjects concerning you, to any recipients or categories of recipients.

We store your personal data as long as this is required by law, is necessary for the purpose or the use in accordance with the legitimate interest of the company requires it. The deletion period listed below follows this storage period.

Data category

Newsletter form

Storage period

Until further notice.

Deletion period

1 year after revocation for traceability.

Art. 14 DSGVO also requires us to provide information about the origin of the data we process for the groups of data subjects concerning you:

Data category

Newsletter form

Origin

From the person concerned.

No automated decision-making, including profiling, is carried out in any of the above-mentioned processing activities.

No risk - let's just stay in touch!

Telefonsymbol in grün für Kontaktaufnahme.
Phone

+43 732 601 216-0

Umschlag-Icon in grün, das den Versand von E-Mails symbolisiert.
E-Mail

office@crisam.net

Papierflieger in grün, der die Versandoption für E-Mails symbolisiert.
Newsletter

Register now

CRISAM GRC Software
Darstellung eines Trends im Risikomanagement

CALPANA business consulting GmbH

Blumauerstr. 45-47

4020 Linz, Austria

+43 732 601 216-0 sales@crisam.net

CALPANA business consulting Deutschland GmbH

Paul-Dessau-Str. 1

22761 Hamburg, Germany

+49 (40) 35 98 29 21 sales@crisam.net

CALPANA business consulting GmbH

Blumauerstr. 45-47

4020 Linz, Austria

+43 732 601 216-0 sales@crisam.net

CALPANA business consulting Deutschland GmbH

Paul-Dessau-Str. 1

22761 Hamburg, Germany

+49 (40) 35 98 29 21 sales@crisam.net
CRISAM®
  • What is CRISAM?
  • CRISAM® Method
  • CRISAM® Content
  • Events
  • Continuing education
Operational area
  • Information Security Management
  • Data protection management
  • Integrated Risk Management
  • Internal Control System & Audit Management
  • Business Continuity Management
  • Project Risk Management
Industries
  • Automobile
  • Energy
  • Health
More
  • Download Center
  • CRISAM® Partner
  • News
  • Contact

© 2026 CALPANA business consulting GmbH. All rights reserved.

  • Imprint
  • Privacy
linkedin
xing