General Data Protection Regulation

The Basic Data Protection Regulation is a European Union regulation which harmonises the rules on the processing of personal data by private companies and public bodies throughout the EU.

Jafila Privacy Policy

  1. General
    1. We, the Diarat GmbH, Heiligenstädter Straße 32/105, 1190 Vienna, commercial register number FN 437566 f at the Commercial Court Vienna, phone nb. +43 664 3228441 and email address data-protection@jafila.com (in short "we" or "Diarat") take your personal data very seriously. You are welcome to address any data protection queries to our Data Protection Officer, Mr. Arian Aal-Hwaiz, using the contact information above.
    2. With this Privacy Policy we want to inform you about the purposes and manner in which we collect and process your personal information when you
      • (i)   visit our website jafila.com or its local versions such as jafila.at, jafila.de etc. (collectively „website“)surf on it and use our local information offers and the local information and merchandise or service offers of third parties,
      • (ii)   subscribe to promotional newsletters,
      • (iii)   are interested in our (advertising) services that we offer to business partners and/or advertisers and are therefore a "prospect",
      • (iv)   already belong to our business partners and/or advertising partners,
      • (v)   belong to our suppliers or other business partners, or
      • (vii)   apply as an employee.
    3. How we process your personal data depends on which of the above mentioned groups of people you belong to. The respective details can be found in the respective points of this privacy policy.
  1. Processing Data of our website visitors
    1. Our host provider
      1. Our website is hosted on our behalf on a server operated by Amazon Web Services, Inc. The server is located in Frankfurt, Germany.
    2. Cookies
      1. A cookie is a small text file that is stored on your computer or mobile device and retrieved on subsequent visits to a website to enhance and facilitate your visit. We do not use cookies to automatically store personal information or provide information to third parties. During all visits our website uses the following cookies, which process and store your personal information below for the following purposes:
        Name of cookie Personal data Purpose Duration of storage
        No cookies none personal data none Amazon Web Service,
        Inc., 410 Terry Avenue
        North, Seattle WA 98109,
        USA: Website-Hostprovider
        und Email-Dienst
        USA
      2. You can deactivate the use of cookies in your browser settings - if you want to do so, please consult your browser manual or use the "Help" button in the menu bar of your browser.
    3. Non-registered users
      1. If you visit and surf on our website but are not a registered user or have not logged into our website with your user account or via Facebook, we will process your personal information to ensure the security and operation of the website as well as to improve our website, which safeguards our legitimate interests (Article 6 (1) (f) GDPR).
      2. For these purposes, the following data is collected and stored on our website: IP address, country, date, time and duration of the website access including the individual pages visited, including the duration of the page visit and your respective entry and exit pages, browser type and operating system.
    4. Registered users
      1. Users logged in via website account: You can create a user account on the website that you can use to log in to the website. You can also log in via Facebook using your Facebook account (to log in via Facebook see the paragraph below) on our website.
      2. If you create a user account on our website and thus log in to the website, we will process, in addition to your data mentioned in points 2.2 and 2.3, the following data that you have provided for the purpose of creating the account and additionally specified (optionally) in your user profile: username and email address, the optional additional data you specify in your user profile, such as profile picture, first name, last name, date of birth, your website, your Twitter, Facebook and Instagram account names including URL to your local profiles, affiliation (including legal form), gender, address, biography, uploaded photos, friends and favorites added (such as other registered website users and business partners and affiliates/or promotional partners), phone number and current location.

        If you do not provide us with your username or email address, you will not be able to register or log in to the website and you will only be able to visit the website as a non-registered user (see point 2.3).

        We process this data so that we can provide you with the services of our website, such as the insertion of personalized advertising (our website and the information there is available to users free of charge), the interaction with other users (including our business and advertising). Partners) and the brokering of contracts (eg if you buy something from another user or one of our business or advertising partners via the website or sell something to another user via the website).

        We rely on your consent in this regard (Article 6 (1) (a) GDPR), which you can revoke at any time by sending us an appropriate email to data-protection@jafila.com (ideally using the subject "Privacy Revocation", so that we can better recognize your e-mail and process it more quickly, but this is not mandatory). Your revocation has no effect on the legality of our data processing until we receive your revocation (Article 7 (3) GDPR).
      3. Users logged in via their Facebook account: If you log in to the website via your Facebook account, in addition to the data mentioned in points 2.2 and 2.3, we will process the following data that will be provided by the Privacy Shield Facebook Inc., 1601 Willow Road, CA-94025 Menlo Park, USA: Your so-called "Public Profile", your so-called "Friends List" and your email address, which you have deposited on Facebook.

        The Facebook log-in screen gives you more detailed information on which of your data is concerned and you can choose which of these data you want to submit to us; however, it is necessary to submit your "Public Profile" to us - if you do not provide us with your "Public Profile", you will not be able to log in via Facebook on the website and will only be able to visit the website as a non-registered user (see Point 2.3).

        We rely on your consent in this regard (Article 6 (1) (a) GDPR), which you can revoke at any time by changing your selection on the Facebook log-in screen or by sending an email to data-protection@jafila.com (ideally with the subject "privacy revocation", so that we can better recognize your email and thus process faster, but this is not mandatory), whereby your revocation does not affect the legality of our data processing until we receive your revocation (Article 7 (3) GDPR).
      4. We process this data so that we can provide you with the services of our website, such as the insertion of personalized advertising (our website and the information there is available to users free of charge), interaction with other users (including our business users) and advertising partners) and the brokering of contracts (eg if you buy something from another user or one of our business or advertising partners via the website or sell something to another user via the website).

        We rely on your consent in this regard (Article 6 (1) (a) GDPR), which you can revoke at any time by sending an email to data-protection@jafila.com (ideally with the subject "Privacy Revocation", so that we can better recognize your e-mail and process it more quickly, but this is not mandatory), whereby your revocation has no effect on the legality of our data processing until we receive your revocation (Article 7 (3) GDPR).
    5. In order to fulfill the above-mentioned purposes, we work with service providers (so-called "contract processors") who process your personal data on our behalf and for our - but not for their own - purposes. These contract processors are the following:
      AV Country of registered seat Basis for
      data transfer for
      non-EU countries
      Amazon Web Service,
      Inc., 410 Terry Avenue
      North, Seattle WA 98109,
      USA: Website-Hostprovider
      und Email-Dienst
      Amazon Web Service,
      Inc., 410 Terry Avenue
      North, Seattle WA 98109,
      USA: Website-Hostprovider
      und Email-Dienst
      Privacy Shield; The Privacy
      Shield status of
      Amazon Webservices Inc
      can be accessed
      here: Link
    6. In order to fulfill the above-mentioned purposes, we also transmit your personal data to the following data protection officers who process the data for their own purposes:
      AV Country of registered seat Basis for
      data transfer for
      non-EU countries
      Our advertising partners
      for the display of
      personalized
      advertising; ; You can find
      the list of our advertising partners
      here:

      Google LCC (für Google
      Adwords), 1600
      Amphitheatre Pkwy,
      Mountain View, California
      94043, USA
      USA Privacy Shield; der Status
      der Privacy Shield of
      Google LLC can be accessed
      here: Link
  1. Data processing of advertising newsletter subscribers
    1. If you have given us your consent to receive electronic promotional newsletters, we will process the personal contact details you have provided, such as your first and last name, as well as your email address and language selection, in order to send the newsletter with personal address, and if necessary, we also process the possible information that the email newsletter could not be delivered to you (eg because your email address no longer exists).
      If you do not provide us with the relevant personal data, we will not be able to send you the desired electronic advertising newsletter.
      In this case, we rely on your consent to receive electronic promotional newsletter (Article 6 (1) (a) GDPR in conjunction with § 107 (2) of the Austrian Telecommunications Act, German acronym: "TKG"), which you can revoke at any time by either clicking on the unsubscribe link that you can find in each newsletter, email us at data-protection@jafila.com (ideally with the subject "privacy notice" so we can better identify your email and process it faster, but this is not mandatory), or change your settings or information in your account on the website, whereby your revocation has no effect on the legality of our data processing until we receive your revocation (Article 7 (3) GDPR).
    2. In order to fulfill the above mentioned purposes, we cooperate with service providers (so-called "contract processors") who process your personal data on our behalf and for our - but not for their own - purposes. These contract processors are the following:
      AV Country of registered seat Basis for
      data transfer for
      non-EU countries
      Amazon Web Service,
      Inc., 410 Terry Avenue
      North, Seattle WA 98109,
      USA: Website-Hostprovider
      und Email-Dienst
      USA Privacy Shield; The Privacy
      Shield status of
      Amazon Webservices Inc
      can be accessed
      here: Link
    3. In order to fulfill the above-mentioned purposes, we also transmit your personal data to the following data protection officers who process the data for their own purposes:
      AV Country of registered seat Basis for
      data transfer for
      non-EU countries
      Google LLC (for Google
      AdWords), 1600
      Amphitheatre Pkwy,
      Mountain View, California
      94043, USA
      USA Privacy Shield; der Status
      der Privacy Shield of
      Google LLC can be accessed
      here: Link
  1. Data processing of our prospective customers
    1. If you send us a request by telephone, mail, email or via the contact form on the website, we will process the contact details you have given us, such as your academic title, first and last name, email address, position within the requesting person’s company, your address or the address of the requesting company in order to respond to the request, and thus to carry out pre-contractual actions that are based on your request (Article 6 (1) (b) GDPR).

      If you do not provide us with the relevant personal data, we are unable to process your request.
    2. In order to fulfill the above mentioned purposes, we cooperate with service providers (so-called "contract processors") who process your personal data on our behalf and for our - but not for their own - purposes. These contract processors are the following:
      AV Country of registered seat Basis for
      data transfer for
      non-EU countries
      Amazon Web Service,
      Inc., 410 Terry Avenue
      North, Seattle WA 98109,
      USA: Website-Hostprovider
      und Email-Dienst
      USA Privacy Shield; The Privacy
      Shield status of
      Amazon Webservices Inc
      can be accessed
      here: Link
  1. Data processing of our business and advertising partners
    1. If you are our business and/or promotional partner, we will process your personal information, such as your academic title, first and last name, email address, position with the contracting company, your address or the business and/or advertising partner’s company address, as well as your or your company’s billing information (such as name and BIC/SWIFT of the bank, the IBAN of the bank account) to carry out pre-contractual measures and to fulfill our contractual obligations under the contractual relationship (Article 6 (1) (b) GDPR) and to comply with our legal obligations (Article 6 (1) (c) GDPR).

      If you do not provide us with the corresponding personal data, we cannot enter into any contractual relationship with you.
    2. In order to fulfill the above mentioned purposes, we cooperate with service providers (so-called "contract processors") who process your personal data on our behalf and for our - but not for their own - purposes. These contract processors are the following:
      AV Country of registered seat Basis for
      data transfer for
      non-EU countries
      Amazon Web Service,
      Inc., 410 Terry Avenue
      North, Seattle WA 98109,
      USA: Website-Hostprovider
      und Email-Dienst
      USA Privacy Shield; The Privacy
      Shield status of
      Amazon Webservices Inc
      can be accessed
      here: Link
    3. In order to fulfill the above-mentioned purposes, we also transfer your personal data to the following Data controllers, who process the data for their own purposes:
      Data controllers Country of registered seat None-EU
      Raiffeisen Bank International;
      our bank where our
      business accounts are located
      Austria Not applicable, as in
      the EU
      Paypal
      (Payment service provider)
      Luxembourg Not applicable, as in
      the EU
      Braintree Payments Luxembourg Not applicable, as in
      the EU
  1. Processing date of our suppliers and other business partners (except business partners and advertising partners within the “Jafila Business Network”)
    1. If you supply us with goods and/or services, or are otherwise our business partner (but not one of our business partners or advertising partners within the “Jafila Business Network”), we process your personal data, such as your academic title, your first and last name, your email address, your position within the respective company, your address or the address of the company, which is our supplier/business partner, as well as your business or billing information (such as name and BIC / SWIFT of the bank and the IBAN of the bank account) in order to carry out pre-contractual measures (eg down payments) or to fulfill our contractual obligations under the contractual relationship (Article 6 ( 1) (b) GDPR) and to comply with our legal obligations (Article 6 (1) (c) GDPR ).

      If you do not provide us with the relevant personal data, we cannot enter into any contractual relationship with you.
    2. In order to fulfill the above-mentioned purposes, we cooperate with service providers (so-called "contract processors") who process your personal data on our behalf and for our - but not for their own - purposes. These contract processors are the following:
      AV Country of registered seat Basis for
      data transfer for
      non-EU countries
      Amazon Web Service,
      Inc., 410 Terry Avenue
      North, Seattle WA 98109,
      USA: Website-Hostprovider
      und Email-Dienst
      USA Privacy Shield; The Privacy
      Shield status of
      Amazon Webservices Inc
      can be accessed
      here: Link
    3. In order to fulfill the above-mentioned purposes, we also transfer your personal data to the following Data controllers who process the data for their own purposes:
      Data controllers Country of registered seat None-EU
      Raiffeisen Bank International;
      our bank where our
      business accounts are located
      Austria Not applicable, as in
      the EU
  1. Data processing of our applicants
    1. If you apply for a job within our company, we process your personal data that you provide us in your application letter and in your CV, such as your academic title, your first and last name, your email address, your address and your career information, to carry out pre-contractual measures, such as the initiation of employment (Article 6 (1) (b) GDPR).
    2. If you give us your consent to keep you in evidence, we process your personal data mentioned above for this purpose. In this case, we rely on your consent to the evidence (Article 6 (1) (a) GDPR), which you can revoke at any time by sending us an appropriate email to data-protection@jafila.com (ideally with the subject "Privacy "Revocation", so that we can better recognize your email and thus process faster, but this is not mandatory), whereby your revocation has no effect on the legality of our data processing until we receive your revocation (Article 7 (3) GDPR).
    3. In order to be able to fulfill the purposes set out in points 7.1 and 7.2, we cooperate with service providers (so-called "contract processors") who process your personal data on our behalf and for our - but not for their own - purposes. These contract processors are the following:
      AV Country of registered seat Basis for
      data transfer for
      non-EU countries
      Amazon Web Service,
      Inc., 410 Terry Avenue
      North, Seattle WA 98109,
      USA: Website-Hostprovider
      und Email-Dienst
      USA Privacy Shield; The Privacy
      Shield status of
      Amazon Webservices Inc
      can be accessed
      here: Link
  1. Storage time
    1. We generally store your personal data only as long as this is necessary for the fulfillment of the respective purpose for which your personal data was collected.
    2. For tax reasons, we store contract documents and the associated documents and communications relating to our contractual relationships with business partners, advertising partners and our suppliers and other business partners for a period of seven years (Section 132 of the Austrian Federal Tax Code, abbreviated to "BAO"). In order to assert or defend against legal claims, we retain this data in individual cases and in the light of Section 1489 of the Austrian General Civil Code ("ABGB") but also up to thirty years after the full termination of contractual relationships.
    3. If you have subscribed to promotional newsletters, we will store your relevant personal data until we have received your revocation of your consent in this regard or until you unsubscribe from the respective advertising newsletter (including the change of your respective settings in your user account).
    4. If you have applied for a job within our company, but we have not entered into a contractual relationship, we will delete your personal data six months after we have received your application, unless you have agreed to be kept in evidence for any future vacancies in our company.
  1. Your rights as a "data subject"
    1. As "data subject" you may assert the following rights regarding the processing of your data:
      1. Right of information, details in Article 15 of the GDPR: Any person affected by data processing has the right to ask our Data Protection Officer as to wether we process your personal data, and if so, which of your personal data we process and to what extent. You have the right to demand a copy of the personal data which is the subject of the processing and to the following information: (a) the processing purposes; (b) the categories of personal data being processed; (c) the recipients or categories of recipients to whom the personal data have been disclosed or are still being disclosed, in particular to recipients in third countries or to international organizations; (d) the duration for which the personal data are stored or, if this is not possible, the criteria for determining that duration; (e) the right of rectification or erasure of your personal data, or the limitation of the controllers processing or the right to object to such processing; (f) the existence of a right of appeal to a supervisory authority; (g) if the personal data are not collected directly from the data subject, all available information on the source of the data; (h) the existence of automated decision-making including profiling.. For all other copies requested, the Data Protection Officer may request an appropriate fee based on the administrative costs. If the data subject files the application electronically, the information shall be provided in a standard electronic format unless otherwise indicated;
      2. Right to correction and deletion, details in Article 16 GDPR: You have the right to demand the correction of inaccurate or incomplete personal data. In consideration of the purposes of the processing, you have the right to request the completion of incomplete personal data, including by means of a supplementary statement. Furthermore, you may request that we delete your personal data without delay. The controller is obliged to delete personal data immediately, if one of the following reasons applies: (a) The processing of the personal data are no longer necessary for the original purposes. (b) You have revoked your consent and there is no other legal basis for processing (c) You file an objection (see below) against processing. (d) The personal data were processed unlawfully. (e) The deletion of personal data is required to fulfill a legal obligation. (f) The personal data has been collected in relation to information society services offered (consent of a child). The right of cancellation does not exist insofar as the processing is necessary to fulfill a legal obligation on the part of the controller, or to perform a task in the public interest or in the exercise of public authority delegated to the controller and/or assertion, exercise or defense of legal claims.
      3. Right to Restrict Processing, details in article 18 GDPR: You have the right to require the restriction of the processing if one of the following conditions is met: (a) you dispute the correctness of the data for a period of time that allows us to verify the accuracy of the data, (b) the processing is unlawful, but you opt against deletion and instead request restriction of the use of your data (c) we do not longer need your personal data for the original purposes of processing, but but you still need the data to assert, exercise or defend your legal rights, (d) you have objected to the processing of the data until it has been established whether the legitimate reasons of the controller outweigh yours. If the processing has been restricted, the personal data may be stored only with your consent or for the purpose of asserting, exercising or defending legal claims or protecting the rights of another natural or legal person or for reasons of significant public interest of the European Union or a Member State. If you have restricted processing, you will be notified by the controller before any restriction is lifted.
      4. Right to Restrict Processing, details in article 18 GDPR: You have the right to require the restriction of the processing if one of the following conditions is met: (a) you dispute the correctness of the data for a period of time that allows us to verify the accuracy of the data, (b) the processing is unlawful, but you opt against deletion and instead request restriction of the use of your data (c) we do not longer need your personal data for the original purposes of processing, but but you still need the data to assert, exercise or defend your legal rights, (d) you have objected to the processing of the data until it has been established whether the legitimate reasons of the controller outweigh yours. If the processing has been restricted, the personal data may be stored only with your consent or for the purpose of asserting, exercising or defending legal claims or protecting the rights of another natural or legal person or for reasons of significant public interest of the European Union or a Member State. If you have restricted processing, you will be notified by the controller before any restriction is lifted.
      5. Right of objection,details in article 21 GDPR: For reasons arising out of your particular situation, you may at any time object to the processing of personal data relating to you which are required in order to safeguard our legitimate interests or those of a third party. Following your objection, the controller then no longer processes your personal data unless he can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or the processing is for the purpose of enforcing, pursuing or defending legal claims. You may object at any time to our forwarding of advertising to you without any need to state reasons for this.
      6. Right of Appeal to the Supervisory Authority If you believe that we are in violation of Austrian or European data protection laws when processing your data, we would ask you to contact us in order to resolve any questions you may have. You also have the right to contact the competent data protection authority. You also have the right to contact the EU Supervisory Authority of the Member State of your residence. The contact details of the Austrian Data Protection Authority can be found here: https://www.dsb.gv.at/.
    2. For any queries regarding data protection at Diarat, we are happy to be available under our contact details mentioned in point Punkt 1.1.