1. Controller
The controller responsible for the processing of personal data on this website is:
Pharmacom Handels GmbH
Makartgasse 3/21
1010 Vienna, Austria
Email: datenschutz@pharmacom.at
Phone: +43 1 272 4555
2. Hosting, Technical Operation & Data Processing
2.1 Web Hosting by Webflow
Our website is hosted and operated via Webflow, Inc., a US-based website platform.
When you visit our website, Webflow processes technical data required to deliver the website and ensure stability and security, including:
- IP address
- Timestamp of the request
- Referrer URL
- Browser type and version
- Operating system
- Access status and error codes
- Device information
Webflow stores this data in server log files. Webflow acts as a processor under Art. 28 GDPR.
Data may be transferred to the United States. Webflow relies on the EU Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection under Art. 46 GDPR.
Further information: https://webflow.com/legal/privacy
2.2 Technical Operation & Additional Processing by Binder Pharma Services GmbH (Company B)
The technical maintenance and operational management of this website—including server administration, error monitoring, performance logging, and processing of form submissions—is performed by:
Binder Pharma Services GmbH
Wurmbrandgasse 15/7
1220 Vienna, Austria
Binder Pharma Services GmbH acts as a data processor pursuant to Art. 28 GDPR.
A data processing agreement (DPA) has been concluded.
Binder processes the following categories of personal data on our behalf:
- Server log data (IP address, request metadata)
- Contact form submissions (names, email addresses, phone numbers, company data, and any voluntarily submitted content)
- Technical usage data (browser information, session data, device identifiers)
- Error logs and security-related metadata
Processing is based on our legitimate interest in the secure, stable, and efficient operation of our website (Art. 6(1)(f) GDPR).
3. Contact Form & Communication
If you contact us through a contact form on our website, we process the personal data you provide, such as:
- Name
- Email address
- Phone number
- Company (optional)
- Message content
We process this data in order to respond to your inquiry (Art. 6(1)(b) GDPR – performance of a contract or pre-contractual steps; or Art. 6(1)(f) GDPR – legitimate interests in communication).
Data may be processed by Binder Pharma Services GmbH on our behalf for technical handling of form submissions.
We store contact inquiries for as long as necessary to handle your request, and beyond that only if required by law or for the establishment or defense of legal claims.
4. Cookies
Our website uses only essential session cookies that are technically required for the proper display and functionality of the website.
- These cookies do not contain personally identifiable information.
- They expire automatically at the end of your browsing session.
- No tracking or marketing cookies are used.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a functional website).
5. Google Maps
Our website may include links or integrations directing you to Google Maps to display our office location.
When using Google Maps, Google may process personal data, including IP address and device identifiers. Data may be transferred to the United States.
Google processes data under its own responsibility.
Privacy policy: https://policies.google.com/privacy
If you are logged into a Google account, data may be associated with your profile. You may prevent this by logging out before using the Maps feature.
6. Data Retention
We retain personal data only for as long as required to achieve the purposes outlined in this Privacy Policy.
Examples:
- Logfiles: 7 days, unless required for security investigations
- Contact form submissions: duration of processing + legal retention requirements
- Technical data: duration of the browsing session
- Cookies: session duration
Longer retention may occur where necessary for the establishment, exercise, or defense of legal claims.
7. Data Subject Rights
Under Art. 15–21 GDPR, you have the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object to processing
To exercise your rights, please contact:
datenschutz@pharmacom.at
8. Right to File a Complaint
If you believe your rights have been violated, you have the right to lodge a complaint with:
Austrian Data Protection Authority (DSB)
www.dsb.gv.at
9. No Third Country Transfers Without Safeguards
Personal data is transferred outside the EEA only when:
- the recipient operates under Standard Contractual Clauses (SCCs), or
- another GDPR-compliant mechanism ensures an adequate level of protection.
Webflow and Google Maps rely on SCCs for transfers to the United States.
