1. General information
The protection of your personal data is very important to us.
We process your data exclusively on the basis of the legal provisions of the General Data Protection Regulation (GDPR) and the Telecommunications Act (TKG 2003).
This privacy policy applies to:
-
The website of hi.one digital marketing OG
-
the mobile applications (Android & iOS)
-
the web-based backend for event and user management
2. Responsible party
hi.one digital marketing OG
Gurkgasse 43, Top 1-2, 1140 Vienna,Austria
hi1
3. Mobile apps (Android & iOS – check-in app)
3.1 Purpose of processing
The mobile app is used to check in to events, in particular by scanning QR codes or tickets.
3.2 Processed data
The following personal data may be processed when using the app:
- Name and email address of participants (e.g., when creating participants)
- Ticket or QR code information
- Internal user, ticket, or event IDs
- user-generated content in the form of a freehand signature
- Technical device information (e.g., operating system version)
The email address can also be used to perform two-factor authentication (2FA) when logging in.
No location data is processed, no advertising is displayed, and no tracking for marketing purposes takes place.
3.3 Camera access
The app requires access to the device's camera solely for the purpose of scanning QR codes.
-
No photos or videos are saved.
-
No further processing of image data takes place.
3.4 Data transmission
The scanned information can be transferred to a server-side backend for validation and storage.
Processing is carried out exclusively for the purpose of event management.
3.5 Legal basis
Processing is based on:
-
Art. 6 para. 1 lit. b GDPR (performance of a contract)
-
Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient event management)
3.6 Freehand signature
The app allows users to capture a freehand signature (e.g., with a finger or pen) to confirm their participation in an event.
Only the graphic representation of the signature is processed.
Optionally, this can be linked to an internal ticket or participant ID and a timestamp.
The signature is used exclusively for documentation and confirmation of participation and is transferred to the server-side backend and stored there.
4. Web backend (event and user management)
4.1 Purpose
The web backend is used to manage:
-
Events
-
participants
-
User accounts (e.g., employees, event organizers)
4.2 Processed data
Depending on usage, the following data may be processed:
-
Name
-
email address
-
User or role information
-
Event-related data
4.3 Access protection
Access to the backend is only possible for authorized users and is carried out via secure connections.
5. Website
5.1 Server log files
When you visit the website, the following data is automatically collected for operational security reasons:
-
IP address
-
Date and time of the request
-
Browser and operating system information
-
referrer URL
This data is used exclusively to ensure operation and for error analysis.
Storage period: maximum 30 days
Legal basis: Art. 6(1)(f) GDPR
5.2 Cookies & Analysis
If analysis or consent tools are used on the website (e.g., cookie banners, web analytics), this is done exclusively in accordance with legal requirements and only after obtaining the appropriate consent.
These technologies are not used within the mobile apps unless expressly stated otherwise.
6. Data transfer
Personal data will only be disclosed:
-
if this is necessary for the fulfillment of the contract
-
if there is a legal obligation
-
or if express consent has been given
No data will be passed on for advertising or marketing purposes.
7. Storage period
Personal data will only be stored for as long as is necessary for the respective purpose or as long as there are legal retention obligations.
8. Your rights
You have the following rights under the GDPR:
-
information
-
correction
-
deletion
-
Restriction of processing
-
data portability
-
Withdrawal of consent
-
Objection to processing
If you believe that the processing of your data violates data protection law, you can lodge a complaint with the competent supervisory authority.
In Austria, this is the data protection authority.
8.1 Data deletion
Data subjects may request the erasure of their personal data in accordance with Art. 17 GDPR.
The request can be made by email to hi1
For clear allocation, please provide the relevant event, ticket, or participant information.
9. Contact
If you have any questions about data protection, please contact us at: hi1