Privacy Policy

Information pursuant to the GDPR (DSGVO), Austrian Data Protection Act (DSG) and Telecommunications Act 2021 (TKG 2021)

1. General Information

The protection of personal data is an important concern for FSC Feitsema Sourcing & Consulting e.U. Personal data is processed exclusively in accordance with the applicable data protection legislation, in particular the General Data Protection Regulation (GDPR)(DSGVO), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021).

This Privacy Policy provides information about the processing of personal data in connection with our website and our business activities, particularly in relation to prospective customers, customers, suppliers, manufacturers, importers, service providers and other business partners.

2. Controller

FSC Feitsema Sourcing & Consulting e.U.
Owner: Willem Feitsema
Stephansplatz 8/20
1010 Vienna
Austria

Email: office@feitsema.com
Telephone: +43 (0)699 1250 9841

The controller within the meaning of the GDPR is FSC Feitsema Sourcing & Consulting e.U.

For any questions regarding data protection, you may contact us at any time using the contact details provided above.

3. Personal Data We Process

Depending on the nature of the enquiry or business relationship, we may process the following personal data in particular:

  • name and title;
  • company, company affiliation and professional function;
  • business address;
  • telephone and mobile telephone number;
  • email address;
  • usernames and profile names on communication platforms;
  • company register information;
  • VAT identification number and other company identification numbers;
  • correspondence language;
  • quotation, order and contractual data;
  • product, price and quantity information;
  • delivery and service terms;
  • delivery addresses and packaging information;
  • payment terms and bank details;
  • commission and brokerage data;
  • invoice and accounting data;
  • creditworthiness and payment information, where required;
  • customs tariff numbers, country of origin and import/export information;
  • transport and logistics data;
  • communication and correspondence data;
  • documents, files and images provided to us; and
  • appointment and meeting information.

These categories are also based on the customer and supplier data protection information provided to us, which includes, among other things, VAT/Intrastat information, commission data, delivery conditions, customs information, payment conditions, bank details and creditworthiness information.

We process only data that is necessary for the respective purpose or that is voluntarily provided to us.

4. Prospective Customers and Business Development

We process personal data relating to prospective customers and potential business partners, in particular for handling enquiries, initiating business relationships, preparing and following up quotations, maintaining business contacts, market and customer development, and providing information about our products and services.

This may include, in particular, the person’s name, company, professional function, contact details, industry, correspondence language and information regarding enquiries, visits and previous business contacts.

The processing of prospective customer data for the development of business activities and direct marketing on the basis of legitimate interests is also provided for in the supplied documentation.

5. Customer and Business Partner Data

As part of existing and prospective business relationships, we process personal data relating to our customers and their contact persons.

Processing is carried out in particular for preparing quotations, commercial brokerage, taking steps prior to entering into contracts, processing orders and contracts, coordinating between customers, suppliers, manufacturers and importers, delivery and logistics processing, invoicing and payment processing, commission settlement, handling complaints, maintaining business relationships and complying with legal obligations.

The customer information provided to us likewise provides for processing for the performance of contracts and pre-contractual measures as well as the processing of contact-person data on the basis of legitimate interests.

6. Suppliers, Manufacturers and Importers

We process data relating to suppliers, manufacturers, importers and their contact persons insofar as this is necessary for our activities as a commercial intermediary.

This may include enquiries and quotations, product information, prices and quantities, delivery terms, payment terms, contractual information, commission information, shipping and logistics data, import and export information, customs and origin information, and business correspondence.

Processing is carried out in particular for the initiation, brokerage, coordination and execution of business transactions.

7. Contacting Us

If you contact us by email, telephone, contact form, messenger service, social network or by any other means, we process the data you provide in order to handle your enquiry and any subsequent questions.

When using a contact form, the data processed may include, in particular, your name, email address and the content of your message.

The website privacy documentation provided to us likewise provides for the storage of contact details submitted by email or contact form for the purpose of responding to enquiries.

8. Business Communications

As part of our daily and international business activities, we use various means of communication and communication platforms.

These include, in particular, email, Microsoft Outlook, Microsoft Teams, Microsoft 365, telephone, mobile telephone, SMS, WhatsApp, WeChat, Telegram, LinkedIn, Facebook Messenger, video conferencing services, social and professional networks, cloud and collaboration services, contact and messaging functions of online platforms and other commonly used communication services.

This list is not exhaustive. Depending on the country, market and business partner, other means of communication may also be used.

Through these services, contact information, messages, documents, quotations, product information, appointment details, and order, delivery and contractual information may be exchanged.

9. Microsoft Outlook, Teams and Microsoft 365

We may use Microsoft Outlook, Microsoft Teams and other Microsoft 365 services for business communications, email correspondence, appointment management, online meetings, video conferences and collaboration.

In this context, contact, communication, appointment and technical data may be processed.

10. WhatsApp, WeChat, Telegram and Messenger Services

For direct business communications, we may use WhatsApp, WeChat, Telegram, Facebook Messenger and comparable messenger services.

These may be used, for example, for product and price enquiries, arranging appointments, coordinating deliveries, quotation and order communications and other short-term business coordination.

Due to the international nature of our business activities, WeChat in particular may also be used for communication with business partners outside the European Economic Area.

The use of a particular messenger service by a business partner is generally voluntary. Where possible, communication by email or telephone may be used as an alternative.

11. LinkedIn and Social Networks

We may use LinkedIn and other professional or social networks for corporate presentation, business development, maintaining contacts, acquiring new customers, business communications and maintaining our international business network.

If you contact us through such a platform, we process the data you provide in order to handle your enquiry.

In addition, the respective platform operators may process personal data under their own responsibility. Their respective privacy policies apply to such processing.

12. Legal Bases for Processing

Personal data is processed in particular on the following legal bases:

Art. 6(1)(a) GDPR – Consent
Where processing is based on your freely given consent.

Art. 6(1)(b) GDPR – Contract and pre-contractual measures
In particular for enquiries, quotations, commercial brokerage, contracts and order processing.

Art. 6(1)(c) GDPR – Legal obligations
In particular for compliance with tax, accounting, regulatory or other legal obligations.

Art. 6(1)(f) GDPR – Legitimate interests
In particular our legitimate interests in efficient business communication, conducting and maintaining business relationships, business development, developing our business activities, protection against economic risks and payment defaults, IT and data security, and the establishment, exercise or defence of legal claims.

This combination of contractual necessity, legal obligations and legitimate interests is also reflected in the customer and supplier data protection information provided to us.

13. Provision of Personal Data

The provision of certain personal data is necessary in order to process enquiries, prepare quotations or establish and conduct a business relationship.

Without the necessary information, it may not be possible to establish or conduct a business relationship.

This principle is also reflected in the supplier information provided to us.

14. Recipients of Personal Data

Personal data is disclosed only insofar as this is necessary for the relevant business activity or is legally permitted or required.

Possible recipients may include customers, suppliers, manufacturers, importers, distribution partners, freight forwarders and logistics companies, parcel and courier services, banks and payment service providers, insurance companies, tax advisers and accounting service providers, IT and hosting providers, email, cloud and communications providers, lawyers, public authorities and courts.

The documentation provided to us likewise provides for the disclosure of personal data to external service providers and public or non-public bodies to the extent permitted by law.

We do not sell personal data.

15. Processors

Where service providers process personal data on our behalf, appropriate data processing agreements pursuant to Art. 28 GDPR are concluded where legally required.

This may apply in particular to hosting, IT, email, cloud and other technical service providers.

The website privacy documentation provided to us also expressly provides for a data processing agreement with the hosting provider.

16. International Data Transfers

Due to our international business activities and the use of international communication, cloud, social media and messenger services, personal data may also be processed outside the European Union or European Economic Area or transferred to countries outside the EU/EEA.

This may apply in particular to international customers, suppliers, manufacturers and business partners and when using international communication platforms.

Where such a transfer falls within our responsibility, we comply with the requirements of Art. 44 to 49 GDPR.

Depending on the recipient, transfers may be based in particular on an adequacy decision of the European Commission, EU Standard Contractual Clauses or other safeguards permitted under the GDPR.

17. Hosting and Server Log Files

Our website is hosted by an external hosting provider.

Hosting provider:
[insert hosting provider]

When visiting our website, technical information may be processed automatically, including the IP address, date and time, page or file accessed, referrer URL, browser and browser version, operating system, amount of data transferred and other technically necessary access data.

Processing is carried out for the secure, stable and efficient provision of our website.

The website privacy documentation provided to us likewise identifies the IP address, time of access, requested page, HTTP status code, referrer, browser and operating system as technically necessary access data.

The legal basis is Art. 6(1)(f) GDPR.

Server log files are retained only for as long as necessary for the security and operation of the website, unless legal obligations or security-related circumstances require longer retention.

18. Cookies and Tracking

Our website does not use tracking or advertising cookies unless expressly stated otherwise.

Technically necessary cookies or comparable technologies may be used where required for the basic functionality or security of the website.

If analytics, marketing or tracking services are used in the future, this Privacy Policy will be amended accordingly and, where legally required, consent will be obtained before such services are activated.

19. External Services on the Website

Where external services such as Google Maps, YouTube, Google Analytics, externally hosted fonts or comparable services are used on our website, additional processing of personal data may occur.

The website privacy documentation provided to us contains, for example, separate provisions concerning Google Analytics, YouTube and Google Maps.
Such services will, however, only be specifically included in our Privacy Policy where they are actually used on our website.

20. Retention Period

Personal data is retained only for as long as necessary for the respective purpose.

Data relating to enquiries will be deleted once the enquiry and any follow-up questions have been completed and there are no legal or legitimate grounds requiring further retention.

Data relating to existing business relationships may be retained for the duration of the business relationship and subsequently in accordance with applicable statutory retention, documentation and limitation periods.

The supplied data protection information likewise provides for retention until the relevant purpose has been fulfilled and for continued retention where statutory retention obligations apply.

21. No Automated Decision-Making

We do not generally use solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning a data subject or similarly significantly affects that person.

This is also consistent with the customer, supplier and prospective customer information provided to us.

22. Data Security

We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or unauthorised disclosure.

Our website uses SSL/TLS encryption to secure data transmission.

However, absolute protection of data transmitted over the internet cannot be technically guaranteed.

23. AI-Generated Images

Our website may contain images, graphics or other visual content generated or edited using artificial intelligence.

Such content is used for illustrative and website design purposes.

Unless expressly stated otherwise, AI-generated images do not necessarily depict actual products, production facilities, machinery, business premises, employees, customers, suppliers, business partners or real events of FSC Feitsema Sourcing & Consulting e.U.

24. Your Rights

Subject to the applicable legal requirements, data subjects have in particular the following rights:

  • right of access pursuant to Art. 15 GDPR;
  • right to rectification pursuant to Art. 16 GDPR;
  • right to erasure pursuant to Art. 17 GDPR;
  • right to restriction of processing pursuant to Art. 18 GDPR;
  • right to data portability pursuant to Art. 20 GDPR; and
  • right to object pursuant to Art. 21 GDPR.

These rights are also set out accordingly in the data protection information provided to us.

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.

You may contact us at any time to exercise your rights.

25. Right to Lodge a Complaint

You also have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.

In Austria, you may in particular contact:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Austria

Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at

26. Data Protection Officer

Where FSC Feitsema Sourcing & Consulting e.U. is not legally required to appoint a Data Protection Officer pursuant to Art. 37 GDPR, no Data Protection Officer has been appointed.

For any data protection enquiries, please contact us directly:

Email: office@feitsema.com
Telephone: +43 (0)699 1250 9841

27. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy if legal requirements, our business activities, the technologies used or the services used on our website change.

The version currently published on our website shall apply.

Last updated: September 2026

28. Contact for Data Protection Enquiries

FSC Feitsema Sourcing & Consulting e.U.
Owner: Willem Feitsema
Stephansplatz 8/20
1010 Vienna
Austria

Email: office@feitsema.com
Telephone: +43 (0)699 1250 9841

Language / Sprache / Taal / Langue