Last updated: 23 July 2026
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
RoHol Vertriebs GmbH
Hauptstraße 31
4581 Rosenau / Hengstpass
Austria
Telephone: +43 (0) 7566 600-0
Email: office@rohol.at
We process personal data only to the extent necessary to provide this website, respond to enquiries and applications, take steps prior to entering into a contract, fulfil contractual or legal obligations, or safeguard legitimate interests.
Processing based on your consent is carried out only for the stated purposes. You may withdraw your consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
We take appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. This website is transmitted in encrypted form via HTTPS.
This website is hosted by World4You Internet Services GmbH, Wolfgang-Pauli-Straße 2, BT3, 4020 Linz, Austria. World4You processes data generated in connection with the hosting as a processor.
When you access our website, the following data in particular may be processed in server log files:
The processing is carried out to provide the website securely and reliably, analyse technical errors and prevent abusive access. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of our website.
Log files and temporary storage data are generally retained only for as long as necessary for the respective security or operational purpose. Depending on the type of logging, the hosting provider usually retains the data for a few days and no longer than 60 to 90 days. Data may be retained for longer if this is necessary to investigate a specific security incident or to establish, exercise or defend legal claims.
Further information: World4You Privacy Policy.
Our website uses cookies and similar storage technologies. Technically necessary cookies enable essential functions such as language selection, website security and the storage of your privacy settings. Where personal data is processed in this context, the legal basis is Article 6(1)(f) GDPR. In these cases, access to or storage of information on your terminal device is necessary to provide the service you have expressly requested in accordance with Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021).
Services and cookies that are not technically necessary are activated only after you have given your consent. The legal bases are Article 6(1)(a) GDPR and Section 165(3) TKG 2021.
We use Complianz – GDPR/CCPA Cookie Consent to manage consent. Your selection is stored in technically necessary cookies in your browser. You can change or withdraw your decision at any time using the “Manage consent” function available on the website.
Details of the cookies and services used, their purposes and retention periods can be found in our Cookie Policy.
If you contact us using a form or by email, we process the data you provide in order to handle and respond to your enquiry. Depending on the form used, this may include in particular your name, company, email address, telephone number, the content of your message and files submitted.
The processing is carried out pursuant to Article 6(1)(b) GDPR where your enquiry relates to steps prior to entering into a contract or the performance of a contract. For other enquiries, processing is carried out pursuant to Article 6(1)(f) GDPR on the basis of our legitimate interest in efficient communication and the handling of requests.
Form content is sent by email to the responsible contact at RoHol. Uploaded files are transmitted as email attachments. They are not stored permanently by the form in the web server’s upload directory, but are processed temporarily for transmission.
The data is deleted once the enquiry has been fully resolved and no statutory retention obligations or legitimate interests require further storage. Where the communication is relevant to a business transaction or contract, it may be retained for up to seven years in accordance with statutory retention obligations under company and tax law.
We use Microsoft 365 to process our email communications. The provider for the European Economic Area is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
Email communication may involve the processing of the sender’s and recipient’s addresses, the time of transmission, subject, message content, technical metadata and attachments. The legal basis depends on the content of the communication and is generally Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. Business correspondence subject to statutory retention obligations is additionally processed pursuant to Article 6(1)(c) GDPR.
Microsoft may also process data outside the European Economic Area. Where data is transferred to the United States, the transfer may be based on the EU-US Data Privacy Framework, provided the respective recipient is appropriately certified. Otherwise, Microsoft uses suitable safeguards, in particular the European Commission’s Standard Contractual Clauses.
Further information: Microsoft Privacy Statement.
If you apply to us through our website or by email, we process the application data you provide for the purpose of conducting the recruitment process. This may include in particular:
The legal basis is Article 6(1)(b) GDPR, as the processing is necessary to take steps prior to entering into a contract at your request. Where data is processed to document the recruitment process and to defend or pursue potential legal claims, the processing is additionally based on Article 6(1)(f) GDPR.
Access to application data is limited to the persons and departments involved in the recruitment process and the processors used for technical operation.
If your application is unsuccessful, the application data is generally deleted seven months after completion of the recruitment process. It is retained for longer only where this is necessary to establish, exercise or defend specific legal claims, or where you have separately consented to longer retention for consideration for future vacancies.
If an employment relationship is established, the data required for its administration is transferred to personnel management and processed and stored in accordance with the applicable legal provisions.
We use Google reCAPTCHA to identify automated and abusive form submissions. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Its use may involve the processing of the IP address, device and browser information, referrer URL, date and duration of the visit, mouse movements, keyboard input and, where applicable, Google cookies and information concerning an existing Google account.
reCAPTCHA is blocked on our website by the consent management system and is activated only if you expressly consent to the service. The legal bases are Article 6(1)(a) GDPR and Section 165(3) TKG 2021. You can withdraw your consent at any time with effect for the future using “Manage consent”.
As reCAPTCHA protects our forms, submitting the respective online form without activating the service is not technically possible. Alternatively, you can contact us by email or telephone.
Google may also process data in the United States. According to its own information, Google LLC is certified under the EU-US Data Privacy Framework. Standard Contractual Clauses may also be used.
Further information: Google Privacy Policy and Google Terms of Service.
Google Maps is embedded on our home page to display our location. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Maps is blocked by the consent management system and loaded only after you have expressly consented. Until then, only a local placeholder or a placeholder provided by the consent management tool is displayed. After activation, your IP address, device and browser data, location data and information about the page accessed may in particular be transmitted to Google, and cookies may be set or read.
The legal bases are Article 6(1)(a) GDPR and Section 165(3) TKG 2021. You can withdraw your consent at any time with effect for the future using “Manage consent”.
Google may also process data in the United States. According to its own information, Google LLC is certified under the EU-US Data Privacy Framework. Standard Contractual Clauses may also be used.
Further information: Google Privacy Policy and Google Maps Terms of Service.
Our website contains links to our profiles on Facebook, Instagram, LinkedIn and Pinterest. These are ordinary external links. Merely accessing our website does not establish a connection to these platforms through the links. The respective platform is accessed only when you click a link. In this case, your IP address, information about the device and browser used, and the previously visited page may in particular be transmitted to the platform operator. If you are logged in to the respective platform, your visit may be associated with your user account.
We maintain these profiles to provide information about our company and services and to communicate with prospective customers, customers and business partners. Where we process personal data ourselves in this context, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in corporate communication and our public presence.
The respective platform operators are generally responsible for further processing on their platforms:
When using these platforms, data may be processed outside the European Economic Area. Information on the applicable transfer mechanisms is available from the respective provider.
We disclose personal data only where this is necessary for the purposes described, where a legal obligation exists, or where you have consented. Recipients may include responsible employees within our organisation, hosting and IT service providers, email service providers, tax and legal advisers, public authorities and other bodies to which data must be disclosed due to a legal obligation or for the pursuit of legal claims.
Where required, we conclude agreements with processors pursuant to Article 28 GDPR.
The use of services provided by international providers may result in personal data being transferred to countries outside the European Union or the European Economic Area. Such a transfer takes place only if the requirements of Articles 44 et seq. GDPR are met. The transfer may be based in particular on an adequacy decision of the European Commission, the EU-US Data Privacy Framework for appropriately certified US companies, or the European Commission’s Standard Contractual Clauses.
Unless a more specific retention period is stated in this Privacy Policy, we retain personal data only for as long as necessary for the respective purpose. The data is then deleted unless statutory retention obligations or legitimate interests require further storage. Business records subject to statutory retention requirements may in particular be retained for seven years under company and tax law. Data may also be retained where this is necessary to establish, exercise or defend legal claims.
Subject to the applicable statutory requirements, you have the following rights in particular:
To exercise your rights, please contact office@rohol.at.
If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a data protection supervisory authority. In Austria, this is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Austria
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
We do not carry out decision-making based solely on automated processing, including profiling, within the meaning of Article 22 GDPR.
We may amend this Privacy Policy if the legal situation, the services used or the nature of the data processing changes. The version published on this website at the relevant time applies.