Packaging that dresses your fashion.
From hangtag to complete outfitting.
Privacy Policy
Preamble
We are delighted that you have shown interest in our enterprise. Data protection is of particularly high priority for the management of WEROCA Kartonagen GmbH & Co. KG. Below, we would like to inform you in detail about which data we collect during your visit to our website and how it is subsequently processed or used, as well as which protective measures we have taken, including on a technical and organisational level.
WEROCA Kartonagen GmbH & Co. KG (hereinafter also »we«, »us«, »our«) provides services in the course of which data, and in particular personal data, are processed. This concerns in particular the areas of our online shop, our communication and marketing activities, the provision of this website and all actions connected therewith.
Information about the Controller
The controller within the meaning of Art. 4 (7) of the General Data Protection Regulation (hereinafter »GDPR«) and other national data protection laws of the member states as well as other data protection provisions is:
WEROCA Kartonagen GmbH & Co. KG
Walter-Werning-Strasse 5
33699 Bielefeld | Germany
T: +49 (0) 521 924 06 0
F: +49 (0) 521 924 06 20
E: info(at)weroca.de
Data Protection Officer
We have appointed a Data Protection Officer for our company:
Thorsten Schröers | SAFE-PORT Consulting GmbH
c/o DSB Weroca
Hülshoff-Straße 7
59469 Ense | Germany
E: privacy(at)safe-port.de
Scope of the Processing of Personal Data
We generally only process personal data of our users to the extent necessary to provide a functioning website as well as our content and services. The processing of personal data of our users generally only takes place with the user’s consent. An exception applies in cases where obtaining prior consent is not possible for factual reasons and the processing of the data is permitted by legal provisions.
Legal Basis for the Processing of Personal Data
Insofar as we obtain the consent of the data subject for processing operations involving personal data, Art. 6 (1)(a) GDPR serves as the legal basis for the processing of personal data.
When processing personal data that is required for the performance of a contract to which the data subject is a party, Art. 6 (1)(b) GDPR serves as the legal basis. This also applies to processing operations required to carry out pre-contractual measures.
Insofar as processing of personal data is necessary to comply with a legal obligation to which our company is subject, Art. 6 (1)(c) GDPR serves as the legal basis.
In the event that vital interests of the data subject or of another natural person require the processing of personal data, Art. 6 (1)(d) GDPR serves as the legal basis.
If the processing is necessary to safeguard a legitimate interest of our company or of a third party and if the interests, fundamental rights and fundamental freedoms of the data subject do not override the first-mentioned interest, Art. 6 (1)(f) GDPR serves as the legal basis for the processing.
Erasure of Data and Storage Duration
The personal data of the data subject will be erased or blocked as soon as the purpose of storage no longer applies. Storage may also take place if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the controller is subject. Data will also be blocked or erased if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or performance of a contract.
Provision of the Website and Creation of Logfiles
Informational Use / Description and Scope of Data Processing
For the merely informational use of our website, it is generally not necessary for you to provide personal data. Instead, we only collect and use those of your data that your internet browser automatically transmits to us, such as:
- Date and time of accessing one of our web pages
- Your browser type
- Your browser settings
- The operating system used
- The page last visited by you
- The amount of data transferred and the access status (file transferred, file not found, etc.)
- Your IP address.
Purpose
During an informational visit, we collect and use this data exclusively in a non-personal form. This is done to enable use of the web pages accessed by you in the first place, for statistical purposes and to improve our website. The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user’s computer. For this purpose, the user’s IP address must remain stored for the duration of the session.
Legal Basis for the Data Processing
The legal basis for the temporary storage of the data and the logfiles is Art. 6 (1)(f) GDPR.
Duration of Storage
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended. In the case of storage of data in logfiles, this is the case after fourteen days at the latest, with longer storage being possible. In this case, users’ IP addresses are deleted or altered so that it is no longer possible to identify the accessing user. Access to log data is possible only directly and exclusively for administrators.
Right to Object and Removal Option
The collection of data for the provision of the services and the storage of data in logfiles is mandatory for the operation of the services offered. Consequently, users do not have the option to object.
Hosting of the Website
This website is hosted by an external service provider (Strato GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, hereinafter »host«). The personal data collected on this website is stored on the host’s servers. This may in particular include IP addresses, contact requests, meta and communication data, contract data, contact data, names, website access data and other data generated via a website.
Our host will only process your data to the extent necessary to fulfil its performance obligations and will follow our instructions with regard to this data.
Insofar as we engage service providers to process data, this is always done in accordance with Art. 28 GDPR on the basis of a so-called data processing agreement. To ensure data protection compliant processing, we have concluded a data processing agreement with our host.
Notice on Data Transfer to the USA and Other Third Countries
We use, among other things, tools of companies domiciled in third countries that are not safe from a data protection perspective, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (»DPF«). If these tools are active, your personal data may be transferred to and processed in these countries. We would like to point out that no level of data protection comparable to that in the EU can be guaranteed in third countries that are not safe from a data protection perspective.
We would like to point out that the USA, as a safe third country, generally has a level of data protection comparable to that in the EU. A data transfer to the USA is therefore permissible if the recipient holds a certification under the EU-US Data Privacy Framework (»DPF«) or has appropriate additional safeguards in place. Information on transfers to third countries, including the data recipients, can be found in these privacy notices.
We have additionally concluded valid, appropriate safeguards with the service providers pursuant to Art. 46 (2) GDPR for the transfer to these third countries. If you have further questions, please feel free to contact our Data Protection Officer.
A data transfer to the USA takes place exclusively on the basis of the data subject’s consent (Art. 6 (1)(a) GDPR). You may revoke a consent already given at any time. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.
Use of Cookies
Description and Scope of Data Processing
Our website uses cookies. Cookies are text files that are stored in or by the internet browser on the user’s computer system. When a user accesses a website, a cookie may be stored on the user’s operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is accessed again.
When you access our website, the user is informed about the use of cookies by way of a consent banner, and consent to the processing of the personal data used in this context is obtained and documented in a data protection compliant manner. In this context, reference is also made to these privacy notices. This also explains how the storage of cookies can be prevented in the browser settings.
You can also determine yourself whether cookies may be set and retrieved through your browser settings. You can, for example, disable the storage of cookies in your browser entirely, restrict it to certain websites, or configure your browser to notify you automatically whenever a cookie is about to be set and ask for your feedback in each case. However, for the full functionality of our website, it is technically necessary to allow the cookies we use.
Legal Basis for the Data Processing
The legal basis for the processing of personal data using technically necessary cookies is Art. 6 (1)(f) GDPR. The legal basis for the processing of personal data using cookies (and comparable recognition technologies) for analysis purposes and for advertising control/evaluation is Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG; consent can be revoked at any time.
Purpose of the Data Processing
If technically necessary cookies are used:
The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognised again after a page change. We require cookies for the following applications: storing the settings selected by visitors in the consent banner.
Our legitimate interest in the processing of personal data pursuant to Art. 6 (1)(f) GDPR also lies in these purposes.
User data collected through technically necessary cookies is not used to create user profiles.
Duration of Storage, Right to Object and Removal Option
Cookies are stored on the user’s computer and transmitted from it to our site. Therefore, as a user you also have full control over the use of cookies. By changing the settings in your internet browser, you can disable or restrict the transmission of cookies. Cookies already stored can be deleted at any time. This can also be done automatically. If cookies are disabled for our website, it may no longer be possible to use all functions of the website to their full extent.
Cookie Consent with the »Borlabs Consent Tool«
Our website uses the cookie consent technology of Borlabs Cookie to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document this in a data protection compliant manner. The provider of this technology is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany (hereinafter »Borlabs«).
Description and Scope of Data Processing
When you visit our website, your consents and other declarations regarding the use of cookies are obtained via our consent tool. The consent tool then stores a cookie in your browser in order to be able to associate the consents granted or their revocation with you.
Legal Basis for the Data Processing
The consent tool is used in order to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 (1)(c) GDPR.
Purpose of the Data Processing
The provision of the consent tool serves to comply with overriding legal provisions and to inform users of the scope within which cookies are used on this website.
Right to Object and Removal Option
The data collected by the consent tool remains stored until you delete the consent cookie yourself, adjust your settings again via the consent banner, or the purpose for storing the data no longer applies. Mandatory statutory retention obligations remain unaffected.
Further Information
We have concluded a data processing agreement with Borlabs. This is a contract required under data protection law that ensures that Borlabs processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Details on the data processing carried out by Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.
Analytics and Measurement
Google Analytics
Our website uses Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow St, Dublin, Ireland (»Google«), which allows the use of websites to be analysed. When using Google Analytics 4, cookies are used. The information collected by cookies about your use of the website (including the IP address transmitted by your device, truncated at the last digits, see below) is generally transmitted to a Google server and stored and processed there. This may also result in the transfer of information to the servers of Google LLC, based in the USA, and further processing of the information there (see also the section »Notice on Data Transfer to the USA and Other Third Countries«).
When using Google Analytics 4, the IP address transmitted by your device when using the website is by default and automatically collected and processed only in an anonymised form. It is therefore not possible to identify a specific person or to make a person identifiable from the information collected. This automatic anonymisation is achieved by Google truncating the IP address transmitted by your device at the last digits within member states of the European Union (EU) or other states party to the Agreement on the European Economic Area (EEA).
On our behalf, Google uses this and other information to evaluate your use of the website, to compile reports on your website activities and usage behaviour, and to provide us with further services associated with website and internet use. In doing so, the truncated IP address transmitted by your device within the scope of Google Analytics 4 is not merged with other Google data. The data collected within the scope of using Google Analytics 4 is retained for 2 months and then deleted.
Via a special function, the so-called »demographic characteristics«, Google Analytics 4 also enables the creation of statistics with information on the age, gender and interests of website users based on an evaluation of interest-based advertising and using third-party provider information. This makes it possible to determine and distinguish groups of website users for the purpose of target-group-optimised marketing measures. However, data collected via the »demographic characteristics« function cannot be attributed to a specific person and thus not to you personally. This data collected via the »demographic characteristics« function is retained for two months and then deleted.
As appropriate consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG. Without your consent, Google Analytics 4 will not be used while you use the website. You may revoke your consent given at any time with effect for the future. To exercise your revocation, please deactivate this service via the »Cookie Consent Tool« provided on the website.
In connection with this website, the service Google Signals is also used as an extension of Google Analytics 4. With Google Signals, we can have Google create cross-device reports (so-called »cross-device tracking«). If you have activated »personalised advertising« in your Google account settings and have linked your internet-enabled devices to your Google account, Google may, upon your consent to the use of Google Analytics 4 pursuant to Art. 6 (1)(a) GDPR, analyse your usage behaviour across devices and create database models based on this. This takes into account the logins and device types of all website users who were logged into a Google account and performed a conversion. Among other things, the data shows on which device you first clicked on an advertisement and on which device the related conversion took place. In doing so, we do not receive any personal data from Google, but only statistics generated on the basis of Google Signals. You have the option to deactivate the »personalised advertising« function in your Google account settings and thereby stop the cross-device analysis in connection with Google Signals. To do so, please follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=en.
Further information on Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=en.
We have concluded a data processing agreement with Google for our use of Google Analytics 4, obliging Google to protect the data of our website users and not to pass it on to third parties.
To ensure compliance with the European level of data protection, also in the event of any transfer of data from the EU or the EEA to the USA and possible further processing there, Google relies on the European Commission’s so-called Standard Contractual Clauses, which we have contractually agreed with Google.
Further legal information on Google Analytics 4, including a copy of the aforementioned Standard Contractual Clauses, can be found at https://policies.google.com/privacy?hl=en&gl=en and at https://policies.google.com/technologies/partner-sites.
The company holds a certification under the EU-US Data Privacy Framework (»DPF«). Further information can be found at the following link: https://www.dataprivacyframework.gov/participant/5780.
To ensure data protection compliant processing, we have additionally concluded a data processing agreement pursuant to Art. 28 GDPR with the provider.
Marketing
No Plugins or Tools of this Category in Use
No plugins or tools of this category are in use.
Settings
Google Fonts (via Google API)
If Google services are activated, Google may use Google Fonts for the purpose of uniform display of fonts. When accessing Google services, your browser loads the required web fonts into its browser cache in order to display texts and fonts correctly.
Further information on Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy?hl=en.
Wordfence
We have integrated Wordfence on this website. The provider is Defiant Inc., Defiant, Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA (hereinafter »Wordfence«). See also the section »Notice on Data Transfer to the USA and Other Third Countries«.
Wordfence serves to protect our website against unwanted access or malicious cyberattacks. For this purpose, our website establishes a permanent connection to Wordfence’s servers so that Wordfence can compare and, if necessary, block access to our website against its databases.
The use of Wordfence is based on Art. 6 (1)(f) GDPR. The website operator has a legitimate interest in the most effective possible protection of its website against cyberattacks. As appropriate consent has been requested, the processing takes place exclusively on the basis of Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
The data transfer to the USA is based on the Standard Contractual Clauses of the EU Commission. Details can be found here: https://www.wordfence.com/help/general-data-protection-regulation/.
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law that ensures that this provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
WPML
This website uses the Google Maps mapping service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (»Google«).
This website uses the WPML plugin. The provider is OnTheGoSystems Limited, 22/F 3 Lockhart Road, Wanchai, Hong Kong (hereinafter »WPML«). See also the section »Notice on Data Transfer to the USA and Other Third Countries«.
WPML is a multilingual plugin for WordPress. We use WPML to present our website in various languages. When you visit our website, WPML stores a cookie on your device to save the language setting you last used. This may result in the storage and evaluation of personal data, in particular the user’s activity (in particular, which pages have been visited and which elements have been clicked on) as well as device and browser information (in particular the IP address and the operating system).
The use of WPML is based on Art. 6 (1)(f) GDPR. The website operator has a legitimate interest in a simplified and user-friendly language setting for the website. As appropriate consent has been requested, the processing takes place exclusively on the basis of Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Alternatively, you can prevent the collection and processing of your personal data by WPML by disabling the storage of third-party cookies on your computer, using the »Do Not Track« function of a supporting browser, disabling the execution of script code in your browser, or installing a script blocker such as NoScript (www.noscript.net) or Ghostery (www.ghostery.com) in your browser. Further information on options to object to and remove data processed by WPML can be found at: https://wpml.org/documentation/privacy-policy-and-gdpr-compliance.
Further information on the processing of data by WPML is available here: https://wpml.org/documentation-3/privacy-policy-and-gdpr-compliance/
To ensure appropriate safeguards for the protection of the transfer and processing of personal data outside the EU, the transfer of data to, and processing by, OnTheGoSystems is based on appropriate safeguards pursuant to Art. 46 et seq. GDPR, in particular through the conclusion of so-called Standard Data Protection Clauses pursuant to Art. 46 (2)(c) GDPR.
Social Media
No Plugins or Tools of this Category in Use
No plugins or tools of this category are in use
Other
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (»Google«).
Google Tag Manager is a tool with the help of which we can integrate tracking or statistics tools and other technologies on our website. Google Tag Manager itself does not create any user profiles, does not store cookies and does not carry out any independent analyses. It merely manages and delivers the tools integrated through it. However, Google Tag Manager does collect your IP address, which may also be transmitted to Google’s parent company in the United States.
The use of Google Tag Manager is based on Art. 6 (1)(f) GDPR. The website operator has a legitimate interest in the fast and uncomplicated integration and management of various tools on its website. As appropriate consent has been requested, the processing takes place exclusively on the basis of Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Further information on the use of Google Tag Manager: https://support.google.com/tagmanager/answer/9323295?hl=en.
When processing the data, information may also be transmitted to the servers of Google LLC, based in the USA, and further processed there (see also the section »Notice on Data Transfer to the USA and Other Third Countries«).
The data transfer to the USA is based on the Standard Contractual Clauses of the EU Commission. Details can be found here: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs/.
The company holds a certification under the EU-US Data Privacy Framework (»DPF«). Further information can be found at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google reCAPTCHA
The website operator uses Google reCAPTCHA (hereinafter »reCAPTCHA«). The provider of this service is Google Ireland Limited (»Google«), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is intended to check whether data entry on this website (e.g. in a contact form) is being carried out by a human or by an automated program. For this purpose, reCAPTCHA analyses the behaviour of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, time spent by the website visitor on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.
The storage and analysis of the data is based on Art. 6 (1)(f) GDPR. The website operator has a legitimate interest in protecting its website offerings from abusive automated spying and from spam. As appropriate consent has been requested, the processing takes place exclusively on the basis of Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Further information on Google reCAPTCHA can be found in Google’s privacy policy and Google’s terms of use at the following links: https://policies.google.com/privacy?hl=en and https://policies.google.com/terms?hl=en.
When processing the data, information may also be transmitted to the servers of Google LLC, based in the USA, and further processed there (see also the section »Notice on Data Transfer to the USA and Other Third Countries«).
The data transfer to the USA is based on the Standard Contractual Clauses of the EU Commission. Details can be found here: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs/.
The company holds a certification under the EU-US Data Privacy Framework (»DPF«). Further information can be found at the following link: https://www.dataprivacyframework.gov/participant/5780.
To ensure data protection compliant processing, we have additionally concluded a data processing agreement pursuant to Art. 28 GDPR with the provider.
Flyeralarm
We use the Flyeralarm digital catalogue service to display our digital flip catalogues on our website. The provider is FLYERALARM GmbH, Alfred-Nobel-Straße 18, 97080 Würzburg, Germany (hereinafter »Flyeralarm«).
Flyeralarm is used to display the content of PDF files as a so-called flip catalogue, freely accessible and easy to read directly in the web browser, without the files first having to be downloaded. To provide the service, your web browser retrieves the content directly from Flyeralarm. In doing so, Flyeralarm receives information about your web browser and the operating system used, as well as your IP address. Flyeralarm uses this data exclusively for the purpose of the online display of the files concerned.
Insofar as personal data is collected and transmitted to Flyeralarm in this context, this is done pursuant to Art. 6 (1)(f) GDPR on the basis of our legitimate interest in the user-friendly availability and optimal integration of PDF files on our website. As appropriate consent has been requested, the processing takes place exclusively on the basis of Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Further information on data protection at Flyeralarm can be found here: https://flyeralarm.digital/datenschutz/.
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law that ensures that this provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Online Shop
For the sale of our products we use the online shop of TO-GO Verpackungen Vertriebs GmbH & Co. KG, Walter-Werning-Straße 5, 33699 Bielefeld, Germany (hereinafter »TO-GO Verpackungen«). If you select a corresponding shop link on our website, you will be redirected to an external website, namely the online shop of TO-GO Verpackungen.
From the moment of redirection, the processing of your personal data – in particular in connection with registration, ordering, payment processing, delivery, customer service and the technical operation of the online shop – is carried out by TO-GO Verpackungen under its own responsibility for data protection. We have no influence on the data processing within this external online shop.
Please therefore refer to the privacy notice of TO-GO Verpackungen at https://www.to-go-verpackungen.de/datenschutz. There you will find, in particular, information on the categories of data processed, the purposes of processing, the legal bases, the recipients, the storage periods and your rights as a data subject.
The integration or linking of the external online shop is based on our legitimate interest pursuant to Art. 6 (1)(f) GDPR in providing our customers with easy access to a means of ordering our products. When a link to the online shop is clicked, data such as your IP address is technically transmitted to the operator of the linked online shop.
3D Configurator
For the individual design and configuration of packaging, we provide you with a 3D configurator. The configurator is technically operated and provided by TO-GO Verpackungen Vertriebs GmbH & Co. KG, Walter-Werning-Straße 5, 33699 Bielefeld, Germany (hereinafter »TO-GO Verpackungen«) via its own website.
When you access the 3D configurator, you will be redirected to a website of TO-GO Verpackungen. In doing so, TO-GO Verpackungen processes personal data under its own responsibility for data protection. This may in particular include technical access data such as your IP address, the date and time of access, information on the browser and end device used, the content accessed and, where applicable, configuration and usage data.
The packaging designs, selected specifications and other entries you create in the configurator are processed by TO-GO Verpackungen to the extent necessary for the technical provision, display, storage, further processing or ordering of the configured packaging. We have no influence on the nature and scope of the data processing within the 3D configurator.
Further information on the processing of personal data, in particular on the purposes of processing, the legal bases, the recipients, the storage periods, possible transfers to third countries and your rights as a data subject, can be found in the privacy policy of TO-GO Verpackungen at: https://www.to-go-verpackungen.de/datenschutz.
The linking or integration of the configurator is intended to provide you with a convenient way to individually configure the packaging we offer. Insofar as Weroca GmbH itself processes personal data in this context, this is done on the basis of Art. 6 (1)(f) GDPR. Our legitimate interest lies in the user-friendly presentation and sale of our products.
Postal Advertising
In compliance with all legal requirements, we use your address for sending postal advertising (»postal advertising«).
The legal basis for this is our legitimate interest in direct marketing pursuant to Art. 6 (1)(f) in conjunction with recital 47 GDPR. Insofar as corresponding consent has been requested, the processing takes place exclusively on the basis of Art. 6 (1)(a) GDPR; consent can be revoked at any time. More specific provisions may be communicated to you, where applicable, in the context of data collection and take precedence over this provision.
Your address will remain with us until the purpose of the data processing no longer applies. If you assert a legitimate request for erasure or revoke your consent to postal advertising, your data will be deleted, unless we have other legally permissible grounds for storing your personal data (e.g. statutory retention periods under tax or commercial law); in the latter case, erasure will take place once these grounds no longer apply.
Prize Draws
We regularly conduct prize draws via our website or our social media presences. In this context, we process your personal data for the proper conduct and handling of the prize draw. To conduct the prize draw, the profile name and, where available, the e-mail address, first name and surname of the respective participant are collected and stored.
The legal basis for the data processing is your consent (Art. 6 (1)(a) GDPR). Your participation in our prize draws is voluntary. You may revoke your consent at any time with effect for the future. In other cases, the legal basis is Art. 6 (1)(b) GDPR (initiation, performance and handling of the corresponding contract on participation in the prize draw). This also includes the necessary contact in the event of a prize notification.
The processing of your personal data serves the purpose of handling the prize draw or promotion, in particular determining and notifying the winners. For the purpose of sending and delivering prizes, we may subsequently collect and process further data, e.g. your postal address. Your data will not be passed on to third parties beyond this.
You have the right at any time to object to the processing of your personal data described above. After the end of the prize draw and announcement of the winners, the data of the participants will be deleted. The data of the winners will be retained, in the case of prizes in kind and prize promotion days, for the duration required by overriding legal provisions and statutory warranty claims.
Contact Form and E-Mail Contact
Our website features a contact form that can be used for electronic contact. If a user makes use of this option, the data entered in the input form will be transmitted to us and stored. This data is:
- Your e-mail address
- The user’s IP address
- Date and time of the message
- Further information you enter in the contact form
For the processing of the data, your consent is obtained during the sending process and reference is made to this privacy policy. Alternatively, contact via the e-mail address provided is possible. In this case, the user’s personal data transmitted with the e-mail will be stored. No data will be passed on to third parties in this context. The data is used exclusively for processing the conversation.
Contacting us by providing an e-mail address is only possible from the age of 16, or with the consent of a parent or legal guardian. By using this function, you confirm that you are over 16 years of age or that the consent of a parent or legal guardian has been obtained.
The processing of this data is based on Art. 6 (1)(b) GDPR, insofar as your request is related to the performance or conclusion of a contract or is necessary for carrying out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1)(f) GDPR) or on your consent (Art. 6 (1)(a) GDPR), insofar as this was requested. The legal basis for the processing of data transmitted in the course of sending an e-mail is Art. 6 (1)(f) GDPR.
The processing of the personal data from the input form serves us solely to process the contact request. In the case of contact by e-mail, this also constitutes the necessary legitimate interest in processing the data. The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems.
The data will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. For the personal data from the input form of the contact form and those sent by e-mail, this is the case when the respective conversation with the user has ended. The conversation is deemed to have ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified. The personal data collected additionally during the sending process will be deleted at the latest after a period of seven days.
The user has the option at any time to revoke their consent to the processing of personal data. If the user contacts us by e-mail, they can object to the storage of their personal data at any time. In such a case, the conversation cannot be continued. You can exercise your right to object by contacting the contact details given above. All personal data stored in the course of contacting us will be deleted in this case.
Inquiries by Telephone or Fax
If you contact us by telephone or fax, your inquiry, including all personal data arising from it (name, inquiry), will be stored and processed by us for the purpose of handling your request. We will not pass on this data to third parties without your consent.
The processing of this data is based on Art. 6 (1)(b) GDPR, insofar as your request is related to the performance of a contract or is necessary for carrying out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1)(f) GDPR) or on your consent (Art. 6 (1)(a) GDPR), insofar as this was requested.
The processing of the personal data serves us solely to handle your request.
The data you send us in your inquiry will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for storing the data no longer applies (e.g. after your request has been fully handled).
The user has the option at any time to revoke the processing of their personal data. You can exercise your right to object by contacting the contact details given above.
All personal data stored in the course of contacting us will be deleted in this case. Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Social Media – General Information
When you visit our social media page, personal information about you is processed. If you have your own user account on a social network and are logged into that account when visiting our presence on that social network, all data collected in the process will be directly assigned to your existing account.
Social networks can generally comprehensively analyse your user behaviour when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). The data collected about you in this process is stored as usage profiles and may be evaluated for purposes of advertising and/or market research.
By actively interacting with us via our social media presences (messages, comments, downloads, etc.), we may be informed of these actions. The functions of the social media pages allow us to view your public profile data. You determine which data is visible yourself, in the settings of your social media account.
Legal Basis
In principle, the legal basis for the processing of your personal data on our social media pages is Art. 6 (1)(f) GDPR. The data processing is necessary in order to be able to provide you with the functions and information you requested, and is in the interest of our public relations work and our communication with you. If you require further information on the balancing of interests to be carried out pursuant to Art. 6 (1)(f) GDPR, please contact our data protection officer using the contact details given in this privacy policy. The analysis processes initiated by the social networks may be based on different legal bases, which are to be specified by the operators of the social networks (e.g. consent within the meaning of Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG).
If your contact is aimed at the conclusion of a contract (or relates to an existing contract), the additional legal basis for the processing is Art. 6 (1)(b) GDPR.
If necessary, we will obtain your consent for the data processing (Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG). Consent can be revoked at any time.
Controller and Exercise of Rights
When you visit one of our social media presences, we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may generally assert your rights (access, rectification, erasure, restriction of processing, data portability and complaint) both against us and against the operator of the respective social media portal. Further information can be found under »Social Media Presences« for the respective presence.
Please note that, despite the joint responsibility with the operators of the social media portals, we do not have full influence over the data processing operations of the social media portals. Our options are largely determined by the corporate policy of the respective provider.
Storage Period
The data collected directly by us via the social media presence is deleted from our systems as soon as you ask us to delete it, revoke your consent to storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory provisions – in particular retention periods – remain unaffected.
We have no influence on the storage period of your data stored by the operators of the social networks for their own purposes. For details on this, please refer directly to the operators of the social networks (e.g. in their privacy policy, see below).
Social Media Presences
By interacting with our Instagram presence (e.g. in the form of messages, comments, or »likes«), your provided data is transmitted by Instagram to us as the operator of the Instagram account. The provider of the service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter »Facebook« or »Instagram«). We would like to point out that we are joint controllers with Facebook within the meaning of Art. 26 GDPR. We have concluded a Joint Controller Addendum with LinkedIn. Further information is available here: https://de-de.facebook.com/legal/terms/information_about_page_insights_data.
The legal basis for these data transfers is, among others, Art. 6 (1)(f) GDPR. You can decide for yourself, in the settings of your Instagram account under »Privacy and Security«, which personal data is publicly accessible. You can control and adjust these settings at https://www.instagram.com/accounts/privacy_and_security/. If you use Instagram lead-generation forms (the legal basis is consent pursuant to Art. 6 (1)(a) GDPR and Section 25 (1) TDDDG, whereby consent can be revoked at any time), personal data (e.g. your name, stated company, your e-mail address or your telephone number) is stored by Instagram or Facebook and made available to us. We use this contact data to provide you with further information on our services and products. The use of lead forms within our Instagram presence takes place pursuant to Art. 6 (1)(f) GDPR. We have legitimate interests in this processing, which can be traced under the point »Legitimate Interest and Rights of Data Subjects« in this section. You may object to the use of your data from the lead form at any time. Lead data is stored on Instagram/Meta for 90 days and then deleted. Further information on how Meta, as the operator of Instagram, uses your data can be found in Meta’s further information at: https://www.facebook.com/business/help/563690893827148?id=735435806665862.
We store your personal data provided to us by Instagram/Facebook for as long as knowledge of the data is necessary for the purposes of the business relationship or the purposes for which it was collected, or as long as statutory or contractual retention obligations exist. In addition, you may object to the storage of data at any time (right to object). Instagram offers page operators analysis functions (»Instagram Insights«). Through these functions, account holders can analyse a summary of data in the form of page statistics within a tool. We use this data to create anonymised statistics (»likes«, page views, the regional distribution of users, post reach, etc.) and to examine the effectiveness of the Instagram presence. The use of the »Instagram Insights function« takes place pursuant to Art. 6 (1)(f) GDPR.
Responsibility for all processing related to Instagram Insights and for further processing of user data lies with Instagram or Facebook (Instagram as a Facebook product). Further information can be found at: https://www.facebook.com/help/instagram/155833707900388.
The company holds a certification under the EU-US Data Privacy Framework (»DPF«). Further information can be found at the following links: https://www.dataprivacyframework.gov/participant/4452, https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://privacycenter.instagram.com/policy/.
By interacting with our LinkedIn presence, your provided data is transmitted by LinkedIn to us as the operator of the LinkedIn presence. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (hereinafter »LinkedIn«). We would like to point out that we are joint controllers with LinkedIn within the meaning of Art. 26 GDPR. We have concluded a Joint Controller Addendum with LinkedIn. Further information is available here: https://legal.linkedin.com/pages-joint-controller-addendum.
The legal basis for these data transfers may also be Art. 6 (1)(f) GDPR. You can largely determine for yourself, via the settings of your LinkedIn account under »Privacy«, which personal data is publicly accessible. You can control and adjust these settings at https://www.linkedin.com/psettings/privacy.
Information on how LinkedIn uses your data can be found in LinkedIn’s privacy policy at: https://www.linkedin.com/legal/privacy-policy.
We store your personal data provided to us by LinkedIn for as long as knowledge of the data is necessary for the purposes of the business relationship or the purposes for which it was collected, or as long as statutory or contractual retention obligations exist. In addition, you may object to the storage of data at any time (right to object).
LinkedIn offers operators of a LinkedIn presence analysis functions. Through this function, operators of a LinkedIn presence can analyse a summary of data in the form of page statistics within a tool.
We use this data to create anonymised statistics (page views, regional distribution, etc.) and to examine the effectiveness of our campaigns. Conclusions about individual users are not possible. The use of the LinkedIn analysis function takes place pursuant to Art. 6 (1)(f) GDPR. See also the point »Legitimate Interest and Rights of Data Subjects«.
Further information on the processing of user data by LinkedIn as controller can be found at https://www.linkedin.com/legal/privacy-policy.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.linkedin.com/help/linkedin/answer/a1343190/datenubertragung-aus-der-eu-dem-ewr-und-der-schweiz?lang=de.
The company holds a certification under the EU-US Data Privacy Framework (»DPF«). Further information can be found at the following link: https://www.dataprivacyframework.gov/participant/5448.
Legitimate Interest and Rights of Data Subjects
The use of our social media presences is in part based on Art. 6 (1)(f) GDPR (legitimate interests). Our interests lie in the analysis of trends, interaction with our social media users, and the improvement of our campaigns and services. If you require further information on the balancing of interests to be carried out pursuant to Art. 6 (1)(f) GDPR, please contact our data protection officer using the contact details given in this privacy policy. If necessary, we will obtain your consent for the data processing (Art. 6 (1)(a) GDPR).
You will find your rights as a data subject vis-à-vis us in the section »Your Rights as a Data Subject«.
Further Information on Our Social Media Presences
Instagram – Further information on how you can directly assert or exercise your rights as a data subject against Facebook (as the operator of Instagram) is available at: https://www.facebook.com/help/instagram/155833707900388. Information on page insights data is available at: https://de-de.facebook.com/legal/terms/information_about_page_insights_data.
LinkedIn – Further information on how you can directly assert or exercise your rights as a data subject against LinkedIn is available at: https://www.linkedin.com/help/linkedin/answer/50191?trk=microsites-frontend_legal_privacy-policy. Information on the Page Insights Joint Controller Addendum can be found here: https://legal.linkedin.com/pages-joint-controller-addendum
Personal Information and Personal Data
The controller collects and processes information about customers and prospective customers both in paper form and digitally. This data may include:
- Personal master data (name, academic title, address, customer number, etc.)
- Contact data (telephone number, e-mail address, etc.)
- Billing data (name, address, billing office, etc.)
- Communication data (e-mails, postal correspondence, etc.)
The personal data is stored, among other places, in the customer management system used by the controller.
Purposes of Collection and Processing
The controller collects, processes and uses your personal data insofar as this is necessary to provide contractual or pre-contractual services. Further processing takes place only if you have given your consent or a statutory provision with priority applies.
In some cases, we make use of external service providers to process your data. These service providers have been carefully selected by us, engaged in writing, and are bound by our instructions. They are regularly monitored by us. The service providers will not pass this data on to third parties, but will delete it after fulfilment of the contract and expiry of statutory retention periods, unless you have consented to further storage.
Legal Basis for the Processing
Data processing for the purpose of initiating and performing a contract (Art. 6 (1)(b) GDPR)
Data is collected and processed for this purpose only insofar as this is legally required and necessary for the purpose of establishing, performing or terminating the contract concluded between you and us, or for carrying out pre-contractual measures (e.g. submitting offers, cost estimates, etc.). Insofar as any further data is not directly necessary for the performance of the business relationship, the processing is based on a legitimate interest of the company.
Data processing based on a balancing of interests (Art. 6 (1)(f) GDPR)
A legitimate interest can arise, for example, from internal organisational and administrative purposes. Processing of your data is permissible here unless the protection of your interests, fundamental rights and freedoms prevails.
Data processing based on consent (Art. 6 (1)(a) GDPR)
In addition, we may process your personal data based on your voluntary consent, e.g. when supporting applications or for sending product information.
Transfer of Your Personal Data
We pass on your personal data to the departments that need this data to fulfil contractual and statutory obligations or to implement our legitimate interest. Your personal data is transmitted or disclosed to external bodies only insofar as this is required by a legal provision or necessary for the performance of the contract concluded with you, e.g. in the context of projects to other external project participants. Service providers engaged by us, e.g. for the provision of IT services, may also be recipients of data about you within the framework of order processing pursuant to Art. 28 GDPR.
Data is not transferred outside the European Union and this is not planned.
Duration of Storage
Your personal data is only stored for as long as knowledge of the data is necessary for the purposes of the business relationship or the purposes for which it was collected, or as long as statutory or contractual retention obligations exist.
Different statutory retention periods arise, for example, from tax law provisions or possible contractual warranty and guarantee rights and extend up to ten years for tax-relevant documents and records.
In addition, data will not be deleted after the purpose has been achieved if this is still necessary for the assertion, exercise or defence of legal claims. The regular limitation period for other claims is three years (Section 195 of the German Civil Code, BGB), and thirty years in the cases of Section 197 BGB.
If a prospective customer decides against concluding a contract, the data will be deleted after 12 months (after the last contact). A prospective customer with no interest in concluding a contract can request the controller to delete their data without delay, unless the reasons mentioned above in this section apply.
Necessity of Provision
We point out that if personal data is not provided, or in the event of your revocation, the fulfilment of (contractual) obligations may be impeded or, under certain circumstances, even made impossible. The provision of your data based on consent is generally voluntary.
Personal Information and Personal Data
We process personal data that we receive from you in the course of our business relationship. This data may include:
- Master data (name, address, company, company address, etc.)
- Contact data (telephone number, e-mail address, company contact data, etc.)
- Order data (order data, product data, etc.)
- Communication data (e-mails, postal correspondence, etc.)
- Documentation data (call notes, etc.)
- Further comparable data from the categories mentioned
Insofar as access to our systems is granted in the course of carrying out the supplier or service-provider relationship, the data required for access is stored (e.g. user accounts and passwords as well as the date and duration of the last access, etc.).
The personal data is stored, among other places, in the supplier management system used by the controller.
Purposes of Collection and Processing
The controller collects, processes and uses your personal data insofar as this is necessary to enable the initiation and performance of the respective supplier or service-provider contractual relationship. This also includes contact for the purpose of contract handling, the provision and maintenance of applications, and notification of defective products/performance of services. Further processing takes place only if you have given your consent or a statutory provision with priority applies.
In some cases, we make use of external service providers to process your data. These service providers have been carefully selected by us, engaged in writing, and are bound by our instructions. They are regularly monitored by us. The service providers will not pass this data on to third parties, but will delete it after fulfilment of the contract and expiry of statutory retention periods, unless you have consented to further storage.
Legal Basis for the Processing
Data processing for the purpose of initiating and performing a contract (Art. 6 (1)(b) GDPR)
Data is collected and processed for this purpose only insofar as this is legally required and necessary for the purpose of the appropriate handling of orders and for the mutual fulfilment of obligations under the contract. Insofar as any further data is not directly necessary for the performance of the business relationship, the processing is based on a legitimate interest of the company.
Data processing based on a balancing of interests (Art. 6 (1)(f) GDPR)
A legitimate interest can arise, for example, from internal organisational and administrative purposes. Processing of your data is permissible here unless the protection of your interests, fundamental rights and freedoms prevails. The following areas may also be regarded as a legitimate interest:
- the assertion of legal claims, and
- defence in legal disputes.
Data processing based on consent (Art. 6 (1)(a) GDPR)
In addition, we may process your personal data based on your voluntary consent, e.g. for sending product information.
Transfer of Your Personal Data
We pass on your personal data to the departments that need this data to fulfil contractual and statutory obligations or to implement our legitimate interest. Service providers engaged by us, e.g. for the provision of IT services, may also be recipients of data about you within the framework of order processing pursuant to Art. 28 GDPR.
Data is not transferred outside the European Union and this is not planned.
Duration of Storage
Insofar as necessary, we process your personal data for the duration of our business relationship; this also includes the initiation and performance of a contract.
In addition, we are subject to various retention and documentation obligations arising, among others, from the German Commercial Code (HGB), the German Fiscal Code (AO) and the German Income Tax Act (EStG), each including the more detailed statutory provisions issued in this regard. The retention or documentation periods specified there amount to up to ten years beyond the end of the business relationship or the pre-contractual legal relationship.
Ultimately, the storage period is also assessed according to the statutory limitation periods, which, for example under Sections 195 et seq. of the German Civil Code (BGB), are generally three years, but in certain cases can also be up to thirty years.
Necessity of Provision
We point out that if personal data is not provided, or in the event of your revocation, the fulfilment of (contractual) obligations may be impeded or, under certain circumstances, even made impossible. The provision of your data based on consent is generally voluntary.
Personal Information and Personal Data
In the application process, we only process the personal data you send us with your application. As a rule, this concerns the following data:
- Surname, first name and date of birth;
- Contact data (telephone number, e-mail address);
- Application data such as CV, cover letter and references;
- Where applicable, information on health status or a severe disability;
- Where applicable, an application photo;
- Account data in the case of reimbursement of travel expenses;
- Where applicable, further information you provide in the course of the interview.
We do not require any information from you that is not usable under the German General Equal Treatment Act (AGG) (race, ethnic origin, gender, pregnancy, information on physical or mental illness, trade union membership, religion or belief, disability, age, sexual identity or sex life).
Please refrain from adding such information to your application documents.
The personal data is stored, among other places, in the applicant management system used by the controller.
Purposes of Collection and Processing
We collect, process and use your personal data insofar as this is necessary to establish a possible contractual relationship. This also includes contact for the purpose of handling the contract and, depending on the type of employment, providing evidence in the course of applicant screening, insofar as this is mandatory for the position to be filled (this information is not transferred to the applicant management system, only the fact that the necessary evidence has been provided).
In some cases, we make use of external service providers to process your data. These service providers have been carefully selected by us, engaged in writing, and are bound by our instructions. They are regularly monitored by us. The service providers will not pass this data on to third parties, but will delete it after fulfilment of the contract and expiry of statutory retention periods, unless you have consented to further storage.
Legal Basis for the Processing
Data processing for the purpose of initiating and performing a contract (Art. 6 (1)(b) GDPR)
Data is collected and processed only to the extent necessary for deciding on the establishment of an employment relationship.
Data processing based on a balancing of interests (Art. 6 (1)(f) GDPR)
A legitimate interest can arise, for example, from internal organisational and administrative purposes. Processing of your data is permissible here unless the protection of your interests, fundamental rights and freedoms prevails. The following areas may also be regarded as a legitimate interest:
- ensuring compliance with security regulations, requirements, industry standards and contractual obligations,
- the assertion of legal claims, and
- defence in legal disputes.
Data processing based on consent (Art. 6 (1)(a) GDPR)
In addition, we may process your personal data based on your voluntary consent, e.g.:
- through the voluntary provision of data that is not strictly necessary for the purpose, or
- the provision of your data for inclusion in our applicant pool.
Insofar as the processing of personal data is based on your consent, you have the right under Art. 7 (3) GDPR to revoke this data protection consent at any time. To exercise your rights as a data subject with regard to the data processed in this application process, please contact our data protection officer using the contact details given above.
Transfer of Your Personal Data
Your applicant data is reviewed and processed by the HR department upon receipt of your application. Suitable applications are then forwarded to the department heads, or their authorised representatives, for the respective open position, following the »need-to-know« principle. The further process is then coordinated. Within the company, in principle only those persons who require it for the proper conduct of our application process have access to your data.
Data is not transferred outside the European Union and this is not planned.
Duration of Storage
Your personal data will be deleted six months after the end of the application process, taking into account Section 61b (1) of the German Labour Courts Act (ArbGG) in conjunction with Section 15 AGG. You will not be separately informed of the deletion of your data.
If you are offered a position in the course of the application process, the data will be transferred from the applicant data system to our human resources information system.
If we do not make you a job offer, there may be a possibility to include you in our applicant pool. If included, all documents and information from the application will be transferred to the applicant pool in order to contact you should suitable vacancies arise.
Inclusion in the applicant pool takes place exclusively on the basis of your express consent (Art. 6 (1)(a) GDPR). Giving consent is voluntary and has no bearing on the current application process. The data subject may revoke their consent at any time. In this case, the data will be irrevocably deleted from the applicant pool, unless there are statutory retention grounds.
Data from the applicant pool will be irrevocably deleted at the latest one year after consent was given. You will not be separately informed of the deletion of your data.
Reporting of Violations
If you believe that applicable laws were violated during the application process, you can use our whistleblower protection platform at https://applicants.safe-trusty.de to report the incident.
To implement the requirements of the German Whistleblower Protection Act (»HinSchG«) in the context of the application process, we use the »SAFE trusty« service of SAFE-PORT Consulting GmbH, Hülshoff-Straße 7, 59469 Ense, Germany (»SAFE-PORT«). The platform and the reports received are centrally managed on SAFE-PORT’s servers. For the use of the »SAFE trusty« services, we have concluded a data processing agreement pursuant to Art. 28 GDPR with the provider.
Necessity of Provision
The provision of personal data is neither legally nor contractually required, nor are you obliged to provide it. However, the provision of personal data is necessary for carrying out the application process and for concluding a contract for an employment relationship. If the data is not provided, it will not be possible to carry out the application process or conclude a contract.
If personal data about you is processed, you are a data subject within the meaning of the GDPR and you have the following rights against the controller:
Right of Access
You can request confirmation from the controller as to whether personal data concerning you is being processed by us.
Where such processing exists, you can request the following information from the controller:
- the purposes for which the personal data is processed;
- the categories of personal data being processed;
- the recipients or categories of recipients to whom the personal data concerning you has been or will still be disclosed;
- the planned duration of storage of the personal data concerning you, or, if specific details are not possible, the criteria used to determine the storage period;
- the existence of a right to rectification or erasure of the personal data concerning you, a right to restriction of processing by the controller, or a right to object to such processing;
- the existence of a right of complaint to a supervisory authority;
- all available information on the origin of the data, where the personal data is not collected from the data subject;
- the existence of automated decision-making, including profiling, pursuant to Art. 22 (1) and (4) GDPR and – at least in those cases – meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.
You have the right to request information as to whether the personal data concerning you is transferred to a third country or to an international organisation. In this context, you may request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
Right to Rectification
You have a right to rectification and/or completion vis-à-vis the controller, insofar as the personal data processed concerning you is inaccurate or incomplete. The controller must carry out the rectification without delay.
Right to Restriction of Processing
Under the following conditions, you may request the restriction of the processing of personal data concerning you:
- if you contest the accuracy of the personal data concerning you, for a period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
- the controller no longer needs the personal data for the purposes of processing, but you need it for the assertion, exercise or defence of legal claims, or
- if you have objected to the processing pursuant to Art. 21 (1) GDPR and it is not yet clear whether the controller’s legitimate grounds override yours.
Where processing of the personal data concerning you has been restricted, such data may – with the exception of its storage – only be processed with your consent or for the assertion, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.
If the processing has been restricted under the above conditions, you will be informed by the controller before the restriction is lifted.
Right to Erasure
Obligation to Erase
You may require the controller to erase the personal data concerning you without undue delay, and the controller is obliged to erase such data without undue delay where one of the following grounds applies:
- The personal data concerning you is no longer necessary for the purposes for which it was collected or otherwise processed.
- You withdraw your consent on which the processing was based pursuant to Art. 6 (1)(a) or Art. 9 (2)(a) GDPR, and there is no other legal basis for the processing.
- You object to the processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21 (2) GDPR.
- The personal data concerning you has been unlawfully processed.
- The erasure of the personal data concerning you is necessary for compliance with a legal obligation under Union law or the law of the Member States to which the controller is subject.
- The personal data concerning you was collected in relation to information society services offered pursuant to Art. 8 (1) GDPR.
Information to Third Parties
Where the controller has made the personal data concerning you public and is obliged pursuant to Art. 17 (1) GDPR to erase it, the controller shall take reasonable steps, including technical measures, taking into account available technology and the cost of implementation, to inform controllers processing the personal data that you, as the data subject, have requested the erasure of any links to, or copies or replications of, that personal data.
Exceptions
The right to erasure does not apply insofar as processing is necessary
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation which requires processing under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health pursuant to Art. 9 (2)(h) and (i) as well as Art. 9 (3) GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes pursuant to Art. 89 (1) GDPR, insofar as the right referred to under point a) is likely to render impossible or seriously impair the achievement of the objectives of such processing, or
- for the assertion, exercise or defence of legal claims.
Right to Notification
If you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to notify all recipients to whom the personal data concerning you has been disclosed of this rectification or erasure of the data or restriction of processing, unless this proves impossible or involves disproportionate effort.
You have the right vis-à-vis the controller to be informed of these recipients.
Right to Data Portability
You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, insofar as
- the processing is based on consent pursuant to Art. 6 (1)(a) GDPR or Art. 9 (2)(a) GDPR or on a contract pursuant to Art. 6 (1)(b) GDPR, and
- the processing is carried out by automated means.
In exercising this right, you further have the right to have the personal data concerning you transmitted directly from one controller to another, insofar as this is technically feasible. This shall not adversely affect the freedoms and rights of other persons.
The right to data portability does not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Right to Object
You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 (1)(e) or (f) GDPR; this also applies to profiling based on these provisions.
The controller shall no longer process the personal data concerning you unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims.
Where personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of the personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
If you object to processing for direct marketing purposes, the personal data concerning you will no longer be processed for these purposes.
You have the option, in the context of the use of information society services, notwithstanding Directive 2002/58/EC, to exercise your right to object by automated means using technical specifications.
Right to Withdraw Data Protection Consent
You have the right to withdraw your data protection consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
Automated Individual Decision-Making, Including Profiling
You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you. This shall not apply if the decision
- is necessary for entering into, or the performance of, a contract between you and the controller,
- is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or
- is based on your explicit consent.
However, such decisions must not be based on special categories of personal data under Art. 9 (1) GDPR, unless Art. 9 (2)(a) or (g) GDPR applies and suitable measures have been taken to safeguard your rights and freedoms and legitimate interests.
With regard to the cases referred to in points (1) and (3) above, the controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.
Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
Data Security
Unfortunately, the transmission of information over the internet is not completely secure, which is why we cannot guarantee the security of data transmitted to our services over the internet. However, we secure our services and other systems through technical and organisational measures against loss, destruction, access, alteration or dissemination of your data by unauthorised persons. In particular, your personal data is transmitted to us in encrypted form. We use the SSL (Secure Socket Layer) [or TLS (Transport Layer Security)] encoding system for this purpose.
We also employ technical and organisational security measures to protect personal data collected or processed, in particular against accidental or intentional manipulation, loss, destruction or against access by unauthorised persons. Our security measures are continuously improved in line with technological developments.
Data Protection and Third-Party Websites
The website may contain hyperlinks to and from third-party websites. If you follow a hyperlink to one of these websites, please note that we cannot accept any responsibility or guarantee for third-party content or privacy terms. Please check the applicable privacy terms before transmitting personal data to these websites.
Changes to This Privacy Policy
We reserve the right to amend this privacy policy at any time with effect for the future. The current version is always available on the website. Please visit the website regularly and inform yourself about the applicable privacy provisions. We will inform you as soon as the changes require an action on your part (e.g. consent) or any other individual notification.
Insofar as we provide addresses and contact information of companies and organisations in this privacy policy, please note that these addresses may change over time, and we ask that you verify the details before making contact.
Currency of This Privacy Policy
To ensure an up-to-date privacy policy in the context of the services on our website, we use the »SAFE policy« service of SAFE-PORT Consulting GmbH, Hülshoff-Straße 7, 59469 Ense, Germany (»SAFE-PORT«). The content of this privacy policy is centrally managed on SAFE-PORT’s servers and embedded directly on this page.
We have a legitimate interest in always providing our website visitors with up-to-date information on data processing. For the use of »SAFE policy«, we have concluded a data processing agreement pursuant to Art. 28 GDPR with the provider.
Translation
For language versions other than German: this privacy policy has been translated from German. In the event of any discrepancies, the German version shall prevail.
Versioning
Version: v3.0.1-260810-1327