Logo
  • Home
  • Privacy policy

Privacy policy

This English version is provided for convenience only. In case of discrepancies, the German version (Datenschutz) shall prevail.

Responsible: Gideon Goerts

1. General information on data processing and legal bases

1.1. This privacy policy informs you about the nature, scope and purpose of the processing of personal data within our online offering and the websites, functions and content associated with it (hereinafter jointly referred to as the “online offering” or “website”). The privacy policy applies irrespective of the domains, systems, platforms and devices (e.g. desktop or mobile) used on which the online offering is operated.

1.2. With regard to the terms used, such as “personal data” or their “processing”, we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

The personal data of users processed within the scope of this online offering include master data (e.g. names, company names, addresses, telephone numbers and e-mail addresses of customers), usage data (e.g. the pages of our online offering visited) and content data (e.g. entries in the contact form).

1.3. The term “user” covers all categories of persons affected by the data processing. These include our business partners, customers, prospective customers and other visitors to our online offering. The terms used, such as “user”, are to be understood as gender-neutral.

1.4. We process the personal data of users only in compliance with the relevant data protection provisions. This means that users' data are processed only where a statutory permission exists. In other words, in particular where the data processing is necessary for the provision of our contractual services (e.g. processing of orders) and online services, or is required by law, where the users have given their consent, or on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation, economic operation and security of our online offering within the meaning of Art. 6 (1) (f) GDPR, in particular in the context of reach measurement, the creation of profiles for advertising and marketing purposes, the collection of access data and the use of third-party services.

1.5. We point out that the legal basis for consent is Art. 6 (1) (a) and Art. 7 GDPR, the legal basis for processing for the performance of our services and the implementation of contractual measures is Art. 6 (1) (b) GDPR, the legal basis for processing for the fulfilment of our legal obligations is Art. 6 (1) (c) GDPR, and the legal basis for processing to safeguard our legitimate interests is Art. 6 (1) (f) GDPR.

2. Security measures

2.1. We take organisational, contractual and technical security measures in accordance with the state of the art to ensure that the provisions of the data protection laws are complied with, and thereby to protect the data processed by us against accidental or intentional manipulation, loss, destruction or access by unauthorised persons.

The security measures include, in particular, the encrypted transmission of data between your browser and our server.

3. Disclosure of data to third parties and third-party providers

3.1. Data are disclosed to third parties only within the framework of the statutory requirements. We disclose users' data to third parties only where this is necessary, e.g. on the basis of Art. 6 (1) (b) GDPR for contractual purposes, or on the basis of legitimate interests pursuant to Art. 6 (1) (f) GDPR in the economic and effective operation of our business.

3.2. Where we use subcontractors to provide our services, we take appropriate legal precautions as well as corresponding technical and organisational measures to ensure the protection of personal data in accordance with the relevant statutory provisions.

3.3. Where, within the scope of this privacy policy, content, tools or other means from other providers (hereinafter jointly referred to as “third-party providers”) are used and their stated registered office is located in a third country, it is to be assumed that data are transferred to the countries in which the third-party providers are based. Third countries are understood to be countries in which the GDPR is not directly applicable law, i.e. in principle countries outside the EU or the European Economic Area. Data are transferred to third countries either where an adequate level of data protection exists, where the users have given their consent, or where another statutory permission applies.

4. Contacting us

4.1. When contacting us (via the contact form or by e-mail), the user's details are processed for the purpose of handling and dealing with the contact enquiry pursuant to Art. 6 (1) (b) GDPR.

5. Comments and contributions

5.1. When users leave comments or other contributions, their IP addresses are stored for 7 days on the basis of our legitimate interests within the meaning of Art. 6 (1) (f) GDPR.

5.2. This is done for our own security, in case someone leaves unlawful content in comments and contributions (insults, prohibited political propaganda, etc.). In such a case we may ourselves be held liable for the comment or contribution and are therefore interested in the identity of the author.

6. Collection of access data and log files

6.1. On the basis of our legitimate interests within the meaning of Art. 6 (1) (f) GDPR, we collect data on every access to the server on which this service is located (so-called server log files). The access data include the name of the web page accessed, file, date and time of access, volume of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider.

6.2. Log file information is stored for security reasons (e.g. to investigate acts of misuse or fraud) for a maximum period of seven days and then deleted. Data whose further retention is required for evidentiary purposes are exempt from deletion until the respective incident has been finally clarified.

7. Cookies & reach measurement

7.1. Cookies are pieces of information that are transferred from our web server or third-party web servers to the users' web browsers and stored there for later retrieval. Cookies may be small files or other types of information storage.

7.2. We use “session cookies”, which are stored only for the duration of the current visit to our online presence (e.g. to enable the storage of your login status or the shopping basket function and thus the use of our online offering at all). A randomly generated unique identification number, a so-called session ID, is stored in a session cookie. A cookie also contains information about its origin and the storage period. These cookies cannot store any other data. Session cookies are deleted when you have finished using our online offering and, for example, log out or close the browser.

7.3. Users are informed about the use of cookies in the context of pseudonymous reach measurement within the scope of this privacy policy.

7.4. If users do not wish cookies to be stored on their computer, they are asked to deactivate the corresponding option in the system settings of their browser. Stored cookies can be deleted in the browser's system settings. The exclusion of cookies may lead to functional restrictions of this online offering.

7.5. You can object to the use of cookies that serve reach measurement and advertising purposes via the opt-out page of the Network Advertising Initiative (http://optout.networkadvertisi...) and additionally via the US website (http://www.aboutads.info/choic...) or the European website (http://www.youronlinechoices.c...).

8. Integration of third-party services and content

8.1. Within our online offering, on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and economic operation of our online offering within the meaning of Art. 6 (1) (f) GDPR), we use content or service offerings of third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter uniformly referred to as “content”). This always presupposes that the third-party providers of this content perceive the users' IP address, since without the IP address they could not send the content to the users' browser. The IP address is therefore required for the display of this content. We endeavour to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and further details on the use of our online offering, and may also be combined with such information from other sources.

8.2. The following overview lists third-party providers and their content, together with links to their privacy policies, which contain further information on the processing of data and, in some cases already mentioned here, options to object (so-called opt-out):

9. Rights of users

9.1. Users have the right, upon request and free of charge, to obtain information about the personal data we have stored about them.

9.2. In addition, users have the right to rectification of inaccurate data, restriction of processing and erasure of their personal data, where applicable, to assert their rights to data portability and, if they believe that data are being processed unlawfully, to lodge a complaint with the competent supervisory authority.

9.3. Users may likewise withdraw consent, in principle with effect for the future.

10. Deletion of data

10.1. The data stored by us are deleted as soon as they are no longer required for their intended purpose and no statutory retention obligations preclude their deletion. Where users' data are not deleted because they are required for other, legally permissible purposes, their processing is restricted. This means that the data are blocked and not processed for other purposes. This applies, for example, to users' data that must be retained for reasons of commercial or tax law.

10.2. In accordance with statutory requirements, data are retained for 6 years pursuant to § 257 (1) HGB (German Commercial Code) (commercial books, inventories, opening balance sheets, annual financial statements, commercial letters, accounting records, etc.) and for 10 years pursuant to § 147 (1) AO (German Fiscal Code) (books, records, management reports, accounting records, commercial and business letters, documents relevant for taxation, etc.).

11. Right to object

Users may object to the future processing of their personal data at any time in accordance with the statutory requirements. The objection may in particular be made against processing for direct marketing purposes.

12. Changes to the privacy policy

12.1. We reserve the right to amend the privacy policy in order to adapt it to changes in the legal situation, or to changes in the service or the data processing. However, this applies only with regard to statements on data processing. Where users' consent is required, or where parts of the privacy policy contain provisions governing the contractual relationship with users, changes are made only with the users' consent.

12.2. Users are asked to inform themselves regularly about the content of the privacy policy.