Information on data collection pursuant to Art. 13 / 14 GDPR
In this document, we aim to explain which data is processed by us for what purposes, which data protection rights you have, and to whom you can address any of your questions.
Name and address oft the data controller
The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union, and other provisions of a data protection nature is:
SÜD-METALL BESCHLÄGE GMBH
Sägewerkstraße 5
D – 83404 Ainring /Hammerau
Tel.: +49 8654 / 4675-50
Email: info@suedmetall.com
Name and address of data protection officer
Thomas Göbel
Contact information: dsb@suedmetall.com
Privacy
When you use this website, various personal data is collected. By using the website of the company SÜD-METALL BESCHLÄGE GMBH, you agree to the processing of data in accordance with the following description. This data protection declaration informs users about the type, scope and purposes of the processing of personal data by the responsible provider on this website. The legal basis for data protection relevant here is found in the EU Data Protection Basic Regulation (GDPR), the Federal Data Protection Act (BDSG) and the Telemedia Act (TMG).
We would like to point out that data transmission over the Internet (e.g. communication by e-mail) might have security gaps. A complete protection of data against access by third parties is therefore not possible.
Handling of personal data
Personal data is information that can be used to identify a person, i.e. information that can be traced back to a person. This includes the name, e-mail address or telephone number. However also information about preferences, hobbies, memberships or which websites somebody viewed counts as personal data.
Personal data will only be collected, used and passed on by us if we have a legal permission to do so or the users have agreed to the data processing.
Web analysis
This website uses the web analysis tool “Google Analytics”, a service offered by Google Ireland Limited. The purpose of the use is the “needs-based design” of this website, which is carried out based on a balancing of interests. The web analysis also enables us to detect and correct errors on the website, e.g. due to faulty links.
Google Analytics uses so-called “cookies”. The use of a web analysis system is advantageous for us in order to optimize this website, as it enables us to measure the success of advertising expenditures. With your consent to the use of cookies, you facilitate this continuous optimization for us.
The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. However, since we have activated the so-called IP anonymization on this website and have concluded a corresponding contract processing agreement with Google, Google will shorten your IP address within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before. Only in exceptional cases, the full IP address will be transferred to a Google server in the USA and shortened there.
You may refuse the transfer of data generated by the cookie and relating to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de).
Alternatively, especially in the case of mobile devices, you can prevent Google Analytics from recording the data, by clicking on the following link. An opt-out cookie will then be set to prevent the future collection of your data when you visit this website: Disable Google Analytics
For more information on the terms of use of Google Analytics and on privacy notices, please visit: https://policies.google.com/privacy
1. Creation of log files
Every time our website is called up, data and information are collected by an automated system. These are stored in the log files of the server.
The following data may be collected:
- Information about the browser type and the version used
- The user’s operating system
- The user’s Internet Service Provider
- The IP address of the user
- Date and time of access
- Web pages from which the user’s system accesses our website (referrer)
- Web pages that are accessed by the user’s system via our website
The processing of the data serves to deliver the contents of our website, to ensure the functionality of our information technology systems and the optimization of our website as well as to provide law enforcement agencies with the information necessary for criminal prosecution in case of a cyber-attack. The data of the log files are always stored separately from other personal data of the users, if available at all. A consolidation of this data with other data sources is not carried out. When using this general data and information, we do not draw any conclusions about the person concerned.
We therefore evaluate these anonymously collected data and information statistically and with the aim of increasing data protection and data security in our company, in order to ultimately ensure an optimum level of protection for the personal data processed by us. This data will not be passed on to third parties.
2. How to contact us
Due to legal regulations, our website contains information that enables quick electronic contact with us as well as direct communication with us, e.g. via a so-called electronic mail address (e-mail address). When contacting us via the address info@suedmetall.com, your data will be stored for processing the inquiry or for contacting us as well as in the event that follow-up questions arise. Mails received centrally will be forwarded to the respective specialist department. This personal data will not be passed on to third parties.
3. Online store
When you use our online store, your e-mail address and the password you entered will be saved upon registration. When ordering via the store, data is processed, such as
- Name, first name, salutation
- Contact details (e-mail, phone)
- Delivery and billing address and order data
- Information about the commission (project, address, project for which the order is being executed)
You will receive an order confirmation by e-mail when you order. The data will be transferred to our order system for further processing of the order and will only be used for the purpose of the order. Past orders can be viewed when you register. The access to this data is restricted to the respective user.
4. SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or requests, which you send to us as, a service provider and responsible entity, this site uses an SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. If the SSL or TLS encryption is activated, third parties cannot read the data you transmit to us.
5. Use of the e-mail address for sending newsletters
If you are a new customer, we will use your e-mail address for our own advertising purposes to send you newsletters, regardless of the contract, only if you have expressly agreed to this. The processing will then take place based on Art. 6 (1) lit. a GDPR with your consent. You may revoke this consent at any time without affecting the legality of the processing carried out based on the consent until revocation. To do so, you can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or by notifying us. Your e-mail address will be deleted from the distribution list afterwards. If you are an existing customer, we will use your e-mail address for our own advertising purposes to send you the newsletter because of our legitimate interest in accordance with Art. 6 Para. 1 point f) GDPR. You can object to the processing of your e-mail address for the future at any time. This does not affect the legality of the processing carried out up to that point. You can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or
6. Privacy policy for cookies
Our website uses cookies. Cookies do not damage your computer and do not contain viruses. These small text files make it possible to store specific information related to the user on the user’s terminal device while he or she is using the website. Cookies make it possible, in particular, to determine the frequency of use and the number of users of the pages, to analyze the behavior of the page use, but also to make our offer more customer-friendly. Most of the cookies we use are so-called “session cookies”. They are automatically deleted at the end of your visit. Other cookies remain stored at the end of a browser session and can be called up again the next time you visit the site. When you visit our website, a pop-up window will appear informing you about the use of cookies. If you do not want your browser to be assigned permanent cookies, you should set your Internet browser to refuse to accept cookies / should you refuse the use of cookies by clicking the “I do not agree” button. By continuing to use the website without responding to the above-mentioned pop-up window, you tacitly agree to the use of cookies. Cookies that are required for the electronic communication process or for the provision of certain functions are stored based on Art. 6 para. 1 point f) GDPR. We have a legitimate interest in the storage of cookies for the technically error-free and optimized provision of our services. Other cookies (e.g. cookies to analyze your surfing behavior) are not stored.
7. Privacy policy for Facebook
Our website contains a button to access our corporate website within the social network Facebook. The companies Facebook Inc. (“Provider”) provide this service.
Facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). If you click on the named button while logged into your Facebook account, Facebook may be able to associate your visit to our pages with your Facebook account. We have no concrete knowledge of the content of the data transmitted in this respect or of how Facebook uses it.
If you do not want Facebook to associate your visit to our website with your Facebook user account, please log out of your Facebook user account before visiting our website. For the purpose and scope of data collection and the further processing and use of data by Facebook, as well as your rights in this regard and setting options for protecting your privacy, please refer to Facebook’s privacy policy at https://de-de.facebook.com/privacy/explanation
8. Privacy policy for YouTube
Our website contains links to various videos about our corporate image and product information. For this, we use the provider YouTube. YouTube is operated by YouTube LLC with headquarters at 901 Cherry Avenue, San Bruno, CA 94066, USA. YouTube is represented by Google Inc. with headquarters at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. If you click on the videos, you will be redirected to the YouTube provider page. If you click on the videos while logged into your Google and/or YouTube account, YouTube may be able to associate your visit to our sites with your account. We have no concrete knowledge of the content of the data transmitted in this respect, nor of its use by the provider or by Google.
If you do not wish YouTube or Google to associate your visit to our website with your respective user account, please log out of your respective user account before visiting our website.
We do not use plugins of the provider YouTube on our website. For the purpose and scope of data collection and the further processing and use of data by YouTube as well as your rights and setting options for the protection of your privacy, please refer to the YouTube privacy policy: http://www.google.de/intl/de/policies/privacy/
9. Privacy policy for Google Tag Manager
This website uses Google Tag Manager. Google Tag Manager is a solution that allows marketers to manage website tags through one interface. The tool itself (which implements the tags) is a cookie-less domain and does not store any personal data. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data.
Main service provider: Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.
Transfers to third countries are possible. So-called standard contractual clauses according to Art. 46 GDPR have been concluded as suitable guarantees. For third countries/companies for which an adequacy decision exists, the adequacy decision also applies. Further information can be found here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en
10. Privacy policy for Leadfeeder
Simultaneously with the use of Google Analytics, this website uses the Leadfeeder service, which is operated by Liidio Oy, Mikonkatu 17, 0100 Helsinki, Finland. Leadfeeder accesses the list of website visitors’ IP addresses provided by Google Analytics in the analysis and links the list of IP addresses to information about the companies that can be found on the Internet under these IP addresses. Due to the shortening of the IP addresses of the website visitors, which is already carried out when using Google Analytics, a direct personal reference is not established. A reference to a person may arise on a presumptive basis when reviewing the linked company information. Leadfeeder’s privacy policy can be found at https://www.leadfeeder.com/privacy, information about Leadfeeder and compliance with the General Data Protection Regulation can be found at https://www.leadfeeder.com/leadfeeder-and-gdpr/.
11. Privacy policy for Cloudflare
Personal usage data, such as your IP address and the times of your calls to our website, are processed via the website to determine as well as to track malfunctions or misuse of our online services or telecommunications services and equipment and to improve the performance of our website. This website uses services from “Cloudflare” (provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare operates a content delivery network (CDN) and provides protection functions for the website (web application firewall). The data transfer between your browser and our servers flows through Cloudflare’s infrastructure and is analyzed there to prevent attacks. Cloudflare uses cookies for this purpose to enable you to access our website. The use of Cloudflare is in the interest of a safe use of our Internet presence and the defense of harmful attacks from the outside. For more information, please see the Cloudflare privacy policy: https://www.cloudflare.com/de-de/privacypolicy/
12. Routine deletion and blocking of personal data
We process and store personal data of the person concerned only as long as this is necessary to achieve the purpose of storage. In addition, data may be stored for as long as the European or national legislator has provided for this in EU ordinances, laws or other regulations to which the person responsible for processing is subject (e.g. commercial and tax law retention periods).
As soon as the purpose of storage ceases to apply or a storage period prescribed by the aforementioned regulations expires, the personal data is routinely deleted, unless it is still necessary for the performance of the contract or the initiation of a contract and/or we have a legitimate interest in the continued storage. The right of objection below remains unaffected.
13. Legal basis of the processing
The above-mentioned and other personal data, which we receive from persons concerned beyond the website visit, are usually only processed within our company if you voluntarily and actively communicate them to us.
Sometimes it may be necessary for the conclusion of a contract that a data subject provides us with personal data, which must subsequently be processed by us. Even when you visit our web store, the basis for processing is the intended or existing contract between you and us. When processing personal data, which are necessary for the performance of a contract, to which the data subject is a party, Article 6 paragraph 1 point b) GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
If the processing of personal data is based on Article 6 paragraph 1 point f) GDPR, our legitimate interest is the performance of our business activities for the benefit of the well-being of all our employees and our shareholders.
Any processing of your personal data beyond the scope of the statutory provisions will only be carried out because of your express consent. For processing operations for which we additionally obtain your consent for a specific processing purpose, Art. 6 para. 1 point a) GDPR then serves as the legal basis.
14. Transfer of data to third parties
Order processors, who support us in processing may, further process the data in relation with the use of our web store, as well as the data resulting from your visit to our website.
15. Rights of the data subject
You have the right:
To request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you may request information on the purposes of the processing, the categories of personal data, the categories of recipients, to whom your data have been or will be disclosed, the planned storage period, the existence of a right of rectification, cancellation, limitation of processing or opposition, the existence of a right of appeal, the origin of your data, if not collected by us. In accordance with Art. 16 GDPR to demand the correction of incorrect or incomplete personal data stored by us immediately. In accordance with Art. 17 GDPR to demand the deletion of your personal data stored by us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims. To demand, in accordance with Art. 18 GDPR, the restriction of the processing of your personal data, if the accuracy of the data is disputed by you, if the processing is unlawful but you refuse to have it deleted and we no longer require the data, but you require it for the assertion, exercise or defense of legal claims or you have lodged an objection to the processing in accordance with Art. 21 GDPR. In accordance with Art. 20 GDPR, to receive your personal data that you have provided us with in a structured, common and machine-readable format or to request that it be transferred to another responsible party. Pursuant to Art. 21 GDPR, for reasons arising from your particular situation, to object to the processing of your personal data by us with effect for the future, if we process your personal data on the basis of our overriding legitimate interest as part of a weighing of interests. If you make legitimate use of your right to object, we will stop processing the data concerned. We reserve the right to further process the data in those cases in which we can demonstrate compelling reasons for processing worthy of protection which outweigh your interests, fundamental rights and freedoms, or if our processing serves the assertion, exercise or defense of legal claims. To complain to a supervisory authority in accordance with Art. 77 GDPR. The supervisory authority responsible for us in matters of data protection law is the data protection commissioner of the federal state in which our company is located. You can find a list of the data protection officers and their contact details at the following link: www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html. In accordance with Art. 7 Para. 3 GDPR, you may revoke your consent to us at any time. Therefore, we are not allowed to continue the data processing in the future, which was based on this consent. If you wish to exercise your right of objection, simply send an e-mail to datenschutz@suedmetall.com. For all concerns regarding your data protection, please contact datenschutz@suedmetall.com or by mail to Süd-Metall Beschläge GmbH, Department of Data Protection, Sägewerkstraße 5, 83404 Ainring/Hammerau, Germany.
16. Validity and changes of this privacy policy
Please note that the version published here is also the current and valid version of the privacy policy. Changes in the law or changes in our internal processes may make it necessary to adapt this data protection declaration at any time. We therefore reserve the right to amend the privacy policy in order to adapt it to changes in the law or to changes in services, functions and data processing – you are therefore asked to inform yourself regularly about the content of this privacy policy. Further information on data processing within our company can be found in our information data sheet according to art. 13, 14 GDPR, Download – HERE –