Information on data collection pursuant to Art. 13 / 14 GDPR
In this document, we aim to explain which data is processed by us for what purposes, which data protection rights you have, and to whom you can address any of your questions.
Name and address oft the data controller
The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union, and other provisions of a data protection nature is:
SÜD-METALL BESCHLÄGE GMBH
D – 83404 Ainring /Hammerau
Tel.: +49 8654 / 4675-50
Name and address of data protection officer
Contact information: firstname.lastname@example.org
When you use this website, various personal data is collected. By using the website of the company SÜD-METALL BESCHLÄGE GMBH, you agree to the processing of data in accordance with the following description. This data protection declaration informs users about the type, scope and purposes of the processing of personal data by the responsible provider on this website. The legal basis for data protection relevant here is found in the EU Data Protection Basic Regulation (GDPR), the Federal Data Protection Act (BDSG) and the Telemedia Act (TMG).
We would like to point out that data transmission over the Internet (e.g. communication by e-mail) might have security gaps. A complete protection of data against access by third parties is therefore not possible.
Handling of personal data
Personal data is information that can be used to identify a person, i.e. information that can be traced back to a person. This includes the name, e-mail address or telephone number. However also information about preferences, hobbies, memberships or which websites somebody viewed counts as personal data.
Personal data will only be collected, used and passed on by us if we have a legal permission to do so or the users have agreed to the data processing.
This website uses the web analysis tool “Google Analytics”, a service offered by Google Ireland Limited. The purpose of the use is the “needs-based design” of this website, which is carried out based on a balancing of interests. The web analysis also enables us to detect and correct errors on the website, e.g. due to faulty links.
The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. However, since we have activated the so-called IP anonymization on this website and have concluded a corresponding contract processing agreement with Google, Google will shorten your IP address within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before. Only in exceptional cases, the full IP address will be transferred to a Google server in the USA and shortened there.
You may refuse the transfer of data generated by the cookie and relating to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de).
Alternatively, especially in the case of mobile devices, you can prevent Google Analytics from recording the data, by clicking on the following link. An opt-out cookie will then be set to prevent the future collection of your data when you visit this website: Disable Google Analytics
1. Creation of log files
Every time our website is called up, data and information are collected by an automated system. These are stored in the log files of the server.
The following data may be collected:
- Information about the browser type and the version used
- The user’s operating system
- The user’s Internet Service Provider
- The IP address of the user
- Date and time of access
- Web pages from which the user’s system accesses our website (referrer)
- Web pages that are accessed by the user’s system via our website
The processing of the data serves to deliver the contents of our website, to ensure the functionality of our information technology systems and the optimization of our website as well as to provide law enforcement agencies with the information necessary for criminal prosecution in case of a cyber-attack. The data of the log files are always stored separately from other personal data of the users, if available at all. A consolidation of this data with other data sources is not carried out. When using this general data and information, we do not draw any conclusions about the person concerned.
We therefore evaluate these anonymously collected data and information statistically and with the aim of increasing data protection and data security in our company, in order to ultimately ensure an optimum level of protection for the personal data processed by us. This data will not be passed on to third parties.
2. How to contact us
Due to legal regulations, our website contains information that enables quick electronic contact with us as well as direct communication with us, e.g. via a so-called electronic mail address (e-mail address). When contacting us via the address email@example.com, your data will be stored for processing the inquiry or for contacting us as well as in the event that follow-up questions arise. Mails received centrally will be forwarded to the respective specialist department. This personal data will not be passed on to third parties.
3. Online store
When you use our online store, your e-mail address and the password you entered will be saved upon registration. When ordering via the store, data is processed, such as
- Name, first name, salutation
- Contact details (e-mail, phone)
- Delivery and billing address and order data
- Information about the commission (project, address, project for which the order is being executed)
You will receive an order confirmation by e-mail when you order. The data will be transferred to our order system for further processing of the order and will only be used for the purpose of the order. Past orders can be viewed when you register. The access to this data is restricted to the respective user.
4. SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or requests, which you send to us as, a service provider and responsible entity, this site uses an SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. If the SSL or TLS encryption is activated, third parties cannot read the data you transmit to us.
5. Use of the e-mail address for sending newsletters
If you are a new customer, we will use your e-mail address for our own advertising purposes to send you newsletters, regardless of the contract, only if you have expressly agreed to this. The processing will then take place based on Art. 6 (1) lit. a GDPR with your consent. You may revoke this consent at any time without affecting the legality of the processing carried out based on the consent until revocation. To do so, you can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or by notifying us. Your e-mail address will be deleted from the distribution list afterwards. If you are an existing customer, we will use your e-mail address for our own advertising purposes to send you the newsletter because of our legitimate interest in accordance with Art. 6 Para. 1 point f) GDPR. You can object to the processing of your e-mail address for the future at any time. This does not affect the legality of the processing carried out up to that point. You can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or
Our website contains a button to access our corporate website within the social network Facebook. The companies Facebook Inc. (“Provider”) provide this service.
Facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). If you click on the named button while logged into your Facebook account, Facebook may be able to associate your visit to our pages with your Facebook account. We have no concrete knowledge of the content of the data transmitted in this respect or of how Facebook uses it.
Our website contains links to various videos about our corporate image and product information. For this, we use the provider YouTube. YouTube is operated by YouTube LLC with headquarters at 901 Cherry Avenue, San Bruno, CA 94066, USA. YouTube is represented by Google Inc. with headquarters at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. If you click on the videos, you will be redirected to the YouTube provider page. If you click on the videos while logged into your Google and/or YouTube account, YouTube may be able to associate your visit to our sites with your account. We have no concrete knowledge of the content of the data transmitted in this respect, nor of its use by the provider or by Google.
If you do not wish YouTube or Google to associate your visit to our website with your respective user account, please log out of your respective user account before visiting our website.
This website uses Google Tag Manager. Google Tag Manager is a solution that allows marketers to manage website tags through one interface. The tool itself (which implements the tags) is a cookie-less domain and does not store any personal data. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data.
Main service provider: Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.
Transfers to third countries are possible. So-called standard contractual clauses according to Art. 46 GDPR have been concluded as suitable guarantees. For third countries/companies for which an adequacy decision exists, the adequacy decision also applies. Further information can be found here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en
12. Routine deletion and blocking of personal data
We process and store personal data of the person concerned only as long as this is necessary to achieve the purpose of storage. In addition, data may be stored for as long as the European or national legislator has provided for this in EU ordinances, laws or other regulations to which the person responsible for processing is subject (e.g. commercial and tax law retention periods).
As soon as the purpose of storage ceases to apply or a storage period prescribed by the aforementioned regulations expires, the personal data is routinely deleted, unless it is still necessary for the performance of the contract or the initiation of a contract and/or we have a legitimate interest in the continued storage. The right of objection below remains unaffected.
13. Legal basis of the processing
The above-mentioned and other personal data, which we receive from persons concerned beyond the website visit, are usually only processed within our company if you voluntarily and actively communicate them to us.
Sometimes it may be necessary for the conclusion of a contract that a data subject provides us with personal data, which must subsequently be processed by us. Even when you visit our web store, the basis for processing is the intended or existing contract between you and us. When processing personal data, which are necessary for the performance of a contract, to which the data subject is a party, Article 6 paragraph 1 point b) GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
If the processing of personal data is based on Article 6 paragraph 1 point f) GDPR, our legitimate interest is the performance of our business activities for the benefit of the well-being of all our employees and our shareholders.
Any processing of your personal data beyond the scope of the statutory provisions will only be carried out because of your express consent. For processing operations for which we additionally obtain your consent for a specific processing purpose, Art. 6 para. 1 point a) GDPR then serves as the legal basis.
14. Transfer of data to third parties
Order processors, who support us in processing may, further process the data in relation with the use of our web store, as well as the data resulting from your visit to our website.
15. Rights of the data subject
You have the right:
To request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you may request information on the purposes of the processing, the categories of personal data, the categories of recipients, to whom your data have been or will be disclosed, the planned storage period, the existence of a right of rectification, cancellation, limitation of processing or opposition, the existence of a right of appeal, the origin of your data, if not collected by us. In accordance with Art. 16 GDPR to demand the correction of incorrect or incomplete personal data stored by us immediately. In accordance with Art. 17 GDPR to demand the deletion of your personal data stored by us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims. To demand, in accordance with Art. 18 GDPR, the restriction of the processing of your personal data, if the accuracy of the data is disputed by you, if the processing is unlawful but you refuse to have it deleted and we no longer require the data, but you require it for the assertion, exercise or defense of legal claims or you have lodged an objection to the processing in accordance with Art. 21 GDPR. In accordance with Art. 20 GDPR, to receive your personal data that you have provided us with in a structured, common and machine-readable format or to request that it be transferred to another responsible party. Pursuant to Art. 21 GDPR, for reasons arising from your particular situation, to object to the processing of your personal data by us with effect for the future, if we process your personal data on the basis of our overriding legitimate interest as part of a weighing of interests. If you make legitimate use of your right to object, we will stop processing the data concerned. We reserve the right to further process the data in those cases in which we can demonstrate compelling reasons for processing worthy of protection which outweigh your interests, fundamental rights and freedoms, or if our processing serves the assertion, exercise or defense of legal claims. To complain to a supervisory authority in accordance with Art. 77 GDPR. The supervisory authority responsible for us in matters of data protection law is the data protection commissioner of the federal state in which our company is located. You can find a list of the data protection officers and their contact details at the following link: www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html. In accordance with Art. 7 Para. 3 GDPR, you may revoke your consent to us at any time. Therefore, we are not allowed to continue the data processing in the future, which was based on this consent. If you wish to exercise your right of objection, simply send an e-mail to firstname.lastname@example.org. For all concerns regarding your data protection, please contact email@example.com or by mail to Süd-Metall Beschläge GmbH, Department of Data Protection, Sägewerkstraße 5, 83404 Ainring/Hammerau, Germany.