Customer Information GDPR April 18th 2019
|pdf download (332 kB)|
Please note that data transmission over the internet (e.g. during communication via email) may have security vulnerabilities. The complete protection of data against access by third parties is not possible.
Scope of applicability and data controller
This privacy notice informs the user of the type, scope, and the purpose of collection and processing of personal data by the data controller, Dr. Demuth Derisol Lackfarben GmbH & Co. KG
Hillerser Straße 8, 37154 Northeim, phone +49 (0) 5551 / 97940, fax +49 (0) 5551 / 979430 on the website (hereinafter “website”).
Contact persons and Data Protection Officer
We have appointed a data protection officer for our company.
Mr Andreas Sorge, DatCon | Ingenieurbüro für Datenschutz und IT-Unternehmensberatung, Am Osterfeuer 26, 37176 Nörten-Hardenberg, phone 05503-9159648, e-mail ed.noctad(ta)egros
How do we record your data?
One way of collecting your data is that you give them to us. These data may e.g. include information that you enter in a contact form. Other data are automatically recorded by IT systems when you visit the website. These data are mainly of technical nature (e.g. Internet browser, operating system or time at which the site was called). These data are recorded automatically as soon as you enter our website.
For which purpose do we use your data?
One part of the data is collected in order to ensure error-free provisioning of the website. Other data may be used to analyse your user behaviour.
Which rights do you have with regard to your data?
In this connection or if you have more questions regarding the data protection topic, you can contact us at the address specified in the legal notice at any time.
Right to erasure
If you have provided us with personal data, you may have it erased again at any time.
Data required for billing and accounting purposes are not affected by termination or erasure.
Right of access
You have the right to obtain information about the personal data that were stored with regard to you.
Right to rectification
Each person affected by the processing of personal data has the right to demand the immediate correction of incorrect personal data.
Naturally, we will then correct incorrect data immediately.
Right to withdraw consent given under privacy law
Each data subject has the right to, at any time, withdraw any consent granted regarding the processing of personal data.
Right to data portability
You have the right to obtain the personal data regarding you that were stored by the company in a structured and commonly used format and to transmit these data to another company for further use and processing.
Right to lodge a complaint
In case of violations under the data protection law, the data subject has the right to lodge a complaint with the responsible supervisory authority. The responsible supervisory authority in questions under the data protection law is the State Data Protection Officer of the state in which our company has its registered office. For a list of the data protection officers and their contact data, please refer to the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
SSL and/or TLS encryption
For security reasons and in order to protect confidential content such as orders or enquires you send to us as website operator, this website uses SSL and/or TLS encryption. You can recognise an encrypted connection by the address line in the browser changing from “http://” to “https://” and by the lock symbol in the browser line.
If the SSL- and/or the TLS encryption is activated, the data you transmit to us cannot be accessed by third parties.
Personal data are pieces of information that can be used to determine your identity. This includes information such as your real name, address, postal address, and phone number. Information, that is not directly linked with your real identity.
Where online forums are to be made available for use by third parties, these third parties are not given access to the personal data saved in regard to the forum users.
A data subject is any identified or identifiable natural person.
Collection of personal data
Your personal data will only be saved if you yourself make these available to us as part of your enquiries and suggestions you send to us by e-mail.
Processing of data (customer and contract data)
We only collect, process, and use personal data insofar as they are required for the establishing of or drafting the content of or changes to the legal relationship (inventory data). We only collect, process, and use personal data regarding the use of our websites (usage data) where doing so is required in order to enable the user to use the service or to charge use of the service to the user.
Some of the websites use so-called cookies. Cookies do not harm your computer and do not contain viruses. Cookies serve the purpose of making our website more user-friendly, effective and secure. Cookies are small text files that are placed on your computer and saved by your browser.
The majority of the cookies used by us are so-called “session cookies”. They are deleted automatically at the end of your visit. Other cookies are stored on your end device until you delete them. These cookies allow us to recognise your browser when you next visit our site.
Cookies that are required for execution of the electronic communication process or for provision of certain features requested by you (e.g. shopping basked feature) are saved based on Art. 6 clause 1 letter f GDPR. The website operator has a legitimate interest in the storage of cookies for the technically smooth and optimised provision of their services. Where other cookies (e.g. cookies for analysis of your browsing behaviour) are stored, these are addressed separately in this privacy notice.
Server log files
The website provider automatically collects and saves information in server log files which your browser automatically sends to us. This information includes the following: Browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request
These data cannot be associated with a specific person. This data is not combined with other data sources. We reserve the right to check this data subsequently in the event of concrete indications of unlawful use.
Disclosure of personal data to third parties
Personal data are only used in connection with orders for products and services. These are not disclosed to third parties without your express consent. Where data are provided to service providers in the course of contract data processing, these service providers are bound by the German Federal Data Protection Act and/or other statutory provisions.
Your data will be disclosed to entities entitled to this information where the data controller is obliged by law or court order to disclose such data.
Security in the processing of personal data
The data controller employs technical and organisational security measures in order to protect your personal data managed by them against accidental or deliberate manipulation, loss, destruction or against access by unauthorised parties. We are continuously improving our security measures in accordance with technological developments.
Erasure of data
Where the purpose of storing personal data no longer applies or if the statutory retention period has expired, the data will be deleted in accordance with statutory provisions. If deletion is not possible, the data will be blocked instead.
Persons less than 18 years of age should not send personal data to me without the permission of their parents or legal guardians.
Links to other websites
This website contains links to other websites. We have no influence on whether or not their operators comply with data protection regulations. This privacy notice exclusively applies to our website.
If you have questions, comments, and suggestions regarding data protection, please send us an e-mail. The fast development of the Internet necessitates adjustment to this guideline from time to time.
In case of questions, explanations, and queries regarding the use of data, our data protection officer will be pleased to help you. Please see the legal notice for contact details.
On this website, you have the options to contact us by e-mail and/or by using a contact form. If you use the contact form, your information is saved for handling contact with you. The Data will not be disclosed to third parties. Neither are these aligned with other data entries on this website.
In general, this website can be used without entering personal data. Where personal data are collected on these websites, provision of these is, wherever possible, voluntary. Such data will not be forwarded to third parties without your explicit consent.
Please note that data transfer via the Internet (e.g. using e-mail) may be subject to security gaps. Complete protection of the data from access by third parties is not possible without further technical measures.
The use of contact data published to comply with imprint obligations by third parties for purposes of sending not expressly requested advertisement and information material is hereby expressly rejected. The operator of the websites expressly reserves all legal steps in case of unsolicited sending of advertisement information, for example spam e-mails.
Processing of data (customer and contract data)
We only collect, process, and use personal data insofar as they are required for the establishing of or drafting the content of or changes to the legal relationship (inventory data). Any of the above take place based on Art. 6 clause 1 letter b GDPR, which allows the processing of data in order to execute a contract or to engage in pre-contractual steps. We only collect, process, and use personal data regarding the use of our websites (usage data) where doing so is required in order to enable the user to use the service or to charge use of the service to the user.
The customer data we collect will be deleted after completion of the order or upon termination of the business relationship. Statutory retention periods remain unaffected.
This website uses the features of the web analysis service Google Analytics. Provider is Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.
Google Analytics uses so-called “cookies”. These are text files stored on your computer allowing them to analyse how you use our website. Information on website usage from your part created by those cookies are generally transferred to Google servers in the US where they are stored.
We have activated the anonymisation of IP addresses on this website. This means that your IP address is abbreviated by Google within European Union member states or other states which are part of the European Economic Area before it is transmitted to the US. Only in exceptional cases is the full IP address transmitted to a Google server in the US and abbreviated there. On behalf of the provider of this website, Google uses this information to analyse your use of the website, to compile reports about the website activity and to provide further services which are connected to the use of this website and of the Internet for its operator. IP addresses which are transmitted from your browser for Google Analytics will not be combined with other data from Google.
Browser plug in
By changing your browser settings accordingly, you may prevent cookies from being stored; however, we point out that you may not have full access to all website functions in this case. In addition, you may prevent any data created by the cookie and relating to website usage on your part (including your IP address) from being transmitted to and being processed by Google by downloading and installing the browser plug-in available at the link below: https://tools.google.com/dlpage/gaoptout?hl=de
Objection to collection of data
You can prevent Google Analytics from collecting your data by clicking on the following link. This places an opt-out cookie which prevents the future collection of your data when visiting this website: Deactivate Google Analytics
Please see the privacy notice of Google for more information regarding the handling of user data by Google Analytics: https://support.google.com/analytics/answer/6004245?hl=de
Contract data processing
We have concluded an agreement for contract data processing with Google and fully implement the strict regulations of German data protection authorities when using Google Analytics.
Demographic data in Google Analytics
This website uses the “demographic data” function of Google Analytics. This allows for the compilation of reports that contain information regarding the age, gender, and interests of the visitors to the website. This information originates from interest-based advertising from Google as well as third-party visitor data. These data cannot be associated with a specific person. You can deactivate this function using the display settings in your Google account at any time or you can generally prohibit the collection of your data by Google Analytics as described in the section “objection to data processing”.
This website uses the map service Google Maps via an API. Provider is Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Your IP address has to be saved in order to be able to use the features of Google Maps. This information will usually be transferred to a Google server in the US, where it will be saved. The provider of this website has no influence on this transfer of data.
Please see the privacy notice of Google for more information regarding the handling of user data: https://www.google.de/intl/de/policies/privacy/
Publication of job advertisements / online job applications
Your application data will be collected and stored by us using electronic means in order to carry out the application process. If your application is followed by conclusion of an employment contract, the data provided by you can be stored by us in your personnel file for purposes of the customary organisational and management process under compliance with pertinent legal provisions.
If your application is rejected, the data provided by you is deleted automatically after two months after the rejection was communicated. This does not apply if storage for a longer period of time is required by law (for example burden of proof under the General Equal Treatment Act) or if you expressly agreed to storage in our prospective employee database for a longer period.
Which rights do you have with regard to your data?
You have, at any time, a right of free access to information on the origin, recipients and purpose of your stored personal data. Moreover, you have the right to request the rectification, blocking or erasure of such data. For this purpose, or if you have any further questions regarding data protection, you may contact us at the address specified in the legal notice at any time. In addition, you have the right to lodge a complaint with the competent supervisory authority. Furthermore, under certain circumstances, you have the right to request that we restrict the processing of your personal data. In the Data Protection Declaration, under the heading “Right to restriction of processing”, you can find details thereon.
Analysis tools and third-party tools
You can object to this analysis. This data privacy notice contains information about the possibilities to object.
Withdrawing your consent to data processing
Much of data processing is only possible with your express consent. You may withdraw the consent that you provided on a previous occasion at any time. To do so, sending us an informal message by email will suffice. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
Right to Object to Data Collection in Special Cases as well as to Direct Marketing (Art. 21 GDPR)
If we process your personal data for the purposes of direct marketing, you have the right to submit an objection to the processing of your personal data for such marketing purposes; insofar as it is associated with such direct marketing, this also applies to profiling. If you file an objection, your personal data will subsequently no longer be used for the purpose of direct marketing (objection under Art. 21(2) GDPR).
Right to lodge a complaint with the responsible supervisory authority
In the event of violations of the GDPR, the data subjects are entitled to lodge a complaint with a supervisory authority, in particular in the member state of their regular residence, their place of work or the place of the alleged violation. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
For a list of the data protection officers and their contact data, please refer to the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
Right to Data Portability
You have the right to be provided with the data that we process automatically on the basis of your consent, or for the performance of a contract, or have us provide such data to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another Controller, this will only be performed insofar as it is technically feasible.
Access, blocking, erasure, and rectification
You have, at any time, subject to applicable legal provisions, the right of free access to your stored personal data, access to information regarding their origin and recipients and the purpose of the data processing and to the rectification, blocking or erasure of this data, if applicable. To this end, or if you have more questions related to the topic of personal data, you can contact us at the address stated in the legal notice at any time.
Right to restrict processing
You have the right to request restriction of the processing of your personal data. For this purpose, you may contact us at the address specified in the legal notice, at any time. The right to restriction of the processing applies in the following cases:
Where you have restricted the processing of your personal data, such personal data may, with the exception of retention, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a member state.
Objection to advertisement e-mails
The use of contact data published to comply with statutory obligations to provide such information for the purposes of sending advertisements and information material which has not been expressly solicited is hereby rejected. The operators of this website expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for instance by means of spam emails.
Google Ads and Google Conversion-Tracking
Google Web Fonts
For the uniform representation of fonts, this website uses “web fonts” which are provided by Google. The Google fonts are installed locally. No connection to Google servers is established for this purpose.
Embedding of third-party services and content
It may be the case that contents or services of third parties, such as RSS feeds or graphics from other websites will be embedded within our online offering. This always requires that the providers of such content (“third-party provider”) are provided with the user’s IP address, since without the IP address, they would not be able to send the contents to the users’ browsers. The IP address is therefore required to display such contents. The provider will attempt to only use content whose providers use IP addresses solely for delivering the content. However, the provider of this website has no influence over whether the third-party provider saves the IP address, e.g. for statistical purposes. Any information that is available in this regard will be communicated to the user.
Publication of Job Advertisements / Online Job Applications
We offer you the possibility to submit an application to us (e.g. by e-mail, letter or the online
application form). Please find below information on the scope, purpose, and use of the personal data that we collect about
you as part of the application process. We guarantee that
your data are collected, processed and used in compliance with applicable data protection law
and all further legal provisions and that your data are treated as strictly confidential.
Scope and Purpose of Data Collection
When you submit an application to us, we will process your associated personal data
(e.g. contact and communication information, application documents, notes taken during job interviews etc.), provided that this is required to make a decision about initiating an employment relationship. The legal basis for this is section 26 of the Federal Data Protection Act - new version (initiation of an employment contract), Art. 6(1) point b GDPR (general initiation of contract) and – if you granted consent – Art. 6(1) point a GDPR. You may revoke your consent at any time. We will only disclose your personal data to such persons within our company that are involved in processing your application. If your application is successful, the data submitted by you are saved in our data processing systems based on section 26 of the Federal Data Protection Act - new version and Art. 6(1) point b GDPR for implementation of the employment contract.
Data storage periodIf we cannot offer you a position, if you reject a job offer, withdraw your application, withdraw your consent to data processing or ask us to erase the data, the data you provided us with, including any remaining physical application documents, will be saved and/or stored for no more than 6 months after completion of the application process (retention period) in order to be able to track details of the application process in case of discrepancies (Art. 6(1) point f GDPR). YOU CAN OBJECT TO SUCH RETENTION OF DATA IF YOU HAVE A JUSTIFIED INTEREST THAT OVERRIDES OURS. Once the retention period has ended, the data are erased, provided that there are no statutory retention obligations or any other legal reasons for further storage. If it is evident that it will be necessary to retain your data after the retention period has ended (e.g. in case of impending or pending legal disputes), the data will only be erased after the data have ceased to be important. Other statutory retention periods remain unaffected.