Name and contact details of the person(s) responsible
Our responsible person(s) (hereinafter referred to as "Responsible Person") within the meaning of Art. 4 no. 7 DS-GVO is:
ASSMANN WSW components GmbH
Auf dem Schüffel 1
58513 Lüdenscheid, Germany
Commercial register no.: HRB 5698
Register court: AG Iserlohn
Tel.: +49 2351 5542-00
Fax: +49 2351 5548-61
Email address: firstname.lastname@example.org
Our responsible data security officer you will reach under the above mentioned contact information or under email@example.com
Data types, purposes of processing and categories of data subjects
In the following we inform you about the type, scope and purpose of the collection, processing and use of personal data.
1. Types of data we process
Usage data (access times, websites visited, etc.), inventory data (name, address, etc.), contact data (telephone number, e-mail, fax, etc.), communication data (IP address, etc.),
2. The purposes of the processing pursuant to Art. 13 (1) c) DS-GVO
Evidence purposes / preservation of evidence, technical and economic optimization of the website, improvement of user experience, marketing / sales / advertising, compilation of statistics, handling of contact requests,
3. Categories of persons concerned under Article 13(1)(e) of the DS-GVO
Visitors/users of the website,
The data subjects are collectively referred to as "users".
Legal basis for the processing of personal data
In the following we inform you about the legal basis of the processing of personal data:
- If we have obtained your consent for the processing of personal data, Art. 6 para. 1 sentence 1 lit. a) DS-GVO is the legal basis.
- If the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures taken in response to your request, Article 6 (1) sentence 1 letter b) DS-GVO is the legal basis.
- If the processing is necessary for the fulfilment of a legal obligation to which we are subject (e.g. statutory storage obligations), Art. 6 Paragraph 1 Sentence 1 lit. c) DS-GVO is the legal basis.
- If the processing is necessary to protect the vital interests of the data subject or of another natural person, Art. 6 (1) sentence 1 lit. d) DS-GVO is the legal basis.
- If the processing is necessary to protect our interests or the legitimate interests of a third party and your interests or fundamental rights and freedoms do not prevail in this respect, Art. 6 (1) sentence 1 lit. f) DS-GVO is the legal basis.
Disclosure of personal data to third parties and processors
Without your consent, we will not pass on any data to third parties. Should this be the case, however, the transfer will be made on the basis of the aforementioned legal bases, e.g. when data is passed on to online payment providers for the purpose of fulfilling a contract or due to a court order or due to a legal obligation to surrender the data for the purpose of criminal prosecution, to avert danger or to enforce intellectual property rights.
We also use contract processors (external service providers e.g. for web hosting of our websites and databases) to process your data. If data is passed on to the processors as part of an agreement for order processing, this is always done in accordance with Art. 28 DS-GVO. We select our processors carefully, check them regularly and have been granted the right to issue instructions regarding the data. In addition, the processors must have taken suitable technical and organisational measures and comply with the data protection regulations according to BDSG n.F. and DS-GVO.
Transfer of data to third countries
The adoption of the European Data Protection Basic Regulation (DS-GVO) has created a uniform basis for data protection in Europe. Your data is therefore processed primarily by companies to which the DS-GVO applies. If, however, processing is carried out by services of third parties outside the European Union or the European Economic Area, they must comply with the special requirements of Art. 44 ff. DS-GVO. This means that the processing is carried out on the basis of special guarantees, such as the EU Commission's officially recognised determination of a level of data protection corresponding to that of the EU or compliance with officially recognised special contractual obligations, the so-called "standard contractual clauses".
We would like to point out that your data could be processed when using Google services in the USA. Google has outsourced a large number of its services (e.g. analytics, web fonts, maps) to European servers. However, it cannot be ruled out that US authorities may be able to access your data on the basis of local legislation without sufficient legal protection options being available to them. For this reason, we ask for your consent before these services are activated or the corresponding cookies are stored. If you do not want this, you can refuse your consent in this regard. Only technically necessary cookies are then stored; the services in question are not activated.
Deletion of data and storage period
Unless expressly stated in this data protection declaration, your personal data will be deleted or blocked as soon as the consent granted for processing is revoked by you or the purpose for storing the data no longer applies or the data is no longer required for the purpose, unless its further storage is required for evidence purposes or this is opposed by statutory storage obligations.
This includes, for example, commercial storage obligations for business letters according to § 257 para. 1 HGB (6 years) as well as tax storage obligations according to § 147 para. 1 AO of receipts (10 years). When the prescribed retention period expires, your data will be blocked or deleted, unless the storage is still necessary for the conclusion or fulfilment of a contract.
Existence of an automated decision making process
We do not use automatic decision making or profiling.
Provision of our website and creation of log files
- If you use our website for informational purposes only (i.e. no registration or other transmission of information), we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data:
- IP address;
- Internet service provider of the user;
- Date and time of access;
- Browser type;
- Language and browser version;
- Content of the request;
- Time zone;
- Access status/HTTP status code;
- Amount of data;
- Websites from which the request comes;
- Operating system.
This data will not be stored together with other personal data of yours.
- These data serve the purpose of user-friendly, functional and secure delivery of our website to you with functions and contents as well as their optimization and statistical evaluation.
- The legal basis for this is our justified interest in data processing in accordance with Art. 6 Para. 1 S.1 lit. f) DS-GVO, which is also contained in the above-mentioned purposes.
- For security reasons, we store this data in server log files for a storage period of 365 days. After this period has elapsed, they are automatically deleted, unless we require their storage for evidence purposes in the event of attacks on the server infrastructure or other legal violations.
The following types of cookies are distinguished:
- Necessary, essential cookies: Essential cookies are cookies that are absolutely necessary for the operation of the website in order to store certain website functions such as logins, shopping cart or user entries, e.g. regarding the language of the website.
- Session-Cookies: Session-Cookies are needed to recognize multiple use of an offer by the same user (e.g. if you have logged in to determine your login status). When you visit our site again, these cookies provide information to automatically recognize you. The information obtained in this way is used to optimise our offers and make it easier for you to access our site. When you close the browser or log out, the session cookies are deleted.
- Persistent cookies: These cookies remain stored even after closing the browser. They are used to store the login, to measure reach and for marketing purposes. They are automatically deleted after a specified period of time, which may vary depending on the cookie. You can delete the cookies at any time in the security settings of your browser.
- Third-party cookies (third-party cookies, especially from advertisers): You can configure your browser settings according to your wishes and, for example, refuse to accept third-party cookies or all cookies. However, we would like to point out at this point that you may then not be able to use all the functions of this website. Read more about these cookies in the respective third-party privacy statements.
- Data Categories: User data, cookie, user ID (including pages visited, device information, access times and IP addresses).
- Purposes of processing: The information obtained in this way serves the purpose of optimising our web offers both technically and economically and of enabling you to access our website more easily and securely.
- Legal basis: If we process your personal data with the aid of cookies on the basis of your consent ("opt-in"), then Art. 6 para. 1 sentence 1 lit. a) DSGVO is the legal basis. Otherwise we have a legitimate interest in the effective functionality, improvement and economic operation of the website, so that in this case Art. 6 para. 1 sentence 1 lit. f) DS-GVO is the legal basis. The legal basis is also Art. 6 Para. 1 sentence 1 lit. b) DS-GVO, if the cookies are set to initiate a contract, e.g. when orders are placed.
- Duration of storage/deletion: The data is deleted as soon as it is no longer required for the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session is ended.
Here you will find information about the deletion of cookies by browser:
Internet Explorer: https://support.microsoft.com/de-at/help/17442/windows-internet-explorer-delete-manage-cookies
Microsoft Edge: https://support.microsoft.com/de-at/help/4027947/windows-delete-cookies
- Objection and "Opt-Out": You can generally prevent cookies from being stored on your hard drive, regardless of consent or legal permission, by selecting "do not accept cookies" in your browser settings. However, this can result in a functional restriction of our offers. You can object to the use of third-party cookies for advertising purposes by means of a so-called "opt-out" via this American website or this European website.
Edit or contradict cookie settings:
Contact via contact form / e-mail / fax / mail
- When contacting us by contact form, fax, post or e-mail, your data will be processed for the purpose of handling the contact request.
- The legal basis for the processing of the data is Art. 6 Paragraph 1 S. 1 lit. a) DS-GVO if you have given your consent. The legal basis for the processing of data transmitted in the course of a contact inquiry or e-mail, letter or fax is Art. 6 Paragraph 1 S. 1 lit. f) DS-GVO. The person responsible has a legitimate interest in the processing and storage of the data in order to be able to respond to user enquiries, to secure evidence on liability grounds and, where appropriate, to be able to comply with his or her statutory obligations to retain business letters. If the contact aims at the conclusion of a contract, an additional legal basis for the processing is Art. 6 Paragraph 1 S. 1 lit. b) DS-GVO.
- We may store your details and contact request in our customer relationship management system ("CRM system") or a comparable system.
- The data will be deleted as soon as they are no longer required for the purpose for which they were collected. For personal data from the input mask of the contact form and those sent by e-mail, this is the case when the respective conversation with you has ended. The conversation is finished when it can be concluded from the circumstances that the matter in question has been finally clarified. Inquiries from users who have an account or a contract with us will be stored for a period of two years after termination of the contract. In the case of legal archiving obligations, deletion takes place after the end of the following periods: End of commercial law (6 years) and tax law (10 years) retention obligation.
- You have the option of withdrawing your consent to the processing of personal data at any time in accordance with Article 6 paragraph 1 sentence 1 letter a) DS-GVO. If you contact us by e-mail, you can object to the storage of your personal data at any time.
- We have developed the website analysis tool "Google Analytics" (service provider: Google Ireland Limited, Register No.: 368047, Gordon House, Barrow Street, Dublin 4, Ireland) on our website.
- Purpose of processing: The use of Google Analytics serves the purpose of analyzing, optimizing and improving our website.
- Legal basis: If you have given your consent ("opt-in") to the processing of your personal data by the third party provider using "Google Analytics", then Art. 6 Paragraph 1 Sentence 1 lit. a) DS-GVO is the legal basis. The legal basis is also our legitimate interest in the above-mentioned purposes (analysis, optimisation and improvement of our website) in data processing in accordance with Art. 6 Paragraph 1 S.1 lit. f) DS-GVO. In the case of services provided in connection with a contract, tracking and analysis of user behaviour is carried out in accordance with Art. 6 Paragraph 1 S.1 lit. b) DS-GVO in order to be able to use the information thus obtained to offer optimised services in order to fulfil the purpose of the contract. For the exceptional cases in which personal data is transferred to the USA, we base the processing on your consent expressly given via the consent banner in accordance with Art 49 I 1 a) GDPR. The legal basis for the use of Google Analytics is your consent, Art 6 I 1 a) GDPR. You can revoke your consent at any time.
- Duration of storage: The data we send and which are linked to cookies, user IDs (e.g. user ID) or advertising IDs are automatically deleted after 14 months. Data whose retention period has been reached is automatically deleted once a month.
- Data transmission/recipient category: Google, Ireland and USA. The acquired data is transferred to the USA and stored there. We have also concluded an agreement with Google for order processing in accordance with Art. 28 DS-GVO.
- Opposition and removal options ("opt-out"):
- You can generally prevent cookies from being stored on your hard drive by selecting "do not accept cookies" in your browser settings. However, this can result in a functional restriction of our offers. You can also prevent the collection of data generated by the cookie and related to your use of the website to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de
- As an alternative to the above browser plugin, you can prevent Google Analytics from collecting data by clicking edit cookie settings and deselect Google Analytics. This will set a settings cookie which will prevent the collection of your information when you visit this website in the future. This cookie is only valid for our website and your current browser and only lasts until you delete your cookies. In this case you would have to set the cookie again.
- You can deactivate the ross-device user analysis in your Google Account under "My data > personal data".
- We have integrated YouTube videos from youtube.com on our website using the embedded function, so that they can be accessed directly on our website. YouTube is owned by Google Ireland Limited, Register No: 368047, Gordon House, Barrow Street, Dublin 4, Ireland.
- Data category and description of data processing: Usage data (e.g. web page accessed, contents and access times). We have integrated the videos in the so-called "extended data protection mode" without using cookies to record usage behaviour in order to personalise video playback. Instead, the video recommendations are based on the video currently playing. Videos played in enhanced privacy mode in an embedded player have no effect on which videos are recommended to you on YouTube. When you start a video (click on the video), you agree to allow YouTube to track the information that you have accessed the corresponding subpage or video on our website and use this information for advertising purposes.
- Purpose of processing: to provide a user-friendly service, to optimize and improve our content.
- Legal basis: If you have given your consent ("opt-in") for the processing of your personal data by means of "etracker" from the third-party provider, then Art. 6 para. 1 sentence 1 lit. a) DS-GVO is the legal basis. The legal basis is also our legitimate interest in data processing for the above purposes in accordance with Art. 6 Paragraph 1 S.1 lit. f) DS-GVO. In the case of services provided in connection with a contract, tracking and analysis of user behaviour is carried out in accordance with Art. 6 Paragraph 1 Sentence 1 lit. b) DS-GVO in order to be able to use the information thus obtained to offer optimised services in order to fulfil the purpose of the contract.
- Data transmission/recipient category: third-party providers in the USA. The data obtained is transmitted to the USA and stored there. This also takes place without a user account with Google. If you are logged into your Google account, Google can assign the above data to your account. If you do not wish this, you must log out of your Google account. Google creates user profiles from such data and uses these data for the purpose of advertising, market research or optimization of its websites.
- Storage period: Cookies up to 2 years or until the cookies are deleted by you as a user.
- You have a right of objection to Google against the creation of user profiles. Please therefore contact Google directly via the data protection declaration below. You can make an opt-out objection regarding advertising cookies here in your Google Account:
- You can also immediately deactivate the local output of YouTube videos in the cookie settings:
- We have on our website maps from "Google Maps" (provider: Google Ireland Limited, Register No.: 368047, Gordon House, Barrow Street, Dublin 4, Ireland).
- Data category and description of data processing: usage data (e.g. IP, location, page accessed). Google Maps allows us to display the location of addresses and directions directly on our website in interactive maps and to enable you to use this tool. When you call up our website, where Google Maps is integrated, a connection is established to the Google servers in the USA. Your IP and location can be transmitted to Google. Google also receives information that you have called up the corresponding page. This is also done without a user account with Google. If you are logged into your Google account, Google can assign the above data to your account. If you do not wish to do so, you must log out of your Google account. Google creates user profiles from such data and uses these data for the purpose of advertising, market research, marketing and sales. We use the so-called two-click solution. This means that when you visit our site, no personal data is initially passed on to Google. We give you the opportunity to use the button to communicate directly with the provider of the plug-in. Only if you click on the marked field and thereby activate it will the plug-in provider receive the information that you have accessed the corresponding website of our online offer and Google Maps will be activated for use.
- Purpose of processing: To provide a user-friendly, economical and optimized website.
- Legal basis: If you have given your consent ("opt-in") for the processing of your personal data using "Google Maps" by the third-party provider, Art. 6 (1) sentence 1 lit. a) DS-GVO is the legal basis. The legal basis is also our legitimate interest in data processing in accordance with Art. 6 (1) sentence 1 lit. f) DS-GVO for the above purposes.
- Data transmission/recipient category: Third party providers in the USA. The legal basis for the data transfer is your express consent in accordance with Art. 49 I GDPR.
- Storage period: Cookies for up to 6 months or until you delete them. Otherwise, as soon as they are no longer needed for processing purposes.
- Possibility of objection and removal:
- You have a right of objection to Google against the creation of user profiles. Therefore, please contact Google directly via the data protection declaration mentioned below. An opt-out objection regarding advertising cookies can be made here in your Google Account:
- You can also immediately deactivate the use of Google Maps in the cookie settings:
Rights of the data subject
- Objection or revocation against the processing of your data
Insofar as the processing is based on your consent pursuant to Art. 6 para. 1 sentence 1 lit. a), Art. 7 DS-GVO, you have the right to revoke your consent at any time. This does not affect the lawfulness of the processing carried out on the basis of the consent until revocation.
Insofar as we base the processing of your personal data on the balancing of interests in accordance with Art. 6 (1) sentence 1 lit. f) DS-GVO, you may object to the processing. This is the case if the processing is not necessary, in particular, for the fulfilment of a contract with you, which is described by us in the following description of the functions. In the event of such an objection, we request that you explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the facts of the case and will either stop or adapt the data processing or show you our compelling reasons worthy of protection on the basis of which we will continue the processing.
You can object to the processing of your personal data for the purposes of advertising and data analysis at any time. You can exercise the right of objection free of charge. You can inform us about your objection to advertising by using the following contact details:
ASSMANN WSW components GmbH
Auf dem Schüffel 1
58513 Lüdenscheid, Germany
Email address: firstname.lastname@example.org
- Right to information
You have the right to ask us to confirm whether personal data concerning you is being processed. If this is the case, you have a right to information about your personal data stored with us in accordance with Art. 15 DS-GVO. This includes, in particular, information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the origin of your data, unless it was collected directly from you.
- Right of rectification
You have a right to correct incorrect data or to complete correct data in accordance with Art. 16 DS-GVO.
- Right to deletion
You have the right to have your data stored by us deleted in accordance with Art. 17 DS-GVO, unless legal or contractual retention periods or other legal obligations or rights to further storage conflict with this.
- Right to restriction
You have the right to request a restriction on the processing of your personal data if one of the conditions in Art. 18 (1) lit. a) to d) DS-GVO is fulfilled:
- If you dispute the accuracy of the personal data concerning you for a period of time that allows the person responsible to verify the accuracy of the personal data;
- the processing is unlawful and you object to the deletion of the personal data and request instead the restriction of the use of the personal data;
- the controller no longer needs the personal data for the purposes of the processing, but you need the personal data in order to assert, exercise or defend legal claims; or
- if you have lodged an objection to the processing in accordance with Article 21 (1) of the DPA and it has not yet been established whether the legitimate reasons given by the controller outweigh your reasons.
- Right to data transferability
You have a right to data transferability in accordance with Art. 20 DS-GVO, which means that you can receive the personal data stored by us about you in a structured, common and machine-readable format or request that it be transferred to another person responsible.
- Right of complaint
You have a right to complain to a regulatory body. As a general rule, you may do so by contacting the supervisory authority, in particular in the Member State in which you are resident, in your place of work or in the place where the suspected infringement is committed.
In order to protect all personal data transmitted to us and to ensure that the data protection regulations are observed by us and our external service providers, we have taken suitable technical and organisational security measures. Therefore, among other things, all data between your browser and our server is transmitted in encrypted form via a secure SSL connection.