Privacy Policy


A. PRIVACY POLICY WEBSITE BBW-LASERTECHNIK.DE

In the following we inform about the collection of personal data when visiting our website. Personal data means any information relating to an identified or identifiable natural person (‘data subject’), e.g. name, address, e-mail addresses, user behaviour.
 

1. Controller of data processing

The controller for data processing in accordance with Article 4 (7) of the EU Data Protection Regulation (GDPR) is

BBW Lasertechnik GmbH

Gewerbering 11
83134 Prutting

Phone: +49 (0) 80 36 9 08 20-0
Telefax: +49 (0) 80 36 9 08 20-28

E-mail: [email protected]

(in the following: "Controller")

The Controller has appointed a data protection officer, who can be contacted as follows: datenschutz(at)bbw-lasertechnik.de
 

2. Collection and processing of personal data

a. When visiting the website

When visiting the controller's website, the following data is transmitted from the user's browser to the controller's server and stored: The user’s operating system, the user’s IP address, date and time of access, websites from which the user’ system reaches our website, the services and functions used on our website. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. The legitimate interest of the controller lies in the fact that this data serves to ensure the functionality of the controller's website.

b. When using the contact form

If the user sends an inquiry to the controller using the online form in the "Contact" section, the name (a pseudonym may also be given) and e-mail address are collected. The indication of the company name is voluntary. The contact request cannot be sent without providing a name and e-mail address. When sending a contact request, the user expects the controller to contact him/her via one of the contact channels given in the contact request. The legal basis is Art. 6 (1) sentence 1 lit. f GDPR. The legitimate interest of the controller is to communicate with the customer in an flexible manner with regard to the customer's specific request and thus to provide a good customer service.

c. Data processing for direct marketing purposes

Personal data is processed to inform about our innovations and services, as well as to ensure comprehensive customer support. The legal basis for this data processing is Art. 6 Abs. 1 S. 1 lit. f DS-GVO. The user has the right to object to the processing for direct marketing purposes at any time. The processing of personal data for direct marketing purposes is in the legitimate interest of the provider. 
 

3. Use of cookies

Cookies are used on the internet pages of the controller. Cookies are small text files that are stored by the Internet browser on the user's computer system. This cookie contains a distinctive string that allows the browser to be uniquely identified when the website is visited again. They serve to make the Internet offer as a whole more user-friendly and effective.

The following types of cookies are used on the provider's website:

- Session cookies: These cookies are automatically deleted when the user closes his browser.

It is possible at any time to restrict the setting of cookies by changing the settings in the Internet browser. The user will then be informed about the setting of cookies and can decide individually about their acceptance or exclude the acceptance of cookies for certain cases or generally. Each browser is different in the way it manages the cookie settings. Set cookies can be deleted by adjusting the settings in the user's browser. Please note that if cookies are deactivated, it may not be possible to use all functions of the controller´s website to their full extent.

The legal basis is Art. 6 Paragraph 1 S. 1 lit. f GDPR. The legitimate interest of the controller is to offer a user-friendly and effective website. 
 

4. Exchange of data

The data collected via the controller's website will only be passed on to third parties if this is otherwise noted in the individual data processing steps. The controller commissions processors (web hosting, IT service providers) who may come into contact with the user's data. 
 

5. Bing Ads

On the website, the provider uses Bing Ads (bingads.microsoft.com), a web analysis service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA ("Microsoft"). "Bing Ads" also uses "cookies", text files that are stored on the user's device (PC, mobile, tablet, etc.) when the user accesses the controller´s website through a Microsoft Bing ad. If the controller's site is visited, the controller and Microsoft are informed that the user has clicked on the ad and has reached the controller's site via the ad. The controller does not receive information that personally identifies users, only information about the total number of users who clicked on a Bing ad and were then redirected to the controller's site. Microsoft collects, processes, and uses information via the cookie to create usage profiles using pseudonyms. These usage profiles are used to analyze visitor behavior and are used for advertising tailored to the user.

The user can prevent the installation of cookies by adjusting the settings of his browser software accordingly.

Furthermore, the user can prevent the collection of data generated by the cookie and related to the use of the website as well as the processing of this data by Microsoft by declaring his objection under the following link http://choice.microsoft.com/de-DE/opt-out .

Further information on data protection and the cookies used by Microsoft and Bing Ads can be found at https://privacy.microsoft.com/de-de/privacystatement.

The legal basis for the use of Bing Adss the consent of the user, Art. 6 para. 1 a) DSGVO. 
 

6. Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is used for the technical management and deployment of scripts (e.g., for Google Analytics or marketing tools). Tag Manager itself does not perform any analyses, does not store cookies, and does not create its own usage profiles.

Technical data (e.g., IP address, browser information) is processed to deliver the Tag Manager. Whenever possible, the Tag Manager is not loaded directly from the servers of googletagmanager.com, but rather via our own infrastructure (e.g., a so-called GTAG Gateway). This reduces data transfer to Google and makes the processing of technical connection data more privacy-friendly.

If data is transmitted to Google (e.g., when the Tag Manager is loaded directly), this may also be transmitted to servers in the United States. Google is certified under the EU-U.S. Data Privacy Framework (DPF).

The use of Tag Manager is based on Article 6(1)(f) of the GDPR (legitimate interest in the efficient and data-protection-compliant management of tracking and marketing services). To the extent that consent is required for integrated tools, these are only activated by the Tag Manager once you have given your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25 of the TDDDG.
 

7. Google Analytics

We use Google Analytics 4 on our website, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). We use Google Analytics 4 to analyze the use of our website, generate reports on our visitors’ activities, and evaluate this data to optimize our content.

Google Analytics 4 uses cookies and similar technologies. However, the information collected about your use of the website (e.g., pages visited, browser information, operating system, and, where applicable, click paths) is not transmitted directly to Google, but is first processed via our server-side tagging server (SST), which we operate in the EU-West 3 region (Frankfurt) on Google Cloud Run.

On this server, your data—in particular the IP address transmitted by your device—is already anonymized or pseudonymized before it is forwarded to Google servers for further processing. In this way, we reduce the direct exchange of data between your device and Google and strengthen the protection of your personal data.

On our behalf, Google uses the data exclusively to generate reports on website activity and to provide other services related to website usage. According to our settings, this data is not combined with other data held by Google. Analytics data is retained for 14 months.

In addition, we use the Google Signals feature as part of Google Analytics 4. This feature enables the creation of cross-device reports, provided you have enabled the “personalized ads” option in your Google Account. In this context, we receive only anonymous, statistical analyses—no personal data. You can disable this feature at any time in your Google Account settings.

The legal basis for the use of Google Analytics 4 is your consent pursuant to Art. 6(1)(a) GDPR, which you provide through our cookie consent tool. Google Analytics 4 will not be used without your consent. You may revoke your consent at any time via the consent tool with future effect.

We have entered into a data processing agreement (Article 28 of the GDPR) with Google. For any transfers to third countries (e.g., the U.S.), Google relies on the Standard Contractual Clauses approved by the European Commission. For more information, please see Google’s privacy policy at:
https://policies.google.com/privacy?hl=de
https://policies.google.com/technologies/partner-sites
 

8. Server-Side Tagging (SST) - Use for Additional Services

In addition to Google Analytics 4, we also use our server-side tagging container (Google Cloud Run, EU West 3 / Frankfurt region) to process and forward data to other marketing and analytics tools, such as Google Ads, Meta Ads (Facebook/Instagram), or conversion APIs.

The process is identical in all cases:

  • Data regarding your website usage is first transmitted to our SST server in the EU.
  • There, to the extent technically possible, the data is anonymized or pseudonymized (e.g., by truncating the IP address).
  • Only then is the processed information forwarded to the respective providers.

The use of these tools is generally subject to your explicit consent (Art. 6(1)(a) GDPR) via our cookie consent tool. We may process purely technical log data—which is necessary to ensure trouble-free operation and IT security—based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR.

If we transfer data to third-party providers (e.g., Google, Meta) based on your consent, the data may also be processed in countries outside the EU (in particular the U.S.). In such cases, the transfer is based on the Standard Contractual Clauses approved by the European Commission or other safeguards.

You may revoke your consent to the respective services at any time with future effect via our consent management tool.
 

9. Google Ads

We use Google Ads Conversion Tracking, a service provided by Google Ireland Limited.

If you arrive at our website via Google ads, a cookie with a limited duration (max. 90 days) is stored, which is used exclusively to measure the effectiveness of the ads. We only receive aggregated data, such as how many users clicked on an ad and subsequently completed a conversion. It is not possible to identify individual users.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TDDDG. No personal data will be transferred without your consent.

Any transfers to the U.S. are based on the EU Commission’s Standard Contractual Clauses. Additionally, Google is certified under the EU-U.S. Data Privacy Framework (DPF).

Consent Mode v2 will be mandatory starting in March 2024. Our cookie banner ensures that consent for the categories “ad_user_data” and “ad_personalization” is obtained in compliance with the GDPR. Without consent, Google processes only anonymized, modeled conversions.

Enhanced Conversions

We use the “Enhanced Conversions” and “Enhanced Conversions for Leads” features offered by Google.

  • Enhanced Conversions for Web: When a conversion takes place (e.g., a purchase or registration), data you enter (e.g., name, email address, mailing address) may be sent to Google in encrypted form (SHA-256) to better attribute conversions across users.
  • Enhanced Conversions for Leads (EHCfL): For lead forms, the email address you enter is hashed and transmitted to Google to better evaluate the quality of leads.

Retention period: up to 63 days.

Legal basis: Your consent pursuant to Art. 6(1)(a) of the GDPR, which may be revoked at any time via the consent tool. 
 

10. Meta Pixel (client-side)

We use the Meta Pixel from the social network Facebook or Instagram (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland; “Meta”) on our website.

The Meta Pixel enables us to identify visitors to our website as a target audience for displaying ads (“Facebook/Instagram Ads”) and to measure the effectiveness of our advertising campaigns (“Conversion Tracking”). With the help of the pixel, we can recognize you on Meta’s platforms after you visit our website and display interest-based ads to you there.

To do this, a direct connection to Meta’s servers is established via your device when you visit our website. The following data, for example, is processed in this process:

  • HTTP headers (IP address, browser information, time of page view),
  • Pixel-specific data (pixel ID, cookie information),
  • Event data (e.g., products viewed, shopping cart, purchase, or registration actions).

Meta may link this data to your Facebook or Instagram account. Meta may also use it for its own purposes, such as profiling and advertising. We have no influence over Meta’s further processing of this data.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TDDDG. Personal data will not be transferred without your consent.
 

11. Meta Conversion API (server-side via SST)

In addition to the client-side pixel, we use the Meta Conversion API (CAPI). With this method, event data is transmitted to Meta on the server side via our server-side tagging container (Google Cloud Run, Region EU-West 3, Frankfurt).

How it works:

  • Your interactions on the website (e.g., purchases, leads, form submissions) are first transmitted to our SST server.
  • There, the data is pseudonymized (e.g., hashing of email addresses using SHA-256) and then forwarded to Meta via a secure interface.
  • In this way, we ensure that sensitive data is not sent directly from your device to Meta servers in the U.S., but is first processed via our EU infrastructure.

The use of both the pixel and the Conversion API serves marketing and optimization purposes, i.e., to target advertisements to appropriate user groups and to statistically evaluate the success of advertising campaigns.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TDDDG. No personal data will be transferred without your consent.
 

12. LinkedIn Insight Tag 

a. LinkedIn Insight Tag (client-side)

We use the LinkedIn Insight Tag from the social network LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland; “LinkedIn”) on our website.

The LinkedIn Insight Tag enables us to identify visitors to our website as a target audience for displaying ads (“LinkedIn Ads”) and to measure the effectiveness of our advertising campaigns (“Conversion Tracking”). Through this tag, we can recognize you on the LinkedIn platform after you visit our website and display interest-based ads to you there.

When you visit our website, a direct connection is established with LinkedIn’s servers. The following data, among other things, may be processed:

  • HTTP headers (e.g., IP address, browser information, timestamp of the page view)
  • Tag-specific data (tag ID, LinkedIn cookie information)
  • Event data (e.g., pages viewed, product interactions, form submissions, or purchases)

LinkedIn may link this data to your LinkedIn account. LinkedIn may also use the data for its own purposes, such as profiling or serving ads. We have no control over LinkedIn’s further processing of this data.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TDDDG. No personal data will be transferred without your consent.
 

b. LinkedIn Conversion API (server-side via SST)

In addition to the client-side Insight Tag, we use the LinkedIn Conversion API. With this API, event data is transmitted to LinkedIn on the server side via our server-side tagging container (Google Cloud Run, Region EU-West 3, Frankfurt).

How it works:

  • Your website interactions (e.g., purchases, leads, form submissions) are first transmitted to our SST server.
  • There, the data is pseudonymized (e.g., by hashing email addresses with SHA-256) and then forwarded to LinkedIn via a secure interface.
  • This ensures that sensitive data is not sent directly from your device to LinkedIn servers in the U.S., but is first processed via our EU infrastructure.

The use of both the Insight Tag and the Conversion API serves marketing and optimization purposes, namely the targeted delivery of advertisements to relevant user groups and the statistical analysis of our advertising campaigns.

Legal Basis & Data Transfer

Legal basis: The use of the LinkedIn Insight Tag and the Conversion API is based exclusively on your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TDDDG. No processing takes place without your consent.

Right to Withdraw Consent: You may withdraw your consent at any time via our consent management tool.

Transfers to the U.S.: Please note that data may also be transferred to the U.S. LinkedIn Corporation (U.S.) is certified under the EU–U.S. Data Privacy Framework (DPF), ensuring an adequate level of data protection. In addition, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission.

For more information on data processing by LinkedIn, please see their privacy policy:
https://www.linkedin.com/legal/privacy-policy
 

13. Microsoft Clarity

To provide statistics on the use of our website—in the form of heat maps and session recordings generated primarily by tracking mouse movements—we use the Microsoft Clarity service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA (“Microsoft”).

To analyze the use of our website, Microsoft Clarity uses cookies and pixels. In doing so, your IP address, mouse movements, clicks, time, frequency, location, and user behavior, as well as interaction data, scrolling activity during your visit to our website, and similar information are collected, transmitted to Microsoft (Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland), and stored there.

In order to assign the statistics to individual campaigns, Microsoft Clarity is linked to Google Analytics 4 (see the separate section in this Privacy Policy regarding the latter service), provided that you have also consented to the use of Google Analytics 4.

The legal basis for the use of Microsoft Clarity, including the integration with Google Analytics 4, is your consent pursuant to Article 6(1)(a) of the GDPR. To the extent that personal data is transferred to the United States, this is done pursuant to Article 45 of the GDPR in conjunction with the European Commission’s Adequacy Decision C(2023) 4745. Both Microsoft and Google have committed to complying with the data processing principles of the Data Privacy Framework (DPF).

Please review Microsoft’s privacy notices at 
https://privacy.microsoft.com/de-de/privacystatement and at 
https://clarity.microsoft.com/terms.
 

14. Leadfeeder (Dealfront)

This website uses Leadfeeder, a service provided by Dealfront Group GmbH, Erbprinzenstraße 4-12, 76133 Karlsruhe, Germany (hereinafter „Dealfront“). Leadfeeder analyses the IP address of visitors in order to determine which companies visit the provider’s website. It is neither intended nor possible to identify individual natural persons in this way.

The following data is processed: the user’s IP address, the pages visited, the time spent on the website, the origin of the visit (source/medium, referrer) and a visitor ID assigned by means of cookies. The IP address is truncated (anonymised) before it is analysed.

For this purpose Leadfeeder sets the cookies „_lfa“ (term 1 year), „_lfa_consent“ (term 2 years) and „_lfa_test_cookie_stored“ (session) as well as the local storage entry „_lfa_expiry“ (term 2 years). These serve to attribute returning visits to the same company.

Leadfeeder is only loaded if the user has consented to the cookie category „Performance“ via the provider’s consent banner. The legal basis is Art. 6 (1) (1) (a) GDPR in conjunction with Sec. 25 (1) TDDDG. The user may revoke this consent at any time with effect for the future via the cookie settings.

A data processing agreement pursuant to Art. 28 GDPR has been concluded with Dealfront. The data collected via the tracker is processed on servers within the EU or the EEA. In addition, Dealfront uses individual sub-processors located in the USA; these transfers are covered by the Standard Contractual Clauses of the European Commission pursuant to Art. 46 (2) (c) GDPR. Dealfront provides an up-to-date overview of its sub-processors. Further information on data protection at Dealfront: https://www.dealfront.com/privacy/
 

15. Routine deletion and blocking of personal data

The controller processes and stores personal data of the person concerned only as long as this is necessary to achieve the purpose of storage. In addition, data may be stored for as long as this is provided for by the European or national legislator in EU provisions, laws or other regulations to which the person responsible for processing is subject.

As soon as the storage purpose ceases to apply or a storage period prescribed by the aforementioned regulations expires, the personal data is routinely deleted. 
 

16. Rights of the user

Under certain conditions, the user has the following rights against the controller with regard to the personal data concerning him/her:

  • Right to information,
  • Right of correction or deletion,
  • Right to restrict processing,
  • Right to object to the processing,
  • Right to data portability.

The user also has the right to complain to a data protection authority about the processing of his personal data by the controller. 
 

17. Revocability of declarations of consent under data protection law

If the user has given his consent to the processing of his data by the controller, he can revoke this consent at any time.
 

To view or adjust your current cookie settings for this browser, please visit Cookie Settings.

 

B. PRIVACY POLICY FOR APPLICANTS

In the following we inform about the processing of personal data when sending an application to us.

 

1. Controller of data processing

The controller for data processing in accordance with Article 4 (7) of the EU Data Protection Regulation (GDPR) is

BBW Lasertechnik GmbH

Gewerbering 11
83134 Prutting

Telefon: (0 80 36) 9 08 20- 0
Telefax: (0 80 36) 9 08 20- 28

e-mail: [email protected]

(in the following: "Controller")

The Controller has appointed a data protection officer, who can be contacted as follows: datenschutz(at)bbw-lasertechnik.de

 

2. Collection and processing of personal data

a. Generally

The personal data of an applicant is processed in order to process the application as a speculative application or in response to a specific job advertisement. Processing is used to check whether the applicant is suitable for a vacant position and, if necessary, to create an employment contract. The applicant has to provide the data required to process the application, otherwise the application cannot be processed.

The legal basis for data processing is § 26 Paragraph 1 German Federal Data Protection Act (FDPA).

b. When using the online form

If the applicant submits his or her application to the controller using the online form in the "Career" section, first name, last name, address, telephone number and e-mail address are collected. The application cannot be sent without providing these data.

The legal basis for data processing is § 26 para. 1 FDPA.

The applicant can also upload documents containing other data relevant to the application. Item 2.a of this data protection notice applies to these data.

 

3. Exchange of data

The applicant data will be passed on to third parties exclusively,

  • If legally required to do so
  • On the basis of the legitimate interest of the controller (e.g. to authorities, lawyers, courts, committees, supervisory bodies)
  • If the applicant has given his consent

In addition, the controller's contract processors may come into contact with the applicant's data.

 

4. Routine deletion and blocking of personal data

The controller processes and stores personal data of the person concerned only as long as this is necessary to achieve the purpose of storage. In addition, data may be stored for as long as this is provided for by the European or national legislator in EU ordinances, laws or other regulations to which the controller is subject.

As soon as the storage purpose ceases to apply or a storage period prescribed by the aforementioned regulations expires, the personal data is routinely deleted.

Candidate data are either deleted (electronic data) or returned to the applicant in their original form (paper documents) six months after the decision is taken, unless the applicant is recruited.

 

5. Rights of the applicant

Under certain conditions, the applicant has the following rights against the controller with regard to the personal data concerning him/her:

  • Right to information,
  • Right of correction or deletion,
  • Right to restrict processing,
  • Right to object to the processing,
  • Right to data portability.

The applicant also has has the right to complain to a data protection authority about the processing of his personal data by the controller.

 

6. Revocability of declarations of consent under data protection law

If the applicant has given his consent to the processing of his data by the controller, he/she can revoke this consent at any time.

 

C. PRIVACY POLICY FOR CUSTOMERS

In the following we inform about the processing of personal data of Customers.

 

1. Controller of data processing

The Controller for data processing pursuant to Article 4 (7) of the EU General Data Protection Regulation (GDPR) is:

BBW Lasertechnik GmbH

Gewerbering 11
83134 Prutting

Telefon: (0 80 36) 9 08 20- 0
Telefax: (0 80 36) 9 08 20- 28

e-mail: [email protected]

(in the following: "Controller")

TThe Controller has appointed a data protection officer, who can be contacted as follows: datenschutz(at)bbw-lasertechnik.de

 

2. General information on data processing

a.    Scope of the processing of personal data

The processing of a Customer's personal data is generally only carried out insofar as this is necessary for the performance of services by the Controller. The processing of personal data regularly takes place only on the basis of the fulfillment of a contract or for the implementation of a pre-contractual measure.

b.    Legal basis for the processing of personal data

Insofar as the Controller obtains the consent of the data subject for processing operations of personal data, Art. 6 para. 1 sentence 1 lit. a. GDPR serves as the legal basis.

When processing personal data that is necessary for the performance of a contract between the Customer and the Controller, Art. 6 para. 1 sentence 1 lit. b. GDPR serves as the legal basis. This also applies to processing operations that are necessary for the performance of pre-contractual measures.

Insofar as processing of personal data is necessary for the fulfillment of a legal obligation to which the Controller is subject, Art. 6 para. 1 sentence 1 lit. c GDPR serves as the legal basis.

In the event that vital interests of the Customer or another natural person make processing of personal data necessary, Art. 6 para. 1 sentence 1 lit. d. GDPR serves as the legal basis.

If the processing is necessary to protect a legitimate interest of the Controller or a third party and the interests of the Customer, fundamental rights and freedoms do not outweigh the former interest, Art. 6 para. 1 sentence 1 lit. f. GDPR serves as the legal basis for the processing.

c.    Data deletion and storage period

Personal data will be deleted or blocked as soon as the purpose of storage ceases to apply. Storage may take place beyond this if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the Controller is subject. Data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need to continue storing the data for the conclusion or fulfillment of a contract.

 

3. Contact by e-mail

a.    Legal basis for data processing

The legal basis for the processing of personal data transmitted in the course of sending an e-mail is Art. 6 para. 1 sentence 1 lit. f EU-GDPR. If the e-mail contact aims at the conclusion of a contract, Art. 6 para. 1 sentence 1 lit. b EU-GDPR is the additional legal basis for the processing of personal data.

b.    Purpose of the data processing

The processing of personal data in the case of contact by e-mail serves us to process the contact.

c.    Data processing for direct marketing purposes

Personal data are processed in order to inform about innovations and services of the Controller, as well as to ensure comprehensive Customer support. The legal basis for this data processing is Art. 6 para. 1 sentence 1 lit. f EU-GDPR. The Customer has the right to object to the processing for direct marketing purposes at any time. The processing of personal data for direct marketing purposes is in the legitimate interest of the Controller.

d.    Possibility of objection and removal

Customers have the option at any time to object for the future to the processing of their personal data in the context of contacting them by e-mail. In such a case, the conversation between the Customer and the Controller cannot be continued. All personal data stored in the course of contacting the Controller will be deleted in this case.

 

4. Legal defense and enforcement of rights

a.    Legal basis for data processing

The legal basis for the processing of personal data in the context of legal defense and enforcement is Art. 6 para. 1 sentence 1 lit. f EU-GDPR.

b.    Purpose of data processing

The purpose of processing personal data in the context of legal defense and enforcement is the defense against unjustified claims and the legal enforcement of claims and rights. In this purpose, Controller has a legitimate interest in the data processing according to Art. 6 para. 1 sentence 1 lit. f EU-GDPR.

c.    Duration of storage

Personal data will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected.

d.    Possibility of objection and removal

The processing of personal data in the context of legal defense and enforcement is mandatory for legal defense and enforcement. Consequently, there is no possibility for the Customer to object.

 

5. Categories of recipients

Within the Controller's company, those offices and departments receive personal data that need it to fulfill the aforementioned purposes. In addition, the Controller sometimes uses different service providers and transmits personal data to other trusted recipients. These may be, for example:

  • Banks
  • Scanning service
  • Printing companies
  • IT service providers
  • Customer relationship service providers
  • Lawyers and courts

 

6. Rights of the data subject

If personal data is processed by the Controller, the Customer is a data subject within the meaning of the EU-GDPR and is entitled to the following rights vis-à-vis the Controller:

a.    Right to information

The Customer may request confirmation from the Controller as to whether personal data concerning him are being processed by the Controller.

If such processing exists, the Customer may request information from the Controller about the following:

(1) The purposes for which the personal data are processed;

(2) The categories of personal data which are processed;

(3) The recipients or categories of recipients to whom the personal data concerning the Customer have been or will be disclosed;

(4) The planned duration of the storage of the personal data relating to the Customer or, if specific information on this is not possible, criteria for determining the storage period;

(5) The existence of a right to rectification or erasure of the personal data concerning the Customer, a right to restriction of processing by the Controller or a right to object to such processing;

(6) The existence of a right of appeal to a supervisory authority;

(7) Any available information on the origin of the data, if the personal data are not collected from the Customer;

(8) The existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) EU-GDPR and - at least in these cases - meaningful information about the logic involved and the scope and intended effects of such processing for the Customer.

The Customer has the right to request information as to whether personal data concerning him are transferred to a third country or to an international organization. In this context, the Customer may request to be informed about the appropriate safeguards pursuant to Art. 46 EU-GDPR in connection with the transfer.

b.    Right to rectification

The Customer has a right to rectification and/or completion vis-à-vis the Controller, insofar as the processed personal data concerning him are incorrect or incomplete. The Controller shall carry out the correction without delay.

c.    Right to restriction of processing

Under the following conditions, the Customer may request the restriction of the processing of personal data concerning him:

(1) If he disputes the accuracy, of the personal data concerning him for a period enabling the Controller to verify the accuracy of the personal data;

(2) The processing is unlawful and he/she refuses the erasure of the personal data and instead requests the restriction of the use of the personal data;

(3) The Controller no longer needs the personal data for the purposes of the processing, but the Customer requires them for the assertion, exercise or defense of legal claims; or

(4) If he has objected to the processing pursuant to Article 21 (1) EU-GDPR and it has not yet been determined whether legitimate reasons of the Controller prevail over the reasons of the Customer.

If the processing of personal data relating to him/her has been restricted, this data may - apart from being stored - only be processed with his/her consent or for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the Union or a Member State.

If the restriction of processing has been restricted in accordance with the above conditions, the Customer will be informed by the Controller before the restriction is lifted.

d.    Right to deletion

i.    Obligation to delete

The Customer may request from the Controller that the personal data concerning him be deleted without undue delay, and the Controller shall be obliged to delete such personal data without undue delay, if one of the following reasons applies:

(1) The personal data concerning the Customer are no longer necessary for the purposes for which they were collected or otherwise processed.

(2) The Customer revokes his consent on which the processing was based pursuant to Art. 6 (1) a or Art. 9 (2) a EU-GDPR and there is no other legal basis for the processing.

(3) The Customer objects to the processing pursuant to Art. 21 (1) EU-GDPR and there are no overriding legitimate grounds for the processing, or objects to the processing pursuant to Art. 21 (2) EU-GDPR.

(4) The personal data concerning the Customer have been processed unlawfully.

(5) The erasure of the personal data concerning the Customer is necessary for compliance with a legal obligation under Union law or the law of the Member States to which the Controller is subject.

(6) The personal data concerning the Customer has been collected in relation to information society services offered in accordance with Article 8(1) EU-GDPR.

ii.    Information to third parties

If the Controller has made personal data concerning the Customer public and is obliged to erase such data pursuant to Article 17(1) EU-GDPR, it shall take reasonable steps, including technical measures, having regard to the available technology and the cost of implementation, to inform data Controllers which process the personal data that the Customer, as a data subject, has requested that they erase all links to, or copies or replications of, such personal data.

iii.    Exceptions

The right to erasure does not exist to the extent that the processing is necessary to.

(1) For the exercise of the right to freedom of expression and information;

(2) For compliance with a legal obligation which requires processing under Union or Member State law to which the Controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;

(3) For reasons of public interest in the area of public health pursuant to Article 9(2)(h) and (i) and Article 9(3) EU-GDPR;

(4) For archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes pursuant to Article 89(1) EU-GDPR, to the extent that the right referred to in section a) is likely to render impossible or seriously prejudice the achievement of the purposes of such processing; or

(5) For the assertion, exercise or defense of legal claims.

e.    Right to information

If the Customer has asserted the right to rectification, erasure or restriction of processing vis-à-vis the Controller, the Controller is obliged to inform all recipients to whom the personal data concerning the Customer have been disclosed of this rectification or erasure of the data or restriction of processing, unless this proves impossible or involves a disproportionate effort.

He/she shall have the right vis-à-vis the Controller to be informed about these recipients.

f.    Right to data portability

The Customer has the right to receive the personal data concerning him, which he has provided to the Controller, in a structured, common and machine-readable format. In addition, he has the right to transfer this personal data, which has been provided to the Controller, to another responsible party without hindrance by the Controller, provided that:

(1) The processing is based on consent pursuant to Art. 6 para. 1 sentence 1 lit. a EU-GDPR or Art. 9 para. 2 lit. a EU-GDPR or on a contract pursuant to Art. 6 para. 1 sentence 1 lit. b EU-GDPR and

(2) The processing is carried out with the aid of automated procedures.

In exercising this right, the Customer also has the right to obtain that the personal data concerning him or her be transferred directly from the Controller to another Controller, insofar as this is technically feasible. Freedoms and rights of other persons may not be affected by this.

The right to data portability shall not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.

g.    Right of objection

The Customer has the right to object at any time, on grounds arising from their particular situation, to the processing of personal data relating to them which is carried out on the basis of Article 6 (1) (e) or (f) EU-GDPR; this also applies to profiling based on these provisions.

The Controller shall no longer process the personal data relating to the Customer unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Customer, or the processing serves to assert, exercise or defend legal claims.

The Customer has the possibility, in connection with the use of information society services - notwithstanding Directive 2002/58/EC - to exercise his right to object by means of automated procedures using technical specifications.

h.    Right to revoke the declaration of consent under data protection law

The Customer has the right to revoke his declaration of consent under data protection law at any time. The revocation of the consent shall not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

i.    Right to complain to a supervisory authority

Without prejudice to any other administrative or judicial remedy, the Customer shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his place of residence, place of work or place of the alleged infringement, if he is of the opinion that the processing of personal data relating to him violates the EU-GDPR.

Competent supervisory authority for the Controller is:

Bavarian State Office for Data Protection Supervision (BayLDA).

Promenade 27

91522 Ansbach

The supervisory authority to which the Customer has submitted a complaint shall inform the Customer of the status and results of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 EU-GDPR.

If the Customer has any queries, the data protection officer appointed by the Controller will be happy to answer them at any time.

Do you have any questions? We’re happy to help!
SZ Auszeichnung Krisensicherste Unternehmen 2025