Information on Data Protection when Using the Website
Below, we will inform you about collection of personal data when you use our website. Personal data are any data that permit a conclusion to you personally, e.g. your name, address, email addresses, user behaviour. We process your personal data under observation of the provisions of the European General Data Protection Regulation (GDPR), the NEW Federal Data Protection Act (Bundesdatenschutzgesetz; BDSG), and any other laws relevant for processing of personal data.
I. Processing of Personal Data
(1) We generally only collect the data required by law or contract, required for entering into a contract, or that we are allowed to collect based on our legitimate interests. There will be no negative consequences if the data are not provided. However, not providing them may make, e.g., communication with you more difficult or cause delays.
(2) Your personal data are always protected from loss and abuse by appropriate technical and organisational measures. They will be stored in a secure operating environment that is not accessible to the public. If you move on our website, your personal data will be encrypted at transmission by way of transport layer security technology (TLS). This means that communication between your computer and our servers takes place using a recognised encryption method.
(3) We will transmit some of your data to third parties and/or contract processors (e.g. IT service providers) who support us in processing personal data, e.g. by helping us meet our statutory obligations. If third parties are contract processors at the same time, we have selected and charged them with care. Contract processes are bound to our instructions and regularly inspected by us.
III. Contact Details of the Data Protection Officer
Our data protection officer can be reached by:
Beauftragter für den Datenschutz
c/o extrutec GmbH
IV. Legal Basis of Processing Activities
The legal basis for processing activities result from the provisions of Art. 6 GDPR, with our processing activities mainly taking place
- based on consent, point (a) of the first sentence of Art. 6(1) GDPR
- to comply with a contract, point (b) of the first sentence of Art. 6(1) GDPR
- to comply with legal obligations, point (c) of Art. 6(1) GDPR
- to protect legitimate interests, point (f) of Art. 6(1) GDPR
V. Your Rights as a Data Subject
(1) You have the following rights towards us regarding the personal data referring to you under the GDPR:
- Right to information, Art. 15 GDPR
- Right to rectification, Art. 16 GDPR
- Right to erasure (“right to be forgotten”), Art. 17 GDPR
- Right to restriction of processing, Art. 18 GDPR
- Right to data portability, Art. 20 GDPR
(2) You also have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you, based on Art. 22 GDPR, provided that the decision is not
- necessary for entering into or performance of a contract between you as the data subject and us as the controller,
- authorised by provisions of Union or Member State law to which we are subject as the controller and which also lays down suitable measures to safeguard your rights and freedoms and your legitimate interests of the data subject or made with your express consent.
(3) If you believe that processing of the personal data concerning you violates any provisions under data protection law, you have the right to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR. The right to complain may specifically be asserted before a supervisory authority of the member state of your residence or the location of the alleged violation.
VI. Your Withdrawal and Objection Rights
Your Right to Withdraw Consent
Sie haben das Recht, eine auf Grundlage von Art. 6 Abs. 1 S. 1 lit. a DSGVO erteilte Einwilligung jederzeit zu widerrufen, ohne dass dies die Rechtmäßigkeit der bisher erfolgten Verarbeitung berührt. Wenn die Einwilligung widerrufen wird, stellen wir die entsprechende Datenverarbeitung ein.
Your Right to Object at Legitimate Interests
In accordance with Art. 21 GDPR, you have the right to object to processing of personal data concerning you that are processed based on point (f) of Article 6(1) GDPR at any time for reasons that result from your particular situation. In that case, we shall no longer process the personal data except if there are verifiable compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
VII. Data Collection for Strictly Informative Use
(1) You may visit our website without providing any information concerning your person. If you use our website for information only, i.e. if you only look around on our website, we will only collect the personal data that your browser automatically submits to our server and records in log files (server log files). Anonymisation of the internet protocol address reduces personal reference.
The following data will be collected:
- Internet protocol address (anonymised)
- Date/time stamp
- Client request
- File name/path
- Server response
- Transferred data volume
- HTTP referrer (the link/page the query came from)
- Information on the client, e.g. browser/operating system
(2) Log files shall be stored in order to ensure the function of the website. We also use the data for optimisation of the website and to ensure stability and security of our information-technical systems.
(3) The legal basis for temporary storage shall be point (f) of the first sentence of Art. 6(1) GDPR, based on the legitimate interest on achieving the above purposes.
(4) We will delete any log files stored after 30 days. Storage beyond this shall only be permitted if suspect processes require longer storage. In such cases, the log files will be deleted at once when the incidents have been resolved.
(5) Collection of the data for provision of the website and recording of the data in log files is mandatory for operation of the site.
IX. Contact by Email
If you contact us by email, we will store the personal data freely provided by you in your email for the purpose of answering your query. The legal basis for processing shall be point (b) of the first sentence of Art. 6(1) GDPR if the purpose of the contact is establishing a contract, and point (f) of Art. 6(1) GDPR for the legitimate interest of contacting you. We will erase the personal data arising in this context after storage is no longer necessary and correspondence has clearly ended, or we shall restrict processing if there are any legal archiving obligations to do so. Business correspondence shall be stored for 6 years (§ 147 of the Tax Code.
(Abgabenordnung; AO), § 256 of the German Commercial Code (Handelsgesetzbuch; HGB)).
X. Bewerbungen für Stellenanzeigen auf unserer Website
(1) If you apply to us by email or mail, we will process the personal data disclosed by you (e.g. name, first name, address details, communication data, birth data, curriculum vitae, certificates, qualifications, answers to queries, and any correspondence with you that may have taken place within the context of the selection process) within the scope of our applicant selection procedure in order to assess whether you have the professional aptitude and qualification, as well as technical performance for the job you apply for. The legal basis for this results from § 26 (1) BDSG in conjunction with Art. 88 GDPR for meeting legal obligations from point (c) Art. 6 (1) GDPR.
XI. Social Media Links
(1) Our website enables you to visit our pages on the social media platforms of LinkedIn and Xing or to share them via your account. You can recognise the provider of the social media platform via the logo.
The social media logos only connect to links. This means that no personal data are automatically transferred to the social networks when visiting our website. When clicking one of the logos, the respective page will be opened in a new tab and you will be forwarded to the respective social network.
(2) Further information on the purpose and scope of data collection and processing by the social network is available in the following data protection statements of those providers as presented below. It also contains further information on your rights to that extent, as well as setting options for protecting your privacy.