of Nordbrand Nordhausen GmbH
This website is operated by Nordbrand Nordhausen GmbH. In the following we inform you about the collection of personal data when you use this website. Personal data is all data which can be related to you personally, e.g. name, address, e-mail addresses, user behaviour.
Your data will be collected, processed and used in accordance with the provisions of the German Telemedia Act (Telemediengesetz, TMG) and data protection law, in particular the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) and the General Data Protection Regulation (GDPR).By means of this data protection declaration we inform about the collection of personal data on and via our website from the data subject in accordance with Art. 13 GDPR.
1. COLLECTION OF PERSONAL DATA FOR INFORMATIONAL USE
(1) If you use the website purely for information purposes, i.e. if you do not log on to, register, or provide us with any other information to use the website, we do not collect any personal data, apart from data which your browser sends to enable you to visit the website. The purpose of this data collection is to enable you to visit the website and to ensure that the website functions properly. In addition, the data serves us to optimize the website and to ensure the security of our information technology systems. This is:
- IP address
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- Data volume transmitted
- Website from which the request comes
- Operating system and its interface
- Language and version of the browser software.
(2) In addition, when you use the website, cookies will be stored on your computer. Cookies are small text files which are stored on your hard drive, are allocated to the browser used by you and through which certain information is sent to the body which places the cookie (in this case us). A cookie typically contains the name of the domain from which the cookie originates, the “lifetime” of the cookie, and a value, normally a unique randomly-generated number. Cookies cannot execute any programmes or transmit viruses to your computer. The purpose of the use is to make our website more user friendly and more effective. Some elements of our website require that the browser can be identified even after a page change.
- Transient cookies (temporary use) are deleted automatically when you close the browser. These include in particular the session cookies. These store a so-called session ID, with which various requests by your browser can be assigned to the shared session. As a result, your computer can be recognized when you return to the website. Session cookies are deleted when you log out or close your browser.
- Persistent cookies (use for a limited time) are automatically deleted after a predetermined time, which can vary depending on the cookie. You can delete these cookies any time in the security settings of your browser.
- Cookies in connection with third-party services, as described below.
- Flash cookies used are not recorded by your browser, but by your Flash plugin. These cookies store the necessary data regardless of the browser you are using and have no automatic expiration date. If you do not wish Flash cookies to be processed, you must install an appropriate add-on.
- Web beacons are electronic signs (also called "Clear GIFs" or "Web Bugs") that allow us to count the number of users who have visited the website.
You can configure your browser settings as you wish and, e.g., refuse the acceptance of third-party or all cookies. Information on the management and deletion of cookies as well as corresponding instructions for common browsers are also available at www.meine-cookies.org. Please note, however, that you then may not be able to use all the functions of this website.
(3) This information is stored separately from any data that may further be stored by us. In particular, the cookie data is not linked to your other data that may be transmitted.
2. COLLECTION OF PERSONAL DATA FOR PERSONALISED USE
(1) In addition to the use of our website purely for information purposes, we also offer a range of services which you can use if you are interested. For this purpose, you usually have to provide additional personal data which we use to provide the respective service. When you have the option of providing additional voluntary information, this is identified accordingly. Only the personal data which is necessary for your use of the website and/or the performance of a contract concluded with us or which you provide yourself is collected, processed and used by us. This concerns in particular master data and user data which may possibly be transmitted via forms on our website:
- Name (consisting of salutation, title, first name, surname and gender)
- Telephone number
- Fax number
- E-mail address
- Date of birth
- User's registration and login data
- User’s bank details
- VAT identification number (optional)
(2) Inventory data and user data are used by us as necessary in order to establish, provide the content of, amend or terminate a contractual relationship with you, in order to meet our contractual obligations, for login by the user on the website, and in order to contact you if you wish or if this is necessary within the scope of the contractual relationship or permitted by law.
The personal data will, with the exception of the data collected by the third-party providers stated below, be stored and processed within the European Union.
3. ERASURE DATES
Inventory data is deleted two years after the termination of the contractual relationship at the end of the calendar year, unless it needs to be stored for a longer period and this is permitted by law.
4. ANONYMOUS STATISTICAL ANALYSIS OF THE USER DATA
We have the right to create user profiles using a pseudonym for purposes of advertising, market research or to design the website to meet the needs of users, unless you object. In particular, we analyse the user data anonymously for statistical purposes in order to design the website to meet the needs of users. You can object to the use of your personal data by sending us a corresponding notification.
5. USE OF GOOGLE ANALYTICS
(1) This website uses Google Analytics, a web analysis service provided by Google Inc. (“Google”). Google Analytics uses “cookies”, text files which are stored on your computers and allow an analysis of the use of the website. The information produced by the cookie on your use of this website will be transmitted to and stored on a Google server in the USA. In the event of IP anonymisation being activated on this website, your IP address will however be shortened beforehand within member states of the European Union or in other states signed up to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA, where it will be shortened. Google will use this information on behalf of the operator of this website to analyse your use of the website, to compile reports on the website activities and perform further services related to the use of the website and internet for the website operator.
(2) The IP address transmitted by your browser while using Google Analytics will not be combined with other data held by Google.
(3) You may prevent cookies from being stored with an appropriate setting in your browser software; we point out, however, that in this case you will not have full use of all of the functions on this website.
(4) You may also prevent data generated by the cookie and relating to your use of the website (including your IP address) being collected and processed by Google by downloading and installing the browser plugin available at the link:
(5) This website uses Google Analytics with the extension “_anonymizeIp()”. As a result IP addresses are only processed in shortened form in order to prevent a direct link to an individual.
6. SOCIAL MEDIA PLUGINS AND SERVICES OF THIRD PARTIES
A. Use of social media plugins
(1) We currently use the following social media plugins: Facebook, Google+, Twitter and Instagram. We use the so-called 2-click solution. This means that when you visit our website, initially no personal data is passed onto the provider of these plugins. You can identify the provider of the plugin by the marking on the greyed-out box with the first letter. Personal data will only be transmitted if you click on one of the plugins: By activating the plugin, data is sent automatically to the respective provider where it is stored (in the case of US providers in the USA). We have no influence over the data collected and data processing procedures, and do not know the full extent of the data collected, the purpose or the retention periods. As the provider collects the data in particular via cookies, we recommend that you delete all cookies via your browser’s security settings before clicking on the greyed-out box.
(2) When you activate a plugin, the provider of the plugin is informed that you have accessed the corresponding subpage of our website. In addition, the data stated under 1.(1) of this policy is transmitted, whereby in the case of Facebook and Xing, according to the respective providers only an anonymised IP is collected in Germany. This happens regardless of whether you have an account with this provider and are logged into it. If you are logged in with the provider, this data will be assigned directly to your account. If you click on the activated button and e.g. link to the site, the provider also stores this information in your user account and officially informs your contacts of this. If you do not want the data to be assigned to your profile with the provider, you have to log out before activating the button.
(3) The provider stores this data as usage profiles and uses this for the purpose of advertising, market research and/or to design the website to meet the needs of users. Such an analysis is done in particular (including for users who are not logged in) to provide appropriate advertising and in order to inform other users of the social network of your activities on our website. You have the right to object to the creation of these user profiles, whereby you have to contact the respective provider in order to exercise this right.
(4) Further information on the purpose and scope of the collection of data and its processing by the respective providers
can be found in the data privacy policies of these providers listed below. These will also provide you with further information on your rights in this respect and settings options to protect your privacy.
(5) Addresses of the respective providers and URL with their data privacy policies:
a) Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA; www.facebook.com/policy.php.
b) Google Inc., 1600 Amphitheater Parkway, Mountainview, California 94043, USA; https://www.google.com/policies/privacy/partners/?hl=de.
c) Twitter, Inc., 1355 Market St, Suite 900, San Francisco, California 94103, USA; twitter.com/privacy.
d) Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA; https://help.instagram.com/155833707900388/
B. Integration of the services of third parties
(1) We have integrated YouTube videos into our website; these are stored on www.YouTube.com and can be played directly from our website. These are all integrated in “enhanced data protection mode”, i.e. no data about you as a user will be transmitted to YouTube if you do not play the videos. Only when you play the videos will the data stated in Para. 2 be transmitted. We have no influence over this data transmission. We have also integrated content from the following third-party providers on this website: Google Maps.
(2) When you visit the website, the third-party provider will be informed that you have accessed the corresponding subpage of our website. The data stated under 1.(1) of this policy is transmitted. This happens regardless of whether this third-party provider has provided you with a user account which you are logged into, or if there is no user account. If you are logged in with the plugin provider, this data will be assigned directly to your account. If you do not want the data to be assigned to your profile with the third-party provider, you have to log out before activating the button.
(3) The third-party provider stores this data as usage profiles and uses this for the purpose of advertising, market research and/or to design the website to meet the needs of users. Such an analysis is done in particular (including for users who are not logged in) to provide appropriate advertising. You have the right to object to the creation of these user profiles, whereby you have to contact the respective third-party provider in order to exercise this right.
(4) Further information on the purpose and scope of the collection of data and its processing by the third-party providers can be found in the data privacy policies of these third-party providers listed below. These will also provide you with further information on your rights in this respect and settings options to protect your privacy.
(5) Addresses of the respective providers and URL with their data privacy policies:
Google Inc., 1600 Amphitheater Parkway, Mountainview, California 94043, USA; https://www.google.com/policies/privacy/partners/?hl=de.
8. SUBCONTRACTORS AND RECIPIENTS OF PERSONAL DATA
In the course of processing personal data we use subcontractors and conclude contracts with these contract data processors in accordance with the requirements of Art. 28 GDPR.
The subcontractor which is used to host the website is Timme Hosting GmbH & Co. KG, Ovelgönner Weg 43, 21335 Lüneburg, Germany.
9. PROTECTION OF PERSONAL DATA
We take technical and organisational measures in accordance with the requirements of Art. 32 GDPR to protect the user's personal data. All of our employees who are involved in the processing of personal data are under obligation to maintain data secrecy. The user’s personal data will be encrypted by HTTPS when it is transmitted to the website.
10. LEGAL BASIS
In accordance with Art. 13 GDPR, we inform you of the legal basis of our data processing.
- Insofar as we obtain the consent of the data subject for the processing of personal data, Art. 6 para. 1 lit. a GDPR serves as the legal basis.
- In the processing of personal data required for the performance of a contract to which the data subject is a party, Article 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
- Insofar as the processing of personal data is required to fulfil a legal obligation to which our company is subject, Art. 6 para. 1 lit. c GDPR serves as the legal basis.
- The legal basis for the temporary storage of data and log files is Art. 6 para. 1 lit. f GDPR.
- The legal basis for the processing of personal data using technically necessary cookies is Art. 6 para. 1 lit. f GDPR. The legal basis for the processing of personal data using cookies for analytical purposes is Art. 6 para. 1 lit. f GDPR GDPR.
- After your registration for our newsletter we save your e-mail address for the purpose of sending you the newsletter. The legal basis is Art. 6 para. 1 sentence 1 lit. a GDPR.
- If processing is necessary to safeguard a legitimate interest of our company or a third party and if the interests, fundamental rights and freedoms of the data subject do not outweigh the first-mentioned interest, Art. 6 para. 1 letter f GDPR serves as the legal basis for processing.
If the processing of personal data is based on Article 6 I lit. f GDPR, it is in our legitimate interest to conduct our business for the well-being of all our employees and our shareholders.
11. NO AUTOMATED INDIVIDUAL DECISION-MAKING / NO PROFILING
We do not make automated decision making or profiling.
12. RIGHTS OF DATA SUBJECTS
The user and other data subjects may demand from us the following rights in respect of their personal data:
- Right of access by the data subject (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to erasure ('right to be forgotten') (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object (Article 21 GDPR)
- Right to revoke consent given at any time without affecting the legality of the processing carried out on the basis of the consent until revocation, if the data processing is based on consent pursuant to Art. 6 para. 1 lit. a or Article 9 para. 2 lit. a GDPR.
You also have the right to complain to a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR).
14. SERVICE PROVIDER / RESPONSIBLE BODY / CONTACT DETAILS / OBJECTION / REVOCATION OF CONSENT
The service provider in accordance with § 13 of the German Tele Media Act (Telemediengesetz, TMG), and responsible body in accordance with Art. 4 No. 7 GDPR other data protection laws and other provisions of a data protection nature in force in the Member States of the European Union is:
Nordbrand Nordhausen GmbH
Fon: +49 (0) 36 31-636-0
All requests for information, corrections and deletions, objections or revocations of consent, the assertion of the right to limit the processing or the right to data portability, as well as comments or questions by the user relating to data protection are to be sent to this address.
15. DATA PROTECTION OFFICER
Our external Data Protection Officer is Stephan Schmidt, Lawyer, of Mainz. You can reach him at datenschutzbeauftragter(at)rotkaeppchen-mumm.de or at our postal address with the addition "the data protection officer".
16. DATA PROTECTION SUPERVISORY AUTHORITY AND RIGHT TO COMPLAIN
The data protection supervisory authority responsible for us, to which any complaint about a breach of data protection law can be sent, is:
Der Hessische Datenschutzbeauftragte,
Gustav-Stresemann-Ring 1, 65189 Wiesbaden
Telefon: 0611/1408-0, Fax 0611/1408-900 oder -901,