1. Name and contact details of the data controller and the company data protection officer
This data protection information applies to data processing by:
Wilhelmshöher Allee 292
D-34131 Kassel, Germany
Tel: +49 (0)561 3166 200
Fax: +49 (0)561 3166 225
Data protection commissioner:
Friedrich-Wilhelm-Straße 148, 57074 Siegen
2. Collection and storage of personal data as well as the nature and purpose of their use
a) Visiting the website
When you visit our website www.gbz-ag.eu, the browser used on your device automatically sends information to our website’s server. This information is temporarily stored in a log file. In the course of this procedure, the following data are collected and stored, without any action on your part, until such time as it is automatically deleted:
- the IP address of the requesting computer,
- the date and time of access,
- the name and URL of the retrieved file,
- the Website from which access is made (referrer URL),
- the browser used and, if applicable, the operating system of your computer as well as the name of your Internet Access Provider.
We process the above-mentioned data for the following purposes:
- to ensure a smooth connection to the website,
- to ensure comfortable use of our website,
- to evaluate system security and stability as well as
- for other administrative purposes.
The legal basis for data processing is Article 6, Para 1, Sentence 1 (f) GDPR. Our legitimate interest is derived from the data collection purposes listed above. In no case shall we use the data collected to draw conclusions about you.
b) Using our contact form
If you have any questions, please feel free to use the contact form on our website. To allow us to learn who the request came from and to enable us to answer it, we require the following information: surname, street, postcode, city and a valid email address. Further information can be provided voluntarily.
Data processing for the purpose of contacting us is based on your voluntary consent in accordance with Article 6, Para. 1, Sentence 1(a) GDPR.
The personal data collected by us for the use of the contact form will be automatically deleted after completion of your request.
3. Disclosure of data
Your personal data are not transferred to third parties for purposes other than those listed below.
We share your personal information with third parties only if:
you have given express consent to this in accordance with Article 6, Para. 1, Sentence 1(a) GDPR,
the disclosure pursuant to Article 6, Para. 1, Sentence 1(f) GDPR is required to assert, exercise or defend legal claims and there is no reason to assume that you have a predominantly legitimate interest in not disclosing your data,
there is a legal obligation to disclose data in accordance with Article 6, Para. 1, Sentence 1(c) GDPR, and
this is legally permissible and required in accordance with Article 6, Para. 1, Sentence 1(b) GDPR for the settlement of contractual relationships with you.
Information is stored in the cookie, which is based on the specific terminal used. However, this does not mean that we are immediately aware of your identity.
Furthermore, to optimise user-friendliness, we also use temporary cookies that are stored on your device for a specified period of time. If you visit our site again to take advantage of our services, it will automatically recognise that you have previously visited our site and will recognise the inputs and settings you have made to save you from having to enter them again.
The data processed via cookies is required for the purposes mentioned in order to safeguard our legitimate interests as well as those of third parties in accordance with Article 6, Para. 1, Sentence 1(f) GDPR.
Most browsers accept cookies automatically. You can configure your browser, however, so that no cookies are stored on your computer or a notification appears before a new cookie is created. Disabling cookies completely, however, may mean that you cannot use all the features of our website.
5. Analysis tools
a) Tracking tools
The tracking measures listed below and used by us are based on Article 6, Para. 1, Sentence 1(f) GDPR. With the tracking measures to be used, we want to ensure a needs-based design and the continuous optimisation of our website. On the other hand, we use the tracking measures to statistically record the use of our website and to evaluate it for the purpose of optimising our services. These interests are to be regarded as justified within the meaning of the aforementioned provision.
The respective data processing purposes and data categories can be found in the corresponding tracking tools.
b) Google Analytics1
For the purpose of customising and continually optimising our website, we use Google Analytics, a web analytics service provided by Google Inc. (https://www.google.com/intl/en/about/) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, hereinafter referred to as “Google”). In this context, pseudonymised usage profiles are created and cookies (see Section 4) are used. The information generated by the cookie about your use of this website such as
- browser type/version,
- operating system,
- referrer URL (the previously visited page),
- host name of the accessing computer (IP address),
- time of server request,
are transmitted to a Google server in the US and stored there. The information is used to evaluate the use of the website, to compile reports on website activity and to provide other services related to website activity and Internet usage for the purposes of market research and needs-based design of this website. This information may also be transferred to third parties if required by law or if third parties process the data by proxy. Under no circumstances will your IP address be merged by Google with any other data. The IP addresses are stored anonymously, which means they cannot be assigned (IP masking).
You can prevent the installation of cookies by setting the browser software accordingly; however, we would point out that in this case not all features of this website may be fully exploited.
You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=en).
As an alternative to the browser add-on, especially for browsers on mobile devices, you can prevent the collection of data by Google Analytics by clicking on this link. An opt-out cookie will be set that will prevent the future collection of your data when you visit this website. The opt-out cookie applies only to this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again.
For more information about privacy related to Google Analytics, see Google Analytics Help (https://support.google.com/analytics/answer/6004245?hl=en).
c) Google Adwords Conversion Tracking
To statistically record the use of our website and to evaluate it for the purpose of optimising our website, we also use Google Conversion Tracking. In doing so, Google Adwords will set a cookie (see Section 4) on your computer if you have reached our website via a Google ad.
These cookies expire after 30 days and are not used for personal identification. If the user visits certain pages of the Adwords customer's website and the cookie has not yet expired, Google and the customer can recognise that the user clicked on the ad and was redirected to this page.
Every Adwords customer receives a different cookie. Cookies cannot be tracked via the websites of Adwords customers. The information gathered using the conversion cookie is used to generate conversion statistics for Adwords customers who have opted for conversion tracking. Adwords customers can see the total number of users who clicked on their ad and were redirected to a conversion tracking tag page. However, they do not receive information that personally identifies users.
6. Plugins and tools
This site uses the mapping services of Google Maps via an API. This is provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
To use the features of Google Maps, it is necessary to save your IP address. This information is usually transmitted to, and stored on, a Google server in the United States. The provider of this site has no influence over this data transfer.
The use of Google Maps is in the interest of attractively presenting our online services and enabling the places we have indicated on the website to be easily found. This constitutes a legitimate interest within the meaning of Article 6, Para. 1(f) GDPR.
7. Rights of the data subject
You have the right:
- in accordance with Article 15 GDPR, to request information about the personal data we process. In particular, you can request information about the purposes of the processing, the categories of personal data, the categories of recipient to whom your data have been or will be disclosed, the planned storage period, the right to rectification, deletion, restriction of processing or objection, the existence of the right to complain, the source of your data, if not collected by us, and the existence of automated decision-making including profiling and, where appropriate, meaningful information about the details of same;
- in accordance with Article 16 GDPR, to demand the immediate correction of incorrect personal data stored with us or to demand its completion;
- in accordance with Article 17 GDPR, to demand the deletion of personal data stored with us, unless processing is required for exercising the right to freedom of expression and information, for fulfilling a legal obligation, for reasons of public interest or for the assertion, exercise or defence of legal claims;
- according to Article 18 GDPR, to demand that the processing of your personal data be restricted if you dispute the accuracy of the data, the processing is unlawful, you reject its deletion and we no longer need the data, you however require the data to assert, exercise or defend legal claims or you have objected to the processing in accordance with Article 21 GDPR;
- in accordance with Article 20 GDPR, to receive the personal data you provided to us in a structured, standard and machine-readable format or to request transmission to another responsible person;
- according to Article 7, Para. 3 GDPR, to revoke your previous consent to us at any time. This means that we are no longer allowed to continue processing the data based on this consent and
- you have the right to complain to a supervisory authority in accordance with Article 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or work or of our registered office.
8. Right of objection
If your personal data are processed based on legitimate interests in accordance with Article 6, Para. 1, Sentence 1(f) GDPR, you have the right to file an objection against the processing of your personal data in accordance with Article 21 GDPR, provided that there are reasons for this arising from your particular situation or that the objection is directed against direct mail. In the latter case, you have a general right of objection, which is implemented by us without the need to specify any particular situation.
If you would like to exercise your right of revocation or objection, please send an e-mail to firstname.lastname@example.org
9. Data security
We use the widespread SSL (Secure Socket Layer) method within the site visit, in conjunction with the highest level of encryption supported by your browser. This is generally 256-bit encryption. If your browser does not support 256-bit encryption, we will use 128-bit v3 technology instead. You can see whether a single page of our website is encrypted by looking for a locked key or lock symbol in the lower status bar of your browser.
We also take appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or total loss, destruction or against unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.
10. Updating and changing this Data Protection Policy
This Data Protection Policy is up-to-date and valid as of May 2018.
It may be necessary to change this Data Protection Policy due to further development of our website and its services or due to changed legal or official requirements. The current Data Protection Policy can be viewed and printed on the website at any time at https://www.gbz-ag.eu.
1 Data protection authorities require a contract data processing agreement to be concluded in order to use Google Analytics. A template is available from Google at http://www.google.com/analytics/terms/en.pdf