Privacy Policy of Hermann GmbH Co. KG (Wellendingen)
This privacy policy serves to inform the user about the nature, scope, and purposes of the collection and use of personal data by the responsible provider (Hermann GmbH Co. KG, Lehrstr. 57, 78669 Wellendingen, Email: info@hermann-drehteile.de) on this website, as well as about the rights to which they are entitled.
The legal foundations of data protection are determined by the General Data Protection Regulation (GDPR) of the European Union (EU). Any processing of personal data (e.g., name, address, email address, or telephone number of a data subject) is always carried out in accordance with these data protection regulations and the respective specific national legal provisions.
You can generally use our website without providing any personal data. If a data subject wishes to use services of our company via our website, processing of personal data may become necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we always obtain the consent of the data subject.
As the responsible party, we take the protection of your data seriously. For this reason, we take all appropriate measures to ensure the most comprehensive protection possible of personal data processed through our website. However, data transmissions over the Internet may still contain security gaps despite all measures taken, so that one hundred percent protection cannot be guaranteed. Alternatively, you can also transmit your data to us via other communication channels, e.g., by telephone or in writing to our postal address.
1. Definitions
Article 4 of the GDPR contains specific definitions that also form the basis of this privacy policy. The privacy policy should be both easy to read and understand for every user. To ensure this, we explain some of the terms used according to Art. 4 GDPR below:
- "Personal data" means any information relating to an identified or identifiable natural person (hereinafter referred to as "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- "Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- "Restriction of processing" means the marking of stored personal data with the aim of limiting their processing in the future;
- "Profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements;
- "Pseudonymization" means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;
- "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
- "Recipient" means a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
- "Third party" means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data;
- "Consent" of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
You can find the complete definitions in the relevant legal text of the GDPR.
2. Name and Contact Details of the Controller
This privacy policy applies to data processing by:
Controller: Hermann GmbH Co. KG - Präzisionsdrehteile, Lehrstr. 57, D-78669 Wellendingen, represented by the Managing Director Guido Hermann, Email: info@hermann-drehteile.de, Phone: +49 (0) 7426 51 96 0, Fax: +49 (0) 7426 51 96 30.
3. Collection and Storage of Personal Data as well as Type and Purpose of Their Use
a) When Visiting the Website
You can use our website without disclosing your identity. When you access our website, information is automatically sent to the server of our website by the browser used on your device. This information is temporarily stored in a log file. The following information is collected without your intervention and stored until automatically deleted:
- IP address of the requesting computer,
- Date and time of access,
- Name and URL of the retrieved file,
- Website from which access is made (referrer URL),
- Browser used and, if applicable, the operating system of your computer as well as the name of your access provider.
The data mentioned are processed by us for the following purposes:
- Ensuring a smooth connection setup of the website,
- Ensuring comfortable use of our website,
- Evaluation of system security and stability, and
- For other administrative purposes.
The legal basis for data processing is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest follows from the data collection purposes listed above. In no case do we use the collected data for the purpose of drawing conclusions about you.
b) When Using Our Contact Form
You can contact us at any time using a form provided on our website. It is necessary to provide your first and last name and a valid email address so that we know who the request is from and in order to respond to it. Further information, such as your telephone number, can be provided voluntarily. It is your free decision whether you want to enter this data in the context of the contact form.
The data processing for the purpose of contacting us is carried out in accordance with Art. 6 (1) sentence 1 lit. a GDPR on the basis of your voluntarily given consent.
The personal data collected by us for the use of the contact form will be automatically deleted after your request has been processed.
c) For Orders via Our Website
You can place orders on our website either as a guest without registering with us, or register in our shop as a customer for future orders. Registration has the advantage that you can log in directly to our shop with your email address and password in the case of a future order, without having to re-enter your contact and shipping details.
Your personal data is entered into an input mask and transmitted to us and stored. If you place an order via our website, we initially collect the following data both in the case of a guest order and in the case of registration in the shop:
- Title, First Name, Last Name,
- A valid email address,
- Address,
The collection of this data is carried out,
- To identify you as our customer;
- To process, fulfill, and complete your order;
- For correspondence with you;
- For invoicing;
- To handle any existing liability claims and to assert any claims against you;
- To ensure the technical administration of our website;
- To manage our customer data.
During the ordering process, your consent for the processing of this data is obtained.
The data processing is carried out based on your order and/or registration and is necessary according to Art. 6 para. 1 p. 1 lit. b GDPR for the stated purposes for the appropriate processing of your order and for the mutual fulfillment of obligations from the purchase contract.
The personal data collected by us for processing your order will be stored until the expiry of the statutory retention obligation and then deleted, unless we are obliged to store it for a longer period in accordance with Article 6 (1) sentence 1 lit. c GDPR due to tax and commercial law retention and documentation obligations (from HGB, StGB or AO) or you have consented to storage beyond this in accordance with Art. 6 para. 1 p. 1 lit. a GDPR.
4. Data Transfer
We only pass on your personal data to third parties exclusively to the service partners involved in the contract processing, such as the commissioned logistics company and the credit institution commissioned with payment matters. In cases where your personal data is passed on to third parties, however, the scope of the transmitted data is limited to the required minimum.
When paying via PayPal, credit card via PayPal, direct debit via PayPal or 'purchase on account' via PayPal, we pass on your payment data to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter 'PayPal') as part of the payment processing. PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or 'purchase on account' via PayPal. PayPal uses the result of the credit check in relation to the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is included in the calculation of the score values. For further data protection information, please refer to the PayPal Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Your personal data will not be transmitted to third parties for purposes other than those listed above.
We will only pass on your personal data to third parties if:
- You have given your express consent in accordance with Art. 6 para. 1 p. 1 lit. a GDPR,
- The disclosure is necessary for the assertion, exercise or defense of legal claims in accordance with Art. 6 para. 1 p. 1 lit. f GDPR and there is no reason to assume that you have an overriding legitimate interest in not disclosing your data,
- In the event that there is a legal obligation for the transfer pursuant to Art. 6 para. 1 p. 1 lit. c GDPR, and
- This is legally permissible and required for the processing of contractual relationships with you in accordance with Art. 6 para. 1 p. 1 lit. b GDPR.
During the ordering process, your consent for the transfer of your data to third parties is obtained.
5. Use of Cookies
We use cookies on our website to make visiting our website attractive and to enable the use of certain functions. These are small text files that your browser automatically creates and that are stored on your device (PC, laptop, tablet, smartphone, etc.) when you visit our website. Information is stored in the cookie that is related to the specific device used. However, this does not mean that we gain immediate knowledge of your identity.
Most of the cookies we use are deleted from your hard drive at the end of the browser session (so-called session cookies). Other cookies remain on your computer and allow us to recognize your computer on your next visit (so-called long-term cookies). These cookies serve to greet you with your username and eliminate the need for you to re-enter your password or fill out forms with your data on subsequent orders. These cookies are automatically deleted after a defined period of time. Our partner companies are not permitted to collect, process or use personal data via cookies through our website.
You can influence the use of cookies. Most browsers have an option to restrict or completely prevent the storage of cookies. However, we point out that the use and especially the ease of use may be limited without cookies.
The data processed by cookies is necessary for the aforementioned purposes to protect our legitimate interests and those of third parties in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR.
6. Links to Third-Party Websites
We are not responsible for the content of linked pages and expressly do not adopt the content of these pages as our own. The provider of the website to which reference was made is solely liable for illegal, incorrect or incomplete content as well as for damages resulting from the use or non-use of the information. The liability of the person who merely refers to the publication through a link is excluded. We are only responsible for external references if we have positive knowledge of them, i.e. also of any illegal or criminal content, and it is technically possible and reasonable for us to prevent their use.
7. Analysis and Tracking Tools
We use various tracking tools on our website to enable demand-oriented design and continuous optimization of the website. The tracking measures listed below and used by us are carried out on the basis of Art. 6 Para. 1 S. 1 lit. f GDPR. On the other hand, we use such measures to statistically record the usage behavior of our website and evaluate it for the purpose of optimizing our offer for you. These interests are to be regarded as legitimate within the meaning of the aforementioned regulation.
You can find out about the respective data processing purposes and data categories from the corresponding tracking tools below.
a) Google Analytics[1]
For the purpose of demand-oriented design and continuous optimization of our pages, we use Google Analytics, a web analysis service provided by Google Inc. (https://www.google.de/intl/de/about/) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter "Google"). In this context, pseudonymized usage profiles are created and cookies (see section 5) are used. The information generated by the cookie about your use of this website such as
- Browser type/version,
- Operating system used,
- Referrer URL (the previously visited page),
- Hostname of the accessing computer (IP address),
- Time of server request,
are transferred to a Google server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on website activities and to provide other services related to website use and internet use for the purposes of market research and demand-oriented design of these internet pages. This information may also be transferred to third parties if this is required by law or if third parties process this data on behalf of the company. Under no circumstances will your IP address be merged with other data from Google. The IP addresses are anonymized so that an assignment is not possible (IP masking).
You can prevent the installation of cookies by setting your browser software accordingly; however, we point out that in this case you may not be able to use all functions of our website to their full extent.
You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing a browser add-on(https://tools.google.com/dlpage/gaoptout?hl=en).
Alternatively to the browser add-on, especially for browsers on mobile devices, you can prevent data collection by Google Analytics by clicking on the aforementioned link. An opt-out cookie will be set that prevents future collection of your data when visiting our website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again.
For more information about privacy in connection with Google Analytics, please see the following link in the Google Analytics Help: https://support.google.com/analytics/answer/6004245?hl=en
b) Google AdWords Conversion Tracking
To statistically record the use of our website and to evaluate it for the purpose of optimizing our website for you, we also use Google Conversion Tracking. Google AdWords sets a cookie (see Section 5) on your computer if you have reached our website through a Google ad.
These cookies expire after 30 days and are not used for personal identification. If the user visits certain pages of the AdWords customer's website and the cookie has not yet expired, Google and the customer can recognize that the user clicked on the ad and was redirected to this page.
Each AdWords customer receives a different cookie. Cookies cannot therefore be tracked across AdWords customers' websites. The information collected using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. AdWords customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
If you do not want to participate in the tracking process, you can also refuse the required setting of a cookie - for example via browser settings that generally deactivate the automatic setting of cookies. You can also deactivate cookies for conversion tracking by setting your browser to block cookies from the domain "www.googleadservices.com". Google's privacy policy for conversion tracking can be found at the following link: https://services.google.com/sitestats/en.html
8. Social Media Plugins
We use social plugins from social networks (e.g. Facebook, Google+, Instagram) on our website based on Art. 6 para. 1 p. 1 lit. f GDPR to make our company better known through this. The underlying advertising purpose is to be regarded as a legitimate interest within the meaning of the GDPR. The responsibility for data protection-compliant operation is to be guaranteed by their respective providers. The integration of these plugins by us is done using the so-called two-click method to protect visitors to our website in the best possible way.
a) Facebook
We use social media plugins from Facebook on our website to make their use more personal. For this we use the "LIKE" or "SHARE" button. This is an offer from Facebook.
If you access a page on our website that contains such a plugin, your browser establishes a direct connection with Facebook's servers. The content of the plugin is transmitted directly from Facebook to your browser and integrated into the website.
By integrating the plugins, Facebook receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook account or are not currently logged in to Facebook. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the USA and stored there.
If you are logged in to Facebook, Facebook can directly associate your visit to our website with your Facebook account. If you interact with the plugins, for example by pressing the "LIKE" or "SHARE" button, the corresponding information is also transmitted directly to a Facebook server and stored there. The information is also published on Facebook and visible to your friends.
Facebook may use this information for the purposes of advertising, market research and tailoring Facebook pages to meet demand. Facebook creates usage, interest and relationship profiles for this purpose, e.g. to evaluate your use of our website with regard to the advertisements displayed to you on Facebook, to inform other Facebook users about your activities on our website and to provide other services associated with the use of Facebook.
If you do not want Facebook to associate the data collected via our website with your Facebook account, you must log out of Facebook before visiting my website. You can also completely prevent the loading of the Instagram plugin with add-ons for your browser, for example with the script blocker “NoScript” http://noscript.net
For information about the purpose and scope of data collection and the further processing and use of the data by Facebook, as well as your related rights and settings options for protecting your privacy, please refer to Facebook's privacy policy, which you can view at the following link: https://www.facebook.com/about/privacy/
b) Google “+1” button
Our website uses the “+1” button of the social network Google, which is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043-1351, USA. The button is labeled with a “+1”.
The “+1” button is a shorthand for “this is pretty cool” or “check this out”. The button is not used to track your visits on the web.
If a webpage of our website contains the “+1” button, your internet browser will load and display this button from the Google server. The Google server is automatically informed about the website you are visiting on our website. When displaying a +1 button, Google does not log your browser history permanently, but only for up to two weeks.
Google keeps this data about your visit stored for this period for system maintenance and troubleshooting purposes. However, this data is not structured according to individual profiles, usernames or URLs. This information is also not accessible to website publishers or advertisers. The use of this information only serves for maintenance and error correction in internal systems at Google. Your visit to a page with a +1 button is not evaluated by Google in any other way.
A further analysis of your visit to a webpage of our website with a “+1” button does not take place.
Giving a +1 itself is a public process, i.e., anyone who performs a Google search or accesses content on the web to which you give +1 can potentially see that you have given +1 to the content in question. Therefore, only give +1 if you are absolutely sure that you want to share this recommendation with the whole world.
A click on this +1 button serves as a recommendation for other users in Google's search results. You can publicly communicate that you like our website, that our website meets your approval, or that you can recommend our website. If you have registered for Google+ and are logged in, the +1 button turns blue when clicked. In addition, the +1 is added to the +1 tab in your Google profile. On this tab, you can manage your +1s and decide whether you want to make the +1 tab public.
To save your +1 recommendation and make it publicly accessible, Google collects information about the URL you recommended, your IP address, and other browser-related information via your profile. If you withdraw your +1, this information will be deleted. All +1 recommendations from you are listed on the +1 tab in your profile.
Further information and the applicable privacy policy of Google can be retrieved at https://www.google.de/intl/de/policies/privacy/. Further information from Google about the Google+1 button can be found at the link https://developers.google.com/+/web/buttons-policy
If you do not want Google to associate the data collected via our website directly with your Google+ profile, you must log out of Google+ before visiting our website. You can also completely prevent the loading of the Google plugins with add-ons for your browser, for example with the script blocker “NoScript” http://noscript.net.
c) Instagram Social Plugins
Our website uses so-called plugins (“Plugins”) from Instagram, which is operated by Instagram LLC., 1601 Willow Road., Menlo Park, CA 94025, USA (“Instagram”). The plugins are marked with an Instagram logo, for example in the form of an “Instagram camera”.
When you access a page on our website that contains such a plugin, your browser establishes a direct connection to Instagram's servers. The content of the plugin is transmitted by Instagram directly to your browser and integrated into the page. Through this integration, Instagram receives the information that your browser has accessed the corresponding page of our website, even if you do not have an Instagram profile or are not logged into Instagram. This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there.
If you are logged into Instagram, Instagram can immediately associate your visit to our website with your Instagram account. If you interact with the plugins, for example by clicking the 'Instagram' button, this information is also transmitted directly to an Instagram server and stored there. The information is also published on your Instagram account and displayed to your contacts.
For information about the purpose and scope of data collection and the further processing and use of the data by Instagram, as well as your related rights and settings options for protecting your privacy, please refer to Instagram's privacy policy https://help.instagram.com/155833707900388.
If you do not want Instagram to associate the data collected via our website directly with your Instagram account, you must log out of Instagram before visiting our website. You can also completely prevent the loading of the Instagram plugin with add-ons for your browser, for example with the script blocker 'NoScript' http://noscript.net.
d) Use of YouTube Plugins
We use the integration of videos via the provider YouTube. YouTube is operated by YouTube LLC., 901 Cherry Avenue, San Bruno, CA 94066, USA ('YouTube'). YouTube is represented by Google Inc. with headquarters at 1600 Amphitheatre Parkway, Mountain View, CA 940431, USA.
We use plugins from the provider YouTube on our websites. When you visit our internet pages that are equipped with such a plugin, a connection to the YouTube servers is established and the plugin is displayed. This transmits to the YouTube server which of our internet pages you have visited. If you are logged in as a member of YouTube, YouTube associates this information with your personal user account. When using the plugin, such as clicking the start button of a video, this information is also associated with your user account. You can prevent this association by logging out of your YouTube user account and other user accounts of YouTube LLC. and Google Inc. and deleting the corresponding cookies of the company before using our website.
For more information on data processing and privacy notices by YouTube (Google), please visit https://google.de/intl/de/policies/privacy
9. Rights of Data Subjects
You have the right:
- in accordance with Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, deletion, restriction of processing or objection, the existence of a right to complain, the origin of your data if not collected by us, as well as the existence of automated decision-making including profiling and, if applicable, meaningful information about their details;
- in accordance with Art. 16 GDPR, to demand the immediate correction of incorrect or completion of your personal data stored by us;
- in accordance with Art. 17 GDPR, to request the deletion of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defense of legal claims;
- in accordance with Art. 18 GDPR, to request the restriction of processing of your personal data, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you refuse its deletion and we no longer need the data, but you need it for the establishment, exercise or defense of legal claims or you have objected to the processing in accordance with Art. 21 GDPR;
- in accordance with Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request the transfer to another controller;
- According to Art. 7 Para. 3 GDPR, you have the right to withdraw your consent given to us at any time. This results in us no longer being allowed to continue the data processing based on this consent for the future and
- According to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.
- According to Art. 21 GDPR, you have the right to object to the processing of your personal data, provided that your personal data is processed on the basis of legitimate interests pursuant to Art. 6 Para. 1 S. 1 lit. f GDPR and if there are reasons for this arising from your particular situation or the objection is directed against direct marketing. In the latter case, you have a general right to object, which we will implement without specifying a particular situation.
If you would like to exercise your right of revocation or objection, simply send an email to: info@hermann-drehteile.de. Alternatively, you can also write to us at:
Hermann GmbH Co. KG
Lehrstr. 57
78669 Wellendingen
10. Data Security
Within the website visit, we use the common SSL procedure (Secure Socket Layer) in conjunction with the highest level of encryption supported by your browser. Usually, this is a 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can recognize whether an individual page of our website is transmitted in encrypted form by the closed key or lock symbol in the lower status bar of your browser.
We also use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
11. Currency and Amendment of this Privacy Policy
This privacy policy is currently valid and is dated February 2020.
[1] Data protection authorities require the conclusion of a data processing agreement for the permissible use of Google Analytics. Google offers a corresponding template at http://www.google.com/analytics/terms/de.pdf.