DATA PROTECTION INFORMATION AS PER ARTICLE 13 GDPR

IDENTITY AND CONTACT DETAILS OF PARTY RESPONSIBLE/CONTROLLER

Controller as per GDPR and other data protection laws is:

ERAMON GmbH

Welserstr. 11

D-86368 Gersthofen

Germany

Phone: +49-821-2498-200

Email: datenschutz@eramon.de

 

IDENTITY AND CONTACT DETAILS OF DATA PROTECTION OFFICER

The data protection officer for the controller is

3 P Datenschutz GmbH

Stefan Leißl

Sanderstraße 47

D-86161 Augsburg

Germany

Telefon: +49 821 6508 8582

E-Mail: leissl@3-p-datenschutz.de

 

GENERAL INFORMATION REGARDING DATA PROCESSING

LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA

As required by Article 13 GDPR we hereby inform you of the legal basis on which we process data. Where the legal basis is not specifically named in the data protection notification, the following will apply: The legal basis for obtaining consent is Article 6 (1) (a) in conjunction with Article 7 GDPR. The legal basis for processing information required to perform our service obligations and carry out contractual measures, as well as information required to answer requests, is: Article 6 (1) (b) GDPR. The legal basis for processing data in order to meet legal obligations is: Article 6 (1) (c) GDPR. If processing of data is necessary to safeguard the legitimate interests of our company or a third party, and they are not overridden by the interests or fundamental rights and freedoms of the data subject, Article 6 (1) (f) GDPR applies. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6 (1) (d) GDPR is the legal basis.

DATA ERASURE AND STORAGE PERIODS

We adhere to the principles of data avoidance and data economy. We save personal data only for as long as it is required in order to achieve the specified purpose, or for the legally mandated retention periods. Personal data is routinely and in accordance with the law erased or blocked once the purpose of the storage has been achieved, or any legal retention periods have expired.

NOTE ON DATA TRANSFER TO THIRD COUNTRIES

Our website also contains tools from companies based in third countries (namely among them the USA) If these tools are activated, your personal data may be transferred to the servers of the respective companies. The level of data protection in these countries is not comparable to the level of data protection under the EU’s GDPR. This could leave your data at risk of having to be handed over for processing by government agencies of these countries for control and surveillance purposes, possibly even without giving you a right of appeal. We do not have any influence on these processing activities.

RIGHTS OF THE DATA SUBJECT

You have the right to request, free of charge, information about the source, the recipient, and the purpose for storing your personal data. You also have the right to obtain a rectification or erasure of this personal data. You can withdraw any previously given consent to the processing of your personal data at any time in the future. Furthermore, you have the right to restrict the processing of your personal data where certain conditions apply. You also have the right to lodge a complaint with a supervisory authority.

You can contact us at any time on these and on other issues relating to data protection. You will find our contact details in the imprint section.

As a data subject as per GDPR you can exercise a number of rights. The rights of the data subject as per GDPR are: the right of access by the data subject (Article 15), the right to rectification (Article 16), the right to erasure (Article 17), the right to restriction of processing (Article 18), the right to object (Article 21), the right to lodge a complaint with a supervisory authority, and the right to data portability (Article 20).

Right of withdrawal:

The processing of certain personal data requires explicit consent. You can withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Right to object:

You as the data subject have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Article 6 (1) (e) or (f) GDPR, including profiling based on those provisions. The controller will no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning yourself for such marketing, which includes profiling to the extent that it is related to such direct marketing. In these cases, personal data will also no longer be processed from the moment the objection has been raised.

Right to lodge a complaint with a supervisory authority:

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement if you consider that the processing of personal data relating to you infringes this Regulation.

Right to data portability:

If your data are processed by automated means, based on consent given, or where processing is necessary for the performance of a contract, you have the right to receive this personal data in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller, where this is technically possible.

Right of access, rectification, and erasure:

You have the right to obtain information which personal data concerning you are being processed, for which purposes, the categories, the recipients, and the period of storage. You also have the right to be informed of your right to request the rectification, erasure, or restriction of processing of personal data concerning you. You can contact us at any time on these and on other issues relating to data protection. You will find our contact details in the imprint section.

Right to restriction of processing:

You have the right to a restriction of processing of your personal data at any time, where one of the following applies:

  • You contest the accuracy of the personal data. For the period required to verify the accuracy, you have the right to demand the restriction of processing your personal data.
  • If the processing is unlawful, you have the alternative to request a restriction of their use instead of their erasure.
  • Should we no longer require your personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defense of legal claims, you can alternatively request a restriction of their processing, instead of their erasure.
  • Should you object to the processing pursuant to Article 21 (1) GDPR, you have the right to restrict the processing of your personal data, pending the verification whether the legitimate grounds of the controller override yours.

Where processing has been restricted, such personal data will, with the exception of storage, will only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person for reasons of important public interest of the Union or of a Member State.

PROVISION OF WEBSITE (WEB HOST)

When you visit our website, we automatically collect and store information in so-called server log files. This information is automatically transmitted by your browser to our server or to the server of our hosting company.

As there are:

  • IP address of the website visitor’s end device
  • Host name of the accessing computer
  • Visitor’s operating system
  • Browser type and version
  • Name of retrieved file
  • Time of server request
  • Data volume
  • Information if the retrieval was successful

We do not combine these data with other data sources.

The legal basis for processing these data is Article 6 (1) (f) GDPR. Our legitimate interest is the technically correct display and optimization of this website.

Instead of operating this website on a separate/our own server, we can also operate it on the server of an external provider (host company). All personal data collected on this website would then be stored on the servers of the host company. In addition to the data listed above, this could also include, for example, contact requests, contact data, names, website access data, meta and communication data, contract data, and other data generated via a website.

The legal basis for processing data by involving a host company is our interest in providing our website safely, fast, and efficiently (Article 6 (1) (f) GDPR). Another legal basis might be in order to meet our contractual obligations with future and existing clients (Article 6 (1) (b) GDPR). Where we have commissioned a host company, there will be a data processing agreement with this service provider.

USE OF COOKIES

Our website uses “cookies “. These are text files stored on your end devices by a web server (the server providing the web content) in order to identify this end device. They are either saved temporarily, as session cookies, for the duration of your visit to that website and erased once you leave the website, or saved permanently, as persistent cookies, on your end device, until you erase them yourself or a they are erased via an automatic erasure by your web browser.

Cookies can also be stored by third-party companies on your end device when you access our site (third-party requests). This allows us as the operator and you as the user, to access services from third-parties that are installed on this website, for example, to process payments, or cookies to play videos.

Cookies can be used for many different purposes. They can improve the functionality of a website, control the shopping basket function, or increase the safety, security and comfort of a website’s handling, as well as to analyze the number of visitors and their behavior. These cookies must be assessed regarding data protection based on their individual functions. Where they are necessary for the operation of the website and the provision of certain functions (shopping basket), or the optimization of the website (e.g. cookies to analyze the web audience), they are used on the legal basis of consent (Article 6 (1) (f) GDPR). As the website operator we have a legitimate interest in the storage of cookies to ensure the technically correct display and optimization of this website. In all other cases we will obtain prior consent from you before storing such cookies (Article 6 (1) (a) GDPR), which you can revoke at any time.

As far as cookies are used by third-party companies or for analytical purposes, we will inform you separately about this as part of this data protection notice. We will obtain your free and explicit prior consent, which you can revoke at any time.

USE OF EXTERNAL SERVICES

We use external services on our website. External services are services provided by third parties that are used on our website. This can be done for a variety of reasons, such as embedding videos or for website security. When using these services, personal data is also passed on to the respective provider. If we do not have a legitimate interest in using these services, we will obtain your consent as a visitor to our website before using them (Article 6 (1) (a) GDPR), which you can revoke at any time.

ANALYTICS

The processing of the personal data of our website visitors enables us to analyze the surfing behavior of our website visitors. By evaluating the data obtained, we are able to compile information about the use of the individual components of our website. This helps us to constantly improve our website and its user-friendliness. The analysis tools used could be used, for example, to create user profiles for the display of targeted or interest-related advertising messages, to recognize our website visitors the next time they visit our website, to measure their click/scroll behavior and downloads, to create heat maps, to recognize page views, to measure the duration of the visit or the bounce rates. It might also recognize the origin of the website visitor (city, country, from which site the visitor comes). The analysis tools help us to improve our market research and marketing.

The processing of the data is founded on the legal basis of consent (Article 6 (1) (a) GDPR). As a visitor to our website you have consented freely, explicitly, and in advance to the processing of your personal data. In the absence of any other justifying legal basis as per Article 6 (1) GDPR, we will not process your personal data in the above manner without separate consent. The same applies if and when you revoke your consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Google Analytics

We use the services of Google Analytics on our website. Provider of this service is: Google Ireland Ltd., Gordon House, Barrow Street Dublin 4, Ireland.

Using this service may result in data being transmitted to a third country (USA).

Further information can be found in the provider’s data protection information at the following URL: https://policies.google.com/privacy.

PHOTO SERVICE

We use photos of external providers to achieve an attractive presentation of our website. These photos are stored on the server of the external provider and retrieved when the page is opened; this establishes a connection to the server of the external provider and data, such as the IP address of the visitor to the website, are transmitted to the provider of the photo service.

The processing of the data is founded on the legal basis of consent (Article 6 (1) (a) GDPR). As a visitor to our website you have consented freely, explicitly, and in advance to the processing of your personal data. In the absence of any other justifying legal basis as per Article 6 (1) GDPR, we will not process your personal data in the above manner without separate consent. The same applies if and when you revoke your consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Google Photos

We use the services of Google Photos on our website. Provider for this service is: Google Ireland Ltd., Gordon House, Barrow Street Dublin 4, Ireland.

Using this service may result in data being transmitted to a third country (USA).

Further information can be found in the provider’s data protection information at the following URL: https://policies.google.com/privacy.

CONSENT MANAGEMENT

To comply with data protection requirements, our website uses a consent management tool. This tool obtains the required consent for the use of cookies or the use of external services. The consent is then saved.

The controller (operator of the website) is subject to a legal obligation which requires the processing. The legal basis for the processing is therefore Article 6 (1) (c) GDPR.

Borlabs Cookie

COOKIE CONSENT WITH BORLABS COOKIE

We use the technology of Borlabs Cookie on our website to obtain your consent to save certain cookies in your browser, and document them in compliance with data protection rules. Provider of this service is: Borlabs – Benjamin A. Bornschein, Georg-Wilhelm-Str. 17, 21107 Hamburg (hereafter referred to as Borlabs).

When accessing our website, a Borlabs cookie will be saved in your browser in which your preferences (consents and revocations) then saved.

These data are not passed on to the Borlabs provider. The recorded data are saved until you request their erasure, or erase the Borlabs cookie yourself, or the purpose for which the data were saved has been achieved. Compelling legitimate retention periods are unaffected by this. See: https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/ for Borlabs Cookie data processing information.

We use the Borlabs Cookie consent technology to ensure that we obtain the required consent for the use of cookies in compliance with the prevailing law. Legal basis for this is Article 6 (1) S. 1 (c) GDPR.

Cookie Settings

 

CONTENT DELIVERY NETWORK (CDN)

We use a Content Delivery Network (CDN) to optimize the performance and availability of our website. For this purpose, your IP address and the information on the time you visited our website will be processed by this service provider who makes this network available. All further information on data processing by this service provider can be found in their data protection information.

We base this processing on a legitimate interest (Article 6 (1) (f) GDPR). Our legitimate interest in using a content delivery network is to be able to display our website as quickly, securely, and reliably as possible.

Google Statics

We use the Google Static service on our website. Provider of this service is: Google Ireland Limited. This has its office at Gordon House, Barrow Street Dublin 4, Ireland.

Using the service may result in data being transferred to a third country (USA).

Further information can be found in the manufacturer’s data protection information at the following URL: https://policies.google.com/privacy.

Display Optimization

We use tools that serve to optimize the presentation of our website. These tools help to display the website in other languages or to make it more accessible.

The processing of the data is founded on the legal basis of consent (Article 6 (1) (a) GDPR). As a visitor to our website you agreed to the processing of your personal data through the consent you gave freely, explicitly, and in advance. In the absence of any other justifying legal basis as per Article 6 (1) GDPR, we will not process your personal data in the above manner without separate consent. The same applies if and when you revoke your consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.

WPML

We use the services of WPML on our website. Provider of this service is: OnTheGoSystems Ltd., 22/F 3 Lockhart Road, Wanchai, Hong Kong, China.

Because this service is hosted locally on the web server, no data are being transmitted to third parties.

We base this processing on a legitimate interest (Article 6 (1) (f) GDPR).

This application is required to ensure the unlimited functionality of the website. It is a language tool which is considered essential.

INTERFACE SOFTWARE

Business processes run more efficiently, faster, and with less errors when they are automated with the help of software via interfaces. In that way they can be integrated via your own website or via social media networks efficiently into the business processes. We use interface software on our website to connect various applications and to transfer personal data securely from one application to another.

The processing of the data is founded on the legal basis of consent (Article 6 (1) (a) GDPR). As a visitor to our website you agreed to the processing of your personal data through the consent you gave freely, explicitly, and in advance. In the absence of any other justifying legal basis as per Article 6 (1) GDPR, we will not process your personal data in the above manner without separate consent. The same applies if and when you revoke your consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.

Google APIs

We use the services of Google APIs on our website. Provider of this services is: Google Ireland Ltd., Gordon House, Barrow Street Dublin 4, Ireland.

Using the service may result in data being transferred to a third country (USA).

Further information can be found in the provider’s data protection information at the following URL: https://policies.google.com/privacy.

SEARCH ENGINE

To improve your reading comfort, we have installed a search engine on our website with a number of functions, so you will find the content you are looking for faster and easier.

The processing of the data is founded on the legal basis of consent (Article 6 (1) (a) GDPR). As a visitor to our website you agreed to the processing of your personal data through the consent you gave freely, explicitly, and in advance. In the absence of any other justifying legal basis as per Article 6 (1) GDPR, we will not process your personal data in the above manner without separate consent. The same applies if and when you revoke your consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.

Google

We use the services of Google on our website. Provider of this service: Google Ireland Ltd., Gordon House, Barrow Street Dublin 4, Ireland.

Using the service may result in data being transferred to a third country (USA).

Further information can be found in the manufacturer’s data protection information at the following URL: https://policies.google.com/privacy.

VIDEO/MUSIC SERVICES

To make our website varied and diverse for you, we are using audio and video files. The audio and video files are retrieved from the server of our provider, the so-called audio or video platform. In order to play an audio or video your end device will connect to the audio or video platform and transmits personal data to the provider of the audio/video service, such as your IP address, but possibly also location data, or the type of end device or browser used.

The processing of the data is founded on the legal basis of consent (Article 6 (1) (a) GDPR). As a visitor to our website you agreed to the processing of your personal data through the consent you gave freely, explicitly, and in advance. In the absence of any other justifying legal basis as per Article 6 (1) GDPR, we will not process your personal data in the above manner without separate consent. The same applies if and when you revoke your consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.

YouTube

We use the services of YouTube on our website. Provider of this service is: Google Ireland Ltd., Gordon House, Barrow Street Dublin 4, Ireland.

Using the service may result in data being transferred to a third country (USA).

Further information can be found in the manufacturer’s data protection information at the following URL: https://policies.google.com/privacy.

WEBFONTS

This page uses web fonts for a uniform display. These are provided by an external provider and loaded by the browser when the website is accessed. The provider of the web font is informed that our website was accessed from your IP address because your browser establishes a direct connection to the provider of the web font.

The processing of the data is founded on the legal basis of consent (Article 6 (1) (a) GDPR). As a visitor to our website you agreed to the processing of your personal data through the consent you gave freely, explicitly, and in advance. In the absence of any other justifying legal basis as per Article 6 (1) GDPR, we will not process your personal data in the above manner without separate consent. The same applies if and when you revoke your consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.

Google Fonts

We use the services of Google Fonts on our website. Provider of this service is: Google Ireland Ltd., Gordon House, Barrow Street Dublin 4, Ireland.

Using the service may result in data being transferred to a third country (USA).

Further information can be found in the manufacturer’s data protection information at the following URL: https://policies.google.com/privacy.

WEBSECURITY

We use tools on our website that protect us from unauthorized access, spam, and other attacks. This serves on the one hand our security, but on the other by extension, also the security of our website visitors.

We base this processing on a legitimate interest (Article 6 (1) (f) GDPR).

Our legitimate interest is to be able to ensure the security of our website and to protect ourselves from unauthorized access, spam, and other attacks.

GOOGLE RECAPTCHA

We use the services of Google Recaptcha on our website. Provider of this service: Google Ireland Ltd., Gordon House, Barrow Street Dublin 4, Ireland.

Using the service may result in data being transferred to a third country (USA).

Further information can be found in the manufacturer’s data protection information at the following URL: https://policies.google.com/privacy.

ADVERTISING

We use tools on our website that facilitate or enable the placement of advertising and analyze the success rate of the placed adverts. Advertising forms a source of income from our website. Personal data processed in the course of this are, for example, the IP address, access times, or device information.

The processing of the data is founded on the legal basis of consent (Article 6 (1) (a) GDPR). As a visitor to our website you agreed to the processing of your personal data through the consent you gave freely, explicitly, and in advance. In the absence of any other justifying legal basis as per Article 6 (1) GDPR, we will not process your personal data in the above manner without separate consent. The same applies if and when you revoke your consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.

Google DoubleClick

We use the services of Google DoubleClick on our website. Provider of this service: Google Ireland Ltd., Gordon House, Barrow Street Dublin 4, Ireland.

Using the service may result in data being transferred to a third country (USA).

Further information can be found in the manufacturer’s data protection information at the following URL: https://policies.google.com/privacy.

CONTACT FORM

You can contact us using the form provided on our website. When using this contact form, we will ask you for certain information, in particular a description of the reason for your contact, and the way you would like us to contact you. These are mandatory fields and have to be completed when using our contact form.

The legal basis for responding to contact requests is the fulfillment of a contract or the performance of pre-contractual measures. There may also be a legitimate interest to maintain business relationships, or to answer your request for other reasons.

The processing of the data is founded on the legal basis of consent either of Article 6 (1) (f) GDPR or Article 6 (1) (b) GDPR.

We save personal data only until your request was answered to your satisfaction, and provided no other retention periods (e.g. relating to tax or commercial law) apply.

CONTACT VIA TELEPHONE OR EMAIL

As required by law, we provide you with an email address and a phone number on our website. Data submitted by these means are automatically stored to enable the processing of the requests or to contact the person making the request. Data obtained in this way will not be passed to third parties without your consent.

Where contact was made by phone or email for pre-contractual or contractual purposes, the processing of personal data is founded on the legal basis of Article 6 (1) (b) GDPR. The processing of personal data obtained in the context of any other contact is based on our legitimate interest (Article 6 (1) (f) GDPR).

HANDLING OF APPLICANT DATA

You have the opportunity to send us your application for example by post, online, or by email. Personal data obtained in the course this are stored and processed to help us decide if an offer of employment should be made.

The processing of the data is founded on the legal basis of consent of Article 6 (1) (b) GDPR and Article 6 (1) (a) GDPR, as far as consent was given. As far as German law applies, processing is also based on § 26 BDSG (para 26 of the German Data Protection Law – Initiation of employment). You can revoke your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.

If your application leads to employment, we will store the data collected to process the employment procedures based on Article 6 (1) (b) GDPR. If no employment results from your application, the data will be stored on the legal basis of Article 6 (1) (f) GDPR for up to 6 months after the application process was closed. We have a legitimate interest in storing this data, in order to defend ourselves against any lawsuits or allegations. Where consent was given, the data will be stored longer on the legal basis of Article 6 (1) (a) GDP. You can revoke your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.

APPLICANT POOL

If no employment results from an application, the applicant can be entered in our applicant pool. All details from the application are stored, so the suitable person can be contacted as and when vacancies arise.

Data is only stored to the applicant pool after consent on the legal basis of Article (1) (a) GDPR has been obtained. This consent can be revoked at any time, which will result in the erasure of the relevant data, assuming no other legal reasons for retention exist. The data will be erased latest two years after consent was given. The withdrawal of consent does not affect the lawfulness of processing based on consent before it.