Duty to provide information in accordance with the General Data Protection Regulation
Data protection is particularly important to us. As of May 25, 2018, the General Data Protection Regulation (GDPR) will apply in all EU member states. With the following information, we would like to give you an overview of how we process your personal data. Even though data protection is not new to us, there are still some new provisions that have prompted us to provide this information.
Important: You do not have to do anything.
This information is intended to explain your rights as a data subject with regard to data protection. Nothing will change in your existing contracts with us. As was already the case in the past, we only use your data to conclude and fulfill contracts with you as our customer, to be able to fulfill the warranty and to implement your wishes and requirements.
The data protection laws oblige us to provide you with some information on data protection.
Who is responsible for data processing?
We are the so-called controller for the processing of personal data:
Company: Ernst Strassacker GmbH & Co. KG Kunstgiesserei
represented by: Mrs. Edith Strassacker
Address: Staufenecker Straße 19, 73079 Süßen
Contact details: 07162/16-0 / email@example.com
You can reach our data protection officer at
For what purposes is your data processed and what is the legal basis that allows us to process it?
a. Contract initiation, support and fulfillment (Art. 6 para. 1 b GDPR).
In order to prepare and execute a contract with you (including provision of the service or delivery and invoicing), we require personal data from you. This includes, for example, your name and address as well as data for the payment of invoices. We may process this data in accordance with Art. 6 para. 1b GDPR.
There are also statutory retention periods that we must comply with. The legal basis for this is e.g. § 257 HGB, § 147 AO on the basis of Art. 6 para. 1 c GDPR.
b. Data processing for legitimate interest (Art. 6 para. 1 f GDPR)
The legislator expressly allows us to process further data for our legitimate interests. We do this, among other things, to improve and develop services and products in order to be able to offer you a customized approach with tailor-made offers and products.
- to conduct market and opinion research or have it conducted by market and opinion research institutes. This provides us with an overview of the transparency and quality of our products, services and communication and enables us to align and design these in the interests of our customers
- Determination of creditworthiness and payment default risks via credit agencies (e.g. Schufa, Creditreform) for online contracts
- Asserting legal claims
- Defense in legal disputes
- Investigation of criminal offenses
- To determine your address
- To use your data anonymously for analysis purposes
- Data processing due to legal requirements (Art. 6 para. 1 c GDPR) or in the public interest (Art. 6 para. 1 e GDPR)
As a company, we are subject to various legal and official obligations (e.g. tax laws, German Commercial Code) that make it necessary to process your data in order to comply with the law.
Do we pass the data on to other parties?
Internally, i.e. within our company, we pass on the data to those persons who need it to fulfill contractual and legal obligations. This also applies to service providers and vicarious agents that we use in order to carry out our tasks properly. We will only pass on your data to third parties if we have a clear legal basis for doing so, if statutory provisions require this, if you have given your consent or if we are otherwise authorized to do so.
The following recipients may receive data from us: Shipping service providers, debt collection service providers, financial and tax authorities, police and investigating authorities (with existing legal basis), official bodies (if transmission is required by law), insurance companies, banks and credit institutions (payment processing), market partners, auditors, and Internet agencies, opinion research institutes, printing service providers, credit agencies, lawyers, auditors.
Transfers that we are legally obliged to make are made in accordance with the applicable legal provisions.
Transfers on the basis of Article 6(1)(f) GDPR (legitimate interests of the controller) may only take place if this is necessary to safeguard our legitimate interests or those of third parties in accordance with the GDPR, and our data protection officer will also check whether your interests or fundamental rights and freedoms do not prevail. If this is the case, the data will remain with us and will not be passed on.
How long do we store the data?
Your data will be processed for the first time from the time it is collected, insofar as you or a third party provide it to us. We delete your personal data when the contractual relationship with you has ended, all mutual claims have been fulfilled and there are no other statutory retention obligations or statutory justifications for the storage. These include retention obligations under the German Commercial Code (HGB) and the German Fiscal Code (AO). We will delete your personal data at the latest after expiry of the statutory retention obligations, which is usually 10 years after the end of the contract.
We process data on the basis of your consent (Art. 6 para. 1a GDPR)
If you have given us your consent to process your data for specific purposes (e.g. for marketing purposes), this processing is lawful. You can withdraw your consent at any time with effect for the future.
Data transfer to third countries
Data is not currently transferred to third countries.
Does profiling take place?
No profiling takes place.
What rights do you have in connection with the processing of your data?
You have the following rights with regard to your personal data:
- Right to information about your stored personal data (Art. 15 GDPR),
- Right to rectification if the stored data concerning you is incorrect, outdated or otherwise inaccurate (Art. 16 GDPR)
- right to erasure if the storage is unlawful, the purpose of the processing has been fulfilled and the storage is therefore no longer necessary or you have withdrawn your consent to the processing of certain personal data (Art. 17 GDPR)
- Right to restriction of processing if one of the conditions listed in Art. 18 para. 1 a) to d) GDPR is met (Art. 18 GDPR),
- Right to transfer the personal data concerning you that you have provided (Art. 20 GDPR)
- Right to withdraw consent, whereby the withdrawal does not affect the lawfulness of processing based on consent before its withdrawal (Art. 7 (3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
Right to object pursuant to Art. 21 GDPR
If we process data to protect our legitimate interests, you have the right to object to this processing at any time on grounds relating to your particular situation. This also includes the right to object to processing for advertising purposes. To do so, please contact us directly at the above address of the data controller.
Collection, processing and use of personal data
You can visit our website without providing any personal data. Even if the visit is made via newsletter links, we only store access data without personal reference, such as
- the name of your Internet service provider
- the page from which you visit us
- the name of the requested file
This data is evaluated solely to improve our offer and does not allow any conclusions to be drawn about your person.
We collect, store and process your data for the order processing of your purchase and any subsequent warranty processing as well as for advertising purposes. Personal data is collected if you provide it to us voluntarily when ordering goods or opening a customer account or registering for the newsletter.
The session cookies (also called session cookies) are deleted after you close your browser.
Your payment data is encrypted during the ordering process and transmitted via the Internet. We use technical and organizational measures to secure our website and other systems against loss, destruction, access, modification and dissemination of your data by unauthorized persons. You should always treat your access information confidentially and close the browser window when you have finished communicating with us, especially if you share your computer with others.
Credit check and scoring
If you have given us your express consent, we may obtain credit information on the basis of mathematical-statistical procedures from the agencies listed below. For this purpose, we transmit the personal data required for a credit check to these agencies and use the information received on the statistical probability of a payment default for a balanced decision on the establishment, execution or termination of the contractual relationship. You can revoke this consent at any time with effect for the future. This may mean that we can no longer offer you certain payment options.
Creditreform Boniversum GmbH
This website uses the "Google Analytics" service offered by Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA) to analyze website usage by users. The service uses "cookies" - text files that are stored on your end device. The information collected by the cookies is usually sent to a Google server in the USA and stored there.
IP anonymization is used on this website. The IP address of users is truncated within the member states of the EU and the European Economic Area. This truncation eliminates the personal reference of your IP address. As part of the contract data agreement that the website operators have concluded with Google Inc., Google Inc. uses the information collected to compile an analysis of website usage and website activity and provides services related to internet usage.
You have the option of preventing cookies from being stored on your device by making the appropriate settings in your browser. There is no guarantee that you will be able to access all functions of this website without restrictions if your browser does not allow cookies. You can also use a browser plugin to prevent the information collected by cookies (including your IP address) from being sent to Google Inc. and used by Google Inc. The following link will take you to the corresponding plugin: https://tools.google.com/dlpage/gaoptout?hl=de
Alternatively, you can prevent Google Analytics from collecting data about you within this website by clicking on this link. By clicking on the above link, you download an "opt-out cookie". Your browser must therefore allow the storage of cookies. If you delete your cookies regularly, you will need to click on the link again each time you visit this website.
You can find more information on the use of data by Google Inc. here: https://support.google.com/analytics/answer/6004245?hl=de
We and our data protection experts will be happy to answer any questions you may have about data protection compliance.
Your Ernst Strassacker GmbH & Co. KG Art Foundry