General information
The protection of your personal data is important to us. We therefore want to inform you as simply and precisely as possible about the ways to contact us and about the data concerning data subjects.
First, you will find information on how to contact our data protection officer and on options for encrypted communication. We then introduce the legal and technical terms used in the further course of this policy. This is followed by an overview of the rights of the data subject and the details of the controller. Finally, we describe the technologies and services used and how we handle them.
1. Contact details of the data protection officer
Our preferred means of contact is e-mail. However, you are also welcome to contact the data protection officer by post or by telephone.
If you would like to encrypt your e-mail to our data protection officer, we recommend reading the following section.
Notes on enquiries:
If you send an enquiry by e-mail during regular business hours, we will confirm receipt of your message on the same day. If you do not receive a confirmation, please contact us by telephone.
If you send an enquiry by post, we will send you a confirmation of receipt on the day of delivery, but no later than one day after delivery. If you do not receive a confirmation, please contact us by telephone.
For enquiries by telephone, please use the telephone number of our data protection partner, eye-i4 GmbH, directly.
2. Terms in a legal context
Before we address legal matters in the further course of this policy, we would first like to introduce the relevant terms:
2.1 EU GDPR (also referred to as GDPR)
The term EU GDPR (hereinafter also GDPR) refers to the General Data Protection Regulation. It is a regulation of the European Union that governs how personal data may be processed. For information purposes, the legal text of the GDPR can be viewed via the following link:
EU GDPR (legal text on the website of the European Union).
2.2 Controller
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
2.3 Personal data and data subject
Personal data means any information relating to an identified or identifiable natural person (hereinafter data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
2.4 Processing
Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
2.5 Restriction of processing
Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.
2.6 Processor
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
2.7 Recipient
Recipient means a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
2.8 Third party
Third party means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
2.9 Consent
Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
2.10 Personal data breach
Personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
2.11 Data concerning health
Data concerning health means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.
2.12 Enterprise
Enterprise means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
2.13 Supervisory authority
Supervisory authority means an independent public authority which is established by a Member State pursuant to Article 51 GDPR.
2.14 Relevant and reasoned objection
Relevant and reasoned objection means an objection to a draft decision as to whether there is an infringement of the GDPR, or whether envisaged action in relation to the controller or processor complies with the GDPR, which clearly demonstrates the significance of the risks posed by the draft decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union.
3. Terms in a technical context
Before we address technical matters in the further course of this policy, we would first like to introduce the relevant terms:
3.1 Filing system
Filing system means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
3.2 Cookies
Cookies are text files that a website stores on your device via your browser. These text files may be intended to implement technical functions, such as a shopping cart, or to identify your visitor behaviour. For this purpose, the text files may contain identifiers and additional information.
You can prevent cookies from being stored in the browser of your device. If cookies are disabled, there may be technical restrictions when using the website.
3.3 Server logs
Server logs are log files created by the web server that document access to a website. A log entry can contain a wide range of information, e.g. the time of access, the browser type, the visitor's IP address, etc.
3.4 Referrer
The referrer is the website from which a visitor accessed the controller's website. The referrer can, for example, be read from server logs.
4. Rights of the data subject
The rights of data subjects arise from the GDPR and from the respective national data protection laws. If you wish to exercise your rights, please contact our data protection officer using the contact details provided at the beginning of this policy. Below we would like to inform you of your rights arising from the GDPR, in particular Chapter 3:
If you have any questions or require information, you can contact our external data protection officer at any time. The contact details are:
| EYE-I4 GmbH Oliver Offenburger, M.Sc. Data Protection Department |
|
| Address: | Mönchweilerstraße 12 78048 Villingen-Schwenningen Germany |
| Phone: Fax: |
+49 7721 69724 00 +49 7721 69724 01 |
| E-mail: | datenschutz@eisenmann-druckguss.de |
| Website: | https://eye-i4.de |
Notes on enquiries:
If you send an enquiry by e-mail during regular business hours, we will confirm receipt of your message on the same day. If you do not receive a confirmation, please contact us by telephone.
If you send an enquiry by post, we will send you a confirmation of receipt on the day of delivery, but no later than one day after delivery. If you do not receive a confirmation, please contact us by telephone.
For enquiries by telephone, please use the telephone number of our data protection partner, eye-i4 GmbH, directly.
2. Terms in a legal context
Before we address legal matters in the further course of this policy, we would first like to introduce the relevant terms:
2.1 EU GDPR (also referred to as GDPR)
The term EU GDPR (hereinafter also GDPR) refers to the General Data Protection Regulation. It is a regulation of the European Union that governs how personal data may be processed. For information purposes, the legal text of the GDPR can be viewed via the following link:
EU GDPR (legal text on the website of the European Union).
2.2 Controller
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
2.3 Personal data and data subject
Personal data means any information relating to an identified or identifiable natural person (hereinafter data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
2.4 Processing
Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
2.5 Restriction of processing
Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.
2.6 Processor
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
2.7 Recipient
Recipient means a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
2.8 Third party
Third party means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
2.9 Consent
Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
2.10 Personal data breach
Personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
2.11 Data concerning health
Data concerning health means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.
2.12 Enterprise
Enterprise means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
2.13 Supervisory authority
Supervisory authority means an independent public authority which is established by a Member State pursuant to Article 51 GDPR.
2.14 Relevant and reasoned objection
Relevant and reasoned objection means an objection to a draft decision as to whether there is an infringement of the GDPR, or whether envisaged action in relation to the controller or processor complies with the GDPR, which clearly demonstrates the significance of the risks posed by the draft decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union.
3. Terms in a technical context
Before we address technical matters in the further course of this policy, we would first like to introduce the relevant terms:
3.1 Filing system
Filing system means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
3.2 Cookies
Cookies are text files that a website stores on your device via your browser. These text files may be intended to implement technical functions, such as a shopping cart, or to identify your visitor behaviour. For this purpose, the text files may contain identifiers and additional information.
You can prevent cookies from being stored in the browser of your device. If cookies are disabled, there may be technical restrictions when using the website.
3.3 Server logs
Server logs are log files created by the web server that document access to a website. A log entry can contain a wide range of information, e.g. the time of access, the browser type, the visitor's IP address, etc.
3.4 Referrer
The referrer is the website from which a visitor accessed the controller's website. The referrer can, for example, be read from server logs.
4. Rights of the data subject
The rights of data subjects arise from the GDPR and from the respective national data protection laws. If you wish to exercise your rights, please contact our data protection officer using the contact details provided at the beginning of this policy. Below we would like to inform you of your rights arising from the GDPR, in particular Chapter 3:
4.1 Right to information
The data subject has the right to receive information about the personal data stored about him or her, both where the data have been collected from the data subject and where they have not been obtained from the data subject. This is governed by Chapter 3, Art. 13 and 14 GDPR.
4.2 Right of access
The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed; where that is the case, he or she has the right of access to the personal data and to further information pursuant to Art. 15 GDPR.
4.3 Right to rectification
The data subject has the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.
Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
4.4 Right to erasure
The data subject has the right to obtain from the controller the erasure of personal data concerning him or her without undue delay, and the controller has the obligation to erase personal data without undue delay where one of the grounds set out in Art. 17 GDPR applies.
4.5 Right to restriction of processing
The data subject has the right to obtain from the controller restriction of processing where one of the conditions set out in Art. 18 GDPR applies.
4.6 Notification obligation
The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Art. 16, Art. 17 (1) and Art. 18 GDPR to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
The controller shall inform the data subject about those recipients if the data subject requests it.
4.7 Right to data portability
The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
4.8 Right to object
The data subject has the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
4.9 Right to lodge a complaint with a supervisory authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your habitual residence or place of work or of the controller's registered office.
Supervisory authority
Our competent supervisory authority is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
(Landesbeauftragte für den Datenschutz und die Informationsfreiheit), Stuttgart
5. Controller pursuant to Art. 24 GDPR
5.1 Details of the controller
The controller pursuant to Art. 24 GDPR is:
Eisenmann Druckguss GmbH
Rietheimer Str. 49
78050 Villingen-Schwenningen
Germany
Further details about the controller can be found in the Imprint.
6. Web technologies used
6.1 Server logs
If you use the website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. When you view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security (the legal basis is Art. 6 (1) sentence 1 lit. f GDPR):
When you use our website, cookies are stored on your computer. You can configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that you may then not be able to use all functions of this website.
This website uses the following types of cookies, the scope and functionality of which are explained below:
6.2.1 Transient cookies
Transient cookies are deleted automatically when you close your browser. These include, in particular, session cookies. They store a so-called session ID, which can be used to assign various requests from your browser to the same session. This allows your computer to be recognised when you return to our website. Session cookies are deleted when you log out or close your browser.
6.3 Google Font API
This site uses so-called web fonts provided by Google for the uniform display of fonts. When you open a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.
For this purpose, the browser you are using must connect to Google's servers. This enables Google to know that our website was accessed via your IP address. Google Web Fonts are used in the interest of a uniform and appealing presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR.
If your browser does not support web fonts, a standard font from your computer will be used.
Further information on Google Web Fonts can be found on this page and in Google's privacy policy.
6.4 Font Awesome web font
This site uses so-called web fonts provided by Fonticons, Inc. for the uniform display of fonts. When you open a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.
For this purpose, the browser you are using must connect to the servers of Fonticons, Inc. This enables Fonticons, Inc. to know that our website was accessed via your IP address. Web fonts are used in the interest of a uniform and appealing presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR.
If your browser does not support web fonts, a standard font from your computer will be used.
Further information on Font Awesome can be found on this page and in the privacy policy of Fonticons, Inc.
7. Storage period
Unless specifically stated otherwise, we only store personal data for as long as is necessary to fulfil the purposes pursued.
In some cases, the law requires personal data to be retained, for example under tax or commercial law. In these cases, we only continue to store the data for these statutory purposes; it is not processed in any other way and is deleted once the statutory retention period has expired.
8. Disclosure to third parties
Your personal data will not be transferred to third parties for purposes other than those listed below.
We only disclose your personal data to third parties if:
The data subject has the right to receive information about the personal data stored about him or her, both where the data have been collected from the data subject and where they have not been obtained from the data subject. This is governed by Chapter 3, Art. 13 and 14 GDPR.
4.2 Right of access
The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed; where that is the case, he or she has the right of access to the personal data and to further information pursuant to Art. 15 GDPR.
4.3 Right to rectification
The data subject has the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.
Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
4.4 Right to erasure
The data subject has the right to obtain from the controller the erasure of personal data concerning him or her without undue delay, and the controller has the obligation to erase personal data without undue delay where one of the grounds set out in Art. 17 GDPR applies.
4.5 Right to restriction of processing
The data subject has the right to obtain from the controller restriction of processing where one of the conditions set out in Art. 18 GDPR applies.
4.6 Notification obligation
The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Art. 16, Art. 17 (1) and Art. 18 GDPR to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
The controller shall inform the data subject about those recipients if the data subject requests it.
4.7 Right to data portability
The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
4.8 Right to object
The data subject has the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
4.9 Right to lodge a complaint with a supervisory authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your habitual residence or place of work or of the controller's registered office.
Supervisory authority
Our competent supervisory authority is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
(Landesbeauftragte für den Datenschutz und die Informationsfreiheit), Stuttgart
5. Controller pursuant to Art. 24 GDPR
5.1 Details of the controller
The controller pursuant to Art. 24 GDPR is:
Eisenmann Druckguss GmbH
Rietheimer Str. 49
78050 Villingen-Schwenningen
Germany
Further details about the controller can be found in the Imprint.
6. Web technologies used
6.1 Server logs
If you use the website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. When you view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security (the legal basis is Art. 6 (1) sentence 1 lit. f GDPR):
- anonymised IP address,
- date and time of the request,
- time zone difference to Greenwich Mean Time (GMT),
- content of the request (specific page),
- access status/HTTP status code,
- amount of data transferred in each case,
- website from which the request originates (referrer),
- browser,
- operating system and its interface,
- language and version of the browser software.
When you use our website, cookies are stored on your computer. You can configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that you may then not be able to use all functions of this website.
This website uses the following types of cookies, the scope and functionality of which are explained below:
- transient cookies,
- persistent cookies.
6.2.1 Transient cookies
Transient cookies are deleted automatically when you close your browser. These include, in particular, session cookies. They store a so-called session ID, which can be used to assign various requests from your browser to the same session. This allows your computer to be recognised when you return to our website. Session cookies are deleted when you log out or close your browser.
6.3 Google Font API
This site uses so-called web fonts provided by Google for the uniform display of fonts. When you open a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.
For this purpose, the browser you are using must connect to Google's servers. This enables Google to know that our website was accessed via your IP address. Google Web Fonts are used in the interest of a uniform and appealing presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR.
If your browser does not support web fonts, a standard font from your computer will be used.
Further information on Google Web Fonts can be found on this page and in Google's privacy policy.
6.4 Font Awesome web font
This site uses so-called web fonts provided by Fonticons, Inc. for the uniform display of fonts. When you open a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.
For this purpose, the browser you are using must connect to the servers of Fonticons, Inc. This enables Fonticons, Inc. to know that our website was accessed via your IP address. Web fonts are used in the interest of a uniform and appealing presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR.
If your browser does not support web fonts, a standard font from your computer will be used.
Further information on Font Awesome can be found on this page and in the privacy policy of Fonticons, Inc.
7. Storage period
Unless specifically stated otherwise, we only store personal data for as long as is necessary to fulfil the purposes pursued.
In some cases, the law requires personal data to be retained, for example under tax or commercial law. In these cases, we only continue to store the data for these statutory purposes; it is not processed in any other way and is deleted once the statutory retention period has expired.
8. Disclosure to third parties
Your personal data will not be transferred to third parties for purposes other than those listed below.
We only disclose your personal data to third parties if:
- you have given your express consent to this pursuant to Art. 6 (1) sentence 1 lit. a GDPR,
- the disclosure is necessary pursuant to Art. 6 (1) sentence 1 lit. f GDPR for the establishment, exercise or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in your data not being disclosed,
- there is a legal obligation to disclose the data pursuant to Art. 6 (1) sentence 1 lit. c GDPR, or
- this is legally permissible and necessary pursuant to Art. 6 (1) sentence 1 lit. b GDPR for the performance of contractual relationships with you.