Data protection

Privacy statement

Introduction

As the site operator, Hesse GmbH & Co. KG (hereinafter: “we”) is the data controller responsible for processing the personal data of the website’s users. Our contact data can be found on the website’s site notice and the contact partner for questions regarding the processing of personal data is noted in this privacy statement.

We take the protection of your privacy and private data very seriously. We collect, store and use your personal data in compliance with the contents of this privacy statement and the applicable legal provisions on data protection, in particular the European General Data Protection Regulation (GDPR) and national provisions on data protection.

With this privacy statement, we would like to inform you about the scope and purpose of processing personal data in connection with using the website.

Personal data

Personal data is information about an identified or identifiable natural person. This includes all information about your identity, such as your name, email address or postal address. Information that cannot be traced back to your person (such as statistical details or the number of website users) is not considered to be personal information.

Generally speaking, you can use our website without disclosing your identity or providing personal data. In such cases, only information about your visit to our website will be collected. Some of the services offered, however, require your personal data to be collected. We will then generally only process this data for the purpose of using the website, in particular to present the requested information. When collecting personal data, only data which is necessary will be requested as mandatory. Moreover, further details may be given voluntarily. We will indicate whether fields are mandatory or voluntary. We will inform you of the individual details in the corresponding section of this privacy statement.

There will be no automatic decision-making on the basis of the personal data collected through use of the website.

Processing personal information

Your details will be stored by us on specially protected servers within the European Union. These protect your data from loss, destruction, access, changes or distribution through a range of technical and organisational measures. Access to your data is only possible by a few authorised persons. They are responsible for the technical, commercial or editorial management of the servers. Despite regular checks, it is not possible to ensure total protection against all risks. Y

our personal data will be transmitted over the internet under encryption. We use an SSL-encryption (secure socket layer) to transmit the data.

Passing on personal data to third parties

We generally only use your personal information to render the services you request. Insofar as external third party contractors are used in the context of rendering services, they will also only have access to your data for the purpose of rendering services. We ensure adherence to the legal provisions on data protection by taking technical and organisational measures and oblige our external contractors to do the same.

Furthermore, we do not pass your data on to third parties without your express consent, especially not for advertising purposes. Your personal data will only be passed on when you have personally consented to such or insofar as we are required or entitled to do so due to legal provisions and/or regulatory or judicial orders. This applies in particular to the provision of information for the purpose of prosecution, averting danger or to enforce intellectual property rights.

Legal basis for data processing

If we obtain consent to process your personal data, article 6, para. 1 lit. a) GDPR will serve as the legal basis for data processing.

Insofar as we process your personal data because this is necessary to fulfil a contract or for quasi contractual relations, article 6, para. 1 lit. b) GDPR will serve as the legal basis for data processing.

Insofar as we process your personal data to fulfil a legal obligation, article 6 para. 1 lit. c) GDPR will serve as the legal basis for data processing.

Article 6 para. 1 lit. f) GDPR will further be considered as a legal basis for data processing if the processing of your personal data is required to uphold one of our company’s or a third party’s legitimate interests, wherein your interests, fundamental rights and fundamental freedoms do not require the protection of personal data.

Throughout this privacy statement, we will inform you about which legal basis is applicable for the processing of your personal data.

Data erasure and storage period

We generally erase or block your personal data once the purpose for storage no longer applies. Storage may nonetheless occur if required for any legal provisions to which we are subject, such as legal retention periods or documentation obligations. In such cases, we erase or block your personal data once the relevant provisions no longer apply.

Use of our website

Information about your computer

Each time you access our website, we collect the following information about your computer, regardless of whether you have registered: your computer’s IP address, your browser’s request and the time of access. Furthermore, the status and data volumes transferred will be collected in the context of your visit. We also collect product information and information about the browser version used, as well as information about the computer’s operating system. We also collect information about the referrer website used to access our website. Your computer’s IP address will therefore only be stored for the duration of your visit to our website, following which it will be erased or anonymised in a shortened version. The remaining data will be stored for a limited period. We use this information to operate the website, in particular, in order to detect and rectify errors, determine the website’s capacity and to make adjustments or improvements. Our legitimate interest in data processing for these purposes is in accordance with article 6 para. 1 lit. f) GDPR.

Use of cookies

As with many websites, our website uses cookies. Cookies are small text files, which are stored on your computer and save specific settings and data in exchange with our website and your browser. A cookie usually contains the name of the domain from which it was sent, as well as information about the age of the cookie and an alphanumerical identifier.

Cookies allow us to recognise your computer and provide any presets to you immediately. Cookies help us to improve the website and offer you a better and more customised service. Our legitimate interest in data processing for this is in accordance with article 6 para. 1 lit. f) GDPR.

The cookies which we use are so-called session cookies, which are automatically erased at the end of your browser session. Occasionally, cookies with longer storage periods may also be used in order to provide your presets and preferences for the next time you visit our website.

Most browsers are configured so as to automatically accept cookies. You can nonetheless deactivate cookies at any time, or configure your browser to inform you as soon as a cookie is sent. Moreover, it is possible to manually delete already stored cookies in your browser settings. Please be aware that under certain circumstances, our website may be restricted or not functional at all if you decline the storage of cookies or delete the required cookies.

Google Analytics

We use Google Analytics for statistical analysis. Google analytics is a website analysis service, provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94034, USA (“Google“). Google Analytics uses so-called “cookies”, text files stored on your computer that allow analysis of your use of the website. The information created by the cookie on how you use this website is generally sent to and stored on a Google server in the USA. However, where IP anonymisation is activated on this website, your IP address is shortened beforehand by Google within Member States of the European Union or in other states party to the Treaty on the European Economic Area. The full IP address is only sent to and stored on a Google server in the USA in exceptional circumstances. Google will use this information on behalf of the operator of this website to assess how it is used, to compile reports into the website activities and to provide the website operator with additional services associated with the use of the website and the internet. The IP address of your browser passed under Google Analytics is not included with other data from Google. You can prevent the storage of cookies by adjusting the settings in your browser software; we must point out however that in this event, not all functions of this website can be used to their full extent. In addition, you can prevent Google from gathering the data created by the cookie, relating to your use of the website (including your IP address), as well as the processing of this data by Google by downloading and installing the following browser plug-in http://tools.google.com/dlpage/gaoptout?hl=de.

For further information on this, see http://tools.google.com/dlpage/gaoptout?hl=de or http://www.google.com/intl/de/analytics/privacyoverview.html (general information on Google Analytics and data protection). We would like to point out that Google Analytics includes the code " anonymizeIp();" on our website, in order to anonymise IP addresses by erasing the final octet. Due to the protective measures implemented (anonymisation and the possibility to object), we believe that the processing of data in order to optimise our website constitutes a legitimate interest in data processing, in accordance with article 6 para. 1 lit. f) GDPR.

Hotjar

We use Hotjar for statistical analysis. Hotjar is a web analysis service, provided by Hotjar Ltd, Level 2, St Julians Business Centre 3, Elia Zammit Street, 3155 St Julians STJ, Malta (“Hotjar“). Hotjar uses cookies in order to analyse the use of our website. The information created by the cookie on how you use this website is generally sent to and stored on a Hotjar server in Ireland. Website visitors receive a simple user ID, which can be reassigned upon future visits. The users’ IP addresses are hidden before they are stored. The final octet of the IP address is then set to 0, so that the full IP address is not collected. The first three octets of the IP address are only used to determine the geographical location of the visitor. Hotjar will use this information on behalf of the operator of this website to assess how it is used, to compile reports into the website activities and to provide the website operator with additional services associated with the use of the website and the internet.

If you do not wish for Hotjar to collect your data, you can deactivate it here: https://www.hotjar.com/legal/compliance/opt-out.

For further information, see https://www.hotjar.com/legal/policies/privacy or https://www.hotjar.com/legal/compliance/gdpr-commitment (general information on Hotjar and data protection).

Due to the protective measures implemented (anonymisation and the possibility to object), we believe that the processing of data in order to optimise our website constitutes a legitimate interest in data processing, in accordance with article 6 para. 1 lit. f) GDPR.

Registration

You can register to use our online website. In connection with the registration, you are required to provide us with certain data, such as your name, address and email address. In addition to this, we collect the date and time of registration and your IP address. In connection with the registration process, we obtain your consent to use the data. You have the benefit of not having to enter this data every time you use the website or make an order and you can benefit from the use of our customer portal.

The legal basis for processing the data for registration is consent, in accordance with article 6 para. 1 lit. a) GDPR. Insofar as you register with us to fulfil or arrange a contract, an additional legal basis for processing the data is article 6 para. 1 lit. b) GDPR.

The mandatory information requested in connection with registration is required in order to fulfil or create a contract for specific services with us. You are, however, not obligated to register and you can, for example, make an order as a guest. In this case, you will have to enter all of the information required to make a contract for every order.

Upon registration, a customer account will be generated for you. The data in the customer account will be stored by us for as long as there is an active customer relationship. If no activity takes place over a period of three years, the customer relationship status will be set to inactive. You can request the erasure of your customer account at any time.

Order processing

We only use your personal information for orders within our company and related companies, as well as companies who are tasked with processing the order.

Storage and passing on data during orders

To process orders, we work together with various companies who are responsible for the processing of payment and logistics. We thereby ensure that our partners also uphold the legal provisions on data protection. Therefore we provide your address data (name and address) to the relevant transportation company, so that they can deliver the product to you. The legal basis for this is article 6 para. 1 lit. b) GDPR. It is necessary to process your personal data in order to fulfil our contract with you.

The data will only be stored by us for as long as is required for the fulfilment of the contract. Moreover, we store this data for the legally required duration so as to fulfil post-contractual obligations and legal trade and fiscal retention periods. This retention period generally lasts 10 years from the end of the relevant calendar year.

Processing order payments, Paypal, instant transfer

Depending on the selected payment method, processing payments for orders may involve the use of a service provider.

For payments by credit card, the required data, such as your name, address and purchase date will be sent to the relevant credit card company.

For Paypal payments, you will be directed to Paypal’s website through a link. This involves the processing of your personal data. This includes your name, address, email address and potentially also your telephone number and account or credit card data. Please pay attention to the general terms and conditions, user conditions and data protection policy held by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg on the website www.paypal.com.

For payments by instant transfer, you will redirected to the website Sofortüberweisung, a service provided by Sofort GmbH, part of Klarna Bank AB (publ), Sveavägen 46111 34 Stockholm, Sweden. This involves the processing of your personal data. This includes your name, address, email address and potentially also your telephone number and account or credit card data. Please pay attention to the general terms and conditions, user conditions and data protection policy held by Klarna, which can be found at https://www.klarna.com.

The legal basis for payment processing is article 6 para. 1 lit. b) GDPR. It is necessary to process your personal data in order to fulfil our contract with you and you may choose your preferred payment method.

The data will only be stored by us for as long as is required for the fulfilment of the contract. Moreover, we store this data for the legally required duration so as to fulfil post-contractual obligations and legal trade and fiscal retention periods. This retention period generally lasts 10 years from the end of the relevant calendar year.

Communicating with us

You can get in touch with us in a number of ways, such as by using the contact form on our website. Furthermore, you can stay regularly up-to-date with our email newsletter.

Contact form

If you would like to use the contact form on our website, we will collect the personal data provided in the contact form, such as your name and email address. We also store your IP address, as well as the date and time of your query. We only process the data transmitted through the contact form in order to answer your query or address your issue.

You can personally decide what information to transmit using the contact form. The legal basis for processing your data is consent, in accordance with article 6 para. 1 lit. a) GDPR.

Once we have resolved your matter, the data will then be stored for the event that you have any further queries. You may request the erasure of the data at any time, otherwise it will be erased once the matter has been fully resolved; legal retention periods, however, remain unaffected.

Newsletter

When you subscribe to our newsletter, your email address will be used for advertising purposes until you unsubscribe. In connection with this, you will receive regular information on current issues by email, as well as emails on certain occasions, such as during special campaigns. The emails may be personalised and customised based on the information we hold about you.

To subscribe to our newsletter and insofar as you have not provided us with your written consent, we will use the so-called double-opt-in procedure, whereby we will only send you a newsletter by email once you have explicitly confirmed in advance that you would like us to send it. We will then send you an email notification and ask that you click on a link contained in this email to confirm that you would like to receive our newsletter.

The legal basis for processing your data is consent, in accordance with article 6 para. 1 lit. a) GDPR, if you have explicitly subscribed to the newsletter. Within the framework of the legal provisions, you may also receive our newsletter without having given your explicit consent because you have ordered goods or services from us and we have obtained your email address in connection with this, whereby you have not objected to receiving information by email. In this case, the legal basis is our legitimate interest to transmit direct advertising, in accordance with article 6 para. 1 lit. f) GDPR.

If you do not wish to receive a newsletter from us anymore, you can revoke the consent you once provided at any time with future effect. Alternatively, you can object to receiving future newsletters, without incurring costs other than the costs for transmission, according to the basic rates. Simply follow the unsubscribe link contained in each newsletter or send a message to us or our data protection officer.

Social Media

You can find links to the social network Facebook, the career networks Xing and LinkedIn and the video hosting site YouTube on our website. The links are indicated by the respective logo of the provider.

By clicking on the links, the corresponding social media websites will be opened. This privacy statement does not apply to these. Details on the relevant provisions for these can be found in the privacy statements for each provider; see:

Facebook: http://www.facebook.com/policy.php

Instagram: https://help.instagram.com/155833707900388

Xing: https://www.xing.com/privacy

LinkedIn: https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv

YouTube: https://www.google.de/intl/de/policies/privacy/

Before visiting the respective links, no personal information will be transmitted to the providers. Your visit to the linked sites is similarly the basis for the respective provider’s data processing.

Your rights and contacts

We strongly believe that it is important to explain the processing of your personal data in the most transparent way possible and to inform you of your applicable rights. If you would like more detailed information or if you wish to exercise your applicable rights, you can contact us at any time so that we can take care of the matter.

Data subject rights

You have a wide range of rights regarding the processing of your personal data. Firstly, you have an extensive right to be informed and, if necessary, you can demand the rectification and/or erasure or blocking of your personal data. You can also request the restriction of processing and you have a right to object. With regards to the personal data transmitted to us by you, you also have the right to data portability.

If you wish to assert one of your rights and/or obtain more information about this, please contact our customer service department. Alternatively, you can also contact our data protection officer.

Revoking consent and objecting

Any consent that you have previously given can be revoked at any time with future effect. By revoking consent, the legality of any data processing conducted up until the point of revocation remains unaffected. Your contact partners for this are our customer service department and data protection officer.

If the processing of your personal data is not based on your consent but rather on another legal basis, you can object to the data processing. Your objection will result in the data processing being inspected and potentially stopped. You will be informed of the results of the inspection and, insofar as the data processing is to be continued, you will receive more information about why the processing of data is permitted.

The data protection officer and contact details

We have appointed an external data protection officer, who can support us in matters regarding data protection. You can contact them at any time. For questions regarding how we handle personal data or for further information on the legal issues surrounding data protection, our data protection officer and his team are happy to provide assistance:

Bechtle GmbH, Piepersberg 42, D-42653 Solingen

Internet: www.bechtle.com

If you would like to contact our data protection officer personally by email, you can also reach him at Peter.Feil(at)Bechtle.com.

Appeals

If you believe that our processing of your personal data is not in compliance with this privacy statement or the applicable provisions on data protection, you have the right to appeal to a supervisory authority. You can appeal to our data protection officer. The data protection officer will then inspect the matter and inform you about the result of the inspection.

Further information and amendments

Links to other websites

Our website may contain links to other websites. These links are generally marked as such. We have no influence over the extent to which the linked websites uphold the provisions on data protection. We therefore recommend that you also read the other websites’ privacy statements.

Amendments to this privacy statement

The date of this privacy statement will be stated (below). We retain the right to amend this privacy statement at any time with future effect. In particular, amendments are made for technical adjustments to the website or changes to the legal provisions on data protection. The currently valid version of the privacy statement is always available on the website. We recommend that you read about amendments to this privacy statement on a regular basis.

Date of this privacy statement: May 2018

For another option for the browser add-on or within browsers on mobile devices, please click this link, to prevent Google Analytics from collecting data for this website (the Opt Out will only work in the browser and only for this domain). During this process, an opt-out cookie will be stored on your device. If you delete your cookies in this browser, you will need to click this link again.