Data Privacy Policy for Customers and Prospective Customers

A.    Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is

Elatec GmbH

Zeppelinstr. 1

82178 Puchheim, Germany

Phone: +49 89 552 9961 0

Fax: +49 89 552 9961 129

E-mail: info-rfid@elatec.com

(hereinafter referred to as Elatec).

The person appointed as Data Protection Officer at the controller can be reached at:

datenschutz@hjp.de

Phone: +49 6841 9816 0

Fax: +49 6841 9816 29

Please do not hesitate to contact our Data Protection Officer if you have questions relating to processing of your personal data and exercising of your rights in accordance with the General Data Protection Regulation (GDPR).

B.    Purposes of and legal basis for processing of your data

We process personal data as part of customer relationships if that is required for concluding, performing or preparing a contract. The relevant legal basis for that is Article 6 (1) point (a) GDPR, if Elatec carries out processing operations where it obtains consent to process data for a specific purpose. If personal data has to be processed for the performance of a contract to which the data subject is a party, such as is the case with processing operations required to supply goods or provide another service or consideration, the legal basis for that is Article 6 (1) point (b) GDPR. The same applies to processing operations required for performance of steps prior to entering into a contract, such as is the case when we receive inquiries about our products and services from customers or prospective customers. If our company is subject to a legal obligation that requires processing of personal data, such as to fulfill tax-related obligations, the basis for that is Article 6 (1) point (c) GDPR. In addition, processing operations may be based on authorization under Article 6 (1) point (f) GDPR. Such processing operations are permissible if they are necessary to safeguard legitimate interests pursued by Elatec or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.

If we are contacted (e.g. using a contact form, by e-mail, phone or social media), the user’s details are processed to handle the contact request in accordance with Article 6 (1) point (b) GDPR. Users’ details can be stored in a customer relationship management system (“CRM system”) or similar means of organizing communication.

C.    Categories of processed personal data

Elatec processes personal data concerning you which is connected with the contractual relationship. That same applies to data from prospective customers who are provided by Elatec with information on possible products and services. The categories of personal data involved here may be general information (such as names, addresses and contact data), communication relating to contracts, or the previous contract history.

D.   Sources of the processed data

The data is usually collected directly from you. That is done by you presenting us with your calling card or giving us your name and contact data. Data is collected indirectly in cases where customers’ personal data is sent to us by third parties. That is the case, for example, when a contact person at a company that is a customer of ours is named by that company. In individual cases, publicly accessible, job-related information of yours may be processed, such as data that can be obtained from a profile on professional social networking sites or the company’s website. If you pass on data of third parties to us, please make sure you have the authorization to do so and that any necessary consent for us to process the data within the meaning of this policy have been obtained from the data subject.

E.    Categories of recipient

Elatec can transfer your personal data to its affiliated companies within the meaning of Article. 4 No. 19 GDPR, provided that is permissible subject to the above purposes and legal grounds. In addition, personal data is processed on our behalf on the basis of contracts in accordance with Article 28 GDPR, in particular by hosting providers or providers of CRM systems.

Within the Elatec organization, your data is passed on to Sales and the departments tasked with handling contractual relationships.

F.     Erasure of your data

Elatec stores your personal data for as long as that is required within the meaning of the law or there is a statutory retention period for it. Inactive customer or prospective customer accounts are erased from the system on a regular basis. If data cannot be erased because that is prevented by statutory retention obligations, the data is blocked. The data can also be blocked in a first stage by means of work instructions that prohibit access to and use of the data by employees.

G.     Transfer of data to a third country

Transfer of data to a third country is not envisaged.

H.   Newsletter

We use the double opt-in procedure for subscription to our newsletter. This means that, after you have subscribed, we will send an e-mail to the e-mail address given by you asking you to confirm that you wish to receive the newsletter. If you do not confirm your subscription, your information will be blocked and finally erased automatically. We also store the IP addresses you use and the times of your subscription and confirmation. The purpose of this procedure is to demonstrate that you have subscribed and to clarify any possible misuse of your personal data (Article 6 (1) point (f) GDPR). After receiving your confirmation, we store your e-mail address for the purpose of sending the newsletter. The legal basis for that is Article 6 (1) sentence 1 point (a) GDPR. You can withdraw your consent to receiving the newsletter and cancel your subscription to it at any time. You can withdraw your consent by clicking on the link in every newsletter e-mail, on our website, or by sending an e-mail, or a message to the contact data stated in the Imprint. We point out that we analyze your user behavior when we send the newsletter. To enable such analysis, the e-mails sent contain web beacons or tracking pixels, 1x1 pixel image files which are stored on our website. As part of the analyses, we link the above data and the web beacons with your e-mail address and an individual ID. We use the data obtained in this way to create a user profile so that the newsletter can be tailored to your personal interests. As part of that, we record when you read our newsletter and what links you click on in it and use that to draw conclusions on your personal interests. We link this data with your activities on our website.

I.   Other processing for marketing purposes

We use your data to inform you about our products and services. Our marketing may comprise measures such as use of the data for addressing advertising to you, additional storage of data, comparing addresses, selection measures or advertisement scoring. Advertising is addressed to you using the contact data available to us and may include contact by electronic communication (including social media), post, phone or in person.

J.   What rights do you have?

You as a customer have – in an individual case and depending on the situation – the rights below. If you wish to exercise them, you can get in touch with Elatec or the Data Protection Officer at any time under the above contact data:

Information on and access to data: You have the right to obtain information on the person data concerning you which has been processed at Elatec and access to your personal data and/or copies of that data. That includes information on the purpose of its use, the category of data used, its recipients and persons authorized to access it and, if possible, the planned length of time for which the data will be stored or, if that is not possible, the criteria used to determine that length of time.

Rectification, erasure or restriction of processing: You have the right to obtain from Elatec without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Right to object: If processing of personal data concerning you is based on Article 6 (1) point (f) GDPR, you have the right to object, on grounds relating to your particular situation, at any time to processing of that data. We will no longer process that personal data unless Elatec demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.

Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw consent at any time, without this affecting the lawfulness of processing based on consent before its withdrawal. To do that, you can get in touch with our Data Protection Officer at any time under the above contact data.

Right to erasure: You have the right to obtain from Elatec the erasure of personal data concerning you without undue delay and Elatec has the obligation to erase personal data without undue delay where one of the following grounds applies:

  • the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
  • you object to the processing and there are no overriding legitimate grounds for the processing;
  • the personal data concerning you has to be erased for compliance with a legal obligation in Union or Member State law to which we are subject. This shall not apply if processing is required for compliance with a legal obligation which requires processing by Union or Member State law to which we are subject.

Right to restriction of processing: You have the right to obtain from Elatec restriction of processing where one of the following applies:

  • the accuracy of the personal data is contested by you, for a period enabling us to verify the accuracy of the personal data;
  • the processing is unlawful and you oppose the erasure of the personal data and request restriction of its use instead;
  • Elatec no longer needs the personal data for the purposes of processing, but it is required by you for the establishment, exercise or defense of legal claims, or you have objected to processing pending verification whether our legitimate grounds override yours.
  • Where processing of personal data concerning you has been restricted, the data shall, with the exception of storage, only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.

If you have obtained restriction of processing, you shall be informed by us before the restriction of processing is lifted.

Right to lodge complaints: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the General Data Protection Regulation (GDPR). You can also contact Elatec’s Data Protection Officer, who can be reached at:

datenschutz@hjp.de

Phone: +49 6841 9816 0

Fax: +49 6841 9816 29

I.       Requirement to provide personal data

The provision of personal data is not prescribed by law or contractually, nor are you obliged to provide personal data. However, you must provide personal data in order to conclude a contract with us. That means: If you do not provide us with personal data, we will not conclude a contractual relationship with you. Insofar as a contract has not yet been concluded, we abide by the principle of collecting as little data as possible. Nevertheless, a minimum of contact data is required to supply you with the information you requested about our products and services and to provide our service.

J.      No automated decision-making

No automated decision-making is carried out in an individual case within the meaning of Article 22 GDPR.