Privacy Policy
Open privacy settingsGeneral introduction:
We take the protection of your personal data very seriously and want you to feel secure when visiting our website. Our data protection practices comply, in particular, with the provisions of the EU General Data Protection Regulation, the German Federal Data Protection Act (BDSG) and the Act Regulating Data Protection and the Protection of Privacy in Telecommunications and Telemedia (TDDDG). We would like to take this opportunity to inform you about the nature, scope and purpose of the processing of your personal data. Please note in advance that this privacy policy relates solely to our websites and does not apply to third-party websites to which we provide links.
Subject matter of protection:
The subject matter of protection is personal data. This refers to all information relating to an identified or identifiable natural person (hereinafter referred to as the ‘data subject’). This includes, in particular, details that allow conclusions to be drawn about your identity (e.g. details such as your name, postal address, email address and telephone number).
Technical requirements:
In order for you to connect to our website, your browser transmits certain data to our website’s web server. This is a technical necessity to ensure that the information you have requested can be made available by the website. To enable this, your IP address, the date and time of your request and the type of operating system you are using, amongst other things, are stored and used for a maximum of 7 days. We reserve the right to store this data for a limited period to safeguard our legitimate interests, so that, in the event of unauthorised access or an attempt to cause us deliberate harm via this channel, we may trace the data back to personal data (Article 6(1)(f) of the GDPR). We will only retain or pass on this data for these purposes and no other, without first informing you and seeking your consent.
Cookies:
Cookies are small text files stored on your computer or mobile device via your browser, for example to recognise whether you visit web pages repeatedly from the same device or browser. In general, we use cookies to analyse interest in our website and to improve its user-friendliness. However, you can generally access our website without cookies.
Cookies can usually be disabled or removed using tools available in most commercial browsers. The settings must be configured separately and individually for each browser you use. The various browsers offer different functions and options for this purpose.
To be able to use our website to its full extent and with ease, you should accept those cookies that enable the use of certain functions or make the user experience more convenient.
You may consent to the use of cookies that are not strictly necessary for us, as the provider, to make our website available to you via our Cookie Consent Manager (in accordance with Section 25(1) of the TDDDG) and withdraw your consent at any time with future effect.
Midas Partners – Marketing Agency:
To support the design, implementation and evaluation of online advertising campaigns via the social media channels listed below (e.g. lead data, conversions) as well as contact enquiries via the landing page platform, the marketing agency Midas Partners Ioannidis & Steih GbR, Paulstraße 16, 42553 Velbert, has been commissioned. We have entered into a data processing agreement with the service provider in accordance with Article 28 of the GDPR.
Users of our contact form:
Our website features contact forms that can be used to get in touch electronically. To ensure the secure transmission of your data, we use a state-of-the-art encrypted connection with an SSL certificate during transmission. By clicking the ‘Send enquiry’ button, you consent to the transmission of the data entered in the form to us. We store your name and email address, and any further information you may have provided, so that we can get in touch with you and respond to your enquiry as effectively as possible. On the one hand, this enables us to offer you the service you expect from us, and on the other hand, it allows us to continuously improve our services (Article 6(1)(f) of the GDPR). You may object to the processing of your data at any time. Full details of your right to object under Article 21 of the GDPR can be found at the end of this privacy policy.
OnePage CRM:
As soon as a user has fully completed and submitted the contact form on the campaign landing page, the data entered is transferred to the CRM system of our marketing agency, Midas Partners Ioannidis & Steih GbR. From there, an email containing the prospect’s full contact details is automatically sent to us. The CRM system has no direct access to the website or CES’s tracking system.
Midas Partners uses OnePage CRM as an internal lead management system in which contact details are stored temporarily. OnePage GmbH is based at Hanauer Landstraße 172, 60314 Frankfurt am Main, Germany. Please note that, in the context described below, data may also be transferred to sub-processors in the USA or other third countries. Data transfers to third countries are carried out on the basis of the EU Commission’s Standard Data Protection Clauses in accordance with Article 46(2)(c) of the GDPR or on the basis of adequacy decisions in accordance with Article 45 of the GDPR (e.g. the EU-US Data Privacy Framework). Midas Partners has entered into a data processing agreement with OnePage GmbH in accordance with Article 28 of the GDPR.
Google Maps:
Our website uses the Google Maps service via an API (application programming interface). The provider of the map service is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA – represented in the EU by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (hereinafter ‘Google’). As soon as the plugin is loaded via the API, Google processes various data (including your IP address) using cookies and similar technologies. It cannot be ruled out that this information may also be transferred to a server in the USA and stored there. To ensure an adequate level of data protection in this case, Google is certified under the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list).
As the website operator, we have no influence over this data transfer. The processing of your information only begins once you have consented to data processing via our Cookie Consent Manager, or activated the map by clicking on it. By doing so, you give your consent to the processing of your data in accordance with Article 6(1)(a) of the GDPR. You may withdraw your consent at any time via our Cookie Consent Manager, with effect for the future. If you are logged into your Google account, Google may add the processed information to your account, depending on your account settings. You can find full details on how Google processes your data at:https://policies.google.com/privacy?hl=de
Google reCAPTCHA:
To protect your orders submitted via the online form, our company uses the reCAPTCHA service provided by Google Inc. (Google). The check is designed to distinguish whether the input is being made by a human or, fraudulently, by automated, machine-based processing. This check involves sending your IP address and, where applicable, any other data required by Google for the reCAPTCHA service to Google. For this purpose, your input is transmitted to Google and processed there.
By using Google reCAPTCHA, you consent to your data being sent to Google. However, if IP anonymisation is enabled on this website, your IP address will first be truncated by Google within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
On behalf of the operator of this website, Google will use this information to evaluate your use of this service. The IP address transmitted by your browser as part of reCAPTCHA will not be merged with other data held by Google. The separate data protection provisions of Google apply to this data.
Further information on Google’s privacy policy can be found athttps://policies.google.com/privacy?hl=de.
YouTube:
We use YouTube, a service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, to embed videos. The embedded videos will only work if you have previously consented to the processing of your data by YouTube via our Cookie Consent Manager, in accordance with Article 6(1)(a) of the GDPR.
As soon as the YouTube video plugin is loaded on our website, Google processes various data (including your IP address) using cookies and similar technologies. It cannot be ruled out that this information may also be transferred to a server in the USA and stored there. To ensure an adequate level of data protection in this case, Google is certified under the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list). As the website operator, we have no influence over this data transfer.
You can withdraw your consent at any time via our Cookie Consent Manager, with effect for the future. If you are logged into your Google account, Google may add the processed information to your account, depending on your account settings. You can find all information regarding the processing of your data by Google at:https://policies.google.com/privacy?hl=de
Mobile Funnel:
We use Mobile Funnel (hereinafter: Funnel), operated by Perspective Software GmbH (hereinafter: Perspective), a company based in Germany which provides software for the creation and operation of Mobile Funnel (https://smex-ctp.trendmicro.com:443/wis/clicktime/v1/query?url=https%3a%2f%2fperspective.co%2fimpressum&umid=45ce8a19-e874-4f5b-81a1-84257fa13510&auth=6dda7ee16f8f1c732e60be068eff4e2c22bf710b-0af118fb73dfe3f7a1900fd20b0bd154c6c2de1c). The data entered whilst using Mobile Funnels is transmitted via SSL encryption and stored in a database. The funnel is used, for example, to create a job advertisement or a quiz, and a contact form can also be included. The funnel is then linked, for example, to CES’s social media channels. CES is solely responsible for the design of the funnel and, consequently, for the personal data entered there, within the meaning of Article 24 of the GDPR. Perspective, on the other hand, is merely the operator of the software and, in this context, a data processor under Article 28 of the GDPR. The basis for processing by Perspective is a data processing agreement between CES and Perspective. In addition, Perspective Software GmbH processes further data – some of which may also be personal data – in order to provide its services, in particular for the operation of the Mobile Funnel. You can find all the relevant information in Perspective’s privacy policy athttps://perspective.co/datenschutzerklaerung/
Tracking tools:
Use of Matomo:
Our website uses Matomo, an open-source web analytics service. Matomo uses your device fingerprint to analyse your usage behaviour on our website. The device fingerprint stores information which Matomo recognises as a unique ‘fingerprint’ the next time you visit our website. Your data is immediately anonymised during this process and randomly altered every 24 hours, ensuring that you, as a user, remain anonymous to us. The information used for the purpose of website optimisation is stored on our server. We carry out this type of audience measurement and analysis on the basis of our legitimate interest in accordance with Article 6(1)(f) of the GDPR. The server on which the data is stored is hosted by a service provider. The legal basis for the transfer of data for this purpose is a data processing agreement in accordance with Article 28 of the GDPR. The following information is stored
in the device fingerprint:
- Location information (continent, country, city, browser language)
- Device (type, model, screen resolution)
- Software (operating system, browser, browser plug-ins)
- (anonymised) IP address
- Times of server requests
- Links from other websites (referrers)
If you do not consent to the storage and analysis of this data from your visit, you can object to its storage and use with a single click. In this case, a so-called opt-out cookie will be stored in your browser, which means that Matomo will not collect any session data. Please note: If you delete your cookies, this will also delete the opt-out cookie, which you may then need to reactivate.You can disable data collection by Matomo at the end of this privacy policy. Provided your browser supports the ‘Do Not Track’ feature and you have enabled it, your visit will be automatically ignored.
Google:
We use various Google services on our website (e.g. Tag Manager, Google Remarketing and Conversion Tracking). The provider of the Google services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google LLC’s headquarters are located at 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. Please note that, in the context described below, data may also be transferred to the USA or other third countries. Data transfers to third countries are carried out on the basis of the EU Commission’s Standard Data Protection Clauses in accordance with Article 46(2)(c) of the GDPR or on the basis of adequacy decisions in accordance with Article 45 of the GDPR (e.g. the EU-US Data Privacy Framework).
Google’s privacy policy can be found at:https://policies.google.com/privacy
Further information on Google Conversion Tracking and how to opt out can be found athttps://tools.google.com/dlpage/gaoptout?hl=de
You can disable the storage and use of information based on your Google account by visiting the ‘Google Ads Preferences’ page athttps://www.google.com/settings/u/0/ads/authenticated and setting the ‘Interest-based advertising’ slider to ‘Off’. You must do this on every device you use to access our website.
Google Tag Manager:
We use Google Tag Manager to integrate third-party content. Google Tag Manager can manage a wide variety of website tags from marketers via a single interface. This is a technical solution which does not itself use any cookies or similar technologies requiring consent, but merely controls the conditions under which the other programmes used on our website and described below are activated.
No data is stored on your device that requires your consent, nor is any data read from your device. The Tag Manager serves exclusively as a technical management system for the scripts used on our website. The legal basis is our legitimate interest in efficient and consistent tag management in accordance with Article 6(1)(f) of the GDPR.
The following services are integrated into our website via Google Tag Manager: Google Ads (remarketing and conversion tracking), LinkedIn Insight Tag and Meta Pixel. These collect personal data and are only loaded once you have given your explicit consent. You can find the privacy notices for these services in the following sections of this privacy policy.
Google Ads Conversion Tracking:
The Google Ads Conversion Tracking service is used to display personalised adverts on the Google Display Network based on your pseudonymised browsing behaviour. This is used to manage advertising campaigns on Google Search and the Google Display Network, as well as to measure the success of our advertising campaigns. If you click on an advert placed by Google, Google Ads will place a conversion tracking cookie on your computer, provided that you have reached our website via a Google advert. These cookies expire after 30 days; they primarily contain hashed IDs and are not used to identify you personally.
If you visit certain pages on our website and the cookie has not yet expired, Google and we can recognise that you clicked on the advert and were redirected to that page. Each Google Ads customer is assigned a different cookie. This means it is not possible for cookies to be tracked across the websites of different Ads customers. The information collected using the conversion cookie is used to generate conversion statistics for us. This tells us the total number of users who clicked on our advert and were redirected to a page tagged with a conversion tracking tag.
Due to the marketing tools used, your browser automatically establishes a direct connection to Google’s server. We have no influence over the scope and further use of the data collected by Google through the use of this tool and are therefore informing you in accordance with our current knowledge. By integrating Google Ads Conversion, Google receives the information that you have accessed the relevant part of our website or clicked on one of our adverts. If you are registered with a Google service, Google may associate the visit with your account. Even if you are not registered with Google or have not logged in, it is possible that the provider may obtain and store your IP address.
Google Ads Remarketing:
We use the remarketing function within the Google Ads service. The remarketing function enables us to show users of our website adverts based on their interests on other websites within the Google advertising network (in Google Search or on YouTube, known as ‘Google Ads’, or on other websites). To do this, we analyse users’ interactions on our website – for example, which offers the user has shown an interest in – so that we can display targeted adverts to users on other sites even after they have visited our website. To this end, Google stores cookies on the devices of users who visit certain Google services or websites within the Google Display Network. These cookies are used to track these users’ visits. The cookies serve to uniquely identify a web browser on a specific device and not to identify an individual.
The processing of personal data by the aforementioned Google Ads functions is carried out on the basis of your prior consent in accordance with Article 6(1)(a) of the GDPR. You may withdraw your consent at any time with future effect via our Cookie Consent Manager.
LinkedIn:
We use various LinkedIn services on our website (e.g. LinkedIn Insight Tag, LinkedIn Ads, LinkedIn Website Retargeting); the provider of these LinkedIn services is LinkedIn Ireland Unlimited Company, Gardner House 2, Wilton Place, Dublin 2, Ireland. LinkedIn’s head office is located at 1000 W. Maude Ave., Sunnyvale, California 94085, USA. Please note that, in the context described below, data may also be transferred to the USA or other third countries. Data transfers to third countries are carried out on the basis of the EU Commission’s Standard Data Protection Clauses in accordance with Article 46(2)(c) of the GDPR and on the basis of adequacy decisions in accordance with Article 45 of the GDPR (e.g. the EU-US Data Privacy Framework).
When using the service, personal data such as IP address (truncated or in full, depending on the processing context), device and browser information, as well as interaction data (e.g. page views, clicks, referrer URL, pages visited, timestamps) and event data (e.g. clicks on adverts, conversions) are processed. This is carried out in particular through the use of cookies and similar tracking technologies when using our website.
The identifier is used for conversion tracking and is stored in the browser for 6 months. IP addresses are truncated or hashed, and direct identifiers of LinkedIn members are removed within seven days to pseudonymise the data. The remaining pseudonymised data is deleted after 180 days. LinkedIn itself does not share any personal data with us, but merely analyses your data and sends us statistical reports and notifications (in which you can no longer be identified by us).
LinkedIn members can also control the use of their personal data for advertising purposes in their account settings at https://www.linkedin.com/psettings/advertising/actions-that-showed-interest.
Further information on the processing of personal data by LinkedIn can be found in LinkedIn’s privacy policy at https://de.linkedin.com/legal/privacy-policy.
LinkedIn Insight Tag:
We use the LinkedIn Insight Tag (via Google Tag Manager) on our website.
The tag is a small piece of code that we have embedded in our campaign landing page to track conversions (e.g. website visits, purchases, newsletter sign-ups or contact enquiries), retarget our website visitors and gather additional information about the people who view our adverts. Among other things, this helps us to make advertising outside our website more targeted and thereby improve the relevance of our adverts.
LinkedIn Ads (Sponsored Content):
We use the LinkedIn Ads (Sponsored Content) service via the LinkedIn Insight Tag, which enables us to display targeted adverts and analyse their performance. This is achieved in particular through the use of cookies and similar technologies.
If the user is logged in to LinkedIn, the pseudonymised LinkedIn ID may also be processed and assigned to the relevant user profile.
LinkedIn Website Retargeting:
The LinkedIn Website Retargeting service, which we use via the LinkedIn Insight Tag, enables us to re-engage users who have visited the landing page but have not completed the contact form. Furthermore, target groups can be addressed through optimised advertising campaigns and contacted via various entry points.
If the user is logged in to LinkedIn at the same time, or is subsequently recognised, LinkedIn may display personalised adverts to that user based on their previous visit to the website.
The processing and transfer of our website visitors’ personal data via the LinkedIn services described above is carried out on the basis of Article 6(1)(a) of the GDPR. You may withdraw your consent at any time with future effect via our Cookie Consent Manager.
Meta:
We use various Meta services on our website (e.g. Meta Pixel, Custom Conversions, Custom Audiences, Lookalike Audiences, Meta Ads); the provider of these Meta services is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Meta’s head office is at 1601 Willow Road, Menlo Park, California 94025, USA. Please note that, in the context described below, data may also be transferred to the USA or other third countries. Data transfers to third countries are carried out on the basis of the EU Commission’s Standard Data Protection Clauses in accordance with Article 46(2)(c) of the GDPR or on the basis of adequacy decisions in accordance with Article 45 of the GDPR (e.g. the EU-US Data Privacy Framework).
When you visit our website, a connection is established with Meta’s servers. In the process, personal data such as IP address, device and browser information, as well as interaction data (e.g. page views, clicks, referrer URL, pages visited, timestamps, and, where applicable, location information) and event data (e.g. access to defined URLs or the triggering of specific events) are collected and transmitted to Meta. Meta uses this data to attribute conversions to specific advertising campaigns and to measure their success. Processing is generally carried out in a pseudonymised manner; we do not carry out any direct identification.
Further information on the collection and use of data by Facebook, your rights in this regard and ways to protect your privacy can be found in Facebook’s privacy policy (https://www.facebook.com/about/privacy/). If you do not wish Facebook to directly associate the collected information with your Facebook user account, you can disable the ‘Custom Audiences’ remarketing feature in the settings of your Facebook user account. To do this, you must be logged in to Facebook.
Meta’s privacy policy can be found at:https://de-de.facebook.com/privacy/policy/
Meta Pixel:
We use the so-called ‘Meta Pixel’ from the social network Facebook on our campaign landing page. By using the Meta Pixel, we can define so-called ‘Custom Audiences’, i.e. user-defined target groups to which you are assigned as part of the tracking carried out by the pixel. The Facebook adverts we place are then only shown to people who have been assigned to the relevant target group. This is intended to ensure that you only see adverts for products and services in which you are actually interested. In this way, we aim to ensure that our adverts match users’ potential interests and do not come across as intrusive. The Meta Pixel measures page visits, progress through the multi-step contact form, and the successful completion of an enquiry.
When you visit the website, the remarketing tag establishes a direct connection to Meta’s servers. This transmits information to Meta about which pages you have visited on our website. Meta associates this information with your personal Facebook user account.
Custom Conversions:
We use Meta’s ‘Custom Conversions’ service on our website. This service enables us to define and analyse specific user actions on our website (e.g. the use of individual steps in the landing page funnel, the lead conversion event following the completion of a form) as so-called conversions. These are used to measure and optimise the success of our advertising campaigns.
Data is collected via the Meta Pixel and, where applicable, via the server-side Conversions API. When you visit our website, a connection is established with Meta’s servers and event data (e.g. URL visits or defined actions) is transmitted to Meta.
Custom Audiences:
By using the Meta Pixel on our website, we can identify so-called ‘Custom Audiences’, i.e. user-defined target groups to which you are assigned as part of the tracking carried out by the pixel. The target groups are automatically generated on the basis of the Custom Audiences and converted leads in order to reach new users with a similar profile. To this end, data on usage behaviour on our website is collected via the Meta Pixel and, where applicable, the Conversions API, and transmitted to Meta. Meta assigns this information – where possible – to existing user profiles and uses it to create target group lists (‘Custom Audiences’). In addition, Custom Audiences can be created based on uploaded contact data (e.g. email addresses in hashed form) from existing CES partners (“Customer List Custom Audiences”).
The Facebook adverts we place are then only shown to people who are assigned to the relevant target group. This is intended to ensure that you only see adverts for products and services in which you are actually interested. In this way, we aim to ensure that our adverts match users’ potential interests and do not come across as intrusive.
Lookalike Audiences:
Using the Lookalike Audiences service, we can identify new target groups that resemble existing users of our website or defined target groups (so-called ‘Custom Audiences’). The aim is to display our adverts specifically to users who may be interested.
To this end, Meta uses information from existing target groups (e.g. website visitors or customer lists) to identify similar user profiles within the Meta platforms using statistical methods. For this purpose, usage and interaction data from existing target groups is analysed. We do not have access to individual personal data of the identified users, but only to aggregated target groups.
Meta Ads:
Meta Ads enables us to display targeted adverts within the Meta platforms (in particular the Facebook and Instagram feeds) and to measure their success. The target region comprises Germany, Austria and, where applicable, Switzerland in the near future.
When you visit our website, a connection to Meta’s servers is established via tracking technologies (in particular the Meta Pixel and, where applicable, the Conversions API). In the process, usage and event data are collected and transmitted to Meta. Meta may use this data to display personalised adverts to users and to evaluate advertising campaigns.
The processing and transfer of our website visitors’ personal data via the aforementioned Meta services is carried out on the basis of Article 6(1)(a) of the GDPR. You may withdraw your consent at any time with future effect via our Cookie Consent Manager.
Website hosting
This website is hosted externally. The personal data collected on this website is stored on the host’s servers. This may primarily include IP addresses, contact enquiries, meta and communication data (e.g. web browser, referrer, URLs visited) as well as contact details (e.g. first name, surname, email address), website visits and other enquiries and data generated via a website.
External hosting is carried out by a professional provider in the interests of ensuring the secure, fast and efficient provision of our website (Article 6(1)(f) of the GDPR). Our hosting provider will only process your data to the extent necessary to fulfil its service obligations and will comply with our instructions regarding this data. We have entered into a data processing agreement with the service provider in accordance with Article 28(3) of the GDPR.
The website is administered by the service provider bitloft GmbH, Schulstraße 2, 42551 Velbert. bitloft GmbH has commissioned the data centre Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, as a sub-processor to store the data. The data is stored exclusively within the European Union. bitloft GmbH has entered into a data processing agreement with Hetzner Online GmbH in accordance with Article 28 of the GDPR.
Reporting Security Vulnerabilities (Vulnerability Disclosure):
Our website provides a contact address through which security researchers and users can report potential vulnerabilities in our products or associated services.
If you report a vulnerability to us via cybersecurity@ces.eu, we process the data you provide to us in this context. This may include, in particular, your email address, a name or pseudonym you provide, and any other contact details you voluntarily share, as well as the content of your report, such as technical details about the vulnerability, proof-of-concept code, or screenshots. As a general rule, we use only the content of your report, and we use your personal data only when it is necessary.
We process this data in order to assess and remediate reported vulnerabilities and, if desired, to communicate with you about the status of that process, on the basis of our legitimate interest in the security of our products and users (Art. 6(1)(f) GDPR, Regulation (EU) 2024/2847 cybersecurity requirements for products with digital elements). If a report confirms an actively exploited vulnerability or a severe incident, we are additionally required, under Article 14 of the EU Cyber Resilience Act, to notify ENISA and the relevant national CSIRT coordinator via the designated Single Reporting Platform; Your personal data will not be disclosed to third parties.
Your report is shared within CES only with the internally responsible security and development teams. Where a vulnerability concerns a third-party component, it may be necessary to pass on technical details to the manufacturer or maintainer of that component; in doing so, we do not disclose any of your contact details to third parties. Data is transmitted to ENISA and the relevant CSIRT coordinator only where legally required under Article 14 of the Cyber Resilience Act. No further disclosure to third parties takes place.
In all other respects, our privacy policy applies.
Further general information:
Changes to this privacy policy
We review the privacy policy at regular intervals to ensure it complies with statutory provisions, case law and the guidance of supervisory authorities, and to ensure it is aligned with emerging trends and developments in technical standards. We therefore reserve the right to amend this privacy policy in order to bring it into line with new data protection legislation and other changes in the factual or legal situation. Please therefore always familiarise yourself with the privacy policy in force at the time you begin using our website.
Who is responsible for data processing? (Art. 13(1)(a), (b) GDPR)
C.Ed. Schulte GmbH Zylinderschlossfabrik is responsible for data processing on our website. You can find the contact details in the legal notice: https://www.ces.eu/de_us/impressum.html
You can contact our Data Protection Officer at the following address:
C.Ed. Schulte GmbH Zylinderschlossfabrik For
the attention of the Data
Protection Officer Friedrichstr.
243 D-42551
Velbert Postfach 10 11 80,
D-42547Email:
datenschutz@ces.euTel.: +49 (0) 2051 204-0
Who receives your personal data? (Art. 13(1)(e), (f) GDPR)
We treat your personal data as confidential and do not, as a matter of principle, pass it on to third parties, unless you have given your consent or the disclosure is required by a legal or contractual obligation. In isolated cases, we engage data processors to process your personal data. This is done in accordance with Article 28 of the GDPR and on the basis of a data processing agreement.
How long is the data retained? (Art. 13(2)(a) GDPR)
The legislator has laid down a wide range of retention obligations and time limits.
As a general rule, we only store your data for as long as is required by law.
Once these time limits have expired, the relevant data is routinely deleted if it is no longer required for the performance of a contract. We store data that we process on the basis of your consent until such consent is withdrawn or for as long as the data is required. We store data that we process on the basis of a legitimate interest for as long as that legitimate interest persists.
Commercial or financial data relating to a completed financial year will be deleted after a further ten years in accordance with legal requirements, unless longer retention periods are prescribed or required for legitimate reasons. Where data is not subject to specific retention periods, it will be deleted once the purposes for which it is processed no longer apply.
For what purposes and on what legal basis do we process your personal data? (Art. 13(1)(c), (d) GDPR)
We have already explained the purposes and legal bases for data processing. In addition, the following generally applies: Where necessary, we process your data to safeguard our legitimate interests or those of third parties in accordance with Article 6(1)(f) of the GDPR, for example to assert legal claims and defend ourselves in legal disputes, or to ensure IT operations and security.
Where we have a legitimate interest or have obtained your written consent to the processing of your personal data, we process your data for the purposes of external communication and marketing on the basis of Article 6(1)(a) or (f) of the GDPR. You have the right to withdraw your consent at any time.
To comply with legal requirements, we may or must, where necessary, process your data and disclose it to third parties (in accordance with Article 6(1)(c)).
We do not use your data in any way for automated decision-making or profiling.
What are your rights and obligations? (Article 13(2)(b), (c), (d) and (e) of the GDPR)
Every data subject has the following rights:
Under Article 15 of the GDPR, you have the right of access. This means you may request confirmation from us as to whether we are processing personal data relating to you.
Under Article 16 of the GDPR, you have the right to rectification. This means you may request that we rectify any inaccurate personal data concerning you.
Under Article 17 of the GDPR, you have the right to erasure (‘right to be forgotten’). This means that you may request that we erase personal data relating to you without undue delay – unless we are unable to erase your data because, for example, we are required to comply with statutory retention obligations.
Under Article 18 of the GDPR, you have the right to restriction of processing. This means that, apart from storing your personal data, we may no longer process it in any practical sense.
Under Article 20 of the GDPR, you have the right to data portability. This means you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, and to transmit this data to another controller.
Under Article 7(3) of the GDPR, you have the right to withdraw your consent at any time with effect for the future.
Under Article 77 of the GDPR, you have the right to lodge a complaint with the relevant supervisory authority.
In addition, you have a right to object, which we explain in more detail at the end of this privacy notice.
If you wish to exercise your rights, please contact the Data Protection Officer (see above for contact details).
Competent supervisory authority
State Commissioner for Data Protection and Freedom of Information, North Rhine-Westphalia Street address
: Kavalleriestr. 2 – 4, 40312 Düsseldorf Postal address
: PO Box 20 04 44, 40102
DüsseldorfTel.: +49 (0) 211/38424-0Email address
: poststelle@ldi.nrw.de
Information regarding your right to object under Article 21 of the General Data Protection Regulation (GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(f) of the GDPR (data processing based on a balancing of interests); this also applies to any profiling based on this provision within the meaning of Article 4(4) of the GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
Please submit your objection in writing (by email or post) to our Data Protection Officer (see above for contact details).