Privacy Policy
Open privacy settingsGeneral Introduction
We take the protection of your personal data very seriously and want you to feel safe when visiting our website. Our data protection practices comply in particular with the requirements of the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications and Telemedia Data Protection Act (TDDDG). Below we would like to inform you about the nature, scope, and purpose of the processing of your personal data. We would like to point out in advance that this privacy policy applies solely to our own websites and does not apply to third-party websites to which we refer by way of links.
Subject of Protection
The subject of protection is personal data. This refers to any information relating to an identified or identifiable natural person (hereinafter the "data subject"). This includes, in particular, information that allows conclusions to be drawn about your identity (e.g. details such as name, postal address, e-mail address, and telephone number).
Technical Requirements
In order to establish a connection to our website, your browser transmits certain data to the web server hosting our website. This is a technical necessity so that the information you request can be provided by the website. To enable this, your IP address, the date and time of your request, and the type of your operating system, among other things, are stored and used for a maximum of 7 days. We reserve the right to store this data for a limited period of time in order to safeguard our legitimate interests, so that, in the event of unauthorized access or an attempt to deliberately harm us by this means, we can trace it back to personal data (Art. 6(1)(f) GDPR). The data is retained or forwarded by us solely for these purposes and for no other purpose, without prior notice to you and without requesting your permission.
Cookies
Cookies are small text files that are stored via your browser on your computer or mobile device, for example to recognize whether you repeatedly visit websites from the same device or browser. In general, we use cookies to analyze interest in our website as well as to improve its user-friendliness. In principle, however, you can also access our website without cookies.
Cookies can generally be disabled or removed using tools available in most commercial browsers. The settings must be defined and configured separately for each browser you use. Different browsers offer different functions and options for this purpose.
In order to use our website to its full extent and comfortably, you should accept those cookies that enable the use of certain functions or make use more comfortable. You can find further down the page for what purpose the cookies we use are used and how long they are stored.
You can consent to the use of cookies that are not required for us, as the provider, to make our website available to you, via our cookie consent manager (pursuant to Section 25(1) TDDDG), and you may revoke your consent at any time with effect for the future.
Midas Partners – Marketing Agency
To support the conception, execution, and evaluation of online advertising campaigns via the social media channels named below (e.g. lead data, conversions), as well as contact requests via the landing page platform (partner program), the marketing agency Midas Partners Ioannidis & Steih GbR, Paulstraße 16, 42553 Velbert, has been engaged. We have concluded a data processing agreement with this service provider pursuant to Art. 28 GDPR.
Users of Our Contact Form
Our website features contact forms that can be used to get in touch electronically. To ensure secure transmission of your data, we use a state-of-the-art encrypted connection with an SSL certificate during transmission. By clicking the "Send Request" button, you consent to the transmission to us of the data entered in the form. We store your name and e-mail address, and, where applicable, any further information you provide, in order to be able to contact you and answer your inquiry as effectively as possible. On the one hand, this allows us to offer you the service you expect from us, and on the other hand, it gives us the opportunity to continuously improve (Art. 6(1)(f) GDPR). You can object to the processing of your data at any time. All information on the right to object under Art. 21 GDPR can be found at the end of this privacy policy.
OnePage CRM
As soon as a user completes and submits the contact form on the campaign landing page, the data entered is transferred to the CRM system of our marketing agency Midas Partners Ioannidis & Steih GbR. An e-mail containing the complete contact information of the interested party is then automatically sent to us from there. The data in OnePage is manually deleted once it is no longer required. The CRM system has no direct access to CES's website or tracking system.
Midas Partners uses OnePage CRM as an internal lead management system, in which contact data is temporarily stored. OnePage GmbH is headquartered at Hanauer Landstraße 172, 60314 Frankfurt am Main, Germany. Please note that, in this context, data may also be transferred to sub-processors in the USA or other third countries. Data transfers to third countries are based on the standard contractual clauses of the EU Commission pursuant to Art. 46(2)(c) GDPR, or on adequacy decisions pursuant to Art. 45 GDPR (e.g. the EU-US Data Privacy Framework). Midas Partners has concluded a data processing agreement with OnePage GmbH pursuant to Art. 28 GDPR.
LeadTable Dashboard
The data from the contact form is collected and processed by Midas Partners in the dashboard of the provider Katiba Technology GmbH (LeadTable), where it is centrally administered. A data processing agreement pursuant to Art. 28 GDPR has been concluded with LeadTable. The Sales and Marketing departments have access to the leads. Follow-up on contacting these individuals is tracked within the dashboard in the form of a note. The lead data and processing history are stored in encrypted form, and login is protected via two-factor authentication. The data is stored for 6 months. Contact persons who enter data in the contact form but do not complete the contact request can only be viewed statistically; the data is processed anonymously so that no association with a specific person is possible.
Google Maps
Our website uses the Google Maps mapping service via an API (application programming interface). The provider of the mapping service is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA – represented in the EU by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (hereinafter "Google"). As soon as the plugin is loaded via the API, Google processes various data (including your IP address) via cookies and similar technologies. It cannot be ruled out that this information is also transmitted to and stored on a server in the USA. To ensure an adequate level of data protection in this case, Google is certified under the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list).
As the website operator, we have no influence over this data transfer. Processing of your information only begins once you have consented to data processing via our cookie consent manager, or once you activate the map by clicking on it. By doing so, you give your consent to the processing of your data pursuant to Art. 6(1)(a) GDPR. You may revoke your consent at any time with effect for the future via our cookie consent manager. If you are logged into your Google account, Google may add the processed information to your account, depending on your account settings. All information on the processing of your data by Google can be found at: https://policies.google.com/privacy?hl=de
Google reCAPTCHA
To protect your requests submitted via internet forms, our company uses the reCAPTCHA service provided by Google Inc. ("Google"). This query serves to distinguish whether the input was made by a human or was submitted abusively through automated, machine processing. The query includes sending your IP address and, where applicable, other data required by Google for the reCAPTCHA service. For this purpose, your input is transmitted to Google and used further there.
By using Google reCAPTCHA, you agree to the transmission of your data to Google. If IP anonymization is activated on this website, your IP address will be shortened beforehand by Google within Member States of the European Union or in other signatory states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there.
On behalf of the operator of this website, Google will use this information to evaluate your use of this service. The IP address transmitted by your browser as part of reCAPTCHA is not merged with other data held by Google. Google's own, differing data protection provisions apply to this data.
Further information on Google's privacy policies can be found at https://policies.google.com/privacy?hl=de.
YouTube
We use YouTube to embed videos, a service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland. The embedded videos only function if you have previously consented to the processing of your data by YouTube via our cookie consent manager, pursuant to Art. 6(1)(a) GDPR.
As soon as the YouTube video plugin is loaded on our website, Google processes various data (including your IP address) via cookies and similar technologies. It cannot be ruled out that this information is also transmitted to and stored on a server in the USA. To ensure an adequate level of data protection in this case, Google is certified under the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list). As the website operator, we have no influence over this data transfer.
You may revoke your consent at any time with effect for the future via our cookie consent manager. If you are logged into your Google account, Google may add the processed information to your account, depending on your account settings. All information on the processing of your data by Google can be found at: https://policies.google.com/privacy?hl=de
Mobile Funnel
We use Mobile Funnel (hereinafter "Funnel"), operated by Perspective Software GmbH (hereinafter "Perspective"), a company based in Germany that offers software for creating and operating Mobile Funnels (https://perspective.co/impressum). Data entered as part of the use of Mobile Funnel is transmitted via SSL encryption and stored in a database. The Funnel is used, for example, to design a job posting or a quiz, within which a contact form can also be embedded. The Funnel is then, for example, linked on CES's social media channels. CES alone is responsible for the design of the Funnel and thus also for the personal data entered here, within the meaning of Art. 24 GDPR. Perspective, on the other hand, is merely the operator of the software and, in this context, a processor pursuant to Art. 28 GDPR. Processing by Perspective is based on a data processing agreement between CES and Perspective. In addition, Perspective Software GmbH processes further data in order to provide its services, in particular to operate Mobile Funnel, some of which may also constitute personal data. All information on this can be found in Perspective's privacy policy at https://perspective.co/datenschutzerklaerung/
Tracking Tools
Use of Matomo
Our website uses Matomo, an open-source web analytics service. Matomo uses your device fingerprint ("Device Fingerprint") to analyze your usage behavior on our website. The Device Fingerprint stores information that Matomo recognizes as a unique "fingerprint" the next time you visit our website. In this process, your data is immediately anonymized and randomly changed every 24 hours, so that you, as a user, remain anonymous to us. The information used for the purpose of website optimization is stored on our server. We carry out this type of reach measurement and analysis on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. The server on which the data is stored is hosted by a service provider. The legal basis for forwarding the data for this purpose is a data processing agreement pursuant to Art. 28 GDPR.
The Device Fingerprint stores the following information:
– Location information (continent, country, city, browser language)
– Device (type, model, screen resolution)
– Software (operating system, browser, browser plugins)
– (Anonymized) IP address
– Timing of server requests
– Referrals from other websites (referrer)
If you do not agree to the storage and evaluation of this data from your visit, you can object to its storage and use with a mouse click. In this case, a so-called opt-out cookie is placed in your browser, with the effect that Matomo does not collect any session data whatsoever. Please note: if you delete your cookies, this will also delete the opt-out cookie, which may need to be reactivated by you. You can disable data collection by Matomo at the end of this privacy policy. If your browser supports the "Do Not Track" technology and you have activated it, your visit is automatically ignored.
We use various Google services on our website (e.g. Tag Manager, Google Remarketing, and Conversion Tracking). The provider of the Google services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google LLC's headquarters are located at 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. Please note that, in this context, data may also always be transferred to the USA or other third countries. Data transfers to third countries are based on the standard contractual clauses of the EU Commission pursuant to Art. 46(2)(c) GDPR, or on adequacy decisions pursuant to Art. 45 GDPR (e.g. the EU-US Data Privacy Framework).
Google's privacy policy can be found at: https://policies.google.com/privacy
Further information on Google Conversion Tracking and how to disable it can be found at https://tools.google.com/dlpage/gaoptout?hl=de
You can disable the storage and use of information based on your Google account by visiting the "Google Ad Settings" page at https://www.google.com/settings/u/0/ads/authenticated and switching the "Interest-based advertising" toggle to "Off". You must do this on every device you use to access our website.
Google Tag Manager
We use Google Tag Manager to embed content from third-party providers. Google Tag Manager can manage various website tags from advertisers via a single interface. This is a technical solution that does not itself use cookies or similar technologies requiring consent, but merely controls the conditions under which the other programs used on our website, described below, are activated.
No storage of data on your device, or reading of data from your device, requiring consent takes place. The Tag Manager serves exclusively as a technical management system for the scripts used on our website. The legal basis is our legitimate interest in efficient and consistent tag management pursuant to Art. 6(1)(f) GDPR.
The following services are embedded on our website via Google Tag Manager: Google Ads (Remarketing and Conversion Tracking), the LinkedIn Insight Tag, and the Meta Pixel. These collect personal data and are only loaded after your explicit consent. The privacy information regarding these services can be found in the following sections of this privacy policy.
Google Ads Conversion Tracking
The Google Ads Conversion Tracking service serves to display personalized advertisements within the Google advertising network, based on your pseudonymized browsing behavior. This serves to manage advertising campaigns in Google Search and the Google advertising network, as well as to measure the success of our advertising campaigns. If you click on an ad placed by Google, Google Ads places a cookie for conversion tracking on your computer, provided you reached our website via a Google ad. These cookies expire after 30 days, contain mainly hashed IDs, and are not used to identify you personally.
If you visit certain pages of our website and the cookie has not yet expired, Google and we can recognize that you clicked on the ad and were redirected to this page. Each Google Ads customer receives a different cookie. As a result, there is no way for cookies to be tracked across the websites of Ads customers. The information obtained using the conversion cookie is used to create conversion statistics for us. This allows us to learn the total number of users who clicked on our ad and were redirected to a page tagged with a conversion tracking tag.
Due to the marketing tools used, your browser automatically establishes a direct connection with Google's server. We have no influence over the scope and further use of the data collected by Google through the use of this tool, and we therefore inform you according to our level of knowledge. By integrating Google Ads Conversion, Google receives the information that you have accessed the corresponding part of our website or clicked on one of our ads. If you are registered with a Google service, Google can associate the visit with your account. Even if you are not registered with Google or not logged in, there is a possibility that the provider may learn and store your IP address.
Google Ads Remarketing
We use the remarketing function within the Google Ads service. With the remarketing function, we can present users of our website with advertisements based on their interests on other websites within the Google advertising network (in Google Search or on YouTube, so-called "Google ads", or on other websites). For this purpose, user interaction on our website is analyzed, e.g. which offers the user was interested in, in order to be able to show users targeted advertising even after they have visited our website, on other pages. For this purpose, Google stores cookies on the devices of users who visit certain Google services or websites within the Google Display Network. These cookies are used to record the visits of these users. The cookies serve to uniquely identify a web browser on a particular device and not to identify a person.
The processing of personal data through the aforementioned Google Ads functions is based on your prior consent pursuant to Art. 6(1)(a) GDPR. You can revoke your consent at any time with effect for the future via our cookie consent manager.
We use various LinkedIn services on our website (e.g. LinkedIn Insight Tag, LinkedIn Ads, LinkedIn Website Retargeting). The provider of the LinkedIn services is LinkedIn Ireland Unlimited Company, Gardner House 2, Wilton Place, Dublin 2, Ireland. LinkedIn's headquarters are located at 1000 W. Maude Ave., Sunnyvale, California 94085, USA. Please note that, in this context, data may also always be transferred to the USA or other third countries. Data transfers to third countries are based on the standard contractual clauses of the EU Commission pursuant to Art. 46(2)(c) GDPR, and on adequacy decisions pursuant to Art. 45 GDPR (e.g. the EU-US Data Privacy Framework).
When using the service, personal data such as IP address (shortened or complete, depending on the processing context), device and browser information, as well as interaction data (e.g. page views, clicks, referrer URL, pages visited, timestamps) and event data (e.g. clicks on ads, conversions) are processed. This is done in particular through the use of cookies and similar tracking technologies when using our website.
The identifier is used for conversion tracking and is stored in the browser for 6 months. IP addresses are shortened or hashed, and direct identifiers of LinkedIn members are removed within seven days in order to pseudonymize the data. The remaining pseudonymized data is deleted after 180 days. LinkedIn itself does not share any personal data with us, but merely evaluates your data and sends us statistical reports and communications (in which you can no longer be identified by us).
LinkedIn members can also control the use of their personal data for advertising purposes in their account settings at https://www.linkedin.com/psettings/advertising/actions-that-showed-interest
Further information on the processing of personal data by LinkedIn can be found in LinkedIn's privacy information at https://de.linkedin.com/legal/privacy-policy.
LinkedIn Insight Tag
We use the LinkedIn Insight Tag (via Google Tag Manager) on our website.
The tag is a small piece of code that we have embedded on our campaign landing page to track conversions (e.g. website visits, purchases, newsletter sign-ups, or contact requests), carry out retargeting of our website visitors, and gain additional information about the people who view our advertisements. This helps us, among other things, to design advertising outside our website in a more targeted manner and thereby improve the relevance of our ads.
LinkedIn Ads (Sponsored Content)
We use the LinkedIn Ads (Sponsored Content) service via the LinkedIn Insight Tag, which allows us to display targeted advertisements and analyze their success. This is done in particular through the use of cookies and similar technologies.
If the user is logged into LinkedIn, the pseudonymized LinkedIn ID may also be processed and associated with the respective user profile.
LinkedIn Website Retargeting
The LinkedIn Website Retargeting service, which we use via the LinkedIn Insight Tag, enables re-engagement of users who visited the landing page but did not complete the contact form. In addition, target groups can be addressed through optimized advertising campaigns and contacted via various entry points.
If the user is simultaneously logged into LinkedIn or is recognized later, LinkedIn can show this user personalized advertising based on their previous website visit.
The processing and forwarding of the personal data of our website visitors through the LinkedIn services described above is based on Art. 6(1)(a) GDPR. You can revoke your consent at any time with effect for the future via our cookie consent manager.
Meta
We use various Meta services on our website (e.g. Meta Pixel, Custom Conversions, Custom Audiences, Lookalike Audiences, Meta Ads). The provider of the Meta services is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Meta's headquarters are located at 1601 Willow Road, Menlo Park, California 94025, USA. Please note that, in this context, data may also always be transferred to the USA or other third countries. Data transfers to third countries are based on the standard contractual clauses of the EU Commission pursuant to Art. 46(2)(c) GDPR, or on adequacy decisions pursuant to Art. 45 GDPR (e.g. the EU-US Data Privacy Framework).
When you visit our website, a connection is established to Meta's servers. In doing so, personal data such as IP address, device and browser information, as well as interaction data (e.g. page views, clicks, referrer URL, pages visited, timestamps, and, where applicable, location information) and event data (e.g. calling up defined URLs or triggering certain events) are collected and transmitted to Meta. Meta uses this data to attribute conversions to specific advertising campaigns and to measure their success. Processing generally takes place in pseudonymized form; no direct identification is carried out by us.
Further information on the collection and use of data by Facebook, and on your related rights and options for protecting your privacy, can be found in Facebook's privacy notices (https://www.facebook.com/about/privacy/). If you do not want Facebook to associate the collected information directly with your Facebook user account, you can disable the "Custom Audiences" remarketing function in your Facebook account settings. To do this, you must be logged into Facebook.
Meta's privacy policy can be found at: https://de-de.facebook.com/privacy/policy/
Meta Pixel
We use the so-called "Meta Pixel" of the social network Facebook on our campaign landing page. By using the Meta Pixel, we can define so-called "Custom Audiences", i.e. custom target groups, to which you may be assigned as part of tracking via the pixel. The Facebook advertising we place will then only be shown to people who belong to the corresponding target group. This is intended to ensure that you only receive advertising for products and services in which you are actually interested. In this way, we want to ensure that our advertising corresponds to the potential interest of users and does not have an intrusive effect. The Meta Pixel measures page visits, progress within the multi-step contact form, and the successful completion of a request.
Via the remarketing tag, a direct connection to Meta's servers is established when the website is visited. This transmits to Meta which pages you have visited on our website. Meta associates this information with your personal Facebook user account.
Custom Conversion
We use Meta's "Custom Conversions" service on our website. This service makes it possible to define and evaluate certain user actions on our website (e.g. the use of individual steps of the landing page funnel, the lead completion event after full completion of the form) as so-called conversions. These are used to measure and optimize the success of our advertising measures.
Collection takes place via the Meta Pixel and, where applicable, via the server-side Conversions API. In doing so, a connection to Meta's servers is established when our website is visited, and event data (e.g. URL calls or defined actions) is transmitted to Meta.
Custom Audiences
By using the Meta Pixel on our website, we can define so-called "Custom Audiences", i.e. custom target groups, to which you may be assigned as part of tracking via the pixel. Target groups are automatically generated based on Custom Audiences and converted leads, in order to reach new users with a similar profile. For this purpose, data on usage behavior on our website is collected via the Meta Pixel and, where applicable, the Conversions API, and transmitted to Meta. Where possible, Meta associates this information with existing user profiles and creates target group lists ("Custom Audiences") from it. In addition, Custom Audiences can be created based on uploaded contact data (e.g. e-mail addresses in hashed form) of existing CES partners ("Customer List Custom Audiences").
The Facebook advertising we place will then only be shown to people who belong to the corresponding target group. This is intended to ensure that you only receive advertising for products and services in which you are actually interested. In this way, we want to ensure that our advertising corresponds to the potential interest of users and does not have an intrusive effect.
Lookalike Audiences
With the help of the Lookalike Audiences service, we can identify new target groups that resemble existing users of our website or defined target groups (so-called "Custom Audiences"). The aim is to display our advertisements in a targeted manner to potentially interested users.
For this purpose, Meta uses information from existing target groups (e.g. website visitors or customer lists) to determine, using statistical methods, similar user profiles within the Meta platforms. For this purpose, usage and interaction data of existing target groups is analyzed. We do not obtain access to individual personal data of the identified users, but only to aggregated target groups.
Meta Ads
Meta Ads allows us to display advertisements in a targeted manner within Meta's platforms (in particular Facebook and the Instagram feed) and to measure their success. The target region includes Germany, Austria, and, possibly soon, Switzerland.
When you visit our website, a connection to Meta's servers is established via tracking technologies (in particular the Meta Pixel and, where applicable, the Conversions API). Usage and event data is collected and transmitted to Meta. Meta may use this data to show users personalized advertising and to evaluate advertising campaigns.
The processing and forwarding of the personal data of our website visitors through the aforementioned Meta services is based on Art. 6(1)(a) GDPR. You can revoke your consent at any time with effect for the future via our cookie consent manager.
Website Hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the hosting provider(s). This may include, in particular, IP addresses, contact requests, meta and communication data (e.g. web browser, referrer, URL visited), as well as contact data (e.g. first name, last name, e-mail address), website access data, and other requests and data generated via a website.
External hosting takes place in the interest of a secure, fast, and efficient provision of our website by a professional provider (Art. 6(1)(f) GDPR). Our hosting provider will only process your data to the extent necessary to fulfill its contractual obligations and will follow our instructions with regard to this data. We have concluded a data processing agreement with the service provider pursuant to Art. 28(3) GDPR.
The website is administered using the PIMCORE content management system, which is provided by the service provider valantic DXA GmbH, Birketweg 21, 80639 Munich. As a managed server service, the "provider services" of Brandler & Krantz GmbH & Co. KG, Kurt-Schumacher-Platz 8, 44787 Bochum, are engaged to store the data. The data is stored exclusively within the European Union. CES has concluded data processing agreements with valantic DXA GmbH and with Brandler & Krantz GmbH & Co. KG pursuant to Art. 28 GDPR.
Wonderland – Marketing Agency
To provide support in the areas of online marketing, communication, social media, content creation, as well as campaign management and evaluation, contact and lead management, and appointment and project organization, the marketing agency Wonderland Consulting GmbH, Fürstenwall 172, 40217 Düsseldorf, has been engaged. It is responsible for creating reports and managing websites, landing pages, subdomains, and social media accounts. AI applications may be used for the creation and publication of text, image, video, and other content. As the controller of the data processing operations, we can decide ourselves on the use of individual tools and are informed of and approve them where necessary. We use AI applications exclusively for purposes that do not pose any risk to data subjects, and we take care to ensure that, wherever possible, no sensitive or particularly confidential personal data (e.g. access credentials, payment data) is processed. We have concluded a data processing agreement with the service provider pursuant to Art. 28 GDPR.
Reporting Security Vulnerabilities (Vulnerability Disclosure):
Our website provides a contact address through which security researchers and users can report potential vulnerabilities in our products or associated services.
If you report a vulnerability to us via cybersecurity@ces.eu, we process the data you provide to us in this context. This may include, in particular, your email address, a name or pseudonym you provide, and any other contact details you voluntarily share, as well as the content of your report, such as technical details about the vulnerability, proof-of-concept code, or screenshots. As a general rule, we use only the content of your report, and we use your personal data only when it is necessary.
We process this data in order to assess and remediate reported vulnerabilities and, if desired, to communicate with you about the status of that process, on the basis of our legitimate interest in the security of our products and users (Art. 6(1)(f) GDPR, Regulation (EU) 2024/2847 cybersecurity requirements for products with digital elements). If a report confirms an actively exploited vulnerability or a severe incident, we are additionally required, under Article 14 of the EU Cyber Resilience Act, to notify ENISA and the relevant national CSIRT coordinator via the designated Single Reporting Platform; Your personal data will not be disclosed to third parties.
Your report is shared within CES only with the internally responsible security and development teams. Where a vulnerability concerns a third-party component, it may be necessary to pass on technical details to the manufacturer or maintainer of that component; in doing so, we do not disclose any of your contact details to third parties. Data is transmitted to ENISA and the relevant CSIRT coordinator only where legally required under Article 14 of the Cyber Resilience Act. No further disclosure to third parties takes place.
In all other respects, our privacy policy applies.
Additional General Information
Changes to This Privacy Policy
We review this privacy policy at regular intervals for compliance with legal requirements, case law, guidance from supervisory authorities, as well as to align it with emerging trends and the development of technical standards. We therefore reserve the right to amend this privacy policy in order to adapt it to new legal data protection requirements and other changes to the facts or legal situation. Please therefore always inform yourself, at the start of each use of our website, about the version of this privacy policy that is valid at that time.
Who Is Responsible for Data Processing? (Art. 13(1)(a), (b) GDPR)
Responsible for data processing on our website is C.Ed. Schulte GmbH Zylinderschlossfabrik. You can find our contact details in the legal notice: https://www.ces.eu/de_us/impressum.html
You can reach our data protection officer at:
C.Ed. Schulte GmbH Zylinderschlossfabrik
An den Datenschutzbeauftragten
Friedrichstr. 243
D-42551 Velbert
Postfach 10 11 80, D-42547
E-mail: datenschutz@ces.eu
Tel.: +49 (0) 2051 204-0
Who Receives Your Personal Data? (Art. 13(1)(e), (f) GDPR)
We treat your personal data confidentially and, in principle, do not pass it on to third parties, unless you have given your consent to do so, or the disclosure is required by a legal or contractual obligation. In individual cases, we engage processors to process your personal data. This is done in accordance with Art. 28 GDPR and on the basis of a data processing agreement.
How Long Is Data Stored? (Art. 13(2)(a) GDPR)
The legislature has enacted a wide range of retention obligations and periods.
In principle, we only store your data for as long as is legally required.
After these periods expire, the corresponding data is routinely deleted, provided it is no longer required for the performance of a contract. Data that we process on the basis of your consent is stored by us until revocation, or for as long as the data is required. Data that we process on the basis of a legitimate interest is stored by us for as long as the legitimate interest exists.
Commercial or financially relevant data from a completed financial year is deleted after a further ten years in accordance with legal requirements, unless longer retention periods are prescribed or required for legitimate reasons. Insofar as data is not subject to specific retention periods, it is deleted once the purposes for which it is processed cease to apply.
For What Purposes and On What Legal Basis Do We Process Your Personal Data? (Art. 13(1)(c), (d) GDPR)
We have already explained the purposes and legal bases of the data processing. In addition, the following generally applies: where necessary, we process your data to safeguard legitimate interests of ourselves or third parties pursuant to Art. 6(1)(f) GDPR, for example to assert legal claims and defend ourselves in legal disputes, or to ensure IT operations and security.
Insofar as we have a legitimate interest or have received written consent from you to process your personal data, we process your data for purposes of external communication and marketing on the basis of Art. 6(1)(a) or (f) GDPR. You have the right to revoke your consent at any time.
In order to comply with legal requirements, we may or must, where necessary, process your data and pass it on to third parties (pursuant to Art. 6(1)(c) GDPR).
We do not use your data in any way for automated decision-making or profiling.
What Rights and Obligations Do You Have? (Art. 13(2)(b), (c), (d), (e) GDPR)
Every data subject has the following rights:
Pursuant to Art. 15 GDPR, you have the right of access. This means you can request confirmation from us as to whether personal data concerning you is being processed by us.
Pursuant to Art. 16 GDPR, you have the right to rectification. This means you can request that we correct inaccurate personal data concerning you.
Pursuant to Art. 17 GDPR, you have the right to erasure ("right to be forgotten"). This means you can request that we delete personal data concerning you without delay – unless we are unable to delete your data because, for example, we are required to comply with statutory retention obligations.
Pursuant to Art. 18 GDPR, you have the right to restriction of processing. This means that, apart from storing it, we are practically no longer permitted to process your personal data.
Pursuant to Art. 20 GDPR, you have the right to data portability. This means you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and to transmit this data to another controller.
Pursuant to Art. 7(3) GDPR, you have the right to revoke a given consent at any time with effect for the future.
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.
In addition, you have a right to object, which we explain in more detail at the end of this privacy notice.
If you wish to exercise your rights, please contact our data protection officer (contact details above).
Competent Supervisory Authority
North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information
Office address: Kavalleriestr. 2 – 4, 40312 Düsseldorf
Postal address: Postfach 20 04 44, 40102 Düsseldorf
Tel.: +49 (0) 211/38424-0
E-mail: poststelle@ldi.nrw.de
Information regarding your right to object under Article 21 of the General Data Protection Regulation (GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(f) of the GDPR (data processing based on a balancing of interests); this also applies to any profiling based on this provision within the meaning of Article 4(4) of the GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
Please submit your objection in writing (by email or post) to our Data Protection Officer (see above for contact details).