1. The data controller
Heinzmann GmbH & Co. KG
Am Haselbach 1
Telephone: +49 7673 8208-0
Telefax: +49 7673 8208-188
2. Contact details of the Data Protection Officer
Telephone: +49 711 4605025-40
Telefax +49 711 4605025-49
3. Legal bases
We process personal data based on at least one of the following legal bases:
- The data subject has given consent to the processing of his or her personal data for one or more specific purposes (Art. 6 (1)(a) GDPR);
- Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR);
- Processing is necessary for compliance with a legal obligation to which we are subject (Art. 6 (1)(c) GDPR);
- Processing is necessary in order to protect the vital interests of the data subject or of another natural person (Art. 6 (1)(d) GDPR);
- Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party
(Art. 6 (1)(f) GDPR).
4. Onward transfer of personal data
We forward personal data to recipients (data processors or other third parties) only to the extent required and only if one of the subsequent conditions are met:
- The data subject has consented to the data transfer;
- The onward transfer is required to fulfil a contractual obligation or pre-contractual measure on the request of the data subject;
- We are obliged by law to make such a transfer;
- The onward transfer is made on the basis of our legitimate interest or those of a third party.
5. Third countries
The transfer of personal data to a third country or an international organisation outside the EU or the
European Economic Area (EEA) is subject to legal or contractual permission only in accordance with the
provisions under Art. 44 et seq. GDPR. Pursuant to Art. 45 GDPR an adequacy decision of the EU commission must be present for the respective country, or appropriate safeguards for data privacy under Art. 46 GDPR, or Binding Corporate Rules under Art. 47 GDPR must exist. In individual cases, a data transfer may be permitted on the basis of an exception under Art. 49 DPR.
We may use on our website external services provided by organisations based in the USA. If these services
are active, personal data is collected in connection with the provision of the relevant service and may be
transferred to and stored on servers in the USA. The European Court of Justice considers the USA to have an inadequate level of data protection. When data is transferred to the US, there is a fundamental risk that the US authorities may access and use the data for surveillance and monitoring purposes without notification and without the possibility of a legal remedy.
6. Rights of data subjects
As a data subject you have the following right:
- Pursuant to Art. 15 GDPR to request information about your personal data processed by us. You may also request information regarding the purposes of the processing, the categories of personal data
concerned, the recipients or categories of recipients to whom the personal data have been or will be disclosed, the envisaged period for which the personal data will be stored or the criteria used to determine that period, the data source (where personal data is not collected from you), the existence
of automated decision-making, including profiling, and meaningful information about the logic involved,
as well as the significance and the envisaged consequences of such processing; the existence of the right to request rectification or erasure of data concerning you, the right to restrict processing or to object to such processing, the right to lodge a complaint with a supervisory authority. Finally, you have a right to know whether personal data has been transferred to a third country or to an international organisation, and, if so, the appropriate safeguards relating to this transfer;
- Pursuant to Art. 16 GDPR to demand the immediate rectification of inaccurate personal data and to have incomplete personal data which is stored by us completed;
- Pursuant to Art. 17 GDPR to demand the erasure of your personal data stored by us, unless the
processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of a legal claim.
- Pursuant to Art. 18 GDPR to request the restriction of the processing of your personal data if the accuracy of the personal data is contested by you; the processing is unlawful but you oppose the erasure of the personal data and request the restriction of their use instead; we no longer need the
personal data for the purposes of the processing but they are required by you for the establishment, exercise or defence of legal claims; you have objected to processing pursuant to Art. 21 (1) GDPR pending the verification whether our legitimate grounds override your interests;
- Pursuant to Art. 20 GDPR to receive your personal data, which you have provided for us, in a structured,
commonly used and machine-readable format and have the right to transmit this data to another controller;
- Pursuant to Art. 21 GDPR to object to the processing of your personal data on grounds relating to your
particular situation, or if you object to processing for direct marketing purposes and the legal basis for
processing is our legitimate interests pursuant to Art. 6 (1)(f) GDPR;
- Pursuant to Art. 7 (3) GDPR to withdraw your consent given to us at any time. As a result, we are no
longer allowed to continue to process the data that was based on this consent in the future;
- Pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. A list of contact details of the data protection officers and supervisory authorities can be found on this website: https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-node.html.
If you wish to assert the data subject rights mentioned above, you can contact us or our data protection officer at any time using the contact details above.
7. Erasure and restriction of personal data
Unless otherwise provided for in this privacy notice, personal data will be deleted, if this data is no longer
necessary in relation to the purposes for which they were collected or otherwise processed and the deletion
does not conflict with statutory retention requirements. In addition, we will erase the personal data processed
by us in accordance with Art. 17 GDPR on your request, if the conditions provided therein are met. If personal
data are required for other lawful purposes, they will not be erased, but their processing will be restricted in
accordance with Art. 18 GDPR.
effective and secure.
We use the following cookies on our website:
8.1 Necessary Cookies
The data processed by necessary cookies are required for the aforementioned purposes to protect our legitimate interests and those of third parties in the provision and operation of our website under Art. 6 (1)(f) GDPR in connection with section 25 (2) No. 2 TTDSG.
Purpose: Google Analytics: throttles the request rate to limit data collection on high traffic websites.
Expires: 10 minutes
Sample content: 1
Purpose: This cookie saves whether the cookie banner is hidden.
Expires: 1 month
Sample content: 1
Purpose: Saves the selected language in which the web page is to be displayed.
Expires: 8 months
Sample content: 1
Name: Session ID
8.2 Cookies for tracking and statistics
Purpose: Standard Joomla cookie for saving the login state.
Expires: End of session
Sample content: 1
Purpose: Google Universal Analytics. Differentiation of unique users by randomly generated number as client ID. Used to identify returning visitors, calculate visitor, session and campaign data.
Expires: 2 years
Sample content: GA1.3.1369932704.1580458261
Further information: https://policies.google.com/privacy?hl=en
Purpose: Google Universal Analytics.Used to distinguish users.
Expires: 24 hours
Sample content: GA1.3.1183256634.1586250684
Further information: https://developers.google.com/analytics/devguides/collection/analyticsjs/
Most browsers accept cookies automatically. However, if you do not wish to accept cookies, you can configure your browser so that no cookies are stored on your device or a message is displayed before new cookies are created. Information on how to remove cookies in Internet Explorer/Edge, please refer to: https://support.microsoft.com/en-gb/windows/delete-and-manage-cookies-168dab11-0753-043d-7c16-ede5947fc64d. Information on the removal of cookies in Firefox, please refer to: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox?redirectlocale=en-US&redirectslug=delete-cookies-remove-info-websites-stored. Learn how to
remove cookies in Safari here: https://support.apple.com/en-gb/guide/safari/sfri11471/mac.
services, as explained at http://www.youronlinechoices.com/ or the opt-out page of the Network Advertising Initiative http://optout.networkadvertising.org. However, disabling cookies may mean that you may not be able to use all the features of our website.