Data protection

We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions, in particular the EU General Data Protection Regulation (in short GDPR) and this Data Privacy Statement.

In the context of this Data Privacy Statement we would like to inform you about the nature, scope and purpose of the personal data collected, used and processed by us.
Personal data means all information that can be related either directly or indirectly to you personally. These include, for example, your name, your address, your e-mail address, online identifiers and your user behaviour, if it is possible to identify you by means of this information or actions.

On our website we use secure SSL encryption to protect your personal data and other confidential content (e.g. in case of orders or use of our online forms).

If you have any questions regarding the collection, processing or use of your personal data, for information, correction, blocking or deletion of data as well as if necessary, revocation of consents granted or opposition to certain data processing, please contact the controller stated below or our Data Privacy Officer.

I. The name and contact details of the controller

The controller within the meaning of Article 4 No. 7 GDPR, other data protection laws applicable in the Member States of the European Union, as well as other data protection regulations is:

Certrans GmbH
Strandstr. 15
24159 Kiel, Germany

Telephone: +49 431 88 807 75 0
Fax: +49 431 88 807 75 15

E-mail: info@--no-spam--certrans.de

II. Your rights

1.) Below we will inform you about your rights with respect to the personal data concerning you.

You have the right free of charge

  • to request a confirmationas to whether or not personal data concerning you are being processed by us (Article 15 GDPR);
  • to request informationabout your personal data processed by us (Article 15 GDPR). In particular, you may request information concerning the purposes of processing, the categories of personal data concerned, the recipients or categories of recipients, to whom your personal data have been or will be disclosed, the envisaged period for which the personal data will be stored, the existence of the right to request from us rectification or erasure of personal data or restriction of processing or objection, the right to lodge a complaint, the source of your data, where the personal data were not collected by us, as well as on the existence of automated decision-making, including profiling and, where necessary, meaningful information about their details,
  • to obtain without undue delay the rectificationof inaccurate personal data stored with us or to have incomplete personal data completed (Article 16 GDPR),
  • to request erasureof personal data stored with us provided that processing is not necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims (Article 17 GDPR),
  • to request restriction of processingof your personal data from us, where one of the following applies: the accuracy of the personal data is contested by you, the processing is unlawful and you oppose to the erasure of the personal data and we no longer need the personal data, but they are required by you for the assertion, exercise or defence of legal claims or if you have objected to processing pursuant to Article 21 (Article 18 GDPR),
  • to receive the personal data which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmitthose data to another controller (Article 20 GDPR),
  • to withdrawthe consent, you may have granted at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

2.) In case you made claimed your right to rectification, erasure of personal data or restriction of processing toward us, we are obliged to communicate any rectification or erasure of personal data or restriction of processing to all recipients to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. You are also entitled to be informed about those recipients (Article 19 GDPR).

3.) Furthermore, you also entitled to lodge a complaintwith the supervisory authority competent for us (Https://www.datenschutzzentrum.de/) concerning the processing of your personal data by us (Article 77 GDPR).

III. Provision of our website and creation of server logfiles

1.) If you only use our website for information purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. When you access our website, we collect the following data that is technically necessary for us to display our website to you and to ensure the stability and security of our website:

  • IP address;
  • date and time of access;
  • time zone difference to Greenwich Mean Time (GMT);
  • content of the request (of the actual page);
  • access status/HTTP status code;
  • the amount of data transferred in each case;
  • website from which your request comes;
  • websites that you call up while being on our pages;
  • information about the browser type and the version used;
  • operating system and its interface;
  • language and version of the browser software.

These general data and information are stored in the log files of our server only temporarily and separately from your personal data, which you may voluntarily transmit to us. The data and information collected anonymously in the log files are only evaluated statistically by us with the aim of increasing data protection and data security in our company and ensuring an optimum level of protection for the personal data processed by us.

2.) The legal basis for data processing in connection with server log files is Article 6 (1) Sentence 1 (f) GDPR. The data will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected. In the case of the data is collected in order to make the website available, this is the case when you exit the respective session.

The collection of data is absolutely necessary for the provision or our website and the storage in log files is essential for the operation of our website. Therefore, there is no possibility for you to object to this data processing.

IV. Use of cookies

1.) We also use cookies when using our website. Cookies are small text files that are assigned in your browser or by your browser and stored on the hard drive of your computer system.

With cookies we can improve the performance and content of our website. Some cookies are absolutely necessary for the operation of our website. The cookies enable us,

  • to make it easier for you to use our website and to make our offers more effective and user-friendly;
  • to determine whether you are still logged in to your customer account, so that you do not have to enter your access data again;
  • to temporarily store the goods you have placed in the virtual shopping basket;
  • to provide access to protected areas of our website;
  • to record previously entered text so that it is not lost when the page is refreshed.

2.) We use two types of cookies on our website: session cookies and persistent cookies. Session cookies are temporary cookies that are stored on your computer system until you leave our website.

Session cookies store a so-called session ID, which can be used to assign various requests from your browser to a shared session. Session cookies are deleted when you log out or close your browser.

Persistent cookies are stored on your hard drive until you delete them or until the cookies reach their respective expiry date.

We use these persistent cookies to check whether you are still logged in to your customer account (storage period: 14 days). 

3.) In addition to our own cookies, we also use third-party cookies. These are third-party providers, such as Google, who also store cookies on your computer system when you visit our website so that the third-party providers can provide the services they offer. We inform you separately about third party cookies in this Data Privacy Statement.

4.) If personal data are processed by cookies, they are processed in accordance with Article 6 (1) sentence 1 (b) GDPR either to implement the contract or to implement pre-contractual measures, otherwise in accordance with Article 6 (1) sentence 1 (f) GDPR to safeguard our legitimate interests in the best possible functionality of the website.

You can individually configure your browser settings to accept or reject third-party cookies or all cookies. We would like to point out that you may not be able to use all functions of our website if you deactivate the acceptance of cookies in your browser.
 

V. Placing an order

1.) On our website, we offer you the opportunity to place an order with us, providing personal data. For this purpose, the following data (mandatory data) will be collected from you, transmitted to us and stored:

  • Name of the company
  • First name(s), surname(s)
  • Address (street, postcode, place, country)
  • E-mail address
  • VAT ID (mandatory field for companies)

When you register, we also store your IP address as well as the date and time of your registration. Further data (e.g. your telephone number or your position in the company) will only be stored by us if you provide us with this data voluntarily. The personal data you enter will be collected and stored exclusively for our own purposes.

2.) If you wish to place an order with us online, it is necessary for the conclusion of the contract that you provide your personal data in accordance with Section V.1. of this Data Privacy Statement. If you do not provide your data this would have the consequence that you would not be able to use the online order form.

We process the data provided by you to process the order, including our services in the event of revocation, claims for defects and to answer your enquiries.

3.) Your personal data will only be transmitted to third parties if this is necessary for contract and payment processing. Third parties commissioned by us, such as shipping partners and payment service providers, receive only those personal data whose transmission is necessary for the delivery of your order and for payment processing.

4.) If you decide to pay using "PayPal" as part of your order process, your personal data will be automatically transmitted to PayPal. PayPal is an offer of PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. PayPal acts as an online payment service provider and a trustee and offers buyer protection services.

Usually the personal data transmitted to PayPal first name, surname, address, e-mail address, IP address, telephone number, mobile phone number or other data necessary for payment processing. In order to implement the order, personal data related to the respective order are also required (e.g. number of items, item number, invoice amount and taxes and other invoice information).

The transmission of your data is necessary for payment processing via PayPal and is intended to confirm your identity and the administration of your payment order. PayPal may share your personal information with associated companies and service providers or subcontractors provided this is necessary to fulfil the contractual obligations or in case of commissioned data processing.

The personal data transmitted by us to PayPal may be transmitted by PayPal to credit agencies. The purpose of this transmission is to check identity and creditworthiness. Here you can see which credit agencies are involved: www.paypal.com/de/webapps/mpp/ua/privacy-full [in German only]
You have the possibility to object to the processing of your personal data at any time. However, the objection shall not affect the lawfulness of the processing if the personal data have to be processed, used or transmitted for the purpose of processing payments in accordance with the contract.

You can read PayPal's Privacy Statement here: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=en_DE#6

5.) The legal basis for the processing of your data in connection with the fulfilment of a contract or pre-contractual measures is Article 6 (1) sentence 1 (b) GDPR.

6.) Due to regulations under commercial and tax law, we are obliged to store your address, payment and order data in connection with a purchase agreement for a period of up to ten years. However, after two years we will restrict the processing, i.e. your data will only be stored to comply with legal obligations.

VI: E-mail communication

You can contact us at any time via the e-mail address provided by us. In this case only the personal data transmitted by you with the e-mail will be stored. The data will only be used to answer your request.

The legal basis for the processing of the data that you transmit to us within the scope of sending an e-mail is Article 6 (1) sentence 1 (f) GDPR.

We delete the data arising in this connection after the storage is no longer necessary, or restrict the processing if there are statutory storage obligations. You can object to the storage of your personal data at any time by sending an e-mail to the contact details given in section I. In this case however, correspondence cannot be continued.

VII: Use of Google Analytics

1.) Our website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics also uses cookies to help analysing how you use our website. The information generated by the cookie about your use of our website will usually be transmitted to and stored by Google on servers in the United States.

2.) We use Google Analytics with the extension "_anonymizeIp()" in order to guarantee an anonymous collection of IP addresses. Your IP address will therefore only be transmitted to Google in abbreviated form in Member States of the European Union or in other signatory states to the Agreement on the European Economic Area, which does not allow any conclusions to be drawn about your identity.

Only in exceptional cases is the full IP address transmitted to a Google server in the US and truncated there. The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google in this case.

On our behalf, Google will use the information to evaluate your use of our website, to compile reports on website activity for us and to provide other services associated with website activity.
The data collected using Google Analytics is stored for a period of 24 months.

3.) You may prevent the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of our website. You can also prevent Google from collecting the data generated by the cookie and related to your use of our website (including your IP address) as well as the processing of this data by Google by downloading and installing the Google Analytics opt-out browser add-on available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

Alternatively, you can use the following link, which sets an opt-out cookie that prevents Google Analytics from collecting your data in the future when you visit our website:

Disable Google Analytics

You can find more information about Google Analytics at the following links:

Google Analytics Terms of Service: https://www.google.com/analytics/terms/us.html

Data privacy overview: https://policies.google.com/privacy?hl=en

Privacy Statement: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=en_DE#6

4.) We use Google Analytics to analyse and regularly improve the use of our website. The statistics obtained allow us to optimise our services and make them more interesting for you as a user. The legal basis for the use of Google Analytics is Article 6 (1) Sentence 1 (f) GDPR.

For the exceptional cases in which personal data is transferred to the USA, Google participates in the EU-U.S. Privacy Shield, www.privacyshield.gov/EU-US-Framework.

VIII. HotJar analysis service

This site uses the HotJar analysis service to improve usability and customer experience. Mouse clicks as well as mouse and scroll movements can be recorded. Keystrokes made on this website can also be recorded. However, recording does not take place in a personalised way and thus remains anonymous. HotJar does not record this data on pages that do not use the HotJar system. You can deactivate the HotJar service by getting in touch with HotJar using the following link:  https://www.hotjar.com/contact.

IX. Social media plug-ins and Google Maps

We use social media plug-ins from Facebook and XING as well as Google Maps on our websites.

1.) Facebook, XING

a.) The provider of the respective plug-in is shown on the "Share” button either with its initial letter or logo. We offer you the possibility to communicate directly with the provider of the plug-in via the button. Only if you click on a "Share” button and activate it, the plug-in provider receives the information that you have called the corresponding website of our web presence. In this case, the data mentioned under III. will also be transmitted to the plug-in provider. By activating the plug-in, personal data is transferred from you to the respective plug-in provider and stored there.

If you are logged in at the plug-in provider, your data collected by us will be directly allocated to your existing account at the plug-in provider. If you press a "Share” button and e.g. link one of our offers, the plug-in provider also stores this information in your user account and communicates it publicly to your contacts.

b.) We have neither influence on the collected data and data processing procedures, nor are we aware of the full scope of data collection, the purposes of processing or storage periods of plug-in providers. We also have no information concerning deletion of the collected data by the plug-in provider.

c.) The plug-in provider stores the data collected about you as usage profiles and uses these for purposes of advertising, market research and/or needs-based design of its website. Such evaluation is carried out in particular for the purpose of presenting demand-oriented advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles. In order to do so, you have to contact the respective plug-in provider directly.

d.) By means of the plug-ins we offer you the possibility to interact with social networks and other users, so that we can improve our offer and make it more interesting for you as a user. The legal basis for the use of the plug-ins is Article 6 (1) Sentence 1 (f) GDPR.

e.) Further information on the purpose and scope of data collection and processing by the respective plug-in provider can be found in the data privacy statements of these providers provided below. There you will also find further information about your rights and setting options to protect your privacy.

Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA:
https://www.facebook.com/policy.php

Xing AG, Gänsemarkt 43, 20354 Hamburg, Germany:
https://www.xing.com/privacy

The plug-in provider facebook selected by us also processes your personal data in the USA and participates in the EU-U.S. Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.

2. Google Maps

a.) On our website we use the services of Google Maps of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). This enables us to display interactive maps directly on the website and enables you to conveniently use the map function in connection with the services we offer.

b.) When you visit our website, Google receives the information that you have accessed the corresponding page of our website. The data referred to in point III will also be transmitted. This occurs regardless of whether you are logged into your Google user account or no user account exists. When you are logged in to Google, your information will be directly allocated to your account. If you do not want your information to be allocated to your Google account, you must log out before using the map feature. Google stores your data as usage profiles and uses them for purposes of advertising, market research and/or needs-based design of its website. Such evaluation is carried out in particular (even for users not logged-in) for the purpose of providing demand-oriented advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles. In order to do so, you have to contact Google directly.

C) The legal basis for the use of Google Maps is Article 6 (1) Sentence 1 (f) GDPR. Further information on the purpose and scope of data collection and processing by Google can be found in Google's privacy policy: https://policies.google.com/privacy?hl=en-US There you will also find further information about your rights in this context and setting options to protect your privacy. Google processes your personal data in the U.S. and participates in the EU-U.S. Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.

X. Use of Google ReCaptcha

We use Google Analytics on our website. This is a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). This function is used to distinguish between entries made by a natural person and misuse by automatic and automated processing. The service includes the transmission of your IP address and possibly further data required by Google for the service reCAPTCHA to Google.

Through the use of reCAPTCHA we would like to determine whether data are entered by a natural person and thus prevent the misuse of our contact form by spam messages. The legal basis for the use of reCAPTCHA is Article 6 (1) Sentence 1 (f) GDPR.

For more information on the purpose and scope of data collection and processing by Google within the framework of reCAPTCHA please refer to Google's privacy policy: https://policies.google.com/privacy?hl=en-US

There you will also find further information about your rights in this context and setting options to protect your privacy. Google processes your personal data in the U.S. and participates in the EU-U.S. Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
 

XI. Applications and application procedures

We collect and process your personal data for the purpose of processing your application. Processing can also take place electronically if you transmit your application documents electronically, for example by e-mail or via a web form.

The legal basis for the processing of your data Article 6 (1) Sentence 1 (f) GDPR. You can object to the storage of your personal in case of applications and during the application procedure data at any time by sending an e-mail to the contact details given in Section I.

If we enter into an employment contract with you, the data transmitted will be stored for the purpose of processing the employment relationship in compliance with the statutory provisions. If no employment contract is concluded with you, the application documents will be automatically deleted two months after notification of the rejection decision, provided that no other legitimate interests stand in the way of deletion. Another legitimate interest is, for example, our duty to provide evidence in proceedings under the German General Equal Treatment Act (Allgemeines Gleichbehandlungsgesetz, AGG).

XII. Routine deletion and blocking of your personal data

We process and store your personal data only for the period of time necessary to achieve the storage purpose or if this has been provided for in EU directives or regulations or another legislator in laws or regulations to which we are subject. If the storage purpose ceases to apply or if a storage period prescribed by EU directives or regulations or another competent legislator expires, the personal data will be routinely blocked or deleted in accordance with the statutory provisions, unless you have consented to further use of your data.

XIII. Right to object (article 21 GDPR)

If we process your personal data on the basis of our predominant legitimate interest in the context of a weighing of interests in accordance with Article 6 (1) Sentence 1 (f) GDPR, you have the right at any time object to this processing on grounds relating to your particular situation with effect for the future free of charge.

If we process your personal data for direct marketing purposes, you also have the right at any time to object to the processing for the purpose of such advertising with effect for the future free of charge; this also applies to profiling to the extent that it is related to such direct marketing.

Please address your objection to the controller named in Section I or to our Data Protection Officer (2e.g. by e-mail).
 

Translated using DeepL Pro, edited by Heike Demme, legal translator
This translation is copright-procted. Any reproduction or use requires the prior written approval of Certrans GmbH.