1.1. Objective and responsibility
- The purpose of this privacy policy is to inform you about the nature, scope and purpose of the processing of personal data on our website heraeus-comvance.com and the associated websites, functionalities and content (hereinafter collectively referred to as "website"). The privacy notice applies regardless of the systems, platforms and devices (e.g. desktop or mobile) on which the website is made available.
- The provider of the website and legally responsible for it under privacy law is heraeus-comvance.com (hereafter referred to as the “provider”, “we” or “us”). For further details as well as how to contact us, please see the legal information on our website.
- Our Data Protection Officer can be reached via the following email address dataprotection@heraeus.com or by post:
Data Protection Officer
c/o Heraeusstr. 12-14
63450 Hanau
- The term “user” includes all customers and their employees as well as visitors to our website.
1.2. Legal basis
Your personal data is collected and processed on the following legal basis:
- Consent in accordance with Art. 6 (1) (a) of the General Data Protection Regulation (GDPR). Consent is a statement of intent, freely given in a specific instance in an informed and unambiguous manner in the form of a declaration or another unequivocal affirmative act, where the data subjects make it clear that they consent to the processing of their personal data.
- Necessity for the performance of a contract or in order to take steps prior to entering into a contract in accordance with Art. 6 (1) (b) GDPR, i.e., the data is necessary for us to carry out our contractual obligations to users or we need the data in order to prepare a contract with users.
- Processing for compliance with a legal obligation in accordance with Art. 6 (1) (c) GDPR, i.e., the data processing is required on the basis of a law or some other requirement.
- Processing to safeguard legitimate interests in accordance with Art. 6 (1) (f) GDPR, i.e., the processing is necessary to safeguard our legitimate interests or those of a third party, provided the interests do not outweigh the fundamental rights and freedoms of users who require the protection of personal data.
1.3. Data subject rights
You can assert your rights as a data subject with regard to your processed personal data at any time using the contact details of the Data Protection Officer given above. As a data subject, you have the following rights.
- Right to revoke consent: If personal data is processed on the basis of consent, you have the right to revoke this consent at any time for the future in accordance with Art. 7 GDPR.
- Right to information: In accordance with Art. 15 GDPR, you can request confirmation of whether your data is being processed. If this is the case, you have the right to information regarding the information at no charge.
- Right to rectification: If personal data has been processed while incorrect, you have the right, to request that this data be corrected immediately in accordance with Art. 16 GDPR.
- Right to erasure: If you have revoked your consent, objected to the processing of your personal data (and there are no overriding legitimate reasons for the processing), your personal data is no longer necessary for the original purpose of the processing, there is a corresponding legal obligation or personal data has been processed unlawfully, you have the right to request the deletion of their personal data in accordance with Art. 17 GDPR.
- Right to restriction of processing: Under the provisions of Art. 18 GDPR, you have the right to demand that the processing of their personal data be restricted.
- Right to data portability: In accordance with Art. 20 GDPR, you have the right to receive the personal data you provided in a structured, commonly used and machine-readable format.
- Right to object: If processing the personal data is necessary to safeguard the legitimate interests of our company, you can object to the processing at any time in accordance with Art. 21 GDPR.
- Right to file a complaint: In accordance with Art. 77 GDPR, you have the right to lodge a complaint with the responsible supervisory authorities.
1.4. Deletion of data
Your personal data is deleted as soon as the purpose for which it was collected has ceased to exist and there are no other legal or contractual obligations to retain it.
1.5. Security measures
State-of-the-art organizational and technical security measures are in place to ensure compliance with relevant legal provisions and to protect personal data against accidental or intentional manipulation, loss, destruction and unauthorized access.
1.6. Transfer of data to third parties and third-party providers
- We transfer data to third parties exclusively in accordance with legal provisions. We only transfer user data to third parties if necessary (for example, for accounting purposes) or for other purposes necessary to meet our contractual obligations to users or legal requirements.
- Where we use sub-contractors to provide our services, we will take appropriate legal precautions and technical and organizational measures to protect personal data in accordance with applicable legal provisions.
- If, within the scope of this privacy policy, we use content, tools or resources of other providers (hereinafter collectively referred to as “third-party-providers“) whose registered office is in a third country, it must be assumed that data are transferred to such third countries.
- Third countries are countries where the GDPR does not apply directly, i.e., in principle, all countries outside the EU or the European Economic Area. Data may only be transferred to third countries if an adequate level of data protection is ensured, if users have given their consent or if the transfer of such data is permitted by law.
1.7. Obligation to provide personal data
We do not make the conclusion of contracts between you and us dependent on you providing us with personal data beforehand. In principle, there is no legal or contractual obligation for you as a customer to provide us with your personal data; however, it may be that we can only provide certain offers to a limited extent or not at all if you do not provide the necessary data. Should this exceptionally be the case for the offers presented below, you will be informed separately.
1.8. Automated decision-making process
We do not intend to use any personal information collected from you for any automated decision-making process (including profiling).