Data protection information according to Art. 13 GDPR

Thank you for visiting our website. Andreas Hettich GmbH in Tuttlingen (hereinafter "Hettich", "we" or "us") puts great emphasis on the security of users' data and compliance with data protection regulations. We would like to inform you below about the processing of your personal data on our website.



Name and address of the person responsible

The responsible entity within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:

Andreas Hettich GmbH
Föhrenstraße 12
78532 Tuttlingen
Germany

Contact information:
Phone: +49 7461 705-0
E-Mail: info@hettichlab.com


Name and address of the Data Controller

The data protection officer of the responsible party is:

DDSK GmbH
Dr.-Klein-Str. 29
88069 Tettnang

Contact information:
Phone: +49 7542 949 21 -0
E-Mail: anfragen@ddsk.de

 

General information on data processing

Legal basis for the processing of personal data

In accordance with Article 13 of the GDPR, we inform you about the legal basis for our data processing activities. If the legal basis is not specifically mentioned in the data protection notice, the following applies:

  • The legal basis for obtaining consent is Article 6 (1) (a) in conjunction with Article 7 GDPR.
     
  • The legal basis for processing required for the performance of our services and the execution of contractual measures, as well as for responding to inquiries, is Article 6 (1) (b) GDPR.
     
  • The legal basis for processing to fulfill our legal obligations is Article 6 (1) (c) GDPR.

If the processing of your data is necessary to safeguard a legitimate interest of our company or a third party, and this interest is not overridden by your interests, fundamental rights, or freedoms, then Article 6 (1) (f) GDPR serves as the legal basis for the processing.

In cases where the processing of personal data is necessary to protect the vital interests of the data subject or another natural person, Article 6 (1) (d) GDPR serves as the legal basis.

 

Data deletion and storage duration

We adhere to the principles of data minimization according to Article 5 (1) (c) GDPR and storage limitation according to Article 5 (1) (e) GDPR.

We only store your personal data for as long as necessary to achieve the purposes mentioned or as required by statutory retention periods. Once the purpose of processing no longer applies or the retention periods expire, the relevant data will be deleted as quickly as possible.

 

Notice on data transfer to third countries

Our website also includes tools from companies based in third countries. When these tools are active, your personal data may be transmitted to the servers of these companies. The level of data protection in third countries generally does not meet the EU data protection standards. This means there is a risk that your data may be transferred to authorities in these countries. We have no influence over these processing activities.


External links

This website may contain links to third-party websites or other websites under our responsibility. When you follow a link to a website outside of our responsibility, please be aware that these websites have their own privacy policies. We are not responsible or liable for these external websites and their privacy notices. Therefore, before using these websites, check whether you agree with their privacy policies.

External links are either visually distinct from the rest of the text or underlined. Your cursor will indicate external links when you hover over them. Only when you click on an external link will your personal data be transferred to the destination of the link. This includes, in particular, your IP address, the time you clicked the link, the page on which you clicked the link, and other information that you can find in the privacy notices of the respective provider.

Please also note that some links may lead to data transfers outside the European Economic Area. This could allow foreign authorities to access your data. You may not have legal remedies against such data access. If you do not want your personal data to be transferred to the destination or exposed to unwanted access by foreign authorities, please do not click on the links.

 

Rights of the data subject

As a data subject under the GDPR, you have the opportunity to exercise various rights. The rights arising from the GDPR are the Right of Access (Article 15), the Right to Rectification (Article 16), the Right to Erasure (Article 17), the Right to Restriction of Processing (Article 18), the Right to Object (Article 21), the Right to Lodge a Complaint with a Supervisory Authority and the Right to Data Portability (Article 20).

Right of withdrawal: 
Some data processing activities may only occur with your explicit consent. You have the right to withdraw your consent at any time. This withdrawal does not affect the lawfulness of the data processing carried out until the withdrawal.

Right to object: 
If the processing is based on Article 6 (1) (e) or (f) GDPR, you, as the data subject, can object to the processing of your personal data at any time for reasons arising from your particular situation. This right also applies to profiling based on these provisions (Article 4 (4) GDPR). If we cannot demonstrate a legitimate interest for the processing that outweighs your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims, we will cease processing your data upon receipt of your objection.

If the processing of personal data is for the purpose of direct marketing, you also have the right to object at any time. The same applies to profiling related to direct marketing. In such cases, we will cease processing your personal data once you object.

Right to lodge a complaint with a supervisory authority:
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. This is without prejudice to any other administrative or judicial remedy and can be done with a supervisory authority in the Member State of your residence, your place of work, or the place of the alleged infringement.

Right to data portability:
If your data is processed automatically based on consent or the fulfillment of a contract, you have the right to receive this data in a structured, commonly used, and machine-readable format. You also have the right to request the transfer and provision of this data to another controller, where technically feasible.

Right to access, rectification, and erasure:
You have the right to obtain information about your processed personal data, including the purpose of processing, categories of data, recipients, and the duration of storage. If you have any questions regarding this or other matters related to personal data, you may contact us using the contact details provided in the imprint.

Right to restriction of processing:
You may request the restriction of processing your personal data at any time if one of the following conditions applies:

  • You dispute the accuracy of the personal data. You have the right to request a restriction of processing while the accuracy is being verified.
  • If the processing is unlawful, you can request the restriction of data usage instead of erasure.
  • If we no longer need your personal data for processing purposes, but you need the data for the establishment, exercise, or defense of legal claims, you can request the restriction of processing instead of erasure.
  • If you object to processing under Article 21 (1) GDPR, an assessment will be made between your and our interests. Until this assessment is complete, you have the right to request the restriction of processing.


A restriction of processing means that the personal data, aside from storage, may only be processed with your consent, for the establishment, exercise, or defense of legal claims, to protect the rights of another natural or legal person, or for reasons of substantial public interest of the Union or a Member State.


Provision of the website (web host)

Our website is hosted by:

Everscale GmbH
Jordanstraße 26A, 30173 Hannover
Germany

When you visit our website, we automatically collect and store information in what are known as server logfiles. This information is automatically transmitted by your browser to our server or to the server of our hosting company.
The information collected includes:

  • IP address of the device used by the website visitor
  • Device used
  • Hostname of the accessing computer
  • Operating system of the visitor
  • Browser type and version
  • Name of the accessed file
  • Time of the server request
  • Amount of data
  • Information on whether the data retrieval was successful

     

This data is not combined with other data sources.

Instead of hosting this website on our own server, we may use the server of an external service provider (hosting company), which is mentioned above. The personal data collected by this website is then stored on the servers of the hosting company. In addition to the data mentioned above, the web hoster also stores, for example, contact inquiries, contact details, names, website access data, meta and communication data, contract data, and other data generated through a website.

The legal basis for processing this data is Article 6 (1) (f) GDPR. Our legitimate interest is the technically error-free presentation and optimization of this website. If the website is accessed for the purpose of entering into contractual negotiations or concluding a contract with us, Article 6 (1) (b) GDPR serves as an additional legal basis. In the event that we have engaged a hosting company, there is a processing agreement with this service provider.


Use of local storage items, session storage items and cookies

Our website uses Local Storage Items, Session Storage Items, and/or Cookies. Local Storage is a mechanism that allows data to be stored within the browser on your device. This data typically includes user preferences, such as the "day" or "night mode" of a website, and is retained until you manually delete it. Session Storage is very similar to Local Storage, except that the data is only retained during the current session, i.e., until you close the current tab. After that, Session Storage Items are deleted from your device. Cookies are pieces of information that a web server (the server providing web content) stores on your device to identify it. They can be either temporary (session cookies) and are deleted after your visit to a website, or permanent (persistent cookies) and remain on your device until you delete them or they are automatically deleted by your web browser.

These objects can also be stored on your device by third parties when you visit our site (third-party requests). This enables us as the operator and you as the visitor to use certain third-party services installed on this website, such as payment processing services or video display.

These mechanisms have various uses. They can improve the functionality of a website, manage shopping cart functions, increase the security and comfort of website usage, and conduct analysis regarding visitor flows and behavior. Depending on the specific functions, they are classified under data protection regulations. If they are necessary for the operation of the website and to provide certain functions (e.g., shopping cart functionality), their use is based on Article 6 (1) (f) GDPR. As website operators, we have a legitimate interest in storing Local Storage Items, Session Storage Items, and Cookies for the technically error-free and optimized provision of our services. In all other cases, the storage of Local Storage Items, Session Storage Items, and Cookies is only done with your explicit consent (Article 6 (1) (a) GDPR).

If Local Storage Items, Session Storage, or Cookies are used by third parties or for analytical purposes, we will inform you separately within this privacy notice. Your required consent will be requested and can be withdrawn at any time.


Use of External Services

Our website employs external services. External services are those provided by third parties that are used on our website. This can be for various reasons, such as embedding videos or enhancing website security. When using these services, personal data may also be shared with the respective providers of these external services. If we do not have a legitimate interest in using these services, we will obtain your consent as a visitor to our website before using them. This consent can be withdrawn at any time (Article 6 (1) (a) GDPR).


Consent Management

To comply with data protection requirements, we use a consent management tool on our website. This tool is used to obtain the necessary consents for setting cookies or using external services. The consents are stored.

The processing is required to fulfill a legal obligation to which the controller (website operator) is subject. Therefore, the legal basis for processing is Article 6 (1) (c) GDPR.


Consent Manager

We use the Consent Manager service on our website. The service provider is:

consentmanager AB
Håltegelvägen 1b,
72348 Västerås,
Sweden

Further information can be found in the provider’s privacy notice at the following URL:
https://www.consentmanager.de/datenschutz/

The service uses cookies on our website and stores data in the local or session storage of the browser:

 

 

 

Content Delivery Network (CDN)

  • We use a Content Delivery Network (CDN) to optimize the performance and availability of our website. For this purpose, the service provider of this network processes your IP address as well as information about when you visited our website. All further information on data processing by this service provider can be found in their privacy notices.
  •  
  • We base this processing on a legitimate interest (Article 6 (1) (f) GDPR). 
  •  
  • Our legitimate interest in using a CDN is to ensure that our website is delivered as quickly, securely, and reliably as possible.

     
  • Google Static

    We use the Google Static service on our website. The service provider is Google Ireland Limited,  Gordon House, Barrow Street, Dublin 4, Ireland.

    Using this service may involve data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.

    Further information can be found in the provider’s privacy notice at the following URL:
    https://policies.google.com/privacy


  • Hosting

  • Hosting refers to the provision of web space and the files located on it by a web host. 
  •  
  • This involves the transmission and storage of personal data on the web host’s servers. In particular, IP addresses, meta and communication data of users, and data about website access are processed. When a visitor accesses the website, a connection is established to the web host’s servers, resulting in the processing of personal data of the website visitor.
  •  
  • We base this processing on a legitimate interest (Article 6 (1) (f) GDPR). 
  •  
  • Our legitimate interest is to be able to display our website and make it available on the Internet.

 

Alibaba Cloud

 

Interface software

  • Business processes run more cost-effectively, quickly, and error-free when they are automated using software through interfaces. This allows them to be efficiently integrated into business processes via your website or social networks. We use interface software on our website to connect various applications and securely transfer personal data from one application to another.
  • Processing only occurs if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Article 6 (1) (a) GDPR). Without your consent, the data processing as described above will not occur. If you withdraw your consent (e.g., through the consent banner or other options provided on this website), we will cease this data processing. The legality of the processing that occurred prior to the withdrawal remains unaffected.

 

Google APIs

  • We use the Google APIs service on our website. The service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
  • Using this service may involve data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.
  •  
  • Further information can be found in the provider’s privacy notice at the following URL: https://policies.google.com/privacy

 

Google Tag Manager

We use the Google Tag Manager service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The use of the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and thus offers an adequate level of data protection.

Further information can be found in the provider's privacy policy at the following URL: https://policies.google.com/privacy.

 

Sales platforms

By implementing elements from sales platforms, the purchase of products on our website or redirection to a provider's website is possible. This involves processing personal data such as name and delivery address.

Processing only occurs if you consent to this data processing (through our consent banner on the website). The legal basis for this processing is consent (Art. 6 (1) (a) GDPR). Without your consent, the data processing described above will not occur. If you withdraw your consent (e.g., through the consent banner or other options provided on this website), we will stop this data processing. The legality of the processing carried out before the withdrawal remains unaffected.


Google Play

We use the Google Play service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Using the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and thus offers an adequate level of data protection. Further information can be found in the provider's privacy policy at the following URL: https://policies.google.com/privacy.


Taobao

We use the Taobao service on our website. The provider of the service is AliCloud (Germany) GmbH, Wiesenhüttenplatz 25, 60329 Frankfurt am Main, Germany. Using the service may result in data transfer to a third country (China). Further information can be found in the provider's privacy policy at the following URL: https://www.alibabacloud.com/help/en/legal/latest/alibaba-cloud-international-website-privacy-policy.

 

Video/Music Services

Our website integrates audio and video content. These are retrieved from the server of our provider, the so-called audio or video platform. To play an audio or video file, your device establishes a connection with the audio or video platform and transmits personal data to it. This includes, in particular, the IP address, potential location data, and information about the browser and device used.

Data processing only occurs if you consent to it (via our consent banner on the website). The legal basis for this processing is consent (Art. 6 (1) (a) GDPR). Without your consent, this data processing will not occur. If you withdraw your consent (e.g., through the consent banner or other options provided on this website), we will stop this data processing. The legality of processing that occurred before the withdrawal remains unaffected.

 

Youku

We use the Youku service on our website. The provider of the service is Youku Tudou Inc., 11/F, SinoSteel Plaza, 8 Haidian Street, Haidian District, Beijing, Beijing 100080, China.

Using the service may result in data transfer to a third country (China). Further information can be found in the provider's privacy policy at the following URL: https://terms.alicdn.com/legal-agreement/terms/suit_bu1_unification/suit_bu1_unification202005141916_91107.html?spm=a2hja.14919748_WEBHOME_NEW.footer-container.5555!2DL5A!4.

The service stores the following data in the local or session storage of the browser:

NameDurationTypePurpose
APLUS_S_CORE_0.21.108_20240718161046_1bb1e2edPersistent3rd-Party LocalStorage, player.youku.comStored by Youku on the local device.
APLUS_LS_KEYPersistent3rd-Party LocalStorage, player.youku.comRegisters statistical data about visitor behavior on the website. Used by the website operator for internal analytics.
  •  

 

YouTube

We use the YouTube service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Using the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and thus offers an adequate level of data protection. Further information can be found in the provider's privacy policy at the following URL: https://policies.google.com/privacy.

The service stores the following data in the local or session storage of the browser:

NameDurationTypePurpose
-556df46621c69b2 [9]Session3rd-Party SessionStorage, www.youtube-nocookie.comStored by YouTube on the local device.
-1e2f14ad-48f4a7feSession3rd-Party SessionStorage, www.youtube-nocookie.comStored by YouTube on the local device.
-4967ec7b-2f772f2fSession3rd-Party SessionStorage, www.youtube-nocookie.comStored by YouTube on the local device.
-735b0d7d-32c306edSession3rd-Party SessionStorage, www.youtube-nocookie.comStored by YouTube on the local device.
18aed84e-456c8568[5]Session3rd-Party SessionStorage, www.youtube-nocookie.comStored by YouTube on the local device.
2580006f40bcaa73[6]Session3rd-Party SessionStorage, www.youtube-nocookie.comStored by YouTube on the local device.
iU5q-!O9@$Session3rd-Party SessionStorage, www.youtube-nocookie.comStored by YouTube on the local device.
yt-remote-cast-installedSession3rd-Party SessionStorage, www.youtube-nocookie.com
  • Used by YouTube to enable tracking based on geographical GPS location, estimate bandwidth, track statistics, and monitor user preferences when viewing an embedded YouTube video. These cookies do not collect information to identify a user.
  •  
yt-remote-connected-devicesPersistent3rd-Party SessionStorage, www.youtube-nocookie.comThis HTML storage key is used to control the behavior of the embedded YouTube video player.
yt-remote-device-idPersistent3rd-Party SessionStorage, www.youtube-nocookie.comStores user settings when retrieving an embedded YouTube video on other websites.
yt-remote-fast-check-periodSession3rd-Party SessionStorage, www.youtube-nocookie.comUsed to regulate the behavior of the embedded YouTube video player.
yt-remote-session-appSession3rd-Party SessionStorage, www.youtube-nocookie.comThis HTML storage key is used to control the behavior of the embedded YouTube video player.
yt-remote-session-nameSession3rd-Party SessionStorage, www.youtube-nocookie.comStores user preferences for the video player with embedded YouTube videos.
yt.innertube::nextIdPersistent3rd-Party LocalStorage, www.youtube-nocookie.comRecords a unique ID to track statistics on which YouTube videos the user has watched.
yt.innertube::requestsPersistent3rd-Party LocalStorage, www.youtube-nocookie.comRecords a unique ID to track statistics on which YouTube videos the user has watched.
ytidb::LAST_RESULT_ENTRY_KEYPersistent3rd-Party LocalStorage, www.youtube-nocookie.comStores user preferences for the video player that uses an embedded YouTube video.

 

Webfonts

This site uses webfonts provided by an external provider to ensure consistent font representation. When you access the website, your browser loads these webfonts, and the provider of the webfonts becomes aware that our website was accessed from your IP address because your browser establishes a direct connection to the webfont provider.

Data processing only occurs if you consent to it (via our consent banner on the website). The legal basis for this processing is consent (Art. 6 (1) (a) GDPR). Without your consent, this data processing will not occur. If you withdraw your consent (e.g., through the consent banner or other options provided on this website), we will stop this data processing. The legality of processing that occurred before the withdrawal remains unaffected.

Google Fonts

We use the Google Fonts service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Using the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and thus offers an adequate level of data protection. Further information can be found in the provider's privacy policy.