Data Protection Statement

The protection of your personal information is important to us, particularly with regard to upholding the right to privacy when processing and using this information. The following provides information about the collection of personal information when you use our website. Personal information is all information which can be personally traced to you, such as your name, address, email addresses, user behavior.

Name and contact details of the controller according to art. 4 para.7 GDPR
Edelmann GmbH
Steinheimer Straße 45
D-89518 Heidenheim
Tel.: +49 7321 340-0
E-Mail: info@edelmann-group.com 

Contact details of the data protection officer:
Edelmann GmbH
Attn: to the data protection officer
Steinheimer Straße 45
D-89518 Heidenheim
E-Mail: datenschutz@edelmann-group.com

Information on data security
This site uses SSL encryption for security reasons and to protect the transmission of confidential content, such as the requests you send to us as site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If the SSL encryption is activated, the data that you send to us cannot be read by third parties.

We also use suitable technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.

We would like to point out that data transmission over the Internet (e.g. communication by e-mail) may be subject to security gaps. It is therefore not possible to completely protect data from access by third parties.

1. purposes and legal basis of the processing of personal data

 

Contact by e-mail or contact form

Purposes of processing
If you send us a message by e-mail or via a contact form, the data you provide will be stored by us and used to process your message and contact you. We will not pass on your data to third parties without your express consent.

Legal basis for processing
The legal basis for the collection and processing of your data is Art. 6 para. 1 lit. b GDPR (implementation of pre-contractual measures), as well as Art. 6 para. 1 lit. a GDPR (consent), if applicable, if we have requested this.  

Groups of persons affected
Website visitors

Processed data
Name, address data, contact data, function in the company, your message 

Duration of storage
The personal data collected in the course of responding to your inquiry will be deleted as soon as storage is no longer required or processing will be restricted if there are legal obligations to keep records. If you revoke the consent you gave us to process your data, your data will be deleted immediately after your revocation.

2. Careers page

 

Purposes of processing 
You can use our careers page to apply speculatively or for particular employment opportunities. Your data transmitted to us in this process will only be processed within the scope of the respective job advertisement or within the scope of your consent to be considered for further job offers. If you have given us your consent to be considered for further job offers, you can revoke this consent at any time with effect for the future.

Note on sensitive data: we expressly inform you that applications, in particular CVs, certificates and other information transmitted to us by you may contain especially sensitive information about mental and physical health, racial or ethnic background, political opinions, religious or philosophical convictions, memberships of unions or political parties or concerning sexual activity. Please note that such data that you send us by e-mail is transmitted unencrypted.

Legal basis for processing
The legal basis for the collection and processing of your personal data is Art. 6 para. 1 lit. b GDPR, §26 BDSG (fulfilment of contracts or pre-contractual measures at the request of the person concerned or establishment of employment relationships), as well as Art. 6 para. 1 lit. a GDPR, if applicable, if you have given us your consent to be considered for further job offers. If you have provided your consent for processing your application data, you can withdraw this at any time.

Groups of persons affected
Website visitors, applicants

Processed data
Names, addresses, contact data, e-mail address, submitted application documents

Duration of storage
In the event of rejection or negative reply to your application, the data transmitted will be deleted at the earliest 3 months after the end of the application process, but at the latest after 6 months. This does not apply if legal regulations oppose the deletion or if further storage is necessary for the purpose of providing evidence or if you have agreed to longer storage. If you have consented to longer-term storage, we will process your data for the purpose of selecting applicants for further job advertisements over a maximum period of 2 years. Your data will be deleted after this period or if you withdraw your consent.
 

3. use of our website

 

Purposes of processing
Like every website, our server automatically and temporarily collects information in server logfiles communicated by your browser. When you choose to view our website, we collect this data which are technically required by us in order to correctly display our website and guarantee its stability and security. The server logfiles are not analyzed for any personal information. At no point is this information attributable to particular individuals by the website provider. We do not combine this information with other sources of information.

Legal basis for processing
The legal basis for the collection and processing of your personal data is our legitimate interest according to Art. 6 para. 1 lit. f GDPR. The processing is necessary to provide you with the website and to ensure the stability and security of the services or to enable communication. In individual cases, the data collected in this context may be used, for example, to determine and rectify malfunctions as well as to clarify, ward off and pursue attempted attacks.

Affected groups of persons
Website visitors

Processed data
IP address of the requesting computer, date and time of the page request, content of the request, access status / HTTP status code, amount of data transferred in each case, website from which the request originates (referrer website), web browser used with version number and set language, operating system used and any interface used.

Duration of storage
Log data generated by the system on the web server is stored for a period of 30 days. After this period an automated deletion will take place.

4. analysis of usage data using Google Analytics

 

Purposes of processing
To analyze usage data and to improve and optimize the content of our website, we use the service Google Analytics, a web analysis service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Through the use of Google Analytics, we, as website operators, can analyze the behavior of the users of our website. In doing so, we obtain various usage data such as page views, length of stay, technical information such as the operating system or web browser used and the approximate geographical origin of the user.

This data may be summarized by Google in a profile and assigned to the user or the terminal device used. Google uses technologies such as cookies or device fingerprinting, which enable recognition for the purpose of analyzing usage behavior. The information thus generated about your use of this website is usually transferred to a Google server in the USA and stored there. We would like to point out, however, that your IP address will be truncated by Google in member states of the European Union or in other signatory states to the Agreement on the European Economic Area before this happens. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. The IP address transmitted by your browser within the scope of Google Analytics is not merged with other data from Google. You can find more information on terms of use and data protection at https://www.google.com/analytics/terms/gb.html or https://policies.google.com/?hl=en.

On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage.

Legal basis for processing
The data processing is carried out on the legal basis of Art. 6 para. 1 lit. a GDPR (consent) as well as our legitimate interest according to Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the optimization of our online offer and our web presence. Since the privacy of our visitors is particularly important to us, the IP address is anonymized by Google as soon as possible.

You can revoke any consent you have given at any time with effect for the future by preventing the storage of cookies by means of a corresponding setting in your browser software or by revoking your consent via the link "Cookie settings" in the footer of our website.

You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser add-on. Opt-out cookies prevent the future collection of your data when visiting this website. To prevent Universal Analytics from collecting data across multiple devices, you must opt-out on all systems in use. Click here to set the opt-out cookie: Disable Google Analytics

 

We have concluded a contract with Google for commissioned data processing and fully implement the strict requirements of the GDPR when using Google Analytics.

Affected groups of persons
Website visitors

Processed data
Abbreviated IP address, digital fingerprints, geo-information, hashed mobile device identification numbers, usage data (e.g. websites visited, interest in content, access times)

Duration of storage
Data sent by us and linked to cookies, user IDs (e.g. User ID) or advertising IDs are automatically deleted after 14 months. Data whose retention period has been reached is automatically deleted once a month.

5. use of Google Maps

 

Purposes of processing
For the purpose of providing directions and to make it easy to find the places we indicate on the website, we use the Google Maps service, which is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. By using Google Maps, your IP address is usually transferred by Google to the USA and processed or stored there. Further information on the handling of user data by Google can be found in the Google data protection information at https://policies.google.com/privacy?hl=en. The terms of use of Google Maps can be found at https://www.google.com/intl/en/help/terms_maps/.

Legal basis for processing
The legal basis for the collection and processing of your personal data is Art. 6 para. 1 lit. f GDPR, i.e. our legitimate interest in making our company or locations easy to find.

Groups of persons affected
Website visitors

Processed data
Information on the scope of data collection can be obtained from the service provider at https://policies.google.com/privacy?hl=en.

Duration of storage
Information on the duration of data storage can be obtained from the service provider at https://policies.google.com/privacy?hl=en.

6. use of Google reCAPTCHA

 

Purposes of processing
In order to prevent misuse of data transmitted via our web forms, we use the service reCAPTCHA from Google Inc. This is mainly to distinguish whether the input and sending of data is done by a natural person or abusively by machine and automated processing.

Legal basis for processing
Google reCAPTCHA is used to protect against misuse of our contact forms and represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.

Affected groups of persons
Website visitors

Processed data
Information on the scope of data collection can be obtained from the service provider at https://policies.google.com/privacy?hl=en.

Duration of storage
Information on the duration of data storage can be obtained from the service provider at https://policies.google.com/privacy?hl=en.

 

7. use of Google Web-Fonts

 

Purposes of processing
This site uses so called web fonts, which are provided by Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly. For this purpose, the browser you use must connect to Google's servers. This enables Google to know that our website has been accessed via your IP address.    

If your browser does not support web fonts, a standard font is used by your computer. In this case, however, the correct display of the website cannot be guaranteed. You can find more information about Google Web Fonts at https://developers.google.com/fonts/faq and in the Google privacy policy: https://policies.google.com/privacy?hl=en.

Legal basis for processing
The use of Google Web Fonts is in the interest of a uniform and attractive presentation of our online offers. This represents a legitimate interest in the sense of Art. 6 para. 1 lit. f GDPR. 

Groups of persons affected
Website visitors

Processed data
IP address

Duration of storage
Information on the duration of data storage can be obtained from the service provider at https://policies.google.com/privacy?hl=en.

8. use of the Google Tag Manager

 

Purposes of processing
On some pages of our website we use the Google Tag Manager. The Google Tag Manager is a solution that allows us to manage website tags through an interface. The Tag Manager tool itself (which implements the tags) does not collect any personal data. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If disabled at the domain or cookie level, it will remain disabled for all tracking tags implemented by Google Tag Manager.

Legal basis for processing
The use of Google Tag Manager is in the interest of a centralized management of website tags in our web presence. This represents a legitimate interest in the sense of Art. 6 para. 1 lit. f GDPR.

Affected groups of persons
Website visitors

Processed data
Information on the scope of data collection and the duration of data storage can be obtained from the service provider at https://policies.google.com/privacy?hl=en.

9. information on the use of cookies

 

In addition to the above-mentioned services, we also use cookies, which are absolutely necessary for the operation of our pages, and so-called functional cookies, which enable us, among other things, to store information already entered (e.g. user name, language selection, contents of form fields, etc.). These cookies therefore increase the comfort when visiting our website.

Cookies are small text files that your web browser stores on your computer or mobile device. Cookies do not damage your computer/mobile device and do not contain viruses.

Most of the cookies we use are deleted from your hard drive at the end of the browser session (so-called session cookies). Other cookies remain on your computer and enable us to recognize your computer during your next visit (so-called permanent cookies).

The legal basis for the use of these cookies is our legitimate interest in a technically error-free and optimized provision of our services in accordance with Art. 6 Par. 1 lit. f GDPR.

You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for specific cases or generally, and activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, however, the functionality of this website may be limited.

For the purpose of permanent deactivation, you can restrict the use of cookies in your browser settings. Below you will find information on how to deactivate cookies in the most common desktop browsers:

Microsoft Internet Explorer
Mozilla Firefox
Google Chrome
Apple Safari
Opera

Furthermore, it is possible to prevent the setting of cookies by browser plug-ins such as “Ghostery”.

10. Data protection information on the processing of personal data (Facebook Insights) when you visit our Facebook pages

 

We process statistical data of different categories such as the number of page views, page activity, "Like" information, demographic information such as age, gender, approximate geographic origin, visiting hours, etc. through the so-called "Insights" of our Facebook page. This data is purely statistical and does not allow any conclusion to be drawn about a natural person. We have no influence on the collection and processing of this data by Facebook and cannot prevent it.

We use the information provided by Facebook only in aggregated and anonymous form. The legal basis for the processing of this data is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to optimize our offer on our Facebook page.

Further data usage by Facebook
Facebook Ireland, Ltd. (Dublin) and Facebook Inc. (Menlo Park, USA) also process data from users who access the pages and / or interact with them according to the current status and our knowledge for the following purposes: Advertising (data analysis and display of personalized advertising), Creation of user profiles and market research. Facebook uses cookies to store and further process the information. Further information on data collection and storage by Facebook can be found in the Facebook data protection declaration: www.facebook.com/about/privacy/.

Facebook grants you various possibilities of objection (opt-out). You can set these using the following links: https://www.facebook.com/settings?tab=ads and www.facebook.com/ads/preferences/

Please also note the information page at https://www.youronlinechoices.com/de/

We draw your attention to the fact that when using the Facebook services, further processing and transfer of personal data to so-called third countries such as to the USA. The USA is not a safe third country in terms of EU data protection law. US companies are obliged to surrender personal data to security authorities without you as the person concerned being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g. secret services) process, evaluate and permanently store your data on US servers for monitoring purposes. We have no influence on these processing activities.

Your rights
If you have any questions regarding the storage of your data by Facebook, we recommend that you contact Facebook directly. You can download a copy of your Facebook information directly from your Facebook user profile. You can find further information here: https://www.facebook.com/help/1701730696756992/?helpref=hc_fnav

If you wish to assert your rights against us with regard to the provision of information, correction or deletion of Insights data, as well as objections or requests for restrictions directed against its processing, we are obliged, in accordance with the agreement under Art. 26 GDPR as joint contollers, to forward your request to Facebook within 7 days.

Information on the joint responsible persons
Direct contact to the data protection officer of Facebook (contact form): Click here

Facebook Ireland Ltd.
4 Grand Canal Square
Grand Canal Harbour
Dublin2, Ireland
 

Direct contact to the data protection officer of Edelmann GmbH:

datenschutz@edelmann-group.com
Edelmann GmbH
Steinheimer Strasse 45
D-89528 Heidenheim
Germany

 

11. Forwarding to third parties

 

Within Edelmann GmbH, access to your data is granted to those entities that require it to fulfill our contractual and legal obligations. Edelmann GmbH is entitled to transfer the user's personal data to affiliated companies of the Edelmann Group if this is necessary for the processing of the legal transaction or an application procedure or if the person concerned has consented to the transfer of data.

Order processors employed by us (cf. Art. 4 Sentence 8 GDPR) may also receive data for the above-mentioned purposes. These are in particular companies in the categories IT services and IT security. All service providers have been carefully selected by us and are subject to regular checks. All commissioned processors are contractually bound in accordance with Art. 28 GDPR and are bound by our instructions.

In addition, we may be obliged to transfer your personal data to other recipients (public authorities), such as public authorities for the purpose of fulfilling statutory notification obligations (tax authorities, etc.). A transfer to other third parties will only take place if you have given your consent.

12. data transmission to third countries

 

Countries outside the European Union (and the European Economic Area "EEA") handle the protection of personal data differently from countries within the European Union. In the event that data is transferred to third countries, we have taken appropriate measures to ensure that your data is processed as securely in the third countries as within the European Union. We conclude standard data protection clauses provided by the Commission of the European Union with service providers in third countries. These clauses provide appropriate guarantees for the protection of your data with service providers in third countries.

13. Your rights 

 

13.1 You have the following rights with regard to personal information concerning yourself:

The right of information and the right of deletion are subject to the restrictions of §§ 34 and 35 BDSG. In order to exercise your rights, you can contact the responsible office or the data protection officer at the contact details given above.

Furthermore, there is a right of appeal to the competent data protection supervisory authority (Art. 77 GDPR in conjunction with § 19 BDSG):

The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg

Home address:
Königstrasse 10a, D-70173 Stuttgart
postal address:
Postfach 10 29 32, D-70025 Stuttgart
Phone: +49 711 615541-0
fax: +49 711 615541-15
e-mail: poststelle@lfdi.bwl.de

14. revocation of your consent and objection to the processing of your personal data

 

You can revoke your consent to the processing of personal data at any time, either in whole or in part. Please note that the revocation is only effective for the future.

As far as we base the processing of your personal data on the weighing of interests, you can object to the processing. This is the case if the processing is in particular not necessary for the fulfillment of a contract with you, such as when you visit our website. In the event of such an objection, please explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either stop or adapt the data processing or show you our compelling reasons worthy of protection on the basis of which we will continue the processing.

 

15. obligation to provide your personal data

 

In order to conclude a contract, you must provide us with the personal data that is necessary for the execution of the contractual relationship or that we are required to collect by law. If you do not provide us with these data, then the execution and processing of the contractual relationship or the provision of services is not possible for us.

In the context of your application, the provision of personal data is necessary for the implementation of the application procedure. This means that if you do not provide us with any personal data in an application, we will not carry out the application process, i.e. we cannot consider you in the selection process.

There will be no automatic decision making or profiling.

We reserve the right to update this data protection information as necessary.