Privacy policy

1. Data protection at a glance

General information

The following information provides an overview of what happens with your personal data when you visit this website. Personal data includes any data that can be used to identify you personally. For more detailed information on the topic of data protection, please refer to the sections below.

Data collection on this website

Who is responsible for collecting data on this website?

Data on this website is processed by the website operator. The contact details for the website operator can be found under “Controller information” in this privacy policy.

How do we collect your data?

Any information that you provide us through this website is collected. This includes e.g. any data that you enter in contact forms. In addition to this data, other data is automatically or, where applicable upon your consent, collected by our IT systems when you visit the website. This primarily includes technical data (e.g. Internet browser, operating system or time of page visit). This data is collected automatically as soon as you access this website.

What do we use your data for?

Some of the data is used to ensure that our website works perfectly without error. Other pieces of data may be used to analyse your user behaviour.

What rights do you have in relation to your data?

You have the right at any time to receive information pertaining to the source, recipient and purpose of your saved personal data free of charge. You also have the right to request the rectification or deletion of this data. If you have previously provided consent to data processing, you may withdraw your consent for any future processing at any time. In certain circumstances, you also have the right to request that processing of your personal data is restricted.

Furthermore, you reserve the right to lodge a complaint with the relevant responsible supervisory authorities.
If you have any questions on this or any other questions about data protection, please do not hesitate to contact us at any time.

Analysis tools and third-party provider tools

Statistical analysis of your browsing behaviour may be performed when you visit this website. This analysis is performed primarily using so-called analysis programs.
Detailed information on these analysis programs can be found in the sections below.

2. Hosting

External hosting

This website is hosted by an external service provider (host). Personal data that is collected on this website is stored on the host’s servers. This data may include information such as IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access and other data generated by a website.
The use of the host is necessary for the performance of the contract with our potential and existing customers (Art. 6 (1)(b) GDPR) and in the interest of providing a secure, fast and efficient website as a professional provider (Art. 6(1)(f) GDPR).
Our host shall only process your data if and to the extent that such processing is required for the purposes of fulfilling its obligations to perform and shall comply with our instructions with regard to this data.
We use the following host:

arcos informationssysteme gmbh
Dauerwangstrasse 9
73457 Essingen
Germany

Data processing

We have signed a Data Processing Agreement (DPA) with the above provider.
This Agreement is a contract required under data-protection law which ensures that the chosen provider only processes the personal data of visitors to our website in line with our instructions and in compliance with GDPR.

3. General information and obligations

Data protection

The operator of this website takes the protection of your personal data very seriously. We treat your personal data as confidential and process this data in accordance with statutory data protection regulations and this privacy policy.

Various forms of personal data are collected when you use this website.
Personal data includes any data that can be used to identify you personally. This privacy policy outlines what data we collect and what we use it for. It also explains how and for what purpose data is collected.

Please note that sending data over the Internet (e.g. via e-mail correspondence) may involve security flaws. Complete protection against third-party access is not possible.

Controller information

The Controller for data processing on this website is:

ELABO GmbH
Roßfelder Straße 56
D-74564 Crailsheim, Germany

Phone: +49 7951 307-0
E-mail: info@elabo.de

The Controller is the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).

Storage period

Unless a special storage period has been specified in this privacy policy, your personal data will be stored by us until the purpose of such data processing ceases to be relevant. Where you submit a legitimate request for deletion of your data or withdraw your consent for data processing, your data will be deleted where we have no other legally permissible reason for storing your personal data (e.g. retention periods under tax or commercial law). In the event of the latter, your data will be deleted after these reasons cease to be applicable.

Data protection officer

We have designated a data protection officer for our company.

Mr Michael Gruber
BSP-SECURITY
Thundorferstr. 10
D-93047 Regensburg
Germany

Phone: +49 941 46290929
E-mail: michael.gruber@bsp-security.de

Information on forwarding data to USA and other third countries

Some of the tools we use are provided by companies based in the USA or other third countries considered not to be secure under data protection law. Where these tools are active, your personal data may be transferred to these third countries and processed there. Please note that a level of data protection similar to that within the EU cannot be guaranteed in these countries.
For example, US companies are obligated to surrender personal data to security agencies without you as the data subject being able to take legal action. We therefore cannot exclude the possibility that your personal data on US servers will be processed, analysed and permanently stored by US authorities (e.g. intelligence agencies) for monitoring purposes. Such processing activities are beyond our control.

Withdrawing your consent for data processing

Many data processing processes are only possible with your explicit consent. You may withdraw your previous consent at any time. This does not affect the legality of any data processing that has taken place up until your withdrawal.

Right to object to collection of data in certain cases and direct marketing (Art. 21 GDPR)

Where data is processed on the basis of Art. 6 (1)(e) or (f) GDPR, you have the right at any time to object to the processing of your personal data on grounds relating to your particular situation. This also applies for profiling based on these provisions. The relevant legal basis for processing is outlined in this privacy policy. If you object to processing, we shall no longer process your personal data unless we demonstrate compelling legitimate grounds for such processing which outweigh your interests, rights and freedoms, or unless such processing is performed for the purposes of enforcing, exercising or defending legal claims (objection in accordance with Art. 21(1) GDPR). Where personal data is processed for direct marketing purposes, you shall have the right to object at any time to processing of personal data concerning you for such marketing. This also includes profiling to the extent that it is related to such direct marketing. Where you object to processing for direct marketing purposes, your personal data shall no longer be processed for such purposes (objection in accordance with Art. 21(2) GDPR).

Right of lodge a complaint with responsible supervisory authorities

Without prejudice to any other administrative or judicial remedy, in the event of any infringement against GDPR, the data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement.

Right to data portability

You shall have the right to have the data that we automatically process based on your consent or for the purposes of performing a contract transmitted to yourself or another third party in a commonly used, machine-readable format. If you request that this data is transmitted to another controller, the data will be transmitted where technically feasible.

SSL and TLS encryption

This site uses an SSL and TLS encryption for security reasons and to protect the transmission of confidential information, such as orders or enquiries that you send to us as the site operator.
An encrypted connection is indicated when the browser address bar changes from “http://” to “https://” and the padlock symbol appears in your browser bar.

An active SSL and TLS encryption ensures that data that you send to us cannot be read by third parties.

Encrypted site payment transactions

You will be required to provide your payment details (e.g. account number for direct debit authorisation) for payment upon signing a fee-based contract.

Payment using commonly used payment methods (Visa/MasterCard, Direct Debit) will only be taken via an encrypted SSL or TLS connection. An encrypted connection is indicated when the browser address bar changes from “http://” to “https://” and the padlock symbol appears in your browser bar.

Encrypted communication ensures that the payment details you provide cannot be read by third parties.

Access, deletion and rectification

You have the right under the applicable statutory provisions to request access to your stored personal data at any time and free of charge, including information on its origin and recipients and the purpose of the data processing. If necessary, you may also request that this data is rectified or deleted. If you have any questions on this or any other questions about personal data, please do not hesitate to contact us at any time.

Right to restriction of processing

You have the right to request that processing of your personal data is restricted. You can contact us at any time for this purpose. The right to restriction of processing applies in the following cases:

  • You contest the accuracy of the personal data stored by us. We will usually require time to review this. You have the right to request that processing of your personal data is restricted for the duration of such review.
  • The processing of your personal data is unlawful and you request the restriction of processing instead of the deletion of said data.
  • We no longer need your personal data but you require this data for the establishment, exercise or defence of legal claims and you request the restriction of processing instead of deletion of this data.
  • You have objected to processing pursuant to Art. 21(1) GDPR and the verification of whether your interests override our interests is still pending. You may request the restriction of processing for the duration of this verification.

Where processing has been restricted, such personal data shall – with the exception of storage – only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.

Objection to marketing e-mails

The use of contact details published as part of our obligation to provide a legal notice on our website for the purposes of sending unsolicited marketing and information materials shall be hereby rejected. The site operator shall reserve the right to take legal action in the event of receipt of unsolicited marketing information (e.g. spam e-mails).

4. Data collection on this website

Cookies
Our website uses cookies. Cookies are small text files and do not harm your end device. They are stored on your end device temporarily for the duration of a browsing session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted when you leave the page or close your browser. Persistent cookies remain stored on your end device until you delete them yourself or they are automatically deleted by your web browser.

Cookies from third parties may also be stored on your end device when you enter our site (third-party cookies). These allow us and/or you to use certain services from third-party companies (e.g. cookies for executing payment services).

Cookies have different functions. Numerous cookies are technically essential to ensure the proper function of certain website features (e.g. basket function or video displays). Other cookies are used to analyse user behaviour or display advertisements.

Cookies that are required for electronic communication (essential cookies) or the function of certain desired features (functional cookies, e.g. shopping cart function) or website optimisation (e.g. cookies for measuring the web audience), are stored pursuant to Art. 6(1)(f) GDPR insofar as no other legal basis is specified. The website operator has a legitimate interest in the storage of cookies to ensure it can provide its services to the best of its ability and without errors. Where consent to the storage of cookies has been requested, such storage of the cookies in question shall only take place once this consent has been granted (Art. 6(1)(a) GDPR). Your consent may be withdrawn at any time.

You can change your browser settings so that you are notified about the use of cookies. You can also adapt your settings to only allow cookies in certain cases or reject them altogether or enable the deletion of cookies every time you close your browser. Disabling cookies may affect the functionality of this website. In line with this privacy policy, we will inform you separately and, if necessary, request your consent where third-party or analytical cookies are used.

Server log files

The site provider automatically collects and stores information in server log files that are automatically communicated to us by your browser. This information includes:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of computer accessing the site
  • Time of server request
  • IP address

This data is not combined with other data sources.

This data is collected pursuant to Art. 6(1)(f) GDPR. The website operator has a legitimate interest in optimising the website and presenting it without errors – server log files must be collected for this purpose.

Contact form

When you send us requests using our contact form, the details you enter in the contact form, incl. any contact details provided, will be stored by us for the purposes of processing your request and responding to any follow-up questions. We will not pass on this data without your consent.

This data is processed pursuant to Art. 6(1)(b) GDPR where your request is in relation to performance of a contract or such processing is required as part of pre-contractual measures. In all other cases, processing is based on our legitimate interest in processing the received request effectively (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where such consent has been requested.

Data provided by you in the contact form will remain with us until you request its deletion, withdraw your consent for its storage or the purpose for such data storage ceases to be relevant (e.g. once your request has been processed). Mandatory statutory provisions – in particular, those pertaining to retention periods – shall remain unaffected.

E-mail, phone or fax requests

Where you contact us by e-mail, phone or fax, your request, incl. any personal data (name, request) you provide as part of this correspondence, will be stored and processed by us for the purposes of dealing with your request. We will not pass on this data without your consent.

This data is processed pursuant to Art. 6(1)(b) GDPR where your request is in relation to performance of a contract or such processing is required as part of pre-contractual measures. In all other cases, processing is based on our legitimate interest in processing the received request effectively (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where such consent has been requested.

Data provided by you via contact requests will remain with us until you request its deletion, withdraw your consent for its storage or the purpose for such data storage ceases to be relevant (e.g. once your request has been processed). Mandatory statutory provisions – in particular those pertaining to statutory retention periods – shall remain unaffected.

5. Analytics tools and ads

Google Analytics

This website uses functions of the web analytics service Google Analytics. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics allows the website operator to analyse the behaviour of visitors to the website. The website operator receives various types of usage data, such as e.g. page views, dwell time, operating system used and user origin, for such analysis. Where applicable, Google may consolidate this data to create a profile assigned to the respective user and/or end device.

Google Analytics also allows us to track your mouse/scroll movements and clicks. Google Analytics employs various modelling approaches to supplement the collected datasets and makes use of machine learning technology for data analysis.

Google Analytics uses technology that allows user recognition for the purposes of analysing user behaviour (e.g. cookies or device fingerprinting). Information collected by Google via the use of this website is generally transferred to a Google server in the USA and stored there.

These analytics tools are used pursuant to Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the analysis of user behaviour for the purposes of optimising its website and its advertisements. Where corresponding consent has been requested (e.g. consent for storing cookies), data will only be processed pursuant to Art. 6(1)(a) GDPR. This consent may be withdrawn at any time.

The Standard Contractual Clauses of the EU Commission apply for data transfers to the USA. You can find more details here:
https://privacy.google.com/businesses/controllerterms/mccs/.

IP anonymisation

We have activated the IP anonymisation function on this website. This feature causes Google to shorten your IP address within EU Member States or in other contracting parties to the Agreement on the European Economic Area prior to transferring the data to the USA. In exceptional cases, your full IP address may be sent to a Google server in the USA and shortened there. Google uses this information on behalf of the website operator to analyse website usage, compile reports on website activity and provide other services linked to website and Internet use for the website operator. IP addresses communicated by your browser within the scope of Google Analytics are not combined with other Google data.

Browser plug-in

You can prevent your data being collected and processed by Google by downloading and installing the browser plug-in available via the following link:
https://tools.google.com/dlpage/gaoptout?hl=en-GB.

For more information on the use of user data for Google Analytics, please refer to Google’s privacy policy::
https://support.google.com/analytics/answer/6004245?hl=en.

Data processing

We have signed a Data Processing Agreement with Google and fully comply with the strict regulations of the relevant German data protection authorities for the use of Google Analytics.

Google Analytics Demographics

This website uses the Google Analytics'“Demographics” function for the purposes of being able to display relevant ads to visitors of the website within the Google Network. This allows us to create reports containing information on the age, gender and interests of visitors to our website. This data is obtained from Google ads based on interests and visitor data from third-party providers. This data cannot be assigned to any particular person. You can disable this function at any time in the ad settings in your Google account or prohibit the collection of your data by Google Analytics altogether as outlined under “Objection to data collection”.

Google Analytics Ecommerce Tracking

This website uses the Google Analytics “Ecommerce Tracking” function. Ecommerce Tracking helps website operators to analyse purchasing behaviour of website visitors for the purposes of improving their online marketing campaigns. This function collects information such as e.g. orders made, average order value, shipping costs and time from viewing a product to its purchase. This data can be compiled by Google under a transaction ID which is assigned to the respective user and/or end device.

Storage period

Event and user-level data saved by Google that is linked with cookies, user IDs or advertising IDs (e.g. double-click cookies, Android advertising ID) is anonymised or deleted after two months. Click the link below for more information:
https://support.google.com/analytics/answer/7667196?hl=en.

Ströer Campaign Tracking

We use advertising services provided by RegioHelden GmbH, a Ströer Media Deutschland GmbH company. RegioHelden collects certain information relating to our interactions with you. RegioHelden provides us with the collected information and we use this in compliance with our privacy policy and the applicable data protection laws.

Call tracking

Any phone number provided on our website may be a call-tracking number which allows the call date, call time, call acceptance, call duration and phone numbers of both parties to the call to be recorded, stored and forwarded to RegioHelden GmbH and ourselves for the purposes of determining the effectiveness of our marketing. Unique phone numbers given to individual customers and used in ads are not linked to the tracking of users’ individual usage behaviour. These numbers are only used depending on certain or several keywords used when searching.

Contact form

Data provided in the contact form is only processed with your consent (Art. 6(1)(a) GDPR). You may withdraw this consent at any time. To do so, simply send us an e-mail. This does not affect the legality of any data processing that has taken place up until your withdrawal.

 

The contact forms accessed by respective users are not linked to the tracking of users’ individual usage behaviour. These forms are only used depending on certain or several keywords used when searching.

If a user fills out the contact form, they must give clear and voluntary consent using the opt-in function prior to sending their data and subsequent data processing. The data provided in the contact form can only be directed to the relevant responsible staff member along with the source with this consent.

Server log files

RegioHelden automatically collects and stores information in so-called server log files that are automatically communicated to RegioHelden by your browser. They are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of computer accessing the site
  • Time of server request
  • IP address

This data is not combined with other data sources.

This data is collected pursuant to Art. 6(1)(f) GDPR. RegioHelden has a legitimate interest in optimising the website and presenting it without errors – server log files must be collected for this purpose.

6. Newsletter

Newsletter data

If you would like to receive the newsletter advertised on the website, we require your e-mail address and other information that allows us to confirm that you are the owner of the e-mail address provided and you consent to receiving the newsletter. No additional data will be collected (excluding any information provided voluntarily). We use this data exclusively for the purposes of sending the required information and do not transfer this data to third parties.

Data provided in the newsletter sign-up form is only processed with your consent (Art. 6(1)(a) GDPR). Any consent given for the storage of data and e-mail addresses and their use for the purposes of sending the newsletter may be withdrawn at any time, e.g. by using the “unsubscribe” link in the newsletter. This does not affect the legality of any data processing that has already taken place.

Any data provided for the purposes of receiving the newsletter will be stored by us and/or the newsletter service provider up until you unsubscribe from the newsletter. After unsubscribing from the newsletter or where the purpose of storing such information ceases to be relevant, your data will be deleted from the newsletter mailing list. We reserve the right to delete or block e-mail addresses from our newsletter mailing list at our own discretion pursuant to our legitimate interests under Art. 6(1)(f) GDPR.

After being removed from the newsletter mailing list, your e-mail address will be stored on our and/or newsletter service provider’s blacklist to avoid future e-mails. Data contained on the blacklist will be used for this sole purpose and will not be combined with other data. This blacklisting is carried out in both your interest and our interest in complying with the legal provisions pertaining to the sending of newsletters (legitimate interest under Art. 6(1)(f) GDPR). Storage of your data on this blacklist is not limited in time. You may object to such storage where your interests outweigh our legitimate interests.

7. Plug-ins and tools

YouTube with enhanced data protection

This website integrates videos from YouTube. These pages are operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

We use YouTube in privacy-enhanced mode. According to YouTube, this mode ensures that no information about the visitors to this website is stored before they view the video. However, the privacy-enhanced mode does not exclude the possibility that your data will be forwarded to YouTube partners. In doing so, regardless of whether you view a video or not, connection to the Google DoubleClick network will be established.

You will be connected to the YouTube servers as soon as you start a YouTube video on this website. This will allow information pertaining to which of our sites you have visited to be communicated to the YouTube server. If you are logged in to your YouTube account, you will allow YouTube to assign your browsing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.

In addition, YouTube may also store various cookies on your end device or use similar recognition technology (e.g. device fingerprinting) after you start a video. This allows YouTube to receive information about visitors to this website. This information is primarily used to obtain video statistics which improve user-friendliness and prevent fraud attempts.

Additional data processing beyond our control may also be triggered by starting a YouTube video.

Use of YouTube on this website is in the interest of presenting our online services in an appealing manner. This represents a legitimate interest under Art. 6(1)(f) GDPR. Where corresponding consent has been requested, data will only be processed pursuant to Art. 6(1)(a) GDPR. This consent may be withdrawn at any time.

More information about data protection at YouTube can be found in their privacy policy here:
https://policies.google.com/privacy?hl=en.

Google Maps

This site uses the map service Google Maps. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Storage of your IP address is required for the use of Google Maps features. This information is generally transferred to a Google server in the USA and stored there.
The provider of this site has no control of this data transfer. If Google Maps is activated, Google may use Google Web Fonts for the purposes of ensuring fonts are displayed in a uniform manner. When accessing Google Maps, your browser accesses the necessary Web Fonts in your browser cache in order to display texts and fonts correctly.

The use of Google Maps on this website is in the interest of presenting our online services in an appealing manner and making it easier for visitors to find the locations stated on the website. This represents a legitimate interest under Art. 6(1)(f) GDPR. Where corresponding consent has been requested, data will only be processed pursuant to Art. 6(1)(a) GDPR. This consent may be withdrawn at any time.

The Standard Contractual Clauses of the EU Commission apply for data transfers to the USA.
You can find more details here:
https://privacy.google.com/businesses/gdprcontrollerterms/ and
https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

For more information on the use of user data for, please refer to Google’s privacy policy:
https://policies.google.com/privacy?hl=en.

8. Our services

Handling applicant data

We offer you the opportunity to apply to work with us (e.g. via e-mail, post or online application form). Please see below information in relation to the extent, purpose and use of your personal data collected as part of the application process. We ensure that your data is collected, processed and used in accordance with the relevant applicable data protection laws and any other statutory provisions, and treated as strictly confidential.

Extent and purpose of data collection

If you send us an application, we will process any related personal data (e.g. contact and communication data, application documents, notes as part of applicant interviews, etc.) where this is required as part of the decision-making process pertaining to your selection and subsequent employment. This processing is pursuant to Section 26 BDSG [Federal Data Protection Act] under German law (initiation of employment), Art. 6(1)(b) GDPR (general initiation of a contract) and – where you have granted your consent – Art 6(1)(a) GDPR. This consent may be withdrawn at any time. Your personal data will only be forwarded to persons within our company that are responsible for processing your application.

If your application is successful, the data submitted by you under Section 26 BDSG and Art 6(1)(b) GDPR will be stored in our data processing systems for the purposes of performing your employment contract.

Data retention period

If we are unable to make you an offer of employment, you reject an offer of employment or you withdraw your application, we reserve the right to retain the data provided by you for up to six months following termination of the application process (incl. rejection or withdrawal) in our legitimate interests (Art. 6(1)(f) GDPR).
The data will be deleted and the application documents will be physically destroyed upon expiration of this six months. Such data is retained for the purposes of providing proof in the event of a legal dispute. Where it becomes apparent that such data will still be required after the six-month retention period (e.g. due to imminent or pending legal action), deletion will only take place once the purpose for the continued retention ceases to be relevant.

Retention for extended periods may also take place where you have provided consent to such (Art. 6(1)(a) GDPR) or where deletion of this data would be in breach of statutory retention obligations.

Applicant pool

Where we do not make you an offer of employment, we may choose to include you in our applicant pool. If submitted, all documents and information provided as part of the application will be transferred to the applicant pool so that we can contact you in the event of any suitable vacancies. You will only be included into our applicant pool with your explicit consent (Art. 6(1)(a) GDPR). This consent is voluntary and shall have no bearing on the ongoing application process. The data subject may withdraw their consent at any time. In such cases, the data will be irreversibly deleted from the applicant pool unless statutory retention obligations prevent us from doing so.

Data from the applicant pool will be irreversibly deleted no later than two years following the issuing of consent.

We respect your privacy

We use cookies to offer you an ideal experience on our website. This includes cookies that are necessary to operate our web pages as well as cookies only used for anonymous statistical purposes, for user experience settings and for displaying customised content. You can decide which categories you want to allow. Please note that based on your settings, not all the functionalities of our site may be available.

Cookie settings

 

Without these cookies, the website cannot function correctly.

 

These cookies are used to analyse user behaviour on our website. They may count how often a user has visited the site or how long they spend on a certain web page.

 

These cookies are used to improve our website’s user experience. They may store whether you have already accessed a Google Maps map so that you won’t be shown our privacy statement again.