Data Protection Information for Customers pursuant to Articles 13 and 14 GDPR

The protection of your data and transparency regarding its processing are of the utmost importance to us. We are therefore hereby fulfilling our obligation to provide information on the circumstances of processing in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR).

The processing of your personal data gives you the following rights:

  1. Right of access (see Article 15 of the GDPR)
  2. Right to rectification (see Article 16 of the GDPR)
  3. Right to erasure (see Article 17 of the GDPR)
  4. Right to restriction of processing (see Article 18 of the GDPR)
  5. Right to object (see Article 21 of the GDPR)
  6. Right to data portability (see Article 20 of the GDPR)

Right to withdraw consent: Where processing is based on Article 6(1)(a) or Article 9(2)(a) of the GDPR, you have the right to withdraw your consent at any time. Data processed prior to withdrawal remains unaffected.

Contact details of the Data Protection Officer: Datenbeschützerin GmbH, Unterer Sand 9, 94209 Regen,
E-Mail: dsb@rkt.de, Tel: 0 99 21 88 22 9000

You have the right to lodge a complaint with a supervisory authority if you believe that your personal data is being processed unlawfully.

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Telephone: +49 (0) 981 180093-0
Telefax: +49 (0) 981 180093-800
E-Mail: poststelle@lda.bayern.de

The data controller is:

RKT Rodinger Kunststoff-Technik GmbH
Represented by: Stephan Schulak
Ernst-Abbe-Straße 3
93426 Roding
Telefon: +49 (0) 94 61 954-0
E-Mail: info@rkt.de

The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).

Data will only be transferred to third countries (countries outside the European Economic Area – EEA) where this is necessary for the performance of the service contract, where you have given us your consent, or where this is otherwise permitted by law. In such cases, we take measures to ensure the protection of your data, for example through contractual arrangements. We transfer data exclusively to recipients who ensure the protection of your data in accordance with the provisions of the GDPR governing transfers to third countries (Articles 44 to 49 of the GDPR).

 

1      Data processing in the context of order fulfilment

1.1        Order entry and processing

In order to process your order or enquiry, we collect personal data from contact persons as part of the process (name, address, email address, telephone number, mobile number). Your data is entered into and stored in SAP, hosted by All for One Group SE, Rita-Maiburg-Straße 40, 70794 Filderstadt-Bernhausen. A data processing agreement has been concluded with the provider.

The processing is based on a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.

Data is transferred internally to the relevant departments and, where necessary, to external parties (e.g. delivery service providers) in order to continue processing the order.

The data is stored in accordance with statutory retention obligations. If no contractual relationship is established, your data will be deleted after one year without active contact.

1.2        Ordering and Dispatch

Personal data is collected for the purposes of ordering and dispatch in order to be able to allocate the goods to the customer. If you place an order directly with us, you will receive a delivery note issued by us. Your data (name, address) is transferred to the delivery service provider for the purpose of processing the dispatch.

The processing is based on a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.

The data is disclosed to internal departments and to the delivery service provider.

The data is stored in accordance with statutory retention obligations.

1.3        Contract management

To organise contracts, all contracts are scanned and stored electronically in our system. This includes all contracts with customers, business partners, service providers, affiliated companies and, where applicable, others. The contracts may contain personal data in the form of contact details required for contract fulfilment.

The processing of the data is based on the performance of a contract pursuant to Article 6(1)(b) of the GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.

The data is stored in accordance with the statutory retention obligations.

1.4        Communication

In order to contact you, we will send you an email containing further information to process your enquiry, your order or as part of our general business relationship. For this purpose, your email address, the content of the email and the communication history are recorded. The emails are hosted by an external service provider. The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. A data processing agreement has been concluded with the provider.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: Data Privacy Framework

Furthermore, we may also contact you by telephone using the landline or mobile number you have provided to us.

The processing of data is based on the performance of a contract in accordance with Article 6(1)(b) of the GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures (customer relationship, contracts with business partners).

Data will only be disclosed if this has been agreed with you or is necessary for the current business transaction.

Your data is stored on our systems in accordance with statutory retention obligations.

2      Data processing in IT systems

2.1        Contact and address management

To manage all contact information for business partners and customers, we store the contacts in our system, which holds: name, contact person (if applicable), address, telephone number, mobile number and email address. The systems are hosted by an external service provider. The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. A data processing agreement has been concluded with the provider.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: Data Privacy Framework

Data collection is based on a legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to manage the contact details of employees and business partners in an organised manner.

Only our staff have access to this system

Your contact details will be stored in our system for the duration of the business relationship and for a further year thereafter.

2.2        Audio and video conferences

2.2.1           Data processing

We use online conferencing tools, amongst other means, to communicate with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conference over the internet, your personal data is collected and processed by us and by the provider of the relevant conferencing tool.

The conferencing tools collect all data that you provide or use in order to utilise the tools (email address and/or your telephone number). Furthermore, the conferencing tools process the duration of the conference, the start and end times of your participation in the conference, the number of participants and other ‘contextual information’ relating to the communication process (metadata).

Furthermore, the tool provider processes all technical data required to facilitate online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speakers, and the type of connection.

Where content is exchanged, uploaded or otherwise made available within the tool, this is also stored on the tool providers’ servers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information shared whilst using the service.

Please note that we do not have full control over the data processing operations carried out by the tools used. Our options are largely determined by the corporate policy of the respective provider. Further information on data processing by the conferencing tools can be found in the privacy policies of the respective tools, which we have listed below this text.

2.2.2           Purpose and legal basis

The conference tools are used to communicate with prospective or existing contractual partners or to offer specific services to our customers (Article 6(1)(b) of the GDPR). Furthermore, the use of these tools serves to generally simplify and speed up communication with us or our company (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). Where consent has been sought, the use of the relevant tools is based on that consent; consent may be withdrawn at any time with future effect.

2.2.3           Retention period

Data collected directly by us via the video and conferencing tools will be deleted from our systems as soon as you request us to do so, withdraw your consent to storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory retention periods remain unaffected.

We have no influence over the retention period of your data stored by the operators of the conferencing tools for their own purposes. For further details, please contact the operators of the conferencing tools directly.

2.3        Conference tools used

We use the following conference tools:

2.3.1           Microsoft Teams

We use Microsoft Teams. The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For details on data processing, please refer to the Microsoft Teams privacy policy: https://privacy.microsoft.com/de-de/privacystatement.

2.3.2           Data Processing

We have entered into a data processing agreement (DPA) with the aforementioned provider. This is a contract required under data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: Data Privacy Framework

2.4        Recording of video conferences

It is possible to record the online meeting. This is done so that we can make the online meeting available to you afterwards and so that you can review the content of the meeting for follow-up purposes. We require your consent to make the recording. You can decide at the start of the meeting whether or not the recording may take place. Your consent will be recorded on video. The recording will process and store your name, the content of the conversation and any shared screen content.

The processing of the data is based on voluntary consent in accordance with Article 6(1)(a) of the GDPR. The data subject may withdraw their consent at any time by means of an informal notification. Any processing that has already taken place remains unaffected by the withdrawal.

The contents of the video remain internal.

The recordings will be stored until you withdraw your consent.

2.5        File sharing via OneDrive

We use OneDrive to exchange files with you. The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (hereinafter ‘OneDrive’).

OneDrive enables us to integrate a folder structure into our system into which you can upload content. When you upload content, it is stored on OneDrive’s servers. A connection is also established with OneDrive, enabling OneDrive to determine that you have visited our system.

The use of OneDrive is based on Article 6(1)(f) of the GDPR. The data controller has a legitimate interest in a reliable and efficient data exchange system.

2.5.1           Data processing on behalf of the controller

We have entered into a data processing agreement (DPA) with the aforementioned provider. This is a contract required under data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: Data Privacy Framework

2.6        Guest Wi-Fi

We offer our guests the option of internet access. To this end, you will be granted access to our guest Wi-Fi. You can obtain access by asking the managing director or a member of staff. We use Clearpass from Hewlett-Packard GmbH, Herrenberger Straße 140, 71034 Böblingen, to manage the guest Wi-Fi. We have entered into a data processing agreement with this provider.

Your name and log data will be stored in our system.

Use of the Wi-Fi is based on voluntary consent in accordance with Article 6(1)(a) of the GDPR. You may withdraw your consent at any time without formal notice. However, this will mean that you will no longer be able to use the internet access.

Data will only be disclosed if this has been agreed with you or is necessary for the current incident.

Log data is stored for three months and then deleted from the system.

2.7        Whistleblowing Portal

2.7.1           Data processing

Through the HinSchG, the Federal Republic of Germany implements the provisions of Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law (‘Whistleblower Protection Directive’).

In order to be able to report breaches in line with these objectives and purposes, companies and public bodies falling within the scope of the Act are obliged to establish and operate a so-called ‘reporting office’.

As part of the data processing activity ‘receipt, processing and advice’, the Whistleblower Officer, acting as the reporting centre, is expected to process the following categories of personal data:

Whistleblower: Personal data (name and gender), contact details (home address, home telephone number, home email address; where applicable, also professional contact details), data relating to professional activity (occupation, employer, role and position with the employer), where applicable, special categories of personal data pursuant to Article 9 of the GDPR, where applicable, personal data relating to criminal offences pursuant to Article 10 of the GDPR

Persons who are the subject of a report: Personal data (name and gender), data relating to professional activities (occupation, employer, role and position with the employer), information on the conduct which, in the opinion of the whistleblower, constitutes the breach; information on the content of follow-up measures and the outcome of the investigations triggered by the report; where applicable, special categories of personal data in accordance with Article 9 of the GDPR; where applicable, personal data relating to criminal offences in accordance with Article 10 of the GDPR

Other individuals affected by a report: personal data (name and gender), where applicable contact details (home address, home telephone number, home email address; where applicable, also professional contact details), data relating to professional activities (occupation, employer, role and position with the employer), where applicable, special categories of personal data pursuant to Article 9 of the GDPR, where applicable, personal data relating to criminal offences pursuant to Article 10 of the GDPR

2.7.2           Purpose and legal bases

The purposes of the processing are specifically set out by the legislator in the HinSchG.

The HinSchG itself states that the purpose of the Act is to protect natural persons who, in connection with their professional activities or in the run-up to such activities, have obtained information about breaches and report or disclose this to the reporting bodies provided for under this Act

(see Section 1(1) of the HinSchG).

Furthermore, the purpose of the Act is also to protect persons who are the subject of a report or disclosure, as well as other persons affected by a report or disclosure (see Section 1(2) of the HinSchG).

2.7.3           Retention period

The reporting procedure is concluded once the reporting body has completed the follow-up measures (Section 18 HinSchG).

The data shall be deleted three years after the conclusion of the procedure in accordance with Section 11(5) of the HinSchG.

The documentation may be retained for a longer period in order to comply with the requirements of this Act or other legal provisions, provided this is necessary and proportionate.

This may be the case, in particular, where internal investigations are ongoing or where administrative and/or judicial proceedings relating to the facts of the report have not yet been concluded.

3      Sales & Marketing

3.1        Exhibition Stand

To enable us to provide you with further information about our companies, products and services after the trade fair, we collect the following data from you at our stand: name, email address, telephone number / mobile number. The data is then entered into our CRM system.

The processing is based on a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.

Only our employees have access to our system. We have engaged an external service provider to provide technical support for the CRM system: [Name, Address]. A data processing agreement has been concluded with this service provider.

4      Financial accounting

4.1        Credit checks

In the case of a purchase on account or any other payment method where we make an advance payment, we may carry out a credit check (scoring). To this end, we transfer the data you have provided (e.g. name, address, age or bank details) to Compagnie Française d’Assurance pour le Commerce Extérieur SA (Coface), German branch, Isaac-Fulda-Allee 1, 55124 Mainz. This data is used to assess the likelihood of a payment default . If the risk of payment default is deemed too high, we may refuse the payment method in question.

The credit check is carried out for the purposes of contract performance (Article 6(1)(b) of the GDPR) and to prevent payment defaults (legitimate interest under Article 6(1)(f) of the GDPR). Where consent has been obtained, the credit check is carried out on the basis of this consent (Article 6(1)(a) of the GDPR); consent may be withdrawn at any time.

4.2        Financial Accounting

To handle financial accounting, we have implemented a process within our IT systems. In the course of this process, personal data relating to contact persons or invoice details (name, address, email address, telephone number, mobile number) may be processed. For this purpose, we use SAP via All for One Group SE, Rita-Maiburg-Straße 40, 70794 Filderstadt-Bernhausen. We have entered into a data processing agreement with this provider.

The processing is based on a legal requirement under Article 6(1)(c) of the GDPR. The processing is necessary for compliance with a legal obligation to which the controller is subject (principles of proper accounting).

The data is forwarded to our appointed tax adviser.

The data is stored in accordance with statutory retention obligations.

4.3        Debt collection

In the event of outstanding debts, reminders will be sent and, in the event of non-payment, the matter will be referred to service providers (solicitors, debt collection agencies). For this purpose, the following information is required: name, address and the amount of the outstanding debt.

Processing is based on a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.

The data is forwarded to the service provider (solicitor, debt collection agency, etc.).

The data is stored in accordance with statutory retention obligations.

5      Facility Management

5.1        Head Office, Visitor Management

Incoming post is distributed to the relevant departments and individuals. Personal letters are delivered unopened. Answering and forwarding calls received at reception. Receiving visitors and recording their details in visitor management software to maintain an overview of which external individuals are on the premises.

To this end, we collect the following data from you: employee name, business partner name, and the visitor’s hours of presence.

Data collection is based on a legitimate interest pursuant to Article 6(1)(f) of the GDPR, to ensure that only authorised persons are granted access to the premises.

Data will only be disclosed if this has been agreed with you or is necessary for the current business transaction.

Your data will be stored on our systems in accordance with statutory retention obligations.

6      Miscellaneous

6.1        Disposal of paper files / data storage media

Paper documents and data storage media containing personal data that are no longer required are destroyed. This ensures compliance with the deletion deadlines following the retention period.

The documents and paper media may contain all data relating to the customer relationship.

The processing of the data is based on a legal requirement under Article 6(1)(c) of the GDPR; the processing is necessary for compliance with a legal obligation to which the controller is subject.

The data is transferred to the certified waste disposal company REISSWOLF International GmbH, Wilhelm-Bergner-Straße 3 A, 21509 Glinde, which the controller has commissioned to carry out the destruction and disposal. A data processing agreement has been concluded with the waste disposal company.

6.2        Data Protection Management

You may contact the external data protection officer at any time by email at dsb@rkt.de or by telephone on +49 9921 88 22 9000.

In doing so, your name, the reason for your enquiry, the details of the matter, and any data relating to the data subject stored in the system will be collected and stored.

The processing of the data is based on the performance of a contract in accordance with Article 6(1)(b) of the GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures (service contract, employment contract).

Information will only be disclosed with your consent.

Your personal data will be stored for as long as is necessary for the purpose. Statutory retention obligations remain unaffected.