HALDRUP Legal Information

Legal Notice

Information pursuant to Section 5 of the German Telemedia Act (TMG):

HALDRUP GmbH
Justus-von-Liebig-Str. 3
74532 Ilshofen
Germany

Represented by:

Andreas Hessenthaler (Management)
Bernd Kettemann (Management)

Contact:

Phone: +49 (0)7904 94 3998-0
Fax: +49 (0)7904 94 39 98-640
Email: info@haldrup.net

Registration:

Entry in the Commercial Register.
Registering court: Stuttgart
Registration number: HRB 571514

VAT ID:

VAT identification number pursuant to Section 27a of the German VAT Act:
DE216412479

Liability for Content

As a service provider, we are responsible for our own content on these pages in accordance with general laws pursuant to Section 7(1) of the German Telemedia Act (TMG). However, pursuant to Sections 8 through 10 of the TMG, we are not obligated as a service provider to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity.

Obligations to remove or block the use of information under general laws remain unaffected by this. However, liability in this regard is only possible from the time we become aware of a specific legal violation. Upon becoming aware of such legal violations, we will remove this content immediately.

Liability for Links

Our website contains links to external third-party websites over whose content we have no influence. Therefore, we cannot assume any liability for this third-party content. The respective provider or operator of the linked pages is always responsible for their content. The linked pages were checked for possible legal violations at the time the links were created. No illegal content was identifiable at the time the links were created.

However, permanent monitoring of the content of the linked pages is not reasonable without concrete evidence of a legal violation. Upon becoming aware of any legal violations, we will remove such links immediately.

Copyright

The content and works on these pages created by the site operators are subject to German copyright law. The reproduction, editing, distribution, and any form of use outside the scope of copyright law require the written consent of the respective author or creator. Downloads and copies of this site are permitted only for private, non-commercial use.

Insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is identified as such. Should you nevertheless become aware of a copyright infringement, please notify us accordingly. Upon becoming aware of any infringements, we will remove such content immediately.

Image Licenses

© [contrastwerkstatt] – stock.adobe.com
© [Monkey Business] – stock.adobe.com
© [LE image] – stock.adobe.com
© [Robert Kneschke] – stock.adobe.com

Information pursuant to the Consumer Dispute Resolution Act (VSBG)

HALDRUP GmbH is neither willing nor obligated to participate in dispute resolution proceedings before a consumer arbitration board. European Commission platform for online dispute resolution: https://ec.europa.eu/consumers/odr/

Privacy Policy

This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “Data”) within our online offering and the associated websites, functions, and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as “Online Offering”). With regard to the terms used, such as “processing” or “controller,” we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Data Controller

HALDRUP GmbH
Justus-von-Liebig-Str. 3
74532 Ilshofen
Germany
Managing Directors: Andreas Hessenthaler, Bernd Kettemann

If you have any questions regarding the processing of your data, you can contact us as follows:

By mail to the address listed above, for the attention of the Data Protection Officer.
By email: Contact Data Protection Officer

Types of data processed

  • Master data (e.g., names, addresses).
  • Contact data (e.g., email, phone numbers).
  • Content data (e.g., text entries, photographs, videos).
  • Usage data (e.g., websites visited, interest in content, access times).
  • Meta/communication data (e.g., device information, IP addresses).

Categories of data subjects

Visitors and users of the online service (hereinafter, we collectively refer to the data subjects as “users”).

Purpose of processing

  • To provide the online service, its functions, and content.
  • Responding to contact requests and communicating with users.
  • Security measures.
  • Audience measurement/marketing

Terms used

“Personal data” refers to any information relating to an identified or identifiable natural person (hereinafter “data subject”); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data.

“Pseudonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

“Profiling” means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

“Controller” means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.

“Processor” means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.

Applicable Legal Bases

In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing. Unless the legal basis is specified in the privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing to fulfill our services, carry out contractual measures, and respond to inquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfill our legal obligations is Article 6(1)(c) of the GDPR, and the legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) of the GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.

Security Measures

In accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and its segregation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the erasure of data, and a response to data breaches. Furthermore, we take the protection of personal data into account already during the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).

Cooperation with Data Processors and Third Parties

If, in the course of our processing activities, we disclose data to other individuals or companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, this is done only on the basis of a legal authorization (e.g., if the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Art. 6(1)(b) GDPR), you have consented, a legal obligation requires it, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.).

If we engage third parties to process data on the basis of a so-called “data processing agreement,” this is done in accordance with Article 28 of the GDPR.

Transfers to Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in connection with the use of third-party services or the disclosure or transfer of data to third parties, this is done only if it is necessary to fulfill our (pre)contractual obligations, based on your consent, due to a legal obligation, or based on our legitimate interests. Subject to statutory or contractual permissions, we process or have the data processed in a third country only if the specific requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of special safeguards, such as the officially recognized determination of a level of data protection equivalent to that of the EU (e.g., for the U.S. through the “Privacy Shield”) or compliance with officially recognized special contractual obligations (so-called “Standard Contractual Clauses”).

Rights of Data Subjects

You have the right to request confirmation as to whether data concerning you is being processed, as well as access to this data, further information, and a copy of the data in accordance with Article 15 of the GDPR.

You have the right, in accordance with Article 16 of the GDPR, to request the completion of data concerning you or the rectification of inaccurate data concerning you.

You have the right, pursuant to Article 17 of the GDPR, to request that the data concerning you be erased without delay, or alternatively, pursuant to Article 18 of the GDPR, to request a restriction on the processing of the data.

You have the right to request that the data concerning you, which you have provided to us, be transferred to you in accordance with Article 20 of the GDPR and to request its transmission to other controllers.

You also have the right, pursuant to Article 77 of the GDPR, to lodge a complaint with the competent supervisory authority.

Right of Withdrawal

You have the right to withdraw any consent you have given in accordance with Article 7(3) of the GDPR with future effect.

Right to object

You may object at any time to the future processing of your personal data in accordance with Article 21 of the GDPR. In particular, you may object to processing for the purposes of direct marketing.

Cookies and the Right to Object to Direct Marketing

“Cookies” are small files that are stored on users’ computers. Various types of information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. “Temporary cookies,” also known as “session cookies” or “transient cookies,” are cookies that are deleted after a user leaves an online service and closes their browser. Such a cookie may, for example, store the contents of a shopping cart in an online store or a login status. Cookies that remain stored even after the browser is closed are referred to as “permanent” or “persistent.” For example, the login status can be stored so that users can access it again after several days. Similarly, such a cookie can store the user’s interests, which are used for audience measurement or marketing purposes. “Third-party cookies” are cookies provided by parties other than the controller operating the online service (otherwise, if only the controller’s cookies are used, they are referred to as “first-party cookies”).

We may use temporary and permanent cookies and provide information about this in our Privacy Policy.

If users do not wish to have cookies stored on their computer, they are asked to deactivate the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Disabling cookies may result in functional limitations of this online service.

A general objection to the use of cookies for online marketing purposes can be submitted for a wide range of services, particularly in the case of tracking, via the U.S. website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be prevented by disabling them in your browser settings. Please note that, in such cases, you may not be able to use all features of this website.

Deletion of Data

The data we process is deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated in this privacy policy, the data stored by us is deleted as soon as it is no longer necessary for its intended purpose and no legal retention obligations prevent its deletion. If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

In accordance with legal requirements in Germany, data is retained for a period of 10 years in particular pursuant to Sections 147(1) AO, 257(1) nos. 1 and 4, (4) HGB (books, records, management reports, accounting documents, trading books, documents relevant for taxation, etc.) and 6 years pursuant to § 257(1) nos. 2 and 3, (4) HGB (business correspondence).

In accordance with legal requirements in Austria, records must be retained for 7 years pursuant to Section 132(1) of the Federal Tax Code (BAO) (accounting records, receipts/invoices, accounts, supporting documents, business papers, statements of income and expenses, etc.), for 22 years in connection with real estate, and for 10 years for documents related to electronically supplied services, telecommunications, radio, and television services provided to non-business entities in EU member states for which the Mini One-Stop Shop (MOSS) is utilized.

Contact

When you contact us (e.g., via contact form, email, phone, or social media), the user’s information is processed to handle the contact request and its resolution in accordance with Art. 6(1)(b) GDPR. User information may be stored in a Customer Relationship Management system (“CRM system”) or a comparable inquiry management system.

We delete the inquiries once they are no longer necessary. We review the necessity of retention every two years; furthermore, statutory archiving obligations apply.

Hosting

The hosting services we use are intended to provide the following services: infrastructure and platform services, computing capacity, storage space, and database services, security services, and technical maintenance services, which we utilize for the purpose of operating this online offering.

In this context, we or our hosting provider process inventory data, contact data, content data, contract data, usage data, meta data, and communication data from customers, prospective customers, and visitors to this online service based on our legitimate interests in the efficient and secure provision of this online service pursuant to Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (Conclusion of a Data Processing Agreement).

Collection of access data and log files

We, or our hosting provider, collect data regarding every access to the server on which this service is located (so-called server log files) based on our legitimate interests within the meaning of Art. 6(1)(f) GDPR. Access data includes the name of the accessed webpage, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address, and the requesting provider.

Log file information is stored for a maximum of 7 days for security reasons (e.g., to investigate misuse or fraud) and is then deleted. Data that must be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully clarified.

Social Media Presence

We maintain online presences on social networks and platforms to communicate with customers, prospects, and users active there and to inform them about our services. When accessing the respective networks and platforms, the terms of service and data processing policies of their respective operators apply.

Unless otherwise specified in our Privacy Policy, we process users’ data if they communicate with us within social networks and platforms, e.g., by posting on our online presences or sending us messages.

Integration of Third-Party Services and Content

Within our online offering, we incorporate to integrate content or services from third-party providers, such as videos or fonts (hereinafter collectively referred to as “Content”).

This always requires that the third-party providers of this Content receive the user’s IP address, as they would not be able to send the Content to the user’s browser without it. The IP address is therefore necessary for the display of this content. We endeavor to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Pixel tags allow information such as visitor traffic on the pages of this website to be analyzed. The pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, visit duration, and other details regarding the use of our online offering, as well as being linked to such information from other sources.

Vimeo

We may embed videos from the “Vimeo” platform provided by Vimeo Inc., Attention: Legal Department, 555 West 18th Street, New York, New York 10011, USA. Privacy Policy: https://vimeo.com/privacy. Please note that Vimeo may use Google Analytics; we refer you to the privacy policy (https://www.google.com/policies/privacy) as well as opt-out options for Google Analytics (http://tools.google.com/dlpage/gaoptout?hl=de) or Google’s settings for data use for marketing purposes (https://adssettings.google.com/).

YouTube

We embed videos from the “YouTube” platform provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

Google Fonts

We integrate fonts (“Google Fonts”) from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

Google reCAPTCHA

We integrate the bot detection feature, e.g., for entries in online forms (“ReCaptcha”) from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

Google Maps

We integrate maps from the “Google Maps” service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The data processed may include, in particular, users’ IP addresses and location data; however, this data is not collected without their consent (which is typically provided through the settings on their mobile devices). The data may be processed in the USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

Typekit fonts from Adobe

Based on our legitimate interests (i.e., interest in the analysis, optimization, and economic operation of our online offering within the meaning of Art. 6(1)(f) GDPR), we use external “Typekit” fonts from the provider Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Republic of Ireland. Adobe is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000TNo9AAG&status=Active”).

Xing

Our online offering may incorporate features and content from the Xing service, provided by XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany. This may include, for example, content such as images, videos, or text, as well as buttons that allow users to express their appreciation for the content, contact the authors of the content, or subscribe to our posts. If users are members of the Xing platform, Xing may associate the access to the aforementioned content and features with the users’ profiles on that platform. Xing’s Privacy Policy: https://www.xing.com/app/share?op=data_protection..

LinkedIn

Our online offering may include features and content from the LinkedIn service, provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. This may include, for example, content such as images, videos, or text, as well as buttons that allow users to express their appreciation for the content, contact the content authors, or subscribe to our posts. If users are members of the LinkedIn platform, LinkedIn may associate the access to the aforementioned content and features with the users’ profiles on that platform. LinkedIn’s Privacy Policy: https://www.linkedin.com/legal/privacy-policy.. LinkedIn is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active). Privacy Policy: https://www.linkedin.com/legal/privacy-policy, Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

As of: 10/2021

Wir benutzen Cookies um die Nutzerfreundlichkeit der Webseite zu verbessen. Durch Deinen Besuch stimmst Du dem zu.