Privacy policy

Responsible party:
J.D. Theile GmbH & Co KG
Letmather Street 26
D-58239 Schwerte
Germany, North Rhine-Westphalia
North Rhine-Westphalia
Phone: +49 (0) 2304 757-0
E-mail: mail(at)jdt.de

Contact details of the data protection officer:
E-mail address: datenschutz(at)jdt.de

Contents
I Introduction
II Legal basis
III Our processors
IV Our data processing and its purposes
V Processing for marketing, tracking and reach measurement
VI Further processing for other purposes
VII Rights of data subjects
VIII Data attributes

I. Introduction
With the following declaration, the controller (hereinafter also referred to as "we" or the "provider") informs you about the type, scope and purposes of the collection, processing and use of your data when you contact the controller by telecommunication or exchange data with the controller.

This privacy policy applies in particular to our website and our other digital services such as company websites. Insofar as we handle data processing uniformly across the digital services we use, we have summarized the relevant information on the processing purposes, the relevant legal bases and the storage periods for you. The necessary details on the digital services we use and their third-party providers (hereinafter referred to as service providers) can be found at the end of the summary section.

Your point of contact for all data protection issues is the controller named above, who you can reach at the address and contact details given above.

Third-party providers (hereinafter referred to as service providers) can be found at the end of the summary section.

Your point of contact for all data protection issues is the controller named above, who you can reach at the address and contact details given above.

II Legal bases
Legal basis Consent
The legal basis for the processing of data is Art. 6 para. 1 lit. a General Data Protection Regulation (GDPR) if you have given us your consent.
You have the option to withdraw your consent to the processing of personal data at any time. You can find more information in the section below entitled Data subject rights.

Legal basis Contract fulfillment
If the purpose of the data processing is the initiation or performance of a contract, Art. 6 para. 1 lit. b GDPR is a legal basis for the data processing.

In the case of the initiation or performance of an employment relationship, our data processing is also governed by Section 26 (1) BDSG.

Legal basis for the legitimate exercise of interests
We are entitled to process your personal data if it is necessary to safeguard legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR. However, such data processing cannot be considered if your interests or fundamental rights and freedoms that require the protection of personal data prevail. Our legitimate interests include the presentation of our company, the development of business relationships, the implementation of advertising measures and the guarantee of IT security. However, we will only ever process data on the basis of our legitimate interests for the appropriate purpose and only to the extent necessary.

Legal basis for fault monitoring and prevention of misuse
The legal basis for data processing to detect faults or errors in telecommunications systems is § 12 TTDSG i.V.m. Art. 95 GDPR as well as Art. 6 para. 1 lit. c GDPR, insofar as action is required for reasons of information security.

If there are actual indications of unlawful use of a telecommunications network or telecommunications service, in particular unreasonable harassment in accordance with Section 7 UWG, we may process traffic data necessary to detect and prevent the unlawful use of the telecommunications network or service in order to protect end users. The legal basis is § 12 TTDSG i.V.m. Art. 95 GDPR.

III Our contract processors
As part of our digital business processes, we use carefully selected service providers who process personal data on our behalf. This is done on the basis of so-called order processing contracts in accordance with Art. 28 GDPR. Data processing is always deemed to be commissioned if an external service provider processes personal data not for its own purposes, but exclusively in accordance with our instructions and for precisely defined purposes, such as when using data traffic analysis programs, cloud providers or hosting services. In such cases, we ensure that our service providers take appropriate technical and organizational measures to protect your data and fully comply with the statutory data protection requirements.

We use the following processors as part of our data processing.

Processors within the EU or EEA

We have concluded contracts with all processors in accordance with Art. 28 GDPR. Our processors are bound by our instructions.

Processors in third countries

  • Google LLC
    1600 Amphitheatre Parkway
    Mountain View
    CA 94043, USA (hereinafter referred to as Google USA)
    Google privacy policy: https://policies.google.com/privacy?gl=ZZ&hl=de
    Google USA is a participant in the EU-U.S. Data Privacy Framework, ensuring an adequate level of data protection in accordance with Art. 45 GDPR
  • InnoCraft Limited
    7 Waterloo Quay PO625
    6140 Wellington
    New Zealand
    InnoCraft Limited Privacy Policy: matomo.org/privacy-policy/
  • OpenAI, L.L.C.
    3180 18th St San Francisco
    CA 94110, USA (hereinafter OpenAI USA)
    OpenAI USA Privacy Policy: https://openai.com/policies/privacy-policy
    OpenAI USA is a participant in the EU-U.S. Data Privacy Framework, so that an adequate level of data protection is ensured in accordance with Art. 45 GDPR

We have concluded contracts with our processors in third countries in accordance with the EU standard contractual clauses. Our processors are bound by our instructions.

Right of objection and removal
The collection of data for the provision of the website and the storage of the data is absolutely necessary for the operation of the website. Consequently, there is no possibility for the user to object.

IV. Our data processing and its purposes
1. introduction
We process the following data in order to be able to communicate with you for business purposes. This includes, for example, responding to your inquiry, preparing an offer, making an appointment and also your subsequent support within the scope of the customer relationship.

In the following, we will inform you for each individual processing activity about which personal data we process for which purposes and on which legal basis this is done. For greater clarity, we have summarized the respective data attributes in a table. The table can be found at the end of this document.
Insofar as the processing is based on Art. 6 para. 1 lit. f GDPR (legitimate interest), we also explain our legitimate interest. In addition, you will find out to which recipients or categories of recipients your data may be transmitted, how long the data will be stored and the criteria according to which the storage period is determined. Finally, we will inform you whether the provision of your data is required by law or contract or is necessary for the conclusion of a contract, whether you are obliged to provide it and what the possible consequences of not providing it would be.

2. general customer communication
If you contact us via the e-mail addresses and telephone numbers provided by us or if you contact us by post, we will store your data in our data processing systems and process it until the intended purposes have been fulfilled or until the storage periods have expired.

In principle, we only process the data that you expressly provide to us. We do not request data from third parties.

Legal basis:

  • Your consent,
  • our legitimate interests (company presentation, targeted advertising),
  • the fulfillment of contractual obligations or the initiation of a contract.

Right to object:
As we process your data on the basis of our legitimate interests, you have the right to object.

Storage period:
Data provided by you will be deleted immediately after your request has been dealt with or, if it has not been dealt with, no later than 3 years after the last contact, unless your data is subject to a longer storage period for a separate reason (e.g. the storage of information used to fulfill a contract). The request is completed when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

3. processing in connection with your use of the website
We process the data you provide to enable you to use our website. We publish information about our company and our services and products via the website.

a. Function of the cookie banner
When you visit our website, you can decide which optional data processing you would like to give us consent to. For this purpose, we show you an overview of these optional data processing operations via a so-called cookie banner. You can use buttons to activate or deactivate certain data processing operations. We store this decision on your end device. Furthermore, the optional data processing that you have activated generally also stores information on your device.

You can revoke or change your decision at any time via the menu at the bottom left of the website. You can find more information on the cookie banner function in the section "Storage of consent". An overview of the data processing that leads to data storage on your device can be found in our "Cookie Policy".

b. Your contact with us via forms
On our website, we offer you the opportunity to contact us via our contact form.

c. Use of our forms
If you use the forms offered on our website in the Contact section, we will process the data you provide to respond to your request.
Our website offers the option of contacting us by e-mail and is therefore used for electronic contact. If a user makes use of one of these options, the data entered in the input mask will be transmitted to us and stored.
These data are

- Company*
- street address
- town
- ZIP CODE
- First name*
- Surname*
- e-mail*
- Telephone
- Request/message*
- file

*Mandatory fields

Legal basis:
- Your consent,
- our legitimate interests (company presentation, target group-oriented advertising),
- the fulfillment of contractual obligations or the initiation of a contract.

Right to object:
As we process your data on the basis of our legitimate interests, you have the right to object.

Storage period:
Data provided by you will be deleted immediately after your request has been dealt with or, if it has not been dealt with, no later than 3 years after the last contact, unless your data is subject to a longer storage period for a separate reason (e.g. the storage of information used to fulfill a contract). The request is completed when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

d. Translation function with OpenAI
In order to make our website and its content, such as texts and buttons, available in multiple languages, we use the translation function of the OpenAI service, which is operated by OpenAI Ireland. When you use the translation function, the relevant content is transmitted to the OpenAI Ireland servers for automated translation. Your browser transmits the IP address of the accessing device. OpenAI uses all transmitted data to perform the translation function. Processing may be carried out by sub-processors in third countries such as OpenAI USA.

Legal basis:

  • Your consent.

Storage period:
Data provided by you will be deleted immediately 30 days after the end of your user session, unless your data is subject to a longer storage period for a separate reason (e.g. storage of information used to fulfill a contract).

e. Processing of data for fault and abuse control
We analyze the log data of our digital services for the purposes of malfunction and abuse control. A malfunction occurs in the event of a malfunction of a telemedium. Misuse of a telemedium exists, for example, if there is unreasonable harassment. The measures we take include the evaluation of error states and system monitoring to detect and prevent system threats.

We do not merge this data with other data sources.

Legal bases:

  • Our legitimate interests (protection of our IT systems),
  • fault control and prevention of misuse.

f. Storage of consents
We place a permanent cookie on your end device if you have given us at least one consent for the data processing mentioned above in the section "Website cookies". We use this cookie to store the consent you have given on your device so that it is taken into account for further use of the website and for your subsequent visits.

You can use the link below to change the cookie settings and thus revoke your previous cookie consent.

Data characteristics (inventory data):

  • Pseudonymous identifier of the end device
  • Processing relevant to consent

Legal basis:

  • Your consent.

Storage period:
Your data will be deleted after 12 months, unless your data is subject to a longer storage period for a separate reason.

Right to object:
As we process your data on the basis of our legitimate interests, you have the right to object. The collection of data for the provision of the telemedium and the storage of data in log files is absolutely necessary for its operation and may also be justified for other legal reasons. However, you can exercise your right to object by means of automated procedures that use technical specifications, e.g. in the case of anonymization of your IP address by VPN providers.

V. Processing for marketing, tracking and reach measurement
a. Use of Matomo (formerly PIWIK) for web analytics TBD
We use the open source software tool Matomo (formerly PIWIK) on our website to analyze the surfing behavior of our users. The software places a cookie on the user's computer (for cookies, see above). If individual pages of our website are accessed, the following data is stored:

1. 2 bites of the IP address of the user's accessing system,
2. the website accessed,
3. the website from which the user came to the website accessed (referrer)
4. the subpages that are accessed from the accessed website
5. the time spent on the website,
6. the frequency with which the website is accessed.

The software runs exclusively on the servers of our website. Users' personal data is only stored there. It is not passed on to third parties.

The software is set so that the IP addresses are not stored in full, but 2 bits of the IP address are masked (example: 192.168.XXX.XXX). In this way, it is no longer possible to assign the shortened IP address to the calling computer.

aa. Purpose of the data processing
The processing of users' personal data enables us to analyze the surfing behavior of our users. By analyzing the data obtained, we are able to compile information about the use of the individual components of our website. This helps us to continuously improve our website and its user-friendliness. These purposes also constitute our legitimate interest in processing the data in accordance with Art. 6 para. 1 lit. f) GDPR. By anonymizing the IP address, the interest of users in the protection of their personal data is adequately taken into account.

ab. Legal basis for the processing of personal data
The legal basis for the processing of users' personal data is Art. 6 para. 1 lit. f) GDPR.

ac. Storage period:
The data is deleted as soon as it is no longer required for our recording purposes. In our case, this is the case after 30 days.

b. Use of maps and route planning
On this website, map material from the Google Maps service is integrated in the [name of category] section. The provider of the map material is Google USA. When you access the section [name of section], your device loads map data and other required files such as images, icons, fonts and JavaScript computer programs from the Google USA servers. In order to use the functions of Google Maps, it is necessary to store certain data about your device, such as your IP address. This information is usually transferred to a Google USA server and stored there. We have no influence on this data transfer.

ba. Legal basis

  • Your consent.

bb. Storage duration
Google USA stores collected data for various periods of time, depending on what data is involved, how we use it and what consent you have given us. The pseudonymous data will be deleted after 18 months at the latest. Storage beyond this period is possible in accordance with data protection legislation.

bc. Joint responsibility
Google USA is our data processor. If you use other services from Google USA or Google Ireland, Google USA or Google Ireland may also use your traffic data for their own purposes. Google USA and Google Ireland are responsible for their own processing under data protection law.

c. Hosting service provider
To operate our website, we use the services of specialized digital agencies, SaaS providers and data center service providers (collectively referred to as hosting service providers).

TREIBSTOFF manages our digital services. The hosting service provider ALL-INKL.COM operates servers for us.

Objection and removal options
Cookies are stored on the user's computer and transmitted by it to our website. As a user, you therefore have full control over the use of cookies. By changing the settings in your Internet browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been saved can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to use all functions of the website to their full extent.

VI Further processing for other purposes
Unless otherwise stated above, your data will not be passed on to third parties and will not be processed for purposes other than those stated.

VII Rights of data subjects
Right to information
You can request information in accordance with Art. 15 GDPR about your personal data that we process.

Right to rectification
If the information concerning you is not (or no longer) correct, you can request a correction in accordance with Art. 16 GDPR. If your data is incomplete, you can request that it be completed.

Right to erasure
You can request the erasure of your personal data in accordance with Art. 17 GDPR.

Right to restriction of processing
In accordance with Art. 18 GDPR, you have the right to request that the processing of your personal data be restricted.

Right to lodge a complaint
If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority of your choice in accordance with Art. 77 para. 1 GDPR. This also includes the data protection supervisory authority responsible for the controller State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, https://www.ldi.nrw.de/kontakt/ihre-beschwerde.

Right to data portability
In the event that the requirements of Art. 20 para. 1 GDPR are met, you have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to third parties. The collection of data for the provision of the website and the storage of log files are absolutely necessary for the operation of the website. They are therefore not based on consent pursuant to Art. 6 para. 1 lit. a GDPR or on a contract pursuant to Art. 6 para. 1 lit. b GDPR, but are justified pursuant to Art. 6 para. 1 lit. f GDPR. The requirements of Art. 20 para. 1 GDPR are therefore not fulfilled in this respect.

Right to object pursuant to Art. 21 (1) GDPR
You have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data which is based on point (f) of Article 6(1) GDPR. The controller will then no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims. The collection of data for the provision of the website and the storage of log files are absolutely necessary for the operation of the website.

If you would like to exercise your right to object, please send a written objection by email to datenschutz(at)jdt.de.

Right to withdraw consent in accordance with Article 7(3) GDPR

You can withdraw the consent you have given us at any time. As a result, we may no longer continue the data processing based on this consent in the future.

Right to withdraw consent in accordance with Article 7(3) GDPR
You can withdraw the consent you have given us at any time. As a result, we may no longer continue the data processing based on this consent in the future.

VIII. Data attributes

Data processingData typeData attribute
General customer communicationInventory data
  • Salutation, title, first and last name,
  • Company name,
  • Address data (regarding contact and billing address) such as street, zip code, city and country,
  • Communication data such as telephone (landline and cell phone number), fax and e-mail address,
  • industry,
  • website,
  • message data.
Customer contact managementInventory data
  • Salutation, title, first name and surname (*),
  • Type of employment,
  • Address data (regarding contact and billing address) such as street, postal code, city and country,
  • Communication data such as telephone (landline and cell phone number), fax and e-mail address,
  • department,
  • Function in the company,
  • company name,
  • Role in the purchasing process (consumer/entrepreneur/employee of a company),
  • Budget responsibility (yes/no),
  • Interest in products,
  • Preferred language,
  • Industry,
  • website
  • IP address,
  • geographical location,
  • browser type,
  • Duration of the visit,
  • pages viewed,
  • Information from completed forms (e.g. name, e-mail address, telephone number, message)(*).

*mandatory information

Use of our formsInventory data
  • Salutation, title, first name and surname (*),
  • Type of employment,
  • Address data (regarding contact and billing address) such as street, postal code, city and country,
  • Communication data such as telephone (landline and cell phone number), fax and e-mail address,
  • department,
  • Function in the company,
  • company name,
  • Role in the purchasing process (consumer/entrepreneur/employee of a company),
  • Budget responsibility (yes/no),
  • Interest in products,
  • Preferred language,
  • Industry,
  • Website,
  • IP address,
  • geographical location ,
  • Browser type,
  • Duration of the visit,
  • pages viewed,
  • Information from completed forms (e.g. name, e-mail address, telephone number, message)(*).
  • File

* Mandatory data

Landing pages/websiteInventory data
  • Salutation, title, first name and surname (*),
  • Type of employment
  • Address data (regarding contact and billing address) such as street, postal code, city and country (*),
  • Communication data such as telephone (landline and cell phone number), fax and e-mail address,
  • department
  • Function in the company,
  • Company name,
  • Role in the purchasing process (consumer/entrepreneur/employee of a company),
  • Budget responsibility (yes/no)
  • Interest in products,
  • Preferred language,
  • Industry,
  • Website,
  • IP address,
  • geographical location,
  • browser type,
  • Duration of the visit,
  • pages viewed,
  • Information from completed forms (e.g. name, e-mail address, telephone number, message)(*).

*Mandatory information

Translation function with OpenAITraffic and usage data
  • Website,
  • IP address,
  • geographical location of the IP address,
  • geographical location as GPS date,
  • browser type,
  • operating system,
  • the device identifier,
  • name of the device,
  • the operating system,
  • the device identifier,
  • Browser used,
  • Duration of the visit,
  • pages accessed,
  • information about the use of the services, such as the type of content viewed or interacted with
  • functions used,
  • actions performed,
  • Time zone of access,
  • Country of access,
  • Date and time of access,
  • User agent and its version,
  • Type of computer or mobile device
  • Computer connection,
  • Information from completed forms (e.g. name, e-mail address, telephone number, message)(*).

*Mandatory information

Processing of data for fault and abuse controlTraffic and usage data
  • Browser type and browser version,
  • Operating system used,
  • URL,
  • referrer URL,
  • Host name of the accessing computer,
  • Date and time of the server request,
  • IP address.
Storage of consentsInventory data
  • Pseudonymous identifier of the end device,
  • Processing relevant to consent.
Use of Google AnalyticsTraffic and usage data
  • Name of the accessed website or url,
  • Date and time of the request,
  • Website from which the request comes,
  • Language setting of the browser,
  • Browser software and software version,
  • Device manufacturer and model name of the end device,
  • Operating system and version,
  • screen resolution,
  • location, country and geocoordinates,
  • Number of views within 24 hours
  • Returners within 24 hours,
  • IP address (anonymized).
Use of maps and route planningUsage data
  • Name of the accessed website or url,
  • Date and time of the request,
  • Website from which the request comes,
  • Language setting of the browser,
  • Browser software and software version,
  • Device manufacturer and model name of the end device,
  • Operating system and version,
  • screen resolution,
  • Location, country and geocoordinates,
  • Number of hits within 24 hours,
  • Returners within 24 hours,
  • IP address (anonymized).