Privacy Statement
I. General information
1. Name and address of the data controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of member states as well as other data protection provisions is:
KAUP GmbH & Co. KG | Gesellschaft für Maschinenbau
Braunstrasse 17
63739 Aschaffenburg
Germany
Tel.: +49 6021 865 0
Website: www.kaup.de (contact)
2. Data protection officer
Our external data protection officer can be reached at the following address:
EDV Sachverständigen- und Datenschutzbüro Michael J. Schüssler
Kolpingstrasse 3
63739 Aschaffenburg
Germany
Tel.: +49 6021 439 1845
Website: www.datenschutz4you-aschaffenburg.de
3. Competent data protection authority
Landesamt für Datenschutzaufsicht
Promenade 27
91522 Ansbach
Germany
Tel.: +49 981 53 1300
Website: www.lda.bayern.de
II. General information on data processing
1. Scope of the processing of personal data
KAUP GmbH & Co. KG (KAUP) processes personal data of our users only to the extent it is needed to provide a functioning web site and for our content and services. The processing of personal data of our users is only carried out on a regular basis with the permission of the user. An exception exists in cases where obtaining permission in advance is not possible for practical reasons and the processing of the data is permitted by legal regulations.
2. Legal basis for the processing of personal data
Where we obtain the permission of the data subject for processing personal data, Art. 6 Para. 1 lit. a GDPR serves as the legal basis. When processing personal data necessary for the fulfilment of a contract for which the data subject is a party to the contract, Art. 6 Para. 1 lit. b GDPR serves as the legal basis. This also applies to processing necessary for carrying out pre-contract measures. If the processing is necessary to protect a legitimate interest of our organization or of a third party, and the first named interest does not outweigh the interests, basic rights and basic freedoms of the data subject, Art. 6 Para. 1 lit. f GDPR serves as the legal basis for processing.
3. Deleting data and retention periods
The personal data of the data subject will be deleted or locked as soon as it is no longer needed for the purpose it was stored for. Retention of data can also occur if this is provided for by European or national legislators with respect to EU regulations, laws or other provisions applicable to the data subject. Locking or deleting the data also occurs when a retention duration laid down by the specified standards expires, unless a need for continued retention of the data exists to complete or fulfil a contract.
III. Providing the web site
1. Description and scope of the data processing
We use the web analysis service 'Google Analytics' on this website. This service is provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies to recognise the user and thus analyse usage behaviour. These cookies are only set with consent. Consent can be revoked at any time and managed in our cookie consent tool.
2. Legal basis for data processing
The legal basis for the temporary retention of the data is Art. 6 Para. 1 lit. f GDPR.
3. Purpose of data processing
Temporary retention of the IP address by the system is necessary to enable the supply of the web site to the user's computer. To do so, the IP address of the user must be retained for the duration of the session. This purpose provides our justified interest in processing the data in accordance with Art. 6 Para. 1 lit. f GDPR.
4. Retention duration
The storage period depends on the type of data processed. Users can choose how long Google Analytics stores data before it is automatically deleted. The maximum lifespan of a Google Analytics cookie is one year.
5. SSL encryption
To protect the security of your data during transmission, we use an encryption process corresponding to the latest technology (e.g. SSL) via HTTPS.
6. Possibility to revoke and tracking opt-in
The information collected here is usually transferred to a Google server in the USA and stored there. On 10 July 2023, the European Commission adopted an adequacy decision for the USA. Google LLC is certified under the EU-US Privacy Framework. However, as the Google servers are located worldwide and data transfer to third countries (e.g. Singapore) cannot be ruled out, the EU Commission's Standard Contractual Clauses (SCC) apply. The use of Google Analytics results in IP anonymisation. The IP address of the respective user is truncated on servers within the member states of the EU (or the European Economic Area) in such a way that it is no longer possible to trace it back to a natural person. In addition, Google undertakes to provide appropriate data protection via the Google data processing conditions and creates an analysis of website use and website activity and provides the services associated with use. The Google Data Processing Terms apply to companies that are subject to the EU General Data Protection Regulation (GDPR) of the European Economic Area (EEA), the California Consumer Privacy Act (CCPA) or similar regulations.
Data processing is carried out on the legal basis of Art. 6 para. 1 lit f (legitimate interest) of the GDPR. KAUP's legitimate interest lies in the optimisation of our online offering and our website. As the privacy of our visitors is particularly important to us, you can object to the data processing described above at any time. Your objection will have no negative consequences for you. An additional browser plugin can be used to prevent the information collected (such as the IP address) from being sent to Google and used by Google. The plugin and further information can be found at
Further information on data protection at 'Google Analytics' can be found here.
7. Use of cookies
Our web site uses cookies for analysis purposes. Cookies are text files that are stored in the Internet browser or by the Internet browser on the user's computer system. When a user accesses our web site, a cookie can be stored in the operating system of the user. This cookie contains a characteristic sequence of characters (cookie ID) that allows a unique identification of the browser when the web site is accessed again.
The user data collected in this way is pseudonymised by technical precautions. It is therefore no longer possible to assign the data to the accessing user. The data is not stored together with other personal user data and is not used to create user profiles.
The legal basis for the processing of personal data using technically required cookies is Art. 6 Para. 1 lit. f GDPR. The legal basis for the processing of personal data when using cookies for analysis purposes when appropriate permission has been granted is Art. 6 Para. 1 lit. a GDPR.
When you call up our website, a large info banner (in the lower part of the screen) informs you about the use of cookies for analysis purposes and draws your attention to this data protection declaration. At this point, you have the opportunity to agree to the use of cookies for statistical purposes or to reject them. Statistical cookies are only used if you have given your consent to the processing of the personal data used in this context. You can change your settings at any time via this link: Open cookie settings. In addition, you can prevent cookies from being set by our website by means of a corresponding setting in the Internet browser you are using and thus permanently object to the setting of cookies. Furthermore, cookies already stored can be deleted at any time using the Internet browser or other software. This is possible in all current Internet browsers. If you deactivate cookies (see Point III. 6.) in the Internet browser used, under some circumstances not all functions of our Internet site will work to their full extent.
The following cookies are stored and transmitted on our website:
Name | Provider | Expiry | Purpose | Category |
---|---|---|---|---|
fe_typo_user | KAUP | After the session | Whenever forms are displayed or a login is used, this cookie is set by TYPO3 by default. | Necessary |
cookieConsent | KAUP | 1 year | Documents the click of the user on the cookie banner. | Necessary |
staticfilecache | KAUP | After the session | Is needed to optimize the delivery time of the website. | Necessary |
AWSALBTG | AWS | After the session | AWS Application Load Balancer Cookie: Load balancing cookie: used to encode information about the selected target group. | Necessary |
AWSALBTGCORS | AWS | After the session | AWS Application Load Balancer Cookie: Load balancing cookie: It contains the same information as the original stickiness cookie plus the SameSite attribute. | Necessary |
_ga | Google Inc. | 1 year | This third-party cookie is stored to recognise website users across multiple sessions. | Statistics |
_ga_(WB1ns2WSJ4) | Google Inc. | 1 year | This third-party cookie contains a randomly generated user ID. Google Analytics can use this ID to recognise returning users to this website and merge the data with data from previous visits to the site. | Statistics |
You can change your settings at any time via this link: Open cookie settings
8. Google Fonts
On our website we use Google Fonts to display external fonts. This is a service of Google LLC, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as "Google". The legal basis is Art. 6 para. 1 lit. f) DSGVO. Our legitimate interest lies in the optimisation and economic operation of our Internet presence.
In order to enable the display of certain fonts on our website, to improve loading times and to ensure uniform display across all devices, a connection to the Google server in the USA is established when our website is called up. Through the connection to Google established when calling up our website, Google can determine from which website your enquiry was sent and to which IP address the font representation is to be transmitted.
↗ Google offers further information and ↗ the possibilities of preventing the use of data.
9. Google Maps
In our internet presence we use the map service Google Maps via an API. This service is provided by Google LLC, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as "Google". The legal basis is Art. 6 para. 1 lit. f) DSGVO. Our legitimate interest lies in the ease with which you can find the places - company locations - indicated by us on the website. In order to use the functions of Google Maps, it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer.
↗ Google offers further information.
10. Social media plug-ins
We use social plug-ins from the social networks LinkedIn, Xing, Vimeo and Instagram on our website on the basis of Art. 6 para. 1 sentence 1 lit. f DSGVO in order to make ourselves better known. The advertising purpose behind this is to be regarded as a legitimate interest within the meaning of the DSGVO. The integration of these plug-ins by us is carried out by means of the so-called Shariff method in order to protect visitors to our website in the best possible way.
If you do not want the respective social networks to be able to directly assign the data collected via our website to your individual account, you must log out of the respective network before visiting our website.
a) LinkedIn
We use the social plug-in of the social media network LinkedIn (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland) on our website. The social plug-in is the link to our LinkedIn corporate site. The social plug-in is clearly marked with the well-known LinkedIn logo.
For any further processing, please note that the privacy policy of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland applies to our LinkedIn corporate site. ↗ More information about LinkedIn's processing of personal data.
b) Instagram
We use on our website the social plug-in of the Instagram social media network, operated by Meta Platforms Ireland Ltd, 4 Grand Canal Square, Dublin 2, Ireland. The social plug-in is a link to our Instagram account. The plugin is marked with an Instagram logo.
For any processing beyond this, we point out that the privacy policy Meta Platforms Ireland Ltd, 4 Grand Canal Square, Dublin 2, Ireland applies to our Instagram site. ↗ More information about Instagram's processing of personal data.
c) XING
On our website we use the social plug-in of the social media network XING, which is operated by New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany. The social plug-in is a link to our XING corporate site. The plug-in is marked with a XING logo.
For any further processing, we would like to point out that the data protection declaration of New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany is applicable on our XING company site. ↗ Further information on the processing of personal data by Xing.
d) Vimeo
On our website we use the social plug-in of the social media video network Vimeo, which is operated by Vimeo, Inc. 555 West 18th Street, New York, New York 10011, USA. The social plug-in is the link to our Vimeo channel. The plug-in is marked with a Vimeo logo or as a video.
When you visit one of our sites equipped with a Vimeo plug-in, a connection to the Vimeo servers is established. This tells the Vimeo server which of our pages you have visited. Vimeo also obtains your IP address. This also applies if you are not logged in to Vimeo or do not have an account with Vimeo. The information collected by Vimeo is transmitted to the Vimeo server in the USA.
If you are logged in to your Vimeo account, you allow Vimeo to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your Vimeo account.
For any processing beyond this, we would like to point out that the privacy policy of Vimeo, Inc., 555 West 18th Street, New York, New York 10011, USA is applicable to our Vimeo channel and embedded videos. ↗ More information about Vimeo's processing of personal data.
11. Newsletter
You can subscribe to a free newsletter on our website to receive information about the KAUP company and its products. Registration for the newsletter takes place using the double opt-in procedure. Our newsletter is organised by CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede (hereinafter: CleverReach) as a technical service. KAUP only uses CleverReach's software and computing capacities.
Your consent is obtained for the processing of the data as part of the registration process, and reference is made to this privacy policy. The legal basis for the processing of data after registration for the newsletter by the user is Art. 6 para. 1 lit. a GDPR if the user has given consent. No data is passed on to third parties in connection with the data processing for sending newsletters. The data is used exclusively for sending the newsletter.
The subscription to the newsletter can be cancelled by the user concerned at any time. For this purpose, there is a corresponding link in every newsletter. This also makes it possible to revoke consent to the storage of personal data collected during the registration process.
KAUP newsletters contain so-called tracking pixels to enable a statistical evaluation of the success or failure of online marketing campaigns. A tracking pixel is a miniature graphic that is embedded in e-mails sent in HTML format to enable log file recording and log file analysis. Based on the embedded tracking pixel, we can recognise whether and when an email was opened by a data subject and which links in the email were accessed. Such personal data collected via the tracking pixels contained in the newsletters are stored and evaluated by us in order to optimise the newsletter dispatch and to adapt the content of future newsletters even better to the interests of the data subject. Data subjects are entitled at any time to revoke the separate declaration of consent given in this regard via the double opt-in procedure. After cancellation, this personal data will be deleted by the controller. Unsubscribing from the newsletter is automatically interpreted as cancellation.
12. Registration log-in area
On our website, we offer users the opportunity to register by providing personal data. User registration is required for the provision of certain content and services on our website. Registered users can access the following additional content:
- (1) Prices: current prices for our attachments can be viewed on the respective product detail pages.
- (2) Price list: the current price list for KAUP is available to download.
- (3) Order documentation: all previous orders including the associated documentation can be viewed and downloaded.
- (4) eQuotation tool: the independent production of a binding offer is possible.
Our prices can only be viewed by authorised persons. Registration is therefore necessary in order to check this authorisation. The order documentation and the eQuotation tool represent added value for the registered user. Registration is necessary to prevent misuse of the information provided and to enable precise allocation.
The data is entered into an input mask and transmitted to us and stored. The legal basis for the processing of the data is Art. 6 para. 1 lit. a GDPR if the user has given consent. The data will not be passed on to third parties.
The data is deleted as soon as it is no longer required to fulfil the purpose for which it was collected. Users also have the option of deleting their registration or changing the stored data themselves at any time.
13. Contact forms
Our website includes several contact forms that can be used to contact us electronically. If a user makes use of these options, the data entered the input mask will be transmitted to us and stored. Your consent is obtained for the processing of the data as part of the sending process, and reference is made to this privacy policy.
The data will not be passed on to third parties in this context. The data is used exclusively for processing the conversation.
The legal basis for the processing of the data is Art. 6 para. 1 lit. a GDPR if the user has given consent.
14. Friendly Captcha (bot/spam protection)
Our website uses the “Friendly Captcha” service. This service is provided by Friendly Captcha GmbH, Am Anger 3-5, 82237 Wörthsee, Germany. Friendly Captcha is an innovative, data protection-friendly protection solution to make it more difficult for automated programs and scripts (so-called “bots”) to use our website.
For this purpose, we have integrated a program code from Friendly Captcha into our website, for example for contact forms, so that the visitor's end device can establish a connection to the Friendly Captcha servers in order to receive a calculation task from Friendly Captcha. The visitor's end device solves the calculation task, which requires certain system resources, and sends the calculation result to our web server. This contacts the Friendly Captcha server via an interface and receives a response whether the puzzle has been solved correctly by the end device. Depending on the result, we can assign security rules to requests via our website and, for example, process or reject them.
- The data is used exclusively to protect against spam and bots as described above.
- Friendly Captcha does not set or read any cookies on the visitor's end device.
- IP addresses are only stored in hashed, i.e. one-way encrypted format and do not allow us or Friendly Captcha to draw any conclusions about an individual person.
- If personal data is stored, this data is deleted within 30 days.
The legal basis for the processing is our legitimate interest in protecting our website from abusive access by bots, i.e. spam protection and protection against attacks such as mass requests), Article 6(1)(f) (GDPR).
↗ Further information on data protection when using Friendly Captcha
IV. Miscellaneous
1. Rights of the data subject
The data subject has the following rights
- Right of access (see Art. 15 GDPR)
- Right to rectification (see Art. 16 GDPR)
- Right to erasure (see Art. 17 GDPR)
- Right to restriction of processing (see Art. 18 et seq. GDPR)
- Right to data portability (see Art. 20 GDPR)
- Right to object (see Art. 21 GDPR)
- Right to withdraw consent under data protection law (see Art. 7 GDPR)
2. Right of complaint to a regulatory authority
Regardless of any other legal remedies relating to administrative or judicial law, you have the right of complaint to a regulatory authority, in particular in the member state where you are located, where your workplace is or in the location of the alleged offence, if you are of the opinion that the processing of your personal data contravenes the GDPR.
The regulatory authority where the complaint is made will inform the complainant of the progress and the results of the complaint including the possibility of judicial remedies in accordance with Art. 78 GDPR.
V. Restriction
KAUP GmbH & Co. KG reserves the right to change these data protection guidelines under consideration of the data protection requirements at any time.