1. Data protection at a glance
Data collection on our website
Who is responsible for data collection on this website?
Data is collected on this website by the website operator. You can obtain the website operator’s contact details from the legal notice on this website.
How do we collect your data?
Some data is collected when you provide it to us. This could, for example, be data you enter on a contact form.
Other data is collected automatically by our IT systems when you visit the website. This data consists primarily of technical data such as the browser and operating system you are using or when you accessed the page. This data is collected automatically as soon as you access our website.
What do we use your data for?
Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyse how you use the site.
What are your rights regarding your data?
You have the right at any time to obtain information free of charge on the origin, recipients and purpose of your stored personal data. You also have the right to have this data corrected, blocked or deleted. You may contact us via the address provided in the legal notice about this and any other questions you may have about data protection at any time. Moreover, you have the right to file complaints with the competent supervisory authority.
Furthermore, you have the right to demand restriction of processing of your personal data under certain circumstances. For additional details, please refer to the Privacy Statement, under “Right to restriction of processing”.
Analytics and third-party tools
You can object to this analysis. We will inform you below about how to exercise your options in this regard.
2. General notes and mandatory information
Please note that data transmitted via the internet (such as via email communication) may be subject to security breaches. Complete protection of your data from third-party access is not possible.
Information about the controller
The controller responsible for data processing on this website is:
ERFURT & SOHN KG
Phone: + 49 202 6110 0
The controller is the natural or legal person which, alone or jointly with others, makes decisions regarding the purposes and means for processing personal data (such as names, email addresses and similar).
Information on data transfer to the USA
Our website includes tools from companies based in the USA. When these tools are active, your personal information may be shared with the U.S. servers of the respective companies. We would like to point out that the USA is not a safe third country under EU Data Protection law. U.S. companies are required to disclose personal data to security authorities without your being able to take legal action. We cannot therefore rule out U.S. authorities (e.g. secret services) processing, evaluating and permanently storing your data on U.S. servers for surveillance purposes. We have no influence over these processing activities.
Withdrawal of your consent to the processing of your data
Many data processing operations are only possible with your express consent. You may withdraw your consent at any time. An informal email making this request is sufficient. The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to object against data collection in specific cases, as well as for direct marketing purposes (Art. 21 GDPR).
If data processing is performed based on Art. 6 (1) (e) or (f) GDPR, you have the right to object at any time to the processing of your personal data on grounds relating to your particular situation; this also applies to any profiling based on these provisions. Please refer to this Privacy Statement regarding the respective legal grounds for the processing of personal data. When you object, we will no longer process the affected personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or processing is made for the establishment, exercise or defense of legal claims (objection pursuant to Art. 21 (1) GDPR).
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. When you object to processing for direct marketing purposes, your personal data will no longer be processed for direct marketing purposes (objection pursuant to Art. 21 (2) GDPR).
Right to file complaints with supervisory authority
In the case of infringements of the GDPR, the affected data subjects have a right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.
Right to data portability
You have the right to have data which we process based on your consent or in fulfilment of a contract automatically delivered to yourself or to a third party in a standard, machine-readable format. If you require the direct transfer of data to another responsible party, this will only be done to the extent technically feasible.
SSL / TLS encryption
This website uses SSL and TLS encryption for security reasons and to protect the transmission of confidential content such as orders or enquiries you send to us as the site operators. You can recognise an encrypted connection in your browser’s address line when it changes from “http://” to “https://” and the lock icon is displayed in your browser’s address bar.
If SSL or TLS encryption is activated, third parties cannot read the data you transmit to us.
Information, blocking, deletion and rectification
You are entitled within the scope of applicable laws to be informed at any time and free of charge about your personal data which is stored, its origin and recipients and the purpose of data processing as well as correction, blocking or deletion of said data if applicable. You may contact us via the address provided in the legal notice about this and any other questions you may have about personal data at any time.
Right to restriction of processing
You have the right to demand restriction of processing of your personal data. For this purpose, you may contact us at the address provided in the legal notice. The right to restriction of processing applies in the following cases:
- If you contest the accuracy of the personal data stored at us, we will usually need some time to verify this claim. During the period we are verifying your claim, you have the right to demand restriction of processing of your personal data.
- If processing of your personal data was or is unlawful, you may demand restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need this data for the exercise, defense or establishment of legal claims, you have the right to demand restriction of processing of your personal data instead of deletion.
- If you objected pursuant to Art. 21 (1) GDPR, a balancing between your and our interests must take place. As long as it is not established which interests are overriding, you have the right to demand restriction of processing of your personal data.
In those cases where you have restricted processing of your personal data, such personal data may, with the exception of storage, only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.
Objection against advertising e-mails
The use of contact data published within the bounds of the disclaimer obligation to send advertising and information that is not expressly requested is hereby forbidden. The site operators expressly reserve the right to take legal action in the event that advertising information is sent through unrequested spam e-mails.
3. Data protection officer
Statutorily required data protection officer
We appointed a data protection officer for our company.
4. Data collection on our website
Most of the cookies we used are what are referred to as session cookies. They are deleted automatically after you end your visit. Other cookies remain on your device until you delete them. These cookies enable us to identify your browser the next time you visit us.
You can configure your browser to notify you when cookies are placed and to only permit cookies in exceptions, to exclude the acceptance of cookies in particular cases or in general as well as to automatically delete the cookies when you close your browser. Deactivating cookies may limit the functionality of this website.
Server log files
The website provider collects and stores information automatically in server log files, which your browser transmits to us automatically. These are:
- Browser type and version
- Used operating system
- Referrer URL
- Host name of the accessing device
- Time of the server request
- IP address
This data is not combined with other data sources.
Recording of this data is based on Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in the technical flawless presentation and optimization of its website - for this purpose server log files must be recorded.
If you send enquiries to us through the contact form, we will store the information you supplied in the contact form including any contact details for the purpose of processing your enquiry. We will not share this data without your consent.
The data entered into the contact form is therefore processed exclusively due to your consent (Art. 6 (1) (a) GDPR). You may withdraw your consent at any time. An informal email making this request is sufficient. The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
The data you enter into the contact form remains with us until you request that we delete it, withdraw your consent to its storage, or the purpose for which the data was stored becomes obsolete (e.g. after your enquiry has been processed). Mandatory statutory provisions - particularly record retention periods - remain unaffected.
Registration on this website
You may register on our website, so that you can use additional functions on our web pages. Data entered for this purpose is only used by us for the usage of the respective offer or service for which you registered. Mandatory information requested during the registration must be entered completely. We will refuse registration, if mandatory information is not entered completely.
In the case of important changes, e.g. scope of offerings or in the case of required technical changes, we will use the e-mail address provided with the registration to inform you of these facts.
The data entered with the registration is processed exclusively based on your consent (Art. 6 (1) (a) GDPR). You may withdraw your consent at any time. An informal email making this request is sufficient. The withdrawal of consent does not affect the lawfulness of prior processing.
We store the data recorded within the scope of your registration as long as you are registered with our website and is subsequently deleted. Statutory retention periods remain unaffected.
5. Analytics-tools and advertising
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses so-called "Cookies". These are text files which are stored on your computer and which allow an analysis of your use of the website. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States .
Storage of Google Analytics Cookies and use of this analysis tool is based on Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in analysing user behaviour, both to optimise its web presence and advertising. If a corresponding consent was requested (e.g. consent to store cookies), processing is exclusively performed based on Art. 6 (1) (a) GDPR; such consent may be withdrawn at any time.
We have activated the IP anonymisation function on this website. This means that your IP address is previously truncated within the member states of the European Union or other members of the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and truncated there. Google will use this information on behalf of the operator of this website to evaluate your use of the website, compile reports on website activity, and provide other services relating to website activity and internet usage for the website operator. Google will not associate your IP address with any other data held by Google.
You can set your web browser to prevent the storage of cookies; however, please note that you may not be able use all functions of this website to their full extent. Additionally you can prevent the acquisition of data which is received through generation of cookies regarding your use of the website (including your IP address) by Google as well as the processing of this data through Google, by downloading and installing the following browser plug in: https://tools.google.com/dlpage/gaoptout?hl=en.
Objection to data collection
You can prevent collection of your data by Google Analytics by clicking on the following link. Doing so will place an opt-out cookie which will prevent your data from being collected when you visit this website in future: Deactivating Google Analytics.
Data processing as a processor under GDPR
We have signed an agreement with Google on commissioned data processing and have fully implemented the strict standards of the German data protection authorities when using Google Analytics.
Google Analytics Demographics
This website uses the Demographics feature of Google Analytics. This enables reports to be generated with information about age, gender and interests of website visitors. This data is derived from interest-based advertising by Google as well as third-party data on visitors. This data cannot be attributed to a specific person. You can deactivate this function at any time in the advertising settings of your Google account or prohibit the collection of your data by Google Analytics in general as explained in “Objecting to data collection”.
Data stored at Google at user or event level that is linked to cookies, user IDs (e.g. User ID) or advertising IDs (e.g. DoubleClick-Cookies, Android-advertising-ID), will be rendered anonymous / will be deleted after 26 months. Details may be obtained at the following link: https://support.google.com/analytics/answer/7667196?hl=de.
Our website uses functions of the Online Marketing Software Provider HubSpot. HubSpot is an integrated software solution, with which we cover various aspects of our online marketing.
This includes, among others:
- Content Management (website and blog)
- E-Mail-Marketing (Newsletter, as well as automated mailings, e.g. provision of downloads)
- Social Media Publishing & Reporting
- Reporting (e.g. traffic sources, accesses, etc. …)
- Contact management (e.g. user segmentation & CRM)
- Landing pages and contact forms
Our registration service provides visitors of our website with the options to learn more about our company, to download content and to provide their contact information, as well as other demographic information.
This information and the contents of our website are stored on the servers of our software partner HubSpot. We can use this information to contact the visitors of our website and to ascertain which services of our company are of interest for visitors. All information recorded by us is subject to this data protection provision. We use all recorded information exclusively for the optimization of our marketing.
HubSpot is a software company located in the USA with a subsidiary in Ireland.
2nd Floor 30 North Wall Quay
Dublin 1, Ireland,
Telefon: +353 1 5187500
HubSpot is certified under the terms of the “EU – U.S. Privacy Shield Framework“ and is subject to the TRUSTe’s Privacy Seal, as well as the “U.S. – Swiss Safe Harbor“ Framework.
Additional information on the HubSpot data protection provisions: https://legal.hubspot.com/privacy-policy
Additional information by HubSpot regarding the EU data protection provisions: https://legal.hubspot.com/data-privacy
Additional information on cookies used by HubSpot can be accessed here: https://knowledge.hubspot.com/articles/kcs_article/reports/what-cookies-does-hubspot-set-in-a-visitor-s-browser
and here: https://knowledge.hubspot.com/articles/kcs_article/account/hubspot-cookie-security-and-privacy
Withdrawal of HubSpot Tracking Setting (Cookies): Please click here
If you wish to receive the Newsletter offered on our website, we will need your e-mail address, as well as information that allows us to verify that you are the holder of the provided e-mail address and that you agree to the receipt of the Newsletter. Additional data is not collected i.e. only on a voluntary basis. We use this data exclusively for the transmission of the requested information and we do not disclose this data to any third party.
The data entered into the Newsletter registration form is processed exclusively based on your consent (Art. 6 (1) (a) GDPR). You may withdraw your consent to the storage of the data, the e-mail address, as well as their use for the transmission of the Newsletter at any time, e.g. by using the “unsubscribe” link in the Newsletter. The withdrawal of consent does not affect the lawfulness of prior data processing operations.
We store the data provided to us for the receipt of the Newsletter until you unsubscribe from the receipt of the Newsletter and we will delete this data after you unsubscribed from the receipt of the Newsletter. Data stored at us for other purposes remain unaffected.
7. Plugins and tools
YouTube with extended data protection
Our website uses plugins of the website YouTube. Operator of the web pages is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.
We use YouTube with extended data protection mode. According to information provided by YouTube this mode has the effect that YouTube does not store any information of visitors of this website prior to visitors watching a video. Forwarding of data to YouTube partners is, however, not necessarily excluded by the extended data protection mode. For example, YouTube will establish - independent of you will watch a video or not - a connection to the Google DoubleClick network.
As soon as you start a YouTube video on our website, a connection to the servers of YouTube is established. Within the scope of this communication, the YouTube server is informed which pages you visited on our website. If you are logged into your YouTube account, you allow YouTube to match your web-browsing behavior directly with your personal profile. You can prevent this by logging-off from your Youtube account.
Furthermore, after the start of a video YouTube may store various cookies on your device. With the help of these cookies, YouTube may obtain information on visitors of our website. This information is, among others, used to record video statistics, to improve user friendliness and prevent fraud attempts. The cookies remain on your device until you delete them.
It is possible that after the start of a YouTube video additional data processing operations are triggered - we do not have any influence or control over such operations.
YouTube is used in the interest to provide an appealing presentation of our online offerings. This constitutes a legitimate interest in the meaning of Art. 6 (1) (f) GDPR.
Additional information on data protection at YouTube can be obtained from the YouTube Privacy Statement at: https://policies.google.com/privacy?hl=de.