top of page

Privacy Policy

This Privacy Policy explains the nature, scope and purposes of the processing of personal data (hereinafter referred to as “data”) within our online services, including associated websites, features and content, as well as our external online presences, such as our social media profiles (hereinafter collectively referred to as the “Online Services”).

For the definitions of terms used, such as “personal data” and “processing”, please refer to Article 4 of the General Data Protection Regulation (GDPR).

​

Data Controller:

Name / Company: DMV GmbH & Co. KG
Street / No.: Dieselstr. 3–7
Postal Code / City: 31812 Bad Pyrmont
Commercial Register / Registration No.: HRA 100493
Managing Directors: Lars Diedrichs, Markus Spieker
Telephone: +49 (0) 5281 – 6052 0
Email: info@dmv-group.com
Contact the Data Protection Officer: datenschutz@dmv-group.com
Whistleblower Protection – DMV Internal Reporting Office: https://whistleblowersoftware.com/secure/DMV-Group-Hinweisgebermeldesystem

Types of Data Processed

  • Master data (e.g. names, addresses).
  • Contact data (e.g. email addresses, telephone numbers).
  • Content data (e.g. text entered, photographs, videos).
  • Usage data (e.g. websites visited, interest in content, access times).
  • Metadata / communication data (e.g. device information, IP addresses).

Processing of Special Categories of Data (Article 9(1) GDPR)

As a general rule, no special categories of data are processed unless users provide such data for processing, for example by entering it in online forms.

Categories of Individuals Affected by the Processing

  • Customers / prospective customers / suppliers.
  • Visitors to and users of the Online Services.
  • Job applicants.
  • Employees.

Hereinafter, the individuals affected are also collectively referred to as “users”.

Purposes of Processing

  • Providing the Online Services, their content and features.
  • Providing contractual services, support and customer care.
  • Responding to enquiries and communicating with users.
  • Marketing, advertising and market research.
  • Providing employee information through tool x.

1. Applicable Legal Bases

In accordance with Article 13 GDPR, we inform you of the legal bases for our data processing. Unless a legal basis is specified in this Privacy Policy, the following applies:

The legal basis for obtaining consent is Article 6(1)(a) and Article 7 GDPR. The legal basis for processing data to provide our services, carry out contractual measures and respond to enquiries is Article 6(1)(b) GDPR. The legal basis for processing data to comply with our legal obligations is Article 6(1)(c) GDPR, and the legal basis for processing data to safeguard our legitimate interests is Article 6(1)(f) GDPR.

Where the vital interests of the data subject or another natural person make the processing of personal data necessary, Article 6(1)(d) GDPR serves as the legal basis.

2. Changes and Updates to the Privacy Policy

Please review the content of our Privacy Policy regularly. We amend this Privacy Policy whenever changes to our data processing activities make this necessary. We will inform you whenever such changes require action on your part, such as providing consent, or otherwise require individual notification.

3. Security Measures

3.1. In accordance with Article 32 GDPR, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. In doing so, we take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input and disclosure of the data, ensuring its availability and keeping it separate.

We have also established procedures to enable the exercise of data subject rights, the erasure of data and responses to threats to data security. Furthermore, we take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and by default (Article 25 GDPR).

3.2. Our security measures include, in particular, the encrypted transfer of files between your browser and our server.

4. Working with Processors and Third Parties

4.1. If, in the course of our processing activities, we disclose data to other individuals or companies (processors or third parties), transfer data to them or otherwise grant them access to the data, we do so only where permitted by law, where you have given your consent, where a legal obligation requires it, or on the basis of our legitimate interests.

This includes, for example, transfers to third parties such as payment service providers where necessary for the performance of a contract under Article 6(1)(b) GDPR, or the use of service providers, web hosting providers and similar parties on the basis of our legitimate interests.

4.2. Where we engage third parties to process data under a “data processing agreement”, this is done in accordance with Article 28 GDPR.

5. Transfers to Third Countries

If we process data in a third country, meaning a country outside the European Union (EU) or the European Economic Area (EEA), or if such processing takes place through the use of third-party services or the disclosure or transfer of data to third parties, we do so only where necessary to fulfil our contractual or pre-contractual obligations, on the basis of your consent, to comply with a legal obligation, or on the basis of our legitimate interests.

Subject to statutory or contractual permissions, we process data, or have data processed, in a third country only where the specific requirements of Articles 44 et seq. GDPR are met. This means, for example, that processing takes place on the basis of specific safeguards, such as an officially recognised finding that the level of data protection is equivalent to that of the EU (e.g. the “Privacy Shield” for the USA), or compliance with officially recognised specific contractual obligations known as “Standard Contractual Clauses”.

6. Rights of Data Subjects

6.1. In accordance with Article 15 GDPR, you have the right to obtain confirmation as to whether personal data concerning you is being processed, access to that data, further information and a copy of the data.

6.2. In accordance with Article 16 GDPR, you have the right to request that incomplete data concerning you be completed and that inaccurate data concerning you be rectified.

6.3. In accordance with Article 17 GDPR, you have the right to request that data concerning you be erased without undue delay or, alternatively, to request restriction of processing in accordance with Article 18 GDPR.

6.4. In accordance with Article 20 GDPR, you have the right to receive the data concerning you that you have provided to us and to request its transfer to another controller.

7. Right to Withdraw Consent

You have the right to withdraw consent you have given at any time, with effect for the future, in accordance with Article 7(3) GDPR.

8. Right to Object

In accordance with Article 21 GDPR, you may object at any time to the future processing of data concerning you. In particular, you may object to processing for direct marketing purposes.

9. Cookies and the Right to Object to Direct Marketing

We use temporary cookies, meaning small files stored on users’ devices. For an explanation of the term and how cookies work, please refer to the final section on cookies in this Privacy Policy.

Some cookies serve security purposes or are necessary for the operation of our Online Services, for example to display the website or to store the user’s choice when confirming the cookie banner.

You can opt out of cookies used for online marketing purposes by many services, particularly those involving tracking, through the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/.

You can also prevent cookies from being stored by disabling them in your browser settings. Please note that this may prevent you from using all the features of our Online Services.

10. Erasure of Data

10.1. Data processed by us is erased or its processing restricted in accordance with Articles 17 and 18 GDPR. Unless expressly stated otherwise in this Privacy Policy, data stored by us is erased as soon as it is no longer required for its intended purpose, provided that no statutory retention obligations prevent its erasure.

If data is not erased because it is required for other legally permissible purposes, its processing is restricted. This means that the data is blocked and is not processed for other purposes. This applies, for example, to data that must be retained for reasons relating to commercial or tax law.

10.2. Under statutory requirements, records are retained, in particular, for six years pursuant to Section 257(1) of the German Commercial Code (HGB), including commercial books, inventories, opening balance sheets, annual financial statements, commercial correspondence and accounting records, and for ten years pursuant to Section 147(1) of the German Fiscal Code (AO), including books, records, management reports, accounting records, commercial and business correspondence, and documents relevant to taxation.

11. Provision of Contractual Services

11.1. We process master data, such as users’ names, addresses and contact details, and contract data, such as services used, names of contact persons and payment information, to fulfil our contractual obligations and provide services in accordance with Article 6(1)(b) GDPR.

Information marked as mandatory in online forms is required to enter into a contract.

12. Contacting Us

12.1. When you contact us by contact form or email, the information you provide is processed to handle and respond to your enquiry in accordance with Article 6(1)(b) GDPR.

12.2. Users’ information may be stored in our customer relationship management system (“CRM system”) or a comparable enquiry management system.

13. Collection of Access Data and Log Files

13.1. On the basis of our legitimate interests within the meaning of Article 6(1)(f) GDPR, we collect data about every access to the server on which this service is hosted, known as server log files.

Access data includes the name of the website or file accessed, the date and time of access, the amount of data transferred, confirmation of successful retrieval, browser type and version, the user’s operating system, the referrer URL (the previously visited page), the IP address and the requesting internet service provider.

13.2. For security reasons, such as investigating misuse or fraud, log file information is retained for the period covering the last complete calendar year and then deleted. Data that must be retained for evidentiary purposes is exempt from deletion until the relevant incident has been fully resolved.

14. Online Presences on Social Media

14.1. We maintain online presences on social networks and platforms to communicate with customers, prospective customers and users who are active there and to inform them about our services.

When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.

14.2. Unless otherwise stated in this Privacy Policy, we process users’ data when they communicate with us through social networks and platforms, for example by posting on our online presences or sending us messages.

15. Cookies and Audience Measurement

15.1. Cookies are information transmitted by our web server or third-party web servers to users’ web browsers and stored there for later retrieval. Cookies may consist of small files or other forms of information storage.

15.2. We use “session cookies”, which are stored only for the duration of your current visit to our online presence. For example, they may store your login status or enable the shopping cart function, thereby making it possible to use our Online Services.

A session cookie stores a randomly generated unique identification number, known as a session ID. A cookie also contains information about its origin and storage period. These cookies cannot store any other data.

Session cookies are deleted when you finish using our Online Services, for example when you log out or close your browser.

15.3. Users are informed in this Privacy Policy about the use of cookies for pseudonymous audience measurement.

15.4. If users do not want cookies to be stored on their computers, they should disable the corresponding option in their browser settings. Stored cookies can be deleted in the browser settings. Disabling cookies may limit the functionality of our Online Services.

15.5. You can opt out of cookies used for audience measurement and advertising purposes through the Network Advertising Initiative’s opt-out page at http://optout.networkadvertising.org/, as well as through the US website http://www.aboutads.info/choices or the European website http://www.youronlinechoices.com/uk/your-ad-choices/.

15.6. This website uses Google Analytics, a web analytics service provided by Google Inc. (“Google”). Its use is based on Article 6(1), first sentence, point (f) GDPR.

Google Analytics uses “cookies”, which are text files stored on your computer that enable an analysis of your use of the website. The information generated by the cookie about your use of the website, such as:

  • Browser type and version.
  • Operating system used.
  • Referrer URL (the previously visited page).
  • Hostname of the accessing computer (IP address).
  • Time of the server request.

is generally transmitted to a Google server in the USA and stored there.

The IP address transmitted by your browser as part of Google Analytics is not combined with other data held by Google. We have also added the “anonymizeIP” code to Google Analytics on this website. This ensures that your IP address is masked so that all data is collected anonymously. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there.

On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity and provide the website operator with other services relating to website and internet usage.

You can prevent cookies from being stored by adjusting your browser settings. However, please note that in this case you may not be able to use all the features of this website to their full extent.

You can also prevent Google from collecting the data generated by the cookie relating to your use of the website, including your IP address, and from processing this data by downloading and installing the browser plug-in available at the following link:

http://tools.google.com/dlpage/gaoptout?hl=de

As an alternative to the browser add-on, particularly when using browsers on mobile devices, you can also prevent collection by Google Analytics by clicking this link. An opt-out cookie will be set to prevent your data from being collected during future visits to this website.

The opt-out cookie applies only to this browser and our website and is stored on your device. If you delete the cookies in this browser, you will need to set the opt-out cookie again.

[Note: Instructions on implementing the opt-out cookie are available at: https://developers.google.com/analytics/devguides/collection/gajs/?hl=de#disable.]

We also use Google Analytics to analyse data from DoubleClick cookies and AdWords for statistical purposes. If you do not wish this to occur, you can disable it through the Ads Preferences Manager:

http://www.google.com/settings/ads/onweb/?hl=de

Further information about data protection in connection with Google Analytics is available, for example, in Google Analytics Help:

https://support.google.com/analytics/answer/6004245?hl=de

You can adjust your cookie settings here.

16. Integration of Third-Party Services and Content

16.1. On the basis of our legitimate interests, meaning our interest in analysing, optimising and operating our Online Services economically within the meaning of Article 6(1)(f) GDPR, we use content or services provided by third parties to integrate their content and services, such as videos or fonts, into our Online Services. These are collectively referred to below as “content”.

This always requires the third-party providers of such content to receive users’ IP addresses, as they would otherwise be unable to send the content to users’ browsers. The IP address is therefore necessary to display this content.

We endeavour to use only content whose providers use IP addresses solely to deliver the content.

Third-party providers may also use “pixel tags”, which are invisible graphics also known as “web beacons”, for statistical or marketing purposes. Pixel tags can be used to analyse information such as visitor traffic on the pages of this website.

Pseudonymous information may also be stored in cookies on users’ devices. This information may include technical details about the browser and operating system, referring websites, the time of the visit and other information about the use of our Online Services. It may also be combined with such information from other sources.

16.2. The following overview lists third-party providers and their content, together with links to their privacy policies. These policies provide further information about data processing and opt-out options, some of which are also listed below:

Last updated: July 2018


Hinweis vor Veröffentlichung: Im Ausgangstext stehen noch „Tool x“ sowie Verweise wie „diesen Link“ und „hier“, für die keine Zieladresse angegeben wurde. Außerdem sollte die Fassung mit Stand Juli 2018 einschließlich der Rechtsgrundlagen, Aufbewahrungsfristen und Anbieterangaben durch den Datenschutzbeauftragten geprüft werden.

bottom of page