Data protection
Data controller:
Name/Company: Langer & Laumann Ing.-Büro GmbH
Address: Wilmsberger Weg 8
Postcode, Town, Country: 48565 Steinfurt, Deutschland
Registered court: Steinfurt, HRB 2943
Managing Director: Dipl.-Ing. Martin Platt
Telephone number: +49 (2552) 92 7 91 0
Email adresse: info@lul-ing.de
Contact details of the Data Protection Officer:
Langer & Laumann Ing.-Büro GmbH
– Data Protection Officer –
Email: datenschutz@lul-ing.de
As at: 15.12.2020
1. General Information on Data Processing and Legal Bases
1.1. This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data within our online offering and the websites, functions, and content associated with it (hereinafter collectively referred to as the “online offering” or “website”). This Privacy Policy applies regardless of the domains, systems, platforms, and devices used (e.g. desktop or mobile) on which the online offering is executed.
1.2. The terminology used, such as “personal data” or “processing,” refers to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
1.3. The personal data of users processed within the scope of this online offering include:
- Login data (account data, email address)
- Inventory data (product inquiries, newsletter subscription – name, address, email)
- Usage data (website visitor tracking of our online offering)
- Content data (emails, contact request forms)
1.4. The term “users” includes all categories of persons affected by data processing. These include:
- Customers
- Interested parties
- Other visitors to our online offering
The terminology used, such as “users,” is to be understood as gender neutral.
1.5. We process users’ personal data only in compliance with the applicable data protection regulations. This means that user data is processed only if there is a legal basis for doingso. In particular, this applies if data processing is necessary to provide our contractual services (e.g. order processing) and online services, is legally required, based on user consent, or based on our legitimate interests (i.e. interest in the analysis, optimization, economic operation, and security of our online offering within the meaning of Art. 6 para. 1 lit. f GDPR), especially for reach measurement, creation of profiles for advertising and marketing purposes, and the collection of access data and use of third-party services.
1.6. We point out that the legal basis for consent is Art. 6 para. 1 lit. and Art. 7 GDPR; the legal basis for processing to fulfill our services and carry out contractual measures is Art. 6 para. 1 lit. b GDPR; the legal basis for processing to fulfill legal obligations is Art. 6 para. 1 lit. c GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6 para. 1 lit. f GDPR.
2. Security Measures
2.1. We take organizational, contractual, and technical security measures in accordance with the state of the art to ensure compliance with data protection laws and to protect the data processed by us against accidental or intentional manipulation, loss, destruction, or unauthorized access.
2.2. Security measures include, in particular, the encrypted transmission of data between your browser and our server.
3. Disclosure of Data to Third Parties and Third-Party Providers
3.1. Data is disclosed to third parties only within the scope of legal requirements. We pass on user data to third parties only if this is necessary, for example, pursuant to Art. 6 para. 1 lit. b GDPR for contractual purposes or pursuant to Art. 6 para. 1 lit. f GDPR based on legitimate interests in the economic and efficient operation of our business.
3.2. If we use subcontractors to provide our services, we take appropriate legal precautions as well as corresponding technical and organizational measures to ensure the protection of personal data in accordance with applicable legal regulations.
3.3. If, within the scope of this Privacy Policy, content, tools, or other resources from other providers (hereinafter collectively referred to as “third-party providers”) are used and their stated place of business is in a third country, it is assumed that data is transferred to the countries where the third-party providers are located. Third countries are countries in which the GDPR does not apply directly, i.e. generally countries outside the EU or the European Economic Area. Data is transferred to third countries only if an adequate level of data protection exists, user consent has been given, or another legal permission applies.
4. Contact
4.1. If you contact us by email, telephone, or fax, your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent. The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your request is related to the fulfillment of a contract or is it necessary to carry out pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively managing inquiries addressed to us (Art. 6 para. 1 lit. f GDPR). The data you send to us via contact requests will remain with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after your request has been fully processed). Mandatory statutory provisions – in particular, statutory retention periods – remain unaffected.
5. Collection of Access Data and Log Files
5.1. Based on our legitimate interests within the meaning of Art. 6 para. 1 lit. f GDPR, we collect data on every access to the server on which this service is located (so-called server log files). Access data includes the name of the accessed website, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address, and the requesting provider.
5.2. This server log information file is stored for security reasons (e.g. to investigate abuse or fraud) for a period of seven days (error log) or 60 days (access log) and then deleted. Data that must be retained for evidentiary purposes is excluded from deletion until the respective incident has been finally clarified. The server location is Germany.
6. Cookies & Reach Measurement
6.1. Cookies are information transmitted from our web server or third-party web servers to users’ web browsers and stored there for later retrieval. Cookies may be small files or other types of information storage.
6.2. We use “session cookies,” which are stored only for the duration of the current visit to our online presence (for storing the wish list function). A randomly generated unique identification number, known as a session ID, is stored in a session cookie. A cookie also contains information about its origin and storage period. These cookies do not store personal data. Session cookies are deleted when you end the use of our online offering, e.g. by logging out or closing the browser.
6.3. Users are informed about the use of cookies for reach measurement within the scope of this Privacy Policy.
6.4. If users do not want cookies to be stored on their device, they are asked to deactivate the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Excluding cookies may lead to functional restrictions on this online offering.
7. Reach Analysis with Matomo (formerly PIWIK)
7.1. Based on our legitimate interests (i.e. interest in the analysis, optimization, and economic operation of our online offering within the meaning of Art. 6 para. 1 lit. f GDPR), we use Matomo, an open-source software for the statistical evaluation of user access. Users’ IP addresses are shortened before being stored. Matomo uses cookies stored on users’ computers that enable analysis of the use of this online offering. Pseudonymous usage profiles of users may be created from the processed data.
7.2. The information generated by the cookie about your use of this online offering is stored on our server and not passed on to third parties.
Matomo status / enable and disable tracking.
8. Integration of Third-Party Services and Content
8.1. Within our online offering, we use content or service offerings from third-party providers based on our legitimate interests (i.e. interest in analysis, optimization, and economic operation within the meaning of Art. 6 para. 1 lit. f GDPR) in order to integrate their content and services, such as videos or fonts (hereinafter uniformly referred to as “content”). This always requires that the third-party providers of this content perceive users’ IP addresses, as they could not send the content to the browser without the IP address. The IP address is therefore required for displaying this content. We strive to use only content whose providers use the IP address solely to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. Pixel tags allow information such as visitor traffic on the pages of this website to be evaluated. The pseudonymous information may also be stored in cookies on users’ devices and may include technical information about the browser and operating system, referring websites, visit times, and other information about the use of our online offering, as well as be combined with such information from other sources.
8.2. The following overview lists third-party providers and their content, along with links to their privacy policies, which contain further information on data processing and, in some cases already mentioned here, opt-out options:
- Videos from the “YouTube” platform provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy
All videos are embedded in compliance with the GDPR. (In this case, YouTube still contacts Google’s DoubleClick service; however, according to Google’s Privacy Policy, personal data is not evaluated.) As a result, YouTube no longer stores information about website visitors unless they watch the video. If you click on the video, your IP address is transmitted to YouTube. If you are logged into YouTube at the same time, this information is also assigned to your user account.
9. Online Presences in Social Media
We maintain online presences within social networks and platforms in order to communicate with customers, interested parties, and users active there and to inform them about our services. We point out that user data may be processed outside the European Union. This may result in risks for users, for example because enforcing user rights may be more difficult. With regard to US providers certified under the Privacy Shield, we point out that they thereby commit to complying with EU data protection standards. Furthermore, user data is generally processed for market research and advertising purposes. For example, usage profiles may be created based on users’ behavior and resulting interests. These usage profiles may in turn be used to place advertisements within and outside the platforms that presumably correspond to users’ interests. For these purposes, cookies are generally stored on users’ devices in which usage behavior and interests are stored. Furthermore, data may also be stored in usage profiles independently of the devices used by users (especially if users are members of the respective platforms and logged in to them). The processing of users’ personal data is based on our legitimate interests in effective user information and communication pursuant to Art. 6 para. 1 lit. f GDPR. If users are asked by the respective platform providers for consent to the processing described above, the legal basis for processing is Art. 6 para. 1 lit. and Art. 7 GDPR. For a detailed description of the respective processing operations and opt-out options, we refer to the information provided by the providers linked below. In the case of information requests and the assertion of user rights, we also point out that these can be most effectively asserted with the providers. Only the providers have access to users’ data and can take appropriate measures and provide information directly. If you still need assistance, you may contact us.
-
Facebook pages and groups (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) based on an agreement on joint processing of personal data.
Privacy Policy: https://www.facebook.com/about/privacy/
Specifically for pages: https://www.facebook.com/legal/terms/information_about_page_insights_data
Specifically for Opt-Out: https://www.facebook.com/settings?tab=ads and http://www.youronlinechoices.com
Specifically for Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active -
Google / YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)
Privacy Policy: https://policies.google.com/privacy
Specifically for Opt-Out: https://adssettings.google.com/authenticated
Specifically for Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active -
LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland)
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
Specifically for Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
Specifically for Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active
10. Users’ Rights
10.1. Users have the right to receive, upon request and free of charge, information about the personal data stored about them.
10.2. Users also have the right to rectify incorrect data, restriction of processing, deletion of their personal data where applicable, to assert their right to data portability, and, in the event of unlawful data processing, to lodge a complaint with the competent supervisory authority.
10.3. Users may also revoke consent at any time, generally with effect for the future.
11. Deletion of Data
11.1. The data stored by us is deleted as soon as it is no longer required for its intended purpose and no statutory retention obligations prevent deletion. If user data is not deleted because it is required for other legally permissible purposes, its processing is restricted. This means the data is blocked and not processed for other purposes. This applies, for example, to user data that must be retained for commercial or tax law reasons.
11.2. Statutory retention periods are six years pursuant to § 257 para. 1 HGB (commercial books, inventories, opening balance sheets, annual financial statements, commercial letters, accounting documents, etc.) and ten years pursuant to § 147 para. 1 AO (books, records, management reports, accounting documents, commercial and business letters, documents relevant for taxation, etc.).
12. Right to Object
Users may object to the future processing of their personal data at any time in accordance with statutory provisions. The objection may in particular be made against processing for direct marketing purposes.
13. Changes to the Privacy Policy
13.1. We reserve the right to amend the Privacy Policy in order to adapt it to changes in the legal situation or to changes in the service and data processing. However, this applies only with regard to statements on data processing. If user consent is required or parts of the Privacy Policy contain provisions governing the contractual relationship with users, changes will be made only with user consent.
13.2. Users are requested to regularly inform themselves about the content of the Privacy Policy.