Privacy

  
Here you will find all information about privacy at HERMA. Please select the appropriate area.

  

Information on the use of personal data (HERMA Sales)

Here you will find information for HERMA customers. All customers receive already these document with their contract documents. In addition, the information is documented here and available for download.

HERMA Sales - Information on the use of personal data (English)

HERMA Vertrieb - Information über die Nutzung von personenbezogenen Daten (Deutsch)

HERMA Distribution - Informations sur l'utilisation des données personelles (Français)

HERMA Verkoop - Informatie over het gebruik van persoonsgegevens (Nederlands)

HERMA Ventas - Información sobre el uso de datos personales (Español)


Data Protection Declaration of the HERMA Group (HERMA)
Websites

  
Status: 01.05.2018

We attach great importance to the protection of your personal data which you provide to us when you visit and use our website.

Your personal data, e.g. name, address, e-mail address or telephone number, will always be processed in accordance with the General Data Protection Regulation and the country-specific data protection regulations which apply to HERMA. If there is legal basis for this processing, we will normally obtain your consent.

The HERMA website can normally be used without providing any personal data. However, if you want to make use of special services via our website, it may be necessary to process personal data.

Through this Data Protection Declaration we would like to inform you, as a visitor to our website, about the nature, extent and purpose of the personal data which we collect, use and process. Your rights are also explained.

  

Table of contents

  1. Responsibility for data processing
  2. Contact with the Data Protection Officer
  3. Definitions of terms
  4. Recording of general data and information
  5. Registration on our website
  6. Subscription to our newsletters
  7. Contact forms
  8. Online application form
  9. Data security
  10. Cookies
  11. Use of YouTube
  12. Use of functions of the Amazon partner programme
  13. Use of Google Analytics (with an anonymisation function)
  14. Use of the website prospecting and personalisation tool Lea
  15. Use of Google Adwords
  16. Use of Bing Ads
  17. Legal or contractual regulations relating to the supply of personal data
  18. Storage period, erasure and blocking of personal data
  19. Rights of website visitors
  20. Existence of automated decision-making

  

1. Responsibility for data processing

Each HERMA Group company operating the website is responsible for data processing.

herma.com, herma.de, herma.at, herma.ch, herma.co.uk, herma.fr, herma.se, herma-etiquetas.es, herma-etichette.it, herma.fi, herma.dk, herma.no, herma.pl, herma.pt, herma-etikettierer.de, herma-etikettierer.ch, herma-labeler.com, herma-etiketten.de, herma-etiketten.at, herma-etiketten.ch, herma-labels.com, herma-etiquettes.fr, herma-labels.nl, herma-material.de, herma-material.fr and herma-material.es

HERMA GmbH
Fabrikstraße 16, 70794 DE-Filderstadt
Tel.: +49 711 / 7702 0  |  Fax: +49 711 / 7702 700  |  E-mail: mail(at)herma.de
 

herma-labellingmachines.co.uk and herma-material.com

HERMA UK LIMITED
The Hollands Centre, Hollands Road, GB-Haverhill, Suffolk CB9 8PR
Tel.: +44 / 1440763366 | Fax: +44 / 1440706834 | E-mail: sales(at)herma.co.uk
 

herma-etiqueteuses.fr

HERMA France S.A.R.L
Parc d'activité de la forêt, 11, Rue de la Forêt, F-67930 Beinheim
Tel.: +33 / 388050580 | Fax: +33 / 388734244 | E-mail: info-fr(at)herma.com
 

herma.nl and herma.be

HERMA Benelux B.V.
Gildeweg 11, NL-3771 NB Barneveld
Tel.: +31 / 342 820217 | Fax: +31 / 342 400722 | E-mail: info(at)herma.nl
 

herma-etikettierer.at

HERMA Etikettiersysteme Gesellschaft m.b.H.
Handelsstraße 6, A-3130 Herzogenburg
Tel.: +43 2782 / 20130-30 | Fax: +43 2782 / 20130-22 | E-mail: office(at)herma.at
 

herma.us

HERMA US Inc.
39 Plymouth Street, Suite 300, US-Fairfield, N.J. 07004
Tel.: +1 973 / 521-7254 | Fax: +1 973 / 521-7943 | E-mail: info-usa(at)herma.com

  

2. Contact with the Data Protection Officer

If you have any questions or suggestions relating to data protection, you may directly contact at any time our employees in each responsible company belonging to the HERMA Group and the Data Protection Officer for HERMA GmbH.

You may contact the Data Protection Officer of HERMA GmbH as follows:
HERMA GmbH, Fabrikstraße 16, 70794 Filderstadt, Germany
To: The Data Protection Officer
E-mail: datenschutz(at)herma.de

  

3. Definitions of terms

Our Data Protection Declaration should be easy to read and comprehensible both for the general public and our customers and business partners. The following terms from our Data Protection Declaration originate from the GDPR.

a) Personal data
Personal data’ means any information relating to an identified or identifiable natural person (hereinafter called ‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

b) Data subject
A data subject is every identified or identifiable natural person whose personal data are processed by the controller.

c) Processing
Processing of personal data includes collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Restriction of processing
Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.

e) Profiling
Means any form of automated processing of personal data consisting of the use of these personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

f) Pseudonymisation
Pseudonymisation means the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that this additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

g) Controller
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

h) Processor
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

i) Recipient
Recipient means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.

j) Third party
A third party means a natural or legal person, public authority, agency or body other than the data subject. controller, processor and persons who, under the direct authority of the controller or the processor, are authorised to process personal data.

k) Consent
Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

  

4. Recording of general data and information

Every time a data subject visits an individual website, the web pages of HERMA collect a range of general data and information which are stored in the server's log files. The following data and information may be collected: (1) Utilised browser types and versions, (2) The operating system used by the accessing system, (3) The website from which an accessing system reaches our website (so-called "referrer"), (4) The sub-websites which are controlled via an accessing system on our website, (5) The date and time of access to the website, (6) An Internet protocol address (IP address), (7) The Internet service provider of the accessing system and (8) Other similar data and information which are used to avert danger in the case of attacks on our computer systems.

This involves information which does not make your person identifiable. This information is used instead to (1) correctly show the contents of our website, (2) optimise the contents of our website and advertising for the website, (3) ensure permanent operability of our computer systems and the technology used on our website, and (4) provide prosecution authorities with the information required for criminal proceedings in the event of a cyber attack.

These anonymously recorded data and information are therefore evaluated by HERMA for statistical purposes and also to increase data protection and data security in our companies so that an optimum protection level is ultimately attained for the personal data which we process. The anonymous data in the server log files are stored separately from all personal data provided by you.

  

5. Registration on our website

The personal data transmitted to HERMA arise from the respective input mask which is used for registration. This normally entails the mandatory fields - e-mail address and name - and voluntary information about gender, forename, phone number and fax number. Without your separate consent, the entered personal data will only be collected and processed to enable us to supply services.

Registration is necessary at times in order to offer you content or services which, due to their nature, can only be provided to registered users, e.g. storage of the label templates in the Online Label Assistant and customer service via the service portal for machines. The legal basis for data processing is Article 6 (1) lit. b and lit. f of the General Data Protection Regulation since processing of your personal data is necessary to furnish the offered (contractual) services and HERMA has a justified interest in customer support in the form of customer services.

HERMA may arrange for data to be transferred to one or more contract processors, e.g. a parcel service provider, who will also use personal data solely for internal purposes on behalf of HERMA.

Through registration on the website, the date and time of registration are also assigned to and stored in the customer's account. These data are stored automatically for purposes of proof and given the fact that this is the only way to prevent misuse of our services and that these data can be used, if necessary, to investigate criminal offences. These data must therefore be stored in order to protect HERMA: Generally speaking, these data will not be passed on to third parties, unless there is a legal obligation to do so or transmission of the data is required for criminal prosecution proceedings.

On request, HERMA will provide you at any time with information about your personal data which we have stored. HERMA will also rectify or erase personal data at your request or indication, provided there are no legal retention obligations in this respect. The Data Protection Officers or, if no Data Protection Officer was appointed for the controller, every employer of the respective controller are available to you as contact persons in this case.

  

6. Subscription to our newsletters

You can subscribe to our company's newsletters on the HERMA website. HERMA regularly informs customers and business partners in a newsletter about offers from the company. The personal data transmitted to each controller during registration for the newsletter arise from the input mask used for this purpose. This normally entails the mandatory field - e-mail address - and voluntary information such as salutation, forename and surname.

We will only collect and process the entered personal data with your consent. We will use these data to send you our newsletter. Subscribers to the newsletter could also be informed by e-mail if this is necessary to operate the newsletter service or register for the newsletter, e.g. in the event of changes to the newsletter service or a change to the technical conditions. The legal basis for use of these data is Article 6 (1) lit. a of the General Data Protection Regulation (consent). The following consent to storage of personal data for newsletter delivery, which you granted us when registering for the newsletter on our website, may be revoked at any time with effect for the future. For the purpose of revocation of your consent, every newsletter contains a corresponding link or a contact e-mail address. We will erase these personal data after revocation of your consent.

Consent to the use of data for newsletter delivery

I hereby agree that HERMA GmbH (Fabrikstrasse 16, 70794 Filderstadt) may store and use the personal data, which I entered when subscribing to the newsletter, to send me the newsletter. The legal basis for use of these data is Article 6 (1) lit. a of the General Data Protection Regulation (consent). This Declaration of Consent may be revoked at any time with effect for the future. For the purpose of revocation of consent, every newsletter contains a corresponding link or a contact e-mail address. We will erase these personal data after revocation of consent.

The personal data collected as part of the newsletter service will be transmitted to the contract data processor Inxmail GmbH which provides HERMA with the necessary infrastructure for newsletter delivery and to the contract data processor Verdure Medienteam GmbH which provides technical support for the website.

The personal data collected as part of the newsletter service will be transmitted to the contract data processor Inxmail GmbH which provides HERMA with the necessary infrastructure for newsletter delivery and to the contract data processor Verdure Medienteam GmbH which provides technical support for the website.

Due to legal reasons, a confirmation e-mail using the double opt-in process will be sent to the e-mail address which you entered for the first time for delivery of the newsletter. This confirmation e-mail is used to verify whether you, as the owner of the e-mail address, have authorised receipt of the newsletter.

When you subscribe to the newsletter, we will also store the IP address assigned by the Internet service-provider (ISP) as well as the date and time of subscription. It is necessary to collect these data in order to track (possible) misuse of your e-mail address at a later date. It therefore legally protects our company. The legal basis for use of these data is Article 6 (1) lit. f of the GDPR (legitimate interest of HERMA). Our newsletters contain so-called tracking pixels. We use the embedded tracking pixel to determine whether and when an e-mail was opened and what links in the e-mail were opened. The success or failure of online marketing campaigns can therefore be evaluated.

HERMA will not collect or store any personal data via the tracking pixels contained in the newsletters. The information collected in this way will be collected, stored and evaluated in an anonymised form in order to optimise newsletter delivery and adapt the content of future newsletters even more closely to your interests.

  

7. Contact forms

You can contact HERMA either by e-mail or by using a contact form. The personal data transmitted to HERMA in this respect arise from the respective input mask which is used to make contact. This normally entails the mandatory boxes - e-mail address and surname - and voluntary information about salutation, forename, phone number and fax number of the inquirer.

Without your separate consent, the entered personal data will be used only for the purposes of making contact in order to process your inquiry.

Data collection and processing through the contact form are based on Article 6 (1) lit. f of the General Data Protection Regulation since HERMA has an economic interest in making contact in order to ensure that communication with you is established as quickly and as easily as possible through these additional services. Product inquiries are also used to initiate a contract.

These personal data will only be transmitted to third parties if this is necessary to process a resulting order.

  

8. Online application form

We collect and process personal data from applicants if an applicant sends us corresponding application documents in encrypted form using the application form on the website. The personal data transmitted to HERMA in this respect arise from the respective input mask which is used for online application. This normally entails the mandatory fields - name, address, phone number and e-mail address. These data are used to assign the applicant and make contact with him/her.

According to § 26 of the German Federal Data Protection Act (2018), the application data are used solely to handle the application process. If HERMA concludes an employment contract with an applicant, the transmitted data are stored for employment-related purposes in accordance with legal regulations.

The application documents are processed by the HR Department and may be passed on to the corresponding technical department. These documents may not be transmitted to third parties

If HERMA cannot find a suitable job matching the applicant's profile in the company, the application documents will normally be erased automatically three months after the application has been rejected.

  

9. Data security

If you transmit your personal data to HERMA via our website (e.g. via the application form, contact form, etc.), they are transmitted in encrypted form (with 128/256 Bit). We have implemented technical and organisational measures to protect our website and other systems against loss, destruction, access to, amendment or dissemination of your data by unauthorised persons.

Would you please only enter your data directly via our website. If you receive unsolicited e-mails in which you are requested to provide or confirm personal information or payment details, plesae ignore these letters and inform your HERMA team at the following e-mail address: ecommerce(at)herma.de.

  

10. Cookies

HERMA's websites use cookies. Cookies are text files which are placed and stored on a computer system by an Internet browser. A large number of cookies contain a so-called cookie ID. A specific Internet browser can be recognised and identified by means of the clear cookie ID.

Through the use of cookies HERMA can provide users of this website with more user-friendly services which would not be possible without setting cookies.

A cookie can be used to optimise the information and offers on our website for the benefit of the user. As already mentioned, cookies enable us to recognise the users of our website. The purpose of this recognition is to make it easier for users to utilise our website. For example, the user of a website utilising cookies need not re-enter his/her access data during every visit to the website since this task is performed by the website and the cookie stored on the user's computer system. Another example is the cookie of a goods basket in the online shop. The online shop notes via a cookie the product which a customer has placed in the virtual goods basket.

You can prevent the placement of cookies by our website at any time through a corresponding setting in the utilised Internet browser and therefore permanently reject the placement of cookies. Cookies which have already been placed can also be erased at any time by means of an Internet browser or other software programs. This is possible in all current Internet browsers. If you deactivate the placement of cookies in the utilised Internet browser, it may be impossible to use all the functions of our website.

  

11. Use of YouTube

HERMA has integrated components of the Internet video portal YouTube on this website.

The company operating YouTube is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA. You can find further information about YouTube at: www.youtube.com/intl/en/yt/about/.

Whenever you visit one of the individual pages of this website which is operated by HERMA and on which a YouTube component (YouTube video) was integrated, the Internet browser on your device is automatically prompted by the respective YouTube component to call up a display of the corresponding YouTube component from YouTube. You can find further information about YouTube at: www.youtube.com/intl/en/yt/about/. During this technical process YouTube and Google are informed about the specific subpage of our website which you visited.

If you are also logged into YouTube, YouTube recognises when a subpage containing a YouTube video is called up what specific subpage of our website you are visiting. This information is collated by YouTube and Google, and is assigned to your YouTube account.

The YouTube component always informs YouTube and Google that you visited our website if you are also logged into YouTube at the time our website is called up; this happens irrespective of whether or not you click on a YouTube video. If you do not want this information to be transmitted to YouTube and Google, you can prevent it by logging out of your YouTube account before visiting our website.

The data protection regulations published by YouTube, which can be called up at www.google.de/intl/en/policies/privacy/, contain information on the collection, processing and use of personal data by YouTube and Google.

  

12. Use of functions of the Amazon partner programme

As a participant in the Amazon partner programme, HERMA has integrated Amazon components on this website. The Amazon components were designed by Amazon in order to procure customers via advertisements on different websites of the Amazon Group, especially Amazon.co.uk, Local.Amazon.co.uk, Amazon.de, BuyVIP.com, Amazon.fr, Amazon. It, Amazon.es and BuyVIP.com on payment of a commission.

The company operating these Amazon components is Amazon EU S.à.r.l, 5 Rue Plaetis, L-2338 Luxembourg, Luxemburg.

Amazon sets a cookie on your device. It was already explained beforehand what cookies are. Every time you visit one of the individual pages of this website which is operated by HERMA and on which an Amazon component was integrated, the Internet browser on your device is automatically prompted by the respective Amazon component to send data to Amazon for the purpose of online advertising and bill commissions to Amazon. During this technical process Amazon obtains information about personal data which help Amazon to trace the origin of orders it receives and then bill commission. Amazon may, for example, see that you clicked a partner link on our website.

As described in § 10, you can permanently object to cookies being set by our website.

Further information and the valid data protection regulations of Amazon are available online at: www.amazon.co.uk/gp/help/customer/display.html/ref=footer_privacy.

  

13. Use of Google Analytics (with an anonymisation function)

HERMA has integrated the component of the Web analysis service Google Analytics (with an anonymisation function) on this website.

The operator of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

HERMA uses the suffix "_gat._anonymizeIp" for Web analysis via Google Analytics. Using this suffix, the IP address of your Internet connection is truncated and anonymised by Google if our web pages are accessed from within any Member State of the European Union or another Contracting State of the Treaty on the European Economic Area.

The purpose of the Google Analytics component is to analyse the flow of visitors to our website (contract data processing). As a contract data processor, Google uses the data and information obtained, among other things, to evaluate the use of our website, to compile online reports for us that highlight the activities on our web pages, and to provide us with further services connected with the use of our website.

Google Analytics places a cookie on your IT system. We already explained above what cookies are. Placement of the cookie enables Google to analyse the use of our website. Every time you access one of the individual pages of this website into which a Google Analytics component has been integrated, the Internet web browser on your IT system is automatically induced by the respective Google Analytics component to transmit data to Google for the purpose of online analysis. Within the context of this technical procedure, Google becomes aware of personal data such as your IP address which Google uses, for example, to comprehend the origin of the visitors and clicks.

Personal information, e.g. the time of access, the location from which this access originated and the frequency of the visits to our website, is saved using the cookie. During every visit to our web pages this personal data, including the IP address of the utilised Internet connection, is transmitted to Google in the USA. These personal data are saved by Google in the USA. In certain circumstances, Google passes these personal data, which were collected via the specific technical procedure, on to third parties.

As already described above in § 10, you may permanently oppose the placement of cookies.

You can also oppose any recording of the data generated by Google Analytics relating to the use of this website, and refuse and prevent the processing of these data by Google, for this purpose, the data subject must download and install a browser add-on under the link tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via JavaScript that no data or information on the visits to web pages may be transmitted to Google Analytics. Google regards installation of the browser add-on as opposition. If your operating system is deleted, formatted or re-installed at a later date, the browser add-on must be re-installed in order to disable Google Analytics. If the browser add-on is uninstalled or disabled by you or another person within your sphere of influence, the browser add-on can be reinstalled or reactivated.

You can prevent recording by Google Analytics by clicking on the following link. An opt-out cookie is placed that prevents future recording of your data when you visit this website.
Deactivate Google Analytics

You have to make this setting for each browser and device individually. If your browser's cookies are deleted, the setting will be lost and you will need to click the link again.

Further information and the valid data protection provisions of Google can be accessed at www.google.de/intl/en/policies/privacy and www.google.com/analytics/terms/us.html. Google Analytics is explained in more detail under this link: www.google.com/intl/en_uk/analytics/.

  

14. Use of the website prospecting and personalisation tool Lea

The analysis tool of LEA UG (limited liability), Marienstrasse 23, D-70178 Stuttgart, is used on this website to collect and store pseudonymous and anonymous data for marketing, market research and optimisation purposes.

Pseudonymous profiles relating to the use of this website are created based on these data. A so-called tracking script is used in this respect to collect company-related data. The data collected with these technologies are not used to personally identify the visitors to this website and are not combined with personal data concerning the bearer of the pseudonym.

Data collection and storage may be revoked at any time with effect for the future by removing the following check box to prevent recording by the analysis tool on the website in future. An opt-out cookie for this website is stored on your device for this purpose. If you erase your cookies in this browser, you must click this link again.

Link: https://app.lea-software.com/opt-out

15. Use of Google Adwords

HERMA has integrated Google Adwords on this website. Google AdWords is a Internet advertising service which enables advertisers to place both advertisements in the search engine results of Google and the Google advertising network.

The company operating the Google AdWords services is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of Google AdWords is to publicise our website through placement of advertising relating to interested parties on the websites of third companies and in the search engine results of the Google search engine.

If you are directed to our website via a Google advertisement, a so-called conversion cookie is stored on your device by Google. It was already explained beforehand what cookies are. A conversion cookie becomes invalid after thirty days and is not used to identify you. If the cookie has not yet expired, it can be used to detect whether specific subpages, e.g. the shopping cart in an online shop, were called up on our website. The conversion cookie enables both our company and Google to ascertain whether you were directed to our website via an advertisement, generated a sale, i.e. completed or stopped a goods purchase, or completed another conversion, e.g. sending a contact form.

The data and information collected through the use of the conversion cookie are used by Google to produce visit statistics for our website. These visit statistics are used in turn by our company to determine the total number of users who were directed to our website via advertisements, i.e. to calculate the success or failure of the particular advertisement and optimise our advertisements for the future. Neither HERMA nor other advertising customers of Google-AdWords receive information from Google through which you can be identified.

The conversion cookie is used to store personal information, e.g. the websites you have visited. Every time you visit our website, personal data including the IP address of the Internet connection used by you are transmitted to Google in the United States of America. These personal data are stored by Google in the United States of America. Google may pass on these personal data collected via the technical process to third parties.

As described in § 10, you can permanently object to cookies being set by our website.

You can also object to Google's use of advertising relating to interested parties. For this purpose, you must call it up from the link www.google.com/settings/ads from every one of the Internet browsers which you use and make the required settings there.

Further information and the valid data protection regulations of Google are available online at: www.google.de/intl/en/policies/privacy/.

  

16. Use of Bing Ads

Data are collected and stored on this website with the aid of Bing Ads technologies. These data are then used to create pseudonymous utilization profiles.

The company operating the services of Bing Ads is the Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

This service enables users' activities on the website to be tracked if these users have accessed the website via Bing Ads advertisements. If you access our website via such an advertisement, a cookie will be set on your computer. A Bing UET tag (Universal Event Tracking Tag) is integrated on the website. This is a code through which some non-personal data on the use of the website are stored in connection with the cookie. These data include, for example, the duration of the visit to the website, what areas of the website were called up and the advertisement through which the users accessed the website. Information about your identity is not recorded.

The recorded information is transmitted to Microsoft servers in the United States of America where it is normally stored for a maximum period of 180 days.

As already described above in § 10, you can permanently object to cookies being ser by our website.

Microsoft can also use so-called cross-device tracking to monitor your utilization behavior across several of your electronic devices and is therefore able to incorporate personalized advertising on or in Microsoft-websites and apps. You can deactivate this behavior at choice.microsoft.com/en-us/opt-out.

You can find further information about the analysis services of Bing on the website of Bing Ads (help.bingads.microsoft.com). You can find further information about data protection at Microsoft and Bing in the Data Protection Regulations of Microsoft (privacy.microsoft.com/en-us/privacystatement).

  

17. Legal or contractual regulations relating to the supply of personal data

We hereby wish to inform you that the supply of personal data is legally prescribed at times or may also arise due to contractual regulations. Failure to supply personal data could result in a contract not being concluded with you or HERMA being unable to furnish the requested service such as delivery of the newsletter or the provision of product information.

  

18. Storage period, erasure and blocking of personal data

HERMA will only process and store your personal data for as long as is necessary to attain the storage purpose or if provision was made for this in a law or regulation to which each HERMA controller is subject – e.g. statutory retention periods.

If the storage purpose ceases to apply or a legally prescribed storage period expires, the personal data will be routinely blocked or erased according to legal regulations.

  

19. Rights of website visitors

If you want to make use of the rights described below, you may also contact our Data Protection Officers or another employee of HERMA for this purpose at any time.

a) Right to receive information
You are entitled to receive information from HERMA free of charge at any time about your stored personal information and a copy of this information. The legislature allows you to receive the following information:

  • Reasons for processing personal data
  • Categories of personal data which are processed
  • The recipients or categories of recipients to whom personal data were or will still be disclosed, especially recipients in third countries or in international organisations
  • If possible, the planned period for which the personal data will be stored or, if this is not possible, the criteria for determining this period
  • The existence of a right to rectification or erasure of your personal data or to restriction of processing by the controller or a right to object to this processing
  • The existence of a right to complain to a supervisory authority
  • If the personal data of a data subject are not recorded: All the available information regarding the origin of the data
  • The existence of automated decision-making, including profiling according to Article 22 (1) and (4) of the GDPR and — at least in these cases — meaningful information about the involved logic, the extent and the intended effects of this processing for the data subject

You are also entitled to receive information on whether personal data were transmitted to a third country or an international organisation.

b) Right to rectification
You have the right to request immediate rectification of inaccurate data concerning you. Taking into account the purposes of processing, you also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

c) Right to erasure (right to be forgotten)
You have the right to request HERMA to immediately erase personal data concerning you if one of the following reasons applies and processing is not necessary:

  • The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
  • You withdraw your consent on which the processing was based according to Article 6 (1) a of the GDPR or Article 9 (2) a of the GDPR, and where there are no other legal grounds for the processing.
  • You object to the processing pursuant to Article 21 (1) of the GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21 (2) of the GDPR.
  • The personal data have been illegally processed.
  • The personal data have to be erased in order to comply with a legal obligation under European Union law or member state law to which the controller is subject.
  • The personal data were collected in relation to services offered by HERMA according to Article 8 (1) of the GDPR.

If we have made your personal data public, we will implement suitable measures after taking account of available technology and the cost of implementation in order to inform other controllers who process your published person data that you requested the erasure of all links to your personal data or copies or replications of these personal data if the processing is not required.

d) Right to restriction of processing
You have the right to request HERMA to restrict processing if one of the following conditions applies:

  • The accuracy of the personal data is contested by you, i.e. for a period which enables HERMA to verify the accuracy of the personal data.
  • The processing is illegal, you oppose the erasure of the personal data and request the restriction of their use instead.
  • HERMA no longer needs the personal data for the purposes of processing, but you require them for the enforcement, exercise or defence of legal claims.
  • You objected to processing pursuant to Article 21 (1) of the GDPR and it has not been determined whether the legitimate grounds of HERMA override your interests.

e) Right to data portability
You have the right to receive your personal data, which you provided to HERMA, in a structured, commonly used and machine-readable format. You are also entitled to transmit these data to another controller without interference by HERMA if processing is based on consent according to Article 6 (1) a of the GDPR or Article 9 (2) a of the GDPR, or on a contract pursuant to Article 6 (1) b of the GDPR and processing is carried out using automated methods, unless processing is required for a task which is in the public interest or in the exercise of public authority vested in HERMA.

In exercising your right to data portability pursuant to Article 20 (1) of the GDPR, you are entitled to have the personal data transmitted directly from one controller to another where this is technically feasible and if the rights and freedoms of other persons are not hereby adversely affected.

f) Right to object
You have the right to object, for reasons relating to your particular situation, at any time to processing of your personal data which is based on Article 6 (1) e or f of the GDPR. This also include profiling based on these provisions.

HERMA will stop processing your personal data in the event of objection, unless we demonstrate compelling legitimate grounds for processing which override your interests, rights and freedoms, or processing is used to enforce, exercise or defend legal claims.

If HERMA processes personal data for direct marketing purposes, you have the right to object at any time to processing of personal data for the purpose of this marketing. This also applies to profiling if it relates to this direct marketing. If you inform HERMA that you object to processing for direct marketing purposes, HERMA will no longer process personal data for these purposes.

You also have the right to object, for reasons relating to your particular situation, to processing of your personal data which is carried out by HERMA for scientific, historical research or statistical purposes according to Article 89 (1) of the GDPR, unless this processing is necessary to perform a task for reasons of public interest.

g) Right to revoke consent to data processing
You have the right to revoke at any time consent to processing of your personal data.

h) Right to complain to supervisory authorities
If you have a problem relating to data protection, you may make use of your right to complain to the responsible national supervisory authorities.

  

20. Existence of automated decision-making

We have waived automated decision-making, unless we have expressly made reference thereto.

  

Die Erstellung der Datenschutzerklärung wurde unterstützt durch die DGD Deutsche Gesellschaft für Datenschutz GmbH, die als externer Datenschutzbeauftragter tätig ist, in Kooperation mit der RC GmbH, die gebrauchte Computer wiederverwertet und der Kanzlei WILDE BEUGER SOLMECKE | Rechtsanwälte erstellt.