Privacy policy for website visitors / webshop
The
protection of your personal data is important to us.
This privacy policy informs you about how we process your data in connection
with the use of our online shop.
Our offer is aimed exclusively at business customers (B2B) in the EU.
§ 1 Information on the collection of personal data
(1) In the following, we provide information about the processing of personal data when using our website. Personal data is all data that can be related to you personally, e.g. name, address, email addresses, user behaviour. We hereby wish to inform you about our processing procedures and at the same time fulfil our legal obligations, in particular those arising from the EU General Data Protection Regulation (GDPR).
(2) The controller pursuant to Art. 4 (7) GDPR is HIOKI EUROPE GmbH, Helfmann-Park 2, 65760 Eschborn, Germany, e-mail hioki[at]hioki[dot]eu (see our imprint). You can contact our data protection officer at datenschutz[at]aklsite[dot]de or at our postal address with the addition "the data protection officer".
(3) When you contact us by e-mail or via a contact form, the data you provide (your e-mail address, your name and telephone number if applicable) will be stored by us in order to answer your questions. If the enquiry is assigned to a contract, we delete the data arising in this context after the contract period, otherwise after the storage is no longer required, or restrict the processing if there are statutory retention obligations.
(4) If we use contracted service providers for individual functions of our offer or wish to use your data for advertising purposes, we will always carefully select and monitor these service providers and inform you in detail below about the respective processes. In doing so, we also specify the defined criteria for the storage period.
§ 2 Processing of personal data when visiting our website
When using the website for information purposes, i.e. simply viewing it without registering and without providing us with any other information, we process the personal data that your browser transmits to our server. The data described below is technically necessary for us to display our website to you and to ensure stability and security and must therefore be processed by us.
The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR:
- IP address
- Date and time of the enquiry
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (page visited)
- Access status/HTTP status code
- Amount of data transferred in each case
- Previously visited page
- Browser
- Operating system
- Language and version of the browser software.
§ 3 Orders via our webshop (only for business customers in the EU)
Orders in our webshop are placed via selfregistration with a VAT ID check.
We use an online shop from shopware AG to process your order.
We have concluded an order processing contract with shopware AG.
Further information on data protection and your rights regarding the use of the ordering system can be found at:
shopware AG: https://www.shopware.com/de/datenschutz/website/
1. Scope of the processing of personal data
Registration in the webshop
For the purpose of order processing, it is necessary to store personal data. Without this data, order processing is not possible.
Your personal data is entered into an input mask and transmitted to us and stored. If you place an order via our webshop, we first collect the following data when you register in the shop:
- Company name
- Company address
- Name of the contact person
- E-mail address of the contact person
- Telephone number (optional)
- Value added tax identification number (VAT ID).
Value added tax validation
We check the VAT ID you have provided manually in a two-stage process: via Vies on-the-Web - European Commission (europa.eu)
we check the validity of the VAT ID, via Google the match of VAT ID and registered company data.
Free text field for items in the shopping basket (visurel.com)
Our online shop offers the option of using free text fields for individual information in the shopping basket. The data you enter will be stored for further processing and fulfilment of your order.
Blog
Our online shop also offers a blog via shop-studio.io. If you register for the blog area or leave comments, we collect data such as
- Name
- E-Mail-adress
- Comments.
2. Purpose of data processing
This data is collected,
- to ensure authorisation to use our B2B offering;
- in order to process, fulfil and process your order;
- for correspondence with you;
- to manage the blog: Grant access and moderate comments;
- for invoicing;
- for the settlement of any liability claims and the assertion of any claims against you;
- to ensure the technical administration of our web shop;
- to manage our customer data.
3. Legal basis for data processing
The data processing takes place in response to your order and/or registration and is required in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR (fulfilment of contract) for the purposes mentioned under 2. for the appropriate processing of your order and for the mutual fulfilment of obligations arising from the purchase contract.
The legal basis for the administration of the blog is Art. 6 para. 1 lit. f GDPR (legitimate interest to enable the exchange in the blogs).
The legal basis for the presentation of your company to the public is Art. 6 para. 1 lit. a GDPR (consent).
4. Forwarding of data
Your personal data will only be passed on by us to third parties to the service partners involved in the processing of the contract.
These service providers (listed below) are contractually obliged to treat your data confidentially and to use it only within the scope of the service.
Our service partners are
- shopware AG as the host of our web shop,
- digitvision creative websolutions
- Internet & Advertising Agency Valkanis IWV
- BlueWolf Produktion for B2B company registration (shopware plugin)
- visurel for the free text fields (visurel.com)
- shop-studio.io for the blog
- ACRIS, the company responsible for surcharges and discounts,
- the payment service provider Stripe and
- the logistics companies DSV Air & Sea Germany GmbH and UPS commissioned with the delivery.
In the case of shipments to a specific person, we will pass on the name of the person to the logistics company.
However, in cases where your personal data is passed on to third parties, the scope of the data transmitted is limited to the minimum necessary.
We have concluded an order processing contract with shopware AG. The processors are contractually obliged to ensure that their subcontractors comply with the same data protection and security standards as set out in the main contract between the controller and the contractors.
The commissioned logistics companies DSV, UPS and the payment service provider Stripe are independently responsible.
Further data protection information can be found in the data protection declarations of our service providers or their partner companies:
- shopware AG: https://www.shopware.com/de/datenschutz/website/
- digitvision https://www.digitvision.de/datenschutz
- IWV https://iwv-online.com/datenschutz
- BlueWolf-Produktion: https://www.bluewolf-produktion.de/datenschutzerklaerung.html
- visurel https://visurel.com/privacy-policy
- shop-studio.io https://www.shop-studio.io/en/privacy-policy
- Logistikdienstleister DSV https://www.dsv.com/de-de/ueber-dsv/datenschutzerklaerung
- Logistikdienstleister UPS https://www.ups.com/de/de/support/shipping-support/legal-terms-conditions/privacy-notice.page
- Stripe https://stripe.com/de/privacy
Payment processing and payment methods
We work together with the external payment provider Stripe to process payments.
The following data is transmitted to Stripe as part of the payment process:
- Name of the company
- Invoice information
- Payment transaction data.
Stripe processes this data on its own responsibility. Further information on data processing by Stripe can be found in Stripe's privacy policy (https://stripe.com/de/privacy).
Your data will be stored until order processing has been completed. This also includes the period required for the processing of refunds, receivables management and fraud prevention. In accordance with § 147 AO / § 257 HGB, a statutory retention period of 10 years applies to us.
Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
5. Data transfer to third countries
Your data will only be transferred to third countries if this is necessary for the fulfilment of the contract or if you have expressly consented to this.
Stripe may process data outside the EU, but ensures that appropriate data protection standards are complied with (EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data).
§ 4 Your rights / right to lodge a complaint with the supervisory authority
(1) You have the following rights vis-à-vis the controller with regard to your personal data:
- Information about the personal data processed by us (Art. 15 GDPR),
- Correction of incorrect data (Art. 16 GDPR)
- Deletion of your data (Art. 17 GDPR), provided there are no statutory retention obligations to the contrary,
- Objection to the processing (Art. 21 GDPR),
- Data portability (Art. 20 GDPR).
You can contact us at any time to exercise your rights.
(2) If you believe that the processing of your data violates the GDPR, you have the right to complain to a data protection supervisory authority about the processing of your personal data by us.
§ 5 Changes to the privacy policy
We reserve the right to amend this privacy policy if necessary in order to adapt it to changes in the legal framework or new services.
The latest version is available on our website.
§ 6 Contact
If you have any questions or concerns about this privacy policy or the processing of your personal data, please contact us using the contact details provided under § 1 (2).