Privacy policy




1. Data protection at a glance


General information

The following information provides a basic summary of what happens to your personal data when you visit this website. Personal data is any data relating to an identifiable individual. Please see our privacy policy set out below for more information on the subject of data protection.


Data collection on this website


Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. Please see the section entitled “Information about the data controller” in this privacy policy for their contact details.

How do we collect your data?

On the one hand, data is acquired by you giving it to us. This can be data that you enter in a contact form, for example.

Other data is collected by our IT systems automatically or after you give us your consent when you visit the website. This is mainly technical data (such as your internet browser, operating system or the time you viewed the site). This data is collected automatically as soon as you access the website.


What do we use your data for?

Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyse your user behaviour.


What rights do you have with respect to your data?

You have the right to be informed about the origin, recipient and purpose of your personal data that has been stored at any time and free of charge. You also have the right to request the rectification or erasure of such data. If you have given your consent to data processing, you may withdraw such consent at any time with effect in the future. You also have the right under certain circumstances to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time with regard to these and other questions on the subject of data protection.

Analysis tools and third party provider tools


When you visit this website, your browsing behaviour may be statistically analysed. This is done primarily using so-called analysis programs.

Please see the following privacy policy for more detailed information about such analysis programs.



2. Hosting and Content Delivery Networks (CDN)

External hosting


This website is hosted by an external service provider (host). The personal data which is collected on this website is stored on the host’s servers. This may be primarily IP addresses, contact requests, metadata and communication data, contract data, contact data, names, website visits and other data which is generated by a website.

The host is engaged for the purpose of performing a contract with respect to our potential and existing customers (Art. 6 (1) b of the GDPR) and in the interest of the safe, fast and efficient provision of our online services by a professional provider (Art. 6 (1) f of the GDPR).

Our host will only process your data to the extent necessary to fulfil its obligations to perform and will follow our instructions in relation to such data.
We use the following host:

basecom GmbH & Co. KG

Hannoversche Str. 6-8

49084 Osnabrück, Germany


Conclusion of a data processing agreement

In order to ensure data protection compliant processing, we have concluded a data processing agreement with our host.



3. General information and required information

Data protection


The operators of this site take the protection of your personal data very seriously. We treat your personal data as confidential and handle it in accordance with statutory data protection provisions and this privacy policy.

Various personal data is collected when you use this website. Personal data is data relating to an identifiable individual. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens.

We wish to point out that data transmission via the internet (for example, in email communications) may have security vulnerabilities. Complete protection of data from third party access is not possible.


Information about the data controller


The data controller for data processing on this website is:

KADECO Sonnenschutzsysteme GmbH

Hindenburgring 14-16

32339 Espelkamp


Telephone: +49 5772 9104 0

Email: info@kadeco.de


The data controller is the natural or legal person which, alone or jointly with others, determines the purposes and means of processing of personal data (for example, names, email addresses, etc.).


Duration of storage


Unless stated otherwise in this privacy policy, we will keep your personal data until the purpose of data processing no longer applies. If you assert a legitimate request for erasure or withdraw your consent to data processing, your data will be erased unless we have other legally admissible reasons for storing your personal data (for example, retention periods under tax or commercial law); in the latter case such data will be erased when these reasons cease to apply.


Statutory data protection officer


We have appointed a data protection officer for our company.


ER Secure GmbH

In der Knackenau 4

82031 Grünwald, Germany


Telephone: +49 5772 9104 0

E-Mail: datenschutz@kadeco.de


Information on data transfer to the USA and other third countries


Among others, tools from companies whose registered offices are in the USA or other third countries that are not safe in terms of data protection legislation are integrated into our website. When these tools are active, your personal data may be transferred to these third countries and processed there. We wish to point out that a level of data protection comparable to that of the EU cannot be guaranteed in such countries. For example, US companies are obliged to hand over personal data to security authorities without you as the data subject being able to take legal proceedings against it. It can therefore not be ruled out that US authorities (for example, intelligence services) might process, analyse and permanently store your data, which is stored on US servers, for surveillance purposes. We have no influence over these processing activities.


Withdrawal of your consent to data processing


Many data processing operations are only possible with your explicit consent. You may withdraw consent that you have already given at any time. The legitimacy of the data processing carried out before the withdrawal will remain unaffected by the withdrawal.


Right to object to data collection in certain circumstances and to object to direct marketing (Art. 21 of the GDPR)


IF THE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 (1) E OR F OF THE GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME ON GROUNDS RELATING TO YOUR PERSONAL SITUATION; THIS ALSO APPLIES TO PROFILING OF ANY DATA BASED ON THESE PROVISIONS. PLEASE SEE THIS PRIVACY POLICY FOR THE RELEVANT LEGAL BASIS FOR DATA PROCESSING. IF YOU LODGE AN OBJECTION, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN PROVE WE HAVE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING IS FOR THE PURPOSE OF ASSERTING, EXERCISING OR DEFENDING LEGAL CLAIMS (OBJECTION IN ACCORDANCE WITH ART. 21 (1) OF THE GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF THE PERSONAL DATA CONCERNED WHICH RELATES TO YOU FOR THE PURPOSE OF SUCH MARKETING AT ANY TIME; THIS ALSO APPLIES TO PROFILING IF IT IS CONNECTED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION IN ACCORDANCE WITH ART. 21 (2) OF THE GDPR).


Right to lodge a complaint with the competent supervisory authority


In cases of breaches of the GDPR, the data subject has a right to lodge a complaint with a supervisory authority, in particular in the member state where they have their normal place of residence, place of work or the place of the suspected breach. The right to object remains unaffected by other legal or administrative remedies.


Right to data portability


You have the right to have the data, which we automatically process on the basis of your consent or while fulfilling a contract, sent to you or a third party in a commonly used and machine-readable format. If you request the direct transfer of the data to another controller, this will only be done if it is technically feasible.


SSL and TLS encryption


This site uses SSL and TLS encryption for security reasons and to protect the transfer of confidential information such as purchase orders or enquiries which you send to us as the website operator. You can recognise an encrypted connection when the address line of the browser changes from “http://” to “https://” and by the padlock symbol in your browser line.

When the SSL or TLS encryption is active, the data that you transmit to us cannot be read by third parties as well.


Information, erasure and rectification


You have the right within the scope of the applicable statutory provisions to be informed about your stored personal data, its origin and recipient and the purpose of the data processing at any time free of charge and, if applicable, a right to rectification or erasure of such data. You can contact us at any time with regard to these and other questions on the subject of personal data.


Right to restriction of processing


You have the right to request the restriction of the processing of your personal data. You can contact us at any time in this regard. The right to restriction of processing exists in the following circumstances:


  • If you dispute the accuracy of your personal data that we have stored, we normally need time to verify it. You have the right to request the restriction of the processing of your personal data while we verify it.
  • If the processing of your personal data happens/happened unlawfully, you may request the restriction of the data processing instead of its erasure.
  • If we no longer need your personal data but you still need it to exercise, defend or establish legal claims, you have the right to request the restriction of the processing of your personal data instead of its erasure.

  • If you have lodged an objection in accordance with Art. 21 (1) of the GDPR, your interests and ours must be weighed up. You have the right to restriction of the processing of your personal data until it has been established whose interests are overriding.

  • If you have restricted the processing of your personal data, such data may only be processed - apart from its storage - with your consent or to establish, exercise or defend legal claims or to protect rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.



4. Data collection on this website


Cookies


Our web pages use so-called “Cookies”. Cookies are small text files and do not cause any damage to your terminal. They are either stored temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your terminal. Session cookies are automatically deleted after the end of your visit. Permanent cookies remain stored on your terminal until you delete them yourself or your web browser automatically deletes them.

Some cookies from third party companies may also be stored on your terminal when you access our site (third party cookies). These allow us or you to use certain services from the third party (for example, cookies to process payment services).

Cookies have various functions. Many cookies are technically necessary since certain website functions do not work without them (for example, shopping basket functions or showing videos). The purpose of other cookies is to analyse your user behaviour or display marketing.

Cookies which are required to perform the electronic communication operation (necessary cookies) or for the provision of certain functions that you have requested (functional cookies, for example for the shopping basket function) or to optimise the website (for example, cookies for measuring the web audience) are stored on the basis of Art. 6 (1) f of the GDPR, unless another legal ground is stated. The website operator has a legitimate interest in storing cookies for the technical error-free and optimised provision of their services. If consent has been requested for the storage of cookies, the cookies concerned will be stored exclusively on the basis of such consent (Art. 6 (1) a of the GDPR); the consent may be withdrawn at any time.

You can adjust your browser settings so that you are informed whenever cookies are placed and only allow cookies on an individual basis, rule out the acceptance of cookies for certain cases or generally and activate the automatic deletion of cookies when you close the browser. If you deactivate cookies, the functionality of this website may be restricted.

If cookies are placed by third companies or for analysis purposes, we inform you separately of such within the scope of this privacy policy and if applicable, request your consent.


Server log files


The website provider automatically collects and stores information in so-called server log files, which your browser automatically sends to us. This is:

  •     Browser type and version
  •     Operating system used
  •     Referrer URL
  •     Host name of the computer accessing the site
  •     Time of server request
  •     IP address


This data is not merged with other data sources.

This data is collected on the basis of Art. 6 (1) f of the GDPR. The website operator has a legitimate interest in the technically error-free display and optimisation of its website – the server log files must be collected in order to do so.


Contact form


If you send us an enquiry using the contact form, your details from the form including the contact details you enter there are stored by us for the purpose of processing the enquiry and in case of subsequent questions. We will not pass this data on without your consent.

The data you enter on the contact form will remain with us until you request its erasure, withdraw your consent to its storage or the purpose of the data processing no longer applies (for example, after your enquiry has been processed fully). Mandatory statutory provisions - in particular retention periods - remain unaffected.

The data you enter on the contact form will remain with us until you request its erasure, withdraw your consent to its storage or the purpose of the data processing no longer applies (for example, after your enquiry has been processed fully). Mandatory statutory provisions - in particular retention periods - remain unaffected.


Enquiries by email, telephone or fax


If you contact us by email, telephone or fax, your enquiry, including all of the personal data that can be taken from it (name, enquiry), will be stored and processed by us for the purpose of processing your query. We will not pass this data on without your consent.

This data is processed on the basis of Art. 6 (1) b of the GDPR provided your enquiry is connected to the fulfilment of a contract or to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interests in the effective processing of enquiries addressed to us (Art. 6 (1) f of the GDPR) or on your consent (Art. 6 (1) a of the GDPR) provided this has been requested.

The data you send to us in contact enquiries will remain with us until you request its erasure, withdraw your consent to its storage or the purpose of the data processing no longer applies (for example, after your query has been processed fully). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.



5. Analysis tools and marketing


Google Tag Manager


We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool, which helps us to integrate tracking or statistics tools and other technologies on our website. Google Tag Manager itself does not create any user profiles, store any cookies or carry out any analysis of its own. It is just used to administer and display the tools integrated by it. However, Google Tag Manager does collect your IP address which may also be transferred to Google’s parent company in the United States.

The use of Google Tag Manager is based on Art. 6 (1) f of the GDPR. The website operator has a legitimate interest in fast and straightforward integration and administration of various tools on its website. Provided consent has been requested accordingly, the processing is carried out exclusively on the basis of Art. 6 (1) a of the GDPR; the consent may be withdrawn at any time.


Google Analytics


This website uses functions from the web analysis service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics allows the website operator to analyse the behaviour of its website visitors. In the process, the website provider receives various user data such as pages accessed, how long was spent there, operating systems used and the origin of the user. This data is collated by Google in a profile which is assigned to the respective user or their terminal.

Google Analytics uses technology, which allows the recognition of the user for the purpose of analysing user behaviour (for example, cookies or device fingerprinting). The information collected by Google about the use of this website is normally transmitted to a Google server in the USA and stored there.

This analytics tool is used on the basis of Art. 6 (1) f of the GDPR. The website operator has a legitimate interest in the analysis of user behaviour in order to optimise its website and marketing. Provided consent has been requested accordingly (for example, consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 (1) a of the GDPR; the consent may be withdrawn at any time.

Data transmission to the USA is based on the standard contract clauses of the EU Commission. You can find the details here: https://privacy.google.com/businesses/controllerterms/mccs/.


IP anonymisation

We have activated the IP anonymisation function on this website. This means that your IP address is shortened by Google within the Member States of the European Union or in other contracting parties to the Agreement on the European Economic Area before transmission to the USA. The full IP address is only transferred to a Google server in the USA and shortened there in exceptional cases. On the instructions of the operator of this website, Google will use this information to analyse your usage of the website, compile reports about website activities and render other services associated with the usage of the website and internet for the website operator. The IP address transmitted by your browser with respect to Google Analytics will not be merged with other data by Google.


Browser Plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available under this link: https://tools.google.com/dlpage/gaoptout?hl=de.

You can find more information on the handling of user data by Google Analytics in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.


Order processing

We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.


Demographic characteristics at Google Analytics

This website uses the “demographics” function of Google Analytics in order to be able to display appropriate advertisements within the Google advertising network to website visitors. This means that reports may be compiled which contain statements regarding the age, gender and interests of website visitors. This data comes from interest-based advertising by Google and from visitor data from third party providers. This data cannot be assigned to any particular person. You can deactivate this function at any time via the advertising settings in your Google account or generally disallow the collection of your data by Google Analytics as shown under the heading “Objection to data collection”.


Google Analytics Ecommerce Tracking

This website uses the “Ecommerce Tracking” function from Google Analytics. Ecommerce tracking allows the website operator to analyse the purchase activity of website visitors to improve their online marketing campaigns. Information such as purchase order transactions, average order value, despatch costs and the time from viewing the product to purchasing it, is collected in the process. This data may be combined by Google under a transaction ID which is assigned to the respective user or their device.


Duration of storage

Data stored by Google at a user and event level that is linked to cookies, user recognition (for example, user ID) or marketing IDs (for example, DoubleClick cookies, Android marketing ID) is anonymised or erased after 14 months. You can find the details by following this link: https://support.google.com/analytics/answer/7667196?hl=de


Google Conversion Tracking


This website uses Google Conversion Tracking. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

With the aid of Google Conversion Tracking we can see if the user has taken certain actions. For example, we can analyse which buttons on our website are clicked and how often and which products are viewed or purchased especially often. This information is used to compile conversion statistics. We find out the total number of users who have clicked on our advertisements and which actions they have taken. We do not receive any information which could be used to personally identify the users. Google itself uses cookies or comparable recognition technologies for identification.

The use of Google conversion tracking is based on Art. 6 (1) f of the GDPR. The website operator has a legitimate interest in the analysis of user behaviour in order to optimise its website and marketing. Provided consent has been requested accordingly (for example, consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 (1) a of the GDPR; the consent may be withdrawn at any time.

You can find more information on Google Conversion Tracking in Google’s privacy policy: https://policies.google.com/privacy?hl=de.



6. Plugins and Tools


YouTube with enhanced privacy


This website integrates YouTube videos. The operator of the site is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

We use YouTube with enhanced privacy mode. According to YouTube, this mode means that YouTube does not store any information about users of this website before they view the video. However, the forwarding of data to YouTube partners is not necessarily ruled out by the enhanced privacy mode. For example, YouTube establishes a link to the Google DoubleClick network - irrespective of whether you view a video.

As soon as you start a YouTube video on this website, a connection is established to the YouTube servers. During this process, the YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you are enabling YouTube to assign your browsing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.

Furthermore, after the video has started, YouTube can store various cookies on your terminal  or use comparable recognition technologies (e.g. device fingerprinting). YouTube can obtain information about visitors to this website in this way. This information is used, among other things, to collect video statistics, improve user-friendliness and prevent attempted fraud.

It might be the case that other data processing actions are triggered by starting a YouTube video, which we have no influence over.

The use of YouTube is in the interest of an appealing display of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1) f of the GDPR. Provided consent has been requested accordingly, the processing is carried out exclusively on the basis of Art. 6 (1) a of the GDPR; the consent may be withdrawn at any time.

You can find more information about YouTube privacy in their privacy policy at: https://policies.google.com/privacy?hl=de.



7. eCommerce and payment service providers


Processing of data (customer and contract data)


We only collect, process and use personal data if it is necessary to establish, organise the contents of or modify the legal relationship (contract data). This is carried out on the basis of Art. 6 (1) b of the GDPR, which permits the processing of data to fulfil a contract or pre-contractual measures. We only collect, process and use personal data relating to the use of this website (user data) if it is necessary to do so, in order to enable the user to make use of the service or to bill them.

The collected customer data is erased after the order has been fulfilled or the business relationship has ended. Statutory retention periods remain unaffected.



8. Audio and video conferences


Data processing


We use online conference tools among other means to communicate with our customers. The specific tools we use are listed below. If you communicate with us via video or audio conference over the internet, your personal data is collected and processed by us and the provider of the conference tool concerned.

In the process, the conference tools collect all the data that you provide/use in order to use the tool (email address and/or your telephone number). Furthermore, the conference tools process the duration of the conference, the start and end (time) of participation in the conference, the number of participants and other “context information” associated with the communication operation (metadata).

Furthermore, the provider of the tool processes all of the technical data which is necessary to handle the online communication. This comprises in particular IP addresses, MAC addresses, terminal IDs, terminal type, operation system type and version, client version, camera type, microphone or loudspeaker and the type of connection.

If content is exchanged, uploaded or provided in any other way within the tool, this is likewise stored on the tool provider’s servers. Such content includes, in particular, cloud records, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information which is shared while the service is being used.

Please note that we do not have full influence on the data processing operations of the tools used. Our options essentially depend on the corporate policy of the provider concerned. Please see the privacy policies of the tools concerned for more information on data processing by the conference tools, which we have listed below.


Purpose and legal bases


The conference tools are used to communicate with prospective or existing contractual partners or to offer certain services to our customers (Art. 6 (1) first sentence (b) of the GDPR). Furthermore, the use of the tools helps to generally simplify and accelerate communication with us or our company (legitimate interest within the meaning of Art. 6 (1) f of the GDPR). Provided consent has been requested, the use of the tools concerned is based on such consent; the consent may be withdrawn at any time with effect for the future.


Duration of storage


The data collected directly by us via the video and conference tools is erased from our systems as soon as you request us to erase it, withdraw your consent to its storage or the purpose of data storage no longer applies. Stored cookies will remain on your terminal until you delete them. Mandatory statutory retention periods remain unaffected.

We have no influence on the duration of storage of your data which is stored by the operators of the conference tool for their own purposes. Please seek information about the details directly from the operators of the conference tools.


Conference tools used


We use the following conference tools:


Zoom

We use Zoom. The provider of this service is Zoom Communications Inc., San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. Please see the privacy policy of Zoom for details on data processing: https://zoom.us/de-de/privacy.html.

Data transmission to the USA is based on the standard contract clauses of the EU Commission. You can find the details here: https://zoom.us/de-de/privacy.html.


TeamViewer

We use TeamViewer. The provider is TeamViewer Germany GmbH, Jahnstr. 30, 73037 Göppingen, Germany. Please see the privacy policy of TeamViewer for details on data processing: https://www.teamviewer.com/de/datenschutzerklaerung/.


GoToMeeting

We use GoToMeeting. The provider is LogMeIn, Inc., 320 Summer Street Boston, MA 02210, USA. Please see the privacy policy of GoToMeeting for details on data processing: https://www.logmeininc.com/de/legal/privacy.

Data transmission to the USA is based on the standard contract clauses of the EU Commission. You can find the details here: https://logmeincdn.azureedge.net/legal/lmi-customer-dpa-2020v1-de.pdf.


Microsoft Teams

We use Microsoft Teams. The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Please see the privacy policy of Microsoft Teams for details on data processing: https://privacy.microsoft.com/de-de/privacystatement.


Conclusion of a data processing agreement

We have concluded a data processing agreement with the provider of Microsoft Teams and fully implement the strict requirements of the German data protection authorities when using Microsoft Teams.


Google Hangouts

We use Google Hangouts. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Please see the privacy policy of Google Hangouts for details on data processing: https://policies.google.com/privacy?hl=de.