Welcome to our website! The protection and security of your personal information when using our website is very important to us. We would therefore like to take this opportunity to inform you which of your personal data we collect when you visit our website and for what purposes it is used. Personal data is individual information about the personal or factual circumstances of a specific or identifiable natural person (data subject), e.g. name, address, email addresses, user behaviour. This is therefore data with which we can identify you. In addition, you will occasionally also find information on data processing processes outside this website (e.g. video conferences or newsletters).
Responsible for data processing
Person responsible
for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)
WestWood® Kunststofftechnik GmbH
An der Wandlung 20
32469 Petershagen
Phone: +49 5702 8392-0
E-mail: info@westwood.de
Data Protection Officer
exkulpa gmbh
Waldfeuchter Str. 266
52525 Heinsberg
Phone: +49 2452 / 99 33 11
E-Mail: datenschutz@westwood.de
General information
In addition to the data that you actively communicate to us on this site (e.g. via our contact form), we collect some technical data. This so-called metadata is automatically transmitted from your computer to our servers as soon as you enter our website (e.g. browser, operating system or time stamp). We use this data to ensure that our website is displayed correctly. We may also collect data via integrated third-party providers (e.g. for external media such as map services or analysis tools). We will inform you about the individual purposes and legal bases in the course of this privacy policy.
Storage duration
If no separate storage period is specified in this privacy policy, we will store your personal data for as long as the purpose of the data processing is given. If you contact us with a justified deletion request or revoke your consent, we will delete your data. Statutory retention obligations remain unaffected.
Legal basis for data processing
If you have consented to data processing, your personal data will be processed on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2lit. a GDPR if special categories of data are processed in accordance with Art.9 para. 1 GDPR. If you expressly consent to the transfer of personal data to third countries, the data will also be processed in accordance with Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information on your end device (e.g. through device fingerprinting), data processing will also take place on the basis of Section 25 (1) TDDDG. Your consent can be revoked at any time. If your data is necessary for the fulfilment of the contract or for the implementation of pre-contractual measures, we process your data in accordance with Art. 6 para. 1 lit. b GDPR. In addition, we process your data if this is necessary to fulfil a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR. Data processing may also be carried out on the basis of our legitimate interest in accordance with Art.6 para. 1 lit. f GDPR. In the following sections of this privacy policy, you will be informed about the respective legal basis in individual cases.
Note on data transfer to third countries and US companies without DPF certification
Please note that we use tools from companies that are based in third countries or the USA that are unsafe under data protection law and that are not covered by the EU-US Data Protection Framework Agreement (DPF). When using these tools, your personal data may be transferred to these countries and processed there. Please note that a level of data protection comparable to that in the EU cannot be guaranteed in these unsafe third countries.
We would like to clarify that the USA generally offers a level of data protection comparable to that of the EU. The transfer of data to the USA is permitted if the recipient has a DPF certification or provides suitable additional guarantees. Information on data transfers to third countries, including data recipients, can be found in our privacy policy.
Automated decision making
Your personal data will not be processed for the purpose of automated decision-making.
Your rights
As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:
Further data processing procedures
General information obligations
This information is intended for customers, interested parties, suppliers and employees. Your personal data will be processed by us for the following purposes:
Categories of recipients of the personal data
Within our company, only those employees who absolutely need the data to fulfil their tasks have access to it (need-to-know principle). Individual processes and services are carried out by carefully selected service providers based within the EEA and commissioned in accordance with data protection regulations. If service providers commissioned by us are given access to personal data when carrying out your services, order processing contracts have been concluded with them in accordance with Art. 28 para. 3GDPR.
Duration of data storage
The data processed by us is stored for the duration of the existence and processing of the contractual relationship and in compliance with statutory retention periods. These are in particular commercial and tax retention obligations under the German Commercial Code (HGB) and the German Fiscal Code (AO). The regular retention and documentation periods are up to ten years. If there is no contractual relationship, we only process the data for as long as required for the specific purpose.
Cookies
Cookies are small text files that are stored by your browser on your end device in order to save certain information during your use of the website. Cookies enable us to improve various aspects of our website and make your visit more convenient.
There are different types of cookies that serve different purposes. Temporary cookies, also known as session cookies, are only stored for the duration of your use of the website and are automatically deleted when you close your browser. Persistent cookies, on the other hand, remain stored on your end device for a longer period of time and enable us to recognise you and your preferences on repeat visits to the website.
Cookies can also be divided into first-party cookies and third-party cookies. First-party cookies are set by our website, while third-party cookies are set by other websites or service providers whose content is integrated on our website, such as plugins or analysis tools.
The use of cookies serves various purposes, for example to ensure the functionality of the website, to save user settings, to compile anonymous statistics on user behaviour or to display personalised content and advertising. The legal basis for the use of cookies varies depending on the purpose of the cookies. In some cases, the setting of cookies is based on your legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to make our website functional and user-friendly. As the website operator, we have a legitimate interest in the storage of necessary cookies for the technically error-free and optimised provision of our services. If we obtain your consent for the use of cookies, the processing is carried out on the basis of Art. 6para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG. Your consent can be revoked at any time.
Data processing in detail
Below we inform you about the individual processing operations, the scope and purpose of the data processing, the legal basis, the obligation to provide your data and the respective storage period. Automated decision-making in individual cases, including profiling, does not take place.
Provision of the website
When you access and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:
Our website is not hosted by us, but by a service provider who processes the aforementioned data on our behalf in accordance with Art. 28 GDPR for the purpose of providing the website.
The hoster is used for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR).
We use the following hoster:
IOK GmbH & Co KG
Brockweg 17
33415 Verl
Contact form
Type and scope of processing
If you send us enquiries (e.g. via contact form, e-mail or telephone), we store all the data that results from this (e.g. name, e-mail address, subject of the enquiry, etc.). We need this data to process your enquiry and to be able to answer any follow-up questions. We will not pass on this data without your consent.
Purpose and legal basis
This data is processed on the basis of Art. 6 para. 1 lit. b GDPR if your enquiry is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. Otherwise, the processing is based on our legitimate interest in the effective processing of the enquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art.6 para. 1 lit. a GDPR) if you have previously given it.
Storage duration
We will retain the data you provide on the contact form until you request its deletion, revoke your consent for its storage, or the purpose for its storage no longer pertains (e.g. after fulfilling your request). Mandatory statutory provisions - in particular retention periods - remain unaffected.
Presence on social media platforms
We operate public profiles in various social networks on our website. You can find more detailed information on the social networks we use in the relevant sections of our privacy policy.
Social networks such as Facebook, Instagram, etc. can comprehensively analyse your user behaviour when you visit their websites or a website with integrated social media content (e.g. like buttons or advertising banners). Visiting our social media presences triggers numerous data protection-relevant processing operations:
If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection takes place, for example, via cookies that are stored on your end device or by recording your IP address.
With the help of the data collected in this way, the operators of the social media portals can create user profiles in which your preferences and interests are stored. This allows interest-based advertising to be displayed to you within and outside the respective social media presence. If you have an account with the respective social network, the interest-based advertising can be displayed on all devices on which you are logged in or were logged in.
Please note that we cannot track all processing operations on the social media portals. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media portals. For details, please refer to the terms of use and data protection provisions of the respective social media portals.
Legal basis for data processing
The purpose of our social media presence is to ensure the widest possible presence on the internet. This is a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. The analysis processes initiated by the social networks may be based on different legal bases, which must be specified by the operators of the social networks (e.g. consent within the meaning of Art. 6 para. 1 lit. a GDPR).
Responsible party and assertion of rights
When you visit our social media sites (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered during this visit. You can assert your rights (information, rectification, erasure, restriction of processing, data portability and complaint) both against us and against the operator of the respective social media portal (e.g. Facebook).
Despite the joint responsibility with the social media portal operators, we do not have full influence on the data processing procedures of the social media portals. Our options are largely determined by the corporate policy of the respective provider.
Duration of data storage
The data collected directly by us via the social media presence will be deleted from our systems as soon as you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies. Stored cookies remain on your end device until you delete them. Mandatory statutory provisions - in particular retention periods - remain unaffected.
We have no influence on the storage period of your data that is stored by the operators of the social networks for their own purposes. For details, please contact the operators of the social networks directly (e.g. via their privacy policy, see below).
Instagram page
Our company has a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
The company is certified according to the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards when processing data in the USA. Certification in accordance with the DPF obliges companies to comply with these data protection standards.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875 and https://de-de.facebook.com/help/566994660333381.
Further information on the handling of your personal data can be found in Instagram's privacy policy: https://help.instagram.com/519522125107875.
LinkedIn page
Our company has a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.
If you wish to deactivate LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
The company is certified according to the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards when processing data in the USA. Certification in accordance with the DPF obliges companies to comply with these data protection standards.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.
Further information on the handling of your personal data can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.
AWS CloudFront
On our website, we use services and functions of AWS CloudFront, offered by Amazon Web Services, Inc.
Type and scope of data processing
AWS CloudFront acts as a content delivery network (CDN) on our website, which means that it helps us to make the content of our online offering - for example graphics or scripts - available quickly and efficiently. When you access this content, a connection is established to the servers of Amazon Web Services, Inc. Data such as your IP address and possibly browser data are transmitted and used exclusively to ensure the security and functionality of AWS CloudFront and to provide the above-mentioned content.Further information can be found in the privacy policy of AWS CloudFront: https://aws.amazon.com/de/privacy/.
Legal basis
We use AWS CloudFront on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest is to ensure the secure and efficient presentation and provision of our online offering.
The company is certified according to the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards when processing data in the USA. Certification in accordance with the DPF obliges companies to comply with these data protection standards.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://aws.amazon.com/de/blogs/security/aws-gdpr-data-processing-addendum/.
Further information about Amazon CloudFront CDN can be found here: https://d1.awsstatic.com/legal/privacypolicy/AWS_Privacy_Notice__German_Translation.pdf.
Order processing
In order to ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have concluded an order processing agreement (AVV) with the provider.
Cookiebot
Our website uses Cookiebot's consent technology to obtain your consent to the storage of certain cookies on your end device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark (hereinafter referred to as "Cookiebot").
When you enter our website, a connection is established to the Cookiebot servers in order to obtain your consent and other declarations regarding the use of cookies. A cookie is set in your browser in order to be able to assign and document your consent or revocation. This data is stored until you delete the cookie, request us to delete the data or the purpose for the data processing no longer applies. Statutory retention obligations remain unaffected.
Cookiebot is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.
Order processing
In order to ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have concluded an order processing agreement (AVV) with the provider.
Google Analytics
We use Google Analytics services and functions on this website, offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Type and scope of data processing
With the help of Google Analytics, we as website operators can determine how our website is used. As part of the analysis, we find out how often our website is accessed, how long visitors stay on the site and which devices or systems they use to access the website. We can also track your mouse movements and clicks. Google Analytics uses machine learning and other technologies to analyse and supplement your data. The data collected is usually processed on Google servers in the USA.
Legal basis
When using Google Analytics, we rely on your consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with §25 para. 1 TDDDG. You can revoke your consent at any time.
The company is certified according to the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards when processing data in the USA. Certification in accordance with the DPF obliges companies to comply with these data protection standards.
The transfer of your personal data to the USA is based on the standard contractual clauses of the EU Commission. You can find more information on this at https://privacy.google.com/businesses/controllerterms/mccs/.
Order processing
In order to ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have concluded an order processing agreement (AVV) with the provider.
Storage duration
Google stores data linked to cookies, user IDs or advertising IDs for two months, after which they are anonymised or deleted. Further information on the storage period or deletion of your data can be found at https://support.google.com/analytics/answer/7667196?hl=de.
Google CDN
For the fast and secure delivery of content, especially large media files, we use the Content Delivery Network (CDN) Google Cloud CDN, a service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Type and scope of data processing
Google Cloud CDN utilises a network of regionally distributed servers connected via the Internet to ensure fast and efficient access to the content we offer. For more information about Google Cloud CDN, please visit the website: https://cloud.google.com/cdn/docs/overview?hl=de.
Legal bases
The use of Google Cloud CDN serves our legitimate interest in the reliable and smooth provision of our online services and is justified in accordance with Art. 6 para. 1 lit. f GDPR.
The company is certified according to the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards when processing data in the USA. Certification in accordance with the DPF obliges companies to comply with these data protection standards.
Data is transferred to the USA on the basis of the European Commission's standard contractual clauses. You can find further information on this at https://cloud.google.com/terms/eu-model-contract-clause.
Order processing
In order to ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have concluded an order processing agreement (AVV) with the provider.
Google Tag Manager
We use Google Tag Manager services and functions on this website, which are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to use other tools on our website. It does not create any user profiles, it does not store any cookies and it does not carry out any independent analyses. However, your IP address is recorded and may be transmitted to the USA. The Google Tag Manager itself is only used to manage these tools that are integrated via it.
When using Google Tag Manager on this website, we rely on Art. 6 para. 1 lit. f GDPR as the legal basis, as we have a legitimate interest in implementing and directing tracking tools on this website quickly and easily. If you have previously given your consent to data processing on this website by Google Tag Manager, the processing of your data takes place solely on the legal basis of Art. 6 para. 1 lit. a GDPR § 25 para. 1 TDDDG. You can revoke your consent at any time.
The company is certified according to the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards when processing data in the USA. Certification in accordance with the DPF obliges companies to comply with these data protection standards.
Google reCAPTCHA
Type and scope of processing
This website uses Google reCAPTCHA. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of reCAPTCHA, the data input (e.g. in a contact form) on this website is to be checked. Specifically, whether this is done by a human or by an automated programme. Google reCAPTCHA analyses the behaviour of the website visitor based on various characteristics. The analysis begins automatically as soon as the visitor accesses the website. The data collected during the analysis, such as the IP address, the time spent on the website by the visitor or the mouse movements made, are forwarded to Google.
Visitors to the website are not made aware that an analysis is taking place; it runs completely in the background.
Google's privacy policy and terms of use can be found at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
Purpose and legal basis
The data is stored and analysed on the basis of our legitimate interest in protecting our website from abusive automated spying and SPAM (Art. 6 para. 1 lit. f GDPR). If a corresponding consent has been requested, the data will be processed exclusively on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR. This can be revoked at any time.
Webflow
Type and scope of processing
Our website was created using the Webflow website construction kit system. Webflow is a service of Webflow, Inc. and offers web development technology, web design and layout tools, domain hosting and other applications for marketing and workflow management.
We use Webflow for web hosting and the presentation of our website, among other things. In addition, Webflow collects statistical data about visits to our website.
The following data is usually transmitted: the website accessed, the date and time of access, the amount of data transferred, notification of whether access was successful, browser type and version, the user's operating system, the website previously visited (referrer) and the IP address.
This log data is processed exclusively for the above-mentioned purposes and to maintain the security, functionality and optimisation of Webflow's offering.
Purpose and legal basis
The use of the service is based on our legitimate interests, i.e. interest in the secure and efficient provision and optimisation of our online offer in accordance with Art. 6 para. 1 lit. f. GDPR.
Storage duration
The specific storage period of the processed data cannot be influenced by us, but is determined by Webflow, Inc. Further information can be found in the privacy policy for Webflow: https://webflow.com/legal/privacy.