Data protection
Data protection information and further information on the protection of your personal data
Data protection information and further information on the protection of your personal data
The protection of personal data you provide to us for processing is of utmost importance to us. In the following, we are providing information on the processing of personal data when using our online services.
Within the framework of our data protection responsibility, the commencement of the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereafter referred to as:“GDPR”) has imposed additional duties on us to ensure the protection of personal data of a person who is affected by the processing of same (we are addressing you, as an affected person, with “Customer”, “User”, “You”, or “Affected Party”).
Insofar that we are making decisions on the purposes and means of data processing, either solely or jointly with others, this especially includes the duty to provide you with transparency regarding the type, scope, purpose, duration and legal basis of the processing (see section 13 and 14 GDPR). With these data protection notices, we are informing you of the way in which we process your personal data.
This website is offered by Schaerer AG, Niedermattstrasse 3b, Postfach 336, 4528 Zuchwil, Schweiz, E-Mail: [email protected] (hereinafter “Schaerer”) as the controller as defined in the EU General Data Protection Regulation (hereinafter the “GDPR”). The processing of your data is subject to the GDPR. You can contact our data protection officer using the contact form available under Send Inquiry to the Data Protection Officer or at our postal address marked Attention: Data Protection Officer.
Within the framework of our business relationships, we may forward or disclose your personal data to third-party companies. They can be located outside of the European Economic Area (EEA), which means in third countries. Such processing exclusively occurs for the performance of contractual and business obligations and to maintain your business relationship with us (legal basis is section 6(1)(b) or (f), in combination with section 44 ff. GDPR). We are providing you with information on the details of the forwarding in the following in the relevant places.
The European Commission certifies for some third countries by way of so-called adequacy decisions that the data protection is comparable to that of the EEA standard (a list of these countries and a copy of the adequacy decisions are provided here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en). In other third countries, to which personal data may be transmitted, the data protection level may not be continuously high under certain circumstances due to the lack of legal requirements. Where this is the case, we are making sure that data protection is adequately ensured. Please contact our Data Protection Officer for more information.
The conclusion of contracts with us is not contingent upon your provision of personal data. You, the customer, are not legally or contractually obligated at any time to provide us with your personal data. However, it is possible that we can provide certain offers only with restrictions or not at all if you do not provide the subsequently required data. Should this be the case as an exception for the products offered by us, you will be notified accordingly.
Under certain circumstances, we may be subject to a particular statutory or legal obligation to provide the legitimately processed personal data to third parties, particularly public bodies (section 6(1)(1)(c) GDPR).
You have the right to request information about the personal data concerning you that we process in accordance with Article 15 of the GDPR.
You have the right to object on compelling legitimate grounds. Pursuant to Article 6(1)(f) of the GDPR, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you. The controller will then no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims. The collection of data for the provision of the website and the storage of log files are essential for the operation of the website.
If the information concerning you is no longer accurate, you can request a correction in accordance with Art. 16 of the GDPR. If your data is incomplete, you can request that it be completed.
You can request the erasure of your personal data in accordance with Art. 17 of the GDPR.
According to Art. 18 GDPR, you have the right to request a restriction of the processing of your personal data.
If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority of your choice in accordance with Article 77 (1) GDPR. This also includes the data protection supervisory authority responsible for the controller.
In the event that the conditions of Art. 20 (1) GDPR are met, you have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract delivered to yourself or to third parties. The collection of data for the provision of the website and the storage of log files are essential for the operation of the website. They are therefore not based on consent pursuant to Article 6(1)(a) of the GDPR or on a contract pursuant to Article 6(1)(b) of the GDPR, but are justified pursuant to Article 6(1)(f) of the GDPR. The requirements of Article 20(1) of the GDPR are therefore not met in this respect.
We are using suitable technical and organisational security measures to protect your data from incidental or intentional manipulations, partial or complete loss, destruction or unauthorised access by third parties (e.g. TLS encryption for our website) under consideration of the state of the art, implementation costs and the nature of the scope, context and purpose of processing as well as the existing risks of a data breach (including its probability and effects for the affected person. We are continuously improving our security measures according to the technological development.
We will be happy to provide you with further information upon request. Please contact our Data Protection Officer.
Every time the website content is accessed, data that may possibly allow identification is temporarily stored. The following data is collected in this process:
Date and time of access
IP address
Host name of the accessing computer
Website from which the website was accessed
Websites accessed via the website
Page visited on our website
Protocols and status code
Amount of data transferred
Information about the browser type and version used
Operating system
User agent
Log data (directory protection user, referrer, host name accessed)
The IP addresses are anonymized and stored. The temporary storage of data is necessary for the process of a website visit to enable delivery of the website. Further storage in log files is done to ensure the functionality of the website and the security of the information technology systems.
During anonymization, all data relating to the sender/recipient, etc. is removed. Only the data regarding the time of sending and information on how the e-mail was processed (queue ID or not sent) is retained.
These purposes also include our legitimate interest in data processing.
The data is processed on the basis of Article 6(1)(f) of the GDPR.
We are using Amazon Web Services (AWS) - as the hosting provider for our websites. AWS is acting as processor and located at Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxemburg
Cloudflare - Cloudflare’s global cloud platform delivers a range of network services to businesses of all sizes around the world—making them more secure while enhancing the performance and reliability of their critical Internet properties. Cloudflare is acting as processor and located at Cloudflare Inc., 101 Townsend St San Francisco, CA, 94107, USA. https://www.cloudflare.com/privacypolicy/ https://www.cloudflare.com/cookie-policy/ Website: https://aws.amazon.com/
Privacy Policy: https://aws.amazon.com/privacy/
GDPR compliance information: https://aws.amazon.com/compliance/gdpr-center/
DPA: https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf
Storyblok - Storyblok and its Affiliates offer a SaaS-based headless content management system (including the Storyblok APIs and Documentation) and a digital experience platform (DXP) with a visual editor, that allows customers to upload, manage and publish Customer Content by using Storyblok APIs (the “Storyblok Services”). Storyblok is acting as processor and located at Storyblok Solutions GmbH is registered in Austria, FN 608512x, ATU79663909, Loquaiplatz 12/1, 1060 Vienna, Austria. (https://www.storyblok.com/terms)
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected, but no later than one day after collection. The cookies for the purpose of providing evidence of consent and the cookie for the watch list are stored for at least one month. The anonymized IP addresses are stored for 60 days. Information on the directory protection user employed is anonymized after one day. The mail logs for sending e-mails from the web environment are anonymized after one day and then stored for 60 days. Error logs, which log incorrect page views, are deleted after seven days. Access via FTP is logged with anonymized information about the user name and IP address and stored for 60 days. Mail logs for sending via our mail servers are deleted after four weeks. The retention period is necessary to ensure the functionality of the mail services and to combat spam.
We use the consent management tool from OneTrust to manage your consent to the processing of personal data on our website. The following data is processed:
Consent details (yes/no)
Time of the consent
IP address
Browser information
Device information
Websites visited
The Consent Management Tool is used for the purpose of:
Management and documentation of your consent to data processing
Compliance with the legal requirements of the General Data Protection Regulation (GDPR)
Ensuring transparent and comprehensible data processing
Optimising the user experience on our website
We process this data on the basis of Art. 6 para. 1 lit. f GDPR (legitimate interest).
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected.
The data collected is passed on to our service provider OneTrust, which supports us in managing the consents. OneTrust receives the above-mentioned data as a processor.
Registered office: OneTrust LLC, 1200 Abernathy Rd, Suite 600, Atlanta, Georgia 30328, USA
Website: https://www.onetrust.com/de
Data protection information: https://www.onetrust.com/de/privacy-notice/
When you use the contact form, the data categories transmitted thereby are: “contact form data”:
personal and contact data
address data
possibly order and product data
and the time of transmission
as well as possibly voluntarily given data on the location and telephone data.
The purpose of the processing is to contact you if you have questions about our products and services and to provide assistance if necessary.
We process this data on the basis of Art. 6 (1) (b) for the purpose of contract initiation or fulfillment.
Sendgrid
The data is deleted as soon as it is no longer required for the purpose for which it was collected. In the case of the contact form, this is usually the case after it has been sent to us. However, it may be stored for up to ten years due to legal obligations. As a rule, the storage period is three years.
We offer you the opportunity to subscribe to our newsletter. If you register for our newsletter, we will process the following “newsletter data”:
IP address (truncated – a personal reference can be created)
Page from which the page was requested (so-called referrer URL)
Date and time of access
Information about the browser type and the version used
E-mail address
Date and time of registration and confirmation
The purpose of the processing is to send you the newsletter and to inform you about current products, product developments and promotions, as well as to fulfill our accountability obligations and, if necessary, to clarify any possible misuse of your personal data.
We would like to point out that we evaluate your user behavior when sending the newsletter. For this evaluation, the sent e-mails contain so-called web beacons or tracking pixels, which represent one-pixel image files stored on our website. For the evaluations, we link the data mentioned in 2.A.a. and the web beacons with your e-mail address and an individual ID. Links contained in the newsletter also contain this ID. We use the data obtained in this way to create a user profile in order to tailor the newsletter to your individual interests. In doing so, we record when you read our newsletters and which links you click on in them, and from this we deduce your personal interests. We link this data to the actions you take on our website.
You can opt out of this tracking at any time by clicking on the separate link provided in each e-mail or by contacting us through another channel. The information is stored for as long as you are subscribed to the newsletter. After you unsubscribe, we store the data in a purely statistical and anonymous form. Furthermore, such tracking is not possible if you have disabled the display of images by default in your e-mail program. In this case, the newsletter will not be displayed in full and you may not be able to use all the functions. If you display the images manually, the tracking described above will take place.
By registering for our newsletter, you consent to the processing of your personal data (legal basis is Art. 6 para. 1 lit. a DS-GVO). We use the so-called double opt-in procedure for registering for our newsletter. This means that after you have registered, we will send you an e-mail to the e-mail address provided, in which we ask you to confirm that you wish to receive the newsletter.
XQueue GmbH, Christian-Pless-Str. 11-13, 63069 Offenbach, is used to process the newsletter procedure. XQueue GmbH receives the above-mentioned data as a processor.
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the newsletter, this is the case when you unsubscribe from the newsletter. Due to obligations to provide evidence, the data may be stored for up to three years after you unsubscribe.
We use a service called Google Tag Manager from Google. “Google” is a group of companies and consists of the companies Google Ireland Ltd. (service provider), Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA and other affiliated companies of Google LLC. We have concluded a data processing agreement with Google. The Google Tag Manager is an auxiliary service and itself processes personal data only for technically necessary purposes. The Google Tag Manager ensures that other components are loaded, which in turn may collect data under certain circumstances. The Google Tag Manager does not access this data. Further information about the Google Tag Manager can be found in the privacy policy of Google. Please note that US authorities, such as secret services, may be able to access personal data that is inevitably exchanged with Google when this service is integrated due to US laws such as the Cloud Act based on the Internet Protocol (TCP). https://policies.google.com/?hl=de .
If you have given your consent, this website uses Google Analytics 4, which is a web analysis service provided by Google LLC. The responsible office for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).
Google Analytics uses cookies that enable us to analyse your use of our websites. The information that is collected by the cookies on your use of this website is generally transmitted to a Google server in the USA and stored there.
We are using the User ID function. With this User ID, we can assign a unique permanent ID to this or multiple sessions (and the activities during these sessions) and analyse user behaviour across devices.
In Google Analytics 4, the anonymisation of IP addresses is activated by default. Due to the IP anonymisation, Google truncates your IP address within the member states of the European Union or in other contractual states of the treaty for the European Economic Area. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and truncated there. According to Google, the IP address transmitted from your browser as part of Google Analytics will not be merged with other data.
During your website visit, your user behaviour will be recorded in form of “events”. Events can be:
Page views
Communication using contact form
Initial visit of the website
Start of the session
Visited websites
Your “click path” interaction with the website
Scrolls (whenever a user scrolls to the end of the page (90%))
Clicks on external links
Internal search queries
Interaction with videos
File downloads
Viewed / clicked advertisements
Language setting
The following is also recorded:
Your approximate location (region)
Date and time of your visit
Your IP address (truncated)
Technical information on your browser and end devices used by you (e.g. language setting, screen resolution)
Your internet provider
Referrer URL (which website/which advertising media brought you to this website)
On behalf of the operator of this website, Google will use this information to analyse your use of the website and to compile reports on website activities. Reports provided by Google Analytics serve to analyse the performance of our website and the success of our marketing campaigns.
Recipients of the data are/may be
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as processor according to section 28 GDPR)
Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA
Alphabet Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA
For the USA, the European Commission has adopted its adequacy decision on 10 July 2023. Google LLC is certified according to the EU-US Privacy Framework. Because Google servers are distributed worldwide and a transfer to third countries (to Singapore, for example) cannot be fully excluded, we have also concluded EU standard clauses with the provider.
We are using DoubleClick Floodlight on our websites. DoubleClick Floodlight is a service offered by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). When you visit our websites, Google sets a cookie on your computer to generate a unique user identification. The data consumed by you is allocated to this user identification. For example, this can prevent that an ad is displayed for you that you have already seen. In addition, the cookies enable the measurement of conversions. This means, it determines if you, after you have viewed or opened a corresponding ad, have executed certain actions.
If you do not wish to receive interest-based advertising, you can deactivate the use of cookies for this purpose by accessing https://www.google.de/settings/ads . Alternatively, users can deactivate the use of cookies from third-party providers by starting the deactivation page of the network advertising initiative.
The users can view the purpose and scope of the data collection and the further processing and use of the data by Google as well as the related rights and setting options for the protection of the privacy of the users in the Google data protection notices: https://policies.google.com/privacy?hl=en.
Our website uses the Microsoft Advertising service. Microsoft Advertising is an online advertising programme of Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521). ("Microsoft").
We use Universal Event Tracking (UET) within the Microsoft Advertising service, which collects and stores data on this website for marketing and optimisation purposes.
For this purpose, your surfing behaviour on our website is analysed, e.g. which offers you have viewed. Microsoft stores a cookie in your browser for this purpose. Your visits are recorded via this cookie. The cookie is used to uniquely identificate your web browser and not to identificate you personally.
Microsoft processes the data collected about you on this website as the sole controller under data protection law. In this context, it is possible that your data may be transferred by Microsoft to the USA. The European Court of Justice has ruled that the USA is a country with an inadequate level of data protection. In this context, there is a particular risk that your data will be processed by American institutions/authorities for control and monitoring purposes without you having sufficient legal recourse against this.
The legal basis for this data processing is Article 6(1)(a) GDPR (consent). You can find more information on Microsoft's privacy policy at: https://privacy.microsoft.com/de-DE/privacystatement
Here you can also assert your data subject rights against Microsoft (e.g. right to erasure).
You can deactivate the use of cookies by Microsoft and thus revoke the consent you have given us for the use of the Microsoft Advertising service or refuse to consent to the use of Microsoft Retargeting by following the link below: https://choice.microsoft.com/de-DE/opt-out
Our website uses the LinkedIn Insight Tag conversion tool from LinkedIn Ireland Unlimited Company. This tool creates a cookie in your web browser, which enables the collection of information such as: IP address, device and browser characteristics and page events (e.g. page views). This data is encrypted, anonymised within seven days and the anonymised data is deleted within 90 days. LinkedIn does not share any personal data with WMF GmbH, but offers anonymised reports on the website target group and display performance. In addition LinkedIn offers the possibility of retargeting via the Insight Tag. WMF GmbH may use this data to display targeted advertising outside its website without identifying you as a website visitor. For more information about LinkedIn's privacy policy please refer to the LinkedIn privacy policy www.linkedin.com/legal/privacy-policy.
LinkedIn members may control the use of their personal information for promotional purposes in their account settings. To disable ("opt-out") the Insight tag on our website www.linkedin.com/psettings/guest-controls/retargeting-opt-out.