1. Information GDPR
Responsibility for data processing in line with Article 13, Paragraph (1) Letter a)
Company name in line with Article 17, Paragraph 1 of the German Commercial Code (HGB) including the contact details of the controller (CEO)
Serafima GmbH & Co. KG
Contact details of the data protection officer in line with Article 13, Paragraph (1) Letter b) of the GDPR
Helbig Datenschutz GmbH
91207 Lauf an der Pegnitz
+49 9123 70275-10
Purposes and legal bases of data processing, in line with Article 13, Paragraph (1) Letter c) of the GDPR
Personal data are processed for the purpose of fulfilling contracts or to perform pre-contractual measures. They include customer master data with points of contact, the contact history, products, orders, invoices, project data and other statutory obligations of the controller.
The legal bases arise from Article 6 of the GDPR. Other main legal bases arise from the German Commercial Code, tax legislation, the companies act and other statutory legislation relevant to Serafima GmbH & Co. KG. This also includes contractual regulations. Processing of newsletters is subject to consent by the data subject.
Processing is to protect the legitimate interests of the controller or a third party in line with Article 13, Paragraph (1) Letter d) of the GDPR
Insofar as it is necessary we process your data beyond the actual fulfilment of the contract in order to preserve our legitimate interests or those of third parties. They include
- sales steering and controlling
- assertion of legal claims and defence in case of legal disputes
- ensuring IT security and operation
- measures for building and plant security (e.g. access control) and preserving the right to determine who is allowed or denied access
- measures for business steering and development
Categories of recipients of personal data (data transmission) in line with Article 13, Paragraph (1) Letter e) of the GDPR
Within Germany, the European Union and European Economic Area Germany
Auditors, bailiffs and other creditors, also other public offices for fulfilling legal obligations and requested certifications, logistics companies, customers and suppliers and other bodies and business partners.
Third countries including adequacy decision in line with Article 13, Paragraph (1) Letter f DSGVO of the GDPR
Within the context of international business relations, transmission is performed in line with Article 6, Paragraph 1, Letter b for the fulfilment of contracts or to perform pre-contractual measures. No adequacy decision in necessary for this purpose.
Retention period in line with Article 13, Paragraph (2), Letter a)
The respective purposes arise from the legal specifications and relevant sector-specific regulations. Personal data are erased once the purpose is fulfilled.
Rights of the data subject in line with Article 13, Paragraph (2), Letter b)
You can exercise your rights at any time via the above contact details. If your personal data are processed, you are a data subject within the meaning of the GDPR and are entitled to the following rights vis-à-vis the controller:
Information on the rights of data subjects
The data subject is entitled to demand from the controller confirmation of whether personal data about them are processed; if this is the case, they have the right to access information about these personal data and to the information listed in detail in Article 15 of the GDPR.
The data subject is entitled to demand from the controller the immediate correction of personal data about them that is incorrect and if necessary to demand completion of incomplete personal data (Article 16 of GDPR).
The data subject has the right to demand of the controller that they immediately erase personal data about them, insofar as one of the reasons listed in Article 17 of the GDPR applies, for instance when the data are no longer required for the purposes pursued (right to erasure).
The data subject has the right to demand of the controller the restriction of processing if one of the prerequisites listed in Article 18 of the GDPR, for instance if the data subject has filed an objection to processing, while the controller reviews the case.
The data subject has the right to file an objection to the processing of their personal data at any time for reasons relating to their particular circumstances. The controller will then no longer process the personal data, unless they can prove urgent legitimate reasons for processing, which take precedence over the interests, rights and freedoms of the data subject, or processing is for the purpose of asserting, exercising or defending legal rights (Article 21 of the GDPR).
Rights of the data subject in line with Article 13, Paragraph (2), Letter c) DSGVO
Insofar as you have given your consent to us to process your personal data for specific purposes (e.g. to process the data subject’s pictures), the legitimacy of this processing is based on your consent.
Once granted, consent can be revoked at any time. This also applies to revoking declarations of consent granted before the GDPR came into effect, thus before 25 May 2018. Please note that the revocation is only effective for the future. Processing performed before your revocation is not affected.
Right to complain to a supervisory authority in line with Article 13, Paragraph (2), Letter D) of the GDPR
Irrespective of any other administrative rights under law or legal redress, every data subject has the right to lodge a complaint with a supervisory authority if they are of the opinion that the processing of personal data about them breaches the GDPR (Article 77 of the GDPR). The data subject can assert this right to a supervisory authority in the member state of their place of residence, their workplace or the place where the alleged breach took place.
In Baden-Württemberg the responsible supervisory authority is:
The State Commissioner for Data Protection and Freedom of Information
Postfach 10 29 32
Tel.: +49 711 615541-0
Fax: +49 711 615541-15
Personal data provided in line with Article 13, Paragraph (2) Letter e) of the GDPR
As part of our business relationship you only need to provide the personal data required for the establishment, execution and termination of the employment relationship or data which are required by law to collect. Without these data we will generally be unable to execute the employment relationship.
Change of purpose
2. An overview of data protection
The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit our website. The term “personal data” comprises all data that can be used to personally identify you. For detailed information about the subject matter of data protection, please consult our Data Protection Declaration, which we have included beneath this copy.
Data collection in our website
Who is the responsible party for the recording of data on this website (i.e. the “controller”)?
How do we record your data?
We collect your data as a result of your sharing of your data with us. This may, for instance be information you enter into our contact form.
Our IT systems automatically record other data when you visit our website. This data comprises primarily technical information (e.g. web browser, operating system or time the site was accessed). This information is recorded automatically when you access our website.
What are the purposes we use your data for?
A portion of the information is generated to guarantee the error free provision of the website. Other data may be used to analyse your user patterns.
What rights do you have as far as your information is concerned?
Analysis tools and tools provided by third parties
There is a possibility that your browsing patterns will be statistically analysed when you visit our website. Such analyses are performed primarily with cookies and with what we refer to as analysis programmes. As a rule, the analyses of your browsing patterns are conducted anonymously; i.e. the browsing patterns cannot be traced back to you. You have the option to object to such analyses or you can prevent their performance by not using certain tools. For detailed information about this, please consult our Data Protection Declaration below.
You do have the option to object to such analyses. We will brief you on the objection options in this Data Protection Declaration.
3. General information and mandatory information
The operators of this website and its pages take the protection of your personal data very seriously. Hence, we handle your personal data as confidential information and in compliance with the statutory data protection regulations and this Data Protection Declaration.
Whenever you use this website, a variety of personal information will be collected. Personal data comprises data that can be used to personally identify you. This Data Protection Declaration explains which data we collect as well as the purposes we use this data for. It also explains how, and for which purpose the information is collected.
We herewith advise you that the transmission of data via the Internet (i.e. through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third party access.
Revocation of your consent to the processing of data
A wide range of data processing transactions are possible only subject to your express consent. You can also revoke at any time any consent you have already given us. To do so, all you are required to do is sent us an informal notification via e-mail. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.
Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)
In the event that data are processed on the basis of Art. 6 Sect. 1 lit. e or GDPR, you have the right to at any time object to the processing of your personal data based on grounds arising from your unique situation. This also applies to any profiling based on these provisions. To determine the legal basis, on which any processing of data is based, please consult this Data Protection Declaration. If you log an objection, we will no longer process your affected personal data, unless we are in a position to present compelling protection worthy grounds for the processing of your data, that outweigh your interests, rights and freedoms or if the purpose of the processing is the claiming, exercising or defence of legal entitlements (objection pursuant to Art. 21 Sect. 1 GDPR).
If your personal data is being processed in order to engage in direct advertising, you have the right to at any time object to the processing of your affected personal data for the purposes of such advertising. This also applies to profiling to the extent that it is affiliated with such direct advertising. If you object, your personal data will subsequently no longer be used for direct advertising purposes (objection pursuant to Art. 21 Sect. 2 GDPR).
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as purchase orders or inquiries you submit to us as the website operator, this website uses either an SSL or a TLS encryption programme. You can recognise an encrypted connection by checking whether the address line of the browser switches from “http://” to “https://” and also by the appearance of the lock icon in the browser line.
If the SSL or TLS encryption is activated, data you transmit to us cannot be read by third parties.
Information, blocking, deletion
As permitted by law, you have the right to be provided at any time with information free of charge about any of your personal data that is stored as well as its origin, the recipient and the purpose for which it has been processed. You also have the right to have this data corrected, blocked or deleted. You can contact us at any time using the address given in our legal notice if you have further questions on the topic of personal data.
Opposition to promotional emails
We hereby expressly prohibit the use of contact data published in the context of website legal notice requirements with regard to sending promotional and informational materials not expressly requested. The website operator reserves the right to take specific legal action if unsolicited advertising material, such as email spam, is received.
4. Data collection on our website
In some instances, our website and its pages use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. The purpose of cookies is to make our website more user friendly, effective and more secure. Cookies are small text files that are placed on your computer and stored by your browser.
Most of the cookies we use are so-called “session cookies.” They are automatically deleted after your leave our site. Other cookies will remain archived on your device until you delete them. These cookies enable us to recognise your browser the next time you visit our website.
You can adjust the settings of your browser to make sure that you are notified every time cookies are placed and to enable you to accept cookies only in specific cases or to exclude the acceptance of cookies for specific situations or in general and to activate the automatic deletion of cookies when you close your browser. If you deactivate cookies, the functions of this website may be limited.
Cookies that are required for the performance of the electronic communications transaction or to provide certain functions you want to use, are stored on the basis of Art. 6 Sect. 1 lit. f GDPR. The website operator has a legitimate interest in storing cookies to ensure the technically error free and optimised provision of the operator’s services. If other cookies (e.g. cookies for the analysis of your browsing patterns) should be stored, they are addressed separately in this Data Protection Declaration.
Server log files
The website provider automatically collects and stores information that your browser automatically transmits to us in "server log files". These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources.
This data is recorded on the basis of Art. 6 Sect. 1 lit. f GDPR. The operator of the website has a legitimate interest in the technically error free depiction and the optimization of the operator’s website. In order to achieve this, server log files must be recorded.
If you submit inquiries to us via our contact form, the information provided in the contact form as well as any contact information provided therein will be stored by us in order to handle your inquiry and in the event that we have further questions. We will not share this information without your consent.
Hence, the processing of the data entered into the contact form occurs exclusively based on your consent (Art. 6 Sect. 1 lit. a GDPR). You have the right to revoke at any time any consent you have already given us. To do so, all you are required to do is sent us an informal notification via e-mail. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.
The information you have entered into the contact form shall remain with us until you ask us to eradicate the data, revoke your consent to the archiving of data or if the purpose for which the information is being archived no longer exists (e.g. after we have concluded our response to your inquiry). This shall be without prejudice to any mandatory legal provisions – in particular retention periods.
Processing of data (customer and contract data)
We collect, process and use personal data only to the extent necessary for the establishment, content organization or change of the legal relationship (data inventory). These actions are taken on the basis of Art. 6 Sect. 1 lit. b GDPR, which permits the processing of data for the fulfilment of a contract or pre-contractual actions. We collect, process and use personal data concerning the use of our website (usage data) only to the extent that this is necessary to make it possible for users to utilize the services and to bill for them.
The collected customer data shall be eradicated upon completion of the order or the termination of the business relationship. This shall be without prejudice to any statutory retention mandates.
Request by e-mail, telephone or fax
If you contact us by e-mail, telephone or fax, your request, including all resulting personal data (name, request) will be stored and processed by us for the purpose of processing your request. We do not pass these data on without your consent.
The processing of these data is based on Art. 6 para. 1 lit. b GDPR, if your request is related to the execution of a contract or if it is necessary to carry out pre-contractual measures. In all other cases, the processing is based on your consent (Article 6 (1) a GDPR) and/or on our legitimate interests (Article 6 (1) (f) GDPR), since we have a legitimate interest in the effective processing of requests addressed to us.
The data sent by you to us via contact requests remain with us until you request us to delete, revoke your consent to the storage or the purpose for the data storage lapses (e.g. after completion of your request). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.
5. Social Media
Share Content via plugins (Facebook, Google+, Twitter, etc.)
The content on our pages can be shared on other social networks like Facebook, Twitter, or Google+. This page uses the eRecht24 Safe Sharing Tool. This tool establishes direct contact between the networks and users only after users click on one of these buttons.
This tool does not automatically transfer user data to the operators of these platforms.
Our users can share the content of this page on social networks without their providers creating profiles of users' surfing behavior.
Our website uses functions of the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.
Any time you access one of our sites that contains functions of LinkedIn, a connection to LinkedIn’s servers is established. LinkedIn is notified that you have visited our websites with your IP address. If you click on LinkedIn’s "Recommend" button and are logged into your LinkedIn account at the time, LinkedIn will be in a position to allocate your visit to our website to your user account. We have to point out that we as the provider of the websites do not have any knowledge of the content of the transferred data and its use by LinkedIn.
The use of the LinkedIn plug-in is based on Art. 6 Sect. 1 lit. f GDPR. The operator of the website has a legitimate interest in being as visible as possible on social media.
For further information on this subject, please consult LinkedIn’s Data Privacy Declaration at: https://www.linkedin.com/legal/privacy-policy.
Our website uses features provided by the XING network. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany.
Each time one of our pages containing XING features is accessed, your browser establishes a direct connection to the XING servers. To the best of our knowledge, no personal data is stored in the process. In particular, no IP addresses are stored nor is usage behavior evaluated.
The use of the XING plug-in is based on Art. 6 Sect. 1 lit. f GDPR. The operator of the website has a legitimate interest in being as visible as possible on social media.
6. Analytics and advertising
This website uses functions of the web analysis service Google Analytics. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses so-called cookies. Cookies are text files, which are stored on your computer and that enable an analysis of the use of the website by users. The information generated by cookies on your use of this website is usually transferred to a Google server in the United States, where it is stored.
The storage of Google Analytics cookies and the utilization of this analysis tool are based on Art. 6 Sect. 1 lit. f GDPR. The operator of this website has a legitimate interest in the analysis of user patterns to optimize both, the services offered online and the operator’s advertising activities.
On this website, we have activated the IP anonymization function. As a result, your IP address will be abbreviated by Google within the member states of the European Union or in other states that have ratified the Convention on the European Economic Area prior to its transmission to the United States. The full IP address will be transmitted to one of Google’s servers in the United States and abbreviated there only in exceptional cases. On behalf of the operator of this website, Google shall use this information to analyse your use of this website to generate reports on website activities and to render other services to the operator of this website that are related to the use of the website and the Internet. The IP address transmitted in conjunction with Google Analytics from your browser shall not be merged with other data in Google’s possession.
You do have the option to prevent the archiving of cookies by making pertinent changes to the settings of your browser software. However, we have to point out that in this case you may not be able to use all of the functions of this website to their fullest extent. Moreover, you have the option prevent the recording of the data generated by the cookie and affiliated with your use of the website (including your IP address) by Google as well as the processing of this data by Google by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
Objection to the recording of data
You have the option to prevent the recording of your data by Google Analytics by clicking on the following link. This will result in the placement of an opt out cookie, which prevents the recording of your data during future visits to this website: Google Analytics deactivation.
For more information about the handling of user data by Google Analytics, please consult Google’s Data Privacy Declaration at: https://support.google.com/analytics/answer/6004245?hl=en.
Contract data processing
We have executed a contract data processing agreement with Google and are implementing the stringent provisions of the German data protection agencies to the fullest when using Google Analytics.
Data on the user or incident level stored by Google linked to cookies, user IDs or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) will be anonymized or deleted after 14 month. For details please click the following link: https://support.google.com/analytics/answer/7667196?hl=de.
7. Plugins and tools
Our website uses plug-ins of the YouTube platform, which is being operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited.
Furthermore, YouTube will be able to place various cookies on your device. With the assistance of these cookies, YouTube will be able to obtain information about our website visitor. Among other things, this information will be used to generate video statistics with the aim of improving the user friendliness of the site and to prevent attempts to commit fraud. These cookies will stay on your device until you delete them.
If you're logged in to your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.
YouTube is used to help make our website appealing. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.
Further information about handling user data, can be found in the data protection declaration of YouTube under https://www.google.de/intl/de/policies/privacy.
For uniform representation of fonts, this page uses web fonts provided by Monotype GmbH and Hoefler & Co. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.
For this purpose your browser has to establish a direct connection to the servers of the mentioned providers. The providers thus becomes aware that our web page was accessed via your IP address. The use of these web fonts is done in the interest of a uniform and attractive presentation of our website. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.
If your browser does not support web fonts, a standard font is used by your computer.
Further information about handling user data, can be found at the following adresses. Hoefler & Co.: https://www.typography.com/home/privacy-cloud-declaration.php and at https://www.typography.com/home/privacy.php. Monotype GmbH: https://www.monotype.com/legal/privacy-policy.
8. Custom Services
We offer website visitors the opportunity to submit job applications to us (e.g. via e-mail, via postal services on by submitting the online job application form). Below, we will brief you on the scope, purpose and use of the personal data collected from you in conjunction with the application process. We assure you that the collection, processing and use of your data will occur in compliance with the applicable data privacy rights and all other statutory provisions and that your data will always be treated as strictly confidential.
Scope and purpose of the collection of data
If you submit a job application to us, we will process any affiliated personal data (e.g. contact and communications data, application documents, notes taken during job interviews, etc.), if they are required to make a decision concerning the establishment or an employment relationship. The legal grounds for the aforementioned are § 26 New GDPR according to German Law (Negotiation of an Employment Relationship), Art. 6 Sect. 1 lit. b GDPR (General Contract Negotiations) and – provided you have given us your consent – Art. 6 Sect. 1 lit. a GDPR. You may revoke any consent given at any time. Within our company, your personal data will only be shared with individuals who are involved in the processing of your job application.
If your job application should result in your recruitment, the data you have submitted will be archived on the grounds of § 26 New GDPR and Art. 6 Sect. 1 lit. b GDPR for the purpose of implementing the employment relationship in our data processing system.
Data Archiving Period
If we should not be able to offer you a position, if you refuse a job offer, retract your application, revoke your consent to the processing of your data or ask us to delete your data, we will store your transferred data, incl. any physically submitted application documents for a maximum of 6 months after the conclusion of the application process (retention period) to enable us to track the details of the application process in the event of disparities (Art. 6 Sect. 1 lit. f GDPR).
You have the option to object to this storage/ retention of your data if you have legitimate interests to do so, that outweigh our interests.
Once the retention period has expired, the data will be deleted, unless we are subject to any other statutory retention obligations or if any other legal grounds exist to continue to store the data. If it should be foreseeable that the retention of your data will be necessary after the retention period has expired (e.g. due to imminent or pending litigation), the data shall not be deleted until the data have become irrelevant. This shall be without prejudice to any other statutory retention periods.