Section 10 Security Information
(1) We have implemented many different security measures of reasonable and adequate scope for the protection of personal data.
(2) Our databases are protected by physical and technical measures as well as procedural measures that limit information access to specially authorised persons in conformity with this privacy statement. Our information system is located behind a software firewall to prevent access from other networks that are connected to the internet. Solely employees with a need to know information for the performance of specific tasks are granted access to personal data. Our employees have been trained in security matters and data protection practices. All of our employees and any and all third parties involved in data processing have been obligated to compliance with the German Federal Data Protection Act and to confidential handling of personal data.
(3) Whenever personal data are collected through our internet sites, the transmission is encrypted using the industry standard secure socket layer (“SSL”) technology via https.
(4) You should never reveal your password for your access to our internet sites to third parties, and you should change this password at regular intervals. When you leave our sites, you should always log out and close your browser to prevent any unauthorised users from obtaining access to your user account.
(5) We cannot warrant complete data security whenever email is used for communication.
Section 11 Use, Transfer and Erasure of Personal Data
(1) We use the personal data you have provided to us to answer your queries, process your orders and check your creditworthiness and for technical administration of the websites.
(2) Your personal data will be transferred to third parties solely if the transfer is required to process the contract or if you have given your express consent.
(3) In addition, we do not exclude the possibility that we will transfer anonymised use data for market research purposes. The identification of specific users is excluded in these cases (see above).
(4) We want to point out that in specific cases we are authorised and required by order of government agencies to provide information about data to the extent that this is necessary
to prosecute criminal activities,
to obtain state police protection from threats,
to perform the legal tasks required of the national and state constitution protection authorities, the Federal Intelligence Service or the Military Counterintelligence Service
or to defend intellectual property rights.
(5) The user data from visitors to the website are automatically erased immediately when the visitors leave the site. The term of the cookies is described in detail in Section 9. Data related to a query are erased once the follow-up correspondence has been completed and no later than six months after the last message that remained unanswered by the user. The data for specific quotations are either erased by the users themselves or at their request and no later than three years after issue of the quotation. Contract data are erased after complete performance of the contractual relationship, in particular after the expiration of warranty, guarantee or liability periods. These periods may be as long as 10 years after delivery of the products or acceptance of the contract performance for the manufacturers of construction products relevant for safety. Our data protection officer will be glad to answer any questions about the erasure policy.
Section 12 Your Privacy Rights
(1) You have the right to access pursuant to Art. 15 GDPR, the right to rectification pursuant to Art. 16 GDPR, the right to erasure pursuant to Art. 17 GDPR, the right to restriction of processing pursuant to Art. 18 GDPR and the right to data portability pursuant to Art. 20 GDPR. Sections 34 and 35 BDSG (Federal Data Protection Act) apply as well with respect to the rights to access and erasure. In addition, there is the right to lodge a complaint with a supervisory authority (Art. 77 GDPR and Section 19 BDSG).
(2) You have the right to obtain from us at any time information about your personal data that we have stored. You also have the right to rectification, blocking or (with the exception of the data storage related to business performance mentioned above) erasure of your personal data. You may contact Thorsten Werbeck, our data protection officer (thorsten.werbeck@novoferm.de), or the data protection officer or persons in charge of data protection at the representative office for your account at any time if you have any questions about the subject of privacy.
(3) Any data that have been blocked must be retained in a blocked file for control purposes so that the blocking of data can be respected at all times. You may also obtain the erasure of the data, provided that there are no statutory retention obligations prohibiting the erasure. If there is such a prohibition of erasure, we will at your request block data.
(4) You may make changes in or withdraw your consent by sending us a message of this content that will become effective for the future. You may withdraw consent at any time without giving your reasons and without observing any special formalities. You may use for this purpose any of the address and contact data of Novoferm tormatic GmbH shown above.
Section 13 Amendment of Our Privacy Policy
We reserve the right to adapt this privacy statement from time to time so that it always conforms to the latest legal requirements or to include changes in our services in the privacy statement, e.g. when we introduce new services or functions. The new privacy statement then applies when you visit the site again.
Section 14 Right to Object
(1) You have the right, on grounds relating to your particular situation
as user of the internet site,
as potential customer after contacting us and our distribution partners,
as registered user of the associated trading platform Tormaticsales,
or as a Novoferm tormatic GmbH customer,
to object at any time to processing of personal data concerning you which is based on point (f) of Art. 6 (1) GDPR (data processing on the grounds of a weighing of interests).
(2) If you lodge an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
(3) The objection may be lodged without special formality and can be sent to our address shown in Section 1.
Novoferm Privacy Policy Internet Services
Record of Processing Activities Pursuant to Art. 30 GDPR
Excerpt from our platform Tormaticsales (see below):
The internet site www.tormatic.de/en (including its B2B trading platform Tormaticsales and the connected lead system, which functions as described above), which is controlled pursuant to data protection and telemedia law independently in legal terms by Novoferm tormatic GmbH, but managed on the same legal grounds, according to the same rules and on the basis of the same privacy policy, operates Novoferm GmbH as processor for the group company.
Complete text
1. Controller on our behalf within the sense of data protection (including the data protection regulations of the TMG [German Telemedia Act] is Novoferm GmbH
Venue: Coesfeld Local Court, HRB 7771
Value-added tax identification number: DE811152143
Managing Directors
Rainer Schackmann, Dipl.-Ing., CEO
Thomas Hage, Dipl.-Kfm.
Dirk Gössling, Dipl.-Ing.
Isselburger Strasse 31
46459 Rees
Phone: (+49)02850-910-0
Fax: (+49)02850-910-646
Internet:
www.novoferm.com (Novoferm Group)
www.novoferm.de (Novoferm Germany)
for the joint internet site of Novoferm Group consisting of
www.novoferm.com | International site for customer information > Guide to internet sites of the local distribution companies in the target countries |
www.novoferm.de | Home page of the European subsidiary Novoferm GmbH. The portal designated as “Extranet” has been set up to provide additional product information to registered users in the addressed professional groups architects, processors (tradespeople and commercially organised entrepreneurs) and dealers. As a B2B-only platform of exclusively informational character, the platform is relevant for privacy within the sense of the GDPR solely with respect to the master data of the registered users and personal entrepreneur data. Additional services on the home page include the postal code generator and the garage door configurator for the end customers (and consumers), who cannot use the other services on the page, namely, the connected services of the trading platform NOVOSALES or the services of the B2B SAP Webshop for export trade. All of the functions relevant for safety of the site and the services offered on the site are described in the privacy statement. Using the generator, users can find what Novoferm distribution partner is responsible for the final customer business in their area by entering the postal code; using the generator, users have the opportunity to transfer the chosen (visual and technical) configuration of the garage door that interests them to the Novoferm distribution partner in their area (selected according to the entered postal code) and to have additional information about the product or a specific quotation sent to them. Users determine the objective and extent of their queries themselves. Users also determine themselves the extent of their consent to the transfer and use of their master and transaction data. The users’ consent must be given by performing an “opt-in” procedure; queries without consent are not transferred to distribution partners and are not entered in the lead system for further data processing. The lead system described below is the principal service relevant for privacy at Novoferm Group. User queries (so-called leads) collected via the group’s internet sites relevant for the system (see the specific information in each case) are recorded in the system, stored, transferred to the distribution partner bound by the Novoferm privacy statement for further transaction-related processing (replying to users’ queries) and checked for proper, competent and prompt response. Registered Novoferm distribution partners can use the system to handle the transaction correspondence through to the quotation to the end customer via the quotation function of the trading platform NOVOSALES in compliance with data protection law. Closed leads are erased by the system administrator Novoferm GmbH (transaction and master data of the users). Representative offices or distribution partners of Novoferm or distribution partners of the representative offices in the target countries are approved solely and exclusively when they have acknowledged and accepted the privacy policy of Novoferm GmbH and the terms and conditions of use of the system services (cf. login routine and terms and conditions of use for the lead system). In the event of violation of the privacy policy, the representative office or distribution partner is excluded from any further use of the system. Email contact data for the corporate group data protection officer (currently Thorsten Werbeck) are made public on all internet sites (including those of the various services and systems) and can be accessed easily and at any time with the two-click rule via the main frame link “Privacy Statement” or the specific information about the user’s declaration of consent related to the collection of the data (reference links to privacy statement). Express reference is made to users’ rights to withdraw declared consent, to rectification, blocking or erasure of their data and to obtain information about what data concerning them has been stored. The record of processing activities is made public as well in the annex to the privacy statement on the internet site. The internet site www.tormatic.de/en (including its B2B trading platform Tormaticsales and the connected lead system, which functions as described above), which is controlled pursuant to data protection and telemedia law independently in legal terms by Novoferm tormatic GmbH, but managed on the same legal grounds, according to the same rules and on the basis of the same privacy policy, operates Novoferm GmbH as processor for the group company. |
www.novofermalsal.com www.novoferm.at www.novoferm.dk www.novoferm.cz www.novoferm.gr www.novofermindustie.be www.novoferm.it www.novoferm.pl www.novoferm.bg | Representative offices on the group site with lead system: Spain | Address: Poligono Industrial de Guarnizo, 39611 Guarnizo-Cantabria Authorised representative: Javier Perez Sanchez No special features | Austria | Address: Roter Hof 1/1,2000 Stockerau Authorised representative: Robert Gruber We operate the trading platform NOVOSALES AUSTRIA parallel to the B2B trading platform NOVOSALES for our representative office in Austria. Its use is governed by the same privacy policy and terms and conditions of use as for commercial users of the trading platform Novosales. | Denmark | Address: Fynsgade 1, 6520 Toftlund Authorised representative: Anders Majland No special features | Czech Republic | Address: Petrovice u Karvine 570, 73572 Petrovice u Karvine Authorised representative: Pavel Nekola No special features | Greece | Address: 19 Asklipiou str, 14572 Kryoneri, Athens Authorised representative: Michalis Manousopoulos No special features | Belgien Industrie | Address: Boomsesteenweg 75, 2630 Aartselaar Authorised representative: René van Luijn No special features | Italy | Address: Via A.Volta 1, 35012 Camposampiero Authorised representative: Dr Mario Francescato No special features | Poland | Address: Ul.Sowia 13 F, 62-080 Tarnowo Podgome Authorised representative: Tomasz Chmielewski No special features | Bulgaria | Address: Quarter “Hadji Dimitar” Vitinia 2 J Street 2 floor Office Novoferm, 1517 Sofia Authorised representative: Ruslan Neychev No special features | |
www.novoferm.fr www.novoferm.ch www.novoferm-romania.ro www.novoferm.be www.novoferm.nl | Representative offices on the group site without lead system: France | Address: Z.i. les Redoux, 44270 Machecoul Authorised representative: Michel Akoum No special features | Switzerland | Address: Höchmatt 3, 4616 Kappel (SO) Authorised representative: Thomas Hage Based on the conduct of a local legal review, our representative in Switzerland has reviewed and confirmed the conformity of our privacy statement based on the GDPR with Swiss law. | Romania | Address: Soseaua Gherase 66-70, 23397 Bucharest Authorised representative: Mircea Bosincian No special features | Belgien Endkunden | Address: Mechelseweg 87, 1880 Kapelle o/d Bos Authorised representative: Willy Feryn No special features | The Netherlands | Address: Industrieweg 4, 6040 KB Roermond Authorised representative: Franz-Wilhelm Rieder, Antonio Venneri No special features | |
| The representative offices in Great Britain (internet site www.novoferm.co.uk) and in Hungary (www.novoferm.hu) appear independently of the group site with internet sites they design, host and operate themselves on their own responsibility under data protection and telemedia law. Our privacy statement and our procedure description do not apply to these sites. |
2. Mr Thorsten Werbeck
Herr Thorsten Werbeck
Isselburger Str. 31, 46459 Rees
Email: thorsten.werbeck@novoferm.de
has been appointed
as group data protection officer pursuant to Art. 37 (2) GDPR for the companies
Novoferm GmbH, Isselburger Str. 31, 46459 Rees
Novoferm Vertriebs GmbH, Schüttensteiner Str. 26, 46419 Isselburg
Novoferm Riexinger Türenwerke GmbH, Industriestr. 12, 74336 Brackenheim
Novoferm tormatic GmbH, Eisenhüttenweg 6, 44145 Dortmund
TST Tor System Technik GmbH, Willi-Bleicher-Str. 7, 52353 Düren
3. User data for website services are stored and processed solely and exclusively for the duration of the use of the site and are erased at the latest upon the closure of the session. User data that have been voluntarily provided with respect to a query are processed, stored and transferred to the indicated distribution partners for processing of the query solely and exclusively for the processing of the query and within the limits of the granted consent; they are erased when the query has been fully processed. Master data from registration are stored for the duration of the utilisation contract and are collected, stored and erased on the basis of the agreed terms and conditions of use. We refer to the privacy policy concerning the handling of contract performance data in operating business.
4. Data subjects are defined as:
Most broadly, all users of our internet sites in the described group site;
Then potential buyers of our products and the services we offer;
Then potential customers submitting queries whose master data are collected for the contact and transferred to the appropriate representative office or distribution partner (see above) for processing of the query and stored for review of the processing in the lead system;
Then the potential and current customers whose data are processed by registered users (representative offices and distribution partners) in the quotation function of our online shops for processing of the queries, requests for submission of quotations or for further performance of contracts (follow-up orders, warranty requests etc.). Business transactions are stored for the representative office or the distribution partner for a period of 6 (six) years. As these parties are the contract partners for the customers, they are themselves responsible for data protection that is beyond our control (lead system, trading platforms).
5. The types of processed data:
Most broadly, the anonymised user data for statistical purposes and for the optimisation of the user friendliness of our internet site described in detail in the privacy statement;
The master data entered by users in the entry mask when establishing contact. The data are correlated to the purpose of the specific user query and include, in addition to the contact data required for processing (address data, marked with *), supplementary voluntary data fields for more convenient or direct establishment of contact (phone data) and free-text fields for limited text messages. In addition to instructions for processing or restrictions of the consent declaration, users can also transmit transaction data related to the content of their queries;
The use of the postal code search requires merely the temporary entry of any postal code; a personal association with users is not established;
During the use of the configurator, the user’s data records are stored solely in accordance with his or her express request and transferred to the distribution partner in the appropriate area solely with his or her express consent (“opt-in”). Here as well, the user must enter the master data for a contact query so that his or her query about the configuration can be processed. The technical and visual data of the configuration are collected and stored along with the master data;
During registration and the conclusion of a utilisation agreement, all master data required for agreement processing and secure identification of the contract partner are collected. For the use of the B2B platforms (Extranet, trading platforms, online shop, lead system), additional master data of the user are required for verification of the entrepreneurial character within the sense of Section 13 BGB [Civil Code] and the master data of authorised representatives. For the use of the quotation function of the trading platforms and the use of the lead system functions, additional data concerning the authorised persons within the sense of data protection (access control) are collected (e.g. personalised email addresses and secure passwords);
During the processing of leads, additional specific transaction data required for processing of the specific query may, under certain circumstances, be collected and merged and processed in conjunction with the data of the query. Such actions may include follow-up questions regarding the suitability of the selected Novoferm product or the precise installation situation (e.g. of the garage door) on the user’s property or in his or her building.
6. Possible recipients of the data:
The target parties of the data transmission shown in the consent information (representative offices or distribution partners of Novoferm GmbH, e.g. Novoferm Vertriebs GmbH for the B2B market in Germany or the locally authorised distribution partner or the representative office in the target country of the user’s query for questions from other European countries);
The company’s own employees obligated to compliance with the Novoferm data protection organisation and the privacy statement and to confidentiality, especially within the framework of their activities as system administrators and order data processors;
Our processors (host service and service operators) contractually obligated to confidentiality and also subject to the European data security level as described in the privacy statement.
7. Data processing outside of the immediate territorial scope of the GDPR takes place solely for users from Switzerland on the basis of Swiss data protection law. Moreover, we also guarantee compliance with the level of European data security as a minimum for our users from Switzerland.
8. User data not related to transactions are erased at the latest immediately after conclusion of the use. Query data are erased after conclusion of the processing of the query to the extent that they do not remain permanently stored because of a subsequent business transaction and are finally erased on the basis of the erasure provisions for contract data (see above).
9. Level of security and security measures (Art. 32 GDPR)
We consider the level of security for address data that are usually available in public directories to be relatively low. We consider individual contact data, in particular transaction data for concrete installation queries, to be critical because in the worst case conclusions about reduced building security, even if only temporary, while work is being done on doors and other entrances and exits in the user’s buildings can be drawn from unauthorised data access with criminal intent in conjunction with address data. The risks related to loss of data are in contrast not a problem because even concrete user queries can be easily reproduced with little or manageable effort using the functions of the services.
We transmit even queries about contract initiation containing concrete user data via the contact forms or the configurator in encrypted form (SSL technology).
Our system administrators ensure that the transmitted data can be attributed solely and exclusively to the concrete lead and consequently the concrete user query. The system functions of the lead system ensure that the user’s data records can be read and processed solely and exclusively by the representative office in his or her area and the office’s distribution partners. (For instance, user query from Germany > access by Novoferm Vertriebs GmbH, user query from Nuremberg > supplementary access by the distribution partner in Nuremberg that prepares the contact quotation for delivery of the garage door or installation of the fire protection doors.)
All entries to the system are appropriately personalised, password-protected and used solely by persons who are contractually obligated to compliance with the Novoferm GmbH privacy policy and to implementation of the European (or Swiss, see above) level of data security within their own work organisation.
The availability and usability of the systems are guaranteed by physical and technical protective measures (firewall, secured servers in data centres, backup systems etc., all using state-of-the-art technology) as described in the general privacy policy.
The restoration of the system data from backups is guaranteed as described in the General Restoration Concept.
The inspection, analysis and evaluation of the effectiveness of the security measures is guaranteed by the PBE Concept of our group data protection officer.
Isselburg in May 2018
Thorsten Werbeck