
Data Protection for Business Partners
Privacy policy for business partners
Here you will find information about the collection and use of personal data (“data”) in the course of conducting our business activities. In this case, we are in a business relationship with you or with your employer or principal, e.g. the initiation, performance or termination of a contractual relationship in the course of our business activities.
The controller pursuant to Art. 4(7) of the EU General Data Protection Regulation (GDPR) is:
Thomas Rosin
Klaus-Groth-Str. 4
23611 Bad Schwarta
Germany
Tel.: 0451 305000-0
E-mail: info<ät>thomasrosin.de
We expressly point out that data transmission over the internet (e.g. when communicating by e-mail) can have security gaps and cannot be completely protected against access by third parties. For a more secure transmission of data, we will be happy to provide you, upon informal request, with
- our PGP key. Information on encryption with PGP can be found in the German Wikipedia (Pretty Good Privacy). Free software for using this procedure can be found on the website of the Gpg4win project (www.gpg4win.de).
- our public S/MIME certificate. Information on encryption using S/MIME can be found here: S/MIME
The use of our contact details for commercial advertising is expressly undesired, unless we have previously given our consent or a business relationship already exists. We hereby object to any commercial use and disclosure of our data.
Personal data
“Personal data are individual details about the personal or material circumstances of an identified or identifiable natural person (data subject).” Personal data include, for example, name, address, date of birth, occupation, religion, but also details such as hobbies, possessions, purchases, behaviours, etc. The purpose of the Federal Data Protection Act and other special provisions is to protect the rights and freedoms of data subjects with regard to their data against misuse.
Data categories and origin (direct collection, employer)
We process personal data that you provide to us in the context of the business relationship. If our business relationship is with your employer or principal, we also collect the personal data either from you yourself or from your employer or principal. This involves the following data or categories of data:
- master data (e.g. name and salutation, title, job title/position designation)
- contact data (e.g. telephone number, fax number, e-mail address, address)
- communication data (e.g. contents of personal, telephone or written communication)
In addition, we process the following categories of personal data that we generate ourselves:
- master data (e. g. customer number or contact number)
- offer and contract data (e.g. contract identifier, contract history)
- consultancy and training data (e.g. minutes, reports, analyses, attendance lists)
Data categories and origin (sales partners)
If you are in contact with one of our sales partners and express the wish to obtain products or services from us, we collect your personal data via this sales partner. This involves the following data or categories of data:
- master data (e.g. name and salutation, title, job title/position designation)
- contact data (e.g. telephone number, fax number, e-mail address, address)
- communication data (e.g. contents of personal, telephone or written communication)
In addition, we process the following categories of personal data that we generate ourselves:
- master data (e. g. customer number or contact number)
- offer and contract data (e.g. contract identifier, contract history)
- consultancy and training data (e.g. minutes, reports, analyses, attendance lists)
Purposes of processing
If you are a contractual partner yourself, we process your personal data to fulfil contractual obligations (Art. 6(1)(1)(b) GDPR), more precisely for the purpose of initiating, performing or fulfilling a contract with you. These include, for example, the placing of orders, internal sales activities, the dispatch and payment of products and services, or contract negotiations.
Insofar as you are not a contractual partner yourself – for example an employee of a business partner – the processing takes place for the same purposes as a legitimate interest pursuant to Art. 6(1)(1)(f) GDPR. We are then in the process of initiating or performing a contractual relationship with your employer or principal in the course of our business activities. On account of your work for your employer or principal, we process your personal data for this purpose.
Furthermore, insofar as necessary, we process personal data to fulfil legal requirements (Art. 6(1)(1)(c) GDPR) for the following purposes:
- fulfilment of statutory retention obligations
- fulfilment of statutory reporting obligations
In addition, we process personal data to safeguard the following legitimate interests (Art. 6(1)(1)(f) GDPR):
- maintaining the business relationship
- conducting training courses or other events
- asserting legal claims and defending against legal disputes
- inclusion in our contact database or maintaining contact following a business contact (e.g. if you provide us with your business card)
- direct marketing to customers or employees of customers (e.g. information about products and services)
- settlement of commissions with sales partners
Furthermore, we may process personal data for whose processing you have given us consent (Art. 6(1)(1)(a) GDPR). We obtain this separately and in the following cases:
- sending newsletters
- photo/video publications
Your rights
You have the following rights vis-à-vis us with regard to the personal data concerning you:
- right of access (Art. 15 GDPR),
- right to rectification or erasure (Art. 16, 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to object to processing that we carry out on the basis of legitimate interests (Art. 21 GDPR); see the further information at the end of this policy in this regard.
You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data by us.
Recipients of data
The personal data processed in connection with our business activities may be disclosed to the following categories of recipients:
- providers of services (e.g. IT services) which are engaged by us without exception as processors.
- service providers for telecommunications and logistics
- signature service providers for the digital signing (signature) of contracts
- authorities and other public bodies insofar as corresponding legal obligations exist
- credit reference agencies, financial service providers
- sales partners
Storage period
We process your personal data for as long as it is necessary for the purposes stated above. After the end of the business relationship, your data are stored for as long as we are legally obliged to do so. This arises from legal evidentiary and retention obligations, which are regulated, among others, in the German Commercial Code (HGB) and the Fiscal Code (AO). The storage period is up to ten years. In addition, it may be necessary for certain personal data to be retained for as long as claims can be asserted against us (limitation period of three to ten years, in rare cases up to thirty years)
Further information
There is no legal obligation to provide your data. However, it is not possible for us to initiate or perform a contractual relationship with you or your employer or principal without processing personal data.
Where applicable, the provision of your data is necessary for the performance of a contract. Please refer to the contractual documents that then exist for information on this.
Automated decision-making that produces legal effects concerning you or similarly significantly affects you does not take place in connection with your use of this website.
Changes to this privacy policy
We reserve the right to adapt this privacy policy in accordance with the statutory data protection provisions. The respective current version applicable is available for you to view in the legal notice/data protection section of our website.
Information about your right to object under Art. 21 GDPR
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which we carry out on the basis of Art. 6(1)(1)(f) GDPR (data processing on the basis of a legitimate interest).
If you object, we will no longer process your personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
The objection can be made without any particular form and should, where possible, be directed to the contact details listed in the privacy policy or in the legal notice.