Privacy notice for business partners, suppliers, and communication partners

In the context of the business relationship between you and a company belonging to the SIEMPELKAMP Group of companies, personal data relating to you is collected. This collection may take place directly from you or through information provided by third parties. With the following information, we would like to give you an overview of the processing activities that take place and your rights:

Who is responsible for data processing and who can I contact?

The sole controller within the meaning of the GDPR is the respective company of the group of companies with which you are in contact and which processes your data.

To the companies

Contact details of the data protection officer

G. Siempelkamp GmbH & Co. KG
Group Data Protection Officer
Siempelkampstr. 75
47803 Krefeld

Mr. Niklas Koenig
Email: datenschutz@siempelkamp.com

If you have any questions about ongoing processing activities, complaints about ongoing processing, or for the exercise of data subject rights, please contact the data protection officer directly and exclusively.

Rights of data subjects

Subject to the conditions of the statutory provisions of the General Data Protection Regulation (GDPR), you as a data subject have the following rights:

Processing in the context of establishing contact and communication

Nature and scope of processing

When you contact or communicate with us, we collect data in order to be able to assign and process your inquiry. In doing so, we collect only the personal data necessary to answer your inquiry, such as:

  • Basic personal data (form of address, title, first and last names)
  • Communication data (telephone, fax, or email address)
  • Product interest
  • Information from your inquiry

The provision of additional personal data such as mobile phone numbers, addresses, etc. is voluntary and is used for the purpose of facilitating contact. There are no negative consequences associated with not providing this data. However, failure to provide it may make communication more difficult or cause delays.

Alternatively, you can contact us via the email addresses provided. In this case, the personal data of the users transmitted with the email will be stored.

Purpose and legal basis

When contact or communication is made and in the further handling, the information provided by users is processed for the purpose of handling the inquiry and its processing on the basis of Article 6(1)(b) GDPR.

If we contact you, we process the data on the basis of our legitimate interest pursuant to Article 6(1)(f) GDPR or Section 7(3) of the German Unfair Competition Act (UWG). You may object to this processing at any time.

Storage period

The data will be erased as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data transmitted by email, this is the case when the respective conversation with the users has been finally concluded. The conversation is deemed to be concluded when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

If contact is made in connection with the conclusion of a contract, data may be stored until claims against the controller become time-barred or if the documents no longer have to be retained due to statutory obligations.

Processing of data in video conferences

Nature and scope of processing

When using video conference tools, we process different types of personal data that are collected by the respective video conference provider to provide the service. The following data, among others, is processed:

  • Information about users (user name, email address)
  • Meeting metadata (IP address, ISP information, electronic ID, subject or description)
  • Dial-in information using telephones (phone number, country designation, start and end time)

Optional information includes:

  • Information about users (image and sound, profile picture)
  • Other (shared screen contents, camera position, information about the immediate surroundings)
  • Optional recordings (MP4 file of all video, audio, and presentation recordings; M4A file of all audio recordings; text file of the online meeting chat)

You may have the option of using the chat, question, or survey functions in an “online meeting.” In this respect, the text entries you make are processed in order to display them in the “online meeting” and, where applicable, to log them. To enable the display of video and the playback of audio, data from the microphone of your end device and from any video camera of the end device will be processed for the duration of the meeting. You can switch off or mute the camera or microphone yourself at any time via the applications.

To participate in an “online meeting” or to enter the “meeting room,” you must at least provide your name.

Purpose and legal basis

Insofar as personal data of employees of the group companies is processed, Article 6(1)(b) GDPR is the legal basis for data processing. If, in connection with the use of services, personal data is not required for the establishment, implementation, or termination of the employment relationship, but is nevertheless an essential component in the use of services, Article 6(1)(f) GDPR is the legal basis for data processing. In these cases, our interest lies in the effective implementation of “online meetings.”

Otherwise, the legal basis for data processing in the implementation of “online meetings” is Article 6(1)(b) GDPR, insofar as the meetings are conducted within the framework of contractual relationships.

If no contractual relationship exists, the legal basis is Article 6(1)(f) GDPR. Here, too, our interest lies in the effective implementation of “online meetings.”

If data is processed in the context of online meetings outside the EU or the EEA, the transfer will take place exclusively to such service providers that have implemented measures within the framework of Article 46 GDPR.

Storage period

We store the data only as long as it is required for the respective purpose.

As part of the technical and organizational measures implemented, we have configured the storage periods so that the processed data is erased after a maximum of 12 months.

If we process your data for the performance of contracts, we store part of this data for as long as it is required for the performance of the contracts.

Transfer of data to group companies

Nature and scope of processing

To provide our services and to handle contracts, we may engage group companies of the SIEMPELKAMP Group to perform these services. The following information may be transferred in this context:

  • Company information
  • Basic personal data (form of address, title, first and last name)
  • Communication information (telephone or email address)
  • Contract information (project periods or service overviews)

Purpose and legal basis

For the handling of contracts, we process the data on the basis of Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.

The transfer takes place for the performance of planning, production, or delivery services.

You may object at any time, without stating reasons, to processing based on Article 6(1)(f) GDPR.

Storage period

We store the data for as long as it is required to preserve, enforce, or defend claims. Depending on the scope of the project, storage for up to 30 years is possible.

Transfer of data to public authorities and government agencies

Nature and scope of processing

We process personal data that we receive from our customers and business partners in the course of our business relationship. In addition, we process personal data that we lawfully obtain from publicly accessible sources (e.g., commercial and association registers, press, internet), insofar as this is necessary for the provision of our services, or that is lawfully transmitted to us by other companies or public authorities.

The transfer of data to public authorities and government agencies takes place exclusively within the framework of statutory provisions. Depending on the context, the data processed may include:

  • Basic personal data (e.g., name, address, date of birth)
  • Communication data (e.g., telephone number, email address)
  • Financial data (e.g., account number, tax information)
  • Other categories required by law

The data is transmitted in electronic form and may be stored in the databases of the public authorities and government agencies.

Purpose and legal basis

The processing of your personal data is carried out on the basis of the statutory provisions of the GDPR and the German Federal Data Protection Act (BDSG). The transfer of data to public authorities and government agencies is primarily for the purpose of complying with a legal obligation pursuant to Article 6(1)(c) GDPR in conjunction with the respective national laws or on the basis of a legitimate interest pursuant to Article 6(1)(f) GDPR. A legitimate interest may be, for example, the detection of criminal offenses, the assurance of network and information security, or the enforcement of legal claims.

Storage period

The storage period for personal data is determined by the statutory retention periods. After these periods have expired, the corresponding data is routinely erased, provided that it is no longer required for the performance or initiation of a contract and/or we no longer have a legitimate interest in further storage.

Carrying out creditworthiness and credit checks

Nature and scope of processing

To check creditworthiness and credit standing, we transmit company information to credit agencies or request information from them before concluding a contract with customers.

In this context, we transmit or receive basic company information:

  • Company information
  • Period
  • Project information
  • Creditworthiness and credit limits
  • Rating by the credit agency

Purpose and legal basis

Depending on the scope of the project, we process your data on the basis of our legitimate economic interest pursuant to Article 6(1)(f) GDPR or, in individual cases, on the basis of Article 6(1)(b) GDPR for the performance of contractual or pre-contractual measures.

Storage period

We retain this information for up to 3 years/months to safeguard our legitimate economic interests.

Carrying out sanctions list screenings

Nature and scope of processing

In the context of mandatory sanctions list screenings, we process personal data that is required to verify the identity of individuals or companies and to determine whether they are listed on sanctions lists. The data processed may include:

  • Basic personal data (form of address, title, first and last name)
  • Identification characteristics (date of birth, place of birth, nationality)
  • Affiliations or geographical information (addresses, company names, and, where applicable, further identification data)

The data may originate from internal sources, such as customer or supplier databases, or from external sources, such as publicly accessible sanctions lists.

Purpose and legal basis

The purpose of processing personal data in the context of sanctions list screenings is to ensure compliance with legal obligations aimed at preventing or terminating business relationships with sanctioned individuals or companies.

The legal basis for processing is compliance with a legal obligation pursuant to Article 6(1)(c) GDPR in conjunction with the relevant sanctions laws and regulations, and, where applicable, the safeguarding of legitimate interests pursuant to Article 6(1)(f) GDPR, such as the interest in preventing legal violations and safeguarding the company’s reputation.

Storage period

The storage period for personal data in the context of sanctions list screenings is determined by the statutory retention periods and the requirements for documenting compliance with sanctions regulations. After the statutory retention periods have expired, the data is routinely erased, provided that no further legal obligations or legitimate interests require continued storage.

Processing in the context of the establishment, exercise, or defense of legal claims

Nature and scope of processing

In the context of the establishment, exercise, and defense of legal claims, we process personal data that is required for the assessment and enforcement of legal claims. The data processed may include:

  • Basic personal data (form of address, title, first and last name)
  • Communication data (email address, telephone number, contact details)
  • Other data (contract data, documentation of facts, financial data, and other data relevant for legal assessment)

The data may originate from internal sources, such as customer or employee databases, or from external sources, such as court files or correspondence with attorneys.

Purpose and legal basis

The purpose of processing personal data in the context of the establishment, exercise, and defense of legal claims is to safeguard and enforce the legal interests of the company or the data subject.

The legal basis for processing is the safeguarding of legitimate interests pursuant to Article 6(1)(f) GDPR. The legitimate interest lies in the establishment, exercise, or defense of legal claims. In certain cases, processing may also be necessary for compliance with a legal obligation pursuant to Article 6(1)(c) GDPR.

Storage period

The storage period for personal data in the context of the establishment, exercise, and defense of legal claims is determined by the statutory retention periods and the requirements for documenting legal proceedings. After the statutory retention periods have expired, the data is routinely erased, provided that no further legal obligations or legitimate interests require continued storage.

Processing for self-registration and participation in tenders

Nature and scope of processing

To conduct and handle tenders, we use the SynerTrade tendering platform. For participation in the tendering procedure, we collect the following data from you:

  • Basic personal data (form of address, title, first and last name)
  • Communication data (e.g., telephone, email)
  • Basic contract data (contractual relationship, product or contract interest)
  • Supplier history
  • Planning and control data
  • Information from third parties (e.g., credit agencies or public registers)
  • Basic product and supplier data

The data you provide is submitted voluntarily, taking into account the privacy notice.

Purpose and legal basis

The purpose of processing is to register your company for participation in and handling of tenders, as well as to handle any contractual relationships arising from them.

The legal basis for registration is the consent you voluntarily give pursuant to Article 6(1)(a) GDPR.

Further legal bases, such as the performance of contractual and pre-contractual measures, are provided by Article 6(1)(b) GDPR.

Storage period

We store your data until the purpose has been fulfilled.

If the tender results in a contractual relationship, we store your data for tax reasons for at least 10 years (Section 257(4) of the German Commercial Code (HGB)).

Reservation of processing due to system or process adjustments (e.g., anonymization, erasure, system change)

Nature and scope of processing

In the context of system or process adjustments, we process personal data that is required for the adjustment, improvement, or maintenance of our systems and processes. The data processed may include:

  • Basic personal data (form of address, title, first and last name)
  • Communication data (email address, telephone number, contact details)
  • Other information (user account data, contract data, technical data, and other data stored in the systems and processes)

The data may originate from internal systems and databases and may be modified, anonymized, erased, or transferred to a new system in the course of the adjustments.

Purpose and legal basis

The purpose of processing personal data in the context of system or process adjustments is to ensure and improve the efficiency, security, and compliance of our systems and processes.

The legal basis for processing may be compliance with a legal obligation pursuant to Article 6(1)(c) GDPR if the adjustments are required to comply with legal requirements. Alternatively, processing may be based on the safeguarding of legitimate interests pursuant to Article 6(1)(f) GDPR if the adjustments are necessary to improve systems and processes.

Storage period

The storage period for personal data in the context of system or process adjustments is determined by the requirements of the adjustment process and the statutory retention periods. Data that is no longer required for the adjustment is erased or anonymized. Data transferred to a new system is subject to the storage periods applicable to the underlying main processing.

Identity verification and data reconciliation by Dun & Bradstreet GmbH

Nature and scope of processing

Dun & Bradstreet (Dun & Bradstreet Deutschland GmbH, Robert-Bosch-Straße 11, 64293 Darmstadt) independently collects and compiles company data and prepares it with an independent unique ID (D&B D-U-N-S® number).

To ensure the accuracy of information and for identity verification, we transmit data of suppliers and service providers to Dun & Bradstreet and reconcile it with the information provided by Dun & Bradstreet. In this process, we supplement the data records of suppliers or service providers with the unique D&B D-U-N-S® number.

Purpose and legal basis

To continuously ensure the accuracy of data, we process company information for the performance of contractual measures (Article 6(1)(b) GDPR) and to safeguard our legitimate economic interests (Article 6(1)(f) GDPR).

We have concluded an agreement on data processing with Dun & Bradstreet Deutschland GmbH.

Storage period

Information that we transmit to Dun & Bradstreet Deutschland GmbH is stored only until the purpose has been fulfilled. Information received from Dun & Bradstreet Deutschland GmbH (e.g., changes of addresses, D&B D-U-N-S® number, or information about companies) is stored until the contractual obligations have been fulfilled or the purpose for which it was collected has been achieved.

Information on data processing by Dun & Bradstreet Deutschland GmbH can be found here: https://www.dnb.com/de-de/datenschutz/

Carrying out AI-supported supplier searches

Nature and scope of processing

We use artificial intelligence (AI) to support our supplier searches. For this purpose, relevant information about potential suppliers is processed. This may include, among other things, the following:

  • Name of the company
  • Contact details (address, telephone number, email address)
  • Type of company
  • Product range
  • Price information
  • Historical order information
  • Other relevant information for assessing the suitability of the supplier

The AI performs an automatic analysis of this data in order to identify and evaluate potential suppliers on the basis of predefined criteria.

Purpose and legal basis

The purpose of this processing is to improve our supplier search and selection in order to make more efficient and effective business decisions. The legal basis for this is Article 6(1)(f) GDPR, namely that processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.

Storage period

The personal data of potential suppliers is stored for as long as is necessary to achieve the above-mentioned purpose. As a rule, this data is reviewed after completion of the supplier selection process and erased if it is no longer required. In the event of a positive selection process, the data is stored in accordance with the statutory retention periods.