Data Protection Declaration of ELAFLEX HIBY GmbH & Co. KG for the use of the Product ID App

The protection of your personal data when using the Product ID app is very important to us. In the following, we wish to inform you about how, to what extent and to which purposes ELAFLEX HIBY GmbH & Co. KG processes your personal data. You can find this Data Protection Declaration on our website at any time at https://app.elaflex.de/dataprivacystatement.html and print it out. We reserve the right to amend the data protection declaration from time to time.

  1. Name and address of the controller pursuant to Article 4(7) of the General Data Protection Regulation

    The controller responsible for processing your personal data within the meaning of the EU General Data Protection Regulation (hereinafter the “GDPR”) is:

    ELAFLEX HIBY GmbH & Co. KG
    Schnackenburgallee 121
    22525 Hamburg
    Germany
    Tel.: +49 40 540 005 0
    E-mail: info@elaflex.de
    Website: http://www.elaflex.de/en/

  2. About data processing in general

    1. Scope of the processing of personal data

      In general, we only process your personal data to the extent necessary to provide a functional app and to provide our content and services. We regularly only process your personal data to the extent that the processing of your personal data is permitted by law or you have consented to the processing of your personal data.

      All data that you enter through the Product ID app and all other communication between the Product ID app saved on your terminal device are transmitted to us through a secure connection.

    2. Legal basis for the processing of personal data

      To the extent that we obtain your consent for the processing of your personal data, the legal basis for the processing is Article 6(1) lit. a GDPR. To the extent that the processing of your personal data is necessary for the performance of a contract with you, Article 6(1) lit. b GDPR serves as the legal basis. This also applies to processing operations required in order to take steps prior to entering into a contract. To the extent that the processing of your personal data is necessary for compliance with a legal obligation to which we are subject, Article 6(1) lit. c GDPR serves as the legal basis. If the processing of your personal data is necessary for the purposes of the legitimate interests pursued by our company or by a third party and your interests, fundamental rights and freedoms do not override the interests first mentioned above, the legal basis for the processing is Article 6(1) lit. f GDPR.

  3. What personal data do we collect and for what purposes do we use your personal data

    1. Personal data that are transmitted to the App Store when downloading the Product ID app

      When downloading the Product ID app, the required information is transmitted to the App Store, in particular the user name, e-mail address and customer number of your App Store account, and the time of the download of the Product ID app. We have no influence on this collection of data. We only process the data to the extent that this is required to download the Product ID app to your mobile device. The legal basis of the data processing by us is Article 6(1) lit. b GDPR. We delete the data as soon as they are no longer required for the purposes for which they were collected.

    2. Personal data that we collect when you register as a user

      In order to be able to use the Product ID app, you have to register as a user after you have downloaded the Product ID app. When you do so, we collect and store the following data:

      Your first and last name, the name, the legal form and the address of the company at which you are employed, your e-mail address and your telephone number, the e-mail address of our contact person at your company (the contact person at your company is hereinafter referred to as the “Coordinator”) and, where applicable, the Elaflex customer number of your company. You also select a password, which we store in an encrypted form.

      We collect and store the personal data that you enter so that we can check that you are authorised to use the Product ID app. The collection and storage of said personal data also serve to assign your user account to you alone, and to enable you to register by entering your password and use the functions of the Product ID app in the login area. We use your e-mail address to be able to communicate with you within the framework of the performance of the contract about the use of the Product ID app. The legal basis for the data processing is Article 6(1) lit. b GDPR.

      We collect and store the e-mail address of your Coordinator so that you can send information (such as maintenance reports and photos of the product in question) straight from the Product ID app by e-mail to your Coordinator. The legal basis of this data processing is Article 6(1) lit. f GDPR.

      We delete the data as soon as they are no longer required for the purpose for which they were collected. For data collected during your registration as a user, this is the case when the registration is revoked by means of a termination, and it is no longer necessary to store your personal data to meet contractual or statutory obligations.

    3. Personal data that we collect every time you access the Product ID app and every time you retrieve files stored in the Product ID app

      Every time you access the Product ID app installed on your mobile device, and every time you retrieve files stored in the Product ID app, we collect the following data, which are technically necessary in order for us to be able to offer you the functions of the Product ID app, to keep it serviced and to improve the Product ID app, to be able to eliminate possible system errors and to clarify abusive activities (e.g. hacker attacks) and protect the system against such activities:

      • your IP address,
      • date and time of the retrieval of a file stored in the Product ID app,
      • the user data entered for authentication,
      • the access status/HTTP status code,
      • the operating system used (iOS and Android version, version number of the Product ID app, Bundle ID of the Product ID app),
      • crash reports of the system,
      • the data of the user agent (i.e., name and version of the program used, name and version of the operating system of your mobile device, name and version of the browser),
      • location data,
      • mobile telephone number.

      The legal basis for the data processing is Article 6(1) lit. f GDPR.

      We delete the data as soon as they are no longer required for the purpose for which they were collected. In the case of the data of the user agent, this is after seven days.

    4. Personal data that we collect during your use of the Product ID app

      If you add and share information on one of our products when using the Product ID app, or enter and share free texts such as comments, the information you have entered (e.g. information about the installation or maintenance of a given product or about test or inspection results for a certain product) will be sent to our server and stored there. At the user's request, this can be done after a delay:

      • Save on the mobile device.
      • Send by e-mail.
      • Save and transmit the data to ELAFLEX.

      In addition to this, the following data are also sent automatically to our server and stored there: the user data entered for authentication, date and time of the information being entered, a notification of a successful retrieval, product information and location data. The data is collected and saved for the purpose of assigning all the information relevant to a certain product to that product (e.g., time and place of the installation), in order to enable a quicker and more efficient maintenance and/or repair of the product.

      The legal basis for the data processing is Article 6(1) lit. f GDPR.

      In order for you to be able to read out the data matrix code (DMC) attached to one of our products, and upload photos that you take of one of our products into the Product ID app and assign them to the product there, we need access to the camera and photos made by your mobile device. When you start using the Product ID app, we request your permission to use the camera and photos on your mobile device. If you do not give us that permission, you will not be able to use all the functions of the Product ID app. You can issue or revoke this consent at a later time in the settings of the operating system of your mobile device.

      The legal basis for the data processing is Article 6(1) lit. f GDPR.

      The data will be deleted as soon as they are no longer required for the purpose for which they were collected.

    5. Personal data that we collect for the purpose of sending a newsletter

      You can subscribe to a free newsletter. When you register to receive our newsletter, we collect your e-mail address. The collection of your e-mail address serves to enable us to send you our newsletter, as long as your subscription to our newsletter is active. We obtain your consent to the processing of your e-mail address for the purpose of sending the newsletter during the registration process.

      When you have declared consent, the legal basis for the processing of your e-mail address after your registration for our newsletter is Article 6(1) lit. a GDPR.

      You can revoke your consent at any time. There is a link for this purpose in every newsletter we send you.

      If you revoke your consent, your subscription to the newsletter will be deactivated and we will no longer use your e-mail address for the purpose of sending you our newsletter.

  4. Integration of “Google Maps” in the context of your use of the Product ID app

    In the Product ID app, we use the component “Google Maps” of Google LLC, Amphitheatre Parkway, Mountain View, CA 94043, United States of America (hereinafter “Google”), in order to display geographic information, in particular your current location, in text form, in order to make it easier to enter the location data of the products.

    If you do not agree to your personal data being processed in this way, then you have the option of deactivating the “Google Maps” service, thus preventing data being transmitted to Google. To do so, you have to deactivate the Java Script function in your browser. We must point out, however, that if you do this, you will not be able to use the functions of the Product ID app or you will only be able to use them in a limited way.

    You can obtain further information on the purpose and scope of the collection and processing of your data by Google in Google's privacy policy. There you can also obtain further information on your rights and setting options for protecting your privacy:
    https://policies.google.com/privacy?hl=en.

    Google processes your personal data in the United States of America and is subject to the EU-US Privacy Shield:
    https://www.privacyshield.gov/EU-US-Framework.

    The use of “Google Maps” and information obtained through “Google Maps” shall be in accordance with the Google Terms of Service
    https://policies.google.com/terms?hl=en&gl=at

    and the Google Maps Additional Terms of Service:
    https://www.google.com/intl/en-US_US/help/terms_maps.html.

  5. Your rights

    When we process personal data from you, you are a data subject within the meaning of the GDPR and have the following rights with regard to us:

    1. Right of access pursuant to Article 15 GDPR

      You can request a confirmation from us as to whether or not we process personal data concerning you.

      If such processing takes place, you can demand from us access to the following information:

      • the purposes for which the personal data are processed,
      • the categories of personal data concerned,
      • the recipients and/or categories of recipients to whom the personal data concerning you have been or will be disclosed,
      • the criteria for determining the period for which your personal data will be stored,
      • the existence of the right to request from us rectification or erasure of your personal data or restriction of processing of personal data concerning you or to object to such processing,
      • the right to lodge a complaint with a supervisory authority.
    2. Right to rectification pursuant to Article 16 GDPR

      You have a right vis-à-vis us to rectify and/or complete your personal data, to the extent that the personal data processed by us concerning you are inaccurate or incomplete.

    3. Right to restriction of processing pursuant to Article 18 GDPR

      You can request that we restrict the processing of the personal data concerning you if

      • you contest the accuracy of the personal data concerning you, for a period enabling us to verify the accuracy of the personal data,
      • the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead,
      • we no longer need the personal data concerning you for the purpose of the processing, but you require them for the establishment, exercise or defence of legal claims, or
      • you have objected to processing pursuant to Article 21(1) GDPR and it has not yet been verified whether the legitimate grounds of the controller override your grounds.
    4. Right to erasure pursuant to Article 17 GDPR

      You can request that we erase the personal data concerning you without undue delay, and we have the obligation to erase personal data concerning you without undue delay where one of the following grounds applies:

      • The personal data concerning you are no longer necessary in relation to the purpose for which they were collected or otherwise processed.
      • You withdraw your consent on which the processing was based according to Article 6(1) lit. a GDPR, and where there is no other legal ground for the processing.
      • You object to the processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21(2) GDPR.
      • The personal data concerning you have been unlawfully processed.
      • The personal data concerning you have to be erased for compliance with a legal obligation in Union or Member State law to which we are subject.

      There shall be no right to erasure to the extent that processing is necessary

      • for exercising the right of freedom of expression and information,
      • for compliance with a legal obligation which requires processing by Union or Member State law to which we are subject,
      • for the establishment, exercise or defence of legal claims.
    5. Right to data portability pursuant to Article 20 GDPR

      You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format. You have the right to transmit those data to another controller without our hindrance, where

      • the processing is based on a consent pursuant to Article 6(1) lit. a GDPR or on a contract pursuant to Article 6(1) lit. b GDPR, and
      • the processing is carried out by automated means.

      In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another, where technically feasible.

      Freedoms and rights of other persons must not be impeded by the exercising of the right to data portability.

    6. Right to object pursuant to Article 21 GDPR

      You have the right to object, on grounds relating to your particular situation, at any time to processing of the personal data concerning you which is based on Article 6(1) lit. e or lit. f GDPR.

      If you have objected, we shall no longer process the personal data concerning you, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.

      Where personal data concerning you are processed for direct marketing purposes, you shall have the right to object at any time to processing of personal data concerning you for such marketing. This shall also apply to profiling, to the extent that it is related to such direct marketing. Where you object to processing for direct marketing purposes, the personal data concerning you shall no longer be processed for such purpose.

    7. Right to withdraw a declaration of consent pursuant to Article 7(3) GDPR

      You shall have the right to withdraw a declaration of consent at any time by sending an e-mail to info@elaflex.de. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

    8. Right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR

      Without prejudice to any other administrative or judicial remedy, you shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.


As of: 26 April 2018