Privacy Policy
This privacy policy is a translation of the German original. In the event of any discrepancy, the German version shall prevail.
1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. For detailed information on data protection, please refer to our privacy policy set out below this text.
Data collection on this website
Who is responsible for data collection on this website? Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the section “Information on the controller” in this privacy policy.
How do we collect your data? On the one hand, your data is collected when you provide it to us. This may, for example, be data that you enter in a contact form or send to us by email. Other data is collected by our IT systems automatically or after you have given your consent when you visit the website. This is mainly technical data (e.g. web browser, operating system or time of page access). This data is collected automatically as soon as you enter this website.
What do we use your data for? Part of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data? You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the rectification or erasure of this data. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. In addition, you have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. You can contact us at any time regarding this and any other questions on the subject of data protection.
2. Hosting
We host the content of our website with an external service provider.
External hosting (Mittwald)
The provider is Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp (hereinafter “Mittwald”). When you visit our website, Mittwald collects various log files, including your IP addresses. For details, please refer to Mittwald’s privacy policy: https://www.mittwald.de/datenschutz.
Mittwald is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. If corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG (German Telecommunications and Digital Services Data Protection Act), insofar as the consent covers the storage of cookies or access to information on the user’s device. Consent can be withdrawn at any time.
Processing on our behalf: We have concluded a data processing agreement (DPA) with Mittwald. This ensures that Mittwald processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Content delivery network and protection against attacks (Cloudflare)
The Cloudflare service is placed in front of our hosting. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”). All requests to this website and its subdomains (addresses beginning with “map.”, “intern.” and “cdn.”) are routed through Cloudflare’s global server network (reverse proxy and content delivery network). Cloudflare delivers our content quickly and protects the website against attacks, for example overload attacks (DDoS) and malicious bots. In doing so, Cloudflare processes in particular your IP address, the date and time of access, the requested address (URL), browser type and browser version (user agent) and technical connection data, and records these in technical logs (log files). Since every request passes through Cloudflare, content that you send to us (e.g. entries in the contact form) also reaches our server via Cloudflare. Cloudflare stores the log data only for as long as is necessary for these purposes or due to legal obligations. For details, please refer to Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/.
When our login page is accessed and when Cloudflare classifies a request as suspicious, Cloudflare shows a brief security check. After the check has been passed, Cloudflare sets a technically necessary cookie (“cf_clearance”, valid for 30 minutes) so that the check does not reappear on every request. During the check itself, short-lived cookies whose names begin with “cf_chl_” may also be set. The legal basis is Art. 6(1)(f) GDPR in conjunction with Section 25(2) No. 2 TDDDG (German Telecommunications and Digital Services Data Protection Act).
Cloudflare is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in providing our website securely, quickly and reliably and in protecting it against attacks. Insofar as personal data is transferred to the USA, the transfer is based on the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR. Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework. In addition, Cloudflare’s data processing agreement contains the standard contractual clauses of the European Commission.
Processing on our behalf: Cloudflare is used via our service provider heinmedia, which looks after our website on our behalf and manages the Cloudflare account (processing on our behalf pursuant to Art. 28 GDPR). Cloudflare is involved as a further processor (sub-processor); this is based on Cloudflare’s data processing agreement (Data Processing Addendum).
3. General information and mandatory information
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. Please note that data transmission over the internet (e.g. when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.
Information on the controller
The controller responsible for data processing on this website is:
Wendler Einlagen GmbH & Co. KG Markwiesenstraße 40 72770 Reutlingen
Represented by its personally liable general partner, Wendler-Einlagen GmbH, which in turn is represented by its managing directors Dr. Gerhart Wendler and Frank Sailer.
Phone: +49 7121 51060 Fax: +49 7121 5106400 Email: [email protected]
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Data protection officer
Ms Ulrike Eben
Rübäcker 9
72488 Sigmaringen, Germany
Phone: +49 151 176 409 68
Email: [email protected]
Storage period
Unless a more specific storage period has been stated in this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a justified request for erasure or withdraw your consent to data processing, your data will be erased unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, erasure will take place once these reasons cease to apply.
General information on the legal bases for data processing
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR. In the case of explicit consent to the transfer of personal data to third countries, data processing is also based on Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device, data processing is additionally based on Section 25(1) TDDDG. The other legal bases are Art. 6(1)(b), (c) and (f) GDPR.
Recipients of personal data
In the course of our business activities, we work with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only pass on personal data to external parties if this is necessary for the performance of a contract, if we are legally obliged to do so, if we have a legitimate interest in the disclosure or if another legal basis permits the disclosure of the data. When using processors, we only pass on personal data of our customers on the basis of a valid data processing agreement.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out until the withdrawal remains unaffected by the withdrawal.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
Access, rectification and erasure
Within the framework of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to rectification or erasure of this data. You can contact us at any time regarding this and any other questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the cases set out in Art. 18(1) GDPR.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as requests that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the lock symbol in your browser bar. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Objection to promotional emails
We hereby object to the use of contact details published as part of our obligation to provide an imprint for the purpose of sending advertising and information material that has not been expressly requested. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, for example by spam emails.
4. Data collection on this website
Cookies
Our website uses so-called “cookies”. Cookies are small data packets and do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.
Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested (e.g. to store the selected language) or to optimise the website (e.g. cookies to ensure technical delivery) (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is stated. If consent to the storage of cookies and similar recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); consent can be withdrawn at any time.
You can find out which cookies and services are used on this website in this privacy policy and in our Cookie Policy. There you can also give or withdraw your consent for each service individually.
To display pop-ups, such as our contact form, our page builder Elementor stores a counter for page views and sessions in your browser’s storage (localStorage “elementor”). This information does not leave your device.
Consent with the consent tool “Complianz”
Our website uses consent technology from Complianz to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies and to document this in compliance with data protection law. The provider of this technology is Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, Netherlands (hereinafter “Complianz”).
When you enter our website, the following personal data is processed: your consent(s) or the withdrawal of your consent(s), your IP address, information about your browser and your device, and the time of your visit to the website. The information collected by Complianz is stored until you ask us to delete it, you delete the consent record yourself or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected.
Complianz is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Art. 6(1)(c) GDPR.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources. This data is collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website; for this purpose, the server log files must be collected.
Contact form
If you send us requests via the contact form, we process the details you provide in the request form, including the contact details you give there, in order to handle your request and in case of follow-up questions.
This data is processed on the basis of Art. 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of requests addressed to us pursuant to Art. 6(1)(f) GDPR.
The data you enter in the contact form will remain with us until the purpose for storing the data no longer applies, you ask us to delete it or you validly object to processing on the basis of Art. 6(1)(f) GDPR. Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
The international phone input field in our form suggests the country code based on the language setting of your browser. No data is transmitted to third parties in the process; we load the necessary program files and flag graphics from our own server.
Protection against misuse of the contact form: When you submit the form, we briefly process your IP address in order to fend off automated mass requests. We do not store the IP address itself, only a check value generated with a secret key (for IPv6, from the network range) together with the number of requests. The entry expires ten minutes after the last request and is deleted at the latest during the daily automatic clean-up. In addition, the form contains a field that is invisible to humans; submissions in which this field has been filled in are discarded. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protection against spam and misuse.
Requests by email, phone or fax
If you contact us by email, phone or fax, your request, including all resulting personal data (name, request), will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of requests addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested.
Sending emails: We use an SMTP service provider to send emails (e.g. confirmations of form requests). Where required, a data processing agreement is in place with this service provider.
Local hosting of fonts (web fonts)
For the uniform display of fonts, this website uses font files hosted locally on our server. No connection to third-party servers (e.g. Google Fonts) is established; no data is transmitted to third parties when the fonts are displayed. The basis for this is our legitimate interest in a uniform and data-minimising presentation of our website (Art. 6(1)(f) GDPR).
Multilingual content (WPML)
We use the WordPress plugin WPML to provide our content in several languages. A technically necessary cookie (`wp-wpml_current_language`) is set to store the language you have selected. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in delivering the website in the correct language). No personal data is transmitted to third parties in this process.
5. Interactive map “Global Network” (WordPress + separate application)
On our website, we embed an interactive world map (“Global Network”) which shows our locations as well as our sales partners and contact persons. This map is implemented as a standalone application under its own subdomain (address beginning with “map.”) and is embedded in our WordPress website via an iFrame. When you access the page with the map, the application is loaded from this subdomain; technical access data (in particular your IP address) may be processed in the process.
Map display with Mapbox
To display the interactive map, we use the map service Mapbox. The provider is Mapbox, Inc., 1509 16th Street NW, Washington, D.C. 20036, USA.
To display the map tiles and map styles, your browser establishes a direct connection to Mapbox servers (including `api.mapbox.com`). In the process, your IP address is transmitted to Mapbox. In addition, Mapbox processes usage or telemetry data on map use via the endpoint `events.mapbox.com`. Mapbox is a US provider; your data may therefore be transferred to the USA.
Mapbox is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Insofar as personal data is transferred to the USA, the transfer is based on the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR. Mapbox, Inc. is certified under the EU-U.S. Data Privacy Framework. Consent can be withdrawn at any time with effect for the future. Further information can be found in the privacy policy of Mapbox: https://www.mapbox.com/legal/privacy.
The map is only loaded after you have given your consent. As long as you have not consented, only a placeholder is displayed at this point; no data is transmitted to Mapbox. Only once you actively enable the map is the application loaded and the connection to Mapbox established.
You give your consent in the cookie banner (category “Interactive map”), in our Cookie Policy or via the “Show map” button on the map. It also applies if you access the map application directly, and can be withdrawn there via “Cookie settings” and on every page via “Manage consent”. Mapbox stores a random identifier in your browser’s storage (localStorage “mapbox.eventData”).
6. Plugins and tools / external services (embedded after consent)
Embedded YouTube videos
Videos from the YouTube platform may be embedded on individual pages of our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The videos are embedded in such a way that no connection to the YouTube servers is initially established when you merely access the page. Data is only transmitted to YouTube once you actively start a video via the placeholder shown or give corresponding consent. YouTube then receives, among other things, the information that you have accessed the relevant page of our website, as well as your IP address. This happens regardless of whether YouTube provides a user account through which you are logged in. If you are logged in to Google, YouTube can assign your usage behaviour directly to your personal profile.
We embed YouTube in privacy-enhanced mode (youtube-nocookie.com); we load the video thumbnails from our own server. You give your consent in the cookie banner (category “Videos and marketing”), in our Cookie Policy or via “Load video” in the player.
YouTube is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Insofar as personal data is transferred to the USA, the transfer is based on the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR. Google LLC is certified under the EU-U.S. Data Privacy Framework. Consent can be withdrawn at any time with effect for the future.
Newsletter
If you subscribe to our newsletter, we use your email address to send you regular information about our company, our products and services. Registration takes place using the double opt-in procedure. Registration and confirmation are logged so that we can prove your consent.
Protection against misuse of the registration: The registration form is protected in the same way as the contact form (invisible field, check value instead of the IP address, legal basis Art. 6(1)(f) GDPR), except that the entry only expires one hour after the last registration attempt.
We use Brevo (formerly Sendinblue) to send and manage our newsletter. The data required for this, in particular your email address and details of your newsletter registration, is processed by Brevo on our behalf. The data processing agreement is part of the Brevo Terms of Service (Appendix 3: Data Processing Agreement).
The legal basis for sending the newsletter is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future via the unsubscribe link in every newsletter or by email to [email protected].
After you unsubscribe, you will be removed from the active newsletter mailing list. Data required to prove that consent was given may continue to be stored within the scope of the statutory requirements.
Further information can be found in the privacy policy of Brevo and in the Brevo Terms of Service.
7. Web analytics / audience measurement with Umami
This website uses the open-source web analytics service Umami for the statistical evaluation of visitor access. Umami is operated on our behalf by our service provider heinmedia on a server in Germany (processing on our behalf pursuant to Art. 28 GDPR); beyond this, no data is transmitted to third parties.
As configured by us, Umami does not use cookies to recognise individual visitors. IP addresses are not stored or are anonymised; only aggregated metrics (e.g. page views, referrers, approximate region of origin, device type, page load times) are collected.
Statistical audience measurement is based on our legitimate interest in a data-minimising analysis and optimisation of our online presence pursuant to Art. 6(1)(f) GDPR.
Session recording and heatmaps: For some visits, Umami may additionally record the course of the visit on the website (mouse movements, clicks, scrolling and content displayed) so that we can improve the usability of our website. Entries in form fields are already masked in your browser and are not transmitted. No cookies are set. The recordings are stored on a server in Germany and deleted as soon as they are no longer required for the evaluation.
Session recording only takes place after you have given your consent. The legal basis is Art. 6(1)(a) GDPR. Insofar as information is stored on or read from your device in the process, this is additionally based on Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via the cookie settings.
8. Applications / handling of applicant data
We offer you the opportunity to apply to us (e.g. by email). Below, we inform you about the scope, purpose and use of your personal data collected as part of the application process. We assure you that the collection, processing and use of your data will be carried out in accordance with applicable data protection law and all other statutory provisions and that your data will be treated in strict confidence.
Scope and purpose of data collection: If you send us an application, we process your associated personal data (e.g. contact and communication data, application documents, notes taken during job interviews, etc.) insofar as this is necessary to decide on establishing an employment relationship. The legal basis for this is Section 26 BDSG (German Federal Data Protection Act) under German law (initiation of an employment relationship), Art. 6(1)(b) GDPR (general initiation of a contract) and, if you have given your consent, Art. 6(1)(a) GDPR. Consent can be withdrawn at any time.
Data retention period: If we are unable to offer you a position, you decline a job offer or you withdraw your application, we reserve the right to store the data you have submitted on the basis of our legitimate interests (Art. 6(1)(f) GDPR) for up to 6 months after the end of the application procedure. The data will then be deleted and the physical application documents destroyed. The retention serves in particular as evidence in the event of a legal dispute. If it is evident that the data will be required after the period has expired (e.g. due to an impending or pending legal dispute), it will only be deleted when the purpose for further retention no longer applies.
9. Social media
Link to LinkedIn
On our website, we use a link to refer to our company profile on the social network LinkedIn. Simply including the link does not transmit any personal data to LinkedIn; data is only transmitted once you actively click the link and thereby access the LinkedIn pages. LinkedIn is then responsible for data processing after the click. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.