69 vehicles available

Privacy policy...

...autogems

 


Privacy policy - English translation for information only

Important: This English text is a translation of the German privacy policy. The German original remains legally authoritative. This page is not a legally certified translation.

A. General information
I. Purpose of this privacy policy and our contact details

The purpose of this privacy policy of Auto Gems (also the "controller" within the meaning of the General Data Protection Regulation, EU Regulation 2016/679 of 27 April 2016, "GDPR") is to explain to data subjects, in a transparent, simple and understandable way:

  • which data we collect, and how and why we collect it;
  • how we handle your data, including where third parties are involved;
  • which situations are covered by the GDPR;
  • which rights and opportunities to participate you have in relation to your data and its use; and
  • which rights we have and how these may affect your rights.

Our contact details are:

Auto Gems
Langenbergerstraße 3
40233 Düsseldorf
Owner: Stefan Gems
info@autogems.de
Website: www.auto-gems.com
Telephone: +49 (0) 211 7377 59-0

II. Data protection terminology

Data protection law and data protection applications sometimes use terms that are not self-explanatory. The definitions in section B explain several of the terms used most frequently in this policy.

III. Our approach to data protection

Data protection is important to us. The principles set out by the GDPR are also our principles when handling your data. We observe purpose limitation and data minimisation and normally request only the minimum data needed to conduct our business or customer relationship with due commercial care and to provide good service. Access to personal data is limited, in principle, to employees who need it for their assigned duties. We store data only for as long as it is needed for these purposes, unless a longer statutory retention period applies. Technical and organisational measures, including up-to-date systems, appropriate safeguards, encryption where appropriate and, if necessary, specialised external companies, are used to maintain a high level of security, prevent unauthorised access and make data recoverable. We also aim to process accurate data and welcome information that helps us update it.

IV. Legal bases

We process data primarily on the basis of the GDPR, the German Federal Data Protection Act (BDSG) and other applicable European or national data protection provisions. Depending on the situation, a legal basis may be your effective consent under Article 6(1)(a) GDPR, the performance of a contract or pre-contractual measures, a legal obligation or our legitimate interests.

B. Definitions

Processor: an entity that processes personal data on behalf of another entity, in particular the controller, such as a data centre.

BDSG: the German Federal Data Protection Act, enacted on 30 June 2017 and applicable, like the GDPR, from 25 May 2018.

Legitimate interest: an interest that may support or oppose processing, depending on the perspective of the company or the natural person concerned. The assessment depends on which interest prevails in the particular situation, taking into account the type of data, the circumstances of collection, the purpose and the fundamental rights and freedoms of the data subject.

Data subject: the person whose data are the subject of a processing operation - here, you.

Browser: a computer program used to display websites, such as Microsoft Edge, Mozilla Firefox or Google Chrome.

Cookie: a small text file sent to and stored on your computer or other device by a visited website through your browser. It can allow a later visit to recognise settings such as the selected language or an earlier state.

Processing: any operation performed on data, whether automated or not, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, comparison, restriction, erasure or destruction.

GDPR: Regulation (EU) 2016/679 of the European Union, enacted on 27 April 2016 and applicable from 25 May 2018.

Last contact: where no contract has been concluded and we have not heard from you for more than three months. Any perceptible contact, for example by e-mail, letter or message, starts this three-month period again.

Personal data: any information relating to an identified or identifiable natural person, directly or indirectly, in particular by reference to a name, identification number, location data, online identifier or other identifying characteristics.

Special categories of personal data: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data used for identification, health data or data concerning sex life or sexual orientation.

Profiling: automated processing used to evaluate personal aspects of a natural person, in particular work performance, economic situation, health, preferences, interests, reliability, behaviour, location or movements.

Controller: the entity that determines, alone or jointly with others, the purposes and means of processing personal data - here, Auto Gems.

Whenever this policy refers to "data", it means personal data. European Union, EU and Union are used synonymously.

C. Scope and supervisory authority
I. Application regardless of nationality

The GDPR and the BDSG generally protect natural persons and their personal data. As a German company, we are subject to these rules. As a precaution and in the interests of data protection, we also treat legal entities like natural persons where the personal element behind the legal entity is affected. These requirements apply not only to German data subjects or residents of EU Member States, but to all persons in relation to whom we carry out or commission data-processing activities in the EU, regardless of nationality and even if the actual processing takes place outside the EU.

II. Competent supervisory authorities

Our registered office is in North Rhine-Westphalia. The primary supervisory authority is:

Land Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Kavalleriestr. 2-4, 40213 Düsseldorf
Telephone: 0211/38424-0
Fax: 0211/38424-10
E-mail: poststelle@ldi.nrw.de

Other German or foreign authorities may also have jurisdiction depending on the place and nature of the relevant activity.

D. Collection of data and purpose limitation
I. How data are collected

Collection is the first step of processing and is lawful only when the statutory requirements are met. In practice, collection or further processing may be based on:

  1. your consent, which may be express;
  2. the performance of a contract or pre-contractual measures requested by you;
  3. compliance with a legal obligation, such as a statutory retention obligation; or
  4. our legitimate interest, where it outweighs your interests, rights and freedoms in the individual case.
1. Collection from you

We normally collect the data relevant to our business directly from you, for example when you use our contact form, ask us about a product, provide information in order to receive an individual offer or make an offer to conclude a contract, or when a lawful business contact develops into a transaction. We generally regard these situations as involving at least implied consent or a request initiated by you. Consent is not tied to a particular form. Since we may have to prove that consent existed, we may subsequently ask you to confirm it formally, for example after a telephone call.

2. Collection from third parties

In exceptional cases we also collect data from third parties. Without your consent this is permitted only where we have a legitimate interest or a statutory exception applies. For example, where we have a substantial obligation to perform in advance, we may obtain a credit assessment from a provider such as Creditreform. We may also consult public registers and publicly available sources such as www.Bundesanzeiger.de. Such data are never used by us for automated decision-making; they only broaden the basis for our own decision. If we obtain data from third parties, we will normally inform you about the type and scope of the data within one month, unless a statutory exception applies, for example disproportionate effort.

3. Automated data collection

When you access our website, temporary data that may permit identification are stored, including the date and time of access, the internet service requested, the resource and action or query, the amount of data transferred, whether access was successful and the IP address of the accessing computer. These data are anonymised and used for statistical evaluation of website use and for preventing or analysing attacks. Cookies may also be used. We provide information about cookies on the website and request your consent where required. You can block cookies or request a warning in your browser settings, but this may restrict or slow down the website and may prevent settings such as language preferences from being retained. Cookies already set can be deleted through your browser.

Google Analytics

We use Google Analytics, a web analysis service of Google (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). It creates pseudonymised usage profiles and uses cookies. Information generated by a cookie about your use of this website, such as browser type and version, operating system, referrer URL, host name or IP address and the time of the server request, may be transferred to and stored on a Google server in the USA. Google evaluates this information to determine how the website is used and produces activity reports for market research. The data may be passed to third parties where permitted or required. Your IP address is anonymised and is not combined with other Google data. You can prevent cookies through your browser settings or prevent collection and processing by installing the Google browser add-on at tools.google.com/dlpage/gaoptout. On mobile devices you can use the Google Analytics opt-out option. If you delete cookies, the opt-out cookie must be set again. Further information is available in the Google Analytics help.

Google Ads conversion tracking

We also use Google conversion tracking to measure and improve website use. If you reach our website through a Google advertisement, Google Ads may place a cookie on your computer. It expires after 30 days and is not used for personal identification. If you visit a tagged page while the cookie is valid, Google and the advertiser can recognise that you clicked the advertisement. Each advertiser receives a different cookie, so cookies cannot be tracked across advertisers' websites. The information is used to create conversion statistics and does not identify individual users. You can refuse the cookie in your browser or block cookies from www.googleadservices.com. Further information is available at Google's conversion tracking information.

Google Maps

Our website embeds maps from Google Maps, a service of Google LLC, USA. In particular, IP addresses and location data may be processed. This does not take place without consent; on mobile devices it normally depends on the device settings. The data are processed in the USA. See Google's privacy policy and opt-out settings.

4. No collection of special categories

We do not collect special categories of personal data as defined above and do not obtain express consent for such data merely as a precaution.

II. Purpose limitation, scope of use and data categories
1. Main purposes

We collect data principally for the operational purposes of our business, in particular:

  • receiving and placing orders and processing them;
  • preparing estimates, quotations and similar offers;
  • drafting and performing contracts, including payment and shipping;
  • meeting statutory warranty obligations and exercising contractual guarantees or related claims against third parties;
  • pursuing and enforcing our claims, including in court, and defending claims against us; and
  • providing a high level of customer service and support.
2. Secondary purposes

Where permitted, data may also be used to determine customer satisfaction with our products, services and website, improve products and services, develop customised offers and provide support or goodwill beyond warranty periods. Additional rights may apply to these purposes, especially direct advertising.

3. Change of purpose

If we want to process data for a purpose different from the purpose for which it was collected and we do not have separate consent, we do so only where the new purpose is compatible with the original one. We assess the context of the original collection, the connection between the purposes, the sensitivity of the data, the consequences for you and safeguards such as encryption.

4. Types of data

The data we may collect and store include your name, address, date of birth, occupation or industry where relevant, contact details such as e-mail, telephone or fax, bank details where required, company information such as company figures, commercial register or tax numbers and management relationships, and information arising from the business relationship such as order history, payment behaviour, complaints, warranty claims and possible interest in further products.

E. Disclosure of data

We generally do not disclose data to third parties unless this is necessary for:

  • operational main or secondary purposes, including contracted subcontractors, forwarding agents or shippers;
  • coordination with external tax, business or legal advisers who are normally bound by professional confidentiality;
  • processing payments;
  • assessing the financial risk of a contemplated or incomplete transaction, including creditworthiness, liquidity and payment history; or
  • meeting public-law obligations, for example in response to a lawful request by an authority.
F. Processing by processors

We use processors. Guarantee agreements require these processors to comply with our data protection policy and the GDPR.

G. Retention of data

Under the storage limitation principle, we normally retain data only for as long as it is needed for the purposes for which it was processed. If no business relationship develops after pre-contractual contact, and no liability situation or realistic prospect of a later transaction exists, the operational reason for retention ends at the latest when possible claims have become time-barred. Statutory obligations, in particular under commercial and tax law, may require longer retention. For example, business letters received or sent may have to be retained for six years. This can postpone or limit a right to erasure.

  1. Where no contract is concluded, no contract is expected, no liability situation exists and no business letters were exchanged: two years from last contact, beginning at the end of the year of last contact.
  2. Where no contract is concluded or expected, no business letters were exchanged, but a liability situation cannot be ruled out: three years from last contact, beginning at the end of the year of last contact.
  3. Where a contract exists or business letters were exchanged: six years from receipt or dispatch of the business letter. If the last contact would result in a later expiry, the later date applies for the relevant data.
  4. Where accounting records, consolidated business documentation or customs documents are involved: ten years from the accounting date, the date of the documentation or the transmission to the customs authorities. If last contact would result in a later expiry, the later date applies for the relevant data.
H. Your rights as a data subject
I. General information

This section is not an exhaustive list of all rights. The GDPR and other applicable laws supplement it. You do not need a particular form to exercise your rights; a telephone call or e-mail is sufficient.

We will respond without undue delay and normally within one month. For complex requests or a large number of requests, the period may be extended by up to two further months; we will inform you of the extension within the first month. If we do not act, we will give reasons within one month. Information and measures required to exercise your rights are free of charge. For manifestly unfounded or excessive requests, especially because of their number, we may charge a reasonable administrative fee or refuse to act.

All rights described below, except the right to complain to a supervisory authority, should be addressed to:

Auto Gems, Langenbergerstraße 3, 40233 Düsseldorf, Owner: Stefan Gems, info@autogems.de, telephone +49 (0) 211 7377 59-0.

II. Right of access

You may ask whether we process personal data about you. If so, you may request information about the categories and purposes of processing, recipients and appropriate safeguards for transfers, the planned retention period or its criteria, the source of data obtained from third parties and meaningful information about system logic and the expected effects of any automated decision-making. We do not currently use such automated decision-making. We will provide a copy, electronically where the request is electronic; a reasonable fee may be charged for additional copies.

III. Withdrawal of consent

You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. After withdrawal we must stop processing if the consent was the only legal basis, unless another obligation, such as retention, applies. Withdrawal is informal and may be made in the same way as consent was given.

IV. Right to rectification

You may require the immediate correction of inaccurate personal data and completion of incomplete data, including by means of a supplementary statement. Where data were disclosed to third parties, we will inform them of the correction where this is not impossible or disproportionate and will name those recipients on request.

V. Right to erasure ("right to be forgotten")

Subject to the exceptions below, you may require us to erase your personal data without undue delay where the data are no longer necessary, consent has been withdrawn, you object to processing, processing was unlawful, erasure is required by Union or national law, or the data were collected from a child under 16 in relation to information-society services. If we have made the data public, we will take reasonable measures, taking account of available technology and implementation costs, to inform other controllers that you requested erasure of the data and copies or links to it. If data were disclosed to third parties, we will inform them where this is not impossible or disproportionate.

Erasure may be refused, in particular where processing is necessary for freedom of expression and information, compliance with a legal obligation, the establishment, exercise or defence of legal claims, where another legal basis remains after withdrawal of consent, or where compelling legitimate grounds override an objection. An objection directed only at direct advertising or related profiling always gives rise to an erasure right. If erasure is not available, you may still have a right to restriction.

VI. Right to restriction of processing

You may request restriction instead of erasure where processing is unlawful, where we no longer need the data but you need them for legal claims, or while we examine an objection or a challenge to accuracy. Restricted data may generally be processed only with your consent, for legal claims, to protect another person's rights or for an important public interest. We may also restrict use after three years plus the remainder of the year in which last contact took place. We will inform you before lifting a restriction and, where possible, notify recipients.

VII. Right to data portability

Where processing is based on consent or a contract and is automated, you may request the data you provided in a structured, commonly used and machine-readable format. Where technically feasible and where the rights of others are not affected, you may request direct transmission to another controller.

VIII. Notification in the event of a data breach

If a personal-data breach is likely to create a high risk to your rights and freedoms, we will notify you without undue delay, including the contact person, likely consequences and measures taken or planned. Notification may be unnecessary if effective measures have removed the high risk, if the data were already protected against unauthorised access, or if notification would require disproportionate effort, in which case a public notice or similar measure may be used.

IX. No decision based solely on automated processing

In principle, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you. We do not currently use such decision-making structures and would inform you separately if this changes.

X. Right to lodge a complaint

You may complain at any time to the competent supervisory authority named in section C. You may also contact us so that we can try to resolve the issue together.

XI. Right to object

Where we process data to protect our legitimate interests or to perform a task in the public interest, you may object at any time. We may continue only if we demonstrate compelling grounds that override your interests, rights and freedoms, or if processing serves legal claims. If you object to direct advertising or related profiling, we will stop using your data for those purposes. You may send an objection in any form.

I. Data protection officer

Auto Gems has not appointed a separate data protection officer. You may contact any department of the company with data protection questions.

J. Changes to this privacy policy

This privacy policy may be changed from time to time, for example to reflect developments in data protection law and case law. We will publish changes on our website. Particularly serious changes may also be communicated individually, normally by e-mail, to customers, users, suppliers and other affected persons for whom we still have contact details.

K. National particularities

Our business activities extend to Germany. If the national law of another EU or EEA country, except Switzerland, requires a higher data-protection standard for activities affecting that country than the GDPR, please inform us promptly about the nature and scope of that requirement so that we can meet it as well.

German privacy policy (legally authoritative original)