We are pleased by your interest in our website. Protecting your privacy is very important to us. In the following, we provide detailed information on how we treat your data.
A. Data controller in charge of the data processing
The data controller in charge of the processing of personal data associated with this Internet service for the purposes of the General Data Protection Regulation (GDPR) is:
NOMOS Glashütte/SA Roland Schwertner KG
Tel. +49 35053 404 0
Fax +49 35053 404 965
Our company’s Data Protection Officer is:
We have prepared this Data Protection Statement to inform you about the scope of processing your personal data (hereinafter "data").
B. Data processing
The operation of our Internet website entails the processing of data. The processing of the data also includes their disclosure by way of transmission.
Data transmissions to the USA are covered under an adequacy decision from the EU commission, also known as the EU-US Privacy Shield. The commission has confirmed that the guarantees for the transmission of data to the USA under the EU-US Privacy Shield conforms with EU data protection standards. To the extent we transmit data to the USA, we have indicated the participation of our respective service providers in the EU-US Privacy Shield.
The data, purposes of processing the data, legal bases, recipients and transmissions third countries concerned in each individual case are set out in the following table:
a) Log file
We store certain information concerning your visit to our website in a log file. The following data will be processed: Name of the website accessed, date and time of the access, transmitted data volume, type of browser and version, your operating system, referrer URL (the previously visited website), your IP address and the provider making the request. This data is required to ensure the security of our website.
We will process this data on the basis of our legitimate interest pursuant to Article 6 para. 1f GDPR. The log file will be deleted after seven days, unless it is required to investigate or establish specific infringements that have become known within the retention period.
All data processed in relation to the operation of this website that concern the area of hosting will be stored. This is necessary to operate the website. We will process this data on the basis of our legitimate interest pursuant to Article 6 para. 1f GDPR. The provision of our Internet service entails the use of web hosting service providers, to whom we will transmit the data specified above.
c) Making contact
If you contact us, we will process your data ( name, contact details, if provided by you) and your message to us exclusively for the purpose of handling and processing your inquiry. We will process this data to handle your inquiry on the basis of Article 6 para. 1b GDPR or Article 6 para. 1f GDPR.
We offer you the option of subscribing to a newsletter, which will regularly inform you about our company and our services. When you subscribe to the newsletter, we will process the data entered by you (email headers and any other data provided voluntarily).
The newsletter will be sent to you on the basis of your declaration of consent pursuant to Article 6 para. 1A GDPR and only after you have completed your subscription.
The newsletter subscription uses the so-called double opt-out procedure. After you have subscribed to the newsletter, we will send you an email asking you to confirm your subscription. This serves the purpose of preventing abuse. We will save your subscription data in a log file order to demonstrate our compliance with the legal requirements. This means that we will store the date and time of your subscription, the date of time of you confirming your subscription, as well as your IP address.
e) Customer account
If you open a customer account, you consent to having your basic data be saved, such as name, address, email address, bank account information, and your user data (username, password). As a result, you have the option of placing orders with us using your email address or your customer number and your personal password.
Your data is processed by us on the basis of your consent in compliance with article 6, para. 1 a) of the GDPR.
f) Processing of purchases
We will process your order data for the purpose of performing the purchase contract. The data is processed on the basis of Art. 6 para. 1b GDPR.
We will disclose your address details to the company contracted by us for delivery. To the extent necessary for us to perform the contract, we will further disclose your email address or telephone number for the purpose of coordinating a delivery date to the company contracted for the delivery.
Payments for purchases made by credit card (MasterCard or Visa), PayPal or Klarna “Sofort” will be processed by our external payment processor Heidelpay GmbH, Vangerowstraße 18, 69115 Heidelberg, Germany („Heidelpay“). The ordering process will forward you directly to the payment page for your preferred method of payment. This will cause payment processing-related data (your first name, last name, street, house number, postcode, town, telephone number and the payment details entered) as well as order-related data to be transmitted directly to Heidelpay. Further information about data protection at your preferred payment processing provider can be found in the Data Protection Statement of Heidelpay available at: https://www.heidelpay.com/en, https://www.heidelpay.com/en/privacy-statement/.
g) Website analysis and marketing
If you do this, you may have to reconfigure some settings each time you visit our website. Some of our websites functions may also not be available if you have cookies deactivated.
aa) Google Analytics
We use Google Analytics, a service provided by Google LLC 1600 Amphitheatre Parkway Mountain View, CA 94043 USA. Google uses special types of cookies for its analysis services. The information on your use of this website generated by the cookie (including your IP address) will be transmitted to and stored on a Google server in the USA.
We use the stored information to analyse your use of the website, to compile reports about website activities for the website operators and to provide additional services associated with the use of the website. We process the data generated on the basis of our prevailing interest in the best possible marketing of our online services pursuant to Article 6 para. 1f GDPR. Google will in no case analyse your IP address inconnection with other data held by Google.
Please note that our website uses Google Analytics with the "anonymizeIp()" extension activated. This means that IP addresses are truncated prior to the transmission to a server in the USA. A direct tracing of the stored data back to individual persons is therefore usually excluded. The full IP address will only be transmitted to a server in the USA truncated there in exceptional cases.
You may object against the collection of data in any time with effect on the future by using the deactivation ad-on for browsers offered by Google Analytics at http://tools.google.com/dlpage/gaoptout?hl=en
Please also note the information on the use of data within the Google partner network available at: http://www.google.com/intl/de/policies/privacy/partners/
Google’s certification can be reviewed at:
Further data protection information can be found at: https://policies.google.com/privacy?hl=en&gl=en
bb) Google Analytics with the additional function “demographic characteristics and interests”
In addition to the standard functions of Google Analytics, we also use the “demographic characteristics” function. This will cause a cookie to be placed on your user device when you visit certain webpages. These cookies serve the purpose of allowing us to analyse the referrer websites from which users access our website. This will entail the collection and analysis of data concerning your demographic characteristics (gender, age). The analysis of this data allows us to serve interest-specific display advertising. The data is processed on the basis of our prevailing interests in the optimised marketing of our online services pursuant to Article 6 paragraph 1 lit. f GDPR.
You may at any time object against the collection of data with prospective effect by objecting against the collection of data by Google Analytics as explained in point B.h) aa), or by deactivating the corresponding function in your Google account. Further information about data protection can be found at: https://policies.google.com/privacy?hl=en&gl=en
If you would like to object against the future use of your data, you can do so by changing the settings at: http://www.google.de/ads/preferences.
Further information on Google AdSense can be found at: https://support.google.com/adsense/answer/140382?hl=en
Please also take note of the information concerning the use of data by Google within the Google partner network available at: http://www.google.com/intl/de/policies/privacy/partners/
Google’s certification can be reviewed at: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
h) Use of external content
We use external dynamic content to optimise the presentation and functionalities of our website. When you visit our website, an API will automatically make a request to the server of the respective content provider and during this course ( transmit certain locked data (i.e. the users IP address). The dynamic content is exclusively transmitted to and displayed on our website.
We use external content in connection with the following features:
We use maps from Google Maps, a service by Google, for the purpose of making the use of an interactive map available to you. The generation of the map will entail the transmission of data, including your IP address and location to Google servers in the USA and stored there. This data processing is based on our prevailing legitimate interest in the best possible marketing of our services pursuant to Art. 6 para. 1f GDPR.
Google’s certification can be reviewed at: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further data protection information can be found at: https://policies.google.com/privacy?hl=en&gl=de
i) Verification against the EU sanctions list
We are under a statutory obligation to validate legal transactions against so-called compliance lists. These lists of names mainly serve the purpose of preventing money-laundering and to fight terrorism. The list used by us is the Compliance List published by the European Union (CFSP). This list was made available to us by: Creditpass GmbH, Mehlbeerenstr. 2, 82024 Taufkirchen b. München. We process your data on the basis of our statutory obligation pursuant to Art. 6 para. 1c GDPR.
j) Social media
Our website contains links to different social media platforms and other websites. Your visit to our website will not cause data to be transmitted to any social media or other websites. You will however be forwarded to the respective websites if you click on one of the external links on our website. These other websites may collect and process your data under their own terms and conditions of use, which you may review directly on the respective website. We recommend to review the data protection statements of the respective service or website and the above declaration of consent before making a decision to access or use any such website or service.
We have no control over the nature and extent of data processing conducted by operators of external websites you may access by clicking on a link on our website. Your respective rights and configuration options to protect your privacy are set out in the respective data protection statements (see above).
C. Duration of the retention period
We will only save your personal data for the period in time it is needed for the purpose it is being processed for or is required, or until you revoke your consent. If and when statutory retention periods must be observed, e.g. under commercial trade or tax law, it may be necessary to retain certain data for up to 10 years.
D. Your rights
Upon request, you can receive information about the personal data that we have saved about you at any time free of charge.
b) Correction, deletion, setting limitations on processing (blocking) and objection
If you no longer agree with your personal data being saved or your information is not correct, we will arrange for your data to be deleted or blocked upon receiving appropriate notification thereof, or we will make the necessary corrections (provided this is possible under applicable laws). The same shall apply if we should only process your data in a more restrictive manner in the future.
c) Data transmissibility
You may request us to provide you with your data in a commonly used, structured and machine-readable format, which you may use to transfer the data to another data controller.
d) Right to lodge a complaint
You have the right to lodge a complaint with the relevant supervisory authority.
e) Right to revoke declarations of consent with effect on the future
You may revoke any previously granted declaration of consent at any time with effect on the future. Your revocation will be without prejudice to the lawfulness of the data processing that took place prior to your revocation.
The rights set out above do not apply to data that does not allow us to identify the data subject, i.e. data that was anonymised for analysis purposes. We may be able to provide you with information on your data, delete your data, restrict the processing of your data, correct your data or transfer your data to another company if you provide us with additional information that allows us to identify you.
g) Exercising your rights as a data subject
If you have any questions concerning the processing of your personal data, or if you would like information or request the correction, deletion or restriction of data, or if you would like to have the data transferred to another company, please send an email to datenschutz(a)glashuette.com