Data protection and data security
Privacy policy
We are pleased that you are visiting our website. The protection and security of your personal information when using our website is very important to us. We would therefore like to inform you here about which of your personal data we collect when you visit our website and for what purposes it is used.
This data protection declaration applies to the Internet offer of Ferdinand Kreutzer Sabamühle GmbH, which is accessible under the domain www.sabamuehle.de as well as the various subdomains (“our website”).
Who is responsible and how can I reach you?
Responsible
for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)
Ferdinand Kreutzer Sabamühle GmbH
Management Dipl. Kfm. Fabian Frank and Christine Sparvoli-Frank M.A., MEB
Burgbernheimer Str. 11
90431 Nürnberg
Phone: 0911-324720
E-Mail: info@saba.de
Data protection officer
Data protection Pöllinger GmbH
Dresdner Str. 38
92318 Neumarkt
Tel.: 09181 – 2705770
E-Mail: datenschutz@datenschutz-poellinger.de
You can find our duty to inform according to Art. 13 and 14 GDPR here:
Video surveillance
Applicants
Customers / Interested parties
Suppliers
Social media
What is it about?
This privacy statement complies with the legal requirements for transparency in the processing of personal data. This is any information relating to an identified or identifiable natural person. This includes, for example, information such as your name, age, address, telephone number, date of birth, email address, IP address or user behaviour when visiting a website. Information for which we cannot (or can only with disproportionate effort) establish a link to your person, e.g. through anonymisation, is not personal data. The processing of personal data (e.g. collection, retrieval, use, storage or transmission) always requires a legal basis and a defined purpose.
Stored personal data are deleted as soon as the purpose of the processing has been achieved and there are no legitimate grounds for further retention of the data. We inform you about the specific storage periods or criteria for storage in the individual processing operations. Irrespective of this, we store your personal data in individual cases for the assertion, exercise or defence of legal claims and if there are statutory retention obligations.
Who gets my data?
We only disclose your personal data that we process on our website to third parties if this is necessary for the fulfilment of the purposes and is covered by the legal basis in the individual case (e.g. consent or safeguarding legitimate interests). In addition, we disclose personal data to third parties in individual cases if this serves the assertion, exercise or defence of legal claims. Possible recipients may then be, for example, law enforcement agencies, lawyers, auditors, courts, etc.
Insofar as we use service providers for the operation of our website who process personal data on our behalf within the scope of commissioned processing pursuant to Art. 28 GDPR, they may be recipients of your personal data. You can find more information on the use of processors and web services in the overview of the individual processing operations.
Do you use cookies?
Cookies are small text files that are sent by us to the browser of your end device when you visit our website and are stored there. As an alternative to the use of cookies, information can also be stored in the local storage of your browser. Some functions of our website cannot be offered without the use of cookies or local storage (technically necessary cookies). Other cookies, however, enable us to carry out various analyses, so that we are able, for example, to recognise the browser you are using when you visit our website again and to transmit various information to us (non-essential cookies). With the help of cookies, we can, among other things, make our website more user-friendly and effective for you, for example by tracking your use of our website and determining your preferred settings (e.g. country and language settings). If third parties process information via cookies, they collect the information directly via your browser. Cookies do not cause any damage to your end device. They cannot execute programs or contain viruses.
We provide information about the respective services for which we use cookies in the individual processing operations. You can find detailed information on the cookies used in the cookie settings or in the Consent Manager of this website.
What rights do I have?
Under the conditions of the statutory provisions of the General Data Protection Regulation (GDPR), you have the following rights as a data subject:
How is my data processed in detail?
In the following, we inform you about the individual processing operations, the scope and purpose of the data processing, the legal basis, the obligation to provide your data and the respective storage period. An automated decision in individual cases, including profiling, does not take place.
Provision of the website
Nature and scope of the processing
When you call up and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:
Our website is not hosted by ourselves, but by a service provider who processes data on our behalf for the above-mentioned purposes in accordance with Art. 28 GDPR.
Purpose and legal basis
The processing is carried out to protect our overriding legitimate interest in displaying our website and guaranteeing security and stability on the basis of Art. 6 para. lit. f GDPR. The collection of data and storage in log files is absolutely necessary for the operation of the website. There is no right to object to the processing due to the exception under Art. 21 (1) GDPR. Insofar as the further storage of log files is required by law, the processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR. There is no legal or contractual obligation to provide the data, however, calling up our website is not technically possible without providing the data.
Storage period
The aforementioned data will be stored for the duration of the website display and, for technical reasons, for a maximum of 6 months.
Contact form
Nature and scope of the processing
On our website, we offer you the opportunity to contact us via a form provided. The information collected via mandatory fields is required in order to process the request. Furthermore, you can voluntarily provide additional information that you consider necessary for processing the contact request.
When using the contact form, your personal data will not be passed on to third parties.
Purpose and legal basis
The processing of your data through the use of our contact form is carried out for the purpose of communication and processing of your enquiry on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Insofar as your enquiry relates to an existing contractual relationship with us, processing is carried out for the purpose of fulfilling the contract on the basis of Art. 6 Para. 1 lit. b GDPR. There is no legal or contractual obligation to provide your data, but the processing of your request is not possible without the provision of the information of the mandatory fields. Insofar as you do not wish to provide this data, please contact us by other means.
Storage period
Insofar as you use the contact form on the basis of your consent, we store the data collected for each enquiry for a period of ten years.
If you use the contact form as part of a contractual relationship, we will store the data collected for each enquiry for a period of ten years.
Presence on social media platforms
We maintain so-called fan pages or accounts or channels on the networks mentioned below in order to provide you with information and offers also within social networks and to offer you further ways to contact us and to inform yourself about our offers. In the following, we will inform you about which data we or the respective social network process from you in connection with calling up and using our fan pages/accounts.
Data we process from you
If you wish to contact us via messenger or direct message via the respective social network, we generally process your user name via which you contact us and, if applicable, store further data provided by you insofar as this is necessary to process/respond to your request.
The legal basis is Art. 6 para. 1 sentence 1 f) GDPR (processing is necessary to protect the legitimate interests of the controller).
(Static) usage data that we receive from the social networks
We receive automated statistics regarding our accounts via Insights functionalities. The statistics include, among other things, the total number of page views, “like” comments, information on page activities and post interactions, reach, video views and information on the proportion of men/women among our fans/followers.
The statistics only contain aggregated data that cannot be related to individual persons. You are not identifiable to us through this.
What data the social networks process from you
In order to view the content of our fan pages or accounts, you do not have to be a member of the respective social network and, in this respect, no user account for the respective social network is required.
Please note, however, that the social networks also collect and store data from website visitors without a user account when the respective social network is called up (e.g. technical data in order to be able to display the website to you) and use cookies and similar technologies, over which we have no control. For details, please refer to the privacy policy of the respective social network (see the corresponding links above).
Insofar as you wish to interact with the content on our fan pages/accounts, e.g. comment on, share or like our postings/contributions and/or contact us via messenger functions, prior registration with the respective social network and the provision of personal data is required.
We have no influence on the data processing by the social networks within the scope of their use by you. To our knowledge, your data is stored and processed in particular in connection with the provision of the services of the respective social network, as well as for the analysis of user behaviour (using cookies, pixels/web beacons and similar technologies), on the basis of which advertising based on your interests is played both within and outside the respective social network. It cannot be ruled out that your data will be stored by the social networks outside the EU/EEA and passed on to third parties.
Information on, among other things, the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines on the use of cookies and similar technologies in the context of registration and use of the social networks can be found in the privacy policy/cookie policy of the social networks. There you will also find information on your rights and objection options.
Facebook page
When you visit our Facebook page, Facebook (Meta) collects, among other things, your IP address and other information that is present on your PC in the form of cookies. This information is used to provide us, as operators of the Facebook pages, with statistical information about the use of the Facebook page. Facebook provides more detailed information on this under the following link: https://facebook.com/help/pages/insights.
We are not able to draw conclusions about individual users by means of the statistical information transmitted. We only use this information to respond to the interests of our users and to continuously improve our online presence and ensure its quality.
We collect your data via our fan page only in order to realise a possible provision for communication and interaction with us. This collection usually includes your name, message content, comment content and the profile information you provide “publicly”.
The processing of your personal data for our above-mentioned purposes is based on our legitimate business and communicative interest in offering an information and communication channel pursuant to Art. 6 para. 1 f) GDPR. If you, as a user, have given your consent to the data processing vis-à-vis the respective provider of the social network, the legal basis of the processing extends to Art. 6 para. 1 a), Art. 7 GDPR.
Due to the fact that the actual data processing is carried out by the provider of the social network, our access to your data is limited. Only the provider of the social network is authorised to fully access your data. Because of this, only the provider can directly take and implement appropriate measures to fulfil your user rights (information request, deletion request, objection, etc.). The most effective way to assert your rights is therefore to contact the provider directly.
We are jointly responsible with Facebook for the personal content of the fan page. Data subject rights can be asserted with Meta Platforms Ireland Ltd. as well as with us.
The primary responsibility for the processing of Insights data lies with Facebook under the GDPR and Facebook complies with all obligations under the GDPR in relation to the processing of Insights data, Meta Platforms Ireland Ltd. provides the essence of the Page Insights Supplement to data subjects.
We do not make any decisions regarding the processing of insights data and storage duration of cookies on user devices.
You can find further information directly at Facebook (Supplementary Agreement with Facebook): https://www.facebook.com/legal/terms/page_controller_addendum.
For more information on, among other things, the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines on the use of cookies and similar technologies in the context of registration and use, please refer to Facebook’s privacy policy/cookie policy:
https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0
https://www.facebook.com/policies/cookies
Twitter page
Twitter is a social network of Twitter Inc. based in San Francisco, California, USA, which enables the creation of private profiles of natural persons (personal account) and professional profiles (professional account) of natural persons and companies. Via Twitter, users can, among other things, write short messages (so-called “tweets”), interact with the content of other users, e.g. write so-called “retweets”, give likes to posts, share posts and reply when other users mention or tag you in content.
When using or visiting the network and thus also when visiting our Twitter account, Twitter automatically collects data from the users or visitors, for example user name and IP address, during the use or visit. This is done with the help of tracking technologies, in particular by using cookies. Twitter provides users with information, offers and recommendations, among other things, on the basis of the data collected in this way. This information is used to provide us, as the operator of our Twitter page, with statistical information about the use of the Twitter page. You can find more information on this in Twitter’s privacy policy: https://twitter.com/privacy#twitter-privacy-1.
We are not able to draw conclusions about individual users by means of the statistical information transmitted. We only use this information to respond to the interests of our users and to continuously improve our online presence and ensure its quality.
We collect your data via our fan page only in order to realise a possible provision for communication and interaction with us. This collection usually includes your name, message content, comment content and the profile information you provide “publicly”.
The processing of your personal data for our above-mentioned purposes is based on our legitimate business and communicative interest in offering an information and communication channel pursuant to Art. 6 para. 1 f GDPR. If you, as a user, have given your consent to the data processing vis-à-vis the respective provider of the social network, the legal basis of the processing extends to Art. 6 para. 1 a, Art. 7 GDPR.
Due to the fact that the actual data processing is carried out by the provider of the social network, our access to your data is limited. Only the provider of the social network is authorised to fully access your data. Due to this, only the provider can directly take and implement appropriate measures to fulfil your user rights (information request, deletion request, objection, etc.). The most effective way to assert your rights is therefore to contact the provider directly.
We are jointly responsible with Twitter for the personal content of the fan page. Data subject rights can be asserted with Twitter Inc. as well as with us.
The primary responsibility under the GDPR for the processing of Insights Data lies with Twitter and Twitter complies with all obligations under the GDPR with respect to the processing of Insights Data. Twitter Inc. provides the essence of the Page Insights Supplement to data subjects.
We do not make any decisions regarding the processing of insights data and storage duration of cookies on user devices.
For more information on, among other things, the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines on the use of cookies and similar technologies in the context of registration and use, please refer to Twitter’s privacy policy/cookie policy:
Privacy
policy: https://twitter.com/privacy#twitter-privacy-1
Cookie policy: https://help.twitter.com/rules-and-policies/twitter-cookies
LinkedIn page
LinkedIn is a social network of LinkedIn Inc. based in Sunnyvale, California, USA, which enables the creation of private and professional profiles of natural persons and company profiles. Users can maintain their existing contacts and make new ones within the social network. Businesses and other organisations can create profiles where photos and other company information are uploaded to present themselves as employers and recruit employees. Other LinkedIn users have access to this information and can write their own articles and share this content with others. The focus of the network is on professional exchange on specialist topics with people who share the same professional interests.
When using or visiting the network, LinkedIn automatically collects data from users or visitors during the use or visit, for example user name, job title and IP address. This is done with the help of various tracking technologies. LinkedIn provides information, offers and recommendations to users on the basis of the data collected in this way.
We only collect your data via our company profile in order to realise a possible provision for communication and interaction with us. This collection usually includes your name, message content, comment content and the profile information you provide “publicly”.
The processing of your personal data for our above-mentioned purposes is based on our legitimate business and communicative interest in offering an information and communication channel pursuant to Art. 6 para. 1 f GDPR. If you, as a user, have given your consent to the data processing vis-à-vis the respective provider of the social network, the legal basis of the processing extends to Art. 6 para. 1 a, Art. 7 GDPR.
Due to the fact that the actual data processing is carried out by the provider of the social network, our access to your data is limited. Only the provider of the social network is authorised to fully access your data. Due to this, only the provider can directly take and implement appropriate measures to fulfil your user rights (information request, deletion request, objection, etc.). The most effective way to assert your rights is therefore to contact the provider directly.
We are jointly responsible with LinkedIn for the personal content of our company profile. Data subject rights can be asserted with LinkedIn Inc. as well as with us.
We do not make any decisions regarding the data collected on LinkedIn’s site using tracking technologies.
For more information on LinkedIn, please visit: https://about.linkedin.com.
Further information on data protection at LinkedIn can be found at: https://www.linkedin.com/legal/privacy-policy.
Further information on storage duration/deletion as well as guidelines on the use of cookies and similar technologies in the context of registration and use on LinkedIn can be found at: https://de.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy.
Google Analytics
Nature and scope of the processing
We use Google Analytics from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as an analysis service for the statistical evaluation of our online offer. This includes, for example, the number of views of our online offering, sub-pages visited and the length of stay of visitors.
Google Analytics uses cookies and other browser technologies to evaluate user behaviour and recognise users.
This information is used, among other things, to compile reports on website activity.
Purpose and legal basis
The use of Google Analytics is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR and § 25 para. 1 TTDSG.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. In cases where no adequacy decision of the European Commission exists (e.g. in the USA), we have agreed with the recipients of the data on other appropriate safeguards within the meaning of Art. 44 et seq. GDPR. These are – unless otherwise stated – standard contractual clauses of the EU Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
In addition, before such a third country transfer, we obtain your consent in accordance with Art. 49 Para. 1 Sentence 1 lit. a. GDPR, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of third country transfers, there may be unknown risks in detail (e.g. data processing by security authorities of the third country, the exact scope of which and its consequences for you we do not know, over which we have no influence and of which you may not become aware).
Storage period
The specific storage period of the processed data cannot be influenced by us, but is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google Analytics: https://policies.google.com/privacy.
Google DoubleClick
Nature and scope of the processing
We have integrated components of DoubleClick by Google on our website. DoubleClick is a brand of Google, under which mainly special online marketing solutions are marketed to advertising agencies and publishers. DoubleClick by Google transfers data to the DoubleClick server with each impression as well as with clicks or other activities.
Each of these data transfers triggers a cookie request to the browser of the data subject. If the browser accepts this request, DoubleClick sets a cookie in your browser.
DoubleClick uses a cookie ID, which is required to process the technical procedure. The cookie ID is required, for example, to display an advertisement in a browser. DoubleClick can also use the cookie ID to record which advertisements have already been displayed in a browser in order to avoid duplicate placements. Furthermore, the cookie ID enables DoubleClick to record conversions. Conversions are recorded, for example, if a DoubleClick advertisement has previously been displayed to a user and the user subsequently makes a purchase on the advertiser’s website using the same internet browser.
A DoubleClick cookie does not contain any personal data, but may contain additional campaign identifiers. A campaign identifier serves to identify the campaigns with which you have already been in contact on other websites. As part of this service, Google obtains knowledge of data that Google also uses to generate commission statements. Among other things, Google can track that you have clicked on certain links on our website. In this case, your data will be passed on to the operator of DoubleClick, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information and the applicable data protection provisions of DoubleClick by Google can be found at https://policies.google.com/privacy.
Purpose and legal basis
We process your data with the help of the Double-Click cookie for the purpose of optimising and displaying advertising on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. You give your consent by setting the use of cookies (cookie banner / Consent Manager), with which you can also declare your revocation at any time with effect for the future in accordance with Art. 7 para. 3 GDPR. The cookie is used, among other things, to place and display user-relevant advertising and to create reports on advertising campaigns or to improve them. Furthermore, the cookie is used to avoid multiple displays of the same advertisement. Each time you call up one of the individual pages of our website on which a DoubleClick component has been integrated, your browser is automatically prompted by the respective DoubleClick component to transmit data to Google for the purpose of online advertising and the settlement of commissions. There is no legal or contractual obligation to provide your data. If you do not give us your consent, it will be possible to visit our website without restriction, but not all functions may be fully available.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. In cases where no adequacy decision of the European Commission exists (e.g. in the USA), we have agreed with the recipients of the data on other appropriate safeguards within the meaning of Art. 44 et seq. GDPR. These are – unless otherwise stated – standard contractual clauses of the EU Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
In addition, before such a third country transfer, we obtain your consent in accordance with Art. 49 Para. 1 Sentence 1 lit. a. GDPR, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of third country transfers, there may be unknown risks in detail (e.g. data processing by security authorities of the third country, the exact scope of which and its consequences for you we do not know, over which we have no influence and of which you may not become aware).
Storage period
The concrete storage period of the processed data cannot be influenced by us, but is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google DoubleClick: https://policies.google.com/privacy.
Google Tag Manager
Nature and scope of the processing
We use Google Tag Manager from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to manage website tags through one interface and allows us to control the precise integration of services on our website.
This allows us to flexibly integrate additional services to evaluate user access to our website.
Purpose and legal basis
The use of Google Tag Manager is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR and § 25 para. 1 TTDSG.
Storage period
The concrete storage period of the processed data cannot be influenced by us, but is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google Tag Manager: https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/.