Information obligations according to the EU General Data Protection Regulation (GDPR)
General
We take the protection of your personal data very seriously. We treat your personal data confiden-tially and in accordance with the statutory data protection regulations and this declaration.
Personal information is information that personally identifies you. This information sheet explains what data we collect and what we use it for. It also explains how and for what purpose.
Responsible post
Company name: Naber GmbH
Address: Enschedestraße 24, 48529 Nordhorn, Germany
Tel.: +49 5921 704-0
Fax: +49 5921 704-140
E-Mail: info@naber.com
Internet: www.naber.com
Data Protection Officer (external)
Dr. Johannes Schröder
Griegstraße 6, 49565 Bramsche, Germany
Tel.: +49 5461 886299
E-Mail: datenschutz@naber.com
Legal basis for the processing of personal data
We only process personal data if there is a legal basis, i.e. if
- the data subject has given their consent (Art. 6, para. 1, lit. a GDPR),
- it is for the fulfilment of a contract (Art. 6, para. 1, lit. b GDPR),
- legitimate interests (Art. 6, para. 1, lit. f GDPR) exist,
- it is for the fulfilment of a legal obligation (Art. 6, para. 1, lit. c GDPR).
Processing of data, data categories and groups of data subjects
All personal data is collected and processed in accordance with the EU General Data Protection Regulation (GDPR) and the Act to Adapt Data Protection Law to Regulation (EU) 2016/679 and to Implement Directive (EU) 2016/680 (DSAnpUG-EU).
We process the following data from you:
Company name, first name and surname of contact person and (end) customer, address, telephone and fax number, e-mail, bank details, contracts, orders, delivery notes, invoices.
The data belongs to the following data categories: identification data, communication data, financial data, order and contract data and billing data.
The following groups of people are affected: customers, prospective customers, suppliers, sales representatives and employees.
Use of your data (purpose)
This data is collected
- to identify you as a customer,
- to process your request, your order appropriately,
- to fulfil orders,
- for correspondence with you,
- for invoicing,
- for informational purposes.
Your rights as a data subject
As a data subject you have the right at any time
- to free information about your stored personal data (Art. 15 GDPR), its origin and recipient and the purpose of the processing of your data,
- to rectification (Art. 16 GDPR),
- to blocking (right to restriction of processing, Art. 18 GDPR),
- to deletion of this data subject to any statutory retention requirements (Art. 17 GDPR),
- to complain to the competent supervisory authority (Art. 77 GDPR),
- to data portability (Art. 20 GDPR).
Disclosure of data
Data is not disclosed to third parties unless this is necessary to fulfil your request/order. The data is not transferred to third countries.
Automated decision making and profiling
No automated decision-making procedures according to Art. 22 GDPR or other profiling measures according to Art. 4 No. 4 GDPR are carried out.
Revocation of consent
You may revoke your consent granted at any time with effect for the future. If you wish to exercise your right of revocation, an e-mail to E Naber GmbH (see above) is sufficient.
Deletion of personal data
The personal data collected by us is deleted after the purpose is finished, taking into account the statutory retention requirements.
Technical-organisational measures
We take technical and organisational measures to process your data with a high degree of security. Importance is especially attached to the following points:
- Confidentiality (Art. 32 para. 1 lit. b GDPR), especially physical, electronic and internal access control and isolation control
- Integrity (Art. 32 para. 1 lit. b GDPR), especially data transfer, data entry, processing, documentation and order control
- Availability and resilience (Art. 32 para. 1 lit. b GDPR), especially availability control and recoverability
- Process for regularly testing, assessing and evaluating (Art. 32 para. 1 lit. d GDPR; Art. 25 para. 1 GDPR), especially data protection management, data-protection-friendly default settings and organisation control