Data privacy statement
1. Name and contact details of the controller responsible for data processing and of the company’s data protection officer
Noris-Color GmbH, represented by managing director Oliver Zeitler (hereafter: Noris-Color), Ziegelhüttener Str. 1, D-95326 Kulmbach, Germany
Telephone: +49 (0)9221/92000 Fax: +49 (0)9221/920090
Noris-Color’s operative data protection officer can be reached at the above address, c/o Antonie Zeitler, or at the following email address firstname.lastname@example.org
2. Acquisition and storage of personal data, and form and purpose of their use
a) Visiting our website
When you visit our website www.noris-color.de
the browser in use on your device automatically sends information to our website’s servers. This information is temporarily stored in something called a logfile. The following data are, without any action on your part, acquired and stored until their automatic deletion:
- the IP address of the device making the request,
- the date and time of the access,
- the name and URL of the file being accessed,
- the website which linked to the requested resouce (referrer URL)
- and the browser in use, as well as potentially your device’s operating system and the name of your service provider.
We use the data given above for the following purposes:
- to establish and guarantee a well-functioning connection to the website,
- to guarantee a convenient user experience on our website,
- to evaluate system security and stability
- and for other administrative purposes.
The legal basis for this data processing is Art. 6 (1)(f) GDPR. Our justifiable interest ensues from the purposes of data acquisition given above. In no way do we use the data thus acquired for the purpose of drawing conclusions regarding you as a person.
b) Registering for our newsletter
With your express consent, in accordance with Art. 6 (1)(a) GDPR, we use your email address to periodically send you our newsletter. An email address is sufficient for receiving the newsletter.
You can unsubscribe at any time, for instance via the link at the bottom of each newsletter. Alternatively, you can unsubscribe at any time via the email address email@example.com
c) Using our contact form
For any questions you may have, you have the opportunity to contact us via our website’s contact form. It is merely necessary that you give a valid email address, so that we know from whom the request is and can effectively answer it. All other information is given voluntarily.
Data processing for the purpose of establishing contact takes place on the basis of your voluntary consent, in accordance with Art. 6 (1)(a) GDPR.
The personal data we gather via the use of the contact form are automatically deleted after the completion of your request.
3. Transferral of data
The transmission of your personal data to third parties does not occur for any purposes other than the ones listed below.
We only transfer your personal data to third parties if
- you have have given us your express permission, in accordance with Art. 6 (1)(a) GDPR,
- their transmission is necessary, in accordance with Art. 6 (1)(f) GDPR, for the establishment, exercise or defence of legal claims, and there is no reason to assume that you have an overriding, defensible interest in your data not being transferred,
- in accordance with Art. 6 (1)(c) GDPR there exists a legal obligation to do so
- or if it is legal and necessary, in accordance with Art. 6 (1)(b) GDPR, for settling contractual relationships with you.
Each cookie stores information which is created in association with the specific device in use. This does not mean, however, that we have direct information regarding your identity.
Cookies are used, firstly, to make your use of our services a more pleasant experience. As such, we use something called session cookies to determine whether or not you have already visited individual pages on our website; they are automatically deleted when you leave our site.
Furthermore, and also in order to optimise user-friendliness, we use temporary cookies, which are stored on your device for a certain, pre-defined length of time. If you visit our website to make use of our services again, it automatically recognises you as a previous visitor, as well as your inputs and settings, so that you do not have to re-enter them.
The data processed by cookies are necessary for the purposes given here to further our justifiable interests and those of third parties, in accordance with Art. 6 (1)(f) GDPR.
Most browsers accept cookies automatically, but you can configure your browser so that no cookies are stored on your computer, or so that a notice always appears before a new cookie is created. If cookies are deactivated completely, however, you may not be able to use all of our website’s functions.
5. Analysis Tools
a) Tracking Tools
The tracking measures described in the following and used by us are implemented on the basis of Art. 6 (1)(f) GDPR. Our use of these tracking measures is intended to guarantee the user-tailored presentation and continual optimisation of our website. We also use tracking measures to assess statistically the usage of our website, analysing it in order to optimise our services to you. These interests can be considered legitimate in the sense of the aforementioned regulation.
The relevant data processing purposes and data categories are discussed in the context of each of the respective tracking tools.
i) Google Analytics1
For the purpose of the user-tailored presentation and the continual optimisation of our web presence, we use Google Analytics, a web analysis service developed by Google Inc. (https://www.google.com/about
) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereafter Google). For this reason, pseudonymous user profiles are created, and cookies are used (see Section 4). The information generated by the cookie about your use of our website, including
- browser type and version,
- your operating system,
- referrer URL (the page you previously visited),
- host name of the accessing device (IP address)
- and time of server request
is transmitted to a Google server in the USA and stored there. This information is used to analyse the usage of our website, to compile reports on website activity, and to deliver further services relating to the usage of the website and the internet for the purposes of market research and the user-tailored presentation of our internet presences. This information may also be transferred to third parties, where stipulated by law or when third parties are contracted to process this data. Your IP address will in no way be integrated with other data from Google. The IP addresses are anonymized so that identification is impossible (IP masking).
You can prevent cookies being installed via your own browser settings; however, we ask that you note that in this case you may not be able to fully use all of our website’s functions.
You can also prevent the acquisition of data generated by cookies and website usage (including your IP address), and of the processing of this data by Google, by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=en
As an alternative to the browser add-on, especially for browsers on mobile devices, you can opt out of data acquisition by Google Analytics by clicking on this link, which creates an opt-out cookie, which prevents the future acquistion of your data when visiting this website. This opt-out cookie functions only for this browser and only for our website, and is stored on your device. If you delete the cookies in this browser then you will have to reactivate the opt-out cookie.
ii) Google Adwords Conversion Tracking
In order to record the usage of our website statistically, and for the purpose of optimising our website for you, we also use Google Conversion Tracking, where Google Adwords creates a cookie (see Section 4) on your device if you arrived at our website via a Google advertisement.
These cookies become invalid after 30 days, and are not used for personal identification. If the user visits certain pages of a website belonging to an Adwords client, and the cookie is still valid, then Google and the client can see that the user clicked on an advertisement and was transferred to the page in question.
Each Adwords client receives a different cookie: consequently, cookies cannot traced via the websites of Adwords clients. The information delivered by the conversion cookie is used to develop conversion statistics for Adwords clients who elected to use conversion tracking. The Adwords clients are informed of the total number of users who clicked on their advertisement and were transferred to a website equipped with a conversion tracking tag. However, they receive no information that could be used to personally identify users.
If you do not wish to participate in the tracking procedure, then you can also opt out of the installation of the requisite cookie – for example by way of a browser setting which deactivates the automatic installation of cookies in general. You can also deactivate cookies for conversion tracking by setting your browser to block cookies from the domain www.googleadservices.com
Under no circumstances are IP addresses identified with other user-relevant data; all IP addresses are anonymized, making this impossible.
Your visit to this site is currently being record by the Matomo web analysis service. Click here (https://matomo.org/docs/privacy
) to stop your visit being recorded.
iiii) ajax.googleapis.com and jQuery
This website uses Ajax and jQuery technologies, which enable optimal loading speeds. To this end, program libraries are loaded from Google servers, using Google’s Content Delivery Network (CDN). If you have used jQuery on another page via Google CDN, your browser will make use of the copy stored in your cache. If this is not these case, the data will be downloaded, with data from your browser being transmitted to Google in the USA. You can learn more on the websites of the services in question.
6. Social Media Plugins
We utilise on our website, in accordance with Art.6 (1)(f) GDPR, social media plugins from the social networks Facebook, Twitter and Instagram, in order to publicize our business via these channels. Promotional purposes of this kind are to be considered legitimate interests in the sense of the GDPR. The respective providers are responsible for the guaranteeing that their operation conforms to data privacy regulations. We integrate these plugins using the so-called two-click method, so as to best protect our website’s visitors.
We use social media plugins on our website to personalise the experience for our users. We make use of the LIKE or SHARE button, as provided by Facebook.
If you visit a page of our web presence which contains one of these plugins, your browser establishes a direct connection to Facebook’s servers. The plugin’s content is transferred by Facebook directly to your browser, which incorporates it into the website.
Via the integration of the plugin, Facebook is informed that your browser has accessed the corresponding page of the website, even if you do not have a Facebook account, or are not currently logged in to Facebook. This information (including your IP address) is directly transmitted by your browser to a Facebook server in the US, and stored there.
If you are logged in to Facebook, Facebook is able to identify your visit to our website with your Facebook account. If you interact with the plugins, for example by pressing the LIKE or SHARE button, the corresponding information is also sent directly to a Facebook server and stored there. This information will also be posted on Facebook and shown to your Facebook friends.
Facebook may use this information for the purposes of advertising, market research and for creating individualised Facebook pages. To this end, Facebook generates profiles of usage, interests and relationships, for instance to evaluate your use of our website in relation to the advertisments displayed on Facebook, to inform other Facebook users about your activities on our website, and to deliver other services related to the use of Facebook.
If you do not want Facebook to identify the data acquired by our web presence to your Facebook account, then please log out of Facebook before visiting our website.
Our web presence includes plugins for the short message network Twitter. The Twitter plugins (Tweet buttons) can be identified as those with the Twitter logo on our website. A brief explanation of Tweet buttons can be found here (https://about.twitter.com/resources/buttons
If you access a page of our website which includes one of these plugins, a direct connection is established between your browser and the Twitter servers. As such, Twitter is informed that that you visited our site via your IP address. If you click on the Tweet button while logged into your Twitter account, you can create a link to the contents of our website on your Twitter profile. This enables Twitter to identify your visit to our website with your user account. We note here that we, as provider of the site in question, cannot account for the content of any data thus transmitted or its usage by Twitter.
If you do not want Twitter to be informed of your visit to our site, then please log out of your Twitter account.
Our website also uses social plugins from Instagram, operated by Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA (hereafter ‘Instagram’). The plugins can be identified by the Instagram logo, for example in the form of the ‘Instagram camera’.
When you access a page of our website which includes a plugin of this kind, your browser establishes a direct connection to the Instagram servers. The plugin’s content is transmitted by Instagram directly to your browser and integrated into the webpage. This integration informs Instagram that your browser has accessed the corresponding page on our website, even if you do not have an Instagram profile or are not currently logged into Instagram.
This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there. If you are logged into Instagram, then Instagram can directly identify your visit to our website with your Instagram account. If you interact with the plugins, for instance by clicking the Instagram button, this information is also transmitted directly to an Instagram server and stored there.
Furthermore, this information is also published on your Instagram account, and displayed to your contacts there.
If you do not want Instagram to be able to directly associate data acquired via our website with your Instagram account, then please log out of Instagram before visiting our website.
7. Your rights as a data subject
You have the right
- in accordance with Art. 15 GDPR to demand access to the personal data processed by us. In particular, you may demand information regarding the purposes of this processing; the categories of your personal data; the categories of actual or potential recipients of your data; the planned storage duration; the existence of the right to rectify or erase the data, and to restrict or object to its processing; the existence of a right to lodge a complaint; the source of your data, if they were not gathered by us; and the existence of automated decision-making, including profiling, and where applicable meaningful information on the details thereof;
- in accordance with Art. 16 GDPR to demand the prompt rectification or completion of incorrect or missing elements of any personal data of yours stored by us;
- in accordance with Art. 17 GDPR to demand the deletion of any of your personal data stored by us, provided that their processing is not necessary in exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of the public interest, or for the establishment, exercise or defence of legal claims;
- in accordance with Art. 18 GDPR to demand the restriction of the processing of your personal data, in cases where you contest the accuracy of the data; where their processing is unlawful, but you oppose their deletion; where we no longer need the data, but you need them for the establishment, exercise or defence of legal claims; or where you have objected to their processing in accordance with Art. 21 GDPR;
- in accordance with Art. 20 GDPR to receive the personal data provided to us in a structured, widely-used and machine-readable format, or to demand their transmission to another controller;
- in accordance with Art. 7 (3) GDPR to withdraw your consent to us at any time. The result of this is that we do not have the right to continue in future the processing of data based on this original consent;
- in accordance with Art. 77 GDPR to lodge a complaint with a supervisory authority. As a rule, you may lodge this complaint with the supervisory authority of your habitual place of residence or place of work, or at our legal offices.
8. Right to object
Where your personal data are being processed based on justifiable interests, as stated in Art 6. (1)(f) GDPR, you have the right, in accordance with Art. 21 GDPR, to oppose the processing of your personal data, either on grounds relating to your own specific situation, or if your objection is to direct advertising. In the latter case, you have a general right to object, which will be acted upon by us without any declaration of a specific individual situation.
If you would like to make use of your right to object, an email to firstname.lastname@example.org
9. Data security
During your visit, we use the widespread SSL protocol (Secure Socket Layer), together with the highest level of encryption that your browser supports, which is usually 256-bit encryption. If your browser does not support 256-bit encryption, we instead utilize 128-bit v3 technology. You can verify whether an specific page of our web presence is encrypted by checking that the key or lock symbol in the status bar at the bottom of your browser is depicted as ‘locked’.
We also make use of the appropriate technical and organisational security measures to protect your data against accidental or deliberate manipulation, partial or complete deletion or destruction, or unauthorised access by third parties. Our security measures are continually updated in compliance with technological developments.
10. Validity of and changes to this data privacy statement
This privacy statement is currently valid, as of May 2018.
Due to developments in our website and our services, or due to changes in legislative or other official stipulations, it may become necessary to alter this privacy statement. You will always have access to the currently valid data privacy statement at https://www.noris-color.de/uploads/files/datenschutz.pdf