Introduction

The following privacy policy is intended to explain to you what types of your personal data (hereinafter also referred to simply as “data”) we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online platforms, such as our social media profiles (hereinafter collectively referred to as the “online offering”).

The terms used are not gender-specific.

As at 31 March 2022

Table of Contents

Data controller

Ollendorf Measurement Systems GmbH
15 Rathenower Straße
39576 Stendal
Germany

Email address:

info(at)ollendorfsystems.com

Overview of processing operations

The following overview summarises the types of data processed and the purposes for which they are processed, and identifies the data subjects.

Types of data processed

  • Stock data.

  • Payment details.

  • Contact details.

  • Table of contents.

  • Contract details.

  • Usage data.

  • Meta/communication data.

Categories of data subjects

  • Prospective customers.

  • Communication partners.

  • Users.

  • Business and contractual partners.

Purposes of processing

  • Provision of contractual services and customer service.

  • Enquiries and communication.

  • Direct marketing.

  • Range measurement.

  • Office and organisational procedures.

  • Conversion tracking.

  • Managing and responding to enquiries.

  • Feedback.

  • Marketing.

  • Profiles containing user-specific information.

  • Provision of our online services and user-friendliness.

Relevant legal bases

Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours, depending on where you or we are resident or have our registered office. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.

  • Consent (Article 6(1), first sentence, point (a) of the GDPR) - The data subject has given their consent to the processing of their personal data for a specific purpose or for several specific purposes.

  • Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) - The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.

  • Legal obligation (Article 6(1), first sentence, point (c) of the GDPR) - The processing is necessary for compliance with a legal obligation to which the controller is subject.

  • Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR) - Processing is necessary to safeguard the legitimate interests of the controller or a third party, unless the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, take precedence.

In addition to the data protection provisions of the General Data Protection Regulation, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, it regulates data processing for the purposes of the employment relationship (Section 26 BDSG), in particular with regard to the establishment, performance or termination of employment relationships, as well as the consent of employees. In addition, state data protection laws of the individual federal states may apply.

Safety measures

We implement technical and organisational measures in accordance with the statutory requirements, taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and safeguarding of the availability of the data, and the segregation of data. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted and that appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and through privacy-friendly default settings.

Truncation of IP addresses: Where IP addresses are processed by us or by the service providers and technologies we use, and where the processing of a full IP address is not necessary, the IP address is truncated (also referred to as ‘IP masking’). In this process, the last two digits, or the last part of the IP address following a full stop, are removed or replaced with placeholders. The purpose of truncating the IP address is to prevent, or make it significantly more difficult, to identify an individual on the basis of their IP address.

SSL encryption (https): To protect the data you submit via our website, we use SSL encryption. You can recognise connections encrypted in this way by the prefix https:// in your browser’s address bar.

Transfer of personal data

As part of our processing of personal data, it may occur that the data is transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the statutory requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.

Data processing in third countries

Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other persons, bodies or organisations, this is done solely in accordance with the statutory requirements.

Subject to express consent or where data transfer is required by contract or by law, we shall only process data, or arrange for it to be processed, in third countries with a recognised level of data protection, subject to contractual obligations under the European Commission’s so-called Standard Data Protection Clauses, where certifications are in place or where binding internal data protection regulations apply (Articles 44 to 49 of the GDPR, European Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).

Deletion of data

The data we process will be deleted in accordance with statutory requirements as soon as the consent given for its processing is withdrawn or any other legal basis for processing ceases to apply (e.g. if the purpose for which the data is processed no longer applies or if the data is no longer necessary for that purpose).

Unless the data is not deleted because it is required for other, legally permissible purposes, its processing shall be restricted to those purposes. This means that the data will be blocked and not processed for any other purposes. This applies, for example, to data which must be retained for commercial or tax law reasons, or where its storage is necessary for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person.

As part of our privacy policy, we may provide users with further information on the erasure and retention of data that applies specifically to the relevant processing operations.

Use of cookies

Cookies are small text files or other storage mechanisms that store information on end-user devices and retrieve information from them. For example, to store the login status in a user account, the contents of a shopping basket in an online shop, the content accessed or the functions used on a website. Cookies may also be used for various other purposes, such as ensuring the functionality, security and user-friendliness of online services, as well as analysing visitor traffic.

Information regarding consent: We use cookies in accordance with the relevant legal provisions. We therefore obtain prior consent from users, unless this is not required by law. In particular, consent is not required if the storage and retrieval of information – including cookies – are strictly necessary to provide users with a telemedia service (i.e. our online offering) that they have expressly requested. The revocable consent is clearly communicated to users and includes information on the specific use of cookies.

Information on the legal basis for data protection: The legal basis under data protection law on which we process users’ personal data using cookies depends on whether we ask users for their consent. If users give their consent, the legal basis for the processing of their data is that expressed consent. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g. the commercial operation of our online service and improving its usability) or, where this takes place within the framework of fulfilling our contractual obligations, where the use of cookies is necessary to fulfil our contractual obligations. We explain the purposes for which we process cookies in this privacy policy or as part of our consent and processing procedures.

Retention period: With regard to their storage duration, the following types of cookies are distinguished:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left an online service and closed their device (e.g. browser or mobile application).

  • Persistent cookies: Persistent cookies remain stored even after the device has been switched off. This allows, for example, the user’s login status to be saved or their preferred content to be displayed immediately when they visit a website again. Similarly, data collected from users via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage period of cookies (e.g. when obtaining consent), users should assume that cookies are permanent and that they may be stored for up to two years.

General information on withdrawal and opting out: Users may withdraw the consents they have given at any time and may also object to the processing of their data in accordance with the legal provisions set out in Article 21 of the GDPR (further information on the right to object is provided in this privacy policy). Users may also exercise their right to object via their browser settings.

Business services

We process data relating to our contractual and business partners, e.g. customers and prospective customers (collectively referred to as ‘contractual partners’), in the context of contractual and similar legal relationships, as well as associated measures, and in the context of communication with contractual partners (or at the pre-contractual stage), e.g. to respond to enquiries.

We process this data in order to fulfil our contractual obligations. These include, in particular, the obligations to provide the agreed services, any obligations to update the data, and to remedy any breaches of warranty or other service disruptions. In addition, we process the data to safeguard our rights and for the purposes of administrative tasks associated with these obligations, as well as for the organisation of our business. Furthermore, we process the data on the basis of our legitimate interests in the proper and sound management of our business, as well as in security measures to protect our contractual partners and our business operations from misuse, risks to their data, confidential information, details and rights (e.g. involving telecommunications, transport and other ancillary services, as well as subcontractors, banks, tax and legal advisers, payment service providers or tax authorities). Within the framework of applicable law, we shall only disclose the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfil legal obligations. Contractual partners shall be informed of further forms of processing, e.g. for marketing purposes, within the framework of this privacy policy.

We inform our contractual partners of which data is required for the aforementioned purposes either before or at the time of data collection, for example in online forms, by means of specific markings (e.g. colours) or symbols (e.g. asterisks or similar), or in person.

We delete the data once statutory warranty obligations and similar obligations have expired, i.e. generally after a period of 4 years, unless the data is stored in a customer account, e.g. for as long as it must be retained for statutory archiving purposes (e.g. for tax purposes, usually 10 years). We delete data disclosed to us by the contracting party in the context of a contract in accordance with the terms of that contract, generally upon completion of the contract.

Where we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms shall apply to the relationship between users and those providers.

Technical Services

We process the data of our customers and clients (hereinafter collectively referred to as “customers”) in order to enable them to select, purchase or commission the chosen services or works, as well as related activities, and to facilitate their payment, provision, execution or delivery.

The required details are identified as such when the contract, order or similar agreement is concluded and include the information necessary for the provision of services and invoicing, as well as contact details to enable any necessary consultations. Where we obtain access to information relating to end customers, employees or other individuals, we process such information in accordance with statutory and contractual requirements.

  • Types of data processed: Master data (e.g. names, addresses); payment details (e.g. bank details, invoices, payment history); contact details (e.g. email, telephone numbers); contract details (e.g. subject matter of the contract, term, customer category).

  • People affected: Prospective customers; business and contractual partners.

  • Purposes of processing: Provision of contractual services and customer service; enquiries and communication; office and organisational procedures; managing and responding to enquiries.

  • Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR); Legal obligation (Article 6(1), first sentence, point (c) of the GDPR); Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Provision of the online service and web hosting

In order to provide our online services securely and efficiently, we use the services of one or more web hosting providers, from whose servers (or servers managed by them) the online services can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space and database services, as well as security and technical maintenance services.

The data processed in connection with the provision of the hosting service may include all information relating to users of our online service that is generated during their use of the service and in the course of communication. This typically includes the IP address, which is necessary to deliver the content of online services to browsers, and any data entered within our online services or on websites.

  • Types of data processed: Content data (e.g. entries in online forms); usage data (e.g. webpages visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).

  • People affected: Users (e.g. website visitors, users of online services).

  • Purposes of processing: Provision of our online services and user-friendliness.

  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Collection of access data and log files: We ourselves (or rather, our web hosting provider) collect data on every access to the server (so-called server log files). The server log files may include the address and name of the web pages and files accessed, the date and time of access, the , a notification of a successful retrieval, browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider.The server log files may be used, on the one hand, for security purposes, e.g. to prevent the servers from becoming overloaded (particularly in the event of malicious attacks, known as DDoS attacks) and, secondly, to ensure the server’s capacity utilisation and stability; Deletion of data: Log file information is stored for a maximum of 30 days and is then deleted or anonymised. Data which must be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.

  • STRATO: Services relating to the provision of information technology infrastructure and associated services (e.g. storage space and/or computing capacity); Service provider: STRATO AG, Pascalstraße 10, 10587 Berlin, Germany; Website: https://www.strato.de; Privacy Policy: https://www.strato.de/datenschutz; Data Processing Agreement: concluded with the provider.

Contact and Enquiry Management

When you contact us (e.g. via the contact form, by email, telephone or via social media), and in the context of existing user and business relationships, the information provided by the enquirers is processed to the extent necessary to respond to enquiries and carry out any requested actions.

Responding to contact enquiries and managing contact and enquiry data in the context of contractual or pre-contractual relationships is carried out to fulfil our contractual obligations or to respond to (pre-)contractual enquiries and, in other respects, on the basis of our legitimate interests in responding to enquiries and maintaining user and business relationships.

  • Types of data processed: Personal details (e.g. names, addresses); contact details (e.g. email addresses, telephone numbers); content data (e.g. information entered into online forms).

  • People affected: Communication partners.

  • Purposes of processing: Enquiries and communication; provision of contractual services and customer service.

  • Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR); Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Legal obligation (Article 6(1), first sentence, point (c) of the GDPR).

Further information on processing procedures, methods and services:

  • Contact form: When users contact us via our contact form, by email or through other channels of communication, we process the data provided to us in this context in order to deal with the enquiry submitted. For this purpose, we process personal data within the framework of pre-contractual and contractual business relationships, insofar as this is necessary for their fulfilment and, in all other respects, on the our legitimate interests, as well as the interests of our communication partners in having their enquiries answered and our statutory retention obligations.

Marketing communications via email, post, fax or telephone

We process personal data for the purposes of marketing communications, which may be carried out via various channels, such as email, telephone, post or fax, in accordance with legal requirements.

Recipients have the right to withdraw their consent at any time or to object to marketing communications at any time.

Following revocation or objection, we retain the data necessary to prove prior authorisation for contacting you or sending you communications for up to three years after the end of the year in which the revocation or objection took place, on the basis of our legitimate interests. The processing of this data is limited to the purpose of potentially defending against claims. Furthermore, on the basis of our legitimate interest in permanently respecting users’ revocation or objection, we also store the data necessary to prevent us from contacting them again (e.g. depending on the communication channel, the email address, telephone number or name).

  • Types of data processed: Personal details (e.g. names, addresses); contact details (e.g. email addresses, telephone numbers).

  • People affected: Communication partners.

  • Purposes of processing: Direct marketing (e.g. by email or post).

  • Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR); legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Web analytics, monitoring and optimisation

Web analytics (also referred to as ‘audience measurement’) is used to analyse visitor traffic to our online service and may include pseudonymous data relating to visitors’ behaviour, interests or demographic information, such as age or gender. With the help of audience measurement, we can, for example, identify at what times our online service, its functions or content are most frequently used, or encourage repeat visits. We can also identify which areas require optimisation.

In addition to web analytics, we can also use testing methods to, for example, test and optimise different versions of our website or its individual components.

Unless otherwise stated below, profiles – that is, data aggregated to reflect a usage session – may be created for these purposes, and information may be stored in a browser or on a device and retrieved from it. The data collected includes, in particular, websites visited and elements used on them, as well as technical details such as the browser and computer system used, and information on usage times. Where users have given their consent to the collection of their location data by us or by the providers of the services we use, location data may also be processed.

Users’ IP addresses are also stored. However, we use an IP masking process (i.e. pseudonymisation by truncating the IP address) to protect users. Generally speaking, no personally identifiable data relating to users (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.

Notes on the legal basis: Where we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is consent. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. websites visited, interest in content, times of access); meta/communication data (e.g. device information, IP addresses).

  • People affected: Users (e.g. website visitors, users of online services).

  • Purposes of processing: Audience measurement (e.g. traffic statistics, identification of returning visitors); profiles containing user-related information (creation of user profiles); Conversion tracking (measuring the effectiveness of marketing activities); provision of our online services and user-friendliness.

  • Safety measures: IP masking (pseudonymisation of the IP address).

  • Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR); legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Social media presence

We maintain an online presence on social media platforms and, in this context, process users’ data in order to communicate with users active on those platforms or to provide information about us.

We would like to point out that this may involve the processing of users’ data outside the European Union. This may entail risks for users, as it could, for example, make it more difficult for them to enforce their rights.

Furthermore, users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of users’ behaviour and the resulting interests. These user profiles can in turn be used, for example, to display adverts both within and outside the networks that are presumed to correspond to users’ interests. For these purposes, cookies are usually stored on users’ computers, in which their usage behaviour and interests are recorded. Furthermore, data may also be stored in the usage profiles regardless of the devices used by users (in particular where users are members of the respective platforms and are logged in to them).

For a detailed explanation of the respective methods of data processing and the options for objecting (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.

We would also like to point out that, in the case of requests for information and the exercise of data subjects’ rights, these can most effectively be exercised by contacting the service providers directly. Only the service providers have access to users’ data in each case and can take appropriate action and provide information directly. Should you nevertheless require assistance, please do not hesitate to contact us.

  • Types of data processed: Contact details (e.g. email, telephone numbers); content data (e.g. entries in online forms); Usage data (e.g. webpages visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).

  • People affected: Users (e.g. website visitors, users of online services).

  • Purposes of processing: Enquiries and communication; feedback (e.g. collecting feedback via an online form); marketing.

  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

Changes to and updates of the Privacy Policy

We ask that you review the content of our privacy policy on a regular basis. We will update the privacy policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.

Where we provide addresses and contact details for companies and organisations in this privacy policy, please note that these details may change over time, and we ask that you check them before getting in touch.

Rights of data subjects

As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:

  • Right to object: You have the right, on grounds relating to your particular circumstances, to object at any time to the processing of personal data relating to you carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If the personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.

  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time.

  • Right of access: You have the right to request confirmation as to whether the data in question is being processed, and to request access to this data, as well as further information and a copy of the data, in accordance with the statutory requirements.

  • Right to rectification: In accordance with the statutory provisions, you have the right to request that the data relating to you be completed or that any inaccurate data relating to you be rectified.

  • Right to erasure and restriction of processing: In accordance with the statutory provisions, you have the right to request that data relating to you be erased without delay, or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of the data.

  • Right to data portability: You have the right to receive the data concerning you that you have provided to us, in accordance with the statutory requirements, in a structured, commonly used and machine-readable format, or to request that it be transferred to another data controller.

  • Complaint to the supervisory authority: In accordance with the statutory provisions and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State in which you habitually reside, the supervisory authority for your place of work or the location of the alleged infringement, should you consider that the processing of personal data relating to you infringes the GDPR.

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the law and are defined, in particular, in Article 4 of the GDPR. The legal definitions are binding. The explanations below, however, are primarily intended to aid understanding. The terms are listed in alphabetical order.

  • Conversion tracking: Conversion tracking (also known as ‘visit-action analysis’) is a method used to determine the effectiveness of marketing measures. To do this, a cookie is usually stored on users’ devices whilst they are on the websites where the marketing measures are carried out, and is then retrieved again on the destination website. For example, this enables us to track whether the adverts we have placed on other websites have been successful.

  • Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject person”); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

  • Profiles containing user-specific information: The processing of “profiles containing user-related information”, or “profiles” for short, encompasses any form of automated processing of personal data that involves the use of such personal data to identify specific personal aspects relating to a natural person (depending on the nature of the profiling, this may include various information regarding demographics, behaviour and interests, such as interaction with websites and their content, etc.) to analyse, evaluate or predict them (e.g. interests in specific content or products, clicking behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.

  • Range measurement: Audience measurement (also known as web analytics) is used to analyse visitor traffic to an online service and may encompass visitors’ behaviour or their interest in specific information, such as website content. With the help of audience analysis, website owners can, for example, identify at what times visitors access their website and what content they are interested in. This enables them, for example, to better tailor the website’s content to the needs of their visitors. For the purposes of audience analysis, pseudonymous cookies and web beacons are frequently used to identify returning visitors and thus obtain more accurate analyses of the use of an online service.

  • Data controller: The term ‘controller’ refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

  • Processing: "Processing" means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, whether it be collection, analysis, storage, transmission or erasure.