Privacy Policy | EXC GmbH

Privacy Policy of EXC GmbH

The German version of the General Terms and Conditions forms the legal basis. Translation errors​​ are not legally applicable.

Thank you for your interest. The protection of your privacy and your personal data is very important to us. The collection and use of your data is therefore always carried out in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the relevant provisions. In the following, we - as the person responsible for data processing - therefore inform you about which data is collected by us and in what way we process this data.

1 Responsible persons within the meaning of data protection

1.1 Responsible for data processing

The controller within the meaning of Art. 4 No. 7 of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection regulations is


EXC GmbH
Nymphenburger Straße 86
80636 München
Germany
Telefon: +49 89 125033980
Fax: +49 89 125033999
info@exc.de
www.exc.de

1.2 Contact details of the data protection officer

You can reach our data protection officer at the above-mentioned postal address as well as by e-mail at: info@exc.de

2 Legal basis for the processing of personal data

Insofar as we obtain the consent of the data subject for the processing of personal data, Art. 6 para. 1 lit. a EU General Data Protection Regulation (GDPR) serves as the legal basis.For the processing of personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 6 para. 1 lit. b GDPR serves as the legal basis. This also applies to processing operations that are necessary for the implementation of pre-contractual measures. Insofar as the processing of personal data is necessary to fulfil a legal obligation to which our company is subject, Art. 6 para. 1 lit. c GDPR serves as the legal basis.In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 lit. d GDPR serves as the legal basis.If the processing is to safeguard a legitimate interest of our company. If the interests, fundamental rights and freedoms of the data subject do not outweigh the first interest, Art. 6 para. 1 lit. f GDPR serves as the legal basis for the processing.

3 Data deletion and storage period

The personal data of the data subject will be deleted or blocked as soon as the purpose of storage no longer applies. Storage may also take place if this has been provided for by the European or national legislator in EU regulations, laws or other regulations to which the controller is subject. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfilment of a contract.


4 Creation of log files

Each time our website is accessed, our system automatically collects data and information from the computer system of the calling computer.The following data is collected:

• Date and time of access
• The IP address of the user
• Product and version information of the browser used (user agent)• The operating system of the user
• Content of the www.exc.de Cookies set
• Website visited
• Amount of data sent in bytes
• Status and the websites from which the user came to our website (Referrer)

The data is also stored in the log files of our system. A storage of this data together with other personal data of the user does not take place. We evaluate these log files exclusively for statistical purposes. The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user's computer. For this purpose, the IP address of the user must remain stored for the duration of the session. The legal basis for the temporary storage of the data is Art. 6 para. 1 lit. f GDPR. Our legitimate interest in temporary storage in log files results from optimising our website by analysing usage behaviour and server load in relation to days and times. In addition, we can detect possible errors through the log files, e.g. incorrect links or program errors, and thus use the log files for the improvement and further development of our website. The data will be deleted in accordance with Art. 17 para. 1 lit. a GDPR as soon as they are no longer necessary to achieve the purpose for which they were collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended. If the data is stored in log files, this is the case after 10 days at the latest. Further storage is possible. In this case, the IP addresses of the users are deleted or alienated, so that an assignment of the calling client is no longer possible. The collection of data for the provision of the website and the storage of the data in log files is absolutely necessary for the operation of the website. Consequently, there is no possibility of objection on the part of the user.


5 Webshop

For an order in the webshop, it is necessary for the conclusion of the contract that you as a user provide your personal data and register, whereby we store your data for later further purchases in your customer account. Mandatory information required for the execution of the contracts is marked separately, further information is voluntary. The following personal data will be processed when you place your order:


• Company name
• Customer number
• VAT ID number
• Salutation
• Surname and first name
• Company address
• Telephone and fax number
• E-mail address

In addition, the following personal data will be processed by you in the role of customer:

• Salutation
• Surname and first name
• E-mail address



For the sake of the environment, the invoice will be sent by e-mail.For this purpose, the following personal data will be processed by you:

• Company name
• Name of the contact person
• E-mail address
• Customer number
• Address
• Telephone number



To prevent unauthorized access by third parties to your personal data, the order process is transmitted over the Internet using SSL encryption. You can recognize such encrypted connections by the prefix ''https://'' in the page link in the address bar of your browser.We process your data for the order processing of your purchase and any subsequent warranty processing. The legal basis for the processing of your personal data for order processing is Art. 6 para. 1 lit. b GDPR. The legal basis for the processing of your personal data in the context of sending e-mails is Art. 6 para. 1 lit. a GDPR. The data will be deleted in accordance with Art. 17 para. 1 lit. a GDPR as soon as they are no longer necessary to achieve the purpose for which they were collected. Due to commercial and tax regulations, we are obliged to store your address, payment and order data for a period of ten years. However, after two years, we impose a restriction on processing, i.e. Your data will only be used to comply with legal obligations. You can have the data stored about you changed at any time. Please send an e-mail to info@exc.de or contact your personal account manager.


6 Registration

On our website, we offer users the opportunity to register by providing personal data. The data is entered into an input mask and transmitted to us and stored. The following personal data is collected as part of the registration process:


• Salutation, title if applicable
• First and last name
• Company
• Customer number
• Company address
• VAT ID number
• Email address
•Telephone number

At the time of registration, the following data is also stored:


• The IP address of the user
• Date and time of registration
• HTTP referrer (origin information)
• Browser type used
Your personal data will only be passed on to service providers used by us in the context of the execution of the order. These are limited to:

• Freight forwarders and parcel service providers

The legal basis for the processing of personal data is Art. 6 para. 1 lit. a GDPR if the user has given his consent. The data will be deleted in accordance with Art. 17 para. 1 lit. a GDPR as soon as they are no longer necessary to achieve the purpose for which they were collected. This is the case for the data collected during the registration process if the registration on our website is cancelled or changed. As a user, you have the option of cancelling the registration and revoking the processing of your personal data at any time. You can have the personal data stored about you changed at any time. Please send an e-mail to:
info@exc.de.

6.1 Contact form

On our website we offer you the opportunity to contact us. For this purpose, we provide you with a contact form. If you send us information or inquiries via our contact form, the following personal data will be processed:

• Full name
• Name of the company
• E-mail address
• Telephone number
• Content of your message


Your data will be processed exclusively for the purpose of taking note of the information or answering the request by EXC GmbH. Your personal data will not be passed on to third parties. The legal basis for the processing of personal data collected in this context is Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest results from the fact that we help you with your request or would like to answer your request and require certain personal data in order to be able to assign the request to a person. You can object to data processing for this purpose at any time (see section 18 of the data protection declaration). We only store your personal data from the contact form for as long as it is necessary for the intended purpose. As a rule, we delete your personal data provided in this context after your request has been processed.If the type or content of your request is subject to a retention period under commercial or tax law, we will store your personal data in accordance with the retention period required by law and then delete it.

7 Newsletter

On our website it is possible to subscribe to a free newsletter. For the dispatch of the newsletter, the following personal data will be processed by you:


• Company
• Salutation
• First and last name
• E-mail address
• IP address
• Country

Your data will be processed exclusively for the purpose of taking note of the information or answering the request by EXC GmbH. Your personal data will not be passed on to third parties. The legal basis for the processing of personal data is Article 6 (1) (a) GDPR. Accordingly, the newsletter will only be sent on the basis of your consent.The data will be deleted in accordance with Art. 17 para. 1 lit. a GDPR as soon as they are no longer necessary to achieve the purpose for which they were collected. As a user, you have the right to object to the use of personal data for the purpose of sending the newsletter at any time in accordance with Article 21 (2) GDPR. To exercise your right to object, you will find a corresponding unsubscribe link in each newsletter.

8 Complaints

As a user, we offer you the opportunity to return defective or incorrectly delivered items to us. For the best possible processing, we provide you with the form ''RMA Request''. In addition to the complaint information, we process the following personal data from you for the processing of the process:

• Company

• First and last name

• Address

• Telephone and fax number

• E-mail address

• Customer number


The processing of the above-mentioned personal data serves to process the complaint. The name and address of the user are required for the identification of you as well as for the assignment of the ordered goods. If we have any doubts about your complaint details, we will use your telephone or fax number as well as the e-mail address you provided to contact you. The legal basis for the processing of your personal data is Article 6 (1) (b) GDPR. The processed data will be deleted in accordance with Art. 17 para. 1 lit. a GDPR as soon as they are no longer necessary to achieve the purpose for which they were collected. Please note that due to commercial and tax law requirements, we are obliged to store your address, payment and order data for a period of ten years.

9 Application management

We look forward to receiving your application for a position in our company and the interest you have shown. Since we process your personal data as part of the application process, we will inform you below about the details of the handling of your personal data.We only process personal data that you have provided to us in connection with your application in order to check your suitability for the corresponding position (or another open position). The legal basis for the processing of your personal data for the purpose of your aptitude test for the advertised position is § 26 para. 1 BDSG (Federal Data Protection Act new version) in conjunction with Art. 6 para. 1 lit. b GDPR. After this period, the processing of your personal data is still permitted insofar as it is necessary to establish an employment relationship. After receipt of your applicant data, your documents will be viewed by the HR department. Your applicant data may be passed on to those responsible for the department. In principle, only those persons who need it for the proper running of our application process have access to your data. Your personal data will be deleted in the role of applicant in the event of a rejection in accordance with Art. 17 para. 1 lit. a GDPR as soon as they are no longer necessary for the purposes of the processing. Should the personal data continue to be required after completion of the application process, the data processing may be carried out on the basis of Art. 6 para. 1 lit. f GDPR to safeguard legitimate interests. Our legitimate interest then arises from the assertion or defence of legal claims. In this case, however, the storage period shall not exceed six months. You have the right to object to the processing within the framework of the legal requirements.

10 Use by Minors

Minors may not transmit any personal data to us without the consent of their legal guardians. As part of the website, we do not process any knowingly obtained personal data of minors.


11 Right of access

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:As a data subject within the meaning of the GDPR, you have the right to information on the part of the controller about the personal data concerned in accordance with Article 15 GDPR, and the right to rectification in accordance with Article 16 GDPR, pursuant to Article 17 GDPR, the right to erasure, pursuant to Article 18 GDPR, the right to restriction of processing, pursuant to Article 21 GDPR, the right to object to processing and pursuant to Article 20 GDPR, the right to data portability. In the case of the right to information and the right to erasure, the restrictions in accordance with §§ 34 and 35 BDSG-neu also apply.Furthermore, you have the right to information as to whether you have been subject to an automated decision in accordance with Art. 22 paragraphs 1 and 4 GDPR, pursuant to Art. 15 para. 2 GDPR whether your personal data and under which guarantees are transmitted to a third country and whether a right of appeal to the competent data protection supervisory authority in accordance with Art. 77 GDPR in conjunction with § § 19 BDSG-new. To exercise your right to information, please contact us in writing with a clear identification of your person:

EXC GmbH
Nymphenburger Strasse 86
80636 Munich
Germany
dataprotection@exc.de


12 Transfers of personal data to a third country

A transfer of personal data to bodies in countries outside the European Union (so-called third countries) takes place insofar as• it is necessary for the execution and processing of a contract• it is required by law• You have given us your consentOur company uses service providers for certain tasks who have their registered office in a third country or for a international group with companies in third countries or which in turn cooperate with service providers based in a third country. A transfer of personal data to such service providers is permissible if the European Commission has decided that an adequate level of protection exists in the third country concerned (in accordance with Art. 45 GDPR). If the Commission has not taken such a decision, our company or the service provider may only transfer personal data to a third country or to an international organisation if appropriate safeguards are provided and enforceable rights and effective remedies are available (Art. 46 para. 1 GDPR). Beyond the aforementioned cases, our company does not transfer any personal data to offices in third countries or to international organizations.


13 Right to information / right of revocation; further rights of data subjects

You have the right to:
• in accordance with Article 15 GDPR, to request information about your personal data processed by us. In particular, you can find out about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to correction, deletion, restriction of processing or objection, the existence of a right of appeal, the origin of your data, if not collected by us, as well as the existence of automated decision-making including profiling and, where applicable, meaningful information on their details;
• in accordance with Article 16 GDPR, to demand the correction of incorrect or completion of your personal data stored by us without undue delay;
• in accordance with Article 17 GDPR, to request the deletion of your personal data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, for the fulfilment of a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
• to demand the restriction of the processing of your personal data in accordance with Article 18 GDPR, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you reject its deletion and we no longer need the data, but you need it to assert, exercise or defend legal claims or you have objected to the processing in accordance with Article 21 GDPR;
• in accordance with Article 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request the transmission to another controller;
• in accordance with Article 7 (3) GDPR, to revoke your consent to us at any time. As a result, we may no longer continue the data processing based on this consent for the future and
• to complain to a supervisory authority in accordance with Article 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.
To revoke your consent to the use of data, to request information or the correction, blocking or deletion or to exercise the other rights of data subjects, please contact:


EXC GmbH
Nymphenburger Straße 86
80636 Munich
Germany
info@exc.de

Status: June 2022