Declaration of data security and information of the data subjects pursuant to Article 13 and Article 14 of the EU General Data Protection Regulation

BHS Corrugated Maschinen- und Anlagenbau GmbH (hereinafter “BHS Corrugated”, “we” or “us”) are pleased about your interest in our enterprise. Data protection is very important for the management of BHS Corrugated. The use of our website is generally possible without any indication of personal data. However, if special services provided by BHS Corrugated via our website are used, processing of personal data may be necessary. If there is no legal basis for a necessary processing of personal data, we generally obtain the consent of the data subject.

The processing of personal data of the data subject, as name, address, e-mail address, or telephone number shall always be compliant with the General Data Protection Regulation (hereinafter “GDPR”), and with the country-specific data protection regulations applicable to BHS Corrugated. The aim of this data protection declaration is to inform the public about nature, scope, and purpose of the personal data that is collected, used, and processed by BHS Corrugated. Furthermore, data subjects are informed about their rights according to GDPR.

As controller, BHS Corrugated has implemented numerous technical and organizational measures to ensure a high level of protection of personal data processed by this website. However, web-based data transmissions may in principle have security gaps, so an absolute protection may not be guaranteed. For this reason, every data subject is free to transfer personal data to us via alternative means, e.g., by telephone.

1. Definitions
The data protection declaration of BHS Corrugated is based on the terms used by the European legislature for the adoption of the General Data Protection Regulation (GDPR). Our privacy policy should be legible and understandable for the public, as well as our customers and business partners. To ensure this, we would like to explain the terms used in our declaration. In this data protection declaration, the following terms are used:

a) Personal data
Personal data means any information relating to an identified or identifiable natural person (hereinafter “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or according to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

b) Data subject
Data subject is any identified or identifiable natural person, whose personal data is processed by the controller responsible for the processing.

c) Processing
Processing is any operation or set of operations which is performed on personal data or on sets of personal data, either without or with automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other way of provision, alignment or combination, restriction, erasure, or destruction.

d) Restriction of processing
Restriction of processing means labeling of stored personal data to limit their processing in the future.

e) Profiling
Profiling is any type of automated processing of personal data using this data to evaluate certain personal aspects, to analyze or predict aspects relating to that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or change of location.

f) Pseudonymization
Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without using additional information, provided that such additional information is stored separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

g) Controller or responsible for the processing
The Controller or the responsible for the processing is a natural or legal person, public authority, agency or other body which, alone or jointly with other parties, determines the purposes and means of the processing of personal data. If the purposes and means of such processing are determined by EU or Member State law, the controller or the specific criteria for its nomination may be provided according to EU or Member State law.

h) Processor
Processor is a natural or legal person, public authority, agency, or any other body which processes personal data on behalf of the controller.

i) Recipient
A recipient is a natural or legal person, public authority, agency, or any other body, to whom the personal data are disclosed (no matter whether it is a third party or not). However, public authorities that may receive personal data related to a particular inquiry in accordance with EU or Member State law shall not be regarded as recipients; the processing of those data by those specific public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.

j) Third party
A third party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor and persons authorized to process personal data by the controller or processor.

k) Consent
Consent of the data subject is any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of his/her personal data.

2. Name and address of the controller
Controller according to GDPR, other data protection laws applicable in Member states of the European Union and other provisions related to data protection is:

BHS Corrugated Maschinen- und Anlagenbau GmbH
Paul-Engel-Str. 1
92729 Weiherhammer
Germany

Phone: + 49 (0) 9605 919 - 0
E-mail: info@bhs-world.com
Website: www.bhs-world.com

3. Contact of the Data Protection Officer
Email: datenschutz@bhs-world.com
Any data subject may contact our Data Protection Officer directly and at any time with any questions or suggestions regarding data protection.

4. Cookies
The websites of the BHS Corrugated use cookies. Cookies are text files that are stored in a computer system by a browser.
Numerous websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie and consists of a string of characters by which websites and servers can be assigned to the specific browser where the cookie was stored. This enables visited websites and servers to distinguish the individual browser of the data subject from other browsers containing other cookies. A specific browser can be recognized and identified using the unique cookie ID.
The usage of cookies enables BHS Corrugated to provide users of this website with more user-friendly services that would not be possible without cookie setting.
Due to a cookie, the information and offers on our website can be optimized according to the user behavior. Cookies allow us, as previously mentioned, to recognize our website users. The purpose of this recognition is to make it easier for users to use our website. For example, the user of a website using cookies does not have to enter his/her access data each time the website is accessed, because this is handled by the website and the cookie stored on the user's computer system. Another example is the cookie of a shopping cart in an online store. The online store remembers articles that a customer has placed in the virtual shopping cart via a cookie.
The data subject may prevent the setting of cookies by our website at any time by an appropriate setting of the browser used and therefore permanently deny the setting of cookies. Furthermore, cookies that have already been set may be deleted at any time via the browser or any other software program. This is possible in all common browsers. If the data subject deactivates the setting of cookies in the browser used, not all functions of our website may be entirely usable.

5. Collection of general data and information
The website of the BHS Corrugated collects a series of general data and information with each call-up of the website by a data subject or automated system. This general data and information are stored in the log files of the server. The following data may be collected: (1) browser types and versions used, (2) operating system used by the accessing system, (3) website from which an accessing system accesses our website (so-called referrer), (4) sub-websites that are accessed via an accessing system on our website, (5) date and time of an access to the website, (6) internet protocol address (IP address), (7) internet service provider of the accessing system and (8) other similar data and information that serve to avert danger in the event of attacks on our information technology systems.
When using these general data and information, BHS Corrugated does not draw any conclusions about the data subject. This information is rather needed (1) to deliver the contents of our website correctly, (2) to optimize the contents of our website and advertising, (3) to ensure the long-term functionality of our information technology systems and the technology of our website, and (4) to provide law enforcement authorities with the information necessary for prosecution in the event of a cyber-attack. Therefore, BHS Corrugated analyzes anonymously collected data and information on the one hand for statistical reasons and on the other hand for the purpose of increasing the data protection and data security of our company, as well as to ensure an optimal level of protection for the personal data processed. The anonymous data of the server log files are stored separately from any personal data submitted by a data subject.

6. Registration on our website
The data subject has the possibility to register on the website of the controller by providing personal data. The necessary personal data that is transmitted to the controller due to the registration process is determined by the respective registration mask. The personal data entered by the data subject are collected and stored exclusively for internal use by the controller and for its own purposes. The controller may request transfer to one or more processors (e.g., a parcel service) who also use the personal data for an internal use attributable to the controller.
By registering on the website of the controller, the IP address assigned by the internet service provider (ISP) of the data subject, the date as well as the time of registration are stored. The storage of this data is necessary to prevent the misuse of our services and if necessary, the stored data will help to expose committed crimes. Thus, the storage of this data is necessary to secure the data controller himself. This data is not passed on to third parties unless there is a statutory obligation to pass on the data, or if the transfer serves the aim of criminal prosecution.
The registration of the data subject, with the voluntary indication of personal data, is intended to enable the controller to offer the data subject contents or services that may only be offered to registered users according to the type of content/service. Registered persons can modify the personal data provided during registration at any time or to have it deleted from the data stock of the controller.
Upon request, the controller shall provide information regarding what personal data is stored of the respective data subject. Furthermore, the controller shall correct or delete personal data upon request or indication of the data subject under the restriction that this is not in conflict with any statutory retention obligations. The data subject may address his request so all employees of the controller.

7. Subscription to our newsletters
Users of the website of BHS Corrugated have the possibility to subscribe to the newsletter of BHS Corrugated. The personal data transmitted to the controller when subscribing for the newsletter is defined by the masks that must be filled in. For this service we use INXMAIL as a service provider (please also see www.inxmail.com/data-conditions). A data processing agreement has been concluded with INXMAIL. Your rights remain unaffected hereof.
BHS Corrugated informs its customers and business partners regularly about offers or company information with this newsletter. For receiving our newsletter, the data subject (1) needs a valid e-mail address and (2) needs to register for the newsletter mailing. For legal reasons and to secure the double-opt-in procedure, a confirmation e-mail is sent to the e-mail address entered by the data subject after registration. This confirmation e-mail is used to verify if the owner of the e-mail address is the data subject that has given the authorization to obtain the newsletter.
By registering for the newsletter, we also store the IP address of the computer system assigned by the Internet service provider (ISP) and used by the data subject at the time of the registration, as well as the date and time of the registration. The collection of this data is necessary to trace (possible) future misuse of the e-mail address of a data subject and it therefore serves the legal protection of the controller.
The personal data collected due to the newsletter registration will only be used to send our newsletter. In addition, subscribers to the newsletter may be informed by e-mail, if this is necessary for the operation of the newsletter service or a related registration, e.g., in the event of modifications to the newsletter offer, or in the event of a change in technical circumstances. The personal data collected is not transferred to third parties, except the newsletter service provider INXMAIL. The subscription to our newsletter may be terminated by the data subject at any time. The consent of the data subject to store the personal data for newsletter dispatch, can be revoked at any time. To revoke the consent a corresponding link can be found in each newsletter. Furthermore, it is possible to unsubscribe the newsletter mailing directly on the website of the controller at any time or to inform the controller of the un-subscription in any other way.

8. Newsletter-Tracking
The newsletters of BHS Corrugated contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in e-mails, which are sent in HTML format to enable log file recording and analysis. This enables a statistical analysis of the success or failure of online marketing campaigns. Based on the embedded tracking pixel BHS Corrugated may track if and when an e-mail was opened by a data subject, and which links in the e-mail were called up by data subjects.
The personal data collected via tracking pixels included in the newsletters are stored and analyzed by the controller to optimize newsletter dispatch, as well as to adapt the content of future newsletters according to the interests of the data subjects. These personal data will not be passed on to third parties. Data subjects are entitled to revoke the respective declaration of consent at any time via the double-opt-in procedure. After a revocation, the respective personal data will be deleted by the controller. A withdrawal from receiving the newsletter is regard as revocation automatically by BHS Corrugated.

9. Contact information on the website
Due to legal requirements the website of BHS Corrugated contains information that enables a quick electronic contact, as well as direct communication with us. This also includes a general address of the so-called electronic mail (e-mail address). If a data subject contacts the controller by e-mail or via contact form, the personal data transmitted by the data subject are automatically stored. Such personal data transmitted by a data subject on a voluntary basis to the data controller are stored for the purpose of processing or contacting the data subject. A disclosure of the respective personal data to third parties does not take place.

10. Routine erasure and blocking of personal data
The controller processes and stores personal data of the data subject only for the period necessary to achieve the purpose of processing personal data, or as long as the storage is permitted by European or national law to which the controller is subject to.
If the purpose to store personal data is no longer applicable or if a storage period prescribed by the European or national law expires, the personal data will be routinely blocked or erased in accordance with legal requirements.

11. Rights of the data subject
In addition, you can assert your rights to information, correction, deletion or to restriction of processing or your right to object to the processing and the right to data portability at any time. Please find the details for contacting us by e-mail or letter in the legal notice. Moreover, you have the right to contact the data protection supervisory authority in the event of complaints.

12. Data protection for applications and application procedures
12.1 Purpose of processing and legal basis
During an application process personal data like title, surname, first name as well as the contact details such as postal address, e-mail address and telephone numbers is stored in the database for applications. In addition to that, application documents such as cover letter, curriculum vitae, professional, educational, and training qualifications, as well as job references are recorded. This data is only stored, evaluated, processed, or forwarded internally due to your application. The personal information is only accessible to employees of the HR department and the persons responsible for the selection of applicants. The data may be processed for statistical purposes (e.g. reporting). However, in this case it is not possible to draw conclusions about individual persons. If you have consented that your application data can be stored in the application talent pool, we will use your data to fill future vacancies. We process your personal data to carry out pre-contractual measures pursuant to Art. 6 para.1 lit.b GDPR. If you have separately agreed to the storage of your personal data for the period after the end of the application process (talent pool), the data processing will be carried out in accordance with Art. 6 para.1 lit.a DSGVO.

12.2 Recipients of personal data
Your data will not be disclosed to companies or persons outside BHS Corrugated unless required by law.

12.3 Data Transfer to a third country
A transfer of data to a third country does not take place.

12.4 Storage period of personal data
If you get an acceptance and join BHS Corrugated as employee your application will be part of our personnel file. In case of a rejection your data will be stored for 6 months after completion of the application process and deleted, if there are no other legitimate interests of the controller that prevent deletion. Other legitimate interest is e.g., to provide evidence in proceedings under the General Equal Treatment Act (AGG).

12.5 Provision of personal data
The provision of personal data is necessary for an application at BHS Corrugated. If the personal data is not provided, you cannot be considered for filling job vacancies.
If you do not agree to the further storage of your application data in the so-called talent pool, we will not be able to consider you for filling future job vacancies.

13. Privacy policy for the use of applications

YouTube
YouTube components are integrated on this website. The collection of personal data when embedding a YouTube video is not our responsibility.
YouTube is a web video portal that allows publishers of videos to post video clips free of charge as well as other users to view, rate and comment on them free of charge. YouTube allows the publication of all types of videos. That is why complete film and TV shows, but also music videos, trailers or videos made by the users themselves can be accessed via the web portal.
The operating company of YouTube is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.
Each time one of the individual pages of this website operated by the controller and including a YouTube component (YouTube video) has been called up by the data subject, the browser on the information technology system of the data subject will cause a download of the respective YouTube component from YouTube for representation. Further information on YouTube can be found at www.youtube.com/yt/about/de. Within the scope of this technical procedure, YouTube and Google get to know which specific subpage of our website was visited by the data subject.
If the data subject is logged in to YouTube at the same time, YouTube recognizes which specific subpage of our website containing a YouTube video was called up by the data subject. This information is collected by YouTube and Google and assigned to the respective YouTube account of the data subject.
YouTube and Google always receive information that the data subject has visited our website via the YouTube component, if the data subject is logged into YouTube at the same time as calling up our website, regardless of whether the data subject clicks on a YouTube video or not. If the data subject does not want this information to be transmitted to YouTube and Google, he or she can prevent the transmission by logging out of his or her YouTube account before accessing our website. The privacy policy published by YouTube, which can be found at www.google.de/intl/de/policies/privacy, provides information about the collection, processing and use of personal data by YouTube and Google.

WhatsApp (use of app only)
WhatsApp is a messenger service from Meta. The company's registered office is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Personal media data is evaluated in the USA. See www.whatsapp.com/privacy and www.whatsapp.com/legal/business-terms.
For more information on WhatsApp data transfer, please visit www.whatsapp.com/legal/business-data-transfer-addendum-20210927.
We offer our customers, partners, and applicants the possibility to contact us via the messenger service WhatsApp.
If you contact us via the messenger service WhatsApp, your mobile number is automatically sent to us but will not be assigned to your contact data and will not be used by BHS for further contact. Legal declarations (such as offers, contracts or contract amendments) via WhatsApp are not accepted. For the data protection agreement please see: www.whatsapp.com/legal/business-data-processing-terms.

Google Analytics
Based on your consent, we use Google Analytics, a web analytics service provided by Google Inc (hereinafter "Google"). Consent is given by setting the appropriate option in the cookie banner. Google uses cookies. The information regarding the online behavior of the data subject generated by the cookie is usually transmitted to a Google server in the USA and stored there.
Google will use this information on our behalf to evaluate the use of our online offer, to compile reports on the activities within this online offer and to provide us with other services related to the use of this online offer and the Internet. Therefore, pseudonymous usage profiles of the users can be created from the processed data.
We use Google Analytics to display ads placed within Google's advertising services and those of its partners only to users who have shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited), which we transmit to Google (so-called "Remarketing Audiences" or "Google Analytics Audiences"). With the help of Remarketing Audiences, we also want to ensure that our ads correspond to the potential interest of users and do not have a harassing effect.
We only use Google Analytics with IP anonymization. This means that the IP address of the user is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases the full IP address will be transferred to a Google server in the USA and shortened there.
The IP address transmitted by the user's browser is not merged with other data from Google. Users can prevent the storage of cookies by setting their browser software accordingly; users can also prevent the collection of data generated by the cookie and related to their use of the online offer to Google as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout.
More information about Google’s use of data, settings and objection options can be found on Google’s websites:

Google Tag Manager
Furthermore, we may use "Google Tag Manager" (if consent for this has been obtained) to integrate and manage Google analysis and marketing services on our website.
For more information on the use of data for marketing purposes by Google, please refer to the overview page: www.google.com/policies/technologies/ads,  Google's privacy policy is available at www.google.com/policies/privacy. If you want to object to interest-based advertising by Google marketing services, you can use the settings and opt-out options provided by Google: www.google.com/ads/preferences .

Facebook
The controller has integrated components of Facebook on his website. Facebook is a social network. A social network is a place for social encounters on the Internet, an online community that usually allows users to communicate and interact with each other in a virtual space. A social network can serve as a platform for sharing opinions and experiences or allow the community to provide personal or business-related information. Among other things, Facebook allows users to create private profiles, upload photos and make contacts through friend requests.
The operating company of Facebook is Facebook, Inc. with its registered office at 1 Hacker Way, Menlo Park, CA 94025, United States. For persons living outside the United States or Canada, the controller is Facebook Ireland Ltd. with its registered office at 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Each time, one of the pages of this website operated by the controller and including a Facebook component (Facebook plug-ins) is called up, the Internet browser on the information technology system of the data subject, automatically causes a download of the corresponding Facebook component from Facebook. An overview of all Facebook plug-ins can be found at https://developers.facebook.com/docs/plugins/. Within the scope of this technical procedure, Facebook knows which specific sub-page of our website is visited by the data subject.
If the data subject is logged in to Facebook at the same time when calling up our website, Facebook recognizes which specific subpage of our website is visited by the data subject each time the data subject calls up our website and for the entire duration of the respective stay on our website. This information is collected via the Facebook component and linked to the respective Facebook account of the data subject. If the data subject clicks on one of the Facebook buttons integrated on our website, e.g. the "Like" button, or if the data subject makes a comment, Facebook assigns this information to the personal Facebook user account of the data subject and stores the personal data.
Facebook always receives information about the visit to our website by the data subject via the Facebook component if the data subject is logged in to Facebook at the same time as calling up our website. This occurs regardless of whether the data subject clicks on the Facebook component or not. If such transmission of information to Facebook is not desired by the data subject, he or she can prevent the transmission by logging out of his or her Facebook account before accessing our website.
The privacy policy published by Facebook, which can be accessed at www.facebook.com/privacy/policy/ provides information about the collection, processing and use of personal data by Facebook. In addition, it explains which setting options Facebook offers to protect the privacy of the data subject. In addition, various setting options are provided to prevent the transfer of data to Facebook. These applications can be used by the data subject to prevent data transmission to Facebook.

Google AdWords
The controller has integrated Google AdWords on this website. Google AdWords is a service for Internet advertising that allows an advertiser to place ads in the results of Google search engine and Google advertising network. Google AdWords allows an advertiser to define specific keywords in advance, that help to only display ads in Google search results when the user uses the search engine to retrieve a keyword-relevant search result. In the Google advertising network, the ads are distributed to relevant web pages with the help of an automatic algorithm considering the previously defined keywords.
Provider of Google AdWords is Google Inc., with its business at 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, UNITED STATES.
The purpose of Google AdWords is to promote our website by displaying relevant advertising on third-party websites and results of Google search engine, as well as a display of third-party advertising on our website.
If a data subject accesses our website via a Google ad, Google will store a conversion cookie on the data subject's information technology system. The definition of cookies is explained above. A conversion cookie loses its validity after 30 days and is not used to identify the data subject. If the cookie has not expired yet, the conversion cookie is used to check whether certain sub-pages, e.g., the shopping cart from an online store system, have been called up on our website. Through the conversion cookie, both Google and the controller can track whether a person who has called up an AdWords ad on our website has generated a sale, i.e., has made or cancelled a purchase of goods.
The data and information collected by the conversion cookie is used by Google to compile statistics for visits of our website. These statistics are used to determine the total number of users targeted through AdWords ads, to determine the success or failure of individual AdWords ads, and to optimize our AdWords ads in the future. Neither our company nor other Google AdWords advertisers receive information from Google with which it is possible to identify the data subject.
The conversion cookie stores personal information, e.g., the internet pages visited by the data subject. Whenever our websites are visited, personal data, including the IP address of the internet access used by the data subject, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may disclose this personal data collected through the technical process to third parties.
The data subject can prevent the setting of cookies by our website, as already described above, at any time by an appropriate setting of the Internet browser used and thus permanently object to the setting of cookies. Such a setting of the Internet browser used would also prevent Google from setting a conversion cookie on the information technology system of the data subject. In addition, a cookie set by Google AdWords can be deleted at any time in the browser or other software programs.
The data subject has the option to object to Google's interest-based advertising, provided that prior consent has been given via the cookie banner. To do this, the data subject must call up the link www.google.de/settings/ads from each of the browsers used and make the desired settings. Further information and the applicable Google privacy policy can be found at www.google.com/intl/en/policies/privacy.

Hotjar
This website uses Hotjar. Provider is Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe (Website: www.hotjar.com).
Hotjar is a tool for analyzing your user behavior on the website. As you browse our website, Hotjar automatically collects information about your user behavior. To be able to collect this information, we have included our own tracking code on our website. The following information may be collected about your computer or browser: IP address of your computer (collected and stored in an anonymous format), screen size, browser info (which browser, which version, etc.), your location (but only the country), your preferred language setting, visited web pages (sub-pages), date and time of access to one of our sub-pages (web pages), moreover, cookies also store data that are placed on your computer (usually in your browser).
Furthermore, we can determine how long you stayed on a page and when you left it.
We can use Hotjar to collect direct feedback from website visitors. This function helps to improve the website operator's web offerings.
Hotjar uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or use of device fingerprinting). The use of this analysis tool is based on Art. 6 para. 1 lit. a GDPR.
Hotjar has imposed a 365-day data retention period on itself. This means that all data collected by Hotjar that is older than one year is automatically deleted.

Azure (just for use of www.icorr.io)

For the registration process (for using our iCorr® Digital Hub) we use Microsoft Azure. Provider is Microsoft Corporation One Microsoft Way Redmond, WA 98052-6399 USA.

Microsoft processes your data i.a. in the US. For processing personal data based in third countries Microsoft uses standard contractual clauses (Art. 46 GDPR). For more information on Microsoft standard contractual clauses see: https://learn.micrsoft.com/en-us/compliance/regulatorey/offering-eu-model-clauses.

For information how Microsoft handles your personal data see: https://privacy.microsoft.com/de-de/privacystatement.

The categories of personal data processed are name and e-mail address. The processing is carried out for the purpose of authenticating users for Single Sign On.

Recipients of personal data include external service providers or other contractors, i.e., for authorization in the respective applications, data processing and storage of the data concerned, and other external bodies to the extent that the data subject has given consent, or a transfer is permitted for prevailing interest, i.e., customers and interested parties in the context of order acquisition. In the context of execution of the contract, processors outside the European Union may also be used, if necessary, Microsoft USA. The duration of data storage depends on the statutory retention obligations and is usually 10 years.

Instagram
Functions of the Instagram service are integrated within our online offer. These functions are offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. If you are logged into your Instagram account, you can link the content of our pages to your Instagram profile by clicking on the Instagram button. This allows Instagram to associate the visit to our pages with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by Instagram. Privacy policy: instagram.com/about/legal/privacy .

LinkedIn
You can recognize the call from LinkedIn, LinkedIn, 2029 Stierlin Courtm, Mountain View, CA 94043 USA, by the "in" sign on a blue background. If you activate our "in" button as part of the 2-click solution, a connection is established with the LinkedIn server and the LinkedIn plugin is reloaded on the respective website. The content of the "in" button is transmitted by LinkedIn directly to your browser and integrated by into the website. It is possible that your IP address will be transmitted to LinkedIn in the USA. For the purpose and scope of data collection and further processing and use of data by LinkedIn, as well as your rights and setting options for protecting your privacy, please refer to LinkedIn's privacy policy (www.linkedin.com/legal/privacy-policy) for the "in" button. If you are a LinkedIn member and do not want LinkedIn to collect and store your data when using our website when the "in" button is, you must log out of LinkedIn before visiting our website.

TikTok:

The privacy policy applies to  BHS Corrugated presence at TikTok within the scope of its own responsibility as well as to the processing of your personal data within the scope of responsibility with TikTok Technology Limited (10 Earlsfort Terrace, Dublin, D02 T380, Ireland; hereinafter: TikTok). It does not extend to any linked websites or Internet presences of other providers and additionally  to the processing of personal data in the sole area of responsibility of TikTok.

We use the TikTok Business platform to promote our recruitment marketing.

The following types of technology are used when using the TikTok platform:

Cookies: Coockies are small text files that allow us and our service providers and partners to uniquely identify your browser or device for various purposes.

Local storage: Local storage files are created by apps and websites to store information locally on your device. They are very similar to cookies, but may have slightly different characteristics (e.g., local storage may be used to store more information and may be stored in a different location on your device than cookie storage). Local storage is typically used to speed up app and website functionality and to save your preferences.

Application Programmable Interface (API): An API is a piece of software that allows two or more applications to communicate with each other. We use them for communication between TikTok and our service providers.

Software Development Kits (SDKs): SDKs are pieces of code that allow data to be collected about your device, your network and your interaction with a website. Like cookies, SDKs typically work by assigning a unique number to your device.

Pixels: Pixels are small, 1 pixel by 1 pixel, invisible image files that are embedded in certain web pages. They can be used to collect information about your visit to this website.

Mobile advertising IDs: Your device has a unique number that is used by TikTok and our service providers to recognize your device. If you have given your consent, this allows us to display personalized advertising on your device and measure the effectiveness of that advertising.

You can find more information at https://www.tiktok.com/legal/page/global/cookie-policy/de.

When you use your TikTok Business account, we process personal data such as your name, your profile picture and the information you have provided as part of the interactive functions (e.g. liking, commenting, sharing and rating). The legal basis for the processing of personal data in the context of the community functions of our TikTok business presence is Art. 6 para. 1 lit. f) GDPR.  Our legitimate interest is to promote our products via the TikTok presence and to communicate with users, customers and interested parties.

TikTok uses subcontractors (such as Google or Facebook) to process the data, possibly also in third countries such as the USA. Further information on data protection at TikTok can be found at https://www.tiktok.com/legal/privacy-policy-eea?lang=de and https://www.tiktok.com/legal/tiktok-website-cookies-policy?lang=de.

We have no influence on the storage period of your personal data that you have published in relation to our TikTok content at TikTok. If statutory retention obligations exist, we will store your data until the purpose of the processing has been achieved. Further information on data protection and the storage period at TikTok can be found at https://www.tiktok.com/legal/privacy-policy-eea?lang=de.

OEE (only when using the OEE app)

When using this app, your personal data such as name/company and mail address are processed to give you access to the machine data and statistics displayed in the OEE app via a login. We do not transmit this data to third parties. We do not use any tracking tools.

In addition, please note that we store your data until it is no longer necessary to achieve the purposes for which it was collected.

iCorr® Assist Glasses (only when used)

Purpose of processing and legal basis:

With iCorr® Assist Glasses, BHS CORRUGATED has laid the foundations for access to the services specified. These are: 

  • One-time postal transmission of (1 pair of) Industrial Glasses passing into the ownership of the customer (at the customer’s request).
  • Access to the iCorr® Assist Glasses platform and the services on this platform.
  • Possibility of calling an audiovisual live support* by BHS staff.
  • Preinstalled software with corresponding license.

For the customer, an individual user account shall be set up on the iCorr® Assist Glasses platform. For access to this platform, the customer receives a link to the Assist Glasses platform by BHS CORRUGATED via which the customer is able to log in after creating its own password. After that, the customer shall receive an individualized QR code, which can then be used to log in to the hardware.

The provided software allows audiovisual contact with experienced BHS staff and thus optimum support for fault identification and troubleshooting on the corrugator. The corresponding software is already preinstalled on the provided AR device. The comprised license allows access and use of the software included in the scope of delivery. The license may be used on various devices.

The package includes the extension of the phone support by the visual component. The employees of the BHS help desk have been trained to ensure and guarantee optimum audiovisual support. The auditive and visual contact between user and BHS expert allows targeted assistance on the current technical problem, opening the way to quicker and more efficient troubleshooting. The support services are provided as part of the iCorr® Operations Support Agreement.

 As part of a pre-contractual relationship, personal data (contact details) is processed to inform interested customers. This data is used to contact the customer, which serves the following purposes:

  • specification of the details for preparation of a quotation.
  • recording and tackling customer problems, requirements, and requests, etc.

When the customer logs in to the software, its login data (mail address and password) is processed to verify the access authorization.

As part of the audiovisual support, image and voice data is processed, also used for the preparation of service reports made available to the customer on request.

Legal basis for this type of data processing is the performance of pre-contractual measures or the contractual performance pursuant to art. 6 paragraph 1 lit. b GDPR.

Audiovisual recordings during the support by the BHS CORRUGATED help desk shall not be started without the customer’s oral consent. These reports including media files are stored on servers of Messrs. Ubimax, with BHS CORRUGATED being the owner of the data.

Legal basis for recording image and voice data is the customer’s oral consent pursuant to art. 6 paragraph 1 lit. a GDPR.

During support calls, there is the possibility of creating voice and image recordings for purposes of documentation. BHS CORRUGATED may use the data for research purposes, which will improve future services when a fault whose solution was already documented in an earlier support call occurs again. The service reports can then be used as a basis for instructions.

Legal basis for data processing is a legitimate interest of the party responsible pursuant to art. 6 paragraph 1 lit. f GDPR in the improvement of the provided services.

For audiovisual support, an agreement for order processing shall be concluded with the customer.

Recipients of Personal Data: There is no intention to transfer data to third parties.

Data Transfer to a Third Country: There is no intention to transfer data to countries outside the EU.

Storage Period of the Personal Data: There is no intention to delete personal data.

Restaurant NEWS app (only when using the app)

When using this app, your personal data that you have provided to us (name, e-mail and telephone number) are processed. We collect and process your data in the course of providing our services.

The data you send to us via contact requests will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g., after we have completed processing your request). Mandatory legal provisions - in particular legal retention periods - remain unaffected.

14. Information about other data processing procedures

14.1 Specific information for the processing of customer data / prospective parties’ data

Affected data:  Data communicated for contract execution; if necessary, additional data for processing on the basis of your express consent.

Processing purpose: Contract execution, e.g, quotations, orders, order fulfillment and invoicing, quality assurance.

Categories of  recipients:

  • Public authorities in the event of priority legislation, e.g., customs
  • External service providers or other contractors, e.g., for data processing and hosting, for shipping, transport and logistics, service provider for printing and shipping of information
  • Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a prevailing interest, e.g., for creditworthiness information for purchases on account, for the electronic dispatch of information, for quality assurance purposes.

Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, among others, e-mail providers.

Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years.

14.2 Specific information on the processing of employee data

Affected data: Data communicated for contract execution; if necessary, additional data for processing on the basis of your express consent.

Processing purpose: Contract execution within the scope of employment.

Categories of recipients:

  • Public authorities in the event of priority legislation, among others tax office, social insurance agency, employers' liability insurance association.
  • External service providers or other contractors, among others data processing and hosting, payroll accounting, travel expense accounting, insurance benefits, vehicle use.
  • Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a prevailing interest among others for order acquisition, insurance benefits.

Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, among others, e-mail providers.

Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years.

14.3 Specific information for the processing of supplier data

Affected data:  Data communicated for contract execution; if necessary, additional data for processing based onyour express consent.

Processing purpose: Contract execution, e.g., , purchase orders, quality assurance.

Categories of recipients:

  • Public authorities in the event of priority legislation, e.g., tax office, customs.
  • External service providers or other contractors, e.g., for data processing and hosting, accounting, payment processing.
  • Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a prevailing interest.

Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, among others, e-mail providers.

Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years.

14.4 Specific information on the use of video conferencing/webinar software

Affected data:  Data provided for the use of the video conferencing software or webinar software (first name, surname, e-mail address; optional sound transmission, image transmission and questions when using chat functions);  To the technically necessary extent, data from your system is processed to establish the connection with the provider of the conference software.

Processing purpose: Conducting video conferences or webinars.

Categories of recipients:          

  • Public authorities in the event of overriding legal provisions.
  • External service providers or other contractors, e.g., for data processing and hosting.
  • Other external bodies if the data subject has given their consent or a transfer is permitted for reasons of overriding interest.

Third-country transfers: Processors outside the European Union are used (here: United States of America); standard contractual clauses have been concluded with the service provider accordingly.

Duration of data storage: Video conferences are only recorded with the prior documented consent of the participants. The technical data is deleted as soon as it is no longer required. The duration of data storage is determined by the statutory retention obligations and is generally 10 years.

14.5 Specific information for Customer Training

We hereby inform you about the nature, scope, and purpose of the collection and use of personal data within the framework of our customer training.

Within the scope of the customer training, we collect the following personal data:

  • First name, last name
  • Contact details (email address, telephone number)
  • Company affiliation
  • Position in the company
  • Participation and performance data (e.g., attendance, test results)

The collected data will be processed for the following purposes:

  • Conducting and organizing the training
  • Issuance of participation certificates and certificates
  • Evaluation and improvement of our training offer
  • Communication within the framework of the training (e.g., sending informational materials)

The processing of your data is based on Art. 6(1)(b) GDPR and Art. 6(1)(a) GDPR.

Your personal data will be shared with our subsidiary, C4Trends GmbH. This company conducts the training on our behalf.

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected or as required by law. Once your data is no longer needed for these purposes, it will be deleted.

15. Handling of business cards
By handing over or exchanging business cards, you provide us with personal data, such as phone number, e-mail address. We use this information exclusively to stay in contact with you. In addition, we may provide you with further information. 5 years after the purpose for which the data was collected has ceased to exist, we will delete your personal data. You have the right of information, deletion, or correction at any time.

16. Legal basis of processing
Article 6 I lit. a GDPR is the legal basis for processing operations of BHS Corrugated for which a consent of the data subject is needed for a certain processing purpose. If the processing of personal data is necessary for the performance of a contract concluded with the data subject, e.g., with processing operations that are necessary for the delivery of goods or the provision of another service or consideration, the processing is based on Article 6 I lit. b GDPR. The same applies to such processing operations that are necessary for the implementation of pre-contractual measures, e.g., in cases of inquiries about our products or services. If our company is subject to a legal obligation by which a processing of personal data becomes necessary, such as the fulfillment of tax obligations, the processing is based on Art. 6 I lit. c GDPR. In some cases, the processing of personal data is necessary to protect vital interests of the data subject or another natural person, e.g., if a person was injured on our premises and as a result the respective personal data of the data subject, like name, age, health insurance data or other vital information had to be passed on to a doctor, hospital or other third party. In this case the processing is based on Art. 6 I lit. d GDPR. Finally, processing operations could be based on Art. 6 I lit. f GDPR. Processing operations that are not covered by any of the aforementioned legal basis are based on legal that processing is necessary to protect a legitimate interest of our company or a third party, provided that the interests, fundamental rights and freedoms of the data subject are not overridden. Such processing operations are permitted to us because they were specifically mentioned by the European legislator. Thus, a legitimate interest could be assumed if the data subject is a customer of the controller (recital 47 sentence 2 GDPR).

17. Duration of storing personal data
Storing of personal data is permitted if required due to the respective statutory retention period. After expiry of the period, the corresponding data is routinely deleted, if it is no longer required for the fulfillment or initiation of the contract.

18. Contractual requirements to provide the personal data; necessity for the conclusion of the contract; obligation of the data subject to provide the personal data; possible consequences of not providing the data
We would like to inform you that the provision of personal data is partly required by law (e.g., tax regulations) or may also result from contractual regulations (e.g., information on the contractual partner). Sometimes, e.g., to conclude a contract, it may be necessary for a data subject to provide us with personal data that must subsequently be processed by us. For example: the data subject is obliged to provide us with personal data to conclude a contract with us. If the personal data is not provided the contract will not be concluded. Before providing personal data by the data subject, the data subject must contact one of our employees. Our employee will explain on a case-by-case basis whether the provision of the personal data is required by law, contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data, and what the consequences of not providing the personal data would be.

19. Decision making
As a responsible company, we do not use automatic decision-making or profiling.

20. Right of complaint to the supervisory authority
The data subject may complain to the competent supervisory authority.

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach
Phone: +49 (0) 981 53 1300
eMail: poststelle@lda.bayern.de