Privacy Policy pursuant to Articles 13 and 21 of the GDPR and Section 25 of the TDDDG
for the content and features of https://www.kahlegmbh.de/ (hereinafter "Services")
As of 2026
1. General Information
The protection of your personal data and your privacy is extremely important to us. That is why we want to provide you with complete transparency regarding the processing of your personal data (GDPR) as well as regarding the storage of information on your device and access to that information (TDDDG). After all, only when the processing of personal data and information is transparent to you, as the data subject, are you sufficiently informed about the scope, purposes, and benefits of the processing. This Privacy Policy applies to all processing of personal data carried out by us, as well as to the storage of information on your devices and access to such information. This includes both the provision of our services and our activities on external online platforms, such as our social media fan pages.
The controller within the meaning of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and other data protection regulations is the
Kahle GmbH
Gebrüder-Heyn-Str. 3 A
21337 Lüneburg
T +49 (0)4131 9696-6000
F +49 (0)4131 9696-6009
kahleservice@kahlegmbh.de
Hereinafter referred to as “Controller” or “we.”
2. General Information on Data Processing
2.1 Personal Data
Personal data consists of specific details regarding the personal or factual circumstances of an identified or identifiable natural person. Examples of such specific details include:
- Name, Age, Marital Status, Date of Birth
- Address, phone number, email address
- Account number, credit card number
- IP Address & Location Data
2.2 How We Process Personal Data
We process personal data within the limits permitted by law. This means that data processing operations are based on a legal basis. These are set forth in Article 6(1) of the GDPR. Most data processing is based on a legitimate interest on our part (Article 6(1)(f) of the GDPR), on processing operations necessary for the performance of a contract (Article 6(1)(b) of the GDPR), or on consent you have provided (Article 6(1)(a) of the GDPR). In the latter case, you will be separately notified of the consent process (e.g., via a cookie banner).
We process personal data only for specific purposes (Art. 5(1)(b) of the GDPR). As soon as the purpose of the processing no longer applies, your personal data will be deleted or protected through technical and organizational measures (e.g., pseudonymization).
The same applies to the expiration of a required retention period, except in cases where further retention is necessary for the conclusion or performance of a contract. In addition, a legal obligation to retain data for a longer period or to disclose it to third parties (particularly law enforcement agencies) may arise. In other cases, the retention period, the type of data collected, and the nature of the data processing depend on which features you use in each specific instance. We would be happy to provide you with specific information regarding this in individual cases, in accordance with Article 15 of the GDPR.
2.3 We process the following categories of data
Data categories include, in particular, the following data:
- Master data (e.g., names, addresses, dates of birth),
- Contact information (e.g., email addresses, phone numbers, messaging services),
- Content data (e.g., text entries, photographs, videos, content from documents/files),
- Contract details (e.g., subject matter of the contract, terms, customer category),
- Payment information (e.g., bank account information, payment history, use of other payment service providers),
- Usage data (e.g., browsing history on our services, use of specific content, access times),
- Connection data (e.g., device information, IP addresses, URL referrers).
2.4 We take the following security measures
In accordance with legal requirements and taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihoods and severity of threats to your rights and freedoms, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, ensuring that your data is stored and processed confidentially, with integrity, and is available at all times. Furthermore, the security measures we implement include controls on access to your data, as well as on data access, entry, disclosure, ensuring availability, and separating your data from that of other individuals. In addition, we have established procedures that ensure the exercise of data subject rights (see Section 5), the deletion of data, and responses in the event of a threat to your data. Furthermore, we take the protection of personal data into account from the very beginning of our software development and through procedures that comply with the principles of data protection by design and privacy-friendly default settings.
2.5 How We Transfer or Disclose Personal Data to Third Parties
As part of our processing of your personal data, this data may be transferred to or disclosed to other entities, companies, legally independent organizational units, or individuals. These third parties may include, for example, payment institutions in connection with payment transactions, service providers entrusted with IT tasks, or providers of services and content that we have integrated into our services. If we transfer or disclose your personal data to third parties, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
2.6 How a transfer to a third country takes place
If this Privacy Policy states that we transfer your personal data to a third country—that is, a country outside the EU or the EEA—the following applies. If we process your data in a third country, or if processing takes place in a third country in connection with the use of third-party services, this is done only in accordance with legal requirements.
Furthermore, transfers to third countries generally take place only with your explicit consent. Regardless of whether such consent has been given, we ensure that we have a contractual or legal basis for the transfer and processing of your data in the relevant third country. Furthermore, we only allow your data to be processed by service providers in third countries that, in our view, have a recognized level of data protection. This means that there is, for example, a corresponding adequacy decision in place between the EU and the country to which we transfer your personal data. An “adequacy decision” is a decision adopted by the European Commission pursuant to Article 45 of the GDPR, which establishes that a third country (i.e., a country not bound by the GDPR) or an international organization offers an adequate level of protection for personal data. Alternatively—for example, if no adequacy decision exists—a transfer to a third country will only take place if, for instance, contractual obligations between us and the service provider in the third country are in place through the European Commission’s so-called Standard Contractual Clauses and further technical safeguards have been implemented, which ensure a level of protection equivalent to that in the EU, or if the service provider in the third country can demonstrate data protection certifications and your data is processed only in accordance with internal data protection regulations (Articles 44–49 of the GDPR. EU Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).
Under the so-called “Data Privacy Framework” (“DPF”), the European Commission has recognized the level of data protection provided by certain U.S. companies as adequate pursuant to the Adequacy Decision of July 10, 2023. A list of certified companies, as well as further information about the DPF, can be found on the U.S. Department of Commerce’s website at https://www.dataprivacyframework.gov/ (in English). In this Privacy Policy, we inform you which of the services we use are certified under the Data Privacy Framework.
2.7 Information About the Cookies Used
Cookies are small text files that contain data from websites or domains you have visited and are stored on your device (computer, tablet, or smartphone). When you access a website, the cookie stored on your device sends information to the party that placed the cookie.
2.7.1 First-Party Cookies and Third-Party Cookies
Our services may set third-party cookies and allow third parties to place cookies on your device. The difference between a first-party cookie and a third-party cookie lies in who controls the placement of the cookie. First-party cookies are cookies specific to the services that created them. Their use enables us to provide an efficient service and to analyze your user behavior within our services. Third-party cookies are stored on your device by third parties (i.e., not by us). Although we may allow third parties to access our services so that they can place cookies on your devices, we have neither control over the information provided by the cookies nor access to that data. This information is processed entirely by the third parties in accordance with their respective privacy policies, as well as any data processing agreements concluded between us and the third parties pursuant to Article 28 of the GDPR or joint controller agreements pursuant to Article 26 of the GDPR.
In practical terms, we distinguish between
- Functional Cookies: These cookies are necessary for the basic technical functions of the services. For example, these cookies enable secure logins and the saving of progress during the ordering process. They also allow us, for example, to save your login information and shopping cart contents, and to ensure consistent display of page content.
- Analytics Cookies: These cookies allow us to analyze our services so that we can measure and improve their performance. You can change your personal settings for analytics cookies by clicking the corresponding opt-out link.
- Marketing Cookies: We use these cookies to show you ads that may be relevant to your interests. These cookies enable you, for example, to share pages on social media and post comments. They also display offers that may match your interests. You can change your personal settings for marketing cookies by clicking the corresponding opt-out link.
2.7.2 How We Use Cookies
We want you to be able to make an informed decision for or against the use of cookies that are not strictly necessary for the technical functionality of our services. Therefore, we allow you to choose which cookies you accept via a consent banner when you first visit our services and, thereafter, permanently through the relevant settings. Please note that functional cookies are essential for visiting our Services and are therefore already enabled by default. Analytics and marketing cookies are optional. You can allow them by giving your consent to the use of these cookies in the cookie banner. Alternatively, you can reject analytics and marketing cookies. Please note that you may still see advertisements even if you reject the use of statistics and marketing cookies. However, these advertisements will be less tailored to your interests. You will still be able to use the full functionality of the services.
2.7.3 Cookie Retention Period
Unless we provide you with explicit information regarding the retention period of cookies (e.g., via the cookie banner), you can assume that the retention period may be up to two years. If cookies were set based on your consent, you have the option at any time to revoke your consent or object to the processing of your data through cookie technologies (collectively referred to as “opt-out”).
2.8 Consent Management
We use Borlabs as a consent management tool in connection with tracking and analytics activities on our services. Borlabs is a service provided by Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg (“Borlabs”). Borlabs collects log file and consent data using JavaScript. This JavaScript makes it possible to inform you about your consent to specific tags in our services and to obtain, manage, and document this consent.
We process the following data: (1) Consent data (anonymized log data (Consent ID, Processor ID, Controller ID), consent status, timestamp), (2) Device data (including truncated IP addresses (IPv4, IPv6), device information, timestamp), (3) User data (including email, ID, browser information, setting IDs, changelog). The Consent ID (which contains the data listed above) and the consent status, including the timestamp, are stored in your browser’s local storage and simultaneously on the cloud servers we use. Further processing takes place only if you submit a request for access or revoke your consent. We also store personal data that we process via Borlabs on our servers. The legal basis for processing personal data via Borlabs in accordance with the provisions set forth here stems from our legitimate interest as well as the need to comply with legal requirements, and thus from Article 6(1)(f) and (c) of the GDPR. We use Borlabs to comply with legal requirements regarding data protection and tracking, thereby ensuring that our information technology systems operate in a manner that is both legally compliant and user-centered.
3. Data Processing in Connection with the Use of Our Services
The use of our services and all their features involves the processing of personal data. We explain exactly how this works here.
3.1 Informational Use of Our Services
Simply accessing our services for informational purposes requires the processing of the following personal data and information: browser type and version, operating system used, addresses of previously visited websites, the IP address of the device you use to access our services, and the time at which you accessed our services. All of this information is automatically transmitted by your browser, unless you have configured it to prevent the transmission of this information.
This personal data is processed for the purpose of ensuring the functionality and optimization of our services, as well as to guarantee the security of our information technology systems. These purposes also constitute legitimate interests under Article 6(1)(f) of the GDPR; the processing is therefore carried out on a legal basis.
3.2 Contact Form / Contacting Us by Email
We process the personal data you provide to us when you contact us for the purpose of responding to your inquiry, your email, or your request for a callback. The categories of data processed include master data, contact information, content data, usage data (if applicable), connection data, and contract data (if applicable). In individual cases, we may forward this data to affiliated companies or third parties that we engage to process orders. The legal basis for the processing depends on the purpose of the contact.
- it is based on our legitimate interest and thus on Article 6(1)(f) of the GDPR;
- If the intention is to enter into a contract, the legal basis is Article 6(1)(b) of the GDPR.
3.3 Applicant Management
We process the personal data you provide to us as part of the application process (e.g., via the corresponding contact form on our website) for the purpose of reviewing your application and conducting the application process. At your request, we will also consider your application in future hiring processes at our company or our subsidiaries. The categories of data processed in this context include master data, contact data, content data, usage data (not applicable for applications submitted by mail), connection data (not applicable for applications submitted by mail), and contract data. The legal basis for processing your data as part of applicant management is based on Art. 88(1) of the GDPR in conjunction with § 26(1), sentence 1 of the BDSG. The legal basis for applying to subsidiaries and for storing your data for future application processes is Article 6(1)(a) of the GDPR in conjunction with Article 7 of the GDPR and Section 26(2) of the BDSG; Article 6(1)(f) of the GDPR.
3.4 Web Hosting
3.4.1 Provision of Our Services
In order to provide you with our services, we use the services of a web hosting provider, Raidboxes GmbH, Hafenstraße 32, 48153 Münster. Our services are hosted on this web hosting provider’s servers. For these purposes, we use the provider’s infrastructure and platform services, computing capacity, storage space, and database services, as well as its security and technical maintenance services.
The data processed includes all data that you enter or that is collected from you in connection with your use of and communication regarding our Services (e.g., your IP address). Our legal basis for using a web hosting provider to deliver our services is Article 6(1)(f) of the GDPR (legitimate interest).
3.4.2 Receiving and Sending E-mails
The web hosting services we use may also include the sending, receiving, and storage of emails. For these purposes, the addresses of the recipients of your emails, the senders, and other information regarding email transmission (e.g., the involved providers), as well as the contents of the respective emails, are processed. The aforementioned data is processed, among other things, for the purpose of detecting spam. Emails are generally not sent in encrypted form over the Internet. Although emails are typically encrypted during transmission, they are not encrypted on the servers from which they are sent and received (unless end-to-end encryption is used). We therefore cannot assume any responsibility for the transmission of emails between the sender and our server. Our legal basis for using a web hosting provider to receive and send emails is Article 6(1)(f) of the GDPR (legitimate interest).
3.4.3 Collection of Access Data and Log Files
We (or our web hosting provider) collect data on every access to the server (server log files). The server log files may include the address and name of the services and files accessed, the date and time of the request, the amount of data transferred, a notification of a successful request, browser type and version, your operating system, the referrer URL (the page visited previously), and, as a rule, IP addresses and the requesting provider.
Server log files may be used, on the one hand, for security purposes—for example, to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks)—and, on the other hand, to ensure server capacity utilization and stability. Our legal basis for using a web hosting provider to collect access data and log files is derived from Article 6(1)(f) of the GDPR (legitimate interest).
3.5 Tracking & Tools
To ensure that our services operate smoothly from a technical standpoint and provide an optimal, user-friendly experience, we use the following services:
Google Tag Manager
Google Tag Manager is a solution that allows us to manage so-called website tags via a user interface and thereby integrate other services into our own. Google Tag Manager itself (which implements the tags) does not process any personal data. For information regarding the processing of personal data by the integrated services, please refer to our explanations for the individual Google services below. Google Tag Manager is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy.
Google Search Console
To continuously optimize our services’ Google rankings, we use Google Search Console, a web analytics service provided by Google. Google Search Console allows us to conduct search analyses that provide insight into how often our services appear in Google search results. This enables us to monitor and manage our services in the search index. No personal user data or tracking data is processed or transmitted to Google in connection with the use of Google Search Console.
Google Analytics
We use Google Analytics to analyze statistics regarding your use of our services. We collect your IP address, which is then anonymized by Google through truncation before it is permanently stored on Google’s servers. The data processed includes usage data and connection data. The recipient of this data is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (as a joint controller, Art. 26 GDPR). Should Google transfer this data to a third country (e.g., the U.S.), this will only occur on a case-by-case basis, based on a data processing agreement concluded with Google and in accordance with standard contractual clauses agreed upon with Google and other security measures permitted by the GDPR, which ensure the security of the processing of your personal data with a level of protection identical to that in the EU, in particular based on the EU-US Data Privacy Framework (DPF). The legal basis for the use of Google Analytics is your consent (e.g., via an opt-in in the cookie banner), provided that you have granted us this consent during your visit to our services, and therefore stems from Article 6(1)(a) of the GDPR. Based on your consent, cookies are stored on your device, and personal data is collected as a result. If you have not given us your consent to use Google Analytics (no opt-in in the cookie banner or withdrawal of your consent), we will not (any longer) use Google Analytics in connection with your visits to our services.
Google Ad Manager
We use the "Google Marketing Platform" (and services such as "Google Ad Manager") to place ads on the Google Display Network (e.g., in search results, in videos, on websites, etc.). The Google Marketing Platform enables ads to be displayed in real time based on users’ presumed interests. This allows us to target ads more effectively so that we present you only with ads that match your potential interests. The data processed includes usage data and connection data. The recipient of this data is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (as a joint controller, Art. 26 GDPR). Should Google transfer this data to a third country (e.g., the U.S.), this will only occur on a case-by-case basis, based on a data processing agreement concluded with Google and in accordance with standard contractual clauses agreed upon with Google and other security measures permitted by the GDPR, which ensure the security of the processing of your personal data with a level of protection identical to that in the EU, in particular based on the EU-U.S. Data Privacy Framework (DPF). The legal basis for using Google Ad Manager is your consent (e.g., via an opt-in in the cookie banner), provided that you have given us this consent during your visit to our services, and therefore stems from Article 6(1)(a) of the GDPR. Based on your consent, cookies are stored on your device, and personal data is collected as a result. If you have not given us your consent to use Google Ad Manager (no opt-in in the cookie banner or revocation of your consent), we will not (any longer) use Google Ad Manager during your visits to our services.
3.6 Fan Pages on Social Media Websites
We maintain fan pages on social media websites and, in this context, process personal data in order to communicate with users active on those platforms or to provide information about us. Please note that when you visit our fan pages, your data may be processed outside the European Union. The operators of the respective social media platforms are responsible for this. You can find a detailed description of the respective forms of processing and the options for objecting (e.g., opting out) in the privacy policies of the operators of the respective social media platforms.
We operate a so-called Facebook Fan Page for our company on Facebook. When you visit the Facebook Fan Page, Facebook may analyze your usage behavior and provide us with information derived from this analysis (“Insights”). We use these Page Insights to optimize our business operations and tailor our services to meet user needs. The categories of data processed may include master data, contact data, content data, usage data, and connection data. The recipient of the data is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, as a joint controller pursuant to Art. 26 of the GDPR. The legal basis for processing the data in accordance with the provisions set forth herein stems from our legitimate interest and thus from Article 6(1)(f) of the GDPR. Facebook is responsible for ensuring your rights as a data subject are upheld. Facebook provides information about your rights as a data subject at: https://www.facebook.com/legal/terms/information_about_page_insights_data. You may also exercise your rights with us; we will then promptly forward your request to Facebook.
We operate an Instagram fan page for our company on Instagram. When you visit the Instagram fan page, Meta may analyze your usage behavior and share the information obtained from this analysis with us (“Insights”). Page Insights are used for the purposes of business optimization and to tailor our website and services to user needs. The categories of data processed may include master data, contact information, content data, usage data, and connection data. The recipient of the data is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, as a joint controller pursuant to Article 26 of the GDPR. The legal basis for processing the data in accordance with the provisions set forth here stems from our legitimate interest and thus from Article 6(1)(f) of the GDPR. Meta is responsible for implementing your data subject rights. Meta provides information about your data subject rights at: https://privacycenter.instagram.com/policy. You may also exercise your rights with us; we will then promptly forward your request to Meta.
We operate a LinkedIn fan page for our company on LinkedIn. When you visit and use the LinkedIn fan page, LinkedIn may analyze your usage behavior and share the information obtained from this with us. This information is used for the purposes of business optimization and to tailor our website and services to your needs. The categories of data processed include master data, contact data, content data, usage data, and connection data. The recipient of the data is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, as a joint controller pursuant to Article 26 of the GDPR. The legal basis for processing the data in accordance with the provisions set forth here stems from our legitimate interest and thus from Article 6(1)(f) of the GDPR. LinkedIn is responsible for ensuring your data subject rights are upheld. LinkedIn provides information about your data subject rights at: https://de.linkedin.com/legal/privacy-policy. You may also exercise your rights with us; we will then promptly forward your request to LinkedIn.
YouTube
We operate a YouTube channel for our company. When you visit and use our YouTube channel, Google may analyze your usage behavior and share the information obtained from this analysis with us. This information is used for the purposes of business optimization and to tailor our website to your needs. The categories of data processed include master data, contact data, content data, usage data, and connection data. The recipient of the data is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, as a joint controller pursuant to Article 26 of the GDPR. The legal basis for processing the data in accordance with the provisions set forth here stems from our legitimate interest and thus from Article 6(1)(f) of the GDPR. YouTube is responsible for ensuring your rights as a data subject are upheld. YouTube provides information about your data subject rights at: https://www.youtube.com/howyoutubeworks/our-commitments/protecting-user-data/#privacy-guidelines. You may also exercise your rights with us; we will then promptly forward your request to YouTube.
3.7 Newsletter
Newsletter and Consent
You can subscribe to our free newsletter on our website. Through the newsletter, we’ll keep you informed about new brochures, flyers, and product updates, as well as expert insights on drinking water hygiene and disinfection. To receive the newsletter, we need your email address. Providing your first name, last name, and company/organization is optional and is used to address you personally.
Double-opt-in process
Signing up for our newsletter is done using the so-called double opt-in process. After you sign up, you will receive an email asking you to confirm your subscription. Only after this confirmation will your email address be added to our mailing list. This ensures that no one can sign up using someone else’s email address. To verify your registration, we log the time of registration and confirmation, as well as your IP address.
Legal Basis
The legal basis for processing your data for the purpose of sending the newsletter is your consent pursuant to Article 6(1), first sentence, letter a of the GDPR, in conjunction with Section 7(2), No. 3 of the UWG.
Withdrawal of Consent / Unsubscribe
You may revoke your consent to receive the newsletter at any time, effective for the future, and unsubscribe from the newsletter. To do so, use the unsubscribe link at the bottom of each newsletter email or send us a message at kahleservice@kahlegmbh.de. The lawfulness of the processing carried out up until the time of revocation remains unaffected by the revocation.
Email marketing service provider CleverReach
Our newsletter is sent via the service provider CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany (hereinafter “CleverReach”). The data you provide when you subscribe is stored and processed on CleverReach’s servers in Germany. CleverReach assists us in organizing and analyzing the distribution of our newsletter. We have entered into a data processing agreement with CleverReach in accordance with Article 28 of the GDPR, in which CleverReach is obligated to protect our subscribers’ data, process it exclusively in accordance with our instructions, and not disclose it to third parties. For more information on data protection at CleverReach, please visit: https://www.cleverreach.com/de/datenschutz/
Retention period
We store the data you provided to subscribe to the newsletter until you unsubscribe, at which point it will be deleted from both our servers and CleverReach’s servers. We store the log data collected to verify your consent (time and IP address) for as long as necessary to safeguard legitimate interests in maintaining a record.
4. Data Processing on Behalf of a Client
Should we use external service providers to process your data, we will carefully select and engage them. If the services provided by these service providers constitute processing on our behalf within the meaning of Article 28 of the GDPR, the service providers are bound by our instructions and are regularly monitored. Our data processing agreements comply with the strict requirements of Article 28 of the GDPR as well as the guidelines of the German data protection authorities.
5. Rights of Data Subjects
If your personal data is processed, you are a data subject within the meaning of the GDPR, and as a user, you have the following rights vis-à-vis the controller:
5.1 Right to Access Information
You may request confirmation from the data controller as to whether we are processing personal data concerning you. If such processing is taking place, you may request the following information from the data controller:
- the purposes for which the personal data is processed;
- the categories of personal data that are processed;
- the recipients or categories of recipients to whom your personal data has been or will be disclosed;
- the planned duration of the storage of your personal data or, if specific details cannot be provided, the criteria used to determine the storage period;
- the existence of a right to have your personal data corrected or erased, a right to restrict processing by the controller, or a right to object to such processing;
- the existence of a right to file a complaint with a supervisory authority;
- all available information regarding the origin of the data, if the personal data is not collected from the data subject;
- the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) of the GDPR; and—at least in such cases—meaningful information regarding the logic involved, as well as the scope and intended effects of such processing on the data subject.
- You have the right to request information regarding whether your personal data is being transferred to a third country or to an international organization. In this context, you may request to be informed of the appropriate safeguards pursuant to Article 46 of the GDPR in connection with the transfer.
5.2 Right to Rectification
You have the right to request that the controller correct and/or complete your personal data if the processed personal data concerning you is inaccurate or incomplete. The controller must make the correction without delay.
5.3 Right to Restriction of Processing
Under the following conditions, you may request that the processing of your personal data be restricted:
- if you contest the accuracy of the personal data concerning you for a period that allows the controller to verify the accuracy of the personal data;
- the processing is unlawful, and you object to the erasure of the personal data and instead request that its use be restricted;
- the controller no longer needs the personal data for the purposes of processing, but you need it to assert, exercise, or defend legal claims, or
- if you have objected to the processing pursuant to Article 21(1) of the GDPR and it has not yet been determined whether the controller’s legitimate grounds outweigh your grounds.
- If the processing of your personal data has been restricted, such data—apart from its storage—may be processed only with your consent or for the purpose of asserting, exercise, or defense of legal claims; to protect the rights of another natural or legal person; or for reasons of a substantial public interest of the Union or a Member State.
If the restriction on processing has been imposed in accordance with the above conditions, the controller will notify you before the restriction is lifted.
5.4 Right to Erasure
5.4.1. You may request that the controller immediately erase the personal data concerning you, and the controller is obligated to erase such data immediately if any of the following grounds apply:
- The personal data concerning you is no longer necessary for the purposes for which it was collected or otherwise processed.
- You withdraw your consent on which the processing was based pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, and there is no other legal basis for the processing.
- You object to the processing pursuant to Article 21(1) of the GDPR, and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21(2) of the GDPR.
- The personal data concerning you was processed unlawfully.
- The erasure of your personal data is necessary to comply with a legal obligation under Union law or the law of the Member States to which the controller is subject.
- The personal data concerning you was collected in connection with the information society services offered, in accordance with Article 8(1) of the GDPR.
5.4.2. If the controller has made your personal data public and is obligated to erase it pursuant to Article 17(1) of the GDPR, the controller shall take reasonable measures, including technical measures, to inform the controllers processing the personal data that you, as the data subject, have requested that they erase all links to that personal data or any copies or replicas of it.
5.4.3. The right to erasure does not apply if the processing is necessary
- to exercise the right to freedom of expression and information;
- to comply with a legal obligation that requires processing under Union or Member State law to which the controller is subject, or to perform a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health pursuant to Article 9(2)(h) and (i) and Article 9(3) of the GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, to the extent that the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of such processing, or
- to assert, exercise, or defend legal claims.
5.5 Right to Information
If you have exercised your right to rectification, erasure, or restriction of processing with the controller, the controller is obligated to notify all recipients to whom your personal data has been disclosed of such rectification, erasure, or restriction of processing, unless this proves impossible or involves a disproportionate effort. You have the right to request information from the controller regarding these recipients.
5.6 Right to Data Portability
You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used, and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that the processing is based on consent pursuant to Art. 6(1)(a) of the GDPR or Art. 9(2)(a) of the GDPR or on a contract pursuant to Article 6(1)(b) of the GDPR, and the processing is carried out by automated means.
In exercising this right, you also have the right to have your personal data transmitted directly from one data controller to another, provided this is technically feasible. This must not infringe upon the freedoms and rights of others. The right to data portability does not apply to the processing of personal data that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.
5.7 Right to Object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data that is carried out pursuant to Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions.
The controller will no longer process your personal data unless it can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, your personal data will no longer be processed for those purposes.
You have the option, in connection with the use of information society services—notwithstanding Directive 2002/58/EC—to exercise your right to object through automated procedures that use technical specifications.
5.8 Right to Withdraw Consent Under Data Protection Law
You have the right to withdraw your consent under data protection law at any time. Withdrawing your consent does not affect the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal.
The processing is lawful until you revoke your consent—the revocation therefore takes effect only with respect to processing that occurs after we receive your notice of revocation. You may revoke your consent informally by mail or email. The processing of your personal data will then cease, unless permitted by another legal basis. If this is not the case, your data must be deleted immediately following your withdrawal of consent in accordance with Art. 17(2) of the GDPR. Your right to withdraw your consent, subject to the conditions mentioned above, is guaranteed. Please send your withdrawal of consent to:
Kahle GmbH
Gebrüder-Heyn-Str. 3 A
21337 Lüneburg
T +49 (0)4131 9696-6000
F +49 (0)4131 9696-6009
kahleservice@kahlegmbh.de
5.9 Right to File a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, your workplace, or the location of the alleged infringement, if you believe that the processing of your personal data violates the GDPR. The supervisory authority to which the complaint was submitted shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78 of the GDPR.
6. Automated decisions in individual cases, including profiling
We do not make automated decisions on a case-by-case basis, including profiling.
7. Disclosure Obligations of the Data Controller
If your personal data has been disclosed to other recipients (third parties) on a lawful basis, we will notify them of any rectification, erasure, or restriction of the processing of your personal data (Art. 16, Art. 17(1), and Art. 18 of the GDPR). The obligation to notify does not apply if it would involve a disproportionate effort or is impossible. We will also inform you of the recipients upon request.