Data protection 

General explanation 

As a user of our website, you will receive all the necessary information in this privacy policy about how, to what extent and for what purpose we or third-party providers collect data from you and process it. Your data is collected and used strictly in accordance with the legal requirements, in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). We are particularly committed to the confidentiality of your personal data and therefore work strictly within the limits set by the legal requirements. Personal data is processed on a voluntary basis if this is possible for us. We also only pass this data on to third parties with your express consent. We ensure a high level of security for particularly confidential data, such as in payment transactions or with regard to your enquiries to us, by using SSL encryption. However, we would like to take this opportunity to draw your attention to the general dangers of Internet use, over which we have no control. Especially in e-mail traffic, your data is not secure without further precautions and may be collected by third parties. 

 1. Name and contact details of the data controller 

IAB Reinraum-Produkte GmbH
Erzberg 5
38126 Braunschweig
Phone: +49 531 28484-0
Fax: +49 531 28484-40
Email: info@iab-bs.de
Managing Director: Karoline Matzi 

 2. Contact details of the data protection officer 

Kämmer Consulting GmbH
Telephone number: +49 531 702249-0
E-mail: dsb-team@kaemmer-consulting.de 

 3. Scope of the processing of personal data 

In general, it is possible to use this website without entering and processing personal data. However, it may be necessary for you to provide us with data in order to process certain transactions, for example via the contact or order form. In this case, we may collect the following categories of data: 
  • Personal data (name, address) 
  • Contact details (e-mail address, telephone number) 
  • Company data (company, address, position, department) 
  • Payment data (bank details)
This data is provided on a voluntary basis. However, if you do not provide us with the required personal data, we may not be able to process your request. 

 4. Collection of access data 

The delivery and presentation of content via our website technically requires the collection of certain data. When you access our website, these so-called server log files are recorded by us or the provider of the web space. These log files do not allow any conclusions to be drawn about you and your person. The corresponding information consists of the 
  •  The name of the website 
  • the current date 
  • the web browser and its version 
  • the operating system used 
  • the referrer URL as the page from which you switched to our site, 
  • and the corresponding IP address. We use this data in anonymised form to display and deliver our content and for statistical purposes. 
The information supports the provision and continuous improvement of our offer and is stored separately from other personal information on secure systems. We reserve the right to check the aforementioned data retrospectively if there is any suspicion of unlawful use of our website. 

 5. Purpose of the processing of personal data 

Your personal data is processed for the following purposes: 
  • Processing of enquiries resulting from the contact form 
  • Establishment and fulfilment of contractual relationships 
  • Sending the newsletter 
  • Server log files: Display and delivery of the content of our website; statistical purposes. 

We process your personal data in accordance with the following legal bases 
  •  Art. 6 para. 1 lit. a): You have given us your consent. 
  • Art. 6 para. 1 lit. b): You have concluded a contract with us or we have to carry out pre-contractual measures. 
  • Art. 6 para. 1 lit. c): We must fulfil a legal obligation. 
  • Art. 6 para. 1 lit. f): Our legitimate interests outweigh your interests worthy of protection. 

We process personal data in the context of data avoidance and data minimisation only to the extent and for as long as is necessary for the use of our website or as required by law. 
If the purpose or legal basis for the data processing no longer applies and the end of the statutory retention period has been reached, the data collected will be deleted or blocked if the statutory retention period still applies. Your personal data will not be disclosed to third parties without your express consent or a legal basis. 
The data collected will not be used for automated case-by-case decisions, profiling or scoring. 

 6. Your rights as a data subject 

You can obtain information free of charge at any time (Art. 15 EU GDPR) about the personal data we have stored about you as well as the origin, recipient and purpose of the data processing. You also have the right to request the rectification (Art. 16 EU GDPR), blocking (Art. 18 EU GDPR) or erasure (Art. 17 EU GDPR) of your data. This does not apply to data that is stored due to legal regulations or is required for proper business processing. You have the right to object to the processing of your data (Art. 21 EU GDPR) and the right to data portability (Art. 20 EU GDPR). 

 Right to object 

In accordance with Art. 21 para. 1 GDPR, you have the right to object to the processing of your personal data at any time, unless this serves the fulfilment of a contract, a legal obligation or the protection of vital interests. 
You have the right to withdraw your consent to the processing of personal data at any time with effect for the future. Processing that took place before the revocation is not affected by this. 
If data is not covered by a statutory archiving obligation, we will delete your data at your request. If the archiving obligation applies, we will block your data. 
For all questions and concerns regarding the correction, blocking or deletion of personal data, please contact our data protection officer using the contact details in this privacy policy or at the address given in the legal notice. 
If you believe that your rights have not been fully respected in the handling of your personal data, you have the right to lodge a complaint with the supervisory authority responsible for you. 

 7. Contact form/email contact 

We provide a contact form on our website that can be used to contact us electronically. If you use this option, the data entered in the input mask will be transmitted to us and processed. These data are 
  •  Your name, 
  • Your e-mail address, 
  • Your address, 
  • Company, 
  • Position, 
  • Department, 
  • Telephone number, 
  • Subject, 
  • Message. 
The following data is also stored when the message is sent: 
  •  Date and time of sending the form. 
Before sending your contact enquiry, you will be referred to this privacy policy and must confirm receipt of the information by ticking a box. Alternatively, you can contact us via the email address provided. In this case, the user's personal data transmitted with the e-mail will be processed. 
The data will not be passed on to third parties in this context. The data is used exclusively for processing the contact enquiry. Once your enquiry has been processed, the personal data from the input screen will be deleted immediately. The additional personal data collected during the sending process will be deleted after a period of seven days at the latest. At your request, we will delete your personal data immediately. However, if you request the deletion of the personal data processed as part of your enquiry (via contact form or e-mail), it may no longer be possible to process your request. 

 8. User/customer account 

When registering for a user/customer account, it is necessary to enter certain mandatory information. This includes 
  •  Name, 
  • Billing and delivery address, 
  • Telephone number, 
  • a valid e-mail address, 
  • a password (this password gives you access to your data and allows you to update it or have it deleted), 
  • Company data (company, department, VAT number), 
  • Payment information. 
Setting up a user/customer account is voluntary. This makes it easier for you to use our services, which go beyond the general content of our website, also in the future. The personal data entered by you and stored by us will only be used for the purposes stated above and to maintain our customer database and will be deleted or blocked if you decide to deactivate or delete your user/customer account and there are no statutory retention periods to the contrary. The personal data of your user/customer account will be processed to fulfil the contract or to carry out pre-contractual measures. If your user/customer account is deleted, it may therefore no longer be possible for us to provide a service. 
In order to be able to process and deliver your order, we only pass on your data to the delivery service commissioned with the delivery. We save the text of the contract and send you the order details by e-mail. 

 9. Dispatch 

Your address will be passed on when the goods are dispatched by our dispatch service provider. 
 Your personal data will only be stored by the shipping service provider for as long as it is required to fulfil the contract or for statutory retention periods. 

10. Processing of personal data for advertising purposes 

In addition to processing your data for the above-mentioned purposes, we also use your data in accordance with Art. 6 para. 1 lit. f) GDPR, regardless of your consent to a newsletter, to communicate with you about your orders, certain products or marketing campaigns and to recommend products or services that may be of interest to you. 
You can object to the use of your personal data for advertising purposes as a whole or for individual measures at any time. A message in text form to the contact details stated in the legal notice or in this privacy policy (e.g. e-mail, letter) is sufficient for this. Alternatively, you can use the unsubscribe link contained in an advertising e-mail. 

11. Processing of payment transactions 

As we process your payment ourselves, the processing of data for handling payment transactions is carried out exclusively by us. 

 12. Security 

We have taken technical and organisational security measures to protect your personal data from loss, destruction, manipulation and unauthorised access. All our employees and all persons involved in data processing are obliged to comply with the EU GDPR, the Federal Data Protection Act (new) and other laws relevant to data protection and the confidential handling of personal data. 

 13. SSL encryption 

Our website uses SSL encryption when it comes to the transmission of confidential or personal content of our users. This encryption is activated, for example, when processing payment transactions and for enquiries that you send to us via our website. Please make sure that SSL encryption is activated on your side for corresponding activities. The use of encryption is easy to recognise: The display in your browser line changes from "http://" to "https://". Data encrypted via SSL cannot be read by third parties. Only transmit your confidential information if SSL encryption is activated and contact us if in doubt. 

14. Content and services from third-party providers 

The offer on our website may also include content, services and benefits from other providers that complement our offer. Examples of such offers are maps from Google Maps, YouTube videos or third-party graphics. Accessing these third-party services regularly requires the transmission of your IP address. This enables these providers to recognise your user IP address and store it. We make every effort to include only those third-party providers who use IP addresses solely for the delivery of content. However, we have no influence on which third-party provider may store the IP address. This storage may be used for statistical purposes, for example. If we become aware of storage processes by third-party providers, we will inform our users of this fact immediately. In this context, please also note the special data protection declarations for individual third-party providers and service providers whose services we use on our website. 
 You can also find them in this privacy policy. 

15. Cookies 

We use cookies on our website. These small text files are stored on your PC from our server. They support the display of our website and help you to navigate our website. Cookies collect data about your 
  •  IP address, 
  • your browser,
  • Your operating system and your internet connection. 
We do not link this information to personal data and do not pass it on to third parties. Under no circumstances do we use cookies to install malware or spyware on your computer. You can also use our website without the use of cookies, which may mean that some of the displays and functions of our website only work to a limited extent. If you wish to deactivate cookies, you can do so via special settings in your browser. Please use the browser's help function to make the appropriate changes. You can manage online ad cookies via the following links: http://www.aboutads.info/choices for the USA http://www.youronlinechoices.com/uk/your-ad-choices for Europe. 

16. Matomo (Piwik) 

On this website, data is collected and stored using the web analysis service software Matomo (www.matomo.org), a service provided by InnoCraft Ltd, 150 Willis St, 6011 Wellington, New Zealand, ("Matomo") on the basis of our legitimate interest in the statistical analysis of user behaviour for optimisation and marketing purposes in accordance with Art. 6 para. 1 lit. f GDPR. Pseudonymised user profiles can be created and evaluated from this data for the same purpose. Cookies can be used for this purpose. Cookies are small text files that are stored locally in the cache of the website visitor's internet browser. Among other things, cookies make it possible to recognise the Internet browser. The data collected using Matomo technology (including your pseudonymised IP address) is processed on our servers. 
The information generated by the cookie in the pseudonymised user profile is not used to personally identify the visitor to this website and is not merged with personal data about the bearer of the pseudonym. 
If you do not agree to the storage and analysis of this data from your visit, you can object to its storage and use at any time by clicking below. In this case, a so-called opt-out cookie will be stored in your browser, which means that Matomo will not collect any session data. Please note that the complete deletion of your cookies means that the opt-out cookie will also be deleted and may have to be reactivated by you. 
You can adjust your consent to tracking here: Cookie settings 

17. YouTube 

Our website uses plugins from the Google-operated YouTube site. The operator of the pages is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA. When you visit one of our pages equipped with a YouTube plugin, a connection to the YouTube servers is established. The YouTube server is informed which of our pages you have visited. 
If you are logged into your YouTube account, you enable YouTube to assign your surfing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account. 
 Further information on the handling of user data can be found in YouTube's privacy policy at https://www.google.de/intl/de/policies/privacy 

18. Google Web Fonts 

This site uses so-called web fonts provided by Google for the standardised display of fonts. When you access a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly. 
 For this purpose, the browser you are using must connect to Google's servers. This informs Google that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. 
If your browser does not support web fonts, a standard font will be used by your computer. 
Further information on Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/. 

19. Changes to this privacy policy 

We will update this policy to protect your personal data from time to time. You should check these guidelines occasionally to keep up to date with how we protect your data and constantly improve the content of our website. If we make significant changes to the processing of the personal data you provide to us, we will notify you by means of a clear and visible notice on the website. By using the website, you declare that you agree to the terms of this privacy policy on the protection of personal data. 
If you have any questions about these data protection provisions, please contact our data protection officer named above.

20. Google reCAPTCHA

We use "Google reCAPTCHA" (hereinafter referred to as "reCAPTCHA") on our websites. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). 
The purpose of reCAPTCHA is to check whether the data input on our websites (e.g. in a contact form) is made by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, time spent on the website by the website visitor or mouse movements made by the user). The data collected during the analysis is forwarded to Google. 
The reCAPTCHA analyses run completely in the background. Website visitors are not informed that an analysis is taking place. 
Data processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its website from abusive automated spying and SPAM. For more information about Google reCAPTCHA and Google's privacy policy, please see the following links: