Privacy Policy

1. Data protection at a glance

The protection of your personal data is very important to us. We treat your data confidentially and in accordance with statutory data protection regulations and this privacy policy.

Below we inform you about which personal data we collect when you use our website, for what purposes we process it, and what rights you have as a data subject.

Personal data is any information relating to an identified or identifiable natural person. This includes, for example, your name, your email address, your telephone number, your IP address, or information about your usage behavior on our website.

2. Responsible Party

The responsible party for data processing on this website is:

Wickeder Westfalenstahl GmbH
Hauptstraße 6
58739 Wickede (Ruhr)
Germany

Phone: +49 2377 917-0
Email: info@wickeder.de

The responsible party decides on the purposes and means of processing personal data.

3. Data Protection Officer

For questions about data protection and to exercise your rights, you can contact our data protection officer at any time.

Data Protection Officer

Email: datenschutz@wickeder.de

or by post to:

Wickeder Westfalenstahl GmbH
Data Protection Officer
Hauptstraße 6
58739 Wickede (Ruhr)

Anonymous contact for legitimate reports of compliance and data protection violations through our whistleblowing portal at:

https://whistleblowersoftware.com/secure/wickeder-group

Reports via this portal can be made completely anonymously – please note that this portal is not intended for general inquiries, but only for specific violations of legal regulations or our Code of Conduct.

4. General Principles of Data Processing

We only process personal data when there is a legal basis for doing so.

This is particularly the case when:

We observe the principles of data minimization, purpose limitation, transparency, and integrity in accordance with Art. 5 GDPR.

5. Visiting Our Website

When you access our website, certain technical information is automatically transmitted by your browser to our web server.

This includes in particular:

  • IP address of the accessing device
  • date and time of access
  • pages and files accessed
  • Browser type and browser version
  • operating system
  • Referrer URL
  • Internet service provider
  • technical status and error information

This data is necessary to provide the website technically, ensure its security, and analyze technical errors.

Purpose of Processing

  • ensuring stable website operation
  • detection and defense against cyberattacks
  • error analysis and system optimization
  • ensuring the functionality of the website

Legal Basis

Art. 6 para. 1 lit. f GDPR.

Our legitimate interest lies in the secure and trouble-free provision of our online offering.

Storage Duration

Server log files are generally deleted within 90 days, unless longer storage is required for security reasons.

6. Use of Cookies and Similar Technologies

Our website uses cookies and comparable technologies to enable and improve the use of our website.

Cookies are small text files that are stored on your device.

We distinguish between:

Technically Required Cookies

These cookies are necessary for the website to function properly and to provide basic functions.

Examples:

  • storage of your privacy settings
  • session management
  • security functions

Legal Basis

  • § 25 para. 2 no. 2 TDDDG
  • Art. 6 para. 1 lit. f GDPR

Analysis, Statistics, and Marketing Cookies

Insofar as we use analysis or marketing technologies, their use is exclusively based on your express consent.

Legal Basis

  • § 25 para. 1 TDDDG
  • Art. 6 para. 1 lit. a GDPR

You can revoke your consent at any time with effect for the future via the cookie settings.

7. Contact

When you contact us – for example via contact form, email, telephone, or post – we process the data you provide.

This may include:

  • name
  • company
  • department
  • address
  • telephone number
  • email address
  • content of your message

Purpose of Processing

  • processing your inquiry
  • communication with you
  • initiation or performance of a contractual relationship

Legal Basis

Art. 6 para. 1 lit. b GDPR
Art. 6 para. 1 lit. f GDPR

Storage Duration

Inquiries are generally deleted once their processing is complete and no legal retention obligations remain.

8. Applications

We appreciate your interest in working for our company.

As part of an application process, we process in particular:

  • master data
  • contact data
  • CVs
  • certificates
  • proof of qualifications
  • cover letters
  • interview notes

Purpose of Processing

  • conducting the application process
  • assessment of professional and personal suitability
  • communication with applicants

Legal Bases

Art. 6 para. 1 lit. b GDPR
§ 26 BDSG

Storage Duration

If no employment takes place, application documents are generally deleted six months after completion of the process, provided there are no legal retention obligations or longer storage has been expressly requested and consented to.

9. Customer and Business Partner Data

As part of our business relationships, we process personal data of customers, suppliers, service providers, and other business partners.

This includes in particular:

  • contact data of contact persons
  • contract data
  • communication data
  • invoice and payment information

Purposes

  • contract initiation and contract performance
  • purchasing and supplier management
  • customer service
  • fulfillment of legal obligations
  • assertion and defense of legal claims

Legal Bases

Art. 6 para. 1 lit. b GDPR
Art. 6 para. 1 lit. c GDPR
Art. 6 para. 1 lit. f GDPR

10. Recipients of Personal Data

Within our company, only those departments that need them to fulfill their tasks receive access to personal data.

In addition, data may be transmitted to external recipients, for example:

  • IT service providers
  • hosting providers
  • cloud service providers
  • telecommunications providers
  • banks
  • tax advisors
  • auditors
  • lawyers
  • transport and logistics companies
  • authorities and courts

Insofar as external service providers process data on our behalf, this is done exclusively on the basis of a contract for commissioned processing in accordance with Art. 28 GDPR.

11. International Data Transfers

Insofar as personal data is transmitted to recipients outside the European Union or the European Economic Area, this is done exclusively in compliance with legal requirements.

We ensure that an adequate level of data protection is guaranteed, for example through:

  • adequacy decisions of the European Commission,
  • standard contractual clauses,
  • or other appropriate safeguards in accordance with Art. 44 et seq. GDPR.

12. Data Security

To protect your data, we employ extensive technical and organizational security measures.

These include in particular:

  • modern encryption technologies
  • access restrictions
  • authorization and role concepts
  • firewall and security systems
  • data backups
  • regular security audits

Despite all security measures, complete security cannot be guaranteed when transmitting data over the Internet.

13. Storage Duration

We only store personal data for as long as is necessary for the respective purposes or legal retention periods exist.

After the purpose of processing ceases or legal deadlines expire, the data will be deleted or anonymized.

14. Rights of Data Subjects – Your Rights as a Data Subject

Under the General Data Protection Regulation (GDPR), you have various rights regarding your personal data. These rights are intended to give you control over how your data is processed.

If you wish to exercise any of these rights, you can contact us at any time. You will find the contact details in this privacy policy.

Right to Access

You have the right to know,

whether we process personal data about you,

what data we have stored,

for what purpose we use it,

where the data comes from,

to whom we may disclose the data,

and how long we store the data.

Upon request, we will provide you with a copy of the personal data stored about you.

Right to Rectification

If your data is incorrect or incomplete, you can request that we correct or complete it.

For example, you can inform us if your name, address, or contact details have changed.

Right to Erasure (“Right to be Forgotten”)

Under certain conditions, you can request that we delete your personal data.

This is possible, for example, if:

the data is no longer needed for the original purpose,

you revoke consent that was given,

the processing was unlawful,

or legal reasons require deletion.

Please note that legal retention obligations may prevent immediate deletion. In such cases, we may only delete the data after the legal deadlines have expired.

Right to Restriction of Processing

In certain cases, you can request that we continue to store your data but temporarily no longer actively use it.

This may be useful, for example, if the accuracy of the data is being verified or if a legal claim needs to be clarified.

Right to Data Portability

You have the right to receive personal data that you have provided to us in a common and machine-readable format.

Where technically feasible, you can also request that we transmit this data directly to another controller.

Right to Object

If we process your data on the basis of a legitimate interest, you can object to this processing for reasons arising from your particular situation.

Following a legitimate objection, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds.

Objection to Direct Marketing

If your personal data is used for direct marketing, you can object to this use at any time.

After your objection, your data will no longer be used for advertising purposes.

Right to Withdraw Consent

If data processing is based on your consent, you can withdraw this consent at any time with effect for the future.

The withdrawal does not affect the lawfulness of processing that took place up to the time of withdrawal.

Right to Lodge a Complaint with a Supervisory Authority

If you believe that the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a data protection supervisory authority.

You can contact the data protection supervisory authority of your federal state or the authority of your place of residence in particular. Further information can be found at: https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_table.html

Of course, we would be pleased if you contact us directly first so that we can resolve your concern quickly and easily.

You have the following rights at any time:

Right to Access

(Art. 15 GDPR)

You can request information about which personal data we process about you.

Right to Rectification

(Art. 16 GDPR)

You have the right to have incorrect or incomplete data corrected.

Right to Erasure

(Art. 17 GDPR)

Under certain conditions, you can request the deletion of your data.

Right to Restriction of Processing

(Art. 18 GDPR)

You can request that the processing of your data be restricted.

Right to Data Portability

(Art. 20 GDPR)

You can request the release of your data in a structured and machine-readable format.

Right to Object

(Art. 21 GDPR)

You can object to processing at any time for reasons arising from your particular situation.

Withdrawal of Consent

(Art. 7 para. 3 GDPR)

Consent given can be withdrawn at any time with effect for the future.

15. Right to Lodge a Complaint with a Supervisory Authority

If you believe that the processing of your personal data violates data protection regulations, you have the right to lodge a complaint with a competent data protection supervisory authority.

This applies in particular to the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement.

16. Currency and Amendment of this Privacy Policy

We reserve the right to amend this privacy policy if this becomes necessary due to legal, technical, or organizational changes.

The current version published on our website applies at all times