Privacy Policy for Suppliers
Information on the Processing of Personal Data of Suppliers
The protection of your personal data is our highest priority and is considered in all our business processes. Below, we inform you about the processing of your personal data.
I. Responsible for Data Processing
Responsible for the following described processing of personal data is:
ensian group GmbH, Zeppelinstr. 44, 88299 Leutkirch
with whom you enter into a supplier relationship.
The contact details of the data protection officer are as follows:
Datenschutzberatung Walliser GbR
Altenwaldstraße 8, 72768 Reutlingen
Email: datenschutz@elobau.de
II. Type, Scope, and Purposes as well as Legal Bases of Data Processing
1.Logfiles
Each time our supplier initial survey is accessed, we collect so-called logfiles (protocol data). These data include:
- IP addresses
- Date and time of requests
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- Each transferred data volume
- Website from which the request comes
- Browser
- Operating system and its interface
- Language and version of the browser software.
We process these logfiles based on our legitimate interest according to Art. 6 para. 1 lit. f) GDPR. The data will be deleted immediately when they are no longer required for the purpose, but no later than 90 days after collection.
2. “Cookies”
By visiting our website, so-called “cookies” are set. These are small text files stored on your device to enable, among other things, automatic recognition on your next visit, proper functioning of the website, and analysis of website usage. These set “functional cookies” are necessary for the proper functionality of the website, see § 25 para. 2 TDDDG. The “session cookies” we set are automatically deleted after you close your browser.
_ga | Google Analytics | Used to distinguish users. | 14 months | Cookie |
_gac_ | Google Analytics | Contains campaign-related information for the user. If you have linked your Google Analytics and Google Ads accounts, the conversion tags of the Google Ads website read this cookie unless you opt-out. | 90 days | Cookie |
_gat | Google Analytics | Used to throttle the request rate. If Google Analytics is provided via Google Tag Manager, this cookie is called dc_gtm*. | 1 minute | Cookie |
_gid | Google Analytics | Google Analytics Used to distinguish users. | 1 day | Cookie |
ga_client_id | Google Analytics | Same value as in _ga, stored in localStorage as a backup. | 14 months | LocalStorage |
_et_coid | etracker | eTracker Analytics: Stores information about how visitors use our website. | 2 years | |
VISITOR_INFO_LIVE | YouTube | YouTube Video | 6 months | Cookie |
YSC | YouTube | YouTube Video session management | Session | Cookie |
OGP | Google Maps | Used by Google to enable and track Google Maps. | 1 year | Cookie |
_gaexp | elobau | Level measurement | 2.4 months | Cookie |
_gaexp_rc | elobau | Level measurement | 10 sec | Cookie |
_ceir, is_returning | Crazy Egg | Track whether a visitor has visited the site before. | 5 years | Cookie |
_CEFT | Crazy Egg | Store page variants assigned to visitors for A/B performance tests. | 1 year | Cookie |
_cer.s | Crazy Egg | Track the unique ID of a recording visitor session, the tracking host, and the start time. | Recording session (expires when the browser is shut down) | Cookie |
_cer.v | Crazy Egg | Track whether a visitor has visited the site before. | Up to 31 days (expires on the first of the month) | Cookie |
_ce.s | Crazy Egg | Track the unique ID of a recording visitor session, the tracking host, and the start time. | 5 years | Cookie |
_fbp | This cookie is used by Facebook to display advertising products. | 3 months | Cookie | |
fr | This cookie is used to ensure that the Facebook pixel works properly. | 3 months | Cookie | |
comment_author_50ae8267e2bdf1253ec1a5769f48e062311829507-3 | This cookie stores the text and name of a user who leaves a comment, for example. | 12 months | Cookie | |
comment_author_url_50ae8267e2bdf1253ec1a5769f48e062 | This cookie stores the URL of the website that the user enters in a text field on our website. | 12 months | Cookie | |
comment_author_email_50ae8267e2bdf1253ec1a5769f48e062 | This cookie stores the user’s email address if they have provided it on the website. | 12 months | Cookie |
3. Supplier
Registration As a supplier or service provider, you have the opportunity to register for inclusion in our supplier pool. For this, it is necessary that you first complete the supplier initial survey on our website. To create your supplier profile and consider you later, we collect and store the following personal data, in particular:
- Company name
- Company address
- Business email addresses and business phone numbers
- Name and first name of the management
- Contact person for sales
- Contact person for sustainability
- Contact person for compliance
- Contact person for quality assurance
We collect and process this data to carry out the registration process and create your supplier profile on our platform.
The processing of data from suppliers (companies) is carried out based on contract initiation or to carry out pre-contractual measures according to Art. 6 para. 1 lit. b) GDPR. The processing of data from employees and contact persons of your company is carried out based on our overriding legitimate interest according to Art. 6 para. 1 lit. f) GDPR. Our legitimate interest is to keep the relevant master and contact data of the responsible contact persons of our suppliers for possible inquiries and to contact them.
III. Supplier Review
As part of the registration, we conduct a business partner review. For this, we collect general data about the company, such as the company’s field of activity, industry affiliation, offered products, quality in terms of manufacturing and production, and environmental compatibility.
We process this information to fulfill legal obligations according to Art. 6 para. 1 lit. c) GDPR in conjunction with §§ 3, 11 Money Laundering Act (GWG) and based on legitimate interest according to Art. 6 para. 1 lit. f) GDPR to identify purchasing partners and their performance.
V. Data Transfer/Recipients of Your Data
- Review of Purchasing Partners (Business Partner Review) We transmit personal data such as name, first name, of beneficial owners, managing directors/board members to assess the integrity and independence of the respective partners and their bodies. This transmission is carried out as part of our business partner review based on our legitimate interest according to Art. 6 para. 1 lit. f) GDPR. The review only takes place if a certain order or contract threshold is exceeded.
- Transfer to External Service Providers/Processors If necessary and legally permissible, we transfer data to external service providers who support us in certain services in the area of purchasing and procurement. These include, in particular, our IT service providers who support us in operating and maintaining our IT infrastructure.
We have concluded the necessary data protection agreements with all service providers who carry out processing on our behalf according to Art. 28 GDPR.
VI. Duration of Data Storage
We store your data as long as it is necessary to fulfill our legal and contractual obligations or we have an overriding legitimate interest in storing it. If the storage of your data is no longer necessary to fulfill contractual or legal obligations, your data will be deleted.
VII. Your Rights
Regarding the processing of your personal data, you have the following rights towards us: You can request information at any time according to Art. 15 GDPR about whether and which personal data concerning you is used by us, for what purposes the processing is carried out, where the data comes from, to which recipients the data may be transmitted, and how long such data is stored with us.
If you find that personal data concerning you is incorrect, you can request the correction of such data at any time, see Art. 16 GDPR (Correction). If data is incomplete from your point of view, you can also request the completion of data.
If you believe that the use of your personal data is no longer necessary or is carried out without sufficient legal basis or is unlawful for other reasons, you can request the deletion of this data, Art. 17 GDPR. Instead of deleting data, you can also request the restriction of data use according to Art. 18 GDPR if data is used unlawfully. You can particularly request such a restriction of data use if you dispute the accuracy of data or have objected to data use.
Regarding the personal data you have provided yourself and which is used based on a contract or consent, you can request that this data be made available to you in a structured, common, and machine-readable format, Art. 20 GDPR (Data Portability). You can also request that this data be transmitted directly to another responsible party.
If you believe that your rights concerning the personal data concerning you have been violated, you have the right to lodge a complaint with a supervisory authority, Art. 77 GDPR. In particular, you can contact the supervisory authority responsible for your place of residence, your workplace, or the place of the alleged violation.
For us, the locally responsible authority is: The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstr. 20, 70173 Stuttgart.
If there are reasons arising from your particular situation that make the use of your personal data, which we use based on a balance of interests (Art. 6 para. 1 lit. f GDPR), inadmissible, you have the right to object to such data use according to Art. 21 GDPR. Furthermore, you have the right to revoke your data protection consent at any time according to Art. 7 para. 3 GDPR.
You can reach our data protection officer at datenschutz@elobau.de or our postal address with the addition “the data protection officer”.