Info: Our products are only sold within the European Union! A sale to non-EU countries is unfortunately no longer possible.

Privacy policy


1. Preamble

We are pleased about your visit on the website of our company. Information protection and in particular data protection is of great importance to our management. In principle, you can use this website without providing any personal data. Should you disclose data to us in connection with the processing described below, we will treat your personal data confidentially and in accordance with the legal data protection regulations of the European Union and the Federal Republic of Germany as well as this data protection declaration.
As the data controller, REFDAT has implemented numerous technical and organizational measures to ensure the complete protection of personal data processed via this website. However, Internet-based data transmissions can generally have security gaps, so that absolute protection cannot be guaranteed. For this reason, you as the person concerned are free to transmit personal data to us by alternative means, for example by telephone or mail.

2. Definitions

REFDAT's data protection declaration is based on the terms used by the European legislator when the basic data protection regulation (GDPR) was issued. The detailed definitions can be found in Art. 4 GDPR. Essentially, these are the following terms, described here in simplified form:

a) Personal data:
This is all information available to us as a responsible person to determine you as a natural person. (e.g. name, address, e-mail, telephone number, IP address etc.)

b) Person concerned:
This is you as a natural person, if we have identified you or can identify you.

c) Processing:
Processing is any collection, storage, further processing, forwarding, archiving and deletion of data. It is irrelevant whether the process is carried out automatically with the aid of IT systems or whether it is carried out manually (e.g. by letter).

d) Restriction of processing:
Restriction of processing is the marking of stored personal data with the aim of restricting their future processing.

e) Profiling:
Profiling is any type of automated processing of your data, which consists in using these data to evaluate certain personal aspects relating to you. In particular, to analyse or predict aspects relating to your job performance, economic situation, health, personal preferences, interests, behaviour, whereabouts or change of location.

f) Pseudonymization:
This is a process to identify your personal data. In the following, only this identifier will be used and without the original key or a "reference database" this pseudonym cannot be resolved (e.g. allocation of a customer number).

g) Responsible Person:
The person responsible or responsible for processing is REFDAT with whom you have a contractual relationship. It is crucial that we can decide independently on the processing methods and means.

h) Contract processor:
A processor is a company that has been commissioned by REFDAT to assist you in the collection, processing, storage, forwarding or deletion of your data. Usually these are IT service providers, but also waste disposal companies that are commissioned, for example, with the destruction of documents.

i) Consent:
Consent is any expression of will given by you for a specific individual case. You will be fully informed about what you are consenting to.

3. The name and address of the controller

The person responsible for this website and the central services of REFDAT within the meaning of the Data Protection Basic Regulation and other regulations of a data protection nature is:

REFDAT
Street: Gamburger Weg 24
City: D-97877 Wertheim

Brigitte Scharmann

E-Mail: info@refdat.net

4. Data Protection Officer

REFDAT is not obliged to appoint a data protection officer. If you have any questions in connection with the processing of your data, please contact info@refdat.net.

5. Rights of the data subject

In accordance with Chapter 3 of the GDPR, you have the following rights as a data subject. In order to fulfil our obligations in connection with your rights in accordance with the law, please address appropriate inquiries to info@refdat.net.

a) Art. 15 Right to information
You have an unlimited right to request information about the personal data processed by you. This information must be provided to you free of charge. You may request information on the following information, a copy of which must also be sent to you

- the purpose of processing your data,
- the categories of the data,
- the internal and external recipients of your data,
- the duration of the data storage,
- their rights under Chapter 3, in connection with data processing,
- the origin of the data, if it was not collected from you,
- whether a profile was created,
- whether your data has been transferred to a third country (non-EU and non-EEA),
- which data protection authority is responsible for our respective company,

b) Art. 16 Right of rectification
Should we process incorrect data from you, you can have this corrected at any time by your contact person.

c) Art. 17 Right of cancellation
You have the right to request the deletion of your personal data at any time. We may be required by law to retain your data for a certain period of time (e.g. 6 years for business mail or 10 years for tax-related documents). In such a case we will block your data record until the retention period has expired and then delete the data record accordingly. Please address deletion requests to the above mentioned mail address.

d) Art. 18 Right to limit processing
If you dispute the accuracy of our personal data, or if you refuse to have your data deleted and instead demand the restriction (e.g. in the case of advertising mail), you can demand the restriction of processing from us. We will then set your data to blocked.

e) Art. 19 Obligations of notification in connection with correction, deletion or restriction
We are obliged to inform all recipients of your data of any correction, deletion or restriction you have commissioned, insofar as this is possible and can be implemented with a reasonable amount of effort. We will inform you about the recipients of your data if you request this.

f) Art. 20 Right to data transfer
You have the right at any time to request our company to transfer your data to another responsible person. This refers to all master data that we keep about you. If technically possible, we will provide the data record in a common machine-readable format (e.g. .csv).

g) Art. 21 Right of objection
If a data processing has been justified on the basis of article 6, paragraph I, letter f (so-called legitimate interest), you may object to the processing in this context.

h) Art. 77 Right to appeal to a supervisory authority
You have the right to complain to the data protection supervisory authority responsible for our company at any time if you believe that we have violated the provisions of the GDPR in any way. The following authority is responsible for REFDAT:

Bayerisches Landesamt f. Datenschutzaufsicht (BayLDA)
Promenade 18
D-91522 Ansbach

You can access the website of the data protection supervisory authority via the following link: https://www.lda.bayern.de/de/index.html

6. Processing operations

In this section we will describe the data processing that is connected with our internet offer or that applies to a general business relationship between you and our company.

The following legal bases serve us for the processing of your data.
Art. 6 I lit. a GDPR serves our company as a legal basis for processing operations for which we obtain consent for a specific processing purpose.

If the processing of your data is necessary for the performance of a contract to which you are a party, as is the case, for example, with processing operations required for the delivery of goods or the provision of other services or consideration, the processing is based on Art. 6 I lit. b GDPR. The same shall apply to such processing operations which are necessary for the performance of pre-contractual measures, for example in cases of inquiries about our products or services.

If our company is subject to a legal obligation which makes the processing of personal data necessary, for example to fulfil tax obligations, the processing is based on Art. 6 I lit. c GDPR.

In rare cases, the processing of personal data may be necessary to protect the vital interests of the person concerned or of another natural person. This would be the case, for example, if a visitor to our company was injured and his name, age, health insurance details or other vital information had to be passed on to a doctor, hospital or other third party. In this case the processing would be based on Art. 6 I lit. d GDPR.

Finally, processing operations could be based on Art. 6 I lit. f GDPR. Processing operations that are not covered by any of the above legal bases are based on this legal basis if the processing is necessary to protect a legitimate interest of our company or a third party, unless the interests, fundamental rights and freedoms of you outweigh the processing. We are permitted to carry out such processing operations in particular because they have been specifically mentioned by the European legislator.

a) Website processing
We operate this website and collect various data in this context.

Cookies

The Internet pages partly use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective and safer. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called "session cookies". They are automatically deleted at the end of your visit. Other cookies remain stored on your end device until you delete them. These cookies enable us to recognize your browser on your next visit.

You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, the functionality of this website may be limited.

Cookies that are required to carry out the electronic communication process or to provide certain functions that you have requested (e.g. shopping basket function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. We, as website operators, have a legitimate interest in the storage of cookies for the technically error-free and optimized provision of our services. Insofar as other cookies (e.g. cookies to analyze your surfing behavior) are stored, they are treated separately in this privacy policy.

Server log data

REFDAT or our website provider collects data about access to our website and stores it as "server log files". The following data is logged in this way:

- Visited website
- Time at the time of access
- Amount of data sent in bytes
- Source/reference from which you reached to the page
- Used Browser
- Operating system used
- IP address used (anonymized)

The data collected is only used for statistical analysis and to improve the website. However, we reserve the right to check the server log files subsequently if there are concrete indications of illegal use.

Registration on our website
On our website you have the possibility to register by providing your personal data. Your data will be entered into an input mask, transmitted to us and then stored. The data will not be passed on to third parties. The following data will be collected during your registration:
• data from input mask
• Personal information (company, first and last name, birth date, address, e-mail address)
• Further details (password, security answer)
By means of your registration we can offer you certain services and contents on our web portal, which due to the nature of things can only be made available to registered users. Your personal data will be processed on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR, unless they are necessary for the performance of a contract pursuant to Art. 6 para. 1 lit. b GDPR to which you are a party. Your data will be deleted as soon as they are no longer required for the purpose of their collection.
You have the possibility to have your data modified or deleted at any time. If you wish to delete your account, you can do so in writing by post, stating your user name (e-mail address), or by e-mail to info@refdat.net. Please note that a deletion may be contrary to contractual or legal obligations. You can change your data at any time in your account.
In addition, your IP address, date and time of your registration will be saved. The reason for this is to prevent misuse of our services and, if necessary, to be able to solve any criminal offences committed. For this reason it is necessary for us to store this data. As a matter of principle, data will not be passed on to third parties, unless there is a legal obligation to do so or the passing on serves the purpose of criminal prosecution.

Onlineshop on our website

Description, purpose and legal basis
You have the possibility to register for our online store on our website by entering your personal data. Which personal data will be transmitted to us in the process is determined by the respective input mask used for registration. The personal data entered by you will be collected and stored exclusively for internal use by us and for the purpose of contract processing. The data processing is thus carried out on the legal basis Art. 6 para. 1 lit. b GDPR for the fulfilment of the contract.
We may pass on your personal data to one or more data processors, for example a parcel service provider such as UPS, who will use your data in particular for the execution of the contract.
When you register in our online store, your IP address assigned by your Internet Service Provider (ISP), the date and time of registration are also stored. The storage of this data is carried out against the background that this is the only way to prevent the misuse of our services and, if necessary, to enable the investigation of criminal offences. To this extent, the storage of this data is necessary for our security. As a matter of principle, this data will not be passed on to third parties, unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution.
If you provide voluntary personal data during registration, this data is used by us to offer you content or services which, due to the nature of the matter, can only be offered to registered users. The data processing is then carried out with your consent in accordance with Art. 6 Para. 1 lit. a GDPR. You have the possibility to change the personal data you have provided us with at any time or to have it completely deleted from our database.
In order to optimize our online offer for you, we have a legitimate interest in passing on your personal data to third parties if necessary. This takes place on the legal basis of Art. 6 para. 1 lit. f GDPR.
Art. 6 para. 1 lit. c GDPR serves as the legal basis for the processing of your commercial and tax law requirements.
On request, we will be pleased to inform you which personal data we have stored about you. Furthermore, we will correct or delete your personal data at your request or notice, provided that no statutory retention periods conflict with your request. You are welcome to contact our employees for this purpose.
We store your personal data for as long as it is necessary to achieve the purpose for which it was collected. The purpose is fulfilled as soon as the contract has been completely processed. Even after the contract has been completely processed, it may be necessary to store your personal data. This is then the case to comply with contractual or legal obligations. We are obliged by commercial and tax law to store your address, payment and order data for a period of 10 years.
You have the right at any time to object to the processing of your personal data on the basis of our legitimate interest. For this purpose, you can contact us by e-mail or by any other means of contact. Please note, however, that the restriction or deletion of your personal data may be contrary to contractual or legal retention periods.

Receiver
For payment processing we pass your data to the appropriate payment service provider. These are listed below:
- PayPal (Europe S.à.r.l. & Cie, S.C.A.)
https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=en_EN

User account
In order to be able to place orders via our online store, you have the possibility to create a password protected user account. This account contains an overview of your transacted orders as well as active order processes. If you leave the online store, you will be logged out automatically.
Please make sure that you have a sufficiently secure password, as we cannot assume liability for password misuse unless we have caused it ourselves.

Order process
If you place an order, the personal data required for this purpose will be processed. These are usually surname, first name, address, payment data and e-mail address. Likewise these are passed on to third service providers for delivery or order processing. After contract processing, your personal data will be deleted if they are no longer required or if a contractual or legal retention period prevents deletion.

Third party modules / analysis tools / advertising
You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

b) Contact / Inquiries

In the following we describe the possibilities of contacting the companies and employees of our company.

E-Mail / Phone inquiry
If you send us inquiries by e-mail or telephone, your data from the e-mail or conversation, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not pass on this data without your consent.

The processing of the data provided in the e-mail or telephone conversation is therefore based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. For this purpose, an informal communication by e-mail to us is sufficient. The legality of the data processing operations carried out up to the point of revocation remains unaffected by the revocation. In further correspondence, there may be a change in legality (e.g. if it is business correspondence), in which case your data will be processed in accordance with Art. 6 Para. 1 lit. b GDPR.

The data provided by you in the mail or from the telephone conversation will remain with us until you request us to delete it, revoke your consent for storage or the purpose for which the data was stored ceases to apply (e.g. after your inquiry has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected by this.

c) Data processing for the fulfilment of contracts

If you have entered into a business relationship with our company, e.g. if you have placed an order with us, the data processing will be carried out on the basis of Art. 6 para. 1 lit. b GDPR. All data necessary to initiate, fulfill or complete this order, such as contact data, object data, service providers involved, photo documentation, plans, orders for goods, etc., may be collected and processed by us without separate consent.

Should it be necessary to call in a subcontractor (e.g. other IT service providers, special software suppliers) to fulfill the contract with you, we may also pass on your data to this subcontractor. We guarantee that we have committed our subcontractors to the same strict data protection requirements that you can expect from us.

The data related to orders are subject to different retention periods. For example, general business letters must be proven for 6 years and tax law documents for 10 years. We will only pass on your data within our company to the extent necessary, if this is justified by the subject of the order.

7. Protection / encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If the SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

8. Profiling

As a responsible company, we avoid automatic decision making or profiling.

9. Actuality / status

This data protection declaration has the current status of January 2022 and is subject to constant updating and adaptation to new legal requirements and technical developments.