As the controller within the meaning of the General Data Protection Regulation (hereinafter referred to as "GDPR"), we at nortus Systronic GmbH, In den Niederwiesen 4a, 76744 Woerth on Rhine (infonortus-systronic.com), Germany, take the protection of your personal data very seriously and comply with the legal provisions on data protection. In the following, we would like to inform you about what data we collect about you when you visit us on our website or when you use our online services and what we use your data for:
I. General information about visiting the homepage
As a matter of principle, we collect and use personal data of our users only insofar as this is necessary to provide a functional website as well as our content and services. The collection and use of personal data of our users is usually only carried out on the basis of a contract concluded with the user or with the user's prior consent. An exception applies in cases where it is not possible to obtain consent for factual reasons or where the processing of the data is permitted by other legal provisions.
II. Contact form and e-mail contact
There is a contact form on our website, which can be used to contact us electronically. You can also contact us by e-mail at info@nortus-systronic.com or by phone at +49 (7271) 12990-60. Please note that our e-mail correspondence regarding your request is unencrypted.
If you use these options and get in touch with us, we will use your data to answer your inquiries and contact you. For these purposes, our legitimate interest lies in the processing of personal data in accordance with Art. 6 (1) (f) GDPR, which is also the legal basis for the processing of the data.
The personal data entered will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. This may vary depending on the request, especially if it has resulted in a customer relationship. At the latest, however, your data will be deleted after the retention periods under tax law (six or ten years).
III. Customer Relationship
We also process your personal data in the context of an initiating or existing customer relationship with you. For this purpose, we collect and process the following data as standard:
- Name
- Address
- Contact details such as e-mail address and telephone number
- VAT ID
We process this data in order to ensure the proper execution of your order or pre-order (e.g. estimate). The legal basis for this is Art. 6 (1) (b) GDPR.
The personal data entered will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. If the order has been processed and the customer relationship has been terminated, your data will generally be deleted after termination in accordance with the tax regulations (six or ten years), unless a longer limitation period is indicated. The retention period begins on 1 January of the year following the termination and ends six/ten years later.
IV. Online Shop/Customer Account
You can (also) order certain of our goods via our online shop. For this purpose, we also need personal data to process your order.
You can register with us and open a customer account. The following data is collected as part of the registration process:
- Surname and first name / company name
- Address
- E-mail address
- Password
- VAT ID
- Contact person name
- Data for the execution of the payment on account
We will first check your data with our systems, after which we will activate you for orders.
In order to process your order as a registered user, we process your data on the basis of a contract. The legal basis for the processing of the data is Art. 6 (1) (b) GDPR.
If you delete your customer account, your personal data will be deleted immediately. You can do this at any time. You can also change your data at any time in your customer account. If you have made a purchase, the data about this purchase (such as name, address, payment details and goods data) will be kept for ten years due to tax and commercial obligations. The retention period begins on 1 January of the year following the purchase and ends ten years later. The data will be deleted accordingly after expiry of this period.
V. Categories of recipients, transfers to third countries
As a matter of principle, we do not transmit your data to third parties, unless we need it to carry out business processes or make use of it within the framework of an order processing agreement. These are, for example: Shipping service providers, payment service providers, merchandise management service providers, service providers for order processing, web hosts or IT service providers. In all cases, we strictly observe the legal requirements.
We do not transfer any data to third countries.
VI. Rights of the data subject
You have the right to:
- in accordance with Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can obtain information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it has not been collected by us, as well as the existence of automated decision-making including profiling and, where appropriate, meaningful information on its details;
- in accordance with Art. 16 GDPR, to demand the correction of incorrect or complete personal data stored by us without undue delay;
- in accordance with Art. 17 GDPR, to request the deletion of your personal data stored by us, insofar as the processing is not necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
- in accordance with Art. 18 GDPR, to request the restriction of the processing of your personal data if the accuracy of the data is disputed by you, the processing is unlawful, but you oppose its deletion and we no longer need the data, but you need it for the assertion, exercise or defense of legal claims or you have objected to the processing in accordance with Art. 21 GDPR;
- pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller;
- in accordance with Art. 7 para. 3 GDPR, to revoke your consent at any time. As a result, we are no longer allowed to continue the data processing that was based on this consent in the future and
- pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or place of work or our registered office.
For more information, please contact us directly. You can contact us
by e-mail (info(at)nortus-systronic.com) or phone +49 7271-12990-0.
VII. Data Protection Officer
If you have any questions about data protection or your personal data with us, you can contact our Data Protection Officer:
by e-mail: info@nortus-systronic.com
or by phone: +49 7271-12990-60
or by post:
nortus Systronic GmbHIn den Niederwiesen 4a76744 Woerth on RhineGermany
As of April 1st 2019