Privacy Policy

  • This privacy policy complies with the provisions of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). Its purpose is to inform you about the nature, scope and purpose of processing and the use of personal data by VARIALUX GmbH as the website operator. While we make every effort to ensure your security when you visit our website, security risks, in particular, when online cannot be completely eliminated. If you have any questions regarding your data, you will find the contact details of the data controller at the end of this document. For definitions of terms used in this privacy policy, please refer to the definitions set out in Article 4 GDPR.

  • Personal data

    When you visit our website, we collect personal data in accordance with the GDPR. We use this data solely to optimise the functionality and content of our website. In accordance with applicable laws and regulations, the collected data will only be retained for as long as you use the service. We comply with the statutory retention and erasure requirements.
    When you contact us by email or by telephone we collect your data solely to process your inquiry in accordance with Article 6 (1) (b) GDPR. We may store user data in a "CRM system" or a comparable system. We will erase your inquiries when they are no longer needed. We will review this need every two years. The statutory archiving obligations apply in a supplementary manner.

  • Hosting

    We use hosting services to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, security services and technical maintenance services that we use for the purpose of operating this website.
    We or our hosting provider process user data, content data and usage data of visitors to this website on the basis of our legitimate interests to offer an efficient and secure website in accordance with Article 6 (1) (f) GDPR in conjunction with Article 28 GDPR. On this basis, we have entered into a data processing agreement. The data is processed completely anonymously and is used neither for automated decision-making nor for profiling.

  • Log files

    A log file is automatically produced by the processing computer system. This means that information about the used device is stored as a log file on a server. These log files cannot be used to identify you.
    On the basis of our legitimate interests within the meaning of Article 6 (1) (f) GDPR, our website operator collects data about each access to its servers on which our web service is located:
    - Name of the website
    - Access to the website: date, time, duration, frequency
    - Referrer URL (previously visited website)
    - Amount of data sent
    - Browser type and version
    - User's operating system and version
    - Your IP address
    Log files are stored for a maximum of seven days for security reasons (e.g. to investigate illegal activities). Data which needs to be stored to provide evidence are exempt from erasure until the relevant incident has been resolved.

  • Cookies

    We use cookies on our website. These small text files are downloaded from our server to your PC. They support website display and help you navigate our website. Cookies collect information about your IP address, your browser, your operating system and your internet connection. We do not link this information to personal data and we do not pass it on to third parties. We will not, under any circumstances, use cookies to spread malware or spyware to your computer. While you can use our website without cookies, you may not be able to use all the functions and features of this website. If you wish to disable cookies, you can do so by changing your browser settings.

  • Google Maps

    This website uses "Google Maps" from Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, to display maps. Privacy policy: https://www.google.com/policies/privacy/, Opt-out: https://adssettings.google.com/authenticated. When you use Google Maps on our website, information about your use of this website and your IP address will be transmitted to a Google server in the US and stored there. We have no knowledge of the exact content of the data transmitted, nor of its use by Google. According to Google, it does not link the information with other data from other Google services or the collection of personal data. However, Google may transfer the information to third parties. If you disable JavaScript in your browser, you will not be able to run Google Maps, and maps will no longer be displayed on our website. By using our website, you consent to the collection and processing of your data by Google LLC as described above.

  • Transmission to third countries

    Where we process data outside the European Union or the European Economic Area or in the context of the use of third-party services or disclosure or transmission of data to third parties, processing will only take place if it is necessary to meet our pre-contractual or contractual obligations, you have given consent to processing, for compliance with a legal obligation or for the purpose of our legitimate interests. Without prejudice to legal or contractual permits, we process the data or have the data processed in a third country only if the requirements of Article 44 et seq. GDPR have been met. Processing is carried out, for example, on the basis of special guarantees, such as the officially recognised assessment of the adequacy of the level of data protection (e.g. the "Privacy Shield" in the US) or in compliance with officially recognised contractual obligations (so-called "standard contractual clauses")

  • Rights of data subjects

    You have the right to obtain from us confirmation as to whether or not personal data concerning you are being processed. You are entitled to request a copy of the data (Article 15 GDPR).
    You have the right to have inaccurate personal data rectified and incomplete personal data completed (Article 16 GDPR). You have the right to obtain from us the erasure of personal data concerning you without undue delay (Article 17 GDPR) or the restriction of processing (Article 18 GDPR).
    You have the right to receive the personal data concerning you and to transmit those data to other controllers (Article 20 GDPR). you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR).
    You can contact the competent supervisory authority at:

    Saxony Data controller/ Data protection (Sächsischer Datenschutzbeauftragter)
    Bernhard-von-Lindenau-Platz 1
    01067 Dresden
    Germany
    Phone: +49 (0) 351/493-5401
    Fax: +49 (0) 351/493-5490
    Email: saechsdsb@slt.sachsen.de

  • Right of withdrawal

    You have the right to withdraw your consent to data processing or collection at any time with effect for the future (Article 7 (3) GDPR).

  • Right to object

    You have the right to object to the future processing of data concerning you at any time (Article 21 GDPR).

  • Responsible contact in accordance with Article 4 (7) GDPR

    VARIALUX GmbH
    Kleinwolmsdorfer Straße 16
    01477 Arnsdorf
    Germany
    Phone: +49 (0) 35200/27-200
    Fax: +49 (0) 35200/27-214
    Email: kontakt@varialux.de
    Managing director: Sylvia Zscherper

  • Changes to the privacy policy

    We reserve the right to change the privacy policy at any time with regard to applicable data protection regulations. Current version: May 2018