Data Protection Regulations
1. Responsible person
The company responsible for the content of the web shop and the processing of data is
Franz Gottwald GmbH + Co. KG
In den Freuen 100/102
28719 Bremen
Germany
represented by the management
- Ulrike Wulf
- Norbert Brothun
You can reach those responsible at
email: info@gottwald-group.com
Phone: +49 421 69469-0
Fax: +49 421 69469-28
2. Data Protection Officer
Franz Gottwald GmbH + Co KG has appointed
Dipl.-Ing. J. Drechsler
from
Medical Data Solutions GmbH
Friedrichstraße 95
10117 Berlin
Germany
as its Data Protection Officer.
You can reach the Data Protection Officer at datenschutz@medaso.de
3. Contract processing
By using our online services, a contract may be concluded between you and us on the provision and use of these offers and for orders in the online shop, a purchase contract may be concluded for the fulfillment of which we require a number of data processing activities, which include, personal data among other information.
In order to be able to provide you with these services, we use the services of various service providers who work for us as processors.
The following sections provide more detailed information on these processing activities.
At no time do we use the data collected for the purpose of exclusively automated decision-making, including profiling.
3.1 Provision of our website and our online shop (hosting)
Our web pages and the web shop are hosted on Internet servers of the companies Strato (web pages) and Hetzner (web shop). For this, we have concluded order processing contracts with the relevant companies, which ensure the smooth operation of our services.
In order to process your requests, it is necessary that we process the following categories of personal Information on the basis of GDPR Article 6 (1) b):
- IP address of the end device
- Technical information on the Internet browser of the end device
- Technical information on the operating system of the end device
- Technical information on the hardware of the end device
This information is necessary to
- enable data exchange between the server and the end device
- ensure error-free display on the end device
- enable input by the user.
To ensure the trouble-free provision of our online offer and for the purpose of implementing information security measures we set additional parameters, such as
- the website that referred the visitor to our website (referrer)
- which web pages were called up how often within a certain period of time, from which visitors.
This allows us to recognize unusual patterns in visitor behavior, for example, which could be an indication of an attempted malicious attack on our offer.
The personal information is usually deleted from this data after 14 days.
We refer to Article 6 (1) f) of the GDPR - protecting the legitimate interests pursued by the controller or by a third as the legal basis for this data collection.
3.2. Use of our website and our web shop
a) Social media links
On our website, you will find links to our social media profiles at
- YouTube
These references are stored as external links. This means that only images of the logos of the respective vendors are displayed on our website. Therefore, no data is forwarded to the respective vendors simply by loading our website.
The logos are provided with external Internet links that redirect to our profile with the respective vendor. If you click on one of the logos, you call up our profile on the respective external social media service. You are therefore leaving the data protection area of responsibility of Franz Gottwald GmbH + Co KG.
b) Contact forms
If you have any questions, we offer you the opportunity to contact us via the forms provided on the website. A valid e-mail address is required so that we know who the request is from and to be able to answer it properly.
Further information can be provided voluntarily.
Data processing for the purpose of contacting us is carried out in accordance with Art. 6 (1) a) GDPR on the basis of your voluntarily given consent.
The personal data collected by us for the use of the contact form will be deleted after your request has been dealt with.
c) Storage of local data on the end device (cookies, etc.)
We use cookies on our website. These are small files that your browser automatically creates and that are stored on your end device (laptop, tablet, smartphone or similar) when you visit our website. Cookies do not cause any damage to your end device, do not contain any viruses, trojans or other malware.
Cookies are used to store information in connection with the specific end device used. However, this does not mean that we thereby obtain direct knowledge of your identity.
On the one hand, the use of cookies serves to make the use of our website more pleasant for you. For example, we use so-called session cookies in order to recognize that you have already visited individual pages of our website. These are automatically deleted after you leave our site.
In addition, we also use temporary cookies that are stored on your end device for a specified period of time to optimize user-friendliness. If you visit our site again to make use of our services, it is automatically recognized that you have already visited us and which entries and settings you have made so that you do not have to enter them again. These cookies are deleted automatically after a defined period of time.
The basis for the use of cookies, which are indispensable for the proper operation of our online offer, is GDPR Article 6 (1) b).
You must select all cookies that are not absolutely necessary when you call up the cookie banner that appears on our website in order to be able to use the associated convenience functions. GDPR Article 6 (1) a) applies as the basis for the data processing.
Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or that a message always appears before a new cookie is created. But the complete deactivation of cookies can lead to you not being able to use all the functions of our website.
In a similar manner, our shop system utilizes other storage options provided locally by your browser to store information during the product selection and ordering process. This information is required for a smooth ordering process. Its processing is therefore covered by GDPR Article 6 (1) b).
3.3 Processing of orders
a) Web shop
Our web shop is based on the shop system from Shopware. We host the shop system ourselves on servers we manage.
In the course of processing orders, status e-mails are sent to customers via the shop system. These include (but not exhaustively):
- If the order is canceled
- If the order is returned
- When shipping the order
- In the event of any delay in delivery
- Online invoice (only for guest customers)
- If the order is scheduled for delivery
- Order receipt confirmation
- In the event of a reminder to pay in advance
- If the order is canceled and payment has already been made by
prepayment (except PayPal) a request to provide the account details for
the refund
- Payment receipt status for any prepayment by bank transfer
We use the e-mail address provided when ordering for this purpose.
Data processing is necessary for the fulfillment of the purchase contract, or necessary for carrying out pre-contractual measures (e.g. recording the order) and therefore falls under GDPR Article 6 (1) b).
No personal data will be passed on to third parties.
b) Product search
We use the plugin Doofinder to improve search results.
In order to provide the search results, we transmit the user’s current IP address and information about the products currently being visited to our processor.
Doofinder generates a search result during the search function in our web shop that is clickable and leads to the result. The customer never leaves the Gottwald online shop for this.
The data transmitted to Doofinder is used exclusively for the purpose of realization of the search function and deleted after completion of the current session.
c) Credit reports
If you choose the payment method “invoice,” we will call up creditworthiness information from specialized financial services companies (credit agencies) upon conclusion of the contract, if necessary.
This data processing is part of the pre-contractual measures necessary that we take to fulfill the purchase contract between you and us resulting from your order.
For this purpose, we transmit on the basis of GDPR Article 6 (1) b) the following categories of personal information to the financial services companies commissioned by us:
- Name
- Address
- Date of birth, if applicable
of customers/interested parties/business partners, for the purpose of a sanction list audit of business partners.
We have concluded order processing contracts with the following credit agencies:
- Creditreform Boniversum GmbH, Hellersbergstraße 11, 41460 Neuss
d) Payment service provider
In the course of contract processing, you have the option to select PayPal as an external payment service provider after placing an order.
If you choose this option, we will transmit the following categories of personal data to the payment service provider you have chosen on the basis of GDPR Article 6 (1) a):
- Invoice amounts
- Payment details
- Customer information (ID, e-mail, name, telephone number, country)
If you decide to use the services of PayPal, a separate contract may be concluded between you and this service provider for which Franz Gottwald GmbH + Co. is not responsible.
Please note that in the course of processing the contract, you may have to receive notifications from PayPal that are part of the payment process and over which we have no influence.
If you choose to receive your invoice on paper, we will send your address data to the postal service provider commissioned by us based on GDPR Article 6 (1) b).
All other payment options will be processed directly by us and require no data to be passed on to third parties. Data processing is then based on GDPR Article 6 (1) b).
e) Shipping service provider
We use shipping service providers to ship your order.
This data processing is necessary for the fulfillment of the contract between you and us.
For this purpose, we transmit on the basis of GDPR Article 6 (1) b) the following categories of personal information to the shipping service provider commissioned by us:
- Name
- Address
- Telephone number, if applicable
- Goods tracking code
We have concluded a data processing agreement with the following service providers:
- UPS for standard parcels
- DB Schenker for forwarding shipments
- TNT/FedEx (FedEx Express Deutschland GmbH)
- GLS (General Logistics Systems Germany GmbH & Co. OHG)
- Night Star Express
- Hellmann Worldwide Logistics Germany GmbH & Co .KG for Hamburg
Our system generates a tracking code for you that we will send to the e-mail address registered during the purchase process.
The e-mail contains a link that you can use to track the shipment with the service provider. By clicking on this link, you will leave Franz Gottwald GmbH + Co KG’s area of responsibility under data protection law.
In exceptional cases, we may use the services of other unnamed shipping service providers in order to deliver your order to you promptly and at a reasonable price.
Please note that in the course of shipping, you may receive notifications from the service providers that are part of the fulfillment of the contract and over which we have no influence.
f) Valuation service providers
When you place an order, we ask you for your consent to send us a review link.
The review system is provided by our partner Trusted Shops. If you select the option "I agree that my contact details will be sent to Trusted Shops in order to provide feedback on my order" in the "Terms and Conditions and Cancellation Policy" box, we will send:
- Order date
- Order number
- Your email address
- Product details
to Trusted Shops SE, Subbelrather Str. 15c, 50823 Cologne.
You will then receive an invitation email from this partner to use the review system. Please note that if you follow the link in the email, the website you access is subject to the data protection responsibility of Trusted Shops SE and not Franz Gottwald GmbH + Co. KG.
f.1.) Will the data be passed on - if so, to which third parties? Also to third countries?
Trusted Shops uses hosting and infrastructure service providers. Services from Amazon Web Services (AWS) are also used. AWS is based in the USA. However, Trusted Shops and AWS agreed that Germany would be the server and thus the processing location. This means that Art. 44 ff. of the GDPR on the transfer of personal data to a third country are not applicable. The ECJ ruling Schrems II therefore has no direct impact on processing.
Transfer to the United States can only occur in the following exceptional case: In order to properly display the Trustbadge, AWS is used as a CDN provider. The processing required for this generally takes place on servers in the European Union, in particular in Germany. However, it can happen that servers in third countries are also used if the website is accessed from such a country.
In addition, when the website is accessed and the Trustbadge is displayed, a log file is written and stored on servers provided by AWS. In this case, too, processing takes place within the European Union.
An appropriate level of data protection is also ensured by the conclusion of EU standard contractual clauses.
f.2.) Integration of the Trusted Shops Trustbadge / other Trusted Shops widgets
Trusted Shops widgets are integrated into this website to display Trusted Shops services (e.g. seal of approval, collected reviews) and to offer Trusted Shops products to buyers after an order. This serves to protect our legitimate interests in optimal marketing by enabling secure shopping in accordance with Art. 6 Paragraph 1 Clause 1 Letter f of GDPR, which prevail in the context of a balancing of interests. The Trustbadge and the services advertised with it are an offer from Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops"), with whom we are jointly responsible for data protection in accordance with Art. 26 of GDPR. As part of this data protection notice, we will inform you below about the essential contractual contents in accordance with Art. 26 Paragraph 2 of GDPR.
As part of the joint responsibility that exists between us and Trusted Shops, please contact Trusted Shops with data protection questions and to assert your rights using the contact options provided in the data protection information there. Regardless of this, you can always contact the responsible person of your choice. Your request will then, if necessary, be forwarded to the next responsible person for response.
f.3.) Data processing when integrating the Trustbadge / other widgets
The Trustbadge is provided by a US CDN provider (content delivery network). Please note the information in "Is the data passed on...".
When you access the Trustbadge, the web server automatically saves a so-called server log file, which also contains your IP address, the date and time of access, the amount of data transferred and the requesting provider (access data) and documents the access. The IP address is anonymized immediately after collection so that the stored data cannot be assigned to you personally. The anonymized data is used in particular for statistical purposes and for error analysis.
f.4.) Data processing after order completion
After the order has been completed, order information (order total, order number, product purchased if applicable) and your email address hashed using a cryptographic one-way function are sent to Trusted Shops. The legal basis is Art. 6 Paragraph 1 Clause 1 Letter f of GDPR. This serves to check whether you are already registered for services with Trusted Shops and is therefore necessary to fulfil our and Trusted Shops' overriding legitimate interests in providing the buyer protection linked to the specific order and the transactional evaluation services in accordance with Art. 6 Paragraph 1 Clause 1 Letter f of GDPR. If this is the case, further processing will take place in accordance with the contractual agreement concluded between you and Trusted Shops. If you are not yet registered for the services, you will then be given the opportunity to do so for the first time (see [evaluation service provider]). Further processing after registration is also governed by the contractual agreement with Trusted Shops. If you do not register, all transmitted data will be automatically deleted by Trusted Shops and personal reference will then no longer be possible.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis is Art. 6 Para. 1 lit. f GDPR for the purpose of ensuring trouble-free operation. Please note the information in "If the data is passed on...".
4. Rights of data subjects
You have the right:
- to request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you can request information about the purposes of the processing, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data, if it was not collected by us, the existence of automated decision-making, including profiling and, where applicable, request meaningful information about its details;
- in accordance with Art. 16 GDPR, to demand immediate correction of incorrect or completion of your personal data stored by us;
- in accordance with Art. 17 GDPR, to demand the deletion of your personal data stored by us unless the processing is necessary for exercising the right to freedom of expression and information, for the fulfillment of a legal obligation, for reasons of public interest or for the establishment, exercise or defense of legal claims;
- in accordance with Art. 18 GDPR, the restriction of the processing of your personal data, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you oppose the erasure of the personal data; and we no longer need the data, but you need it to assert your rights, exercise or defend legal claims or you have lodged an objection to the processing in accordance with Art. 21 GDPR;
- in accordance with Art. 20 GDPR, your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request the transfer to another controller;
- in accordance with Art. 7 (3) GDPR, you may revoke your consent to us at any time. The consequence of this is that we will not be able to continue this data processing based on this consent in the future and
- in accordance with Art. 77 GDPR to lodge a complaint with a supervisory authority if you are of the opinion that the processing of your personal data has been performed unlawfully. You can usually contact the
supervisory authority of your usual place of residence or workplace or of our registered office.
It is sufficient to send an e-mail to the e-mail address provided in the imprint in order to exercise these rights.
5. Data security
We use the common SSL procedure (Secure Socket Layer) within the website visit in connection with the respective highest encryption level supported by your browser. As a rule, this is 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. Whether a single page of our website is transmitted in encrypted form can be recognized by the closed display of the key or lock symbol in the lower status bar of your browser.
We also make use of appropriate technical, organizational measures and security measures to protect your data against accidental or deliberate manipulation, partial or complete loss, destruction or against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
6. Up-to-dateness and amendment of this Data Protection Declaration
This Data Protection Declaration is currently valid and was last updated in September 2024.
Due to the further development of our website and offers on it or to changes in legal or regulatory requirements, it may be necessary to change this Data Protection Declaration. You can access and print out the respective current Data Protection Declaration on this website at any time.