Privacy Policy
General Information
Data protection is an important topic. Below, we provide information on the collection of personal data when using our website. Personal data refers to all data that can be personally related to you.
When using the website for informational purposes only, i.e., if you do not register or otherwise transmit information to us, we only collect the personal data that your browser technically transmits to our server to display the website (Section 5).
Controller pursuant to Art. 4 para. 7 GDPR
GEVAG GmbH
Hasselstrasse 7a
D-58091 Hagen
info@gevag.de
Data Protection Officer:
Frank Berns
Konzept 17 GmbH
Westring 3
24850 Schuby
Email: mail@konzept17.de
Brief Overview of Data and Processing Operations
We aim to provide you with the required transparency (pursuant to Article 12 GDPR). Therefore, here is an overview of the processing activities:
Types of Data Processed:
- Usage data or communication data (When accessing a website, IP address, device information, access time and time of access, etc.)
- Contact data upon registration or data entry
- Inventory data (Name, company, address, etc.)
- Communication data (if applicable, metadata about calls, emails)
- Content data (especially when sending emails)
Furthermore (internally), the following additional data for our customers, prospective customers, suppliers, and business partners for the provision of services in the areas of quotation and contract management, service and marketing, direct advertising, and customer care:
- Contract data
- Customer master data (CRM)
- Payment data
- Order data and invoice data
Data Subjects (Categories)
- Users of this website (also referred to as visitors)
- Customers (for emails, etc.)
- Suppliers
Purposes
- Operating the website and providing information
- Ensuring the operation of the website and our systems (e.g., firewall, backups)
- Communication with our customers
- Answering inquiries
- Optimization and analysis of the website (e.g., using web analysis tools, see Section 7)
- Providing information for our (potential) customers and suppliers
Legal Bases in General
When processing personal data necessary for the performance of a contract to which the data subject is a party, Art. 6 para. 1 lit. b GDPR serves as the legal basis. This also applies to processing operations necessary for carrying out pre-contractual measures.
If processing is necessary for safeguarding a legitimate interest of our company or a third party, and the interests, fundamental rights, and freedoms of the data subject do not override the first-mentioned interest, then Art. 6 para. 1 lit. f GDPR serves as the legal basis for processing. This is particularly the case when we conduct tracking for website optimization or newsletter reach measurement, as well as for corresponding direct marketing.
Insofar as processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6 para. 1 lit. c GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person necessitate the processing of personal data, Art. 6 para. 1 lit. d GDPR serves as the legal basis.
Insofar as we obtain the data subject's consent for processing operations involving personal data, Art. 6 para. 1 lit. a EU General Data Protection Regulation (GDPR) serves as the legal basis.
Data Subject Rights in General
Briefly:
- Right of Access
- Erasure / Restriction
- Rectification
- Portability
- Withdrawal
- Complaint to the Authority
Detailed Rights:
to request information pursuant to Art. 15 GDPR about your personal data processed by us. In particular, you can request information on the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, and the existence of automated decision-making, including profiling, and, if applicable, meaningful information about its details;
to request without undue delay the rectification of inaccurate personal data or the completion of your personal data stored by us pursuant to Art. 16 GDPR;
to request the erasure of your personal data stored by us pursuant to Art. 17 GDPR, unless processing is necessary for exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims;
to request the restriction of processing of your personal data pursuant to Art. 18 GDPR, insofar as the accuracy of the data is contested by you, the processing is unlawful but you oppose its erasure, and we no longer need the data, but you require it for the establishment, exercise, or defense of legal claims, or you have objected to the processing pursuant to Art. 21 GDPR;
to receive your personal data, which you have provided to us, in a structured, commonly used, and machine-readable format pursuant to Art. 20 GDPR, or to request its transmission to another controller;
to withdraw your consent given once at any time to us pursuant to Art. 7 para. 3 GDPR. This means that we may no longer continue the data processing that was based on this consent for the future and
to lodge a complaint with the supervisory authority responsible for us pursuant to Art. 77 GDPR:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Düsseldorf
Tel.: +49 211/38424-0
poststelle@ldi.nrw.de
Exceptions
The right to erasure does not apply insofar as processing is necessary
- for exercising the right to freedom of expression and information;
- for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health pursuant to Art. 9 para. 2 lit. h and i and Art. 9 para. 3 GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Art. 89 para. 1 GDPR, insofar as the right referred to in section a) is likely to render impossible or seriously impair the achievement of the objectives of that processing, or
- for the establishment, exercise, or defense of legal claims
Website Usage
General Data when Accessing the Page
When using the website for informational purposes only, i.e., if you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security (legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR):
- IP address
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- amount of data transferred in each case
- Website from which the request originates
- Browser
- Operating system and its interface
- Language and version of the browser software
Log Files
Storage in log files takes place to ensure the functionality of the website. Furthermore, the data serves us for website optimization and to ensure the security of our information technology systems. No evaluation of the data for marketing purposes takes place in this context. Our legitimate interest in data processing pursuant to Art. 6 para. 1 lit. f GDPR also lies in these purposes.
The data will be deleted as soon as they are no longer required for the achievement of the purpose for which they were collected.
In the case of data storage in log files, this is the case after seven days at the latest. Further storage is possible. In this case, the IP addresses of users are deleted or anonymized, so that attribution to the calling client is no longer possible.
Cookies
In addition to the data mentioned above, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive, assigned to the browser you are using, and through which certain information flows to the entity setting the cookie (in this case, us). Cookies cannot execute programs or transmit viruses to your computer. They serve to make the overall internet offering more user-friendly and effective.
a) This website uses the following types of cookies, whose scope and functionality are explained below:
- Transient cookies (see b)
- Persistent cookies (see c)
- Depending on the consent given: Cookies for statistical and marketing purposes (e.g., for Google Analytics 4 and Google Ads, see Section 7)
b) Transient cookies are automatically deleted when you close the browser. These include, in particular, session cookies. These store a so-called session ID, with which various requests from your browser can be assigned to the common session. This allows your computer to be recognized when you return to our website. Session cookies are deleted when you log out or close the browser.
c) Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete the cookies in your browser's security settings at any time.
d) You can configure your browser settings according to your wishes and, for example, reject the acceptance of third-party cookies or all cookies. We would like to point out that you may not be able to use all functions of this website.
e) We use cookies to be able to identify you for subsequent visits if you have an account with us. Otherwise, you would have to log in again for each visit.
f) Insofar as we use analytics or marketing cookies (e.g., Google Analytics 4, Google Ads), this only takes place on the basis of your consent. You can withdraw any given consent at any time with effect for the future by deleting the corresponding cookies or changing your settings in the browser or in any cookie settings provided on our website.
Real Cookie Banner
To manage the cookies and similar technologies (tracking pixels, web beacons, etc.) used and related consents, we use the consent tool "Real Cookie Banner". Details on how "Real Cookie Banner" works can be found at https://devowl.io/de/rcb/datenverarbeitung/.
Legal bases for the processing of personal data in this context are Art. 6 para. 1 lit. c GDPR and Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the related consents.
The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we cannot manage your consents.
Cookie Settings
Social Media
We are also represented on social media. However, we do not directly integrate any platform. If you click on the icons of the corresponding portals, the terms of use and data protection regulations of the respective portals apply.
There is no obligation at any time to register on any of these portals for informational purposes or to contact us (the provider). Instead, various contact options are available to you (phone, email, contact form).
No unauthorized disclosure of personal data exists through integration.
Integration of Third-Party Services and Plugins
WEB ANALYTICS BY GOOGLE ANALYTICS 4
We use Google Analytics 4 on our website, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google). Google Analytics uses cookies or similar technologies that enable an analysis of your use of the website.
The following data may be processed in particular:
- IP address (usually only in abbreviated form)
- Information about browser and device
- pages accessed and click paths
- time spent on the pages
- approximate location (region)
- technical events (e.g., errors, loading times)
We have configured Google Analytics so that your IP address is usually truncated within the EU or EEA. Direct personal identifiability is thus to be excluded.
Google will use the information generated by the cookies to evaluate your use of the website, to compile reports on website activities, and to provide us with other services related to website usage and internet usage.
Data may be transferred to servers of Google LLC in the USA. Insofar as data is transferred to third countries, this takes place on the basis of appropriate safeguards (e.g., EU standard contractual clauses or an adequacy decision).
The legal basis for the use of Google Analytics 4 is your consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TTDSG (consent to the storage of information on your terminal equipment or access thereto). You can withdraw your consent at any time with effect for the future by deleting the corresponding cookies or changing your settings.
Further information on Google Analytics can be found at:
https://policies.google.com/privacy and
https://support.google.com/analytics
GOOGLE ADS (CONVERSION TRACKING AND, IF APPLICABLE, REMARKETING)
We use Google Ads, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google), for placing ads in search results and on the Google advertising network, and for measuring the effectiveness of our advertising campaigns (Conversion Tracking). Depending on the configuration, remarketing functions may also be used to display interest-based advertising.
As part of conversion tracking, a cookie is set when you click on an ad placed by Google. If you then visit certain pages of our website, Google and we can recognize that you clicked on the ad and were redirected to our website. A different cookie is assigned to each Google Ads customer. Cookies cannot therefore be tracked across the websites of Ads customers.
The following data may be processed in particular:
- Clicks on ads
- pages accessed and actions on the website
- pseudonymous user ID
- IP address (truncated)
- Browser and device data
When using remarketing, users can be categorized into target groups based on their usage behavior on our and other websites, to whom interest-based advertising is then displayed.
Data may be transferred to Google LLC servers in the USA. Insofar as a transfer to third countries takes place, this is done on the basis of suitable guarantees (e.g. EU standard contractual clauses or an adequacy decision).
The legal basis for the use of Google Ads is your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. You can revoke your consent at any time with effect for the future by deleting the corresponding cookies or changing your settings. In addition, you can deactivate personalized advertising in the settings for advertisements from Google: https://adssettings.google.com
Further information can be found in Google's privacy policy:
https://policies.google.com/privacy
INTEGRATION OF GOOGLE MAPS
On this website, we use the offer of Google Maps. This allows us to display maps directly on the website and enable the convenient use of the map function.
By visiting the corresponding subpage of our website, Google receives the information that you have accessed this subpage. In addition, the data mentioned under §5 of this declaration will be transmitted. This happens regardless of whether Google provides a user account through which you are logged in, or whether there is no user account. If you are logged in to Google, your data will be directly assigned to your account. If you do not want the assignment to your profile on Google, you must log out before calling up the map.
Google stores your data as usage profiles and uses them for purposes of advertising, market research and/or demand-oriented design of its website. Such evaluation takes place in particular - even for users who are not logged in - to provide demand-oriented advertising and to inform other users of the service about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right.
Further information on the purpose and scope of data collection and its processing by Google can be found in Google's privacy policy. There you will also receive further information on your rights and setting options to protect your privacy: https://policies.google.com/privacy
Google may also process personal data in the USA. Insofar as data is transferred to third countries, this is done on the basis of suitable guarantees (e.g. EU standard contractual clauses or an adequacy decision).
IMAGE OPTIMIZATION BY IMAGIFY
To optimize the loading times and the display of images on our website, we use the Imagify service, a service of WP Media SAS, 2 rue des Moulins, 44000 Nantes, France. As part of image optimization, the images used on our website can be processed and delivered on WP Media's servers.
In particular, the following data can be processed:
- IP address of the calling system
- accessed pages or image URLs
- Browser and device information
- technical usage data (e.g. time of retrieval)
Imagify is used to improve the performance of our website and thus our online offer. The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in a fast and efficient provision of the website). Insofar as the use is connected with the setting of cookies that are not technically necessary and we obtain your consent for this, the additional legal basis is Art. 6 para. 1 lit. a GDPR or § 25 para. 1 TTDSG.
Further information on data protection at Imagify/WP Media can be found at:
https://imagify.io/legal/privacy-policy
BACKUPS AND MAINTENANCE BY UPDRAFTPLUS
To secure and restore our website, we use the backup plugin UpdraftPlus from the provider Updraft WP Software Ltd (Simba Hosting), Britannia House, Caerphilly Business Park, Caerphilly, CF83 3GG, United Kingdom.
Backup copies of the website are created at regular intervals. These backups may contain all contents of the website including personal data that was entered via the website (e.g. contents from contact forms).
Depending on the configuration, the backups are stored on our web server or with external storage providers. Insofar as personal data is transferred to external service providers, this is done on the basis of order processing agreements and - in the case of storage services outside the EU/EEA - possibly additional guarantees (e.g. EU standard contractual clauses).
The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in securing our systems and the recoverability of our website in the event of technical problems or security incidents).
Contact Form and E-Mail Contact
A contact form is available on our website, which can be used for electronic contact. The form is provided via the Content Management System WordPress (Plugin Contact Form 7). If a user makes use of this option, the data entered in the input mask will be transmitted to us and stored. This data
- Name of the user
- E-mail address
- Message
- Information about receiving a copy of the contact e-mail
- Consent to data storage
At the time of sending the message, the following data is also stored:
- The IP address of the user
- Date and time of sending
Alternatively, it is possible to contact us via the e-mail address provided. In this case, the user's personal data transmitted with the e-mail will be stored.
In this context, the data will not be passed on to third parties. The data will be used exclusively for processing the conversation.
Status of the Privacy Policy
The privacy policy is occasionally adapted to be able to correspond to the changes in the business process and the legal side. You can always find the latest version on the website.
Status: November 2025