2 Data Processing in Detail
2.1 Collection of access data
(1) When accessing our website, information is automatically transmitted from your browser to us; this includes the name of the website and files that are accessed, the date and time they are accessed, the quantity of data transmitted, reports about successful access, the browser type and version, your operating system, the referrer URL (the page you visited prior to visiting our website), your IP address and the requesting provider.
(2) The processing of your above-mentioned personal data is technically necessary for offering our website as a service to you and is carried out based on our legitimate interests in accordance with Art. 6(1) (f) GDPR regarding the operation of our website and, to ensure the safeguarding of the security of the processing (e.g., to prevent and identify cyber-attacks).
(3) The collection and storage of your personal data in log files is necessary for the provision of the website. For this reason, you may not request the deletion or correction of this data or object to its processing.
2.2 Contacting us
(1) When you contact us (via contact form or e-mail) the request including all resulting personal data (name, request, contact details) will be stored and processed by us for the purpose of processing your request.
(2) This data is processed based on Art. 6 (1) (b) GDPR if the request is related to the fulfillment of an order or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR), if applicable.
(3) Your information may be stored in our customer relationship management systems (“CRM systems”). The legal basis for the further processing of your data is the preparation of a business transaction (in accordance with Art. 6 (1) (f) GDPR).
2.3 Use of cookies
(1) We only use non-essential cookies if you have given your express consent (opt-in) in accordance with § 25 German Telecommunications-Telemedia Data Protection Act (TTDSG). In addition, if you do not want to have cookies stored on your computer you can deactivate the corresponding option in your system settings on their browser. Stored cookies can also be deleted in the browser’s system settings. Disabling cookies may limit the functionalities of this website.
(2) The legal basis for the use of cookies that are required for the technical functionality of the online platform is Art. 6 (1) (f) GDPR. Our legitimate interest is the user-oriented and economically efficient operation of our website.
(3) If you have consented to the storage of cookies or to access information on your end device, both activities are carried out based on § 25 (1) TTDSG.
(4) The legal basis for the data processing of data stored in cookies for the online marketing measures described below is your consent in accordance with Art. 6 (1) (a) GDPR.
2.4 Cookie consent management
(1) We use the cookie consent management tool provided by Cookiebot, a company registered under the trade name Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark. Cookiebot uses technologically required cookies (cookiebot cookie) to manage user consent in order to save the user’s consent to use the cookie. Cookiebot does not process any personal data whatsoever.
(2) The cookie that is stored only contains information about your consent, which was granted or declined when accessing the website. If you later would like to revoke this consent, you can simply delete the cookie in the browser. If you access the website again, the website will ask for you to consent to the cookie again.
(3) We obtain the consent granted by the user so we can use cookies on all web pages in the www.heraeus.com domain.
2.5 Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager is a tool that we can use either directly in your browser (client-side tagging) or indirectly cloud-based (server-side tagging) to integrate tracking or statistical tools and other technologies on our website. No user profiles are created by the Google Tag Manager itself, no cookies are set or stored and no independent analyzes are carried out. The Google Tag Manager only serves to manage and display the tools integrated via it. When using the Google Tag Manager, however, your IP address is recorded, which can also be transmitted to Google's parent company in the United States.
With regard to the processing of users' personal data, reference is made to the following information on Google services. Usage guidelines:
https://www.google.com/intl/de/tagmanager/use-policy.html
The Google Tag Manager is used based on your consent under Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. The consent can be revoked at any time for the future.
2.6 Google Analytics
This website uses functions of the web analysis service Google Analytics either directly in your browser (client-side tracking) or indirectly on our webserver (server-side tracking). The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors.
The website operator receives various usage data, such as page views, length of stay, operating systems used and origin of the user. This data may be summarized by Google in a profile that is assigned to the respective user or their device.
The aim of using Google Analytics is to enable the user to be recognized for the purpose of analyzing user behavior through the use of various technologies (e.g., cookies or device fingerprinting). We use demographic characteristics for our analyses. The information collected by Google about the use of our website is usually transmitted to a Google server in the USA and stored there.
The use of Google Analytics is based on your consent according to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. The consent can be revoked at any time for the future.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://privacy.google.com/businesses/controllerterms/mccs/
.
You can object to the collection and storage of data at any time with effect for the future. You can object to the future collection and storage of your data by Google Analytics by downloading and installing the browser plug-in available under the following link:
https://tools.google.com/dlpage/gaoptout
.
We have concluded an order processing contract with Google.
Data stored by Google at the user and event level that is linked to cookies, user identifiers (e.g., User ID) or advertising IDs (e.g., DoubleClick cookies, Android advertising ID) are anonymized after 26 months or deleted. You can find details on this under the following link:
https://support.google.com/analytics/answer/7667196
.
You can find more information about the use of data by Google as well as settings and opt-out options on Google’s websites:
https://www.google.com/intl/de/policies/privacy/partners
(“Use of data by Google when using the websites or apps of our partners”),
https://www.google.com/policies/technologies/ads
(“Use of data for advertising purposes),
https://www.google.de/settings/ads
(“Managing information that Google uses to show you advertising”).
2.7 Google Target Audience
We use Google Analytics (for details please see above) to form target groups, provided you have given your consent to the use of Google Analytics, in order to show the ads that are displayed within the advertising services of Google and its affiliates only to those users who have either shown an interest in our website or who have certain characteristics (e.g., interests in certain topics or products determined from websites visited) and that we have sent to Google (so-called “remarketing” or “Google Analytics Audiences”).
We use Remarketing Audiences to ensure that our ads correspond to the potential interests of users.
The data is processed on the basis of your consent in accordance with Art. 6 (1) (a) GDPR.
You can find more information about the use of data by Google as well as settings and opt-out options on Google’s websites:
https://policies.google.com/technologies/partner-sites
(“Use of data by Google when using the websites or apps of our partners”),
https://www.google.com/policies/technologies/ads
(“Use of data for advertising purposes),
https://www.google.de/settings/ads
(“Managing information that Google uses to show you advertising”).
2.8 Google Display & Video 360
This website uses functions of Google Display and Video 360. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
We use the Google online marketing service “Display & Video 360” to place ads in the Google advertising network (e.g., in search results, in videos, on websites, etc.). Display & Video 360 differs from other services in that it shows real time advertisements based on your presumed interests. This allows us to show ads for and within our website in a more targeted manner so that we only show you those ads that potentially correspond to their interests. When you are shown an ad for products that you have been viewing on other websites, this is referred to as “remarketing”. For these purposes, upon accessing our websites and other websites on which the Google Advertising Network is active, Google will immediately run a code and so-called (re)marketing tags (invisible graphics or code, also known as "web beacons") will be incorporated into the website. With their help, an individual cookie, i.e., a small file, will be saved on the user’s device (comparable technologies may also be used instead of cookies). This file keeps a record of which websites you have visited, what content you are interested in and what offers you have clicked on, as well as technical information about the browser and operating system, websites that have referred you, access duration, and other information regarding the use of our website.
The above information may also be linked with such information from other sources by Google. If you subsequently visit other websites, you may be shown advertisements tailored to your presumed interests on the basis of your user profile.
Your data is processed pseudonymously within the Google Advertising Network. This means that Google does not store and process, for example, your name or email address but instead processes the relevant data using cookies within the pseudonymous user profile. In other words, from the perspective of Google, the ads are not managed and displayed for a person who is concretely identifiable, but rather for the person with the cookie, irrespective of who this person is. This does not apply if you have expressly permitted Google to process the data without pseudonymization. The information about you collected by Google Marketing Services is transmitted to Google and stored on Google servers in the U.S.
The use of Google Remarketing is based on your consent according to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. The consent can be revoked at any time for the future.
You can find more information about the use of data by Google as well as setting and opt-out options in Google’s privacy policy (
https://policies.google.com/technologies/ads
s) as well as the settings for showing ads by Google (
https://adssettings.google.com/authenticated
).
2.9 Google (re)marketing services
This website uses functions of Google Analytics Remarketing. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Remarketing analyzes your user behavior while visiting our website in order to classify you into certain advertising target groups in order to show you suitable web messages when you visit other online offers (remarketing or retargeting).
Furthermore, the advertising target groups created with Google Remarketing can be linked to Google's cross-device functions. In this way, interest-related, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one end device (e.g. mobile phone) can also be displayed on another of your end devices (e.g. tablet or PC).
If you have a Google account, you can object to personalized advertising using the following link:
https://www.google.com/settings/ads/onweb/
.
The use of Google Remarketing is based on your consent according to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. The consent can be revoked at any time for the future.
Further information and the data protection regulations can be found in Google's data protection declaration at:
https://policies.google.com/technologies/ads
.
2.10 Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on this website. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With reCAPTCHA we want to check whether the data entry on our website is done by a human or by an automated program. To do this, Google reCAPTCHA analyzes your surfing behavior based on various characteristics. This analysis starts automatically as soon as you enter our website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, how long you have stayed on our website or the mouse movements you have made). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyzes run completely in the background. When you visit our website, you will not be explicitly informed that an analysis is taking place.
The service involves the transmission of your IP address and other data required by Google for the reCAPTCHA service to Google and is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in identifying individual responsibility on the internet and avoiding abuse and spam. Within the framework of the use of Google reCAPTCHA your personal data may be transmitted to Google LLC servers in the U.S.
Further information on Google reCAPTCHA can be found in the Google data protection regulations and the Google terms of use under the following link:
https://policies.google.com/privacy
2.11 LinkedIn Lead Gen Form
As part of our use of LinkedIn, a service offered by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, we use so-called Lead Gen Forms.
Lead Gen Forms are ad placements that enable the integration of contact forms in sponsored content directly on the platform. We use the data you provide there to process your request for information. This data is transmitted to us by LinkedIn.
Our processing of the data is based exclusively on your consent (Art. 6 (1) (a) GDPR). You can revoke this consent for the future at any time. For this purpose, a communication by email to
socialmedia@heraeus.com
is sufficient. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.
The data you entered will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g., after we have completed processing your request). Mandatory legal provisions - in particular retention periods - remain unaffected.
The specific purpose of the data processing of the respective Lead Gen Forms is explicitly listed in the context of the advertisement (e.g., sending product information or contacting you for the purpose of answering your inquiry).
2.12 LinkedIn Insight Tag
We use the service LinkedIn Insight Tag, provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, to measure conversions.
This tool creates a cookie on your web browser. We set the cookie exclusively with your consent in accordance with § 25 (1) TTDSG. The processing of the data is based exclusively on your consent (Art. 6 (1) (a) GDPR).
The cookie enables the collection of data regarding LinkedIn member’s visits on our website including the URL, referrer, IP address, device and browser characteristics (User Agent), and timestamp. The IP addresses are truncated or hashed (when used for reaching LinkedIn members across devices), and LinkedIn members’ direct identifiers are removed within seven days in order to make the data pseudonymous. This remaining pseudonymized data is then deleted within 180 days.
LinkedIn does not share any personal data with us, but offers anonymous reports on website audience and display performance.
LinkedIn members can control the use of their personal data for advertising purposes through their account settings:
https://www.linkedin.com/psettings/advertising/actions-that-showed-interest
Further information on data protection at LinkedIn can be found in LinkedIn's data protection information:
https://www.linkedin.com/legal/privacy-policy
2.13 LinkedIn Retargeting
We use the LinkedIn remarketing provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, to display our advertising to a dedicated target group.
We use LinkedIn to show the advertisements displayed within LinkedIn advertising services and its affiliates only to those users who have also shown an interest in our website or who have certain characteristics (e.g., interests in specific themes or products that are determined from the websites visited), which we submit to LinkedIn (so-called "remarketing"). We use LinkedIn to ensure that our ads correspond to the potential interests of users.
In addition, LinkedIn offers the possibility of retargeting via the Insight Tag. We can use this data to display targeted advertising outside of our website without identifying you as a website visitor.
The processing of the data is based exclusively on your consent (Art. 6 (1) (a) GDPR). You can revoke this consent for the future at any time by changing the Heraeus cookie settings:
https://www.heraeus.com/en/group/heraeus_group/cookie.html
LinkedIn members can control the use of their personal data for advertising purposes through their account settings:
https://www.linkedin.com/psettings/advertising/actions-that-showed-interest
Further information on data protection at LinkedIn can be found in LinkedIn's data protection information:
https://www.linkedin.com/legal/privacy-policy
2.14 Microsoft Dynamics 365 Cloud for Marketing
We use the Microsoft Dynamics 365 Cloud for Marketing automation system provided by Microsoft Corporation (Microsoft Deutschland GmbH, Walter-Gropius-Straße 5, 80807 Munich, Germany) – hereafter referred to as “Microsoft” – to carry out marketing campaigns, for analysis purposes and for target group-specific contact with customers and potential customers. The data is processed within the European Union.
In particular, we use the system to send email communications (e.g., in connection with the provision of downloads), for event management (e.g., to manage event participants) and to provide landing pages and contact forms.
The use of Microsoft and the system, the collection and analysis of statistics and the logging of the registration procedure for communication by email are carried out based on your consent to receive email communication via Microsoft Dynamics 365 Cloud for Marketing according to Art. 6 (1) (a) GDPR, according to Art. 6 (1) (f) GDPR regarding the download of Whitepapers and according to § 25 (1) TTDSG regarding the use of cookies. The consent can be revoked at any time for the future. We are interested in a user-friendly and secure system that both serves our business interests and also meets the expectations of users.
System components integrated in our website (e.g., forms) use so-called “cookies” that are stored on the user’s computer and enable us to analyze the use of the website.
In particular, the following information is collected: client ID, geographical location, browser type, duration of the visit and pages accessed.
Pseudonymized email tracking: The statistical information collected also includes whether the newsletter was opened, when it was opened, and which links you clicked on. While this information can technically be attributed to individual newsletter recipients, the analysis of personal data has been deactivated and information about newsletter recipients is only analyzed pseudonymously and cannot be decrypted and attributed to individual users.
Double opt-in and recording of data: Subscribing to our newsletter is subject to a so-called double opt-in process. This means that after subscribing for our newsletter you receive an email in which you are asked to confirm your subscription. Such confirmation is necessary to ensure that people do not subscribe using someone else’s email address. The newsletter subscription is logged so the subscription process can be verified in accordance with legal requirements. This includes recording the date and time of the subscription and the confirmation as well as the IP address. The changes to your data saved by the email marketing service provider are also logged.
Unsubscribe: You can unsubscribe from the newsletter at any time, i.e., you can revoke your consent to receive it. There is an unsubscribe link at the end of each newsletter. Your personal data that has been processed in connection with the mailing of the newsletter will be deleted after you unsubscribe.
Further data privacy information can be found in the Microsoft privacy policy at
https://privacy.microsoft.com/en-US/privacystatement
.
Further information about the use of cookies in connection with the system can be found at
https://docs.microsoft.com/en-US/dynamics365/marketing/cookies
.