Data Protection Notice
ITK Engineering GmbH (hereinafter “ITK Engineering“ or “We“ or “Us”) welcomes you to our internet pages and mobile applications (together also referred to as “Online Offers”). We thank you for your interest in our company and our products.
ITK Engineering respects your privacy
The protection of your privacy throughout the course of processing personal data as well as the security of all business data is an important concern to us. We process personal data that was gathered during your visit of our Online Offers confidentially and only in accordance with statutory regulations.
Data protection and information security are included in our corporate policy.
ITK Engineering is the controller responsible for the processing of your data; exceptions are outlined in this data protection notice.
Our contact details are as follows: ITK Engineering GmbH, Im Speyerer Tal 6, 76761 Rülzheim, info[@]itk-engineering.de.
Collection, processing and usage of personal data
Processed categories of data
The following categories of data are processed:
- Communication data (e.g. name, telephone, e-mail, address, IP address)
- Contractual master data (e.g. contractual relationships, contractual or product interest)
- Client history
- Contract accounting and payment data
- Planning and regulation data
- Transaction data
- Provision of information (from third parties, e.g. credit reference agencies or from public directories)
Personal data consists of all information related to an identified or identifiable natural person, this includes, e.g. names, addresses, phone numbers, email addresses, contractual master data, contract accounting and payment data, which is an expression of a person’s identity.
We collect, process and use personal data (including IP addresses) only when there is either a statutory legal basis to do so or if you have given your consent to the processing or use of personal data concerning this matter, e.g. by means of registration.
Processing purposes and legal bases
We; as well as the service providers commissioned by us; process your
- Provision of these Online Offers (Legal basis: Justified interest on our part in direct marketing as long as this occurs in accordance with data protection and competition law).
- Resolving service disruptions as well as for security reasons. (Legal bases: Fulfillment of our legal obligations within the scope of data security, and justified interest in resolving service disruptions as well as in the protection of our offers).
- Self-promotion and promotion by others as well as market research and reach analysis done within the scope statutorily permitted or based on consent (Legal bases: Consent / justified interest on our part in direct marketing if in accordance with data protection and competition law).
- Product or customer surveys performed via email and/or telephone subject to your prior express consent. (Legal basis: Consent). Note: In case we involve a market research institute for the purpose of surveys, it shall only act based on our instructions and follow our directives.
- Sending an email newsletter subject to the recipient’s consent (Legal basis: Consent).
- Safeguarding and defending our rights. (Legal basis: Justified interest on our part for safeguarding and defending our rights).
Use and disclosure of personal data for the purpose of processing applications and recruitment
The personal data you share with us will be collected, processed, and used by ITK Engineering solely for the purpose of processing applications and recruitment. ITK ensures data confidentiality by storing and processing your data in accordance with applicable data protection regulations. Recruitment at ITK is carried out in collaboration with the relevant HR representative and department manager. The data shared will be deleted within the statutory period stipulated by law.
Each time you use the internet, your browser is transmitting certain information which we store in so-called log files.
We save log files for a short period of time to determine service disruptions and for security reasons (e.g., to investigate attack attempts) and delete them afterwards. Log files which need to be maintained for evidence purposes are excluded from deletion until the respective incident is resolved and may, on a case-by-case basis, be passed on to investigating authorities.
Log files are also used for analysis purposes (without the IP address or without the complete IP address). Also see module web analysis.
In log files, in particular the following information is saved:
- IP address (internet protocol address) of the terminal device which is being used to access the Online Offer;
- Internet address of the website from which the Online Offer is accessed (so-called URL of origin or referrer URL);
- Name of the service provider which was used to access the Online Offer;
- Name of the files or information accessed;
- Date and time as well as duration of recalling the data;
- Amount of data transferred;
- Operating system and information on the internet browser used, including add-ons installed (e.g., Flash Player);
- http status code (e.g., “Re-quest successful” or “File re-quested not found”).
This Online Offer is not meant for children under 16 years of age.
Data transfer to other controllers
Principally, your personal data is forwarded to other controllers only if required for the fulfillment of a contractual obligation, or if we ourselves, or a third party, have a legitimate interest in the data transfer, or if you have given your consent. Particulars on the legal bases can be found in the Section – Purposes of Processing and Legal Bases. Third parties may also be other companies of the Bosch group. When data is transferred to third parties based on a justified interest, this is explained in this data protection notice.
Additionally, data may be transferred to other controllers when we are obliged to do so due to statutory regulations or enforceable administrative or judicial orders.
Service providers (general)
We involve external service providers with tasks such as sales and marketing services, contract management, payment handling, programming, data hosting and hotline services. We have chosen those service providers carefully and monitor them on a regular basis, especially regarding their diligent handling of and protection of the data that they store. All service providers are obliged to maintain confidentiality and to comply to the statutory provisions. Service providers may also be other Bosch group companies.
Duration of storage; retention periods
Principally, we store your data for as long as it is necessary to render our Online Offers and connected services or for as long as we have a justified interest in storing the data (e.g. we might still have a justified interest in postal mail marketing after fulfillment of our contractual obligations). In all other cases we delete your personal data with the exception of data we are obliged to store for the fulfillment of legal obligations (e.g. due to retention periods under the tax and commercial codes we are obliged to have documents such as contracts and invoices available for a certain period of time).
Cookies are small text files that are saved on your computer when an Online Offer is accessed. In case you access this Online Offer another time, your browser sends the cookies’ content back to the respective seller and, thus, allows the re-identification of the terminal device. Reading the cookies allows us to design our Online Offers optimally for you and makes it easier for you to use them.
Deactivation and deletion of cookies
Your browser allows you to delete any cookies at all times. To do so, please consult your browser’s help functions. This might, however, lead to individual functions no longer being available.
In addition, you could manage and deactivate the use of third party cookies on the following web page: www.youronlinechoices.com/uk/your-ad-choices.
As we do not operate this website, we are not responsible and we are unable to influence the content and availability.
Overview of cookies used by us
In this section, please find an overview of the cookies we use.
Absolutely necessary cookies
Certain cookies are necessary to provide our Online Offers in a secure manner. This category includes, e.g.:
- Cookies that identify or authenticate our users;
- Cookies that temporarily save certain input of the user (e.g. content of a shopping cart or of an online form);
- Cookies that store certain user preferences (e.g. search or language settings);
- Cookies that store data to ensure a trouble-fee playback of video or audio content.
We use analytical cookies to record the usage behavior (e.g. ad banners clicked on, search queries put in) of our users and to evaluate it statistically.
Tracking cookies in connection with social plugins
In our Online Offers we use so-called social plugins from various social networks. They are individually described in this section.
When using plugins, your internet browser creates a direct connection to the respective social networks’ server. This way, the respective provider receives the information that your internet browser accessed from the respective site of our Online Offers – even if you do not have a user account with this provider or are currently not logged into your account. Log files (including the IP address) are, in this case, directly transmitted from your internet browser to a server of the respective provider and might be stored there. The provider or its server may be located outside the EU or the EEA (e.g. in the United States).
The plugins are standalone extensions by social network providers. For this reason, we are unable to influence the scope of data collected and stored by them.
Purpose and scope of the collection, the continued processing and usage of data by the social network as well as your respective rights and setting options to protect your privacy can be found by consulting the respective social network’s data protection notices.
In case you do not wish social network providers to receive and, if applicable, store or use data, you should not use the respective plugins.
Facebook is operated under www.facebook.com by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, and under www.facebook.de by Facebook Ireland Limited, Hanover Reach, 5-7 Hanover Quay, Dublin 2, Ireland (“Facebook”). Find an overview over Facebook’s plugins and their appearance here: developers.facebook.com/plugins; find information on data protection at Facebook here: www.facebook.com/policy.php
Google+ is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Find an overview over Google’s plugins and their appearance here: developers.google.com/+/plugins; find information on data protection at Google+ here: www.google.com/intl/de/+/policy/+1button.html.
Our Online Offers use the YouTube video platform which is operated by YouTube, LLC, 901 Cherry Ave. San Bruno, CA 94066, USA („YouTube”). YouTube is a platform which allows the playback of audio and video files.
When you access a respective site of our Online Offers that contains an embedded YouTube player, this creates a connection to YouTube so that the video or audio file can be transmitted and played back. In do-ing so, data is transferred to YouTube as a data processor. We are not responsible for the processing of such data by YouTube.
Additional information on the scope and purpose of collected data, on further processing and usage of data by YouTube, on your rights and the privacy options available to be cho-sen by you, can be found in YouTube’s data protection notice.
Newsletter with opt-in; Right of withdrawal
Within the scope of our Online Offers you can sign up for newsletters. We provide the so-called double opt-in option which means that we will only send you a newsletter via email after you have explicitly confirmed the activation of the newsletter service to us by clicking on the link in a notification. In case you wish to no longer receive newsletters, you can terminate the subscription at any time by withdrawing your consent. You can withdraw your consent to email newsletters by clicking on the link which is sent in the respective newsletter mail, or in the administrative settings of the online offer. Alternatively, please contact us via the contact details provided in the Contact section.
Our Online Offers may contain links to third party internet pages – by providers who are not related to us. Upon clicking on the link, we have no influence on the collecting, processing and use of personal data possibly transmitted by clicking on the link to the third party (such as the IP address or the URL of the site on which the link is located) as the conduct of third parties is naturally beyond our supervision. We do not assume responsibility for the processing of personal data by third parties.
Our employees and the companies providing services on our behalf, are obliged to confidentiality and to compliance with the applicable data protection laws.
We take all necessary technical and organizational measures to ensure an appropriate level of security and to protect your data that are administrated by us especially from the risks of unintended or unlawful destruction, manipulation, loss, change or unauthorized disclosure or unauthorized access. Our security measures are, pursuant to technological progress, constantly being improved.
To enforce your rights, please use the details provided in the Contact section. In doing so, please ensure that an unambiguous identification of your person is possible.
Right to information and access:
You have the right to obtain confirmation from us about whether or not your personal data is being processed, and, if this is the case, access to your personal data.
Right to correction and deletion:
You have the right to obtain the rectification of inaccurate personal data concerning yourself without undue delay from us. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
This does not apply to data which is necessary for billing or accounting purposes or which is subject to a statutory retention period. If access to such data is not required, however, its processing is restricted (see the following).
Restriction of processing:
You have the right to demand for– as far as statutory requirements are fulfilled – restriction of the processing of your data.
Objection to data processing:
You have the right to object to data processing by us at any time. We will no longer process the personal data unless we demonstrate compliance with legal requirements to provide provable reasons for the further processing which are beyond your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.
Objection to direct marketing:
Additionally, you may object to the processing of your personal data for direct marketing purposes at any time. Please take into account that due to organizational reasons, there might be an overlap between your objection and the usage of your data within the scope of a campaign which is already running.
Objection to data processing based on the legal basis of “justified interest”:
In addition, you have the right to object to the processing of your personal data at any time, insofar as this is based on a justified interest. We will then terminate the processing of your data, unless we demonstrate compelling legitimate grounds according to legal requirements which override your rights.
Withdrawal of consent:
In case you consented to the processing of your data, you have the right to revoke this consent with immediate effect. The legality of data processing prior to your revoca-tion remains unchanged.
You are entitled to receive data that you have provided to us in a structured, commonly used and machine-readable format or – if technically feasible – to demand that we transfer those data to a third party.
Right of complaint with supervisory authority:
You have the right to lodge a complaint with a supervisory authority. You can appeal to the supervisory authority which is responsible for your place of residence or your state of residency or to the supervisory authority responsible for us.
Changes to the Data Protection Notice
We reserve the right to change our security and data protection measures if this is required due to technical development. In such cases, we will amend our data protection notice accordingly. Please, therefore, notice the current version of our data protection notice, as this is subject to change.
Data protection notice for the “ITK Engineering” channel on Facebook
Data Protection Notice
ITK Engineering GmbH (in the following “we” or “us”) thanks you for visiting our Facebook page (also “fan page”) and for your interest in our company.
Controller and privacy policies/ data protection notice
The controllers responsible for processing your data with regard to our fan page are Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland and ITK Engineering GmbH, Im Speyerer Tal 6, 76761 Rülzheim, GERMANY.
You can find our data protection notice at www.itk-engineering.de/en/privacy-policy/. You can also send us an email to datenschutz[@]itk-engineering.de if you have any questions on how we protect your data.
Collecting, processing and using personal data
Data processing by Facebook
Facebook processes your personal data when you visit our fan page. For more information on what kinds of personal data Facebook processes and on what data protection rights you have against Facebook please see Facebook’s privacy notice referred to above. We have no influence on Facebook’s data processing.
Settings options and access to statistical data
Facebook allows us to adjust the following settings on our fan page and gives us access to the following data:
- We can select the target group for which our Facebook fan page and our individual posts published on our fan page are intended. The settings are adjusted based on general parameters (e.g. age group, language, region, interests), which makes it possible to address specific groups with our contents. It is not possible to address or identify individual persons based on the adjustments of the settings Facebook allows us to make.
- Facebook grants us access to statistical analyses that provide information on the use of our fan page. The analyses to which we have access are not suited to individually analyze the browsing habits of selected persons. We merely have access to aggregated data (such as the number of visits, number of likes, number of followers, region of origin, age group, gender) that provide information on our clientele and the use of our fan page. For more information on the statistics provided by Facebook please visit de-de.facebook.com/business/a/page/page-insights.
We cannot influence Facebook’s data processing in any other ways. We process these data in order to publish contents on our fan page addressing the appropriate target group and to better understand and optimize the use of our fan page.
Communication tools we use to communicate with you
You can send us messages on Facebook. When you send us a message on Facebook, we receive the following data from Facebook:
- Incoming message
- Profile picture
- Voice messages
Using these data allows us to process your query and to offer you support (for example, via our fan page you can send us questions regarding our products which we will then answer). We also use these data in an aggregated and anonymized form in order to better understand how our fan page is used. In this regard, we can analyze what groups of persons (e.g. end customers, private individuals, employees) use the communication channels offered on our fan page in what countries and in what language. The processed personal data is deleted 180 days upon receipt of your message the latest.
We will forward the personal data you provide to the Bosch legal entity responsible for the processing of your query (for example, in the event your query refers to a product that is distributed by another Bosch legal entity). The responsible Bosch entity may be located outside the EEA. In such cases, we will transfer your personal data to recipients that are located outside the EEA in so called third countries. In such cases, prior to the transfer we ensure that an appropriate level of data protection exists. You are entitled to receive an overview of third country recipients and a copy of the specifically agreed-provisions securing an appropriate level of data protection. For this purpose, please use contact information provided in our data protection notice referenced above.
The legal basis for the processing of your data is our legitimate interest (Article 6(1)(f) GDPR) or, if applicable, an existing contractual relationship (Article 6(1)(b) GDPR).
If you wish to contact us, please find us at the address stated in the “Controller” section.
To assert your rights, for data protection breaches as well as for suggestions and complaints regarding the processing of your personal data we recommend that you contact our group commissioner for data protection:
Mr. Matthias Goebel
Group Commissioner for Data Protection
Information Security and Privacy Bosch Group (C/ISP)
Robert Bosch GmbH
Date of last revision: 25.05.2018