Data Privacy

As of 04 / 2024

We take the protection of your personal data very seriously and strive to provide you with comprehensive information about the processing of your personal data. The following privacy policy explains how and for what purposes we process your personal data when you visit our website and/or contact us.

As a rule, the personal data of yours that we collect is obtained directly from you. The specific legal bases are the EU General Data Protection Regulation (GDPR) and the German Telecommunications and Telemedia Data Protection Act (Telekommunikation-Telemedien-Datenschutz-Gesetz – TTDSG).

1. Controller within the Meaning of Article 4(7) GDPR

The controller within the meaning of Article 4(7) GDPR responsible for the processing of data described below is:

Schwarz Unternehmenskommunikation GmbH & Co. KG
Stiftsbergstraße 1
74172 Neckarsulm, Germany

Phone: +49(0)7132 – 30788600
E-mail: kontakt@mail.schwarz

2. Communication by E-mail/Telephone/Mail

2.1. Purposes of the Processing/Legal Basis

We treat all personal data that we receive from you by e-mail, telephone or mail confidentially. We use your data solely for the limited purpose of processing your inquiry. The legal basis for the processing is Article 6(1)(f) GDPR. Our legitimate interest arises from the interest in responding to your inquiries so that customer satisfaction is ensured and promoted.

When you send us personal data by contacting us for purposes of initiating or performing an existing contractual relationship, Article 6(1)(b) GDPR is the legal basis for data processing.

2.2. Recipients/categories of recipient

As a rule, we do not transfer the data to third parties outside of Schwarz Unternehmenskommunikation GmbH & Co. KG. In exceptional cases, we will have a processor process the data on our behalf. Such processors are carefully selected and bound by contract in accordance with Article 28 GDPR.

Where necessary to process your inquiry, we transfer your data to companies of Schwarz Group, such as Schwarz Dienstleistung KG.

2.3. Obligation to Provide Your Data

You are under no statutory or contractual obligation to provide personal data to us. However, if you do not provide us with the data required to process your request, we will not be able to process or respond to it.

2.4. Storage Time/Criteria for Determining Storage Time

We delete or securely anonymize all information we receive from you when you make inquiries no later than 90 days after the final response is sent to you. The information is retained for 90 days in case you contact us again after receiving a response from us on the same matter and we need to refer to our previous correspondence. Based on experience, we generally do not receive any questions concerning our responses after 90 days. If you assert your rights as a data subject, your personal data will be stored for three years after the final response in order to document the fact that we provided you with comprehensive information and that the legal requirements have been met.

Personal data that you send to us as part of initiating or performing a contract will be deleted after no more than 12 years.

3. Press Inquiries

3.1. Purposes of the Processing/Legal Basis

As part of your press inquiry, we also process your business contact details in addition to your inquiry. We use your data solely for the limited purpose of processing your inquiry. In addition, we keep your request for a fixed period of time to ensure that the request history can be traced. The legal basis for the processing is Article 6(1)(f) GDPR. The legitimate interest lies in effectively and expertly processing your inquiry.

In addition, we may forward your request internally to other companies of Schwarz Group for coordination. Article 6(1)(f) GDPR is the applicable legal basis for this. The legitimate interest lies in a uniform external presentation of the Schwarz Group and the effective and professional processing of your request.

3.2. Recipients/Categories of Recipient

As a rule, we do not transfer the data to third parties outside of Schwarz Group. In exceptional cases, we will have a processor process the data on our behalf. Such processors are carefully selected and bound by contract in accordance with Article 28 GDPR.

Where necessary to process your inquiry, we transfer your data to companies of Schwarz Group.

3.3. Obligation to Provide Your Data

You are under no statutory or contractual obligation to provide personal data to us. However, if you do not provide us with the data required to process your request, we will not be able to process it.

3.4. Storage Time/Criteria for Determining Storage Time

We will retain any personal data that we receive from you in connection with inquiries for 10 years.

4. Data Processed when You Visit this Website

4.1. Purposes and Legal Basis of Data Processing

When you visit this website, log files are generated containing the following information:

  • the website from which you visit our site;
  • the date and time of access;
  • the client request;
  • the browser you use to access our website;
  • the http response code;
  • the data volume transmitted;
  • the operating system-

The legal basis for the processing is Article 6(1)(f) GDPR. Our legitimate interest arises from our interest in protecting our systems and preventing improper and/or fraudulent activity each time that a user accesses this website.

4.2. Recipients/Categories of Recipient

In exceptional cases, your personal data may be accessible to Schwarz IT KG, Stiftsbergstraße 1, 74172 Neckarsulm, Germany, for support and maintenance purposes because the website is hosted on our behalf on servers provided and operated by Schwarz IT KG.

4.3. Obligation to Provide Your Data

You are under no statutory or contractual obligation to provide personal data to us. However, such data will be processed for technical reasons as soon as you access our site. The only way to prevent your data from being processed is to stop using our website.

4.4. Storage Time

We retain said data for a period of 10 days.

5. Cookies

We, Schwarz Unternehmenskommunikation GmbH & Co. KG, Stiftsbergstraße 1, 74172 Neckarsulm, Germany, are the controller with respect to data processing in connection with the use of "cookies" and other similar technologies to process usage data on all (sub-)domains at www.gruppe.schwarz.
Cookies are small text files that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit our websites. Cookies do not cause any harm to your end device, nor do they contain any viruses, trojans or other malware. The cookie stores certain information connected with the specific end device deployed. This does not, however, mean that we will immediately become aware of your identity.
You may also configure your browser to ensure that a warning appears every time a new cookie is placed. This makes the use of cookies more transparent for you. You may also configure your browser to refuse acceptance of all or some cookies from certain sources. Please be advised, however, that disabling cookies may limit the functionality of this website.

5.1. Purposes and legal basis of processing

Cookies and the other technologies used to process usage data are deployed for the following purposes, depending on the categories of cookie/other technologies:

  • Technically necessary: these cookies help to make a website usable by enabling basic functions such as site navigation and access to secure pages. The website cannot function properly without these cookies.
  • Preferences: using these methods, we can take into account your actual or perceived preferences to enhance the user experience. For example, we can use your settings to display our website in a language relevant to you. They also mean we can avoid displaying products that may not be available in your region.
  • Statistics: these methods enable us to tailor the design of our services by producing anonymized statistics about how they are used. For example, we can use them to determine how better to adapt our websites to user habits.
  • Marketing: these enable us to display relevant advertising content based on an analysis of your usage behavior. Your usage behavior can also be tracked over various websites, browsers or devices via a user ID (unique identifier).

Depending on the purpose, the use of cookies and similar technologies to process usage data involves processing the following types of personal data in particular:

Technically Necessary:

  • user inputs, in order to remember inputs across multiple sub-pages;
  • Data to play back multimedia content (e.g., playing videos selected by you).
  • Required Data.

Preferences:

  • Settings to customize the user interface that are not linked to a permanent identifier.

Statistics:

  • pseudonymized usage profiles containing information on the use of our website. These contain in particular:
  • browser type/browser version;
  • operating system used;
  • referrer URL (i.e., the previously visited page);
  • host name of the accessing computer (IP address);
  • time of the server request;
  • individual user ID; and
  • events triggered on the website (web browsing behavior).
  • The IP address is routinely anonymized, which in principle means it is no longer possible to identify you.
  • We only store the user ID together with other data you provide (e.g., name, e-mail address) if you give us express permission to do so. In itself, we cannot use the user ID to identify you.

Marketing:

  • pseudonymized usage profiles containing information on the use of our website. These contain in particular:
  • IP address;
  • individual user ID;
  • events triggered on the website (web browsing behavior).
  • IP addresses are routinely anonymized, which in principle means it is no longer possible to identify you.
  • We only store the user ID together with other data you provide (e.g., name, e-mail address) if you give us express permission to do so. In itself, we cannot use the user ID to identify you. We may potentially share the user ID and associated usage profiles with third parties via providers of advertising networks.

The legal basis for using preference, statistics and marketing cookies and similar technologies is your consent given pursuant to Article 6(1)(a) GDPR. The legal basis for using technically necessary cookies and similar technologies is your consent given pursuant to Article 6(1)(f) GDPR and section 25 (2) no. 2 TTDSG. We have a legitimate interest in ensuring the technical stability and security of website operation.

You may withdraw/modify your consent at any time with effect for the future without this affecting the lawfulness of the processing based on consent before its withdrawal. Click here to make your selection.

For an overview of the cookies and other technologies we use, including the respective purposes of processing, storage periods and any third party providers involved, see our cookie policy.

6. Our Social Media Sites

6.1. Responsibilities

The party responsible for the collection and processing of data described below (the controller) is in some cases us, Schwarz Dienstleistung KG, Stiftsbergstraße 1, 74172 Neckarsulm, and in some cases the operator of the relevant social media platform. For certain types of processing, Schwarz Dienstleistung KG and the platform operator act as joint controllers as defined in Article 26 GDPR.

Schwarz Dienstleistung KG, operates the following social media sites: TikTok

6.1.1. Responsibilities of the Platform Operator

Schwarz Dienstleistung KG (SDL) has only limited control over the processing of data by the operators of social media platforms (e.g., the management of members and the information shared). In the situations in which SDL is able to have influence and can set parameters for the data processing, SDL endeavors to ensure within the confines of the options available to it that the social media platform operator deals with the data in accordance with data protection law requirements. In many cases, however, SDL is unable to influence the way in which social media platform operators process data and also does not know exactly which data they process.

Platform operators operate the entire IT infrastructure of the service, have their own privacy policies and maintain their own user agreements with you (where you are a registered user of the social media service). The operator is also solely responsible for all questions relating to the data that makes up your user profile, which SDL as a company has no access to.

You will find further information about the data processing performed by social media platform operators and your rights to object in the privacy policies of the operators. TikTok

6.1.2. Responsibilities of Schwarz Dienstleistung KG

6.1.2.1. Purposes and Legal Basis of Data Processing

SDL processes data on its social media sites for the purpose of providing information to users about services, promotions, prize draws, specific topics and latest company news, to interact with visitors to its social media sites on these topics, and to respond to relevant inquiries and positive or negative feedback.

SDL merely reserves the right to delete content if it becomes necessary to do so. SDL may share your content on its site if this is one of the functions of the social media platform, and communicates with you through the social media platform. Article 6(1)(f) GDPR is the legal basis for this. The processing is carried out for the purpose of public relations work and communications. Operators have no ability to influence SDL's processing of your data in connection with customer communications or prize draws.

As already mentioned, where social media platform operators give SDL the option, it makes sure it designs its social media sites to be as compliant as possible with data protection laws.

6.1.2.2. Recipients/Categories of Recipient

The data entered by you on SDL’s social media sites, such as comments, videos, images, likes, public messages, etc., is published by the social media platforms and is not used or processed by SDL for other purposes at any time. SDL merely reserves the right to delete unlawful content if it becomes necessary to do so. This would be the case, for example, for posts that infringe rights or violate the law, comments that incite hatred, offensive comments (sexually explicit content) or attachments (e.g., images or videos), which may be in violation of copyright laws, moral rights/rights of publicity or criminal law.

SDL may share your content on its site if this is one of the functions of the social media platform, and communicates through the social media platform. If you post an inquiry on the social media platform, SDL may also, depending on the required response, refer you to other more secure modes of communication that guarantee confidentiality. You always have the option of sending confidential inquiries to the SDL's postal address.

6.1.2.3. Obligation to Provide Your Data

You are under no statutory or contractual obligation to provide personal data to SDL. When you use its social media sites for purely informational purposes, SDL does not collect any personal data. You can still visit SDL’s sites even if you do not wish to provide it with any personal data, but you will not be able to use any enhanced features such as the news function and the function allowing you to post images or comments etc.

6.1.2.4. Storage Time

SDL deletes or securely anonymizes all information it receives from you when you make inquiries no later than 90 days after the final response is sent to you. The information is retained for 90 days in case you contact SDL again after receiving a response from SDL on the same matter and it needs to refer to our previous correspondence. Based on experience, we generally do not receive any questions concerning responses after 90 days. If you assert your rights as a data subject, your personal data will be stored for three years after the final response in order to document the fact that SDL provided you with comprehensive information and that the legal requirements have been met.

All public posts that you put on the social media sites remain in the timeline for an indefinite period, unless SDL deletes them as part of updating the information on the topic, they violate the law or breach SDL’s guidelines or policies, or you delete the post yourself. SDL has no control over the deletion of your data by the operator itself. The privacy policy of the relevant operator therefore also applies in relation to the storage period.

6.2. Processing as joint controllers

In some cases, we and the operator of the social media service act as joint controllers as defined in Article 26(1) GDPR:

SDL and the platform operator act as joint controllers with regard to the web tracking methods used by the social media platform operator. Web tracking can occur regardless of whether you are logged in or registered on the social media platform. As already explained, unfortunately SDL has almost no control over the web tracking methods used by social media platforms. SDL cannot switch this off, for example.

The legal basis for the web tracking methods is Article 6(1)(f) GDPR. Optimizing social media platforms and the relevant fan pages is seen as a legitimate interest for the purpose of the above provision.

For further information about recipients and categories of recipients and the storage time/criteria for determining storage time, please refer to the privacy policies of the platform operators. SDL has no influence on these.

You will find information on the rights available to you to prevent these web tracking methods in the privacy policies of the platform operators. You can also contact the platform operators about this using the contact details provided in the legal notice section of their respective websites.

SDL has only a very limited ability to influence and prevent the provision of statistics to it by social media platform operators. However, SDL does ensure that it does not receive any additional optional statistics.

Please be aware that it is possible that social media platforms will use your profile and user behavior data in order to analyze, for example, your habits, personal relationships and preferences etc. SDL has no control over the processing or disclosure of your data by social media platform operators.

6.3. TikTok Analytics

As the operator of the TikTok Page, SDL has access to the so-called TikTok Analytics. The TikTok Analytics are a non-derogable part of a TikTok Page and contain anonymized statistical data of users who have interacted with the TikTok Page of the SDL and/or its content.

This data is collected with the help of so-called cookies, which are set by TikTok and each contain a unique user ID. TikTok processes the so-called "engagement data" to create TikTok Analytics. This may include some or all of the following:

Actions of persons: Viewing content provided by a TikTok account; liking content; commenting on or sharing content; clicking on areas within a TikTok account or its content (e.g., video anchor, account profile, app download); starting a communication with the TikTok account that provided the content.

Information about the actions, the people performing the actions and the browsers/apps used to perform them, such as date and time of action; viewing duration; country/city; age/gender group; user interests; user's device type; and source of content views (e.g., "For You" tab, "Follow" tab, search, etc.).

SDL does not have access to this information collected by TikTok. As the operator of the TikTok Page, TikTok only provides SDL with anonymized statistical analyses and reports on the information collected.

As the operator of the TikTok Page, SDL is jointly responsible with TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, for the collection of the information presented and its consolidation into anonymized analytics provided to SDL by TikTok, so that it has concluded a joint responsibility agreement with TikTok. You can access this at  https://www.tiktok.com/legal/page/global/tiktok-analytics-joint-controller-addendum/en A summary of the main contents of this agreement can be found at  https://www.tiktok.com/legal/page/global/information-about-tiktok-analytics/en .

By collecting the collected data and aggregating it into anonymized statistics, SDL aims to better understand site visitors and gain insights into what content on its TikTok Page is of interest to its audience. On the basis of Article 6(1)(f) GDPR, SDL aims to tailor the content and its information offering to the needs of its visitors in the best possible way and to optimize it accordingly.

If you have any questions about the use of your data with regard to TikTok Analytics and/or wish to assert your data subject rights in this regard, you can contact TikTok directly: https://www.tiktok.com/legal/report/privacy . Alternatively, you can contact TikTok's data protection officer directly: https://www.tiktok.com/legal/report/DPO .

As the provider of the social network and the fact that SDL, as the operator of the TikTok Page, does not have access to the data collected about you as part of TikTok Analytics, TikTok alone has direct access to the necessary information and can also immediately take any necessary measures and provide information. In this respect, you are requested to assert your rights directly against TikTok. Should you nevertheless require the support of SDL, we will be happy to assist you.

7. Your Rights as the Data Subject

Under Article 15(1) GDPR, you have the right to obtain information, free of charge, on the personal data stored about you.

If the statutory requirements are met, you also have a right to rectification (Article 16 GDPR), erasure (Article 17 GDPR) and restriction of processing (Article 18 GDPR) of your personal data.

If the basis of processing is Article 6(1)(e) or (f) GDPR, you have a right to object under Article 21 GDPR. If you object to processing, your data will no longer be processed thereafter, unless the controller demonstrates compelling legitimate grounds for the processing which override the interests of the data subject in the objection.

If you have provided the processed data yourself, you have a right to data portability under Article 20 GDPR.

If the data processing is carried out on the basis of consent granted under Article 6(1)(a) or Article 9(2)(a) GDPR, you may withdraw that consent at any time with effect for the future without this affecting the lawfulness of the previous processing.

In the above-mentioned cases, or if you have questions or complaints, please write to or e-mail the data protection officer. You also have a right to lodge a complaint with a data protection supervisory authority. The data protection supervisory authority located in the state in which you live or where the controller is domiciled has jurisdiction.

8. Data Protection Officer Contact Information

For further questions concerning the processing of your data or the exercise of your rights, please contact the data protection officer of the respective controller.

Schwarz Unternehmenskommunikation GmbH & Co. KG
- Data protection officer -
Stiftsbergstraße 1
74172 Neckarsulm, Germany
datenschutz@mail.schwarz

Schwarz Dienstleistung KG
- Data protection officer -
Stiftsbergstraße 1
74172 Neckarsulm, Germany
datenschutz@mail.schwarz