Data protection notice regarding the obligation to provide information
Thank you for visiting our Internet pages and for your interest in our company. We take the protection of your private data very seriously and want you to feel at ease when visiting our website. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection notice. The use of our website is generally possible without the need to provide personal data. When you visit our Internet pages, we store the date, time, duration, and IP address, as well as the pages you view. This is done exclusively for statistical purposes. This data will not be passed on to third parties. No user-related surfer profiles or the like will be created or processed. Please note that sending data over the Internet (e.g. when communicating by e-mail) may not be fully secure. Complete protection of data against access by third parties is not possible.
Protecting your personal data is very important to us. We therefore process your data strictly in compliance with legal requirements (GDPR). This notice informs you about the way your personal data is processed by KRIWAN Industrie-Elektronik GmbH. The General Data Protection Regulation (GDPR) regulates the information obligations of the data controller towards the data subject, depending on whether personal data is collected from the data subject (direct collection, Art. 13 GDPR) or from third parties (third party collection, Art. 14 GDPR). We process your personal data exclusively within the framework of legal regulations. This includes the following categories of personal data: Master data (e.g. last name, first name, address), contract data (e.g. customer number, insurance number), billing data and bank data, and other similar data.
The following general Data Privacy Policy applies for the KRIWAN INTspector App.
1. Controller of the processed data
KRIWAN Industrie-Elektronik GmbH
Allmand 11
74670 Forchtenberg
Germany
Phone and hotline: +49 (0) 79 47 - 8 22 – 0
Fax: +49 (0) 79 47 - 71 22
E-Mail: info(at)kriwan.de
1.1 Name of the external data protection officer
Firma Priolan
Ulrich Jahnke
u.jahnke(at)priolan.de
Gottlieb-Daimler-Straße 9
74076 Heilbronn
Germany
2. Purposes and legal bases of data processing
2.1 Data processing for the purpose of initiating and executing contracts (Art. 6 Para. 1 b GDPR)
Data processing is necessary for the initiation, execution, and settlement of your contract.
2.2 Data processing with your consent (Art. 6 Para.1 a GDPR)
Where we have obtained your consent to process personal data for specific purposes, processing on this basis is lawful. Consent that has been granted may be withdrawn at any time. This also applies to the withdrawal of declarations of consent that you provided to us before the GDPR became applicable on May 25, 2018.
The withdrawal of consent applies to the future and does not affect the lawfulness of data processing carried out prior to the withdrawal.
2.3 Data processing for legitimate interests (Art. 6 Para. 1 f GDPR)
We process your data lawfully in order to safeguard our legitimate interests. This includes using your personal data to:
If we intend to process your personal data for a purpose not previously specified, we will inform you in advance in accordance with the applicable statutory provisions.
2.4 Data processing based on legal requirements (Art. 6 Para. 1 c GDPR) or in the public interest (Art. 6 Para. 1 e GDPR)
As a company, we are subject to various legal obligations (e.g. tax laws and the German Commercial Code) that require the processing of your data in order to comply with the law.
3. Categories of recipients of personal data
Within our company, access to your data is granted to those departments that require it to fulfill the purposes specified above (see Purposes and Legal Bases of the Processing of Personal Data). This also applies to service providers and agents engaged by us.
We only transfer personal data to third parties if this is necessary for the aforementioned purposes or if you have given your prior consent.
Recipients of personal data may include, for example, printing service providers, retailers, analytics specialists, and data processing companies.
Data transfers, particularly by means of administrative access, to organizations or countries outside the European Union (third-country transfers) are not possible on the basis of the aforementioned purposes and legal bases. In such cases, data may only be accessed if an adequacy decision by the European Commission exists for the respective country, if we have agreed with the service providers on the Standard Contractual Clauses provided by the European Commission for such cases, or if the respective company has established its own binding internal data protection regulations that have been recognized by the data protection supervisory authorities.
4. Duration of data storage
We store your personal data for the purposes specified above. Your data is processed from the time it is collected, insofar as you or a third party provide it to us.
We delete your personal data when the contractual relationship with you has ended, all mutual claims have been fulfilled, and there are no other statutory retention obligations or legal grounds justifying continued storage.
These include, among others, retention obligations under the German Commercial Code (HGB) and the German Fiscal Code (AO). This means that we delete your personal data no later than upon expiry of the statutory retention periods, which are generally 10 years after the end of the contract.
5. Rights of the data subject
You may request information pursuant to Art. 15 GDPR regarding the personal data stored about you by contacting us at the address stated above.
In addition, subject to the requirements of the GDPR, you may request the rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), and restriction of processing (Art. 18 GDPR) of your data.
You have the right to receive the data you have provided in a structured, commonly used, and machine-readable format.
These rights may be subject to restrictions due to statutory or legitimate business interests. In such cases, you will be provided with appropriate information on the basis of your right of access.
5.1 Right of objection
Where we process data to safeguard our legitimate interests (see Section 2.3, Data Processing Based on Legitimate Interests), you have the right to object to such processing at any time on grounds relating to your particular situation.
This also includes the right to object to processing for advertising purposes.
5.2 Right of withdrawal of consent
Consent that has been granted may be withdrawn at any time (see Section 2.2, Data Processing Based on Your Consent).
6. Provision of personal data
Within the scope of our business relationship, you must provide the personal data required to establish and conduct the business relationship and to fulfill the associated contractual obligations, as well as any data that we are legally required to collect.
Without this data, we cannot enter into the contract.
7. Automated decision-making
No automated decision-making, including profiling, takes place for the purpose of establishing or performing this contract.
8. Data sources
We process personal data that we receive from our customers within the scope of our business relationship.
We also process personal data that we are legally permitted to obtain from publicly accessible sources, such as debtor registers, land registers, commercial and association registers, the press, and the Internet.
In addition, we use personal data that we lawfully receive from companies within our Group or from third parties, such as credit agencies.
9. Amendment clause
As our data processing activities are subject to change, we will also update our data protection information from time to time. We will inform you of any changes in due time.
10. Security
We use technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access.
Our security measures are continuously improved in line with technological developments.
11. Children
Personal data should not be transmitted to KRIWAN’s website by children under the age of 18 without the consent of their parents or legal guardians.
KRIWAN encourages all parents and guardians to instruct their children in the safe and responsible handling of personal data on the Internet.
KRIWAN will not knowingly collect, process, or use personal data relating to children.
12. Cookies
This website uses cookies. Cookies are small text files that are sent from the web server to your PC and are usually stored on your hard drive. They are not programs and cannot cause damage to the user's PC.
Cookies enable us to determine whether you are visiting our website again. Personal data is not stored. The information cannot be assigned to a specific person.
You can disable the storage of cookies in your browser settings. For further information, please refer to the help function or user manual of your Internet browser. In this case, some features of the website may only be available to a limited extent.
13. Analytics Tools and Advertising
13.1 Google Analytics
This website uses functions of the Google Analytics web analytics service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page views, length of visit, operating systems used, and the user's origin. This data is combined in a user ID and assigned to the respective device used by the website visitor.
Furthermore, Google Analytics allows us to record, among other things, your mouse and scrolling movements and clicks. Google Analytics also uses various modeling approaches to supplement the collected data sets and uses machine-learning technologies for data analysis.
Google Analytics uses technologies that enable the recognition of users for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is generally transferred to a Google server in the USA and stored there.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time.
Data transfers to the USA are based on the Standard Contractual Clauses of the European Commission. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF is required to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/participant/5780
IP Anonymization
Google Analytics IP anonymization is enabled. This means that your IP address is truncated by Google within Member States of the European Union or other contracting states to the Agreement on the European Economic Area before being transmitted to the USA.
Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide the website operator with other services relating to website and Internet usage.
The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at: https://tools.google.com/dlpage/gaoptout?hl=en
More information on how Google Analytics handles user data can be found in Google's Privacy Policy: https://support.google.com/analytics/answer/6004245?hl=en
Data Processing Agreement
We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
13.2 Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It is used solely to manage and deploy the tools integrated through it.
However, Google Tag Manager collects your IP address, which may also be transferred to Google's parent company in the United States.
Google Tag Manager is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the quick and uncomplicated integration and management of various tools on its website.
Where appropriate consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when data is processed in the United States.
Every company certified under the DPF is required to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/participant/5780
13.3 Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites when users enter certain search terms into Google (keyword targeting).
Targeted advertisements may also be displayed based on user data available to Google (e.g. location data and interests; audience targeting).
As the website operator, we can quantitatively analyze this data, for example by analyzing which search terms resulted in our advertisements being displayed and how many advertisements resulted in corresponding clicks.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time.
Data transfers to the USA are based on the Standard Contractual Clauses of the European Commission. Details can be found at: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when data is processed in the United States.
Every company certified under the DPF is required to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/participant/5780
13.4 Google Conversion-Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google Conversion Tracking, Google and we can determine whether a user has performed certain actions. For example, we can evaluate which buttons on our website were clicked and how often, and which products were viewed or purchased particularly frequently.
This information is used to compile conversion statistics. We learn the total number of users who clicked on our advertisements and which actions they performed. We do not receive any information that allows us to personally identify users.
Google itself uses cookies or comparable recognition technologies for identification purposes.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time.
More information about Google Conversion Tracking can be found in Google's Privacy Policy: https://policies.google.com/privacy?hl=en
The company is certified under the “EU-US Data Privacy Framework” (DPF).
13.5 Which Cookies Are Set by Google Ads Conversion Tracking?
Google Ads Conversion Tracking sets the IDE cookie and, where applicable, the test_cookie cookie.
Further details on the storage duration and purpose can be found here:
https://traffic3.net/wissen/datenschutz/google-cookies#s43
The same cookies are also set when you use the Google Ads Remarketing Tag.
13.6 Google Ads and Google Display & Video 360
If you use remarketing tags or conversion tags for Google Ads or Floodlight tags for Google Display & Video 360, the following cookies are set:
| Cookie | Domain | Purpose | Storage Period |
|---|---|---|---|
| test_cookie | doubleclick.net (3rd party) | Set as a test to determine whether the browser permits cookies to be set. Contains no identifying characteristics. | 15 minutes |
| IDE | doubleclick.net (3rd party) | Contains a randomly generated user ID. This ID enables Google to recognize the user across different websites and domains and display personalized advertising. |
13.7 Matomo
This website uses the open-source web analytics service Matomo.
With the help of Matomo, we are able to collect and analyze data about how website visitors use our website. Among other things, this enables us to determine when individual pages were accessed and from which region the visits originated.
We also collect various log files (e.g. IP address, referrer, browsers and operating systems used) and can measure whether our website visitors perform certain actions (e.g. clicks, purchases, etc.).
This analytics tool is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.
Where appropriate consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
IP Anonymization
When analyzing data with Matomo, we use IP anonymization. Your IP address is truncated before analysis so that it can no longer be clearly assigned to you.
Cookie-Free Analysis
We have configured Matomo so that Matomo does not store cookies in your browser.
Hosting
We host Matomo exclusively on our own servers, meaning that all analytics data remains with us and is not passed on.
14. Social Media
14.1 Instagram
This website integrates functions of the Instagram service. These functions are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and Instagram's server. Instagram thereby receives information about your visit to this website.
If you are logged into your Instagram account, clicking the Instagram button allows you to link content from this website to your Instagram profile. This enables Instagram to associate your visit to this website with your user account.
We would like to point out that, as the provider of this website, we have no knowledge of the content of the data transmitted or how Instagram uses it.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time.
Where personal data is collected on our website with the help of the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, are jointly responsible for this data processing pursuant to Art. 26 GDPR.
Joint responsibility is limited exclusively to the collection of data and its transfer to Facebook or Instagram. Processing carried out by Facebook or Instagram after the transfer is not part of the joint responsibility.
The obligations jointly incumbent upon us have been set out in a joint processing agreement. The wording of the agreement can be found at: https://www.facebook.com/legal/controller_addendum
According to this agreement, we are responsible for providing data protection information when using the Facebook or Instagram tool and for implementing the tool on our website in compliance with data protection requirements.
Facebook is responsible for the data security of Facebook and Instagram products.
You can exercise data subject rights (e.g. requests for information) regarding data processed by Facebook or Instagram directly with Facebook. If you exercise your data subject rights with us, we are obliged to forward them to Facebook.
Data transfers to the USA are based on the Standard Contractual Clauses of the European Commission.
Further information can be found in Instagram's Privacy Policy.
The company is certified under the “EU-US Data Privacy Framework” (DPF).
14.2 YouTube
This website embeds videos from YouTube. The operator is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in enhanced privacy mode. According to YouTube, this mode means that YouTube does not store information about visitors to this website before they watch the video.
However, the transfer of data to YouTube partners is not necessarily excluded by enhanced privacy mode. For example, YouTube establishes a connection to the Google DoubleClick network regardless of whether you watch a video.
As soon as you start a YouTube video on this website, a connection to YouTube's servers is established. The YouTube server is informed which of our pages you have visited.
If you are logged into your YouTube account, you enable YouTube to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.
Furthermore, after a YouTube video has been started, YouTube may store various cookies on your device or use comparable recognition technologies (e.g. device fingerprinting).
In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to compile video statistics, improve user-friendliness, and prevent attempted fraud.
Additional data processing operations may be triggered after a YouTube video is started, over which we have no control.
YouTube is used in the interest of presenting our online content in an appealing manner. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
Where appropriate consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time.
Further information about data protection at YouTube can be found in Google's Privacy Policy.
14.3 LinkedIn
This website uses elements of the LinkedIn network. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
Whenever a page of this website containing LinkedIn elements is accessed, a connection to LinkedIn's servers is established.
LinkedIn is informed that you have visited this website using your IP address. If you click LinkedIn's “Recommend” button while logged into your LinkedIn account, LinkedIn can associate your visit to this website with you and your user account.
We would like to point out that, as the provider of this website, we have no knowledge of the content of the data transmitted or how LinkedIn uses it.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time.
Data transfers to the USA are based on the Standard Contractual Clauses of the European Commission.
Further information can be found in LinkedIn's Privacy Policy.
The company is certified under the “EU-US Data Privacy Framework” (DPF).
14.4 Facebook
This website integrates elements of the Facebook social network. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
According to Facebook, however, the collected data is also transferred to the USA and other third countries.
When the social media element is active, a direct connection is established between your device and Facebook's server. Facebook thereby receives information that you have visited this website using your IP address.
If you click the Facebook “Like” button while logged into your Facebook account, you can link content from this website to your Facebook profile.
This enables Facebook to associate your visit to this website with your user account. We would like to point out that, as the provider of this website, we have no knowledge of the content of the data transmitted or how Facebook uses it.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time.
Where personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited are jointly responsible for this data processing pursuant to Art. 26 GDPR.
Joint responsibility is limited exclusively to the collection of data and its transfer to Facebook. Processing by Facebook after the transfer is not part of the joint responsibility.
The obligations jointly incumbent upon us have been set out in a joint processing agreement.
According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for implementing the tool on our website in compliance with data protection requirements. Facebook is responsible for the data security of Facebook products.
Data subject rights regarding data processed by Facebook can be exercised directly with Facebook. If you exercise these rights with us, we are obliged to forward them to Facebook.
Data transfers to the USA are based on the Standard Contractual Clauses of the European Commission.
The company is certified under the “EU-US Data Privacy Framework” (DPF).
14.5 Newsletter Tool
Newsletter Data
If you would like to subscribe to the newsletter offered on our website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter.
No additional data is collected, or it is collected only on a voluntary basis.
We use newsletter service providers to manage and distribute our newsletters, as described below.
Brevo
This website uses Brevo to send newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.
Brevo is a service that can be used, among other things, to organize and analyze the distribution of newsletters.
The data you enter for the purpose of subscribing to the newsletter is stored on the servers of Sendinblue GmbH in Germany.
Data Analysis by Brevo
With the help of Brevo, we are able to analyze our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links, if any, have been clicked.
This allows us, among other things, to determine which links are clicked particularly frequently.
We can also determine whether certain predefined actions were performed after opening or clicking the newsletter (conversion rate). For example, we can determine whether you made a purchase after clicking on the newsletter.
Brevo also enables us to divide newsletter recipients into different categories (“clusters”). Newsletter recipients can, for example, be categorized by age, gender, or place of residence. This allows newsletters to be better tailored to the respective target groups.
If you do not want your data to be analyzed by Brevo, you must unsubscribe from the newsletter. We provide an appropriate unsubscribe link in every newsletter message.
Detailed information about Brevo's features can be found at: https://www.brevo.com/de/newsletter-software/
Legal Basis
Data processing is based on your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw this consent at any time.
The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
Storage Period
The data you provide to us for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe.
Data stored by us for other purposes remains unaffected.
After you unsubscribe from the newsletter distribution list, your email address may be stored by us or the newsletter service provider in a blacklist if this is necessary to prevent future mailings.
The data in the blacklist is used exclusively for this purpose and is not combined with other data.
This serves both your interests and our interest in complying with legal requirements when sending newsletters and therefore constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
Storage in the blacklist is not subject to a time limit. You may object to the storage if your interests outweigh our legitimate interest.
Further information can be found in Brevo's Privacy Policy.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the aforementioned service.
This is a contract required under data protection law that ensures that the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
14.6 WhatsApp Business
For communication with our customers and other third parties, we use, among other services, the instant messaging service WhatsApp. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Communication is protected by end-to-end encryption, which prevents WhatsApp or other third parties from accessing the content of the communication. However, WhatsApp has access to metadata generated in the course of the communication (e.g. sender, recipient, and time). We would also like to point out that, according to WhatsApp, it shares personal data of its users with its parent company Meta, which is based in the USA. Further details on data processing can be found in WhatsApp’s Privacy Policy at: https://www.whatsapp.com/legal/#privacy-policy.
Access to Contact Data (Address Book)
When using WhatsApp, the application may access the address book stored on the device and transmit contact data stored there – in particular telephone numbers – to WhatsApp or Meta. This may also affect personal data of individuals who do not themselves communicate with us via WhatsApp and who have not consented to such transmission.
To protect the rights of these individuals, we have implemented technical and organizational measures: [We use WhatsApp on a separate device whose address book does not contain any contact data of uninvolved third parties; automatic contact synchronization is disabled. Via WhatsApp, we process only the contact data of individuals who have contacted us on their own initiative using this communication channel.] As a result of these measures, address book data relating to uninvolved third parties is not transmitted to WhatsApp.
The use of WhatsApp is based on our legitimate interest in communicating as quickly and effectively as possible with customers, prospective customers, and other business and contractual partners (Art. 6(1)(f) GDPR). Where appropriate consent has been obtained, data processing is carried out exclusively on the basis of this consent; consent may be withdrawn at any time with effect for the future.
The content of communications exchanged between you and us via WhatsApp will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your inquiry has been fully processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF is required to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/7735.
We use the “WhatsApp Business” version of WhatsApp.
Data transfers to the USA are based on the Standard Contractual Clauses of the European Commission. Details can be found here: https://www.whatsapp.com/legal/business-data-transfer-addendum.
We have concluded a Data Processing Agreement (DPA) with the aforementioned provider.
15. Vulnerability Management & PSIRT
File Upload
Purpose and Scope of Processing
On our website, we provide a contact form and the email address psirt(at)kriwan.com to enable security researchers, customers, and third parties to report potential product vulnerabilities.
If you use this channel, we process the information you provide (e.g. name, email address, organization, and technical descriptions of the vulnerability) as well as the files you upload (e.g. screenshots and log files) in order to assess and remediate the reported vulnerability and comply with statutory reporting obligations.
We expressly ask you not to submit any personal data relating to third parties (e.g. customer data) as part of vulnerability reports or file uploads.
Legal Basis
Your contact details and the technical report are processed on the basis of:
Storage Period and Data Disclosure
The reporter's personal data will be deleted as soon as it is no longer required to remediate the vulnerability and document the incident.
Technical vulnerability reports are retained permanently for documentation purposes but are generally fully anonymized, meaning that they no longer contain personal information relating to the reporter.
Data is disclosed to third parties only where we are legally required to do so (e.g. reporting to market surveillance authorities such as the BSI or ENISA in the event of actively exploited vulnerabilities in accordance with CRA requirements) or where such disclosure has been explicitly agreed with you as part of a Coordinated Vulnerability Disclosure (CVD).
The reporter's personal data will only be disclosed to authorities where this is strictly required by law.
16. Right of Access
If you have any questions or comments regarding the processing of your personal data, please contact our Data Protection Officer: Datenschutzbeauftragter(at)kriwan.com
Upon request, we will inform you in writing as soon as possible and in accordance with applicable laws and regulations whether we store personal data relating to you and, if so, which personal data we store.
If outdated or incorrect information is stored, we will correct it at your request.
You also have the right to request the restriction or deletion of data in compliance with applicable legal obligations.
We ensure compliance with data protection regulations in all areas. If you have any questions, you can also contact us directly. Please write to:
KRIWAN Industrie-Elektronik GmbH
Allmand 11
74670 Forchtenberg
Germany
Phone and hotline: +49 (0) 79 47 - 8 22 – 0
Fax: +49 (0) 79 47 - 71 22
Priolan
Ulrich Jahnke
u.jahnke(at)priolan.de
Gottlieb-Daimler-Straße 9
74076 Heilbronn
Germany