General Privacy Policy Business Partners

General Privacy Policy Business Partners

In the course of our business relationship with you, it is essential that we process your personal data. “Personal data” means any information that relates to an individual, either directly or indirectly (e.g. names and addresses).

The protection of personal data of our business partners (such as customers and suppliers) is the responsibility of EDRO Specialty Steels GmbH, Industriestr. 5c, 77767 Appenweier, Germany (“EDRO”) very important. We are committed to protecting your privacy and we take that responsibility seriously. We expect the same from our business partners.

Please find attached a summary of the processing of personal data of business partners:

DATA CATEGORIES, PURPOSE OF PROCESSING AND LEGAL BASIS
In the context of cooperation with business partners, EDRO processes personal data for the following purposes:
  • Communication with business partners about products, services and projects, e.g. to process inquiries from the business partner;
  • Initiation, processing and management of (contractual) business relationships and maintenance of business relationships between EDRO and the business partner, e.g. to process the ordering of products and services, to collect payments, for accounting, billing and debt collection purposes and to carry out deliveries, maintenance work or repairs ;
  • Conducting customer surveys, marketing campaigns, market analysis, sweepstakes, contests or similar promotions and events;
  • Maintaining and protecting the security of our products and services and our websites, preventing and detecting security risks, fraudulent activities or other criminal or malicious activities;
  • Compliance with (i) legal requirements (e.g. tax and commercial law retention requirements), and (ii) EDRO guidelines;
  • Settling legal disputes, enforcing existing contracts and asserting, exercising and defending legal claims.
For the aforementioned purposes, EDRO may process the following categories of personal data:
  • professional contact information, such as name, professional contact address, professional phone number, or email address;
  • Payment Data, such as information required to process payments or prevent fraud, including credit card information and card security numbers;
  • Information collected from publicly available sources, information databases or credit bureaus;
  • other personal data whose processing is necessary for the initiation, processing and management of (contractual) business relationships and maintenance of business relationships or which you provide voluntarily, such as orders placed, order details, inquiries made or project details, correspondence, other data about the cooperation ;

The processing of personal data is necessary to achieve the above-mentioned purposes, including the fulfillment of a contractual relationship or a pre-contractual activity with the business partner.

Unless expressly stated otherwise, the legal basis for data processing is Article 6 Para. 1 lit a (if consent has been given) or Article 6 Para. 1 lit b and f of the General Data Protection Regulation (GDPR):

  • the processing is necessary for the performance of a contract to which the data subject is party or for the implementation of pre-contractual measures;
    the processing is necessary to protect the legitimate interests of the person responsible or a third party.

If the personal data mentioned is not provided or not provided to the required extent or if EDRO cannot collect it, the individual purposes described may not be provided or the request(s) made may not be processed. Please note that this would not constitute a breach of contract on our part.

Transmission and disclosure of personal data

EDRO may transmit personal data to other voestalpine Group companies (www.voestalpine.com/standorte) or courts, authorities or law firms or other business partners (such as shipping or logistics partners for the execution and processing of orders) within the scope of legal permission.

In addition, EDRO commissions processors (service providers) to process personal data (e.g. as part of an IT support contract). These processors are contractually obliged to comply with data protection regulations.

The recipients described in this Section 2 may be located in countries outside the European Union (“Third Countries”) in which the applicable law does not guarantee the same level of data protection as in your home country. In this case, a transfer will only take place in accordance with the legal requirements if the European Commission has issued an adequacy decision for the third country, appropriate guarantees have been agreed with the recipient (e.g. EU standard contractual clauses have been concluded), the recipient participates in an approved certification system, binding internal data protection regulations in accordance with Art. 47 General Data Protection Regulation or an exception pursuant to Art. 49 General Data Protection Regulation (because you have expressly consented to the proposed data transfer after you have been informed of the possible risks for you of such data transfers without the existence of an adequacy decision and without suitable guarantees). Further information and a copy of the measures implemented can be obtained from the contact specified under point 6.

retention periods

If no express storage period is specified during collection (e.g. as part of a declaration of consent), your personal data will be deleted if they are no longer required to fulfill the purpose of storage and there are no statutory storage obligations (e.g. commercial and tax storage obligations) or the assertion of legal claims stand in the way of deletion.

Right to information, correction, deletion or restriction of your personal data, right of objection, right to data portability and revocation of a given consent
  • In accordance with Article 15 GDPR, you have the right to request confirmation as to whether personal data is being processed by the person responsible and the right to information about this data. This right does not exist in the case of Section 34 (1) BDSG.
  • In accordance with Article 16 GDPR, you have the right to immediately request the correction of incorrect data concerning you and/or the completion of incomplete personal data.
  • In accordance with Article 17 GDPR, you have the right to have your personal data deleted. This right does not exist in the case of Section 35 (1) BDSG; in its place then comes the right to restriction of processing.
  • According to Art. 18 you have the right to restriction of processing. This right is supplemented by § 35 Para. 2 BDSG.
  • According to Art. 20 GDPR you have the right to data transfer.
  • In accordance with Article 21 GDPR, you have the right to object to data processing.
  • Ultimately, you have the opportunity to lodge a complaint with the supervisory authority.
  • If your data is processed on the basis of your consent, you have the right to revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent up to the point of revocation.
Protection of your personal data

The security of your personal data is of particular concern to us. To protect your personal data from misuse and loss and from unauthorized access, alteration or disclosure, we take the following measures, among others:

  • Restriction of access to our premises (access control)
  • Implementation of access permissions and protection of data carriers (access and transfer control)
  • Use of network security measures such as antivirus software, firewall, security updates, etc. (network control)

We also transfer our understanding of security to the contract processors we use, which we have obliged to comply with similar or equivalent security precautions.

Contact Person

For questions on the subject of data protection and the assertion of your aforementioned rights, you can contact the data protection organization at info.germany@edro.com.

EDRO Specialty Steels GmbH

privacy

Industriestr. 5c

77767 Appenweier

Phone: +49-(0)7805 915790

This General Privacy Policy for Business Partners will be amended from time to time. The date of the last update can be found in the footer.