Information about data protection

Information for data subjects about the processing of their personal data, provided as required by articles 13 and 14 of the EU GDPR by VSM AG

You have used a link to access this page, where we provide you with information about how we handle your personal data. To fulfil our duties to provide information about data protection according to articles 13 and 14 of the EU General Data Protection Regulation (GDPR), we are pleased to do so as follows. Please click the category relevant to you: a section providing information is then shown underneath the category.

Category: Service providers and suppliers

You have used a link to access this page, where we provide you with information about how we handle your personal data. To fulfil our duties to provide information about data protection according to articles 13 and 14 of the EU General Data Protection Regulation (GDPR), we are pleased to do so as follows:

I. Name and contact details of the controller
The controller, as defined by GDPR art. 4(7), other national data protection legislation enacted by EU member states and other regulations governing data protection, is:

VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG
Siegmundstrasse 17
30165 Hanover, Germany
Tel.: +49 511 3526-0
Fax: +49 511 3521 315
info@vsmabrasives.com
www.vsmabrasives.com

II. Name and contact details of the Data Protection Officer
The Data Protection Officer for the controller is:

Thomas Spaeing
ds² Unternehmensberatung GmbH & Co. KG
Berliner Straße 1
49201 Dissen, Germany
T +49 5421 30 89 518
datenschutzbeauftragter@vsmabrasives.com

III. Transfer to a third country or an international organization
In the context of supplier self-disclosures, we use a service provider based in the USA to which we intend to transfer personal data. There is no adequacy decision by the Commission for the transfer to the USA. The transfer to the service provider is based on appropriate guarantees. Standard Contractual Caluses have been concluded with the service provider for this purpose. A copy of these guarantees can be obtained as follows: https://www.sogosurvey.com/gdpr-compliance/

IV. No automated decision-making or profiling
No automated decision-making or profiling is conducted in the sense as defined by GDPR art. 22.

V. Purposes for which your personal data is processed
1. Address management and communication (by email)
2. Order processing (services provided to VSM AG)
3. Data that is required for the establishment, exercise or defence of potential legal claims vis-à-vis you or third parties
4. Management of rights granted to data subjects under data protection law

VI. Legal basis on which your personal data is processed
For 1: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract with you or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in communicating with you effectively and efficiently.

For 2: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in ensuring the proper handling and completion of the services that we have commissioned from you or your employer.

For 3: Your personal data, which we have received in the course of our relationship relating to services or an order, may be required for the establishment, exercise or defence of potential legal claims vis-à-vis you or third parties. The legal basis for this processing is point (f) of art. 6(1) of the GDPR. In this case, VSM AG has a legitimate interest in the use of personal data for the reasons mentioned above.

For 4: Processing is completed in order to maintain or fulfil legal obligations and honour the rights of the data subject as stated in GDPR chapter III (arts. 12-22), which VSM AG is required to comply with as a controller in the sense as defined by GDPR art. 4(7). The legal basis for this processing is point (c) of art. 6(1) of the GDPR.

VII. Description of personal data categories
For 1: Contact details (first and last name, email address, phone number, address details, type of contact, fax number), correspondence.

For 2: Contract data, order data and correspondence, as well as other data we have received from you as part of order processing.

For 3: Contact details (first and last name, email address, phone number, address details, type of contact, fax number), correspondence.

For 4: Declarations of withdrawal of consent concerning consent you have given: declarations of objection that you may make to the processing of your personal data; declarations and information that we receive from you in order to exercise your rights as a data subject granted by GDPR chapter III (arts. 12-22) or in the course of exercising such rights.

VIII. Categories of recipients to whom the personal data has been or will be disclosed
Employees of VSM AG as well as the phone service and IT service providers employed as part of conducting our business, with whom corresponding contracts have been concluded to ensure the protection of your personal data is safeguarded at all times. Government agencies (in the event of a criminal investigation)

IX. Deletion periods for the various data categories and retention criteria
Personal data is erased once the purpose of data processing no longer applies and no later than the end of the business relationship (limitation on storage), except in cases where legal retention periods or legal limitation periods apply that prohibit this erasure.

X. Requirement to make data available
There is no legal or contractual requirement for you to make your personal data available. However, we need you to make your personal data available in order to conduct activities related to our business relationship. If you do not wish to make your personal data available, we will be unable to establish a business relationship or exchange business correspondence with you.

XI. Data sources
We work with data that you provide us with directly; we may also receive this data from other persons in your company or other business contacts.

XII. Rights of the data subject
In cases where your personal data is processed, you are a 'data subject' as defined by the GDPR and you are granted the following rights vis-à-vis the controller (VSM AG):

1. Right to access
On the basis of GDPR art. 15, you can ask us, as the controller, to provide you at any time with information about your personal data that we process and how we process this data.

2. Right to rectification
On the basis of GDPR art. 16, you are granted a right to the rectification and/or completion of incomplete data vis-à-vis the controller, in cases where your personal data that is processed is inaccurate or incomplete. The controller must make such rectifications without undue delay.

3. Right to restriction of processing
On the basis of GDPR art. 18, you can make a request to have the processing of your personal data restricted by the controller.

4. Right to erasure and the 'right to be forgotten'
On the basis of the right granted by GDPR art. 17, you can make a request to have your personal data erased by the controller; by making this request, you can thereby exercise your 'right to be forgotten'.

5. Right to information
If you have exercised your right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is required by law to notify all recipients to whom personal data about you has been disclosed about this rectification, erasure or restriction of processing, except in cases where this notification proves to be impossible or would involve a disproportionate amount of effort on the part of the controller. On the basis of GDPR art. 19, you have the right to request information about these recipients from the controller.

6. Right to data portability
On the basis of GDPR art. 20, you have the right to receive the personal data about you that you have provided to the controller in a structured, commonly used and machine-readable format.

7. Right to object
On the basis of GDPR art. 21, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data about you, where such processing is based on point (e) or (f) of art. 6(1) of the GDPR; this right also includes profiling based on these provisions. As the controller, VSM AG will no longer process your personal data unless we are able to demonstrate compelling legitimate grounds for this processing that override your interests, rights and freedoms as the data subject, or where this processing is required for the establishment, exercise or defence of legal claims.

8. Right to withdraw consent as given under data protection law
You have the right to withdraw your consent as given under data protection law at any time. Withdrawal of consent does not affect the legitimacy of processing completed on the basis of this consent until the point in time of withdrawal.9. Right to lodge a complaint with a supervisory authorityWithout prejudice to other legal remedies provided under administrative law or by a court order, you have the right to lodge a complaint with a supervisory authority, whether in the member state of your place of residence, your workplace or the place of the alleged violation, if you believe that the processing of your personal data was done in violation of the provisions of the GDPR. The supervisory authority with whom the complaint is lodged informs the plaintiff about the progress and results of the complaint, including the possibility of obtaining an effective judicial remedy on the basis of GDPR art. 78.

The competent state supervisory authority for VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG is:

State Data Protection Commissioner for Lower Saxony
Prinzenstrasse 5
30159 Hanover, Germany
Phone: +49 (511) 120 45-00
Fax: +49 (511) 120 45-99
Email: poststelle@lfd.niedersachsen.de

Category: Applicants

You have used a link to access this page, where we provide you with information about how we handle your personal data. To fulfil our duties to provide information about data protection according to articles 13 and 14 of the EU General Data Protection Regulation (GDPR), we are pleased to do so as follows:

I. Name and contact details of the controller
The controller, as defined by GDPR art. 4(7), other national data protection legislation enacted by EU member states and other regulations governing data protection, is:

VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG
Siegmundstrasse 17
30165 Hanover, Germany
Tel.: +49 511 3526-0
Fax.: +49 511 3521-315
info@vsmabrasives.com
www.vsmabrasives.com

II. Name and contact details of the Data Protection Officer
The Data Protection Officer for the controller is:

Thomas Spaeing
ds² Unternehmensberatung GmbH & Co. KG
Berliner Straße 1
49201 Dissen
T +49 5421 30 89 518
datenschutzbeauftragter@vsmabrasives.com

III. No transfer to a third country or an international organisation
Your personal data is not transferred to a third country or an international organisation and no such transfer is intended in the future.

IV. No automated decision-making or profiling
During the application procedure, no automated decision-making or profiling is conducted in the sense as defined by GDPR art. 22.

V. Purposes for which your personal data is processed

1. Address management and email communication
2. Completion of the application procedure
3. Reimbursement of expenses for applicant travel to interview
4. Data that serves to establish, exercise or defend any potential legal claims during the course of the application procedure (e.g. claims made on the basis of the German General Equal Treatment Act)
5. For transfer to the personnel file if the candidate is hired
6. Management of rights granted to data subjects under data protection law

VI. Legal basis on which your personal data is processed
For 1: Address management and processing forms part of the application procedure. The processing of your personal data is required in order to establish an employment relationship with you as the data subject. Accordingly, we process your data on the basis of point (b) of art. 6(1) of the GDPR and section 26(1) of the German Federal Data Protection Act (BDSG).

For 2: Since this processing is required to establish an employment relationship with you as the data subject, we process your data on the basis of point (b) of art. 6(1) of the GDPR and section 26(1) of the German Federal Data Protection Act (BDSG).

For 3: Section 670 of the German Civil Code (BGB) grants applicants a right to have costs associated with travelling to a job interview reimbursed if no agreement has been made about the proportion of these applicant costs that will be borne by the employer. Since this processing is required to conduct the job interview and therefore establish an employment relationship with you as the data subject, we process your data on the basis of point (b) of art. 6(1) of the GDPR and section 26(1) of the German Federal Data Protection Act (BDSG).

For 4: Your personal data, which we have received in the course of the application procedure, may be used by us for the establishment, exercise or defence of potential legal claims (such as cases where the VSM AG believes it is exposed to claims arising from the German General Equal Treatment Act). The legal basis for this processing is point (f) of art. 6(1) of the GDPR. In this case, VSM AG has a legitimate interest in the use of personal data for the reasons mentioned above.

For 5: This data is transferred to the personnel file if the candidate is hired by our company. The legal basis for this processing is section 26(1) of the BDSG.

For 6: Processing is completed in order to maintain or fulfil legal obligations and honour the rights of the data subject as stated in GDPR chapter III (arts. 12–22), which VSM AG is required to comply with as a controller in the sense as defined by GDPR art. 4(7). The legal basis for this processing is point (c) of art. 6(1) of the GDPR.

VII. Description of personal data categories
For 1: Contact details (first and last name, email address, phone number, address details, type of contact, fax number), correspondence.

For 2: Covering letter, CV, photo, references and other documentation about skills and experience, and other data you have provided us with voluntarily during the application procedure.

For 3: Travel data (outward/return journey, travel expenses, means of transport), bank details.

For 4: Master data, communications data, data records proving the application procedure was conducted in compliance with the law.

For 5: Master data, communications data, covering letter, CV, photo, references and other documentation about skills and experience, and other data you have provided us with voluntarily during the application procedure.

For 6: Declarations of withdrawal of consent concerning consent you have given: declarations of objection that you may make to the processing of your personal data; declarations and information that we receive from you in order to exercise your rights as a data subject granted by GDPR chapter III (arts. 12–22) or in the course of exercising such rights.

VIII. Categories of recipients to whom the personal data has been or will be disclosed
Those of our employees within VSM AG who need to receive the data in order to conduct the application procedure (company management team, business departments, HR department), as well as the phone service and IT service providers employed as part of conducting our business, with whom corresponding contracts have been concluded to ensure the protection of your personal data is safeguarded at all times. Potentially: government agencies (criminal investigations).

IX. Duration of storage for your personal data
If you are not offered employment by VSM AG after completing the application procedure, your data will be erased within 6 months of the date of your rejection letter. If you are hired by VSM AG, your personal data is erased once the purpose of data processing no longer applies and no later than the end of the employment relationship (limitation on storage), except in cases where legal retention periods or legal limitation periods apply that prohibit this erasure.

X. Requirement to make data available
There is no legal or contractual requirement for you to make your personal data available. However, we need you to make your personal data available in order to conduct and complete the application procedure. If you do not wish to make your personal data available, we will be unable to consider you as a candidate within the VSM application procedure.

XI. Data sources
We work with data that you provide us with voluntarily as part of the application procedure.

XII. Rights of the data subject
In cases where your personal data is processed, you are a ‘data subject’ as defined by the GDPR and you are granted the following rights vis-à-vis the controller (VSM AG):

1. Right to access
On the basis of GDPR art. 15, you can ask us, as the controller, to provide you at any time with information about your personal data that we process and how we process this data.

2. Right to rectification
On the basis of GDPR art. 16, you are granted a right to the rectification and/or completion of incomplete data vis-à-vis the controller, in cases where your personal data that is processed is inaccurate or incomplete. The controller must make such rectifications without undue delay.

3. Right to restriction of processing
On the basis of GDPR art. 18, you can make a request to have the processing of your personal data restricted by the controller.

4. Right to erasure and the ‘right to be forgotten’
On the basis of the right granted by GDPR art. 17, you can make a request to have your personal data erased by the controller; by making this request, you can thereby exercise your ‘right to be forgotten’.

5. Right to information
If you have exercised your right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is required by law to notify all recipients to whom personal data about you has been disclosed about this rectification, erasure or restriction of processing, except in cases where this notification proves to be impossible or would involve a disproportionate amount of effort on the part of the controller. On the basis of GDPR art. 19, you have the right to request information about these recipients from the controller.

6. Right to data portability
On the basis of GDPR art. 20, you have the right to receive the personal data about you that you have provided to the controller in a structured, commonly used and machine-readable format.

7. Right to object
On the basis of GDPR art. 21, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data about you, where such processing is based on point (e) or (f) of art. 6(1) of the GDPR; this right also includes profiling based on these provisions. As the controller, VSM AG will no longer process your personal data unless we are able to demonstrate compelling legitimate grounds for this processing that override your interests, rights and freedoms as the data subject, or where this processing is required for the establishment, exercise or defence of legal claims.

8. Right to withdraw consent as given under data protection law
You have the right to withdraw your consent as given under data protection law at any time. Withdrawal of consent does not affect the legitimacy of processing completed on the basis of this consent until the point in time of withdrawal.

9. Right to lodge a complaint with a supervisory authority
Without prejudice to other legal remedies provided under administrative law or by a court order, you have the right to lodge a complaint with a supervisory authority, whether in the member state of your place of residence, your workplace or the place of the alleged violation, if you believe that the processing of your personal data was done in violation of the provisions of the GDPR. The supervisory authority with whom the complaint is lodged informs the plaintiff about the progress and results of the complaint, including the possibility of obtaining an effective judicial remedy on the basis of GDPR art. 78.

The competent state supervisory authority for VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG is:

State Data Protection Commissioner for Lower Saxony
Prinzenstrasse 5
30159 Hanover, Germany
Phone: +49 (511) 120 45-00
Fax: +49 (511) 120 45-99
Email: poststelle@lfd.niedersachsen.de

Category: Potential customers

You have used a link to access this page, where we provide you with information about how we handle your personal data. To fulfil our duties to provide information about data protection according to articles 13 and 14 of the EU General Data Protection Regulation (GDPR), we are pleased to do so as follows:

I. Name and contact details of the controller
The controller, as defined by GDPR art. 4(7), other national data protection legislation enacted by EU member states and other regulations governing data protection, is:

VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG
Siegmundstrasse 17
30165 Hanover, Germany
Tel.: +49 511 3526-0
Fax.: +49 511 3521-315
info@vsmabrasives.com
www.vsmabrasives.com

II. Name and contact details of the Data Protection Officer
The Data Protection Officer for the controller is:

Thomas Spaeing
ds² Unternehmensberatung GmbH & Co. KG
Berliner Straße 1
49201 Dissen, Germany
T +49 5421 30 89 518
datenschutzbeauftragter@vsmabrasives.com

III. No transfer to a third country or an international organisation
Your personal data is not transferred to a third country or an international organisation and no such transfer is intended in the future.

IV. No automated decision-making or profiling
No automated decision-making or profiling is conducted in the sense as defined by GDPR art. 22.

V. Purposes for which your personal data is processed
1. Address management and communication (by email)
2. Processing your enquiry
3. New business development
4. Data that is required for the establishment, exercise or defence of potential legal claims vis-à-vis you or third parties
5. Management of rights granted to data subjects under data protection law

VI. Legal basis on which your personal data is processed
For 1: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in communicating with you effectively and efficiently.

For 2: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in providing a prompt and professional response to your enquiry as a service performed by VSM AG.

For 3: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in acquiring new customers, so as to perform and expand our business activities and operations.

For 4: Your personal data, which we have received in the course of our communications with you, may be required for the establishment, exercise or defence of potential legal claims vis-à-vis you or third parties. The legal basis for this processing is point (f) of art. 6(1) of the GDPR. In this case, VSM AG has a legitimate interest in the use of personal data for the reasons mentioned above.

For 5: Processing is completed in order to maintain or fulfil legal obligations and honour the rights of the data subject as stated in GDPR chapter III (arts. 12–22), which VSM AG is required to comply with as a controller in the sense as defined by GDPR art. 4(7). The legal basis for this processing is point (c) of art. 6(1) of the GDPR.

VII. Description of personal data categories
For 1: Contact details (first and last name, email address, phone number, address details, type of contact, fax number).

For 2: Contact details (first and last name, email address, phone number, address details, type of contact, fax number), correspondence relating to your enquiry.

For 3: Contact details (first and last name, email address, phone number, address details, type of contact, fax number) and correspondence.

For 4: Master data, communications data, contract data.

For 5: Declarations of withdrawal of consent concerning consent you have given: declarations of objection that you may make to the processing of your personal data; declarations and information that we receive from you in order to exercise your rights as a data subject granted by GDPR chapter III (arts. 12–22) or in the course of exercising such rights.

VIII. Categories of recipients to whom the personal data has been or will be disclosed
Employees of VSM AG as well as the phone service and IT service providers employed as part of conducting our business, with whom corresponding contracts have been concluded to ensure the protection of your personal data is safeguarded at all times. Government agencies (in the event of a criminal investigation)

IX. Deletion periods for the various data categories and retention criteria
Personal data is erased once the purpose of data processing no longer applies and no later than the end of the business relationship (limitation on storage), except in cases where legal retention periods (e.g. as defined by commercial or tax law) or legal limitation periods apply that prohibit this erasure.

X. Requirement to make data available  
There is no legal or contractual requirement for you to make your personal data available. However, we need you to make your personal data available in order to conduct activities related to our business relationship. If you do not wish to make your personal data available, we will be unable to process your enquiry or handle your business; we will also be unable to communicate with you.

XI. Data sources
We work with data that you provide us with directly; we may also receive this data from other persons in your company or other business contacts.

XII. Rights of the data subject
In cases where your personal data is processed, you are a ‘data subject’ as defined by the GDPR and you are granted the following rights vis-à-vis the controller (VSM AG):

1. Right to access
On the basis of GDPR art. 15, you can ask us, as the controller, to provide you at any time with information about your personal data that we process and how we process this data.

2. Right to rectification
On the basis of GDPR art. 16, you are granted a right to the rectification and/or completion of incomplete data vis-à-vis the controller, in cases where your personal data that is processed is inaccurate or incomplete. The controller must make such rectifications without undue delay.

3. Right to restriction of processing
On the basis of GDPR art. 18, you can make a request to have the processing of your personal data restricted by the controller.

4. Right to erasure and the ‘right to be forgotten’
On the basis of the right granted by GDPR art. 17, you can make a request to have your personal data erased by the controller; by making this request, you can thereby exercise your ‘right to be forgotten’.

5. Right to information
If you have exercised your right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is required by law to notify all recipients to whom personal data about you has been disclosed about this rectification, erasure or restriction of processing, except in cases where this notification proves to be impossible or would involve a disproportionate amount of effort on the part of the controller. On the basis of GDPR art. 19, you have the right to request information about these recipients from the controller.

6. Right to data portability
On the basis of GDPR art. 20, you have the right to receive the personal data about you that you have provided to the controller in a structured, commonly used and machine-readable format.

7. Right to object
On the basis of GDPR art. 21, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data about you, where such processing is based on point (e) or (f) of art. 6(1) of the GDPR; this right also includes profiling based on these provisions. As the controller, VSM AG will no longer process your personal data unless we are able to demonstrate compelling legitimate grounds for this processing that override your interests, rights and freedoms as the data subject, or where this processing is required for the establishment, exercise or defence of legal claims.

8. Right to withdraw consent as given under data protection law
You have the right to withdraw your consent as given under data protection law at any time. Withdrawal of consent does not affect the legitimacy of processing completed on the basis of this consent until the point in time of withdrawal.

9. Right to lodge a complaint with a supervisory authority
Without prejudice to other legal remedies provided under administrative law or by a court order, you have the right to lodge a complaint with a supervisory authority, whether in the member state of your place of residence, your workplace or the place of the alleged violation, if you believe that the processing of your personal data was done in violation of the provisions of the GDPR. The supervisory authority with whom the complaint is lodged informs the plaintiff about the progress and results of the complaint, including the possibility of obtaining an effective judicial remedy on the basis of GDPR art. 78.

The competent state supervisory authority for VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG is:

State Data Protection Commissioner for Lower Saxony
Prinzenstrasse 5
30159 Hanover, Germany
Phone: +49 (511) 120 45-00
Fax: +49 (511) 120 45-99
Email: poststelle@lfd.niedersachsen.de

Category: Customers / Customer employees

You have used a link to access this page, where we provide you with information about how we handle your personal data. To fulfil our duties to provide information about data protection according to articles 13 and 14 of the EU General Data Protection Regulation (GDPR), we are pleased to do so as follows:

I. Name and contact details of the controller
The controller, as defined by GDPR art. 4(7), other national data protection legislation enacted by EU member states and other regulations governing data protection, is:

VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG
Siegmundstrasse 17
30165 Hanover, Germany
Tel.: +49 511 3526-0
Fax.: +49 511 3521-315
info@vsmabrasives.com
www.vsmabrasives.com

II. Name and contact details of the Data Protection Officer
The Data Protection Officer for the controller is:

Thomas Spaeing
ds² Unternehmensberatung GmbH & Co. KG
Berliner Straße 1
49201 Dissen
T +49 5421 30 89 518
datenschutzbeauftragter@vsmabrasives.com

III. No transfer to a third country or an international organisation
Your personal data is not transferred to a third country or an international organisation and no such transfer is intended in the future.

IV. No automated decision-making or profiling
No automated decision-making or profiling is conducted in the sense as defined by GDPR art. 22.

V. Purposes for which your personal data is processed
1. Address management and communication (by email)
2. Order processing (services provided by VSM AG), incl. sending of technical information by email
3. Data that is required for the establishment, exercise or defence of potential legal claims vis-à-vis you or third parties
4. Management of rights granted to data subjects under data protection law

VI. Legal basis on which your personal data is processed
For 1: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in communicating with you effectively and efficiently.

For 2: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in providing a prompt and professional response to your enquiry as a service performed by VSM AG.

For 3: Your personal data, which we have received in the course of our communications with you, may be required for the establishment, exercise or defence of potential legal claims vis-à-vis you or third parties. The legal basis for this processing is point (f) of art. 6(1) of the GDPR. In this case, VSM AG has a legitimate interest in the use of personal data for the reasons mentioned above.

For 4: Processing is completed in order to maintain or fulfil legal obligations and honour the rights of the data subject as stated in GDPR chapter III (arts. 12–22), which VSM AG is required to comply with as a controller in the sense as defined by GDPR art. 4(7). The legal basis for this processing is point (c) of art. 6(1) of the GDPR.

VII. Description of personal data categories
For 1: Contact details (first and last name, email address, phone number, address details, type of contact, fax number), correspondence.

For 2: Contract data, correspondence and order data, as well as other data we have received from you as part of order processing.

For 3: Master data, communications data, contract data.

For 4: Declarations of withdrawal of consent concerning consent you have given: declarations of objection that you may make to the processing of your personal data; declarations and information that we receive from you in order to exercise your rights as a data subject granted by GDPR chapter III (arts. 12–22) or in the course of exercising such rights.

VIII. Categories of recipients to whom the personal data has been or will be disclosed
Employees of VSM AG as well as the phone service and IT service providers employed as part of conducting our business, with whom corresponding contracts have been concluded to ensure the protection of your personal data is safeguarded at all times. Government agencies (in the event of a criminal investigation)

IX. Deletion periods for the various data categories and retention criteria
Personal data is erased once the purpose of data processing no longer applies and no later than the end of the business relationship (limitation on storage), except in cases where legal retention periods (e.g. as defined by commercial or tax law) or legal limitation periods apply that prohibit this erasure.

X. Requirement to make data available  
There is no legal or contractual requirement for you to make your personal data available. However, we need you to make your personal data available in order to conduct activities related to our business relationship. If you do not wish to make your personal data available, we will be unable to establish a business relationship or exchange business correspondence with you.

XI. Data sources
We work with data that you provide us with directly; we may also receive this data from other persons in your company or other business contacts.

XII. Rights of the data subject
In cases where your personal data is processed, you are a ‘data subject’ as defined by the GDPR and you are granted the following rights vis-à-vis the controller (VSM AG):

1. Right to access
On the basis of GDPR art. 15, you can ask us, as the controller, to provide you at any time with information about your personal data that we process and how we process this data.

2. Right to rectification
On the basis of GDPR art. 16, you are granted a right to the rectification and/or completion of incomplete data vis-à-vis the controller, in cases where your personal data that is processed is inaccurate or incomplete. The controller must make such rectifications without undue delay.

3. Right to restriction of processing
On the basis of GDPR art. 18, you can make a request to have the processing of your personal data restricted by the controller.

4. Right to erasure and the ‘right to be forgotten’
On the basis of the right granted by GDPR art. 17, you can make a request to have your personal data erased by the controller; by making this request, you can thereby exercise your ‘right to be forgotten’.

5. Right to information
If you have exercised your right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is required by law to notify all recipients to whom personal data about you has been disclosed about this rectification, erasure or restriction of processing, except in cases where this notification proves to be impossible or would involve a disproportionate amount of effort on the part of the controller. On the basis of GDPR art. 19, you have the right to request information about these recipients from the controller.

6. Right to data portability
On the basis of GDPR art. 20, you have the right to receive the personal data about you that you have provided to the controller in a structured, commonly used and machine-readable format.

7. Right to object
On the basis of GDPR art. 21, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data about you, where such processing is based on point (e) or (f) of art. 6(1) of the GDPR; this right also includes profiling based on these provisions. As the controller, VSM AG will no longer process your personal data unless we are able to demonstrate compelling legitimate grounds for this processing that override your interests, rights and freedoms as the data subject, or where this processing is required for the establishment, exercise or defence of legal claims.

8. Right to withdraw consent as given under data protection law
You have the right to withdraw your consent as given under data protection law at any time. Withdrawal of consent does not affect the legitimacy of processing completed on the basis of this consent until the point in time of withdrawal.

9. Right to lodge a complaint with a supervisory authority
Without prejudice to other legal remedies provided under administrative law or by a court order, you have the right to lodge a complaint with a supervisory authority, whether in the member state of your place of residence, your workplace or the place of the alleged violation, if you believe that the processing of your personal data was done in violation of the provisions of the GDPR. The supervisory authority with whom the complaint is lodged informs the plaintiff about the progress and results of the complaint, including the possibility of obtaining an effective judicial remedy on the basis of GDPR art. 78.

The competent state supervisory authority for VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG is:

State Data Protection Commissioner for Lower Saxony
Prinzenstrasse 5 30159 Hanover, Germany
Phone: +49 (511) 120 45-00
Fax: +49 (511) 120 45-99
Email: poststelle@lfd.niedersachsen.de

Category: Training Participants

You have used a link to access this page, where we provide you with information about how we handle your personal data. To fulfil our duties to provide information about data protection according to articles 13 and 14 of the EU General Data Protection Regulation (GDPR), we are pleased to do so as follows:

I. Name and contact details of the controller
The controller, as defined by GDPR art. 4(7), other national data protection legislation enacted by EU member states and other regulations governing data protection, is:  

VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG  
Siegmundstrasse 17  
30165 Hanover, Germany  
Tel.: +49 511 3526-0  
Fax.: +49 511 3521-315  
info@vsmabrasives.com
www.vsmabrasives.com

II. Name and contact details of the Data Protection Officer  
The Data Protection Officer for the controller is:  

Thomas Spaeing
ds² Unternehmensberatung GmbH & Co. KG
Berliner Straße 1
49201 Dissen
T +49 5421 30 89 518
datenschutzbeauftragter@vsmabrasives.com

III. No transfer to a third country or an international organisation  
Your personal data may be transferred to our subsidiaries outside the EU for planning and carrying out the training.

IV. No automated decision-making or profiling  
No automated decision-making or profiling is conducted in the sense as defined by GDPR art. 22.  

V. Purposes for which your personal data is processed  
1. Address management and communication (by email)  
2. Order processing (services provided by VSM AG), incl. sending of technical information by email  
3. Data that is required for the establishment, exercise or defence of potential legal claims vis-à-vis you or third parties  
4. Management of rights granted to data subjects under data protection law

VI. Legal basis on which your personal data is processed  
For 1: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in communicating with you effectively and efficiently.  

For 2: Insofar as processing is required to fulfil a contract or to take steps prior to entering into a contract with a direct relationship to you as the data subject, we process your data in accordance with point (b) of art. 6(1) of the GDPR. Insofar as processing is not required to fulfil a contract or to take steps prior to entering into a contract, processing is conducted in accordance with point (f) of art. 6(1) of the GDPR. Our legitimate interest lies in providing a prompt and professional response to your enquiry as a service performed by VSM AG.  

For 3: Your personal data, which we have received in the course of our communications with you, may be required for the establishment, exercise or defence of potential legal claims vis-à-vis you or third parties. The legal basis for this processing is point (f) of art. 6(1) of the GDPR. In this case, VSM AG has a legitimate interest in the use of personal data for the reasons mentioned above.  

For 4: Processing is completed in order to maintain or fulfil legal obligations and honour the rights of the data subject as stated in GDPR chapter III (arts. 12-22), which VSM AG is required to comply with as a controller in the sense as defined by GDPR art. 4(7). The legal basis for this processing is point (c) of art. 6(1) of the GDPR.  

VII. Description of personal data categories  
For 1: Contact details (first and last name, email address, phone number, address details, type of contact, fax number), correspondence.  

For 2: Contract data, correspondence and order data, as well as other data we have received from you as part of order processing.  

For 3: Master data, communications data, contract data.  

For 4: Declarations of withdrawal of consent concerning consent you have given: declarations of objection that you may make to the processing of your personal data; declarations and information that we receive from you in order to exercise your rights as a data subject granted by GDPR chapter III (arts. 12-22) or in the course of exercising such rights.  

VIII. Categories of recipients to whom the personal data has been or will be disclosed  
Employees of VSM AG and, if applicable, its subsidiaries as well as the phone service and IT service providers employed as part of conducting our business, with whom corresponding contracts have been concluded to ensure the protection of your personal data is safeguarded at all times. In case you have requested a hotel reservation or the organisation of taxi rides in context of the registration for the training, the data will be transfered on to the hotels or taxi companies to the extent necessary. Any transfer to the subsidiaries of VSM AG is only for internal administrative purposes, such as planning and carrying out the training. Government agencies (in the event of a criminal investigation)

IX. Deletion periods for the various data categories and retention criteria  
Personal data is erased once the purpose of data processing no longer applies and no later than the end of the business relationship (limitation on storage), except in cases where legal retention periods (e.g. as defined by commercial or tax law) or legal limitation periods apply that prohibit this erasure.

X. Requirement to make data available    
There is no legal or contractual requirement for you to make your personal data available. However, we need you to make your personal data available in order to conduct activities related to our business relationship. If you do not wish to make your personal data available, we will be unable to establish a business relationship or exchange business correspondence with you.

XI. Data sources
We work with data that you provide us with directly; we may also receive this data from other persons in your company or other business contacts.

XII. Rights of the data subject  
In cases where your personal data is processed, you are a 'data subject' as defined by the GDPR and you are granted the following rights vis-à-vis the controller (VSM AG):

1. Right to access  
On the basis of GDPR art. 15, you can ask us, as the controller, to provide you at any time with information about your personal data that we process and how we process this data.

2. Right to rectification  
On the basis of GDPR art. 16, you are granted a right to the rectification and/or completion of incomplete data vis-à-vis the controller, in cases where your personal data that is processed is inaccurate or incomplete. The controller must make such rectifications without undue delay.

3. Right to restriction of processing  
On the basis of GDPR art. 18, you can make a request to have the processing of your personal data restricted by the controller.

4. Right to erasure and the 'right to be forgotten'  
On the basis of the right granted by GDPR art. 17, you can make a request to have your personal data erased by the controller; by making this request, you can thereby exercise your 'right to be forgotten'.  

5. Right to information  
If you have exercised your right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is required by law to notify all recipients to whom personal data about you has been disclosed about this rectification, erasure or restriction of processing, except in cases where this notification proves to be impossible or would involve a disproportionate amount of effort on the part of the controller. On the basis of GDPR art. 19, you have the right to request information about these recipients from the controller.  

6. Right to data portability  
On the basis of GDPR art. 20, you have the right to receive the personal data about you that you have provided to the controller in a structured, commonly used and machine-readable format.  

7. Right to object  
On the basis of GDPR art. 21, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data about you, where such processing is based on point (e) or (f) of art. 6(1) of the GDPR; this right also includes profiling based on these provisions. As the controller, VSM AG will no longer process your personal data unless we are able to demonstrate compelling legitimate grounds for this processing that override your interests, rights and freedoms as the data subject, or where this processing is required for the establishment, exercise or defence of legal claims.

8. Right to withdraw consent as given under data protection law  
You have the right to withdraw your consent as given under data protection law at any time. Withdrawal of consent does not affect the legitimacy of processing completed on the basis of this consent until the point in time of withdrawal.  

9. Right to lodge a complaint with a supervisory authority  
Without prejudice to other legal remedies provided under administrative law or by a court order, you have the right to lodge a complaint with a supervisory authority, whether in the member state of your place of residence, your workplace or the place of the alleged violation, if you believe that the processing of your personal data was done in violation of the provisions of the GDPR. The supervisory authority with whom the complaint is lodged informs the plaintiff about the progress and results of the complaint, including the possibility of obtaining an effective judicial remedy on the basis of GDPR art. 78.

The competent state supervisory authority for VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG is:

State Data Protection Commissioner for Lower Saxony  
Prinzenstrasse 5
30159 Hanover, Germany  
Phone: +49 (511) 120 45-00  
Fax: +49 (511) 120 45-99  
Email: poststelle@lfd.niedersachsen.de

Category: Video surveillance

You have used a link to access this page, where we provide you with information about how we handle your personal data. To fulfil our duties to provide information about data protection according to articles 13 and 14 of the EU General Data Protection Regulation (GDPR), we are pleased to do so as follows:

I. Name and contact details of the controller
The controller, as defined by GDPR art. 4(7), other national data protection legislation enacted by EU Member States and other regulations governing data protection, is:
VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG
Siegmundstrasse 17
30165 Hanover, Germany
T +49 511 3526 0
F +49 511 3521 315
info@vsmabrasives.com
www.vsmabrasives.com

II. Contact details of the Data Protection Officer
The controller’s Data Protection Officer is:
Thomas Spaeing
ds² Unternehmensberatung GmbH & Co. KG
Berliner Strasse 1
49201 Dissen, Germany
T +49 5421 30 89 50
datenschutzbeauftragter@vsmabrasives.com

III. No transfer to a third country or an international organisation
Your personal data is not transferred to a third country or an international organisation and no such transfer is intended in the future.

IV. No automated decision-making or profiling
No automated decision-making or profiling, as defined by GDPR art. 22, takes place.

V. Purposes for which your personal data is processed
1. For the protection of the company’s premises against unauthorised access
2. For compliance with customs requirements

3. For the prevention of vandalism and the investigation of crimes (including theft)

4. For protection of the householder’s rights

Legal basis for the processing of your personal data
In cases 1, 3 and 4: Processing is based our legitimate interest in accordance with GDPR art. 6(1)(f). Our legitimate interest lies in the protection of the householder’s rights and the protection of property against unauthorised access and against the committing of criminal offences. The data subjects’ interests or fundamental rights and freedoms that require protection of personal data are not overridden and the data subject is not a child. The processing is transparent and can be easily retraced and fully understood by the data subject

In case 2: Processing is carried out to comply with legal obligations in accordance with GDPR art. 6(1)(c). It serves to fulfil the requirements for obtaining a customs AEO authorisation in accordance with Art. 39(e) of Regulation 952/2013 in connection with Art. 28(1)(b) of the Commission Implementing Regulation (EU) 2015/2447.

VII. Description of personal data categories
In cases 1–4: Behaviour data and vehicle licence plate data

VIII. Categories of recipients to whom the personal data has been or will be disclosed
VSM AG employees in the gatekeeper’s office.

IX. Deletion periods for the various data categories, and retention criteria
The collected data is transmitted to the screens in real time. No storage or recording takes place.

X. Requirement to make data available
There is no legal or contractual requirement for you to make your personal data available. However, the data needs to be made available for protection of the householder’s rights and for maintaining the customs status.

XI. Data sources
We work with data that we collect directly from you.

XII. Rights of the data subject
In cases where your personal data is processed, you are a ‘data subject’ as defined in the GDPR and you have the following rights vis-à-vis the controller (VSM AG):

1. Right to access
On the basis of GDPR art. 15, you can ask us, as the controller, to provide you at any time with information about your personal data that we process and how we process this data.

2. Right to rectification
On the basis of GDPR art. 16, you have the right to require the controller to rectify and/or complete the personal data if the processed personal data concerning you is incorrect or incomplete. The controller must make such rectifications without undue delay.

3. Right to restriction of processing
On the basis of GDPR art. 18, you can make a request to have the processing of your personal data restricted by the controller.

4. Right to erasure and the ‘right to be forgotten’
On the basis of the right granted by GDPR art. 17, you can make a request to have your personal data erased by the controller; by making this request, you can thereby exercise your ‘right to be forgotten’.

5. Right to information
If you have exercised your right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is required by law to notify all recipients to whom personal data about you has been disclosed about this rectification, erasure or restriction of processing, except in cases where this notification proves to be impossible or would involve a disproportionate amount of effort on the part of the controller. On the basis of GDPR art. 19, you have the right to request information about these recipients from the controller.

6. Right to data portability
On the basis of GDPR art. 20, you have the right to receive the personal data about you that you have provided to the controller in a structured, commonly used and machine-readable format.

7. Right to object
On the basis of GDPR art. 21, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data about you, where such processing is based on point (e) or (f) of art. 6(1) of the GDPR; this right also includes profiling based on these provisions. As the controller, VSM AG will no longer process your personal data unless we are able to demonstrate compelling legitimate grounds for this processing that override your interests, rights and freedoms as the data subject, or where this processing is required for the establishment, exercise or defence of legal claims.

8. Right to withdraw consent as given under data protection law
You have the right to withdraw your consent as given under data protection law at any time. Withdrawal of consent does not affect the legitimacy of processing completed on the basis of this consent until the point in time of withdrawal. 9. Right to lodge a complaint with a supervisory authority Without prejudice to other legal remedies provided under administrative law or by a court order, you have the right to lodge a complaint with a supervisory authority, whether in the Member State of your place of residence, your workplace or the place of the alleged violation, if you believe that the processing of your personal data was done in violation of the provisions of the GDPR. The supervisory authority with whom the complaint is lodged informs the plaintiff about the progress and results of the complaint, including the possibility of obtaining an effective judicial remedy on the basis of GDPR art. 78.

The competent state supervisory authority for VSM · Vereinigte Schmirgel- und Maschinen-Fabriken AG is:

State Data Protection Commissioner for Lower Saxony
Prinzenstrasse 5
30159 Hanover, Germany
Phone: +49 (511) 120 45 00
Fax: +49 (511) 120 45 99
Email: poststelle@lfd.niedersachsen.de