You are here: Home / Data protection information for customers

Data protection information for customers

published Jan 29, 2020 04:10 PM
Information about the collection and processing of your personal data: Care and transparency is the basis for trusting collaboration with our customers. We therefore inform you about how we process your data and how you can exercise your rights, to which you are entitled according to the General Data Protection Regulation (GDPR). Which personal data we process and for what purpose, depends on the respective contractual relationship.

Responsible office:

catworkx GmbH
Schellerdamm 16
21079 Hamburg, Germany

You can reach our data protection officer at:

catworkx GmbH
The Data Protection Officer
Schellerdamm 16
21079 Hamburg, Germany
[Email protection active, please enable JavaScript.]

Processing of personal data:
We process the personal data you provide us with if you have an inquiry, want us to make you an offer, or in the context of the implementation or the initiation of a contractual relationship. We also process your personal data for the purpose of carrying out direct advertising for our own similar goods or services. The legal basis for the processing of your personal data is Article 6 paragraph 1 (a), (b) and (f) GDPR.

Insofar as the processing of your personal data is based on a legitimate interest, our business purpose represents legitimate interest:

  • central customer data management of the catworkx group
  • measures for building and facility safety
  • consultation of and data exchange with credit agencies
  • determining credit and default risks
  • ensuring IT security and IT operation 

If you have given us your voluntary consent to the collection, processing or transmission of certain personal data, then this consent forms the legal basis for the processing of these data:

In the following cases, we process your personal data on the basis of your consent: 

  • sending an e-mail newsletter
  • personalized newsletter tracking
  • market research (e.g. customer satisfaction surveys)
  • marketing and advertising creation of customer profiles
  • publication of a customer reference (name and picture)

Within this contractual relationship we will process your data in particular to carry out the following activities:

  • order related contact 
  • order management
  • ongoing customer support
  • service
  • exercise of warranty claims 
  • receivables management
  • contract termination management

Depending on the legal basis, the categories of personal data concerned are:
First name, last name, address, communication data (telephone, e-mail address), date of birth, nationality, contract master data, in particular contract number, duration, period of notice, type of contract, invoice data/turnover data, creditworthiness data, payment data/account information, account details, in particular registration and logins.

We store your personal data as long as it is necessary to fulfil our legal and contractual obligations. If storage of the data is no longer necessary for the fulfilment of contractual or legal obligations, your data will be deleted, unless further processing is required for the following purposes:

  • compliance with commercial and tax retention requirements
  • preservation of evidence within the framework of the legal statute of limitations. According to the statutes of limitation of the German Civil Code, these periods of limitation can in some cases be up to 30 years; the regular period of limitation is three years.

Transfer of personal data:
To fulfill our contractual and legal obligations, your personal data may be disclosed to various public bodies or internal departments, as well as external service providers.

Within the corporate group, data may be passed on to the following companies:

  • catworkx Holding GmbH
  • catworkx GmbH, Germany
  • catworkx GmbH, Austria
  • catworkx AG, Switzerland

Depending on the existing contractual relationship, data may also be passed on to the following recipients:

  • IT service providers (e.g. maintenance service providers, hosting service providers, hardware suppliers)
  • service providers for file and data destruction
  • printing services
  • telecommunication
  • payment service providers
  • advice and consulting
  • service providers for marketing or sales
  • service providers for telephone support (call centers)
  • auditors

Countries outside the European Union (and the European Economic Area, "EEA") treat the protection of personal data differently from countries within the European Union. We also use service providers located in third countries outside the European Union to process your data. There is currently no EU Commission decision that these third countries generally offer an adequate level of protection.

We have therefore taken special measures to ensure that your data is processed in third countries as securely as within the European Union. We include standard data protection clauses provided by the Commission of the European Union in the contracts agreed with service providers in third countries. These clauses provide appropriate safeguards for the protection of your data with service providers in third countries.

Our service providers in the USA are also certified under the EU-US Privacy Shield agreement.      

If you wish to inspect the existing guarantees, you can contact us at [Email protection active, please enable JavaScript.]

Right of objection:
You can object to the use of your data for advertising purposes at any time. 

Under Article 21 paragraph 1 of the GDPR, you have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6 paragraph 1 (f) GDPR. In the event of your objection, we will no longer process your personal data, unless we can prove compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

If we process your personal data for the purpose of direct advertising, you have the right to object to the processing of your personal data for the purpose of such advertising at any time in accordance with Article 21 paragraph 2 GDPR.

If you object to processing for the purpose of direct advertising, we will no longer process your personal data for these purposes.

Withdrawal of consent:
You can revoke your consent to the processing of personal data at any time. Please note that the revocation is only valid for the future.

Right to information:
You can request information about whether we have stored personal data about you. If you so wish, we will inform you of the data concerned, the purposes for which the data is processed, to whom the data is disclosed, how long the data is stored and what other rights you have in relation to the data.

Other rights:
Furthermore, you have the right to correct incorrect data or to delete your data. If there is no reason for further storage, we will delete your data, otherwise we will limit the processing. You can also request that we make all personal data you have provided us with available in a structured, conventional and machine-readable format either to you or to a person or company of your choice.

In addition, there is a right of appeal to the competent data protection supervisory authority (Article 77 GDPR in conjunction with paragraph 19 Federal Data Protection Act).

In order to exercise your rights and if you have further questions about data protection, you can contact the person responsible or the data protection officer at the contact details provided.