Privacy Policy - hsb group - Data protection


1.    Scope


This privacy policy applies to the entire hsb group and is directed at the employees, partners, customers, suppliers and other interested parties of this company. The protection and security of personal data is carried out in accordance with the guidelines of the DSGVO. In the following, you will be informed about the type of data collected and the purpose for which they are collected:


2.    Purpose of the data processing


The hsb group processes personal data of employees, partners, customers and suppliers for the purpose of providing the business activity and the fulfilment of related legal and contractual requirements.


  1. a.    Processing of customer and supplier data


Our company stores and processes the personal data provided by customers, suppliers and other interested parties for the purpose of preparing offers and processing orders as well as fulfilling the associated contractual and legal obligations. In order to fulfil legal obligations, the data is also forwarded to authorities and public bodies.


  1. b.    Applicants


The contact data and application documents submitted in the course of an application are electronically processed by us for the purpose of selecting suitable candidates for an employment relationship and transmitted to our customers.


In the event of a rejection, the application documents will only be kept on file if you agree to this.


c.    Contact form and order tool


If you contact us via the online form or by e-mail, we store the information and data you provide in order to answer your inquiry and to be able to deal with any open questions. Furthermore, even in the case of order enquiries via our order tool, the data transmitted by you will be stored and further processed for the purpose of submitting offers and invoicing.


d.    Video data / company premises


Image acquisition is used for the preventive protection of persons and company property on private properties that are used exclusively by the person responsible. It does not extend spatially beyond the property, with the exception of the inclusion of public traffic areas, which may be unavoidable in order to achieve the purpose. Recorded personal data is deleted when it is no longer needed for the purpose for which it was collected and there is no other legal obligation to retain it.


3.    Data logging


When you visit this page, the web server automatically records log files that cannot be assigned to a specific person. This data includes, for example, browser type and version, operating system used, referrer URL (the previously visited page), IP address of the requesting computer, access date and time of the server request and the file request of the client (file name and URL). This data is collected only for the purpose of statistical analysis. A transfer to third parties, for commercial or non-commercial purposes, does not take place.


4.    Use of personal data


Personal data is mainly collected, processed and stored for business relations, orders via order tool or within an employment relationship, if this information is provided voluntarily or if you have given your consent. Provided that there are no necessary reasons in connection with a business transaction or an employment relationship, you can revoke the previously granted approval of your personal data storage by transmitting your postal identification with immediate effect in writing (e.g. by e-mail or fax) at any time. Your data will not be passed on to third parties, unless a transfer is required by law.


5.    Principles governing the processing of personal data


The processing of personal data is based on strict principles which consider the protection and security of data and the rights of the persons concerned as the highest good.


a.    Legality & Transparency


Data processing is carried out in a lawful manner, in good faith. When the data are collected, the data subject is informed of the planned processing and handling of the data. This will at least inform those concerned about the following points:

  • Person responsible for data processing
  • Purpose of the data processing
  • Legal basis of the processing


b.    Earmarking


The data is collected and processed for specified, clear and legitimate purposes. The data will not be processed in a manner incompatible with these purposes.


c.    Data minimization


Only those data are collected and processed that are absolutely necessary for the specified purposes. If it is possible to achieve the purpose and if the effort is reasonable, only anonymous data will be processed.


d.    Memory limitation and deletion


Personal data is deleted as soon as the purpose for which it was originally collected expires and legal retention periods do not prevent deletion.


If in individual cases there are interests worthy of protection in these data, they will continue to be stored until the interest worthy of protection has been legally clarified.


e.    Data security


Data secrecy applies to personal data. The data is to be treated confidentially and is protected by appropriate organizational and technical measures against unauthorized access, illegal manipulation or disclosure, as well as loss and destruction.


f.     objective accuracy


Personal data must be kept correct, complete and up-to-date. Appropriate measures shall be taken to correct any outdated, incorrect or incomplete data.


6.   Rights of data subjects


In accordance with applicable law, you can request information from us at any time in writing by transmitting your postal identification as to whether and which of your personal data is collected and processed in our company. Furthermore, it is possible to arrange for the correction, restriction, transfer or deletion of your data if required. You also have the right to complain to the data protection authority at any time.


a.    Identification


Data security also has a high priority in relation to the rights of data subjects, which is why the assertion of data subject rights is only possible after unambiguous identification by means of post-identification of the data subject.


b.    Information


Data subjects may at any time request information about the personal data that is processed about them and the purposes of such processing.


c.    Correction


Data subjects shall have the right to request the rectification without delay of inaccurate personal data concerning them.


d.    Restriction


Data subjects shall have the right to obtain a restriction on processing if the accuracy of the data concerning them is disputed, if the processing is unlawful, if the data are no longer needed for the processing or if the data subjects have objected to the processing.


e.    Transferability


Data subjects have the right to receive the personal data concerning them, which they have made available to the hsb group, in a structured, common and machine-readable format. You also have the right to request the transfer of this data to another responsible person, if technically feasible.

The transferability applies only to personal data processed by automated means.


f.     Deletion


The data subject has the right to request the immediate erasure of personal data concerning him/her if the legal basis for the processing of the data is missing or expires, the data processing is opposed, the data processing is unlawful and no legal retention periods make erasure impossible.


Exceptions to the deletion: This is data for business purposes or the data is subject to the legal obligation to retain data. For these purposes please contact our data protection coordinator at / contact details of the data protection coordinator.


g.    Revocation of a declaration of consent


Data subjects have the right to object at any time to the processing of personal data concerning them, to which they have given their prior consent by means of a declaration of consent.


7.   Data transmission


A transmission of personal data to recipients outside of the hsb group and recipients in EU third countries is only carried out in accordance with applicable laws and on a legal basis, as well as in compliance with highest confidentiality and data security.

Within the scope of the group-wide processing of data, an exchange of personal data between companies of the hsb group takes place. This exchange is regulated by a set of rules, the Binding Corporate Rules, and represents a uniform standard for the protection and legally compliant processing of data.

Our company makes use of various contract processors for the processing of data, who are contractually obliged to comply with the legally applicable data protection regulations by means of a contract processor agreement.


8.   Data economy


In accordance with the principles of data avoidance and data economy, we only store personal data for as long as it is necessary or required by law (legal retention period). If the purpose of the collected information ceases to apply or the storage period ends, the data is deleted.


9.   SSL encryption


A Basic SSL certificate is used. The SSL certificate ensures encrypted access to the website and thus enables a secure connection between a web browser and an SSL-enabled web server. In this way, the user is guaranteed that it is really the corresponding website.


10.  General information about Google services used


This website uses various services provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ("Google") if you are a resident of the European Union, the European Economic Area and Switzerland, Google Ireland Limited (registration number: 368047), Gordon House, Barrow Street, Dublin 4, Ireland. Which services exactly this website uses is explained in the following.


By integrating Google services into this website, Google also collects and processes personal information. A transfer of the collected information to a third country cannot be excluded. With the certification for the Privacy Shield, Google has committed itself to compliance with the EU-US and Swiss-US Privacy Shield Framework requirements. Information about participation can be found under the search term Google here: The information may also be disclosed to Google's contractual partners.


11.   Google Tag Manager


This website uses the Google Tag Manager. This service allows website tags to be managed via an online interface. Tags are information in the code of the website that makes it easier to manage, find and market the website. Neither cookies are used nor personal data is collected. The Google Tag Manager may trigger other tags that may also collect personal information. However, the Google Tag Manager does not access this data. If you have blocked cookies and tag processing in your browser, the Google Tag Manager will take this into account.


You can find more information about how it works at:


12.   Note on Google Analytics


This website uses Google Analytics, a web analysis service of Google Inc. "( Google ). Google Analytics uses so-called "cookies", i.e. text files which are stored on your computer and which enable an analysis of your use of the website. The information generated by the cookie about your use of this website (including your IP address) is transferred to a Google server in the USA and stored there. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties if this is legally required or if third parties process this data on behalf of Google. Under no circumstances will Google link your IP address to other Google data.

You can prevent the installation of cookies by selecting the appropriate settings in your browser software. However, we point out that in this case you may not be able to use all functions of this website to their full extent. By using this website, you agree to the processing of the data collected about you by Google in the manner described above and for the aforementioned purpose.


13.   Cookies


On some of our pages we use so-called "session cookies" to make it easier for you to use our websites. These are small text files that are only stored on your hard drive for the duration of your visit to our website and are deleted again when you exit the browser, depending on the settings of your browser program. These cookies do not retrieve any information about you stored on your hard drive and do not affect your PC or files. Most browsers are set in such a way that they automatically accept cookies. However, you can deactivate the storage of cookies or set your browser to notify you when cookies are sent.


14.   Facebook pixels


Within our online offer, the pixel of the social network Facebook, which is operated by Facebook Inc, 1 Hacker Way, Menlo Park, CA 94025, USA, or for residents of the European Union, the European Economic Area and Switzerland by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook"), is used.


With the integration and use of Facebook Pixel, Facebook also collects and processes personal information. A transfer to a third country cannot be excluded.


Facebook Pixel tracks the behavior of website visitors after they have clicked on a Facebook ad to reach the provider's website. This enables an analysis of the effectiveness of Facebook ads for statistical and market research purposes and their future optimization. The use is based on Art. 6 para. 1 lit. f DSGVO. We have a legitimate interest in the analysis of user behaviour in order to optimise both our website and our advertising.


The collected data is anonymous for us as the operator of this website. However, the data is stored and processed by Facebook, which can establish a connection to your Facebook profile. Facebook may use this information for its own promotional purposes in accordance with the Terms of Use. This allows Facebook to display ads on both Facebook and third-party websites.


For more information about protecting your privacy, please see the Facebook privacy policy:



You can also disable the remarketing feature for custom audiences in the Ad Settings section of You must first log in to Facebook. If you do not have a Facebook account, you can suppress Facebook usage-based advertising on the European Interactive Digital Advertising Alliance website:


15.   Changes to this privacy policy


We will update this policy from time to time to protect your personal information. You should review this policy from time to time to stay informed about how we protect your information and continually improve the content of our website. If we make material changes in the way we collect, use and/or share the personal information you provide to us, we will notify you by posting a prominent notice on the Site. By using the website, you agree to the terms of this privacy Policy.