Privacy Policy
Hornik GmbH
Alexander-Fleming-Str. 3851643 Gummersbach
Germany
Contact
Phone: +49 2261 815870
Email: info@hornikgroup.com
Website: hornikgroup.com
1. General information
Protecting personal data is important to us. This Privacy Policy explains which personal data we process in connection with our B2B shop, for which purposes we process it and which rights data subjects have. Although our shop is intended for business customers, personal data of contact persons, employees, suppliers and other natural persons may be processed.
2. Data we process
Depending on how the shop is used, we may process the following categories of data:
- Contact details such as name, business address, email address and telephone number.
- Company-related data such as company name, department, role, VAT ID and billing details.
- Account and order data such as login data, cart, quotations, orders, delivery addresses and communication history.
- Payment, shipping and fulfilment data where required for quotations, contracts, delivery, invoicing or complaints.
- Technical data such as IP address, date and time of access, browser type, operating system, referrer URL and server log files.
- Voluntary information submitted through contact forms, email, telephone or other communication channels.
3. Purposes and legal bases
We process personal data in particular for the following purposes:
- Providing, securing and maintaining the technical stability of the B2B shop.
- Handling enquiries, quotations, customer accounts, orders, deliveries and complaints.
- Complying with contractual, tax and commercial law obligations.
- Communicating with customers, prospects, suppliers and business partners.
- Direct marketing and newsletters where legally permitted or where consent has been given.
The legal bases include Art. 6(1)(b) GDPR for pre-contractual and contractual measures, Art. 6(1)(c) GDPR for legal obligations, Art. 6(1)(f) GDPR for legitimate interests such as IT security, business operations and customer communication, and Art. 6(1)(a) GDPR where consent is obtained.
4. Cookies and shop functions
Our B2B shop uses technically necessary cookies to provide core functions such as the shopping cart, login, language settings, security features and checkout processes. Optional cookies, for example for analytics, convenience or marketing, are used only where legally permitted and, where required, based on consent. Cookie settings can be adjusted or withdrawn via the consent tool used on the website and through the browser settings.
5. Recipients and service providers
Personal data is not sold. Data is disclosed only where necessary for the purposes described above, where required by law or where consent has been given. Recipients may include IT and hosting providers, payment service providers, shipping and logistics partners, tax advisers, accounting systems, support and CRM providers as well as public authorities within the legally permitted scope. Where required, service providers are bound by data processing agreements.
6. Transfers to third countries
Processing generally takes place within the European Union or the European Economic Area. If a transfer to a third country is required in an individual case, it will take place only on the basis of suitable safeguards, such as an adequacy decision, EU Standard Contractual Clauses or explicit consent.
7. Retention period
We retain personal data only for as long as necessary for the relevant purposes or as required by statutory retention obligations. Contract, invoice and accounting data is retained in accordance with commercial and tax law requirements. Afterwards, data is deleted or restricted unless further legitimate grounds for retention exist.
8. Contact, newsletter and applications
If you contact us by email, telephone or form, we process the data provided to handle the enquiry. Newsletters are sent only where there is a valid legal basis, in particular consent. Unsubscribing is possible at any time. Application data is processed solely for the recruitment process and is deleted after completion unless statutory retention obligations or legitimate interests require further storage.
9. Rights of data subjects
Under the GDPR, data subjects have the following rights in particular:
- Right of access to personal data processed about them.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure where no retention obligations prevent deletion.
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing based on legitimate interests.
- Right to withdraw consent with effect for the future.
- Right to lodge a complaint with a competent data protection supervisory authority.
10. Security and automated decision-making
We implement technical and organisational measures to protect personal data against loss, misuse, unauthorised access and alteration. We do not use solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR.