Transparency declaration by bg电子娱乐场 AG & Co. KGaA with regard to business relationships
B2B-Transparency Declaration
bg电子娱乐场 aims to conduct all business in an ethically and legally sound manner. In particular, this also includes compliance with the applicable data protection laws.
It is against this background that we should like to inform you, as
- a current or prospective customer of bg电子娱乐场 AG & Co. KGaA or another bg电子娱乐场 company affiliated with bg电子娱乐场 AG & Co. KGaA 鈥(bg电子娱乐场 Group Company),
- a current or prospective supplier of bg电子娱乐场 AG & Co. KGaA or a bg电子娱乐场 Group Company,
- an employee of the aforementioned current or prospective customer or supplier of bg电子娱乐场 AG & Co. KGaA or bg电子娱乐场 Group Company, or
- another person in a current or prospective business relationship with bg电子娱乐场 AG & Co. KGaA or bg电子娱乐场 Group Company,
about the processing of your personal data by bg电子娱乐场 AG & Co. KGaA as well as the rights you have as the data subjects of this data processing.
Please notice that this Transparency Declaration addresses different business relationships and different data processing activities only one or few of which may apply to you personally. To what extent we process personal data about you largely depends on your specific business relationship with bg电子娱乐场.
1. Who is the data controller?
For the processing of your data as described in this transparency declaration, the following controller is responsible in terms of the data protection law, unless stated otherwise:
bg电子娱乐场 AG & Co. KGaA
bg电子娱乐场str. 67
40589 D眉sseldorf
(henceforth 鈥渂g电子娱乐场鈥, 鈥渦s鈥, or 鈥渨e鈥)
2. How can I contact the data protection officer of bg电子娱乐场 AG & Co. KGaA?
The contact details of the data protection officer of bg电子娱乐场 AG & Co. KGaA are:
bg电子娱乐场 AG & Co. KGaA
Datenschutzbeauftragter
bg电子娱乐场str. 67
40589 D眉sseldorf
Email address: datenschutz@henkel.com
3. From which sources is my personal data obtained?
We process personal data about you which we have received or collected directly from you when we interact with you in the circumstances of our business relationship with you 鈥(e.g. you place an order for bg电子娱乐场 products and share your name and address with us for shipment).
We may also process personal data about you we have received from another bg电子娱乐场 Group Company. Such transferring bg电子娱乐场 Group Companies are especially the local bg电子娱乐场 companies outside of Germany. Since bg电子娱乐场鈥檚 IT-systems are maintained centrally by bg电子娱乐场 in Germany, your personal data will be transferred to and processed by bg电子娱乐场. In case of such a data transfer by a bg电子娱乐场 Group Company to bg电子娱乐场, the respective bg电子娱乐场 Group Company is the responsible Controller in the meaning of Art. 4 No. 7 GDPR as regards the transfer of your personal data. Once transferred, bg电子娱乐场 acts as responsible Controller in the meaning of Art. 4 No. 7 GDPR as regards the processing of your personal data in the global bg电子娱乐场 database.
We may also receive your personal data from your employer if this is necessary regarding the business relationship with your employer 鈥(e.g. your employer is a supplier and organised a meeting between you and bg电子娱乐场 representatives regarding our business relationship).
We may also receive your personal data from other companies which have a business relationship with bg电子娱乐场, and/or a bg电子娱乐场 Group company, and/or your employer (e.g. another supplier refers you regarding a certain service bg电子娱乐场 seeks to purchase).
4. What personal data is being processed?
Please notice: The specific types of personal data we are processing rely heavily on your business relationship with bg电子娱乐场. Therefore, the necessary processing of personal data varies depending on your connection to bg电子娱乐场, only individual categories from the following list of personal data may be processed. Depending on the respective business relationship and your specific role in it, we process the following personal data:
- Contact data, in particular postal address, electronic addresses 鈥(e.g. email address), telephone numbers and user identifications;
- Contract data, in particular details on the start and end of contract, on services and products provided and projects during contract time;
- Data on former products or service provided, in particular with companies in the bg电子娱乐场 Group;
- Organisation data, in particular details on the position, cost centre, room number, department, line managers;
- Remuneration data, in particular payment data as well as other data about payments in connection with the products or service provided;
- Bank data, in particular account number, financial institute, credit card number, debit card number;
- Assessment data, in particular data with regard to assessments of payment history and payment behaviour;
- CV data, this data category also includes data in online profiles, e.g. LinkedIn profiles;
- Customer classification data, in particular with regard to the assessment of interests in certain product categories;
- Learning data, in particular data about participation in further training or eLearnings;
- Communication data, in particular content of electronic communication, e.g. via email, Skype, Sharepoint, MS Teams;
- Connection data, in particular data that describes the circumstances of telecommunications or electronic communications as well as data from web analysis tools, e.g. log files;
- Creditworthiness data, in particular data that determine the creditworthiness of a person or company, and data for the assessment of creditworthiness, e.g. public information on the seizure of property or insolvency;
- ID data, in particular data that is generally stated on an identity card or a driving licence, e.g. the birthday or passport number;
- Pictures, in particular photographs as well as images from video surveillance;
- Time stamps, in particular personalized records of activities with time stamps 鈥(time events), e.g. logging of events in computer systems, safety systems;
- Transaction data, in particular data on particular contracts or legal relationships, deliveries or other details of business transactions.
5. For what purposes and on what legal basis is my data processed?
We will process your personal data specified under 3. in accordance with all statutory provisions, in particular the General Data Protection Regulation 鈥(GDPR), the German Federal Data Protection Act 鈥(BDSG) and other applicable laws 鈥(e.g. the German Works Constitution Act and the German Working Hours Act) on the basis of the following legal grounds for the following purposes:
- To perform the contract concluded or to be concluded between you and bg电子娱乐场 AG & Co. KGaA and/or another bg电子娱乐场 Group Company, if you are personally a customer of, supplier of, or in another current or prospective business relationship with bg电子娱乐场 AG & Co. KGaA and/or the other bg电子娱乐场 Group Company (Art. 6 Paragraph 1 lit b GDPR). We process your data for purposes of the contractual relationship including its execution, implementation, or termination. We also process your data as far as necessary to effect pre-contractual measures carried out at your request.
- To fulfill a legal obligation that we are subjected to, such as tax laws, anti-money laundering law, and social security laws (Art. 6 Paragraph 1 lit. c GDPR). To the extent this is necessary to comply with these legal obligations, we also process your data for this purpose.
- To achieve purposes of our legitimate interests or the legitimate interests of a third party, in particular those of a company within the bg电子娱乐场 Group, which are not overridden by your interests (Art. 6 Paragraph 1 lit. f GDPR).
Such legitimate interests are: communication with you and or/your employer; organisation of supply chains and/or product deliveries; administration of projects you are involved in; provision of suitable IT systems; IT security measures; prevention and detection of criminal offences; video surveillance on our premises to safeguard and enforce domiciliary rights and the collection of evidence in the event of any burglaries, sabotage and thefts; measures for building and plant safety (e.g. physical access control); asserting or defending against any legal claims and litigation; measures to secure domiciliary rights; measures for business control and development as well as for the production of services and products; risk management via bg电子娱乐场 Group; management and coordination of companies belonging to the bg电子娱乐场 Group; and internal administrative purposes. - On the basis of your consent (Art. 6 Paragraph 1 lit. a GDPR), which you may have provided us with regarding specific processing activities. In connection to these processing activities we will also inform you specifically when collecting consent from you.
If data processing is based on your consent, you have the right to withdraw such consent at any time with effect for the future. The legitimacy of the processing effected on the basis of your consent until such withdrawal is not affected by the withdrawal. Additional information on this topic is also provided in the respective declaration of consent.
6. Do I have a duty to provide my data?
If your data is necessary to establish, conduct or terminate your contractual relationship or to fulfil any contractual obligations associated with the same, you are under an obligation to provide these data. This also applies to the extent we have a statutory obligation to collect these data.
If you do not provide these data it might lead to disadvantages for you and/or your employer. Thus, depending on the respective context and business connection, it is possible, for instance, that in such case we would need to terminate the contractual relationship with you or your employer, since you or your employer would not be able to perform the contract concluded with bg电子娱乐场, or that we will not be able to carry out certain measures or provide working equipment.
7. For how long will my data be stored?
We will store and process your data for as long as this is necessary for the respective purpose for which it is being processed 鈥(e.g. for the duration of the business relationship) or - to the extent that your data is processed based on your consent - whichever comes first - until you withdraw this consent. Subsequently, the data will be deleted.
However, in exceptional cases, we will continue to store and process the data as long as we are legally obliged to retain and store this information (for example, for tax or labour law reasons), as long as this is necessary to assert, exercise or defend legal rights or if we have legal grounds allowing further processing.
8. Will my data be processed in connection with profiling?
In short, we understand profiling to be the electronic processing of your data for assessing certain personal aspects 鈥(cf. Art. 4 No. 4 GDPR). However, bg电子娱乐场 will never make any decisions affecting you solely based on automated processing as described in Art. 22 GDPR.
If necessary in the context of the respective business relationship with you or your employer, we may process personal data for a profiling in order to evaluate your performance as a supplier to bg电子娱乐场. In this way, we may assess the business relationship we have with you or your employer from time to time in order to determine whether an adjustment is necessary in this regard. Based on our assessment, we may decide which supplier to enter into, extend or exit a business relationship with.
If you are a customer, we may also assess your personal interests in different services or products in order to determine which services or products to offer you within the boundaries of our business relationship.
9. To whom will my data be passed on?
Within bg电子娱乐场 AG & Co. KGaA, your data will only be provided to such employees and agencies 鈥(for example, specialist departments) who need them in connection with their official duties for the above-mentioned purposes.
In addition, your data may be passed on to other companies within the bg电子娱乐场 Group if this is necessary in the context of the respective business relationship. Furthermore, the Shared Service-Centers of the bg电子娱乐场 Group may also receive your data if this is necessary in the context of the respective business relationship.
We also use external service providers for the provision of various services 鈥(e.g. logistics, IT services, printing services, telecommunications, debt collection, consulting, financial services, marketing agencies, as well as insurance). As far as necessary in order to achieve the purposes disclosed above, your data will be shared with these service providers. These service providers are strictly bound to bg电子娱乐场鈥檚 instructions.
To the extent that this is required and permitted by data protection law 鈥(for example, if you have consented thereto or if a legal basis allows us to do so), we will also pass on your data to recipients outside the bg电子娱乐场 Group. Such recipients may be e.g.: Public authorities, bodies for which you have given your consent, social insurance carriers, pension funds, tax authorities, public bodies and institutions 鈥(e.g. law enforcement authorities) in the presence of a statutory or regulatory obligation, credit and financial services institutions or similar institutions to which we transfer personal data for implementing the contractual relationship, auditors and tax inspectors, service providers we use in the context of contract processing relationships, creditors or liquidators who - in connection with enforcement measures 鈥 request the data, and courts.
In this context, personal data may also be transmitted to countries outside the European Economic Area 鈥(EEA), in particular to other bg电子娱乐场 Group companies. Furthermore, some of our external service providers to whom we may transfer your personal data reside outside the EEA.
If data is transmitted to countries outside the EEA, this will only be done if the EU Commission has decided that this country, this area or the specific sector provides an adequate level of protection (this is currently the case, for instance, in Andorra, Argentina, Faroe Islands, Guernsey, Israel (with restrictions), Isle of Man, Jersey, Canada (with restrictions), New Zealand, Switzerland, Uruguay and - under the EU-US Privacy Shield - the USA), or if suitable guarantees are provided for and enforceable rights and effective remedies are available to you (e.g. after conclusion of the EU Standard Contractual Clauses) or if there is an exemption according to Art. 49 GDPR (e.g. if you have consented to such a transfer or if this is necessary to fulfil the employment contract with us).
10. Which rights am I entitled to as a data subject under data protection law?
As a data subject affected by data processing, you are in particular entitled to the following rights on the basis of data protection law: Right to information acc. to Art. 15 GDPR, right to rectification acc. to Art. 16 GDPR, right to deletion acc. to Art. 17 GDPR, right to a restriction of processing acc. to Art. 18 GDPR, and the right to data portability acc. to Art. 20 GDPR.
You also have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6 Paragraph 1 lit. f or Art. 6 Paragraph 1 lit. e GDPR. If you have objected to the processing of your data in accordance with these requirements, we will no longer process the personal data affected, unless we can prove compelling legitimate grounds for such processing that outweigh your interests, rights and freedoms, or such processing serves to assert, exercise or defend legal claims.
In order to exercise these rights or if you have any further questions regarding the processing of your personal data, please contact the data protection officer of bg电子娱乐场 using the contact information disclosed above.
Furthermore, you have the right to raise a complaint with a data protection supervisory authority acc. to Art. 77 GDPR.
11. Update of the transparency declaration
We reserve the right to change this transparency declaration from time to time, in particular in the event of a change in the processing of your data. The respective current version is to be found on this web page.