
Notes on Data Processing for Business Partners, Interested Parties and Other Persons Concerned («Data Protection Information»)
The processing of personal data, such as the name, address, e-mail address, or telephone number of a data subject shall always be in line with the EU General Data Protection Regulation (GDPR), and in accordance with the country-specific data protection regulations applicable to KYB.
This privacy policy applies to the processing of personal data by KYB. With regard to the terminology used (e.g. «personal data», «processing» or «controller»), reference is made to the definitions in Art. 4 of the EU General Data Protection Regulation (hereinafter referred to as «GDPR»).
If interested parties, business partners and contacts are not at the same time persons concerned, they will pass on the data protection information to the natural persons acting on their behalf (e.g. their contact persons, other commissioned or authorized persons).
The Controllers for the processing of personal data within the meaning of Art. 4 para. 7 GDPR are
KYB Europe GmbH
Margaretha-Ley-Ring 2
85609 Aschheim
Germany
You can contact the Data Protection Officer designated by KYB also at the aforementioned postal address by inserting “To the Data Protection Officer”, or via E-Mail: data.protection@kyb-europe.com
Within the framework of the initiation (e.g. processing of an inquiry, preparation of an offer), justification, processing and handling of the contractual relationship, KYB processes the data provided and required for this purpose (master and contact data of the business partner or his contact persons and other parties involved, contract and accounting data, communication with business partners or his contact persons and other parties involved, further information necessary for processing the enquiry or the order). The processing of these data takes place primarily for appropriate order processing.
This also includes processing for the following purposes:
Within the framework of the contractual relationship, it may be necessary for KYB to collect personal data from publicly accessible sources (e.g. public registers, press, Internet).
Data processing is required pursuant to Art. 6 para. 1 s. 1 lit. b GDPR for the aforementioned purposes. If it is not you, but your employer or client, who is a contractual partner of KYB, the processing of the data provided by the contractual partner within the framework of the contractual relationship is carried out on your person on the basis of Art. 6 para. 1 s. 1 lit. f GDPR. The justified interest of KYB results from the necessity of the processing of these data for purposes of the order fulfilment and/or contribution of pre-contractual measures.
KYB processes personal data to fulfil legal obligations such as compliance with commercial law, money laundering law and tax law documentation and storage obligations.
Legal basis for this is Art. 6 para. 1 s. 1 lit. c GDPR in conjunction with the respective legal obligations.
If KYB has received your business contact data within the scope of a business event, business appointments, seminars or similar or within the scope of a business initiation or order (e.g. within the scope of handing over business cards), KYB stores your contact data in the CRM system (Customer Relationship Management System) for the purpose of maintaining and managing business contacts. The legal basis is Art. 6 para. 1 s. 1 lit. f GDPR. The legitimate interest arises from the aforementioned purposes.
KYB also uses the contact data for the purpose of sending event invitations, information brochures or other information on products and topics (e.g. on current topics in the field of energy generation), events, etc. to business partners and potential interested parties. If your business contact details are publicly accessible (e.g. via the company website or professional networks such as Xing, LinkedIn) and KYB events and/or services may be of interest to you due to your business activities, KYB may also use and store your business contact details for the aforementioned purposes.
If you have given KYB your consent to this, your contact data will be used for these purposes on the basis of Art. 6 para. 1 s. 1 lit. a, Art. 7 GDPR. Your consent is freely revocable with effect for the future at any time (cf. Article 7 thereon). For the rest, the use of your contact data for the aforementioned purposes is subject to the requirements of Art. 6 para. 1 s. 1 lit. f GDPR. The legitimate interest of KYB lies in customer care and the acquisition of new business contacts. If you do not wish information material and/or event invitations to be sent and your contact data to be used for these purposes, you may object to this at any time (cf. Article 8 thereon).
In order to ensure the security, stability, integrity and functionality of the IT systems and IT operations, as well as the security of the data stored and the data processing operations at KYB, it may be necessary to process the personal data stored in the KYB IT systems (e.g. when creating backups or performing tests). The legal basis for this processing of personal data is Art. 6, para. 1, s. 1 (f) GDPR. The legitimate interest arises from the aforementioned purposes.
The processing of personal data generally takes place in states of the European Union (EU) or the European Economic Area (EEA) or within the United Kingdom. If KYB transfers personal data to affiliated group companies or service providers in countries outside the EU/EEA (so-called third countries), the transfer will only take place if the third country has been confirmed an appropriate level of data protection by the EU Commission or other appropriate data protection guarantees (e.g. EU standard contractual clauses) are in place.
As a matter of principle, KYB stores your personal data only for as long as this is necessary to perform the processing purposes described in these Privacy Policy provisions or statutory requirements or filing duties. Other major filing duties arise under commercial law (in particular the storage of commercial and business letters for 6 years and of accounting documents for 10 years, section 257 German Commercial Code (Handelsgesetzbuch hereinafter “HGB”), under tax law (in particular filing of accounting documents for 10 years and of other tax-relevant documents for 6 years, section 147 Fiscal Code (Abgabenordnung, hereinafter “AO”) and under anti-money laundering law (filing of records and other documents as defined in section 8 para. 1 to 3 GwG for 5 years from the end of the calendar year in which the business relations ended, section 8 para. 4 GwG).
After expiry of the statutory filing periods, the data and documents are erased or destroyed unless KYB requires the same to protect its own professional interests taking account of the limitation period stipulated in section 199 para. 3 German Civil Code (Bürgerliches Gesetzbuch, hereinafter “BGB”) for a period of 10 years, beginning with the end of the year in which the relevant engagement was ended or unless the data subject has consented to a longer period of storage.
Where this is necessary to administer contractual relationships, your personal data are transferred to third parties or other organizations. This includes in particular the transfer to service providers (e.g. forwarding agents) for the purpose of proper order processing.
KYB also uses external service providers who may have access to personal data within the scope of their activities for KYB (e.g. postal/transport services, IT service providers, waste disposal companies). Such service providers are only commissioned in accordance with the relevant data protection regulations.
In connection with the processing of personal data, you as a data subject are entitled to the following rights under the GDPR:
Right to information: Pursuant to Art. 15 GDPR, you have the right to ask for information at all times about your personal data processed by KYB and receive the information listed in Art. 15 paras. 1 and 2 GDPR in connection with processing. In accordance with your right to information, you have the right to receive a copy of your personal data subject to the requirements of Art. 15 para. 3 GDPR. The restrictions of the right to information under Art. 15 para. 4 GDPR and section 34 Federal Data Protection Act (Bundesdatenschutzgesetz, hereinafter “BDSG”) must be observed.
Right to rectification: In accordance with Art. 16 GDPR, you may require rectification of your personal data stored by KYB if they are inaccurate or their completion if they are incomplete.
Right to erasure: In accordance with Art. 17 GDPR, you may require the erasure of your personal data stored at KYB, unless processing is necessary to fulfil a legal obligation or to assert, exercise or defend legal claims. The further restrictions under Art. 17 para. 3 GDPR and section 35 BDSG must be observed.
Right to restriction of processing: Subject to the requirements of Art. 18 GDPR, you have the right to restrict processing of your personal data. In this event, your personal data – apart from their storage – may only be processed with your consent or subject to the requirements of Art. 18 para. 2 GDPR.
Right to data portability: Subject to the requirements of Art. 20 GDPR, you have the right to receive your personal data which you have provided to KYB in a structured, common and machine-readable format or, as far as technically feasible, to request transfer directly to another controller.
Revocation of consent granted: In accordance with Art. 7 para. 3 GDPR, you are entitled to withdraw at any time your consent after once having given it to KYB. The consequence of this is that KYB may not continue the data processing, which was based on this consent, in the future.
If you would like to exercise the rights listed above, please contact the Data Protection Officer of KYB, please refer to contact details in Article 2.
If your personal data are processed on the basis of legitimate interests in accordance with Art. 6 para. 1 s. 1 lit. f GDPR or on grounds of public interest in accordance with Art. 6 para. 1 s. 1 lit. e GDPR, you have the right, in accordance with Art. 21 GDPR, to lodge an objection to the processing of your personal data at any time, if there are grounds for the objection arising from your particular situation.
In the event of a justified objection to the processing of your personal data under Art. 6 para. 1 s. 1 lit. e or f GDPR, we must refrain from any further processing of your data unless it is necessary on grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. The right to objection is subject to the restrictions of section 36 BDSG.
If your personal data are processed for direct marketing purposes, you have the right to object at any time without restriction to the processing of your data for such direct marketing purposes. The statement of reasons is not required. This also applies to profiling that it is related to such direct marketing. In the event of your objection to the processing of your personal data for direct marketing purposes, we must refrain from any further processing of your data for such purposes.
The objection can be addressed form-free to the Data Protection Officer of KYB, please refer to contact details in Article 2.
If you are of the opinion that the processing of your personal data by us infringes data-protection regulations, you also have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR.
To this purpose, you can normally contact the supervisory authority at your usual place of residence or place of work or at the place of the suspected infringement.