Data Protection


General information

Thank you for visiting our website and for your interest in our company and our products. The protection of your personal data is very important to HAHN Plastics (North America) Ltd. We process personal data that is collected when you visit our online offers confidentially and only in accordance with the statutory provisions. It is important for us to inform you about which personal data is collected, how it is used and what options you have in this regard.

1.    Responsible Person

The data controller is HAHN Plastics (North America) Ltd., Waterloo ON N2V 1N3, Canada. Exceptions are explained in this data protection notice. If you have any questions about data protection, you can contact our data protection officer at info@hahnplastics.com.

2.    Collection, processing and use of personal data

2.1    Categories of data processed

Communication data (e.g. name, telephone number, e-mail address, personal address, IP address) and / or usage data (e.g. session duration, browser and operating system) with and without personal reference can be processed.


2.2    Principles

Personal data is all information that relates to an identified or identifiable natural person, e.g. names, addresses, telephone numbers or e-mail addresses that express the identity of a person.

We collect, process and use personal data (including IP addresses) only if there is a legal basis for this or if you e.g. have given your consent when contacting us.


2.3    Processing purposes and legal bases

We and service providers commissioned by us process your data for the following processing purposes:

  • Provision of this online offer
    Legal basis: Overriding legitimate interest on our part in direct marketing as long as this is done in accordance with data protection and competition law requirements.
    Recipient: technical service providers (e.g. hosting)

  • Answering user inquiries using a contact form
    Legal basis: Overriding legitimate interest on our part in marketing and in the improvement of our products and services, as long as this is in accordance with data protection and competition law requirements or the fulfilment of the contract or consent.
    Recipient: technical service providers and customer service

  • Identification of malfunctions and security reasons
    Legal basis: Fulfilment of our legal obligations in the area of data security and an overriding legitimate interest in the elimination of disruptions and the security of our offers.
    Recipient: technical service providers

  • In-house and third-party advertising as well as market research and range measurement to the extent permitted by law or on the basis of consent
    Legal basis: Consent or overriding legitimate interest on our part in direct marketing, as long as this is in accordance with data protection and competition law requirements.
    Recipient: Marketing service provider

  • Protecting and defending our rights
    Legal basis: Legitimate interest on our part in asserting and defending our rights.
    Recipient: Legal institutions

2.4    Transfer of data

  • Transfer of data to other responsible parties
    Your personal data will only be transmitted by us to other responsible parties insofar as this is necessary to fulfil the contract (e.g. delivery with a shipping and logistics company), we or the third party have a legal requirement to pass it on (e.g. Customs clearance) or you have given your consent (e.g. forwarding of the data to subsidiaries or dealers of HAHN Plastics (North America) Ltd). Details on the legal bases and the recipients or the categories of recipients can be found in the section "Processing purposes and legal bases" (see No. 2.3).

    In addition, data can be transmitted to other responsible parties, insofar as we are obliged to do so due to statutory provisions or an enforceable official or judicial order.

  • Service provider (general)
    We commission external service providers who do not use the data themselves, with tasks such as marketing services, programming and data hosting under contract processing agreements. We have carefully selected these service providers and regularly monitor them, in particular their careful handling and protection of the data stored with them. All service providers are obliged by us to maintain confidentiality and to comply with legal requirements. Other companies in the HAHN Group can also be service providers.

  • Duration of storage and retention periods
    When ordering or registering on our site, as appropriate, you may be asked to enter your name, email address, mailing address, phone number or other details to help you with your experience. We collect information from you when you subscribe to a newsletter, fill out a form or enter information on our site. We may use the information we collect from you when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways:
  • To improve our website in order to better serve you
  • To allow us to better service you in responding to your customer service requests

  • Protecting visitor information
    We do not use vulnerability scanning and/or scanning to PCI standards. We use regular Malware Scanning.

    Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology. We implement a variety of security measures when a user enters, submits, or accesses their information to maintain the safety of your personal information. All transactions are processed through a gateway provider and are not stored or processed on our servers.

  • California Online Privacy Protection Act
    CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law's reach stretches well beyond California to require a person or company in the United States (and conceivably the world) that operates websites collecting personally identifiable information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals with whom it is being shared, and to comply with this policy. - See more at: http://consumercal.org/california-online-privacy-

  • Protecting visitor information
    According to CalOPPA we agree to the following: Users can visit our site anonymously. Once this privacy policy is created, we will add a link to it on our home page or as a minimum on the first significant page after entering our website.

2.5    Log-Files

Each time you use the Internet, your Internet browser automatically transmits certain information and saves it in so-called log files. We store the log files for a period of 14 days to identify faults and for security reasons (e.g. to investigate attempted attacks) and then delete them. Log files, the further storage of which is necessary for evidence purposes, are excluded from deletion until the respective incident has been finally clarified and can be passed on to investigating authorities in individual cases. Log files are also used for analysis purposes (without or without a full IP address) subject to the requirements of Section 2.3 "In-house and third-party advertising as well as market research and reach measurement to the extent permitted by law or on the basis of consent".

In particular, the following information is stored in the log files:

  • IP address (Internet protocol address) of the device from which the online offer is accessed;
  • Internet address of the website from which the online offer was accessed (so-called origin or referrer URL);
  • Name of the requested URL of our website (request URL);
  • Date of retrieval;
  • Amount of data transferred;
  • Information on the Internet browser used (user agent) including installed add-ons (e.g. for the Flash Player).


2.6    Age Requirement

This online offer is aimed at adults. The resulting age limit is based on the regulations of the corresponding country or location from which our online offer is accessed.


3.    Use of cookies and similar technologies

Cookies and similar technologies can be used as part of the provision of our online offer. Cookies are small text files that can be saved on your device when you visit an online offer. Tracking is possible using various technologies.


3.1    Cookie Categories

Required Cookies
Required cookies are necessary so that you can navigate through the website and use essential functions

Cookie
Purpose
Validity period
cookie-preference
Save the selected cookie settings of a user.
1 month
csrf [several]
Protection against CSRF attacks on the identity of a user.
Until the browser is closed. May vary depending on browser settings.
session-
Allows you to save information about the current session e.g. the status of the shopping cart or the wish list.
Until the browser is closed. May vary depending on browser settings.
Timezone
Saving a user's time zone.
1 month

Analytical cookies

Analytical cookies help us to better understand your user behaviour. For example, we use analytical cookies to analyse user behaviour on the basis of anonymous and pseudonymous information. Direct conclusions about a person are not possible.

Cookie
Purpose
Validity period
_ga
Contains a randomly generated user ID. Using this ID, Google Analytics can recognize returning users on this website and merge the data from previous visits.
2 years
_gid
Contains a randomly generated user ID. Using this ID, Google Analytics can recognize returning users on this website and merge the data from previous visits.
24 hours
_dc_gtm_xxx
Certain data is only sent to Google Analytics a maximum of once per minute. The cookie has a lifespan of one minute. As long as it is set, certain data transfers are prevented.1 minute
IDE
Contains a randomly generated user ID. Using this ID, Google can recognize the user across different websites across domains and display personalized advertising.1 year

Technologies used in connection with analytical cookies

Google Analytics
If you have given your consent, Google Analytics, a web analysis service provided by Google LLC, is used on this website. The responsible service provider in the EU is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

Scope of processing
Google Analytics uses cookies that enable your use of our website to be analysed. The information collected by the cookies about your use of this website is usually transmitted to a Google server in the USA and stored there.

We use the user ID function. With the help of the user ID, we can assign a unique, permanent ID to one or more sessions (and the activities within these sessions) and analyse user behaviour across all devices.

We use the anonymizeIP function (so-called IP masking): Due to the activation of IP anonymization on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. The full IP address is only transmitted to a Google server in the USA and shortened there in exceptional cases. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

During your visit to the website the following data may be collected:

  • the pages you have visited, your "click path"
  • Achievement of "website goals" (so-called conversions, e.g. newsletter registrations, downloads)
  • Your user behaviour (e.g. clicks, length of stay, bounce rates)
  • Your approximate location (region)
  • your IP address (in abbreviated form)
  • technical information about your browser and the end devices you use (e.g. language setting, screen resolution)
  • the referrer URL (via which website / which advertising material you came to this website)
Purposes of processing
On behalf of the website operator, Google will use this information to evaluate your use of the website and to compile reports on website activity. The reports provided by Google Analytics are used to analyse the performance of our website and the success of our marketing campaigns.

Recipient
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland as the processor. We have concluded an order processing contract with Google for this purpose. Google LLC, based in California, USA, and possibly US authorities can access the data stored by Google.

Transfer to third countries
A transmission of data to the USA cannot be ruled out.

Storage period
The data sent by us and linked to cookies is automatically deleted after 14 months. The deletion of data whose retention period has expired takes place automatically once a month.

You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by clicking
a. Do not give your consent to the setting of analytical cookies or
b. Download and install the browser add-on to deactivate Google Analytics here.

You can also prevent the storage of cookies by setting your browser software accordingly. However, if you configure your browser so that all cookies are rejected, functionality on this and other websites may be restricted.

Legal basis and possibility of withdrawal
The legal basis for this data processing is your consent in accordance with Article 6 Paragraph 1 Sentence 1 Letter a GDPR. You can revoke your consent at any time with effect for the future by changing the cookie settings via this link and change your selection there.

For more information on the terms of use of Google Analytics and data protection at Google, see 
https://marketingplatform.google.com/about/analytics/terms/de/ and https://policies.google.com/?hl=de.

Marketing cookies
Marketing cookies are used to show you personalised and relevant advertising content. Direct conclusions about a person are not possible. Marketing and retargeting cookies help us to display possible relevant advertising content for you. By suppressing marketing cookies, you will continue to see the same number of advertisements, but they may be less relevant to you.

Cookie
Purpose
Validity period
test_cookie
Is set as a test to check whether the browser allows cookies to be set. Does not contain any identification features.
15 minutes
IDE
Contains a randomly generated user ID. Using this ID, Google can recognize the user across different websites across domains and display personalized advertising.
1 year

Technologies used in connection with marketing cookies

Google Ads
This website uses the remarketing function of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

Scope of processing
This function is used to present interest-based advertisements to visitors to the website as part of the Google advertising network. The website visitor's browser saves so-called “cookies”, text files that are saved on your computer and enable the visitor to be recognized when they visit websites that belong to the Google advertising network. On these pages, the visitor can then be presented with advertisements that relate to content that the visitor has previously accessed on websites that use Google's remarketing function. According to its own information, Google does not collect any personal data during this process.

Recipient
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland as the processor. We have concluded an order processing contract with Google for this purpose. Google LLC, based in California, USA, and possibly US authorities can access the data stored by Google.

Legal basis and possibility of withdrawal
The legal basis for this data processing is your consent in accordance with Article 6 Paragraph 1 Sentence 1 Letter a GDPR. You can revoke your consent at any time with effect for the future by changing the cookie settings via this link and change your selection there

Further information can be found at: https://adssettings.google.com/authenticated.


3.2    Management of cookies

  • Management of your settings regarding technically unnecessary cookies and tracking mechanisms
    When you visit our website, you will be asked in a cookie layer for which categories of cookies you give us your consent. The cookie settings you have chosen are saved for a month before you are automatically prompted to set your cookie preferences when you visit our website again. You can use the link in our privacy policy to call up the cookie layer again at any time and edit or revoke your settings with effect for the future or give us your consent at a later point in time.

3.3    Google Maps

This website uses the Google Maps map service via an API. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

When you click on the integrated Google Maps map, personal data (in this case the IP address) are forwarded to Google. This information is usually transmitted to a Google LLC server in the USA and stored there. The provider of this site has no influence on this data transfer.

The use of Google Maps is in the interest of an appealing presentation of our online offers and to make it easy to find the places we have indicated on the website. This represents an overriding legitimate interest on our part within the meaning of Art. 6 Para. 1 lit. f GDPR.

You can find more information on handling user data in Google's privacy policy: https://www.google.de/intl/de/policies/privacy/.


3.4    Google Web Fonts

We use Google Fonts on our website to display external fonts. This is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as “Google”. In order to enable the display of certain fonts on our website, a connection to Google servers in the USA is established when you visit our website. The fonts used are loaded into your browser cache when you call up this page so that the content (text and characters) is displayed correctly. As part of the connection between your browser and Google, Google is informed that your IP address has accessed our website. Data that are transmitted in connection with the page view are sent to specific domains such as fonts.googleapis.com or fonts.gstatic.com. They are not associated with data that may be collected or used in connection with the parallel use of authenticated Google services such as Gmail. You can set your browser so that the fonts are not loaded from the Google servers, for example by installing add-ons such as NoScript or Ghostery for Firefox.

The legal basis is Art. 6 Para. 1 lit. f) GDPR. The use of Google Fonts takes place in the interest of a uniform and appealing presentation of our online offers, the maintenance-free and efficient use of fonts and compliance with the licensing provisions for their use.

You can find more information about Google Fonts at https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/


3.5    YouTube

This online offer uses the YouTube video platform operated by YouTube, LLC, 901 Cherry Ave. San Bruno, CA 94066, USA (“YouTube”). YouTube is a platform that enables the playback of audio and video files.

If you call up a corresponding page of our offer, the embedded YouTube player connects to YouTube so that the video or audio file can be transmitted and played. In doing so, data is also transferred to YouTube as the controller. We are not responsible for the processing of this data by YouTube.

For more information on the scope and purpose of the data collected, on further processing and use of the data by YouTube, on your rights and the data protection options you can select, see the YouTube data protection notice at https://policies.google.com/privacy?hl=de.


3.6    Newsletter CleverReach

We use CleverReach to send newsletters. The provider is CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede. CleverReach is a service with which the newsletter dispatch can be organized and analysed.

If you would like to receive the newsletter offered on the website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. The processing of the data entered in the newsletter registration form takes place exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke your consent to the storage of the data, the e-mail address and their use for sending the newsletter at any time using the unsubscribe link in the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation. The data you enter for the purpose of receiving the newsletter (e.g. email address) will be stored on CleverReach's servers in Germany or Ireland until you unsubscribe from the newsletter. After unsubscribing from our newsletter, your data will be deleted from both our servers and CleverReach's servers. You can find more information in the CleverReach data protection provisions at: https://www.cleverreach.com/de/datenschutz/.

CleverReach enables us to analyse the behaviour of newsletter recipients. Here u. a. It analyses how many recipients have opened a newsletter or how often a link in the newsletter was clicked. Further information on data analysis by CleverReach is available at: https://www.cleverreach.com/de/funktionen/reporting-und-tracking/.

If you do not want an analysis by CleverReach, you must unsubscribe from our newsletter. We provide a link for this in every newsletter.


4.    External Links

Our online offer may contain links to third-party websites that are not affiliated with us. After clicking the link, we no longer have any influence on the collection, processing and use of any personal data transferred to the third party when the link is clicked (such as the IP address or the URL of the page on which the link is located), since the behaviour of third parties is naturally beyond our control. We are not responsible for the processing of such personal data by third parties.


5.    Safety

Our employees and the service companies commissioned by us are bound to secrecy and compliance with the provisions of the applicable data protection laws. We take all necessary technical and organisational measures to ensure an appropriate level of protection and to protect your data managed by us, in particular from the risks of unintentional or unlawful destruction, manipulation, loss, alteration or unauthorised disclosure or unauthorised access. Our security measures are continuously improved in line with technological developments.


6.    User rights

To assert your rights, please use the information in the "Contact" section (see No. 12). Please make sure that we can clearly identify you.


6.1    Right to information and access

You have the right to receive information from us about the processing of your data. To do this, you can assert a right to information in relation to the personal data that we process about you.


6.2    Right to rectification and erasure

You can ask us to correct incorrect data. As long as the legal requirements are met, you can request the completion or deletion of your data. This does not apply to data that are required for billing and accounting purposes or are subject to statutory retention requirements. If access to such data is not required, their processing will be restricted (see below).


6.3    Restriction of processing

If the legal requirements are met, you can request that we restrict the processing of your data.


6.4    Data portability

As long as the legal requirements are met, you can request that the data you have made available to us be transmitted in a structured, common and machine-readable format or - if technically feasible - that the data be transmitted to a third party.

6.5    Right to object

  • Objection to direct marketing
    You can object to the processing of your personal data for advertising purposes at any time ("advertising objection"). Please note that, for organizational reasons, there may be an overlap between your objection and the use of your data in the context of an ongoing campaign.
  • Objection to data processing on the legal basis “legitimate interest “
    You have the right to object to data processing by us at any time, provided this is based on the legal basis of "legitimate interest". We will then stop processing your data, unless we can - in accordance with the legal requirements - prove compelling reasons worthy of protection for further processing, which outweigh your rights.

6.6    Revocation of Consent

If you have given us your consent to process your data, you can revoke this at any time with effect for the future. This does not affect the legality of processing your data until you withdraw your consent.


6.7    Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. You can contact the data protection supervisory authority that is responsible for your place of residence or your state or the data protection supervisory authority responsible for us.

Complaints body in Canada
Office of the Privacy Commissioner of Canada
https://www.priv.gc.ca/en/report-a-concern/file-a-formal-privacy-complaint/file-a-complaint-about-a-business/

Office of the Privacy Commissioner of Canada

30, Victoria Street
Gatineau, Quebec

K1A 1H3

Toll-free: 1-800-282-1376

Phone: (819) 994-5444

TTY: (819) 994-6591

Complaints body in USA
U.S. Department of State – Bureau of Administration Privacy Office

Office of Global Information Services

Privacy Office – A/GIS/PRV

State Annex 9

U.S. Department of State

Washington, DC 20006

Email: privacy@state.gov


7.    Change of data protection notice

We reserve the right to change our security and data protection measures. In these cases, we will also adapt our information on data protection accordingly. Therefore, please note the current version of our data protection notice.


8.    Contact

If you would like to get in contact with us, you can reach us at the address given in the “Responsible” section (see No. 1).

For suggestions and complaints regarding the processing of your personal data, we recommend that you contact our data protection officer: info@hahnplastics.com.


Data protection information as of 01/01/2021