1. Name and address of the controller

The controller responsible for processing personal data as defined by the EU General Data Protection Regulation (GDPR) is:

Herbert Hänchen GmbH
Brunnwiesenstr. 3
73760 Ostfildern
+49 711 44139-0

2. Name and address of the data protection officer

For information about the processing of your personal data, their modification or erasure, or any objections, please contact our data protection officer:

Herbert Hänchen GmbH
Lars-Holger Krause
Brunnwiesenstr. 3
73760 Ostfildern
+49 171-1040792

3. Categories of personal data

Personal data means any information about personal or factual circumstances relating to an identified or identifiable natural person (data subject). We only collect categories of data we need to contact you and handle your request. This includes information such as your name, address, email address, telephone number and the department.

Your personal data are always processed in compliance with the GDPR and in accordance with the country-specific data protection regulations applicable to Herbert Hänchen GmbH.

4. Purpose and legal basis for processing personal data

Personal data are collected and processed pursuant to Art. 6 GDPR when interest is shown in an employment relationship or when initiating a business process, e.g. through your interest in our products and services or our interest in the products and services of the company you represent. Should you or a third party provide us with your address, email address or telephone number, we will communicate with you through one or more of these methods of communication, provided you have not objected to this.

If no legal basis exists for this kind of processing, we generally obtain your consent as the data subject pursuant to Art. 6 Para. 1(a) GDPR.

If it is necessary to process personal data for the performance of a contract or in order to take steps prior to entering into a contract, processing is based on Art. 6 Para. 1(b) GDPR.

Where our company is subject to a legal obligation requiring the processing of personal data, such as to meet tax obligations, this processing is based on Art. 6 Para. 1(c) GDPR.

To protect the vital interests of the data subject or of another natural person, it may be necessary to process personal data pursuant to Art. 6 Para 1(d) GDPR. For example, this would be the case if you, as a visitor to our business, were to become injured and your data then had to be disclosed to a doctor, hospital or other third party.

We process personal data for direct advertising purposes for our products and services on the basis of Art. 6 Para. 1(f) GDPR if we have a legitimate interest in doing so and if this interest is not overridden by the interests or fundamental rights and freedoms of you as the data subject. In doing so, we rely on recital Art. 47 GDPR, taking into account Sec. 7 Para. 3 of the German Act Against Unfair Practices (Gesetz gegen den unlauteren Wettbewerb [UWG]), which, for example, permits us to contact customers without consent if the communication relates to similar goods or services from Herbert Hänchen GmbH and the customer has not objected to being contacted in this way.

5. Legitimate interests in the processing of personal data

If the processing of your personal data is based on Art. 6 Para. 1(f) GDPR, our legitimate interest is the performance of our business operations to benefit the welfare of all of our employees and shareholders.

6. Requirement to provide personal data

It is generally possible to use the Herbert Hänchen GmbH website without providing personal data.

Due to statutory provisions (e.g. tax regulations) or contractual provisions (e.g. information on the contracting party), it may be necessary to provide your personal data. As the data subject, you may be required to provide Herbert Hänchen GmbH with personal data if we conclude a contract. Failure to provide this personal data would result in us being unable to conclude the contract with you as the data subject.

In individual cases, our data protection officer may provide you with clarification as to whether the provision of your data is required by law or under a contract or whether it is necessary in order to conclude a contract, whether you are obligated to provide such data and what the consequences of failing to provide such data would be.

7. Use of cookies

Cookies are text files that are placed on your hard drive through an internet browser. However, these cannot be used to read data or files on your computer.

Using cookies allows Herbert Hänchen GmbH to recognise internet browsers and analyse the use of its websites so we can design them to be more user friendly. No data collected in this way are attributed to individual users, and these data are only used for statistical purposes.

Most browsers accept cookies automatically. You can prevent cookies from being set at any time by adjusting your browser’s settings. You can also permanently object to cookies being set. In addition, existing cookies can be erased. If you disable cookies, you may not be able to enjoy the full functionality of our website.

If you give your consent via the cookie banner, we use the following cookies:
Google Analytics _ga Cookie - runtime 2 years
Google Analytics _gat Cookie - runtime 1 minute

Youtube Cookie - runtime 30 days

8. Collection of general data and information

Every time a data subject visits the Herbert Hänchen GmbH website, we collect a range of general data and information that are stored in the server log files. The following data may be collected: the browser types and versions used, the operating system used, the website that directed you to us, the sub-pages you navigate to, the date and time of access to the website, your IP address and internet service provider and other similar data and information that help us defend against any danger in the event of an attack on our systems.

This information is necessary in order to provide the content of our website correctly. This data is not analysed for statistical purposes; the individual user remains anonymous. When data is passed on to external service providers, technical and organisational measures are taken to ensure that data protection regulations are observed.

9. How to get in touch with us; contact form

If you contact us by email, using the contact form on the website or the Hänchen configurator, HäKo https://haeko.haenchen.de, we will store the information you provide, including the contact details you provide, to process your request and in the event of follow-up questions. The personal data transmitted in the process depend on the input mask used or your email signature.

If you use one of our contact forms, your information is encrypted during electronic transmission. To protect your data, we use a secure online transmission procedure, known as secure socket layer (SSL) transmission.

10. Registering for the HäKo configurator

Users of the Hänchen configurator, HäKo https://haeko.haenchen.de, have the option to contact our company directly. The personal data transmitted in the process depend on the input mask used.

a)     Requests without setting up a customer account
For price and CAD requests submitted through HäKo, mandatory fields are used to request and store all the data needed to carry out and process the request.

b)    Customer account/registration
You have the option of creating a HäKo customer account. To do so, in addition to entering your email address, you can choose a password. Both allow you to store configurations and notes for a subsequent visit and to generate price and CAD requests. Hänchen stores the data you enter to set up a customer account to process any requests. In addition, the date and time of registration and the last log-in are stored. These data are stored in the knowledge that this is the only way to prevent our services from being abused. Registered persons are free to modify the personal data they entered when registering at any time or to erase their Hänchen customer account and its content. To completely erase the personal data provided in the contact form, please contact our data protection officer.

c)     Security
We encrypt your password and the information stored in your customer account according to the current state of the art. Herbert Hänchen GmbH assumes no responsibility for damages to the respective Hänchen customer account resulting from the account holder misusing their log-in data, in particular their password.

d)    Access permissions
Herbert Hänchen GmbH is entitled to revoke access permissions without prior notification. This may occur, for example, if:

  • the information included in the contact form is untrue;
  • the user misuses the information provided, or impairs its functionality;
  • there have been any violations of the duty of care when handling the log-in details provided.

11. Direct advertising and tracking via email

As a Hänchen customer, you may receive emails from us at irregular intervals. These emails will inform you of current news and information relating to products you have purchased from us. You may object to the use of your data for direct advertising purposes at any time with future effect. To do so, please use the link included in each email or contact our data protection officer.

The emails we generate for direct advertising purposes contain what are known as web beacons. If you have consented to our tracking when registering for the newsletter, Herbert Hänchen GmbH can use these tracking pixels to recognise whether and when an email was opened by a data subject and which links in the email were called up by the data subject. We store and analyse the data collected in this way in order to better adapt the content of future direct advertising to the interests of our target group. You are entitled to object to this kind of tracking at any time. To do so, please contact our data protection officer.

12. Recipients and transmission of personal data

Herbert Hänchen GmbH employees use your personal data to process your requests and provide you with the information you requested. This sometimes involves the need to forward the information you provided to one of our subsidiaries or sales partners if they are responsible for the request you made. Data are only transmitted to third countries if the data subject is operating on behalf of a company based outside of the European Union (EU) and transmission is necessary on the basis of pre-contractual measures pursuant to Art. 49 Para. 1(b) GDPR.

As a matter of principle, your data are never transmitted outside of the Hänchen Group unless we are legally required to do so or have obtained your express prior consent to forward your data. External service providers and partner companies only receive your data where this is necessary to execute a business relationship. In these cases, however, the scope of the data transmitted is limited to the minimum required.

13. Length of time personal data are stored

If the purpose of storage no longer applies or if a legally required retention period expires, personal data are routinely blocked or erased. Please note that, for every erasure, data are initially only blocked and are only ultimately erased after some delay for technical reasons.

14. Data protection for applications and application processes

Incoming applications received via email or through the application form on our website are stored by Herbert Hänchen GmbH for the application process in an electronic application system.

The separate privacy notice pertaining to the application process at Herbert Hänchen GmbH is available here:
Privacy notice for the Application Process

15. Rights of the data subject

You have sovereignty over the data we have stored about you and may avail yourself of the rights listed below at any time. To do so, please contact our data protection officer as listed in this privacy notice.

a)     Right of access pursuant to Art. 15 GDPR
You have the right to obtain information as to whether or not your personal data are being processed by us and, where that is the case, information about the concerned, and information about the purposes of the processing, who views your data and where we have obtained your data from.

b)    Right to rectification pursuant to Art. 16 GDPR
It is important to us to keep your data up to date. As such, you are entitled to request your data be rectified at any time.

c)     Right to erasure pursuant to Art. 17 GDPR and Art. 19 GDPR
If you wish for your personal data to be erased, we will do so immediately, provided these data are not required to meet a legal obligation. Please note that, for every erasure, data are initially only blocked and are only ultimately erased after some delay for technical reasons. If you no longer wish for us to contact you, we recommend only blocking the data (name and company). This is the only way we can guarantee that you will not be listed as a “new contact” in our system.

In the event that your data have been disclosed to other recipients by Herbert Hänchen GmbH and we are obligated to erase your personal data pursuant to Art. 17 Para. 1 GDPR, we will take appropriate measures to ensure your data are also erased there.

d)    Right to restriction of processing pursuant to Art. 18 GDPR
In addition, you have the right to request the restriction of processing or use of your data for a limited or unlimited period of time pursuant to Art. 18 GDPR.

e)     Right to data portability pursuant to Art. 20 GDPR
You may avail yourself of the right to request the personal data we have electronically stored about you in this form in order to transmit these data to another controller.

f)   Right to object pursuant to Art. 21 GDPR
Where we use your data for direct advertising, marketing and opinion research, you generally have the right to object to the processing of your data for the purposes of such use.

g)   Automated individual decision-making, including profiling, pursuant to Art. 22 GDPR
Herbert Hänchen GmbH does not engage in automated decision-making or profiling.

h)    Right to withdraw consent relating to data protection pursuant to Art. 7 Para. 3 GDPR
You have the right to withdraw your consent to the processing of your personal data at any time. This does not affect the lawfulness of processing conducted before your consent was revoked.

i)    Right to lodge a complaint with a supervisory authority
If you believe your personal data are being processed in violation of the law, you have the right to notify a supervisory authority of this pursuant to Art. 77 GDPR. The state body for data protection and freedom of information for our jurisdiction is Baden-Württemberg:

Königstrasse 10 a                        P.O. box 10 29 32
70173 Stuttgart, Germany           70025 Stuttgart, Germany
+49 711 615541-0

16. Use of Google Analytics

This website uses Google Analytics, this web service does not use any personal data. No data is read or stored on the website visitor's end device. The IP address of the website visitor is anonymised. It is not possible to recognise the website visitor beyond the website. Cookies are not set; any existing cookies are transmitted as a technical necessity, but are also not used. Web analysis enables the website operator to record and analyse the use of this website by website visitors. The website operator receives various usage data, such as usage time, page views, length of visit, operating systems used or screen resolution used.

The anonymised analysis data is transferred via this server to the web analysis service Google Analytics without using personal data of the website visitor and is usually stored there on a Google server in the USA. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. It is not possible to create a profile or link to other sources with this anonymised analysis data. You can find more information on how Google Analytics handles user data in Google's privacy policy.

17. Use of Google AdWords

In order to raise awareness of our services, we run Google AdWords advertisements in Google’s search engine results (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland) to provide personalised, interest- and location-based online advertising.

Herbert Hänchen GmbH generally does not use any conversion cookies, so disabling this type of cookies is not necessary for our website.

In general, you can disable cookies for conversion tracking by adjusting your browser’s settings to block cookies from the domain “googleadservices.com”. Furthermore, you have the option to object to Google's interest-based advertising. To do so, visit the link provided by Google on advertising settings in the browser you are using and adjust your settings as desired.

More information on Google’s privacy notice is available here.

18. Use of YouTube

Our website uses iFrames, which are shown on YouTube (YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA), a website run by Google. If you visit one of our websites that features a YouTube iFrame and have consented to the associated cookie, a connection to the YouTube servers is established, from which a representation of the corresponding YouTube components is automatically downloaded. We have enabled “enhanced protected mode” for all of our videos, which means no information about your visit to our website is transmitted to YouTube unless you watch the video.

YouTube is then only able to attribute the information about which of our web pages you are visiting (where these pages contain a YouTube video) to you personally if you are simultaneously logged in to YouTube when you play the video. You can prevent this by logging out of your YouTube account.

The YouTube logo embedded in the sitemap is not a plugin. This means that YouTube does not receive any information about which of our web pages you have visited. Only when this logo link is clicked will YouTube receive information about which of our sub-pages you have accessed YouTube from.

YouTube LLC as a subsidiary of Google LLC with headquarters at 1600 Amphitheatre Parkway, Mountain View, California, USA, is certified in accordance with the EU-US-Privacy-Shield (find it under search term: "Google"). The Privacy Shield is an agreement between the European Union (EU) and the USA to ensure observation of European data protection standards in the USA.

More information on Google’s privacy notice is available here.

19. Use of Facebook

The Facebook logo embedded in the sitemap is not a plugin or beacon. This means that Facebook does not receive any information about which of our web pages you have visited. Only when this logo link is clicked will Facebook receive information about which of our sub-pages you have accessed Facebook from.

20. Use of Xing

The Xing logo embedded in the sitemap is not a plugin. This means that Xing does not receive any information about which of our web pages you have visited. Only when this logo link is clicked will Xing receive information about which of our sub-pages you have accessed Xing from.

21. Use of Linkedin

The Linkedin logo embedded in the sitemap is not a plugin. This means that Linkedin does not receive any information about which of our web pages you have visited. Only when this logo link is clicked will Linkedin receive information about which of our sub-pages you have accessed Linkedin from.

22. Photo and film recordings at events

During our events (such as trade fairs, company celebrations, etc.), photos and films may be taken so that they can subsequently be used for presentation, in particular on our websites and our social media channels (LinkedIn, Facebook, Instagram, etc.) and for printed advertising material for the purpose of advertising our own services.

We will inform you (e.g. via a poster) if photographs and film recordings are made and you may be depicted as a result. By participating, you agree to the publication of photographs and film recordings of the event to the extent specified, on which you may also be depicted.

If you do not agree to this, please inform the person taking the photograph or one of our employees. You have the right to revoke your declaration of consent at any time. However, even if consent is withdrawn, the photographs may still be published and displayed for reporting purposes in accordance with § 23 Para. 1 No. 3 of the German Art Copyright Act (KUG) if the event itself is recognisably in the foreground of the photographs.

We would like to point out that information on the Internet is accessible worldwide, can be found using search engines and linked to other information, from which personality profiles can be created under certain circumstances. Information posted on the Internet, including photos, can be easily copied and redistributed, and there are specialised archiving services whose aim is to permanently document the status of certain websites on certain dates. This can mean that information published on the Internet can still be found elsewhere even after it has been deleted from the original site. 

We would also like to point out that, according to the information currently known, photos and data on Facebook cannot be deleted at all, but are only no longer shown publicly. There is currently insufficient information about the internal use of photos and data by Facebook - for example to create personality profiles.

23. Security notice

We implement technical and organisational security measures to protect the data we manage about you against manipulation, loss, destruction and access by unauthorised persons. We continually work to improve our security measures in line with technological developments. The data you provide to us through a contact form are transmitted online in an encrypted form using standard transmission protocols.

We have a firewall (security software) in place to protect internal information from the internet. In addition, only employees who need the information to complete a specific task receive access to personal information. These employees are trained on security and data protection and handle your data confidentially.

You should never disclose your password for a customer account in the HäKo Hänchen configurator to third parties, and you should regularly change it.

If you wish to contact us via email, we would point out that we cannot guarantee the confidentiality of the information transmitted. The content of emails may be viewed by third parties.


Date June 17, 2024