Data protection

1.  General aspects data protection

Welcome to the SMR Automotive Mirrors Stuttgart GmbH website. We appreciate your interest in our company. Protection of the personal data you entrust to us is a priority for us, and we want you to feel safe and secure when you visit our website or use our online offers.

It is important to us that you are fully informed about the personal data that we collect when you use our online offers and services, and are familiar with how we use them.

Intended use of data processing

Wherever SMR processes personal data, such processing is carried out for the purposes defined in this data privacy statement.

 

2.  Processing of personal data

Scope and purpose of the processing of personal data

We collect and use personal data only to provide you a functional website, our content and services. The collection and use of personal data is regularly only carried out with your consent. An exception applies in those cases in which prior consent cannot be obtained for actual reasons and the processing of the data is permitted by statutory provisions.

Legal basis for the processing of personal data

So far as we obtain the consent of the data subject for the processing of personal data, Art. 6 (1) lit. a GDPR serves as the legal basis for the processing of personal data. Art. 6 (1) lit. b GDPR serves as the legal basis for the processing of personal data required for the performance of a contract to which the data subject is a party. This also applies to processing operations that are necessary for the implementation of pre-contractual measures. Insofar as the processing of personal data is necessary to fulfil a legal obligation to which our company is subject, Art. 6 (1) lit. c GDPR serves as the legal basis. In the event that vital interests of the data subject or another natural person necessitate the processing of personal data, Art. 6 (1) lit. d GDPR serves as the legal basis. If the processing is necessary to ensure a legitimate interest of our company or a third party and if the interests, fundamental rights and fundamental freedoms of the data subject do not outweigh the first-mentioned interest, Art. 6 (1) lit. f GDPR serves as the legal basis for the processing.

Visiting our website

We record and save your computer's IP address in order to send the contents of our website visited by you to your computer (e.g. texts, pictures, and files provided for downloading, etc.) (cf. Art. 6 (1) lit. b GDPR). We also process these data to identify and pursue any misuse. Legal basis in this case is Art. 6 (1) lit. f GDPR. In this context, our legitimate interest in data processing is to ensure the due functioning of our website and the business transacted via the website.

In as far as we process your data as described above for the purpose of providing the functions of our website, you are contractually bound to make these data available to us.

Server data

For technical reasons, in particular to ensure a secure and stable Internet presence, data are transmitted to us or to our web space provider via your Internet browser.

With these server log files, the type and version of your Internet browser, the operating system, the website from which you switched to our Internet presence (referrer URL), the website(s) of our Internet presence that you visit, the date and time of the respective access and the IP address of the Internet connection from which the use of our Internet presence is made will be collected.

This data will be stored temporarily, but not together with other data from you. This storage takes place on the legal basis of Art. 6 (1) lit. f GDPR. Our legitimate interest lies in the improvement, stability, functionality and security of our Internet presence.

The data will be deleted after seven days at the latest, as long as no further storage is necessary for evidence purposes. Otherwise, the data shall be completely or partially excluded from deletion until the final clarification of an incident.

Use of our contact form and e-mail contact

A contact form is available on our website, which can be used for electronic contacting. If a user takes this opportunity, the data entered in the input mask will be transmitted to us and stored. These data are:

  • Name
  • Mail address
  • Message/enquiry

At the time the message is sent, the following data will also be stored:

  • The IP address of the user
  • Date and time of registration

The data must be provided in order to process and respond to your enquiry - we cannot answer your enquiry or only to a limited extent without the required data. Your consent will be obtained for the processing of the data and also a reference will be made to this data protection declaration during the sending process. The legal basis for this processing is Art. 6 (1) lit. a), b) GDPR. Alternatively, you can contact us via the provided e-mail address. In this case, the personal data of the user transmitted with the e-mail will be stored. The data will not be passed on to third parties in this context. Your data will be deleted as long as your request has been answered finally and if there are no legal obligations to retain data to prevent deletion, e.g. in case of any subsequent processing of a contract.

 

3.  Transfer to third parties

Due to legal obligation

In certain cases, we are required by law to transfer data to a requesting public authority. Personal data will only be transferred to state institutions and public authorities within the framework of mandatory national legal provisions or if disclosure is necessary in the event of attacks on the network infrastructure for legal or criminal prosecution. The legal basis for processing is Art. 6 (1) lit. c GDPR or § 24 (1) No. 1 German Federal Data Protection Act

Data processing by data processor

Sometimes we use external service providers to process your data. In these cases, the information is transferred to third parties to enable further processing. External service providers are selected carefully and audited at regular intervals to ensure protection of your data privacy.

These service providers / processors are bound by instructions. Given this, they are subject to our requirements, which include processing of your data exclusively in line with our instructions and in compliance with the applicable Data Protection Act. In particular, they are contractually bound to treat your data with strict confidentiality, and are not permitted to process data for other purposes than the ones agreed.

Data transfer to the data processor is effected on the basis of Art. 28 (1) GDPR.

Intended data transfer to third countries

At present, data transfer to third countries is not planned. Otherwise we will establish the required legal conditions. In particular, you will be informed of the respective recipients or categories of recipients of the personal data in line with the legal requirements.

 

4.  Applications

For our application portal we use the software of the external service provider Prescreen International GmbH, Mariahilfer Straße 17, 1060 Vienna, Austria. We have a data processing agreement (Art. 28 GDPR) with this service provider to ensure that your personal data are processed exclusively in accordance with these data privacy statement. You can read the privacy policy of the service provider here https://prescreen.io/en/privacy-policy/.

 

5.  Security

SMR takes appropriate technical and organizational measures to protect any personal data you provide to SMR from accidental or intentional manipulation, loss, destruction, or access by unauthorized parties. This also applies to any external services purchased. We verify the effectiveness of our data protection measures and continuously improve them in line with technological development. Any personal data entered are encrypted during transfer using a secure encryption process.

 

6.  Cookies

For a user-friendly website experience and to tailor the operations of our website to your needs, some areas of our website may use cookies. A cookie is a small file that is stored locally on your computer when you visit a website. When you revisit the website on the same device, the cookie will indicate, for example, that you are a repeat visitor. Cookies also allow us to analyze the use of our website. They do not include any personal data and cannot identify you on third-party websites––including those of analytics providers.

We use the following types of cookies:

  • Essential/necessary cookies

These cookies are essential for the functioning of our website. This includes, for example, issue of anonymous session IDs to summarize multiple queries to a web server, or ensuring fault-free functioning of registrations and orders.

  • Functionality Cookies

These cookies help us to save your chosen settings or support other functions when you are navigating our website. They allow us, for example, to remember your preferred settings for your next visit or save your login data for certain areas of our Website.

  • Performance/statistics cookies

These cookies collect information about how you use our website (e.g. which Internet browser you use, how often you visit our website, which pages you open, or how long you stay on our website). These cookies do not store any information that enables visitors to be personally identified. The information collected with the help of these cookies is aggregated, and thus anonymous..

You can accept or decline cookies - including those used for website tracking - by selecting the appropriate settings for your browser. You can set your browser to notify you when you receive a new cookie, or to decline cookies altogether. However, if you choose to decline cookies you may not be able to use all the features of our website (e.g. for purchasing orders). Your browser also offers you the option to delete cookies (e.g. via the Clear Browsing History function). For further information, please refer to the user help function under Settings in your web browser.

 

7.  Website tracking

Google Analytics

This website uses Google Analytics for web analysis. This is a service provided by Google Ireland Limited ("Google"), a company incorporated and operated under the laws of Ireland (registration number: 368047) with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses "cookies". The information generated by the cookie about your use of our website (including your IP address) will be transmitted and stored by Google. It is not excluded that data processing may take place outside the scope of EU law. Google has joined the Privacy Shield so that Google guarantees compliance with EU data protection standards.

However, if you activate the IP anonymization on this website, your IP address will be shortened previously by Google within Member States of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases the full IP address is transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with further services related to website and internet use. The IP address transmitted by your browser within the scope of Google Analytics will not be aggregated with other Google data. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=en. You can prevent Google Analytics from collecting data by clicking on the following link. An opt-out cookie is set that prevents future collection of your data when you visit this website: https://tools.google.com/dlpage/gaoptout/eula.html?hl=en

For more information on terms of use and privacy, please visit http://www.google.com/analytics/terms/en.html or https://www.google.com/intl/en/privacy.html. Please note that on the website Google Analytics has been extended by the code "anonymizeIP" in order to guarantee an anonymous registration of IP addresses (so-called IP masking).

The legal basis for processing is Art. 6 (1) f GDPR, whereby our authorization arises from the fact that, on the one hand, SMR, Stuttgart, Germany, has an interest in evaluating the website data for purposes of website optimization and, on the other hand, a concerned person can reasonably foresee at the time when the personal data is collected and in view of the circumstances under which it is carried out (in particular the above-mentioned measures) that it will possibly be processed for this purpose.

Google Tag Manager

This website uses the Google Tag Manager. Google Tag Manager is a solution that allows SMR to manage website tags through a single interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not collect any personally identifiable information. The tool triggers other tags that may themselves collect data. Google Tag Manager does not access this data. If deactivation has been made at the domain or cookie level, it will persist for all tracking tags implemented with Google Tag Manager.

 

8.  Embedding of social plugins  

Our website uses buttons for the following social Networks

  • facebook, Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA
  • Xing, XING AG, Gänsemarkt 43, 20354 Hamburg, Deutschland
  • LinkedIn, LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA

The buttons show the logos of the individual social networks. However, the buttons are not standard social plugins, i.e. plugins provided by social networks, but links with button icons. These buttons are only activated by deliberate actions (clicking). As long as you do not click the buttons, no data will be transferred to the social networks. By clicking the buttons, you accept communication with the servers of the social network, thereby activating the buttons and establishing the link.

Once clicked, the button functions as a share plugin. The social network then obtains information about the site you have visited, which you can share with your friends and contacts. You need to be logged in to “share” information. If you are not logged in, you will be forwarded to the login page of the social network you have clicked, thereby leaving the pages of smr-automotive.com. If you are logged in, your “like” or recommendation of the article in question will be transmitted.

When you activate the button, the social networks will also receive the information that you accessed the respective page of our website and when you did so. In addition, information such as your IP address, details about the browser you used, and your language settings may be transmitted. If you click the button, your click will be transferred to the social network and used according to their data policy.

When you click the button we have no control over the data collected and the data-processing operations. We are not responsible for this data processing, nor are we the “controller” as defined in the GDPR. Neither are we aware of the full extent of data collection, its legal basis, purposes and storage periods. Given this, the information provided here is not necessarily complete.

The data will be transmitted irrespective of whether you actually have an account with this provider or whether you are logged in there. If you are logged in with the provider, your data will be assigned directly to your account. Providers may also use cookies on your computers to track you.

As far as we know, these providers store these data in user profiles which they use for advertising, market research and/or demand-oriented website design. This type of analysis is performed (also for users who are not logged in) to present demand-oriented advertising and inform other users of the social network of your activities on our website. You have the right to object to the creation of these user profiles. To exercise your right of objection, please contact the relevant provider.

Please consult the information provided by the following social media sites for details of the purpose and scope of data collection and of further processing and use of the data by the respective social network, and for your rights and privacy settings:

If you do not wish social networks to obtain data about you, do not click the button.

 

9.  Online presences in social media

SMR maintains online presences within social networks and platforms, such as LinkedIn, in order to be able to communicate with active users there and to inform them about our service portfolio. SMR uses the technical platforms and services offered by the operators. In social networks and on other external platforms the data protection regulations of the operators apply, even though we publish information and maintain presences there.

We would like to point out that you use the services of the social networks and platforms offered here as well as their functions under your own responsibility.

This applies in particular to the use of interactive functions (e.g. commenting, sharing, rating etc.). The data collected about you in this context will be processed by the platform operators and, if necessary, transferred to countries outside the European Union. Which information the operators receive and how these are used, describe the respective data protection guidelines in general form. On the individual platforms you will also find information on how to contact the operators and on the setting for advertisements.

In which way the social network operators use the data from the visits of the respective pages for own purposes, to what extent activities on the pages are assigned to individual users, how long these data are stored and whether data from a visit of the respective page are passed on to third parties, is not conclusively and clearly named by the operators and is not known to us.

I. LinkedIn

  • Facebook Pixel
    LinkedIn uses the remarketing tool „Facebook Pixel“, a service of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA. This function is used to display interest-based adverts (“Facebook ads”) to visitors when they visit the website.  For this purpose, Facebook's remarketing tag has been implemented on this website. The tag establishes a direct connection to the Facebook servers when you visit the website. This information is transmitted to the Facebook server that you have visited this website and Facebook assigns this information to your personal Facebook user account. https://www.facebook.com/business/help/742478679120153?helpref=search&sr=3&query=pixel
  • Nielsen NetRatings
    Nielsen NetRatings is provided by Nielsen GmbH, Lindwurmstraße 10, 80634 Munich and is an Internet tracking service for measuring and analyzing consumer behavior. You can object to the collection or evaluation of your data using this tool by downloading or setting and saving the opt-out cookie available under the following link: http://www.nielsen.com/us/en/privacy-statement/digital-measurement.htm
  • AppNexus
    AppNexus is provided by von AppNexus Inc., 28 W 23rd Street, 4th floor, New York, NY - 10010, USA and is a tool for web analysis and interest-oriented advertisement. You can object the collection and evaluation of your data here: https://www.appnexus.com/en/company/platform-privacy-policy-de
  • Eloqua Tracking
    Eloqua, a service of Oracle Cor, 500 Oracle Parkway, M/S 5op7, Redwood Shores, CA 94065, USA, places a persistent cookie on the respective login page, if no Eloqua cookie already exists on your device. If you have already used a website that uses Eloqua, you may already have an Eloqua cookie. The Eloqua cookie may be used to analyze your use of pages to improve them. Emails sent using Eloqua use the tracking technologies described above. If you want to completely eliminate the use of Eloqua tracking technologies for your device, you can do so on the Eloqua Opt-Out page. For more information, please see Eloqua's Privacy Policy. (https://www.oracle.com/marketingcloud/products/marketing-automation/index.html)

 

10.     Use of Google Maps  

This website uses Google Maps, a map service of Google Ireland Limited ("Google"), to display an interactive map. Google Ireland Limited ("Google"), is a company incorporated and operated under the laws of Ireland (registration number: 368047) with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

Through the use of Google Maps, information about your use of this website (including your IP address) may be transferred to a Google server in the United States of America and stored there. Google will transfer the information obtained through Google Maps to third parties if this is required by law or if third parties process these data on behalf of Google.

Google will in no case associate your IP address with other data from Google. Nevertheless, it would be technically possible that Google could make an identification of the least single users on the basis of the data obtained. It would be possible for personal data and personality profiles to be processed by users of Google’s website for other purposes to which we have no influence. This and the fact that data are transmitted to the US is problematic for reasons of data protection law. You can easily disable the Google Maps service, preventing data transfer to Google: For this, disable JavaScript in your browser. Please note that in this case, you can no longer use the map display.

By using this website and not disabling java, you agree with the collection, processing and use of the automatically collected data and the data entered by you (including your IP address) by Google, one of its representatives or third-party providers.

The terms of use for Google Maps can be found at the following link: https://www.google.com/intl/en/policies/terms/regional.html

In-depth information about transparency and choices, as well as the data protection policy, can be found at the Google Privacy Center: https://policies.google.com/privacy?hl=en

 

11.     Standard periods for deletion of data  

Legislation has defined numerous data storage periods and obligations. At the end of these periods, the relevant data will be routinely deleted. Data that are not affected by the above storage periods and obligations are deleted or anonymized as soon as the purposes defined in this data privacy statement no longer apply. Unless this data privacy statement includes other deviating provisions for data storage, we will store any data we collect for as long as they are required for the above purposes for which they were collected.

 

12.     Other data use and deletion

Any further processing or use of your personal data will generally only be carried out to the extent permitted on the basis of a legal regulation or where you have consented to data processing or data use. In the case of further processing for other purposes than the ones for which the data were originally collected, we will inform you about these other services and provide you with all other significant information before further processing.

 

13.     Misuse detection and prosecution

Information for the detection and prosecution of misuse, in particular your IP address, will be kept available for a maximum of 7 days. The legal basis in this respect is Art. 6 (1) lit. f GDPR. Our legitimate interest in the retention of data for 7 days is to ensure the proper functioning of our website and the transactions conducted over it, and to be able to ward off cyber attacks and the like. We may use anonymous usage information to design our website to meet your needs.

 

14.     Rights concerning the processing of personal data

Right of access

On request, you have the right to obtain information from us about the personal data concerning you and processed by us, to the extent defined in Art. 15 GDPR. You can send your request either by mail or email to the addresses given below.

Right to rectification

You have the right to require us to rectify any inaccurate personal data concerning you without undue delay (Art. 16 GDPR). For this purpose, please contact the address given below.

Right to deletion

Where the legal reasons defined in Art. 17 GDPR apply, you have the right to immediate deletion (“right to be forgotten”) of personal data concerning you. These legal reasons include: the personal data are no longer necessary for the purposes for which they were processed, or you withdraw your consent, and there are no other legal grounds for processing; the data subject objects to the processing (and there are no overriding legitimate grounds for processing––does not apply to objections to direct advertising). To assert your above right, please contact the contact address given below.

 Right to restriction of processing

If the criteria defined in Art. 18 GDPR are fulfilled, you have the right to restriction of processing as established in the above article of the GDPR. According to this article, restriction of processing may be called for in particular if processing is unlawful and the data subject opposes deletion of the personal data and requests the restriction of their use instead, or if the data subject has objected to processing according to Art. 21 (1) GDPR as long as it is unclear whether our legitimate interest overrides the interest of the data subject. To assert your above right, please contact the contact address given below.

Right to data portability

You have the right to data portability as defined in Art. 20 GDPR. This means you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, and have the right to transmit those data to another controller, such as another service provider. Prerequisite is that processing is based on consent or a contract, and is carried out using automated means. To assert your above right, please contact the contact address given below.

 

15.     Right to object

You have the right to object at any time under Art. 21 GDPR to processing of personal data concerning you which is based on Art 6 (1) lit. e or f GDPR, on grounds relating to your particular situation. We will desist from processing your personal data unless we can demonstrate compelling legitimate grounds for processing which override your interests, rights, and freedoms, or unless processing is for the establishment, exercise, or defence of legal claims. To assert your above right, please contact the contact address given below.

 

16.     Right to file a complaint with a supervisory authority

If you think that processing of personal data concerning you and carried out by us is unlawful or impermissible, you have the right to file a complaint with the supervisory authority responsible for us. You can contact the corresponding authority at: Link

 

17.     Data Protection Officer

Please address any questions regarding the processing of your personal data, requests for information, applications, or complaints directly to our data protection officer, who will be happy to be of service:

Data Protection Officer SMR Automotive Mirrors Stuttgart GmbH
Hedelfinger Straße 60
70327 Stuttgart
mail: data.protection@motherson.com

 

18.     Contact data of the controller:

SMR Automotive Mirrors Stuttgart GmbH
Hedelfinger Straße 60
70327 Stuttgart
Deutschland

phone: +49 (0) 711 18561 0
fax: +49 (0) 711 18561 2345
mail: info@smr-automotive.com