Privacy Policy

1. Privacy Policy for this website

Various data are collected when you visit our website. The main reason for this is so that we can provide convenient and secure access to our information and what we offer. Of course, we also pursue economic interests with our website with a view to strengthening our image and boosting our sales. For reasons of fairness and transparency, we would like to inform you about this in detail below in accordance with the EU General Data Protection Regulation (GDPR):

Who is responsible for data collection?
As the website operator (https://weco.ag/impressum), we are responsible for collecting the data resulting from your visit to this website, as we are responsible for the technologies that are used on our website and the purposes for which they are used.

How do we collect your data?
Firstly, your data are collected when you provide the data to us. These may be data that you enter in a contact form, for example. Other data are collected automatically by our IT systems when you visit the website. These are primarily technical data (for example, Internet browser, operating system or time the page was viewed). These data are collected automatically as soon as you enter our website.

What do we use your data for?
Some data are collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour and improve our offering to you.

What rights do you have with regard to your data?
You have the right to obtain information at any time free of charge about any of your personal data that are stored as well as their origin, the recipient and the purpose for which the data have been processed. You also have the right to request the correction, blocking or deletion of these data. You also have the right to lodge a complaint with the competent supervisory body. You can contact us at any time using the address stated in the legal notice for further information on this and on the subject of data protection.

SSL or TLS encryption
This website uses SSL or TLS encryption for security reasons and to protect the transfer of confidential content, such as orders or enquiries that you send to us as the website operator. You can recognise an encrypted connection in your browser’s address line when it changes from ‘http://’ to ‘https://’ and the lock icon is displayed in your browser’s address bar. If SSL or TLS encryption is enabled, the data you transfer to us cannot be read by third parties.

2. General notes and mandatory information

The operators of these web pages take the protection of your personal data very seriously. When you use this website, various personal data are collected that can be used to identify you. We treat your personal data (definition according to Article 4(1) GDPR) confidentially and in accordance with statutory data protection regulations. This Privacy Policy explains which data we collect, what we use the data for, how we use the data and for what purpose. We would like to point out that there may be security vulnerabilities when transferring data online, even with the best possible security (for example, when communicating by email). Complete protection of data against access by third parties is not possible.

Information on data controller
The data controller within the meaning of data protection law (Article 4(7) GDPR) is Weco Service GmbH (Legal notice – hereinafter referred to as ‘Weco’). If you have any questions about the use of your data, please contact us.

3. Contacting our data protection officer

Every user has the right to obtain information at any time free of charge about their personal data that are stored. Users can contact datenschutz@weco.ag for example, for information.

4. Data collection on our website

Cookies
Our website uses cookies. These help make our website more user-friendly, effective and secure. Cookies are small text files that are stored in the browser on your device. Cookies do not damage your computer and do not contain viruses.

Most of the cookies we use are ‘session cookies’. They will be deleted automatically at the end of your visit. Other cookies are stored on your device until you delete them. These cookies enable us to recognise your browser on your next visit and to apply the settings you have previously configured.

You can configure your browser so that you are notified about the use of cookies and only allow them in individual cases, refuse to accept cookies in specific cases or in general and enable the automatic deletion of cookies when closing your browser. If cookies are disabled, the functionality of this website may be limited.

Cookies that are required for the electronic communication process are stored on the basis of Article 6(1) f) GDPR. The website operator has a legitimate interest in storing cookies for error-free (without technical issues) and enhanced provision of its services. Insofar as other cookies (for example, to analyse your surfing behaviour) are stored, these are addressed separately in this Privacy Policy.

Google Analytics

If you have given your consent, we use the web analysis tool Google Analytics on our website. Google Analytics helps us analyse the user behaviour of visitors to our website in pseudonymised and anonymised form.

You can disable data processing by Google Analytics at any time in our ‘Cookie Dashboard’. Alternatively, you can install a browser plug-in from Google that prevents data collection by Google Analytics: http://tools.google.com/dlpage/gaoptout?hl=de .

The purposes of data processing are to analyse user behaviour and measure the reach of our website and advertisements placed in order to enhance our website.

The data processed are:

Google Analytics HTTP data:
These data are log data generated for technical reasons via the Hypertext Transfer Protocol (Secure) (HTTP(S)) when using the web analysis tool Google Analytics used on the website: Data include IP address, type and version of your Internet browser, operating system used, web page accessed, previous website you visited (referrer URL), date and time of access.

  • Google Analytics device data:
    Data generated by the web analysis tool Google Analytics and assigned to your device: Data include a unique ID for recognising returning visitors (‘client ID’) as well as certain technical parameters for controlling data collection for web analysis.
  • Google Analytics measurement data:
    Device-related raw data (‘dimensions’ and ‘measured values’), which are collected and analysed by the web analysis tool Google Analytics when using our website: Data include, in particular, information about the sources through which visitors reach our website, information about the location, browser and device used, information about the use of the website (in particular page views, frequency of visits and length of stay on accessed pages) and information about the fulfilment of certain purposes (in particular transactions in the online store). The data are associated with the client ID assigned to your device. As a result, device-related usage profiles are created in which all device-related raw data are combined for a client ID. The data we collect using Google Analytics do not enable us to identify you personally (i.e. by your real name). We also do not merge device-related raw data and the resulting device-related usage profiles with data that directly identifies you without your consent.
  • Google Analytics report data:
  • Data contained in aggregated segment and device-related reports generated by the web analytics tool Google Analytics based on the analysis of raw device-related data. The legal basis for processing is Article 6(1) a) GDPR (consent). The data are provided automatically by the user’s browser.
  • The recipient of the data is Google Ireland Limited (Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) which we use as processor within the framework of a data processing agreement. Google Ireland Limited uses Google LLC in the USA (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) as its service provider. The basis for data processing in the USA is your consent given via the cookie consent banner (Article 49(1) a) GDPR). In the USA, there is no level of data protection that is comparable to the requirements of the GDPR. It is possible that US government agencies may access personal data without us or you being informed. Enforcing your rights is unlikely to be possible in the USA. You can withdraw your consent at any time with future effect by clicking the ‘Individual data protection settings’ button.
  • The data will be deleted after 14 months.
  • The provision of data is not required by law or under a contract or necessary for the conclusion of a contract. The data subject is under no obligation to provide the data. If the data are not provided, we cannot perform web analysis using Google Analytics.

Server log files
Our website provider automatically collects and stores information in server log files which your browser transfers to us automatically. Data in log files include:

referrer URL (address of the web page where you clicked a link that sent you to our website), browser type, browser version and language, operating system used and its interface, IP address (anonymised), time of server request, HTTP status code – access status, volume of data transferred, storage period is 7 days

These data are not merged with other data sources.

The legal basis for data processing is Article 6(1) f) GDPR, which permits the processing of data for optimum presentation and security of the website based on our legitimate interest, except where your interests in the exclusion of data collection are overriding.

5. Visitor interaction on the website

Contact form
If you send us enquiries via the contact form, your details from the enquiry form, including the contact details you provide there, will be stored by Weco Service GmbH for the purpose of processing your enquiry and in the event of any follow-up questions. We do not pass these data on to third parties without your consent.

The data entered in the contact form are generally processed on the legal basis of Article 6(1) b) GDPR and Article 6(1) f) GDPR  (performance of a contract or in order to take steps prior to entering into a contract). Your data will remain with us until you ask us to delete the data or the purpose for storing the data no longer applies (for example, after your enquiry has been processed – but only if we do not have to comply with any retention periods).

Application form

If you apply using the application form, you agree that your data will be made available to all affiliated companies of the Promota Group for application purposes. We would also like to point out that application details may be stored for more than six months.

Email or telephone enquiry

If you contact us by email or telephone, we will store and process your enquiry, including all personal data arising from your enquiry (name, question), for the purpose of processing your request. We do not pass on these data without your consent.

These data are processed on the basis of Article 6(1) b) GDPR if your enquiry relates to the performance of a contract or is necessary for taking steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective processing of enquiries addressed to us (Article 6(1) f) GDPR) or on your consent (Article 6(1) a) GDPR) if this has been requested.

The data you send to us through contact enquiries will remain with us until you ask us to delete the data, withdraw your consent to storage or the purpose for data storage no longer applies (for example, after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.

Communication via WhatsApp

We use the instant messaging service WhatsApp, among other services, to communicate with our customers, employees and other third parties. Communication takes place via end-to-end encryption (peer-to-peer), which prevents WhatsApp or other third parties from gaining access to the content of communication. However, WhatsApp receives access to metadata that are created in the course of the communication process (for example, sender, recipient and time).  

The legal basis for processing these data is Article 6(1) a) GDPR (consent) and Article 25(1) of the German Telecommunications-Telemedia Data Protection Act (TTDSG), insofar as consent includes the storage of cookies or access to information in your device (for example, device fingerprinting) within the meaning of the TTDSG. Consent can be withdrawn at any time. In addition, we have a legitimate interest in the efficient organisation of our customer service, in responding to your request as quickly as possible and in optimising our service offering in accordance with Article 6(1) f) GDPR.  

The recipient of your data is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. We have entered into a data processing agreement with WhatsApp, which ensures the protection of your data and prohibits unauthorised disclosure to third parties.

In addition, we have agreed with WhatsApp that customer data will only be processed on EU servers and consequently data transfer to the USA will be reduced to a minimum. However, data transfer to the USA cannot be ruled out completely. We would like to point out that WhatsApp states that it shares personal data of its users with its parent company Meta Platforms, which is based in the USA. Meta Platforms has its head office in Menlo Park, California, United States (USA). The EU Commission has not yet issued an adequacy decision in respect of the USA. Data are therefore transferred, inter alia, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data. Nevertheless, both Meta Platforms and US government authorities can access your data. Further information on terms of use and data protection can be found at https://www.whatsapp.com/legal/#privacy-policy.

The content of communication exchanged between you and us and on WhatsApp will remain with us until you ask us to delete it, withdraw your consent to storage or the purpose for data storage no longer applies (for example, after your enquiry has been processed). Mandatory statutory provisions – in particular retention periods – remain unaffected. However, full deletion of your data at WhatsApp and Meta Platforms cannot be guaranteed due to a lack of access options.

Communication via 3CX

We use the 3CX communication system for online phone calls, chats and/or video conferences. Various types of personal data are processed when using 3CX. The scope of data processing also depends on the information you provide before or during participation in a web meeting and the settings you configure. Your personal text, audio and video data as a participant will also be collected and stored, where appropriate, if you join the web meeting yourself by initiating the corresponding functions via chat or video. The legal basis in this respect is your consent in accordance with Article 6(1) a) GDPR, which you give by enabling the relevant functions in 3CX. By using 3CX, you accept the 3CX terms of use and data protection regulations in the applicable original version. These data protection regulations are accepted by the user on registration in the 3CX Cloud. The following personal data are processed: 

User details: The data stored at 3CX are processed. These data may include: Your first and last name, email address, password, profile picture (if you have provided one).

6. Plug-ins

Social media plug-ins

Facebook

We offer a Facebook plug-in on our website. Facebook is a social media network. The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Facebook receives all the information that your browser transfers automatically (including your IP address). Facebook also sets its own cookies on your device. This happens even if you do not have a Facebook account. If you are logged in to Facebook, your data will be assigned directly to your account. If you do not want data assigned to your Facebook account, you must log out of Facebook.

The legal basis for enabling the collection of personal data via our website is Article 6(1) a) GDPR (consent) and Article 25(1) TTDSG, insofar as consent includes the storage of cookies or access to information in the user’s device (for example, device fingerprinting) within the meaning of TTDSG. Consent can be withdrawn at any time. Your data are also processed on the basis of Article 6(1) f) GDPR. The website operator has a legitimate interest in a varied and entertaining design of its website.

The processing of your data is the sole responsibility of Meta Platforms Ireland Limited. However, Meta Platforms Ireland Limited uses Meta Platforms Inc. in the USA (1 Hacker Way, Menlos Park, CA 94025, USA) as its service provider. We are not aware of any further details of the processing of personal data within Facebook’s area of responsibility or of possible data processing in the USA. We have no control over the processing of data by Facebook.  Despite the current Data Privacy Framework Agreement, available at https://commission.europa.eu/system/files/2023-07/Adequacy decision EU-US Data Privacy Framework_en.pdf, the level of data protection in the USA is unlikely to be comparable with the requirements of the GDPR. Therefore, it cannot be ruled out that US government agencies may access personal data without us or you being informed. Enforcing your rights is unlikely to be possible in the USA.

Facebook undertakes to comply with data privacy when processing relevant data outside the EU through the standard contractual clauses approved by the EU Commission in accordance with Article 46(2) and (3) GDPR.

A link will take you to Facebook. Facebook is responsible for the further processing of your data.
If you have any questions about data collection and processing by Facebook, you can find information on the following page: https://www.facebook.com/policy.php/

Instagram

We offer an Instagram plug-in on our website. Instagram is a social network with a focus on video and photo sharing from US provider Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA.

Instagram LLC is a subsidiary of Meta Platforms Inc. which, as the operator of Instagram, receives all the information that your browser transfers automatically (including your IP address) when you use our plug-in. Meta also places its own cookies on your device. This happens even if you do not have an Instagram, Facebook or Meta account. If you are logged in to Instagram or Facebook, your data will be assigned directly to your account. If you do not want your data to be assigned to your Instagram or Facebook account, you must log out of Instagram or Facebook before using the plug-in. Facebook receives all the information that your browser transfers automatically (including your IP address). Facebook also sets its own cookies on your device. This happens even if you do not have a Facebook account. If you are logged in to Facebook, your data will be assigned directly to your account. If you do not want data assigned to your Facebook account, you must log out of Facebook.

The legal basis for enabling the collection of personal data via our website is Article 6(1) a) GDPR (consent) and Article 25(1) TTDSG, insofar as consent includes the storage of cookies or access to information in the user’s device (for example, device fingerprinting) within the meaning of TTDSG. Consent can be withdrawn at any time. Your data are also processed on the basis of Article 6(1) f) GDPR. The website operator has a legitimate interest in a varied and entertaining design of its website.

Your data are processed exclusively within the area of responsibility of Instagram LLC or Meta Platforms Inc. in the USA (1 Hacker Way, Menlos Park, CA 94025, USA). We are not aware of any further details of the processing of personal data within the area of responsibility of Instagram or Meta or of possible data processing in the USA. We have no control over the processing of data by Instagram or Meta.  Despite the current Data Privacy Framework Agreement, available at https://commission.europa.eu/system/files/2023-07/Adequacy decision EU-US Data Privacy Framework_en.pdf, the level of data protection in the USA is unlikely to be comparable with the requirements of the GDPR. Therefore, it cannot be ruled out that US government agencies may access personal data without us or you being informed. Enforcing your rights is unlikely to be possible in the USA.

Meta undertakes to comply with data privacy when processing relevant data outside the EU through the standard contractual clauses approved by the EU Commission in accordance with Article 46(2) and (3) GDPR. A link will take you to Meta. Meta is responsible for the further processing of your data. If you have any questions about data collection and processing by Instagram, you can find information on the following page: https://help.instagram.com

LinkedIn Insight Tag

If you have given your consent, we use the ‘LinkedIn Insight Tag’. Cookies from LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (‘LinkedIn’) are used for this purpose. The ‘LinkedIn Insight Tag’ enables LinkedIn to, among other things, collect information about the activities of our website users. By incorporating the ‘LinkedIn Insight Tag’, we enable LinkedIn to collect personal data. According to LinkedIn, the data processed are:

LinkedIn Insight Tag HTTP data

These data are log data generated for technical reasons via the Hypertext Transfer Protocol (Secure) (HTTP(S)) when using the LinkedIn Insight Tag used on the website: Data include IP address, type and version of your Internet browser, operating system used, web page accessed, previous website you visited (referrer URL), date and time of access.

LinkedIn Insight Tag – device data

Data assigned to your device by the LinkedIn Insight Tag: These include a unique ID for recognising returning visitors.

LinkedIn Insight Tag report data

Data generated by LinkedIn based on information collected by the LinkedIn Insight Tag and assigned to the unique visitor ID of the respective visitor included in the LinkedIn Insight Tag device data: The data include information about the effectiveness of LinkedIn advertisements and the allocation of users to target groups for LinkedIn advertisements. LinkedIn may be able to generate further data from the information collected for its own purposes or for third-party purposes. We are not aware of the details of the data generated by LinkedIn.

LinkedIn only provides us with evaluations or other information created on the basis of the data collected in aggregated, anonymised form. We are not able to assign the information provided to us to any natural person. You can disable data processing by LinkedIn at any time in our cookie banner. Alternatively, you can disable LinkedIn Insight Tag for the browser you are currently using by disabling the storage of cookies in your browser settings.

The legal basis for enabling the collection of personal data via our website is Article 6(1) a) GDPR (consent) and Article 25(1) TTDSG, insofar as consent includes the storage of cookies or access to information in the user’s device (for example, device fingerprinting) within the meaning of TTDSG. Consent can be withdrawn at any time. Your data are also processed on the basis of Article 6(1) f) GDPR. The website operator has a legitimate interest in a varied and entertaining design of its website.

The recipient of the data collected via our website is LinkedIn Ireland Unlimited Company as the controller responsible for collecting and processing personal data. LinkedIn Ireland Unlimited Company uses LinkedIn Corporation in the USA (1000 W. Maude Avenue, Sunnyvale, CA 94085, USA) as its service provider. We are not aware of the details of the processing of personal data within LinkedIn’s area of responsibility in the USA. We have no control over the processing of data by LinkedIn.  Despite the current Data Privacy Framework Agreement, available at https://commission.europa.eu/system/files/2023-07/Adequacy decision EU-US Data Privacy Framework_en.pdf, the level of data protection in the USA is unlikely to be comparable with the requirements of the GDPR. Therefore, it cannot be ruled out that US government agencies may access personal data without us or you being informed. Enforcing your rights is unlikely to be possible in the USA.

For more information about the processing of personal data by LinkedIn, please refer to LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.

Google Web Fonts
This website uses web fonts provided by Google for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into your browser cache in order to display text and fonts correctly. These fonts are stored in your browser cache for one year to improve loading times. Furthermore, there is less administrative effort and fewer sources of error with font updates via Google.
The browser you are using needs to connect to Google’s servers for this purpose. This lets Google know that our website has been accessed via your IP address (with browser and device data). The use of Google Web Fonts is in the interest of a uniform and appealing presentation of our website. This constitutes a legitimate interest within the meaning of Article 6(1) f) GDPR.
If your browser does not support web fonts, your computer will use a standard font.
You can find more information about Google Web Fonts at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://www.google.com/policies/privacy/.

7. What rights do you have under the EU GDPR?

The EU GDPR aims to ensure that you as the data subject have the greatest possible control over your personal data. All data that can be directly or indirectly related to you as a person is considered personal data. In order that you can exercise effective control over your data, you have the following rights:
Right of access under Article 15 EU GDPR, right to rectification under Article 16 EU GDPR, right to erasure under Article 17 EU GDPR, right to restriction of processing under Article 18 EU GDPR, right to object under Article 21 EU GDPR.

In addition, you have the right to lodge a complaint with a data protection supervisory authority in accordance with Article 77 GDPR if you believe that we are processing your data unlawfully. You can find a list of all supervisory authorities here: www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

The right to data portability according to Article 20 is only relevant when visiting our website if you have the option of creating a profile (for example, applicant profile, member profile or similar) or entering relevant information about yourself.