Controller and Scope
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Consilio Concept GmbH
Schumanstr. 14
52146 Wurselen
Germany
Phone: +49 2405 6458383
Email: info@consilio-concept.com
Represented by the Managing Director.
This Privacy Policy applies in particular to the use of our B2B online store and to the processing of personal data in connection with our business relationships, the initiation of business relationships, and contract performance.
Our B2B online store is intended exclusively for businesses, legal entities under public law, and special funds under public law.
Personal data within the meaning of the GDPR may also be processed in the course of business transactions. This applies in particular to data relating to sole proprietors as well as managing directors, employees, buyers, contacts, and other contact persons of our customers, prospective customers, suppliers, and business partners.
Pure company data that does not relate to an identified or identifiable natural person does not constitute personal data within the meaning of the GDPR.
Access Data and Hosting
You can generally visit our website without providing any personal information yourself.
Each time our website is accessed, the web server may automatically process so-called server log files. These may include in particular:
- IP address,
- date and time of access,
- page or file accessed,
- amount of data transferred,
- referrer URL,
- browser type and browser version,
- operating system,
- host name of the accessing device, and
- requesting Internet service provider.
The processing is carried out to ensure the smooth and secure operation of our website, to protect against attacks and misuse, and to technically optimize our offering.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and proper provision of our B2B online offering.
Access data is stored only for as long as necessary for the purposes stated above, unless longer storage is required due to a specific security incident or legal obligations.
Hosting
For the hosting and technical provision of our online offering, we use services provided by:
ecomDATA GmbH
Steinamangererstrasse 9/16
7400 Oberwart
Austria
Phone: +43 3326 20410 / +49 8654 4093901
Email: info@ecomdata.de
Website: www.ecomdata.de
In connection with hosting, access data and data collected through our online store, customer accounts, orders, forms, or other functions of our website may in particular be processed.
Where ecomDATA processes personal data on our behalf, the processing is carried out on the basis of a data processing agreement pursuant to Article 28 GDPR.
Business Relationships and Contract Performance
3.1 Orders and Contract Performance
For the initiation, performance, and processing of business relationships and contracts, we process the data required for these purposes.
This may include in particular:
- first and last name,
- company or business name,
- legal form,
- function or position within the company,
- billing and delivery address,
- business email address,
- phone number,
- customer and customer account numbers,
- VAT identification number,
- order and purchase order data,
- product and delivery information,
- invoice data,
- payment information,
- communication data,
- complaint, return, and defect data, and
- other information required for the respective business relationship.
If the data subject is the contracting party, for example as a sole proprietor, the processing is carried out in particular on the basis of Article 6(1)(b) GDPR for the performance of pre-contractual measures and the performance of the contract.
If a data subject acts as an employee, managing director, buyer, or other contact of a company that is or is intended to become a contracting party, the processing is carried out in particular on the basis of Article 6(1)(f) GDPR.
Our legitimate interest is the initiation, performance, administration, and documentation of our business relationships and efficient communication with our business customers and business partners.
Where processing is necessary to comply with retention obligations under commercial, tax, or other laws, it is carried out on the basis of Article 6(1)(c) GDPR.
Data relating to complaints, warranty cases, performance issues, or other contractual disputes may also be processed where this is necessary to review, assert, exercise, or defend legal claims. The legal basis is, in particular, Article 6(1)(f) GDPR.
Our B2B offering does not include a consumer right of withdrawal.
3.2 Enterprise Resource Planning System JTL-Wawi
We use JTL-Wawi to manage our inventory and for order and contract processing.
In connection with the use of JTL-Wawi, the following data may in particular be processed:
- customer and company master data,
- contact persons,
- contact information,
- orders and purchase orders,
- invoices and credit notes,
- payment information,
- shipping data,
- returns,
- complaints, and
- other contract-related information.
Where the data subject is the contracting party, the processing is carried out on the basis of Article 6(1)(b) GDPR.
For contacts and employees of our business customers, the processing is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest is efficient inventory management and the proper administration and processing of our business relationships.
Where data is stored due to statutory retention obligations, the processing is additionally carried out on the basis of Article 6(1)(c) GDPR.
The technical storage and processing of data managed through JTL-Wawi may take place on systems provided by us or by our IT and hosting service providers.
3.3 Customer Account
Where our B2B online store provides a customer account, we process the data provided during registration to create and manage the customer account and to process future orders and business transactions.
Required information is marked accordingly.
Where the account holder is the contracting party, the processing is carried out on the basis of Article 6(1)(b) GDPR.
Where the customer account is used by an employee or other contact of a business customer, the processing is additionally or instead carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest is the provision and administration of an efficient B2B customer area.
A customer account may be deleted upon request, provided that no statutory retention obligations or other legitimate grounds prevent deletion.
Data relating to completed orders, invoices, or other business transactions subject to retention obligations may continue to be stored in accordance with statutory retention obligations regardless of deletion of a customer account.
3.4 Contacting Us
If you contact us, for example by email, phone, contact form, or other means of communication, we process the personal data you provide in order to handle your inquiry.
This may include in particular:
- name,
- company,
- function,
- email address,
- phone number,
- content and time of the communication, and
- other information provided by you.
If the inquiry relates to a contract with the data subject or to pre-contractual measures at the data subject's request, the processing is carried out on the basis of Article 6(1)(b) GDPR.
When communicating with contacts of a company or in connection with other business inquiries, the processing is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest is handling business inquiries and communicating with existing and potential business partners.
3.5 Contacts at Business Customers and Business Partners
As part of our B2B business activities, we process personal data relating to contacts at our customers, suppliers, service providers, prospective customers, and other business partners.
This includes in particular:
- name,
- company,
- business contact information,
- position or function,
- area of responsibility, and
- business correspondence.
The processing is carried out on the basis of Article 6(1)(f) GDPR.
Our legitimate interest is the initiation, maintenance, performance, and documentation of business relationships and efficient business communication.
Data Processing for Shipping and Delivery
4.1 Disclosure to Shipping, Freight Forwarding, and Logistics Service Providers
To fulfill an order, we transmit the personal data required for delivery to the parcel service, freight forwarder, carrier, logistics partner, or other delivery service provider commissioned for the respective delivery.
This may include in particular:
- name of the recipient,
- company,
- delivery address,
- phone number,
- email address,
- order or shipment information, and
- other information required for the specific delivery.
Where the data subject is the contracting party, the processing is carried out on the basis of Article 6(1)(b) GDPR.
For employees or contacts of a business customer, the processing is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest is the proper performance of delivery to our business customer.
4.2 Delivery Notifications and Appointment Coordination
Where a phone number or email address is required for the specific performance of a delivery, in particular for freight deliveries, scheduled deliveries, two-person handling, or agreed assembly services, this data may be disclosed to the responsible logistics or assembly partner.
Where the data subject is the contracting party, the processing is carried out on the basis of Article 6(1)(b) GDPR and otherwise on the basis of Article 6(1)(f) GDPR.
Where the disclosure of contact information serves exclusively as an additional convenience service that is not necessary for performance of the contract, it takes place only if the corresponding consent has been given pursuant to Article 6(1)(a) GDPR.
Consent that has been given may be withdrawn at any time with effect for the future.
Payment Processing and Credit Checks
5.1 Payment Processing
Depending on the selected payment method, we work in particular with financial institutions, payment service providers, and technical payment service providers to process payments.
Only the personal data required to perform and allocate the respective payment is transmitted.
This may include in particular:
- name,
- company,
- billing address,
- invoice and order information,
- payment amount,
- payment reference,
- bank or payment data, and
- where applicable, other information required for the respective payment service.
Where the data subject is the contracting party, the processing is generally carried out on the basis of Article 6(1)(b) GDPR.
For contacts of a business customer, the processing is carried out, where necessary, on the basis of Article 6(1)(f) GDPR.
5.2 PayPal
If you select PayPal as the payment method, the data required for payment processing is transmitted to:
PayPal (Europe) S.a r.l. et Cie, S.C.A.
22-24 Boulevard Royal
L-2449 Luxembourg
Luxembourg
PayPal processes some of the data required for payment under its own responsibility under data protection law.
The nature and scope of further processing are governed by PayPal's privacy policy.
5.3 Fraud Prevention and Payment Management
To prevent payment defaults, attempted fraud, abusive orders, or other financial loss, we may evaluate order, contract, communication, and payment data.
Pursuant to Article 6(1)(f) GDPR, this serves our legitimate interest in preventing fraud and payment defaults and in secure and efficient payment and receivables management.
Where necessary to review a specific matter, the data required for this purpose may be transmitted to participating payment service providers, financial institutions, legal advisors, or other entities required for this purpose.
5.4 Credit Checks
Where we offer payment methods under which we assume an economic risk of default, in particular payment by invoice or the granting of payment terms, we may carry out a credit check to the extent legally permissible.
The following data may in particular be processed for this purpose:
- name or company,
- address,
- company data,
- payment and contract history,
- amount of the respective order, and
- other information required to assess the risk of payment default.
Where necessary and legally permissible, data may be transmitted to credit agencies or comparable service providers, or credit information may be obtained from them.
The legal basis is Article 6(1)(f) GDPR.
Our legitimate interest is the assessment and reduction of economic default and credit risks.
Where a credit check is carried out solely on the basis of express consent, Article 6(1)(a) GDPR is the legal basis.
Receivables Management and Debt Collection
If due receivables are not properly paid, we may transmit the personal data required to enforce the claim to debt collection service providers, attorneys, courts, bailiffs, or other entities involved in enforcement of the claim that we have commissioned.
This may include in particular:
- name and address,
- company affiliation,
- contact information,
- contract and invoice data,
- amount and due date of the outstanding receivable,
- payment information,
- payment reminder and collection status, and
- correspondence required to enforce the claim.
The processing is carried out on the basis of Article 6(1)(f) GDPR.
Our legitimate interest is the assertion, enforcement, and defense of our contractual and statutory claims.
Where data processing is necessary to comply with legal obligations, it is additionally carried out on the basis of Article 6(1)(c) GDPR.
B2B Direct Marketing and Business Development
7.1 Processing of Business Contact Information
As part of our activities as a B2B company, we may process personal business contact information of existing and potential business customers and business partners in order to initiate business relationships, maintain existing business relationships, and provide information about our products, services, and offers.
This may include in particular:
- name,
- company,
- business position or function,
- business address,
- business phone number,
- business email address,
- area of responsibility,
- publicly available company information, and
- information about previous business communications.
The data may come directly from the data subject or, to the extent legally permissible, from publicly accessible business sources, such as company websites, business directories, or publicly accessible professional contact information.
To the extent legally permissible, personal data is processed for direct marketing and business development purposes on the basis of Article 6(1)(f) GDPR.
Our legitimate interest is the acquisition of new business customers, the marketing of our products and services, and the maintenance of existing business relationships.
When selecting the method of contact, we also take into account the applicable requirements of competition law, in particular Section 7 UWG.
Where personal data is not collected directly from the data subject, the information obligations under Article 14 GDPR also apply.
7.2 B2B Telephone Outreach
We may contact business contacts of potential business customers by phone if the applicable legal requirements are met.
For telephone advertising directed at companies or other market participants, promotional contact is made only where at least presumed consent within the meaning of Section 7 UWG can be assumed.
In particular, this depends on whether, based on specific circumstances, a factual interest of the contacted company in our products or services can be assumed.
To the extent permitted, the associated processing of personal data is carried out on the basis of Article 6(1)(f) GDPR.
7.3 Email Marketing
We send promotional emails only where the applicable legal requirements are met.
This is the case in particular where
- the corresponding consent has been given, or
- the statutory requirements for advertising to existing customers, in particular under Section 7(3) UWG, are met.
Consent that has been given may be withdrawn at any time with effect for the future.
The withdrawal does not affect the lawfulness of processing carried out on the basis of consent before the time of withdrawal.
Where direct marketing within an existing business relationship is based on a legitimate interest, Article 6(1)(f) GDPR is the legal basis under data protection law.
The competition-law requirements for the specific contact remain unaffected.
7.4 Objection to Direct Marketing
You may object at any time to the processing of your personal data for direct marketing purposes.
Following such an objection, we will no longer use your personal data for direct marketing.
Where necessary, we may store individual contact information on a suppression list to ensure that your objection to marketing is also observed in the future.
Storage on such a suppression list is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest is the permanent observance of your objection to marketing and the prevention of renewed unwanted contact.
Cookies and Other Technologies
8.1 Technically Necessary Technologies
Cookies and comparable technologies may be used on our website.
Cookies are small pieces of information that can be stored on or read from a user's device.
Certain technologies are technically necessary in order to provide the digital service expressly requested by you.
These may include, for example, technologies required for:
- shopping cart functions,
- login and customer account,
- technical session management,
- security functions,
- payment or checkout functions,
- language settings, or
- storage of privacy and cookie settings.
Where the storage of information on your device or access to information already stored on it is strictly necessary, this takes place without consent in accordance
Social Media
9.1 Social Media Links
Section reserved pending the remaining legal source text.
9.2 Our Social Media Profiles
Section reserved pending the remaining legal source text.
Recipients of Personal Data
Section reserved pending the remaining legal source text.
Transfers to Third Countries
Section reserved pending the remaining legal source text.
Data Retention
Section reserved pending the remaining legal source text.
Your Data Protection Rights
Section reserved pending the remaining legal source text.
Right to Object
Section reserved pending the remaining legal source text.
Data Protection Contact
Section reserved pending the remaining legal source text.