BWB-Holding AG and its subsidiaries (“BWB Surface Technology”; hereinafter also “we”) are pleased that you have visited our website. We process and use personal data collected during your visit to our website confidentially and only in accordance with the applicable provisions of data protection law. Protecting the personal data of Internet users is our top priority.
The BWB website is subject to Swiss data protection law, in particular pursuant to the Federal Data Protection Act (FADP) and the Ordinance to the Federal Data Protection Act (FADP), as well as any applicable foreign data protection law, such as the General Data Protection Regulation (GDPR) of the European Union (EU). The EU recognizes that Swiss data protection law ensures adequate data protection.
1 Contact addresses and data protection officers
Inquiries from supervisory authorities and data subjects usually reach us by e-mail, but are also possible by letter post.
Data Protection Officer Switzerland
The Data Protection Officer Switzerland is responsible for data protection at BWB-Holding AG and its Swiss subsidiaries:
Competent supervisory authority: Federal Data Protection and Information Commissioner (FDPIC)
Data Protection Officer Germany
The responsible data protection representative in the EU as the point of contact vis-à-vis supervisory authorities and data subjects in accordance with Art. 27 GDPR and for data protection at Nehlsen-BWB Flugzeug-Galvanik Dresden GmbH & Co. KG is the Data Protection Officer Germany:
Nehlsen-BWB Flugzeug-Galvanik Dresden GmbH & Co. KG
Border road 2
Competent supervisory authority: Free State of Saxony / Saxon Data Protection Commissioner
Data protection information of Nehlsen-BWB Flugzeug-Galvanik Dresden GmbH & Co. KG for customers and suppliers
Data Protection Officer Romania
Responsible for data protection at BWB Surface Technology S.R.L. is the Data Protection Officer Romania:
BWB Surface Technology S.R.L.
St. Hermann Oberth 30
RO-507075 Ghimbav / Braşov / Judetul Braşov
Competent supervisory authority: Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal
Data Protection Officer Netherlands
Responsible for data protection at BWB-Alucol B.V. is the Data Protection Officer Netherlands:
NL-6086 BW Neer
Competent supervisory authority: Autoriteit Persoonsgegevens
2 General information on the collection and processing of your data
2.1 Scope of data processing
As a matter of principle, we only process personal data insofar as this is necessary for the provision of a functioning website, as well as our content and services. The processing of personal data takes place only after consent. An exception applies to cases in which prior consent cannot be obtained for factual reasons and the processing of the data is permitted by law.
2.2 Legal basis
We process personal data in accordance with Swiss data protection law. Your data will be processed either on the basis of your consent or in the event that the processing is necessary for the performance of a contract to which you are a party or at your request in order to take measures prior to the conclusion of a contract or on the basis of a legitimate interest (cf. Art. 31 para. 1 et seq. DSG and Art. 6 para. 1 lit. a, b, f GDPR).
If your consent is the basis for the processing, you can withdraw your consent at any time by contacting the contacts or data protection officers listed in section 1.
Otherwise, if and to the extent that the GDPR is applicable, we process personal data in accordance with the following legal bases:
- Art. 6 par. 1 lit. a GDPR for the processing of personal data with the consent of the data subject.
- Art. 6 par. 1 lit. b GDPR for the necessary processing of personal data for the fulfillment of a contract with the data subject as well as for the implementation of corresponding pre-contractual measures.
- Art. 6 par. 1 lit. c GDPR for the necessary processing of personal data to comply with a legal obligation to which we are subject under any applicable law of the EU or under any applicable law of a country where the GDPR applies in whole or in part.
- Art. 6 par. 1 lit. d GDPR for the necessary processing of personal data to protect vital interests of the data subject or another natural person.
- Art. 6 par. 1 lit. f DSGVO for the necessary processing of personal data to protect the legitimate interests of us or of third parties, unless the fundamental freedoms and rights and interests of the data subject prevail. Legitimate interests include, in particular, our business interest in being able to provide our website, information security, the enforcement of our own legal claims and compliance with Swiss law.
2.3 Storage and deletion of your data
We process personal data for the duration required for the respective purpose or purposes. In the case of longer-term storage obligations due to legal and other obligations to which we are subject, we restrict processing accordingly. We delete or block the personal data of the data subject as soon as the purpose of the storage has been fulfilled. Storage may also take place if this has been provided for by the national or European legislator to which our company is subject. Data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless it is necessary to continue storing the data for the purpose of concluding or fulfilling a contract.
2.4 Data retention policy
Due to tax regulations, data concerning the area of bookkeeping and accounting are kept for 10 years by BWB Surface Technology. The retention periods are regulated accordingly in the Code of Obligations (OR) and the Value Added Tax Act (MWSTG), among others.
2.5 Retention of data to meet legal requirements
You may not request BWB Surface Technology to change the standard retention periods. However, you can propose changes to comply with specific industry policies and regulations.
3 Provision of the website and creation of log files
3.1 Scope of data processing
As a matter of principle, we only process personal data insofar as this is necessary for the provision of a functioning website, as well as our content and services. The processing of personal data takes place only after consent. An exception applies to cases in which prior consent cannot be obtained for factual reasons and the processing of the data is permitted by law. Any information we collect from you may be used for one or more of the following purposes:
- To personalize your experience (the information helps us better meet your individual needs).
- To improve our website (we strive to improve our website based on the information and feedback we receive from you).
- To establish a communication channel with you
3.2 Processed data
Each time our website is accessed, our system automatically collects data and information from the computer system of the calling computer. This is information such as
- IP address
- Date and time of your access
- Information about the type and version of your Internet browser
- the operating system of your computer or smartphone
- Browser used including language and version
- Geographical location
- Websites from which you came to us
- Websites you visit from our website
We collect such technical information in so-called “log files” so that you can view our website correctly and we can determine the causes of any technical problems, for the technical optimization of our website and for the purpose of the security of our computer systems and networks. The legal basis for these purposes is the legitimate interest in processing the data pursuant to Art. 6 para. 1 lit. f GDPR. The collection of data for the provision of the website and the storage of the data in log files is mandatory for the operation of the website.
The data is deleted as soon as it is no longer required for the purpose for which it was collected. As a rule, this technical information is deleted or made unrecognizable after 6 months at the latest.
4 Contact requests for product information, sample orders, applications, or other concerns.
4.1 Description and scope of data processing
On our website you can contact us in various ways: among others via contact form, sample orders or the function “Apply”. If you use this option, the data entered in the input mask will be transmitted to us and stored. In addition to the specific data in the input mask, the IP address, the date and the time of the request are collected and stored.
Alternatively, it is possible to contact us by e-mail address. In this case, your personal data transmitted with the e-mail will be stored.
In this context, the data will not be passed on to third parties, unless this is necessary for the processing of the query. In this case, the data will be used exclusively for processing the request, unless otherwise agreed.
4.2 Legal basis for the processing
The legal basis for the processing of the data is the existence of an explicit consent of the user pursuant to. Art. 6 par. 1 lit. a GDPR.
4.3 Purpose of the data processing
The processing of personal data from the input mask serves us solely to process your inquiry or application.
4.4 Duration of storage
If you have requested samples or a quote, we reserve the right to retain the data for five years to measure the effectiveness of our sales and marketing efforts. Otherwise, we delete the data as soon as they are no longer required to achieve the purpose for which they were collected. For the personal data from the input mask of the contact form and those sent by e-mail, this is the case when the respective conversation with the user has ended. The conversation is ended when it is clear from the circumstances that the matter in question has been conclusively clarified.
For persons who have applied for a vacancy at BWB Surface Technology, shorter storage periods are applied to protect the personality of the person concerned. Applicant data will be stored and processed for as long as is necessary to achieve the purposes for which it was collected or as long as this is provided for in laws or regulations to which we are subject. At the latest 6 months after notification of rejection, your data will be anonymized and all application documents deleted. If you expressly agree to longer storage in our database (for future suitable jobs), we will delete the data later at an agreed time, but no later than after two years.
4.5 Possibility of appeal and removal
You have the possibility to revoke your consent to the processing of personal data at any time. If you contact us by e-mail, you can object to the storage of your personal data at any time. In such a case, the conversation cannot be continued. All personal data stored in the course of contacting us will be deleted in this case.
You can sign up to receive a free newsletter. When registering for the newsletter, the data entered in the input mask is also stored in order to provide the newsletter. The legal basis for this processing is Art. 6 para. 1 lit. a GDPR. Your e-mail address, the time of registration and the IP address used for registration will be stored for as long as you subscribe to our newsletter. Optionally, we will process your first name, last name, company name and country of residence to send you personalized newsletters. For sending the newsletter, we use the so-called double opt-in procedure, i.e. we will only send you a newsletter by e-mail if you have previously expressly confirmed that you want us to activate the newsletter service. Upon your registration, we will send you a notification email to the email address you provided and ask you to confirm that you would like to receive our newsletter by clicking on a link contained in that email.
You can object to the use of your data for advertising purposes by e-mail at any time with effect for the future. A notification in text form to firstname.lastname@example.org or to the contact details below is sufficient for this purpose. You will also find an unsubscribe link in every newsletter.
Your data will be processed with your consent for the purpose of sending the newsletter. Your data will be deleted again if you do not confirm receipt of the newsletter or you unsubscribe from the newsletter. There will be no use for other purposes.
The newsletter is sent using “MailChimp”, a newsletter sending platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA.
The e-mail addresses of our newsletter recipients, as well as their other data described in the context of this notice, are stored on the servers of MailChimp in the USA. MailChimp uses this information to send and evaluate the newsletters on our behalf. Furthermore, MailChimp may, according to its own information, use this data to optimize or improve its own services, e.g. for the technical optimization of the dispatch and the presentation of the newsletters or for economic purposes to determine from which countries the recipients come. However, MailChimp does not use the data of our newsletter recipients to write to them itself or to pass them on to third parties.
The newsletters contain a so-called “web-beacon”, i.e. a pixel-sized file that is retrieved from the MailChimp server when the newsletter is opened. Within the scope of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of the retrieval are initially collected. This information is used for the technical improvement of the services based on the technical data or the target groups and your reading behavior based on their retrieval locations (which can be determined with the help of the IP address) or the access times.
Statistical surveys also include determining whether newsletters are opened, when they are opened, and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our nor MailChimp’s intention to monitor individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.
6 Cookies and tracking technologies
7 Online presence in social networks
We maintain online presences in social networks in order to communicate there with customers and interested parties, among others, and to provide information about our products and services.
User data is usually processed by the respective social networks for market research and advertising purposes. In this way, usage profiles can be created that are based on the interests and surfing behavior of users. For this purpose, cookies and other identifiers are stored on users’ computers. Based on these usage profiles, advertising is then displayed within the social networks, for example, but also on third-party websites.
As part of the operation of our online presences, it is possible that we may access information such as statistics on the use of our online presences provided by the social networks. These statistics are aggregated and may include, in particular, demographic information and data about interaction with our online presences and the posts and content distributed through them. For details and links to the social network data that we, as operators of the online presences, can access, please refer to the list below.
The legal basis for data processing is Art. 6 para. 1 lit. a-b GDPR to stay in contact with our customers, to inform them and to carry out pre-contractual measures with future customers and prospects.
For the legal basis of the data processing carried out by the social networks under their own responsibility, please refer to the data protection notices of the respective social network. The following links will also provide you with further information on the respective data processing and on the options to object.
We would also like to point out that data protection concerns can be raised most efficiently with the respective provider of the social network, as only these providers have access to the data and can take appropriate measures directly. Below you will find a list with information about the social networks in which we operate online presences:
- LinkedIn (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland)
- Operation of the LinkedIn company page under joint responsibility on the basis of an agreement on joint processing of personal data (so-called Page Insights Joint Controller Addendum).
- Information on the processed Page Insights data and the contact option for data protection concerns: https://legal.linkedin.com/pages-joint-controller-addendum
- Sign off: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
- Instagram (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland)
- Google/YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)
- Google My Business (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)
- We operate a so-called Google My Business entry. Should you find us in this way, we use the information service offered by Google and the services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”).
- We do not know to what extent Google uses the collected data from your visit for its own purposes, to what extent activities of individual users are assigned, how long Google stores this data and whether data is passed on to third parties. When you access Google services, the IP address assigned to your terminal device is transmitted to Google. Google also stores information about its users’ end devices; this may enable Google to assign IP addresses to individual users or user accounts.
8 Links from third parties
Occasionally, at our sole discretion, we may offer third party products or services on our website. These third-party websites have separate, independent privacy policies. We therefore accept no responsibility or liability for the content and activities of these linked websites. Nevertheless, we try to protect the integrity of our website and welcome any feedback on these web pages.
9 Recipients of data and data transfer to third countries
9.1 Recipients of data
BWB Surface Technology does not sell, trade, or otherwise disclose personally identifiable information to third parties.
This does not apply to trusted third parties or processors who assist us in operating our website, conducting our business, or providing services to you. Such trusted parties may have access to personal data to the extent necessary. However, you are contractually obligated to keep your data confidential.
We only pass on the data we collect if this is necessary to fulfill a contract or to provide the technical functionality of the website, or if there is another legal basis for the transfer.
9.2 Data transfer to third countries
If a transfer to a third country is envisaged and no adequacy decision or appropriate safeguards are in place, there is a possibility and risk that authorities of the respective third country (e.g. intelligence services) may gain access to the transferred data in order to collect and analyze it, and that the enforceability of your rights as a data subject is not guaranteed.
10 Rights of data subjects
If personal data of yours is processed, you are a data subject according to the GDPR and you are entitled – after successful identification – to the following rights against us:
- Right of access (Article 15 GDPR)
- Right to erasure (Article 17 GDPR)
- Right of rectification (Article 16 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to withdraw your consent at any time (Article 7 (3) GDPR)
- Right to object (Article 21 GDPR).
To exercise your rights described here, you can contact us at any time using the contact details listed under“Contact addresses and data protection officers“.
Persons about whom we process personal data have a right of appeal to a competent supervisory authority for data protection. The supervisory authority for data protection in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).
11 Security and integrity of the data
Protecting the information you provide to us or that we obtain about you is our priority. We take appropriate security measures to protect your information from loss, misuse and unauthorized access, alteration, disclosure or destruction. BWB Surface Technology has taken measures to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services that process personal data and will restore availability and access to information in a timely manner in the event of a physical or technical incident.