Privacy Policy
We manufacture die-cut and adhesive die-cut parts precisely to your specifications – from development and prototyping to series production. Modern die-cutting technology, precise laser manufacturing, cleanroom technology, and reliable adhesive solutions ensure that your components fit perfectly and are reproducible every time.
The protection of your personal data is important to us, therefore we want to provide you with information about contact options and data subjects as simply and accurately as possible.
First, you will find information below about how to contact our data protection officer and options for encrypted communication. Next, we will explain the legal and technical terms used throughout this document. Following this, you will find an overview of the rights of data subjects. Next, you will find information about the data controller. Finally, we will discuss the technologies and services used and how we handle data protection.
1. Contact the Data Protection Officer
Should you have any questions or require further information, you can contact our external data protection officer at any time. Contact details are as follows:
Oliver Offenburger, M.Sc.
Email: datenschutz@gsform.de
eye-i4 GmbH
Data Protection Department
Mönchweilerstraße 12
78048 Villingen-Schwenningen
Phone: 07721 69724 00
Fax: 07721 69724 01
Website: https://eye-i4.de
Our preferred method of contact is email. However, you are also welcome to contact the data protection officer by post or telephone. If you wish to encrypt your email to our data protection officer, we recommend that you read the following section.
Instructions for inquiries:
If you contact us by email during regular business hours, we will confirm receipt of your message on the same day. If you do not receive a confirmation, please contact us by phone.
If you submit a request by mail, we will send you confirmation of receipt on the same day it is sent, but no later than one day after. If you do not receive confirmation, please contact us by phone.
For telephone inquiries, please use the telephone number of our data protection partner, eye-i4 GmbH, directly.
1.1 Encryption of emails to our data protection officer
We advocate for encrypted email communication. Therefore, to ensure confidentiality and integrity, we offer you the option of encrypting your requests to the data protection officer.
We use PGP for encryption. Information about free usage options and setup can be found on our data protection partner's website, see the following link: https://eye-i4.de/blog-kostenlose-pgp-verschluesselung.html
You can download our PGP key via the link below:
[Icon] [Link to PGP key]
Should you wish to verify the fingerprint, please contact our data protection partner, eye-i4 GmbH, by telephone.
If you have any further questions about encryption, please contact our data protection officer.
2 terms in a legal context
Before discussing legal matters further, we would first like to introduce the relevant terms:
2.1 EU GDPR (also called GDPR)
The term EU GDPR (hereinafter also referred to as "GDPR") refers to the General Data Protection Regulation. This is a regulation of the European Union that governs how personal data may be processed. For informational purposes, the text of the GDPR can be viewed via the following link: https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32016R0679
2.2 responsible
‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law.
2.3 Personal data and data subject
"Personal data" means any information relating to an identified or identifiable natural person (hereinafter the "data subject"); a natural person is regarded as identifiable, which can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special features, the expression of the physical , physiological, genetic, mental, economic, cultural or social identity of this natural person.
2.4 processing
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
2.5 Restriction of processing
“Restriction of processing” means marking stored personal data with the aim of limiting its future processing.
2.6 Data processors
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
2.7 receiver
The “recipient” is a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
2.8 Third
“Third party” means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
2.9 Consent
‘Consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
2.10 Personal data breach
“Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
2.11 Health data
“Health data” means personal data relating to the physical or mental health of a natural person, including the provision of health services, and revealing information about their health status.
2.12 companies
“Undertaking” means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations that regularly engage in an economic activity.
2.13 Supervisory Authority
The ‘supervisory authority’ is an independent public authority established by a Member State in accordance with Article 51.
2.14 Relevant and substantiated objection
The ‘relevant and reasoned objection’ means an objection as to whether or not there has been an infringement of this Regulation or whether the proposed action against the controller or processor complies with this Regulation, and where the objection clearly demonstrates the scope of the risks posed by the draft decision in relation to the fundamental rights and freedoms of data subjects and, where applicable, the free movement of personal data within the Union.
3 terms in a technical context
Before discussing technical matters further, we would first like to introduce the relevant terms:
3.1 File system
The “filing system” is any structured collection of personal data which is accessible according to specific criteria, regardless of whether this collection is maintained centrally, decentrally or according to functional or geographical considerations.
3.2 Cookies
Cookies are text files that a website stores on your device via your browser. These text files can be used to implement technical functions such as a shopping cart mechanism, or to identify your browsing behavior. For this purpose, the text files can contain identifying information and additional data.
You have the option to prevent the storage of cookies in your browser settings. Disabling cookies may result in technical limitations when using the website.
Details about the cookies used:
NID
The cookie is included in requests sent by browsers to Google websites. The NID cookie contains a unique ID that Google uses to store your preferences and other information, such as your preferred language (e.g., German), the number of search results to display per page (e.g., 10 or 20), and whether the Google SafeSearch filter should be enabled. You can find more detailed information at the following link: https://www.google.com/policies/technologies/types/
3.3 Server logs
Server logs are log files created by the web server that document access to a website. A log entry can contain a variety of information, such as the access time, browser type, visitor's IP address, etc.
3.4 Referrer
The referrer is the website from which a user accessed the website of the data controller. The referrer can be read from server logs, for example.
4 rights of the data subject
The rights of data subjects arise from the GDPR and the respective national data protection laws. Should you wish to exercise your rights, please contact our data protection officer using the method described above. Below, we would like to inform you of your rights arising from the GDPR, in particular Chapter 3:
4.1 Duty to provide information
The data subject has the right to obtain information about the personal data stored about them, whether or not the data was collected directly from them. This is regulated in Chapter 3, Articles 13 and 14 of the GDPR.
4.2 right to information
The data subject has the right to request confirmation from the controller as to whether personal data concerning him or her are being processed; if this is the case, he or she has the right to access this personal data and to further information in accordance with Article 15 GDPR.
4.3 right to rectification
The data subject has the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.
Taking into account the purposes of the processing, the data subject has the right to request the completion of incomplete personal data, including by means of a supplementary statement.
4.4 Right to Erasure
The data subject has the right to request from the controller the erasure of personal data concerning him or her without undue delay, and the controller is obliged to erase personal data without undue delay where one of the grounds set out in Article 17 of the GDPR applies.
4.5 right to restriction of processing
The data subject has the right to request from the controller the restriction of processing if one of the conditions set out in Article 18 GDPR is met.
4.6 Duty to notify
The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Articles 16, 17(1) and 18 of the GDPR to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
The controller shall inform the data subject about these recipients if the data subject requests it.
4.7 right to data portability
The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller without hindrance from the controller to whom the personal data have been provided.
4.8 right of objection
The data subject has the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
4.9 Complaint to the supervisory authority
According to Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. Generally, you can contact the supervisory authority of your habitual residence, your place of work, or the location of the data controller's registered office.
Our responsible supervisory authority is: State Commissioner for Data Protection and Freedom of Information, Stuttgart
5. Information about the responsible party
The controller pursuant to Article 24 GDPR is listed below:
GS Form- & Stanzteile GmbH
Niederwiesenstraße 30
78050 Villingen-Schwenningen
Further information about the responsible party can be found in the legal notice.
6 Web technologies used
6.1 Server logs
When you use our website for purely informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security (legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR):
- Anonymized IP address,
- Date and time of the request,
- Time zone difference to Greenwich Mean Time (GMT),
- Content of the request (specific page),
- Access status/HTTP status code,
- each data volume transferred,
- Website from which the request originates (referrer),
- browsers,
- Operating system and its interface
- Language and version of the browser software.
6.2 Google Maps
On this website we use the offer of Google Maps. This enables us to show you interactive maps directly on the website and enables you to conveniently use the map function.
By visiting our website, Google receives the information that you have accessed the corresponding subpage. This occurs regardless of whether Google provides a user account that you are logged into, or whether no user account exists. If you are logged into Google, your data will be directly associated with your account. If you do not want this association with your Google profile, you must log out before activating the button. Google stores your data as usage profiles and uses them for advertising, market research, and/or the needs-based design of its website. Such analysis is carried out in particular (even for users who are not logged in) to provide targeted advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and to exercise this right, you must contact Google.
Further information on the purpose and scope of data collection and its processing by the plug-in provider can be found in the provider's privacy policy. There you will also find further information on your related rights and settings options to protect your privacy: http://www.google.de/intl/de/policies/privacy . Google also processes your personal data in the USA and has committed to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
7 Duration of storage
Unless specifically stated, we store personal data only as long as necessary to fulfill the purposes pursued.
In some cases, the legislator provides for the retention of personal data, for example in tax or commercial law. In these cases, the data will be stored by us only for these legal purposes, but not otherwise processed and deleted after expiration of the statutory retention period.
8 Disclosure to third parties
A transfer of your personal data to third parties for purposes other than those listed below does not take place.
We only share your personal information with third parties if:
- You have given your explicit consent in accordance with Art. 6 para. 1 sentence 1 lit. a. GDPR,
- the transfer is necessary pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR for the establishment, exercise or defense of legal claims and there is no reason to assume that you have an overriding legitimate interest in not having your data transferred,
- in the event that there is a legal obligation to disclose the data pursuant to Art. 6 para. 1 sentence 1 lit. c GDPR, as well as
- This is legally permissible and necessary for the performance of a contract with you in accordance with Article 6(1)(b) GDPR.