Data Protection Declaration
Thank you for your interest in our website.
The protection of your personal data during the collection, processing and use on the occasion of your visit to our website is an important concern for us. Your data is protected within the framework of the legal regulations.
Please take a moment and read the following information. They will inform you about how we handle your personal data, how and for what purpose this data is used, to whom we pass this data on and how we protect your personal data.
Your personal rights are our highest priority and we do our best to protect and guarantee these rights.
Controller of the processing of your personal data in accordance with the General Data Protection Regulation is:
Haworth GmbH
Am Deisterbahnhof 6,
31848 Bad Münder am Deister
Germany
Phone: +49 (0) 5042 501 180
E-Mail: shopping@haworth.com
Business Registration Number: hrb 212482
Data Protection Officer
If you have any questions regarding data protection, our data protection officer S-CON DATENSCHUTZ,
Kriegerstraße 44, 30161 Hannover, Germany, will be pleased to assist you (datenschutzteam124@s-con.de).
Collection and processing of data
Every access to our website and every retrieval of a file stored on the website is logged. The storage serves internal system-related and statistical purposes.
The following will be logged:
- Name of the retrieved file,
- Date and time of the retrieval,
- transferred data volume,
- Message about successful retrieval,
- the operating system used,
- Browser and browser type,
- the website from which the redirection was made,
- the Internet service provider,
- visited pages and
- requesting domain.
In addition, the IP addresses of the requesting computers are logged. However, the person responsible does not draw any conclusions about a person.
This data is only required to be able to display the contents of our website correctly, to optimise the contents permanently for you and to support criminal prosecution in case of hacker attacks. The data is processed on the basis of our legitimate interest in accordance with Art. 6 paragraph 1 subparagraph 1 lit. f) GDPR. The processing of the data is necessary for the operation of the website.
The data is stored for as long as it is needed to fulfil the purpose and then automatically deleted.
Rights of data subjects
In accordance with Art. 15 GDPR, you have a right to information about the processing of your personal data.
Furthermore, you are free to exercise your rights of correction, deletion or, if deletion is not possible, restriction of processing and data transferability in accordance with articles 16-18, 20 GDPR. Should you wish to exercise this right, please contact our data protection officer.
Furthermore, you have the right to complain to the responsible supervisory authority at any time. If you are of the opinion that your personal data is not being processed in compliance with the data protection laws, we would politely ask you to contact our data protection officer.
In addition, you have the right to object to the processing of your personal data at any time in accordance with Art. 13 paragraph 2 lit. b) GDPR.
Contact form
All your personal data and other information that you provide us with via the contact form set up on our website will only be collected and processed for the purpose of processing and answering your enquiries on the basis of Art. 6 paragraph 1 subparagraph 1 lit. a) and b) GDPR. Your data will be forwarded to us via our provider by e-mail. In case of non-availability, it is unfortunately not possible for us to contact you and process your request. An automated decision making process will not be carried out.
Your personal data will not be forwarded to external third parties.
A transfer of the personal data provided by you to a third country or an international organisation does not take place and is not planned.
You have the right to revoke your consent at any time with effect for the future. The legality of the data processing carried out up to the revocation remains unaffected.
Your personal data, which you communicate to us via the contact form, will be stored by us for the duration of processing your request and will be deleted or blocked immediately after processing.
E-Mail-Contact
On our website it is possible to contact us via the e-mail address provided. If you take this opportunity, the personal data transmitted with the e-mail will be stored and only collected and processed for the purpose of processing and answering your enquiries on the basis of Art. 6 paragraph 1 subparagraph 1 lit. a) and b) GDPR. In the event of non-availability, it is unfortunately not possible for us to process your request. An automated decision making process will not be carried out.
Your personal data will not be forwarded to external third parties.
A transfer of the personal data provided by you to a third country or an international organisation does not take place and is not planned.
You have the right to withdraw your consent at any time with effect for the future. The legality of the data processing carried out up to the revocation remains unaffected.
Your personal data, which you communicate to us, will be stored by us for the duration of the processing of your request and will be deleted or blocked immediately after processing.
Blog
If you are interested in our blog article, you will be automatically redirected to the website
https://blog.haworth.com/.
We would like to point out that with regard to the processing of personal data, the rules and data protection regulations there apply.
User-Log-In
All your personal data and other information that you provide us with when registering on our website and within the customer portal will only be collected and processed for the purpose of your registration and for processing and answering your enquiries on the basis of Art. 6 paragraph 1 subparagraph 1 lit. a) and b) GDPR. In the event of non-availability, it is unfortunately not possible for you to register on our website and it is not possible for us to answer your enquiries via the customer portal. An automated decision making process will not be carried out.
Your personal data will not be forwarded to external third parties.
A transfer of your personal data to a third country or an international organisation does not take place and is not planned.
You have the right to withdraw your consent at any time with effect for the future. The legality of the data processing until revocation remains unaffected.
Your personal data, which you provide to us via registration and in our customer portal, will be stored by us until you log out and, if necessary, in accordance with a statutory retention period.
Online order
All of your personal data and other information that you provide us with in the course of an online order will only be collected and processed for the purpose of processing your order in our web shop on the basis of Art. 6 paragraph 1 subparagraph 1 lit. b) GDPR. In case of non-availability, it is unfortunately not possible to accept an online order. An automated decision making process will not be carried out.
A transfer of the personal data provided by you to a third country or an international organisation does not take place and is not planned. Your personal data will not be transferred to external third parties.
Your personal data, which you provide us with when placing an online order, will be stored by us for the duration of the ordering process as well as stored in accordance with the legal retention period and deleted or blocked immediately after this period has expired.
Protection of stored data
We use technical and organizational security measures to protect the personal data you provide us from manipulation, loss, destruction or access by unauthorized persons. Our security measures are continuously improved and adapted to the state of the art. It cannot be ruled out that data transmitted by you without encryption may be viewed by third parties during transmission. It is pointed out that no conclusively secure transmission can be guaranteed with regard to data transmission via the Internet (e.g. communication by e-mail). Sensitive data should therefore either not be transmitted over the Internet at all or only via a secure connection (SSL).
Protection of minors
Consent to the processing of personal data can only be given by a person of full age. For information society services, the consent of a child is permissible from the age of sixteen years in accordance with Art. 8 GDPR.
Storage of anonymised data/cookies
Tracking cookies are used on this website. Cookies are text files that are stored on your computer and enable an analysis of your use of the website. However, these collect and store the data exclusively in pseudonymous form. They are not used to identify you personally and are not combined with data about the bearer of the pseudonym. We use this information to determine the attractiveness of our website and to continuously improve its content.
The legal basis for the use of tracking cookies is the consent given by you in accordance with Art. 6 paragraph 1 subparagraph 1 lit. a) GDPR.
You have the right to revoke your consent at any time with effect for the future. The legality of the data processing until revocation remains unaffected.
Your data will not be transferred to external bodies. You can delete the cookies on your PC at any time.
Technically necessary cookies (session cookies)
In addition to the use of cookies for analysis purposes, other cookies are used to make our website more user-friendly. In order to use the full range of functions of our website, it is therefore necessary for technical reasons to allow session cookies.
The purpose of using such cookies is to enable you to use the website in a simpler and more user-friendly manner. It is therefore necessary for the browser to be able to identify you even after a page change. The data stored and transmitted are language settings, items in the shopping cart and log-in information.
Cookies are required for the following applications:
Shopping cart in the online shop
Transfer of language settings
Registration in our portal
The data will not be used to create a user profile of you. The legal basis for the use of technical cookies is our legitimate interest according to Art. 6 paragraph 1 subparagraph 1 lit. f) GDPR. It is not possible to use the website without session cookies.
Google Analytics
This website uses Google Analytics, a web analysis service of Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland; hereinafter “Google”), which uses cookies. Cookies are text files which are stored on your computer and enable an analysis of your use of the website. Cookies usually transfer the information generated about your use of this website to a Google server in the USA and are stored there. However, since this website performs IP anonymisation, your IP address is first shortened by Google within member states of the European Union or in other states that are party to the Agreement on the European Economic Area.
Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. On our behalf, Google uses this information to evaluate your use of the website, to compile reports on the website activities and to provide further services to the website operator in connection with the use of the website and the Internet. The IP address transmitted by your browser within the framework of Google Analytics is not merged with other Google data.
You can prevent the storage of cookies by adjusting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all the functions of this website to their full extent. Furthermore, you can prevent the collection of the data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
The collection within the scope of this service will only take place after your explicit consent has been given.
You can prevent the collection of your data by Google Analytics at any time, even after you have given your consent, by clicking on the following link. An opt-out cookie is set, which prevents the future collection of your data when visiting this website: Deactivate Google Analytics.
If you delete the cookies in this browser, you will have to activate the opt-out cookie again.
The purpose of the survey is to evaluate the use of our website. Furthermore, we can use Google Analytics to create reports on website activities and thus improve our Internet presence. The legal basis for this is your consent in accordance with Art. 6 paragraph 1 subparagraph 1 lit. a) GDPR. Besides us, Google is to be mentioned as the recipient of the data. The data will be deleted as soon as they are no longer required for our recording purposes.
Google Translate
Our website uses Google Translate, a service of Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland; hereinafter referred to as “Google”) in order to be able to make the information on our website available to foreign-language visitors, as we only offer this service in German. By using Google Translate, you consent to the collection, processing and use by Google or one of its representatives or third parties of the data automatically collected during the use of Google Translate and the data you enter. This consent also forms the data protection legal basis for processing in accordance with Art. 6 paragraph 1 subparagraph 1 lit. a) GDPR. You have the right to revoke your consent at any time with effect for the future.
When using Google Translate, Google processes data on the use of the translation functions by the person concerned. You can find more information about the collection and processing of your data by Google and your rights as a data subject in this regard in the Google data protection declaration: https://policies.google.com/privacy?hl=de
It is possible that personal data may be transferred to Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) in the course of using this Google service. In this case, Google has submitted to the EU-US Privacy Shield, which regulates the protection of personal data transferred from the European Union to the USA. You can find further information at: https://www.privacyshield.gov/EU-US-Framework
WordPress Stats
Our website uses WordPress Stats. This is a service provided by Automattic, Inc. 132 Hawthorne Street, San Francisco, CA 94107, hereinafter “Automattic”. WordPress Stats uses, among other things, cookies that are stored on your computer and enable an analysis of the use of our website. As part of the use, data, such as IP address and user activity, may be transmitted to and stored on an Automattic server. This enables us to optimise our Internet presence for you and ensure a better user experience. This also represents our legitimate interest in accordance with Art. 6 paragraph 1 subparagraph 1 lit. f) GDPR.
Automattic may transfer this information to third parties where required by law or where such data is processed by third parties. You can prevent the collection and forwarding of personal data (in particular your IP address) and the processing of this data by deactivating the execution of the JavaScript in your browser.
For more information about the collection and processing of your data by WordPress Stats and your rights as a data subject, please refer to the WordPress Stats privacy policy below: http://automattic.com/privacy
Jetpack
Our website has integrated the Jetpack tool. The operating company of the Jetpack plug-in for WordPress is Automattic Inc. (132 Hawthorne Street, San Francisco, CA 94107, USA; hereinafter referred to as “Jetpack”). The operating company uses the tracking technology of Quantcast Inc. 201 Third Street, San Francisco, CA 94103, USA.
Jetpack is a WordPress plug-in that offers additional functions to the operator of a website based on WordPress. Among other things, Jetpack allows the website operator to obtain an overview of the visitors to the site. By displaying related articles and publications or the possibility of sharing content on the site, it is also possible to increase the number of visitors. In addition, security functions are integrated into Jetpack so that a website using Jetpack is better protected against brute force attacks. Jetpack also optimizes and accelerates the loading of the images integrated on the website.
Jetpack places a cookie on the information technology system of the person concerned. Each time the data subject calls up one of the individual pages of this website, which is operated by the data controller and on which a Jetpack component has been integrated, the Internet browser on the information technology system of the data subject is automatically prompted by the respective Jetpack component to transmit data to Automattic for analysis purposes. In the course of this technical process, Automattic obtains knowledge of data which is subsequently used to create an overview of the visits to the website. The data thus obtained is used to analyse the behaviour of the data subject who has accessed the controller’s website and is evaluated with the aim of optimising the website. The data collected via the Jetpack component will not be used to identify the data subject without the prior explicit consent of the data subject.
The legal basis for the use is the consent per cookie notice according to Art. 6 paragraph 1 subparagraph 1 lit. a) GDPR.
Automattic’s applicable data protection provisions are available at https://automattic.com/privacy/.
Social Media
We would like to get in contact with you and other interested parties, customers and users. For this we use different social networks. Which individual social networks we use can be found in the following section.
However, we would like to point out that we basically have no influence on which data is collected. As a rule, however, these are data which are used in the context of market research and for advertising purposes. This is usually done by creating user profiles and the interests identified from them. Through this it is possible to offer you customized advertising. For this reason, the use of social networks may also set cookies for you.
Furthermore, we would like to point out that your data may also be processed outside the European Union and that you therefore run the risk of not being able to enforce your rights properly. With regard to providers based in the United States, however, we would like to point out that an EU-US Privacy Shield exists, which guarantees an equivalent level of data protection as in the European Union.
In principle, we would like to provide you with information in the simplest and quickest way possible or give you the opportunity to share such information. Therefore, unless you have consented to data processing on the respective platform, the legal basis is our legitimate interest according to Art. 6 paragraph 1 subparagraph 1 lit. f) GDPR. If you have consented on the respective platform, your consent pursuant to Art. 6 paragraph 1 subparagraph 1 lit. a) GDPR is the legal basis of the processing. You have the right to revoke your consent at any time with effect for the future. The legality of the data processing until revocation remains unaffected.
Facebook (Link)
On our website, we use a reference (link) to our presence on the social network Facebook (Facebook fan page) to interact with Facebook users who call up the fan page. For this Facebook fan page we are affiliated with Facebook Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland; hereinafter referred to as “Facebook”) as the joint responsible party pursuant to Art. 26 of the General Data Protection Regulation (GDPR). The agreement on joint responsibility can be found under the following link: https://www.facebook.com/legal/terms/page_controller_addendum
We hereby inform you about the type and scope of personal data that is processed when using our Facebook fan page.
With the processing of your personal data, we pursue the purpose of providing visitors with an up-to-date information platform and an opportunity to interact on Facebook. The basis of the processing is therefore our legitimate interest according to Art. 6 paragraph 1 subparagraph 1 lit. f) GDPR. The interests of the users are always taken into account. Information on the legal basis for processing on Facebook can be found at http://www.facebook.com/about/privacy/legal_bases/.
When visiting our Facebook fan page, Facebook collects and processes personal data on the basis of the legitimate interest pursuant to Art. 6 paragraph 1 subparagraph 1 lit. f) GDPR. Part of this data is made available to us in summary form via the so-called “Insights” (Facebook user statistics). A cookie is stored for this purpose on the user’s end device. This serves to be able to use this information again at a later date. The cookie remains active for a period of two years if it is not deleted. Further information from Facebook on the use of cookies can be found in the Facebook cookie policy at https://de-de.facebook.com/policies/cookies/. The transmission of these usage statistics is exclusively in anonymous form and there is no possibility for us to access the data on which they are based.
Whether Facebook transfers personal data to third parties is beyond our control. It is possible that Facebook Inc., based in the USA, may process personal data outside the European Union. Facebook Inc. has been certified under the EU-US data protection agreement “Privacy Shield” and has thus committed itself to comply with European data protection regulations.
Personal data will not be passed on to third parties by us. You can find further information on the “Privacy Shield” at: https://www.facebook.com/about/privacyshield
If you are already logged in to Facebook via your personal user account, the information about your visit to our website will be automatically forwarded to Facebook. It is then possible for Facebook to assign the visit to the website to your account.
If you do not wish your data to be transmitted and stored by Facebook, please log out of your Facebook account.
Facebook plug-ins (Like and Share button)
You can recognize the Facebook plug-ins by the “Like, Share or Sendbuttons” (“Like”) on our website. These are provided by Facebook Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland; hereinafter: “Facebook”) and are subject to joint responsibility with Facebook for the area classified as data processing initiated by us, in accordance with Art. 26 GDPR. The joint responsibility of Facebook and us as website operators is limited to those processing operations where the purpose and means of processing are jointly decided. In the case of the Like and Share button, this is the collection of personal data and the transfer. A detailed overview of the Facebook plug-ins is available at the following link: http://developers.facebook.com/docs/plugins/.
When you visit our website, a direct connection is established between the Facebook server and your browser via the plug-in. This tells Facebook that you have visited our site using your IP address. If the “Like-Button” is clicked while you are logged in to your Facebook account, it is possible that you can link the contents of our website on your Facebook profile. This enables Facebook to assign your visit to our website to your user account.
Your data will only be transmitted after your express consent. We would like to point out that we have no knowledge of the content of the transmitted data or its use by Facebook. The Facebook data protection declaration can be found at: https://www.facebook.com/privacy/explanation.
Twitter (Link)
On our website we use a reference (link) to our presence in the social network Twitter. This is an application of Twitter Inc. (1355 Market St, Suite 900, San Francisco, CA 94103, USA; in the following: “Twitter”)
We would like to point out that we have no knowledge of the content of the transmitted data or its use by Twitter. You can find further information at: https://twitter.com/de/privacy
The Twitter function integrated on our website is provided by Twitter Inc. (1355 Market St, Suite 900, San Francisco, CA 94103, USA). By using this function, your visit to our website is linked to your Twitter account. In the course of this, the data is automatically transmitted to Twitter. If you do not want data to be transferred to Twitter, you can change your account settings on Twitter.
We would like to point out that we are not aware of the transmitted data, neither of its content nor of its use by Twitter. The privacy policy of Twitter can be accessed via: https://twitter.com/privacy?lang=de.
Twitter plug-ins (Like and Share button)
You can recognize the Twitter plug-ins by the “Like, Share or Sendbuttons” on our website. These are operated by the social network Twitter Inc. (1355 Market St, Suite 900, San Francisco, CA 94103, USA; hereinafter referred to as “Twitter”).
When you visit our website, a direct connection is established between the Twitter server and your browser via the plug-in. Twitter thereby receives the information that you have visited our site with your IP address. If the “Share-Button” is clicked while you are logged in to your Twitter account, it is possible that you can link the contents of our website on your Twitter profile. This enables Twitter to associate your visit to our website with your user account.
Your data will only be transmitted after your explicit consent. We would like to point out that we do not have any knowledge of the content of the transmitted data or its use by Twitter. You can find the Twitter privacy policy at: https://twitter.com/privacy?lang=de
LinkedIn (Link)
On our website we use a reference (link) to the social network LinkedIn, which is operated exclusively by LinkedIn Corporation (2029 Stierlin Court, Mountain View, CA 94043, USA; hereinafter referred to as “LinkedIn”). The link is identified by the LinkedIn logo (no LinkedIn plug-in).
When you click on the LinkedIn logo, your browser establishes a direct connection to the LinkedIn servers. If you are already logged in to LinkedIn through your personal account, information about your visit to our website is automatically forwarded to LinkedIn. It is then possible for LinkedIn to associate your visit to the website with your account. We would like to point out that we have no knowledge of the content of the transmitted data or how LinkedIn uses it. The following link will take you to LinkedIn’s privacy policy: http://de.linkedin.com/legal/privacy-policy.
LinkedIn (plug-ins)
Our website integrates plug-ins from the LinkedIn social career network of LinkedIn Corporation (2029 Stierlin Court, Mountain View, CA 94043, USA; hereinafter “LinkedIn”). The LinkedIn plug-ins can be recognized by the LinkedIn logo or the “Share Button” (“Recommend”). When you call up our website, the plug-in establishes a direct connection between the LinkedIn server and your browser. This connection tells LinkedIn that you have visited our website using your IP address. If you are logged into your LinkedIn account and click the “Share Button” (“Recommend”), you have the option of linking content from our website on your LinkedIn profile. This will link your visit to our website to your LinkedIn account. We would like to point out that we have no knowledge of the content of the transmitted data or its use by LinkedIn. The following link will take you to LinkedIn’s privacy policy: http://de.linkedin.com/legal/privacy-policy.
Instagram (link)
On our website we use a reference (link) to our appearance in the social network Insta-gram. This is an application of Facebook Inc. (Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland; hereinafter referred to as “Facebook”)
We would like to point out that we have no knowledge of the content of the transmitted data or its use by Facebook. You can find further information at: https://help.instagram.com/519522125107875
The “Pin it” button of the Pinterest social network used on our website is operated by Pinterest Inc, (808 Brannan St, San Francisco, CA 94103, USA; hereinafter “Pinterest”). By using this feature, your visit to our website will be automatically linked to your Pinterest account. In the course of this, data will be transmitted to Pinterest. If you do not wish data to be transmitted to Pinterest, you must log out of your Pinterest account. Please note that we are not aware of the content of the data transmitted or how Pinterest uses it. Pinterest’s privacy policy can be accessed via: https://about.pinterest.com/de/privacy-policy.
Pinterest plug-in (Pin-it button)
You can recognize the Pinterest plug-in by the button with the “Pin-it” sign on a white background on our website. This is provided by Pinterest Inc. (808 Brannan St, San Francisco, CA 94103, USA; hereinafter “Pinterest”). An overview of the Pinterest plug-ins is available at the following link: https://developers.pinterest.com/docs/getting-started/introduction.
When you visit our website, a direct connection is established between the Pinterest server and your browser via the plug-in. Pinterest transmits the content of the plug-in directly to your browser and integrates it into the page. Even if you do not have a profile with Pinterest or are not logged in to Pinterest when you click on the button, the integration will inform Pinterest that your browser has called up the corresponding page on our website. Your browser sends this information (including your IP address) to a Pinterest server in the USA, where it is stored.
If you log in to Pinterest, your visit to our website is immediately linked to your Pinterest profile. If you interact with the plug-ins by clicking the “Pin it” button, the information will be transmitted directly to a Pinterest server, where it will be stored. In addition, the information is published on Pinterest and displayed to your contacts.
We would like to point out that we have no knowledge of the content of the data transmitted or how Pinterest uses it. The Pinterest Privacy Policy can be found at: https://about.pinterest.com/de/privacy-policy.
YouTube (appearance)
We run a presence on the YouTube video platform. This is an application of YouTube LLC (901 Cherry Ave, San Bruno, CA 94066 USA; hereinafter: “YouTube”).
We would like to point out that we have no knowledge of the content of the transmitted data or its use by YouTube. You can find further information at: www.google.de/intl/de/policies/privacy/
It is possible that personal data may be transferred to the USA in the course of using this Google service. In this case Google has submitted to the EU-US Privacy Shield, which regulates the protection of personal data transferred from the European Union to the USA. You can find further information at:
https://www.privacyshield.gov/EU-US-Framework