Privacy overview
The website www.atorn.de serves the joint presentation of the ATORN tool brand by HAHN+KOLB Werkzeuge GmbH, Hommel Hercules Werkzeughandel GmbH & Co. KG and SARTORIUS Werkzeuge GmbH & Co. KG.
If you contact one of these companies directly, for example by e-mail, telephone, post or as part of a business relationship, the subsequent processing of your personal data may be carried out in accordance with the privacy notice applicable to the respective company. Please therefore also refer to the privacy notice of the company with which you are in contact or maintain a business relationship. These notices contain further information about the processing of personal data carried out by that company.
Privacy notice of HAHN+KOLB Werkzeuge GmbH:
https://www.hahn-kolb.de/de/hahn_kolb/rechtliches/datenschutz/datenschutz.php
Privacy notice of HOMMEL HERCULES Werkzeughandel GmbH & Co. KG:
https://www.hommel-hercules.com/de/infocenter/datenschutzerklaerung
Privacy notice of SARTORIUS Werkzeuge GmbH & Co. KG:
https://wwv.sartorius-werkzeuge.de/rechtliches/datenschutz/
The website www.atorn.de is jointly operated by the companies listed below.
HAHN+KOLB Werkzeuge GmbH
Schlieffenstraße 40
D-71636 Ludwigsburg
Telephone: +49 (0) 7141 498-40
E-mail: info@hahn-kolb.de
Hommel Hercules Werkzeughandel GmbH & Co. KG
Heidelberger Straße 52
D-68519 Viernheim
Telephone: +49 (0) 6204 739-0
E-mail: info@hommel-hercules.com
SARTORIUS Werkzeuge GmbH & Co. KG
Harkortstraße 54
D-40880 Ratingen
Telephone: +49 (0) 2102 4400-0
E-mail: info@sartorius-werkzeuge.de
Authorised representatives
HAHN+KOLB Werkzeuge GmbH: Managing Directors: Katrin Hummel, Steffen Vogl, Jacqueline Wiertz; shareholder: Adolf Würth GmbH & Co. KG, D-74653 Künzelsau
Hommel Hercules Werkzeughandel GmbH & Co. KG: General partner: Hommel Hercules-Meßtechnik, Verwaltungs-GmbH, registered office in Künzelsau, Managing Director: Dirk Adamczyk
SARTORIUS Werkzeuge GmbH & Co. KG: General partner: SARTORIUS Werkzeuge Beteiligungsgesellschaft mbH, 40880 Ratingen, Managing Directors: Karsten Bloch, Özcan Esen
E-mail address: info@hahn-kolb.de
Telephone: +49 7141 498-40
Legal notice: Legal notice
The following overview summarises the types of data processed, the purposes of processing and the categories of data subjects concerned.
Types of data processed
- Contact details
- Content data
- Usage data
- Meta, communications and procedural data
- Log data
Categories of data subjects
- Communication partners
- Users
Purposes of processing
- Communication
- Security measures
- Reach measurement
- Tracking
- Audience segmentation
- Organisational and administrative procedures
- Feedback
- Marketing
- Provision of our online services and user-friendliness
- Information technology infrastructure
Relevant legal bases under the GDPR: The following provides an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your country of residence or our country of registered office. If more specific legal bases apply in individual cases, we will inform you of these in the privacy notice.
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data.
National data protection provisions in Germany: In addition to the GDPR, national data protection provisions apply in Germany. This includes, in particular, the Federal Data Protection Act (BDSG). The BDSG contains specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers and automated decision-making in individual cases, including profiling. Data protection laws of the individual federal states may also apply.
Note on the applicability of the GDPR and the Swiss FADP: This privacy information serves to provide information in accordance with both the Swiss FADP and the General Data Protection Regulation (GDPR). Please note that, due to the broader territorial scope and for ease of understanding, the terms used in the GDPR are applied. In particular, the terms “processing” of “personal data”, “legitimate interest” and “special categories of data” used in the GDPR are used instead of the terms “processing” of “personal data”, “overriding interest” and “particularly sensitive personal data” used in the Swiss FADP. The legal meaning of these terms remains governed by the Swiss FADP where it applies.
In accordance with the statutory requirements, and taking into account the state of the art, the implementation costs, the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input, disclosure, availability and separation of the data. We have also established procedures to ensure that data subjects can exercise their rights, that data can be erased and that threats to data are addressed. Furthermore, we take the protection of personal data into account from the outset when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and data protection by default.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect users’ data transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions comply with the highest security standards. If a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL. This indicates to users that their data is transmitted securely and in encrypted form.
As part of our processing of personal data, it may be necessary to transfer or disclose such data to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data to protect your data.
Data transfers within the group of companies: We may transfer personal data to other companies within our group or grant them access to it. This data sharing is based on our legitimate business and commercial interests. These include, for example, improving business processes, ensuring efficient and effective internal communication, making optimal use of our personnel and technological resources and enabling well-founded business decisions. In certain cases, data sharing may also be necessary to fulfil our contractual obligations, or it may be based on the consent of the data subjects or a statutory authorisation.
We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consent is withdrawn or there are no longer any other legal bases for processing. This applies in cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions apply where statutory obligations or particular interests require data to be retained or archived for longer.
In particular, data that must be retained for commercial or tax reasons, or whose storage is necessary for the pursuit of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy information contains additional details on the retention and erasure of data that apply specifically to certain processing activities.
If several retention periods or erasure deadlines are specified for data, the longest period shall always apply. Data that is retained not for its original purpose but due to statutory requirements or other reasons is processed solely for the purposes that justify its retention.
Retention and erasure of data: The following general periods apply to the retention and archiving of data under German law:
- 10 years – retention period for books and records, annual accounts, inventories, management reports, opening balance sheets, as well as the operating instructions and other organisational documents required to understand them
- 8 years – accounting records, such as invoices and cost records
- 6 years – other business documents, in particular commercial or business letters and other documents relevant for taxation
- 3 years – data required to take potential warranty and damages claims or similar contractual claims and rights into account, and to process related enquiries
Period beginning at the end of the year: If a period does not expressly begin on a specific date and is at least one year long, it automatically begins at the end of the calendar year in which the event triggering the period occurred.
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you.
- Right to withdraw consent: You have the right to withdraw consent at any time.
- Right of access: You have the right to request confirmation as to whether personal data concerning you is being processed, as well as access to that data and a copy of it in accordance with the statutory requirements.
- Right to rectification: You have the right to request the completion or rectification of inaccurate personal data concerning you.
- Right to erasure and restriction of processing: You have the right to request the erasure of personal data concerning you or, alternatively, the restriction of its processing in accordance with the statutory requirements.
- Right to data portability: You have the right to receive personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
- Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR.
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: Usage data; meta, communications and procedural data; log data
- Data subjects: Users, e.g. website visitors and users of online services
- Purposes: Provision of our online services and user-friendliness; information technology infrastructure; security measures
- Retention and erasure: Erasure in accordance with the information in the section “General information on data storage and deletion”
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR)
Further information: To provide our online services, we use storage space, computing capacity and software from a server provider. Access is recorded in server log files. Log file information is stored for a maximum of 30 days and then erased or anonymised. Data requiring further retention as evidence is exempt from erasure until the relevant incident has been finally clarified.
The term “cookies” refers to functions that store information on users’ devices and read it from them. Cookies may be used for various purposes, such as ensuring the functionality, security and convenience of online services and analysing visitor traffic.
We use cookies in accordance with the statutory provisions. Where required, we obtain users’ consent in advance. If consent is not required, we rely on our legitimate interests. Consent may be withdrawn at any time.
Storage period:
- Temporary cookies: These are deleted at the latest once a user has left an online service and closed their device.
- Permanent cookies: These remain stored even after the device has been closed. Unless explicit information is provided, the storage period may be up to two years.
General information on withdrawal and objection: Users may withdraw their consent at any time and object to processing in accordance with the statutory provisions.
- Types of data processed: Meta, communications and procedural data
- Data subjects: Users
- Legal bases: Legitimate interests and consent
Consent management: We use a consent management solution to obtain, record, manage and withdraw consent. Consent is stored for up to two years.
When you contact us, for example by post, contact form, e-mail, telephone or via social media, or as part of an existing user or business relationship, we process the information provided by the enquirer where this is necessary to respond to the enquiry and take any requested action.
- Types of data processed: Contact details and content data
- Data subjects: Communication partners
- Purposes: Communication; organisational and administrative procedures; feedback; provision of our online services and user-friendliness
- Retention and erasure: Erasure in accordance with the information in the section “General information on data storage and deletion”
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR)
We integrate functional and content elements into our online services that are obtained from the servers of the respective third-party providers. These may include graphics, videos or maps, for example.
Such integration requires the third-party providers to process users’ IP addresses, as they would not be able to send the content to users’ browsers without the IP address. Third-party providers may also use pixel tags for statistical or marketing purposes.
Information on the legal bases: If we request consent for the use of third-party providers, consent constitutes the legal basis. Otherwise, user data is processed on the basis of our legitimate interests.
- Google Fonts: The fonts are hosted on our own server; no data is transmitted to Google.
- YouTube videos: Video content; service provider: Google Ireland Limited, Dublin, Ireland; legal basis: consent. Website · Privacy policy.
We ask you to regularly review the content of our privacy notice. We update the privacy notice as soon as changes to the processing activities carried out by us make this necessary. We will inform you as soon as the changes require your cooperation, for example by providing consent, or require other individual notification.
If we provide addresses and contact details of companies and organisations in this privacy notice, please note that these details may change over time. Please check the information before contacting them.
