Privacy Policy
This data protection information explains how and for what purposes HanseMerkur Trust AG processes your personal data and what rights and options you have in this regard. It applies to all personal data you provide to HanseMerkur Trust AG or that arises from your contractual relationship or other interaction with HanseMerkur Trust AG.
Who is responsible for your personal data
We, HanseMerkur Trust AG, Neue Rabenstrasse 3, 20354 Hamburg, are the controller for all personal data you provide to us within the scope of our business relationship.
Categories of personal data we collect
We collect and process in particular the following categories of personal data:
-
Contact information such as full name, business address, business telephone number, business mobile number, business fax number, and business email address, your mobile phone's identification number, and the IP address of your computer when you use our websites.
-
Further business information that is necessarily processed in a contractual or other contractual relationship with HanseMerkur Trust AG or provided voluntarily by you, such as placed orders, purchases, services and other business transactions, product feedback and other information that you provide to us in the context of a business relationship or that arises from it.
-
Information we obtain from public sources, databases, and credit agencies.
-
Insofar as we are legally obliged to do so, we collect information for compliance purposes, for example, about legal disputes or court proceedings in which you or persons with whom you are in a business relationship are involved, as well as information about interactions with you that may be relevant under antitrust law.
-
Technical data: when you access our website www.hmt-ag.de, the browser used on your device automatically sends information to our website's server. This information is temporarily stored in a so-called log file. The following information is collected without your intervention and stored until automated deletion (in particular the IP address of the requesting computer, date and time of access, name and URL of the retrieved file, website from which access was made (referrer URL), browser used and, if applicable, the operating system of your computer, and the name of your access provider).
-
Special categories of personal data. In connection with registering for an event or seminar and granting access to it, it is possible that we may request information about your health to determine any disability or special dietary needs on your part and to take these into account. Any such information will only be used with your consent. If you do not provide us with information about disabilities or special dietary needs, we cannot make appropriate arrangements.
Access data
We, the website operator or page provider, collect data about access to the website based on our legitimate interest (see Art. 6 Para. 1 lit. f. GDPR) and store it as "server log files" on the website's server. The following data is logged in this way:
-
Visited website
-
Time of access
-
Amount of data sent in bytes
-
Source/referrer from which you accessed the page
-
Browser used
-
Operating system used
-
IP address used
The server log files are stored for a maximum of 7 days and then deleted. Data is stored for security reasons, for example, to be able to investigate cases of abuse. If data must be kept for evidentiary purposes, they are excluded from deletion until the incident is finally clarified.
Cookies
We use cookies. Cookies are small text files that are stored on your device when you visit the page. These can neither transmit viruses nor malware to your computer, but they can contain information that enables user identification.
A distinction must be made between transient cookies, which are deleted as soon as your browser is closed, and persistent cookies, which are stored beyond the respective session and recognize you on your next visit to the website.
Regarding their function, a distinction must be made between technically necessary and non-necessary cookies.
Technically necessary cookies
Here you will find all cookies that are required for the operation of our website and its functions (technically necessary cookies). These are generally set in response to an action you have taken. It is possible to deactivate these cookies in your browser. In this case, the error-free functioning of our website can no longer be guaranteed.
Plugins and Tools
Google Maps
This site uses the Google Maps map service via an API. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
To use the functions of Google Maps, it is necessary to save your IP address. This information is usually transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transmission.
The use of Google Maps is in the interest of an appealing presentation of our online offers and an easy findability of the locations we have indicated on the website. This represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
More information on the handling of user data can be found in Google's privacy policy:
https://www.google.de/intl/de/policies/privacy/.
For what purposes we use your personal data
We will use your personal data exclusively for the following purposes ("Permissible Purposes"):
-
Initiation, execution, and management of your contractual relationship (or your organization's contractual relationship) with HanseMerkur Trust AG Group, e.g., by executing transactions and orders for products or services, processing payment transactions, accounting, auditing, invoicing, and debt collection activities, arranging shipments and deliveries, repairs, and providing support services or other services that you may have commissioned or requested.
-
Maintaining and protecting the security of our products, services, and websites or other systems, preventing and detecting security risks, fraud, or other criminal or unlawful acts.
-
General compliance purposes, in particular to ensure compliance with our legal and regulatory obligations and requirements, such as compliance screenings or record-keeping obligations (e.g., due to competition law, export law, trade sanctions and embargo regulations or for the prevention of white-collar crime or money laundering). This may include the following measures: matching your contact or identity data against relevant sanctions lists and confirming your identity in case of a possible match, recording your cooperation with third parties insofar as this may be relevant under antitrust law, reports to or inspections by competent supervisory, law enforcement or other competent authorities.
-
Information within an existing business relationship about similar or related products or services from HanseMerkur Trust AG, insofar as this is permissible under applicable law.
-
Resolution of disputes, enforcement of our contractual agreements, and the establishment, exercise or defense of legal claims or ensuring compliance with legal obligations, e.g., retaining sales records for tax purposes or sending legally required notices and other announcements.
Insofar as you have explicitly given us your consent, we may also use your personal data for the following purposes:
-
Communication with you via the communication channels to which you have consented, to keep you informed about the latest announcements, offers and other information about HanseMerkur Trust AG products, technologies and services (including marketing-related newsletters) as well as
-
HanseMerkur Trust AG events and projects;
-
Managing and conducting customer surveys, marketing campaigns, market analyses, competitions or other promotional activities or events or
Please note: Pursuant to Article 21 (2) EU General Data Protection Regulation ("GDPR"), you have the right to object to the processing of your personal data for marketing purposes. Please refer to the "Your Rights" section for a detailed explanation of your rights and how to assert them.
We will only communicate with you for promotional purposes (e.g., by emails and phone calls) if you have explicitly consented to this beforehand, as required by law. You have the option to withdraw your consent at any time if you no longer wish to receive marketing-related information from us.
We will not use your personal data to make automated decisions concerning you or to create profiles in any other way than described above.
The legal bases for processing your personal data are set out in Article 6 GDPR. Depending on which of the permissible purposes described above we process your personal data for, the processing is carried out either for the performance of a contract or another business agreement with HanseMerkur Trust AG, or to comply with our legal obligations, or to safeguard the legitimate interests of HanseMerkur Trust AG or third parties, always provided that your interests or fundamental rights and freedoms do not outweigh and oppose processing. Furthermore, processing may take place on the basis of your explicit consent, if you have given it to us.
How we collect and use your personal data
Typically, we will collect your personal data directly from you during our interaction, for example, when you visit our website, communicate with us regarding our products and services, place an order, subscribe to our newsletter, or participate in our customer surveys.
If you have given us your explicit consent, we may also receive your personal data from third parties for marketing purposes. Should this be the case, you will be informed in accordance with applicable law.
Where personal data is processed
HanseMerkur Trust AG is a globally active company. In the course of our business activities, it is possible that we may also transfer your personal data to recipients in countries outside the European Economic Area ("third countries") where the level of data protection is not the same as in your home country. Insofar as we do so, we comply with the applicable data protection requirements and take appropriate security measures to ensure that your personal data is protected and secure, in particular by agreeing to EU standard contractual clauses, which are available [here]. If you would like more information about these security measures, you can contact us at any time using the contact details below.
How we protect your personal data
To protect your personal data, we take physical, electronic, and process-technical security measures that comply with the current state of the art and legal data protection requirements. These protective measures include the implementation of certain technologies and procedures to protect your privacy, such as secure servers, firewalls, and SSL encryption. We always act in accordance with applicable laws and regulations regarding the confidentiality and security of personal data.
To whom we disclose your personal data
We may disclose your personal data as follows:
-
to our affiliated companies worldwide, if and to the extent necessary for the permissible purposes described above and legally permitted. In such cases, these companies will only use the personal data for the same permissible purposes and under the same conditions as stated above.
-
to service providers (so-called processors) within or outside the HanseMerkur Trust AG Group, domestically or abroad (e.g., shared service centers or cloud providers), who have been commissioned by us to process personal data on our behalf and exclusively according to our instructions for the permissible purposes. HanseMerkur Trust AG retains control over and responsibility for your personal data and will take appropriate protective measures required by applicable law to ensure the integrity and security of your personal data when engaging such service providers.
-
to courts, law enforcement agencies, or other competent authorities or lawyers insofar as legally permissible and necessary to comply with a legal obligation or for the establishment, exercise, or defense of legal claims.
-
to credit agencies and other companies in the context of credit decisions, to prevent fraud and for debt collection.
-
Furthermore, your personal data may also be disclosed to third parties if we sell or buy parts of a business or assets; in this case, we may disclose personal data to the prospective buyer or seller and their advisors. Should HanseMerkur Trust AG or substantially all of its assets be acquired by a third party, the personal data we store about customers and other contact persons will be part of the transferred assets.
Otherwise, we will only disclose your personal data if you instruct us to do so or give your consent, if we are legally obliged to do so due to a judicial or official order, or if we suspect fraudulent or criminal acts.
How long we store your personal data
We will store your personal data for as long as necessary to provide the commissioned services or products or requested information and to carry out and manage our business relationship with you. If you have asked us not to contact you, we will retain this information for as long as necessary to fulfill this request. Furthermore, we are legally obliged to retain certain types of personal data for certain periods (e.g., due to commercial or tax law retention obligations). Your personal data will be deleted immediately if they are no longer required for these purposes.
Your Rights
Under certain legally defined conditions, you can request information about your personal data, its rectification or erasure, or the restriction of its processing. You can also object to the processing or assert your right to data portability. In particular, you have the right to request a copy of the personal data we hold about you. If you make such requests repeatedly, we may charge a fee for this. For more detailed information about your data protection rights, please refer to Articles 15-22 GDPR.
If you have consented to the processing of your personal data, you can withdraw your consent at any time with effect for the future, i.e., the withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. In the event of a withdrawal of consent, we will only continue to process the personal data if there is another legal basis for the processing or if we are legally obliged to do so.
To make any of the aforementioned requests, please send a brief description of the personal data in question to the contact address below. We may require additional proof of identity to protect your personal data from unauthorized access. We will carefully review your request and, if necessary, discuss with you how best to fulfill it.
If you have concerns about how we process your personal data or wish to file a complaint, you can contact us at the contact address below to have this investigated. If you are not satisfied with our response or believe that we are not processing your personal data in accordance with applicable law, you can lodge a complaint with the competent supervisory authority for data protection in your country. The data protection supervisory authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationssicherheit (The Hamburg Commissioner for Data Protection and Freedom of Information)
Ludwig-Erhard-Str 22, 7. OG
20459 Hamburg
Obligation to provide personal data
In general, you provide us with your personal data on a voluntary basis. As a rule, there are no adverse consequences for you if you do not consent or do not provide your personal data. However, there are cases in which HanseMerkur Trust AG cannot act without certain personal data, e.g., if this personal data is necessary to process your orders, give you access to an online offer or newsletter, or carry out a legally required compliance check. In these cases, HanseMerkur Trust AG unfortunately cannot fulfill your request without the relevant personal data.
If I am under 16 years old
If you are under 16 years old, you need the consent of your parents/guardian before providing us with your personal data. Persons under 16 years of age are not permitted to submit their personal data to us without such consent.
Changes to this information
This data protection information was last amended in October 2023. We may amend or supplement this information if this becomes necessary due to changes in the way data is processed or in the legal framework. Please therefore check from time to time or when you provide us with personal data whether any changes have occurred. Changes to the data protection information are effective from the date they are published on our website.
How to contact us
If you have any questions or wish to exercise your rights, please click [here]. You can also contact us in writing at:
Contact details of the Data Protection Officer
HanseMerkur Trust AG
Betrieblicher Datenschutzbeauftragter (Company Data Protection Officer)
Herr Thomas Prigge
Neue Rabenstrasse 3
20354 Hamburg
E-Mail: datenschutz@hmt-ag.de