Data protection
I. General information
1. Introduction
With the following Data Protection Information (Privacy Policy), we would like to inform you about which categories of your personal data (hereinafter also referred to as "data") we process for what purposes and to what extent when you visit our website www.nitrochemie.com.
2. Controller
The Controller pursuant to Art. 4 (7) of the General Data Protection Regulation (hereinafter referred to as GDPR) for the data processing on this website is:
Nitrochemie Wimmis AG
Niesenstraße 44
3752 Wimmis
Switzerland
Telephone: +41 33 22-81000
Telefax: +41 33 22-81330
Commercial Registry Office Berner Oberland
Company number: CH-092.3.001.139-0
UID-No.: CHE-108.693.134
Liebigstraße 17
84544 Aschau am Inn
Deutschland
Telephone: +49 8638 68-0
Telefax: +49 8638 68-375
Local District Court Traunstein
HRB 10968
USt-IdNr.: DE 812327671
3. Data Protection Officer
If you have any questions regarding the processing of your personal data, you can contact our Data Protection Officer.
Contact details of the data protection officer of Nitrochemie Aschau GmbHRheinmetall AG
Datenschutzbeauftragter
Rheinmetall Platz 1
40476 Düsseldorf
Germany
dsb-rhag@rheinmetall.com
II. Data processing activities on our website
In principle, you can visit our website without disclosing your identity. If you use certain functions/areas of our website, it may be necessary to provide or collect personal data, depending on the circumstances. In the following, we will go into the details of the respective data processing activities on our website.
1. Hosting of the website / logging of website visits
In order to provide our website securely and efficiently, we use the services of the web hosting provider net.DE AG (Büttnerstraße 57, 30165 Hannover, Germany; hereinafter "net.DE"), from whose servers the website is accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space and database services as well as security services and technical maintenance services provided by net.DE. In this regard, net.DE carries out data processing on our behalf in accordance with Art. 28 GDPR. The servers are located in Germany.
When you visit our website, we or net.DE collect data on each access to the server (so-called server log files). The collected data includes:
- IP address
- Date and time of your visit
- The browser you are using (incl. its version)
- The operating system you are using (incl. its version)
- Which resources (e.g. sub-page, contact form) you access on our website (is logged in the form of the so-called URL)
We process these server log files on the basis of our legitimate interest pursuant to Art. 6 (1) lit. f GDPR for the following purposes:
- Ensuring the security and stability of the website (e.g. avoiding server overloads due to abusive attacks, so-called DDoS attacks).
- Ensuring a proper connection to the website
- Ensuring a comfortable use of the website
- Evaluation of system security and stability
- For other administrative purposes
We may analyze these server log files retrospectively if we become aware of specific indications of unlawful use. The server log files will be deleted immediately if they are no longer required to achieve these purposes, but no later than 90 days after their collection.
Furthermore, this website is maintained and administered by our parent company Rheinmetall AG (Rheinmetall Platz 1, 40476 Düsseldorf, Germany) on our behalf. Nitrochemie is part of the Rheinmetall Group.
2. Use of cookies, web analysis & tracking
This website uses "cookies" and similar technologies. Cookies are text files that are stored on your terminal device and that enable, for example, individualization/adaptation of the website to your preferences, automatic recognition on your next visit, proper functioning of the website or analysis of the use of the website.
The specific use of cookies on our website is determined by your voluntary selection in the cookie banner, which is displayed to you in particular when you visit our website for the first time and/or by the corresponding settings of your browser.
Here we distinguish between three cookie categories:
(1) Essential or necessary cookies
Essential cookies ensure the correct functioning of the website. Without these cookies, malfunctions or error messages may occur.
(2) Functional cookies
Functional cookies facilitate a comfortable visit to the website and save settings, for example, so that you do not have to enter them again each time you visit the site. They also enable the use of certain functions on our website.
(3) Marketing cookies
Marketing cookies allow us to create evaluations of user behavior on our website and to measure the reach of our website. This gives us the opportunity to analyze the performance of the site and to improve it continuously.
2.1 Essential or necessary cookies
If you click on "Only necessary cookies" in the cookie banner or select only "essential cookies" or do not make any selection at all, only necessary cookies will be used. This includes the use of cookies from our cookie banner "Usercentric Consent Management Platform", which store your selection in the cookie banner so that you do not have to be asked to make a selection each time you call up a new sub-page or visit the website again (within a certain time frame). The use of these cookies for "the management of cookie selection / consent " is carried out in accordance with Art. 6 (1) lit. c GDPR to fulfill our obligations under data protection law to provide proof and accountability.
2.2 Functional cookies
If you select the use of "functional cookies" in the cookie banner, further cookies will be set in addition to the aforementioned "essential or necessary cookies". Currently, this only includes cookies that are related to the embedding of YouTube videos on our website. If you select these cookies, you will no longer be asked in advance for the necessary consent for the data transmission to or data processing by YouTube/Google, including the activation of YouTube cookies, when playing YouTube videos embedded on our website. The use of these functional cookies is based on your informed and voluntary consent pursuant to Art. 6 (1) lit. a GDPR and § 25 (1) German Telecommunications Telemedia Data Protection Act (TTDSG), which you give us via your explicit selection in the cookie banner.
Regardless of your selection in the cookie banner, these functional YouTube cookies will also be activated if you play an embedded YouTube video on our website and give your consent to this by clicking on "Accept" in the information window displayed in advance. You can find more information on this in section 4.1.
You can revoke your consent at any time with effect for the future by changing your cookie setting accordingly (via the cookie banner) or deleting the cookies on your terminal device. You may need to restart your browser for these changes to take effect.
These YouTube cookies have different storage durations and are automatically deleted after 24 months at the latest, unless you have already manually deleted them.
2.3 Marketing Cookies / Google Analytics
If you select the use of "marketing cookies" in the cookie banner or click on "accept all", further cookies will be set in addition to the aforementioned necessary cookies and functional cookies, in particular to measure the reach of our website and to analyze user behavior on our website. In particular, the following purposes are pursued herewith:
- Measuring the effectiveness of the website
- Analysis of user interactions with the website
- Optimization of the structure of the website
- Adaptation of the offer to the requirements of the users
This selection also includes "Google Analytics", a web analytics service provided by Google Ireland Limited (Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland; hereinafter referred to as "Google"). Here, Google uses various cookies/technologies that enable an analysis of your use of the website. The information generated by these cookies/technologies about your use of this website (including your shortened IP address) is also transmitted to servers of Google LLC (parent company of Google Ireland Ltd: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) in the USA and processed there. Google will use this information for the purpose of evaluating your use of the website on our behalf, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf.
To enable the use of Google Analytics, the "Google Tag Manager" is also activated. Via the Google Tag Manager, so-called tags can be integrated centrally via a user interface. So-called script codes of other tools (here Google Analytics) are integrated via the Google Tag Manager. The Tag Manager makes it possible to control when a specific tag is triggered (see also Section II.4.2).
Google stores cookies on your terminal device for a period of up to two years from your last visit. These cookies contain a randomly generated user ID with which you can be recognized during future website visits. The recorded data is stored together with the randomly generated user ID, which enables the evaluation of pseudonymous user profiles. This user-related data is automatically deleted after 26 months, unless you visit our website again (using the marketing cookies). Other (non-personal) data remains stored in aggregated form indefinitely.
The processing of your data by Google is generally anonymized, because your IP address is automatically shortened after collection by Google, making it impossible to identify you on the basis of this shortened IP address. However, it cannot be ruled out that Google may still be able to draw conclusions about your person in exceptional cases on the basis of further information that is collected through your use of other Google services (e.g. an Android smartphone, Google Chrome web browser). For full details on data processing by Google, please visit Google's Privacy Center at https://policies.google.com/privacy.
The use of these marketing cookies (including cookies from Google) is based on your informed and voluntary consent pursuant to Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG, which you give us via your explicit selection in the cookie banner.
Additional note on data transfer to the USA: By selecting "Marketing Cookies", you also expressly consent in accordance with Art. 49 (1) lit. a GDPR that your data collected by Google may also be transferred to Google servers in the USA. The USA has been classified by the European Court of Justice (ECJ) as a country with an insufficient level of data protection according to EU standards.
You can revoke your consent at any time with effect for the future by changing your cookie setting accordingly (via the cookie banner) or deleting the cookies on your terminal device. You may need to restart your browser for these changes to take effect.
In addition, you have the option to prevent the processing of your data by Google Analytics by installing the "Google Analytics Opt-out Browser Add-on". You can download this add-on from the following Google page: https://tools.google.com/dlpage/gaoptout?hl=de.
2.4. Browser settings to limit the use of cookies
You can prevent the use of cookies by configuring your browser settings accordingly. This may result in certain websites/resources not working properly or to their full extent.
If the "DoNotTrack" function of your browser is activated, this will of course be observed and no marketing cookies (web analysis/tracking) will be set.
You may need to restart your browser for changes to your cookie selection or setting to take effect.
2.5 Overview of the cookies used
You may find more detailed information on the cookies in the cookie banner, which is displayed to you in particular when you visit the website for the first time or which can be accessed at any time via the blue "fingerprint button" in the lower section of the website.
3. Communication
If you contact us (e.g. by contact form, e-mail, telephone), the information or data you provide will be processed to the extent necessary to process or respond to the contact request and any requested activities.
In particular, you may write us via the contact forms provided in the "Contact" section of the website. The information marked as mandatory in the respective contact form (e.g. first name, last name, e-mail address) must be provided. In addition, further data can be provided voluntarily. This also includes all data that you mention in the free text field of your message to us.
All messages received via the contact forms are forwarded to the relevant mailbox. Only a limited number of authorized persons within our company have access to these mailboxes. If necessary to process your request, your inquiry may be forwarded to other departments within our company or to other companies of the Rheinmetall Group. In exceptional cases, this may also involve affiliated companies outside the European Union (EU) or the European Economic Area (EEA). We ensure an appropriate level of data protection at affiliated companies of the Rheinmetall Group outside the EU/EEA in accordance with Art. 44 ff. GDPR. Data will not be forwarded to persons or companies outside the Rheinmetall Group without your prior express consent.
The data processing necessary to adequately answer/respond to your inquiry/message is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR. This legitimate interest also includes any necessary forwarding of your inquiry/message to affiliated companies of the Rheinmetall Group. If you submit an inquiry/message within the scope of a contractual or pre-contractual relationship with us, the necessary data processing is based on Art. 6 (1) lit. b GDPR for the purpose of fulfilling our contractual obligations or to answer (pre-)contractual inquiries.
Your inquiry/message (including the transmitted data) is usually deleted 7 days after completion, unless there are legal retention periods or other legitimate reasons for further storage (e.g. assertion, exercise or defense of legal claims). In the latter cases, your data will be deleted after expiry of the applicable statutory retention period (e.g. from commercial or tax law) or after the other legitimate reasons for processing no longer apply (the legal basis for further retention for these legitimate reasons is usually Art. 6 (1) lit. f GDPR).
Special note on job applications: Applications are to be submitted exclusively via our separate application/career portal. All applications received by other means will be deleted unprocessed.
4. Plugins and embedded functions / content
4.1 Embedded YouTube videos
We integrate functional and content elements of the YouTube video platform on our website to enable the playback of selected YouTube videos directly on our website. This requires, among other things, the establishment of a connection to YouTube's servers and the use of YouTube cookies (see also Section II.2.2).
The service provider of YouTube (https://www.YouTube.com) is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), whose parent company is Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), headquartered in the USA. The privacy information of the provider can be accessed via the following link: https://policies.google.com/privacy.
The YouTube videos are embedded in the so-called extended data protection mode of YouTube. This mode ensures that the connection to YouTube is only established when the video is actively played. Before that, there is no connection to YouTube and thus no data transmission to YouTube.
When you click on an embedded YouTube video, you will be shown a separate information window in which you can give your express consent to the data transfer and cookie use required for the video playback ("ACCEPT" button). If you have already previously accepted the use of function cookies or all cookies/functions in the cookie banner, this separate information window will no longer be displayed. Your selection in the information window or cookie banner will also be saved for subsequent website visits. You can find more information about the storage period in the cookie banner under YouTube.
When playing the embedded YouTube video, a connection to YouTube is established, during which, among other things, your IP address is transmitted. In addition, YouTube cookies are then also set on your terminal device, which can also be used to analyze your usage behavior for market research and marketing purposes by YouTube. If you are logged into your YouTube account at the same time, you potentially enable YouTube to assign your surfing behavior to your personal profile. You can prevent this, inter alia, by logging out of your YouTube account. Details on the cookies used can be found in the cookie banner.
By playing the embedded YouTube video (after prior corresponding selection in the cookie banner or notice window), you give your express and voluntary consent in accordance with Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG in this data processing and this cookie use by YouTube. We have no influence on this data processing by YouTube.
Note on data transfers to the USA: Since YouTube is a service of the US company Google, a transfer of your data to the USA cannot be ruled out. By playing the embedded YouTube video, you therefore at the same time expressly consent pursuant to Art. 49 (1) lit. a GDPR that your data collected by YouTube or Google may also be processed by Google in the USA. The USA has been classified by the European Court of Justice (ECJ) as a country with an insufficient level of data protection according to EU standards.
4.2 Google Tag Manager
This website also uses the Google Tag Manager to enable the use of Google Analytics. However, this only takes place with your prior explicit selection in the cookie banner (consent pursuant to Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG). You can find more information on this in section II.2.3.
The Google Tag Manager can manage so-called website tags. Google Tag Manager is operated by Google Ireland Limited (Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland). The Google Tag Manager merely implements tags, but does not itself collect any personal data. The Google Tag Manager triggers other tags, which in turn may collect data (here: Google Analytics, see Section II.2.3).
4.3 Event streaming on microsites
You can access so-called microsites on our website via special links that are communicated, for example, as part of Rheinmetall online events. These microsites are quasi-hidden subpages that can only be accessed via these separate links. The following special features apply to these microsites in addition to the information provided in this data protection information:
On these microsites, you will typically find streams/content that are integrated via a so-called inline frame (iFrame) (hereinafter referred to as "streams"). These streams are offered by our service provider Dubidot GmbH (P.O. Box 291, 9650 Nesslau, Switzerland) and are operated/hosted on servers in Germany. (Note: Switzerland is a country with an adequate level of data protection according to the adequacy decision of the European Commission).
When such a stream is called up, data on each access to the server (so-called server log files) are automatically collected by Dubidot. The data collected includes:
- IP address
- Date and time of your visit
- Which resources (e.g. subpage, contact form) you access on this website area
- The browser you are using (incl. version)
- The operating system you are using (incl. version)
These server log files are processed on the basis of our and Dubidot's legitimate interest pursuant to Art. 6 (1) lit. f GDPR for the following purposes:
- Ensuring the security and stability of the website/streams (e.g. avoiding server overloads due to abusive attacks, so-called DDoS attacks)
- Ensure proper connection to the website/streams
- Ensuring comfortable use of the website/streams
- Evaluation of system security and stability.
The data is deleted immediately when it is no longer required to achieve these purposes, but no later than 6 months after collection.
Furthermore, in addition to the general cookies of our website, which are activated according to your selection in the cookie banner (see Chapter II.2), additional cookies from our service provider Dubidot are used when you visit a microsite. These are exclusively cookies that are necessary for the proper functionality of the stream. These cookies are automatically deleted after the session expires (i.e., after you close your browser). The use of these necessary cookies is based on our and Dubidot's legitimate interest (ensuring the functionality of the microsite and the stream) pursuant to Art. 6 (1) lit. f GDPR.
5. Job advertisements and career pages
In our career section you may find a link to the central career website of the Rheinmetall Group (https://www.rheinmetall.com/career). By clicking on this link you will be redirected to this separate website of Rheinmetall AG, for which Rheinmetall AG is exclusively responsible and which has its own privacy policy (only this privacy policy applies there).
On this career website you will find plenty of information on career opportunities in the Rheinmetall Group as well as an overview of job vacancies and entry-level opportunities. Among other things, you have the option to apply for jobs. By clicking on the application button ("Apply Online Now!" / "Jetzt Online Bewerben!") of the respective job offer, you will be directed to our separate career / recruitment platform (independent website), for which a separate Data Protection Information applies, which you can also access here.
Job applications are only accepted via our career platform!
6. General information on the deletion of your data
In general, the data processed by us will be deleted in accordance with the legal requirements as soon as it is no longer necessary to achieve the purpose of processing, the purpose of processing is fulfilled or no longer applies, or you revoke any consent you may have given. In addition, we will delete your data if you request a corresponding deletion in accordance with Art. 17 GDPR or - in the case of processing based on legitimate interests in accordance with Art. 6 (1) lit. f GDPR - if you object to this processing in accordance with Art. 21 GDPR (further information on your rights can be found in section IV. of this data protection information).
However, the deletion of your data may be precluded by legal retention periods or other justified reasons for retention on our part. Data that we are legally obligated to retain will be deleted after these retention periods have expired. Data that we continue to retain due to conflicting legitimate retention reasons (e.g. for the assertion, exercise or defense of legal claims pursuant to Article 17 (3) lit. e GDPR or Article 21 (1) GDPR) will be deleted after these legitimate retention reasons cease to apply.
In the event that your data is not deleted because of further legally permissible retention purposes, their processing will be limited to these purposes, its processing will be limited to those purposes.
More detailed information on the specific storage or deletion of your data can be found in the individual sections of Section II "Data processing activities on our website".
7. Links
On this website, you may find links to online or social media presences of the Rheinmetall Group (see corresponding icons in the footer/lower section of the website).
Clicking on the respective icon or link takes you to the corresponding external online or social media platform. The data protection information stored there applies to the respective presence. Clicking on the respective icon/link does not result in any data transmission by us to the external operators of the platforms.
The privacy information for those social media presences can also be found here.
III. Technical and organizational measures
We implement appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, context and purposes of the processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk.
Such measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, availability and separation to and of the data. Furthermore, we have established procedures to ensure that data subjects' rights can be exercised, data can be deleted, and responses are made to any threats to the data. Additionally, we already consider privacy matters during the development or selection process of hardware, software and procedures in accordance with the principle of Privacy-by-Design and Privacy-by-Default.
SSL encryption (https): To properly protect your transmitted data, this website uses a so-called SSL encryption. You can recognize such encrypted connections by the prefix "https://" in the page link (URL) in the address line of your browser. Unencrypted pages are prefixed by "http://".
Thanks to this SSL encryption, no data which you transmit to this website – for example in case of inquiries – can be read by third parties without further significant efforts.
IV. Your rights
As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
Right to be informed and of access (Art. 15 GDPR): In accordance with the statutory provisions, you have the right to request information as to whether and to what extent we process your personal data.
Right to rectification (Art. 16 GDPR): In accordance with the statutory provisions, you have the right to request the rectification or completion of incorrect or incomplete data concerning yourself.
Right to erasure (Art. 17 GDPR): In accordance with the statutory provisions, you have the right to demand that your personal data be erased. Note: An immediate deletion of your data may be opposed by statutory retention obligations or other justified reasons for further processing.
Right to restrict processing (Art. 18 GDPR): In accordance with the statutory provisions, you have the right to demand that the processing of your personal data be restricted.
Right to data portability (Art. 20 GDPR): In accordance with the statutory provisions, you have the right to receive your personal data in a structured, commonly used and machine-readable format and - as far as technically feasible - to demand that it be transferred to another controller.
Right to object (Art. 21 GDPR): In accordance with the statutory provisions, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation, provided that the data processing is carried out on the basis of legitimate interests (cf. Art. 6 (1) lit. e or lit. f GDPR).
If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to such processing, including profiling, insofar as it is connected with such direct marketing.
Right to withdraw consent (Art. 7 (3) GDPR): You have the right to withdraw any consent you have given at any time with effect for the future without having to state reasons. Such withdrawal of consent does not affect the lawfulness of processing that has taken place on the basis of consent until the time of withdrawal.
To exercise your rights, please contact:
Nitrochemie Aschau GmbH
Data Privacy
Liebigstr. 17
84544 Aschau am Inn
DSB@nitrochemie.com
Right to lodge a complaint with a supervisory authority (Art. 77 (1) GDPR): In accordance with the statutory provisions, you have the right to lodge a complaint with a data protection supervisory authority of your choice, in particular in the Member State of your habitual residence, place of work or place of alleged infringement, if you believe that the processing of your personal data violates the GDPR.
V. Miscellaneous
We may adapt this Data Protection Information if changes in the legal situation or the data processing carried out by us make it necessary.
The currently displayed Data Protection Information upon your visit applies. Where necessary and possible, we will inform you if any changes require your involvement (e.g. renewed consent) or individual notification.
Where we provide addresses and contact information of other companies and organizations in this privacy information, please note that the addresses may change over time.
The terms used herein are not gender-specific.
Status of this data protection information: May 23, 2023