Data Protection

1. Privacy Notice

Krones AG (hereinafter referred to as “we” or “us”) is glad that you are visiting our websites as well as mobile applications (collectively also referred to as “Online Offer”) and that you are interested in our Company and our products.

We view the protection of your private sphere during the processing of personal data and the security of all business data as important considerations which we take into account in our business processes. We process personal data collected during your visit to our Online Offers in a confidential manner any only in compliance with the statutory provisions.

Data protection and information security are part of our company policy.

2. Controller

Krones AG is the Controller responsible for the processing of your data.

Our contact details are as follows:

Krones AG
Böhmerwaldstraße5
93073 Neutraubling
Germany

Phone: +49 9401 70 – 0
Fax: +49 9401 70 – 24 88

E-mail: info@krones.com

You can contact our Data Protection Officer using the following contact details:

Krones AG
Böhmerwaldstraße5
93073 Neutraubling
Germany

Phone: +49 9401 70 – 0
Fax: +49 9401 70 – 24 88

E-mail: data.protection@krones.com

3. Processing of personal data

3.1. Personal data

Personal data is any information relating to an identified or identifiable natural person, i.e. for example names, addresses, telephone numbers, e-mail addresses, contractual, booking and accounting data which is the expression of a person’s identity.

We process personal data (including IP addresses) only if there is a legal basis for this or if you granted us your consent in this regard, for example in the course of a registration.

Which data is processed in detail and how it is used depends largely on the agreed services and your use of our website. Therefore, not all parts of this information will apply to you.

3.2. Categories of data processed

The following data categories are processed:

  • Communication data (e.g. name, telephone, e-mail, address, IP address)
  • Key contract data (contractual relationship, product or contractual interest)
  • Customer history
  • Contract billing and payments data
  • Disclosed information (from third parties, e.g. credit reference agencies or from public directories)
  • Http data that is technically generated when the website is called up. This includes, for example, IP addresses, type and version of your internet browser, the pages accessed, the previously visited page, date and time of access
  • Search function data that you enter as search terms in the respective search form of the website
  • Cookie setting data, which we use to manage your cookie settings. This includes your consent (if given), your objections and, if applicable, your individual selection for the use of cookies and other tracking tools
  • Depending on your individual cookie selection, other transaction data about your visit to our website for reach measurement and market research
  • Error data are error messages from the server and individual applications, which are stored

3.3. Purpose of processing and legal basis

We and service providers engaged by us process your personal data for the following purposes of processing and subject to the following legal bases:

3.3.1. Contractual basis (preperation, performance, termination)

  • Answering enquiries
  • Handling of your orders
  • Preparation, negotiation and fulfilment of a contract with you
  • Granting access to certain information and offers
  • Preparation and implementation of face-to-face meetings and virtual events

3.3.2. Legal obligation

  • Official or judicial order
  • Tax and commercial legislation

3.3.3. Our Legitimate interest

  • Enabling the use of the services of our online offers
  • Direct marketing
  • Improvement of products and services
  • Online surveys (note: if we involve a market research institute for survey, it will only become active on our behalf and subject to our instructions.)
  • Establishment or protection of legal claims or defence of court actions
  • Prevention and detection of abuse, attacks on our IT infrastructure or other unlawful activities
  • Guarantee of data security

3.3.4. Consent

  • Product or customer surveys by e-mail and/or telephone
  • Sending newsletters
  • Use of cookies for marketing or statistical purposes

3.4. Log files

During each use of our website, your internet browser automatically transmits certain information to us which we store in so-called log files (e.g. internet browser used and operating system; domain name of the website you previously visited number of visits; average dwell time, pages accessed). This information is not associated with a specific person.

We and our subsidiary companies worldwide store these log files for the detection of disturbances and for security reasons (e.g. for the clarification of attempted attacks) for a short time and deleted thereafter. Log files the continued retention of which is required for evidentiary purposes shall be excluded from the deletion until final clarification of the respective incident and can be forwarded to investigating authorities on an individual basis.

Log files are also used for analysis purposes (without or without the complete IP address); for this, see the Web Analysis Section.

4. Obligation for the provision of personal data

To the extent there is a contract between you and us, you have to provide the personal data which is required for commencement, performance and termination of the contractual relationship and for the fulfilment of the contractual obligations related thereto or to the collection of which we are legally obliged. Without the provision of such data, we will generally not be able to enter into, perform and terminate a contract with you.

The transmission of certain personal data (e.g. IP address) is required to establish a connection to our website and to display the content of the website. To the extent the data processing in the course of your use of our website is not required for the commencement, performance and termination of a contractual relationship or for the fulfilment of contractual obligations and is not required under applicable laws, the provision of your data shall be voluntary. Please note that certain functionalities of the website or services cannot be used if you do not provide the data required for such purposes.

5. Use of cookies

Our website uses cookies. Cookies are small text files that are stored on your computer when you visit our website. We use cookies particularly to guarantee the use of our online offer, for marketing, for individual website optimisation and to guarantee IT security.

When you visit our website, we display a so-called "cookie banner" in which you can click on a button to declare your consent to the use of cookies on this website and make an individual selection of the cookies used on the website. Your selection will also be saved for future visits.

We use the Consent Management Platform (CMP) of Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany. The tool allows you to conveniently manage your consent to the setting of cookies that are technically not necessary and to make relevant changes such as revocations of consent or objections. The tool also includes the information required by Article 13 GDPR on the processing of your personal data by Usercentrics CMP and cookies that are technically not necessary. You may access our CMP settings by clicking on the fingerprint icon in the lower left of the web page.

Alternatively, you can also adjust the settings for cookie management in your Internet browser. You can particularly arrange for cookies that have already been set to be deleted or prevent cookies from being set in the future. Please note that the settings will vary depending on the browser you are using.

Depending on their function and purpose, the use of certain cookies requires the user's consent.

Cookies, which are necessary to use our online offer or to guarantee IT security, do not require consent. The setting of these cookies and related processing activities are permitted by art. 6 para. 1 lit. f) GDPR (legitimate interest). According to Section 25 (2) TTDSG, no consent is required for the use of such cookies.

Cookies for all other purposes, such as for individual website optimization, for marketing or for carrying out statistical evaluations of your activities on the website, require your consent in accordance with art. 7 GDPR respectively Section 25 (1) TTDSG, which we request as part of the cookie banner.

5.1. Web analysis

We need statistical information on the use of our online offer in order to make it more user-friendly, to perform reach measurements and to carry out market research activities. To that end, we use the web analysis tools described in this Section.

The use profiles generated by using analysis cookies or evaluating the log files will not be combined with personal data. The tools either do not use IP addresses of the users at all or shorten them immediately after collection. The providers of the tools process data as processors only subject to our instructions and not for their own purposes.

For tools which work with opt-out cookies, it has to be noted that the opt-out function is specific to devices and/or browsers and generally only applies to the end device or browser you are currently using. If you use several end devices and/or browsers, you have to set opt-out for each individual end device and for each browser used.

Furthermore, you can prevent the generation of user profiles as a whole by deactivating the use of cookies in general.

5.1.1. WiredMinds

For marketing and optimization purposes, products and services of the company WiredMinds GmbH, Lindenspürstraße 32, 70176 Stuttgart are used on this website. This involves processing data from which usage profiles are created under a pseudonym. Where possible and reasonable, the usage profiles are completely anonymized. Cookies are used for this purpose. The collected data, which may also include personal data, is transmitted to WiredMinds or collected directly. We may use information left behind by visits to the website to create anonymized usage profiles. The data obtained in this way will not be used to personally identify the visitor to this website without the separately granted consent of the person concerned, and it will not be merged with personal data about the bearer of the pseudonym. Insofar as IP addresses are collected, they are anonymized immediately after collection by deleting the last number block. You may object to data processing at any time with effect for the future by adjusting your cookie settings.

5.1.2. Matomo

For marketing and optimization purposes, we use the Matomo Analytics software (on-premise) (https://matomo.org/). This involves processing data from which usage profiles are created un-der a pseudonym. Where possible and reasonable, the usage profiles are completely anony-mized. Cookies are used for this purpose. The collected data, which may also include personal data, is transmitted to our self-hosted system or collected directly. We may use information left by visits to the website to create anonymized usage profiles. The data obtained in this way will not be used to personally identify the visitor to this website without the separately granted con-sent of the person concerned, and it will not be merged with personal data about the bearer of the pseudonym. Insofar as IP addresses are collected, they are anonymized immediately after collection by deleting the last number block. You can object to data processing at any time with effect for the future by adjusting your cookie settings.

5.1.3. Google Analytics

Google Analytics is a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyse how users use the site. The information collected by the cookie about the use of our website (including your IP address) is usually transmitted to a Google server in the USA and stored there. We would like to point out that on our websites Google Analytics has been extended by the code "gat._anonymizeIp();" in order to ensure anonymised collection of IP addresses (so-called IP masking). At our instigation, your IP address is therefore only recorded by Google in shortened form, which ensures anonymisation and does not allow any conclusions to be drawn about your identity. If IP anonymisation is activated on our websites, your IP address will be shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. For more information on data processing involving data transfer to a third country, please refer to section 7.

Google will use this information for the purpose of evaluating your use of our website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. A transfer of this data by Google to third parties only takes place on the basis of legal regulations or within the framework of commissioned data processing. Under no circumstances will Google merge your data with other data collected by Google.

By giving your consent, you agree to the processing of the data collected about you by Google and to the aforementioned method of data processing as well as to the aforementioned purpose.

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website.

5.2. BotDetect Captcha

We use the BotDetect Captcha service, which protects our website from spam and abuse. BotDetect Captcha prevents automated software (known as bots) from engaging in abusive activities on the website. It does so by checking whether the inputs being made are actually being made by a human. To enable this process, the following details are collected and processed:

  • Referrer (the address of the page on which the captcha is used)
  • IP address of the user
  • The input behaviour of the user (e.g. answering the BotDetect Captcha question, the speed of entry in the form fields, the order in which the input fields are selected by the user) is analysed in order to improve pattern detection at Google. Browser, browser size and resolution, browser plug-ins, date, language setting
  • Cascading style sheets (CSS) and scripts (Javascript) of the web page
  • Mouse and touch-pad events within the page

5.3. Google Web Fonts

This website uses the so-called "Google Fonts" service ("Google Fonts") provided by Google Inc. ("Google") service.

By including Google Fonts on our website, your browser establishes a connection to Google's servers in the USA when you visit our website. This will inform the Google server information of the fact that the IP address assigned to you during use has visited our website. When you visit our website, your browser loads the fonts you need into its browser cache to display text and fonts correctly and to display the fonts uniformly.

The use of Google Web Fonts is subject to your consent. If you refuse/withdraw consent or if your browser does not support web fonts, only a standard font will be used by your computer. For more information about Google Fonts, see https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/.

6. Data disclosure

6.1. Forwarding of data to other controllers

In general, we transfer your personal data to third parties only if this is required for contract performance or if the third party has a legitimate interest in the data disclosure of if you provided your consent thereto. Third parties may be subsidiary companies of Krones AG.To the extent data is transferred to third parties based upon a legitimate interest, this is explained in this Privacy Notice.

Furthermore, data can be transferred to other controllers to the extent we are obliged to do so due to statutory provisions or enforceable official or judicial orders.

Under these conditions, recipients of personal data may be:

  • Public authorities and institutions (e.g. tax authorities, law enforcement agencies, family courts, land registry offices) in the event of a legal or official obligation
  • Credit and financial institutions or comparable institutions to which we transmit personal data within the scope of the business relationship (e.g. banks, credit agencies)
  • Other affiliated companies for risk management purposes due to legal or official obligations
  • Creditors or insolvency administrators who make enquiries in the course of compulsory enforcement proceedings
  • Auditors

6.2. Service providers

We engage external service providers to perform tasks such as sales and marketing services, contract management, payment processing, programming, data hosting and hotline services and implementation of virtual events. We have chosen these service providers carefully and monitor them on a regular basis, in particular their careful treatment and protection of the data stored with them. We oblige all service providers to maintain confidentiality and to comply with the statutory regulations.

7. Disclosure to recipients outside the EEA

We may also transfer personal data to recipients who are based outside the European Economic Area (EEA) in so-called third countries. Such data transfer takes place insofar as:

  • It is necessary for the execution of your orders (e.g. delivery orders)
  • It is required by law (e.g. tax reporting obligations) or
  • You have given us your consent

Furthermore, a transfer to third countries cannot be excluded in the following cases:

  • To maintain and ensure the IT operation and IT security of the company, and
  • To combat money laundering, the financing of terrorism and other criminal offences.

In these cases, we ensure before the transfer that the recipient either has an adequate level of data protection (e.g. on the basis of an adequacy decision of the European Commission for the respective country or the agreement of so-called EU standard contractual clauses with the recipient) or has your consent to the transfer.

The current version of the EU standard contractual clauses adopted by the European Commission on 4 June 2021 is available at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?uri=CELEX:32021D0914&locale=de. For data transfers since 27 September 2021, we will only use the version of the EU Standard Contractual Clauses available at the reference provided. By 27 September 2022, we will - in accordance with the obligation specified for this purpose - adapt all our existing data transfers to this current version.

If data is transferred to the USA in the constellations described above, we only use EU standard contractual clauses, as there is no adequacy decision by the European Commission in this case.

8. Use of our mobile applications

In addition to our online offer, we also provide to with mobile applications (“apps”) which you can download to your mobile end device. Apart from the data collected on websites, we collect further personal data vial our apps which arise from the specific use of a mobile end device. However, we only do this if you provide us with your consent.

8.1. Processing of you location data

Our offer also includes so-called location based services by means of which we provide you with specific offers which are customised for your individual location. In order to be able to provide you with these functions of the app, we collect the respective last three GPS locations transmitted by the mobile end device and your IP address if you consent thereto. We do not create movement profiles in the course thereof. You can deactivate or reactivate or temporarily deactivate in the pause mode this function in the settings of the respective app or the operating system of your mobile end device without impairing the basic functionality of the app.

8.2. App analysis

We need statistical information on the use of our online offer in order to make it more user-friendly, to perform reach measurements and to carry out market research activities. To that end, we use the app analysis tools described in this Section.

The use profiles generated by these tools will not be combined with personal data. The tools either do not use IP addresses of the users at all or shorten them immediately after collection.

The providers of the tools process data as processors only subject to our instructions and not for their own purposes.

Below, you will find information regarding each tool on the respective provider and on your possibility to object to the collection and processing of data by the tool.

8.3. Data processing by operators of app stores

The transfer of data such as user name, e-mail address and individual device identification number to an app store (e.g. Google Play by Google, App Store of Apply, Galaxy App Store of Samsung) in the course of downloading the respective application shall not represent data collection by us and is outside our scope of responsibility. We do not have any influence on such data collection and further processing by the app store as data controller.

9. Duration of storage; retention periods

In general, we store your personal data as long as this is required for the provision of our online offers and the services related thereto or as long as we have a legitimate interest in continued storage (for example, we may have a legitimate interest in postal marketing after fulfilment of the contract). In all other cases, we delete your personal data with the exception of data which we have to keep for the fulfilment of legal obligations (e.g. under tax or commercial law).

10. Newsletter

In the course of our online offer, you can subscribe to newsletters. For this, we use the so-called double opt-in process; accordingly, we will only send you a newsletter by e-mail, mobile messenger services (e.g. WhatsApp), SMS or push message if you first expressly confirm activation of the newsletter service by clicking on a link in a notification. If you no longer wish to receive newsletters, you can end the subscription at any time by withdrawing your consent. The withdrawal is made for e-mail newsletters by clicking on the link set forth in the newsletter or, where applicable, in the administrative settings of the respective online offer. Alternatively, please contact us using the details set forth in the “Controller” section.

11. External Links

Our online offer may contain links to third-party websites (i.e. Facebook, Instagram, XING, Twitter). After clicking on the link, we do not have any influence on the collection, processing and use of any personal data (such as the IP address or the URL of the page containing the link) on the linked website as the behaviour of third parties is naturally not under our control. We do not assume any responsibility for the processing of such personal data by third parties.

12. Safety

Our employees and the service providers acting on our behalf are obliged to maintain confidentiality and comply with the provisions of the applicable data protection laws.

We take all required technical and organizational measures in order to ensure an appropriate level of protection and to protect your data managed by us particularly against the risks of accidental or unlawful destruction, manipulation, loss, alteration or unauthorized disclosure or unauthorized access. Our security measures are subject to continuous improvement according to technological developments.

13. Your rights as a user

Please use the details set forth in the “Controller” section to assert your rights. When doing so, please ensure that we are able to clearly identify you.

You are entitled to obtain from us information on the processing of your personal data. For this purpose, you can assert a right of access regarding your personal information we process. In addition, you can require us to rectify incorrect data and - to the extent the statutory provisions are met - complete or erase your data. However, this shall not apply to data required for billing and accounting purposes or subject to the statutory retention obligation. To the extent access to such data is not required, processing thereof will be restricted. In addition, you can require us to - to the extent the statutory provisions are met - restrict the processing of your data.

Objection to direct marketing:

Apart from that, you can object to the processing of your personal data for marketing purposes at any time (“objection to marketing”). Afterwards, your personal data will no longer be used for marketing purposes. Please note that for organizational reasons, your withdrawal and the use of your data in the course of a campaign which has already commenced may overlap.

Objection to data processing if “legitimate interest“ is the legal basis:

In addition, you are entitled to object to data processing by us at any time to the extent such processing is based upon the legal basis of a legitimate interest (Article 6 (1) (f) GDPR). We will then cease processing your data, unless we can - in accordance with the statutory provisions - demonstrate compelling legitimate grounds for the further processing which override your interests.

Withdrawal of consent

If you have given us your consent to the processing of your data, you can withdraw it at any time with effect for the future. A withdrawal shall not affect the lawfulness of the data up until the time of the withdrawal.

13.1. Data portability

Furthermore, you are entitled to receive data which you provided to us in a structured, common and machine-readable format or - to the extent technically feasible - to request transfer of such data to a third party.

13.2. Right to lodge a complaint with the supervisory authority:

You are entitled to lodge a complaint with a supervisory authority. For this, you can contact the data protection authority which is competent for your place of residence or your state or the data protection authority competent for us. This is:

Bayerisches Landesamt für Datenschutzaufsicht
Promenade 27 (Schloss)
91522 Ansbach
Germany

Phone: +49 (0) 981 53 1300
Fax: +49 (0) 981 53 98 1300

E-Mail: poststelle@lda.bayern.de

13.3. Fully automated decision-making:

In accordance with Art. 22 DGDPR, you also have the right not to be subject to fully automated decision-making. As a matter of principle, we do not use fully automated decision-making for the implementation and termination of the business relationship. Should we use this procedure in individual cases (e.g. to improve our products and services), we will inform you separately about this and about your rights in this regard, insofar as this is legally prescribed.

14. Changes to the Privacy Notice

We reserve the right to amend our security and data protection measures to the extent this is necessary due to technological advancements. In these cases, we will also adjust our data protection information accordingly. Therefore, please note the respective current version of our Privacy Notice.

State:04.02.2022