Privacy Policy

1. Introduction

With the following information, we would like to provide you, as a “data subject,” with an overview of the processing of your personal data by us and your rights under data protection laws. In principle, it is possible to use our website without providing personal data. However, if you wish to use special services offered by our company via our website, processing of personal data may become necessary. If the processing of personal data is required and there is no legal basis for such processing, we generally obtain your consent.

The processing of personal data, such as your name, address, or email address, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to “ROSE Systemtechnik GmbH.” By means of this privacy policy, we would like to inform you about the scope and purpose of the personal data we collect, use, and process.

As the controller responsible for processing, we have implemented numerous technical and organizational measures to ensure the most complete protection possible of personal data processed through this website. Nevertheless, internet-based data transmissions may generally have security gaps, so absolute protection cannot be guaranteed. For this reason, you are free to transmit personal data to us via alternative means, for example by telephone or post.

You can also take simple measures to protect your data against unauthorized access by third parties. Therefore, we would like to provide you with some guidance on the secure handling of your data:

Protect your account (login, user or customer account) and your IT system (computer, laptop, tablet, or mobile device) with secure passwords.
Only you should have access to your passwords.
Ensure that you use your passwords for only one account.
Do not use the same password for different websites, applications, or online services.
Especially when using publicly accessible or shared IT systems: always log out after using a website, application, or online service.

Passwords should consist of at least 12 characters and be chosen so that they are not easy to guess. Therefore, they should not include common everyday words, your own name, or names of relatives, but should include uppercase and lowercase letters, numbers, and special characters.

2. Controller

The controller within the meaning of the GDPR is:

ROSE Systemtechnik GmbH
Erbeweg 13–15, 32457 Porta Westfalica, Germany

Phone: 0571-50 41-0
Fax: 0571-50 41-6
Email: rose@rose-pw.de

Representative of the controller: Dr. Heinz Werner Rixen

3. Data Protection Officer

You can contact the data protection officer as follows:

Thomas Otten

Phone: 05221 87292-08
Fax: 05221 87292-49
Email: datenschutz-rose-systemtechnik@audatis.de

You can contact our data protection officer at any time with questions or suggestions regarding data protection.

4. Definitions

This privacy policy is based on the terminology used by the European legislator in the adoption of the GDPR. To ensure clarity, we explain the key terms used:

1. Personal Data
Any information relating to an identified or identifiable natural person.

2. Data Subject
Any identified or identifiable natural person whose personal data is processed.

3. Processing
Any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.

4. Restriction of Processing
Marking stored personal data with the aim of limiting its future processing.

5. Profiling
Automated processing of personal data to evaluate personal aspects.

6. Pseudonymization
Processing of data in such a way that it cannot be attributed to a specific person without additional information.

7. Processor
A natural or legal person processing personal data on behalf of the controller.

8. Recipient
A person or entity to whom personal data is disclosed.

9. Third Party
Any person or entity other than the data subject, controller, or processor.

10. Consent
Any freely given, informed, and unambiguous indication of the data subject’s wishes.

5. Legal Basis of Processing

Processing is based on the following legal grounds:

Art. 6(1)(a) GDPR – Consent
Art. 6(1)(b) GDPR – Contract performance
Art. 6(1)(c) GDPR – Legal obligation
Art. 6(1)(d) GDPR – Vital interests
Art. 6(1)(f) GDPR – Legitimate interests

Our services are generally aimed at adults. Persons under 16 may not submit personal data without parental consent.

6. Transfer of Data to Third Parties

Your personal data is only shared if:

You have given explicit consent
It is necessary for legitimate interests
There is a legal obligation
It is required for contract performance

We use standard contractual clauses for international transfers where necessary.

7. Technology

7.1 SSL/TLS Encryption

We use SSL/TLS encryption to protect transmitted data.

7.2 Data Collection When Visiting the Website

When visiting our website, we collect technical data such as:

Browser type and version
Operating system
Referrer URL
Subpages accessed
Date and time of access
IP address (anonymized)
Internet service provider

This data is used for technical operation, security, and optimization.

7.3 Encrypted Payment Transactions

Payments are processed via encrypted connections.

7.4 Cloudflare (CDN)

We use Cloudflare to improve performance and security. Data may be processed and analyzed to prevent attacks.

7.5 Hosting by Hetzner

Our website is hosted by Hetzner. Data processing is based on a data processing agreement.

7.6 jsDelivr

We use jsDelivr as a CDN to deliver website content efficiently.

8. Cookies

8.1 General Information

Cookies are small files stored on your device to improve usability and analyze usage.

8.2 Real Cookie Banner

We use a consent tool to manage and document cookie consent.

9. Website Content

9.1 Customer Account & Contract Processing

Personal data is processed for contract fulfillment and account management.

9.2 Order Processing

Data is shared with logistics and payment providers where necessary.

9.3 Online Shop & Shipping

Data is only shared when necessary for contract execution.

9.4 Contact Form

Data submitted via forms is used solely to respond to inquiries.

9.5 Applications

Applicant data is processed for recruitment purposes and deleted after 6 months if no contract is concluded.

10. Social Media

We maintain social media pages to communicate with users. Data processing may occur outside the EU.

Platforms include:

Facebook
Instagram
LinkedIn
X (Twitter)
XING
YouTube

11. Web Analytics

We use tools such as:

Google Analytics 4
Google Analytics (Universal)
HubSpot
Leadinfo
LinkedIn Analytics
Microsoft Clarity
WiredMinds

These tools analyze user behavior and improve our services (usually based on consent).

12. Advertising

We use advertising services such as:

Google AdSense
Google Ads (with conversion tracking)
LinkedIn Ads
Microsoft Bing Ads

13. Affiliate Programs

We use DoubleClick by Google for advertising optimization.

14. Plugins and Services

We integrate:

Google Photos
Google Tag Manager
Google Web Fonts
HubSpot CRM
YouTube (privacy-enhanced mode)

15. Your Rights

You have the right to:

Confirmation of data processing
Access to your data (Art. 15 GDPR)
Rectification (Art. 16 GDPR)
Erasure (Art. 17 GDPR)
Restriction (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Objection (Art. 21 GDPR)
Withdraw consent
Lodge a complaint with a supervisory authority

16. Storage and Deletion

Data is stored only as long as necessary and deleted according to legal requirements.

17. Storage Duration

The retention period depends on legal obligations.

18. Updates

This privacy policy is valid as of April 2026 and may be updated at any time.

If you want, I can also shorten this into a cleaner, website-ready version or adapt it to more natural legal English (UK/US style)—this is a very literal translation right now.

ROSE worldwide

Please choose your preferred language: