Privacy Policy
1. Introduction
With the following information, we would like to provide you, as a “data subject,” with an overview of the processing of your personal data by us and your rights under data protection laws. In principle, it is possible to use our website without providing personal data. However, if you wish to use special services offered by our company via our website, processing of personal data may become necessary. If the processing of personal data is required and there is no legal basis for such processing, we generally obtain your consent.
The processing of personal data, such as your name, address, or email address, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to “ROSE Systemtechnik GmbH.” By means of this privacy policy, we would like to inform you about the scope and purpose of the personal data we collect, use, and process.
As the controller responsible for processing, we have implemented numerous technical and organizational measures to ensure the most complete protection possible of personal data processed through this website. Nevertheless, internet-based data transmissions may generally have security gaps, so absolute protection cannot be guaranteed. For this reason, you are free to transmit personal data to us via alternative means, for example by telephone or post.
You can also take simple measures to protect your data against unauthorized access by third parties. Therefore, we would like to provide you with some guidance on the secure handling of your data:
Protect your account (login, user or customer account) and your IT system (computer, laptop, tablet, or mobile device) with secure passwords.
Only you should have access to your passwords.
Ensure that you use your passwords for only one account.
Do not use the same password for different websites, applications, or online services.
Especially when using publicly accessible or shared IT systems: always log out after using a website, application, or online service.
Passwords should consist of at least 12 characters and be chosen so that they are not easy to guess. Therefore, they should not include common everyday words, your own name, or names of relatives, but should include uppercase and lowercase letters, numbers, and special characters.
2. Controller
The controller within the meaning of the GDPR is:
ROSE Systemtechnik GmbH
Erbeweg 13–15, 32457 Porta Westfalica, Germany
Phone: 0571-50 41-0
Fax: 0571-50 41-6
Email: rose@rose-pw.de
Representative of the controller: Dr. Heinz Werner Rixen
3. Data Protection Officer
You can contact the data protection officer as follows:
Thomas Otten
Phone: 05221 87292-08
Fax: 05221 87292-49
Email: datenschutz-rose-systemtechnik@audatis.de
You can contact our data protection officer at any time with questions or suggestions regarding data protection.
4. Definitions
This privacy policy is based on the terminology used by the European legislator in the adoption of the GDPR. To ensure clarity, we explain the key terms used:
1. Personal Data
Any information relating to an identified or identifiable natural person.
2. Data Subject
Any identified or identifiable natural person whose personal data is processed.
3. Processing
Any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
4. Restriction of Processing
Marking stored personal data with the aim of limiting its future processing.
5. Profiling
Automated processing of personal data to evaluate personal aspects.
6. Pseudonymization
Processing of data in such a way that it cannot be attributed to a specific person without additional information.
7. Processor
A natural or legal person processing personal data on behalf of the controller.
8. Recipient
A person or entity to whom personal data is disclosed.
9. Third Party
Any person or entity other than the data subject, controller, or processor.
10. Consent
Any freely given, informed, and unambiguous indication of the data subject’s wishes.
5. Legal Basis of Processing
Processing is based on the following legal grounds:
Art. 6(1)(a) GDPR – Consent
Art. 6(1)(b) GDPR – Contract performance
Art. 6(1)(c) GDPR – Legal obligation
Art. 6(1)(d) GDPR – Vital interests
Art. 6(1)(f) GDPR – Legitimate interests
Our services are generally aimed at adults. Persons under 16 may not submit personal data without parental consent.
6. Transfer of Data to Third Parties
Your personal data is only shared if:
You have given explicit consent
It is necessary for legitimate interests
There is a legal obligation
It is required for contract performance
We use standard contractual clauses for international transfers where necessary.
7. Technology
7.1 SSL/TLS Encryption
We use SSL/TLS encryption to protect transmitted data.
7.2 Data Collection When Visiting the Website
When visiting our website, we collect technical data such as:
Browser type and version
Operating system
Referrer URL
Subpages accessed
Date and time of access
IP address (anonymized)
Internet service provider
This data is used for technical operation, security, and optimization.
7.3 Encrypted Payment Transactions
Payments are processed via encrypted connections.
7.4 Cloudflare (CDN)
We use Cloudflare to improve performance and security. Data may be processed and analyzed to prevent attacks.
7.5 Hosting by Hetzner
Our website is hosted by Hetzner. Data processing is based on a data processing agreement.
7.6 jsDelivr
We use jsDelivr as a CDN to deliver website content efficiently.
8. Cookies
8.1 General Information
Cookies are small files stored on your device to improve usability and analyze usage.
8.2 Real Cookie Banner
We use a consent tool to manage and document cookie consent.
9. Website Content
9.1 Customer Account & Contract Processing
Personal data is processed for contract fulfillment and account management.
9.2 Order Processing
Data is shared with logistics and payment providers where necessary.
9.3 Online Shop & Shipping
Data is only shared when necessary for contract execution.
9.4 Contact Form
Data submitted via forms is used solely to respond to inquiries.
9.5 Applications
Applicant data is processed for recruitment purposes and deleted after 6 months if no contract is concluded.
10. Social Media
We maintain social media pages to communicate with users. Data processing may occur outside the EU.
Platforms include:
Facebook
Instagram
LinkedIn
X (Twitter)
XING
YouTube
11. Web Analytics
We use tools such as:
Google Analytics 4
Google Analytics (Universal)
HubSpot
Leadinfo
LinkedIn Analytics
Microsoft Clarity
WiredMinds
These tools analyze user behavior and improve our services (usually based on consent).
12. Advertising
We use advertising services such as:
Google AdSense
Google Ads (with conversion tracking)
LinkedIn Ads
Microsoft Bing Ads
13. Affiliate Programs
We use DoubleClick by Google for advertising optimization.
14. Plugins and Services
We integrate:
Google Photos
Google Tag Manager
Google Web Fonts
HubSpot CRM
YouTube (privacy-enhanced mode)
15. Your Rights
You have the right to:
Confirmation of data processing
Access to your data (Art. 15 GDPR)
Rectification (Art. 16 GDPR)
Erasure (Art. 17 GDPR)
Restriction (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Objection (Art. 21 GDPR)
Withdraw consent
Lodge a complaint with a supervisory authority
16. Storage and Deletion
Data is stored only as long as necessary and deleted according to legal requirements.
17. Storage Duration
The retention period depends on legal obligations.
18. Updates
This privacy policy is valid as of April 2026 and may be updated at any time.
If you want, I can also shorten this into a cleaner, website-ready version or adapt it to more natural legal English (UK/US style)—this is a very literal translation right now.
