Contact

Address:
Saint-Gobain Services
Construction Products GmbH
Bürgermeister Grünzweig-Str. 1
67059 Ludwigshafen
Telefon: +49 (0) 621 501 0

 

Datenschutz

PRIVACY POLICY

Privacy Policy for the Saint-Gobain Services Construction Products GmbH

Last updated: May 2018

The provisions of the EU General Data Protection Regulation (hereinafter referred to as the “GDPR”) have been valid throughout Europe since May 25, 2018. We would like to take this opportunity to inform you about how Saint-Gobain Services Construction Products GmbH processes personal data in accordance with this new regulation (see Art. 13 GDPR). Please read our Privacy Policy carefully. Should you have any questions or comments about our Privacy Policy, you may contact our data protection officer as indicated in Section 2.

Table of Contents

1. Overview

2. Contact information for the controller and the corporate data protection officer

3. Purposes of data processing, legal bases and legitimate interests pursued by Saint-Gobain Services Construction Products GmbH or a third party and categories of recipients

3.1. Accessing our website or application

3.2. Conclusion, performance or termination of a contract

3.2.1. Data processing upon the conclusion of a contract

3.2.2. Identity, credit rating and transmission to credit agencies

3.3. Data processing for advertising purposes

3.3.1. Advertising purposes of Saint-Gobain Services Construction Products GmbH and of third parties

3.3.2. Right to object

3.3.3. Sending newsletters

3.4. Website and website optimization

3.4.1. Cookies - General information

3.4.2. Google Analytics

3.4.3. Social media plug-ins

3.4.4. Facebook

4. Transmission to recipients outside the EU

5. Your rights

5.1. Overview

5.2. Right to object

6. Data security

1. Overview

The following data protection notices inform you about the type and scope of personal data processed by Saint-Gobain Services Construction Products GmbH. Personal data is information that can be used to personally identify you whether directly or indirectly, e.g. name, address, e-mail address, or user behavior.

Data processing performed by Saint-Gobain Services Construction Products GmbH may essentially be divided into two categories:

  • All data required for the performance of a contract with Saint-Gobain Services Construction Products GmbH will be processed for the purpose of performing the contract. If external service providers are also involved in performing a contract, e.g. logistics companies or subcontractors, your data will be passed on to them to the extent necessary in each particular case.

  • A variety of information is exchanged between your terminal device and our server when you access the website / application operated by Saint-Gobain Services Construction Products GmbH. This may also involve personal data. The information collected in this way is used, among other things, to optimize our website or to display advertising in your terminal device’s web browser.

In accordance with the provisions of the GDPR, you have a variety of rights that you may exercise in your dealings with us. These include, among others, the right to object to specific forms of data processing, in particular data processing for advertising purposes.

Should you have any questions regarding this data protection notice, please feel free to contact our corporate data protection officer at any time. You will find relevant contact information below.

2. Contact information for the controller and the corporate data protection officer

This Privacy Policy applies to data processing by Saint-Gobain Services Construction Products GmbH, Bürgermeister Grünzweig Straße 1, 67059 Ludwigshafen and to the following websites and applications: www.sgs-diy.de and www.saint-gobain-services.de. The Saint-Gobain Services Construction Products GmbH corporate data protection officer can be contacted at the address listed above and by e-mail at Datenschutzbeauftragter.CP@saint-gobain.com.

3. Purposes of data processing, legal bases and legitimate interests pursued by Saint-Gobain Services Construction Products GmbH or a third party and categories of recipients

3.1. Accessing our website or application

When you access our website/application, the browser used on your terminal device automatically sends information to the server for our website/application and temporarily saves it in a so-called log file. We have no control over this. The following information will be collected without action on your part and stored until automatic deletion:

The IP address of the requesting Internet-capable device

The date and time of access

The name and URL of the retrieved file

The referral website (referrer URL)

The browser you are using and, if applicable, the operating system of your Internet-enabled computer as well as the name of the access provider.

The legal basis for processing this data is Article 6(1 lit. f) GDPR. Our legitimate interest is based on the purposes of data collection described below. The data collected does not enable us to identify you nor do we attempt to do so.

We use the IP address of your terminal device and other data listed above for the following purposes:

  • Ensuring a trouble-free connection

  • Ensuring convenient use of our website/application

  • Evaluating system security and stability

We also use “cookies,” tracking tools and social media plug-ins for our website / application. The exact procedures involved, and how your data will be used for the respective purposes, are explained in more detail in Section 3.4 below.

If you have consented to geo-localization in your browser or operating system or other settings on your terminal device, we will use this function to offer you individual services related to your current location (e.g. the location of the nearest branch). We process your location data collected in this way exclusively for this function. This data is deleted upon the conclusion of your use of this function.

3.2. Conclusion, performance or termination of a contract

3.2.1. Data processing upon the conclusion of a contract

Saint-Gobain Services Construction Products GmbH is an internal service provider within the SAINT-GOBAIN Group that provides finance, purchasing, fleet management and IT services. The DIY business unit is the sales and marketing organization for the Isover, Rigips and Weber brands and is responsible for the DIY stores sales channel (“Do it yourself,” or DIY for short).

In this context, we process the data required for the conclusion, performance or termination of a contract with you. This includes:

  • Company, first name, last name

  • Invoicing and shipping address

  • E-mail address, if applicable

  • Invoice and payment information

  • Date of birth, if applicable

  • Telephone number, if applicable

The legal basis for this is Art. 6(1 lit. b) GDPR, i.e. you provide us data on the basis of the contractual relationship between you and us. Provided we do not use your contact information for advertising purposes (see Section 3.3.), we will store the data collected for the performance of the contract until the expiration of any applicable statutory or contractual warranty and guarantee rights. Upon expiration of this period, we retain information concerning the contractual relationship required by commercial and tax law for the applicable periods specified by law. During this period (regularly ten years from the conclusion of the contract), the data will be subject to processing again solely in the event of an audit by the tax authorities.

3.2.2. Identity, credit rating and transmission to credit agencies

Where necessary, we verify your identity using information from service providers. The legal basis for this is Art. 6(1 lit. f and b) GDPR. The right to do so results from the protection of your identity and the avoidance of fraud attempts at our expense. The circumstances and the result of our inquiry will be added to your customer account for the duration of the contractual relationship.

If you have already purchased items from us, your data stored by us about you can be supplemented by so-called score values. Scoring is the creation of a forecast of future events based on collected information and past experience. An assignment is made to statistical groups of persons who had similar entries in the past on the basis of personal data stored about you. The underlying method used is a well-founded mathematical-statistical method for predicting risk probabilities that has long been tried and tested in practice.

In the event of a delay in payment, we will transmit the relevant data to a company commissioned to collect the claim if other applicable legal requirements are met. The legal bases for this are both Article 6(1 lit. b) and Article 6(1 lit. f) GDPR. The assertion of a contractual claim is deemed to be a legitimate interest within the meaning of the second provision referred to above. Information about the delay in payment or a possible loss of receivables will also be forwarded to credit agencies cooperating with us if other applicable legal requirements are met. The legal basis for this is Article 6(1 lit. f) GDPR. The legitimate interest required here arises from our interest and that of third parties in reducing contractual risks for future contracts.

3.3. Data processing for advertising purposes

The following information relates to the processing of personal data for advertising purposes. The GDPR considers this form of data processing to be permitted in principle on the basis of Art. 6(1 f) GDPR and to be a legitimate interest. The retention period for data used for advertising purposes is not based on rigid principles and is rather determined on the basis of whether continued retention is necessary for purposes of advertising-related contact. Please see Section 3.3.3. for the process applicable should you object.

3.3.1. Advertising purposes of Saint-Gobain Services Construction Products GmbH and of third parties

We will list you as an existing customer in the event you have concluded a contract with us. In this case, we process your postal contact data outside the scope of a specific consent in order to send you information about new products and services.

3.3.2. Right to object

You can object to data processing for the above-mentioned purposes at any time free of charge, specifically for the respective communication channel and with effect for the future. All you need to do is send an e-mail or a letter by regular mail using the contact information provided in Section 2.

If you submit an objection, the contact address concerned will be blocked for further promotional data processing. We would like to note that in exceptional cases advertising material may still be sent for a short period even after receipt of your objection. This is a technical feature of the required lead time for advertisements and does not mean that we have not implemented your objection. We apologize for the inconvenience.

3.3.3. Sending newsletters

You have the option of subscribing to our newsletter on our website. We use the so-called double opt-in procedure in order to ensure that no errors were made when entering the e-mail address: After you have entered your e-mail address in the registration field, we will send you a confirmation link. Only after you have clicked on this confirmation link will your e-mail address be added to our mailing list. You can withdraw your consent at any time with effect for the future. For this purpose, sending a short note by e-mail to the e-mail address provided in Section 2 is sufficient. In addition, the e-mail in which the newsletter is sent to you contains a link that you can use to exercise your right to withdraw consent by clicking on it.

3.4. Website and website optimization

3.4.1. Cookies - General information

We use so-called “cookies” on our website. In cases where these cookies represent personal data, they are used on the basis of Art. 6(1 lit. f) GDPR. Our interest in optimizing our website qualifies as a legitimate interest for purposes of the regulation referred to above. Cookies are small files created automatically by your browser that are stored on your terminal device (laptop, tablet, smartphone, etc.) when you visit our site. Cookies do not cause any damage to your terminal device and do not contain viruses, Trojans or other malware. Information is stored in the cookie that relates to the specific terminal device in use. However, this does not provide us with direct information about your identity. On the one hand, cookies are used to make your use of our website more convenient. For example, we use so-called session cookies to recognize that you have already visited individual pages on our website or that you have already logged into your customer account. These will be deleted automatically after leaving our site. In addition, we also use temporary cookies that are stored on your terminal device for a specified period of time to increase user-friendliness. If you visit our site again to use our services, the site automatically recognizes that you have visited our site previously and what inputs and settings you have made so that you do not have to enter them again.

On the other hand, we use cookies in order to record the use of our website statistically and to evaluate it for the purpose of optimizing our offerings for you and to display information specially tailored to you. These cookies enable us to automatically recognize that you have already visited our site when you visit it again. These cookies are automatically deleted after a specified period of time. Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer, or a message always appears before a new cookie is created. Complete deactivation of cookies, however, may result in you being unable to use all the functions of our website. The length of time cookies are stored depends on their purpose and is not the same for all of them.

3.4.2. Google Analytics

We use Google Analytics, a web analysis service provided by Google Inc. (“Google”), for the purpose of designing and continuously optimizing our website on an as-needed basis. Pseudonymized user profiles are created and cookies are used in this context. The information generated by the cookie about your use of this site such as

Browser type/version

Operating system in use

Referrer URL (the previously visited website)

Host name of the accessing computer (IP address)

Time of the server request

is generally transmitted to a Google server in the United States and stored there. This information is used to evaluate the use of the website, to compile reports on website activities and to provide other services related to website and Internet use for market research purposes and for purposes of the user-friendly design of this website. This information may also be transferred to third parties, provided this is legally required, or to the extent that such third parties are commissioned to process the information. Under no circumstances will your IP address be merged with other Google data. IP addresses are anonymized so that such association is not possible (so-called IP masking).

You can prevent the use of cookies by selecting the appropriate settings on your browser, however please note that you may not be able to use all the functions of our website should you do so. Furthermore, you can prevent the collection of data generated by the cookie thatrelates to your usage of the website (including your IP address), and the processing of this data by Google, by downloading and installing this browser add-on. Alternatively, especially for browsers on mobile terminal devices, you can also prevent Google Analytics from collecting data by clicking this link. It sets an opt-out cookie which prevents any future collection of your data when visiting this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must save the opt-out cookie again. You can find further information about data protection in connection with Google Analytics on the Google Analytics website.

3.4.3. Social media plug-ins

On our website, we use social media plug-ins from the Facebook and YouTube social networks in order to increase familiarity with our company. The underlying advertising purpose is to be regarded as a legitimate interest within the meaning of the GDPR. The providers of the respective networks are required to ensure that operations comply with data protection requirements. These plug-ins are integrated using the “double-click” method in order to provide the best-possible protection for visitors to our website: By default, we embed disabled buttons into our website that do not connect to social networking servers. The buttons only become active and establish the connection once you have clicked on them and thus stated your consent to communication with Facebook, Google or Twitter, etc. You can then submit your recommendation with a second click. If you are already logged in to the social network of your choice, Facebook will not open another window.

3.4.4. Facebook

Our website uses plug-ins from the Facebook social network operated by Facebook Inc. The Facebook plug-ins are marked with a Facebook logo or the add-on “Like,” “Facebook” or “Share.” An overview of the Facebook plug-ins and their appearance can be found at the following link. When you activate such a plug-in (first click), your browser establishes a direct connection to Facebook’s servers. The contents of the plug-in are transmitted directly from Facebook to your browser and integrated into the web page. As a result of this connection, Facebook is notified that your browser has accessed the relevant page of our website, even if you do not have a Facebook account or are not currently logged in to Facebook. This information (including your IP address) is transmitted by your browser directly to a Facebook server in the United States and stored there. If you are logged into Facebook, it can directly associate your visit to our website with your Facebook profile. If you interact with the plug-ins, for example by pressing the “Like” button, this information is also transmitted directly to a Facebook server and stored there. The information will also be posted on your Facebook profile and displayed to your Facebook friends.

Please see Facebook’s Privacy Policy for information about the purpose and scope of data collection, further processing and use of the data by Facebook, as well as your rights in this regard and setting options to protect your privacy. If you do not want Facebook to associate the information collected about your visit to our site directly with your Facebook profile, you must log out of Facebook before visiting our site. You can also completely prevent Facebook plug-ins from loading using add-ons for your browser, e.g. the “Facebook Blocker.”

4. Transmission to recipients outside the EU

With the exception of the processing operations described in detail under Section 3, we do not pass on your data to recipients domiciled outside the European Union or the European Economic Area. Insofar as the processing operations mentioned under Section 3. involve the transmission of data to recipients domiciled outside the European Union or the European Economic Area, the respective servers are located in the United States. The relevant transmission of data is made in accordance with the principles of the “Privacy Shield” and on the basis of standard contractual clauses from the EU Commission.

5. Your rights

5.1. Overview

In addition to the right to withdraw any consent given to us, you are entitled to exercise the following additional rights if the respective legal requirements are met:

Right of access to your personal data stored by us in accordance with Art. 15 GDPR; in particular, you can obtain information about the processing purposes, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the origin of your data, unless it has been collected directly from you.

Right to rectification of incorrect data or completion of correct data according to Art. 16 GDPR.

Right to the erasure of your data stored by us in accordance with Art. 17 GDPR insofar as no legal or contractual retention periods, or other legal obligations or rights to further retention, must be observed.

Right to restriction of processing of your data in accordance with Art. 18 GDPR if the accuracy of the data is disputed by you, the processing is unlawful, but you refuse to erase it; the controller no longer needs the data but you need it to establish, exercise, or defend legal claims or you have objected to the processing in accordance with Art. 21 GDPR.

Right to data portability in accordance with Art. 20 GDPR, i.e. the right to receive selected data about you stored by us in a commonly-used, machine-readable format, or to request its transfer to another controller.

The right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority at your usual place of residence or workplace or our headquarters.

5.2. Right to object

Subject to the conditions of Art. 21(1) GDPR, data processing may be objected to for reasons arising from the particular situation of the data subject.

The general right of objection referred to above applies to all processing purposes described in this Privacy Policy that are processed on the basis of Article 6(1 f) GDPR. In contrast to the special right of objection related to data processing for advertising purposes, under the GDPR, we are only obliged to honor such a general objection if you give us reasons of overriding importance (e.g. a possible danger to life or health). In addition, you may also contact the supervisory authority responsible for Saint-Gobain Services Construction Products GmbH: The State Commissioner for Data Protection and Freedom of Information for Rhineland-Palatinate.

6. Data security

All data transmitted by you personally, including your payment information, is transmitted using the generally accepted and secure standard SSL (Secure Socket Layer). SSL is a secure and proven standard, which is also used in online banking, for example. You can recognize a secure SSL connection by the suffix “s” at the end of http (i.e. https://...) in the address bar of your browser or by the padlock symbol at the bottom of your browser.

We also use suitable technical and organizational security measures to protect your personal data stored with us against manipulation, partial or complete loss and against unauthorized access by third parties. Our security measures are continuously improved to meet state-of-the-art requirements.

We're using cookies to statistically monitor the usage of our website.

OK Deny tracking Privacy policy