With the following information, we would like to provide you, as a ‘data subject’, with an overview of how we process your personal data and of your rights under data protection legislation. In principle, it is possible to use our website without providing any personal data. However, if you wish to make use of specific services offered by our company via our website, the processing of personal data may be necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we will generally seek your consent.
The processing of personal data, such as your name, address or email address, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to “Datenschutz im Quadrat GmbH”. Through this privacy notice, we wish to inform you about the scope and purpose of the personal data we collect, use and process.
As the data controller, we have implemented numerous technical and organisational measures to ensure the most comprehensive possible protection of the personal data processed via this website. Nevertheless, internet-based data transmissions may, in principle, be subject to security vulnerabilities, meaning that absolute protection cannot be guaranteed. For this reason, you are free to provide us with personal data via alternative means, such as by telephone or post.
You, too, can take simple and easy-to-implement measures to protect yourself against unauthorised access to your data by third parties. We would therefore like to provide you with some guidance on how to handle your data securely:
l Protect your account (login, user or customer account) and your IT system (computer, laptop, tablet or mobile device) with secure passwords.
l Only you should have access to your passwords.
l Ensure that you only ever use your passwords for a single account (login, user or customer account).
l Do not use the same password for different websites, applications or online services.
l In particular when using IT systems that are publicly accessible or shared with others, it is essential that you log out every time after logging in to a website, application or online service.
Passwords should consist of at least 12 characters and be chosen so that they cannot be easily guessed. They should therefore not contain common everyday words, your own name or the names of relatives, but should include a mix of upper- and lower-case letters, numbers and special characters.
The data controller within the meaning of the GDPR is:
Gruber GmbH & Co KG
Muldenstraße 17–25
67069 Ludwigshafen
Email: info@sped-gruber.de
Representatives of the controller: Werner Weber, Kurt Richter
You can contact the Data Protection Officer as follows:
Datenschutz im Quadrat GmbH
Hans-Thoma-Straße 92
68163 Mannheim
www.dsiq.de
Email: sped-gruber@dsiq-dsb.de
You can contact our Data Protection Officer directly at any time with any questions or suggestions regarding data protection.
This privacy notice is based on the terminology used by the European legislative bodies when enacting the General Data Protection Regulation (GDPR). Our privacy policy is intended to be easy to read and understand for the general public as well as for our customers and business partners. To ensure this, we would like to explain the terms used at the outset.
In this privacy policy, we use the following terms, amongst others:
1. Personal data
Personal data means any information relating to an identified or identifiable natural person. A natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
2. Data subject
A data subject is any identified or identifiable natural person whose personal data is processed by the data controller (our company).
3. Processing
Processing means any operation or set of operations which is carried out on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or any other form of provision, the matching or linking, the restriction, erasure or destruction.
4. Restriction of processing
Restriction of processing means the marking of stored personal data with the aim of restricting its future processing.
5. Profiling
Profiling means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements of that natural person.
6. Pseudonymisation
Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures that ensure the personal data is not attributed to an identified or identifiable natural person.
7. Dataprocessor
A data processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the data controller.
8. Recipients
A recipient is a natural or legal person, public authority, agency or other body to whom personal data are disclosed, irrespective of whether or not they are a third party. However, public authorities which may receive personal data in the course of a specific investigation mandate under Union law or the law of the Member States shall not be regarded as recipients.
9. Third
party A third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons authorised to process the personal data under the direct responsibility of the controller or the processor.
10. Consent
Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, expressed in the form of a statement or by a clear affirmative action, by which the data subject indicates that they consent to the processing of personal data relating to them.
Article 6(1)(a) of the GDPR (in conjunction with Section 25(1) of the TDDDG (formerly the TTDSG)) serves as the legal basis for our company in relation to processing operations where we obtain consent for a specific processing purpose.
If the processing of personal data is necessary for the performance of a contract to which you are a party – as is the case, for example, with processing operations required for the delivery of goods or the provision of any other service or consideration – the processing is based on Article 6(1)(b) of the GDPR. The same applies to processing operations necessary for the implementation of pre-contractual measures, such as in cases of enquiries regarding our products or services.
Where our company is subject to a legal obligation which necessitates the processing of personal data, such as to fulfil tax obligations, the processing is based on Article 6(1)(c) of the GDPR.
In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were to be injured on our premises and their name, age, health insurance details or other vital information subsequently had to be passed on to a doctor, a hospital or other third parties. In such cases, the processing would be based on Article 6(1)(d) of the GDPR.
Finally, processing operations may be based on Article 6(1)(f) of the GDPR. This legal basis applies to processing operations not covered by any of the aforementioned legal bases, where the processing is necessary to safeguard a legitimate interest of our company or of a third party, provided that the interests, fundamental rights and freedoms of the data subject do not take precedence. We are permitted to carry out such processing operations in particular because they have been specifically mentioned by the European legislator. In this regard, the legislator took the view that a legitimate interest could be assumed if you are a customer of our company (Recital 47, second sentence, of the GDPR).
Our services are generally aimed at adults. Persons under the age of 16 must not provide us with any personal data without the consent of their parents or legal guardians. We do not request, collect or pass on any personal data from children or young people to third parties.
6.1 SSL/TLS encryption
This site uses SSL or TLS encryption to ensure the security of data processing and to protect the transmission of confidential information, such as orders, login details or contact enquiries, which you send to us as the site operator. You can recognise an encrypted connection by the fact that ‘https://’ appears in the browser’s address bar instead of ‘http://’, and by the padlock icon in your browser bar.
We use this technology to protect the data you send us.
6.2 Data collection when visiting the website
When you use our website purely for information purposes – that is, if you do not register, do not otherwise send us any information, or do not give your consent to processing operations requiring such consent – we collect only those data that are technically essential for the provision of the service. This typically comprises data that your browser transmits to our server (in so-called server log files). Each time you or an automated system accesses a page on our website, our website records a range of general data and information. This general data and information is stored in the server’s log files. The following may be recorded:
1. browser types and versions used,
2. the operating system used by the accessing system,
3. the website from which an accessing system reaches our website (known as a referrer),
4. the subpages on our website accessed via the accessing system,
5. the date and time of access to the website,
6. an Internet Protocol address (IP address) and,
7. the Internet service provider of the accessing system.
We do not draw any conclusions about your identity when using this general data and information. Rather, this information is required in order to
1. deliver the content of our website correctly,
2. optimise the content of our website and the advertising displayed on it,
3. ensure the long-term functionality of our IT systems and the technology underpinning our website, and
4. provide law enforcement agencies with the information necessary for criminal prosecution in the event of a cyber-attack.
We therefore analyse this collected data and information both statistically and with the aim of enhancing data protection and data security within our organisation, ultimately to ensure an optimal level of protection for the personal data we process. The data from the server log files is stored separately from any personal data provided by a data subject.
The legal basis for data processing is Article 6(1), first sentence, point (f) of the GDPR. Our legitimate interest arises from the purposes of data collection listed above.
6.3 Hosting by IONOS
We host our website with IONOS SE, Elgendorfer Str. 57, 56410 Montabaur (hereinafter referred to as ‘IONOS’).
When you visit our website, your personal data (e.g. IP addresses in log files) is processed on IONOS’s servers.
The use of IONOS is based on Article 6(1)(f) of the GDPR. We have a legitimate interest in ensuring that our website is displayed, provided and secured as reliably as possible.
We have entered into a data processing agreement (DPA) with IONOS in accordance with Article 28 of the GDPR. This is a contract required under data protection law, which ensures that IONOS processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Further information on IONOS’s data protection policy can be found at: https://www.ionos.de/terms-gtc/terms-privacy
7.1 General information about cookies
Cookies are small files that your browser creates automatically and which are stored on your IT system (laptop, tablet, smartphone, etc.) when you visit our website.
Information is stored in the cookie that relates to the specific device you are using. However, this does not mean that we thereby gain direct knowledge of your identity.
The use of cookies serves to make your experience of our website more convenient. For example, we use so-called session cookies to recognise that you have already visited individual pages on our website. These are automatically deleted when you leave our website.
In addition, to optimise user-friendliness, we also use temporary cookies which are stored on your device for a specific, pre-defined period. If you visit our site again to use our services, the system automatically recognises that you have visited us before and recalls the entries and settings you have made, so that you do not have to enter them again.
We also use cookies to collect statistical data on the use of our website and to analyse our offering for the purpose of optimisation. These cookies enable us to automatically recognise that you have previously visited our website when you visit it again. The cookies set in this way are automatically deleted after a defined period. The respective storage periods for the cookies can be found in the settings of the consent tool used.
7.2 Legal basis for the use of cookies
The data processed by the cookies, which is required for the website to function properly, is therefore necessary to safeguard our legitimate interests and those of third parties in accordance with Article 6(1)(f) of the GDPR.
For all other cookies, you have given your consent via our opt-in cookie banner in accordance with Article 6(1)(a) of the GDPR.
7.3 Usercentrics (Consent Management Tool)
We use the ‘Usercentrics’ consent management tool provided by Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany. This service enables us to obtain and manage website users’ consent to data processing.
Usercentrics collects data generated by end users who use our website. When an end user gives their consent, Usercentrics automatically logs the following data:
l Browser information.
l Date and time of access.
l Device information.
l The URL of the page visited.
l Geographical location.
l Page path on the website.
l The end user’s consent status, which serves as proof of consent.
The consent status is also stored in the end user’s browser, enabling the website to automatically read and honour the end user’s consent for all subsequent page requests and future end-user sessions for up to 12 months. Consent data (consent and withdrawal of consent) is stored for three years. The retention period corresponds to the standard limitation period in accordance with Section 195 of the German Civil Code (BGB). The data is then immediately deleted or, upon request, provided to the data subject in the form of a data export.
The functionality of the website cannot be guaranteed without the processing described above. The user has no right to object as long as there is a legal obligation to obtain the user’s consent for certain data processing operations (Article 7(1), 6(1), first sentence, point (c) of the GDPR).
Usercentrics is the recipient of your personal data and acts as a data processor on our behalf.
Detailed information on the use of Usercentrics can be found at: https://usercentrics.com/privacy-policy/.
8.1 Contacting us / Contact form
Personal data is collected when you contact us (e.g. via the contact form or by email). The data collected when using a contact form is specified on the relevant contact form. This data is stored and used solely for the purpose of responding to your enquiry or for establishing contact and the associated technical administration. The legal basis for the processing of the data is our legitimate interest in responding to your enquiry in accordance with Article 6(1)(f) of the GDPR. If your enquiry is aimed at concluding a contract, the additional legal basis for the processing is Article 6(1)(b) of the GDPR. Your data will be deleted once your enquiry has been fully processed; this is the case when the circumstances indicate that the matter in question has been conclusively resolved and there are no statutory retention obligations preventing deletion.
8.2 Application Management / Job Board
We collect and process the personal data of applicants for the purpose of handling the application process. Processing may also take place electronically. This is particularly the case where an applicant submits the relevant application documents to us electronically, for example by email or via a web form on the website. If we enter into an employment or service contract with an applicant, the data provided will be stored for the purpose of administering the employment relationship in accordance with statutory provisions. If we do not enter into a contract with the applicant, the application documents will be automatically deleted six months after notification of the rejection decision, provided that no other legitimate interests on our part preclude such deletion. An example of such a legitimate interest is the burden of proof in proceedings under the General Equal Treatment Act (AGG).
The legal basis for the processing of your data is Article 6(1)(b) and Article 88 of the GDPR in conjunction with Section 26(1) of the Federal Data Protection Act (BDSG).
Our website does not currently use any plugins or services.
10.1 Right to confirmation
You have the right to request confirmation from us as to whether personal data concerning you is being processed.
10.2 Right of access (Article 15 of the GDPR)
You have the right to obtain from us, free of charge, information at any time regarding the personal data we hold about you, as well as a copy of that data, in accordance with the statutory provisions.
10.3 Right to rectification (Article 16 of the GDPR)
You have the right to request the rectification of inaccurate personal data concerning you. Furthermore, you have the right to request the completion of incomplete personal data, taking into account the purposes of the processing.
10.4 Erasure (Article 17 of the GDPR)
You have the right to request that we erase personal data concerning you without delay, provided that one of the grounds laid down by law applies and insofar as the processing or storage is not necessary.
10.5 Restriction of processing (Article 18 of the GDPR)
You have the right to request that we restrict the processing of your personal data if one of the statutory conditions is met.
10.6 Data portability (Article 20 of the GDPR)
You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller to whom the personal data has been provided, without hindrance from us, provided that the processing is based on consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR or on a contract pursuant to Article 6(1)(b) GDPR, and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.
Furthermore, when exercising your right to data portability pursuant to Article 20(1) of the GDPR, you have the right to have the personal data transferred directly from one controller to another, provided this is technically feasible and does not adversely affect the rights and freedoms of others.
10.7 Objection – Article 21 of the GDPR
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) of the GDPR (data processing in the public interest) or Article 6(1)(f) of the GDPR (data processing based on a balancing of interests).
This also applies to profiling based on these provisions within the meaning of Article 4(4) of the GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves to establish, exercise or defend legal claims.
In certain cases, we process personal data for the purposes of direct marketing. You may object at any time to the processing of your personal data for the purposes of such marketing. This also applies to profiling insofar as it is related to such direct marketing. If you object to us processing your personal data for direct marketing purposes, we will no longer process your personal data for these purposes.
Furthermore, you have the right, on grounds relating to your particular situation, to object to the processing of personal data concerning you which we carry out for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1) of the GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.
You are free, in connection with the use of information society services, notwithstanding Directive 2002/58/EC, to exercise your right to object by means of automated procedures using technical specifications.
10.8 Withdrawal of consent under data protection law
You have the right to withdraw your consent to the processing of personal data at any time with effect for the future.
10.9 Lodging a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority responsible for data protection regarding our processing of personal data.
This privacy notice is currently valid and was last updated in August 2026.
As our website and services continue to evolve, or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. You can view and print the latest version of the privacy policy at any time on our website at “www.sped-gruber.de/datenschutzhinweise”.