Legal notices

We are proud of our company – that’s why we work in a transparent and open fashion.

Data Privacy

PRIVACY POLICY

We at Raffinerie Heide take data protection very seriously and want to guarantee that your privacy is protected at all times when you use our website. The following privacy policy therefore explains how we handle your data on heiderefinery.com (the ‘Raffinerie Heide website’ or ‘website’).

Übersicht
I. General information about the collection of personal data
II. Contact details of the controller and data protection officer
III. Information about legal grounds and duration of storage
IV. Your rights
V. Visits to the Raffinerie Heide website and generation of log files
VI. Contacting Raffinerie Heide
VII. Applying to Raffinerie Heide via the online application portal
VIII. Newsletter
IX. Use of Cookies and Marketing tools
X. Company profiles on social media
XI. Transfers to third parties
XII. Security standards
XIII. Amendments to this privacy policy

 

I. General information about the collection of personal data

The Raffinerie Heide website is operated by Raffinerie Heide GmbH (‘Raffinerie Heide’). This privacy policy describes how Raffinerie Heide (‘we’, ‘us’ and ‘our’) uses and protects the personal data collected through the Raffinerie Heide website.

Personal data are any data that relate to you personally such as your title, name, address, email address and IP address. We only collect and process your personal data in accordance with the provisions of the European Union General Data Protection Regulation (EU GDPR) and other provisions of European and applicable national data protection legislation.

This privacy policy exclusively applies to our Raffinerie Heide website. If you are redirected to third-party websites or apps by links on our Raffinerie Heide website, please read about how those parties handle your data in each case. The same applies if you are redirected to other websites belonging to us from the Raffinerie Heide website.

II. Contact details of the controller and data protection officer

The controller in the sense of the GDPR and all other applicable data protection regulations in the European Union is Raffinerie Heide. If you have any questions, suggestions or criticisms in connection with data protection on our Raffinerie Heide website, please contact:

Raffinerie Heide GmbH
Meldorfer Strasse 43
25770 Hemmingstedt
Email: info@heiderefinery.com

If they have any questions or suggestions concerning data protection, the data subject can also contact our data protection officer directly at any time. The data protection officer is available at the address above and at datenschutzbeauftragter@heiderefinery.com.

III. Information about legal grounds and duration of storage

1st Legal grounds for the processing of personal data

Where we obtain your consent to process personal data, Article 6, paragraph 1 a), of the GDPR serves as the legal grounds for the processing of personal data. You can withdraw consent with future effect.

Article 6, paragraph 1 b), of the GDPR serves as the legal grounds for the processing of personal data where the processing is necessary for the performance of a contract with you or your company. This also applies to processing that becomes relevant prior to the conclusion of a contract.

Article 6, paragraph 1 c), of the GDPR serves as the legal grounds where it is necessary to process your personal data in order to comply with our legal obligations.

Article 6, paragraph 1 f), of the GDPR serves as the legal grounds where processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where our legitimate interests are overridden by your interests, fundamental rights and freedoms.

2nd Duration of storage and erasure of data

As a rule, we only store the personal data we collect, process and store for as long as necessary for the specific purpose. When the purpose for which the data are being stored no longer exists, your data are erased or their processing is restricted.

Furthermore, however, it is possible that European regulations, applicable national laws or other regulations require us to store data we are processing for a longer period of time. We will erase your data or restrict their processing when these time limits expire.

IV. Your rights

When we process personal data concerning you, you are a data subject in the sense of the GDPR. As a data subject, you have the following rights with regard to Raffinerie Heide:

1st Right to access information about processing

In line with the statutory provisions, you can obtain from us information as to whether personal data relating to you are being processed by us at any time. If this is the case, you have the right to demand information about the scope of data processing (Article 15 of the GDPR).

2nd Right to rectification

If we are processing personal data concerning you which are inaccurate or incomplete, you have the right to have Raffinerie Heide rectify and/or complete your data (Article 16 of the GDPR).

3rd Right to restrict processing

Where the requirements are met, you have the right to demand the restriction of processing of your personal data (Article 18 of the GDPR).

4th Right to erasure

Where the requirements are met, you can demand that Raffinerie Heide erase the personal data concerning you without undue delay. The right to erasure does not exist to the extent that processing is necessary (Article 17 of the GDPR).

5th Right to notification

Raffinerie Heide will communicate any rectification or erasure of personal data or restriction of processing to which you have exercised your right to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller will notify these recipients if you request it (Article 19 of the GDPR).

6th Right to data portability

You are entitled to receive the personal data concerning you which you have provided to Raffinerie Heide in a structured, commonly used and machine-readable format. Additionally, you have the right to transmit those data to another company without hindrance from Raffinerie Heide, to which the personal data have been provided, provided that the requirements for this are met (Article 20 of the GDPR).

7th Right to object

You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you which is based on Article 6, paragraph 1 f), of the GDPR (Article 21, paragraph 1, of the GDPR). If you object, Raffinerie Heide will no longer process the personal data concerning you unless Raffinerie Heide demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
Where personal data concerning you are processed for direct marketing purposes, you have the right to object, at any time, to processing of personal data concerning you for such marketing (see Article 21, paragraph 2, of the GDPR).

You can use the contact details below to notify us of your objection:

Raffinerie Heide GmbH
Meldorfer Strasse 43
25770 Hemmingstedt
Email: kommunikation@heiderefinery.com

8th Right to withdraw consent

Where you have given consent to data processing, you can withdraw it at any time (Article 7 of the GDPR). The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

9th Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR (Article 77 of the GDPR).

V. Visits to the Raffinerie Heide website and generation of log files

Every time you visit our Raffinerie Heide website, our system automatically collects data and information from your computer system. The following data in particular are collected:

  • Page from which the file was requested
  • File name
  • Date and time of the request
  • Time you spend on the site
  • Volume of data transferred
  • Access status (i.e. whether the file has been transferred, potentially not found, etc.)
  • Anonymised IP address of your computer
  • Description of the type and version of your browser
  • Your operating system and screen resolution

These data concerning you are stored in log files in our system. These data are not stored together with other personal data. As your IP address is anonymised by the host as soon as you visit the website, your IP address is anonymous when it is stored in the log files.

Article 6, paragraph 1 f), of the GDPR serves as the legal grounds for the temporary storage of the data and for the log files. We have a legitimate interest in collecting and temporarily storing the data because it is necessary for the system to temporarily store your IP address in order that the website can be sent to your computer.

It is stored in log files to guarantee the functionality of the website. We also use these data in order to optimise our website and guarantee the security of our IT systems. Your log files will not be evaluated for marketing purposes.

As soon as they are no longer necessary for the purpose stated in this privacy policy, the data will be erased or masked to prevent them from being associated with you. In cases where the data are stored in log files, the data are normally erased after seven days.

VI. Contacting Raffinerie Heide

1st By email, phone and fax

Our Raffinerie Heide website provides an email address, a phone number and a fax number for you to get in touch with us. If you send us an email, we will store your email address and other data you provide each time. Even if you phone us or send us a fax, we might store the data we need to respond to your enquiry. The processing is based on Article 6, paragraph 1 b) and f), of the GDPR, as you may be contacting us in order to initiate a contract. However, Raffinerie Heide also has a legitimate interest in processing your data in order to respond to you.

If we would like to use your data for marketing purposes, especially your phone or fax number or your email address, we will ask for your consent first. In this case, Article 6, paragraph 1 a), of the GDPR serves as the legal grounds. You may withdraw your consent at any time with future effect. In cases of direct marketing, our processing of data is also based on our legitimate interest pursuant to Article 6, paragraph 1 f), of the GDPR.

The data will be erased as soon as they are no longer necessary for the purpose for which they were collected and the erasure is not prevented by any statutory or contractual storage obligations. This is the case after a maximum of ten years. The conversation will be considered ended when the circumstances imply that the matter in question has been resolved.

2nd By contact form

Our website features a contact form that you can use to contact Raffinerie Heide electronically. If you make use of the form, the data entered in the contact form will be transmitted to us and stored.

The data will be processed on the basis of Article 6, paragraph 1 a), b) or f), of the GDPR. Besides the purposes described above, we will only process the personal data provided in our contact form to process your enquiry, which is in our interest. For instance, this might be the initiation of a contract. The data will be erased as soon as they are no longer necessary for the purpose for which they were collected and the erasure is not prevented by any statutory storage obligations. The conversation will be considered ended when the circumstances imply that the matter in question has been resolved.

3rd Contact for contract signings

We may use DocuSign (Main Street 221, 94105-0000 San Francisco, US) for digital contract management and contract signing with you. For this purpose, your name, e-mail address, signature, company and the language you use will be processed. The periods for the retention period result from § 257 HGB and § 147 AO. Accordingly, commercial or business letters must be kept for 10 years.

As the legal basis for digital contract management and contract signing, we cite our legitimate interest in accordance with Art. 6 (1) lit. f GDPR. Our interests are:

  • Extension of legal certainty
  • Increased audit security
  • Increased user-friendliness

Usually, no data transfer to third countries is intended. DocuSign warrants that no data transfer to the headquarters in the United States will take place and that all data of European citizens will be processed on servers in the EU. However, since at the end of the signing process each signatory receives a copy of the signed document, it may happen that their personal data, such as name and signature, are transferred to a third country if one of the signatories is located in a third country.

You have the right, on grounds relating to your particular situation, to object to processing at any time in accordance with Article 21 (1) GDPR.
The contact details of the controller and the data protection officer can be found in Section II of our data protection information. Your rights as a data subject can be found in Section IV of our privacy policy.


VII. Applying to Raffinerie Heide via the online application portalPlease see the separate privacy policy regarding the collection and processing of your personal data as part of the application process at Raffinerie Heide. The separate privacy policy regarding the application process applies on a supplementary basis alongside this general privacy policy.

The separate privacy policy is available at the following address: Raffinerie Heide GmbH (jobbase.io)

VIII. Newsletter

1st Newsletter subscriptions

We offer a job newsletter in our careers portal. When you subscribe to the job newsletter, we will use your email address to inform you of new job advertisements by means of the newsletter. If you consent, we will inform you about the latest job advertisements by means of the newsletter. The data you entered in the newsletter subscription form will be transferred to us in the process. This is typically:

  • Your email address
  • Potentially your name

We need your email address to send you the newsletter and to identify and verify your consent. You are free to volunteer the rest of the information.

We use the double opt-in procedure for newsletter subscriptions. This means that, after you register, we will send an email to the email address you provided prompting you to confirm that you wish to receive the newsletters. If you do not confirm your registration within 24 hours, the processing of your information will be restricted and the information will be erased automatically in one month. After you confirm your registration, we will store your email address and other information for the purposes of sending the newsletter. The legal grounds for this are provided by Article 6, paragraph 1 a), of the GDPR.

We will erase your data as soon as you unsubscribe from the newsletter or we discontinue it. You can unsubscribe from the newsletter at any time by withdrawing your consent with future effect. Every newsletter we send you contains a link for you to unsubscribe without any hassle. However, you can also unsubscribe from the job newsletter by visiting https://seu2.cleverreach.com/f/125616-301057/wwu/, by sending an email indicating your withdrawal of consent to info@heiderefinery.com or by sending a message to the controller named at the start of this privacy policy.

2nd Processing by CleverReach

Our job newsletter is sent by CleverReach, a newsletter distribution platform provided by CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany (‘CleverReach’). We use the services of CleverReach as part of a processing agreement. For statistical purposes, CleverReach analyses what links users click on in the newsletter. Your name and email address are shared with CleverReach at this point. After anonymising them, CleverReach processes both of these as well as your user behaviour.

CleverReach is based in Germany and performs its services in accordance with the GDPR. Likewise, CleverReach will only share your data with third parties in line with the legal requirements of the GDPR.

CleverReach will erase your data as soon as we ask CleverReach to erase or return your data. This is the case, for example, if you withdraw your consent.

The privacy policy of CleverReach is available at https://www.cleverreach.com/en/privacy-policy/.

IX. Use of cookies and marketing tools

1st General information about cookies

In addition to the aforementioned data, various types of cookies are used and stored on your computer or mobile device when you use our Raffinerie Heide website. Cookies are small text files which are stored on your computer or mobile device when you visit our Raffinerie Heide website. We receive various information from cookies.

We do not engage in user tracking or web analytics with sensitive user data.

We use the following types of cookies:

  • Essential cookies: These cookies are essential for the website to work properly.
  • Functional cookies: Using cookies, we can also provide you with more user-friendly services which would be completely impossible without cookies.
  • Performance cookies: We do not currently use these cookies. These cookies enable us to count visits and sources of traffic so we can measure and improve the performance of our website. They help us determine what pages are most popular, what pages are used least often and how users behave on the website. All of the information collected by these cookies is aggregated and therefore anonymous. If you do not allow these cookies, we cannot know when you have visited our website.

If we ask for your consent, Article 6, paragraph 1 a), of the GDPR serves as the legal grounds. You can withdraw your consent at any time with future effect. Where the cookies are necessary for the performance of a contract, Article 6, paragraph 1 b), of the GDPR serves as the legal grounds. Otherwise, our processing of data is based on our legitimate interest pursuant to Article 6, paragraph 1 f), of the GDPR: we want to provide you with a comprehensive service that is always up to date.

We will use the data collected by cookies for as long as the data are necessary for the stated purpose.

2nd Cookies we use

Cookies are stored on your computer. You can decide to delete the cookies from your computer at any time. In your browser settings, you yourself can deactivate or limit how your computer sends cookies to us or even clear the cookies completely. If all cookies are deactivated for our website, this might result in the features of the website not being fully available.

The following list provides more information about how to deactivate or manage your cookie settings in your browser:

You can also change your cookie settings on the Raffinerie Heide website. When you go to Heide Raffinerie – Data privacy and legal notices (heiderefinery.com), you can choose what types of cookies to activate on the Raffinerie Heide website and what ones you wish to deactivate by opting out. You can change your settings at any time. Please note: If you clear your cookies, the opt-out cookie will be erased too and you will need to activate it again if you want to continue using it.

You can change the settings for cookies here: Cookie Settings

Here you will find an overview of the cookies we use:

Essenziell

Essenzielle Cookies ermöglichen grundlegende Funktionen und sind für die einwandfreie Funktion der Website erforderlich.

WPML WordPress Mulitlingual

NameWPML WordPress Mulitlingual
VendorOwner of this website
PurposeSaves the current language setting.
Cookie Name_icl_*, wpml_*, wp-wpml_*
Cookie validity1 Tag

Externe Medien

Inhalte von Videoplattformen und Social-Media-Plattformen werden standardmäßig blockiert. Wenn Cookies von externen Medien akzeptiert werden, bedarf der Zugriff auf diese Inhalte keiner manuellen Einwilligung mehr.

OpenStreetMap

NameOpenStreetMap
VendorOpenstreetmap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom
PurposeWird verwendet, um OpenStreetMap-Inhalte zu entsperren.
Privacy Policyhttps://wiki.osmfoundation.org/wiki/Privacy_Policy
Host(s).openstreetmap.org
Cookie Name_osm_location, _osm_session, _osm_totp_token, _osm_welcome, _pk_id., _pk_ref., _pk_ses., qos_token
Cookie validity1-10 Jahre

YouTube

NameYouTube
VendorGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
PurposeUsed to unlock YouTube content.
Privacy Policyhttps://policies.google.com/privacy
Host(s)google.com
Cookie NameNID
Cookie validity6 Monate

Jobbase.io (Prescreen)

NameJobbase.io (Prescreen)
VendorPrescreen.io
PurposeWe use the applicant management system of our content partner Prescreen in the job-section of our website. Cookies are set for the application and the display of the currently retrieved job advertisement.
Privacy Policyhttps://prescreen.io/en/privacy-policy/
Host(s)www.heiderefinery.com
Cookie Nameps_widget_token, PHPSESSID
Cookie validity1 Woche, Session 1 Tag

3rd Borlabs

Our website uses cookie consent technology from Borlabs in order to obtain your consent to the storage of certain cookies on your device and document it in accordance with the data protection regulations.
This is a service that runs exclusively on the Raffinerie Heide website and does not pass on any data.

When you enter our website, your consents and other declarations on cookie use are obtained via a cookie box. Borlabs then stores an essential cookie in your browser in order to be able to allocate the consents given to you or their revocation. The data collected in this way is stored until you request us to delete it, delete the Borlabs cookie yourself or the purpose for storing the data no longer applies. Mandatory legal storage obligations remain unaffected.

We use Borlabs in order to obtain the legally required consent to the use of cookies. The legal grounds for this are provided by Article 6, paragraph 1, sentence 1 c), of the GDPR.

4th Google Fonts

The Raffinerie Heide website uses Google Fonts to display fonts from Google in a consistent manner. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (‘Google’) is responsible for this in Europe. We have integrated the fonts locally – that is, on our web server – and not on the servers of Google. This means that there is no connection with Google servers and therefore no data is transferred or stored.

5th YouTube

The Raffinerie Heide website uses embedded content (videos) from YouTube which is stored on https://youtube.com and can be played on our website directly in order to improve user-friendliness and present various types of content (such as the work of Raffinerie Heide). It is provided by YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA, represented by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (‘YouTube’). In the United States and Canada, the representative is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

We have embedded our videos in privacy-enhanced mode so your data remain private when you view them.

YouTube normally uses cookies to analyse how you use the website and obtain your IP address. However, according to YouTube, no data relating to user activity are collected in privacy-enhanced mode.

If you access the Raffinerie Heide website with such content, a connection will be established with the YouTube servers. If you play the video, the content will be sent to your browser and played on our website. In the process, the YouTube server is notified of what websites you have visited. If you are also logged in to YouTube at the same time, YouTube will be able to associate this information with your personal user account. You can prevent this by logging out of your YouTube account before you visit the Raffinerie Heide website. According to YouTube and Google, the collected data are also transferred to the United States and other third countries.

According to Google and YouTube, Google uses general legal conditions and takes other steps to guarantee an adequate level of data protection.

YouTube is used on the basis of Article 6, paragraph 1 f), of the GDPR, as Raffinerie Heide has a legitimate interest in processing the data in this case. We use YouTube to provide you with video content. We will only process your data for as long as necessary for the purpose for which the data were collected.

To opt out, please visit https://adssettings.google.com/authenticated.

The privacy policy of YouTube and Google is available at https://policies.google.com/privacy.

6th ‘Share’ links on social networks

The content on our website can be shared on social networks such as XING, LinkedIn, Facebook, Twitter and Pinterest. Our websites do not contain plug-ins that are provided by the social networks Facebook, Twitter, Pinterest, etc. User data are not transferred to the operators of these platforms automatically on our website. Our ‘Share’ links only establish a connection between users and the networks when the user actively clicks on one of the links. When ‘Share’ links from XING, LinkedIn, Facebook, Twitter and Pinterest are used, an information window will open where the user can edit the text before posting it if the user is logged in to one of the social networks. This means that our users can post Raffinerie Heide content on social networks without the operators of the networks generating complete surfing profiles.

X. Company profiles on social media

1st General information about data processing by social media platforms

We operate publicly accessible company profiles on social media in order to share information about news, events and services of Raffinerie Heide and to give insights into Raffinerie Heide itself. The profiles also make it possible for us to contact you if you are a user of the social media platform. See below for details about the platforms on which we have company profiles.

Social media platforms such as Facebook and Twitter can normally thoroughly analyse your user behaviour when you visit their website or a website with integrated social media content (e.g. ‘Like’ buttons or web banners). Visiting our social media platforms initiates numerous data processing procedures. Each social media platform is able to send us anonymous statistics and insights into things such as how users interact with our posts. From this information, we can see whether visitors of the platform have visited our website through our company profile as well as details such as age and gender groups (the latter only if the users are logged in). We have no control over the data that are sent to us and cannot prevent the social media platforms from carrying out this procedure. We use the data that are sent to us to optimise our posts and company profile and tailor them to the interests of people who visit our website.

The social media platforms will install cookies on your device or collect your IP address. The purpose of this is to analyse your visit to the social media platform and our company profile for statistical and market research purposes, and it can help optimise future advertising by the social media platforms. Consequently, it is possible that the social media platforms will use the data they collect about your user behaviour to show you personalised advertisements which can appear on any device on which you are or were logged in.

If you are logged in to a social media platform when you visit our company profile, the data relating to your visit to our company profile can be associated with your account and merged with your account data. Please note that it is possible for social media platforms to collect your data even if you do not have an account.

Depending on the platform, your data might be processed in other ways as well. For more details, please see the terms of use and privacy policy of each social media platform.

2.1 Legal grounds

We have a legitimate interest in operating Raffinerie Heide sites and in processing your data from the company profile in order to design and implement contemporary means of sending information and communicating. The legal grounds for this are provided by Article 6, paragraph 1 f), of the GDPR.

If you use the messenger feature or the email address in our company profile to contact us, we will store your profile name and email address as well as other data you provide. The processing is based on Article 6, paragraph 1 b), of the GDPR, provided that you are contacting us in order to initiate a contract or about matters relating to a contract. We also have a legitimate interest in processing your data in order to respond to your enquiry.

The methods of analysis used by the social media platforms might be based on different legal grounds which the operators of the social media platforms must specify (e.g. consent in the sense of Article 6, paragraph 1 a), of the GDPR; consent can be withdrawn at any time).

You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you which is based on Article 6, paragraph 1 f), of the GDPR (see Article 21, paragraph 1, of the GDPR). If you object, Raffinerie Heide will no longer process the personal data concerning you unless Raffinerie Heide demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. Where personal data concerning you are processed for direct marketing purposes, you have the right to object, at any time, to processing of personal data concerning you for such marketing (see Article 21, paragraph 2, of the GDPR). You can use the contact details in section 2 to notify us of your objection.

2.2 Controller

In accordance with a decision by the European Court of Justice, operators of fan pages (including us) are a joint controller with the social media platform in the sense of the GDPR.

As the data (and user data) are collected and stored by the social media platform, you can also exercise your rights against the platform in question. See section IV for information about your rights with regard to us.

2.3 Duration of storage

The data will be erased as soon as they are no longer necessary for the purpose for which they were collected and the erasure is not prevented by any statutory or contractual storage obligations. The conversation will be considered ended when the circumstances imply that the matter in question has been resolved.

You can break the connection with our company profile and stop the related processing of your data by clicking on ‘Unfollow’ and removing the ‘Follow’ button (or clicking on ‘I no longer like this page’).

See below for information about the duration of storage and what data are stored by the individual social media platforms.

2.4 Types of data

We may process master data concerning your social media account (e.g. your first name and surname, address, email address, phone number, gender, age and date of birth), user data (e.g. websites you have visited and your interest in content) and content data (e.g. photos, videos and text).

3rd Company profiles on specific social media platforms

3.1 YouTube

We have a YouTube profile. The (joint) controller is Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland (‘YouTube’). For people who live in the United States and Canada, it is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. According to YouTube and Google, the collected data are also transferred to the United States and other third countries. YouTube and Google also use analytics tools (e.g. Google Analytics).

According to Google and YouTube, Google uses standard contractual causes and takes other steps to guarantee an adequate level of data protection.

If you wish to deactivate advertising cookies from YouTube and Google, please visit adssettings.google.com or adssettings.google.com/authenticated.

For details about how they handle your personal data, please see the YouTube privacy guidelines at support.google.com/youtube/answer/7585465 as well as its privacy policy at https://policies.google.com/privacy.

3.2 XING

We have a XING profile. The (joint) controller is New Work SE, Dammtorstrasse 30, 20354 Hamburg, Germany (‘XING’). According to XING, the data it collects are also transferred to third countries. XING uses advertising cookies. XING also uses analytics tools from other companies such as Google Analytics.

According to XING, it uses standard contractual clauses approved by the European Commission as well as other measures under EU law to legitimise data transfers from the EEA to other countries.

For more details, see the privacy policy of XING at https://privacy.xing.com/en/privacy-policy.

3.3 Kununu

We have a Kununu profile. The (joint) controller is New Work SE, Dammtorstrasse 30, 20354 Hamburg, Germany (‘XING’). According to XING, the data it collects are also transferred to third countries. XING uses advertising cookies. XING also uses analytics tools from other companies such as Google Analytics.

According to XING, it uses standard contractual clauses approved by the European Commission as well as other measures under EU law to legitimise data transfers from the EEA to other countries.

For more details, see the privacy policy of XING at privacy.xing.com/en/privacy-policy.

3.4 LinkedIn

We have a LinkedIn profile. The (joint) controller is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. For people who live in the United States and Canada, it is LinkedIn Corporation, 1000 West Maude Avenue, Sunnyvale, CA 94085, USA (‘LinkedIn’). According to LinkedIn, the collected data are also transferred to the United States and other third countries. LinkedIn uses advertising cookies. LinkedIn also uses analytics tools from other companies such as Google Analytics.

According to LinkedIn, it uses standard contractual clauses approved by the European Commission as well as other measures under EU law to legitimise data transfers from the EEA to the United States and other countries.

For more details, see the privacy policy of LinkedIn at https://www.linkedin.com/legal/privacy-policy.

XI. Transfers to third parties

1st Principles

We will only share your personal data with service providers, business partners and third parties in accordance with the relevant data protection legislation, and will provide you with sufficient information about this.

We can disclose personal data to service providers whose services we have engaged and have them undertake to process data on our behalf. In doing so, we comply with the strict national and European data protection regulations.

We can disclose personal data to a different third party if we are compelled to do so by a law or legal proceedings or in order to perform and manage our services. Additionally, we can be compelled to disclose information to a law enforcement agency or another authority. Likewise, we are authorised to disclose data if you give consent or if it is necessary to pass on information for the purposes of working together and therefore the performance of services for you by Raffinerie Heide. In most cases, disclosing data is also unavoidable when audits are pending.

2nd Web hosting with Host Europe

We host the Raffinerie Heide website and your data with companies including Host Europe, Hansestrasse 111, 51149 Cologne, Germany (‘Host Europe’). Host Europe is only authorised to access the data in line with our instructions (as a processor). Likewise, Host Europe implements strict technical measures to protect your personal data. Host Europe will not share your personal data with third parties except where the disclosure is necessary for the performance of the agreed services or Host Europe is obliged to do so in order to comply with a law or a valid compulsory order from a government or regulatory authority. The transferred data will be kept to the necessary minimum.

Your data are processed on the basis of Article 6, paragraph 1 f), of the GDPR. The purpose of data processing is for Host Europe to enable us to store data on Host Europe servers.

We will store the data for as long as we are required to do so by the statutory storage periods.

For more information about data protection at Host Europe, visit https://www.hosteurope.de/AGB/Datenschutzerklaerung/.

3rd Application development and website maintenance

We work with nordzuwort (owned by Katja Niebuhr), an agency for corporate design, websites and social media (‘nordzuwort’), in connection with application development and website maintenance. nordzuwort is based at Meldorfer Str. 22, 25770 Hemmingstedt, Germany.

nordzuwort is only authorised to access the data in line with our instructions (as a processor). Likewise, nordzuwort implements strict technical measures to protect your personal data. nordzuwort will not share your personal data with third parties except where the disclosure is necessary for the performance of the agreed services or nordzuwort is obliged to do so in order to comply with a law or a valid compulsory order from a government or regulatory authority. The transferred data will be kept to the necessary minimum.

nordzuwort is obliged to follow our instructions and is subject to strict contractual restrictions with regard to the processing of personal data. Under these restrictions, processing is only permitted where it is necessary to perform the services on our behalf or comply with legal requirements. At the outset, we define exactly what rights and duties nordzuwort is to have with regard to personal data.

4th Disclosure of investor data to our partners

For the purposes of processing your registration for the investors’ area and providing further investor support, your data will be shared with Klesch and Company Limited (‘Klesch & Co. Ltd’) which, like Raffinerie Heide, belongs to the Klesch Group. Klesch & Co. Ltd is based at 16 Palace Street, London, SW1E 5JD, United Kingdom.

Your data are processed on the basis of Article 6, paragraph 1 f), of the GDPR. The purpose of processing is to have Klesch & Co. Ltd manage account creation, admission to the secure investors’ area as an investor, and investor support and administration for internal administrative purposes, as it is in charge of central investor support for Raffinerie Heide within the Group. Klesch & Co. Ltd will store your data for as long as necessary in order to achieve the purpose. The data transfer to Great Britain fulfills the appropriateness according to the GDPR after examination by the European Commission. Great Britain is therefore a safe third country for data transfer.

XII. Security standards

Raffinerie Heide has implemented reasonable physical, technical and administrative security standards to protect personal data against loss, misuse, modification and destruction. Our service providers and affiliates are contractually obliged to treat personal data as confidential. Additionally, they may not use the data for purposes which have not been approved by us.

As the security of your data is very important to us, your entire visit takes place over a secure TLS connection. We use TLS 1.3 encryption. Where personal data are collected, the data transfer is also TLS-encrypted. TLS encryption prevents unauthorised third parties from accessing your data when they are transmitted over the internet.

XIII. Amendments to this privacy policy

We can update this privacy policy from time to time. We therefore recommend that you read this privacy policy on a regular basis so you are familiar with our data protection practices. This privacy policy was last updated on 14 April 2021.

Industrial property rights

The content of our website and the intellectual property it contains, including text, images, patents, trademarks and copyrights, are legally protected. The presentation of our company on the internet does not constitute a licence to use of this intellectual property. The duplication, transmission, alteration, public reproduction, dissemination or other use of this content is prohibited without the written consent of the respective legal owner.