Privacy Policy SUSPA® Inc.

Welcome to our website and thank you for your interest in our company. We take the protection of your personal data very seriously. We process your data in accordance with applicable personal data protection legislation, in particular the GDPR and our country-specific implementation laws, which provide comprehensive information about the processing of your personal data by SUSPA® Inc. and your rights.

Personal data is any information that makes it possible to identify a natural person. This includes, in particular, your name, date of birth, address, telephone number, email address and IP address. Anonymous data is available if no personal reference to the individual/user can be made.

Responsible body and data protection officer

SUSPA® Inc.
3970 Roger B. Chaffee Memorial Dr
Grand Rapids, MI  49548
Telephone: 616.241.4200
Fax:            616.531.3310
sim(at)us.suspa.com
Contact info of the data protection officer: datenschutz(at)de.suspa.com   

Your rights as a data subject

We would first like to notify you of your rights as a data subject. These rights are set out in Articles 15 - 22 GDPR, and include: 

  • The right of access (Art. 15 GDPR),
  • The right to rectification (Art. 16 GDPR),
  • The right to data portability (Art. 20 GDPR),
  • The right to object to data processing (Art. 21 GDPR),
  • The right to erasure / right to be forgotten (Art. 17 GDPR),
  • The right to restriction of data processing (Art. 18 GDPR).

To exercise these rights, please contact: datenschutz(at)de.suspa.com. The same applies if you have any questions regarding data processing in our company. You also have a right of appeal to the relevant data protection supervisory authority.

Right to object

Please note the following with respect to your right to object:

When we process your personal data for the purpose of direct marketing, you have the right to object to this data processing at any time without providing the reasons for such objection. This also applies to profiling insofar as it is associated with direct marketing.

If you object to the processing for direct marketing, we will no longer process your personal data for such purposes. The objection is free of charge and can be made informally, where appropriate to: datenschutz(at)de.suspa.com.

Should we process your data to protect legitimate interests, you may object to such processing at any time for reasons that arise from your specific situation; this also applies to profiling based on these provisions.

We will then cease to process your personal information unless we can demonstrate compelling legitimate grounds for processing such information that outweigh your interests, rights and freedoms, or the processing is intended to assert, exercise or defend legal claims.

Purposes and legal bases of data processing

The processing of your personal data complies with the provisions of the GDPR and all other applicable data protection regulations. Legal bases for data processing arise in particular from Art. 6 GDPR.

We use your data to initiate business, to fulfil contractual and legal obligations, to conduct the contractual relationship, to offer products and services and to consolidate customer relationships, which may include marketing and direct marketing. 

Your consent also constitutes a data protection regulation. In this respect, we will inform you of the purposes of data processing and the right to withdraw your consent. If the consent also relates to the processing of special categories of personal data, we will explicitly notify you in the consent process, Art. 88 (1) GDPR.

Processing of special categories of personal data within the meaning of Art. 9 (1) GDPR may only take place where necessary on the grounds of legal regulations and there is no reason to assume that your legitimate interests should prevail to the exclusion of processing such data, Art. 88 (1) GDPR.

Data transfers / Disclosure to third parties

We will only transmit your data to third parties within the scope of given statutory provisions or based on consent. In all other cases, information will not be transferred to third parties unless we are obliged to do so owing to mandatory legal regulations (disclosure to external bodies, including the supervisory authorities or law enforcement authorities).

Data recipients / categories of recipients

In our organisation, we ensure that only individuals who are required to process the relevant data to fulfil their contractual and legal obligations are authorised to handle personal data. 

In many cases, service providers assist our specialist departments to fulfil their tasks. The necessary data protection contract has been concluded with all service providers.  We transmit certain data, that accrue by browsing the web to marketing service providers to analyse the data.

Transfers of personal data to third countries

A transfer of data to third countries (outside the European Union or the European Economic Area) shall only take place if required by law or if you have provided your consent for such a transfer.

We transfer your personal data to service providers or group companies outside the European Economic Area. 

Period of data storage

We store your data for as long as such is required for the relevant processing purposes. Please note that numerous retention statutory periods require that data must be stored for a specific period of time. This relates in particular to retention obligations for commercial or fiscal purposes (e.g. commercial code, tax code, etc.). The data will be routinely deleted after use unless a further period of retention is required.

We may also retain data if you have given us your permission to do so, or in the event of any legal disputes and we use the evidence within the statutory limitation period, which may be up to 30 years; the standard limitation period is 3 years.

Secure transfer of data

We implement the appropriate technical and organisational security measures to ensure the optimal protection of the data stored by us against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. The security levels are continuously reviewed in collaboration with security experts and adapted to new security standards.

The data exchange to and from our website is encrypted. We provide https as a transfer protocol for our website, and always use the current encryption protocols TLS 1.2. In addition, we offer our users content encryption in our contact forms and applications. We alone can decrypt this data. It is also possible to use alternative communication channels (e.g. surface mail).

Obligation to provide data

A range of personal data is required to establish, implement and terminate the obligation and the fulfilment of the relevant contractual and legal obligations. The same applies to the use of our website and the various functions we provide.

We have summarised the relevant details in the above point. In some cases, legal regulations require data to be collected or made available. Please note that it will not be possible to process your request or execute the underlying contractual obligation without this information.

Data categories, sources and origin of data

The data we process is defined by the relevant context: it depends on whether, for example, you place an order online, enter a request on our contact form or if you want to send us an application or submit a complaint. 

Please note that we may also provide information at specific points for specific processing situations separately where appropriate, e.g. when making a contact request.

We collect and process the following data when you visit our website:

  • Web browser and operating system used
  • Information on the website from which you visited us
  • The IP address by your allocated Internet service provider (anonymised)
  • Files accessed, volume of data transferred, downloads/file export
  • Information on websites accessed on our site, including date and time
  • Referer is transmitted and saved as referrer in the log

For reasons of technical security (in particular to safeguard against attempts to attack of our web server), this data is stored in accordance with Article 6 (1) lit f GDPR. Anonymisation of  the IP address takes place immediately so that no reference is made to the user.

We collect and process the following data as part of a contact request:

  • Last name, first name
  • Contact information
  • E-Mail address
  • Info on wishes and interests

We process the following data as part of the ordering process:

  • Last name, first name
  • Company name
  • Delivery address, Invoice address
  • E-Mail address
  • Phone number
  • Payment information

We collect and process the following data as part of online applications (catalog downloads)

  • Last name, first name
  • Company name
  • E-Mail address
  • Phone number
  • Address

Selection of the language

When visiting our website we temporarily collect your full IP address to be able to automatically present the complete range of our internet pages in your local language. Your IP address will not be saved and will be cancelled after selection of the language. Insofar it will not be communicated to third parties. In this connection, we refer to our legitimate interest to offer an attractive and easily accessible internet site according to Article 6 I f EU-DSGVO.

Contact form / Contact via email

A contact form is available on our website which can be used to contact us electronically. If you write to us using the contact form, we will process the data you submitted in the contact form to respond to your queries and requests. 

In so doing, we respect the principle of data minimisation and data avoidance, such that you only have to provide the information we require to contact you, which is your email address and the message field itself. Your IP address will also be processed for technical reasons and for legal protection. All other data is voluntary, and additional fields are optional (e.g. to provide a more detailed response to your questions). 

If you contact us by email, we will process the personal information provided in the email solely for the purpose of processing your request. If you do not contact us using the forms provided, no additional data will be collected.

Web shop

We process the data provided by you within the scope of the order form solely to execute and fulfil the underlying contractual relationship, unless you agree to further use. The principle of data minimisation and data avoidance is observed here, as we only request data that is required to perform the contract or fulfil our contractual obligations (i.e. your name, address, email address, phone number and the payment data for the specific payment method you have chosen) or to collect data that is mandatory under the law. 

Your IP address will also be processed for technical reasons and legal protection. If this data is not provided, we will have to decline the conclusion of the contract, as we cannot then perform the contract or will be obliged to terminate an existing contract, where appropriate. You can of course provide additional data on a voluntary basis.

Registration / Customer account

Users can provide personal data to enable them to register on our website. The advantage here is that you can, in particular, view your order history and save your data to use for your next order, without having to re-submit it. 

Registration is therefore necessary to perform a contract (via our online shop) with you or required to implement pre-contractual measures.

When ordering in our online shop, we also require the billing address information for the delivery (title, first name, last name, address). If the delivery address is different from the billing address, the delivery address details mentioned above must also be provided.

When you register on our website, the user’s IP address and the date and time of registration are also stored. Activate the "Register now" to consent to the processing of your data. 

Please note: We will encrypt the password you entered which will be stored with us. Our company employees cannot view this password. They just can tell the system to send you a password hint email. 

In this event, use the "Forgotten password" function, which will send you an automatically generated new password by email. No employee is authorised to request your password by telephone or in writing. Please never disclose your password should you receive such requests.

Upon completion of the registration process, your data will be stored with us for use in the protected customer area. When you log in to our website with your email address as your username and your password, this data will be made available to you on our website (e.g. for orders in our online shop). Completed orders can be tracked in the order history. You can specify changes to the billing or delivery address here.

Registered persons are free to amend/correct the billing or delivery address in the order history. You can also contact our customer service team, who will be happy to apply any changes / corrections. You can of course cancel or delete the registration or your customer account by contacting our customer account: esupport(at)us.suspa.com

Payment systems / credit check

In our online shop you can pay by credit card. In order to proceed accordingly, the relevant payment data is collected to perform and process your order. The payment system we use implements SSL encryption to protect your data. Your IP address will also be processed for technical reasons and legal protection. 

The principle of data minimisation and data avoidance is observed in a manner that you only submit the data we need to process the payment and therefore fulfil the contract or to collect the payment for which we are under a legal obligation. We cannot fulfil the contract without this data, and we will therefore have to decline it.

Note on credit card payment: As a standard procedure with credit card payments, your credit card details will be checked and a credit check is carried out.

Automated decisions in individual cases

We do not use purely automated processing to make decisions.

Cookies

Our website uses “cookies” at various locations, which serve to make our offer more user-friendly, effective and secure. Cookies are small text files that are placed on your computer and stored by your browser (locally on your hard disk).

Cookies enable us to analyse how users use our websites so we can design the website content in accordance with the visitor’s needs. Cookies also allow us to measure the effectiveness of a particular ad and, for example, to place it based on the user's interests.

Most of the cookies we use are "session cookies", which will be automatically deleted after your visit. Persistent cookies are automatically deleted from your computer when their validity period (generally six months) has expired or you delete them yourself prior to expiry.

Most web browsers automatically accept cookies. You can generally change your browser's settings if you prefer not to send the information. You can still use the offers on our website without restrictions (exception: configurators).

We use cookies to make our offers more user-friendly, effective and secure. We also use cookies to analyse how users use our websites so we can design the website content in accordance with the visitor’s needs. Cookies also allow us to measure the effectiveness of a particular ad and, for example, to place it based on the user's interests.

Cookies are stored on the user’s computer which then transmits them to us. As a user, you therefore exercise full control over the use of cookies. You can change the settings in your Internet browser to disable or restrict the sending of cookies. In addition, cookies that have already been saved on your computer can be deleted at any time via an Internet browser or other software programs. All this is possible in all the current Internet browsers.

Please note: If you deactivate the placing of cookies on your device, you may not be able to access all our website functions in certain circumstances.

Web tracking

We do not use any web-tracking / online analysis programs and other techniques for evaluating your usage behaviour on our website.

Social plugins

You will find on our side links to social networks, these links won´t transmit personal data. 

Online offers for children

Persons under the age of 16 may not submit personal data to us or give a declaration of consent without the authorisation of their legal guardian. We encourage parents and guardians to actively participate in the online activities and interests of their children.

Links to other providers

Our website also contains clearly identifiable links to the Internet sites of other companies. Although we provide links to websites of other providers, we have no influence on their content, and no guarantee or liability can therefore be assumed for such. The content of these pages is always the responsibility of the respective provider or operator of the pages.

The linked pages were checked at the time of linking for potential legal violations and identifiable infringements. No illegal content was identified at the time of linking. However, a permanent content control of the linked pages is not reasonable without concrete evidence of an infringement and, upon notification of a violation of rights, such links will be promptly removed.