Download Data Protection Information
Data protection information for employees, temporary workers, Bachelor and Master students, interns, applicants
Data protection information for customers, suppliers, partners
Welcome to BEWA solutions GmbH
Thank you for your interest in our online presence. The protection of your personal data and the protection of your privacy are very important to us. At this point, we would therefore like to inform you about the processing of your personal data when visiting our website. Of course, we comply with the legal provisions of the European Data Protection Regulation (DS-GVO), the Federal Data Protection Act (BDSG), the Telecommunications Digital Services Data Protection Act (TDDDG) and other data protection regulations.
Please note the explanations/definitions of terms at the end of the text
You can visit our website anonymously at any time. We respect the freedom of the individual to decide when and for what purpose he or she wishes to provide certain personal information. We do not use any technologies to identify you or create personal profiles!
We collect personal data only to a limited extent and where necessary for the following:
- Provision of our services
- Contract performance (including initiation, conclusion, fulfilment and termination of a contract)
- Processing and answering enquiries (contact form)
- Safeguarding our operations
- Improving our website
- Preventing, detecting and investigating potentially prohibited or illegal activities and asserting our General Terms and Conditions.
To ensure that you are fully familiar with the processing of personal data on our websites, we have compiled this clear and comprehensive information for you. We would like to assure you that we will make every necessary technical and organisational effort to protect your data.
1. Controller
Responsible for the processing of personal data is:
BEWA solutions GmbH
Horst-Uhlig-Str. 4
56291 Laudert
Germany
Phone: +49 / 6746 / 94 11 90
E-mail: mail@bewa-solutions.de
Other information: see Legal Notice
2. Data Protection Officer
As Data Protection Officer we have appointed:
Verimax GmbH,
Warndtstr. 115, 66127 Saarbrücken
Attn: Mr. Michael Grein
Fax: +49 / 89 / 800 65 78 – 29
E-mail: DSB-bewa-solutions@verimax.de
Reporting office in the event or suspicion of data protection incidents:
E-mail: datenschutz@bewa-solutions.de
3. Types of data and data subjects
When you access our websites, we automatically process data of a general nature. This data, which may be stored (where applicable) in “server log files”, includes:
- your browser type* (type/version)
- operating system of accessing computer*
- domain name of your internet provider (IP address)
- time of website access
- referrer URL* (site previously visited)
- cookies if applicable/in some cases (also see section 4 below.)
- and other similar general data (e.g. size of your browser window).
*If necessary, you can disable this data by making the appropriate settings in your system.
This data is used in accordance with Article 6 (1)(b) GDPR to provide you with the websites and to display them correctly; it is accessed each time you use the internet.
In addition, the data is temporarily stored in accordance with Article 6 (1)(f) of the GDPR for the purpose of fraud prevention and to investigate attacks on our website when our system detects such attacks.
The data is also further processed for statistical purposes after the IP address has been anonymized. Since this data no longer (can) be linked to any specific individual, it is no longer considered processing within the meaning of the GDPR.
4. Cookies
“Cookies” are small information packages that are stored on your computer by a domain (in this instance: schottel.de) and can only be processed again by this domain. Cookies cannot contain or spread malicious code or start programs.
We do not tolerate cookies from third-party domains and use our own cookies extremely sparingly. We never store any personal data in them and use them only for the following purposes:
| Cookie-Name | Purpose | Storage period | Art |
| wp-wpml_current_language | Saving the selected language for the current session | until the end of the meeting | Cookie |
The information generated by the cookies about your use of this website is never passed onto third parties. You can decide at any time if and which cookies are allowed or not allowed on your computer. You can also delete individual or all cookies on your computer at any time. To do this, use the settings in your web browser.
5. Collection and storage of usage data (statistics)
In order to optimize our websites and adapt them to changing habits and technical requirements, we use statistical tools. In doing so, we measure, for example, which elements are visited by users, whether the information they are looking for is easy to find, and so on. This information only becomes interpretable and meaningful at all when a larger group of users is considered. For this purpose, the collected data is aggregated, i.e. combined into larger units.
BEWA solutions GmbH does not profile visitors or use retargeting technologies and does not measure “customer journeys” by means of other sites. Therefore we are neither interested in the behaviour of an individual nor in the person behind it.
This enables us to adapt the design of web pages or optimize content if, for example, we find that a relevant proportion of visitors are using new technologies or finding existing information difficult or impossible to find.
For the statistics we use Matomo. This is software that is installed on our own server and also only processes data that has been stored on our server. Matomo uses cookies to recognize which page views belong to a session and whether you are a first-time or repeat visitor. Your IP address is anonymized immediately and before it is stored, so that you as a user always remain completely anonymous to us.
We take structural measures (separation of databases and responsibilities) to ensure that statistical data cannot contain or be linked to personal data at any time.
If your browser is configured to instruct our server that you do not wish to be tracked (“do not track”), Matomo will not record your visit to our site (we never store personal data anyway).
We neither sell statistical data nor do we share information about your browser session with third parties, regardless of whether you have enabled the “Global Privacy Control” feature in your browser. Information about your visit to our site is shared exclusively with social media platforms if you explicitly choose to be redirected there from our site.
6. Specific use of data
We observe the principle of data use for specific purposes and process your personal data only for those purposes for which you have provided the data. Your personal data will not be passed onto third parties without your express consent, unless this is necessary for the provision of the service or the execution of the contract. Furthermore, the transfer of data to state institutions and authorities entitled to receive information is only carried out within the scope of the legal obligation to provide information or if we are obliged to provide information by court order.
We also take our in-house data protection very seriously. We have obligated our employees and the service companies we commission to maintain secrecy and to comply with the provisions of data protection law.
7. Third country
There is no deliberate transfer of personal data to third countries or to international organizations, nor is there any plan to do so. However, when a website is accessed, it cannot be guaranteed that the data will remain within the EU/EEA. Due to the way the internet works, it may be technically possible that a request on the way from you to us or a reply on the way back may be routed via a server in a non-secure third country. This cannot be prevented either. However, since we encrypt the data traffic between your browser and our server (see section 8 below), there is no particular risk in this respect.
8. Data minimization, data economy and data security
In general, it is not necessary for you to provide personal data to use our website. However, in order for us to actually provide our services, we may need your personal data. This applies both to the sending of any information or ordered goods and to replies to individual requests.
If you commission us to provide a service or to send you goods, we shall only process your personal data in accordance with Article 6(1)(b) GDPR to the extent necessary to provide the service or implement the contract. For this purpose, it may be necessary to pass on your personal data to companies that we use to provide the service or implement the contract, such as transport companies or other service providers. If we wish to process your personal data for certain actions or services with your consent (in accordance with Article 6(1)(a) GDPR), we will ask you for your express consent at the appropriate point on our website.
Your personal data will be encrypted (bug-proof) on all pages with input fields by means of TLS/HTTPS for transmission over the internet (identifiable by the lock symbol in the URL line of the browser). We use technical and organizational measures to secure our website and other systems against loss, destruction, access, modification or distribution of your data by unauthorized persons.
9. Contact form and getting in touch
We offer you several ways to get in touch with us. One of these options is one of our contact forms. In order to process your inquiry, we need at least your first and last name, as well as an email address. In addition, you may voluntarily provide further information that will help us better address your inquiry or avoid follow-up questions. Your data will be transmitted in encrypted form.
Of course, you can also send us an email to an address published on the website. In this case, the personal data transmitted with the email will be stored.
If your inquiry relates to a service we offer, we process your data on the basis of Article 6(1)(b) of the GDPR. For all other inquiries, providing personal data is not required and is therefore based solely on your consent (Article 6(1)(a) of the GDPR). You grant your consent by providing the non-required data.
If you use a so-called “disposable” email address to contact us, you can also communicate with us completely anonymously.
Third country
During e-mail correspondence, it cannot be guaranteed that the data will remain within the EU/EEA. Due to the way the internet works, it may be technically possible that an e-mail on the way from us to you and vice versa may be routed via a server in a non-secure third country. Opt for the postal service if you want to send information confidentially, or encrypt the information/files separately (e.g. In an encrypted ZIP file) and send the key via another channel (e.g. SMS).
10. Storage period
Your processed personal data will only be stored for as long as it is necessary to fulfil the intended purpose. Once this purpose has been fulfilled, the data will be deleted, unless mandatory retention periods prevent this. In this case, the data will be limited in its processing so that it can only be used for the purpose that requires its retention (e.g. tax audit). Once these retention periods have expired, this data will also be deleted.
11. Profiling and automated decision-making
If we have access to the relevant information, a customer or prospective customer profile may be created in order to provide you with the best possible advice.
For this purpose, we use the following information in particular:
- Your contact data from registrations, requests and orders
We do not engage in automated decision-making, including profiling*, based on your personal data. However, we use so-called spam or junk filters in electronic communication to protect our systems. This involves the use of sender, time, content, character set and origin, among other things, to automatically sort out unwanted e-mails. If you feel that your e-mails have not arrived or are being rejected, please contact us via another communication channel (telephone, fax or letter).
* Merging individual data to gain insights into key aspects of personality.
12. Videos per Vimeo
For better performance, we use the provider Vimeo for the presentation of our videos so that they can be accessed from all parts of the world without any time lag. Vimeo is operated by Vimeo.com, Inc. with head office in New York (USA).
Note: The following information would be necessary to a similar extent if we used YouTube instead of Vimeo.
On some of our web pages we use software (plugins) from the provider Vimeo. If you call up the pages of our website that use such a plugin, no connection to the Vimeo servers is initially established – only a preview image is displayed. It is only by actively clicking actively the “Play Video” button in this preview image (consent), Vimeo reloads video data from the nearest server of its service providers (e.g. Akamai, Cloudflare). This consent applies for all Vimeo videos embedded on our website. In the process, data is transferred to the Vimeo server thereby revealing which of our websites you have visited. The consent is only valid for the current browser session, i.e. if you want to revoke the consent, please close your browser.
If you are logged in as a Vimeo member at the time, Vimeo may assign this information to your personal user account. This information may also be assigned to your user account when you use the plugin, such as by clicking the start, stop, fast forward or rewind buttons of a video. You can prevent this assignment by logging out of your Vimeo user account and deleting the relevant Vimeo cookies before activating the video. Regardless of this type of assignment to your Vimeo user account, your personal data will nevertheless be transferred to Vimeo – and therefore to a third country – even if you have no Vimeo user account.
A transfer to third countries is only permitted under the conditions of Chapter V of the GDPR. Vimeo.com, Inc. has been certified under the EU-US Data Privacy Framework since September 10, 2018. Further information regarding data processing and data protection by Vimeo can be found at https://vimeo.com/privacy.
13. Rights of data subjects
Subject to certain conditions or limitations as applicable, you have the following rights:
Right to information:
- data processed by us;
- the purposes of processing;
- the categories of personal data processed and, where appropriate, the (categories of) recipients to whom the personal data has been or will be disclosed (including, where applicable, appropriate safeguards if the personal data is transferred outside the EU);
- if possible, the intended duration for which the personal data will be stored or, if this is not possible, the criteria for determining this duration;
- and, if applicable, the origin of the data.
You have the right to rectification, deletion, restriction of processing, a right to data transferability, a right to object and a right to revoke consent at any time. This does not affect the legality of the processing of data up to the time of a revocation/objection. For the declaration of a revocation/objection, you will not be charged in addition to costs incurred by the basic rates. If costs are incurred in exercising the other rights, we shall inform you in advance. You may assert your rights against us via a designated channel (e.g. unsubscribe link) or any other communication channel (see “Controller” above or in the Imprint).
14. Queries regarding data protection and right of complaint
If you have any further questions about data processing on our website or about our processes, please contact the data controller listed above or our Data Protection Officer. You can also contact the Data Protection Officer confidentially at DSB-bewa-solutions@verimax.de.
If you believe you have a reason to file a complaint or if you notice a data protection violation, please contact our data protection team at: datenschutz@bewa-solutions.de.
We assure you that we will process your request promptly and thank you in advance for your support.
You also have the right to file a complaint with a supervisory authority. The supervisory authority responsible for the data controller is the State Commissioner for Data Protection and Freedom of Information in Rhineland-Palatinate.
You can also contact our Data Protection Officer directly:
Verimax GmbH, Warndtstr. 115, 66127 Saarbrücken
Attn: Mr. Michael Grein
Phone: +49 / 89 / 800 65 78 – 25
E-mail: DSB-bewa-solutions@verimax.de
15. Applications
Applying is really straightforward. We have made our application process as streamlined as possible to ensure that it progresses swiftly for both sides. Please send your documents digitally (ideally as a single PDF file) to karriere@bewa-solutions.de.
Please also note the information under “Third country” in section 9 above. As an alternative, you are also more than welcome to use the postal service.
We will conduct interviews with people on the short list together with the specialist and HR department and, depending on the position, also with the head of department. For trainees, there is an entrance test and for dual study students an assessment centre; in some cases, we also recommend a pre-study placement.
You can find out about vacancies on our career page and apply online. If you would like to apply for a position, we will need you to provide us with all the information and documents required as part of the application process. This is subject to Section 26 Federal Data Protection Act (BDSG).
Furthermore, you can provide additional information voluntarily (Section 26 BDSG (2)), which will enable us to assess your application more easily.
Recipients
Your data will be forwarded to our company employees entrusted with the respective matter. Depending on the subject matter, your data will also be transmitted to:
- affiliated companies of the SCHOTTEL Group, where applicable, external service providers and partners who provide data processing services on our behalf or otherwise process personal data for the purposes described in this notice or stated at the time of collection of the personal data;
- any competent supervisory body, court, law enforcement agencies, governmental authorities or third parties if we believe that processing is necessary
(i) to comply with applicable laws or regulations;
(ii) exercise, establish or defend our legal rights or
(iii) to protect your vital interests or those of third parties.
Appropriate data protection agreements have been concluded with the relevant external service providers, e.g. pursuant to Article 28 GDPR.
Data is not transferred to third countries as a matter of principle. Our servers are located within the EU or the EEA. If necessary, SCHOTTEL Group companies, external service providers and partners may be granted access to your personal data, even if they operate outside the EU/EEA.
In such cases, we ensure compliance with the provisions of Chapter V GDPR, in particular that personal data shall only be transferred to third countries if they offer an adequate level of protection in accordance with the European Commission (Article 45 GDPR) or if appropriate guarantees exist in accordance with Article 46 GDPR.
You can find the download titled “Privacy Notice for Employees, Temporary Workers, Bachelor’s and Master’s Students, Interns, and Job Applicants” at the top of this privacy policy.
16. Social media platforms
We use several social media channels as another way of getting in touch with you. In this case, personal data may also be processed outside the EEA, but we have no control over this. We have listed the (technical) operators of the relevant platforms at the end of this section. Addresses and other contact details can also be found there, e.g. for requests for information.
Your data and your usage behaviour will be comprehensively analysed by these operators. Cookies or comparable technologies or the storage of used IP addresses may be used for this purpose. The data may subsequently be used for advertising purposes and market research. This means that you may receive advertising tailored to your user profile within these platforms or on other sites that are able to use the cookies, etc., set by these platforms.
As a registered user of these sites, this information may also be used independently of the respective device. Some of the data uses are only permitted with your consent (Article 6(1)(a) GDPR) or may be justified by a legitimate interest in efficient advertising via a platform used worldwide (Article 6(1)(f) GDPR). Since the operators of the platforms determine the technologies used, we have no way of obtaining any necessary permissions from you or of weighing them against the interests of the parties concerned. Further details on this and on your user/data subject rights with the operators can be found in the privacy policies of their respective websites.
The social media channels we use are only intended to provide a convenient way of communicating with those users who are already members of these networks. It is not necessary and we do not recommend that you become a member of these networks in order to contact us. We also communicate information or special offers on other channels, in particular on our website. Please use one of our contact options to get in touch with us directly.
For our presence on Instagram, Linkedin or X (Twitter), we have concluded contracts with the European subsidiaries of the respective US groups. The contents of the contracts are specified by the portal operators. Although it is not necessary for technical or organizational reasons to process personal data obtained in Europe outside Europe, the companies reserve the right to transfer the data to the USA. We have no influence over this.
Since July 2023, the transfer of personal data based on the EU-US Data Privacy Framework has been permitted. The portal operators were certified accordingly at the time this privacy policy was created. We regularly review the certifications, typically annually. Since the certification can be revoked, and we neither know nor determine the purpose or scope of data processing (including in the USA), we cannot inform you about the legal basis nor obtain effective consent from you. Therefore, we ask you to only visit our social media presences or follow the links to them if you have an account with these services.
Facebook/Instagram:
Our contractual partner and (technical) operator of the Facebook/Instagram services is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, or its parent company, Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA – hereinafter referred to as “Meta.”
We restrict access to our Instagram account in such a way that only registered users are granted access. As a member of the social network “Facebook/Instagram” you can therefore follow us on our account. In doing so, personal data is processed by the operator, among other things, within the framework of the so-called ‘Insight’ service and provided to us in aggregated form (statistics). The processing may also take place outside the European Economic Area (EEA), particularly in the USA, which we cannot influence.
We are jointly responsible with Meta according to Article 26 GDPR and have concluded a “Page Insights Controller Addendum” with Meta. According to this, Meta is obliged to fulfill all obligations under the GDPR with regard to the processing of Insights data (including Articles 12 and 13 GDPR, Articles 15 to 22 GDPR, and Articles 32 to 34 GDPR). In addition, Meta will provide you with the essentials of the agreement (the Page Insights Addendum).
We have no influence on the extent of the data processed by Meta, nor does Meta inform us outside of the “Information on Page Insights Data” about which specific personal data is processed and how. As a member of Facebook/Instagram, you may have consented to the processing of your personal data by Meta and can influence the scope of the processing through appropriate settings in your user profile on Instagram.
Although Meta refers to the Data Privacy Framework certification, you must expect that various risks may arise for you as a user through the use. Meta informs about its privacy policy at: https://privacycenter.instagram.com/policy/. There you will find, in addition to the scope of data collection (for example: “Device Information”), the address and further contact options, for example, for information requests.
Your data, your device (contents), and your usage behavior are comprehensively analyzed by Meta. Cookies or similar techniques or the storage of IP addresses are used for this purpose. The data is mainly used for advertising purposes and market research. Thus, you receive advertising tailored to you within Facebook/Instagram or on other sites that are able to use the techniques employed by Meta based on your user profile.
As a registered user of the site, this information is also used regardless of the respective device. We can use the aggregated data provided to us by Meta within the framework of the ‘Page Insights’ function, which is not personally identifiable to us, to optimize our advertising measures on Instagram based on your consent given to us.
Your rights, especially according to Article 15 of the EU General Data Protection Regulation, in connection with the use of our fan page
Meta has committed to fulfilling all obligations according to Articles 15 to 22 GDPR (right to: information, correction, deletion, restriction of processing, data portability, and objection as well as the right not to be subject to a decision based solely on automated processing, if applicable). You can therefore exercise your rights (more quickly) directly against Meta. For more details on your rights with Meta, please refer to their (linked above) privacy policy. If you contact us to exercise your rights, we will forward your request to Meta within seven days. Meta has committed to responding.
We do not use any techniques offered by Meta for measuring and controlling advertising (“Instagram Insights”) on our websites.
LinkedIn:
We do not restrict access to our LinkedIn account so that you can visit us there “anonymously.” In this case, please make sure you have logged out of LinkedIn and deleted the LinkedIn cookies from your device beforehand.
As a member of the social network ‘LinkedIn’, you can follow our account there. In doing so, personal data is processed by the operator, including as part of the so-called ‘Insight’ service, and made available to us in summarised form (statistics).
Together with LinkedIn, we are ‘joint controllers’ in accordance with Article 26 of the GDPR and have concluded a ‘Page Insights Joint Controller Addendum’ with LinkedIn. According to this, LinkedIn undertakes to fulfil all obligations under the GDPR with regard to the processing of Insights data (including in accordance with Articles 12 to 22 GDPR and Articles 32 to 34 GDPR). If you contact us to exercise your rights, we will forward your request to LinkedIn within three working days. LinkedIn has undertaken to respond.
We have no influence on the scope of the data processed by LinkedIn, nor does LinkedIn inform us outside of the Page Insights Addendum about which specific personal data is processed and how. As a member of LinkedIn, you may have consented to the processing of your personal data by LinkedIn and can influence the scope of processing by adjusting the settings in your LinkedIn user profile.
Although LinkedIn refers to the Data Privacy Framework certification, you should be aware that using LinkedIn may involve various risks for you as a user. LinkedIn provides information about its privacy policy at: https://de.linkedin.com/legal/privacy-policy. There you will also find further contact options, e.g. for any requests for information or complaints. Please note that the transfer of personal data to the USA or third countries is only permitted under strict conditions. According to its own information (https://www.linkedin.com/help/linkedin/answer/62533), LinkedIn’s services require data transfer to the USA. BEWA solutions does not initiate any transfer to these countries, nor are we responsible for such transfers. If you do not wish such a transfer to take place, please do not use our LinkedIn presence.
Your data, your devices (including their contents) and your usage behaviour are analysed comprehensively by LinkedIn. Cookies or similar technologies or the storage of IP addresses are used for this purpose. The data is mainly used for advertising purposes and market research. Based on your user profile, you will receive tailored advertising within LinkedIn or on other sites that are able to use the techniques used by LinkedIn.
As a registered user of the site, this information is also used independently of the device you are using. We may use the aggregated data provided to us by LinkedIn as part of the “Page Insights” feature, which is not personally identifiable to us, to optimise our advertising measures on LinkedIn based on your consent.
We do not use any techniques offered by LinkedIn to measure and control advertising (“LinkedIn Insights”) on our websites.
17. Terms of Use
Please observe our Terms of Use.
18. Change of the privacy policy
Our Privacy Policy may be amended at irregular intervals to comply with current legal requirements or to implement changes to our services, e.g. when new offers are added. The new Privacy Policy will then automatically apply next time you visit.
Terms
GDPR:
Regulation (EU) 2016/79 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data (General Data Protection Regulation).
EU:
Europäische Union
EU-US Data Privacy Framework:
An international data protection agreement between the EU and the United States that serves as the basis for the adequacy decision under Article 45 of the GDPR, which has been in effect since July 2023.
ECJ:
European Court of Justice
EEA:
European Economic Area: EU, Iceland, Liechtenstein and Norway
Personal data:
any information relating to an identified or identifiable natural person […]; (Article 4(1) of the GDPR).
Controller:
the […] legal person […] which alone or jointly with others determines the purposes and means of the processing of personal data […]; (Article 4.7. of the GDPR)
The terms used here, as far as they are determined in Article 4 GDPR, are used according to the definition there.
Status of data protection information: April 2026