Data protection

Salzgitter AG is delighted that you are interested in our company and have chosen to visit our website. We take the issue of protecting your personal data very seriously. This document explains how personal data is processed when using our website and outlines the rights you hold in this regard.

Controller, Data Protection Officer

The Controller pursuant to Art. 4 para. 7 EU General Data Protection Regulation (GDPR) is

Salzgitter AG
Konzernkommunikation
Eisenhüttenstr. 99
38239 Salzgitter, Germany
Phone: +49 5341 21-01

You can contact our Data Protection Officer either via post by addressing your letter to the “Data Protection Officer” or via email at:
datenschutz.holding@salzgitter-ag.de

Data processing

We specifically process the following personal data:

Server log files

Every time a user accesses our website and every time a file is downloaded, data regarding this process is temporarily stored in a log file. The stored data is analyzed anonymously and will only be used for internal statistical purposes so that we can continually improve the web content we offer. No person-related use takes place in this respect. In particular, a data set containing the following information is stored upon each user access:

  • the IP address used
  • the operating system used
  • the browser used
  • the time of access
  • the pages you visit on our site
  • the website you last visited (if transmitted)
  • the volume of data transmitted

Google Webfonts (local)

We have only integrated Google fonts locally on our website, i.e. no data is transferred to Google servers through their use.

Use of Google web fonts (local embedding)

On our website we use Google Fonts of the company Google Inc. For the European area the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible. We have embedded the Google fonts locally, i.e. on our web server - not on Google's servers. This means that there is no connection to Google servers and thus no data transfer or storage.

What are Google Fonts?

Google Fonts used to be called Google Web Fonts. This is an interactive directory of over 800 fonts that Google provides free of charge. With Google Fonts, you could use fonts without uploading them to your own server. However, in order to prevent any information transfer to Google servers in this regard, we have downloaded the fonts to our server. This way we act privacy compliant and do not send any data to Google Fonts. Unlike other web fonts, Google allows us unlimited access to all fonts. So we have unlimited access to a sea of fonts to get the most out of our website. You can find out more about Google Fonts and other issues at https://developers.google.com/fonts/faq?tid=111266255.

Libraries of ajax.googleapis.com for jQuery and jQueryUI

This site uses the javascript library jQuery from the content delivery network of Google. When your Browser downloads the jQuery library from Google, your data will be send from your browser to Google Inc. (“Google”). You agree that your Data will be stored in the USA.You can find out more about this at: https://developers.google.com/speed/libraries/#jquery and the privacy policy of google.de at https://policies.google.com/privacy?hl=en&gl=en.

Web analysis

Our website uses the web analysis tool Siteimprove, provided by Siteimprove GmbH, a company based in Berlin with servers in Germany and Denmark. This tool uses information of cookies and server log files: this information is transmitted to the Siteimprove server, where it is processed to evaluate visitors’ use of our website and to compile reports for us concerning website activities. Siteimprove does not pass this information on to third parties. IP addresses are irreversibly anonymized before the collected data is made accessible by Siteimprove Analytics. We have concluded a corresponding data processing contract with Siteimprove.

You can prevent Siteimprove from collecting your data at any time by adjusting your current selection under "Data protection settings". Doing so places an opt-out cookie that prevents your data from being collected when you visit our website in future. Please note that web analysis will only be prevented as long as the opt-out cookie is stored in your browser; if you delete the cookie, web analysis will not be prevented in future.

Opt-out - Disable Siteimprove Analytics: Adjust privacy settings

Web analysis

Our web site uses Matomo (formerly Piwik) - open-source software for the statistical evaluation of user visits. Cookies are used for this, which are text files stored on your PC. Usage information generated by the cookies is sent to our server and stored for user analysis purposes, helping us to optimize the web site. This procedure immediately renders your IP address anonymous, ensuring that you remain an anonymous user as far as we are concerned. The server on which the statistical data is stored belongs to a German provider and is also physically located in Germany.

You can prevent Matomo from collecting your data at any time by adjusting your current selection under "Data protection settings". Doing so places an opt-out cookie that prevents your data from being collected when you visit our website in future. Please note that web analysis will only be prevented as long as the opt-out cookie is stored in your browser; if you delete the cookie, web analysis will not be prevented in future.

Opt-out - Disable Matomo Web Analytics: Adjust privacy settings

Use of Indeed Conversion Tracking

We use the online advertising program "indeed Conversion Tracker" to evaluate the job advertisements published on our website. The indeed Conversion Tracker is an analysis service of indeed Ireland Operations Limited, (124 St. Stephen's Green, Dublin 2, Ireland "indeed"), which we use to measure how an application reached us. The method used to measure applications referred via indeed is a so-called tracking pixel, which is incorporated into the site programming by means of a 1x1 pixel transparent image. When visiting the website of indeed, a cookie is set in the browser of the respective visitor, which contains a so-called session ID. This session ID is unique and makes it possible to record which job ads the visitor has clicked on within the indeed site visit. If the visitor follows the application path via a job ad to such an extent that an application is completed, it can thus be reported back to the indeed customer account via the tracking pixel URL within the conversion tracker that an application with the respective session ID has taken place via a job ad placed by us on indeed. Accordingly, the data collection is done by indeed itself and indeed compares the collected data through the conversion tracker at the end of the application process with the cookie set on indeed. Subsequently, this information is transmitted to our employer account at indeed to identify the application. The session ID is valid for about one hour and is then deleted.

An opt-out cookie is set in this case, which prevents the future collection of your data when visiting this website. If you delete your cookies in the relevant browser, you must click this link again.

For further information and indeed's privacy policy, please visit: https://de.indeed.com/legal?hl=en&redirect=true

Opt-out - Disable Indeed Conversion Tracker: Customize privacy settings

Polyfill

We use the "Polyfill.io" service of The Financial Times Limited, Number One Southwark Bridge, London. This enables us to reproduce content in the best possible quality even on older browser versions. When you load a website that uses the Polyfill service, your browser will download all the Polyfill files necessary to display the website successfully or optimized in your browser. In order to provide the Polyfills, the Service receives certain technical information from your browser, including: browser details; connection data (such as your IP address); the URL of the website that made the request to the Service. This information is used to determine which Polyfills are required by your browser. The legal basis for this processing is Art. 6 paragraph 1 sentence 1 letter f DSGVO. The processing is based on our legitimate interest in enhancing your user experience and for the general optimisation of our website. The data will be deleted as soon as the purpose for which they were collected has been fulfilled. Further information on the handling of the transferred data can be found in the data protection declaration of polyfill.io: https://polyfill.io/v3/privacy-policy.

You can prevent the collection and processing of your data by polyfill.io by deactivating the execution of script code in your browser or by installing a script blocker in your browser (you can find this for example at www.noscript.net or www.ghostery.com).

Contact forms

If you wish to use the contact forms on our website to communicate with us, you will be required to enter your forename, surname and email address. We will not be able to process the issue you enter in the contact form without this information. Entering your postal address is optional; it enables us to process your issue and reply via post, if you wish. In addition, our system collects the IP address of the computer you use to submit the form as well as the date and time the form is submitted. The information you provide is collected to the required extent and is used exclusively for the purpose of processing your inquiry.

You can find information about online applications here.

Contact forms

If you wish to use the contact forms on our website to communicate with us, you will be required to enter your forename, surname and email address. We will not be able to process the issue you enter in the contact form without this information. Entering your postal address is optional; it enables us to process your issue and reply via post if you wish. In addition, our system collects the IP address of the computer you use to submit the form as well as the date and time the form is submitted. The information you provide is collected to the required extent and is used exclusively for the purpose of processing your inquiry.

You can find information about online applications here.

Google

Our website uses PlugIns from the company Google Inc. for depicting maps. These sites are operated by Google Inc., 1600 Amphitheatre ParkwayMountain View, California, 94043, USA. When visiting one of our sites that contains a Google PlugIn, a connection to the Google servers will be established. The Google server will receive information which sites you have visited. Further information about collection and use of user data can be found in the data protection declaration of Google available at: http://www.google.com/intl/de/privacy/privacy-policy.html

Social Plugins

On our website we integrated so called „Social Plugins“ of the following social networks: „Facebook“, „Instagram“, „YouTube“ „X (formerly known as Twitter)“, „Google Maps“, „LinkedIn“ and „XING“. Social plugins can be recognized by the corresponding logo of each network and/or additions like „Share on Facebook", „Share on LinkedIn", „Share on X" and „Share on XING".

Please note that by activating social plugins certain information may be transmitted to the provider of the respective social network, these include e.g. address of the website, which integrated the activated social plugin, exact date and time of your visit or of the activation of the social plugin; information regarding your current browser and software system; your current IP address.

If you are logged-in to a social network by the time you activate the social plugin, the provider is able to identify your user name or even your real name from the data mentioned above. In this case, the respective network provider can process the information even in countries outside of the European Union. This means that we have no influence over the processing of any of your data by the respective provider of the network. Please note, that the provider is able to create a pseudonymized and even individualized user profiles. At any time, you can deactivate the activated social plugins. But this does not affect the data, which already have been transmitted by the provider of the respective social network.

For any details regarding the purpose and extent of the data collection or its further processing and utilization by the networks, and regarding your relevant rights and your privacy setting please see the privacy notices of the provider of the respective social network:

• Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA - http://www.facebook.com/about/privacy/

• Instagram LLC, represented by Kevin Systrom and Mike Krieger, 1601 Willow Rd, Menlo Park CA 94025, USA - http://help.instagram.com/155833707900388

• X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103 USA - https://twitter.com/privacy

• Google Inc., 1600 Amphitheatre ParkwayMountain View, California, 94043, USA - http://www.google.com/privacy/privacy-policy.html

• LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Irland - https://www.linkedin.com/legal/privacy-policy

• XING SE, Dammtorstraße 30, 20354 Hamburg, Deutschland - https://privacy.xing.com/en

 

Newsletter

On our website, you have the possibility to subscribe to a free newsletter that provides you with information on our company on a regular basis. When you register for the newsletter, the data from the input mask are sent to us (name and E-Mail address). The following data are also collected during the registration: IP address of the computer on which you are working and the date and time of day of the registration.
To process the data, we obtain your consent and refer to this data protection statement as a part of the registration procedure. You will then receive an E-Mail from us with the request that you confirm your registration data (double-opt-in). This serves to authenticate you and prevent third parties from misusing your E-Mail address.
No data will be passed on to third parties in association with the data processing used to dispatch newsletters.  The data are used exclusively to dispatch the newsletter. You can cancel your subscription to the newsletter at any time. Each of the newsletters that we send you contains a link to cancel or end the subscription.

Newsletter

On our website, you have the possibility to subscribe to a free newsletter that provides you with information on our company on a regular basis. When you register for the newsletter, the data from the input mask are sent to us (name and e-mail address). The following data are also collected during the registration: IP address of the computer on which you are working and the date and time of day of the registration.

To process the data, we obtain your consent and refer to this data protection statement as a part of the registration procedure. You will then receive an e-mail from us with the request that you confirm your registration data (double-opt-in). This serves to authenticate you and prevent third parties from misusing your e-mail address.

In connection with the data processing to send newsletters, we are working with a German service provider that has certification in accordance with the GDPR (General Data Protection Regulation) and the BDSG (German Federal Data Protection Act). The data are sent directly to the service provider, who is forbidden to use the data for purposes other than to send the newsletter. The data are not permitted to be passed on or sold. The data are used exclusively to send the newsletter. You may elect to stop receiving the newsletter at any time. Each of the newsletters we send to you contains a link to unsubscribe or end the subscription.

YouTube

We have integrated YouTube videos on our website that are stored at www.youtube.com and can be viewed directly from our website.

They are all integrated in “privacy-enhanced mode”, which means that no data about you as a user is transmitted to YouTube, if you do not watch these videos. Data is only transmitted to the YouTube server when you play the videos. If you are logged into your YouTube account at the same time, this information is attributed to your YouTube user account. You can prevent this by logging out of your YouTube user account before visiting our website.

YouTube is operated by YouTube LLC, headquartered at 901 Cherry Avenue, San Bruno, CA 94066, USA. YouTube is represented by Google Inc., based at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. You can find more information about how YouTube (Google) handles user data at: www.google.de/intl/de/policies/privacy.

Mapbox

We use the services of Mapbox Inc. (Mapbox) to display interactive maps on some pages of our website. Using our website may lead to information about your use of this website, including your IP address, being transmitted to Mapbox in the USA.

When you access a page that contains Mapbox maps, your browser establishes a direct connection with Mapbox servers. The map content is directly transmitted by Mapbox to your browser, which integrates the content into the website. We therefore cannot influence the amount of data, which is collected by Mapbox in this manner.

If you do not want Mapbox to process your data via our website, you can deactivate JavaScript in your browser settings. However, if you choose to do so, you will not be able to view the maps on our site.

You can find further information about the purpose and scope of data processing by Mapbox, your rights in this regard, and the configuration options available to protect your privacy in the Mapbox privacy policy at: https://www.mapbox.com/privacy/.

You can prevent Mapbox from placing cookies on your device by deactivating third-party cookies in your browser settings.

Google Maps

This website uses the map service Google Maps from Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). This service is used through our location marketing service provider uberall.com to provide the "Global Locations at a Glance" feature. In order for the Google map material we use to be integrated and displayed in your web browser, your web browser must connect to a Google server when you access the location map. This server can be located in the USA. For more information, please refer to the Google Maps Terms of Use at https://www.google.com/intl/en_ALL/help/terms_maps/. To further enhance the usefulness of the location map feature, you may be asked to approve your location. Of course, you will not be able to release this without problems.

Uberall Locator

On our homepage, we use the uberall GmbH locator to search for and display the global locations of the Salzgitter Group. Locator is operated by uberall GmbH, Hussitenstraße 32-33, 13355 Berlin, Germany.

The uberall data protection declaration can be viewed at https://uberall.com/en-us/privacy-policy. To display the Salzgitter Group locations on a geographical map, uberall uses the Google Maps API (interface) within the Locator, a mapping service provided by Google LLC. ("Google"). For information on the use of "Google Maps", please refer to the following item "Google Maps" in our data protection declaration.

Google Maps

On this website we use the offer of Google Maps. This allows us to show you interactive maps directly on the website and enables you to conveniently use the map function such as displaying global location or planning a route to the location.

Google Maps is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The legal basis for the processing results from Art 6 I lit a, f DSGVO due to your voluntary information for the search and, when used, for the creation of a map and our legitimate interests in the presentation of our location as well as an easy findability of the places we indicate on the website.

By using Google Maps, information about your use of this website (including your IP address) may be transmitted to and stored by Google on servers in the United States. Google may transfer the information obtained through Maps to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google. Nevertheless, it would be technically possible for Google to identify at least individual users on the basis of the data received, especially if the user is logged in to Google. It would be possible that personal data and personality profiles of users of the website could be processed by Google for other purposes over which we have and can have no influence.

The Google Maps service is deactivated until the user gives his or her consent and can be revoked at any time via the cookie settings even after consent has been given. We would like to point out that a map display and use of the associated comfort functions is not possible without consent.

The Google privacy policy and additional terms of use for Google Maps can be found at https://www.google.com/intl/en_en/help/terms_maps/.
You can also change the loading of Google plugins in your privacy settings at https://myaccount.google.com/intro. Google uses cookies and other data to provide, manage and improve services. The use of Google services may also be analysed by Google partners. You can also find out more about Google privacy tools at https://tools.google.com/dlpage/gaoptout?hl=en. Help page with further information on Google Maps: https://support.google.com/maps.

Twitter

We have included a Twitter widget on our Group websites to display tweets of our Twitter account. Therefore, the server is simply connected to Twitter and the content is then processed by our server before it is displayed on our Group pages. This excludes a direct and unknowable communication between the user of the Group websites and Twitter in the first place.

(Personal) data is only transmitted when the user clicks on one of the links within the Twitter post. Regardless of the registration status, data will be transmitted to Twitter from this point on. For this, a connection to Twitter is established, log data is transmitted to Twitter and, if necessary, a cookie is set on the user's computer. According to its own information, Twitter begins to delete, remove the identification or the record of data after a maximum of 10 days; this should normally take place immediately, but can take up to a week. Further information can be found at https://twitter.com/privacy?lang=en#widget-jump.

Career blog's comment function

You can use the comment function to add your own comments. To use the comment function, a user must enter a name; users may choose to enter a pseudonym, if they wish. They must also enter their email address. Entry of an email address is required so that we can pass on any complaints relating to your comments on the blog and ask you to make a statement in this regard. It is not possible to use the comment function without entering this information. In publishing your comment, we save the email address you enter but do not publish it. We also save your IP address. Your name is only published, if you write a comment using your real name rather than a pseudonym. Comments are not reviewed prior to publication. We reserve the right to delete comments that third parties claim to be illegal.

Share buttons on the careers blog

We use secure data Shariff buttons on our web site to provide users with social media buttons. Where data from social networks such as the number of likes for the user is displayed, these requests are made from the web site server. The user therefore remains anonymous via this procedure until they become active when the button is clicked. Clicking transfers the necessary data to the relevant social media pages and assigns the action (share or like) to the IP address or logged-on user account on the platform. Further information about the Shariff project is available at https://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html.

Share-Buttons/Social Plug-Ins

On our career-related blog "Karriereblog", we use secure Shariff interfaces to provide social media plugins from Facebook, Twitter and Xing to our website’s users. Where data from social networks – such as the number of likes – is shown to the user, these queries are submitted to the website by our server. The user remains anonymous during this process until they become active by clicking on the respective button.

You can find more information on the Shariff Project at:

https://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html.

Only when you click on the marked field and thereby activate it, the plugin provider is informed that you have accessed the corresponding page of our web content and can then attribute the action (share or like) to your IP address or, if applicable, to a user account on the respective platform, if you are logged in at the time. By activating the button, personal data is therefore transmitted to the respective provider and stored here.

We cannot influence the collected data or data processing operations, nor are we aware of the full scope of data collection, the purposes of data processing or the retention periods of the data.

The plugin provider stores the data collected about you as a user profile and uses this profile for the purposes of advertising, market research, and/or to tailor their website according to your needs. An evaluation of this type is conducted in particular (including for users who are not logged in) to display tailored advertisements and to inform other social network users about your activities on our website. You have the right to object to the creation of this user profile; to exercise this right, you should contact the respective plugin provider directly. The purpose of integrating plugins is, to enable our users to share our website’s content and to make this content more interesting.

You can find more information about the purpose and scope of data collection and the processing of this data by the plugin provider in the providers’ data privacy policies listed below. These documents also provide further information regarding your rights in this regard and configuration options to protect your privacy.

Links

Our website contains links to other websites in some places. We take all reasonable care to check these links. The company is not responsible for the content of linked pages or for ensuring data privacy on these pages. You can find further information about the social media presences accessible from our site by clicking here.

SSL encryption

For security reasons and in order to safeguard the transmission of confidential data you send to us, this website uses SSL encryption. You can recognize an encrypted connection by your browser’s address bar, which changes from “http://” to “https://” and displays a lock symbol.

When SSL encryption is activated, the data you transmit to us cannot be read by third parties.


Deletion and storage periods of data

If we have stored personal-related data of you, we will only process this data for the time period required to serve the purpose it was stored for or for the time period required by law.

If the storage purpose ceases to exist or if the storage period required by law expires, the personal data will be routinely blocked or deleted in accordance with legal requirements.

Logfiles are deleted according to provider specifications:

  • The access logs of the Web servers capture, which page views took place at which time. They contain the following data: IP, directory protection user, date, time, pages viewed, protocols, status code, data volume, referer, user agent, host name viewed.
  • The IP addresses are stored anonymously. The last three digits are removed, i.e. 127.0.0.1 becomes 127.0.0.*. IPv6 addresses are also anonymized. The anonymous IP addresses are kept for 60 days. Information about the directory protection user used is anonymized after one day.  
  • Error logs, which log incorrect page views, are deleted after seven days. Those include, in addition to error messages, the IP address accessing the page and, depending on the error, the website accessed. 
  • Access via FTP is logged with anonymous information on user name and IP address and stored for 60 days. 
  • The mail logs for sending e-mails from the web environment are anonymized after one day and then kept for 60 days. During anonymization, all data concerning the sender/recipient etc. is removed. Only the data at the time of sending and the information on how the e-mail was processed (queue ID or not sent) are retained.
  • Mail logs for sending via our mail server are deleted after four weeks. The longer retention period is necessary to ensure the functionality of the mail services and to combat spam.
  • It is not possible to individually define the storage period.

A storage going beyond this is exceptionally possible. In this case, however, the IP addresses of the users are deleted or alienated so that an assignment of the calling client is no longer possible.

Your data from the input mask of the contact form will be deleted when the respective conversation with you has ended. The conversation is terminated when it can be seen from the circumstances that the matter in question has been conclusively clarified. The additional personal data collected during the sending process (e.g. IP address) will also be deleted according to the aforementioned provider specifications.

Deletion of data

If we have stored personal-related data of you, we will only process this data for the period of time required to serve the purpose for which it was stored or for the period of time required by law.

If the storage purpose ceases to exist or if the storage period required by law expires, the personal data will be routinely blocked or deleted in accordance with legal requirements.

Log files are deleted after seven days. In exceptional cases, however, log files may be stored for longer periods. In this case, the users’ IP addresses are deleted or distorted so that they can no longer be attributed to the client making the inquiry.

The data you entered in the contact form’s input interface will then be deleted when the respective conversation with you is over. The conversation is considered to be over when the circumstances indicate that the issue in question has been conclusively resolved. The personal data additionally collected during the submission procedure (e.g. IP address) is deleted after a period of seven days at most.

Categories of recipient

Within Salzgitter AG, access to your data is only afforded to people and departments that require access to perform their duties within Salzgitter AG, to pursue our legitimate interests or to fulfill contractual and legal obligations.

To enable us to offer you the best possible service and remain competitive, we also exchange data with other allied companies of Salzgitter AG where necessary to pursue our legitimate interests, provided that your interests or your basic rights or freedoms do not outweigh our interest. Whenever we exchange information with allied companies, we guarantee that data is transmitted in accordance with data privacy requirements and that your personal data is protected.

As a fundamental rule, if you provide your personal data to us, we will not pass this data on to third parties. Such data will only be disclosed

  • in order to fulfill legal obligations to authorized authorities,
  • in accordance with consent you provided and
  • to IT service providers, e.g. in relation to administration and hosting of our website.

Non-disclosure of data

Personal data will not be disclosed unless there is a specific legal requirement to do so.

Data transfer to third countries

Data is only transferred to countries outside of the EU or the EEA (so-called third countries) insofar as this is stated in the present data privacy statement, is necessary to perform contracts, or is legally required, or in the case you have given us your consent to do so.

Rights of data subjects

All data subjects have a right of access in accordance with Art. 15 GDPR. If we process your personal data, you have the right of rectification in accordance with Art. 16 GDPR, the right to erasure in accordance with Art. 17 GDPR, the right to restrict the processing in accordance with Art. 18 GDPR, the right to object pursuant to Art. 21 GDPR and the right of data portability pursuant to Art. 20 GDPR. Restrictions to the right of access and the right to erasure apply pursuant to Sections 34 and 35 of the German Federal Data Protection Act (BDSG). Furthermore, data subjects have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR in conjunction with Section 19 BDSG).

If you have given us consent to process your personal data, you can also revoke this consent at any time by the same method you first provided it. You can revoke your consent without completing a form, e.g. by emailing datenschutz.holding@salzgitter-ag.de or by sending a message to the contact address listed above. Revoking your consent does not affect the legality of the processing performed on the basis of your previously issued consent.

Right to object to data processing

Pursuant to Art. 21 para. 1 GDPR, you have the right to object at any time to the processing of your personal data performed on the basis of Art. 6 para. 1 lit. f) GDPR (data processing for the purposes of legitimate interests).

If you do raise an objection, we will no longer process your personal data for the purposes to which you have objected, unless

  • we can demonstrate overriding legitimate grounds that outweigh the interests, rights and freedoms of the data subject, or
  • the processing serves to assert, exercise or defend legal claims.

In the case that the objection only or also relates to data processing for the purpose of direct marketing, we will no longer process your personal data for this purpose.

You can raise an objection without completing a form, e.g. by emailing datenschutz.holding@salzgitter-ag.de or by sending a message to the contact address listed above.

Legal basis for processing

Personal data processing relating to the use of contact forms is performed on the basis of Art. 6 para. 1 lit. b) GDPR, provided that the purpose of making contact serves to fulfill a contract or perform pre-contractual measures.

If our company is subject to a legal obligation which necessitates the processing of personal data, this processing is based on Art. 6 para. 1 lit. c) GDPR.

If we obtain your consent for personal data processing operations, this consent serves as the legal basis for processing pursuant to Art. 6 para. 1 lit. a) GDPR.

Furthermore, processing operations can be performed on the basis of Art. 6 para. 1 lit. f) GDPR, whereby processing is necessary to pursue a legitimate interest held either by our company or a third party, provided that the data subject’s interests, basic rights, or basic freedoms do not override our interest.

We use server log files, cookies, web fonts, Mapbox, embedded YouTube videos and web analysis tools so that you can use all of our website’s functions to their full extent and in order to structure and optimize our website in accordance with its users’ requirements. If you contact us via our contact form or using the functions in our Career blog, we will use your data for the purpose of interacting with you and for corporate communications.

Obligation to provide personal data

As a fundamental rule, there is no obligation to provide personal data when visiting our website. Contractual regulations may provide otherwise. If the specified personal data is not provided, in some circumstances, it may not be possible to achieve the individual described purposes.

No automated decision-making

We do not use fully automated decision-making within the meaning of Art. 22 GDPR.

Amendments to the data privacy statement

As the internet continues to develop, it will be necessary to make periodic amendments to the data privacy statement. Reviewing the data privacy statement at regular intervals will give you the opportunity to stay apprised of amendments.

Additional data protection information

Supplementary data privacy statements for the management holding company’s business partners and interested parties are listed below. This information is available for you here.