Data protection

I. Overview of Data Protection

1. General information

Salzgitter AG appreciates your interest in our company and your visit to our website. The protection of your personal data is very important to us.

In this section, “Data protection at a glance,” we provide you with a simple overview of what happens to your personal data when you visit this website. For detailed information on data protection, please refer to the section II. Privacy Policy.

2. How do we collect your data?

Your data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g., Internet browser, operating system, or time of page view). This data is collected automatically as soon as you enter this website.

On the other hand, data is collected when you provide it to us. This may include, for example, data that you enter in a contact form.

3. What do we use your data for?

Some of the data is collected to ensure that the website is provided without errors. Other data may be used to analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other order inquiries.

4. What rights do you have regarding your data?

You have the right to receive information about the origin, recipient, and purpose of your stored personal data at any time and free of charge. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

5. What analytics and third-party tools do we use?

When you visit this website, your surfing behavior may be statistically evaluated. This is primarily done using so-called analysis programs. Detailed information about these analysis programs can be found in the following privacy policy.

II. Privacy Policy

1. General information and mandatory information

As the operator of these pages, we take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We would like to point out that data transmission over the Internet (e.g. when communicating by e-mail) may be subject to security vulnerabilities. It is not possible to completely protect data from access by third parties.

2. Information about the responsible body

The controller pursuant to Art. 4 (7) of the EU General Data Protection Regulation (GDPR) is

Salzgitter AG
Konzernkommunikation
Eisenhüttenstr. 99
38239 Salzgitter, Germany
Phone: +49 5341 21-01

You can contact our data protection officer via our postal address with the addition “Data Protection Officer” or at:
datenschutz.holding@salzgitter-ag.de

3. Hosting

We host the content of our website with the following provider:

Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4-6, 32339 Espelkamp (hereinafter Mittwald).

For details, please refer to Mittwald's privacy policy: https://www.mittwald.de/datenschutz.

The use of Mittwald is based on Art. 6 (1) lit. f GDPR. We have a legitimate interest in ensuring that our website is as reliable as possible. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

We have concluded a contract for order processing (AVV) with Mittwald for the use of hosting services. This is a contract required by data protection law, which ensures that Mittwald processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

4. Data collection on this website

a) Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • IP address used
  • Operating system used
  • Browser used
  • Time of access
  • Websites you visit on our site
  • Website from which you are visiting us (if transmitted)
  • Host name of the accessing computer

This data is not merged with other data sources. The collection of this data is carried out on the basis of Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and the optimization of its website – for this purpose, the server log files must be collected.

b) Contact form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not pass on this data without your consent.

This data is processed on the basis of Art. 6 (1) (b) GDPR, provided that your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. Data protection information for business partners and interested parties of the management holding company is available here.

In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) if this has been requested; consent can be revoked at any time.

The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions — in particular retention periods — remain unaffected.

c) Request by email or phone

If you contact us by email or telephone, your request, including all personal data (name, request), will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.

This data is processed on the basis of Art. 6 (1) (b) GDPR, provided that your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR), if this has been requested; consent can be revoked at any time.

Additional information can be found in the data protection information for business partners and interested parties.

d) Information on data processing for online applications

You can find detailed information in our Data Privacy Information for Applicants.

e) Cookies

Our websites use so-called “cookies.” Cookies are small data packets and do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or your web browser automatically deletes them. Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services). Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., displaying stock prices). Other cookies can be used to evaluate user behavior or for advertising purposes. Cookies that are necessary for carrying out the electronic communication process, for providing certain functions you have requested (e.g., the shopping cart function), or for optimizing the website (necessary cookies), are stored on the basis of Art. 6 (1) (f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6 (1) (a) GDPR and § 25 (1) TDDDG); consent may be revoked at any time. You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, the functionality of this website may be restricted. You can revoke your cookie consent for this website at any time and adjust your cookie settings: Cookie consent / Cookie settings

5. Storage period

Unless a more specific storage period is specified in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., retention periods under tax or commercial law); in the latter case, deletion will take place once these reasons no longer apply.

6. General information on the legal basis for data processing on this website

If you have consented to data processing, we process your personal data on the basis of Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR, if special categories of data are processed in accordance with Art. 9 (1) GDPR. In the event of express consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49 (1) (a) GDPR.

If you have consented to the storage of cookies or access to information on your end device (e.g., via device fingerprinting), data processing will also be carried out on the basis of Section 25 (1) TDDDG. Consent can be revoked at any time.

If your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 (1) (b) GDPR.

Furthermore, we process your data if this is necessary to fulfill a legal obligation on the basis of Art. 6 (1) (c) GDPR.

Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 (1) (f) GDPR. The relevant legal basis in each individual case is explained in the following paragraphs of this privacy policy.

7. Recipients of personal data

We only disclose personal data to external parties if this is necessary for the performance of a contract, if we are legally obliged to do so (e.g., disclosure of data to law enforcement authorities), if we have a legitimate interest in the disclosure pursuant to Art. 6 (1) (f) GDPR, or if another legal basis permits the disclosure of data.

When using processors, we only disclose our customers’ personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.

8. Your rights as a data subject under the GDPR

a) Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke any consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

b) Right to object to data collection in specific cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6 (1) (E) OR (F) OF THE GDPR, YOU HAVE THE RIGHT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES TO ASSERT, EXERCISE, OR DEFEND LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 (1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21 (2) GDPR).

c) Right to lodge a complaint with a supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged violation. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.

d) Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or in fulfillment of a contract, either to yourself or to a third party, in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be carried out where technically feasible.

e) Information, correction, and deletion
Within the framework of the applicable legal provisions, you have the right to obtain information free of charge at any time about your stored personal data, its origin and recipients, and the purpose of data processing, and, if applicable, a right to correct or delete this data. You can contact us at any time with any questions you may have on this topic or on the subject of personal data.

f) Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time to do so. The right to restriction of processing applies in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we will usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you require it to exercise, defend, or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.>
  • If you have lodged an objection pursuant to Art. 21 (1) GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data – apart from their storage – may only be processed with your consent or for the assertion, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.

9. SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

10. Consent to cookies / Cookie settings

Our website uses its own consent technology to obtain your consent for the storage of certain cookies on your device or for the use of certain technologies, and to document this in compliance with data protection requirements.

Consent technology stores a cookie in your browser in order to be able to assign the consents you have given or their revocation. The data collected in this way is stored until you request us to delete it, delete the consent manager provider cookie yourself, or the purpose for data storage no longer applies.

The consent tool is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6 (1) (c) GDPR.

Here you can find a personalized overview of which cookies you have consented to:

Your consent applies to the following domains: www.salzgitter-ag.com

Essential Keine Daten gefunden
Statistic Keine Daten gefunden
External media Keine Daten gefunden
Checksum Keine Daten gefunden
Consent date Keine Daten gefunden

Cookie declaration last updated on 23.07.2025

Essential

Essential (necessary) cookies enable basic functions and are required for the proper functioning and use of the website.

Name CookieConsent
Explanation Saves the visitors' settings, which services and cookies should be allowed.
Provider Salzgitter AG
Cookies
Name Lifetime
tx_cookieconsent 365 Tage
Privacy Policy https://www.salzgitter-ag.com/de/kontakt/datenschutz.html
Name Favorites function Career area
Explanation Saves favorite job offers and is used to display them in the top area of the page.
Provider Salzgitter AG
Cookies
Name Lifetime
tx_szagcareerfrontend_favorites 7 days
Privacy Policy https://www.salzgitter-ag.com/en/contact/data-protection/data-privacy-information-for-applicants.html
Name Equitystory
Explanation Some current financial data of Salzgitter AG (e.g., share price) and graphical representations thereof are loaded via the EQS Group platform and integrated into the page. PHPSESSID retains the user's status for all page requests, while TS# is used to ensure website security and fraud detection.
Provider EQS Group
Cookies
Name Lifetime
PHPSESSID Session
TS# Session
Domains equitystory.com
Privacy Policy https://www.eqs.com/about-eqs/data-protection/
Name Filter Karrierebereich
Explanation Saves the currently set filters to apply them again once you navigate back to a listing.
Provider Salzgitter AG
Cookies
Name Lifetime
tx_szagcareerfrontend_filters Session
Privacy Policy https://www.salzgitter-ag.com/de/kontakt/datenschutz.html

Statistic

This cookie is used to record the behavior of visitors to the website in an anonymous form. It is used to collect statistics about website usage, such as when the visitor last visited the website. The cookie does not contain any personal data and is used solely for website analysis.

Name Siteimprove
Explanation This cookie is used to record the behavior of visitors to the website. It is used to collect statistics about website usage, such as when the visitor last visited the website. The cookie does not contain any personal data and is used solely for website analysis.
Provider Siteimprove GmbH
Cookies
Name Lifetime
nmstat 1000 days
Domains siteimprove.com,ssl.siteimprove.com,siteimproveanalytics.com
Privacy Policy https://www.siteimprove.com/privacy/website-privacy-policy/

External media

Embedded third-party content, e.g. from map providers, video platforms and social media providers, is initially blocked by default and only displayed after the user's active consent.

Name YouTube
Explanation Used to unblock YouTube content.
Provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Cookies
Name Lifetime
YSC Session
VISITOR_INFO1_LIVE 6 months
PREF 8 months
CONSENT 2 years
SOCS 13 months
NID 6 months
IDE 13 months
Domains google.com, youtube.com, youtube-nocookie.com
Privacy Policy https://policies.google.com/privacy
Name Uberall
Explanation Uberall provides a location finder that can show you our global offices. Saves the last location information displayed for back navigation in the widget.
Provider uberall GmbH, Hussitenstraße 32 – 33, 13355 Berlin, Germany
Cookies
Name Lifetime
ub_trk 7 days
ub_u_id 7 days
uberallAccessCookie 7 days
Domains uberall.com, static-prod.uberall.com
Privacy Policy https://uberall.com/de/privacy-policy
Name Google Maps
Explanation Display of interactive maps showing the global locations of the Salzgitter Group.
Provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Cookies
Name Lifetime
NID 6 months
OGPC 1 month
1P_JAR 1 month
AEC 6 months
SOCS 13 months
CONSENT 2 years
SAPISID 2 years
Domains maps.googleapis.com, maps.gstatic.com
Privacy Policy https://policies.google.com/privacy
Name Mapbox
Explanation Mapbox provides maps and geo-functions for this website.
Provider Mapbox, Inc.
Cookies
Name Lifetime
mapbox Session
mapbox_session Session
mbx_user up to 13 months
Domains api.mapbox.com
Privacy Policy https://www.mapbox.com/legal/privacy/
Name Company Webcast
Explanation Provision of a webcast, access security, prevention of multiple submissions in surveys, quality adjustment of the video stream.
Provider Company Webcast B.V. (Teil von Euronext Corporate Services), Rivium Boulevard 176, 2909 LK Capelle aan den IJssel, Niederlande.
Cookies
Name Lifetime
viewToken-[eventId] 90 days
authToken-[eventId] 7 days
[pollId] 21 days
Domains salzgitterag.engagestream.companywebcast.com
Privacy Policy https://engagestream.companywebcast.com/cwc/privacy-policy-engagestream.pdf

11. Analytics tools

Siteimprove

Our website uses the web analytics tool Siteimprove, provided by Siteimprove GmbH, based in Berlin, with servers located in Germany and Denmark. For this purpose, information from cookies and server log files is transferred to Siteimprove’s servers in Denmark and processed there in order to evaluate the use of the website and to compile reports on website activity for us. Siteimprove will not disclose this information to third parties.

IP addresses are not irreversibly anonymized before collected data can be viewed via Siteimprove Analytics.

The installation of cookies can be prevented by adjusting the settings of the user’s browser software. However, in this case, not all functions of this website may be fully available. By using this website, you consent to the processing of data collected about you by Siteimprove in the manner and for the purposes described above. You can prevent data collection by Siteimprove Analytics by clicking on the following link. An opt-out cookie will then be set, which prevents the future collection of your data when visiting this website.

We have concluded a corresponding data processing agreement with Siteimprove.

Further information on data protection at Siteimprove can be found at https://www.siteimprove.com/de/privacy/.

12. Newsletter

Newsletter data

If you would like to subscribe to the newsletter offered on the website, we require your email address and information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.

The data entered in the newsletter registration form is processed exclusively on the basis of your consent (Art. 6 (1) (a) GDPR). You can revoke your consent to the storage of data, your email address, and its use for sending the newsletter at any time, for example via the “unsubscribe” link in the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.

The data you provide to us for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe from the newsletter or after the purpose ceases to exist. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest pursuant to Art. 6 (1) (f) GDPR.

Data stored by us for other purposes remains unaffected by this.

After you have unsubscribed from the newsletter distribution list, your email address may be stored in a blacklist with us or with the newsletter service provider, insofar as this is necessary to prevent future mailings. The data in the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with the legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 (1) (f) GDPR). Storage in the blacklist is not limited in time. You may object to the storage of your data if your interests outweigh our legitimate interests.

Newsletter distribution to existing customers

If you order goods or services from us and provide your email address, we may subsequently use this email address to send you newsletters, provided that we inform you of this in advance. In such a case, the newsletter will only be used to send direct advertising for our own similar goods or services. You can unsubscribe from this newsletter at any time. For this purpose, there is a corresponding link in every newsletter. The legal basis for sending the newsletter in this case is Art. 6 (1) (f) GDPR in conjunction with § 7 (3) UWG.

After you unsubscribe from the newsletter distribution list, your email address may be stored in a blacklist to prevent future mailings to you. The data from the blacklist is used only for this purpose and is not merged with other data. This serves both your interests and our interests in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 (1) (f) GDPR). There is no time limit for storage in the blacklist. You can object to the storage if your interests outweigh our legitimate interest.

13. Google Fonts (local hosting)

This site uses Google Fonts, which are provided by Google, to ensure consistent font display. The Google Fonts are installed locally. There is no connection to Google servers.

Further information about Google Fonts can be found here https://developers.google.com/fonts/faq and in Google's privacy policy: https://policies.google.com/privacy?hl=de.

14. Google Maps

This site uses the Google Maps map service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. This service allows us to integrate map material into our website.

To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer. If Google Maps is activated, Google may use Google Fonts for the purpose of uniform font display. When you access Google Maps, your browser loads the required web fonts into your browser cache to display text and fonts correctly.

Google Maps is used in the interest of an appealing presentation of our online offerings and to make it easy to find the locations we have indicated on the website. This constitutes a legitimate interest within the meaning of Art. 6 (1)(f) GDPR. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and
https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

For more information on how user data is handled, please refer to Google's privacy policy: https://policies.google.com/privacy?hl=en.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

15. Mapbox

We have integrated Mapbox on this website. The provider is Mapbox, Inc., 740 15th Street NW, 5th Floor, Washington, District of Columbia 20005, USA (hereinafter referred to as “Mapbox”). This service enables us to integrate map material on our website.

In order to use the functions of Mapbox, it is necessary to store your IP address, user agent, and other data. This information is usually transferred to a Microsoft server in the USA and stored there. The provider of this site has no influence on this data transfer.

This constitutes a legitimate interest on the part of the provider within the meaning of Art. 6 (1) (f) GDPR. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

For further details, please refer to the provider's privacy policy at https://www.mapbox.com/legal/privacy.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5640.

16. Links to the Salzgitter Group's social media channels

You will find links to our social media channels in various places on our website.

No third-party content (such as social media feeds, like or share buttons) is directly integrated into our website (with the exception of the career blog under the subdomain karriere-blog.salzgitter-ag.com, additional information see 18. and 19.). Furthermore, we only refer to corresponding platforms or channels (e.g. Facebook, Instagram, YouTube, etc.) via external links. When you visit our website, no personal data is automatically transferred to these third-party providers.

Please note that when you click on such an external link, the respective platform may set its own cookies and process data in accordance with its privacy policy. We have no influence on this data processing.

Further information can be found in the privacy policies of the respective providers.

Further information on the social media presences accessible via our website can be found at the following link: Privacy Policy for our Social Media Channels.

17. YouTube with enhanced privacy settings

This website links to videos on the YouTube website. The operator of the website is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of these websites that contains a link to YouTube, no connection to YouTube's servers is established. Only when you click on the link will YouTube's server be notified which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.

We use YouTube in extended data protection mode. According to YouTube, videos played in extended data protection mode are not used to personalize browsing on YouTube. Ads played in extended data protection mode are also not personalized. No cookies are set in extended data protection mode. Instead, however, so-called local storage elements are stored in the user's browser, which, similar to cookies, contain personal data and can be used for recognition purposes. Details on extended data protection mode can be found here: https://support.google.com/youtube/answer/171780.

After a YouTube video has been activated, further data processing operations may be triggered over which we have no influence.

YouTube is used in the interest of an appealing presentation of our online offerings. This constitutes a legitimate interest within the meaning of Art. 6 (1) (f) GDPR. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

For more information about data protection on YouTube, please refer to their privacy policy at: https://policies.google.com/privacy?hl=en.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

18. Further links

Our website contains links to other websites, for example those of business partners. These links have been checked by us with reasonable care. However, Salzgitter AG is not responsible for the content or the protection of data privacy on the websites we link to.

19. Comment function on the career blog

You may comment on posts using the comment function. The use of this comment function requires the entry of a name, although you may also choose a pseudonym. In addition, an email address must be provided. The provision of an email address is necessary so that we can forward to you any complaints about your comments on the blog and request a statement from you. Use of the comment function is not possible without this information. When your comment is published, the email address you provide will be stored but not published. Furthermore, your IP address will be stored. Your name will only be published if you have not written under a pseudonym. Comments are not reviewed prior to publication. We reserve the right to delete comments if they are objected to by third parties as unlawful.

20. Share buttons on the career blog

We use social media plugins (“social buttons”) on our website, e.g., from services such as X (formerly Twitter), Facebook, Xing, LinkedIn, or other social networks. To ensure the protection of your personal data when using our website, we use the privacy-friendly “Shariff” solution.

Shariff technology allows social media buttons to be integrated into a website in such a way that a direct connection between your browser and the social network servers is only established when you actively click on the respective button.

This means that no personal data will be transmitted to the social networks as long as you do not click on a button. Only by actively clicking do you consent to communication with the respective platform. In this case, the privacy policies of the respective provider apply.

The legal basis for processing your data after clicking is Art. 6 (1) (a) GDPR (consent). Our legitimate interest in the data protection-compliant presentation of social media content on our website is based on Art. 6 (1) (f) GDPR.

Further information on Shariff can be found at https://www.heise.de/hintergrund/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html.

21. Webcast

Company Webcast B.V., part of Euronext Corporate Services BV, is the streaming provider for our conference calls on the occasion of the publication of the 3M and 9M quarterly statements.

The Company Webcast B.V. privacy policy can be found here:
https://engagestream.companywebcast.com/cwc/privacy-policy-engagestream.pdf

Your data will be processed and forwarded in accordance with Art. 6 (1) (f) GDPR and our legitimate interest in providing you with the functionality on our website.

22. Change of Privacy Policy

As the Internet continues to evolve, it is necessary to update the privacy policy from time to time. Regularly reviewing the privacy policy gives you the opportunity to stay informed about any changes.

Salzgitter AG is delighted that you are interested in our company and have chosen to visit our website. We take the issue of protecting your personal data very seriously. This document explains how personal data is processed when using our website and outlines the rights you hold in this regard.

Controller, Data Protection Officer

The Controller pursuant to Art. 4 para. 7 EU General Data Protection Regulation (GDPR) is

Salzgitter AG
Konzernkommunikation
Eisenhüttenstr. 99
38239 Salzgitter, Germany
Phone: +49 5341 21-01

You can contact our Data Protection Officer either via post by addressing your letter to the “Data Protection Officer” or via email at:
datenschutz.holding@salzgitter-ag.de

Data processing

We specifically process the following personal data:

Server log files

Every time a user accesses our website and every time a file is downloaded, data regarding this process is temporarily stored in a log file. The stored data is analyzed anonymously and will only be used for internal statistical purposes so that we can continually improve the web content we offer. No person-related use takes place in this respect. In particular, a data set containing the following information is stored upon each user access:

  • the IP address used
  • the operating system used
  • the browser used
  • the time of access
  • the pages you visit on our site
  • the website you last visited (if transmitted)
  • the volume of data transmitted

Google Webfonts (local)

We have only integrated Google fonts locally on our website, i.e. no data is transferred to Google servers through their use.

Use of Google web fonts (local embedding)

On our website we use Google Fonts of the company Google Inc. For the European area the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible. We have embedded the Google fonts locally, i.e. on our web server - not on Google's servers. This means that there is no connection to Google servers and thus no data transfer or storage.

What are Google Fonts?

Google Fonts used to be called Google Web Fonts. This is an interactive directory of over 800 fonts that Google provides free of charge. With Google Fonts, you could use fonts without uploading them to your own server. However, in order to prevent any information transfer to Google servers in this regard, we have downloaded the fonts to our server. This way we act privacy compliant and do not send any data to Google Fonts. Unlike other web fonts, Google allows us unlimited access to all fonts. So we have unlimited access to a sea of fonts to get the most out of our website. You can find out more about Google Fonts and other issues at https://developers.google.com/fonts/faq?tid=111266255.

Libraries of ajax.googleapis.com for jQuery and jQueryUI

This site uses the javascript library jQuery from the content delivery network of Google. When your Browser downloads the jQuery library from Google, your data will be send from your browser to Google Inc. (“Google”). You agree that your Data will be stored in the USA.You can find out more about this at: https://developers.google.com/speed/libraries/#jquery and the privacy policy of google.de at https://policies.google.com/privacy?hl=en&gl=en.

Web analysis

Our website uses the web analysis tool Siteimprove, provided by Siteimprove GmbH, a company based in Berlin with servers in Germany and Denmark. This tool uses information of cookies and server log files: this information is transmitted to the Siteimprove server, where it is processed to evaluate visitors’ use of our website and to compile reports for us concerning website activities. Siteimprove does not pass this information on to third parties. IP addresses are irreversibly anonymized before the collected data is made accessible by Siteimprove Analytics. We have concluded a corresponding data processing contract with Siteimprove.

You can prevent Siteimprove from collecting your data at any time by adjusting your current selection under "Data protection settings". Doing so places an opt-out cookie that prevents your data from being collected when you visit our website in future. Please note that web analysis will only be prevented as long as the opt-out cookie is stored in your browser; if you delete the cookie, web analysis will not be prevented in future.

Opt-out - Disable Siteimprove Analytics: Adjust privacy settings

Web analysis

Our web site uses Matomo (formerly Piwik) - open-source software for the statistical evaluation of user visits. Cookies are used for this, which are text files stored on your PC. Usage information generated by the cookies is sent to our server and stored for user analysis purposes, helping us to optimize the web site. This procedure immediately renders your IP address anonymous, ensuring that you remain an anonymous user as far as we are concerned. The server on which the statistical data is stored belongs to a German provider and is also physically located in Germany.

You can prevent Matomo from collecting your data at any time by adjusting your current selection under "Data protection settings". Doing so places an opt-out cookie that prevents your data from being collected when you visit our website in future. Please note that web analysis will only be prevented as long as the opt-out cookie is stored in your browser; if you delete the cookie, web analysis will not be prevented in future.

Opt-out - Disable Matomo Web Analytics: Adjust privacy settings

Use of Indeed Conversion Tracking

We use the online advertising program "indeed Conversion Tracker" to evaluate the job advertisements published on our website. The indeed Conversion Tracker is an analysis service of indeed Ireland Operations Limited, (124 St. Stephen's Green, Dublin 2, Ireland "indeed"), which we use to measure how an application reached us. The method used to measure applications referred via indeed is a so-called tracking pixel, which is incorporated into the site programming by means of a 1x1 pixel transparent image. When visiting the website of indeed, a cookie is set in the browser of the respective visitor, which contains a so-called session ID. This session ID is unique and makes it possible to record which job ads the visitor has clicked on within the indeed site visit. If the visitor follows the application path via a job ad to such an extent that an application is completed, it can thus be reported back to the indeed customer account via the tracking pixel URL within the conversion tracker that an application with the respective session ID has taken place via a job ad placed by us on indeed. Accordingly, the data collection is done by indeed itself and indeed compares the collected data through the conversion tracker at the end of the application process with the cookie set on indeed. Subsequently, this information is transmitted to our employer account at indeed to identify the application. The session ID is valid for about one hour and is then deleted.

An opt-out cookie is set in this case, which prevents the future collection of your data when visiting this website. If you delete your cookies in the relevant browser, you must click this link again.

For further information and indeed's privacy policy, please visit: https://de.indeed.com/legal?hl=en&redirect=true

Opt-out - Disable Indeed Conversion Tracker: Customize privacy settings

Contact forms

If you wish to use the contact forms on our website to communicate with us, you will be required to enter your forename, surname and email address. We will not be able to process the issue you enter in the contact form without this information. Entering your postal address is optional; it enables us to process your issue and reply via post, if you wish. In addition, our system collects the IP address of the computer you use to submit the form as well as the date and time the form is submitted. The information you provide is collected to the required extent and is used exclusively for the purpose of processing your inquiry.

You can find information about online applications here.

Contact forms

If you wish to use the contact forms on our website to communicate with us, you will be required to enter your forename, surname and email address. We will not be able to process the issue you enter in the contact form without this information. Entering your postal address is optional; it enables us to process your issue and reply via post if you wish. In addition, our system collects the IP address of the computer you use to submit the form as well as the date and time the form is submitted. The information you provide is collected to the required extent and is used exclusively for the purpose of processing your inquiry.

You can find information about online applications here.

Google

Our website uses PlugIns from the company Google Inc. for depicting maps. These sites are operated by Google Inc., 1600 Amphitheatre ParkwayMountain View, California, 94043, USA. When visiting one of our sites that contains a Google PlugIn, a connection to the Google servers will be established. The Google server will receive information which sites you have visited. Further information about collection and use of user data can be found in the data protection declaration of Google available at: http://www.google.com/intl/de/privacy/privacy-policy.html

Social Plugins

On our website we integrated so called „Social Plugins“ of the following social networks: „Facebook“, „Instagram“, „YouTube“ „X (formerly known as Twitter)“, „Google Maps“, „LinkedIn“ and „XING“. Social plugins can be recognized by the corresponding logo of each network and/or additions like „Share on Facebook", „Share on LinkedIn", „Share on X" and „Share on XING".

Please note that by activating social plugins certain information may be transmitted to the provider of the respective social network, these include e.g. address of the website, which integrated the activated social plugin, exact date and time of your visit or of the activation of the social plugin; information regarding your current browser and software system; your current IP address.

If you are logged-in to a social network by the time you activate the social plugin, the provider is able to identify your user name or even your real name from the data mentioned above. In this case, the respective network provider can process the information even in countries outside of the European Union. This means that we have no influence over the processing of any of your data by the respective provider of the network. Please note, that the provider is able to create a pseudonymized and even individualized user profiles. At any time, you can deactivate the activated social plugins. But this does not affect the data, which already have been transmitted by the provider of the respective social network.

For any details regarding the purpose and extent of the data collection or its further processing and utilization by the networks, and regarding your relevant rights and your privacy setting please see the privacy notices of the provider of the respective social network:

• Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA - http://www.facebook.com/about/privacy/

• Instagram LLC, represented by Kevin Systrom and Mike Krieger, 1601 Willow Rd, Menlo Park CA 94025, USA - http://help.instagram.com/155833707900388

• X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103 USA - https://twitter.com/privacy

• Google Inc., 1600 Amphitheatre ParkwayMountain View, California, 94043, USA - http://www.google.com/privacy/privacy-policy.html

• LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Irland - https://www.linkedin.com/legal/privacy-policy

• XING SE, Dammtorstraße 30, 20354 Hamburg, Deutschland - https://privacy.xing.com/en

 

Newsletter

On our website, you have the possibility to subscribe to a free newsletter that provides you with information on our company on a regular basis. When you register for the newsletter, the data from the input mask are sent to us (name and E-Mail address). The following data are also collected during the registration: IP address of the computer on which you are working and the date and time of day of the registration.

To process the data, we obtain your consent and refer to this data protection statement as a part of the registration procedure. You will then receive an E-Mail from us with the request that you confirm your registration data (double-opt-in). This serves to authenticate you and prevent third parties from misusing your E-Mail address.

No data will be passed on to third parties in association with the data processing used to dispatch newsletters.  The data are used exclusively to dispatch the newsletter. You can cancel your subscription to the newsletter at any time. Each of the newsletters that we send you contains a link to cancel or end the subscription.

Newsletter

On our website, you have the possibility to subscribe to a free newsletter that provides you with information on our company on a regular basis. When you register for the newsletter, the data from the input mask are sent to us (name and e-mail address). The following data are also collected during the registration: IP address of the computer on which you are working and the date and time of day of the registration.

To process the data, we obtain your consent and refer to this data protection statement as a part of the registration procedure. You will then receive an e-mail from us with the request that you confirm your registration data (double-opt-in). This serves to authenticate you and prevent third parties from misusing your e-mail address.

In connection with the data processing to send newsletters, we are working with a German service provider that has certification in accordance with the GDPR (General Data Protection Regulation) and the BDSG (German Federal Data Protection Act). The data are sent directly to the service provider, who is forbidden to use the data for purposes other than to send the newsletter. The data are not permitted to be passed on or sold. The data are used exclusively to send the newsletter. You may elect to stop receiving the newsletter at any time. Each of the newsletters we send to you contains a link to unsubscribe or end the subscription.

YouTube

We have integrated YouTube videos on our website that are stored at www.youtube.com and can be viewed directly from our website.

They are all integrated in “privacy-enhanced mode”, which means that no data about you as a user is transmitted to YouTube, if you do not watch these videos. Data is only transmitted to the YouTube server when you play the videos. If you are logged into your YouTube account at the same time, this information is attributed to your YouTube user account. You can prevent this by logging out of your YouTube user account before visiting our website.

YouTube is operated by YouTube LLC, headquartered at 901 Cherry Avenue, San Bruno, CA 94066, USA. YouTube is represented by Google Inc., based at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. You can find more information about how YouTube (Google) handles user data at: www.google.de/intl/de/policies/privacy.

Mapbox

On some subpages, our website uses functions of the map service Mapbox, provided by Mapbox Inc, 740 15th Street NW, 5th Floor, Washington, D.C. 20005, USA. By using this service, information about the use of this website, including your IP address, may be transmitted to Mapbox in the USA.

When you access a page that contains Mapbox maps, your browser establishes a direct connection with Mapbox servers. The map content is directly transmitted by Mapbox to your browser, which integrates the content into the website. We therefore cannot influence the amount of data, which is collected by Mapbox in this manner.

If you do not want Mapbox to process your data via our website, you can deactivate JavaScript in your browser settings. However, if you choose to do so, you will not be able to view the maps on our site.

You can find further information about the purpose and scope of data processing by Mapbox, your rights in this regard, and the configuration options available to protect your privacy in the Mapbox privacy policy at: https://www.mapbox.com/legal/privacy.

You have the option of preventing cookies from Mapbox by deactivating third-party cookies in your browser settings or via the cookie settings on this website.

Google Maps

This website uses the map service Google Maps from Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). This service is used through our location marketing service provider uberall.com to provide the "Global Locations at a Glance" feature. In order for the Google map material we use to be integrated and displayed in your web browser, your web browser must connect to a Google server when you access the location map. This server can be located in the USA. For more information, please refer to the Google Maps Terms of Use at https://www.google.com/intl/en_ALL/help/terms_maps/. To further enhance the usefulness of the location map feature, you may be asked to approve your location. Of course, you will not be able to release this without problems.

Uberall Locator

On our homepage, we use the uberall GmbH locator to search for and display the global locations of the Salzgitter Group. Locator is operated by uberall GmbH, Hussitenstraße 32-33, 13355 Berlin, Germany.

The uberall data protection declaration can be viewed at https://uberall.com/en-us/privacy-policy. To display the Salzgitter Group locations on a geographical map, uberall uses the Google Maps API (interface) within the Locator, a mapping service provided by Google LLC. ("Google"). For information on the use of "Google Maps", please refer to the following item "Google Maps" in our data protection declaration.

Google Maps

On this website we use the offer of Google Maps. This allows us to show you interactive maps directly on the website and enables you to conveniently use the map function such as displaying global location or planning a route to the location.

Google Maps is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The legal basis for the processing results from Art 6 I lit a, f DSGVO due to your voluntary information for the search and, when used, for the creation of a map and our legitimate interests in the presentation of our location as well as an easy findability of the places we indicate on the website.

By using Google Maps, information about your use of this website (including your IP address) may be transmitted to and stored by Google on servers in the United States. Google may transfer the information obtained through Maps to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google. Nevertheless, it would be technically possible for Google to identify at least individual users on the basis of the data received, especially if the user is logged in to Google. It would be possible that personal data and personality profiles of users of the website could be processed by Google for other purposes over which we have and can have no influence.

The Google Maps service is deactivated until the user gives his or her consent and can be revoked at any time via the cookie settings even after consent has been given. We would like to point out that a map display and use of the associated comfort functions is not possible without consent.

The Google privacy policy and additional terms of use for Google Maps can be found at https://www.google.com/intl/en_en/help/terms_maps/.
You can also change the loading of Google plugins in your privacy settings at https://myaccount.google.com/intro. Google uses cookies and other data to provide, manage and improve services. The use of Google services may also be analysed by Google partners. You can also find out more about Google privacy tools at https://tools.google.com/dlpage/gaoptout?hl=en. Help page with further information on Google Maps: https://support.google.com/maps.

Twitter

We have included a Twitter widget on our Group websites to display tweets of our Twitter account. Therefore, the server is simply connected to Twitter and the content is then processed by our server before it is displayed on our Group pages. This excludes a direct and unknowable communication between the user of the Group websites and Twitter in the first place.

(Personal) data is only transmitted when the user clicks on one of the links within the Twitter post. Regardless of the registration status, data will be transmitted to Twitter from this point on. For this, a connection to Twitter is established, log data is transmitted to Twitter and, if necessary, a cookie is set on the user's computer. According to its own information, Twitter begins to delete, remove the identification or the record of data after a maximum of 10 days; this should normally take place immediately, but can take up to a week. Further information can be found at https://twitter.com/privacy?lang=en#widget-jump.

Career blog's comment function

You can use the comment function to add your own comments. To use the comment function, a user must enter a name; users may choose to enter a pseudonym, if they wish. They must also enter their email address. Entry of an email address is required so that we can pass on any complaints relating to your comments on the blog and ask you to make a statement in this regard. It is not possible to use the comment function without entering this information. In publishing your comment, we save the email address you enter but do not publish it. We also save your IP address. Your name is only published, if you write a comment using your real name rather than a pseudonym. Comments are not reviewed prior to publication. We reserve the right to delete comments that third parties claim to be illegal.

Share buttons on the careers blog

We use secure data Shariff buttons on our web site to provide users with social media buttons. Where data from social networks such as the number of likes for the user is displayed, these requests are made from the web site server. The user therefore remains anonymous via this procedure until they become active when the button is clicked. Clicking transfers the necessary data to the relevant social media pages and assigns the action (share or like) to the IP address or logged-on user account on the platform. Further information about the Shariff project is available at https://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html.

Links

Our website contains links to other websites in some places. We take all reasonable care to check these links. The company is not responsible for the content of linked pages or for ensuring data privacy on these pages. You can find further information about the social media presences accessible from our site by clicking here.

SSL encryption

For security reasons and in order to safeguard the transmission of confidential data you send to us, this website uses SSL encryption. You can recognize an encrypted connection by your browser’s address bar, which changes from “http://” to “https://” and displays a lock symbol.

When SSL encryption is activated, the data you transmit to us cannot be read by third parties.


Deletion and storage periods of data

If we have stored personal-related data of you, we will only process this data for the time period required to serve the purpose it was stored for or for the time period required by law.

If the storage purpose ceases to exist or if the storage period required by law expires, the personal data will be routinely blocked or deleted in accordance with legal requirements.

Logfiles are deleted according to provider specifications:

  • The access logs of the Web servers capture, which page views took place at which time. They contain the following data: IP, directory protection user, date, time, pages viewed, protocols, status code, data volume, referer, user agent, host name viewed.
  • The IP addresses are stored anonymously. The last three digits are removed, i.e. 127.0.0.1 becomes 127.0.0.*. IPv6 addresses are also anonymized. The anonymous IP addresses are kept for 60 days. Information about the directory protection user used is anonymized after one day.  
  • Error logs, which log incorrect page views, are deleted after seven days. Those include, in addition to error messages, the IP address accessing the page and, depending on the error, the website accessed. 
  • Access via FTP is logged with anonymous information on user name and IP address and stored for 60 days. 
  • The mail logs for sending e-mails from the web environment are anonymized after one day and then kept for 60 days. During anonymization, all data concerning the sender/recipient etc. is removed. Only the data at the time of sending and the information on how the e-mail was processed (queue ID or not sent) are retained.
  • Mail logs for sending via our mail server are deleted after four weeks. The longer retention period is necessary to ensure the functionality of the mail services and to combat spam.
  • It is not possible to individually define the storage period.

A storage going beyond this is exceptionally possible. In this case, however, the IP addresses of the users are deleted or alienated so that an assignment of the calling client is no longer possible.

Your data from the input mask of the contact form will be deleted when the respective conversation with you has ended. The conversation is terminated when it can be seen from the circumstances that the matter in question has been conclusively clarified. The additional personal data collected during the sending process (e.g. IP address) will also be deleted according to the aforementioned provider specifications.

Deletion of data

If we have stored personal-related data of you, we will only process this data for the period of time required to serve the purpose for which it was stored or for the period of time required by law.

If the storage purpose ceases to exist or if the storage period required by law expires, the personal data will be routinely blocked or deleted in accordance with legal requirements.

Log files are deleted after seven days. In exceptional cases, however, log files may be stored for longer periods. In this case, the users’ IP addresses are deleted or distorted so that they can no longer be attributed to the client making the inquiry.

The data you entered in the contact form’s input interface will then be deleted when the respective conversation with you is over. The conversation is considered to be over when the circumstances indicate that the issue in question has been conclusively resolved. The personal data additionally collected during the submission procedure (e.g. IP address) is deleted after a period of seven days at most.

Categories of recipient

Within Salzgitter AG, access to your data is only afforded to people and departments that require access to perform their duties within Salzgitter AG, to pursue our legitimate interests or to fulfill contractual and legal obligations.

To enable us to offer you the best possible service and remain competitive, we also exchange data with other allied companies of Salzgitter AG where necessary to pursue our legitimate interests, provided that your interests or your basic rights or freedoms do not outweigh our interest. Whenever we exchange information with allied companies, we guarantee that data is transmitted in accordance with data privacy requirements and that your personal data is protected.

As a fundamental rule, if you provide your personal data to us, we will not pass this data on to third parties. Such data will only be disclosed

  • in order to fulfill legal obligations to authorized authorities,
  • in accordance with consent you provided and
  • to IT service providers, e.g. in relation to administration and hosting of our website.

Non-disclosure of data

Personal data will not be disclosed unless there is a specific legal requirement to do so.

Data transfer to third countries

Data is only transferred to countries outside of the EU or the EEA (so-called third countries) insofar as this is stated in the present data privacy statement, is necessary to perform contracts, or is legally required, or in the case you have given us your consent to do so.

Rights of data subjects

All data subjects have a right of access in accordance with Art. 15 GDPR. If we process your personal data, you have the right of rectification in accordance with Art. 16 GDPR, the right to erasure in accordance with Art. 17 GDPR, the right to restrict the processing in accordance with Art. 18 GDPR, the right to object pursuant to Art. 21 GDPR and the right of data portability pursuant to Art. 20 GDPR. Restrictions to the right of access and the right to erasure apply pursuant to Sections 34 and 35 of the German Federal Data Protection Act (BDSG). Furthermore, data subjects have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR in conjunction with Section 19 BDSG).

If you have given us consent to process your personal data, you can also revoke this consent at any time by the same method you first provided it. You can revoke your consent without completing a form, e.g. by emailing datenschutz.holding@salzgitter-ag.de or by sending a message to the contact address listed above. Revoking your consent does not affect the legality of the processing performed on the basis of your previously issued consent.

Right to object to data processing

Pursuant to Art. 21 para. 1 GDPR, you have the right to object at any time to the processing of your personal data performed on the basis of Art. 6 para. 1 lit. f) GDPR (data processing for the purposes of legitimate interests).

If you do raise an objection, we will no longer process your personal data for the purposes to which you have objected, unless

  • we can demonstrate overriding legitimate grounds that outweigh the interests, rights and freedoms of the data subject, or
  • the processing serves to assert, exercise or defend legal claims.

In the case that the objection only or also relates to data processing for the purpose of direct marketing, we will no longer process your personal data for this purpose.

You can raise an objection without completing a form, e.g. by emailing datenschutz.holding@salzgitter-ag.de or by sending a message to the contact address listed above.

Legal basis for processing

Personal data processing relating to the use of contact forms is performed on the basis of Art. 6 para. 1 lit. b) GDPR, provided that the purpose of making contact serves to fulfill a contract or perform pre-contractual measures.

If our company is subject to a legal obligation which necessitates the processing of personal data, this processing is based on Art. 6 para. 1 lit. c) GDPR.

If we obtain your consent for personal data processing operations, this consent serves as the legal basis for processing pursuant to Art. 6 para. 1 lit. a) GDPR.

Furthermore, processing operations can be performed on the basis of Art. 6 para. 1 lit. f) GDPR, whereby processing is necessary to pursue a legitimate interest held either by our company or a third party, provided that the data subject’s interests, basic rights, or basic freedoms do not override our interest.

We use server log files, cookies, web fonts, Mapbox, embedded YouTube videos and web analysis tools so that you can use all of our website’s functions to their full extent and in order to structure and optimize our website in accordance with its users’ requirements. If you contact us via our contact form or using the functions in our Career blog, we will use your data for the purpose of interacting with you and for corporate communications.

Obligation to provide personal data

As a fundamental rule, there is no obligation to provide personal data when visiting our website. Contractual regulations may provide otherwise. If the specified personal data is not provided, in some circumstances, it may not be possible to achieve the individual described purposes.

No automated decision-making

We do not use fully automated decision-making within the meaning of Art. 22 GDPR.

Amendments to the data privacy statement

As the internet continues to develop, it will be necessary to make periodic amendments to the data privacy statement. Reviewing the data privacy statement at regular intervals will give you the opportunity to stay apprised of amendments.

Additional data protection information

Supplementary data privacy statements for the management holding company’s business partners and interested parties are listed below. This information is available for you here.