Data Protection Declaration
The companies of the Webasto Group respect your privacy and take the protection of personal data very seriously. We would like you to know when we store such data, which data we store and how we use it. We have taken technical and organizational measures to ensure that the relevant data protection regulations are observed. We process personal data exclusively in accordance with the provisions of the General Data Protection Regulation (“GDPR”) and the German Federal Data Protection Act [Bundesdatenschutzgesetz, “BDSG”].
Personal data is information relating to your person. This includes information such as your name, address, postal address and telephone number. Furthermore, when you visit our online presence (www.webasto.de, www.webasto.com and www.webasto-group.com) further usage data is logged such as
– the IP address,
– the browser type and operating system of your PC,
– the website from which you are visiting us, and
– the date, time, and the websites that you have visited.
Personal data is only collected by the companies of the Webasto Group if it is generated automatically as part of the usage process or if you provide us with such data voluntarily, for example when filling out a registration form or registering for personalized services. Your data entered in the form will be stored for the following purposes exclusively:
On this website, in particular, we collect personal data from you that is essential for the order process. If the personal data requested in the form is not provided, no order can be placed.
The processing of your personal data is based on your consent.
Purposes of processing and legal basis
For the fulfilment of contractual obligations (Article 6 para. 1 lit. b GDPR)
Your data will be processed in accordance with Article 6 para. 1 lit. b GDPR for the purpose of performing, executing and fulfilling orders and contracts within the scope of the implementation of our contracts with our customers and suppliers or for the purpose of implementing pre-contractual measures which are taken at your request. This includes, in particular, concrete inquiries that we receive at events such as trade fairs. Furthermore, the relevant legal provisions apply to those processing operations that are necessary for us to be able to make our online services available to you.
The purposes of data processing depend primarily on the specific product and/or service provided and may include, but are not limited to, demand analyses, consultations, purchase contracts, and contracts for work and labor as well as regulatory requirements. Also recorded is the transfer of data to our installation partners, service providers or suppliers. Further details on data processing purposes can be found in the relevant contract documents and terms and conditions.
Irrespective of established contractual relationships and your interest in our services, you also enter into a user relationship with us simply by visiting our online presence. The processing of usage data resulting from the visit to our online presence is also legitimized by Article 6 para. 1 lit. b GDPR.
Within the scope of the balancing of interests (Article 6 para. 1 lit. f GDPR)
If necessary, we process your data beyond the actual performance of the contract to protect our legitimate interests or those of third parties. Due to the multitude of processing contexts that are theoretically conceivable, the following points should only be understood as a selection of the most practice-relevant situations. We can provide more detailed information within the framework of specific claims for information. This includes in particular
- the consultation of and data exchange with credit agencies (e.g. SCHUFA) to determine creditworthiness and default risks in our transactions,
- the review and optimization of procedures for demand analyses for the purpose of direct customer approach,
- advertising or market and opinion research, unless you have objected to the use of your data,
- the subscription to the newsletter and the sending of the newsletters,
- the recording and storage of contact data when business cards are handed over in the event of someone being interested in our services, e.g. at trade fairs,
- the enforcement of legal claims and defense in legal disputes,
- ensuring the company’s IT security and operation,
- the analysis of anonymized user data for the purpose of expanding and improving our website,
- the prevention and investigation of criminal offences,
- measures for business management and further development of services and products,
- risk management in the Webasto Group.
Based on your consent (Article 6 para. 1 lit. a GDPR)
If you have granted your consent to the processing of personal data for specific purposes (e.g. advertising measures for non-customers or the use of photographs), the lawfulness of this processing is established by virtue of this consent.
A given consent can be revoked at any time. This also applies to the revocation of declarations of consent issued to us prior to the validity of the GDPR, i.e. before May 25, 2018. The withdrawal of a consent only takes effect for the future and does not affect the lawfulness of the data processed until this withdrawal.
Based on legal provisions (Article 6 para. 1 lit. c GDPR)
In addition, as a company, we are subject to various legal obligations, i.e. statutory requirements (e.g. German Money Laundering Act [Geldwäschegesetz, GwG], tax laws and regulatory requirements). The purposes of processing include, among other things, creditworthiness checks, identity and age checks, fraud and money laundering prevention, compliance with control and reporting obligations under tax law, and the assessment and management of risks within the company.
Transfer of personal data to installation partners, service providers & suppliers
Webasto deploys installation partners, service providers and suppliers (hereinafter jointly referred to as “service providers”) to provide and deliver the services and products offered in its online shop. All service providers engaged by Webasto have been commissioned and carefully checked and selected in accordance with the relevant data protection requirements.
In order to be able to carry out an on-site visit at your premises and, if necessary, the installation of the required hardware such as the Wallbox at a later date, we must provide our installation partner in your region with your contact details as well as with further information on the products you require. For this purpose, we must provide the necessary data (name, address, ordered products, telephone number for the appointment).
Your data will be collected exclusively for the execution of the order and, if necessary, for further support services under the current contract. A processing for further purposes is only carried out to the extent permitted by law. In particular, we do not transmit data to our cooperation partners to enable them to carry out any advertising measures.
Within the scope of the installation, the service provider will collect further data from you that are necessary for the installation on site and the operation. In this context, technical aspects such as details regarding the existing power supply and possibilities for connecting to the Internet are recorded. This additional data is collected and processed by the service provider and also forwarded to Webasto for the execution of the contract. Upon request, we will be happy to inform you about the service provider who will carry out the installation for us in your region. Please contact our customer service under the hotline number or by e-mail.
For the provision of services within the framework of Webasto Connectivity, Webasto also cooperates with the external service provider Allego B.V., Industriepark Kleefse Waard, Westervoortsedijk 73, 6827 AV Arnhem, Netherlands („Allego“). For this purpose, Webasto has concluded a corresponding service contract with the service provider, including an agreement on order processing in accordance with Article 28 GDPR.
On behalf of Webasto and in compliance with the relevant data protection regulations, Allego collects and processes your personal data, which are necessary for the use of Connectivity and which you have made available to us. The data is managed by Allego in the European Microsoft Azure Cloud. The Connectivity functions are based on the transmission of data from Webasto Live to Allego’s backend. The Connectivity functions allow the user to view information about the started and finished loading processes that were performed with Webasto Live.
Allego provides the following services for Webasto:
- Provision of the Webasto Branded Mobile App (“App”) and the Webasto Portal (web portal);
- Assistance with problems in backend management (“service”).
Webasto will of course be happy to assist you with a justified request for information or data deletion.
In order to deliver the goods you have ordered, we pass on your data to the logistics company commissioned by us. If you order any goods or arrange for a viewing appointment at your premises, your payment information is processed exclusively by the payment service provider you have chosen and not by Webasto. Webasto has no influence on the handling of your data by the payment service provider. Webasto bills installation services directly with the payment service provider.
The data will not be transferred to other third parties, unless you have expressly consented to this.
Duration of data storage
We process and store your personal data as long as this is necessary for the fulfillment of our contractual and legal obligations.
If the data are no longer required for the fulfillment of our contractual or legal obligations, they are deleted at regular intervals, unless their – limited – further processing is necessary for the following purposes:
- compliance with obligations to preserve business records under commercial and tax law, acc. to German Commercial Code [Handelsgesetzbuch, HGB], the Fiscal Code of Germany [Abgabenordnung, AO], or the German Money Laundering Act [Geldwäschegesetz, GwG]. The periods for storage and documentation specified there are generally two to ten years.
- Preservation of evidence within the framework of the statutory statute of limitations. According to Sections 195 et seq. of the German Civil Code [Bürgerliches Gesetzbuch, BGB], these limitation periods can be up to 30 years, whereby the regular limitation period is 3 years.
You have the following statutory rights regarding the processing of your personal data:
– the right of access to your personal data stored,
– the right to rectification,
– the right to erasure,
– the right to object,
– the right to restriction of processing,
– the right to data portability.
To exercise your rights, please use the contact information indicated below. You can withdraw your consent to the processing of your personal data at any time.
In addition, you have the right to appeal to the competent data protection supervisory authority in Bavaria (Article 77 GDPR in conjunction with Section 19 BDSG).
Should you no longer agree to the storage of your personal data or in case this data has become inaccurate or incomplete, we will, upon receipt of corresponding instructions, arrange for the deletion, amendment, or blocking of your data within the limits of the relevant statutory provisions. Upon request, you will receive information regarding all of your personal data that we have stored on you free of charge. The restrictions according to Sections 34 and 35 BDSG apply to the right of access and the right of erasure. If you have any questions regarding the collection, processing, or use of your personal data, for information, rectification, blocking, or erasure of data as well as for the use of further rights, please contact our customer center at email@example.com or the respective company of the Webasto Group in writing.
Use of “cookies”
Cookies are used on our websites. Cookies are small text files that are placed on your computer when you visit our websites. We set cookies for the purposes of guaranteeing the use of our online services, for individual website optimization and to guarantee IT security. For further information on our cookies, please refer to the following link: https://www.webasto-group.com/de/cookies/
Cookies that are absolutely necessary to use our online services or to guarantee IT security do not require your consent. The use of these cookies and related processing activities are permitted by Article 6 para. 1 lit. f) GDPR.
Cookies for all other purposes, such as for individual website optimization, for marketing or for carrying out statistical evaluations of your activities on our website, however, require your consent.
Links to other websites
Our online presence includes links to other websites. We do not have any influence on whether the operators of these websites comply with the relevant data protection regulations. You should therefore examine the respectively offered data protection statements separately. Neither do we have any influence whatsoever on the lawfulness of the contents of these websites. Therefore, we reject any responsibility for the contents of other websites.
Usage analysis of our website
We utilize a solution from AT Internet for analyzing the usage of our website. The aim is to design our website in such a way as to ensure that it is optimally tailored to your needs. We want to improve both the user-friendliness and the quality of our web presence and present you with products and information that are most relevant to you in a prompt and customer-friendly manner.
In order to achieve the above-stated goal, it is necessary to statistically record and analyze the user behavior on our website. For this purpose, we analyze the collected data for the following purposes:
- to make performance and profitability comparisons for our website,
- to count the number of visitors,
- to track user awareness of, for instance, online advertising, partner and affiliate programs, rich media content or special campaigns that appear on the website,
- to rate the areas of the website that are particularly attractive to you,
- to evaluate the origin of online users in order to localize our services.
We differentiate between raw data (1) and processed data (2):
(1) The following data is collected:
– either a cookie (which is a small text file stored on your computer by a website) containing several items of information:
— the name of the server that placed the cookie,
— an anonymous identifier in the form of a unique number,
— an expiry date;
– or a mobile identifier (which is a unique number that allows the device to be unmistakably identified)
– and the IP address used for geolocation. The IP address is anonymized by truncating the last three digits;
– all navigation data that is collected in relation to these identifiers.
(2) Once the raw data has been processed, we speak of processed data, which provides the following information:
– a unique visitor ID,
– all digital analytics data associated with the identifier that are processed by the processor.
The following storage periods are applicable:
– The raw data is deleted six months after collection.
– The processed data is stored for the duration of the agreement between us and our provider plus six months.
Transmission of personal data
We and AT Internet, as our processor, have access to the digital analytics data.
You can object to your data being processed by AT Internet via the following link: http://www.xiti.com/de/optout.aspx
Management of online advertising measures with Netzeffekt GmbH
For the optimization and billing of our advertising measures and to enable the re-addressing of visitors to our websites, Netzeffekt GmbH, Theresienhöhe 28, 80339 Munich, Germany, also collects, stores, and processes, on our account, anonymized, non-personal data about your visit. For this purpose, cookies are used occasionally. However, Netzeffekt cannot and will not associate these visitor data with your name or any other personal information you have provided us with.
You can object to the data processing by Netzeffekt GmbH via the following link: http://datenschutz.netrk.net/optout
Use of social plugins from Facebook, Google+, Twitter and XING
On our website you will find bars linking to the following social networks /services:
The external social network Facebook of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA. The plugins can be identified by one of the Facebook logos (white “f” on a blue tile or a “thumbs up” symbol) or are marked with the “Facebook Social Plugin” label. The list and the appearance of the Facebook Social Plugins can be viewed at http://developers.facebook.com/plugins.
The external social network “Google+” of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. On our websites, the plugins are marked by the Google+ logo or the “+ 1” label.
The external Twitter service of Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA. This service can be identified by terms such as “Twitter” or “follow”, combined with a stylized blue bird. The buttons can be viewed at https://twitter.com/about/resources/buttons. Through the use of the buttons it is possible to share a contribution or page of our website on Twitter or to follow us on Twitter.
The XING network of XING AG, Gänsemarkt 43, 20354 Hamburg, Germany. The plugins are identified by the XING Share button.
The buttons and/or plugins used are deactivated by default and need to be expressly activated by you. The functions assigned to the links to the respective networks/services (Facebook, Google+, Twitter, XING), in particular the transmission of information and user data, are not automatically activated when you visit our website, but only when you click on the corresponding links. If these links are followed by clicking on the respective button, the plugins of Facebook, Google+, Twitter and/or XING are activated and your browser establishes a direct connection to the servers of the respective network/service, i.e. Facebook, Google+, Twitter and/or XING. If you follow the links during your visit to our website while being logged into the respective network/service (Facebook, Google+, Twitter, XING) via your personal user account, the information that you have visited our website will be forwarded to the respective operator (Facebook, Google+, Twitter, XING). In this event, the respective operator (Facebook, Google+, Twitter, XING) can assign the visit to the website to your account. This information is transmitted to the operator (Facebook, Google+, Twitter, XING) and may be stored there. In order to prevent this, you must log out of your account before clicking on the link. You can find additional information regarding the information stored under the following links:
Even if you are not a member of one of the above-mentioned social networks/services, there is a possibility that they can identify your IP address via the social plugin and save it as the case may be. For details regarding the purpose and scope of the processing, collection, and use of data by Facebook, Google+, Twitter, and XING and your rights and setting options in this regard, please refer to the respective data protection information:
- Facebook: http://www.facebook.com/about/privacy/
- Google+: http://www.google.com/intl/de/+/policy/+1button.html
- Twitter: https://twitter.com/privacy
- XING: http://www.xing.com/privacy
In addition, you have the possibility of blocking social plugins through the use of add-ons for your browser, such as the Facebook plugin with the “Facebook blocker”, which can be downloaded here: http://webgraph.com/resources/facebookblocker/.
In some cases you can also change your data protection settings, e.g. at http://twitter.com/account/settings.
With the help of the provider YouTube LLC , 901 Cherry Avenue, San Bruno, CA 94066, USA (“YouTube”), we include videos on our websites. YouTube is a subsidiary of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). When you visit a page with embedded videos, your IP address is sent to YouTube and cookies are placed on your computer. We embed our YouTube videos in the advanced privacy mode. In this case, YouTube will inform Google’s “Double Click” service, but none of your personal data will be analyzed. YouTube only stores usage data about visitors if these visitors actually watch the video on our website. Therefore, please note that your IP address is transmitted to YouTube in connection with the corresponding usage data (videos viewed) when you click on a video. If you are logged in to YouTube, this information is also assigned to your user account. You can prevent this by logging out of YouTube before viewing the video.
Questions and comments
If you have any questions, suggestions, or comments regarding the subject of data protection, please contact our customer service by e-mail at firstname.lastname@example.org.
Controller within the meaning of data protection law
Webasto Thermo & Comfort SE
Friedrichshafener Str. 9
P.O. Box 1410, 82199 Gilching
Phone: +49 (89) 8 57 94-0
Fax: +49 (89) 8 57 94-4 48
You can contact our corporate data protection officer at:
We send newsletters, e-mails and other electronic notifications containing advertising information (hereinafter jointly referred to as “newsletters“) only with the consent of the recipient or as permitted under law. If the contents of the newsletter are specifically described within the scope of registration, they are decisive for the consent of the user.
If you subscribe to our newsletter, we will use the data required for this purpose or separately provided by you in order to send you our e-mail newsletter on a regular basis. Unsubscribing from the newsletter is possible at any time and can be done either by sending a corresponding request to the contact person indicated below or via a link provided for this purpose directly in the newsletter.
In order to subscribe to the newsletter, it is sufficient to enter your e-mail address. The registration to our newsletter is carried out in a so-called double-opt-in procedure. This means that, after subscribing, you will receive an e-mail in which you will be asked to confirm your subscription. This confirmation is necessary in order to ensure that nobody can subscribe using the e-mail address of someone else.
Subscriptions to the newsletter are recorded in order to ensure that we can verify the registration process according to the statutory requirements. This includes the storage of information on the time of the registration and confirmation as well as the IP address.
You can cancel the receipt of our newsletter at any time, i.e. withdraw your consent. At the same time, your consent to its dispatch will expire. You can find a link for the cancellation of the newsletter at the end of each newsletter.