PRIVACY POLICY
SMF GmbH
Privacy policy for business partners, suppliers and service providers
Privacy Policy
We are pleased that you are visiting our website. The protection and security of your personal information when using our website is very important to us. Therefore, we would like to inform you at this point which of your personal data we collect when you visit our website and for what purposes it is used.
This Privacy Policy applies to the website of SMF GmbH, which can be accessed via the domain www.smf.de and the various subdomains (“our website”).
Who is responsible and how can I reach you?
Responsible
for the processing of personal data within the meaning of the EU General Data Protection Regulation (DSGVO)
SMF GmbH
Paul-Henri-Spaak-Strasse 5
44263 Dortmund
+49 231 9644-0
info@smf.de
Data Protection Officer
AGAD Service GmbH
Waldring 43-47
44789 Bochum
datenschutz@agad.de
What is it about?
This privacy policy meets the legal requirements for transparency in the processing of personal data. This is any information relating to an identified or identifiable natural person. This includes, for example, information such as your name, age, address, telephone number, date of birth, email address, IP address or user behavior when visiting a website. Information for which we cannot (or can only with a disproportionate effort) establish a reference to your person, e.g. by anonymization, is not personal data. The processing of personal data (e.g. collection, retrieval, use, storage or transmission) always requires a legal basis and a defined purpose.
Stored personal data will be deleted as soon as the purpose of the processing has been achieved and there are no legitimate grounds for further storage of the data. We will inform you about the specific storage periods or criteria for storage in the individual processing operations. Irrespective of this, we store your personal in individual cases for the assertion, exercise or defense of legal claims and if there are legal retention obligations.
Who receives my data?
We only share your personal data that we process on our website with third parties if this is necessary for the fulfillment of the purposes and is covered by the legal basis in the individual case (e.g. consent or safeguarding legitimate interests). In addition, we disclose personal data to third parties in individual cases if this serves the assertion, exercise or defense of legal claims. Possible recipients may then be, for example, law enforcement agencies, lawyers, auditors, courts, etc.
Insofar as we use service providers for the operation of our website who process personal data on our behalf within the scope of commissioned processing pursuant to Art. 28 DSGVO, they may be recipients of your personal data. For more information on the use of processors as well as web services, please refer to the overview of the individual processing operations.
Do you use cookies?
Cookies are small text files that are sent by us to the browser of your terminal device during your visit to our websites and stored there. As an alternative to the use of cookies, information can also be stored in the local storage of your browser. Some functions of our website cannot be offered without the use of cookies or local storage (technically necessary cookies). Other cookies, on the other hand, enable us to perform various analyses, so that we are able, for example, to recognize the browser you are using when you visit our website again and to transmit various information to us (non-essential cookies). With the help of cookies, we can, among other things, make our website more user-friendly and effective for you, for example by tracking your use of our website and determining your preferred settings (e.g. country and language settings). If third parties process information via cookies, they collect the information directly from your browser. Cookies do not cause any damage to your end device. They cannot execute programs or contain viruses.
We provide information about the respective services for which we use cookies in the individual processing procedures. You can find detailed information about the cookies used in the cookie settings or in the Consent Manager of this website.
What rights do I have?
Under the conditions of the statutory provisions of the General Data Protection Regulation (DSGVO), you have the following rights as a data subject:
Information according to Art. 15 DSGVO about the data stored about your person in the form of meaningful info.
How is my data processed in detail?
Below, we inform you about the individual processing activities, the scope and purpose of data processing, the legal basis, the obligation to provide your data, and the respective storage duration. Automated decision-making in individual cases, including profiling, does not take place.
Provision of the Website
Type and Scope of Processing
When accessing and using our website, we collect personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the retrieved file
- Website from which access is made (referrer URL)
- Browser used and, if applicable, your computer’s operating system and the name of your access provider
[Our website is not hosted by ourselves but by a service provider who processes the above-mentioned data on our behalf in accordance with Art. 28 GDPR.]
Purpose and Legal Basis
Processing is carried out to safeguard our overriding legitimate interest in displaying our website and ensuring its security and stability, based on Art. 6(1)(f) GDPR. The collection of data and storage in log files is mandatory for the operation of the website. There is no right to object to this processing due to the exception under Art. 21(1) GDPR.
If further storage of log files is required by law, processing is based on Art. 6(1)(c) GDPR. There is no legal or contractual obligation to provide the data; however, accessing our website without providing the data is technically impossible.
Storage Period
Unless a more specific storage period is stated in this Privacy Policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or withdraw consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, deletion will take place after these reasons no longer apply.
Contact Form
Nature and Scope of Processing
On our website, we offer you the opportunity to contact us via a contact form. The information collected in the mandatory fields is required in order to process your enquiry. In addition, you may voluntarily provide further information which you consider necessary for handling your enquiry.
When you use the contact form, your personal data will not be disclosed to third parties.
Purpose and Legal Basis
We process your data submitted via the contact form for the purpose of communicating with you and handling your enquiry, based on your consent pursuant to Article 6(1)(a) GDPR.
Where your enquiry relates to an existing contractual relationship with us, processing is carried out for the performance of the contract pursuant to Article 6(1)(b) GDPR.
There is no statutory or contractual obligation to provide your data. However, we cannot process your enquiry without the information required in the mandatory fields. If you do not wish to provide this information, please contact us by other means.
Storage Period
Where you use the contact form on the basis of your consent, we store the data collected for each enquiry for a period of three years, starting from the date your enquiry has been completed or until you withdraw your consent.
If you use the contact form within the context of a contractual relationship, we store the data collected for each enquiry for a period of three years from the end of the contractual relationship.
Newsletter
Nature and Scope of Processing
If you subscribe to our newsletter via our website, we collect your email address and store it together with the date of registration and your IP address.
You will then receive an email in which you must confirm your subscription (double opt-in). If you do not confirm your subscription within 24 hours, your registration will automatically expire and the data will not be processed for the purpose of sending the newsletter.
Purpose and Legal Basis
We process your data for the purpose of sending the newsletter based on your consent pursuant to Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future by unsubscribing from the newsletter in accordance with Article 7(3) GDPR.
There is no statutory or contractual obligation to provide your data. However, it is not possible to send the newsletter without the provision of your data.
Storage Period
Following registration for the newsletter, we store your data for a maximum of 24 hours until you confirm your subscription.
Once your subscription has been successfully confirmed, we store your data until you withdraw your consent (unsubscribe from the newsletter).
Social Media Presences
We maintain fan pages, accounts or channels on the networks listed below in order to provide information and offers within social networks and to offer additional ways for you to contact us and find out about our services. Below, we explain which data we and/or the respective social network process in connection with your access to and use of our fan pages/accounts.
Data We Process
If you contact us via messenger or direct message on the respective social network, we generally process your user name and may store additional information you provide, insofar as this is necessary to handle and respond to your request.
The legal basis is Article 6(1)(f) GDPR (processing is necessary for the purposes of the controller’s legitimate interests).
Usage Data We Receive from Social Networks
We receive statistics about our accounts that are provided automatically via insight functionalities. These statistics may include, among other things, the total number of page views, likes, information on page activity and post interactions, reach, video views, and information on the proportion of male/female followers.
These statistics contain only aggregated data and do not relate to identifiable individuals. Users are not identifiable to us on this basis.
Data Processed by Social Networks
You do not need to be a member of the respective social network in order to view the content of our fan pages/accounts and therefore no user account is required for this purpose.
Please note, however, that social networks may also collect and store data from website visitors without a user account when the relevant social network is accessed (e.g. technical data required to display the website) and may use cookies and similar technologies over which we have no influence. Further details can be found in the privacy policies of the respective social networks (see the links below).
If you wish to interact with the content on our fan pages/accounts (e.g. comment on, share or like posts) and/or contact us via messenger functions, prior registration with the respective social network and the provision of personal data to that provider are required.
We have no influence over the data processing carried out by the social networks when you use them. To the best of our knowledge, your data is processed in particular in connection with the provision of the respective social network’s services, as well as for analysing user behaviour (using cookies, pixels/web beacons and similar technologies). On this basis, interest-based advertising may be displayed both within and outside the respective social network.
It cannot be ruled out that your data may also be stored by the social networks outside the EU/EEA and shared with third parties.
Further information on the scope and purposes of processing, storage periods/deletion, and policies on the use of cookies and similar technologies in connection with registration and use of the social networks can be found in the privacy policies/cookie policies of the respective providers. These also include information about your rights and options to object.
Facebook Page
When you visit our Facebook page, Facebook (Meta) collects, among other things, your IP address and further information stored on your device in the form of cookies. This information is used to provide us, as the operator of the Facebook page, with statistical information about the use of the Facebook page (Facebook Insights). Further information is available from Facebook here:
https://facebook.com/help/pages/insights
The statistical information provided does not allow us to draw conclusions about individual users. We use it only to better understand user interests, continuously improve our online presence and ensure its quality.
We collect data via our fan page only to enable communication and interaction with us. This usually includes your name, message content, comment content and the profile information you have made publicly available.
The processing of your personal data for the purposes described above is based on our legitimate economic and communication interests in providing an information and communication channel pursuant to Article 6(1)(f) GDPR. If you have given the relevant social network provider your consent to data processing, the legal basis also includes Article 6(1)(a) and Article 7 GDPR.
As the actual data processing is carried out by the social network provider, our access to your data is limited. Only the provider has full access to your data. For this reason, the provider is also the primary contact for exercising your rights (access request, erasure request, objection, etc.). Exercising these rights is therefore most effective when done directly with the provider.
We and Facebook are joint controllers for the processing of personal data on the fan page. Data subject rights may be asserted both with Meta Platforms Ireland Ltd. and with us.
Primary responsibility for the processing of Insights data lies with Facebook under the GDPR, and Facebook fulfils all obligations under the GDPR with regard to Insights data processing. Meta Platforms Ireland Ltd. makes the essential content of the Page Insights Controller Addendum available to data subjects.
We do not make decisions regarding the processing of Insights data or the storage duration of cookies on users’ devices.
Further information (Page Controller Addendum):
https://www.facebook.com/legal/terms/page_controller_addendum
Further information on data protection and cookies:
https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0
https://www.facebook.com/policies/cookies
Instagram Page
When you visit our Instagram page, Instagram collects, among other things, your IP address and further information stored on your device in the form of cookies. This information is used to provide us, as the operator of the Instagram page, with statistical information about the use of the Instagram page (Insights). Further information is available here:
https://facebook.com/help/pages/insights
The statistical information provided does not allow us to draw conclusions about individual users. We use it only to better understand user interests, continuously improve our online presence and ensure its quality.
We collect data via our fan page only to enable communication and interaction with us. This usually includes your name, message content, comment content and the profile information you have made publicly available.
Processing is based on our legitimate interests pursuant to Article 6(1)(f) GDPR. Where you have given the provider your consent, the legal basis also includes Article 6(1)(a) and Article 7 GDPR.
Due to the fact that the actual processing is carried out by the provider, our access to your data is limited. The most effective way to exercise your rights is therefore directly with the provider.
We and Instagram are joint controllers for the processing of personal data on the fan page. Data subject rights may be asserted both with Facebook Ireland and with us.
Primary responsibility for Insights data lies with Instagram under the GDPR. Instagram fulfils all GDPR obligations regarding Insights data processing, and Facebook Ireland makes the essential content of the Page Insights Controller Addendum available to data subjects.
We do not make decisions regarding the processing of Insights data or any other information required under Article 13 GDPR, including the legal basis, the identity of the controller, or the storage duration of cookies on users’ devices.
Further information (Page Controller Addendum):
https://www.facebook.com/legal/terms/page_controller_addendum
Twitter Page
Twitter is a social network operated by Twitter Inc., headquartered in San Francisco, California, USA. It enables the creation of private profiles (personal accounts) as well as professional profiles (professional accounts) for individuals and companies. Twitter allows users, among other things, to publish short messages (“tweets”) and interact with other users’ content, e.g. by reposting (“retweets”), liking posts, sharing posts and replying, including where other users mention or tag you.
When you use or visit the network (and therefore also when you visit our Twitter account), Twitter automatically collects data from users and visitors, such as user name and IP address. This is done using tracking technologies, in particular cookies. Twitter uses the data collected to provide users with information, offers and recommendations and to provide us, as the operator of our Twitter page, with statistical information about the use of the Twitter page. Further information can be found in Twitter’s privacy policy:
https://twitter.com/privacy#twitter-privacy-1
The statistical information provided does not allow us to identify individual users. We use it only to better address user interests, improve our online presence and ensure its quality.
We collect data via our fan page only to enable communication and interaction with us. This usually includes your name, message content, comment content and the profile information you have made publicly available.
Processing is based on our legitimate interests pursuant to Article 6(1)(f) GDPR. Where you have given the provider your consent, the legal basis also includes Article 6(1)(a) and Article 7 GDPR.
As the actual processing is carried out by the provider, our access to your data is limited. Exercising your rights is therefore most effective when done directly with the provider.
We and Twitter are joint controllers for the processing of personal data on the fan page. Data subject rights may be asserted both with Twitter Inc. and with us.
Primary responsibility for the processing of Insights data lies with Twitter under the GDPR. Twitter fulfils all obligations under the GDPR with regard to Insights data processing. Twitter Inc. makes the essential content of the Page Insights Controller Addendum available to data subjects.
We do not make decisions regarding the processing of Insights data or the storage duration of cookies on users’ devices.
Further information on Twitter’s privacy and cookie policies:
Privacy Policy: https://twitter.com/privacy#twitter-privacy-1
Cookie Policy: https://help.twitter.com/rules-and-policies/twitter-cookies
LinkedIn Page
LinkedIn is a social network operated by LinkedIn Inc., headquartered in Sunnyvale, California, USA. It enables the creation of private and professional profiles for individuals as well as company profiles. Users can maintain existing contacts and establish new ones. Companies and other organisations can create profiles, upload photos and company information, and present themselves as employers and recruit employees. Other LinkedIn users may access this information, publish their own articles and share content. The focus of the network is professional exchange on specialist topics among people with similar professional interests.
When you use or visit the network, LinkedIn automatically collects data from users and visitors, such as user name, job title and IP address. This is done using various tracking technologies. LinkedIn uses the data collected, among other things, to provide users with information, offers and recommendations.
We collect data via our company profile only to enable communication and interaction with us. This usually includes your name, message content, comment content and the profile information you have made publicly available.
Processing is based on our legitimate interests pursuant to Article 6(1)(f) GDPR. Where you have given the provider your consent, the legal basis also includes Article 6(1)(a) and Article 7 GDPR.
As the actual processing is carried out by the provider, our access to your data is limited. Exercising your rights is therefore most effective when done directly with the provider.
We and LinkedIn are joint controllers for the processing of personal data on our company profile. Data subject rights may be asserted both with LinkedIn Inc. and with us.
We do not make decisions regarding the data collected by LinkedIn via tracking technologies on its platform.
Further information about LinkedIn:
https://about.linkedin.com
LinkedIn privacy policy:
https://www.linkedin.com/legal/privacy-policy
LinkedIn cookie policy:
https://de.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy
XING Page
XING is a social network operated by XING SE, headquartered in Hamburg, Germany. It enables the creation of private and professional profiles. Users can maintain existing contacts and establish new ones. Companies can create profiles, upload photos and other company information. Other XING users can access this information, write their own articles and share content.
The focus is on professional exchange on specialist topics among people with similar professional interests. In addition, XING is often used by companies and other organisations to recruit employees and present themselves as attractive employers.
Further information about XING:
https://corporate.xing.com/de/unternehmen/
XING privacy policy:
https://privacy.xing.com/de/datenschutzerklaerung
We do not collect or process personal data via our XING company page.
Google Analytics
Nature and Scope of Processing
We use Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as an analytics service to statistically evaluate our online offering. This includes, for example, the number of visits to our online offering, visited sub-pages and the length of time visitors spend on the site.
Google Analytics uses cookies and other browser technologies to analyse user behaviour and recognise users.
This information is used, among other things, to compile reports on website activity.
Purpose and Legal Basis
Google Analytics is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG.
Storage Period
The specific storage period of the processed data is not controlled by us but is determined by Google Ireland Limited. Further information can be found in the Google Analytics privacy policy:
https://policies.google.com/privacy
Google Tag Manager
Nature and Scope of Processing
We use Google Tag Manager, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to manage website tags via an interface and enables us to control the integration of services on our website.
This allows us to flexibly integrate additional services and evaluate user access to our website.
Purpose and Legal Basis
Google Tag Manager is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG.
Storage Period
The specific storage period of the processed data is not controlled by us but is determined by Google Ireland Limited. Further information can be found in Google Tag Manager’s privacy information:
https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/
HubSpot
Nature and Scope of Processing
We use HubSpot, a service provided by HubSpot Ireland Limited, 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland, for lead management, analysis of user behaviour, creation of user profiles and the implementation of marketing measures (e.g. email marketing, lead tracking, automation).
HubSpot uses cookies and similar technologies to collect data about visitors’ use of our website. This data may include in particular:
- IP address (shortened/appropriately anonymised)
- Browser type and version
- Operating system
- Pages visited and interactions
- Date and time of access
- Data entered in forms
Personal data entered in forms (e.g. name, email address) is stored and processed in our HubSpot CRM.
Purpose and Legal Basis
Processing is carried out in particular for:
- analysing and improving our online offering,
- handling and managing contact enquiries,
- carrying out marketing and lead nurturing activities,
- sending newsletters (only with separate consent).
Processing is based on your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG where tracking cookies are used. Where personal data is processed for the purpose of taking steps prior to entering into a contract (e.g. handling an enquiry), processing is also based on Article 6(1)(b) GDPR.
Transfers to Third Countries
It cannot be ruled out that data may be transferred to HubSpot servers in the USA. HubSpot is certified under the EU–US Data Privacy Framework.
Storage Period
Data is stored only for as long as necessary for the respective purposes or where statutory retention obligations apply.
Withdrawal of Consent
You may withdraw your consent at any time with effect for the future by adjusting your cookie settings or by contacting us. Further information can be found in HubSpot’s privacy policy:
https://legal.hubspot.com/de/privacy-policy
Leadinfo
Nature and Scope of Processing
We use Leadinfo, a service provided by LeadInfo B.V., Crooswijksesingel 50, 3034 CJ Rotterdam, The Netherlands, which identifies anonymous website visitors and provides business contact details and insights into visit history.
Leadinfo uses cookies and other browser technologies to analyse user behaviour and recognise users.
Among other things, Leadinfo shows us which companies have visited our website and records the course of the visit, including all pages viewed and the duration of the visit.
Leadinfo collects and processes company-related data such as company name, telephone number, address, website, industry, company profile, turnover and key contacts on LinkedIn.
Purpose and Legal Basis
Leadinfo is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG.
Storage Period
The specific storage period of the processed data is not controlled by us but is determined by LeadInfo B.V. Further information can be found in Leadinfo’s privacy policy:
https://www.leadinfo.com/de/datenschutz/
Leadinfo CDN
Nature and Scope of Processing
We use Leadinfo CDN to ensure the proper delivery of content on our website. Leadinfo CDN is a service provided by LeadInfo B.V. which acts as a content delivery network (CDN) on our website.
A CDN helps deliver content (in particular files such as images or scripts) more quickly via regionally and internationally distributed servers. When you access such content, a connection is established to LeadInfo B.V. servers (Crooswijksesingel 50, 3034 CJ Rotterdam, The Netherlands). Your IP address and, where applicable, browser data such as your user agent may be transmitted. This data is processed solely for the purposes stated above and to maintain the security and functionality of Leadinfo CDN.
Purpose and Legal Basis
The use of the CDN is based on our legitimate interests, i.e. our interest in secure and efficient provision and in optimising our online offering, pursuant to Article 6(1)(f) GDPR.
Storage Period
The specific storage period of the processed data is not controlled by us but is determined by LeadInfo B.V.
LinkedIn Insight Tag
Nature and Scope of Processing
We use the LinkedIn Insight Tag, provided by LinkedIn Corporation, Sunnyvale, California, USA, to create audiences, segment visitor groups of our online offering, measure conversion rates and optimise them. This is particularly the case if you interact with advertisements placed by us via LinkedIn. LinkedIn also offers retargeting for website visitors in order to display targeted advertising outside our website.
The LinkedIn Insight Tag collects data about visits to our website, including URL, referrer URL, IP address, device and browser characteristics (user agent) and timestamps. This data is used to generate anonymised reports about website audiences and ad performance.
Purpose and Legal Basis
The LinkedIn Insight Tag is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG.
Transfers to Third Countries
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Transfers to the USA take place pursuant to Article 45(1) GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US subcontractors are certified under the EU–US Data Privacy Framework (EU–US DPF).
Where no adequacy decision exists (including US companies not certified under the EU–US DPF), we have agreed other appropriate safeguards within the meaning of Articles 44 et seq. GDPR with the recipients. Unless otherwise stated, these are the European Commission’s Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021. A copy is available at:
https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE
In addition, prior to such transfers to third countries we obtain your consent pursuant to Article 49(1)(a) GDPR, which you provide via the consent manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks that are not fully known in detail (e.g. access by public authorities in the recipient country), over which we have no influence and of which you may not become aware.
Storage Period
The specific storage period of the processed data is not controlled by us but is determined by LinkedIn Corporation. Further information can be found in LinkedIn’s privacy policy:
https://www.linkedin.com/legal/privacy-policy

