Privacy Statement of the Vossloh Group

The protection of privacy for Vossloh’s customers and interested parties is a priority of our Company. This is particularly true when it comes to the handling of your personal data collected through our website www.vossloh.com / www.vossloh.de. In this privacy statement, we would like to explain the type of data we collect, how we use it and the rights you have. All data collected by Vossloh is collected, stored and processed in accordance with applicable data protection regulations, in particular, the European Data Protection Regulations (“GDPR”). The data protection principles outlined in this statement do not apply to websites on the Internet that are accessible via links found on our website.

Please keep in mind that any transfer of data on the Internet carries a security risk. It is not possible to achieve absolute protection from access by third parties.

Which data are collected and how?

Throughout our website, you can obtain information related to our company and the products and services that we offer in various ways. For example, you have the option of subscribing to our newsletter service, you can order or download our publications or you can get in touch directly with our Investor Relations and PR Department or Vossloh in general. In addition, you are able to apply for employment with Vossloh online.

Should you take advantage of one of these methods of obtaining information or applying for employment, you will be directed to the relevant contact or application mailbox. When you enter your personal data, only the data entered in the relevant input screen and any sent application documents will be saved. After you have entered or sent your data, it will be automatically forwarded to the responsible member of staff by email.

To the extent necessary for the performance of the services that you have requested, or for the purpose of processing your online application, we will collect the personal data that you have entered in the relevant contact form or in the context of your online application, such as your name, your address, telephone number, e-mail address and other entered data.

The legal basis for the processing of personal data from this website is Art. 6, para. 1, (b) GDPR, unless otherwise described in the following paragraphs.

When and how is information collected automatically?

Data is gathered and stored from this website for marketing and optimization purposes using the technologies of etracker GmbH. Using this data, user profiles can be created under a pseudonym. Cookies can be used for this purpose. Cookies are small text files that are saved locally in the cache of the Internet browser of the person visiting the site. The data gathered using the etracker technologies will not be used, without the express permission of the user, to identify the user of this website personally and will not be combined with the personal data of the carrier of the pseudonym. Consent to future collection and storage of data can be revoked at any time.

If we insert the disclaimer (IR-area) cookies will be used. We do not save any IP addresses for this purpose.

We use a "Content Delivery Network" (CDN) on our website. A CDN is a service with the help of which the content of an online offer, in particular large media files such as graphics or programme scripts, can be delivered more quickly and securely with the help of regionally distributed servers connected via the Internet. The legal basis for the use of CDN services on our website are legitimate interests (Art. 6 para. 1, (f) GDPR).

For what purposes and for how long do we use your data?

Vossloh uses your personal data for the technical administration of the website, for customer and application management and for marketing, but in each case only within the scope that is legally permitted and required. If you decide to provide us with your personal data for these purposes then this data will only be saved and used for these purposes.

We provide a newsletter service for press representatives and interested third parties. You can subscribe to this service. The data provided in the newsletter subscription will, unless you expressly agree to a further use for a particular purpose, be used exclusively for sending the newsletter. You can unsubscribe at any time using one of the options set out in the newsletter.

Any personal data shared in the context of an electronic application is in principle used exclusively for processing the application and for contacting the applicant.

If Vossloh executes an employment agreement with an applicant then the data that has been transferred will be saved for the purpose of developing the employment relationship, in compliance with statutory regulations.

Furthermore, following the conclusion of the application process, even if no employment agreement is concluded with the applicant, your personal data will be deleted by our employees responsible for personnel management, in principle, two months after notification of the decision not to proceed, provided that there are no legitimate interests on the part of Vossloh that would prevent such deletion. Such a legitimate interest might include, for example, the obligation to provide evidence that an open and non-discriminatory application procedure has been implemented under the principles of the General Equal Treatment Act (Allgemeines Gleichbehandlungsgesetz or AGG) or corresponding legislation under other jurisdictions.

In principle, Vossloh is the entity that stores your personal data. However, Vossloh can instruct external IT service providers or other companies in the Vossloh Group to carry out the storage and processing of your personal data. In this event Vossloh will execute a commissioned data processing agreement with the service provider, which will ensure that your personal data is handled in accordance with data protection regulations.

When and how is your personal data passed on to third parties?

Your personal data will only be transferred to third parties if required to process your requests or to comply with mandatory legal requirements. Your personal data will not be transferred to other third parties for any other purposes, such as for market research or other marketing objectives.

Social Plugins

Vossloh uses Social Plugins (below, “buttons“), in the form of links from our website to social networks such as Facebook, Google+ and Twitter, as well as to the video portal YouTube. The following data protection notice shall apply to these:

When you visit our website, these buttons are disabled by default. Before you use the buttons, you need to activate them by clicking on them. The button will remain active until you deactivate it or delete your cookies.

Following activation, a direct connection with the server of the relevant social network or YouTube will be created. The contents of the button will then be transferred directly from the social network or YouTube to your browser and connected from this to the website.

Once a button has been activated, the relevant social network or YouTube will be able to collect data immediately, irrespective of whether or not you interact with the button. If you are logged into a social network account or into YouTube through a google account, it can assign your visit to the website to your user account.

If you belong to a social network and do not want it to link the data collected through your visit to our website with your saved member data, then you will need to log out of the relevant social network before activating the buttons.

Vossloh has no control over the extent of data gathered by the social networks and YouTube through the activation of the respective buttons. Please refer to the data protection notices of the relevant providers to obtain information concerning the type of data collected and how it is used and processed by the social networks and YouTube, as well as your rights with regards to the configuration options available to ensure the protection of your privacy.

How do we protect your data?

All of your personal data collected through this website is protected by suitable technical and organizational measures against accidental or deliberate manipulation, misuse, loss or destruction and against access by unauthorized persons. Our security measures are constantly being improved in line with technological development. For example, your data is stored in a secure operating environment that is not accessible by the public. In certain situations your personal data will be encrypted during transfer through Secure Socket Layer (SSL) technology. This means that an approved encryption method will be used for the communication between your computer and the Vossloh servers, provided that your browser supports SSL.

Our employees are bound by special confidentiality obligations in accordance with applicable data protection regulations.

What are your rights?

Your rights are set out in the relevant regulations of the GDPR (articles 15 to 21).
These are the rights to:
  • Disclosure
  • Correction
  • Deletion
  • Objection

Upon your written request, we will notify you, as promptly as possible, of your personal data that we have stored. If the personal data that we have stored is not correct (or is no longer correct), then you may request a correction. If your data is incomplete, then you may request an amendment. If we have passed your data onto third parties, we will inform such third parties of your correction – provided that this is prescribed by law.

You may request a deletion of any of your personal data that we have stored. For example, you may request a deletion of your personal data if your data is no longer necessary for the purposes for which it was collected, if it has been processed unlawfully, if you have revoked your consent or if another legal basis for storage is absent.

You may also object to the processing of your personal data, on the grounds of legitimate interests or for the public benefit, unless we can demonstrate compelling legitimate grounds for such processing that outweigh your interests, rights and freedoms, or if such processing is for the purpose of the assertion, exercise or defense of legal claims.

Contact

If you have any questions or comments on this privacy statement, in particular, regarding the exercise of your rights, please feel free to contact us at any time by email or by post:

Datenschutzbeauftragter für die Vossloh Aktiengesellschaft
Vosslohstraße 4
D-58791 Werdohl
datenschutzbeauftragter@vossloh.com