1. Introduction
RFS GmbH ("RFS", "we", "our", or "us") is committed to protecting the privacy of visitors to our website and our business partners. This Privacy Policy explains how we collect, use, store, and share personal data when you interact with our Site, submit inquiries, request quotations, or otherwise engage with our services. RFS processes personal data in compliance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection laws.
2. Data Controller
The data controller responsible for processing your personal data is:
RFS GmbH
Musterstrasse 42
30159 Hanover, Germany
Email: [email protected]
Phone: +49 511 554-60
3. Data We Collect
We collect the following categories of personal data:
3.1 Information You Provide
- Contact & inquiry data: name, company name, job title, email address, phone number, and project requirements submitted through contact forms, quotation requests, or email correspondence.
- Account data: login credentials if you register for access to restricted technical documentation or our customer portal.
- Transaction data: billing address, shipping address, purchase order numbers, and payment information related to product orders.
3.2 Data Collected Automatically
- Technical data: IP address, browser type and version, operating system, device identifiers, screen resolution, and language preferences.
- Usage data: pages visited, time spent on pages, referral source, click paths, search queries on the Site, and download history for technical documents.
- Cookie data: session identifiers and preference cookies (see Section 8 below).
4. How We Use Your Data
We process your personal data for the following purposes:
- Respond to inquiries: processing technical consultation requests, quotation requests, and general inquiries (legal basis: contract performance, Art. 6(1)(b) GDPR).
- Order fulfillment: processing, shipping, and invoicing product orders (legal basis: contract performance, Art. 6(1)(b) GDPR).
- Site functionality: ensuring the technical operation, security, and performance of the Site (legal basis: legitimate interest, Art. 6(1)(f) GDPR).
- Analytics: analyzing usage patterns to improve Site content, navigation, and user experience (legal basis: legitimate interest, Art. 6(1)(f) GDPR).
- Marketing communications: sending product updates, technical bulletins, event invitations, and industry news only with your explicit consent (legal basis: consent, Art. 6(1)(a) GDPR).
- Legal compliance: meeting regulatory obligations including export control, tax, and accounting requirements (legal basis: legal obligation, Art. 6(1)(c) GDPR).
5. Data Sharing
RFS does not sell your personal data to third parties. We may share your data with:
- RFS group companies: subsidiaries and regional offices for fulfilling your requests and providing localized support.
- Service providers: hosting providers, email service providers, CRM platforms, and analytics tools that process data on our behalf under data processing agreements.
- Authorized distributors: when your inquiry relates to a region served by an authorized RFS distribution partner, with your knowledge.
- Legal authorities: when required by law, court order, or to protect RFS rights, safety, or property.
6. International Data Transfers
RFS operates engineering centers in Germany, the United States, China, Brazil, and Australia. Personal data may be transferred to RFS facilities outside the European Economic Area (EEA). When transferring data outside the EEA, we implement appropriate safeguards including EU Standard Contractual Clauses (SCCs) approved by the European Commission, or rely on adequacy decisions where applicable.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Inquiry data: 24 months from last interaction.
- Transaction data: 10 years as required by German commercial and tax law (HGB §257, AO §147).
- Marketing consent records: retained until consent is withdrawn.
- Technical logs: 90 days.
8. Cookies
The Site uses the following types of cookies:
- Strictly necessary cookies: required for Site operation (e.g., session management, security tokens). These do not require consent.
- Functional cookies: remember your language preference and form inputs to enhance usability.
- Analytics cookies: help us understand how visitors interact with the Site. These are only placed with your consent.
You can manage cookie preferences through your browser settings or our cookie consent banner. Disabling certain cookies may limit Site functionality.
9. Your Rights
Under GDPR and applicable data protection laws, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16 GDPR): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR): request deletion of your personal data where applicable.
- Right to restriction (Art. 18 GDPR): request limitation of processing under certain circumstances.
- Right to data portability (Art. 20 GDPR): receive your data in a structured, machine-readable format.
- Right to object (Art. 21 GDPR): object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent: withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
10. Data Security
RFS implements appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include TLS encryption for data in transit, access controls based on the principle of least privilege, regular security assessments, and employee training on data protection requirements.
11. Children's Privacy
The Site is designed for business professionals and is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete it promptly.
12. Changes to This Policy
RFS may update this Privacy Policy from time to time to reflect changes in our data practices or legal requirements. The revised policy will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.
13. Supervisory Authority
If you believe that our processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with a supervisory authority. The competent authority for RFS is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hanover, Germany
Website: www.lfd.niedersachsen.de
14. Contact
For any questions or concerns about this Privacy Policy or our data processing practices, please contact:
RFS GmbH — Data Protection
Musterstrasse 42, 30159 Hanover, Germany
Email: [email protected]
Phone: +49 511 554-60