Information about data processing
Transparency and Information Obligations for Customers, Contractual Partners, and Prospective Customers of Bausch+Ströbel SE + Co. KG.
under the EU General Data Protection Regulation (GDPR)
This document provides information about the processing of your personal data by Bausch+Ströbel SE + Co. KG and about the rights to which you are entitled under data protection law.
Responsible Body / Data Protection.
Bausch+Ströbel SE + Co. KG
Parkstraße 1
74532 Ilshofen
Germany
Tel.: +49 7904 701-0
Fax: +49 7904 701-222
Data Protection Contact: dsb.b-s@bausch-stroebel.de
Categories / Sources of Data
As part of establishing and maintaining a contractual relationship, we process the following personal data:
Contact details (e.g. first and last names of current and, where applicable, former contacts, including name prefixes or suffixes, company name and address of the customer (employer), mobile and landline telephone numbers including extension numbers, email address, fax number)
Professional information (e.g. position within the company, department)
Bank account details, where applicable (in the case of a SEPA direct debit mandate, also the first and last name of the account holder)
Credit rating information, where applicable
As a rule, we obtain your personal data directly from you during the initiation of a contract or in the course of an ongoing contractual relationship.
In exceptional cases, your personal data may also be collected from other sources in specific situations. This includes context-specific queries with credit reference agencies, particularly regarding credit ratings.
Bausch+Ströbel SE + Co. KG uses, among other things, products of Microsoft Corporation within its IT environment. In the course of using these IT systems, the following categories of data may be processed:
Functional data (data that is strictly necessary for the provision of services/functions)
Content data (content-related data processed within the scope of the services or applications)
Diagnostic and log data (technically logged data required for maintenance, troubleshooting, and, in some cases, further development)
These categories of data are collected directly from you through the relevant systems. Upon request, we will be pleased to provide you with further information regarding data processing in specific IT systems.
As part of our online meetings using Microsoft Teams, we process the following personal data:
Communication data (e.g. your email address, if you voluntarily provide it as personal information)
Log files and logging data
Metadata (e.g. IP address, time of participation, etc.)
Profile data (e.g. your username, if you voluntarily provide it)
Please note that any further data processing activities, for example those related to accessing the Microsoft Teams website and/or installing the Microsoft Teams application, are not within our area of responsibility.
Microsoft reserves the right to process customer data for its own business purposes. We have no influence over these data processing activities carried out by Microsoft. To the extent that Microsoft Teams processes personal data in connection with Microsoft's own business purposes, Microsoft acts as an independent controller for such processing activities and is responsible for complying with all applicable data protection regulations.
If you require information about Microsoft's processing of personal data, please refer to the relevant Microsoft privacy statement.
Purposes and Legal Bases of Data Processing
When processing your personal data, we always comply with the provisions of the GDPR (General Data Protection Regulation), the German Federal Data Protection Act (BDSG), and all other applicable legal requirements.
Your personal data is processed exclusively for the purpose of carrying out pre-contractual measures (e.g. preparing quotations for products or services) and for the fulfilment of contractual obligations (e.g. providing our services or handling orders, contracts, and payments) pursuant to Article 6(1)(b) GDPR, or where processing is necessary to comply with a legal obligation (e.g. obligations under tax law) pursuant to Article 6(1)(c) GDPR. Your personal data was originally collected for these purposes.
A data protection provision may, of course, also be based on your consent to the processing of your personal data (Article 6(1)(a) GDPR). Before obtaining your consent, we will inform you about the purpose of the data processing and your right to withdraw consent in accordance with Article 7(3) GDPR.
Bausch+Ströbel SE + Co. KG also has a legitimate interest in maintaining its customer relationship with you and in providing you with information and offers relating to our products and services by email. Therefore, we process your data for the purpose of sending you such information and offers (Article 6(1)(f) GDPR).
Your personal data will be processed for the purpose of detecting criminal offences only under the conditions set out in Article 10 GDPR.
Data Retention Period
Your data will be deleted by us as soon as it is no longer required for the purposes described above or if you withdraw your consent.
Data will only be retained beyond the duration of the contractual relationship where we are obliged or permitted to do so. Legal provisions requiring us to retain data can be found, for example, in the German Commercial Code (Handelsgesetzbuch, HGB) and the German Fiscal Code (Abgabenordnung, AO). These requirements may result in retention periods of up to ten years. In addition, applicable statutory limitation periods must be observed.
Recipients of Data / Categories of Recipients, Transfers to Third Countries / Intention to Transfer Data to Third Countries
Within our company, we ensure that only those individuals who require your data to fulfil contractual and legal obligations are granted access to it.
In certain cases, service providers support our specialist departments in carrying out their tasks. The necessary data protection agreements have been concluded with all such service providers in accordance with applicable data protection laws.
We will only disclose your data to additional recipients or third parties within the meaning of the GDPR where you have given your consent or where such disclosure is permitted under applicable law, in particular where we are required to do so by mandatory legal provisions (for example, disclosure to external bodies such as supervisory authorities, law enforcement agencies, tax authorities, or customs authorities).
Personal data will only be transferred to third countries (countries outside the European Union (EU) or the European Economic Area (EEA)) where this is necessary for the performance of the contractual relationship, required by law, or where you have given your consent to such transfer.
We transfer your personal data to service providers or affiliated group companies located outside the European Economic Area (EEA), specifically in the United States of America.
Compliance with the required level of data protection is ensured through appropriate safeguards, such as EU Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and, where applicable, additional protective measures and guarantees.
When selecting service providers, every effort is made to engage European service providers (i.e. service providers located within the European Economic Area (EEA)). However, this is not always possible, for example in the case of Microsoft.
Microsoft is certified under the EU-U.S. Data Privacy Framework and therefore meets the requirements established by the European Commission for the protection of personal data transferred to the United States.
Where service providers from third countries are used, care is taken to ensure the most restrictive configuration possible.
(In the case of Microsoft, for example, data processing is contractually agreed to take place in Europe. In addition, system configurations are restricted by IT experts, and individual processing activities are coordinated with the Data Protection Officer.)
Rights of Data Subjects
The rights of data subjects are set out in Articles 15 to 22 of the GDPR. These include:
The right of access (Article 15 GDPR)
The right to rectification (Article 16 GDPR)
The right to erasure (Article 17 GDPR)
The right to restriction of processing (Article 18 GDPR)
The right to object to processing (Article 21 GDPR)
The right to data portability (Article 20 GDPR)
To exercise these rights, please contact our Data Protection Officer at dsb.b-s@bausch-stroebel.de. The same contact may be used if you have questions regarding the processing of data within our company or if you wish to withdraw any consent you have previously given. You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.
If we process your data on the basis of legitimate interests, you may object to such processing at any time on grounds relating to your particular situation. This also applies to any profiling based on these provisions.
In such cases, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise, or defence of legal claims.
If we process your personal data for the purposes of direct marketing, you have the right to object to such processing at any time without providing any reasons. This also applies to profiling insofar as it is related to such direct marketing.
If you object to the processing of your personal data for direct marketing purposes, we will no longer process your personal data for those purposes.
Obligation to Provide Data
In order to establish and administer a contractual relationship, you are required to provide certain personal data. This is necessary for the initiation, performance, and termination of the contractual relationship, as well as for the fulfilment of the associated contractual and legal obligations. It is not possible to fulfill the contract without providing this information.
Automated Individual Decision-Making
We do not use any purely automated processing procedures to make decisions.
This privacy notice is currently valid and reflects the status as of September 2026. Due to the further development of our products and services or changes in legal or regulatory requirements, it may become necessary to amend this notice. The most current version of this notice can be accessed and printed at any time.