GDPR BURY GmbH & Co. KG

INFORMATION CLAUSE ON PERSONAL DATA PROCESSING BURY GmbH & Co. KG

This Policy applies to the personal data processing principles used by BURY GmbH & Co. KG, Robert-Koch-Straße 1-7, 32584 Löhne, Germany, hereinafter referred to as: “the Company” — as the Controller of personal data, the ways and purposes for which the data are processed, as well as the rights of individuals related to the collection and use of such data.

In connection with its business activities, the Company collects and processes personal data following relevant regulations, including, in particular, the regulations of the GDPR.

The Company ensures transparency of data processing; in particular, it always informs about data processing at the time of collection, including the purpose and legal basis of processing.
The Company ensures that data is collected only to the extent necessary for the stated purpose and processed only for the required period.

When processing data, the Company ensures its security and confidentiality, as well as access to information about the processing for data subjects.

To ensure the integrity and confidentiality of the data, the Company has implemented procedures to allow access to personal data only to authorized persons and only to the extent necessary due to their duties.  In addition, the Company shall take all necessary measures to ensure that its subcontractors and other cooperating entities also provide guarantees to apply appropriate security measures whenever they process personal data on behalf of the Company.

Under this Policy, we would like to inform you of any use of information that identifies individuals, hereinafter referred to as “personal data” (“processing”), with respect to individuals who are:

  1. customers, including potential customers of the Company,
  2. partners, associates, employees, legal representatives, attorneys or agents of such customers and
  3. other individuals whose data we process for the purpose of performing a contract between customers and the Company, including for the purpose of issuing or processing invoices (collectively referred to in this Policy as “you” or “customers”).

as well as:

Personal Data Controller

The Controller of your personal data is BURY GmbH, Robert-Koch-Straße 1-7, 32584 Löhne, Germany. Contact with the Controller is possible through the postal address: Robert-Koch-Straße 1-7, 32584 Löhne, Germany (hereinafter referred to as the ” Controller “, “Company” or “we”).

Types of personal data

Data provided by customers

In connection with the cooperation between you and the Company, as well as cooperation through intermediary entities, including affiliates within the BURY Group, we may process the personal data you provide, such as:

  1. name, company, business address and mailing addresses,
  2. numbers held in relevant registries (e.g., TIN or National Business Registry Number),
  3. identification numbers such as PESEL, 
  4. contact information, such as your email address or telephone or fax number,
  5. the position you hold within your organization,
  6. bank account number.

In the case of concluding an agreement directly between you and the Company, providing the data specified above is voluntary but necessary for the purpose of concluding the agreement and cooperation between the Customer and the Company. If you do not enter into an agreement directly with the Company, providing personal information may be your business obligation.

The consequence of failing to provide data is the inability to cooperate between the Company and the Customer.

Secondary Data Collection

We may obtain your personal data from publicly available sources, such as the Central Register and Information on Economic Activity (CEIDG) or the National Court Register (KRS), and the National Business Register (REGON), to verify the information provided by customers. The scope of the processed data will then be limited to the data publicly available in the relevant registers.

We may also obtain your personal data from entities where you are employed or of which you are a representative.  The scope of the processed data in such an instance will include information necessary for the execution of the agreement between the Company and such entity, i.e. information about a change in contact details or a change in an official position.

We may also obtain your data from internal databases maintained by our group affiliates.  It applies to data enabling contact with a specific customer who was a recipient or supplier of products of one of the Company’s affiliates.

Legal bases for processing personal data

We may process personal data if we have a valid legal basis for doing so. Therefore, we process personal data only if:

a) The processing is necessary to fulfill contractual obligations to you if you are a party to an agreement with the Company or you place orders for the Company’s products or services, or you fulfill the Company’s orders for your products or services;

b) The processing is necessary to fulfill our legal obligations, such as the obligation to issue an invoice or other document required by law, or we are directly ordered to do so by law;

c) The processing is necessary for the legitimate interests of the Company or a third party and does not unduly affect your interests or fundamental rights and freedoms, e.g. for:

Processing time periods for personal data

Personal data are processed only for the specified purpose and to the extent necessary to achieve it and for as long as needed.

Your personal data will be kept for the period of execution of the agreement concluded with the Company and after the termination of the agreement for the period necessary to secure the assertion of possible claims, and to meet obligations under the law, and in the case of withdrawal of consent to the processing of personal data or filing an objection – until the withdrawal of consent or filing an objection, respectively. In a situation where the processing of personal data is carried out based on the law, the data will be kept for a period of time under specific legislation, e.g. for 5 years from the end of the calendar year in which the deadline for payment of taxes has passed.

Transfer of personal data

Transfer of personal data within the group of entities affiliated with the Company

We may transfer personal data to our employees, associates, and other entities affiliated with the Company.  It applies to the following situations:

Transfer of personal data to other recipients

Data may be transferred to recipients and other third parties to fulfill the purposes listed above, to the extent that they are necessary for them to perform the Company’s tasks, if required by law or if the Company has another legal basis.  Recipients or other third parties may be considered:

Transfer Of Personal Data Outside The European Economic Area (EEA)

Your personal data may be subject to cross-border transfers to countries outside the European Economic Area (“EEA”) and to countries that do not have laws specifying special protection for personal data.  The Company has taken measures to ensure that all personal data is adequately protected and that transfers of personal data outside the EEA are lawful. In the case of transfers of personal data outside the EEA to a country that, according to the European Commission, does not provide an adequate level of protection for personal data, the transfer will be based on an agreement that takes into account EU requirements for transfers of personal data outside the EEA, such as standard contractual clauses approved by the European Commission.

Consumer rights

You have the right to:

Individuals have the right to restrict processing or object to processing their personal data at any time, based on their particular situation, unless the processing is required by law.

In such a case, we will no longer process the personal data or limit the processing as long as we can demonstrate a legitimate basis for the processing or for establishing, exercising or defending our rights.

The above rights are not absolute; the regulations provide exceptions to their application.

To execute the above rights, please send an email or contact the Company by correspondence to the respective addresses of the Controller indicated above in the section “PERSONAL DATA CONTROLLER”.

Policy updates

This Policy was updated on 1.02.2023 and may be subject to further changes.  If required by law, we will inform you of any material changes via our website or other customary communication channels.