Data Protection and Privacy

We as GROHE appreciate your interest in our company, our products and our services. We take the protection of your privacy when using our GROHE-X Platform very seriously. In the following we are pleased to inform you about the collection of personal data. 

 

A. Responsible for the data processing

The person responsible for the processing of personal data in the context of this Website in accordance with the regulations of the European General Data Protection Regulation (GDPR) is

Grohe AG,
Postfach 1361,
58653 Hemer
Germany.

You can reach our Corporate Data Protection Officer at DataProtection(a)Grohe. com.

With this privacy statement we inform you about the extent of the processing of your personal data (hereinafter only "data").

 

B. Data processing when using the GROHE X Platform

As part of the operation of the GROHE X Platform („Website“) we process data. The processing of the data also includes the disclosure by transmission.

The data, processing purposes, legal bases, recipients and transfers to non-EEA countries concerned are listed in the following list:

a) Use of cookies

In order to make visiting our Website more attractive and to enable the use of certain functions, we use so-called cookies. These are small text files that are stored on your terminal device.

The cookies can be transmitted to a page when it is called up and thus enable the user to be identified. Cookies help to simplify the use of Internet pages for users. Cookies from third-party providers are also used on our platform (e.g. to support our advertising and marketing measures). Some of the cookies we use are deleted after the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your terminal device and enable us to recognize your browser the next time you visit us (so-called persistent cookies).

You can set your browser so that you exclude the acceptance of cookies for certain cases or generally. You can delete cookies that have already been set. If you do not accept cookies, the functionality of our Website may be limited.

For details on the cookies we use, please refer to the below information in the "Cookie List".

 

b) Log file

We log your visit to our Website. The following data is processed: Name of the retrieved web page, date and time of retrieval, time difference to Greenwich Mean Time, access status, amount of data transferred, browser type and version, the operating system you are using, the referrer URL (previously visited Website), your IP address and the requesting provider. This is necessary to ensure the security of the website. 

We process the data on the basis of our legitimate interests in accordance with Art. 6 para. 1 f) GDPR. The log file will be deleted after seven days, unless it is required to clarify or to prove concrete infringements that have become known within the retention period.

c) Registration on the Website

On the Website, you have the opportunity to participate in digital events as well as to use the content provided there. In order to use all functions and services on the Website, it is necessary that you register and create your own user account. 

When you create a user account, we process the data required for registration and login to the Website. This includes your name, e-mail address, company name, country, academic title and profession, if applicable, as well as your access data (user name, password).

We process the personal data on the basis of Article 6 para. 1 b) DSGVO. The purpose of the data processing is the conclusion and performance of the contract for the use of the Website (Terms of Use) and, in connection with this, the provision of the functions and services available on the Website.

 

d) Use of the Website as a digital content and event platform

We make various functions and services available to you on the Website. This includes in particular the organization of digital events as well as the provision of digital content (e.g. articles on product inspirations, design stories, project examples, training or installation videos, presentations). We store your personal interaction with the Website, for example whether you register for an event or you add certain content to your personal favourites. You can view the events you have booked as well as your personal favourites in your personal account area ("My Grohe X").

If you register for an event on the Website that is organized by a GROHE regional entity, we will share your data with the respective regional entity to the extent necessary for the purpose of organizing and carrying out the event.

We process the personal data on the basis of Article 6 para. 1 b) GDPR. The purpose of the data processing is the conclusion and performance of the contract for the use of the website (Terms of Use) and, in connection with this, the provision of the functions and services available on the Website.

e) Notifications about new content on the Website (Grohe X Notifier).

We are constantly striving to adapt and expand the content provided on the Website. If you create a user account, we will regularly notify you about new content on the Website via the email address you provided during registration (so-called Grohe X Notifier). This includes, for example, information on upcoming online events and other new content (e.g. articles on product inspirations, design stories, project examples, training or installation videos, presentations) as well as news on new features and services on the Website. The sending of this information is based on your personal target group according to your interests. 

We process the personal data on the basis of Article 6 para. f) DSGVO. The purpose of the data processing and our legitimate interest is to inform you about content on the Website at any time. You can object to the sending of such notifications by e-mail at any time free of charge by clicking on the unsubscribe button contained in the respective notifications, without incurring any costs other than the transmission costs according to the prime rates.

f) Hosting and technical operation of the Website

Within the scope of hosting, all data to be processed in connection with the operation of this Website is stored. This is necessary to enable the operation of the Website. We process the data to implement the contract underlying the use of the Website in accordance with Art. 6 para. 1 b) GDPR. To provide our online presence, we use the services of technical IT service providers who store the above-mentioned data. In some cases, these IT service providers are based outside the EEA, specifically in India.

 

g) Contacting us and exchange of information

We offer you the possibility on the Website to contact us via the functions and forms provided there and to request information from us. Information can be offered in digital form, in written form or also in the context of appointments. You are free to choose from the available information.

We process your data for the purpose of processing your request as well as providing you with the requested information, contacting you for further assistance and asking you for feedback on our services and events. We also use your data for statistical purposes to measure success and to further improve our services. We transmit relevant data to contracted companies only in the context of hosting and logistics services. In the case of a personal appointment, we pass on relevant data to the GROHE branch or GROHE regional entity responsible for you. You can find an overview of the individual GROHE regional entity [here]. Your data will not be passed on to other third parties.

If you order information material from our employees, we will transmit your address data to the company commissioned with the delivery. If it is necessary for processing, for example, due to a high order volume, we transmit additional contact information (for example, your e-mail address or your telephone number) to the company responsible for delivery to coordinate a delivery date (notification).

This data is processed by us on the basis of Art. 6 para. 1 b) DSGVO or Art. 6 para. 1 f) DSGVO to process your request. 

 

h) Newsletter

You can register for the GROHE newsletter on the Website in order to regularly receive customized information about offers, products and services from GROHE and the GROHE regional entities. When you register for the newsletter, we process the data you enter (name, e-mail address, your company category and interests) and pass it on to the GROHE regional entity responsible for you. You can find an overview of the individual GROHE regional entities [here].

We obtain the following consent when you register for the newsletter:
"I hereby consent to receive information about new offers, products and services from Grohe AG and the Grohe regional entities by e-mail based on my individual interests. I can revoke my consent at any time. For more information on newsletter delivery and the Grohe regional entities, please refer to our data protection policy."

The transmission of the newsletter by means of registration takes place on the basis of your consent in accordance with Art. 6 para. 1 a) GDPR. You can revoke your consent at any time via the unsubscribe link included in the specific email.

The registration for the newsletter takes place in the so-called double opt-in procedure. To prevent abuse, we will send you an e-mail after your registration, asking you to confirm your registration. In order to prove the registration process according to the legal requirements, your application will be logged. Affected are the storage of the registration and the confirmation time and your IP address. To send the newsletter, we use service providers to whom we provide the above data.

To receive details regarding the specific Newsletter such as content or frequency, please refer to the respective registration page.

 

i) Website analysis

We use the following third-party analytics tools for our Website to better understand and evaluate the behaviour of our users. We only use these analysis tools if you have given us your prior consent to do so. The legal basis for the processing of personal data is therefore Art. 6 para. 1 a) GDPR. (consent).

Insofar as you have consented to the use of cookies, first party cookies and third party cookies are placed on your device when you visit the website. Third party cookies are cookies that are controlled and managed by a third-party provider (such as Google or Facebook). First party cookies are placed by us are managed and read out directly by us. In certain cases - which we explicitly address in this section - we pass on the data collected by first party cookies (IP address and cookie IDs) to third parties.

 

Google Analytics
We use Google Analytics a service of Google LLC 1600 Amphitheater Parkway Mountain View, CA 94043 USA. Google uses certain cookies. The information generated by the cookie about your use of this Website (including your IP address) will be transmitted to and stored by Google on servers in the United States. We use the information stored to evaluate your use of the Website, to compile reports on website activity for website operators, and to provide other Website-related services.

Please note that this website uses Google Analytics with the extension "anonymizeIp ()". This truncates IP addresses before transmitting them to a server in the United States. A direct personal reference in connection with the stored data is thus usually excluded. Only in exceptional cases will the full IP address be sent to a server in the USA and shortened there.

You may opt-out of the collection of data at any time by opting for the Google Analytics Disable Add-on at any time

tools.google.com/dlpage/gaoptout?hl=en

Further information on data protection can be found at:

https://policies.google.com/privacy?hl=en&gl=en
http://www.google.com/intl/de/policies/privacy/partners/
https://www.google.com/policies/privacy/ads/ 

 

Hotjar
We use Hotjar to better understand our users' needs and to optimize our services and the experiences offered. Hotjar is a technology service that helps us better understand our user experience (e.g. how much time is spent on which page, which links they choose to click on, what users like or dislike) and this allows us to customize and maintain our services using user feedback. Hotjar uses cookies and other technology to collect data about our users' behavior and the devices they use. 

This includes device IP address (processed during your session and stored in an unidentifiable form) screen size of the device used, type of device, geographic location (country) and preferred language used to view our site. Hotjar stores this information for us in a pseudonymized user profile. Hotjar is contractually prohibited from selling this data for or on our behalf. 

For more information, please see the "about Hotjar" section of the Hotjar support page.

 

j) Online marketing

We use various third-party services on our Website for conversion tracking and remarketing. These services enable us to statistically record and improve the effectiveness of our advertisements.

For this purpose, we collect various information as well as user interactions in connection with the use of the offers and functions provided on our Website and the interaction with the advertisements placed by us on other websites (e.g. whether a user clicks on an advertisement and subsequently registers on our platform).

The information collected includes the IP address and other data of the device used (e.g. device ID, operating system), the content of the respective advertisement as well as the user's reaction to the respective advertisement (e.g. registration, newsletter subscription). The collection of the respective information and interactions usually takes place by the respective third-party providers storing cookies on the end device of the users and evaluating tags embedded on our Website.

Based on the information and interactions collected, we can improve the targeting of our advertisements and optimise the offers and functions provided on our Website. It is also possible for us to draw users' attention to our offers and products again, e.g. by placing individual advertisements based on the interests of the respective users on other websites of the respective third-party providers and the advertising networks operated by them.

Specifically, we use the following services:

  • DoubleClick by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA and Google Ireland Limited, Gordon House, Barrow Street 4, Dublin, Ireland ("Google").
  • Facebook Pixel by Facebook Inc, 1601 Willow Road, Menlo Park, CA 94025, USA and Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook").
  • Amazon Ads pixel

    This website uses the Amazon Conversion Pixel and Amazon Remarketing Pixel web analytic services provided by Amazon Europe (Amazon Europe Core SARL, Amazon EU SARL, Amazon Services Europe SARL and Amazon Media EU SARL, all four at 38 avenue John F. Kennedy, L-1855, Luxembourg and as Amazon Digital Germany GmbH, Domagkstr. 28, 80807 Munich (together "Amazon Europe")). 

    Details about the designated data processor can be found here

    Categories of data processed: Data about the use of the website and logging of clicks on individual elements. 

    Purpose of processing: Investigation of usage behavior, analysis of the effect of online marketing measures and selection of online advertising on other platforms, which are automatically selected by means of real-time bidding based on usage behavior.

    The legal basis for the processing: Your consent according to Art. 6 (1) a GDPR. A transfer of data takes place: to the independent data controller Amazon Europe. This may also mean a transfer of personal data to a country outside the European Union. The transfer of data is based on your consent in accordance with Art. 6 (1) (a) in conjunction with Art. 44 (1) (a) GDPR.

    For the Data Privacy Policy of Amazon Europe: https://advertising.amazon.com/en-gb/legal/privacy-notice?ref_=a20m_us_fnav_l_prvcy 

    Duration of processing: is variable and ends when the purpose of processing ceases.

 

The legal basis for the processing of personal data is your consent pursuant to Art. 6 para. 1 a) GDPR.

You can also find more information about the cookies we use in online marketing in the below Cookie list and in the cookie settings (within the section "Targeting cookies").

 

k) Google Tag Manager

We use the Google Tag Manager from Google on the GROHE-X Platform. The Google Tag Manager supports us in the administration and control of the use of our services by implementing so-called website tags.

Website tags are small pieces of code that are inserted into a web page. Using these website tags, it is possible to track users' actions that they perform on the website as part of the processing for web analysis and online marketing described above.

The Google Tag Manager itself is a cookie-less domain. No cookies are used here and no personal data is collected. The Google Tool Manager merely triggers other tags, which in turn may collect data. However, the Google Tag Manager does not access this data.

 

C. Data processing within fairs, exhibitions, events, training courses and as well seminars

If and to the extent we process data that we receive in connection with industry trade fairs, exhibitions or events (outside the Website) as well as the associated registration on our online registration portal, if applicable, you will find further information on the scope of this data processing below:

a) Registration for specific events

 

To participate in our events, it is necessary to register as a participant.

It is necessary that you provide us with the personal data required for a specific registration. Required information is marked, without which a registration cannot take place.

An automated decision making process will not be carried out.

With your registration for a specific event we obtain the following consent:
"I would like to register for a specific GROHE event. I agree that GROHE, as well as the GROHE regional entity responsible for me, may use my data for this purpose, as well as for purposes of planning, voting and communication, conducting and following up this event with surveys, and for statistical purposes. I can revoke my consent at any time by sending an e-mail to "Gdpr-hospitality (a) grohe.com" with effect for the future".

If you enter data on behalf of individual participants, and register for a specific event only on behalf of others, you ensure that you have received the same consent from the respective participant, and that you have informed the participant of his or her right to withdraw.

In the event of a revocation, it may take up to 96 hours for us to process your request.

Your data will be processed on the basis of your consent in accordance with Art. 6 para. 1 a) GDPR.

 

b) Consent by handing over a business card within the framework of an event

As it is customary in the industry, the exchange of business cards means that you wish to be contacted by us for a specific purpose, such as further personal consultation. 

In terms of data protection law, however, the handing over of a business card does not have this effect.

In order to support you during a visit to our trade fair stand or one of our events, we offer you the opportunity to give us your consent to store the data of your business card for you and to subsequently contact you in order to agree on a specific support requirement. Our staff will be happy to support you in this process.

If you only register at an event and give GROHE your business card to complete your data, but without making a further selection of specific consulting or information offers, we will obtain the following consent when you register: 
"I would like to be contacted by GROHE AG and the GROHE regional entity responsible for me to arrange an appointment and to coordinate further activities. I agree that GROHE may process the data provided by my business card for this purpose, as well as for conducting surveys and for statistical purposes, and may transfer my data within the GROHE Group to the GROHE regional entity responsible for me for further support. I can revoke my consent at any time by sending an e-mail to "Gdpr-hospitality (a) grohe.com" with effect for the future".

In the event of a revocation, it may take up to 96 hours for us to process your request.

Your data will be processed on the basis of your consent in accordance with Art. 6 Par. 1 a) GDPR.

 

c) Photo and video recordings

In the context of trade fairs, exhibitions and events, we may take photographs and / or video recordings ("media") without your prior written consent. 

Instead of written consent, we will inform you as early as possible about a recording activity. By participating in our event, for example by entering our booth, you give your implied consent by conclusive action. 

Our recording activities will be open and visible, and in the case of individual recordings we will ask you, verbally or by gesture, whether you are available for recording, alone or in a group of individuals. You will always have the opportunity to object to a single shot with the respective film team.

Overall shots in which the focus is on the presentation of the event and not on the presentation of a single person / group of individuals (portrait shot) are excluded from this. Video recordings always represent an overall recording. If an overall recording is made in which persons are merely "accessories" to a scene in the sense of the law, this recording is made on the basis of our legitimate interests in accordance with Art. 6 Para. 1 f) GDPR.

We use media in the form of complete or portrait photographs, also in parts, for publications within the scope of our business activities and for the presentation of the company on intranet and internet sites, social media, print brochures, catalogues or via other forms of publication such as customer events and trade fairs, in digital and/or analogue form, worldwide.

By entering our booth, you give the following consent:
"I agree that GROHE AG may produce media from me and that I may transfer my rights to these media royalty-free, without retention of my own rights, to GROHE AG and its national subsidiaries for use within the scope of the stated purposes. 
I can exercise my right of withdrawal directly towards the film team, either by implied conduct or verbal communication. I understand that in order to exercise my right of revocation, I can always signal to the film team that I do not wish to have a portrait shot of myself and can therefore revoke my consent to the film team for the respective individual case. In each individual case, my revocation has the consequence that a picture will not be taken or, if the picture has already been taken, I can have it deleted by the film team immediately after taking it.”

We will process the data accordingly on the basis of your consent in accordance with Art. 6 para. 1 a) GDPR. 

 

D. Duration of data storage

We only store personal data for as long as it is necessary for the purposes for which it is processed or if your consent has been revoked. As far as statutory storage requirements are concerned, the storage period for certain data can be up to 10 years, regardless of the processing purposes.  

 

E. Data transfer to third countries

We transfer personal data to service providers and recipients in countries outside the European Economic Area (EEA) where such transfer is necessary for the purposes set out in this Privacy Policy. Such transfer takes place in the following cases:

  • Processing of personal data by providers of tracking and web analytics tools as well as marketing tools (see section B.i, B.j.).
  • Processing of personal data by IT service providers acting on our behalf, including hosting, security checks, algorithm testing, account management, web analytics (see section B.f).
  • Processing of personal data by GROHE regional entities insofar as they are located in a third country (see sections B.g., B.h., C.a., C.b.)

A transfer to a third country will only take place in compliance with the applicable data protection regulations, in particular the guarantee of an adequate level of data protection. This means that your data will only be transferred insofar as a decision of the EU Commission on an adequate level of data protection exists for the respective third country (Art. 45 GDPR), appropriate guarantees are provided for the protection of your personal data (cf. Art. 46 GDPR) or a legal permission norm exists (cf. Art. 49 GDPR). Appropriate safeguards within the meaning of Art. 46 GDPR include the standard data protection clauses published by the EU Commission, which we have concluded with service providers and recipients. For more information on this or a copy of the aforementioned standard contractual clauses, you can contact us at the contact information provided in section A.

 

F. Data Subjects’ Rights
a) Information

Upon request, you will receive information about all personal data that we have stored about you free of charge at any time. 

For your own protection, we reserve the right to obtain further information upon request to confirm your identity in order to prevent unauthorized persons from gaining access to personal data that we undertake to protect. If identification is not possible, we reserve the right to refuse to process the request.

 

b) Correction, cancellation, limitation of processing (blocking), opposition

If you no longer consent to the storage of your personal data or if these have become incorrect, we will, upon appropriate instructions, arrange for the deletion or blocking of your data or make the necessary corrections (to the extent permitted by applicable law). The same applies if we are to process data in the future only in a restrictive way.

 

c) Data Portability

Upon request, we will provide you with your data in a standard, structured and machine-readable format so that you can, if you wish, submit the data to another person in charge. 

 

d) Right of Objection

Pursuant to Article 21 of the GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6 para. 1 f) GDPR (data processing on the basis of a legitimate interest); this also applies to any profiling based on this provision within the meaning of Art. 4 para. 4) GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

The objection can be made form-free and should preferably be addressed to the office mentioned in the data protection declaration under section D-h.

 

e) Right to Complain

There is a right of appeal to the competent supervisory authority: 

www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

 

f) Right of revocation in the case of consent with effect for the future

Any given consent can be revoked at any time with effect for the future. Your revocation does not affect the lawfulness of the processing until the time of revocation. 

 

g) Limitation

Data where we are unable to identify the data subject, for example, if they have been anonymised for analysis purposes, is not covered by the above rights. Information, deletion, blocking, correction or transfer to another company may be possible with respect to such information if you provide us with additional information that allows us to identify it.

 

h) Exercising your Rights

If you have any questions regarding the processing of your personal data, information, correction, blocking, opposition or deletion of data or the desire to transfer the data to another company, please contact „central(a)grohe-x.com“. 

 

G. Data Security

To ensure the security of the data transmitted to us, we use TLS encryption with 128 bits. You recognize such encrypted connections with the prefix "https: //" in the page link in the address bar of your browser. Unencrypted pages are identified by "http: //".

All data that you submit to our Website - such as inquiries or logins - cannot be read by third parties thanks to SSL encryption.

 

H. Change of the privacy policy

In order to ensure that our data protection guidelines always comply with the current legal requirements, we reserve the right to make changes at any time. This also applies in the event that the data protection information must be adjusted due to new or revised offers or services.

 

STATUS: 06.2021