Privacy Policy (GDPR)

Notice: We do not use your data for marketing purposes. We do not send any advertising, newsletters, or circulars by email or post, and we do not make any promotional telephone calls.


1. Controller Responsible for Data Processing
Responsible for the processing of personal data on this website, within the scope of commercial transactions, on-site at the retail store, via telephone and email contact, as well as at trade fairs/events is:
Homberg + Brusius e.K., Owner: Kitty Homberg, Auf der Lay 31, 55743 Kirschweiler, Germany
Phone: +49 (0)6781 35036, mail@homberg-und-brusius.de

2. General Information and Scope
This information provides a simple overview of what happens to your personal data when you visit our website or enter into business contact with us. Personal data means any data by which you can be personally identified.
This policy applies equally to our end customers (B2C) as well as to the contact persons, representatives, and employees of our business, trade fair, and cooperation partners (B2B). Purely corporate data without personal reference is not subject to the GDPR, but the data of the acting natural persons (e.g., managing directors, contact persons, or clerks) is.

3. Data Collected and Purposes of Processing
a) Provision of the Website and Creation of Server Log Files
When you access our website, our host STRATO automatically collects information that your browser transmits to us.
• Data: IP address, browser type/browser version, operating system used, referrer URL (the previously visited page), host name of the accessing computer, and time of the server request.
• Purpose: Ensuring an error-free, stable, and secure provision of the website as well as defense against cyberattacks.
• Legal Basis: Art. 6 para. 1 lit. f GDPR (Legitimate interest in the technical functionality and security of our website).
• Storage Duration: For security reasons, the server log files are stored by the host for a maximum of 7 days and are subsequently anonymized by shortening the IP address.
b) Contact Form, Inquiries, and Direct or Trade Fair Contacts (B2C & B2B)
If you use our contact form, send an inquiry to us, or enter into business contact with us on-site in our retail store, at trade fairs/events (e.g., via business card or lead sheet), by phone, letter, or email, we process the data you provide to us.
• Data: Last name, first name, company name if applicable, position/department, email address, phone number, message text, and payment data for on-site purchases if applicable.
• Purpose: Answering and processing your inquiries, preparing offers, processing sales contracts, and general maintenance of customer and business relationships.
• Legal Basis:
o For B2C customers and pre-contractual inquiries: Art. 6 para. 1 lit. b GDPR (Performance of a contract or pre-contractual measures).
o For B2B contact persons: Art. 6 para. 1 lit. f GDPR (Legitimate interest in communication and maintenance of business relationships with our contractual partners).
o To fulfill legal obligations (e.g., tax requirements for business agreements): Art. 6 para. 1 lit. c GDPR.

4. Cookies and Consent (Cookie Banner)
When you access our website, a cookie notification banner provided by our host STRATO appears. This banner allows you, as a website visitor, to make a granular choice regarding the cookies and data processing to be loaded by means of an opt-in procedure. The system distinguishes between the following categories:
• Technically necessary cookies: These are strictly required for the secure, stable, and error-free operation of the website (e.g., protection against hacker attacks or detection of mobile devices). They cannot be deactivated. The legal basis is our legitimate interest in a technically flawless provision pursuant to Art. 6 para. 1 lit. f GDPR in conjunction with Section 25 para. 2 No. 2 TDDDG.
• Analytical cookies: Provided you give your consent, the host's system collects anonymized statistics on the use of our website (e.g., the number of page views) in order to optimize the technical user experience. No profiles are created that can be traced back to you as a person. The legal basis is your consent pursuant to Art. 6 para. 1 lit. a GDPR.
• Third-party content (external content): This category regulates the activation of external media or scripts. If you do not consent here, external content will be blocked by the system and will not be loaded.
On our website, we also use a static link (button) to our Instagram profile (Meta Platforms Ireland Limited). This is a simple link. No automatic social media plug-ins are active that transfer data as soon as the page loads. You only leave our website when you actively click on the button.
You can view, adjust, or withdraw your cookie consents at any time with effect for the future via the banner on our website.

5. Period of Data Storage and Email Archiving
Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for processing the data no longer applies or statutory retention periods have expired.
• Data from commercial transactions / contracts (10 years): In order to comply with statutory, tax, and accounting obligations (German Commercial Code / HGB and Fiscal Code / AO), all data in connection with a sales contract will be stored for a duration of 10 years.
• Business emails and correspondence: The archiving of our business email infrastructure takes place fully automatically, unalterably, and in an audit-proof manner in accordance with the standards of the German GoBD requirements for 10 years at our service provider STRATO.
• Pure prospective customer and trade fair inquiries (3 years): For inquiries that did not lead to the conclusion of a contract, the data will be deleted for a duration of 3 years (regular limitation period pursuant to Section 195 of the German Civil Code / BGB) after the end of the year in which the inquiry was made. If these inquiries were captured via our automated GoBD email archive, they will remain stored there, protected and blocked, due to the technical impossibility of selective deletion until the expiry of the 10-year total retention period (Legal basis: Art. 6 para. 1 lit. f GDPR – Legitimate interest in compliance with the GoBD).

6. Recipients of Data (Data Processors)
We never sell your data to third parties for advertising purposes. Within the scope of our technical, operational, and tax administration, we transfer data to service provider partners with whom we have concluded data processing agreements pursuant to Art. 28 GDPR or who are independently responsible:
• STRATO GmbH (Otto-Ostrowski-Straße 7, 10249 Berlin): For web hosting, provision of the website infrastructure, and GoBD-compliant email archiving (Data Processor).
• DATEV eG (Nuremberg): For the legally secure digital capturing and archiving of tax-relevant accounting data (depending on the structure of the service, either as a data processor or as an independently responsible controller within the scope of professional law).
• Our tax advisor (Tax advisory firm / Auditor): For the fulfillment of our tax and commercial law obligations (Independently responsible controller).
• Shipping and logistics service providers: For the purpose of delivering goods or offers, we transfer exclusively the strictly necessary address data (name and address) to the transport companies commissioned by us (e.g., DHL, DPD, or freight forwarders). A disclosure of your email address or phone number to the shipping service provider will not take place without your separate consent.
• Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland): Only a static link to our Instagram profile is placed on our website. Data is only transmitted to Meta when you actively click the button and leave our website.

7. Data Security
For security reasons and to protect the transmission of confidential content (such as inquiries via a contact form), this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser bar.
To protect your data outside of the website as well, we use appropriate technical and organizational security measures (pursuant to Art. 32 GDPR). The digital storage and management of everyday business data takes place on our local in-house IT systems as well as encrypted in the certified German data centers of our partners. These systems are continuously protected by state-of-the-art firewalls and antivirus programs. Retired digital data carriers are layout-permanently destroyed before disposal. Physical paper files are destroyed in compliance with data protection regulations using a document shredder after the expiry of the statutory periods. Use of unsecure or non-European cloud services does not take place.

8. Your Rights (Data Subject Rights under the GDPR)
As a data subject affected by the data processing, you have the following rights at any time within the scope of statutory provisions:
• Right of access (Art. 15 GDPR): You can request information about your personal data processed by us.
• Right to rectification (Art. 16 GDPR): You can request the immediate correction of incorrect or completion of your data.
• Right to erasure (Art. 17 GDPR): You can request the deletion of your data, provided that no statutory retention obligations stand in the way.
• Right to restriction of processing (Art. 18 GDPR): You can request the restriction of data processing under certain conditions.
• Right to data portability (Art. 20 GDPR): You can request to receive your data in a structured, commonly used, and machine-readable format.
• Right to withdraw consent (Art. 7 para. 3 GDPR): You can withdraw a consent once given to us at any time with effect for the future.
RIGHT TO OBJECT (Art. 21 GDPR)
If your data is processed on the basis of legitimate interests (Art. 6 para. 1 lit. f GDPR), you have the right to object to the processing of your personal data, provided that there are reasons arising from your particular situation. If your data is processed for direct marketing purposes, you have a general right to object, which will be implemented by us without stating a particular situation.
If you wish to exercise any of these rights, simply write an informal email to us at:
mail@homberg-und-brusius.de
You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR (Art. 77 GDPR). A list of supervisory authorities and their contact details can be found via the following link: edpb.europa.eu



 
E-Mail
Anruf
Karte
Infos
Instagram