The purpose of this document is to outline the rules and actions regarding the collection, processing, and protection of personal data by Moldcom Composites with regards to the requirement of the EU General Data Protection Regulation (GDPR).
We assure that we apply technical and organizational measures with the utmost care so that your personal data are protected in the best possible way. We protect your data against unauthorized access, as well as other cases of disclosure, loss or unauthorized modification.
1. Controller of your personal data
The entity responsible for the processing of personal data is:
Moldcom Composites, S.L.( B97772412)
c/s, 2. Pol Industrial el Oliveral.
46394, Ribarroja del Túria (Valencia)
+34 96 321 23 11
(hereinafter referred to as: the “Controller”)
You can contact our data protection officer at:
Or by mail via the address stated above.
2. Personal data we process
We process personal data that we receive from you while using our website and, if applicable, during our business relationship.
In the case of purely informational use of our website, i.e., if you do not submit information to us through a form, we only collect the personal data that your browser transmits to our server. When you access our website, we collect access data, which is technically necessary for us to present our website to you and to ensure stability and security.
The access data includes:
- the IP address, date and time of the request,
- content of the request (i.e. name of the specific website accessed),
- access status/HTTP status code,
- amount of data transferred in each case,
- operating system and its interface, language and version,
- type of browser software,
- notification of successful retrieval.
Furthermore, we receive your personal data if you contact us via contact form or e-mail. Personal data here are, for example, name, address, e-mail, telephone number and, if applicable, the data that you send us in the message (hereinafter referred to as "contact data").
3. Legal basis of processing your personal data
We process personal data in accordance with the GDPR for the following purposes and based on the following legal grounds:
If you have given us consent to process personal data for certain purposes, in particular for contacting you (e.g. via our contact form or by e-mail for processing and handling the enquiry, sending newsletters, advertising by telephone, e-mail, SMS, etc.), this processing is lawful on the basis of your consent.
You may revoke given consent at any time with effect for future processing. You can send the revocation to the above contact details or to email@example.com.
Consent, Art. 6 para 1 sentence 1 lit. a GDPR
When contacting us (via contact form or e-mail) to get information about our products, your data will be processed for the purpose of managing your request and providing you the requested information.
Performance of a contract or execution of pre-contractual measures upon request of the person, Art. 6 para 1 lit b GDPR,
When you visit our website for the first time, we will ask you whether you wish to consent to the use of non-essential cookies. (The use of essential cookies does not require your consent.)
More on cookies and how you can manage them, see section “Cookies” [https://mcbath.eu/en/cookies-policy].
Consent, Art. 6 para. 1 sentence 1 lit. a GDPR
We process your access data to safeguard our legitimate interests or those of third parties. We pursue the following legitimate interests:
As part of the balancing of interests for the safeguarding of legitimate interests, Art. 6 para. 1 sentence 1 lit. f GDPR
4. Recipients of your personal data
Within the organization, departments that need to know your data to fulfill our contractual and regulatory obligations can access your data.
In addition, processors (Art. 28 GDPR) engaged by us may also obtain access to data for the above-mentioned purposes. If we use processors to provide our services, we will take appropriate legal precautions as well as the relevant technical and organizational measures to protect personal data in accordance with applicable law.
Any transfer of data to third parties will be made only within the scope of legal requirements. We will disclose your data to third parties only if this is required, for example, under Art. 6 para. 1 sentence 1 lit. b GDPR for contractual purposes or based on legitimate interests pursuant to Art. 6 para 1 sentence 1 lit. f GDPR in the economic and effective operation of our business or if you have consented to the transfer of data. In the case of purely informational use of the website, we do not pass on any data to third parties.
We may share your personal data with the following categories of recipients and data processors:
- entities rendering accounting and tax services for our company,
- entities providing legal services for our company,
- entities servicing and managing our IT system,
- entities providing courier or postal services for our company,
- banks – if it is necessary to make settlements,
- insurance companies which adjust claims,
- state authorities or other entities authorized under legal regulations – to perform duties imposed on us,
- in the case of data obtained in connection with direct marketing – marketing agencies.
5. Period of data storage
For security reasons (e.g. to clarify acts of abuse or fraud), log file information is stored for a maximum of seven days and then deleted (see point 2 above). Data whose further storage is necessary for evidentiary purposes is exempt from deletion until the final clarification of the respective incident.
As far as necessary, we process and store your personal data for the duration of our business relationship, which also includes, for example, the initiation of a contract via contact form or by e-mail.
Applicant data will be deleted after six months in the event of a rejection. If you have agreed to further storage of your personal data, we will transfer your data to our applicant pool. There, the data will be deleted if you revoke your consent or after five years at the latest. Should we fill the advertised position with you, your data will be stored in our personnel management system.
We are legally obliged to store personal data in the context of performing contracts and complying with fiscal obligations. The according retention periods to the records apply.
6. Transfer of personal data to third countries or international organizations
The data provided will be processed within the European Union and in the USA. For countries without an adequacy decision by the Commission according to Article 45 GDPR, as is the case with the USA, we generally agree on EU standard contractual clauses with the recipients of your data or obtain your consent for the data transfer. Furthermore, transfer of data is based on a Data Transfer Impact Assessment.
Note: The protection of personal data in the USA does not correspond to the level of data protection required by the EU. In particular, there are no enforceable rights to protect your data against access by government authorities. Therefore, there is a risk that these government agencies can access the personal data without the data transmitter or the recipient being able to effectively prevent this.
7. Your rights as a data subject
In connection with the processing of your personal data by us, you have the following rights:
- The right to information about personal data processing: you have the right to obtain from us information about the purposes and grounds for personal data processing, the scope of data stored, entities to which they are transferred, and the planned date of data erasure.
- The right to access your data and receive their copy: you have the right to receive a copy of the data processed which concern you.
- The right to rectify (correct) personal data: you have the right to request that we remove incompatibilities or errors regarding your data and demand them to be supplemented or updated – if they turn out to be incomplete or out-of-date.
- The right to restrict processing of personal data: you have the right to demand that we cease to perform certain operations on your personal data.
- The right to erase personal data: you have the right to demand that we erase data whose processing is no longer necessary for the purposes for which they have been collected (the so-called “right to be forgotten”).
- The right to data portability: you have the right to obtain from us personal data concerning you which you provided to us based on a contract or your consent, in a structured, commonly used machine-readable format. You can request us to forward your data directly to another controller (if it is technically possible).
- The right to object to the processing of personal data: “marketing” objection – you have the right to object to the processing of your data to conduct direct marketing; if you exercise this right – we will stop processing data for this purpose. Objection in a specific case – you also have the right to object to the processing of your data based on a legitimate interest for purposes other than direct marketing, and when processing is necessary for us to perform a task carried out in the public interest or to exercise public authority entrusted to us. In this case, you should indicate to us your specific situation which in your view justifies the cessation of processing covered by the objection. We will stop processing your data for these purposes, unless we demonstrate that the basis for processing of your data is superior to your rights, or that your data are necessary to us to establish, exercise or defend claims. Objections do not require a particular form and no costs are incurred, other than the transmission costs according to the basic tariffs. If possible, any objection should be addressed to the above-mentioned address or email.
- The right to revoke consent to the processing of personal data: if personal data are processed based on your consent, you have the right to revoke your consent at any time (revocation of your consent will not affect the lawfulness of the processing carried out prior to the revocation of your consent).
The above notifications and measures requested by you will be made available to you free of charge in accordance with Art. 12 para 5 GDPR.
To exercise your rights referred to hereinabove, all correspondence should be sent via post or e-mail to the following address: Moldcom Composites, S.L.( B97772412), c/s, 2. Pol Industrial el Olivaral. 46394, Ribarroja del Túria (Valencia), email: firstname.lastname@example.org. Before complying with your rights, we will have to ensure that you are really you, i.e., identify you accordingly.
If you believe that we are processing your personal data in violation of the provisions of the GDPR or other legal acts regulating personal data protection, you have the right to lodge a complaint to the President of the Office for Personal Data Protection.
8. Automated individual decision-making, including profiling
In the context of accessing our website or in the context of contacting us by form or e-mail, we do not use any fully automated decision-making pursuant to Article 22 GDPR. Should we use these procedures in individual cases, we will inform you about this separately if this is required by law. We do not process your data automatically with the aim of evaluating certain personal aspects (profiling).
9. Information on source of data/voluntary provision of data
Providing personal data by you is voluntary. However, if you do not provide the data which are necessary, for example, to render certain services by us or provide you with a response to your request, it may prevent us from taking specific actions.
In addition, if you raise objection regarding our direct marketing, you will not be informed about our marketing activities.
In the situation of performing a contract, we obtained your data from our contractor who indicated you as a contact person and provided us with data regarding your name, surname, e-mail address and telephone number. If we have obtained your data from another source, we will provide you with relevant additional information in this regard.
With the following information, we inform you about our newsletter as well as the registration, dispatch and evaluation procedure and inform you about your rights of objection. If you subscribe to our newsletter, you agree to receive the newsletter and the described procedures.
Newsletter content: We send newsletters, emails and other electronic notifications with promotional information (hereinafter "newsletter") only on the basis of the consent of the recipient or on the basis of a legal permission. If we specifically describe individual newsletters as part of the registration process, this description is decisive for the consent of a newsletter subscriber. If there is no separate description, you will receive information about our products, offers and promotions as well as information about our company in our newsletters.
To register for the newsletter, it is sufficient to enter your e-mail address. Optionally, we ask you to enter a name for the purpose of personal address in the newsletter.
Double-Opt-In: The registration for our newsletter takes place in the so-called Double-Opt-In procedure. This means that after registering for the newsletter, we will send you an e-mail in which we ask you to confirm your registration. This confirmation serves to ensure that only persons who have access to the specified e-mail address register for our newsletter. We log the registrations to the newsletter in order to be able to prove the registration process according to the legal requirements. This includes the storage of the registration and confirmation time, as well as the IP address. Changes to your data stored with the newsletter service provider are also logged.
The newsletters contain a so-called web beacon, i.e. a pixel-sized file that is retrieved from the server of the newsletter service provider when the newsletter is opened. Within the scope of this retrieval, technical information, such as information on the browser and your system, as well as your IP address and the time of the retrieval are initially collected. This information is used for the technical improvement of the services on the basis of the technical data or the target groups and your reading behaviour on the basis of their retrieval locations (which can be determined with the help of the IP address) or the access times. Statistical surveys also include determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our intention nor that of the dispatch service provider to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.
The dispatch of the newsletter and the measurement of its success are based on the consent of the recipients in accordance with Art. 6 Para. 1 Sentence 1 lit. a), Art. 7 GDPR.
The logging of the registration process takes place on the basis of our legitimate interests pursuant to Art. 6 (1) sentence 1 lit. f) GDPR and serves as proof of consent to receive the newsletter.
You can unsubscribe from our newsletter at any time, i.e. revoke your consent. You will find a link to cancel the newsletter at the end of each newsletter. If users have only subscribed to the newsletter and cancelled this subscription, their personal data will be deleted.
12. Processing of personal data in the context of the use of external online services
12.1 Google Analytics
We use the web analytics service Google Analytics from Google Ireland Limited (registration number: 368047), Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) hereinafter "Google".
Google processes the data for us to evaluate the use of our website by the website visitors, to create reports about the activities within our website and to provide further services connected with the use of our website. In doing so, pseudonymous usage profiles of the website visitors are created from the processed data.
During your visit to the website, the following information is collected, among other things:
- Pages viewed,
- Achievement of contact targets, such as contact requests or newsletter sign-ups,
- Your use of our website, for example clicks and time spent on one of our pages,
- Your approximate location (country),
- Your IP address (in shortened form, so that no clear assignment is possible),
- Technical information such as browser type, internet provider used, terminal device and screen resolution,
- Via which website or advertising medium you came to us.
Recorded data is stored together with the randomly generated user ID, which enables the evaluation of pseudonymous user profiles. This user-related data is automatically deleted after 14 months. Other, non-personal data remain stored in aggregated form for an unlimited period of time. The IP address transmitted by your browser will not be merged with other data from Google.
We use Google Analytics with IP anonymization enabled. This means that the IP address of the user is shortened by Google within the European Union or European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
You can also opt-out from Google Analytics via a browser add-on, which you can download here: https://tools.google.com/dlpage/gaoptout?hl=en
Further information on data processing by Google, setting and objection options can be found on the Google website at https://policies.google.com/technologies/partner-sites.
12.2 Google Tag Manager
We use the Google Tag Manager service from Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, based on your consent.
The Google Tag Manager is a service that organizes the loading of additional tools - especially analytics tools. Google receives your IP address when the Google Tag Manager is loaded. The Google Tag Manager servers are usually located in Ireland, but also in the USA.
There are corresponding risks associated with processing your data in the USA. Please note that US authorities, such as intelligence agencies, could potentially gain access to personal data exchanged with Google through the integration of this service due to US laws such as the Cloud Act.
By giving your consent via our cookie banner, you consent to the processing of your data in the USA, despite potential access by US authorities, Art. 49 (1) p. 1 lit. a GDPR.
For more information on Google Tag Manager, please see Google's privacy notice at https://www.google.de/intl/de/policies/privacy/.
We use the "reCAPTCHA" function of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), in order to be able to recognize whether entries in forms are made by humans and not by automatically acting software tools (so-called "bots").
The data processed includes IP address, information on operating systems, devices and browsers used, language settings, location, mouse movements, interactions with reCAPTCHA on other websites, cookies if applicable and results of manual recognition processes (e.g. selection of images according to certain criteria).
There are corresponding risks associated with the processing of your data by Google in the USA. By giving your consent via our cookie banner, you agree to the processing of your data (here your IP address) in the USA despite potential access by US authorities.
The privacy information can be found at https://policies.google.com/technologies/partner-sites.
We have integrated YouTube videos into our online offer, which are stored on http://www.YouTube.com of Google Ireland Limited (registration number: 368047), Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) and can be played directly from our website. The legal basis for the use of YouTube is your consent in accordance with Art. 6 (1) p. 1 lit. a) and Art. 49 (1) p. 1 lit. a GDPR.
The videos are integrated in such a way that data about you as a user is only transmitted to YouTube when you play the videos. We have no influence on the data transmission to Google that then takes place.
By visiting the website, YouTube receives the information that you have accessed the corresponding subpage of our website and data on location (GPS data), IP address and devices used, including information on objects in the vicinity of your device, such as WLAN access points, radio masts and Bluetooth-enabled devices, as well as sensor data from your device (see YouTube privacy information of the provider). This is done regardless of whether you are logged in to Google or YouTube. If you are logged in, however, your data may be assigned to your account. If you do not wish to have your data associated with your YouTube profile, you must log out before activating a video. YouTube stores your data in case you are logged in as user profiles and uses them for purposes of providing the services, maintaining and improving the services, measuring performance, developing new services and providing personalized services, including content and advertisements. You have the right to object to the creation of these user profiles, and you must contact YouTube to exercise this right.
The processing of data within the scope of this service also takes place in the USA. The information generated by the cookies about the use of our website is usually transferred to a Google server in the USA and stored there. There are corresponding risks associated with the processing of your data in the USA. By giving your consent via our cookie banner, you consent to the processing of your data in the USA, despite potential access by US authorities, Art. 49 para. 1 p. 1 lit. a GDPR.
For more information about the purpose and scope of data collection and processing by YouTube, please see the privacy information. There you will also find further information about your rights and setting options to protect your privacy:
12.5 Facebook Pixel
We use on the basis of your consent (via our cookie banner) the so-called "Facebook pixel" of the social network Facebook, which is operated by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (parent company: Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA).
With the help of the Facebook pixel, it is possible for Facebook to determine the visitors to our website as a target group for the display of advertisements (so-called "Facebook ads"). Accordingly, we use the Facebook pixel based on our legitimate interests in the analysis, optimization and economic operation of our website and our company in order to display the Facebook ads placed by us only to those Facebook users who have also shown an interest in our website or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited), which we transmit to Facebook (so-called "Custom Audiences"). With the help of the Facebook pixel, we also want to ensure that our Facebook ads correspond to the potential interest of users and do not have a harassing effect. With the help of the Facebook pixel, we can also track the effectiveness of the Facebook ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook ad (so-called "conversion").
The collected data is also transferred by Facebook to the USA and other third countries. Please note that the protection of personal data in the USA and third countries does not correspond to the level of data protection required by the EU. In particular, there is a lack of enforceable rights that safeguard the protection of your data against access by government authorities. Thus, there is a risk that these governmental entities may be able to access the personal data without the data transmitter or the recipient being able to effectively prevent this. If you do not want Facebook to be able to associate your visit to this website with your Facebook user account, please log out of your Facebook user account.
The processing of the data is carried out under the joint responsibility of Facebook and us in accordance with Art 26 of the GDPR. The primary responsibility for the processing of personal data in the context of the plugins lies with Facebook and all obligations under the GDPR with regard to the processing of personal data are fulfilled by Facebook (in particular the information obligations pursuant to Article 12 et seq. GDPR, ensuring the rights of data subjects pursuant to Article 15 et seq. GDPR, notification of data breaches pursuant to Articles 33, 34 GDPR).
You can find Facebook's privacy information at https://www.facebook.com/about/privacy/.
You can opt-out of the Facebook Pixel's collection and use of your data to display Facebook Ads. To adjust which types of ads are displayed to you within Facebook, you can visit the page set up by Facebook and follow the instructions there on the settings for usage-based advertising: https://www.facebook.com/settings?tab=ads.
13. Social media
You can find us on social networks and platforms, so that we can also communicate with you there and inform you about our services.
We point out that your data may be processed outside the European Union / European Economic Area and that the data is usually processed for market research and advertising purposes. Profiles can be created from the usage behavior and resulting interests of the users. These profiles can in turn be used, for example, to place advertisements within and outside the platforms that presumably correspond to the interests of the users. For this purpose, cookies may be stored on the computers of the users, in which the usage behavior and the interests of the users are stored. Other data may also be stored in these usage profiles, especially if the users are members of the respective platforms and are logged in to them.
We only link to our company profiles on the respective social networks on our website. However, please note that when you click on a link to the social networks, data is transmitted to their servers. If you are logged in to the respective social network at this time with your username and password, the information that you have visited our company profile on the respective social network from our website will be transmitted there and the respective provider can store this information in your user account.
In principle, we have no influence on the data processing of the social networks. However, we receive statistics from them about the use and visits of our company profile in their social network (e.g. information about the number of views, interactions such as likes and comments as well as summarized demographic and other information or statistics). For more information about the data processed by the social networks, please see the respective privacy notices linked below.
Insofar as we receive your personal data in the context of our social media profiles (e.g. in the context of a communication), you are entitled to the rights mentioned in this privacy notice. You can address your requests regarding data processing within the scope of our company profiles to us via the contact data mentioned above.
If you also wish to exercise rights against the provider of the social network, the easiest way to do so is to contact the respective network directly. The network knows both the details of the technical operation of the platform and the associated data processing as well as the specific purposes of the data processing. The contact details can be found in the privacy notice linked below. We will also be happy to support you in exercising your rights, insofar as this is possible for us.
The processing of your personal data is generally based on your consent in accordance with Art. 6 para 1 sentence 1 lit. a GDPR. The legal basis is also Art. 6 para 1 lit. b GDPR if we receive and process your data as part of a contract-related inquiry. The legal basis for the linking and operation of our company profiles in the social networks, including the receipt of statistics on the use of our company profiles, is Art. 6 para 1 lit. f GDPR based on our legitimate interest in our corporate communication in the respective social networks.
For information on the respective processing and the objection options, we refer to the privacy notice of the networks linked below:
- LinkedIn (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland), social network for maintaining existing and making new business contacts - privacy information https://www.linkedin.com/legal/privacy-policy , opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- Google YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), video portal - privacy information: https://policies.google.com/privacy, opt-out: https://adssettings.google.com/authenticated
- Pinterest (Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA) - Privacy Information/ Opt-Out: https://about.pinterest.com/de/privacy-policy
- Facebook (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland), We operate our Facebook page on the basis of a shared personal data processing agreement with Facebook - Privacy Information: https://www.facebook.com/about/privacy/ , Opt-Out: https://www.facebook.com/settings?tab=ads and http://www.youronlinechoices.com.^
- Instagram (Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland), online photo and video sharing service, privacy information https://help.instagram.com/519522125107875/?helpref=hc_fnav