1. nrwglobalbusiness.com
  2. Privacy Policy

Privacy Policy

Below, we would like to explain to you what data we collect about you personally and what we do with these data. We will also provide you with information about your data protection rights and explain who you can contact with questions about the protection of your data.


Who we are

The body responsible for processing your data:

NRW.Global Business GmbH
Trade & Investment Agency
of the German State of North Rhine-Westphalia (NRW)
Völklinger Strasse 4
40219 Düsseldorf, Germany

Tel: +49 211 13000-0

nrw@nrwglobalbusiness.com 

CEO:
Felix Neugart Petra Wassner

Concerning questions about this Data Protection Notice, processing of your data, your rights or other data protection topics, our data protection officer (DPO) would be pleased to help you.

Contact details for the Data Protection Officer:

NRW.Global Business GmbH
Trade & Investment Agency
of the German State of North Rhine-Westphalia (NRW)
The Data Protection Officer
Völklinger Strasse 4
40219 Düsseldorf, Germany

datenschutz@nrwgloblabusiness.com


Scope of application

This privacy policy applies to the nrwinvest.com website. It is intended for visitors to our website. Our web pages contain additional links that lead to the websites of other operators. This privacy policy does not apply to them. The respective operator is responsible for insertions of advertising banners, textual advertising or publicity films before or during embedded videos.


Do I have to provide my data?

When you visit our website, user data are automatically saved. Some of the data collected is necessary for the use of a website. In addition, we also process your data to safeguard our legitimate interests after consideration of all the relevant interests. This enables us to continuously improve the services we offer you. On the following pages, you will find out the background to our interests and whether or how you can object to the use of your data or disable the use yourself.

In order to take advantage of one of our offers or to send an enquiry, you are requested to submit your personal data. You can decide yourself whether to make use of these offers and submit your data for this purpose. We of course only process your data for the purpose for which you have provided your data to us. We also offer you services for which we only process your data if you have given your consent to this. Consent is always given voluntarily. Consent that has been given on one occasion can be withdrawn at any time.

Please note that, if you provide details about other people, you must have obtained their prior authorisation and have informed them about the purposes for passing the information on – as they are presented in this privacy policy.

We would be grateful if you could also pass on this information to the people you are including for the use of our services, such as family members or authorised representatives.


What data are processed?

I. Your visit to our website

Various data about you personally are saved and used during your visit to our website.

  1. Data processed and purposes of processing:
  • Service provision: the specified data must be collected to enable our website to be visited and used.
  • Data security: each time our Internet offering is accessed, this is stored in a log file. We only collect and use these data for the purposes of data security.
  • Optimisation of the Internet offering, including profiling: we are constantly improving our web pages to offer you an optimum experience. For this purpose we process the specified data about your visit. We will not match visitor data with your name or other personal information that you gave to us.

Data

Service provision

Data security

Optimisation of the Internet offering, including profiling

IP number

x

x

x

Name of the file accessed

 

x

 

Quantity of data transferred

 

x

 

Website accessed

x

 

x

Referrer URL (the previously visited website)

 

x

x

Search terms which have brought the Internet user to our website

 

 

x

User agent that your browser sends (only for mobile version or automatic voice command)

x

x

x

Session cookie

 

x

x

Date and time of visit

 

x

 

Date and time of the last user activity (for session timeout)

 

 

x

Operating system

 

 

x

Browser type, Browser version, Browser resolution (inner window size), Browser language, Screen format,Screen resolution, including colour depth

x

 

x

URL of the page viewed/downloads

 

 

x

Cookies on/off

x

 

x

JavaScript on/off

x

 

x

Installed plugins

 

 

x

Mouse movement within the browser window

 

 

x

Cookie for differentiating first visits and subsequent visits

 

 

x


2. Information about automated individual decisions

No automated individual decisions are made.

3. Legal basis/bases for using your data

  1. We process the personal data specified under Service provision to fulfil the quasi-contractual relationship with you so that you can access and use our service, in other words our website (Art. 6 (1) (b) GDPR).
  2. Furthermore, we process your data to safeguard our legitimate interests (Art. 6 (1) (f) GDPR):
    1. It is in our interest to be able to ensure data security. To this end, the data concerning every visit are saved in a log file and analysed.
    2. It is in our legitimate interest to optimise our Internet offering. To this end, service providers are used to carry out processing on our behalf, cookies are enabled, and the data provided about your visit to our website are processed.

You have the right, on the basis of reasons related to your particular situation, to object to the processing of your data for safeguarding our legitimate interests. For more on this please read 7. Cookies and web tracking.

4. Deletion deadlines (or storage time)

  • Closing the browser results in automatic deletion of the session cookies.
  • Technically, we need your IP number in order to supply the tracking pixel. It is not used for statistical purposes and is then immediately anonymised by our service provider, etracker GmbH. (see 6. Data recipients).
  • The data used for the optimisation of our Internet offering, including profiling, are deleted on a regular basis.
  • We use cookies to enable us to distinguish a return visit from your first visit to our website. You can delete the cookie manually, otherwise it will be automatically deleted after 28 days following your last visit to our website and then enabled again using a new ID on your next visit.

5. Source of the data

There is no third party data collection.

6. Cookies and web tracking

Cookies are used. You can delete these cookies at any time by changing your browser settings or preventing their acceptance.

If you do not want us to record your visits, then please click on the following link:

An opt-out cookie is enabled by clicking on the objection link. Please do not delete this cookie because it shows us your objection. If you use different browsers or PCs to visit our website, please click on the link in each browser.


II. Use of the knowledge base

1. Data processed and purposes of processing

The NRW knowledge base is a unique state-wide information and presentation database for the business location of North Rhine-Westphalia which you can access via our website and which you can log into. Via this database, North Rhine-Westphalia's partners, such as the state government, state initiatives and municipal and regional economic development agencies, have access to current economic and location data. We ask you to enter the data listed below to create an account:

  • Preferred user name (required later for login)
  • Password (required later for login)
  • Form of address
  • First name
  • Surname
  • Company
  • Street or PO box
  • Town/city
  • Postcode
  • Telephone
  • E-mail address

2. Information about automated individual decisions

No automated individual decisions are made.

3. Legal bases for using your data

  1. We process the above-mentioned data for the activation and use of the NRW knowledge base in the context of a quasi-contractual relationship of trust (Art. 6 (1) (b) GDPR). If you would like to make use of this service, we need the specified data to provide this service.

4. Deletion deadlines (or storage time)

  • To conserve evidence, we retain data within the scope of the legal statutes of limitations provisions in accordance with sections 195 et seq. BGB (German Civil Code).
  • Your personal data will be deleted within 14 days after the account is closed.

5. Source of the data

There is no third party data collection.


III. Making contact and other services

  1. Data processed and purposes of processing

Below, we would like to explain the purposes for which your data are processed if you have a request or use our services.

  • Dealing with enquiries, including contact forms: we process the data you give us when you have a question or request. This also includes the data which you have entered on the contact form or sent by e-mail or fax.
  • Newsletter: you can subscribe to our newsletter and we need an e-mail address for this.
  • Map service: in order to help you find NRW.INVEST more easily and to enable you to plan your journey, we provide you with a map from the Google Maps service. Use of the map means data are collected and processed by Google Inc. You can obtain further information in the Google Maps terms of use. We have no influence on data collection and processing by Google Inc.
  • Use of social plugins: our website uses social plugins for the Twitter, Xing and LinkedIn social networks to enable you to use the interactive facilities of the social networks you use on our Internet pages as well. Using a social plugin means the relevant operator is informed that you have accessed the corresponding page on our website. NRW.INVEST does not itself record any personal data via the social plugins or through their use, provided that you do not enable the plugin. In order to prevent data from being communicated to service providers in the USA without the user's knowledge, NRW.INVEST uses something known as the Shariff solution. The solution ensures that no personal data are initially passed on to the providers of the individual social plugins when you visit our website. Data are not passed on until you click on one of the social plugins. For example, if you are logged in to the operator, they can assign the visit to your account. If you interact with the plugins, for example press the "like" button or make a comment, the corresponding information is communicated to the operator directly from your browser and stored there. You can obtain further information in the Twitter, Xing and LinkedIn terms of use.
  • Showing videos: we incorporate YouTube videos into our online offering. These are stored on the YouTube servers and can be played directly from our website.

Data

Dealing with enquiries,
including contact forms

Newsletter

Map Service 
Google Maps

Use of social plugins
(after activation)

Showing videos

Form of address

x

x

 

 

 

First name, surname

x

x

 

 

 

E-mail address

x

x

 

 

 

Subject

x

 

 

 

 

Title (optional information)

x

 

 

 

 

Message

x

 

 

 

 

Country (optional information)

x

 

 

 

 

IP address

 

 

x

x

x

Time of access

 

 

x

x

x

Operating system used

 

 

x

x

x

Screen format, resolution

 

 

x

x

x

Browser type, version, plugins installed

 

 

x

x

x

Referrer URL (the previously visited website)

 

 

x

x

x

JavaScript on/off

 

 

x

x

x

URL of the page viewed / downloads

 

 

x

x

x

Town/City, Adress, Postcode

   

x

   


2. Information about automated individual decisions

No automated individual decisions are made.

3. Legal bases for using your data

  1. Furthermore, we process your data to safeguard our legitimate interests (Art. 6 (1) (f) GDPR):
  2. We process your data as stated under "Dealing with enquiries, including contact forms", "Newsletter", "Map service" and "YouTube videos" in the context of a quasi-contractual relationship of trust (Art. 6 (1) (b) GDPR). If you would like to make use of these services, we need the specified data to provide these services.
  • We provide you with social plugins for the Twitter, Xing and LinkedIn social networks in order to make it easier for you to exchange ideas about our content on social media and so as to design our website in an attractive way.
  1. We use your e-mail address to send our newsletter with information about our offers and services on the basis of the consent received from you (Art. 6 (1) (a) GDPR).

4. Deletion deadlines (or storage time)

  • Your personal data are deleted within 14 days after receipt of your enquiry.
  • Your e-mail address is deleted as soon as you unsubscribe from our newsletter or withdraw your consent.
  • To conserve evidence, we retain data within the scope of the legal statutes of limitations provisions in accordance with sections 195 et seq. BGB (German Civil Code).

5. Source of the data

There is no third party data collection.


Other processing purposes

In addition, the above-mentioned data are used for the following purposes in the context of a balance of interests (Art. 6 (1) (f) GDPR). The interests are described below

  1. Should a security incident occur in our company that affects your data, we are   obliged to report the case to our data protection supervisory authority (Article 33 GDPR). Since our legitimate interest is to comply with this statutory reporting obligation as quickly as possible, it may happen that in the context of the investigation of the corresponding security incident data about you are processed. Reports of these security incidents to data protection supervisory authorities do not contain any of your personal data.
  2. As it is in our interest to ensure the security of our systems, we regularly conduct security and efficiency tests that allow us to process your above-mentioned data.
  3. Since it is our interest to solve legal disputes, we process your data in that specific case. It is also in our interest, in the event of litigation, to keep evidence until all relevant statutory limitation periods pursuant according to sections 195 and fallowing of the German Civil Code, have expired. For this purpose, we retain the relevant data about you in accordance with these limitation periods. The retention periods cannot be globally predicted, since they depend on the particular matter in dispute and the respective statutory limitation period, which can be up to 30 years. The regular limitation period is three years.
  4. In addition, it is in our interest to investigate suspected cases and to hand over relevant information to law enforcement authorities in case of a specific criminal suspicion.
  5. We perform (internal) audits and other control activities (e.g. data protection officer’s monitoring activities), because it is our legitimate interest to comply with legal provisions, to obtain transparency about our business processes, to constantly optimise these processes and to prevent and identify harmful acts against our business. In doing so, documents or data sets with your personal data may be processed.
  6. We process your data for testing IT systems and software products and for migrations. The processing is necessary for satisfying our legitimate interest in evaluating if new products are correct and if migrations are complete.


Which organisations receive your data?

The following list shows which organisations ("data recipients") receive your data in which cases. In order to see which specific data this involves, you can read through the relevant sections of this policy. Your data are sometimes passed on due to statutory reporting requirements. In other cases, we use selected agents and service providers who operate on our behalf as processors (in accordance with Art. 28 GDPR) and may be given access to your data to the extent required in each case. Processors are subject to numerous contractual obligations and must in particular only process your personal data acting on our instructions and exclusively for the fulfilment of orders received from us.

  • Auditors
  • Data protection officer
  • Service providers for mass file destruction
  • Service providers for maps
  • Service providers for newsletter distribution
  • Service providers for optimisation of our website
  • Service providers for mailing and logistics
  • Recipient’s e-mail provider (for communication via e-mail)
  • IT service providers
  • Lawyers, law enforcement agencies, public prosecutor, courts, opposing lawyers, state or federal criminal police (for legal disputes or actual suspicious cases only)
  • Social media
  • Service providers for telecommunication

Data recipients in non-EU countries

  • This website uses a map service by Google Inc. ("Google") to display our company and its international offices on an interactive map. Use of Google Maps may mean that the data specified under "Map service" in the table above is transferred to a Google server in the USA and stored there. The EU Commission specifies which non-EU countries have an appropriate level of data protection.
  • Our website uses social plugins ("plugins") for the Twitter social network. Use of the plugin means that Twitter receives the data specified in the above table under "Use of social plugins (after activation)".
  • Our website uses social plugins ("plugins") for the LinkedIn social network. Use of the plugin means that LinkedIn receives the data specified in the above table under "Use of social plugins (after activation)".
  • We incorporate YouTube videos into our online offering. These are stored on the YouTube servers and can be played directly from our website. The videos are embedded in "enhanced data protection mode", which means that no data about you as a user are communicated to YouTube if you do not play the video. YouTube does not receive the data specified in the above table under "YouTube videos" until you play the videos. This is the case irrespective of whether YouTube provides a user account via which you are logged in or if no user account exists. If you are logged in with Google, your data are assigned directly to your account. If you do not wish them to be assigned to your profile, you have to log out before you play a video. Please consult YouTube's privacy notice for information on the purpose and scope of data collection, further processing and use of the data by YouTube, along with your rights associated with this and the setting options available for protecting your privacy.

The EU Commission specifies which non-EU countries have an appropriate level of data protection. The EU Commission recognises companies in the USA which participate in the EU-US Privacy Shield as data recipients with an appropriate level of data protection. This agreement between the USA and the EU ensures that data protection regulations comply with the level of data protection required in the European Union when data are processed by US companies subject to the EU-US Privacy Shield. According to their own statements, Google LLC, YouTube LLC, Twitter Inc. and LinkedIn Inc. are contracted into the EU-US Privacy Shield.

Information about the appropriate or reasonable guarantees for the level of data protection with Google LLC, Twitter Inc., LinkedIn Inc. and YouTube LLC as data recipients and how to obtain a copy of these guarantees or where they are available, can for instance be requested from:

NRW.INVEST GmbH
Economic Development Agency
of the German State of North Rhine-Westphalia (NRW)
The Data Protection Officer
Völklinger Strasse 4
40219 Düsseldorf, Germany
datenschutz@nrwinvest.com

Our IT service providers have affiliates or subcontractors outside the EU who can access your data. The transfer uses the EU standard contract according to Commission Decision 2010/87/EU, the model of which can be found on the websites of the European Commissioner for Justice and in the Official Journal of the EU.


Your rights | You have the right to:

  • Access the personal data stored about you (Art. 15 GDPR)
  • Data portability (Art. 20 GDPR)
  • Rectification and completion of the data we have about you (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Objection to the processing of your data to safeguard our legitimate interests or the legitimate interests of third parties (Art. 21 GDPR) – You have the right, on the basis of reasons related to your particular situation, to object to processing of this kind at any time; this also applies to profiling based on these provisions within the meaning of Art. 4 (4) GDPR.
  • Objection to direct marketing – You have the right to object to the processing of your data for the purpose of direct marketing at any time without giving reasons.
  • Withdrawal of consent that has been given (Art. 7 GDPR) with future effect for:
  • Newsletters: you can cancel the storage and use of your e-mail address and your name for sending out newsletters at any time with future effect. In order to unsubscribe from our newsletter, you can for example use the unsubscribe link within the newsletter.

To exercise these rights, you can in particular contact us via

NRW.Global Business GmbH
Trade & Investment Agency
of the German State of North Rhine-Westphalia (NRW)
The Data Protection Officer
Völklinger Strasse 4
40219 Düsseldorf, Germany

datenschutz@nrwgloblabusiness.com

 


If you do not want data about your visit to our website to be recorded for the purpose of optimising our Internet offering, you can check here : "6. Cookies and tracking" in section "I. Your visit to our website"  to see how recording can be disabled.

You also have the right to make a complaint to a data protection supervisory authority.