Data Protection

Data protection information

This information pursuant to Art. 13 ff. GDPR on data protection serves to fulfil our duty to provide information when collecting personal data on our website.
The protection of your privacy is of paramount importance to our company and we are committed to handling your personal data in a responsible and trustworthy manner. With the following data protection information, we would like to give you a better understanding of how we collect, use, protect and share your personal data when you visit our websites, use our offers via our website and manage our relationships with interested parties and customers.

1. Name and contact details of the controller
CIM med GmbH
Margot-Kalinke-Str. 9
Euro-Industriepark
80939 Munich / Germany
Phone: +49 89. 978 94 08-00
Email: info@cim-med.com

2. Contact details of the data protection officer
Holzhofer Consulting GmbH
Martin Holzhofer
Lochhamer Str. 31
82152 Planegg / Germany
Phone: +49 89. 1 25 01 56-00
Email: dsb-cim-med@holzhofer-consulting.de

3. Purposes for which the personal data is to be processed and the legal basis for processing

3.1. Collection of access data / server log files
For technical reasons, we process a limited amount of data (so-called connection data) each time you access the website. This data is technically necessary to establish and maintain a connection between your device and our servers. This data is processed in the main memory of the web server for the duration of the connection.
The following data or data categories may be collected:

  • IP address
  • Timestamp (date and time) of the retrieval
  • Notification of whether the retrieval was successful (via HTTP error code)
  • User agent (browser type and version used to access our website)

The IP address, timestamp, HTTP error code, and user agent are automatically logged when you access our website to ensure the functionality and security of our website. Furthermore, the logs are used to optimize the website. Your IP address is only processed in abbreviated form in the logs and is therefore anonymized. We cannot create user profiles with personal references using this data.

3.2. Cookies and similar technologies

3.2.1 General
This website partially uses so-called cookies and related technologies (e.g., scripts). Cookies do not cause any damage to your computer and do not contain viruses. Cookies are designed to make our service more user-friendly, effective, and secure. These are small text files that are stored on your device and saved by your browser, for example, to “remember” information about you, such as your language settings or login information. Some of these cookies are set by us and are referred to as first-party cookies. We also use third-party cookies and related technologies that originate from a domain other than the website you are visiting.

By selecting appropriate technical settings in your internet browser, you can be notified before cookies are set and decide individually whether to accept them, as well as prevent the storage of cookies and the transmission of the data they contain. Cookies that have already been saved can be deleted at any time. However, we would like to point out that you may not then be able to fully use all of the functions of this website.

The following links provide information on how to manage (including deactivate) cookies in the most important browsers:

We generally distinguish between the following categories:

  • Technically required cookies and related technologies (“Necessary”)
  • Statistical cookies and related technologies (“Statistics”)
  • Marketing cookies and related technologies (“Marketing”)
  • Functional cookies and related technologies (“Functional”)

Further information on the individual categories, as well as the option to reject each category (except for those that are technically required), can also be found in the “Privacy Settings”.

3.2.2. Technically Necessary Cookies and Similar Technologies
Most of the cookies we use are so-called “session cookies.” They are automatically deleted after your visit. Such cookies are technically necessary for the operation of the website and to provide the service requested by the user and therefore cannot be deactivated.

The storage of information in the end user’s terminal device or access to information is carried out in accordance with Section 25 (2) No. 2 of the Telemedia Act (TDDDG). The processing of personal data is based on our legitimate interest in ensuring the optimal functionality of the website and a user-friendly and effective design of our offering in accordance with Art. 6 (1) (f) GDPR. A balancing of interests was carried out and concluded that the processing is necessary to protect our legitimate interests and that these outweigh your interests, fundamental rights, and freedoms, which require the protection of personal data.

3.2.3 Cookies requiring consent, such as analysis and tracking cookies and similar technologies (e.g. tracking scripts)
The website also integrates third-party services such as advertising, marketing and analysis tools, as well as other third-party services (e.g. online video platforms). These are not technically necessary for the operation of the website, but serve, for example, to record the behaviour of the user, to create a user profile and to send them tailored advertising, or to enable an analysis of the use of our website (e.g. Google Analytics).
An overview of all third-party services integrated into the website, as well as detailed information on each of these services, can be found in section 10.

3.3 Processing when contacting us by email
If you contact us by email on your own initiative, we will only collect your personal data (name, email address, individual message) to the extent that you provide it. The data processing serves to process and respond to your contact request.

The legal basis for the processing of your data is our legitimate interest pursuant to Art. 6 (1) lit. f GDPR. A balancing of interests was carried out and concluded that the interests of the data subjects do not outweigh our interests in processing. In this case, we have a legitimate interest in responding to your enquiry, for which the processing of the data and data categories mentioned here is necessary.

If the purpose of the contact is to carry out pre-contractual measures (e.g. advice on purchase interest, preparation of an offer) or relates to a contract already concluded between the data subject and us, this data processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.

4. Automated decision-making, including profiling
CIM med GmbH does not engage in automated individual decision-making, including profiling, in accordance with Art. 22(1) and (4) GDPR.

5. Data transfer to a third country
Data transfers to countries outside the EU and the European Economic Area (‘third countries’) occur in the context of the administration, development and operation of IT systems. The transfer takes place only on the basis of:

  • An adequacy decision by the European Commission within the meaning of Art. 45 GDPR.
  • An approved certification mechanism pursuant to Art. 42 GDPR together with legally binding and enforceable obligations on the part of the controller or processor in the third country.
  • Standard data protection clauses adopted by the Commission in accordance with the examination procedure pursuant to Art. 93(2) GDPR.

Currently, personal data is transferred to the United States through the use of analysis and tracking tools in the following cases:

  • Transfer of data to Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, United States.
  • Transfer of data to LinkedIn Corp., 1000 W. Maude Avenue, Sunnyvale, CA 94085, United States.
  • CleanTalk Inc, 711 S Carson Street, suite 4, Carson City, NV, 89701, USA

Currently, personal data is transferred to the United Kingdom through the use of an interactive map service:

  • OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom

6. Categories of recipients of data and data sources

6.1 Categories of recipients of data
For the processing of personal data for the purposes stated here, we use the following categories of recipients as processors within the meaning of Art. 28 GDPR:

  • Providers of servers for the purpose of hosting our websites
  • IT service providers for maintaining our IT infrastructure
  • Providers of third-party services for interactive maps (OpenStreetMap)
  • Service providers for spam protection (Clean Talk)
  • Providers of marketing, analysis and other third-party services
  • (Google, LinkedIn, borlabs-cookie, WPML),
  • Other processors within the meaning of Art. 28 GDPR in the course of order processing

These service providers process information about you on our behalf and on the basis of our instructions and are contractually obliged to comply with the applicable data protection laws within the meaning of Art. 28 GDPR.

Your data will also be passed on if we are legally obliged to do so.

6.2 Data sources
In this case, we have received all data from you in connection with your use of our website.

7. Storage period and criteria for determining the duration
Personal data is generally only stored for as long as is necessary to fulfil the purposes stated here or as required by the retention periods specified by law. Once the respective purpose no longer applies or the retention periods have expired, the data will be deleted in accordance with the statutory provisions.

For advertising purposes, we store your data until you object to its use, revoke your consent or contact is no longer permitted by law. We store your other data for as long as we need it to fulfil the specific purpose (e.g. to fulfil or process a contract) and delete it once the purpose no longer applies.

In this case, all connection data in the web server’s memory is automatically deleted shortly after the end of the connection. The access logs are stored for 30 days. In the event that parts of the access logs are required for the purpose of preserving evidence, they are excluded from deletion until the respective incident has been finally clarified.

8. Information about your rights as a data subject
CIM med GmbH is responsible for processing your data, unless otherwise stated.

You can request information from us at any time (Art. 15 GDPR) about the data stored about you and its correction (Art. 16 GDPR) in the event of errors. Furthermore, you may request the restriction of processing (Art. 18 GDPR), the transferability (Art. 20 GDPR) of the data you have provided to us in a machine-readable format, or the erasure of your data (Art. 17 GDPR) – insofar as it is no longer required.

In addition, you have the right to object at any time to the use of your data based on public or legitimate interests (Art. 21 GDPR).

If we process your data on the basis of your consent, you can revoke this consent at any time with effect for the future (Art. 7 (3) GDPR). Upon receipt of your revocation, we will no longer process your data for the purposes specified in the consent.

If you wish to exercise your rights as a data subject, please send your request by email to marketing@cim-med.com or by post to:
CIM med GmbH
Margot-Kalinke-Str. 9
Euro-Industriepark
80939 Munich / Germany

9. Right to lodge a complaint with a supervisory authority
In addition, you can lodge a complaint with a supervisory authority at any time in accordance with Art. 77(1) GDPR. For us, this is generally the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, P.O. Box 1349, 91504 Ansbach, email: poststelle@lda.bayern.de, telephone: +49 (0) 981 180093-0.

Alternatively, you can contact your local supervisory authority.

10. Data protection information for all third-party services integrated into the website

Data protection information on the use of Google Fonts API/ gStatic API
External fonts such as Google Fonts and gStatic are used on this website to improve its visual appearance. These are services provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA (‘Google’).

These web fonts are integrated via a server call, usually a Google server in the USA. This establishes a connection with your device and transmits, among other things, which of our web pages you have visited to the server. Google also collects the IP address of your device’s browser. This data is not linked to your Google account.

Your data may be transferred to the USA. For the USA, there is an adequacy decision by the EU Commission within the meaning of Art. 46 (3) GDPR, which extends to the EU-US Data Privacy Framework (DPF). For data exports to recipients in the USA who are certified under the DPF, the level of data protection is therefore considered adequate. Google has certified itself under the DPF and is therefore committed to complying with European data protection principles.

The storage of and access to information in the end user’s terminal equipment is based on informed consent in accordance with Section 25 (1) TTDSG. The legal basis for the further processing of your personal data is your voluntary and informed consent in accordance with Art. 6 (1) (a) GDPR. You can give your consent via the consent banner.
Further information can be found at https://developers.google.com/fonts/faq or https://policies.google.com/?hl=en&gl=US.

Data protection notice regarding the use of Google Analytics
These websites use Google Analytics, a web analytics service provided by Google Inc. LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (‘Google’).

Google Analytics uses technologies such as cookies, web storage in the browser and tracking pixels, which enable an analysis of your use of the websites. The following information, among other things, may be collected:

  • Host name of the accessing computer (IP address)
  • Browser type/version
  • Operating system used
  • Referrer URL (the previously visited page)
  • Click path
  • Date and time of the server request
  • Location data
  • Purchasing activities

Your data may be linked by Google to other data, such as your search history, your personal accounts, your usage data from other devices and all other data that Google has about you.

The storage period for data generated by Google Analytics is 14 months. After this period, all data is automatically deleted. We have also added the code ‘anonymizeIP’ to Google Analytics on these websites.

The data generated about your use of the websites is usually transferred to a Google server in the USA and stored there. For the USA, there is an adequacy decision by the EU Commission within the meaning of Art. 45 (3) GDPR, which extends to the EU-US Data Privacy Framework (DPF). For data exports to recipients in the USA who are certified under the DPF, the level of data protection is therefore considered adequate. Google has certified itself under the DPF and is thus committed to complying with European data protection principles.

The data processing serves the purpose of analysing these websites and their visitors, as well as for marketing and advertising purposes. On behalf of the operator of these websites, Google will therefore use this information to evaluate your use of the websites, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator. You may refuse the use of cookies by selecting the appropriate settings on your browser; however, please note that if you do this, you may not be able to use the full functionality of this website.

You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en

The storage of and access to information in the end user’s terminal equipment is based on informed consent in accordance with Section 25 (1) TDDDG. The legal basis for the further processing of your personal data is your voluntary and informed consent in accordance with Art. 6 (1) (a) GDPR. You can give your consent via the consent banner.

Further information on the handling of user data in Google Analytics can be found at the following links:
https://support.google.com/analytics/answer/6004245?hl=en
https://marketingplatform.google.com/about/analytics/terms/us/?utm_source=chatgpt.com
https://policies.google.com/?hl=en

Privacy notice regarding the use of OpenStreetMap
This website uses the open source map service provided by OpenStreetMap (OSM). OSM is used to provide an interactive map on our website that shows you how to find and reach us. This service enables us to present our website in an appealing way by loading map material from an external server. The provider is the OpenStreetMap Foundation (OSMF), St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, UK.

When you visit a website that incorporates OSM, your IP address and other information (e.g. your interactions with the digital map, device type, browser data, operating system, timestamp) are forwarded to OSMF. OSM may store cookies in your browser or use similar detection technologies for this purpose. The IP address and other user data are usually deleted after 180 days.

In addition, your location may be recorded if you have allowed this in your device settings, e.g. on your mobile phone. We have no influence on this data transfer.
The storage of and access to information in the end user’s terminal equipment is based on informed consent in accordance with Section 25 (1) TDDDG. The legal basis for the further processing of your personal data is your voluntary and informed consent in accordance with Art. 6 (1) (a) GDPR. You can give your consent via the consent banner.
For details, please refer to the OpenStreetMap privacy policy at: https://wiki.osmfoundation.org/wiki/Privacy_Policy

Privacy notice regarding the use of CleanTalk
This website uses anti-spam plugins from CleanTalk. The provider is CleanTalk Inc, 711 S Carson Street, suite 4, Carson City, NV, 89701, USA (hereinafter referred to as ‘CleanTalk’).

CleanTalk serves to protect our website from spam activities (e.g. preventing unwanted advertising, unwanted messages or comments). For this purpose, CleanTalk collects various personal data such as IP address, email address, nickname of the message sender, information about the JavaScript technology in the sender’s browser and the texts entered. This information is transferred to a CleanTalk server in the EU and stored there. For security reasons and as protection against spam, your data is processed in the CleanTalk Cloud Service and stored in log files for a maximum of 31 days. After the aforementioned period has expired, this data is completely deleted. The use of CleanTalk is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in protecting its website from spam activities as effectively as possible. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device within the meaning of the TDDDG. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here: https://cleantalk.org/my/session?back_url=profile#scc_agreement.

Order processing
We have concluded an order processing agreement (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed in accordance with our instructions and in compliance with the GDPR.

Media Center
Configurator