Hitachi Zosen KRB AG
CH-9470 Buchs SG
We, the companies of the Hitachi Zosen Inova Group (HZI Group), take the protection of your personal data very seriously. We respect the privacy rights of individuals and we treat your personal data confidentially and in accordance with the statutory personal data protection regulations and our Data Protection Policy.
If you have any questions about our Data Protection Policy, you can always contact us.
This Privacy Notice informs you about how the companies of the HZI Group process your personal data. Personal data is all information that relates to an identified or identifiable natural person that is obtained in the context of an individual’s relationship with the HZI Group. Personal data include without limitation employment data, customer, partner, and supplier data.
This Privacy Notice applies to all companies of the HZI Group and their employees. It is applicable to all personal data, regardless of the way (“online” or “offline”, for example, through our online offerings, when recording or making a sales pitch) or through which information channels (such as telephone, e-mail, applications, social media or other corporate websites the HZI Group) we receive your personal data.
Data processing when visiting our website or our corporate presence on Social Media
We operate the websites www.hz-inova.com and www.hz-krb.com and use LinkedIn, Xing and YouTube for our corporate appearance. Some of our online offerings are restricted to specific users and registration is required. Our online offering is not aimed at children, consumers or the general public.
If you use the contact information on our website and contact us by e-mail, telephone, mail or via a contact form, the information provided by you (e.g. name, e-mail address, postal address, telephone number, company you work for, any other information you share with us) will be saved in order to answer your question or to process your request. We do so on grounds of legitimate interests, both in your interest – you have contacted us – and in our interest to provide satisfaction to all inquirers or, if necessary, to fulfill a contract with you or to perform pre-contractual action. We will only process your personal data for the purpose that our request dictates.
Depending on your request, your personal data can be stored in our Customer Relationship Management System, in our Supplier Portal (“SUMO”) or in other technical systems.
If you use a contact form, your personal data will be encrypted according to the current state of the art. You voluntarily provide us with your personal data, but only as much data is required as necessary (mandatory information is provided with an asterisk) to enable you to contact us. All other information is optional.
You may object to personal data processing for legitimate interests at any time by notifying us.
Transfer of personal data
We do not sell or otherwise disclose personal data except as described in our HZI Group Data Protection Policy. In sharing or transferring personal data within the HZI Group or third parties we observe the rules of our Data Protection Policy including the following: (a) we may transfer personal data to third parties hired to perform services on our behalf provided that these third parties use the personal data in accordance with our Data Protection Policy and our instructions; (b) we may transfer and/or store personal data in Countries which may have different data protection laws than the Country in which the personal data was provided. If we do so, we will transfer the personal data only for the legitimate purposes described in our Policy. We hereby expressly point this out, so that you are aware of the risks of such data transmission. You can revoke your consent at any time in the future.
Duration of personal data storage
We take steps to keep personal data only for as long as necessary for the purposes for which it is collected and used, and we delete or render it anonymous after such retention requirements have been met.
Hosting and other services
We use the services of authorized service providers in Switzerland, Germany, and England, which we use for the purposes of operating our online service. These have been carefully selected and commissioned by us. They are bound by our instructions and are regularly inspected.
When using our online offer, contact data, content data, usage data, meta and communication data are processed by us or our service providers on our behalf. This is done on the basis of our legitimate interests in the efficient and secure provision of the online offer, protection against misuse and other unauthorized use, on the basis of a service requested by you or in certain cases after your consent.
Collection of access data and log files
Every access to the server on which a service used by us is located (so-called server log files) is collected by us or our service provider. This includes the following data that is technically necessary to display our online offer and to ensure the stability and security of the website: the name of the website accessed, file, date and time of retrieval, amount of data transferred, successful retrieval message, browser type, and version, the user’s operating system, previously visited pages, access status / HTTP status code, IP address, and the requesting provider.
Log file information is stored for security reasons (for example, to investigate abusive or fraudulent activities) for a maximum of 7 days and then deleted. Logfile information beyond this period of time required for evidence purposes, such as for use as evidence before authorities or court for the illegal use of our web pages by the website user, are excluded until the final clarification of the respective incident of the deletion and can up to a final decision or judgment.
A transfer of the above-mentioned data to third parties does not take place unless it is necessary for the pursuit of our claims, for the fulfillment of the intended purpose or there is a legal obligation to do so.
Cookies, web beacons and other technical means
Cookies are small text files that are assigned and stored on your device to the browser you use, and that provide certain information to the body that sets the cookie. Cookies cannot run programs or transmit viruses to your device. They serve to make the internet offer more user-friendly and effective overall, which is in your interests as well as in ours.
For some cookies that are not indispensable for the technical storage or access to our online offer or that are not only used to enable the use of a service that you have expressly requested, but we will also ask for your consent before processing the data.
Our online offer uses the following types of cookies, the scope, and operation of which are explained below, and which are used either by us (first-party cookies) or by third-party providers (third-party cookies):
- Session cookies: these are automatically deleted after closing the browser. You save a so-called session ID, with which various requests from your browser can be assigned to the common session. This will allow your device to be recognized when you return to our website. The session cookies are deleted when you close the browser.
- Persistent cookies: these are automatically deleted after a specified period, which may differ depending on the cookie. You can still delete these cookies in the security settings of your browser at any time.
You can configure your browser settings yourself according to your wishes. For example, you can only decline to accept third-party cookies or all cookies. We would like to point out that in the latter case you may not be able to use all the features of our online offer. We recommend that you regularly delete your cookies and browser history manually.
Third-party cookies require consent. With these and cookies for marketing purposes, we will give you the opportunity to consent to this before processing data. You can revoke such consent at any time, whereby the processing of the data until the revocation of the consent is not affected.
Disclosure to third parties of data stored by cookies is done in order to process them according to their purpose. Sharing of aggregate statistics and information about unidentifiable users of our online offering and our other corporate appearances with companies of the HZI Group may be based on legitimate interests.
In order to display our online offer, in the language of your choice, we use automated processing to match the language settings of our online offer to your whereabouts. For this, we process your IP address, which gives information about your whereabouts.
Our e-mails / newsletters use web beacons. These are small, unrecognizable, embedded images or objects (such as clear gifs, pixel tags, and single-pixel gifs) that return information from you after opening the received email. In this way, we can make success measurements to build statistics for the popularity of our offer.
If you give us your consent, we will evaluate your user behavior accordingly. We will continue to store information about the browser you are using and the settings you have made in your operating system, as well as information about your internet connection that will allow you to reach our website. Through the newsletter sent to you, we receive among other things receipt notifications and read receipts as well as information about the links you clicked on in our newsletter. Through this data processing (success measurements), we would like to tailor our advertising approach to your interests and optimize our offers on our website for you.
Within our online offer, you have the opportunity to subscribe to our newsletter.
- The content of the newsletter: we send you newsletters, e-mails and other electronic notifications with advertising information (hereinafter “newsletter”) only with your consent. Our newsletters contain information about the services provided by HZI Group companies and companies [link to the group companies] themselves.
- Consent: the sending of the newsletter and the associated performance measurement is based on your consent.
- Credentials: to sign up for the newsletter, it is sufficient to provide your e-mail address. Optionally, you can enter a name for a personal address in the newsletter.
- Cancellation: you can stop receiving our newsletter at any time, i.e. you revoke your consent by sending an e-mail to email@example.com, by contacting the contact details provided in the imprint or by clicking on the unsubscribe link in the newsletter. As a result, you will incur no costs other than the transmission costs according to the basic rates. A corresponding link for the revocation can be found at the end of each newsletter.
- Storage after revocation: we can save the delivered e-mail addresses for up to three years in order to be able to provide evidence of previously given consent. The processing of this data is limited to the purposes of a possible defense against claims. An individual request for cancellation is possible at any time, provided that at the same time the former existence of consent is confirmed. Any other use of your data after withdrawal of your consent will only be made if you have expressly consented thereto or further processing is justified, about which we will inform you.
Other marketing measures by e-mail
If in connection with the sale of a product or service, we have received your e-mail address and you have not objected to its following use, we reserve the right to use your e-mail address for direct marketing of your own product or similar products. These marketing measures serve, after a balance of interests, our legitimate interests of a promotional address of our existing customers.
When collecting the e-mail address and every time we use it, we will clearly point out to you that you can object to the use at any time without incurring other than internet costs according to the basic rates.
These marketing measures by e-mail can be carried out by a commissioned service provider in Switzerland or Germany. For this purpose, we will forward your e-mail address to this provider. You can object to these marketing measures at any time by sending an e-mail to firstname.lastname@example.org, using the contact details provided in the imprint [link with imprint] or by clicking on the unsubscribe link in the e-mail. As a result, you will incur no costs other than costs according to the basic rates. A corresponding link for the objection can be found at the end of each such e-mail.
In order to be able to send you interesting offers about us, our products, services or events organized by us by post, we reserve the right to use your first and last name as well as your postal address for such advertising purposes. This customer approach by post serves, after a balance of interests, our legitimate interests of a promotional address of our customers.
You can object to the storage and use of your personal data for this purpose at any time by sending a message to email@example.com or by contacting the contact details provided in the imprint.
Our Candidate Data Protection Notice forming part of our Data Protection Policy describes the way in which the companies of the HZI Group handle and protect the personal data which the Group is provided access to in connection with its recruiting process.
Job Applications [“Current vacancies”] and “Jobmail”
Within our online offer “Current job offers” and our company presence on LinkedIn and Xing you have the opportunity to find out about current job offers and to apply for them. You can use the respective links on Xing, LinkedIn and on our website “Job Vacancies” and “Jobmail”. For this, we use services of Xing, LinkedIn and a commissioned service provider in Germany, which we use for the purposes of implementing the offer.
Applications – “Current vacancies”
If you apply for a vacancy via the “Job Opportunities” application form, the information provided by you (e.g. salutation, name, postal address, e-mail address, telephone number, work permit type, languages, how you found us, earliest entry, cover letter, and other information you provide us with) will be saved by us in order to process your application. We do this to carry out pre-contractual actions with you regarding possible employment.
If you send us sensitive data as part of your application, this is based on your express consent, which you at any time can revoke with effect for the future.
By using the application form, your personal data will be encrypted according to the current state of the art. You voluntarily give us your data when applying, whereby only as much data as necessary for the processing of your application is requested (mandatory information is provided with *). All other information is optional.
Please only use our application tool “Aktuelle Stellenangebote” for applications. Applications sent by e-mail or by post cannot be considered and will be returned.
If you are applying for a job within the HZI Group, for example in Switzerland, Germany or the United Kingdom, then the relevant Human Resources Department and the recruiting manager will be informed of your application, using secure transmission procedures. Such submission of your application is based on legitimate interests – both yours – you have applied to the respective position, as well as our interests in order to be able to process your application satisfactorily and to enable a company-wide application offer.
If you would like to be informed about current job advertisements, you have the option of registering with Jobmail.
• The content of Jobmail: we will send you newly published vacancies that match your search specifications (hereinafter “Jobmail”) only with your consent.
• Registration procedure and logging: so that nobody can register with an email address that is not their own, you will receive an e-mail after logging in to ask for confirmation of your registration. This confirmation is necessary to receive Jobmail. If the login is not confirmed within 7 days, the information is locked and automatically deleted afterward. Logins to Jobmail are logged to prove the login process according to the legal requirements. This includes the storage of the login and the confirmation time, as well as the IP address. Likewise, the changes to your stored data are logged.
• Credentials: to sign up for Jobmail, it is sufficient to provide your e-mail address. Optionally, you can provide additional information to tailor the search for newly published job offers to your needs.
• Cancellation: you can stop receiving Jobmail at any time, i.e. revoke your consent by sending an e-mail to [specify e-mail address], using the contact details provided in the imprint [link with imprint] or by clicking on the unsubscribe link in Jobmail. As a result, you will incur no costs other than the internet costs according to the basic rates. A corresponding link for the revocation can be found at the end of each job mail.
• Storage after revocation: we can save the revoked e-mail addresses for up to three years in order to be able to prove previously given consent. The processing of this data is limited to the purpose of a possible defense against claims. An individual cancellation request is possible at any time. At the same time, the former existence of consent is confirmed. Any other use of your data after withdrawal of your consent will only be made if you have expressly consented thereto or further processing is justified, about which we will inform you.
Our supplier portal SUMO
On our website, we offer the possibility for suppliers to register for our SUMO portal under the login.
Registering with SUMO requires that you and the company you work for are authorized to register with SUMO have a D & B DUNS® number (Data Universal Numbering System). This D & B DUNS® number is a “non-speaking” 9-digit number key for the worldwide and unambiguous identification of companies and can be purchased from Bisnode D & B Germany under the following link https://www.upik.de/en/. Bisnode D & B Germany develops the UPIK® online platform in consultation with the UPIK® partners. Through our membership of the UPIK® Identification System, we have access to the information stored there to help us make business decisions.
After entering the D & B DUNS® number of the company you are working for, you will receive an invitation e-mail to register with SUMO. For this, you enter your business e-mail address as well as a password, which you change after the first login according to the given information. After successful registration, you can use SUMO for the company you work for. Detailed information on using the SUMO portal can be found here: http://www.hz-inova.com/cms/en/home?page_id=5664
In addition to the information of the company, which would like to act as a supplier to us, your contact information such as the name, your position, business e-mail address and phone number are stored. The specification of your mobile number is optional. In addition, we store and process all communications with you through SUMO and information voluntarily provided through the SUMO Portal about you and the Company, such as requests or documents uploaded to SUMO.
The SUMO portal is available to suppliers who want to work for the HZI Group. The personal data processing in SUMO is done so that we can check whether the company qualifies as a possible supplier for us, as well as the successful execution of orders if a contractual relationship with a supplier is justified. You can object to your personal data processing based on legitimate interests at any time by notifying us of this or by requesting deletion from the SUMO Portal.
We will erase your personal data in the SUMO Portal, provided the storage is no longer required, the purpose of participating in SUMO has been rectified or you have objected to processing unless such storage is required or further processing is warranted.
If you have questions about the SUMO portal, you can contact us at any time.
We include maps from the Google Maps service provided by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA. This will allow us to show you an interactive map directly on the website so you can conveniently use the map feature. Just by visiting the website with Google Maps, Google receives the information that you have accessed the corresponding sub-page. In addition, further access data and log files are transmitted. This is done regardless of whether Google provides a user account that you are logged in to, or if there is no user account. When you’re logged in to Google, your data will be assigned directly to your account. If you do not wish to be associated with your profile on Google, you must log out before activating the card. Google stores your data like user profiles and uses them for purposes of advertising, market research and/or tailor-made website design. Such an evaluation is carried out in particular (even for users who are not logged in) in order to provide needs-based advertising and to inform other users of the social network about the activities of the users on this website. You have a right to object to the formation of these user profiles, and you must contact Google directly to exercise.
Google also processes personal information in the US and has submitted to the Swiss / EU-US Privacy Shield:
Companies of the HZI Group, such as Hitachi Zosen Inova BioMethan GmbH (“the company” in this section), may maintain a corporate presence on Twitter.
On this corporate presence on Twitter, the company can see all the information that visitors publicly and voluntarily provide to this corporate website by either liking posts or posting a comment. It also processes user data as long as it communicates with the company within the social network, e.g. writing posts on the online presence or sending messages.
In addition, Twitter will provide the company with statistical data of visitors to this company website on their Twitter admin account. This includes data to evaluate the interactions of visitors with our respective posts, follower demographics, and their origins. However, the company cannot view any personal data of the visitors, but only general data without any personal reference.
We have no influence on the collected data and data processing by Twitter. You have the right to object to the creation of these user profiles, which you must contact Twitter directly to exercise.
Data processing by Twitter after using a link on the company’s presence on Twitter takes place regardless of whether you have an account on Twitter and are logged in there. If you are logged in to Twitter, your data will be mapped directly to your Twitter account.
For more information on the purpose and scope of the data collection and its processing, please refer to Twitter. Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, United States
Twitter is subject to the Swiss / EU-US privacy shield.
Our website currently offers a link to our LinkedIn presence.
On our LinkedIn corporate presence, we can see all the information that visitors voluntarily provide by either liking one of our posts or posting a comment.
In addition, LinkedIn provides us with statistical information about visitors to our corporate website in our LinkedIn Admin account. This includes data to evaluate visitor interactions with our respective posts, follower demographics and their origins, as well as web traffic and activity on our corporate website. However, we cannot view any personal data of visitors, but only general data without any reference to persons.
We have no control over the collected data and data processing operations by LinkedIn. You have a right to object to the creation of these user profiles, which must contact LinkedIn directly to exercise.
Any data processing by LinkedIn after using a link on our website takes place regardless of whether you have an account on LinkedIn and are logged in there. When you are logged in to LinkedIn, your data will be mapped directly to your LinkedIn account.
LinkedIn has submitted to the Swiss / EU-US Privacy Shield:
Companies of the HZI Group, such as Hitachi Zosen Inova BioMethan GmbH (“the company” in this paragraph), may have a corporate presence on Xing. On this corporate presence on Xing, both the HZI Group and the company can see all the information that visitors volunteer by either liking one of the company’s posts or posting a comment. It also processes user data as long as it communicates with the company within the social network, e.g. writing posts on the online presence or sending messages.
In addition, Xing will provide the company with statistical information about visitors to the company’s Xing Admin account. This includes data to evaluate visitor interactions with their respective contributions, follower demographics and their origins, and internet traffic and activity on the corporate presence. However, the company cannot view any personal data of the visitors, but only general data without any personal reference.
The Company has no control over the data collection and data processing operations by Xing. You have the right to object to the creation of these user profiles, which must contact Xing directly to exercise.
Any data processing by Xing after using a link on the corporate presence is done regardless of whether you have an account with Xing and are logged in there. When you are logged in to Xing, your data will be mapped directly to your existing Xing account.
XING Luxembourg, XING S.á r.l., 9, Avenue Guillaume, 1651 Luxembourg, Luxembourg
The inclusion of YouTube videos or use of YouTube plugins
On the websites of the HZI Group companies, content is integrated via the video platform service YouTube or will be integrated in the future. This is done partly via software extensions (plugins). This serves the preservation of our legitimate interests in an optimal presentation of our offer.
YouTube is operated by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA (“Google”), which is why its privacy policies should be consulted for any questions regarding the inclusion of YouTube videos on our websites.
We have included YouTube videos in our online offering, which are stored on http://www.YouTube.com and are directly playable from our web pages. These are all included in the “extended privacy mode”, i.e. you do not transfer data about you as a user to YouTube if you are not playing the videos. Only when you play the videos will the data mentioned in the following paragraph be transmitted. We have no influence on this data transfer.
By visiting the website, YouTube is informed that you have accessed the corresponding sub-page of one of our websites. In addition, the data mentioned earlier in this declaration will be transmitted. This happens regardless of whether YouTube provides a user account that you are logged in to, or if there is no user account. When you’re logged in to YouTube, your data will be assigned directly to your account. If you do not wish to associate with your profile on YouTube, you must log out before activating the button. You have a right to object to the creation of these User Profiles, and you must comply with YouTube to exercise it.
For more information on the purpose and scope of your data collection and processing through YouTube: https://www.google.com/intl/en/policies/privacy.
Google also processes your personal data in the US and has submitted to the Swiss / EU-US Privacy Shield, see: https://www.privacyshield.gov/EU-US-Framework; the details of the same can be found under the following link:
Our online offer can include hyperlinks to external websites of other companies outside the HZI Group. This Privacy Notice does not extend to the websites of these other companies. When using these websites, the privacy statements of these companies must be observed as far as their data processing is concerned. Nevertheless, we check these websites at regular intervals in order to remove the link immediately in case of possible infringements. If you have any indications of possible infringements on the linked pages, we ask you to inform us so that we can prevent a possible link.
If you click on such links, your personal data may reach companies in countries outside Switzerland, the EU and the EEA which do not guarantee an adequate level of protection for the processing of personal data. Please remember, before you click on a link and trigger a possible transfer of your data.
Our online offer, as well as all online forms, are secured (https) and the data is transmitted using 128-bit SSL encryption.
As of June 2018