Privacy Policy

As of August 2026

This Privacy Policy explains what personal data is processed when you visit our website or contact us.

Minimizing Data Usage on Our Website

Our website is intentionally designed to minimize data collection. When you visit our site for informational purposes only, we do not collect any information such as your name, contact information, or other details you actively provide. We do not use analytics or marketing services, do not create user profiles, and do not track your behavior across different pages or visits.

When you visit the website, only the connection data technically necessary for the connection between your browser and our web server is transmitted. This may include, in particular, the IP address, the date and time of the visit, the requested page or file, technical information about the browser and operating system, and the transmission status.

This data is processed solely for the purpose of ensuring the technical operation of the website and protecting it from errors, misuse, and attacks. It is not analyzed for advertising purposes and is not used to create visitor profiles. IP addresses are stored in the regular server log files only in anonymized form.

We process other personal data only if you contact us yourself or submit an application to us.

1. Data Controller

Seifert Kunststoff GmbH
35½ Max-Eyth-Straße
89231 Neu-Ulm
Germany

Phone:+49 (0)731 9774430
Email:info@seifert-kunststoff.de

2. Visiting Our Website

When you visit our website, data is transferred between your browser and our web server for technical reasons. In particular, the following data may be processed:

  • Date and time of access,
  • page or file accessed,
  • amount of data transferred,
  • HTTP status code,
  • the previously visited page, provided that this information is transmitted by the browser,
  • Browser type, browser version, and operating system, as well as
  • anonymized IP address.

Data is processed to provide the website from a technical standpoint, to ensure its stability and security, and to detect technical errors and attacks.

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring that our website is provided in a secure, stable, and fully functional manner.

Hosting and Server Log Files

Our website is hosted on a managed server. The server infrastructure is provided by Hetzner Online GmbH, which is based in Germany. Hosting and technical maintenance are handled by IT service providers we have contracted.

In the standard Apache access and error log files, IP addresses are anonymized before being stored, in accordance with the hosting provider’s default configuration. These log files are generally deleted after seven days.

3. Cookies and External Content

No cookies are set during normal public visits to our website. We do not use either local storage or session storage to store information on your device.

We do not use any analytics or marketing services. Content such as fonts, scripts, images, or videos is not loaded from external platforms.

4. Website Protection by Shield Security

To protect our website from unauthorized access, malware, automated attacks, and other security risks, we use the security software Shield Security.

General logging of all website visits via Shield Security's request logging is disabled. However, in the event of security-related incidents, the following data in particular may be processed:

  • IP address,
  • Date and time of the event,
  • path called,
  • Browser and device information,
  • Type of security incident detected, as well as
  • Additional technical information about the respective process.

Data processing is carried out on the basis of Article 6(1)(f) of the GDPR. Our legitimate interest is to protect our website, our IT systems, and the data processed through them from attacks, misuse, and unauthorized access.

The retention period depends on the significance of the respective security event. Standard events are generally stored for up to 30 days, warning and security events for up to 180 days, and events of particular security relevance—such as IP or login blocks—for up to 730 days. Data is stored for a longer period only if it is necessary to investigate or prevent a specific security incident or to assert, exercise, or defend legal claims.

Shield Security is provided by Fernleaf Systems Limited, based in the United Kingdom. As part of the automatically active ShieldNET security network, IP addresses and associated security information may be transmitted in the event of access attempts classified as malicious or security-related. This processing is intended to identify known sources of attacks, fend off attacks, and protect connected websites from malicious access.

5. Contact via email or phone

When you contact us by email or phone, we process the data you provide, such as your name, contact information, the content of your message, and, if applicable, any other information you submit.

Your information will be processed in order to handle and respond to your inquiry.

If your inquiry relates to the initiation or performance of a contract, the legal basis is Article 6(1)(b) of the GDPR. For all other inquiries, processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the proper handling of business and general inquiries.

We may use email, telecommunications, and IT service providers contracted by us to handle the technical aspects of communication.

The data will be deleted as soon as your inquiry has been fully processed and there are no legal retention requirements or other legitimate reasons for further storage. If a business relationship results from your inquiry, the necessary data will be stored for the duration of that relationship and in accordance with the statutory retention periods.

6. Applications

If you apply for a position with us via email, we will process the data you provide for the purpose of conducting the application process. This may include, in particular, your contact and personal information, your resume, certificates, proof of qualifications, and other application documents.

The legal basis for the processing is Section 26(1), first sentence, of the Federal Data Protection Act (BDSG). The processing is carried out to the extent necessary for the decision regarding the establishment of an employment relationship.

To the extent that application materials contain special categories of personal data as defined in Article 9(1) of the GDPR and their processing is necessary for the application process, the processing is based on Section 26(3) of the Federal Data Protection Act (BDSG) in conjunction with Article 9(2)(b) of the GDPR.

If an employment relationship is established, the data required for that relationship will be further processed and stored in accordance with applicable laws.

If an employment relationship is not established, application documents are generally deleted two months after notification of rejection. This does not apply if there are legitimate interests that preclude deletion. Such an interest may, in particular, consist in the retention of documents for the purpose of asserting, exercising, or defending legal claims, for example, in proceedings under the General Equal Treatment Act. In this case, the data will be deleted as soon as the reason for further storage no longer applies.

7. Recipients and Data Processors

Within our company, only those individuals who need access to personal data in order to perform their duties are granted such access.

In addition, personal data may be transferred to service providers we use, in particular to:

  • Hosting and data center providers,
  • IT, security, and maintenance service providers,
  • Email and telecommunications service providers, as well as
  • Backup and data protection service providers.

To the extent that these service providers process personal data on our behalf, they are engaged on the basis of a data processing agreement in accordance with Article 28 of the GDPR. Any further disclosure will only take place if it is permitted or required by law.

8. Transfer to Third Countries

We primarily use service providers located within the European Union or the European Economic Area.

In connection with data backup or the security services used, service providers based in a country outside the European Union or the European Economic Area may be engaged. Such a transfer takes place only under the conditions set forth in Articles 44 through 49 of the GDPR, in particular on the basis of an adequacy decision by the European Commission or appropriate safeguards.

The European Commission has issued adequacy decisions for the United Kingdom and Switzerland.

9. Data Backup

Backup copies are created regularly to restore our website in the event of technical malfunctions, configuration errors, or security incidents.

Backup copies may contain personal data that was stored on the website or in security logs at the time the backup was created. The data contained in the backup copies is not analyzed for any other purpose. Access to this data is generally restricted to cases where it is necessary to restore the website.

Daily backups are retained for up to 14 days, weekly backups for up to six months, and annual archive copies for up to three years. If a backup is restored, the applicable retention periods are applied again to the restored data.

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the availability, integrity, and recoverability of our website and our IT systems.

10. Provision of Personal Data

You do not need to actively provide us with any personal data simply by visiting our website. The connection data required for technical purposes is transmitted automatically by your browser.

Providing data when contacting us or submitting a job application is always voluntary. However, without the information required to process your request or application, we may not be able to handle it.

11. Automated Decisions and Profiling

We do not engage in any fully automated decision-making, including profiling, as defined in Article 22 of the GDPR.

12. Your Rights

Subject to the legal requirements, you have the following rights in particular:

  • Right to access your processed personal data pursuant to Article 15 of the GDPR,
  • Right to have inaccurate data corrected or incomplete data completed in accordance with Article 16 of the GDPR,
  • Right to erasure under Article 17 of the GDPR,
  • Right to restriction of processing under Article 18 of the GDPR,
  • Right to data portability pursuant to Article 20 of the GDPR, as well as
  • Right to object under Article 21 of the GDPR.

Right to Object

If we process personal data pursuant to Article 6(1)(f) of the GDPR, you may object to such processing at any time on grounds relating to your particular situation.

We will no longer process the data in question unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

To exercise your rights, you may contact us using the contact information listed under “Data Controller.”

13. Right to File a Complaint with a Supervisory Authority

Under Article 77 of the GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.

The regulatory authority responsible for us is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany

Phone:+49 (0)981 180093-0
Website:www.lda.bayern.de

14. Changes to This Privacy Policy

We will update this Privacy Policy if there are changes to the procedures, services, or legal requirements we use. The version currently published on this website is the one that applies.

Contact

Get in touch with us – we look forward to hearing from you.

Our technically knowledgeable contacts will guide you from the initial contact through to production.