Privacy Policy

We are pleased that you are visiting our website and interested in what we have to offer. We want you to feel comfortable while browsing and not have to worry about the confidentiality of your data.
We are strongly committed to data protection and believe that transparency in handling your data is essential. That’s why we would like to inform you about which data we collect, for what purpose, and how you can exercise control over your data at any time.

Controller

The controller within the meaning of data protection law for the processing of personal data is:

Dr. Wack Holding GmbH & Co. KG
Untere Au 9
D-85107 Baar-Ebenhausen
Germany

Categories of Data, Purpose, and Legal Basis for Processing

You can of course visit our website without providing any personal information. Our privacy policy can be accessed via the link at the bottom of each page.

We only use your personal data in the context of your website visit for the operation and optimization of our site. For this purpose, we collect the IP address, various technical details of your device (e.g., operating system, browser used, etc.), and data related to the use of our website. This data is not stored beyond the statutory retention periods or the fulfillment of its purpose. Processing this data is necessary to ensure the functionality of the website. If you do not agree to this processing, we will unfortunately be unable to provide our online services.

We evaluate this information statistically to make the website experience more user-friendly for all visitors. This data is not linked to any personal data we may already have stored. The data collected in connection with your website use is deleted no later than 14 months after collection. In individual cases, retention may be extended for the purpose of asserting or defending legal claims or due to legal obligations.

The processing of personal data for the operation of the website and for network and information security is based on Article 6(1)(f) of the GDPR. There is no legal or contractual obligation for you to provide data when using our website. However, operating the website or responding to your inquiries is not possible without processing your data.

For further details on the specific data collected by individual services, please refer to the relevant sections of this privacy policy.

Recipients of the Data

Your data will not be disclosed to third parties unless there is a legal obligation to transmit the data. Such processing is carried out on the basis of Article 6(1)(c) GDPR in conjunction with the specific order or legal obligation to which we are subject in the individual case. According to Article 6(1)(c) GDPR, the processing of personal data is permitted if it is necessary for compliance with a legal obligation to which the controller is subject.

Categories of data recipients include public authorities in cases of legal obligation, data processors who process data collected online on our behalf, and, where applicable, joint controllers.

The following data processors may be involved:

Abacus Umantis AG
Ingolstadt Online Gmbh
Google Inc.
Meta Ireland
LinkedIn
Microsoft Corp.

Contact

When you fill out the contact form or contact us by email or phone, you provide us with personal data. We may collect the following types of data: name, email address, company name, and information necessary to create a personalized offer or to respond to your inquiry.

We use this data solely to respond to your specific request or inquiry and to provide the requested information. To protect your data, we use a recognized encryption method during transmission. We will retain your personal data for as long as necessary to fulfill the purposes described in this privacy notice. Statutory retention periods remain unaffected.

The legal basis for processing general inquiries is your consent in accordance with Article 6(1)(a) GDPR.
For inquiries related to contracts or pre-contractual measures, the legal basis is Article 6(1)(b) GDPR.
For inquiries concerning data protection matters, the legal basis is Article 6(1)(c) GDPR.
By submitting the form, you consent to the processing of your data.

Information Security

Do you have questions, suggestions for improvement, incidents, or events related to our information security objectives?
Feel free to contact our ISMS team at: isb@wackholding.com

Video Surveillance

Video surveillance is carried out for the purpose of building security and the protection of employees, as well as for the prevention of theft and burglary. The security of our premises and staff constitutes a legitimate interest. The legal basis for video surveillance is Article 6(1)(f) of the GDPR.

Recordings are made only in the event of suspicious activity. These recordings are retained for the period necessary to assert or defend legal claims.

Visitor Log

When you enter our premises as a visitor, we collect the following personal data in a visitor log: name, company, address, and the duration of your visit on our premises.

The legal basis for this processing is our legitimate interest in being able to trace who was present in our building at any given time in the event of security or other incidents (Article 6(1)(f) GDPR).

The personal data is retained for 30 days and then deleted.

Cookies

We use session cookies on our website. Below, we would like to briefly explain the purpose of these cookies. Cookies are small text snippets that we store on your device. Cookies do not execute any commands on your computer and therefore do not pose a security risk.

Session cookies store certain information while you browse our website. They are not stored permanently and are deleted once you leave the site.

The use of session cookies is based on Article 6(1)(f) of the GDPR. Operating the website is in the legitimate interest of the controller.

You can manage how your browser handles cookies, including rejecting them entirely or configuring your browser to delete them automatically on a regular basis. You can find detailed instructions on this in your browser settings or online.

Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics uses so-called “cookies”—text files that are stored on your device and enable an analysis of your use of the website.

The following data, among others, may be collected: IP address, time spent on the website, language, location, and the browser you are using. The analysis is carried out using an algorithm (machine learning) that evaluates your user behavior and can recognize you across multiple devices.

Your IP address is anonymized by default before being transmitted to Google.

We have also disabled the collection of precise location, position, and device data.
In addition, Google Signals has been disabled.

You can find more information on how Google uses this data here: https://policies.google.com/technologies/partner-sites

Data transfers to the USA are carried out on the basis of the EU-U.S. Data Privacy Framework.

Google Analytics is only used with your explicit consent. The legal basis for this processing is Article 6(1)(a) of the GDPR and Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).

You can withdraw your consent at any time by clicking “Cookie Settings” under the “Cookies” section and saving a new selection.

The data collected via Google Analytics is internally shared with and processed by our HR and Online Marketing departments.

Another recipient of the data is Abacus Umantis AG.

Your data will be deleted after 14 months.

Microsoft Clarity

We use Microsoft Clarity on our website, a service provided by Microsoft Corporation. Clarity anonymously analyzes the performance of our website. For example, it provides us with heatmaps that show which parts of our website are particularly popular, helping us to better tailor our site to the needs of our users. This is the purpose of the data processing.

Microsoft Clarity is only used if you have given your consent (Article 6(1)(a) GDPR). The storage period for the collected data is one year.

Microsoft processes the data strictly in accordance with our instructions and on our behalf. We have concluded a data processing agreement with Microsoft in accordance with legal requirements.

Xing

We operate a Xing account provided by XING SE, Dammtorstraße 30, 20354 Hamburg, Germany.

We use our Xing account to stay in contact with visitors and interested parties, build new connections, and share relevant information with our network. In doing so, we process the personal data you may provide when contacting us or sending us messages via Xing.

We also use Xing to reach out to potential employees.

The legal basis for this processing is our legitimate interest in modern communication and interaction with our network, as well as in recruiting new employees, pursuant to Article 6(1)(f) GDPR.

We store your data for as long as necessary to fulfill the respective purpose, and beyond that, only in accordance with legal retention obligations.

For information on how Xing itself processes personal data, please refer to Xing’s privacy policy at: https://privacy.xing.com/en/privacy-policy

Facebook Pixel

We use the so-called Facebook Pixel on our website.

This service is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (Meta).

When you visit a page on our website that contains a Facebook Pixel, your browser establishes a direct connection to Meta’s servers. The content of the Facebook Pixel is transmitted directly from Meta to your browser and embedded in the page.

By integrating the Facebook Pixel, Meta receives the information that your browser has accessed the corresponding page of our website—even if you do not have a profile or are not logged in. This information is transmitted directly from your browser to Meta’s server and stored there. If you are logged into your Meta account, your visit to our website can be directly linked to your profile.

The Facebook Pixel also transmits information about your actions on our website to Meta (for example, if you complete a purchase).

For more information about the purpose and scope of data collection, as well as Meta’s further processing and use of the data, and your rights and privacy settings, please see Meta’s privacy policy:
http://www.facebook.com/policy.php

Meta is certified under the EU-U.S. Data Privacy Framework.

The legal basis for this processing is your consent in accordance with Article 6(1)(a) GDPR.

Facebook/Instagram Account

We maintain profiles on Facebook and Instagram, both operated by Meta Platforms Inc., 1 Hacker Way, Menlo Park, California 94025, USA.

We have entered into a Controller Addendum with Meta regarding joint responsibility under the GDPR. This agreement defines which data processing operations are the responsibility of us and which are the responsibility of Meta when you visit our Facebook fan page. According to this agreement, Meta assumes primary responsibility under the GDPR for the processing of Insights data.

You can view the agreement here:
https://www.facebook.com/legal/terms/page_controller_addendum

You can manage your personal advertising preferences in your user account. To do so, log in at the following link:
https://www.facebook.com/settings?tab=ads

For more information about how Meta processes personal data, please refer to Meta’s privacy policy:
https://www.facebook.com/about/privacy

The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest lies in tailoring our content and posts to relevant audiences. Meta provides us with aggregated statistics that do not allow any conclusions to be drawn about individual users.

LinkedIn Pixel

We use the so-called LinkedIn Pixel on our website.

This service is provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

When you visit a page on our website that includes the LinkedIn Pixel, your browser automatically establishes a direct connection to LinkedIn’s servers. The content of the LinkedIn Pixel is transmitted directly from LinkedIn to your browser and embedded in the website.

Through this integration, LinkedIn is informed that your browser has accessed the corresponding page of our website, even if you do not have a LinkedIn profile or are not logged in. This information is sent directly from your browser to LinkedIn’s server and stored there. If you are logged into your LinkedIn account, your visit to our website can be directly linked to your profile.

Additionally, the LinkedIn Pixel transmits information about your interactions on our website to LinkedIn (e.g. if you complete a purchase).

For details on the scope and purpose of data collection, further processing and use of data by LinkedIn, and your rights and settings to protect your privacy, please refer to LinkedIn’s privacy policy:
https://www.linkedin.com/legal/privacy-policy

LinkedIn is certified under the EU-U.S. Data Privacy Framework.

The legal basis for processing is your consent in accordance with Article 6(1)(a) GDPR.

LinkedIn Account

We operate a LinkedIn account managed by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

To adjust your advertising preferences on LinkedIn, please use the following link:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out

We have entered into a Joint Controller Agreement with LinkedIn. This agreement specifies which data processing operations are the responsibility of LinkedIn and which are ours when you visit our LinkedIn page. According to this agreement, LinkedIn Ireland assumes primary responsibility under the GDPR for the processing of Insights data.

You can view the agreement here:
https://legal.linkedin.com/pages-joint-controller-addendum

For more information on how LinkedIn processes personal data, please see LinkedIn’s privacy policy:
https://www.linkedin.com/legal/privacy-policy

Your Rights Regarding the Processing of Your Personal Data

In accordance with the GDPR, you have various rights regarding the processing of your personal data. We would like to inform you of these rights below. Further details can be found in Articles 15 to 21 of the General Data Protection Regulation (GDPR) as well as Sections 32 to 37 of the German Federal Data Protection Act (BDSG).

You have the right to access the personal data we hold about you and the right to rectification of inaccurate data.

Under certain circumstances, you are also entitled to:

  • the erasure of your data (right to be forgotten),
  • the restriction of processing,
  • and the right to data portability.

If your data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object to this processing, including to profiling as defined in Article 21 GDPR.

Any consent you have given—particularly in the context of using this website—can be revoked at any time, without stating reasons, and with effect for the future.

All of the rights listed above under Articles 15 to 21 GDPR may be asserted informally, either by email or postal mail, addressed to the controller.

You also have the right to lodge a complaint with the competent data protection supervisory authority if you believe that the processing of your personal data violates applicable data protection law.
A list of supervisory authorities in Germany (including contact information) can be found at:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

If you have any questions regarding data protection, feel free to contact our external Data Protection Officer:

David Gabel
david.gabel@your-insider.com

General information about data protection and the processing of personal data is also available at: https://www.dsgvo-support.de

Privacy Notice for Our LinkedIn Page

We are committed to data protection and believe that transparency in how your data is handled is essential. Therefore, we would like to inform you about how we and LinkedIn process your personal data.

A joint controllership agreement pursuant to Article 26 GDPR exists between LinkedIn and us. This agreement is available at the following link:
https://legal.linkedin.com/pages-joint-controller-addendum

According to this agreement, LinkedIn assumes full responsibility for fulfilling data protection obligations related to LinkedIn Page Insights.

1. Name and Address of the Joint Controllers

a) LinkedIn Ireland Unlimited Company
Wilton Place, Dublin 2, Ireland
You can reach LinkedIn’s Data Protection Officer via this form:
https://www.linkedin.com/help/linkedin/ask/ppq

b) Dr. Wack Holding GmbH & Co. KG
Untere Au 9, 85107 Baar-Ebenhausen, Germany
Our external Data Protection Officer:
Email: david.gabel@your-insider.com

2. Categories of Data, Purposes and Legal Basis of Processing

a) Statistical Data (LinkedIn Page Insights)

We receive statistical data from LinkedIn about the usage of our LinkedIn page (e.g., number of likes, comments, shares, clicks, video views, conversion rate). These anonymized statistics are generated and provided by LinkedIn.
For more details, please refer to:
https://business.linkedin.com/de-de/marketing-solutions/reporting-analytics

The legal basis for processing this data is Article 6(1)(f) GDPR. Our legitimate interest lies in improving the relevance and reach of our content.

b) Interaction with Our LinkedIn Account

When you interact with our LinkedIn page (e.g., by liking, commenting, or messaging), we may gain access to your profile data (such as username, profile picture, and time of interaction). This data is only made available to us through your active engagement.

The legal basis for this is Article 6(1)(b) GDPR (performance of a contract or pre-contractual measures).

For processing activities carried out by LinkedIn, please refer to:
https://www.linkedin.com/legal/privacy-policy


3. Recipients of the Data

LinkedIn may share your data with third parties. We have no influence over this process.
Please refer to LinkedIn’s privacy policy for more information:
https://www.linkedin.com/legal/privacy-policy

We do not disclose your personal data unless there is a legal obligation to do so (Article 6(1)(c) GDPR). Potential recipients may include public authorities or processors acting on our behalf (e.g., hosting or analytics providers).


4. Storage Duration and Deletion

Details about data storage by LinkedIn can be found in their privacy policy.
We store personal data only as long as necessary to fulfill the purposes for which it was provided or as required by law. Once these purposes or retention periods have expired, the data will be deleted or anonymized.


5. Your Rights under the GDPR

In accordance with Articles 15 to 21 GDPR and Sections 32 to 37 of the German Federal Data Protection Act (BDSG), you have the following rights:

  • Right to access your data
  • Right to rectification of incorrect data
  • Right to erasure of data
  • Right to restriction of processing
  • Right to data portability
  • Right to object to data processing based on Article 6(1)(f) GDPR
  • Right to withdraw consent at any time with future effect

To exercise these rights, you may contact us informally by email or post using the contact details above.

You also have the right to lodge a complaint with the competent supervisory authority for data protection if you believe your data has been processed unlawfully. A list of data protection authorities and their contact details can be found at:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

If your inquiry relates to data processing carried out by LinkedIn (especially in connection with Page Insights), please contact LinkedIn directly using the contact options listed above. Alternatively, you may contact us, and we will forward your request to LinkedIn in accordance with our joint controllership agreement.

Privacy Overview
WACK GROUP

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.

Additional Cookies

This website uses the following additional cookies:

(List the cookies that you are using on the website here.)