Privacy Policy
We are pleased that you are visiting our website. The protection of your personal data is important to us. Below, we inform you about which personal data we process when you use our website, for what purposes we process it, and what rights you have.
1. Controller
The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Thiele Metalltechnik GmbH
Baudirektor-Hahn-Straße 30
27472 Cuxhaven
Germany
Phone: +49 4721 7390
E-mail: info@tmt-cuxhaven.de
Represented by Managing Director Ralf Thiele.
2. General Information on Data Processing
We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications and Digital Services Data Protection Act (TDDDG).
Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, address, e-mail address, telephone number, IP address, and information concerning your use of our website.
3. Accessing Our Website and Server Log Files
Whenever you access our website, the web server automatically processes information transmitted by your browser to our server. This may include, in particular:
- IP address of the accessing device,
- date and time of access,
- pages and files accessed,
- referrer URL,
- browser type and browser version,
- operating system used,
- technical information concerning the browser and device environment.
The processing is carried out to make the website technically available, ensure its security and stability, detect errors, and protect the website against misuse and unauthorized access.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable, and technically reliable provision of our website.
Server log files are deleted as soon as they are no longer required for the purposes stated above, unless statutory retention obligations or the assertion, exercise, or defense of legal claims require longer storage.
4. Contact by E-mail, Telephone or Contact Form
If you contact us by e-mail, telephone, or via a contact form provided on our website, we process the personal data you provide to the extent necessary to process your inquiry.
This may include your name, contact details, the content of your inquiry, and any other information you voluntarily provide.
Depending on the nature of your inquiry, the processing is based on Art. 6(1)(b) GDPR if the processing is necessary for the performance of a contract or for taking steps prior to entering into a contract, or on Art. 6(1)(f) GDPR based on our legitimate interest in processing and responding to inquiries.
If you have given us your consent to process your data, the legal basis is Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future.
The data you provide will be deleted once your inquiry has been conclusively dealt with and provided that no statutory retention obligations or legitimate interests require further storage.
5. Cookies and Similar Technologies
Our website uses cookies and similar technologies. Cookies are small text files that may be stored on your device. Similar technologies may also be used to store information on your device or access information already stored on your device.
We distinguish between technically necessary technologies and technologies used, for example, for preferences, marketing, or the integration of external content.
5.1 Technically Necessary Cookies and Technologies
Technically necessary cookies and similar technologies may be used where they are required for the operation of the website, the provision of functions expressly requested by you, or the security of the website.
Our website uses, among other things, functions provided by WordPress, Polylang, and Wordfence. WordPress is used as the technical content management system. Polylang is used to provide and manage the different language versions of the website. Wordfence is used to protect the website and detect or prevent security-related access attempts.
According to the currently published cookie overview, the cookies wpEmojiSettingsSupports, wp-settings-*, wordpress_test_cookie, wordpress_logged_in_*, pll_language, and wfwaf-authcookie* are assigned to the functional or technical functions of the website.
Where the storage of information on your device or access to information already stored on your device is strictly necessary to provide a digital service expressly requested by you, no consent is required pursuant to Section 25(2) No. 2 TDDDG.
5.2 Cookie Consent Management
We use a consent management system to manage your cookie preferences. This may include cookies such as cmplz_functional, cmplz_preferences, cmplz_marketing, cmplz_consented_services, cmplz_policy_id, cmplz_statistics, and cmplz_banner-status.
These cookies are used in particular to store your consent decision and to manage the categories and services you have selected in accordance with your decision.
The processing associated with managing your consent is carried out to comply with data protection obligations and to document your consent decision.
5.3 Non-Essential Cookies and Technologies
For cookies and similar technologies that are not technically necessary, we generally obtain your consent before using them where legally required.
Consent is obtained through our cookie consent management system. You can make your selection and change or withdraw your consent at any time with effect for the future.
The legal basis for processing personal data in connection with non-essential cookies and similar technologies is generally Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
6. Google Maps
Google Maps may be embedded on our website to display maps and our company location.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For certain processing activities, companies affiliated with Google outside the European Economic Area may also be involved.
According to the currently published cookie overview, Google Maps is assigned to the marketing category. The Google Maps API listed there may process, in particular, the user’s IP address.
When Google Maps is used, Google may process technical information concerning the device used, the browser, the IP address, and use of the service. Google may also process information about how its services are used.
Google Maps is therefore only loaded or activated on our website where the required consent has been provided.
The legal basis for processing personal data in connection with the activation of Google Maps is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Further information on data processing by Google can be found in Google’s privacy information.
7. WordPress
Our website is based on the WordPress content management system. WordPress is used for the technical provision and administration of the website.
Technically necessary cookies and similar technologies may be used as part of the operation of the website. These serve in particular to ensure technical functionality, manage user preferences, and, where necessary, provide functions for logged-in users.
Where necessary, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website securely and reliably.
8. Polylang
We use Polylang to technically provide and manage the different language versions of our website.
The pll_language cookie may be used to store the language selected by you.
The processing is based on Art. 6(1)(f) GDPR insofar as storing the language preference is necessary to provide the website in a user-friendly manner.
9. Wordfence
We use Wordfence to protect our website against attacks, abusive access, and other security-related activities.
This may involve processing technical information about accessing devices and connections to the extent necessary to detect and prevent security threats. This may include IP addresses, access times, URLs accessed, and technical information concerning HTTP requests.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, our IT systems, and the data we process against attacks and misuse.
Wordfence is provided by Defiant Inc. Depending on the specific functions used, personal data may be processed as part of the website security services. Where personal data is transferred outside the European Union or the European Economic Area, such transfers are carried out in accordance with the applicable requirements of Art. 44 et seq. GDPR.
10. Social Media Content
The currently published cookie overview does not list any Facebook or Instagram cookies. If social media content or functions provided by third parties are nevertheless embedded on the website, their processing will only take place in accordance with the applicable data protection requirements.
If social media services are embedded in the future, this Privacy Policy will be updated accordingly and prior consent will be obtained where required.
11. SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, our website uses SSL/TLS encryption.
You can recognize an encrypted connection by the fact that the browser’s address bar begins with “https://” and, depending on your browser, a padlock symbol is displayed.
Encryption means that data you transmit generally cannot be read by unauthorized third parties during transmission.
12. Legal Bases for Processing
Depending on the specific processing activity, personal data is processed in particular on the basis of the following legal grounds:
- Art. 6(1)(a) GDPR: Consent of the data subject.
- Art. 6(1)(b) GDPR: Processing necessary for the performance of a contract or for taking steps prior to entering into a contract.
- Art. 6(1)(c) GDPR: Processing necessary for compliance with a legal obligation.
- Art. 6(1)(f) GDPR: Processing necessary for the purposes of legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
13. Recipients of Personal Data
Personal data is only disclosed where there is a legal basis for doing so.
As part of the technical operation of our website, personal data may be processed in particular by IT and hosting service providers, providers of security solutions, and providers of integrated third-party services.
Where we engage service providers as processors, processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR, where the statutory requirements for this are met.
14. Transfers to Third Countries
When using certain services, personal data may be processed by providers located outside the European Union or the European Economic Area.
Personal data is only transferred to a third country where the requirements of Art. 44 et seq. GDPR are met. This may include, in particular, an adequacy decision by the European Commission, appropriate safeguards, or, where legally permissible, explicit consent.
15. Storage Period
We generally store personal data only for as long as necessary for the respective processing purposes or as required by statutory retention obligations.
Once the respective purpose no longer applies, the data will be deleted unless statutory retention obligations or legitimate interests require further storage.
16. Your Rights as a Data Subject
Subject to the applicable statutory requirements, you have the following rights:
- Right of access pursuant to Art. 15 GDPR,
- Right to rectification pursuant to Art. 16 GDPR,
- Right to erasure pursuant to Art. 17 GDPR,
- Right to restriction of processing pursuant to Art. 18 GDPR,
- Right to data portability pursuant to Art. 20 GDPR,
- Right to object to certain processing activities pursuant to Art. 21 GDPR,
- Right to withdraw consent pursuant to Art. 7(3) GDPR.
If you withdraw your consent, the lawfulness of processing carried out prior to the withdrawal shall remain unaffected.
To exercise your rights, you may contact us at any time using the contact details provided above.
17. Right to Object
You have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data where such processing is based on Art. 6(1)(e) or (f) GDPR.
Where personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes.
18. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR.
The data protection supervisory authority responsible for non-public entities in Lower Saxony is:
The State Commissioner for Data Protection of Lower Saxony
Prinzenstraße 5
30159 Hannover
Germany
Phone: +49 511 120-4500
E-mail: poststelle@lfd.niedersachsen.de
19. Currency and Amendments to This Privacy Policy
We reserve the right to amend this Privacy Policy if this becomes necessary due to changes to our website, the services we use, legal requirements, or technological developments.
The version of this Privacy Policy published on our website at the time of your visit shall apply.
Last updated: September 18, 2026
