Vossloh connect - Privacy Policy

1. Introduction

Welcome to Vossloh connect ("Platform"), a product of Vossloh AG ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and protect your Personal Data through your use of the Platform. It is important to us that you understand how your data is handled and your rights concerning it. 

This Privacy Policy applies to  

(1) our business partners (“Partners”, “you”, “your”) who are using the Platform to provide “Partner Services” to their customers (“End Users”) as defined in the Partnership Platform Agreement with us; and  

(2) to a limited scope - to End Users (“you”, “your”) who are using the Platform to receive the Partner Services.  

Where this Privacy Policy does not explicitly distinguish between Partners and End Users but merely addresses “you” or “your”, this is supposed to likewise refer to Partners as well as End Users. 

Please note that this Privacy Policy only applies to you as an End User in the context of our processing of your Personal Data for using, improving and innovating the Platform. This Privacy Policy does not apply to the collection and processing of End Users’ Personal Data in the context of the provision of Partner Services by the Partners to you as End Users. If you want to learn more about how the Partners process your Personal Data in the context of the Partner Services, please visit the Privacy Policy of the relevant Partner. 

2. Data Controller

Vossloh AG  acts as the data controller responsible for Personal Data under the EU General Data Protection Regulation (“GDPR”) for the Platform Services.  

If you have any questions about this Privacy Policy or our privacy practices, please contact our data protection officer (“DPO”) using the following contact details: 

Data Protection Officer of the Vossloh Aktiengesellschaft 

Thomas Quietmeyer  

Datenschutzbeauftragter für die Vossloh Aktiengesellschaft 

Vosslohstraße 4 

D-58791 Werdohl 

datenschutzbeauftragter@vossloh.com 

3. Information We Collect

“Personal Data” means any information about an individual from which that person can be identified. 

We may collect and process the following types of Personal Data about you: 

  • Contact Information: Name, email address. 

  • Account Information: Usernames, passwords, and other security-related information. 

  • Usage Data: Information about how you use our Platform, including log data, preferences, and actions taken on the Platform. 

  • Communication Data: Records of your correspondence with us, including emails and messages. 

  • 2 factor authentication mean : phone model and OS version 

We use cookies solely for the purpose of maintaining your authentication session when you use the Vossloh connect Platform. These cookies are essential for ensuring that you can securely access and navigate our services. You have the option to manage or disable these cookies in your browser settings, but please note that doing so may impact the functionality and security of the Platform. For more information on how we use cookies and your cookie management options, please refer to our Cookie Policy. 

4. Purposes for Which We Use Your Personal Data

We process your Personal Data for the following purposes: 

  • Personal Data pertaining to Partners: 

  • Providing Services: To deliver and maintain our Platform and its features. 

  • Communication: To respond to your inquiries, provide support, and send important updates. 

  • Analytics: To analyze platform usage patterns, improve user experience, and enhance our services. 

  • Legal Compliance: To fulfill our legal obligations and protect our rights. 

  • Marketing: With your consent, to send promotional materials and updates about our services. 

 

We do not process your Personal Data for profiling or automated-decision making purposes. 

5. Legal Basis for Processing

Our processing of your Personal Data is based on various legal grounds, depending on the specific purposes for which we process it. 

  • Personal Data pertaining to Partners: 

  • If we process your Personal Data to provide our services to you and to communicate with you, we do this based on the performance of our contract with you (Art. 6 para. 1 lit. b GDPR). 

  • Our processing of your Personal Data for legal compliance purposes is based on Art. 6 para. 1 lit. c GDPR. 

  • If we process your usage data for analytics purposes, such processing is based on our legitimate interests to improve and innovate the Platform (Art. 6 para. 1 lit. f GDPR). 

  • We only process your contact information for marketing purposes if we have obtained your prior consent for this (Art. 6 para. 1 lit. a GDPR). 

  • Personal Data pertaining to End Users: 

  • If we process your Personal Data to provide our services to you and to communicate with you, we do this based on the performance of our contract with you (Art. 6 para. 1 lit. b GDPR). 

  • Our processing of your Personal Data for legal compliance purposes is based on Art. 6 para. 1 lit. c GDPR. 

  • If we process your usage data for analytics purposes, such processing is based on our legitimate interests to improve and innovate the Platform (Art. 6 para. 1 lit. f GDPR). 

6. Data Sharing

We may share your Personal Data with: 

  • IT Service Providers: Third-party IT vendors who help us provide the Platform. 

  • Business Partners: In case of collaborations or partnerships related to our services. 

  • Legal Authorities: To comply with legal requirements and protect our rights. 

  • Affiliates: In the context of corporate reorganization or restructuring. 

7. International Transfers

We do not transfer your Personal Data outside the EU. 

8. Data Retention

We will retain your Personal Data for as long as is reasonably necessary to fulfil the purposes we collected it for and/or for as long as we have contractual or legal obligations or legitimate interests (e.g., to provide a service you have requested, to comply with legal obligations to retain data or to enforce legal claims). 

9. Your Rights

You have the right to: 

- Access: Request access to the Personal Data we hold about you. 

- Rectification: Request corrections to inaccurate or incomplete Personal Data. 

- Erasure: Request deletion of your Personal Data under certain conditions. 

- Restriction: Request a restriction on the processing of your Personal Data under certain circumstances. 

- Data Portability: Receive a copy of your Personal Data in a structured, machine-readable format. 

- Objection: Object to processing based on legitimate interests. If you object to our processing based on legitimate interest, we will no longer process your Personal Data for the relevant purposes unless we have compelling legitimate grounds for such processing or where the processing is otherwise required for the establishment, exercise, or defence of legal claims. 

- Withdraw Consent: If processing is based on your consent, you can withdraw it at any time. 

You also have the right to file a complaint with a supervisory authority. We would, however, appreciate the chance to deal with your concerns before you approach the supervisory authority, so please contact us in the first instance. 

10. Data Security

We implement appropriate technical and organizational measures to safeguard your data against unauthorized access, disclosure, or alteration. 

11. Updates to the Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices. We will notify you of any material changes.