+49 7161 4016170  ·  info@flexq-connectors.com
Downloads

Legal

Privacy policy

Last updated: 09/2026

Privacy policy

This privacy policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter "data") within our online offering and the associated websites, functions and content, as well as external online presences such as our social media profiles (hereinafter collectively "online offering"). With regard to the terms used, such as "processing" or "controller", we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

Controller

baha-Tools GmbH
represented by the managing director Dipl.-Ing. Aydin Hanedar
Holzheimer Straße 8
73037 Göppingen, Germany
Phone: +49 7161 4016170
E-mail: info@flexq-connectors.com

Types of data processed

Master data · contact data · content data · contract data · usage data · meta/communication data

Processing of special categories of data (Art. 9 (1) GDPR): no special categories of data are processed.

Categories of data subjects

Customers, prospects, visitors and users of the online offering, business partners. Hereinafter we also refer to the data subjects collectively as "users".

Purpose of processing

Provision of the online offering, its content and functions · performance of contractual services, service and customer care · answering contact enquiries and communicating with users · marketing, advertising and market research.

1. Terms used

1.1. "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

1.2. "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.

1.3. "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

2. Relevant legal bases

In accordance with Art. 13 GDPR, we inform you of the legal bases of our data processing. If the legal basis is not stated in the privacy policy, the following applies: the legal basis for obtaining consent is Art. 6 (1) (a) and Art. 7 GDPR; the legal basis for processing to provide our services and carry out contractual measures and to answer enquiries is Art. 6 (1) (b) GDPR; the legal basis for processing to fulfil our legal obligations is Art. 6 (1) (c) GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6 (1) (f) GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) (d) GDPR serves as the legal basis.

3. Changes and updates to the privacy policy

Please check the content of our privacy policy regularly. We adapt the privacy policy as soon as changes to our data processing make this necessary. We will inform you as soon as the changes require action on your part (e.g. consent) or other individual notification.

4. Security measures

4.1. In accordance with Art. 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. These include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data as well as access to, input, disclosure, securing the availability and separation of the data. We have also established procedures to ensure that data subjects' rights are exercised, data is deleted and threats to the data are responded to. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).

4.2. The security measures include in particular the encrypted transmission of data between your browser and our server.

5. Disclosure and transfer of data

5.1. If, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transfer it to them or otherwise grant them access to the data, this is done only on the basis of a statutory permission, your consent, a legal obligation or our legitimate interests (e.g. when using agents, hosting providers, tax, business and legal advisers).

5.2. If we commission third parties to process data on the basis of a so-called "data processing agreement", this is done on the basis of Art. 28 GDPR.

6. Transfers to third countries

If we process data in a third country (outside the EU/EEA) or this happens in the context of using third-party services, this only takes place if it is necessary to fulfil our (pre-)contractual obligations, on the basis of your consent, a legal obligation or our legitimate interests, and only subject to the special requirements of Art. 44 et seq. GDPR (e.g. recognised level of data protection or standard contractual clauses).

7. Rights of data subjects

7.1. You have the right to request confirmation as to whether data concerning you is being processed, and to access, further information and a copy of the data in accordance with Art. 15 GDPR.

7.2. In accordance with Art. 16 GDPR, you have the right to request the completion or rectification of data concerning you.

7.3. In accordance with Art. 17 GDPR, you have the right to request the immediate deletion of your data or, alternatively, in accordance with Art. 18 GDPR, a restriction of processing.

7.4. You have the right to receive the data you have provided in accordance with Art. 20 GDPR and to request its transfer to other controllers.

7.5. In accordance with Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.

8. Widerrufsrecht

You have the right to withdraw consent given in accordance with Art. 7 (3) GDPR with effect for the future.

9. Widerspruchsrecht

You can object to the future processing of data concerning you in accordance with Art. 21 GDPR at any time, in particular to processing for direct marketing purposes.

10. Cookies and right to object to direct marketing

10.1. "Cookies" are small files stored on users' computers. "Session cookies" are deleted after a user leaves the online offering and closes the browser; "permanent" cookies remain stored afterwards. "Third-party cookies" come from providers other than the operator of the online offering.

10.2. We do not use cookies for advertising or analytics purposes. If users generally do not want cookies to be stored, they can deactivate the corresponding option in their browser settings; this may restrict functionality.

10.3. A general objection to cookies for online marketing purposes can be aboutads.info/choices or youronlinechoices.com declared via these services.

10.4. Our website does not use cookies for advertising or analytics purposes. For the enquiry basket we use your browser's local storage. It stores the selected items, your entries for reference, requested delivery date and note and, after your first submission, your contact details (company, contact person, e-mail, phone) so that you do not have to enter them again. This data remains on your device and is only transmitted to us when you send an enquiry. You can delete it at any time in your browser settings. The storage is strictly necessary for the function you requested (Section 25 (2) No. 2 TDDDG).

11. Deletion of data

11.1. The data we process is deleted or its processing restricted in accordance with Art. 17 and 18 GDPR as soon as it is no longer required for its intended purpose and no statutory retention obligations prevent deletion.

11.2. Germany: retention in particular for 6 years in accordance with Section 257 (1) HGB and 10 years in accordance with Section 147 (1) AO.

11.3. Austria: retention in particular for 7 years in accordance with Section 132 (1) BAO, 22 years for real-estate-related documents, 10 years for electronically supplied services (Mini One Stop Shop).

12. Contact and customer service

12.1. When you contact us (form or e-mail), we process the information to handle the enquiry in accordance with Art. 6 (1) (b) GDPR.

12.2. The information may be stored in our CRM system or a comparable enquiry management system.

12.3. We delete enquiries as soon as they are no longer required; the necessity is reviewed every two years. We store enquiries from customers with a customer account permanently.

12.4. Enquiry basket: The enquiry basket allows you to compile items and send them to us as an enquiry. You provide your company and e-mail address and, optionally, contact person, phone number, message, reference, requested delivery date and note, together with the selected items. The information is transmitted to our server in encrypted form and forwarded from there to us as an e-mail with a PDF overview of the items. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) and your consent pursuant to Art. 6 (1) (a) GDPR.

12.5. To protect against abusive and automated requests, our server briefly stores a checksum of your IP address together with the times of your requests. Requests older than ten minutes are no longer taken into account. The legal basis is our legitimate interest in the secure operation of the website (Art. 6 (1) (f) GDPR).

12.6. The "Share link" function lets you pass on your enquiry list as a link or QR code. The link contains only the items as well as reference, delivery date and note, but no contact details, and is not transmitted to us.

12.7. For our e-mail communication we use Microsoft 365 of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Enquiries by e-mail or via our forms are stored and processed there. A data processing agreement pursuant to Art. 28 GDPR is in place with Microsoft. A transfer to Microsoft Corporation in the USA cannot be ruled out; Microsoft is certified under the EU-US Data Privacy Framework.

13. Collection of access data and log files

13.1. On the basis of our legitimate interests in accordance with Art. 6 (1) (f) GDPR, we collect data on every access to the server (server log files): page accessed, file, date and time, amount of data transferred, success message, browser type, operating system, referrer URL, IP address and requesting provider.

13.2. For security reasons, log file information is stored for a maximum of seven days and then deleted unless required for evidentiary purposes.

13.3. Hosting: Our website is operated by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. Processing takes place in data centres within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS.

14. Online presence on social media

14.1. On the basis of our legitimate interests in accordance with Art. 6 (1) (f) GDPR, we maintain online presences on social networks in order to communicate with customers, prospects and users. The terms and conditions and data processing policies of the respective operators apply.

14.2. Unless otherwise stated, we process users' data if they communicate with us within the social networks.

15. Communication by post, e-mail, fax or phone

15.1. For business transactions and marketing, we use means of distance communication such as post, telephone or e-mail and process master, address, contact and contract data in doing so.

15.2. Processing is based on Art. 6 (1) (a), Art. 7 GDPR or Art. 6 (1) (f) GDPR in conjunction with statutory requirements for advertising communication. Contact is only made with consent or within the scope of statutory permissions.

16. Newsletter

16.1. The following information explains the content of our newsletter, the sign-up, dispatch and analysis procedures, and your rights to object.

16.2. We only send newsletters with the recipients' consent or statutory permission, containing information about our products, offers, promotions and our company.

16.3. Sign-up uses the double opt-in procedure; the time of sign-up and confirmation and the IP address are logged.

16.4. The dispatch service provider is "Zoho Campaigns" of Zoho Corporation GmbH, Il Hagen 7, 45127 Essen, Germany. The data is stored in Zoho data centres within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with Zoho. Further information: zoho.com/de/privacy.html.

16.5. The dispatch service provider may use the data in pseudonymised form to optimise its own services, but not to contact the recipients itself or pass the data on to third parties.

16.6. An e-mail address is sufficient for signing up; optionally we ask for a name so that we can address you personally.

16.7. Newsletters contain a "web beacon" for measuring success (opens, clicks, technical data, IP address, time) in order to improve the services and adapt the content.

16.8. Germany: dispatch and success measurement are based on Art. 6 (1) (a), Art. 7 GDPR in conjunction with Section 7 (2) No. 3 UWG or Section 7 (3) UWG.

16.9. Austria: in accordance with Section 107 (2) or (2) and (3) TKG.

16.10. Logging is based on our legitimate interests in accordance with Art. 6 (1) (f) GDPR to prove consent.

16.11. Newsletter recipients can unsubscribe at any time via a link at the end of each newsletter. Unsubscribed e-mail addresses may be stored for up to three years for evidentiary purposes.

16.12. When you sign up via our form, your e-mail address is transmitted directly to Zoho Campaigns; Zoho then sends you the e-mail with the confirmation link. For control purposes we also receive a notification containing your e-mail address. To prevent misuse, our server briefly stores a checksum of your IP address (see 12.5).

17. Integration of third-party services and content

17.1. On the basis of our legitimate interests pursuant to Art. 6 (1) (f) GDPR, we use third-party services to present our website in a consistent and appealing way. This requires the third-party providers to receive the users' IP address.

17.2. Fonts: We use "Adobe Fonts" of Adobe Systems Software Ireland Limited, 4–6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. When you open our pages, your browser loads the fonts from Adobe servers; in doing so, your IP address is transmitted to Adobe. According to Adobe, no cookies are set. A transfer to Adobe Inc. in the USA is possible; Adobe is certified under the EU-US Data Privacy Framework. Further information: adobe.com/de/privacy/policies/adobe-fonts.html.

17.3. Links to social networks (LinkedIn, Instagram, Facebook, YouTube) are simple links. Data is only transmitted to the respective provider when you click on such a link.