Privacy Policy

1. Responsible person


The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws as well as other data protection regulations is:

Nessensohn GmbH

Steigäcker 6

D-88454 Hochdorf

Telephone: +49 7355 93389-0

Fax: +49 7355 93389-99

Email: info@nessensohn.com

Website: www.nessensohn.gmbh

Managing Directors authorized to represent the company: Alexandra Völkle, Olaf Nessensohn


2. Data Protection Contact Person


For questions regarding data protection, please contact:

Thomas Bucher

Email: datenschutz@nessensohn.com

We are not required to appoint a data protection officer and have not done so. The requirements of Section 38 Paragraph 1 of the German Federal Data Protection Act (BDSG) are not met, nor are the requirements of Article 37 Paragraph 1 of the GDPR. For data protection-related questions or to exercise your data subject rights, please contact us at the address provided above.



3. General information on data processing


3.1 Scope of processing personal data

We process personal data to the extent necessary for initiating, executing, and processing our contracts, providing our website and our content and services, or fulfilling legal obligations. We only obtain consent where no other legal basis exists for processing—for example, for sending our newsletter and for using cookies and similar technologies for analysis and marketing purposes. You can revoke your consent at any time with effect for the future.


3.2 Legal basis

Insofar as we obtain the consent of the data subject for processing operations involving personal data, Article 6(1)(a) GDPR serves as the legal basis.

When processing personal data necessary for the performance of a contract to which the data subject is a party, Article 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations necessary for carrying out pre-contractual measures.

Where processing is necessary for compliance with a legal obligation, Article 6(1)(c) GDPR serves as the legal basis.

If processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, and the interests or fundamental rights and freedoms of the data subject do not override those interests, then Article 6(1)(f) GDPR serves as the legal basis for the processing.


3.3 Recipient category

Your data will only be transferred to third parties if this is necessary for the performance of the contract, if you have given your consent, or if we are legally obligated to do so. Recipients may include, in particular:

  • Manufacturers and suppliers, insofar as this is necessary for order processing, spare parts procurement or the handling of warranty claims.
  • Subcontractors and service partners commissioned by us
  • Shipping and forwarding service providers (see section 16)
  • Payment service providers and credit institutions (see paragraphs 11 and 12)
  • IT, hosting, telecommunications and archiving service providers who act as data processors for us in accordance with Article 28 GDPR.
  • our tax advisor as well as financial and other authorities within the framework of legal obligations (§ 147 AO, §§ 238 ff. HGB, § 14 UStG)
  • Lawyers, courts and debt collection agencies, insofar as this is necessary for the assertion, exercise or defense of legal claims.


3.4 Data deletion and storage period

The personal data of the data subject will be erased or blocked as soon as the purpose of storage no longer applies. Storage may also take place if this is provided for by European or national legislation in EU regulations, laws, or other provisions to which the controller is subject. Data will also be blocked or erased when a storage period prescribed by the aforementioned regulations expires, unless further storage of the data is necessary for the conclusion or performance of a contract.


4. Provisioning the website and creating log files


4.1 Description and scope of data processing

Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. The following data is collected:

  • User's IP address (anonymized)
  • Date and time of access
  • Websites from which the user's system accessed our website
  • Websites accessed by the user's system via our website
  • Browser type and version
  • User's operating system
  • User's Internet service provider

This data is stored in our system's log files. This data is not stored together with other personal data of the user.


4.2 Legal basis

The legal basis for the temporary storage of data and log files is Article 6(1)(f) GDPR. Our legitimate interest lies in ensuring the technical operation of the website.


4.3 Storage duration

The data is deleted as soon as it is no longer needed for the purpose for which it was collected. In the case of data collected for the provision of the website, this is the case when the respective session ends. Log files are deleted after 14 days at the latest.


5. SSL encryption


This site uses SSL encryption for security reasons and to protect the transmission of confidential information, such as inquiries you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the padlock icon in your browser's address bar.

When SSL encryption is enabled, the data you send to us cannot be read by third parties.


6. Contact form and email contact


6.1 Description and scope of data processing

Our website includes a contact form that can be used to contact us electronically. If a user chooses to use this form, the data entered will be transmitted to us and stored. This data includes:

  • name
  • e-mail address
  • News
  • Phone number (if applicable)

The following data is also stored at the time the message is sent: the user's IP address and the date and time of registration.

Your consent for the processing of your data will be obtained during the submission process, and you will be referred to this privacy policy.

Alternatively, you can contact us via the provided email address. In this case, the personal data you transmit with your email will be stored.


6.2 Legal basis

The legal basis for processing data when the user has given consent is Article 6(1)(a) GDPR. The legal basis for processing data transmitted in the course of sending an email is Article 6(1)(f) GDPR. If the email contact aims at concluding a contract, the additional legal basis for processing is Article 6(1)(b) GDPR.


6.3 Storage duration

The data will be deleted as soon as it is no longer required for the purpose for which it was collected. For personal data from the contact form and data transmitted by email, this is the case when the respective conversation with the user has ended. A conversation is considered ended when it is clear from the circumstances that the matter in question has been resolved. Where statutory retention obligations under tax or commercial law exist (Section 147 of the German Fiscal Code, Sections 238 et seq. of the German Commercial Code), the storage period is up to 10 years.


7. Online shop and contract processing


7.1 Description and scope of data processing

We operate an online shop at www.nessensohn.gmbh. In connection with ordering and contract processing, we process the following personal data:

  • First and Last Name
  • Delivery address and billing address
  • E-mail address
  • Telephone number (optional)
  • Order details (items, quantities, prices)
  • Payment details (are transferred directly to the payment service provider Stripe)


7.2 Legal basis

The processing is based on Art. 6 para. 1 lit. b GDPR (performance of a contract) and Art. 6 para. 1 lit. c GDPR (compliance with legal obligations, e.g. bookkeeping obligations pursuant to §§ 238 ff. HGB, § 147 AO).


7.3 Storage duration

Order data is stored in accordance with statutory retention periods (up to 10 years for tax purposes, up to 6 years for commercial purposes). After these periods have expired, the data is routinely deleted unless it is still required for the fulfillment of the contract.


8. Customer service, maintenance and service orders

When we carry out work on your heating or heat supply system—such as maintenance, troubleshooting, repairs, or commissioning—we process the necessary data. This applies regardless of whether the order was placed by telephone, in writing, via our website, or on-site.


8.1 Description and scope of data processing

The following are processed in particular:

  • Name and address of the client and the address of the plant location, if different
  • Contact details (telephone, mobile phone, email address)
  • different billing address and order or contract number
  • Plant data (plant type, power, serial number, year of manufacture, commissioning date, installed components)
  • Order and deployment data (date, working hours, travel times, technician deployed)
  • Technical measurement, operating and test values of the system, as well as the findings and recommendations recorded in the customer service report.
  • used replacement and wear parts
  • Billing and payment data


8.2 Purposes and legal bases

The processing of your data is carried out for the execution and invoicing of the order placed, for documenting the work performed, for fulfilling warranty and verification obligations, and for scheduling follow-up maintenance. The legal basis for this is Article 6(1)(b) GDPR. Where we are legally obligated to invoice, retain, or document data, the legal basis is Article 6(1)(c) GDPR in conjunction with Section 14 of the German Value Added Tax Act (UStG), Section 147 of the German Fiscal Code (AO), and Sections 238 et seq. of the German Commercial Code (HGB).

Insofar as we notify you of an upcoming maintenance appointment or inform you about safety or operational matters concerning your existing system, we base this on Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in the safe and trouble-free maintenance of the system. You can object to this at any time.


8.3 Recipient

In addition to the recipient categories mentioned in section 3.3, we transmit your data in particular to the plant manufacturer, insofar as this is necessary for the handling of a warranty claim, for a technical clarification or for the procurement of spare parts, as well as to subcontractors commissioned by us, insofar as they provide services on your plant.


8.4 Storage duration

We retain documents relevant to invoicing in accordance with statutory retention periods (up to 10 years for tax purposes according to § 147 AO, up to 6 years for commercial purposes according to §§ 238 ff. HGB). We store plant, maintenance, and reporting data for the duration of the plant's maintenance and beyond, for as long as necessary to trace the plant's history, fulfill warranty obligations, or assert, exercise, or defend legal claims.


8.5 Necessity of provision

Providing your contact, location, and equipment data is necessary for us to fulfill this order. Without this data, we cannot plan, execute, or bill for the customer service call.


9. Passwordless login (Magic Link)


9.1 Description and scope of data processing

Our shop offers passwordless registration via a so-called "Magic Link." Simply enter your email address. You will then receive an email with a temporary login link, which, once clicked, will automatically log you into your customer account. No password is saved.

Data processed: Email address, timestamp of the request, IP address (for security purposes). The registration link is time-limited and expires after a single use.


9.2 Legal basis

The legal basis is Art. 6 para. 1 lit. b GDPR (performance of a contract, provision of the customer account) and Art. 6 para. 1 lit. f GDPR (legitimate interest in secure authentication).


9.3 Storage duration

Unused Magic Links are automatically deleted after their expiration date. The email address is stored for as long as the customer account exists. After the account is deleted, all associated data is also deleted.


10. Online cancellation form


10.1 Description and scope of data processing

In accordance with § 356a BGB (as amended on 19.06.2026), we provide you with an electronic cancellation form, which you can use to declare your cancellation directly via our website (www.nessensohn.gmbh/widerrufsformular).

When you use the cancellation form, we process the following personal data:

  • First and Last Name
  • Address (street, house number, postal code, city)
  • E-mail address
  • Type of contract (delivery of goods / service)
  • Order number or order date/description
  • Reason for revocation (voluntary)
  • Date and time the form was submitted (automatically recorded timestamp)

The data submitted via this form will be sent to us by email and automatically forwarded to your specified email address as confirmation of receipt. The timestamp of the confirmation of receipt documents the timely receipt of your cancellation notice.


10.2 Legal basis

The processing is based on Art. 6 para. 1 lit. c GDPR (compliance with a legal obligation) in conjunction with § 356a BGB as well as Art. 6 para. 1 lit. b GDPR (processing of the revocation as a contractual obligation).


10.3 Storage duration

Cancellation data is stored as proof of proper cancellation processing in accordance with the commercial and tax law retention periods for at least 3 years, and up to 10 years in connection with tax-relevant booking transactions.

Your cancellation data will not be passed on to third parties unless this is necessary for processing your order (e.g., returning goods).


11. Payment processing via Stripe


11.1 Description and scope of data processing

We use the payment service provider Stripe to process payments in our online shop. When you make a payment via Stripe, your payment details (e.g., credit card information, bank account details) are transmitted directly to Stripe. We do not store any complete payment data ourselves.

The following data will be transmitted to Stripe:

  • Name and billing address
  • E-mail address
  • Order amount and order reference
  • Payment information (directly to Stripe, not to us)
  • IP address (for fraud detection purposes by Stripe)


11.2 Providers

Stripe's responsible bodies for users in Germany (EEA):

Contract partner (DPA):

Stripe Payments Europe, Limited (SPEL)

1 Grand Canal Street Lower, Dublin 2, Ireland

Email: privacy@stripe.com

Regulated Payment Services (EEA):

Stripe Technology Europe, Limited (STEL)

1 Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland

Stripe's privacy policy can be found at: https://stripe.com/de/privacy


11.3 Legal basis

The legal basis for the transfer of data is Article 6(1)(b) GDPR (performance of a contract). A data processing agreement pursuant to Article 28 GDPR exists with Stripe.


11.4 Third-country transfer

Stripe may transfer data to the USA. The basis for data transfers to third countries is the EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 para. 2 lit. c GDPR. Stripe LLC is also certified under the EU-US Data Privacy Framework (Adequacy Decision of the EU Commission of 10 July 2023).


11.5 Right to object

You can object to the processing of your data by Stripe, insofar as Stripe acts as an independent data controller. Further information can be found in Stripe's privacy policy: https://stripe.com/de/privacy


12. Payment processing via PayPal


12.1 Description and scope of data processing

On our website, we offer payment via the PayPal payment service. If you choose PayPal as your payment method, the data required for processing the payment will be transmitted to PayPal. This includes, in particular:

  • First and Last Name
  • Billing address and, if applicable, delivery address
  • E-mail address
  • Order amount and order reference
  • IP address (collected by PayPal for fraud detection)

The provider of the payment service for the European area is:

PayPal (Europe) S.à rl et Cie, SCA

22-24 Boulevard Royal, L-2449 Luxembourg

Website: www.paypal.com/de/webapps/mpp/ua/privacy-full


12.2 Independent responsibility

PayPal is not a data processor within the meaning of Article 4 No. 8 GDPR, but rather the independent controller of the data it collects. The processing of personal data by PayPal is governed exclusively by PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full


12.3 Legal basis

The legal basis for transferring your data to PayPal is Article 6(1)(b) GDPR (performance of a contract). This transfer only occurs if you select PayPal as your payment method.


12.4 Third-country transfer

PayPal may transfer data to the USA and other third countries. PayPal relies on Binding Corporate Rules and EU Standard Contractual Clauses pursuant to Art. 46 para. 2 lit. c GDPR for this purpose.


13th Newsletter


13.1 Description and scope of data processing

You can subscribe to a free newsletter on our website. When you subscribe, the data you enter in the registration form will be transmitted to us:

  • E-mail address
  • Name (optional)

Your consent for data processing will be obtained during the registration process, and you will be referred to this privacy policy. In connection with data processing for sending newsletters, your data will not be shared with third parties. The data will be used exclusively for sending the newsletter.


13.2 Legal basis

The legal basis for processing the data after registration for the newsletter by the user is, if the user has given consent, Art. 6 para. 1 lit. a GDPR.


13.3 Storage period / Revocation of consent

The data will be deleted as soon as it is no longer needed for the purpose for which it was collected. The user's email address will therefore be stored for as long as the newsletter subscription is active. Other personal data collected during the registration process will generally be deleted after seven days.

The newsletter subscription can be cancelled by the user at any time. A corresponding link can be found in every newsletter for this purpose.


14. Google Analytics 4


14.1 Description and scope of data processing

Our website uses Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics 4 uses technologies (including cookies and similar storage technologies) that enable an analysis of your use of the website.

GA4 is used on this website with the tracking ID G-D5M51Z98LR.

The following data, among others, may be collected:

  • Page views and visited subpages
  • Time spent on the website
  • Visitor origin (referrer URL)
  • Approximate location (region/country, not exact GPS coordinates)
  • Technical information about browser, device and operating system
  • Interactions on the website (scroll depth, clicks, downloads)
  • IP address (automatically shortened – last octet in IPv4 is set to 0)

IP anonymization is enabled by default in Google Analytics 4. Your IP address is shortened by Google within the EU/EEA before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

The information generated by GA4 about your use of this website is usually transmitted to and stored on a Google server in the USA.


14.2 Order processing

We have concluded a data processing agreement with Google in accordance with Article 28 of the GDPR. Google processes the data on our behalf to compile reports on website activity.

The recipients of the data are:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Data Processor)
  • Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA


14.3 Third-country transfer

Google LLC is certified under the EU-US Data Privacy Framework (Adequacy Decision of the EU Commission of 10 July 2023). Since Google servers are distributed worldwide and a transfer to other third countries cannot be completely ruled out, we have also concluded the EU Standard Contractual Clauses (SCCs) with Google pursuant to Art. 46 para. 2 lit. c GDPR.


14.4 Legal basis and consent (§ 25 TDDDG)

The use of Google Analytics 4 is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG (Telecommunications Digital Services Data Protection Act, formerly TTDSG). Consent is obtained via our cookie banner upon your first visit to our website. Google Analytics will only be activated after your explicit consent.


14.5 Storage duration

User and event data in Google Analytics 4 are automatically deleted after 14 months. The maximum lifespan of cookies set by GA4 is 2 years (_ga cookie). Data whose retention period has expired is automatically deleted once a month.


14.6 Revocation of consent / Opt-out

You can withdraw your consent at any time with effect for the future by accessing our cookie settings and changing your selection there. The lawfulness of the processing carried out on the basis of the consent until its withdrawal remains unaffected.

Alternatively, you can prevent tracking by Google Analytics by:

Download and install the browser add-on to deactivate Google Analytics (https://tools.google.com/dlpage/gaoptout), or reject all cookies in your browser.

For more information about Google's privacy policy, please visit: https://policies.google.com/privacy


15. Google Ads


15.1 Description and scope of data processing

Our website uses Google Ads (formerly Google AdWords), an online advertising service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads allows us to place advertisements on the Google search network and on partner websites. This service uses conversion tracking, which places a cookie when a user clicks on one of our Google ads.

The information generated by this cookie (pseudonym, no real name) is transmitted to Google and used to evaluate the effectiveness of our advertising campaigns. We only receive information about the total number of users who clicked on our ad and were redirected to a page with a conversion tracking tag.


15.2 Legal basis

The legal basis is your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, which is obtained via our cookie banner.


15.3 Third-country transfer

Google LLC is certified under the EU-US Data Privacy Framework. For transfers to other third countries, EU Standard Contractual Clauses pursuant to Art. 46 para. 2 lit. c GDPR have been agreed upon.


15.4 Opt-Out / Cancellation

You can prevent the storage of cookies by adjusting your browser settings accordingly. You can also disable ad personalization in your Google settings at https://adssettings.google.com. You can withdraw your consent at any time via our cookie settings.

Further information on data protection at Google: https://policies.google.com/privacy


16. Shipping service provider


16.1 Parcel shipping – GLS

For the parcel shipping of ordered goods, we use the following parcel service provider:

General Logistics Systems Germany GmbH & Co. OHG

GLS-Germany-Straße 1–7, 36286 Neuenstein

Website: www.gls-group.com

To fulfill your shipping order, we will transmit your name, delivery address, and, if applicable, your email address and telephone number to GLS so that the delivery can be carried out properly and you can be informed about the delivery status.

The legal basis is Article 6(1)(b) GDPR (performance of a contract). A data processing agreement pursuant to Article 28 GDPR exists with GLS.


16.2 Freight forwarding – Grieshaber Logistics

For the shipment of bulky or heavy goods via freight forwarding, we work with the following service provider:

Grieshaber Logistik GmbH

To fulfill the shipping order, we will forward your name, delivery address and, if applicable, your email address and telephone number to Grieshaber Logistik so that the delivery can be properly coordinated and carried out.

The legal basis is Article 6(1)(b) GDPR (performance of a contract). A data processing agreement pursuant to Article 28 GDPR exists with Grieshaber Logistik GmbH.


17. Credit check


17.1 Description and scope of data processing

To protect against payment defaults, Creditreform Boniversum GmbH (Hellersbergstraße 11, 41460 Neuss) may obtain a credit report about you. Your name, address, and, if applicable, your date of birth will be transmitted to Creditreform.


The result of the credit check influences whether and to what extent certain payment methods (e.g., purchase on account) are offered. This does not prevent the conclusion of the contract itself; you will always have other payment methods available.


17.2 Legal basis

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in protecting against payment defaults. This information is only requested if you select a corresponding payment method.


18. Use of an AI telephone assistant (Fonio)

We use an AI-powered telephone assistant from the provider Fonio (hereinafter referred to as "telephone AI") to receive and pre-qualify incoming calls. The telephone AI records your request, asks clarifying questions about the conversation, and—depending on the content of the call—directs you to the responsible department within our company or takes messages for a callback.


18.1 Responsible party and service provider used

The Nessensohn GmbH mentioned under point 1 is responsible for data processing in connection with the telephone AI.

We use the "Fonio" service from
Fonio GmbH
Joanelligasse 5/16
AT- 1060 Vienna
Website: https://www.fonio.ai

Fonio acts as a data processor for us within the meaning of Article 28 GDPR. The details of the data processing (subject matter and duration, nature and purpose, type of personal data, categories of data subjects, and the obligations and rights of the parties) are governed by a data processing agreement, which is part of Fonio's contractual documents.

According to Fonio, processing takes place on servers in Germany (data center Nuremberg) and therefore within the European Union.


18.2 Categories of processed data

In the context of using the telephone AI, the following categories of personal data may be processed in particular:

  • Master data (e.g. name, company if applicable)
  • Contact details (e.g. telephone number, possibly email address for callback and appointment confirmation)
  • Conversation content data (description of your request, e.g., malfunction, maintenance request, quote request)
  • Technical connection data (e.g. phone number, date, time and duration of the call, routing information)
  • We ask that you do not disclose any special categories of personal data within the meaning of Article 9 GDPR (e.g. health data) when using the telephone AI.


    18.3 Purposes of processing and legal bases

    The data is processed by the telephone AI for the following purposes:

    • Receiving and processing incoming calls
    • Pre-qualification of customer requests and assignment to the responsible contact persons
    • Documentation of messages and callback requests
    • Ensuring the accessibility and efficient organization of our customer service
    • The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the communication is related to the fulfillment of a contract or the implementation of pre-contractual measures (e.g. requests for quotations, coordination of execution details, fault reports, appointment scheduling).

      Furthermore, processing is based on Article 6(1)(f) GDPR. The legitimate interest lies in ensuring accessibility, the orderly handling of calls, and relieving employees of routine tasks, without your interests or fundamental rights overriding this. You can request to be connected directly to an employee at any time.


      18.4 Conversation transcription and use of AI components

      The telephone AI automatically transcribes incoming calls to capture your request in a structured manner and assign it internally. The transcripts are stored in the Fonio platform and can be transmitted to internal systems (e.g., ticketing system, order management, calendar).

      Fonio uses various AI components for its service (e.g., speech-to-text, text-to-speech, and speech modeling services). According to the contractual agreement, the processed call data will not be used to train generally available AI models or to develop independent products by Fonio outside of our contract, but solely for providing and improving the contractually agreed-upon telephone AI service.

      Insofar as conversation content or transcripts are stored beyond the mere processing of the call, this is only done to the extent necessary for the performance of the contract or for the establishment, exercise or defense of legal claims (Art. 6 para. 1 lit. b and lit. f GDPR).


      18.5 Recipients and any transfers to third countries

      The recipients of the data processed within the framework of the telephone AI are Nessensohn GmbH as the data controller and Fonio GmbH as the data processor. Fonio may use further technical sub-processors to provide the service (e.g., hosting providers, providers of AI components).

      Currently, data processing generally takes place on servers in Germany or the EU. Should a transfer to a third country (e.g., the USA) be necessary in individual cases, this will only occur on the basis of an adequacy decision by the European Commission (Art. 45 GDPR, e.g., EU-US Data Privacy Framework) or suitable safeguards pursuant to Art. 46 GDPR (e.g., EU Standard Contractual Clauses).


      18.6 Storage duration

      Connection data (in particular, phone number, date, time, and duration of the call) and call transcripts are stored only as long as necessary to achieve the aforementioned purposes. Deletion or anonymization regularly occurs within 90 days of the conclusion of the communication, unless the data is required for a longer period in individual cases for contract processing or for the establishment, exercise, or defense of legal claims.

      If conversation content is stored in our own systems (e.g., as conversation notes in the order, in the customer account or in a service ticket), the retention periods shown there apply accordingly to this privacy policy.


      18.7 Voluntary nature of the provision and right to object

      Providing your data during a call is neither legally nor contractually required. However, without processing this data, it is not possible to handle your request via the telephone AI. In this case, you can alternatively contact us by email, via the contact form on our website, or by post.

      Insofar as the processing is based on Article 6(1)(f) GDPR, you have the right to object pursuant to Article 21 GDPR. You can object to the processing at any time by informing the telephone AI that you wish to speak directly to an employee, or by contacting us using the contact details provided in section 2.


      19. Rights of the data subject


      If your personal data is being processed, you are a data subject within the meaning of the GDPR and you have the following rights against the controller:


      19.1 Right to information

      You can request confirmation from the controller as to whether personal data concerning you is being processed by us (Art. 15 GDPR).


      19.2 Right to rectification

      You have the right to rectification and/or completion vis-à-vis the controller if the processed personal data concerning you is inaccurate or incomplete (Art. 16 GDPR).


      19.3 Right to restriction of processing

      Under the conditions set out in Article 18 GDPR, you can request the restriction of the processing of your personal data.


      19.4 Right to erasure

      You can request that the controller erase your personal data without undue delay if one of the grounds listed in Article 17 of the GDPR applies.


      19.5 Right to information

      If you have asserted your right to rectification, erasure or restriction of processing against the controller, the controller is obliged to communicate this rectification or erasure of data or restriction of processing to all recipients to whom the personal data concerning you have been disclosed (Art. 19 GDPR).


      19.6 Right to data portability

      You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used and machine-readable format (Art. 20 GDPR).


      19.7 Right to object

      You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) of the GDPR (Article 21 GDPR). We will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing.

      If personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing.


      19.8 Right to withdraw consent

      You have the right to withdraw your consent to data processing at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal (Art. 7 para. 3 GDPR).


      19.9 Right to lodge a complaint with a supervisory authority

      Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR (Art. 77 GDPR).

      The responsible supervisory authority for Baden-Württemberg is:

      The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg

      Lautenschlagerstraße 20

      70173 Stuttgart

      Telephone: +49 711 615541-0

      Email: poststelle@lfdi.bwl.de

      Website: www.lfdi.bwl.de


      20. Asserting your rights


      To assert your rights, contact:

      Nessensohn GmbH

      Attn: Data Protection

      Steigäcker 6, D-88454 Hochdorf

      Email: datenschutz@nessensohn.com

      Telephone: +49 7355 93389-0

      For faster processing, we kindly ask you to submit your request preferably by email and to prove your identity with suitable documents.


      21. Note on cross-border sales within the EU


      We also deliver goods to other EU member states. The GDPR applies uniformly throughout the European Union, so customers from other EU countries enjoy the same data protection rights as German customers.

      The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW) remains the competent data protection supervisory authority for our company as the lead supervisory authority pursuant to Art. 56 GDPR.

      Customers from other EU member states can choose to assert their data subject rights either by contacting us directly (datenschutz@nessensohn.com) or by contacting the competent data protection authority in their country of residence.


      22. Currentness of this privacy policy

      This privacy policy is dated August 31, 2026. Due to the ongoing development of our services and website, or due to changes in legal or regulatory requirements, it may become necessary to amend it. You can access and print the current version at any time at www.nessensohn.gmbh.