Skip to main navigation Skip to main content Skip to page footer

CVM Chemie-Vertrieb Magdeburg GmbH & Co. KG

We hereby provide you with all the information regarding data processing carried out by our company. This covers the relevant obligations set out in Articles 13, 13a, 14, 15, 26 and 30 of the GDPR. 

Procurement

Below, we provide you with detailed information on all the key aspects of this data processing. We refer to all the information requirements arising from Articles 13, 14, 15, 26 and 30 of the GDPR.
 

  1. What is the purpose of this processing?
    The purchase of goods and services for our own purposes and for resale; ensuring the availability of materials and resources via post, email, telephone and fax; identifying suitable suppliers; conducting price negotiations; and handling returns and incorrect deliveries; verification of the identity of the person authorised to represent the potential customer in accordance with EU Regulation 2019/1148 on the marketing and use of explosives
      precursors
  2. Who is responsible for this processing?
    CVM Chemie-Vertrieb Magdeburg GmbH & Co. KG
    Address: Werner-von-Siemens-Ring 8, 39116 Magdeburg
    Telephone: +49 (0) 391 / 50 86 20 - 0
    Fax: + 49 (0) 391 / 50 86 20 - 40
    Website: www.cvh.de
    Email: magdeburg@cvh.de
     
  3. Who has been appointed as the company’s data protection officer?
    Martin Lorenz, Am Hang 8, 31655 Stadthagen, datenschutzbeauftragter.cvhgruppe[at]triades-datenschutz.de
     
  4. What is the legal basis? Why is this processing permitted?
     

    • Protection of the controller’s legitimate interests in accordance with Article 6(1)(f) of the GDPR
    • Compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR


    Explanation of the multiple legal bases:
     

    • Art. 6(1)(f) for the purchase of goods and services
    • Article 6(1)(c) for the procurement of raw materials for explosives

     

  5. Specifically, which ‘legitimate interests’ is the controller pursuing?
    Generally necessary measures relating to operational organisation
     
  6. Are there any statutory or contractual requirements? What would happen if you did not provide your data?
    Without the data, the requirements of Article 8(2) of EU Regulation 2019/1148 cannot be met.
     
  7. Who are the authorised recipients (both internal and external)? 

    • Purchasing and procurement  
    • Suppliers’ employees  
    • Accounts  
    • Management  
    • Administrative staff  
    • Sales  

     

  8. When will the data be deleted? 

    • 18 months from the date of the transaction (in accordance with Article 8(4) of EU Regulation 2019/1148) for the CUSTOMER’S DECLARATION (with proof of identity) regarding the specific use(s) of a restricted explosive precursor  
    • 6 years after the end of the calendar year (in accordance with Section 257(4) of the German Commercial Code – including for commercial and business correspondence)  
    • 10 years after the end of the calendar year (in accordance with Section 147(3) of the German Fiscal Code)  
    • 3 years after the right to performance arises (in accordance with Section 195 of the German Civil Code (BGB) on the general limitation period)  
    • Data is deleted once the purpose no longer applies and retention obligations have expired  

     

  9. Which categories of data are processed? 

    • Identity data (name, identity card number, issuing authority)
    • (bank and credit card details
    • Order and delivery data
    • Email (date, recipient, text, attachments)
    • Contact details (name, telephone number, email, address, etc.)
    • Contract details

     

  10. Which individuals are affected? 

    • Employees
    • Service providers
    • Customers
    • Suppliers

     

  11. The right to ‘access’
    You have the right to access the data relating to you. This document largely ensures that this right is upheld. If you have any further questions or concerns, please do not hesitate to contact us.
     
  12. The right to “rectification” of inaccurate data
    You generally have the right to have inaccurate data rectified. Please contact us in this regard.
     
  13. The right to “erasure of your data”
    You have the right to have your data erased provided that (a) the data is no longer necessary, (b) you have withdrawn your consent where applicable or there is no other legal basis (any longer), (c) you have lawfully objected, (d) the data has been processed unlawfully, (e) erasure is required by law, (f) the data relates to children and is to be erased. Please note that, in accordance with Article 17(3) of the GDPR, it may not be possible or permissible to erase the data.
     
  14. The right to ‘restriction of processing’
    You have the right to have your data ‘blocked’ provided that (a) you contest the accuracy of the data, (b) the processing is unlawful and you oppose erasure, (c) we no longer require the data, but you still require it for your own legal claims, (d) you have objected to the processing and it has not yet been determined whether the legitimate interests of the controller override yours.
     
  15. The right to “object to processing”
    You have the right to object to processing, provided there are grounds relating to your SPECIFIC SITUATION. We will then assess whether we have compelling legitimate grounds for processing.
     
  16. The right to “withdraw consent”
    You have the right to withdraw your consent (where this is relevant to the processing described here). The withdrawal applies only with future effect.
     
  17. The right to “data portability”
    You have the right to receive a copy of your data (“data portability”), provided that (a) the legal basis is consent or a contract, and (b) you have provided this data yourself, and (c) the data is processed by automated means. Provided these conditions are met, you may also request that we transfer the data to a recipient of your choice.
     
  18. The right to “lodge a complaint”
    You have the right to lodge a complaint with any data protection supervisory authority. The contact details of the data protection supervisory authority responsible for us are: LDI Saxony-Anhalt, Leiterstr. 9, 39104 Magdeburg, GERMANY, Tel. 0049 391-81803-0, www.datenschutz-sachsen-anhalt.de.
    You are welcome to contact us first before reaching out to the supervisory authority; our highly competent in-house data protection officer will deal with your enquiry much more quickly and just as thoroughly. If we are unable to assist you, you can always contact the supervisory authority afterwards.
     
  19. Data collection by third
    parties No, no data is collected by third parties. This means that all data is requested and collected by us directly.
     
  20. Does profiling take place? Are personal characteristics analysed or predicted? Does automated individual decision-making take place?
    No, this does not take place.
     
  21. Are data transferred to recipients in third countries (i.e. outside the EU)?
    No, this does not take place.
     
  22. Are there several data controllers in the sense of ‘joint controllership’?
    No, there is only the ONE data controller mentioned above.
     

 

Additional information

There are letter templates circulating on the internet for requests for information which demand the most comprehensive information conceivable. In some cases, they request information that goes far beyond what is legally required. We would like to briefly explain this:

  • With regard to specific data details (such as first name, surname, telephone number, etc.), there is no obligation to provide such information under the relevant Articles 14(1d), 15(1b) and 30(1c). Accordingly, we are providing you – as requested – with the CATEGORIES of data.
     
  • There is also no right to information regarding technical and organisational measures. We do not specify these measures because doing so would play into the hands of potential attackers. Only the supervisory authority is permitted, in accordance with Article 30(1g), to request a general description of these measures. Please rest assured that we take appropriate measures.
     
  • With regard to a list of all third parties and data processors, we shall only specify the CATEGORIES of recipients and not any specific company names. This is a permissible option under Articles 13(1e), 14(1e) 15(1c) and 30(1d). We regard the list of our (very carefully selected) suppliers as a trade and business secret and wish to avoid any risks to ourselves and our customers that might arise should it become public knowledge. 

Blanket requests for erasure/restriction or blanket withdrawals of consent/objections etc. are problematic. Please put yourself in our shoes: are we expected to alter our data processing without reliable proof of identity? This could lead to serious problems and may even constitute a data protection breach. We will therefore, as a general rule, request additional information in accordance with Article 12(6) before we comply with these data subject rights under Articles 15–21. Please contact us in this regard.

Our Chemistry Works