Data protection

Privacy Policy

We are pleased that you are visiting our website. The protection of your personal data is important to us. Below, we inform you about which personal data we process when you use our website, for what purposes we process this data, and what rights you have.

1. Controller

The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Thiele Metalltechnik GmbH
Baudirektor-Hahn-Straße 30
27472 Cuxhaven
Germany

Phone: +49 4721 7390
E-mail: info@tmt-cuxhaven.de

Represented by Managing Director Ralf Thiele.

2. General Information on Data Processing

We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications and Digital Services Data Protection Act (TDDDG).

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, address, e-mail address, telephone number, IP address, and information concerning your use of our website.

3. Accessing Our Website and Server Log Files

Whenever you access our website, the web server automatically processes information transmitted by your browser to our server. This may include, in particular:

  • IP address of the accessing device,
  • date and time of access,
  • pages and files accessed,
  • referrer URL,
  • browser type and browser version,
  • operating system used,
  • technical information concerning the browser and device environment.

The processing is carried out to make the website technically available, ensure its security and stability, detect errors, and protect the website against misuse and unauthorized access.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable, and technically reliable provision of our website.

Server log files are deleted as soon as they are no longer required for the purposes stated above, unless statutory retention obligations or the assertion, exercise, or defense of legal claims require longer storage.

4. Contact by E-mail, Telephone or Contact Form

If you contact us by e-mail, telephone, or via a contact form provided on our website, we process the personal data you provide to the extent necessary to process your inquiry.

This may include your name, contact details, the content of your inquiry, and any other information you voluntarily provide.

Depending on the nature of your inquiry, the processing is based on Art. 6(1)(b) GDPR if the processing is necessary for the performance of a contract or for taking steps prior to entering into a contract, or on Art. 6(1)(f) GDPR based on our legitimate interest in processing and responding to inquiries.

If you have given us your consent to process your data, the legal basis is Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future.

The data you provide will be deleted once your inquiry has been conclusively dealt with and provided that no statutory retention obligations or legitimate interests require further storage.

5. Cookies and Similar Technologies

Our website uses cookies and similar technologies. Cookies are small text files that may be stored on your device. In addition, similar technologies may be used to store information on your device or access information already stored on your device.

We distinguish between technologies that are technically necessary and those used, for example, for marketing, analytics, or the integration of external content.

5.1 Technically Necessary Cookies and Technologies

Technically necessary cookies and similar technologies may be used where they are required for the operation of the website, the provision of a service or function expressly requested by you, or the security of the website.

Our website uses, among other things, functions provided by WordPress, Polylang, and Wordfence. WordPress is used as the technical content management system. Polylang is used to provide and manage the different language versions of the website. Wordfence is used to protect the website and detect or prevent security-related access attempts.

Where the storage of or access to information on your device is strictly necessary to provide a digital service expressly requested by you, no consent is required pursuant to Section 25(2) No. 2 TDDDG.

5.2 Non-Essential Cookies and Technologies

For cookies and similar technologies that are not technically necessary, we generally obtain your consent before using them where legally required.

Consent is obtained through our cookie consent management system. You can make your selection there and change or withdraw your consent at any time with effect for the future.

The legal basis for processing personal data in connection with non-essential cookies and similar technologies is generally Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

5.3 Managing Your Cookie Settings

You can change or withdraw your consent at any time via the cookie settings on our website. Processing that has already taken place remains lawful until the time of withdrawal.

The cookies and similar technologies currently used, including their purposes and storage periods, can be viewed in our cookie overview.

6. Embedded Content from Facebook and Instagram

Our website may contain embedded content and functions from the social networks Facebook and Instagram. This may include, for example, social media content, posts, or buttons.

When such content is embedded, personal data, in particular technical information and information concerning your visit to our website, may be transmitted to the respective provider. Depending on the specific technical implementation, cookies or similar technologies may also be used.

Processing by Facebook or Instagram will only take place where an appropriate legal basis exists and, where required, where you have provided your prior consent.

The provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Meta Platforms, Inc., USA, may also be involved in certain processing activities.

Further information on data processing by Meta can be found in the privacy information provided by the respective service.

7. Website Security with Wordfence

We use Wordfence to protect our website against attacks, abusive access, and other security-related activities.

This may involve processing technical information about accessing devices and connections to the extent necessary to detect and prevent security threats.

The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, our IT systems, and the data we process against attacks and misuse.

The provider of the security solution is Defiant Inc., USA. Where personal data is transferred to recipients outside the European Union or the European Economic Area in connection with the use of Wordfence, such transfers are carried out in accordance with the applicable requirements under Art. 44 et seq. GDPR.

8. Language Versions and Polylang

Our website is available in several languages. We use Polylang to technically manage and store your selected language.

This may involve the use of a cookie or similar technology to store your language preference.

The processing is based on Art. 6(1)(f) GDPR insofar as storing the language preference is necessary to provide the website in a user-friendly manner.

9. Social Media Presences

We may maintain presences on social networks. When you visit our corresponding social media pages, the respective operator of the social network may process personal data relating to you.

We generally have only limited influence over the data processing carried out by operators of social networks. The respective providers’ privacy policies apply.

If social media content is embedded on our website, processing by the respective provider will only take place in accordance with the applicable data protection requirements.

10. SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content, our website uses SSL/TLS encryption.

You can recognize an encrypted connection by the fact that the browser’s address bar begins with “https://” and, depending on your browser, a padlock symbol is displayed.

Encryption means that data you transmit generally cannot be read by unauthorized third parties during transmission.

11. Legal Bases for Processing

Depending on the specific processing activity, personal data is processed in particular on the basis of the following legal grounds:

  • Art. 6(1)(a) GDPR: Consent of the data subject.
  • Art. 6(1)(b) GDPR: Processing necessary for the performance of a contract or for taking steps prior to entering into a contract.
  • Art. 6(1)(c) GDPR: Processing necessary for compliance with a legal obligation.
  • Art. 6(1)(f) GDPR: Processing necessary for the purposes of legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.

12. Recipients of Personal Data

Personal data is only disclosed where there is a legal basis for doing so.

As part of the technical operation of our website, personal data may be processed in particular by IT and hosting service providers, providers of security solutions, and providers of integrated third-party services.

Where we engage service providers as processors, processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR, where the statutory requirements for this are met.

13. Transfers to Third Countries

When using certain services, personal data may be processed by providers located outside the European Union or the European Economic Area.

Personal data is only transferred to a third country where the requirements of Art. 44 et seq. GDPR are met. This may include, in particular, an adequacy decision by the European Commission, appropriate safeguards, or, where legally permissible, explicit consent.

14. Storage Period

We generally store personal data only for as long as necessary for the respective processing purposes or as required by statutory retention obligations.

Once the respective purpose no longer applies, the data will be deleted unless statutory retention obligations or legitimate interests require further storage.

15. Your Rights as a Data Subject

Subject to the applicable statutory requirements, you have the following rights:

  • Right of access pursuant to Art. 15 GDPR,
  • Right to rectification pursuant to Art. 16 GDPR,
  • Right to erasure pursuant to Art. 17 GDPR,
  • Right to restriction of processing pursuant to Art. 18 GDPR,
  • Right to data portability pursuant to Art. 20 GDPR,
  • Right to object to certain processing activities pursuant to Art. 21 GDPR,
  • Right to withdraw consent pursuant to Art. 7(3) GDPR.

If you withdraw your consent, the lawfulness of processing carried out prior to the withdrawal shall remain unaffected.

To exercise your rights, you may contact us at any time using the contact details provided above.

16. Right to Object

You have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data where such processing is based on Art. 6(1)(e) or (f) GDPR.

Where personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes.

17. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR.

The supervisory authority primarily responsible for our company is:

The State Commissioner for Data Protection of Lower Saxony
Prinzenstraße 5
30159 Hannover
Germany

Phone: +49 511 120-4500
E-mail: poststelle@lfd.niedersachsen.de

Further information and the online complaint form can be found on the website of the State Commissioner for Data Protection of Lower Saxony.

18. Currency and Amendments to This Privacy Policy

We reserve the right to amend this Privacy Policy if this becomes necessary due to changes to our website, the services we use, legal requirements, or technological developments.

The version of this Privacy Policy published on our website at the time of your visit shall apply.

Last updated: September 18, 2026