Privacy Policy

We welcome you to our website and appreciate your interest in our company. We take the protection of your personal data very seriously. We process your data in accordance with applicable data protection regulations, particularly the EU General Data Protection Regulation (GDPR) and the national provisions applicable to us.

With this privacy policy, we comprehensively inform you about the processing of your personal data by H2APEX Group SCA and about your rights.

Personal data is information that can be used to identify a natural person directly or indirectly, such as name, date of birth, address, telephone number, email address, or your IP address.

Last updated: [21.02.2025]

Controller and Data Protection Officer

H2APEX Group SCA
19, rue de Flaxweiler
6776 Grevenmacher
Luxembourg

Phone: +352 28 38 47 20
Fax: +352 28 38 47 29
Email: info@h2apex.com
Web: www.h2apex.com

Contact of the Data Protection Officer: datenschutz@h2apex.com

Your Rights as a Data Subject

First, we would like to inform you about your rights as a data subject. These rights are set out in Articles 15-22 GDPR. This includes:

  • The right to access (Art. 15 GDPR),
  • The right to erasure (Art. 17 GDPR),
  • The right to rectification (Art. 16 GDPR),
  • The right to data portability (Art. 20 GDPR),
  • The right to restriction of processing (Art. 18 GDPR),
  • The right to object to data processing (Art. 21 GDPR).

To exercise these rights, please contact: datenschutz@h2apex.com. The same applies if you have questions about data processing in our company.

You also have the right to lodge a complaint with a data protection supervisory authority.

Right to Object

Please note the following in connection with your right to object: If we process your personal data for direct marketing purposes, you have the right to object to this data processing at any time without giving reasons. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes. The objection can be made without formal requirements to: datenschutz@h2apex.com

In the event that we process your data to protect legitimate interests, you can object to this processing at any time for reasons arising from your particular situation.

We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves to establish, exercise, or defend legal claims.

Purposes and Legal Bases of Data Processing

When processing your personal data, the provisions of the GDPR and all other applicable data protection regulations are observed. Legal bases for data processing arise in particular from Art. 6 GDPR.

We use your data for business initiation, to fulfill contractual and legal obligations, to carry out a contractual relationship, to offer products and services, to provide our website and our online services, and to strengthen customer relationships, which may also include analyses for marketing purposes and direct marketing.

Your consent also constitutes a data protection permission regulation. In this context, we inform you about the purposes of data processing and your right of withdrawal. If the consent also relates to the processing of special categories of personal data, we will explicitly inform you of this in the consent.

The specific purposes and legal bases on which the respective processing activities are based are set out in this privacy policy.

Transfer to Third Parties / Recipients

We will only share your data with third parties within the framework of legal provisions or with appropriate consent. Otherwise, data will not be shared with third parties unless we are obliged to do so due to mandatory legal regulations (disclosure to external bodies such as supervisory authorities or law enforcement authorities).

Within our corporate group, we ensure that only those persons receive your data who need it to fulfill contractual and legal obligations.

In many cases, service providers support our departments in fulfilling their tasks. The necessary data protection contract has been concluded with all service providers (in particular data processing agreements according to Art. 28 GDPR).

Third Country Transfer

Data transfer to third countries (outside the European Union or the European Economic Area) only takes place if this is necessary for the purposes mentioned above.

If personal data is transferred to recipients outside the European Union/European Economic Area, we conclude standard contractual clauses with these recipients, unless these recipients are based in countries with an adequacy decision according to Art. 45 GDPR.

Storage Duration of Data

We store your data as long as it is needed for the respective processing purpose. Please note that we are also entitled or obliged to store your data beyond this in accordance with statutory retention periods. This particularly concerns commercial law or tax law retention obligations. If no further retention obligations exist, the data will be routinely deleted after the purpose has been achieved.

In addition, we may retain data if you have given us your consent to do so or in the event of legal disputes and we use evidence within the framework of statutory limitation periods.

Secure Transmission of Your Data

To protect the data stored by us as best as possible against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons, we use appropriate technical and organizational security measures. The security levels are continuously reviewed in cooperation with security experts and adapted to new security standards.

Data exchange to and from our website is always encrypted. We offer HTTPS as a transmission protocol for our website, using the current encryption protocols. In addition, we offer our website users content encryption as part of the contact forms and for applications. Decryption of this data is only possible for us. There is also the possibility to use alternative communication channels (e.g., postal mail).

Obligation to Provide Data

The provision of personal data is neither legally nor contractually required.

However, if you use our contact form, certain personal data (e.g., salutation, department, name, first name, email address, telephone number, and the content of the message field) is required so that we can process your request. You are not obliged to provide this data, but we may not be able to answer your request in this case.

Categories, Sources, and Origin of Data

The data we process depends on the respective context: This depends on whether you, for example, place an order online or enter a request in our contact form, send us an application, or submit a complaint. Please note that we may also provide information for special processing situations separately at an appropriate point (see, for example, the privacy information for applicants).

When visiting our website, we collect and process the following data:

  • Name of the Internet service provider
  • Information about the website from which you visit us
  • Web browser used and operating system used
  • The IP address assigned by your Internet service provider (anonymized)
  • Requested files, amount of data transferred, downloads/file export
  • Information about the websites you visit on our site, including date and time

For reasons of technical security (especially to defend against attack attempts on our web server), this data is stored in accordance with Art. 6 Para. 1 S. 1 lit. f) GDPR. After a maximum of 7 days, the IP address is anonymized by shortening, so that no connection to the user is established.

Cookies

In some areas of our website, we use cookies. Cookies are small text files that are stored by the browser on your device (e.g., computer, tablet, or mobile phone) when you visit a website and can be read by us or a third-party provider. They serve to identify your device for a certain period of time.

WPML (WordPress Multilingual Plugin)

WPML uses cookies to store the language settings of website visitors and ensure consistent language display when navigating the website. For example, the user’s preferred language is recorded in order to automatically provide the selected language version for future visits. These cookies do not contain any personal data and serve exclusively the functionality of the multilingual website. For more information, please see the WPML documentation: https://wpml.org/documentation/privacy-policy-and-gdpr-compliance/.

Borlabs Cookie

Borlabs Cookie stores the consent preferences of website visitors in its own cookie. Information is stored about which cookie categories (e.g., Essential, Statistics, Marketing, External Media) the user has accepted or rejected. This data is used to store the settings made and ensure that only the corresponding allowed cookies are set for future visits. The Borlabs cookie does not contain any personal data, but only stores an anonymized ID and the selected preferences in encrypted form. This way, the user does not have to make their settings again for each visit.

Google Analytics

This website uses functions of the web analytics service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

IP Anonymization

We have activated the IP anonymization function on this website. As a result, your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases is the full IP address transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activities, and to provide further services related to website and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.

Browser Plugin

You can prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google as well as the processing of this data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

Objection to Data Collection

You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set that prevents the collection of your data during future visits to this website: Disable Google Analytics.

More information on how Google Analytics handles user data can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=en.

Demographic Features in Google Analytics

This website uses the “demographic features” function of Google Analytics. This allows reports to be created that contain statements about the age, gender, and interests of site visitors. This data comes from interest-based advertising from Google as well as visitor data from third-party providers. This data cannot be assigned to a specific person. You can disable this feature at any time through the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the “Objection to data collection” section.

Contact Form / Contact by Email

On our website, we provide a contact form that can be used for electronic contact. If you write to us through this form, we process the data you provide for the purpose of contacting you and processing your request. This includes your salutation, department, name, first name, email address, telephone number, and the content of the message field. For technical reasons and legal security, we also record your IP address. All other fields are voluntary and can be filled out by you as needed.

If you contact us by email, we process the personal data contained in your email exclusively for the purpose of processing your request.

We process your data to protect our legitimate interests according to Art. 6 Para. 1 S. 1 lit. f) GDPR to appropriately respond to contact requests. If you are inquiring about an offered product or service, the processing is carried out to implement pre-contractual measures according to Art. 6 Para. 1 S. 1 lit. b) GDPR.

Newsletter Distribution with CleverReach

You have the option to subscribe to our newsletter. With our newsletter, we inform you about us and our offers.

We use the service provider CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany, for sending our newsletter. CleverReach offers a professional platform for creating, sending, and analyzing newsletter campaigns.

As part of the newsletter registration, we collect and process only data that is necessary for sending the newsletter:

  • Email address
  • Possibly name, first name (for a personal salutation)
  • Technical information for sending

For registration to our newsletter, we use the double opt-in procedure. This means:

  • You register on our website with your email address.
  • You then receive a confirmation email with a confirmation link.
  • Only with this confirmation is your email address added to our distribution list.

CleverReach enables us to analyze the newsletter dispatch. For example, the following can be recorded:

  • How many recipients have opened the newsletter?
  • Which links were clicked?
  • Were newsletters delivered or marked as spam?

These evaluations are carried out in pseudonymized form and are used exclusively to optimize our newsletter content and customer contact. No conclusions are drawn about individual persons.

When using CleverReach, the data you provide is transmitted to CleverReach GmbH & Co. KG and stored there. No further disclosure of your data to third parties takes place. CleverReach has its headquarters in Germany, so data processing generally takes place within the EU/EEA.

Your data will remain in our newsletter distribution list until you unsubscribe from the newsletter or we no longer need the data for our newsletter service.

Our newsletter is sent on the basis of your prior express consent, Art. 6 Para. 1 S. 1 lit. a) GDPR. You can revoke your consent to receive the newsletter at any time, e.g., via the unsubscribe link at the end of each newsletter or by sending a message to info@h2apex.com. As soon as you unsubscribe, your email address will be blocked in our mailing list and subsequently deleted, unless there are other legal retention periods. For more information about data protection at CleverReach, please visit: https://www.cleverreach.com/en/privacy-policy/

Online Application

On our website, we offer you the opportunity to apply online for advertised positions. In this regard, we refer to the separate privacy notices for applicants.

Marketing Purposes for Existing Customers

H2APEX Group SCA places great importance on good customer relationships. Therefore, we would like to regularly send our existing customers information and offers about our products and services as well as invitations to events and trade fairs by email. For this purpose, we process your personal data (in particular: name, email address).

This serves to protect our legitimate interest, which outweighs other interests in the context of a balancing of interests, in conducting direct marketing, Art. 6 Para. 1 S. 1 lit. f) GDPR. Of course, you can object to the use of your personal data for direct marketing purposes at any time, without incurring any costs other than the transmission costs according to the basic rates. Upon receipt of your objection, we will no longer process your data for this purpose.

The objection can be made without formalities and free of charge – preferably by email to datenschutz@h2apex.com or by post to the address mentioned above.

Web Analysis with Matomo (formerly Piwik)

We use the open-source web analysis tool Matomo on our website to record the usage behavior of our visitors and to continuously improve our content. Matomo is hosted on our own servers, so no data is shared with third parties.

We have configured Matomo to work without the use of cookies. This means that no tracking cookies are stored on your device when you visit our website. To capture usage data, Matomo instead uses other technological measures (e.g., the shortened recording of your IP address, device and browser recognition) to analyze visitor behavior.

We use the anonymization function provided by Matomo. Your IP address is anonymized immediately after it is captured, making it impossible to trace back to you as an individual. All stored data is kept exclusively on our servers and is not shared with third parties.

The processing of the data is based on our legitimate interests pursuant to Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the analysis of user behavior in order to optimize both our website and our offers. Since no cookies are set and your IP address is anonymized, we also assume a minimal interference with your personal rights.

If, despite the high level of data protection, you do not want your visit to be recorded for our internal statistics, you have the option to object to web tracking at any time. Depending on the configuration, we offer you either an opt-out function on our website (e.g., via a checkbox or button) or you can activate “Do Not Track” in your browser. As soon as you use this function, no data will be collected about your visit.

Content from External Providers

Our website also contains – clearly identifiable – links to websites of other companies. Since we have no influence on their content, we can neither guarantee nor assume liability for them. The respective provider or operator is always responsible for the content of the linked pages.

At the time of linking, we checked the external pages for possible legal violations and did not identify any illegal content. However, permanent content control of the linked pages is not reasonable without concrete evidence of a legal violation. Should we become aware of legal violations, we will remove such links immediately.

If a user agrees to the “External Media” category in the Borlabs Cookie, content from third-party providers such as YouTube (Google) is automatically loaded. This may involve the transfer of personal data, such as the IP address, to the respective service provider. YouTube stores and processes this data in accordance with its own privacy policies. Without the user’s consent, such external content is blocked by H2PEX and only loaded after explicit approval. For more information on data processing by YouTube, please see Google’s privacy policy: https://policies.google.com/privacy.

Changes to This Privacy Policy

Due to the development of our website and our online services or due to changed legal and official requirements, it may be necessary to adjust this privacy policy occasionally.

If you have questions about the processing of your data, we are happy to help.