Privacy Policy

1 General

1.1 Objective and responsibility

(1) The purpose of this privacy policy is to inform you about the nature, scope and purpose of personal data processing on our internet website and the associated sites, functionalities and content (hereinafter collectively referred to as “website”). The privacy policy applies irrespective of the domains, systems, platforms and devices (e.g., desktop or mobile) on which the website is made available.

(2) The provider of the website and legally responsible for it under privacy law is Heraeus Holding GmbH, Heraeusstraße 12-14, 63450 Hanau, Germany (hereafter referred to as the “provider”, “we” or “us”). For further details as well as how to contact us, please see the  legal information on our website.

(3) Our Data Protection Officer can be reached via the following email address:  dataprotection@heraeus.com or by post:

Data Protection Officer

c/o Heraeus Business Solutions GmbH

Heraeusstr. 12-14

63450 Hanau.

(4) The term “user” includes all customers and their employees as well as visitors to our website.

(5) The products and services of Heraeus are intended exclusively for companies. Heraeus' websites, including its advertising and any business contact forms on Heraeus' websites, are not directed at children and adolescents (persons under 18 years of age). Persons under 18 years of age are not authorized to fill in and submit these contact forms to Heraeus. Except as stated below, does not knowingly collect personal information from persons under 18 years of age. Heraeus will only request data from persons under 18 years of age if such persons apply for a job, an apprenticeship or a student internship at Heraeus in a Heraeus application portal which is set up separately for such persons. The requested data is used exclusively for the purpose of the application process. They will not be used for any other purpose and will be deleted after the application procedure has been completed in accordance with the requirements of data protection law.

1.2 Legal basis

Your personal data is collected and processed on the following legal basis:

a) Consent in accordance with Art. 6 (1) (a) of the General Data Protection Regulation (GDPR). Consent is a statement of intent, freely given in a specific instance in an informed and unambiguous manner in the form of a declaration or another unequivocal affirmative act, where the data subjects make it clear that they consent to the processing of their personal data.

b) Necessity for the performance of a contract or in order to take steps prior to entering into a contract in accordance with Art. 6 (1) (b) GDPR, i.e., the data is necessary for us to carry out our contractual obligations to users or we need the data in order to prepare a contract with users.

c) Processing for compliance with a legal obligation in accordance with Art. 6 (1) (c) GDPR, i.e., the data processing is required on the basis of a law or some other requirement.

d) Processing to safeguard legitimate interests in accordance with Art. 6 (1) (f) GDPR, i.e., the processing is necessary to safeguard our legitimate interests or those of a third party, provided the interests do not outweigh the fundamental rights and freedoms of users who require the protection of personal data.

1.3 Data subject rights

You can assert your rights as a data subject with regard to your processed personal data at any time using the contact details of the Data Protection Officer given above. As a data subject, you have the following rights.

(1) Right to revoke consent: If personal data is processed on the basis of consent, you have the right to revoke this consent at any time for the future in accordance with Art. 7 GDPR.

(2) Right to information: In accordance with Art. 15 GDPR, you can request confirmation of whether their data is being processed. If this is the case, users have the right to information regarding the information at no charge.

(3) Right to rectification: If personal data has been processed while incorrect, you have the right, to request that this data be corrected immediately in accordance with Art. 16 GDPR.

(4) Right to erasure: If you have revoked your consent, objected to the processing of your personal data (and there are no overriding legitimate reasons for the processing), your personal data is no longer necessary for the original purpose of the processing, there is a corresponding legal obligation or personal data has been processed unlawfully, you have the right to request the deletion of their personal data in accordance with Art. 17 GDPR.

(5) Right to restriction of processing: Under the provisions of Art. 18 GDPR, you have the right to demand that the processing of their personal data be restricted.

(6) Right to data portability: In accordance with Art. 20 GDPR, you have the right to receive the personal data they provided in a structured, commonly used and machine-readable format.

(7) Right to object: If processing the personal data is necessary to safeguard the legitimate interests of our company, you can object to the processing at any time in accordance with Art. 21 GDPR.

(8) Right to file a complaint: In accordance with Art. 77 GDPR, you have the right to lodge a complaint with the responsible supervisory authorities.

1.4 Deletion of data

Your personal data is deleted as soon as the purpose for which it was collected has ceased to exist and there are no other legal or contractual obligations to retain it.

1.5 Security measures

State-of-the-art organizational and technical security measures are in place to ensure compliance with relevant legal provisions and to protect personal data against accidental or intentional manipulation, loss, destruction and unauthorized access.

1.6 Transfer of data to third parties and third-party providers

(1) Heraeus transfers data to third parties exclusively in accordance with legal provisions. We only transfer user data to third parties if necessary (for example, for accounting purposes) or for other purposes necessary to meet our contractual obligations to users or legal requirements.

(2) Where we use sub-contractors to provide our services, we will take appropriate legal precautions and technical and organizational measures to protect personal data in accordance with applicable legal provisions.

(3) If, within the scope of this privacy policy, we use content, tools or resources of other providers (hereinafter collectively referred to as “third-party-providers“) whose registered office is in a third country, it must be assumed that data are transferred to such third countries.

(4) Third countries are countries where the GDPR does not apply directly, i.e., in principle, all countries outside the EU or the European Economic Area. Data may only be transferred to third countries if an adequate level of data protection is ensured, if users have given their consent or if the transfer of such data is permitted by law.

1.7 Obligation to provide personal data

We do not make the conclusion of contracts with us conditional on you providing us with personal data beforehand. In principle, there is no legal or contractual obligation for you as a customer to provide us with your personal data; however, it may be that we can only provide certain offers to a limited extent or not at all if you do not provide the data required for this. If this should exceptionally be the case with the products we offer presented below, you will be informed of this separately.

1.8 Automated decision-making process

We do not intend to use any personal information collected from you for any automated decision-making process (including profiling).

2 Data Processing in Detail

2.1 Collection of access data

(1) When accessing our website, information is automatically transmitted from your browser to us; this includes the name of the website and files that are accessed, the date and time they are accessed, the quantity of data transmitted, reports about successful access, the browser type and version, your operating system, the referrer URL (the page you visited prior to visiting our website), your IP address and the requesting provider.

(2) The processing of your above-mentioned personal data is technically necessary for offering our website as a service to you and is carried out based on our legitimate interests in accordance with Art. 6(1) (f) GDPR regarding the operation of our website and, to ensure the safeguarding of the security of the processing (e.g., to prevent and identify cyber-attacks).

(3) The collection and storage of your personal data in log files is necessary for the provision of the website. For this reason, you may not request the deletion or correction of this data or object to its processing.

2.2 Contacting us

(1) When you contact us (via contact form or e-mail) the request including all resulting personal data (name, request, contact details) will be stored and processed by us for the purpose of processing your request.

(2) This data is processed based on Art. 6 (1) (b) GDPR if the request is related to the fulfillment of an order or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR), if applicable.

(3) Your information may be stored in our customer relationship management systems (“CRM systems”). The legal basis for the further processing of your data is the preparation of a business transaction (in accordance with Art. 6 (1) (f) GDPR).

2.3 Use of cookies

(1) We only use non-essential cookies if you have given your express consent (opt-in) in accordance with § 25 German Telecommunications-Telemedia Data Protection Act (TTDSG). In addition, if you do not want to have cookies stored on your computer you can deactivate the corresponding option in your system settings on their browser. Stored cookies can also be deleted in the browser’s system settings. Disabling cookies may limit the functionalities of this website.

(2) The legal basis for the use of cookies that are required for the technical functionality of the online platform is Art. 6 (1) (f) GDPR. Our legitimate interest is the user-oriented and economically efficient operation of our website.

(3) If you have consented to the storage of cookies or to access information on your end device, both activities are carried out based on § 25 (1) TTDSG.

(4) The legal basis for the data processing of data stored in cookies for the online marketing measures described below is your consent in accordance with Art. 6 (1) (a) GDPR.

2.4 Cookie consent management

(1) We use the cookie consent management tool provided by Cookiebot, a company registered under the trade name Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark. Cookiebot uses technologically required cookies (cookiebot cookie) to manage user consent in order to save the user’s consent to use the cookie. Cookiebot does not process any personal data whatsoever.

(2) The cookie that is stored only contains information about your consent, which was granted or declined when accessing the website. If you later would like to revoke this consent, you can simply delete the cookie in the browser. If you access the website again, the website will ask for you to consent to the cookie again.

(3) We obtain the consent granted by the user so we can use cookies on all web pages in the www.heraeus.com domain.

2.5 Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The Google Tag Manager is a tool that we can use either directly in your browser (client-side tagging) or indirectly cloud-based (server-side tagging) to integrate tracking or statistical tools and other technologies on our website. No user profiles are created by the Google Tag Manager itself, no cookies are set or stored and no independent analyzes are carried out. The Google Tag Manager only serves to manage and display the tools integrated via it. When using the Google Tag Manager, however, your IP address is recorded, which can also be transmitted to Google's parent company in the United States.

With regard to the processing of users' personal data, reference is made to the following information on Google services. Usage guidelines:  https://www.google.com/intl/de/tagmanager/use-policy.html

The Google Tag Manager is used based on your consent under Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. The consent can be revoked at any time for the future.

2.6 Google Analytics

This website uses functions of the web analysis service Google Analytics either directly in your browser (client-side tracking) or indirectly on our webserver (server-side tracking). The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyze the behavior of website visitors.

The website operator receives various usage data, such as page views, length of stay, operating systems used and origin of the user. This data may be summarized by Google in a profile that is assigned to the respective user or their device.

The aim of using Google Analytics is to enable the user to be recognized for the purpose of analyzing user behavior through the use of various technologies (e.g., cookies or device fingerprinting). We use demographic characteristics for our analyses. The information collected by Google about the use of our website is usually transmitted to a Google server in the USA and stored there.

The use of Google Analytics is based on your consent according to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. The consent can be revoked at any time for the future.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:  https://privacy.google.com/businesses/controllerterms/mccs/ .

You can object to the collection and storage of data at any time with effect for the future. You can object to the future collection and storage of your data by Google Analytics by downloading and installing the browser plug-in available under the following link:  https://tools.google.com/dlpage/gaoptout .

We have concluded an order processing contract with Google.

Data stored by Google at the user and event level that is linked to cookies, user identifiers (e.g., User ID) or advertising IDs (e.g., DoubleClick cookies, Android advertising ID) are anonymized after 26 months or deleted. You can find details on this under the following link:  https://support.google.com/analytics/answer/7667196 .

You can find more information about the use of data by Google as well as settings and opt-out options on Google’s websites:  https://www.google.com/intl/de/policies/privacy/partners (“Use of data by Google when using the websites or apps of our partners”),  https://www.google.com/policies/technologies/ads (“Use of data for advertising purposes),  https://www.google.de/settings/ads (“Managing information that Google uses to show you advertising”).

2.7 Google Target Audience

We use Google Analytics (for details please see above) to form target groups, provided you have given your consent to the use of Google Analytics, in order to show the ads that are displayed within the advertising services of Google and its affiliates only to those users who have either shown an interest in our website or who have certain characteristics (e.g., interests in certain topics or products determined from websites visited) and that we have sent to Google (so-called “remarketing” or “Google Analytics Audiences”).

We use Remarketing Audiences to ensure that our ads correspond to the potential interests of users.

The data is processed on the basis of your consent in accordance with Art. 6 (1) (a) GDPR.

You can find more information about the use of data by Google as well as settings and opt-out options on Google’s websites:  https://policies.google.com/technologies/partner-sites (“Use of data by Google when using the websites or apps of our partners”),  https://www.google.com/policies/technologies/ads (“Use of data for advertising purposes),  https://www.google.de/settings/ads (“Managing information that Google uses to show you advertising”).

2.8 Google Display & Video 360

This website uses functions of Google Display and Video 360. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

We use the Google online marketing service “Display & Video 360” to place ads in the Google advertising network (e.g., in search results, in videos, on websites, etc.). Display & Video 360 differs from other services in that it shows real time advertisements based on your presumed interests. This allows us to show ads for and within our website in a more targeted manner so that we only show you those ads that potentially correspond to their interests. When you are shown an ad for products that you have been viewing on other websites, this is referred to as “remarketing”. For these purposes, upon accessing our websites and other websites on which the Google Advertising Network is active, Google will immediately run a code and so-called (re)marketing tags (invisible graphics or code, also known as "web beacons") will be incorporated into the website. With their help, an individual cookie, i.e., a small file, will be saved on the user’s device (comparable technologies may also be used instead of cookies). This file keeps a record of which websites you have visited, what content you are interested in and what offers you have clicked on, as well as technical information about the browser and operating system, websites that have referred you, access duration, and other information regarding the use of our website.

The above information may also be linked with such information from other sources by Google. If you subsequently visit other websites, you may be shown advertisements tailored to your presumed interests on the basis of your user profile.

Your data is processed pseudonymously within the Google Advertising Network. This means that Google does not store and process, for example, your name or email address but instead processes the relevant data using cookies within the pseudonymous user profile. In other words, from the perspective of Google, the ads are not managed and displayed for a person who is concretely identifiable, but rather for the person with the cookie, irrespective of who this person is. This does not apply if you have expressly permitted Google to process the data without pseudonymization. The information about you collected by Google Marketing Services is transmitted to Google and stored on Google servers in the U.S.

The use of Google Remarketing is based on your consent according to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. The consent can be revoked at any time for the future.

You can find more information about the use of data by Google as well as setting and opt-out options in Google’s privacy policy (  https://policies.google.com/technologies/ads s) as well as the settings for showing ads by Google (  https://adssettings.google.com/authenticated ).

2.9 Google (re)marketing services

This website uses functions of Google Analytics Remarketing. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Remarketing analyzes your user behavior while visiting our website in order to classify you into certain advertising target groups in order to show you suitable web messages when you visit other online offers (remarketing or retargeting).

Furthermore, the advertising target groups created with Google Remarketing can be linked to Google's cross-device functions. In this way, interest-related, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one end device (e.g. mobile phone) can also be displayed on another of your end devices (e.g. tablet or PC).

If you have a Google account, you can object to personalized advertising using the following link:  https://www.google.com/settings/ads/onweb/ .

The use of Google Remarketing is based on your consent according to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. The consent can be revoked at any time for the future.

Further information and the data protection regulations can be found in Google's data protection declaration at:  https://policies.google.com/technologies/ads .

2.10 Google reCAPTCHA

We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on this website. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

With reCAPTCHA we want to check whether the data entry on our website is done by a human or by an automated program. To do this, Google reCAPTCHA analyzes your surfing behavior based on various characteristics. This analysis starts automatically as soon as you enter our website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, how long you have stayed on our website or the mouse movements you have made). The data collected during the analysis is forwarded to Google.

The reCAPTCHA analyzes run completely in the background. When you visit our website, you will not be explicitly informed that an analysis is taking place.

The service involves the transmission of your IP address and other data required by Google for the reCAPTCHA service to Google and is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in identifying individual responsibility on the internet and avoiding abuse and spam. Within the framework of the use of Google reCAPTCHA your personal data may be transmitted to Google LLC servers in the U.S.

Further information on Google reCAPTCHA can be found in the Google data protection regulations and the Google terms of use under the following link:  https://policies.google.com/privacy

2.11 LinkedIn Lead Gen Form

As part of our use of LinkedIn, a service offered by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, we use so-called Lead Gen Forms.

Lead Gen Forms are ad placements that enable the integration of contact forms in sponsored content directly on the platform. We use the data you provide there to process your request for information. This data is transmitted to us by LinkedIn.

Our processing of the data is based exclusively on your consent (Art. 6 (1) (a) GDPR). You can revoke this consent for the future at any time. For this purpose, a communication by email to  socialmedia@heraeus.com is sufficient. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.

The data you entered will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g., after we have completed processing your request). Mandatory legal provisions - in particular retention periods - remain unaffected.

The specific purpose of the data processing of the respective Lead Gen Forms is explicitly listed in the context of the advertisement (e.g., sending product information or contacting you for the purpose of answering your inquiry).

2.12 LinkedIn Insight Tag

We use the service LinkedIn Insight Tag, provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, to measure conversions.

This tool creates a cookie on your web browser. We set the cookie exclusively with your consent in accordance with § 25 (1) TTDSG. The processing of the data is based exclusively on your consent (Art. 6 (1) (a) GDPR).

The cookie enables the collection of data regarding LinkedIn member’s visits on our website including the URL, referrer, IP address, device and browser characteristics (User Agent), and timestamp. The IP addresses are truncated or hashed (when used for reaching LinkedIn members across devices), and LinkedIn members’ direct identifiers are removed within seven days in order to make the data pseudonymous. This remaining pseudonymized data is then deleted within 180 days.

LinkedIn does not share any personal data with us, but offers anonymous reports on website audience and display performance.

LinkedIn members can control the use of their personal data for advertising purposes through their account settings:  https://www.linkedin.com/psettings/advertising/actions-that-showed-interest

Further information on data protection at LinkedIn can be found in LinkedIn's data protection information:  https://www.linkedin.com/legal/privacy-policy

2.13 LinkedIn Retargeting

We use the LinkedIn remarketing provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, to display our advertising to a dedicated target group.

We use LinkedIn to show the advertisements displayed within LinkedIn advertising services and its affiliates only to those users who have also shown an interest in our website or who have certain characteristics (e.g., interests in specific themes or products that are determined from the websites visited), which we submit to LinkedIn (so-called "remarketing"). We use LinkedIn to ensure that our ads correspond to the potential interests of users.

In addition, LinkedIn offers the possibility of retargeting via the Insight Tag. We can use this data to display targeted advertising outside of our website without identifying you as a website visitor.

The processing of the data is based exclusively on your consent (Art. 6 (1) (a) GDPR). You can revoke this consent for the future at any time by changing the Heraeus cookie settings:  https://www.heraeus.com/en/group/heraeus_group/cookie.html

LinkedIn members can control the use of their personal data for advertising purposes through their account settings:  https://www.linkedin.com/psettings/advertising/actions-that-showed-interest

Further information on data protection at LinkedIn can be found in LinkedIn's data protection information:  https://www.linkedin.com/legal/privacy-policy

2.14 Microsoft Dynamics 365 Cloud for Marketing

We use the Microsoft Dynamics 365 Cloud for Marketing automation system provided by Microsoft Corporation (Microsoft Deutschland GmbH, Walter-Gropius-Straße 5, 80807 Munich, Germany) – hereafter referred to as “Microsoft” – to carry out marketing campaigns, for analysis purposes and for target group-specific contact with customers and potential customers. The data is processed within the European Union.

In particular, we use the system to send email communications (e.g., in connection with the provision of downloads), for event management (e.g., to manage event participants) and to provide landing pages and contact forms.

The use of Microsoft and the system, the collection and analysis of statistics and the logging of the registration procedure for communication by email are carried out based on your consent to receive email communication via Microsoft Dynamics 365 Cloud for Marketing according to Art. 6 (1) (a) GDPR, according to Art. 6 (1) (f) GDPR regarding the download of Whitepapers and according to § 25 (1) TTDSG regarding the use of cookies. The consent can be revoked at any time for the future. We are interested in a user-friendly and secure system that both serves our business interests and also meets the expectations of users.

System components integrated in our website (e.g., forms) use so-called “cookies” that are stored on the user’s computer and enable us to analyze the use of the website.

In particular, the following information is collected: client ID, geographical location, browser type, duration of the visit and pages accessed.

Pseudonymized email tracking: The statistical information collected also includes whether the newsletter was opened, when it was opened, and which links you clicked on. While this information can technically be attributed to individual newsletter recipients, the analysis of personal data has been deactivated and information about newsletter recipients is only analyzed pseudonymously and cannot be decrypted and attributed to individual users.

Double opt-in and recording of data: Subscribing to our newsletter is subject to a so-called double opt-in process. This means that after subscribing for our newsletter you receive an email in which you are asked to confirm your subscription. Such confirmation is necessary to ensure that people do not subscribe using someone else’s email address. The newsletter subscription is logged so the subscription process can be verified in accordance with legal requirements. This includes recording the date and time of the subscription and the confirmation as well as the IP address. The changes to your data saved by the email marketing service provider are also logged.

Unsubscribe: You can unsubscribe from the newsletter at any time, i.e., you can revoke your consent to receive it. There is an unsubscribe link at the end of each newsletter. Your personal data that has been processed in connection with the mailing of the newsletter will be deleted after you unsubscribe.

Further data privacy information can be found in the Microsoft privacy policy at  https://privacy.microsoft.com/en-US/privacystatement .

Further information about the use of cookies in connection with the system can be found at  https://docs.microsoft.com/en-US/dynamics365/marketing/cookies .

3 CRM Systems

3.1 Microsoft Dynamics 365

We use the Microsoft Dynamics 365 CRM system from Microsoft Corporation (One Microsoft Way, Redmond, WA 98052-6399, United States) – hereafter referred to as Microsoft – as a cloud service, i.e., the data is processed at Microsoft data centers.

We use your data solely for the technical processing of requests and we do not disclose the data to third parties.

In particular, we use the system to manage customers and prospective customers (leads) and to process user requests faster and more efficiently. The use of the system is based on our legitimate interest in accordance with Art. 6 (1) (f) GDPR.

Further data privacy information can be found in the Microsoft privacy policy at  https://privacy.microsoft.com/en-US/privacystatement .

3.2 Salesforce

We use the Salesforce CRM system from Salesforce.com Germany GmbH (Erika-Mann-Str. 31, 80636 Munich, Germany) – hereafter referred to as “Salesforce” – as a cloud service, i.e., the data is processed at Salesforce data centers. Salesforce stores personal data mainly in the U.S.

Salesforce only uses user data for the technical processing of requests.

In particular, we use the system to manage customers and prospective customers (leads) and to process user requests faster and more efficiently. The use of the system is based on our legitimate interest in accordance with Art. 6 (1) (f) GDPR.

Further data privacy information can be found in the Salesforce privacy policy at  https://www.salesforce.com/company/privacy/

4 Online Presence in Social Media

(1) We maintain a presence in social networks and platforms in order to be able to communicate with active customers, interested parties and users who are active there and to provide information to users there about our services.

(2) Please note that user data may be processed outside of the European Union and Switzerland. This may imply risks for users because, for example, it could be more difficult to enforce user rights.

(3) In addition, user data is generally processed for market research and advertising purposes. For example, user behavior and the resulting information about the user’s interests can be used to create user profiles. The user profiles can, in turn, be used to place advertisements, for example, within and outside of platforms that are supposedly in line with user interests. For these purposes, cookies that record the user’s behavior and interests are generally stored on the user’s computer. In addition, data can also be stored in the user profiles separately from the users' devices (in particular if the users are members of the relevant platforms and are logged in to them).

(4) The personal data of users is processed on the basis of our legitimate interests in providing effecting information to users and communicating with users. If the users are asked to consent to data processing by the respective providers (i.e., give their consent, for example, by clicking a check box or pressing a button), the legal basis of the processing is consent.

(5) For a detailed overview of the processing and opt-out options discussed in this paragraph, see the information from the provider in the following link:

• Facebook (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland)

a.) Privacy policy:  https://www.facebook.com/about/privacy/

b.) Opt-out:  https://www.facebook.com/settings?tab=ads

• Google/YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)

a.) Privacy policy:  https://policies.google.com/privacy

b.) Opt-out:  https://adssettings.google.com/authenticated

• Twitter (Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, United States)

a.) Privacy policy:  https://twitter.com/de/privacy

b.) Opt-out:  https://twitter.com/personalization

• LinkedIn (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland)

a.) Privacy policy:  https://www.linkedin.com/legal/privacy-policy

b.) Opt-out:  https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out

• XING (XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany)

Privacy policy/opt-out:  https://privacy.xing.com/en .

Please note that if you are looking for information or asserting your rights, it is best to contact the respective provider directly. Only the providers have access to your data and can take appropriate measures and provide information. You can contact us if you still need assistance.

5 Conducting Webinars

(1) A webinar is comparable to a face-to-face seminar and takes place on the internet with computer / software support.

(2) Heraeus uses the GoToWebinar software from LogMeIn Ireland Limited to process customer webinars (processor). As part of the registration on the infrastructure of LogMeIn (Bloodstone Building Block C70 Sir John Rogerson’s Quay Dublin 2, Ireland), personal data is collected / stored.

(3) The legal basis for data processing is Art. 6 (1) (f) GDPR. The data is processed within the legally permissible framework in Germany, the European Union and the USA.

(4) For the order-related implementation of the webinar, we transmit your registration or customer data to LogMeIn, Inc. For this purpose, the following data is requested: first name, last name, company name, zip code, e-mail address, telephone (optional).

An appropriate level of protection has been established for data processing in the USA through agreement of the EU standard contractual clauses. Please also note the data protection regulations of LogMeIn:  https://www.logmeininc.com/gdpr/gdpr-compliance

6 Conducting Customer Surveys with Survey Tools

(1) Heraeus collects feedback from its customers at regular intervals and on various occasions. We use your data to contact you to ask you to take part in the survey. Participation in customer surveys is always voluntary.

(2) Heraeus uses the following survey tools (data processors) to conduct customer surveys:

Survey Monkey software of the provider SurveyMonkey Europe UC (Shelbourne Road, Dublin, Ireland). Please note their privacy policy and find more information about it at the following link:  https://en.surveymonkey.com/mp/legal/privacy/ .

Dynamics Customer Voice" of the provider Microsoft Corporation (One Microsoft Way, Redmond, WA 98052-6399, USA) - hereinafter "Microsoft" - as a cloud service.

Users can find further information on data protection in Microsoft's privacy policy at  https://privacy.microsoft.com/en-gb/privacystatement .

Personal data may be collected / stored when processing the survey.

(3) The legal basis for data processing is Art. 6 (1) (f) GDPR. For the processing of data by the providers of external survey tools, corresponding contracts for commissioned processing have been concluded in accordance with Art. 28 of the GDPR or EU standard contractual clauses (SCC) in the respective valid version, provided that the processing takes place outside the EU, the European Economic Area or countries that offer an appropriate level of security.

(4) For the purpose of conducting the survey, in most cases we create an ID for your questionnaire, through which we can assign your answers to a specific process and thus usually also to your person. In doing so, we do not transmit your personal data to the provider of the survey tool. If the invitation to the survey already takes place via the provider's software, we transmit your business contact data to the provider in advance: First name, last name, company name, e-mail address.

(5) Personal data, e.g., your interest in products, your assessment of your experience with Heraeus or your telephone number for queries, may also be collected in the course of the survey. We will use your answers to continuously improve our offer - if necessary, also in cooperation with you. In the course of this, we will contact you - if there is a reason to do so, for example because you have expressed a wish, a suggestion or an expectation. If, as part of the survey, you take part in a raffle offered by us, we may also use your data to contact you as part of the raffle in order to inform you of any prize that may have been won and to coordinate the further procedure in this regard with you.

(6) If you would like your answers to be deleted after the survey has started or even after you have sent them, you can inform us of this at any time - for example, in response to your invitation to the survey. We will then immediately delete your answers from the survey tool and - provided they have been forwarded and there are no legal requirements to the contrary - from our systems. Irrespective of this, your data will be deleted at the latest in accordance with the statutory deletion periods stored in our systems.

7 Changes to the Privacy Policy

(1) We reserve the right to change the privacy policy in order to adapt to changes in the legal situation or to changes in our services and data processing. However, this only applies to policies regarding data processing.

(2) If the consent of the user is required or if elements of the privacy policy contain components of the contract agreed the user, the changes will only be made with the user's consent.

(3) Users are requested to familiarize themselves regularly with the content of the privacy policy.

Last updated: 4th of August 2022

Version: web-2.0

Special information for United Kingdom

Further information can be found under http://www.google.com/analytics/terms/gb.html (Google Analytics Terms of Service & Privacy).

Please note that on this website, Google Analytics code is supplemented by “gat._anonymizeIp();” to ensure an anonymized collection of IP addresses (so called IP-masking).