Privacy Policy

1. Introduction

This website is operated by HOF Automotive GmbH. We attach great importance to handling the data of our website visitors responsibly and protecting it in the best possible way. For this reason, we make every effort to comply with the requirements of the GDPR.

In the following, we explain how we process your data on our website. We use clear and transparent language so that you can truly understand what happens to your data.

2. General Information

2.1 Processing of Personal Data and Other Terms

Data protection applies to the processing of personal data.

“Personal data” means all data that can identify you personally. This includes, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently using.

Such data is processed whenever “something happens to it.” For example, when your browser transmits your IP address to our provider and it is automatically stored there – that already constitutes processing (according to Art. 4 No. 2 GDPR) of personal data (as defined in Art. 4 No. 1 GDPR).

These and other legal definitions can be found in Art. 4 GDPR.

2.2 Applicable Regulations / Laws – GDPR, BDSG and TDDDG

The scope of data protection is governed by laws – in particular:

  • the General Data Protection Regulation (GDPR) as an EU regulation
  • the Federal Data Protection Act (BDSG) as a national law
  • the Telecommunications and Telemedia Data Protection Act (TDDDG), which complements the GDPR where cookies or similar technologies are used.

2.3 Data Controller

The controller responsible for data processing on this website is the entity that, alone or jointly with others, determines the purposes and means of processing personal data.

Controller:

HOF Automotive GmbH
Fronäckerstraße 44
71063 Sindelfingen
Germany

E-mail: contact@h-o-f.com
Web: https://h-o-f.com

2.4 Data Protection Officer

We have appointed a Data Protection Officer for our company:

simply Legal GmbH
Attn: Sebastian Schenk
Burkarderstr. 36
97082 Würzburg
Germany

E-mail: dpo@dieter-datenschutz.de

2.5 How Data Is Generally Processed on This Website

Certain data (such as IP addresses) are automatically collected when you visit our website. These data are mainly required for the technical provision and secure operation of the website.

If we process additional personal data or collect other data, we will inform you accordingly or request your consent.

Other personal data are deliberately shared by you, for example when you use our contact form. You can find detailed information about this below.

2.6 Your Rights

The GDPR grants you comprehensive rights, such as the right to receive free information about the origin, recipients and purpose of your stored personal data.

You also have the right to request rectification, restriction or deletion of this data and to lodge a complaint with the competent data protection authority. Any consent you have given can be withdrawn at any time with effect for the future.

Details on your rights and how to exercise them can be found in Section 6 of this Privacy Policy.

2.7 Our View on Data Protection

For us, data protection is more than just a legal obligation.

Personal data has great value, and careful handling of such data should be a matter of course in today’s digital world. Furthermore, as a website visitor, you should be able to decide what happens to your data, when, and by whom.

Therefore, we commit to complying with all legal requirements, collecting only the data necessary for us, and treating it confidentially.

2.8 Data Sharing and Deletion

We only share personal data where there is a legal basis for doing so and only to the extent necessary – for example when we work with processors under a data processing agreement pursuant to Art. 28 GDPR (e.g. hosting provider, technical service providers, CRM provider).

We delete your data once the purpose and legal basis for processing no longer exist and there are no other legal obligations preventing deletion (e.g. commercial or tax retention periods). For more details, see Art. 17 GDPR.

2.9 Hosting and Technical Service Providers

This website is hosted on servers of our hosting provider:

Mittwald CM Service GmbH & Co. KG
Königsberger Str. 4–6
32339 Espelkamp
Germany

The personal data collected on this website are stored on Mittwald’s servers – including automatically collected log files (see below) and any other data you provide via forms.

We also work with our digital agency neusta for development, maintenance and technical operation of the website. neusta may have access to personal data in the course of providing these services and acts as a processor under our instructions.

External hosting ensures the secure, fast and reliable provision of our website and serves to fulfil contractual obligations towards potential and existing customers.

The legal basis for processing is Art. 6 (1)(b) GDPR (contract performance) and Art. 6 (1)(f) GDPR (legitimate interest in secure and efficient website operation). Where consent is required for the storage of or access to information on the user’s device (e.g. cookies), § 25 (1) TDDDG and Art. 6 (1)(a) GDPR apply.

We have concluded data processing agreements with our hosting provider and technical service providers.

2.10 Legal Bases

Processing personal data always requires a legal basis. Article 6 (1) GDPR provides the main options:

  • (a) Consent
  • (b) Contract performance or pre-contractual measures
  • (c) Legal obligation
  • (d) Vital interests
  • (e) Public interest / exercise of official authority
  • (f) Legitimate interests, except where overridden by your interests or fundamental rights and freedoms.

In the following sections, we specify the exact legal basis for each type of processing.

3. What Happens on Our Website

By visiting our website, we process certain personal data from you. To protect this data as best as possible against unauthorized access by third parties, we use SSL/TLS encryption. You can recognize an encrypted connection by the prefix “https://” in your browser’s address bar or by a lock symbol.

Below you will find which data are collected when you visit our website, for what purpose, and on what legal basis.

3.1 Data Collection When Accessing the Website (Server Log Files)

When you access the website, information is automatically stored in so-called server log files. This includes:

  • browser type and version
  • operating system used
  • referrer URL
  • hostname of the accessing computer
  • time of the server request
  • IP address

These data are temporarily required to ensure that our website is displayed permanently and without errors. They serve in particular the following purposes:

  • system security
  • system stability
  • error detection and correction
  • establishing a connection to the website
  • proper display of the website

Data processing is carried out in accordance with Art. 6 (1)(f) GDPR, based on our legitimate interest in ensuring the website’s functionality and security.

Wherever possible, these data are stored in a pseudonymized form and deleted after their intended purpose is achieved. If the server log files allow identification of the data subject, the data are stored for a maximum of 14 days, unless a security-related incident requires longer storage.

There is no merging of this data with other data sources.

3.2 Cookies

3.2.1 General Information

This website uses cookies and similar technologies. Cookies are small text files stored in your browser that relate to our website.

The use of cookies can make it easier for visitors to navigate and use our website and allows us to perform statistical and marketing analyses.

We use a cookie-consent tool (consent management platform, “CMP”) that informs you in detail about all cookies and similar technologies used on our site and allows you to manage your preferences.

3.2.2 Rejecting Cookies

All cookies that are not technically necessary can be managed directly through our cookie-consent tool. You can withdraw your consent at any time with effect for the future.

You can also prevent the storage of cookies by adjusting your browser settings. Please note that blocking or deleting cookies completely may restrict website functionality.

3.2.3 Technically Necessary Cookies

We use technically required cookies to ensure that our website functions properly and complies with applicable law (e.g. consent management, security, session handling).

Legal basis: Art. 6 (1)(b), (c) and/or (f) GDPR, depending on context.

3.2.4 Non-Essential Cookies (Analytics and Marketing)

We also use cookies that are not technically necessary, for example to analyse user behaviour (Google Analytics) or for marketing purposes (Meta Pixel).

These cookies are only set if you have given your consent via the cookie-consent tool.

Legal basis: Art. 6 (1)(a) GDPR in conjunction with § 25 (1) TDDDG.

You can withdraw your consent at any time via the cookie-consent tool.

3.3 Data Processing Through User Input

3.3.1 Contact by E-mail or Phone

If you contact us by e-mail or phone, we process your contact details and any other data you provide (e.g. name, company, phone number, content of the enquiry).

Depending on the context, the legal basis is Art. 6 (1)(b) GDPR (contract-related communication or pre-contractual measures) or Art. 6 (1)(f) GDPR (our legitimate interest in processing inquiries).

Data will be deleted once the matter has been conclusively dealt with and there are no legal obligations requiring longer storage.

3.3.2 Contact Form

If you use our contact form, we process the data you enter (e.g. name, e-mail address, phone number, subject, message).

These data are stored on our web server and transmitted internally to the relevant contact persons. In addition, they are stored in our Odoo CRM system (see Section 4.2).

Legal basis: Art. 6 (1)(b) GDPR (pre-contractual measures / contract performance) and Art. 6 (1)(f) GDPR (efficient handling of inquiries).

We delete these data once your request has been processed and provided there are no legal retention obligations.

3.4 Cookie-Consent Tool (Consent Management Platform)

To ensure that only cookies and tools that require consent are activated after you have given your consent, we use a consent management platform (CMP). This tool stores your consent or refusal and documents it in compliance with data protection regulations.

For this purpose, a connection to the CMP provider’s servers is established and a cookie is stored in your browser to assign your choices.

Legal basis: Art. 6 (1)(c) GDPR (legal obligation to obtain and document consent) and Art. 6 (1)(f) GDPR (legitimate interest in legally compliant consent management).

The consent data are stored for as long as necessary for documentation purposes and will then be deleted, unless statutory retention obligations require longer storage.

4. Analytics, CRM and Marketing Tools

4.1 Google Analytics

We use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses cookies that allow analysis of how visitors use the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.

We use IP anonymisation, which shortens your IP address before transmission within EU/EEA countries. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there.

The data collected are used to evaluate visitor behaviour, compile reports and improve our online offering.

Legal basis: your consent under Art. 6 (1)(a) GDPR and § 25 (1) TDDDG. You can withdraw your consent at any time via the cookie-consent tool.

We have concluded EU Standard Contractual Clauses (SCCs) with Google to ensure an adequate level of data protection.

Further information: https://policies.google.com/privacy

4.2 Odoo CRM

We use Odoo as our customer relationship management (CRM) system:

Odoo S.A.
Chaussee de Namur 40
1367 Ramillies
Belgium

In Odoo we store contact and customer data that arise, for example, from contact forms, e-mails, telephone calls or contractual relationships (e.g. name, contact data, company, communication history, contract data).

Legal bases:

  • Art. 6 (1)(b) GDPR (contract performance and pre-contractual measures)
  • Art. 6 (1)(f) GDPR (legitimate interest in efficient customer and lead management)

Data are stored for as long as necessary for the relevant purpose (e.g. contract performance, customer support) and as long as legal retention obligations exist.

Further information: https://www.odoo.com/privacy

4.3 Meta (Facebook) Pixel

We use the Meta Pixel from Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

This tool helps us measure the effectiveness of Meta ads (e.g. Facebook / Instagram) by tracking user actions after viewing or clicking an ad (conversions).

The collected data (e.g. IP address, browser information, referrer URL, time of visit, actions on the website) can be stored and processed by Meta and may be linked to your Meta account and used for Meta’s own advertising purposes.

Legal basis: your consent under Art. 6 (1)(a) GDPR and § 25 (1) TDDDG. You can withdraw your consent at any time via the cookie-consent tool.

Data processing by Meta may take place in the USA. Meta is certified under the EU–US Data Privacy Framework. Further information: https://www.facebook.com/about/privacy/

5. Social Media

We maintain online presences on various social networks (e.g. Facebook, Instagram, LinkedIn, YouTube) to communicate with users and provide information about our company.

When you visit these platforms, the respective providers process personal data in their own responsibility. We have no control over these data processing operations.

Our own processing (e.g. when we evaluate comments or messages) is based on Art. 6 (1)(f) GDPR (legitimate interest in communication and public presence).

For details on data processing by the platform providers, please refer to their respective privacy policies.

6. Rights of Data Subjects

As a user of this website, you have various rights under the GDPR:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (“right to be forgotten”, Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7 (3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

To exercise your rights, you can contact us or our Data Protection Officer at any time using the contact details provided above.

7. Data Retention Period

Personal data are stored only as long as necessary for the purpose of processing, unless:

  • statutory retention obligations require longer storage (e.g. commercial or tax law),
  • you have consented to longer storage, or
  • we have a legitimate interest in longer storage (e.g. legal defence).

Once the relevant purpose ceases to apply and there are no retention obligations, your data will be deleted or anonymised.

8. Data Security

We use appropriate technical and organisational measures (TOMs) to protect your data against accidental or intentional manipulation, loss, destruction or unauthorised access.

Our website uses SSL/TLS encryption for secure data transmission. Nevertheless, we would like to point out that data transmission over the Internet (e.g. communication by e-mail) can have security gaps and cannot be fully protected against access by third parties.

9. Changes to This Privacy Policy

We reserve the right to update or amend this Privacy Policy at any time, in order to comply with current legal requirements or to reflect changes to our services.

The new Privacy Policy will apply from the time it is published on our website. The current version is always available under the menu item “Privacy Policy”.

10. Contact

Controller

HOF Automotive GmbH
Fronäckerstraße 44
71063 Sindelfingen
Germany

E-mail: contact@h-o-f.com

Data Protection Officer

simply Legal GmbH
Attn: Sebastian Schenk
Burkarderstr. 36
97082 Würzburg
Germany

E-mail: dpo@dieter-datenschutz.de