General Privacy Notice
(Data protection information pursuant to Art. 13 and 14 GDPR)
We take the protection of your personal data very seriously and treat your personal data confidentially and in accordance with statutory data protection requirements and this Privacy Notice.
This Privacy Notice explains how GURTEC GmbH processes personal data in connection with enquiries, quotations, orders, contracts, projects, supplier and customer relationships, business communications, direct marketing and, where applicable, applications.
Supplementary or overriding privacy notices may apply to the use of our website, the whistleblowing system or other specific procedures.
1. Controller
GURTEC GmbH
Represented by the Managing Director
Gurtecstraße 3
38170 Schöppenstedt
Phone: +49 5332 9309-0
Email: info@gurtec.com
2. Data Protection Officer
Dr. Hufenbach Consulting GmbH
Düstere-Eichen-Weg 50
37073 Göttingen
Phone: +49 551 383310
Email: dsb@hufenbach.de
You may contact either GURTEC GmbH or the Data Protection Officer directly with data protection questions or to exercise your rights.
3. To whom does this Notice apply?
This Notice is intended in particular for natural persons who
- are themselves customers, suppliers, service providers, sales partners or other business partners,
- act as employees or other contact persons for a company or organisation,
- submit an enquiry, request a quotation, participate in a project or correspond with us,
- receive marketing information or a newsletter, or
- apply directly to us, provided that no separate applicant information is made available for this purpose.
4. Categories of personal data
Depending on the context and business relationship, we process, in particular, the following categories of data:
- Master and contact data: e.g. name, address, email address, telephone number, form of address and language.
- Professional and organisational data: e.g. company, role, department, area of responsibility and business contact details.
- Contract, order and project data: e.g. quotations, orders, contractual relationship, products, deliveries, services, project information, complaints and customer or supplier history.
- Communication and documentation data: e.g. content of emails, letters, meeting notes, appointment and process documentation.
- Billing, payment and creditworthiness data: e.g. bank details, invoices, payment behaviour and, where necessary, creditworthiness information.
- Marketing data: e.g. interests, preferences, records of consent and objections, and responses to marketing activities, insofar as this has been transparently communicated and is legally permissible.
- Technical and security data: e.g. user identifiers, access and log data, device or connection information to ensure secure IT operations.
- Application data: e.g. CV, qualifications, certificates, professional history, interview notes and salary expectations, if you apply to us.
We process special categories of personal data within the meaning of Art. 9 GDPR only if this is necessary in an individual case and legally permitted or if explicit consent has been given.
5. Source of the data
Depending on the case, we receive personal data
- directly from you, e.g. through enquiries, orders, contracts, conversations, forms or application documents,
- from your employer or another business partner if you have been named there as a contact person,
- from companies of the NEPEAN Group, sales partners or other parties involved in a business or project process,
- from publicly accessible sources, e.g. company websites, commercial and company registers or professional networks, and
- where necessary and permissible, from credit agencies, banks, insurance companies, authorities, courts or other third parties.
Where your data is not collected directly from you, we will inform you in accordance with Art. 14 GDPR. We will provide the specific source upon request, unless statutory restrictions prevent this.
6. Processing activities
6.1 Data protection in connection with enquiries, contract initiation and contract performance
6.1.1 Purposes and legal basis of processing
We process data to handle enquiries, prepare and review quotations, process orders and perform contracts, coordinate projects, deliver goods, provide services, handle billing, payment and complaints, and support customers, suppliers and other business partners.
Your personal data is processed:
- on the basis of Art. 6(1)(b) GDPR if you are a party to the contract or if pre-contractual measures are taken at your request,
- on the basis of Art. 6(1)(f) GDPR if you act as a contact person for a legal entity or organisation; our legitimate interest lies in the efficient initiation, performance and documentation of the business relationship,
- on the basis of Art. 6(1)(c) GDPR insofar as statutory evidence, retention, audit, tax, commercial-law or other cooperation obligations apply, and
- on the basis of Art. 6(1)(a) GDPR insofar as we ask you for consent in an individual case.
6.2 Data protection in connection with business communications and contact management
6.2.1 Purposes and legal basis of processing
We process contact data and communication content in order to manage contacts, conduct business correspondence, organise appointments and meetings, document processes and coordinate collaboration.
Depending on the context, the legal bases are Art. 6(1)(b), (c) or (f) GDPR. Our legitimate interests are reliable communication, orderly business operations, maintaining business relationships and documenting business processes.
6.3 Data protection in connection with credit checks, receivables management and legal enforcement
6.3.1 Purposes and legal basis of processing
Where necessary to establish or conduct a business relationship, we may obtain creditworthiness information, determine payment terms, process outstanding receivables and use data for the establishment, exercise or defence of legal claims.
Processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interests lie in avoiding payment defaults, securing our claims and defending our legal interests. Where a statutory obligation exists, Art. 6(1)(c) GDPR applies.
6.4 Data protection in connection with marketing, including newsletters
6.4.1 Purposes and legal basis of processing
We may use contact data to provide information about our own products, services, events or comparable business topics and to maintain existing customer relationships.
- Electronic advertising is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 7 UWG or, for existing customers and where all statutory requirements are met, on the basis of Art. 6(1)(f) GDPR in conjunction with Section 7(3) UWG.
- Postal direct advertising and individual approaches relating to an existing business relationship may be based on Art. 6(1)(f) GDPR. Our legitimate interest lies in providing information about our range of services and maintaining business relationships.
- You may withdraw consent at any time with effect for the future. You may object at any time to the use of your data for direct advertising without stating reasons.
6.5 Data protection in connection with applications
6.5.1 Purposes and legal basis of processing
If you apply directly to us and no separate applicant information is provided, we process your data to carry out the application process, communicate with you, assess your suitability and decide on the establishment of an employment relationship.
The legal bases are Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG. Insofar as special categories of personal data must be processed, Art. 9(2)(b) GDPR may apply. Your consent pursuant to Art. 6(1)(a) GDPR is the legal basis for voluntary inclusion in an applicant or talent pool.
6.6 Data protection in connection with IT security, abuse prevention and internal organisation
6.6.1 Purposes and legal basis of processing
We process technical and organisational data to provide and secure our systems, manage users and authorisations, analyse errors, defend against attacks and abuse, and conduct internal audits and compliance activities.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interests are the secure and uninterrupted operation of our IT, the protection of trade secrets and personal data, and the prevention and investigation of security incidents. Where statutory obligations exist, we process data pursuant to Art. 6(1)(c) GDPR.
7. Recipients of personal data
Within GURTEC GmbH, only those departments that require the data for the stated purposes receive access. In addition, data may be transferred, in each case only where necessary and legally permissible, to the following categories of recipients:
| Recipient category | Within GDPR scope | Third country (possible) |
| Within the company, to the competent specialist departments | ☒ | ☐ |
| Companies of the NEPEAN Group | ☒ | ☒ – depending on group location |
| Processors and IT service providers, e.g. hosting, cloud, email, ERP/CRM, support, IT security, archiving, marketing or newsletter services | ☒ | ☒ – depending on provider and location |
| Business and project partners, e.g. customers, suppliers, sales partners, subcontractors and technical service providers | ☒ | ☒ – depending on project and recipient |
| Logistics, payment and financial partners, e.g. transport and logistics companies, banks, insurance companies, credit agencies and debt collection service providers | ☒ | ☒ – depending on process and recipient |
| Advisers and audit bodies, e.g. tax advisers, auditors, lawyers and data protection and compliance advisers | ☒ | ☐ |
| Public bodies, e.g. authorities and courts, where there is a statutory obligation or for legal enforcement | ☒ | ☐ |
We conclude the required data processing agreements with processors pursuant to Art. 28 GDPR. Where purposes and means are jointly determined, we enter into an arrangement pursuant to Art. 26 GDPR where required.
The specific recipient category and country allocation depend on the respective processing operation.
8. Transfers to third countries
Due to our international business activities and our membership of the globally active NEPEAN Group, it may be necessary in individual cases to transfer personal data to recipients outside the EU or to enable them to access it.
Such transfers take place only in compliance with Art. 44 et seq. GDPR:
- If an adequacy decision of the European Commission exists for the recipient country or the specific recipient, we base the transfer on Art. 45 GDPR.
- Otherwise, we use appropriate safeguards under Art. 46 GDPR, in particular the standard contractual clauses adopted by the European Commission, and take supplementary technical, contractual or organisational measures where necessary.
- A transfer may be based on Art. 49 GDPR only in exceptional cases provided for by law.
9. Retention and deletion
We retain personal data only for as long as this is necessary for the respective purpose. We then delete or anonymise the data unless statutory retention obligations, legitimate documentation interests or ongoing legal disputes prevent this.
- Contract and business data: for the duration of the business relationship and beyond in accordance with statutory retention periods. Documents relevant under commercial and tax law must generally be retained for six, eight or ten years, depending on the type of document (Section 257 HGB, Section 147 AO).
- Legal claims: insofar as data is required for asserting or defending claims, generally until the expiry of the relevant limitation periods; the regular limitation period is three years and generally begins at the end of the respective calendar year.
- Enquiries and business correspondence: until final processing and thereafter only for as long as documentation of the process or the protection of legal interests is required.
- Marketing data: until consent is withdrawn, until you object to direct advertising or until the marketing purpose no longer applies. Records of consent, withdrawals or objections may be retained for longer in order to fulfil accountability and evidence obligations.
- Application data: in the event of a rejection, generally for up to six months after completion of the application process; in the event of hiring, required data will be transferred to the personnel file. We store data in a voluntary talent pool until consent is withdrawn or until the notified period expires.
- Technical log data: in accordance with the respective security and deletion concept, only for as long as this is required for operation, error analysis and IT security.
10. Rights of data subjects
Where the statutory requirements are met, you have in particular the following rights:
- access to the data processed concerning you and further information pursuant to Art. 15 GDPR,
- rectification of inaccurate data and completion of incomplete data pursuant to Art. 16 GDPR,
- erasure pursuant to Art. 17 GDPR,
- restriction of processing pursuant to Art. 18 GDPR,
- data portability pursuant to Art. 20 GDPR, insofar as the processing is based on consent or contract and is carried out by automated means, and
- the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.
11. Withdrawal of consent and objection
Where you have given us consent to process personal data, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
If we process your data on the basis of Art. 6(1)(e) or (f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims.
You may object at any time to the processing of your data for direct advertising without stating reasons. After such an objection, we will no longer use the data concerned for direct advertising.
Withdrawals and objections may be submitted using the contact details stated in Section 1 or Section 2.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
The State Commissioner for Data Protection of Lower Saxony
Prinzenstraße 5
30159 Hannover
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
You may also contact another competent data protection supervisory authority, in particular at your habitual residence, your place of work or the place of the alleged infringement.
13. Requirement to provide data
In the context of contract initiation or a business relationship, you must provide the data required to carry out pre-contractual measures, conclude and perform the contract, or which we are legally obliged to collect. Without this data, we may be unable to process an enquiry or establish or conduct a business relationship. There is no obligation to provide data for marketing purposes.
14. Automated decision-making and profiling
Within the scope of the processing described in this Privacy Notice, we generally do not make decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR. Profiling for such purposes generally does not take place. If a specific procedure deviates from this, we will inform you separately.
15. Communication by email
When information is transmitted via ordinary email systems, full end-to-end encryption cannot be guaranteed in every case. Please send particularly confidential or sensitive information only via a secure transmission channel agreed in advance.
16. Current version of this Privacy Notice
We will update this Privacy Notice if processing activities, legal requirements or our organisation change. The current version applies in each case.
As of: 17 July 2026