Privacy Policy
ZESS Privacy Policy in Accordance with the GDPR
The protection and security of your personal and device-related data (collectively referred to as “data”) are of utmost importance to us. ZESS complies with the applicable statutory regulations to ensure the highest level of data protection.
This Privacy Policy explains the type, scope, and purpose of our data processing in accordance with Art. 13 GDPR.
1. Contact Details of the Controller (Art. 13 (1)(a) GDPR)
Responsibility for the operation of the ZESS website and the handling of personal data lies with:
ZESS
[Your Company Address]
[ZIP Code, City, Country]
[Phone Number]
[Email Address]
2. Contact Details of the Data Protection Officer (Art. 13 (1)(b) GDPR)
Data protection concerns may be directed to:
[Name of DPO (if applicable)]
c/o ZESS
[Address]
[Email of DPO]
3. General Information
- ZESS provides both public and access-protected areas on its website, including an online shop for product orders. Data processing varies based on user access level and interaction.
- Public website visits result in anonymized IP addresses being logged, preventing user identification.
- Accessing protected areas, such as for purchases or saved preferences, requires registration or login.
4. Types of Personal Data
a. Website Visits / Downloads
- Browser type and version
- Operating system
- Referrer URL
- Anonymized IP address
- Login timestamps
- Email (for web app access)
b. Account Registration (ZESS ID)
- Name, title, and contact details
- Company and branch
- Billing/shipping address
- Phone, fax, mobile, and website (optional)
c. Contact via Email
- Email address and content
- Metadata associated with the email
d. Contact Form
- Name, company, address, contact number
- Message content
e. Applications (Jobs Page)
Applicant-provided data (CV, contact, etc.)
f. Online Shop Orders
- Billing and shipping addresses
- Payment data (credit card info, if applicable)
g. Newsletter Subscription
- Name, email
- IP address, registration date/time
- Interaction metrics (opens, clicks, etc.)
5. Purpose of Data Processing (Art. 13 (1)(c) GDPR)
- Website Use: For security, functionality, and analytics
- Account Creation: Customer management, internal service use
- Contact/Support: Responding to inquiries
- Applications: Candidate evaluation
- Online Shop: Order processing and fulfillment
- Newsletter: Communication and marketing analysis (with consent)
6. Data Recipients & Transfers (Art. 13 (1)(e)(f) GDPR)
Your data may be accessed or processed by:
- Internal staff
- IT service providers under data processing agreements (Art. 28 GDPR)
- Shipping and logistics partners (for order fulfillment)
No data is transferred outside the EU without your express consent. All servers are located in the EU.
7. Cookies & Analytics Tools
a. Session Cookies
Used to manage session-specific settings like watch lists and user logins. Automatically deleted when the browser is closed.
b. Matomo (Self-Hosted)
Used for anonymous website usage statistics. IPs are truncated and not personally identifiable. Tracking respects “Do Not Track” browser settings. You may opt out at any time.
8. Social Media Integrations
ZESS uses links to platforms such as:
Clicking on these links will transfer you to the respective platform, where their privacy policies apply. ZESS does not control third-party data collection.
9. Newsletter Policy
ZESS sends newsletters only with:
- Your explicit consent (double opt-in), or
- A prior business relationship where similar products/services are promoted.
You may revoke consent at any time via the unsubscribe link in emails or by contacting us.
Tracking: We may track newsletter interactions (clicks, views) to tailor content. You can opt out by unsubscribing.
10. Legal Bases (Art. 13 (1)(c) GDPR)
- Website & Cookies: Art. 6 (1)(f) GDPR (legitimate interest)
- Account Creation / Orders: Art. 6 (1)(b) GDPR (contract performance)
- Newsletter: Art. 6 (1)(a) GDPR (consent) or Art. 6 (1)(f) GDPR
- Applications: § 26 BDSG
- Contact Forms: Art. 6 (1)(a) GDPR (consent)
11. Duration of Storage (Art. 13 (2)(a) GDPR)
- Log Files: Deleted after 14 days
- Support Emails/Contact Forms: Deleted 1 year after final response
- Account/Order Data: Retained as required by tax and commercial laws
- Newsletter Data: Stored until unsubscribe or revocation of consent
12. Your Rights
Under GDPR, you have the right to:
- Access, rectify or erase your data
- Restrict or object to processing
- Data portability
- Lodge a complaint with a supervisory authority
Contact us at [Your privacy contact email] to exercise any of these rights.