Privacy Policy
1. Data protection at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data means any information that can identify you. Detailed information is set out below in this privacy policy.
Data collection on this website
Who is responsible for data processing on this website?
The website operator is the controller. Contact details are listed under “Controller”.
How do we collect your data?
Some data you provide yourself. For example, data you enter into a contact form or send by email. Other data is collected automatically or after your consent when you visit the site. This includes technical data such as browser, operating system, and time of access.
What do we use your data for?
Part of the data is used to ensure error-free provision of the website. We may also analyse user behaviour. Where contracts can be initiated or concluded via the site, transmitted data is processed for offers, orders, or other requests.
What rights do you have?
You can request information about origin, recipients, and purpose of your stored personal data at any time. You can request rectification or deletion. If you have given consent, you may withdraw it with effect for the future. You can request restriction of processing in certain cases. You also have the right to lodge a complaint with a supervisory authority.
You can contact us at any time regarding these and other questions on data protection.
Analytics and third-party tools
Your browsing behaviour may be statistically evaluated. We mainly use analytics software for this. Details are below.
2. Hosting
External hosting by STRATO
This website is hosted by:
-
STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany
Personal data collected via the website is processed on STRATO’s servers. This may include IP addresses, log data, contact requests, metadata and communication data, contractual data, contact details, names, website access data, and other data generated via the site.
Legal bases: Article 6(1)(b) GDPR (contract or pre-contractual measures) and Article 6(1)(f) GDPR (secure, fast, and efficient provision). Where consent is requested, Article 6(1)(a) GDPR and Section 25(1) TDDDG apply. You can withdraw consent at any time.
We have concluded a data processing agreement (Article 28 GDPR) with STRATO.
3. General notes and mandatory information
Controller
Hartmann & Weiss GmbH
Rahlstedter Bahnhofstraße 47
22143 Hamburg, Germany
Phone: 040 / 677 55 85
Fax: 040 / 677 55 92
Email: info@hartmannandweiss.com
Website: www.hartmannandweiss.com
Corporate purpose: Production and industrial manufacturing of precision engineering and mechanical components
Commercial Register: HRB 28926, Local Court of Hamburg
Data protection officer
No data protection officer is currently appointed, as there is no statutory obligation. Your point of contact for data protection is the controller named above.
Data security and transmission on the internet
We treat your personal data confidentially in line with legal requirements and this policy. Internet data transmission can have security gaps.
Storage period
Unless a more specific period is stated in this policy, we store personal data only as long as necessary for the relevant purpose. Statutory retention duties remain unaffected.
Legal bases for processing
-
Consent: Article 6(1)(a) GDPR and Section 25(1) TDDDG
-
Contract or pre-contractual measures: Article 6(1)(b) GDPR
-
Legal obligation: Article 6(1)(c) GDPR
-
Legitimate interests: Article 6(1)(f) GDPR
-
Special categories: Article 9(2)(a) GDPR, where applicable and only with explicit consent
Your rights
-
Withdraw consent at any time
-
Object to processing based on Article 6(1)(e) or (f) GDPR, including profiling (Article 21 GDPR)
-
Access, rectification, deletion, restriction (Articles 15–18 GDPR)
-
Data portability (Article 20 GDPR)
-
Lodge a complaint with a supervisory authority. In Hamburg: The Hamburg Commissioner for Data Protection and Freedom of Information
SSL/TLS encryption
This site uses HTTPS. You can recognise this by the padlock icon and “https://” in your browser’s address bar.
Objection to unsolicited emails
We object to the use of contact data published here for unsolicited advertising.
4. Data collection on this website
Server log files
The hosting provider automatically collects and stores information in server log files that your browser transmits:
-
IP address (shortened or pseudonymised where possible)
-
Date and time of the request
-
Time zone difference
-
Requested content or URL
-
Access status/HTTP status code
-
Transferred data volume
-
Referrer URL
-
Browser, operating system, language
Legal basis: Article 6(1)(f) GDPR. Legitimate interests: technical provision, security, error analysis. Logs are deleted or anonymised according to provider practice.
Cookies and similar technologies
We use cookies. Session cookies are deleted after your visit. Persistent cookies remain stored until you delete them or your browser removes them. We use first-party and third-party cookies.
Necessary cookies are stored on the basis of Article 6(1)(f) GDPR to enable communication, provide requested functions, or optimise the site.
Non-essential cookies are used only with your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG.
You can set your browser to inform you about cookies, allow them only in specific cases, exclude them, or delete them automatically when closing the browser.
Consent management with Borlabs Cookie
We use “Borlabs Cookie” by Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, to obtain and document user consents. When you access the site, a Borlabs cookie stores your consents or withdrawals. Data is not transmitted to Borlabs.
Legal basis: Article 6(1)(c) GDPR and, where relevant, Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Storage: until you delete the Borlabs cookie or the purpose ceases.
Details: https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/
Contact by email, phone, or fax
If you contact us, we process your data to handle your enquiry and any follow-up.
Legal basis: Article 6(1)(b) GDPR where related to a contract or pre-contractual steps, otherwise Article 6(1)(f) GDPR or Article 6(1)(a) GDPR if consent is requested.
Storage: until the enquiry is completed, statutory retention duties remain unaffected.
Communication via WhatsApp Business
We use WhatsApp Business to communicate with customers and other third parties. Provider: WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. Content is end-to-end encrypted. Metadata such as sender, recipient, and time is processed. According to the provider, user data is shared with its US parent company Meta.
Data Privacy Framework: the provider is certified. Info: https://www.dataprivacyframework.gov/participant/7735
Data transfers to the USA are based on EU Standard Contractual Clauses. Details: https://www.whatsapp.com/legal/business-data-transfer-addendum
Our accounts are configured with no automatic address book syncing. We have a data processing agreement in place.
Legal basis: Article 6(1)(f) GDPR for fast and effective communication. With consent: Article 6(1)(a) GDPR.
Storage: until the purpose is fulfilled, consent is withdrawn, or retention duties apply.
5. Plugins and tools
Google Fonts (local)
We use locally hosted Google Fonts for consistent typography. No connection to Google servers is established.
Legal basis: Article 6(1)(f) GDPR.
Adobe Fonts
We use Adobe Fonts for certain typefaces. Provider: Adobe Inc., 345 Park Avenue, San Jose, CA 95110-2704, USA. Your browser loads the fonts directly from Adobe. Your IP address may be transferred to the USA. According to Adobe, no cookies are set for font delivery.
Legal basis: Article 6(1)(f) GDPR. If consent is requested: Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Transfers to the USA are based on Standard Contractual Clauses. Adobe is also DPF-certified.
More information:
-
EU data transfers: https://www.adobe.com/de/privacy/eudatatransfers.html
-
Adobe Fonts: https://www.adobe.com/de/privacy/policies/adobe-fonts.html
-
Adobe Privacy Policy: https://www.adobe.com/de/privacy/policy.html
-
DPF participation: https://www.dataprivacyframework.gov/participant/5660
Web analytics with Matomo
We use Matomo for statistical analysis of website use. Data is stored only on our own server at STRATO and is not shared with third parties. Matomo runs without cookies or uses only technically necessary cookies. IP addresses are anonymised before storage, for example by truncating the last two bytes.
Purpose: reach measurement and content optimisation.
Legal basis: Article 6(1)(f) GDPR. If operated on a consent basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Opt-out: activate your browser’s Do Not Track setting or use the following opt-out: [Insert Matomo opt-out].
6. Recipients of personal data
We transfer personal data only where necessary for contract performance, where required by law, where we have a legitimate interest, or where another legal basis permits it.
Regular recipients:
-
Hosting and technical services: STRATO AG (processor, Germany)
-
Consent management: Borlabs GmbH (Germany)
-
Web analytics: self-hosted Matomo (Germany)
-
Typeface delivery: Adobe Inc. (USA, SCC and DPF)
-
Communication: WhatsApp Ireland Limited and Meta Platforms, Inc. (EU/USA, SCC and DPF)
We have data processing agreements with processors. Joint controllership agreements are concluded where applicable.
7. Contract handling, offers, orders
If contracts are initiated or concluded via the website, we process the data required for this purpose, such as master data, communication data, contract and payment data.
Legal basis: Article 6(1)(b) GDPR. Retention under commercial and tax law: Article 6(1)(c) GDPR.
8. Minors
Our services are not directed at children under the age of 16.
9. Data security
We implement technical and organisational measures under Article 32 GDPR.
10. Changes to this policy
We may update this policy. The current version published on this website applies.
Last updated: 12 November 2025
Contact
Hartmann & Weiss GmbH
Rahlstedter Bahnhofstraße 47, 22143 Hamburg, Germany
Phone: 040 / 677 55 85
Fax: 040 / 677 55 92
Email: info@hartmannandweiss.com