01Controller
The controller responsible for data processing on this website within the meaning of the EU General Data Protection Regulation (GDPR) is:
Midesco Handelsgesellschaft für Industriebedarf mbH
Römerstraße 96
68623 Lampertheim, Germany
Managing Director: Mario Peter Maiwald-Merzbach
Commercial register: Amtsgericht Darmstadt, HRB 108908
Email: midescogmbh@inbox.eu
Phone: +49 163 9421576
We have not appointed a data protection officer as we are not legally required to do so. Please direct any data protection questions to the contact details above.
02Overview
We process personal data only to the extent necessary to provide a functional website, to answer inquiries and to conduct our business relationships. This policy explains which data we process, for what purposes, on which legal basis and what rights you have.
Our website is directed at business customers (B2B). We do not use tracking, profiling, analytics or advertising tools.
03Hosting & server log files
When you visit this website, the hosting provider automatically collects information that your browser transmits, in particular:
- IP address (anonymised or deleted after a short period)
- Date and time of the request
- Requested page / file and amount of data transferred
- Referrer URL
- Browser type and version, operating system
This data is processed to ensure the secure and stable operation of the website (Art. 6(1)(f) GDPR — legitimate interest in IT security and error analysis). Log files are deleted after no more than 14 days unless longer retention is required to investigate a specific security incident.
Our hosting provider processes this data on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
04Contacting us
If you contact us by email, telephone or via the contact form, we process the details you provide (e.g. name, company, email address, phone number, content of your request) in order to handle your inquiry and any follow-up questions.
The contact form on this website does not transmit data to our servers: it prepares a message in your own email program, which you then send yourself.
Legal basis: Art. 6(1)(b) GDPR where your inquiry relates to a contract or pre-contractual measures, otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries). We delete inquiry data once it has been dealt with, unless statutory retention obligations apply.
05Business relationships
For customers, suppliers and business partners we process contact and contract data (e.g. names of contact persons, business contact details, order, delivery and invoice data) to perform contracts and pre-contractual measures (Art. 6(1)(b) GDPR) and to comply with legal obligations such as commercial and tax retention requirements and export control regulations (Art. 6(1)(c) GDPR).
Commercial documents are retained for 6 years and accounting records for up to 10 years in accordance with § 257 HGB and § 147 AO.
06Cookies & local storage
We only use technically necessary browser storage (localStorage / sessionStorage) to remember your cookie choice and whether the intro animation has already been shown. This is permitted without consent under § 25(2) No. 2 TDDDG. No tracking or marketing cookies are used. Details can be found in our Cookies Policy.
07Google Fonts
This website uses fonts provided by Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When a page is loaded, your browser connects to Google's servers and transmits your IP address in order to load the fonts. Legal basis is Art. 6(1)(f) GDPR — our legitimate interest in a consistent and appealing presentation of our website.
Data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework. For more information see Google's privacy policy.
08Recipients
Within the scope of our business, personal data may be passed on to the following categories of recipients where necessary: logistics and freight service providers, customs agents, inspection companies, IT and hosting service providers, tax advisers and auditors, banks, and public authorities where we are legally obliged.
09Transfers to third countries
As an international trading company, we may transfer business contact data to recipients outside the EU/EEA where this is necessary to perform a contract with you (Art. 49(1)(b) GDPR) or where appropriate safeguards such as an adequacy decision or EU Standard Contractual Clauses are in place (Art. 45, 46 GDPR).
10Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15)
- rectification (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- withdraw any consent at any time with effect for the future (Art. 7(3))
Right to object (Art. 21 GDPR): where we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds.
To exercise your rights, simply contact us at midescogmbh@inbox.eu.
11Supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
12Security
This website uses TLS encryption for the transfer of data. We implement appropriate technical and organisational measures to protect your data against loss, manipulation and unauthorised access.
13Changes to this policy
We may update this Privacy Policy when our services or the legal situation change. The current version is always available on this page.