Data privacy notes for the usage of the Oerlikon Supplier Web Portal („SWP“)

The protection of your personal data is a very import issue for the Oerlikon Textile GmbH & Co. KG ("Oerlikon") and the other companies of the Oerlikon group. Therefore, we will carry out our activities in accordance with the applicable legal provisions regarding the protection of personal data and data security. Below, we would like to inform you according to the guidelines of the EU General Data Protection Regulation (Ordinance (EU) 2016/679 of the European Parliament and the Council dated April 27th, 2016 - in the following called "GDPR") about the processing of your personal data when using our Oerlikon Supplier Portal (in the following called SWP). Additionally, our general data privacy notes will apply, which you can download here.

1. Responsible

Oerlikon Textile GmbH & Co. KG
Leverkuser Strasse 65,
42897 Remscheid
Germany
E-mail: datenschutz.manmade-fibers@oerlikon.com

2. Data protection officer

Data protection officer of the Oerlikon Textile GmbH & Co. KG
c/o Oerlikon Textile GmbH & Co. KG
Leverkuser Strasse 65,
42897 Remscheid
Germany

can be contacted also by e-mail:dsb.manmade-fibers@oerlikon.com

3. Scope of application of these data privacy notes

These notes refer to the procedure of how your data will be collected and used when using the SWP.

4. Collection and processing of data

Regarding the usage of our SWP, you will find below an overview of the data categories which we can directly collect from you:

If you visit our websites or use our applications, subscribe to our newsletters or interact in another way with us via our digital channels, we will collect - in addition to the information you have shared with us directly - also data which have been submitted to us by your computer, mobile phone or other access device. We can e.g. collect the following data automatically:

5. Data usage and purpose

We will use your personal data only to the extent necessary for the technical administration of SWP, mapping the transports as well as the invoicing per credit procedures.

We can use your data based on other justified reasons and for various justified operational purposes. Please find below an overview of the purposes for which we can process your data:

If we ask you to submit data and you reject to do so, we will in some cases not be able to offer you the full functional scope of our products, services, systems, or applications. Probably, we will not be able to answer your requests.

6. Legal bases for data processing

In order to process your data we can proceed on the basis of various legal bases; in case of the SWP in particular:

7. Dissemination of data

The dissemination of personal data to national institutions and authorities is carried out only in the scope of obligations as a result of national legislation. We transfer your personal data within our parent group OC Oerlikon Corporation AG in order to provide optimum service and information. Our employees, agencies and dealers are bound to confidentiality.

A transfer, sale or other form of transmission of your personal data is not carried out, unless this is required in the framework of our business purpose or the purpose of contract processing or in case you have given your approval. For example, if you have ordered our products or services, it may be required that we forward your address and order data to our contract partners or to special service providers which support us in our activities. We may forward your data to other parties such as professional consultants, i.e. banks, insurance associations, auditors, lawyers, tax consultants or other professional consultants.

We also employ external service providers to take over certain assignments and services on our behalf and according to our instructions. The external service providers support us with our IT solutions, operate our computer centers, provide customer or payment services, send electronic messages, support us in the fight against fraud, carry out risk assessments and ensure the compliance in the fields export control, ITAR, and trade control. External service providers only have access to the personal data which they need for the execution of their specific assignments. These external service providers have committed themselves in agreements regarding the data processing to use personal data exclusively in the scope of the agreed outsourcing, to protect your data and not sell the data to third parties.

We can forward your data also in case of company transactions such as the sale of a company or part of the company to another company or in the course of a reorganization, corporate merger, joint venture or another kind of sale of our business, our capital or our shares (also with respect to insolvency or corresponding proceedings).

8. Data transfer to another country

Because of our global activities, your submitted data may be forwarded to and reviewed by affiliated companies or trusted third parties. Therefore, your data may be processed outside the country of your residence if this is required for the purposes described in this note.

If you are in a member state of the European Economic Area, we may transfer your data to countries outside the European Economic Area. According to the opinion of the European Commission, some of these countries offer a sufficient level of protection. However, it may be required to transfer data to countries the data privacy laws of which do not guarantee an appropriate privacy level. Please find a list of countries with Oerlikon representations under www.oerlikon.com. If we forward your personal data, we will always ensure that the international transfer is carried out in compliance with the applicable data privacy laws.

9. Deleting of data

We store your data for the time period which is necessary to fulfill the tasks for which they had been collected (please find more details regarding these purposes in the previous section "Data usage and purpose").

In the context of the processing of your personal data in the SWP, the deletion period for transport registrations is two years. Log files are deleted after 6 months at the latest with the exception of the date of the last login. Users are deleted three years after the last login date, provided that no more transport logins were made during this period. This period results from the general limitation period under German civil law (§ 195 BGB).

10. Data security

We use technical and organizational security measures to protect your data, which are processed by us, against manipulation, loss, destruction and the access by unauthorized people. Our security measures are continuously improved corresponding to the technical development. We request our service providers to take appropriate measures for the protection of the confidentiality and the security of your personal data.

11. Your options

As a person affected by the processing of personal data, you can exercise certain rights. In accordance with Art. 15 GDPR, you have the right to obtain information about the data stored about you. If incorrect personal data have been processed, you have the right to have them corrected in accordance with Art. 16 GDPR. If the legal requirements are met, you can demand the deletion or restriction of processing, as well as object to data processing (Art. 17, 18 and 21 GDPR). According to Art. 20 GDPR, you can assert the right to data transferability in the case of data that is processed automatically on the basis of your consent or a contract with you. If you have given us your consent, you can revoke it at any time. Please note that the revocation of consent does not affect the legality of the processing carried out up to the revocation. These rights can be asserted against Oerlikon Textile GmbH & Co KG at the address stated above under "Responsible" by post, e-mail or fax.

If you are of the opinion that data processing violates data protection law, you have the right to complain to a data protection supervisory authority of your choice (Art. 77 GDPR in conjunction with § 19 BDSG). This also includes the data protection supervisory authority responsible for us, which you can reach at the following contact details: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, P.O. Box 200444, D-40102 Düsseldorf

Last update: 09.03.2021