If you wish to make use of special services of our company via our website or the apps or if you order something via our eShop, the processing of personal data may become necessary. If the processing of personal data is necessary and there is no legal basis for such processing (for example, the implementation of a contractual agreement), we will ask for your consent.
This Privacy Statement contains information about the data we collect from you, how we use it and how you can object to the use of this data.
Heidelberger Druckmaschinen AG welcomes your visit to our web pages and app and your interest in our products. Please note that this Privacy Statement no longer applies if you follow links to third-party sites or register in areas controlled by other data controllers.
The data controller with respect to this website or app is:
Heidelberger Druckmaschinen AG
Tel.: +49 (0)6221 92 00
Our data protection officer can be contacted at:
Heidelberger Druckmaschinen AG
Data Protection Officer
In the following, we will give you a general overview of the processing purposes and legal bases in the context of our web pages and app. We have collected more detailed information for you below, sorted by the tools used.
For technical reasons, certain data must be collected and stored when you visit our web pages, such as the date and duration of your visit, the web pages used, the identification data of the type of browser and operating system used and the website from which you are visiting us.
In order to fulfill a contract, we require certain personal data from you. This data is required to make bookings in the eShop, process payments, carry out credit checks, deliver to the specified address (if items are to be shipped) and, where appropriate, to process cancellations or refunds.
In this case, the contract is the legal basis for the processing of your personal data in accordance with Art. 6 para. 1 lit. b of the General Data Protection Regulation (GDPR). Art. 6 para. 1 lit. b GDPR also applies in respect of processing operations that are necessary for carrying out pre-contractual measures, for example in the event of inquiries regarding our products or services.
If we obtain your consent for the processing of personal data (for example, if you sign up for the newsletter or use the “stay signed in” option), this serves as the legal basis in accordance with Art. 6 para. 1 lit. a GDPR.
If our company is subject to a legal obligation rendering the processing of personal data necessary, for example in order to meet tax obligations, the processing is based on Art. 6 para. 1 lit. c GDPR.
In order to constantly improve the services we offer you, we store and analyze usage data from the online area on a pseudonymized basis. The legal basis for this is our legitimate interest in the optimization of our web pages and apps, and in the effective design of our advertising in accordance with Art. 6 para. 1 lit. f GDPR.
Only applies to existing customers: We are also interested in maintaining our customer relationship with you and in providing you with information and offerings that we believe match your interests. We therefore process your data on the basis of Art. 6 para. 1 lit. f GDPR (also with the help of service providers) in order to send you information and offerings. We use your contact data (name and e-mail address that we have received from our business relationship with you) for advertising by post and for market research, unless you object to such use.
Internal transfer of personal data:
Heidelberg's internal IT departments and the selected service providers engaged by them can access user data insofar as this is necessary in the course of fulfilling their tasks.
Orders for information material via the app or our contact form are handed over to Heidelberg’s marketing team or sales team as part of lead management.
Transfers to third parties:
Personal data is usually transferred to third parties in the context of our web pages and apps if their services are deliberately used or accessed by the user.
More detailed, additional or different information, such as further recipients or the transfer to third countries, can be found below under the details of the respective service.
Personal data that we process on the basis of consent will be processed by us for as long as the wording of the consent allows or until the consent of the data subject is revoked. We store tax-relevant personal data for ten years, pursuant to the first sentence of Section 147 para. 3 of the German Fiscal Code (AO), the first half sentence of Section 257 para. 4 of the German Commercial Code (HGB) in conjunction with Section 257 para. 1 nos. 1 and 4 HGB, and sentences 1 and 2 of Section 14b para. 1 of the German VAT Act (UStG). We store personal data on user accounts/master data, for push notifications, and for the allocation of performance data on the basis of our legitimate interest in defending or asserting legal claims up to their limitation period for three years from the end of the year in which the processing was carried out, pursuant to Art. 6 para. 1 lit. f GDPR and Sections 280 para. 1, 195, and 199 para. 1 of the German Civil Code (BGB).
Due to our legitimate interest in security and troubleshooting, we store personal communication data and protocols for a maximum of seven days from the end of processing, pursuant to Art. 6 para. 1 lit. f GDPR.
We store personal analysis and statistical data, such as Google Analytics data relating to user behavior, only for as long as this is necessary in order to create the anonymized data records. This corresponds to a deletion within a very short time.
We may also store your data for a longer period of time if necessary, for example to assert or defend legal claims, solve technical problems, or analyze security incidents.
Erasure of data
We always erase personal data when there is no requirement for further storage. A requirement may exist in particular if the data is still needed to fulfill contractual services, or so that we can check and allow or fend off warranty claims and, if applicable, guarantee claims. In the event of statutory retention obligations, the data can only be erased after the respective retention obligation has expired.
Unless otherwise specified in the consent, we retain proof of consent and opt-out for 5 years after the end of processing in order to be able to demonstrate compliance with the data protection regulations, Art. 6 para. 1 lit. f GDPR.
We do not carry out profiling or automated decision making in the normal course of business. We expressly refer to exceptions under the respective headings below.
You have various rights under the GDPR as a user* of our app: In accordance with Art. 15 GDPR, you can request information about the personal data relating to you that we process. When requesting this information, you should outline your concern more precisely in order to make it easier for us to compile the necessary data.
If the legal requirements of Art. 15 para. 3 or Art. 20 GDPR are met, you have the right to receive a copy of your data or to have your data transferred to you.
If the information concerning you is not (or no longer) correct, you can request a correction in accordance with Art. 16 GDPR. If your data is incomplete, you can request that it be completed. You can request the deletion of your personal data under the provisions of Art. 17 GDPR.
Within the framework of the provisions of Art. 18 GDPR, you have the right to request that the processing of data concerning you be restricted.
Where data is processed on the basis of legitimate interests, you have the right under Art. 21 GDPR to object at any time to the processing of data concerning you for reasons arising from your particular situation. You may object to the processing of your personal data on the basis of legitimate interests for direct marketing purposes at any time without giving reasons.
You can revoke your consent at any time with future effect.
You may assert these rights against Heidelberger Druckmaschinen AG free of charge via the e-mail address or postal address stated above.
Please feel free to contact us first before you make use of your right to lodge a complaint with the data protection supervisory authorities. Our competent data protection supervisory authority is: “The State Commissioner for Data Protection and Freedom of Information” in Baden-Württemberg.
The Heidelberg Group may make the following personal data available to you on web pages or in the app:
We receive this data on a voluntary basis directly from the people concerned and use it for advertising or information purposes only after express consent and approval has been given. The legal basis for processing this data (information on speakers and contacts) is the consent of the data subjects pursuant to Art. 6 para. 1 lit. a GDPR.
If you register to use the Heidelberg Assistant, you will be asked to provide the following information: last name, first name, e-mail address, country, and customer affiliation. Providing the information is voluntary. If you provide us with this information, we will use it to identify users and to make personal and individual content of the app visible.
If users receive a voucher from us, these vouchers will be assigned to user e-mail addresses and displayed within the app, provided that the user logs into the app with this e-mail address. We receive the e-mail address via the registration; the allocation of vouchers by HDM AG and its Sales and Service Center.
When you set up the app, you will be asked if the app is allowed to send you notifications. If you agree, we will use push notifications to send you alerts about the app, as well as marketing messages. The service then sends the registration ID (Android) or the token (iOS) to the registered device. The app sends the ID or token to the server, where it is stored in a database. If a push notification is to be sent, the server sends the desired message with registration ID/token to the platform’s push service, which forwards the push notification to the respective devices.
You can suspend receipt of push notifications when not using the app by explicitly logging out of the app.
You can revoke your consent to receive push notifications via the operating system as follows:
When you use our app, the data that is sent by your browser during usage and that is required to use our services is automatically recorded. This data includes the IP address, installation ID, operating system, platform (iOS, Android, Windows), and the date and time of use of our services. Every time our app is used or a file stored in the app is retrieved, this action is logged.
The following is logged: name of the retrieved file, date and time of retrieval, amount of data transferred, notification of successful retrieval, app ID and requesting domain. The IP addresses of the requesting devices are also logged. Access is registered for reasons of data security, to ensure the stability and operational reliability of our system and to protect against possible external attacks. In addition, the data is statistically evaluated to optimize the services we offer. It is not possible to trace which contents you have accessed or which files you have retrieved on the basis of the logged data. The temporary collection of the data is necessary in order to enable the delivery of the content to the terminal devices and to guarantee its reproduction. This data is not merged with other data sources.
The data will be deleted as soon as it is no longer necessary for the purpose for which it was collected. For the storage of data in log files, this is the case after seven days at the latest. It is possible that the data may additionally be stored with our technical service providers for statistical purposes, inter alia. In this case, the IP address will be deleted or masked so that the calling device can no longer be assigned.
The collection of data for the provision of the app and its storage is absolutely necessary for the operation of the service, so that there is no option for the user to object. The legal basis for the processing of user account/master data and the assignment of performance data and communication data is the fulfillment of our contract with you for the provision of the Heidelberg Assistant and your content in accordance with Art. 6 para. 1 lit. b GDPR.
The legal basis for the processing of push notifications, and for information and marketing purposes, is our legitimate interest in providing users with relevant information about the Heidelberg Group in accordance with Art. 6 para. 1 lit. f GDPR.
In addition, we use the Google Firebase service for our app to analyze and categorize user groups, and to send push notifications. You can find more information here, at Google, or directly in our app.
The web server for the operation of our online survey is Microsoft Forms and is operated by Microsoft.
Microsoft Ireland Operations Limited
One Microsoft Place
South County Industrial Park, Leopardstown
The data is processed on servers located in the European Union. In exceptional cases, access by Microsoft from third countries is possible. Microsoft is certified under the EU-US Privacy Shield, and furthermore guarantees an adequate level of data protection through the use of the EU standard clauses:
Storage duration and storage periods:
The storage period of the personal data transmitted via the forms is determined by the respective processing purpose. If you do not receive additional information regarding the storage period, the retention periods stated in our general privacy information apply.
When you access our web pages, you transmit (for technical reasons) data via your Internet browser to our web server. The following data is recorded for communication purposes between your Internet browser and our web server while a connection is established:
For technical security reasons, in particular as a defense against attempted attacks on our web server, this data is temporarily stored by us. It is not possible for us to trace the data back to a specific person. The data will be anonymized after a maximum of seven days by truncating the IP address at domain level, which makes it no longer possible to establish a link to the individual user. The data is also processed in anonymized form for statistical purposes; it is neither in part nor in full matched against other databases or disclosed to third parties. Only the number of page views is shown in our server statistics, which we publish every two years in our activity report.
Recipients or recipient categories
As a rule, the personal data you provide will only be processed by employees of Heidelberg companies and their commissioned processors. For the fulfillment of our tasks and obligations, it may, however, become necessary for us to disclose your personal data stored to individual and legal entities, authorities, institutions, or other bodies. In particular, the following recipient categories are eligible:
The web server for the operation of our online survey Forms is technically operated by Microsoft.
Microsoft Ireland Operations Limited
One Microsoft Place
South County Industrial Park, Leopardstown
The data is processed on servers located in the European Union. In exceptional cases, access by Microsoft from third countries is possible.
Purpose of processing
We use the Microsoft Teams tool to conduct telephone conferences, online meetings, video conferences and/or web conferences (in the following: “online meetings”). Microsoft Teams is a service from the Microsoft Corporation.
Heidelberger Druckmaschinen AG is the controller for data processing directly related to the holding of online meetings.
Note: If you access the Microsoft Teams website, the provider of Microsoft Teams is the data processing controller. However, to use Microsoft Teams, it is only necessary to access the website to download the software for using Microsoft Teams.
If you do not wish to or cannot use the Microsoft Teams app, you can also use Microsoft Teams from your browser. The service is then also provided via the Microsoft Teams website.
Which data is processed?
When you use Microsoft Teams, different types of data are processed. The scope of the data also depends on what information you provide before or during participation in an online meeting.
The following personal data is subject to processing:
Scope of processing
We use Microsoft Teams in order to hold online meetings. If we want to record online meetings, we will inform you transparently in advance and – if necessary – ask for your consent.
Chat content is logged when you use Microsoft Teams. Files shared by users in chats are stored in the OneDrive for Business account of the user who shared the file. Files shared by team members in a channel are stored on the team's SharePoint site.
Automated decision-making within the meaning of Art. 22 GDPR is not used.
Legal bases for processing the data
If personal data is processed by employees of Heidelberger Druckmaschinen AG, the legal basis for the data processing is Section 26 of the German Federal Data Protection Act (BDSG). If, in connection with the use of Microsoft Teams, personal data is not required for the establishment, implementation or termination of the employment relationship but is nevertheless an elementary component during the use of Microsoft Teams, Art. 6 para. 1 lit. f GDPR is the legal basis for the data processing. In these cases our interest lies in the effective holding of online meetings.
In all other respects, the legal basis for data processing when holding online meetings is Art. 6 para. 1 lit. b GDPR, insofar as the meetings are held within the framework of contractual relationships.
If no contractual relationship exists, the legal basis is Art. 6 para. 1 lit. f GDPR. In this case too our interest lies in the effective holding of online meetings.
Recipients/Transfer of data
Personal data that is processed in connection with participation in online meetings will not be transferred to third parties, unless the data is intended for transfer. Please note that content from online meetings and face-to-face meetings is often used to communicate information to customers, interested parties or third parties and is therefore intended for transfer.
Additional recipients: The provider of Microsoft Teams necessarily obtains knowledge of the above-mentioned data to the extent that this is provided for in our commissioned processing contract with Microsoft Teams.
If you contact us via a contact form, Heidelberger Druckmaschinen AG will process your first name, last name, job title, company and number of employees, and your contact details (telephone number and e-mail address), the content of the message and, on a voluntary basis, the customer number provided. The processing of the data is carried out to deal with your request and is necessary in order to handle the request. Contact details are processed in order to respond to queries and communicate on the matter. If you are assigned to an advisor, the data will be passed on to the advisor (acting as a self-employed commercial agent) and the advisor’s employees for processing.
Processing for the purpose of initiating and implementing contracts is based on Art. 6 para. 1 lit. b GDPR. The legal basis for the processing otherwise depends on your specific request.
You will find more detailed information on data protection in the context of the respective communication objectives and partners.
Further information on data protection is provided in the context of the application procedure or in the following document:
This website also includes plug-ins from the social network Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA (“Instagram”). You can recognize the Instagram plug-in by the Instagram button on our site.
Our website uses features of the XING network. The provider is XING AG, Dammtorstrasse 29-32, 20354 Hamburg, Germany.
Every time you access one of our pages containing XING features, a connection to XING’s servers is established. No personal data is stored in the process, to our knowledge. In particular, no IP addresses are stored or usage behavior evaluated.
The XING plug-in is used on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in achieving the widest possible degree of visibility on social media.
We use a consent management platform. The service lets you decide which of the various services available on our web pages (associated with personal data processing) you wish to use only on the basis of consent. It also allows us to document your consent to the data processing and to provide the legally required proof of this. Your declaration applies to all our web pages and apps.
The following data is processed:
The legal basis of the processing is Art. 6 para. 1 lit. f GDPR in conjunction with Art. 7 para. 1 GDPR.
Regarding data retention: All information is stored for three years from the end of processing. The legal basis for this is our obligation to document the fulfillment of the data protection requirements according to Art. 6 para. 1 lit. c GDPR in conjunction with Art. 5 para. 2 and Art. 24 GDPR, combined with our legitimate interest in proving compliance under Art. 6 para. 1 lit. f GDPR in conjunction with Section 41 of the German Federal Data Protection Act (BDSG), and with Section 41 para. 2 no. 1 of the German Administrative Offenses Act (OWiG). The platform is operated by our commissioned processor, Usercentrics GmbH, Sonnenstrasse 23, 80331 Munich, Germany.
You can find more information about data protection at Usercentrics here.
Description: This cookie is used to manage the cookie consent on our page and to store your preference.
Expiration: Persistent until you delete cookies from your browser or changes inside the cookie consent tool are undertaken
We use Google Tag Manager. The provider of the Google Tag Manager component is Alphabet Inc. This service enables website tags to be managed via an API. Google Tag Manager only implements tags. This means that cookies are not used and no personal data is collected. Google Tag Manager triggers other tags that can be used to collect data, however, Google Tag Manager does not access this data. If deactivation has been carried out at domain or cookie level, this will remain in place for all tracking tags implemented with Google Tag Manager.
This is a conversation search platform and a configurator. We use Zoovu for our PANTONE® Manager, where customers can search for a color that meets their requirements.
The following data is processed by Zoovu:
To opt out of the data processing, click here. We would like to point out that the functions of our eShop may be limited as a result.
The information required for the selected action is transmitted on the basis of our legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of advertising products and offers from Heidelberger Druckmaschinen AG.
To provide you with podcasts, we use the podcast hosting service of our commissioned processor Podigee UG, Am Walde 2, 56249 Herschbach, Germany. The podcasts are loaded by Podigee or transmitted via Podigee, so when you access a podcast integrated in our web pages, data is transmitted to our service provider.
The use is based on our legitimate interests, i.e. our interest in the secure and efficient provision, analysis and optimization of our range of podcasts in accordance with Art. 6 para. 1 lit. f GDPR.
Podigee processes IP addresses and device information to enable podcasts to be downloaded/played and to determine statistical data, such as download numbers. This data is anonymized or pseudonymized before being stored in Podigee’s database unless it is required for the provision of the podcasts. Data that is required for provision of the podcasts will be deleted no later than seven days after this provision if it is not required for billing purposes (see above under “How long will your data be stored?”).
This service (e.g. for contact forms, and newsletter registrations) is used for purposes of identification and to prevent the services provided from being misused by machines. “Captchas” are generated and verified on application servers from Heidelberger Druckmaschinen AG. No data is transmitted to third parties in the process.
Click here to opt out on all the processing company's domains.
To optimize the loading times of our website and our online eShop application, we use a so-called content delivery network (CDN) offered by Akamai Technologies, Inc., 150 Broadway, Cambridge, MA 02142, USA.
Akamai is a content delivery and cloud infrastructure service provider that coordinates and optimizes the load balancing of web content for online applications. We use Akamai services to speed up our websites so that they can provide an acceptable response time worldwide.
The legal basis for the processing of users' personal data is our legitimate interest in providing an online presence that can be used worldwide without restriction in accordance with Art. 6 para. 1 lit. f GDPR.
We use a plug-in from the New Relic web analysis service on this website. It enables us to record statistical evaluations of the speed of the website, to determine whether the website can be accessed, and how quickly the respective page is displayed when accessed. This service is operated by New Relic Inc. (188 Spear Street, Suite 1200, San Francisco, CA 94105, USA; “New Relic”).
Through the integration of the plug-in, New Relic is informed that a user has accessed the corresponding page of our website. If the user is logged in at New Relic, New Relic can assign the visit to the user’s New Relic account. If a user is not a member of New Relic, New Relic nevertheless saves the user’s IP address.
The legal basis for the processing of personal data is our legitimate interest in the evaluation of the availability and speed of our website in accordance with Art. 6 para. 1 lit. f GDPR. Heidelberg does not receive any personal data from New Relic, but only anonymous, statistical evaluations.
If you are a member of New Relic and do not want New Relic to collect data about you through this website and link it with your membership data stored at New Relic, you should log out of New Relic before visiting the website.
Google Analytics is only used by us in conjunction with activated IP anonymization (IP masking). This means that users’ IP addresses are truncated by Google for users within member states of the European Union or other states party to the agreement on the European Economic Area. Only in exceptional cases (e.g. in the event of a technical defect in the European Union) is the IP address sent to a US server and truncated there.
The IP address anonymization method used by Google does not write IP addresses to a disk, as anonymization takes place in the main memory immediately after the request is received. We do not receive any personal data from Google, only anonymized statistics.
Transfer to third countries (outside the EU and the EEA): Google receives personal data in the course of analyzing user behavior on the basis of your consent and processes this data worldwide if necessary for the provision of the services:
Google Ireland Limited
Gordon House, Barrow Street
Tel: +353 1 543 1000
Fax: +353 1 686 5660
We store the data on pseudonymized profiles that cannot be associated with any individual person for a period of 26 months to prevent cases of abuse and to optimize our web pages. This data is automatically deleted after 26 months. Move your mouse over here to opt out on all domains of the processing company or to download the browser add-on to deactivate Google Analytics.
Name: _ga, _gat
Provider: Google Universal Analytics
Description: Both analyse browsing pattern and allow creation of flow statistics; _ga is used to distinguish individual users by means of designation of a randomly generated number as client identifier (based on browser and device), which allows calculation of visits and sessions; _gat is used to distinguish between the different monitoring objects created in the session.
Expiration: _ga | Two years from settings, update or until you delete cookies from your browser; _gat | 20 minutes from settings or update
Provider: Google Universal Analytics
Description: Captures the origin from where a user came on our pages.
Expiration: 1 year from settings or update
With your consent under Art. 6 para. 1 lit. a GDPR, we use Google Analytics advertising features on our web pages. This enables us to display personal offers to you, including outside the websites hosted by Heidelberger Druckmaschinen AG.
By linking your anonymous usage data collected through Google's DoubleClick Advertising Network, we can analyze the demographic composition of our website visitors and impact on our users' interests. This helps us to present you with better and above all more relevant advertising.
You can revoke your consent at any time with future effect: More information and opt-out.
Revised and posted as of March 15, 2021.
We look forward to your message. In order to be able to react quickly to your request, we need some information. *These fields are required.