Legal
Privacy policy
Controller
ENFIT e.V. Internationaler Verband Supply Chain Safety
Grüne Straße 5
49610 Quakenbrück
Germany
What this website collects
This website sets no cookies, embeds no analytics or tracking services, and stores nothing in your browser. No usage profiles are created. The membership application form is the one exception — see its own section below.
Fonts
The fonts used here are downloaded when the site is built and served from our own server. Opening the website therefore creates no connection to third-party servers.
Server log data
When you open the website, your browser transmits technically necessary data such as IP address, time, the page requested and the browser identifier. This data is required for delivery and is logged. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in stable and secure operation.
Hosting
This website is hosted by Netlify (Netlify, Inc., 512 2nd Street, San Francisco, CA 94107, USA). Netlify processes the log data described above on our behalf under a data processing agreement. As the provider is based in the United States, data is transferred to a third country. This is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023.
Getting in touch
If you write to us by email, we process your details solely to handle your enquiry. The legal basis is Art. 6(1)(b) or (f) GDPR. Our email is processed through Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) under a data processing agreement. A transfer to Google LLC in the United States cannot be ruled out; this is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023. The same applies to newsletter sign-ups, which currently go by email.
Membership application
When you submit the membership application on this website, we process the details you enter: company name, address, tax ID, industry branch, website, and the name, position, email address and phone number of the people you name. The legal basis is Art. 6(1)(b) GDPR — the processing is necessary for steps taken at your request prior to entering into a contract.
Your details are not stored in a database on this website. They are sent by email to the association's office and to bulkvision GmbH (Planckstraße 13, 22765 Hamburg, Germany) immediately after submission; bulkvision handles membership administration on our behalf under a data processing agreement. You also receive the application as a PDF at the contact address you provided. After that they exist only in the mailboxes involved, where they are kept for as long as handling the application and statutory retention obligations require. We neither record nor store your IP address.
Both of these emails are sent using Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA), which processes the data contained in the application on our behalf. As the provider is based in the United States, data is transferred to a third country; this is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023. The incoming mail is then processed through Google Workspace, as described under “Getting in touch”.
The form is protected against automated submissions by Cloudflare Turnstile (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Opening the form page loads a script from Cloudflare, which thereby receives technical connection data including your IP address. In doing so, Turnstile may store or read information in your browser in order to maintain the check. We do not ourselves transmit your IP address to Cloudflare. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in protecting the form against misuse.
Agreeing to the use of your logo and of event photographs is voluntary and not required for the application. It is consent under Art. 6(1)(a) GDPR and can be withdrawn at any time with effect for the future; an informal message to the address above is enough.
Your rights
You have the following rights regarding your personal data:
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
An informal message to the address above is enough to exercise them. You also have the right to lodge a complaint with a data protection supervisory authority.
