kb_privacy_notice_business_partner_en_20201209

knorr-bremse-privacy-policy-for-social-media-presence_20210223

Protecting your personal data is important to us. Knorr-Bremse therefore processes your personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR) and further applicable laws on data protection and data security.
This privacy notice details how we process personal data of contact persons at (prospective) customers, suppliers, vendors and partners (following “Business Partner”).

1. Data Controller
The data controller under the GDPR is:
Knorr-Bremse AG
Moosacher Str. 80
80809 Munich
Germany
Tel.: +49 89 3547-0
E-Mail: info@knorr-bremse.com

In individual cases other affiliated companies of the Knorr-Bremse Group may act as controllers – either alone or jointly with the Knorr-Bremse AG. You can find the contact data of all Knorr-Bremse companies via: https://www.knorr-bremse.com/en/company/knorr-bremse-worldwide/
The contact details of the data protection officer are:
Corporate Data Protection Officer Knorr-Bremse
Moosacher Str. 80
80809 Munich
Germany
E-Mail: dataprotectionofficer@knorr-bremse.com

2. Categories of personal data processed and purpose of the processing
In the context of the business relationship with us, we may process the following categories of personal data of contact persons at (prospective) customers, suppliers, vendors and partners.
In this context we process the following data:
• Contact information, such as full name, work address, work telephone number, work mobile phone number, work fax number and work email address;
• Payment data, such as data necessary for processing payments and fraud prevention;
• Further information necessarily processed in a project or contractual relationship with Knorr-Bremse or voluntarily provided by the Business Partner, such as personal data relating to orders placed, requests, and project details;
• Personal data collected from publicly available resources, integrity databases and credit agencies; and
• If legally required for Business Partner compliance screenings (Business Partner Due Diligence): all publicly available information such as trade register excerpts, press coverage, financial information and information about relevant and significant litigation or other legal proceedings against Business Partners.
Copyright © Knorr-Bremse AG. All rights reserved, including industrial property rights applications.
Knorr-Bremse AG retains any power of disposal, such as for copying and transferring 2/3
We may process the personal data for the following purposes:
• Communicating with Business Partners about products, services and projects, e.g. by responding to inquiries or requests or providing you with information about purchased products;
• Planning, performing and managing the (contractual) relationship with Business Partners; e.g. by performing transactions and orders of products or services, processing payments, performing accounting, auditing, billing and collection activities, arranging shipments and deliveries, facilitating repairs and providing support services;
• Administrating and performing customer surveys, marketing campaigns, market analysis, sweepstakes, contests, or other customer activities or events;
• Maintaining and protecting the security of our products, services and websites, preventing and detecting security threats, fraud or other criminal or malicious activities;
• Ensuring compliance with legal obligations (such as record keeping obligations), export control and customs, Business Partner compliance screening obligations (to prevent white-collar or money laundering crimes), and our policies or industry standards; and
• Solving disputes, enforce our contractual agreements and to establish, exercise or defend legal claims.

3. Legal basis of processing
The processing of the personal data is necessary to fulfill the above-mentioned purposes including the performance of the (contractual) business relationship with the Business Partner. The legal basis for the processing is – unless noted otherwise:
− the performance of a contract (Art. 6 Para. 1 lit. b) GDPR),
− the legitimate interest pursued by Knorr-Bremse (Art. 6 Para. 1 lit. f) GDPR),
− the compliance with our legal obligation (Art. 6 Para. 1 lit. c) GDPR) or
− the explicit granted consent of our contact person (Art. 6 Para. 1 lit. a) GDPR).

4. Transfer and disclosure of personal data
We may pass on personal data to affiliated companies if necessary, to fulfill the above-mentioned purposes.
We may pass on personal data to court, public authorities or law firms, if we are legally obliged to do so or if this is necessary for the assertion, exercise or defense of legal claims.
In addition, we are supported by service providers (so-called data processors) e.g. for IT maintenance services. Those service providers process the personal data only on instructions from Knorr-Bremse and are bound by contract to adhere to all applicable data protection requirements.
In some cases, the mentioned recipients of personal data might be based in countries outside the European Union (EU) or the European Economic Area (EEA) that may have a lower level of data protection than within the EU. In such cases, we will ensure an adequate level of data protection for personal data by other means. A transmission will only take place if the recipient signed EU standard contractual clauses with Knorr-Bremse or has implemented Binding Corporate Rules. Further information can be obtained from the contact mentioned in paragraph 1.
Copyright © Knorr-Bremse AG. All rights reserved, including industrial property rights applications.
Knorr-Bremse AG retains any power of disposal, such as for copying and transferring 3/3

5. Retention Periods
Unless indicated otherwise at the time of the collection of the personal data, we erase your personal data if the retention of that personal data is no longer necessary (i) for the purposes for which they were collected or otherwise processed, or (ii) to comply with legal obligations (such as retention obligations under tax or commercial laws).

6. Your Rights
Subject to the requirements stipulated by the GDPR, you have the following rights:
• access to your personal data,
• the rectification of incorrect or incomplete data,
• deletion of your personal data,
• restriction of the processing of your personal data,
• the right to receive your personal data in structured, commonly used and machine-readable format and the transfer of that the data to another controller,

7. Right to object
Where we process your personal data based on our legitimate interest (Art. 6 Para. 1 lit. f) GDPR) and there are reasons based on your particular situation, you may have the right to object to the processing of your personal data. Especially you may object to the processing for the purposes of direct marketing.

8. Right to withdraw consent
Where we process your personal data based on your consent, you have the right to withdraw that consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

9. Contact and competent Data Protection Authority
If you have any questions about privacy or wish to exercise your rights, please contact the Knorr-Bremse data protection organization at privacy@knorr-bremse.com.
We take your requests very seriously and are committed to address any of your concerns. Nonetheless, you have the right to file a complaint with a competent data protection authority at any time. In Bavaria, the competent supervisory authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

 

Privacy policy for social media presence

Thank you for visiting our social media presence and taking an interest in our company and our products. Protecting personal data is very important to us. For this reason, Knorr-Bremse pro-cesses your data in accordance with the provisions of the EU’s General Data Protection Regulation (GDPR) and other applicable legislation concerning the protection of personal data and data secu-rity.
With this privacy policy, we inform you about the processing of your personal data and about your rights as a data subject in connection with the use of the social media presences operated by Knorr-Bremse AG and its affiliated companies („Knorr-Bremse Group“). The contact details of Knorr-Bremse AG can be found under point 1. You can also find information on the persons re-sponsible for the respective social media presence under the contact details listed there.
The following terms and conditions only apply insofar as the data processing performed within the scope of these social media presences actually lies within our area of responsibility and no more specific and therefore overriding privacy policy is provided within the scope of these social media presences.
1. Responsible body
The responsible body within the meaning of data protection law is
Knorr-Bremse AG Moosacher Str. 80 80809 München Germany Tel.: +49 89 3547-0 Email: info@knorr-bremse.com Internet: www.knorr-bremse.com
The responsible entity is the group company specified in the legal notice of the respective social media presence.
The contact details of the data protection officer are:
Group Data Protection Officer Knorr-Bremse AG Moosacher Str. 80 80809 München Germany Email: datenschutzbeauftragter@knorr-bremse.com
Copyright © Knorr-Bremse AG. All rights reserved, including industrial property rights applications.
Knorr-Bremse AG retains any power of disposal, such as for copying and transferring 2/8

5. LinkedIn company page
We use the „LinkedIn“ service of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ire-land (contact the data protection officer) and operate our LinkedIn company page via this service.
The following functionalities are available to you on our LinkedIn company page:
 Interact with us and other users
 Comment on posts
When interacting with you as a user of our LinkedIn company page, the following data is pro-cessed:
 Date and time of the interaction
 Type and content of interaction (e.g. direct messages, comments)
 Profile name
 Profile picture
The privacy policy of LinkedIn Ireland Unlimited Company can be accessed here.
Copyright © Knorr-Bremse AG. All rights reserved, including industrial property rights applications.
Knorr-Bremse AG retains any power of disposal, such as for copying and transferring 5/8
The processing of your personal data in the context of the operation of the LinkedIn company page is based on Article 6 Paragraph 1 Points b) and f) of the GDPR and serves the interaction with us and other users and the provision of information about our company and current job vacancies. As such, processing is necessary for the purpose of pursuing a legitimate interest.
The recipients of your personal data are internal departments. We do not transfer your data to a third country. Regarding the recipients and the third country transfer of LinkedIn Ireland Unlimited Company, please refer to its privacy policy.
We delete your personal data after fully responding to the direct communication or after removal of the post being commented on. In addition, illegal content is deleted as necessary. Regarding dele-tion by LinkedIn Ireland Unlimited Company, please refer to its privacy policy.
6. Xing company profile
We use the „Xing“ service of XING SE, Dammtorstraße 30, 20354 Hamburg, Germany (contact the data protection officer) and operate our Xing company profile via this service.
The following functionalities are available to you on our Xing company profile:
 Interact with us and other users
 Comment on posts
 Mark us as employer of choice
When interacting with you as a user of our Xing company profile, the following data is processed:
 Date and time of the interaction
 Type and content of interaction (e.g. direct messages, comments)
 Profile name
 Profile picture
The privacy policy of XING SE can be accessed here.
The processing of your personal data in the context of the operation of the Xing company profile is based on Article 6 Paragraph 1 Points b) and f) of the GDPR and serves the interaction with us and other users and the provision of information about our company and current job vacancies. As such, processing is necessary for the purpose of pursuing a legitimate interest.
The recipients of your personal data are internal departments. We do not transfer your data to a third country. Regarding the recipients and the third country transfer of XING SE, please refer to its privacy policy.
We delete your personal data after fully responding to the direct communication or after removal of the post being commented on. In addition, illegal content is deleted as necessary. Regarding dele-tion by XING SE, please refer to its privacy policy.
Copyright © Knorr-Bremse AG. All rights reserved, including industrial property rights applications.
Knorr-Bremse AG retains any power of disposal, such as for copying and transferring 6/8

7. Kununu company profile
We use the „kununu“ service of XING SE, Dammtorstraße 30, 20354 Hamburg (contact the data protection officer) and operate our kununu company profile via this service.
The following functionalities are available to you on our kununu company profile:
 Rate us as a current or former employer
 Rate the application process you completed with us
As a rule, it will not be possible to derive any personal information about you from your rating, as you will not be asked to identify yourself when submitting the rating. If you provide personal data in your rating or if it is possible to derive any personal information about you from the content of your rating in individual cases (for example, because your position is unique within a certain division), we will process the following personal data about you:
 Date and content of your rating
 Job status (if specified)
 Position/seniority (if specified)
 Division (if specified)
The privacy policy of XING SE can be accessed here.
The processing of your personal data in the context of the operation of the kununu company profile is based on Article 6 Paragraph 1 Points b) and f) of the GDPR and serves the interaction with us and other users and the provision of information about our company. As such, processing is neces-sary for the purpose of pursuing a legitimate interest.
The recipients of your personal data are internal departments. We do not transfer your data to a third country. Regarding the recipients and the third country transfer of XING SE, please refer to its privacy policy.
We delete your personal data after fully responding to the direct communication or after removal of the post being commented on. In addition, illegal content is deleted as necessary. Regarding dele-tion by XING SE, please refer to its privacy policy.

8. YouTube channel
We use the „YouTube“ service of YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066 USA (represented by Google, Inc, Amphitheatre Parkway, Mountain View, CA 94043, USA) (contact the data protection officer) and operate our YouTube channel via this service.
The following functionalities are available to you on our YouTube channel:
 Interact with us and other users
 Participate in surveys and competitions
Copyright © Knorr-Bremse AG. All rights reserved, including industrial property rights applications.
Knorr-Bremse AG retains any power of disposal, such as for copying and transferring 7/8
 Comment on posts
When interacting with you as a user of our YouTube channel, the following data is processed:
 Date and time of the interaction
 Type and content of interaction (e.g. likes, direct messages, comments)
 Profile name
The privacy policy of Google, Inc can be accessed here.
The processing of your personal data in the context of the operation of the YouTube channel is based on Article 6 Paragraph 1 Points b) and f) of the GDPR and serves the interaction with us and other users and the provision of information about our products and our company. As such, processing is necessary for the purpose of pursuing a legitimate interest.
The recipients of your personal data are internal departments. We do not transfer your data to a third country. Regarding the recipients and the third country transfer of Google, Inc., please refer to its privacy policy.
We delete your personal data after fully responding to the direct communication or after removal of the post being commented on. In addition, illegal content is deleted as necessary. Regarding dele-tion by Google, Inc., please refer to its privacy policy

9. Rights of the data subject
As a subject of data processing, you benefit from a number of rights. Specifically:
The right to be informed: You have the right to obtain information about the data we have col-lected about you.
The right to rectification and erasure: You can demand that we correct any incorrect data and – insofar as the legal requirements are met – erase your data.
The right to restrict processing: Insofar as the legal requirements are met, you can demand that we restrict the processing of your data.
The right to data portability: If you have provided us with data on the basis of a contract or con-sent, you may, insofar as the legal requirements are met, demand that we send you the data you have provided in a structured, common and machine-readable format or that we transfer it to an-other responsible party.
Objection to data processing on the legal basis of „legitimate interest”: You have the right to object to data processing by us at any time for reasons arising from your particular situation, inso-far as this rests on the legal basis of „legitimate interest“. If you exercise your right to object, we will stop processing your data unless we can demonstrate – in accordance with the legal requirements – compelling reasons worthy of protection for the further processing that outweigh your rights.
Copyright © Knorr-Bremse AG. All rights reserved, including industrial property rights applications.
Knorr-Bremse AG retains any power of disposal, such as for copying and transferring 8/8
Objection to data processing for the purpose of direct marketing: If we process your personal data on the legal basis of „legitimate interest“ for the purpose of direct marketing, you have the right to object to this processing at any time.
Withdrawal of consent: If you have given us consent to process your data, you can withdraw this consent at any time with future effect. The lawfulness of the processing of your data up until the withdrawal remains unaffected by this.
The right to lodge a complaint with a supervisory authority: You can also lodge a complaint with the competent supervisory authority if you believe that the processing of your data violates ap-plicable law. To do this, you can contact the data protection authority responsible for your place of residence or for your country or the data protection authority responsible for us.
Contacting us and exercising your rights: Furthermore, you can contact us free of charge if you have any questions about the processing of your personal data, your rights as a data subject and any consent you may have given. To exercise any of your aforementioned rights, please contact us at the address given above in the section „Responsible body“.
When doing so, please ensure that it is possible for us to clearly identify you. When withdrawing consent, you can also use the same contact method that you used when giving your consent.

10. Status
The current version of this privacy policy applies.
Status: 23 February 2021 – Version 1.0