DATA PROTECTION INFORMATION FOR VISITORS

Data Protection Information for Visitors

The protection of personal data of guests and visitors (hereinafter referred to as "Visitors") on our company and factory premises is of great importance to EDAG Engineering GmbH and its subsidiaries (hereinafter referred to as "EDAG"). Therefore, we hereby provide you with information on the extent to which EDAG processes personal data in accordance with applicable laws and regulations for the protection of personal data and data security.

  • I. Name and address of the data controller:
      • The data controller within the meaning of the General Data Protection Regulation (hereinafter "GDPR") and other national data protection laws of the member states, as well as other data protection provisions, is:

        EDAG Engineering GmbH
        Kreuzberger Ring 40
        65205 Wiesbaden
        Tel: +49 611 7375-0
        Fax: +49 611 7375-265
        E-Mail: info(at)edag.com
         

  • II. Name and address of the data protection officer:
  • III. Description of data processing:

      1. Description and scope of data processing
      Access to EDAG's company and factory premises is generally not freely accessible. Entry is only possible after registration, which requires the completion of a visitor questionnaire. As part of this process, personal data is collected directly from or by you.
      This includes, among other things, the following information:

      • First name, last name
      • Company or organization
      • Data on the visit (arrival and departure from the building)
      • Data on accompanying cameras or electronic devices for data processing
      • Your signature

      2. Legal basis for the processing of personal data
      The legal basis for processing personal data from the visitor questionnaire is, on the one hand, the fulfillment and compliance with legal requirements pursuant to Article 6(1)(c) of the GDPR, and on the other hand, it is based on our legitimate interests pursuant to Article 6(1)(f) of the GDPR. In the context of the balancing of interests, our interest in ensuring general security on our company and factory premises and enforcing and monitoring our rights on the premises outweighs any conflicting interests of the visitors.

      3. Purpose of data processing
      The data processing serves the purpose of restrictive access control and thus the security of the employees working on the company and factory premises, but above all, it serves the compliance with and enforcement of our rights on the premises. This, in turn, serves, among other things, the confidentiality of EDAG's trade secrets, with which visitors may come into contact when entering the company and factory premises. Access should therefore only be granted to authorized persons. For this purpose, visitor registration and the collection of personal data in the visitor questionnaire are required. This also serves the documentation of visitor management, in particular to record and determine who is present or has been present in the business premises, as well as to comply with internal guidelines and requirements.

      4. Data deletion and storage period
      Unless an explicit storage period is specified during collection, your personal data collected will be deleted as soon as it is no longer necessary to fulfill the purpose of storage, unless their temporary further processing is necessary.
      Your personal data from the visitor questionnaire will be retained for 3 years and then destroyed.

      5. Recipients of the data
      Within our company, only those departments or positions that require access to your data for the fulfillment of our contractual and legal obligations or for the purposes mentioned above will have access to it. Service providers and processors employed by us may also receive data for this purpose.
      EDAG may disclose personal data to courts, law enforcement authorities, or law firms, for example, in the event of a breach of house rules, suspicion of a criminal offense, or when required by law. This is done only if there is a legal obligation under Article 6(1)(c) of the GDPR or if it is necessary under Article 6(1)(f) of the GDPR for the establishment, exercise, or defence of legal claims, and there is no reason to believe that our visitors have an overriding legitimate interest in not disclosing the data.
      EDAG collaborates with service providers (so-called processors), such as IT maintenance service providers. These processors only act on the instructions of EDAG and are contractually obliged to comply with applicable data protection requirements. To this end, we conclude written data processing agreements with these service providers.

      6. Use of the digital visitor management system “friendlyway Visitor Flow”

      For visitor management, the EDAG Group uses the software “friendlyway Visitor Flow” of SaM Digital Solutions GmbH. The system is operated on servers in Germany; SaM is certified in accordance with ISO 27001. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. The software is used for the digital recording, management and documentation of visits. Reception employees receive defined access rights for this purpose; in addition, visitor terminals are used. Via the system, required documents, requirements and notices can be provided and corresponding confirmations by the Visitors can be recorded and stored. This information is retained for up to three years. Via the visitor terminal, a call to reception staff or the inviting person can also be triggered via Microsoft Teams. In this context, a virtual, non-personal user is used; the conversations are not recorded. For Microsoft Teams, the privacy policy for electronic communication and appointment management also applies in addition: Data Protection Teams & E-Mail - EDAG Group

      7. Data Transfer to Third Countries
      EDAG may transfer personal data to other EDAG group companies for the purposes mentioned above, but only if and to the extent necessary to fulfill the aforementioned purposes.
      If we transfer personal data to service providers or group companies outside the European Economic Area (EEA), the transfer will only take place if the third country has been confirmed by the European Commission to have an adequate level of data protection or if other appropriate data protection safeguards exist (such as binding corporate rules or EU standard contractual clauses).

  • IV. Rights of the data subjects

      If personal data relating to you is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:

      1. Right of access

      You have the right at any time, within the scope of Art. 15 GDPR, to request information about your personal data that we process.

      2. Right to rectification and completion

      If your personal data is incorrect or incomplete, you have the right, within the scope of Art. 16 GDPR, to rectification and completion.

      3. Right to restriction of processing

      If the legal requirements are met, you may request restriction of the processing of your personal data within the scope of Art. 18 GDPR.

      4. Right to erasure

      Within the scope of Art. 17 GDPR, you may request erasure of your personal data at any time, provided we are not legally obliged or entitled to continue processing your data.

      5. Right to data portability

      You have the right, within the scope of Art. 21 GDPR, to object to processing insofar as the data processing is carried out for the purposes of direct marketing or profiling. You may object to processing on the basis of a balancing of interests by stating reasons arising from your particular situation.

      7. Right to withdraw the data protection declaration of consent

      You have the right to withdraw your data protection declaration of consent at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the time of withdrawal.

      8. Right to lodge a complaint with a supervisory authority

      Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR. The supervisory authority with which the complaint has been lodged shall inform the complainant about the status and the results of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.

Status: February 2026