The privacy policy of HSR GmbH

Data protection information

General information and mandatory information

The aim of data protection and us as HSR GmbH is to organise the handling of personal data in such a way that the personal rights of the individual are protected.

In order to ensure the fulfilment of this objective, entities responsible for the processing of personal data are obliged to comply with the provisions of EU legislation (General Data Protection Regulation (GDPR)) and national data protection laws.

Personal data may only be collected and processed if this is permitted by the GDPR or another law. The fundamental principles of the GDPR are

  • Lawfulness of processing, processing in good faith, transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy of the data processing
  • Storage limitation and erasure concepts
  • Integrity and confidentiality
Information obligations of the controller and rights of the data subject

Name and contact details of the controller

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e. g. names, email addresses etc.).

The controller responsible for data processing on this website is

Oderstraße 3

47506 Neukirchen-Vluyn

Telephone: +49 (0) 2845 / 2950 - 170


Contact details of the data protection officer

You can reach our data protection officer at   

Purpose of data collection, processing or use

HSR GmbH specialises in all aspects of high-pressure connections for systems in industry and the construction sector.

The collection, processing or use of personal data is carried out to fulfil this corporate purpose or supporting secondary purposes (e.g. customer advice).

Affected groups of persons and related data or data categories

The groups of persons concerned are:

  • Current employees
  • Former employees
  • Applicants
  • Interested parties
  • Customers
  • Suppliers
  • Service providers
  • Other business partners

The relevant data includes all personal data required to fulfil the respective purpose. The specific data of the data subjects that is processed is explained in detail below.

Legal basis

The processing of personal data is only lawful if this is permitted by law, i.e. if there is a legal basis, or if the person has given their consent.

Personal data is only processed in our company in accordance with the statutory provisions. As a rule, these are

  • if consent to the processing of personal data has been given (Art. 6 para. 1 lit. a GDPR),
  • if personal data must be processed for the fulfilment of a contract or the initiation of a contract (Art. 6 para. 1 lit. b GDPR),
  • if the processing of personal data is necessary to fulfil a legal obligation (Art. 6 para. 1 lit. c GDPR) or
  • if we process personal data on the basis of a legitimate interest or on the basis of a legitimate interest of a third party (Art. 6 para. 1 lit. f GDPR).

Special feature regarding the legal basis of data processing for contractual purposes

HSR GmbH primarily addresses its services to tradespeople. Therefore, when processing personal data for contractual purposes, the legal basis is, unless otherwise specified in individual cases

1. if you are a registered trader or freelancer, Art. 6 para. 1 lit. b GDPR, data processing for the purpose of performing the contract or pre-contractual measures with the data subject; or
2. if you act as an employee of a company, e.g. as an employee in purchasing, Art. 6 para. 1 lit. f GDPR, is the legitimate interest of HSR GmbH. The legitimate interest of HSR GmbH in this case is the sale of its own goods and services, which is based in particular on entrepreneurial freedom and freedom to choose an occupation.

As part of this processing purpose, we summarise data that is stored and processed in our central systems as a result of interactions with us by customers or interested parties and their employees via the various communication channels (in particular field service, branches and telephone sales) and also use the data when contacting you via another communication channel.

For the sake of simplicity, the term "data processing for contractual purposes" is used below.

Potential recipients for data transfers

The potential recipients of transferred personal data are

  • Public authorities, insofar as a legal obligation exists or this is necessary to safeguard legal claims,
  • Service providers and other business partners, insofar as this is necessary to fulfil the respective purpose and a legal provision permits or requires this or the data subject has consented.
Planned data transfer to third countries or international organisations

If we transfer your data to a third country (countries that are not member states of the European Union) or to an international organisation, we will provide you with the information required for this case.

Standard periods for the deletion of data

The deletion of personal data is carried out in accordance with the applicable statutory or contractual regulations on data deletion, taking into account statutory or contractual retention obligations. Such legal obligations arise from the German Commercial Code (HGB) and the German Fiscal Code (AO), among others. The retention and documentation periods specified there are up to ten years beyond the end of the business relationship or the pre-contractual legal relationship.

Furthermore, other statutory provisions may require a longer retention period, such as the preservation of evidence within the scope of the statutory limitation period. The regular limitation period is three years; in certain cases, however, limitation periods of up to 30 years or, in individual cases, even longer may apply. The deletion of personal data that is not subject to any statutory or contractual retention or deletion obligation takes place after it is no longer required to fulfil the respective purpose.

Your rights with regard to data protection (Art. 12 ff. GDPR)

The data subject has various rights with regard to data protection. These rights are explained below. The above contact details can be used to exercise these rights.

Right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), restriction of processing (Art. 18 GDPR) and erasure (Art. 17 GDPR)

Within the framework of the applicable legal provisions, you have the right to obtain information free of charge at any time about the personal data concerning you that is stored by the controller, its origin and recipients and the purpose of the data processing and, if applicable, a right to rectification, blocking or erasure of this data.

Right to object (Art. 21 GDPR)

Every data subject has the right to object to the processing of their data if the data processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR or for direct marketing purposes. In the event of an objection to the processing of your personal data, we will examine your objection on a case-by-case basis. If we are obliged to erase your personal data due to your objection under data protection law, we will erase your data in compliance with statutory retention obligations. The objection does not affect the permissibility of the processing that took place before the objection.

Right to data portability (Art. 20 GDPR)

You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract transferred to yourself or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place if it is technically feasible.

Obligation to disclose data

Every data subject has the right to know whether the provision of personal data is required by law or contract or is necessary for the conclusion of a contract, whether the data subject is obliged to provide the personal data and what the possible consequences of non-provision would be.

Right to lodge a complaint with the competent supervisory authority

Data subjects have the right to lodge a complaint with the competent supervisory authority if they believe that their rights have been violated. The competent supervisory authority for data protection issues is the state data protection officer of the federal state in which our company is based. In principle, however, the person concerned can also contact the supervisory authority of their place of residence or the place of the suspected infringement.  A list of data protection officers and their contact details can be found at the following link:

Withdrawal of your consent to data processing

Some data processing operations are only possible with your consent. You can withdraw your consent at any time. All you need to do is send an informal e-mail to one of the e-mail addresses given above. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Use of your data for (direct) marketing purposes

Irrespective of your subscription to our newsletter, we may use your data, in particular your e-mail address, for (direct) marketing purposes. We will only use your data for this purpose if you have not objected to this. We would like to point out that you can object to the use of your data for (direct) marketing purposes at any time, without incurring any costs other than the transmission costs at the basic rates.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Data collection on our website

Server log files

When you visit our website, we process information in so-called server log files, which your browser automatically transmits to us. The purpose of data processing is to ensure that the website is displayed correctly and to guarantee the secure operation of the website.

Categories of processed data

The categories of data collected are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Date and time of the server request
  • IP address
  • Amount of data transferred
  • Message about successful retrieval
  • Name of the website accessed
  • Requesting internet service provider

This data is not merged with other data sources.

Legal basis

The legal basis for data processing is Article 6 para. 1 lit. f GDPR, § 25 para. 2 no. 2 TTDSG. As the website operator, we have a legitimate interest in the correct presentation of the website and in ensuring the secure operation of the website.

Storage period

The data that is processed in connection with the collection of server log files is stored for as long as is necessary for the stated purposes.


The websites of HSR GmbH partly use so-called cookies. Cookies are used to make our website more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

We process cookies for contractual purposes if they are required to carry out the electronic communication process or to provide our services (e.g. shopping basket function). HSR GmbH primarily uses these cookies to process your orders in the online shop. Insofar as other cookies (e.g. cookies to analyse your surfing behaviour) are stored, these are treated separately in this data protection information and only processed with your prior consent.

You can view an overview of the active cookies on this page under "Analysis tools and advertising". The cookie settings can also be changed there at any time.

"Do Not Track" settings

You can control the storage of cookies using the "Do Not Track" (DNT) settings in your browser. Depending on the browser, DNT is either a setting in the programme settings or a so-called plug-in or add-on. When activated, the browser signals that tracking measures by this tool are not desired without your explicit consent. If the setting is activated, the tracking functions of tools are anonymised by us. Please note that the procedure for activating DNT differs depending on the browser you are using.

Alternatively, you can check whether advertising cookies are set in your browser and deactivate them on the deactivation page for consumers from the EU (

Contact form

If you send us an enquiry via the contact form, your details from the enquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions.

Categories of personal data

The following categories of personal data are processed for an enquiry via the contact form:

  • Salutation
  • Your name
  • Company name
  • Location
  • E-mail address
  • Telephone number
  • Your message

Legal basis

The mandatory data is processed for contractual purposes. The processing of the data voluntarily provided by you is carried out on the basis of Art. 6 para. 1 lit. f GDPR. This permits processing that is necessary to safeguard our legitimate interests. Our legitimate interest is to have contact with you, our customers, to improve the quality of our advice and to be able to contact you more easily in the event of any queries.

Storage period

The data you enter in the contact form will remain with us until you ask us to delete it or the purpose for storing the data no longer applies (e.g. after your enquiry has been processed). An exception to this may be statutory retention obligations.


MyHSR is your digital customer area. After registering in the customer portal, you can conveniently access your invoices, search for them by invoice number and even download the associated service reports with just one click. The mandatory information requested during registration must be provided in full. Otherwise we will reject your registration.

Categories of processed data

The following data is processed when you use the online shop:

Company details

  • Customer number*
  • Company name*

Personal details

  • Salutation*
  • First name*
  • Surname*
  • Telephone number
  • Position in the company
  • E-mail*
  • Password*

Legal basis

The processing of the mandatory information (marked with "*") when registering in MyHSR serves data processing for contractual purposes.

The processing of the data voluntarily provided by you is carried out on the basis of Art. 6 para. 1 lit. f GDPR. According to this, processing is permitted if it is necessary to safeguard our legitimate interests. Our legitimate interest is to improve the quality of our advice and to be able to contact you more easily in the event of any queries.

Storage period

The data collected will be stored by us for as long as you have a business relationship with us.  Your data will be deleted once the business relationship has ended. After cancellation of your access to the online shop, your Würth customer account will be retained and your customer data will continue to be stored. Statutory retention periods remain unaffected.

Applicant portal

We use a digital applicant portal for our applicant management. The provider is rexx systems GmbH, Süderstraße 75-79, 20097 Hamburg. We collect and process applicants' personal data when they apply. The information provided by the applicant in the applicant profile is processed by us to handle the application process.

Categories of processed data

The following categories of personal data are processed when using the applicant portal

  • Salutation
  • First name
  • Surname
  • Date of birth
  • Telephone number
  • E-mail address
  • Your address
  • Details in
    • Cover letter
    • curriculum vitae
    • Certificates
    • Other documents relevant to the application

Legal basis  

The legal basis for the processing of applicant data is Art. 6 para. 1 lit. b i. in conjunction with Art. 88 GDPR, § 26 BDSG.

Storage period

If the application is not considered as part of the application procedure, the application documents will be automatically deleted no later than six months after notification of the rejection decision, provided that no other legitimate interests of the data controller conflict with deletion.

Further use of the applicant profile

If the applicant profile is also to be considered for future job advertisements, this will only take place with the consent of the applicant.

In this case, the legal basis for the further storage and processing of the applicant data is Art. 6 para. 1 lit. a GDPR. This consent can be revoked at any time. Please contact us for this purpose:


HR Development

Oderstraße 3

47506 Neukirchen-Vluyn 

Applicants have the option of withdrawing their applications at any time. In this case, the application documents will be deleted immediately.

Perspective applicant funnel

We use an external service provider for the provision of contact, enquiry or application forms: Perspective Software GmbH, Mailbox 659770, D-96035 Bamberg (hereinafter referred to as "Perspective"). Perspective itself stores your data exclusively on European servers. However, there is a possibility that your data may be accessible to organisations in the United States of America because Perspective uses sub-processors based in the USA. As the Commission of the European Union has determined that the data protection laws of the United States do not ensure an adequate level of protection for personal data collected from data subjects in the European Union, Perspective provides additional measures and safeguards for data transfers to the United States in accordance with the requirements of the GDPR to ensure an adequate level of protection. For example, by concluding standard contractual clauses between Perspective and the sub-processors.

Categories of data processed

When using Perspective's contact, enquiry or application forms, the following data is transmitted to Perspective's servers:

  • Date and time of access
  • Websites from which you came to our website ("referrer")
  • Context information (e.g. button clicks on the pages, selections made on the pages)
  • Contents of all completed text fields (e.g. contact details, such as your name or address, or other personal data, depending on the question shown in the specific text field)
  • Files uploaded by you 

Legal basis  

‍‍The purpose of this data processing is to ensure the communication you have recorded.

The processing of your data from contact, enquiry or application forms is therefore initially based on your consent. The legal basis is Art. 6 para. 1 sentence 1 lit. a GDPR. If a contract is initiated via an enquiry form, the legal basis is also Art. 6 para. 1 sentence 1 lit. b GDPR. The legal basis for the processing of data in an application form may be Art. 88 GDPR in conjunction with 26 BDSG in addition to Art. 6 para. 1 sentence 1 lit. f GDPR.

Storage period

Your personal data will be stored for as long as it is necessary to fulfil the purpose of processing or until you withdraw your consent. Exceptions to this principle are data that Perspective must retain due to legal obligations. These include, for example, retention obligations under commercial and tax law. These retention periods are - currently - up to ten years.

Analysis tools and advertising

Services used on our website

Our website uses various services to improve functionality and user-friendliness. Below you will find a detailed list of the services used, their purpose and information about the respective providers:

1. Usercentrics Consent Management Platform

Purpose: Management of consents to the use of cookies and other technologies on our website.
Provider: Usercentrics GmbH

2. DoubleClick Ad

Purpose: Display of personalised advertising.
Provider: Google Inc.
Data processing in: USA

3. facebook social plugins

Purpose: Integration of Facebook content and interaction options.
Provider:Facebook Inc.
Data processing in:USA

4. google analytics

Purpose:Analysis of user behaviour on our website.
Provider:Google Inc.
Data processing in: USA
Note:We use Google Analytics with activated IP anonymisation.

5. google fonts

Purpose: Provision of fonts.
Provider:Google Inc.
Data processing in: USA

6. google maps

Purpose: Display of interactive maps.
Provider: Google Inc.
Data processing in:USA

7. google optimise

Purpose: To carry out A/B tests and personalisation.
Provider: Google Inc.
Data processing in: USA

8. google tag manager

Purpose: Management of website tags.
Provider: Google Inc.
Data processing in:USA

9. google translate

Purpose:Provision of translation functions.
Provider:Google Inc.
Data processing in: USA


Purpose: Loading static content such as libraries and frameworks.
Provider:Google Inc.
Data processing in: USA

11. Microsoft Clarity

Purpose: Analysis of user behaviour and session recordings.
Provider:Microsoft Corporation
Data processing in: USA

12. vimeo

Purpose: Integration and display of videos.
Provider: Vimeo Inc.
Data processing in: USA

13. YouTube Video

Purpose:Integration and display of videos.
Provider: Google Inc.
Data processing in: USA


Consent and cancellation

Some of these services are only activated after you have given your consent. You can adjust or revoke your consent at any time via the settings in our cookie banner. 

Data transfer to third countries

Please note that data may be transferred to third countries (e.g. the USA) when you use the above-mentioned services. These countries may not have a level of data protection comparable to that of the EU. We have concluded corresponding data protection agreements with the providers of these services in order to ensure adequate protection of your data.

Social networks

We maintain profiles on social networks to present our company and to communicate with customers and interested parties. In the following, we will inform you about the associated processing activities.

Data processing for presentation and communication

Social networks enable us to present our company to people who have an account with the social network (hereinafter "users") and to all visitors to our profiles without an account with the social network (hereinafter "guest"). Furthermore, customers and interested parties can contact us via this profile. As a rule, our profiles and posts can be viewed by users and guests (hereinafter users and guests are referred to collectively as "visitors"). If you comment on our posts or send us a message, this data is stored by the social network and can be viewed by us. We can reply to your comment or message. In the case of posts, your comment and our reply may still be visible to all users of the social network or to all visitors.

Data processing for statistical and advertising purposes

When you visit our profile, the social network can save and evaluate your visit and all other interactions you have on the social network's website. This data is made available to the profile owners as statistics and processed by the social networks for advertising purposes, among other things.

If you have an account with the social network and are logged in when you visit our profile, the provider of the social network can link your interactions with our profile to your account data and process them further. However, it is also possible that data about your interactions with our profile may be stored by the social network for the duration of your visit and processed for further purposes if you are not logged in there or do not have an account. In this case, an assignment can be made, for example, through the use of cookies, small files that are stored on your end device, or in connection with your IP address.

The purpose of data processing is generally to create a profile of the visitor's interests and to use these profiles for advertising purposes. If a person visits certain websites, information about this visit is analyzed and the provider assigns interests to the visitor. Based on the assigned interests, the visitor is shown advertisements. Interest-based advertisements can be displayed by the provider both within and outside the websites of the social network.

Categories of data subjects

Persons who access our profile on the respective social network (both users with an account with the provider of the social network and visitors without an account).

Asserting your rights as a data subject

For requests for information or to assert your other rights as a data subject, we recommend that you contact the provider directly, as only the provider has full access to the data that is processed in connection with accessing our profile or interacting with us on the social network. You can find the social networks' contact information for exercising your rights as a data subject under "Information on the social networks we use". In the case of data processing where the provider of the social network and we are jointly responsible, you also have the right to assert your rights as a data subject against us. In such a case, we will forward your request to the social network insofar as the request concerns data or processing activities that are processed by the social network.

Further information on the processing activities of the social networks and the existing options to object can be found under "Information on the social networks we use".

Information about Facebook and Instagram:



Meta Platforms Ireland Limited , 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter "Facebook")


Form for contacting the Facebook data protection officer 

Facebook data policy 

Our profile 




Meta Platforms Ireland Limited , 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland


Data policy of Instagram 

Our profile


Categories of personal data processed when visiting our profile on Facebook and Instagram

  • Technical information about the end device: operating system, information about the browser used, IP address, other information about the end device and the internet connection
  • Contact details: If applicable, information about the user's account;
  • Data about interactions: Information about profiles visited, links clicked, date and time of interaction, other interactions of the visitor.

Further information on the processed data can be found at 

Shared responsibility for the processing of Page Insights data

We have entered into a joint controllership agreement with Meta that applies to the processing of data in connection with our profile on Facebook (the "Page") for the prov­­ision of the profile and the statistical analysis of the interactions of visitors to our profile. This agreement specifies which obligations in connection with data processing are to be fulfilled either by Meta or by us and which party is responsible for the individual processing activities.

Agreement on joint responsibility for data processing for Page Insights between Meta and us as the owner of a profile on Facebook in accordance with Art. 26 GDPR: 

Further information on the processing of Page Insights data: 

Purposes and legal basis

  • Presentation of our company, legitimate interest (Art. 6 para. 1 lit. f GDPR)

Processing for this purpose is based on the legitimate interests of the company. Specifically, the interest in maintaining the corporate culture and the company's public relations work. These interests are derived from our right to entrepreneurial freedom and professional freedom.

  • Communication with customers and interested parties, legitimate interest (Art. 6 para. 1 lit. f GDPR)

The processing of data in messages or comments on Facebook is based on our legitimate interests in offering customers and interested parties an easy way to contact us and to improve the quality of our advice. These interests are derived from our right to entrepreneurial freedom and professional freedom.

  • Statistical purposes, legitimate interest (Art. 6 para. 1 lit. f GDPR)

The processing of data for statistical purposes in connection with Page Insights is based, insofar as we are jointly responsible for the processing with Meta, on our legitimate interest in improving the quality of our advice. This interest is derived from our right to freedom to conduct a business and freedom to choose an occupation.

Insofar as Meta carries out further processing activities or processes data for statistical or advertising purposes, Meta is the controller for the processing and the processing may be based on other legal bases. Further information on this can be found under "Meta's Data Policy".


Processor of Meta

When using Facebook, personal data may also be transferred to Meta Platforms Inc, 1 Hacker Way, Menlo Park, CA 94025, USA in the USA. For the transfer of personal data to Meta Platforms Inc. based in the USA, Platforms Ireland Limited uses so-called standard contractual clauses of the Commission of the European Union. A copy of the standard contractual clauses used can be requested here: 

Options to object

If you wish to object to processing by Meta, you will find options for objecting to various processing activities under this link: 

For your Facebook account, you can use the following link to manage the advertising settings yourself and, for example, deactivate interest-based advertising: 

If you do not have a Facebook account, you can use the following link to deactivate interest-based online advertising for participating websites: 

Right to lodge a complaint

You have the right to lodge a complaint with the competent supervisory authority. You can find out which supervisory authority is responsible in this data protection information under "Right to lodge a complaint with the competent supervisory authority". With regard to processing in connection with our profile on Facebook, you can also contact the Irish Data Protection Commission. You can find the contact details of the Irish Data Protection Commission at 

Information on the other social networks we use:


Provider: XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany


Privacy policy: 

Our profile:   



Provider:  LinkedIn Ireland Unlimited Company, Attn: Legal Dept (Privacy Policy and User Agreement), Wilton Plaza, Wilton Place, Dublin 2, Ireland


Privacy Policy:   

Our profile: 

Disclaimer/ update/ status

HSR GmbH's data protection information does not apply to applications, products, services, websites or social media functions of third-party providers that can be accessed via links that we provide for information purposes. When using these links, you leave the HSR GmbH website, so there is a possibility that information about you may be collected or passed on by third parties. HSR GmbH has no influence whatsoever on third-party websites and makes no recommendations or assurances about these websites or their data protection practices. We therefore encourage you to carefully read and review the privacy policies of all websites with which you may interact before allowing them to collect, process and use your personal data.

We ask you to inform yourself regularly about the content of our privacy policy. We will adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. If we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and ask you to check the information before contacting us.

Status: May 2024