Privacy Policy for Business Partners and Prospective Clients of the Diehl Group

Blurry image

We hereby inform you about the processing of your personal data (hereinafter also referred to as “data”) by the Diehl Group and the rights to which you are entitled.

Your personal data is processed in compliance with the General Data Protection Regulation (GDPR) and other applicable legal regulations.

Data Categories / Origin

We process the following data as part of contractual relationships and for contract initiation:

  • Contact data, e.g., first/last name of current and previous contact persons and honorifics, company name and address, telephone number with extension and business email address
  • Professional data, e.g., function at company and division

Your data is provided to us by you during contract initiation or over the course of a contractual relationship.

Data Processing Purposes and Legal Bases

Your data is processed for the performance of pre-contractual measures, e.g., to prepare offers for products or services, and for the performance of contractual obligations, e.g., to perform our services or complete orders or payments. The legal basis for this is Art. 6(1) Letter b GDPR. In addition, we will process your data in case of corresponding legal obligations, e.g., due to tax law requirements. The legal basis for this is Art. 6(1) Letter c GDPR.

We are also interested in maintaining relationships with our clients. If you are one of our clients, we will process the data provided by you to, e.g., send you information about additional services by email. The legal basis for this is Art. 6(1) Sentence 1 Letter f GDPR. If you are not in accordance this, you may object to the use of your personal data for such direct marketing purposes at any time; this also applies to profiling if related to direct marketing. If you object, we will no longer process your data for these purposes. Objections may be submitted informally, free of charge and without stating reasons via the unsubscribe link in our emails or to

For the detection of crimes, your data will only be processed in compliance with Art. 10 GDPR.

Your consent to data processing (Art. 6(1) Letter a GDPR) may, of course, also represent your permission under data protection law. We will inform you about the purpose of the data processing and about your right to object under Art. 7(3) GDPR before you grant your consent.

Data Storage Duration

When your data is no longer necessary for the above-stated purposes or if you withdraw your consent, we will erase your data. We will only store your data beyond the contractual relationship if we are required or authorized to do so. Regulations of, e.g., the German Commercial Code [Handelsgesetzbuch, HGB] or the German Fiscal Code [Abgabenordnung, AO] may require us to store your data for up to 10 years. In addition, legal limitation periods must be observed.

Data Recipients / Categories of Recipients

At our company, we ensure that your data is only provided to divisions and persons that need your data for the performance of our contractual and legal obligations.

In many cases, service providers assist our divisions with the performance of their tasks. Necessary data protection agreements are concluded with these service providers.

Transfers to Third Countries / Intentions of Transfers to Third Countries

Data will only be transferred to third countries (outside of the European Union or the European Economic Area) if necessary for the performance of the contractual or supplier relationship or if required by law or with your consent.

We will not transfer your personal data to service providers or allied companies outside of the European Economic Area.

Data Subject Rights

Your rights as a data subject are specified by Art. 15 - 22 GDPR.

These include:

  • The right of access (Art. 15 GDPR)
  • The right to rectification (Art. 16 GDPR)
  • The right to erasure (Art. 17 GDPR)
  • The right to restriction of processing (Art. 18 GDPR)
  • The right to object to processing (Art. 21 GDPR)
  • The right to data portability (Art. 20 GDPR)

To exercise these rights, please contact us at: The same applies if you have any questions about data processing by our company or wish to withdraw your consent. In addition, you may lodge a complaint with a data protection supervisory authority.

If we process your data for the purpose of legitimate interests, you may object to this processing at any time on grounds relating to your particular situation; this also applies to profiling based on this regulation.

We will then no longer process your data, unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.


Status 1st of October 2019