Article: Data protection
The use of our web pages without providing personal data is possible as a general rule. However, if you want to use special services provided by our company via our web page, it may be necessary to process personal data. If processing personal data is required and there is no legal basis for such processing (for example, carrying out a contractual agreement, we must ask for your consent.
In this notice, we will inform you about what data we collect on you, how we use it and how you can raise an objection to the use of the data.
1. Who or what is responsible for collecting and processing my data?
ESG Rail collects and processes your data as data controller. If you have any questions, comments and/or criticism with regard to www.deutschebahn.com/dbesg please contact:
ESG
Derwent House
rtc Business Park
London Road
Derby DE24 8UP
Please direct your questions and comments related to data privacy or data protection to the following e-mail address: enquiries@dbesg.com
Version dated: November 2022
End of expander content2. Category, scope, purpose and legal basis of data processing
All data collection and data processing is done for a specific purpose. This may include technical requirements, contractual requirements or express user requests.
For technical reasons, we must collect and store specific data when you visit www.db-esgrail.com (date and duration of your visit, the web pages you used, the identification data of the browser and operating system type in use and the website from which you came to visit us). If these data enable an indication of the number of visitors and how our website is used, data is collected and processed in anonymised form only.
In specific cases, we additionally require personal data to provide services. We use the data you provided without your express consent exclusively to perform the below-mentioned services.
In particular, the following data are collected and used:
- Contact form on the website of ESG Rail for questions directed to ESG Rail: first name, last name, e-mail address
If you send us requests using the contact form, the information you provide in the request form, including any contact information you provide there, will be used only to process the request and will be saved and processed for the event that we have any follow-up questions. Subsequently, your data will be deleted or will be locked until expiry of the retention periods under tax and commercial law and then deleted, unless you expressly consent to the further use of your data.
Legal basis of data processing:
To the extent that we have obtained your consent to process personal data, the legal basis is Article 6 (1) (a) of the General Data Protection Regulation (GDPR).
When personal data is processed that is required to fulfil a contract agreed with you, the legal basis is the contract in accordance with Article 6 (1) (b) of the GDPR. Article 6 (1) (b) of the GDPR also applies to processing activities that are required in order to perform contract activities prior to the contract, for example in cases where requests are made about our products and/or services.
If our company is subject to a legal obligation when requires the processing of personal data, for example fulfilment of tax requirements, this is considered processing in accordance with Art. 6 (1) (c) of the GDPR.
We are continually improving our offering by saving and analysing user data from online on a pseudo-anonymised basis. The legal basis for this is Art. 6 (1) (f) of the GDPR.
Version dated: November 2022
3. Are data forwarded?
The external service providers who we hire to process data are carefully selected and subject to strict contractual obligations. The service providers work in accordance with the instructions we provide and this is verified by technical and organisational actions and supplementary checks.
Furthermore, transmission of your data only takes place where you have given your express approval or on the basis of a statutory requirement.
Transmission to third countries outside the EU/EEA or to an international organisation will not take place unless appropriate guarantees have been provided. These include the EU standard contractual clauses and an adequacy decision from the EU Commission.
Version dated: November 2022
End of expander content4. When are cookies used?
Cookies are small text files for storing personal data. When a page is accessed, cookies can be transferred to it, making it possible to identify the user. Cookies help to make web pages easier for users to use.
We distinguish between cookies that are essential for the website's technical functions and cookies that are not essential for the website's technical functions.
We want to give you the opportunity to make an informed decision for or against the use of cookies that are not essential for the webpage's technical functions.
For more information on the data processing by Deutsche Bahn AG related to website analytics, click “Manage analytics” in the footer of this page.
Version dated: November 2022
End of expander content5. Web analysis service?
We use the analysis service Matomo (formerly Piwik) on our website to analyse how are website is used and to improve it regularly. The statistics we gain from this allow us to improve our offering and make it more interesting for users. With the help of small text files (cookies), we collect data on how you use our website, which includes your IP address. This data is anonymised and stored on our servers. The legal basis of the use of Matomo is Art. 6 (1) Sentence 1 (f) of the GDPR.
Your deactivation options: If you do not consent to the analysis of your user behaviour, you can change your browser settings at any time to prevent analysis cookies from being set. In addition, you can also decide whether a unique web analysis cookie can be stored in your browser, allowing the operator of the website to record and analyse different statistical data.
If you decide against this, click on the following link in order to install the Piwik deactivation cookie on your browser: https://dbwas.service.deutschebahn.com/piwik/index.php?module=CoreAdminHome&action=optOut&language=en
Version dated: November 2022
End of expander content6. Embedded content/YouTube
Offering embedded content
Our website www.db-esg-rail.com contains integrated YouTube videos. The legal basis for this is Art. 6 (1) (f) of the GDPR.
When you visit www.db-esgrail.com, you will find a link that ensures that we submit no data to Google, the operator of YouTube. Google only requests the information from our web server regarding how often the video was clicked.
When you click the link to play the video, you are leaving our website and are forwarded to YouTube. When you do this, Google, the operator of YouTube, sets cookies and pixel tags to personalise the adverts and search results. The data controller for this data processing is exclusively Google, the operator of YouTube. We do not know nor can we influence which data is processed when this happens. You can find more information here: https://www.google.de/intl/de/policies/privacy/
Version dated: November 2022
End of expander content7. How long do you store my data?
We store your data only for as long as is necessary to fulfil the purpose for which the data was to collected (for example in the context of a contractual relationship), or to comply with statutory requirements.
Version dated: November 2022
End of expander content8. What are my rights as a user of www.deutschebahn.com/dbesg?
- You may request information on what data we store about you.
- You can request the correction, deletion and blocking of your personal data as long as this is permitted by law and possible within the scope of an existing contractual relationship.
- You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for DB ESG is:
The Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow
Cheshire, SK9 5AF - You have the right to portability of the data which you have provided to us based on a declaration of consent or a contract (data portability).
- If you grant us consent to use your data, you can withdraw it at any time using the same method you used to grant it. Any processing of your personal data that took place from the time at which you granted your consent to the time at which you withdrew it will still be considered to have been lawful.
- You can opt out of targeted advertising at any time. This takes effect for the future (advertising opt-out). You can exercise your rights by sending
a letter by post to ESG Rail, ESG, Derwent House, rtc Business Park, London Road, Derby DE24 8UP
or an e-mail to enquiries@dbesg.com.
Version dated: November 2022
End of expander content10. How are links to external site handled?
If you click a link to an external website, you are leaving the pages of www.db-esgrail.com. This means that DB Systemtechnik is not responsible for the content, services or products offered on the linked website, nor is it responsible for the data protection or the technical security on the linked website.
Version dated: November 2022