Data protection information for new contacts

Information to new contacts in accordance with Art. 13 GDPR

Responsibility for data processing

BHS Control Systems GmbH & Co. KG
(Member and subsidiary of the BHS-Sonthofen Group) 
An der Eisenschmelze 47
87527 Sonthofen

Purpose of data processing

We only process your personal data in compliance with the relevant data protection regulations.

We use your data to respond to inquiries or to make contact and communicate on the respective matter and to process the contract.

We store and process your data in our internal administration programs, e-mail program and Office programs.

Access to your data is defined according to a rights and roles concept and is only permitted to the group of persons required for the respective purpose.

Legal basis of the processing

The legal basis for the processing of your personal data is primarily Art. 6 para. 1 lit. b) GDPR. Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps prior to entering into a contract.

If necessary, we also base the processing on Art. 6 para. 1 lit. f) GDPR. Processing takes place on the basis of legitimate interest. We assume that processing for communication purposes, for example, is also in the interests of the data subject. This also includes the storage of your data in our internal administration programs/systems.

For certain other processing operations, we also base the processing on your consent (Art. 6 (1) (a) GDPR). In these cases, we will obtain your consent separately.

Storage duration or criteria for determining the duration

We only store the data you provide to us for as long as necessary to fulfill the aforementioned purposes or as stipulated by the various storage periods provided for by law. For example, the retention period for your data may be derived from Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO). Here, every merchant is required to keep commercial books for a period of 10 years and commercial letters (including e-mails relevant to contracts) for a period of 6 years. The retention period begins at the end of the calendar year in which the last entry was made in the commercial register or the commercial letter was received or sent.

If the respective purpose no longer applies or after the corresponding periods have expired, your data will be routinely blocked or deleted in accordance with the statutory provisions.

Disclosure of your data to third parties

We only transfer your personal data to third parties if this is permitted by law or if you have given your consent.

We pass on your data to the following service providers for the purpose described in each case: Company commissioned for transportation/forwarding agent - coordination of delivery.

The service provider used may have access to your data as part of IT support. We have concluded an order processing contract with the provider, which ensures the protection of the data and prohibits unauthorized disclosure to third parties.

Data transfer to a third country or an international organization

Third countries are countries in which the GDPR is not directly applicable law. This basically includes all countries outside the EU or the European Economic Area.

No data is transferred to a third country or an international organization without a legal basis.

By using Microsoft 365, we cannot rule out the possibility that data may be transferred to a third country (despite the servers being located in Germany).

The following applies to data transfers to the USA: Since July 2023, there has been an adequacy decision by the EU Commission (Data Privacy Framework), which identifies the USA as a third country with a level of data protection comparable to that of the EU. The adequacy decision can now serve as the basis for data transfers to certified organizations in the USA.

According to the list of certified companies published by the US Department of Commerce, Microsoft Corporation is listed as a certified company.


If the processing is based on consent, you have the option at any time to revoke the use of your data for internal purposes with effect for the future. All you need to do is send an email to this effect to Of course, you have the option of sending your revocation in writing by post to the address given by the controller or contacting us by telephone on +49 8321 6099-0.

Reference to the respective data subject rights

You have the right to receive information from us about the data we process about you (Art. 15 GDPR). You can also request that we rectify inaccurate personal data concerning you (Art. 16 GDPR). If applicable, you can request that the personal data processed about you be deleted (Art. 17 GDPR) or that the processing be restricted (Art. 18 GDPR). In certain cases, you also have the right to data portability (Art. 20 GDPR). Under certain circumstances, you can also object to the processing (Art. 21 GDPR).

Contact details of the data protection officer

Data protection law firm Lenz GmbH & Co. KG
Mr. Sven Lenz
Bahnhofstraße 50
87435 Kempten

Telefon: +49 831 930653-00

If you have any questions about data protection or other data protection concerns, please send an e-mail to the following e-mail address:

Reference to the right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with the competent supervisory authority for data protection if you believe that your personal data is being processed unlawfully.

The address of the supervisory authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach

Telefon: +49 981 53-1300
Fax: +49 981 53-981300

You can open the complaint form via the following link:

Changes to our data protection information

We reserve the right to adapt our data protection information at short notice so that it always complies with current legal requirements.