Information on data protection for customers and suppliers

Dear Sir or Madam,

based on Art. 12 pp. GDPR we would like to inform you about the processing of your personal data:

1. Name and contact details of the controller and the data protection officer

Responsible for the processing is:

Westfalia-Automotive GmbH
Am Sandberg 45
D-33378 Rheda-Wiedenbrück

You can contact the data protection officer via e-mail:

Please direct general inquiries regarding data protection at Westfalia-Automotive GmbH to the above-mentioned e-mail address.

2. Purposes and legal bases of data processing

At Westfalia-Automotive GmbH, we process your personal data to fulfil a contract or to carry out pre-contractual measures. This applies to customers as well as supplier relationships. The legal basis for this is Art. 6 para. 1 lit. b GDPR. The purposes pursued include:

  • Carrying out credit checks
  • Order processing (including offers, order confirmation, delivery bills, orders, invoicing, dunning, bookings, technical service, coordination of logistics, shipping, payment transactions)
  • Processing of returns and complaints; advance warranty replacement
  • Communication by mail, telephone or e-mail
  • Processing of customer and supplier inquiries that are not directly related to the fulfilment of the contract.

For the fulfilment of legal obligations, your personal data will also be processed on the basis of Art. 6 para. 1 lit. c GDPR. The purposes pursued include:

  • Fulfilment of retention and identification obligations
  • Tax reporting and control obligations
  • Processing requests from authorities

Furthermore, your personal data may also be processed on the basis of our legitimate interest in ensuring customer or supplier satisfaction, maintaining a good customer or supplier relationship, averting risks / economic disadvantages for our company and simplifying administrative procedures. The legal basis for this is Art. 6 para. 1 lit. f GDPR. The purposes pursued include:

  • Processing of customer and supplier inquiries that are not directly related to the fulfilment of the contract.
  • Digitalisation of files
  • Conducting surveys to evaluate our company
  • Storage and use of contact details of customers
  • Defense against threats and liability claims and avoidance of legal risks
  • Detection of potentially malicious emails / files
  • Prevention of criminal acts
  • Settlement of insurance claims
  • General internal management purposes

Should we require to obtain consent for the processing of your personal data, Art. 6 para. 1 lit. a GDPR constitutes the legal basis. For more information, please refer to the informed consent provided to you.

3. Data categories

The following personal data is collected and processed by Westfalia-Automotive GmbH:

Personal master data (first and last name, title, position, department, address), contact data (telephone number, mobile number, fax number, e-mail address), bank data, creditworthiness data, legitimation and authentication data (commercial register excerpts, ID data, signatures), order data, correspondence.

4. Data transmission

In order to fulfil the aforementioned purposes, your personal data will be forwarded to the internal departments required for this purpose. This includes, among others, the management and the relevant departments (sales, purchasing, accounting, etc.). Furthermore, we use data processors and other service providers for the aforementioned purposes, who may then also have access to the data. Compliance with data protection requirements is contractually ensured.

Your data may also be transferred to companies within the group for the purpose of fulfilling internal contractual obligations.

In addition, it may be necessary for us to transfer your personal data to the following entities in order to fulfil legal obligations:

  • Judicial and law enforcement authorities, e.g. police, courts, public prosecutor's office
  • Lawyers or notaries, e.g. in legal disputes
  • Certified Public Accountant

A forwarding to so-called third countries (non-EU countries) does not take place, unless there is a corresponding obligation due to judicial or official orders, you have consented to the transfer or it is necessary for the fulfilment of the contract.

In the event that data is transferred to third countries, Westfalia-Automotive GmbH shall ensure that all measures necessary under data protection law for a lawful transfer of data have been taken.

5. Data storage

Your personal data will be stored for a period of 10 years due to the legal retention period according to § 147 AO and § 257 HGB. After expiry of the aforementioned period, your personal data will be deleted or, if this is not possible, marked with a blocking and deletion notice. Irrespective of this, your personal data will be deleted as soon as the purpose for which it was collected has been fulfilled. Also in the case of the enforcement or defense of legal claims, a longer storage period of 3 to 30 years (depending on the claim) may result.

If your personal data has been collected on the basis of consent and you revoke this consent, we will delete your personal data within one week after receipt of the revocation.

6. Automated decision making

No fully automated decision-making (including profiling) pursuant to Art. 22 GDPR is used to process your personal data.

7. Data subject rights

According to Art. 15 GDPR, you have a right of information about the personal data stored about you, about the purposes of processing, about any transfers to other bodies and about the duration of storage.

If data is incorrect or no longer necessary for the purposes for which it was collected, you may request its correction (Art. 16 GDPR), deletion (Art. 17 GDPR) or restriction of processing (Art. 18 GDPR). You may also exercise the right of data portability under Article 20 of the GDPR.

You can revoke your consent at any time, even in part, for the future. For this purpose, please contact us by e-mail to or in writing to Westfalia-Automotive, Am Sandberg 45, D-33378 Rheda-Wiedenbrück.

In justified cases, you may object to processing based on our legitimate interest pursuant to Art. 21 GDPR. Please also use the aforementioned contact information for this purpose.

If you have any questions about your rights and how to exercise them, please contact the data controller or the company data protection officer.

8. Complaints about the processing of your personal data

If you have any concerns or questions about the processing of your personal data, feel free to contact us at


You also have the right to lodge a complaint with a supervisory authority for data protection.


Rheda-Wiedenbrück, November 2022