Privacy Policy
Our Privacy Statement
The Sumitomo Riko group companies in Europe are responsible for data processing in connection with Sumitomo Riko products, services and websites in Europe.
This Privacy Policy explains the types of information that we may collect and hold, how that information is used and with whom the data is shared. It also sets out how you can contact us if you have any queries or concerns about this information. Some of our services also have their own privacy policy which provide details of the use of your information by that service.
We encourage you to read this Privacy Policy carefully. If you do not wish your personal data to be used by us as set out in this Privacy Policy, please do not provide us with your personal data. Please note that in such a case, we may not be able to provide you with our services, you may not have access to and/or be able to use some features of the Website, and your customer experience may be impacted.
Article 1 Definition
The terms used in this Privacy Policy shall be defined as follows:
Applicable Privacy Laws and Regulations means applicable privacy laws and regulations, including the General Data Protection Regulation (“GDPR”) of EU and the relevant national implementation acts.
Personal Data means any information relating to an identified or identifiable natural person that is Processed by Sumitomo Riko, as specified in Article 3 of this Privacy Policy.
Privacy Policy means this privacy policy.
Process (Processed or Processing) means any single operation or a series of operations which is performed on Personal Data or on a set of Personal Data, whether or not by automated means (including collection, recording, editing, structuring, storage, adaptation and/or alternation, retrieval, reference, use, disclosure by transmission, dissemination or otherwise making available, alignment and/or combination, restriction, erasure and/or destruction of data).
Controller means the natural or legal person, governmental authority or body, or others which, alone or jointly with others, determine the purpose and means of Processing Personal Data. For the purposes of this Privacy Policy, the Controller includes each of the companies listed in the Annex. Relevant responsibility regarding the concrete data processing lies with such Sumitomo Riko group company in Europe which is holder of the contract or of the contract to be concluded within the meaning of Article 4 (2). In all other cases the Controller is such European Sumitomo Riko group company which determines the purpose and means of the processing of personal data.
Website means each group company´s website URL.
Sumitomo Riko means the Sumitomo Riko group company in Europe , listed in the Annex.
Article 2 Scope of Privacy Policy
This Privacy Policy applies to the Processing of Personal Data, to which the Privacy Laws and Regulations are applicable. Sumitomo Riko is the designated Controller for this Processing, according the definition regarding “Controller” (Article 1 above).
Article 3 Personal Data to be Collected
- Sumitomo Riko may collect the following Personal Data from its customers, suppliers, other business partners, job applicants, its employees, and its affiliates’ employees and users of the Website:
Contact information: such as your name, company or organization, department, job title, address, phone, email and other similar information.
Technical details of your visit to the Website: such as your IP address, cookie and operating system, browser type (for visits to our Website), details of the device you are using (e.g. your device serial number, unique identification number, MAC address) and technical and event based data in relation to your usage of your device (e.g. internet and Bluetooth pairing and connectivity data and session duration.
Any other information you submit to Sumitomo Riko: such as opinions and any other information you provide.
- Sumitomo Riko does not collect any sensitive Persona Data, such as health data, except as set forth in the Applicable Privacy Laws and Regulations.
Article 4 Legal Ground of Data Processing
Sumitomo Riko may Process your Personal Data for the purposes detailed below, which are required so that Sumitomo Riko can pursue our legitimate interests and provide you with adequate products and services:
(1) Where you have given consent.
(2) To perform contracts to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract.
(3) Where necessary for Sumitomo Riko’s legitimate interests, as listed below, and where our interests are not overridden by your data protection rights.
to offer you our products and services;
to ensure business continuity;
to manage our employees and services related to their employment relationship;
to provide, improve, and develop our products, services, and advertising;
to inform you about our policies and terms;
to promote safety and security;
to use personal data for purposes such as business administration, data analysis, research, and audits;
to ensure that content from the Website is presented in the most effective manner for you;
to notify you about changes to our products or services;
to manage your account;
and
to comply with our legal obligations, to enforce our legal rights or to protect rights of third parties.
(4) Where necessary to comply with a legal obligation.
(5) Where necessary to protect Sumitomo Riko’s legitimate interests and legal rights, and where our interests and not overridden by your data protection rights.
(6) Protecting our legitimate business interests and legal rights. This includes, but is not limited to, use in connection with compliance, regulatory, auditing, legal claims (including disclosure of such information in connection with legal process or litigation) and other ethics and compliance reporting requirements.
Article 5 Purposes of Processing the Personal Data
- Sumitomo Riko may Process the Personal Data for the purposes detailed below:
to conclude or fulfill contracts with our suppliers, customers or other business partners;
to offer you our products and services;
to ensure business continuity;
to manage our employees and services related to their employment relationship;
to provide, improve, and develop our products, services, and advertising;
to inform you about our policies and terms;
to promote safety and security;
to use personal information for purposes such as business administration, data analysis, research, and audits;
to ensure that content from the Website is presented in the most effective manner for you; and
to notify you about changes to our products or services;
- Sumitomo Riko may also Process the Personal Data for the following purposes:
to honor our obligations with employees, contractors, vendors and other natural persons providing Sumitomo Riko with their services;
to comply with our legal and regulatory obligations and requests anywhere in the world, including reporting to and/or being audited by national and international regulatory bodies;
for administrative purposes of job applications;
for fraud and crime prevention and detection purposes;
for administrative purposes in relation to the security of and access to our systems, premises, platforms and websites and applications;
to comply with court orders and exercise and/or defend our legal rights;
to protect rights of third parties;
for any other legitimate business purpose; and
as otherwise permitted or required by any applicable law or regulation.
- Sumitomo Riko Processes the Persona Data in accordance with the Applicable Privacy Laws and Regulations, as specified in this Privacy Policy.
- If Sumitomo Riko intends to further Process the Personal Data for purposes other than the Processing purpose at the time of collection of the Personal Data, it shall provide information about such other purposes and all relevant additional information before such further Processing.
Article 6 Transmission of Personal Data to Third Parties
Sumitomo Riko may transfer Personal Data to entities, including Sumitomo Riko group companies, in countries or jurisdictions outside the EEA, such as Japan. Please note that such countries or jurisdictions may not have the same data protection laws as the EEA and may not afford many of the rights conferred upon data subjects in the EEA. When Sumitomo Riko transfers your Personal Data outside the EEA, it will ensure that your Personal Data is protected and transferred in a manner consistent with legal requirements applicable to such Personal Data. You may obtain more details regarding the protection given to your Personal Data by contacting Sumitomo Riko when your Personal Data is transferred outside the EEA.
Article 7 Security
- Sumitomo Riko implements appropriate organizational and/or technical security measures to protect the Personal Data and to prevent misuse, loss or alteration thereof. Furthermore, Sumitomo Riko limits access to the Personal Data to its employees, agents, contractors and other third parties who need access to such Personal Data. Those aforementioned persons are bound by an obligation to maintain confidentiality, either in accordance with their employment agreements or (data processing) agreements.
- In the event that Sumitomo Riko entrusts the handling of your Personal Information, it will obligate such entrusted person to take appropriate security control according to contract and it will exercise necessary and appropriate supervision over such entrusted person.
Article 8 Retention Periods
- Sumitomo Riko does not store the Personal Data beyond the extent that is necessary for the purpose for which such Personal Data is collected.
- Data subject of the Personal Data may request Sumitomo Riko to delete their Personal Data at any time. Furthermore, when the Personal Data is no longer necessary or required for the purposes of collecting or Processing, Sumitomo Riko deletes such Personal Data.
Article 9 Cookies
- Sumitomo Riko uses cookies to ensure that the Website functions properly.
- Cookies are information stored by the browser on the computers of User of Website. Sumitomo Riko uses different types of cookies for different purposes.
- Functional cookies: cookies necessary for the Website to function properly, including cookies necessary for creating an account;
- Analytical cookies: cookies used to obtain information on how the Website (or a part of the Website) is used by a User of Website. With such information, Sumitomo Riko can improve the Website so that the Website can fit as much as possible with what the User of Website finds interesting and important. Sumitomo Riko only uses the data obtained with these cookies to analyze how the Website is being used.
- Sumitomo Riko only uses third parties’ cookies for the purpose of improving the quality and effectiveness of the Website, e.g. Google Analytics which is used by some of the Sumitomo Riko companies.
- Cookies are enabled as a default setting on most browsers. The User of Website can set the browser to disable cookies or indicate when a cookie is being sent. However, if cookies are disabled, it is possible that some functions or services of Sumitomo Riko or other websites may not function properly.
Article 9 A Data protection provisions about the application and use of Google Analytics (with anonymization function)
On the website, the controller has integrated the component of Google Analytics (with the anonymizer function). Google Analytics is a web analytics service. Web analytics is the collection, gathering, and analysis of data about the behavior of visitors to websites. A web analysis service collects, inter alia, data about the website from which a person has come (the so-called referrer), which sub-pages were visited, or how often and for what duration a sub-page was viewed. Web analytics are mainly used for the optimization of a website and in order to carry out a cost-benefit analysis of Internet advertising.
The operator of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States.
For the web analytics through Google Analytics the controller uses the application “_gat. _anonymizeIp”. By means of this application the IP address of the Internet connection of the data subject is abridged by Google and anonymized when accessing our websites from a Member State of the European Union or another Contracting State to the Agreement on the European Economic Area.
The purpose of the Google Analytics component is to analyze the traffic on our website. Google uses the collected data and information, inter alia, to evaluate the use of our website and to provide online reports, which show the activities on our websites, and to provide other services concerning the use of our Internet site for us.
Google Analytics places a cookie on the information technology system of the data subject. The definition of cookies is explained above. With the setting of the cookie, Google is enabled to analyze the use of our website. With each call-up to one of the individual pages of this Internet site, which is operated by the controller and into which a Google Analytics component was integrated, the Internet browser on the information technology system of the data subject will automatically submit data through the Google Analytics component for the purpose of online advertising and the settlement of commissions to Google. During the course of this technical procedure, the enterprise Google gains knowledge of personal information, such as the IP address of the data subject, which serves Google, inter alia, to understand the origin of visitors and clicks, and subsequently create commission settlements.
The cookie is used to store personal information, such as the access time, the location from which the access was made, and the frequency of visits of our website by the data subject. With each visit to our Internet site, such personal data, including the IP address of the Internet access used by the data subject, will be transmitted to Google in the United States of America. These personal data are stored by Google in the United States of America. Google may pass these personal data collected through the technical procedure to third parties.
The data subject may, as stated above, prevent the setting of cookies through our website at any time by means of a corresponding adjustment of the web browser used and thus permanently deny the setting of cookies. Such an adjustment to the Internet browser used would also prevent Google Analytics from setting a cookie on the information technology system of the data subject. In addition, cookies already in use by Google Analytics may be deleted at any time via a web browser or other software programs.
In addition, the data subject has the possibility of objecting to a collection of data that are generated by Google Analytics, which is related to the use of this website, as well as the processing of this data by Google and the chance to preclude any such. For this purpose, the data subject must download a browser add-on under the link https://tools.google.com/dlpage/gaoptout and install it. This browser add-on tells Google Analytics through a JavaScript, that any data and information about the visits of Internet pages may not be transmitted to Google Analytics. The installation of the browser add-ons is considered an objection by Google. If the information technology system of the data subject is later deleted, formatted, or newly installed, then the data subject must reinstall the browser add-ons to disable Google Analytics. If the browser add-on was uninstalled by the data subject or any other person who is attributable to their sphere of competence, or is disabled, it is possible to execute the reinstallation or reactivation of the browser add-ons.
Further information and the applicable data protection provisions of Google may be retrieved under https://www.google.com/intl/en/policies/privacy/ and under http://www.google.com/analytics/terms/us.html. Google Analytics is further explained under the following Link https://www.google.com/analytics/.
Article 9 B Contact possibilities via the website and Compliance Helpline
The website of Sumitomo Riko (please see annex, without Poland and Italy) contains information that enables a quick electronic contact to our enterprise, as well as direct communication with us, which also includes a general address of the so-called electronic mail (e-mail address). If a data subject contacts the controller by e-mail or via contact forms, the personal data transmitted by the data subject are automatically stored. Such personal data transmitted on a voluntary basis by a data subject to the data controller are stored for the purpose of processing or contacting the data subject. There is no transfer of this personal data to third parties.
Direct contact to Sumitomo Riko (please see annex, without Poland and Italy) or use of the compliance helpline (data protection in case of contacting the external lawyer is given).
Compliance Helpline contact possibilities:
- Direct contact to compliance committee of SumiRiko AVS Germany GmbH via contact form.
- Contact to external lawyer via contact form. Data protection in case of contacting the external lawyer is also given.
Article 9 C Data protection for applications and the application procedures
Only reg. SumiRiko AVS Germany GmbH:
The data controller shall collect and process via company Concludis GmbH, Frankfurter Straße 561, 51145 Köln, the personal data of applicants for the purpose of the processing of the application procedure. The processing may also be carried out electronically. This is the case, in particular, if an applicant submits corresponding application documents by e-mail or by means of a web form on the website to Concludis. If the data controller concludes an employment contract with an applicant, the submitted data will be stored for the purpose of processing the employment relationship in compliance with legal requirements. If no employment contract is concluded with the applicant by the controller, the application documents shall be automatically erased six months after notification of the refusal decision, provided that no other legitimate interests of the controller are opposed to the erasure. Other legitimate interest in this relation is, e.g. a burden of proof in a procedure under the General Equal Treatment Act (AGG).
Article 10 Data breaches
In case of breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed, we have the mechanisms and policies in place in order to identify it and assess it promptly. Depending on the outcome of our assessment, Sumitomo Riko will make the requisite notifications to the supervisory authorities and communications to the affected data subjects, which might include you.
Article 11 Rights of Data Subject
- As long as the Processing of the Personal Data is based on consent, the data subject of the Personal Data has the right to withdraw consent in respect of their Personal Data at any time.
- The data subject of the Personal Data has the right to request access to their Personal Data. This allows the data subject to receive a copy of their Personal Data retained by Sumitomo Riko.
- The data subject of the Personal Data has the right to request correction of their Personal Data retained by Sumitomo Riko. This allows the data subject of the Personal Data to have any incomplete or inaccurate data concerning themselves, which are retained by Sumitomo Riko, corrected.
- The data subject of the Personal Data has the right to request deletion of their Personal Data. This allows Sumitomo Riko to delete the Personal Data that Sumitomo Riko has been Processing without legitimate reasons.
- The data subject of the Personal Data has the right to raise objections to the Processing of their Personal Data which Sumitomo Riko conducts for its legitimate interests. If Sumitomo Riko has been Processing the Personal Data for the purposes of direct marketing, Sumitomo Riko shall accept the objections from the data subject of the Personal Data at all times. If Sumitomo Riko has been Processing the Personal Data for other purposes, Sumitomo Riko shall cease the Processing of the Personal Data, unless it has compelling legitimate reasons (i) which override the interests or rights and freedom of the data subject of the Personal Data, or (ii) which are related to the commencement or implementation of legal action or for the proof of claims purposes.
- The data subject of the Personal Data has the right to request restriction on the Processing of their Personal Data.
- The data subject of the Personal Data has the right to request a transmission of their Personal Data to themselves or to a third party. Sumitomo Riko shall provide a data subject of the Personal Data or a third party designated by such user with the Personal Data of the said data subject in a structured, commonly used, machine-readable format. Please be advised that this right only applies to automatically Processed information for which the data subject of the Personal Data initially provided consent or which Sumitomo Riko used to perform an Agreement with a data subject of the Personal Data.
- The exercise of the aforementioned rights is free of charge. Sumitomo Riko will provide information about the follow-up to the request from the data subject of the Personal Data immediately and in any case within one (1) month of receipt of such request. This period may be extended by another two (2) months, depending on the complexity of the request and the number of requests. Sumitomo Riko will notify a data subject of the Personal Data of such an extension within one (1) month of receipt of the request.
- If a request from a data subject of the Personal Data is clearly ungrounded or excessive, in particular if the same request is made repeatedly, Sumitomo Riko will either charge such data subject of the Personal Data a reasonable fee or refuse to respond to the request from such user.
- In addition to the aforementioned rights, a data subject of the Personal Data has the right to file a complaint to a supervisory authority (in particular, a supervisory authority in the EU Member State where the data subject of the Personal Data habitually resides, or at the place of work or where an alleged infringement of the GDPR occurred) at any time. However, Sumitomo Riko would appreciate an opportunity to deal with concerns of the data subject of the Personal Data, before they contact the supervisory authority. Your initial contact to resolve the issue would be highly appreciated.
Article 12 Contact
For any inquiries or complains, or if you wish to exercise any of the rights specified in Article 9 of this Privacy Policy, please contact Sumitomo Riko, i.e. the relevant DPO supporter of each company, shown in the Annex (primary contact) and the DPO at dpo(at)eu.sumitomoriko.com (secondary contact).
Article 13 External links
The Websites may contain information of third parties (for example, hyperlinks or banners). Sumitomo Riko does not control such third parties’ information and is not responsible for compliance with the Applicable Privacy Laws and Regulations on behalf of these third parties. We ask the User of Website to carefully read the privacy policies of the third party websites they are visiting.
Article 14 Miscellaneous
- Sumitomo Riko reserves the right to revise this Privacy Policy on a regular basis. It is the responsibility of the data subject of the Personal Data to regularly review the applicable provisions. This Privacy Policy was last revised in [October] 2018.
- If a provision of this Privacy Policy is in conflict with the laws or regulations, it shall be replaced by a provision of the same purport that reflect the original intention of the provision, to the extent legally permissible. In this case, the remaining provisions shall remain applicable and unchanged.
Annex: Sumitomo Riko group company in Europe
SumiRiko AVS Holding Germany GmbH
Karl-Winnacker-Str. 19
36396 Steinau an der Straße
Germany
Tel.: +49 6663 91280
DPO: Joshua.Rahimi(at)avs.sumiriko.com
SumiRiko AVS Germany GmbH
Karl-Winnacker-Straße 19
36396 Steinau an der Straße
Germany
Tel.: +49 6663 91280
DPO: Joshua.Rahimi(at)avs.sumiriko.com
SumiRiko AVS Netherlands B.V.
Celsiusweg 32
5928PR Venlo
The Netherlands
Tel.: +49 6663 91280
DPO: Joshua.Rahimi(at)avs.sumiriko.com
SumiRiko AVS Spain S.A.U.
Poligono Industrial, Las Casas, Calle F
42005 Soria
Spain
Tel.: +34 975 010150
DPO supporter: Georgina.Tomas(at)avs.sumiriko.com
SumiRiko Rubber Compounding France S.A.S.
Usine des Caillots
F-58302 Decize Cedex
France
Tel.: +33 3 86 77 32 32
DPO supporter: Aline.Pautrat(at)avs.sumiriko.com
SumiRiko SD France S.A.S.
Usine des Caillots
58302 Decize Cedex
France
Tel.: +33 3 86 77 32 32
DPO supporter: Aline.Pautrat(at)avs.sumiriko.com
SumiRiko AVS Romania S.R.L.
Parc Industrial Sud 11
440247 Satu Mare
Romania
Tel.: +40 261 706 748
DPO supporter: Florin.Popovici(at)avs.sumiriko.com
SumiRiko AVS Czech s.r.o.
Drnovice 146
763 25 Ujezd
Czech Republic
Tel.: +42 157 7311411
DPO supporter: Jaromir.Uher(at)avs.sumiriko.com
SumiRiko Poland Sp. z o. o.
ul. 1 Maja 100
32-340 Wolbrom
Poland
Tel.: +48 32 647 2500
DPO supporter: Aneta.Pokorska(at)sumiriko.pl
SumiRiko Poland Sp. z o. o.
ul. Składowa 2
38-540 Zagórz
Poland
Tel.: +48 13 426 48 00
DPO supporter: Aneta.Pokorska(at)sumiriko.pl
SumiRiko Italy S.p.A.
Corso Unione Sovietica 612/15C
10135 Torino
Italy
Tel.: +39 011 3233411
DPO supporter: Giuliana.Ribet(at)it.sumiriko.com
SumiRiko Italy S.p.A.
Via F.lli Meliga, 20/C
Frazione Mosche
10034 Chivasso
Italy
Tel.: +39 0119158111
DPO supporter: Giuliana.Ribet(at)it.sumiriko.com
SumiRiko Italy S.p.A.
Via E. Giani 2
Località La Botte
58020 Scarlino
Italy
Tel.: +39 056675111
DPO supporter: Giuliana.Ribet(at)it.sumiriko.com
SumiRiko Automotive Hose Poland Sp. z o.o.
Gabriela Narutowicza 61
41-200 Sosnowiec
Poland
Tel.: +48 32 784 70 00
DPO supporter: Krystian.Zielinski(at)hp.sumiriko.com
Sumitomo Riko Europe GmbH
Hanauer Landstraße 187-189
60314 Frankfurt am Main
Germany
Tel.: +49 69 94947980
DPO: Joshua.Rahimi(at)avs.sumiriko.com