Skip to content
Carimex – Experts in Tendering Business
  • About Us
  • Services & Products
  • Contact
Language
  • ENG
  • |
  • DE

Information On Data Protection

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Carimex Handel mit Kraftfahrzeugteilen GmbH & Co. KG
Robert-Bosch-Straße 42
46397 Bocholt
Telefon: +49 2861-93070
E-Mail: info@carimex.net

You can contact us at any time using the details above with any questions about data protection.

2. Overview

Personal data is any data with which you can be personally identified. This notice explains which data is processed when you visit this website, for what purpose and on what legal basis.

This website sets no cookies, stores nothing in your browser, embeds no third-party services and opens no connection to third-party servers when you load it. No third-party analytics or tracking services are used. Personal data is processed only in the cases described below: when pages are requested (server log files), by our own cookieless reach measurement where it is enabled (section 4), and when you write to us using the contact form.

3. Hosting and server log files

This website is maintained by our web agency, A/L Werbekonzept GbR, Alte Furt 28, 46499 Hamminkeln, Germany, and hosted on servers of IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. Both process the resulting data on our behalf.

With every request to this website — including when the contact form is sent — the web server automatically records in log files:

  • the IP address of the requesting device
  • the date and time of the request
  • the requested address (URL) and the request method
  • the HTTP status code and the volume of data transferred
  • the previously visited page (referrer), where your browser sends it
  • the browser identification (user agent), which shows browser, version and operating system

This data is technically necessary in order to deliver the website, to ensure its stability and security, and to investigate attacks or misuse. The legal basis is our legitimate interest in operating the website securely and reliably (Art. 6 (1) (f) GDPR). The data is not combined with other data sources. The server administration software also produces monthly access statistics from the log files (AWStats), which include a list of the requesting IP addresses. These statistics are password-protected and kept for the current and the three preceding months.

The access and error logs are rotated by size rather than after a fixed period: older files are deleted automatically once ten archived files per log have been reached. How long an entry is kept therefore depends on the volume of traffic; in logs that are written to rarely, such as the error log, entries can currently be kept for more than a year. The server's security logs (web application firewall and automatic blocking of attacks), which can also contain IP addresses, are instead deleted on fixed schedules after around eight weeks at the latest.

4. Reach measurement (only where enabled)

Our own data-minimising reach measurement is available for this website. Our web agency, A/L Werbekonzept GbR, operates it on our behalf on its server at IONOS SE. It is not a third-party service such as Google Analytics or the Meta Pixel; there is no advertising tracking, no cross-site tracking and no profiling. The following applies only where reach measurement is enabled for this website. As long as it is not enabled, no measurement script is loaded, your browser sends no requests to the analytics server and no processing for analytics purposes takes place. If it is disabled, the analytics server stops accepting reports immediately; the measurement script is removed with the next update of the website.

Where it is enabled, your browser sends a short report to the analytics server whenever a page is opened. The following is processed from it:

  • the page opened (path without parameters or anchors) and the time it was opened
  • the previously visited page, if you came from another website (stored without parameters)
  • campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term), if the address contains any
  • device type, operating system and browser as broad categories, derived from the browser identification (user agent); the browser identification itself is not stored
  • your preferred language, from the language setting your browser sends with every request (the language code only, e.g. “de”)
  • country, region and, where available, town, roughly derived from the IP address — using a database on the server itself, without passing the IP address to third parties

Reach measurement sets no cookies, stores no information on your device and uses no persistent identifier; the measurement script does not actively access additional device characteristics such as screen or window size or comparable properties, and no fingerprinting takes place. To be able to count visits, the server combines the IP address and browser identification with a random value generated anew each day to form a pseudonymous visitor value (hash) — pseudonymous, not anonymous data. The random value applies to one calendar day only and is deleted automatically once it is more than two days old (normally on the third following day); after that the visitor value can no longer be recreated, and a visit on another day is not recognised as the same visitor. Page views less than 30 minutes apart are grouped by the server into one visit with a random session identifier, which is not sent to your browser.

Reach measurement does not store your IP address. It is used only briefly in working memory: for the coarse location, for the pseudonymous visitor value and to limit the number of reports per sender within ten minutes. Like any web request, however, the report to the analytics server is recorded with the IP address in that web server's log files; the purposes and deletion rules described under “Hosting and server log files” apply.

Individual page views are stored for 90 days and then deleted automatically. After that only daily totals, with no link to individual visits, are kept for 760 days (around 25 months). The data is held in our web agency's database on the IONOS SE server; backup copies of this database are additionally stored on a separately rented, access-restricted backup server from the provider Hostinger and deleted after around three months at the latest.

The legal basis is our legitimate interest in evaluating the use of our website in a data-minimising way and improving what we offer (Art. 6 (1) (f) GDPR). You may object to the processing at any time on grounds relating to your particular situation (Art. 21 GDPR); an informal message to the contact details above is enough.

5. Contact form

If you send us an enquiry using the contact form, we process the details you enter:

  • required: last name, first name and e-mail address
  • optional: postcode, town, company or business, telephone number and your message
  • your consent, which is recorded together with the enquiry

Your entries are transmitted over an encrypted connection to our web agency's form server, which runs on the same IONOS SE server, and delivered from there by e-mail to our mailbox info@carimex.net. Dispatch runs through the mail server of IONOS SE. Your e-mail address is set as the reply address so that we can answer you directly. The e-mail contains your details, the language of the form and the time it was sent, but not your IP address.

Where the enquiry inbox is enabled for this website, the form server additionally stores a copy of your enquiry in our web agency's database once the e-mail has been sent, so that it does not exist only in an e-mail mailbox. If reach measurement is also enabled, the landing page, the referring website and any campaign parameters of your current visit are attached to the enquiry. No IP address is stored with it. This copy is deleted automatically two years after it was received; backup copies of the database (Hostinger) after around three months at the latest. Where the enquiry inbox is not enabled, your enquiry is delivered by e-mail only and not stored in a database.

The legal basis is the consent you give explicitly in the form (Art. 6 (1) (a) GDPR) and, where your enquiry relates to a contract or pre-contractual measures, Art. 6 (1) (b) GDPR. We need the required details in order to deal with and answer your enquiry; without them the form cannot be sent.

We keep your enquiry until you ask us to delete it, withdraw your consent or the purpose of storage no longer applies (e.g. once your enquiry has been dealt with). Mandatory statutory provisions — in particular retention periods — remain unaffected.

6. Contact form spam protection

To protect the form against automated submissions we do not use a third-party CAPTCHA service. The following checks run in your browser and on the form server instead:

  • an additional field that is invisible to you and that only automated scripts fill in
  • a check on whether the form was completed in a time that is plausible for a person
  • a short computation your browser solves in the background
  • a limit on the number of submissions per IP address within a given time window

For the last check your IP address is processed briefly in the server's working memory; only submissions from the last ten minutes are counted, and none of it is stored permanently. If a submission is rejected because of the hidden field or the computation, the IP address is noted together with the reason for rejection in the form server's application log so that misuse can be investigated; this log is rotated weekly and deleted after around five weeks at the latest. Accepted enquiries are noted there without an IP address. The legal basis is our legitimate interest in a working, abuse-free contact route (Art. 6 (1) (f) GDPR). No cookies are set and no data is transmitted to third parties.

7. Cookies and browser storage

This website sets no cookies and uses no comparable technologies such as localStorage or sessionStorage — neither to operate the site nor for the language selection or the spam protection. Reach measurement (section 4) does not store anything on your device either. No cookies are set, reach measurement stores no information on your device, and no cookie banner is currently used.

8. Fonts

This website exclusively uses fonts stored on this website's own server. When you open a page, no connections to third-party servers — such as Google Fonts — are established.

9. Links to social networks

The references to our Instagram and LinkedIn profiles are plain links. No data is transmitted to these networks when you load this website; only when you click a link are you taken to the provider's page, whose data processing is that provider's responsibility.

10. SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, such as the enquiries you send to us, this site uses TLS encryption. You can recognise an encrypted connection by “https://” and the lock symbol in your browser's address bar. Please note that data transmission over the Internet, for example by e-mail, may have security gaps.

11. Recipients of your data

Your data is received only by us and, for technical reasons, by our web agency A/L Werbekonzept GbR and our hosting and e-mail provider IONOS SE, which act on our behalf. Where reach measurement or the enquiry inbox is enabled, the data stored there also ends up in backup copies on the backup server of the provider Hostinger (sections 4 and 5). No transfer to a third country outside the EU is intended. Your data is not passed on for advertising purposes.

12. Your rights

Within the framework of the statutory provisions, you have the right at any time

  • to obtain information about the personal data we hold about you, its origin, its recipients and the purpose of processing (Art. 15 GDPR),
  • to have inaccurate data rectified (Art. 16 GDPR),
  • to have your data erased (Art. 17 GDPR),
  • to have processing restricted (Art. 18 GDPR),
  • to data portability for data you have provided to us on the basis of your consent or a contract (Art. 20 GDPR),
  • to object, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 6 (1) (f) GDPR) (Art. 21 GDPR),
  • to withdraw consent you have given, with effect for the future (Art. 7 (3) GDPR); the lawfulness of processing carried out before the withdrawal remains unaffected.

An informal message to the contact details above, e.g. by e-mail, is sufficient.

13. Right to lodge a complaint with a supervisory authority

If you believe that the processing of your data infringes data protection law, you may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

14. Objection to advertising e-mails

The use of contact data published as part of the imprint obligation to send unsolicited advertising and information materials is hereby prohibited. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, for example through spam e-mails.

Carimex

Contact

Carimex GmbH & Co. KG

Robert-Bosch-Straße 42
46397 Bocholt
Germany

+49 2861-93070

info@carimex.net

Business hours

Mon – Thu: 9:00 a.m. – 5:00 p.m.
Fri: 9:00 a.m. – 2:00 p.m.

Legal

  • Imprint
  • Privacy Policy
  • Terms and Conditions
  • Terms of Purchase

Follow us on

Copyright © 2026, Carimex GmbH & Co. KG — All Rights Reserved

Language
  • ENG
  • |
  • DE
Back to top