
Legal
Privacy policy
Updated: 9 September 2026
1. Controllers and contact
This website is operated jointly by BEB Stahlbearbeitung KG, personally liable partner Christian Nadrowski, and BEB Stahlhandel GmbH & Co. KG, represented by its personally liable partner BEB Bau- und Handel GmbH, represented by managing director Christian Nadrowski. Both companies are located at Josef-Baumann-Str. 29a, 44805 Bochum, Germany. Joint contact: +49 234 891130, info@beb-stahl.de.
The companies jointly control the shared website operations. Privacy requests are handled by our data protection officer and reviewed jointly by both companies. You may exercise your rights against either company. Our offering is directed at businesses; this policy also covers personal data of their representatives and our website visitors.
2. Data protection officer
Heimann und Drabas – Jens Heimann
Pallasstr. 80, 44575 Castrop-Rauxel, Germany
Phone: +49 2305 356040
Email: jens.heimann@shd-tax.de
3. Hosting, logs and backups
Our hosting provider is ALL-INKL.COM – Neue Medien Münnich, proprietor René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. Data is processed in Germany to provide and protect the hosting infrastructure under a data processing agreement. See ALL-INKL privacy information.
When you visit the website, technical data is processed to deliver content and ensure secure operation. This includes your full IP address, request date and time, requested page or file, browser and connection information and, where transmitted or recorded, operating system, referring page, response status and amount of data transferred. Access and error logs are automatically deleted after 30 days.
Access logs are also evaluated on the server to create usage statistics and improve our website. No third-party analytics script is loaded in your browser for this purpose. Retention of raw logs is separate from retention of aggregated statistics. The legal basis for operation, security and this evaluation is Article 6(1)(f) GDPR, reflecting our legitimate interests in a reliable, secure and useful business website.
Webspace backups are retained for a maximum of 60 days, then deleted or overwritten. This period does not govern business emails in Microsoft 365.
4. Enquiries and communication
If you contact us by form, email or telephone, we process the information you provide to handle your enquiry and communicate with you. This may include your company, name, email address, telephone number, requested service, project and material details, deadlines and message content. Enquiries are routed to the employees responsible for the selected service. Where the other company handles the enquiry, it receives the information necessary for that purpose.
Article 6(1)(b) GDPR applies where processing is necessary to enter into or perform a contract with you as a natural person. For business representatives and general business enquiries, Article 6(1)(f) GDPR applies based on our legitimate interests in handling enquiries and maintaining business relationships. Statutory retention obligations are fulfilled under Article 6(1)(c) GDPR.
Fields marked as mandatory must be completed to submit the form; other information is voluntary. Alternatively, you may contact us by email or telephone. Enquiry data is deleted when no longer needed for handling the enquiry or follow-up questions, unless statutory obligations or other lawful retention grounds apply. If a business relationship follows, the necessary data continues to be processed for that relationship.
5. Attachments
You may voluntarily upload documents relevant to your enquiry. They are temporarily processed on the web server and sent to the responsible recipients as email attachments. They are not intended for public access. Please avoid unnecessary personal data about third parties. The purposes, legal bases and retention criteria in section 4 apply. Email attachments are also subject to mailbox retention and any mailbox backups.
6. Protection against abusive submissions
The form uses technical checks to limit automated or excessively frequent submissions. A hash derived from the IP address and timing information are used to identify short-term repeat submissions. We do not treat this hash as reliably anonymous. These auxiliary data are automatically deleted after 24 hours. Article 6(1)(f) GDPR applies based on our legitimate interest in protecting the form, our systems and recipients against abuse.
7. Cookies and similar technologies
With your consent, we use Google Ads conversion measurement as described below. No embedded social media feeds are used. Server-side statistics are described in section 3 and external maps in section 8.
Google Ads enquiry measurement
With your consent, Google Ads (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) measures successful form submissions and clicks on telephone and email links to help us assess our advertisements. A telephone or email click does not confirm an actual conversation or sent email. Form success means our mail server accepted the message for sending; it does not confirm delivery to a recipient.
Google tags remain blocked until you consent. Technical browser and device information, IP address, page and advertising click identifiers and conversion events may then be processed by Google. We do not transmit form fields, message contents, contact details or attachments as conversion data. Enhanced conversions and personalised advertising are not enabled by this integration.
Your choice is saved in browser local storage under beb-ads-consent-v1 for up to 180 days. After consent, Google may store advertising attribution cookies, including _gcl_ cookies, configured for up to 90 days. An opaque form receipt is associated with a Secure, HttpOnly, SameSite=Strict cookie named beb_form_receipt under /api/ for up to ten minutes, only after a successful submission with measurement consent. It contains no form contents, is consumed once and helps prevent duplicate counting. Expired server sessions are cleared by PHP session garbage collection.
The basis for optional measurement is your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. You can decline or withdraw consent for the future using “Privacy settings” on every page. Declining does not restrict the form. Withdrawal stops this integration and removes accessible first-party attribution cookies; previous processing is not reversed. Details of Google, possible USA transfers and safeguards are in section 8 and the Google privacy policy.
Storage or access strictly necessary to provide a service expressly requested by you is based on section 25(2)(2) TDDDG without separate consent. Subsequent personal data processing requires the applicable GDPR legal basis. Non-essential storage or access requires consent under section 25(1) TDDDG.
The restricted editorial area uses the beb_redaktion session cookie to associate requests with the authenticated session. It is restricted to /redaktion/ and configured with Secure, HttpOnly and SameSite=Strict. Its purpose is secure access control under Article 6(1)(f) GDPR. It normally expires at the end of the browser session; browser session restoration may affect this.
8. Google Maps
You may activate Google Maps on the locations page. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map is loaded only after consent. Google may receive your IP address, browser and device information and map usage data, use cookies or similar technologies and associate activity with your Google account if signed in.
The legal basis for embedding is Article 6(1)(a) GDPR and, where required, section 25(1) TDDDG. Without consent, the rest of the website and locally provided location information remain available.
Select “Consent and load Google map” to activate a map. Select “Withdraw consent and hide map” beneath that map to withdraw consent for the future and remove the embedded content. Your choice is not stored permanently and applies only to that map during the page visit. Withdrawal does not reverse past transfers or delete data or cookies already stored by Google.
Processing outside the EEA, particularly in the USA, is possible. Google LLC is certified under the EU-US Data Privacy Framework; the adequacy decision under Article 45 GDPR applies to transfers covered by it. Google describes the use of standard contractual clauses under Article 46 GDPR for transfers not covered by an adequacy decision. See Google privacy policy and international transfer safeguards for details, retention and settings.
9. External links, Instagram and LinkedIn
Our social media and external route-planning links are ordinary links, not embedded feeds or plugins. Merely displaying them does not connect to the platforms. Opening a link takes you to the respective provider, whose privacy information applies there. Processing on our social media profiles, including messages and platform statistics, may be covered by separate profile-specific information.
10. Recipients and Microsoft 365
Enquiry data is accessible to persons responsible for handling it. Hosting, email and IT providers may process data to provide the services; processing by processors is contractually governed under Article 28 GDPR. Disclosure to authorities or other recipients requires a legal obligation or another legal basis.
We use Microsoft 365 (Exchange Online) to receive, process and store business emails, including sender and recipient addresses, message content, attachments and technical connection data. Microsoft's EU contact is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The purposes, legal bases and retention criteria in section 4 apply. Website backup retention does not determine email retention.
Microsoft processes data under its contractual data protection terms for business services. Processing outside the EEA, including in the USA, is possible. Microsoft's safeguards include EU standard contractual clauses. See Microsoft privacy information and Microsoft standard contractual clauses.
11. Your rights
Subject to the statutory conditions, you have rights of access, rectification, erasure and restriction of processing. Where processing is automated and based on consent or contract, the right to data portability applies under Article 20 GDPR. You may withdraw consent at any time for the future without affecting the lawfulness of earlier processing. Contact us or use the map controls described in section 8.
Right to object: You may object to processing based on Article 6(1)(f) GDPR for reasons relating to your particular situation. Processing will cease unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or processing is needed for legal claims. You may object to direct marketing at any time without giving reasons.
You may complain to a supervisory authority, particularly where you habitually live or work or where the alleged infringement occurred. In North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany; poststelle@ldi.nrw.de; www.ldi.nrw.de.
The website functions described here do not provide for solely automated decisions producing legal or similarly significant effects under Article 22 GDPR.
12. Updates
We update this policy when our processing, services or relevant legal requirements change. This version describes website hosting at ALL-INKL.