Privacy notice

Thank you for visiting our website and for your interest in Vattenfall's companies. We take the protection of your data very seriously and want you to feel safe and comfortable when visiting our website.

In the following, we would like to inform you about which personal data we collect when you visit our website, how we process this data and what rights you have in connection with your personal data.

Responsible for data processing on the website
Data security
Reporting of security vulnerabilities through "responsible disclosure"
Website functionalities
To which categories of recipients will my data be transmitted?
What do I have to consider when using links on our website?
What rights do I have in relation to my data?
Provision of personal data
Automated decision-making / profiling
Updates to the data protection information

Responsible for data processing on the website

Vattenfall Energy Trading GmbH
Dammtorstraße 29-32
20354 Hamburg
Email: impressum@vattenfall.de

Contact details of the data protection officer:

You can reach the data protection officer responsible for Vattenfall Energy Trading GmbH within datenschutz@vattenfall.de. She will be happy to answer any questions you may have about data protection.

Data security

In order to protect your data as comprehensively as possible from unwanted access, manipulation or loss, we take technical and organizational measures that correspond to the current state of the art. We use an encryption method on our websites. Your data will be transmitted from your computer to our server and vice versa via the Internet using TLS encryption. You can usually recognize this by the fact that the lock symbol in the status bar of your browser is closed and the address line begins with https://.

Reporting of security vulnerabilities through "responsible disclosure"

Vattenfall attaches great importance to the security of its information and communication systems. In principle, security vulnerabilities cannot be 100% ruled out. Exploitation or abuse of these vulnerabilities is illegal.

In order to prevent identified vulnerabilities from being exploited by attackers, the German Federal Office for Information Security (BSI) also recommends the application of the "Responsible Disclosure" principle. The application of this principle guarantees a coordinated and trust-based collaboration between the discoverer of the vulnerability and the affected manufacturer or service provider.

Inform and report a security vulnerability

Website functionalities

As a rule, you can visit the pages of Vattenfall Energy Trading GmbH without us needing any personal data from you. We collect and process your data only if we have either received your consent to the data processing or the processing is permitted by our legitimate interest.

Technically necessary usage data and log files

If you visit our website for purely informational purposes, i.e. do not transmit any data (e.g. via a contact form), we will collect the data that your browser transmits to us. Specifically, these are the following data:

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • Amount of data transferred in each case
  • Website from which you visit us (referrer URL)
  • Website you are visiting
  • Browser type and version used
  • Operating system and its interface
  • Language and version of the browser software

Purpose of processing: The collection and processing of this data is carried out in order to be able to display the website to you, to ensure and improve stability, as well as for security reasons. The setting of technically necessary log files is absolutely necessary for operation.

Legal basis: This processing is based on our legitimate interest (Art. 6 para. 1 lit. f) GDPR).

Storage period: The data will be deleted as soon as they are no longer required for the aforementioned purposes. If an IP address is stored, it will be deleted or anonymized after 30 days at the latest.

Use of cookies and other technologies

In addition, cookies and other technologies are used when using our website. Cookies are small text files that are stored on your computer by us or by another body (more detailed information can be found in the description of our analysis procedures below) and through which certain information flows to the body setting the cookie. Cookies are always assigned to the browser. By using cookies, it is not possible to run programs or transmit viruses to your PC.

You can configure your browser settings according to your wishes and, for example, refuse to accept third-party cookies or all cookies. You are also free to delete all cookies at any time via the settings of your browser.

This subdomain only uses necessary cookies. For other cookies on the main domain, this privacy notice is not applicable.

Use of necessary cookies

We use cookies to offer you the following functions and services, what is needed for the use and availability of our website.

CloudFlare

The cookie is set by CloudFlare (CDN) and speeds up page loading times and overrides any security restrictions that may be applied to a browser based on the IP address from which it comes.

Legal basis: The data processing is based on § 25 para. 2 TTDSG in conjunction with Art. 6 para. 1 f) GDPR. Our legitimate interest in the processing of cookies arises from the mentioned purpose.

Place of processing: USA, European Union

Data recipient: Cloudflare Group

Cookies:

Cookie name purpose of processing storage time
_cfuvid The cookie is used to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application and does not store any personally identifiable information. 1 month

Optimizely (Episerver)

For identification and storage of the form submissions.

Legal basis: The data processing is based on § 25 para. 2 TTDSG in conjunction with Art. 6 para. 1 f) GDPR. Our legitimate interest in the processing of cookies from the mentioned purpose.

Place of processing: European Union

Data recipients: Optimizely

Cookies:

Cookie name purpose of processing storage time
.EPiForm_BID Identifies the form submission made to the site when a visitor submits data via an Optimizely form. Stores a GUID as the browser ID. 90 days
.EPiForm_VisitorIdentifier Identifies the form submission to the site when a visitor submits data to via an Optimizely form. Stores a GUID which is the visitor identifier. 90 days
EPiForm_{FormGuid}: {Username} Stores partial form submissions so that a visitor can continue with a form submission upon return. One cookie is created for each form and each logged in visitor. Stores the current submission status of the form (formGuid, submissionID, and if submission is finalized or not). 90 days

Microsoft

Identify and detects on an anonymous way the sessions and the requests and user activity on the site.

Legal basis: The data processing is based on § 25 para. 2 TTDSG in conjunction with Art. 6 para. 1 f) GDPR. Our legitimate interest in the processing of cookies from the mentioned purpose.

Place of processing: USA, European Union

Recipients: Microsoft

Cookies:

Cookie name purpose of processing storage time
ASP.NET_SessionId Required to identify requests from the same browser during a limited session time window when browsing the website. General purpose platform session cookie, used by sites written with Microsoft .NET based technologies. Usually used to maintain an anonymised user session by the server. Session out
ai_session Detects how many sessions of user activity have included certain pages and features of the app. 30 minutes
ai_user Detects how many people used the site and its features. Users are counted using anonymous IDs. 1 year

Contact possibility via phone or e-mail

You have the option of contacting Vattenfall Energy Trading GmbH by telephone or e-mail as part of its services. If you contact us by phone or e-mail, we will use the data you provide to us (e.g. e-mail address, telephone number, name) in accordance with the purpose for which you contacted us.

Legal basis: We have a legitimate interest (Art. 6 para. 1 lit. f GDPR) in your data in order to be able to answer your request. In addition, Art. 6 (1) (b) GDPR can also be considered as a legal basis if your request serves to carry out pre-contractual measures.

Recipients: We only process your data internally and do not disclose your personal data to third parties or other recipients.

Storage period: Your data will only be processed to answer your request. We delete your data if it is no longer required and does not conflict with statutory retention obligations.

Third-country transfer: There is no third-country transfer.

Contact forms on the website

You also have the option of contacting Vattenfall Energy Trading GmbH via a contact form in relation to the respective service. As part of the use of the respective contact form, the personal data visible from the form itself (usually surname, first name and e-mail address) are collected and processed for the purpose of answering your request.

Legal basis: We have a legitimate interest (Art. 6 para. 1 lit. f GDPR) in your data in order to be able to answer your request. In addition, Art. 6 (1) (b) GDPR can also be considered as a legal basis if your request serves to carry out pre-contractual measures.

Recipients: We only process your data internally within Vattenfall Energy Trading GmbH and do not disclose your personal data to recipients / third parties.
Storage period: Your data will only be processed to answer your request. We delete your data if it is no longer required and does not conflict with statutory retention obligations.

Third-country transfer: There is no third-country transfer.

To which categories of recipients will my data be transmitted?

We treat your data confidentially. Within Vattenfall Energy Trading GmbH, only those departments and employees who need it to fulfil the above-mentioned purposes have access to your data.

Personal data will only be transmitted by us to third parties if this is necessary for the aforementioned purposes and permitted by law or if you have given your prior consent.

What do I have to consider when using links on our website?

The website of Vattenfall Energy Trading GmbH sometimes contains links to websites of third-party providers or affiliated Vattenfall companies. If you use these links, you leave this website and thus also the scope of this privacy policy. Vattenfall Energy Trading GmbH is not responsible for compliance with the legal requirements by these other operators. The responsibility for those is exclusively with the respective website operator.

What rights do I have in relation to my data?

With regard to the processing of your personal data, you have the right of access pursuant to Art. 15 GDPR, the right to rectification pursuant to Art. 16 GDPR, the right to erasure pursuant to Art. 17 GDPR, the right to restriction of processing pursuant to Art. 18 GDPR, the right to notification pursuant to Art. 19 GDPR and the right to data portability pursuant to Art. 20 GDPR.

If you have any questions regarding the processing of your personal data, you can contact our data protection officer directly at datenschutz@vattenfall.de.

Revoke of consent

If the processing of data is based on your consent, you are entitled to revoke your consent to the processing of your personal data at any time in accordance with Art. 7 (3) GDPR. Please note that the revocation is only effective for the future. Processing that took place before the revocation is not affected by this.

Right to object regarding to Art. 21 GDPR

If we process your data on the basis of legitimate interests (Art. 6 para. 1 lit. f) GDPR) and if your particular situation gives rise to reasons against this processing, you have the right to object to this processing in accordance with Art. 21 para. 1 GDPR. In the event of an objection, we will no longer process your data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

You can send your objection informally to info@perspektive-brunsbuettel.de at any time.

Right to lodge a complaint

In addition, there is a right of appeal to a competent data protection supervisory authority in accordance with Art. 77 GDPR. The data protection supervisory authority responsible for Vattenfall Energy Trading GmbH can be reached at:

The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 2
20459 Hamburg

Provision of personal data

With the exception of the technically necessary data for the display of our website, any data provision by you is voluntary. If, in exceptional cases, this should be different, this is explicitly mentioned at the appropriate point in this declaration.

Automated decision-making / profiling

There is no automated decision-making, including profiling.

Updates to the data protection information

As our data processing is subject to change, we will also adapt our data protection information from time to time. The current status of these data protection regulations can be found here.