Legal

Privacy policy

How personal data is handled when you use this website and when you send us a service request.

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Schirmer GmbH
Unter den Eichen 15
57635 Weyerbusch
Germany
Represented by Eduard Schirmer
E-mail: info@gymservice.lu
Telephone: +49 (1556) 3166425

No data protection officer has been appointed. For any question about data protection, please use the contact details given above.

2. Server log files

When you access this website, the hosting provider automatically collects and stores information in so-called server log files, which your browser transmits automatically. This typically includes the browser type and version, the operating system used, the referrer URL, the host name of the accessing device, the time of the server request and the IP address.

This data is not merged with other data sources. Processing is based on Art. 6 (1) (f) GDPR: the operator has a legitimate interest in the technically error-free presentation and the security of the website.

This website runs on a virtual server operated by DigitalOcean, LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA. The server is located in the Frankfurt am Main data centre in Germany, where the data is processed. A processing agreement under Art. 28 GDPR is in place — the provider's agreement forms part of its terms of service. Where data does reach the United States, the provider relies on its certification under the EU-U.S. Data Privacy Framework and, as a fallback, on Standard Contractual Clauses.

In front of the server sits Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare speeds up delivery of the pages and fends off attacks; as a result every request to this website passes through Cloudflare's servers, including your IP address. A processing agreement under Art. 28 GDPR is likewise in place, and Cloudflare is also certified under the EU-U.S. Data Privacy Framework. The legal basis is Art. 6(1)(f) GDPR, the legitimate interest being the secure and uninterrupted operation of the site.

Server log files are deleted after two months.

3. Contact form and e-mail contact

If you send us a service request via the contact form or by e-mail, the details you provide — including name, company, e-mail address, telephone number, location, equipment data, your description of the problem and any files you attach — will be stored for the purpose of processing the enquiry and in case of follow-up questions.

The legal basis is Art. 6 (1) (b) GDPR where the request relates to the initiation or performance of a contract, and otherwise Art. 6 (1) (f) GDPR, based on our legitimate interest in answering enquiries addressed to us. Providing the data is voluntary; without the details marked as required we cannot process the request.

The enquiry is sent by a script on our own server into a Telegram chat that only we read; no third-party form service is involved. Telegram is operated by Telegram FZ-LLC, Dubai, United Arab Emirates — so the message leaves the EU. That transfer to a third country is necessary in order to deal with your enquiry within the meaning of Art. 49(1)(b) GDPR. If you would rather avoid it, simply call us or send an e-mail.

A few technical details travel with the message, which your browser sends anyway or which are read on the page: IP address, the country derived from it, operating system and browser, screen size, time zone and language, and the page the form was sent from. They serve one purpose only — telling a fake enquiry from a real one (Art. 6(1)(f) GDPR) — are not stored, and exist only inside the message itself.

4. Cookies and local storage

This website does not use tracking cookies, advertising cookies or web analytics. No third-party scripts are loaded and no fonts are fetched from external servers.

The website may store your chosen language locally in your browser (localStorage) so that it does not have to ask again on your next visit. This information stays on your device, is not transmitted to us and can be deleted at any time via your browser settings. See the cookie policy for details.

5. Recipients of the data

Personal data is received only by the providers named in section 2 (DigitalOcean and Cloudflare) and by Telegram if you write to us through the form (section 3). No other third party receives it, in particular not for advertising purposes, and data is never sold. Beyond that we disclose data only where the law obliges us to.

6. Storage period

Personal data is stored for as long as it is required for the purposes described above. Statutory retention obligations — in particular under commercial and tax law — remain unaffected and may require longer storage of business correspondence.

Specifically: server log files are deleted after two months. Enquiries that do not lead to an order are removed from the Telegram chat and from the inbox after two months. If an enquiry does lead to a contract, the business correspondence is subject to the retention periods laid down in commercial and tax law.

7. Your rights

Under the GDPR you have the following rights in relation to your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing based on legitimate interests (Art. 21 GDPR)
  • Right to withdraw consent at any time, with effect for the future (Art. 7 (3) GDPR)

To exercise these rights, please contact us using the details in section 1. You also have the right to lodge a complaint with a supervisory authority.

The competent supervisory authority for the controller is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz, Deutschland
Telefon: +49 6131 8920-0 · E-Mail: poststelle@datenschutz.rlp.de
www.datenschutz.rlp.de

8. SSL/TLS encryption

This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognise an encrypted connection by the "https://" in the address bar of your browser. When encryption is active, the data you transmit to us cannot be read by third parties.

9. Changes to this privacy policy

We will adapt this privacy policy whenever changes to the website or to the applicable legal situation make it necessary. The current version always applies.

Service request

How would you like to reach us?

Tell us the manufacturer, the model and what the machine is doing — a photo of the type plate and a short video of the fault are the fastest route to a useful answer.

Call now+49 (1556) 3166425Write an e-mailinfo@gymservice.luFill in the service formEverything we need, in one step
Ask us to call you back Leave a name and a number

Service throughout the Grand Duchy of Luxembourg — commercial and private customers.