Privacy Policy
Your privacy is important to us. This comprehensive policy explains how we collect, use, and protect your personal data in compliance with GDPR and international data protection regulations.
Last Updated: December 15, 2024
This Privacy Policy describes how AgriGear Direct GmbH ("we," "our," or "us") collects, uses, and protects your personal information when you use our website and services related to agricultural machinery. As a German-based company operating globally, we are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
This policy applies to all users of our website, customers, and anyone who interacts with our agricultural machinery services, regardless of their location. By using our services, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect
1.1 Personal Information
We collect the following types of personal information to provide our agricultural machinery services:
- Identity Information: Full name, title, and professional credentials
- Contact Information: Email address, phone number, fax number, and postal address
- Business Information: Company name, business registration number, VAT number, industry sector, and company size
- Equipment Requirements: Specific machinery needs, brand preferences, technical specifications, and budget constraints
- Communication Records: Email correspondence, phone call logs, chat transcripts, and support ticket history
- Financial Information: Payment method details, billing address, credit card information (processed securely), and financing preferences
- Logistics Information: Shipping address, delivery preferences, customs requirements, and import/export documentation
- Technical Preferences: Equipment specifications, maintenance history, and operational requirements
1.2 Technical Information
We automatically collect technical information when you visit our website or use our services:
- Device Information: IP address, device type, operating system, browser type and version, screen resolution, and language settings
- Usage Analytics: Pages visited, time spent on pages, click patterns, search queries, and navigation paths
- Performance Data: Page load times, error logs, and system performance metrics
- Location Data: Country and region information (derived from IP address) for service optimization
- Cookies and Tracking: Session cookies, persistent cookies, and similar technologies for functionality and analytics
- Security Information: Login attempts, security events, and fraud prevention data
- Mobile App Data: App usage statistics, crash reports, and device-specific information (if applicable)
2. How We Use Your Information
We use your personal information for the following purposes, always in accordance with applicable data protection laws:
- Service Provision: Process equipment requests, provide personalized quotes, and coordinate machinery sales and delivery
- Customer Support: Respond to inquiries, provide technical assistance, and resolve issues related to agricultural machinery
- Logistics Management: Coordinate international shipping, customs clearance, and delivery services worldwide
- Financial Services: Process payments, handle financing applications, and manage billing and invoicing
- Quality Assurance: Conduct equipment inspections, quality assessments, and warranty management
- Communication: Send order confirmations, shipping updates, and important service notifications
- Marketing and Analytics: Send relevant product updates, industry news, and promotional offers (with your consent)
- Legal Compliance: Fulfill regulatory requirements, maintain business records, and respond to legal requests
- Security and Fraud Prevention: Protect against fraud, abuse, and security threats
- Business Improvement: Analyze usage patterns to improve our services and develop new features
3. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances, always ensuring appropriate safeguards are in place:
- With Your Consent: When you explicitly authorize us to share your information with specific third parties
- Legal Requirements: To comply with applicable laws, regulations, court orders, or government requests
- Safety and Security: To protect our rights, property, safety, or the safety of others
- Service Providers: With trusted partners who assist in providing our services:
- Shipping and logistics companies for equipment delivery
- Financial institutions for payment processing and financing
- Technical support providers for website and system maintenance
- Marketing partners for promotional activities (with consent)
- Legal and compliance advisors for regulatory matters
- Business Transfers: In connection with mergers, acquisitions, or sale of business assets
- Emergency Situations: When necessary to prevent harm or address urgent safety concerns
All third-party service providers are contractually obligated to protect your information and use it only for specified purposes.
4. Data Security
We implement comprehensive technical and organizational measures to protect your personal information in accordance with industry best practices and regulatory requirements:
- Data Encryption: All sensitive data is encrypted using industry-standard protocols (AES-256) both in transit (TLS/SSL) and at rest
- Access Controls: Multi-factor authentication, role-based access controls, and regular access reviews for all systems
- Network Security: Firewalls, intrusion detection systems, and regular security monitoring
- Physical Security: Secure data centers, access controls, and environmental protections
- Employee Training: Regular data protection training, security awareness programs, and confidentiality agreements
- Incident Response: Comprehensive incident response plan, breach notification procedures, and recovery protocols
- Regular Audits: Internal and external security assessments, penetration testing, and compliance audits
- Data Minimization: Collecting only necessary data and implementing retention policies
- Vendor Management: Security assessments of third-party providers and contractual data protection requirements
- Business Continuity: Backup systems, disaster recovery plans, and data recovery procedures
Despite our best efforts, no method of transmission over the internet or electronic storage is 100% secure. We continuously monitor and improve our security measures to protect your information.
5. Your Rights and Choices
Under GDPR and other applicable data protection laws, you have the following rights regarding your personal information:
- Right of Access: Request a copy of your personal data and information about how we process it
- Right of Rectification: Request correction of inaccurate or incomplete personal data
- Right of Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of how we process your data
- Right to Data Portability: Request your data in a structured, machine-readable format
- Right to Object: Object to processing of your data for specific purposes
- Right to Withdraw Consent: Withdraw consent for data processing at any time
- Right to Lodge a Complaint: File a complaint with relevant data protection authorities
- Right to Opt-Out: Unsubscribe from marketing communications and promotional emails
- Right to Information: Be informed about data breaches affecting your personal information
To exercise these rights, please contact us using the information provided in the "Contact Us" section. We will respond to your request within 30 days, as required by law.
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your browsing experience and provide personalized services:
- Essential Cookies: Required for basic website functionality, security, and user authentication
- Analytics Cookies: Help us understand how visitors use our website and improve our services
- Functional Cookies: Remember your preferences, language settings, and customized features
- Marketing Cookies: Enable personalized content and targeted advertising (with consent)
- Performance Cookies: Monitor website performance and identify technical issues
- Social Media Cookies: Enable sharing content on social media platforms
You can control cookie settings through your browser preferences. However, disabling certain cookies may affect website functionality. For detailed information about our cookie policy, please visit our Cookie Policy.
7. International Data Transfers
As a global agricultural machinery company operating worldwide, we may transfer your personal information to countries outside your residence. We ensure appropriate safeguards are in place to protect your data in accordance with applicable laws and regulations:
- EU Standard Contractual Clauses: For transfers to non-EU countries without adequate data protection
- Adequacy Decisions: For transfers to countries with recognized adequate data protection standards
- Binding Corporate Rules: Internal policies ensuring consistent data protection across our organization
- Certification Schemes: Industry-recognized data protection certifications
- Derogations: Specific exceptions for limited transfers under strict conditions
We maintain detailed records of all international data transfers and regularly review our transfer mechanisms to ensure continued compliance with evolving regulations.
8. Children's Privacy
Our agricultural machinery services are designed for business customers and are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16.
If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately. We will take steps to verify the child's age and, if confirmed, will promptly delete any such information from our records.
We encourage parents and guardians to supervise their children's online activities and to teach them about safe internet practices.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes through the following methods:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending email notifications to registered users for significant changes
- Displaying prominent notices on our website for major updates
- Updating our mobile applications and other service platforms
Your continued use of our services after such changes constitutes acceptance of the updated policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
10. Data Retention and Deletion
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements:
- Active Customer Data: Retained for the duration of our business relationship plus 7 years for legal compliance
- Financial Records: Retained for 10 years as required by German tax and accounting laws
- Marketing Data: Retained until consent is withdrawn or 3 years from last interaction
- Technical Logs: Retained for 12 months for security and troubleshooting purposes
- Website Analytics: Retained for 26 months in accordance with Google Analytics policies
- Support Communications: Retained for 5 years for quality assurance and legal protection
When data is no longer needed, we securely delete or anonymize it. You may request early deletion of your data, subject to legal requirements.
11. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to fulfill our contractual obligations to you
- Legitimate Interest: Processing for our legitimate business interests, balanced against your rights
- Consent: Processing based on your explicit consent for specific purposes
- Legal Obligation: Processing required by applicable laws and regulations
- Vital Interest: Processing necessary to protect vital interests in emergency situations
We conduct regular assessments to ensure our processing activities remain lawful and necessary.
12. Automated Decision Making and Profiling
We may use automated processing to improve our services, but we do not make decisions that significantly affect you based solely on automated processing:
- Recommendation Systems: Suggest relevant equipment based on your preferences and requirements
- Fraud Detection: Automated systems to detect and prevent fraudulent activities
- Customer Segmentation: Analyze patterns to provide personalized services
- Quality Assessment: Automated quality checks for equipment listings and descriptions
You have the right to request human review of any automated decisions that affect you.
13. Third-Party Services and Integrations
Our website and services may integrate with third-party services that have their own privacy policies:
- Payment Processors: Stripe, PayPal, and other payment gateways for secure transactions
- Analytics Services: Google Analytics for website usage analysis
- Email Services: Mailchimp and similar services for marketing communications
- Cloud Storage: AWS, Google Cloud for secure data storage
- Customer Support: Zendesk and similar platforms for customer service
- Social Media: Facebook, LinkedIn, and other social platforms for marketing
We carefully select third-party providers and ensure they meet our data protection standards through contractual agreements.
14. Data Breach Procedures
In the event of a data breach that affects your personal information, we have established procedures to:
- Immediate Response: Contain and assess the breach within 24 hours
- Notification: Notify affected individuals within 72 hours of becoming aware
- Regulatory Reporting: Report to relevant data protection authorities as required
- Investigation: Conduct thorough investigation to determine cause and scope
- Remediation: Implement measures to prevent future breaches
- Documentation: Maintain detailed records of all breach-related activities
We will provide clear information about the breach, potential risks, and steps you can take to protect yourself.
15. Agricultural Industry Specific Considerations
As an agricultural machinery company, we handle specific types of data related to farming operations:
- Equipment Specifications: Detailed technical data about machinery requirements and capabilities
- Operational Data: Information about farming operations, crop types, and land size
- Financial Information: Equipment financing, leasing terms, and payment schedules
- Logistics Data: Shipping routes, customs requirements, and delivery specifications
- Technical Support: Maintenance records, warranty information, and service history
- Regulatory Compliance: Import/export documentation and agricultural regulations
We ensure that all agricultural-specific data is handled with the same level of protection as other personal information.
16. Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your data protection rights, please contact us:
Data Protection Officer: privacy@agrigeardirect.com
General Inquiries: info@agrigeardirect.com
Phone: +49 40 5729 0308
Fax: +49 40 5729 0309
Address: AgriGear Direct GmbH, Kleine Reichenstrasse 1, 20457 Hamburg, Germany
Business Hours: Monday - Friday, 8:00 AM - 6:00 PM CET
For complaints about our data processing practices, you may also contact the relevant data protection authority in your jurisdiction. In Germany, this is typically the state data protection authority in your federal state.