Privacy Policy

Wilh. Werhahn KG takes the protection of personal data very seriously. This privacy policy explains the processing of personal data when using the Compliance Helpline. 

The data controller for the processing of personal data is:
Wilh. Werhahn KG
Königstr. 1
41460 Neuss
Germany
Tel.: +49 2131 916-0
E-mail: info@werhahn.de
Website: www.werhahn.de

You can contact our data protection officer at:
Wilh. Werhahn KG
Data Protection Officer
Königstr. 1
41460 Neuss
Germany
Tel.: +49 2131 916-0
E-mail: datenschutz@werhahn.de
Website: www.werhahn.de

Processing of personal data when you use the Compliance Helpline
The use of the Compliance Helpline is fundamentally completely anonymous, so it can be used without providing any personal data. However, you can provide personal data voluntarily during the process, e.g. information on your identity, first and last name, country of residence, telephone number or e-mail address. 

The Compliance Helpline website guarantees anonymous use by means of an encrypted connection. When you use the helpline, neither your IP address nor your current location are collected. Only in the context of your language selection is the chosen language stored by a so-called session cookie. No other data (especially browser data) is processed. It is therefore not possible to identify users of the Compliance Helpline via usage data.

After sending a message, you will receive an access link and a unique password to access the Compliance Helpline mailbox so that you can continue protected communication after your initial message.

Wilh. Werhahn KG operates the Compliance Helpline for itself and the other companies of the Werhahn Group. Reports via the Compliance Helpline are not processed by Wilh. Werhahn KG, but are sent to the external ombudsperson, Prof. Dr. Eva Kohler, Ruhrtal 5, 58456 Witten/Germany. The ombudsperson makes an initial assessment of the report and decides whether information should be sent to representatives of the company concerned. If this is the case, she sends the personal data required for the information about the message to the respective designated company representatives. Your personal data is not transmitted to us or the company concerned if you specify this accordingly in the context of your entry. 

Purpose and legal basis of the processing
The personal data collected in connection with the Compliance Helpline is processed in order to follow up on indications of violations which require reporting and, if applicable, to clarify any suspicion of indications which are either deliberately untruthful or as a result of gross negligence. The legal basis for data processing is provided by Article 6 (1) c) and f) GDPR and the German Act on Corporate Due Diligence to Prevent Human Rights Violations in Supply Chains (LkSG) and the German Whistleblower Protection Act (HinSchG). The companies of the Werhahn Group are required to set up internal reporting offices and to protect whistleblowers. They also have a legitimate interest in ensuring compliance with laws and guidelines by employees of the Werhahn Group.

If a message relates to an incident that does not constitute a violation in need of reporting, but requires attention by other departments or specialist areas within the Werhahn Group, the personal data stored in connection with the message may be passed on to the responsible departments or specialist areas in the respective company of the Werhahn Group after consultation with the person who made the report and with his or her consent. The legal basis for this processing is provided by Article 6 (1) sentence 1 a) and f) GDPR.

Disclosure of the personal data
Depending on the circumstances of the individual case, the personal data collected in connection with the Compliance Helpline is passed on to the following recipients:
  • Executive staff and compliance officers of the companies of the Werhahn Group as well as departments and specialist areas, insofar as they are permitted to be involved in compliance investigations within the scope of their duties. A list of the Werhahn Group companies that come into consideration is included in the list of shareholdings in the respective annual report of Wilh. Werhahn KG, which is published on the homepage of Wilh. Werhahn KG.   A number of these companies are located in countries outside the European Union (EU) and the European Economic Area (EEA). For these countries, there is a list, which you can obtain from the compliance officers responsible for your company, which indicates whether they have an adequate level of data protection according to the findings of the European Commission (Art. 45 GDPR) or which suitable or appropriate data protection guarantees the Werhahn Group has implemented in order to make the lawful transfer of data to these companies possible. If data protection guarantees are implemented, these can also be obtained from the compliance officers responsible for your company.
  • Law enforcement agencies and other authorities, as well as courts, if they order and demand the exceptions to confidentiality.

Length of storage
If personal data is collected or processed in connection with a report to the Compliance Helpline, it is only to be retained for as long as and insofar as it is required for tasks of the Compliance Helpline in processing the report. After that, especially when the procedure has been completed, it is to be deleted immediately. The data is also deleted if an internal investigation is not carried out.

Your rights
Every data subject has the right of access in accordance with Article 15 of the GDPR, the right to rectification in accordance with Article 16 of the GDPR, the right to erasure in accordance with Article 17 of the GDPR, the right to restriction of processing in accordance with Article 18 of the GDPR and the right to data portability in accordance with Article 20 of the GDPR.

Where personal data is processed for the performance of tasks in the public interest (Article 6 (1) e) GDPR) or for the purposes of legitimate interests (Article 6 (1) f) of the GDPR), you may object to the processing of your personal data at any time with effect for the future (right of objection (Article 21 of the GDPR)).

If you wish to exercise any of the above rights, please contact us at the above address. 

In addition, there is a right of appeal to a competent data protection supervisory authority (Article 77 GDPR).