Select branch and language

Select language

Personal AI assistant

Do you have any questions? Start a conversation.

Internal sales

For all sales-related matters:

Tel: +49 7940 123 8309

Send an enquiry

Service helpline

For all after-sales matters:

Tel: +49 7940 123 450

Contact the helpline

Privacy Policy Asset-Lifecycle-Management-Platform

As of: August 2026

Preamble

Data protection is a top priority for GEMÜ Gebr. Müller Apparatebau GmbH & Co. KG. The careful handling of your personal information is important to us. For this reason, your data will be treated confidentially by us in strict compliance with the applicable data protection regulations.

In the following, we explain to you which data we use at what time and for what purpose when you use our Asset-Lifecycle-Management-Platform (comprised of Portal and App). Our aim is to help you understand how our Asset-Lifecycle-Management-Platform works and what measures we take to ensure the protection of your personal data, which is important to us. We only use your personal data if we have your consent or legal permission.

In our Asset-Lifecycle-Management-Platform, we process the data that we need for the functioning of the software. In addition, we optionally collect data for the diagnosis of our software. We also use your data when you communicate with us for the purpose of contacting us.

If you have any questions about data protection, please feel free to contact us at any time, for example by e-mail at[email protected] or by telephone on+49 7940 123-0.

Table of Contents

A. General Information

I. Identity and contact details of the data controller

II. Contact details of the data protection officer

III. General information on data processing

IV. Rights of the data subject

B. General

I. Contact via Email

II. Registration

C. Regarding the Portal

I. Provision of the Portal and creation of log files

II. Usage of Cookies

D. Regarding the App

E. Identification Link Generator

F. Hosting

G. Amendment of the Privacy Policy

A. General Information

I. Identity and contact details of the data controller

The data controller responsible in accordance with the purposes of the General Data Protection Regulation (GDPR) of the European Union and other data protection regulations is:

GEMÜ Gebr. Müller Apparatebau GmbH & Co. KG (short: GEMÜ)

Gert-Müller-Platz 1

74635 Kupferzell

Germany

Website:www.gemu-group.com

II. Contact details of the data protection officer

The designated data protection officer of the data controller can be reached at[email protected].

III. General information on data processing

1. Scope of processing personal data

In general, we only process the personal data of our users to the extent necessary to provide a functioning Asset-Lifecycle-Management-Platform with our content and services. The regular processing of personal data only takes place with the consent of the user. Exceptions include cases where prior consent cannot be technically obtained and where the processing of the data is permitted by law.

2. Legal basis for data processing

Where consent is appropriate for processing personal data, Art. 6 (1a) GDPR serves as the legal basis to obtain the consent of the data subject for the processing of their data.

As for the processing of personal data required for the performance of a contract of which the data subject is a party, Art. 6 (1b) GDPR serves as the legal basis. This also applies to processing operations required to carry out pre-contractual activities.

When it is necessary to process personal data to fulfil a legal obligation to which our company is subject, Art. 6 (1c) GDPR serves as the legal basis.

If vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1d) GDPR serves as the legal basis.

If the processing of data is necessary to safeguard the legitimate interests of our company or that of a third party, and the fundamental rights and freedoms of the data subject do not outweigh the interest of the former, Art. 6 (1f) GDPR will serve as the legal basis for the processing of data.

3. Data removal and storage duration

The personal data of the data subject will be erased or restricted as soon as the purpose of its storage has been accomplished. Additional storage may occur if this is provided for by the European or national legislator within the EU regulations, law, or other relevant regulations to which the data controller is subject. Restriction or erasure of the data also takes place when the storage period stipulated by the aforementioned standards expires, unless there is a need to prolong the storage of the data for the purpose of concluding or fulfilling a respective contract.

IV. Rights of the data subject

When your personal data is processed, you are a data subject within the meaning of the GDPR and have the following rights:

1. Right of access (Art. 15 GDPR)

You may request the data controller to confirm whether your personal data is processed by them.

If such processing occurs, you can request the following information from the data controller:

  • Purposes of processing
  • Categories of personal data being processed
  • Recipients or categories of recipients to whom the personal data have been or will be disclosed
  • Planned storage period or the criteria for determining this period
  • The existence of the rights of rectification, erasure, restriction or opposition
  • The existence of the right to lodge a complaint with a supervisory authority
  • If applicable, origin of the data (if collected from a third party)
  • If applicable, existence of automated decision-making including profiling with meaningful information about the logic involved, the scope and the effects to be expected
  • If applicable, transfer of personal data to a third country or an international organization

2. Right to rectification (Art. 16 GDPR)

If your personal data is incorrect or incomplete, you have the right to request that it is corrected or supplemented without delay.

3. Right to the restriction of processing (Art. 18 GDPR)

You may request the restriction of the processing of your personal data under the following conditions:

  • If you challenge the accuracy of your personal data for a period that enables the data controller to verify the accuracy of your personal data;
  • The processing is unlawful, and you oppose the erasure of the personal data and instead request the restriction of their use;
  • The data controller or its representative no longer need the personal data for the purpose of processing, but you need it to assert, exercise or defend legal claims; or
  • If you have objected to the processing and it is not yet certain whether the legitimate interests of the data controller override your interests.

4. Right to erasure ("Right to be forgotten") (Art. 17 GDPR)

If one of the following reasons applies, you have the right to request the deletion of your personal data without undue delay:

  • Personal data concerning you is no longer necessary for the purposes for which they were collected or processed.
  • You withdraw your consent on which the processing is based and where there is no other legal basis for processing the data.
  • You object to the processing of the data and there are no longer overriding legitimate grounds for processing, or you object pursuant to Art. 21 (2) GDPR.
  • Your personal data has been processed unlawfully.
  • The personal data must be deleted to comply with a legal obligation in Union law or Member State law to which we are subject.
  • Your personal data was collected in relation to information society services offered pursuant to Art. 8 (1) GDPR.

The right to deletion does not exist if the processing is necessary:

  • to exercise the right to freedom of speech and information;
  • to fulfil a legal obligation required by the law of the Union or Member States to which we are subject, or to perform a task of public interest or in the exercise of public authority delegated to the representative;
  • for reasons of public interest in the field of public health;
  • for archival purposes of public interest, scientific or historical research purposes or for statistical purposes;
  • to enforce, exercise or defend legal claims.

5. Right to data portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, common and machine-readable format or to request that it is transferred to another controller.

6. Right to object to certain forms of data processing (Art. 21 GDPR)

For reasons that arise from your particular situation, you have, at any time, the right to object to the processing of your personal data pursuant to Art. 6 (1e) or 6 (1f) GDPR; this also applies to profiling based on these provisions.

If the personal data relating to you are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data in regard to such advertising; this also applies to profiling associated with direct marketing.

7. Right to complain to a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the supervisory authority (State Commissioner for Data Protection and Information Security Baden-Württemberg, PO Box 10 29 32, 70025 Stuttgart, Germany, Tel.: +49 711/ 615541-0, email: [email protected]) if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority to which the complaint has been lodged shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Art. 78 GDPR.

B. General

I. Contact via Email

1. Description and scope of data processing

On our website, on the Asset-Lifecycle-Management-Platform and in the App, it is possible to contact us via the email address provided. In this case the personal data of the user transmitted with the email will be stored. This includes the following data:

  • Email address
  • Communication content (text/attachments)
  • Communication metadata (time, subject, sender/recipient)

The data will be used exclusively for the processing of the conversation. The recipients of the data are the relevant internal departments and, where applicable, email/IT service providers acting as our processors. The data will not be transferred to third countries.

2. Purpose of data processing

If you contact us via email, this also constitutes the necessary legitimate interest in the processing of the data. The processing is carried out for the purpose of handling and responding to the enquiry and, if necessary, for follow-up communication.

3. Legal basis for data processing

The legal basis for the processing of data transmitted when sending an email is Art. 6 (1f) GDPR. Our legitimate interest lies in responding to your enquiry, which you send by email, in the best possible and most efficient manner.

If the purpose of the email contact is to conclude a contract, the additional legal basis for the processing is Art. 6 (1b) GDPR.

4. Duration of storage

The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected and there are no legal retention periods preventing deletion. For personal data sent by email, this is the case when the respective conversation with the user has ended. The conversation ends when it can be concluded from the circumstances that the matter in question has been conclusively resolved.

5. Objection and removal

If the user contacts us by email, he can object to the storage of his personal data at any time. In such a case, the conversation cannot be continued.

The objection to storage is made available via the email address [email protected].

In this case, all personal data stored while establishing contact will be deleted.

II. Registration

1. Description and scope of data processing

A user account is required to use the Portal. This is created by the administrator of the Portal and then saved in the Portal. The data will not be passed on to third parties. The following data is collected as part of the registration process:

  • Username
  • Email address
  • Cryptographic hash of the password
  • Salutation (gender), optional
  • Telephone / mobile phone number (optional)
  • Language (optional, otherwise the language set in the browser is used)
  • User permissions (roles)

As part of the registration process, the user's consent to the processing of this data is obtained.

The data is provided automatically when the platform is accessed; without processing this data, the Asset-Lifecycle-Management-Platform may not be able to be provided securely.

The recipients of the data are the relevant specialist department, our IT department and administrators, as well as, where applicable, hosting and IT service providers acting as our data processors. The data is not transferred to a third country.

2. Purpose of data processing

Registration of the user is necessary for the fulfilment of a contract with the user or for the implementation of pre-contractual measures.

3. Legal basis for data processing

If the registration serves the fulfilment of a contract to which the user is a party or the execution of pre-contractual measures, the additional legal basis for the processing of the data is Art. 6 (1b) GDPR.

4. Duration of storage

The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected.

This is the case for the data collected during the registration process for the fulfilment of a contract or for the execution of pre-contractual measures if the data is no longer required for the implementation of the contract. Even after the conclusion of the contract, it may be necessary to store personal data of the contractual partner to comply with contractual or legal obligations.

5. Objection and removal

As a user you have the possibility to cancel the registration at any time. You can request a change to the data stored about you at any time.

If the data is necessary for the fulfilment of a contract or for the implementation of pre-contractual measures, a premature deletion of the data is only possible insofar as contractual or legal obligations do not stand in the way of a deletion.

C. Regarding the Portal

I. Provision of the Portal and creation of log files

1. Description and scope of data processing

Each time the Portal is accessed, our system automatically collects data and information from the computer system of the calling device.

The following data is collected:

  • Date and time of access
  • Page accessed/URL
  • Status code
  • Browser type/version, operating system, language settings
  • In the event of errors: error messages/technical diagnostic data, amount of data transferred, and, where applicable, referrer URL

This data is stored in the log files of our system. Not affected by this are the IP addresses of the user or other data that allow the data to be assigned to a user.

In the event of an error, details of the error that occurred are logged in the existing log file.

This data is not stored alongside any other personal data of the user. This data is not merged with other data sources.

The data is provided automatically when the Portal is accessed; without processing this data, the Portal may not be able to be provided securely.

The recipients of the data are our IT department and administrators, as well as, where applicable, hosting and IT service providers acting as our data processors. The data is not transferred to third countries.

2. Purpose of data processing

The storage in log files is done to ensure the functionality of the Portal. The data is also used to optimize the Portal and to ensure the technical stability, error analysis, prevention of misuse and safeguard the IT security of our information technology systems. An analysis of the data for marketing purposes does not take place.

These purposes, i.e. secure and trouble-free operation and the prevention/analysis of attacks and errors, also constitute our legitimate interest in data processing in accordance with Art. 6 (1f) GDPR.

3. Legal basis for data processing

The legal basis for the temporary storage of data is Art. 6 (1f) GDPR.

4. Duration of storage

The data will be deleted as soon as it is no longer required for the purpose of its collection. In the case of data storage in log files, this is the case after fifteen (15) days.

II. Usage of Cookies

1. Description and scope of data processing

Our Portal uses cookies. Cookies are text files that are stored in the internet browser or by the internet browser on the user's computer system. When a user calls up the Portal, a cookie may be stored on the user's operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the Portal is called up again.

We use cookies to make our Portal more user-friendly. Some elements of our website require that the calling browser can be identified even after a page change.

The following data is stored and transmitted in the cookies:

  • Session information – JSESSIONID and Portal-timeout-Cookie

The user data collected in this way is pseudonymized by technical precautions. Therefore, it is no longer possible to assign the data to the calling user. The data is not stored together with other personal data of the users.

2. Purpose of data processing

The purpose of using technically necessary cookies is to simplify the use of the Portal for users. Some functions of our software cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after a page change.

We require cookies for the following applications:

  • Log-in information

The user data collected through technically necessary cookies are not used to create user profiles.

3. Legal basis for data processing

The provisions of the Federal Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (TDDDG) apply to the storage of information on the end-user's device and/or access to information already stored on the end-user's device. Where the setting and reading of cookies is technically necessary, this is done to ensure the functionality of our Portal. In this case, the storage of and access to cookies on your end device is carried out on the basis of Section 25 (2)(2) of the TDDDG. This storage and access to the information on your end device serve to facilitate your use of our Portal and to enable us to offer you our services as you have requested. Some functions of our Portal also do not work without the use of these cookies and could therefore not be provided. The cookies are generally deleted at the end of the session (e.g. when you log out or close your browser) or after a specified period has elapsed. Information on different retention periods for cookies can be found in the preceding sections of this Privacy Policy.

4. Duration of storage, objection and removal

Cookies are stored on the user's computer and transmitted from it to our site. Therefore, you as a user have full control over the use of cookies. By changing the settings in your internet browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are deactivated for our Portal, it may no longer be possible to use all the functions of the Portal to their full extent.

D. Regarding the App

1. Scope of the processing of personal data when using the App

When using our App the following personal data is collected:

  • IP address,
  • Username (if available),
  • Date and time of access

When you use our App to carry out cloud synchronisation, the App connects to the relevant Portal and downloads the corresponding product data. In the process, log files are created on our servers, which contain the following data records:

  • Date and time of access
  • Relevant communication data (e.g. username)

The data is provided automatically when the App is launched; without processing this data, the App may not be able to function securely.

The recipients of the data are the relevant specialist department, our IT department and administrators, as well as, where applicable, hosting and IT service providers acting as our data processors. The data is not transferred to a third country.

The legal basis for this is Article 6 (1b) GDPR, i.e. the initiation or implementation of contractual relationships (in this case our user agreement).

2. Installation of the App

The App is installed via the technical operators iTunes or the Google Play Store under their conditions. Insofar as the App installation takes place via iTunes, for example, this is Apple Inc., 1 Infinite Loop, Cupertino, California, USA 95014. The loading of the App is carried out by each user through the Apple ID they have created themselves. For this, each user has already had to agree to Apple's terms and conditions. Details of the "Apple Privacy Policy" can be found at https://www.apple.com/de/privacy/. Google Play, on the other hand, makes its notices and privacy policy available at https://www.google.de/policies/privacy/. The processing of personal data in connection with app stores is the sole responsibility of the respective providers.

3. App optimization

The App optionally collects and transmits data to ensure the quality of the App and to optimize the user experience. In the process, data on the device and its use (stack traces in the event of problems in the App) are collected by the App and transferred to a server of one of our IT service providers. These servers are generally located in an ISO 27001 certified data centre in Germany.

Data processing for App optimization is only activated during installation if you give your consent. We then process the following data:

  • Timestamp
  • Version of the operating system used
  • AppVersion (build)
  • PortalUrl (customer)
  • Device name
  • Screen resolution
  • Screen orientation
  • Username
  • Type of log file (INFO, ERROR, EXCEPTION)
  • Title and content of the log file
  • Language

The legal basis for the reading and transmission of your usage behaviour is Article 6 (1a) GDPR, i.e. your consent. This consent can be revoked at any time in the future. If you do not wish to contribute to improving the App, you can deactivate the services in the App settings at any time.

4. Duration of storage

We store the log files on our servers for fifteen (15) days and then automatically delete them from our systems.

The App optimisation data is stored for ninety (90) days and then automatically deleted.

E. Identification Link Generator

1. Description and scope of data processing

To use the Identification Link Generator, registration is required to create a user account. This is created by the user himself and then stored in the GEMÜ Identity Provider. No data is passed on to third parties.

The following data is collected as part of the registration process:

  • First name/last name
  • Username
  • Email address
  • Cryptographic hash of the password
  • User authorizations (roles)

As soon as the registration process is completed, a technically necessary cookie is set, which is discarded when the user logs out. If the user does not log out, the cookie is deleted after twelve (12) hours at the latest.

The data is provided automatically when the page is accessed; without processing this data, the Identification Link Generator may not be able to be provided securely.

The recipients of the data are the relevant specialist department, our IT department and administrators, as well as, where applicable, hosting and IT service providers acting as our data processors. The data is not transferred to a third country.

2. Purpose of data processing

Registration of the user is required for the fulfilment of a contract.

3. Legal basis for data processing

Registration serves to fulfil a contract to which the user is a party, which is why the legal basis for processing the data is Art. 6 (1b) GDPR.

The legal basis for the use of technically necessary cookies is Section 25 (2)(2) Federal Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (TDDDG) in conjunction with Art. 6 (1f) GDPR.

4. Duration of storage

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected.

This is the case for data collected during the registration process for the fulfilment of a contract when the data is no longer required for the performance of the contract. Even after the conclusion of the contract, there may be a need to store personal data of the contractual partner to comply with contractual or legal obligations.

5. Objection and removal

As a user, you have the option of cancelling your registration at any time. You can have the data stored about you changed at any time. You can find contact information for this under point "I. Identity and contact details of the data controller".

F. Hosting

The Portal of the Asset-Lifecycle-Management-Platform is hosted on servers of a service provider commissioned by us.

Our service providers are: ETES GmbH (for production Portals) and Netcup GmbH (for test installations, PoC, etc.).

Should you have any queries or require further clarification on this matter, we will be glad to inform you, upon request, where the service you have commissioned is hosted at any given time.

The Identification Link Generator is hosted on servers belonging to the following service provider, whom we have commissioned: Netcup GmbH.

These service providers act on behalf of GEMÜ as data processors in accordance with Article 28 of the GDPR.

The software servers are geographically located in Germany.

G. Amendment of the Privacy Policy

We reserve the right to amend the Privacy Policy in order to adapt it to any changes in the legal situation or in the event of changes to the service and data processing.