Data protection

Privacy policy / user information

User information and information obligations of Vattenfall Energy Trading GmbH and Vattenfall Europe Power Management GmbH in accordance with the General Data Protection Regulation (GDPR).

Thank you for visiting our website and for your interest in the Vattenfall companies. We take the protection of your data very seriously and want you to feel safe and comfortable when visiting our website. Below you will find all the information for customers, interested parties and suppliers that applies to data protection and the use of our Internet pages.

Vattenfall Energy Trading GmbH

 

Privacy Policy/
User information (Status: January 2024)

User information and information obligations of

Vattenfall Energy Trading GmbH

according to the German Data Protection Regulation (DS-GVO)

 

Thank you for visiting our website and for your interest in Vattenfall companies. We take the protection of your data seriously and want you to feel safe and comfortable when visiting our Internet pages.

Below you will find all the information for customers, interested parties and trading partners that applies to data protection and the use of our Internet pages.

  • Information on data protection
  • Information on the use of the Internet pages

Information on data protection

 

Person responsible for data processing:

Vattenfall Energy Trading GmbH

represented by:

Frank van Doorn
Patrice Petong
Dammtorstraße 29-32
D-20354 Hamburg

Contact details of the data protection officer:

Vattenfall Energy Trading GmbH
Email datenschutz@vattenfall.de

Processing frame

Data categories

Data of customers, prospective customers and trade partners are processed, provided that they are necessary for the fulfillment of the purposes mentioned below. This includes the following categories of personal data: Name, first name, company name, e-mail address and telephone number . Upon request, we will be happy to inform you in which procedure your data may be stored and what data is involved.

Purposes and legal bases of data processing

As a rule, you can visit the pages of the Vattenfall companies without us requiring any personal data from you. We only store access data without personal reference. We process personal data in accordance with the provisions of the EU General Data Protection Regulation (DS-GVO) and the German Federal Data Protection Act (BDSG)

a) for the fulfillment of contractual obligations (Art. 6 para.1 lit. b DS-GVO).

The data processing is necessary for the contract initiation and execution of the supplier contract. The data collection takes place in the context of the conclusion of the contract and for the duration of the contract. Among other things, personal details of contact persons in your company such as name, address, e-mail address, contract data and payment information (such as bank data, billing data) are collected.

b) Based on consent (Art. 6 para.1 lit. a DS-GVO).

Insofar as we have obtained consent from you to process personal data for specific purposes, the processing is lawful on this basis. For the promotional approach to our products and services, as well as offers and services of our partners, we only contact you via communication channels for which we have received prior consent, subject to the sending of mail. We use your contact information for personalized offers and newsletter subscriptions.

Consent given can be revoked at any time without giving reasons with effect for the future. You can object to the use of your data for advertising purposes at any time at werbewiderspruch-b2b@vattenfall.de for the future.

c) Data processing based on a legitimate interest (Art. 6 para. 1 lit. f DS-GVO)

It is our goal to provide our interested parties with optimal advice and support through services tailored to their needs. For this purpose, in addition to the data provided by you, we also make use of publicly available data and service providers. This includes the use of your data for the following purposes:

  • Sending information about our energy products, services and activities (e.g. events, sponsoring) also from partners and affiliated companies.

This use of data is carried out in a permissible manner, taking into account the legitimate interests of both parties. The legitimate interest on our part is to be able to provide you with information and offers tailored to your needs through this purposeful use. In order to protect your legitimate interests, we process your data only strictly for the intended purpose and take reasonable care to limit the use of the data to a minimum. In addition, you have the right to object to the use of your data for advertising purposes at any time.

d) Data processing due to legal obligation (Art. 6 para. 1 lit. c DS-GVO).

As a company, we are subject to various legal obligations (e.g. tax laws, commercial code) that make it necessary to process your data to comply with the law.


Data sharing

In some cases, internal and external processors (e.g. IT service providers) are commissioned to process the data in compliance with the requirements of Art. 28 DS-GVO in order to fulfill the above-mentioned purposes.

A transfer of data takes place due to legal obligations to public bodies in the presence of overriding legal provisions.

A transfer of customer or prospective customer data to third countries (outside the EU/EEA) is not planned. Sub-processes of the processing of supplier data (master data, contact data and bank data) are carried out with the cooperation of service providers in the USA and India. This relates in particular to administrator access by IT service providers. As far as there is no adequacy decision of the EU Commission for these countries, the compliance with the data protection level of the GDPR is secured by the conclusion of EU standard contractual clauses. For more information, please contact the data protection officer (datenschutz@vattenfall.de).

Storage period of personal data

We process your personal data as long as it is necessary for the fulfillment of our contractual and legal obligations and the processing purposes mentioned above. The legislator has enacted a variety of retention obligations and periods. These include, among others, retention obligations from the German Commercial Code (HGB) and the German Fiscal Code (AO). After these periods have expired, the corresponding data is routinely deleted. If data is not affected by this, it is deleted when the aforementioned purposes cease to apply.

Obligation to provide data

We only request and process personal data from you that we absolutely need to process and fulfill the above-mentioned purposes and obligations. Without this data, no services can be provided.

Automated decision making

No automated decision-making, including profiling, takes place for the justification and implementation of the described processing operations.

 

Information about data subject rights

Data subject rights

If you have any questions regarding the processing of your personal data, you can contact our data protection officer directly, who is also available with his team in the event of requests for information, applications or complaints. All inquiries regarding the data stored about you pursuant to Art. 15 DS-GVO should be addressed to:

Vattenfall Energy Trading GmbH
E-mail: datenschutz@vattenfall.de

The Data Protection Officer is also your contact for exercising your rights to rectification in the event of errors in the storage and processing of your data (Art. 16 DS-GVO), deletion of your data, for example, if the purpose ceases to apply or if you revoke consent given (Art. 17 and 18 DS-GVO), restriction of processing, for example, due to the contestation of the accuracy of personal data or for the protection of possible existing claims (Art. 18 DS-GVO), objection to processing based on legitimate interest (Art. 21 DS-GVO) and data portability over the data provided by you in a machine-readable format (Art. 20 DS-GVO).

Revocation of consent

If your data processing is based on the legal basis of consent, you have the right to revoke this consent at any time for the future.

You can object to the use of your data for advertising purposes at any time at werbewiderspruch-b2b@vattenfall.de.

Objection according to Art. 21 DS-GVO:

If the data processing is carried out on the basis of balancing interests according to Art. 6 (1) lit f DS-GVO, you have the right to object to this processing at any time on the basis of reasons arising from your particular situation.

Please send your objection to: werbewiderspruch-b2b@vattenfall.de.

Right of appeal:

In addition, there is a right of appeal to a competent data protection supervisory authority (Art. 77 DS-GVO). The data protection supervisory authority responsible for Vattenfall Energy Trading GmbH can be reached at:

The Hamburg Commissioner for Data Protection and Freedom of Information.
Klosterwall 6 (Block C), 20095 Hamburg, Germany.
Tel.: (040) 4 28 54 - 40 40
E-Fax: (040) 4 279 - 11811
E-mail: mailbox@datenschutz.hamburg.de

Information on the use of the Internet pages

Collection and processing of personal data when visiting websites

As a rule, you can visit the pages of the Vattenfall companies mentioned above without us requiring any personal data from you.

We only store access data without personal reference (for example, browser type, operating system used or access time and time spent on the pages). Each device requires a unique IP address for the transmission of data on the Internet. We store this temporarily for data security reasons, in order to ensure the stability and operational reliability and operability of our system. No personal evaluation takes place in the process. A statistical evaluation of anonymized data records is reserved.

These data are only evaluated for the technical operation of the Internet pages as well as for statistical purposes to improve the offer and are subsequently deleted, unless they are further required for evidentiary purposes in legal prosecution.

Personal data is only requested and processed if it is absolutely necessary for the service offers of Vattenfall Energy Trading GmbH (for example, to register for our newsletter) in order to process your request. Information on the above-mentioned service offers on the Internet pages is described in the respective sections.

Data security

When using the services offered, your personal data is encrypted and transmitted via the Internet using a secure transmission protocol (https). We regularly use technical and organizational measures to secure our websites and other systems against access, loss, destruction or modification of your data by unauthorized persons.


Use and disclosure of personal data and purpose limitation

All data from the Vattenfall Internet services are processed in accordance with the applicable regulations on the protection of personal data. This is done only for the purpose of contract processing and to protect our own legitimate business interests with regard to advising and supporting our customers and designing products to meet their needs.

No personal data is passed on to third parties via our Internet pages. Communication for web analysis only takes place in anonymized form through the use of cookies and pixels with the providers described in the sections on the use of web tracking tools below. For the use of web tracking tools, we require your consent, which you give us when entering the website and can also revoke at any time.

You can adjust the decision to use statistical or personalized cookies at any time using the command in the footer of our pages.

Storage period

We store personal data for as long as it is required for the use of the purpose. The respective validity period can be found for web analytics in the section Use of web tracking tools specifically described for each cookie category individually. Further information on the storage period for personal data can be found in the section Information on data protection.

Reporting security vulnerabilities through Responsible Disclosure

Vattenfall attaches the highest importance to the security of its information and communication systems. In principle, security vulnerabilities cannot be 100% excluded. Exploitation or misuse of these vulnerabilities is illegal.
To prevent identified security vulnerabilities from being exploited by attackers, the German Federal Office for Information Security (BSI) also recommends the application of the "Responsible Disclosure" principle. The application of this principle guarantees a coordinated and trust-based cooperation between the discoverer of the security vulnerability and the affected manufacturer or service provider.

Inform and report a security vulnerability

Use of cookies and web tracking tools

In some areas of the Internet pages, Vattenfall Energy Trading GmbH uses cookies as web tracking in order to provide you with our service in a more individualized manner. Cookies are text files that a web server can store on your terminal device (for example, computer, smartphone, tablet) to identify the terminal device for the duration of the visit. We use cookies that are automatically deleted when you exit the browser (session cookies), as well as cookies that help us recognize you the next time you visit our website (personalized cookies). When visiting our Internet pages, you can decide at any time whether web tracking should be permitted. You can set your browser to inform you about the placement of cookies. This makes the use of cookies even more transparent for you. Should you additionally deactivate the cookies used on our Internet pages through your browser, ordering or modification actions, for example, cannot be carried out. You will receive corresponding error messages.

In addition to cookies, other technologies (for example, pixels) are occasionally used to be able to collect corresponding information.

Technically necessary tools & cookies
These tools are necessary for the smooth functioning of our websites and cannot be deactivated in our systems. The use of the tools is based on Art. 6 para. 1 lit. f DSGVO.
We store the cookies as long as they are necessary for the use of the purpose and the consent is given by you. You can see the validity period at the respective definition of the cookie.

Technically necessary tools and their cookies are used by the following operators:

Microsoft Azure
Microsoft Azure is a scalable cloud computing platform from Microsoft, which provides various cloud services for operating websites and other services worldwide.

List of cookies used:

Name

Description

Validity

ARRAffinity

These cookies are set by web pages running on the Windows Azure cloud platform. They are used for server load balancing and to ensure that visitor page requests are forwarded to the same server in each browsing session.

Until end of session

CONSENTUsed to determine whether the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for the website's compliance with the GDPR.6068 Days
CONSENTUsed to determine whether the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for the website's compliance with the GDPR.6068 Days
CookieConsentStores the user's consent status for cookies on the current domain.1 Year
PHPSESSIDRetains the user's states for all page requests.Session
test_cookieUsed to check if the user's browser supports cookies.1 Day
Hyphenator_5.3.0_deNot classifiedPersistent

 

Tools for statistical purposes

In order to further improve our website for you, we collect general information (for example, page viewed, browser used, time spent on pages). For this purpose, statistical tools are used to perform statistical analyses of usage behavior on Internet pages. For this purpose, statistics are generated that provide an overview of visits and access sources, this data is therefore not personal. This is done through the use of our own cookies (so-called first party cookies) and third-party cookies (so-called third party cookies). Neither Vattenfall nor the operators of the respective analysis tools collect information that allows conclusions to be drawn about the identity of the users. The use of the tools is based on Art. 6 (1) lit. a DSGVO. Consent can be stored and revoked anywhere in cookie settings of the websites centrally for the site.
We store the cookies as long as they are necessary for the use of the purpose and the consent is given by you. You can see the validity period at the respective definition of the cookie.

The following operators and services and their associated cookies are used by us for statistical purposes:

Opentracker

Our website uses the services of the web analytics service Opentracker to analyze user traffic to our site. This information is used to provide user interests and helps us to customize and improve our pages. When you visit our pages, a small text file, a cookie, is loaded onto your terminal device. This information is collected only for traffic analysis and does not contain any personal data. Depending on your browser, you can restrict the use of cookies on your end device via the browser settings or delete them again. Opentracker assures in its TOS that it will not sell or share this data or pass on the statistics generated to third parties for marketing and/or other data collection purposes.

List of cookies used:

Name

Description

Validity

_otui

Used to distinguish users and sessions. The cookie is created when the javascript library executes and no existing _otui cookies exists. The cookie is updated every time data is sent to Opentracker.

2 years from set/ update

_otsUsed to determine new sessions/visits. The cookie is created when the javascript library executes and no existing _ots cookies exists. The cookie is updated every time data is sent to Opentracker.30 mins from set/ update
_otpeUsed to store the previous event before landing on the current page.30 mins from set/ update
_otorUsed to store the original referrer/ event that that explains how the user reached your site. The cookie is created when the javascript library is executes for the first time.2 years from set/ update
machine-idDeprecated: was used to store the original country from which the user reached your site. The cookie is created when the javascript library is executes for the first time.2 years from set/ update
utm_*Optional: Used to store the original utm_/ event that that explains which campaign the user reached your site with. The cookie is created when the javascript library is executes with an optional utm_* parameter in the query portion of the url.2 years from set/ update

 

Merchant information: Opentracker, Torenallee 45 - 7.17, NL 5617 Eindhoven
More information about the provider's privacy policy can be found at this address: https://www.opentracker.net/privacy/.

Personalization tools
Cookies and similar technologies are used to personalize and optimize the user experience as well as our advertising campaigns. This allows individualized, promotional content to be displayed in a targeted manner. On some of our websites, we use retargeting technology (e.g. from Google, Facebook). The use of the tools is based on Art. 6 para. 1 lit. a DSGVO. Consent can be stored and revoked anywhere in cookie settings of the websites centrally for the site.
We store the cookies as long as they are necessary for the use of the purpose and the consent is given by you. The validity period can be seen in the respective definition of the cookie.

The following operators and services and their associated cookies are used by us for personalized purposes:

Google-Ads
We use the Google services "Google Ad Manager" (formerly "DoubleClick for Publishers"), "Google Ads Conversion Tracking" (formerly "Google Adwords"), Google Campaign Manager (formerly "Double Click Campaign Manager") and Google Search Ads 360 (formerly "DoubleClick Search"). This allows us to measure and optimize the success of the various advertising measures and better tailor advertising to your needs.

List of cookies used:

Name

Description

Validity

_gcl_auUsed to measure interaction with advertising and resulting web page visits.90 Days
DVUsed to support Google's advertising services.5 Minutes
1P_JARContains information about how the end user uses the website, as well as advertisements that the end user may have seen before visiting this website.1 Month
_uetsidUsed to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.Persistent
_uetsidCollects data on visitor behavior on multiple websites to present more relevant ads - This also allows the website to limit the number of times the same ad is displayed.1 Day
_uetsid_expContains the expiration date for the cookie with corresponding name.

Persistent

_uetvidUsed to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.

Persistent

_uetvidUsed to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.1 Year
_uetvid_expContains the expiration date for the cookie with corresponding name.

Persistent

bcookieUsed by the social networking service LinkedIn for tracking the use of embedded services.2 Years
bscookieUsed by the social networking service LinkedIn for tracking the use of embedded services.2 Years
IDEUsed by Google DoubleClick to record and report the user's actions on the website after viewing or clicking on one of the provider's ads, with the purpose of measuring the effectiveness of an advertisement and displaying targeted advertisements to the user.1 Year
langSet by LinkedIn when a web page contains an embedded "Follow us" window.Session
lidcUsed by the social networking service LinkedIn for tracking the use of embedded services.1 Day
MUIDWidely used by Microsoft as a unique user ID. The cookie enables user tracking by synchronizing the ID in many Microsoft domains.1 Year
UserMatchHistoryUsed to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.29 Days
VISITOR_INFO1_LIVETries to estimate user bandwidth on pages with integrated YouTube videos.179 Days
YSCRegisters a unique ID to keep statistics of the videos from YouTube that the user has watched.Session
yt.innertube::nextIdRegisters a unique ID to keep statistics of the videos from YouTube that the user has watched.Persistent
yt.innertube::requestsRegisters a unique ID to keep statistics of the videos from YouTube that the user has watched.

Persistent

yt-remote-cast-availableNot classified

Session

yt-remote-cast-installedSaves the user settings when retrieving a Youtube video integrated on other web pages

Session

yt-remote-connected-devicesSaves the user settings when retrieving a Youtube video integrated on other web pages

Persistent

yt-remote-device-idSaves the user settings when retrieving a Youtube video integrated on other web pages

Persistent

yt-remote-fast-check-periodSaves the user settings when retrieving a Youtube video integrated on other web pages

Session

yt-remote-session-appSaves the user settings when retrieving a Youtube video integrated on other web pages

Session

yt-remote-session-nameSaves the user settings when retrieving a Youtube video integrated on other web pages

Session

langSaves the language version of a web page selected by the user

Session

 

Provider information: Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA

More information on terms of use and privacy can be found here:

http://www.google.com/policies/technologies/ads 
http://www.google.de/settings/ads

Use of social media channels
Detailed information on our social media channels can be found here.

You Tube Plugin Video
Our website uses videos that are integrated via the provider YouTube. This belongs to Google Inc., based in San Bruno/California, USA. When you enter our website, no personal data is sent to YouTube. Personal data, such as the anonymized IP and technical connection data, in particular which Internet pages you have visited, are only processed by YouTube when the video is clicked on and thus played.

An assignment to your person is only possible if you are logged into YouTube or another Google service when you call up the page. You can prevent this assignment by logging out of your YouTube user account and other user accounts of the companies YouTube LLC and Google Inc. before using our website and deleting the corresponding cookies of the companies.

Provider information: Google/YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Privacy policy of Youtube: http://www.google.com/intl/de/policies/privacy/.


Links to other websites


The Vattenfall Energy Trading GmbH website may contain links to websites of third parties or affiliated companies. If you use these links, you will leave the Vattenfall Energy Trading GmbH website and thus also the scope of this privacy policy. Vattenfall Energy Trading GmbH is not responsible for compliance with the legal provisions by these other operators. The responsibility lies exclusively with the respective website operator.


Vattenfall Europe Power Management GmbH

 

Privacy Policy/
User information (26.11.2021)

User information and information obligations of

Vattenfall Europe Power Management GmbH

according to the German Data Protection Regulation (DS-GVO)

 

Thank you for visiting our website and for your interest in Vattenfall companies. We take the protection of your data seriously and want you to feel safe and comfortable when visiting our Internet pages.

Below you will find all the information for customers, interested parties and trading partners that applies to data protection and the use of our Internet pages.

  • Information on data protection
  • Information on the use of the Internet pages

Privacy information

 

Information about the data processor

Person responsible for data processing:

Vattenfall Europe Power Management GmbH

represented by:

Christian Sdralek
Christian Wulle
Dammtorstraße 29-32
D-20354 Hamburg

Contact for privacy issues:

Vattenfall Europe Power Management GmbH
Management
or per Email to: datenschutz@vattenfall.de


Processing frame

Data categories

Data of customers, interested parties and trading partners are processed, provided that they are necessary for the fulfillment of the purposes mentioned below. This includes the following categories of personal data: Name, first name, company name, e-mail address and telephone number . Upon request, we will be happy to inform you of the procedure in which your data may be stored and what data is involved.

Purposes and legal basis of data processing

As a rule, you can visit the pages of the Vattenfall companies without us requiring any personal data from you. We only store access data without any personal reference. We process personal data in accordance with the provisions of the EU General Data Protection Regulation (DS-GVO) and the German Federal Data Protection Act (BDSG)

a) for the fulfillment of contractual obligations (Art. 6 para.1 lit. b DS-GVO)

The data processing is necessary for the contract initiation and execution of the supplier contract. The data collection takes place in the context of the conclusion of the contract and for the duration of the contract. Among other things, personal details of contact persons in your company such as name, address, e-mail address, contract data and payment information (such as bank data, billing data) are collected.

b) Based on consent (Art. 6 para.1 lit. a DS-GVO).

Insofar as we have obtained consent from you to process personal data for specific purposes, the processing is lawful on this basis. For the promotional approach to our products and services, as well as offers and services of our partners, we only contact you via communication channels for which we have received prior consent, subject to the sending of mail. We use your contact information for personalized offers and newsletter subscriptions.

Consent given can be revoked at any time without giving reasons with effect for the future. You can object to the use of your data for advertising purposes at any time at werbewiderspruch-b2b@vattenfall.de for the future.

c) Data processing based on a legitimate interest (Art. 6 para. 1 lit. f DS-GVO).

It is our goal to provide our interested parties with the best possible advice and support through services tailored to their needs. For this purpose, in addition to the data provided by you, we also make use of publicly available data and service providers. This includes the use of your data for the following purposes:

 

Sending information about our energy products, services and activities (e.g. events, sponsoring) also from partners and affiliated companies.

This use of data is carried out in a permissible manner, taking into account the legitimate interests of both parties. The legitimate interest on our part is to be able to provide you with information and offers tailored to your needs through this purposeful use. In order to protect your legitimate interests, we process your data only strictly for the intended purpose and take reasonable care to limit the use of the data to a minimum. In addition, you have the right to object to the use of your data for advertising purposes at any time.

d) Data processing due to legal obligation (Art. 6 para. 1 lit. c DS-GVO).

As a company, we are subject to various legal obligations (e.g. tax laws, commercial code) that make it necessary to process your data to comply with the law.


Passing on the data

In some cases, internal and external processors (e.g. IT service providers) are commissioned to process the data in compliance with the requirements of Art. 28 DS-GVO in order to fulfill the above-mentioned purposes.

A transfer of data takes place due to legal obligations to public bodies in the presence of overriding legal provisions.

A transfer of customer or prospective customer data to third countries (outside the EU/EEA) is not planned. Sub-processes of the processing of supplier data (master data, contact data and bank data) are carried out with the cooperation of service providers in the USA and India. This relates in particular to administrator access by IT service providers. As far as there is no adequacy decision of the EU Commission for these countries, the compliance with the data protection level of the GDPR is secured by the conclusion of EU standard contractual clauses. For more information, please contact the data protection officer (datenschutz@vattenfall.de).

Storage period of personal data

We process your personal data as long as this is necessary for the fulfillment of our contractual and legal obligations and the processing purposes mentioned above. The legislator has enacted a variety of retention obligations and periods. These include, among others, retention obligations from the German Commercial Code (HGB) and the German Fiscal Code (AO). After these periods have expired, the corresponding data is routinely deleted. If data is not affected by this, it is deleted when the aforementioned purposes cease to apply.

 

Obligation to provide data

We only request and process personal data from you that we absolutely need to process and fulfill the above-mentioned purposes and obligations. Without this data, no services can be provided.

Automated decision making

No automated decision-making, including profiling, takes place for the justification and implementation of the described processing operations.

 

 

Information about data subject rights

Rights of data subjects

If you have any questions regarding the processing of your personal data, you can contact our data protection officer directly, who is also available with his team in the event of requests for information, applications or complaints. All inquiries regarding the data stored about you in accordance with Art. 15 GDPR should be directed to:

Vattenfall Europe Power Management GmbH
Email: datenschutz@vattenfall.de

The data protection officer is also your contact person for exercising your rights to rectification in the event of errors in the storage and processing of your data (Art. 16 GDPR), deletion of your data, for example, if the purpose no longer applies or if you revoke your consent (Art. 17 and 18 GDPR), Restriction of processing, for example, on the basis of contesting the accuracy of personal data or for the protection of possible existing claims (Art. 18 GDPR), objection to processing on the basis of legitimate interest (Art. 21 GDPR) and data portability of the data provided by you in a machine-readable format (Art. 20 GDPR).

Revocation of consent

If your data processing is based on the legal basis of consent, you have the right to revoke this consent at any time for the future.

You can object to the use of your data for advertising purposes at any time under werbewiderspruch-b2b@vattenfall.de.

Objection according to Art. 21 GDPR:

If the data processing is carried out on the basis of a balancing of interests in accordance with Art. 6 (1) (f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation.

Please send your objection to: werbewiderspruch-b2b@vattenfall.de.

 

Right to lodge a complaint:

In addition, there is a right of appeal to a competent data protection supervisory authority (Art. 77 GDPR). The data protection supervisory authority responsible for Vattenfall Europe Power Management GmbH can be reached at:

The Hamburg Commissioner for Data Protection and Freedom of Information
Klosterwall 6 (Block C), 20095 Hamburg
Tel.: (040) 4 28 54 - 40 40
E-Fax: (040) 4 279 - 11811
Email: mailbox@datenschutz.hamburg.de

 

Information on the use of the Internet pages

Collection and processing of personal data when visiting websites

As a rule, you can visit the pages of the Vattenfall companies mentioned above without us requiring any personal data from you.

We only store access data without personal reference (for example, browser type, operating system used or access time and time spent on the pages). Each device requires a unique IP address for the transmission of data on the Internet. We store this temporarily for data security reasons, in order to ensure the stability and operational reliability and operability of our system. No personal evaluation takes place in the process. A statistical evaluation of anonymized data records is reserved.

These data are only evaluated for the technical operation of the Internet pages as well as for statistical purposes to improve the offer and are subsequently deleted, unless they are further required for evidentiary purposes in legal prosecution.

Personal data is only requested and processed if it is absolutely necessary for the service offers of Vattenfall Energy Trading GmbH (for example, to register for our newsletter) in order to process your request. Information on the above-mentioned service offers on the Internet pages is described in the respective sections.

Data security

When using the services offered, your personal data is encrypted and transmitted via the Internet using a secure transmission protocol (https). We regularly use technical and organizational measures to secure our websites and other systems against access, loss, destruction or modification of your data by unauthorized persons.


Use and disclosure of personal data and purpose limitation

All data from the Vattenfall Internet services are processed in accordance with the applicable regulations on the protection of personal data. This is done only for the purpose of contract processing and to protect our own legitimate business interests with regard to advising and supporting our customers and designing products to meet their needs.

No personal data is passed on to third parties via our Internet pages. Communication for web analysis only takes place in anonymized form through the use of cookies and pixels with the providers described in the sections on the use of web tracking tools below. For the use of web tracking tools, we require your consent, which you give us when entering the website and can also revoke at any time.

You can adjust the decision to use statistical or personalized cookies at any time using the command in the footer of our pages.

Storage period

We store personal data for as long as it is required for the use of the purpose. The respective validity period can be found for web analytics in the section Use of web tracking tools specifically described for each cookie category individually. Further information on the storage period for personal data can be found in the section Information on data protection.

Reporting security vulnerabilities through Responsible Disclosure

Vattenfall attaches the highest importance to the security of its information and communication systems. In principle, security vulnerabilities cannot be 100% excluded. Exploitation or misuse of these vulnerabilities is illegal.
To prevent identified security vulnerabilities from being exploited by attackers, the German Federal Office for Information Security (BSI) also recommends the application of the "Responsible Disclosure" principle. The application of this principle guarantees a coordinated and trust-based cooperation between the discoverer of the security vulnerability and the affected manufacturer or service provider.

Inform and report a security vulnerability

Use of cookies and web tracking tools

In some areas of the Internet pages, Vattenfall Energy Trading GmbH uses cookies as web tracking in order to provide you with our service in a more individualized manner. Cookies are text files that a web server can store on your terminal device (for example, computer, smartphone, tablet) to identify the terminal device for the duration of the visit. We use cookies that are automatically deleted when you exit the browser (session cookies), as well as cookies that help us recognize you the next time you visit our website (personalized cookies). When visiting our Internet pages, you can decide at any time whether web tracking should be permitted. You can set your browser to inform you about the placement of cookies. This makes the use of cookies even more transparent for you. Should you additionally deactivate the cookies used on our Internet pages through your browser, ordering or modification actions, for example, cannot be carried out. You will receive corresponding error messages.

In addition to cookies, other technologies (for example, pixels) are occasionally used to be able to collect corresponding information.

Technically necessary tools & cookies
These tools are necessary for the smooth functioning of our websites and cannot be deactivated in our systems. The use of the tools is based on Art. 6 para. 1 lit. f DSGVO.
We store the cookies as long as they are necessary for the use of the purpose and the consent is given by you. You can see the validity period at the respective definition of the cookie.

Technically necessary tools and their cookies are used by the following operators:

Microsoft Azure
Microsoft Azure is a scalable cloud computing platform from Microsoft, which provides various cloud services for operating websites and other services worldwide.

List of cookies used:

Name

Description

Validity

ARRAffinity

These cookies are set by web pages running on the Windows Azure cloud platform. They are used for server load balancing and to ensure that visitor page requests are forwarded to the same server in each browsing session.

Until end of session

CONSENTUsed to determine whether the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for the website's compliance with the GDPR.6068 Days
CONSENTUsed to determine whether the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for the website's compliance with the GDPR.6068 Days
CookieConsentStores the user's consent status for cookies on the current domain.1 Year
PHPSESSIDRetains the user's states for all page requests.Session
test_cookieUsed to check if the user's browser supports cookies.1 Day
Hyphenator_5.3.0_deNot classifiedPersistent

 

Tools for statistical purposes

In order to further improve our website for you, we collect general information (for example, page viewed, browser used, time spent on pages). For this purpose, statistical tools are used to perform statistical analyses of usage behavior on Internet pages. For this purpose, statistics are generated that provide an overview of visits and access sources, this data is therefore not personal. This is done through the use of our own cookies (so-called first party cookies) and third-party cookies (so-called third party cookies). Neither Vattenfall nor the operators of the respective analysis tools collect information that allows conclusions to be drawn about the identity of the users. The use of the tools is based on Art. 6 (1) lit. a DSGVO. Consent can be stored and revoked anywhere in cookie settings of the websites centrally for the site.
We store the cookies as long as they are necessary for the use of the purpose and the consent is given by you. You can see the validity period at the respective definition of the cookie.

The following operators and services and their associated cookies are used by us for statistical purposes:

Opentracker

Our website uses the services of the web analytics service Opentracker to analyze user traffic to our site. This information is used to provide user interests and helps us to customize and improve our pages. When you visit our pages, a small text file, a cookie, is loaded onto your terminal device. This information is collected only for traffic analysis and does not contain any personal data. Depending on your browser, you can restrict the use of cookies on your end device via the browser settings or delete them again. Opentracker assures in its TOS that it will not sell or share this data or pass on the statistics generated to third parties for marketing and/or other data collection purposes.

Matomo

This website uses Matomo cookieless for website analysis to give us insights into the use of this website. This tool does not require cookies to be set in the browser or device. So-called browser fingerprinting or device fingerprinting is used to collect the data. We do not use this to collect any personal data, but instead determine a so-called visit ID, which is transmitted via various features of the browser program each time a page is accessed. This includes, for example, the operating system, language or installed fonts. The visit ID is also referred to as config_id and is a randomly set, time-limited hash of a limited number of settings and attributes of the visitor's browser.

Purpose of processing: With the help of Matomo cookieless, we obtain a website analysis and can statistically measure our number of visitors.

Legal basis: Data processing is based on Art. 6 para. 1 f) GDPR. Our legitimate interest in statistical processing arises from the aforementioned purpose.

Recipient: We treat your data confidentially. Our website is only analyzed by internal employees; it is not forwarded or transmitted. 

Storage duration: The config_id is only valid for a maximum of 24 hours and is then rotated so that a new random and different config_id is assigned afterwards.

Third country transfer: There is no third country transfer. 

List of cookies used:

Name

Description

Validity

_otui

Used to distinguish users and sessions. The cookie is created when the javascript library executes and no existing _otui cookies exists. The cookie is updated every time data is sent to Opentracker.

2 years from set/ update

_otsUsed to determine new sessions/visits. The cookie is created when the javascript library executes and no existing _ots cookies exists. The cookie is updated every time data is sent to Opentracker.30 mins from set/ update
_otpeUsed to store the previous event before landing on the current page.30 mins from set/ update
_otorUsed to store the original referrer/ event that that explains how the user reached your site. The cookie is created when the javascript library is executes for the first time.2 years from set/ update
machine-idDeprecated: was used to store the original country from which the user reached your site. The cookie is created when the javascript library is executes for the first time.2 years from set/ update
utm_*Optional: Used to store the original utm_/ event that that explains which campaign the user reached your site with. The cookie is created when the javascript library is executes with an optional utm_* parameter in the query portion of the url.2 years from set/ update

 

Merchant information: Opentracker, Torenallee 45 - 7.17, NL 5617 Eindhoven
More information about the provider's privacy policy can be found at this address: https://www.opentracker.net/privacy/.

Personalization tools
Cookies and similar technologies are used to personalize and optimize the user experience as well as our advertising campaigns. This allows individualized, promotional content to be displayed in a targeted manner. On some of our websites, we use retargeting technology (e.g. from Google, Facebook). The use of the tools is based on Art. 6 para. 1 lit. a DSGVO. Consent can be stored and revoked anywhere in cookie settings of the websites centrally for the site.
We store the cookies as long as they are necessary for the use of the purpose and the consent is given by you. The validity period can be seen in the respective definition of the cookie.

The following operators and services and their associated cookies are used by us for personalized purposes:

Google-Ads
We use the Google services "Google Ad Manager" (formerly "DoubleClick for Publishers"), "Google Ads Conversion Tracking" (formerly "Google Adwords"), Google Campaign Manager (formerly "Double Click Campaign Manager") and Google Search Ads 360 (formerly "DoubleClick Search"). This allows us to measure and optimize the success of the various advertising measures and better tailor advertising to your needs.

List of cookies used:

Name

Description

Validity

_gcl_auUsed to measure interaction with advertising and resulting web page visits.90 Days
DVUsed to support Google's advertising services.5 Minutes
1P_JARContains information about how the end user uses the website, as well as advertisements that the end user may have seen before visiting this website.1 Month
_uetsidUsed to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.Persistent
_uetsidCollects data on visitor behavior on multiple websites to present more relevant ads - This also allows the website to limit the number of times the same ad is displayed.1 Day
_uetsid_expContains the expiration date for the cookie with corresponding name.

Persistent

_uetvidUsed to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.

Persistent

_uetvidUsed to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.1 Year
_uetvid_expContains the expiration date for the cookie with corresponding name.

Persistent

bcookieUsed by the social networking service LinkedIn for tracking the use of embedded services.2 Years
bscookieUsed by the social networking service LinkedIn for tracking the use of embedded services.2 Years
IDEUsed by Google DoubleClick to record and report the user's actions on the website after viewing or clicking on one of the provider's ads, with the purpose of measuring the effectiveness of an advertisement and displaying targeted advertisements to the user.1 Year
langSet by LinkedIn when a web page contains an embedded "Follow us" window.Session
lidcUsed by the social networking service LinkedIn for tracking the use of embedded services.1 Day
MUIDWidely used by Microsoft as a unique user ID. The cookie enables user tracking by synchronizing the ID in many Microsoft domains.1 Year
UserMatchHistoryUsed to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.29 Days
VISITOR_INFO1_LIVETries to estimate user bandwidth on pages with integrated YouTube videos.179 Days
YSCRegisters a unique ID to keep statistics of the videos from YouTube that the user has watched.Session
yt.innertube::nextIdRegisters a unique ID to keep statistics of the videos from YouTube that the user has watched.Persistent
yt.innertube::requestsRegisters a unique ID to keep statistics of the videos from YouTube that the user has watched.

Persistent

yt-remote-cast-availableNot classified

Session

yt-remote-cast-installedSaves the user settings when retrieving a Youtube video integrated on other web pages

Session

yt-remote-connected-devicesSaves the user settings when retrieving a Youtube video integrated on other web pages

Persistent

yt-remote-device-idSaves the user settings when retrieving a Youtube video integrated on other web pages

Persistent

yt-remote-fast-check-periodSaves the user settings when retrieving a Youtube video integrated on other web pages

Session

yt-remote-session-appSaves the user settings when retrieving a Youtube video integrated on other web pages

Session

yt-remote-session-nameSaves the user settings when retrieving a Youtube video integrated on other web pages

Session

langSaves the language version of a web page selected by the user

Session

 

Provider information: Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA

More information on terms of use and privacy can be found here:

http://www.google.com/policies/technologies/ads 
http://www.google.de/settings/ads

Use of social media channels
Detailed information on our social media channels can be found here.

You Tube Plugin Video
Our website uses videos that are integrated via the provider YouTube. This belongs to Google Inc., based in San Bruno/California, USA. When you enter our website, no personal data is sent to YouTube. Personal data, such as the anonymized IP and technical connection data, in particular which Internet pages you have visited, are only processed by YouTube when the video is clicked on and thus played.

An assignment to your person is only possible if you are logged into YouTube or another Google service when you call up the page. You can prevent this assignment by logging out of your YouTube user account and other user accounts of the companies YouTube LLC and Google Inc. before using our website and deleting the corresponding cookies of the companies.

Provider information: Google/YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Privacy policy of Youtube: http://www.google.com/intl/de/policies/privacy/.


Links to other websites


The Vattenfall Energy Trading GmbH website may contain links to websites of third parties or affiliated companies. If you use these links, you will leave the Vattenfall Energy Trading GmbH website and thus also the scope of this privacy policy. Vattenfall Energy Trading GmbH is not responsible for compliance with the legal provisions by these other operators. The responsibility lies exclusively with the respective website operator.