We would like to inform you, by means of the following data protection information, about which personal data is collected, processed and possibly transmitted when you visit our website, to what extent and for what purpose.
Where this website links to external websites of other providers, you will leave our website by clicking on these links. The operators of those linked websites are solely responsible for compliance with data protection regulations.
Data protection principles
Protecting your privacy and ensuring the security of all business data are of utmost importance to us, and we take this into account in our business processes. Data protection and information security are integral parts of our corporate policy.
We place the utmost importance on the protection of your personal data and process it exclusively in accordance with the laws and regulations of the Federal Republic of Germany and applicable European legal requirements, including the EU General Data Protection Regulation (GDPR) and other national laws that may apply. Your personal data will be processed to the extent and for the purposes described below. This means we only use your personal data if data protection laws expressly permit it or if you have given us your prior consent.
Data security
We have implemented comprehensive technical and organizational security measures to protect your data, which we manage, against manipulation, loss, destruction, or unauthorized access or disclosure. This includes ensuring that only authorized personnel have access to your personal data, and only to the extent necessary for the stated purposes. Our security procedures are regularly reviewed and updated to reflect the latest technological advancements. Our employees are bound by confidentiality agreements and receive periodic training on data protection and security topics.
Definitions
The EU General Data Protection Regulation uses certain terms that are defined in Article 4, e.g. personal data, processing, pseudonymization, controller, processor, recipient, third party, consent.
Name and contact details of the responsible party
Website: www.gk-graphite.comGraphit Kropfmühl GmbH
Langheinrichstraße 1
94051 Hauzenberg
Germany
Tel.: +49 8586 609-0
E-mail:
Website: www.graphit-bbw.de
Graphit Kropfmühl Visitor Mine gGmbH
Langheinrichstraße 1
94051 Hauzenberg
Germany
Tel.: +49 8586 609-147
E-mail:
For questions regarding data protection and to assert your data subject rights, please contact our data protection team.
E-mail:
Name and address of the data protection officer
Dr. Eddie KohfeldtLangheinrichstraße 1
94051 Hauzenberg
Germany
Tel.: 08586 609-0
E-mail:
General information on the processing of personal data
Scope of processingWe process personal data to provide a website with various content and functions, and when this is necessary for offering, providing and billing our business services and products.
Purposes of processing
The purposes of processing personal data are based on the conduct of the controller's business operations and all related ancillary business.
Legal basis for processing
Personal data is processed exclusively on the basis of the currently applicable legal principles.
- For the processing of personal data necessary for the performance of a contract to which the data subject is a party, Article 6(1)(b) GDPR is the legal basis. This also applies to processing operations necessary for carrying out pre-contractual measures.
- If processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, and the interests or fundamental rights and freedoms of the data subject do not override those interests, then Article 6(1)(f) GDPR is the legal basis for the processing.
- Insofar as we obtain the consent of the data subject for processing operations involving personal data, the legal basis is Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR (in the case of special categories of personal data).
- If the processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Article 6(1)(c) GDPR is the legal basis.
- In the event that the processing of personal data is necessary to protect the vital interests of the data subject or of another natural person, Article 6(1)(d) GDPR is the legal basis.
- If data is transferred to third countries, this is done either on the basis of an adequacy decision of the European Union (Art. 45 GDPR), on the basis of suitable safeguards (Art. 46 GDPR) or on the basis of Art. 49 para. 1 lit. b if this is necessary for the performance of the contract.
Legal or contractual requirements for providing personal data
The provision of personal data by you may be required by law or contract, or necessary for entering into a contract.
In particular, you may be required to provide us with personal data for the conclusion of contracts. Failure to provide this personal data would mean that the contract with you could not be concluded.
Disclosure of personal data
We only share your personal data with third parties if
- this is necessary for initiating or carrying out a contractual relationship with you;
- it is necessary to protect our legitimate interests or those of a third party, unless the interests or fundamental rights and freedoms of you (the data subject) which require protection of personal data override those interests;
- we are legally obliged to do so;
- this is necessary to enforce our claims and rights;
- We receive requests from government bodies (e.g., regulatory authorities or law enforcement agencies, if disclosure is necessary to avert dangers to public safety and order and to prosecute criminal offenses).
In the context of such a transfer, the recipients may only use the personal data for the respective purpose.
Integration of external service providers
We are not specialists in everything. Therefore, in certain areas of our business, we use service providers who support us, e.g.
- Data centers / Cloud services for the secure operation of our services
- IT service providers for the maintenance of our infrastructure
- IT developers in the further development of our applications
- IT service provider for business applications (ERP, CRM, AI applications)
- Agencies and printing companies for sending email information or printed information
We have concluded the legally required data processing agreements, which specify exactly what the service provider is permitted to do with which data. In particular, the use of the data by the service provider for its own purposes and its transfer to third parties are prohibited. Service providers are contractually obligated to comply with applicable data protection regulations.
Data deletion and storage period
Personal data will be erased or blocked as soon as the purpose for which it was stored no longer applies. Notwithstanding this, data may be stored for a longer period if this is provided for by European or national legislation in EU regulations, laws, or other provisions to which the controller is subject (e.g., documentation requirements, retention periods), or if consent has been given. Data will be erased or blocked when a storage period prescribed by the aforementioned regulations expires, unless there is another justifiable reason for further storage of the data.
Details on the processing of personal data
Provision of the website and creation of log files
Use of cookies
Contact us via contact form, email and telephone
Processing of business contacts
If you make a reservation for the visitor mine
Use of third-party extensions
When you apply to us
Social Media
Your rights as a data subject
If your personal data is being processed, you are a data subject within the meaning of the GDPR and you have the following rights against the controller:
Right to information
You can request confirmation as to whether and which personal data concerning you is being processed by us.
Right to rectification
You have the right to rectification and/or completion if the processed personal data concerning you is inaccurate or incomplete.
Right to erasure (“right to be forgotten”)
You can request that your personal data be deleted without undue delay, and the controller is obliged to delete this data without undue delay if certain grounds apply.
Right to restriction of processing
Under certain conditions, you can request the restriction of the processing of your personal data (e.g., blocking its use or temporarily removing it from the website if it was published there)
Right to information
If you have asserted your right to rectification, erasure or restriction of processing, the controller is obliged to communicate this rectification or erasure of data or restriction of processing to all recipients to whom the personal data concerning you have been disclosed.
Right to data portability
You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used and machine-readable format. You also have the right to have the data transmitted directly to another controller, provided this is technically feasible and does not adversely affect the rights and freedoms of others.
Right to object
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) of the GDPR. This includes, in particular, the right to object to direct marketing.
Right to withdraw consent under data protection law
You have the right to withdraw your consent to data processing at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Automated decision-making in individual cases, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority.
How to exercise your rights:
You can exercise these rights by contacting us via email at
If necessary, we may request additional information required to verify your identity, such as a photocopy of an identity card.
Your requests will be processed promptly, usually within one month. If circumstances require, the processing time may be extended by two further months.
Changes to the privacy policy
We reserve the right to amend this privacy policy when introducing or modifying new services to ensure it always complies with current legal requirements. The latest version will apply to your next visit to our website.
Kropfmühl, April 2026

