Data protection



1. Data privacy responsible and data protection officer

2. Data security policy

3. Principles for the storage and deletion of personal data


1. Purposes and legal principles, based on which your data are processed

2. Purposes for the fulfilment of a contract or pre-contractual measures

3. Purposes within the scope of a legitimate interest of our own or of third parties

4. Purposes within the scope of your consent

5. Purposes for the fulfilment of legal requirements or in public interest

6. The categories of data we process, as regards data not directly obtained, and their origin

7. Recipients or categories of recipients of your data


1. General information on using the website

2. Contracted data processors

3. Cookies

4. Webtracking: Matomo (Piwik)

5. Web fonts


1. Communication and contact form


- Right to information

- Right to rectification

- Right to restriction of processing

- Right to deletion

- Right to data portability

- Right to objection

- Right of appeal to a supervisory authority

- Separate reference to the right of objection pursuant to Art. 21 para. 1, 2 GDPR




We appreciate your interest in our online offer. Below we inform you about the handling of personal data and about the data subject rights in accordance with the provisions of the General Data Protection Regulation (GDPR). Personal data is any data which is personal to you, e.g. name, address, e-mail address, user behaviour.



Responsible in the meaning of the Art. 4 Nr. 7 GDPR is 
METTEN Stein+Design GmbH & Co. KG
Industriegebiet Hammermühle
D-51491 Overath
(s.a. our Imprint)

The data protection officer can be reached at:
METTEN Stein+Design GmbH & Co. KG
Data Protection Officer
Industriegebiet Hammermühle
D-51491 Overath 


2. Data security policy

We secure our website and other systems by technical and organisational measures against loss, destruction, access, modification or dissemination of your data by unauthorised persons. Access to customer accounts is only possible after entering a user ID and a personal password. You should always treat your access data confidentially and close the browser window when you have finished communicating with us, especially if you share the computer with others.

For secure communication with us, we offer encrypted communication via the SSL protocol, which we use to secure the transfer of your personal data in our online shop.

To enable access to our web site, there is limited to a no longer 30 days period, in principle, of temporarily data storage carried out for the purpose of ensuring data and system security. This refers to data that may allow identification of a person (e.g., the IP address). The potential processing of such personal data for the purposes of data and system security is based on stipulations under Art. 6 para. 1 sentence 1 lit. f GDPR and our legitimate interest in securing our systems and preventing abuse.


3. Principles for the storage and deletion of personal data

Personal data will only be processed for the period required to achieve the respective processing purpose or if provided for in applicable laws or regulations, e.g. commercial or tax retention requirements. If a storage purpose ceases or if a legally prescribed storage period expires, the personal data concerned will be routinely and in accordance with the statutory provisions deleted or their processing will be restricted, e.g. limited under commercial or fiscal retention requirements.

The processing of personal data based on a legal obligation, namely the fulfilment of statutory retention obligations, and is based on stipulations under Art. 6 para. 1 sentence 1 lit. c GDPR Insofar as personal data pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR are processed for purposes of securing evidence; these processing purposes are dispensed with after expiry of the statutory limitation periods; the statutory period of limitation is of three years.

For more details on specific storage and deletion periods, we refer to individual service descriptions or information in this privacy policy.





We process your personal data in accordance with the provisions of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and other applicable data protection regulations. Which data is processed in detail and how it is used depends largely on the services requested or agreed upon in each case. Further details or additions to the purposes of data processing can be found in the respective contract documents, forms, a declaration of consent and/or other information provided to you. In addition, data protection information may be updated from time to time, as you can see from our website.



We process personal data to implement our contracts with you and to execute your orders as well as to carry out measures and activities within the scope of pre-contractual relations. These essentially include contract-related communication, the corresponding invoicing and associated payment transactions, verifiability of transactions, orders and other agreements, goodwill procedures, measures for controlling and optimising business processes and for fulfilling due diligence obligations, statistical evaluations for corporate management, cost recording and controlling, internal and external communication, emergency management, accounting and tax assessment of operational services, risk management, assertion of legal claims and defence in legal disputes, ensuring IT security and general security, securing and exercising domiciliary rights, guaranteeing the integrity, authenticity and availability of data, prevention and investigation of criminal offences, control by supervisory bodies or controlling authorities.



Beyond the actual fulfilment of the contract or preliminary contract, we may process your data, if necessary, to protect our own legitimate interests or those of third parties, in particular for the following purposes

  • advertising or market and opinion research, unless you have withdrawn consent for processing your data
  • obtaining information and data exchange with credit agencies, to the extent that this exceeds our financial risk
  • testing and optimising procedures for requirements analysis
  • further development of services and products as well as of existing systems and processes
  • for comparison with European and international anti-terrorism lists, insofar as they go beyond statutory requirements
  • augmentation of our data, among other things by using or researching publicly available data
  • statistical evaluation or market analysis
  • benchmarking
  • asserting legal claims and defence in legal disputes which are not directly attributable to the contractual relationship
  • limited storage of the data, if deletion is not possible or only possible with disproportionately high expenditure due to the special type of storage
  • developing scoring systems or automated decision-making processes
  • prevention and investigation of criminal offences, insofar as not exclusively for fulfilling legal requirements
  • security of buildings and facilities (e.g. by means of access controls and video surveillance) insofar as this goes beyond the general duty of care
  • internal and external investigations, security checks
  • possibly listening to telephone conversations for training purposes
  • obtaining and maintaining certifications whether from a private entity or a public authority
  • securing and exercising domiciliary rights by means of appropriate measures as well as of video surveillance to protect our customers and employees and to secure evidence in the event of criminal offences and prevention thereof.



Your personal data can also be processed for specific purposes (e.g. use of your e-mail address for marketing purposes) on the basis of your consent. You can generally withdraw this at any time. This also applies to withdrawing declarations of consent which were granted to us prior to the application of the GDPR, as of 25.05.2018. You will be separately informed about the purposes and consequences of withdrawing or failing to grant consent in the corresponding text of the consent. In principle, withdrawing a consent is only valid for the future. Any processing that has taken place prior to the withdrawal shall not be affected and shall remain lawful.



Like any other company, we are also subject to a large number of legal obligations. These may primarily involve legal requirements, but may also be regulatory or official requirements. In addition, the disclosure of personal data may become necessary in the context of official/judicial measures for the purpose of gathering evidence, prosecution or enforcement of civil claims.


6. The categories of data we process, as regards data not directly obtained from you, and their origin

Insofar as this is necessary for the provision of our services, we process personal data received from other companies or other third parties as permitted. In addition, we process personal data that we have permissibly obtained, received or acquired from public sources and we are allowed to process. Relevant categories of personal data may include in particular:

  • Personal data
  • Contact information
  • Address data
  • Payment/coverage dates for bank and credit cards
  • Creditworthiness data
  • Customer history
  • Data about your use of telemedia offered by us



The internal departments or organisational units within our company that receive your data are those which require the data to fulfil our contractual and legal obligations or within the scope of processing and implementing our legitimate interests. Your data will be passed on to external parties solely

  • in connection with the fulfilment of the contract
  • for the purposes of fulfilling legal requirements according to which we are obliged to provide, report or forward information or if forwarding information serves the public interest (cf. section II, 5.)
  • insofar as external service providers process your data on our behalf as contracted data processors or function providers
  • on the basis of our legitimate interest or the legitimate interest of the third party for the purposes mentioned under II, 3
  • if you have given us your consent for transferring to third parties

We will not forward your data to third parties for any other reason. If we commission service providers within the scope of order processing, your data will be subject to the same security standards by them as by us. In other cases, the recipients may use the data only for the purposes for which these were transmitted to them.


III. Visit our website


1. General information on using the website

In the case of merely informative use of the website, i.e. if you do not register or otherwise provide us with information, we will only collect the following personal data that your browser transmits to our server, which is technically necessary for us to display our website and to ensure its stability and safety: IP address, date and time of the request, Greenwich Mean Time (GMT), time zone difference, request content (concrete page), access status / HTTP status code, amount of data transferred, the website that receives the request, browser, operating system and its interface as well as language and version of the browser software. The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. f) GDPR. Our legitimate interest in the sense of this standard lies in the provision of a functional website. The personal data will be deleted as soon as the purpose of the storage is omitted.


2. Contracted data processors

As part of the operation of this website and related processes, we may be assisted by other service providers (for example, web hosting and web development) who work for us as contracted processors. These service providers are strictly bound by instructions and contractually obliged to us.


3. Cookies

We use cookies on our site. These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our site. In the cookie is stored information resulting from the connection with the specific terminal used. However, this does not mean that we are immediately aware of your identity.

On the one hand, the use of cookies serves to make the use of our offer more pleasant for you. For example, we use so-called session cookies to recognise that you have already visited individual pages on our website. These are automatically deleted after leaving our page.

On the other hand, we use cookies in order to statistically record the use of our website and to evaluate it for the purpose of optimising our offer (see Section 4 "Web tracking: MATOMO (PIWIK)“). These cookies allow us to automatically recognise when you visit our site again, that you have already visit us previously. These cookies are automatically deleted after a defined time.

In addition, we use cookies for the provision of certain services that are stored on your device for a certain period of time.

Our legitimate interest within the meaning of Art. 6 para. 1 sentence 1 lit. f) GDPR consists in providing and optimising our services.

Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or always a hint appears before a new cookie is created. However, disabling cookies completely may mean that you cannot use all features of our website.


4. Webtracking: Matomo (Piwik)

We use the web tracking tool "Matomo" (formerly "Piwik"), an open-source software for the statistical analysis of visitor access. Matomo uses for the analysis of the use of the website cookies, which are stored on your computer. The usage information generated by the cookie is transmitted and stored onto our server for the purpose of optimising our online offer. An evaluation of IP address data is carried out in any case only in abbreviated / anonymised form, so that a personal reference is excluded. Regarding the nature, extent and functionality of cookies in general, we refer to the general cookie explanation above.

The legal basis for the processing of personal data using Matomo is Art. 6 (1) sentence 1 lit. f) GDPR. Our legitimate interest in the sense of this standard is to provide a user-friendly and optimised website.

In the sense of an opt-out, you can decide whether a web analytics cookie for Matomo may be stored in your browser, in order to enable us to collect and analyse various statistical data provided by Matomo.

This places a so-called deactivation cookie in your browser. Please note that the Matomo deactivation cookie of this website will also be deleted if you remove the cookies stored in your browser. In addition, if you're using another computer or web browser, you'll need to go through the deactivation process again.


5. Web fonts

On our website, so-called web fonts from Adobe Typekit are used for the uniform display of certain fonts. The provider is Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe).

The browser loads the required fonts directly from Adobe when the respective pages are opened, so that they can be displayed correctly. In doing so, the browser connects to the servers of Adobe in the USA. This way, Adobe is notified that our website has been accessed via your IP address. According to Adobe, no cookies are stored when the fonts are provided.
Adobe has joined the EU-US Privacy Shield. For further information, please visit:

We use typekit in the interest of a correct presentation of the website. Therefore, the use is based on a legitimate interest in the sense of art. 6 par. 1 letter f of the GDPR. For more information about Adobe Typekit Web Fonts, please visit:






1. Communication and contact form

On our website, we offer you various ways to contact us and send us messages. Contact is in particular carried out by means of a phone, e-mail or via the provided contact form which can be used for electronic contact. As far as you agree to this, the data entered in the input mask will be transmitted to us and stored. At the time of sending the completed contact form, the following data will also be stored: IP address of the calling computer, date and time of sending. Alternatively, contact via the provided e-mail address or by phone is also possible. In this case, your personal data transmitted by e-mail or by phone will be stored.

The data is used exclusively for processing the conversation. The legal basis for the processing of the data is Art. 6 para. 1 sentence 1 lit. f) GDPR. If the establishment of contact aims at concluding a contract, then additional legal basis for the processing is Art. 6 para. 1 p.1 lit. b) of GDPR. The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems. This is also our legitimate interest.

The personal data transmitted to us in case of a contact made will be deleted if the respective conversation with you is over and the storage of the data is no longer necessary. 



We are happy to inform you about your rights under the GDPR as "data subject". You have the following rights regarding your personal data:

  • Right to Information (Art. 15 para. 1, 2 GDPR)
  • Right to Correction (Art. 16 GDPR) or Deletion (Art. 17 GDPR)
  • Right to Restriction of processing (Art. 18 GDPR)
  • Right to Data Portability (Art. 20 GDPR)
  • Right to Objection to data processing (Art. 21 GDPR)
  • Right to Withdrawal (Art. 7 para. 3 GDPR)
  • Right to appeal to a supervisory authority (Art. 77 GDPR)

In addition, we summarise here the key points of the data subject rights under the GDPR as follows, although this description does not claim to be exhaustive, but merely addresses the main features of the data subjects under the GDPR provisions:


- Right to information (including the rights to confirmation and to data provision)

The data subject has the right to ask the person responsible for its presumable data processing for a confirmation of the processing of the personal data concerned.

The data subject has the right to access personal data concerning him or her and the following related information: 

  • the processing purposes;
  • the categories of personal data being processed;
  • the recipients or categories of recipients to whom the personal data have been disclosed or are still being disclosed, in particular to recipients in third countries or to international organisations;
  • if possible, the planned duration for which the personal data are stored or, if this is not possible, the criteria for determining that duration;
  • the existence of a right to rectification or erasure of the personal data concerning them, or to the restriction of processing by the controller or a right to object to such processing;
  • the existence of a right of appeal to a supervisory authority;
  • if the personal data are not collected from the data subject, all available information on the source of the data;
  • the existence of automated decision-making including profiling under Article 22 (1) and (4) GDPR and - at least in these cases - meaningful information about the logic involved, and the scope and intended impact of such processing on the data subject;
  • if personal data are transmitted to a third country or to an international organisation, to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.

The data subject has the right to provide a copy of the personal data with regard to the personal data relating to him or her that is the subject of a data processing.  


- Right to rectification

The data subject has the right to demand from the person responsible without delay the correction of incorrect personal data concerning him. In consideration of the purposes of the processing, the data subject has the right to request the completion of incomplete personal data, including by means of a supplementary statement.


- Right to restriction of processing

The data subject has the right to require the controller to restrict the processing if one of the following conditions is met: 

  • the accuracy of the personal data is disputed by the data subject for a period allowing the controller to verify the accuracy of the personal data;
  • the processing is unlawful and the data subject refuses to delete the personal data and instead requests the restriction of the use of the personal data;
  • the controller no longer needs the personal data for the purposes of the processing, but the data subject requires them to assert, exercise or defend legal claims; or
  • the data subject has lodged an objection to the processing pursuant to Art. 21 (1) GDPR, as long as it is not certain that the legitimate reasons of the person responsible outweigh those of the data subject.


- Right to deletion

In principle and subject to the statutory necessity of data processing (see, for example, Art. 17 (3) GDPR), the data subject has the right to demand that the data subject's personal data be deleted immediately if one of the following reasons applies: 

  • The personal data are no longer necessary for the purposes for which they were collected or otherwise processed.
  • The data subject revokes their consent to the processing pursuant to Art. 6 para. 1 sentence 1 lit. a or Art. 9 para. 2 lit. GDPR and there is no other legal basis for processing.
  • According to Art. 21 (1) GDPR, the data subject objects to the processing of his or her personal data and there are no legitimate reasons for such processing, or the data subject objects to the processing according to rights pursuant to Art. 21 (2) GDPR.
  • The personal data were processed unlawfully.
  • The erasure of personal data is necessary to fulfil a legal obligation under the European Union law or a national law to which the data controller is subject.
  • The personal data were collected in relation to information society services offered pursuant to Art. 8 (1) GDPR.


- Right to data portability

The data subject has the right to receive personal data relating to him or her which were prior provided to a data controller, in a structured, common and machine-readable format. S/he has the right to request the transfer of that information to another person, without interference from the data controller having being prior provided with such data, subject to the fact that the respective data processing is based on a consent or on a contract pursuant to Art. 6 (1) sentence 1 lit. b GDPR and the data processing is carried out using automated procedures.

In exercising the right to data portability, the data subject has the right to obtain the personal data to be transferred directly from one controller to another, where this is technically feasible. 


- Right to objection

The data subject has the right to revoke any consent granted, at any time. The revocation of the consent does not affect the legality of the processing carried out on the basis of the consent given, until the revocation.


- Right of appeal to a supervisory authority

Any data subject shall have the right to complain to a supervisory authority, in particular in the Member State of his or her residence, place of work or place of alleged infringement, if the data subject considers that the processing of personal data concerning him/her violates this Regulation.

The data protection supervisory authority responsible for us is:  
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf


- Separate reference to the right of objection pursuant to Art. 21 para. 1, 2 GDPR

For reasons arising from your particular situation, you have the right, at any time, to object against the Processing of personal data related to you, which was carried out pursuant to Art. 6 para. 1 lit. e or f GDPR. This also applies to profiling based on these provisions. If you object, your personal data will no longer be processed, unless we can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms of the data subject, or the processing is carried out for the purposes of asserting, exercising or defending legal claims.

If personal data is processed in order to operate Direct mail activities, you have the right to object at any time against the processing of your personal data for the purpose of such advertising; this also applies to profiling, insofar as it is associated with such direct mail activities. 



For questions about the processing of personal data and for asserting the stipulations under para. IV., please contact our data protection officer:

METTEN Stein+Design GmbH & Co. KG

Industriegebiet Hammermühle
51491 Overath
Phone: 02206 / 603-0
Telefax: 02206 / 603-80