Privacy Policy & Data Protection Statement
This Privacy Policy governs the processing of personal data collected through the DoorHan global B2B digital portal (doorhan.com). It outlines our strict adherence to the General Data Protection Regulation (EU) 2016/679 (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and international industrial data security frameworks.
01 Data Controllers & Scope of Policy
The entity responsible for the processing of personal data (the "Data Controller") on this portal depends on the territorial origin of your inquiry and the specific commercial relationship:
This policy applies to all visitors, commercial customers, certified dealers, architectural designers, and industrial contractors who access or use doorhan.com.
02 Fundamental Principles of Processing
DoorHan adheres strictly to the principles established under Article 5 of Regulation (EU) 2016/679 (GDPR):
- Lawfulness, Fairness, and Transparency: Data is processed legitimately, transparently, and in good faith toward the data subject.
- Purpose Limitation: Information is collected exclusively for specified, explicit, and legitimate B2B engineering and contractual purposes.
- Data Minimization: We collect only the minimum data strictly necessary to fulfill technical, supply, and support inquiries.
- Accuracy: Reasonable measures are taken to ensure personal data is kept up to date and rectified without delay.
- Storage Limitation: Data is preserved no longer than required for the operational and legal fulfillment of corporate duties.
- Integrity and Confidentiality: Data is protected against unauthorized access, accidental loss, disclosure, or cyber threats using multi-tiered technical safeguards.
03 Categories of Personal Data Collected
Depending on how you interact with our portal, we collect and process the following categories of information:
A. Information You Provide Directly to Us:
- Contact Information: First and last name, business email address, direct telephone number, country, and postal jurisdiction.
- Corporate & B2B Data: Company name, industrial sector, architectural role, VAT/tax identification number (where applicable).
- Engineering & Inquiry Details: Object specifications, opening dimensions, requested product configurations (industrial doors, dock levelers, automated gate operators), blueprints, and project notes submitted via contact forms.
B. Information Collected Automatically (Technical Telemetry):
- Network Identifiers: IP address (pseudonymized in web server logs for DDoS mitigation), requested URL path, date and precise timestamp of access.
- Device & Browser Telemetry: Browser type and version, language preference, operating system architecture, HTTP response status code, and volume of transmitted bytes.
DoorHan does NOT collect, request, or process any special categories of sensitive personal data (e.g., genetic, biometric, political, health, or financial account credentials) via this portal.
04 Legal Grounds for Processing (GDPR Art. 6)
Under European and global data protection regulations, every processing activity must have a recognized legal basis:
- Performance of a Contract or Pre-Contractual Steps (Art. 6(1)(b) GDPR): Processing is necessary to deliver formal price calculations, technical BIM/CAD specs, dealer applications, or direct commercial contracts upon your request.
- Legitimate Commercial Interests (Art. 6(1)(f) GDPR): To protect corporate digital infrastructure against cyber attacks, ensure continuous server uptime, optimize industrial catalog rendering, and maintain enterprise B2B partner relationships.
- Compliance with Statutory Legal Obligations (Art. 6(1)(c) GDPR): To fulfill national and EU commercial, taxation, export control, and warranty compliance standards.
- Consent (Art. 6(1)(a) GDPR): Where you have explicitly granted opt-in consent for optional non-essential preferences or direct marketing updates.
05 Purposes of Data Processing
We process your information exclusively for specific, declared operational goals:
- Processing and answering incoming engineering, architectural, and commercial inquiries.
- Routing dealer and installer partnership applications to the designated regional manufacturing hub (Kadaň or Suzhou).
- Providing authorized CAD/BIM drawings, structural calculation sheets, and European CE / ISO certificates.
- Preventing denial-of-service (DDoS) events, brute-force exploits, and unauthorized server modifications.
- Monitoring anonymous aggregate portal usage to enhance industrial navigation usability.
06 Cookies & Local Storage Policy
Our portal uses minimal, strictly necessary cookies and local storage tokens to ensure secure, rapid browsing and anti-tampering protection:
| Token / Name | Category | Lifespan | Purpose & Description |
|---|---|---|---|
SITE_SESSID |
Strictly Necessary | Session | Maintains secure HTTP session integrity and handles CSRF (Cross-Site Request Forgery) anti-tampering verification for form submissions. |
cookie_consent_accepted |
Functional (LocalStorage) | 12 Months / Persistent | Stores your explicit confirmation of our cookie notification banner to prevent redundant popups on subsequent page loads. |
Browser-Level Cookie Control:
You may configure, disable, or delete cookies at any time directly through your web browser preferences (Chrome, Safari, Firefox, Microsoft Edge). Please note that disabling strictly necessary cookies may impair form submission security and interactive catalog features.
07 International Data Transfers & Cross-Border Safeguards
DoorHan maintains global production hubs in the European Union (Czech Republic) and Asia (China). Whenever personal data is transferred across borders between our entities, we enforce rigorous legal and technical safeguards in full compliance with Chapter V of the GDPR:
- Standard Contractual Clauses (SCCs): Transfers outside the European Economic Area (EEA) are governed by the European Commission approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), ensuring recipients guarantee an equivalent standard of data protection.
- Technical Encryption: All cross-border data in transit is encrypted using 256-bit TLS/SSL protocols.
- Access Restrictions: Internal enterprise systems permit data visibility exclusively to authorized engineering and logistics personnel.
08 Data Retention Periods
In accordance with the principle of storage limitation, personal data is retained only for the duration necessary to satisfy the purposes for which it was gathered:
- Commercial & Dealer Inquiries: Retained for the active duration of the business engagement or up to three (3) years from the date of the last verified communication.
- Statutory Commercial & Accounting Records: Where an inquiry results in a binding commercial invoice or contract, relevant documentation is retained for up to ten (10) years in accordance with Czech Act on Accounting and EU tax regulations.
- Technical Server Access Logs: Automatically cycled and securely deleted within ninety (90) days, unless flagged for ongoing cybersecurity investigation.
09 Your Statutory Rights (GDPR & CCPA)
Under the General Data Protection Regulation (EU) and international data privacy regulations, you possess comprehensive rights concerning your personal data:
- Right of Access (Art. 15 GDPR): You have the right to request confirmation as to whether your data is being processed and obtain a copy of such data.
- Right to Rectification (Art. 16 GDPR): You may request the immediate correction of inaccurate or incomplete information.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You may request the deletion of your personal data when it is no longer required for the original purpose or when you withdraw consent.
- Right to Restriction of Processing (Art. 18 GDPR): You have the right to limit the scope of processing under specific legal conditions.
- Right to Data Portability (Art. 20 GDPR): You may receive your data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON).
- Right to Object (Art. 21 GDPR): You may object at any time to processing grounded on legitimate interests.
Notice of No Sale: DoorHan does NOT sell, rent, disclose, or trade personal data to third parties for monetary or commercial advertising value. Under California law, residents have the right to request deletion, disclosure of data categories collected, and non-discriminatory service.
Right to Lodge a Complaint: If you believe our processing infringes data protection legislation, you have the right to file a formal complaint with the competent supervisory authority:
Úřad pro ochranu osobních údajů (ÚOOÚ) — Pplk. Sochora 27, 170 00 Praha 7, Czech Republic | Web: uoou.gov.cz.
10 Technical & Organizational Security Measures
DoorHan applies enterprise-grade cybersecurity controls to protect personal and commercial data against unauthorized access, loss, or disclosure:
- End-to-End Encryption: Mandatory 256-bit TLS/HTTPS cryptographic protocol with HSTS (HTTP Strict Transport Security) across all domain routes.
- CSRF & Input Sanitization: Cryptographic anti-forgery tokens validate all feedback requests; automated filters neutralize SQL injection and XSS exploits.
- Hardened Server Headers: Implementation of X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, and secure session cookie flags.
- Role-Based Access Control (RBAC): Strict compartmentalization restricting customer inquiry visibility strictly to authorized personnel.
11 Contact Information & Data Protection Inquiries
To exercise any of your statutory rights, submit questions regarding this Privacy Policy, or request data rectification or erasure, please contact our Data Protection Officer (DPO) directly:
Notice: In compliance with Article 12(3) of the GDPR, all formal data subject inquiries are acknowledged promptly and resolved free of charge within thirty (30) calendar days.