Privacy
Privacy Policy
How WiBa handles enquiries, website data and your privacy choices.
1. Who is responsible
WiBa GmbH is responsible for the processing described in this privacy policy.
WiBa GmbH
Im Nettelfelde 17
29690 Lindwedel
Germany
Email: sales@wiba-parts.com
Contact us at this address for privacy questions and to exercise your rights. This policy covers wiba-parts.com, enquiries submitted through our website, and the associated communication and measurement services. It was updated on 13 September 2026.
2. Your choices and the information we process
You can use our website and send a spare-parts, equipment or other enquiry without accepting optional analytics or advertising cookies. Fields marked as required are needed to handle the selected request; other information is voluntary. If essential contact or request information is missing, we may be unable to answer or prepare a quotation. Please do not include sensitive personal information that is unnecessary for your enquiry.
We process information you provide, such as your name, business contact details, company, delivery location, machine and part details, and messages. Our website and its service providers also receive technical data, such as IP address, browser and device information, requested pages, times, and security or error information. If you permit the relevant measurement, we additionally process interaction events, campaign and click identifiers, and conversion-matching information.
Accepting analytics or advertising is separate from sending an enquiry. Refusing these purposes does not reduce the service we offer in response to your request. Refusal does not prevent the technical processing required to deliver and protect the website or the limited Google signals explained in section 7.
3. Purposes and legal bases
We use the following legal bases under the General Data Protection Regulation (GDPR):
Article 6(1)(b): processing needed to take steps at your request before a contract or to perform a contract, including preparing and handling a quotation or order.
Article 6(1)(f): our legitimate interests in answering business enquiries, communicating with company representatives, operating and securing the website, preventing automated abuse, and maintaining evidence needed to establish or defend legal claims. The specific interests in consent-state management and limited measurement are explained below. You can object to processing based on legitimate interests as described in section 15.
Article 6(1)(a): your consent for optional analytics, advertising measurement, conversion matching, advertising fraud analysis, and third-party video players. You may withdraw consent at any time.
Article 6(1)(c): compliance with applicable legal obligations, including required business and tax records and data-protection accountability.
For storing information on, or accessing information from, your device, we request consent under section 25(1) of Germany's TDDDG where required. The exception in section 25(2) applies only where the operation is necessary for transmission or strictly necessary to provide a service you expressly request. A service's label in the cookie panel does not itself change these legal requirements.
4. Enquiries, email, WhatsApp and Salesforce
We use your request and contact information to identify the required part or equipment, clarify specifications, prepare a quotation, arrange the next steps and respond to you. Our staff and Salesforce, our customer-relationship-management provider, process this information in the enquiry workflow. Relevant information may also be handled by our communication and technical service providers. Information needed to fulfil an order may be shared with the suppliers, delivery partners or professional advisers involved in that order.
When you deliberately select an email or WhatsApp contact link, we may create a contact reference in Salesforce and add it to the prepared message so that we can associate the conversation with your request. A browser-session reference supports this function. A click does not necessarily mean that you sent a message or placed an order. With advertising consent, campaign information may accompany the contact reference; without that consent, our website does not add its optional campaign and click-attribution fields to the request.
Opening WhatsApp connects you to that service. In the European Economic Area, it is provided by WhatsApp Ireland Limited. WhatsApp processes account, connection and communication-related information under its own privacy information. You can instead use the website form or email. Your chosen email provider also processes messages you send.
Our enquiry processing relies on Article 6(1)(b) GDPR for contractual requests and Article 6(1)(f) for other business correspondence and contact with company representatives. Advertising matching requires separate consent; we do not make it a condition of receiving a reply.
Salesforce privacy information:
https://www.salesforce.com/company/legal/privacy/
WhatsApp privacy information:
https://www.whatsapp.com/legal/privacy-policy-eea
5. Website delivery, Cloudflare and Sanity
Cloudflare delivers our website and runs its server-side request handling. It receives the technical information necessary to deliver pages, route form requests and protect the service, including IP addresses, requested URLs, browser/network information and request times. Form submissions pass through this infrastructure on their way to our enquiry system.
We manage website content in Sanity. Public pages are generated from that content before delivery, and images are delivered by Sanity's content delivery network. Requesting an image therefore shares technical connection information with the content-delivery service. Ordinary page viewing does not sign you into our Sanity editorial application or require you to use the Sanity editor.
This processing serves website delivery, stability and security under Article 6(1)(f) GDPR and, for handling your contractual enquiry, Article 6(1)(b). Technical records are kept according to the operational, security and incident-investigation needs described in section 14.
Cloudflare privacy information:
https://www.cloudflare.com/policies/privacy/
Sanity privacy information:
https://www.sanity.io/legal/privacy
6. CookieYes and browser storage
CookieYes Limited provides our consent panel. It presents the available categories, records your choices and helps us apply them. This involves a consent identifier, the selected categories, the time of the choice and technical information needed to provide and document that choice. CookieYes states that it stores IP addresses in masked form. Remembering your selection is necessary to provide the preference-management function. Documenting consent also supports our accountability obligations under Article 6(1)(c) GDPR; providing and respecting the preference service serves our legitimate interest under Article 6(1)(f).
Use Cookie settings in the footer to accept, reject or change optional purposes. Withdrawal affects future consent-based processing and does not make earlier processing unlawful. Your browser can also delete or block cookies and website storage. Deleting the preference cookie may cause the banner to ask you again.
Cookies are not the only storage involved. With advertising consent, the website uses local storage and session storage to remember the first and most recent campaign visits. The persistent attribution entry has a 90-day expiry refreshed when a permitted visit is captured. Our application removes these attribution entries on refusal or withdrawal. Session storage also holds short-lived measurement-deduplication entries and the functional email/WhatsApp contact references described above; session storage follows the lifetime of the browser tab/session.
The cookie panel lists detected cookies, their purposes and stated durations. A browser cookie's lifetime is different from the time that a provider retains records already received. Section 14 describes the latter. To ensure that a previously loaded third-party page script is no longer running after a change, reload the page after saving your new choice.
CookieYes privacy and processing information:
https://www.cookieyes.com/privacy-policy/
https://www.cookieyes.com/dpa/
7. Google Analytics, Tag Manager and Consent Mode
We use Google Analytics 4 to understand website visits, navigation, interaction and form use. Google Tag Manager controls the deployment of measurement tags; it is not itself a substitute for the analytics and advertising services. Google services may involve Google Ireland Limited and Google LLC in the United States.
With analytics consent, measurement can use browser identifiers and information about pages, interactions, device/browser characteristics, approximate location and traffic sources. We use it to understand use of the site, identify problems and improve the enquiry experience. This optional analytics processing relies on Article 6(1)(a) GDPR.
Our Google tags use advanced Consent Mode. They load with storage and advertising-data consent denied by default and adapt to your choice. When storage consent is denied, Google can still receive limited cookieless signals, including consent status, page or event information, time, browser headers and referrer information, for aggregate measurement and modelling. Network requests necessarily expose connection information to the recipient. Refusing cookies therefore does not mean that no request reaches Google, and cookieless does not automatically mean anonymous.
For transmitting the consent state and limited cookieless measurement signals, we rely on Article 6(1)(f) GDPR: our interests in applying visitors' choices, understanding aggregate use and advertising effectiveness, and avoiding persistent identification when permission is absent. Our website does not attach enhanced-conversion contact details to a denied marketing event. The right to object to legitimate-interest processing is explained in section 15.
Google's explanation of information received from websites:
https://policies.google.com/technologies/partner-sites
Google Consent Mode:
https://developers.google.com/tag-platform/security/concepts/consent-mode
Google privacy information:
https://policies.google.com/privacy
8. Google Ads and enhanced conversions
With advertising consent, we use Google Ads conversion measurement to understand which advertisements lead to contact and submitted enquiries and to improve campaign delivery. This can involve campaign parameters, Google click identifiers, visited pages, conversion type and time, and a transaction or event reference used to avoid duplicate counting.
After a successful form submission, enhanced conversions can use the email address, telephone number, name, country and postal code you supplied for matching an enquiry to an advertising interaction. The Google tag handles supported matching identifiers using one-way hashing before transmission for enhanced-conversion matching. Hashes remain personal data where they can be matched; they are not anonymous. The free-text description of the requested part is not an enhanced-conversion identifier.
This matching and consented advertising measurement rely on Article 6(1)(a) GDPR. You can withdraw advertising consent through Cookie settings. Google can process information further under its own applicable terms and privacy information, including for advertising measurement and, where permitted by your choices, personalisation.
Enhanced-conversion information:
https://support.google.com/google-ads/answer/9888656
Google advertising information:
https://policies.google.com/technologies/ads
9. Meta Pixel and Conversions API
With advertising consent, we use Meta Pixel and Meta Conversions API to measure website activity and the effectiveness of Facebook and Instagram advertising. Events can be delivered by the browser and by server-side integrations, including our Cloudflare Worker. Meta receives this data; for people in the European Economic Area, the relevant Meta entity is Meta Platforms Ireland Limited, with processing also involving Meta group infrastructure outside the EEA.
The information can include pages and interactions, event type and time, campaign/click and browser identifiers, IP address, browser information, and an event reference. When an enquiry is successfully created, our Worker can send email and telephone identifiers after one-way hashing for matching. Browser advanced matching can also use contact identifiers supplied in the form. Hashing does not make the information anonymous. A shared event identifier helps Meta recognise browser and server copies of the same submitted enquiry.
We use the reports to evaluate advertising and improve delivery to relevant audiences. Meta may associate events with a Meta account and use them for measurement, advertising and other purposes described in its privacy information. Our collection and transmission for these optional purposes rely on Article 6(1)(a) GDPR. Sending an enquiry does not require this consent.
For the collection and transmission of Business Tool event data covered by Meta's Controller Addendum, WiBa and Meta have joint-controller responsibilities; Meta's subsequent processing is governed by its applicable terms. You can exercise your rights with us or with Meta. Meta's addendum explains the allocation of responsibilities, including its contact point for rights relating to data held by Meta.
Meta privacy information and Business Tools terms:
https://www.facebook.com/privacy/policy/
https://www.facebook.com/legal/terms/businesstools
Meta Controller Addendum:
https://www.facebook.com/legal/controller_addendum
10. Microsoft Clarity
With analytics consent, Microsoft Clarity, provided by Microsoft Corporation and its affiliates, records how the website is used through interaction measurements, heatmaps and session replay. It can process page and referral information, browser/device characteristics, approximate location, timing, clicks, scrolling, navigation, errors and a representation of the displayed page. We use these records to investigate usability and performance problems and improve the website. Session replay is a reconstruction of website interactions, not a recording from your camera or microphone.
Clarity uses cookies and other identifiers for its service. Our integration starts it after analytics consent and stops it when that consent is withdrawn. Microsoft can also use data for service improvement, security and, where advertising permission applies, advertising purposes under its privacy statement. Our optional analytics processing is based on Article 6(1)(a) GDPR. Advertising-related storage is signalled separately according to your advertising choice.
Microsoft states that ordinary playback data is retained for 30 days; labelled or favourited sessions and heatmap/click data are retained for 9 months. These are Clarity's published retention periods, not the retention period for your enquiry in Salesforce.
Microsoft privacy information:
https://www.microsoft.com/en-us/privacy/privacystatement
Clarity retention information:
https://learn.microsoft.com/en-us/clarity/setup-and-installation/data-retention
11. ClickCease advertising-fraud protection
With advertising consent, we load ClickCease, provided by CHEQ, to identify invalid or automated advertising traffic and protect our advertising budget. Its browser technology can process IP addresses, advertising click and visit information, browser/device characteristics, device fingerprints and interaction/session-recording information. A fingerprint combines device and browser characteristics to help distinguish repeat or suspicious traffic; it is not a physical fingerprint.
We use the results to investigate suspicious visits and reduce invalid advertising clicks, including through advertising-platform exclusion or blocking functions. This optional website tracking is based on Article 6(1)(a) GDPR and is separate from the security checks required to send the contact form. ClickCease identifies its provider as CHEQ AI Technologies (2018) Ltd, based in Israel, and describes processing for customer websites under its customer data-processing terms.
Withdrawing advertising consent prevents our website from starting ClickCease on later page loads. Because a third-party script already loaded in the current page can remain active, reload the page after withdrawing consent to end that page's script execution. The privacy choice does not prevent you from sending an enquiry.
ClickCease privacy information:
https://www.clickcease.com/privacy.html
CHEQ processing information:
https://support.clickcease.com/hc/en-us/articles/16111797774865-CHEQ-s-GDPR-and-CCPA-Ready
12. Google reCAPTCHA and automated-abuse protection
Pages containing our enquiry forms load Google reCAPTCHA to help distinguish genuine requests from automated abuse. Its script can receive technical and interaction information when the form page is opened, before the final submission. When you submit, it provides a token and risk assessment that our server checks before accepting the request. Google identifies the _GRECAPTCHA cookie as part of its risk-analysis function; requests to Google's domain can also involve existing Google cookies.
We use this protection under Article 6(1)(f) GDPR to keep the enquiry service available, prevent spam and protect our systems. Optional advertising consent is not required to submit the form, but the security verification must succeed. If verification fails, you can retry or contact us by email. The security score can prevent an automated submission; it does not decide whether we will sell to you or the terms of a quotation. You can ask our team to handle your enquiry directly.
This site is protected by reCAPTCHA. Google's Privacy Policy and Terms of Service apply:
https://policies.google.com/privacy
https://policies.google.com/terms
13. Optional video players and external links
Some brand pages offer YouTube or Vimeo videos. The external player loads only after advertising consent and an explicit play action. Until then, the page uses a poster image delivered with the site content. Starting playback sends the selected video, page and technical connection information to the provider and may allow the provider to use cookies or other identifiers. YouTube uses the privacy-enhanced embed hostname; this does not make playback anonymous. We rely on Article 6(1)(a) GDPR for loading these optional players.
The relevant providers are Google/YouTube and Vimeo.com, Inc. Their processing, account association and retention are described in their own privacy information. Withdrawing the required consent removes the embedded player. An external Google Maps link opens Google's service only when selected. Links to third-party websites or communication apps are governed by those providers' privacy information once you follow them.
YouTube/Google privacy information:
https://policies.google.com/privacy
Vimeo privacy information:
https://vimeo.com/privacy
14. Retention, recipients and international processing
We keep enquiry and communication records for the time needed to respond, clarify requirements, maintain the resulting business relationship and handle follow-up requests. If they become contract, invoice or other legally relevant records, applicable business/tax retention duties and the period needed to establish, exercise or defend legal claims determine longer retention. Records needed only for a concluded enquiry should not be kept indefinitely merely because a CRM can store them. The applicable criteria are the request's status, continuing business need, legal obligations and outstanding disputes.
Technical and security records are retained for service operation, incident investigation and abuse prevention, taking account of whether an issue is ongoing and whether evidence is needed. Consent records are retained to apply and demonstrate the recorded choice and to resolve consent-related questions or claims. Browser storage expires or is removed as explained in section 6 and the cookie panel. Clarity periods are listed in section 10.
For other analytics, conversion and fraud-analysis records, retention depends on the provider's service and account retention controls, the reporting or fraud-investigation purpose, consent withdrawal/deletion requests and legal requirements. Browser-cookie expiry does not itself delete a record already held by Google, Meta, CHEQ or another provider. Their linked privacy information explains their own retention criteria and controls. Contact us if you need the applicable period or deletion status for a particular enquiry or identifiable record.
Recipients include our authorised staff and the hosting, content-delivery, customer-management, communication, consent, security, analytics, advertising and media providers described in this policy. Providers processing on our behalf are subject to the applicable data-processing terms. Providers may separately process data for purposes for which they are responsible under their own privacy information. We may disclose information when required by law or where necessary for legal claims.
These services use international infrastructure and support. Processing can take place outside the EEA, including in the United States, the United Kingdom and Israel. An EEA-facing provider entity does not guarantee that all processing stays in the EEA. The European Commission recognises the UK and Israel as providing adequate protection, and its US adequacy decision applies only to participating organisations within the scope of the EU–US Data Privacy Framework. Where no applicable adequacy decision covers a transfer, the relevant provider arrangements use safeguards such as the European Commission's standard contractual clauses or approved binding corporate rules. These measures do not mean that foreign laws and access powers are identical to those in the EEA.
The providers publish information on their processing and transfer safeguards. You can request information or a copy of the safeguards relevant to your data from us at sales@wiba-parts.com. The links below provide the published frameworks; the mechanism applicable to a particular service depends on its terms and the recipient.
Cloudflare:
https://www.cloudflare.com/cloudflare-customer-scc/
Sanity:
https://www.sanity.io/legal/dpa
Salesforce:
https://www.salesforce.com/company/legal/privacy/privacy-overview/
CookieYes:
https://www.cookieyes.com/dpa/
European Commission adequacy decisions:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
15. Your privacy rights
Subject to the conditions in the GDPR, you may request access to your personal data, correction of inaccurate information, erasure, restriction of processing and a portable copy of data you supplied where processing is based on consent or contract and carried out automatically. We may need proportionate information to verify a request. Some records cannot be erased immediately where a legal retention duty or another lawful exception applies.
You may withdraw consent at any time through Cookie settings or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal. It does not end processing that has a separate legal basis, such as handling your requested quotation or retaining legally required business records.
Right to object: where we rely on Article 6(1)(f) GDPR, you may object for reasons relating to your particular situation. We must then stop that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or need it for legal claims. You may object at any time to processing for direct marketing, including related profiling; we will stop that use.
We do not use the website's analytics or advertising profiles to make a solely automated decision about you with legal or similarly significant effects. Automated form-abuse screening is explained in section 12, including the alternative of contacting a person.
To exercise your rights, email sales@wiba-parts.com or write to WiBa GmbH at the address in section 1. You also have the right to complain to a data-protection supervisory authority, in particular in the place of your habitual residence, work or the alleged infringement. Our local authority is the Lower Saxony Commissioner for Data Protection (Der Landesbeauftragte für den Datenschutz Niedersachsen). Its complaint and contact information is available here:
https://www.lfd.niedersachsen.de/startseite/