Privacy Notice for the Implementation of Gira's Vulnerability Management Program (Coordinated Vunerability Disclosure)
Juli 2026
We, Gira Giersiepen GmbH & Co. KG, hereby inform you about the processing of your personal data in connection with the implementation of Gira’s vulnerability management program (Coordinated Vulnerability Disclosure). Your personal data is processed exclusively in accordance with the applicable provisions of data protection law, in particular the General Data Protection Regulation (hereinafter “GDPR”) and the Federal Data Protection Act (“BDSG”).
I. Who is responsible for Data Processing, and who is the Data Protection Officer?
1. The entity responsible for processing your personal data is:
Gira Giersiepen GmbH & Co. KG
Dahlienstr. 12
42477 Radevormwald
Germany
Tel.: +49 2195-6020
info@gira.de
2. You can contact our data protection officer as follows:
Dr. Gregor Scheja
Scheja und Partners GmbH &Co. KG
Adenauerallee 136
53113 Bonn
Germany
Tel.: (+49) 0228-227 226 0
https://scheja-partners.de/kontakt/
www.scheja-partners.de
II. What Is the scope of Data Protection?
Data protection applies to personal data. This refers to any information relating to an identified or identifiable natural person (known as a “data subject”). This includes, for example, information such as name, mailing address, email address, or phone number.
III. Which of my personal data are being processed?
As part of GIRA’s vulnerability management (Coordinated Vulnerability Disclosure) program, we process only the personal data we collect from you that is related to this program. Specifically, this may include:
Name (optional)
E-Mail-Adress
Organization/Company (optional)
In addition, we generate server log files and collect the following information:
IP-adress
calling URL
registration time
IV. What are the purposes of processing my personal data, and on what legal basis is this processing carried out?
Below, we provide an overview of the purposes and legal bases for processing your personal data in connection with the implementation of GIRA’s vulnerability management program (Coordinated Vulnerability Disclosure):
1. Compliance with legal obligations
We process your personal data to comply with our legal obligations, which arise in particular from the Cyber Resilience Act (CRA). The purposes of the processing are determined by the respective legal obligation.
Data processing in this regard is based on Article 6 (1) (c) of the GDPR.
We will delete the data once the legal obligation to retain it no longer applies, provided that no other legal grounds - in particular, statutory or contractual retention periods - apply.
2. Processing to Protect Legitimate Interests
We process server log files to protect our legitimate interests. We process your personal data only if, after balancing our interests in carrying out the processing against your potentially conflicting interests, fundamental rights, and freedoms, we determine that our interests prevail. This may apply in the following cases:
Protection and security of our IT resources
Our legitimate interests in this regard lie in pursuing the aforementioned purposes.
Data processing is carried out on the basis of Article 6 (1) (f) of the GDPR.
We delete the data when it is no longer necessary for the purposes we pursue and no other legal basis applies.
V. Is my personal information also collected by third parties?
We process only the personal data that we receive directly from you.
VI. Is automated decision-making or profiling used?
We do not use automated decision-making or profiling as defined in Article 22 of the GDPR.
VII. Do I have to provide my personal data?
As part of the GIRA vulnerability management process (Coordinated Vulnerability Disclosure), you are not required to provide any additional personal data, with the exception of server log files; you may also submit a vulnerability report anonymously. If you do not submit a vulnerability report anonymously but instead provide us with personal data (e.g., your email address), we will use this data exclusively in connection with your vulnerability report (for example, to inform you of the current status or to request further information regarding your report).
VIII. Who has access to my personal data, and who receives it?
Within our company, access to your personal data is limited to those departments and their employees who absolutely need such access to perform their duties or tasks. This includes the GIRA PSIRT team, which is responsible for handling vulnerability reports.
We will only disclose your personal data to external recipients if there is a legal basis for doing so or if you have given your consent. External recipients may include:
Data Processors: Service providers entrusted with the provision and/or maintenance of our IT systems. We carefully select and regularly review these data processors to ensure that your personal data is processed lawfully. These service providers may process your personal data solely for the purposes specified by us.
Public authorities: Government agencies and institutions, such as public prosecutors’ offices, courts, or government agencies, to which we may need to disclose personal data in a individual case.
IX. Is there an intention to transfer my personal data to third countries?
As part of GIRA’s vulnerability management process (Coordinated Vulnerability Disclosure), your personal data will not be transferred to entities whose headquarters or data processing location is not situated in a member state of the European Union or in another signatory state to the Agreement on the European Economic Area.
X. How long will my personal data be stored?
For information on how long your personal data will be retained, please refer to the relevant section on data processing under Section IV.
XI. What rights do I have as a data subject?
You have the following rights regarding the processing of your personal data:
1. Right of access to personal data
You have the right to receive confirmation from us as to whether or not we are processing personal data about you. If we are, you have the right to access your personal data and to receive further information regarding its processing.
2. Right to rectification
You have the right to request the correction of your inaccurate personal data and to have incomplete personal data completed.
3. Right to erasure („right to be forgotten“)
Under certain circumstances, you have the right to request that we delete your personal data. This right applies, for example, if the personal data is no longer necessary for the purposes for which it was collected or otherwise processed, or if the personal data has been processed unlawfully.
4. Right to restriction of processing
Under certain circumstances, you have the right to request that we restrict the processing of your personal data. In this case, we will only store the personal data for which you have given consent or for which the GDPR permits processing. For example, you may have the right to restrict processing if you have contested the accuracy of your personal data.
5. Right to data portability
If you have provided us with personal data based on a contract or your consent, you may, provided the legal requirements are met, request to receive the personal data you have provided in a structured, commonly used, and machine-readable format, or request that we transfer it to another data controller.
6. Right to withdrawal the consent
If you have given us your consent to process your personal data, you may revoke that consent at any time with future effect. The lawfulness of the processing of your personal data up until the time of revocation remains unaffected.
7. Right to object
RIGHT TO OBJECT IN INDIVIDUAL CASES
YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU THAT IS CARRIED OUT PURSUANT TO ARTICLE 6 (1) (F) OF THE GDPR (DATA PROCESSING BASED ON A BALANCING OF INTERESTS). IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.
8. Right to file a complaint with the Supervisory Authority
In addition, you have the right to file a complaint with the competent supervisory authority if you believe that the processing of your personal data violates applicable law. To do so, you may contact the data protection authority responsible for your place of residence, workplace, or the location of an alleged violation, or the data protection authority responsible for us (State Commissioner for Data Protection and Freedom of Information in North Rhine-Westphalia).
XII. Who can I contact if I have questions or wish to exercise my rights as a data subject?
If you have any questions regarding the processing of your personal data or wish to exercise your rights as a data subject as set forth in Section XI, Nos. 1 through 7, you may contact us free of charge. Please use the contact information provided in Section I. To withdraw your consent, you may also use the same method of contact that you used when you provided your consent.