Privacy Notice

1. Introduction

It is important to us to protect your personal data during handling throughout the entire business process. In the following, we explain what personal data DHL Global Forwarding Management GmbH (‘DHL’) collects when you visit ESP website/app and how this data is processed and for what specific purposes.

2. What is personal data?

Personal data means any information relating to an identified or identifiable natural person ('data subject'). This includes information such as your real name, address, telephone number and date of birth. Information which cannot be linked to your real identity a number of users of a site is not considered personal data.

3. Who is responsible?

This Privacy Notice applies for the data processing carried out by:

DHL Global Forwarding Management GmbH
Johanniterstr. 1
53113 Bonn

Data Protection Officer of Controller; contact details:
Deutsche Post AG
Global Data Protection
53250 Bonn

If you have queries with regard to the processing of your personal data, please contact:
dataprotectionDGFF@dhl.com

4. What are the purposes of and the legal basis for the processing of personal data?

4.1. ESP Website

a) Information that you submit

The purpose of the ESP web portal is to provide an electronic interface to our suppliers. Information that you submit to us, for providing, ordering or receiving a service (e.g. electronic recording of consignee's signature, AWB numbers, addresses etc.), will be processed by DHL and will be used exclusively for the provision of DHL's service. DHL does not collect and process Customer or Shipment Information except when specifically, voluntarily and knowingly provided by you. The legal basis for the processing of this data is the performance of a contract according to Art. 6 (1) (b) GDPR.

b) Visiting ESP website

When you visit ESP website, our web servers temporarily save the connection data of the computer connecting to our site to guarantee security and a smooth connection setup. These connection data include: a list of the web pages that you visit within our site; the date and duration of your visit; the IP address of your device; the identification data of the type of browser and operation system used as well as the website through which you linked to our site. Additional personal information such as your name, address, telephone number or e-mail address is not collected unless you provide this data voluntarily, e.g. as part of a registration or an information request. The legal basis for the processing of the aforementioned data categories is Art. 6 (1) (f) GDPR. The data will be stored for a period of 7 days and then automatically deleted.

c) Cookies

We are using cookies. "Cookies" are small files that enable us to store information related to your device and you, the user, while you visit ESP website. We are using strictly necessary "session cookies" which process a Session-ID during a session in order to enable you to move around the website and use its features. Without these cookies, services you have asked for cannot be provided. These cookies are stored exclusively for the duration of your visit to our internet pages. They are automatically deleted when you close your browser. The legal basis for the use of strictly necessary cookies is legitimate interests according to Art. 6 (1) (f) GDPR.

Cookie Name Purpose
Session Cookie ESP_AntiXsrfToken To protect against XSRF attacks
Session Cookie ESP_Language For upholding user language

d) User account

For creating your user account you need first to register. In the registration form you will need to enter your company email, email code, mobile number, SMS code, company, password, access code. For logging your email and password will be requested. The legal basis for the processing of this data is performance of a contract according to Art. 6 (1) (b) GDPR.

4.2. ESP app

a) Information that you submit

ESP app is a shipment tool for carriers to receive shipment milestones e.g. signature-on-glass from customers/consignees for proof of delivery (POD) and other transportation related events. Information that you submit to us, for providing, ordering or receiving a service (e.g. electronic recording of consignee's signature, AWB numbers, addresses etc.), will be processed by DHL and will be used exclusively for the provision of DHL's service. DHL does not collect and process personal information except when specifically, voluntarily and knowingly provided by you. The legal basis for the processing of this data is the performance of a contract according to Art. 6 (1) (b) GDPR. DHL may also process location data (i.e. GPS milestones only), when voluntarily provided by you. The processing of such personal data is based on legitimate interest and is necessary for optimization and facilitation of pick-up and delivery functions according to Art. 6 (1) (f) GDPR.

b) Visiting ESP app

When you visit ESP app, our web servers temporarily save the connection data of the device connecting to our app to guarantee security and a smooth connection setup. These connection data include: the date and duration of your visit; the IP address of your device; the identification data of the type of browser and operation system used. Additional personal information such as your name, address, telephone number or e-mail address is not collected unless you provide this data voluntarily, e.g. as part of a registration or an information request.

The legal basis for the processing of the aforementioned data categories is Art. 6 (1) (f) GDPR. The data will be stored for a period of 7 days and then automatically deleted.

c) Cookies

We are using cookies. "Cookies" are small files that enable us to store information related to your device and you, the user, while you visit ESP app. We are using strictly necessary "session cookies" which process a Session-ID during a session in order to enable you to move around the app and use its features. Without these cookies, services you have asked for cannot be provided. These cookies are stored exclusively for the duration of your visit. They are automatically deleted when you close the app. The legal basis for the use of strictly necessary cookies is legitimate interests according to Art. 6 (1) (f) GDPR.

Cookie Name Purpose
Session Cookie ESP_AntiXsrfToken To protect against XSRF attacks
Session Cookie ESP_Language For upholding user language

d) User account

For using ESP app you need first to download the ESP app and to register with user name and password. Only authorized users can use the ESP app. When using the ESP app we will collect a device identifier for authorization purposes. The legal basis for the processing of this data is performance of a contract according to Art. 6 (1) (b) GDPR.

5. Will my data be passed on to third parties?

DHL does not share, sell, transfer or otherwise disseminate your personal data to third parties and will not do so in future, unless required by law, unless required for the purpose of the contract or unless you have given explicit consent to do so. External service providers that process data on our behalf are contractually obliged to maintain strict confidentiality. DHL retains responsibility for safeguarding your information in such circumstances. The service providers follow the instructions of DHL and this is guaranteed by technical and organizational measures, as well as by means of checks and controls.

6. When will my personal data be deleted?

We will keep your data for as long as necessary to fulfill our purposes, to execute our contracts and to comply with any legal obligation. The retention period may differ per country based on applicable country laws. We continuously strive to minimize the retention period of data where the purpose, the law or contracts allows us to do so. The data that we collect based on your consent will be kept until you withdraw your consent.

7. What is the DHL Group Data Privacy Policy?

The DHL Group Data Privacy Policy regulates the Group-wide standards for data processing with a special focus on so-called third country transfers, meaning transfers of personal data to countries outside the EU, which do not have an adequate level of data protection. If you are interested in learning more about the DHL Group Data Privacy Policy, please use the following link: DHL Group Privacy Policy.

8. What are my data subject’s rights?

8.1. Overview

You have the following rights:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf
Germany

8.2. Right to object

The right to object applies for all processing of personal data which is based on Art. 6 (1) f) GDPR. To exercise your right, simply get in touch with us by using the contact details mentioned above.

9. Changes to Privacy Notice

We keep our Privacy Notice under regular review. DHL reserves the right to change its Privacy Notice at any time with or without prior notice. Please check back frequently to be informed of any changes.

This statement was last updated on April 2024.