of HÖRMANN Intralogistics Solutions GmbH
Our Trust Center—your gateway to all information regarding information security, data protection, quality management, and compliance at HÖRMANN Intralogistics.
Information security
At HÖRMANN Intralogistics, we protect your data and our systems through a comprehensive information security management system (ISMS).
Our measures:
ISMS & Organization
- ISMS established: An information security management system is implemented and continuously improved.
- Information Security Officer: An ISO is appointed and responsible for the operational implementation of information security.
- Risk management: Information security risks are systematically identified, assessed, and mitigated through appropriate measures.
- Continuous improvement: Management is committed to ongoing development of the ISMS.
- Regular internal audits: Compliance with security policies is verified through planned internal audits.
- Vulnerability scans: Our IT infrastructure is regularly scanned for vulnerabilities.
- Threat monitoring: We continuously monitor current threats and adapt our protective measures accordingly.
Classification & Access Control
- Information classification: All information is classified according to security levels and protected accordingly.
- Need-to-know principle: Access to data is granted only to authorized individuals.
- Personalized user accounts: Each user account is uniquely assigned to an individual—shared accounts are avoided.
- Rights management: Access rights are regularly reviewed and adjusted immediately upon departure or job change.
- Privileged account protection: Administrator accounts are subject to enhanced security measures.
- Separate administrator accounts: Administrators use separate accounts for administrative tasks.
- Multi-factor authentication: We implement multi-factor authentication for confidential cloud applications.
- Secure password policy: Passwords must meet complex requirements and are renewed regularly.
- Account lockout: User accounts are automatically locked after multiple failed attempts.
Encryption & Data Protection
- Encryption: Confidential data is protected using current encryption standards.
- Key sovereignty: HÖRMANN Intralogistics retains full control over cryptographic key material.
- End-to-end encryption: Confidential emails are transmitted with end-to-end encryption.
- Mobile device encryption: All notebooks and mobile data carriers are encrypted.
- Special protection for sensitive data: Data with very high protection requirements is stored in encrypted containers with multi-stage authentication.
Network & Infrastructure
- Network segmentation: Our network is divided into security zones to prevent unauthorized access.
- Secure communication: We use only approved and secure communication and sharing platforms.
- VPN requirement: VPN connection is mandatory when using public or unsecured networks.
- Web filter: Malicious and suspicious websites are blocked by technical filters.
Operational Security
- Malware protection: Multi-layered protection systems, regular updates, and phishing awareness secure our systems.
- Patch management: Security updates are promptly evaluated and deployed to close known vulnerabilities.
- Software and online service approval process: New software and online services undergo an internal review and approval process before use.
- Change management: Changes to IT systems are planned, reviewed for security risks, and documented.
- Fallback solutions: For critical changes, fallback solutions are defined to ensure availability.
- Separate environments: Development, test, and production environments are physically separated.
Data Backup & Recovery
- Geo-redundant backup: Backups are stored at two physically separate locations.
- Encrypted backups: Our data backups are stored in encrypted form.
- Regular restore testing: The recoverability of backups is tested on a regular basis.
Physical Security & Workplace
- Access controls: Our facilities are secured through electronic and physical access controls.
- Security zones: Our company premises are divided into security zones with graduated access permissions.
- Access logging: Entry to secured areas is electronically logged.
- Visitor management: Visitors are registered at reception and accompanied in sensitive areas.
- Clean desk policy: Sensitive information is protected from unauthorized access—both physically and digitally.
- Secure handling of data carriers: Mobile data carriers are encrypted, issued with documentation, and securely disposed of.
Mobile Work & Travel
- Secure mobile work: Home office and mobile work are subject to the same security standards as office work.
- Travel protection: When traveling to security-sensitive countries, enhanced protective measures apply to devices and data.
- Remote deletion: In case of loss or theft of mobile devices, data can be deleted remotely.
Software Development
- Security by design: Information security is considered during the planning phase of projects.
- Secure software development: Security requirements are incorporated in all phases of the development cycle.
- Quality assurance through testing: Software undergoes defined test phases before deployment.
Incident Management
- Reporting channels for security incidents: Defined reporting channels exist for information security incidents.
- Response times: Response times are defined for processing security incidents.
- Incident management: Security incidents are reported immediately and handled according to defined processes.
- Incident documentation: All security incidents are fully documented and tracked.
- Lessons learned: Following security incidents, findings are documented and improvement measures are derived.
Emergency & Crisis Management
- Business Continuity Management: A BCM system protects time-critical business processes and minimizes the impact of emergencies.
- Emergency plans: Emergency plans are defined for various scenarios (power outages, fires, IT outages, cyberattacks).
- Regular emergency drills: The effectiveness of emergency plans is tested through regular exercises.
- Disaster Recovery: A disaster recovery plan ensures restoration in case of emergency.
AI & Other Matters
- Responsible AI use: Reviewed AI applications, trained employees, data protection-compliant processing.
- Controlled external communication: Only authorized individuals communicate on behalf of the company on social media.
- Protection of intellectual property: Confidential information and intellectual property are protected.
Training
- Training: All employees complete regular mandatory training on information security.
Data protection
Protection of your personal data is a matter of course for us. We process data exclusively on the basis of valid legal regulations.
Our measures:
- Data Protection Officer: We have appointed an external data protection officer.
- Lawful processing: Personal data is processed only on the basis of valid legal grounds or with consent.
- Contractual safeguards: We conclude data processing agreements (DPA) or other required data protection contracts with service providers.
- Rights of data subjects: Requests for information, correction, or deletion are processed promptly.
- Incident management: Data protection incidents are reported and handled within statutory deadlines.
- Deletion concept: Personal data is regularly deleted and documented after the retention period has expired.
- Records of processing activities: We maintain a register of all processing activities in accordance with Article 30 GDPR.
- Data Protection Impact Assessment: For high-risk processing, we conduct a Data Protection Impact Assessment (DPIA) in advance.
- Obligation to data confidentiality: All employees are bound by the obligation to maintain data confidentiality.
- Documented deletion processes: Deletion procedures are documented to ensure traceability of data deletion.
- Secure data destruction: Physical data carriers are destroyed by certified service providers in accordance with the security levels of DIN 66399.
- Annual review: Retention periods and purposes are reviewed at least once per year.
- Privacy by Default: Privacy-friendly default settings are standard in our systems and processes.
- Data processing in the EEA: Cloud services with data processing outside the European Economic Area are subject to special review.
- Special categories of personal data: Particularly sensitive personal data (e.g., health data) are subject to enhanced protective measures and must not be stored in the cloud.
- Training: All employees receive regular data protection training.
Contact: For data protection inquiries or to exercise your rights as a data subject: Email: datenschutz@hoermann-logistik.de
For the complete privacy policy: Privacy Policy | HÖRMANN Intralogistics
QM & Compliance
We act responsibly, maintain the highest quality standards in our work, and comply with all applicable laws and internal guidelines.
Quality Management
- Continuous improvement: We continuously optimize our processes according to the ISO 9001 standard.
- Customer orientation: The satisfaction of our customers is at the center of our actions.
- Process orientation: Defined and documented processes ensure consistently high quality.
- Quality awareness: We promote quality awareness among our employees through training, information, and the exemplary conduct of management.
- Regular review: Our quality policy is reviewed regularly and adjusted as needed to reflect changed circumstances.
Business Partners & Integrity
- Business partner screening: Potential partners are screened for integrity.
- Compliance due diligence: Critical business partners undergo an integrity assessment before contract conclusion.
- Regular review: Business partner approvals are renewed every two years.
- Ongoing monitoring: During the business relationship, we watch for warning signals and conduct reassessments as needed.
- Four-eyes principle: Contracts are reviewed and signed according to the four-eyes principle.
- Know Your Customer (KYC): We identify and verify our business partners before entering into a business relationship.
- No anonymous transactions: We do not accept anonymous payments or transactions without adequate identity verification.
- Risk-based monitoring: We continuously monitor business relationships and watch for warning signals.
- Remediation before termination: We support business partners in remedying violations before we terminate business relationships.
Suppliers & Service Providers
- Security requirements for suppliers: Service providers must meet defined information security requirements.
- Supplier evaluation: Suppliers are evaluated and monitored based on their risk potential.
- Certification review: For critical suppliers, we verify certifications (e.g., ISO 27001, TISAX).
- Audit rights: We reserve the right to audit suppliers for information security compliance.
- Supplier reporting obligation: Suppliers are obligated to report security incidents immediately.
- Confidentiality agreements: External partners and service providers are bound by confidentiality agreements (NDA).
- Cloud security: Cloud providers must provide valid ISO 27001 certification or comparable evidence.
- Exit strategy: When switching cloud providers, secure data migration and deletion are ensured.
Anti-Corruption & Competition
- Corruption prevention: Corruption and bribery are not tolerated in any form.
- Gift policy: We do not accept gifts that could influence decisions.
- Transparency in benefits: Gifts and invitations are accepted or granted only within socially acceptable limits.
- Fair competition: We strictly comply with all competition and antitrust laws and do not participate in anticompetitive agreements.
- No price fixing: We do not exchange competition-relevant information such as prices, terms, or calculations with competitors.
- Transparency in tenders: In tender procedures, we act independently and without agreements with competitors.
Export Control & Anti-Money Laundering
- Export control: In cross-border transactions, we verify goods, recipients, destination countries, and end use.
- Embargo and sanctions list screening: Business partners and destination countries are screened against current sanctions lists.
- Trained export officers: Employees in the export field receive regular training and continuing education.
- Anti-money laundering: We do not tolerate money laundering or terrorism financing and watch for suspicious transactions.
Human Rights & Social Responsibility
- Respect for human rights: We are committed to the UN Guiding Principles on Business and Human Rights and ILO core labor standards.
- Supply chain due diligence: We conduct risk analyses in our supply chain and implement prevention and remediation measures in accordance with the LkSG.
- Human rights officer: We have appointed a human rights officer who oversees risk management.
- Prohibition of child labor and forced labor: Child labor and forced labor are not tolerated in any form.
- Freedom of association: We respect the right to collective bargaining and union representation.
- Fair working conditions: We ensure fair compensation and compliance with statutory working hours.
- Diversity and inclusion: We promote diversity and do not tolerate discrimination.
- Workplace safety: We take measures to protect the physical and mental integrity of our employees.
Environment & Sustainability
- Environmental responsibility: We are guided by the principles of sustainability and promote environmentally friendly practices.
- Climate targets: We aim to reduce Scope 1 and Scope 2 emissions by 42% by 2030 (base year 2022) and achieve climate neutrality by 2045.
- Resource conservation: We use resources responsibly and minimize water and energy consumption.
- Animal welfare: We expect compliance with all animal welfare regulations.
Personnel
- Obligation to confidentiality: All employees are bound by the obligation to maintain confidentiality.
- Security screening upon hiring: Employees for sensitive areas undergo a suitability assessment in compliance with data protection regulations.
Whistleblower System & Other Matters
- Whistleblower system: Violations can also be reported anonymously through an external ombudsperson.
- Whistleblower protection: Employees who report violations are protected from retaliation.
- Avoidance of conflicts of interest: Private interests are strictly separated from business decisions.
- Financial integrity: Business records and financial reports are kept complete, accurate, and truthful.
- Training: All employees complete regular compliance training.
- For the whistleblower system: https://www.hoermann-gruppe.com/beschwerdemanagement
Software & Services
At HÖRMANN Intralogistics, we maintain the highest standards for the quality and security of our software solutions—even after handover to the customer.
Software Updates in Productive Systems:
- Customer approval prior to updates: Software updates are performed exclusively after prior notification and written customer consent.
- Timely notification: Customers receive a detailed announcement before each update including date, content, duration, and planned test scenarios.
- Quality assurance prior to deployment: Every update undergoes internal testing and is validated in a test environment before being deployed to the production system.
- Staging concept: Updates are first deployed to the customer’s test system, validated by the customer, and only transferred to the production system after written approval.
- Fallback planning: Prior to each update, a fallback scenario is defined to ensure a safe return to the previous state in case of error.
- Joint acceptance: After a successful update, we conduct functional tests jointly with the customer.
- No weekend updates: Software updates are generally not performed on Fridays or weekends to minimize risks.
Technical Documentation:
- Complete customer documentation: Customers receive complete technical documentation including operating manuals, maintenance instructions, drawings, and declarations of conformity.
- Documentation in local language: Documentation is provided in the contractually agreed language versions.
- Secure handover: Digital documentation is handed over encrypted (e.g., on encrypted USB storage media with separate password transmission).
- Structured filing: Documentation follows a uniform, clear structure for quick access.
Occupational Health and Safety
The primary objective of occupational health and safety is to minimize risks for our employees, external partners, and third parties. We create a safe and healthy working environment—both at our facilities and on construction sites and customer installations.
Organization & Responsibilities:
- Occupational safety organization: An occupational safety committee (OSC) meets regularly and addresses important occupational health and safety topics.
- Occupational safety specialist: We have appointed occupational safety specialists who support us in implementing occupational safety measures.
- Safety officers and first aiders: Trained safety officers and certified first aiders are designated at all locations.
- Occupational health services: Our employees have access to occupational health services.
- Occupational health screening: For activities with special hazards (e.g., work at great heights), suitability is ensured through occupational health screening.
Prevention & Hazard Assessment:
- Hazard assessments: We regularly conduct hazard assessments and derive protective measures from them.
- STOP principle: In hazard minimization, we follow the recognized STOP principle (Substitution, Technical Measures, Organizational Measures, Personal Protective Equipment).
- Ergonomic workplace design: Workplaces are set up in accordance with recognized safety and occupational health standards.
- Physical and mental health: We promote a working environment that is healthy from both a physical and mental perspective.
Personal Protective Equipment (PPE):
- PPE requirement: On construction sites, safety helmets, safety shoes, and high-visibility vests are generally mandatory.
- Enhanced protective equipment: For special hazards, additional protective equipment (e.g., fall arrest harnesses, hearing protection, eye protection) is used.
- CE-marked work equipment: Only tested and CE-marked work equipment and protective equipment are used.
Construction Sites & Customer Installations:
- Mandatory site rules: All construction sites are subject to mandatory site rules with clear safety regulations.
- Safety requirements for subcontractors: Subcontractors and external contractors must also comply with our safety standards and provide hazard analyses.
- Safety briefings: All employees and external partners receive a briefing before work begins. Briefings are documented.
- Coordination on multi-trade sites: When multiple trades work simultaneously, close coordination is conducted through regular coordination meetings.
- Access restrictions for hazardous areas: Access to hazardous areas (e.g., automated systems) is permitted only for authorized and trained personnel.
- Approval requirement for work in hazardous areas: Work in hazardous areas requires written approval and registration with responsible personnel.
- Supervision requirement for hazardous work: Work on hazardous systems may only be performed in the presence and supervision of qualified personnel.
- Alcohol and drug prohibition: A strict alcohol and drug prohibition applies at all construction sites.
Fire and Environmental Protection:
- Fire protection: Preventive fire protection measures, regular maintenance of fire protection systems, and training on behavior in case of fire are established.
- Hot work permit: Welding and cutting work in fire-hazard areas requires a written hot work permit.
- Safe handling of hazardous substances: Hazardous substances are handled, stored, and disposed of safely. Safety data sheets and operating instructions are available to all employees.
- Environmental protection: We ensure proper waste disposal, noise minimization, and water protection on all construction sites.
Emergency Preparedness:
- Emergency plans: Emergency plans are prepared and accessible for all locations and construction sites.
- Regular emergency drills: Response capability is tested through regular exercises.
- Evacuation and rescue routes: Evacuation and rescue routes as well as assembly points are marked and kept clear.
- First aid equipment: Emergency equipment is regularly checked for usability and replaced as needed.
Training & Reporting Obligations:
- Regular safety briefings: All employees receive regular safety briefings.
- Obligation to report hazards: Employees are obligated to immediately report identified hazards, deficiencies, and safety incidents.
- Accident reporting: Work accidents and incidents are reported immediately and documented.
Sanctions:
- Consequences for violations: Persons may be removed from the construction site for gross violations of safety regulations.
Certifications & Standards
Our measures in the areas of information security, data protection, and quality management are confirmed by independent certifications.
You can download the certificates here: Certifications » for the highest quality and the best competence