Privacy Policy in technical language
Privacy Policy in technical language
Introduction
The following privacy policy is intended to inform you about the types of personal data (hereinafter also referred to simply as “data”) that we process, the purposes for which we do so, and the extent of such processing. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online platforms, such as our social media profiles (hereinafter collectively referred to as the “online offering”).
As at: 15 July 2021
Data controller
ASA-FF e.V.
Zietenstraße 2A, 09130 Chemnitz
Email address: gruendungsgarage@asa-ff.de
You can find more information in the legal notice.
Overview of data processing
The following overview summarises the types of data processed and the purposes for which they are processed and identifies the data subjects.
Types of data processed
Master data (e.g. names, addresses).
Applicant data (e.g. personal details, postal and contact addresses, the documents forming part of the application and the information contained therein, such as cover letters, CVs, certificates and other information relating a specific vacancy or voluntarily provided by applicants regarding their personal details or qualifications).
Content data (e.g. entries in online forms).
Contact details (e.g. email address, telephone numbers).
Meta/communication data (e.g. device information, IP addresses).
Usage data (e.g. websites visited, interest in content, times of access).
Contract details (e.g. subject matter of the contract, term, customer category).
Payment details (e.g. bank details, invoices, payment history).
Categories of data subjects
Applicants.
Business and contractual partners.
Prospective applicants.
Communication partners.
Members.
Users (e.g. website visitors, users of online services).
Purposes of processing
Provision of our online services and user-friendliness.
Recruitment procedure (reasons for, and any subsequent implementation of, the procedure, as well as the possible subsequent termination of the employment relationship).
Office and organisational procedures.
Direct marketing (e.g. by email or post).
Feedback (e.g. collecting feedback via an online form).
Marketing.
Enquiries and communication.
Profiles containing user-related information (creation of user profiles).
Safety measures.
Provision of contractual services and customer service.
Managing and responding to enquiries.
Relevant legal bases
Below is an overview of the legal bases under the GDPR on which we process personal data . Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours, depending on where you or we are resident or have our registered office. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.
Consent (Article 6(1), first sentence, point (a) of the GDPR) - The data subject has given their consent to the processing of their personal data for a specific purpose or for several specific purposes.
Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) - The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
Legal obligation (Article 6(1), first sentence, point (c) of the GDPR) - The processing is necessary for the fulfilment of a legal obligation to which the controller is subject.
Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR) - The processing is necessary to safeguard the legitimate interests of the controller or a third party, unless the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, take precedence.
The recruitment process as a pre-contractual or contractual relationship (Article 9(2)(b) of the GDPR) - Where, as part of the recruitment process, special categories of personal data within the meaning of Article 9(1) of the GDPR (e.g. health data, such as severe disability status or ethnic origin) are requested from applicants so that the controller or the data subject may exercise their rights arising from employment law and the law on social security and social protection and fulfil their respective obligations in this regard, such data shall be processed in accordance with Article 9(2) (b) of the GDPR; in the case of the protection of the vital interests of applicants or other individuals, in accordance with Article 9(2) (c) of the GDPR; or for the purposes of preventive healthcare or occupational medicine, for the assessment of an employee’s of the employee, for medical diagnosis, care or treatment in the health or social sector or for the administration of systems and services in the health or social sector in accordance with Article 9(2)(h) of the GDPR. Where special categories of data are provided on the basis of voluntary consent, their processing is carried out on the basis of Article 9(2)(a) of the GDPR.
National data protection regulations in Germany: In addition to the data protection provisions of the General Data Protection Regulation, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, it governs data processing for the purposes of the employment relationship (Section 26 BDSG), in particular with regard to the establishment, performance or termination of employment relationships as well as the consent of employees. In addition, state data protection laws of the individual federal states may apply.
Safety measures
We implement appropriate technical and organisational measures in accordance with the statutory requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, , as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and safeguarding of the availability of the data, and its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted and that appropriate action is taken in the event of a data breach . Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design, and through privacy-friendly default settings.
Truncation of the IP address: Where IP addresses are processed by us or by the service providers and technologies we use, and where the processing of a full IP address is not necessary, the IP address is truncated (also known as ‘IP masking’). In this process, the last two digits, or the last part of the IP address following a full stop, are removed or replaced with placeholders. The purpose of truncating the IP address is to prevent or make it significantly more difficult to identify a person on the basis of their IP address.
SSL encryption (https): To protect the data you submit via our online service, we use SSL encryption. You can recognise connections encrypted in this way by the prefix https:// in your browser’s address bar.
Transfer of personal data
As part of our processing of personal data, it may happen that the data is transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
Data transfer within the organisation: We may transfer personal data to other departments within our organisation or grant them access to such data. Where such disclosure is made for administrative purposes, it is based on our legitimate business and business interests, or where it is necessary to fulfil our contractual obligations, or where the data subjects have given their consent or there is a legal basis for doing so.
Data processing in third countries
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or where processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other individuals, bodies or organisations, this is done solely in accordance with the statutory requirements.
Subject to express consent or where the transfer is required by contract or by law, we shall process or allow the data to be processed only in third countries with a recognised level of data protection, subject to contractual obligations through the European Commission’s so-called standard data protection clauses, where certifications are in place, or in accordance with binding internal data protection regulations (Articles 44 to 49 of the GDPR, European Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).
Use of cookies
Cookies are text files that contain data from websites or domains visited and are stored by a browser on the user’s computer. A cookie is primarily used to store information about the user during or after their visit to an online service. The information stored may include, for example, language settings on a website, login status, a shopping basket or the point at which a video was being watched. We also include within the term ‘cookies’ other technologies that fulfil the same functions as cookies (e.g. where user data is stored using pseudonymous online identifiers, also known as ‘user IDs’)
A distinction is made between the following types and functions of cookies:
Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once users have left a website and closed their browser.
Persistent cookies: Persistent cookies remain stored even after the browser is closed. For example, this allows the login status to be saved or preferred content to be displayed immediately when users revisit a website. Similarly, users’ interests, which are used for audience measurement or marketing purposes, can be stored in such a cookie.
First-Party-Cookies: First-party cookies are set by us.
Third-party cookies (also known as third-party cookies): Third-party cookies are mainly used by advertisers (so-called third parties) to process user information.
Necessary (also: essential or strictly necessary) cookies: On the one hand, cookies may be absolutely essential for the operation of a website (e.g. to store logins or other user input, or for security reasons).
Statistics, marketing and personalisation cookies: Furthermore, cookies are generally also used in the context of audience measurement, as well as when users’ interests or behaviour (e.g. viewing certain content, using functions, etc.) on individual websites are stored in a user profile . Such profiles are used, for example, to display content to users that corresponds to their potential interests. This process is also referred to as ‘tracking’, i.e. the tracking of users’ potential interests . Where we use cookies or ‘tracking’ technologies, we will inform you separately in our privacy policy or when seeking your consent.
Notes on the legal basis: The legal basis on which we process your personal data using cookies depends on whether we ask for your consent. If this is the case and you consent to the use of cookies, the legal basis for the processing of your data is the consent you have given. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g. in the commercial operation of our online service and its improvement) or, where the use of cookies is necessary to fulfil our contractual obligations.
Retention period: Unless we provide you with specific information regarding the retention period of permanent cookies (e.g. as part of a so-called cookie opt-in), please assume that the retention period may be up to two years.
General information on withdrawal and opting out: Depending on whether the processing is carried out on the basis of consent or statutory authorisation, you have the option at any time to withdraw any consent you have given or to object to the processing of your data via cookie technologies (collectively referred to as ‘opt-out’). You can initially express your objection via your browser settings, for example, by disabling the use of cookies (although this may also restrict the functionality of our online service). An objection to the use of cookies for online marketing purposes can also be made via a variety of services, particularly in the case of tracking, via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/. In addition, you can find further information on how to object within the details provided regarding the service providers and cookies used.
Processing of cookie data on the basis of consent: We use a procedure for cookie consent management, under which users’ consent to the use of cookies, or to the processing activities and providers specified within the cookie consent management procedure, , and which can be managed and withdrawn by users. In this context, the declaration of consent is stored so that users do not have to be asked for consent again and so that consent can be demonstrated in accordance with the legal obligation. Storage may take place on the server and/or in a cookie (a so-called ‘opt-in’ cookie, or using comparable technologies) in order to be able to associate the user’s consent with their device. Subject to specific information provided by the providers of cookie management services, the following applies: Consent may be stored for up to two years. In this process, a pseudonymous user identifier is generated and stored together with the time of consent, details of the scope of the consent (e.g. which categories of cookies and/or service providers) as well as the browser, operating system and end device used.
Types of data processed: Usage data (e.g. websites visited, interest in content, times of access), Meta/communication data (e.g. device information, IP addresses).
People affected: User (e.g. website visitors, users of online services).
Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Performance of duties in accordance with the Articles of Association or Rules of Procedure
We process the data of our members, supporters, prospective members, business partners or other individuals (collectively, ‘data subjects’) when we have a membership or other business relationship and carry out our duties, or where they are recipients of services and grants. Furthermore, we process the data of data subjects on the basis of our legitimate interests, e.g. in the case of administrative tasks or public relations work.
The data processed in this context, the nature, scope and purpose of such processing, and the necessity thereof, are determined by the underlying membership or contractual relationship, from which the necessity any data to be provided (we will, incidentally, draw your attention to any data that is required).
We delete data that is no longer required for the fulfilment of our statutory and business purposes. This is determined in accordance with the respective tasks and contractual relationships. We retain the data for as long as it may be relevant for the conduct of business, as well as in respect of any warranty or liability obligations based on our legitimate interest in their resolution. The necessity of retaining the data is reviewed on a regular basis; in all other respects, the statutory retention obligations apply.
Types of data processed: Master data (e.g. names, addresses), payment data (e.g. bank details, invoices, payment history), contact details (e.g. email, telephone numbers), contract data (e.g. subject matter of the contract, term, customer category).
People affected: Users (e.g. website visitors, users of online services), members, business and contractual partners.
Purposes of processing: Provision of contractual services and customer service, contact enquiries and communication, administration and responding to enquiries.
Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Business services
We process data relating to our contractual and business partners, e.g. customers and prospective customers (collectively referred to as “contractual partners”) in the context of contractual and similar legal relationships, as well as related measures, and in the context of communication with contractual partners (or at a pre-contractual stage), e.g., to respond to enquiries.
We process this data to fulfil our contractual obligations, to safeguard our rights, and for the purposes of the administrative tasks associated with this information, as well as for business organisation. We only disclose the data of contractual partners to third parties, in accordance with applicable law, to the extent that this is necessary for the aforementioned purposes or to fulfil legal obligations, or where the data subjects have given their consent (e.g. to telecommunications, transport and other ancillary service providers, as well as subcontractors, banks, tax and legal advisers, payment service providers or tax authorities). Contracting parties will be informed about other forms of data processing, e.g. for marketing purposes, in this privacy policy.
We inform our contractual partners of the data required for the aforementioned purposes either before or during the data collection process, e.g. in online forms, by means of specific markings (e.g. colours) or symbols (e.g. asterisks or similar), or in person.
We delete the data once statutory warranty obligations and similar obligations have expired, i.e., in principle after a period of 4 years, unless the data is stored in a customer account, e.g., for as long as it must be retained for statutory archiving purposes (e.g. for tax purposes, usually 10 years). We delete data disclosed to us by the contracting party in the context of an assignment in accordance with the terms of the assignment, generally upon completion of the assignment.
Where we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms shall apply to the relationship between users and those providers.
Types of data processed: Master data (e.g. names, addresses), payment data (e.g. bank details, invoices, payment history), contact details (e.g. email, telephone numbers), contract data (e.g. subject matter of the contract, term, customer category).
People affected: Prospective customers, business partners and contractual partners.
Purposes of processing: Provision of contractual services and customer service, contact enquiries and communication, office and organisational procedures, administration and responding to enquiries.
Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), Legal obligation (Article 6(1), first sentence, point (c) of the GDPR), Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Provision of the online service and web hosting
In order to provide our online services securely and efficiently, we use the services of one or more web hosting providers, from whose servers (or servers managed by them) the online services can be accessed . For these purposes, we may make use of infrastructure and platform services, computing capacity, storage space and database services, as well as security and technical maintenance services.
The data processed in connection with the provision of the hosting service may include any information relating to users of our online service that is generated in the course of their use of the service and their communications. This typically includes the IP address, which is necessary to deliver the content of online services to browsers, and any data entered within our online service or on websites.
Email delivery and hosting: The web hosting services we use also include the sending, receiving and storage of emails. For these purposes, the addresses of the recipients and senders, as well as further information relating to the sending of emails (e.g. the providers involved) and the contents of the respective emails, are processed. The aforementioned data may also be processed for the purpose of detecting spam. Please note that emails are generally not sent in encrypted form over the internet. Although emails are usually encrypted during transmission, they are not stored on the servers from which they are sent and received (unless a so-called end-to-end encryption method is used) not on the servers from which they are sent and received . We are therefore unable to accept any responsibility for the transmission of emails between the senders and their receipt on our server.
Collection of access data and log files: We (or rather, our web hosting provider) collect data on every access to the server (so-called server log files). The server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, a record of whether the request was successful retrieval, browser type and version, the user’s operating system, the referrer URL (the page visited previously) and, as a rule, IP addresses and the requesting provider.
The server log files can be used, on the one hand, for security purposes, e.g. to prevent the servers from becoming overloaded (particularly in the event of malicious attacks, known as DDoS attacks) and, on the other hand, to ensure the servers’ performance and stability.
Types of data processed: Content data (e.g. information entered into online forms), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
People affected: User (e.g. website visitors, users of online services).
Purposes of processing: Provision of our online services and user-friendliness.
Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Services used and service providers:
STRATO: Services relating to the provision of IT infrastructure and associated services (e.g. storage space and/or computing capacity); Service provider: STRATO AG, Pascalstraße 10, 10587 Berlin, Germany; Website: https://www.strato.de; Privacy policy: https://www.strato.de/datenschutz.
Blogs and publication platforms
We use blogs or similar means of online communication and publication (hereinafter referred to as the ‘publication medium’). Readers’ data is processed for the purposes of the publication medium only to the extent that this is necessary for its presentation and for communication between authors and readers, or for security reasons. Furthermore, we refer you to the information regarding the processing of data relating to visitors to our publication medium as set out in this privacy policy.
Comments and posts: When users leave comments or other posts, their IP addresses may be stored on the basis of our legitimate interests. This is done for our own security in the event that anyone posts unlawful content in comments or posts (insults, prohibited political propaganda, etc.). In such cases, we ourselves may be held liable for the comment or post and are therefore interested in the identity of the authors.
Furthermore, we reserve the right, on the basis of our legitimate interests, to process users’ data for the purpose of spam detection.
On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for the duration of the survey and to use cookies to prevent multiple votes.
The personal information provided in comments and posts, including any contact details and website information, as well as the content of these posts, will be stored permanently by us until the user objects.
Types of data processed: Personal details (e.g. names, addresses), contact details (e.g. email addresses, telephone numbers), content data (e.g. entries in online forms), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
People affected: User (e.g. website visitors, users of online services).
Purposes of processing: Provision of contractual services and customer service, feedback (e.g. collecting feedback via an online form), security measures, administration and responding to enquiries.
Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Getting in touch
When you contact us (e.g. via the contact form, by email, telephone or social media), the details of the enquirer will be processed to the extent necessary to respond to the enquiry and to carry out any requested actions .
Responses to enquiries made in the context of contractual or pre-contractual relationships are provided in order to fulfil our contractual obligations or to respond to (pre-)contractual enquiries, and otherwise on the basis of our legitimate interests in responding to such enquiries.
Types of data processed: Personal details (e.g. names, addresses), contact details (e.g. email addresses, telephone numbers), content data (e.g. information entered in online forms).
People affected: Communications officer.
Purposes of processing: Enquiries and communication.
Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Video conferences, online meetings, webinars and screen sharing
We use platforms and applications provided by third parties (hereinafter referred to as “conference platforms”) for the purpose of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as “conferences”). When selecting conference platforms and their services, we comply with the relevant legal requirements.
Data processed by conference platforms: When participating in a conference, the conference platforms process the participants’ personal data listed below. The scope of the processing depends, on the one hand, on what data is required for a specific conference (e.g. provision of login details or real names) and which optional details are provided by participants. In addition to processing for the purpose of running the conference, participants’ data may also be processed by the conference platforms for security purposes or to optimise the service. The data processed includes personal details (first name, surname), contact details (email address, telephone number), login details (access codes or passwords), profile pictures, information on professional status/role, and the IP address of the internet connection.
Types of data processed: Personal details (e.g. names, addresses), contact details (e.g. email addresses, telephone numbers), content data (e.g. entries in online forms), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
People affected: Communication partner, user (e.g. website visitors, users of online services).
Purposes of processing: Provision of contractual services and customer service, enquiries and communication, office and organisational procedures.
Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR), performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Application process
The application process requires applicants to provide us with the information necessary for their assessment and selection. The information required is set out in the job description or, in the case of online forms, in the details provided there.
Generally speaking, the required details include personal information such as your name, address, contact details and evidence of the qualifications required for the post. We are also happy to provide further details on what information is required upon request.
Where available, applicants may submit their applications to us via an online form. The data is transmitted to us in encrypted form using state-of-the-art technology. Applicants may also submit their applications to us by email. However, please note that emails are generally not sent in encrypted form over the internet. Although emails are usually encrypted whilst in transit, they are not encrypted on the servers from which they are sent and received.
Types of data processed: Applicant data (e.g. personal details, postal and contact addresses, the documents accompanying the application and the information contained therein, such as a covering letter, CV, references, as well as any other information relating to a specific vacancy or provided voluntarily by applicants regarding their personal details or qualifications).
People affected: Applicant.
Purposes of processing: Recruitment procedure (reasons for, and any subsequent implementation of, as well as the possible subsequent termination of the employment relationship).
Legal basis: The recruitment process as a pre-contractual or contractual relationship (Article 9(2)(b) of the GDPR).
Newsletters and electronic notifications
We send out newsletters, emails and other electronic notifications (hereinafter “newsletters”) only with the consent of the recipients or where permitted by law. Where, as part of the newsletter subscription process, the content of the newsletter is specifically described, this forms the basis for the user’s consent. In addition, our newsletters contain information about our services and our organisation.
To subscribe to our newsletters, you generally only need to provide your email address. However, we may ask you to provide a name, so that we can address you personally in the newsletter, or further details, where these are necessary for the purposes of the newsletter.
Double opt-in procedure: Subscription to our newsletter is generally carried out via a so-called double opt-in procedure. This means that, after subscribing, you will receive an email asking you to confirm your subscription . This confirmation is necessary to ensure that nobody can subscribe using someone else’s email address. Subscriptions to the newsletter are logged so that we can provide evidence of the subscription process in accordance with legal requirements . This includes storing the time of registration and confirmation, as well as the IP address. Any changes to your data stored with the email service provider are also logged.
Erasure and restriction of processing: We may store the email addresses of users who have unsubscribed for up to three years on the basis of our legitimate interests, before deleting them, in order to be able to provide evidence of consent that was previously given . The processing of this data is limited to the purpose of potentially defending against claims . An individual request for erasure may be made at any time, provided that the former existence of consent is confirmed at the same time. In the event of obligations to permanently comply with objections, we reserve the right to store the email address solely for this purpose in a block list.
The registration process is logged on the basis of our legitimate interests for the purpose of providing evidence that it has been carried out correctly. Where we engage a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure email delivery system.
Notes on the legal basis: Newsletters are sent on the basis of the recipient’s consent or, where consent is not required, on the basis of our legitimate interests in direct marketing, provided that this is permitted by law, e.g. in the case of marketing to existing customers. Where we engage a service provider to send emails, this is done on the basis of our legitimate interests. The registration process is recorded on the basis of our legitimate interests, in order to demonstrate that it was carried out in accordance with the law.
Contents: Information about us, our services, promotions and special offers.
Types of data processed: Personal details (e.g. names, addresses), contact details (e.g. email addresses, telephone numbers), meta/communication data (e.g. device information, IP addresses), usage data (e.g. websites visited, interest in content, access times).
People affected: Communications officer.
Purposes of processing: Direct marketing (e.g. by email or post).
Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Right to object (opt-out): You can unsubscribe from our newsletter at any time, i.e. withdraw your consent or object to receiving further issues. You will find a link to unsubscribe from the newsletter either at the end of each newsletter, or you can use one of the contact options listed above, preferably by email, to do so.
Services used and service providers:
Mailchimp: email marketing platform; service provider: “Mailchimp” – Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA; website: https://mailchimp.com; Privacy policy: https://mailchimp.com/legal/privacy/; Standard contractual clauses as the basis for processing in the USA: https://mailchimp.com/legal/data-processing-addendum/; specific security measures: https://mailchimp.com/help/Mailchimp-european-data-transfers/.
Measuring open and click-through rates:
The newsletters contain a so-called ‘web beacon’, i.e. a pixel-sized file which, when the newsletter is opened, is retrieved from our server or, if we use a mailing service provider, from their server. As part of this retrieval, technical information – such as details about your browser and system – as well as your IP address and the time of retrieval, is collected.
This information is used to improve our newsletter from a technical perspective, based on technical data or target groups and their reading behaviour, as determined by their location (which can be identified using their IP address) or the times at which they access the newsletter . This analysis also includes determining whether the newsletters are opened, when they are opened and which
Types of data processed: Personal details (e.g. names, addresses), contact details (e.g. email addresses, telephone numbers), meta/communication data (e.g. device information, IP addresses), usage data (e.g. websites visited, interest in content, access times).
People affected: Communications officer.
Purposes of processing: Direct marketing (e.g. by email or post).
Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Right to object (opt-out): You can unsubscribe from our newsletter at any time, i.e. withdraw your consent or object to receiving further issues. You will find a link to unsubscribe from the newsletter either at the end of each newsletter, or you can use one of the contact options listed above, preferably by email, to do so.
Marketing communications via email, post, fax or telephone
We process personal data for the purposes of marketing communications, which may be carried out via various channels, such as email, telephone, post or fax, in accordance with the relevant legal requirements.
Recipients have the right to withdraw their consent at any time or to object to marketing communications at any time.
Following withdrawal or objection, we may store the data required to provide evidence of consent for up to three years on the basis of our legitimate interests before we delete it. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for erasure may be made at any time, provided that the prior existence of consent is confirmed at the same time.
Types of data processed: Personal details (e.g. names, addresses), contact details (e.g. email addresses, telephone numbers).
People affected: Communications officer.
Purposes of processing: Direct marketing (e.g. by email or post).
Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Online marketing
We process personal data for online marketing purposes, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as ‘content’) based on users’ potential interests, as well as the measurement of its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (known as a ‘cookie’) or similar methods are used to store the user’s details relevant to the display of the aforementioned content. This information may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical details such as the browser used, the computer system used, and information on usage times. Where users have consented to the collection of their location data, this may also be processed.
Users’ IP addresses are also stored. However, we use the available IP masking methods (i.e. pseudonymisation by truncating the IP address) to protect users. Generally, as part of online marketing procedures, no users’ plain data (such as email addresses or names) is stored, but rather pseudonyms. This means that neither we nor the providers of the online marketing services know the actual identity of the users, but only the information stored in their profiles.
The information contained in the profiles is usually stored in cookies or by means of similar methods. These cookies can generally also be read later on other websites that use the same online marketing method, analysed for the purpose of displaying content, supplemented with further data, and stored on the server of the online marketing provider.
In exceptional cases, clear data may be linked to profiles. This is the case, for example, when a user is a member of a social network whose online marketing methods we use, and the network links the user’s profiles to the aforementioned information. Please note that users may enter into additional agreements with the providers, for example by giving their consent during registration.
As a general rule, we only have access to aggregated information regarding the performance of our adverts. However, as part of what is known as conversion tracking, we can analyse which of our online marketing methods have led to a so-called conversion, i.e. for example, the conclusion of a contract with us. Conversion tracking is used solely to analyse the success of our marketing activities.
Unless otherwise stated, please assume that the cookies used will be stored for a period of two years.
Notes on the legal basis: Where we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is consent. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Types of data processed: Usage data (e.g. websites visited, interest in content, times of access), Meta/communication data (e.g. device information, IP addresses).
People affected: User (e.g. website visitors, users of online services).
Purposes of processing: Marketing, profiles containing user-related information (creation of user profiles).
Safety measures: IP masking (pseudonymisation of the IP address).
Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Right to object (opt-out): Please refer to the privacy notices of the respective providers and the opt-out options specified by them. If no explicit opt-out option has been specified, you do have the option of disabling cookies in the settings . However, this may restrict certain functions of our online service. We therefore also recommend the following opt-out options, which are summarised and tailored to the respective regions : a) Europe: https://www.youronlinechoices.eu. b) Canada: https://www.youradchoices.ca/choices. c) USA: https://www.aboutads.info/choices. d) Across all regions: https://optout.aboutads.info.
Services used and service providers:
Google Analytics: online marketing and web analytics; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of adverts: https://adssettings.google.com/authenticated.
Social media presence
We maintain an online presence on social media platforms and, in this context, process users’ data in order to communicate with users active on those platforms or to provide information about us.
We would like to point out that this may involve the processing of users’ data outside the European Union. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights.
Furthermore, users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on users’ behaviour and the resulting interests of the users. These user profiles can in turn be used, for example, to display adverts both within and outside the networks that are presumed to correspond to users’ interests . For these purposes, cookies are usually stored on users’ computers, in which users’ usage behaviour and interests are recorded. Furthermore, data may also be stored in the usage profiles regardless of the devices used by users (in particular, if users are members of the respective platforms and are logged in to them).
For a detailed description of the various forms of data processing and the options for opting out, please refer to the privacy policies and information provided by the operators of the respective networks.
In the case of requests for information and the exercise of data subjects’ rights, we would also like to point out that these can be exercised most effectively by contacting the service providers directly. Only the service provider has access to users’ data in each case and can take appropriate action directly and provide information. Should you nevertheless require assistance, please do not hesitate to contact us.
Facebook: We are jointly responsible with Facebook Ireland Ltd. for the collection (but not the further processing) of data relating to visitors to our Facebook page (known as a ‘fan page’). This data includes information on the types of content that users view or interact with, or the actions they take (see ‘Things you and others do and provide’ in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see ‘Device information’ in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under ‘How do we use this information?’, Facebook also collects and uses Facebook also collects and uses information to provide analytics services, known as ‘Page Insights’, to page administrators, so that they can gain insights into how people interact with their pages and the content associated with them . We have entered into a specific agreement with Facebook (“Information on Page Insights”, https://www.facebook.com/legal/terms/page_controller_addendum), which sets out in particular the security measures Facebook must observe and in which Facebook has agreed to (i.e. users can, for example, submit requests for information or erasure directly to Facebook). Users’ rights (in particular the rights to access, erasure, objection and to lodge a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the “Information on Page Insights” (https://www.facebook.com/legal/terms/information_about_page_insights_data).
Types of data processed: Contact details (e.g. email address, telephone numbers), content data (e.g. information entered in online forms), usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
People affected: User (e.g. website visitors, users of online services).
Purposes of processing: Enquiries and communication, feedback (e.g. collecting feedback via an online form), marketing.
Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Services used and service providers:
Instagram: social network; service provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.instagram.com; Privacy policy: https://instagram.com/about/legal/privacy.
Facebook: social network; service provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Opt-out option: Advertising settings: https://www.facebook.com/adpreferences/ad_settings (Facebook login required).
Deletion of data
The data we process will be deleted in accordance with statutory requirements as soon as the consent permitting its processing is withdrawn or other authorisations cease to apply (e.g. if the purpose of processing this data no longer applies or if it is no longer necessary for that purpose).
Unless the data is not deleted because it is required for other, legally permissible purposes, its processing is restricted to those purposes. This means that the data is blocked and not processed for any other purposes. This applies, for example, to data which must be retained for commercial or tax law reasons, or where its storage is necessary for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person.
Our privacy notices may also contain further details regarding the retention and erasure of data, which take precedence in relation to the respective processing operations.
Changes to and updates of the Privacy Policy
We ask that you check the content of our privacy policy regularly. We will update the privacy policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.
Where we provide addresses and contact details for companies and organisations in this privacy policy, please note that these addresses may change over time, and we ask that you check the details before making contact.
Rights of data subjects
As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
Right to object: You have the right, on grounds relating to your particular situation, at any time to object to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
Right of access: You have the right to request confirmation as to whether the data in question is being processed, and to request access to this data, as well as further information and a copy of the data, in accordance with the statutory requirements.
Right to rectification: In accordance with the relevant legal provisions, you have the right to request that the data relating to you be completed or that any inaccurate data relating to you be rectified.
Right to erasure and restriction of processing: In accordance with the statutory provisions, you have the right to request that data relating to you be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of such data.
Right to data portability: You have the right to receive the data relating to you that you have provided to us in a structured, commonly used and machine-readable format, in accordance with the statutory requirements, or to request that it be transferred to another data controller.
Complaint to the supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place where the alleged infringement occurred, if you consider that the processing of your personal data infringes the provisions of the GDPR.
Definitions of terms
This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the law and are defined, in particular, in Article 4 of the GDPR. The legal definitions are binding. The explanations below, however, are primarily intended to aid understanding. The terms are listed in alphabetical order.
IP Masking: The term ‘IP masking’ refers to a method in which the last octet – that is, the last two digits of an IP address – is deleted so that the IP address can no longer be used to uniquely identify an individual. IP masking is therefore a means of pseudonymising data processing procedures, particularly in online marketing
Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); an identifiable natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Profiles containing user-related information: The processing of ‘profiles containing user-related information’, or ‘profiles’ for short, encompasses any form of automated processing of personal data which consists of using such personal data to analyse, evaluate or draw conclusions about certain personal aspects relating to a natural person (depending on the nature of the profiling, this may include various types of information relating to demographics, behaviour and interests, such as interaction with websites and their content, etc.) to analyse, evaluate or to predict them (e.g. interests in specific content or products, clicking behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
Data controller: The term ‘controller’ refers to the natural or legal person, public authority, body or other organisation which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processing: "Processing" means any operation or set of operations which is carried out on personal data, whether or not by automated means, or any such set of operations in connection with personal data. The term is broad and covers virtually any handling of data, be it collection, analysis, storage, transmission or erasure.
Created using the free Datenschutz-Generator.de tool by Dr Thomas Schwenke.