Privacy policy
Introduction
With the following Privacy Policy, we would like to inform you about the types of personal data (hereinafter also referred to as “data”) we process, the purposes for which we process it, and the scope of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and on external online platforms, such as our social media profiles (hereinafter collectively referred to as the “Online Offer”).
The terms used are not gender-specific.
As of November 11, 2021
Table of Contents
- Introduction
- Person in Charge
- Overview of Processing Steps
- Relevant Legal Bases
- Safety Measures
- Transfer of Personal Data
- Deletion of Data
- Use of Cookies
- Performance of duties in accordance with the bylaws or rules of procedure
- Business Services
- Payment Methods
- Provision of the Online Service and Web Hosting
- Social Media Presence
- Plugins, Embedded Functions, and Content
- Changes and Updates to the Privacy Policy
- Rights of Data Subjects
Person in Charge
TROPICA VERDE e.V.
Association for the Protection of Tropical Habitats
Information Office at the Ökohaus
Room No. 361, 3rd Floor / East
Kasseler Straße 1 A
D-60486 Frankfurt am Main
Phone: +49 (0)69 75 15 50
Email: mail@tropica-verde.de
Authorized Representatives: Michael Ott, Prof. Dr. Martin Scholz.
Email address: mail@tropica-verde.de.
Phone: +49 (0)69 75 15 50.
Legal Notice: https://tropica-verde.de/impressum/.
Overview of Processing Steps
The following overview summarizes the types of data processed and the purposes of such processing, and identifies the data subjects.
Types of Data Processed
- Master data (e.g., names, addresses).
- Content data (e.g., entries in online forms).
- Contact information (e.g., email, phone numbers).
- Meta/communication data (e.g., device information, IP addresses).
- Usage data (e.g., websites visited, content interests, access times).
- Contract details (e.g., subject matter of the contract, term, customer category).
- Payment information (e.g., bank account information, invoices, payment history).
Categories of Data Subjects
- Business and contractual partners.
- Prospective buyers.
- Communication partners.
- Customers.
- Members.
- Users (e.g., website visitors, users of online services).
Purposes of Processing
- Provision of our online services and user-friendliness.
- Office and Organizational Procedures.
- Direct marketing (e.g., via email or mail).
- Feedback (e.g., collecting feedback via an online form).
- Marketing.
- Contact Requests and Communication.
- Safety measures.
- Provision of contractual services and customer service.
- Managing and responding to inquiries.
Relevant Legal Bases
Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country of residence or our country of residence or registered office. If, in individual cases, more specific legal bases apply, we will inform you of these in the Privacy Policy.
- Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR) — The data subject has given consent to the processing of personal data concerning him or her for a specific purpose or for several specific purposes.
- Performance of a Contract and Precontractual Inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR) — Processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of precontractual measures taken at the data subject’s request.
- Legal Obligation (Art. 6(1), first sentence, subparagraph (c) of the GDPR) — Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR) - Processing is necessary to safeguard the legitimate interests of the controller or a third party, unless the interests or fundamental rights and freedoms of the data subject that require the protection of personal data take precedence.
National Data Protection Regulations in Germany: In addition to the data protection regulations of the General Data Protection Regulation (GDPR), national data protection regulations apply in Germany. These include, in particular, the Act on the Protection Against the Misuse of Personal Data in Data Processing (Federal Data Protection Act—BDSG). The BDSG contains, in particular, special provisions regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making in individual cases, including profiling. Furthermore, it governs data processing for the purposes of the employment relationship (Section 26 BDSG), particularly with regard to the establishment, performance, or termination of employment relationships, as well as the consent of employees. In addition, state data protection laws of the individual federal states may apply.
Safety Measures
We implement technical and organizational measures appropriate to the circumstances and the purposes of the processing, as well as to the varying likelihoods and severity of threats to the rights and freedoms of natural persons, in accordance with legal requirements and taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and maintaining its separation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the deletion of data, and responses to data breaches. Furthermore, we take the protection of personal data into account from the very beginning of the development or selection of hardware, software, and procedures, in accordance with the principle of data protection through technical design and privacy-friendly default settings.
SSL Encryption (https): To protect the data you submit through our online services, we use SSL encryption. You can recognize such encrypted connections by the prefix https:// in your browser’s address bar.
Transfer of Personal Data
As part of our processing of personal data, the data may be transferred to or disclosed to other agencies, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
Data Transfer Within the Organization: We may transfer personal data to other departments within our organization or grant them access to such data. If this transfer is for administrative purposes, it is based on our legitimate business and operational interests, or it is necessary to fulfill our contractual obligations, or it is based on the consent of the data subjects or a legal authorization.
Deletion of Data
The data we process will be deleted in accordance with legal requirements as soon as the consent authorizing its processing is revoked or other legal grounds for processing no longer apply (e.g., if the purpose for which the data is being processed no longer exists or if the data is no longer necessary for that purpose).
Unless the data is not deleted because it is required for other, legally permissible purposes, its processing is limited to those purposes. This means that the data is blocked and not processed for any other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary to assert, exercise, or defend legal claims, or to protect the rights of another natural or legal person.
Our privacy policy may also contain additional information regarding the retention and deletion of data, which takes precedence over the respective processing activities.
Use of Cookies
Cookies are text files that contain data from websites or domains visited and are stored by a browser on the user’s computer. A cookie is primarily used to store information about a user during or after their visit to an online service. The stored information may include, for example, language settings on a website, login status, a shopping cart, or the point at which a video was paused. We also include other technologies that perform the same functions as cookies under the term “cookies” (e.g., when user information is stored using pseudonymous online identifiers, also known as “user IDs”).
We distinguish between the following types and functions of cookies:
- Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest after a user leaves a website and closes their browser.
- Persistent cookies: Persistent cookies remain stored even after the browser is closed. For example, this allows the login status to be saved or preferred content to be displayed immediately when the user visits a website again. Similarly, users’ interests—which are used for audience measurement or marketing purposes—can be stored in such a cookie.
- First-party cookies: First-party cookies are set by us.
- Third-party cookies (also known as third-party cookies): Third-party cookies are primarily used by advertisers (so-called third parties) to process user information.
- Necessary (also: essential or strictly required) cookies: Cookies may be strictly necessary for the operation of a website (e.g., to store logins or other user input, or for security reasons).
- Statistics, Marketing, and Personalization Cookies: Cookies are also generally used for audience measurement and when a user’s interests or behavior (e.g., viewing certain content, using certain features, etc.) on individual web pages are stored in a user profile. Such profiles are used, for example, to display content to users that corresponds to their potential interests. This process is also referred to as “tracking,” i.e., tracking users’ potential interests. To the extent that we use cookies or “tracking” technologies, we will inform you separately in our Privacy Policy or when obtaining your consent.
Information on Legal Bases: The legal basis on which we process your personal data using cookies depends on whether we ask for your consent. If this is the case and you consent to the use of cookies, the legal basis for processing your data is your expressed consent. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g., in the business operation of our online service and its improvement) or, if the use of cookies is necessary to fulfill our contractual obligations.
Retention Period: Unless we provide you with specific information regarding the retention period for persistent cookies (e.g., as part of a so-called cookie opt-in), please assume that the retention period may be up to two years.
General Information on Withdrawal of Consent and Objection (Opt-Out): Depending on whether the processing is based on consent or legal authorization, you have the option at any time to withdraw your consent or object to the processing of your data through cookie technologies (collectively referred to as “opt-out”). You can initially exercise your right to object through your browser settings, for example, by disabling cookies (although this may also limit the functionality of our online services). You can also object to the use of cookies for online marketing purposes through a variety of services—particularly in the case of tracking—via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/. In addition, you can find further information on how to object in the details provided about the service providers and cookies used.
Processing of Cookie Data Based on Consent: We use a cookie consent management process through which users’ consent to the use of cookies—as well as to the processing activities and providers specified within the cookie consent management process—is obtained, and through which users can manage and revoke their consent. The declaration of consent is stored so that users do not have to be asked for consent again and so that we can provide proof of consent in accordance with legal requirements. Storage may occur on the server and/or in a cookie (a so-called opt-in cookie, or using comparable technologies) to associate the consent with a user or their device. Subject to specific information provided by cookie management service providers, the following applies: Consent may be stored for up to two years. In this process, a pseudonymous user identifier is generated and stored along with the time of consent, details regarding the scope of consent (e.g., which categories of cookies and/or service providers), as well as the browser, operating system, and device used.
- Types of Data Processed: Usage data (e.g., websites visited, content interests, access times), meta/communication data (e.g., device information, IP addresses).
- Data subjects: Users (e.g., website visitors, users of online services).
- Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR), Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Performance of duties in accordance with the bylaws or rules of procedure
We process the data of our members, supporters, prospective members, business partners, or other individuals (collectively, “data subjects”) when we have a membership or other business relationship with them, when we carry out our duties, and when they are recipients of services and benefits. In addition, we process the data of data subjects based on our legitimate interests, e.g., in connection with administrative tasks or public relations activities.
The data processed in this context, as well as the nature, scope, purpose, and necessity of such processing, are determined by the underlying membership or contractual relationship, which also establishes the necessity of providing any data (we will, incidentally, indicate which data is required).
We delete data that is no longer necessary for the fulfillment of our statutory and business purposes. This is determined based on the respective tasks and contractual relationships. We retain data for as long as it may be relevant for business transactions, as well as with regard to any warranty or liability obligations, based on our legitimate interest in addressing such matters. The necessity of retaining the data is reviewed on a regular basis; otherwise, statutory retention requirements apply.
Register of associations: No. VR 9422
Register court: Registered in the Frankfurt am Main register of associations
- Types of Data Processed: Master data (e.g., names, addresses), payment data (e.g., bank account information, invoices, payment history), contact information (e.g., email, phone numbers), contract data (e.g., subject matter of the contract, term, customer category).
- Data subjects: Users (e.g., website visitors, users of online services), members, business partners, and contractual partners.
- Purposes of processing: Providing contractual services and customer service; handling contact requests and communication; managing and responding to inquiries.
- Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR), Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Business Services
We process data from our contractual and business partners, such as customers and prospective customers (collectively referred to as “contractual partners”), in connection with contractual and similar legal relationships, as well as related measures and communications with contractual partners (or on a pre-contractual basis), e.g., to respond to inquiries.
We process this data to fulfill our contractual obligations, to safeguard our rights, and for the purposes of administrative tasks associated with this information as well as for business organization. We disclose the data of our contractual partners to third parties in accordance with applicable law only to the extent that this is necessary for the aforementioned purposes or to fulfill legal obligations, or with the consent of the individuals concerned (e.g., to involved telecommunications, transportation, and other support services, as well as subcontractors, banks, tax and legal advisors, payment service providers, or tax authorities). Contractual partners will be informed about other forms of data processing—such as for marketing purposes—in this Privacy Policy.
We inform our contractual partners of which data is required for the aforementioned purposes either before or during the data collection process—for example, in online forms, through special markings (e.g., colors) or symbols (e.g., asterisks or similar), or in person.
We delete the data after the expiration of statutory warranty obligations and similar obligations, i.e., generally after 4 years, unless the data is stored in a customer account, e.g., as long as it must be retained for legal archiving purposes (e.g., for tax purposes, typically 10 years). We delete data disclosed to us by the contracting party in connection with an order in accordance with the terms of the order, generally upon completion of the order.
To the extent that we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms apply to the relationship between users and those providers.
Shop and E-Commerce: We process our customers’ data to enable them to select, purchase, or order the products, goods, and related services of their choice, as well as to facilitate payment and delivery or fulfillment. To the extent necessary for fulfilling an order, we engage service providers—in particular postal, freight, and shipping companies—to carry out delivery or fulfillment for our customers. We use the services of banks and payment service providers to process payment transactions. The required information is clearly marked as such during the ordering process or similar purchase transaction and includes the details necessary for delivery, provision of goods, and billing, as well as contact information to facilitate any necessary communication.
- Types of Data Processed: Master data (e.g., names, addresses), payment data (e.g., bank account information, invoices, payment history), contact data (e.g., email, phone numbers), contract data (e.g., subject matter of the contract, term, customer category), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
- Data subjects: Prospective customers, business partners, and contractual partners; customers.
- Purposes of processing: Provision of contractual services and customer service; contact requests and communication; office and organizational procedures; management and response to inquiries; security measures.
- Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, lit. b of the GDPR), Legal obligation (Art. 6(1), first sentence, lit. c of the GDPR), Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Payment Methods
In the context of contractual and other legal relationships, in accordance with legal obligations, or otherwise based on our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, engage not only banks and credit institutions but also other service providers (collectively, “payment service providers”).
The data processed by the payment service providers includes personal information, such as name and address; banking information, such as account numbers or credit card numbers; passwords, TANs, and checksums; as well as details related to the contract, transaction amounts, and recipients. This information is required to process the transactions. However, the data entered is processed and stored solely by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers may transmit the data to credit bureaus. The purpose of this transmission is to verify identity and creditworthiness. For more information, please refer to the terms and conditions and privacy policies of the payment service providers.
Payment transactions are subject to the terms and conditions and privacy policies of the respective payment service providers, which are available on their respective websites or within the transaction applications. We also refer you to these documents for further information and to exercise your rights of withdrawal, access, and other data subject rights.
Direct Debit
If you choose this payment method for donations, we will not collect any personal data from you beyond the information required to process your donation.
- Types of data processed: Master data (e.g., names, addresses), payment data (e.g., bank account information, invoices, payment history), contract data (e.g., subject matter of the contract, term, customer category), usage data (e.g., websites visited, content interests, access times), meta/communication data (e.g., device information, IP addresses).
- Data subjects: Customers, prospective customers.
- Purposes of processing: Provision of contractual services and customer service.
- Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR), Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Services Used and Service Providers:
- PayPal: Payment services and solutions (e.g., PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Website: https://www.paypal.com/de; Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Provision of the Online Service and Web Hosting
In order to provide our online services securely and efficiently, we use the services of one or more web hosting providers, from whose servers (or servers managed by them) the online services can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space, and database services, as well as security and technical maintenance services.
The data processed in connection with the provision of the hosting service may include any information relating to users of our online service that is generated during their use of the service and in the course of communication. This typically includes the IP address, which is necessary to deliver the content of online services to browsers, and all entries made within our online service or on websites.
Collection of Access Data and Log Files: We (or our web hosting provider) collect data on every access to the server (so-called server log files). Server log files may include the address and name of the web pages and files accessed, the date and time of the request, the amount of data transferred, a notification of a successful request, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider.
Server log files can be used, on the one hand, for security purposes—for example, to prevent server overload (particularly in the case of malicious attacks, known as DDoS attacks)—and, on the other hand, to ensure server performance and stability.
- Types of data processed: Content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Providing our online services and ensuring user-friendliness, fulfilling contractual obligations, and providing customer service.
- Legal Basis: Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Services Used and Service Providers:
- IONOS by 1&1: Hosting platform for e-commerce / websites; Service provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; Website: https://www.ionos.de; Privacy Policy: https://www.ionos.de/terms-gtc/terms-privacy; Data Processing Agreement: https://www.ionos.de/hilfe/datenschutz/allgemeine-informationen-zur-datenschutz-grundverordnung-dsgvo/auftragsverarbeitung/?utm_source=search&utm_medium=global&utm_term=Auft&utm_campaign=HELP_CENTER&utm_content=/help/.
Social Media Presence
We maintain online presences on social media platforms and, in this context, process user data in order to communicate with users active on those platforms or to provide information about us.
Please note that this may involve the processing of user data outside the European Union. This may pose risks to users, as it could, for example, make it more difficult to enforce their rights.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, user profiles can be created based on users’ behavior and the resulting interests. These user profiles can in turn be used, for example, to display advertisements both within and outside the networks that are presumed to correspond to users’ interests. For these purposes, cookies are typically stored on users’ computers to record their usage behavior and interests. Furthermore, data may also be stored in the usage profiles regardless of the devices used by users (particularly if users are members of the respective platforms and are logged in to them).
For a detailed description of the specific processing methods and opt-out options, please refer to the privacy policies and information provided by the operators of the respective networks.
We would also like to point out that requests for information and the exercise of data subject rights are most effectively addressed directly with the service providers. Only the providers have access to users’ data and can take appropriate action and provide information directly. If you still need assistance, however, you can contact us.
Facebook Pages: We are jointly responsible with Facebook Ireland Ltd. for the collection (but not the further processing) of data from visitors to our Facebook page (known as a “fan page”). This data includes information about the types of content users view or interact with, or the actions they take (see “Things You and Others Do and Share” in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices users use (e.g., IP addresses, operating system, browser type, language settings, cookie data; see “Device Information” in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under “How do we use this information?” , Facebook also collects and uses information to provide analytics services—known as “Page Insights”—to page administrators, so they can gain insights into how people interact with their pages and the content associated with them. We have entered into a specific agreement with Facebook (“Information on Page Insights,” https://www.facebook.com/legal/terms/page_controller_addendum), which specifically sets forth the security measures Facebook must observe and in which Facebook has agreed to comply with data subject rights (i.e., users can, for example, submit requests for information or deletion directly to Facebook). Users’ rights (in particular the rights to access, erasure, objection, and filing a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the “Page Insights Information” (https://www.facebook.com/legal/terms/information_about_page_insights_data).
- Types of data processed: Contact information (e.g., email, phone numbers), content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Contact requests and communication, feedback (e.g., collecting feedback via an online form), marketing.
- Legal Basis: Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Services Used and Service Providers:
- Instagram: Social network; Service provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA; Website: https://www.instagram.com; Privacy Policy: https://instagram.com/about/legal/privacy.
- Facebook Pages: Profiles within the Facebook social network; Service Provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Standard Contractual Clauses (ensuring an adequate level of data protection for processing in third countries): https://www.facebook.com/legal/EU_data_transfer_addendum; Data Processing Agreement: https://www.facebook.com/legal/terms/dataprocessing.
- Twitter: Social network; Service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; Parent company: Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; Privacy Policy: https://twitter.com/de/privacy, (Settings) https://twitter.com/personalization.
- YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Privacy Policy: https://policies.google.com/privacy; Opt-out option: https://adssettings.google.com/authenticated.
Plugins, Embedded Functions, and Content
We incorporate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos, or city maps (hereinafter collectively referred to as “content”).
This integration always requires that the third-party providers of this content process users’ IP addresses, since they would not be able to send the content to users’ browsers without the IP address. The IP address is therefore necessary for displaying this content or these features. We strive to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These “pixel tags” allow information—such as visitor traffic on the pages of this website—to be analyzed. This pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, the time of the visit, and other details regarding the use of our online services; it may also be linked to such information from other sources.
Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.
- Types of data processed: Usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses), master data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., entries in online forms).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Providing our online services and ensuring user-friendliness, fulfilling contractual obligations, and providing customer service.
- Legal Basis: Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR), Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR), performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
Services Used and Service Providers:
- Google Fonts: We integrate fonts (“Google Fonts”) from the provider Google, whereby user data is used solely for the purpose of displaying the fonts in the user’s browser. This integration is based on our legitimate interests in the technically secure, maintenance-free, and efficient use of fonts and their consistent display, while taking into account any licensing restrictions that may apply to their integration. Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent Company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://fonts.google.com/; Privacy Policy: https://policies.google.com/privacy.
- Google Maps: We integrate maps from the “Google Maps” service provided by Google. The data processed may include, in particular, users’ IP addresses and location data; however, this data is not collected without their consent (which is typically provided through the settings on their mobile devices); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://cloud.google.com/maps-platform; Privacy Policy: https://policies.google.com/privacy; Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying ads: https://adssettings.google.com/authenticated.
- YouTube Videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.youtube.com; Privacy Policy: https://policies.google.com/privacy; Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying ads: https://adssettings.google.com/authenticated.
- YouTube Videos: Video content; YouTube videos are embedded via a special domain (identifiable by the "youtube-nocookie" component) in what is known as "Enhanced Privacy Mode," which means that no cookies are collected regarding user activity for the purpose of personalizing video playback. However, information regarding user interaction with the video (e.g., remembering the last playback position) may be stored; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.youtube.com; Privacy Policy: https://policies.google.com/privacy.
Changes and Updates to the Privacy Policy
We ask that you review the content of our Privacy Policy on a regular basis. We will update the Privacy Policy as soon as changes to our data processing activities make it necessary to do so. We will notify you as soon as the changes require action on your part (e.g., consent) or any other individual notification.
If we provide addresses and contact information for companies and organizations in this Privacy Policy, please note that these addresses may change over time, and we ask that you verify the information before contacting them.
Rights of Data Subjects
As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 through 21 of the GDPR:
- Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out pursuant to Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to Withdraw Consent: You have the right to withdraw your consent at any time.
- Right of Access: You have the right to request confirmation as to whether your personal data is being processed, as well as access to that data, additional information, and a copy of the data in accordance with legal requirements.
- Right to Rectification: In accordance with legal requirements, you have the right to request that data concerning you be completed or that any inaccurate data concerning you be corrected.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be erased without delay or, alternatively, to request a restriction on the processing of such data in accordance with legal requirements.
- Right to Data Portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, in accordance with legal requirements, or to request that it be transferred to another data controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the location of the alleged infringement, if you believe that the processing of your personal data violates the provisions of the GDPR.
Created using the free Datenschutz-Generator.de by Dr. Thomas Schwenke