ss

Conall

PRIVACY POLICE

Home  |  PRIVACY POLICE

Privacy Police

Introduction

Mit der folgenden Datenschutzerklärung möchten wir Sie darüber aufklären, welche Arten Ihrer personenbezogenen Daten (nachfolgend auch kurz als “Daten“ bezeichnet) wir zu welchen Zwecken und in welchem Umfang verarbeiten. Die Datenschutzerklärung gilt für alle von uns durchgeführten Verarbeitungen personenbezogener Daten, sowohl im Rahmen der Erbringung unserer Leistungen als auch insbesondere auf unseren Webseiten, in mobilen Applikationen sowie innerhalb externer Onlinepräsenzen, wie z.B. unserer Social-Media-Profile (nachfolgend zusammenfassend bezeichnet als “Onlineangebot“).

The terms used are not gender-specific.

Responsible

Friends of the GRASSI Museum of Applied Art e.V.

Authorised representative: Günther Gromke

Phone: +49 341 420550

Legal notice: https://www.handwerkskunst-leipzig.de/en/datenschutz/

Overview of processing

The following table summarises the types of data processed and the purposes of their processing, and refers to the data subjects.

Types of data processed

  • Inventory data (e.g. names, addresses).
  • Content data (e.g. text entries, photographs, videos).
  • Contact data (e.g. e-mail, telephone numbers).
  • Meta/communication data (e.g. device information, IP addresses).
  • Usage data (e.g. websites visited, interest in content, access times).

Categories of data subjects

  • Business and contractual partners.
  • Members.
  • Users (e.g. website visitors, users of online services).

Purposes of processing

  • Provision of our online offer and user-friendliness.
  • Feedback (e.g. collecting feedback via online form).
  • Contact requests and communication.
  • Security measures.
  • Administration and answering of enquiries.

Relevant legal bases

In the following, we provide the legal basis for the Basic Data Protection Regulation (DSGVO), on the basis of which we process personal data. Please note that in addition to the regulations of the DSGVO, national data protection regulations may apply in your or our country of residence and domicile. Should more specific legal provisions apply in individual cases, we will inform you of these in the data protection declaration.

  • Consent (Art. 6 para. 1 S. 1 lit. a DSGVO) – The data subject has given his or her consent to the processing of personal data relating to him or her for one or more specific purposes.
  • Fulfilment of a contract and pre-contractual requests (Art. 6 para. 1 S. 1 lit. b. DSGVO) – Processing is necessary for the performance of a contract to which the data subject is party or for the implementation of pre-contractual measures taken at the request of the data subject.
  • Protection of vital interests (Art. 6 para. 1 S. 1 lit. d. DSGVO) – Processing is necessary to protect the vital interests of the data subject or of another natural person.
  • Legitimate interests (Art. 6 para. 1 S. 1 lit. f. DSGVO) – The processing is necessary to protect the legitimate interests of the controller or of a third party unless the interests or fundamental rights and freedoms of the data subject which require the protection of personal data outweigh those of the data subject.

National data protection regulations in Germany: In addition to the data protection regulations of the Basic Data Protection Regulation, national regulations on data protection apply in Germany. These include in particular the law on protection against misuse of personal data in data processing (Federal Data Protection Act – BDSG). In particular, the BDSG contains special regulations on the right to information, the right to deletion, the right of objection, the processing of special categories of personal data, processing for other purposes and transmission as well as automated decision making in individual cases including profiling. Furthermore, it regulates data processing for the purposes of the employment relationship (Section 26 BDSG), in particular with regard to the establishment, implementation or termination of employment relationships and the consent of employees. Furthermore, state data protection laws of the individual federal states may apply.

Security measures

We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access, input, disclosure, security of availability and separation of data relating to them. Procedures have also been put in place to ensure that data subjects' rights are respected, that data are deleted and that responses to data breaches are made. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures in accordance with the principle of data protection, by designing technology and by using data protection-friendly default settings.

Transmission and disclosure of personal data

In the course of our processing of personal data, it may happen that the data is transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases we observe the legal requirements and in particular conclude appropriate contracts or agreements with the recipients of your data which serve to protect your data.

Data processing in third countries

If we process data in a third country (i.e. outside the European Union (EU), the European Economic Area (EEA)) or if the processing takes place in the context of the use of services of third parties or the disclosure or transfer of data to other persons, bodies or companies, this will only take place in accordance with the legal requirements.

Subject to express consent or transfer required by contract or by law, we will only process the data or have it processed in third countries with a recognised level of data protection, a contractual obligation through so-called standard protection clauses of the EU Commission, in the case of certifications or binding internal data protection regulations (Art. 44 to 49 DSGVO, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de ).

Use of cookies

Cookies sind Textdateien, die Daten von besuchten Websites oder Domains enthalten und von einem Browser auf dem Computer des Benutzers gespeichert werden. Ein Cookie dient in erster Linie dazu, die Informationen über einen Benutzer während oder nach seinem Besuch innerhalb eines Onlineangebotes zu speichern. Zu den gespeicherten Angaben können z.B. die Spracheinstellungen auf einer Webseite, der Loginstatus, ein Warenkorb oder die Stelle, an der ein Video geschaut wurde, gehören. Zu dem Begriff der Cookies zählen wir ferner andere Technologien, die die gleichen Funktionen wie Cookies erfüllen (z.B., wenn Angaben der Nutzer anhand pseudonymer Onlinekennzeichnungen gespeichert werden, auch als “Nutzer-IDs” bezeichnet)

The following cookie types and functions are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed his browser.
  • Permanent cookies: Permanent cookies remain stored even after the browser is closed. For example, the login status can be saved or preferred content can be displayed directly when the user visits a website again. Likewise, the interests of users used for reach measurement or marketing purposes can be stored in such a cookie.
  • First-party cookies: First-party cookies are set by us.
  • Third party cookies (also: third-party provider cookies):Third party cookies are mainly used by advertisers (so-called third parties) to process user information.
  • Third party cookies are mainly used by advertisers (so-called third parties) to process user information. Cookies may be absolutely necessary for the operation of a website (e.g. to store logins or other user entries or for security reasons).
  • Statistical, marketing and personalisation cookies:: Ferner werden Cookies im Regelfall auch im Rahmen der Reichweitenmessung eingesetzt sowie dann, wenn die Interessen eines Nutzers oder sein Verhalten (z.B. Betrachten bestimmter Inhalte, Nutzen von Funktionen etc.) auf einzelnen Webseiten in einem Nutzerprofil gespeichert werden. Solche Profile dienen dazu, den Nutzern z.B. Inhalte anzuzeigen, die ihren potentiellen Interessen entsprechen. Dieses Verfahren wird auch als “Tracking”, d.h., Nachverfolgung der potentiellen Interessen der Nutzer bezeichnet. Soweit wir Cookies oder “Tracking”-Technologien einsetzen, informieren wir Sie gesondert in unserer Datenschutzerklärung oder im Rahmen der Einholung einer Einwilligung.

Notes on legal bases: The legal basis on which we process your personal data using cookies depends on whether we ask you for your consent. If this is the case and you consent to the use of cookies, the legal basis for processing your data is the declared consent. Otherwise, the data processed with the aid of cookies will be processed on the basis of our legitimate interests (e.g. in the commercial operation of our online offer and its improvement) or, if the use of cookies is necessary to fulfil our contractual obligations.

Storage duration: Unless we provide you with explicit information on the storage duration of permanent cookies (e.g. within the framework of a so-called cookie opt-in), please assume that the storage duration can be up to two years.

General information on revocation and objection (opt-out): Abhängig davon, ob die Verarbeitung auf Grundlage einer Einwilligung oder gesetzlichen Erlaubnis erfolgt, haben Sie jederzeit die Möglichkeit, eine erteilte Einwilligung zu widerrufen oder der Verarbeitung Ihrer Daten durch Cookie-Technologien zu widersprechen (zusammenfassend als “Opt-Out” bezeichnet). Sie können Ihren Widerspruch zunächst mittels der Einstellungen Ihres Browsers erklären, z.B., indem Sie die Nutzung von Cookies deaktivieren (wobei hierdurch auch die Funktionsfähigkeit unseres Onlineangebotes eingeschränkt werden kann). Ein Widerspruch gegen den Einsatz von Cookies zu Zwecken des Onlinemarketings kann auch mittels einer Vielzahl von Diensten, vor allem im Fall des Trackings, über die Webseiten https://optout.aboutads.info and https://www.youronlinechoices.com/ . In addition, you can receive further notices of objection in the context of the information on the service providers and cookies used.

Processing of cookie data based on consent: Before we process or have processed data in the context of the use of cookies, we ask users for their consent, which can be revoked at any time. Before consent has not been given, we will only use cookies that are absolutely necessary for the operation of our online service.

  • Processed data types: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
  • Persons concerned: Users (e.g. website visitors, users of online services).
  • Legal basis: Consent (Art. 6 para. 1 S.1 letter a DSGVO), legitimate interests (Art. 6 para. 1 S. 1 letter f. DSGVO).

Carrying out tasks under the statutes or rules of procedure

Wir verarbeiten die Daten unserer Mitglieder, Unterstützer, Interessenten, Geschäftspartner oder sonstiger Personen (Zusammenfassend “Betroffene”), wenn wir mit ihnen in einem Mitgliedschafts- oder sonstigem geschäftlichen Verhältnis stehen und unsere Aufgaben wahrnehmen sowie Empfänger von Leistungen und Zuwendungen sind. Im Übrigen verarbeiten wir die Daten Betroffener auf Grundlage unserer berechtigten Interessen, z.B. wenn es sich um administrative Aufgaben oder Öffentlichkeitsarbeit handelt.

The data processed, the type, scope, purpose and necessity of their processing are determined by the underlying membership or contractual relationship, from which the necessity of any data information also arises (in other respects we refer to necessary data).

We delete data that is no longer necessary for the performance of our statutory and business purposes. This is determined according to the respective tasks and contractual relationships. We retain the data for as long as they may be relevant to the business transaction and with regard to any warranty or liability obligations based on our legitimate interest in their regulation. The necessity of storing the data is regularly reviewed; otherwise the statutory storage obligations apply.

  • Processed data types: Inventory data (e.g. names, addresses), payment data (e.g. bank details, invoices, payment history), contact data (e.g. e-mail, telephone numbers), contract data (e.g. subject matter of the contract, duration, customer category).
  • Persons concerned: Users (e.g. website visitors, users of online services), members, business and contractual partners.
  • Purposes of processing: Contractual services and service, contact requests and communication, administration and answering of requests.
  • Legal basis: Fulfilment of contract and pre-contractual enquiries (Art. 6 Paragraph 1 S. 1 lit. b. DSGVO), legitimate interests (Art. 6 Paragraph 1 S. 1 lit. f. DSGVO).

Providing the online offer and web hosting

In order to be able to deliver our online offer securely and efficiently, we use the services of one or more web hosting providers from whose servers (or servers managed by them) the online offer can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space and database services as well as security and technical maintenance services.

The data processed within the framework of the provision of the hosting offer may include all data relating to the users of our online offer, which are generated within the framework of use and communication. This regularly includes the IP address, which is necessary to be able to deliver the contents of online offers to browsers, and all entries made within our online offer or from websites.

Collection of access data and log files:We ourselves (or our web hosting provider) collect data on every access to the server (so-called server log files). Server log files may include the address and name of the web pages and files accessed, date and time of access, data volume transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider.

The server log files can be used for security purposes, e.g. to avoid overloading the servers (especially in the case of abusive attacks, so called DDoS attacks) and to ensure the capacity utilisation of the servers and their stability.

  • Processed data types: Content data (e.g. text entries, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
  • Persons concerned: Users (e.g. website visitors, users of online services).
  • Legal basis: Legitimate interests (Art. 6 para. 1S. 1 lit. f. DSGVO).

Plugins and embedded functions and content

Wir binden in unser Onlineangebot Funktions- und Inhaltselemente ein, die von den Servern ihrer jeweiligen Anbieter (nachfolgend bezeichnet als “Drittanbieter”) bezogen werden. Dabei kann es sich zum Beispiel um Grafiken, Videos oder Social-Media-Schaltflächen sowie Beiträge handeln (nachfolgend einheitlich bezeichnet als “Inhalte”).

Die Einbindung setzt immer voraus, dass die Drittanbieter dieser Inhalte die IP-Adresse der Nutzer verarbeiten, da sie ohne die IP-Adresse die Inhalte nicht an deren Browser senden könnten. Die IP-Adresse ist damit für die Darstellung dieser Inhalte oder Funktionen erforderlich. Wir bemühen uns, nur solche Inhalte zu verwenden, deren jeweilige Anbieter die IP-Adresse lediglich zur Auslieferung der Inhalte verwenden. Drittanbieter können ferner sogenannte Pixel-Tags (unsichtbare Grafiken, auch als “Web Beacons” bezeichnet) für statistische oder Marketingzwecke verwenden. Durch die “Pixel-Tags” können Informationen, wie der Besucherverkehr auf den Seiten dieser Webseite, ausgewertet werden. Die pseudonymen Informationen können ferner in Cookies auf dem Gerät der Nutzer gespeichert werden und unter anderem technische Informationen zum Browser und zum Betriebssystem, zu verweisenden Webseiten, zur Besuchszeit sowie weitere Angaben zur Nutzung unseres Onlineangebotes enthalten als auch mit solchen Informationen aus anderen Quellen verbunden werden.

Notes on legal bases: If we ask users for their consent to use the third party providers, the legal basis for processing data is consent. Otherwise, the users' data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient-friendly services). In this context we would also like to draw your attention to the information on the use of cookies in this data protection declaration.

  • Processed data types: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
  • Persons concerned: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online offer and user-friendliness, contractual services and service.
  • Legal basis: Legitimate interests (Art. 6 para. 1S. 1 lit. f. DSGVO).

Services used and service providers:

  • Font Awesome: Representation of fonts and symbols; service providers: Fonticons, Inc. .6 Porter Road Apartment 3R, Cambridge, MA 02140, USA; website: https://fontawesome.com/; privacy policy https://fontawesome.com/privacy.
  • Google Fonts: Wir binden die Schriftarten (“Google Fonts”) des Anbieters Google ein, wobei die Daten der Nutzer allein zu Zwecken der Darstellung der Schriftarten im Browser der Nutzer verwendet werden. Die Einbindung erfolgt auf Grundlage unserer berechtigten Interessen an einer technisch sicheren, wartungsfreien und effizienten Nutzung von Schriftarten, deren einheitlicher Darstellung sowie unter Berücksichtigung möglicher lizenzrechtlicher Restriktionen für deren Einbindung. Dienstanbieter: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland, Mutterunternehmen: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://fonts.google.com/; privacy policy https://policies.google.com/privacy.
  • OpenStreetMap: Wir binden die Landkarten des Dienstes “OpenStreetMap” ein, die auf Grundlage der Open Data Commons Open Database Lizenz (ODbL) durch die OpenStreetMap Foundation (OSMF) angeboten werden. Die Daten der Nutzer werden durch OpenStreetMap ausschließlich zu Zwecken der Darstellung der Kartenfunktionen und zur Zwischenspeicherung der gewählten Einstellungen verwendet. Zu diesen Daten können insbesondere IP-Adressen und Standortdaten der Nutzer gehören, die jedoch nicht ohne deren Einwilligung (im Regelfall im Rahmen der Einstellungen ihrer Mobilgeräte vollzogen) erhoben werden. Dienstanbieter: OpenStreetMap Foundation (OSMF); Website: https://www.openstreetmap.de; privacy policy https://wiki.openstreetmap.org/wiki/Privacy_Policy.

Deletion of data

The data processed by us will be deleted in accordance with the legal requirements as soon as their consent permitted for processing is revoked or other permissions cease to apply (e.g. if the purpose for which the data were processed ceases to apply or if they are not necessary for the purpose).

Unless the data are deleted because they are required for other and legally permissible purposes, their processing is limited to these purposes. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for reasons of commercial or tax law or that are required to be retained for the assertion, exercise or defence of legal claims or to protect the rights of another natural or legal person.

Further information on the deletion of personal data can also be provided in the individual data protection notes of this data protection declaration.

Changes and updates to the privacy policy

We ask you to inform yourself regularly about the content of our data protection declaration. We will adapt the data protection declaration as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes make it necessary for you to take action to cooperate (e.g. to give your consent) or to receive other individual notification.

If we provide addresses and contact information of companies and organisations in this data protection declaration, please note that the addresses may change over time and please check the information before contacting us.

Rights of data subjects

As a data subject, you are entitled to various rights under the DSGVO, which result in particular from Art. 15 to 21 DSGVO:

  • Right of objection: You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data relating to you which is carried out pursuant to Art. 6 paragraph 1 letter e or f FADP; this also applies to profiling based on these provisions. If personal data concerning you are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing, including profiling, insofar as it is linked to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
  • Right of access: You have the right to obtain confirmation as to whether or not data in question is being processed and to obtain information about such data and further information and a copy of the data in accordance with the law.
  • Right of rectification: You have the right to request the completion of data concerning you or the rectification of incorrect data concerning you, in accordance with the law.
  • Right to erasure and limitation of processing: You have the right to request, in accordance with the law, the immediate erasure of data concerning you or, alternatively, in accordance with the law, the limitation of processing of the data.
  • Right to data transferability: You have the right to obtain, in accordance with the law, data concerning you which you have provided to us in a structured, common and machine-readable format or to request that it be transferred to another controller.
  • Complaints to the supervisory authority: You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State in which you are habitually resident, your place of work or the place where the alleged infringement occurred, in accordance with the law, if you consider that the processing of personal data relating to you is in breach of the DPA.

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the law and defined above all in Art. 4 DSGVO. The legal definitions are binding. The following explanations, on the other hand, are primarily intended to help you understand them. The terms are sorted alphabetically.

  • Personal data: “Personenbezogene Daten“ sind alle Informationen, die sich auf eine identifizierte oder identifizierbare natürliche Person (im Folgenden “betroffene Person“) beziehen; als identifizierbar wird eine natürliche Person angesehen, die direkt oder indirekt, insbesondere mittels Zuordnung zu einer Kennung wie einem Namen, zu einer Kennnummer, zu Standortdaten, zu einer Online-Kennung (z.B. Cookie) oder zu einem oder mehreren besonderen Merkmalen identifiziert werden kann, die Ausdruck der physischen, physiologischen, genetischen, psychischen, wirtschaftlichen, kulturellen oder sozialen Identität dieser natürlichen Person sind.
  • Controller: Als “Verantwortlicher“ wird die natürliche oder juristische Person, Behörde, Einrichtung oder andere Stelle, die allein oder gemeinsam mit anderen über die Zwecke und Mittel der Verarbeitung von personenbezogenen Daten entscheidet, bezeichnet.
  • Processing: “Verarbeitung” ist jeder mit oder ohne Hilfe automatisierter Verfahren ausgeführte Vorgang oder jede solche Vorgangsreihe im Zusammenhang mit personenbezogenen Daten. Der Begriff reicht weit und umfasst praktisch jeden Umgang mit Daten, sei es das Erheben, das Auswerten, das Speichern, das Übermitteln oder das Löschen.

Version: 2020

Created with free data protection generator.de by Dr. Thomas Schwenke. The translation was supported by the online provider free DeepL

EN