Privacy Policy
This privacy policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offering and the associated websites, functions and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering"). With regard to the terms used, such as "processing" or "controller", we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).
Controller
Andreas Schumm
Am Mittelfeld 2E
01640 Coswig
Germany
Email address:
Phone: 03523-8673812
Types of data processed:
- Basic data (e.g., names, addresses).
- Contact data (e.g., email, phone numbers).
- Content data (e.g., text entries, photographs, videos).
- Usage data (e.g., websites visited, interest in content, access times).
- Meta/communication data (e.g., device information, IP addresses).
Categories of data subjects
Visitors and users of the online offering (hereinafter we also collectively refer to the data subjects as "users").
Purpose of processing
- Provision of the online offering, its functions and content.
- Answering contact requests and communicating with users.
- Security measures.
- Reach measurement/marketing
Terms used
"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Processing" is any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.
"Pseudonymisation" means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
"Profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
"Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
"Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Applicable legal bases
In accordance with Art. 13 GDPR, we inform you of the legal basis for our data processing. Unless otherwise stated in this privacy policy, the following applies: the legal basis for obtaining consent is Art. 6 (1) (a) and Art. 7 GDPR; the legal basis for processing to perform our services and carry out contractual measures and to respond to inquiries is Art. 6 (1) (b) GDPR; the legal basis for processing to fulfil our legal obligations is Art. 6 (1) (c) GDPR; and the legal basis for processing to protect our legitimate interests is Art. 6 (1) (f) GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) (d) GDPR serves as the legal basis.
Security measures
In accordance with Art. 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data as well as access to, entry into, disclosure of, and the securing of the availability of and separation of the data. We have also established procedures to ensure the exercise of data subjects' rights, the deletion of data, and responses to data compromise. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and through privacy-friendly default settings (Art. 25 GDPR).
Cooperation with processors and third parties
If, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transmit it to them, or otherwise grant them access to the data, this is done only on the basis of a legal permission (e.g. if a transmission of the data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Art. 6 (1) (b) GDPR), if you have consented, if a legal obligation provides for it, or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).
If we engage third parties to process data on the basis of a so-called "data processing agreement", this is done on the basis of Art. 28 GDPR.
Transfers to third countries
If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transmitting data to third parties, this only happens if it is necessary to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or have the data processed in a third country only if the special requirements of Art. 44 et seq. GDPR are met. This means, for example, that the processing takes place on the basis of special guarantees, such as the officially recognised determination of a level of data protection equivalent to that of the EU (e.g. for the USA through the "Privacy Shield") or the observance of officially recognised special contractual obligations (so-called "standard contractual clauses").
Rights of data subjects
You have the right to request confirmation as to whether data concerning you is being processed, and to receive information about this data as well as further information and a copy of the data in accordance with Art. 15 GDPR.
In accordance with Art. 16 GDPR, you have the right to demand the completion of data concerning you or the correction of inaccurate data concerning you.
In accordance with Art. 17 GDPR, you have the right to demand that data concerning you be deleted without delay, or alternatively, in accordance with Art. 18 GDPR, to demand a restriction of the processing of the data.
You have the right to demand that the data concerning you that you have provided to us be handed over to you in accordance with Art. 20 GDPR and to demand that it be transferred to other controllers.
You furthermore have the right, pursuant to Art. 77 GDPR, to lodge a complaint with the competent supervisory authority.
Right of withdrawal
You have the right to withdraw consent given, pursuant to Art. 7 (3) GDPR, with effect for the future.
Right to object
You may object at any time to the future processing of data concerning you in accordance with Art. 21 GDPR. This objection may, in particular, be made against processing for the purposes of direct marketing.
Cookies and right to object to direct marketing
"Cookies" are small files that are stored on users' computers. Various information can be stored within cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to an online offering. Cookies that are deleted after a user leaves an online offering and closes their browser are referred to as temporary cookies, "session cookies" or "transient cookies". Such a cookie can be used, for example, to store the contents of a shopping cart in an online shop or a login status. Cookies that remain stored even after the browser is closed are referred to as "permanent" or "persistent". For example, the login status can be saved if users visit again after several days. Such a cookie can likewise be used to store the interests of users, which are used for reach measurement or marketing purposes. Cookies offered by providers other than the controller operating the online offering are referred to as "third-party cookies" (otherwise, if they are only its own cookies, they are referred to as "first-party cookies").
We may use temporary and permanent cookies and clarify this within the scope of our privacy policy.
If users do not want cookies to be stored on their computer, they are asked to disable the corresponding option in their browser's system settings. Stored cookies can be deleted in the browser's system settings. Excluding cookies may lead to functional limitations of this online offering.
A general objection to the use of cookies used for online marketing purposes can be declared for a large number of services, especially in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be prevented by disabling them in the browser settings. Please note that in this case not all functions of this online offering may be usable.
Erasure of data
The data we process is deleted or its processing restricted in accordance with Art. 17 and 18 GDPR. Unless expressly stated within this privacy policy, the data stored with us will be deleted as soon as it is no longer required for its intended purpose and there are no statutory retention obligations preventing deletion. If the data is not deleted because it is required for other legally permissible purposes, its processing is restricted. This means the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
According to statutory requirements in Germany, retention is required in particular for 10 years pursuant to Sections 147 (1) of the German Fiscal Code (AO) and 257 (1) nos. 1 and 4, (4) of the German Commercial Code (HGB) (books, records, management reports, accounting vouchers, commercial books, documents relevant to taxation, etc.), and 6 years pursuant to Section 257 (1) nos. 2 and 3, (4) HGB (commercial correspondence).
According to statutory requirements in Austria, retention is required in particular for 7 years pursuant to Section 132 (1) of the Austrian Federal Fiscal Code (BAO) (accounting documents, receipts/invoices, accounts, vouchers, business papers, statement of income and expenses, etc.), for 22 years in connection with real property, and for 10 years for documents relating to electronically supplied services, telecommunications, broadcasting and television services provided to non-business customers in EU member states for which the Mini One Stop Shop (MOSS) is used.
Integration of third-party services and content
Within our online offering, on the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offering within the meaning of Art. 6 (1) (f) GDPR), we use content or service offerings from third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter uniformly referred to as "content").
This always requires that the third-party providers of this content perceive the users' IP address, as without the IP address they could not send the content to their browser. The IP address is therefore required for the display of this content. We endeavour to use only content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may include technical information about the browser and operating system, referring websites, visit time, and other information about the use of our online offering, as well as being combined with such information from other sources.
YouTube
We integrate videos from the "YouTube" platform provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy/, opt-out: https://adssettings.google.com/authenticated.
Jitsi Meeting Room (8x8 JaaS)
On our website we offer a meeting room implemented via the "8x8 JaaS" (Jitsi as a Service) service provided by 8x8, Inc., 6720 Via Austi Parkway, Las Vegas, NV 89119, USA. When using the meeting room, video and audio data (camera, microphone) as well as technical connection data (IP address) are transmitted to and processed by 8x8 in order to establish the video/audio connection. Access to the meeting room is additionally password-protected. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in a functioning communication solution), or Art. 6 (1) (a) GDPR insofar as you consent to the use by entering the meeting room.
As 8x8, Inc. is based in the USA, this may result in a transfer of data to a third country (see "Transfers to third countries" above). Further information: https://www.8x8.com/legal/privacy-policy.
GLOBAL RANDOM – integrated third-party providers
Within our "GLOBAL RANDOM" application, we integrate the following external services via direct calls from your browser in order to provide certain functions (translation, weather data, music information, encyclopaedic knowledge). In each case your IP address is transmitted to the respective provider, as this is technically necessary for the delivery of the content. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the functionality of the offering).
- MyMemory Translation API (text translation) – provider: Translated S.r.l., Via Vittorio Bachelet 6, 00185 Rome, Italy. Further information: https://mymemory.translated.net/doc/usagelimits.php.
- Open-Meteo (weather data) – provider: Open-Meteo.com. Further information: https://open-meteo.com/en/terms.
- Wikipedia / Wikimedia REST API (encyclopaedic content) – provider: Wikimedia Foundation, Inc., 1 Montgomery St, Suite 1600, San Francisco, CA 94104, USA. Further information: https://foundation.wikimedia.org/wiki/Policy:Privacy_policy.
- MusicBrainz (music metadata) – provider: MetaBrainz Foundation Inc., USA. Further information: https://metabrainz.org/privacy.
- Wikidata SPARQL endpoint – provider: Wikimedia Deutschland e.V. / Wikimedia Foundation, Inc. (see above).
- jsDelivr CDN (delivery of a JavaScript component for emoji rendering) – provider: Prospect One sp. z o.o. Further information: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.
Spotify integration
Within GLOBAL RANDOM, tracks may be displayed and played back via an embedded Spotify element (iFrame). The provider is Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden. Loading this element establishes a connection to Spotify's servers and transmits your IP address to Spotify; Spotify may also set its own cookies on your device and evaluate usage for its own purposes. Further information on data processing by Spotify: https://www.spotify.com/en/legal/privacy-policy/.
Created with Datenschutz-Generator.de by RA Dr. Thomas Schwenke
Deutsch (Deutschland)
English (United Kingdom) 