DATA PROTECTION, GENERAL INFORMATION
OVERVIEW OF THE PROCESSING
REQUEST BY EMAIL/PHONE
SERVER LOG FILES
LINKS TO THIRD PARTY WEBSITES
ANALYSIS TOOLS AND ADVERTISING
PLUG-INS AND TOOLS
SOCIAL MEDIA APPEARANCES
DATA PROTECTION, GENERAL INFORMATION
When you visit our Site a variety of personal information will be collected. Personal data means any information relating to an identified or identifiable natural person and comprises data that can be used to personally identify you, such as your name, address, email address, IP address, or user behavior. We process personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR) and the applicable national law. This Privacy explains how and which data we collect through your use of our Site, as well as for what purpose and on what legal basis we use this data.
We herewith advise you that the transmission of data via the Internet (i.e., through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.
OVERVIEW OF THE PROCESSING
Who is responsible for processing your personal data?
The data processing controller (referred to as the “controller” in the GDPR) is
The TMRW Foundation S.à.r.l.
14-16, Avenue Pasteur
– Email: email@example.com
The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g., names, e-mail addresses, etc.).
How do we record your data?
What personal data do we collect when you visit the Website and use the service?
The information we collect, and how that information is used, depends on how you use the Website and how you manage your privacy controls and the requirements of applicable law.
We collect information to provide better services to all our users. We do not sell personal information to third parties but only use it to deliver the Website, to identify and troubleshoot problems and improve it.
Types of data collected:
We may collect, use, store and transfer different kinds of personal data about you, grouped together as follows: Personal data (e.g. names, addresses), Contact data (e.g. e-mail, telephone numbers) and Communications data ( Information about your communications with us, including relating to support questions and other inquiries.), Content data (e.g. entries in online forms), Meta/communication data (e.g. device information, IP addresses),usage data (e.g. websites visited).
Categories of data subjects: Users (e.g. website visitors)
How do we process (or use) your information? – purposes and legal basis of the processing
We use personal data to provide, maintain and improve our Website and your user experience; for security and safety to help improve the safety and reliability of our Website (including detecting, preventing, and responding to fraud, abuse, security risks, and technical issues that could harm us, the users or third parties); for communication with you about our products, features, and services, including product updates, and changes to our policies; for marketing and promotions: to market, advertise, and promote products; for legal reasons: In order to comply with applicable law or respond to valid legal process or legal action, including by law enforcement or regulatory authorities.
Legal Basis: Your collected personal data is processed on the basis of art. 6 para. 1 p. 1 lit. b GDPR if your inquiry is related to the fulfillment of a contract or is required for the performance of pre-contractual measures. In all other cases, the data are processed on the basis of our legitimate interest in the effective handling of inquiries submitted to us and in offering efficient, economical and user-friendly services (art. 6 para. 1 p. 1 lit. f GDPR) or on the basis of your consent (art. 6 para. 1 p. 1 lit. a GDPR) if it has been obtained. The data sent by you to us via contact requests remain with us until you request us to delete, revoke your consent to the storage or the purpose for the data storage lapses (e.g. after completion of your request). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Who do we share your personal data with?
We only pass on your personal data to third parties
How do we store and safeguard your data?
Storage Duration: Unless explicitly stated in this Privacy, your personal data stored by us will be deleted as soon as the purpose for which it was collected no longer applies and the deletion does not conflict with any statutory storage requirements. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g. tax or commercial law retention periods). In the latter case, the deletion will take place after these reasons cease to apply. If the data is not deleted because it is required for other and legitimate purposes, its processing will be restricted. That means the data is blocked and not processed for other purposes.
Security Measures: We take appropriate technical and organisational measures in accordance with the law, taking into account the state of the technic, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the different probabilities of occurrence and the level of threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk. If IP addresses are processed by us or by the service providers and technologies used and the processing of a complete IP address is not necessary, the IP address is shortened (Shortening of the IP address also referred to as „IP masking“). For security reasons and to protect the transmission of confidential content, such as inquiries you submit to us, we use either an SSL or a TLS encryption program.
As far as your information is concerned, you have the following rights:
TO EXERCISE YOUR RIGHTS OR IF YOU HAVE ANY PRIVACY-RELATED QUESTIONS OR COMMENTS RELATED TO THIS STATEMENT, PLEASE CONTACT US AT ANY TIME AT firstname.lastname@example.org
If you submit inquiries to us via our contact form, the information provided in the contact form as well as any contact information provided therein will be stored by us in order to handle your inquiry and in the event that we have further questions. We will not share this information without your consent.
The processing of these data is based on art. 6 para. 1 p. 1 lit. b GDPR, if your request is related to the execution of a contract or if it is necessary to carry out pre-contractual measures. In all other cases the processing is based on our legitimate interest in the effective processing of the requests addressed to us (art. 6 para. 1 p. 1 lit. f GDPR) or on your consent (art. 6 para. 1 p. 1 lit. a GDPR) if this has been requested.
The information you have entered into the contact form shall remain with us until you ask us to eradicate the data, revoke your consent to the archiving of data or if the purpose for which the information is being archived no longer exists (e.g., after we have concluded our response to your inquiry). This shall be without prejudice to any mandatory legal provisions, in particular retention periods.
REQUEST BY E-MAIL, TELEPHONE
If you contact us by email/phone your request, including all resulting personal data (name, request) will be stored and processed by us for the purpose of processing your request. We do not pass these data on without your consent.
These data are processed on the basis of art. 6 para. 1 p. 1 lit. b GDPR if your inquiry is related to the fulfillment of a contract or is required for the performance of pre-contractual measures. In all other cases, the data are processed on the basis of our legitimate interest in the effective handling of inquiries submitted to us (art. 6 para. 1 p. 1 lit. f GDPR) or on the basis of your consent (art. 6 para. 1 p. 1 lit. a GDPR) if it has been requested. The data sent by you to us via contact requests remain with us until you request us to delete, revoke your consent to the storage or the purpose for the data storage lapses (e.g. after completion of your request). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
HOSTING WITH Hetzner
We use Hetzner on the basis of Art. 6 para. 1 p. 1 lit. f GDPR. We have a legitimate interest in the most reliable depiction of our website possible. If appropriate consent has been obtained, the processing is carried out exclusively on the basis of Art. 6 para. 1 p. 1 lit. f GDPR and § 25 (1) TTDSG, insofar the consent includes the storage of cookies or the access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TTDSG. This consent can be revoked at any time.
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.
Cookies have a variety of functions. Many cookies are technically essential since certain website functions would not work in the absence of the cookies (e.g., the shopping cart function or the display of videos). The purpose of other cookies may be the analysis of user patterns or the display of promotional messages. Cookies, which are required for the performance of electronic communication transactions (required cookies) or for the provision of certain functions you want to use (functional cookies, e.g., for the shopping cart function) or those that are necessary for the optimization of the website (e.g. cookies that provide measurable insights into the web audience), shall be stored on the basis of art. 6 para. 1 p. 1 lit. f GDPR, unless a different legal basis is cited. The operator of the Website has a legitimate interest in the storage of cookies to ensure the technically error free and optimized provision of the operator’s services. If your consent to the storage of the cookies has been requested, the respective cookies are stored exclusively on the basis of the consent obtained ( art. 6 para. 1 p. 1 lit. a GDPR); this consent may be revoked at any time.
You have the option to set up your browser in such a manner that you will be notified any time cookies are placed and to permit the acceptance of cookies only in specific cases. You may also exclude the acceptance of cookies in certain cases or in general or activate the delete function for the automatic eradication of cookies when the browser closes. If cookies are deactivated, the functions of this Website may be limited. In the event that third-party cookies are used or if cookies are used for analytical purposes, we will separately notify you in conjunction with this Privacy and, if applicable, ask for your consent.
Our cookies consent tool (Cookies settings) contains a detailed description of the optional cookies we use. You may at any time object to the setting of optional cookies by using the respective objection option: Cookies settings
CONSENT WITH BORLABS COOKIE
Our Website uses the Borlabs consent technology to obtain your consent to the storage of certain cookies in your browser or for the use of certain technologies and for their data privacy protection compliant documentation. The provider of this technology is Borlabs – Benjamin A. Bornschein, Rübenkamp 32, 22305 Hamburg, Germany (hereinafter referred to as Borlabs).
Whenever you visit our Website, a Borlabs cookie will be stored in your browser, which archives any declarations or revocations of consent you have entered. These data are not shared with the provider of the Borlabs technology.
The recorded data shall remain archived until you ask us to eradicate them, delete the Borlabs cookie on your own or the purpose of storing the data no longer exists. This shall be without prejudice to any retention obligations mandated by law. To review the details of Borlabs’ data processing policies, please visit <a href=“https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/“>https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/</a>
SERVER LOG FILES
The provider of this Website automatically collects and stores information in so-called server log files, which your browser communicates to us automatically. The information comprises:
This data is not merged with other data sources. This data is recorded on the basis of art. 6 para. 1 p. 1 lit. f GDPR. We have a legitimate interest in the technically error free depiction and the optimization of the Website. In order to achieve this, server log files must be recorded.
LINKS TO THIRD PARTY WEBSITES
Certain links within the Website or the Site may lead to other independent companies. We will never share your personal information with these third party companies.
Links to third party websites provided are provided as a service to you. We have no control over these sites or over their privacy practices, which may differ from ours. We do not endorse and are not responsible for any content on third party sites that may be accessed through our Site.
Here we inform you about which plugins or tools we use for statistical or advertising purposes on the Website.
Google Analytics 4
This Website uses functions of the web analysis service Google Analytics ( Google Analytics 4). The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyse the behaviour patterns of website visitors. To that end, the website operator receives a variety of user data, such as pages accessed, time spent on the page, the utilised operating system and the user’s origin. This data is summarised in a user-ID and assigned to the respective end device of the website visitor.
Furthermore, Google Analytics allows us to record your mouse and scroll movements and clicks, among
other things. Google Analytics uses various modelling approaches to augment the collected data sets and
uses machine learning technologies in data analysis.
Google Analytics uses technologies that make the recognition of the user for the purpose of analysing the user behaviour patterns (e.g., cookies or device fingerprinting). The Website use information recorded by Google and is, as a rule, transferred to a Google server in the United States, where it is stored.
All processing described above, in particular the setting of Google Analytics cookies for the storage and reading of information on the end device used by you for the use of the Website, only takes place if you have given us your express consent for this in accordance with art. 6 para. 1 p.1 lit. a GDPR and § 25 (1) TTDSG, insofar the consent includes the storage of cookies or the access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TTDSG. Without your consent, Google Analytics will not be used during your use of the Website. You can revoke your consent at any time with effect for the future.
To exercise your revocation, please deactivate this service via the cookie consent tool provided on the website (Cookies Settings).
In connection with this Website, the „UserIDs“ function is also used as an extension of Google Analytics 4. By assigning individual UserIDs, we can have Google create cross-device reports (so-called „cross-device tracking“). This means that your usage behaviour can also be analysed across devices if you have given your corresponding consent to the use of Google Analytics 4 in accordance with art. 6 para. 1 lit. a GDPR, if you have set up a personal account by registering on this Website and are logged into your personal account on different end devices with your relevant login data. The data collected in this way shows, among other things, on which end device you clicked on an ad for the first time and on which end device the relevant conversion took place.
Otherwise Google Analytics may be used on the basis of art. 6 para. 1 p. 1 lit. f GDPR. As operator of this Website we have a legitimate interest in the analysis of user patterns to optimise both, the services offered online and the operator’s advertising activities.
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.
On this Website, we have activated the IP anonymization function. That means that your IP address is shortened beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google LLC.server in the USA and shortened there. On behalf of the operator of this Website, Google shall use this information to analyse your use of this Website to generate reports on Website activities and to render other services to the operator of this Website that are related to the use of the Website and the Internet. The IP address transmitted in conjunction with Google Analytics from your browser shall not be merged with other data in Google’s possession.
Browser plug-in and Opt Out
You can prevent the recording and processing of your data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
For more information about the handling of user data by Google Analytics, please consult Google’s Data Privacy Declaration at: https://support.google.com/analytics/answer/6004245?hl=en.
Google Analytics also enables the creation of statistics with statements about the age, gender and interests of site visitors on the basis of an evaluation of interest-based advertising and with the inclusion of third-party information via a special function, the so-called „demographic characteristics“. This allows the definition and differentiation of user groups of the Website for the purpose of targeting marketing measures. However, data records collected via the „demographic characteristics“ cannot be assigned to a specific person.
You have the option to deactivate this function at any time by making pertinent settings changes for advertising in your Google account or you can generally prohibit the recording of your data by Google Analytics as explained in section “Objection to the recording of data”.
The retention period of the data depends on the properties used. When using the Google Analytics 4 properties, the retention period of your user data is fixed at 14 months. For other so-called event data, we have the option to choose a retention period of 2 months or 14 months.
In addition, there is also the option for data to be deleted only when you no longer visit our Website within the period we have chosen. In this case, the retention period will be reset each time you visit our Website again within the specified period.
Once the specified period has expired, the data is deleted once a month. This retention period applies to your data associated with cookies, user recognition and advertising IDs (e.g. DoubleClick domain cookies). Reporting results are based on aggregated data and are stored separately from user data. Aggregated data is a merging of individual data into a larger unit.
For details, please click the following link: https://support.google.com/analytics/answer/7667196?hl=en
We have executed a contract data processing agreement with Google and are implementing the stringent provisions of the German data protection authorities to the fullest when using Google Analytics.
We use the open source programme Umami Analytics on our Website, hosted on our local server, to track general trends in the use of our website. This is an open source software that allows us to analyze the use of our website. your IP address, the website(s) you visit on our website, the website from which you linked to our website (referrer URL), the time you spend on our website and the frequency with which you visit one of our websites are processed. All data is collected anonymously so that no conclusions can be drawn about your person. The data is stored on our local server in Germany and is not passed on.
Umami Analytics only collects aggregate information that does not allow us to identify any visitor to our website. For more information, please see documentation for Umami Analytics at: https://umami.is/.
The legal basis is art. 6 para. 1 p. 1 lit. f DSGVO. Our legitimate interest lies in the analysis and optimisation of our website.
PLUG-INS AND TOOLS
YouTube with expanded data protection integration
This Website embeds videos of the website YouTube. The website operator is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
If you visit a page on this Website into which a YouTube has been embedded, a connection with YouTube’s servers will be established. As a result, the YouTube server will be notified, which of our pages you have visited. Furthermore, YouTube will be able to place various cookies on your device or comparable technologies for recognition (e.g. device fingerprinting). In this way YouTube will be able to obtain information about this website’s visitors. Among other things, this information will be used to generate video statistics with the aim of improving the user friendliness of the site and to prevent attempts to commit fraud. If you are logged into your YouTube account while you visit our site, you enable YouTube to directly allocate your browsing patterns to your personal profile. You have the option to prevent this by logging out of your YouTube account.
The use of YouTube is based on our interest in presenting our online content in an appealing manner. Pursuant to art. 6 para. 1 p. 1 lit. f GDPR, this is a legitimate interest. If a corresponding agreement has been requested, the processing takes place exclusively on the basis of art. 6 para. 1 p. 1 lit. a GDPR; the agreement can be revoked at any time.
We use YouTube in the expanded data protection mode. According to YouTube, this mode ensures that YouTube does not store any information about visitors to this Website before they watch the video.
Nevertheless, this does not necessarily mean that the sharing of data with YouTube partners can be ruled out as a result of the expanded data protection mode. For instance, regardless of whether you are watching a video, YouTube will always establish a connection with the Google DoubleClick network. As soon as you start to play a YouTube video on this Website, a connection to YouTube’s servers will be established. As a result, the YouTube server will be notified, which of our pages you have visited. If you are logged into your YouTube account while you visit our site, you enable YouTube to directly allocate your browsing patterns to your personal profile. You have the option to prevent this by logging out of yourYouTube account.
Furthermore, after you have started to play a video, YouTube will be able to place various cookies on your device or comparable technologies for recognition (e.g. device fingerprinting). In this way YouTube will be able to obtain information about this website’s visitors. Among other things, this information will be used to generate video statistics with the aim of improving the user friendliness of the site and to prevent attempts to commit fraud.
Google Web Fonts (local embedding)
This Website uses so-called Web Fonts provided by Google to ensure the uniform use of fonts on this site.
These Google fonts are locally installed so that a connection to Google’s servers will not be established in conjunction with this application. For more information on Google Web Fonts, please follow this link:
https://developers.google.com/fonts/faq and consult Google’s Data Privacy Declaration under: https://policies.google.com/privacy?hl=en.
OUR SOCIAL MEDIA APPEARANCES
Data Processing Through Social Networks
We maintain publicly available profiles in social networks. The individual social networks we use can be found below.
On the Website we link to the online presence of the different social media. Our icon in this regard acts as an external link, so that no information is transmitted to the social media (e.g. LinkedIn) without clicking on the icon. When the user clicks on the icon, the User is redirected to the website of the respective provider. The URL of the current page is transferred as a parameter. We have no influence on whether or how the different social media (e.g. LinkedIn) use this date for evaluation. If you do not want the different social media to collect information about the use of our Website, please do not click on the social media icons.
Social networks such as Facebook, Instagram, LinkedIn etc. can generally analyze your user behavior comprehensively if you visit their website or a website with integrated social media content (e.g. like buttons or banner ads). When you visit our social media pages, numerous data protection-relevant processing operations are triggered. In detail: If you are logged in to your social media account and visit our social media page, the operator of the social media portal can assign this visit to your user account. Under certain circumstances, your personal data may also be recorded if you are not logged in or do not have an account with the respective social media portal. In this case, this data is collected, for example, via cookies stored on your device or by recording your IP address.Using the data collected in this way, the operators of the social media portals can create user profiles in which their preferences and interests are stored. This way you can see interest-based advertising inside and outside of your social media presence. If you have an account with the social network, interest-based advertising can be displayed on any device you are logged in to or have logged in to.
Legal basis: Our social media appearances should ensure the widest possible presence on the Internet. This is a legitimate interest within the meaning of art. 6 para. 1 p. 1 lit. f GDPR. The analysis processes initiated by the social networks may be based on divergent legal bases to be specified by the operators of the social networks (e.g. consent within the meaning of art. 6 para. 1 p. 1 lit. a GDPR).
Responsibility and assertion of rights: If you visit one of our social media sites (e.g., Facebook), we, together with the operator of the social media platform, are responsible for the data processing operations triggered during this visit. You can in principle protect your rights (information, correction, deletion, limitation of processing, data portability and complaint) vis-à-vis us as well as vis-à-vis the operator of the respective social media portal (e.g. Facebook).
Please note that despite the shared responsibility with the social media portal operators, we do not have full influence on the data processing operations of the social media portals. Our options are determined by the company policy of the respective provider.
Storage time: The data collected directly from us via the social media presence will be deleted from our systems as soon as the purpose for their storage lapses, you ask us to delete it, you revoke your consent to the storage. Stored cookies remain on your device until you delete them. Mandatory statutory provisions – in particular, retention periods – remain unaffected.
Individual Social Networks
We have a LinkedIn profile. The provider is the LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.
If you want to disable LinkedIn advertising cookies, please use the following link:
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.
Last update: February 7, 2022