Privacy policy
This privacy policy informs you about the type, scope and purpose of the processing of personal data (hereinafter referred to as “data”) within our online offering and the websites, functions and content associated with it, as well as external online presences such as our social media profiles (collectively referred to as the “online offering”). With regard to the terminology used, such as “processing” or “controller”, we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Controller
AT-Verband
WaldburgstraĂźe 96
D-70563 Stuttgart
Phone: +49 (0)
711-7355282
Fax: +49 (0) 711-7355280
Email: info@at-verband.de
Website:
www.at-verband.de
Authorised representative and chairperson: Dieter Steinbach
Registered
association (e.V.)
Register of associations: VR4586
Types of data processed
- Inventory data (e.g. names, addresses).
- Contact data (e.g. email addresses, telephone numbers).
- Content data (e.g. text entries, photographs, videos).
- Usage data (e.g. websites visited, interest in content, access times).
- Meta/communication data (e.g. device information, IP addresses).
Categories of data subjects
Visitors and users of the online offering (hereinafter we also collectively refer to the data subjects as “users”).
Purpose of processing
- Provision of the online offering, its functions and content.
- Responding to contact enquiries and communicating with users.
- Security measures.
- Reach measurement.
Terminology used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); a natural person is regarded as identifiable if he or she can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.
“Pseudonymisation” means the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data cannot be attributed to an identified or identifiable natural person.
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
“Controller” means the natural or legal person, authority, institution or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
“Processor” means a natural or legal person, authority, institution or other body which processes personal data on behalf of the controller.
Relevant legal bases
In accordance with Article 13 GDPR, we inform you of the legal bases of our data processing. Unless the legal basis is explicitly stated in this privacy policy, the following applies: the legal basis for obtaining consent is Article 6(1)(a) and Article 7 GDPR; the legal basis for processing for the performance of our services and contractual measures as well as for responding to enquiries is Article 6(1)(b) GDPR; the legal basis for processing for compliance with our legal obligations is Article 6(1)(c) GDPR; and the legal basis for processing in order to safeguard our legitimate interests is Article 6(1)(f) GDPR. If vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) GDPR serves as the legal basis.
Security measures
In accordance with Article 32 GDPR, and taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input of, disclosure of, safeguarding of availability of and separation of the data. Furthermore, we have established procedures to ensure that data subjects can exercise their rights, that data can be deleted and that we can respond to data risks. We also take the protection of personal data into account when developing or selecting hardware, software and procedures, in line with the principles of data protection by design and by default (Article 25 GDPR).
Cooperation with processors and third parties
If, within the scope of our processing, we disclose data to other persons or companies (processors or third parties), transfer data to them or otherwise grant them access to the data, this is done only on the basis of a legal permission (for example where a transfer of data to third parties, such as payment service providers, is necessary for contract performance pursuant to Article 6(1)(b) GDPR), where you have consented, where a legal obligation requires it, or on the basis of our legitimate interests (for example when using agents, web hosts, etc.).
If we commission third parties to process data on the basis of a so-called data processing agreement, this is done on the basis of Article 28 GDPR.
Transfers to third countries
If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this takes place in the context of using third-party services or disclosing or transferring data to third parties, this is done only if it is necessary for the fulfilment of our (pre-)contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests.
Subject to legal or contractual permissions, we process or have data processed in a third country only if the special requirements of Articles 44 et seq. GDPR are met. This means, for example, that processing takes place on the basis of special guarantees such as an officially recognised determination of a level of data protection equivalent to that of the EU (e.g. for the USA through the “Privacy Shield”) or compliance with officially recognised specific contractual obligations (so-called “standard contractual clauses”).
Rights of data subjects
You have the right to request confirmation as to whether the relevant data is being processed and to obtain information about this data as well as further information and a copy of the data in accordance with Article 15 GDPR. In accordance with Article 16 GDPR, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you. In accordance with Article 17 GDPR, you have the right to request that the relevant data be deleted without undue delay or, alternatively, to request a restriction on the processing of the data in accordance with Article 18 GDPR.
You also have the right to request that the data concerning you which you have provided to us be received in accordance with Article 20 GDPR and to request its transmission to other controllers. Furthermore, pursuant to Article 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.
Right of withdrawal
You have the right to withdraw consent granted in accordance with Article 7(3) GDPR with effect for the future.
Right to object
You may object at any time to the future processing of data concerning you in accordance with Article 21 GDPR. In particular, you may object to processing for the purposes of direct marketing.
Cookies and the right to object to direct advertising
“Cookies” are small files that are stored on users’ computers. Different information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after his or her visit to an online offering. Temporary cookies, also known as “session cookies” or “transient cookies”, are cookies that are deleted after a user leaves an online offering and closes the browser. Such a cookie may, for example, store the contents of a shopping basket in an online shop or a login status.
“Permanent” or “persistent” cookies are cookies that remain stored even after the browser has been closed. For example, the login status can be stored if users visit the website several days later. Likewise, user interests may be stored in such a cookie and used for reach measurement or marketing purposes. “Third-party cookies” are cookies offered by providers other than the controller operating the online offering (otherwise, if only the controller’s own cookies are involved, they are referred to as “first-party cookies”).
We may use temporary and permanent cookies and provide information about them within this privacy policy. If users do not want cookies to be stored on their computers, they are asked to deactivate the relevant option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Excluding cookies may lead to functional restrictions of this online offering.
A general objection to the use of cookies used for online marketing purposes can be declared for a large number of services, especially in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. In addition, cookies can be prevented from being stored by switching them off in the browser settings. Please note that in this case not all functions of this online offering may be available.
Deletion of data
The data processed by us will be deleted or its processing restricted in accordance with Articles 17 and 18 GDPR. Unless expressly stated otherwise in this privacy policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and no statutory retention obligations prevent deletion. If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for other purposes.
This applies, for example, to data that must be retained for commercial or tax law reasons. According to legal requirements in Germany, retention is carried out in particular for 10 years pursuant to Sections 147(1) AO and 257(1) nos. 1 and 4, para. 4 HGB (books, records, management reports, accounting documents, commercial books, documents relevant for taxation, etc.) and for 6 years pursuant to Section 257(1) nos. 2 and 3, para. 4 HGB (commercial letters). According to legal requirements in Austria, retention is carried out in particular for 7 years pursuant to Section 132(1) BAO (accounting documents, receipts/invoices, accounts, business papers, statements of income and expenses, etc.), for 22 years in connection with real estate and for 10 years for records relating to electronically supplied services, telecommunications, radio and television services supplied to non-taxable persons in EU member states and for which the Mini-One-Stop-Shop (MOSS) is used.
Provision of our services in accordance with our statutes and business activities
We process the data of our members, supporters, interested parties, customers and other persons in accordance with Article 6(1)(b) GDPR if we offer them contractual services or act within the framework of existing business relationships, for example vis-Ă -vis members, or if we ourselves are recipients of services and benefits. Otherwise, we process the data of data subjects pursuant to Article 6(1)(f) GDPR on the basis of our legitimate interests, for example where administrative tasks or public relations work are involved.
The data processed in this context, the type, scope, purpose and necessity of processing are determined by the underlying contractual relationship. This generally includes personal master data (e.g. name, address, etc.), contact data (e.g. email address, telephone number, etc.), contractual data (e.g. services used, content and information communicated, names of contact persons) and, if we offer services or products for which payment is required, payment data (e.g. bank details, payment history, etc.).
We delete data that is no longer required for the fulfilment of our statutory and business purposes. This is determined according to the respective tasks and contractual relationships. In the case of business processing, we retain the data for as long as it may be relevant for business transactions and with regard to any warranty or liability obligations. The necessity of retaining the data is reviewed every three years; in all other respects, the statutory retention obligations apply.
Contacting us
When contacting us (e.g. by contact form, email, telephone or via social media), the user’s details are processed for the purpose of handling the contact enquiry and its processing in accordance with Article 6(1)(b) GDPR. The user’s details may be stored in a customer relationship management system (“CRM system”) or a comparable enquiry organisation.
We delete enquiries if they are no longer required. We review the necessity every two years; statutory archiving obligations also apply.
Cookie settings on this website
This website uses a consent dialog for optional categories. Essential cookies are required for the technical operation of the website. Optional categories such as statistics, marketing or external media are only activated after your explicit consent. You can change or withdraw your selection at any time via the “Cookie settings” link in the footer.
