This privacy policy informs you about the nature, scope, and purpose of processing personal data within our online services, associated websites, functions, and content (hereinafter referred to as “data”). For the definitions of terms such as “processing” or “controller,” please refer to Article 4 of the General Data Protection Regulation (GDPR).
Controller: Christoph Kunz, Verax Institute, Rugenstrasse 19, 3800 Matten BE, Switzerland
Types of data processed:
- Master data (e.g., names and addresses).
- Contact data (e.g., email addresses and telephone numbers).
- Content data (e.g., text entries, photographs, and videos).
- Usage data (e.g., websites visited, interest in content, access times).
- Metadata/communication data (e.g., device information, IP addresses).
Data Subject Categories
Visitors and users of the online service (hereinafter, we will refer to the data subjects collectively as “users”).
Purpose of processing:
- Provision of the online service, its functions, and content.
- Responding to contact requests and communicating with users.
- Security measures. Audience measurement/marketing
Definitions Used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”). An identifiable natural person is someone who can be identified, either directly or indirectly, particularly by reference to an identifier, such as a name, identification number, location data, online identifier (e.g., cookies), or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural, or social identity.
“Processing” refers to any operation or set of operations performed on personal data, whether automated or manual. This broad term encompasses virtually any handling of data.
“Pseudonymization” refers to processing personal data so that it can no longer be attributed to a specific data subject without the use of additional information. This information must be kept separately and be subject to technical and organizational measures that ensure the data is not attributed to an identified or identifiable natural person.
“Profiling” refers to any form of automated processing of personal data that involves using personal data to evaluate certain personal aspects relating to a natural person. This can include analyzing or predicting aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
The term “controller” refers to a natural or legal person, public authority, agency, or other body that determines the purposes and means of processing personal data, either alone or jointly with others.
“Processor” refers to a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Relevant Legal Bases
In accordance with Article 13 of the GDPR, we are informing you of the legal basis for our data processing. Unless otherwise stated in this privacy policy, the following applies: The legal basis for obtaining consent is Articles 6(1)(a) and 7 of the GDPR. The legal basis for processing data to provide services, implement contractual measures, and respond to inquiries is Article 6(1)(b). The legal basis for processing data to comply with legal obligations is Article 6(1)(c). The legal basis for processing data to protect legitimate interests is Article 6(1)(f). When processing personal data is necessary to protect the vital interests of the data subject or another person, Article 6(1)(d) of the GDPR serves as the legal basis.
Security Measures
In accordance with Article 32 of the GDPR, and taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security that is appropriate to the risk.
These measures include ensuring the confidentiality, integrity, and availability of data by controlling physical access to it, as well as access to, input of, and disclosure of it, and ensuring its availability and separation. Furthermore, we have established procedures to ensure the exercise of data subject rights, the erasure of data, and the response to data breaches. In accordance with the principles of data protection by design and by default (Article 25 of the GDPR), we also consider the protection of personal data during the development and selection of hardware, software, and processes.
Cooperation with Processors and Third Parties
In the course of processing, we may disclose data to other persons and companies (processors or third parties), transmit it to them, or otherwise grant them access to the data. This is done only on the basis of legal permission. For example, the transfer of data to third parties, such as payment service providers, may be necessary for the performance of a contract pursuant to Art. 6 para. 1 lit. b GDPR), with your consent, due to a legal obligation, or based on our legitimate interests (e.g., when using agents, web hosts, etc.).
If we commission third parties to process data, we do so on the basis of a “data processing agreement” pursuant to Art. 28 GDPR.
Transfers to Third Countries
We will only process data in a third country (i.e., outside the European Union (EU) or the European Economic Area [EEA]) if it is necessary for the performance of our (pre-)contractual obligations, based on your consent, due to a legal obligation, or based on our legitimate interests. This includes processing data in the context of using third-party services or disclosing or transferring data to third parties. Subject to legal or contractual permissions, we will only process data or have data processed in a third country if the special requirements of Art. 44 et seq. GDPR are met. For example, processing must be based on special guarantees, such as an official finding that the level of data protection is equivalent to that of the EU (e.g., for the U.S. through the “Privacy Shield”), or compliance with specific contractual obligations (“standard contractual clauses”).
Rights of Data Subjects
In accordance with Article 15 of the GDPR, you have the right to request confirmation as to whether personal data concerning you is being processed, as well as access to this data and further information. You also have the right to a copy of the data.
According to Article 16, you have the right to request completion of your incomplete personal data or rectification of your inaccurate personal data.
According to Article 17, you have the right to request the erasure of your personal data without undue delay. Alternatively, according to Article 18, you have the right to request the restriction of the processing of your personal data.
In accordance with Article 20 of the GDPR, you have the right to receive the personal data that you have provided to us and to request its transmission to another controller.
Furthermore, in accordance with Article 77 of the GDPR, you have the right to lodge a complaint with the relevant supervisory authority.
Right of withdrawal
You have the right to withdraw any consent you have given under Article 7. 7, para. 3 of the GDPR, with effect for the future.
Right to object
You can object to the future processing of your personal data at any time in accordance with Art. 21 GDPR. The objection can be made, in particular, against processing for direct marketing purposes.
Cookies and the Right to Object to Direct Marketing
Cookies are small files stored on users’ computers. Various types of information can be stored within them. Cookies primarily serve to store information about users (or the devices on which they are stored) during and after their visits to online services. Temporary cookies, also known as “session” or “transient” cookies, are deleted when a user leaves an online service and closes their browser. For example, such a cookie might store the contents of a shopping cart in an online store or a login status. “Permanent” or “persistent” cookies remain stored even after the browser is closed. These cookies can be used to store login status, allowing users to remain logged in when they return to the site after several days, for example. Similarly, user interests can be stored in a permanent cookie for audience measurement or marketing purposes. Third-party cookies are offered by providers other than the website operator. Otherwise, they are called first-party cookies.
We use temporary and persistent cookies, as explained in our privacy policy.
Users who do not want cookies stored on their computer are asked to deactivate the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Disabling cookies may limit this website’s functionality.
You can declare a general objection to the use of cookies for online marketing purposes, especially tracking, for many services via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Additionally, you can prevent the storage of cookies by disabling them in your browser settings. Please note that some features of this online service may be unavailable if you do not comply with these terms.
Data Deletion
In accordance with Articles 17 and 18 of the GDPR, the data we process will be deleted or its processing restricted. Unless this privacy policy expressly states otherwise, we will delete the data we store as soon as it is no longer required for its intended purpose and there are no legal obligations to retain it. If the data cannot be deleted because it is required for other legally permissible purposes, its processing will be restricted. This means the data will be blocked and not processed for other purposes. This applies to data that must be retained for commercial or tax law reasons, for example.
In accordance with German legal requirements, records are retained for ten years, particularly pursuant to Sections 147, Paragraph 1, AO; 257, Paragraph 1, Nos. 1 and 4; and Paragraph 4, HGB (books, records, management reports, accounting documents, ledgers, tax-relevant documents, etc.), and for six years, pursuant to Sections 257, Paragraph 1, Nos. 2 and 3; and Paragraph 4, HGB (commercial correspondence).
Provision of our statutory and business services
In accordance with Article 6(1)(b) GDPR, we process the data of our members, supporters, prospective members, customers, and other individuals if we offer them contractual services, act within the framework of an existing business relationship (e.g., with members), or are recipients of services and contributions. Furthermore, we process data based on legitimate interests in accordance with Article 6(1)(f) GDPR, e.g., for administrative tasks or public relations.
The nature, scope, and purpose of the data processed, as well as the necessity of its processing, are determined by the underlying contractual relationship. This includes personal data (e.g., name and address), contact information (e.g., email address and telephone number), contract data (e.g., services used and information and content provided), and payment data (e.g., bank details and payment history) if we offer payment-based services or products.
We delete data that is no longer required to fulfill our statutory and business purposes. This is determined according to the respective tasks and contractual relationships. In the case of business processing, we retain the data for as long as it may be relevant for business transactions, as well as with regard to any warranty or liability obligations. We review the necessity of retaining the data every three years; otherwise, the statutory retention periods apply.
Registration Function
Users can create an account. During registration, users are informed of the mandatory information required, which is processed in accordance with Article 6, Paragraph 1, Letter b of the GDPR for the purpose of providing the account. This data includes login information such as name, password, and email address. This data is used for the intended purpose of the user account.
Users may receive emails with information relevant to their account, such as technical updates. Once a user account is terminated, the associated data will be deleted, unless there are any statutory retention obligations. Users are responsible for backing up their data before the end of the contract if they terminate their account. We are entitled to irretrievably delete all user data stored during the contract period.
When using our registration and login functions, as well as the user account, we store the IP address and time of each user action. This data is stored based on our legitimate interests and the users’ interest in protection against misuse and unauthorized use. This data is generally not shared with third parties unless it is necessary to pursue our claims or if we are legally obligated to do so pursuant to Art. 6, para. 1 lit. c GDPR. IP addresses are anonymized or deleted within seven days.
Contacting Us
When you contact us via the contact form, email, telephone, or social media, the information you provide will be processed to handle and resolve your inquiry in accordance with Art. 6, para. 1 lit. b (within the framework of contractual/pre-contractual relationships) and Art. 6, para. 1 lit. f GDPR. Your information may be stored in a customer relationship management (“CRM”) system or a comparable system for managing inquiries.
We delete inquiries when they are no longer needed. We review the necessity of retaining inquiries every two years, and statutory archiving obligations also apply.
Newsletter
The following information details the content of our newsletter and explains our registration, distribution, and statistical analysis procedures. It also outlines your right to object. By subscribing, you agree to receive the newsletter and accept the described procedures.
Newsletter content: We send newsletters, emails, and other electronic notifications containing promotional information (“newsletter”) only with the recipient’s consent or based on legal permission. If the newsletter’s content is described during the registration process, that description is decisive for the user’s consent. Otherwise, our newsletters contain information about our services and company.
Double Opt-In and Logging: Registration for our newsletter uses a double opt-in process. This means that, after registering, you will receive an email asking you to confirm your subscription. This confirmation is necessary to prevent someone from subscribing with a different email address. We log newsletter subscriptions to document the registration process in accordance with legal requirements. This includes storing the registration and confirmation times, as well as the IP address. Changes to your data stored with the email service provider are also logged.
Registration Data: To subscribe to the newsletter, you only need to provide your email address. You have the option of providing a name for personalized addressing in the newsletter.
The newsletter is sent and its performance is measured based on recipients’ consent pursuant to Art. 6, para. 1 lit. a, Art. 7 of the GDPR, in conjunction with Section 7, Paragraph 2, Number 3 of the German Act Against Unfair Competition (UWG). If consent is not required, it is based on our legitimate interests in direct marketing, pursuant to Article 6, Paragraph 1, Letter f of the GDPR. 6 para. 1 lit. f GDPR and Section 7, para. 3 UWG.
The registration process is logged based on our legitimate interests pursuant to Art. 6(1)(f) GDPR. 1 lit. f GDPR. We are interested in using a user-friendly and secure newsletter system that serves our business interests, meets user expectations, and allows us to document consent.
Unsubscribe/Revocation: You can unsubscribe from our newsletter at any time and revoke your consent. You will find an unsubscribe link at the end of each newsletter. Based on our legitimate interests, we may store unsubscribed email addresses for up to three years before deleting them, in order to be able to prove previously given consent. We only process this data for the purpose of defending against potential claims. You may request deletion of your data at any time, provided that the prior existence of consent is confirmed.
Newsletter – Mailchimp & Substack
The newsletter is sent via MailChimp, a newsletter distribution platform owned by the U.S. company Rocket Science Group, LLC, located at 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308. You can view the data protection policy of the email service provider here: https://mailchimp.com/legal/privacy/. Rocket Science Group LLC d/b/a MailChimp is certified under the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, guaranteeing compliance with European data protection standards (https://www.dataprivacyframework.gov, https://www.edpb.europa.eu/system/files/2024-07/edpb_dpf_faq-for-businesses_en.pdf, https://www.news.admin.ch/de/nsb?id=102054). We use the email service provider based on our legitimate interests pursuant to Art. 6, para. 1 lit. f GDPR and a data processing agreement pursuant to Art. 28, para. 3 sentence 1 GDPR.
Substack Inc.: Email Marketing Platform
111 Sutter Street, 7th Floor
San Francisco, CA 94104
USA
T: +1 (415) 592-7299
The email service provider may use recipient data in pseudonymized form — i.e., without linking it to a specific user — to optimize or improve its own services. Examples include technical optimization of newsletter delivery and display or statistical purposes. However, the email service provider does not use the data of our newsletter recipients to contact them directly or share it with third parties.
Newsletter – Performance Measurement
The newsletters contain a “web beacon,” which is a pixel-sized file retrieved from our server (or, if we use an email service provider, their server) when the newsletter is opened. During this process, technical information, such as your browser and system information, IP address, and the time of retrieval, is collected.
We use this information to improve our services based on technical data and to analyze target groups and their reading behavior based on their locations (determined using the IP address) or access times. Statistical analysis also includes determining whether newsletters are opened and which links are clicked. Although this information can be associated with individual newsletter recipients, neither we nor the mailing service provider intend to monitor individual users. Rather, these analyses help us understand our users’ reading habits so we can tailor our content accordingly or send different content based on our users’ interests.
Unfortunately, it is not possible to revoke consent for performance tracking separately; in this case, you must cancel your entire newsletter subscription.
Hosting and Email Delivery
We use hosting services to provide infrastructure and platform services, computing capacity, storage space, database services, email delivery, security services, and technical maintenance services for operating this online service.
During this process, we or our hosting provider process the inventory, contact, content, contract, usage, meta, and communication data of customers, prospective customers, and visitors to this online service based on our legitimate interest in efficiently and securely providing this online service pursuant to Art. 6, para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).
Collection of Access Data and Log Files
Based on our legitimate interests within the meaning of Art. 6 para. 1 lit. f DSGVO, we (or rather our hosting provider) collect data about every access to the server on which this service is located (so-called server log files). 6, para. 1 lit. f GDPR. This access data includes the name of the accessed website or file, the date and time of access, the amount of data transferred, a notification of successful access, the type and version of the browser, the user’s operating system, the referrer URL (the previously visited page), the IP address, and the requesting provider.
Log file information is stored for a maximum of seven days for security reasons (e.g., to investigate misuse or fraud) and then deleted. Data whose further retention is required for evidentiary purposes is exempt from deletion until the final resolution of the respective incident.
Integration of Third-Party Services and Content
This is based on our legitimate interests, i.e., our interest in analyzing, optimizing, and economically operating our online services, as defined in Art. 6 para. 1 lit. f GDPR), we integrate the content and services of third-party providers into our online services, including videos and fonts, among other things. This content and services are referred to collectively as “Content.”
This requires the third-party providers of this content to be aware of users’ IP addresses because they cannot send content to browsers without IP addresses. Therefore, the IP address is necessary for displaying this content. We strive to use only content from providers who use IP addresses solely for delivering content. Third-party providers may also use pixel tags, which are invisible graphics also known as “web beacons,” for statistical or marketing purposes. These pixel tags allow information such as visitor traffic on the pages of this website to be evaluated. This pseudonymous information may be stored in cookies on users’ devices and can include technical information about the browser and operating system, referring websites, time of visit, and other information about the use of our online services. It may also be combined with information from other sources.
Vimeo
We may embed videos from the Vimeo platform, which is provided by Vimeo, Inc. Legal Department
555 West 18th Street
New York, NY 10011
USA For more information, see the privacy policy: https://vimeo.com/privacy. Please note that Vimeo may use Google Analytics. For more information, refer to Google’s privacy policy (https://www.google.com/policies/privacy) and opt-out options (http://tools.google.com/dlpage/gaoptout?hl=de) for Google Analytics, or Google’s settings for data usage for marketing purposes (https://adssettings.google.com/).
Google reCAPTCHA
We have integrated a bot detection feature (e.g., reCAPTCHA) for online form entries, which is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). For more information, see the Privacy Policy: https://www.google.com/policies/privacy/. To opt out, visit: https://adssettings.google.com/authenticated.
This was adapted by the website owner and created with the help of the Datenschutz-Generator.de tool by attorney Dr. Thomas Schwenke.
.
