Privacy Policy
This privacy policy is intended to inform you about how we process personal data and to explain your rights. We are aware of the importance of processing personal data for you as a user and therefore comply with all relevant legal requirements. The protection of your privacy is of utmost importance to us. We process your personal data in compliance with the General Data Protection Regulation and the data protection provisions of the federal state.
Data controller
Carl Bosch Museum gGmbH
Schloss-Wolfsbrunnenweg 46
69118 Heidelberg
Phone: +49 (6221) 603616
Fax: +49 (6221) 603618
Email: kontakt(at)carl-bosch-museum.de
Contact details of the data protection officer: eprivacy@carl-bosch-museum.de
Definitions
This privacy policy uses the terminology of the General Data Protection Regulation (GDPR):
‘Personal data’ means any information relating to an identified or identifiable natural person (hereinafter referred to as ‘data subject’); A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
‘Processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or otherwise making available, alignment or combination, restriction, erasure or destruction.
‘Restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future.
‘Pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
‘File system’ means any structured collection of personal data which are accessible according to specific criteria, whether centralised, decentralised or organised according to functional or geographical criteria.
‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
‘Processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
‘Recipient’ means a natural or legal person, public authority, agency or another body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of such data by those authorities shall be carried out in accordance with applicable data protection rules for the purposes of the processing.
‘Third party’ means any natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
‘Consent’ means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Processing operations
We collect and process the following personal data about you:
- Contact, address and sales information, provided that you have submitted your contact information to us or registered on our site,
- Online identifiers (e.g. your IP address, browser type and browser version, the related operating system, the referrer URL, the IP address, the file name, the access status, the amount of data transferred, the date and time of the server request),
- Social media identifiers.
Purposes of data processing
We process your data for the following purposes:
- to contact you as requested,
- to provide information about our activities and offers,
- to book and process museum events,
- for advertising purposes,
- to send the email newsletter, provided you have subscribed to it,
- for quality assurance, and
- recruitment (by post, email or via the application portal),
- to hold events,
- video conferences,
- audio and video recordings,
- for our statistics.
Legal basis for data processing
Your data is processed on the following legal bases:
- your consent in accordance with Art. 6(1)(a) GDPR,
- for the performance of a contract with you pursuant to Art. 6(1)(b) GDPR,
- for the fulfilment of legal obligations pursuant to Art. 6(1)(c) GDPR, or
- on the basis of a legitimate interest pursuant to Art. 6(1)(f) GDPR.
Processing operations
We collect and process the following personal data about you:
- Contact, address and sales information, provided that you have submitted your contact information to us or registered on our site,
- Online identifiers (e.g. your IP address, browser type and browser version, the related operating system, the referrer URL, the IP address, the file name, the access status, the amount of data transferred, the date and time of the server request),
- Social media identifiers.
Purposes of data processing
We process your data for the following purposes: - to contact you as requested,
- to provide information about our activities and offers,
- to book and process museum events,
- for advertising purposes,
If we base the processing of your personal data on legitimate interests within the meaning of Art. 6 (1) (f) GDPR, these are
- the improvement of our offerings,
- protection against misuse, and
- the maintenance of our statistics.
Data sources
We receive the data from you (including via the devices you use). If we do not collect the personal data directly from you, we will also inform you of the source of the personal data and, if applicable, whether it comes from publicly available sources.
Transmission/data recipients
When processing your data, we work with the following service providers who have access to your data:
- Providers of web analysis tools,
- Web hosting providers,
- Newsletter software providers,
- Administrative service providers,
- Video conferencing service providers,
- Advertising agencies,
- Printing service providers,
- Kitchen service providers,
- Security service providers,
- Social media providers.
Data is transferred to third countries outside the European Union. This is done on the basis of contractual provisions provided for by law, which are intended to ensure adequate protection of your data and which you can view on request.
We also transfer your data to the parties involved in the sales promotion, in particular the retailers.
Duration of processing
We only store your personal data for as long as is necessary to achieve the purpose of processing or if the storage is subject to a statutory retention period.
We store your data
- if you have consented to processing, for no longer than until you revoke your consent,
- if we need the data to perform a contract, for no longer than the duration of the contractual relationship with you or the statutory retention periods,
- if we use the data on the basis of a legitimate interest, for no longer than your interest in deletion or anonymisation prevails.
Your rights
You have the right, subject to certain conditions, to
- request information about the processing of your data free of charge and to receive a copy of your personal data. You can request information about the purposes of the processing, the categories of personal data being processed, the recipients of the data (if it is passed on), the duration of storage or the criteria for determining the duration;
- correct your data. If your personal data is incomplete, you have the right to have it completed, taking into account the purposes of the processing;
- Have your data deleted or blocked. Reasons for the existence of a right to deletion/blocking may include, among other things, the revocation of the consent on which the processing is based, the data subject objects to the processing, the personal data has been processed unlawfully;
- Have the processing restricted;
- Object to the processing of your data;
- Withdraw your consent to the processing of your data for the future; and
- Complain to the competent supervisory authority about unlawful data processing.
Further information on data protection
Contact form
The contact form on our website is an easy way to get in touch with us quickly. To enable us to contact you, some fields are marked as mandatory. By filling in the fields and selecting ‘Send’, you agree that your data will be sent to us by email along with your message. The data will not be stored on the web server.
Email newsletter
If you subscribe to our newsletter, we will use the data required for this purpose or provided separately by you to send you our email newsletter on a regular basis. You can unsubscribe from the newsletter at any time by sending a message to the contact option described above or by using the unsubscribe link provided in the newsletter.
Data security
We have taken extensive technical and organisational measures to protect your data against possible dangers such as unauthorised access, unauthorised disclosure, alteration or distribution, as well as against loss, destruction or misuse.
In order to protect your personal data from unauthorised access by third parties during transmission, we secure data transmissions using SSL encryption where necessary. This is a standardised encryption method for online services, especially for the web.
Log files
Each time our website is accessed, usage data is transmitted by the respective internet browser and stored in log files, known as server log files. The data records stored in this process contain the following information: Domain from which the user accesses the website, date and time of access, IP address of the accessing computer, website(s) visited by the user within the scope of the offer, amount of data transferred, browser type and version, operating system used, name of the internet service provider, notification of whether the access was successful. These log file data records are evaluated in anonymised form in order to improve the website and make it more user-friendly, to find and fix errors, and to control server utilisation.
Cookies
This website uses cookies. A cookie is a text file with an identification number that is transmitted to the user’s computer when using the website, together with the other data actually requested, and stored there. The file is kept there for later access and is used to authenticate the user. Since cookies are only simple files and not executable programmes, they do not pose any risk to the computer. Depending on the settings selected by the user in their internet browser, cookies are accepted automatically. However, these settings can be changed and the storage of cookies can be deactivated or set so that the user is notified as soon as a cookie is set. However, if cookie use is deactivated, some functions of the website may not be available or may only be available to a limited extent. You can prevent the setting of cookies by our website at any time by means of a corresponding setting in the Internet browser used and thus permanently object to the setting of cookies. Cookies that are already active can be deleted at any time via an Internet browser or other software programmes.We may work with advertising partners who help us make our website more interesting for you. For this purpose, cookies from partner companies are also stored on your hard drive when you visit our website (third-party cookies). If we work with the aforementioned advertising partners, you will be informed individually and separately about the use of such cookies and the scope of the information collected in each case in the following paragraphs.
The following types of cookies are distinguished:
First-party cookies: First-party cookies are transmitted by the platform you are currently visiting.
Third-party cookies: Third-party cookies are cookies that are transmitted by a provider other than the platform visited by the user. If a user visits a platform and another entity transmits a cookie through this platform, this is a third-party cookie.
Strictly necessary cookies: These cookies are necessary for you to navigate the platform and use its functions, such as accessing secure areas of the platform. Without these, certain services cannot be provided, such as displaying content tailored to your computer or device.
Performance cookies: These cookies collect information about how visitors use the platform, such as which pages are visited most frequently and whether they receive error messages from web pages. However, these cookies do not collect information about the visitor’s identity. All information collected by these cookies is aggregated and therefore anonymous. They are only used to optimise the platform.
Functionality cookies: These cookies enable the platform to remember choices you make (e.g. language settings and your region) and provide you with enhanced, more personal features. They can also be used to store your settings regarding text size, font and other customisable parts of the website. They can also be used to provide services you request, such as displaying a video or the comment function within a blog. The information collected by these cookies can be anonymised. Your browsing activity cannot be tracked on other platforms.
Social media cookies: These cookies are used when you click on a button to share information on social media on the platform. The social network records this action and may use it for marketing or advertising purposes.
Facebook
Our pages incorporate plugins from the social network Facebook, Meta Platforms Ireland Limited, 4 Grand Square, Grand Canal Harbour, Dublin 2, Ireland. You can recognise the Facebook plugins by the Facebook logo or the ‘Like’ button on our page. An overview of the Facebook plugins can be found here: https://developers.facebook.com/docs/plugins/. When you visit our pages, the plugin establishes a direct connection between your browser and the Facebook server. This tells Facebook that you have visited our site with your IP address. If you click the Facebook ‘Like’ button while you are logged into your Facebook account, you can link the content of our pages to your Facebook profile. This allows Facebook to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the data transmitted or its use by Facebook. For more information, please see Facebook’s privacy policy at https://de-de.facebook.com/policy.php.
Instagram
Our pages incorporate features of the Instagram service. These features are offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
If you are logged into your Instagram account, you can link the content of our pages to your Instagram profile by clicking on the Instagram button. This allows Instagram to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the data transmitted or its use by Instagram. If you do not want Instagram to be able to associate your visit to our pages, please log out of your Instagram user account. Further information on this can be found in Instagram’s privacy policy httpss://instagram.com/about/legal/privacy/.
YouTube
Our site uses YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA, represented by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to embed videos.
Normally, when you visit a page with embedded videos, your IP address is sent to YouTube and cookies are installed on your computer. However, we have integrated our YouTube videos with the extended data protection mode (in this case, YouTube still contacts Google’s Double Click service, but according to Google’s privacy policy, personal data is not evaluated). This means that YouTube no longer stores any information about visitors unless they watch the video. If you click on the video, your IP address is transmitted to YouTube and YouTube learns that you have watched the video. If you are logged in to YouTube, this information is also assigned to your user account (you can prevent this by logging out of YouTube before accessing the video). We have no knowledge of and no influence on the possible collection and use of your data by YouTube. For more information, please refer to YouTube’s privacy policy at www.google.de/intl/de/policies/privacy/. In addition, we refer you to our general description in this privacy policy for the general handling and deactivation of cookies.
Events
We offer various events in the form of workshops, lectures and conferences, which are listed under the heading ‘Events’. For some of these events, we ask you to register in advance, during which you will be asked to provide mandatory information. This includes, in particular, your name, title, email address, institution and any other data required for participation in and implementation of the event. A detailed overview can be found in the respective registration form.
The data is processed for the purpose of fulfilling contractual obligations, including the creation of accompanying material for the event, such as participant lists. We use the email address provided during registration to contact you to send you information about the event and to notify you of important changes, such as changes to the scope of the event or technical requirements. We store the data collected during registration until the purpose for data processing no longer applies or the data is no longer required for that purpose. Unless the data is deleted because it is required for other, legally permissible purposes, its processing will be limited to these purposes. The data will therefore be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for the assertion, exercise or defence of legal claims or for the protection of the rights of another natural or legal person. If users request the deletion of their personal data, their data will be deleted, subject to any legal retention obligations. This does not apply to data that has already been printed and distributed.
Data protection information for applicants
We are delighted that you wish to apply for a position with us. Below, we would like to explain how we process the personal data that you provide to us during the application process.
- Definitions: Personal data is any information relating to an identified or identifiable natural person (hereinafter referred to as the data subject). A natural person is considered identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special characteristics that express the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person. Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or other forms of provision, alignment or combination, restriction, erasure or destruction. The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The data subject is the employee.
- What data do we process? As part of the application process, we collect and process personal data that you provide to us, namely contact and address information, your application photo, information about your career to date, and your educational and professional training.
- The purpose of the processing is to carry out the application process and select the applicant.
- On what legal basis do we process your data? The legal basis is Article 6(1)(b) of the GDPR, namely the implementation of pre-contractual measures.
We receive the data from you. If we do not collect the personal data directly from you, we will also inform you of the source of the personal data and, if applicable, whether it comes from publicly available sources. - Is your data transferred to third parties? As part of the application process, data may be transferred to service providers, companies within the Klaus Tschira Group, the controller and affiliated companies. Data is only ever passed on to third parties within the legally permissible framework and to the extent necessary for the application process.
- Storage period: We only store your personal data for as long as is necessary to achieve the purpose of processing or if storage is subject to a statutory retention period. If we are unable to offer you a position as a result of the application process, we will return your submitted documents and delete the data collected in our systems six months after the end of the application process.
- Your rights: You have the right to a) request information about the processing of your data, b) request a copy of your personal data, c) have your data corrected. If your personal data is incomplete, you have the right, taking into account the purposes of the processing, to have the data completed, to have your data deleted or blocked, to have the processing restricted, to object to the processing of your data, to withdraw your consent to the processing of your data for the future and to complain to the competent supervisory authority about unlawful data processing. If you wish to exercise your rights as a data subject or have any other questions about this notice, please contact
kontakt(at)carl-bosch-museum.de
or the data protection officer of the Carl Bosch Museum, who can be reached at
eprivacy(at)carl-bosch-museum.de
Unless expressly stated in the collection, the provision of data is not necessary or mandatory. Such an obligation may arise from legal or contractual regulations.
Status of this privacy policy
November 2022
We reserve the right to change this privacy policy at any time with future effect.