PRIVACY POLICY

This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter “Data”) in connection with the use of our online services. This includes all associated websites, features, and content, as well as external online presences such as our profiles on social media (collectively referred to as “Online Services”). For the data protection terms used — such as “processing” or “controller” — we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Person in charge

The “OSIANTO” e-learning application is provided by 30 doradus media design gmbh
Niederstr. 29
40789 Monheim, Germany
Email: info@30doradus.deManaging Director: Jürgen Osterberg

Types of data processed:

  • Master data (e.g., names, addresses)
  • Contact information (e.g., email addresses, phone numbers)
  • Content data (e.g., text entries, photographs, videos)
  • Usage data (e.g., websites visited, access times, interest in content)
  • Meta and communication data (e.g., device information, IP addresses)

Categories of data subjects

Data processing affects visitors and users of our online services. We will collectively refer to them as “users” hereinafter.

Purposes of processing

  • Provision of the online service, including all features and content
  • Processing contact requests and communicating with users
  • Implementation of security measures to ensure data protection
  • Reach measurement and marketing

Terminology used

In this Privacy Policy, we use various terms as defined in the General Data Protection Regulation (GDPR). “Personal data” refers to any information relating to an identified or identifiable natural person. A person is considered identifiable if they can be identified directly or indirectly—for example, by association with a name, an identification number, location data, an online identifier (such as a cookie), or by specific characteristics that reflect that person’s physical, physiological, genetic, mental, economic, cultural, or social identity.

“Processing” refers to any operation or set of operations performed on personal data—regardless of whether it is carried out with or without the aid of automated means. The term is very broad and encompasses virtually any handling of data.

“Pseudonymization” refers to the processing of personal data in such a way that the data can no longer be linked to a specific individual without additional information. This additional information must be stored separately and protected by appropriate technical and organizational measures to prevent re-identification.

“Profiling” refers to any form of automated processing of personal data in which such data is used to evaluate certain personal aspects of an individual—such as work performance, financial situation, health, preferences, interests, reliability, behavior, or location.

The “controller” is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.

A “data processor,” on the other hand, is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the data controller.

Relevant legal bases

The processing of personal data is based on various legal grounds set forth in the General Data Protection Regulation (GDPR). Below, we would like to outline the most important legal grounds on which we base the processing of your data:

  • Consent (Art. 6(1)(a) GDPR): If you give us your explicit consent to process your data, this serves as the legal basis for the processing. You may withdraw this consent at any time.
  • Performance of a contract (Art. 6(1)(b) of the GDPR): If the processing of your data is necessary to fulfill a contract with you or to take precontractual measures at your request, we rely on this legal basis.
  • Legal obligation (Art. 6(1)(c) GDPR): If we are required to process your data due to legal requirements, the processing is based on this legal obligation.
  • Legitimate interests (Art. 6(1)(f) GDPR): In some cases, we process your data because we have a legitimate interest in carrying out certain activities, such as improving our services or ensuring IT security. In such cases, we ensure that your rights and freedoms are not unduly compromised.

Safety measures

In accordance with Article 32 of the GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk posed to the rights and freedoms of data subjects. In doing so, we take into account the state of the art, the costs of implementation, the nature and scope of the processing, as well as the specific circumstances and purposes of the data processing. We also take into account the likelihood and severity of the risks associated with the processing of personal data.

The measures taken include, in particular:

  • Ensuring the confidentiality, integrity, and availability of data through controlled physical access and targeted measures to protect against unauthorized access, as well as ensuring data security during input, processing, transmission, and storage.
  • The implementation of procedures that make it possible to protect the rights of data subjects, delete data, and respond appropriately to potential data security threats.

In addition, we take the protection of personal data into account from the very beginning of the development and selection of hardware, software, and processes, and implement the principle of data protection through technology design and privacy-friendly default settings in accordance with Article 25 of the GDPR.

Cooperation with data processors and third parties

If, in the course of our data processing, we disclose personal data to other individuals or companies, transfer such data to them, or otherwise grant them access to the data, we do so exclusively on the basis of a legal authorization. This may be the case, for example, when the transfer of data to third parties, such as payment service providers, is in accordance with Article 6(1)(b) of the GDPR requires this for the performance of a contract. Furthermore, this may also occur if you have consented to the data transfer, if there is a legal obligation to do so, or if it is based on our legitimate interests (e.g., when using service providers such as web hosting providers).

When we engage third parties to process personal data under a so-called “data processing agreement,” we do so in accordance with the requirements of Article 28 of the GDPR.

Transfers to third countries

If we process personal data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in connection with the use of third-party services or the disclosure or transfer of data to third parties, we do so only if it is necessary to fulfill our (pre)contractual obligations, based on your consent, due to a legal obligation, or based on our legitimate interests.

Provided that statutory or contractual authorizations exist, we process data in a third country—or commission third parties to do so—only if the specific requirements of Articles 44 et seq. of the GDPR are met. This means, for example, that processing may only take place on the basis of specific safeguards, such as a recognized determination that a level of protection equivalent to that of the EU exists (for example, for the United States through the “Privacy Shield”) or through compliance with officially recognized specific contractual obligations, such as “standard contractual clauses.”

Rights of data subjects

Under Article 15 of the GDPR, you have the right to request confirmation from us as to whether your personal data is being processed. In addition, you may request access to this data, as well as further information and a copy of the data.

Under Article 16 of the GDPR, you have the right to request that your personal data be completed or that inaccurate data be corrected.

Under Article 17 of the GDPR, you have the right to request the immediate erasure of your personal data. Alternatively, under Article 18 of the GDPR, you may request that the processing of your data be restricted.

Pursuant to Article 20 of the GDPR, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that it be transmitted to another controller.

In addition, pursuant to Article 77 of the GDPR, you have the right to file a complaint with the competent supervisory authority.

Right of withdrawal

You have the right to withdraw any consent you have given, effective for the future, in accordance with Article 7(3) of the GDPR.

Right to object

You may object to the future processing of your personal data at any time in accordance with Article 21 of the GDPR. In particular, the objection may be directed against processing for direct marketing purposes.

Cookies and the right to object to direct marketing

“Cookies” are small files that are stored on users’ devices and may contain various types of information. The main purpose of cookies is to store user information during or after their visit to a website. Temporary cookies, also known as “session cookies” or “transient cookies,” are deleted when the user leaves the website and closes the browser. These cookies store, for example, the contents of a shopping cart in an online store or the user’s login status. “Permanent” or “persistent” cookies remain stored even after the browser is closed. For example, they can maintain the user’s login status if the user revisits the website after several days. The user’s interests can also be stored in persistent cookies for use in audience measurement or marketing purposes. “Third-party cookies” are cookies set by providers other than the party responsible for the website, while “first-party cookies” are set only by that party itself.

We use both temporary and permanent cookies, and provide information about them in our Privacy Policy.

Users can prevent cookies from being stored by disabling the corresponding option in their browser settings. Cookies that have already been stored can be deleted in the browser’s system settings. Please note that disabling cookies may result in limited functionality of this website.

You can generally object to the use of cookies for online marketing purposes—particularly with regard to tracking—on many services via the U.S. website http://www.aboutads.info/choices/ or the European website http://www.youronlinechoices.com/. In addition, you can prevent cookies from being stored by disabling them in your browser settings. Please note that in this case, not all features of this website may be available.

Deletion of data

The data we process is deleted or its processing is restricted in accordance with the provisions of Articles 17 and 18 of the GDPR. Unless expressly stated otherwise in this Privacy Policy, the data we store will be deleted as soon as it is no longer necessary for the intended purpose and there are no legal retention obligations that prevent its deletion. If the data is not deleted because it is needed for other legally permissible purposes, its processing will be restricted. This means that the data will be blocked and may not be used for any other purposes. This applies, for example, to data that must be retained in accordance with commercial or tax law regulations.

In Germany, data is retained in accordance with legal requirements, specifically for 10 years pursuant to Section 147(1) of the German Fiscal Code (AO) and Section 257( 1) Nos. 1 and 4, para. 4 of the German Commercial Code (HGB) (including books, records, management reports, accounting documents, trading records, and documents relevant for tax purposes) and for 6 years pursuant to § 257, para. 1, Nos. 2 and 3, and para. 4 of the German Commercial Code (HGB) (including business correspondence).

In Austria, records are retained in accordance with statutory provisions, specifically for 7 years pursuant to Section 132(1) of the Federal Tax Code (BAO) (including accounting records, receipts/invoices, accounts, business documents, and statements of income and expenses), for 22 years in connection with real estate, and for 10 years for documents related to electronically supplied services, telecommunications, radio, and television services provided to non-business customers in EU member states where the Mini One-Stop Shop (MOSS) is utilized.

Business-Related processing

In addition, we process:

  • Contract details (e.g., subject matter of the contract, term, customer category),
  • Payment information (e.g., bank account information, payment history),

from our customers, prospective customers, and business partners in order to provide contractual services, ensure customer service and support, and conduct marketing, advertising, and market research.

Agency services

We process our customers’ data in connection with the provision of contractual services, which include conceptual and strategic consulting, campaign planning, software and design development, consulting, and maintenance; the implementation of campaigns and processes; as well as server administration, data analysis, consulting services, and training programs.

In doing so, we process:

  • Master data (e.g., customer master data such as names or addresses),
  • Contact information (e.g., email addresses, phone numbers),
  • Content data (e.g., text entries, photographs, videos),
  • Contract details (e.g., subject matter of the contract, term),
  • Payment information (e.g., bank account information, payment history),
  • Usage and metadata (e.g., for evaluating and measuring the success of marketing campaigns).

Special categories of personal data are generally not processed, unless they are part of a commissioned processing operation. The data subjects include our customers, prospective customers, and their customers, users, website visitors, employees, and third parties. The purpose of data processing is to provide contractual services, handle billing, and provide customer service. The legal basis for the processing is set forth in Article 6(1)(b) of the GDPR (contractual services) and Article 6(1)(f) of the GDPR (analysis, statistics, optimization, security measures).

We process only the data necessary to establish and fulfill contractual obligations and will inform you of the necessity of providing this data. Data will only be disclosed to third parties if this is necessary within the scope of a contract. In the context of data processing on behalf of a client pursuant to Article 28 of the GDPR, we process the data entrusted to us exclusively in accordance with the client’s instructions and solely for the purposes specified in the contract.

The data is deleted once statutory warranty obligations and similar obligations have expired. The necessity of retaining the data is reviewed every three years. In the case of legally mandated archiving obligations, the data is deleted once those obligations have expired (6 years pursuant to Section 257(1) of the German Commercial Code (HGB), 10 years pursuant to Section 147(1) of the German Fiscal Code (AO)). For data provided to us in connection with an assignment, we delete it in accordance with the terms of the assignment, typically upon completion of the assignment.

Contractual services

We process the data of our contractual partners, prospective customers, and other clients, customers, or contractual partners (hereinafter collectively referred to as “contractual partners”) in accordance with Article 6(1)(b) of the GDPR in order to provide them with our contractual or pre-contractual services. The nature, scope, and purpose of the processing, as well as the necessity of the data processing, depend on the underlying contractual relationship.

The data processed includes, in particular:

  • Master data of our contractual partners (e.g., names and addresses),
  • Contact information (e.g., email addresses, phone numbers),
  • Contract data (e.g., services used, contract details, contractual communications, names of contact persons),
  • Payment information (e.g., bank account information, payment history),

Special categories of personal data are generally not processed, unless they are part of commissioned or contractual processing.

We process only the data necessary to establish and fulfill contractual obligations, and—unless it is obvious to the contracting parties—we inform them of the necessity of providing this data. Data is disclosed to external individuals or companies only if required under the terms of a contract. When processing data entrusted to us as part of an assignment, we act in accordance with the client’s instructions and legal requirements.

When you use our online services, we may store your IP address and the time of each user action. This data is stored based on our legitimate interests and the users’ interest in protection against misuse and unauthorized use. As a general rule, this data is not disclosed to third parties unless it is necessary to pursue our claims in accordance with Art. 6( 1) required by the GDPR, or there is a legal obligation under Article 6(1)(c) of the GDPR.

Data will be deleted when it is no longer necessary for the fulfillment of contractual or statutory duties of care, as well as for the fulfillment of warranty and similar obligations. The necessity of retention is reviewed every three years; otherwise, the statutory retention requirements apply.

Contact us

When you contact us (e.g., via the contact form, email, phone, or social media), your information is processed in accordance with Article 6(1)(b) of the GDPR for the purpose of handling your inquiry and processing it. User data may be stored in a customer relationship management system (“CRM system”) or a comparable inquiry management system.

We delete the requests as soon as they are no longer necessary. We review their necessity every two years; in addition, statutory retention requirements apply.

Collection of access data and log files

We, or rather our hosting provider, collect data regarding every access to the server on which this service is hosted (so-called server log files) based on our legitimate interests pursuant to Article 6(1)(f) of the GDPR. The access data includes the name of the webpage accessed, the file, the date and time of access, the amount of data transferred, a notification of a successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), the IP address, and the requesting provider.

For security reasons (e.g., to investigate cases of misuse or fraud), log file information is stored for a maximum of 7 days and then deleted. Data that must be retained for evidentiary purposes remains stored until the incident in question has been fully resolved.

Google AdWords and conversion tracking

Based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the efficient operation of our online services within the meaning of Article 6(1)(f) of the GDPR), we use the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

Google is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).

As part of our online marketing efforts, we use the “Google AdWords” service to place ads on the Google Display Network (e.g., in search results, in videos, on websites, etc.) that are shown to users who are likely to be interested in these ads. This allows us to place targeted ads within our online offerings and to present users only with advertisements that potentially match their interests. One example of this is “remarketing,” in which a user is shown ads for products they have previously shown interest in on other websites. For these purposes, a code is executed directly by Google when a user visits our website or other websites where the Google Display Network is active. So-called (re)marketing tags (invisible graphics or code, also known as “web beacons”) are embedded on the websites. This causes an individual cookie to be stored on the user’s device (comparable technologies may also be used instead of cookies). This file stores information about which websites the user has visited, what content has interested them, and which offers they have clicked on, as well as technical information about the browser and operating system, referring websites, visit times, and other details regarding the use of the online service.

In addition, we receive a unique “conversion cookie.” Google uses the information collected by the cookie to generate conversion statistics for us. However, we only see the anonymous total number of users who clicked on our ad and were redirected to a page tagged with a conversion tracking tag. We do not receive any information that can be used to personally identify users.

User data is processed pseudonymously within the Google advertising network. This means that Google does not, for example, store users’ names or email addresses, but instead processes the relevant data within pseudonymous user profiles. As a result, ads are not displayed to a specifically identified individual, but rather to the owner of the cookie, regardless of that person’s actual identity. This does not apply if a user has expressly authorized Google to process the data without this pseudonymization. The collected information is transmitted to Google and stored on Google’s servers in the United States.

For more information about Google’s use of data, as well as options for adjusting settings and opting out, please see Google’s Privacy Policy (https://policies.google.com/technologies/ads) and the settings for Google ads (https://adssettings.google.com/authenticated).

Measuring reach with Matomo

As part of the audience analysis conducted with Matomo, the following data is processed based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR): browser type and version, operating system, country of origin, date and time of the server request, number of visits, time spent on the website, and the external links you clicked on. The IP address is anonymized (by masking the last bytes) the moment Matomo receives it and is only then stored.

To this end, Matomo uses cookies that are stored on users’ computers and enable us to analyze the use of our online service. Pseudonymous user profiles can be created from the processed data. By default, the cookies have the following retention periods:

  • Visitor ID, expires after 13 months
  • Session cookie, expires after 30 minutes
  • Referrer information, expires after 6 months

The information collected by the cookie is stored exclusively on our own server and is not shared with third parties. We automatically delete the logs containing pseudonymous usage data after 6 months at the latest.

Users can object to Matomo’s anonymous data collection at any time, effective for the future, by unchecking the checkbox below. In this case, an opt-out cookie will be stored in your browser, preventing Matomo from collecting any further session data. If you delete your cookies, you will need to re-enable the opt-out cookie if necessary:

Social media presence

We maintain an online presence on social networks and platforms to communicate with customers, prospective customers, and users who are active there and to inform them about our services. When accessing these networks and platforms, the terms and conditions and data processing policies of the respective operators apply.

Unless otherwise specified in this Privacy Policy, we process users’ data when they communicate with us on social networks and platforms, for example, by posting comments on our online presence or sending us messages.

Integration of third-party services and content

Within our online offering, we rely on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) to incorporate content or services from third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter collectively referred to as “content”).

This requires that the third-party providers of this content collect users’ IP addresses, since without the IP address they would not be able to send the content to users’ browsers. The IP address is therefore necessary for displaying this content. We strive to use only content whose respective providers use the IP address exclusively for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Pixel tags can be used to analyze information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and includes, among other things, technical information about the browser and operating system, referring websites, visit times, and other details regarding the use of our online service. This information may be combined with data from other sources.

Integration of social plugins from the social network Meta (formerly Facebook)

Based on our legitimate interests (Art. 6(1)(f) GDPR), we use social plugins (“plugins”) from the social network Meta, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The plugins include interactive elements or content (e.g., videos, graphics, or text posts) and can be recognized by one of the Meta logos (a white “f” on a blue tile, “Like,” “Gefällt mir,” or “Thumbs Up”) or are labeled “Facebook Social Plugin.” A complete list and the current appearance of the social plugins can be found here:
https://developers.facebook.com/docs/plugins.

When you visit a page on our website that contains such a plugin, your device establishes a direct connection to Meta’s servers, and the plugin’s content is integrated into the website. Meta may create usage profiles in this process and—if you are logged in to Meta—associate your visits with your Meta profile.

The transfer of personal data to third countries (e.g., the United States) is based on the Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an adequate level of data protection. For more information on data protection at Meta, please see the Privacy Policy at https://www.facebook.com/privacy/policy and for personalization and advertising settings (opt-out) at https://www.facebook.com/business/help/1739644726781076 or https://www.facebook.com/help/247395082112892

Embedding content from social network X

As part of our online offering, features and content from the X service may be provided. X Corp. (formerly Twitter, Inc.), 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, is responsible for this. Embedded content includes tweets, images, videos, and buttons for “Liking” or following profiles.

If you are logged in to X as a member or have a profile there, X can associate views of the embedded content with your user account. The transfer of personal data to third countries (e.g., the U.S.) is based on the Standard Contractual Clauses (SCCs) approved by the European Commission. For more information on data protection at X, please see X’s Privacy Policy at
https://x.com/privacy and for opt-out and personalization settings, visit https://help.x.com/personalization-data-settings.