Privacy
Responsible party pursuant to data protection laws, in particular the EU General Data Protection Regulation (GDPR), is datenschutzbeauftragter@startsteps.org
Your rights as the data subject
You can exercise the following rights at any time using the contact details of our data protection officer:
- Information on your data stored by us and the processing thereof (Art. 15 GDPR)
- Rectification of inaccurate personal data (Art. 16 GDPR)
- Deletion of your data stored by us (Art. 17 GDPR)
- Restriction of the data processing, provided that we may not delete your data due to legal obligations (Art. 18 GDPR)
- Objection to the processing of your data with us (Art. 21 GDPR)
- Data portability, provide that you have consented to the data processing or have entered into a contract with us (Art. 20 GDPR)
If you have given us consent, you may withdraw it at any time, which will remain in effect in the future.
You can contact a supervisory authority with a complaint at any time, e.g. the supervisory authority of the state of your residence or the authority that oversees us as the responsible party.
You’ll find a list of supervisory authorities (for the non-public area) with their respective addresses at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
Collecting general information during a visit to our website
Type and purpose of the processing
When you access our website – i.e. if you do not register or submit information – information of a general nature will be collected automatically. This information (server log files) contains the type of web browser, the operating system used, the domain name of your Internet service provider, your IP address and the like.
It is processed in particular for the following purposes:
- Ensuring an unproblematic website connection
- Ensuring seamless use of our website
- Analysis of system security and stability
- For additional administrative purposes
We will not use your data to draw conclusions about your person. This type of information will be statistically analysed by us if necessary to optimise our website and its underlying technology.
Legal basis
The processing occurs according to Art. 6 Para. 1 (f) GDPR, based on our legitimate interest in improving the stability and functionality of our website.
Recipients
Recipients of the data may be technical service providers, who work on the operation and maintenance of our website as the processor.
Retention period
The data will be deleted as soon as they are no longer required for the reason they were collected. This is generally the case, after the respective session has ended, for data that are used to make the website available.
Mandatory or required provision
The provision of the aforementioned personal data is neither legally nor contractually mandatory. Without the IP address however, the service and functionality of our website are not guaranteed. Furthermore, individual services can be unavailable or limited. For this reason, an objection is excluded.
Registration on our website
Type and purpose of the processing
With the registration to use our personalised services, some personal data such as name, address, contact and communication information (e.g. phone number and e-mail address) are collected.
If you are registered with us, you can access content and services that we only offer to registered users. Registered users also have the ability to change or delete the data entered during registration at any time.
Legal basis
The data entered during registration are processed on the basis of the user’s consent (Art. 6 Para. 1 (a) GDPR).
If the registration fulfils the obligations of a contract, or serves pre-contractual measures, the additional legal basis is Art. 6 Para. 1 (b) GDPR.
Recipients
Technical service providers involved in the maintenance of the site.
Retention period
Data is processed only while consent is valid. Afterwards, deletion is subject to legal retention periods.
Mandatory or required provision
Voluntary, based on your consent. Without it, access to our services is not possible.
Lead Sharing with German Educational Resellers
Type and purpose of the processing
We may share qualified leads with our German educational resellers to complete educational or sales cycles.
Legal basis
Our resellers are separate data controllers and must comply with GDPR.
Recipients
German educational resellers.
Retention period
Retained only for compliance purposes.
Mandatory or required provision
Rights to access, rectify, or erase data must be exercised directly with the reseller or via our contact.
Newsletter
Type and purpose of the processing
Used to send subscribed newsletters. Name helps personalize content.
Legal basis
Based on your express consent (Art. 6 Para. 1 (a) GDPR).
Recipients
Processors involved in sending.
Retention period
As long as consent is valid.
Mandatory or required provision
Voluntary. Newsletter cannot be sent without consent.
Contact Form
Type and purpose of the processing
Data is used to follow up on inquiries. Name and email are required.
Legal basis
Legitimate interest (Art. 6 Para. 1 (f)) or pre-contractual obligation (Art. 6 Para. 1 (b)).
Retention period
Deleted within 6 months, or per statutory retention if under contract.
Analytics & External Services
Google Analytics
Used with IP anonymization. Based on user consent. Google is a processor.
Google Webfonts
Used for consistent font rendering. Based on user consent.
Google Maps
Displays interactive maps. Personalization depends on Google account login state.
YouTube Embeds
YouTube cookies and viewing behavior tracked if logged in. Consent-based use.
Google AdWords & Remarketing
Conversion tracking and personalized ads. Cookies stored via AdWords click.
SSL Encryption
We use SSL encryption for secure data transfer over HTTPS.
Revision of our privacy policy
The policy may be updated to comply with legal or service changes. Future visits are subject to updates.
Questions for the data protection officer
Email: mozamel@startupistan.org