1.   Privacy Policy

The Foundation Remembrance, Responsibility and Future (EVZ) appreciate your visit to its websites and your interest in its work. Protecting your personal data when using our websites is very important to us. In the following text, we would like to inform you about when we collect which data and how we use it.

Personal data, such as the name, address, email address, or telephone number of a data subject shall always be processed in accordance with the General Data Protection Regulation (GDPR) and with the country-specific data protection provisions applicable to the Foundation Remembrance, Responsibility and Future (EVZ). We have prepared this Privacy Policy in order to inform the public about the nature, scope, and purpose of the personal data collected, used, and processed by our institution. This Privacy Policy also informs data subjects of their rights.

The Foundation Remembrance, Responsibility and Future (EVZ) has implemented numerous technical and organizational measures in order to ensure the most complete protection of personal data processed through this website.
Nevertheless, security vulnerabilities may arise when transmitting data via the Internet and, therefore, complete protection cannot be guaranteed. For this reason, every data subject has the option of providing us with personal data by alternative means, for example by phone.

2.   Controller and contact with the Data Protection Officer

The controller responsible for processing your data is the Foundation Remembrance, Responsibility and Future (EVZ). Our contact details are as follows:

Stiftung Erinnerung, Verantwortung und Zukunft (EVZ)
Friedrichstraße 200
10117 Berlin
info@stiftung-evz.de

For any questions and queries regarding data protection, any data subject may at any time contact our Data Protection Officer via the following email address: datenschutz@stiftung-evz.de.

3.   Your rights as a data subject

Regarding your personal data, you have the following rights vis-à-vis a controller:

  • The right of access to the data processed and to obtain a copy,
  • The right to rectification if we process inaccurate data concerning you,
  • The right to erasure, unless exceptions apply as to why we are still storing the data, for example, retention obligations or limitation periods,
  • The right to restriction of processing of data,
  • The right to withdraw consent to data processing at any time,
  • The right to data portability,
  • The right to object to processing of data in the public or legitimate interest,
  • The right to lodge a complaint with the competent supervisory authority in case you consider that we are not processing your data in accordance with the applicable regulations.

The lawfulness of the processing of your personal data will only be affected from the time you inform us that you have revoked your consent. The lawfulness of any processing of your personal data that takes place up until this time will remain unaffected.

If you have given your consent to the processing of your data, you may withdraw this consent at any time. Such a withdrawal affects the legitimacy of the processing of your personal data after you submit your withdrawal to us. The legitimacy of the processing of your personal data prior to the time of your withdrawal remains unaffected.

4.  Duration of storage with respect to personal data

Personal data is erased after the end of its purpose or once statutory retention periods have expired, depending on which period is longer.

5.   Recipients of personal data

In general, we do not pass on any personal data. However, we use service providers who may receive knowledge of your personal data in the course of their duties.

This includes the agency commissioned with the creation of our website and our web hosting providers.

6.   Processing of personal data when you visit our website

During the merely informative use of the website, i.e. the mere display of the website without registration and without you providing us with any other information, we process the personal data that your browser transmits to our server. The data described below is technically necessary for us to be able to provide you with our website and to ensure stability and security, and must therefore be processed by us. The legal basis is Art. 6(1), sentence 1, lit. f) GDPR. Our legitimate interest is the above-mentioned purposes.

  • IP address
  • Date and time of the request
  • Difference in time zone from the Greenwich Mean Time (GMT)
  • Content of the request (page visited)
  • Access status/HTTP status code
  • Quantity of data transmitted in each case
  • Previously visited page
  • Browser
  • Operating system
  • Language and browser software version

After 14 days, we will erase this data.

If you click on any of the social media buttons (Facebook, Instagram, X, YouTube), you will be redirected to the website of the respective provider. During this process, usage information (e.g. IP address, date, time, web page accessed) may be transmitted to these services and processed there.

Please note that we have no control over the nature and scope of the data processing activities carried out by these providers. Please refer to the privacy policies on the respective platforms for further information. It is also possible that data will be transmitted to countries outside the EU/EEA.

7.   Matomo

The party responsible for the processing has integrated the “Matomo” tool into this website. Matomo is an open-source web analytics software provided by InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand. 

Web analytics comprises the generation, collection, and evaluation of data concerning the behavior of website visitors. The data collected by a web analytics tool includes 

  • the website a data subject visited before coming to this website (known as the “referrer”),
  • which subpages of the website were visited,
  • how often a subpage was visited, and for how long. 

The software runs on the server of the party responsible for the processing; the log files subject to data protection law are stored on this server only.

The EVZ Foundation mainly uses web analytics in order to optimize its website. The purpose of the Matomo tool is to analyze visitor traffic to our website. The party responsible for the processing utilizes the data and information obtained to assess the use of our website, to compile online reports that describe the activities undertaken on our website, and for other purposes.

Matomo places a cookie on the data subject’s computer system. The placement of this cookie enables us to analyze the use of our website. Every visit to one of the individual pages on this website causes the browser on the data subject’s computer system to automatically transmit data to our server via the Matomo tool for purposes of online analysis. This technical procedure allows us to gain insights into personal data such as the data subject’s IP address, thus enabling us for example to identify the origin of visitors and clicks.

The cookie is used to save personal information such as the time of access, the place from which the website was accessed, and the frequency of visits to our website. These personal data, including the IP address of the Internet connection being used by the data subject, are transmitted to our server on every visit to our website. They are then stored by us. We do not forward these personal data to third parties. In order to guarantee the best possible data protection, the IP address is anonymized before storage so that no conclusions can be drawn regarding the data subject’s identity.

The data subject can amend or withdraw their consent to the placement of cookies on their computer by our website at any time by changing their cookie settings accordingly.

We process the information in compliance with Art. 6(1)(f) GDPR. The purpose of the processing, which also constitutes our legitimate interest, is to improve our website services for visitors.

The statistical data we collect is erased after 166 days.

Information on how the third-party provider “Matomo” protects data is available at matomo.org/privacy-policy/

8. Cookies

We use cookies. Cookies are small text files containing information about visited websites or domains. They are stored on the computer of website users. Cookies are used for various purposes, and mainly serve to make the website faster and more user-friendly.
For instance, cookies can be used to store language settings or login details. However, cookies can also collect statistical data, and thus help to improve the website. Furthermore, there may also be cookies that show preferred content upon revisiting the website, or even show interest-related data on our website or on other websites via web tracking and the creation of a user profile. However, cookies cannot carry out any programs or send viruses to your computer. You can disable the use of cookies in your browser settings. However, this may lead to not all features of our website being able to be used properly.

We use the following cookies:

(1) Session cookies: These are deleted when you close the browser. They are used to make the website more user-friendly. 

(2) Technically required cookies: Certain cookies may be strictly necessary for our website to function accurately. (e.g. cookies for the display).

(3) Persistent cookies: These remain stored even after you have closed the browser, so that you do not have to log in again, for example. Similarly, information for range measurement, marketing and web tracking can also be stored in such a cookie.

(4) Statistics cookies: These are used to improve our own website. User behavior is analyzed on the website for this purpose. For example, it is possible to find out which web subpages have been visited particularly frequently, how many visitors there are, which pages have been accessed for the first or last time (entry or exit pages) or even the time spent on the website by visitors. We describe the data processing of our used statistic tools in detail in an additional item.

It is possible for you to disable the use of cookies in your browser. This can be set differently in each browser. This can usually be done by clicking on the Data Protection and Cookies tab. Please note that certain parts and / or certain functions of our website may then no longer operate correctly.

The data processing with session and technically required cookies is carried out on the basis of Art. 6(1) lit. f) GDPR. Our legitimate interest is the improved performance, operation and security of our website. Cookies for statistics, marketing and from third-party providers are explained in an extra item in this Privacy Policy. The corresponding legal basis for this is specified accordingly.

The first time you visit our website, a cookie banner will appear allowing you to accept or reject the use of cookies and similar technologies. Your selection will be saved and can be changed at any time by adjusting your cookie settings.

9.   Newsletter and newsletter tracking

Users can subscribe to the EVZ Foundation newsletter on the Foundation’s website. The purpose of the transmission of personal data to the controller when subscribing to the newsletter, and which personal data is transmitted is specified in the input screen used in this regard.

For this purpose, we use the so-called double opt-in process, according to which we will only send you a newsletter by email if you have previously given us explicit consent to activate the newsletter service by clicking on a link contained in a message. In case you do not confirm your registration within 24 hours, your registration details will be locked and automatically deleted after one week. In addition, we store your IP addresses and times of registration and confirmation. The purpose of the procedure according to Art. 6(1) lit. f) GDPR is to be able to verify your registration and, if necessary, to clarify a possible misuse of your personal data. This also constitutes our legitimate interest at the same time.

If you subsequently change your mind about receiving the newsletter, you can cancel your subscription at any time by withdrawing your consent. You can withdraw your consent to receiving the email newsletter using the link provided in the newsletter or the website’s administration settings. Alternatively, please contact us via the details provided in the Contact section.

For the supply of the newsletter, your personal data (email address) will be transmitted to our partner regarding the newsletter mailing, CleverReach (CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany). We have concluded a contract processing agreement with CleverReach.

Your personal data (email address) entered for the purpose of receiving the newsletter will be stored on CleverReach's servers in Germany or Ireland. By sending the newsletter, the respective opening rate and the further click-through rate within the newsletter are tracked and processed. The analysis shows us how often the newsletter was opened and how often which links were clicked. The EVZ Foundation thus assesses the newsletter usage by analyzing the actual usage (recording the reach). However, we only see the total number of users and cannot identify individual users. The purpose of the analyses is to customize and optimize our services.

Your consent to the processing of your data is based on the consent you gave when subscribing to the newsletter using the double opt-in procedure (Art. 6(1)(a) GDPR). You can revoke your consent at any time by unsubscribing from the newsletter.

We only carry out these analyses if we explicitly request your consent for newsletter tracking on the respective registration page. If no consent is requested on the respective registration page, we do not carry out any newsletter tracking for this newsletter.

Data processing is carried out on the basis of your consent (Art. 6(1) lit. a) GDPR). You can withdraw this consent at any time by unsubscribing from the newsletter. The data you provide for the purpose of receiving the newsletter will be stored until your unsubscription from the newsletter and will be deleted from our servers as well as from the CleverReach servers after you unsubscribe from the newsletter.

10.   Surveys

(1) We conduct surveys subject to your consent pursuant to Art. 6(1)(a) GDPR. In doing so, we process statistical data such as your age group, your country, and your knowledge of the EVZ Foundation in order to improve the EVZ Foundation’s work (communication services, funding programs, etc.).

The surveys also enable us to prepare for and carry out our events better and to improve future events (see section 11 on event registrations).

(2) The fields not marked optional must be completed in order to receive the surveys. The provision of other, separately marked data is voluntary. If the survey is sent to you by email, we will store your email address solely for transmission purposes. Unless otherwise stated, the legal basis is Art. 6(1)(a) and (b) GDPR.

(3) You can revoke your consent to the processing of your data for survey purposes at any time with future effect by sending an email to kommunikation@stiftung-evz.de. We will then delete your data without delay.

11. Event registrations

(1) Our website allows you to register for events. When you do so, your data are processed on the basis of your consent pursuant to Art. 6(1)(a) GDPR or on the basis of the underlying contractual relationship pursuant to Art. 6(1)(b) GDPR.

When you register for an event, the same data are transmitted as when you access the website. We also process

  • personal data such as your last name, first name, email address, location, country, language, activity/position, organization, and the selected workshop for the purpose of preparing and carrying out the event as well as possible.
  • personal data such as your title, last name, first name, email address, organization, address, location, and country.

The processed data may also include special categories (food intolerances, allergies and special requirements, gender identity, etc.), which we process on the basis of your consent pursuant to Art. 9(2)(a) GDPR so that we can take your health requirements into account or address you correctly.

(2) We use the so-called “double opt-in” procedure for event registration purposes. This means that after you register, we will send an email to the email address provided asking you to confirm that you wish to take part in the event. If you do not confirm your registration within 24 hours, your information will be blocked and automatically deleted after one week. We also store data about your IP addresses and the times at which you registered and confirmed your registration. Under Art. 6(1)(f) GDPR, these data are stored as evidence of your registration and to enable us to investigate any improper use of your personal data should this become necessary. These purposes also constitute our legitimate interest.

(4) The fields not marked optional must be completed so that we can send you the registration documents. The provision of other, separately marked data is voluntary. The personal data collected are processed solely for the purpose of organizing and carrying out the respective event. Once we have received your confirmation, we will store your email for the purpose of sending you your registration documents. Unless otherwise specified, the legal basis is Art. 6(1)(a) and (b) GDPR. (5) Once the event is over, your data will be deleted within 90 days unless you have expressly agreed to their further storage (e.g. for future events). You can cancel your participation in the event or revoke your consent to the storage of your data for future events at any time by sending an email to event@stiftung-evz.de. We will then delete your data without delay.

12. Orders

(1) Our website allows you to place orders. When you do so, your data are processed on the basis of your consent pursuant to Art. 6(1)(b) GDPR. 

When you place an order, the same data are transmitted as when you access the website. We also process the following data in order to accept and process your order and send you the requested copies free of charge:

(2) We will not use your data to contact you again or send you information not connected with your order.

(3) We will only store your order data for as long as is necessary to execute the order. In general, your data will be deleted within 90 days of all contractual obligations being discharged except in cases where your data are subject to statutory retention periods. 

13. Integration of videos

We embed videos on our websites that are not stored on our server. To ensure that visiting our websites with embedded videos does not automatically result in third-party content being reloaded, we initially only display locally stored preview images of the videos. This means that the third-party provider does not receive any information.

Only after clicking on the preview image will third-party content be loaded. This provides the third-party provider with information that you have accessed our site, as well as the technically necessary usage data. In addition, the third-party provider is then able to implement tracking technologies. We have no influence on further data processing by the third-party provider. By clicking on the preview image, you give us your consent to reload the third-party provider's content.

The embedding is based on your consent in accordance with Art. 6 (1) (a) GDPR, provided that you have given your consent by clicking on the preview image. 

Please note that embedding many videos means that your data will be processed outside the EU or the EEA. In some countries, there is a risk that authorities may access the data for security and surveillance purposes without you being informed or being able to seek legal remedy. If we use providers in unsafe third countries and you consent, the transfer to an unsafe third country will be based on Art. 49 (1) (a) GDPR.

13.1 Embedding YouTube videos
(1) Our website uses YouTube videos from the website YouTube.com, which is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: “Google”). We have implemented the “double-click” solution with YouTube. The double-click solution blocks the transmission of personal data to Google when you access our website. YouTube will only play the video and start transmitting the above-mentioned server data and site information to Google when you confirm your consent by double-clicking on the video. (Collection of general data and information) We have no influence over this data transmission. The legal basis for showing the videos is Art. 6(1)(a) GDPR, i.e. the videos are only embedded after you have given your consent.

(2) When you visit the website, YouTube receives the information that you have accessed the corresponding subpage on our website. The basic server data mentioned above (e.g. IP address, timestamp) are also transmitted. This occurs regardless of whether or not you are logged in through a user account provided by YouTube. If you are logged in to Google/YouTube, your data will be directly associated with your account. If you do not wish your data to be associated with your YouTube profile, you must log out before clicking the button. YouTube stores your data in the form of user profiles and uses them for purposes of advertising, market research and/or the needs-based configuration of its website. These analyses are performed (even if the user is not logged in) mainly for the purpose of displaying demand-oriented advertising and informing other social network users about your activities on our website. You have the right to object to the creation of these user profiles but must contact Google if you wish to do so. The information collected is stored on Google servers, which are also located in the USA. Google has obtained Data Privacy Framework certification for the transmission of data to the USA, thus demonstrating its compliance with appropriate data privacy standards.

(3) You will find further information on the purpose and scope of YouTube’s data collection and processing activities in the privacy policies published by YouTube and Google. These also provide more information on your rights and the options available for adjusting your settings to protect your privacy. 
YouTube: www.youtube.com/intl/en_us/howyoutubeworks/our-commitments/protecting-user-data/
Google: www.google.de/intl/en/policies/privacy

13.2 Embedding YouTube videos
(1) On this website, we use Vimeo videos from the website vimeo.com, which is operated by Vimeo.com, Inc., 330 West 34th Street, 10th Floor, New York, New York 10001, USA (hereinafter referred to as “Vimeo”). Only when you have confirmed your consent by clicking on the video twice will the video be played by Vimeo, and the transmission of the above-mentioned server data and location information to Vimeo will begin. (Collection of general data and information) We have no influence over this data transmission. The legal basis for showing the videos is Art. 6(1)(a) GDPR, i.e. the videos are only embedded after you have given your consent.

(2) When you visit the website, Vimeo receives information that you have accessed the corresponding subpage of our website. The basic server data mentioned above (e.g., IP address, timestamp) are also transmitted. This occurs regardless of whether Vimeo provides a user account that you are logged in to or whether no user account exists. If you are logged in to Vimeo, your data will be directly associated with your account. If you do not want your data to be associated with your Vimeo profile, you must log out before activating the button. Vimeo stores your data as usage profiles and uses them for the purposes of advertising, market research, and/or the design of its website in line with current needs. These analyses are performed (even if the user is not logged in) mainly for the purpose of displaying demand-oriented advertising and informing other social network users about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact Vimeo to exercise this right. The information collected is stored on Vimeo's servers, including in the USA. For data transfers to the USA, Vimeo has certified itself under the Data Privacy Framework, thereby demonstrating an adequate level of data protection.

(3) Further information on the purpose and scope of data collection and its processing by Vimeo can be found in Vimeo's privacy policy. These also provide more information on your rights and the options available for adjusting your settings to protect your privacy.
https://vimeo.com/privacy 

This privacy statement was created in cooperation with the EVZ Foundation’s Data Protection Officer.