Privacy notice

We are pleased that you are visiting our website and thank you for your interest in phi and the corresponding services.

In the following, we inform you about the collection of personal data when using our website. Personal data means data that can be related to you, such as name, address, email addresses, user behaviour.

 

Responsible for data processing

Responsible in accordance with Article 4 (7) of the General Data Protection Regulation (GDPR) is the following entity: IPH gGmbH (see legal notice).

Contracted service providers:

The general provision and maintenance of our websites and email systems is carried out with the support of IT service providers who work on our behalf and can therefore also view (receive) your data to the extent required.

Data protection officer:

Althammer & Kill GmbH & Co. KG
Thomas Althammer

Roscherstraße 7
30161 Hannover

kontakt-dsb@althammer-kill.de

 

Collection and use of your data

The scope and the nature of collection and use of your personal data differs depending on whether you visit our website only to retrieve information or whether you use any services we may offer.

If we use other (IT) service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes (all data processing) below. We also state specified criteria for the storage period and the applicable legal basis for data processing.

Informational use

When you use our website for informational purposes, we only collect personal data that your browser automatically transmits to us, such as:

  • IP address,
  • Date and time of the request,
  • Time zone difference to Greenwich Mean Time (GMT),
  • Content of the request (specific page),
  • Amount of data transferred and the access status (file transferred, file not found …),
  • Website from which the request originated,
  • Browser type / version / language,
  • Operating system and its interface,
  • Language setting and version of your browser.

 

Storage period:

Storage period for log files:

  • Mail server log: 7 days
  • Apache log: 1 month
  • Backups are kept in encrypted form for 14 days

 

Legal basis for data processing:

The above data is technically necessary to display our website to you and to ensure stability and security, in accordance with Article 6 paragraph 1 letter f GDPR.

Newsletter

For you to regularly receive our newsletter, we need at least your e-mail address (mandatory) to which the newsletter is to be sent. In addition. your consent is required. Any further information is voluntary and is used to address you personally and to clarify any queries about the email address.

We use the so-called double opt-in procedure for registration, which means that we will only send you the newsletter if you have previously confirmed your registration via a link contained in a confirmation email sent to you for this purpose. We want to ensure that only you, as the owner of the specified email address, can register for the newsletter. Your confirmation in this regard must be made promptly after receipt of the confirmation email, otherwise your newsletter registration will be deleted automatically.

Revocation of your consent:

You can unsubscribe from the newsletter that you have subscribed to at any time by clicking on the corresponding link at the end of the newsletter or by sending a message to the contact details given in the legal notice.

Contracted service providers:

We have not commissioned a specialized service provider to deliver the newsletter. We send the newsletter directly via this website. 

Storage period:

If you do not confirm your registration, your information will be deleted after 4 months at the latest.

Following successful registration, your data will be saved for as long as you have subscribed to the newsletter.

In addition, we save the IP addresses you have used and the times of registration and confirmation of the newsletter. The background to this is the necessary proof of your consent and, if necessary, the clarification of any misuse of your personal data (e.g. a third party is not using your email address for registration).

Legal basis for data processing:

The subscription to the newsletter takes place with your personal consent, in accordance with Article 6 paragraph 1 letter a GDPR.

The storage of more detailed information regarding the time of your registration and the IP address used is in our interest, in accordance with Article 6 paragraph 1 letter f GDPR.

The evaluation of your pseudonymized user behaviour (success measurement of our newsletter) is carried out in our interest. The purpose is to deliver an interesting newsletter and to better tailor it to our reader group, in accordance with Article 6 paragraph 1 letter f GDPR.

The evaluation of your personalized user behaviour (measurement of the success of our newsletter) is based on your personal consent, in accordance with Article 6 paragraph 1 letter a GDPR.

 

Use of cookies 

We use cookies for our website. Cookies are small text files that are sent from our web server to your browser when you visit our website and are stored by your browser on your computer for later retrieval. They are used for making the offer more user-friendly and effective overall.

[borlabs-cookie type=”btn-cookie-preference” title=”Cookie Auswahl ändern” element=”link”/]

 

This website uses cookies to the following extent:

[borlabs-cookie type=”cookie-list”/]     

Cookies can basically be divided into two categories:

Transient cookies are automatically deleted when you close the browser. This includes, in particular, session cookies. These store a so-called session ID, with which various requests from your browser can be assigned to the common session. This allows your computer to be recognized when you return to the website. The session cookies are deleted when you log out or close the browser.

Persistent cookies are automatically deleted after a specified period, which can differ depending on the cookie. You can delete the cookies at any time in the security settings of your browser.

You can configure your browser settings according to your preferences and, e.g., no accepting third-party cookies or any cookies. However, we would like to point out that you may not be able to use all functions of this website when disabling certain cookies.

More information on how cookies may be rejected by special browser plugins can also be found in the introduction to the chapter Integrated services below in our privacy notice.

 

Web analysis

It is important to us to design our website as best as possible and to make it appealing for our visitors. To thins end, we need to know which parts of it are received by our visitors and in what way. To do this, we use the following technologies in our interest.

Google Analytics

We use Google Analytics, a web analysis service from Google, on our website. Google Analytics uses cookies that are stored on your computer that enable us to analyse the use of the website. The information generated by the cookie about your use of our website is usually transferred to a Google server in the United States and stored there. We have activated IP anonymization on our website. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission. The entire IP address is only transmitted to Google in exceptional cases.

Revocation of the analysis of user behavior:

You can prevent the storage of cookies by modifying your browser settings accordingly. You can also prevent the collection of the data generated by the cookie (including your IP address) and the processing of this data by Google by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en. The use of alternative plugins or the deactivation of all cookies in the settings of your browser also prevents the analysis of your usage behaviour.

Alternatively, you can object to the use of your data by Google using the following link. An opt-out cookie is set, which prevents the future collection of your data when you visit our website.

[borlabs-cookie type=”btn-switch-consent” id=”google-analytics” title=”Google Analytics deaktivieren”/]

 

Warning: If you delete your cookies, the opt-out cookie will also be deleted and may have to be reactivated by you.

Service providers:

Google uses this information on our behalf to evaluate your use of the website, to compile reports on website activity and to provide us with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland.

Further information on data protection at Google Ireland Ltd. and Google Inc. (USA). can be found at:

https://support.google.com/analytics/answer/6004245?hl=en

https://policies.google.com/privacy?hl=en

Storage period:

The anonymized usage processes that are stores are deleted after 26 months at the latest. 

Legal basis for data processing:

We use Google Analytics in our own interest so that we can analyse the use of our website and improve it on a regular basis. We can use the statistics obtained to improve our offer and make it more appealing to you as a user, in accordance with Article 6 paragraph 1 letter f GDPR.

For the exceptional cases in which personal data (your IP address) is transferred to the USA, Google relies on the European standard contractual clauses:

https://policies.google.com/privacy/frameworks?hl=en

https://business.safety.google/compliance/#!?modal_active=none#gdpr

 

Integrated services 

For the design of our website and the provision of additional functions, we integrate the following external services in our own interest.

All services can be deactivated by using special plugins for your browser or, more specifically, the necessary connection to the corresponding servers is prevented. Please note, however, that the use of such tools could be associated with a loss in the familiar everyday convenience, because many things then no longer work as you might normally expect.

Interested readers are recommended to use tools such as NoScript, uBlock Origin or uMatrix. There are many tools that generally intend to make Internet traffic safer, but they are not automatically privacy friendly.

Incidentally, if configured correctly, these tools can also generally prevent web analysis or usage-based advertising networks and other connections to third-party providers that are automatically triggered in the background for all websites you visit.

Google Web Fonts

Google Web Fonts are implemented on our website. These are responsible for the representation of fonts. By using Google Web Fonts, a Google server in the United States is involved, and your IP address is transmitted to Google. If you are logged in to Google with an existing user account while visiting our website, Google may also be able to assign your visit to our website to your user behaviour. We have no influence on this procedure and we do not receive any information from Google about the transmitted content. If you do not wish to be assigned to your profile on Google, you must log out of Google before visiting our website again.

Service is provided by:

Provider: Google Inc. 1600 Amphitheater Parkway Mountain View, CA 94043, USA
Representative in the EU: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland.

Further information on data protection at Google Inc. can be found at:
https://policies.google.com/privacy?gl=en

Storage period:

See storage duration of the logs under informational use above in this privacy notice.

Legal basis for data processing:

The service is integrated to optimize our website in our own interest, in accordance with Article 6 paragraph 1 letter f GDPR.

For exceptional cases in which personal data (your IP address) is transferred to the USA, Google relies on the European standard contractual clauses:

https://policies.google.com/privacy/frameworks?hl=en

Google reCAPTCHA

The reCAPTCHA technology from Google is integrated into our contact form. With this, we protect ourselves against spam messages and overloading our websites through automated attacks. In principle, we would like you to confirm to us by means of a plausibility check that you are not a (bad) machine. By using Google reCAPTCHA, a Google server is involved, and your IP address is transmitted to Google. If you are logged in to Google with an existing user account while visiting our website, Google may also be able to assign your visit to our website to your user behaviour. In addition, Google can send additional cookies to your browser. We would like to point out that, as the provider of our websites, we have no knowledge of the content of the transmitted data or its use by Google and that we also have no way of further restricting the transmission of data to Google and its partners.

Analysis of your user behaviour by Google:

Google saves your data as a usage profile and uses it for advertising, market research and / or needs-based design of your website. Such an evaluation takes place (even for users who are not logged in), in particular, to provide needs-based advertising and to inform other users of the social network about your activities on our websites.

You have the right to object to the creation of these user profiles, although you must contact Google to exercise this right.

Service is provided by:

Provider: Google Inc. 1600 Amphitheater Parkway Mountain View, CA 94043, USA
Representative in the EU: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland

Further information on data protection at Google Inc. can be found at:
https://policies.google.com/privacy?gl=en

Storage period:

See storage duration of the logs under informational use above in this privacy notice.

Legal basis for data processing:

The service is integrated to secure our website in our own interest, in accordance with Article 6 paragraph 1 letter f GDPR.

For exceptional cases in which personal data (your IP address) is transferred to the USA, Google relies on the European standard contractual clauses:

https://policies.google.com/privacy/frameworks?hl=en

 

YouTube

We have integrated YouTube videos into our websites, which are stored on https://www.youtube.com and can be played directly from our website.

Basically, these YouTube videos are integrated in the extended data protection mode (YouTube internal function). Initially, only a connection to YouTube’s server is established under the domain “youtube-nocookie.com” and your IP address is transmitted to YouTube. Only when you play the videos, other personal data be transferred to YouTube (Google).

If you are logged in to Google with an existing user account while visiting our website, Google may also be able to assign your visit to our website to your user behaviour. In addition, further cookies can be sent to your browser by YouTube (Google). We have no influence on this procedure and we do not receive any information from YouTube (Google) about the transmitted content. We would like to point out that, as the provider of our website, we have no knowledge of the content of the data transmitted or its use by YouTube (Google) and that we also have no way of further restricting the transmission of data to YouTube (Google) and its partners. If you do not want the assignment to your profile on YouTube, you must log out before activating the video.

Analysis of your user behaviour by YouTube (Google):

YouTube (Google) saves your data as a user profile and uses it for advertising, market research and / or needs-based design of your website. Such an evaluation takes place (even for users who are not logged in), in particular, to provide needs-based advertising and to inform other users of the social network about your activities on our websites.
You have the right to object to the creation of these user profiles, although you must contact YouTube (Google) to exercise this right.

Service is provided by:

Provider: YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA
Further information on data protection at YouTube Inc. (Google Inc.) can be found at:

https://policies.google.com/privacy?hl=en

Storage period:

See storage duration of the logs under informational use above in this privacy notice.

Legal basis for data processing:

The service is integrated to optimize our website in our own interest, in accordance with Article 6 paragraph 1 letter f GDPR.

For the exceptional cases in which personal data (your IP address) are transferred to the USA, YouTube (Google) relies on the European standard contractual clauses:

https://policies.google.com/privacy/frameworks?hl=en

 

Social media links

There are links to various social media services with the corresponding logos on our website. These are not social media plug-ins, but merely a link to our offers / channels within these services. If you click on one of these links, your IP address will be transmitted to the operators of the respective platform. If you use one of these services and are also logged in with your specific account, information on your internet usage behaviour may also be recorded by the social media service. The transmission of your IP address to the operator of the accessed websites is technically necessary and applies to all websites.

 

Processing of your personal data in countries outside the EU and the EEA (third countries)

Your personal data will not be processed in countries outside the European Union and the European Economic Area, except for the United States (see integrated services).

 

Your rights

You have the following rights vis-à-vis us concerning your personal data:

  • Right to information and access,
  • Right to correction or deletion,
  • Right to restriction of processing,
  • Right to data portability.

Right to complain to a supervisory authority

You also have the right to complain to a data protection supervisory authority about the processing of your personal data by us.

The supervisory authority directly responsible for us is:

State Commissioner for Data Protection in Lower Saxony
www.lfd.niedersachsen.de

Right of objection and right of withdrawal

If you have given your consent to the processing of your data, you can revoke this at any time. Such a revocation affects the permissibility of the processing of your personal data after you have given it to us.

If we base the processing of your personal data on the balancing of interests (Article 6 paragraph 1 letter f GDPR), you can object to it. This is the case if the processing is not particularly necessary to fulfil a contract with you, which is addressed by us in the explanation of the individual data processing and functions on our website above in this data protection notice. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either stop or adjust the data processing or point out to you our compelling legitimate grounds for the processing on the basis of which we will continue the processing.


Right to object to direct advertising

Of course, you can object to the processing of your personal data for the purposes of advertising and data analysis at any time, e.g., when you receive advertising in form of a newsletter, customer magazine or information material by post from us as part of a business relationship.

If we use your data in the context of functions of our website for direct advertising and an associated data analysis, we will inform you about this data processing above in this data protection notice, including the possibility of exercising your right of revocation using technical means.

Contact options regarding your rights

You can contact us at any time to exercise your rights. It is best to use the following email address: info@iph-hannover.de

You are also welcome to use one of the contact options in our imprint or contact our data protection officer directly (contact details above).

 

Data security

We also use technical and organisational security measures to protect any personal data that arises or that has been collected. In particular, these measures protect against accidental or deliberate manipulation, loss, destruction or against attacks by unauthorized persons. Our security measures are continuously improved in line with technological developments.

The transmission of your personal data is encrypted using SSL technology (https) to prevent access by unauthorized third parties.

Communication by email

Our e-mail systems support encrypted communication using SSL technology (TLS 1.2 including PFS). The transmission of your e-mail can therefore always be encrypted. Please note, however, that the encryption also depends on the configuration of your email application, and we therefore cannot guarantee complete data security for the transport route.

For information that requires a high degree of confidentiality, we recommend that you send it by post.