applications. It also explains the choices you have about your personal information and how you can contact us.
I. General information
1. Overview of contents
With the following information, NABU Niedersachsen e.V. first gives you an overview of the office responsible for data processing, the contact details of your contact person for data protection and your rights as a data subject. In Part II, we then present the processing of your personal data as a member, donor, interested party and business partner in accordance with the DSGVO. Finally, Part III gives you an overview of the processing of your personal data when you visit our website and the Facebook fan page. Information on the cookies used on the website can be found under the Cookie Directive[e1] . Information on the use of mobile applications (our "Apps") can be found in the respective App.
2. Responsible authority and contact data
Responsible authority for the processing of your personal data is:
NABU Lower Saxony e.V.
You can also reach our contact person for data protection at the above address or by e-mail at firstname.lastname@example.org
3. Your data protection rights
Insofar as contractual and legal obligations do not contradict this, you as the party concerned are entitled to the following further rights in principle:
- Right to information (Art. 15 DSGVO) with the restrictions of §§ 34, 35 BDSG n.F.;
- Right to correction of inaccurate data (Art. 16 DSGVO);
- Right to deletion (Art. 17 DSGVO) with the restrictions according to §§ 34, 35 BDSG n.F.;
- Right to limit the processing of personal data (Art. 18 DSGVO);
- Right to data transferability (Art. 20 DSGVO);
- Right to complain to a data protection supervisory authority (Art. 77 DSGVO);
Rights of objection
There is an individual right of objection (Art. 21 para. 1 DSGVO) for reasons arising from your particular situation and relating to data processing pursuant to Art. 6 para. 1 lit. e) and Art. 6 para. 1 lit. f) DSGVO. In this case, the objection against data processing must be justified. If the data processing is based on a consent, your consent can be revoked at any time with effect for the future.
Furthermore, there is a right to object to the processing of data for advertising purposes (cf. Art. 21 para. 3 DSGVO), the so-called right to object to advertising. You can object to the use of your data for advertising purposes, including an analysis of data for advertising purposes, at any time without stating reasons and with effect for the future under the contact data listed above (see section 1.).
The easiest way to exercise the rights of data subjects is to contact email@example.com. In addition, you have the right to lodge a complaint with the data protection supervisory authority responsible for you.
II. Processing your personal data as a member, donor, interested party and business partner
1. Categories of personal data
Which categories of personal data are processed by NABU Niedersachsen e.V. depends to a large extent on the occasion and extent to which a contact or contractual relationship arises or exists with you. A distinction must be made, for example, between members, donors, interested parties and business partners. NABU Niedersachsen e.V. generally processes the following categories of data within the framework of a membership, a donation, a participation campaign, a request, a consent or any other contract, depending on the concrete relationship:
- Name, first name, address, contact data (telephone, e-mail), date of birth, place of birth, marital status,
Branch/occupation; further data on family members, e.g. family memberships, member and occupation
- Company name, if applicable also consisting of surname, first name, address, contact data (telephone, e-mail),
Industry sector, contact person in the company with surname, first name, function, contact data (telephone,
- Identity data (e.g. ID card data), Authentiﬁkationsdaten (e.g. specimen signature), tax ID;
- Payment transaction and order data (e.g. bank account/credit card data, payment orders), credit assessment
score (payment history with business partners);
- Order history and sales with business partners;
- Member and donor histories, interested party histories with regard to legacies.
If there are direct contacts with you during the membership, the donation and prospective customer support of participation actions or a business relationship, further data such as information about contact channel, date, occasion and result and copies of the correspondence will be processed.
2. purposes of the data processing and legal bases
If you as NABU Niedersachsen e.V. have given us your consent to process personal data for certain purposes, the lawfulness of this processing is given on the basis of your consent in accordance with Art. 6 Para. 1 lit. a) DSGVO. A given consent can be revoked at any time with effect for the future under the contact data listed above (see point 1.). Consents can be given for the following, among other things
- the sending of a NABU newsletter oriented to your interests (e.g. within the scope of information requests)
to your e-mail address;
- the use of the occasion resp. content of a participation in petitions for the purpose of ensuring that the content of
the petition is in line with the interests of the interested party Design of the newsletter, whereby, depending on the
content of the petition, special categories are personal data in accordance with Art. 9 DSGVO and the consent to
this is a separate Note contains;
- the telephone advertising within the scope of the statutory purposes of NABU Niedersachsen e.V. also for
donations for the benefit of NABU Niedersachsen e.V.
NABU Niedersachsen e.V. also processes your aforementioned personal data and categories of personal data in order to fulfil the respective contract (e.g. membership, donation, participation action, other business relationship) or to carry out pre-contractual measures (e.g. contact enquiries, information orders) with you in accordance with Art. 6 para. 1 lit. b) DSGVO. Your contact data will also be used for these purposes, for example in the context of concrete information and queries.
NABU Niedersachsen e.V. is also subject to various legal requirements (e.g. money laundering law, tax laws, principles of proper accounting) and processes your data in this respect also on the basis of legal requirements pursuant to Art. 6 (1) c) or in the public interest pursuant to Art. 6 Para. 1 lit. e) DSGVO. The purposes of processing include, but are not limited to
- the application and verification obligations within the framework of grants by public bodies;
- the prevention of fraud and money laundering;
- compliance with tax control and reporting obligations and auditing requirements;
- compliance with official and court directives and orders;
- as well as the assessment and management of risks at NABU.
If necessary, the NABU Niedersachsen e.V. processes Your data within the scope of the balancing of interests pursuant to Art. 6 para. 1 lit. f) DSGVO in order to safeguard the legitimate interests of NABU or third parties. For example:
- Measures to control the association and further develop statutory tasks
- Assertion of legal claims and defence in legal disputes;
- Guarantee of IT security and IT operations of Niedersachsen e.V.;
- Prevention of criminal offences;
- Measures for building and plant security (e.g. access controls);
- Use of the guest WLAN;
- Data exchange with credit agencies to determine creditworthiness and default risks for business partners.
NABU Niedersachsen e.V. also processes data within the scope of the balancing of interests pursuant to Art. 6 (1) f) DSGVO for the protection of legitimate interests of NABU Niedersachsen e.V. Your data, for example, on the basis of membership, the donation relationship, participatory campaigns, existing contracts or requests for needs-based information within the framework of the statutory purposes of NABU Niedersachsen e.V., will be processed by NABU Niedersachsen e.V. on the basis of the following criteria (self-advertising) in accordance with the following conditions:
- postal advertising if you have not objected to this processing; you can use this promotional
Use at any time with effect for the future under the contact data listed above (see point 1).
(see section 7.);
- telephone advertising to companies in the case of your presumed consent
unless you have objected to this processing; you can use this promotional use at any time.
with effect for the future under the contact details given above (see point 1.) (see point
NABU Niedersachsen e.V. does not pass on your data to third parties for advertising purposes.
3. recipients and categories of recipients of the data
Within the NABU Niedersachsen e.V., only those offices will have access to your data which they require for the fulfilment of our above-mentioned purposes and for the fulfilment of further tasks which are directly and indirectly connected with these purposes and which are covered by one of the above-mentioned legal bases. Service providers used by NABU Niedersachsen e.V. may also receive data for these purposes if they are commissioned as processors in accordance with Art. 28 DSGVO. Furthermore, some cooperation partners receive data if this is necessary for the fulfilment of our above-mentioned purposes in connection with the cooperation, in particular if it concerns a joint responsibility according to Art. 26 DSGVO. A secure transfer of the data is guaranteed taking into account the state of the art and the means available.
Possible recipients of personal data are for example:
- NABU e.V. within the framework of its statutory, multi-tiered membership in NABU.
Federal office, the NABU regional associations responsible for your place of residence and regional divisions;
- Cooperation partners and joint data controllers, with whom joint actions and
Projects (e.g. participatory campaigns) can be carried out online or using print products;
- public bodies and institutions (e.g. municipalities, tax authorities, Federal Central Tax Office)
if there is a statutory or official obligation or other cooperation in the sense of the
- other credit and financial services institutions;
- Contract processors, for example, for membership and fundraising, for the support/maintenance of
EDP/IT applications, archiving, document processing, call center services, compliance services, the
Controlling, data screening according to legal requirements, printing and shipping of personalized
the sending of letters, e-mails, data destruction, auditing services, and the
- Credit bureaus in the context of a creditworthiness enquiry about companies;
- other data recipients on the basis of your consent.
4. transfer of data to a third country or an international organisation
A data transfer to countries outside the EU or the EEA (so-called third countries) ﬁndet only takes place if this is necessary for the execution of your orders, legally prescribed (for example, tax reporting obligations), you have given us consent or in the context of order data processing. If service providers are used in a third country, they must, in addition to written instructions, take appropriate measures (e.g. agreement of the EU standard contract clauses) to comply with the data protection level in Europe verpﬂichtet.
5. duration of data storage
NABU processes and stores your personal data as long as it is necessary for the fulfilment of its contractual and legal obligations Pﬂichten and on the basis of the existing consents as well as the weighing of interests under consideration of the respective data category. If the data are no longer required for this purpose, they are deleted regularly unless their further processing - for a limited period - is necessary, for example in a separate archive with limited access rights, for the following purposes:
- Compliance with commercial and tax retention periods (e.g. German Commercial Code),
tax code, the German Banking Act and the Money Laundering Act with the deadlines specified therein.
storage or documentation for a period of two to ten years);
- Preservation of evidence within the framework of the statute of limitations (e.g. the Civil Code with its
a limitation period of up to 30 years and a regular limitation period of three years).
6. obligation to provide data
In the context of a business relationship (e.g. memberships, donation processing, other contracts) you must provide the personal data that is required for the establishment and implementation of a business relationship and the fulfilment of the associated contractual Pﬂichten or for the collection of which we are legally verpﬂichtet Without this data we will normally have to refuse the conclusion of the contract or the execution of the order or will no longer be able to execute an existing contract and may have to terminate it.
III. to process your personal data when visiting the website
1. notes on ensuring data security
We take technical and operational security precautions on our pages in order to protect the personal data stored with us against access by third parties, loss or misuse and to enable secure data transfer.
However, we must point out that due to the structure of the Internet, unwanted data access by third parties may occur. It is therefore also your responsibility to protect your data against misuse by encryption or other means. Without appropriate protective measures, unencrypted data in particular can be read by third parties, even if this is done by e-mail.
2. processing of data when accessing our website - log files
When you access our website, information of a general nature is automatically collected. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your Internet service provider and the like. In addition, the IP address is transmitted and used to use the service you have requested. This information is technically necessary in order to correctly deliver content requested by you from websites as well as to combat misuse and is mandatory when using the Internet. The data will not be passed on or used in any other way. However, we reserve the right to subsequently check the server log files in concrete cases of suspicion of illegal use.
This log file data is automatically deleted after 7 days after the end of the usage process. The legal basis for data processing is our legitimate interest pursuant to Art. 6 Para. 1 lit. f) DSGVO.
3. data processing when accessing our website - cookies
Our website uses so-called cookies. Cookies are small text files that are stored on your terminal and stored by your browser. They serve to make our offers more user-friendly, more effective and safer. We use so-called temporary cookies, which are automatically deleted when you close your browser ("session cookies"), as well as persistent (permanent) cookies.
You have the choice whether you want to allow the setting of cookies or not. You can make changes in your browser settings. You can choose whether you want to accept all cookies, be informed when cookies are set or reject all cookies. If you choose the last option, it is possible that you will not be able to use our services in full. When cookies are used, a distinction must be made between the mandatory cookies and those required for further purposes (measurement of access figures, advertising purposes).
4. data processing when using the website - your requests
If you send us an enquiry by e-mail or via the contact form on the website, we collect the data you provide for processing and answering your request. We store this information for verification purposes for a period of up to two years. The legal basis for data processing is Art. 6 para. 1 lit. b) or f) DSGVO. For more information on the service providers we use, see below.
5. integration of external services
The website is hosted by the service provider Jimdo GmbH, Stresemannstr. 375, 22761 Hamburg Germany, who provides the following services: Infrastructure and platform services, computing capacity, storage space and database services, e-mail dispatch, security services and technical maintenance services. Some of these services are made possible by the integration of additional service providers.
Integration of Google Analytics:
This website uses Google Analytics, a web analysis service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website will generally be transmitted to and stored by Google on servers in the United States. However, due to the activation of IP anonymisation on this website, your IP address will be shortened by Google in advance within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA where it will be shortened. In this case, personal data is transferred to a third country. On our behalf, Google will use this information to evaluate your use of the website, compile reports on website activity and provide us with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google.
We use Google Analytics to analyse the use of our website and to improve it regularly. The statistics obtained allow us to improve our services and make them more interesting for you as a user. For the exceptional cases in which personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. The legal basis for the storage of cookies is the consent given (Art. 6 Para. 1 S. 1 lit. a DS-GVO). The further evaluation of the collected data by means of Google Analytics takes place over a period of [two] years on the basis of Art. 6 Para. 1 S. 1 lit. f DS-GVO.
Further information can also be found at http://tools.google.com/dlpage/gaoptout?hl=en or https://www.google.de/intl/de/policies/privacy/ (general information on Google Analytics and data protection).
Status: May 2018
Update: November 2018