FOUR PAWS Data Privacy Statement

Data Privacy Statement US

Data protection is important to us!

7/11/2022

1. General Information

1.1. Objective and Responsibility 

1. 1.      This Data Privacy Statement is to inform you about the nature, scope and purpose of the processing of personal data related to our services and the related websites, features and contents (hereinafter collectively referred to as "online service" or "website"). Details of these processing activities can be found in section 2.

2.      Details of data processing for the purpose of carrying out our business processes are described in section 3.

3.      The online service is provided by FOUR PAWS International, Inc. 36 Bromfield Street, #410. Boston, MA 02108 – hereinafter referred to as "provider", "we" or "us" - who is also legally responsible under the data protection law.

4.      Our online service is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, and is maintained by web&co, Marxergasse 5/24, A-1030 Vienna, Austria.

5.       You can reach out to our Data Protection Officer using the e-mail address info@fourpawsusa.org  or under (617) 942-1233

The term "user" encompasses all 

1.2. Legal Bases

We collect and process personal data based on the following legal grounds:

a.       Consent in accordance with Article 6 paragraph 1 (a) General Data Protection Regulation (GDPR). Consent meaning any freely given, specific, informed and unambiguous indication of agreement, which could be in the form of a statement or any other unambiguous confirmatory act, given by the data’s subject consenting to the processing of personal data relating to him or her.

b.      Necessity for the performance of a contract or in order to take steps prior to entering into a contract according to Article 6 paragraph 1 (b) GDPR, meaning the data is required in order for us to fulfil our contractual obligations towards you or to prepare the conclusion of a contract with you.

c.       Processing to fulfil a legal obligation in accordance with Article 6 paragraph 1 (c) GDPR, meaning that e.g. the processing of data is required by law or other provisions.

d.      Processing in order to protect legitimate interests in accordance with Article 6 paragraph 1 (f) GDPR, meaning that the processing is necessary to protect legitimate interests pursued by us or by a third party, unless such interests are overridden by your interests or fundamental rights and freedoms which require the protection of personal data.

1.3. Data Subject Rights

You have the following rights with regards to the processing of your data through us:

a.       The right to lodge a complaint with a supervisory authority in accordance with Article 13 paragraph 2 (d) GDPR and Article 14 paragraph 2 (e) GDPR.

b.      Right of access in accordance with Article 15 GDPR

c.       Right to rectification in accordance with Article 16 GDPR

d.      Right to erasure (”right to be forgotten“) in accordance with Article 17 GDPR

e.      Right to restriction of processing in accordance with Article 18 GDPR

f.        Right to data portability in accordance with Article 20 GDPR

g.       Right to objection in accordance with Article 21 GDPR

Notice: Users may object to the processing of their personal data in accordance with legal allowances at any time with effect for the future. The objection may in particular be made against processing for the purposes of direct marketing.

Without prejudice to any other administrative or judicial remedy, you shall have the right to complain to a supervisory authority, in particular in the Member State of your place of residence, employment or the place of the alleged infringement, if you believe that the processing of your personal data violates the GDPR.

1.4. Data Erasure and Duration of Storage

The personal data of the data subject will be erased or blocked as soon as the purpose of the storage is inapplicable. Storage of data beyond that may occur if such storage is required by the European or national legislator in EU regulations, laws or other regulations to which the controller is subject. Blocking or erasure of data also takes place when a retention period mandated by the standards mentioned expires, unless the continued storage of data is required for the conclusion of a contract or the fulfillment of contractual obligations.

1.5. Security of Processing

1.      We have implemented appropriate and state-of-the-art technical and organizational security measures (TOMs). Thus, the data that is processed by us is protected against accidental or intentional manipulation, loss, destruction and unauthorized access.

2.      These security measures include in particular the encrypted transfer of data between your browser and our server.

1.6. Transfer of Data to Third Parties, Subcontractors and Third Party Providers

1. A transfer of personal data to third parties only occurs within the framework of legal requirements. We only disclose personal data of users to third parties, if this is required e.g. for billing purposes or other purposes, if the disclosure is necessary to ensure the fulfillment of contractual obligations towards the users.

2. If we engage subcontractors for our online service, we have made appropriate contractual arrangements as well as adequate technical and organizational measures with these companies.

3. If we use content, tools or other means from other companies (hereinafter collectively referred to as "third party providers") whose registered offices are located in a third country, it is assumed that a transfer of data to the home countries of these third party providers occurs. The transfer of personal data to third countries takes place exclusively only, if an adequate level of data protection, the user’s consent or another legal permission is present.

2. Processing Activities within the Scope of our Online Service 

2.1. Collection of Information

1. When using our online service, information may be transferred automatically from the browser of the user to us; this information includes the name of the accessed website, file, date and time of the access, amount of data transferred, notification about successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider.

2. The processing of this information takes place based on legitimate interests in accordance with Article 6 paragraph 1 (f) GDPR (e.g. to optimize the online service) as well as to ensure the security of processing in accordance with Article 5 paragraph 1 (f) GDPR (e.g. for the defense and clarification purposes of cyber attacks).

3. This information will be automatically deleted 30 days after the termination of the connection, unless any other retention periods require otherwise.

4. The collection of the data and the storage of the data in log files is essential for the provision of the online service. Therefore users are not entitled to the options of erasure, objection or correction.

2.2. Tools in our Domain

Google Tag Manager

1. This website uses the Google Tag Manager. This service allows website tags to be managed through an interface. The Google Tool Manager only implements tags, does not set cookies and does not collect any personal data. The Google Tag Manager triggers other tags that may collect personal information. However, the Google Tag Manager does not access this data.

2. If deactivated at domain or cookie level, it will remain valid for all tracking tags implemented with Google Tag Manager.

Google Analytics

1. We use Google Analytics, a web analytics service of Google Ireland Limited (Gordon House Barclays Dublin Ireland - hereinafter "Google"), on the basis of your consent for the analysis, optimization and economic operation of our online offer pursuant to Art. 6 para. 1 lit. a. GDPR. Google uses cookies and other technologies. The information generated by the service about the use of the online offer by the users is transmitted to a Google server in the USA and processed there.

2. Google acts on our behalf within the framework of order processing in accordance with Article 28 GDPR. We have concluded a data protection agreement with Google that contains the EU standard data protection clauses.

3. We use Google Analytics with IP anonymization enabled.

4. Google Analytics stores cookies in your web browser for a period of two years since your last visit. These cookies contain a randomly generated user ID that can be used to recognize you during future website visits. Users can prevent the storage of cookies by setting their browser software accordingly; users can also prevent the collection of data generated by the cookie and related to their use of the online offer to Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

5. The recorded data is stored together with the randomly generated user ID, which enables the evaluation of pseudonymous user profiles. This user-related data is automatically deleted after 26 months. Other data remains stored in aggregated form indefinitely.

6. For more information on data usage by Google, settings and revocation options, please visit Google's websites:

https://policies.google.com/technologies/partner-sites ("Data use by Google when you use our partners' websites or apps").

https://policies.google.com/technologies/ads ("Data use for advertising purposes")

https://adssettings.google.com/authenticated ("Manage information Google uses to serve ads to you").

Cloudflare

On our website Cloudflare is used as a so-called content delivery network (CDN). Cloudflare is a service of Cloudflare Inc., 101 Townsend Street, San Francisco, California 94107, USA, ("Cloudflare").

ATTENTION: Within the scope of this service, data is transferred to the US or such a transfer cannot be excluded.

A CDN is a service that helps us to provide content from our website, especially large media files, such as images, by using regional and Internet-connected servers to be delivered faster. Delivering content through servers near you reduces average website load times.

Cloudflare contributes both web optimization and security services. Cloudflare blocks threats and limits misuse of server resources and bandwidth. Our website is significantly more powerful and less vulnerable to spam or other attacks thanks to Cloudflare.

Cloudflare uses cookies and processes data of our website users.

If you visit our website, your requests will be directed by the server of Cloudflare. In this case, statistical access data is collected when visiting our website.

Access data includes:

- your IP address,
- the address(es) of our website you have visited,
- type and version of the internet browser you are using,
- the operating system you are using,
- the website from which you have switched to our website (referrer URL),
- the time of your stay on our website and
- the frequency of calling our websites.

This data helps Cloudflare in particular to detect new threats and to ensure a high security standard for the operation of our website.

Your data is processed to maintain the security and functionality of the CDN and to optimize our loading times. The use of cookies by Cloudflare is done for security reasons to ensure the trustworthiness of an end device and is absolutely necessary for the security function. This represents a legitimate interest within the meaning of Art 6 paragraph 1 lit. f GDPR.

Cloudflare keeps data logs only as long as necessary and this data is deleted within 24 hours in most cases. However, there is information that Cloudflare keeps indefinitely as part of its permanent logs in order to improve Cloudflare's overall performance. However, this data is not personal and is anonymized by Cloudflare. What data is involved can be found at https://www.cloudflare.com/application/privacypolicy/.

For more information on handling the transferred data to Cloudflare, see Cloudflare's Privacy Policy: https://www.cloudflare.com/en-gb/privacypolicy/ 

Google APIs & Google Fonts

To display fonts consistently, our website uses Web Fonts which are provided by Google. Google Fonts is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). In order to use these Web Fonts we also use Google APIs

To display web fonts, the web browser you use must connect with a Google server. This informs Google that our website is being accessed via your IP address. The IP address from the browser of the device you are using to access our site is also stored by Google. If your browser does not support Web Fonts, your device will display the site using a standard font type. With each Google Font request, your IP address is automatically transferred to a Google server along with information such as your language preferences, display resolution, version and name of your browser. The usage data collected by Google enables them to determine the popularity of specific font types. Google publishes these findings on internal analytics sites (e.g. Google Analytics).

For more information about Google Fonts, refer to https://developers.google.com/fonts/faq and the Google Privacy Policy: https://policies.google.com/privacy

Google Photos

To display video thumbnails, our website uses Google Photos which are provided by Google. Data is not collected by their use. For more information on the Google Privacy Policy visit the Google Privacy Policy: https://policies.google.com/privacy.

Google Maps

Google Maps is an online map service that makes geographical information more readable for you as a user via your device. Among other things, directions are displayed or map sections of a location can be integrated into a website.

When Google Maps is started, your browser establishes a connection to Google's servers. This enables Google to know that our website has been accessed via your IP address. The use of Google Maps enables Google to collect and process data on the use of the service.

In addition to your IP address, Google Maps processes search terms entered and latitude and longitude coordinates for the provision of this service. If you use the route planner function of Google Maps, the starting address entered will also be stored. This data processing takes place exclusively through your voluntary use of Google Maps and is not within our sphere of influence.

The data processing terms and conditions for Google products and the standard contractual clauses for data transfers to third countries can be found at https://business.safety.google/adsprocessorterms/

Google Ad Services

1. This website uses the remarketing or "similar target group" function of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ("Google").

2. You can be targeted with advertising by placing personalized and interest-based ads when you visit other websites in the so-called "Google Display Network". "Google Remarketing" or the function "Similar target groups" uses so-called "cookies", text files which are stored on your computer and which enable an analysis of your use of the website. These text files are used to record your visits and anonymous data about the use of the website. Personal data will not be stored. If you visit another website in the so-called "Google Display Network", you may see advertisements that most likely take into account product and information areas previously accessed on our website.

3. You can prevent the "Google Remarketing" or the "Similar target group" function by preventing the storage of cookies by setting your browser software accordingly. However, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website and from processing this data by Google by downloading and installing the browser plug-in available under the following link: https://www.google.com/settings/ads/plugin?hl=en. You may also disable the use of cookies by third parties by visiting the Network Advertising Initiative deactivation page at http://www.networkadvertising.org/choices/  and implementing the additional opt-out information described therein.

4. Google's privacy policy for remarketing with further information can be found here: https://www.google.com/privacy/ads/.

Google AdWords Conversion Tracking

1. This website uses the "Google AdWords Conversion Tracking" function of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ("Google").

2. Google AdWords Conversion Tracking uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site when they click on a Google ad. The cookies are valid for a maximum of 90 days. Personal data will not be stored. As long as the cookie is valid, Google and we as website operators can recognize that you clicked on an ad and reached a specific target page (e.g. order confirmation page, newsletter registration). These cookies cannot be tracked across multiple websites by different AdWords participants. The cookie creates conversion statistics in "Google AdWords". These statistics record the number of users who clicked on one of our ads. It also counts how many users have reached a target page that has been provided with a "conversion tag". However, the statistics do not contain any data with which you can be identified.

3. You can prevent cookies from being stored on your hard disk by selecting "do not accept cookies" in your browser settings (in MS Internet Explorer under "Tools > Internet Options > Privacy > Settings"; in Firefox under "Tools > Settings > Privacy > Cookies"); however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent.

4. By using this website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.

5. For more information on how Google uses conversion data and Google's privacy policy, please visit: https://support.google.com/adwords/answer/93148?ctx=tltp , https://policies.google.com/privacy

YouTube

1. We use YouTube for the integration of videos. The videos were embedded in the extended data protection mode.

2. YouTube's website uses cookies to collect information about the users of its website. YouTube uses them, among other things, to collect video statistics, to prevent fraud and to improve user-friendliness.

3. By using YouTube, a connection is established with the Google Ad Manager network. Starting the video could trigger further data processing. We have no influence on that.

4. For more information about privacy at YouTube, please see their privacy policy at: https://www.youtube.com/t/privacy_at_youtube

Google Ad Manager

1. Google Ad Manager by Google is a service of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").

2. Google Ad Manager by Google uses cookies to serve ads relevant to you. Your browser is assigned a pseudonymous identification number (ID) to check which ads have been displayed in your browser and which ads have been called. The cookies do not contain any personal information. The use of Google Ad Manager cookies only allows Google and its partner websites to serve ads based on previous visits to our or other websites on the Internet. The information generated by the cookies is transmitted by Google to a server in the USA for analysis and stored there. Under no circumstances will Google match your data with other data collected by Google.

3. By using our website, you consent to the processing of data about you by Google and the manner of data processing described above as well as the named purpose.

4. You may refuse the use of cookies by selecting the appropriate settings on your browser. You can also prevent Google from collecting the data generated by the cookies and relating to your use of the website and from processing this data by Google by downloading and installing the browser plug-in available under the following link under "Extension for Google Ad Manager deactivation".

5. For more information about Google Ad Manager by Google and privacy, please visit: https://policies.google.com/technologies/ads?hl=en

jQuery

1. We use jQuery CDN services by the jQuery Foundation to quickly and easily deliver our website and subpages to you on different devices. jQuery is distributed via the Content Delivery Network (CDN) of the American software company StackPath (LCC 2012 McKinney Ave. Suite 1100, Dallas, TX 75201, USA). This service stores, manages and processes your personal data.

2. A content delivery network (CDN) is a network of regionally distributed servers that are connected to each other via the Internet. Through this network content and especially very large files, can be delivered quickly – even in peak demand periods. jQuery creates a copy of our website on its servers. Thus, our website can be delivered as quickly as possible. This means the data transfer to your browser is shortened by a CDN.

3. It goes without saying that we want to provide you with a comprehensive and well-functioning service on our website. This of course includes our website loading swiftly. Thanks to jQuery you can load our website much faster. The implementation of jQuery is particularly helpful for users from abroad, since the page can then be delivered from a server nearby.

4. StackPath’s privacy policy explicitly mentions that StackPath uses aggregated and anonymized data of various services (such as jQuery) for both, security enhancement and its own services. However, it is impossible for you to be personally identified with the use of this data.

5. If you want to avoid this data transfer, you always have the option to use JavaScript blockers such as ghostery.com or noscript.net. You can also simply deactivate the execution of JavaScript codes in your browser. If you decide to deactivate JavaScript codes, the usual functions will also change. For example, websites may no longer load as quickly.

6. For more information please click on the following link: https://privacy-policy.openjsf.org

Hotjar

We use Hotjar in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf.

For further details, please visit Hotjar’s website: https://www.hotjar.com/legal/policies/privacy/.

Font Awesome

Font Awesome provides us with an icon library and toolkit that allow us to scale vector images and customize them with CSS.

For further details, please visit Font Awesome’ s website:

https://cdn.fontawesome.com/privacy

Google reCAPTCHA

1. We use Google's reCAPTCHA service, which protects our site from spam and misuse. The service prevents automated software (so-called bots) from executing abusive activities on our websites, which means that it is checked whether the entries made actually come from a human being. Google collects the following data:

·       Referrer (address of the page where the captcha is used)

·       IP address of the user

·       Google account (if the user is registered with Google, this is recognized and assigned)

·       The input behavior of the user (eg, input speed into the form fields, order of selection of the input fields by the user) is used to improve pattern recognition on Google.

·       Browser, browser size and resolution, browser plugins, date, language settings

·       Presentation instructions (CSS) and scripts (Javascript) of the website

·       Mouse and touch events within the page

2. Google also reads cookies from other Google services, such as Gmail, Search, and Analytics. All data are encrypted and sent to Google. There is no reading or saving of personal data from the input fields of the respective form.

3. For more information about Google's privacy policy, visit http://www.google.com/policies/privacy/

4. The processing of this information takes place based on legitimate interests in accordance with Article 6 (1) (f) GDPR.

AB Tasty

We use the web analysis service AB Tasty from the company AB TASTY SAS (17-19 Rue Michel-le-Comte, 75003 Paris, France). This service is used to carry out A/B or multivariate tests and thus continuously improve our online offering. Further information on the processing of your data can be found at: https://www.abtasty.com/privacy-policy/

Collection of usage data and statistical evaluation

AB Tasty collects statistical information about visitor access. This information is usage data (browser used, number of pages viewed, number of visits, order of visit, duration of visit, interactive actions such as filling/emptying a shopping cart, recording of the use of individual websites (except in check-out and in the registration process), etc.) which are collected anonymously and statistically evaluated. For this processing it is not possible to draw conclusions about a specific person at any time.

Geolocation

In addition, AB Tasty process your IP address to geolocate the visitors of FOUR PAWS' websites as part of the TCP/IP protocol. (regional details of your location). The IP address is used to extract the geolocation of the visitor on a city-wide scale.

This processing occurs in Belgium, via AB Tasty’s subprocessor Google Ireland (GCP).

The following personal data will be processed due to geolocation:

o   The IP address of the visitors of FOUR PAWS' websites

The legal basis for the processing is your consent in accordance with Article 6 (1) (a) GDPR. You can withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

After geolocation, which takes place when you visit the site immediately after you consent, your IP address will be deleted immediately and will not be stored.

Creation of a personalised pattern

To display content that caters to your interests, a personalized pattern is formed. This pattern is encrypted.

The following aspects will be taken into account when creating content specific to your profile and connected to your IP address:

o   A click

o   A hover

o   A pageview

o   A transaction

o   A bounce

o   A scroll

o   The number of seconds on a page

o   A form-filling

o   A validation

o   An upload/download

o   An element that arrives on the visible screen area (above the fold)

o   etc.

The legal basis for the processing is your consent in accordance with Article 6 (1) (a) GDPR. You can withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Your personalised pattern will be stored for a period of 13 months and deleted automatically or until you revoke your consent.

Cookies

Cookies are stored to save and recognise site visitors. AB Tasty places the following cookies on the terminal of Visitors of the Site or on connected tools:

A) Two purely technical cookies:

1. The "ABTasty" cookie: it checks whether the Visitor's terminal can technically accept the writing of a cookie or, on the contrary, whether it refuses it;

2. The "ABTastyDomainTest" cookie: it validates that the JS Tag is running on the Customer’s URL.

The life span of these two cookies is only a few dozen milliseconds. They are immediately deleted from the Visitor's terminal.

B) Two non-technical cookies:

1. The "ABTastySession" cookie: it stores the Visitor's arrival page, the fact that the Visitor opens a new session, and other technical-functional data. It is deleted 30 minutes after the last page viewed by the Visitor.

2. The "ABTasty" cookie: it stores behavioral information of the Visitors of the Website or other connected tools of the Customer and in particular the anonymous Visitor ID which allows to collect the Anonymous Information related to the behavior of the Visitors and which are linked to:

i. to the machine used (device) by the Visitor;

ii. the browser used by the Visitor, and;

iii. physical actions taken by the Visitor (e.g. using a keyboard, a computer mouse, or such other tools on a tactile keyboard).

These have a maximum storage period of 13 months and are then automatically deleted.

The legal basis for the two non-technical cookies is your consent in accordance with Article 6 (1) (a) GDPR. You can withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Playable

Playable will only collect Personal Information where the information is necessary for Playable to perform one or more of its functions or activities. In this context, “collect” means gather, acquire or obtain by any means, information in circumstances where the individual is identifiable or identified.

Playable collects Personal Information primarily to supply organizations and individuals who obtain Playable products and services directly from Playable with information and details of its products and services. Playable also collects and uses Personal Information for secondary purposes including:

1. provision of products and services;

2. accounting purposes; and

3. business planning and product development.

For more information on data usage by Playable, settings and revocation options, please visit their website: https://playable.video/privacy-policy/

3. Processing for the purpose of carrying out our business processes

3.1. Contact Form and Contacting via e-mail

1. When contacting us (via online form or e-mail), the data provided by the user will be processed exclusively for processing the inquiry and its handling.

2. Any other use of the data will only take place based on the given consent from the user.

3. The users' data will be stored in our Customer Relationship Management System (Salesforce) or a comparable software/database. The legal retention periods for business letters apply.

3.2. Newsletter and e-mail Communication

1. With the following information we inform you about the contents of our newsletter and e-mail communication as well as the registration, dispatch and statistical evaluation procedure and your rights of objection. By subscribing to our newsletter you agree to the receipt and the described procedures.

2. Consent

As part of the registration for our newsletter and email communication, we obtain the consent of our supporters through a dedicated checkbox added in our various channels. The registrations for the newsletter and email communication are recorded for the fulfilment of legal obligations of proof. This includes the storage of the time of registration and confirmation.

3. E-mail tool

The newsletter and e-mail communication is sent out by using the email tool Marketing Cloud - hereinafter referred to as "dispatch service provider". The data protection regulations of the email tool provider can be viewed here: https://www.salesforce.com/eu/company/privacy/

Some donor emails are sent with Blackbaud’s Raizer’s Edge. The email service provider’s data privacy statements can be found here: https://www.blackbaud.com/company/privacy-policy/north-america.

According to its own information, the email tool provider can use this data in pseudonymous form - i.e. without allocation to a user, to optimize or improve its own services, e.g. to technically optimize the dispatch and presentation of the newsletter and email communication or for statistical purposes in order to determine from which countries the recipients come. However, the email tool provider does not use the data of our newsletter recipients to contact themselves or to pass the data on to third parties.

4. Registration data

To register for the newsletter and email communication, you must enter your email address, title, first name and surname as well as to check the consent checkbox.

5. Statistical survey and analyses

The newsletters and email communication contain a so-called "web-beacon", i.e. a pixel-sized file which is retrieved from the server of the email tool provider when the newsletter or email communication is opened. Within the scope of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and time of retrieval are initially collected. This information is used to technically improve the services based on the technical data or the target groups and their reading behavior based on their retrieval locations (which can be determined using the IP address) or access times.

The statistical surveys also include determining whether the newsletters and email communications are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to the individual newsletter recipients. However, it is not our intention, nor that of the email tool provider, to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our contents to them or to send different contents according to the interests of our users.

6. Legal bases

The use of the email tool provider, the performance of statistical surveys and analyses as well as the logging of the registration process shall be based on our legitimate interests in accordance with Article 6 (1) (f) GDPR. We are interested in using a user-friendly and secure newsletter system that serves our business interests and meets the expectations of our users.

7. Termination/Revocation

You can cancel the receipt of our newsletter and email communication at any time, i.e. revoke your consent. You will find a link to opt out at the end of each newsletter and email communication. If the users have cancelled the newsletter or email communication reception, the personal data of the users processed for its dispatch will be deleted.

3.3 In Country Office

1. Scope and purpose of data processing, legal basis

We exclusively process the necessary data for the support of volunteers according to Article 6 paragraph 1 lit. a GDPR (consent). 

The sending of our e-mail communication is also based on Article 6 paragraph (1) lit. a GDPR (consent).

2.  Data

In particular, personal master data and contact data (e.g. e-mail address and telephone number) are processed.

3. Possibility of objection and removal

You can object to the sending of our e-mail communication at any time with effect for the future.

You can revoke your consent to data processing at any time with effect for the future.

3.4. Donations and Sponsorship

1. Scope and purpose of data processing, legal basis

We provide forms in our online presence that the user can use to make a donation or sponsorship electronically. We process the data collected in this context for the purpose of processing the payment and for the support of donors and sponsors in accordance with Article 6 paragraph 1 lit b GDPR (performance of a contract).

The use of your address data for interest-based postal, promotional purposes is carried out in accordance with Article 6 paragraph 1 lit. f GDPR (balancing of interests).

Furthermore, the processing of data is necessary due to tax regulations as well as money laundering regulations according to article 6 paragraph 1 lit. c GDPR (legal obligation).

2. Data

The data collected in each case are recognizable in the form used; these are in particular data on the donation (e.g. amount, donation interval and payment method) as well as personal master data and contact data (e.g. email address and telephone number).

3. Recipient

Credit card

If you choose the payment method "credit card", we transmit personal data, which is necessary for the processing of the payment, to the payment service provider BlueSnap and Stripe. 

Your credit card data is transmitted exclusively via 256-bit SSL encryption to BlueSnap and Stripe where the correctness of the card data is compared with the respective credit card institute and creditworthiness and validity are checked. We do not store your credit card data.

Information on data protection at https://home.bluesnap.com/privacy-policy and https://stripe.com/en-nl/privacy

Paypal

If you select the payment method "PayPal", we transmit personal data required for the processing of the payment to PayPal (Paypal Headquarters 2211 N. 1st St. San Jose, CA 95131).

Information on data protection at PayPal can be found at https://www.paypal.com/us/webapps/mpp/ua/privacy-full   

Venmo

If you use Venmo as a payment method, we do not receive any personal data. Information on data protection at Venmo can be found at https://venmo.com/legal/us-privacy-policy/

The Giving Block

If you use The Giving Block to donate cryptocurrency, we do not receive any personal information from that transaction. Information on data protection at The Giving Block can be found at https://thegivingblock.com/about/privacy-policy

4. Possibility of objection and removal

You can object to us using your data for advertising purposes at any time with effect for the future.

You can revoke your consent to data processing at any time with effect for the future.

3.5. Petition

1. Scope and purpose of data processing, legal basis

We process only the necessary data for the implementation of petitions in accordance with Article 6 paragraph 1 lit. a GDPR (consent).

The sending of a newsletter by email is based exclusively on your separate consent pursuant to Article 6 paragraph 1 lit. a GDPR.

2. Data

In particular, personal master data, contact data (e.g. email address and telephone number) and petition data are processed.

3. Recipients

The data will be transmitted exclusively to the addressee(s) of the petition (i.e. to the relevant competent body - e.g. public authority or parliament).

4. Possibility of objection and removal

You can object to the sending of our e-mail newsletter at any time with effect for the future.

You can revoke your consent to data processing at any time with effect for the future.

3.7. Online events, such as online screening of docufilms

On our website, online events will be available on specific dates. To participate in them, you must register for the event, informing personal data such as your name and e-mail. The day before the event you will receive an e-mail from us with the link and details of the online screening. And after the event you will receive a thank-you e-mail.

The legal basis for this processing is your consent in accordance with art. 6 (1) (a) GDPR.

In the event registration process, you will also be able to voluntarily opt-in to receive future communications from us about other events and marketing. The legal basis for this is your additional consent in accordance with art. 6 (1) (a) GDPR, which is not a requirement for you to participate in the event.

Your data will be stored from your registration and for the duration of the event, unless you withdraw your consent or other legal bases or retention periods allow or require storage for a longer time.

You can withdraw your consent at any time. The withdrawal of your consent does not affect the lawfulness of processing based on consent before its withdrawal.

For the reproduction of the online events we may use service providers, such as Slido. These providers may have access to your personal data, such as your IP address. For more information about the service provider, please see: (Legal | Slido - Audience Interaction Made Easy).

When using these tools on our website, your data may be transferred to third countries, such as the United States. Based on the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework (DPF), it was found that the United States ensures an adequate level of protection – comparable to that of the European Union – for transferred personal data transferred to US companies under the new framework.

If personal data is transferred to third countries for which there is no adequacy decision of the European Commission, this is done on the basis of the standard contractual clauses.

4. Cookie Policy 

4.1. General Information

1. Cookies are information transmitted by our web server or third-party web servers to the users' web browsers where they are stored for later retrieval. Cookies can be in the form of small files or any other types of information storage.

2.. In the case that users do not want that cookies are stored on their computer, they will be asked to disable the corresponding option in their browser's system settings. Saved cookies may be deleted in the system settings of the browser. The exclusion of cookies can lead to functional impairments of this online service.

4.2. Consent Management by Usercentrics

1. We use the Usercentrics Consent Management Platform as a consent management tool as part of the Analytics activities on our website. The Usercentrics Consent Management Platform collects log file and consent data using JavaScript. This JavaScript enables us to inform users about their consent to certain tags on our website and to obtain, manage and document this consent.

2. We process the following data in the process:

  • Consent data or data of consent (anonymized log data (Consent ID, Processor ID, Controller ID), Consent Status, Timestamp).
  • Device data (e.g. shortened IP addresses (IP v4, IP v6), device information, timestamp)
  • User data (e.g. e-mail, ID, browser information, SettingIDs, Changelog)

The ConsentID (contains the above data), the Consent status incl. timestamp are stored in the local memory of your browser and simultaneously on the cloud servers used. Further processing will only take place if you submit a request for information or revoke your consent. In this case, the relevant information is provided to us in a compact data format in an easily readable text form for the purpose of data exchange (JSON file).

3. No user information is stored for the statistics of the use of the granted or not granted consent. Only the frequency and locations of clicks are stored.

4. The personal data is stored on a Google Cloud server located in the EU (Brussels, Belgium or Frankfurt am Main, Germany).

5. The purpose of the data processing is the analysis and management of the consents granted, in order to comply with our obligation of a GDPR-compliant consent management. The use of Usercentrics serves the purpose of proving granted and non-granted consents as well as their management.

6. The legal basis for the management of your consents for the processing of your personal data is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the legally secure documentation and verifiability of consents, the control of marketing measures on the basis of the consent granted as well as the optimization of consent rates.

7. The data is deleted as soon as it is no longer required. The associated cookie has a term of 60 days. The revocation document of a previously granted consent is kept for a period of three years. The retention is based on the one hand on our accountability pursuant to Art. 5 para. (2) GDPR.

4.3 Objection Options

After a given consent, you may object to the use of cookies that are used for measuring the range of coverage and promotional purposes here.

5. Changes to the Data Privacy Policy 

5.1. Version: December 2021

We reserve the right to change this Data Privacy Policy with regards to the data processing, in order to adapt it to changed legal situations, to changes of the online service or of the data processing. 

If users' consents are required or if elements of the Data Privacy Policy contain provisions in regards to the contractual relationship with the users, the changes will only be made with the consent of the users. 

Users are requested to keep themselves informed about the content of this Data Privacy Policy on a regular basis.

Share now!

Search