The protection of your data at certified-senders.org and summit.certified-senders.org
The Certified Senders Alliance is a service from eco – Association of the Internet Industry, Lichtstrasse 43h, 50825 Cologne (hereinafter referred to as “eco”). We, as eco, take the protection of your personal data very seriously, and we strictly comply with the regulations of the data protection statutes. The following declaration provides you with an overview as to how we ensure this protection. In particular, we would like to explain to you – as a visitor to our website, a subscriber to our newsletter, as a guest at one of our numerous events, or as an applicant– which types of data we gather, why we collect these types of data, how we use this data, and how you at any and all times can determine how your personal data is treated.
According to the General Data Protection Regulation (GDPR) you have various rights which you can assert in relation to us. This includes, among others, the right to withdraw consent to the processing of data, in particular data processing for the purposes of marketing. The possibility to withdraw consent is typographically highlighted.
II. Name and contact details of the person responsible for processing and the data protection officer
Our data protection officer, Mr. Jan Stumpf, can be contacted via the email address firstname.lastname@example.org, by post to: eco – Association of the Internet Industry, Mr. Jan Stumpf, Lichtstrasse 43h, 50825 Cologne, with the keyword “Data Protection,” or by fax at the number +49 (221) 70 00 48-111.
III. Purpose of data processing, legal basis, and legitimate interests that are pursued by eco or a third party, and categories of recipients
1. Surfing on this website
eco gathers and automatically stores log file information in its server, which your browser deposited with us while you were surfing.
In brief, here is the key data that we store:
- Type of browser/browser version
- The operating system used
- Referrer URL (the page visited previously)
- URLs / pages on this website that have been accessed
- IP address of the accessing computer along with its name
- Time of the server request
- Visitor history
Furthermore, we record the complete Uniform Resource Locator (URL) Clickstream through and from our website, i.e. the sequence of the pages of our website that you visit, including date and time, cookie or flash cookie number, and the content that you viewed or for which you searched.
The legal basis for the processing of the IP address is Article 6, Para 1f) of the GDPR. Our legitimate interest results from the following list of purposes of the data processing. Please note on this point that it is not possible for us to draw any direct conclusions about your identity on the basis of the data collected, nor do we attempt to draw such conclusions.
The IP address of your device and the remaining data listed above is used by us for the following purposes:
- Ensuring a seamless establishment of the connection
- Ensuring the comfortable use of our website
- Assessing the system security and stability
The data is saved for a period of 7 days, after which it is automatically deleted or anonymized. Further, we make use of so-called cookies, tracking tools and social media plug-ins for our website. Exactly what process is undertaken and how your data is used for these is clarified in Section III.12. below.
2. Contact Form and Email Contact
On our website, you have the option of getting in contact with us via a contact form or via email. The information you impart via the contact form is usually:
– First name
The personal data imparted to us will be used exclusively for the purpose of processing your enquiry and will be deleted after processing your query. The legal basis for this is your consent within the meaning of Art. 6 No. 1) a GDPR, as well as Art. 6 No. 1) f GDPR. The proper processing of your enquiry is to be regarded as a legitimate interest within the meaning of the GDPR. You can withdraw your consent to the processing of the personal data imparted to us at any time with effect for the future, using the contact information provided under II. From the moment of withdrawal, it will no longer be possible to process your enquiry.
3. Registration for events
Registration forms for CSA’s numerous events are provided in advance on our website. In the scope of your registration, personal data will generally be collected. This includes:
– Family name
– First name
– Job title
– When necessary, billing and delivery address
– When necessary, billing and payment details
– Email address
– When necessary, phone number.
These details are collected for the purposes of identifying and registering you on the day of the event.
The legal basis for this is Article 6, Para 1b) of the GDPR, i.e. you make the data available to us on the basis of the contractual relationship between yourself and us. In addition, regarding the processing of your email address, the German Civil Code requires us by law to send an electronic order confirmation (Article 6, Para. 1c)). Insofar as we do not use your contact details for marketing purposes (see section III.4.1 below), we store your data collected for the fulfillment of the contract until the expiration of the legal or possible contractual warrantee and guarantee rights. After expiry, we retain the information regarding the contractual relationship that is required by commercial law and tax law for the legally determined period. For this period of time (generally 10 years from the conclusion of the contract), the data will only be re-processed in the case of an audit by the taxation authorities.
We ordinarily creates participant lists for events. The purpose of these is to inform the participants, and these lists are attached to the event documents. The lists usually include the surname, first name, and employer of each of the event’s attendees.
You can withdraw consent to the publication of your personal data in the list of participants at any time, by email to email@example.com, by post to: eco – Association of the Internet Industry, Lichtstrasse 43h, 50825 Cologne, or by fax to: +49(0)221 – 7000 48-111.
Our events are also documented on the Internet. This includes the publication of photos or video recordings of the event. Further information can be found in our Privacy Notice Event Participation.
4. Data processing for marketing purposes
The following information concerns the processing of personal data for marketing purposes. The GDPR declares such data processing on the basis of Article 6 Para. 1f) as conceivable in principle and to be a legitimate interest. The duration of data storage for marketing purposes does not follow any strict precepts and is oriented around the question of whether the storage is necessary for marketing purposes. How this proceeds in the case of the withdrawal of your consent is clarified in section III.4.2.
4.1. Marketing purposes of eco
Insofar as you have concluded a contract with us regarding participation in an event, we will process your postal contact address apart from of a concrete declaration of consent, in order to occasionally in this way provide you with news on the association or forthcoming events. We process your email address in order to provide you with information regarding our own similar products apart from of a concrete declaration of consent.
4.2 Right to withdraw consent
You can withdraw your consent to the data processing for the purposes set out above at any time, without incurring costs, for each channel independently, and with effect for the future. For this, an email or letter to the contact details listed in Section II suffices. There are no costs other than the transmission costs according to the basic tariffs.
Insofar as you withdraw consent, the affected contact addresses will be blocked for further marketing-related data processing. Please note that in exceptional cases, it is possible that further sending of marketing material may take place temporarily, even after receiving your withdrawal of consent. This is technically due to the necessary lead-in time for advertisements and does not mean that we will not comply with your objection. Thank you for your understanding.
5. Sending of newsletters
You can subscribe to our newsletter on CSAs website. Within the scope of making a subscription, we will collect personal-related data from you such as name and email address. We shall solely use these types of data for personalization and implementation of our email mailings. In order to prevent the misuse of email addresses, subscribers must confirm the ordering of our newsletter in an automated process via email (double opt-in). Only after you have clicked on the confirmation link will your email address be added to our mailing list. Your thus declared consent can be withdrawn at any time with effect for the future. This can be done conveniently with the aid of the link that is located in the lower section of each of our mailings, via email to firstname.lastname@example.org , or by means of a message to our office – by mail to: eco – Association of the Internet Industry, Lichtstrasse 43h, 50825 Cologne, or by fax to: +49-221-7000-48-11.
The legal basis for sending our newsletter is Art. 6 Para. 1 lit. a GDPR as well as § 7 Para. 2 No. 3 or Para. 3 UWG (the German Federal Law on Unfair Competition). The legal basis for the use of Mappthe performance of statistical surveys and analyses, and the recording of the registration procedure is our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR. Our interest is in the deployment of a user-friendly and secure newsletter system that serves both our business interests and the expectations of users.
6. Participation in Webinars
On our website, you have the possibility to register for our webinars. For the organization of webinars we use the software GoToWebinar from LogMeIn Ireland Limited. In the course of registration, personal data is collected on the infrastructure of the firm LogMeIn (10 Hanover Quay, Dublin 2, D02R573 Ireland). In particular, this data includes the registrant’s surname, first name, company, function, and email address. The legal basis for this data processing is Art. 6 Para 1 f) of the GDPR.
For you, participation in our webinars is free of charge. In order to be able to maintain our free offer, we use the data collected during registration not only to conduct the webinar, but also to occasionally offer you information that may be of interest to you about other webinars, events, or lectures of CSA or eco. You have the possibility to object to this use at any time. You can find the relevant contact details in II. Beyond that, no further use of your data takes place without your explicit consent. Likewise, no transfer to other third parties takes place.
If you have been certified as a sender with the CSA, we will collect and process various data from you, including personal data, that you provide to us via the CSA online form or other forms required for the certification process. We use this data in the context of the contract initiation, e.g. to assess whether you are eligible for CSA certification. When a contract is concluded we use this data, for example, to fulfill the contract concluded between you and us, for accounting purposes, or in order to be able to contact you. The legal basis for this is Article 6 Para 1 b) of the GDPR.
Within our company group, those personnel who need the data to fulfil the contractual or legal obligations are given access to the data. In addition, service providers commissioned by us may also receive data from us for these purposes, e.g. credit reporting agencies, sales partners, credit institutions, IT service providers.
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of a conclusion of a contract, this is usually the case upon termination of the contractual relationship, provided that there are no legal obligations to retain data. In this case, a longer retention period is required. This period can be up to 10 years. If data is to be retained to ensure the enforcement of legal claims, the limitation period can be up to 30 years, whereby the regular limitation period is three years.
8.Use of the CSA Customer Portal
On our CSA website, customers have the opportunity to register to our CSA Customer Portal area. Each customer receives from us as the registration data (username, password). A transfer of data to third parties does not take place. Registration is required for the use and provision of CSA services through the CSA Customer Portal.
The legal basis for this is Article 6, Para 1b) of the GDPR, i.e. you make the data available to us on the basis of the contractual relationship between customers and CSA.
The data will be deleted as soon as it is no longer necessary for the purpose of its collection. This is the case when the data for the implementation of the contract are no longer required. Even after the conclusion of the contract, there may be a need to store personal data of the contracting party in order to comply with contractual or legal obligations. After expiry, we retain the information regarding the contractual relationship that is required by commercial law and tax law for the legally determined period. For this period of time (generally 10 years from the conclusion of the contract), the data will only be re-processed in the case of an audit by the taxation authorities.
9. Applications to eco
With the transferal of your (online) application, you give us permission to store and use your application documents for the application process. The legal basis for this is Article 6, Para 1a) of the GDPR. Your data will be handled as strictly confidential. Personal data will exclusively be made accessible to staff involved in the application process. Your data will be deleted 3 months after notification of a rejection if it does not lead to the beginning of a work or training relationship and deletion does not conflict with any other legitimate interests (e.g. obligation to provide evidence in a process according to the General Equal Opportunities Act (AGG)).
Your agreement to the saving and processing of your application data can be withdrawn at any time with effect for the future by sending an email to email@example.com, via post to: eco – Association of the Internet Industry, Lichtstrasse 43h, 50825 Cologne, or by fax to: +49 (221) 7000 48-11 with a request to have the data deleted.
We will then delete all data transmitted to us in the context of the application process, insofar as we are not entitled to or required to retain them in accordance with legal regulations.
10. Online Presence on Social Media
In addition to this website, we also maintain an online presence on the social media channels Facebook, Twitter, Xing, Linked-in, Youtube, Flickr, and a Slack Channel. You can access these by clicking on the corresponding menu items on our website.
We would like to point out that your use of these pages and their functions lies within your own responsibility. This applies in particular to the use of interactive functions (e.g. commenting, sharing, rating).
When visiting such a page, personal data may be transferred to the provider of the social media channel. The social media provider collects and processes your IP address, the type of processor and browser version used, including plug-ins and, where applicable, other information.
The data collected about you in this context will be processed by the provider of the social media channel and in some instances may be transferred to countries outside of the European Union.
If you are logged in with your personal user account of the respective channel during your visit to such a website, this channel can assign the visit to your account.
If you wish to avoid this, you should log out of the social media channel before visiting our online presence or deactivate the “remain logged in” function, delete the cookies present on your device, and exit and restart your browser. In this way, information which could be used to directly identify you is deleted.
As the operator of the respective online presence, we do not collect or process any further data from your use of the corresponding social media channel.
11. Online presence and website optimization
Insofar as these cookies are those that are necessary to ensure the proper functioning of our website, the use of these takes place on the basis of Article 6 Para 1a) of the GDPR. Our interest in optimizing is thereby to be seen as legitimate in the sense of the aforementioned regulation. In all other cases, we ask you for your consent, which allows us to set further cookies (analysis cookies, marketing cookies). No cookies are set (except required/essential cookies) without giving consent. Further information can be found in our “Individual Cookie Settings”.
You can change or withdraw your consent at any time in the “Individual Cookie Settings” or via the button “Change Cookie Settings” on our website.
These cookies are automatically deleted after a respectively defined period of time. You can, however, configure your browser so that no cookies are stored on your computer, or so that a warning always appears before a new cookie is created. However, the complete deactivation of cookies can result in your not being able to use all functions on our website. The storage duration of the cookies is dependent on their purpose and is not the same for all.
11.2. Google Analytics
For the purposes of needs-oriented design and continual optimization of our webpages, we use Google analytics, a web analytics service from Google Inc (“Google”) on the basis of Article 6, Para 1a) of the GDPR. In conjunction with this, anonymized usage profiles are generated and cookies are used. The information generated through the cookie about your use of this website, such as
- Browser type/version,
- Operating system in use,
- Referrer URL (the previously visited website),
- Host name of the computer accessing the site (IP address),
- Time of the service request,
is transferred to and stored on a Google server in the USA. The information is used in order to analyze the use of the website, create reports on website activities, and to deliver further services in connection with the use of the Internet for the purposes of market research and the needs-oriented design of these webpages. This information is also, if necessary, forwarded to third parties, insofar as this is required by law or data processing is outsourced to said third party. Under no circumstances will your IP address be merged with any other data from Google. The IP addresses are anonymized, so that correlation is not possible (so-called IP masking). You can prevent cookies from being saved by using the corresponding settings in your browser software; however, we wish to inform you that, in that case, this may result in you not being able to make complete use of all functions on this website. You can also prevent the collection of data by Google related to your use of the website (including your IP address) generated through this cookie, and the processing of this data by Google, by downloading and installing the Browser-Plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en
You can also prevent data collection by Google Analytics by clicking on the following link. This will set an Opt-Out cookie, which will prevent the future collection of your data when visiting this website:
Further information regarding data protection in connection with Google Analytics can be found on the Google Analytics website. You can also change or withdraw your individual cookie settings as described in 12.1. In this case, no more data is processed via Google Analytics, too.
11.3. Matomo (formerly Piwik)
If you are not in agreement with the storage and analysis of data from your visit, you can dissent to the storage and analysis at any time by clicking on the link below. In this case, an Opt-Out cookie will be set in your browser, after which Matomo will collect no data from your sessions on this website. Please note: If you delete your cookies, this will also result in your Opt-Out cookie being deleted, so that you will need to reactivate it.
Click here to deactivate the tracking by Matomo.
11.4. Social Media Plugins
On the basis of Article 6, Para 1a) of the GDPR, we place plugins for the social networks Facebook, Twitter, Xing and LinkedIn on our website in order to increase awareness of our association. The responsibility for the data protection compliant operation is to be guaranteed by each provider respectively. Our integration of these plugins takes place through the so-called Shariff method, in order to protect visitors to our website in the best way possible. In order to best protect visitors to our website, our integration of these plug-ins is achieved using the “Shariff” method. At the point of loading a website on which they are integrated, the buttons offered directly by social network operators are already transmitting personal data such as your IP address or entire cookies without permission, and thus pass on precise details of your surfing behavior to the social providers without any request. For this to happen, you do not need to be logged in or be a member of the respective network. A Shariff button, on the other hand, only establishes direct contact between the social network and the visitor when the latter actively clicks on the Share button. Shariff thereby prevents you from leaving a digital track on every page you visit and improves data protection. By using Shariff, we can protect your personal data and still integrate buttons for social sharing.
On our website, we use plugins for the social network Facebook that are offered by Facebook Inc. The Facebook plugins are denoted through a Facebook logo or with the addition “Like” or “Share”. An overview of the Facebook plugins and their appearance can be found at https://developers.facebook.com/docs/plugins/?locale=en_EN
When you activate such a plugin (first click), your browser establishes a direct connection to the Facebook servers. The content of the plugin is directly transmitted to your browser and is integrated in the page. Through this integration, Facebook obtains the information that your browser has accessed the specific page of our web presence, even if you do not possess a Facebook profile or are not currently logged in at Facebook. This information (including the IP address) is transferred directly from your browser to a Facebook server in the USA, and is stored there. If you are logged in at Facebook, Facebook can directly relate the visit to our website with your Facebook profile. If you interact with the plugins, for example, by pressing the “Like” button, this information is also directly transmitted to and stored in a Facebook server. The information will also be published on your Facebook profile and shown to your Facebook friends.
The purpose and the extent of data collection and the further processing and use of the data by Facebook, as well as your rights and possible settings for the protection of your privacy can be found in Facebook’s data protection information at https://facebook.com/policy.php If you do not wish Facebook to relate information gathered through your visit to our website directly with your Facebook profile, you need to log out of Facebook before visiting our website. You can also completely prevent the loading of the Facebook plugins using add-ons for your browser, e.g. with the “Facebook Blocker” or with the Facebook Container Add-On (for Firefox).
Our website has integrated plugins for the micro-blogging network Twitter Inc. The Twitter plugins (“Tweet” button) are denoted by the Twitter logo (a white bird on a blue background) and the addition “Tweet”. When you activate such a plugin by clicking on it, a direct connection is established between your browser and the Twitter server. Through this, Twitter obtains the information that you, with your IP address, have visited our website. If you click the Twitter button while you are logged in to your Twitter account, you can link the content on our site with your Twitter profile. Through this, Twitter can relate the visit to our webpages with your user account. Please note that we as provider of the website obtain no information from Twitter about the content of the data transmitted or its use. Further information on this can be found here: https://twitter.com/privacy?lang=en. If you do not wish Twitter to attribute to you the visit to our website, please log out of your Twitter account.
Our website has integrated plugins for the social media network, LinkedIn. LinkedIn is an Internet-based social network that enables a connection between the user and existing business contacts, as well as the creation of new business contacts. When you activate such a plugin by clicking on it, a direct connection is established between your browser and the LinkedIn server. Through this, LinkedIn obtains the information that you, with your IP address, have visited our website. If you click the LinkedIn button while you are logged in to your LinkedIn account, you can link the content on our site with your LinkedIn profile. Through this, LinkedIn can relate the visit to our webpages with your user account. Please note that we as provider of the website obtain no information from LinkedIn about the content of the data transmitted or its use. If you do not wish LinkedIn to attribute to you the visit to our website, please log out of your LinkedIn account.
Our website has integrated plugins for the social media network, Xing. Xing is an Internet-based social network that enables a connection between the user and existing business contacts, as well as the creation of new business contacts. When you activate such a plugin by clicking on it, a direct connection is established between your browser and the Xing server. Through this, Xing obtains the information that you, with your IP address, have visited our website. Further information about Xing plugins can be found at https://dev.xing.com/plugins. If you click the Xing button while you are logged in to your Xing account, you can link the content on our site with your Xing profile. Through this, Xing can relate the visit to our webpages with your user account. Please note that we as provider of the website obtain no information from Xing about the content of the data transmitted or its use. If you do not wish Xing to attribute to you the visit to our website, please log out of your Xing account.
11.5. Use of Google reCaptcha
11.6. Adobe Typekit
For the unified presentation of texts types (fonts), the sites www.eco.de, www.international.eco.de, www.siwecos.de, www.botfrei.de and www.botfrei.eu use the Adobe Typekit service. Adobe Typekit is a service that enables access to a font library and is made available by the company Adobe Systems Inc., 345 Park Avenue, San Jose, CA 95110-2704, USA (“Adobe”). When accessing a site, your browser loads the required fonts into your browser cache, in order to display texts and fonts correctly.
In the course of providing the Typekit service, no cookies are placed or used to supply the fonts. To provide the Typekit service, Adobe can collect information about the font, which service to identify the website itself and the associated Typekit account. Adobe Typekit is used in the interest of enabling a unified and appropriate presentation of our online offer. This represents a legitimate interest as defined in Art. 6, Para 1 f) GDPR. If your browser does not support web fonts, a standard font from your computer is used.
Adobe Systems Inc., located in the USA, is certified according to the „EU-US Privacy Shield“, which ensures compliance with the prevailing EU data protection level.
More information about the Typekit can be found at https://helpx.adobe.com/typekit/using/what-is-typekit.html and generally about Adobe at https://www.adobe.com/en/privacy.html.
11.7. Google Maps
We use the map service Google Maps via an interface to visually display geographical information. The provider of this service is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).
Data about the use of the map function by visitors is collected, processed and used by Google when Google Maps is used. This information is as a rule transferred to a Google server in the USA and stored there.
Google Maps is used in the interest of enabling a unified and appropriate presentation of our online offer and easy findability of our locations listed on the website. The legal foundation for this is Art. 6 Para 1 f) GDPR.
12. Joint controllers pursuant to Article 26 Para. 2 (2) of the GDPR
In order to spare resources and use them more effectively, eco e.V. and the deutsche medienakademie GmbH (German Media Academy), as a 100 percent subsidiary of eco e.V., use a joint database to manage their address databases.
As part of their joint data protection responsibility, eco and dma have agreed which of them fulfils which obligations under the GDPR. To this end, eco and dma have each assigned the individual data files to a company responsible for processing the personal data. This applies in particular to the observation of the rights of the data subjects and the fulfilment of the information obligations pursuant to Articles 13 and 14 of the GDPR.
You can assert your data protection rights centrally at: firstname.lastname@example.org, or alternatively at: email@example.com.
IV. Your rights
Alongside the right to withdraw the consent given to us, you also have the following rights, when the respective legal conditions are extant:
- Right of information regarding your personal data stored by us in accordance with Article 15 of the GDPR; in particular, you can obtain information about the purpose of processing, the category of personal data, the category of recipient for whom your data is or has been made available, the planned period of retention, the origin of your data, insofar as it was not collected directly from you,
- Right of rectification of erroneous or to completion of correct data in accordance with Article 16 of the GDPR,
- Right to deletion of your data stored by us in accordance with Article 17 of the GDPR, insofar as there are no legal or contractual requirements to retain the data, or other legal obligations or rights to the continued retention of the data,
- Right to limit the processing of your data in accordance with Article 18 of the GDPR, insofar as you dispute the correctness of the data, the processing is illegal, but you oppose the deletion of said data; the data controller no longer requires the data, but you require said data for the assertion, exercise or defense of legal claims, or you have filed an objection to the processing in accordance with Article 21 of the GDPR,
- Right to data portability in accordance with Article 20 of the GDPR, i.e. the right to receive selected data about you stored by us in a standard, machine-readable format, or to have this transmitted to another data controller,
- Right to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your normal place of residence or work, or of our association headquarters to do this.
2. Right to object
Under the conditions of Article 21, Para 1 of the GDPR, the data processing can be objected to on grounds arising out of the special situation of the person affected.
V. Forwarding to third parties
The data collected by us are not sold. We provide information that we obtain to third parties exclusively to the extent described in the following:
1. Affiliated companies
2. Service providers
3. Protection of eco and third parties
We disclose personal data when we are legally obliged to do so, or when such disclosure is necessary to protect our rights and those of third parties.
4. Recipients outside of the EU
With the exception of the processing described below. we do not forward your data to recipients with headquarters outside of the European Union or the European Economic Area.
VI. Further information and notes
V02 Cologne, August 2020