12 Priorities for Action   

COOKIE POLICY OF THE CANDID FOUNDATION gGMBH

We, the team of the Candid Foundation gGmbH, are very pleased about your interest in our services and your visit to our website. We know that the security of your personal data and the protection of your privacy is important to you and ensure this through a variety of measures. This cookie guideline explains to you which personal data we collect, store and process through interaction with you and serves to implement the information obligation resulting from Art. 12 DSGVO, to inform you transparently about the type, scope and purpose of data collection and to inform you about your existing rights.
 

1. PERSON RESPONSIBLE FOR DATA PROCESSING AND CONTACT DATA

We, the Candid Foundation gGmbH, Chausseestraße 11 in 10115 Berlin, are responsible for the data processing described below in accordance with Art. 4 No. 7 DSGVO. Our contact details are as follows:
* Address: Chausseestraße 11, 10115 Berlin, Germany
* email: berlin@candid-foundation.org
* Phone: +4930 398351880
* Website: candid-foundation.org
 

2. WHAT ARE COOKIES AND WHAT TYPES OF COOKIES ARE THERE?

We use so-called cookies in connection with our online services. Cookies are small data packages that are sent from the server of the website to your browser and stored on your end device (computer or smartphone). A cookie does not contain a program, but a so-called cookie ID, which enables it to be allocated to the browser.

Cookies that are placed on the website by the content provider are called "first party cookies" or "first provider cookies". Cookies that are placed by third parties on the content provider's Web site are called "third-party cookies”.

Cookies can be used as so-called "session cookies". In this case the cookies are not stored permanently, but only for the duration of the call of the website and are deleted after the end of the session. Cookies can also be used as so-called "persistent cookies". In this case, the cookie - provided it is not deleted via the user's browser - remains on the user's terminal even if it closes the website accessed; the persistent cookie is then reactivated when the website is visited again.

Cookies can also be used for various data processing purposes. So-called technical cookies are cookies that are required for the basic performance of the website, enable the requested options or services or improve the performance of the website (e.g. user authentication, session creation).

Cookies that are not necessary for technical reasons are not required for the provision of the service, but are used to analyse user behaviour, improve the provision of advertising and marketing measures and web tracking for website visitors. Technologies that also fulfil the aforementioned purposes are so-called "web beacons" (action tags and pixel gifs), which we also refer to as cookies. Web tracking refers to the possibility of recording user behaviour on the Internet using cookie technology. Web tracking is used in particular to display targeted advertisements to the online user. Depending on the cookie used, the options for recording and evaluating user behaviour using tracking technology can include online use across several websites and retargeting.

In addition, technically unnecessary cookies are those that are provided by social media platforms (Twitter, LinkedIn, Facebook, etc.) in order to display the content of the social media platforms, own content or third-party content online as advertising and to fulfill the tracking and targeting measures described above. Further information on cookie technology can be found on the website of the Fraunhofer Institute for Secure Information Technology.
 

3. TYPE AND PURPOSE OF OUR COOKIE USAGE

(1) We use technically necessary cookies in order to be able to present our services to you online and to guarantee the technical accessibility/controllability of our online presence. For this purpose, data is stored by the cookie and transmitted to us. These are:

Data for user authentication; data for session creation, reminder of preferred language settings and log files.

(2) In addition, we use analysis cookies, which we use for usage analysis and control of our advertising measures as well as for the continuous optimisation of our website. For the above purposes, we use Google Analytics, an advertising and web analysis service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google" - https://www.google.de/intl/de/about/). For this purpose, the cookie stores and transmits data about the use of this website and the surfing behaviour. These are:

Browser type/version, time of server request, referrer URL (previously visited page), search queries, website scrolling, exchanged data volume, duration of use, number of visitors, regional origin of visitors, visitor sources, number of pages accessed per visit, log files.

The data collected is used to create anonymous user profiles (see below), which are then transmitted to a Google server in the USA and stored there.

We use the "IP anonymization" version (IP masking) of Google. Here your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area and transmitted to a Google server only in the shortened version. Only in exceptional cases will the IP address be transmitted to Google in the USA and anonymised there. Due to the anonymization carried out, it is no longer possible to assign the data stored under your IP address unambiguously at a later date. A user-related traceability of the stored data is excluded.

On our behalf (Art. 28 DSGVO) Google uses this information to evaluate the use of our website and your surfing behaviour by anonymous and pseudonymous profiles and to compile reports on website activities. The anonymous IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google. Google Inc. is a company certified according to the EU-US Privacy-Shield. Companies that are certified according to the EU-US Privacy Shield are certified by the EU Commission as having an appropriate level of data protection.

We use additional products from Google on the basis of the anonymous usage profiles collected by Google Analytics in order to be able to offer our online advertising measures in a more targeted manner. We use Google AdWords cookies for this purpose. We use Google AdWords to provide you and/or other users with targeted product recommendations and interest-based advertising when you visit a website based on your user behaviour. For this purpose, data is stored by the cookie and transmitted to us. These are:

Data on visits to Google display pages (= third pages on which ads are placed), Google search queries, regional origin of visitors, measurement of the success of banner advertising (e.g. how many clicks and visits or purchases were made via a particular ad), user interaction with the ad, log files.

We use the Mailchimp program (https://mailchimp.com/) of The Rocket Science Group LLC, based in the United States, to operate our newsletter. The program allows us to design our newsletter and measure your interaction (read/not read). The latter helps us assess whether the content we share is of interest to you. The Rocket Science Group LLC processes this data on our behalf in accordance with Art. 28 DSGVO. The Rocket Science Group LLC is a company certified according to the EU-US Privacy-Shield. Companies that are certified according to the EU-US Privacy Shield are certified by the EU Commission as having an adequate level of data protection.

For example, if you visit another website on the Google Advertising Network or perform a Google search, the above information will be provided to us so that we can display targeted advertisements. We can then place this interest-based advertising in a target-group-oriented manner (e.g. limited to users from a certain federal state).

For the same purposes we also use cookies from Hotjar Ltd. (Lyons Range- 20 Bisazza Street- Sliema SLM 1640, Malta). Hotjar's cookies also help us to analyse surfing behaviour and to display interest-based advertising. For this purpose, data is stored by the cookie and transmitted to us. These are:

Among other things, browser type/version, IP, time of server request, referrer URL (the previously visited page), location, search queries, website scrolling, exchanged data volume, duration of use, number of visitors, regional origin of visitors, visitor sources, number of pages accessed per visit, log files (IP), notifications as to whether an interaction with switched advertising or e-mails took place. Hotjar evaluates this data on our behalf (Art. 28 DSGVO) and makes it available to us. We use this data to track your usage behaviour on our website using so-called heat maps and thereby improve the usability of the website and the retrieval of information. We may associate this data with your personal customer data, for example by receiving a notification whether you have clicked on our email newsletter, for which purpose so-called "web beacons" are used. The latter enables us, for example, to draw conclusions as to whether selected topics are of interest to you. In addition, we use the data to control our campaigns and to be able to insert interest-based advertising.

To operate our newsletter, we use the Mailchimp program (https://mailchimp.com/) from The Rocket Science Group LLC, based in the United States. The program allows us to design our newsletter and measure your interaction (read/not read).

The latter helps us to assess whether the content we communicate is of interest to you. The Rocket Science Group LLC processes this data on our behalf in accordance with Art. 28 DSGVO. The Rocket Science Group LLC is a company certified according to the EU-US Privacy-Shield. Companies that are certified according to the EU-US Privacy Shield are certified by the EU Commission as having an adequate level of data protection.

(3) Our website also includes so-called plug-ins from social networks, which are also based on cookie technology and whose services are offered by the respective company. These include plug-ins from Facebook Inc. (Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland) and Twitter International Company (One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland). You can recognize the plug-ins by the respective button of the social media company, e.g. the "f" button on Facebook or the "bird" button on Twitter. With the help of the plug-ins embedded on our website, an automatic data exchange takes place via your browser between our website and the websites of the respective social networks over which we have no further influence. For example, when you visit our site, the IP address is transmitted to the social network, even if you are not a registered user. If you are registered as a user with a social network and access our website without logging out from the social network, the social network in question can assign your visit to our website to your member account to the best of our knowledge. If you as a logged-in user of the social network also interact with the plug-in, e.g. click on the Facebook "Share" button, this information may be published by the social network. The data is stored abroad to the best of our knowledge. We have no influence on the type and scope of the data transmitted and on their further processing. The data exchange takes place according to the respective guidelines of the social network. Details on the plug-ins used by Facebook and Twitter and the respective data protection regulations of the social networks can be found under the following links:

- https://developers.facebook.com/docs/plugins (Facebook) 
- https://www.facebook.com/about/privacy (Facebook)
- https://dev.twitter.com/docs/tfw (Twitter)
- https://twitter.com/privacy (Twitter)
 

4. LEGAL BASIS OF OUR USE OF COOKIES

By using our technical cookies, we ensure the functionality of our online media and thus our business presence. This also enables us to obtain and use our services. As far as we process the data for the presentation of offers and contract processing, our legal basis is Art. 6 Para. 1 lit. b) DSGVO. In all other cases, the legal basis for our data processing is Art. 6 Para. 1 lit. f) DSGVO (weighing of interests).

With the use of our Google Analysis Cookies we process data beyond the actual contractual purposes. The legal basis is our legitimate interest in the sense of the

Art. 6 para. 1 f DSGVO. Accordingly, processing is permitted if it is necessary to safeguard the legitimate interests of the data controller, i.e. us, or a third party, and if it does not outweigh the fundamental rights of the person affected by the processing, i.e. you.

We operate with the use of analysis cookies interest-based advertising. In principle, advertising, also in the form of direct advertising, is recognised as a legitimate interest within the meaning of Art. 6 (f) DSGVO [Recital 47 to the DSGVO]. We take sufficient account of your claim to respect for your privacy when using Google cookies by only transmitting your IP address anonymously and only creating pseudonymous profiles. The provider also guarantees us through technical and contractual measures that the data collected will be used in accordance with our instructions and will not be merged with our own data, so that a high level of protection can be guaranteed as a result. We also take into account that target group-oriented advertising is permissible in principle according to the will of the legislator, the Article 29 Data Protection Working Party (cf. Statement 2/2010 on advertising on the basis of Behavioural Targeting) and the current draft of the EU Commission on the future ePrivacy Regulation (Art. 8 para. 1 d ePrivacy Regulation) and that you as a consumer expect these measures. With the use of our newsletter cookie Mailchimp, we process data beyond the actual contractual purposes. The legal basis for this is your consent pursuant to Art. 6 Para. 1 lit. a) DSGVO, if granted. With the use of our Hotjar Cookies we process data beyond the actual contractual purposes. The legal basis for this is your consent pursuant to Art. 6 lit. a) DSGVO, if granted.
 

5. CONSENT TO THE USE OF OUR COOKIES/REJECTION TO THE USE OF OUR COOKIES

If you wish to prevent our use of Google Analytics, you can also prevent the processing by Google by calling up and installing the browser add-on or by preventing cookie storage via your browser settings. You can find out how to do this below:

Mozilla Firefox
Internet Explorer
Google Chrome
Safari
Bing

If you want to prevent our use of Hotjar cookies, you can prevent Hotjar from processing them by setting an opt-out cookie, which you can activate via this Link. In addition, you can prevent the storage - as described above - via your browser settings. In this context, please note that you must reactivate an opt-out cookie once it has been installed if and to the extent that you have deleted all cookies, including the opt-out cookie, via your browser settings.
 

6. DURATION OF STORAGE

The aforementioned cookies have the following deletion periods:
- Google [ga (2 years), gid (24 hours), gat (1 minute), AMP_Token (90 days)]
- Hotjar Ltd.
- The Rocket Science Group LLC
- Facebook .......
 

7.CHANGES TO THE COOKIE POLICY

We will adapt our cookie policy to technical, organisational and legal changes and change it if necessary. Therefore, please note the current version. Changes always take effect in the future and do not affect the data processing that took place before the changes were made.
 

8. YOUR RIGHTS

Your other rights, about which we inform you in the context of our data protection information , apply accordingly to the data processed by means of cookie use.
 

9. DATA TRANSFER IN CONNECTION WITH THE USE OF PLUG-INS

So-called plug-ins from social networks are integrated on our website, whose services are offered by the corresponding company (Facebook, Google+, Twitter). You can recognize the plug-ins by the respective button of the social media company, e.g. by the "Like or Share" button on Facebook. With the help of the plug-ins embedded on our website, your browser automatically exchanges data between our website and the websites of the respective social networks. For example, when you visit our site, the IP address is transmitted to the social network, even if you are not a registered user.
If you are registered as a user with a social network and access our website without logging out of the social network, the social network can assign your visit to our website to your member account to the best of our knowledge. If you as a logged-in user of the social network also interact with the plug-in, e.g. click on the Facebook "Share" button, this information may be published by the social network. The data is stored abroad to the best of our knowledge. We have no influence on the type and extent of the data transmitted and on their further processing. Data exchange takes place in accordance with the respective guidelines of the social network. Details on the plug-ins used by Facebook, Google and Twitter and the respective data protection regulations of the social networks can be found under the following links:

- https://developers.facebook.com/docs/plugins (Facebook) 
- https://www.facebook.com/about/privacy (Facebook)
- https://dev.twitter.com/docs/tfw (Twitter)
- https://twitter.com/privacy (Twitter)
- https://developers.google.com/+/web/ (Google+)
- http://www.google.com/intl/de/policies/privacy/ (Google+)

In order to limit the collection of data by social networks, which we cannot control, we have taken technical measures to prevent the data from being passed on. In this way, we ensure that no data is transferred to the aforementioned social networks when you visit our website. This only takes place when you activate the button of the respective social network that is integrated into our website by clicking on it.