Privacy Policy

General Information

The following information provides a brief overview of how personal data is processed when you visit our website and in connection with the services we provide in accordance with our business operations and bylaws. Personal data refers to any data that can be used to personally identify you.

Below, we provide you with the information required under Articles 13 and 14 of the GDPR, which you need to review and exercise your data protection rights. We are the data controller within the meaning of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG), as well as other data protection regulations such as the Telecommunications and Digital Services Data Protection Act (TDDDG), for our website and the associated data processing. Comprehensive information about our organisation can be found in the legal notice.

The following privacy policy is divided into the following sections:

I. Information about the Data Controller

II. Data Processing on Our Website

III. Data Processing in Connection with Our Business Activities and Statutory Services

IV. Rights of Data Subjects

I. Information about the Data Controller

Data Controller:

Kreisau-Initiative e. V.

c/o Allianz SE

Merlitzstraße 9

12489 Berlin

Germany

Phone: +49 (0)30 / 53 89 31 63 64

Email address: info@kreisau.de

Website: http://www.kreisau.de

Data Protection Officer

GFAD Datenschutz, LLC

Data Protection Officer

Huttenstraße 34/35

10553 Berlin

Phone: +49 (0)30 269 111-601

Email: datenschutz@gfad.de

II. Data Processing on Our Website

Data Security on Our Website

To ensure the security of our website, we use a valid, state-of-the-art SSL certificate. A website encrypted with SSL transmits personal data to the server in an encrypted form, making it impossible for third parties to intercept or read it. A certificate verifies our identity. Depending on your browser, you can tell that a secure connection is in place by the display of a padlock icon. By clicking on the lock icon, you can view our online identity verification. Because the data transmission is encrypted, you can be confident that the information you enter is adequately protected against unauthorized access during transmission, in accordance with the latest technical standards.

Protection of Minors

Our services are generally intended for adults. Individuals under the age of 18 may not provide us with any personal data without the consent of their parents or legal guardians. Minors under the age of 16 also require the consent of their parents or legal guardians to use external services on the website.

Hosting

The hosting services we use are intended to provide the following services: infrastructure and platform services, computing capacity, storage space, and database services, as well as security and technical maintenance services, which we utilize for the purpose of operating this online service.

In this context, we—or our hosting service provider acting on our behalf—process customer information, contact information, content data, contract data, usage data, meta and communication data from customers, prospective customers [DS3], and visitors to this online service based on our legitimate interests in providing this online service efficiently and securely in accordance with Article 6(1)(f) of the GDPR. Our hosting service provider’s data processing is carried out under a data processing agreement in accordance with Article 28 of the GDPR.

Cookies

When you use our website, cookies are stored on your computer. Cookies are small text files that are stored on your device and associated with the browser you are using, and the service provider that sets the cookie receives certain information. Cookies cannot run programs or transmit viruses to your computer. They generally serve to make the website more user-friendly and effective overall. The legal basis for the use of technically necessary cookies required for the operation of the website is Section 25(2)(2) of the TDDDG, if the storage of information on the end user’s device or access to information already stored on the end user’s device is absolutely necessary for the provider of a telemedia service to make available a telemedia service expressly requested by the user. The processing of personal data by technically necessary cookies is carried out to safeguard our legitimate interest pursuant to Article 6(1)(f) of the GDPR in designing and optimizing our website to be user-friendly. Section 25(1) of the German Telemedia Data Protection Act (TDDDG) applies to all cookies that are not technically necessary, for which consent is obtained. If personal data is also processed through technically non-essential cookies, consent under data protection law pursuant to Article 6(1)(a) of the GDPR will be obtained as necessary, provided that no other legal basis pursuant to Article 6(1) of the GDPR exists.

This website uses the following types of cookies; their scope and functionality are explained below:

Transient Cookies

These cookies are automatically deleted when you close your browser. This includes, in particular, session cookies. These store a so-called session ID, which allows various requests from your browser to be associated with the same session. This enables your computer to be recognized when you return to our website. These cookies are technically necessary for the optimization and display of the website. Session cookies are deleted when you log out or close your browser. Session cookies are generally technically necessary for the operation of the website and are therefore set on the legal basis of Section 25(2)(2) of the TDDDG.

Persistent Cookies

These cookies are automatically deleted after a specified period of time, which may vary depending on the cookie. You can delete the cookies at any time in your browser's security settings.

Third-Party Cookies

To further develop and improve our online offerings (website optimization), we use services (YouTube video service; OpenStreetMap maps; spam protection[DS4]) from third-party providers (Google) that also use cookies. To the extent that the third-party cookies used are not technically necessary for the operation of the website or the provision of the service to safeguard our legitimate interests pursuant to Article 6(1)(f) of the GDPR, consent is obtained via a consent banner or a consent management platform. To the extent that personal data is also processed by these services and/or cookies, this is done in accordance with Article 6(1)(a) of the GDPR, unless another legal basis for the processing of personal data exists under Article 6(1) of the GDPR.

Further information about the third-party services we use on our website is listed separately below as part of our privacy policy.

Blocking Cookies

You can configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that you may then be unable to use all features of this website. In addition, users have the option of accessing our website without cookies. To do so, you must change the corresponding settings in your browser. Please consult your browser’s help function to learn how to disable cookies. However, please note that this may impair some features of this website and limit your user experience. The websites http://www.aboutads.info/choices/ (U.S.) and http://www.youronlinechoices.com/uk/your-ad-choices/ (Europe) allow you to manage online advertising cookies. If cookie consent is obtained via consent banners, you can change your cookie settings at any time and revoke any consent you have given.

Website Hosting and Log Files

Entering personal data is not required to use our website for informational purposes only—that is, if you do not otherwise provide us with any information.

Nevertheless, every time you visit our website, in addition to information from the user’s computer or device, personal data is automatically collected that your browser transmits to our server. We collect the following data, which is technically necessary for us to display our website to you:

Data Processed:

  • Browser type and version
  • IP-addresses
  • Operating System
  • Date and time of access
  • Time Zone Difference from GMT
  • Details of the Request
  • Amount of Data Transferred
  • Referrer URL
  • Access Status / HTTP Status Code
  • Language Settings and Browser Software
  • Internet Service Provider

Purposes of Processing:

The temporary storage of this data in so-called log files is necessary to protect our legitimate interests in ensuring the technical functionality, stability, and security of the website. The data is not analyzed for marketing purposes in this context.

Legal Bases:

Article 6(1)(f) GDPR

Legitimate Interests

Technical Design, Stability, and Security of the Website

Storage Period:

The data listed above will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. In the case of data collected for the purpose of providing the website, this occurs when the respective session ends. In the case of data stored in log files, this occurs after 30 days at the latest. Storage beyond this period is possible if there are indications of an unlawful attack on our systems. In addition, statistical analyses of visits to our website may be stored in anonymized form for 12 months.

Safeguards for Third-Country Transfers:

No Third-Country Transfers at Present

Right to Object (Opt-Out):

Only if the data subject demonstrates grounds relating to their particular situation, and provided that there are no compelling legitimate grounds for the processing that override those grounds.

Additional Information on Processing Activities, Procedures, and Services:

none

Third-Party Services

YouTube video service

We embed videos from YouTube on our website. YouTube is a service provided by the Google Group. This group includes, in particular, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Videos are not loaded until you have explicitly given your consent in the respective placeholder. Only then will data—in particular, your IP address—be transmitted to Google, and cookies may be set. We store your consent exclusively locally in your browser.

Once activated, information such as your IP address, browser and device details, the page you visited or referrer information, online identifiers, and details regarding your use of the embedded video may be transmitted to YouTube or Google and processed there. YouTube may use cookies or similar technologies for this purpose. If you are logged into your YouTube or Google account at the same time, your usage may be associated with your account.

Purposes of Processing:

The hosting and playback of embedded YouTube videos, as well as the related technical provision of the YouTube service.

Legal Bases:

The storage of information on your device or access to information already stored there is, where applicable, based on your consent in accordance with Section 25(1) of the TDDDG. The associated processing of personal data is based on your consent in accordance with Article 6(1)(a) of the GDPR.

Withdrawal:

You can withdraw your consent at any time, effective for the future, through the cookie or consent settings on our website. The lawfulness of the processing carried out prior to the withdrawal remains unaffected. Without your consent, the YouTube player will not load.

Transfers to third countries:

When using YouTube, the transfer of personal data to the United States and other third countries cannot be ruled out. Such transfers are carried out in accordance with Articles 44 et seq. of the GDPR and the transfer mechanisms used by Google for this purpose.

Storage Period:

We generally have no control over how long YouTube or Google retains the data processed after the player is activated. This is governed by Google’s respective privacy and data retention policies.

Recipients of data:

Affiliated Companies and Subcontractors

Enhanced Privacy Mode:

To the extent that we embed YouTube videos using the enhanced privacy mode offered by YouTube (youtube-nocookie.com), YouTube states that playback data is not used, in particular, to personalize the YouTube experience or advertising. However, even in this mode, data processing by YouTube or Google takes place once the player is activated.

For more information about data processing by Google and YouTube, please see the Google Privacy Policy at https://policies.google.com/privacy and YouTube's information on embedding videos.

Web Analytics with Plausible Analytics

We use Plausible Analytics on our website to statistically analyze the use of our online services. The provider of the cloud version we use is Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible processes the analytics data on our behalf. To the extent that this constitutes processing on our behalf within the meaning of the GDPR, it is carried out on the basis of a contract in accordance with Article 28 of the GDPR.

The software runs on a server operated by our service provider, does not use cookies, and generates only aggregated statistics that do not contain any personally identifiable information.

In particular, the following information is collected and stored: the URL of the page accessed, the referrer, information about the browser, operating system, and device type derived from the user agent, and approximate location data derived from the IP address. The raw IP address and the full user agent are not stored. To determine unique visitors on a daily basis, an identifier is generated from the IP address, user agent, website domain, and a daily changing random value; the random value is deleted after 24 hours. According to the provider, this does not allow for recognition across multiple days.

Purposes of Processing:

Audience measurement, statistical analysis of website usage, and needs-based and technical optimization of our online offerings

Legal Bases:

Art. 6(1)(f) of the GDPR, to the extent that personal data is processed in the context of technical processing.

Legitimate Interests

Minimal data usage, aggregated analysis of the use of our online services, and website optimization.

Data Retention Period and Data Transfer:

According to Plausible, visitor data is generally processed and stored within the European Union. Raw IP addresses are not stored. For more information on data processing by Plausible, please visit https://plausible.io/data-policy and https://plausible.io/privacy.

Right to object:

To the extent that the processing is based on Article 6(1)(f) of the GDPR, the right to object under Article 21 of the GDPR applies subject to the conditions set forth therein.

CARTO / OpenStreetMap

We use CARTO for the map data in our interactive map, which is based on OpenStreetMap. When you visit a page containing a map, your IP address is transmitted to CARTO.

The OpenStreetMap map service is provided by the OpenStreetMap Foundation (OSMF), St. John’s Innovation Center, Cowley Road, Cambridge, CB4 0WS, United Kingdom. The map data is integrated into our website via an API provided by the OpenStreetMap Foundation.

When you visit our website, personal data is therefore transmitted to the OpenStreetMap Foundation (OSMF) via the OSMF API. To this end, OpenStreetMap may store cookies in your browser or use web analytics services such as Matomo. To display the map data, OpenStreetMap uses the open-source JavaScript library Leaflet. The library uses HTML5 and CSS3 and is therefore compatible with most desktop and mobile browsers.

In addition, your location may be tracked if you have enabled this feature in your device settings—for example, on your cell phone. As the provider of this website, we have no control over this data transfer. The OpenStreetMap Foundation is the data controller responsible for processing the data in connection with the provision of map data.

For more details, please refer to OpenStreetMap's privacy policy at the following link: https://wiki.osmfoundation.org/wiki/Privacy_Policy#Introduction

The website, the API servers, the databases, and the servers for support services are currently located in the United Kingdom and the Netherlands, and are therefore within the EEA.

We incorporate OpenStreetMap maps into our website to ensure an appealing presentation of our online offerings and to make it easy to locate the places listed on our website.

Data Processed:

  • IP-addresses
  • Browser and Device ID
  • Operating System
  • Referrer URL
  • Timestamp
  • Geodata
  • Data Used to Compile Usage Statistics

Purposes of Processing:

  • Measuring Click-Through and Open Rates (Reporting)
  • Advertising / Marketing
  • Attractive Presentation of Online Offerings
  • Ease of finding the locations listed on the website

Legal Bases:

  • Article 6(1)(f) GDPR

Legitimate Interests

Optimizing Online Services and Making It Easy to Find Locations

Storage Period:

IP addresses are deleted after 180 days, and personal data is stored only for as long as necessary for the purposes for which it was collected.

Legal Basis for Third-Country Transfers:

UK General Data Protection Regulation, Adequacy Decision pursuant to Article 45(1) of the GDPR

Right to Object (Opt-Out):

Only if the data subject demonstrates grounds relating to their particular situation, and provided that there are no compelling legitimate grounds for the processing that override those grounds.

Additional Information on Processing Activities, Procedures, and Services:

Matomo: OpenStreetMap may store cookies in your browser for this purpose or use web analytics services, such as Matomo, to collect statistics on traffic and user flows. We host Matomo exclusively on our own web servers, so the analytics data is not shared with third parties. Legal basis: Art. 6(1)(f) GDPR Provider: InnoCraft Ltd. (provider of Matomo), 150 Willis St, 6011 Wellington, New Zealand

Leaflet: is a freeJavaScriptlibrary designed for the user-friendly integration of interactive maps. Thanks to its JavaScript API, it is also easy to add markers and other overlays to maps. Its free counterpart, OpenStreetMap, does not offer such a simple approach. The Leaflet JavaScript library, however, offers features for creating interactive maps based on OpenStreetMap. Legal basis: Art. 6(1)(f) GDPR

Newsletter Sign-Up

On our website, we offer you the option to subscribe to our newsletter. If you provide us with separate consent, we will keep you informed via email about our work as an organisation. You can subscribe to the newsletter using the open-source solution CiviCRM. We use Brevo, a service provided by Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany, for sending newsletters, technical administration, and—if enabled by us—statistical analysis. Brevo processes the newsletter data required for this purpose from CiviCRM on our behalf. We have a data processing agreement with Brevo in accordance with Article 28 of the GDPR.

To the extent that we process your personal data based on your consent, you may revoke your consent at any time with future effect, without this affecting the lawfulness of the processing that took place prior to the revocation. If consent is revoked, we will cease the corresponding data processing. The data you provide to subscribe to the newsletter (e.g., email address and, if applicable, name) is transmitted to Brevo for the administration and distribution of the newsletter and is processed there on our behalf.

Your data used for sending the newsletter will generally be deleted when you unsubscribe from the newsletter and the data is no longer needed for sending it, provided that no legal retention or documentation requirements prevent this. If necessary, your email address may be added to a block list to ensure that no further newsletters are sent after you unsubscribe.

Data Processed:

  • Email addresses
  • Last Name, First Name
  • IP address
  • Timestamp
  • Usage patterns

Purposes of Processing:

  • Measuring Click-Through and Open Rates (Reporting)[DS8]
  • Advertising / Marketing
  • Direct Marketing via Email

Legal Bases:

Art. 6(1)(a) of the GDPR

Storage Period:

The data listed above will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected and there are no statutory retention periods that prevent its deletion.

Legal Basis for Third-Country Transfers:

To the extent that Brevo engages subprocessors outside the EU or the EEA in connection with the provision of services and personal data is transferred in the process, such transfer shall take place only in accordance with Articles 44 et seq. of the GDPR, in particular on the basis of an adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. The contractual and data protection terms applicable to the respective Brevo account shall prevail.

Right to Object (Opt-Out):

Withdrawal by Unsubscribing from the Newsletter

Additional Information on Processing Procedures, Methods, and Services: If the analytics features in Brevo are enabled, we can track whether a newsletter message has been opened and which links have been clicked. In particular, we may process data regarding opens and clicks, the time of access, and technical information. We use this analysis to improve the content and distribution of our newsletters. The analysis is based on the consent provided for the newsletter in accordance with Art. 6(1)(a) of the GDPR. For more information on data protection at Brevo, please visit https://www.brevo.com/de/legal/privacypolicy/.

Online Membership Form

To apply for membership using the online form, you must provide personal data. Data processing is carried out in accordance with Article 6(1)(b) of the GDPR for the duration of your membership. After your membership ends, your data will be deleted once the statutory retention periods have expired. As part of your membership, we use your contact information to inform you about activities within the association related to your membership. If you no longer wish to receive such information, you have the right at any time to object to future communications by sending an informal notice to info@kreisau.de, effective for the future, without incurring any costs other than the transmission costs according to standard rates. The membership list may be viewed by any member of the association upon request.

Donations

The processing of personal data is required under Article 6(1)(b) of the GDPR for the transfer and acceptance of donations, unless the donation is anonymous. When a donation is transferred to our donation account, the name of the account holder making the transfer and the bank account information are processed and stored. The address is also required to issue a donation receipt. For tax purposes, donation data must be retained for 10 years. We subsequently provide regular updates on how donations are used and on our work, provided that you have not objected to receiving such information.

Contact Us by Email

You can contact us using the email addresses provided. In this case, the personal data of the sender—that is, the user—submitted with the inquiry will be stored. We send all incoming and outgoing emails using state-of-the-art transport encryption with at least TLS 1.2. In this context, we would like to point out that sending unencrypted emails poses certain security risks, as the possibility of eavesdropping or unauthorized access cannot be ruled out. We process this personal data solely for the purpose of responding to your inquiry. Your data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. For personal data sent via email, this is the case once the respective inquiry has been answered and the conversation with the user has ended. The conversation is considered concluded when the circumstances indicate that the matter in question has been definitively resolved and no contract has been concluded.

Data Processed:

  • Email address
  • Name
  • Usage Data
  • Traffic Data

Data Subjects:

  • Employees
  • Customers*
  • Interested Parties
  • Service Providers*
  • Applicants*
  • Third

Purposes of Processing:

Electronic Communications

Legal Bases:

  • Article 6(1)(f) GDPR
  • Art. 6(1)(b) of the GDPR

Legitimate Interests

Electronic Communications

Storage Period:

The above-mentioned data will be deleted as soon as it is no longer required for the purposes for which it was collected, provided that no statutory retention obligations prevent its deletion. Email messages may also constitute business or commercial correspondence. In such cases, they must be retained for six years in accordance with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB).

Safeguards for Third-Country Transfers:

No Third-Country Transfers at Present

Right to Object (Opt-Out):

Only if the data subject demonstrates grounds relating to their particular situation, provided that there are no compelling legitimate grounds for the processing.

Additional Information on Processing Activities, Procedures, and Services:

None

Applying for Our Job Openings

If you are interested in one of our job openings and would like to apply, please email us your complete application materials in PDF format to the email address provided. This includes a cover letter, resume, and any employment references you have. If your application materials include photographs, we will consider this to be implied consent to the processing of the photograph. In accordance with Article 7(3), first sentence, of the GDPR, you have the right to withdraw this consent at any time.

We would also like to point out that sending your documents via unencrypted email poses certain security risks (such as unauthorized viewing, unauthorized access, malware infection, data loss, etc.) that cannot be ruled out. Your application materials will only be forwarded to the relevant employees within our organisation for processing. Your application materials will be reviewed for the purpose of establishing an employment relationship.

We will retain your application materials for up to 6 months, unless you give us your consent to retain them for a longer period.

Data Processed:

  • Contact Information: Last Name, First Name, Date of Birth, Email Address, Mailing Address, Phone Number
  • application photo, if applicable
  • Demographic information: age, income, origin (place of birth)
  • Information on Education: Degrees, Diplomas, and Qualifications
  • Special categories of personal data: religious affiliation, information regarding a severe disability, to the extent that such information is disclosed
  • Other Information: Data entered in online forms and HR questionnaires; information from the job interview

Data Subjects:

Job Applicant*

Purposes of Processing:

  • Conducting the Application Process
  • personality tests, if applicable
  • Job Interviews
  • Evaluation of the Application Process
  • Pre-employment check, if applicable
  • Hiring Decision by the Department and HR Managers
  • Notification of the Hiring Decision

Only with consent:

  • Contacting References
  • Inclusion in the Talent Pool

Legal Bases:

  • Processing of contractual and/or precontractual measures pursuant to Article 6(1)(b) of the GDPR
  • Art. 9(2)(b) of the GDPR in conjunction with § 26(3) of the BDSG, to the extent that special categories of personal data are processed
  • Legitimate interest pursuant to Article 6(1)(f) of the GDPR
  • Consent of the applicant pursuant to Article 6(1)(a) of the GDPR for the talent pool

Legitimate Interests

Pre-employment check, if applicable

Storage Period:

The data listed above will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected and there are no statutory retention periods that prevent its deletion. The application documents of rejected applicants will be deleted no later than 6 months after the rejection decision. If an applicant is hired, the application documents will be transferred to the personnel file.

Safeguards for Third-Country Transfers:

No Third-Country Transfers at Present

Right to Object (Opt-Out):

Only if the data subject demonstrates grounds relating to their particular situation, provided that there are no compelling legitimate grounds for the processing.

Withdrawal:

Consent granted for specific data processing activities may be revoked at any time with future effect by means of an informal notice. All other data processing activities that are permitted without consent remain unaffected by the revocation.

Additional information regarding unsolicited applications:

If there are no suitable job openings available at the moment, you are also welcome to send us a speculative application.

Legal Bases:

Implied consent pursuant to Article 6(1)(a) of the GDPR upon submission of the application materials. If you are a potential candidate, a recruitment process will be conducted to establish and carry out an employment relationship in accordance with Article 6(1)(b) of the GDPR. Based on our legitimate interest in carefully selecting applicants pursuant to Article 6(1)(f) of the GDPR, we will retain your application materials for up to 6 months, unless you grant us consent to retain them for a longer period.

Recipients of the data or categories of recipients

Within our organisation, access to your data is granted only to those departments that need it to fulfill contractual and legal obligations.

External Service Providers (Data Processors)

Your data will be shared with our IT and software service providers for the maintenance and support of IT systems and software, in order to assist us in providing our services.

The processing of your personal data by contracted service providers takes place within the framework of data processing on behalf of the controller in accordance with Article 28 of the GDPR.

Transfers to Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in connection with the use of third-party services, disclosure, or transfer of data to third parties, this is generally done only if it is necessary to fulfill our (pre)contractual obligations, based on a legal obligation, to protect our legitimate interests, if consent is given, or if another legal basis permits it. Subject to statutory or contractual permissions, we transfer data to third countries only if the specific requirements of Articles 44 et seq. of the GDPR are met. In such cases, a transfer takes place only on the basis of an EU adequacy decision pursuant to Article 45 of the GDPR or subject to appropriate safeguards pursuant to Article 46(2) of the GDPR, such as EU Standard Data Protection Clauses or binding internal data protection rules, known as Binding Corporate Rules (BCR). In addition, data transfers to third countries may occur in certain exceptional cases, e.g., to fulfill a contract or based on consent granted in accordance with Article 49 of the GDPR.

Data Transfer to the United States

Our website incorporates, among other things, services provided by companies based in the United States. When these services are active, your personal data may be transferred to the respective companies’ servers in the United States. On July 10, 2023, the European Commission adopted the new Data Privacy Framework (DPF) adequacy decision. This decision now serves as the basis for data transfers to the United States under the following conditions:

Under the DPF, personal data can now be transferred from the EU to the U.S. without the need for additional transfer mechanisms (such as standard contractual clauses) or supplementary measures. The DPF is based on a self-certification mechanism. A prerequisite for this is that the U.S. companies to which data is to be transferred are also certified under the EU-U.S. Data Privacy Framework.

In contrast, standard contractual clauses must be entered into separately for each individual instance of data transfer, unless certification under the DPF has been obtained.

Data Storage

To the extent necessary, we process and store personal data for the duration of the business relationship. This also includes the initiation and execution of a contract. The personal data required for warranty and guarantee claims is stored for the duration of such claims. In addition, we store personal data to the extent that we are legally required to do so. The corresponding documentation and retention requirements arise from the German Commercial Code (HGB) and the German Fiscal Code (AO). The retention and documentation periods specified therein generally range from six to ten years in accordance with commercial and tax law provisions under § 257 HGB and § 147 AO. The statute of limitations under the German Civil Code (BGB) may be up to 30 years if a court judgment has been issued (Sections 195 et seq. BGB). Unless a court judgment has been obtained against the data subject, the standard statute of limitations of three years applies. We delete the data subject’s personal data as soon as the purpose for which it was stored no longer applies and statutory retention periods do not preclude deletion.

III. Data Processing in Connection with Our Business Activities and Statutory Services

Membership in the Association

We process your data for the purpose of registering and managing memberships, as well as to fulfill the obligations toward association members arising from membership, based on the legal basis of Article 6(1)(b) of the GDPR for the duration of your membership. Upon termination of your membership, your data will be deleted after the statutory retention periods have expired. As part of your membership, we use your contact information to inform you about activities within the association related to your membership. If you no longer wish to receive such information, you have the right at any time to object with future effect by sending an informal notice to info@kreisau.de, without incurring any costs other than the transmission costs according to standard rates. The membership list may be viewed by any member of the association.

Events

To register for one of our events, we require certain personal data to better plan and coordinate the event. The processing of personal data is therefore carried out for the purpose of fulfilling and conducting the event in accordance with Article 6(1)(b) of the GDPR.

Participation in Association Events

If a request for participation in club events is made, participation is generally voluntary. If participation is confirmed, personal data will be processed for the purpose of organizing the event in accordance with Article 6(1)(b) of the GDPR. A confirmation of participation may be withdrawn at any time. For registration for a club event, the primary data processed are last name, first name, and email address. The processing of personal data of accompanying persons is carried out to safeguard the legitimate interests of the organizer in accordance with Article 6(1)(f) of the GDPR. Accompanying persons are informed by the person registering them about the processing of their personal data and the taking of photographs at the event, and are made aware of this privacy notice. This notice may also be viewed or sent upon request at any time. Depending on the type of event, additional information may be requested. This information is provided only to internal employees who need it to fulfill the purpose of the event or to perform their professional duties, as well as to the Human Resources department. If external service providers are engaged to fulfill the purpose, the information may be disclosed to them on a need-to-know basis, to the extent necessary for the performance of their tasks. Personal data will be deleted once the purpose has been fulfilled, unless it is required for billing purposes or subject to statutory retention obligations.

Photography and Videography at Association Events

At club events, photos and videos may be taken to document the event and for public relations purposes. These recordings may be published internally as well as on the club’s website, in the club’s newsletters, on the club’s social media channels (particularly Facebook and LinkedIn), and in the club’s print publications. To the extent that the focus of the recordings is on the event itself, processing is based on the club’s legitimate interests pursuant to Article 6(1)(f) of the GDPR regarding documentation and public relations. The rights and interests of the individuals depicted are taken into account when selecting and publishing the photographs. If, due to a specific situation, photographs of individual participants are not to be taken or published, this may be communicated to the photographer or the association.
In the case of targeted individual portraits or similar images in which a person is the focal point, consent is generally obtained prior to publication, unless, in exceptional cases, another legal basis applies. In the case of minors, their special protection interests are taken into account; if consent is required, it is obtained from the persons authorized to give it. In these cases, processing is based on consent in accordance with Art. 6(1)(a) of the GDPR. Consent that has been given may be revoked at any time with future effect. Revoking consent or refusing to give it will not result in any disadvantages.

Data Processing of Natural Persons Who Are Contractual and Business Partners, External Service Providers, Prospective Clients, and Points of Contact

We process the data of our contractual partners, prospective clients, clients, suppliers, service providers, and customers in accordance with Article 6(1)(b) of the GDPR in order to provide them with our contractual or precontractual services. The data processed in this context, as well as the nature, scope, purpose, and necessity of its processing, are determined by the underlying contractual relationship.

Data Processed:

  • Master Data (Last Names, First Names, and Addresses)
  • Contact Information (Email Addresses and Phone Numbers)
  • Contract Information
  • Payment Information (Bank Account Information, Payment History)
  • IP-addresses
  • Usage Data
  • Billing Information
  • Customer History

Data Subjects:

  • Employees of our contractual partners (clients, service providers, suppliers) as points of contact
  • Interested Parties

Purposes of Processing:

To establish and fulfill contractual obligations; direct marketing to protect our legitimate interests in initiating and developing contractual relationships

Legal Bases:

Art. 6(1)(b) of the GDPR; Art. 6(1)(f) of the GDPR

Legitimate Interests

Direct marketing, if applicable

Storage Period:

The above-mentioned data will be deleted as soon as it is no longer required for the purposes for which it was collected, provided that no statutory retention obligations prevent its deletion. Email messages may also constitute business or commercial correspondence. In such cases, they must be retained for six years in accordance with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB).

Safeguards for Third-Country Transfers:

Currently, there are no transfers to third countries.

Right to Object (Opt-Out):

Only if the data subject demonstrates grounds relating to their particular situation, provided that there are no compelling legitimate grounds for the processing.

Additional Information on Processing Activities, Procedures, and Services:

Direct Marketing

If we receive your email address and mailing address in connection with the conclusion of a contract, we may process this information to inform you in the future, via email and mail, about our own similar products and services. The legal basis for this is Article 6(1)(f) of the GDPR in conjunction with Section 7(3) of the UWG. If you do not wish to receive any further promotional information via email or mail, you may object to the use of your contact information for promotional purposes at any time with future effect, without incurring any costs other than the transmission costs according to the standard rates. You may submit your objection by mail or email to the following contact addresses.

Kreisau-Initiative e. V.
c/o Allianz SE
Merlitzstraße 9
12489 Berlin
Germany
Tel.: +49 (0)30 / 53 89 31 63 64
Email address: info@kreisau.de

Other Service Providers, Partners, and Third Parties

We may collaborate with other partners if it is necessary to fulfill our service offerings or if we are legally required to disclose data. These may include the following partners or third parties:

  • Credit Institutions and Payment Service Providers
  • Credit Reporting Agencies
  • Disclosure to public authorities or pursuant to a court order
  • Advertising Agencies
  • Document Shredding Companies, Logistics
  • Advisory and Consulting Services, Certified Public Accountants
  • Insurance
  • Law Firms and Jurisdiction
  • Service Companies
  • Social Organisations in the Context of Social Management
  • Member and Partner Organisations

We make it a priority to process your data within the EU. However, there may be instances where we use service providers that operate outside the EU. In such cases, we ensure that an adequate level of data protection is established before your personal data is transferred. This means that, through EU Standard Data Protection Clauses or an EU Adequacy Decision, a level of data protection is achieved that is comparable to the standards within the EU.

Source of Personal Data

We process personal data that we receive in the course of our business relationship. In addition, to the extent necessary for the provision of our services and the fulfillment of contracts, we process personal data that we have lawfully received from third parties (e.g., credit reporting agencies) on a lawful basis (e.g., to execute orders, fulfill contracts, or based on consent you have provided). We also process personal data that we have lawfully obtained from publicly available sources (e.g., commercial and association registries, the press, and the media) and are permitted to process.

Categories of Personal Data

We process the following categories of personal data about you:

Employee master data (name, address, and other contact information, date of birth); where applicable, order and contract data (e.g., delivery order), payment data, data related to the fulfillment of our contractual obligations, marketing and sales data, documentation data (data from consulting and service meetings), and similar data.

IV. Rights of Data Subjects

Rights of Data Subjects

If a user’s personal data is processed, that user is considered a data subject under the GDPR. As the data controller, the user has the following rights with respect to us:

  • Right to Information
  • Right to Correction
  • Right to Restriction of Processing
  • Right to Erasure
  • Right to Information
  • Right to Data Portability
  • Right to Object
  • Right to Withdraw Consent Under Data Protection Law
  • Right to File a Complaint with a Data Protection Supervisory Authority

Right to Access, Restriction of Processing, Erasure, and Rectification

In accordance with applicable legal provisions, you have the right at any time to receive, free of charge, information about your stored personal data, its origin and recipients, and the purpose of the data processing; and, if the legal requirements are met, you have the right to have this data corrected, to restrict its processing, or to have it deleted.

Right to Restriction of Processing

You have the right to request that the processing of your personal data be restricted. To do so, you may contact us at any time at the address listed in the legal notice. The right to restriction of processing applies in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the verification process, you have the right to request that the processing of your personal data be restricted.
  • If the processing of your personal data was or is unlawful, you may request that the processing be restricted instead of having the data deleted.
  • If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request that the processing of your personal data be restricted instead of being erased.
  • If you have filed an objection under Article 21(1) of the GDPR, a balancing of your interests against ours must be conducted. Until it is determined whose interests prevail, you have the right to request that the processing of your personal data be restricted.

If you have restricted the processing of your personal data, such data—other than for storage purposes—may be processed only with your consent or for the purpose of asserting, exercise, or defense of legal claims; to protect the rights of another natural or legal person; or for reasons of a substantial public interest of the European Union or a Member State.

Right to Data Portability

You have the right to have data that we process automatically—based on your consent or in fulfillment of a contract—provided to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another data controller, this will be done only to the extent that it is technically feasible.

Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You may revoke any consent you have already given at any time. To do so, simply send us an informal email. The lawfulness of the data processing carried out prior to the revocation remains unaffected by the revocation.

Right to object to data collection in specific cases and to direct marketing (Art. 21 GDPR)

If data processing is based on Article 6(1)(e) or (f) of the GDPR, you have the right at any time to object to the processing of your personal data for reasons arising from your particular situation; this also applies to profiling based on these provisions. You can find the specific legal basis on which processing is based in this Privacy Policy. If you object, we will no longer process your personal data in question, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims (objection under Article 21(1) of the GDPR).

If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing. If you object, your personal data will no longer be used for the purposes of direct marketing (objection pursuant to Art. 21(2) of the GDPR).

Right to File a Complaint with a Regulatory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the location of the alleged violation. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

Rights Regarding Data Processing Based on Legitimate Interest

Pursuant to Article 21(1) of the GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out pursuant to Article 6(1)(e) of the GDPR (data processing in the public interest) or Article 6(1)(f) of the GDPR (data processing to safeguard a legitimate interest). This also applies to profiling based on these provisions. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

Rights Regarding Direct Marketing

If we process your personal data for the purpose of direct marketing, you have the right under Article 21(2) of the GDPR to object at any time to the processing of your personal data for the purposes of such marketing; this also applies to profiling to the extent that it is related to such direct marketing.

If you object to the processing of your personal data for direct marketing purposes, we will no longer process your personal data for these purposes. The objection may be submitted in any form and should, if possible, be addressed to:

Kreisau-Initiative e. V.
c/o Allianz SE
Merlitzstraße 9
12489 Berlin
Germany
Tel.: +49 (0)30 / 53 89 31 63 64
Email address: info@kreisau.de

Legal or contractual requirements regarding the provision of personal data; necessity for the conclusion of the contract; the data subject’s obligation to provide personal data; possible consequences of failure to provide such data

We would like to inform you that the provision of personal data is, in some cases, required by law (e.g., tax regulations) or may also arise from contractual provisions (e.g., information about the contracting party). To enter into a contract, you must provide us with personal data. Without this data, we will generally have to refuse to enter into the contract or will no longer be able to fulfill an existing contract and may have to terminate it. If there is a legal obligation to provide the data, you are required to provide us with personal data. Before providing personal data, the data subject may contact our Data Protection Officer. Our Data Protection Officer will inform the data subject, on a case-by-case basis, whether the provision of personal data is required by law or contract, or is necessary for the conclusion of the contract; whether there is an obligation to provide the personal data; and what the consequences of failing to provide the personal data would be.

Automated decision-making, profiling

As a general rule, we do not use fully automated decision-making, including profiling, as defined in Article 22 of the GDPR, for the purpose of establishing and carrying out a contractual relationship.

Objection to Promotional Emails

We hereby object to the use of contact information published in compliance with legal disclosure requirements for the purpose of sending unsolicited advertising and informational materials. The operators of this website expressly reserve the right to take legal action in the event of the unsolicited transmission of advertising information, such as through spam emails.

Changes to the Privacy Policy

This privacy policy is updated on an ongoing basis as the Internet and our services continue to evolve. We will announce any changes on this page in a timely manner. To stay informed about the current status of our data usage policies, you should visit this page regularly. (Current as of: August 27, 2026)