Privacy policy
1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to identify you personally. Detailed information on the subject of data protection can be found in our data protection declaration listed below this text.
Data collection on our website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the legal notice of this website.
How do we collect your data?
On the one hand, your data is collected when you provide it to us. This may, for example, be data that you enter in a contact form.
Other data is collected automatically by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of page view). This data is collected automatically as soon as you enter our website.
What do we use your data for?
Some of the data is collected to ensure that the website is provided without errors. Other data can be used to analyse your user behavior.
What rights do you have with regard to your data?
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction, blocking or deletion of this data. You can contact us at any time at the address given in the legal notice if you have any further questions on the subject of data protection. You also have the right to lodge a complaint with the competent supervisory authority.
Analysis tools and third-party tools
When you visit our website, your surfing behavior may be statistically evaluated. This is mainly done using cookies and so-called analysis programs. The analysis of your surfing behavior is usually anonymous; the surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. Detailed information on this can be found in the following privacy policy.
2. General notes and mandatory information
Data protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the Internet (e.g. when communicating by e-mail) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information on the responsible body
The responsible body for data processing on this website is:
Bundesdeutscher Arbeitskreis für Umweltbewusstes Management (BAUM) e.V.
Osterstraße 58
20259 Hamburg
Phone: 040 – 49 07 11 00
E-mail:
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw your consent at any time. All you need to do is send us an informal e-mail. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
If data processing is carried out on the basis of Art. 6 para. 1 lit. e or f GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation; this also applies to profiling based on these provisions. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing serves the establishment, exercise or defense of legal claims (objection pursuant to Art. 21 (1) GDPR).
If your personal data are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is associated with such direct marketing. If you object, your personal data will subsequently no longer be used for the purpose of direct marketing (objection pursuant to Art. 21 (2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of breaches of data protection law, the data subject has the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Thomas Fuchs
Ludwig-Erhard-Str. 22, 7th floor
20495 Hamburg
Phone: 040/428 54-40 40
Fax: 040/428 54-40 00
E-mail:
SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Information, blocking, deletion
You have the right to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction, blocking or deletion of this data at any time within the framework of the applicable legal provisions. You can contact us at any time at the address given in the legal notice if you have further questions on the subject of personal data.
4. Processing of data by BAUM
BAUM collects and processes data for the fulfillment of its purpose and in the context of membership in BAUM and in the BAUM Circle of Sponsors.
The data collection and data processing is necessary for the fulfillment of the tasks of BAUM and the resulting obligations and tasks and is based on Article 6 para. 1 GDPR.
BAUM does not transmit your data to third parties for advertising purposes.
Within BAUM, only those departments that need your data to fulfill its contractual and legal obligations will have access to it. Service providers used by BAUM may also receive data for these purposes if they are commissioned as processors in accordance with Art. 28 GDPR.
5. Data collection on our website
Cookies
Some of the web pages use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies are used to make our website more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called “session cookies”. They are automatically deleted at the end of your visit. Other cookies remain stored on your end device until you delete them. These cookies enable us to recognise your browser on your next visit.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.
Cookies that are required to carry out the electronic communication process or to provide certain functions that you have requested (e.g. shopping basket function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the storage of cookies for the technically error-free and optimised provision of its services. Insofar as other cookies (e.g. cookies to analyze your surfing behavior) are stored, these are treated separately in this privacy policy.
We use the “Real Cookie Banner” consent tool to manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and related consents. Details on how “Real Cookie Banner” works can be found at https://devowl.io/de/rcb/datenverarbeitung/.
The legal basis for the processing of personal data in this context is Art. 6 para. 1 lit. c GDPR and Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the related consents.
The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we will not be able to manage your consent.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are
-
Browser type and browser version
-
Operating system used
-
Referrer URL
-
Host name of the accessing computer
-
Time of the server request
-
IP address
This data is not merged with other data sources.
The basis for data processing is Art. 6 para. 1 lit. f GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.
Registration on this website
You can register on our website in order to use additional functions on the site. We will only use the data you enter for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject your registration.
We will use the e-mail address provided during registration to inform you of important changes, such as changes to the scope of the offer or technically necessary changes.
The data entered during registration is processed on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw your consent at any time. All you need to do is send us an informal e-mail. The legality of the data processing that has already taken place remains unaffected by the revocation.
The data collected during registration will be stored by us as long as you are registered on our website and will then be deleted. Statutory retention periods remain unaffected.
Processing of data (customer and contract data)
We collect, process and use personal data only insofar as it is necessary for the establishment, content or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures. We collect, process and use personal data about the use of our website (usage data) only insofar as this is necessary to enable the user to use the service or to bill the user.
The customer data collected will be deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
Data transmission upon conclusion of a contract for services and digital content
We only transmit personal data to third parties if this is necessary in the context of contract processing, for example to the credit institution commissioned with payment processing.
No further transmission of data takes place or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.
6. Analysis tools and advertising
Web analysis with Koko Analytics
This website uses the privacy-friendly analysis plugin “Koko Analytics”. Only anonymous, aggregated statistical data on page views and visitor access is collected. The data is collected in cookie-free mode without storing personal data. The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in measuring reach). The data is processed exclusively on the web server of this website. It is not passed on to third parties.
7. Newsletter
Registration & dispatch
We use the double opt-in procedure for the newsletter. Mandatory information: e-mail address, first name, surname
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
Revocation: at any time via the unsubscribe link in the newsletter or by e-mail to
Mailing service provider Mailchimp
The newsletter is sent via Mailchimp (The Rocket Science Group LLC, 675 Ponce de Leon Ave NE, Atlanta,GA30308, USA). Mailchimp processes data on our behalf.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
Data transfer: USA; protection via standard contractual clauses (SCC) or the EU-US Data Privacy Framework (if applicable)
Storage period: until consent is withdrawn
8. External links
This website contains links to third party websites or to other websites under our responsibility. If you follow a link to any of the websites outside our responsibility, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies.
External links are marked with a symbol.
9. Plugins and tools
YouTube
Our website uses plugins from the Google-operated YouTube site. The operator of the pages is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA.
When you visit one of our pages equipped with a YouTube plugin, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited.
If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.
The use of YouTube is in the interest of an appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
Further information on the handling of user data can be found in YouTube’s privacy policy at: https://www.google.de/intl/de/policies/privacy
OpenStreetMap
This website uses the open source mapping tool “OpenStreetMap” (OSM) to display geodata.
To use the functions of OpenStreetMap, it is necessary to save your IP address. This information is usually transmitted to a server of the OpenStreetMap project.
OSM does not store any user data. Further details can be found at https://wiki.openstreetmap.org/wiki/Legal_FAQ. The provider of this site has no influence on this data transfer.
The use of OpenStreetMap is in the interest of an appealing presentation of our online offers and to make it easy to find the places we have indicated on the website. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
Integration of LinkedIn content via Elfsight
We integrate content from the social network LinkedIn via the service “Elfsight, LLC, 0015, Armenia, Yerevan, Paronyana str., 19/3, 201”. The content is not loaded directly from LinkedIn, but from the Elfsight servers. There is no direct connection between your device and the LinkedIn servers. https://elfsight.com/privacy-policy/
When a page with the widget is called up, technical information (e.g. IP address, browser type, operating system, referrer URL) is transmitted to Elfsight to enable the display and to ensure system security. Elfsight stores server logs for 7 days. In addition, the cookie elfsight_viewed_recently can be set to control the display; it is not used for marketing or tracking purposes. If the widget contains input fields (e.g. forms), these inputs are stored in encrypted form on Google Cloud Platform servers.
Purpose
Presentation of LinkedIn content on our website via a more data protection-friendly intermediate service (Elfsight), performance optimisation through caching, ensuring technical provision.
Legal basis
The widget is loaded and non-technically required information is accessed and stored on your device on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with Section 25 para. 1 TDDDG. The widget will not be loaded without consent. You can withdraw your consent at any time using our consent tool.
Recipients and third country transfers
The recipient of the data is Elfsight, LLC. The processing takes place on servers of the Google Cloud Platform, which are located in the USA and possibly in the EU. A third country transfer cannot be ruled out and takes place on the basis of standard contractual clauses of the EU Commission.
Storage duration
server logs: 7 days. Cookie elfsight_viewed_recently: function-related, duration depends on Elfsight configuration.
10 Our social media presence
Data processing by social networks
We maintain publicly accessible profiles on social networks. The individual social networks we use can be found below.
Social networks such as Facebook, Twitter etc. can generally analyze your user behavior comprehensively when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). Visiting our social media presences triggers numerous data protection-relevant processing operations. In detail:
If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection takes place, for example, via cookies that are stored on your end device or by recording your IP address.
With the help of the data collected in this way, the operators of the social media portals can create user profiles in which your preferences and interests are stored. In this way, interest-based advertising can be displayed to you inside and outside the respective social media presence. If you have an account with the respective social network, the interest-based advertising can be displayed on all devices on which you are logged in or were logged in.
Please also note that we cannot track all processing operations on the social media portals. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media portals. For details, please refer to the terms of use and data protection provisions of the respective social media portals.
Legal basis
Our social media presences are intended to ensure the widest possible presence on the internet. This is a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. The analysis processes initiated by the social networks may be based on different legal bases, which must be specified by the operators of the social networks (e.g. consent within the meaning of Art. 6 para. 1 lit. a GDPR).
Controller and assertion of rights
If you visit one of our social media sites (e.g. LinkedIn), we are jointly responsible with the operator of the social media platform for the data processing operations triggered during this visit. You can assert your rights (information, rectification, erasure, restriction of processing, data portability and complaint) both against us and against the operator of the respective social media portal (e.g. against LinkedIn).
Please note that despite our joint responsibility with the social media portal operators, we do not have full influence on the data processing operations of the social media portals. Our options depend largely on the company policy of the respective provider.
Storage period
The data collected directly by us via the social media presence will be deleted from our systems as soon as you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies. Stored cookies remain on your end device until you delete them. Mandatory statutory provisions – in particular retention periods – remain unaffected.
We have no influence on the storage period of your data that is stored by the operators of social networks for their own purposes. For details, please contact the operators of the social networks directly (e.g. in their privacy policy, see below).
Social networks in detail
LinkedIn
We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
You can adjust your LinkedIn privacy settings yourself in your user account. To do this, click on the following link and log in:https://www.linkedin.com/mypreferences/d/categories/privacy
Details can be found in LinkedIn’s privacy policy:https://de.linkedin.com/legal/privacy-policy?
Instagram
We have a profile on Instagram. The provider is Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:https://www.facebook.com/legal/EU_data_transfer_addendum,https://help.instagram.com/519522125107875 and https://de-de.facebook.com/help/566994660333381
Details on how they handle your personal data can be found in Instagram’s privacy policy:https://help.instagram.com/519522125107875