Skip to content

Data protection is important to us.

I. Introduction and terminology

GENERAL
We process personal data when operating our website at www.startschuss.org (hereinafter referred to as ‘website’). We treat this data confidentially and process it in accordance with the applicable laws – in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). With these data protection provisions, we want to inform you about which personal data we collect from you, for which purposes and on which legal basis we use it and, if applicable, to whom we disclose it. In addition, we will explain to you which rights you have to safeguard and enforce your data protection.
TERMS
Our data protection provisions contain technical terms that are found in the GDPR and the BDSG. For your better understanding, we would like to explain these terms in advance in simple terms:
2.1 Personal data ‘Personal data’ is any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR). Information about an identified person may be, for example, their name or email address. However, data in which the identity is not immediately apparent but can be determined by combining one’s own or third-party information and thus learning who is involved is also personal data. A person can be identified, for example, by providing their address or bank details, their date of birth or user name, their IP addresses and/or location data. All information that can be used to identify a person in any way is relevant here.
2.2 Processing According to Art. 4 No. 2 GDPR, ‘processing’ refers to any operation carried out in connection with personal data. This includes, in particular, the collection, recording, organisation, sorting, storage, adaptation or alteration, retrieval, consultation, use, disclosure, transmission, dissemination or any other form of provision, alignment or combination, restriction, erasure or destruction of personal data.


II. Controller and data protection officer

RESPONSIBLE PARTY
The following person is responsible for data processing:
Club: Startschuss Queerer Sportverein Hamburg e.V. (‘we’) Legal representative: Janko Zehe, Jan Dietrich, Florian Kloth Address: c/o Hein und Fiete Pulverteich 21, 20099 Hamburg Email: buero[at]startschuss.org
DATA PROTECTION OFFICER
We have appointed an external data protection officer for our association. You can contact him at:
Company: HABEWI GmbH & Co. KG Legal representative: General partner HABEWI Beteiligungs GmbH, represented by Arne Platzbecker (managing director) Address: Palmaille 96, 22767 Hamburg Telephone: 040/ 46008966 Fax: 040/ 46008977 E-mail: datenschutz@habewi.de


III. Processing framework

PROCESSING FRAMEWORK: WEBSITE
We process the personal data that we have collected from you and that is listed in detail in Section IV. in the context of the website. We only process data that you actively provide on the website (e.g. by filling out forms) or that you automatically provide when using our services.
Your data will be processed exclusively by us and will not be sold, lent or passed on to third parties. If we use the help of external service providers to process your personal data, this is done within the framework of so-called order processing, in which we, as the client, have the authority to issue instructions to our contractors. We use external service providers for the hosting of our website. We host our website with the external provider Misto Ltd. (address: 15, Level 3, Mannarino Road, Birkirkara BKR 9080, Malta) at the data centre location in Düsseldorf, Germany. Should further external service providers be used for the processing operations listed in Section IV, they will be named there.
We do not transfer data to third countries and do not plan to do so. We will provide information on exceptions to this principle in the processing operations described below. Any data transfer to third countries will then be carried out on the basis of the so-called EU standard contractual clauses.


IV. Processing in detail

PROVISION OF THE WEBSITE AND SERVER LOGFILES
6.1 Description of the processingEvery time you visit the website, we automatically collect information that your browser transmits to our server. This is the following data:

  • IP address
  • Browser software used, as well as its version and language
  • Operating system
  • The website from which visitors came to the website (so-called referrer)
  • The sub-pages accessed on the website
  • the date and time of the website visit
  • internet service provider
    These are also stored in our system’s log files. The system needs to store your IP address temporarily in order to deliver our website to a user’s device. To do this, the user’s IP address must be stored for the duration of the session. However, your IP address is not stored in the log files.
    6.2 Purpose: The processing is carried out to enable the website to be accessed and to ensure its stability and security. In addition, the processing is used for the statistical evaluation and improvement of our online services.
    6.3 Legal basis: The processing is necessary to safeguard the overriding legitimate interests of the data controller (Art. 6 para. 1 lit. f GDPR). Our legitimate interest lies in the purpose stated in section 6.2.
    6.4 Storage period The data will be deleted as soon as it is no longer required for the purpose for which it was collected. In the case of data collection for the provision of the website, this is the case when the respective session has ended. The log files are deleted after 7 days.
    COOKIES
    7.1 Description of the processing Our website uses cookies. Cookies are small text files that are stored on the respective user’s device when they visit a website. Cookies contain information that enables the recognition of a device and, if necessary, certain functions of a website. We distinguish between our own cookies and external, so-called third-party cookies. Our site uses so-called ‘session cookies’ and ‘persistent cookies’. ‘Session cookies’ are automatically deleted when you end your internet session and close your browser. Persistent cookies remain stored on your end device for a longer period of time. We only use cookies that are technically necessary for the operation of our site. No consent is required for these cookies. The following overview shows which cookies are used on our website for which purpose, how long they are stored on your end device and which consents you may have already given. Cookie Name Purpose Storage duration PHPSESSID Stores important settings for PHP session administration. This cookie is deleted at the end of the session. Page 3 of 5 7.2 Purpose We use cookies to make our website more user-friendly and to offer the functions described in section 7.1. 7.3 Legal basis The processing is necessary to safeguard the overriding legitimate interests of the controller (Art. 6 para. 1 lit. f GDPR). Our legitimate interest lies in the purpose stated in Section 7.2. 7.4 Storage period Cookies are automatically deleted at the end of a session or when the specified storage period has expired. Since cookies are stored on your end device, you as a user have full control over the use of cookies. You can disable or restrict the transmission of cookies by changing the settings in your internet browser. Cookies that have already been stored can be deleted. This can also be done automatically. If cookies for our website are deactivated, deleted or restricted, it is possible that individual functions of our website cannot be used or can only be used to a limited extent.
    7.5 Recipients When third-party cookies are used, data may be transmitted to the corresponding providers of these third-party services. Under certain circumstances, data may also be transmitted to third countries outside the European Union or the European Economic Area. We provide information about the recipients of data and any transmission to third countries in the corresponding section on the third-party service in this privacy policy.
    CONTACT FORM AND CONTACT BY E-MAIL
    8.1 Description of the processing To contact us, we have provided a contact form on our website. In this form, you are asked to enter your e-mail address, your name and a message to us. When you click on the ‘Send’ button, the data is transmitted to us using SSL encryption (see Section 10). The contact form can only be transmitted if you confirm that you have read this data protection declaration by clicking on the corresponding checkbox. You can also contact us using the e-mail addresses provided on the website. To contact us, you can write to us at the e-mail address provided on the website. In this case, we will process the personal data transmitted with the e-mail.
    8.2 Purpose: By providing a contact form on our website, we want to offer you a convenient way to get in touch with us. The data transmitted with and in the contact form or your e-mail will be used exclusively for the purpose of processing and answering your request.
    8.3 Legal basis The processing is necessary to safeguard the overriding legitimate interests of the controller (Art. 6 para. 1 lit. f GDPR). Our legitimate interest lies in the purpose stated in Section 8.2. If the purpose of the email contact is to conclude or fulfil a contract, the data processing is carried out to fulfil the contract (Art. 6 (1) (b) GDPR).
    8.4 Storage period We will delete the data as soon as it is no longer required to achieve the purpose for which it was collected. This is usually the case when the respective communication with you has ended. Communication is deemed to have ended when it can be inferred from the circumstances that your request has been conclusively resolved. If statutory retention periods prevent deletion, deletion will take place immediately after the statutory retention period has expired.
    SOCIAL NETWORKS
    9.1 Description of the processingOur website does not use any so-called social media plugins. The Facebook logos displayed on our website are only linked to the corresponding profiles of our association on social networks. No data transfer to the social networks takes place with the integration of the logos. If you click on one of the logos, you will only be redirected to the external website of the respective social network.
    However, our profiles within the social networks do constitute data processing. If you are logged into the respective social network when you visit such a profile, this information will be assigned to your user account there. If you interact with our profile, e.g. comment on, ‘share’, ‘like’ or ‘retweet’ a post, this information is also stored in your user account. As a rule, we can also see your interactions with our profile.
    On the social network Facebook, we have the option of obtaining statistical data about the use of our Facebook page via the so-called ‘Insights’ function. These statistics are provided by Facebook. The ‘Insights function’ is not optional. We cannot decide to switch this function on or off. It is available to all Facebook fan page operators, regardless of whether they use the Facebook Insights function or not. Facebook Insights provides us with the following data for a selectable period of time with regard to fans, subscribers, people reached and people interacting: total number of page views, ‘likes’ including origin, page activity, post interactions, reach, post reach (divided into organic, viral and paid interactions), comments, shared content, replies and demographic analyses, i.e. country of origin, gender and age. The insights statistics do not allow us to identify subscribers and fans of our page and view their profiles. The social networks you communicate with store your data as user profiles using pseudonyms and use them for advertising purposes and for market research. For example, advertisements may be displayed to you within the social network and on other third-party websites that correspond to your presumed interests. As a rule, cookies that the social network stores on your end device are used for this purpose. You have the right to object to the creation of these user profiles, and to exercise this right you must contact the social networks directly. 9.2 Purpose We maintain profiles on the aforementioned social networks for the purpose of public relations and association communication with members and interested parties. We use the ‘Insights’ function of Facebook to evaluate the reach of our posts on the social network and to make them more appealing to our visitors in the future.
    9.3 Legal basis The legal basis for data processing in the context of our social network profiles is the protection of our overriding legitimate interests (Art. 6 (1) (f) GDPR). Our legitimate interest lies in the purpose stated in Section 9.2. If you are asked by the respective operator of a social network for consent, the legal basis is Art. 6 para. 1 lit. a GDPR. The data processing is carried out with regard to our presences on Facebook, otherwise on the basis of a joint responsibility in accordance with Art. 26 GDPR.
    9.4 Recipients and transfers to third countries The respective social networks are operated by the companies listed below. Further information on data protection with regard to our profile on social networks can be found in the linked data protection provisions.
  • Facebook: Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA. Privacy Policy: http://www.facebook.com/policy.php; http://www.facebook.com/help/186325668085084, http://www.face-book.com/about/privacy/your-info-on-other#applications and http://www.facebook.com/about/privacy/your-info#everyoneinfo.
    The social networks also process your personal data in the USA.


    V. Security measures

    To protect your personal data from unauthorised access, we have provided our website with an SSL or TLS certificate. SSL stands for ‘Secure Sockets Layer’ and TLS for ‘Transport Layer Security’ and encrypts the communication of data between a website and the user’s end device. You can recognise active SSL or TLS encryption by the small padlock symbol that appears on the far left of the browser’s address bar.


    VI. Your rights

    Rights of data subjects
    With regard to the data processing described above by our association, you have the following rights as a data subject:
    11.1 Information (Art. 15 GDPR) You have the right to request confirmation from us as to whether we are processing personal data concerning you. If this is the case, you have the right to information about this personal data and to the information specified in Art. 15 GDPR under the conditions specified in Art. 15 GDPR.
    11.2 Rectification (Art. 16 GDPR) You have the right to request that we rectify any inaccurate personal data concerning you without undue delay and, if necessary, to complete incomplete personal data.
    11.3 Erasure (Art. 17 GDPR) You have the right to obtain from us the erasure of personal data concerning you without undue delay where one of the grounds listed in Art. 17 GDPR applies, e.g. if your data is no longer required for the purposes pursued by us.
    Page 5 of 5
    11.4 Restriction of data processing (Art. 18 GDPR) You have the right to request that we restrict processing if one of the conditions listed in Art. 18 GDPR is met, e.g. if you dispute the accuracy of your personal data, data processing will be restricted for the period that enables us to verify the accuracy of your data.
    11.5 Data portability (Art. 20 GDPR) You have the right, under the conditions set out in Art. 20 GDPR, to request the disclosure of data concerning you in a structured, commonly used and machine-readable format.
    11.6 Revocation of consent (Art. 7 (3) GDPR) You have the right to revoke your consent at any time in the case of processing based on consent. The revocation applies from the time of its assertion. In other words, it applies for the future. The processing does not become retrospectively unlawful as a result of the revocation of consent.
    11.7 Right to lodge a complaint (Art. 77 GDPR) If you consider that the processing of personal data relating to you infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. You can exercise this right with a supervisory authority in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement.
    11.8 Prohibition of automated decision-making/profiling (Art. 22 GDPR) Decisions that have legal consequences for you or significantly affect you may not be based solely on automated processing of personal data, including profiling. We hereby inform you that we do not use automated decision-making, including profiling, with regard to your personal data.
    11.9 Right to object (Art. 21 GDPR) If we process your personal data on the basis of Art. 6 (1) point f GDPR (for the purposes of our overriding legitimate interests), you have the right to object to this under the conditions listed in Art. 21 GDPR. However, this only applies if there are reasons for doing so that arise from your particular situation. After an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms. We are also not required to stop processing if it serves the establishment, exercise or defence of legal claims. In any case – and irrespective of the specific situation – you have the right to object at any time to the processing of your personal data for direct marketing purposes.
    As of: June 2021