Privacybeleid
Kintamani Campur e.V. is een Duitse vereniging. Deze pagina is beschikbaar in het Engels en het Duits.
This is an English translation of our German privacy policy. If the two versions differ, the German version prevails.
Preamble
With the following privacy policy we would like to inform you which types of your personal data (hereinafter also referred to as “data”) we process, for which purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online services”).
The terms used are not gender-specific.
Last updated: 1 October 2026
Table of contents
- Preamble
- Controller
- Overview of processing
- Relevant legal bases
- Security measures
- Transfer of personal data
- International data transfers
- General information on data retention and deletion
- Rights of data subjects
- Provision of the online services and web hosting
- Use of cookies
- Donations and payment service providers
- Contact and enquiry management
- Newsletter
- Use of web fonts
- Web analytics, monitoring and optimisation
- Changes and updates
- Definitions
Controller
Kintamani Campur e.V.
Röntgenstr. 25
41747 Viersen
Germany
Authorised representatives: Andreas Hölters, Gita Andria Puspita (board)
Email address: hi@kintamanicampur.com
Legal notice: kintamanicampur.com/nl/imprint/
Overview of processing
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
- Master data.
- Payment data.
- Contact data.
- Content data.
- Usage data.
- Meta, communication and process data.
- Log data.
Categories of data subjects
- Communication partners.
- Users.
- Donors.
- Prospective adopters and other interested parties.
Purposes of processing
- Communication.
- Security measures.
- Reach measurement.
- Organisational and administrative procedures.
- Feedback.
- Processing of donations.
- Direct marketing (newsletter).
- Provision of our online services and usability.
- Information technology infrastructure.
Relevant legal bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or registered office. Should more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations: In addition to the General Data Protection Regulation (GDPR), national data protection regulations apply in the country in which the controller has its registered office (Germany).
Security measures
In accordance with the legal requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input, disclosure, availability and separation of the data. We have also established procedures to ensure that data subjects' rights are exercised, data is deleted and threats to data are responded to. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in line with the principles of data protection by design and by default.
Securing online connections with TLS/SSL encryption (HTTPS): To protect users' data transmitted via our online services against unauthorised access, we use TLS/SSL encryption. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), protecting the data against unauthorised access. TLS, as the more advanced and secure successor to SSL, ensures that all data transmissions meet high security standards. When a website is secured by an SSL/TLS certificate, this is indicated by “HTTPS” in the URL, signalling to users that their data is transmitted securely and in encrypted form.
Transfer of personal data
In the course of processing personal data, it may happen that the data is transferred or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are embedded in a website. In such cases, we comply with the legal requirements and in particular conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
International data transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies (which can be recognised from the postal address of the respective provider or where this privacy policy expressly refers to a transfer to third countries), this is always done in accordance with the legal requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognised as a safe legal framework by an adequacy decision of the European Commission of 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the European Commission and set out contractual obligations to protect your data.
This double safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the standard contractual clauses serve as additional security. Should changes occur within the DPF, the standard contractual clauses act as a reliable fallback. In this way we ensure that your data remains adequately protected even in the event of political or legal changes.
For the individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.
For data transfers to other third countries, corresponding safeguards apply, in particular standard contractual clauses, explicit consent or transfers required by law. Information on third-country transfers and applicable adequacy decisions can be found on the European Commission's website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
General information on data retention and deletion
We delete personal data that we process in accordance with the legal provisions as soon as the underlying consent is withdrawn or there are no further legal grounds for processing. This applies to cases in which the original purpose of processing no longer applies or the data is no longer needed. Exceptions apply where legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and deletion of data that applies specifically to certain processing operations.
Where several retention periods or deletion deadlines apply to an item of data, the longest period is always decisive. Data that is no longer kept for its originally intended purpose but due to legal requirements or other reasons is processed by us exclusively for the reasons that justify its retention.
Periods starting at the end of the year: If a period does not expressly begin on a specific date and is at least one year, it automatically begins at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the course of which data is stored, the triggering event is the date on which the termination or other ending of the legal relationship takes effect.
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
- Right of access: You have the right to obtain confirmation as to whether data concerning you is being processed and to access this data as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without delay or, alternatively, to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. You may lodge the complaint in particular with a supervisory authority in the member state of your habitual residence, place of work or place of the alleged infringement.
Provision of the online services and web hosting
We process users' data in order to provide our online services to them. For this purpose, we process the user's IP address, which is necessary to deliver the content and functions of our online services to the user's browser or device.
- Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved); log data (e.g. log files relating to logins, data retrieval or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and usability; information technology infrastructure (operation and provision of information systems and technical equipment such as computers and servers); security measures.
- Retention and deletion: Deletion in accordance with the section “General information on data retention and deletion”.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Provision of the online services on rented server space: To provide our online services, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also called a “web host”).
- Collection of access data and log files: Access to our online services is logged in the form of so-called “server log files”. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful retrieval, browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files can be used for security purposes, e.g. to prevent server overload (in particular in the case of abusive attacks, so-called DDoS attacks), and to ensure server load and stability. Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is necessary for evidential purposes is excluded from deletion until the respective incident has been finally clarified.
Use of cookies
The term “cookies” refers to functions that store information on users' devices and read it from them. Cookies can be used for various purposes, such as the functionality, security and convenience of online services and the analysis of visitor flows. We use cookies in accordance with the legal requirements. Where necessary, we obtain users' consent in advance. Where consent is not required, we rely on our legitimate interests. This is the case where storing and reading information is essential to provide content and functions that have been expressly requested, such as storing settings and ensuring the functionality and security of our online services. Consent can be withdrawn at any time. We inform clearly about its scope and which cookies are used.
Information on legal bases under data protection law: Whether we process personal data using cookies depends on consent. If consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage duration: With regard to storage duration, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online service and closed their device (e.g. browser or mobile application).
- Persistent cookies: Persistent cookies remain stored even after the device is closed. For example, the login status can be saved and preferred content displayed directly when the user visits a website again. Likewise, user data collected with cookies can be used for reach measurement. Unless we provide users with explicit information on the type and storage duration of cookies (e.g. when obtaining consent), users should assume that cookies are persistent and may be stored for up to two years.
General information on withdrawal and objection (opt-out): Users can withdraw any consent they have given at any time and can also object to processing in accordance with the legal requirements, including via the privacy settings of their browser.
- Types of data processed: Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); consent (Art. 6(1)(a) GDPR).
Further information on processing operations, procedures and services:
- Cookie notice on this website: On your first visit, we display a notice about cookies. We store your choice (“Accept” or “Decline”) in the cookie “kc_cookie_consent” on your device so that the notice does not reappear on every page view. The cookie contains only your choice, is not transmitted to third parties and is automatically deleted after 180 days. Our own website does not set any other cookies. When you open the donation form, the payment service provider Donorbox and the payment providers it integrates may set their own cookies required for processing payments (see section “Donations and payment service providers”). Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Section 25(2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act).
Donations and payment service providers
We use the service Donorbox to process donations. The donation form is displayed on our website in an embedded window; for this purpose, a script from Donorbox is loaded on all pages. In the process, your IP address and information about your browser and operating system are transmitted to Donorbox for technical reasons.
When you donate, Donorbox processes the data you enter, in particular your name, email address, address if applicable, donation amount, donation frequency and payment data, in order to process the donation and send you a confirmation. Depending on the payment method chosen, the actual payment is processed by the payment service providers connected to Donorbox (in particular Stripe and PayPal), which process their own data for this purpose and may set their own cookies. We do not receive full credit card or bank account details. We receive the details of your donation from Donorbox in order to manage donations, thank you and, where applicable, issue donation receipts.
- Types of data processed: Master data (e.g. names, addresses); payment data (e.g. donation amount, payment method, payment history); contact data (e.g. email addresses); meta, communication and process data (e.g. IP addresses, timestamps).
- Data subjects: Donors; users (e.g. website visitors).
- Purposes of processing: Processing of donations; organisational and administrative procedures; communication.
- Retention and deletion: Deletion in accordance with the section “General information on data retention and deletion”. Donation data relevant to the association's accounting or to donation receipts is retained in accordance with the statutory retention periods (up to ten years).
- Legal bases: Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Donorbox: Online donation platform; service provider: Rebel Idealist, Inc. (Donorbox), USA; website: https://donorbox.org; privacy policy: https://donorbox.org/privacy. Basis for third-country transfer: Standard contractual clauses (Art. 46(2)(c) GDPR), where provided by the provider.
- Stripe: Payment service provider; service provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; privacy policy: https://stripe.com/privacy.
- PayPal: Payment service provider; service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg; privacy policy: https://www.paypal.com/de/legalhub/privacy-full.
Contact and enquiry management
When you contact us (e.g. by post, contact form, email, telephone or via social media) and in the context of existing user and business relationships, the information provided by the enquiring persons is processed to the extent necessary to answer the contact enquiries and any requested measures.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts and information relating to them, such as authorship or time of creation); meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners; interested parties (e.g. in an adoption).
- Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via online form); provision of our online services and usability.
- Retention and deletion: Deletion in accordance with the section “General information on data retention and deletion”.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR).
Further information on processing operations, procedures and services:
- Contact form: When you contact us via our contact form, by email or through other channels, we process the personal data provided to us in order to answer and handle your request. This usually includes your name, contact details and any other information you provide that is necessary to handle the request appropriately. We use this data exclusively for the stated purpose of contact and communication. This also applies to adoption enquiries you send via the corresponding forms on our website.
- Formspree: The content of our forms (contact, adoption and newsletter forms) is transmitted to us via the service Formspree. Formspree receives the data entered and, for technical reasons, your IP address and browser information, stores the message and forwards it to us by email. Formspree processes the data on our behalf; service provider: Formspree, Inc., USA; website: https://formspree.io; privacy policy: https://formspree.io/legal/privacy-policy. Basis for third-country transfer: Standard contractual clauses (Art. 46(2)(c) GDPR), where provided by the provider.
Newsletter
With our newsletter we share news about our dogs, rescues and the association. To subscribe, you only need to provide your email address. The subscription is transmitted to us via Formspree (see section “Contact and enquiry management”). We use your email address exclusively to send the newsletter and do not pass it on to third parties.
You can unsubscribe from the newsletter at any time, e.g. via the unsubscribe link in each issue or by email to hi@kintamanicampur.com. Your email address will then be removed from the mailing list. In order to be able to prove consent given previously, we may retain the subscription data for up to three years; processing is then limited to this purpose.
- Types of data processed: Contact data (email address); meta, communication and process data (e.g. time of subscription, IP address).
- Data subjects: Communication partners; users.
- Purposes of processing: Direct marketing (newsletter); communication.
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR) for proof of consent.
Use of web fonts
To ensure a consistent appearance, we use fonts from external providers. When you open a page, your browser loads the font files directly from the providers' servers. In the process, your IP address, the date and time of the request and information about your browser and operating system are transmitted to the respective provider for technical reasons. To our knowledge, no cookies are set in the process.
- Types of data processed: Usage data (e.g. pages visited, device types and operating systems used); meta, communication and process data (e.g. IP addresses, timestamps).
- Data subjects: Users (e.g. website visitors).
- Purposes of processing: Provision of our online services and usability.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR) in a consistent and appealing presentation of our online services.
Further information on processing operations, procedures and services:
- Google Fonts: Font “Archivo”; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://fonts.google.com/; privacy policy: https://policies.google.com/privacy; basis for third-country transfer: Data Privacy Framework (DPF).
- Fontshare: Font “Clash Display”; service provider: Indian Type Foundry, India; website: https://www.fontshare.com/.
Web analytics, monitoring and optimisation
Web analytics (also referred to as “reach measurement”) is used to evaluate the flow of visitors to our online services and may include behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis we can, for example, recognise at what times our online services or their functions or content are used most frequently, or invite users to return. It also allows us to understand which areas need optimisation.
In addition to web analytics, we may also use testing procedures, for example to test and optimise different versions of our online services or their components.
Unless stated otherwise below, profiles, i.e. data summarised for a usage session, may be created for these purposes and information may be stored in and read from a browser or device. The data collected includes in particular websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. If users have agreed to the collection of their location data with us or with the providers of the services we use, the processing of location data is also possible.
The IP addresses of users are also stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear data of users (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation, but pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, only the information stored in their profiles for the purposes of the respective procedures.
Information on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, users' data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, please also refer to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles).
- Retention and deletion: Deletion in accordance with the section “General information on data retention and deletion”. Storage of cookies for up to 2 years (unless stated otherwise, cookies and similar storage methods may be stored on users' devices for a period of two years).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Cloudflare Web Analytics: We use Cloudflare Web Analytics on this website to evaluate the use of our online services statistically. When a page is opened, a JavaScript file from Cloudflare is loaded. In the process, data is transmitted to Cloudflare for technical reasons, in particular the IP address, the page visited, the previously visited page (referrer), the date and time of access, browser, operating system, device type, screen size and page load times. According to Cloudflare, the IP address is not stored for the statistics and is not used to recognise visitors. In deviation from the general information in this section, no cookies are set, no information is stored on the device and no user profiles are created. We only receive aggregated statistics (e.g. number of visits, most visited pages, countries of origin) and cannot draw any conclusions about individual persons. Since no information is stored on or read from your device beyond what is technically necessary to display the website, consent under Section 25 TDDDG is not required. Cloudflare processes the data on our behalf on the basis of a data processing agreement (Art. 28 GDPR). You can prevent collection by disabling JavaScript in your browser or by using a script or ad blocker. Service provider: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA; website: https://www.cloudflare.com/web-analytics/; privacy policy: https://www.cloudflare.com/privacypolicy/; legal basis: Legitimate interests (Art. 6(1)(f) GDPR); basis for third-country transfer: Data Privacy Framework (DPF).
Changes and updates
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that addresses may change over time and please check the information before contacting them.
Definitions
This section provides an overview of the terms used in this privacy policy. Where terms are defined by law, their legal definitions apply. The following explanations are primarily intended to aid understanding.
- Master data: Master data comprises essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs).
- Content data: Content data comprises information generated in the course of creating, editing and publishing content of all kinds. This category may include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the content itself but also includes metadata that provides information about the content, such as tags, descriptions, author information and publication dates.
- Contact data: Contact data is essential information that enables communication with persons or organisations. It includes telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Meta, communication and process data: Meta, communication and process data are categories containing information about how data is processed, transmitted and managed. Metadata, also known as data about data, includes information describing the context, origin and structure of other data, such as file size, creation date, author of a document and change histories. Communication data covers the exchange of information between users via various channels, such as email traffic, call logs, social network messages and chat histories, including the persons involved, timestamps and transmission paths. Process data describes processes and workflows within systems or organisations, including workflow documentation, logs of transactions and activities, and audit logs used to track and review operations.
- Usage data: Usage data refers to information that records how users interact with digital products, services or platforms. It covers a wide range of information showing how users use applications, which functions they prefer, how long they stay on certain pages and which paths they take through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services, and plays an important role in identifying trends, preferences and potential problem areas within digital offerings.
- Personal data: “Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: The processing of “profiles with user-related information”, or “profiles” for short, includes any form of automated processing of personal data consisting of the use of such personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include information on demographics, behaviour and interests, such as interaction with websites and their content), e.g. interest in certain content or products, click behaviour on a website or location. Cookies and web beacons are often used for profiling purposes.
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically includes information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used to analyse system problems, monitor security or generate performance reports.
- Reach measurement: Reach measurement (also referred to as web analytics) is used to evaluate the flow of visitors to an online service and may include the behaviour or interests of visitors in certain information, such as website content. With the help of reach analysis, operators of online services can, for example, recognise at what times users visit their websites and which content they are interested in, allowing them to better adapt website content to their visitors' needs.
- Controller: “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: “Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically every handling of data, be it collection, analysis, storage, transmission or deletion.
- Payment data: Payment data comprises all information required to process payment transactions, including means of payment (e.g. credit cards, bank accounts), payment amounts, transaction data and information on payment history.
Based on the free privacy policy generator Datenschutz-Generator.de by Dr. Thomas Schwenke