Our website contains links to other sites on the internet. For all these links we expressly emphasize: We have no influence on the design and content of the linked pages. We therefore expressly distance ourselves from all content on all linked pages. This declaration applies to all links on our website and to all contents of the websites to which the links lead.
This data protection declaration explains to you the type, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offer and the associated websites, functions and content as well as external online presences, such as our social media profile (hereinafter collectively referred to as "online offer"). With regard to the terms used, such as "processing" or "person responsible", we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).
Kulturinsel Stuttgart non-profit GmbH
Types of data processed:
- Inventory data (e.g., names, addresses).
- Contact details (e.g., email, phone numbers).
- Content data (e.g., text input, photographs, videos).
- Usage data (e.g. websites visited, interest in content, access times).
- Meta / communication data (e.g. device information, IP addresses).
Categories of data subjects
Visitors and users of the online offer (in the following we also refer to the persons concerned collectively as "users").
Purpose of processing
- Provision of the online offer, its functions and content.
- Answering contact inquiries and communicating with users.
- Safety measures.
- Reach measurement / marketing
“Personal data” is all information that relates to an identified or identifiable natural person (hereinafter “data subject”); A natural person is regarded as identifiable who can be identified directly or indirectly, in particular by means of assignment to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or one or more special features, which express the physical, physiological, genetic, psychological, economic, cultural or social identity of this natural person.
“Processing” is any process carried out with or without the aid of automated processes or any such series of processes in connection with personal data. The term is broad and encompasses practically every handling of data.
"Pseudonymization" the processing of personal data in such a way that the personal data can no longer be assigned to a specific data subject without the use of additional information, provided that this additional information is stored separately and is subject to technical and organizational measures that ensure that the personal data cannot be assigned to an identified or identifiable natural person.
"Profiling" means any type of automated processing of personal data that consists of using this personal data to evaluate certain personal aspects relating to a natural person, in particular aspects relating to work performance, economic situation, health, personal To analyze or predict the preferences, interests, reliability, behavior, whereabouts or relocation of this natural person.
“Responsible” is the natural or legal person, authority, institution or other body that alone or jointly with others decides on the purposes and means of processing personal data.
"Processor" means a natural or legal person, authority, institution or other body that processes personal data on behalf of the person responsible.
Relevant legal bases
In accordance with Art. 13 GDPR, we will inform you of the legal basis for our data processing. If the legal basis is not mentioned in the data protection declaration, the following applies: The legal basis for obtaining consent is Art. 6 Para. 1 lit. a and Art. 7 GDPR, the legal basis for processing to fulfill our services and to carry out contractual measures Answering inquiries is Art. 6 Para. 1 lit.b GDPR, the legal basis for processing to fulfill our legal obligations is Art. 6 Para. 1 lit.c GDPR, and the legal basis for processing to safeguard our legitimate interests is Art . 6 para. 1 lit.f GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6 (1) (d) GDPR serves as the legal basis.
In accordance with Art. 32 GDPR, taking into account the state of the art, the implementation costs and the type, scope, circumstances and purposes of processing as well as the different probability of occurrence and severity of the risk for the rights and freedoms of natural persons, we make suitable technical and organizational measures to ensure a level of protection appropriate to the risk.
The measures include, in particular, securing the confidentiality, integrity and availability of data by controlling physical access to the data, as well as the access, input, transfer, ensuring availability and their separation. Furthermore, we have set up procedures that ensure the exercise of data subject rights, deletion of data and reaction to data threats. Furthermore, we already consider the protection of personal data during the development or selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and data protection-friendly default settings (Art. 25 GDPR).