Privacy Policy

This Privacy Policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “Data”) within our online offering and the associated websites, features, and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the “Online Offering”). With regard to the terms used, such as “processing” or “controller,” please refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Data Controller

 

TC Tobacco Hakenfelde e.V.
Werderstrasse 26H
13587 Berlin
Germany
Phone: +49 (0)152 08694052
Mail: info@tc-tobacco.de
Web: https://www.tc-tobacco.de

Types of Data Processed

  • Master data (e.g., names, addresses).
  • Contact information (e.g., email, phone numbers).
  • Content data (e.g., text entries, photographs, videos).
  • Usage data (e.g., websites visited, interest in content, access times).
  • Meta/communication data (e.g., device information, IP addresses).

Categories of Data Subjects

 

Visitors and users of the online service (hereinafter, we collectively refer to these individuals as “users”).

Purpose of Processing

  • Providing the online service, its features, and content.
  • Responding to contact requests and communicating with users.
  • Security measures.
  • Audience measurement/marketing.

Terminology Used

 

“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, commercial, cultural, or social identity of that natural person.


"Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data.

“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

 

“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

 

"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

 

"Processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Relevant Legal Bases

 

In accordance with Art. 13 of the GDPR, we inform you of the legal bases for our data processing activities. Unless the legal basis is specified in the privacy policy, the following applies: The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 of the GDPR; the legal basis for processing to fulfill our services, carry out contractual measures, and respond to inquiries is Art. 6(1)(b) of the GDPR; the legal basis for processing to fulfill our legal obligations is Art. 6(1)(c) of the GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6(1)(f) of the GDPR. In the event that the vital interests of the data subject or another natural person require the processing of personal data, Art. 6(1)(d) of the GDPR serves as the legal basis.

Safety Measures

 

In accordance with Article 32 of the GDPR, and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as controlling access to, input of, and disclosure of the data, and ensuring data availability and segregation. Furthermore, we have implemented procedures to guarantee the exercise of data subjects' rights, the deletion of data, and responses to threats to data security. In addition, we take the protection of personal data into account during the development or selection of hardware, software, and processes, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).

Collaboration with Data Processors and Third Parties

 

If, in the course of our processing activities, we disclose data to other persons and companies (processors or third parties), transmit it to them, or otherwise grant them access to the data, this is done only on the basis of legal authorization (e.g., if the transmission of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Art. 6(1)(b) GDPR), your consent, a legal obligation, or our legitimate interests (e.g., when using agents, web hosts, etc.).

If we commission third parties to process data based on a so-called "data processing agreement," this is done on the basis of Article 28 of the GDPR.

Transfers to Third Countries

 

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA))—or if this occurs in the context of using third-party services or disclosing or transmitting data to third parties—we do so only to fulfill our (pre-)contractual obligations, based on your consent, due to a legal obligation, or based on our legitimate interests. Subject to legal or contractual permissions, we process data in a third country—or have it processed there—only if the specific requirements of Articles 44 et seq. of the GDPR are met. This means, for example, that processing takes place based on special safeguards, such as an official determination that the level of data protection is equivalent to that of the EU (e.g., for the USA via the "Privacy Shield") or compliance with officially recognized special contractual obligations (so-called "Standard Contractual Clauses").

Rights of Data Subjects

 

You have the right to request confirmation as to whether the data in question is being processed, and to obtain access to that data as well as further information and a copy of the data, in accordance with Art. 15 GDPR.

 

In accordance with Art. 16 GDPR, you have the right to request the completion of data concerning you or the rectification of incorrect data concerning you.

Subject to Art. 17 GDPR, you have the right to request the immediate erasure of the data in question or, alternatively, to request a restriction on the processing of the data in accordance with Art. 18 GDPR.

 

You have the right to receive the data concerning you that you have provided to us, in accordance with Art. 20 GDPR, and to request its transmission to other controllers.

 

Furthermore, pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.

Right of Withdrawal

 

You have the right to withdraw any consent you have given, in accordance with Art. 7(3) GDPR, with effect for the future.

Right to Object

 

You may object to the future processing of data concerning you at any time in accordance with Article 21 of the GDPR. In particular, you may object to processing for direct marketing purposes.

Cookies and the Right to Object to Direct Marketing

 

"Cookies" are small files stored on users' computers. Various types of information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. Cookies that are deleted after a user leaves an online service and closes their browser are referred to as temporary cookies, "session cookies," or "transient cookies." Such cookies can store, for example, the contents of a shopping cart in an online shop or a login status. Cookies that remain stored even after the browser is closed are referred to as "permanent" or "persistent" cookies. For instance, a user's login status can be saved so that it remains active when the user visits the site again days later. Such cookies can also store user interests, which are used for audience measurement or marketing purposes. "Third-party cookies" are cookies placed by providers other than the controller operating the online service (conversely, cookies placed by the operator itself are known as "first-party cookies").

 

We may use temporary and permanent cookies and provide information about this in our privacy policy.

 

If users do not wish to have cookies stored on their computers, they are asked to disable the corresponding option in their browser's system settings. Stored cookies can be deleted in the browser's system settings. Excluding cookies may result in functional limitations regarding this online service.

 

A general objection to the use of cookies employed for online marketing purposes can be declared for a large number of services—particularly regarding tracking—via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be prevented by disabling them in the browser settings. Please note that, in that case, it may not be possible to use all functions of this online service.

Deletion of Data

 

The data we process is deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated otherwise in this privacy policy, data stored by us is deleted as soon as it is no longer required for its intended purpose and provided that no statutory retention obligations prevent such deletion. If the data is not deleted because it is required for other legally permissible purposes, its processing is restricted; this means the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

 

In accordance with statutory requirements in Germany, retention takes place specifically for 10 years pursuant to Sections 147 (1) of the Fiscal Code (AO) and 257 (1) Nos. 1 and 4 and (4) of the Commercial Code (HGB) (books, records, management reports, accounting vouchers, commercial books, documents relevant for taxation, etc.) and for 6 years pursuant to Section 257 (1) Nos. 2 and 3 and (4) HGB (commercial correspondence).

 

In accordance with statutory requirements in Austria, retention takes place specifically for 7 years pursuant to Section 132 (1) of the Federal Fiscal Code (BAO) (accounting records, vouchers/invoices, accounts, receipts, business papers, statements of income and expenditure, etc.), for 22 years in connection with real estate, and for 10 years for documents relating to electronically supplied services, telecommunications, broadcasting, and television services provided to non-business customers in EU Member States for which the Mini One-Stop Shop (MOSS) scheme is utilized.

Provision of our services in accordance with our bylaws and business practices

 

We process the data of our members, supporters, interested parties, customers, or other individuals in accordance with Art. 6(1)(b) GDPR, provided we offer them contractual services, act within the scope of an existing business relationship (e.g., with members), or are ourselves recipients of services and contributions. Otherwise, we process the data of data subjects pursuant to Art. 6(1)(f) GDPR based on our legitimate interests—for example, in the context of administrative tasks or public relations work.

 

The data processed in this context, as well as the nature, scope, purpose, and necessity of such processing, are determined by the underlying contractual relationship. This generally includes the individuals' inventory and master data (e.g., name, address, etc.) and contact details (e.g., email address, telephone number, etc.), as well as contract data (e.g., services utilized, content and information provided, names of contact persons) and—where we offer paid services or products—payment data (e.g., bank details, payment history, etc.).

 

We delete data that is no longer required for fulfilling our statutory and business purposes. This is determined based on the specific tasks and contractual relationships involved. In the case of business-related processing, we retain data for as long as it may be relevant for conducting business or regarding potential warranty or liability obligations. The necessity of data retention is reviewed every three years; otherwise, statutory retention obligations apply.

Registration Function

 

Users may create a user account. During registration, users are informed of the mandatory information required; this data is processed pursuant to Art. 6(1)(b) GDPR for the purpose of providing the user account. The data processed includes, in particular, login information (name, password, and an email address). Data entered during registration is used for the purpose of utilizing the user account and its associated functions.

 

Users may be notified via email of information relevant to their user account, such as technical changes. Once users have terminated their user account, their account-related data will be deleted, subject to any statutory retention obligations. It is the user's responsibility to back up their data prior to the end of the contract following termination. We reserve the right to irretrievably delete all user data stored during the term of the contract.

 

When users utilize our registration and login functions or the user account itself, we store the IP address and the time of the respective user action. This storage is based on our legitimate interests—as well as the users' interests—in protection against misuse and other unauthorized use. As a general rule, this data is not disclosed to third parties unless necessary for the pursuit of our claims or required by law pursuant to Art. 6(1)(c) GDPR. IP addresses are anonymized or deleted after no more than 7 days.

Contacting us

 

When you contact us (e.g., via contact form, email, telephone, or social media), the user's information is processed for the purpose of handling and managing the inquiry in accordance with Art. 6(1)(b) GDPR (within the scope of contractual or pre-contractual relationships) and Art. 6(1)(f) GDPR (for other inquiries). User data may be stored in a customer relationship management system ("CRM system") or a comparable inquiry management system.

 

We delete inquiries when they are no longer required. We review the necessity of retention every two years; statutory archiving obligations also apply.

Newsletter

 

The following information outlines the content of our newsletter, the procedures for registration, distribution, and statistical analysis, as well as your right to object. By subscribing to our newsletter, you consent to receiving it and agree to the procedures described herein.

 

Newsletter Content: We send newsletters, emails, and other electronic notifications containing promotional information (hereinafter referred to as the "Newsletter") only with the recipient's consent or where legally permitted. If the specific content of the newsletter is described during the registration process, that description forms the basis of the user's consent. Otherwise, our newsletters contain information about us and our services.

 

Double Opt-In and Logging: Registration for our newsletter follows a "double opt-in" procedure. This means that after registering, you will receive an email asking you to confirm your subscription. This confirmation is necessary to prevent unauthorized individuals from registering using someone else's email address. Newsletter registrations are logged to provide evidence of the registration process in compliance with legal requirements. This includes storing the times of registration and confirmation, as well as the IP address. Changes to the data stored with the email service provider are also logged.

 

Registration details: To subscribe to the newsletter, providing your email address is sufficient. We also ask you to optionally provide a name so that we can address you personally in the newsletter.

 

The newsletter is sent, and performance is measured, based on the recipients' consent pursuant to Art. 6(1)(a) and Art. 7 of the GDPR in conjunction with Section 7(2) No. 3 of the UWG (Act Against Unfair Competition), or—where consent is not required—based on our legitimate interests in direct marketing pursuant to Art. 6(1)(f) of the GDPR in conjunction with Section 7(3) of the UWG.

 

The registration process is logged based on our legitimate interests pursuant to Art. 6(1)(f) of the GDPR. Our interest lies in using a user-friendly and secure newsletter system that serves our business interests, meets user expectations, and enables us to provide proof of consent.

 

Cancellation/Revocation – You may cancel your newsletter subscription at any time—that is, revoke your consent. You will find a link to unsubscribe at the bottom of every newsletter. We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, in order to be able to demonstrate that consent was previously given. Processing of this data is limited to the purpose of potentially defending against claims. An individual request for deletion may be made at any time, provided that the prior existence of consent is simultaneously confirmed.

Hosting and Email Delivery

 

The hosting services we utilize serve to provide the following: infrastructure and platform services, computing capacity, storage space and database services, email delivery, security services, and technical maintenance services, all of which we employ for the purpose of operating this online service.

 

In doing so, we—or our hosting provider—process inventory data, contact details, content data, contract data, usage data, and meta/communication data belonging to customers, interested parties, and visitors to this online service. This processing is based on our legitimate interests in providing this online service efficiently and securely, in accordance with Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).

Collection of Access Data and Log Files

 

We, or our hosting provider, collect data regarding every access to the server hosting this service (so-called server log files) based on our legitimate interests within the meaning of Art. 6(1)(f) GDPR. Access data includes the name of the accessed website, the file, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user's operating system, the referrer URL (the previously visited page), the IP address, and the requesting provider.

 

Log file information is stored for security reasons (e.g., to investigate abuse or fraud) for a maximum of 7 days and then deleted. Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident has been finally resolved.

Social Media Presence

 

We maintain online presences on social networks and platforms in order to communicate with customers, interested parties, and users active there and to inform them about our services. When accessing these networks and platforms, the terms and conditions and data processing policies of the respective operators apply.

 

Unless otherwise stated in our privacy policy, we process user data when users communicate with us via these social networks and platforms—for example, by posting on our online presences or sending us messages.

Integration of Third-Party Services and Content

 

Within our online services, and based on our legitimate interests (i.e., the interest in analyzing, optimizing, and economically operating our online services within the meaning of Art. 6(1)(f) GDPR), we incorporate content or services from third-party providers—such as videos or fonts (hereinafter collectively referred to as "Content").

 

This requires that the third-party providers of such Content perceive the users' IP addresses, as they would otherwise be unable to transmit the Content to the users' browsers. The IP address is therefore necessary for the display of this Content. We endeavor to use only Content from providers who utilize the IP address solely for the purpose of delivering that Content. Furthermore, third-party providers may use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. These pixel tags allow for the analysis of information such as visitor traffic on this website. This pseudonymous information may also be stored in cookies on the user's device and may include technical details regarding the browser and operating system, referring websites, time of visit, and other data concerning the use of our online services, as well as being linked with information from other sources.