Privacy Policy

Preamble

With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter also briefly referred to as "data") we process for what purposes and to what extent in the context of providing the application "Stadtführer Görlitz".

The terms used are not gender-specific.

Last updated: February 25, 2024

Table of Contents

Overview of Processing

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.

Types of Data Processed

Categories of Data Subjects

Purposes of Processing

Legal Basis

Legal Basis under the GDPR:Below you will find an overview of the legal basis under the GDPR on which we process personal data. Please note that in addition to the GDPR regulations, national data protection regulations may apply in your or our place of residence or jurisdiction. Should more specific legal bases be applicable in individual cases, we will inform you of this in the privacy policy.

National Data Protection Regulations in Germany:In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include in particular the Act on Protection against Misuse of Personal Data in Data Processing (German Federal Data Protection Act – BDSG). The BDSG contains in particular special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission as well as automated decision-making in individual cases including profiling. Furthermore, state data protection laws of the individual German states may apply.

Security Measures

We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the different probabilities and extent of the risk to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

Measures include in particular the safeguarding of confidentiality, integrity and availability of data through control of physical and electronic access to the data as well as access to it, input, transmission, safeguarding of availability and its separation. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the deletion of data and responses to data security threats. We also take into account the protection of personal data in the development and selection of hardware, software and procedures in accordance with the principle of data protection, through technology design and privacy-friendly default settings.

TLS/SSL Encryption (https): To protect user data transmitted through our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing Internet connections by encrypting data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) is displayed in the URL when a website is secured by an SSL/TLS certificate.

International Data Transfers

Data Processing in Third Countries: To the extent that we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA)) or processing takes place in the context of using third-party services or disclosure or transmission of data to other persons, entities or organisations, this takes place only in accordance with legal requirements.

EU-US Trans-Atlantic Data Privacy Framework: As part of the so-called "Data Privacy Framework" (DPF), the EU Commission has recognized the level of data protection as adequate for certain companies from the USA in its adequacy decision of 10 July 2023. The list of certified companies and further information about the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). In our privacy notice we inform which of our service providers are certified under the Data Privacy Framework.

Rights of Data Subjects

Rights of Data Subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:

Provision of Online Services and Web Hosting

We process user data in order to be able to provide our online services to them. For this purpose, we process the user's IP address, which is necessary to transmit the contents and functions of our online services to the user's browser or end device.

Further Information on Processing Processes, Procedures and Services:

Created with free privacy policy generator from Dr. Thomas Schwenke