Farbe sam health scaled

Privacy policy

We have relaunched our website and are updating our information on data protection promptly.

Privacy Policy

With the following data protection information, we, the

Deutsche Aidshilfe e. V.

Wilhelmstr. 138
10963 Berlin
Tel.: 030 - 69 00 87 0
Fax : 030 - 69 00 87 42
Email: dah@aidshilfe.de

as the controller within the meaning of the General Data Protection Regulation (GDPR), which personal data we process when you visit our website and use our online services.

We reserve the right to occasionally update our privacy policy to ensure that it always complies with current legal requirements or to reflect changes to our services. We therefore recommend that you read the privacy policy regularly to stay informed about the protection of the personal data we process.

Data protection officer

datenschutz@dah.aidshilfe.de

If you wish to exercise your rights as a data subject with regard to your right to erasure under Article 17 of the GDPR, please write to sam@dah.aidshilfe.de.

All data transfers to our website are carried out via an encrypted connection.

What do we use your personal data for?

Some data is collected to ensure the error-free provision of our website. Data is also processed to enable the smooth processing of orders, consultations, and payment transactions. Specifically:

Website hosting

Hosting via Digital Ocean LLC

This website is hosted on the cloud platform of Digital Ocean LLC, 106 6th Avenue, New York, USA. The legal basis for this is our legitimate interest in the error-free provision of our online services. We have entered into a data processing agreement with Digital Ocean. This agreement is publicly available: https://www.digitalocean.com/legal/privacy-policy.

Digital Ocean participates in the EU-US Data Privacy Framework, which regulates the secure transfer of data from EU citizens to the US. Data transfers to the US are also based on the EU standard contractual clauses. You can find out more about data processing at Digital Ocean here: https://www.digitalocean.com/legal?tid=135694281

Logging and creation of log files

When you visit our website, a range of technical data is logged. This general data and information is stored in the server's log files. Your IP address, browser identification and domain, the name of the file accessed, the date and time of access, the amount of data transferred and the successful access are recorded in a log file. The processing of personal data is carried out for the purpose of providing the website and for troubleshooting on the basis of a legitimate interest in accordance with Art. 6 (1) (f) GDPR. The log files are deleted after 90 days.

Cloudflare

Cloudflare Inc. – Content Delivery Network
 

We use a so-called “content delivery network” (CDN) provided by Cloudflare. Cloudflare is certified under the Privacy Shield Agreement and thus guarantees compliance with European data protection law.

A CDN is a service that helps deliver content from our online offering, especially large media files such as graphics or scripts, more quickly with the help of regionally distributed servers connected via the Internet. The processing of user data (e.g., contact information, IP addresses, performance data for websites, and browser activities derived from this) is carried out solely for the aforementioned purposes and to maintain the security and functionality of the CDN. The use is based on our legitimate interests, i.e., interest in the secure and efficient provision, analysis, and optimization of our online offering in accordance with Art. 6 (1) lit. f. GDPR.

Further information can be found in Cloudflare's privacy policy. You can prevent Cloudflare from collecting and processing your data by disabling the execution of script code in your browser or installing a script blocker in your browser.

Furthermore, based on the legitimate interest pursuant to Art. 6 (1) lit. f GDPR, only technically necessary cookies are used. The legitimate interest of DAH in this regard is to ensure user-friendliness, to ensure that the website is provided in compliance with data protection regulations (e.g., storage of the selection made regarding the cookie banner), and to ensure unrestricted technical functionality of the website, in particular the login area. These cookies are stored for a maximum of twelve months.

Contact

Registration/customer account

When you create an account with us via our online shop, we store your data in accordance with the information you provide during registration and when placing an order. When you open a customer account, we also store your user data (user name, password). At the same time, we store the IP address and the date and time of your registration for tracking purposes in the event of misuse, based on our legitimate interest pursuant to Art. 6 (1) lit. f) GDPR.

The data collected will be deleted as soon as processing is no longer necessary. However, we must observe tax and commercial law retention periods.

Transfer of data to checkpoints

Our service includes advice from employees at so-called checkpoints. The legal basis for this is Art. 6 (1) (b) GDPR, insofar as the transfer is necessary for the performance of the contract. If you provide us with health data in order to use our services, we will process this data in accordance with the legal requirements (Article 9(1) GDPR) exclusively on the basis of your consent. We have taken technical and organizational measures to ensure that your health data can only be accessed by authorized persons who need this data to provide our services.

Data transfer upon conclusion of a contract for services and digital content

We only transfer personal data to third parties if this is necessary for the execution of the contract, for example to checkpoints or the credit institution responsible for payment processing, or when transferring data to a shipping company or direct mail order company.

The basis for data processing is Art. 6 (1) lit. b GDPR, fulfillment of a contract or pre-contractual measures.

Email

When you contact us, personal data is collected. This data is stored and used for the purpose of responding to your request or for contacting you and for the associated technical administration.

The collected data is processed for the purpose of responding to contact requests and for communication. For the fulfillment of the contract and for pre-contractual inquiries on the basis of Art. 6 para. 1 sentence 1 lit. b. GDPR, or on the basis of our legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f. GDPR. Your data will be deleted after your inquiry has been processed, provided that there are no legal retention obligations to the contrary.

Cookies

We use cookies on our website. Cookies enable us to optimize the information and offers on our website for the benefit of the user. Cookies allow us to recognize users of our website. The purpose of this recognition is to make it easier for users to use our website.

Online marketing with Google tools

We process personal data for online marketing purposes on the basis of your consent in accordance with Art. 6 (1) (a) GDPR and our legitimate interest in efficient, economical, and recipient-friendly services in accordance with Art. 6 (1) (f) GDPR.

Unless otherwise stated, please assume that the cookies used are stored for a period of two years.

Google Tag Manager

Google Tag Manager is a tool that allows us to manage website tags and thus integrate Google Analytics and other Google marketing services into our online offering. The Tag Manager itself does not create user profiles or store cookies. Google only receives the user's IP address, which is necessary to run Google Tag Manager.  The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://fonts.google.com/; privacy policy: https://policies.google.com/privacy. We would like to point out that, if the service provider supports this, we will work towards concluding agreements on order processing in accordance with Art. 28 GDPR and standard data protection clauses in accordance with Art. 46 (2) lit. d GDPR.

Google Analytics

With your consent pursuant to Art. 6(1)(a) GDPR, we use Google Analytics, a web analytics service provided by Google Ireland Limited (“Google”).

The cookies set by Google Analytics or comparable technologies process usage data (e.g., visited websites, access times) and communication data (e.g., IP addresses, device information) are processed on our behalf in order to evaluate the use of our online offering, compile reports on the activities within our online offering, and provide other services related to the use of our online offering. This also allows for the creation of pseudonymized user profiles. Google Analytics is used exclusively with IP anonymization. All processed personal data is deleted or completely anonymized after 14 months. We have concluded an agreement with Google for order processing in accordance with Art. 28 GDPR. For more information about Google's use of data, settings, and options for objection, please refer to Google's privacy policy and the settings for the display of advertisements by Google.

Your consent covers the transfer of data to the USA in accordance with Art. 49 (1) (a) in conjunction with Art. 6 (1) (a) GDPR, which does not have a level of data protection that complies with EU standards. If the service provider supports this, we will work towards the conclusion of standard data protection clauses in accordance with Art. 46 (2) (d) GDPR.

Google Ads and conversion measurement

Google Ads is an online marketing method. We use Google Ads to place ads on the Google advertising network that match your presumed interests in the ads. We also measure the conversion rate of the ads. This gives us an overview of the cost-benefit factor of our advertising campaigns. We can see how many people click on our ad and visit our website. The service collects connection data, data from your web browser, and data about the content accessed. In addition, tracking and recognition software is executed and data is stored on your device. The tracking and recognition software enables the service to recognize you when you visit other websites and to display personalized advertising. We only learn the anonymous total number of users who clicked on our ad and were redirected to a page marked with a so-called “conversion tracking tag.” The data on your device is stored for up to two years. We have no influence on how Google further processes the collected data. The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://ads.google.com/; privacy policy: https://policies.google.com/privacy

You have the option of not participating in conversion tracking. By deactivating cookies via your browser, you block conversion tracking. In this case, you will also not be included in the statistics of the tracking tools.

Google Ad Manager

We use the “Google Marketing Platform” (and services such as “Google Ad Manager”) to place ads on the Google advertising network (e.g., in search results, in videos, on websites, etc.) that may be of interest to you. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Privacy Shield (guarantee of data protection level when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.

DoubleClick (by Google)

Information is collected and evaluated using cookies or pixel tags, or web beacons (= tracking pixels), in order to optimize advertising. For this purpose, we use targeting technologies from Google Inc. (Double Click, Double Click Exchange Buyer, Double Click Bid Manager) Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Privacy Shield (guarantee of data protection level when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.

Matomo

In order to optimize the website in terms of user needs and to document usage frequency, we analyze the usage behavior of visitors to our website (e.g., which content is particularly popular? Which is not?). For this purpose, we use the data-efficient web analysis tool Matomo.

Matomo does not use cookies; returning users are identified using a so-called “digital fingerprint,” which is stored anonymously and changed every 24 hours.

With the “digital fingerprint,” user movements within our online offering are recorded using pseudonymized IP addresses in combination with user browser settings in such a way that it is not possible to draw conclusions about the identity of individual users.

The data collected in the context of using Matomo is not passed on to third parties, except in cases where there is a legal obligation to do so.

The legal basis for processing is our legitimate interests (Art. 6 (1) (f) GDPR) and the obligation to be accountable to our funding provider (Art. 6 (1) (c)).

Google Ads

Google Ads is an online marketing method. We use Google Ads to place ads on the Google advertising network that match your presumed interests in the ads. We also measure the conversion rate of the ads. This allows us to gain an overview of the cost-benefit factor of our advertising campaigns. We can see how many people click on our ad and visit our website. The service collects connection data, data from your web browser, and data about the content accessed. In addition, tracking and recognition software is executed that stores data on your device, enabling the service to recognize you when you visit other websites or to display personalized advertising.

We only learn the anonymous total number of users who clicked on our ad and were redirected to a page marked with a so-called “conversion tracking tag.” We have no influence on how Google further processes the collected data.

We use Google Ads based on our legitimate interests (Art. 6 (1) lit f. GDPR) to effectively advertise our products, measure the effectiveness of our advertising measures, and design our website to meet your needs.

The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://ads.google.com/; privacy policy: https://policies.google.com/privacy.

You have the option of not participating in conversion tracking. By deactivating cookies via your browser, you block conversion tracking. In this case, you will not be included in the statistics of the tracking tools.

Payment service provider

Within the framework of our contractual relationship, based on legal obligations and our legitimate interest, we offer efficient and secure payment methods. These provide us with the technical means to receive immediate payment confirmation. This enables us to deliver goods to you immediately after you place your order. The legal basis for this is: for the performance of the contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR) and our legitimate interests (Art. 6 (1) (f) GDPR).

Stripe

We offer the option of processing payments via the payment service provider Stripe, ℅ Legal Process, 510 Townsend St., San Francisco, CA 94103 (Stripe). The legal basis for this is our legitimate interest in offering an efficient and secure payment method (Art. 6 (1) (f) GDPR). In this context, Stripe receives the following data to the extent necessary for the performance of the contract (Art. 6 (1) (b) GDPR).

Name of the cardholder, email address, customer number, order number, bank details, credit card details, credit card expiry date, credit card verification number (CVC), date and time of the transaction, transaction amount, name of the provider, location.

Without the transfer of your personal data, we cannot process a payment via Stripe.

Information on data subject rights

Data subjects may at any time request information about their personal data and, if necessary, request correction or deletion or restriction of processing, or object to processing. They also have the right to data portability. Furthermore, if data processing is carried out on the basis of consent, this consent may be revoked at any time with future effect. To exercise your rights, please contact our data protection officer at the following address:

datenschutz@dah.aidshilfe.de

Further contact details can be found at: https://www.samhealth.de/en/imprint/

In addition, pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you suspect that the processing of personal data is unlawful.