
Privacy policy
Privacy Policy
With the following data protection information, we, the
Deutsche Aidshilfe e. V.
Wilhelmstr. 138
10963 Berlin
Tel.: 030 - 69 00 87 0
Fax : 030 - 69 00 87 42
Email: dah@aidshilfe.de
as the controller within the meaning of the General Data Protection Regulation (GDPR), which personal data we process when you visit our website and use our online services.
We reserve the right to occasionally update our privacy policy to ensure that it always complies with current legal requirements or to reflect changes to our services.
Data protection officer
All data transfers to our website are carried out via an encrypted connection.
What do we use your personal data for?
Some data is collected to ensure the error-free provision of our website. Data is also processed to enable the smooth processing of orders, consultations, and payment transactions. Specifically:
Website hosting
Hosting via Digital Ocean LLC
This website is hosted on the cloud platform of Digital Ocean LLC, 106 6th Avenue, New York, USA. The legal basis for this is our legitimate interest in the error-free provision of our online services.
The server location is a certified data center in Germany. We have concluded a data processing agreement with Digital Ocean. This can be viewed publicly at: https://www.digitalocean.com/legal/privacy-policy. Digital Ocean participates in the EU-US Data Privacy Framework, which regulates the secure transfer of data from EU citizens to the USA. Data transfer to the US is also based on the EU standard contractual clauses. You can find out more about data processing at Digital Ocean here: https://www.digitalocean.com/legal?tid=135694281
Logging and creation of log files
When you visit our website, a range of technical data is logged. This general data and information is stored in the server's log files. Your IP address, browser ID and domain, the name of the file accessed, the date and time of access, the amount of data transferred and the successful access are recorded in a log file. The processing of personal data is carried out for the purpose of providing the website and for troubleshooting on the basis of a legitimate interest pursuant to Art. 6 (1) (f) GDPR. The log files are deleted after 30 days.
Contact
Registration/customer account
When you create an account with us via our online shop, we store your data in accordance with the information you provide during registration and when placing an order. When you open a customer account, we also store your user data (username, password). At the same time, we store your IP address and the date and time of your registration for tracking purposes in the event of misuse, based on our legitimate interest pursuant to Art. 6 (1) (f) GDPR.
The data collected will be deleted as soon as processing is no longer necessary. However, we must comply with tax and commercial law retention periods.
When you contact us, personal data is collected. This data is stored and used for the purpose of responding to your request or for establishing contact and the associated technical administration.
The collected data is processed for the purpose of responding to contact requests and for communication. For the fulfillment of the contract and in the case of pre-contractual inquiries on the basis of Art. 6 (1) (b) GDPR, or on the basis of our legitimate interest pursuant to Art. 6 (1) (f) GDPR. Your data will be deleted after your inquiry has been processed, provided that there are no legal retention obligations to the contrary.
Transfer of data
Our service includes advice from employees at the so-called checkpoints. The legal basis is Art. 6 (1) (b) GDPR, insofar as the transfer is necessary for the performance of the contract. If you provide us with health data in order to use our services, we will process this data in accordance with the legal requirements (Art. 9 (1) GDPR) exclusively on the basis of your consent. We have taken technical and organizational measures to ensure that your health data can only be accessed by authorized persons who need this data to provide our services.
Data transfer upon conclusion of a contract for services and digital content
We only transfer personal data to third parties if this is necessary for the execution of the contract, for example to checkpoints or the credit institution responsible for payment processing, or when handing over to a shipping company or a direct mailer.
The basis for data processing is Art. 6 (1) lit. b GDPR, fulfillment of a contract or pre-contractual measures.
Other data transfers to third parties
Selected data is forwarded to funding institutions (e.g., BiÖG) for the purpose of applying for and accounting for grants in accordance with Art. 6 (1) lit. c GDPR in conjunction with § 44 BHO.
Cookies
We only use technically necessary cookies on our website to provide our services and ensure the functionality of our shop system.
Matomo/Umami
In order to optimize the website in line with user needs and to document usage frequency, we analyze the usage behavior of visitors to our website (e.g., which content is particularly popular? which is not?). To do this, we use the data-saving web analysis tools Matomo and Umami.
Neither tool uses cookies; returning users are recognized using a “digital fingerprint” that is stored anonymously and changed every 24 hours.
With “digital fingerprinting,” user movements within our online offering are recorded using pseudonymized IP addresses in combination with user browser settings in such a way that it is not possible to draw conclusions about the identity of individual users.
The data collected in the context of the use of Matomo and Umami is not passed on to third parties, except on the basis of a legal obligation.
The legal basis for processing is our legitimate interest (Art. 6 (1) (f) GDPR) and the obligation to be accountable to our funding body (Art. 6 (1) (c)).
Google Tag Manager
Google Tag Manager is a tool that allows us to manage website tags and thus integrate Google Analytics and other Google marketing services into our online offering. The Tag Manager itself does not create user profiles or store cookies. Google only receives the user's IP address, which is necessary to execute the Google Tag Manager. The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website:https://tagmanager.google.com/; privacy policy: https://policies.google.com/privacy. We would like to point out that, if the service provider supports this, we will work towards concluding agreements on order processing in accordance with Art. 28 GDPR and standard data protection clauses in accordance with Art. 46 (2) lit. d GDPR.
Online marketing with Google tools
We process personal data for online marketing purposes on the basis of your consent in accordance with Art. 6 (1) (a) GDPR and our legitimate interest in efficient, economical, and recipient-friendly services in accordance with Art. 6 (1) (f) GDPR.
Unless otherwise stated, please assume that cookies used will be stored for a period of two years/30 days.
Google Analytics
With your consent in accordance with Art. 6 (1) (a) GDPR, we use Google Analytics, a web analytics service provided by Google Ireland Limited (“Google”).
The cookies set by Google Analytics or comparable technologies collect usage data (e.g., websites visited, access times) and communication data (e.g., IP addresses, device information) are processed on our behalf in order to evaluate the use of our online offering, compile reports on the activities within our online offering, and provide other services related to the use of our online offering. This also allows the creation of pseudonymized user profiles. Google Analytics is used exclusively with IP anonymization. All processed personal data is deleted or completely anonymized after 14 months. We have concluded an agreement with Google for order processing in accordance with Art. 28 GDPR. For more information about Google's use of data, settings, and options for objection, please refer to Google's privacy policy and the settings for the display of advertisements by Google.
Your consent covers the transfer of data to the USA in accordance with Art. 49 (1) (a) in conjunction with Art. 6 (1) (a) GDPR, which does not have a level of data protection that meets EU standards. If the service provider supports this, we will work towards the conclusion of standard data protection clauses in accordance with Art. 46 (2) (d) GDPR.
Google Ads and conversion measurement:
Google Ads is an online marketing method. We use Google Ads to place ads on the Google advertising network that match your presumed interests in the ads. We also measure the conversion of the ads. This gives us an overview of the cost-benefit factor of our advertising campaigns. We can see how many people click on our ad and visit our website. The service collects connection data, data from your web browser, and data about the content accessed. In addition, tracking and recognition software is executed and data is stored on your device. The tracking and recognition software enables the service to recognize you when you visit third-party websites and to display personalized advertising. We only learn the anonymous total number of users who clicked on our ad and were redirected to a page marked with a so-called “conversion tracking tag.” The data on your device is stored for up to two years. We have no influence on how Google further processes the collected data. The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://ads.google.com/; privacy policy: https://policies.google.com/privacy
You have the option of not participating in conversion tracking. By deactivating cookies in your browser, you can block conversion tracking. In this case, you will not be included in the statistics of the tracking tools.
Google Ad Manager:
We use the “Google Marketing Platform” (and services such as “Google Ad Manager”) to place ads on the Google advertising network (e.g., in search results, in videos, on websites, etc.) that may be of interest to you. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Privacy Shield (guarantee of data protection level when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.
DoubleClick (by Google):
Cookies, pixel tags, and web beacons are used to collect and analyze information for the purpose of optimizing advertising. For this purpose, we use targeting technologies from Google Inc. (Double Click, Double Click Exchange Buyer, Double Click Bid Manager) Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Privacy Shield (guarantee of data protection level when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.
Re-Marketing
Google Ads
We use Google Ads to place ads on the Google advertising network that match your presumed interests in the ads. We also measure the conversion rate of the ads. This allows us to gain an overview of the cost-benefit factor of our advertising campaigns. We can see how many people click on our ad and visit our website. The service collects connection data, data from your web browser, and data about the content accessed. In addition, tracking and recognition software is executed that stores data on your device. This enables the service to recognize you when you visit other websites and to display personalized advertising.
We only receive anonymous aggregate data on the number of users who clicked on our ad and were redirected to a page marked with a so-called “conversion tracking tag.” We have no influence on how Google processes the collected data.
We use Google Ads based on our legitimate interest (Art. 6 (1) lit f. GDPR) to effectively advertise our products, measure the effectiveness of our advertising measures, and design our website to meet user needs.
The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://ads.google.com/; privacy policy: https://policies.google.com/privacy.
You have the option of not participating in conversion tracking. By deactivating cookies via your browser, you block conversion tracking. In this case, you will not be included in the statistics of the tracking tools.
Payment service providers
Within the framework of our contractual relationship, based on legal obligations and our legitimate interest, we offer efficient and secure payment methods. These provide us with the technical means to receive immediate payment confirmation. This enables us to deliver goods to you immediately after you place your order. The legal basis for this is the fulfillment of the contract and pre-contractual inquiries (Art. 6 (1) (b) GDPR) and our legitimate interests (Art. 6 (1) (f) GDPR).
Stripe
We enable the payment process to be handled via the payment service provider Stripe, ℅ Legal Process, 510 Townsend St., San Francisco, CA 94103 (Stripe). The legal basis for this is our legitimate interest in offering an efficient and secure payment method (Art. 6 (1) (f) GDPR). In this context, Stripe receives the following data to the extent necessary for the performance of the contract (Art. 6 (1) (b) GDPR).
Cardholder name, email address, customer number, order number, bank details, credit card details, credit card expiration date, credit card verification number (CVC), date and time of transaction, transaction amount, name of provider, location.
Without the transfer of your personal data, we cannot process a payment via Stripe.
Information on data subject rights
Data subjects may at any time request information about their personal data and, if necessary, request correction or deletion or restriction of processing, or object to processing. They also have the right to data portability. Furthermore, if data processing is carried out on the basis of consent, this consent can be revoked at any time for the future. To exercise your rights, please contact our data protection officer at the contact details provided:
datenschutz@dah.aidshilfe.de
Further contact details can be found at: https://www.samhealth.de/impressum/
Furthermore, in accordance with Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you suspect that the processing of personal data is unlawful.
The supervisory authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin.