Data protection declaration for the website of the Federal Association for Materials Management, Purchasing and Logistics (BME)

The Federal Association of Materials Management, Purchasing and Logistics e. V. (BME) (hereinafter referred to as the "Association") appreciates your visit to our website and your interest in our Association and our products. The protection of personal data is important to us. The provision of personal data is voluntary. The BME processes these data in accordance with the provisions of the European General Data Protection Regulations, the German Telemedia Act and the German Data Protection Act.

In the following, we describe which data is processed during your visit on the company's website.

1. Data Controller

Responsible for the processing of your data is the Bundesverband Materialwirtschaft, Einkauf und Logistik e. V. (Federal Association for Materials Management, Purchasing and Logistics). (BME) and its affiliated companies consisting of BME Akademie GmbH, BMEnet GmbH, BME Marketing GmbH and BMÖ GmbH - hereinafter BME Group. Exceptions in this context are explained in this data protection declaration.

Our contact details are as follows:

Bundesverband Materialwirtschaft, Einkauf und Logistik e. V. (BME)
Frankfurter Str. 27
D-65760 Eschborn, Germany
Email: info(at)bme.de.

You will find the contact details of the data protection officer further down in section 23.

2. Personal data

Personal data are individual details about personal or factual circumstances of a specific or identifiable natural person. This includes information such as your IP address, your real name, your address, your telephone number and your date of birth. Information that is not directly associated with your real identity - such as favorite websites or the number of users of a site - is not personal data.

3. Processing of personal data

When you visit the BME website, we temporarily process and store data of various kinds in order to provide our services. This includes the connection data of the requesting computer, the Internet pages that you select from our site as well as the date and duration of the visit. Furthermore, we determine the IP address of the requesting computer, the access date, the identification data of the Internet browser and operating system type used, the file request of the client (file name and URL), the HTTP response code, the website from which you are visiting us and the number of bytes transferred during the connection. These data are deleted after the end of the respective Internet session. Additional personal data such as your name, address, telephone number or e-mail address will only be collected if you have given your consent, e.g. as part of an online order for a product or service, a survey, an information request or a competition. If you are a subscriber to one of our e-mail newsletters, we as the website operator ensure that your e-mail address is not passed on to the URL. Your e-mail address will also not be passed on to our service providers.

4. Earmarked use and forwarding of personal data

BME uses the personal data you provide for the purposes of technical administration of the website, for services, for customer and member administration, for product-related surveys and for marketing only to the extent necessary in each case.

5. Legal basis for data processing

The legal basis for processing your personal data depends on the underlying purpose of the data processing.

5.1 Technical administration of the website

The legal basis for the processing of personal data for the above-mentioned purpose is Art. 6 para. 1 lit. b) GDPR, insofar as a contractual relationship exists with you. If there is no contractual relationship between the association and you, the legal basis for data processing is Art. 6 para. 1 lit. f) GDPR. The transmission of personal data (e.g. the IP address) is necessary to establish the connection and to display the contents of the website.

5.2 Services and event bookings

The legal basis for the processing of personal data for the above-mentioned purpose is Art. 6 para. 1 lit. b) GDPR. We provide our services and events within the framework of the fulfilment of contractual obligations. Without the processing of personal data, we cannot fulfil or execute the existing contract with you.

5.3 Google Analytics und Matomo

The legal basis for the processing of personal data in the context of the use of Google Analytics and Matomo is Art. 6 para. 1 lit. f) GDPR. We need statistical information about the use of our online offer in order to make it more user-friendly, to make range measurements and to conduct market research.

5.4 Online orders

When you place an online order on our website, we collect various data required to conclude the contract. The legal basis is the conclusion and implementation of a contract in accordance with Art. 6 para. 1 sentence 1 b GDPR. The data will be stored for the duration of the contract.

5.5 BME Webinars

When you register for a BME webinar, we collect certain data to enable you to participate in the webinar. The legal basis for the processing is your consent pursuant to Art. 6 para. 1 sentence 1 a GDPR. We store the data for this purpose until the webinar has taken place. We use order data processor to collect the registration and host the webinar, which are recipients of your personal data accordingly.

In addition, we use the data you enter for marketing purposes as described, which is hereby included as a reference.

5.6 Data processing for general advertising purposes

We process personal data of our customers as well as other entrepreneurs and companies not in a business relationship with us, and in this connection, where appropriate, also from the contact persons there for the purpose of direct advertising, insofar as legally permissible. If we have not collected this data directly from the respective data subject, we may also obtain contact data of the data subject from public sources, such as in particular the website of the respective company, trade directories or advertisements placed by the company. In connection with these direct advertising purposes we can also take into account the previous contracts concluded by our members, customers and company specifics such as sector affiliation or company size of the respective entrepreneur/company in order to design the advertising as appropriately as possible. The legal basis is a legitimate interest within the meaning of Art. 6 para. 1 sentence 1 f GDPR. The legitimate interest is the processing of personal data for the purpose of direct marketing itself (see recital 47 GDPR). The data subjects have the right to object at any time to the processing of personal data concerning them for the purpose of such advertising. You can file this objection any time using the contact data specified in section 23, in the case of advertisement by e-mail you find an Opt Out link also directly in the respective e-mail. We store the data for this purpose as long as we are interested in concluding a contract with the company concerned or until an objection has been declared.

5.7 Advertising displays by an commissioned service provider / online marketer Business Advertising GmbH (businessAD), Tersteegentrasse 30, D-40474 Düsseldorf, Germany

The collection of your data by our advertising service provider takes place for the provision, improvement and development of the advertising displays, is based on legitimate interest for refinancing our content and is GDPR-compliant.

6. Information disclosure

Your personal data will not be passed on to third parties unless this is necessary for the purpose of contract processing or you have expressly consented. Your personal data will only be passed on within the BME Group with your consent. If we commission external service providers, they are carefully selected and obliged to comply with all data protection regulations in accordance with Article 28 GDPR.

7. Registration feature

We offer you the possibility to register on our site. The data entered in the course of this registration process, which can be seen from the input mask of the registration form, will be collected and stored exclusively for the use of our offer. When you register on our site, we will also store your IP address, the date and time of your registration and your last login. In the event that a third party misuses your data and registers on our site with this data without your knowledge, this serves as a safeguard on our part.  The data will not be passed on to third parties. A cross-referencing of the data collected in this way with data that may be collected by other components of our site does not take place either.

8. Newsletter

If you would like to subscribe to the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter (double opt-in procedure). In order to personalize the newsletter, we store personal data such as first name, surname and e-mail address. We use this data exclusively for the dispatch of the requested information and for the documentation of your consent. You can revoke your consent to the storage of the data, the e-mail address as well as their use for sending the newsletter at any time and with effect for the future, for example via the "unsubscribe" link in the newsletter. We use an external service provider to manage and send our newsletter. This service provider has of course been carefully selected and obliged to comply with all data protection regulations in accordance with Article 28 of the GDPR.

9. Use of cookies

In order to make our website as user-friendly as possible, we - like many well-known companies - use so-called cookies. Cookies are small text files that are stored on your computer when you visit our website. This allows us to design our website more individually for the user. This means you do not have to log in to a service every time and we can adapt the offers on our web portal to your interests. You can agree to the use of these cookies on our site.

We use cookies to analyze the use of our website and to provide you with interesting information. Most of the cookies we use are so-called "session cookies", which are deleted when you end your browser session. Of course, you can also use our offers without cookies. Browsers can be set so that cookies are generally rejected. You can also delete cookies already set in your browser settings. However, if you do not use cookies, you may not be able to use the full functionality of our website.

Users of our website use different browsers and different computers. To make your visit as pleasant as possible with the technology you use, we collect information about the browser type (e.g. Chrome, Internet Explorer, Mozilla, Netscape) and its operating system (e.g. Windows or Mac) used by a visitor, the domain name of his/her Internet provider and the width and height of the browser window, screen resolution and color depth.

Information and objection:

For more information about the use of cookies and how to disable them, see: meine-cookies.org oder youronlinechoices.com.

10. Statistical evaluation

We need statistical information about the use of our online offer in order to make it more user-friendly, to make range measurements and to conduct market research. For this purpose we use the web analysis tools described in this section.

10.1 Google Analytics

Google Analytics is provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). This analysis software is configured in accordance with data protection regulations. In particular, we use Google Analytics with the additional function offered by Google for anonymizing IP addresses. Google's IP address is usually already shortened within the EU and only in exceptional cases only in the U.S. and in any case only stored in shortened form.

You can object to the collection and/or evaluation of your data by this tool by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de

10.2 Use of Matomo

Data is collected and stored on this website using the web analysis service software Matomo (www.matomo.org), a service of InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand, ("Matomo") on the basis of our legitimate interest in statistical analysis of user behavior for optimization and marketing purposes pursuant to Art. 6 para. 1 lit. f) GDPR. Pseudonymised user profiles can be created and evaluated from this data for the same purpose. Cookies may be used for this purpose. The cookies enable, among other things, the recognition of the Internet browser. The data collected with Matomo technology (including your pseudonymized IP address) is processed on our servers. The information generated by the cookie in the pseudonymous user profile is not used to personally identify the visitor to this website and is not combined with personal data about the bearer of the pseudonym.

If you do not agree to the storage and evaluation of this data from your visit, then you can object to the subsequent storage and use at any time by mouse click. In this case, a so-called opt-out cookie is stored in your browser, which means that Matomo does not collect any session data. Please note that the complete deletion of your cookies means that the opt-out cookie will also be deleted and may have to be activated again by you.

Privacy policy

With the following information we would like to give you as a visitor of our online offer an overview about the processing of your personal data by us and about your rights from the data protection law. Which data is processed in detail and how it is used depends largely on the agreed services. Therefore, not all parts of this information will apply to you.

 

1. Responsible body and contact details of the data protection officer

Responsible is

Bundesverband Materialwirtschaft, Einkauf und Logistik e. V. (BME)

Frankfurter Straße 27

65760 Eschborn

Tel. +49 6196 5828-0

Fax +49 6196 5828-199

E-Mail: info(at)bme.de

 

(hereinafter referred to as the Association )

You can reach our external data protection officer by e-mail: datenschutz@bme.de or by telephone: 06196 - 5828 - 252.

 

2.  Processing of personal data in connection with your use of our websites, applications and online platforms

 

a.  Categories of data, purpose of processing and legal basis 

 

In the course of your use of the Association's website, applications or online tools (hereinafter collectively "Online Offerings"), we process the following personal data:

·       Personal data that you yourself enter voluntarily in the context of an online offer (such as during registration, requests to contact you or in the context of participation in surveys, etc.), such as first and last name, e-mail address, telephone number, information provided in the context of a support request, comments or forum posts and

·       Information that is automatically sent to us by your web browser or terminal device, such as your IP address, device type, browser type, previously visited web pages, sub-pages visited or the date and time of each visitor request.

 

We process your personal data for the following purposes: 

·       to enable you to use the services and functions of the online offers,

·       to process your request,

·       to establish your identity and enable user authentication,

·       to send you marketing information or contact you as part of customer satisfaction surveys, as described below,

·       to enforce our Terms of Use, to assert or defend against legal claims, and to deter and prevent fraudulent and similar activity, including attacks on our IT infrastructure; and

·       to assess your creditworthiness.

 

The processing of personal data is necessary to achieve the stated purposes. Unless explicitly stated otherwise when collecting personal data, the legal basis for data processing is:

·       The execution and fulfillment of a contract with you according to Art. 6 para. 1 lit. b GDPR,

·       the fulfillment of legal obligations to which the association is subject in accordance with Art. 6 para. 1 lit. c GDPR, or

·       the protection of legitimate interests according to Art. 6 para. 1 lit. f GDPR. The legitimate interest of the association lies in the processing of your personal data for the purpose of offering and operating the online services.

 

In some cases, we explicitly ask for your consent to the processing of your personal data. In this case, the legal basis for the processing of your personal data is the consent given by you in accordance with Art. 6 para. 1 lit. a GDPR.

 

b. Cookies

 

Cookies are small text files that are automatically created by your browser and stored on your mobile device when you visit the website. Cookies contain information that results in each case in connection with the context of use and your terminal device.

Depending on the type, the use of cookies is possible without consent and subject to consent. Cookies that do not require consent are in particular those that are necessary in order to use our online services or that serve IT security purposes. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR.

On the other hand, cookies that require your consent serve on the one hand to adapt the use of our offer individually to your preferences. You give your consent to this when you call up our online offer by displaying our "cookie banner". Here you can declare your consent to the use of cookies on this website by clicking a button.

For example, we use cookies to recognize that you have already visited our online offer. In addition, we also use temporary cookies for the purpose of user-friendliness, which are stored on your end device for a certain fixed period of time. If you visit our site again, the circumstance of your visit as well as your entries will be automatically recognized and completed if necessary.

You can change or withdraw your consent at any time from the cookie statement on our website.

The following cookies are used by us:

(1) Necessary cookies

Necessary cookies are essential for the use of website services by enabling basic functions such as page navigation and access to secure areas of the website. The website usually does not function properly without setting necessary cookies. Furthermore, necessary cookies are those that serve IT security.

 

(2) Preference cookies

Preference cookies allow you to store website preferences that are not associated with a permanent website identifier such as a username. As a rule, such cookies contain information about language settings or the display of search results.

 

(3) Marketing and statistics cookies

Marketing and statistics cookies are used for behavioural advertising. These include, in particular, cookies for the purpose of frequency capping or affiliate marketing. This also includes analysis or statistics cookies (which are partially differentiated in other representations), which are used to determine the number of individual visitors or the respective usage behaviour on the respective website. Marketing cookies are set when users follow links to websites in order to track click-through behavior.

 

 (4) Third party cookies

These cookies are set by third parties, e.g. social networks such as Facebook, Twitter and Google+, whose content you can integrate via the "social plug-ins" offered on the websites.

 

c. Session cookies

 

 

 

In the context of the notification of a personal data breach, so-called session cookies are used in particular. Session cookies are text files that are stored by the Internet browser on your computer system. When the website is accessed, a session cookie is stored on your operating system. This session cookie enables the browser to be identified when the website is called up again. In the session cookies, an identifier is stored and transmitted to identify your session.

The purpose of using these technically necessary session cookies is to enable the use of the website. This is because it is necessary that the browser is recognized even after a page change. The user data collected by the session cookies are not used to create user profiles.

 

d. Google Analytics

 

 

 

This website uses functions of the web analysis service "Google Analytics". The provider is Google Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.

Google Analytics uses so-called cookies. These are text files which are stored on your computer and which enable an analysis use of the website by you. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.

The storage of Google Analytics cookies is based on Art. 6 para. 1 lit. a GDPR. We obtain the necessary consent from our users immediately after they access our website.

(i)      IP anonymization

We have activated the IP anonymization function on this website. This means that your IP address is shortened by Google within the states of the European Union or other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser within the scope of Google Analytics will not be merged with other Google data.

 

(i)      Browser plug-in

You can prevent the storage of cookies by selecting the appropriate settings in your browser software. However, we would like to point out that in this case you may not be able to use all the functions of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google, by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

 

(i)      Objection to data collection

You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this website:  DisableGoogle Analytics.

For more information on how Google Analytics handles user data, please see Google's privacy policy at the following link: https://support.google.com/analytics/answer/6004245?hl=de.

 

e.  Matomo

 

 

 

This website uses the web analysis service software Matomo (www.matomo.org). The provider is InnoCraft Ltd, 150 Willis St, 6011 Wellington, New Zealand.

The service is used to analyse user behaviour and for optimisation and marketing purposes. Cookies can be used for this purpose. The cookies enable, among other things, the recognition of the Internet browser. The data collected using Matomo technology (including your pseudonymised IP address) is processed on our servers. The information in the pseudonymous user profile is not used to personally identify the visitor to this website; it is not merged with personal data about the bearer of the pseudonym.

The legal basis for the processing of personal data using cookies is based on Art. 6 para. 1 lit. a GDPR. We obtain the necessary consent from our users immediately after they access our website.

You can object to the collection of your data and prevent the collection of data by Matomo by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this website:  DisableMatomo.

For more information on how Matomo handles user data, please see Matomo's privacy policy at the following link

 

 

 

 

f. etracker 

 

This website uses the software tool etracker (https://www.etracker.com/) for web analysis. Provider is etracker GmbH, Erste Brunnenstraße 1, 20459 Hamburg, Germany.

The etracker component serves to optimise the website and is used to analyse visitor flows and the cost-benefit analysis of Internet advertising. Among other things, data is collected about the website from which a data subject has accessed a website (so-called referrer), which sub-pages of the website have been accessed or how often and for how long a sub-page has been viewed. Cookies are used for this purpose. The setting of the cookie enables us to analyse the use of our website. Each time one of the individual pages of this website is called up, the Internet browser on the information technology system of the data subject is automatically caused by the etracker component to transmit data to our server for the purpose of online analysis. Within the scope of this technical procedure, we obtain knowledge of personal data, such as the IP address of the person concerned. The access time, the location from which an access originated and the frequency of visits to our website are stored. Each time you visit our website, this personal data, including the IP address of the Internet connection used by the person concerned, is transmitted to our server. The controller uses the data and information obtained, among other things, to evaluate the use of this website in order to compile online reports showing the activities on our websites. We do not pass on personal data to third parties.

The legal basis for the processing of personal data using cookies is based on Art. 6 para. 1 lit. a GDPR. We obtain the necessary consent from our users immediately after they access our website.

You can object to the collection of your data and prevent the collection of data by etracker by clicking on the following link. An opt-out cookie will be set to prevent the collection of your data during future visits to this website: deactivateetracker.

You can find more information on the handling of user data at etracker in etracker's privacy policy under the following link.

 

g. GoAccess

 

This website uses the web server analysis tool GoAccess (https://goaccess.io/).

The service is used for real-time analysis of web traffic. GoAccess provides statistics for system administrators who need a visual server report during operation to evaluate non-personal access. Cookies are used for this purpose, which enable an analysis of the use of the website. The information thus generated is transferred to our server and stored there. The data collected is anonymous and there is no profiling.

 

h. Vimeo

 

Provider: Vimeo Inc., Legal Department, 555 West 18th Street New York, New York 10011, USA

Privacy Policy https://vimeo.com/privacy

Opt-Out: We point out that Vimeo may use Google Analytics and refer to the privacy policy (https://policies.google.com/privacy) and the opt-out options for Google Analytics (http://tools.google.com/dlpage/gaoptout?hl=de) or the settings of Google for the use of data for marketing purposes (https://adssettings.google.com/).

i. BusinessAD

 

Marketing of online advertising space, analysis and personalisation of your use of BO and use of external content

We use technology on our site for online advertising marketing, content analysis, market research, personalization of your use of BO, and integration of external content. These technologies, such as cookies, either store data on your terminal device or access such data on your terminal device - in each case, of course, only with your express consent.

Cookies that have already been set can also be deleted by you at any time using an Internet browser or other software programs. This is possible in all common Internet browsers. Please note that in this case, the privacy settings you have made will also be deleted and would have to be made again when you visit our website again. The duration of the cookies used is limited to a maximum of one year, unless otherwise stated.

In the following, we would first like to inform you in general terms about the processing of data in connection with these purposes and then also explain in more detail what we mean by the terms we use in the privacy settings.

Marketing of online advertising space

To enable us to offer you BO's services free of charge, we market advertising space on our website - such as the space around our editorial offers or space between the editorial offers - to advertising companies.

The more specifically the advertising is adapted to the user visiting the page and is geared to his interests, the better we can finance our offer. In order to achieve such an orientation, we use a so-called advertising marketer, in our case Business Advertising GmbH (BusinessAD), which mediates our advertising spaces (possibly with the help of other service providers) to advertising companies. For more information on Business Ad, please visit https://www.businessad.de/nutzungsbasierte-werbung-oba.

The list of current vendors can be found here: http://businessad.de/tracking

Please send any queries regarding the businessAD vendor list to:  adm(at)businessad.de

In order to be able to target a group, our advertising marketer or the other service providers must have the necessary information about the respective users. Personal data is therefore processed by us, the advertising marketer or the other service providers. However, this is not data that allows an actual conclusion to be drawn about your civil identity, i.e. in particular your name, address or similar directly identifying data, but rather data processed pseudonymously - i.e. under a randomly assigned ID. This information is either collected on BO directly, but also collected from other sites you have visited. The marketing of advertising space also includes measuring the success and use of the advertisements.

In the following sections, we describe the specific purposes and the legal bases on which we base the processing. You will also find the same division in our privacy settings

Selection of simple displays

For the purpose and in the interest of optimizing the selection and playout of the ads played out to refinance our offer, to control the frequency and order of the ad insertions and to prevent an ad from being displayed in an unsuitable editorial environment (brand-unsafe), we or third parties process real-time information about the context in which the ad is displayed, including information about the content environment as well as the device used, such as device type and functions, browser ID, URL, IP address and the approximate location data of a user.

Personalized ad profile

Subject to your consent, we use services for the purpose of aligning the advertisements played to refinance our offer with your interests on the basis of your usage behaviour. For this purpose, a profile of your usage is created with information about your activities, interests, visits to websites or use of applications, demographic information or location.

Selection of personalized ads

Subject to your consent, we use services for the purpose of playing ads of interest to you based on the personalized ad profile just described.

Measurement of the display performance

Subject to your consent, we use services for the purpose of measuring ad performance. These services measure, among other things, whether and how ads were displayed to a user and how the user interacted with them, whether an ad is displayed in an inappropriate editorial environment (brand-unsafe), and determine the percentage of time the ad could have been noticed, including the duration (ad perception chance). They also generate reports on ads, including their effectiveness and performance, on how users interact with ads, using data measured during the course of the user's interaction with that ad.

Personalization of content, content measurement, market research and integration of external content

In addition to advertising marketing, we also use technologies with your consent to personalize content, measure content, conduct market research or integrate external content.

In the following sections, we describe the specific purposes and the legal bases on which we base the processing. You will also find the same division in our privacy settings as a setting option:

Personalized content profile

For the purpose of, and in our legitimate interest in, tailoring the selection of content in our Offerings to your usage patterns and, consequently, your presumed interests, we profile your usage with information about your activities, interests and visits to websites or use of applications, demographic information or location.

Personalized content

For the purpose and in our legitimate interest to make our offer more interesting for you, we process information about your usage behaviour or other historical usage data, including previous activities, interests, visits to websites or use of applications, location or demographic information, in order to be able to serve you selected content according to this information.

Contents Measurement

Subject to your consent, we use services for the purpose of measuring the performance of content on our site. This involves measuring and reporting on how content is delivered to users and how they have interacted with it.

Market research (knowledge about target groups)

Subject to your consent, we use services for the purpose of gaining insights about audiences for advertising and content. This involves the production of aggregated reports for advertisers or their representatives on the target groups reached by their advertisements, obtained on the basis of survey panels or similar methods.

Aggregate reports are also generated for service providers on the audiences reached or interacted with by the content and/or ads on their services, as determined by survey panels or similar methods. The reports do not allow any conclusions to be drawn about a specific or identifiable person. However, information about your usage behavior is processed to create these reports. In addition, offline data is associated with an online user for market research purposes in order to gain insights into target groups, insofar as providers have declared that they will match and merge offline data sources.

Product development and improvement

Subject to your consent, we use services for the purpose of developing and improving products, e.g. by adding new features. For this purpose, information about your usage behavior is processed.

Third-party integration / social networks

For the purpose of displaying external content and enhancing the user experience in our offer, we also embed services of third-party providers, each of which is an independent data controller. Subject to your consent, your browser establishes a direct connection to the server of the respective third-party provider. In doing so, the third-party provider always processes your IP address, which is required to establish the connection to the third-party provider's server and to play out the content.

Legal basis for data processing, third party providers and revocation

The legal basis for the aforementioned data processing is Art. 6 para. 1 lit. a and f) GDPR, whereby the legitimate interest which we pursue with the processing lies in the purposes pursued.

For the aforementioned purposes, we also use services of third-party providers who are independent data controllers for the data processing that takes place via the service. Further information on data processing by these third-party providers and your rights as a data subject can be found via the privacy statements of the providers stored in the privacy settings.

You can revoke your consent, as well as the creation of personalized content profiles, at any time with effect for the future in your privacy settings.

Privacy settings

 

j. Online behavioral advertising 

 

This website uses a service of the advertising marketer businessAD(www.businessad.de) for displaying usage-based advertising. The following companies used by businessAD and/or Ströer Digital Group are responsible for data collection for the delivery of usage-based online advertising: ADTECH, AppNexus, The ADEX, Emetriq GmbH, nugg.ad GmbH, Ströer SSP (together "businessAD").

In doing so, businessAD sets a cookie on your end device, in which your interests (e.g. clicked advertising banners, visited subpages etc.) are stored. This data is used for the purpose of displaying content and advertising that matches your interests. Under no circumstances will personal data such as name, address, email address or IP address be stored in the cookies. The use of businessAD serves the analysis, optimisation and economic operation and security of the online offer, in particular with regard to range measurement, the creation of profiles for advertising and marketing purposes as well as the collection of access data and the use of third-party services.

The legal basis for the processing of personal data using cookies is based on Art. 6 para. 1 lit. a GDPR. We obtain the necessary consent from our users immediately after they access our website.

If you no longer wish to receive usage-based advertisements from businessAD, you can object and deactivate the data collection on the following links: ADTECH, AppNexus, TheADEX, Emetriq GmbH, nugg.ad GmbH, Ströer SSP.       

 Auf den Webseiten http://meine-cookies.org, http://optout.networkadvertising.org/, http://optout.networkadvertising.org/, http://www.aboutads.info/choices und http://optout.networkadvertising.org/ können Sie weitere Informationen zu Cookies, die der Reichweitenmessung und Werbezwecken dienen, und den einzelnen Anbietern nachlesen. There you also have the option to object to usage-based online advertising by individual companies or by all companies.

For more information about the use of third-party companies and businessAD's privacy practices, please visitwww.businessad.de/datenschutz. 

k. Recommendation and personalization system from Taboola Europe Ltd.

 

This website uses the service of Taboola (https://www.toboola.com/). The provider is Taboola, 16 Madison Square West, 10010 New York, USA. 

Taboola's service makes it possible to provide user-specific recommendations for content and advertisements based on surfing behavior and customer interests in order to improve the user-friendliness of our offering. The usage profiles are created using pseudonyms, they are not merged with the data about the bearer of the pseudonym and do not allow any conclusions to be drawn about personal data. Taboola collects the following information about the user's operating system by means of cookies: Web pages/content accessed on our web pages, referrer/link through which the user came to our website, time and number of website visits, visits to error pages, location information (city and state) and IP addresses in shortened form.

The legal basis for the processing of personal data using cookies is based on Art. 6 para. 1 lit. a GDPR. We obtain the necessary consent from our users immediately after they access our website.

You can object to the collection of your data and prevent the collection of data by taboola by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this website: disable taboola.

More information about the handling of user data at taboola can be found in taboola's privacy policy under the following link. There you can deactivate tracking at any time in the "User choices" section. Once you have opted out, no more personalised content/advertising will be played to you.

 

l. 123Formbuilder

 

For all forms on our website, we use 123FormBuilder from 123 FormBuilder, Flavia Palace, Vladimirescu n° 10, Ground Floor 300195, Timisoara, Romania, EU, https://www.123formbuilder.com/de/within the framework of our legitimate interest in a technically flawless online offering and its economically efficient design and optimization pursuant to Art. 6 para. 1 lit. f) GDPR.

123 FormBuilder receives and collects all data you enter in our forms, including usage data. Before using any form, you must first give your consent to the processing of your data within the framework of this declaration; in this respect, we refer to our general presentation on contact forms.

For more information about 123 FormBuilder's data processing practices, please see 123 FormBuilder's privacy policy at

https://www.123formbuilder.com/de/datenschutzrichtlinie/

https://www.123formbuilder.com/de/termsofservice.html.

We have entered into a contract with 123 FormBuilder under which they process the data only on our behalf.

 

m. Newsletter

 

If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter (double opt-in procedure). For the personalization of the newsletter we store personal data e.g. first name, last name and company. We use this data exclusively for sending the requested information and for documenting your consent. You can revoke your consent to the storage of data, the e-mail address and their use for sending the newsletter at any time and with effect for the future, for example via the "unsubscribe" link in the newsletter.

We use an external service provider to manage and send our newsletter. Of course, he was carefully selected and obliged to comply with all data protection regulations in accordance with Art. 28 GDPR]

 

n. Contact

 

Contact forms are available on our website, which can be used for electronic contact. If a user makes use of these options, the data entered in the input mask is transmitted to us and part of the data is stored.

The processing of the personal data from the input mask serves us for the treatment of the establishment of contact and for the prevention of the abuse of the contact form.

The legal basis for the processing of the data is Art. 6 para. 1 lit. f GDPR.


The user has the possibility to object to the processing of his personal data at any time. In such a case, the correspondence cannot be continued. Please send us your deletion request via e-mail to info(at)bme.de. All personal data stored in the course of contacting us will be deleted in this case.

 

o. Registration 

 

We offer you the possibility to register on our website. From the input mask of the registration form you can see the mandatory fields which are marked with "*"; all other information is voluntary. The data entered in the course of this registration will be collected and stored exclusively for the use of our offer. When you register on our site, your IP address and the date and time of your registration and last login are also stored.

The processing of personal data from the input mask serves to prevent the misuse of your data. The legal basis for the processing of the data is Art. 6 para. 1 lit. f GDPR.

 

p. BME Webinars 

 

We offer the possibility for you to participate in our BME webinars. You can register for this on our website. When you register, we collect the personal data specified in the input mask. The fields marked with "*" are mandatory; all other fields are optional. The purpose of the data processing is to enable you to participate in the webinar. We also use the information you provide for marketing purposes.

The legal basis for the processing is your consent in accordance with Art. 6 para. 1 Sentence 1 a GDPR. You have the right to object to the use of your data for these purposes at any time by sending an e-mail to info@bme.de or by making use of the objection option in the message you received. 

We use external service providers to manage and send our newsletter in order to host the webinar. They were of course carefully selected and, in accordance with Art. 28 GDPR, obliged to comply with all data protection regulations.

 

q. Raffle

 

Occasionally, there are sweepstakes offered on the website. We process and store your personal data, which you have provided when entering a competition, for the purpose of conducting the competition. In this case, the respective conditions of participation and data protection declaration of the competition apply, which will be pointed out to you separately in the context of the respective competition.

 

r. Links to other websites and to our social media pages

 

This data protection declaration only applies to our online offers and not to websites and applications of third parties. Our online offers may contain links to websites and applications of third parties that may be of interest to you. We are not responsible for the collection, processing and use of your data within the framework of websites or applications that are not operated by us, or for their content.

We use links to the social networks Facebook, LikedIn, Xing, YouTube and Twitter on our website on the basis of Art. 6 para. 1 sentence 1 lit. f GDPR in order to draw attention to our services and products and to contact you as a visitor and user of these social media sites and our website. We have no influence on the processing of your personal data when visiting the social media sites. The provider of the social network has control over the data processing in the context of the use of the respective service. This includes, for example, the storage and use of cookies on user devices and the analysis of your behavior on the social network.

You can recognize the references ("links") by the logo of the respective social network. When you click on the logo, a direct connection is established between your browser and the server of the respective service and you are redirected to the website of the service provider.

For more information about data processing on social media sites, please refer to the privacy policy of the relevant social network:

·    Facebook:    https://www.facebook.com/privacy/explanation

·    Xing:            https://privacy.xing.com/de/datenschutzerklaerung

·    LinkedIn:      https://www.linkedin.com/legal/privacy-policy

·    YouTube:      https://policies.google.com/privacy?hl=de&gl=de

·    Twitter:         https://twitter.com/de/privacy

 

s. Facebook fan page

 

We maintain a so-called "Facebook fan page"(www.facebook.com/pg/BMEeV/about/?ref=page_internal) in order to communicate with customers and interested parties there and to inform them about our services and activities.  On our website we provide links to this fan page for this purpose. We have no influence on the type and extent of processing by Facebook. This applies in particular to the use of interactive functions (e.g. sharing, rating). Nor are there any effective means of control in this respect. When you access the platform, Facebook's terms and conditions and data processing policies apply. We would like to point out that you use the services and their functions on your own responsibility.When you visit our Facebook fan page, Facebook collects your IP address in particular, as well as other information that may be present on your PC in the form of cookies. This information is used to provide us, as the owner of the Facebook fan page, with statistical information about the use of the Facebook page.

 

The data collected about you in this context will be processed by Facebook and may be transferred outside the European Union. We point out that Facebook is responsible under data protection law for corresponding transmission and subsequent processing operations. What specific data Facebook receives and how it is used is described in general terms in Facebook's privacy policy. For more information, please see Facebook's privacy policy:

http://de-de.facebook.com/about/privacy

In addition, Facebook provides us with so-called page insights data. We are jointly responsible with Facebook for this data processing. Page Insights data are anonymous statistics that help us evaluate the quality of our Facebook page and content. These statistics are created based on usage data that Facebook collects about your interaction with our Facebook page; we do not have access to this usage data. Facebook has made a commitment to us to take primary responsibility for the processing of Page Insights Data and for fulfilling your rights under the EU General Data Protection Regulation and to provide you with the essence of the agreement that applies to this. For more information on page insights, click the linkbelow.

 

 

11. Usage-Based Advertising - Online Behavioural Advertising (OBA)

When you visit these Internet pages, your interests (e.g. clicked advertising banners, visited subpages, etc.) are recorded in a cookie by means of an anonymous user number on behalf of businessAD via Google dfp ad servers. Identified by Google Publisher Tags or Doubleclick. This data is used for the purpose of displaying content and advertising according to your interests and also regulate one advertising playout capped per user (e.g. max. 4 banner insertions per user per month). In no case personal data such as name, address, e-mail address or IP address are stored in the cookies.

Usage-based online advertising is delivered by businessAD and Ströer Digital Group. The following companies used by businessAD and/or Ströer Digital Group are responsible for data collection to deliver usage-based online advertising: ADTECH, AppNexus, The ADEX, Emetriq GmbH, Ströer SSP.

Due to the pseudonymous or anonymous nature of the data, we and the third party companies mentioned do not require separate consent for use-based online advertising (Section 15 Para. 3 Telemedia Act). If you no longer wish to receive usage-based advertisements, you can object on the following links and deactivate data collection:

ADTECH:
http://www.youronlinechoices.com/opt-out-interface

AppNexus:
https://www.appnexus.com/en/company/platform-privacy-policy-de#choices

TheADEX:
http://de.theadex.com/company/consumer-opt-out/

Emetriq GmbH:
https://www.emetriq.com/en/opt-out-eng/

Ströer SSP:
http://ih.adscale.de/adscale-ih/oo

You can read more information about cookies and the individual providers on the websites meine-cookies.org or youronlinechoices.com. There you also have the opportunity to object to usage-based online advertising by individual companies or by all companies. To go directly to the preference manager, please click here: https://www.youronlinechoices.com/de/praferenzmanagement/.

In general, you can prevent cookies from being stored on your hard disk by selecting "do not accept cookies" in your browser settings. You can also set your browser so that it asks you whether you agree before setting cookies. Finally, you can also delete cookies once they have been set at any time. Please refer to your browser manufacturer's instructions to find out how all this works in detail. If you do not accept cookies, this may lead to functional restrictions of the website in individual cases. Please note that if you wish to delete a cookie, you must also activate the opt-out link again.

IP address

On the Internet, every device needs a unique address, the so-called IP address, to transmit data. The at least short-term storage of the IP address is technically necessary due to the functioning of the Internet. We also use your IP address for statutory purposes. The IP addresses are shortened and therefore do not allow any conclusions to be drawn about a natural person.

12. Data protection

Our employees and the service companies commissioned by us are bound to secrecy and compliance with the provisions of the applicable data protection laws. The company takes appropriate technical and organisational security measures to protect your personal data from loss, alteration, destruction and from access by unauthorised persons or unauthorized disclosure. Our security measures are constantly improved in line with technological developments.

13. Duration of data storage

We store your data as long as this is necessary for the provision of our online offer and the associated services or we have a legitimate interest in further storage (e.g. we may still have a legitimate interest in postal marketing even after fulfillment of a contract). The data will be deleted upon expiry of the statutory or contractual retention periods (e.g. tax and commercial retention periods). Data that is not subject to the obligation to retain will be deleted after the described earmarking has ceased to apply.

14. Rights as user

As a user of our website, you have various rights. Please use the information in the Contact section to assert your rights. Please ensure that we can uniquely identify you.

15. Rights to information, correction or deletion of data

In accordance with the General Data Protection Regulation (GDPR), you will receive written information at any time upon request and free of charge about which personal data (e.g. name, address) is stored. Furthermore you have the right to correction or deletion of this data, as far as the legal requirements are fulfilled. Excluded from the claim for deletion are, for example, stored data on business processes that are subject to the legal obligation to retain data.

16. Right to restrict data processing

You have the right to restrict the processing of your personal data.

17. Right of objection

You also have the right to object to our processing of your data at any time. We will then stop processing your data unless we can - in accordance with legal requirements - prove compelling reasons worthy of protection for further processing, which outweigh your rights.

18. Right to data transferability

Furthermore, on request, we guarantee the transferability of the personal data transmitted by you by providing it in a common and machine-readable data format.

19. Revocation of consent

You have the right to revoke your consent for the processing of your personal data at any time with effect for the future, which you have given us for one or more specific purposes. Legitimacy of the processing of your data until revocation remains unaffected by this.

20. Obligation to provide personal data

Insofar as a contract exists between the BME Group and you, you must provide those personal data which are required for the establishment, execution and termination of the contractual relationship and for the fulfillment of the associated contractual obligations or which we are legally obliged to collect. Without the provision of this information, we will generally not be able to enter into, execute and terminate a contract with you.

As far as the data processing within the scope of the use of this website is not necessary for the establishment, execution and termination of a contractual relationship or for the fulfillment of contractual obligations, the provision of your data is voluntary. Please note that certain functionalities of the website or services cannot be used if the necessary data is not provided.

21. Automatic processing of personal data

Your personal data will only be processed exclusively automatically if this is necessary for the conclusion or performance of a contract and this has no legal or similar effect for you.

22. Complaint to supervisory authorities

In the event of complaints regarding the processing of your personal data, you have the right to contact the competent supervisory authorities. You can contact the data protection authority responsible for your place of residence or federal state or the data protection authority responsible for us. This is:

The Hessian Data Protection Commissioner
Gustav-Stresemann-Ring 1
65189 Wiesbaden

23. Contact details

If you have any questions regarding the processing of your personal data, suggestions or complaints, please contact our data protection officer. We recommend that you send confidential information only by post.

Data Protection Officer of the BME:
Patrich Paschke
Franfurter Str. 27
65760 Eschborn, Germany

Email: datenschutz(at)bme.de
Phone: +49 6196 5828 252

The data protection officer of businessAD, Romina Adler, can be reached at datenschutz(at)businessad.de

3. Recipients and categories of recipients

Within our association, access to your data is granted to those offices that need it in order to fulfil our contractual and legal obligations. Service providers and vicarious agents employed by us may also receive data for these purposes, provided that they maintain confidentiality and integrity in particular. These are companies in the categories of IT services, logistics, printing services, telecommunications, debt collection, consulting, and sales and marketing.

With regard to the transfer of data to recipients outside our association, it should first be noted that we only pass on necessary personal data in compliance with the applicable data protection regulations. We may only pass on information about you if this is required by law, you have given your consent or we are authorized to provide information. Under these conditions, recipients of personal data may be:

·     public bodies and institutions (e.g. tax authorities, prosecution authorities, family courts, land registry offices) in the event of a legal or official obligation,

·     credit and financial service institutions or comparable institutions to which we transmit personal data in the course of the business relationship (e.g. banks, credit agencies),

·     other related associations to manage risks arising from legal or regulatory obligations,

·     creditors or insolvency administrators inquiring in the context of a compulsory execution,

·     auditors,

·     service providers that we use within the framework of order processing relationships,

·     trade representatives of the Association.

 

 

4. Transmission to third countries

In the case of data transfer to an entity in a third country, appropriate safeguards for the protection of your personal data will ensure that the level of data protection in the European Union is respected.

“Through the use of our social media offer, the analysis tools (Google Anlalytics, Taboola*) and because of the use of IT service providers**, data transfers and a subsequent processing of usage data of the respective services in the USA may occur. The basis for any processing activities is your explicitly declared declaration of consent, which you have given via the cookie banner. Your declaration of consent justifies such data processing on an exceptional and case-by-case basis in accordance with Art. 49 para. 1 lit. a GDPR. Please note that there is no comparable level of data protection in the USA as in the EU and the EEA. In particular, it is possible that government agencies may access your personal data on the basis of legal authorisations without us or you becoming aware of this. Comparable possibilities to enforce one's own rights do not exist in the USA, so that this does not appear to be promising.

Any data transfers take place exclusively in an automated manner in connection with the use of our offer of social media, the analysis tools and because of the use of IT service providers** and with the help of the use of cookies. You can find out more details about this in this data protection declaration in the sections "Links to other websites and to our social media pages" (clause 2 o.), Facebook fan page (clause 2 p.), Google Anlalytics (clause 2. d.), Taboola (clause 2. I) * and recipients and categories of recipients (clause 3) **.

You can revoke your consent at any time with effect for the future. To do so, please email our Privacy Officer at datenschutz@bme.de and delete the appropriate cookies from your browser."

Please note:

(1) *The tools GoAccess and Online Behavioural Advertising used by you are usually operated by us, so that there is no transfer of data to a third country. If this is not the case for you and the data can be transferred to a third country or the USA, you would have to add this here and in the cookie banner.

(2) **If the integration of the service provider for the newsletter dispatch results in a data transfer to a third country, this would also have to be added to the data protection information and the cookie banner.

 

5.  Storage period 

We process and store your personal data as long as it is necessary for the fulfilment of our contractual obligations and the exercise of our rights.

If the data are no longer required for the fulfillment of contractual or legal obligations, they are regularly deleted, unless their - temporary - further processing is necessary for the following purposes:

·     Fulfillment of storage obligations under commercial and tax law from the German Commercial Code (HGB), the German Fiscal Code (AO) and the German Money Laundering Act (GwG). The periods specified there for storage and documentation are generally two to ten years.

·     Preservation of evidence under the statutory limitation provisions. According to Sections 195 et seq. of the German Civil Code (BGB), these limitation periods can be up to 30 years, with the regular limitation period being 3 years.

 

6.  Data security

Our employees and the service companies commissioned by us are obliged to maintain confidentiality and to comply with the provisions of the applicable data protection laws. To protect your personal data against loss, alteration, destruction and against access by unauthorized persons or against unauthorized disclosure, the association uses appropriate technical and organizational security measures. Our security measures are constantly being improved in line with technological developments.

 

7.  Data subject rights

Every data subject has the right to information according to Art. 15 GDPR, the right to correction according to Art. 16 GDPR, the right to deletion according to Art. 17 GDPR, the right to restriction of processing according to Art. 18 GDPR and the right to data portability according to Art. 20 GDPR.

The restrictions according to Sections 34 and 35 of the German Data Protection Act (BDSG) apply to the right of information and the right of deletion. In addition, there is a right of appeal to a competent data protection supervisory authority (Art. 77 GDPR in conjunction with Section 19 BDSG).

You can revoke your consent to the processing of personal data at any time. This also applies to the revocation of declarations of consent given to us prior to the applicability of the GDPR, i.e. prior to 25 May 2018. Please note that the revocation is only effective for the future. Processing that took place before the revocation is not affected.

You also have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data relating to you which is carried out on the basis of Article 6 para. 1 lit e GDPR (data processing in the public interest) and Article 6 para. 1 f GDPR (data processing on the basis of a balance of interests); this also applies to profiling based on this provision within the meaning of Article 4 para. 4 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights and freedoms. In particular, this includes when the processing is necessary for the assertion, exercise or defence of legal claims.

In addition, you have the right not to be subject to fully automated decision-making in accordance with Art. 22 GDPR. As a matter of principle, we do not use fully automated decision-making for the establishment, implementation and termination of the business relationship. Should we use these procedures in individual cases (e.g. to improve our products and services), we will inform you separately about this and about your rights in this regard, insofar as this is required by law.

For further information and clarification on the above rights, please consult the European Commission's "Rights for Citizens" website.

 

8.  Obligation to provide data

Within the scope of our business relationship, you must provide the personal contractual data that is required for the establishment, implementation and termination of a business relationship and for the fulfillment of the associated contractual obligations, or which we are legally obliged to collect. Without this information, we will generally not be able to enter into, perform or terminate a contract with you.

The same applies to the visit of our online offer and the collection of usage data. Without the collection of usage data, we and our service providers are not able to provide you with our online offer.

 

9. Actuality and changes of this privacy policy 

This privacy policy is currently valid and has the status November 2021.