Privacy
We take data protection seriously
Protecting your privacy when processing personal data is important to us. When you visit our website, our web servers automatically store the IP address of your Internet service provider, the website from which you visit us, the websites you visit on our site, and the date and duration of your visit. This information is essential for the technical transmission of the websites and secure server operation. This data is not evaluated on a personal basis.
If you send us data via the contact form, this data will be stored on our servers as part of data backup. We will use your data exclusively for the purpose of processing your request. Your data will be treated as strictly confidential. It will not be passed on to third parties.
Responsible party:
Leibniz Institute for Immunotherapy
Franz-Josef-Strauß-Allee 11
93053 Regensburg
Tel: 0941 944–38100
Fax: 0941 944–38103
Email info@lit.eu
Personal data
Personal data is data about you as an individual. This includes your name, address, and email address. You do not have to disclose any personal data in order to visit our website. In some cases, we need your name and address as well as other information in order to provide you with the service you require.
The same applies if we send you information material at your request or if we respond to your inquiries. In these cases, we will always inform you accordingly. Furthermore, we only store data that you have provided to us automatically or voluntarily.
When you use one of our services, we generally only collect the data necessary to provide you with our service. We may ask you for further information, but this is voluntary. Whenever we process personal data, we do so in order to provide you with our service or to pursue our commercial objectives.
Contact
When you contact us (e.g., via contact form, email, telephone, or social media), the information provided by the inquiring persons will be processed to the extent necessary to respond to the contact requests and any requested measures.
Responding to contact requests within the framework of contractual or pre-contractual relationships is done to fulfill our contractual obligations or to respond to (pre-)contractual inquiries and, in addition, on the basis of legitimate interests in responding to the inquiries.
Automatically stored data
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
This data is not merged with other data sources. Processing is carried out in accordance with Art. 6 (1) lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website.
For reasons of technical security, in particular to defend against attempts to attack our web server, we store this data for a short period of time. We cannot draw any conclusions about individual persons based on this data. After at the latest seven days, the data is anonymized by shortening the IP address at the domain level so that it is no longer possible to establish a connection to the individual user.
The data is also processed in anonymized form for statistical purposes; it is not compared with other data sets or passed on to third parties, even in excerpts.
Cookies
When you visit our website, we may store information on your computer in the form of cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a string of characters that can be used to assign websites and servers to the specific internet browser in which the cookie was stored. This enables the visited websites and servers to distinguish the individual browser of the person concerned from other Internet browsers that contain other cookies. A specific Internet browser can be recognized and identified via the unique cookie ID.
By using session cookies, the controller can provide users of this website with a user-friendly service that would not be possible without the use of cookies. Without consent, we only use technically necessary cookies on the legal basis of legitimate interest pursuant to Art. 6 (1) lit. f GDPR.
We only use personal cookies to improve our website or for marketing or advertising purposes with your consent. On your first visit, you can voluntarily agree to tracking or analysis via the cookie banner that appears. Your data may be passed on to partners or third-party providers. These cookies are only stored if you explicitly agree to this. The legal basis is then your consent in accordance with Art. 6 (1) (a) GDPR.
You can change your cookie settings at any time here.
We use the content delivery network (CDN) and security features provided by
Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA.
Cloudflare operates a globally distributed network of servers. The content of our website is delivered via this network, which improves loading speed and provides protection mechanisms against attacks on our IT systems.
The following data may be processed when using Cloudflare:
This data processing is carried out to ensure the stability and security of our website.
Legal basis
The processing is based on our legitimate interest pursuant to
Art. 6 (1) lit. f GDPR in the secure and efficient provision of our website.
Insofar as technically necessary cookies or similar technologies are used, this is done on the basis of Section 25 (2) No. 2 TDDDG.
Third country transfer
Cloudflare is a provider based in the USA. The transfer of personal data to the USA cannot therefore be ruled out.
Data transfer is based on the EU-US Data Privacy Framework in accordance with Art. 45 GDPR, provided that Cloudflare is certified accordingly.
Further information can be found at:
https://www.cloudflare.com/privacypolicy/
On our website, we use services provided by
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google may collect information about the use of our website in connection with the use of its services. In particular, the following data may be processed:
The specific data processing depends on the Google service used in each case.
Legal basis
Insofar as Google services provide analysis, marketing, or convenience functions, their use is based exclusively on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TDDDG.
Consent can be revoked at any time with future effect via our consent management tool.
Third country transfer
When using Google services, personal data may be transferred to servers of Google LLC in the USA.
The data transfer is based on the EU-US Data Privacy Framework in accordance with Art. 45 GDPR, provided that Google is certified accordingly.
Further information:
https://policies.google.com/privacy
This website uses the Google Maps map service. The provider is
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
To use the functions of Google Maps, it is necessary to process your IP address. This information is usually transferred to Google servers and stored there.
The use of Google Maps enables an appealing presentation of our online offerings and makes it easy to find the locations we specify.
Legal basis
Use is based exclusively on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TDDDG.
Consent can be revoked at any time via our consent management tool.
Third country transfer
The transfer of personal data to the USA cannot be ruled out.
The transfer is based on the EU-US Data Privacy Framework in accordance with Art. 45 GDPR, provided that Google is certified accordingly.
Further information:
https://policies.google.com/privacy
PayPal
On our website, we offer payment via the payment service provider
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg.
When you make a payment via PayPal, the payment details you enter are transmitted to PayPal.
The data is transmitted in particular for the following purposes:
The following data in particular may be processed:
Legal basis
Processing is carried out for the performance of contracts in accordance with
Art. 6 (1) (b) GDPR.
PayPal may also process data to protect its own legitimate interests, in particular for fraud prevention, on the basis of Art. 6 (1) lit. f GDPR.
Third country transfer
When using PayPal, personal data may be transferred to companies in the PayPal group in third countries, in particular the USA.
The data transfer is based on appropriate safeguards in accordance with Art. 46 GDPR and, where applicable, on an adequacy decision in accordance with Art. 45 GDPR.
Further information:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Registration on the website
The data subject has the option of registering on the website of the controller by providing personal data. The following personal data is collected: name, address, telephone number, email address, date of birth, bank details.
By registering on the website of the controller, the IP address assigned by the data subject’s Internet service provider (ISP), the date and time of registration are also stored. This data is stored to prevent misuse of our services and to enable us to investigate criminal offenses if necessary. In this respect, the storage of this data is necessary to protect the controller. This data is not passed on to third parties unless there is a legal obligation to do so or the disclosure serves the purpose of criminal prosecution.
The registration of the data subject by voluntarily providing personal data serves the purpose of the controller to offer the data subject content or services that, due to the nature of the matter, can only be offered to registered users.
Registered persons are free to change the personal data provided during registration at any time or to have it completely deleted from the data controller’s database.
The personal access data must be treated confidentially by the data subject and must not be made accessible to unauthorized third parties. We accept no liability for misused passwords, unless we are responsible for the misuse.
With the “stay logged in” function, we want to make your visit to our websites as pleasant as possible. This function allows you to use our services without having to log in again each time. For security reasons, however, you will be asked to enter your password again if, for example, you want to change your personal data or place an order. We recommend that you do not use this function if the computer is used by multiple users. Please note that the “stay logged in” function is not available if you use a setting that automatically deletes stored cookies after each session.
Security
We have taken technical and organizational security measures to protect your personal data against loss, destruction, manipulation, and unauthorized access. All our employees and service providers working for us are obliged to comply with the applicable data protection laws.
Whenever we collect and process personal data, it is encrypted before it is transmitted. This ensures that your data cannot be misused by third parties. Our security measures are subject to a continuous improvement process, and our privacy statements are updated regularly. Please ensure that you have the latest version.
What data is processed and from which sources does this data originate?
We process the data that we have received from you in the course of initiating or executing a contract, on the basis of your consent, or in the course of your application to us or your employment with us.
Personal data includes:
Your master/contact data, for example, first and last name, address, contact details (email address, telephone number, fax), and bank details.
For visitors to our company, this includes name and signature.
For journalists, this includes first and last name, email address, and fax number.
In addition, we also process the following other personal data:
For what purposes and on what legal basis is the data processed?
We process your data in accordance with the provisions of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act 2018, as amended:
Your data is processed for the purpose of contract execution online or in one of our branches, for the purpose of contract execution with your employees in our company. The data is processed in particular during the initiation of business and during the execution of contracts with you.
Processing of your data is necessary for the purpose of fulfilling various legal obligations, e.g., under the German Commercial Code or the German Fiscal Code.
Based on a balancing of interests, data processing may be carried out beyond the actual fulfillment of the contract in order to protect our legitimate interests or those of third parties. Data processing to protect legitimate interests takes place, for example, in the following cases:
If you have given us your consent to process your data, e.g., to send you our newsletter, publish photos, etc.
Processing of personal data for advertising purposes
You can object to the use of your personal data for advertising purposes at any time, either in whole or for individual measures, without incurring any costs other than the transmission costs according to the basic rates.
Under the legal requirements of Section 7(3) UWG (German Unfair Competition Act), we are entitled to use the email address you provided when concluding the contract for direct advertising of our own similar goods or services. You will receive these product recommendations from us regardless of whether you have subscribed to a newsletter.
If you do not wish to receive such recommendations from us by email, you can object to the use of your address for this purpose at any time without incurring any costs other than the transmission costs according to the basic rates. A notification in text form is sufficient for this purpose. Of course, every email always contains an unsubscribe link.
Who receives my data?
If we use a service provider for order processing, we remain responsible for the protection of your data. All processors are contractually obliged to treat your data confidentially and to process it only within the scope of the service provision. The processors commissioned by us receive your data if they need it to perform their respective services. These include, for example, IT service providers that we need for the operation and security of our IT system, as well as advertising and address publishers for our own advertising campaigns.
In the event of a legal obligation and in the context of legal proceedings, authorities, courts, and external auditors may be recipients of your data.
In addition, insurance companies, banks, credit agencies, and service providers may be recipients of your data for the purpose of contract initiation and fulfillment.
How long will my data be stored?
We process and store your personal data for as long as is necessary to fulfill our contractual and legal obligations. This includes the duration of the entire business relationship and, in addition, the statutory retention periods in accordance with the German Commercial Code (HGB), the German Fiscal Code (AO), or the German Working Hours Act (ArbZG). In addition, we store your data until the conclusion of any legal disputes in which the data is required as evidence.
Is personal data transferred to a third country?
As a matter of principle, we do not transfer any data to third countries. In individual cases, data may only be transferred on the basis of an adequacy decision by the European Commission, standard contractual clauses, appropriate safeguards, or your express consent.
What data protection rights do I have?
You have the right to obtain information about the personal data we have stored at any time. In addition, you have the right to have your data corrected, deleted, or restricted. You also have the right to object to the processing of your data and the right to data portability. You
also have the right to complain to a data protection supervisory authority. You are entitled to these rights in accordance with the requirements of the applicable data protection laws.
Right to information:
You can request information from us about whether and to what extent we process your data.
Right to rectification:
If we process your data that is incomplete or incorrect, you can request that we correct or complete it at any time.
Right to erasure:
You can request that we erase your data if we process it unlawfully or if the processing disproportionately interferes with your legitimate interests. Please note that there may be reasons that prevent immediate erasure, e.g., in the case of statutory retention obligations.
Regardless of whether you exercise your right to erasure, we will erase your data immediately and completely, provided that there are no legal or contractual retention obligations that prevent this.
Right to data portability:
You may request that we provide you with the data you have provided to us in a structured, commonly used, and machine-readable format and that you may transmit this data to another controller without hindrance from us, provided that
If technically feasible, you may request that we transfer your data directly to another controller.
Right to object:
If we process your data on the basis of legitimate interest, you may object to this data processing at any time; this would also apply to profiling based on these provisions. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims. You may object to the processing of your data for direct marketing purposes at any time without giving reasons.
Right to lodge a complaint:
If you believe that we are violating German or European data protection law when processing your data, please contact us so that we can clarify any questions. You also have the right to
contact the supervisory authority responsible for you, the respective state office for data protection supervision.
If you wish to exercise any of the above rights against us, please contact our data protection officer. In case of doubt, we may request additional information to confirm your identity.
Am I obliged to provide data?
The processing of your data is necessary for the conclusion or fulfillment of your contract with us. If you do not provide us with this data, we will generally have to refuse to conclude the contract or will no longer be able to perform an existing contract and will therefore have to terminate it. However, you are not obliged to give your consent to data processing with regard to data that is not relevant to the fulfillment of the contract or not required by law.
Changes to this privacy policy
We reserve the right to change our privacy policy if this becomes necessary due to new technologies. Please ensure that you have the latest version. If fundamental changes are made to this privacy policy, we will announce them on our website.
All interested parties and visitors to our website can contact us with any questions regarding data protection at:
Projekt 29 GmbH & Co. KG
Ostengasse 14
93047 Regensburg
Tel.: 0941 2986930
Fax: 0941 29869316
Email: anfragen@projekt29.de
Website: www.projekt29.de