Skip to main content

Literally Peace

Privacy Policy

This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) within our online services and associated websites, features, and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as “Online Services”). With regard to the terminology used, such as “processing” or “controller”, we refer to the definitions set out in Art. 4 of the General Data Protection Regulation (GDPR).

Controller

Tramountani, Maria / Literally Peace e. V.
c/o Stadtjugendring Stuttgart e. V.
Burgenlandstraße 15
70469 Stuttgart
Germany

Email: maria.tramountani@literallypeace.com
Owner: Tramountani, Maria

Types of Data Processed

  • Inventory data (e.g., names, addresses).

  • Contact details (e.g., email addresses, telephone numbers).

  • Content data (e.g., text inputs, photographs, videos).

  • Usage data (e.g., visited web pages, interest in content, access times).

  • Meta/communication data (e.g., device information, IP addresses).

Categories of Data Subjects

Visitors and users of the Online Services (hereinafter collectively referred to as “users”).

Purposes of Processing

  • Provision of the Online Services, their functions, and contents.

  • Answering contact inquiries and communicating with users.

  • Security measures.

  • Reach measurement and marketing.

Terminology

  • Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

     
  • “Processing” means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.

  • “Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

     
  • “Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

     
  • “Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

  • “Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Relevant Legal Bases

In accordance with Art. 13 GDPR, we inform you of the legal bases of our data processing. Unless a specific legal basis is mentioned in this privacy policy, the following applies:

  • The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR.

  • The legal basis for processing to fulfill our services, execute contractual measures, and respond to inquiries is Art. 6(1)(b) GDPR.

  • The legal basis for processing to fulfill our legal obligations is Art. 6(1)(c) GDPR.

  • The legal basis for processing to protect our legitimate interests is Art. 6(1)(f) GDPR.

  • In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6(1)(d) GDPR serves as the legal basis.

Security Measures

In accordance with Art. 32 GDPR, taking into account the state of the art, the implementation costs, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, entry, transfer, securing availability, and data separation. Furthermore, we have established procedures to guarantee the exercise of data subjects’ rights, deletion of data, and responses to data vulnerabilities. We also consider the protection of personal data during the development and selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).

Cooperation with Processors and Third Parties

If, within the scope of our processing, we disclose data to other persons and companies (processors or third parties), transfer data to them, or otherwise grant them access to data, this will only be done on the basis of a legal permission (e.g., if transfer to third parties such as payment providers is required for contract performance pursuant to Art. 6(1)(b) GDPR), if you have consented, if a legal obligation requires it, or based on our legitimate interests (e.g., when using agents, web hosts, etc.).

If we commission third parties with the processing of data on the basis of a data processing agreement, this is done on the basis of Art. 28 GDPR.

Transfers to Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing/transferring data to third parties, this only takes place if necessary to fulfill our (pre-)contractual obligations, based on your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or let data be processed in a third country only if the special requirements of Art. 44 et seq. GDPR are met (e.g., based on recognized adequacy decisions or compliance with officially recognized standard contractual clauses).

Rights of Data Subjects

  • Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether data concerning you is being processed, to obtain information about this data, and to receive further information and a copy of the data.

  • Right to rectification (Art. 16 GDPR): You have the right to request the completion or rectification of inaccurate data concerning you.

  • Right to erasure & restriction (Art. 17 & 18 GDPR): In accordance with Art. 17 GDPR, you have the right to demand that relevant data be deleted immediately, or alternatively, pursuant to Art. 18 GDPR, to demand a restriction of the processing of the data.

  • Right to data portability (Art. 20 GDPR): You have the right to receive the data concerning you that you provided to us and to request its transfer to other controllers.

  • Right to lodge a complaint (Art. 77 GDPR): You also have the right to lodge a complaint with the competent supervisory authority.

Right of Withdrawal

You have the right to withdraw consents granted pursuant to Art. 7(3) GDPR with effect for the future.

Right to Object

You may object at any time to the future processing of data concerning you in accordance with Art. 21 GDPR. The objection may in particular be made against processing for direct marketing purposes.

Cookies and Right to Object in Direct Marketing

“Cookies” are small files that are stored on users’ computers. Different types of information can be stored inside cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service.

  • Temporary/Session cookies: Cookies that are deleted after a user leaves an online service and closes their browser (e.g., cart contents or login status).

  • Permanent/Persistent cookies: Cookies that remain stored even after closing the browser (e.g., keeping login status or tracking user interests for analytics/marketing).

  • Third-party cookies: Cookies offered by providers other than the controller operating the online service (first-party cookies refer to the controller’s own cookies).

We may use temporary and permanent cookies and clarify this within the scope of our privacy policy.

If users do not want cookies stored on their computer, they are requested to disable the corresponding setting in their browser. Stored cookies can be deleted in the browser settings. Disabling cookies may lead to functional restrictions of this online service.

A general objection to the use of cookies used for online marketing purposes can be declared for a variety of services (especially tracking) via the US website aboutads.info/choices or the EU website youronlinechoices.com.

Deletion of Data

The data processed by us will be deleted or restricted in its processing in accordance with Art. 17 and 18 GDPR. Unless expressly stated in this privacy policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and deletion does not conflict with statutory retention obligations. If data is not deleted because it is required for other legally permissible purposes, its processing will be restricted (i.e., blocked and not processed for other purposes).

  • Germany: Statutory retention periods include 10 years pursuant to §§ 147(1) AO, 257(1) Nos. 1 & 4, (4) HGB (accounting records, commercial books, tax-relevant documents) and 6 years pursuant to § 257(1) Nos. 2 & 3, (4) HGB (commercial letters).

  • Austria: Statutory retention periods include 7 years pursuant to § 132(1) BAO (accounting records, receipts, accounts), 22 years in connection with real estate, and 10 years for documents related to electronically supplied services, telecommunications, radio, and television services provided to non-taxable persons in EU member states under the Mini-One-Stop-Shop (MOSS).

Comments and Contributions

When users leave comments or other contributions, their IP addresses may be stored for 7 days on the basis of our legitimate interests within the meaning of Art. 6(1)(f) GDPR. This is done for our security in case illegal content is posted (e.g., insults, prohibited political propaganda). In such cases, we could be held liable ourselves and are therefore interested in the author’s identity.

Furthermore, we reserve the right to process user data for spam detection based on our legitimate interests (Art. 6(1)(f) GDPR). On the same legal basis, in the case of surveys, we reserve the right to store IP addresses for the duration of the survey and use cookies to prevent multiple votes. The data entered in comments and contributions will be stored permanently until the user objects.

Akismet Anti-Spam Check

Our Online Services use the “Akismet” service, offered by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. Usage is based on our legitimate interests within the meaning of Art. 6(1)(f) GDPR. This service distinguishes comments made by real individuals from spam comments. All comment entries are sent to a server in the USA where they are analyzed and stored for comparison purposes for four days. If a comment is categorized as spam, the data is stored beyond this period. This data includes the entered name, email address, IP address, comment content, referrer, browser/operating system specifications, and timestamp.

For more information on data collection and use by Akismet, see Automattic’s privacy policy: https://automattic.com/privacy/.

Users are welcome to use pseudonyms or refrain from entering a name or email address. You can completely prevent data transmission by not using our comment system.

Retrieval of Profile Images via Gravatar

Within our Online Services, and particularly in our blog, we use the Gravatar service from Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

Gravatar allows users to register and store profile pictures along with their email addresses. When users leave posts or comments on other online platforms using that email address, their profile image can be displayed alongside. For this purpose, the email address provided by the user is transmitted in encrypted form to Gravatar to check if a profile exists. This is the sole purpose of transmitting the email address; it is not used for other purposes and is deleted afterward.

The use of Gravatar is based on our legitimate interests within the meaning of Art. 6(1)(f) GDPR. By displaying the images, Gravatar receives the user’s IP address, as this is technically necessary for browser communication. For more information, see: https://automattic.com/privacy/.

If you do not want an image linked to your Gravatar email to appear in comments, use an email address not registered with Gravatar.

Retrieval of Emojis and Smileys

Within our WordPress blog, graphical emojis (smileys) fetched from external servers are used. The server providers collect the IP addresses of users to transmit the emoji files to the user’s browser. The emoji service is provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA (Privacy Policy). The server domains used are s.w.org and twemoji.maxcdn.com, which operate as Content Delivery Networks solely for fast and secure file delivery; user personal data is deleted after transmission.

The use of emojis is based on our legitimate interests in an appealing presentation of our Online Services (Art. 6(1)(f) GDPR).

Hosting and Email Delivery

The hosting services we use provide infrastructure and platform services, computing capacity, storage space, database services, email dispatch, security services, and technical maintenance services required for operating this online presence.

Here, we or our hosting provider process inventory data, contact data, content data, contract data, usage data, and meta/communication data of customers, interested parties, and visitors based on our legitimate interests in the efficient and secure provision of this online service pursuant to Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (Data Processing Agreement).

Google Analytics

Based on our legitimate interests (analysis, optimization, and economic operation of our Online Services under Art. 6(1)(f) GDPR), we use Google Analytics, a web analysis service from Google LLC (“Google”). Google uses cookies. The information generated by the cookie about the use of the online service by users is usually transferred to a Google server in the USA and stored there.

 

Google will use this information on our behalf to evaluate the use of our Online Services, compile reports on website activity, and provide us with further services related to website and internet usage. Pseudonymous user profiles can be created from the processed data.

 

We only use Google Analytics with activated IP anonymization. This means that the IP address of users is shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there.

The IP address transmitted by your browser will not be merged with other Google data. You can prevent cookie storage through browser settings or prevent Google from collecting and processing data by downloading and installing the browser plug-in available at: http://tools.google.com/dlpage/gaoptout?hl=en.

Further information on data usage by Google, setting options, and opt-outs can be found in Google’s Privacy Policy (https://policies.google.com/technologies/ads) and ad settings (https://adssettings.google.com/authenticated). User data is deleted or anonymized after 14 months.

Statistical Analysis of Website Usage (WP Statistics)

Our website uses the WP Statistics plugin for statistical analysis of visitor traffic. This allows us to see how many visitors have accessed specific pages. The evaluation takes place purely locally on a server located in Germany where this website is hosted. Your IP address is anonymized before it is stored in the statistics.

The legal basis for processing your data is our legitimate interest in tailoring our website to user needs (Art. 6(1)(f) GDPR).

Social Media Online Presences

We maintain online presences within social networks and platforms to communicate with active customers, interested parties, and users, and to inform them about our services. When accessing these networks and platforms, the terms and conditions and data processing guidelines of the respective operators apply.

Unless otherwise stated in this privacy policy, we process user data if they communicate with us within social networks and platforms (e.g., write posts on our pages or send us messages).

Integration of Third-Party Services and Content

Based on our legitimate interests (Art. 6(1)(f) GDPR), we incorporate third-party content and service offerings (such as videos or fonts, hereinafter referred to uniformly as “Content”).

This always requires that the third-party providers perceive the user’s IP address, as they cannot send content to the browser without it. Third-party providers may also use pixel tags (web beacons) for statistical or marketing purposes to evaluate visitor traffic. Pseudonymous information may also be stored in cookies on the user’s device containing technical information about browser and OS, referring web pages, visiting time, and other details.

Google Fonts

We integrate fonts (“Google Fonts”) provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Privacy Policy: https://www.google.com/policies/privacy/

Opt-Out: https://adssettings.google.com/authenticated

Use of Facebook Social Plugins

Based on our legitimate interests (Art. 6(1)(f) GDPR), we use Social Plugins of the social network facebook.com, operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). The plugins can represent interaction elements or content (e.g., videos, graphics, text posts) and are recognizable by one of the Facebook logos (white “f” on a blue tile, the terms “Like”, or a “thumbs up” sign) or marked with the addition “Facebook Social Plugin”. List and appearance: https://developers.facebook.com/docs/plugins/.

When a user opens a function containing such a plugin, their device establishes a direct connection with Facebook’s servers. Facebook transmits the plugin content directly to the user’s device. We have no influence on the scope of data collected by Facebook via these plugins. By integrating the plugins, Facebook receives information that a user has called up the corresponding page. If the user is logged into Facebook, Facebook can assign the visit to their account. If users interact with plugins (e.g., clicking the Like button or leaving a comment), the information is sent directly to Facebook and stored there. Even if a user is not a member of Facebook, there is a possibility that Facebook will obtain and store their IP address (in Germany, according to Facebook, only an anonymized IP is stored).

Purpose and scope of data collection, further processing, and your rights/settings to protect privacy can be found in Facebook’s data policy: https://www.facebook.com/about/privacy/.

To prevent Facebook from collecting data about you via our Online Services and linking it to your member data, log out of Facebook and delete cookies before using our website. Further settings and opt-outs for advertising purposes: https://www.facebook.com/settings?tab=ads, aboutads.info/choices, or youronlinechoices.com.

Instagram

Functions and contents of the service Instagram, offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA, may be integrated into our Online Services (e.g., images, videos, texts, and sharing buttons). If users are members of Instagram, Instagram can assign the call of these contents and functions to their profiles.

Instagram Privacy Policy: http://instagram.com/about/legal/privacy/

Created with Datenschutz-Generator.de by Attorney at Law Dr. Thomas Schwenke