Privacy Policy

Overview

With this privacy policy, we inform you about our handling of your personal data and about your rights under the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The Leibniz Institute of Virology (hereinafter referred to as "we" or "us") is responsible for data processing (unless otherwise stated below).

Our data protection information consists of two parts. Part A provides you with general information on data protection at our company and explains, among other things, what rights you have and where you can assert them. Part B is dedicated to the various groups of data subjects and explains in detail what data we collect and process about you. We address you in your role as:

a. Visitors to our websites;
b. Newsletter subscribers;
c. Contact persons at service providers, suppliers and business partners;
d. Event visitors
e. Journalists/press representatives;
f. Donors;
g. Applicants;
h. Social media visitors.

A. General information

1. Our contact details

If you have any questions or suggestions regarding this information or would like to assert your
rights, please send your request to:

Leibniz Institute of Virology
 - Civil law foundation -
Martinistraße 52
20251 Hamburg

2. On what basis do we process your data?

The data protection term "personal data" refers to all information relating to an identified or identifiable person. We process personal data in compliance with the relevant data protection regulations, in particular the GDPR and the BDSG. Data processing by us only takes place on the basis of legal permission. We process personal data only with your consent (Art. 6 para. 1 lit. a GDPR), for the performance of a contract to which you are a party or at your request for the implementation of pre-contractual measures (Art. 6 para. 1 lit. b GDPR), for compliance with a legal obligation (Art. 6 para. 1 lit. c GDPR) or if the processing is necessary to safeguard our legitimate interests or the legitimate interests of a third party, unless your interests or fundamental rights and freedoms, which require the protection of personal data, prevail (Art. 6 para. 1 lit. f GDPR).

If you apply for an open position at our institute, we will also process your personal data to decide on the establishment of an employment relationship (Section 26 (1) sentence 1 BDSG).

3. Your rights

You decide on your data! As a data subject, you therefore have the right to assert your data subject rights against us. You have the following rights within the scope of the data protection laws applicable to you:

  • In accordance with Art. 15 GDPR and Section 34 BDSG, you have the right to request information as to whether or not we process personal data relating to you and, if so, to what extent.
  • You have the right to demand that we rectify your data in accordance with Art. 16 GDPR.
  • You have the right to demand that we erase your personal data in accordance with Art. 17 GDPR and Section 35 BDSG.
  • You have the right to restrict the processing of your personal data in accordance with Art. 18 GDPR.
  • In accordance with Art. 20 GDPR, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to transmit those data to another controller.
  • If you have given us separate consent to process your data, you can withdraw this consent at any time in accordance with Art. 7 (3) GDPR. Such a revocation does not affect the legality of the processing that was carried out on the basis of the consent
    until the revocation.
  • If you believe that the processing of your personal data violates the provisions of the GDPR, you have the right to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR.

In accordance with Art. 21 para. 1 GDPR, you have the right to object to processing based on the legal basis of Art. 6 para. 1 lit. e or f GDPR on grounds relating to your particular situation. If we process personal data about you for the purpose of direct marketing, you can object to this processing in accordance with Art. 21 para. 2 and 3 GDPR.

If you exercise your rights in accordance with Art. 15 to 22 GDPR, we process the personal data transmitted for the purpose of implementing these rights by us and to be able to provide proof of this. We will only process data stored for the purpose of providing and preparing information for this purpose and for the purposes of data protection monitoring and will otherwise restrict processing in accordance with Art. 18 GDPR.

This processing is based on the legal basis of Art. 6 para. 1 lit. c GDPR in conjunction with. Art. 15 to 22 GDPR and § 34 para. 2 BDSG.

4. Where do we process your data?

In principle, we process your data on European servers with the highest security standards. In providing our services, we are supported by external service providers to whom we send your data. Some data processing may involve the transfer of certain personal data to third countries, i.e. countries in which the GDPR is not applicable law. Such a transfer is permitted if the European Commission has determined that an adequate level of data protection is required in such a third country. This applies to all transfers to countries in this list: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-dataprotection/adequacy-decisions_en
If there is no such adequacy decision by the European Commission, personal data will only be transferred to a third country if there are suitable guarantees in accordance with Art. 46 GDPR or if one of the requirements of Art. 49 GDPR is met.

Unless there is an adequacy decision and unless otherwise stated below, we use the EU standard data protection clauses as appropriate safeguards for the transfer of personal data from the scope of the GDPR to third countries. You have the option of obtaining or viewing a copy of these EU standard data protection clauses. Please contact us at the address given under Contact.

If you consent to the transfer of personal data to third countries, the transfer takes place on the legal basis of Art. 49 para. 1 lit. a GDPR.

5. To whom and why do we pass on your personal data?

In order to provide our services and operate as a foundation, we use various external companies to which we transfer personal data in some cases. If other specific recipients contain personal data for some groups of data subjects, we will inform you about this in Part B.

  • Hosting provider: We commission certified service providers to host our data who have the highest security standards.
  • IT service providers and SaaS providers: We use the services of various service providers who support us as processors and simplify and optimize our processes, including service providers for the administration and processing of newsletter distribution and the processing of applications.
  • Administration and authorities: In order to comply with legal regulations or to respond to court orders or other similar official requests, further transfers may take place. This also includes transfers to the tax authorities and tax consultancy/auditing firms.

6. How long do we store your data?

Unless otherwise stated in the following information, we only store the data for as long as is necessary to achieve the purpose of processing or to fulfill our contractual or legal obligations. Such statutory retention obligations may arise in particular from commercial or tax law regulations. From the end of the calendar year in which the data was collected, we will store such personal data contained in our accounting data for ten years and store personal data contained in commercial letters and contracts for six years. In addition, we will retain data in connection with consents requiring proof and with complaints and claims for the duration of the statutory limitation periods. We will delete data stored for advertising purposes if you object to processing for this purpose.

7. How do we use "cookies" and other tracking technologies?

We use cookies and similar technologies on our websites. We have compiled more information about how we use these technologies in our cookie banner. The banner can be accessed via the "Privacy settings" link in the footer of our websites. There you will also find a list of other companies that place cookies on our websites and process data on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR, a list of cookies that we place and an explanation of how you can refuse certain types of cookies.

8. How can you contact our data protection officer?

You can reach our data protection officer using the following contact details:
Arne Düsedau
c/o
Leibniz Institute of Virology
Martinistraße 52, 20251 Hamburg
Please enable JavaScript to render this link!


B. Special section - How and why we process your data

a. Visitors to our website

1) We process pseudonymous information about the device and browser you are using, server log files, your network connection and your IP address for the following purposes:

  • Ensuring the security, operability and stability of our websites, including defense
    against attacks;
  • Integration of third-party content, such as videos or other media content;
  • Obtain and manage your consents via our Consent Management Tool.

Legal basis: Legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in the flawless functionality and stability of the website or consent to the use of data for the display of third-party content.

2) We process information about how you behave on the website. This includes the IP address and user IDs, some of which are assigned by third-party providers, and is used for the following purposes:

  • Reach measurement and analysis of visitor behavior to optimize our websites, increase customer satisfaction and error analysis.

Legal basis: Consent in accordance with Art. 6 para. 1 lit. a GDPR, which we obtain via the consent banner on our website and which you can revoke or adjust at any time via the "Privacy settings" link in the footer of the website.

3) We process data that you provide to us in contact forms about yourself or the company in which you work, such as your name and e-mail address, for the following purposes:

  • Support and communication;
  • Answering inquiries.

Legal basis: If your request is aimed at the conclusion or execution of a contract with us, Art. 6 para. 1 lit. b GDPR is the legal basis for data processing. Otherwise, we process the data on the basis of our legitimate interest in contacting inquiring persons. The legal basis for data processing is then Art. 6 para. 1 lit. f GDPR.

b. Newsletter subscribers

1) We process the name and contact details that you provide to us when registering for our newsletter for the following purposes:

  • Sending personalized advertising mailings with information and updates on current topics relating to the research institution and our research work;
  • Verification of your e-mail address via the double opt-in procedure.

The legal basis for data processing in connection with our newsletter is your consent pursuant to Art. 6 para. 1 lit. a GDPR, which you can revoke at any time by contacting us using the contact details above or by using the unsubscribe link.

c. Contact persons at service providers/ suppliers/ business partners

1) We process data that you provide to us about yourself and the company in which you work, such as your name, e-mail address and telephone number, for the following purposes:

  • Fulfillment of the contract with the company in which you work (this includes contract management, documentation for ongoing cooperation, billing and communication).

Legal basis: Legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in the performance of the contract between the company in which you work and us.

d. Event visitors

1) When you attend an event with us, we process data that you provide about yourself, such as your name, e-mail address, attendance details and comments, for the following purposes:

  • Planning and implementation of the respective event;
  • Sending information about or following the event.

Legal basis: Legitimate interest according to Art. 6 para. 1 lit. f) GDPR and fulfillment of the contract according to Art. 6 para. 1 lit. b) GDPR.

e. Journalists/press representatives

1) If you have registered for our e-mail distribution list, we will process your contact data for the following purpose:

  • Sending of press releases with current information from the Leibniz Institute of Virology.

The legal basis for data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR, which you can revoke at any time by contacting us using the contact details above.

f. Donors

1) If you register with us as a donor and become a member of our association, we process data that you provide to us via the registration form, such as your name, address, contact details and membership fee, for the following purposes:

  • Membership administration in accordance with the Statutes;
  • Collection of membership fees or donations.

Legal basis: Legitimate interest according to Art. 6 para. 1 lit. f) GDPR and fulfillment of the contract according to Art. 6 para. 1 lit. b) GDPR.

g. Applicants

1) Data that you provide to us in the course of your application or that a recruitment agency transmits to us. This is information about your CV, your previous career and other data that we process for the following purposes:

  • Determining whether employment is possible;
  • Initiation of an employment relationship.

Legal basis: Contract initiation in accordance with Art. 6 para. 1 lit. b) GDPR and § 26 para. 1 sentence 1 BDSG.

  • Fulfillment of statutory retention obligations or defense against legal claims.

Legal basis: Compliance with legal obligations pursuant to Art. 6 para. 1 lit. c) GDPR.

  • Inclusion in our talent pool for later contact if no employment relationship is established for the time being.

Legal basis: Consent pursuant to Art. Art. 6 para. 1 lit. a GDPR, which you can revoke at any time by contacting us using the contact details above.

If we are unable to offer you employment, we will retain the application documents you have submitted for up to six months after any rejection for the purpose of answering questions in connection with your application and rejection. This does not apply if statutory provisions prevent deletion, if further storage is necessary for the purpose of providing evidence or if you have expressly consented to longer storage.

h. Social media visitors

1)Responsibility of the social media providers
When you visit our social media pages (Facebook, Instagram, LinkedIn, X, YouTube) on which we present our company, certain information about you as a visitor is processed.

Further information:
Facebook and Instagram:

LinkedIn: Privacy Policy of LinkedIn Ireland Unlimited Company
X: Further information can be found in the privacy policy
YouTube: Google's privacy policy and terms of use

2) Joint responsibility of the social media providers and the Leibniz Institute of Virology (joint controllers)
The social media providers collect and process event data and send us anonymized statistics and data for our pages that help us gain insights into the various activities that visitors perform on our site (so-called "Page Insights"). These Page Insights are created based on certain information about people who have visited our site(s).

Further information:
Facebook and Instagram:

LinkedIn:

  •  Joint Controller Agreement
  • Data subject rights can be asserted via this contact form at LinkedIn. You can contact LinkedIn's data protection officer via this link.
  • LinkedIn and we have agreed that the Irish Data Protection Commission is the competent supervisory authority overseeing the processing of Page Insights. You can lodge your complaint with the Irish Data Protection Commission (see www.data protection.ie) or with another supervisory authority.
     

3) Under the responsibility of the Leibniz Institute of Virology
We process information that you have made available to us via our social media channels on the respective social media platform. This information may be the name used, contact information or a message to us.
Legal basis: Legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in communicating with interested parties and followers.

Contact

Arne Düsedau

Data protection officer

Phone: +49 (0)40 48051-377

Email: Please enable JavaScript to render this link!