Privacy Notice for Social Media
Privacy Policy for ZKM Social Media Presences
-
Instagram
Table of contents
1. Purpose of data protection and legal framework
2. General information on the Instagram platform
3. Making direct contact
4. User interactions
5. Cookies
6. User analysis ("Insights" function)
7. Analytics and reports using Google Data Studio
8. Recipients of personal data
9. Data processing in third countries
10. Retention policy
11. Your rights
12. Data Protection Officer
13. Safety and security
14. AmendmentsAs the controller and simultaneously the service provider, we
ZKM | Zentrum für Kunst und Medien Karlsruhe
Public Foundation
Lorenzstraße 19
76135 Karlsruhe, Germany
Email: info@zkm.de
(Legal notice)(hereinafter also referred to as "we" or "ZKM")
hereby inform you of the processing of your personal data and of your rights as a data subject within the context of your use of the presences
https://www.instagram.com/zkmkarlsruhe/ („zkmkarlsruhe“)
https://www.instagram.com/zkm_muskom/ („zkm_muskom“)
https://www.instagram.com/zkm_collections/ („zkm_collections“)(hereinafter "Instagram presences")
which we operate on the social media platform Instagram (hereinafter "Instagram platform").
The provider of the Instagram platform, Meta Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (hereinafter also "Meta"), is also responsible for data processing on our Instagram presences as controller in addition to us.
The processing of your personal data is performed exclusively within the framework of the provisions of data protection law, in particular the EU General Data Protection Regulation (hereinafter "GDPR"), and also the Data Protection Act of the State of Baden-Württemberg (hereinafter "LDSG BW") and other statutory provisions on data protection.
This Privacy Policy applies only to those of our Instagram presences indicated above. With respect to other (online or social media) presences of ZKM, only the privacy policies published on such presences apply. Furthermore, the following information does not apply to third-party social media presences or websites run by other operators which may be linked to from our Instagram presences.
The terms used in this Privacy Policy, such as "personal data" or "processing", are given the definitions contained under Article 4 GDPR. If you would like to read the GDPR or LDSG BW for yourself, you can find a copy at: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 and https://dejure.org/gesetze/LDSG respectively.
1. Purpose of data protection and legal framework
The purpose of data protection is to protect personal data. Personal data means all information relating to an identified or identifiable person (a so-called data subject). Therefore, your personal data includes all data that could be used to identify your person, e.g. your name, address, telephone number, or email address. Personal data also includes information generated by your use of our Instagram presences.
We only process your data where this is permitted by an applicable legal regulation. Unless otherwise described in the following sections of this Privacy Policy, the processing of your data is based on our legitimate interests (Article 6(1)(1), point (f) GDPR) in the commercial operation and optimization of our Instagram presences and in the analysis of the use of the same.
2. General information on the Instagram platform
We inform you that you use our Instagram presences and their functions, as well as the Instagram platform as a whole, under your own responsibility. This applies in particular to the use of interactive functions (e.g. likes, follows, comments, shares).
Your use of the Instagram platform and data processing by Meta as provider of the Instagram platform is governed first and foremost by the Terms of Use (https://help.instagram.com/581066165581870?cms_id=581066165581870) and Privacy Policy (https://help.instagram.com/519522125107875) of Instagram.
Some parts of our Instagram presences can be used without registering with the Instagram platform. However, even if you are using the Instagram platform without registering, personal data may still be processed.
We hereby explicitly inform you that Meta stores the data of users registered with the Instagram platform (hereinafter also "users") and other interested visitors to the Instagram platform (hereinafter also "visitors"), e.g. personal information, IP address, cookies etc., outside of the European Union (EU) or European Economic Area (EEA) and uses these data for its own commercial purposes.
We do not generally have any control over the collection and processing of data by Meta. We have no knowledge of nor any control over how much, where, and for how long these data are stored, or the extent to which Meta complies with existing erasure obligations, or what analyses and connections with data Meta has undertaken, or who Meta forwards these data to. We therefore kindly ask you to think carefully about the personal data you reveal as a user of the Instagram platform.
We operate our Instagram presences in order to keep users and visitors up-to-date with our company and our activities, primarily by sharing photos and videos, and to interact with these same users and visitors. If you would like to stay up-to-date with us without using the Instagram platform, you can alternatively access much of the information published via our Instagram presences on our Website (https://zkm.de/de).
3. Making direct contact
If you contact us directly via our Instagram presences (e.g. via direct message), we process the data you provide in this context (e.g. Your name, email address) solely for its intended purpose, and in order to receive and, where applicable, respond to your inquiry. Your data may also be transmitted to our systems for this purpose.
If this communication relates to initiation of a contractual relationship, the data that are transmitted via the Instagram platform within the context of making direct contact are processed on the basis of Article 6(1)(1), point (b) GDPR. If we ask you to consent to data processing, e.g. in relation to one of the forms we provide, the legal basis for this data processing is Article 6(1)(1), point (a) GDPR as applicable. Otherwise, the legal basis is our legitimate interest (Article 6(1)(1), point (f) GDPR) in processing contact requests sent to us voluntarily.
The confidentiality of the information you provide us with in the context of making direct contact is particularly important to us. Therefore, since we have no knowledge of how Meta, as the provider of the Instagram platform, uses this information, please refrain from sending us sensitive data or other confidential information, e.g. application documents or bank/credit card details, via this channel. We recommend using a secure method of transmission for such data, such as ordinary mail.
4. User interactions
Due to the way in which a social media platform works, ZKM has the ability to identify users who like our Instagram presences and our posts, or who rate, comment or share such, provided their interactions on the Instagram platform are public and are not explicitly marked as "private". We analyze this information in aggregated form in order to create more relevant content for users and visitors to our Instagram presences which may be of greater interest to these persons (see Sec. 6). The information we obtain in this way does not allow us to identify any natural persons.
As a user of Instagram, you can actively hide your "posts" or "followers" via your Instagram profile or unfollow our Instagram presences. You will then no longer appear in the lists of followers of our Instagram presences.
5. Cookies
As the provider of the Instagram platform, Meta uses cookies and cookie-related technologies, i.e. small files which are stored on your end device (hereinafter referred to jointly as "cookies") in order to provide you with greater functionality, to make your use of the platform more convenient, and to optimize their own offering. The data obtained using cookies is stored and processed directly by Meta. ZKM has no access to these data nor any control over how Meta uses them.
Meta can use the information obtained using cookies within the Instagram platform and other Meta services, and also in third-party services which Meta services use, in order to generate user profiles for market research and advertising purposes. These processes take into account, in particular, your user behavior and the interests they derive from this. For example, Meta can allow Meta partners or even third parties to use these data in order to display advertising inside and outside the Instagram platform. If you use Instagram or other Meta services on multiple end devices, your data may be collected and analyzed across these devices, especially if you are logged in as a user.
More information on the nature, purposes, legal framework and relevant settings ("Opt-in"/"Opt-out") relating to the use of cookies on the Instagram platform can be found in the Instagram Help Center under "About Cookies" (https://help.instagram.com/1896641480634370/?helpref=hc_fnav&bc[0]=Instagram-Hilfebereich&bc[1]=Richtlinien%20und%20Meldungen).
According to information provided by Meta as provider of the Instagram platform, cookies are stored and used in connection with personalized advertising or analysis and research, and functional cookies, insofar as such originate from companies other than Meta, are stored and used only if you have consented to such (Article 6(1)(1), point (a) GDPR). According to information provided by Meta, it is not possible to block the cookies used by Meta for the aforementioned purposes or other cookies which are used to ensure the safety and security of visitors, users and the Instagram platform, to identify users when they use the Instagram platform, to access settings, and to ensure the functionality of the Instagram platform.
You also can block the storage of cookies by selecting "Block all cookies" in your browser or device settings. For details of how to manage and delete cookies via your browser or device settings, please refer to the Help function in your browser or on your device.
You can also block the storage of cookies using free browser add-ons such as "Adblock Plus" (https://adblockplus.org/en/) combined with the "EasyPrivacy" list (https://easylist.to).
However, blocking the storage of cookies may restrict the functionality of the Instagram presences.
6. User analysis ("Insights" function)
In operating our Instagram presences, we use the Instagram platform's "Insights" function, through which Meta, as the provider of the Instagram platform, provides us with statistical data on the use of our Instagram presences. This data is anonymous for us, i.e. we cannot view the personal data of individual users or visitors. We are not aware of what data specifically Meta uses in order to analyze the use of our Instagram presences ("Insights data"). Specifically, we can see the following aggregated data: Accounts reached, content interactions, and total number of followers, including trends for each of these areas over the past 7 days.
7. Analytics and reports using Google Data Studio
We use Google Data Studio, an analytics service from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter "Google"), to compile reports and analyze aggregated data that are collected concerning our Website (www.zkm.de) and social media channels.
Google Data Studio uses aggregated data (e.g. number of visits, post reach etc.) from various data sources which we connect to Data Studio via Application Programming Interfaces (APIs). One of the data sources we have connected to Data Studio is our Instagram presences.
The information generated, such as information on the use of our social media channels, is generally transmitted to a Google server in the USA where it is stored. Google will use this information on our behalf to analyze the use of our social media channels in order to compile reports on activities and visualize these data. Our Data Studio Dashboard is configured such that analytics are performed exclusively on the basis of aggregated data, and not at a user or post level. Personally identifiable information, such as IP addresses, is not input into Data Studio.
However, in the interests of data protection, we have concluded a data processing agreement with Google which also applies to the use of the Google Data Studio app.
Analytics do not require a specific legal basis due to the upstream aggregation of data (collation) and the subsequent lack of personally identifiable information in the data in Google Data Studio. Where necessary, the legal basis for this upstream aggregation is our legitimate interest according to Article 6(1)(1), point (f) GDPR. Our legitimate interest consists in analyzing the use of our social media channels and our Website so that we can continuously improve both of these.
8. Recipients of personal data
We only ever forward your personal data to external recipients where this is necessary in order to handle or process your inquiry, or we have your consent to do so, or we have other permission to do so under law. Such a transmission of data is thus based on Article 6(1)(1), point (c) and/or point (f) GDPR, whichever applies to the individual case. External recipients may also include data processors (e.g. technical service providers) who use personal data exclusively for the purposes we have specified and according to our instructions, subject to compliance with the legal requirements of Article 28 GDPR.
Data may also be transmitted to other private and public agencies, e.g. tax advisors, financial auditors, supervisory authorities, public prosecutors, or courts. Such transmissions are based on Article 6(1)(1), point (c) and/or point (f) GDPR.
For details of how Meta, as provider of the Instagram platform, transmits your data within and outside of the Meta Group, please refer to the Meta Privacy Policy (https://de-de.facebook.com/privacy/explanation/) and Instagram Privacy Policy (https://help.instagram.com/519522125107875).
9. Data processing in third countries
Insofar as we transmit your data to third countries outside of the EU or EEA according to the explanations above, we ensure prior to this transmission that, notwithstanding the exceptions permitted by law, the recipient has an appropriate level of data protection or you consent to this transmission of data. An appropriate level of data protection can be guaranteed by conclusion of EU standard contractual clauses, for example, or the existence of so-called Binding Corporate Rules (BCR).
We can provide you with an overview of recipients in third-party states and a copy of the concrete regulations that have been agreed in order to ensure the appropriate level of data protection. Please do not hesitate to get in touch with our Data Protection Officer directly at datenschutz@zkm.de.
As the provider of the Instagram platform, Meta regularly processes data in third countries outside of the EU/EEA, in particular in the USA. Data transfers to the USA are subject to so-called EU standard contractual clauses.
10. Retention policy
We only store your personal data for as long as this is necessary in order to fulfill the relevant purposes or – if you give your consent – until such time as you withdraw your consent. If you do withdraw your consent, we will stop processing your personal data unless we are permitted or required to continue processing according to the relevant statutory provisions (e.g. within the context of retention obligations under commercial and tax law). We will also erase your personal data where we are required to do so for legal reasons.
We review the necessity of the personal data we are storing on the Instagram platform at least once per year and carry out corresponding erasure routines, during which we erase messages sent to us, for example. However, since we do not have control over the technology behind the Instagram platform, we cannot guarantee that Meta does in fact subsequently erase the data we have erased.
In principle, we have no control over how Meta stores or erases your data within the context of the Instagram platform.
For details, please see the Meta Privacy Policy (https://de-de.facebook.com/privacy/explanation/) and Instagram Privacy Policy (https://help.instagram.com/519522125107875).
11. Your rights
As a data subject, you have a number of rights. These rights are:
- Right of access (Article 15 GDPR, § 21 LDSG BW);
- Right to rectification (Article 16 GDPR);
- Right to erasure (Article 17 GDPR, § 23 LDSG BW);
- Right to restriction of processing (Article 18 GDPR);
- Right to data portability (Article 20 GDPR).
- Right to object to data processing on the grounds of legitimate interests (Article 21 GDPR): You have the right to object, on grounds relating to your particular situation, to our processing of personal data, provided this is based on legitimate interests within the meaning of Article 6(1)(1), point (f) GDPR. If you make use of your right to object, we will stop processing your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, or this processing serves to establish, exercise or defend legal claims.
- Withdrawing consent (Article 7 GDPR): If you have consented to our processing of your data, you can withdraw this consent at any time with effect for the future. This shall not affect the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR): You can also lodge a complaint with the relevant supervisory authority for data protection if you are of the opinion that the processing of your data infringes on applicable law. To do this, you can contact either the data protection authority with jurisdiction over your place of residence, workplace or place of the purported violation, or the data protection authority with jurisdiction over us.
The supervisory authority for data protection with jurisdiction over us is the State Data Protection and Freedom of Information Officer for Baden-Württemberg (LfDI) who can be reached at Königstraße 10a, 70173 Stuttgart, Germany, Tel.: +49 711 615541-0, Fax: +49 711 615541-15, Email: poststelle@lfdi.bwl.de, Website: www.baden-wuerttemberg.datenschutz.de.
You can also contact our Data Protection Officer directly in order to exercise your rights as a data subject. Please use the communication channels indicated under Sec. 11.
However, we recommend sending requests for information directly to and exercising other data subject rights directly against Meta where this makes more sense. This is because, as the provider of the Instagram platform, only Meta has direct access to the necessary information and only Meta is able to take any necessary steps or provide information.
To find out whether you can exercise your rights as a data subject against Meta, please refer to the Meta Privacy Policy (https://de-de.facebook.com/privacy/explanation/) and Instagram Privacy Policy (https://help.instagram.com/519522125107875). You can exercise certain rights via your Instagram account settings, in particular your right to:
- access the information concerning you that is stored on the platform and download this as an archive (https://www.instagram.com/download/request/),
- request to erase individual content, such as comments, or block certain accounts (https://www.instagram.com/accounts/data_controls_support/),
- temporarily deactivate your account (https://www.instagram.com/accounts/edit/).
- permanently delete your account (https://www.instagram.com/accounts/remove/request/permanent/).
12. Data Protection Officer
We have appointed a company Data Protection Officer. You can reach them via the following contact details:
ZKM Data Protection Officer
c/o V-Formation GmbH
Stephanienstr. 18
76133 Karlsruhe
Tel.: +49 (0) 721/17029034Email: datenschutz@zkm.de
You can reach the Data Protection Officer for Meta (as provider of the Instagram platform) using a contact form available on the Facebook platform: https://www.facebook.com/help/contact/540977946302970.
13. Safety and security
We implement technical and organizational security measures in order to protect your personal data against intentional or unintentional manipulation, loss, destruction, or access by authorized persons. These measures are always adjusted in line with the current state of the art.
Personal data concerning you that are transmitted in the context of your use of our Instagram presences are transmitted to us securely using encryption. Instagram does this using the Transport Layer Security (TLS), encryption protocol, largely known by its former name Secure Socket Layer (SSL).
Our employees are obliged to observe confidentiality.
14. Amendments
From time to time, it may be necessary to modify the content of this Privacy Policy. We reserve the right to amend this policy at any time. We will publish the amended version of the Privacy Policy in the same location as this current Privacy Policy. You should therefore read through the revised Privacy Policy the next time you visit our Instagram presences.
-
Twitter
Table of contents
1. Purpose of data protection and legal framework
2. General information on the Twitter platform
3. Making direct contact
4. User interactions
5. Cookies
6. User analysis ("Analytics" function)
7. Analytics and reports using Google Data Studio
8. Recipients of personal data
9. Data processing in third countries
10. Retention policy
11. Your rights
12. Data Protection Officer
13. Safety and security
14. AmendmentsAs the controller and simultaneously the service provider, we
ZKM | Zentrum für Kunst und Medien Karlsruhe
Public Foundation
Lorenzstraße 19
76135 Karlsruhe, Germany
Email: info@zkm.de
(Legal notice)(hereinafter also referred to as "we" or "ZKM")
hereby inform you of the processing of your personal data and of your rights as a data subject within the context of your use of the presences
https://twitter.com/zkmkarlsruhe („ZKM Karlsruhe“ - @zkmkarlsruhe)
https://twitter.com/zkm_collections („ZKM | Collection and Archives“ - @zkm_collections)(hereinafter referred to individually as "Twitter presence" or jointly as "Twitter presences")
which we operate on the social media platform Twitter (hereinafter "Twitter platform").
The provider of the Twitter platform, Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland (hereinafter also "Twitter"), is also responsible for data processing on our Twitter presences as controller in addition to us.
The processing of your personal data is performed exclusively within the framework of the provisions of data protection law, in particular the EU General Data Protection Regulation (hereinafter "GDPR"), and also the Data Protection Act of the State of Baden-Württemberg (hereinafter "LDSG BW") and other statutory provisions on data protection.
This Privacy Policy applies only to those of our Twitter presences indicated above. With respect to other (online or social media) presences of ZKM, only the privacy policies published on such presences apply. Furthermore, the following information does not apply to third-party social media presences or websites run by other operators which may be linked to from our Twitter presences.
The terms used in this Privacy Policy, such as "personal data" or "processing", are given the definitions contained under Article 4 GDPR. If you would like to read the GDPR or LDSG BW for yourself, you can find a copy at: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 and https://dejure.org/gesetze/LDSG respectively.
1. Purpose of data protection and legal framework
The purpose of data protection is to protect personal data. Personal data means all information relating to an identified or identifiable person (a so-called data subject). Therefore, your personal data includes all data that could be used to identify your person, e.g. your name, address, telephone number, or email address. Personal data also includes information generated by your use of our Twitter presences.
We only process your data where this is permitted by an applicable legal regulation. Unless otherwise described in the following sections of this Privacy Policy, the processing of your data is based on our legitimate interests (Article 6(1)(1), point (f) GDPR) in the commercial operation and optimization of our Twitter presences and in the analysis of the use of the same.
2. General information on the Twitter platform
We inform you that you use our Twitter presences and their functions, as well as the Twitter platform as a whole, under your own responsibility. This applies in particular to the use of interactive functions (e.g. likes, follows, comments, shares, polls).
Your use of the Twitter platform and data processing by Twitter is governed first and foremost by Twitter's Terms of Service (https://twitter.com/en/tos) and Privacy Policy (https://twitter.com/en/privacy).
Some parts of our Twitter presences can be used without registering with the Twitter platform. However, even if you are using the Twitter platform without registering, personal data may still be processed.
We hereby explicitly inform you that Twitter stores the data of users registered with the Twitter platform (hereinafter also "users") and other interested visitors to the Twitter platform (hereinafter also "visitors"), e.g. personal information, IP address, cookies etc., outside of the European Union (EU) or European Economic Area (EEA) and uses these data for its own commercial purposes.
We do not generally have any control over the collection and processing of data by Twitter. We have no knowledge of nor any control over how much, where, and for how long these data are stored, or the extent to which Twitter complies with existing erasure obligations, or what analyses and connections with data Twitter has undertaken, or who Twitter forwards these data to. We therefore kindly ask you to think carefully about the personal data you reveal as a user of the Twitter platform.
We operate our Twitter presences in order to keep users and visitors up-to-date with our company and our activities, and to interact with these same users and visitors. If you would like to stay up-to-date with us without using the Twitter platform, you can generally also access much of the information published via our Twitter presences on our Website (https://zkm.de/) and in particular at https://zkm.de/en/collections-archives.
3. Making direct contact
If you contact us directly via our Twitter presences (e.g. via direct message), we process the data you provide in this context (e.g. Your name, email address) solely for its intended purpose, and in order to receive and, where applicable, respond to your inquiry. Your data may also be transmitted to our systems for this purpose.
If this communication relates to initiation of a contractual relationship, the data that are transmitted via the Twitter platform within the context of making direct contact are processed on the basis of Article 6(1)(1), point (b) GDPR. If we ask you to consent to data processing, e.g. in relation to one of the forms we provide, the legal basis for this data processing is Article 6(1)(1), point (a) GDPR as applicable. Otherwise, the legal basis is our legitimate interest (Article 6(1)(1), point (f) GDPR) in processing contact requests sent to us voluntarily.
The confidentiality of the information you provide us with in the context of making direct contact is particularly important to us. Therefore, since we have no knowledge of how Twitter, as the provider of the Twitter platform, uses this information, please refrain from sending us sensitive data or other confidential information, e.g. application documents or bank/credit card details, via this channel. We recommend using a secure method of transmission for such data, such as ordinary mail.
4. User interactions
Due to the way in which a social media platform works, ZKM has the ability to identify users who like our Twitter presences and our posts, or who rate, comment or share such, provided their interactions on the Twitter platform are public and are not explicitly marked as "private". We analyze this information in aggregated form in order to create more relevant content for users and visitors to our Twitter presences which may be of greater interest to these persons. The information we obtain in this way does not allow us to identify any natural persons.
As a user of Twitter, you can actively hide your "tweets" or "followers" via your Twitter profile or unfollow our Twitter presences. You will then no longer appear in the lists of followers of our Twitter presences.
5. Cookies
Twitter uses cookies and cookie-related technologies, i.e. small files which are stored on your end device (hereinafter referred to jointly as "cookies") in order to provide you with greater functionality, to make your use of the platform more convenient, and to optimize their own offering. The data obtained using cookies is stored and processed directly by Twitter. ZKM has no access to these data nor any control over how Twitter uses them.
Twitter can use the information obtained via cookies within the Twitter platform and other Twitter services, and also in third-party services which Twitter services use, in order to generate user profiles for market research and advertising purposes. These processes take into account, in particular, your user behavior and the interests they derive from this. For example, Twitter can allow Twitter partners or even third parties to use these data in order to display advertising inside and outside the Twitter platform. If you use Twitter on multiple end devices, your data may be collected and analyzed across these devices, especially if you are logged in as a user.
More information on the nature, scope, purposes of processing, legal framework and relevant settings ("Opt-in"/"Opt-out") relating to the use of cookies by Twitter can be found in the Twitter Cookie Guidelines (https://help.twitter.com/en/rules-and-policies/twitter-cookies).
You also can block the storage of cookies by selecting "Block all cookies" in your browser or device settings. For details of how to manage and delete cookies via your browser or device settings, please refer to the Help function in your browser or on your device.
You can also block the storage of cookies using free browser add-ons such as "Adblock Plus" (https://adblockplus.org/) combined with the "EasyPrivacy" list (https://easylist.to).
However, blocking the storage of cookies may restrict the functionality of the Twitter presences.
6. User analysis ("Analytics" function)
In operating our Twitter presences, we use the Twitter platform's "Analytics" function, through which Twitter provides us with statistical data on the use of our Twitter presences. This data is anonymous for us, i.e. we cannot view the personal data of individual users or visitors. We are not aware of what data specifically Twitter uses in order to analyze the use of our Twitter presences ("Analytics data"). Specifically, we can see the following aggregated data: Number of so-called impressions, profile visits and followers (including trends for each of these areas over time).
7. Analytics and reports using Google Data Studio
We use Google Data Studio, an analytics service from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter "Google"), to compile reports and analyze aggregated data that are collected concerning our Website (www.zkm.de) and social media channels.
Google Data Studio uses aggregated data (e.g. number of visits, post reach etc.) from various data sources which we connect to Data Studio via Application Programming Interfaces (APIs). One of the data sources we have connected to Data Studio is our Twitter presences.
The information generated, such as information on the use of our social media channels, is generally transmitted to a Google server in the USA where it is stored. Google will use this information on our behalf to analyze the use of our social media channels in order to compile reports on activities and visualize these data. Our Data Studio Dashboard is configured such that analytics are performed exclusively on the basis of aggregated data, and not at a user or post level. Personally identifiable information, such as IP addresses, is not input into Data Studio.
However, in the interests of data protection, we have concluded a data processing agreement with Google which also applies to the use of the Google Data Studio app.
Analytics do not require a specific legal basis due to the upstream aggregation of data (collation) and the subsequent lack of personally identifiable information in the data in Google Data Studio. Where necessary, the legal basis for this upstream aggregation is our legitimate interest according to Article 6(1)(1), point (f) GDPR. Our legitimate interest consists in analyzing the use of our social media channels and our Website so that we can continuously improve both of these.
8. Recipients of personal data
We only ever forward your personal data to external recipients where this is necessary in order to handle or process your inquiry, or we have your consent to do so, or we have other permission to do so under law. Such a transmission of data is thus based on Article 6(1)(1), point (c) and/or point (f) GDPR, whichever applies to the individual case. External recipients may also include data processors (e.g. technical service providers) who use personal data exclusively for the purposes we have specified and according to our instructions, subject to compliance with the legal requirements of Article 28 GDPR.
Data may also be transmitted to other private and public agencies, e.g. tax advisors, financial auditors, supervisory authorities, public prosecutors, or courts. Such transmissions are based on Article 6(1)(1), point (c) and/or point (f) GDPR.
For details of how Twitter transmits your data within and outside of the Twitter Group, please refer to the Twitter Privacy Policy (https://twitter.com/en/privacy).
9. Data processing in third countries
Insofar as we transmit your data to third countries outside of the EU or EEA according to the explanations above, we ensure prior to this transmission that, notwithstanding the exceptions permitted by law, the recipient has an appropriate level of data protection or you consent to this transmission of data. An appropriate level of data protection can be guaranteed by conclusion of EU standard contractual clauses, for example, or the existence of so-called Binding Corporate Rules (BCR).
We can provide you with an overview of recipients in third-party states and a copy of the concrete regulations that have been agreed in order to ensure the appropriate level of data protection. Please do not hesitate to get in touch with our Data Protection Officer directly at datenschutz@zkm.de.
Twitter regularly processes data in third countries outside of the EU/EEA, in particular in the USA. Data transfers to the USA are subject to so-called EU standard contractual clauses.
10. Retention policy
We only store your personal data for as long as this is necessary in order to fulfill the relevant purposes or – if you give your consent – until such time as you withdraw your consent. If you do withdraw your consent, we will stop processing your personal data unless we are permitted or required to continue processing according to the relevant statutory provisions (e.g. within the context of retention obligations under commercial and tax law). We will also erase your personal data where we are required to do so for legal reasons.
We review the necessity of the personal data we are storing on the Twitter platform at least once per year and carry out corresponding erasure routines, during which we erase messages sent to us, for example. However, since we do not have control over the technology behind the Twitter platform, we cannot guarantee that Twitter does in fact subsequently erase the data we have erased.
In principle, we have no control over how Twitter stores or erases your data within the context of the Twitter platform.
For details, please refer to the Twitter Privacy Policy (https://twitter.com/en/privacy).
11. Your rights
As a data subject, you have a number of rights. These rights are:
- Right of access (Article 15 GDPR, § 21 LDSG BW);
- Right to rectification (Article 16 GDPR);
- Right to erasure (Article 17 GDPR, § 23 LDSG BW);
- Right to restriction of processing (Article 18 GDPR);
- Right to data portability (Article 20 GDPR).
- Right to object to data processing on the grounds of legitimate interests (Article 21 GDPR): You have the right to object, on grounds relating to your particular situation, to our processing of personal data, provided this is based on legitimate interests within the meaning of Article 6(1)(1), point (f) GDPR. If you make use of your right to object, we will stop processing your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, or this processing serves to establish, exercise or defend legal claims.
- Withdrawing consent (Article 7 GDPR): If you have consented to our processing of your data, you can withdraw this consent at any time with effect for the future. This shall not affect the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR): You can also lodge a complaint with the relevant supervisory authority for data protection if you are of the opinion that the processing of your data infringes on applicable law. To do this, you can contact either the data protection authority with jurisdiction over your place of residence, workplace or place of the purported violation, or the data protection authority with jurisdiction over us.
The supervisory authority for data protection with jurisdiction over us is the State Data Protection and Freedom of Information Officer for Baden-Württemberg (LfDI) who can be reached at Königstraße 10a, 70173 Stuttgart, Germany, Tel.: +49 711 615541-0, Fax: +49 711 615541-15, Email: poststelle@lfdi.bwl.de, Website: www.baden-wuerttemberg.datenschutz.de.
You can also contact our Data Protection Officer directly in order to exercise your rights as a data subject. Please use the communication channels indicated under Sec. 11.
However, we recommend sending requests for information directly to and exercising other data subject rights directly against Twitter where this makes more sense. This is because, as the provider of the Twitter platform, only Twitter has direct access to the necessary information and only Twitter is able to take any necessary steps or provide information.
To find out whether you can exercise your rights as a data subject against Twitter, please refer to the Twitter Privacy Policy (https://twitter.com/en/privacy). You can exercise certain rights directly against Twitter, in particular your right to:
- access the information concerning you that is stored on the Twitter platform and download this as an archive (https://help.twitter.com/de/managing-your-account/how-to-download-your-twitter-archive),
- request deletion of individual Twitter posts from Google search (https://help.twitter.com/de/safety-and-security/remove-twitter-profile-from-google-search),
- deactivate your account (https://help.twitter.com/de/managing-your-account/how-to-deactivate-twitter-account).
We also recommend regularly reviewing your settings in order to protect your privacy on the Twitter platform. Specifically, as a user of Twitter you can configure your settings via the Twitter Safety Settings (https://twitter.com/settings/safety).
12. Data Protection Officer
We have appointed a company Data Protection Officer. You can reach them via the following contact details:
ZKM Data Protection Officer
c/o V-Formation GmbH
Stephanienstr. 18
76133 Karlsruhe
Tel.: +49 (0) 721/17029034Email: datenschutz@zkm.de
You can reach the Data Protection Officer for Twitter using a contact form provided by Twitter: https://twitter.ethicspointvp.com/custom/twitter/forms/data/form_data.asp?lang=en.
13. Safety and security
We implement technical and organizational security measures in order to protect your personal data against intentional or unintentional manipulation, loss, destruction, or access by authorized persons. These measures are always adjusted in line with the current state of the art.
Personal data concerning you that are transmitted in the context of your use of our Twitter presences are transmitted to us securely using encryption. Twitter does this using the Transport Layer Security (TLS), encryption protocol, largely known by its former name Secure Socket Layer (SSL).
Our employees are obliged to observe confidentiality.
14. Amendments
From time to time, it may be necessary to modify the content of this Privacy Policy. We reserve the right to amend this policy at any time. We will publish the amended version of the Privacy Policy in the same location as this current Privacy Policy. You should therefore read through the revised Privacy Policy the next time you visit our Twitter presences.
-
LinkedIn
-
Facebook
-
YouTube
Table of contents
1. Purpose of data protection and legal framework
2. General information on the YouTube platform
3. Making direct contact
4. User interactions
5. Cookies
6. User analysis ("Analytics" function)
7. Analytics and reports using Google Data Studio
8. Recipients of personal data
9. Data processing in third countries
10. Retention policy
11. Your rights
12. Data Protection Officer
13. Safety and security
14. AmendmentsAs the controller and simultaneously the service provider, we
ZKM | Zentrum für Kunst und Medien Karlsruhe
Public Foundation
Lorenzstraße 19
76135 Karlsruhe, Germany
Email: info@zkm.de
(Legal notice)(hereinafter also referred to as "we" or "ZKM")
hereby inform you of the processing of your personal data and of your rights as a data subject within the context of your use of the presence
https://www.youtube.com/zkmkarlsruhe ("ZKM Karlsruhe")
(hereinafter "YouTube channel")
which we operate on the social media platform YouTube (hereinafter "YouTube platform").
The provider of the YouTube platform, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter also "Google"), is also responsible for data processing on our YouTube channel as controller in addition to us.
The processing of your personal data is performed exclusively within the framework of the provisions of data protection law, in particular the EU General Data Protection Regulation (hereinafter "GDPR"), and also the Data Protection Act of the State of Baden-Württemberg (hereinafter "LDSG BW") and other statutory provisions on data protection.
This Privacy Policy applies only to our YouTube channel as indicated above. With respect to other (online or social media) presences of ZKM, only the privacy policies published on such presences apply. Furthermore, the following information does not apply to third-party social media presences or websites run by other operators which may be linked to from our YouTube channel.
The terms used in this Privacy Policy, such as "personal data" or "processing", are given the definitions contained under Article 4 GDPR. If you would like to read the GDPR or LDSG BW for yourself, you can find a copy at: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 and https://dejure.org/gesetze/LDSG respectively.
1. Purpose of data protection and legal framework
The purpose of data protection is to protect personal data. Personal data means all information relating to an identified or identifiable person (a so-called data subject). Therefore, your personal data includes all data that could be used to identify your person, e.g. your name, address, telephone number, or email address. Personal data also includes information generated by your use of our YouTube channel.
We only process your data where this is permitted by an applicable legal regulation. Unless otherwise described in the following sections of this Privacy Policy, the processing of your data is based on our legitimate interests (Article 6(1)(1), point (f) GDPR) in the commercial operation and optimization of our YouTube channel and in the analysis of the use of the same.
2. General information on the YouTube platform
We inform you that you use our YouTube channel and its functions, as well as the YouTube channel platform as a whole, under your own responsibility. This applies in particular to the use of interactive functions (e.g. likes, subscribes, comments, shares).
Your use of the YouTube platform and data processing by Google as provider of the YouTube platform is governed first and foremost by the Terms of Service for the YouTube platform (https://www.youtube.com/t/terms) and the Google Privacy Policy (https://policies.google.com/privacy?hl=en).
Some parts of our YouTube channel can be used without registering with the YouTube platform. However, even if you are using the YouTube platform without registering, personal data may still be processed.
We hereby explicitly inform you that Google, as provider of the YouTube platform, stores the data of users registered with the YouTube platform (hereinafter also "users") and other interested visitors to the YouTube platform (hereinafter also "visitors"), e.g. personal information, IP address, cookies etc., outside of the European Union (EU) or European Economic Area (EEA) and uses these data for its own commercial purposes.
We do not generally have any control over the collection and processing of data by Google as the provider of the YouTube platform. We have no knowledge of nor any control over how much, where, and for how long these data are stored, or the extent to which Google, as the provider of the YouTube platform, complies with existing erasure obligations, or what analyses and connections with data Google has undertaken, or who Google forwards these data to. We therefore kindly ask you to think carefully about the personal data you reveal as a user of the YouTube platform.
We operate our YouTube channel in order to keep users and visitors up-to-date with our company and our activities, primarily by sharing videos, and to interact with these same users and visitors. If you would like to stay up-to-date with us without using the YouTube platform, you can alternatively access much of the information published via our YouTube channel on our Website https://zkm.de/en/collection-archives/video-audio.
3. Making direct contact
If you contact us directly via our YouTube channel (e.g. via direct message), we process the data you provide in this context (e.g. Your name, email address) solely for its intended purpose, and in order to receive and, where applicable, respond to your inquiry. Your data may also be transmitted to our systems for this purpose.
If this communication relates to initiation of a contractual relationship, the data that are transmitted via the YouTube platform within the context of making direct contact are processed on the basis of Article 6(1)(1), point (b) GDPR. If we ask you to consent to data processing, e.g. in relation to one of the forms we provide, the legal basis for this data processing is Article 6(1)(1), point (a) GDPR as applicable. Otherwise, the legal basis is our legitimate interest (Article 6(1)(1), point (f) GDPR) in processing contact requests sent to us voluntarily.
The confidentiality of the information you provide us with in the context of making direct contact is particularly important to us. Therefore, since we have no knowledge of how Google, as the provider of the YouTube platform, uses this information, please refrain from sending us sensitive data or other confidential information, e.g. application documents or bank/credit card details, via this channel. We recommend using a secure method of transmission for such data, such as ordinary mail.
4. User interactions
Due to the way in which a social media platform works, ZKM has the ability to identify users who like our YouTube channel and our posts, or who rate, comment or share such, provided their interactions on the YouTube platform are public and are not explicitly marked as "private". We analyze this information in aggregated form in order to create more relevant content for users and visitors to our YouTube channel which may be of greater interest to these persons. The information we obtain in this way does not allow us to identify any natural persons.
As a user of YouTube, you can use your YouTube profile to mark videos you have posted, playlists you have created, and which YouTube channels you follow as private so that other users cannot view these. You can also choose to unsubscribe from our YouTube channel. You will then no longer appear in the list of subscribers to our YouTube channel.
5. Cookies
The YouTube platform uses cookies and cookie-related technologies, i.e. small files which are stored on your end device (hereinafter referred to jointly as "cookies") in order to provide you with greater functionality, to make your use of the platform more convenient, and to optimize their own offering. Data obtained using cookies is stored and processed directly by Google as the provider of the YouTube platform. ZKM has no access to these data nor any control over how Google uses them.
As the provider of the YouTube platform, Google can use the information obtained using cookies within the YouTube platform and other Google services, and also in third-party services which Google services use, in order to generate user profiles for market research and advertising purposes. These processes take into account, in particular, your user behavior and the interests they derive from this. For example, as the provider of the YouTube platform, Google can allow Google partners or even third parties to use these data in order to display advertising inside and outside the YouTube platform. If you use YouTube on multiple end devices, your data may be collected and analyzed across these devices, especially if you are logged in as a user.
More information on the nature, purposes, legal framework and relevant settings ("Opt-in"/"Opt-out") relating to the use of cookies on the YouTube platform can be found in the Privacy and Terms of the Google website under "How Google uses cookies“ (https://policies.google.com/technologies/cookies?hl=de&utm_source=ucb).
You also can block the storage of cookies by selecting "Block all cookies" in your browser or device settings. For details of how to manage and delete cookies via your browser or device settings, please refer to the Help function in your browser or on your device.
According to information provided by Google as provider of the YouTube platform, cookies are stored and used in connection with personalized advertising and other personalized offers only if you have consented to such (Article 6(1)(1), point (a) GDPR). According to information provided by Google, as the provider of the YouTube platform, it is not possible to block other cookies for the purposes of analysis and research, and also functional cookies and cookies which are used to guarantee the safety and security of visitors, users and the YouTube platform, to identify users when they use the YouTube platform, to access settings, and to ensure the functionality of the YouTube platform.
You can also block the storage of cookies using free browser add-ons such as "Adblock Plus" (https://adblockplus.org/) combined with the "EasyPrivacy" list (https://easylist.to).
However, blocking the storage of cookies may restrict the functionality of the YouTube platform.
6.User analysis ("Analytics" function)
In operating our YouTube channel, we use the YouTube platform's "Analytics" function, through which Google, as the provider of the YouTube platform, provides us with statistical data on the use of our YouTube channel. This data is anonymous for us, i.e. we cannot view the personal data of individual users or visitors. We are not aware of what data specifically Google, as the provider of the YouTube platform, uses in order to analyze the use of our YouTube channel ("Analytics data"). Specifically, we can view the following aggregated data: Overview (e.g. number of views, total length of video views), reach (e.g. types of sources, from which videos are accessed), interaction (e.g. information on videos with the longest playback time), target group (e.g. age, gender and region of viewers), income (e.g. information on anticipated income and sources of income).
7. Analytics and reports using Google Data Studio
In addition to the "Analytics" function on the YouTube platform, we also analyze our YouTube channel using Google Data Studio, an analysis service provided by Google LLC/Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043-1351, USA ("Google").
Google Data Studio uses data from various data sources which we connect to the tool. The information generated, such as information on the use of our YouTube channel, is generally transmitted to a Google server in the USA where it is stored. Google will use this information on behalf of ZKM to analyze your use of our YouTube channel in order to compile reports on activities on our YouTube channel and, where applicable, to render services for ZKM.
The purpose of Google Data Studio is to analyze numbers of visitors to our YouTube channel. Google uses the data and information obtained to analyze the use of our YouTube channel in order to compile online reports visualizing the activities on our YouTube channel, and to render other services pertaining to the use of our YouTube channel.
The legal basis for using Google Data Studio is our legitimate interest according to Article 6(1)(1), point (f) GDPR. Our legitimate interest here consists in the continuous improvement and commercial operation of our YouTube channel.
We have concluded a data processing agreement with YouTube. In instances where personal data are transmitted to the USA, we base this transmission on the EU standard contractual clauses concluded between us and Google.
8. Recipients of personal data
We only ever forward your personal data to external recipients where this is necessary in order to handle or process your inquiry, or we have your consent to do so, or we have other permission to do so under law. Such a transmission of data is thus based on Article 6(1)(1), point (c) and/or point (f) GDPR, whichever applies to the individual case. External recipients may also include data processors (e.g. technical service providers) who use personal data exclusively for the purposes we have specified and according to our instructions, subject to compliance with the legal requirements of Article 28 GDPR.
Data may also be transmitted to other private and public agencies, e.g. tax advisors, financial auditors, supervisory authorities, public prosecutors, or courts. Such transmissions are based on Article 6(1)(1), point (c) and/or point (f) GDPR.
For details of how Google, as provider of the YouTube platform, transmits your data within and outside of the Google Group, please refer to the Google Privacy Policy (https://policies.google.com/privacy).
9. Data processing in third countries
Insofar as we transmit your data to third countries outside of the EU or EEA according to the explanations above, we ensure prior to this transmission that, notwithstanding the exceptions permitted by law, the recipient has an appropriate level of data protection or you consent to this transmission of data. An appropriate level of data protection can be guaranteed by conclusion of EU standard contractual clauses, for example, or the existence of so-called Binding Corporate Rules (BCR).
We can provide you with an overview of recipients in third-party states and a copy of the concrete regulations that have been agreed in order to ensure the appropriate level of data protection. Please do not hesitate to get in touch with our Data Protection Officer directly at datenschutz@zkm.de.
As the provider of the YouTube platform, Google regularly processes data in third countries outside of the EU/EEA, in particular in the USA. Data transfers to the USA are subject to so-called EU standard contractual clauses.
10. Retention policy
We only store your personal data for as long as this is necessary in order to fulfill the relevant purposes or – if you give your consent – until such time as you withdraw your consent. If you do withdraw your consent, we will stop processing your personal data unless we are permitted or required to continue processing according to the relevant statutory provisions (e.g. within the context of retention obligations under commercial and tax law). We will also erase your personal data where we are required to do so for legal reasons.
We review the necessity of the personal data we are storing on the YouTube platform at least once per year and carry out corresponding erasure routines, during which we erase messages sent to us, for example. However, since we do not have control over the technology behind the YouTube platform, we cannot guarantee that Google, as the provider of the YouTube platform, does in fact subsequently erase the data we have erased.
In principle, we have no control over how Google, as the provider of the YouTube platform, stores or erases your data within the context of the YouTube platform.
For details, please refer to the Google Privacy Policy (https://policies.google.com/privacy).
11. Your rights
As a data subject, you have a number of rights. These rights are:
- Right of access (Article 15 GDPR, § 21 LDSG BW);
- Right to rectification (Article 16 GDPR);
- Right to erasure (Article 17 GDPR, § 23 LDSG BW);
- Right to restriction of processing (Article 18 GDPR);
- Right to data portability (Article 20 GDPR).
- Right to object to data processing on the grounds of legitimate interests (Article 21 GDPR): You have the right to object, on grounds relating to your particular situation, to our processing of personal data, provided this is based on legitimate interests within the meaning of Article 6(1)(1), point (f) GDPR. If you make use of your right to object, we will stop processing your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, or this processing serves to establish, exercise or defend legal claims.
- Withdrawing consent (Article 7 GDPR): If you have consented to our processing of your data, you can withdraw this consent at any time with effect for the future. This shall not affect the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR): You can also lodge a complaint with the relevant supervisory authority for data protection if you are of the opinion that the processing of your data infringes on applicable law. To do this, you can contact either the data protection authority with jurisdiction over your place of residence, workplace or place of the purported violation, or the data protection authority with jurisdiction over us.
The supervisory authority for data protection with jurisdiction over us is the State Data Protection and Freedom of Information Officer for Baden-Württemberg (LfDI) who can be reached at Königstraße 10a, 70173 Stuttgart, Germany, Tel.: +49 711 615541-0, Fax: +49 711 615541-15, Email: poststelle@lfdi.bwl.de, Website: www.baden-wuerttemberg.datenschutz.de.
You can also contact our Data Protection Officer directly in order to exercise your rights as a data subject. Please use the communication channels indicated under Sec. 11.
However, we recommend sending requests for information directly to and exercising other data subject rights directly against Google, as the provider of the YouTube platform, where this makes more sense. This is because as the provider of the YouTube platform, only Google has direct access to the necessary information and only Google is able to take any necessary steps or provide information.
To find out whether you can exercise your rights as a data subject against Google, as the provider of the YouTube platform, please refer to the Google Privacy Policy (https://policies.google.com/privacy). You can exercise certain rights directly against Google, in particular your right to:
- access the information concerning you that is stored on the platform and download this as an archive;
- request deletion of your activities or your profile across all or certain Google services;
- delete your entire Google account.
Relevant details and instructions can be found at https://support.google.com/policies/answer/9581826?hl=en&visit_id=637551018509708100-3057127733&rd=1#zippy=%2Ckontakt-zur-datenschutzabteilung-von-google-aufnehmen%2Cmeine-daten-aus-google-produkten-und-diensten-herunterladen.
We also recommend regularly reviewing your settings in order to protect your privacy on the YouTube platform. Specifically, as a YouTube user you can configure your settings in YouTube's Account Privacy Settings (https://www.youtube.com/account_privacy) and Google's Privacy Settings (https://policies.google.com/privacy#infochoices).
12. Data Protection Officer
We have appointed a company Data Protection Officer. You can reach them via the following contact details:
ZKM Data Protection Officer
c/o V-Formation GmbH
Stephanienstr. 18
76133 Karlsruhe
Tel.: +49 (0) 721/17029034Email: datenschutz@zkm.de
You can reach the Data Protection Team for Google (as provider of the YouTube platform) using an online contact form available on the Google website: https://support.google.com/policies/contact/general_privacy_form.
13. Safety and security
We implement technical and organizational security measures in order to protect your personal data against intentional or unintentional manipulation, loss, destruction, or access by authorized persons. These measures are always adjusted in line with the current state of the art.
Personal data concerning you that are transmitted in the context of your use of our YouTube channel are transmitted to us securely using encryption. Google, as the provider of the YouTube platform, does this using the Transport Layer Security (TLS), encryption protocol, largely known by its former name Secure Socket Layer (SSL). According to Google, 100% of YouTube traffic has been encrypted since the start of 2020 (https://transparencyreport.google.com/https/overview?hl=en).
Our employees are obliged to observe confidentiality.
14. Amendments
From time to time, it may be necessary to modify the content of this Privacy Policy. We reserve the right to amend this policy at any time. We will publish the amended version of the Privacy Policy in the same location as this current Privacy Policy. You should therefore read through the revised Privacy Policy the next time you visit our YouTube channel.
-
Vimeo
Last updated: July 2022