Privacy Policy
Below you will find the privacy policy for our website, including our registration tool.
Further information regarding further data processing can be found at the end of this privacy policy.
- Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data means any data by which you can be personally identified. Detailed information on data protection can be found in the privacy policy set out below.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. The operator’s contact details can be found in the section “Information on the controllers” in this privacy policy.
How do we collect your data?
Some data is collected when you provide it to us. This may include, for example, data that you enter in a contact form.
Other data is collected automatically by our IT systems when you visit the website or after you have given your consent. This primarily comprises technical data (e.g. internet browser, operating system or time of the page view). This data is collected automatically as soon as you access this website.
What do we use your data for?
Some data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour. Where contracts can be concluded or initiated via the website, the data submitted is also processed for contractual offers, orders or other service enquiries.
What rights do you have regarding your data?
You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the rectification or erasure of this data. If you have given consent to data processing, you may withdraw this consent at any time with effect for the future. You also have the right, under certain circumstances, to request restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time regarding this or any other questions concerning data protection.
Analytics tools and third-party tools
When you visit this website, your browsing behaviour may be statistically analysed. This is done primarily using analytics programs.
Detailed information on these analytics programs can be found in the following privacy policy.
- Hosting and Content Delivery Networks (CDN)
We host the content of our website with the following provider:
External hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the hosting provider(s). This may include, in particular, IP addresses, contact enquiries, metadata and communication data, contractual data, contact details, names, website access data and other data generated via a website.
External hosting is carried out for the purpose of performing contracts with our prospective and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of the secure, fast and efficient provision of our online services by a professional provider (Art. 6 para. 1 lit. f GDPR). Where consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Our hosting provider will process your data only to the extent necessary to fulfil their contractual obligations and will follow our instructions with regard to this data.
We use the following hosting provider:
SiteGround Spain S.L.
Calle de Prim 19
28004 Madrid
Spain
TUMO Ventures has concluded a data processing agreement (DPA) for the use of the above service. This is a contract required under data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Hosting of the registration page (Microsoft Azure)
The registration page available at https://register.ffm.tumo.org/ is operated by TUMO Ventures in its own technical environment within the Microsoft Azure cloud infrastructure. The provider of the cloud infrastructure is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter “Microsoft”).
When the registration page is used, Microsoft processes server log data and other technical data in particular, insofar as this is necessary for the provision, security and stability of the infrastructure. Processing is carried out in the interest of the secure, fast and reliable provision of the registration page on the basis of Art. 6 para. 1 lit. f GDPR and, insofar as processing is required to handle the registration, on the basis of Art. 6 para. 1 lit. b GDPR.
TUMO Ventures has concluded a data processing agreement with Microsoft. Where processing takes place outside the European Union or the European Economic Area, the safeguards contained in the Microsoft Products and Services Data Protection Addendum apply, in particular the European Commission’s Standard Contractual Clauses. Further information: https://www.microsoft.com/privacy/privacystatement.
CDN – Cloudflare
We use the “Cloudflare” service. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).
Cloudflare provides a globally distributed content delivery network with DNS. The transfer of information between your browser and our website is technically routed through Cloudflare’s network. This enables Cloudflare to analyse the traffic between your browser and our website and to act as a filter between our servers and potentially malicious internet traffic. Cloudflare may also use cookies or other technologies to recognise internet users, but these are used solely for the purpose described here.
The use of Cloudflare is based on our legitimate interest in providing our website as securely and without errors as possible (Art. 6 para. 1 lit. f GDPR).
Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.
The company is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/participant/5666.
TUMO Ventures has concluded a data processing agreement (DPA) for the use of the above service. This is a contract required under data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
- General information and mandatory disclosures
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection provisions and this privacy policy.
When you use this website, various types of personal data are collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information on the controllers
A controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, email addresses or similar information).
The controllers responsible for data processing on this website are:
Technical operator:
TUMO Ventures, CSJC
16 Halabyan Street
0038 Yerevan
Armenia
Contact
Telephone: +374 10 398413
Email: pegor.papazian@tumo.org
Content operator:
Operator of TUMO Frankfurt:
Volkshochschule Frankfurt am Main
Sonnemannstraße 13
60314 Frankfurt am Main
Germany
Contact TUMO Frankfurt:
Telephone: +49 (0) 151 4 62 67 10 8
Email: frankfurt@tumo.de
Information on responsibility:
TUMO Ventures, CSJC is solely the technical operator of the website. It owns the domain, holds the contract with the hosting provider and creates the basic design. Volkshochschule Frankfurt is responsible for the content design, including the selection of the tools used on the website.
As part of the technical provision, TUMO Ventures, CSJC may also obtain access to data processed through the registration tools used (e.g. for administration, maintenance and error analysis).
TUMO Ventures is responsible for the content design of the registration page, including the selection of the tools used.
The parties have concluded an agreement on joint controllership pursuant to Art. 26 GDPR as well as a data processing agreement pursuant to Art. 28 GDPR.
Storage period
Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for processing the data no longer applies. If you assert a legitimate request for erasure or withdraw your consent to data processing, your data will be erased unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the data will be erased once those reasons no longer apply.
General information on the legal bases for data processing on this website
Where you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR if special categories of data within the meaning of Art. 9 para. 1 GDPR are processed. Where express consent has been given to the transfer of personal data to third countries, the data processing is also based on Art. 49 para. 1 lit. a GDPR. Where you have consented to the storage of cookies or access to information on your terminal device (e.g. through device fingerprinting), the processing is additionally based on Section 25 para. 1 TDDDG. Consent may be withdrawn at any time. Where your data is required for the performance of a contract or in order to take steps prior to entering into a contract, we process your data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, where your data is required to comply with a legal obligation, we process it on the basis of Art. 6 para. 1 lit. c GDPR. Data processing may also be based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Information on the legal bases applicable in each individual case is provided in the following sections of this privacy policy.
Data Protection Officer
Both parties have appointed data protection officers:
TUMO Frankfurt (Volkshochschule Frankfurt am Main):
TUMO Frankfurt’s Data Protection Coordinator can be contacted at datenschutz.tumo.vhs@stadt-frankfurt.de or by post at Datenschutz, TUMO Frankfurt, im Nordwestzentrum, Tituscorso 13, 60439 Frankfurt am Main, Germany.
The official Data Protection Officer of the City of Frankfurt can be contacted at datenschutz@stadt-frankfurt.de or by post at Stadt Frankfurt am Main, Referat für Datenschutz und Informationssicherheit (11B), Sandgasse 6, 60311 Frankfurt am Main, Germany.
TUMO Ventures:
Data Protection Officer
TUMO Ventures, CSJC
16 Halabyan Street
0038 Yerevan
Armenia
Email: dpo@tumo.org
Recipients of personal data
In the course of our business activities, we work with various external parties. In some cases, this also requires personal data to be transferred to these external parties. We disclose personal data to external parties only where this is necessary for the performance of a contract, where we are legally obliged to do so (e.g. disclosure to tax authorities), where we have a legitimate interest in the disclosure pursuant to Art. 6 para. 1 lit. f GDPR, or where another legal basis permits the disclosure. When using processors, we disclose our customers’ personal data only on the basis of a valid data processing agreement. In the case of joint processing, an agreement on joint processing is concluded.
Rights of data subjects
The parties have concluded an agreement on joint controllership pursuant to Art. 26 GDPR. Data subject rights may be exercised against either party; the parties ensure that requests are processed without undue delay and fulfilled in a coordinated manner.
Withdrawal of your consent to data processing
Many data processing operations are possible only with your express consent. You may withdraw consent that you have already given at any time. The lawfulness of the data processing carried out before the withdrawal remains unaffected by the withdrawal.
Right to object to data collection in specific cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).
WHERE YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract provided to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will be done only where technically feasible.
Access, rectification and erasure
Within the scope of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients and the purpose of the data processing, and, where applicable, a right to have this data rectified or erased. You may contact us at any time regarding this or any other questions concerning personal data.
Right to restriction of processing
You have the right to request restriction of the processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing applies in the following cases:
- If you dispute the accuracy of the personal data we have stored about you, we generally need time to verify this. For the duration of the verification, you have the right to request restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you may request restriction of data processing instead of erasure.
- If we no longer need your personal data, but you require it for the establishment, exercise or defence of legal claims, you have the right to request restriction of the processing of your personal data instead of erasure.
- If you have objected pursuant to Art. 21 para. 1 GDPR, your interests must be weighed against ours. As long as it has not yet been determined whose interests prevail, you have the right to request restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data may – apart from being stored – be processed only with your consent or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection because the address line of your browser changes from “http://” to “https://” and a padlock symbol appears in your browser bar.
If SSL or TLS encryption is enabled, data that you transmit to us cannot be read by third parties.
Objection to marketing emails
We hereby object to the use of contact details published as part of our legal notice obligations for the purpose of sending unsolicited advertising and information materials. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, for example through spam emails.
- Data collection on this website
Cookies
Our websites use “cookies”. Cookies are small data packages and do not cause any damage to your terminal device. They are stored on your terminal device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your terminal device until you delete them yourself or they are automatically deleted by your web browser.
Cookies may originate from us (first-party cookies) or from third-party companies (third-party cookies). Third-party cookies enable certain services provided by third-party companies to be integrated into websites (e.g. cookies for processing payment services).
Cookies perform various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g. the shopping basket function or the display of videos). Other cookies may be used to analyse user behaviour or for marketing purposes.
Cookies that are required to carry out the electronic communication process, to provide certain functions requested by you (e.g. the shopping basket function), or to optimise the website (e.g. cookies for measuring web audiences) (necessary cookies) are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimised provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of that consent (Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG); consent may be withdrawn at any time.
You can configure your browser to notify you when cookies are set, to permit cookies only in individual cases, to exclude the acceptance of cookies in certain cases or generally, and to activate the automatic deletion of cookies when the browser is closed. If cookies are disabled, the functionality of this website may be restricted.
If other cookies and services are used on this website, details can be found in this privacy policy.
Consent with Borlabs Cookie
Our website uses Borlabs Cookie consent technology to obtain your consent to the storage of certain cookies in your browser or to the use of certain technologies and to document this consent in compliance with data protection law. The provider of this technology is Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Germany (hereinafter “Borlabs”).
When you access our website, a Borlabs cookie is stored in your browser in which the consent you have given or the withdrawal of that consent is recorded. This data is not disclosed to the provider of Borlabs Cookie.
The data collected is stored until you request its erasure, delete the Borlabs cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected. Details on data processing by Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.
Borlabs Cookie consent technology is used to obtain the consent required by law for the use of cookies. The legal basis is Art. 6 para. 1 lit. c GDPR.
Proprietary consent solution on the registration page
The registration page available at https://register.ffm.tumo.org/ uses a consent solution developed by TUMO Ventures and operated within its own source code. No external provider is involved; data concerning your consent decision is not transferred to a third-party company.
The consent solution stores your selection in the “cc_cookie” cookie so that the cookie categories and consent choices you have selected can be taken into account during subsequent page views. Under the current configuration, the storage period is generally 182 days. Storage is necessary to comply with statutory accountability obligations. The legal basis is Art. 6 para. 1 lit. c GDPR; access to the terminal device takes place pursuant to Section 25 para. 2 no. 2 TDDDG.
You may change or withdraw your selection at any time via the cookie settings provided on the registration page.
Server log files
The provider of the pages automatically collects and stores information in server log files, which your browser automatically transmits to us. This information comprises:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data is not combined with other data sources.
This data is collected on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website – server log files must be collected for this purpose.
Contact form
If you send us an enquiry via the contact form, the information you provide in the enquiry form, including the contact details you enter there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We do not disclose this data without your consent.
This data is processed on the basis of Art. 6 para. 1 lit. b GDPR if your enquiry is related to the performance of a contract or is necessary in order to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in effectively handling the enquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR), where this has been requested; consent may be withdrawn at any time.
The data you enter in the contact form will remain with us until you request its erasure, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. after your enquiry has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Contact Form 7
This website uses the WordPress plugin Contact Form 7 to provide contact and enquiry forms. The plugin is operated locally on our servers.
Contact Form 7 enables us to record the data you enter in the form (e.g. name, email address, message/enquiry and, where applicable, other form fields) in a structured manner and process it in order to handle your enquiry.
Processing is based on our legitimate interest in handling enquiries efficiently (Art. 6 para. 1 lit. f GDPR) and – where the enquiry relates to the conclusion or performance of a contract – on Art. 6 para. 1 lit. b GDPR.
The data you enter in the form will remain with us until you request its erasure or the purpose for storing the data no longer applies (e.g. after your enquiry has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
ElemForm7 Pro
This website uses the ElemForm7 Pro plugin to extend or integrate form functions. The plugin is operated locally on our servers.
ElemForm7 Pro enables us to record form entries in a structured manner and process them for the purpose of handling enquiries/registrations. The data you enter in the form (e.g. contact details and content data) is processed in this context.
Processing is based on our legitimate interest in providing user-friendly forms and handling form enquiries efficiently (Art. 6 para. 1 lit. f GDPR) and – where applicable – in order to take steps prior to entering into a contract or to perform a contract (Art. 6 para. 1 lit. b GDPR).
The data you enter in the form will remain with us until you request its erasure or the purpose for storing the data no longer applies. Mandatory statutory provisions – in particular retention periods – remain unaffected.
Enquiries by email or telephone
If you contact us by email or telephone, your enquiry, including all personal data arising from it (name, enquiry), will be stored and processed by us for the purpose of handling your request. We do not disclose this data without your consent.
This data is processed on the basis of Art. 6 para. 1 lit. b GDPR if your enquiry is related to the performance of a contract or is necessary in order to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in effectively handling the enquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR), where this has been requested; consent may be withdrawn at any time.
The data sent to us in connection with contact enquiries will remain with us until you request its erasure, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. after your request has been fully processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Microsoft Forms
We use Microsoft Forms for registration for our information events. The provider of the service is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter “Microsoft”).
When you complete the registration form, we process the information you select and enter. This includes, in particular, the selected event date, your first and last name and your email address. In addition, technical data may be processed when the form is accessed and used, such as the IP address, browser and device information, and the date and time of access.
Processing is carried out for the purpose of receiving and handling your registration, allocating the available places, organising and holding the information event, and communicating with you in relation to the event.
The legal basis for processing is Art. 6 para. 1 lit. b GDPR, as processing is necessary to handle your registration and enable your participation in the event you have requested.
Microsoft processes the data on our behalf as a processor. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Microsoft.
Microsoft has established an EU Data Boundary for its Microsoft 365 enterprise services. Where a Microsoft 365 tenant is located within the European Union or the European Economic Area, customer data and personal data are generally stored and processed within the EU or the EEA. In limited cases, however, access or processing outside the EU or EEA cannot be completely ruled out, for example in connection with support, security or maintenance services.
Where personal data is transferred to countries outside the European Union or the European Economic Area, the transfer is based on the data protection safeguards contained in the Microsoft Products and Services Data Protection Addendum, in particular the European Commission’s Standard Contractual Clauses.
The data submitted through the form will be erased once the relevant information event has taken place and the related communication has been completed, unless statutory retention obligations or other legal grounds require longer storage.
Further information on data processing by Microsoft can be found in Microsoft’s privacy statement.
According to Microsoft’s current information, Microsoft Forms is included in the EU Data Boundary. Microsoft also provides a current Data Protection Addendum governing processing on behalf of customers and the Standard Contractual Clauses.
Registration form (operated in-house)
We provide a registration form on this website. The provider and controller responsible for data processing in connection with the registration form is TUMO Ventures, CSJC, 16 Halabyan Street, 0038 Yerevan, Armenia.
The registration form enables us to record and process registrations and the information submitted in connection with them in a structured manner and – where necessary – to communicate with you regarding the registration. The data you enter is transferred directly to TUMO 365, TUMO Ventures’ central administration system, and processed there. TUMO Frankfurt accesses the registration data in order to process and organise the registration and to run the TUMO programme. In connection with hosting, technical monitoring and audience measurement, the service providers named in the following sections may receive personal data as processors.
Authorised employees of TUMO Ventures in Armenia also have the technical ability to access the registration data stored in TUMO 365. As a rule, TUMO Ventures does not access this data. Access may, however, be necessary in particular to administer and maintain the system, provide support or rectify errors. Armenia is a third country outside the European Union and the European Economic Area for which no adequacy decision by the European Commission exists. The technical ability to access the data from Armenia therefore already constitutes a transfer to a third country. The transfer is based on the European Commission’s Standard Contractual Clauses agreed between the joint controllers. In addition, the risks associated with the transfer have been assessed and appropriate technical and organisational safeguards have been agreed.
The registration form is used on the basis of our legitimate interest in processing registrations in the most user-friendly manner possible (Art. 6 para. 1 lit. f GDPR). Insofar as processing is necessary in order to take steps prior to entering into a contract or to perform a contract, it is also based on Art. 6 para. 1 lit. b GDPR.
The data you enter in the form will remain with us until you request its erasure or the purpose for storing the data no longer applies, for example once the registration has been fully processed. Where processing is based on your consent, the relevant data will also be erased if you withdraw your consent and there is no other legal basis for continued processing. Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
Note: Any tracking or analytics tools used on the website are explained in the relevant sections of this privacy policy.
- Analytics tools and advertising
Google Tag Manager (registration page)
Google Tag Manager is used on the registration page. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to manage and control other website tags. Tag Manager does not itself create user profiles; however, when the service is accessed, technical data, in particular the IP address, may be transmitted to Google. The other data processed depends on the services integrated through Tag Manager.
Google Tag Manager and the non-essential analytics tags controlled through it are loaded only after you have given your consent. The legal bases are Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. You may withdraw your consent at any time via the cookie settings.
Google is certified under the EU-U.S. Data Privacy Framework. The European Commission’s Standard Contractual Clauses may also be used. Further information: https://policies.google.com/privacy?hl=en.
Google Analytics 4 (registration page)
Google Analytics 4 is used on the registration page. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables the use of the registration page to be statistically analysed. In particular, page views, interactions, technical device and browser information, approximate location data and referrer information may be processed.
Google Analytics uses, in particular, the “_ga” and “_ga_RF0SEMQT17” cookies. Under the current configuration, their storage period is up to two years. User-related and event-related data stored in the Analytics system is retained in accordance with the retention period configured in the Google Analytics property.
The service is used exclusively on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. You may withdraw your consent at any time via the cookie settings.
Google is certified under the EU-U.S. Data Privacy Framework. The European Commission’s Standard Contractual Clauses may also be used. Further information: https://policies.google.com/privacy?hl=en.
Datadog Real User Monitoring (registration page)
Datadog Real User Monitoring (RUM) is used on the registration page. The provider is Datadog, Inc., 620 8th Avenue, 45th Floor, New York, NY 10018, USA. Datadog is used to monitor the technical performance, stability and absence of errors on the registration page. In particular, page views, interactions, loading times, error messages, the IP address, and browser, device and session information may be processed.
Datadog uses the “_dd_s” cookie to group events generated within a session. The cookie expires 15 minutes after the last activity; it may be renewed during use, with the maximum session duration under the current configuration being approximately four hours.
The service is used exclusively on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. You may withdraw your consent at any time via the cookie settings.
TUMO Ventures has concluded a data processing agreement with Datadog. Where data is transferred to the USA or other third countries, Datadog bases the transfer in particular on the European Commission’s Standard Contractual Clauses. Further information: https://www.datadoghq.com/legal/privacy/ and https://www.datadoghq.com/legal/data-processing-addendum/.
Hotjar (registration page)
This website uses Hotjar. The provider is Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe (website: https://www.hotjar.com).
Hotjar is a tool for analysing your user behaviour on this website. Hotjar enables us, among other things, to record your mouse and scrolling movements and clicks. Hotjar can also determine how long you leave your mouse pointer in a particular place. This information is used to create heat maps showing which areas of the website are viewed most frequently by visitors.
We can also determine how long you remain on a page and when you leave it. We can also determine at what point you abandoned your entries in a contact form (conversion funnels).
Hotjar can also be used to obtain direct feedback from website visitors. This function is used to improve the website operator’s online services.
Hotjar uses technologies that enable users to be recognised for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting).
Hotjar is used exclusively on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. You may withdraw your consent at any time via the cookie settings.
Disabling Hotjar
If you wish to disable data collection by Hotjar, click on the following link and follow the instructions provided there: https://www.hotjar.com/policies/do-not-track/
Please note that Hotjar must be disabled separately for each browser and each terminal device.
Further information about Hotjar and the data collected can be found in Hotjar’s privacy policy at: https://www.hotjar.com/privacy
TUMO Ventures has concluded a data processing agreement (DPA) for the use of the above service. This is a contract required under data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Cloudflare Statistics / Web Analytics (registration page)
Cloudflare Web Analytics is used on the registration page. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).
Cloudflare Web Analytics is used for privacy-friendly statistical analysis and to measure the technical performance of the registration page. In particular, page views, paths accessed, referrers, country, browser and operating system information and performance metrics are processed. According to Cloudflare, Web Analytics does not use cookies or local storage and does not fingerprint visitors.
Processing is based on our legitimate interest in audience measurement and in the technical optimisation and secure provision of the registration page pursuant to Art. 6 para. 1 lit. f GDPR. As Cloudflare Web Analytics does not store any information on your terminal device or access information already stored on it under the configuration used, consent pursuant to Section 25 para. 1 TDDDG is not required.
Where data is transferred to the USA, the transfer may be based on Cloudflare’s certification under the EU-U.S. Data Privacy Framework and, additionally, on the European Commission’s Standard Contractual Clauses. Further information: https://www.cloudflare.com/privacypolicy/.
- Newsletter
Newsletter distribution to existing customers
If you order goods or services from us and provide your email address, we may subsequently use that email address to send newsletters, provided that we inform you of this in advance. In such a case, the newsletter will contain only direct marketing for our own similar goods or services. You may unsubscribe from this newsletter at any time. A corresponding link is included in every newsletter for this purpose. The legal basis for sending the newsletter in this case is Art. 6 para. 1 lit. f GDPR in conjunction with Section 7 para. 3 UWG.
After you unsubscribe from the newsletter distribution list, we may store your email address in a blocklist to prevent future mailings to you. The data in the blocklist is used only for this purpose and is not combined with other data. This serves both your interest and our interest in complying with the statutory requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage in the blocklist is not limited in time. You may object to the storage if your interests override our legitimate interest.
- Plugins and tools
Security Optimizer
This website uses the Security Optimizer security plugin to protect our website against unauthorised access and attacks. The plugin is operated locally on our servers.
The provider is SiteGround Hosting Ltd., 7th Floor, 50 Broadway, London, SW1H 0DB, United Kingdom.
Depending on the protection functions enabled, Security Optimizer may process technical information (e.g. IP address, time of access, URL accessed, user agent, login attempts/failed attempts) in order to detect and prevent attacks and ensure system security.
Processing is based on our legitimate interest in the secure and uninterrupted provision of our website (Art. 6 para. 1 lit. f GDPR). Where the plugin stores cookies or accesses information on your terminal device for this purpose, this is done on the basis of Section 25 para. 2 no. 2 TDDDG (technically necessary).
The resulting log/security data is erased as soon as it is no longer required for the purposes stated.
YouTube
This website embeds videos from the YouTube website. The operator of the website is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit one of our web pages on which YouTube is embedded, a connection to YouTube’s servers is established. The YouTube server is informed which of our pages you have visited.
YouTube may also store various cookies on your terminal device or use comparable recognition technologies (e.g. device fingerprinting). In this way, YouTube may receive information about visitors to this website. This information is used, among other things, to compile video statistics, improve user-friendliness and prevent attempted fraud. The data collected is also processed within Google’s advertising network.
If you are logged into your YouTube account, you enable YouTube to associate your browsing behaviour directly with your personal profile. You can prevent this by logging out of your YouTube account.
YouTube is used in the interest of presenting our online services in an appealing manner. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Further information on how user data is handled can be found in YouTube’s privacy policy at: https://policies.google.com/privacy?hl=en.
The company is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/participant/5780.
Google Fonts (local hosting)
This site uses Google Fonts provided by Google to ensure the consistent display of fonts. Google Fonts are installed locally. No connection to Google’s servers is established.
Further information on Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy?hl=en.
Google Maps
This site uses the Google Maps map service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. This service enables us to embed maps on our website.
In order to use the functions of Google Maps, it is necessary to store your IP address. This information is generally transmitted to and stored on a Google server in the USA. The provider of this site has no influence over this data transfer. If Google Maps is enabled, Google may use Google Fonts to ensure the consistent display of fonts. When Google Maps is accessed, your browser loads the required web fonts into its browser cache in order to display text and fonts correctly.
Google Maps is used in the interest of presenting our online services in an appealing manner and making the locations stated on our website easy to find. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
Further information on how user data is handled can be found in Google’s privacy policy: https://policies.google.com/privacy?hl=en.
The company is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/participant/5780.
- Processing of contractual data
Processing of customer and contractual data
We collect, process and use personal customer and contractual data for the establishment, substantive organisation and amendment of our contractual relationships. We collect, process and use personal data relating to the use of this website (usage data) only insofar as this is necessary to enable the user to use the service or for billing purposes. The legal basis is Art. 6 para. 1 lit. b GDPR.
The customer data collected will be erased after completion of the order or termination of the business relationship and expiry of any applicable statutory retention periods. Statutory retention periods remain unaffected.
Data transfer upon conclusion of a contract for services and digital content
We transfer personal data to third parties only where this is necessary for contract performance. Your data will not be disclosed to third parties without your express consent, for example for advertising purposes.
The legal basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the performance of a contract or in order to take steps prior to entering into a contract.
- Proprietary services
Handling applicant data
We offer you the opportunity to apply to us (e.g. by email, by post or via an online application form). Further information can be found here: https://frankfurt.tumo.de/datenschutzhinweise-fuer-bewerber/
- Further information regarding data processing can also be found here:
The documents are currently available only in German.
Social media:
https://frankfurt.tumo.de/datenschutzerklaerung-socialmedia
Messenger:
https://frankfurt.tumo.de/datenschutzhinweise-messenger
Applicants:
https://frankfurt.tumo.de/datenschutzhinweise-fuer-bewerber
Email communication:
https://frankfurt.tumo.de/datenschutzhinweise-email
Video calls:
https://frankfurt.tumo.de/datenschutzhinweise-videotelefonie