Privacy policy

Purpose of this website

Thank you for visiting our website. Here we provide professionals, cooperation partners and interested parties with information about our services in the areas of child, youth and family support, elderly care, social psychiatry, further training and counselling, as well as various socially oriented projects, and enable them to contact the people responsible for the respective services.

Data protection framework

As a diaconal organisation, we are subject to the Church Law on Data Protection of the Protestant Church in Germany (DSG-EKD).
– which you can view here https://www.kirchenrecht-ekd.de/document/41335 – applies in the currently valid version.

Responsible body for data processing on this website

St. Elisabeth-Verein e.V., represented by the Executive Board
Hermann-Jacobsohn-Weg 2, 35039 Marburg, 06421-3038-0, info@elisabeth-verein.de

Legal basis for the processing of personal data on this website

We attach great importance to data protection and the lawful processing of your personal data and explain below the underlying legal bases for the various processing situations when using our website.

Processing situation: General use of the website for information purposes

When using this website for information purposes without contacting us by e-mail or contact form, technically necessary usage data, such as the IP address, which is considered a personal date, is processed for security, functionality and visitor analysis of the website. This type of processing is based on § 6 No. 4 DSG-EKD.

Technically required usage data is:

a) Access and error log files (so-called server log files)

These log files contain the user’s IP address, date and time of access, HTTP protocol version, method of access and the URL accessed, HTTP status, size of the data transfer, referrer (= website from which the user came), user agent (information on the user’s browser and operating system).

The data in the access log (webaccess.log) is stored for a maximum of 24 hours. After 24 hours, the IP addresses of the logs are anonymised. The anonymised data is stored for 3 months. The data in the error log (webservererror.log) is stored for 7 days. The IP addresses are anonymised after 7 days. The anonymised data is stored for 3 months and then automatically deleted.

b) Session cookies

Cookies are small files that are stored on your end device via your browser and are also read out again from there. The cookies we use are exclusively so-called “session cookies”, which only ensure the functionality of the website.

The session cookies are automatically deleted at the end of your visit to our website and cannot be assigned to a specific person. The setting and reading of these technically necessary session cookies on your end device does not require separate consent.

Processing situation: Further use of the website with contacting

If you transmit further personal data to us by email or in a contact form, e.g. name, email address, communication links and any other content, the processing of this data and information for the purpose of processing your request may also be based on Section 6 No. 5 DSG-EKD in addition to Section 6 No. 4 DSG-EKD. This information will not be passed on to third parties unless we are legally obliged to do so in individual cases after careful examination. The deletion or anonymisation of this data takes place as soon as the purpose of the transmission (i.e. the processing of your request/enquiry) no longer applies, provided that there are no statutory retention obligations to the contrary. This would be the case, for example, if the enquiry or initiation sent to us by you via this website results in a (social or business) service to be provided by us from the above-mentioned fields of work. In this case, the personal data associated with your original enquiry will continue to be processed on the basis of Section 6 No. 5 DSG-EKD – and possibly also on the basis of other provisions from the Social Code relating to social data protection, for example, or possibly also on the basis of other sector-specific laws – and may then also be subject to various statutory retention obligations.

Encryption

Communication between your computer and this website is secured by transport encryption (SSL/TLS) for security reasons and to protect the transmission of confidential content, such as the enquiries you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. If SSL/TLS encryption is activated, the data you transmit to us via this website cannot be read by third parties. However, if you contact us by email or using the contact form, encryption is not always guaranteed. Our e-mail server uses transport encryption whenever possible. However, this automatic encryption of the transmission path only takes place if this is also supported by your e-mail provider.

Recipients of personal data / processors

Our website is hosted on a web server of the company Hostserver GmbH, Biegenstraße 20, 35037 Marburg.

To ensure data protection and data security, we have concluded a contract for order processing in accordance with Section 30 DSG-EKD or a corresponding contract for order processing in accordance with Art. 28 GDPR together with a supplementary agreement (annex) for church data protection supervision with all service providers named here working on our behalf.

Transfer of personal data to third countries outside the European Union

We do not use any elements/tools/functions on our website (such as analysis tools, external fonts, interactive map tools, embedded functions of social networks or video platforms, newsletter tools or other elements) that automatically transmit personal data (e.g. your IP address) to the servers of (often well-known and globally active) providers in third countries outside the EU when the page is called up.

Links to external websites

External websites can also be accessed from our website via links.

In contrast to internal links, these external links are all labelled with the symbol.

If you click on such external links, you will be taken to the websites of other website operators. For these websites, the data protection information published there or the corresponding data protection declaration belonging to the website accessed then applies under the responsibility of the respective operator. We have no influence on how personal data is processed on the linked external sites.

If you access (known) websites or portals of large global companies from third countries outside the European Union, e.g. from the USA, via external links, there may be special data protection risks, as the level of data protection may not correspond to the level within the scope of the EU GDPR or the level in the DSG-EKD applicable to us as a diaconal organisation. For example, US security authorities could, under certain circumstances, gain access to the usage data collected by the providers (including IP addresses) by applying the corresponding security laws there. In addition, such globally active providers generally make intensive use of the usage data obtained for personalised advertising and the creation of user profiles.

Your rights as a data subject

You have the right to obtain information about your personal data processed by us. You can also request the correction of incorrect data. In addition, under certain conditions, you have the right to erasure of data, the right to restriction of data processing and the right to data portability.

Your data is processed on the basis of the legal regulations listed above. We only require your consent in certain exceptional cases. In these cases, you have the right to withdraw the consent we have already obtained from you separately for future processing.

If you would like to exercise one or more of your data subject rights or have any other questions about data protection in our data processing operations, you are welcome to contact our local data protection officer (data protection officer).

Local data protection officer / data protection officer

Stefan Kissel
06421-1808-53
s.kissel@elisabeth-verein.de

You also have the right to lodge a complaint with the competent data protection supervisory authority if you are of the opinion that the processing of your personal data on our website is not lawful.

Responsible data protection supervisory authority

The Commissioner for Data Protection of the Protestant Church in Germany (BfD-EKD)
Data Protection Region Centre-West
Cemetery 4
44135 Dortmund
0231-533827-0
mitte-west@datenschutz.ekd.de