PRIVACY POLICY
The protection of your privacy is very important to us. We as medifundo GmbH and operator of the matching platform www.medifundo.de (hereinafter also referred to as "platform" or "website") value the protection and confidentiality of your data very highly. The collection and use of your personal data is carried out exclusively within the framework of the statutory provisions, in particular the applicable data protection law (EU Data Protection Basic Regulation and BDSG). In the following we inform you in detail about the handling of your data.
RESPONSIBLE IN THE CONTEXT OF DATA PROTECTION
medifundo GmbH
Behamstraße 17
80687 Munich
Germany
General manager: Peter Biewald und Marcus Irsfeld
Phone: +49 89 21752966
Email: kontakt@medifundo.de
Website: www.medifundo.de
PERSON-RELATED DATA
Introduction
Person-related data is individual information about personal or objective circumstances of an identified or identifiable natural person. This includes, for example, your name, your address, your date of birth, your user name, your password, your e-mail address and your payment data, but also your IP address. We describe below how we process your personal data.
Website deployment and creation of log files
You can visit our website at any time without having to register or provide personal information. Whenever you visit our website, however, our system automatically collects data and information from the computer system of the requesting computer.
Description and scope of data processing
The following data is automatically collected when a page is called up:
- Browser type and version,
- operating system and its interface,
- Language and version of the browser software,
- Website from which you visit us (referrer URL),
- website that you visit,
- Access status/HTTP status code,
- Date and time of your access,
- Time zone difference to Greenwich Mean Time (GMT),
- Your Internet Protocol (IP) address.
The collection of data for the purpose of providing the website and the storage of the data in log files is mandatory for the operation of the website.
Legal regulation for the data processing
The legal regulation for the temporary storage of data and log files is Art. 6 para. 1 lit. f EU Data Protection Basic Regulation (DS-GVO).
Purpose of data processing
The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this purpose, the user's IP address must remain stored for the duration of the session. The purpose of saving in log files is to ensure the functionality and stability of the website. In addition, the data serves us to optimize the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context. These purposes also include our legitimate interest in data processing in accordance with Art. 6 para. 1 lit. f DS-GVO.
Duration of storage
The data will be deleted as soon as they are no longer necessary for the purpose of their collection. In the case of the collection of data for the preparation of the website, this is the case when the respective session is ended.
REGISTRATION
Introduction
On our website you have the possibility to register to receive detailed project information and to invest in projects. For this purpose we process your data as follows:
Description and scope of data processing
The data you enter in the input mask will be transmitted to us and stored. The data will not be passed on to third parties.
At the time of registration, the following data is also stored:
(1) The IP address of the user
(2) Date and time of registration
During the registration process, the user's consent to the processing of this data is obtained.
We use your e-mail address and telephone number as a contact channel for information and queries about the processing status. We would like to point out that communication by e-mail can be potentially unsafe.
The provision of personal data by you is not required by law and, in the case of pure information, also not contractually. You are not obliged to provide us with personal data. If you do not provide us with personal data, the consequence will be that we will not be able to provide you with detailed project information, as far as this is mandatory.
Legal regulation for the data processing
The legal regulation for the processing of the data is Art. 6 para. 1 lit. a DS-GVO if the user has given his consent. If the registration serves the fulfilment of a contract to which the user is a party or the implementation of pre-contractual measures, this is an additional legal basis for the processing of the data Art. 6 para. 1 letter b DS-GVO.
Purpose of data processing
If you are only requesting detailed company information, the purpose of registration is to provide you with this information. Some companies may wish to provide information voluntarily or may be required by law to restrict the number of potential investors they can contact or their place of residence. Registration is the only way to efficiently limit the number of persons who can be contacted.
Duration of storage
The data will be deleted as soon as they are no longer necessary for the purpose of their collection. After complete processing of the contract, the data will only be stored for the legally prescribed periods. Subsequently, your personal data will be deleted, unless you have agreed to further use or processing.
NEWSLETTER
Description and scope of data processing
When registering for our free newsletter, the data from the input mask is transferred to us. For the processing of the data, your consent will be obtained as part of the registration process and reference will be made to this privacy policy.
At the time of sending the registration the following data will also be saved:
(1) The IP address of the user
(2) Date and time of registration.
If you open one of our newsletters or click on a link in it, this may be logged by the web server (date, time, e-mail address). This serves internal statistical purposes, so that we can tailor our information offer even better to the interests of our newsletter users. This is also our legitimate interest in data processing. These data are not combined to personal user profiles.
The provision of personal data by you is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with personal data. If you do not provide us with personal data, we will not be able to send you a newsletter, as far as this is mandatory.
Legal regulation for the data processing
The legal basis for the processing of data after registration for the newsletter is the consent you have given (Art. 6 Par. 1 letter a DS-GVO). The legal basis for any statistical evaluations that may be carried out is Art. 6 Para. 1 lit. f DS-GVO.
Purpose of data processing
The collection of your e-mail address is used to send you the newsletter. If other personal data is provided voluntarily by you during the registration process, this serves to individualize the newsletter and to prevent misuse of the services or the e-mail address used.
Duration of storage
The personal data provided by you will be stored until you withdraw your consent to receive the newsletter. After receipt of a revocation by you, your e-mail address will be marked with a blocking note to document that you no longer wish to be contacted by us via e-mail in the future. Any other personal data collected with the newsletter registration will be deleted immediately. The blocking note and your e-mail address will be deleted three years after the end of the calendar year in which the blocking note was set.
COMMUNICATION BY EMAIL
Description and scope of data processing
By sending a contact request via our contact form (if included), the data entered in the input mask is transmitted to us and stored.
At the time of sending the message, the following data is also stored:
(1) The IP address of the user
(2) Date and time of message sending.
The provision of personal data by you is not required by law or contract, nor is it necessary for the initiation of contact with a company seeking financial support. You are not obliged to provide us with personal data. If you do not provide us with personal data, it will not be possible to contact you via the contact form, as long as this information is mandatory.
Alternatively, it is possible to contact us via the provided e-mail address. In this case your personal data transmitted with the e-mail will be stored.
Legal regulation for the data processing
The legal basis for the processing of data transmitted via the contact form or in the course of sending an e-mail is Art. 6 Par. 1 letter f DS-GVO. Our legitimate interest lies in answering the contact request of the sender. If the e-mail contact is aimed at establishing contact with a company seeking financial backers, an additional legal basis for processing is Art. 6 (1) lit. b DS-GVO.
Purpose of data processing
The processing of the personal data from the input mask serves us only to process the contact request. The other personal data processed during the sending process serves to prevent misuse of the contact form and to ensure the security of our information technology systems.
Duration of storage
The data will be deleted as soon as they are no longer necessary for the purpose of their collection. For the personal data from the input mask of the contact form and those sent by e-mail, this is the case when the respective conversation with you has ended, unless contractual or legal obligations prevent deletion. The conversation is finished when the circumstances indicate that the matter in question has been finally clarified.
Any additional personal data collected during the sending process will be deleted after a period of seven days at the latest.
TRANSMISSION OF PERSON-RELATED DATA
medifundo GmbH will not pass on your data to third parties, unless you have given your express consent to a transfer in advance or the transfer is required or permitted by law. Excluded from this are our service partners, who are required to process the contractual relationship and who have been commissioned by us within the framework of a contract processing agreement to process personal data in accordance with our instructions, as well as those companies looking for investors who require the necessary personal data (name, address, date of birth, e-mail address, telephone number) to initiate and conduct negotiations between the company and the investor. We will neither sell your data to third parties nor otherwise pass them on to third parties for advertising purposes. Our employees are obliged to maintain secrecy and to comply with data protection regulations.
COOKIES
Description and scope of data processing
To make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your end device.
You can set your browser to inform you about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or generally. If cookies are not accepted, the functionality of our website may be limited. The following links show you how the settings can be adjusted for the following common browsers:
Chrome: https://support.google.com/chrome/answer/95647?hl=de Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies Safari: https://support.apple.com/kb/PH21411?viewlocale=de_DE&locale=de_DE
Please adapt to your language!
Legal regulation for the data processing
If personal data is processed using cookies, the legal basis is Art. 6 para. 1 lit. f DS-GVO.
Purpose of data processing
The purpose of the processing is to make the visit to our website attractive and to enable the use of certain functions. Some functions of our website cannot be offered without the use of cookies. For these it is necessary that the browser is recognized even after a page change.
We require cookies for the following applications:
(1) LDUG[Vis]: Query whether new or returning visitor
(2) cookieconsent_status: Query cookie approval
(3) _ga, _gat, _gid: website analytics with Google Analytics (see below)
(4) IDE: Online Marketing Tool DoubleClick (see below)
(5) 1P_Jar, CONSENT, NID, DV: Use of Google Services
The user data collected by cookies is not used to create user profiles.
Duration of storage
Transient cookies are automatically deleted when you close the browser. This includes in particular the session cookies. These store a so-called session ID, with which various requests from your browser can be assigned to the shared session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser. Persistent cookies are automatically deleted after a preset period of time, which may vary depending on the cookie. You can delete the cookies in the security settings of your browser at any time.
WEBSITE ANALYSIS
Use of Google Analytics
Our site www.medifundo.de uses Google Analytics, a web analytics service provided by Google Inc, (1600 Amphitheatre Parkway Mountain View, CA 94043, USA) in Universal Analytics mode. This makes it possible to assign data, sessions and interactions across multiple devices to a pseudonymous user ID and thus analyze the activities of a user across multiple devices. Google Analytics uses so-called cookies, text files which are stored on your computer and which enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there.
However, since this website uses Google Analytics with the extension "_anonymizeIp()", your IP address will be shortened by Google within member states of the European Union or in other signatory states of the Agreement on the European Economic Area before. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. The IP address transmitted by your browser within the scope of Google Analytics is not merged with other data from Google. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage. These purposes also include our legitimate interest in data processing.
The legal basis for the use of Google Analytics is Art. 6 para. 1 lit. f DS-GVO and with your consent Art. 6 para. 1 lit. a DS-GVO.
The data sent by us and linked to cookies, user IDs (e.g. user ID) or advertising IDs are automatically deleted after 14 months. Data whose retention period has been reached is automatically deleted once a month. You can find more information on terms of use and data protection at https://www.google.com/analytics/terms/de.html or https://policies.google.com/?hl=de.
You can prevent the storage of cookies by adjusting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available under the following link: http://tools.google.com/dlpage/gaoptout?hl=de. Opt-out cookies prevent the future collection of your data when visiting this website. To prevent Universal Analytics from collecting data across multiple devices, you must opt-out on all systems in use.
Automated decision making including profiling: There is no automated decision making including profiling.
RIGHTS OF THE PERSON CONCERNED
Introduction
If your personal data is processed, you are a data subject within the meaning of the DS-GVO and you are entitled to the following rights vis-à-vis the person responsible:
Right to information
In accordance with Art. 15 of the DS-GVO, you have the right to request information about your personal data processed by us; in particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right of correction, deletion, restriction of processing or opposition, the existence of a right of appeal, the origin of your data, if it has not been collected by us, as well as the existence of automated decision making, including profiling and, where applicable, meaningful information on the details thereof.
Right of rectification
In accordance with Art. 16 DS-GVO, you have the right to demand the immediate correction of incorrect or incomplete personal data stored by us.
Right to deletion
In accordance with Art. 17 DS-GVO, you have the right to demand the deletion of your personal data stored with us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims.
Right of restriction
Pursuant to Art. 18 DS-GVO, you have the right to demand the restriction of the processing of your personal data if the accuracy of the data is disputed by you, the processing is unlawful but you refuse to delete it and we no longer need the data, but you need the data for the assertion, exercise or defence of legal claims or you have lodged an objection to the processing pursuant to Art. 21 DS-GVO.
Right of data transferability
In accordance with Art. 20 DS-GVO, you have the right to receive your personal data that you have provided us with in a structured, common and machine-readable format or to request that it be transferred to another person responsible. Right of complaint: Pursuant to Art. 77 DS-GVO, you have the right to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our registered office for this purpose. The supervisory authority responsible for our registered office is: The Bavarian State Commissioner for Data Protection, Dr. Thomas Petri, Postfach 22 12 19, 80502 Munich or Wagmüllerstr. 18, 80538 Munich; telephone: +49 89 21 26 72-0, fax: +49 89 21 26 72-50, e-mail: poststelle@datenschutz-bayern.de.
Right of objection
You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you, which is carried out on the basis of Art. 6 Paragraph 1 letter f of the DS-GVO.
If the personal data concerning you are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing.
Right of withdrawal
You have the right to revoke your consent to the processing of your personal data at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until revocation. Revocation is possible at any time by e-mail to kontakt@medifundo.de or by post using the address given above.
DATA SECURITY
We use the common SSL (Secure Socket Layer) procedure within the website visit in connection with the highest encryption level supported by your browser. Usually this is a 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can recognize the encryption by the closed display of the key or lock symbol in the lower status bar or the address line of your browser (https). We also use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
CHANGE OF OUR DATA PROTECTION REGULATIONS
We reserve the right to adapt this data protection declaration from time to time so that it always meets the current legal requirements or to implement changes to our services in the data protection declaration, e.g. when new services are introduced. The current data protection declaration applies to your next visit to our website.
EFFECTIVE DATE: OCTOBER 2020