Data Privacy Policy

I. Name and address of the controller:

The controller in the sense of the General Data Protection Regulation and other national data protection laws of the Member States as well as other provisions pertaining to data privacy and protection laws is:

Delegation of German Industry and Commerce in Sri Lanka

161 A Dharmapala Mawatha 6th Floor, Colombo 7 Sri Lanka

Tel.: +94 - 112 - 314364/67

E-Mail: schonburg@srilanka.ahk.de

II. Name and address of contact person:

Ms. Marie Antonia von Schönburg

Delegation of German Industry and Commerce in Sri Lanka

161 A Dharmapala Mawatha 6th Floor, Colombo 7 Sri Lanka

Tel.: +94 11 2314364

E-Mail: schonburg@srilanka.ahk.de

 

III. General information regarding data processing

1. Scope of processing of personal data

In principle, we collect and use personal data of our users only to the extent it is required to provide a functioning website as well as for our content and services. The processing of personal data of our users is carried out regularly only after consent is given by our users. An exception applies in cases in which a previous obtaining of a consent is not possible for actual reasons and where the processing of data is permitted on the basis of statutory provisions.

2. Legal basis for the processing of personal data

To the extent that we obtain consent from the data subject for the processing of personal data, Section 6 Subsection 1 lit. a EU General Data Protection Regulation (GDPR) serves as legal basis for the processing of personal data. For the processing of personal data required to execute a contract whose contractual party is the data subject, Section 6 Subsection 1 lit. b GDPR serves as legal basis. This also applies to processing that is required for the execution of pre-contractually measures. If such processing is required to maintain a legitimate interest of our company or a third party, and if the interests, basic rights and fundamental freedoms of the data subject do not outweigh the former interest, Section 6 Subsection 1 lit. f GDPR serves as legal basis for such processing.

3. Data deletion and duration of storage

Personal data of the data subject will be deleted or blocked as soon as the purpose for storing such data no longer applies. Storage beyond such a period can be effected if such storage is prescribed by the European or national legislative body in provisions pertaining to European Union law or other provisions the data subject is subject to. Blocking or deletion of data is also effected if a storage period expires that is prescribed by the cited standards, unless there is a requirement for further storage of such data to enter into a contract or to execute a contract.

 

I. Provisioning of website and creation of logfiles

1. Description and scope of data processing

Any time our web page is visited, our system collects data and information in an automated fashion from the computer system of the accessing computer. The following data is collected in the process:

(1) Information regarding the browser type and the version used

(2) The operating system of the user

(3) The internet service provider of the user

(4) The IP address of the user

(5) Date and time of access

(6) Websites that are accessed by the system of the user via our website

2. Legal basis for the processing of data

Legal basis for the temporary storage of data and the logfiles is Section 6 Subsection 1 lit. f GDPR.

3. Purpose of data processing

The temporary storage of the IP address by the system is necessary to facilitate delivery of the website to the computer of the user. To do so, the IP address of the user must remain stored for the duration of the session.

Storing of logfiles is effected to ensure the functionality of the website. In addition, such data helps us to optimize the website and to ensure the security of our information technology systems. An analysis of such data for marketing purposes will not be carried out in this context.

4. Duration of storage

Data is deleted as soon as it is no longer required to fulfill the purpose of its collection. In the event of collection of data for the provisioning of the website this is the case whenever the respective session ends.

In the event of storing of data in logfiles this is after seven days the case at the latest. Storage to exceed such a period is not possible. In such a case, the IP addresses of the users are deleted or redacted so that an allocation of the accessing client is no longer possible.

5. Option for objection and removal

Collection of data for the provisioning of the website and storing of data in logfiles is required for the operation of the web page. Consequently, the user has no possibility to object.

 

II. Use of cookies

a) Description and scope of data processing

We use cookies to make our website more user-friendly. Some elements of our web page require that the accessing browser can also be identified when the user moves from one page to the next. No personal data is collected in the process.

To do so, the following files are stored and transmitted in the cookies:

(1) fonts = standard cookie variable used by us to reload the fonts in the browser after a page refresh.

(2) fullcss = standard cookie variable used by us to reload the CSS file in the browser after a page refresh.

Maximum cookie lifetime: 730 days

In addition, we use on our website cookies that enable an analysis of the surfing behavior of users.

When visiting our website, the users are informed via web banner about the use of cookies for analytical purposes and referred to this data privacy statement. In this context, it is also pointed out how the storing of cookies can be disabled in the browser settings. This service is provided via the Consent Manager of the Piwik PRO Analytics Suite.

Analysis cookies are used to improve the quality of our website and its content. Through the analysis cookies, we learn how the website is used and can thus constantly optimize our offer.

We use cookies of the Piwik PRO Analytics:

_pk_id = Used to recognize visitors and hold their various properties. Expires after: 13 months if user consents; expires after 30 minutes if user does not consent

_ppms_privacy = Stores visitor’s consent to data collection and usage. Expires after: 365 days

_pk_ses = Shows an active session of the visitor. Expires after: 30 minutes

b) Legal basis for the processing of data

Legal basis for the processing of personal data while using technically required cookies is Section 6 Subsection 1 lit. f GDPR.

Legal basis for the processing of personal data while using cookies for analytical purposes is Section 6 Subsection 1 lit. a GDPR if the respective consent of the user is on hand.

c) Purpose of data processing

The purpose of using technically required cookies is the simplification of use of websites for the users. Some functions or our web page cannot be provided without the use of cookies. For such it is necessary that the browser is also recognized when the user moves from one page to the next.

We need cookies for the following applications:

(1) fonts = standard cookie variable used by us to reload the fonts in the browser after a page refresh.

(2) fullcss = standard cookie variable used by us to reload the CSS file in the browser after a page refresh.

Maximum cookie lifetime: 730 days

User data collected via technically required cookies is not used to create user profiles.

The use of analytical cookies also serves to improve the quality of our website and its content. From analytical cookies we gain knowledge of how the website is used; we are then able to constantly optimize our services.

We use cookies of the Piwik PRO Analytics:

_pk_id = Used to recognize visitors and hold their various properties. Expires after: 13 months if user consents; expires after 30 minutes if user does not consent

_ppms_privacy = Stores visitor’s consent to data collection and usage. Expires after: 365 days

_pk_ses = Shows an active session of the visitor. Expires after: 30 minutes

d) Duration of storage, option for objection and removal

Cookies are stored on the computer of the user and transmitted from such to our website. This is why you as the user have full control of the use of cookies. By changing your browser’s settings, you may disable or limit the transmission of cookies. Already stored cookies can be deleted at any time. This can also be done in an automated fashion. If cookies are disabled for our website, it is possible that not all functions of the website may be used to the full extent.

 

III. Newsletter

1. Description and scope of data processing

On our web page, there is the option to subscribe to a free newsletter. During the registration for the newsletter, data from the input mask added by iFrame is transmitted to the service provider commissioned by us for email marketing software providers.

The following data is collected:

  • Title
  • First name(s)
  • Last name
  • Email address

Furthermore, the following data is collected upon registration:

  • Date and time of registration

For the processing of data, in line with the registration process, we obtain your consent and refer to this data privacy statement. In connection with the processing of data for the sending of newsletters, with the exception of the provider of email marketing software, data is not forwarded to third parties. Such data is only used for the newsletter to be sent to you.

2. Legal basis for the processing of data

Legal basis for the processing of data after registration for the newsletter by the user is Section 6 Subsection 1 lit. a GDPR if the consent of the user is on hand.

To the extent this pertains to the sending of a newsletter in line with membership to registered data of our database, legal basis is Section 6 Subsection 1 lit. b GDPR.

3. Purpose of data processing

Collection of the email address of the user is done to deliver the newsletter.

4. Duration of storage

Data is deleted as soon as it is no longer required to fulfill the purpose of its collection. The email address of the user is therefore stored for as long as the newsletter subscription is active.

5. Newsletter tracking

To optimize our newsletter offer, we use personalized newsletter tracking. In this context, besides the email address, we also collect activities connected to the newsletters (click behavior).

6. Option for objection and removal

A newsletter subscription may be cancelled by the respective user at any time. A special link is provided in every newsletter for this purpose. Alternatively, you may also send an email to communication@srilanka.ahk.de

 

IV. Registration 
 

1. Description and scope of data processing

On our web page we give our users the option to register while providing personal data. In the process, data is entered into an input mask, transmitted to us and stored. Forwarding of such data to third parties is not effected.

The following data is collected in line with the registration process:

  • Full Name
  • Contact Number
  • Job Title 
  • Company 
  • Email

At the time of registration, also the following data is stored:

  • Date and time of registration
  • Used browser
  • Operating system

In line with the registration process, consent is obtained from the user for processing of such data.

2. Legal basis for the processing of data

Legal basis for the processing of data is Section 6 Subsection 1 lit. a GDPR if the consent of the user is on hand. If the registration serves the execution of a contract whose contractual party is the user, or the execution of pre-contractual measures, the additional legal basis for the processing of data is Section 6 Subsection 1 lit. b GDPR.

3. Purpose of data processing

A registration of the user is required for the execution of a contract with the user, or for the execution of pre-contractual measures. Your registration may be an application for membership or an event registration.

4. Duration of storage

Data is deleted as soon as it is no longer required to fulfill the purpose of its collection. This is the case for data collected during the registration process for the execution of a contract or for the execution of pre-contractual measures if such data is no longer required for the execution of the contract. Even after having entered into a contract, the requirement to store personal data of the contractual partner may remain in existence to fulfill contractual or statutory requirements.

5. Option for objection and removal

As user, you have at any time the option to cancel the registration. Your stored personal data can be amended at any time. To amend or delete your data, please contact communication@srilanka.ahk.de. All personal data stored in the process of establishing contact will be deleted in such a case.

VI. Forwarding of personal data to third parties

1. Website operators

In line with processing, personal data is forwarded to the agency commissioned to run the website as well as to the technical service provider. Such is regulated via a corresponding agreement with the service provider.

2. Social media sharing button

General notice: Social media plugins usually lead to the fact that every visitor to a website is immediately captured by such services by means of his IP address and that his subsequent browser behavior is logged. This can also occur if you do not press the button. To prevent this, we use the Shariff method. Here, our social media buttons only establish direct contact between the social network and you only if you click on the respective sharing button. If you are already logged in with a social network, this is done without an extra window for Facebook and Google+. Twitter displays a pop-up window in which the text of the tweet can still be edited. This way, you may publish our content in social networks without such networks being able to compile complete surfing profiles.

Facebook

Our website uses plugins of the social network Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. By using the Shariff method, Facebook only gains knowledge of your IP address and your visit to our website if you click the button. If you use the plugin while being logged in on Facebook, Facebook is able to allocate your use to your user account.

We have no knowledge of any subsequent potential collection and use of your data by Facebook and also have no influence on such. More information can be found in the data privacy statement of Facebook at de-de.facebook.com/policy.php. Regarding the general handling with and the disabling of cookies, we also always refer to our general description in this data privacy statement.

LinkedIn

Our website uses the LinkedIn share plugin of the social network LinkedIn, LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. By clicking the button, your browser connects to LinkedIn to carry out the functions of the plugin. In this context, no personal data is stored by LinkedIn, and your use is also not recorded via a cookie. More information can be found in the data privacy statement of LinkedIn at www.linkedin.com/legal/privacy-policy. Regarding the general handling with and the disabling of cookies, we also always refer to our general description in this data privacy statement.

3. Website Analysis with Piwik PRO

We use Piwik PRO Analytics Suite as our website/app analytics software and consent management tool. We collect data about website visitors based on cookies. The collected information may include a visitor’s IP address, operating system, browser ID, browsing activity and other information. See the scope of data collected by Piwik PRO.

We calculate metrics like bounce rate, page views, sessions and the like to understand how our website/app is used. We may also create visitors’ profiles based on browsing history to analyze visitor behavior, show personalized content and run online campaigns.

We host our solution on Microsoft Azure in Germany, and the data is stored for 25 months.

The purpose of data processing: analytics and conversion tracking based on consent. Legal basis: Art. 6 (1)(a) GDPR.

Piwik PRO does not send the data about you to any other sub-processors or third parties and does not use it for its own purposes. For more, read Piwik PRO’s privacy policy.

VII. Rights of the data subject

You have the following rights according to the EU General Data Protection Regulation: If your personal data is processed, you have to right to obtain information regarding the storage of your personal data (Section 15 GDPR).

If incorrect personal data is processed, you have the right to correction of such (Section 16 GDPR).

If legal requirements are given, you have the right to request the deletion or limitation of processing, and you have the right to object to such processing (Sections 17, 18 and 21 GDPR).

If you have given your consent to data processing or if a contract exists pertaining to data processing and if such data processing is carried out via automated processes, you have a right to data portability where applicable (Section 20 GDPR).

Should you exercise your above-mentioned rights, the AHK Sri Lanka will review whether statutory requirements are met.