(Translation, the German original is authorative)
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to any data with which you can be personally identified. For detailed information on data protection, please refer to our Privacy Policy listed below this text.
Data Collection on this Website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find the contact details of the operator in the “Notice on the Responsible Party” section of this Privacy Policy.
How do we collect your data?
Your data is collected in two ways:
- Data that you provide to us, such as information you enter into a contact form.
- Other data is automatically collected by our IT systems when you visit the website. This includes technical data, such as the browser type, operating system, or the time of the page access. The collection of this data occurs automatically as soon as you access the website.
For what purposes do we use your data?
Part of the data is collected to ensure the website is provided without errors. Other data may be used to analyze your user behavior. If contracts are entered into or initiated via the website, the transmitted data may also be processed for contract offers, orders, or other inquiries.
What are your rights regarding your data?
You have the right to obtain information about the origin, recipients, and purpose of your stored personal data free of charge at any time. You also have the right to request correction or deletion of this data. If you have provided consent for data processing, you can revoke this consent at any time for future processing. Additionally, you have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the appropriate supervisory authority.
For further questions regarding data protection, you can contact us at any time.
Analytics Tools and Third-Party Tools
When you visit this website, your browsing behavior may be statistically analyzed. This is primarily done using so-called analytics programs. Detailed information about these analytics programs can be found in the following Privacy Policy.
2. Hosting
Hosting Provider
We host the content of our website with the following provider:
All-Inkl
The provider is ALL-INKL.COM – Neue Medien Münnich, owned by René Münnich, Hauptstraße 68, 02742 Friedersdorf (hereinafter referred to as “All-Inkl”). You can find more details in All-Inkl’s privacy policy:
https://all-inkl.com/datenschutzinformationen/
The use of All-Inkl is based on Art. 6(1)(f) GDPR. We have a legitimate interest in ensuring the most reliable display of our website. If corresponding consent has been requested, the processing is carried out exclusively based on Art. 6(1)(a) GDPR and § 25(1) TDDG, insofar as the consent includes the storage of cookies or access to information on the user’s end device (e.g., device fingerprinting) as defined by TDDG. Consent can be revoked at any time.
Data Processing Agreement (DPA)
We have entered into a Data Processing Agreement (DPA) for the use of the above service. This is a legally required contract that ensures All-Inkl processes the personal data of our website visitors strictly in accordance with our instructions and in compliance with GDPR.
3. General Information and Mandatory Disclosures
Data Protection
The operators of this website take the protection of your personal data very seriously. We handle your personal data confidentially and in accordance with statutory data protection regulations as well as this Privacy Policy.
When you use this website, various personal data is collected. Personal data refers to data that can be used to personally identify you. This Privacy Policy explains what data we collect and how we use it. It also explains how and for what purposes this occurs.
We would like to point out that data transmission over the Internet (e.g., communication via email) can have security vulnerabilities. A complete protection of data against access by third parties is not possible.
Notice on the Responsible Party
The responsible party for data processing on this website is:
Cosyland e.V.
Moosdorfstr. 7-9
c/o Kreatur Works
10243 Berlin
Germany
Phone: [Phone number of the responsible party]
Email: hello@cosyland.org
The responsible party is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Storage Duration
Unless a specific storage period has been specified in this Privacy Policy, your personal data will remain with us until the purpose for the data processing ceases. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted, provided we have no other legally permissible reasons for storing your personal data (e.g., retention periods under tax or commercial law); in such cases, the data will be deleted after these reasons no longer apply.
General Information on the Legal Basis for Data Processing on this Website
If you have consented to data processing, we process your personal data based on Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, if special categories of data according to Art. 9(1) GDPR are processed. In the case of explicit consent for the transfer of personal data to third countries, data processing is also carried out based on Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your end device (e.g., via device fingerprinting), data processing is additionally based on § 25(1) TDDG. Consent can be revoked at any time.
If your data is required for contract performance or pre-contractual measures, we process your data based on Art. 6(1)(b) GDPR. Furthermore, we process your data if this is necessary for compliance with a legal obligation based on Art. 6(1)(c) GDPR. Data processing may also be based on our legitimate interest pursuant to Art. 6(1)(f) GDPR. Specific legal bases for each case are provided in the following sections of this Privacy Policy.
Recipients of Personal Data
In the context of our business operations, we work with various external entities. Sometimes it is necessary to transfer personal data to these external parties. We only transfer personal data to external parties if it is necessary for contract performance, if we are legally required to do so (e.g., transfer of data to tax authorities), if we have a legitimate interest pursuant to Art. 6(1)(f) GDPR, or if another legal basis permits the data transfer.
When using data processors, we only transfer personal data of our customers based on a valid Data Processing Agreement. In the case of joint processing, a joint processing agreement will be concluded.
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent. You can revoke consent that has already been given at any time. The legality of the data processing carried out before the revocation remains unaffected by the revocation.
Right to Object to Data Collection in Special Cases and Direct Advertising (Art. 21 GDPR)
IF DATA PROCESSING IS CARRIED OUT BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS FOR PROCESSING CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE REASONS FOR THE PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS, AND FREEDOMS OR THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING PURPOSES, INCLUDING PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION UNDER ART. 21(2) GDPR).
Right to Lodge a Complaint with a Supervisory Authority
In the case of violations of the GDPR, affected individuals have the right to lodge a complaint with a supervisory authority, particularly in the member state of their habitual residence, workplace, or the place of the alleged violation. The right to lodge a complaint is without prejudice to other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data that we process based on your consent or in fulfillment of a contract in a commonly used, machine-readable format. If you request the direct transfer of data to another controller, this will only be done to the extent technically feasible.
Access, Correction, and Deletion
Within the scope of applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin, recipients, and the purpose of data processing, and, if applicable, the right to correct or delete this data. For further questions regarding personal data, you can contact us at any time.
Right to Restrict Processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restrict processing applies in the following cases:
- If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need it for the establishment, exercise, or defense of legal claims, you have the right to request the restriction of processing instead of deletion.
- If you have objected to processing pursuant to Art. 21(1) GDPR, a balancing of your and our interests must be carried out. As long as it is not clear whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data—apart from being stored—may only be processed with your consent or for the establishment, exercise, or defense of legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the European Union or a member state.
SSL or TLS Encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator. You can recognize an encrypted connection by the browser’s address bar switching from “http://” to “https://” and the lock icon appearing in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
4. Data Collection on This Website
Cookies
Our website uses “cookies.” Cookies are small data packages that do not harm your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted after your visit. Persistent cookies remain stored on your device until you delete them yourself or your browser performs an automatic deletion.
Cookies can originate from us (first-party cookies) or third-party companies (third-party cookies). Third-party cookies allow the integration of certain services provided by third-party companies within websites (e.g., cookies for processing payment services).
Cookies serve various purposes. Many cookies are technically necessary as certain website functions would not work without them (e.g., the shopping cart function or video display). Other cookies are used to analyze user behavior or for advertising purposes.
Cookies necessary for electronic communication, providing certain functions you have requested (e.g., shopping cart functionality), or optimizing the website (e.g., cookies for measuring web audience) are stored based on Art. 6(1)(f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimized provision of its services. If consent for the storage of cookies or similar recognition technologies has been requested, processing occurs exclusively based on this consent (Art. 6(1)(a) GDPR and § 25(1) TDDG); consent can be revoked at any time.
You can configure your browser to inform you about the setting of cookies, allow cookies only on a case-by-case basis, exclude cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Deactivating cookies may limit the functionality of this website.
Details about the cookies and services used on this website can be found in this Privacy Policy.
Comment Function on This Website
For the comment function on this website, in addition to your comment, information about the time of the comment’s creation, your email address, and, if you do not post anonymously, the username you selected will be saved.
Storage of the IP Address
Our comment function stores the IP addresses of users who post comments. As we do not review comments before they are published on this site, we need this data to take action against the author in case of legal violations such as insults or propaganda.
Storage Duration of Comments
Comments and associated data are stored on this website and remain there until the commented content is fully deleted or the comments must be deleted for legal reasons (e.g., offensive comments).
Legal Basis
The storage of comments is based on your consent (Art. 6(1)(a) GDPR). You can revoke your consent at any time. For this, an informal message via email to us is sufficient. The legality of data processing already carried out remains unaffected by the revocation.
5. Social Media
This website integrates elements of the Facebook social network. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. According to Facebook, the data collected is also transferred to the USA and other third countries.
You can find an overview of the Facebook social media elements here:
https://developers.facebook.com/docs/plugins/?locale=de_DE.
When the social media element is active, a direct connection between your device and the Facebook server is established. Facebook thereby receives information that you have visited this website with your IP address. If you click the Facebook “Like” button while logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to associate your visit to this website with your user account. We would like to point out that, as the provider of this website, we have no knowledge of the content of the transmitted data or its use by Facebook. For more information, please see Facebook’s Privacy Policy:
https://de-de.facebook.com/privacy/explanation.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDG. Consent can be revoked at any time.
When personal data is collected on our website using the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited to the collection of data and its transfer to Facebook. The subsequent processing of the data by Facebook is not part of the joint responsibility.
Our mutual responsibilities have been outlined in an agreement on joint processing. The wording of this agreement can be found here:
https://www.facebook.com/legal/controller_addendum.
According to this agreement, we are responsible for providing privacy information when using the Facebook tool and for implementing the tool on our website in compliance with data protection laws. Facebook is responsible for the security of Facebook products. Affected rights (e.g., access requests) regarding the data processed by Facebook can be asserted directly with Facebook. If you assert your rights with us, we are obliged to forward them to Facebook.
The transfer of data to the USA is based on the EU Commission’s standard contractual clauses. Details can be found here:
- https://www.facebook.com/legal/EU_data_transfer_addendum
- https://de-de.facebook.com/help/566994660333381
- https://www.facebook.com/policy.php.
Meta Platforms Ireland Limited is certified under the “EU-US Data Privacy Framework” (DPF), which ensures compliance with European data protection standards for processing in the USA. More details about the DPF can be found here:
https://www.dataprivacyframework.gov/participant/4452.
X (formerly Twitter)
This website integrates features of the service X (formerly Twitter). These features are provided by X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. For data processing related to individuals outside the USA, the responsible entity is Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.
When the social media element is active, a direct connection between your device and the X server is established. X receives information that you have visited this website. By using X and the “Retweet” or “Repost” function, the websites you visit are linked to your X account and shared with other users. We would like to point out that we, as the provider of this website, have no knowledge of the content of the transmitted data or its use by X. For more information, please see X’s Privacy Policy:
https://x.com/de/privacy.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDG. Consent can be revoked at any time.
The transfer of data to the USA is based on the EU Commission’s standard contractual clauses. Details can be found here:
https://gdpr.x.com/en/controller-to-controller-transfers.html.
You can adjust your privacy settings on X in your account settings at:
https://x.com/settings/account.
X is certified under the “EU-US Data Privacy Framework” (DPF), which ensures compliance with European data protection standards for processing in the USA. More details about the DPF can be found here:
https://www.dataprivacyframework.gov/participant/2710.
This website integrates features of the Instagram service, provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection between your device and the Instagram server is established. Instagram receives information that you have visited this website. If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account.
We would like to point out that, as the provider of this website, we have no knowledge of the content of the transmitted data or its use by Instagram. For more information, please see Instagram’s Privacy Policy:
https://privacycenter.instagram.com/policy/.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDG. Consent can be revoked at any time.
When personal data is collected on our website using the tool described here and forwarded to Instagram, we and Meta Platforms Ireland Limited are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited to the collection of data and its transfer to Instagram. The subsequent processing of the data by Instagram is not part of the joint responsibility.
Our mutual responsibilities have been outlined in an agreement on joint processing. The wording of this agreement can be found here:
https://www.facebook.com/legal/controller_addendum.
Affected rights (e.g., access requests) regarding the data processed by Instagram can be asserted directly with Instagram. If you assert your rights with us, we are obliged to forward them to Instagram.
The transfer of data to the USA is based on the EU Commission’s standard contractual clauses. Details can be found here:
- https://www.facebook.com/legal/EU_data_transfer_addendum
- https://privacycenter.instagram.com/policy/
- https://de-de.facebook.com/help/566994660333381.
Meta Platforms Ireland Limited is certified under the “EU-US Data Privacy Framework” (DPF), which ensures compliance with European data protection standards for processing in the USA. More details about the DPF can be found here:
https://www.dataprivacyframework.gov/participant/4452.
6. Newsletter
Newsletter Data
If you wish to receive the newsletter offered on this website, we require an email address from you as well as information that allows us to verify that you are the owner of the provided email address and consent to receiving the newsletter. No further data is collected or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.
The processing of the data entered into the newsletter subscription form is based solely on your consent (Art. 6(1)(a) GDPR). You can revoke your consent to the storage of data, the email address, and its use for sending the newsletter at any time, for example, via the “unsubscribe” link in the newsletter. The legality of the data processing carried out prior to the revocation remains unaffected.
The data you provide for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe. Data stored by us for other purposes remains unaffected.
After you unsubscribe from the newsletter distribution list, your email address may be stored in a blacklist to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest as defined in Art. 6(1)(f) GDPR). Blacklist storage is indefinite. You can object to the storage if your interests outweigh our legitimate interest.
7. Plugins and Tools
YouTube with Enhanced Privacy
This website embeds videos from YouTube. The operator of the service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit a page on this website that includes a YouTube video, a connection to YouTube’s servers is established. This notifies the YouTube server about which pages you visited. If you are logged into your YouTube account, you enable YouTube to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube with enhanced privacy mode. According to YouTube, this mode ensures that YouTube does not store information about visitors to this site before they watch the video. However, enhanced privacy mode does not necessarily prevent data sharing with YouTube partners. For instance, YouTube connects to the Google DoubleClick network whether or not you are watching a video.
As soon as you start a YouTube video on this website, YouTube may store various cookies on your device or use similar recognition technologies. These cookies are used to collect information about the visitor’s behavior. This information is used to optimize video functionality and prevent fraud.
The use of YouTube is in the interest of providing an appealing presentation of our online content. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If corresponding consent has been obtained, processing is based exclusively on Art. 6(1)(a) GDPR and § 25(1) TDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g., via device fingerprinting). Consent can be revoked at any time.
For more information about privacy on YouTube, please see their Privacy Policy:
https://policies.google.com/privacy?hl=de.
Google is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA to ensure compliance with European data protection standards for data processing in the USA. Certified companies commit to adhering to these standards. More information can be found here:
https://www.dataprivacyframework.gov/participant/5780.
Vimeo without Tracking (Do-Not-Track)
This website uses plugins from the video portal Vimeo. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.
When you visit one of our pages featuring Vimeo videos, a connection to Vimeo’s servers is established. This informs the Vimeo server about which of our pages you have visited. Vimeo also obtains your IP address. However, we have configured Vimeo to not track your user activities and to not set cookies.
The use of Vimeo is in the interest of providing an appealing presentation of our online content. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If corresponding consent has been obtained, processing is based exclusively on Art. 6(1)(a) GDPR; consent can be revoked at any time.
The data transfer to the USA is based on the EU Commission’s standard contractual clauses and, according to Vimeo, on “legitimate business interests.” Details can be found here:
https://vimeo.com/privacy.
For more information about how Vimeo handles user data, please refer to Vimeo’s Privacy Policy:
https://vimeo.com/privacy.
Vimeo is certified under the “EU-US Data Privacy Framework” (DPF). Certified companies commit to adhering to these standards. More information can be found here:
https://www.dataprivacyframework.gov/participant/5711.
Google Fonts (Local Hosting)
This website uses Google Fonts to ensure a consistent presentation of fonts. Google Fonts are locally installed on our servers. No connection to Google servers is established in this process.
For more information about Google Fonts, see https://fonts.google.com/ and Google’s Privacy Policy:
https://policies.google.com/privacy?hl=de.