Data protection

We appreciate your interest in our website. The protection of your personal data during the collection, processing and use on the occasion of your visit to our website is very important to us. Your data is protected in accordance with legal regulations. Please take a moment to read the information below. These provide you with information on how we handle your personal data, how and for what purpose this data is used, to whom we pass this data on and how we protect your personal data. Your personal rights are our top priority and we do our best to protect and guarantee these rights.

The person responsible for processing your personal data within the meaning of the European General Data Protection Regulation is:

Kestner Gesellschaft e.V.
Goseriede 11
30159 Hanover
Phone: +49 511 70120 - 0
Email: kestner @ kestnergesellschaft .de

Data protection officer

If you have any questions about data protection, our data protection officer Michael Schöpf schoepf.consulting e.K. michael@schoepf.consulting +49 511 79090938 will be at your service.

Collection and processing of data

Every access to our website and every retrieval of a file stored on the website is logged. The storage serves internal system-related and statistical purposes. The following are recorded:

  • Name of the file accessed
  • Date and time of access
  • amount of data transferred
  • Notification of successful retrieval
  • operating system used
  • Browser and browser type
  • the website from which you were redirected
  • the internet service provider
  • pages visited and
  • requesting domain

Additionally, the IP addresses of the requesting computers are logged. However, the person responsible does not draw any conclusions about a person. This data is only required to be able to display the content of our website correctly, to optimize the content permanently for you and to support criminal prosecutions in the event of hacker attacks. The data are processed on the basis of our legitimate interest in accordance with Art. 6 Para. 1 Subpara. 1 lit. f) GDPR processed. The processing of the data is necessary for the operation of the website. The data is stored as long as it is required to fulfill the purpose and is then automatically deleted.

Affected Rights

According to Art. 15 GDPR, you have the right to information about the processing of your personal data. In addition, you are free to exercise your rights to correction, deletion or, if deletion is not possible, to restriction of processing and data portability in accordance with Articles 16-18, 20 GDPR. If you want to exercise this right, please contact our data protection officer. You also have the right to complain to the responsible supervisory authority at any time. If you are of the opinion that your personal data is not being processed in compliance with data protection laws, we would kindly ask you to contact our data protection officer. You also have the right to object to the processing of your personal data at any time.

Protection of stored data

We use technical and organizational security measures to protect the personal data you have made available to us from manipulation, loss, destruction or access by unauthorized persons. Our security measures are continuously improved and adapted according to the state of the art. It cannot be ruled out that data transmitted by you in unencrypted form can be viewed by third parties during the transmission. It should be noted that with regard to data transmission over the Internet (e.g. when communicating by e-mail), no ultimately secure transmission can be guaranteed. Sensitive data should therefore either not be transmitted at all or only via a secure connection (SSL) over the Internet.

Protection of minors

Consent to the processing of personal data can only be given by an adult. For information society services, the consent of a child from the age of sixteen is permitted in accordance with Art. 8 GDPR.

Inquiry form (kestnershop)

All your personal data and other information that you provide to us via the registration form on our website will only be collected and processed for the purpose of processing and answering your inquiries. If you contact us, you give your consent for data processing in accordance with Art. 6 Para. 1 subpara. 1 lit. a) GDPR. If you are interested in an offer, your personal data will be used for the purpose of contract initiation in accordance with Art. 6 Para. 1 subpara. 1 lit. b) GDPR processed. Your data will be forwarded to us via email via our provider. If this is not provided, it is unfortunately not possible for us to contact you and process your request. Automated decision-making is not carried out.

Your personal data will not be passed on to external third parties. A transfer of the personal data you have provided to a third country or an international organization does not take place and is also not planned.

You have the right to revoke your consent at any time with future effect. The legality of the data processing carried out until the revocation remains unaffected. Your personal data, which you communicate to us via the contact form, will be stored by us for the duration of the processing of your request and kept until the relevant legal deadlines have expired.

E-mail contact

You can contact us on our website using the email address provided. If you take advantage of this option, the personal data transmitted with the email will be saved and only collected and processed for the purpose of processing and answering your questions. If you contact us, you give your consent for data processing in accordance with Art. 6 Para. 1 subpara. 1 lit. a) GDPR. If you are interested in an offer, your personal data will be processed for the purpose of contract initiation in accordance with Art. 6 para. 1 subpara. 1 lit. b) GDPR processed. If it is not made available, it is unfortunately not possible for us to process your request. Automated decision-making is not carried out.

Your personal data will not be passed on to external third parties. A transfer of the personal data you have provided to a third country or an international organization does not take place and is also not planned.

You have the right to revoke your consent at any time with effect for the future. The legality of the data processing carried out up to the point of revocation remains unaffected. Your personal data, which you communicate to us, will be stored by us for the duration of the processing of your request until the relevant legal deadlines have expired.

Newsletter

If you order our electronic newsletter, your personal data will only be used for the purpose of regularly sending our newsletter and the associated performance measurement on the basis of Art. 6 para. 1 subpara. 1 lit. a) GDPR processed. After registration, we will send you a confirmation e-mail that allows us to verify your identity and confirms your consent again. Your data will be forwarded to us by email via our provider. If it is not provided, it is unfortunately not possible for us to provide you with our newsletter, to contact you and to process your request. Automated decision-making is not carried out. We point out that we have no knowledge of the transmitted data, neither of the content nor of their use by Mailchimp. Mailchimp's privacy policy is available at: https://mailchimp.com/legal/privacy/

You have the right to revoke your consent at any time with effect for the future. The legality of the data processing until the revocation remains unaffected. Your personal data that you provide to us when you subscribe to the newsletter will be stored by us until you withdraw your consent to receive the newsletter and will be removed from the mailing list after you unsubscribe.

User log-in (account)

All your personal data and other information that you provide to us when registering on our website and within the customer portal will only be used for the purpose of your registration and future login on the basis of Art. 6 Para. 1 subpara. 1 lit. b) GDPR collected and processed. If you do not provide it, you will unfortunately not be able to register on our website and use the customer portal. Automated decision-making is not carried out.

Your personal data will not be passed on to external third parties. A transfer of the personal data you have provided to a third country or an international organization does not take place and is also not planned.

Your personal data, which you provide to us via registration and in our customer portal, will be stored by us until you log out or have your user account deleted or deleted and, if applicable, in accordance with a statutory retention period.

Kestnershop

All your personal data and other information that you provide to us in the course of an online order will only be used for the purpose of processing your order in our Kestnershop on the basis of Art. 6 Para. 1 subpara. 1 lit. b) GDPR collected and processed. If this is not provided, it is unfortunately not possible to take an online order. Automated decision-making is not carried out.

Your personal data will not be passed on to external third parties. A transfer of the personal data you have provided to a third country or an international organization does not take place and is also not planned. Your personal data that you provide to us when ordering online will be stored by us for the duration of the ordering process and in accordance with the statutory retention period and will be deleted or blocked immediately after this time has elapsed.

Cookies

Technically necessary cookies (session cookies)

We use technical cookies on our website to make the website more user-friendly. In order to use the full functionality of our website, it is therefore necessary for technical reasons to allow session cookies. The purpose of using such cookies is to enable you to use the website in a simplified and more user-friendly manner. It is therefore necessary that the browser can also identify you after changing pages.

The data will not be used to create a user profile for you. The legal basis for the use of technical cookies is our legitimate interest in accordance with Art. 6 Para. 1 subparagraph. 1 lit. f) GDPR. It is not possible to use the website without session cookies.

Analysis cookies (tracking cookies)

In addition to the use of technical cookies, tracking cookies are used on this website. Cookies are text files that are stored on your computer and that enable your use of the website to be analyzed. However, these collect and save the data exclusively in pseudonymous form. They are not used to personally identify you and are not merged with data about the bearer of the pseudonym. We use this information to determine the attractiveness of our website and to continuously improve its content. The legal basis for the use of tracking cookies is the consent you have given in accordance with Art. 6 Para. 1 subparagraph. 1 lit. a) GDPR. You have the right to revoke your consent at any time with effect for the future. The legality of the data processing until the revocation remains unaffected. You can adjust the cookie settings at any time.

Individual information about the cookies and analysis services used as well as the purpose and legal basis of the data processing are further described in detail in the data protection declaration.

Matomo

We use the open source software Matomo (formerly PIWIK) on our website. Matomo is offered by Matomo.org. This is provided in particular by InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand. Cookies are text files that are stored on your computer and make it possible to analyze your use of the website. The information generated is stored on our servers. Your IP address is stored anonymously in order to evaluate visitor access. A connection to your person is therefore excluded. The IP address transmitted by Matomo is not merged with other data. The collection within the scope of this service only takes place after you have given your express consent. The legal basis for the survey is your consent in accordance with Art. 6 Para. 1 Subpara. 1 lit. a) GDPR. You have the right to revoke your consent at any time with future effect. The legality of the data processing until the revocation remains unaffected.

Your personal data will not be passed on to external third parties. A transfer of the personal data you have provided to a third country or an international organization does not take place and is also not planned. The data will be deleted as soon as they are no longer required for our recording purposes. Further information on data protection can be found at: https://matomo.org/gdpr-analytics/

Google Maps

Our website uses Google Maps API (Application Programming Interface) for the visual display of geographic information (site plans). Google Maps is operated by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland; hereinafter: “Google”). This enables us to make it easier for you to find us or to point out specific locations.

Google should therefore also be named as the recipient of the data. When using Google Maps, information about the use of our website including your IP address is transmitted to a Google server in the USA and stored there. This data processing takes place on the basis of Art. 6 Para. 1 Subpara. 1 lit. a) GDPR, as the IP address is required in order to be able to deliver the content to you. You have the right to revoke your consent at any time with future effect. The legality of the data processing until the revocation remains unaffected.

In this processing, the cooperation with Google takes place on the basis of a contract on joint responsibility in accordance with Art. 26 GDPR. This can be called up at https://privacy.google.com/intl/de/businesses/mapscontrollerterms/.

The transmission of data to the USA is associated with risks in terms of data protection law. If you do not want the transmission, you can deactivate your consent in the cookie settings. However, we would like to point out that in this case you will not be able to use the map display.

You can find more information about the collection and processing of your data by Google as well as your relevant data subject rights in Google's data protection declaration at http://www.google.com/policies/privacy/?hl=de as well as in the additional terms of use for Google Maps or . Google Earth at https://www.google.com/intl/de_de/help/terms_maps.html.

Social media

We would like to get in contact with you and other interested parties, customers and users. We use different social networks for this. You can find out which individual social networks we use in the following section.

However, we would like to point out that we basically have no influence on which data is collected. As a rule, however, this is data that is used in the context of market research and for advertising purposes. This is usually done by creating user profiles and the interests determined from them. This makes it possible to show you customized advertising. Therefore, cookies may also be set on your computer when you use social networks.

Furthermore, we would like to point out that your data can also be processed outside of the European Union and therefore there is a risk that you will not be able to properly enforce your rights.

Basically, we would like to provide you with information in the easiest and fastest way possible or give you the opportunity to share it. Therefore, if you have not consented to the data processing on the respective platform, the legal basis is our legitimate interest in accordance with Art. 6 Para. 1 Subpara. 1 lit. f) GDPR. If you have given your consent to the respective platform, your consent is required in accordance with Art. 6 Para. 1 subpara. 1 lit. a) GDPR the legal basis for processing. You have the right to revoke your consent at any time with effect for the future. The legality of the data processing until the revocation remains unaffected.

Facebook (Link)

On our website we use a reference (link) to our presence in the social network Facebook (Facebook fan page) in order to interact with Facebook users who call up the fan page. For this Facebook fan page we are with Facebook Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland; hereinafter: "Facebook") joint controller in accordance with Art. 26 of the General Data Protection Regulation (GDPR). The agreement on joint responsibility can be found under the following link: https://www.facebook.com/legal/terms/page_controller_addendum

We hereby inform you about the type and scope of the personal data that are processed when you use our Facebook fan page.

By processing your personal data, we pursue the purpose of providing visitors with a modern information platform and an opportunity to interact on Facebook. The basis of the processing is therefore our legitimate interest in accordance with Art. 6 Para. 1 Subpara. 1 lit. f) GDPR. The interests of the users are always taken into account. Information on the legal basis for processing on Facebook can be found at http://www.facebook.com/about/privacy/legal_bases/.

When visiting our Facebook fan page, Facebook will, on the basis of the legitimate interest in accordance with Art. 6 Para. 1 Subpara. 1 lit. f) GDPR collected and processed personal data. Part of this data is made available to us in a summarized form via the so-called "Insights" (Facebook user statistics). A cookie is stored on the user's device for this purpose. This serves to be able to use this information again at a later point in time. The cookie remains active for two years if it is not deleted. Further information from Facebook on the use of cookies can be found in the Facebook cookie policy at https://de-de.facebook.com/policies/cookies/. The transmission of these user statistics takes place exclusively in anonymous form and we have no access to the respective underlying data.

Whether Facebook transmits personal data to third parties is beyond our control. It is possible that Facebook Inc., based in the USA, processes personal data outside of the European Union.

If you are already logged in to Facebook via your personal user account, the information about your visit to our website is automatically forwarded to Facebook. It is then possible for Facebook to assign the visit to the website to your account. If you do not want Facebook to transmit and save your data, please log out of your Facebook account.

Twitter (Link)

On our website we use a reference (link) to our presence on the social network Twitter. This is an application from Twitter Inc. (1355 Market St, Suite 900, San Francisco, CA 94103, USA; hereinafter: “Twitter”). We would like to point out that we have no knowledge of the content of the data transmitted or its use by Twitter. You can find more information at: https://twitter.com/de/privacy

The Twitter function integrated on our website is offered by Twitter Inc. (1355 Market St, Suite 900, San Francisco, CA 94103, USA). By using this function, your visit to our website is linked to your Twitter account. In the course of this, the data is automatically transmitted to Twitter. If you do not want data to be transmitted to Twitter, you can change your Twitter account settings. We would like to point out that we have no knowledge of the transmitted data, neither of its content nor of its use by Twitter. Twitter's data protection declaration can be accessed at: https://twitter.com/privacy?lang=de.

Instagram (Link)

On our website we use a reference (link) to our presence on the social network Instagram. This is an application from Facebook Inc. (Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland; hereinafter: "Facebook"). We would like to point out that we have no knowledge of the content of the data transmitted or its use by Facebook. More information is available at: https://help.instagram.com/519522125107875

Vimeo (videos)

This website integrates videos via Vimeo.com, a service provided by Vimeo LLC (555 West 18th Street, New York, New York 10011, USA; hereinafter: "Vimeo"). When you view videos via Vimeo, a connection to Vimeo's servers in the USA is established. As a result, certain information is transmitted to Vimeo. It is also possible that Vimeo places cookies on your device. Vimeo also enables certain other functions to be used, such as rating or sharing videos. To do this, it may be necessary for you to log into your user account at Vimeo or certain third-party providers (such as Facebook or Twitter) so that they can assign the information you have transmitted to your respective user account. These functions are offered exclusively by Vimeo and the respective third party providers. You should check their data protection regulations carefully before using the respective functions. We have no knowledge of the content of the data collected by Vimeo or third-party providers and we have no influence on their use. Further information on the collection and use of your data by Vimeo and your rights in this regard can be found in Vimeo's data protection declaration at: https://vimeo.com/privacy.


Newsletter

Subscribe to our newsletter! We will inform you regularly about our exhibitions, events and digital offers.