Privacy Policy

1. Data protection at a glance

General information

The following provides a simple overview of what happens to your personal data when you visit our website. Personal data is all data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy set forth below.

Data collection on our website

Who is responsible for data collection on this website?

The data processing on this website is carried out by the website operator whose contact details can be found in the legal notice of this website.

How do we collect your data?

On the one hand, your data is collected by your communicating it to us. This can be data that you enter in a contact form, for example.

Other data is automatically collected by our IT systems when you visit the website. This is primarily technical data (e.g. Internet browser, operating system or time of the page call). This data is collected automatically as soon as you access our website.

What do we use your data for?

Some of the data is collected to ensure that the website is error-free. Other data may be used to analyse your user behaviour.

What rights do you have with regard to your data?

You have the right at any time and free of charge to receive information about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction, blocking or deletion of this data. You can contact us at any time at the address given in the legal notice in this respect and for any other questions on the subject of data protection. Furthermore, you have the right to appeal to the competent supervisory authority.

Analysis tools and tools of third parties

When you visit our website, your surfing behaviour can be statistically evaluated. This is done primarily with cookies and so-called analysis programmes. As a rule, the analysis of your surfing behaviour is anonymous. Your surfing behaviour cannot be traced back to you. You may object to the analysis thereof or prevent it by not using certain tools. You will find detailed information on this in the following privacy policy.

You can object to this analysis. We will inform you about the possibilities of objection in this privacy policy.

2. General information and mandatory information

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains which data we collect and for what purpose we use it. It also explains how and for what purpose this is done.

We would like to point out that data transmission via the Internet (e.g. communication by e-mail) may be subject to security breaches. Complete protection of the data against access by third parties is not possible.

Note on the responsible body

The responsible body for data processing on this website is:

East Prussian State Museum
Heiligengeiststraße 38, 21335 Luneburg, Germany

Phone: (0)4131 75995-0
E-mail:

The responsible body is the natural person or legal entity who alone or jointly with others decides on the purposes and means of processing personal data (e.g. names, e-mail addresses, etc.).

Revocation of your consent to data processing

Many data processing transactions are only possible with your express consent. You may revoke your consent at any time. For this purpose, an informal notification by e-mail to us is sufficient. The legality of the data processing carried out until the revocation shall remain unaffected by the revocation.

Right of appeal to the competent supervisory authority

In the event of a breach of the data protection law, the person concerned shall have the right to lodge a complaint with the competent supervisory authority. The responsible supervisory authority for data protection issues is the data protection officer of the federal state in which our enterprise is domiciled. A list of data protection officers and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_linksnode. html.

Supervisory authority: Government of Middle Franconia, supervisory authority for foundations, Promenade 27, 91522 Ansbach, Germany

Right to data portability

You have the right to have data which we process automatically on the basis of your consent or in execution of a contract provided to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another responsible person, this will only be done insofar as this is technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock icon in your browser address line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Information, blocking, deletion

Within the scope of the applicable legal provisions, you have the right at any time and free of charge to receive information about your stored personal data, their origin and recipient and the purpose of data processing and, if applicable, a right to correction, blocking or deletion of this data. You can contact us at any time at the address given in the legal notice in this respect and for any other questions on the subject of personal data.

Objection to advertising mails

We hereby object to the use of contact data published in accordance with the obligation to issue a legal notice for the purpose of sending unsolicited advertising and information material. The website operators expressly reserve the right to take legal action against unsolicited mailing of advertising material, such as spam e-mails.

3. Data collection on our website

Cookies

Some of the web pages use so-called cookies. Cookies do not harm your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, more effective and safer. Cookies are small text files which are stored on your computer by your browser.

Most of the cookies we use are so-called "session cookies". They are automatically deleted at the end of your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognise your browser on your next visit.

You can configure your browser so that you are informed about the use of cookies and only allow cookies in individual cases, accept cookies for certain cases or generally exclude them and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

Cookies, which are necessary for the execution of the electronic communication process or for the provision of certain functions you wish to use (e.g. shopping basket function), are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the storage of cookies for the technically error-free and optimised provision of services. As far as other cookies (e.g. cookies for the analysis of your surfing behaviour) are stored, these are treated separately in this privacy policy.

Server log files

The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

This data shall not be combined with data from other sources.

The basis for data processing is Art. 6 para. 1 lit. f GDPR, which permits the processing of data for the fulfilment of a contract or pre-contractual measures.

Contact form

If you send us enquiries via the contact form, your details from the enquiry form including the contact data you provided there will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We do not pass on this data without your consent.

The processing of the data entered in the contact form is therefore carried out exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You may revoke this consent at any time. For this purpose, an informal notification by e-mail to us is sufficient. The legality of the data processing carried out until the revocation shall remain unaffected by the revocation.

The data entered by you in the contact form shall remain with us until you request us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions – in particular retention periods – shall remain unaffected.

4. Social media

Facebook plugins (Like & Share button)

Our website includes plugins of the social network Facebook, provider Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA. You can recognise the Facebook plugins by the Facebook logo or the "Like" button on our website. An overview of the Facebook plugins can be found here: https://developers.facebook.com/docs/plugins/.

When you visit our website, the plugin establishes a direct connection between your browser and the Facebook server. Facebook receives the information that you have visited our website with your IP address. If you click on the Facebook "Like" button while logged into your Facebook account, you can link the content of our website to your Facebook profile. This allows Facebook to associate visits to our website with your user account. We would like to point out that as the provider of the website, we have no knowledge of the content of the transmitted data or its use by Facebook. For more information, please refer to Facebook's privacy policy at: https://dede. facebook.com/policy.php.

If you do not want Facebook to associate visits to our website to your Facebook user account, please log out of your Facebook user account.

5. Newsletter

Newsletter data

If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. Further data will not be collected or will only be collected on a voluntary basis. We use this data exclusively for the dispatch of the requested information and do not pass this on to third parties.

The processing of the data entered in the newsletter registration form takes place exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent to the storage of data, e-mail address and their use to send the newsletter at any time, for example via the "Unsubscribe" link in the newsletter. The legality of the data processing that has already taken place shall remain unaffected by the revocation.

The data that you have stored with us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted after unsubscribing from the newsletter. This does not affect data stored by us for other purposes (e.g. e-mail addresses for the member area).

MailChimp

This website uses the services of MailChimp to send newsletters. The provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.

MailChimp is a service with which the sending of newsletters can be organised and analysed. If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), this will be stored on MailChimp servers in the USA.

MailChimp has a certification according to the "EU-US-Privacy-Shield". The "Privacy-Shield" is an agreement between the European Union (EU) and the USA which is intended to ensure compliance with European data protection standards in the USA.

With the help of MailChimp we can analyse our newsletter campaigns. When you open an e-mail sent via MailChimp, a file contained in the e-mail (a so-called web beacon) connects to MailChimp servers in the USA. In this way it can be determined whether a newsletter message has been opened and which links have been clicked on. Technical information is also recorded (e.g. time of access, IP address, browser type and operating system). This information cannot be allocated to the respective newsletter recipient. It is used exclusively for statistical analyses of newsletter campaigns. The results of these analyses can be used to tailor future newsletters to the interests of recipients more effectively.

If you do not want an analysis by MailChimp, you must unsubscribe from the newsletter. For this purpose we provide a corresponding link in every newsletter message. You can also unsubscribe from the newsletter directly on the website.

Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time by unsubscribing the newsletter. The legality of the data processing operations that have already taken place shall remain unaffected by the revocation.

The data that you have stored with us for the purpose of subscribing to the newsletter will be stored until you unsubscribe from the newsletter and will be deleted from our servers as well as those of MailChimp's after you cancel the newsletter. This shall not affect data stored by us for other purposes (e.g. e-mail addresses for the member area).

For more information, please refer to MailChimp's privacy policy at: https://mailchimp.com/legal/terms/.

Conclusion of a data processing agreement

We have concluded a so-called "Data Processing Agreement" with MailChimp in which we commit MailChimp to protect the data of our customers and to refrain from passing it on to third parties. This agreement can be viewed under the following link: https://mailchimp.com/legal/forms/data-processing-agreement/sampleagreement/.