Information regarding the collection of personal data
In this declaration, we inform you about the collection of personal data when you use our website.
The entity responsible as defined in Art. 4, Section 7 of the EU General Data Protection Regulation (GDPR) is
Deutsche Energie-Agentur GmbH (dena)
Tel: +49 (0)30 66 777 - 0
Fax: +49 (0)30 66 777 - 699
Directors with authorisation to represent the company: Andreas Kuhlmann, Kristina Haverkamp
You can contact our company data protection officer at firstname.lastname@example.org or via our postal address, with the additional line: ‘z.H. betriebliche Datenschutzbeauftragte’ (‘For the company data protection officer’)
Definition of terms in accordance with Art. 4 GDPR
‘Personal data’ is all information that relates to an identified or identifiable natural entity (e.g. name, address, telephone number, date of birth, e-mail address or usage behaviour).
‘Processing’ means any operation or set of operations, with or without the aid of automated methods, in connection with personal data, such as the collection, recording, organisation, ordering, storage, adaptation or alteration, read-out, querying, usage, disclosure through transmission, distribution or other form of provision, comparison or linkage, restriction, deletion, or destruction.
The ‘controller’ is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Collection of personal data
The following personal data of visitors and users is regularly collected during use of our online offer and our services:
- Basic data (e.g. name, address)
- Contact data (e.g. e-mail, telephone number)
- Contract data (e.g. subject of contract, period of validity, payment history)
- Content data (e.g. text inputs, photographs, videos)
- Usage data (e.g. device information, IP addresses)
Purpose of processing and legal basis
We process your personal data for the following purposes:
- Provision of an online offer (incl. functions and content)
When the website is used for purely informational purposes, i.e., when you do not register or transfer any other information to us, we collect the following data in order to display our website to you and to guarantee stability and security (the legal basis is Art. 6, Section 1, p. 1 lit. f GDPR):
- IP address
- Date and time of the query
- Content of the request (specific page)
- Access status/HTTP status code
- Operating system and its interface
- Language and version of the browser software
The above data (or ‘log files’) is stored for a maximum of 30 weeks for security reasons and for the detection of faults. The log files are then deleted. If, however, the storage of this information is required for the purpose of providing evidence (e.g. during investigation into misuse or fraud), it is not deleted until the investigation of the respective incident has been concluded.
- The provision of contractual performances
In order to fulfil the contract or implement pre-contractual measures, personal data such as basic data and contractual data is processed (legal basis, Art. 6 Section 1 lit b) GDPR).
- Contact enquiries
If you contact us (e.g., by e-mail, telephone, contact form, or social media), your data will be processed in order to process the contact enquiry and its implementation (legal basis Art. 6, Section 1 lit b) GDPR).
If your enquiry is no longer necessary, we will delete it unless statutory storage periods apply. We check the necessity every 3 months. The statutory storage periods continue to apply.
You may assert the following rights with regard to the personal data of which you are the subject:
- The right to information
- The right to correction or erasure
- The right to restriction of processing
- The right to object to processing
- The right to data portability
You can also revoke your consent with effect for the future at any time.
You also have the right to submit a complaint to a data protection supervisory authority regarding the processing of your personal data by us.
Cooperation with order processors and third parties
Your personal data is only disclosed, transferred or otherwise provided for access to third parties on the basis of a statutory permission (e.g. for the fulfilment of contract, following your consent, on the basis of our justified interests or in cases of legal obligation).
If third parties are commissioned with the processing of data on the basis of an order processing contract, they may only process this personal data according to our instructions, in accordance with Art. 28 GDPR.
Thirdly country transfer
It is ensured that before forwarding personal data, either a suitable data protection level exists, or there is an agreement of so-called EU standard contractual clauses of the European Union between dena and the recipients, and/or sufficient approval has been provided by the data subject.
Erasure of data
Your data is only stored for as long as is necessary for the provision of our services and the online offer, and no other statutory period of retention applies. Data that is subject to a statutory retention period is blocked until the corresponding retention period expires. This data is no longer available for further use.
Incorporation of services and content of third parties
On our website, services of third parties are used in order to include e.g. videos or fonts. This is done on the basis of Art. 6, Section 1 lit f) GDPR.
We use the ‘YouTube’ platform to embed videos:
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, represented by Sundar Pichai (Chief Executive Officer). Data Protection Declaration: https://policies.google.com/privacy?hl=de&gl=de
We link geographical maps provided by ‘Google Maps’, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, represented by Sundar Pichai (Chief Executive Officer).
Data Protection Declaration: https://policies.google.com/privacy?hl=de&gl=de
We link fonts provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, represented by Sundar Pichai (Chief Executive Officer). Data Protection Declaration: https://policies.google.com/privacy?hl=de&gl=de
Linkage to third-party pages
Our website also contains links to third-party websites. These websites use the services of suppliers who are not connected to us. After you click on the link, we have no further influence on the collection, storage or processing of personal data transferred to third parties (e.g. IP address or the URL of the page on which the link is located).
Within our website, we use links to Facebook (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland).
Data Protection Declaration: https://de-de.facebook.com/privacy/explanation
Within our website, we use links to Twitter (Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA) profiles. If the user is a member of Twitter, Twitter can assign the retrieval of the above contents and functions to its profiles of users.
Data Protection Declaration: https://twitter.com/de/privacy
Within our website, we use a link to Xing (XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany). If the user is a member of Xing, Xing can assign the retrieval of the above contents and functions to its profiles of users.
Xing data protection declaration: https://www.xing.com/app/share?op=data_protection
On the basis of our justified interest in accordance with Art. 6, Section 1 lit. f) GDPR (interest in improving our online offer), we use tools for analysing the use of our website.
For detailed information, see our cookie guideline.