When you use a service provided by hcsb.digtal GmbH, we process your personal data. This privacy policy explains how and why we process your data and how we ensure that it remains confidential and protected.
We take data protection seriously: as a matter of principle, we only process personal data if this is necessary for the provision of a service or offer or if it is provided voluntarily by the user. We also use technical and operational security measures to protect personal data against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. We regularly review and modernise these precautions.
We collect the data that is generated when you access our digital offers automatically. Otherwise, we collect data based on your entries or messages or through the use of cookies or similar technologies.
Provision of content
Communication
In order to use our digital services, it may be necessary to transfer certain personal data to third countries, i.e. countries where the GDPR does not apply. However, we only allow your data to be processed in a third country if the specific requirements of Art. 44 ff. GDPR are met and thus an adequate level of data protection is guaranteed in that country. This means that the third country must either have an adequacy decision by the European Commission or suitable safeguards in accordance with Art. 46 GDPR or one of the conditions of Art. 49 GDPR. Unless otherwise stated below, we use the currently valid [standard contractual clauses](https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/? uri=CELEX:32021D0914&from=DE “current version of the standard contractual clauses”) for the transfer of personal data to processors in third countries.
In order to protect your privacy and ensure a level of protection appropriate to the risk, we take technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons. These measures ensure the confidentiality, integrity, availability, and resilience of your data. This includes, among other things, the use of recognized encryption methods (SSL or TLS) and pseudonymization.
However, we would like to point out that, due to the structure of the Internet, it is possible that the rules of data protection and the above-mentioned security measures may not be observed by other persons or institutions outside our area of responsibility. In particular, unencrypted data disclosed, e.g., by email, may be read by third parties. We have no technical influence on this.
We delete or anonymize your personal data as soon as it is no longer required for the purposes for which we collected or used it.
However, we may still need to store your data until the expiry of the retention obligations and periods imposed by the legislator or supervisory authorities, which may arise from the German Commercial Code, the German Fiscal Code, and the German Money Laundering Act (usually 6 to 10 years). In addition, we may retain your data until the expiry of the statutory limitation periods (i.e., usually 3 years, but in individual cases up to 30 years) if this is necessary for the assertion, exercise, or defense of legal claims. After that, the relevant data will be deleted.
You can contact the data protection officer with your request by mail or by email at swmh-datenschutz@atarax.de.
This privacy policy is updated from time to time. The date of the last update can be found at the beginning of this information.
We use cookies and similar technologies to provide you with the best experience when using our digital offerings. We use them to ensure functionality, IT security, and fraud prevention.
If cookies, device identifiers, or other personal data are stored or accessed on your device for processing purposes, this is done on one of the legal bases set out in Art. 6 GDPR.
In order to be able to provide the telemedia service you have expressly requested, we also take into account the provisions of Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG), in particular the requirement under Section 25 (2) No. 2 TDDDG.
Cookies are text files that contain data from visited websites or domains and are stored by a browser on users' devices. A cookie primarily serves to store information about a user during or after their visit to an online offering. The stored information may include, for example, language settings on a website, login status, a shopping cart, or video interactions. The term “cookies” also includes other technologies that perform the same functions as cookies (e.g., when user information is stored using pseudonymous online identifiers, also known as “user IDs”).
There are the following types of cookies and functions:
When our offer is used, we automatically employ essential technologies and process the following information:
The collection of these logs and their temporary storage and processing are necessary to ensure system security and integrity (in particular to ward off and defend against attempts at attack or damage) and are carried out in accordance with our legitimate interest (§ 25 (2) No. 2 TDDDG, Art. 6 (1) f GDPR).
The storage period for this log data is usually seven days; for reliable detection of AI bots, it is 30 days. From this point on, this specific server log data is anonymized based on our legitimate interest in statistical evaluation to assess AI bots and their impact on our content (Art. 6 (1) f GDPR).
The legal basis for the aforementioned data processing is our legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f) GDPR.
The following tools and cookies are strictly necessary technologies, i.e., essential for providing our services as requested by the user.
The legal basis for the data processing described below is our legitimate interest pursuant to Art. 6 (1) (f) GDPR.
In order to obtain and store your consent under data protection law, we use the consent management platform from Sourcepoint (Sourcepoint Technologies, Inc., 228 Park Avenue South, #87903, New York, NY 10003-1502, United States). This platform uses strictly necessary cookies to query the consent status and thus display the corresponding content.
The data is stored for a maximum of 13 months.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| consentUUID | UniqueUserID to store the user's consent status | 12 months | Cookie |
| _sp_su | Identification of users for sampling consent rates reporting | 12 months | Cookie |
| _sp_user_consent | UniqueUserID to retrieve the user's consent status stored in our database if necessary | Unlimited | Local storage |
| _sp_local_state | Determines whether a user has seen the consent banner so that it is only shown once | unlimited | local storage |
| _sp_non_keyed_local_state | Information about the metadata and the user's UniqueUserID | unlimited | local storage |
Some elements of our website require that the calling browser can be identified even after a page change. For this purpose, we set the cookie SESSIONID for the duration of your session.
We use the Matomo web analytics platform to analyze visitor data. This serves to optimize our products based on our legitimate interest, Art. 6 (1) (f) GDPR. For this purpose, the following usage information is transmitted to our server and stored for analysis purposes:
Sie können sich über unsere Login-Systeme ein digitales Konto anlegen, mit dem Sie sich nach der ersten Registrierung bei allen unseren jeweiligen digitalen Angeboten anmelden können. Einige Angebote können Sie nur nutzen, wenn Sie sich ein Konto einrichten, beispielsweise
Bei der Anmeldung nutzen wir Cookies in Ihrem Browser, um Sie zu identifizieren.
The following data is processed when a digital account is created:
| Data | Purpose of processing | Storage period |
|---|---|---|
| Log-in data (email address, password) | Logging in or rejecting a user | Until account deletion or after two years if not used if not used after two years |
| Master data | Personal address | Until objection |
| Pseudonymous identifier | Link between user account and subscriber data and recognition of a user | Until end of contract |
| Opt-in data | Securing system operation and identification of the e-mail address | Three years |
| Subscription data | Query of reading authorisation | Until end of contract |
| Identification numbers | Prevention and analysis of misuse | Seven days |
| Usage data | Further development and optimisation of our digital products and subscription offers | Until revocation |
The legal basis for the aforementioned data processing is Art. 6 para. 1 lit. b) GDPR.
Die Löschung Ihres digitalen Kontos können Sie unter leserservice@verlagsgruppe-hcs.de beauftragen. Sie können dann keine anmeldepflichtigen digitalen Dienste mehr nutzen. Wenn Sie noch digitale Abonnements bei uns haben, für die ein digitales Konto erforderlich ist, kann dieses Konto aus rechtlichen Gründen nicht vor Ende der vereinbarten Abo-Laufzeit gelöscht werden. Wenn Sie Ihr digitales Konto löschen, ersetzt das nicht die schriftliche Kündigung eines digitalen Abos. Wenn Sie als Abonnent der gedruckten Ausgabe ein digitales Konto bei uns haben, können Sie Ihr digitales Konto löschen oder dies beauftragen, verzichten dann aber auf die damit verbundenen Funktionen wie den Online-Aboservice.
Wenn Sie sich später wieder für ein digitales Konto registrieren wollen, ist dies jederzeit möglich.
We use cookies based on our legitimate interest in providing a user-friendly service (Art. 6 (1) (f) GDPR) so that you do not have to log in again when you return to the website or app and so that we can automatically recognize you. The function is deleted after 30 days of inactivity. Once the “Stay logged in” function has expired, you will be asked to log in again.
With “Plural,” we offer a digital community platform where users can post comments, engage in discussions, rate content, and participate in interactive formats. The platform is accessible at Plural.
When you use “Plural,” we process personal data necessary for providing and using the community features. This includes, in particular, registration data (e.g., name, email address, ZIP code), profile data, content and interactions within the community (e.g., comments, replies, or reactions), as well as technical usage data such as IP address, device information, and times of use.
This data is processed to provide community features, moderate discussions, ensure the security and integrity of the platform, and improve our services.
The legal basis for the processing is Article 6(1)(b) of the GDPR, to the extent that the processing is necessary for the use of the community, as well as Article 6(1)(f) of the GDPR based on our legitimate interest in ensuring a functional, secure, and constructive discussion platform.
Posts and comments within the community may be visible to other users. Therefore, please do not publish any sensitive or confidential personal data in publicly visible content.
External service providers may be used for the technical provision and moderation of the platform. Where required by law, data processing agreements in accordance with Article 28 of the GDPR have been concluded with these providers.
We reserve the right to moderate, hide, or delete content if it violates legal requirements, our Terms of Use, or our Community Guidelines.
When you contact us, we only collect personal data (e.g. name, e-mail address, telephone number) if you provide it to us voluntarily. This information is expressly provided on a voluntary basis. The purpose of processing your data is to process and respond to your enquiry. This is also our legitimate interest in data processing in accordance with Art. 6 para. 1 sentence 1 lit. f) GDPR.
In the case of a telephone enquiry, your data will also be processed by telephone applications and in some cases also via a voice dialogue system in order to support us in the distribution and processing of enquiries.
We will delete your data that we have received in the course of contacting you as soon as your request has been fully processed and no further communication with you is required or requested by you.
The controller within the meaning of the GDPR is
hcsb.digital GmbH
Schützenstr. 2, d-98527 Suhl
atarax group of companies
Luitpold-Maier-Str. 7
D-91074 Herzogenaurach
Phone: 09132 79800
Email: swmh-datenschutz@atarax.de.
Right to object
If your personal data is processed on the basis of legitimate interests in accordance with Art. 6 para. 1 sentence 1 lit. f) GDPR or Art. 6 para. 1 sentence 1 lit. e) GDPR, you have the right to object to the processing of your personal data in accordance with Art. 21 GDPR. In the event of such an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
In the case of direct marketing, you have the right to object at any time to the processing of personal data concerning you. If you object to processing for direct marketing purposes, the personal data will no longer be processed for these purposes.
Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority against the processing of your personal data if you feel that your rights under the GDPR have been violated. As a rule, you can contact the supervisory authority of your usual place of residence, your workplace or our company headquarters.
We link to websites of other providers or have integrated elements from them into our website. This data protection information does not apply to them - we have no influence on these sites and cannot check that others comply with the applicable data protection regulations.
We reserve the right to change or adapt this privacy policy at any time in compliance with the applicable data protection regulations.