Introduction
The protection of your personal data is our highest priority. This privacy policy explains the type, scope, and purpose of processing personal data (hereinafter referred to as "data") in connection with our online offer. This includes the associated website, functions, and content, as well as external online presences, such as social media profiles (hereinafter collectively referred to as "online offer"). Your personal data will be treated confidentially and in strict compliance with statutory data protection regulations as well as the provisions of this privacy policy.
General Information
This privacy policy provides you with a comprehensive overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to personally identify you. Detailed information on data protection can be found in this full privacy policy.
Responsible Entity
Data processing on this website is carried out by the website operator. The contact details of the controller can be found in the "Controller" section of this privacy policy.
Collection of Your Data
Personal data is collected, on the one hand, when you actively communicate it to us, e.g., by filling out a contact form. Other data is collected automatically or after your consent when you visit the website by the controller's IT systems. This is mainly technical data (e.g., internet browser, operating system, or time of page view). This data collection occurs automatically as soon as you enter the website.
Use of Your Data
Part of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior in order to optimize the offer and adapt it to your needs. More on this in the "Cookies" section.
Data Transfer to External Parties
Within the scope of the controller's business activities, it may be necessary to transfer personal data to external parties. This transfer takes place only under certain conditions: if the disclosure is necessary for the performance of a contract, if a legal obligation exists, for example to tax authorities, if a legitimate interest according to Art. 6 Para. 1 lit. f GDPR exists, or if another legal basis permits the data transfer. When using external service providers for data processing, the transfer of personal data takes place exclusively on the basis of a valid contract for order processing according to Art. 28 GDPR. If joint processing of data with other entities takes place, a joint controller agreement according to Art. 26 GDPR is concluded.
Revocation of Consent to Data Processing
Certain data processing operations can only take place with your explicit consent. This consent can be revoked at any time. The lawfulness of the data processing carried out up to the time of revocation remains unaffected by the revocation.
Right to Object in Specific Cases and to Direct Marketing (Art. 21 GDPR)
If the processing of your personal data is based on Art. 6 Para. 1 lit. e or f GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation. This also applies to profiling based on these provisions. The specific legal basis for data processing can be found in this privacy policy. In the event of an objection, the controller will no longer process your personal data unless compelling legitimate grounds can be demonstrated which override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims (objection according to Art. 21 Para. 1 GDPR). If your personal data is used for direct marketing purposes, you have the right to object to this processing at any time. This also applies to profiling in connection with direct marketing. After your objection, the controller will no longer use your personal data for these advertising purposes (objection according to Art. 21 Para. 2 GDPR).
Rights under the General Data Protection Regulation
You have the right to lodge a complaint with a competent supervisory authority in the event of infringements of the GDPR. This right can be exercised in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. Other administrative or judicial remedies remain unaffected. Personal data processed automatically based on consent or to fulfill a contract can be requested in a structured, commonly used, and machine-readable format. Upon request, a direct transfer of this data to another controller can also take place, provided this is technically feasible. Every data subject has the right to obtain free information about their stored personal data, its origin, recipient, and the purpose of data processing. Furthermore, there is a right to rectification or erasure of this data, provided legal provisions permit this. For further questions or concerns regarding personal data, you can contact the controller at any time. There is a right to request restriction of processing of personal data if the accuracy of the data is contested and a verification is pending. Also, in the case of unlawful processing, restriction of data processing can be requested instead of erasure. Furthermore, restriction can be demanded if the data is no longer needed but is required to assert, exercise, or defend legal claims. In the event of an objection to processing according to Art. 21 Para. 1 GDPR, pending clarification of whose interests prevail, the right to restriction also exists. If the processing of personal data has been restricted, such data – with the exception of storage – may only be processed with the data subject's consent or to assert, exercise, or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest of the EU or a Member State.
Controller
The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Kamedin WebSolutions
Eldin Trumic
Address: Stargarder Weg 50
Website: www.kamedin.org
Email: website@kamedin.org
Processors
We cooperate with various processors who process data on our behalf. These service providers are contractually obligated to treat the data confidentially and to use it exclusively within the scope of the respective service. Additionally, there are cases where responsibility for data processing is shared jointly with other entities. In such cases, responsibilities are regulated and documented transparently to ensure compliance with data protection requirements.
Definitions
To ensure transparency and make this privacy policy understandable for everyone, terms defined in the General Data Protection Regulation (GDPR) are primarily used. The full statutory definitions can be found in Art. 4 GDPR. The most important terms in connection with this privacy policy are explained below: Personal data: This includes all information relating to an identified or identifiable natural person (hereinafter "data subject"). A person is considered identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie), or one or more specific characteristics that express the physical, physiological, genetic, psychological, economic, cultural, or social identity of this person. Processing: This term includes any action or series of actions performed in connection with personal data, whether or not by automated means. This may include collecting, recording, organizing, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning or combining, restricting, erasing, or destroying data. Controller: This is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Processor: A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller. Consent: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them. Website: The website refers to the entire internet offer provided by the controller under a specific URL. This includes all content, information, functions, and services published by the controller and made accessible to the user via this URL. The website serves as a digital platform for providing information, services, and interaction between the controller and users. End device: An end device is an electronic device capable of accessing the internet and loading web pages. These include computers, laptops, tablets, and smartphones. These definitions help to better understand the privacy policy and comprehend the meaning of the terms used.
Hosting
This website is hosted on the servers of an external service provider to ensure reliable and secure use of this online offer. Data processing by the hosting provider is carried out in accordance with Art. 6 Para. 1 lit. f GDPR, as the controller has a legitimate interest in providing a stable and secure website. Should it be necessary to obtain the user's consent (for example, for the use of certain cookies or tracking technologies), data processing is based on the user's consent in accordance with Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. You can revoke your consent at any time with effect for the future.
The hosting provider is:
1&1 Ionos
Elgendorfer Str. 57, 56410 Montabaur, Germany
Details on data processing and data protection can be found in the privacy policy of the hosting provider. You can find it here: https://www.ionos.de/terms-gtc/datenschutzerklaerung/
Legal Bases for Data Processing
The processing of your personal data is based on the General Data Protection Regulation (GDPR) and other relevant statutory provisions. Depending on the purpose of the data processing, different legal bases apply. If you have consented to the processing of your personal data, this is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR. This applies in particular to the processing of special categories of personal data in accordance with Art. 9 Para. 2 lit. a GDPR as well as the transfer of personal data to third countries under Art. 49 Para. 1 lit. a GDPR. Your consent can be revoked at any time. The processing of your data may be necessary to fulfill a contract or to carry out pre-contractual measures and, in this case, is based on Art. 6 Para. 1 lit. b GDPR. Furthermore, processing may be required to comply with legal obligations, which then occurs in accordance with Art. 6 Para. 1 lit. c GDPR. In certain cases, processing takes place to safeguard the legitimate interests of the controller or a third party, provided that your interests or fundamental rights and freedoms do not override. This processing is based on Art. 6 Para. 1 lit. f GDPR. For certain processing operations, national regulations, such as § 25 TDDDG for the storage of cookies or access to information on your end device, may also apply. The respective applicable legal bases are explained in detail in the specific sections of this privacy policy. If your data is required for the fulfillment of a contract or to carry out pre-contractual measures, processing is based on Art. 6 Para. 1 lit. b GDPR. For compliance with a legal obligation, processing is based on Art. 6 Para. 1 lit. c GDPR. Furthermore, data processing may take place on the basis of legitimate interests according to Art. 6 Para. 1 lit. f GDPR. The specific legal bases in individual cases are explained in the following sections of this privacy policy.
Data Transfer to Insecure Third Countries and Non-DPF Certified US Companies
If tools from companies based in third countries that are insecure under data protection law are used on this website, or US tools are used whose providers are not certified under the EU-US Data Privacy Framework (DPF), your personal data may be transferred to these countries and processed there. It is pointed out that in insecure third countries, a level of data protection comparable to that of the EU cannot be guaranteed. For the USA as an insecure third country, a level of data protection comparable to the EU is generally not guaranteed. A data transfer to the USA is therefore only permissible if the recipient either holds a certification under the "EU-US Data Privacy Framework" (DPF) or has suitable additional guarantees. Detailed information on potential transfers to third countries, including data recipients, can be found in this privacy policy.
Storage Period
Unless a more specific storage period has been specified within this privacy policy, personal data remains with the controller until the purpose for data processing no longer applies. If a legitimate request for erasure is made or consent to data processing is revoked, the data concerned will be deleted, unless there are other legally permissible reasons for storing the personal data (e.g., tax or commercial retention periods). In these cases, erasure takes place after these reasons cease to exist. The controller stores personal data only as long as necessary to fulfill the respective purposes for which the data was collected. These include in particular the fulfillment of contractual obligations, compliance with statutory retention periods, and the safeguarding of legitimate interests of the controller, such as IT security and protection against misuse. Should the processing of personal data be based on consent, storage takes place until this consent is revoked by the data subject. Such revocation is possible at any time with effect for the future. Thereafter, the data will be deleted immediately, unless statutory retention obligations or other overriding legal reasons require further storage. In summary, personal data is deleted after the purpose is fulfilled or the legal basis for storage no longer applies, unless there are still legal obligations or legitimate interests that justify further storage.
Security Measures and Data Minimization
Comprehensive technical and organizational measures are taken to effectively protect your personal data from accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. Care is taken to ensure that only the data absolutely necessary for the respective purpose is collected and processed. This strategy of data minimization helps to significantly reduce the risk of misuse and unauthorized access. The security measures are continuously adapted to the state of the art to permanently ensure a high level of protection for your data.
SSL/TLS Encryption
To protect the security of your data during transmission, encryption methods corresponding to the current state of the art (e.g., SSL or TLS) are used over HTTPS. SSL (Secure Socket Layer) and TLS (Transport Layer Security) are protocols for encrypting data transmissions on the internet. This ensures that the data exchanged between your browser and the server is protected against unauthorized access. You can recognize an encrypted connection by the browser's address line changing from "http://" to "https://" and by the lock symbol in your browser line.
Use of the Contact Form
For questions of any kind, there is the possibility to contact the controller via a form provided on this website. To know who sent the request and to be able to answer it, the following details are required: first name, last name, email address, your inquiry. Data processing for the purpose of contacting the controller is carried out in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR on the basis of voluntarily given consent or to perform pre-contractual measures (Art. 6 Para. 1 lit. b GDPR). The personal data collected for using the contact form will be deleted after completion of your request.
Inquiries by Email or Phone
It is possible to send inquiries to the controller by email. The personal data transmitted (e.g., name, email address, and the inquiry itself) will be processed and stored by the controller solely for the purpose of processing the inquiry and any follow-up questions. The legal basis for this data processing is Art. 6 Para. 1 lit. b GDPR, as processing is necessary to fulfill a contract or perform pre-contractual measures. If the processing is not related to a contract, it is based on Art. 6 Para. 1 lit. f GDPR, as the controller has a legitimate interest in processing and answering the inquiries.
Prohibition of Advertising Emails
The use of contact data published in the legal notice for sending unsolicited advertising and information materials is hereby prohibited. Any unauthorized use of the contact data for advertising purposes represents a violation of the rights of the operator of this website and will not be tolerated. The operator of this website expressly reserves the right to take legal action in the event of violations, particularly regarding the unsolicited sending of advertising information such as spam emails.
Processing of Customer and Contract Data
Personal customer and contract data is collected, processed, and used for the establishment, content organization, and modification of contractual relationships. This may include name, address, email address, and phone number. This information is necessary to provide services and communicate. Depending on the selected payment method, payment information such as credit card details, bank details, or information on other payment services is also collected, which is used exclusively for the payment process. In addition, usage and order data are processed, including information on orders, the services used, prices, and delivery details. Personal data regarding the use of this website (usage data) is only collected, processed, and used to the extent necessary to enable the user to use the service or to bill them. The processing of personal data occurs on various legal bases. In accordance with Art. 6 Para. 1 lit. b GDPR, data processing is carried out to fulfill a contract or perform pre-contractual measures, for example, to process orders and provide services. In addition, processing takes place according to Art. 6 Para. 1 lit. c GDPR to fulfill legal obligations, including statutory retention periods. Furthermore, processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR to safeguard legitimate interests, such as improving services and ensuring IT security. The collected customer data will be deleted after completion of the order or termination of the business relationship and expiry of any existing statutory retention periods. Statutory retention periods remain unaffected.
Server Log Files
The operator of the website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- - Browser type and browser version
- - Operating system used
- - Referrer URL (the previously visited page)
- - Hostname of the accessing computer (IP address)
- - Time of the server request
This data cannot be assigned to specific persons. A combination of this data with other data sources is not performed. Processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR (legitimate interest) to ensure IT security, stability, and error-free provision of our website.
Measures for Misuse and Spam Prevention (Rate Limiting)
To protect our contact form from automated attacks, abuse, and spam (e.g., by botnets), we use automated request limiting (so-called rate limiting) on our server. Here, the IP address of the requesting end device is temporarily recorded in our server's RAM in order to limit the number of requests within a defined time window. The IP address is processed exclusively for this security purpose and is automatically deleted after the time window expires. Permanent storage in a database does not take place. The legal basis for this processing is Art. 6 Para. 1 lit. f GDPR (legitimate interest), as we have an urgent interest in protecting our information technology systems from overload and misuse.
Conclusion of Contracts for Services or Digital Content
When concluding contracts for services or digital content, the controller collects and processes your personal data to fulfill contractual obligations. This data includes, in particular, your contact information such as name, address, email address, and relevant information on the use of the services or digital content. The processing of your data occurs on various legal bases: In accordance with Art. 6 Para. 1 lit. b GDPR, the controller processes your data to fulfill the contract and perform pre-contractual measures, such as providing and using the services. In addition, processing takes place according to Art. 6 Para. 1 lit. c GDPR to fulfill legal obligations, including compliance with statutory retention obligations. Furthermore, processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR to safeguard legitimate interests, such as improving services and ensuring IT security. The collected data is used exclusively for the performance and fulfillment of contracts and is deleted after completion of the contractual relationship and expiry of any statutory retention periods. Your data may be passed on to third parties involved in rendering the service within the scope of contract fulfillment, such as IT service providers. These third parties are contractually obligated to treat your data confidentially and use it exclusively within the scope of rendering the service. The controller ensures that your data is only passed on to the extent necessary for contract fulfillment. Any further transfer of the data does not take place unless you have explicitly consented to the transfer. A transfer of your data to third parties without explicit consent, for example for advertising purposes, does not occur.
Google Fonts
Google Fonts are used on this website. Google Fonts is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This service enables the use of fonts provided by Google to improve the visual design of this website. To ensure the protection of your data, Google Fonts are hosted locally on our own server. As a result, no connection is established to Google's servers, and no transmission of your IP address to Google takes place. Your data remains entirely on the controller's server and is not passed on to third parties.
Cookies
When using tracking software (local/session storage or cookies), a distinction is made between technically necessary cookies and those requiring consent.
To ensure smooth operation of the app, the cookie "aprendo_sid" is used when using the app. This stores your login status to prevent having to log in again with every interaction (§ 25 Para. 2 TDDDG and Art. 6 Para. 1 lit. b GDPR).
To analyze user behavior and display products/information more optimally, the cookies "_ga" and "_ga-XXX" are used.
Technically necessary
In the app area, the app language selected by the user is stored under the cookie 'aprendo_app_lang'.
In the website area, the language selected by the user is stored under the cookie 'lang'.
App Area
When registering in the app, the following data is collected:
- - Username and email address.
- - Passwords are hashed and cannot be viewed, not even by support staff.
- - Your created subjects, sub-topics, main topics, and the flashcards you created, including the corresponding text and image content that you enter.
- - Dates on which vocabs were created and learned.
- - Number of learning rounds of the vocabs, including correct/incorrect counts and the resulting level.
- - If you share your vocabs, they are also visible to visitors without an account.
Legal basis: Art. 6 Para. 1 lit. b GDPR (Performance of a contract).