Data protection statement*

I. Scope

Kulturprojekte Berlin GmbH, Klosterstraße 68, 10179 Berlin-Mitte (hereinafter referred to as „Kulturprojekte Berlin“ or „Lange Nacht der Museen“ or „we“) operates the website accessible at langenachtdermuseen.berlin and its respective subdirectories (hereinafter also referred to as the “website”), including all of the associated project web pages (together “websites”), and the web shop (https://shop.langenachtdermuseen.berlin), as well as the database „Datenhub“ (https://datenhub.kulturprojekte.berlin), and social media profiles (hereinafter also referred to as “social networks”).

This data protection statement is designed to provide you with information on the personal data we collect when you use our websites and the manner in which it is processed. This includes the data that is processed when you visit our project websites and social media profiles as well as when you subscribe to our newsletter. By issuing this statement, we are also fulfilling our legal obligation to provide users with information in accordance with Art. 13 and Art. 14 of the European Union’s General Data Protection Regulation (GDPR).

II. Controller

Kulturprojekte Berlin GmbH
Klosterstraße 68, 10179 Berlin-Mitte
Managing director: Moritz van Dülmen
Project lead: Annette Meier
Email: [email protected]

III. Data protection officer

Dr. Michael Funke
JBB Data Consult GmbH
Friedrichstraße 95, 10117 Berlin
Phone: +49 (0)30 443765-0
Email: [email protected]

IV. Purposes and legal bases as well as duration of data processing

1. Data processing on the websites to which this privacy policy applies

1.1 Website of the Lange Nacht der Museen
Lange Nacht der Museen automatically collects and stores information in its server log files that your browser transmits to us. This information comprises the following:

• user agent (browser type / version)
• host name of the accessing computer (IP address)
• time stamp of the request
• requested file

This information does not permit Lange Nacht der Museen to draw any conclusions about you as a specific person.

Insofar as a connection IP address is processed, the legal basis for this processing is derived from Art. 6(1)(f) GDPR. Our legitimate interest here is to offer you access to our website and to enable you to use the site, as well as for us to be able to track unauthorised access attempts and unlawful use of the website or portal.

We store our log files for 24 hours.

1.2 Web shop
The sub-page for our web shop (https://shop.langenachtdermuseen.berlin) is provided via the platform go-mus by Giant Monkey, an external service provider. For more information, please refer to Section XI in this privacy notice: Use of technologies and integration of external services

1.3 User account „Datenhub“
When you register as partner of Lange Nacht der Museen at www.datenhub.kulturprojekte.berlin, we will ask in particular for your name and your email address. We will process the access data you provide upon registration solely for the purpose of giving you access to your user account and making your account available for use. The legal basis for this processing of your data is Art. 6(1)(b) GDPR, i.e. this processing is necessary for the provision of the account.

We store your data for as long as you have a user account with us. After that, your data will be deleted immediately. To delete your user profile, please contact the controller named above under II. or [email protected]. If you encounter any problems, please also contact [email protected].

2. Newsletter
We provide you with the opportunity to subscribe to a newsletter, and in order to be able to send it to you, we ask that you provide an email address. We also analyse our newsletter service by collecting certain usage data.

The legal basis for the processing of your data for the purposes of sending the newsletter derives from Art. 6(1)(a) GDPR. The analysis of user data is based on Art. 6(1)(f) GDPR. Our legitimate interest in both of these cases lies in the optimisation of our newsletter services.

We store the data processed for the email newsletter until you revoke your consent. The analysed usage data is stored for a maximum of one year.

3. Contact

We offer you the opportunity to contact us, for example via our email address or by telephone. When you send us an email, you provide us in most cases with your email address, your name, a subject header and the content of your enquiry. We process this data in order to be able to answer your enquiry. This purpose also constitutes our legitimate interest in data processing (Art. 6(1)(f) GDPR). If necessary, this processing may also take place for the performance of a contract with you. The legal basis in this case is Art. 6(1)(b) GDPR.

In general, we store your enquiry for as long as necessary to process your enquiry, unless any legal provisions prohibit such a deletion and/or, in particular, if further storage is required in accordance with Art. 6(1)(f) GDPR for the purpose of complying with obligatory storage periods in accordance with Art. 6(1)(c) GDPR. If the enquiry is made in the context of an existing or prospective contractual relationship with us, the storage period will depend on the underlying contractual relationship.

V. Data processing period

Unless a data storage period is expressly mentioned elsewhere in this data protection statement, we will process your data only as long as required for the purpose of processing. In addition, we may store your data, if necessary, for the purpose of establishing, exercising and defending legal claims or to comply with statutory data retention periods. The legal basis for this is Art. 6(1)(c) GDPR in conjunction with §147 and §257 of Germany’s Fiscal Code (AO) as well as Art. 17(3) GDPR. We will delete your data as soon as we no longer need it for these purposes.

VI. Recipients of your data (categories of recipients)

Your data will be processed internally by those members of our staff who are responsible for the matter that concerns you. We also use external service providers insofar as we are not able – or cannot reasonably – perform the services ourselves. These external service providers are primarily providers of IT services, such as hosts, email providers or telecommunications providers.

VII. Data transfer to a third country

Unless expressly stated elsewhere in this data protection statement, we do not intend to transfer your personal data to a third country outside of the EU or EEA states.

VIII. Rights of the data subject

Unless expressly stated elsewhere in this data protection statement, we do not intend to transfer your personal data to a third country outside of the EU or EEA states.

  • Art. 15 GDPR – The data subject’s right to information: You have the right to obtain confirmation from us as to whether or not personal data concerning you are being processed and, where that is the case, to be informed as to what these data are as well as more detailed information on the nature of the data processing.
  • Art. 16 GDPR – Right to rectification: You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
  • Art. 17 GDPR – Right to erasure (‘right to be forgotten’): You have the right to obtain from us the erasure of personal data concerning you without undue delay.
  • Art. 18 GDPR – Right to restriction of processing: You have the right to obtain from us the restriction of processing.
  • Art. 20 GDPR – Right to data portability: If the processing is based on consent or a contract, you have the right to receive the personal data concerning you and which you provided to us in a structured, commonly used and machine readable format, and to transmit this data to another controller without hindrance from us. You also have the right to have those data transmitted directly from us to another controller, insofar as this is technically feasible.
  • Art. 21 GDPR – Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is necessary due to a legitimate interest on our part or for the performance of a task carried out for reasons of public interest or in the exercise of official authority.

    If you make use of your right to object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves the establishment, exercise or defence of legal claims.

    Where we process your personal data for direct marketing purposes, you have the right to object at any time to this processing. If you object to processing for direct marketing purposes, we will no longer process your personal data for such purposes.
  • Art. 77 GDPR in conjunction with § 19 of Germany’s Federal Data Protection Act (BDSG) – Right to lodge a complaint with a supervisory authority: You have the right at any time to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal information relating to you violates applicable law.
  • Withdrawal of consent: If you have given us consent, you have the right to withdraw this consent at any time. All data processing that we have carried out up to the point of your withdrawal of consent will remain lawful in this case. For the purpose of withdrawing your consent, we ask that you send us a message at one of the abovementioned addresses.

IX. Obligation to provide data

You have no contractual or legal obligation to provide us with personal data. However, without the data you provide, we may not be able to provide you with our services.

X. Existence of automated decision making (including profiling)

We do not use automated decision making that has any legal impact on you or adversely affect you.

XI. Use of technologies and integration/involvement of external services

1. Cookies and other technologies

Our websites use so-called cookies and other technologies. They help to make our services more user-friendly, effective and secure. Cookies do not cause any damage to your computer and do not contain any viruses. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called “session cookies”. They are automatically deleted at the end of your visit. Other cookies remain stored on whatever device you are using until you delete them yourself. These cookies make it possible for us to recognise your browser upon your next visit to our website.

You can usually adjust your browser settings to inform you when cookies are stored, to only allow cookies in individual cases, to prohibit the acceptance of cookies in certain cases or overall, and to activate the automatic deletion of cookies when closing your browser. When you deactivate cookies, it might limit the functionality of these websites.

The legal basis for the processing of personal data in this context derives from Art. 6(1)(f) GDPR insofar as the cookies are used to provide the services you have requested. Our legitimate interest here is to provide you with the best possible user experience. To the extent that cookies are not required, they are used with your consent in accordance with Art. 6(1)(a) GDPR, which you can revoke at any time with effect from that moment on.

2. User access analysis (Google Analytics)

This website makes use of the functions offered by the web analysis service Google Analytics. The provider is Google LLC., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA (“Google”).

We use Google Analytics to analyse the visits made to our website. For this purpose, Google Analytics uses cookies that have the names „_ga“ and „_ga_<container-id>“, whose storage period is 2 years. The information created by cookies in connection with your use of this website will usually be transmitted to a server belonging to Google in the US, where it will be stored. In this process, we use the function anonymizeIP, which anonymises your IP address by abbreviating it, which means that the IP address is not saved by Google in its complete form. For the purposes of data transmission to the US, we have concluded so-called standard data protection agreements with Google LLC. You may request a copy at [email protected]. More information on how Google Analytics handles user data can be found in Google’s own data protection statement: https://support.google.com/analytics/answer/6004245?hl=en&sjid=13276331846777168576-EU

The legal basis for this processing is your consent in accordance with Art. 6(1)(a) GDPR. You may revoke your consent to the use of web analysis at any time with effect from that moment on by clicking here (opt-out link). In this case, a so-called opt-out cookie will be stored in your browser to ensure that Google Analytics no longer collects any data from you. However, if you delete your cookies, the opt-out cookie will also be deleted and you will be asked again for your consent the next time you visit our websites.

In addition to revoking your consent, you can also generally prevent the collection of your data by Google Analytics by clicking on the following link https://tools.google.com/dlpage/gaoptout?hl=en. An opt-out cookie will be stored in your browser which will prevent the collection of your data upon future visits to this website.

3. Social networks

We have profiles on social networks. Our social media accounts complement our website and give you the opportunity to interact with us. As soon as you access our social media profiles on social networks, the terms and conditions and data processing policies of the respective operators apply.

Strictly speaking, we have no influence on the data processing carried out on social networks. When you use the services of these networks, the data collected about you is processed by the networks themselves and may be transmitted to countries outside the European Union. Information on which data are processed by social networks and for what purposes is found below in the privacy policies and data protection statements of the respective networks. We use the following social networks:

Facebook
Meta Platforms Ireland Limited ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Irland
Privacy policy: www.facebook.com/about/privacy/
Opt-out options: www.facebook.com/settings?tab=ads and www.youronlinechoices.com
About insights: www.facebook.com/legal/terms/information_about_page_insights_data

Instagram
Meta Platforms Ireland Limited ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Irland
Privacy policy / Opt-Out-Options: www.privacycenter.instagram.com/policy/

Tiktok
TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Irland.
Privacy policy: www.tiktok.com/legal/page/eea/privacy-policy/en
Opt-out options: https://support.tiktok.com/en/account-and-privacy/personalized-ads-and-data/personalization-and-data

X (Former Twitter)
Twitter International Company, c/o: Data Protection Officer, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07 Ireland.
Privacy policy: www.x.com/de/privacy
Opt-out options: www.twitter.com/personalization

Threads
Meta Platforms Ireland Limited ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Irland
Privacy policy / Opt-Out-Options: https://help.instagram.com/515230437301944

When you send us enquiries via social media profiles, we process your personal data in our function as data controller. We process this data as a way of responding to your enquiries, which is also our legitimate interest in accordance with Art. 6 (1)(f) GDPR.

As joint controllers alongside the following networks, we are also jointly responsible for the following processing in accordance with Art. 26 GDPR.

When visiting our profiles on Facebook, Instagram and TikTok, each of these networks collects aggregated statistics (“Insights data”) that are created from certain events logged by their servers when you interact with our profiles and related content. We receive these aggregated and anonymous statistics from the networks with regard to the use of each profile. In general, we are not able to attribute data to specific users. We are able only to a certain extent to determine the criteria according to which each network creates these statistics for us. We use these statistics to make our profiles more interesting and informative for you. This also establishes our justified interest in accordance with Art. 6(1)(f) GDPR in the data collection carried out by the respective social network in order to provide us with statistics. Further information on this data processing can be found in each of the site’s Joint Controller Agreements:

Facebook / Instagram / Threads: www.facebook.com/legal/terms/page_controller_addendum?_rdr

TikTok: www.tiktok.com/legal/page/global/tiktok-analytics-joint-controller-addendum/en

4. Open Street Map

We use the OpenStreetMap (OSM) map service. We integrate the map material from OpenStreetMap on the server of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. The United Kingdom is considered a secure third country under data protection law. This means that Great Britain has a level of data protection that corresponds to the level of data protection in the European Union. When using the OpenStreetMap maps, a connection is established to the servers of the OpenStreetMap Foundation. Among other things, your IP address and other information about your behaviour on this website may be forwarded to the OSMF. For this purpose, OpenStreetMap may store cookies in your browser or use comparable recognition technologies. The use of OpenStreetMap is in the interest of an appealing presentation of our online offers and an easy findability of the places indicated by us on the website. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user’s terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

5. Typeform

For the purpose of processing various queries and forms, we use a service called Typeform by TYPEFORM SL, C/Bac de Roda, 163 (Local), 08018 Barcelona Spain (Typeform). This service makes it possible for us to provide you with a simple contact option and also to simplify queries.

For this purpose, we regularly pass the following personal information to Typeform:
• your e-mail address
• your first name
• your last name

In addition, depending on the requirements associated with the query, it is possible that further personal data (for example, information pertaining to a person’s profession in the case of press accreditation forms) may be transmitted to Typeform. Mandatory information is marked with an “*”.

Typeform is the recipient of your personal data and carries out the processing of the data on our behalf. The processing of the data specified in this section is neither legally nor contractually prescribed. Without your consent and the transmission of your personal data, we will not be able to make a contact form available to you. However, you also have the option of contacting us using the e-mail address given above. Your data will be stored exclusively for the purpose of sending and responding to enquiries. In this case, the mandatory information is necessary to be able to properly allocate and respond to your enquiry. In addition, Typeform uses cookies to collect the following personal data: information about your device, including IP address, device details, operating system, browser settings, etc.

In addition, user data such as the time and date you used the contact form will also be collected. Typeform requires this data to ensure that the contact form is displayed correctly and to guarantee that it functions properly. This is in keeping with the legitimate interest of Typeform in accordance with Art. 6 (1) (f) GDPR and serves the purpose of carrying out the contract in accordance with Art. 6 (1) (b) GDPR. For more information, please visit: https://help.typeform.com/hc/en-us/articles/360029581691-What-happens-to-my-data

For more information on your options for redress and the removal of your information in relation to Typeform, please visit: https://admin.typeform.com/to/dwk6gt

The legal basis for the processing of your data is your consent in accordance with Art. 6 (1) (a) GDPR. You can withdraw your consent to the processing of your personal data at any time by using the contact options provided. Your data will be processed for as long as you have given consent. When you withdraw your consent, it shall not affect the legality of the processing that has taken place thus far.

Your data will be deleted no later than 12 months after processing has been completed.

6. Cloudflare

On our website we use a so-called Content Delivery Network (“CDN”) of the technology service provider Cloudflare Inc, 101 Townsend St. San Francisco, CA 94107, USA (“Cloudflare”). The use of Cloudflare’s Content Delivery Network helps us to optimise the performance of our website.

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the secure and efficient operation and improvement of the stability and functionality of our website.

We have concluded a data processing addendum with Cloudflare (available at www.cloudflare.com/media/pdf/cloudflare-customer-dpa.pdf), which obliges Cloudflare to protect the data of our website visitors and not to pass it on to third parties. For the transfer of data from the EU to the USA, Cloudflare relies on so-called standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection in the USA.

Further information can be found in Cloudflare’s privacy policy at: www.cloudflare.com/privacypolicy/

7. External platform go-mus (web shop)

The sub-page for our web shop (https://shop.langenachtdermuseen.berlin) is provided via the go-mus shop platform by the external service provider Giant Monkey.

7.1 Provision of the shop and web hosting
Description: The website is hosted with a website hosting provider that utilises cloud-based servers within the EU to provide a stable and secure hosting platform. Our website is distributed via a content delivery network with servers around the world to ensure fast and secure delivery of our website to our website visitors.

Types of data processed:
• Usage data: e.g. web pages visited, access times, all entries within our online offering or from websites
• Communication data: e.g. browser type, operating system or IP addresses

Data protection subjects: Users (website visitors). Purpose of processing: Fast provision of a stable and secure online service Legal basis: Technically necessary (§ 25 para. 2 no. 2 TTDSG) and legitimate interest (Art. 6 para. 1 sentence 1 lit. f. GDPR).

Recipients or categories of recipients: Website hosting provider, SSL certificate provider, content delivery network provider

The data is stored for 90 to 180 days.

7.2 Order process
Description: The online shop enables the purchase of tickets for the Long Night of Museums in Berlin. Personal data is collected for the purpose of the purchase and the obligations arising from the resulting purchase contract.

Types of data processed:
• Usage data (mandatory fields are marked with an asterisk *): First name*, last name*, company, street and house number*, address suffix, postcode*, city*, federal state/canton, telephone, e-mail*, VAT ID no., country*

Data protection subjects: Users (shop customers)

Purpose of processing: Fulfilment of the purchase contract

Legal basis: Contract fulfilment and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b. GDPR)

Recipients or categories of recipients: Website hosting provider, transactional email provider, invoice provider, Kulturprojekte Berlin

Personal data will be processed for the purposes mentioned until the end of the existing contract. In addition, we store personal data in accordance with Art. 6 para. 1 lit c) GDPR to fulfil our statutory retention obligations in accordance with § 257 para. 4 HGB, § 147 para. 3 AO.

7.3 Payment service providers
Description: We use external payment providers for the online shop on this website in order to offer our customers various payment options. The processed data will only be passed on for the purpose of payment processing with the payment service provider and only to the extent necessary for this purpose. We do not store any credit card data ourselves.

Types of data processed:
• Usage data: Name, address, account number, sort code, credit card number (if applicable), invoice amount, currency and transaction number
• Communication data: e.g. IP addresses, browser type, operating system. Data protection subjects: Users (website visitors)

Purpose of processing: Offering external payment providers for the online shop on this website in order to offer customers various payment options. Legal basis: Contract fulfilment and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b. GDPR).

Recipients or categories of recipients:
• Usage data: Adyen N.V. German Branch, Jägerstraße 27 10117 Berlin, https://www.adyen.com/de_DE/privacy-policy/transaction
• Communication data: Website hosting provider, transactional email provider

Personal data will be processed for the purposes mentioned until the end of the processing of the existing contract. In addition, we store personal data in accordance with Art. 6 para. 1 lit c) GDPR to fulfil our statutory retention obligations.

* Please note: This is an English translation of the original German Datenschutzerklärung (data protection statement). It provides an overview of your data protection rights and the manner in which we process your personal data. This English translation is intended solely as a convenience to the non-German-reading public. If there is any divergence between the German original and the English translation, the German version shall be the prevailing one.