Data protection information

We are pleased that you are visiting our website and thank you for your interest in the Rathaus Galerie Essen and the corresponding offers.

In the following, we provide information about the collection of personal data when using our website. Personal data is all data that can be related to you personally, e.g. name, address, e-mail addresses, user behavior.

Person responsible for data processing

Responsible acc. Art. 4 para. 7 of the General Data Protection Regulation (GDPR) is HBB Centermanagement GmbH & Co. KG, see our legal notice.

Contracted service providers:

The general provision and maintenance of our website and e-mail systems is carried out with the support of IT service providers who work on our behalf and can therefore also view (receive) your data to the extent necessary.

Data Protection Officer:

Althammer & Kill GmbH &Co. KG
Roscherstrasse 7, 30161 Hanover
Phone: 0511 330603-90
E-mail: kontakt-dsb@althammer-kill.de

Collection and use of your data

The scope and type of collection and use of your personal data differs depending on whether you visit our website only to retrieve information or to make use of any services offered by us.

If we use other (IT) service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail below about the respective processes (all data processing). We also state the specified criteria for the storage period and the applicable legal basis for data processing.

Informational use

For the informational use of our website, we only collect the personal data that your browser automatically transmits to us, such as:

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • the amount of data transferred and the access status (file transferred, file not found, etc.)
  • Website from which the request comes
  • Browser type / version / language
  • Operating system and its interface
  • Language and version of your browser.

Storage duration:

The storage period for this data (logs) is 7 days.

Legal basis for data processing:

The above-mentioned data is technically necessary to display our website to you and to ensure stability and security, in accordance with. Art. 6 para. 1 lit. f) GDPR.

Contact us

When you contact us via the contact form or by e-mail, the data you provide (your name, your e-mail address and your message) will be stored by us in order to answer your question(s).

Storage duration:

We delete the data arising in this context after storage is no longer required, or restrict processing if there are statutory retention obligations (max. ten years in the context of the archiving of business e-mail traffic required under commercial and tax law).

Legal basis for data processing:

Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract, in accordance with Art. 6 para. 1 lit. a GDPR. Art. 6 para. 1 lit. b) GDPR.

Applications

We advertise job vacancies on our website on behalf of the Center’s stores. However, we are not entrusted with the application process. All stores have their own application procedures and are therefore responsible for implementing the data protection regulations themselves. If you have any questions about individual applications, please contact the store directly.

Newsletter

In order to receive our newsletter regularly, in addition to your consent under data protection law, we require at least your e-mail address (mandatory information) to which the newsletter is to be sent.

In addition, we store the IP addresses you use and the times of registration and confirmation of the newsletter. The background to this is the required proof of your consent and, if necessary, the clarification of a misuse of your personal data (e.g. a third party uses your e-mail address for registration without authorization).

We use the so-called double opt-in procedure for registration, i.e. we will only send you the newsletter if you first confirm your registration via a confirmation e-mail sent to you for this purpose by means of a link contained therein. This is to ensure that only you, as the owner of the e-mail address provided, can subscribe to the newsletter.

Withdrawal of your consent:

You can unsubscribe from our newsletter at any time by clicking on the corresponding link at the end of the newsletter or by sending a message to the contact details given in the legal notice.

Newsletter performance measurement:

We would like to point out that we evaluate your user behavior when sending the newsletter. For this evaluation, the e-mails sent contain so-called web beacons or tracking pixels, which are single-pixel image files and are stored on our websites.

The data is collected exclusively in pseudonymized form, i.e. the IDs are not linked to your other personal data, and direct personal references are excluded.

Revocation of the performance measurement:

If you do not want us to analyze your data, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. You can also unsubscribe from the newsletter directly on the website.

Such tracking is also not possible if you have deactivated the display of images in your e-mail program by default. In this case, the newsletter will not be displayed in full and you may not be able to use all functions. If you display the images manually, the above-mentioned performance measurement is carried out.

Contracted service providers:

We use Brevo to send newsletters. Brevo is a service that can be used to organize and analyze newsletter distribution. The data you enter for the purpose of receiving the newsletter (e.g. e-mail address) will be stored on Brevo’s servers in Germany.

You can find more details in Brevo’s privacy policy at: https://www.brevo.com/de/legal/privacypolicy/

We have concluded a contract with Brevo for commissioned data processing, in which we oblige Brevo to protect our subscribers’ data and not to pass it on to third parties.

Storage duration:

The data you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted from both our servers and Brevo’s servers after you unsubscribe from the newsletter.

Legal basis for data processing:

The subscription to the newsletter is based on your personal consent, in accordance with Art. Art. 6 para. 1 lit. a) GDPR. You can revoke this consent at any time by unsubscribing from the newsletter

The storage of more detailed information regarding the time of your registration and the IP address used is in our interest, in accordance with Art. 6 para. 1 lit. f GDPR. Art. 6 para. 1 lit. f) GDPR.

The evaluation of your pseudonymized user behavior (measurement of the success of our newsletter) is carried out in our interest in making the newsletter generally more interesting and better tailored to our reader group, in accordance with Art. 6 para. 1 lit. a GDPR. Art. 6 para. 1 lit. f) GDPR.

Use of cookies

We use cookies for our website. Cookies are small text files that are sent to your browser by our web server when you visit our website and are stored on your computer for later retrieval. They serve to make the website more user-friendly and effective overall.

Cookies can basically be divided into two categories:

Transient cookies are automatically deleted when you close the browser. These include session cookies in particular. These store a so-called session ID, with which various requests from your browser can be assigned to the shared session. This allows your computer to be recognized when you return to the website. The session cookies are deleted when you log out or close the browser.

Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete the cookies in the security settings of your browser at any time.

Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them. These cookies are stored on the basis of Art. 6 para. 1 lit. f) GDPR, unless another legal basis is specified. We have a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of this website. Other cookies can be used to evaluate user behavior or for advertising purposes. The integration of these cookies takes place exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); the consent can be revoked at any time.

Consent management

When you visit this website for the first time, you will be given the opportunity to configure the cookie and privacy settings in the consent manager according to your wishes and to prohibit the acceptance or setting of certain cookie categories, e.g. third-party cookies. However, we would like to point out that you may then not be able to use all the functions of this website.

We use the technology of Borlabs GmbH, Rübenkamp 32, 22305 Hamburg (hereinafter referred to as Borlabs) to obtain your consent to the storage of certain cookies in your browser or to the use of certain technologies and to document these in accordance with data protection regulations.

When you enter our website, a Borlabs cookie is stored in your browser in which the consents you have given or the revocation of these consents are stored. This data is not passed on to the provider of Borlabs Cookie.

The data collected will be stored until you ask us to delete it or delete the Borlabs cookie yourself or until the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected.

Details on the data processing of Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.

Borlabs cookie consent technology is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.

You can change your privacy configuration at any time at the bottom right of each page.

In addition, we use a so-called two-click solution in certain areas. In this case, a reference to the integrated content, e.g. the YouTube video, is first displayed and only after an additional click on the corresponding button is a cookie set or the data collection and transmission begins.

Web analysis

It is important to us to design our websites as optimally as possible and thus make them attractive for our visitors. To do this, we need to know which parts of it are received by our visitors and how. We use the following technologies for this purpose.

Google Analytics

This website uses functions of the web analysis service Google Analytics.

Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, length of visit, operating systems used and origin of the user. This data may be summarized by Google in a profile that is assigned to the respective user or their end device.

Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to a Google server in the USA and stored there.

We have activated the IP anonymization function on this website. As a result, your IP address will be shortened by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Service is provided by:

Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.

Further information on data protection at Google Ireland Ltd. and Google Inc. (USA). can be found at: https://support.google.com/analytics/answer/6004245?hl=de.

Storage duration:

The stored anonymized usage processes are deleted after 2 months at the latest.

Legal bases:

We only use Google Analytics on the basis of your personal consent, in accordance with Art. Art. 6 para. 1 lit. a) GDPR.

Revocation of the analysis of user behavior:

You have the right to withdraw your consent at any time.

You can change your configuration at any time at the bottom right of each page.

Integrated services

We use the following external services to design our website and provide additional functions.

Google Tag Manager

We use “Google Tag Manager” on our website, a service provided by Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland (hereinafter referred to as “Google”). Google Tag Manager enables us as marketers to manage website tags via a single interface. The Google Tag Manager tool, which implements the tags, is a cookie-free domain and does not itself collect any personal data. Google Tag Manager triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If a deactivation has been made at domain or cookie level, this remains in place for all tracking tags that are implemented with Google Tag Manager.

Further information on data protection can be found on the following Google websites:

Privacy policy: https://policies.google.com/privacy?hl=de&gl=de

FAQ Google Tag Manager: https://www.google.com/intl/de/tagmanager/faq.html

Google Tag Manager Terms of Use: https://www.google.com/intl/de/tagmanager/use-policy.html

 

Service is provided by:

The provider is Google Inc. 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, the representative in the EU is Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.

Further information on data protection at Google Inc. can be found at: https://www.google.com/intl/de/policies/privacy/

Storage duration:

See Storage duration of the logs under Informational use above in this privacy policy.

Legal basis for data processing:

We only use this service on the basis of your personal consent, in accordance with Art. Art. 6 para. 1 lit. a) GDPR.

Revocation:

You have the right to withdraw your consent at any time.

You can change your configuration at any time at the bottom right of each page.

Google Maps

We integrate content from Google Maps on our website to show you our location more easily.

We use a two-click solution to protect your personal data. When you access a page in which Google Maps is embedded, a connection to the Google servers is only established when you click on the corresponding button.

If you are logged in to Google with an existing user account at the same time as visiting our website, Google may also be able to assign your visit to our website to your user behavior. In addition, other cookies may be sent to your browser by Google. We have no influence on this procedure and do not receive any information from Google about the transmitted content.

Analysis of your user behavior by Google:

Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its websites. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website.

You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right.

Service is provided by:

The provider is Google Inc. 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, the representative in the EU is Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.

Further information on data protection at Google Inc. can be found at: https://www.google.com/intl/de/policies/privacy/

Storage duration:

See Storage duration of the logs under Informational use above in this privacy policy.

Legal basis for data processing:

We only use this service on the basis of your personal consent, in accordance with Art. Art. 6 para. 1 lit. a) GDPR.

Revocation:

You have the right to withdraw your consent at any time.

You can change your configuration at any time at the bottom right of each page.

YouTube

We have integrated YouTube videos into our website, which are stored on https://www.youtube.com and can be played directly from our websites.

We use a two-click solution to protect your personal data. When you visit a page in which a YouTube video is embedded, a connection to the YouTube/Google servers is only established when you click on the corresponding button.

If you are also logged in to Google with an existing user account while visiting our website, Google may also be able to assign your visit to our website to your user behavior. In addition, other cookies may be sent to your browser by YouTube (Google). We have no influence on this procedure and do not receive any information from YouTube (Google) about the transmitted content. We would like to point out that, as the provider of our website, we have no knowledge of the content of the transmitted data or its use by YouTube (Google) and also have no possibility of further restricting the transmission of data to YouTube (Google) and its partners. If you do not wish to be associated with your YouTube profile, you must log out before activating the video.

Analysis of your user behavior by YouTube (Google):

YouTube (Google) stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its websites. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website.

You have the right to object to the creation of these user profiles, whereby you must contact YouTube (Google) to exercise this right.

Service is provided by:

The provider is Google Inc. 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, the representative in the EU is Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.

Further information on data protection at YouTube (Google Inc.) can be found at: https://www.google.de/intl/de/policies/privacy

Storage duration:

See Storage duration of the logs under Informational use above in this privacy policy.

Legal basis:

We only use this service on the basis of your personal consent, in accordance with Art. Art. 6 para. 1 lit. a) GDPR.

Revocation of the analysis of user behavior:

You have the right to withdraw your consent at any time.

You can change your configuration at any time at the bottom right of each page.

Social media links

Our website contains links to various social media with the corresponding logos. These are not social media plug-ins, but merely a link to our offers within these media. If you click on one of these links, your IP address will always be transmitted to the operators of the various platforms. If you use one of these services and are also logged in with your specific account, information about your surfing behavior may also be collected by the social media operators. The transmission of your IP address to the operators of the website accessed is technically necessary and applies to all websites.

Your rights

You have the following rights vis-à-vis us with regard to your personal data:

  • Right to information,
  • Right to rectification or erasure,
  • Right to restriction of processing,
  • Right to data portability.

Right to lodge a complaint with a supervisory authority

You also have the right to complain to a data protection supervisory authority about the processing of your personal data by us. The supervisory authority directly responsible for us is

The Hamburg Commissioner for Data Protection and Freedom of Information: https://datenschutz-hamburg.de/pages/impressum/

Right of objection and revocation

If you have given your consent to the processing of your data, you can revoke this at any time. Such a revocation affects the permissibility of the processing of your personal data after you have declared it to us.

Insofar as we base the processing of your personal data on the balancing of interests (legal basis is then Art. 6 para. 1 lit. f) GDPR), you can object to the processing. This is the case if the processing is not required in particular to fulfill a contract with you, which is addressed by us in the explanation of the individual data processing and functions on our website further up in this privacy policy. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either discontinue or adapt the data processing or point out to you our compelling reasons worthy of protection on the basis of which we will continue the processing.

Right to object to direct advertising

Of course, you can object to the processing of your personal data for advertising and data analysis purposes at any time, e.g. even if you receive advertising from us in the form of a newsletter, customer magazine or information material by post as part of a business relationship.

If we use your data in the context of functions of our website for direct advertising and an associated data analysis, we will inform you about this data processing further above in this data protection declaration, incl. the possibility of exercising your right of withdrawal by technical means.

Contact options re. Your rights

You can contact us at any time to exercise your rights. Please use the following e-mail address: impressum@hbb.de

You are also welcome to use one of the contact options in our legal notice or contact our data protection officer directly (contact details above).

Data security

We also use technical and organizational security measures to protect personal data that is generated or collected, in particular against accidental or intentional manipulation, loss, destruction or attack by unauthorized persons. Our security measures are continuously improved in line with technological developments.

The transmission of your personal data is encrypted using SSL technology (https) to prevent access by unauthorized third parties.

Communication by e-mail

Our e-mail systems support encrypted communication using SSL technology. The transmission of your e-mail can therefore always be encrypted. Please note, however, that encryption also depends on the configuration of your e-mail program and that we are therefore unable to guarantee complete data security for the transport route.

For information requiring a high level of confidentiality, we recommend that you send it by post.