Data Protection Declaration of CORESTATE Capital Foundation gGmbH

At this point we would like to inform you about the processing of your personal data in connection with your visit to the website „https://foundation.corestate-capital.com/“ (the „Website“). The protection of privacy and your personal data is an important concern for us.

1. RESPONSIBLE BODY
The person responsible within the meaning of the General Data Protection Regulation („GDPR“) with regard to the processing of personal data in connection with the website is:

CORESTATE Capital Foundation gGmbH
Friedrich-Ebert-Anlage 35-37 / Tower 185
D-60327 Frankfurt am Main
Phone: +49 69 3535 6300
Fax: +49 69 3535 630 29
E-Mail: ESG@corestate-capital.com

2. PROCESSING OF YOUR DATA
(I) PROCESSING OF DATA FOR PURELY INFORMATIONAL USE OF THE WEBSITE
If you are merely using the website for information purposes, i.e. if you do not actively transmit information to us, we do not collect any personal data (subject to the further information in this data protection declaration, in particular with regard to cookies (clause 2. (III)), with the exception of the data that your browser automatically transmits and which may allow identification. This includes information about your visit to the website, which includes in particular the following data:

• IP address of the requesting computer
• Date and time of access
• Amount of data transmitted in each case
• Browser type and browser version
• Operating system used
• Referrer URL
• Host name of the accessing computer
• URLs that are accessed via the website
• Visited page on our website
• Message whether the access to the website was successful

The aforementioned processing of personal data is basically carried out for the purpose of enabling the use of the website (connection establishment) or to improve the attractiveness and usability of the website and, if necessary, to detect technical problems and faults on the website at an early stage.

A storage of individual data (information concerning the browser; see above) is carried out in individual cases for a maximum period of four weeks. Insofar as the processing of the above-mentioned data involves personal data, the corresponding processing of these data is based on Art. 6 para. 1 sentence 1 lit. f GDPR (legitimate interest; the legitimate interest follows from the above-mentioned purposes).

(II) DONATION
If you make a donation via the website, the personal data you provide in this connection (name, account details, donation amount) will be processed in order to transfer the donation. We store your aforementioned data for the fulfilment of the legal storage and documentation obligations, which result, among others, from the German Commercial Code (HGB) or the German Fiscal Code (AO), for a time period between two and ten years.

The legal basis for the processing of the aforementioned personal data is Art. 6 para. 1 sentence 1 lit. b GDPR (fulfilment of contract or pre-contractual measures) or, with regard to storage for the fulfilment of our legal storage and documentation obligations, Art. 6 para. 1 sentence 1 lit. c GDPR (legal obligation).

To process donations via the website, we make use of a processor, CORESTATE Capital Group GmbH, which transfers the data to our bank for the purpose of collecting the donation amount.

(III) COOKIES
The website partly uses so-called cookies. Cookies are small text files that are stored on your computer and saved by your browser.

We use so-called session cookies to recognize that you have already visited individual pages of our website. Session cookies are only stored for the duration of access to the website and are automatically deleted when the browser is closed or the website is left. These cookies do not contain any personal data, but merely identify the browser used to access the website. They serve to make the offer on the website more user-friendly, more effective and safer, or to facilitate your navigation through the website.

We also use so-called temporary cookies. These enable specific information related to the device to be stored on the user’s access device (PC, smartphone or similar), even beyond a session. They are used, for example, to keep page settings available for future visits to the website. These cookies remain stored on your end device for a maximum period of four weeks (usually for a shorter period). These cookies enable us to recognize your browser on your next visit.

The aforementioned cookies are used to carry out the electronic communication process, to ensure the integrity and security of the website, to measure the range and for statistical analyses and to optimise the services offered on the website. The legal basis for the corresponding processing of personal data is Art. 6 para. 1 sentence 1 lit. f GDPR (legitimate interest; the legitimate interest follows from the aforementioned purposes).

As a rule, you can configure your browser so that no cookies are stored or a message always appears before a new cookie is created. However, deactivating cookies may mean that you cannot (fully) use all the functions of our website.

Insofar as other cookies or cookie-like tools (e.g. tools for analysing your surfing behaviour) are used on or in connection with the website, these are dealt with separately in this data protection declaration (see in particular below under point 3(V)).

(IV) IT THEMES SECURITY
This website uses the tool „iThemes Security“. In particular, the IP addresses of visitors to the website are processed to detect malicious activities and to protect the website from certain types of attacks. The IP addresses are only stored anonymously in a local database of our contract processor, CORESTATE Capital Group GmbH, for a period of four weeks and are not transmitted to third parties. The legal basis for the corresponding processing of personal data is Art. 6 para. 1 sentence 1 letter f GDPR (legitimate interest; the legitimate interest is that we must protect the website against corresponding attacks by third parties).

(V) GOOGLE TOOLS
GOOGLE ANALYTICS

The website uses – (with regard to your visit to the website) if you give your consent when (first) visiting the website – Google Analytics, a web analysis service of Google Inc. 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA („Google“) Google Analytics uses so-called „cookies“, text files which are stored on your computer and which enable an analysis of your use of the website. The information generated by the cookie about your use of the website is usually transferred to a Google server in the USA and stored there. However, due to the activation of IP anonymisation on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before. Only in exceptional cases is the full IP address transferred to a Google server in the USA and shortened there. On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide us with further services related to website and internet usage. The IP address transmitted by your browser within the framework of Google Analytics is not merged with other data from Google.

You can prevent the storage of cookies (after consent has been given) by adjusting your browser software accordingly. However, we would like to point out that in this case you may not be able to use all functions of the website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

Further information about Google Analytics can be found here:
http://www.google.com/analytics/terms/de.html http://www.google.de/intl/de/policies/privacy/
und at Google Inc., 1600 Amphitheater Parkway, Mountainview, California 94043, USA.

GOOGLE ADS
We use the Google Ads service from Google to draw attention to the charitable projects that we support with the help of advertising material (so-called Google Ads) on external websites. In relation to the data of the advertising campaigns, we can determine how successful the individual advertising measures are. With this, we pursue the interest to show you advertising that is of interest to you, to make our website more interesting for you and to achieve a fair calculation of advertising costs.

These advertising media are delivered by Google via so-called „Ad Servers“. For this purpose, we use Ad Server cookies, which allow us to measure certain parameters to measure success, such as the display of ads or clicks by users. If you reach our website via a Google Ad, Google Ads will store a cookie on your PC. These cookies usually expire after 30 days and are not used to identify you personally. For this cookie, the unique cookie ID, number of Ad impressions per placement (frequency), last impression (relevant for post-view conversions) and opt-out information (marking that the user no longer wishes to be addressed) are usually stored as analysis values.

These cookies enable Google to recognize your internet browser. If a user visits certain pages of an Ad-client’s website and the cookie stored on their computer has not expired, Google and the client may recognize that the user clicked on the Ad and was redirected to that page. A different cookie is assigned to each ad customer. Cookies can therefore not be tracked on the websites of Ads customers. We ourselves do not collect and process any personal data in the advertising measures mentioned. We only receive statistical evaluations from Google. Based on these evaluations, we can identify which of the advertising measures used are particularly effective. We do not receive any further data from the use of the advertising material, in particular we cannot identify the users on the basis of this information.

Due to the marketing tools used, your browser automatically establishes a direct connection with the Google server. We have no influence on the scope and further use of the data collected by Google through the use of this tool and therefore inform you according to our state of knowledge: Through the integration of Ads, Google receives the information that you have called up the corresponding part of our website or clicked on an Ad from us. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or have not logged in, there is a possibility that the provider will find out and save your IP address.

You can prevent participation in this procedure in various ways: a) by adjusting your browser software accordingly, in particular by suppressing third-party cookies, so that you do not receive any third-party ads; b) by deactivating the interest-based Ads of the providers that are part of the self-regulation campaign „About Ads“ via the link http://www.aboutads.info/choices, whereby this setting is deleted when you delete your cookies; c) by permanently deactivating it in your Firefox, Internet Explorer or Google Chrome browsers via the link http://www.google.com/settings/ads/plugin. We point out that in this case you may not be able to use all functions of this offer to their full extent.

GOOGLE WEB FONTS
This page uses so-called web fonts, which are provided by Google, for the uniform display of fonts. The Google web fonts are installed locally on our server (in this respect, data processing may take place as described above under point 3(I); see also the information on the relevant legal basis there). A connection to Google servers does not take place.

INTEGRATION OF YOUTUBE VIDEOS
On this website we may include YouTube videos from the online video platform „YouTube“ of the operator YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA, which are stored on servers of YouTube and can be played directly from our website (YouTube, LLC is a subsidiary of Google).

The videos are integrated in the so-called extended data protection mode, which means that personal data about you as a user is only transferred to YouTube when you play the videos. We have no influence on this data transmission. This data transfer takes place regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google at the same time, your data will be assigned directly to your account. If you do not wish to be associated with your profile on YouTube, you must log out before playing the video (or refrain from consenting to the corresponding data processing when you access the website (for the first time); see below). YouTube stores your data as user profiles and uses them for purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have a right of objection to the creation of these user profiles, and you must contact YouTube to exercise this right.

However, the data processing described above will only be carried out if you give us permission to do so when you visit the website (for the first time) (if you do not give such permission, YouTube content will not be available on the website or will only be accessible to a limited extent).

Further information on the purpose and scope of data collection and its processing by YouTube can be found in the privacy policy regarding YouTube. There you will also find further information on your rights and setting options to protect your privacy: https://www.google.de/intl/de/policies/privacy.

FURTHER INFORMATION ON THE TOOLS MENTIONED IN POINT 3 (V)
The legal basis for the above-mentioned processing of your personal data by us in connection with Google Analytics, YouTube and Google Maps is Art. 6 para. 1 sentence 1 lit. a GDPR (consent; you can revoke the corresponding consent at any time without giving reasons with effect for the future).

The legal basis for the aforementioned processing of your personal data by us in connection with Google Ads is Art. 6 para. 1 sentence 1 lit. f GDPR (legitimate interests). The legitimate interest here is that we have a legitimate economic interest in understanding whether, and how (often), the website is used or how we can successfully place advertising. On the other hand, the interests of the website users are not or only to a very limited extent affected in this context (since the data processed in this context make it difficult to classify them and no particularly critical data or special categories of personal data are processed). Against this background, our legitimate interests outweigh the interests of the user.

In connection with the aforementioned tools, personal data may be processed in the USA (see above). Google is committed to complying with the EU-US Privacy Shield Agreement published by the U.S. Department of Commerce regarding the collection, use and retention of personal data from EU member states. Google has declared through certification that it complies with the relevant privacy shield principles. The EU Commission assumes that the United States provides adequate legal protection for personal data transferred from the EU to self-certified organisations in the USA under the Privacy Shield. Further information can be found at: https://www.privacyshield.gov/EU-US-Framework

4. TRANSFER OF DATA TO THIRD PARTIES
We may use technical service providers (IT service providers) who process personal data on our behalf. These service providers process the corresponding personal data exclusively according to our instructions (order processors).

We may pass on your personal data to third parties if we are legally obliged to do so (e.g. at the request of a court or a criminal prosecution authority). The legal basis for such data processing is Art. 6 para. 1 sentence 1 letter c GDPR (legal obligation).

In addition, personal data collected in the course of using the website will not be passed on or otherwise transferred to third parties without your consent, except in other cases expressly described in this privacy policy.

5. DURATION OF THE STORAGE OF YOUR PERSONAL DATA
Insofar as no other storage period is specified in the other provisions of this data protection declaration, we store the personal data which we obtain from you in connection with the use of the website only for as long as is necessary to achieve the purpose for which it was collected; in the case of the provision of the website, this is the case when the respective session is ended. In addition, we store the data only to the extent and insofar as we are obliged to do so on the basis of mandatory statutory storage obligations; the legal basis for this storage is Art. 6 para. sentence 1 lit. c GDPR (legal obligation). If we no longer need your data for the purposes described above, they will only be stored during the respective legal retention period and will not be processed for other purposes.

6. RIGHTS OF DATA SUBJECTS
You have the right to request information from us at any time about the personal data we have stored about you (Art. 15 GDPR). Insofar as the legal requirements are met, you also have the right vis-à-vis us to correct (Art. 16 GDPR), delete (Art. 17 GDPR) or restrict the processing of the corresponding personal data (Art. 18 GDPR) and the right to data transferability (you may transmit this data or have it transmitted to other bodies) (Art. 20 GDPR). If we process your data for legitimate interests, you have the right to object to the processing of your data for reasons arising from your particular situation at any time on the basis of legitimate interests in accordance with Article 21 GDPR.

If you have given your consent to the use of personal data, you can revoke this consent at any time without giving reasons for the future; however, the legality of the processing carried out on the basis of the consent until revocation remains unaffected.

You can send us your revocation informally at any time (see clause 1). You can also contact us for the assertion of your other, aforementioned rights via the contact details given in clause 1.

If you believe that the processing of personal data concerning you by us is in breach of the applicable data protection law, you can complain to a supervisory authority for data protection (Art. 77 GDPR).

7. SECURITY OF YOUR DATA
The data you provide us with will be protected by suitable technical and organizational means to protect it from accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security measures are continuously monitored and improved in accordance with technological development and organisational possibilities.