Responsible for Content:
Prof. Dr. Laura Bechthold
Bavarian Foresight Institute
Technische Hochschule Ingolstadt
Esplanade 10, 85049 Ingolstadt
E-Mail: info@sciencefictionthinking.com
Privacy Policy
Privacy Policy
We are very pleased about your interest in our initiative. Data protection is of particularly high priority to us. Using the “Science Fiction Thinking” website is generally possible without providing any personal data. However, if a data subject wishes to use special services via our website, processing of personal data may become necessary. If processing is required and there is no statutory basis for it, we generally obtain the consent of the data subject.
The processing of personal data, such as the name, address, email address, or telephone number of a data subject, is always carried out in accordance with the General Data Protection Regulation (GDPR) and country-specific data protection regulations. Through this privacy policy, we wish to inform the public about the nature, scope, and purpose of the personal data we collect, use, and process, and inform data subjects of their statutory rights.
As the controller for this website, we have implemented numerous technical and organizational measures to ensure the most complete protection possible for personal data processed through this site. However, internet-based data transmissions can fundamentally have security vulnerabilities, meaning absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us via alternative means, such as by telephone.
1. Definitions
This privacy policy is based on the terms used by the European legislator when adopting the General Data Protection Regulation (GDPR). Our privacy policy should be easily readable and understandable for both the public and our users. To ensure this, we explain the terminology used below:
- A) Personal Data: Any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- B) Data Subject: Any identified or identifiable natural person whose personal data is processed by the controller.
- C) Processing: Any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- D) Restriction of Processing: The marking of stored personal data with the aim of limiting its processing in the future.
- E) Profiling: Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
- F) Pseudonymization: The processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
- G) Controller: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
- H) Processor: A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
- I) Recipient: A natural or legal person, public authority, agency, or another body to which the personal data are disclosed, whether a third party or not. Public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
- J) Third Party: A natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
- K) Consent: Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
2. Name and Address of the Controller
The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in Member States of the European Union, and other provisions of a data protection nature are the individuals named above.
3. Cookies
The “Science Fiction Thinking” website uses cookies. Cookies are text files that are stored on a computer system via an internet browser.
Many websites and servers use cookies, and many cookies contain a unique identifier known as a cookie ID. This allows visited websites and servers to distinguish the individual browser of the data subject from other internet browsers that contain other cookies. Through the use of cookies, “Science Fiction Thinking” can provide users of this website with more user-friendly services that would not be possible without the cookie setting.
By means of a cookie, the information and offers on our website can be optimized with the user in mind. Cookies enable us to recognize users of our website so they do not have to re-enter access data each time they visit.
The data subject can prevent the setting of cookies by our website at any time by means of a corresponding setting in the browser used, thus permanently objecting to cookie deployment. Furthermore, cookies already set can be deleted at any time via an internet browser or other software programs. If the data subject deactivates the setting of cookies, not all functions of our website may be entirely usable.
4. Collection of General Data and Information
The “Science Fiction Thinking” website collects a series of general data and information when a data subject or automated system accesses the website. This information is stored in the server log files. The data collected may include:
- The browser types and versions used
- The operating system used by the accessing system
- The website from which an accessing system reaches our website (so-called referrers)
- The sub-websites accessed via an accessing system on our website
- The date and time of an access to the website
- An Internet Protocol address (IP address)
- The Internet service provider of the accessing system
- Other similar data and information used for security in the event of attacks on our information technology systems
When using this general data and information, we draw no conclusions about the data subject. Rather, this information is required to deliver the content of our website correctly, optimize website content and advertising, ensure the permanent functionality of our systems, and provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyberattack. These anonymously collected data and information are evaluated statistically with the aim of increasing data protection and data security within our organization. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.
5. Registration on Our Website
The data subject has the possibility to register on the website of the controller by providing personal data. Which personal data is transmitted is determined by the input mask used for registration. The personal data entered is collected and stored exclusively for internal use by the controller and for their own purposes. The controller may arrange for transfer to one or more processors, such as a parcel service, who also use the personal data solely for internal use attributable to the controller.
Upon registration, the IP address assigned by the data subject’s Internet service provider (ISP), along with the date and time of registration, are also stored. This storage takes place to prevent misuse of our services and, if necessary, to enable the investigation of criminal offenses committed. A transfer of this data to third parties does not take place unless there is a statutory obligation to do so or the transfer serves the purpose of criminal prosecution.
Registration of the data subject, with the voluntary provision of personal data, enables the controller to offer content or services that can only be offered to registered users due to the nature of the matter. Registered persons are free to modify the personal data provided during registration at any time or have it completely deleted from the database of the controller.
The controller shall provide each data subject at any time upon request with information about what personal data is stored concerning them, and correct or delete such data upon request, provided there are no statutory storage obligations to the contrary. All employees of the controller are available to the data subject in this regard as contact persons.
6. Contact Possibility via the Website
Due to legal requirements, the “Science Fiction Thinking” website contains information that enables quick electronic contact with us and direct communication, including a general email address. If a data subject contacts the controller via email or a contact form, the personal data transmitted by the data subject is automatically stored. Such personal data transmitted on a voluntary basis is stored for the purpose of processing the inquiry or contacting the data subject. There is no transfer of this personal data to third parties.
7. Routine Erasure and Blocking of Personal Data
The controller processes and stores personal data of the data subject only for the period necessary to achieve the purpose of storage, or as provided for by European directives and regulations or other relevant legal provisions. If the storage purpose ceases to apply or an applicable statutory retention period expires, the personal data is routinely blocked or erased in accordance with legal provisions.
8. Rights of the Data Subject
- A) Right of Confirmation: Every data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning them is being processed.
- B) Right of Access: Every data subject has the right to obtain free information about their stored personal data and a copy of this information at any time. This includes information regarding the purposes of processing, categories of data, recipients or categories of recipients, planned retention periods, the existence of rights to rectification, erasure, restriction, or objection, the right to lodge a complaint with a supervisory authority, the source of data if not collected directly, and the existence of automated decision-making, including profiling pursuant to Art. 22(1) and (4) GDPR. Furthermore, data subjects have the right to know if personal data has been transferred to a third country or international organization and the appropriate safeguards in place.
- C) Right to Rectification: Every data subject has the right to demand the immediate rectification of inaccurate personal data concerning them, including the completion of incomplete personal data.
- D) Right to Erasure (Right to Be Forgotten): The data subject has the right to obtain the erasure of personal data concerning them without undue delay where one of the grounds specified in Art. 17(1) GDPR applies (e.g., data is no longer necessary, consent is withdrawn, valid objection is raised, or data was processed unlawfully) and processing is not necessary. Where “Science Fiction Thinking” has made personal data public and is obliged to erase it, reasonable steps will be taken to inform other controllers processing the data of the request.
- E) Right to Restriction of Processing: Every data subject has the right to obtain restriction of processing where the accuracy of the data is contested, the processing is unlawful but erasure is opposed, the controller no longer needs the data but the subject requires it for legal claims, or an objection under Art. 21(1) GDPR is pending verification.
- F) Right to Data Portability: Every data subject has the right to receive personal data concerning them in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance, provided the processing is based on consent or contract and is carried out by automated means.
- G) Right to Object: Every data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them based on Art. 6(1)(e) or (f) GDPR, including profiling. In the case of an objection, the controller will no longer process the personal data unless compelling legitimate grounds can be demonstrated. Where personal data is processed for direct marketing, the data subject has the right to object at any time.
- H) Automated Individual Decision-Making, Including Profiling: Every data subject has the right not to be subject to a decision based solely on automated processing—including profiling—which produces legal effects concerning them or similarly significantly affects them, subject to statutory exceptions.
- I) Right to Withdraw Data Protection Consent: Every data subject has the right to withdraw their consent to the processing of their personal data at any time.
9. Data Protection Provisions Regarding the Application and Use of Facebook
The controller has integrated components of the enterprise Facebook on this website. Facebook is an online social network. The operating company of Facebook is Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. For individuals living outside the USA or Canada, the controller is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Each time one of the individual pages of this website equipped with a Facebook component (plug-in) is accessed, the internet browser is automatically prompted to download a display of the corresponding component from Facebook. An overview of Facebook plug-ins can be accessed at https://developers.facebook.com/docs/plugins/?locale=de_DE. Through this process, Facebook gains knowledge of which specific subpage was visited.
If the data subject is logged in to Facebook at the same time, Facebook detects this with every visit and associates the interaction with the personal Facebook account of the data subject. If the data subject clicks on an integrated Facebook button, such as the “Like” button, or submits a comment, Facebook assigns this information to the personal account. To prevent this transmission, the data subject must log out of Facebook before visiting our website. The data policy published by Facebook is available at https://de-de.facebook.com/about/privacy/.
10. Data Protection Provisions Regarding the Application and Use of Google Analytics (with Anonymization Function)
The controller has integrated the component Google Analytics (with anonymization function) on this website. The operating company is Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland.
We use the extension “_gat._anonymizeIp” for web analysis via Google Analytics, which truncates and anonymizes the IP address of the data subject’s internet connection within Member States of the European Union or other contracting states to the Agreement on the European Economic Area. Google uses this information on our behalf to evaluate the use of the website, compile reports on website activity, and provide other services related to website and internet use.
Google Analytics places a cookie on the information technology system of the data subject. The data subject can prevent the setting of cookies via their browser settings and can object to the collection of data generated by Google Analytics by downloading and installing a browser add-on available at https://tools.google.com/dlpage/gaoptout. Further information and Google’s applicable privacy policy can be retrieved under https://www.google.de/intl/de/policies/privacy/ and under http://www.google.com/analytics/terms/de.html.
11. Data Protection Provisions Regarding the Application and Use of Jetpack for WordPress
The controller has integrated Jetpack on this website. Jetpack is a WordPress plug-in providing additional administrative, traffic, and security features. The operating company is Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA / Aut O’Mattic A8C Ireland Ltd., Business Centre, No.1 Lower Mayor Street, International Financial Services Centre, Dublin 1, Ireland.
Jetpack sets a cookie to analyze user behavior. The data collected is also accessed by Quantcast, which uses it for the same purposes. The data subject can prevent the setting of cookies through browser settings or opt out of data processing by Quantcast using the opt-out button at https://www.quantcast.com/opt-out/. Further privacy information is available at https://automattic.com/privacy/ and https://www.quantcast.com/privacy/.
12. Data Protection Provisions Regarding the Application and Use of LinkedIn
The controller has integrated components of the LinkedIn Corporation on this website. The operating company is LinkedIn Corporation, 2029 Stierlin Court Mountain View, CA 94043, USA (for privacy matters outside the USA: LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland).
When accessing a page that contains a LinkedIn plug-in, the browser downloads the component from LinkedIn, allowing LinkedIn to track which specific page is visited. If the user is logged into LinkedIn, this data is assigned to their account. Users can opt out of targeted ads, messages, and cookie tracking via https://www.linkedin.com/psettings/guest-controls. Privacy policies are available at https://www.linkedin.com/legal/privacy-policy and https://www.linkedin.com/legal/cookie-policy.
13. Data Protection Provisions Regarding the Application and Use of Xing
The controller has integrated components of Xing on this website. The operating company is New Work SE (formerly XING SE), Dammtorstraße 30, 20354 Hamburg, Germany.
Through each visit to a subpage containing a Xing plug-in, the browser downloads the respective component from Xing. If the user is logged into Xing at the same time, Xing tracks which pages are being viewed and assigns this to the user’s account. Logging out of Xing prevents this direct data association. Xing’s data privacy notice is available at https://www.xing.com/privacy.
14. Legal Basis for the Processing
Art. 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. If processing is necessary for the performance of a contract (e.g., delivery of goods or services), it is based on Art. 6(1)(b) GDPR, which also applies to pre-contractual measures. Where processing is required to fulfill a legal obligation (such as tax compliance), it is based on Art. 6(1)(c) GDPR. In rare cases, processing may be based on Art. 6(1)(d) GDPR to protect vital interests. Finally, processing operations not covered by the above can be based on Art. 6(1)(f) GDPR if necessary for the legitimate interests of our organization or a third party, except where overridden by the interests or fundamental rights and freedoms of the data subject (Recital 47 GDPR).
15. Legitimate Interests in Processing Pursued by the Controller or a Third Party
Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is the carrying out of our business activities for the benefit of all our employees and shareholders.
16. Period for Which Personal Data Will Be Stored
The criterion for determining the duration of storage is the respective statutory retention period. After the expiration of that period, the corresponding data is routinely erased, provided it is no longer required for the fulfillment or initiation of a contract.
17. Statutory or Contractual Requirements to Provide Personal Data
We clarify that the provision of personal data is partly required by law (e.g., tax regulations) or can result from contractual arrangements (e.g., information on the contractual partner). Failure to provide personal data may mean that a contract cannot be concluded with the data subject. Before providing personal data, the data subject may contact an employee to clarify on a case-by-case basis whether provision is mandatory and what consequences non-provision would entail.
18. Existence of Automated Decision-Making
We do not use automatic decision-making or profiling.
This privacy policy was generated by the Privacy Policy Generator of DGD Deutsche Gesellschaft für Datenschutz GmbH in cooperation with the privacy lawyers of the law firm WILDE BEUGER SOLMECKE | Rechtsanwälte.