Cividata – Non-Profit Organizations Worldwide

Cividata is a volunteer project to display data about non-profit organizations from Wikidata.

The website is self-programmed and I try to collect as little data as possible. However, since I want to know how the website is being used, I use a self-hosted version of Matomo without cookies for analysis. But read for yourself:

Privacy Policy

This privacy policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter referred to as "data") within my online offering and the associated websites, functions and content, as well as my social media profiles (hereinafter collectively referred to as "online offering"). Regarding the terms used, such as "processing" or "controller", I refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Controller

Jona Hölderle
Wolterstraße 18
15366 Neuenhagen bei Berlin
Germany

Types of Data Processed:

  • Usage data (e.g., visited websites, interest in content, access times).
  • Meta/communication data (e.g., device information, IP addresses).

Categories of Data Subjects

Visitors and users of the online offering (hereinafter I also refer to the data subjects collectively as "users").

Purpose of Processing

  • Provision of the online offering, its functions and content.
  • Handling contact requests and communication with users.
  • Security measures.
  • Reach measurement/Marketing

Terms Used

"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

"Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and encompasses practically any handling of data.

"Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Relevant Legal Bases

In accordance with Article 13 GDPR, I inform you about the legal bases of data processing. Unless the legal basis is mentioned in the privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 GDPR, the legal basis for processing to fulfill my services and implement contractual measures and respond to inquiries is Article 6(1)(b) GDPR, the legal basis for processing to fulfill my legal obligations is Article 6(1)(c) GDPR, and the legal basis for processing to protect my legitimate interests is Article 6(1)(f) GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) GDPR serves as the legal basis.

Collaboration with Processors and Third Parties

If, in the context of my processing, I disclose data to other persons and companies (processors or third parties), transmit it to them, or otherwise grant them access to the data, this will only be done on the basis of legal permission (e.g., if transmission of the data to third parties, such as payment service providers, is necessary for contract fulfillment pursuant to Article 6(1)(b) GDPR), if you have consented, if a legal obligation provides for this, or on the basis of my legitimate interests (e.g., when using agents, web hosts, etc.).

If I commission third parties to process data on the basis of a so-called "data processing agreement", this is done on the basis of Article 28 GDPR.

Rights of Data Subjects

You have the right to request confirmation as to whether relevant data is being processed and to receive information about this data as well as further information and a copy of the data in accordance with Article 15 GDPR.

You have the right, in accordance with Article 16 GDPR, to request the completion of data concerning you or the correction of incorrect data concerning you.

In accordance with Article 17 GDPR, you have the right to demand that relevant data be deleted immediately, or alternatively, in accordance with Article 18 GDPR, to demand restriction of the processing of the data.

You have the right to receive the data concerning you that you have provided to me in accordance with Article 20 GDPR and to request their transmission to other controllers.

Furthermore, pursuant to Article 77 GDPR, you have the right to file a complaint with the competent supervisory authority.

Right of Withdrawal

You have the right to withdraw granted consents pursuant to Article 7(3) GDPR with effect for the future.

Right to Object

You may object to the future processing of data concerning you in accordance with Article 21 GDPR at any time. The objection may be made in particular against processing for direct marketing purposes.

Deletion of Data

The data processed by me will be deleted or its processing restricted in accordance with Articles 17 and 18 GDPR. Unless expressly stated in this privacy policy, the data stored by me will be deleted as soon as it is no longer required for its intended purpose and the deletion does not conflict with any statutory retention obligations. If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax reasons.

According to legal requirements in Germany, storage is carried out in particular for 6 years pursuant to § 257(1) HGB (commercial books, inventories, opening balances, annual accounts, commercial letters, accounting documents, etc.) and for 10 years pursuant to § 147(1) AO (books, records, management reports, accounting documents, commercial and business letters, documents relevant for taxation, etc.).

According to legal requirements in Austria, storage is carried out in particular for 7 years pursuant to § 132(1) BAO (accounting documents, receipts/invoices, accounts, vouchers, business papers, statement of income and expenditure, etc.), for 22 years in connection with real estate and for 10 years for documents in connection with electronically supplied services, telecommunications, broadcasting and television services provided to non-entrepreneurs in EU Member States for which the Mini-One-Stop-Shop (MOSS) is used.

Hosting

The hosting services I use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, security services, and technical maintenance services that I use for the purpose of operating this online offering.

In doing so, I or my hosting provider Variomedia GmbH process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, interested parties, and visitors to this online offering on the basis of my legitimate interests in an efficient and secure provision of this online offering pursuant to Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (conclusion of data processing agreement).

Collection of Access Data and Log Files

Our hosting provider collects data about every access to the server on which this service is located (so-called server log files) on the basis of my legitimate interests within the meaning of Art. 6(1)(f) GDPR. Access data includes the name of the accessed website, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address, and the requesting provider.

Log file information is stored for security reasons (e.g., to investigate abuse or fraud) for a maximum of 7 days and then deleted. Backups are deleted after 14 days. Data whose further retention is necessary for evidential purposes is exempt from deletion until the respective incident has been finally clarified.

Contact

When contacting me (e.g., via contact form, email, telephone, or social media), the user's information is processed for handling the contact request and its processing pursuant to Art. 6(1)(b) GDPR. The user's information may be stored in an address book.

I delete the requests once they are no longer necessary. I review the necessity every two years; Furthermore, the statutory archiving obligations apply.

Reach Measurement with Matomo

As part of Matomo's reach analysis, the following data is processed on the basis of my legitimate interests (i.e., interest in the analysis, optimization, and economic operation of my online offering within the meaning of Art. 6(1)(f) GDPR): the browser type and version you use, the operating system you use, your country of origin, date and time of the server request, number of visits, your length of stay on the website, and the external links you click. The IP address of users is anonymized before it is saved.

Matomo does not use cookies for analysis in the version we use.

Users can object to the anonymized data collection by the Matomo program at any time with effect for the future by clicking on the link below. In this case, a so-called opt-out cookie will be stored in their browser, which results in Matomo no longer collecting any session data. However, if users delete their cookies, this will result in the opt-out cookie also being deleted and therefore needing to be reactivated by users.

Online Presence in Social Media

We maintain online presences within social networks and platforms in order to communicate with customers, interested parties, and users active there and to inform them about my services. When calling up the respective networks and platforms, the terms of business and the data processing guidelines of their respective operators apply.

Unless otherwise stated in my privacy policy, I process users' data if they communicate with me within the social networks and platforms, e.g., write posts on my online presences or send me messages.