Privacy Policy

1. Controller

AWO Perspektiven gGmbH
Kruppstraße 105 60388 Frankfurt am Main
60388 Frankfurt am Main
post@awo-hs.org
Data Protection Officer: post@awo-hs.org

This privacy policy refers to the technical use of the web app. For information on the processing of personal data in the context of support services (e.g., data of children, health data, payment data), please refer to the privacy policy of AWO Perspektiven gGmbH, which is provided during registration.

2. Technical service provider and order processor

We work with the following technical service provider as a processor:

Stefan Landvogt - IT Consulting
Wolfratshauser Str. 137a
81479 München
hilfe@awo-care.org

The technical service provider is responsible for the provision and operation of the web app's technical infrastructure. Data processing is carried out exclusively on behalf and according to the instructions of the controller based on a data processing agreement in accordance with Art. 28 GDPR.

3. Collection and processing of personal data

For the use of the web app, we collect and process the following data:

  • Email addressFor registration, password reset, notifications, and communication within the platform.
  • PasswordStored in encrypted form to protect access to your account.

4. Purpose of data processing

We use the collected data exclusively for the following purposes:

  • Provision of the web appWe use your data to provide you with the functions of the web app, such as creating, editing, and managing orders.
  • CommunicationWe use your contact details to send you important information about the web app, such as updates, security notices, or answers to your inquiries.
  • AuthenticationYour password is used to prevent unauthorized access to your account.
  • AnalysisWe analyze usage data anonymously to continuously improve the functionality of the web app.

5. Legal basis

The processing of your personal data is based on Article 6 paragraph 1 lit. b GDPR (performance of a contract) and Article 6 paragraph 1 lit. f GDPR (legitimate interest). Our legitimate interest lies in providing and improving our services.

6. Data Transfer

We generally do not share your personal data with third parties. Exceptions apply only if:

  • You have given us your explicit consent.
  • Disclosure is necessary to fulfill legal obligations.
  • Disclosure is necessary to enforce our rights.

We use the following third-party providers:

  • CloudflareTo provide the web app and protect against cyberattacks. Cloudflare processes data such as IP addresses and browser information to ensure secure and fast delivery of the web app.
  • FirebaseTo provide various services, including hosting, database, authentication, and Cloud Functions. Firebase, a service from Google, processes data for authentication, storage and hosting of content, as well as for the execution of Cloud Functions.
  • Google reCAPTCHATo protect against automated requests (spam protection). IP address and usage behavior are transmitted to Google.

Your data is primarily stored in the EU. However, due to the technical architecture of Google Firebase, your data may also be temporarily transferred or processed in other regions, including the USA. Google has committed to adhering to EU data protection standards and has implemented appropriate security measures. For more information on the privacy policies of third-party providers, please see here:

7. Duration of Data Storage

We generally only store your personal data for as long as it is necessary for the fulfillment of the purposes mentioned above or as long as statutory retention periods exist. After these periods expire, your data will be deleted.

8. Your Rights

You have the right to:

  • InformationYou can request information about your personal data stored with us at any time.
  • RectificationIf incorrect data is stored, you can request its correction.
  • ErasureUnder certain conditions, you can request the deletion of your data.
  • Restriction of processingYou can request the restriction of the processing of your data.
  • Data PortabilityYou have the right to receive your data in a structured, common, and machine-readable format or to have it transferred to another controller.
  • ObjectionYou can object to the processing of your data if it is based on Article 6 paragraph 1 lit. f GDPR.
  • Complaint to the supervisory authorityYou have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR).

9. Security

We implement technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access.

10. Changes to this Privacy Policy

We reserve the right to amend this privacy policy at any time. We will inform you of any significant changes in a timely manner.

11. Contact for Data Protection Questions

If you have any questions regarding data protection, please contact:
AWO Perspektiven gGmbH
post@awo-hs.org