Data Protection on this Website

The Staatliche Museen zu Berlin – Preussischer Kulturbesitz places great importance on handling your personal data in a responsible manner. To this end, the following information will outline:

  • why the Staatliche Museen zu Berlin collects and stores data
  • what rights users of this website have
  • how the Staatliche Museen zu Berlin collects data and which data it retains
  • which kinds of cookies are used on the website of the Staatliche Museen zu Berlin
  • how you can object to or avoid the collection of your personal data
  • who is responsible for this website and its data privacy policies

1. Why does the Staatliche Museen zu Berlin collect data and utilize user analysis software?

As a general rule, we collect and use personal data related to our users only to the extent that this is necessary for us to ensure the functionality of the website and to deliver our content and services. For example, it is necessary for our system to temporarily save a user’s IP address in order to facilitate a stable and secure delivery of the website to the computer of the user. To this end, it is necessary to save the anonymized IP address of the user for the duration of 60 days. This data is erased as soon as it is no longer necessary

The Staatliche Museen zu Berlin carry out analysis of the ways users interact with this website. This provides us with information to improve our online presence. This includes, for example, knowing how often particular aspects on a website are clicked on, or which browsers are used to view the site. The data that is saved for this is anonymized or pseudo- anonymized, and is used by the Staatliche Museen zu Berlin exclusively for the purposes of statistical analysis. The data is not used for any other purpose, nor is it passed on to third parties. 

2. What rights do users have on our website?

In relation to personal data and our website, you have the following rights, as defined by the EU’s General Data Protection Regulation:

  • the right of access (art. 15 GDPR),
  • the right of notification and erasure (art. 16&17 GDPR),
  • the right to restriction of processing (art. 18 GDPR),
  • the right to object against processing (art. 21 GDPR),
  • the right to data portability (art. 20)

Additionally, you have the right to make a complaint to a data privacy regulating body about the way we have processed your personal data (art. 77 GDPR). For the Staatliche Museen zu Berlin, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) is the relevant body.

3. What data is collected?

a) Website functionality and creation of log files

With every visit to our website, our system automatically collects data and information from the computer system of the computer producing the traffic. The processing of this personal information is regulated by art. 6 para. 1f of the GDPR. The following data is collected:

  • IP addresses
  • Log files
  • Inventory data, traffic data and content data of the website
  • Error protocols

Log files allow website operators to monitor activities on their websites. The access logs of the web server keep a record of when each particular page was visited. This includes the following data: IP address, directory protection users, date, time, pages visited, protocols, status codes, data size, referrer, user agent, host name used.

Our website is stored on a server belonging to the company Mittwald. Mittwald saves data for the following periods of time:

  • The IP addresses are saved in anonymized form. For this, the final three digits are removed, that is, 127.0.0.1 becomes 127.0.0.*. IPv6 addresses are likewise made anonymous. These anonymized IP addresses are saved for 60 days. Information about the directory protection user will be made anonymous after one day. 
  • Error logs that monitor failed site visits are deleted after seven days. Along with the error notice, these include the IP address accessing the site and, depending on the kind of error, the website being accessed.
  • Visits via FTPs are anonymized and saved for 60 days.

The agency xmental also has access to this data in TYPO3 for the purposes of website maintenance and programming.

The Staatliche Museen zu Berlin has carefully selected the agency xmental and the server provider Mittwald. A contract was signed with these service providers to regulate data processing. xmental and Mittwald are obliged to follow the instructions of the Staatliche Museen zu Berlin, and their activities are regularly evaluated.

b) Which cookies does this website use?

Cookies are small text files which are saved on your computer when you visit a website and are accessed by the browser you use. Cookies allow information to be exchanged between computer programmes or to be saved for a limited time. Specific information is transmitted to our site from the saved cookies. However they are unable to operate a programme or transfer viruses to your computer.

Cookies can only be saved if you have authorized this in your browser settings. Therefore, as a user, you also have full control over the use of cookies. By changing your settings in your internet browser, you can deactivate or limit the transmission of cookies. Cookies that have already been saved can be deleted at any time. This can be done automatically.

With every visit to a website, and every time you access a file online, it is typical for browsers to transmit data. The processing of personal data is regulated by art. 6, para. 1f of the GDPR. Of the data that is transmitted when you visit this website, the Staatliche Museen zu Berlin save the following information:

  • Browser type/version
  • Operating system
  • Referrer URL
  • Date and time of the server inquiry
  • Page(s) visited and file(s) accessed
  • Amount of data transmitted
  • Anonymized/pseudo-anonymized IP address
  • Country of origin
  • Notification of whether the attempt at access was successful.

The website of the Staatliche Museen zu Berlin uses cookies very sparingly. This means that you can generally also view the website without cookies. The cookies used on this website have two different functions:

  • Part of the cookies we use (so-called transient cookies) guarantee that the website functions seamlessly. The validity of these cookies is limited to the individual web session. As soon as you shut down your browser, these so-called “session cookies” are deleted.
  • For website analysis, the Staatliche Museen zu Berlin employ the user analysis software Matomo (previously known as Piwik), which is recommended by data privacy advocates. The processing of the personal data of users allows us to analyse the interaction of our users with the site. Through evaluating this data, we are able to piece together information about the use of individual components on our website. This helps us to continually improve our website and make it more user-friendly. Through anonymized IP addresses, the data collected can no longer be  ascribed to particular individuals. This makes it impossible to connect usage data or usage profiles with personal data. The software for this runs exclusively on the servers of our website. It is only there that personal data about users is saved. This data is not forwarded on to third parties. Depending on whether you have consented to or rejected the collection of data, there will either be two website analysis cookies or a Matomo deactivation cookie saved on your computer. These are so-called “persistent cookies”, which are automatically deleted after two years. You can also delete these cookies yourself in your browser security settings at any time.

Refusing authorization of data collection by the website analysis software Matomo

You have the right to decide whether or not you consent to the Staatliche Museen zu Berlin collecting and analysing the statistical data described above.

PLEASE NOTE: If you have activated automatic deletion of cookies in your browser, when you shut down your programme, the deactivation cookie will also be deleted. In this case, the next time you visit this website, you will need to reject the collection of data once again. Additionally, if you use another computer or another web browser, you also need to reject the collection of your data again.

More detailed information on the privacy settings of Matomo software can be found at the following link: https://matomo.org/docs/privacy/.

c) Which data is saved in the event of digital inquiries by email or using a contact form?

For mail inquiries or contact via an online form, you are required to enter specific information so that the Staatliche Museen zu Berlin can contact you or send you the documents you have requested. The processing of your personal data is regulated by art. 6 para. 1a of the GDPR.

Registering for the press mailing list:
Obligatory fields: Surname, first name, street, house number, postcode, city, email address, telephone number
Optional: Publication, position, medium/institution, mobile number, fax, homepage
The form data and date are sent by the backend of the website to the recipient via email.

Downloading press images:
Obligatory fields: Surname, first name, medium, email address
The form data and date are saved in the backend of the website.

Permission request to use photos or film or video recordings for current reporting:
Obligatory fields: First name, surname, email address, telephone number
Optional: Channel/publisher/institution, publication, fax
The form data and date are sent by the backend of the website to the recipient via email.

Permission request outside of the confines of current reporting:
Obligatory fields: First name, surname, medium, publication/channel/production company, email address, telephone number (with prefix), mobile
Optional: Fax (with prefix)
The form data and date are sent by the backend of the website to the recipient via email.

Contact form for visitors: Questions, bookings, feedback
Obligatory fields: First name, surname, email address
Optional: title
The data of the contact form for visitors is sent via the network protocol SOAP to OTRS and saved there. OTRS is the case management system for the information services from the Education, Outreach, and Visitor Services Department. All form inquiries are processed in OTRS. The form data and date are sent from the backend of the website to the recipient by email.

Registration for the Fotowalk:
Obligatory fields: Surname, first name, account name, email address
The form data and date are sent from the backend of the website to the recipient by email.

The engineering bureau of Dr Jürgen Freundel also has access to some of this data in SMart for maintenance and programming tasks.

The Staatliche Museen zu Berlin have carefully chosen this service provider and signed a contract with them to regulate data processing. The engineering bureau of Dr Jürgen Freundel is obliged to follow the instructions of the Staatliche Museen zu Berlin, and their activities are regularly evaluated.

If you transmit personal data to the Staatliche Museen zu Berlin through an inquiry, this information will only be used for that specific instance of correspondence or for the purpose named in the form. The data is saved for as long as is required by the purpose for which you have given your consent. You have the right to rescind your consent for future instances.

d) Newsletter

For sending the free newsletter, the Staatliche Museen zu Berlin uses the content management system TYPO3 with the Direct Mail extension.

Your information is stored in an encrypted form on servers in Germany. When you register, the following information is collected:

  • First name
  • Surname
  • Email address
  • Date and time of the registration and activation

The processing of this data is regulated by art 6 para. 1a of the GDPR. Registration is by way of a “double opt-in” model. In the registration process, we secure your consent and alert you to our data protection policy. If you register for our newsletter, this information will only be used for this purpose.

Of course you can cancel your registration at any point in the future. To unsubscribe, click on the link at the end of the newsletter, or use the following links:

Unsubscribe to the newsletter (General, Children and Families, Schools): https://www.smb.museum/newsletter/abonnieren.html

Unsubscribe to the newsletter of the Hamburger Bahnhof – Museum für Gegenwart – Berlin: https://www.smb.museum/museen-und-einrichtungen/hamburger-bahnhof/newsletter/abonnieren.html

Your details will then be deleted.

e) Images and videos of individuals on the website

The General Data Protection Regulation (GDPR) has strengthened the rights of affected individuals. It is possible that there are older images or videos on our website that show people who did not give their consent to be photographed or recorded. If this affects you, then you have “the right to withdraw [your] consent at any time”.

f) Presence on online channels and incorporation of services and content from third parties

Online channels of the Staatliche Museen zu Berlin

We are active on social media and platforms with our own profiles, in order to communicate with visitors, interested individuals and users, and to inform them about our services.

You can find details about how user data is managed in Facebook’s data privacy policy, at: https://www.facebook.com/about/privacy/, Opt-Out: https://www.facebook.com/settings?tab=ads und http://www.youronlinechoices.com, Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active.

It is currently unclear whether or not Facebook complies with the level of protection required by the European Union in relation to personal data. In light of this, the use of Facebook poses a risk in terms of data privacy.

Details about how user data is managed on Instagram are available in their data policy, at: http://instagram.com/about/legal/privacy/.

Details about how user data is managed on YouTube are available in their data policy, at: https://policies.google.com/privacy, Opt-Out: https://adssettings.google.com/authenticated, Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.

YouTube

For embedding and displaying video content, our website uses plugins from YouTube. The provider of this video portal is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.

When visiting a page with a YouTube plugin integrated into it, a connection to the YouTube servers is produced. Through this, YouTube receives information about which of our pages you have visited.

If you are logged into your YouTube account, YouTube can directly connect your internet activity with your personal profile. By logging out in advance, you are able to prevent this from occurring.

We use YouTube in the interests of delivering a dynamic presentation of our online content. This is considered a justified interest as outlined by art. 6 para. 1f of the GDPR.

Details about how user data is managed on YouTube are available in their data policy at: https://www.google.de/intl/de/policies/privacy.

Integration of Google Maps

On this website we use the services of Google Maps. This allows us to show an interactive map directly on the website, and allows you to comfortably use the map function.

By visiting the website, Google receives the information that you have visited this particular page on our website. Additionally, the data outlined in section 3 of this policy is transmitted. This occurs regardless of whether you are already logged into a Google account or have no user account. If you are logged into Google, your details will be directly connected with your account. If you do not wish to be connected with your account, you need to log out of your account before activating the button. Google saves your details as a usage profile and uses them for the purposes of advertising, market research and/or for optimizing its website. Such usage occurs in particular (even for users who are not logged in) for delivering customized advertising, and to inform other users of social networks about your activity on our website. You have the right to object to the creation of this user profile, however to make use of this right, you need to contact Google. 

Further information on the purpose and scope of data collection and its processing through the plugin provider can be found in the data policy of the provider. There you can also find further information on your rights in this area, and on your ability to protect your privacy through settings: www.google.de/intl/de/policies/privacy. Google also processes your personal information in the USA and is subject to the EU-US Privacy Shield https://www.privacyshield.gov/EU-US-Framework.

Incorporation of other services and external content

This website incorporates external content, an example being audio recordings from VoiceRepublic, or ePaper from Yumpu. This requires the providers of this content (hereafter referred to as “third party providers”) to process the IP addresses of users, since without the IP address, they could not send the content to the browser of the user. We make an effort to only use content for which the provider uses IP addresses of users exclusively for content provision. However we have no power to prevent third party providers from using the IP addresses for statistical purposes, for example. If we know that such practices are occurring, we make users aware of it.   

4. Who is responsible for content and maintenance, and who looks after data protection?

For this website, the Staatliche Museen zu Berlin – Preussischer Kulturbesitz, legally represented by Prof Dr Hermann Parzinger, President of the Stiftung Preussischer Kulturbesitz, is responsible for data protection.  

Staatliche Museen zu Berlin – Preussischer Kulturbesitz
General Directorate
Stauffenbergstraße 41
10785 Berlin
Germany

Telephone: +49 (0)30 2660
Email: kommunikation[at]smb.spk-berlin.de
Website: www.smb.museum

For questions relating to data protection, the Stiftung Preussischer Kulturbesitz has a Data Protection Officer whom you can contact at our aforementioned postal address, addressed to the “Datenschutzbeauftragte”. Alternatively, you can contact them at:

Email: 
Website of the Stiftung Preussischer Kulturbesitz: http://www.preussischer-kulturbesitz.de/service/kontakt/ansprechpartnerinnen/interessenvertretungen.html

5. Changes to the Data Protection Policy

The Staatliche Museen zu Berlin reserves the right to adapt this policy to meet technological developments and changes to legal frameworks. The date of the most recent version of this data protection policy can be found at the end of this notice.

Date: May 2018