Privacy statement

Privacy statement

Data protection (information pursuant to Art. 13 GDPR)

MAHLE FOUNDATION GmbH (in the following „we“ or „us“) is delighted about your visit to its internet pages and your interest in its work and organization.

The following information refers to the website accessible at the URL: https://www.mahle-stiftung.de/ and their subpages as well as on the URL https://antragmahle.syprof.de/AccountPortal/Home.cshtml accessible restricted area of our funding portal (hereinafter also referred to as the ‘funding portal’) with its subpages.

We attach great importance to data protection and process your personal data confidentially and only in accordance with the statutory regulations. Below, we provide information about when we collect which data and how we use it.
 

A. Controller

Responsible controller for data protection is:

MAHLE FOUNDATION GmbH
Leibnizstrasse 35
70193 Stuttgart, Germany
Phone +49 711 6566169-0
E-Mail info@mahle-stiftung.de

Managing Partner: Jürgen Schweiß-Ertl
Court of registration: Amtsgericht Stuttgart
Number of Registration: HRB 2989
 

B. Scope of personal data processing

All information relating to an identified or identifiable natural person is personal data, such as name, identification number, email addresses or contract details. This may also include data that provides information about the physical, physiological, genetic, mental, economic, cultural or social identity of a natural person. We collect and use personal data only to the extent necessary to provide a functional website and our content and services. The collection and use of personal data of users of our website only takes place if there is a legal basis for this or if you have given us your consent.
 

C. Categories of data processed

I. When visiting the website

When you visit our website, the following categories of personal data are processed:

  • Technical contact data that is essential for accessing our website and documents the connection established, such as IP address, date and time of website access, browser type and operating system used.
  • Tracking data on your usage behaviour.

II. When using the enquiry function

If you use our enquiry function under the rubric ‘Enquiry’, the following data categories will be processed:

  • Communication data (e.g. name, institution, e-mail address)
  • Project-related information (e.g. brief description of the project, desired funding amount, project location and funding period)
  • Contents of communication processes

III. When using the funding portal

When you use our funding portal, the following categories of data are processed:

  • Communication data (e.g. title, name, telephone number, email address, postal address)
  • Project-related information and documents
  • Contents of communication processes
  • Contract data and contents of agreements

IV. When registering for and subscribing to our newsletter

When you register to receive our newsletter, we process the following categories of data:

  • Email address
  • Postal address and country (for postal delivery)
  • Data documenting your consent to data processing
     

D. Purposes and legal bases of data processing

We process your personal data for the following purposes:

•    Provision of the website (legal basis: legitimate interest of the MAHLE FOUNDATION in public relations within the framework of data protection regulations in accordance with Art. 6 (1) (f) GDPR)

•    Evaluation of usage behaviour (legal basis: consent pursuant to Art. 6 (1) (a) GDPR)

•    Communication by e-mail, post, telephone (legal basis: legitimate interest in responding to your inquiry in accordance with Art. 6 (1) (f) GDPR or, where applicable, the implementation of a contract or the initiation of a contract in accordance with Art. 6 (1) (b) GDPR)

•    Sending letters and information by post and/or e-mail to draw attention to tenders, for press communication, sending invitations, connecting project partners, sending greetings (legal basis: legitimate interest in sending in accordance with Art. 6 (1) (f) GDPR or, where applicable, consent given in accordance with Art. 6 (1) (a) GDPR)

•    Processing for archival and historiographical purposes (legal basis Art. 89 GDPR in conjunction with § 28 BDSG (Federal Data Protection Act))

•    Conducting business relationships (legal basis: legitimate interest in the use of, for example, contact details in accordance with Art. 6 (1) (f) GDPR)

•    Provision of video files from third-party providers (YouTube) (legal basis: consent pursuant to Art. 6(1)(a) GDPR)

•    Provision of map services via third-party providers (Google Maps) (legal basis: consent pursuant to Art. 6(1)(a) GDPR)

•    To identify malfunctions and for security reasons (legal basis: fulfilment of our legal obligations in the area of data security and legitimate interest in eliminating malfunctions and ensuring the security of our services pursuant to Art. 6(1)(c) and (f) GDPR).

•    Fulfilment of usage contracts (legal basis: fulfilment of the agreement pursuant to Art. 6(1)(b) GDPR)

•    Enquiry function to determine whether a formal application for funding has sufficient prospects of success (legal basis: legitimate interest in an efficient formal application procedure for funding in accordance with Art. 6 (1) (f) GDPR)

•    Use of our funding portal by registering to submit applications and implement funding projects (legal basis: contract initiation and contract fulfilment pursuant to Art. 6(1)(b) GDPR).

•    Promotion and implementation of projects (legal basis: fulfilment of contract pursuant to Art. 6(1)(b) GDPR)

•    Sending the newsletter to recipients by email (legal basis: consent pursuant to Art. 6(1)(a) GDPR)

•    Sending the newsletter to recipients by post (legal basis: consent pursuant to Art. 6(1)(a) GDPR)

•    Safeguarding and defending our rights (legal basis: legitimate interest of MAHLE FOUNDATION in asserting and defending its rights pursuant to Art. 6(1)(f) GDPR).

•    Documentation of declaration(s) of consent (legal basis: Art. 6(1)(c) in conjunction with Art. 7(1) GDPR).
 

E. Transfer of data

I. General Information

Your personal data will not be transferred to third parties for purposes other than those stated. We will only transfer your personal data to third parties if:

•    you have given your express consent,

•    the processing is necessary for the initiation or execution of a contract with you,

•    the processing is necessary to fulfil a legal obligation

 •   the processing is necessary to safeguard legitimate interests and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data.

II. Transfer to other controllers

We will only transfer your personal data to other controllers if this is necessary for the fulfilment of a contract, if we or the third party have a legitimate interest in the transfer, or if you have given your consent. In addition, data may be transferred to other controllers if we are obliged to do so by law or by an enforceable administrative or court order.

III. Transfer to service providers

We carefully select and regularly monitor the service providers we commission (e.g. programming or web hosting). All service providers are bound by us to maintain confidentiality and comply with the legal requirements regarding data protection.

IV. Transfer to recipients outside the EEA

We may also transfer personal data to recipients located outside the EEA and thus in so-called third countries. In such a case, prior to the transfer, we ensure that the recipient either provides an appropriate level of data protection (e.g. due to a decision of adequacy by the EU Commission for the respective country or due to the agreement based on so-called EU standard contractual clauses of the European Union with the recipient) or that you have given your consent to the transfer.
 

F. Duration of storage and deletion of data

We only store your personal data for as long as it is necessary to provide our online services or to carry out a funding project, or for as long as we have a legitimate interest in further processing. In all other cases, we delete the personal data unless we are obliged to continue storing it due to legal obligations (For example, we are obliged to retain certain documents for the period specified by law due to tax and commercial law deadlines).
 

G. Data processing when visiting our website

I. General Information

When you visit our website, certain personal data is collected. This serves to improve the content and functionality and thus the attractiveness of our website.

We use these server log files to store information that your browser automatically transmits to us for technical reasons. This data is not stored in a way that can be traced back to you. Nor is this data merged with other data sources. The log files are stored to ensure smooth connection establishment, convenient use of our website, evaluation of system security and stability, and for security reasons (e.g. to investigate attempted attacks).

In individual cases, log files may be passed on to investigating authorities. We generally store your IP address in anonymised form; no personal evaluation takes place. With the exception of storage for the purpose of logging consent, the pseudonymised IP address is deleted promptly after your visit to our website.

The server log files differ – including in terms of the general storage period – depending on whether you visit our website at https://www.mahle-stiftung.de/  (with subpages) or whether you visit https://antragmahle.syprof.de/AccountPortal/Home.cshtml  with subpages. Both areas are therefore distinguished below.

1. This applies when you visit our website at https://www.mahle-stiftung.de/

When you visit our website at https://www.mahle-stiftung.de/, we store the following server log files

• Browser type/version including installed add-ons

• Pseudonymised IP address (so-called Internet Protocol address) of the end device from which our online service is accessed.

• Operating system used on the end device

• Referrer URL (the previously visited website)

• Date, time and duration of the server request

• Amount of data transferred

• Name of the files or information accessed

These log files are deleted after a storage period of 6 months, unless longer storage is necessary for purposes of evidence or to clarify an incident.

2. This applies when accessing our funding portal at https://antragmahle.syprof.de/ AccountPortal/Home.cshtml

When you visit our funding portal at

https://antragmahle.syprof.de/AccountPortal/Home.cshtml

we store the following information, which your browser automatically transmits for technical reasons:

• Operating system used on the end device

• Date, time and duration of the server request

• Email address

• Session ID

These log files are deleted after a storage period of 3 months, unless longer storage is necessary for evidence purposes or to investigate an incident.

II. Use of cookies

We use cookies on our website that are necessary for the use of our online services. Cookies are small text files that are stored on your device and can be read. A distinction is made between session cookies, which are deleted as soon as you close your browser, and permanent cookies, which are stored beyond the individual session.

You can use your browser settings to decide for yourself whether and which cookies your browser allows and to delete individual or all cookies. Please note that the functionality of websites may be restricted or even disabled if certain cookies are not allowed.

Depending on their function and purpose, the use of certain cookies may require the user's consent. You can give your consent via a so-called ‘cookie banner’:   When you visit our website, we display our cookie banner. In our cookie banner, you can declare your consent to the use of all cookies on this website that require consent by clicking on the ‘Select all’ button. Without such consent, cookies requiring consent will not be activated.

By adjusting the individual sliders, you can also make differentiated settings with regard to individual cookies or completely reject all cookies requiring consent and then click on the corresponding button to ‘Save settings’. Your decision will be stored in a cookie.

We use the following cookies on our website:

For more information on the use of cookies when using Google Analytics, please refer to the following section.

III. Use of Google Analytics

If you have given your consent, we use the web analysis service Google Analytics on our website. This is done using the ‘cookies’ mentioned in the previous section. With the help of Google Analytics, we can analyse the user behaviour of visitors to our website in pseudonymised and anonymised form. The purposes of data processing are to evaluate the use of the website and to compile reports on activities on the website. The recipient of the data within the scope of processing on behalf is Google Ireland Limited (Google Building, Gordon House, Barrow Street, Dublin 4, Ireland). Google Ireland Limited uses Google LLC in the USA (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) as its service provider.

The provision of data is neither mandatory nor technically necessary for the use of our website. You are under no obligation to provide the data. If you do not provide the data, we will not be able to perform web analysis using The provision of data is neither mandatory nor technically necessary for the use of our website. You are under no obligation to provide the data. If you do not provide the data, we will not be able to perform web analysis using Google Analytics. You can prevent cookies from being stored by adjusting your browser software settings accordingly. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website, as well as preventing Google from processing this data, by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de

IV. Use of Google Maps

On our website, we embed the Google Maps map service provided by Google LLC (based at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), which is not stored on our servers. To ensure that visiting our website with embedded map services does not automatically result in Google Maps content being reloaded, we initially only display locally stored preview images of the maps. Through this, Google does not receive any information.

Only after clicking on the preview image will content from Google Maps be loaded. This provides Google with the information that you have accessed our site, as well as the technically necessary usage data. We have no influence on further data processing by the third-party provider. By clicking on the preview image, you give us your consent to load content from the third-party provider.

The embedding is based on your consent in accordance with Art. 6(1)(a) GDPR, provided that you have previously given your consent by clicking on the preview image.

Please note that embedding Google Maps means that your data will be processed outside the EU or the EEA. In some countries, there is a risk that authorities may access the data for security and surveillance purposes without you being informed or being able to seek legal remedies.

If we use providers in unsafe third countries and you consent, the transfer to an unsafe third country will be based on Art. 49(1)(a) GDPR

In the case of Google Maps, there is no adequate level of data protection. The transfer is based on Art. 49(1)(a) GDPR.

Withdrawal of consent: If you have clicked on a preview image, the third-party content will be reloaded immediately. If you do not want this to happen, please do not click on the preview images.

V. Integration of YouTube (so-called embedding in privacy mode)

By activating the corresponding slider in the cookie banner or on the preview within the embedded video to play the content, you agree that we may allow Google, as the provider of the YouTube service, to collect data for its own purposes. The collection and processing of this data is the sole responsibility of Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland. Google Ireland Limited uses Google LLC in the USA (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) as its service provider.

We then embed videos stored on YouTube on our website. It is also possible to embed Google Fonts content. When embedded, content from the YouTube website is displayed in parts of a browser window. However, the YouTube videos are only accessed by clicking on the video separately. YouTube content is embedded in what is known as ‘extended data protection mode’. This is provided by Google as the operator of YouTube and ensures that no data is transmitted to Google and no cookies are stored on your device before you click on the cookie banner or activate your consent in the section of the browser window for playing the video.

As soon as you activate the corresponding slider in the cookie banner or give your consent by clicking to load the video, the video will be loaded from YouTube. Technically, the same thing happens as if you were to switch to the YouTube website via a link: YouTube receives all the information that your browser automatically transmits (including your IP address). YouTube also sets its own cookies on your device. This also happens if you do not have a YouTube user account. If you are logged in to YouTube or Google, your data will be directly associated with your account. If you do not want your data to be associated with your YouTube or Google user account, you must log out of YouTube and Google before clicking on the corresponding slider in the cookie banner or the consent notice in the video frame of the browser window.

We have no knowledge of further details regarding the processing of personal data in this regard within Google's area of responsibility. MAHLE FOUNDATION has no influence on Google's data processing.

Information about Google's processing of personal data can be found in Google's privacy policy: https://policies.google.com/privacy.  

The integration of YouTube is based on your consent in accordance with Art. 6 (1) (a) GDPR, provided that you have previously given your consent by clicking on the preview image or in the cookie banner.

Withdrawal of consent: Once you have clicked on a preview image, the content from YouTube will be reloaded immediately. If you do not want this reloading to occur on other pages, please do not click on the preview images.

VI. Data processing when using the enquiry function

On our website, you can send us an informal enquiry under the heading ‘Enquiry’. This should not be confused with our funding portal. Based on the information you provide in your enquiry, we can regularly assess whether we would be able to support your request. This allows us to provide you with initial feedback quickly and easily.

To do this, you must enter the following information in the form on the website:

Your name, the name and address of the institution, an email address, telephone number, project title, project location, project period, brief description of the project, other sponsors, total project costs, and the amount of funding requested.

We process this data on the basis of our legitimate interest in an efficient application process (the legal basis for this is Art. 6 (1) (f) GDPR). This allows us to check whether funding is possible based on the information in your enquiry.

You have the option to object to the processing of your data. If you exercise this right, we ask you to explain the reasons why we should not process your personal data as we have done. We will then review the situation and either adjust or discontinue the data processing or explain to you our compelling legitimate reasons for continuing the processing.

We store the personal data transmitted as part of the inquiry procedure until your inquiry has been processed.

We also do not pass this data on to third parties.

VII. Use of our funding portal

Our funding portal serves to submit applications, transmit necessary information, and implement and process project funding.

The transmission of documents and communication before, during, and after the completion of a project funding can thus be handled promptly, without major effort, and in compliance with data protection regulations. The standardized and predefined input form also makes it easier for us to review and process project funding.

If you would like to use our funding portal, you must create a user profile by entering your email address, a password of your choice, your first and last name, and your institution. This information is required for registration.

For this service, we use the double opt-in procedure, which means that you will receive an email in which you must confirm that you are the owner of the email address provided and that you wish to receive communications via this email address during the application process and during and after the funding period. We store the data you provide, the time of your registration, and your IP address until your user profile (account) is permanently deleted. 

After registration, further contact details must be provided, such as business telephone number and address.

Please note that using the funding portal does not constitute private communication! Messages and documents can be viewed by all MAHLE FOUNDATION employees as well as by your organization and its employees.

When you use our funding portal, we store the data required for contract initiation and, if applicable, contract fulfillment until your user profile is deleted. We also store the voluntary data you provide for the duration of your use of the funding portal, unless you delete it beforehand. You can manage and change all information in the protected area of the funding portal. The legal basis for processing is Art. 6 (1) sentence 1 lit. b GDPR.

Furthermore, we store project-related information and documents, the content of communications, contract data and the content of agreements, as well as bank account details (no payment transactions) beyond the end of the project until the expiry of the retention periods required by tax law.

For data protection reasons, please avoid providing personal data of third parties (e.g., names and contact details) when submitting your application. The only exceptions are contact persons for your project and authorized representatives of your organization.

It is also possible that you may receive so-called system messages within the funding portal. System messages are only sent to you as a user of the funding portal. The email address provided when registering for the funding portal is used for this purpose. Other persons, such as contact persons designated by you for the funding project, do not receive system messages.

To prevent unauthorized access by third parties to your personal data and confidential business data, in particular financial data, the connection is encrypted using TLS technology.

VIII. Newsletter Distribution

Our cost-free newsletter provides you with regular updates on current events and projects via email. We use the double opt-in procedure for registering for our newsletter. This means that after you register, we will send an email to the email address you provided, asking you to confirm that you are the owner of the email address and that you wish to receive the newsletter.

If you do not confirm your registration within 30 days, your information will be automatically deleted after the 30 days have expired. In addition, we store your IP addresses and the times of registration and confirmation. This serves the purpose of verifying your registration and, if necessary, investigating any possible misuse of your personal data.

The only mandatory information required for sending the newsletter is your email address. The provision of additional, separately marked data is voluntary and is used to address you personally.   The data you enter for this purpose will only be used to personalise the newsletter and will not be passed on to third parties.

After your confirmation, we will store your email address for the purpose of sending you the newsletter. The legal basis for this is Art. 6 (1) sentence 1 lit. a GDPR. You can unsubscribe from the newsletter at any time by clicking on the link provided in each newsletter email or revoke your consent at any time by sending an email to info@ or by sending a message to the contact details provided in the imprint.

IX. Data security: SSL encryption

To protect the security of your data during transmission, we use state-of-the-art encryption methods (e.g. SSL) via HTTPS.
 

H. Your rights

You have the right to:

•    information about your data stored by us and its processing,
•    correction of incorrect personal data, deletion of your data stored by us,
•    restriction of data processing if we are not yet permitted to delete your data due to legal obligations,
•    objection to the processing of your data by us if the requirements of Art. 21 GDPR are met,
•    data portability,
•    right to revoke consent: if you have given us your consent, you can revoke it at any time with effect for the future.

You also have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. This may be the data protection authority responsible for your place of residence or federal state, or the data protection authority responsible for us. The data protection authority responsible for us is:

The State Commissioner for Data Protection and Freedom of Information

Street address:
Königstrasse 10a
70173 Stuttgart

Postal address:
PO Box 10 29 32
70025 Stuttgart
Tel.: 0711/615541-0
Fax: 0711/615541-15
E-Mail: poststelle@lfdi.bwl.de
 

I. Changes to our privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. The new privacy policy will then apply to your next visit.