Privacy Policy


The privacy policy also applies to our social media accounts:

https://www.facebook.com/kunsthallebad
https://www.instagram.com/kunsthallebadenbaden/
https://www.youtube.com/user/kunsthallebadenbaden

1. An overview of data protection

General information

The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit this website. The term “personal data” comprises all data that can be used to personally identify you. For detailed information about the subject matter of data protection, please consult our Data Protection Declaration, which we have included beneath this copy.

Data recording on this website

Who is the responsible party for the recording of data on this website (i.e., the “controller”)?

The data on this website is processed by the operator of the website, whose contact information is available under section “Information about the responsible party (referred to as the “controller” in the GDPR)” in this Privacy Policy.

How do we record your data?

We collect your data as a result of your sharing of your data with us. This may, for instance be information you enter into our contact form.

Other data shall be recorded by our IT systems automatically or after you consent to its recording during your website visit. This data comprises primarily technical information (e.g., web browser, operating system, or time the site was accessed). This information is recorded automatically when you access this website.

What are the purposes we use your data for?

A portion of the information is generated to guarantee the error free provision of the website. Other data may be used to analyse your user patterns. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders or other order enquiries.

What rights do you have as far as your information is concerned?

You have the right to receive information about the source, recipients, and purposes of your archived personal data at any time without having to pay a fee for such disclosures. You also have the right to demand that your data are rectified or eradicated. If you have consented to data processing, you have the option to revoke this consent at any time, which shall affect all future data processing. Moreover, you have the right to demand that the processing of your data be restricted under certain circumstances. Furthermore, you have the right to log a complaint with the competent supervising agency.

Please do not hesitate to contact us at any time if you have questions about this or any other data protection related issues.

Analysis tools and tools provided by third parties

There is a possibility that your browsing patterns will be statistically analysed when your visit this website. Such analyses are performed primarily with what we refer to as analysis programs.

For detailed information about these analysis programs please consult our Data Protection Declaration below.

2. Hosting

We are hosting the content of our website at the following provider:

External Hosting

This website is hosted externally. Personal data collected on this website are stored on the servers of the host. These may include, but are not limited to, IP addresses, contact requests, metadata and communications, contract information, contact information, names, web page access, and other data generated through a web site.

External hosting is carried out by a professional provider in order to perform a task in the public interest and in the interest of providing our online services securely, quickly and efficiently (Art. 6(1)(e) GDPR). If appropriate consent has been obtained, the processing is carried out exclusively on the basis of Art. 6 (1)(a) GDPR and § 25 (1) TDDDG, insofar the consent includes the storage of cookies or the access to information in the user's end device (e.g., device fingerprinting) within the meaning of the TDDDG. This consent can be revoked at any time.

Our host will only process your data to the extent necessary to fulfil its performance obligations and to follow our instructions with respect to such data.

We are using the following host:

Prolog AG
Hammerstrasse 44
4058 Basel
Schweiz

Data processing

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.

3. General information and mandatory information

Data protection

The operators of this website and its pages take the protection of your personal data very seriously. Hence, we handle your personal data as confidential information and in compliance with the statutory data protection regulations and this Data Protection Declaration.

Whenever you use this website, a variety of personal information will be collected. Personal data comprises data that can be used to personally identify you. This Data Protection Declaration explains which data we collect as well as the purposes we use this data for. It also explains how, and for which purpose the information is collected.

We herewith advise you that the transmission of data via the Internet (i.e., through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.

Information about the responsible party (referred to as the “controller” in the GDPR)

The data processing controller on this website is:

Staatliche Kunsthalle Baden-Baden
Lichtentaler Allee 8 a
76530 Baden-Baden

Phone: +49 7221-30076-400
E-mail: info[at]kunsthalle-baden-baden.de

The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g., names, e-mail addresses, etc.).

Storage duration

Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.

General information on the legal basis for the data processing on this website

If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9 (2)(a) GDPR, if special categories of data are processed according to Art. 9 (1) DSGVO. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also based on Art. 49 (1)(a) GDPR. If you have consented to the storage of cookies or to the access to information in your end device (e.g., via device fingerprinting), the data processing is additionally based on § 25 (1) TDDDG. The consent can be revoked at any time. If your data is required for the fulfilment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, if your data is required for the fulfilment of a legal obligation, we process it on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of Art. 6 (1)(e) GDPR if it is necessary for the performance of a task in the public interest. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.

Designation of a data protection officer

We have appointed a data protection officer.

dacuro GmbH
Heinrich-Hertz-Straße 11
69190 Walldorf

E-Mail: datenschutz[at]kunsthalle-baden-baden.de
Website: https://www.dacuro.de/

Recipients of personal data

In the scope of our business activities, we cooperate with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is required as part of the fulfilment of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if the disclosure is necessary for the performance of a task in the public interest (Art. 6 (1)(e) GDPR), or if another legal basis permits the disclosure of this data. When using processors, we only disclose personal data of our customers on the basis of a valid contract on data processing. In the case of joint processing, a joint processing agreement is concluded.

Revocation of your consent to the processing of data

A wide range of data processing transactions are possible only subject to your express consent. You can also revoke at any time any consent you have already given us. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.

Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)

IN THE EVENT THAT DATA ARE PROCESSED ON THE BASIS OF ART. 6(1)(E) GDPR, YOU HAVE THE RIGHT TO AT ANY TIME OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA BASED ON GROUNDS ARISING FROM YOUR UNIQUE SITUATION. THIS ALSO APPLIES TO ANY PROFILING BASED ON THESE PROVISIONS. TO DETERMINE THE LEGAL BASIS, ON WHICH ANY PROCESSING OF DATA IS BASED, PLEASE CONSULT THIS DATA PROTECTION DECLARATION. IF YOU LOG AN OBJECTION, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE ARE IN A POSITION TO PRESENT COMPELLING PROTECTION WORTHY GROUNDS FOR THE PROCESSING OF YOUR DATA, THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR IF THE PURPOSE OF THE PROCESSING IS THE CLAIMING, EXERCISING OR DEFENCE OF LEGAL ENTITLEMENTS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED IN ORDER TO INFORM YOU ABOUT YOUR OWN SIMILAR OFFERS, EVENTS OR SERVICES WITHIN THE FRAMEWORK OF DIRECT INFORMATION, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH INFORMATION; THIS ALSO APPLIES TO PROFILING, INSOFAR AS IT IS RELATED TO SUCH INFORMATION TRANSMISSION. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR THIS PURPOSE (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to log a complaint with the competent supervisory agency

In the event of violations of the GDPR, data subjects are entitled to log a complaint with a supervisory agency, in particular in the member state where they usually maintain their domicile, place of work or at the place where the alleged violation occurred. The right to log a complaint is in effect regardless of any other administrative or court proceedings available as legal recourses.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you should demand the direct transfer of the data to another controller, this will be done only if it is technically feasible.

Information about, rectification and eradication of data

Within the scope of the applicable statutory provisions, you have the right to demand information about your archived personal data, their source and recipients as well as the purpose of the processing of your data at any time. You may also have a right to have your data rectified or eradicated. If you have questions about this subject matter or any other questions about personal data, please do not hesitate to contact us at any time.

Right to demand processing restrictions

You have the right to demand the imposition of restrictions as far as the processing of your personal data is concerned. To do so, you may contact us at any time. The right to demand restriction of processing applies in the following cases:

  • In the event that you should dispute the correctness of your data archived by us, we will usually need some time to verify this claim. During the time that this investigation is ongoing, you have the right to demand that we restrict the processing of your personal data.
  • If the processing of your personal data was/is conducted in an unlawful manner, you have the option to demand the restriction of the processing of your data instead of demanding the eradication of this data.
  • If we do not need your personal data any longer and you need it to exercise, defend or claim legal entitlements, you have the right to demand the restriction of the processing of your personal data instead of its eradication.
  • If you have filed an objection in accordance with Art. 21(1) GDPR, it will be checked whether there are compelling legitimate grounds for the processing or whether the processing serves to assert, exercise or defend legal claims. For the duration of the audit, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data – with the exception of their archiving – may be processed only subject to your consent or to claim, exercise or defend legal entitlements or to protect the rights of other natural persons or legal entities or for important public interest reasons cited by the European Union or a member state of the EU.

SSL and/or TLS encryption

For security reasons and to protect the transmission of confidential content, such as purchase orders or inquiries you submit to us as the website operator, this website uses either an SSL or a TLS encryption program. You can recognize an encrypted connection by checking whether the address line of the browser switches from “http://” to “https://” and also by the appearance of the lock icon in the browser line.

If the SSL or TLS encryption is activated, data you transmit to us cannot be read by third parties.

Rejection of unsolicited e-mails

We herewith object to the use of contact information published in conjunction with the mandatory information to be provided in our Site Notice to send us promotional and information material that we have not expressly requested. The operators of this website and its pages reserve the express right to take legal action in the event of the unsolicited sending of promotional information, for instance via SPAM messages.

4. Recording of data on this website

Cookies

Our websites and pages use what the industry refers to as “cookies.” Cookies are small data packages that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or they are permanently archived on your device (permanent cookies). Session cookies are automatically deleted once you terminate your visit. Permanent cookies remain archived on your device until you actively delete them, or they are automatically eradicated by your web browser.

Cookies can be issued by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services of third-party companies into websites (e.g., cookies for handling payment services).

Cookies have a variety of functions. Many cookies are technically essential since certain website functions would not work in the absence of these cookies (e.g., the shopping cart function or the display of videos). Other cookies may be used to analyse user behaviour or for promotional purposes.

Cookies, which are required for the performance of electronic communication transactions, for the provision of certain functions you want to use (e.g., for the shopping cart function) or those that are necessary for the optimization (required cookies) of the website (e.g., cookies that provide measurable insights into the web audience), shall be stored on the basis of Art. 6(1)(e) GDPR, unless a different legal basis is cited. The operator of the website has a legitimate interest in the storage of required cookies to ensure the technically error-free and optimized provision of the operator’s services. If your consent to the storage of the cookies and similar recognition technologies has been requested, the processing occurs exclusively on the basis of the consent obtained (Art. 6(1)(a) GDPR and § 25 (1) TDDDG); this consent may be revoked at any time.

You have the option to set up your browser in such a manner that you will be notified any time cookies are placed and to permit the acceptance of cookies only in specific cases. You may also exclude the acceptance of cookies in certain cases or in general or activate the delete-function for the automatic eradication of cookies when the browser closes. If cookies are deactivated, the functions of this website may be limited.

If other cookies and services are used on this website, you can find this information in this privacy policy.

Server log files

The provider of this website and its pages automatically collects and stores information in so-called server log files, which your browser communicates to us automatically. The information comprises:

  • The type and version of browser used
  • The used operating system
  • Referrer URL
  • The hostname of the accessing computer
  • The time of the server inquiry
  • The IP address

This data is not merged with other data sources.

This data is recorded on the basis of Art. 6(1)(e) GDPR. The collection of the server log files is necessary for the performance of a task in the public interest, in particular to ensure the technically error-free presentation, the security and the stability of the website.

Request by e-mail, telephone, or fax

If you contact us by e-mail, telephone or fax, your request, including all resulting personal data (name, request) will be stored and processed by us for the purpose of processing your request. We do not pass these data on without your consent.

These data are processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the fulfilment of a contract or is required for the performance of pre-contractual measures. In all other cases, the processing is based on the performance of a task in the public interest (Art. 6(1)(e) GDPR) or on the basis of your consent (Art. 6(1)(a) GDPR) if it has been obtained; the consent can be revoked at any time.

The data sent by you to us via contact requests remain with us until you request us to delete, revoke your consent to the storage or the purpose for the data storage lapses (e.g. after completion of your request). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.

5. Social media

We maintain publicly accessible profiles in social networks. Social networks such as Facebook, X (Twitter), etc. can analyze your user behavior when you visit their website or a website with integrated social media content (e.g. Like-Buttons or advertising banners). A visit to our social media sites triggers numerous processing operations.

If you are logged in to your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media portal. In this case, this data is collected, for example, via cookies that are stored on your end device or by recording your IP address.

Using the data collected in this way, the operators of the social media portals can create user profiles in which their preferences and interests are stored. This way you can see interest-based advertising inside and outside of your social media presence. If you have an account with the social network, interest-based advertising can be displayed on any device you are logged in to or have logged in to.

Please also note that we cannot retrace all processing operations on the social media portals. Depending on the provider, additional processing operations may therefore be carried out by the operators of the social media portals. Details can be found in the terms of use and privacy policy of the respective social media portals.

Legal basis

Our social media presences are intended to ensure the most comprehensive presence possible on the Internet. They serve to inform the public and to carry out our public tasks. This is the processing of personal data for the performance of a task in the public interest (Art. 6(1)(e) GDPR). The analysis processes initiated by the social networks may be based on divergent legal bases to be specified by the operators of the social networks (e.g., consent within the meaning of Art. 6(1)(a) GDPR).

Responsibility and assertion of rights

If you visit one of our social media sites (e.g., Facebook), we, together with the operator of the social media platform, are responsible for the data processing operations triggered during this visit. You can in principle protect your rights (information, correction, deletion, limitation of processing, data portability and complaint) vis-à-vis us as well as vis-à-vis the operator of the respective social media portal (e.g., Facebook).

Please note that despite the shared responsibility with the social media portal operators, we do not have full influence on the data processing operations of the social media portals. Our options are determined by the company policy of the respective provider.

Storage time

The data collected directly from us via the social media presence will be deleted from our systems as soon as you ask us to delete it, you revoke your consent to the storage or the purpose for the data storage lapses. Stored cookies remain on your device until you delete them. Mandatory statutory provisions - in particular, retention periods - remain unaffected.

We have no control over the storage duration of your data that are stored by the social network operators for their own purposes. For details, please contact the social network operators directly (e.g., in their privacy policy, see below).

Social networks in detail

Facebook

We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland (hereinafter Meta). According to Meta’s statement the collected data will also be transferred to the USA and to other third-party countries.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link:
https://www.dataprivacyframework.gov/participant/4452

We have concluded a joint processing agreement (Controller Addendum) with Facebook. This agreement defines which data processing operations we or Facebook are responsible for when you visit our Facebook page. We receive "Insights" data from Facebook, i.e. data on user numbers. These "Insights" data are personal data according to the GDPR, which are collected and processed in connection with a visit to or interaction of persons with a page and its contents.

The agreement on joint responsibility can be viewed at the following link:
https://www.facebook.com/legal/terms/page_controller_addendum

Facebook also processes information about the users of the Facebook Platform in other ways, and you, as a user of Facebook, have a direct relationship with Facebook in this regard. In this respect, we refer you to the Facebook privacy policy. You can customize your advertising settings independently in your user account. Click on the following link and log in:
https://www.facebook.com/settings?tab=ads.

Details can be found in the Facebook privacy policy:
https://de-de.facebook.com/privacy/explanation

Data processing for interactions on our Facebook page

On our Facebook page you have the possibility to get in contact with us by commenting on our contributions, creating a contribution yourself or sending us private messages. If you want to avoid Facebook processing personal data that you have submitted to us, please contact us by other means.

Instagram

We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875, and
https://de-de.facebook.com/help/566994660333381.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link:
https://www.dataprivacyframework.gov/participant/4452

For details on how they handle your personal information, see the Instagram Privacy Policy:
https://help.instagram.com/519522125107875.

Data processing for interactions on our Instagram profile

When using certain interactive features on Instagram (such as the comment feature or the "Like" button), comments or likes will be visible to other users and to us as the provider of the Instagram site. This allows a direct user assignment based on the personal data disclosed.

As an Instagram user, you have a direct relationship with Instagram. In this respect we refer you to the Instagram data protection information. We have no control over interactive functionality and visibility of comments, likes or other activities on our Instagram site. The type, scope and duration of processing and storage of personal data in this respect are determined by Instagram, so that Instagram is also responsible for them. We expressly point out that Instagram, and thus Meta, stores the data of its users (e.g. personal information, IP address, etc.) and may also use this data for business purposes.
When you visit our Instagram site, Instagram and its affiliated company Facebook collects, among other things, your IP address and other information available on your PC in the form of cookies. This information is used to provide us, as the operator of the Instagram pages, with statistical information about the usage of the Instagram page.

Further information on Instagram's data processing can be found in Instagram's privacy policy at:
https://privacycenter.instagram.com/,
https://www.facebook.com/privacy/center and https://help.instagram.com/196883487377501?ref=dp

YouTube

We use the platform YouTube to post your own videos and make them publicly available. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Irland.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://policies.google.com/privacy/frameworks?hl=de

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link:
https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Our website contains links or connections to content posted through YouTube. In general, we are not responsible for the content of websites that are linked to our website. Please note that when you click on a YouTube link, YouTube will store and use your information (e.g., personal information, IP address) for business purposes in accordance with its own data use policy.

If you visit our YouTube channel, please note the following:

When using the YouTube service, data collected about you will be processed by the provider and, if necessary, transferred to countries outside the European Union.

We also receive aggregated statistical data (so-called insights) from YouTube. These statistics receive information about the source of the call to the YouTube channel, the type of end device used to access the channel or the page views. We only receive anonymous information and statistics if the visitor to our YouTube channel is registered with YouTube.

Address and link to the privacy policy of Google:
https://policies.google.com/privacy?hl=de

6. Analysis tools and advertising

Matomo

This website uses the open-source web analysis service Matomo.

Through Matomo, we are able to collect and analyse data on the use of our website-by-website visitors. This enables us to find out, for instance, when which page views occurred and from which region they came. In addition, we collect various log files (e.g. IP address, referrer, browser, and operating system used) and can measure whether our website visitors perform certain actions (e.g. clicks, purchases, etc.).

The use of this analysis tool is based on your consent in accordance with Art. 6(1)(a) GDPR and, insofar as the consent includes the storage of cookies or access to information in the user's end device (e.g. device fingerprinting) within the meaning of the TDDDG, on the basis of § 25 (1) TDDDG. The consent can be revoked at any time.

IP anonymization

For analysis with Matomo we use IP anonymization. Your IP address is shortened before the analysis, so that it is no longer clearly assignable to you.

Hosting

We host Matomo with the following third-party provider:

InnoCraft Ltd.
150 Willis St
Wellington 6011
Neuseeland

EU representative according to Art. 27 GDPR:
ePrivacy Holding GmbH
Burchardstraße 14
20095 Hamburg

E-Mail: eu.rep[at]eprivacy.eu

Data processing

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.

7. Newsletter

Newsletter data

If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. Further data is not collected or only on a voluntary basis. For the handling of the newsletter, we use newsletter service providers, which are described below.

Mailchimp

This website uses the services of Mailchimp to send out its newsletters. The provider is the Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.

Among other things, Mailchimp is a service that can be deployed to organize and analyse the sending of newsletters. Whenever you enter data for the purpose of subscribing to a newsletter (e.g. your e-mail address), the information is stored on Mailchimp servers in the United States.

With the assistance of the Mailchimp tool, we can analyse the performance of our newsletter campaigns. If you open an e-mail that has been sent through the Mailchimp tool, a file that has been integrated into the e-mail (a so-called web-beacon) connects to Mailchimp’s servers in the United States. As a result, it can be determined whether a newsletter message has been opened and which links the recipient possibly clicked on. Technical information is also recorded at that time (e.g. the time of access, the IP address, type of browser and operating system). This information cannot be allocated to the respective newsletter recipient. Their sole purpose is the performance of statistical analyses of newsletter campaigns. The results of such analyses can be used to tailor future newsletters to the interests of their recipients more effectively.

If you do not want to permit an analysis by Mailchimp, you must unsubscribe from the newsletter. We provide a link for you to do this in every newsletter message.

The data is processed based on your consent (Art. 6(1)(a) GDPR). You may revoke any consent you have given at any time by unsubscribing from the newsletter. This shall be without prejudice to the lawfulness of any data processing transactions that have taken place prior to your revocation.

The data deposited with us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter or the newsletter service provider and deleted from the newsletter distribution list after you unsubscribe from the newsletter. Data stored for other purposes with us remain unaffected.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://mailchimp.com/eu-us-data-transfer-statement/ and https://mailchimp.com/legal/data-processing-addendum/#Annex_C_-_Standard_Contractual_Clauses.

After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist, if such action is necessary to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves to comply with the legal requirements when sending newsletters on the basis of Art. 6(1)(e) GDPR in conjunction with Art. 7(3) GDPR. The storage in the blacklist is not limited in time.

For more details, please consult the Data Privacy Policies of Mailchimp at: https://mailchimp.com/legal/terms/.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/7693.

Data processing

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.

Newsletter mailing to existing customers

If you order goods or services from us and enter your e-mail address, this e-mail address may subsequently be used by us to send you newsletters, provided we inform you of this in advance. In such a case, only direct advertising for our own similar goods or services will be sent via the newsletter. You can unsubscribe from this newsletter at any time. There is a corresponding link in every newsletter for this purpose. In this case, the legal basis for sending the newsletter is Art. 6 (1)(f) GDPR in conjunction with Section 7 (3) UWG.

After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist, if such action is necessary to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves to comply with the legal requirements when sending newsletters on the basis of Art. 6(1)(e) GDPR in conjunction with Art. 7(3) GDPR. The storage in the blacklist is not limited in time.

8. Plug-ins and Tools

YouTube with expanded data protection integration

This website integrates videos from the YouTube website. The operator of the website is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of these websites on which YouTube is integrated, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to assign your surfing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.

We use YouTube in extended data protection mode. According to YouTube, videos that are played in extended data protection mode are not used to personalize browsing on YouTube. Ads that are played in extended data protection mode are also not personalized. No cookies are set in extended data protection mode. Instead, so-called local storage elements are stored in the user's browser, which contain personal data similar to cookies and can be used for recognition. Details on the extended data protection mode can be found here: https://support.google.com/youtube/answer/171780.

After activating a YouTube video, further data processing operations may be triggered over which we have no influence.

YouTube is used exclusively on the basis of your consent in accordance with Art. 6(1)(a) GDPR and – insofar as information is accessed in the end device or stored (e.g. device fingerprinting) – on the basis of Section 25 (1) TDDDG. The consent can be revoked at any time.

For more information on how YouTube handles user data, please consult the YouTube Data Privacy Policy under: https://policies.google.com/privacy?hl=en.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5780.

Webfonts by Hoefler & Co.

This page is used for the uniform display of fonts from Hoefler & Co. (The Hoefler Type Foundry, Inc.). The provider is part of Monotype Imaging Holdings Inc. (600 Unicorn Park Drive, Woburn, Massachusetts 01801, USA). When you call up a page, your browser loads the required fonts into your browser cache in order to display texts and fonts correctly.

The use of the externally integrated web fonts of Hoefler & Co. is exclusively on the basis of your consent in accordance with Art. 6(1)(a) GDPR and – insofar as information is accessed in the end device or the storage of information – on the basis of § 25(1) TDDDG.

To do this, the browser you are using must connect to Monotype's servers. This will make Monotype aware that your IP address has been used to access this website. The consent can be revoked at any time.

If your browser does not support Webfonts by Hoefler & Co., a standard font will be used by your computer.

For more information on Webfonts by Hoefler & Co. or Monotype Imaging Holdings Inc., please visit:
https://www.typography.com/policies/privacy and under
https://www.monotype.com/legal/privacy-policy/website-use-privacy-policy,
https://www.monotype.com/legal/privacy-policy

Das Unternehmen verfügt über eine Zertifizierung nach dem „EU-US Data Privacy Framework“ (DPF). Der DPF ist ein Übereinkommen zwischen der Europäischen Union und den USA, der die Einhaltung europäischer Datenschutzstandards bei Datenverarbeitungen in den USA gewährleisten soll. Jedes nach dem DPF zertifizierte Unternehmen verpflichtet sich, diese Datenschutzstandards einzuhalten. Weitere Informationen hierzu erhalten Sie vom Anbieter unter folgendem Link: https://www.dataprivacyframework.gov/participant/6347.

9. eCommerce and payment service providers

Processing of Customer and Contract Data

We collect, process, and use personal customer and contract data for the establishment, content arrangement and modification of our contractual relationships. Data with personal references to the use of this website (usage data) will be collected, processed, and used only if this is necessary to enable the user to use our services or required for billing purposes. The legal basis for these processes is Art. 6(1)(b) GDPR.

The collected customer data shall be deleted upon completion of the order or termination of the business relationship and upon expiration of any existing statutory archiving periods. This shall be without prejudice to any statutory archiving periods.

Data transfer upon closing of contracts for online stores, retailers, and the shipment of merchandise

Orders placed via our online shop are currently only made by e-mail, which you send us. The associated payments are made exclusively in advance. In order to ship your order, we will pass on your personal data to the transport company entrusted with the delivery. Only the data these respective service providers require to meet their obligations will be shared. The legal basis for this sharing is Art. 6 (1)(b) GDPR, which permits the processing of data for the fulfilment of contractual or pre-contractual obligations. If you give us your respective consent pursuant to Art. 6 (1)(a) GDPR, we will share your email address with the transportation company entrusted with the delivery so that this company can notify you on the shipping status for your order via email. You have the option to revoke your consent at any time.

10. Custom Services

Handling applicant data

We offer website visitors the opportunity to submit job applications to us (e.g., via e-mail, via postal services on by submitting the online job application form). Below, we will brief you on the scope, purpose and use of the personal data collected from you in conjunction with the application process. We assure you that the collection, processing, and use of your data will occur in compliance with the applicable data privacy rights and all other statutory provisions and that your data will always be treated as strictly confidential.

Scope and purpose of the collection of data

If you submit a job application to us, we will process any affiliated personal data (e.g., contact and communications data, application documents, notes taken during job interviews, etc.), if they are required to make a decision concerning the establishment or an employment relationship.

The legal basis for the processing in the application process is Art. 6 (1) (e) GDPR in conjunction with § 15 LDSG Baden-Württemberg (processing of personal data of employees). If you have given your consent, the processing will also be carried out on the basis of Art. 6(1)(a) GDPR. The consent can be revoked at any time. Your personal data will only be passed on within our company to persons who are involved in processing your application.

If your job application should result in your recruitment, the data you have submitted will be archived on the grounds of Art. 6(1)(e) GDPR in conjunction with § 15 LDSG Baden-Württemberg (processing of personal data of employees) for the purpose of implementing the employment relationship in our data processing system.

As part of the application process, we may also conduct an internet search on you. This primarily includes Google searches, LinkedIn, and Xing. The legal basis for this type of processing is Art. 6(1)(e) GDPR in conjunction with § 15 LDSG Baden-Württemberg, insofar as this is necessary for an appropriate decision on the establishment of an employment relationship.

Data Archiving Period

If we are unable to make you a job offer or you reject a job offer or withdraw your application, we reserve the right to retain the data you have submitted on the basis of our legitimate interests (Art. 6(1)(f) GDPR) for up to 6 months from the end of the application procedure (rejection or withdrawal of the application). Afterwards the data will be deleted, and the physical application documents will be destroyed. The storage serves in particular as evidence in the event of a legal dispute. If it is evident that the data will be required after the expiry of the 6-month period (e.g., due to an impending or pending legal dispute), deletion will only take place when the purpose for further storage no longer applies.

Longer storage may also take place if you have given your agreement (Article 6(1)(a) GDPR) or if statutory data retention requirements preclude the deletion.

11. Further mandatory information

The information required in accordance with Art. 12 and 13 GDPR on your rights as a data subject, the controller and the contact details of the data protection officer can be found in the general section of this data protection declaration under point 3.

Image and film recordings at events

At events, the Staatliche Kunsthalle Baden-Baden creates image and film recordings of speakers, participants and guests, which are processed for the documentation, follow-up reporting and promotion of museum-relevant content.

Scope and purpose of the collection of data

The recordings are used, among other things, in articles on our homepage, in newsletters, publications, print media and in our social media channels such as Facebook, YouTube and Instagram. You will be informed of this on the website and in the invitations to the events.

The photos and film recordings may also be passed on to media representatives as part of press work.

Legal basis

Data processing is carried out on the basis of Art. 6(1)(e) GDPR (performance of a task in the public interest). It serves public relations, the presentation of the activities of the Staatliche Kunsthalle Baden-Baden and the information of the public about museum-relevant content.

Video surveillance of the Staatliche Kunsthalle Baden-Baden

The properties of the Staatliche Kunsthalle Baden-Baden are under video surveillance in order to safeguard domiciliary rights as well as for the purposes of danger prevention and law enforcement in the interior. All areas within the properties that are under video surveillance are marked by corresponding pictograms with information on the responsible body as well as contact options.

Legal basis and storage time

The processing of personal data is carried out on the basis of Art. 6(1)(e) GDPR in conjunction with § 4 LDSG Baden-Württemberg.

Image recording is fully automated and permanent (24/7). The video stream is stored on internal file servers with separate access restrictions until the available storage capacity is reached; afterwards, the oldest records are automatically overwritten. Due to the quality of the recording, this overwriting cycle usually begins after about 30 days.

The data collected will only be transmitted to law enforcement authorities to the extent that this is necessary in the context of a justified police measure or by judicial order for the purposes mentioned. The transfer of the data is documented. The transmission is usually made to the Baden-Württemberg State Police. There is no further transmission to third parties or an automated comparison with other police information systems.

Monday
Closed
Tuesday
10am - 6pm
Wednesday
10am - 6pm
Thursday
10am - 6pm
Friday
10am - 6pm
Saturday
10am - 6pm
Sunday
10am - 6pm
Adults
10 €
Reduced admission
7 €
School students (aged 9–17)
4 €
Family
18 €
Public guided tour
3 €, plus entrance fee
Public guided tour group
75 €
Shared ticket with Museum Frieder Burda
23 €
Discounted shared ticket with Museum Frieder Burda
17 €
Shared ticket with Museum Frieder Burda Family
49 €
Vocational school students / university students / trainees
People with a severe disability ID card. Free admission for one accompanying person upon presentation of a severe disability ID card marked with “B”.
Job seekers with valid proof
Groups of 15 people or more
Members of the Bundesverband Bildender Künstlerinnen und Künstler (Federal Association of Visual Artists)
Children aged 8 and under
Friends of the Staatlichen Kunsthalle Baden-Baden
Holders of the Landesfamilienpass
Holders of the Museums-Pass-Musées
ICOM Members
Members of the Museumsverband Baden-Württemberg
Members of the Deutschen Museumsbund

NEWSLETTER

Don't miss an event again and find out more about our multi-faceted program. You have taken note of the information on data protection.

STAATLICHE KUNSTHALLE BADEN-BADEN

Lichtentaler Allee 8 a
76530 Baden-Baden
Germany
Phone: +49 7221 300 76 400
E-Mail: info@kunsthalle-baden-baden.bwl.de
            presse@kunsthalle-baden-baden.bwl.de
Phone: +49 7221 300 76 400

CONTACT CAFÉ KUNSTHALLE

Phone: +49 7221 39 20 00
E-Mail: info@cafe-kunsthalle.de