Data protection
Privacy Policy
Personal data (usually referred to just as "data" below) will only be processed by us to the extent necessary for providing a functional and user-friendly website, including its contents, and the services offered there, and in accordance with the General Data Protection Regulation (EU) 2016/670 ("GDPR").
The following privacy policy is intended to inform you in particular about the type, scope, purpose, duration, and legal basis for the processing of such data either under our control or in conjunction with others. We also inform you below about the third-party components we use to optimize our website and improve the user experience which may result in said third parties also processing data they collect and control.
Our privacy policy is structured as follows:
I. Information about us as controllers of your data
II. What are your rights?
III. How do we collect your data?
IV. What data do we collect and how do we use it?
V. How long do we store your data?
VI. Where do we process your data?
VII. Who do we share your data with?
VIII. How do we protect your data?
IX. Cookie Notice
X. Changes to this privacy policy
I. INFORMATION ABOUT US AS CONTROLLERS OF YOUR DATA
The party responsible for this website (the "controller") for purposes of data protection law is:
Advanced Therapies in Orthopaedics Foundation
c/o Prof. Dr. Tobias Winkler
Charité – Universitätsmedizin Berlin
BIH - Julius Wolff Institut für Biomechanik und Muskuloskeletale Regeneration
Campus Virchow-Klinikum
Cranach Haus
Augustenburger Platz 1
13353 Berlin
The controller's data protection officer is:
Advanced Therapies in Orthopaedics Foundation
c/o Prof. Dr. Tobias Winkler
Charité – Universitätsmedizin Berlin
BIH - Julius Wolff Institut für Biomechanik und Muskuloskeletale Regeneration
Campus Virchow-Klinikum
Cranach Haus
Augustenburger Platz 1
13353 Berlin
II. WHAT ARE YOUR RIGHTS?
With regard to the processing of your data, you have the right:
- to obtain information about whether your data is being processed, in particular, you have the right to request copies of the data we hold about you (cf. also Art. 15 GDPR);
- to correct or complete incorrect or incomplete data (cf. also Art. 16 GDPR);
- to have your data deleted (cf. also Art. 17 DSGVO), or, alternatively, if further processing is necessary as stipulated in Art. 17 Para. 3 GDPR, to restrict such processing per Art. 18 GDPR;
- to receive copies of your data in a structured, commonly used machine-readable format and have it transmitted to other providers/controllers (cf. also Art. 20 GDPR); and
- to file complaints with the supervisory authority if you believe that data concerning you is being processed by us in breach of data protection provisions (see also Art. 77 GDPR).
In addition, we will inform all recipients to whom we disclose data of any such corrections, deletions, or restrictions placed on processing as per Art. 16, 17 Para. 1, 18 GDPR. This does not apply if such notification is impossible or involves a disproportionate effort. Nevertheless, you have a right to information about these recipients. Likewise, under Art. 21 GDPR, you have the right to object to our future processing of your data according to Art. 6 Para. 1 lit. f) GDPR. In particular, you can object to data processing for direct marketing purposes including profiling related to it.
For any of the above requests, please send a description of the data concerned and appropriate proof of identity to the contact details in Part I. We may require additional proof of identity to protect your data against unauthorized access. We will carefully consider the request and may discuss how it can best be fulfilled.
If you have any concerns about how data is handled by us or wish to raise a complaint about how we have handled data, you can contact us at the contact details in Part I to have the matter investigated. If you are not satisfied with our response or believe we are processing your personal data not in accordance with the law you can complain to the competent data protection supervisory authority in your country.
III. How do we collect your data?
We may collect your data in various ways, including:
- Directly from you when you interact with us (e.g., when you voluntarily submit information to our website, submit your job application, or when you submit an enquiry through our contact form);
- Indirectly from other sources (e.g. by your internet browser); or
- Automatic collection tools (e.g. cookies and other analytics or tracking technology may be used to collect certain information as set out above when you visit our website located or third party sites we direct you to, or access to communicate with you about our services). For more information on our automatic collection tools please refer to our Cookie Notice in Part IX.
IV. What data do we collect and how do we use it?
Depending on the nature of our relationship, we may collect and process the following types of data for the following purposes ("Permitted Purposes"). We have set out the legal basis we rely on and the retention period for each Permitted Purpose.
If you have given us your consent for the processing of your personal data, you may withdraw your consent at any time with future effect, i.e. the withdrawal of the consent does not affect the lawfulness of processing based on the consent before its withdrawal. If you withdraw your consent, we will only continue processing your personal information where there is another legal ground or where we are legally required to do so.
Where your explicit permission is required for any marketing-related communication, we will only provide you with such information if you have opted in. You may opt-out at any time if you do not want to receive any further marketing-related types of communication from us. We will not use your personal data to taking any automated decisions affecting you or creating profiles.
Permitted Purpose |
Types of Data Collected |
Legal Basis |
Website security: to ensure our website is secure and stable |
Server Data: type and version of your browser, operating system, the website from which you came (referrer URL), the webpages on our site visited, the date and time of your visit, IP address from which you visited our site |
Our legitimate interest to improve our website and to ensure its stability, functionality and security; Art. 6 (1)(f) GDPR |
Order processing: to fulfil your order |
Shipping details: name, address, shipping address, phone number, email address, order number |
To fulfil your contract with us; Art. 6 (1)(b) GDPR |
Customer account/registration: to register an account for you on our website and to provide you with our services, to fulfil your orders or contracts, and provide customer care |
Account details: name, address, email address, phone number, IP address, date and time of registration |
Your consent; Art. 6 (1)(a) GDPR To lead to the initiation of a contractual relationship with us or to fulfil your contract with us; Art 6(1)(b) |
Newsletters: to send you our free newsletters and optimize our newsletter and respond to the wishes of our readers. |
Subscription data: email address, name and address, computer hardware, IP address and date and time of registration |
Your consent; Art. 6 (1)(a) GDPR |
Contact: to answer inquiries that you have submitted to us via email or on our contact form |
Inquiry data: name, email data contained within the inquiry (e.g. health data), address, phone (if applicable) |
To lead to the initiation of a contractual relationship with us or to fulfil your contract with us; Art. 6 (1)(b) GDPR |
User questions, answers, comments, and ratings (Posts): to publish your Posts on our website. |
Post data: date and time of your post, a pseudonym used, IP address and email address |
Your consent; Art. 6 (1)(a) GDPR Our legitimate interest to take action if your post infringes the rights of third parties and/or is otherwise unlawful; Art. 6 (1)(f) GDPR |
Online job applications/publication of job advertisements: to process your application. If you are hired, the data will be stored in your personnel file for usual organizational and administrative processes and to comply with legal obligations. If you are not hired, we may store for legal reasons such as evidence of equal treatment of applicants. |
Job application data: name, address, email, phone number, work experience, photographic identification, gender, date of birth, title, marital status, academic and professional qualifications, dates of study, nationality, visa status, language skills, interests, data provided by your referees, equal opportunities, ethnic origin, criminal offence data, |
Your consent; Art. 6 (1)(a) GDPR To comply with our legal obligations; Art 6(1)(c) To establish, exercise and defend legal claims: Art. 6(1)(f) Processing in the employment context; Art 88(1) GDPR
|
Twitter presence: to maintain our online presence on Twitter to present our company and our services, and to communicate with (prospective) customers. Twitter is a service provided by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. |
Please see Twitter's privacy policy here: |
Our legitimate interest to maintain a Twitter presence and communicate with customers; Art. 6(1)(f) |
Youtube presence: to maintain our online presence on Youtube to present our company and our services, and to communicate with (prospective) customers. |
Please see Youtube's privacy policy here: |
Our legitimate interest to maintain a Youtube presence and communicate with customers; Art. 6(1)(f) |
LinkedIn presence: to maintain our online presence on LinkedIn to present our company and our services, and to communicate with (prospective) customers. |
Please see LinkedIn's privacy policy here: |
Our legitimate interest to maintain a LinkedIn presence and communicate with customers; Art. 6(1)(f) |
LinkedIn PlugIn: to improve the quality of our website For further information, see Part VII below |
Please see LinkedIn's privacy policy here: |
Our legitimate interest to improve the quality of our website; Art. 6(1)(f) |
Twitter PlugIn: to improve the quality of our website For further information, see Part VII below |
Please see Twitter's privacy policy here: |
Our legitimate interest to improve the quality of our website; Art. 6(1)(f) |
Google Analytics: to analyse visits to our website and how our website is used. For further information, see Part VII below |
Please see Google's privacy policy here: https://policies.google.com/technologies/partner-sites?hl=de |
Your consent; Art. 6(1)(a) |
Google Maps: to display our location and provide directions For further information, see Part VII below |
Please see Google's privacy policy here: https://policies.google.com/technologies/partner-sites?hl=de |
Our legitimate interest to optimise the functionality of our website; Art. 6(1)(f) |
FontAwesome: to display fonts and visual elements of our website For further information, see Part VII below |
Please see Font.com's privacy policy here: |
Our legitimate interest to optimise the functionality of our website; Art. 6(1)(f) |
V. How long do we store your data?
We will hold your personal data as long as required to provide you with the products, services or information you have requested and to execute and administer your relationship with us. If you have asked us not to communicate with you, we will hold this information as long as required to comply with your request. We are also required to keep certain of your personal data (e.g. relating to business or tax-relevant transactions) for certain retention periods under applicable law. Your personal data will be promptly deleted when it is no longer required for these purposes.
VI. Where do we process your data?
In the course of our activities, we may engage service providers outside of the European Economic Area, in which applicable laws do not offer the same level of data protection as the laws of your home country. Where this is the case, we take appropriate safeguards to ensure the security and integrity of your personal data to ensure that your data is as protected as it is in the European Economic Area, in particular by entering into the EU Standard Contractual Clauses which are available here. If you would like more information about these security measures, please contact us at any time using the contact details in Part I.
VII. Who do we share your data with?
We may share your personal data as follows:
- Service providers who we engage to process personal data for the Permitted Purposes on our behalf and in accordance with our instructions only. We will retain control over and will remain fully responsible for your personal data and will use appropriate safeguards as required by the applicable law to ensure the integrity and security of your personal data when engaging such service providers;
- Courts, regulators, law enforcement or other competent authorities or legal advisors if legally permitted and necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims; and
- We may also share your personal data with third parties if we sell or buy any business or assets, in which case we may disclose personal data to the prospective seller or buyer of such business or assets, along with its professional advisers. If substantially all of our assets are acquired by a third party, personal data held by us about customers and other contacts will be one of the transferred assets.
Otherwise, we will only disclose your personal data when you direct or give us permission, when we are required by applicable law or regulations or judicial or official request to do so, or when we suspect fraudulent or criminal activities.
Please see below for a summary of the service providers and the services provided:
Social media links via graphics
We also integrate the following social media sites into our website. The integration takes place via a linked graphic of the respective site. The use of these graphics stored on our servers prevents the automatic connection to the servers of these networks for their display. Only by clicking on the corresponding graphic will you be forwarded to the service of the respective social network.
Once you click, that network may record information about you and your visit to our site. It cannot be ruled out that such data will be processed in the United States.
Initially, this data includes such things as your IP address, the date and time of your visit, and the page visited. If you are logged into your user account on that network, however, the network operator might assign the information collected about your visit to our site to your personal account. If you interact by clicking Like, Share, etc., this information can be stored in your personal user account and possibly posted on the respective network. To prevent this, you need to log out of your social media account before clicking on the graphic. The various social media networks also offer settings that you can configure accordingly.
The following social networks are integrated into our site by linked graphics:
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Irland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085 USA.
For further information, please see LinkedIn's Privacy Policy.
Twitter plug-in
Our website uses a Twitter plug-in. The Twitter service is operated by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA ("Twitter"). If the plug-in is stored on one of the pages you visit on our website, your browser will download an icon for the plug-in from Twitter's servers in the USA. For technical reasons, Twitter must process your IP address. In addition, the date and time of your visit to our website will also be recorded.
If you are logged in to Twitter while visiting one of our plugged-in websites, the information collected by the plug-in from your specific visit will be recognized by Twitter. The information collected may then be assigned to your personal account on Twitter. If, for example, you use the Twitter Tweet button, this information will be stored in your Twitter account and may be published on the Twitter platform. To prevent this, you must either log out of Twitter before visiting our site or make the appropriate settings in your Twitter account.
For further information, please see Twitter's Privacy Policy.
Google Analytics
We use Google Analytics on our website. This is a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Usage and user-related information, such as IP address, place, time, or frequency of your visits to our website will be transmitted to a Google server in the United States and stored there. However, we use Google Analytics with the so-called anonymization function, whereby Google truncates the IP address within the EU or the EEA before it is transmitted to the US.
Google may also transfer this information to third parties where required to do so by law or where such third parties process this data on Google’s behalf. Google states that it will not associate your IP address with other data held by it.
You can prevent cookies from being installed by Google Analytics by downloading and installing on your web browser: Google Analytics Opt-out Browser Add-on
The add-on informs Google Analytics' JavaScript (ga.js) that no information about the website visit should be transmitted to Google Analytics. However, this does not prevent information from being transmitted to us or to other web analytics services we may use as detailed herein.
For further information, please also see Google's Privacy Policy.
Google-Maps
Our website uses Google Maps to display our location and to provide directions. This is a service provided by Google.
To enable the display of certain fonts on our website, a connection to the Google server in the USA is established whenever our website is accessed.
If you access the Google Maps components integrated into our website, Google will store a cookie on your device via your browser. Your user settings and data are processed to display our location and create a route description. We cannot prevent Google from using servers in the USA.
By connecting to Google in this way, Google can determine from which website your request has been sent and to which IP address the directions are transmitted.
If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. Further details can be found in the section about cookies above.
In addition, the use of Google Maps and the information obtained via Google Maps is governed by the Google Terms of Use and the Terms and Conditions for Google Maps.
For further information, please also see Google's Privacy Policy.
FontAwesome
To be able to display fonts and visual elements of our website, we use font.com external fonts. Font.com is a service of Monotype,600 Unicorn Park Drive, Woburn, MA 01801
When you access our website, a connection is established to the FontAwesome server in the USA to enable and update the display of fonts and visual elements.
By connecting to the FontAwesome server when you access our website, Font.com can determine from which website your request was sent and to which IP address the font should be sent.
For further information, please see Font.com's Privacy Policy.
MailChimp - Newsletter
We offer you the opportunity to register for our free newsletter via our website.
We use MailChimp, a service of The Rocket Science Group, LLC, 512 Means Street, Suite 404, Atlanta, GA 30318, USA, hereinafter referred to as "The Rocket Science Group".
If you register for our free newsletter, the data requested from you for this purpose will be processed by The Rocket Science Group. During the registration process, your consent to receive this newsletter will be obtained together with a concrete description of the type of content it will offer and a reference made to this privacy policy.
The newsletter then sent out by The Rocket Science Group will also contain a tracking pixel called a web beacon. This pixel helps us evaluate whether and when you have read our newsletter and whether you have clicked any links contained therein.
For further information, please see Rocket Science Group's Privacy Policy.
VIII. How do we protect your data?
We maintain physical, electronic and procedural safeguards in accordance with the technical state-of-the-art and legal data protection requirements to protect your personal data from unauthorized access or intrusion. These safeguards include implementing specific technologies and procedures designed to protect your privacy, such as secure servers, firewalls and SSL encryption. We will at all times strictly comply with applicable laws and regulations regarding the confidentiality and security of personal data.
IX. Cookie Notice
We use cookies on our website. Cookies are small text files or other storage technologies stored on your computer by your browser. These cookies process certain specific information about you, such as your browser, location data, or IP address.
a) Cookie Types
Essential cookies
These cookies are essential for our website to work properly for you. These cookies ensure the security, safety, integrity and operation of our website. This includes cookies that enable you to log onto secure areas of our website.
The legal basis for such processing is to provide you with the services that you have requested (Art. 6 Para. 1 lit. b) GDPR) and our legitimate interest to operate our website (Art. 6 Para. 1 lit. f) GDPR).
Analytical cookies
Our website may use cookies from companies with whom we cooperate for the purpose of analyzing and improving our website. These cookies allow us to count visits, know which pages are the most and least popular and see how users move around the site. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
The legal basis for such processing is your consent (Art. 6 Para. 1 lit. a) GDPR).
Advertising cookies
Our website may use cookies from companies with whom we cooperate for the purpose of advertising. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests.
The legal basis for such processing is your consent (Art. 6 Para. 1 lit. a) GDPR).
b) Customising cookies
Within the Cookie Preferences, you can choose which analytical and advertising cookies we can set by clicking on the button(s) on the bottom right corner of the screen.
c) Blocking cookies
You can refuse the use of cookies (including essential cookies) by changing the settings on your browser. Likewise, you can use the browser to delete cookies that have already been stored. Guidance on how to block and delete cookies for common browsers is linked below.
Browser settings cannot prevent so-called flash cookies from being set. Instead, you will need to change the setting of your Flash player. The steps and measures required for this also depend on the Flash player you are using. If you have any questions, please use the help function or consult the documentation for your Flash player or contact its maker for support.
If you prevent or restrict the installation of cookies, not all of the functions on our site may work.
d) Further details on cookies we use
Cookie Name |
Cookie Type |
Purpose |
More Information |
cookie-agreed |
Session |
Saves state if the user allowed cookies or not |
Expiry: 100 days |
X. CHANGES TO THIS PRIVACY POLICY
This Privacy Policy was last updated on 03.03.2023. From time to time, we may make changes or amend it as required to reflect any changes to the way in which we use your personal data or changing legal requirements. So you may wish to check back from time to time or whenever you make available personal data to us. Any amended Privacy Policy will apply from the date it is posted on our website.