1. General information

The protection of your personal data is important to us. In this privacy policy, we inform you about the processing of personal data when using our online portal to enter and change your fundraising campaign

The online portal for managing your donation data is provided by Wikando GmbH as the operator of FundraisingBox from our customer organizations. The online portal is named individually by the organizations. This declaration applies regardless of this individual designation, as it has no influence on the data processing operations

2. Responsible person

The CEO and the data protection officer of Wikando GmbH are responsible for data processing on this website.

Contact details of the person responsible Wikando GmbH Peter Kral (Geschäftsführer) Schießgrabenstrasse 32 86150 Augsburg Deutschland Phone: +4982190786252 E-Mail: info@fundraisingbox.com

Contact details of the data protection officer Datenschutzberatung Mundanjohl Andreas Mundanjohl Zeller Strasse 30 73101 Aichelberg Deutschland Phone: +4982190782120 E-Mail: datenschutz@wikando.de

3. Collection and storage of personal data and the nature and purpose of their use

a) When visiting the Donor Portal

When you access the Donor Portal ("Portal"), the browser used on your device automatically sends information to the server of our website. This information is temporarily stored in a so-called log file. The following information is collected without any action on your part and stored until it is automatically deleted:

  • IP address of the requesting computer,
  • Date and time of access,
  • Name and URL of the retrieved file,
  • Website from which access is made (referrer URL),
  • the browser used and, if applicable, the operating system of your computer and the name of your access provider.

The specified data is processed by us for the following purposes:

  • Ensuring a smooth connection to the website,
  • Ensuring convenient use of our website,
  • Evaluating system security and stability, and
  • for further administrative purposes.

b) When using the donor data input

Your donation data is automatically transferred to the portal of the organisation where you made your donation. This happens as a result of your donation. Your donation data will not be passed on to or accessed by other organisations. If you donate to more than one organisation that uses the portal updates of your personal data made on one portal will only be present in the same.

  • Last name, first name
  • Contact details (e-mail address, telephone number, address as given in the original form)
  • Active permanent donations
  • Donation amount and frequency
  • Depending on the information and use, data on the means of payment used for the donations. No payment method data for donations for which no payment transaction exists will be processed in the online portal:
  • Paypal login address
  • IBAN
  • Credit card details

This data is processed for the following purposes:

  • Administration and allocation of donations
  • Creation and provision of donation receipts
  • Communication with the donors

Tracking

When using the Donor Portal, we collect certain data in order to improve the user experience and better understand how the portal is used. Data is collected through the implementation of the Mixpanel SDK on both the client and server side. The following information is collected automatically:

  • Device used
  • Browser used
  • Referrer information
  • Libraries used

Cookies and local storage:

The Mixpanel JavaScript library sets a cookie by default. If desired, this can be prevented and storage can be restricted to the local memory of the device.

No collection of geolocation data:

We do not collect geolocation information

Additional data collected:

  • A unique user ID that enables us to assign events to a specific session.
  • The identifier of the organization using the Donor Portal.

Processing of the data

The event data collected is not sent directly to Mixpanel, but is first transmitted to a server operated by us. In this way, we ensure that the IP addresses of users are not transmitted to Mixpanel.

Events recorded:

- `page.view` (page view)

Header

- `header.donate.click` (click on "Donate" in the header)

Footer

- `footer.powered-by.click` (click on "Powered by" in the footer)

Login

- `login.email.submit` (sending the e-mail when logging in)

Dashboard

- `dashboard.edit-personal-data.click` (click on "Edit personal data") - `dashboard.edit-recurring.click` (click on "Edit") - `dashboard.view-donation-receipts.click` (click on "Show all donation receipts") - `dashboard.view-donation-history.click` (click on "Show full donation history") - `dashboard.logout.click` (click on "Logout") - `dashboard.contact.click` (click on "Contact us")

Profile

- `profile.change-personal-data.select` (Selecting "Edit Personal Data") - `profile.change-personal-data.return` (cancel the change of personal data) - `profile.change-personal-data.save` (saving changes to personal data) - `profile.change-email.select` (selection "Edit email") - `profile.change-email.return` (cancel the e-mail change) - `profile.change-email.save` (saving the e-mail change) - `profile.confirmation-code.cancel` (canceling the confirmation code) - `profile.confirmation-code.save` (saving the confirmation code) - `profile.confirmation-code.resend` (resend the confirmation code)

Recurring donations

- `recurring.change-amount.select` (selection "Donation amount") - `recurring.amount-input.change` (change of the amount field) - `recurring.change-amount.apply` (applying the amount change) - `recurring.change-amount.return` (cancel the amount change) - `recurring.change-interval.select` (selection "Change interval") - `recurring.change-interval.apply` (applying the interval change) - `recurring.change-interval.return` (cancel the interval change) - `recurring.changes.save` (saving the changes) - `recurring.unsaved-changes.save` (saving unsaved changes) - `recurring.unsaved-changes.discard` (discard unsaved changes) - `recurring.cancel.click` (click on "Cancel donation") - `recurring.termination.pause` (click on "Pause donation") - `recurring.termination.return ` (canceling the termination) - `recurring.termination.save` (cancel donation now)

Donation receipt

- `donation.receipt.download` (Download the donation receipt) - `donation.receipt.request` (requesting a donation receipt)

Contact us

- `contact.message.send` (sending a message via the contact form) This information helps us to further improve the portal and respond to the needs of our users. Of course, we always pay attention to the protection of your data and compliance with the statutory data protection regulations.

The data is processed via the FundraisingBox services. The FundraisingBox privacy policy for customers, contractual partners and interested parties can be accessed here.

4. Disclosure of data

Your personal data will not be transferred to third parties for purposes other than those listed below.

We only pass on your personal data to third parties if:

  • you have given your express consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR,
  • the disclosure pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR is necessary for the assertion, exercise or defence of legal claims and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data,
  • in the event that there is a legal obligation for disclosure pursuant to Art. 6 para. 1 sentence 1 lit. c GDPR, and
  • This is legally permissible and necessary for the processing of contractual relationships with you in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR.

5. Rights of data subjects

You have the right:

  • to request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, and the existence of automated decision-making including profiling and, if applicable, meaningful information about its details;
  • in accordance with Art. 16 GDPR, to immediately request the correction of incorrect or incomplete personal data stored by us;
  • in accordance with Art. 17 GDPR, to demand the deletion of your personal data stored by us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
  • in accordance with Art. 18 GDPR, to demand the restriction of the processing of your personal data, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you refuse to delete it and we no longer need the data, but you need it to assert, exercise or defend legal claims or you have objected to the processing in accordance with Art. 21 GDPR;
  • in accordance with Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller
  • in accordance with Art. 7 para. 3 GDPR, to revoke your consent once given to us at any time. The consequence of this is that we may no longer continue the data processing that was based on this consent in the future and
  • to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.

6. Right of objection

If your personal data is processed on the basis of legitimate interests in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right to object to the processing of your personal data in accordance with Art. 21 GDPR, provided that there are reasons for this arising from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right to object, which will be implemented by us without specifying a particular situation.

If you wish to exercise your right of revocation or objection, simply send an e-mail to datenschutz@wikando.de.

7. Data security

We use the widespread SSL (Secure Socket Layer) method in conjunction with the highest level of encryption supported by your browser when you visit our website. As a rule, this is 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can tell whether an individual page of our website is transmitted in encrypted form by the closed display of the key or lock symbol in the lower status bar of your browser.

The currently applicable technical and organisational measures can be viewed at https://fundraisingbox.com/en/privacy/technical-and-organizational-measures/ . If there are any changes to the technical and organisational measures (which may not result in a deterioration in the level of data protection), the controller will be informed of this with a notice period of 4 weeks. All versions are also available in their previous version under the above link to the technical and organisational measures.

8.Topicality and amendment of this privacy policy

This privacy policy is currently valid and is dated 25.07.2024. It may become necessary to amend this privacy policy as a result of the further development of our website and services or due to changes in legal or regulatory requirements. The current privacy policy can be accessed at any time in the portal.