Foreword
We, the German Red Cross (DRK General Secretariat), as organiser of the Global Dialogue Platform on Anticipatory Action and operator of the associated event website, hereinafter referred to as "the organisation," "we," or "us," take the protection of your personal data seriously and would like to inform you about data protection in connection with your registration for and participation in the event and your visit to the event website.
As per the European Union General Data Protection Regulation (Regulation (EU) 2016/679; henceforth referred to as "GDPR"), there exist obligations to safeguard the personal data of individuals affected by processing (hereinafter addressed as the "participant," "user," "you," "yours," or "data subject").
Our privacy policy is organised into modules. It comprises a general section applicable to any processing of personal data (Part A. General) and specific sections whose content pertains solely to the indicated processing situation – in particular your participation in the event and your visit to the event website, the tools used, image and video recordings, and social media plugins.
A. General
1. Definitions
Following the guidelines outlined in Article 4 of the General Data Protection Regulation (GDPR), the privacy policy provided herein is based on the following definitions:
"Personal Data" (Art. 4 No. 1 GDPR): All information pertaining to an identified or identifiable natural person, commonly referred to as the "data subject."
"Processing" (Art. 4 No. 2 GDPR): Any operation or set of operations carried out on personal data, encompassing collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
"Controller" (Art. 4 No. 7 GDPR): The individual, authority, or entity responsible for determining the purposes and means of processing personal data.
"Third Party" (Art. 4 No. 8 GDPR): Any person, authority, or entity excluding the data subject, the controller, and the processor.
"Consent" (Art. 4 No. 11 GDPR): Voluntary, informed, and unambiguous expression of the data subject’s will regarding the processing of their personal data.
2. Name and Address of the Controller Responsible for Processing
We, the German Red Cross, act as the entity responsible for processing your personal data in accordance with Article 4 No. 7 GDPR. You can contact us at:
Deutsches Rotes Kreuz e.V.
DRK-Generalsekretariat
Carstennstraße 58
12205 Berlin
Phone: 030 / 85404 – 0
E-Mail: drk@drk.de
The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g. names, e-mail addresses, etc.). For additional information concerning our organization, please refer to the legal notice (Imprint) on the event website.
3. Contact Details of the Data Protection Officer
Our company data protection officer is available at all times to answer any questions you may have and to act as your contact person on the subject of data protection. Their contact details are:
R2Data GmbH
Scanbox 18556
Ehrenbergstraße 16a
10245 Berlin
Datenschutz@r2data.de
4. Legal Basis for Data Processing
By law, the general principle is that the processing of personal data is prohibited, and it is only permitted when the data processing falls under one of the following legal justifications:
Art. 6 para. 1 sentence 1 lit. a GDPR ("Consent"): If the data subject has voluntarily, informed, and unequivocally consented to the processing of their personal data for one or more specific purposes.
Art. 6 para. 1 sentence 1 lit. b GDPR: If the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures requested by the data subject.
Art. 6 para. 1 sentence 1 lit. c GDPR: If the processing is necessary for compliance with a legal obligation to which the controller is subject.
Art. 6 para. 1 sentence 1 lit. e GDPR: If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
Art. 6 para. 1 sentence 1 lit. d GDPR: If the processing is necessary to protect the vital interests of the data subject or another natural person.
Art. 6 para. 1 sentence 1 lit. f GDPR ("Legitimate Interest"): If the processing is necessary for the protection of legitimate interests of the controller or a third party, unless the overriding interests or rights of the data subject prevail.
Insofar as personal data of employees of the DRK is processed, § 26 BDSG serves as the legal basis. For the processing operations we carry out, we indicate the applicable legal basis in each case below. Processing can also be based on several legal bases. If you have consented to the storage of cookies or access to information in your end device (e.g. via device fingerprinting), the data processing is also carried out on the basis of § 25 (1) TDDDG (Telecommunications Digital Services Data Protection Act, which superseded the TTDSG). Consent can be revoked at any time.
5. Data Erasure and Storage Duration
For the processing operations carried out by us, we indicate below how long the data will be stored by us and when it will be deleted or blocked. Unless a more specific storage period is specified below, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g. tax or commercial law retention periods, such as § 257 HGB or § 147 AO); in the latter case, the deletion will take place after these reasons cease to apply.
6. Data Security (SSL / TLS encryption)
We use suitable technical and organisational measures to protect your data from manipulation, loss, destruction or unauthorised access by third parties. For security reasons and to protect the transmission of confidential content, such as inquiries you submit to us as the website operator, this website uses SSL or TLS encryption. You can recognise an encrypted connection by checking whether the address line of the browser switches from "http://" to "https://" and by the lock icon in the browser line. If SSL or TLS encryption is activated, data you transmit to us cannot be read by third parties.
Please note that the transmission of data via the Internet (e.g. through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.
7. Cooperation with Contract Processors
We use external domestic and foreign service providers to process our business transactions (e.g. for IT, hosting, streaming, video conferencing and communication). These service providers only act in accordance with our instructions and are contractually obliged to comply with data protection regulations in accordance with Art. 28 GDPR.
8. Requirements for the Transfer of Personal Data to Third Countries
As part of the operation of the event, your personal data may be transferred or disclosed to third-party companies which may also be located outside the EEA, i.e. in third countries. Such processing takes place exclusively to fulfil contractual and business obligations. We will inform you about the respective details of the transfer at the relevant points below.
The European Commission certifies that some third countries have data protection standards comparable to the EEA standard by means of so-called adequacy decisions (a list of these countries and a copy of the adequacy decisions can be found here: commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en).
Where personal data is transferred to third countries without an adequate level of protection, we ensure adequate safeguards, in particular through the standard contractual clauses of the European Commission.
Information on data transfer to the USA in particular
The event uses services provided by companies based in the United States. When these services are used, personal data may be transferred to and processed in the United States. On 10 July 2023, the European Commission adopted an adequacy decision for the EU-U.S. Data Privacy Framework (EU-U.S. DPF). Where a U.S. recipient is certified under the EU-U.S. DPF and the relevant transfer is covered by the adequacy decision, the transfer may be based on Art. 45 GDPR. Where the EU-U.S. DPF does not apply, we ensure that another lawful transfer mechanism and appropriate safeguards are in place, in particular the European Commission's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, where applicable. Further information on the applicable transfer mechanism is provided below for the individual services.
9. No Automated Decision-Making (including profiling)
We do not use automated decision-making within the meaning of Art. 22 GDPR (including profiling) for personal data collected from you.
10. No Obligation to Provide Personal Data
As a participant, you are under no legal or contractual obligation to provide us with your personal data; however, certain data (in particular the registration data marked as mandatory) is required in order to register for and participate in the event. If you do not provide this data, participation may not be possible or only possible to a limited extent.
11. Legal Obligation to Transmit Certain Data
Under certain circumstances, we may be subject to a specific legal or statutory obligation to provide the lawfully processed personal data to third parties, in particular public authorities (Art. 6 para. 1 sentence 1 lit. c GDPR).
12. Your Rights
You can assert your rights as a data subject with regard to your processed personal data at any time by contacting us using the contact details provided under A. (2). As the data subject, you have the right:
in accordance with Art. 15 GDPR, to request information about your data processed by us, in particular the purposes of processing, the categories of data and recipients, the planned storage period, and the origin of your data;
in accordance with Art. 16 GDPR, to request the correction of incorrect data or the completion of your data stored by us;
in accordance with Art. 17 GDPR, to demand the erasure of your data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
in accordance with Art. 18 GDPR, to demand the restriction of the processing of your data if the accuracy of the data is disputed by you or the processing is unlawful;
in accordance with Art. 20 GDPR, to receive your data in a structured, commonly used and machine-readable format ("data portability"), where technically feasible;
in accordance with Art. 21 GDPR, the right to object to the collection of data in special cases and to direct marketing, provided that the processing is carried out on the basis of Art. 6 para. 1 sentence 1 lit. e or lit. f GDPR;
in accordance with Art. 7 (3) GDPR, to withdraw your consent once given at any time, with effect for the future; and
in accordance with Art. 77 GDPR, to complain to a data protection supervisory authority, in particular in the member state of your domicile, place of work or the place of the alleged violation.
Rejection of unsolicited e-mails
We herewith object to the use of contact information published in conjunction with the mandatory information in our Imprint to send us promotional and information material that we have not expressly requested. The operators of this website reserve the express right to take legal action in the event of the unsolicited sending of promotional information, for instance via SPAM messages.
13. Changes to the Privacy Policy
We will revise this privacy policy in the event of changes in data processing or other occasions that make this necessary, in particular to reflect the further development of data protection law or technological or organisational changes. You will always find the current version on the event website.
B. Participation in the Event and Visiting the Website
When you register for and participate in the event and when you visit the event website, the following categories of personal data may be collected, stored and processed by us:
1. Data Processing, Purpose and Legal Basis
Registration for the event
When you register for the Dialogue Platform, we collect and process the following registration data:
Salutation
First name
Last name
E-mail address
Organization / Institution
Position of work
Region
Country
In addition, during participation in the event we may process content you actively provide, such as chat messages and materials shared in the event environment. These data are participation data and are not part of the registration data.
We process the registration data in order to administer your registration and participation and to run the event. The legal basis is Art. 6 para. 1 lit. b GDPR. If you separately agree to receive invitations to future Global Dialogue Platforms beyond the event and its directly related follow-up activities, the legal basis for that additional use is your consent pursuant to Art. 6 para. 1 lit. a GDPR. Consent can be withdrawn at any time with effect for the future.
Chat function in the login area
In the protected login area of the event website (only visible to registered participants), you will find a chat function. The chat history will be saved and will remain available to registered participants for information purposes and to the organiser for logging purposes. This data will be archived after one year, unless you explicitly request the deletion of your data. The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in the exchange between participants and in logging).
Server Log Files ("log data")
The provider of the event website automatically collects and stores information in so-called server log files, which your browser communicates to us automatically. This consists of:
the type and version of browser used
the operating system used
the referrer URL
the hostname of the accessing computer
the time of the server inquiry
the IP address
This data is not merged with other data sources. It is processed for the technically error-free depiction and optimisation of the website. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR.
2. Duration of Data Processing
Registration and participation data are retained only for as long as necessary to organise, conduct and conclude the Global Dialogue Platform, including directly related follow-up sessions, participant surveys, and event-related communications, and are then deleted or anonymised unless statutory retention obligations or another legal basis require longer storage. Data processed on the basis of separate consent for invitations to future Global Dialogue Platforms may be retained until that consent is withdrawn or the purpose no longer applies.
The event will be supported by a donor, and the DRK is obliged to provide evidence of the proper use of funds. The donor may, for example, require the submission of lists of participants. These will be destroyed after the retention period.
The chat history in the login area will be archived after one year unless you explicitly request deletion. Archived image and sound recordings of the event as well as publications will generally not be deleted (see Part D).
3. Transfer of Personal Data to Third Parties; Legal Basis
For the purpose of coordinating invitations and planning sessions, we may share your name, professional affiliation and e-mail address with the organising partners of the event as listed in the Concept Note. The legal basis is Art. 6 para. 1 lit. f GDPR (our legitimate interest in the efficient joint organisation of the event). You have the right to object to processing based on Art. 6 para. 1 lit. f GDPR on grounds relating to your particular situation (Art. 21 GDPR). Where separate consent is requested for a specific disclosure or purpose, Art. 6 para. 1 lit. a GDPR applies.
In addition, participant lists may be transferred to the donor for the purpose of providing evidence of the proper use of funds (Art. 6 para. 1 lit. c and lit. f GDPR). Further recipients may be processors that support the operation of the event website and the tools used (see Part C). Beyond this, we only pass on your personal data to third parties if you have given your express consent (Art. 6 para. 1 sentence 1 lit. a GDPR) or if this is necessary on the basis of the contract with you (Art. 6 para. 1 lit. b GDPR).
4. Hosting and Content Delivery Networks (CDN)
The event website is hosted by an external service provider (host). Personal data collected on this website is stored on the servers of the host. This may include, but is not limited to, IP addresses, contact requests, metadata and communications, contract and contact information, names, website access data, and other data generated through a website.
The website is operated on our behalf by storytile GmbH (Imprint: storytile.net/impressum; privacy policy: storytile.net/datenschutzerklaerung). The host is used for the purpose of fulfilling the contract with our participants (Art. 6 para. 1 lit. b GDPR) and in the interest of secure, fast and efficient provision of our online services by a professional provider (Art. 6 para. 1 lit. f GDPR). Our host will only process your data to the extent necessary to fulfil its performance obligations and to follow our instructions.
Contract processing
In order to guarantee processing in compliance with data protection regulations, we have concluded an order processing agreement (DPA) with our host.
C. Use of Cookies, Plugins and Other Services on our Website
1. General: Cookies and comparable technologies
Our websites and pages use what the industry refers to as "cookies." Cookies are small text files that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently archived on your device (permanent cookies). Session cookies are automatically deleted once you terminate your visit; permanent cookies remain archived on your device until you actively delete them or they are automatically eradicated by your web browser. In some cases, third-party cookies may be stored on your device once you enter our site.
Cookies and comparable technologies that are strictly necessary to provide a service expressly requested by you may be used without consent where the requirements of § 25 (2) TDDDG are met; related processing of personal data is based on the applicable GDPR legal basis, in particular Art. 6 para. 1 lit. f GDPR where appropriate. Non-essential technologies, including technologies used for optional embedded content or similar functions, are used only after consent where required. In that case, access to or storage of information on your end device is based on § 25 (1) TDDDG and subsequent processing of personal data on Art. 6 para. 1 lit. a GDPR. Consent can be withdrawn at any time with effect for the future.
You can set your browser so that you are notified about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.
2. Statistical Analysis
No personal data is collected for statistical purposes. Only the number of logins per participant is collected for technical reasons in order to detect misuse. Google Analytics is not used.
3. Cookies, Plugins and Other Third-Party Services
The following interactive tools are used to run the event and to enable exchange during sessions. Some tools (e.g. survey and collaboration tools such as Mentimeter, Etherpad, Padlet, Miro or Slido) are only activated when you use them; your contributions in these tools may be and remain partially publicly visible. We have no influence on whether and to what extent the respective provider processes personal data after activation. If you do not agree with the terms of use of a provider, you have the alternative option of not using the tool and instead participating in the online workshop as a viewer.
1) Zoom (Video conferencing, streaming and Q&A)
Provider: Zoom Video Communications, Inc. (USA). Responsible for the data processing directly related to the implementation of "online meetings" is the DRK.
Purpose: Conducting video conferences and online meetings; streaming of panel discussions, lectures and workshops (recorded and published on the event page afterwards); enabling participants to ask questions via audio or video on request (you consent by activating the respective button).
Legal basis: Art. 6 para. 1 lit. b GDPR where meetings are conducted within the framework of contractual relationships; otherwise Art. 6 para. 1 lit. f GDPR (legitimate interest in the effective implementation of online meetings); § 26 BDSG where personal data of DRK employees is processed. Automated decision-making within the meaning of Art. 22 GDPR is not used.
Data processed: User data (first name, last name, e-mail address; optionally telephone, password, profile picture, department); meeting metadata (topic, optional description, participant IP addresses, device/hardware information); optional recordings (MP4 video/audio/presentation, M4A audio, text file of the meeting chat); phone dial-in data (incoming/outgoing number, country name, start and end time, where applicable device IP address); text, audio and video data from chat, question and survey functions and from your microphone/camera.
Recipients / third-country transfer: Zoom Video Communications, Inc. is based in the USA. Personal data may therefore be processed in the United States. Where Zoom is certified under the EU-U.S. Data Privacy Framework and the relevant transfer is covered by the adequacy decision, the transfer may be based on Art. 45 GDPR. Where this does not apply, appropriate safeguards such as the European Commission's Standard Contractual Clauses pursuant to Art. 46 GDPR are used where applicable. A data processing agreement meeting the requirements of Art. 28 GDPR has been concluded.
Retention period: If you are registered as a user, reports on online meetings (meeting metadata, telephone dial-in data, webinar questions and answers, survey results) can be stored with the provider for up to one month.
Further information: https://www.zoom.com/en/trust/privacy/privacy-statement/
2) YouTube (Embedded videos)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Embedding of videos that are not stored on our servers, in the interest of making our site appealing and informative. When you access pages with embedded videos, content is downloaded from the provider, which is thereby informed that you have visited our site.
Legal basis: Embedded YouTube content is activated only after your consent where the embedding involves access to or storage of information on your end device. In that case, the legal basis is § 25 (1) TDDDG and Art. 6 para. 1 lit. a GDPR. Consent can be withdrawn at any time with effect for the future.
Data processed: The usage data technically required to deliver the video; the provider is informed that you have called up our site. If you are logged into your account, your visit may be allocated to your profile.
Recipients / third-country transfer: Google Ireland Limited and, where applicable, other Google group companies. Personal data may be processed in the USA. Where the U.S. recipient is certified under the EU-U.S. Data Privacy Framework and the transfer is covered by the adequacy decision, the transfer may be based on Art. 45 GDPR; otherwise appropriate safeguards such as Standard Contractual Clauses pursuant to Art. 46 GDPR are used where applicable.
Retention period: Not separately specified; determined by Google/YouTube.
Further information: https://policies.google.com/privacy (Opt-out: https://adssettings.google.com/authenticated)
3) Mentimeter (Live polls and surveys)
Provider: Mentimeter AB, Sweden.
Purpose: Conducting live polls and enabling exchange during workshop sessions.
Legal basis: Where use of the tool is optional and initiated by you, processing necessary to provide the interactive or collaboration function is based on Art. 6 para. 1 lit. f GDPR where appropriate; where consent is required for access to or storage of information on your end device or is otherwise requested, § 25 (1) TDDDG and Art. 6 para. 1 lit. a GDPR apply.
Data processed: Your poll inputs/contributions, which may be and remain partially publicly visible; usage data. We have no influence on the provider’s processing after activation.
Recipients / third-country transfer: Depending on the provider's processing structure, personal data may be processed outside the EEA. Transfers to recipients covered by an adequacy decision may be based on Art. 45 GDPR; otherwise appropriate safeguards such as Standard Contractual Clauses pursuant to Art. 46 GDPR are used where applicable.
Retention period: Not separately specified.
Further information: https://www.mentimeter.com/privacy
4) Padlet (Digital pinboard / collaboration)
Provider: Wallwisher, Inc. (Padlet), USA.
Purpose: Interactive collaboration and collection of contributions (e.g. digital pinboard) during workshop sessions.
Legal basis: Where use of the tool is optional and initiated by you, processing necessary to provide the interactive or collaboration function is based on Art. 6 para. 1 lit. f GDPR where appropriate; where consent is required for access to or storage of information on your end device or is otherwise requested, § 25 (1) TDDDG and Art. 6 para. 1 lit. a GDPR apply.
Data processed: Contributions (e.g. text, files), which may be and remain partially publicly visible; where applicable name/pseudonym; usage data.
Recipients / third-country transfer: Depending on the provider's processing structure, personal data may be processed outside the EEA. Transfers to recipients covered by an adequacy decision may be based on Art. 45 GDPR; otherwise appropriate safeguards such as Standard Contractual Clauses pursuant to Art. 46 GDPR are used where applicable.
Retention period: Not separately specified.
Further information: https://padlet.com/about/privacy
5) Miro (Collaborative whiteboard)
Provider: Miro (RealtimeBoard, Inc. / Miro).
Purpose: Collaborative whiteboard for exchange and joint work during workshop sessions.
Legal basis: Where use of the tool is optional and initiated by you, processing necessary to provide the interactive or collaboration function is based on Art. 6 para. 1 lit. f GDPR where appropriate; where consent is required for access to or storage of information on your end device or is otherwise requested, § 25 (1) TDDDG and Art. 6 para. 1 lit. a GDPR apply. [TECHNICAL CHECK BEFORE PUBLICATION: confirm the actual integration and consent flow.]
Data processed: Contributions (e.g. text, notes), which may be and remain partially publicly visible; usage data.
Recipients / third-country transfer: Depending on the provider's processing structure, personal data may be processed outside the EEA. Transfers to recipients covered by an adequacy decision may be based on Art. 45 GDPR; otherwise appropriate safeguards such as Standard Contractual Clauses pursuant to Art. 46 GDPR are used where applicable.
Retention period: Not separately specified.
Further information: https://miro.com/legal/privacy-policy/
6) Slido (Q&A and polls)
Provider: Slido (Cisco Systems, Inc.).
Purpose: Conducting Q&A and polls during sessions.
Legal basis: Where use of the tool is optional and initiated by you, processing necessary to provide the interactive or collaboration function is based on Art. 6 para. 1 lit. f GDPR where appropriate; where consent is required for access to or storage of information on your end device or is otherwise requested, § 25 (1) TDDDG and Art. 6 para. 1 lit. a GDPR apply.
Data processed: Your questions and poll answers, which may be and remain partially publicly visible; usage data.
Recipients / third-country transfer: Depending on the provider's processing structure, personal data may be processed outside the EEA. Transfers to recipients covered by an adequacy decision may be based on Art. 45 GDPR; otherwise appropriate safeguards such as Standard Contractual Clauses pursuant to Art. 46 GDPR are used where applicable.
Retention period: Not separately specified.
Further information: https://www.sli.do/terms#privacy-policy
D. Image and Video Recordings (Press and Public Relations Work)
We document the event through image, video and audio recordings. Group and overview photographs and live-stream images that depict the event as a whole may be produced and used for press and public relations purposes by the DRK-Generalsekretariat, the donor and the organising partner organisations. Where the requirements are met, the publication of such event images is based on § 23 (1) no. 3 KunstUrhG in conjunction with Art. 6 para. 1 lit. f GDPR; legitimate interests of persons depicted are taken into account in accordance with § 23 (2) KunstUrhG. For photographs or video/audio recordings in which an individual participant is specifically and individually identifiable and is the focus of the recording, we request separate voluntary consent pursuant to Art. 6 para. 1 lit. a GDPR and, for the use of the person's image, § 22 KunstUrhG. Such consent is not a condition of participation and may be withdrawn at any time with effect for the future.
Session recordings made available in the protected participant area are retained for [INSERT PERIOD, e.g. duration of the event / X months after the event] and are then removed from that area unless a separate lawful basis applies. Published press and public-relations materials and archival copies may be retained for documentation and archival purposes for as long as the relevant purpose and legal basis continue to apply. Where consent is withdrawn, future use based on that consent will cease; material already lawfully published, printed or archived may not always be capable of being recalled.
E. Social Media Plugins
The event website may provide links to social media services and, where technically implemented, optional social media plugins. Ordinary external links do not transmit data to the social media provider merely because you visit our website. If an actual plugin or embedded social-media function is used, it is integrated in a deactivated form and is activated only after the action or consent required for that service.
For further information about processing by the respective providers, please refer to their privacy information:
Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) – on the basis of an agreement on the joint processing of personal data. Privacy policy: facebook.com/about/privacy; for pages: facebook.com/legal/terms/information_about_page_insights_data; opt-out: facebook.com/settings?tab=ads and youronlinechoices.com.
Google / YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) – privacy policy: policies.google.com/privacy; opt-out: adssettings.google.com/authenticated.
Instagram (Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) – privacy policy / opt-out: instagram.com/about/legal/privacy.
X (formerly Twitter) (X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA) – privacy policy: x.com/en/privacy.
XING (New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany) – privacy policy: privacy.xing.com/de/datenschutzerklaerung.
LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland) – privacy policy: linkedin.com/legal/privacy-policy.