Legal
Privacy notice
Last updated:
This notice covers this website, where we present the Holigence study app. The app has its own privacy policy (section 6).
In short
- This website consists of static files. It sets no cookies and contains no analytics or advertising services.
- There is no form and no account. We do not learn who you are.
- So that your browser can load the page, our hosting provider Cloudflare processes your IP address. Cloudflare is a company based in the United States.
- The study app at holigence.app has its own privacy policy.
1. Who is responsible
Holigence GbRStettiner Straße 26
61184 Karben
Germany
Represented jointly by the partners Niklas Sipf and Marcel Molenda. Email: privacy@holigence.de
We have not appointed a data protection officer, because the law does not require one for us. For any privacy question, write to privacy@holigence.de.
2. What happens when you open the website
When you open this website, your browser requests the files from our hosting provider, Cloudflare. In doing so, Cloudflare processes connection data: your IP address, the time of the request, the address requested and the technical information your browser sends, for example browser type, operating system, language setting and the page you came from.
This processing is needed to deliver the website and to protect it against attacks and overload. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to provide the website securely and reliably.
No law or contract obliges you to provide this data. Without it, however, your browser cannot load the website.
We keep no visit logs of our own and build no profiles. The connection to the website is encrypted (HTTPS).
Cloudflare also instructs your browser to report connection errors (Network Error Logging). If a request to this website fails, your browser may send a technical error report to Cloudflare. According to Cloudflare, no data that identifies you is stored in the process, and your IP address is discarded once the report has been processed.
3. Cloudflare and the transfer to the United States
The recipient of the connection data is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare processes it on our behalf and on our instructions under a data processing agreement (Art. 28 GDPR).
Your request is answered by the Cloudflare data centre that receives it. If you open the website from outside the EU, that data centre can be outside the EU. Cloudflare states that it processes log data about requests in data centres in the United States and in Europe.
The transfer to the United States is covered by the European Commission’s adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework. Cloudflare, Inc. is certified under that framework. Should the certification end, the EU Standard Contractual Clauses apply, which our agreement with Cloudflare already contains. You can get a copy of these safeguards by writing to privacy@holigence.de.
Cloudflare states that it keeps the log data only for a limited period. It does not name a fixed period, so we cannot be more precise. What counts is how long the data is needed to deliver and protect the website.
4. Cookies and storage in your browser
This website sets no cookies and uses neither local storage nor any other storage in your browser for its own purposes.
Your browser remembers only two technical rules: that it should open this website over an encrypted connection only (for one year), and the instruction to report errors described in section 2, together with the Cloudflare address a report would go to (for seven days). Neither is a cookie.
The website respects whether you have asked your operating system for reduced motion. Your browser works that out by itself. The setting is neither stored nor sent to us.
5. No analytics, no advertising, no third-party content
We use no analytics or advertising services, no tracking pixels and no social media embeds. Fonts, scripts, images and animations are served from this website itself. When the page loads, your browser therefore connects to Cloudflare only.
6. Links to the app and to other websites
The buttons and links to the app lead to holigence.app. Your browser contacts the app only when you follow such a link. We operate the app as well. It has its own privacy policy, which is available in English only: holigence.app/privacy-policy
Links to other websites, for example to CFA Institute, open that operator’s site; the operator is responsible for the processing there. The site you go to learns from your browser at most the address of this website, not the page you came from.
7. When you write to us
If you send us an email, we process your email address, your message and whatever you tell us in it, in order to answer you. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to answer enquiries. Where the message concerns a contract or steps towards one, the legal basis is Art. 6(1)(b) GDPR; for requests about your privacy rights it is Art. 6(1)(c) GDPR.
The mailbox is hosted by STRATO GmbH in Berlin, which runs it on our behalf in Germany. We keep messages for as long as we need them to handle your request and any follow-up, and longer only where a law requires it.
8. Your rights
Under the GDPR you have the right to
- learn whether we process data about you, and which (Art. 15),
- have inaccurate data corrected (Art. 16),
- have your data erased (Art. 17),
- have the processing restricted (Art. 18),
- receive data you have given us in a commonly used, machine-readable format, where the conditions for this are met (Art. 20),
- object to the processing (Art. 21, see below),
- lodge a complaint with a data protection supervisory authority (Art. 77).
To use these rights, write to privacy@holigence.de. We answer within one month. In complex cases this period can be extended by up to two further months, and we will tell you if it is. We usually cannot link the connection data of a page view to a person. To answer a request for access to it, we therefore need details that allow your requests to be found (Art. 11 GDPR).
Right to object under Art. 21 GDPR: where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We then stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. An email to privacy@holigence.de is enough.
You can complain to any data protection supervisory authority, for example where you live. The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7
65185 Wiesbaden
Germany
datenschutz.hessen.de
9. No automated decisions
This website involves no automated decision-making and no profiling (Art. 22 GDPR).
10. Changes
We update this notice when the website or the law changes. The date at the top shows when the current version was written.
If the German and English versions of this notice differ, the German version applies.