Skip to content
DEEN
Contact

Home›Privacy policy

Privacy policy

How we handle your data.

The protection of your personal data matters to us.

Under the EU General Data Protection Regulation (GDPR), we are obliged to inform you of the purposes for which we process personal data, that is, collect, store or transfer it. This information also sets out your rights with regard to data protection. This English version is provided for convenience; the German version is legally binding.

Controller

MLI Leadership Institut GmbH
Munich Metropolitan Region
Mühlstraße 4
86911 Dießen am Ammersee, Germany

Phone: +49 8807 244446-0
E-mail: info@leadership-munich.org

Fax: +49 8807 244446-9

Data protection officer

Anja Spittler
on behalf of Pagestreet, a service of
legal.solutions GmbH
Sophienstraße 1
10178 Berlin, Germany

Phone: +49 160 8457361
E-mail: a.spittler@pagestreet.de

Purposes of data processing

We process your personal data for four purposes.

  1. Performance of contractual obligationsArt. 6(1)(b) GDPR. If we request personal data from you before a contract is concluded, we process it to prepare the contract — for example, when drawing up a proposal.
  2. Compliance with legal obligationsArt. 6(1)(c) GDPR, such as retention obligations under commercial and tax law.
  3. Protection of legitimate interestsArt. 6(1)(f) GDPR: maintaining IT operations and ensuring IT security, informing you about our company’s services, using external service providers such as tax advisors, banks, postal and parcel services, telecommunications and e-mail providers. If you object to processing for marketing purposes, we keep a blocking list so that your objection is also respected when backups are restored. In addition, the assertion, exercise or defense of legal claims.
  4. Purposes covered by your consentArt. 6(1)(a) GDPR. Should we wish to process personal data for a purpose not listed here, we will inform you beforehand within the framework of the statutory provisions.

Legal bases and storage period

The data we process are deleted as soon as they are no longer required for the purpose of processing. Exceptions are cases in which deletion is not possible due to statutory retention periods and further processing under Art. 6(1)(c) GDPR is mandatory, in which you have consented to storage beyond that under Art. 6(1)(a) GDPR, or in which the data are required for the assertion, exercise or defense of legal claims under Art. 17(3)(e) GDPR.

Recipients of your data

Within our company, only those units that need access to fulfill the purposes stated receive it. Further recipients may be: processors such as IT service providers, software manufacturers and data and document destruction services, as well as tax advisors, banks, postal and parcel services, auditors, external data protection officers, insurers and telecommunications providers. In legal disputes, associations, lawyers, debt collection agencies, public prosecutors, courts, bailiffs or other authorities may be added.

Origin of your data and obligation to provide them

As a rule, your personal data are collected directly from you when a contract is being prepared and performed.

Within our contractual relationship, you must provide the data that are required to establish, perform and terminate the contractual relationship and to fulfill the associated obligations, or that we are legally obliged to collect. Without these data, we cannot perform the contract.

Transfer to third countries

We use online services from Microsoft with servers located in the EU. Nevertheless, your personal data may be transferred to the company’s US servers. The legal basis is the adequacy decision of the European Commission, which applies to companies certified under the EU-U.S. Data Privacy Framework. Microsoft holds the corresponding certification.

No automated decision-making. No profiling takes place.

Use of this website

What happens when you visit these pages.

This section describes the technology actually in use on this website, as a privacy policy is required to do.

  1. Access dataWhen the site is accessed, the server logs technical data: IP address, time, page accessed, amount of data transferred, browser type. The legal basis is our legitimate interest in secure operation, Art. 6(1)(f) GDPR.
  2. Fonts and imagesFonts and graphics are served from our own server. No connection to Google Fonts or other third-party providers is established when you visit.
  3. Cookies and audience measurementThis website sets no cookies and does not measure reach. That is why there is no consent banner.
  4. Appointment bookingFor appointments we use Microsoft Bookings, a service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. When you click an appointment button, you leave our website and open a page hosted by Microsoft. Your IP address and technical details of your browser are transmitted to Microsoft, and Microsoft may set cookies. If you book an appointment, we process your name, your email address and the information you provide in order to hold the appointment. The legal basis is Article 6(1)(b) of the General Data Protection Regulation, for steps prior to entering into a contract, and our legitimate interest in straightforward scheduling under Article 6(1)(f). A transfer to the United States is possible; Microsoft is certified under the EU-US Data Privacy Framework. Microsoft’s privacy statement is available at privacy.microsoft.com. We delete appointment data as soon as it is no longer required for the appointment and any retention obligations.
  5. Compass downloadIf you request the AI Leadership Compass on the AI Transformation page, we process your name, e-mail address and company in order to provide you with the document and to contact you about it once. The legal basis is your consent, Art. 6(1)(a) GDPR; you can withdraw it at any time with effect for the future. The form is transmitted via Netlify Forms (Netlify, Inc., San Francisco, USA) as a processor; data may be transferred to the USA in the process. We delete the information no later than twelve months after the request unless a business relationship results. No disclosure to third parties takes place; requesting the compass does not subscribe you to a newsletter.
  6. Contact form and getting in touchIf you write to us via the form on the contact page or by e-mail, we process your name, your e-mail address and, where provided, your organization and phone number, as well as the content of your message — to handle the inquiry and any follow-up questions. The legal basis is Art. 6(1)(b) GDPR for pre-contractual inquiries, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding.

    Transmission takes place via Netlify Forms (Netlify, Inc., San Francisco, USA) as a processor. Netlify stores every submission within our account and also sends us a notification to info@leadership-munich.org; data may be transferred to the USA in the process. We delete submissions at Netlify no later than twelve months after the inquiry unless a business relationship results, and we do not pass them on to third parties. An inquiry does not subscribe you to a newsletter unless you expressly request it. To fend off automated submissions, we use a technical check field and a field invisible to you; no data are transmitted to third parties and no cookies are set.
  7. NewsletterYou can subscribe to Impulse vom Ammersee on the page impulse.html with your name and email address. You can also indicate voluntarily in the contact form that you would like to receive them. In both cases we use your name and email address for this purpose. The legal basis is your consent under Art. 6(1)(a) GDPR.

    The sign-up is completed using a double opt-in procedure: we first send you an email that you need to answer. Only then do we add you to the list. Without your reply we delete the entry. Sign-up and confirmation are logged with the date so that the consent can be demonstrated. The sign-up form is transmitted, like our other forms, via Netlify Forms (Netlify, Inc., San Francisco, USA) as a processor; data may be transferred to the USA. Issues are sent about every three months from our own mailbox; we do not currently use an external mailing system, and open or click rates are not measured. You can withdraw your consent at any time with effect for the future, informally to info@leadership-munich.org or via the note in every issue.

Your rights

Six rights you can assert at any time.

By post or by e-mail to the contact details above. No reason needs to be given.

Access

You have the right to obtain confirmation as to whether personal data concerning you are being processed. If so, you have a right of access to these data.

Rectification, erasure, restriction, portability

You have the right to rectification of incorrectly processed data and to erasure or restriction of processing. Where parts of the data are subject to a statutory or regulatory retention obligation, blocking takes the place of erasure. You may also have a right to receive the data you have provided in a structured, commonly used and machine-readable format.

Objection

You have the right to object to processing under Art. 21 GDPR. In individual cases, exercising this right may mean that you can no longer use our services. We then examine whether there are compelling legitimate grounds for the processing. If we process your data for direct marketing purposes, you can object at any time; we will then no longer use your data for this purpose.

Withdrawal of consent

You can withdraw consent under data protection law at any time with effect for the future, by post or e-mail.

Complaint to the supervisory authority

You have the right to lodge a complaint with the competent supervisory authority if you disagree with a request for access or with the way data are processed.

Competent supervisory authority

Bavarian State Office for Data Protection Supervision (BayLDA)
Postfach 1349, 91504 Ansbach, Germany
Phone: +49 981 180093-0
Fax: +49 981 180093-800
lda.bayern.de

↑Top