Privacy Policy

Vetklinfo takes your privacy very seriously and handles your personal data confidentially and in accordance with applicable law. Please bear in mind that data transmitted over the internet may have security vulnerabilities. Complete protection against access by third parties cannot be guaranteed.

The EU General Data Protection Regulation (GDPR) has applied since 25 May 2018. This notice explains how vetklinfo processes personal data in accordance with Article 13 GDPR.

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Dr. Stefan Lindner
vetklinfo
Kirschallee 1
04416 Markkleeberg
Telephone: +49 (0)341 - 863 99 450
E-Mail: info@vetklinfo.com

Data security

We use an encrypted HTTPS connection (TLS encryption) during your visit to our website to protect transmitted data from unauthorised third-party access. We also take appropriate technical and organisational security measures to protect personal data, in particular against loss, manipulation and unauthorised access. We review and adapt these measures in line with technological developments.

YouTube

Our website may embed videos from YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

YouTube videos are not loaded automatically when you visit our website. A connection to YouTube is established only when you expressly consent to loading the relevant video and activate it.

When you activate a video, your IP address, information about your device and browser, and details of your visit to our website may be transmitted to Google. If you are signed in to your Google or YouTube account at the same time, Google may associate the visit with your account.

Processing is based on your consent under Article 6(1)(a) GDPR and, where information is stored on or accessed from your device, on section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future.

Google may also process data outside the European Economic Area, in particular in the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework. For more information about Google's privacy practices, see: Google Privacy Policy

Server log files

When you visit our website, your browser automatically sends information to our website's server. The following data may be processed in particular:

This data is processed on the basis of Article 6(1)(f) GDPR. Our legitimate interests are providing a secure and reliable website, monitoring system security and stability, and detecting and preventing misuse and security incidents.

Log data is deleted as soon as it is no longer needed for these purposes, unless further retention is necessary to investigate a specific security incident or to meet legal obligations.

Hosting

Our website and associated technical systems are hosted by the following provider:

checkdomain GmbH
Große Burgstraße 27/29
23552 Lübeck

As part of providing hosting services, checkdomain processes personal data generated when you use our website. This may include IP addresses, server log data and data processed through our website, online shop or other applications hosted on the server.

We use this hosting provider to make our website and technical systems available securely and reliably. Where personal data is processed on our behalf, processing is governed by a data processing agreement under Article 28 GDPR.

According to checkdomain, the servers used for web hosting are located in Germany. For more information about checkdomain's privacy practices, see: checkdomain Privacy Policy

Jetpack security features

We use Jetpack security features, in particular protection against brute-force attacks, to protect our WordPress and WooCommerce systems from unauthorised login attempts.

This may involve processing the IP address, the username or email address used in a login attempt, browser and device information, and details of failed login attempts. The data is used to detect and, where appropriate, block suspicious or automated login attempts.

Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is protecting our website, online shop and the personal data processed through them.

During certain security checks, Jetpack may set a technically necessary cookie, for example to confirm that a security CAPTCHA has been solved successfully.

General information about the processing of personal data

Personal data is any information relating to an identified or identifiable natural person. We process personal data only where necessary to provide our website, communicate with you, deliver our seminars and perform contracts, or where another legal basis permits the processing.

Depending on the purpose, processing is based in particular on your consent under Article 6(1)(a) GDPR; steps taken before entering into a contract or performance of a contract under Article 6(1)(b); compliance with a legal obligation under Article 6(1)(c); or our legitimate interests under Article 6(1)(f).

We disclose personal data to third parties only where necessary to perform a contract, where we are legally required or permitted to do so, where you have given your consent, or where we use a service provider in accordance with applicable data protection law.

The use of the contact details published in our legal notice to send unsolicited advertising or information materials is expressly prohibited.

Contacting us

If you contact us, for example by email or telephone, we process the personal data you provide to the extent necessary to handle your enquiry.

Where your enquiry relates to entering into or performing a contract, processing is based on Article 6(1)(b) GDPR. In other cases, it is based on our legitimate interest in responding to your enquiry under Article 6(1)(f) GDPR.

When you communicate with us by email, messages and related technical connection data are processed through the email systems of our hosting provider, checkdomain GmbH. Where checkdomain processes personal data on our behalf, this is governed by a data processing agreement under Article 28 GDPR.

Data collected when you contact us is deleted as soon as it is no longer needed to handle your enquiry and no statutory retention obligation or other legitimate reason for continued storage applies.

Seminar bookings and contract administration

When you book a seminar through our online shop, we process the data needed to handle your order and perform the contract. This may include the following personal data:

This data is processed to take steps before entering into a contract and to perform our contract with you, on the basis of Article 6(1)(b) GDPR.

Where data is processed to comply with tax or commercial record-keeping obligations, processing is based on Article 6(1)(c) GDPR.

Personal data is deleted as soon as it is no longer needed to perform the contractual relationship and no statutory retention obligation or other lawful reason for continued storage applies. Tax-relevant accounting records and invoices must generally be retained for eight years. In individual cases, the law may require longer retention periods.

Evidence of participant status and professional qualifications

For certain discounted rates or profession-specific seminars, we may require proof that the participant belongs to the intended audience or meets the conditions for the selected rate. This may include an enrolment certificate, student ID, veterinary surgeon's ID, licence to practise or comparable proof of profession or qualification submitted with the order.

The file you submit is used solely to verify eligibility to participate or the participant status stated. Where verification is necessary to perform the booked contract or grant the selected rate, processing is based on Article 6(1)(b) GDPR.

Please submit only the information required for the relevant proof. You may redact unnecessary personal data, such as your enrolment number, photograph, date of birth, QR codes or other additional information, provided the required status or qualification remains clear.

Once verification is complete, the submitted file is deleted as soon as it is no longer needed for this purpose and no legal obligation or other lawful reason for continued storage applies. The outcome of the verification may be documented to the extent necessary.

For continuing education recognised by the Academy for Veterinary Continuing Education (ATF), the applicable recognition requirements oblige us to provide certain participant information to the ATF on request. This includes verifying the status of a veterinary surgeon or veterinary medicine student. The ATF requires this participant information to be retained for three years, starting at the beginning of the year following the training. Where documentation beyond immediate contract performance is necessary, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the proper delivery and verifiability of recognised training. The proof document itself is not retained longer than necessary for verification unless a further obligation requires its retention.

Moodle learning platform

We use the Moodle learning platform to deliver our online seminars. After a seminar is booked through our online shop, a Moodle user account is automatically created for the participant, if one does not already exist, and the participant is enrolled in the course.

For this purpose, the data needed to create or identify the user account and enrol the participant in the course is transferred from our online shop to our Moodle installation. This includes, in particular, first name, last name, email address and information about the seminar booked.

This data is transferred and processed to deliver the booked seminar, on the basis of Article 6(1)(b) GDPR. Data taken from the order process is not used for other purposes unless another legal basis permits that use.

The following personal data is processed in particular:

Technical usage and log data may also be processed when you use Moodle, such as login times and activities completed. This data supports delivery and proper conduct of the seminar, as well as the security and operation of the learning platform.

Data needed for seminar participation is processed to perform our contract with you, on the basis of Article 6(1)(b) GDPR.

The Moodle user account and associated personal data no longer needed to administer the seminar are generally deleted six months after the last login, provided the person is no longer enrolled in any course at that time and no statutory retention obligation or other lawful reason for continued storage applies.

Data used to issue and later verify certificates of attendance is retained for three years from the end of the relevant course to document successful participation. This processing is based on Article 6(1)(f) GDPR. Our legitimate interest is being able to trace and, where needed, confirm certificates issued during that period.

Any different statutory retention or evidentiary obligations, including those arising from accreditation, remain unaffected.

Recipients of personal data

To provide our website, administer contracts and deliver our seminars, personal data may be shared with the following categories of recipients:

Where service providers process personal data on our behalf, this is governed by a data processing agreement under Article 28 GDPR, where the legal requirements apply.

Your rights

Subject to the applicable legal requirements, you have the following rights concerning your personal data:

Right to object under Article 21 GDPR

Where we process personal data on the basis of Article 6(1)(e) or (f) GDPR, you may object to that processing at any time on grounds relating to your particular situation.

If you make a valid objection, we will stop processing the personal data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.

If personal data is processed for direct marketing, you may object at any time. The data will then no longer be processed for direct marketing.

Right to lodge a complaint with a supervisory authority

Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.

The supervisory authority responsible for vetklinfo is:

Saxon Data Protection and Transparency Commissioner
Maternistraße 17
01067 Dresden
Telephone: +49 351 85471-101
E-Mail: post@sdtb.sachsen.de
www.datenschutz.sachsen.de

To exercise your data protection rights, you may contact us at any time using the details above.

Online shop and technically necessary cookies

We operate our seminar shop using WordPress and WooCommerce. The online shop uses technically necessary cookies and similar storage technologies required to provide functions such as the shopping cart, checkout and session management.

Where these technologies are strictly necessary to provide the online shop you have expressly requested, they are used on the basis of section 25(2)(2) TDDDG. Where personal data is processed, this is done in particular to take steps before entering into a contract and to perform our contract with you under Article 6(1)(b) GDPR.

When you place an order, we process in particular the contact, billing and order details you provide at checkout. We use this data to administer your seminar booking and payment and to deliver the seminar.

We disclose personal data only where necessary to perform the contract, where we are legally required to do so, or where a service provider acts on our behalf in accordance with applicable data protection law.

Google reCAPTCHA

We use Google reCAPTCHA to protect our website, particularly forms and shop functions, against automated access, misuse, spam and attempted fraud.

Use of reCAPTCHA may involve processing your IP address, information about your device and browser, and information about user interactions. This data is used to assess whether access is by a person or automated.

Processing personal data is based on Article 6(1)(f) GDPR. Our legitimate interest is protecting our website and online shop from misuse and automated access, and preventing spam and fraud.

To conduct its risk analysis, reCAPTCHA may store information on your device or access information already stored there. Where this is strictly necessary to protect and securely provide the functions you expressly use, it is based on section 25(2)(2) TDDDG.

Google provides this service. Where Google processes personal data through reCAPTCHA on our behalf, the processing is governed by the data processing terms applicable to Google Cloud.

According to Google, data collected through reCAPTCHA is used only to provide and secure the reCAPTCHA service and is not used for personalised advertising.

Payment service provider PayPal

We offer PayPal as one of our payment services. For users in the European Economic Area, the provider is:

PayPal (Europe) S.à r.l. et Cie, S.C.A.
22-24 Boulevard Royal
L-2449 Luxemburg

When you open the checkout page, connections to PayPal may be established to provide the payment method and for security and fraud prevention. This may involve processing your IP address, browser and device information, technical identifiers and cookies. Where access to information on your device is strictly necessary to provide the payment function securely, it is based on section 25(2)(2) TDDDG.

If you select PayPal and initiate payment, the personal data required to process the payment is sent to PayPal. This may include your name, billing address, email address, order details, payment amount and other information needed to process the payment.

The data required to process payment is sent to PayPal to perform our contract with you, on the basis of Article 6(1)(b) GDPR.

PayPal processes personal data for its services as an independent controller. It may process data to handle payments, prevent fraud, verify identity and meet legal obligations. Depending on the PayPal payment method selected, additional checks, such as credit checks, may be carried out.

For more information about how PayPal processes personal data, see PayPal's privacy policy: PayPal Privacy Policy

Payment service provider WooPayments (Stripe)

We use WooPayments to accept credit and debit card payments. WooPayments is integrated into WooCommerce and operated in cooperation with payment service provider Stripe.

When you open the checkout page, connections to Stripe may be established to provide card payments and prevent fraud. This may involve processing your IP address, browser and device information, technical identifiers and information about interactions with the checkout page. WooPayments also uses Stripe's methods to detect and assess potentially fraudulent transactions.

If you select credit or debit card payment and initiate the transaction, the data required to process the payment is sent to WooPayments or Stripe. This may include your name, email address, billing address, order details, payment amount and payment or transaction identifiers.

Data required to process payment is processed to perform our contract with you, on the basis of Article 6(1)(b) GDPR. Data processed to prevent fraud and handle payments securely is processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is preventing misuse and fraudulent payments.

Where information is stored on or accessed from your device to provide the payment function securely, and this is strictly necessary for the payment function you requested, this is based on section 25(2)(2) TDDDG.

Sensitive card details are entered into payment fields provided by WooPayments or the payment service provider. Full card details and the card verification code (CVC) are not stored on our web server.

For more information, see the WooCommerce privacy notice for payment services and the Stripe Privacy Policy .