Data Protection

GENERAL INFORMATION ON THE PROCESSING OF YOUR DATA

This Privacy Notice informs you about the processing of your personal data and your rights in connection with counseling services provided by Themis. Terms such as "personal data" and "processing" are defined in Article 4 of the General Data Protection Regulation (GDPR).

Data Controller
The controller responsible for the processing of your personal data is:
Themis-Vertrauensstelle gegen sexuelle Belästigung und Gewalt e.V.
Frankfurter Allee
10365 Berlin
Germany
Email: kontakt@themis-vertrauensstelle.de
Phone: +49 30 23 63 20 210

Data Protection Contact
If you have any questions regarding data protection at our organization, you may contact our external Data Protection Officer:
Email: datenschutz@themis.de

Purpose of Processing
Your personal data are processed for the purpose of providing professional counseling services by Themis e.V. This includes initiating, providing, and administering the counseling services.

Legal Basis
Your personal data are collected and processed on the basis of your consent pursuant to Article 6(1)(a) GDPR.
Your consent will be obtained in writing prior to the counseling session and, in exceptional cases, may also be obtained orally.

Categories of Personal Data

The following categories of personal data are collected, stored, and processed in connection with the counseling services:

  • Name (or, where applicable, a pseudonym)
  • Contact details
  • Details of your inquiry, including, where applicable, information relating to legal or other proceedings
  • Information about other persons involved (e.g. employers, alleged perpetrators, witnesses)
  • Professional group or occupation
  • Industry or sector

These data will often include special categories of personal data within the meaning of Article 9 GDPR, such as health data or information concerning sexual orientation.

Internal Processing by Themis
Your personal data may be processed by employees of Themis and, where necessary, by external experts engaged by Themis.

Access to personal data is granted strictly on a need-to-know basis. Employees and experts only have access to the personal data required for the respective purpose, in accordance with the principle of data minimization.

Disclosure to Third Parties
Your personal data will only be disclosed to third parties (such as lawyers, employers, or other parties) if you provide us with a separate written authorization.

For annual reports, statistical analyses, publications, and advocacy activities, Themis anonymizes all data so that no individual can be identified

Data Retention
Your personal data will be securely deleted or destroyed two years after the counseling process has ended or after our last contact with you.

Personal data will be retained beyond this period only where necessary to comply with a legal obligation or for the establishment, exercise, or defense of legal claims.

Your Rights
You have the following rights under the GDPR:

  • Right of access: You have the right to obtain information about the personal data we process concerning you in accordance with Article 15 GDPR.
  • Right to rectification: If the personal data we hold about you are inaccurate or incomplete, you have the right to request their correction or completion pursuant to Article 16 GDPR.
  • Right to erasure: Under the conditions set out in Article 17 GDPR, you have the right to request the deletion of your personal data.
  • Right to restriction of processing: Under Article 18 GDPR, you have the right to request that the processing of your personal data be restricted.
  • Right to object: Under Article 21(1) GDPR, you have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data where such processing is based on Article 6(1)(e) or (f) GDPR. In such cases, we will no longer process your personal data unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defense of legal claims.
  • Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time in accordance with Article 7(3) GDPR. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to data portability: Under Article 20 GDPR, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format and, where the legal requirements are met, to have those data transmitted to another controller.

You may exercise these rights by contacting the Data Controller using the contact details provided above.

If you believe that the processing of your personal data violates applicable data protection law, you also have the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR. This includes the supervisory authority responsible for the Data Controller:

Berlin Commissioner for Data Protection and Freedom of Information
Friedrichstraße 219
10969 Berlin
Germany

Telephone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de

COUNSELING

Data protection online counseling

Online counseling
You’ll learn here about how your data is collected and processed in connection with our online counseling service at https://c02.aygonet.org/themis-vertrauensstelle/ob/

Purpose of processing
Your data is processed for the purpose of providing professional counseling by Themis e.V. via our online portal https://c02.aygonet.org/themis-vertrauensstelle/ob/

Categories of data subjects
Registered users of the online service.

Legal basis
The legal basis for the collection and processing of your data is your active consent (pursuant to Art. 6(1)(a) GDPR), which must be given during registration by ticking the relevant box.

Collection of your data
To use the online counseling service, you need to register and create an account to access the counseling software.

To do this, choose a username and create a password that only you know and that the counseling team cannot access.

Please make sure to use this username and password only for this counseling service and not for other login accounts.

If you voluntarily provide an email address:

  • You’ll be emailed when you receive a response in the mail counseling system.
  • If necessary, you can use the “Forgot password” function, which works only via email.

Providing an email address also means you can enable multi-factor authentication, which increases the security of your login by requiring an additional code sent by email during login. This function can be activated or deactivated in your profile settings.

If you receive counseling via chat, the counsellor will begin by asking whether a chat transcript should be created. At the end of the chat, they will ask whether the transcript should be saved or deleted for both you and the counsellor.

Web-based counseling software, cookies, log files, and time-out
Your login data and your inquiry are transmitted directly to a server via a secure data tunnel (SSL) and are not forwarded elsewhere. They are read and answered directly on the server (web-based).

This means that your inquiry always reaches the counseling team via an encrypted connection, and counsellors have to log into this encrypted counseling software to respond.

For statistical purposes, counseling sessions are analysed in a protected database after anonymisation. No personal identification is possible in this process.

Our counseling service works with a software provider who is contractually bound to comply with our data protection standards.

When visiting the website www.themis-???.de and using our online counseling service, only technically necessary session cookies are used. These cookies do not remain on your device after the session ends.

The following data is processed only for the duration of your visit to the online counseling service:

  • Anonymised IP address
  • Date and time
  • Accessed page / name of the retrieved file
  • Message indicating whether the access/retrieval was successful

This data can only be temporarily stored by the server service-provider in the case of unusual behaviour or errors, for the purpose of defending against attacks or correcting technical errors.

After one hour of inactivity (no activity within the software), you will be automatically logged out (time-out).

Recipients of the data
All counsellors at Themis are bound by confidentiality.

If you contact the online counseling service more than once, you will generally receive a response or an appointment from the same counsellor.

The Themis counseling team has different areas of specialisation, including legal counseling and psychological counseling.

As a result, it might sometimes happen that:

  • We advise you to involve a colleague with a complementary specialisation, or
  • If your counsellor is unavailable, we ask whether another colleague can take over the consultation.

In these situations, all involved counsellors will have access to your request.

Deletion of data
You can delete your account, counseling requests, and chat transcripts at any time and without providing a reason.

If you no longer use the counseling service, your account and all counseling records will be automatically deleted two years after your last login.

MATERIALS

Data protection Materials

Ordering materials

Our publications, studies and other useful information are available to download from our website. To order printed versions of our materials, please use the order form on our website. For delivery, we require your name, a postal address and an email address for any queries.

Purposes of processing
The Themis Trust Centre uses the data exclusively for the dispatch of the ordered materials.
All data is deleted three months after dispatch.
Payment transactions relating to postage costs are retained for ten years to fulfil reporting obligations to the tax authorities.

Legal basis
The legal basis for the processing of your data is Article 6(1)(a) of the GDPR, in the form of your consent at the end of the order form.

WEBSITE

Date protection for the Website

Visiting this website
You may generally use this website without disclosing your identity, purely for information purposes. When you visit this website, only technically necessary cookies are used. These include cookies used, for example, to save your language selection, which are deleted once you leave the website.
Tracking tools, statistics programmes or similar functions are not used.

Purposes of processing
The temporary processing of this data is necessary to technically enable the functioning of a website visit and the delivery of the website to your device.

Legal basis
The legal basis for the processing is Article 6(1)(f) of the GDPR. Our legitimate interests lie in ensuring the functionality of the website.

SEMINARS

Data protection for Seminars

Seminars
In our interactive seminars, we teach practical psychological and legal principles for dealing with sexual harassment in the workplace – with a particular focus on the cultural and media sectors. We empower participants in their respective roles, explain their rights and obligations under the General Equal Treatment Act (AGG), and promote confidence in taking action, solidarity and sensitive communication.
Registration takes place via the form on our website.

Purposes of processing
Initiation, development, delivery, administration and promotion of Themis seminars

Data subjects
Participants in Themis seminars.

Categories of data
To fulfil these purposes, we require the following from you:

  • Identification data (name, address), contact details (telephone, email),
  • field of work, LAG membership
  • bank account details

Legal basis
The legal basis for the processing of your data is Article 6(1)(b) of the GDPR in the form of your consent provided during registration.

Transfer to third countries
The use of the Zoom video conferencing tool involves the transfer of data to the USA, in accordance with the provider’s policies: https://www.zoom.com/de/trust/gdpr/

Recipients of the data
Your data will only be viewed and processed within Themis by authorised personnel.
If external speakers deliver the seminar, they will receive the data relating to the participants concerned.
Upon request, the tax office receives details of income generated by our seminars.

Deletion
Themis deletes the data at the end of the year, three years after the end of the process.
Speakers delete data relating to participants immediately after the course.
Themis is obliged to store details of costs and income relating to the seminars for ten years for the tax office.

Data protection In-house Seminars

In-house Seminars
In our interactive in-house seminars, we provide practical psychological and legal guidance on dealing with sexual harassment in the workplace – tailored to the structures and needs of your institution within the cultural and media sector. The content is aimed exclusively at employees of your organisation and helps to build confidence in taking action, clarify roles, enhance legal knowledge in line with the AGG, and foster a supportive and sensitive culture of dialogue and collaboration.
To find out whether we currently have capacity for a bespoke format, you can either email us at praevention@themis-vertrauensstelle.de
or use the “Request a bespoke quote” form at the very bottom of our website at
https://themis-vertrauensstelle.de/seminare/

Purposes of processing
Initiation, development, delivery, administration and promotion of Themis in-house seminars.

Data subjects
Contact persons in the commissioning organisation.
Participants in Themis seminars.

Data categories
To fulfil these purposes, we require the following data from participants:

  • Identification data (name, address), contact details (telephone, email),
  • field of work, education
  • bank account details of the paying institution

And from the contact persons in the commissioning organisations:

  • Name
  • Position
  • Contact details

And regarding the contact persons at the commissioning organisations:

  • Name
  • Position
  • Contact details

Legal basis
The legal basis for the processing of the data is Article 6(1)(b) of the GDPR, in the form of the contract with the commissioning organisation.

Transfer to third countries
The use of the Zoom video conferencing tool involves the transfer of data to the USA, in accordance with the provider’s policies: https://www.zoom.com/de/trust/gdpr/

Recipients of the data
Within Themis, the data is accessed and processed only by authorised personnel.
If external speakers deliver the seminar, they will receive the data relating to the participants concerned.
Upon request, the tax office receives details of income generated by our seminars.

Deletion
Themis deletes the data at the end of the year three years after the end of the process.
Speakers delete data relating to participants immediately after the course.
Themis is obliged to retain details of costs and income relating to the seminars for ten years for the tax office.

MEMBERS

Privacy Notice and Consent for Membership

General Information on the Processing of Your Data
This Privacy Notice informs you about the processing of your personal data and your rights in connection with a membership at Themis e.V. The legal definitions set out in Article 4 of the General Data Protection Regulation (GDPR), such as "personal data" and "processing," shall apply.

Data Controller
The controller responsible for processing personal data is:Data Controller
The controller responsible for processing personal data is:

Themis – Trust Centre Against Sexual Harassment and Violence e.V.
Frankfurter Allee
10365 Berlin
Email: kontakt@themis-vertrauensstelle.de
Phone: +49 30 23 63 20 210

Legal Representatives:
Martina Zöllner (President)
Maren Lansink (Managing Director)

Questions Regarding Data Protection
If you have any questions regarding data protection at our organization, you may contact our external Data Protection Officer:
Email: datenschutz@themis.de

Purpose of Processing
Your personal data is processed for the purpose of establishing, administering, and managing your membership in the association.
This includes:

  • Organizing the General Assembly and the Assembly of Delegates
  • Supporting the sections of Themis
  • Providing member services, such as free webinars and prevention materials
  • Internal association communications, including the annual Christmas card
  • Invitations to events
  • Maintaining an up-to-date membership directory, which is published on the Themis website

Legal Basis
Your personal data is collected and processed on the basis of Article 6(1)(b) GDPR (performance of a contract).
The relevant consent/declaration is provided together with the membership application.

Categories of Data
Although the members are legal entities (i.e. organizations), Themis stores and processes the personal data of the respective contact persons.
This includes:

  • Name
  • Position/Role
  • Contact details

Internal Processing Within Themis
Your personal data is processed by Themis employees. This also includes the respective Chairs of the Themis sections, where necessary to facilitate communication within the sections and the association. Section Chairs process these data exclusively for internal section-related communication and in accordance with the rules of procedure governing their respective sections.

Disclosure to Third Parties
Personal data will only be disclosed to third parties where required by law, for example to tax authorities.

Your Rights
You have the following rights with regard to your personal data:

  • Right of access: You have the right to obtain information about the personal data we process concerning you in accordance with Article 15 GDPR.
  • Right to rectification: If the personal data concerning you are inaccurate or incomplete, you may request their correction or completion pursuant to Article 16 GDPR.
  • Right to erasure: You may request the deletion of your personal data in accordance with Article 17 GDPR.
  • Right to restriction of processing: You have the right to request restriction of the processing of your personal data in accordance with Article 18 GDPR.
  • Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data carried out on the basis of Article 6(1)(e) or (f) GDPR, pursuant to Article 21(1) GDPR. In such a case, we will cease processing your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or where the processing serves the establishment, exercise, or defence of legal claims.
  • Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time pursuant to Article 7(3) GDPR. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to data portability: You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format and, where the requirements of Article 20(1)(a) and (b) GDPR are met, to transmit those data to another controller in accordance with Article 20 GDPR.

You may exercise your rights by contacting us using the contact details provided under "Data Controller."
If you believe that the processing of your personal data violates data protection law, you also have the right to lodge a complaint with a supervisory authority of your choice pursuant to Article 77 GDPR. This includes the supervisory authority responsible for Themis:

Berlin Commissioner for Data Protection and Freedom of Information
Friedrichstraße 219
10969 Berlin
Germany
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de