Privacy Policy

Privacy Policy

General information
The Continental BKK takes the protection of personal data very seriously. We want you to know when we store which data and how we use it. All data we collect is subject to social data protection in accordance with the Social Code (SGB). Data collected and stored for the purpose of participating in services offered on the website is subject to data protection regulations the Digital Services Act (DDG). We collect and use your personal data exclusively in accordance with these provisions. We have implemented technical and organisational measures to ensure that data protection regulations are observed both by us and by external service providers. With regard to the terminology used, please refer to the definitions in Art. 4 the General Data Protection Regulation (GDPR).

Person responsible
Conti­nentale Company Health Insurance Scheme
Stefan Lorenz
Sengelmann Street. 120 | 22335 Hamburg
kundenservice@​continentale-​bkk.​de

Data Protection Officer
Conti­nentale Company Health Insurance Scheme
Data Protection Officer
Sengelmann Street. 120 | 22335 Hamburg
datenschutz@​continentale-​bkk.​de

Types of data processed

  • Master data (e.g. names, addresses).
  • Contact details (e.g. email, telephone numbers).
  • Content data (e.g. text entries, photographs, videos).
  • Usage data (e.g. websites visited,
  • interest in content, access times).
  • Meta/communication data (e.g. device information, IP addresses).

Purpose of processing

  • Provision of the online service, its functions and content.
  • Responding to enquiries and communicating with users.
  • Security measures.
  • Audience measurement/​Marketing

Personal data
Personal data is information that can be used to identify you. This includes, for example, information such as your first name and surname, address, postal address and telephone number.

In this privacy policy, we explain how, to what extent and for what purpose we collect and use personal data when you visit our website.

In accordance with Article. 13 GDPR We hereby inform you of the legal bases for our data processing activities. Where the legal basis is not specified in the privacy policy, the following applies: The legal basis for obtaining consent is Article. 6 para. 1 lit. a and Art. 7 GDPR, the legal basis for processing data for the purpose of providing our services, carrying out contractual obligations and responding to enquiries is Article. 6 para. 1 lit. b GDPR, the legal basis for processing data in order to fulfil our legal obligations is Article. 6 para. 1 lit. c GDPR, and the legal basis for processing to safeguard our legitimate interests is Article. 6 para. 1 lit. f GDPR. In the event that the vital interests of the data subject or of another natural person necessitate the processing of personal data, Article. 6 para. 1 lit. d GDPR as the legal basis.

If you are suffering from 16 If you are under 18, we require the consent of your parents or legal guardians. Otherwise, you must not send us any data.

Use for information purposes
In principle, you can use our online services without revealing your identity if you simply wish to browse this website for information and do not wish to log in, register or submit any other information via the website.

In the case of this so-called „use for information purposes“, only data transmitted by your browser is collected, in order to enable you to visit our website.

These include, for example,.

  • IP address,
  • Date and time of the request,
  • Content of the request (specific page)

Right of access, erasure and withdrawal
You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to that data, as well as further information and a copy of the data, in accordance with Article. 15 GDPR.

You have, in accordance with Article. 16 GDPR the right to request that the data relating to you be completed or that any inaccurate data relating to you be rectified.
You have, in accordance with Article. 17 GDPR the right to request that the relevant data be erased without delay, or, alternatively, in accordance with Article. 18 GDPR to request that the processing of the data be restricted.
You have the right to request that the data relating to you, which you have provided to us, be processed in accordance with Article. 20 GDPR to obtain such data and to request that it be transferred to other data controllers.
You have the right to withdraw any consent you have given in accordance with Art. 7 para. 3 GDPR to revoke with effect from now on.
You may object to the future processing of your personal data in accordance with Article. 21 GDPR object at any time. In particular, you may object to the processing of your data for the purposes of direct marketing
Furthermore, pursuant to Article. 77 GDPR the right to lodge a complaint with the relevant supervisory authority.

Our data protection supervisory authority is:
Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Graurheindorfer Street. 153 | 53117 Bonn
Telephone: +49(0)228 997799 – 0
Email: poststelle@​bfdi.​bund.​de | De-Mail: poststelle@​bfdi.​de-​mail.​de

Co-operation with data processors and third parties
Where, in the course of our data processing, we disclose data to other individuals and organisations (data processors or third parties), transfer it to them or otherwise grant them access to the data, this is done only on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is required under Art. 6 para. 1 lit. b GDPR is necessary for the performance of a contract), you have given your consent, there is a legal obligation to do so, or on the basis of our legitimate interests (e.g. when using data processors, web hosting providers, etc.).

Where we engage third parties to process data on the basis of a so-called „data processing agreement“, this is done in accordance with Article. 28 GDPR.

Web hosting and email delivery
The hosting services we use are intended to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email delivery, security services and technical maintenance services, which we utilise for the purpose of operating this online service.

In doing so, we – or our hosting provider – process customer records, contact details, content data, contractual data, usage data, meta-data and communication data relating to customers, prospective customers and visitors to this online service on the basis of our legitimate interests in the efficient and secure provision of this online service in accordance with Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (Conclusion of a contract for the processing of orders).

Collection of access data and log files
We, or rather our hosting provider, collect data on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f. GDPR Data relating to every access to the server on which this service is hosted (so-called server log files). The access data includes the name of the web page accessed, the file, the date and time of access, the amount of data transferred, a notification of successful access, the browser type and version, the user’s operating system, and the referrer URL (the page visited previously), IP address and the requesting internet service provider.

For security reasons (e.g. to investigate cases of misuse or fraud), log file information is retained for a maximum period of 7 Stored for a few days and then deleted. Data that needs to be retained for evidential purposes is exempt from deletion until the incident in question has been fully resolved.

Social media
We maintain an online presence on social media networks and platforms in order to communicate with customers, prospective customers and users active on these platforms and to provide them with information about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.

Unless otherwise stated in our privacy policy, we process users’ data when they communicate with us via social networks and platforms, for example by posting comments on our online presence or sending us messages.

Integration of third-party services and content
Within our online service, we rely on our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online service within the meaning of Art. 6 para. 1 lit. f. GDPR) It incorporates content or services from third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter collectively referred to as “content”).

This always presupposes that the third-party providers of this content collect users“ IP addresses, as they would be unable to send the content to users” browsers without them. The IP address is therefore necessary for the content to be displayed. We endeavour to use only content where the respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These ‘pixel tags’ enable information, such as visitor traffic on the pages of this website, to be analysed. This pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical information about the browser and operating system, referring websites, time of visit and further details regarding the use of our online service, and may also be linked to such information from other sources.

Liability for links
Our website contains links to external third-party websites over whose content we have no control. We are therefore unable to accept any liability for this external content. The respective provider or operator of the linked pages is always responsible for their content. The linked pages were checked for possible legal infringements at the time the links were created. No unlawful content was identifiable at the time the links were created. However, it would be unreasonable to expect us to monitor the content of the linked pages on an ongoing basis without specific evidence of a legal infringement. Should we become aware of any legal infringements, we will remove such links immediately.

Our website contains links to other websites. We have no control over whether their operators comply with data protection regulations.

System security
We shall act in accordance with Article. 32 GDPR taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability and its segregation. Furthermore, we have put procedures in place to ensure that data subjects’ rights are upheld, that data is deleted and that we respond to any threats to data security. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).

Matomo (formerly Piwik)

Our website uses the web analytics service Matomo. Matomo is an open-source solution from the provider InnoCraft Ltd., 150 Willis Street, 6011 Wellington, New Zealand.

Matomo uses „cookies“. These are small text files that your web browser stores on your device and which enable the analysis of website usage. Information generated by cookies regarding the use of our website is stored on our server. Your IP address is anonymised before it is stored.

Matomo cookies remain on your device until you delete them.

Matomo cookies are set in accordance with Article. 6 para. 1 lit. a GDPR. Matomo is disabled when you visit our website. Your browsing behaviour will only be recorded anonymously once you have actively given your consent.

No information stored in the Matomo cookie regarding your use of this website will be disclosed to third parties. You can prevent your web browser from setting cookies; however, this may restrict some of the functions on our website.


Google Analytics

Nature and scope of the processing
We use Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as an analytics service for the statistical analysis of our website. This includes, for example, the number of visits to our website, the sub-pages visited and the time spent on the site by visitors.
Google Analytics uses cookies and other browser technologies to analyse user behaviour and recognise users.
This information is used, amongst other things, to compile reports on website activity.

Purpose and legal basis
The use of Google Analytics is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR and § 25 para. 1 TDDDG.
We intend to transfer personal data to third countries outside the European Economic Area, in particular to USA, to be transmitted. In cases where no adequacy decision has been adopted by the European Commission (e.g. in the USA) we have put in place other appropriate safeguards with the recipients of the data in accordance with Article. 44 ff. GDPR agreed. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with the Implementing Decision EU) 2023/​1795 from the 10. July 2023. You can find a copy of these standard contractual clauses at https://​eur​-lex​.europa​.eu/​l​e​g​a​l​-​c​o​n​t​e​n​t​/​DE​/​T​X​T​/​?​uri​=​C​E​L​E​X​:​32023​D1795 view.
Furthermore, prior to any such transfer to a third country, we will seek your consent in accordance with Art. 49 para. 1 Sentence 1 lit. a. GDPR which you provide via the Consent Manager (or other forms, registrations, etc.). We would like to draw your attention to the fact that, in the case of transfers to third countries, there are risks whose precise nature is unknown (e.g. data processing by security authorities in the third country, the exact scope of which and its consequences for you we do not know, over which we have no control and of which you may not become aware).

Retention period
We have no control over the specific retention period for the processed data; this is determined by Google Ireland Limited. Further information can be found in the Google Analytics privacy policy: https://​policies​.google​.com/​p​r​ivacy.

Google Tag Manager

Nature and scope of the processing
We use Google Tag Manager, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to manage website tags via a single interface and enables us to control the precise integration of services on our website.
This enables us to flexibly integrate additional services in order to analyse users’ access to our website.

Purpose and legal basis
The use of Google Tag Manager is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR and § 25 para. 1 TDDDG.

Retention period
We have no control over the specific retention period for the processed data; this is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google Tag Manager: https://​market​ing​platform​.google​.com/​a​b​o​u​t​/​a​n​a​l​y​t​i​c​s​/​t​a​g​-​m​a​n​a​g​e​r​/​u​s​e​-​p​olicy

Google Ads Customer Match

We use Google Ads Customer Match lists as part of our Google advertising activities. We use Google Ads Customer Match with your consent in accordance with Art. 6 para. 1 (a) GDPR. To use Customer Match, lists containing encrypted user data (e.g. names, email addresses, postal addresses, Mobile Advertiser ID, customer-specific identifiers) are uploaded to Google. Google then checks whether the user data provided matches existing Google customers. These can in turn be used to create target audiences for the delivery of adverts and campaigns. Once the Customer Match lists have been created, the encrypted customer data is automatically deleted. This means that providers do not gain access to any new addresses.

The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as a data processor. To this end, we have entered into a data processing agreement with Google. Google LLC based in California, USA is the EU-U.S. Data Privacy Framework and has been certified accordingly.

You can object to this use by preventing the installation of cookies through the relevant settings in your browser software (disable option). You can also customise personalised advertising in your Google account under the „Privacy“ tab according to your preferences. To do this, log in to Google and go to „Manage your Google Account“, then to the ‘Data and privacy’ section.

You can find out how Google uses and processes your data in general here:
https://​policies​.google​.com/​t​e​c​h​n​o​l​o​g​i​e​s​/​p​a​r​t​n​e​r​-​sites