Legal Notice
Continentale Company Health Insurance Fund
Public-law body
120 Sengelmann Street
22335 Hamburg
Tel: 0800 6 262626
Fax: 040 526777-1125
Email: customer-service(at)continentale-bkk.de
Website: www.continentale-bkk.de
Board of Directors: Stefan Lorenz
Deputy Chair: Jutta Grauel
VAT registration number: DE288366316
Regulatory authority:
Federal Social Security Office
38 Friedrich-Ebert-Allee, 53113 Bonn
Copyright
All content on the Continentale BKK website is protected by copyright and may not be copied or reproduced without express permission.
Disclaimer of Liability and Warranty
Despite careful checking of the content, all details and information on the Continentale BKK website are provided without guarantee and are subject to errors and changes. Continentale BKK accepts no liability for any damage arising from websites being inaccessible or files being technically faulty. We also accept no liability for the content of external websites, e.g. those of our cooperation partners, or for their availability.
The external content has been checked to ensure that it does not breach any applicable civil or criminal law. However, we cannot rule out the possibility that this content may be altered by the respective providers at a later date. Please let us know if you notice anything unusual (e.g. a breach of applicable law, inappropriate content). In this respect, we accept no liability for the content of linked external websites, nor for their availability.
Image credits
Concept and implementation
Ideenbude GbR, Hamburg
Privacy Policy
General information
Continentale BKK takes the protection of personal data very seriously. We want you to know when we collect which data and how we use it. All data we collect is subject to social data protection in accordance with the Social Security Code (SGB). Data collected and stored for the purpose of participating in services offered on the website is subject to data protection regulations the Digital Services Act (DDG). We collect and use your personal data exclusively in accordance with these provisions. We have implemented technical and organisational measures to ensure that data protection regulations are observed by both us and external service providers. With regard to the terminology used, we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Data controller
Continentale Company Health Insurance Fund
Stefan Lorenz
120 Sengelmann Street | 22335 Hamburg
Data Protection Officer
Continentale Company Health Insurance Fund
Data Protection Officer
120 Sengelmann Street | 22335 Hamburg
Types of data processed
Purpose of processing
Personal data
Personal data is information that can be used to identify you. This includes, for example, information such as your first name and surname, address, postal address and telephone number.
In this privacy policy, we explain how, to what extent and for what purpose we collect and use personal data when you visit our website.
In accordance with Article 13 of the GDPR, we hereby inform you of the legal bases for our data processing activities. Where the legal basis is not specified in the privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing to fulfil our services, carry out contractual measures and respond to enquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfil our legal obligations is Article 6(1)(c) of the GDPR, and the legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) of the GDPR. In the event that the vital interests of the data subject or another natural person necessitate the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.
If you are under 16, we require the consent of your parents or legal guardian. Otherwise, you must not send us any data.
For information purposes only
You can generally use our online services without revealing your identity if you simply wish to browse this website and do not wish to log in, register or submit any other information.
In the case of this so-called „use for information purposes“, we collect only the data that your browser transmits to enable you to visit our website.
These include, for example,.
Right of access, erasure and withdrawal
You have the right to request confirmation as to whether the relevant data is being processed, and to obtain access to that data, as well as further information and a copy of the data, in accordance with Article 15 of the GDPR.
In accordance with Article 16 of the GDPR, you have the right to request that data concerning you be completed or that any inaccurate data concerning you be rectified.
In accordance with Article 17 of the GDPR, you have the right to request that the relevant data be erased without delay; alternatively, in accordance with Article 18 of the GDPR, you have the right to request that the processing of the data be restricted.
You have the right to request that the personal data you have provided to us be made available to you in accordance with Article 20 of the GDPR, and to request that it be transferred to other data controllers.
You have the right to withdraw any consent you have given in accordance with Article 7(3) of the GDPR with effect for the future.
You may object at any time to the future processing of your personal data in accordance with Article 21 of the GDPR. In particular, you may object to the processing of your data for the purposes of direct marketing
You also have the right, in accordance with Article 77 of the GDPR, to lodge a complaint with the relevant supervisory authority.
Our data protection supervisory authority is:
Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Graurheindorfer Str. 153 | 53117 Bonn
Telephone: +49(0)228 997799-0
Email: | De-Mail:
Cooperation with data processors and third parties
Where, in the course of our data processing activities, we disclose data to other individuals or organisations (data processors or third parties), transfer it to them or otherwise grant them access to the data, this is done only on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract in accordance with Article 6(1)(b) of the GDPR), you have given your consent, a legal obligation requires it, or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).
Where we engage third parties to process data on the basis of a so-called „data processing agreement“, this is done in accordance with Article 28 of the GDPR.
Web hosting and email services
The hosting services we use are provided for the purpose of delivering the following services: infrastructure and platform services, computing capacity, storage space and database services, email delivery, security services and technical maintenance services, which we utilise for the purpose of operating this website.
In this context, we, or our hosting provider, process personal details, contact details, content data, contractual data, usage data, meta and communication data relating to customers, prospective customers and visitors to this online service on the basis of our legitimate interests in the efficient and secure provision of this online service in accordance with Article 6(1)(f) of the GDPR in conjunction with Article 28 of the GDPR (conclusion of a data processing agreement).
Collection of access data and log files
We, or rather our hosting provider, collect data on every access to the server on which this service is hosted (so-called server log files) on the basis of our legitimate interests within the meaning of Article 6(1)(f) of the GDPR. The access data includes the name of the webpage accessed, the file, the date and time of access, the amount of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), IP address and the requesting provider.
For security reasons (e.g. to investigate cases of misuse or fraud), log file information is stored for a maximum of 7 days and then deleted. Data that must be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.
Social media
We maintain an online presence on social media networks and platforms in order to communicate with customers, prospective customers and users who are active on these platforms and to provide them with information about our services. When accessing these networks and platforms, the terms and conditions and data processing policies of their respective operators apply.
Unless otherwise stated in our privacy policy, we process users’ data when they communicate with us via social networks and platforms, for example by posting comments on our online presence or sending us messages.
Integration of third-party services and content
Within our online offering, we use third-party content and service providers on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) to integrate content or services from third-party providers in order to incorporate their content and services, such as videos or fonts (hereinafter collectively referred to as “content”).
This always presupposes that the third-party providers of this content will be able to see the user’s IP address, as they would be unable to send the content to the user’s browser without it. The IP address is therefore necessary for the content to be displayed. We endeavour to use only content where the respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Pixel tags enable information such as visitor traffic on the pages of this website to be analysed. The pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical information about the browser and operating system, referring websites, time of visit and further details regarding the use of our online service, as well as being linked to such information from other sources.
Liability for links
Our website contains links to external third-party websites over whose content we have no control. We therefore accept no liability for this external content. The respective provider or operator of the linked sites is always responsible for their content. The linked sites were checked for possible legal infringements at the time the links were created. No illegal content was identifiable at the time the links were created. However, it is not reasonable to expect us to monitor the content of the linked pages on an ongoing basis without concrete evidence of a legal infringement. Should we become aware of any legal infringements, we will remove such links immediately.
Our website contains links to other websites. We have no control over whether their operators comply with data protection regulations.
System security
In accordance with Article 32 of the GDPR, we shall implement appropriate technical and organisational measures, taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability and its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, data is deleted and appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).
Matomo (formerly Piwik)
Our website uses the web analytics service Matomo. Matomo is an open-source solution provided by InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand.
Matomo uses „cookies“. These are small text files that your web browser stores on your device and which enable the analysis of website usage. Information generated by cookies regarding the use of our website is stored on our server. Your IP address is anonymised before it is stored.
Matomo cookies remain on your device until you delete them.
Matomo cookies are set in accordance with Article 6(1)(a) of the GDPR. Matomo is disabled when you visit our website. Your usage behaviour is only recorded anonymously once you have actively consented.
The information stored in the Matomo cookie regarding your use of this website will not be disclosed to third parties. You can prevent your web browser from accepting cookies; however, this may restrict some of the functions available on our website.
Google Analytics
Nature and scope of processing
We use Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as an analytics service to analyse the statistics relating to our website. This includes, for example, the number of visits to our website, the subpages visited and the length of time visitors spend on the site.
Google Analytics uses cookies and other browser technologies to analyse user behaviour and recognise users.
This information is used, amongst other things, to compile reports on website activity.
Purpose and legal basis
The use of Google Analytics is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. In cases where no adequacy decision has been issued by the European Commission (e.g. in the USA), we have agreed on other appropriate safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the EU Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2023/1795 of 10 July 2023. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32023D1795.
In addition, prior to any such transfer to a third country, we will seek your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by security authorities in the third country, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
Retention period
We have no control over the specific retention period for the processed data; this is determined by Google Ireland Limited. Further information can be found in the Google Analytics privacy policy: https://policies.google.com/privacy.
Google Tag Manager
Nature and scope of processing
We use Google Tag Manager, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to manage website tags via a single interface and enables us to control the precise integration of services on our website.
This allows us to flexibly integrate additional services in order to analyse how users access our website.
Purpose and legal basis
The use of Google Tag Manager is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Retention period
We have no control over the specific retention period for the processed data; this is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google Tag Manager: https://marketingplatform.google.com/about/analytics/tag-manager/use-policy
Google Ads Customer Match
We use Google Ads Customer Match lists as part of our Google advertising activities. We use Google Ads Customer Match with your consent in accordance with Article 6(1)(a) of the GDPR. To use Customer Match, lists containing encrypted user data (e.g. names, email addresses, postal addresses, Mobile Advertiser ID, customer-specific identifiers) are uploaded to Google. Google then checks whether the transmitted user data matches existing Google customers. This in turn allows target groups to be created, which can be used for the delivery of adverts/campaigns. Once the Customer Match lists have been created, the encrypted customer data is automatically deleted. This means that the providers do not gain access to new addresses.
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acting as a data processor. We have entered into a data processing agreement with Google for this purpose. Google LLC, based in California, USA, has joined the EU-US Data Privacy Framework and is certified accordingly.
You can object to this use by preventing the installation of cookies through the relevant settings in your browser software (disable option). You can also customise personalised advertising in your Google Account under the „Privacy“ tab according to your preferences. To do this, sign in to Google and go to „Manage your Google Account“ in the ‘Data and privacy’ section.
You can find out how Google uses and processes your data in general here:
https://policies.google.com/technologies/partner-sites