The following information pursuant to Art. 13 of the General Data Protection Regulation (GDPR) explains how your personal data is processed when you visit and use this web application. Please note that, to the extent described below, your data is processed by two different controllers.
Table of Contents
- Data Processing by GOe FUTURE Management GmbH
- Joint Data Processing by GOe FUTURE Management GmbH and Innoloft GmbH
- Joint Controllers
- Joint Point of Contact for Data Subjects
- Joint Data Processing
- Your Rights
1. Data Processing by GOe FUTURE Management GmbH
Controller:
GOe FUTURE Management GmbH
Startup Factory for Life Sciences
City Campus
Hermann-Rein-Straße 3
37075 Göttingen
Phone: +49 151 43351842
Email: hello@goe-future.de
2. Further Information pursuant to Art. 13 GDPR
2.1 Purposes and Legal Bases of Data Processing
We process personal data, in particular master data (e.g. name, contact details, function/position), communication data (e.g. email correspondence), as well as information relating to company-related processes, for the following purposes and on the following legal bases:
Network Admission and Management:
Collection and processing of startup information and contact details for the implementation of pre-contractual measures, in particular reviewing and deciding on admission to the network, and for the performance of the agreement regarding admission to the network (Art. 6(1)(b) GDPR).
Communication within the Network:
Contact by email or telephone for the organization and implementation of network activities (Art. 6(1)(b) GDPR).
Newsletter, Information and Event Invitations:
Sending information about network services, events and relevant topics on the basis of consent provided by you (Art. 6(1)(a) GDPR).
Registration for our newsletter uses a so-called double opt-in procedure. After registering, you will receive an email asking you to confirm your registration. Your registration will only be completed once you have provided this confirmation. This ensures that no one can register using someone else's email address. The logging of the registration and confirmation procedure (time, IP address, content of consent) is based on Art. 6(1)(c) and (f) GDPR in order to demonstrate compliance with data protection requirements.
With your consent, you will regularly receive emails containing general information or event invitations. The legal basis for processing your data for the purpose of sending the newsletter is your consent pursuant to Art. 6(1)(a) GDPR.
For sending our newsletter, we use the service “Mailchimp” provided by Intuit Inc. (USA) as a technical service provider. Mailchimp processes your email address and, where applicable, other data provided during newsletter registration on our behalf in order to technically distribute the newsletter and perform statistical analysis. We have concluded a data processing agreement with Mailchimp pursuant to Art. 28 GDPR.
Data processing by Mailchimp takes place, among other things, on servers in the USA. Mailchimp and Intuit are active participants in the EU-U.S. Data Privacy Framework, which regulates the transfer of personal data of EU citizens to the USA. Mailchimp also uses so-called Standard Contractual Clauses (SCCs), which are intended to ensure that data processing complies with European data protection standards when data is transferred to and stored in third countries such as the USA. Further information is available here:
https://mailchimp.com/de/gdpr/
Consent to receive the newsletter is voluntary and may be revoked at any time with effect for the future.
Transfer of Funding-Relevant Data to Funding Bodies:
Transfer of structural information relating to participating startups to funding bodies, insofar as this is necessary to fulfill legal obligations arising from the grant notification or funding guidelines (Art. 6(1)(c) GDPR).
Visibility within the Network, Mention and Logo, Photo and Video Recordings:
Publication of startup information and logos, as well as use of photo and video recordings for public relations purposes, based on your consent (Art. 6(1)(a) GDPR). Consent is voluntary and may be revoked at any time.
Recipients of the Data
Data will only be disclosed to third parties insofar as this is necessary to fulfill the purposes stated above or you have given your consent. Recipients may include, in particular:
- Network participants
- Funding bodies (within the scope of the funding conditions)
- Service providers acting on behalf of the network (e.g. IT service providers)
- The public (where consent has been given for publication, use of logos or images)
Withdrawal of Consent
Consent that has been given may be revoked at any time with effect for the future. Revocation may be submitted informally by email to the contact address stated above.
The lawfulness of processing carried out prior to revocation shall remain unaffected.
2.2 Storage Period
Data will only be stored for as long as necessary for the purposes stated, as long as statutory retention obligations apply, or until consent that has been granted is revoked. Once the purpose of processing no longer applies, statutory retention periods have expired or consent has been revoked, the data will be deleted.
2.3 Data Subject Rights
Under the GDPR, you have the following rights:
- Right of access to the personal data stored about you (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure, insofar as there are no statutory retention obligations to the contrary (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent that has been granted (Art. 7(3) GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
2.4 Obligation to Provide Data
The provision of data is required for admission to and participation in the network. Participation is not possible without providing this information. Consent to promotional communications and public relations activities is voluntary and is not a prerequisite for admission to the network.
3. Cross-Company Processing of Data
3.1 Data Processing
The web application available at https://goe-future.loftos.com (hereinafter also referred to simply as the “Web Application”) stores and manages personal data, in particular master data (e.g. name, contact details, function/position), communication data (e.g. email correspondence), as well as information relating to company-related processes.
3.2 Controller and Joint Use by GOe FUTURE Management GmbH and Life Science Valley GmbH
The controller responsible for processing data in the Web Application is generally GOe FUTURE Management GmbH and, in certain areas, Innoloft GmbH (see below). In addition, the stored data is also used by Life Science Valley GmbH, City Campus, Hermann-Rein-Straße 3, 37075 Göttingen, for the following purposes:
- Supporting network participants and maintaining relationships with and between network participants
- Strategic management and optimization of services
- Conducting workshops and coaching sessions
- Community management
- Event management
- Startup journey tracking
- Matchmaking
The companies involved have concluded internal agreements governing the joint use of the Web Application and personal data in compliance with data protection requirements. These agreements regulate, in particular, responsibilities, access rights, technical and organizational measures, and your data subject rights.
3.3 Legal Bases for Processing and Data Exchange
Depending on the circumstances, the processing of data in the Web Application and its use by our parent company is based on the following legal grounds:
- For the performance of a contract or for the implementation of pre-contractual measures with you (Art. 6(1)(b) GDPR), insofar as processing is necessary for the initiation, performance or termination of the contractual relationship;
- For compliance with legal obligations (Art. 6(1)(c) GDPR), such as statutory retention obligations under commercial and tax law;
- For the purposes of pursuing legitimate interests (Art. 6(1)(f) GDPR), in particular an efficient, cross-company coordinated support of network participants, consistent management of service processes and avoidance of duplicate structures.
When sharing and using your data across companies, we carry out a balancing of interests and take into account, in particular, the type of data, the expectations of the data subjects, as well as the implementation of appropriate technical and organizational measures and access restrictions. We are of the opinion that the cooperation between GOe FUTURE Management GmbH and Life Science Valley GmbH is exclusively beneficial, particularly for members of the network and users of the Web Application.
3.4 Recipients and Access Groups
Only employees who require this information to perform their respective duties have access to the data stored in the Web Application (“need-to-know principle”). Cross-company disclosure shall only take place on the basis of corresponding authorization concepts and access profiles.
4. Joint Data Processing by GOe FUTURE Management GmbH and Innoloft GmbH
In connection with providing access to the Web Application at https://goe-future.loftos.com , GOe FUTURE Management GmbH and Innoloft GmbH work closely together. This also concerns the processing of personal data relating to you. To the extent described below, the controllers are jointly responsible for protecting the personal data they process (Art. 26 GDPR).
4.1 Joint Controllers
Controller 1:
Innoloft GmbH
Jülicher Straße 72a
D-52070 Aachen
www.innoloft.com
Contact details of the Data Protection Officer of Controller 1:
PROLIANCE GmbH
Leopoldstr. 21
80802 Munich
Email: datenschutzbeauftragter@datenschutzexperte.de
When contacting the joint point of contact, please specify Innoloft GmbH and the company, organization or URL of the Web Application to which your request relates. Please refrain from attaching sensitive information, such as a copy of your identity document, to your request.
Controller 2:
GOe FUTURE Management GmbH
Startup Factory for Life Sciences
City Campus
Hermann-Rein-Straße 3
37075 Göttingen
Phone: +49 151 43351842
Email: hello@goe-future.de
Contact details of the Data Protection Officer of Controller 2:
[Name/designation of Data Protection Officer of Controller 2]
[Address of Data Protection Officer]
[Email address of Data Protection Officer]
4.2 Joint Point of Contact for Data Subjects
PROLIANCE GmbH
Leopoldstr. 21
80802 Munich
Email: datenschutzbeauftragter@datenschutzexperte.de
When contacting the joint point of contact, please specify Innoloft GmbH and the company, organization or URL of the Web Application to which your request relates. Please refrain from attaching sensitive information, such as a copy of your identity document, to your request.
4.3 Joint Data Processing
Scope and Regulation of Joint Data Processing
The two controllers are jointly responsible to a limited extent for data processing in connection with your access to the Web Application and have concluded an agreement pursuant to Art. 26 GDPR. The agreement specifies which processing activities are covered and which obligations under the GDPR are assumed by each of the two controllers.
Why Are There Two Joint Controllers?
The Web Application available at https://goe-future.loftos.com is provided on the basis of the platform Innoloft LoftOS developed by Innoloft GmbH. The platform combines the development and hosting of Web Applications with social media platform functions. One of its main use cases is the creation of communication and information platforms.
One function of LoftOS is the Innoloft Ecosystem. This includes certain networking and communication functions. Users can use the same login credentials to register with any application created with LoftOS, manage their unified profile there and communicate across applications with all operators of the Web Applications and other users.
In order to provide these basic functions of the Innoloft Ecosystem, the user data required for this purpose is processed by Innoloft GmbH (Controller 1) and the operator of the Web Application (Controller 2) for a common purpose and in a common interest. To this extent, Innoloft GmbH and the operator of the Web Application are jointly responsible for data processing as described below.
What Have the Controllers Agreed?
As part of their joint responsibility under data protection law, GOe FUTURE Management GmbH and Innoloft GmbH have set out in a written agreement which data protection obligations are incumbent upon each of them and which obligations each party fulfills. In particular, the controllers have agreed which party is responsible for handling data subject rights pursuant to Art. 15–22 GDPR and for fulfilling information obligations pursuant to Art. 12–14 GDPR.
Which Processing Activities Are Subject to Joint Responsibility?
The following list provides further information on the scope of joint data processing, the categories of data processed, the categories of data subjects and the legal basis for processing.
Description of processing activity: Provision of the authentication and login system of Innoloft LoftOS
Controllers: Controller 1; Controller 2
Categories of data processed: User login data (email address, password, IP address, log data)
Categories of data subjects: Users of Innoloft LoftOS and the Innoloft Ecosystem
Purposes and legal bases: Enabling users to log in to applications within Innoloft LoftOS. Art. 6(1)(f) GDPR, Art. 6(1)(b) GDPR
Description of processing activity: Provision of the user profile within Innoloft LoftOS
Controllers: Controller 1; Controller 2
Categories of data processed: Information contained in the user profile (first name, last name, profile picture, job title, company, interests, biography)
Categories of data subjects: Users of Innoloft LoftOS and the Innoloft Ecosystem
Purposes and legal bases: Displaying the User as a member of an application within Innoloft LoftOS. Art. 6(1)(f) GDPR, Art. 6(1)(b) GDPR
Description of processing activity: Provision of interaction, communication and networking functions of the Innoloft Ecosystem for applications of Controller 2 within Innoloft LoftOS and for users of these applications
Controllers: Controller 1; Controller 2
Categories of data processed: User data (first name, last name, profile picture); usage data (IP address, date and time); User's membership status in an application; data concerning the User's interaction with application content; content data (chats, messages)
Categories of data subjects: Users of Innoloft LoftOS and the Innoloft Ecosystem
Purposes and legal bases: Enabling networking and interaction between the User and applications of Controller 2 and other applications. Art. 6(1)(f) GDPR, Art. 6(1)(b) GDPR
Description of processing activity: Monitoring system stability and error analysis using Sentry
Controllers: Controller 1; Controller 2
Categories of data processed: User ID, browser information, URL, triggering error code
Categories of data subjects: Users of Innoloft LoftOS and the Innoloft Ecosystem
Purposes and legal bases: Monitoring the stability of the functions of Innoloft LoftOS, the Innoloft Ecosystem and the applications of Controller 2 for the purpose of error analysis and troubleshooting. Art. 6(1)(f) GDPR, Art. 6(1)(b) GDPR
The processed data is stored in Innoloft LoftOS for as long as necessary for the aforementioned data processing activities. As a rule, this is as long as the User has access to the Web Application or as long as their user profile exists.
The following processors are used within the scope of the joint responsibility:
Processor (name, address, country): Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland
Description of processing activity: Address completion when entering an address in the organization profile; translation of information in the user profile
Categories of data processed: IP address, address
Categories of data subjects: Users of Innoloft LoftOS and the Innoloft Ecosystem
Server location: EU
Safeguards to ensure an adequate level of protection: Standard Contractual Clauses (SCCs) and supplementary measures; certification under the EU-U.S. Data Privacy Framework (Google LLC)
Processor (name, address, country): Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
Description of processing activity: Monitoring the system stability and functionality of applications within Innoloft LoftOS
Categories of data processed: User ID, browser information, URL, triggering error code
Categories of data subjects: Users of Innoloft LoftOS and the Innoloft Ecosystem
Server location: Iowa, USA
Safeguards to ensure an adequate level of protection: Standard Contractual Clauses (SCCs) and supplementary measures; certification under the EU-U.S. Data Privacy Framework
Processor (name, address, country): Sinch AB, Lindhagensgatan 74, Stockholm, 112 18, Sweden
Description of processing activity: Sending system emails relating to authentication and login to the LoftOS system
Categories of data processed: Email address, first name, last name
Categories of data subjects: Users of Innoloft LoftOS and the Innoloft Ecosystem
Server location: EU
Safeguards to ensure an adequate level of protection: Not required, as this is an EU-based company
Apart from the processing activities listed above, personal data is otherwise processed by Controller 2 under separate responsibility — see “Privacy Information – Independent Responsibility”.
Who Fulfills Which Obligations under the GDPR and What Does This Mean for You as a Data Subject?
As part of their joint responsibility under data protection law, Controllers 1 and 2 have agreed which of them fulfills which obligations under the GDPR and have documented this in a written agreement:
Obligation under the GDPR: Art. 5 and 6 GDPR Compliance with data protection principles and existence of a legal basis
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): Yes
Obligation under the GDPR: Art. 26(1) Transparent determination in an agreement of which party fulfills which obligations under the Regulation. The agreement must appropriately reflect the respective actual functions and relationships of the jointly responsible parties towards data subjects.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): Yes
Obligation under the GDPR: Art. 26(1) Information regarding the point of contact for data subjects.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 26(2) The essential content of the agreement shall be made available to the data subject.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 27 Written appointment of an EU representative where a controller is not established in the EU.
- Innoloft GmbH (Controller 1): No
- GOe FUTURE Management GmbH (Controller 2): Yes
Obligation under the GDPR: Art. 13 Information obligations when personal data is collected from the data subject.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 14 Information obligations where personal data has not been obtained from the data subject.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 15 Handling requests concerning the data subject's right of access.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 16 Handling requests concerning the right to rectification.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 17 and 18 Handling requests concerning the right to erasure or restriction of processing, including Art. 19, notification of the obligation to erase.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 20 Handling requests concerning the right to data portability.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 21 Handling requests concerning the right to object.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 24(1) in conjunction with Art. 32 Determination of technical and organizational measures for risk assessment and, where applicable, for a data protection impact assessment (Art. 35), as well as consultation with a supervisory authority/provision of important information (Art. 36(3)).
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 24(1) Documentation of the selection of technical and organizational measures (as evidence).
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 24(1) Review and updating of technical and organizational measures.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 28 GDPR Selection and monitoring of processors and conclusion of corresponding agreements.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Art. 30 Maintaining a record of processing activities.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): Yes
Obligation under the GDPR: Art. 32 GDPR Data security.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): No
Obligation under the GDPR: Arts. 33 and 34 Procedures for notifying the supervisory authority of personal data breaches.
- Innoloft GmbH (Controller 1): Yes
- GOe FUTURE Management GmbH (Controller 2): Yes
4.4 Your Rights
The following information explains which data subject rights applicable data protection law grants you with regard to the processing of your personal data by the controller:
You have the right pursuant to Art. 15 GDPR to request information about your personal data processed by us. In particular, you may request information about the purposes of processing, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the source of your data where it was not collected from us, as well as the existence of automated decision-making, including profiling, and, where applicable, meaningful information about the details thereof.
You have the right pursuant to Art. 16 GDPR to request without undue delay the rectification of inaccurate or completion of incomplete personal data stored by us.
You have the right pursuant to Art. 17 GDPR to request the erasure of your personal data stored by us, unless processing is necessary for exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defense of legal claims.
You have the right pursuant to Art. 18 GDPR to request restriction of the processing of your personal data insofar as the accuracy of the data is disputed by you, the processing is unlawful but you oppose its erasure and we no longer need the data, but you require it for the establishment, exercise or defense of legal claims, or you have objected to processing pursuant to Art. 21 GDPR.
You have the right pursuant to Art. 20 GDPR to receive the personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller. You also have the right pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority of the federal state in which our registered office stated above is located or, where applicable, the supervisory authority of your usual place of residence or workplace.
You have the right to withdraw consent pursuant to Art. 7(3) GDPR. You may withdraw consent previously given for the processing of your data at any time with effect for the future. In the event of withdrawal, we will delete the data concerned without undue delay unless further processing can be based on another legal basis that does not require consent. Withdrawal of consent shall not affect the lawfulness of processing carried out on the basis of consent prior to withdrawal.
Right to Object
If your personal data is processed by us on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right pursuant to Art. 21 GDPR to object to the processing of your personal data where there are grounds relating to your particular situation. Where the objection is directed against the processing of personal data for the purposes of direct marketing, you have a general right to object without having to provide reasons relating to your particular situation.
Irrespective of the provisions above concerning which of the two joint controllers is responsible for exercising data subject rights pursuant to Arts. 15 to 22 GDPR, you may exercise your rights against either controller or the joint point of contact for data subjects using the contact details stated above.
When contacting the joint point of contact, please specify Innoloft GmbH and the company, organization or URL of the Web Application to which your request relates. Please refrain from attaching sensitive information, such as a copy of your identity document, to your request.
