Privacy policy for the 3rd BAUHAUS Corporate Challenge Europe 2023

This privacy policy informs you about how BAUHAUS processes personal data as part of the "BAUHAUS Corporate Challenge Europe" campaign, what data protection rights you are entitled to and how you can contact us in this regard and if you have any questions about data protection. Participation in the BAUHAUS Corporate Challenge Europe by BAUHAUS employees is voluntary. 

I. Scope of this privacy policy

Please note that this privacy policy contains sections that are only relevant either for data processing on the website https://www.bauhaus-challenge.eu (see under III.) or only for data processing in the BAUHAUS CCE App (see under IV.) or only for data processing in the context of evaluating the results and compiling statistics (see under V.).

Sections I, II, and III apply to all data processing activities related to the BAUHAUS Corporate Challenge Europe.

II. Controller and Data Protection Officer

The Controller within the meaning of Art. 4 No. 7 GDPR is BAUHAUS AG, Zweigniederlassung Mannheim, Gutenbergstraße 21, D-68167 Mannheim, Germany (hereinafter referred to as "BAUHAUS", "we" or "us").

For specific enquiries, you are also welcome to contact the designated Data Protection Officer directly at any time by e-mail at datenschutzbeauftragter@bauhaus.info. The topics and contents addressed are subject to strict confidentiality.

For general enquiries about data protection and requests for information, please contact the BAUHAUS data compliance department at datenschutz@bauhaus.info, giving precise details of your request and your contact address.

III. Data subject rights 

As a data subject, you are entitled to the following data protection rights if the applicable conditions are met:

  • The right to information (Art. 15 GDPR)
  • The right to correction (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing pursuant to Art. 18 GDPR
  • The right to data portability (Art. 20 GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

Furthermore, you have a right of objection (Art. 21 GDPR) if we process data on the basis of Art. 6 para. 1 lit. f GDPR. You can send your objection to us by e-mail to datenschutz@bauhaus.info

If we process data relating to you on the basis of consent given by you pursuant to Art. 6 para. 1 S. 1 lit. a GDPR, you may revoke your consent with effect for the future. The lawfulness of the processing prior to consent remains unaffected by the revocation. You can send your revocation to us by email to datenschutz@bauhaus.info.

IV. Information on data processing on the website

We operate a separate website  https://www.bauhaus-challenge.eu, where we provide information about the Corporate Challenge Europe and offer you the opportunity to register for participation. Within this section, we provide information on the data processing that takes place on the website.

1. Log files

Each time you visit this website, your browser automatically transmits information (log files) to us. These include:

  • the IP address of your device;
  • date and time of access;
  • the name and address of the requested file;
  • data volume transferred;
  • message as to whether the request was successful;
  • information about the browser and operating system used and the name of your internet provider;
  • websites from which the user's system accesses our website (tracking);
  • websites that are accessed by the user's system via our website.

This data is processed to enable and facilitate the use of the website. In addition, the data is evaluated in anonymised and aggregated form and used in the interest of system security and the technical administration of the network infrastructure. We reserve the right to subsequently review the log data if there is a justified suspicion of unlawful use based on specific indications. The data processing described above is carried out on the basis of our legitimate interests in providing our website in a secure manner and in evaluating the use of our website and based on Art. 6 para. 1 S.1 lit. f GDPR.

The storage period of the data described above is usually seven days from the collection of the data. In exceptional cases, the data is stored to clarify suspected cases of unlawful use until the suspicion has been clarified.

The recipient of the data is the website's hosting provider, one4vision GmbH (Talstraße 34-42, D-66119 Saarbrücken).

2. Registration and queries

We have set up a subpage on the website https://www.bauhaus-challenge.eu for registration to participate in the BAUHAUS Corporate Challenge Europe. If you are interested in participating in the BAUHAUS Corporate Challenge Europe, you can register for it on the sub-page. In the course of the registration we collect the following data:

  • Last name (optional) or name abbreviation (optional) or pseudonym*; 
  • First name (optional) or name abbreviation (optional) or pseudonym*;
  • Email address*;
  • BAUHAUS country/branch number;
  • Password;
  • “My personal goal”
  • Please indicate if you would like to receive a T-shirt and specify the size (S-XXL) (voluntary)

* By using an abbreviated name (e.g., MM for Max Mustermann) or pseudonym (e.g., Mannheim68), your personal data will be processed in a manner that prevents direct association with a specific individual without additional information. However, complete pseudonymization will only be achieved if you also provide a pseudonymous email address (e.g., Mannheim68@webmail.de).

If you do not complete the registration process because you do not set a password, the data you have provided will not be stored. Only when you have set a password will we store the data you have provided. The processing of the aforementioned data serves the purpose of fulfilling our contractual obligations arising from the contract concluded with you for the participation, implementation and handling of the BAUHAUS Corporate Challenge (Art. 6 para. 1 S. 1 lit. b GDPR). If you provide information regarding your preferred T-shirt size, this is done based on BAUHAUS' legitimate interests in providing its employees with a T-shirt for the BAUHAUS Corporate Challenge and meeting the employees' legitimate interests in receiving a T-shirt from BAUHAUS for the purpose of participating in the BAUHAUS Corporate Challenge without relying on their own clothing (Art. 6 para. 1 S. 1 lit. b GDPR). 

We use the personal data you provide during registration to create a clearly identifiable account and for the subsequent clear allocation of your result achieved in the BAUHAUS Corporate Challenge Europe. We use your e-mail address to send you a confirmation e-mail with an individual link, the access data and an activation code for the "BAUHAUS CCE" app for tracking the virtual race and to assign an e-mail address to you. Furthermore, it is necessary for the execution and participation that we record your location to determine your result. You can control the location tracking on your mobile phone according to your preferences.

We store the password you selected in order to be able to offer you protected access to the "BAUHAUS CCE" app and to prevent misuse. We carry out this data processing on the basis of our legitimate interests in offering a protected account and preventing misuse on the basis of Art. 6 para. 1 S. 1 lit. f GDPR.

The statement "my personal goal" does not serve the purpose of evaluating or assessing the participants' performance. This information is solely intended for gamification purposes and highlighting the playful element of the BAUHAUS Corporate Challenge Europe, based on Art. 6 para. 1 S. 1 lit. f GDPR.

We store all data from your registration for three months after the end of the BAUHAUS Corporate Challenge Europe. 

If you have general questions about the BAUHAUS Corporate Challenge Europe and its procedure, about participation or the participation requirements and conditions, or technical questions about participation in the BAUHAUS Corporate Challenge Europe, you can contact us at any time by e-mail at info@bauhaus-challenge.eu. The processing of the data provided by you in connection with such queries, in particular your e-mail address, serves the purpose of fulfilling our contractual obligations arising from the contract concluded with you or in the process of being concluded for the participation, implementation and handling of the BAUHAUS Corporate Challenge Europe (Art. 6 para. 1 S. 1 lit. b GDPR).

The recipient of the data provided during registration is race result Timing BW GmbH (Nachtigallenweg 19, D-71032 Böblingen, Germany), which assists us with the collection of registration data. Our service provider n plus sport GmbH (Großherzog-Friedrich-Str. 100, D-66121 Saarbrücken, Germany) is also the recipient of the data you provide within the registration process in order to later create evaluations and statistics for us on the results of individual countries, branches and various groups of people. In addition, our service provider n plus sport GmbH (Großherzog-Friedrich-Str. 100, 66121 Saarbrücken) is the recipient of the data you provide in connection with any queries directed to info@bauhaus-challenge.eu.

3. Social Wall (Flockler)

On a subpage of our website, https://www.bauhaus-challenge.eu, we have integrated the service "Flockler" as a subcontractor through our data processor. Flockler is operated by Flockler Oy, with its headquarters located at Rautatienkatu 21 B, 33100 Tampere, Finland. We use this service to display social media content from participants on the BAUHAUS Corporate Challenge Europe website. 

The Social Wall/Flockler scans the publicly accessible area of Facebook and Instagram for the designated hashtags for BAUHAUS Corporate Challenge Europe. It then collects the voluntarily shared public posts on Facebook and Instagram by the participants using these hashtags and displays them on the BAUHAUS Corporate Challenge Europe website. A prerequisite for displaying social media content is that the creator of a post has set the content as publicly available in the settings of their social media profile. Only the participants can choose to deselect the "public" setting in their social media accounts and control which of their posts, if any, can be found, mirrored, and displayed on the Social Wall. They have control over the designated "#" hashtags or keywords in their posts.

The mirrored social media posts displayed on the website are available for a period of 60 days. These are then automatically deleted. We base the use of personal data as part of the social media posts on our legitimate interests in displaying publicly available posts to show BAUHAUS' involvement in the BAUHAUS Corporate Challenge Europe. The legal basis for this is our legitimate interests according to Art. 6 para. 1 S. 1 lit. f GDPR.

Depending on the social media platform, the social media services process information about you if you decide to interact with the content displayed on our social wall (e.g. play a video or visit a profile). By embedding the Flockler code into our website, Flockler obtains the IP address of our website visitors to protect Flockler from unusual traffic volume and any malicious activity patterns. The legal basis is Art. 6 para. 1 S. 1 lit. f GDPR. Our legitimate interest is in the secure integration of the Flockler service and the display of publicly available posts related to BAUHAUS. The storage period of the IP address is usually seven days from the collection of the data. In exceptional cases, the data is stored to clarify suspected cases of unlawful use until the suspicion has been clarified.

Flockler uses services from Amazon (Amazon Data Service Ireland Ltd., 1 Burlington Plaza Burlington Road, Dublin 4, D04RH96 Ireland) to provide its services to us. The data is primarily stored in Germany. For data transfers outside the EU and EEA, Flockler has concluded standard contractual clauses with Amazon Web Services Inc. (410 Terry Avenue North, Seattle, WA 98109-5210, USA), which can be accessed at: https://d1.awsstatic.com/Controller_to_Processor_SCCs.pdf.

4. Cookies

On our website, we use cookies that are absolutely necessary for the operation of the website, such as session cookies, which are only stored for the visit to the website and serve exclusively to display the website. Therefore, we do not ask for your consent for the use of cookies. A cookie is a small text file that is sent by the respective servers when a website is visited and is temporarily stored on the user's hard drive.

The cookies we use are necessary for the provision of our website or a function of the website requested by you or for the fulfilment of our legal obligations. The legal basis for the use of cookies is § 25 para. 2 no. 2 TTDSG. We process the personal data obtained with the help of these types of cookies and similar technologies either on the basis of our legitimate interests in providing our website and functions requested by you according to Art. 6 para. 1 S. 1 lit. f GDPR or to fulfil a legal obligation based on Art. 6 para. 1 S. 1 lit. c GDPR. You can view the storage period of the cookies in your browser settings.

5. Publication of results

We publish results of the BAUHAUS Corporate Challenge Europe on our website. We use the following data to display the list of results: 

  • First name and surname or name abbreviation or pseudonym
  • completed kilometres
  • “My personal goal”
  • Country of your BAUHAUS company
  • Branch number of your BAUHAUS company.

Some of the results we publish do not refer to an individual person but to a group (e.g. the result of all participants of a branch or a country). Persons who have achieved the best result overall or the best result from a group are displayed on the leader board with their first and last name or name abbreviation or pseudonym in connection with the result. Furthermore, if you have registered with your first and last name and not with a name abbreviation or pseudonym, it is possible that other people who are also participating in BAUHAUS Corporate Challenge Europe can search for you on our website and view your result. A corresponding list in PDF format is not available for download on our website. 

The legal basis for publishing personal data as part of BAUHAUS Corporate Challenge Europe results and enabling the search function is Art. 6 para. 1 S. 1 lit. b GDPR for the performance of the contract with you within the context of your participation and Art. 6 para. 1 S. 1 lit. f GDPR. Our legitimate interests lie in the publication of participants' results in order to make the results and the overall progress in the Challenge recognisable and the associated presentation of BAUHAUS as a company participating in the BAUHAUS Corporate Challenge Europe. Personal data as part of published results will be automatically removed from the website three months after the end of the BAUHAUS Corporate Challenge Europe. In addition, the website with the results is particularly technically protected by a password so that third parties cannot access the list of results.

Furthermore, we display the results of the BAUHAUS Corporate Challenge Europe in a leader board. The technical integration of the leader board is carried out with the help of the service provider Racemap GmbH (Timaeusstrasse 1, D-01099 Dresden, Germany, https://my.raceresult.com/), which is the recipient of the data processed by the use of the search function. 

On https://my.raceresult.com/249480/results you have the opportunity to print a certificate of the results list with your registered name or pseudonym. Please note that for technical reasons it is not possible for everyone to download only their own certificate of their own result, which is why we recommend that you use a name abbreviation or pseudonym instead of your first and last name as part of the registration process for data protection reasons, if you do not want others to be able to download your result with your first and last name.

Racemap GmbH uses services of Amazon (Amazon Data Service Ireland Ltd., 1 Burlington Plaza Burlington Road, Dublin 4, D04RH96 Ireland) for the provision of services to us. The data is primarily stored in Germany/Europe. For data transfers outside the EU and EEA, Racemap GmbH has concluded the new EU standard contractual clauses with Amazon Web Services Inc. (410 Terry Avenue North, Seattle, WA 98109-5210, USA), which can be accessed at: https://d1.awsstatic.com/Controller_to_Processor_SCCs.pdf.

V. Information on data processing in the "BAUHAUS CCE" app

You can use the "BAUHAUS CCE" app to take part in the BAUHAUS Corporate Challenge Europe and we will use this app to record the distances you have completed and show you your results and the results of other BAUHAUS Corporate Challenge Europe participants. Within this section, we provide information about the data processing that takes place in the app.

1. Log files

When you use the BAUHAUS CCE app, information is automatically sent to us (log files). These include:

  • Type Phone / Telefontyp
  • Operating system of the phone

This data is processed to enable and facilitate the use of the app. In addition, the data is evaluated in anonymised and aggregated form and used in the interest of system security and the technical administration of the network infrastructure. We reserve the right to subsequently review the log data if there is a justified suspicion of unlawful use based on specific indications. These previously described data processing operations are carried out on the basis of our legitimate interests in providing our app offer in a secure manner and in evaluating the use of our app and based on Art. 6 para. 1 S.1 lit. f GDPR. Our legitimate interest is that we want to provide you with the most secure app possible and better understand how you use it so that we can tailor our app offering to you even better.

The storage period of the data described above is usually seven days from the collection of the data. In exceptional cases, the data is stored to clarify suspected cases of unlawful use until the suspicion has been clarified.

The recipient of the personal data contained in log files is our service provider Racemap GmbH (Timaeusstrasse 1, D-01099 Dresden, Germany). Racemap GmbH uses services of Amazon (Amazon Data Service Ireland Ltd., 1 Burlington Plaza Burlington Road, Dublin 4, D04RH96 Ireland) for the provision of services to us. The data is primarily stored in Germany. For data transfers outside the EU and the EEA, Racemap GmbH has concluded standard contractual clauses with Amazon Web Services Inc. (410 Terry Avenue North, Seattle, WA 98109-5210, USA), which can be accessed at the following URL: https://d1.awsstatic.com/Controller_to_Processor_SCCs.pdf.

2. Participation in the challenge via the app

The email sent to you after registering on the website will contain a link with a unique key that the app will use to recognise you and create a link between the information you provided when registering on the website and your use of the app. Please note that you can download the app, but you will not be able to access the challenge without the individual access key. To obtain the access key, you must register via the official website. Only then will you receive the confirmation email with the access key. After clicking the link, you will either be redirected to the place where you can download the BAUHAUS CCE app on your device, or if you have already installed the app, you will be redirected to the BAUHAUS CCE app.

When you open the app, you will be asked to verify your registration in the app by confirming your details (first name and surname or name abbreviation or pseudonym and start number). Using the app, we do not process all the data you provided during registration on the website, but the individual key assigned to you, first name and surname or name abbreviation or pseudonym, as well as the start number and its locations and the routes you cover as part of the challenge. 

If you want to start completing a route intended for the challenge, you can switch on the recording of your location within the BAUHAUS CCE app and switch it off again at the end. The app keeps track of the total kilometres travelled using the GPS geodata whenever you separately activate the recording of your location for the challenge on your smartphone. It is ensured that there are no geographical representations of the completed distance because no maps are activated. As soon as the app detects inactivity, especially if your speed is below 5 km/h or if you are indoors, you will be reminded accordingly to stop tracking. 

The legal basis for data processing is the fulfilment of the participation agreement pursuant Art. 6 para. 1 S. 1 lit. b GDPR. 

The data will be deleted three months after the end of BAUHAUS Corporate Challenge Europe.

The accumulated kilometres as well as the overall progress, can be seen on the results list and the leader board within the app. Furthermore, it is possible that other people who are also participating in the BAUHAUS Corporate Challenge Europe can search for you in this app and view your result if you have registered with your first and last name and not with a name abbreviation or pseudonym. A corresponding list as a PDF is not available for download. 

The legal basis for publishing personal data as part of BAUHAUS Corporate Challenge Europe results and enabling the search function is Art. 6 para. 1 S. 1 lit. f GDPR. Our legitimate interests lie in the publication of participants' results in order to make the results and the overall progress in the Challenge recognisable and the associated presentation of BAUHAUS as a company participating in the BAUHAUS Corporate Challenge Europe. Personal data as part of published results will be removed from the website three months after the end of the BAUHAUS Corporate Challenge Europe.

We operate the BAUHAUS CCE app with the help of the service provider Racemap GmbH (Timaeusstrasse 1, D-01099 Dresden, Germany), the recipient of the data depending on the data provided during registration as well as the consecutive, automatically assigned number and the access key, which are processed through the use of the app. Racemap GmbH uses services of Amazon (Amazon Data Service Ireland Ltd., 1 Burlington Plaza Burlington Road, Dublin 4, D04RH96 Ireland) for the provision of services to us. The data is primarily stored in Germany. For data transfers outside the EU and EEA, Racemap GmbH has concluded the new EU standard contractual clauses with Amazon Web Services Inc. (410 Terry Avenue North, Seattle, WA 98109-5210, USA), which can be accessed at: https://d1.awsstatic.com/Controller_to_Processor_SCCs.pdf.

Our service provider and order processor pursuant to Art. 28 GDPR n plus sport GmbH (Großherzog-Friedrich-Str. 100, D-66121 Saarbrücken, Germany) is the recipient of the results obtained from you in order to prepare evaluations and statistics on the results of individual countries, branches and various groups of persons for us.

VI. Information on the evaluation of results and compilation of statistics

Within this bullet point, we provide information about the data processing that takes place outside the app and the website within the context of the evaluation of results and the creation of statistics.

Outside of the BAUHAUS CCE app and our BAUHAUS Corporate Challenge Europe website, we evaluate the results of the Challenge and create various statistics. For this purpose, we use your result, the country and the branch number of the BAUHAUS company for which you work in order to be able to carry out group-specific evaluations. We carry out the evaluation and compilation of statistics on the basis of Art. 6 para. 1 S. 1 lit. f GDPR. Our legitimate interests lie in the evaluation and finding of correlations and the creation of meaningful statistics that are displayed to the participating persons. The recipient of the personal data used in the evaluation and creation of statistics is our service provider n plus sport GmbH (Großherzog-Friedrich-Str. 100, D-66121 Saarbrücken, Germany), which carries out the evaluation and creation of statistics.

We store personal data as part of evaluations and statistics for a period of three months after the end of BAUHAUS Corporate Challenge Europe. After that, they will be deleted automatically.

As at: 07/2023