DFL Deutsche Fußball Liga GmbH, Guiollettstr. 44-46, D-60325 Frankfurt am Main ("DFL") collects, processes and uses personal data which has been captured from visits to the websites www.bundesliga.de and www.bundesliga.com (collectively the "website") in compliance with the applicable data protection provisions of the Federal Republic of Germany. This Data Protection Policy Statement sets out which visitor ("user") data is captured on the website and how this information is processed and used.
1. Personal data
Personal data is all data containing information about the personal or material circumstances of an identified or identifiable natural person. This includes, for example, name, email address, home address, phone number or date of birth.
2. Data collection, processing and use when the website is accessed over the internet
Each time a user accesses the website, the user's internet browser, for technical reasons, automatically supplies the following data to the DFL's web server:
- IP address of the computer
- date and time of access
- name and URL of file downloaded
- amount of data transmitted
- access status (file transmitted, file not found, etc.)
- data identifying internet browser software and operating system used
- name of internet access provider of user
- website from which the access was made
The collection, processing and use of this information is solely for the purpose of enabling the use of the website (connection set-up), system security and technical administration of the network infrastructure. No comparison with other datasets or any transfer of the collected data to third parties, even partial transfer, is carried out.
With regard to data collection, processing, and use for the purpose of optimizing the website through web analytics and the creation of user profiles, additional reference is made to Section 4 of this Data Protection Policy Statement.
3. Data collection, processing and use within the scope of the Services offered on the Website
The use of certain services on the Website, especially the Bundesliga Newsletter, the Official Fantasy Bundesliga and the Official Bundesliga Predictor, as well as newsletters with product information and other information from partners and licensees of the DFL, requires prior registration, including the submission of personal data (name, residential address, telecommunications data, etc.) by the User ("Services").
The collection, processing and use of these personal data are carried out solely for the purpose of providing the User with the information and Services and only in the manner and extent to which the User has given prior express consent.
Any further use of such personal data for the purpose of sending additional product and service offerings, especially by DFL's cooperation partners, only takes place if the user has given prior express consent. The User can revoke consent at any time with effect for the future.
The following is a description of the basis of the data processing for the Services that are subject to registration:
3.1 Registration and Login
The DFL uses the Customer Identity Management Platform provided by Gigya Inc., 855 El Camino Real, Palo Alto, CA 94301 ("Gigya") for the registration for the Services and the login. The use of these data will only be processed for the purposes of enabling the use and the technical administration of the Service(s) selected by the User. The legal basis for processing is § 4 para. 1 German Data Protection Act [Bundesdatenschutzgesetz, "BDSG"] (consent) and § 28 para. 1 sentence 1 no. 1 BDSG (contract performance).
3.2 Social Logins
The social login function which is also provided by Gigya allows the User to log in with his/her social media account at Facebook or Twitter. The legal basis for processing is § 4 para. 1 BDSG (consent). The following privacy notices regarding the data transmission apply in addition to Clause 5 of this Privacy Statement for sharing the Website’s content.
3.2.1 FacebookIf the User logs in using Facebook, the following data transfers will take place:
- The transmission of information and user data (visited pages, activated fields) to Facebook, with the possibility for Facebook to merge these data with the data relating to the User. Data will then also be transmitted to the US with possible data access by national security authorities without ensuring an European level of data protection. Facebook is a registered member of the EU-US Privacy Shield
- The transmission of certain information from the User’s Facebook account to the DFL with the consequence that in addition to the data outlined in this Privacy Statement (IP address), the following information is transmitted to the DFL:
- Profile picture,
- first name and last name,
- email address,
- birth date,
- language and
- time zone.
IF THE USER DOES NOT WANT TO SHARE THIS INFORMATION, THE USER SHOULD USE THE REGULAR LOGIN VIA THE PASSWORD GENERATED BY HIM OR HER.
If the User logs in using Twitter, the following data transfers will take place:
- The transmission of information and user data (visited pages, activated fields) to Twitter with the possibility for Twitter to merge these data with the data relating to the User. Data will then also be transmitted to the US with possible data access by national security authorities without ensuring an European level of data protection. Twitter is a registered member of the EU-US Privacy Shield.
- The transmission of certain information from the User’s Twitter account to the DFL with the consequence that in addition to the data (IP address) outlined in this Privacy Statement (IP address) the following information is transmitted to the DFL:
- Profile picture,
- first name and last name and
IF THE USER DOES NOT WANT TO SHARE THESE INFORMATION THE USER SHOULD USE THE REGULAR LOGIN VIA THE PASSWORD GENERATED BY HIM OR HER.
3.3 "Keep me logged in" Function
When the User selects the function "Remember me", his/her login (email address, password) will be stored. After the end of a session (either through logging out or by clearing the User's browser’s history and cache) or at least after six months, the User must log in again. In order to prevent unauthorized account access, the User should not choose this function on a computer or device also used by others. If the User does not select this function, the User will be logged out automatically when closing his/her browser.
3.4 Special terms and conditions for specific services
The User has been informed in detail about the nature, scope, location and purpose of the collection, processing and use of the personal data. The users of the Bundesliga Newsletter are assigned a UserID, which allows the DFL to determine when the respective Bundesliga Newsletter was opened and which links or functions from the respective Bundesliga Newsletter were activated. This tracking (tracing) takes place for the internal optimization of the Bundesliga Newsletter. These data will not be disclosed. The legal basis for this data processing is § 15 para. 3 German Telemedia Act ["Telemediengesetz", TMG]. If the User of the Bundesliga Newsletter does not want this tracking to take place, he/she can unsubscribe from the Bundesliga Newsletter.
3.4.2 Official Fantasy Bundesliga and Official Bundesliga Predictor
The User has agreed that in a case of winning, his/her first name and the first letter of his/her surname, as well as the country will be published in the official tele-media and/or social media of DFL, as well as that the ranking lists of the Official Fantasy Bundesliga and the Official Bundesliga Predictor are available on the Website. Regarding the Official Bundesliga Predictor this also applies to the Users' predictions.
4. Data collection, processing and use in the context of web analytics, creation of user profiles and measuring range
Without the separately issued, express consent of the user, no data collected using e-Tracker technology will be used to identify the user personally, nor will it be combined with any personal data relating to the holder of the pseudonym. The user may object to the collection and processing of data for web analytics and creation of user profiles under the following link at any time and with effect for the future by setting up an opt-out cookie
4.1 Web analysis by Google Analytics
The information generated by the cookie about the user’s use of the website (including the user’s IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information on the DFL’s behalf for the purpose of evaluating the user’s use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate the user’s IP address with any other data held by Google.
The DFL has followed the procedures recommended by the German Data Protection Authorities to protect the user’s privacy, including measures to anonymise/shorten the user’s IP address as far as possible ( see the English version). Therefore the user’s IP address will be shortened by the "IP-Anonymise"-function for the use within the European Union/European Economic Area, only in exceptional cases will the full IP address be transferred to and shortened in the United States The user may refuse the use of his/her data using a browser plugin provided by Google by following this link.
Further information about the Google privacy terms can be found under the following links: Google Analytics Terms of Service or Google Analytics Overview. Please note that on this website, Google Analytics code is supplemented by "gat._anonymizeIp();" to ensure an anonymized collection of IP addresses (so called IP-masking).
4.2 Web analysis for targeted, group appropriate fade-in of online advertising
An application from the companies nugg.ad AG, AdAudience and Criteo are used to direct advertising fade-ins on the website. This application helps to analyse the user behaviour in order to be able to fade in advertising tailored to the user's interests (so-called "predictive behaviour targeting"). Anonymised user data is collected for this purpose and compared with already existing data from polling, e.g., concerning socio-demography or product interests. Cookies are used to collect user data anonymously. It is not possible to draw conclusions about personal data of the user by means of cookies. Furthermore, the user can configure the settings of the user's internet browser so that cookies are rejected or directly deleted. In any event, the user can object to the anonymized collection of user data for directing advertising fade-ins under the applications by setting an opt-out cookie at any time with effect for the future under the following links Nugg.ad AG, AdAudience GmbH, Criteo GmbH.
4.3 Range measurement with "scalable central measurement procedure"
DFL also uses the so-called scalable central measurement procedure (SCM) of INFOnline GmbH which has been retained by the DFL in accordance with § 11 German Data Protection Act in order to statistically measure the use of the DFL website (range measurement). Anonymous measurement values are collected for this purpose in order to statistically determine the use intensity and the number of users of the website. In the course of this range measurement, a cookie with the designation "ivwbox.de" is normally used to identify the inquiring computer. The cookie receives a random, internally issued sequence of numbers which cannot be attributed to any specific person and is instead issued anonymously. The validity of the cookie is limited to one year. If the user's internet browser does not permit cookies, an identification number with the designation "signature" is created on the basis of an anonymised IP address created by cutting off its last numbers and the used internet browser. The complete IP address is not stored and instead even the anonymised IP address is immediately deleted after processing. Furthermore, encryption prevents any conclusion about the identity of the user from being derived from the identification number. The use statistics are provided to website operators which are members of the Information Association for the Determination of the Distribution of Advertising Media (Informationsgemeinschaft zur Feststellung der Verbreitung von Werbeträgern e.V.) ("IVW" - www.ivw.eu) or which participate in the study "internet facts" of the Online Research Working Group (Arbeitsgemeinschaft Online-Forschung e.V.) ("AGOF" - www.agof.de) and the user statistics are published monthly by AGOF and the Working Group for Media Analysis (Arbeitsgemeinschaft Media-Analyse e.V.) as well as IVW. Anyone can review the statistics at http://www.agof.de/home.564.en.html, http://www.agma-mmc.de and http://www.ivw.eu. The DFL is a member of IVW and participates in the study "internet facts" of AGOF. The user can object to the collection, processing and use of data for range measurement under the SCM at any time with effect for the future by setting an opt-out cookie at the following link.
4.4 Web analysis for carrying out A/B and multivariate testing
Further information about the way of functioning of this web analytics service can befound under the following link: https://www.optimizely.com/privacy/
4.5 Web analysis for statistically analysis of the speed of the website
Furthermore, the DFL uses a plugin of the performance analysis service of New Relic Inc. (“New Relic”) which enables the DFL to statistically analyse the speed of the website.
When a user visits a page of this website which contains such a plugin, his/her browser builds a direct connection to the servers of New Relic. Therefore, the DFL has no influence on the scope of data collected by New Relic and informs the user according to its current information.
By integrating the plugin, New Relic receives the information that a user has accessed the corresponding page of the website. If the user is logged in at New Relic, New Relic may assign the user’s visit to the website to his/her account at New Relic. If a user is not a member of New Relic, there is still the possibility that New Relic will detect and store his/her IP address.
If a user is a member of New Relic and does not want New Relic to collect data about them in order to combine them with the member data stored by New Relic, the user must logout of New Relic before visiting the website.
5. Use of social media platforms Facebook, Twitter, Google+ and WhatsApp
The DFL provides users of the website with the opportunity to share the website's content on social media services provided by Facebook, Twitter, Google+ and WhatsApp. To this end, social plugins from the providers of the three aforementioned platforms have been made available.
The use of these plugins will normally result in the transfer of data to Facebook, Twitter or Google+ with each page visit, without the user's explicit permission. Along with the web address of the page visited, an identifier will also be transmitted which enables a direct connection to be made between the user and his/her profile on the platform in question.
The platform operators do not pass on any specific details pertaining to what other data is transmitted. The platform providers are moreover constantly developing their services and make available information as to how the accompanying data is used. The currently valid data protection regulations of the platform providers can be found here: Facebook, Twitter, Google+ and WhatsApp.
In order to prevent any unwanted transmission of users' data to Facebook, Twitter, Google+ and WhatsApp and to give users a choice as to whether they wish to use social media services, the DFL only offers social sharing links. This ensures no data will be transferred to third parties without the express permission of the user. Only when the user activates the social media services, therefore consenting to connect with Facebook, Twitter, Google+ and WhatsApp, the contact with their services will be established and the social sharing links provided.
6. Live blogs and news tickers
The DFL uses the service "ScribbleLive" from Scribble, Inc. (Canada) ("Scribble") for content involving live blogs or news tickers.
When a User visits a page with a live blog or news ticker, his/her browser establishes a direct link to Scribble’s server. The User’s IP address and other device-related information are communicated. Scribble and any of its sub-processors have pledged to abide by European data protection laws. The live blog or news ticker also places temporary cookies on the User’s hard drive. This allows the User to take advantage of the live blog or news ticker’s interactive features. Tracking cookies, which allow the formation of user profiles, are not employed on the Website where the ScribbleLive service is embedded.
7. Feedback service
8. Online quizzes, surveys and other interactive content
The DFL uses a plugin from Apester Ltd. (Tel Aviv) ("Apester") to create and to offer online quizzes, surveys and other interactive content. If a User participates in such an online quiz, survey or other interactive content, Apester could collect certain information (e.g. IP addresses, device-related information) which can be considered as personal data under the applicable data privacy laws.
Further information about the collection and of the processing of this information through Apester can be found under the following link: http://apester.com/privacy/
9. Purpose of processing and use of personal data
Any processing or use of a user's personal data is only for the purposes stated in this Data Protection Policy Statement and only to the extent necessary to achieve the respective purposes. Personal data will not be published by DFL, nor will it be passed on to third parties without authorisation. Transmission of personal data to government institutions and authorities will only be carried out within the framework of mandatory national legislation or if the transmission is necessary for legal or law enforcement purposes as a result of attacks on the network infrastructure.
10. Retention and deletion of personal data
As soon as it is no longer needed for the purposes for which it was collected or as soon as the User requests so, all personal data stored and all pseudonymised usage data will be directly and irretrievably deleted; this will be the case, provided that the DFL is not under a statutory duty to store the data. If the DFL is under a statutory duty to store the data, the stored personal information and the pseudonymised usage data will be permanently deleted upon expiry of the relevant statutory retention periods.
The DFL uses technical and organisational security measures to protect the personal data of Users from accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. These security measures are continually being updated in line with technological developments.
12. Links to other websites
The website may contain links to other websites. This Data Protection Policy Statement applies solely to the website of DFL. The DFL has no influence over, and does not control whether other providers comply with applicable data protection provisions.
13. Right of information, rectification, blocking or deletion of data
Users of the website have a right to receive information with regard to the personal data collected concerning them. They also have a right to rectification of inaccurate data, as well as blocking or deletion of data. To contact DFL, click here.
14. Acceptance, validity, and timeliness of the Data Protection Policy Statement
By using the website, the user agrees to the collection, processing, and use of his/her data, as described in this Data Protection Policy Statement. This Data Protection Policy Statement is currently valid and dated as of 26 July 2017. DFL reserves the right to change this Data Protection Policy Statement at any time as needed with effect for the future, especially in order to adapt it to the further development of the website or the implementation of new technologies.