Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH
The Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH attaches great importance to the responsible and transparent handling of personal data.
This Privacy Policy provides users of southnorth.global with information about:
- who they can contact regarding data protection,
- what personal data is processed when they visit the website,
- what personal data is processed when they contact us,
- how and for what purposes website usage is analysed, and
- what rights they have with respect to the processing of their personal data.
1. Information on the collection of personal data
General information
The Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG).
Personal data is any information relating to an identified or identifiable natural person. This may include, for example, names, addresses, email addresses, IP addresses and information about website usage.
GIZ processes personal data only to the extent necessary for the operation of southnorth.global and the services provided through the website.
2. Controller and data protection officer
The controller responsible for data processing in connection with this website is:
Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH
Friedrich-Ebert-Allee 32 + 36
53113 Bonn
Germany
and
Dag-Hammarskjöld-Weg 1–5
65760 Eschborn
Germany
For questions specifically concerning data protection, users may contact GIZ’s data protection officer.
datenschutzbeauftragter@giz.de
The original policy identifies GIZ as the controller and provides the Bonn and Eschborn addresses. Eingefügter Text
3. Collection of data when visiting the website
When southnorth.global is accessed, the user’s browser automatically transmits information required to deliver the website and ensure its stability and security.
This may include:
- the page or resource requested,
- IP address of the accessing device,
- referrer URL,
- browser type and version,
- operating system,
- hostname of the accessing device, and
- date and time of the server request.
This processing is necessary for the technically reliable and secure operation of the website.
The legal basis for this processing is Article 6(1)(f) GDPR. GIZ has a legitimate interest in the secure, stable and technically error-free operation of the website.
4. Hosting
The website is hosted by:
Mittwald CM Service GmbH & Co. KG
Königsberger Str. 4–6
32339 Espelkamp
Germany
The hosting provider processes technically necessary server log data in connection with the provision and security of the website.
The server infrastructure used for the website is located within the European Union (EU) or European Economic Area (EEA).
The hosting provider and server-log information is based on the existing GIZ policy and has been confirmed for southnorth.global. Eingefügter Text
5. Cookies and similar technologies
The website uses technically necessary cookies and similar technologies where required for the operation and functionality of the website.
The website uses Complianz to manage cookie information and, where necessary, user consent.
Detailed and up-to-date information about the cookies and technologies used on the website, their purposes and storage periods can be found in the website’s Cookie Policy (EU).
Users can change or withdraw cookie preferences using the cookie settings provided on the website.
Language preference
The website uses Polylang to provide multilingual content. A functional cookie may be used to remember the language selected by the visitor.
6. Matomo web analytics
We use the open-source web analytics software Matomo to obtain statistical information about the use of southnorth.global and to improve the website and the information provided through it.
Matomo is operated locally as part of the website’s WordPress installation. Analytics data is processed within the website’s own Matomo installation and is not transferred to Matomo as an external analytics provider.
Cookieless tracking
Matomo has been configured to operate without analytics cookies. In particular, the usual Matomo visitor-tracking cookies are disabled.
Matomo therefore does not use persistent analytics cookies to recognise visitors across visits.
IP address anonymisation
IP addresses are anonymised for analytics purposes. Matomo is configured to mask two bytes of the visitor’s IP address. The anonymised IP address is also used when processing visits.
This reduces the precision with which visitors can be geographically located and limits the ability to associate analytics information with individual devices.
Referrer information
Referrer information is limited so that only the domain of the referring website is retained rather than the complete referring URL.
Data processed
Depending on the interaction with the website, Matomo may process information such as:
- pages accessed,
- date and time of access,
- anonymised IP address,
- referring domain,
- browser and device information,
- operating system, and
- interactions with website content.
This information is used exclusively for statistical analysis and improvement of the website.
Storage period
Detailed Matomo visitor and action data is configured to be automatically deleted after 180 days.
Aggregated statistical reports are subject to separate retention settings. Detailed reports older than 12 months are deleted in accordance with the configured Matomo retention settings, while selected aggregated metrics may be retained for long-term statistical comparison.
The legal basis for the statistical analysis of website usage is Article 6(1)(e) GDPR in conjunction with Section 3 BDSG, insofar as the processing is necessary for GIZ’s public-interest tasks and public relations activities.
7. Contact by email
Users may contact us by email.
When a user contacts us by email, the personal data contained in the message is processed for the purpose of responding to and handling the enquiry. This includes the user’s email address and any other information voluntarily provided in the message.
The data is used only insofar as necessary to process the respective enquiry.
The legal basis for processing in connection with communication relating to GIZ’s public tasks is Article 6(1)(e) GDPR in conjunction with Section 3 BDSG. Where communication is required for pre-contractual or contractual purposes, Article 6(1)(b) GDPR may apply instead.
The website does not currently provide a contact form, newsletter subscription, user registration or press mailing list.
8. Wordfence
We use Wordfence Security to protect southnorth.global against cyberattacks, malicious access attempts and other security threats.
Wordfence is provided by:
Defiant, Inc.
800 5th Ave, Suite 4100
Seattle, WA 98104
USA
For security purposes, Wordfence may process technical information associated with access to the website, including IP addresses and information relating to potentially malicious requests.
The processing is based on Article 6(1)(f) GDPR. GIZ has a legitimate interest in protecting its website and IT infrastructure against unauthorised access and cyberattacks.
Where personal data is transferred to a recipient outside the EU or EEA, such transfers are subject to the applicable requirements of Chapter V GDPR.
Further information about Wordfence and data protection is available from the provider.
9. Disclosure of personal data
GIZ does not disclose personal data collected through southnorth.global to third parties unless this is necessary for the operation and security of the website, required for the fulfilment of GIZ’s tasks, permitted by law or required by law.
In particular, Matomo analytics data collected through southnorth.global is not shared with UNEP or another project partner for website analytics purposes.
Processors used for the technical operation of the website process personal data only within the scope of the applicable contractual and legal requirements.
10. Transfers to third countries
Where individual service providers process personal data outside the European Union or European Economic Area, such processing takes place only where the requirements of Articles 44 et seq. GDPR are met.
Depending on the recipient and country concerned, this may include an adequacy decision by the European Commission or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
11. Duration of data retention
Personal data is retained only for as long as necessary for the purpose for which it was collected or as required by applicable law.
Specific retention periods are described above where applicable.
In particular, detailed Matomo analytics data is configured for deletion after 180 days.
12. IT security
GIZ attaches great importance to the protection of personal data.
Appropriate technical and organisational security measures are used to protect data against accidental or intentional manipulation, loss, destruction and unauthorised access.
These measures are reviewed and adapted in accordance with technological developments and the risks associated with the processing.
13. Rights of data subjects
Users whose personal data is processed have the rights provided for under the GDPR. Subject to the applicable statutory requirements, these include the right:
- to obtain information about personal data processed by GIZ (Article 15 GDPR),
- to have inaccurate personal data rectified (Article 16 GDPR),
- to have personal data erased (Article 17 GDPR),
- to obtain restriction of processing (Article 18 GDPR),
- to receive personal data in a structured, commonly used and machine-readable format where the requirements of Article 20 GDPR are met,
- to object to processing in accordance with Article 21 GDPR, and
- to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Users also have the right to lodge a complaint with a competent data protection supervisory authority pursuant to Article 77 GDPR.
The existing GIZ policy identifies the Federal Commissioner for Data Protection and Freedom of Information (BfDI) as the competent supervisory authority. Eingefügter Text
Bonn, 2026