Data protection
Data protection
SW Healthservices is pleased that you have visited our website and that you are interested in our company and our services. Data protection is more than just lip service for us, which is why we take the protection of your personal data very seriously and handle your data very carefully and confidentially. The current data protection regulations, in particular the General Data Protection Regulation (GDPR), are our top priority.
- Name and address of the person responsible
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection provisions is:
Company: SW Healthservices GmbH
Managing Director: Michael Staudenmeier
Julius-Hölder-Strasse 47
70597 Stuttgart
Email: info@belehrung-ifsg.de
- General information on data processing
1. Definitions
Following the example of Art. 4 GDPR, this data protection notice is based on the following definitions:
- "Personal data" (Art. 4 No. 1 GDPR) is all information relating to an identified or identifiable natural person ("data subject"). A person is identifiable if he or she can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier, location data or with the help of information about his or her physical, physiological, genetic, mental, economic, cultural or social identity characteristics. Identifiability can also be achieved by linking such information or other additional knowledge. The origin, form or embodiment of the information is not important (photos, video or sound recordings can also contain personal data).
- "Processing" (Art. 4 No. 2 GDPR) is any process in which personal data is handled, whether with or without the aid of automated (i.e. technology-based) procedures. This includes in particular the collection (i.e. procurement), recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or other provision, comparison, linking, restriction, erasure or destruction of personal data as well as the change of a target or purpose on which data processing was originally based.
- “Controller” (Article 4 No. 7 GDPR) is the natural or legal person, public authority, agency or other body which alone or jointly with others decides on the purposes and means of processing personal data.
- "Third party" (Article 4 No. 10 GDPR) means any natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons authorised to process the personal data under the direct responsibility of the controller or processor; this also includes other legal entities belonging to the group.
- "Processor" (Art. 4 No. 8 GDPR) is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller, in particular in accordance with its instructions (e.g. IT service providers). In the sense of data protection law, a processor is in particular not a third party.
- “Consent” (Article 4 No. 11 GDPR) of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes in the form of a statement or other unambiguous confirmatory act by which he or she signifies agreement to the processing of personal data concerning him or her.
2. Scope of processing of personal data
We generally only process our users' personal data to the extent that this is necessary to provide a functional website and our content and services. Our users' personal data is generally only processed with the user's consent. An exception applies in cases where prior consent cannot be obtained for actual reasons and the processing of the data is permitted by law.
3. Legal basis for the processing of personal data
If we obtain consent from the data subject for processing personal data, Art. 6 (1) (a) GDPR serves as the legal basis.
When processing personal data that is necessary to fulfill a contract to which the data subject is a party, Art. 6 (1) (b) GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
If the processing of personal data is necessary to fulfill a legal obligation to which our company is subject, Art. 6 (1) (c) GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) (d) GDPR serves as the legal basis.
If processing is necessary to protect a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not outweigh the former interest, Art. 6 (1) (f) GDPR serves as the legal basis for processing.
4. Data deletion and storage period
The personal data of the data subject will be deleted or blocked as soon as the purpose for which they were stored no longer applies. Data may also be stored if this has been provided for by the European or national legislator in EU regulations, laws or other provisions to which the controller is subject. Data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need to continue storing the data for the conclusion or fulfillment of a contract.
However, storage may take place beyond the specified period in the event of an (impending) legal dispute with you or other legal proceedings or if storage is required by legal provisions to which we as the responsible party are subject (e.g. Section 257 HGB, Section 147 AO). If the storage period prescribed by the legal provisions expires, the personal data will be blocked or deleted unless further storage by us is necessary and there is a legal basis for doing so.
- Conditions for the transfer of personal data to third countries
As part of our business relationships, your personal data may be passed on or disclosed to third parties. These may also be located outside the European Economic Area (EEA), i.e. in third countries. Such processing is carried out exclusively to fulfill contractual and business obligations and to maintain your business relationship with us (the legal basis is Art. 6 Para. 1 lit. b or lit. f in conjunction with Art. 44 ff. GDPR). We will inform you about the respective details of the transfer below in the relevant places.
The European Commission has certified that some third countries have data protection comparable to the EEA standard through so-called adequacy decisions (a list of these countries and a copy of the adequacy decisions can be found here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en). In other third countries to which personal data may be transferred, there may not be a consistently high level of data protection due to a lack of legal provisions. Where this is the case, we ensure that data protection is adequately guaranteed. This is possible through binding corporate rules, standard contractual clauses of the European Commission for the protection of personal data in accordance with Art. 46 (1), (2) lit. c GDPR (the standard contractual clauses from 2021 are available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0915&locale-en), certificates or recognized codes of conduct).
- Data security
We use suitable technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties (e.g. TSL encryption for our website), taking into account the state of the art, the implementation costs and the nature, scope, context and purpose of the processing as well as the existing risks of a data breach (including its likelihood and impact) for the data subject. Our security measures are continuously improved in line with technological developments.
III. Data collection on our website
- Description and scope of data processing
Every time our website is accessed, our system automatically records data and information from the computer system of the accessing computer. The following data is collected:
- User’s IP address
- Referrer, date and time of access
- Access method and transmitted input values of the requesting computer
- Access status of the web server (file transferred, not found, command not executed, etc.)
- Name of the requested file
- User’s browser and operating system version
- the IP address of the requesting computer, which is shortened so that a personal reference can no longer be established
- the amount of data transferred
- the operating system
- the message whether the call was successful (access status/Http status code)
- the GMT time zone difference
- Legal basis for data processing
The legal basis for the temporary storage of data is Art. 6 (1) lit. f GDPR.
- Purpose of data processing
The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this purpose, the user's IP address must be stored for the duration of the session.
Our legitimate interest in data processing pursuant to Art. 6 (1) (f) GDPR also lies in these purposes.
- Duration of storage
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. If the data is collected to provide the website, this is the case when the respective session has ended.
- Possibility of objection and removal
The collection of data to provide the website and the storage of data in log files is essential for the operation of the website. Consequently, the user has no option to object.
IV. Inquiries by email or telephone
- Description and scope of data processing
If you contact us by email or telephone, your request, including all personal data resulting from it, will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.
- Legal basis for data processing
This data is processed on the basis of Art. 6 (1) (b) GDPR, provided that your request is related to the fulfillment of a contract or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the request addressed to us (Art. 6 (1) (f) GDPR) or on your consent, if this was requested (Art. 6 (1) (a) GDPR).
- Purpose of data processing
The data is used to process your enquiries and to carry out contractual or pre-contractual measures.
- Duration of storage, possibility of objection and removal
The data you send to us via contact request will remain with us until you request deletion, revoke your consent to storage or the purpose for storing the data no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular statutory retention periods - remain unaffected.
V. Use of cookies
- Description and scope of data processing
Our website uses cookies. Cookies are text files that are stored in the Internet browser or by the Internet browser on the user's computer system. When a user visits a website, a cookie can be stored on the user's operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is visited again.
We use cookies to make our website more user-friendly. Some elements of our website require that the browser that is accessing the website can be identified even after a page change.
- Legal basis for data processing
The legal basis for the processing of personal data using cookies is Art. 6 (1) (f) GDPR.
- Purpose of data processing
The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after changing pages.
The user data collected through technically necessary cookies are not used to create user profiles.
Our legitimate interest in processing personal data for these purposes also lies in accordance with Art. 6 (1) (f) GDPR.
- Duration of storage, possibility of objection and removal
Cookies are stored on the user's computer and transmitted from there to our site. Therefore, as a user, you have full control over the use of cookies. You can deactivate or restrict the transmission of cookies by changing the settings in your Internet browser. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to fully use all of the website's functions.
- Cookies that are not technically necessary
If other cookies (e.g. cookies to analyze your surfing behavior) are stored, these will be treated separately in this privacy policy.
VI. Payment procedure
- Description and scope of data processing
As part of the contractual relationship, the service provider “Shopify” (Shopify Inc., a Canadian corporation with offices at 151 O'Connor Street, Ground floor, Ottawa, ON, K2P 2L8, on behalf of itself, its Singaporean affiliate Shopify Commerce Singapore Pte. Ltd., and its Irish affiliate Shopify International Ltd.) is used to provide efficient and secure payment options. The data processed by the payment service provider includes name, company name, email address, address, bank details (account number or credit card number, PayPal account, AmazonPay account). The information is required to carry out the transactions. The data is only processed by the payment service provider. We have concluded a corresponding data processing agreement with the company Shopify.
- Legal basis for data processing
The legal basis for the processing of personal data using Shopify is Art. 6 (1) (b) GDPR and Art. 6 (1) (f) GDPR.
- Purpose of data processing
The data is processed so that we can provide our online services in a complete and user-friendly manner. The transmission of the data is necessary for the fulfillment of the contract or for the implementation of pre - contractual measures.
- Duration of storage, possibility of objection and removal
The duration of storage of the processed data as well as the rights of those affected can be found in Shopify's privacy policy: https://www.shopify.com/legal/privacy .
- Third country transfer
Personal data may be processed at Shopify’s locations listed above.
To meet GDPR requirements, Shopify relies on the European Commission's adequacy decision for Canada ( https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en ) when Shopify International Limited transfers personal data to its Canadian-incorporated parent company, Shopify Inc.
In addition, Shopify uses comprehensive data transfer and processing agreements (DPAs) that incorporate the latest version of the standard contractual clauses approved by the European Commission ( https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en ) to govern:
- All transfers within the Shopify group
- Further transfers to their sub-processors
All other precautions taken by Shopify to ensure secure data transfer can be found here: https://help.shopify.com/de/manual/privacy-and-security/privacy/international-data-transfers/onward-transfers
VII. Cloud services
- Description and scope of data processing
We use software services accessible via the Internet and running on the servers of their providers (so-called "cloud services") for the storage and management of content (e.g. document storage and management). In this context, personal data may be processed and stored on the providers' servers if they are part of communications with us or are otherwise processed by us as set out in the data protection declaration.
- a) Google Drive
The uploaded identification documents are stored on Google Drive. The following personal data is processed: name, address, date of birth, place of birth, photo, nationality, eye color, height, issuing authority. We have concluded a corresponding data processing agreement with Google Drive.
- b) Airtable
The cloud service Airtable is used to store and access the certificates created. The following personal data is processed by the certificate: name, address, email address, company name, date of birth.
- Legal basis for data processing
The legal basis for the processing of personal data using Google Drive and Airtable is Art. 6 (1) lit. a, b and f GDPR.
- Purpose of data processing
The data is processed in order to properly issue the certificates purchased and send them to the customer. In accordance with standard requirements, the Stuttgart Health Department requires us to identify the person in question in writing using an identification document before we can issue a corresponding certificate.
- Duration of storage, possibility of objection and removal
The duration of storage and the rights of those affected can be found in the privacy policy of Google Drive ( https://policies.google.com/privacy?hl=de ) and Airtable ( https://www.airtable.com/company/privacy/de ).
The uploaded ID document will be deleted no later than 24 hours after verification. The ID document will be verified within 48 hours of its upload.
We will delete the uploaded certificates on Airtable after one year at the latest.
- Third country transfer
- a) Google Drive
The service provider of Google Drive is Google Ireland Limited. However, personal data may also be transferred to the parent company Google LLC. This company is based in the USA. There is an adequacy decision for the transfer of data to the USA. Google LLC is also DPF (Data Privacy Framework) certified. Further details can be found in the privacy policy: https://policies.google.com/privacy?hl=de
- b) Airtable
Airtable's servers are located in the USA, which means that personal data is processed in the USA. The adequacy decision and corresponding standard contractual clauses also serve as the legal basis here. Further details can be found in the privacy policy: https://www.airtable.com/company/privacy/de
VIII. Data collection on our server
- Description and scope of data processing
After one year, we transfer the data stored on Airtable to our own server (US-i-1 based in the USA). This means that the personal data associated with the issuance and storage of the certificate is processed.
- Legal basis for data processing
The legal basis for the processing of personal data using Google Drive and Airtable is Art. 6 (1) lit. b and f GDPR.
- Purpose of data processing
The data is transferred from Airtable to our own server so that the data can be deleted from Airtable after one year at the latest. In order to comply with statutory retention periods and to give you the opportunity to have the certificate sent to you again if it is lost, the data is stored on our server.
- Duration of storage, possibility of objection and removal
The personal data from the issued certificate will remain with us until you request deletion, revoke your consent to storage or the purpose for storing the data no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular statutory retention periods - remain unaffected.
- Third country transfer
The data is processed on a server located in the USA. There is an adequacy decision for the transfer of data to the USA.
IX. Google Analytics
- Description and scope of data processing
We use cookies on our website that enable us to analyze your surfing behavior. For this purpose, we use Google Analytics (Google Ireland Limited, Google Building House, 4 Barrow Street, Dublin D04 E5W5, Ireland). We process data on surfing and purchasing behavior in order to create anonymized statistical evaluations and analyses that help us optimize our processes and workflows. The following data is processed here: IP address, zip code, city. Order data (order ID, shopping cart value, product ID, order period), cookie ID, browser information (browser version, operating system, screen and browser image resolution, device type, browser apps), information about the website and/or ad you previously visited.
We use the code extension "anonymizeIP", which is used to activate IP anonymization on our website. By using this extension, the IP address is shortened within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a server in the USA and shortened there. The IP address transmitted by the browser as part of Google Analytics is not merged with other Google data.
- Legal basis for data processing
The legal basis for the further processing of the personal data collected by means of the analysis cookies is your consent in accordance with Art. 6 (1) (a) GDPR. Insofar as the purpose of the processing is fraud prevention/abuse prevention, prevention and control when using our online shop, the legal basis is our legitimate interest in accordance with Art. 6 (1) (f) GDPR.
- Purpose of data processing
The purpose of the processing is to analyze the surfing behavior of website visitors in order to improve our website and our offering.
- Duration of storage, possibility of objection and removal
The data is stored for a maximum of 6 months. The rights of those affected can be found in Google's privacy policy ( https://policies.google.com/privacy?hl=de ).
- Third country transfer
The service provider of Google Analytics is Google Ireland Limited. However, personal data may also be transferred to the parent company Google LLC. This company is based in the USA. There is an adequacy decision for the transfer of data to the USA. Google LLC is also DPF (Data Privacy Framework) certified. Further details can be found in the privacy policy: https://policies.google.com/privacy?hl=de
X. Google Tag Manager
- Description and scope of data processing
The Google Tag Manager is a tag management system that allows us to integrate and manage code snippets such as tracking codes or conversion pixels on our website. The following personal data is collected but not stored: name, address, date of birth, email address
- Legal basis for data processing
The legal basis for the processing of the personal data collected is your consent in accordance with Art. 6 (1) (a) GDPR.
- Purpose of data processing
The purpose of data processing is to transmit the data and to implement and manage tracking tags on websites. The tag manager enables the efficient management and implementation of various tracking tags on websites without having to make direct code changes. No data is stored.
- Duration of storage, possibility of objection and removal
No data is stored. The tag manager is used exclusively for data processing and transmission. The rights of those affected can be found in Google's privacy policy ( https://policies.google.com/privacy?hl=de ).
- Third country transfer
The service provider of Google Tag Manager is Google Ireland Limited. However, personal data may also be transferred to the parent company Google LLC. This company is based in the USA. There is an adequacy decision for the transfer of data to the USA. Google LLC is also DPF (Data Privacy Framework) certified. Further details can be found in the privacy policy: https://policies.google.com/privacy?hl=de
XI. Rights of the data subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller.
1. Right to information
You can request confirmation from the controller as to whether personal data concerning you are being processed by us.
If such processing takes place, you can request the following information from the controller:
(1) the purposes for which the personal data are processed;
(2) the categories of personal data being processed;
(3) the recipients or categories of recipients to whom the personal data concerning you have been or will be disclosed;
(4) the planned duration for which the personal data concerning you will be stored or, if specific information is not possible, the criteria for determining that period;
(5) the existence of a right to rectification or erasure of personal data concerning you, a right to restriction of processing by the controller or a right to object to such processing;
(6) the existence of a right to lodge a complaint with a supervisory authority;
(7) all available information as to their origin, where the personal data are not collected from the data subject;
(8) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.
You have the right to request information as to whether the personal data concerning you will be transferred to a third country or to an international organization. In this context, you can request to be informed of the appropriate guarantees in accordance with Art. 46 GDPR in connection with the transfer.
2. Right to rectification
You have the right to request rectification and/or completion from the controller if the personal data concerning you that are processed are incorrect or incomplete. The controller must carry out the rectification immediately.
3. Right to restriction of processing
You can request the restriction of the processing of personal data concerning you under the following conditions:
(1) if you contest the accuracy of the personal data concerning you for a period enabling the controller to verify the accuracy of the personal data;
(2) the processing is unlawful and you oppose the erasure of the personal data and request the restriction of the use of the personal data instead;
(3) the controller no longer needs the personal data for the purposes of the processing, but you require them to assert, exercise or defend legal claims, or
(4) if you have objected to processing pursuant to Art. 21 (1) GDPR and it has not yet been determined whether the legitimate reasons of the controller outweigh your reasons.
If the processing of personal data concerning you has been restricted, these data may – with the exception of storage – only be processed with your consent or for the establishment, exercise or defence of legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
If the restriction of processing has been restricted in accordance with the above-mentioned requirements, you will be informed by the controller before the restriction is lifted.
4. Right to erasure
a) Obligation to delete
You may request that the controller delete the personal data concerning you immediately and the controller is obliged to delete this data immediately if one of the following reasons applies:
(1) The personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed.
(2) You withdraw your consent on which the processing is based according to Art. 6 (1) (a) or Art. 9 (2) (a) GDPR, and there is no other legal basis for the processing.
(3) You object to the processing pursuant to Art. 21 Para. 1 GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21 Para. 2 GDPR.
(4) The personal data concerning you have been processed unlawfully.
(5) The erasure of personal data concerning you is necessary to fulfil a legal obligation under Union or Member State law to which the controller is subject.
(6) The personal data concerning you were collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.
b) Information to third parties
If the controller has made the personal data concerning you public and is obliged to erase them pursuant to Art. 17 Para. 1 GDPR, the controller shall take appropriate measures, including technical ones, taking into account the available technology and the implementation costs, to inform data controllers which process the personal data that you, as the data subject, have requested the erasure by them of all links to these personal data or of copies or replications of these personal data.
c) Exceptions
The right to erasure does not exist if processing is necessary
(1) to exercise the right to freedom of expression and information;
(2) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(3) for reasons of public interest in the area of public health pursuant to Art. 9 (2)(h) and (i) and Art. 9 (3) GDPR;
(4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Art. 89 (1) GDPR, insofar as the right referred to in section a) is likely to render impossible or seriously compromise the achievement of the objectives of that processing, or
(5) to assert, exercise or defend legal claims.
5. Right to information
If you have asserted your right to rectification, erasure or restriction of processing vis-à-vis the responsible party, this party is obliged to inform all recipients to whom the personal data concerning you were disclosed of said rectification, erasure or restriction of processing, unless doing so should prove impossible or involve disproportionate expenditure.
You have the right to be informed by the controller about these recipients.
6. Right to data portability
You have the right to receive the personal data concerning you that you have made available to the controller in a structured, common and machine-readable format. In addition, you have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was made available, provided that
(1) the processing is based on consent pursuant to Art. 6 (1)(a) GDPR or Art. 9 (2)(a) GDPR or on a contract pursuant to Art. 6 (1)(b) GDPR and
(2) the processing is carried out by automated means.
In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another, where technically feasible. This must not affect the freedoms and rights of other persons.
The right to data portability does not apply to the processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
7. Right of objection
You have the right to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR, for reasons related to your particular situation; this also applies to profiling based on these provisions.
The controller will no longer process the personal data concerning you unless he can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing serves to assert, exercise or defend legal claims.
If the personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such advertising; this also applies to profiling insofar as it is related to such direct marketing.
If you object to processing for direct marketing purposes, the personal data concerning you will no longer be processed for these purposes.
In connection with the use of information society services, you have the option of exercising your right of objection by means of automated procedures that use technical specifications, regardless of Directive 2002/58/EC.
8. Right to revoke the declaration of consent under data protection law
You have the right to revoke your consent to data protection at any time. The revocation of the consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.
9.Automated decision-making in individual cases, including profiling
You have the right not to be subjected to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you. This shall not apply if the decision
(1) is necessary for the conclusion or performance of a contract between you and the controller,
(2) is permitted by Union or Member State law to which the controller is subject and which contains appropriate measures to safeguard your rights and freedoms as well as your legitimate interests, or
(3) with your express consent.
However, these decisions must not be based on special categories of personal data pursuant to Art. 9 (1) GDPR, unless Art. 9 (2)(a) or (g) GDPR applies and appropriate measures to protect your rights and freedoms as well as your legitimate interests have been taken.
In the cases referred to in (1) and (3), the controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.
10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or place of the alleged infringement if you consider that the processing of personal data concerning you infringes the GDPR.
A list of supervisory authorities (for the non-public sector) with addresses can be found at https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html