Privacy Policy
Heilbronn University of Applied Sciences (hereinafter referred to as "HHN") and its institutions take the protection of your personal data very seriously. We therefore process your personal data in accordance with the applicable statutory data protection requirements for the purposes listed below. Personal data within the meaning of this privacy information is all information that relates to you personally.
Hochschule Heilbronn
a body governed by public law
Represented by the rector Professor Dr.-Ing. Oliver Lenzen
Max-Planck-Str. 39
74081 Heilbronn
Phone: 07131 504-0
E-Mail: info@hs-heilbronn.de
Web: https://www.hs-heilbronn.de/en
We have appointed an external data protection officer at our higher education institution. You are welcome to share confidential data protection concerns directly with them:
External data protection officer:
Maximilian Musch – Deutsche Datenschutzkanzlei
Phone: 07542 949 21-02
E-Mail: musch@ddsk.de
Web: www.ddsk.de
Internal data protection office:
If you have any questions about data protection, please contact the Heilbronn University data protection office at: dsb@hs-heilbronn.de.
The technical terms used in this privacy policy are to be understood as legally defined in Article 4 of the General Data Protection Regulation (GDPR).
The terms "users" and "website visitors" are used synonymously in our privacy policy.
Service providers used (recipients of data) are named under the respective category/heading.
The data subjects fall into two categories: website visitors and other users of online services.
General information on data processing on the website
Our website can be visited without actively providing personal data. However, we automatically store access data (server log files) such as the name of the Internet service provider, the operating system used, the website from which the user visits us, the date and duration of the visit or the name of the requested file, and for security reasons, e.g. to detect attacks on our website, the IP address of the end device used for a maximum period of four weeks. These data are not combined with data from other sources. We process and use the data for the following purposes: provision of the website, prevention and detection of errors/malfunctions, and misuse of the website.
Data categories
Meta and communication data (e.g. IP address, date and time of access, time, type of HTTP request, website from which access is made (referrer URL), browser used and, if applicable, operating system of the accessing computer (user agent))
Purpose of processing:
Prevention and detection of errors/malfunctions, detection of misuse of the website, fraud prevention to detect misuse of the website
Legal basis:
Article 6 paragraph 1 pt. e GDPR (performance of a task carried out in the public interest or in the exercise of official authority vested in the controller).
To enable the use of the basic functions on our website and to provide the service requested by the user, we use cookies on our website. Cookies are a standard Internet technology for storing and retrieving information for website users. Cookies represent information and/or data that can be stored on the user’s device, for example. With traditional cookie technology, the user's browser is instructed to store certain information on the user's end device when a specific website is accessed.
Strictly necessary cookies are used to provide a telemedia service expressly requested by the user, e.g.:
- cookies for error analysis and security purposes
- cookies for storing logins
- cookies for storing data in online forms if the form extends over several pages
- cookies for storing (language) settings
- cookies for storing consent or revocation (opt-in, opt-out)
Some of the cookies used (so-called session cookies) are deleted after the end of the browser session, i.e., after closing the browser. Cookies can be deleted by users afterwards to remove data that the website has stored on the user's computer.
The data processing described may also relate to information that is not personal but constitutes information within the meaning of the German telecommunications telemedia data protection act (Telekommunikation-Telemedien-Datenschutz-Gesetz, TTDSG). Even in these cases, this information may be required for the use of an expressly requested service and may therefore be stored in accordance with section 25 TTDSG.
Purpose:
Storage of opt-in preferences, presentation of the website, ensuring the functionality of the website, maintaining user status across the entire website, recognition for next website visitors, user-friendly online services, ensuring chat function if necessary
Opt-out:
Internet Explorer/Edge:
https://support.microsoft.com/en-us/edge/manage-cookies-in-microsoft-edge-view-allow-block-delete-and-use
Firefox:
https://support.mozilla.org/en-US/kb/how-do-i-turn-do-not-track-feature
https://support.google.com/chrome/answer/95647?hl=en-GB&sjid=13193369226372943420-EU
Safari:
https://support.apple.com/en-gb/105082
Legal basis:
Consent (art. 6 para. 1 pt. a GDPR), performance of a task carried out in the public interest pursuant to art. 6 para. 1 pt. e GDPR.
The relevant legal basis is specifically named with the corresponding tool.
Beyond the required scope, user data may be processed by means of cookies, similar technologies or application-related technologies, e.g. for the purpose of (cross-site) tracking or personalised advertising, etc. This may involve the transfer of data to third-party providers. The storage and further processing of usage data that is not necessary to provide the telemedia service is carried out on the basis of consent within the meaning of art. 6 para. 1 pt. a GDPR (if applicable in conjunction with section 25 para. 1 sentence 2 TTDSG).
We use a consent management process on our website to store and manage the consent given by website visitors in a verifiable manner in accordance with data protection requirements. The consent management platform we use helps us to recognise all cookies and tracking technologies and control them based on the status of consent. At the same time, visitors to our website can use the integrated consent management service to manage the consents and preferences given (optional setting of cookies and other technologies that are not required) or revoke consent at any time by selecting the respective settings.
The status of consent is stored on the server of the subcontractor of our content management system (SCRIVITO CMS from the provider Just Relate) in a cookie (so-called opt-in cookie) in order to be able to assign the consent to a user or their device. The time that consent was given is also recorded.
Data categories:
Consent data (consent ID and number, time consent was given, opt-in or opt-out), meta and communication data (e.g. device information, IP addresses)
Purposes of processing:
Ensuring accountability, consent management
Legal basis:
Legal obligation (art. 6 para. 1 pt. c GDPR in conjunction with art. 7 GDPR)
The higher education institution's websites are hosted by an external service provider. Personal data of users, in particular so-called log files, are stored on the servers of a selected service provider. By using a specialised service provider, the online services are provided securely and efficiently. The hosting provider we use does not process the data for its own purposes. Within our higher education institution, only selected administrators have access to our platform.
We also use a content delivery network (CDN) in order to be able to provide the content of our online services more quickly. When visitors of our website access graphics, lecture scripts or other content, these are provided quickly and in an optimised manner with the help of servers distributed regionally and internationally. When the files are retrieved, a connection is established to the servers of a CDN provider, whereby personal data of the visitors of our online services are processed, for example the IP address, browser data or the user agent.
Data categories:
Usage data (e.g. websites visited, interest in content, access times), meta and communication data (e.g. device information, IP addresses)
Purposes of processing:
Permanent availability of the website for reliable use of our services at all times, high scalability and avoidance of downtime.
Legal basis:
Performance of a task carried out in the public interest pursuant to art. 6 para. 1 pt. e GDPR
Goals & interests:
Proper presentation and optimisation of the website, fast accessibility of the website, avoidance of downtimes, reduction of latency, high scalability
Amazon CloudFront
Recipients: Amazon.com, Inc., server location: The Netherlands
Transfer to third countries: Based on the adequacy decision of the European Commission for the USA and Data Privacy Framework certification
Recipient’s privacy policy:
https://www.amazon.de/gp/help/customer/display.html?nodeId=GX7NJQ4ZB8MHFRNJ&ref_=footer_privacy&language=en_GB
Website support and development
We have commissioned an agency to provide consulting and development for services and applications on our website. This agency supports us in all activities related to the design and functionality of our website and provides us with a content management system (CMS).
In this context, the web design agency selected by us receives the access data for our website in order to make necessary adjustments and changes, such as the design of forms or other programming activities.
Personal data, such as data from forms or log data of website visitors, may also be accessed. The web design agency therefore acts as a processor and acts exclusively on our instructions. Data is not processed for other purposes.
Data categories:
Usage data (e.g. access times), meta and communication data (e.g. device information, IP addresses), contact data (e.g. email address), content data (e.g. text),
Purposes of processing:
Support with web analysis and optimisation, analysis of user behaviour on the website (website interaction) for web optimisation and measuring reach, monitoring website performance
Legal basis:
Performance of a task carried out in the public interest pursuant to art. 6 para. 1 pt. e GDPR
Goals & interests:
Support and assistance with website maintenance through high level of expertise, efficiency through outsourcing
SCRIVITO CMS
Provider: JustRelate Group, Kitzingstraße 15, 12277 Berlin, Germany
Recipient’s privacy policy: https://www.iubenda.com/privacy-policy/49159983 Noch auf deutsch - sollen wir die der Website auf englisch nehmen? https://www.justrelate.com/privacy-policy
Web analysis and optimisation
We use procedures on our website to analyse user behaviour and to measure reach. For this purpose, information about the behaviour, interests or demographic information of visitors is collected in order to determine whether and where our website needs to be optimised or adapted (e.g. forms on the website, improved placement of buttons or call-to-action buttons, etc.).
We can also measure the click and scroll behaviour of website visitors. Among other things, this helps us to recognise at what time our website, its functions or content are most used.
The collection of this data is made possible by the use of certain technologies (e.g. cookies). These are stored on users' end devices as part of client-side tracking when they visit our website.
We take precautions to protect the identity of our website visitors. We do not process any personal data of website visitors for the purposes described.
Data categories:
Usage data (e.g. websites visited, interest in content, access times), meta and communication data (e.g. device information, anonymised IP addresses, location data)
Purpose of processing:
Checking the status of target achievement (success monitoring) of all online activities: Analysis of user behaviour on the website (website interaction) for web optimisation and reach measurement, checking website capacity, lead evaluation, budget control
Legal basis:
Consent (art. 6 para. 1 pt. a GDPR) or the performance of a task carried out in the public interest pursuant to art. 6 para. 1 pt. e GDPR.
Goals & interests:
Optimisation and development of the website: Checking page load times and making adjustments to improve speed, tracking the most frequent click paths of users to understand the customer journey and improve navigation, revising the design to achieve a better user experience, evaluating data on which devices are used to optimise the page, monitoring errors to ensure that it works properly and is error-free
No data is transmitted to the provider. The data is stored on the university’s own server.
You have the option to prevent the actions you take here from being analysed and linked. This will protect your privacy, but will also prevent the site owner from learning from your actions and improving the user experience for you and other users.
Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal basis: Consent (Article 6(1)(a) of the GDPR)
Transfer to third countries: Based on the adequacy decision of the European Commission for the USA and Data Privacy Framework certification
Privacy Policy: https://policies.google.com/privacy?hl=en-US
Online marketing
Our website uses various services and methods for online marketing purposes.
We use search engine marketing methods. Search engine marketing includes all measures that are suitable for improving the visibility of our website in the organic or non-organic search results of search engines, increasing our reach and thus increasing website traffic.
Search advertising can be placed on various external platforms or websites. These ads can be text, display, or video ads and are shown to users.
We first create a search advertising campaign and provide relevant information that is to be recorded by the search engine provider selected by us, e.g. user location, device information and target groups (demographic information). This enables us to gain further insights into the interests of users in our content/products and, if necessary, to identify trends.
Key Word Advertising
In addition, our ad is linked to specific keywords (search terms) that we have defined in advance and to our website. The ad will then also appear to users who search for a specific keyword that we have defined in advance. These are connected to our products or services.
The process is implemented using a cookie or similar technology. When a visitor visits our website or searches for a specific keyword using a search engine (e.g. Google), a cookie or similar technology is set on the website visitor's device. This may include data such as user locations and device information, which is transmitted to the search engine provider's server. The search engine provider aggregates this data and automatically provides us with a statistical analysis of it via a dashboard in our account.
The statistics provide us with information about which of our ads were clicked on, how often and at what price. Since we incur costs for every click on an ad, these clicks are recorded on external platforms and websites using our tracking tool. This recording is used for budget control. We cannot identify individual users on the basis of this information.
Conversion measurement (measuring the success of our ads)
We can determine the success of our advertisements using aggregated data provided to us by the search engine provider (known as conversion tracking). This enables us to track whether a marketing initiative has led to a so-called event (e.g. downloading a PDF or playing a video) or a conversion. The evaluation is provided to us in the form of statistics via our analytics tool and is used to analyse the success of our online activities (performance monitoring). It helps us to identify measures to improve the so-called customer journey.
Information:
Data of the website visitor (e.g. name and email address) can be assigned directly if they are logged into their account with the search engine provider. If the website visitor does not want their profile to be assigned to their activities, they must log out of their account with the search engine provider before visiting our website.
Data categories:
Usage and interaction data (e.g. websites visited, interest in content, access times), meta and communication data (e.g. device information, anonymised IP addresses), location data if applicable, contact data (e.g. email addresses)
Purpose of processing:
Increasing sales and reach, conversion measurement, target group formation, identification of trends for the development of marketing strategies
Legal basis:
Consent (art. 6 para. 1 pt. a GDPR)
Google Adverts
Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Transfers to third countries: Based on the European Commission’s adequacy decision for the United States, together with Privacy Framework certification
Privacy Policy: https://policies.google.com/privacy?hl=en-US
The higher education institution provides information online on various social media platforms (e.g. fan pages).
The higher education institution uses social media channels to increase their visibility among potential students and make themselves visible to the public. Social networks have proven to be useful tools for increasing reach and actively promoting interaction and communication with students.
Communication and press and public relations are core responsibilities of the state’s higher education institutions. Social media activities and communication play a key role in attracting new students. Social media and the website can be used to share relevant information about the degree programmes, inform about upcoming events and communicate important short-term announcements and job advertisements.
User profiles can be created and used based on the usage behaviour of social network users, such as the interests they specify, in order to tailor advertisements to the interests of target groups. For this purpose, cookies are regularly stored on users' end devices, in some cases regardless of whether they are registered users of the social network.
Insights (statistics)
The data evaluated by the social media platform operators is provided to us in the form of anonymised statistics, which no longer contain any personal data of users. We can use the statistics to see, for example, how often and at what time our social media profile was visited. It is currently not possible for fan page operators to deactivate this function. We therefore have no influence on the extent to which data is processed by social media platforms.
Social media messenger
In connection with the use of social media, we use the associated messenger services to easily get in touch with users. Communication via social media channels is an important and essential part of public relations for the higher education institution.
Please note that the security of individual services may depend on the user's account settings. Even in the case of end-to-end encryption, the platform operator can draw conclusions about the fact that and when users communicate with the higher education institution and, if necessary, collect location data.
Depending on where the social network is operated, usage data may be processed outside the European Union or outside the European Economic Area. This can result in risks for users, as it may be more difficult for them to enforce their rights.
We inform users that the higher education institution has no further influence on the processing of personal data on these platforms. Only the respective platform operator has full knowledge of the content of the transmitted data and its use.
Data categories:
User names (e.g. name, address), contact data (e.g. email address, telephone number), content data (e.g. text, photos, videos), usage and interaction data (e.g. websites visited, interests, access times), meta and communication data (e.g. device information, IP address and, if applicable, location data)
Purpose of processing:
Expanding reach, networking with students, promote interaction and communication, press and public relations
Goals & interests:
Ensuring the higher education institution's visibility in society, improving and promoting its public image, interaction and communication on social media, insights into target groups, press and public relations
Recipient: Meta Platforms, 4 Grand Canal Square, Dublin 2, Ireland
Recipient’s privacy policy: https://www.facebook.com/privacy/explanation
and https://www.facebook.com/legal/terms/page_controller_addendum
Opt-out-link: https://www.facebook.com/settings?tab=ads
Recipient: LinkedIn Corporation, 1000 West Maude Avenue, Sunnyvale, CA 94085, USA
Recipient’s privacy policy: https://www.linkedin.com/legal/privacy-policy
Opt-out-link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
TikTok
Recipient: TikTok Inc., 10100 Venice Blvd., Culver City, CA 90232, USA
Recipient’s privacy policy: https://www.tiktok.com/legal/privacy-policy?lang=de (only available in german)
YouTube
Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland
Recipient’s privacy policy: https://policies.google.com/privacy?hl=de&gl=de (only available in german)
Opt-out-link: https://tools.google.com/dlpage/gaoptout?hl=de (only available in german)
Alternative Information and Communication Options:
For alternative information and communication options, please contact us via our postal address given above or the following email address: info@hs-heilbronn.de
We use our social media channels to advertise our programmes, research projects and events. Our aim is to address a broad community that we cannot reach using traditional advertising channels, e.g. offline marketing measures such as flyers. Social media advertising is shown to users in the form of text, display or video ads on their social media channels.
Targeting
As part of our social media channels, we use targeting methods to track certain user activities (interactions) and to ensure that our ads are delivered to specific target groups. We use the methods and technologies of various social media providers. A common technology is the so-called pixel (a snippet of a JavaScript code).
This pixel is included in the source code of our website. It ensures that users' navigation is recorded. When users interact with our website or our ad on social media, pixels record the website visitors and the actions they take (e.g. clicks on ads, bounces on websites) and they save which pages and subpages have been accessed.
The user interactions with our ads are analysed by means of the technologies used. This information is used to show potential students real-time, behaviour-based ads on various social media platforms.
Support with social media marketing
As part of our social media marketing activities, we are supported by an advertising agency (Klick Piloten GmbH, Hermannstraße 5A, 70178 Stuttgart). In this context, we provide the agency with the access data for our website so it can make necessary adjustments and changes, such as the design of forms or other programming activities.
Data categories:
Usage and interaction data (e.g. websites visited, interests, access times), meta and communication data (e.g. device information, IP address, location data if applicable)
Porpose of processing:
Improving reach, reach analysis and statistical evaluations
Legal basis:
Consent (art. 6 para. 1 pt. a GDPR)
Goals & interests:
Ensuring the visibility of the higher education institution in society, information about current degree programmes, target group formation, click tracking, development of strategies to attract new students and employees, for example
Meta Pixel (Facebook Ads and Instagram Ads)
Recipient: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
Privacy policy: https://www.facebook.com/privacy/explanation (only german available)
Opt-out-link: https://www.facebook.com/policies/cookies/ (only german available)
Legal basis: Consent (art. 6 para. 1 pt. a GDPR)
TikTok Pixel (TikTok Ads)
Recipient: TikTok Inc., 10100 Venice Blvd., Culver City, CA 90232, USA
Privacy policy: https://www.tiktok.com/legal/page/row/privacy-policy/en
Legal basis: Consent (art. 6 para. 1 pt. a GDPR)
Functions and elements from third-party providers are integrated on our website. These are, for example, videos, graphics, buttons, maps or posts (hereinafter referred to as content). If website visitors access (e.g. click, play, etc.) this third-party content, information and data is collected and linked to the website visitor's end device in the form of cookies or other technologies (e.g. pixels, JavaScript commands or WebAssembly) and transmitted to the server of the third-party provider used. The third-party provider thereby receives usage and interaction data of the website visitor.
Without this processing activity, it is not possible to load and display third-party content.
In order to protect the personal data of website visitors, we have taken protective measures to prevent the automatic transmission of this data to the third-party provider. Data is only transmitted when users actively use the buttons and click on the third-party content.
Data categories:
Usage data (e.g. websites visited, interests, access time), meta and communication data (e.g. device information, anonymised IP address)
Purpose of processing
Sharing of posts and content, interest and behaviour-based marketing, evaluation of statistics, cross-device tracking, increasing the reach of advertisements in social media
Legal basis:
Consent (art. 6 para. 1 pt. a GDPR)
YouTube
Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Opt-out-link: https://tools.google.com/dlpage/gaoptout?hl=en-GB
or https://myaccount.google.com/
Recipient’s privacy policy: https://policies.google.com/privacy?hl=en-GB&gl=de
Vimeo
Recipient: Vimeo Inc., 555 West 18th Street New York, New York 10011, USA
Opt-out-link: https://vimeo.com/cookie_policy
Recipient’s privacy policy: https://vimeo.com/privacy
On our website, users have the option of subscribing to our newsletter or comparable notifications via various channels (hereinafter referred to as newsletter). We can also send out specific information about events, degree programmes or the higher education institution itself.
In accordance with the statutory provisions, we only send newsletters and other information to recipients who have consented to receive the newsletter.
We occasionally use selected service providers to send our newsletter.
To subscribe to our newsletter, users need to provide an email address. We may collect additional data, such as your name, in order to personalise our newsletter.
Our newsletter will only be sent after the double opt-in procedure has been completed. If users of our online services decide to subscribe to our newsletter, they will receive a confirmation email, which serves to prevent the misuse of false email addresses and to prevent a newsletter subscription after a user’s single, possibly accidental click on the subscription button. Users can unsubscribe from our newsletter at any time. An unsubscribe link (opt-out link) is included at the end of each newsletter.
We are also obliged to provide proof that our subscribers actually wanted to receive the newsletter. For this purpose, we collect and store the IP address and the time of subscription and unsubscription.
Data categories:
Core data (e.g. name, address), contact data (e.g. email address, telephone number), meta and communication data (e.g. device information, IP address), usage data (e.g. interests, access times)
Purpose of processing:
Provision of information and news
Legal basis:
Consent (art. 6 para. 1 pt. a GDPR)
Brevo (formerly Sendinblue)
Recipient: Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin
Recipient's privacy policy: https://www.brevo.com/de/legal/privacypolicy/ (only german available)
Intranet and digital services
We make use of the opportunity to hold online meetings, webinars, courses and events. For this purpose, we use the services of other providers, which we have carefully selected.
When such services are used, data of the participants is processed and stored on the servers of the third-party providers used, insofar as this data is required for the communication process. We ensure that communication via the selected providers is end-to-end encrypted when selecting them.
Data categories:
Core data (e.g. name, address), contact data (e.g. email address, telephone number), content data (e.g. chat texts, etc.), meta and communication data (e.g. device information, IP addresses)
Purpose of processing:
Promoting cross-location collaboration, faster communication
Legal basis:
Consent (art. 6 para. 1 pt. a GDPR)
Cisco Webex Hier jetzt Microsoft!!!!
Empfänger: Cisco Systems, Inc., 170 West Tasman Dr., San Jose, CA 95134, USA
Datenschutz: https://www.cisco.com/c/de_de/about/legal/privacy-full.html
eveeno
Recipient: eveeno, Andreas Bothe, Ellenbogen 8, 91056 Erlangen, Germany
Privacy Policy: https://eveeno.com/de/privacy (only german available)
In order to use the Intranet of the higher education institution, we use an authentication procedure. This requires students or staff at the higher education institution to register on the website using their own login details. It is not possible to register for the Intranet via the website.
The use of the Intranet requires an existing university account. Access data is issued by the higher education institution as part of enrolment and when an employment relationship is established. User handles are generated for the authentication process. Among other things, this is a user ID along with information indicating whether the user is authorised to use the Intranet.
We receive the ID solely for the purpose of authentication. As a rule, the data processed is the access data (email address, user name, password).
Data categories:
User credentials (e.g. username, password, authentication confirmation)
Purpose of processing:
Authentication or verification of authorisation to use the higher education institution's Intranet
Legal basis:
The use of the Intranet and the associated processing of personal data on the platform is based on art. 6 para. 1 pt. e in conjunction with art. 6 para. 3 pt. b GDPR in conjunction with section 4 LDSG and section 2 LHG. Consent to data processing in accordance with art. 6 para. 1 pt. a GDPR can also be the legal basis if the users have given their consent to the platform operator.
Goals & interests:
Provision of a central platform with relevant information on studies and the organisation for use on the higher education institution’s Intranet, transparent mapping of processes for students and legal requirements, process support (e.g. applications, termination of enrolment, etc.)
We offer the option of downloading material (e.g. PowerPoint slides, PDFs, texts and graphics) from our online services in order to provide students with up-to-date and relevant information. In some cases, students can make downloads without this being recorded by our system. In this case, no tracking or statistical analysis is carried out.
Data categories:
Meta and communication data (device information, IP address), usage data (access times, interests)
Purpose of processing:
Provision of an up-to-date overview of the course content or information material of degree programmes as well as information on statutes and examination regulations, etc.
Legal basis:
Art. 6 para. 1 pt. e GDPR (for the performance of a task carried out in the public interest) in conjunction with art. 6 para. 3 GDPR and section 4 LDSG as well as on the basis of the LHG; consent (art. 6 para. 1 pt. a GDPR)
Our website offers the option of contacting us directly or obtaining information through various channels.
When we are contacted, we process the personal data of the person making the enquiry to the extent necessary in order to answer or process it. The data processed may vary depending on how the enquiry is made.
Data categories:
Core data (e.g. first name, last name, student ID number, address), contact data (e.g. email address, telephone number), content data (e.g. text), usage data (e.g. access times), meta and communication data (e.g. device information, IP address)
Purpose of processing:
Processing of enquiries
Legal basis:
Fulfilment or initiation of a contract (art. 6 para. 1 pt. b GDPR); art. 6 para. 1 pt. e GDPR (for the performance of a task carried out in the public interest) in conjunction with art. 6 para. 3 GDPR and section 4 LDSG as well as on the basis of the LHG, if applicable consent (art. 6 para. 1 pt. a GDPR)
Further mandatory information on data processing
We transfer the personal data of visitors of our online services for internal purposes (e.g. for internal administration or in order for the personnel department to comply with legal or contractual obligations). The internal transfer or disclosure of data only takes place to the extent necessary in compliance with the relevant data protection regulations.
It may be necessary for us to share personal data for the performance of contracts or to fulfil a legal obligation. If the data required in this respect is not provided to us, it may not be possible to conclude the contract with the data subject.
If your data is processed in third countries outside the EU/EEA (e.g. USA), we ensure that this is done in accordance with the requirements of art. 44 et seq. GDPR. We take additional measures to ensure the highest possible level of protection for the personal data of data subjects. The guarantee applicable to the third country transfer is specified in the Privacy Policy under the respective recipients.
Recipients may act as processors on our behalf. We have concluded contracts on data processing with them in accordance with art. 28 para. 3 GDPR. This means that the processors may only process your personal data in a manner that we have explicitly instructed them to. Processors take adequate technical and organisational measures to process your data securely and in accordance with our instructions.
We generally store the data of users of our online services for as long as is necessary to provide our service or if storage has been provided for by the European legislator or another legislator in laws or regulations to which we are subject. In all other cases, we erase the personal data after the purpose has been fulfilled, with the exception of data that we must continue to store in order to fulfil legal obligations (e.g. we are obliged to retain documents such as contracts and invoices for a certain period of time due to retention periods under tax and commercial law).
Storage period for required cookies: 30 days
Storage period for non-essential cookies/technologies: 30 days or until the revocation by the data subject
We do not use automated decision-making or profiling in accordance with art. 22 GDPR.
The GDPR is the main source of relevant legal provisions. These are supplemented by national laws of the member states and may apply along with or in addition to the GDPR.
Consent:
Art. 6 para. 1 pt. a GDPR serves as the legal basis for processing activities for which we have obtained consent for a specific purpose.
Contract fulfilment:
Art. 6 para. 1 pt. b GDPR serves as the legal basis for processing activities which are necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Legal obligation:
Art. 6 para. 1 pt. c GDPR serves as the legal basis for processing activities which are necessary for compliance with a legal obligation.
Vital interests:
Art. 6 para. 1 pt. d GDPR serves as the legal basis for processing activities which are necessary to protect the vital interests of the data subject or another natural person.
Public interest:
Article 6 para. 1 pt. e GDPR serves as the legal basis for processing activities which are necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Legitimate interest:
Art. 6 para. 1 pt. f GDPR serves as the legal basis for processing activities which are necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Right of access:
Pursuant to art. 15 GDPR, data subjects have the right to request confirmation as to whether we process data concerning them. They can request information about this data as well as the further information listed in art. 15 para. 1 GDPR and a copy of their data.
Right to rectification:
Pursuant to art. 16 GDPR, data subjects have the right to request the rectification or completion of data concerning them and processed by us.
Right to erasure:
Data subjects have the right under art. 17 GDPR to demand the erasure of data concerning them without undue delay. Alternatively, they can request that we restrict the processing of their data in accordance with art. 18 GDPR.
Right to data portability:
In accordance with Article 20 of the GDPR, data subjects have the right to request a copy of the data they have provided to us and to request that it be transferred to another controller.
Right to lodge a complaint:
Data subjects also have the right to lodge a complaint with the supervisory authority responsible for them in accordance with art. 77 GDPR.
Right to object:
If personal data is processed on the basis of legitimate interests in accordance with art. 6 para. 1 s. 1 pt. f GDPR, data subjects have the right to object to the processing of their personal data in accordance with art. 21 GDPR, provided that there are grounds for this relating to their particular situation or the objection is directed against direct marketing purposes. In the latter case, data subjects have a general right to object, for which no particular situation needs to be specified and appropriate action is taken by us in response.
Withdrawal of consent
Certain data processing operations are only possible with the explicit consent of the data subjects. You have the right to withdraw any consent you have already given at any time. To do so, simply send us an informal message or email to komma@hs-heilbronn.de. The lawfulness of any data processing carried out prior to the withdrawal remains unaffected by the withdrawal.
Our website may contain links to the online services of other providers. We hereby point out that we have no influence on the content of the linked online services or the providers’ compliance with data protection regulations.
We reserve the right to modify this data protection information at any time, in order to comply with applicable data protection regulations and to reflect changes to our online services.
The German Privacy Policy was created by
Deutsche Datenschutzkanzlei – Maximilian Musch
The translation of this Privacy Policy was provided by the University of Mannheim and serves information purposes only. Only the official German version is legally binding. Any differences that may arise in the translation are not binding and have no legal effect for compliance or enforcement purposes.
Further information on data protection
As of 2026-08-13