Terms
The technical terms used in this privacy policy are to be understood as legally defined in Article 4 of the GDPR.
Principles governing the collection and processing of personal data
In principle, it is possible to use our website without providing any personal data. However, if you wish to make use of specific services offered by our company via our website, the processing of personal data may be necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we will obtain the consent of the data subject.
Automated data collection
You can visit our website without actively providing any personal details. However, whenever you access the website, we automatically store access data (server log files) such as the name of your internet service provider, the operating system used, the website from which you are visiting us, the date and duration of your visit, or the name of the file requested; and, for security reasons – for example, to detect attacks on our websites – the IP address of the computer used, which is stored for a period of 7 days. This data is analysed solely to improve our services and does not allow any conclusions to be drawn about your identity. This data is not combined with other data sources. The legal basis for the processing of the data is Article 6(1)(f) of the GDPR. We process and use the data for the following purposes:
1. Provision of Christian Thies’s website,
2. Improving our websites and
3. Prevention and detection of errors, malfunctions and misuse of the websites.
Data processing of this kind is carried out either to fulfil the contract governing the use of Christian Thies’s website, or because we have a legitimate interest in ensuring the functionality and fault-free operation of Christian Thies’s website, as well as in adapting these web pages to users’ requirements.
Use of Google services
To make your visit to our website more engaging and to simplify your use of certain features, we use Google programmes that rely on cookies. The use of these Google programmes serves our legitimate interest, in accordance with Article 6(1)(f) of the GDPR, in making your visit to our website clear, straightforward and as pleasant as possible for you. Google’s privacy policy can be found at https://policies.google.com/privacy?hl=de read up on.
Google services
Google Web Fonts
We use the Web Fonts application on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter ‘Google’). The service is used to display a system font in a web application. When you visit the page, the web fonts are transferred to your browser’s cache and made available for display. In doing so, data relating to the website and your IP address is transmitted to Google’s server. You can configure your browser settings to prevent fonts from being loaded from Google’s servers. The terms of use for Google Web Fonts can be found at https://developers.google.com/fonts/faq?hl=de-DE&csw=1 You can find general information on data protection at Google at http://www.google.com/intl/de-DE/policies/privacy/
Retention period
As a general rule, we retain your data for as long as is necessary to provide our services, or where this is required by European directives and regulations or by any other legislative body in laws or regulations to which the data controller is subject. In all other cases, we will erase your personal data once the purpose for which it was collected has been fulfilled, with the exception of data which we are required to retain in order to comply with legal obligations (for example, we are obliged under tax and commercial law retention periods to retain documents such as contracts and invoices for a certain period).
Technical safety
Christian Thies employs technical and organisational security measures to protect the data we manage on your behalf against accidental or deliberate manipulation, loss, destruction or access by unauthorised persons. Our security measures are continuously improved in line with technological developments. For security reasons and to protect the transmission of confidential content – such as enquiries you send to us as the website operator – this site uses SSL (Secure Socket Layer) encryption in conjunction with the highest encryption level supported by your browser. This is usually 256-bit encryption. If your browser does not support 256-bit encryption, we will use 128-bit v3 technology instead. You can tell whether a particular page on our website is being transmitted in an encrypted form by the fact that the browser’s address bar changes from „http://“ to „https://“ and by the padlock icon in your browser bar. When SSL encryption is enabled, the data you send to us cannot be read by third parties. Please note that data transmission over the internet (e.g. when communicating by email) may be subject to security vulnerabilities. It is not possible to guarantee complete protection of data against access by third parties.
Legal basis for processing
Article 6(1)(a) of the GDPR serves as our legal basis for processing operations for which we have obtained consent for a specific purpose of processing.
If the processing of personal data is necessary for the performance of a contract to which the data subject is a party – as is the case, for example, with processing operations required for the delivery of goods or the provision of any other service or consideration – then the processing is based on Article 6(1)(b) of the GDPR. The same applies to processing operations necessary for the implementation of pre-contractual measures, such as in cases of enquiries regarding our products or services.
Where we are subject to a legal obligation which requires the processing of personal data, such as to fulfil tax obligations, the processing is based on Article 6(c) of the GDPR.
Where the processing of personal data is necessary to protect the vital interests of the data subject or of another natural person, the processing is based on Article 6(1)(d) of the GDPR.
The processing of data may also be carried out on the basis of Article 6(1)(e) of the GDPR in conjunction with Article 6(3) of the GDPR and Section 4 of the Baden-Württemberg State Data Protection Act (LDSG), in the version applicable from 21 June 2018, as well as on the basis of the Baden-Württemberg State Higher Education Act (LHG) and the Higher Education Data Protection Regulation in the context of study and teaching at the university.
Ultimately, processing operations may be based on Article 6(f) of the GDPR. Processing operations are based on this legal basis where the processing is necessary to safeguard a legitimate interest of ours or of a third party, provided that the interests, fundamental rights and fundamental freedoms of the data subject do not take precedence.
Rights of data subjects
Under Article 15 of the GDPR, you have the right to request confirmation as to whether we are processing data relating to you. You may request access to this data, as well as the further information set out in Article 15(1) of the GDPR, and a copy of your data.
In accordance with Article 16 of the GDPR, you have the right to request the rectification or completion of the data relating to you that we process.
You have the right, under Article 17 of the GDPR, to request the immediate erasure of data relating to you. Alternatively, you may request that we restrict the processing of your data, in accordance with Article 18 of the GDPR.
Under Article 20 of the GDPR, you have the right to request that the data you have provided to us be made available to you and to request that it be transferred to another data controller.
You also have the right to lodge a complaint with your competent supervisory authority in accordance with Article 77 of the GDPR.
Withdrawal of your consent to data processing
Some data processing operations are only possible with your explicit consent. You have the option to withdraw any consent you have already given at any time. To do so, simply send an informal notification to christian.thies@reutlingen-university.de by email to us. The lawfulness of any data processing carried out up to the point of withdrawal remains unaffected by the withdrawal.
External links
On our website, you will find links to the websites of other providers. We hereby point out that we have no influence over the content of the linked websites or over the providers’ compliance with data protection regulations.
Use of web analytics tools
To understand how our website is used and to improve it, we use the web analytics tool Plausible Analytics. Plausible does not set any cookies, does not store any information in the browser, and generally does not collect any personal data. You can find more information about Plausible and the tool’s privacy policy here. Service provider: OÜ Plausible Insights, Västriku tn 2, Tartu 50403, Estonia; Website: https://plausible.io/, Data protection: https://plausible.io/data-policy.
Changes to our privacy policy
We reserve the right to amend this privacy policy at any time in the event of changes to our website and in accordance with the applicable data protection regulations, to ensure that it complies with legal requirements.
Contact details of the data controller and the external data protection officer
Data controller:
Christian Thies, Alteburgstraße 150, 72762 Reutlingen
Tel.: 07121 271 4076
Email: christian.thies@reutlingen-university.de
External Data Protection Officer:
German data protection law firm
Maximilian Musch
Tel.: 07542 949 21 02
Email: musch@ddsk.de