Privacy Policy
- Information on the Controller/Data Protection Officer
- General information on Processing Personal Data
- Provision of the Website and Creation of Log Files
- Use of Cookies
- Contact by Email
- Forms and Contact
- Booking of Consultation Appointments
- Newsletter Dispatch
- Newsletter-Tracking
- Online-Marketing
- Integration of Social Media and Third-Party Content
- Your Rights/Right of Appeal
- Transfer to Third Countries
- Further Information
1. Information on the Controller/Data Protection Officer
1.1 Name and Address of the Controller
The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection regulations is the
Technical University of Munich
represented by the President Prof. Dr. Thomas F. Hofmann
Arcisstr. 21
80333 Munich
Munich, Germany
Phone: 089/289-01
E-mail: poststelle(at)tum.de
Website: www.lll.tum.de
1.2 Name and Address of the Data Protection Officer
Data Protection Officer of the Technical University of Munich
Postal address: Arcisstr. 21, 80333 München
Tel.: 089/289-17052
Mail: beauftragter(at)datenschutz.tum.de
2. General information on Processing Personal Data
2.1 Scope of Data Processing
We only collect and use our users’ personal data insofar as this serves to fulfill the public tasks assigned to us by law, in particular to inform the public. This also includes the provision of a functional website as well as our content and services. The collection and use of our users’ personal data only takes place regularly with the user’s consent. An exception applies in cases where prior consent cannot be obtained for factual reasons and the processing of the data is permitted by law.
2.2 Lawfulness of Data Processing
Unless otherwise stated in this privacy policy, the legal basis for the processing of your data results from Art. 4 para. 1 of the Bavarian Data Protection Act (BayDSG) and Art. 2 of the Bavarian Higher Education Act (BayHSchG) in conjunction with Art. 6 para. 1 lit. e, para. 3 of the General Data Protection Regulation (GDPR).
Insofar as we obtain the consent of the data subject for the processing of personal data, Art. 4 para. 1 of the BayDSG in conjunction with Art. 6 para. 1 sentence 1 lit. a of the EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data. Please note that from December 1, 2021, the storage of information in “end devices” of end users and access to information already stored in them will be based on the legal basis of Art. 4 para. 1 of the BayDSG in conjunction with Section 25 of the Telecommunications Telemedia Data Protection Act (TDDDG). § Section 25 TDDDG is then the legal basis for the consent requirement for the use of cookies and comparable technologies.
When processing personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 4 para. 1 of the BayDSG in conjunction with Art. 6 para. 1 sentence 1 lit. b GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
Insofar as the processing of personal data is necessary to fulfill a legal obligation to which we are subject, Art. 4 para. 1 of the BayDSG in conjunction with Art. 6 para. 1 sentence 1 lit. c GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 4 para. 1 of the BayDSG in conjunction with Art. 6 para. 1 sentence 1 lit. d GDPR serves as the legal basis.
If the processing is necessary to safeguard our legitimate interests or those of a third party and if the interests, fundamental rights and freedoms of the data subject do not outweigh the former interest, Art. 4 para. 1 of the BayDSG in conjunction with Art. 6 para. 1 sentence 1 lit. f GDPR serves as the legal basis for the processing.
2.3 Data Erasure and Storage Period
The personal data of the data subject will be deleted as soon as the purpose of storage no longer applies. Data may also be stored if this has been provided for by the European or national legislator in EU regulations, laws or other provisions to which the controller is subject. The data will also be deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfillment of a contract.
2.4 Recipients of Personal Data
When operating our website, various data recipients receive access to personal data. Our web server is operated by the Leibniz Supercomputing Center of the Bavarian Academy of Sciences and Humanities (LRZ). The personal data transmitted by you when you visit our website is therefore processed by the LRZ on our behalf:
Leibniz Supercomputing Center (LRZ) of the Bavarian Academy of Sciences and Humanities
Boltzmannstraße 1
D-85748 Garching near Munich
Telephone: (089) 35831 8000
Fax: (089) 35831 9700
E-mail: lrzpost(at)lrz.de
https://www.lrz.de
If necessary, your data will be transmitted to the responsible supervisory and auditing authorities to exercise the respective control rights.
In order to avert threats to information technology security, data may be forwarded to the State Office for Information Technology Security in the event of electronic transmission and processed there on the basis of Art. 12 ff. of the Bavarian E-Government Act.
Further data recipients can be found under the respective processing activities in this privacy policy.
3. Provision of the Website and Creation of Log Files
3.1 Description and Scope of Data Processing
When you access this or other Internet pages, you transmit data to our web server via your Internet browser. The following data is temporarily recorded in a log file during an ongoing connection for communication between your Internet browser and our web server:
- IP address of the requesting computer
- Date and time of access
- Name, URL and transferred data volume of the retrieved file
- Access status (requested file transferred, not found, etc.)
- Identification data of the browser and operating system used (if transmitted by the requesting web browser)
3.2 Legal Basis for Data Processing
The legal basis for the temporary storage of data and log files is Article 6(1)(1)(f) GDPR.
3.3 Purpose of Data Processing
Die vorübergehende Speicherung der IP-Adresse durch das System ist notwendig, um eine Auslieferung der Website an den Rechner des Nutzers zu ermöglichen. Hierfür muss die IP-Adresse des Nutzers für die Dauer der Sitzung gespeichert bleiben.
Die Speicherung in Logfiles erfolgt, um die Funktionsfähigkeit der Website sicherzustellen. Zudem dienen uns die Daten zur Sicherstellung der Sicherheit unserer informationstechnischen Systeme. Eine Auswertung der Daten zu Marketingzwecken findet in diesem Zusammenhang nicht statt.
In diesen Zwecken liegt auch unser berechtigtes Interesse an der Datenverarbeitung nach Art. 4 Abs. 1 des BayDSG in Verbindung mit Art. 6 Abs. 1 S. 1 lit. f DSGVO.
3.4 Storage Period
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.
If the data is stored in log files, this is the case after seven days at the latest. Storage beyond this period is possible. In this case, the IP addresses of the users are deleted or anonymized so that it is no longer possible to identify the accessing client.
4. Use of Cookies
4.1 General About Cookies We Use
Our website uses cookies. Cookies are text files that are stored in the Internet browser or by the Internet browser on the user’s computer system. The information stored in a cookie can include, for example, the language settings on a website (with us you have the choice of whether the website is displayed in German or English) or consent to the use of cookies.
The following distinction helps you to better understand what types of cookies there are:
- Temporary cookies are automatically deleted when you close the browser. These include session cookies in particular. These store a so-called session ID, with which various requests from your browser can be assigned to the joint session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
- Permanent cookies remain stored even after the browser is closed. They are automatically deleted after a specified period, which may vary depending on the cookie. You can delete the cookies at any time in the security settings of your browser.
- First-party cookies: These are set by us.
- Third-party cookies (= cookies from third-party providers): These are mainly used by traders (so-called third parties) to process user information.
- Necessary (also essential) cookies are those that are absolutely necessary for the operation of the website.
- Statistical and marketing cookies: These are cookies that are used for online marketing purposes (in particular marketing of advertising space, targeted advertising) and analysis of user behavior for the purpose of optimizing the online offering. Such cookies are also used for profiling. Profiling is used to show users content that matches their potential interests. If we use cookies or tracking technologies, we will inform you of this separately in the privacy policy or when obtaining your consent.
You can configure your browser settings according to your wishes and, for example, refuse to accept third-party cookies or all cookies. We would like to point out that you may then not be able to use all the functions of this website.
4.2 Description and Scope of Data Processing
The cookies store usage data (including access times, websites you have visited, content you have viewed) and meta/communication data (information about your devices, IP addresses).
4.3 Legal Basis for Data Processing
If we ask you to consent to the processing of your personal data using cookies and you consent, the legal basis for the data processing is your consent (,Art. 6 para. 1 sentence 1 lit. a GDPR, Section 25 para. 1 of the Telecommunications Digital Services Data Protection Act [TDDDG]). Otherwise, the legal basis for the processing of personal data using cookies is Art. 6 para. 1 sentence 1 lit. f GDPR, Section 25 para. 2 TDDDG.
4.4 Storage Period
In the context of obtaining consent (so-called cookie consent), we point out the storage period of the respective permanent cookie. Otherwise, the storage period can be up to two years. Session cookies are deleted when you log out or close the browser.
4.5 Objection and Revocation of Consent
If the processing of your personal data by cookies is based on legal permission, you can object to the processing at any time. You can first declare your objection by changing your browser settings (e.g. by deactivating the use of cookies). Please note that certain functions of our website (e.g. the default language) will then no longer work. We will draw your attention to further objection options in the information on the service providers and cookies used.
If the processing of personal data by cookies is based on your consent, you can withdraw your consent at any time. We use a cookie consent management tool for this purpose. This tool provides you with information about the cookies we use (processing and provider). You can also give and/or withdraw your consent in this tool. The declaration of consent is stored by a cookie. This is done so that the query about the use of cookies does not have to be made again and we can also prove the consent in accordance with our legal obligation. The settings you have made in the cookie tool are stored in the cookie.
You can access the cookie settings here:
4.6 Security Services (Google reCAPTCHA)
(a) Service
Our website uses “Google reCAPTCHA” to protect forms from spam and automated access. When loading reCAPTCHA, personal data such as IP address, browser and device information, and usage data is transmitted to Google. This serves to analyze whether the input is made by a human. Data may be transferred to the USA.
Activation occurs only after your consent via our consent tool (Borlabs Cookie). You can withdraw consent at any time via the cookie settings.
Legal basis: Your consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with Art. 4 para. 1 BayDSG and § 25 TDDDG.
(b) Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA;
Privacy Policy: https://policies.google.com/privacy
4.7 Technically Necessary Cookies (e.g., WPML)
(a) Service
We use technically necessary cookies to ensure the basic functions of our website. This includes the WPML plugin, which stores your language preferences so that the website is displayed in the language you selected. Without these cookies, the use of the website is not possible.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in a functional website).
(b) Provider
OnTheGoSystems Ltd., 22/F 3 Lockhart Road, Wanchai, Hong Kong; Privacy Policy: https://wpml.org/documentation/privacy-policy-and-gdpr-compliance/
4.8 External Fonts (OMGF / Google Fonts)
(a) Service
We use the plugin OMGF to provide Google Fonts locally on our server. This means no data is transmitted to Google. This serves to optimize loading times and provide consistent fonts.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in a technically optimized website).
(b) Provider
OMGF (Daan van den Bergh), ‘t Grachtje Over 11, 1625 PG Hoorn, NL;
Privacy Policy: https://daan.dev/about/privacy-policy/
5. Contact by Email
You can use the provided email addresses to contact us. The personal data transmitted with the email will be stored.
There is no disclosure of the data to third parties in this context. The data is used exclusively for processing the conversation.
Legal basis: When sending an email, Art. 4 para. 1 BayDSG in conjunction with Art. 6 para. 1 lit. f GDPR. If the email contact aims at concluding a contract, the additional legal basis for processing is Art. 4 para. 1 BayDSG in conjunction with Art. 6 para. 1 lit. b GDPR.
Purpose: In the case of contact by email, our legitimate interest in processing the data lies in responding to your inquiry.
Storage period: The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. For personal data transmitted by email, this is the case when the conversation with the user has ended. The conversation ends when it can be inferred from the circumstances that the relevant matter has been conclusively clarified.
Withdrawal: If you contact us by email, you can object to the storage of your personal data at any time, e.g., by email. In such a case, the conversation cannot be continued.
All personal data stored in the course of contacting us will then be deleted, unless a contract is concluded and the personal data from the email communication must continue to be processed for this purpose.
6. Forms and Contact
6.1 General Information on Forms
(a) Service
Our website inquiries, applications, downloads, event registrations, and newsletter subscriptions. The data you enter is processed, stored in our website database, and transmitted to us via email, as well as transferred to our CRM system (see section 6.3). Mandatory fields are marked accordingly. Additionally, you can upload files in specific formats (e.g., CV). These are transmitted in encrypted form and used exclusively for the specified purpose.
Legal basis: For the processing of mandatory information Art. 6 para. 1 lit. b GDPR (contract performance), Art. 6 para. 1 lit. a GDPR for voluntary information as well as Art. 4 para. 1 BayDSG. You can withdraw your consent at any time.
(b) Provider
Rocketgenius, Inc. (Gravity Forms), 1620 Centerville Turnpike, Suite 102, Virginia Beach, VA 23464-6500, USA;
Privacy Policy: https://www.gravityforms.com/privacy/
6.1.1 Email Sending and Logging
(a) Service
For sending emails generated via our forms, we use the plugin WP Mail SMTP to ensure secure delivery via a configured SMTP service. Additionally, we use WP Mail Logging to log the sending process (recipient, subject, sending time, content) and ensure traceability.
Purpose: Ensuring email delivery and error analysis.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract performance) for mandatory information as well as Art. 6 para. 1 lit. f GDPR (legitimate interest in functional communication).
Storage period: Logs are regularly deleted as soon as they are no longer required for the purpose (max. 90 days).
(b) Provider
WPForms LLC, 400 Executive Center Drive, Suite 208, West Palm Beach, FL 33401, USA;
Privacy Policy: https://wpmailsmtp.com/privacy-policy/
Depending on configuration, data may be transmitted to the SMTP service used (e.g., Microsoft, Google). Details can be found in the privacy policies of the respective providers.
6.2 Spam Protection
(a) Service
To protect against automated access, we use the service Google reCAPTCHA. Details can be found in the section “Use of Cookies.”
(b) Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Privacy Policy: https://policies.google.com/privacy
6.3 Transfer to CRM
(a) Service
The data collected via the forms is transferred to our CRM system CAS genesisWorld to process your inquiry or registration and to document communication. Storage takes place for the duration of the business relationship and beyond in accordance with statutory retention obligations (usually up to 10 years). You can withdraw your consent at any time, unless legal obligations prevent this.
(b) Provider
CAS Software AG, CAS-Weg 1-5, 76131 Karlsruhe; Privacy Policy: https://www.cas.de/datenschutz
We have concluded a data processing agreement with CAS Software AG pursuant to Art. 28 GDPR.
6.4 Event Registration
You have the option to register for events via our website. Mandatory fields are marked with an asterisk “*”. Without this information, registration is not possible. All other information is voluntary. Depending on the type of event, different data is requested, e.g.:
First name, surname
telephone number
e-mail address
title
Date of birth
Position/Department
Organization/Company
Billing address
For proof of knowledge: Curriculum vitae or link to a LinkedIn profile
You also have the option of subscribing to our newsletter (please see our information on “Newsletter” in this privacy policy).
Legal basis: Art. 4 para. 1 BayDSG in conjunction with Art. 6 para. 1 lit. b GDPR (for mandatory information) as well as your consent pursuant to Art. 6 para. 1 lit. a GDPR.
Purpose: We process your information exclusively for the purpose of conducting the event for which you register.
Storage period: The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. This is generally the case after five years. Longer retention periods may result from tax and commercial law retention and documentation obligations as well as regulations applicable to our university.
Withdrawal: You can withdraw your consent at any time. We will then only process your data insofar as this is necessary for the performance of the contract or statutory retention obligations exist.
7. Booking of Consultation Appointments
We have integrated meetergo on this website. The provider is meetergo GmbH, Hansaring 61, 50670 Cologne (hereinafter referred to as meetergo). meetergo provides an online appointment booking tool. If you make an appointment with us online, the data you enter for this purpose will be stored on meetergo’s servers in Germany. In addition, meetergo briefly records your IP address, your referrer URL, the time of access and can determine that you have made a request to us; this data is used exclusively for the technical provision of the service and is then automatically deleted again. The use of meetergo is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in making appointments as uncomplicated as possible. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time.
8. Newsletter
(a) Service
We offer you the opportunity to subscribe to a free newsletter to inform you about training, events, and relevant topics. Registration takes place via a form technically based on Gravity Forms (see section 6). For sending, we use the service provider Inxmail GmbH.
The following data is processed by us:
Email address
First and last name
Title
In addition, the following data is collected during registration: date/time
For processing the data, your consent is obtained during the registration process via the so-called double opt-in and reference to this privacy policy. We also store the registration process so that we can prove its proper execution.
Legal basis: The processing of newsletter subscription data is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR.
Purpose: Collecting your name, title, and email address serves to deliver the newsletter and address you correctly.
Collecting other personal data during the registration process serves to prevent misuse of the services or the email address used and to prove the proper execution of the registration.
Storage period: The data will be deleted as soon as it is no longer required. The above-mentioned data is therefore stored as long as the newsletter subscription is active. After that, we may store the unsubscribed email address for up to three years based on our legitimate interest to prove originally given consent. The purpose of processing during this period is limited to defending claims.
Withdrawal: You can cancel the newsletter subscription at any time. For this purpose, each newsletter contains a corresponding “Unsubscribe” link. This also enables withdrawal of consent to store the personal data collected during the registration process.
(b) Provider
For newsletter distribution, we use the company Inxmail GmbH, Wentzingerstraße 17, 79106 Freiburg (please find Inxmail’s privacy policy here: https://www.inxmail.de/datenschutz). We have concluded a data processing agreement (Art. 28 GDPR) with Inxmail (hereinafter also newsletter service provider). The data is used exclusively for sending the newsletter. In connection with data processing for newsletter distribution, there is no disclosure of data to third parties.
9. Newsletter-Tracking
To measure how successful our newsletter is, we have our service provider Inxmail measure the open rate and click rate of our newsletter.
The open rate refers to the ratio between the number of recipients who opened the mailing and the number of emails delivered. Recipients who opened the mailing are those who opened the mailing at least once, which is recorded by an image inserted in the newsletter (so-called “tracking pixel”). This is loaded from the server of our newsletter service provider when opened. The click rate is also used for the open rate. The click rate refers to the percentage ratio of recipients who clicked to those who opened. This gives us insight into which topics are relevant for recipients who open the newsletter.
The following data is collected:
- Information about your browser and system
- IP address
- Time of retrieval
Legal basis for newsletter tracking (measurement of open and click rates and storage of the measurement result) is your consent, which you gave when subscribing to the newsletter with reference to this privacy policy (Art. 6 para. 1 lit. a GDPR; § 25 para. 1 Telecommunications-Digital Services Data Protection Act [TDDDG]).
Purpose: The information obtained through newsletter tracking is used to technically improve newsletter delivery based on technical data or recipient groups and their reading behavior as well as access times. We also learn whether the newsletter was opened, when this happened, and which links were clicked (please also see the notes under item 1 of this section). Although this information can be assigned to individual newsletter recipients, we do not intend to monitor recipients of our newsletter. The information obtained allows us to tailor our newsletter service even better to the interests of recipients, e.g., by adapting different content to recipients’ interests and learning about their reading habits.
Storage period: We store your data in anonymized form until you withdraw your consent for 2 years.
Withdrawal: You can object to newsletter tracking at any time for the future. To do so, simply cancel your newsletter subscription. Each newsletter contains a corresponding link (“Unsubscribe”). This also ends your newsletter subscription and newsletter tracking.
10. Online-Marketing
In the context of online marketing, we process personal data for the purpose of presenting advertising or other content that is intended to address the potential interests of users. Another purpose of the processing is to measure the effectiveness of the measures and to optimize our website content.
For this purpose, relevant information is stored in so-called user profiles in relation to said content. These user profiles are stored in cookies (please also see our information on cookies in this privacy policy). The information stored includes, among other things
- online networks used
- websites visited
- content viewed
- browser used
- computer system used
- usage times
- IP addresses
- Device information
However, the IP addresses are pseudonymized by shortening the IP address to protect the user. If Java Script content from external providers is used, you can prevent the processing of personal data by installing a Java Script blocker such as the browser plug-in “NoScript” (www.noscript.net) or deactivating Java Script in your browser.
If you have a user account with the relevant service (e.g. Google, Facebook) and are logged in there, the data collected will be assigned directly to your account. If you do not wish to be associated with your profile, you must log out before visiting our website or before giving your consent to the processing of your data.
In the following, we will first provide you with information on the services used by the third-party providers and on the third-party providers themselves, after which we will go into the legal basis, the purpose of processing and the storage period
10.1 Overview of Online Marketing Third-Party Providers
10.1.1 Alexa Metrics
(a) Service
Our website uses “Alexa Metrics”. This service is provided by Alexa Internet, Inc. and enables us to analyze user behavior on our website and to design our website in line with requirements.
(b) Provider
Alexa Internet, Corporation Service Company, 2730 Gateway Oaks Drive, Suite 100, Sacramento, CA 95833, USA; Website: www.alexa.com; Privacy Policy: https://www.alexa.com/help/privacy; Opt-Out for Alexa Measurement Pixel: https://support.alexa.com/hc/en-us/articles/200685410-Opting-Out-of-Alexa-Measurement-Pixel
10.1.2 Facebook-Pixel
(a) Service
Facebook Pixel is an analytics service provided by Facebook Ireland Ltd. that combines data from the Facebook network with the actions taken through this website. This allows users of the website to be shown interest-based advertisements (“Facebook ads”) when they visit the Facebook social network or other websites that also use the process. We are interested in showing you advertisements that are of interest to you in order to make our website more interesting for you. For this purpose, your browser automatically establishes a direct connection with the Facebook server. We have no influence on the scope and further use of the data collected by Facebook through the use of this tool and therefore inform you according to our level of knowledge: By integrating the Facebook Pixel, Facebook receives the information that you have accessed the corresponding web pages of our website or have clicked on an advertisement from us. If you are registered with a Facebook service, Facebook can assign the visit to your account. Even if you are not registered with Facebook or have not logged in, it is possible for the provider to find out and store your IP address and other identifying features.
(b) Provider
Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Opt-Out: https://www.facebook.com/settings?tab=ads.
10.1.3 Google Services
(a) Service
We use various services of the Google Marketing Platform and other Google services on our website to improve functionality, provide content, and optimize marketing measures.
Personal data such as IP address, browser information, usage behavior, and cookie IDs may be processed. These data serve to analyze user behavior, display advertising, and provide interactive content.
Integration of these services occurs only after your consent via our consent tool (Borlabs Cookie). You can withdraw your consent at any time via the cookie settings.
Legal basis: Processing is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with § 25 TDDDG.
Third-country transfer: Google processes your personal data in the USA. Each transfer of personal data is carried out in compliance with Art. 44–50 GDPR and other GDPR provisions to ensure an adequate level of data protection. Further information can be found in the provider’s privacy policies.
(b) Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Privacy Policy: https://policies.google.com/privacy
10.1.3.1 Google Ads
Service & Purpose: We use Google Ads, a service provided by Google Ireland Ltd, on our website. With Google Ads, we can draw attention to our offers with the help of advertising material on external websites. This allows us to draw conclusions about the success of individual advertising measures. The advertising material is delivered by Google via so-called “AdServers”. We use so-called AdServer cookies to measure success. If you reach our website via a Google ad, Google Ads will store a cookie on your device. This cookie contains the following information: Unique cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions), opt-out information (marking that the user no longer wishes to be addressed). However, we only receive statistical evaluations from Google. Based on these evaluations, we can recognize which of the advertising measures used are successful.
Storage period: As long as necessary for the purpose.
10.1.3.2 Google Analytics
Service & Purpose: Our website uses Google Analytics, a web analytics service provided by Google Inc. or Google Ireland Ltd (“Google”). The information stored in a cookie about your use of our website is generally transmitted to a Google server in the USA and stored there. However, if IP anonymization is activated as on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area beforehand. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. Google will use this information on our behalf to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage to the website operator.
The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Storage period: As long as necessary for the purpose. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Further information: https://marketingplatform.google.com/intl/de/about/analytics/
Opt-out option: https://tools.google.com/dlpage/gaoptout?hl=de
Settings for ad display: https://adssettings.google.com/authenticated
10.1.3.3 Google DoubleClick
Service & Purpose: Google DoubleClick is an online marketing tool from Google Ireland Ltd. This tool is used on our website for marketing and optimization purposes. Among other things, Google DoubleClick uses cookies (please refer to the information on cookies in this privacy policy) to prevent ads from being displayed more than once. The cookie can also be used to record “conversions” that are related to ad requests. This is the case, for example, if you see a DoubleClick ad and later visit the advertiser’s website with the same browser and make a purchase or use services there.
Storage period: As long as necessary for the purpose.
10.1.3.4 Google Maps
Service & Purpose: We use the Google Maps service on our website. This allows us to show you interactive maps directly on the website and enables you to use the map function conveniently.
10.1.3.5 Google Tag Manager
Service & Purpose: Our website uses “Google Tag Manager.” This service is provided by Google Ireland Ltd. and allows us to manage website tags via an interface. Google Tag Manager performs the function of implementing tags, but does not itself collect personal data.
10.1.4 LinkedIn Insight Tag
(a) Service
Our website uses LinkedIn Insight Tag. This is an analysis service provided by LinkedIn Corporation or LinkedIn Ireland Unlimited Company, which links the data from the LinkedIn network with the actions taken through this website. We are interested in showing you advertising that is of interest to you in order to make our website more interesting for you.
(b) Provider
LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA; Website: https://www.linkedin.com; Security measures: IP masking (pseudonymization of the IP address); Privacy Policy: https://www.linkedin.com/legal/privacy-policy, Cookie Policy: https://www.linkedin.com/legal/cookie_policy; Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
10.1.5 Microsoft Advertising
(a) Service
Microsoft Advertising is used on our website. This analysis tool is provided by Microsoft Corporation. Using a conversion tracking tag from Microsoft Advertising, we can learn more about user behavior when you access our website via a Microsoft advertisement (e.g. keyword, ad, click behavior on our website, etc.). We only receive data or evaluations of your behavior on the Internet. We do not know what data Microsoft processes. Microsoft also processes data in the USA, among other places. Data processing is based on the standard contractual clauses approved by the EU Commission.
(b) Provider
Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Privacy Policy: https://privacy.microsoft.com/de-DE/privacystatement; Opt-out: https://account.microsoft.com/privacy/ad-settings/signedout
10.1.6 Microsoft Clarity
We use the analysis tool Microsoft Clarity on our website, a service of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (“Microsoft”). Microsoft Clarity enables us to analyze user behavior on our website, in particular by recording mouse movements, scrolling behavior and clicks. This information helps us to better understand the use of our website and to continuously improve the user experience.
The legal basis is your consent (Art. 6 para. 1 lit. a GDPR, § 25 para. 1 TDDDG), which you can revoke at any time with effect for the future.
Microsoft Clarity collects the following information, among others
- Pages visited on our website
- Length of stay on the pages
- Mouse movements and click behavior
- Anonymized IP address
- Technical information, such as browser used, operating system and device type
This data cannot be directly linked to a person. Microsoft Clarity also uses cookies to store information about the use of our website.
The data collected by Microsoft Clarity may be transferred to the USA and processed there. Microsoft is committed to complying with the data protection standards of the GDPR and is part of the Data Privacy Framework Program (DPF).
Further information on data protection at Microsoft Clarity can be found at: https://privacy.microsoft.com/de-de/privacystatement.
10.1.7 Outbrain Pixel
If you have given your consent, we will implement a pixel from Outbrain UK Limited (“Outbrain”) on our website to collect data for retargeting and conversion tracking. This pixel determines whether the user who accesses our website has an Outbrain UUID. If there is a UUID associated with the user, Outbrain can allow us to retarget this UUID and send us the total number of UUIDs that have reached our site. If there is no Outbrain UUID for the user, the Outbrain pixel does not collect any data about this user. We do not receive any information from Outbrain with which we can personally identify one of our customers. If you use different browsers and/or different end devices, Outbrain attempts to recognize this and merge the individual Outbrain UUIDs of your browsers/end devices. To do this, Outbrain uses its own linking methods based on the data collected by Outbrain, such as the IDs of advertising partners or encrypted e-mail addresses that partners provide to Outbrain.
The collection and processing of this data is the sole responsibility of Outbrain. Outbrain provides us with evaluations or other information created on the basis of the data collected only in aggregated, anonymized form. We cannot assign the information provided to us to any natural person. We have no knowledge of the details of the processing of personal data in Outbrain’s area of responsibility. Information on the processing of personal data by Outbrain can be found in Outbrain’s data policy: https://www.outbrain.com/legal/privacy#privacy-policy.
You can control the processing of data by Outbrain by activating or deactivating Outbrain for the browser you are currently using in our “Cookie Dashboard”. Alternatively, you can deactivate Outbrain for the browser you are currently using by deactivating the storage of cookies in your browser settings.
The controller for data processing is Outbrain Inc, 39 West 13th Street, 3rd floor, New York, NY 10011.
(i) The purpose of data processing by Outbrain is to enable Outbrain to collect and process user data on our website. The purposes of the processing are determined solely by Outbrain.
(ii) The processed data are:
Outbrain UUID
This is a unique user ID that is assigned by Outbrain. By assigning a UUID, Outbrain can combine the pages visited and the clicks on Outbrain’s recommendations from this UUID.
Outbrain HTTP data
This is log data that is generated for technical reasons when the Outbrain tool used on the website is used via the Hypertext Transfer Protocol (Secure) (HTTP(S)): This includes IP address, device type, browser type, operating system, the pages visited, the time of the visit and the referring URLs.
Usage data
Usage data is primarily clicks on advertisements, time spent on the website and information about websites visited. This information is linked to the Outbrain UUID.
(iii) The legal basis for enabling Outbrain to collect personal data via our website is Article 6(1)(a) GDPR (consent). We do not process any personal data via this pixel in our area of responsibility. We have no knowledge of the details of the processing of the data in Outbrain’s area of responsibility, in particular the legal basis used by Outbrain for the processing.
(iv) The data is generated independently by Outbrain. We do not know whether Outbrain uses other data sources.
(v) The recipient of the data is Outbrain as the controller responsible for the collection and processing of personal data. Data may also be transferred to the USA. The data will only be transferred if you have given us your consent to do so in accordance with Art. 6 para. 1 letter a, 49 para. 1 sentence 1 letter a GDPR. Corresponding information on the risks of such data transfers and revocation options can be found under B. I. 3.
(vi) The pixel loses its validity after 90 days and, according to Outbrain, does not contain any personal data other than the UUID.
(vii) The provision of data is not required by law or contract or necessary for the conclusion of a contract. The data subject is under no obligation to provide the data. If the data is not provided, Outbrain cannot carry out retargeting or conversion tracking.
(viii) We do not use automated decision-making in our area of responsibility. We have no knowledge of the details of the processing of the data in Outbrain’s area of responsibility, in particular of any automated decision-making.
10.1.8 Pinterest Cookie
(a) Service
Our website uses cookies from the service “Pinterest” to measure the effectiveness of advertising campaigns and optimize content. In doing so, personal data such as IP address, browser and device information, and usage data is processed. Data may be transferred to the USA. Activation occurs only after your consent via our consent tool (Borlabs Cookie). You can withdraw your consent at any time via the cookie settings.
Legal basis: Your consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with Art. 4 para. 1 BayDSG and § 25 TDDDG.
(b) Provider
Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland
Website: https://www.pinterest.com
Privacy Policy: https://policy.pinterest.com/de/privacy-policy
10.1.9 Rank Math SEO
(a) Service
We use the plugin Rank Math SEO to improve the search engine optimization of our website. In doing so, technical data such as IP address, browser information, and usage behavior may be processed, especially when analytics functions or integrations with external services are activated. Rank Math may set cookies to ensure functionality.
Legal basis: Your consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with § 25 TDDDG, insofar as cookies or tracking technologies are used.
Purpose: Optimization of the visibility of our website in search engines and analysis of SEO-relevant data.
Storage period: As long as necessary for the purpose or until you withdraw your consent.
Withdrawal: You can withdraw your consent at any time via the cookie settings.
(b) Provider
Rank Math SEO; c/o One.com India Private Limited; Office No. 2, Floor 5, Tower A; Building 9, DLF Cyber City Complex; Phase III, Gurgaon, Haryana 122002, India
Privacy Policy: https://rankmath.com/privacy-policy/
10.1.10 Yumpu
(a) Service
Our website uses the yumpu software (which is provided by i-magazine AG). The yumpu software enables us to track the reading behavior of our users. We do not know what data i-magazine AG processes.
(b) Provider
Yumpu is a software of i-magazine AG, Gewerbestrasse 3, 9444 Diepoldsau; privacy policy: https://www.yumpu.com/de/info/privacy_policy
10.2 Scope of the Processing of Personal Data
The above-mentioned online marketing services process the following personal data about you:
- Usage data (characteristics for identifying the user, information about the start and end as well as the scope of the respective use, websites visited, information about the content viewed by the user)
- Meta/communication data
- Location data
- Event data (Facebook)
10.3 Legal Basis for the Processing of Personal Data
If you consent to the use of third-party providers, the legal basis for the processing of your personal data is consent (Art. 6 para. 1 sentence 1 lit. a GDPR, Section 25 para. 1 TDDDG).
Processing does not take place without consent (please also see the section on cookies and cookie settings).
10.4 Purpose of Data Processing
We use the above-mentioned services for the purposes of tracking, re-marketing, to make our offer more attractive, to obtain information about our target group and to be able to measure the success of our advertising campaigns.
10.5 Duration of Storage, Objection and Removal Options
In the cookie settings, you will find information on the duration of cookie storage and can revoke your consent (please refer to the section on cookies). Please also refer to the data protection declarations of the respective providers (see above) with regard to the storage period, objection and removal options. You can also disable cookies in your browser settings.
10.6 Security Measures
The IP address is pseudonymized (IP masking).
11. Integration of Social Media and Third-Party Content
We do not use classic social media plug-ins that transmit data to providers when the page loads. Our website only links to our profiles on social networks (Facebook, LinkedIn, Instagram, Twitter) as well as our Spotify and YouTube channels. When you click on a logo, you will be redirected to our respective profile and personal data (e.g., IP address, referrer URL) will be transmitted to the respective provider. If you are logged in there, the data can be linked to your account.
In addition, we offer the option to share content via share buttons in social networks. When you click on a share button, personal data (e.g., IP address, referrer URL) is transmitted to the respective provider.
Further information on data processing can be found in the providers’ privacy policies:
(a) Facebook: https://www.facebook.com/policy.php
(b) Instagram: https://help.instagram.com/155833707900388
(c) Twitter/X: https://twitter.com/de/privacy
(d) Spotify: https://www.spotify.com/de/legal/privacy-policy/
(e) YouTube: https://policies.google.com/privacy?hl=de
(f) LinkedIn: https://www.linkedin.com/legal/privacy-policy
Additionally, we embed third-party content directly on our pages (e.g., YouTube videos, Spotify podcasts, LinkedIn feed). These contents are loaded only after your consent via our consent tool (Borlabs Cookie). Legal basis for all embedded content described below is your consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with Art. 4 para. 1 BayDSG and § 25 TDDDG (consent requirement for cookies/comparable technologies). You can withdraw consent at any time via the cookie settings.
11.1 YouTube
(a) Service
Our website displays videos loaded from YouTube. Purpose: to provide you with attractive content via our website. When playing a video, personal data such as IP address and browser information is transmitted to Google. Data may also be transferred to the USA. You can decide whether you want to play YouTube videos. Integration occurs only after your consent via our consent tool (Borlabs Cookie). You can withdraw consent at any time via the cookie settings.
Legal basis: see introduction to section 11.
(b) Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Privacy Policy: https://policies.google.com/privacy
11.2 Spotify
(a) Service
Our website embeds podcasts via the service “Spotify” to provide audio content directly on our pages. When loading the Spotify player, personal data such as IP address, browser/device information, and possibly cookie IDs or similar technologies are transmitted to Spotify. Depending on technical provision, data transfers to third countries may occur. Integration occurs only after your consent via our consent tool (Borlabs Cookie). You can withdraw consent at any time via the cookie settings.
Legal basis: see introduction to section 11.
(b) Provider
Spotify AB, Regeringsgatan 19, 11153 Stockholm, Sweden
Privacy Policy: https://www.spotify.com/de/legal/privacy-policy/
11.3 LinkedIn Feed
(a) Service
Our website embeds content from LinkedIn (e.g., feed/posts) to provide current information from our network. Integration occurs via the Tagembed widget. Further information can be found in section 11.4. When loading this content, personal data such as IP address, browser/device information, and possibly cookie IDs or similar technologies are transmitted to LinkedIn. Depending on technical provision, data transfers to third countries (especially USA) may occur. Integration occurs only after your consent via our consent tool (Borlabs Cookie). You can withdraw consent at any time via the cookie settings.
Legal basis: see introduction to section 11.
(b) Provider
LinkedIn Corporation, 2029 Stierlin Court, Mountain View, California 94043, USA
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
11.4 Tagembed
(a) Service
We use the Tagembed widget to display content from our LinkedIn feed directly on our website. When loading this content, personal data such as IP address and browser information is transmitted to the provider. Cookies may be set to ensure functionality. Integration occurs only after your consent via our consent tool (Borlabs Cookie). You can withdraw your consent at any time via the cookie settings.
Legal basis: see introduction to section 11.
(b) Provider
Tagembed, 340 S Lemon Ave #5780, Walnut, CA 91789, USA;
Privacy Policy: https://tagembed.com/privacy-policy/
12. Your Rights/Right of Appeal
12.1 Your Rights
If we process your personal data, you have the following rights as a data subject:
- You have the right to information about the personal data stored about you (Art. 15 GDPR).
- If incorrect personal data is processed, you have the right to rectification (Art. 16 GDPR).
- If the legal requirements are met, you can request the erasure or restriction of processing (Art. 17 and 18 GDPR).
- If you have consented to the processing or a contract for data processing exists and the data processing is carried out using automated procedures, you may have a right to data portability (Art. 20 GDPR).
- If you have consented to the processing and the processing is based on this consent, you can revoke your consent at any time for the future. This does not affect the lawfulness of the data processing carried out on the basis of the consent until revocation. You have the right to object to the processing of your data at any time for reasons arising from your particular situation if the processing is carried out exclusively on the basis of Art. 6 para. 1 letter e) or f) GDPR (Art. 21 para. 1 sentence 1 GDPR)
12.2 Right of Appeal to the Supervisory Authority
You also have the right to lodge a complaint with a supervisory authority. The Bavarian State Commissioner for Data Protection is responsible for the Technical University of Munich.
You can reach him under the following contact details:
Postal address: P.O. Box 22 12 19, 80502 Munich
Address: Wagmüllerstraße 18, 80538 Munich
Telephone: 089 212672-0
Fax: 089 212672-50
E-mail: poststelle(at)datenschutz-bayern.de
https://www.datenschutz-bayern.de/
13. Transfer to Third Countries
If there is a transfer of personal data to a third country, this is described in this declaration in connection with the respective processing. The current Standard Contractual Clauses (SCC) of the EU Commission are used to secure the transfer if there is no adequacy decision for the third country. In the case of third country transfers to the USA, the data recipient regularly participates in the Data Privacy Framework Program (DPF).
14. Further Information
In addition to the services mentioned above, we use additional technical solutions to ensure the security, maintenance, and performance of our website. In doing so, personal data such as IP address, browser information, and usage behavior may be processed. Integration occurs only after your consent if cookies or comparable technologies are used. You can withdraw your consent at any time via the cookie settings.
14.1 ManageWP Worker
(a) Service
We use the service ManageWP Worker to facilitate the maintenance and management of our website. Technical data such as IP address and system information is processed to perform backups, updates, and security checks.
Purpose: Ensuring the functionality and security of our website.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in a secure and functional website).
(b) Provider
GoDaddy.com LLC (ManageWP), 14455 N Hayden Rd Ste 219, Scottsdale, AZ 85260, USA;
Privacy Policy: https://managewp.com/privacy
14.2 Stape.io (Server-Side Tagging)
(a) Service
We use the service Stape.io for server-side tagging. The purpose is privacy-compliant control of tracking data and improvement of data quality. Personal data such as IP address, browser information, and event data is processed. Data is not sent directly from your browser to third-party providers but via a server container.
Legal basis: Your consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with § 25 TDDDG.
(b) Provider
Stape Europe OÜ, Sepapaja 6, Tallinn, 15551, Estonia; Privacy Policy: https://stape.io/eu-gdpr
14.3 Technical Infrastructure / Hosting
Operation of our website and processing of access and connection data is carried out via the Leibniz Supercomputing Centre (LRZ). Details on recipient, address, and contact can be found in section 2.4 “Recipients of personal data.”
14.4 Technical Plattform (WordPress)
(a) Service
Our website is based on the content management system WordPress. Technically necessary data such as IP address and access logs are processed to ensure the provision of the website. Storage takes place in our own database at the hosting provider’s location (see section 2.4).
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in a functional website).
(b) Provider:
WordPress Foundation, 660 4th Street, San Francisco, CA 94107, USA; Privacy Policy: https://wordpress.org/about/privacy/
14.5 Contact for Further Information
For further information on the processing of your data and your rights, you can contact us using the contact details provided above (see section 1).
You are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from reCAPTCHA. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Mapbox. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from OpenStreetMap. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information