Privacy Policy
Preamble
This Privacy Policy explains which types of your personal data (hereinafter also referred to simply as "data") we process, for what purposes and to what extent. This Privacy Policy applies to all processing of personal data carried out by us, both in the provision of our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as our "online services").
The terms used are gender-neutral.
Last updated: 27 November 2024
Contents
- Preamble
- Controller
- Contact Details of the Data Protection Officer
- Overview of Processing
- Applicable Legal Bases
- Security Measures
- General Information on Data Retention and Erasure
- Rights of Data Subjects
- Provision of Online Services and Web Hosting
- Registration, Login and User Accounts
- Plugins and Embedded Features and Content
- Changes and Updates
- Definitions
Controller
M. Nürnberger
Jena University Hospital
Am Klinikum 1
07747 Jena
Email address: info@klein-score.de
Contact Details of the Data Protection Officer
info@klein-score.de
Overview of Processing
The following overview summarises the types of data processed and the purposes of their processing, and identifies the data subjects concerned.
Types of Data Processed
- Master data.
- Contact data.
- Content data.
- Usage data.
- Metadata, communication data and procedural data.
- Log data.
Categories of Data Subjects
- Users.
Purposes of Processing
- Provision of contractual services and fulfilment of contractual obligations.
- Security measures.
- Organisational and administrative procedures.
- Provision of our online services and user-friendliness.
- Information technology infrastructure.
Applicable Legal Bases
Applicable legal bases under the GDPR: The following provides an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. If more specific legal bases apply in individual cases, we will inform you of these in this Privacy Policy.
- Consent (Article 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract.
- Legitimate interests (Article 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, provided that these are not overridden by the interests or fundamental rights and freedoms of the data subject that require the protection of personal data.
National data protection provisions in Germany: In addition to the data protection provisions of the GDPR, national data protection provisions apply in Germany. These include, in particular, the Act on Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains specific provisions concerning, in particular, the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers and automated individual decision-making, including profiling. The data protection laws of the individual German federal states may also apply.
Third country (outside the EU and Switzerland): The data protection provisions in the controller's country of establishment apply in addition to or alongside the provisions of the GDPR. These provisions may contain specific requirements that go beyond or differ from those of the GDPR. These include, among other things, provisions on protection against the misuse of personal data, rights of access and erasure, rights to object, processing of special categories of personal data, processing for other purposes, data transfers and automated decision-making, including profiling.
Security Measures
In accordance with legal requirements, and taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to data, as well as access permissions, data entry, disclosure, availability and segregation. We have also established procedures to ensure the exercise of data subject rights, the erasure of data and responses to threats to data security. Furthermore, we take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and by default.
IP address truncation: If IP addresses are processed by us or by the service providers and technologies we use, and processing a complete IP address is not necessary, the IP address is truncated (also known as "IP masking"). This involves removing the last two digits or the last part of the IP address after a dot, or replacing them with placeholders. Truncating the IP address is intended to prevent or significantly hinder the identification of a person through their IP address.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect user data transmitted through our online services against unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are cornerstones of secure data transmission on the internet. These technologies encrypt information transmitted between the website or app and the user's browser (or between two servers), protecting the data against unauthorised access. TLS, the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL. This signals to users that their data is transmitted securely and in encrypted form.
General Information on Data Retention and Erasure
We erase personal data that we process in accordance with legal requirements as soon as the underlying consent is withdrawn or there is no longer any other legal basis for processing. This applies where the original purpose of processing no longer exists or the data is no longer required. Exceptions apply where legal obligations or particular interests require data to be retained or archived for longer.
In particular, data that must be retained for commercial or tax law purposes, or whose retention is necessary to pursue legal claims or protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on data retention and erasure that applies specifically to particular processing activities.
If several retention periods or erasure deadlines are specified for an item of data, the longest period always applies.
If a period does not expressly begin on a specific date and lasts at least one year, it automatically begins at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in which data is stored, the triggering event is the date on which termination takes effect or the legal relationship otherwise ends.
Data that is retained no longer for its originally intended purpose, but because of legal requirements or other reasons, is processed exclusively for the purposes that justify its retention.
Further information on processing activities, procedures and services:
- Data retention and erasure: The following general periods apply to retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, the work instructions and other organisational documents necessary to understand them, accounting vouchers and invoices (Section 147(3) in conjunction with Section 147(1), nos. 1, 4 and 4a AO; Section 14b(1) UStG; Section 257(1), nos. 1 and 4, and Section 257(4) HGB).
- 6 years – Other business documents: commercial or business correspondence received, copies of commercial or business correspondence sent, and other documents insofar as they are relevant for taxation, such as hourly wage slips, cost allocation sheets, calculation documents and price records, as well as payroll documents insofar as they are not already accounting vouchers, and cash register tapes (Section 147(3) in conjunction with Section 147(1), nos. 2, 3 and 5 AO; Section 257(1), nos. 2 and 3, and Section 257(4) HGB).
- 3 years – Data required to address potential warranty and compensation claims or similar contractual claims and rights, and to handle related enquiries, based on previous business experience and customary industry practices, is retained for the standard statutory limitation period of three years (Sections 195 and 199 BGB).
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent at any time.
- Right of access: You have the right to request confirmation as to whether relevant data is being processed, to obtain access to this data and further information, and to receive a copy of the data in accordance with legal requirements.
- Right to rectification: In accordance with legal requirements, you have the right to request that incomplete data concerning you be completed or that inaccurate data concerning you be corrected.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be erased without undue delay or, alternatively, that processing of the data be restricted.
- Right to data portability: In accordance with legal requirements, you have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR.
Provision of Online Services and Web Hosting
We process user data to provide our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and features of our online services to the user's browser or device.
- Types of data processed: Usage data (e.g. page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and features); metadata, communication data and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); log data (e.g. log files relating to logins, data retrieval or access times); content data (e.g. text or image messages and posts, and related information such as authorship or time of creation).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment, such as computers and servers); security measures.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Retention and Erasure".
- Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- Provision of online services using rented storage space: To provide our online services, we use storage space, computing capacity and software that we rent or otherwise obtain from a server provider (also known as a "web host"); Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
- Collection of access data and log files: Access to our online services is recorded in what are known as "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, confirmation of successful retrieval, the browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used for security purposes, for example to prevent server overload, particularly in the event of abusive attacks known as DDoS attacks, and to ensure appropriate server utilisation and stability; Legal bases: Legitimate interests (Article 6(1)(f) GDPR). Erasure of data: Log file information is stored for a maximum of 30 days and then erased or anonymised. Data that must be retained for evidentiary purposes is exempt from erasure until the relevant incident has been finally resolved.
- Email sending and hosting: The web hosting services we use also include sending, receiving and storing emails. For these purposes, the addresses of recipients and senders, other information relating to email transmission (e.g. the providers involved) and the content of the respective emails are processed. This data may also be processed to detect spam. Please note that emails sent over the internet are not generally encrypted throughout. Although emails are usually encrypted during transmission, they are not encrypted on the servers from which they are sent and received unless end-to-end encryption is used. We therefore cannot assume responsibility for the transmission of emails between the sender and their receipt on our server; Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
- STRATO: Services relating to the provision of information technology infrastructure and associated services (e.g. storage space and/or computing capacity); Service provider: STRATO AG, Pascalstraße 10,10587 Berlin, Germany; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://www.strato.de; Privacy Policy: https://www.strato.de/datenschutz/. Data processing agreement: Provided by the service provider.
Registration, Login and User Accounts
Users can create a user account. During registration, users are informed of the mandatory information required, which is processed to provide the user account on the basis of the fulfilment of contractual obligations. The data processed includes, in particular, login information (username, password and an email address).
When users use our registration and login functions and their user accounts, we store the IP address and the time of the respective user action. This storage is based on our legitimate interests and those of users in protection against misuse and other unauthorised use. As a rule, this data is not disclosed to third parties unless disclosure is necessary to pursue our claims or is required by law.
Users may be informed by email about matters relevant to their user accounts, such as technical changes.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts, and related information such as authorship or time of creation); usage data (e.g. page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and features); log data (e.g. log files relating to logins, data retrieval or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; security measures; organisational and administrative procedures; provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Retention and Erasure". Erasure following termination.
- Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- Registration using pseudonyms: Users may use pseudonyms as usernames instead of their real names; Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
- User profiles are not public: User profiles are not publicly visible or accessible.
- Erasure of data following termination: When users terminate their user accounts, the data relating to their accounts is erased, subject to any statutory permission or obligation, or the users' consent; Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
- No obligation to retain data: Users are responsible for backing up their data before the end of the contract once notice of termination has been given. We are entitled to irretrievably erase all user data stored during the contractual period; Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
Plugins and Embedded Features and Content
We integrate functional elements and content into our online services that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may include, for example, graphics, videos or maps (hereinafter collectively referred to as "content").
Embedding this content always requires third-party providers to process users' IP addresses, as they could not send the content to users' browsers without them. The IP address is therefore necessary to display this content or provide these features. We endeavour to use only content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Pixel tags can be used to analyse information such as visitor traffic on this website. This pseudonymous information may also be stored in cookies on users' devices and may include technical information about the browser and operating system, referring websites, the time of the visit and further information about the use of our online services. It may also be combined with such information from other sources.
Information on legal bases: Where we ask users for their consent to the use of third-party providers, consent forms the legal basis for processing. Otherwise, user data is processed on the basis of our legitimate interests (i.e. an interest in efficient, economical and user-friendly services). In this context, please also refer to the information on the use of cookies in this Privacy Policy.
- Types of data processed: Usage data (e.g. page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and features); metadata, communication data and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Retention and Erasure". Cookies may be stored for up to 2 years (unless otherwise stated, cookies and similar storage methods may remain on users' devices for a period of two years).
- Legal bases: Consent (Article 6(1)(a) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Changes and Updates
Please review the contents of our Privacy Policy regularly. We amend this Privacy Policy whenever changes to our data processing activities make this necessary. We will inform you if the changes require action on your part, such as consent, or otherwise require individual notification.
Where this Privacy Policy includes addresses and contact information for companies and organisations, please note that these may change over time. Please check the details before making contact.
Definitions
This section provides an overview of the terminology used in this Privacy Policy. Where terms are defined by law, their statutory definitions apply. The explanations below are primarily intended to aid understanding.
- Master data: Master data comprises essential information required to identify and manage contractual partners, user accounts, profiles and similar records. This data may include personal and demographic details such as names, contact information (addresses, telephone numbers and email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for formal interactions between individuals and services, institutions or systems by enabling clear identification and communication.
- Content data: Content data comprises information generated in the course of creating, editing and publishing content of any kind. This category may include text, images, videos, audio files and other multimedia content published across different platforms and media. Content data is not limited to the content itself, but also includes metadata providing information about the content, such as tags, descriptions, author information and publication dates.
- Contact data: Contact data is essential information that enables communication with individuals or organisations. It includes telephone numbers, postal addresses and email addresses, as well as communication identifiers such as social media handles and instant messaging identifiers.
- Metadata, communication data and procedural data: These categories contain information about how data is processed, transmitted and managed. Metadata, also known as data about data, includes information describing the context, origin and structure of other data. It may include file size, creation date, document author and revision histories. Communication data records the exchange of information between users through various channels, such as email correspondence, call logs, social network messages and chat histories, including the participants, timestamps and transmission routes. Procedural data describes processes and workflows within systems or organisations, including workflow documentation, transaction and activity records, and audit logs used to track and review operations.
- Usage data: Usage data refers to information recording how users interact with digital products, services or platforms. It encompasses a wide range of information showing how users use applications, which features they prefer, how long they spend on particular pages and which paths they follow through an application. Usage data may also include frequency of use, activity timestamps, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Usage data also plays a key role in identifying trends, preferences and potential problem areas within digital services.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, an online identifier (e.g. a cookie), or one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity.
- Log data: Log data is information about events or activities recorded in a system or network. It typically includes information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used to analyse system problems, monitor security or produce performance reports.
- Controller: The "controller" is the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of processing personal data.
- Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data, including collection, analysis, storage, transmission and erasure.