Privacy
I. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
University of Siegen
Faculty III, Information Systems and New Media
Prof. Dr. Volker Wulf
Kohlbettstraße 15
57072 Siegen
Germany
Tel.: +49 271 740-4036
Email: volker.wulf@uni-siegen.de
Website: www.wineme.uni-siegen.de
II. Data protection officer
The data protection officer of the University of Siegen can be reached at:
University of Siegen
Data Protection Officer
Adolf-Reichwein-Straße 2a
57076 Siegen
Germany
Tel.: +49 271 740-5147
Email: datenschutzbeauftragter@uni-siegen.de
III. General information on data processing
1. Scope of processing
We process users' personal data only as far as necessary to provide a working website and our content and services. This website sets no cookies, uses no analytics or tracking tools and loads no content from other providers. Fonts, images and scripts are served from our own server. There is no registration and no newsletter.
2. Legal basis
Where we obtain the data subject's consent, Art. 6 (1) (a) GDPR is the legal basis. Where processing is necessary for a legitimate interest of ours or of a third party and the data subject's interests, fundamental rights and freedoms do not override it, the legal basis is Art. 6 (1) (f) GDPR.
3. Erasure and retention
Personal data is erased or blocked as soon as the purpose of storage no longer applies. Storage may continue where European or national law to which the controller is subject provides for it. Data is also blocked or erased when a retention period prescribed there expires.
IV. Providing the website and server logs
1. Description and scope
Each time the website is accessed, our system automatically collects data from the accessing device:
- browser type and version
- operating system
- IP address
- date and time of access
- the page requested and the page you came from
This data is stored in our system's log files. It is not stored together with other personal data of the user.
2. Legal basis
The legal basis for the temporary storage of the data and the log files is Art. 6 (1) (f) GDPR.
3. Purpose
Temporary storage of the IP address is necessary to deliver the website to your device; for this the IP address must be kept for the duration of the session. Storage in log files serves the functioning and optimisation of the website and the security of our IT systems. The data is not evaluated for marketing purposes. These purposes are also our legitimate interest under Art. 6 (1) (f) GDPR.
4. Retention
Data is erased as soon as it is no longer needed for its purpose. For delivering the website, that is when the session ends. Log files are erased after seven days at the latest. Longer storage is possible; in that case IP addresses are erased or altered so that they can no longer be attributed to the accessing device.
5. Objection and removal
Collecting the data to provide the website and storing it in log files is strictly necessary for operating the site. There is therefore no right to object.
V. Cookies and local storage
This website sets no cookies. If you turn the page sound off, your browser remembers this setting locally (localStorage). It is not sent to us and you can delete it at any time in your browser settings. It is strictly necessary for the function you asked for (§ 25 (2) no. 2 TDDDG).
VI. Contact form and contact by email
The homepage has a contact form. If you use it, your name, email address, message and the language of the page are sent to our server and forwarded from there as an email to the project team at the University of Siegen. The message itself is not stored on the server. To prevent misuse, the server keeps an irreversible checksum (hash) of your IP address together with the time of sending for one hour. It is then deleted.
You can also write to us directly at david.unbehaun@uni-siegen.de. In both cases we store the data sent (at least your email address and the content of the message) to answer your enquiry. We do not pass it on to third parties.
The legal basis is Art. 6 (1) (f) GDPR. If the contact aims at concluding a contract, Art. 6 (1) (b) GDPR is an additional legal basis. The data is erased once the conversation has ended, that is, when the circumstances show that the matter has been conclusively resolved. You can object to the storage at any time. The conversation cannot then be continued, and all data stored in the course of the contact is erased.
VII. External links
In some places this website links to pages of other providers, such as publications and partners. When you click a link you leave our website. The respective providers are responsible for data processing there.
VIII. Rights of the data subject
If personal data about you is processed, you are a data subject within the meaning of the GDPR and have the following rights against the controller:
1. Right of access
You can ask for confirmation of whether we process personal data concerning you. If we do, you can request information about:
- the purposes of the processing;
- the categories of personal data processed;
- the recipients or categories of recipients to whom the data has been or will be disclosed;
- the planned retention period or, if that is not possible, the criteria for determining it;
- the existence of a right to rectification, erasure, restriction of processing and objection;
- the right to lodge a complaint with a supervisory authority;
- any available information on the source of the data, if it was not collected from you;
- the existence of automated decision-making including profiling under Art. 22 (1) and (4) GDPR, with meaningful information about the logic involved and its significance and consequences.
You can also ask whether your data is transferred to a third country or an international organisation, and be informed of the appropriate safeguards under Art. 46 GDPR.
2. Right to rectification
If the data concerning you is inaccurate or incomplete, you can ask for it to be rectified and completed without delay.
3. Right to restriction of processing
You can ask for processing to be restricted if
- you contest the accuracy of the data, for the period we need to verify it;
- the processing is unlawful and you oppose erasure and ask for restriction instead;
- we no longer need the data but you need it to establish, exercise or defend legal claims, or
- you have objected under Art. 21 (1) GDPR and it is not yet clear whether our legitimate grounds override yours.
Where processing is restricted, the data may, apart from storage, only be processed with your consent, to establish, exercise or defend legal claims, to protect the rights of others or for reasons of important public interest. You will be informed before the restriction is lifted.
4. Right to erasure
You can ask for the data concerning you to be erased without delay, and we must erase it if one of these grounds applies:
- The data is no longer necessary for the purposes for which it was collected.
- You withdraw your consent (Art. 6 (1) (a) or Art. 9 (2) (a) GDPR) and there is no other legal basis.
- You object under Art. 21 (1) GDPR and there are no overriding legitimate grounds, or you object under Art. 21 (2) GDPR.
- The data was processed unlawfully.
- Erasure is necessary to comply with a legal obligation.
- The data was collected in relation to information society services under Art. 8 (1) GDPR.
If we have made data public and must erase it, we take reasonable steps, taking into account available technology and cost, to inform other controllers that you have requested erasure of all links to, copies or replications of that data.
The right to erasure does not apply to the extent that processing is necessary
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation or for a task carried out in the public interest or in the exercise of official authority;
- for reasons of public interest in the area of public health;
- for archiving purposes in the public interest, scientific or historical research or statistical purposes under Art. 89 (1) GDPR, insofar as erasure is likely to render impossible or seriously impair those aims, or
- for the establishment, exercise or defence of legal claims.
5. Right to notification
If you have asserted rectification, erasure or restriction of processing, we notify every recipient to whom your data was disclosed, unless this proves impossible or involves disproportionate effort. You have the right to be informed about these recipients.
6. Right to data portability
You have the right to receive the data you provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller without hindrance, where the processing is based on consent (Art. 6 (1) (a) or Art. 9 (2) (a) GDPR) or a contract (Art. 6 (1) (b) GDPR) and is carried out by automated means. Where technically feasible, you can have the data transmitted directly from us to another controller. This must not adversely affect the rights and freedoms of others. The right does not apply to processing necessary for a task carried out in the public interest or in the exercise of official authority.
7. Right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you that is based on Art. 6 (1) (e) or (f) GDPR. We then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. In connection with information society services you can also exercise this right by automated means using technical specifications.
8. Right to withdraw consent
You can withdraw any consent you have given at any time. This does not affect the lawfulness of processing carried out before the withdrawal.
9. Automated individual decision-making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not make such decisions.
10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement, if you consider that the processing of your data infringes the GDPR. For the University of Siegen this is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany. The authority informs you of the progress and outcome of the complaint, including the possibility of a judicial remedy under Art. 78 GDPR.