Data Protection Policy

Data Protection Information for Fraunhofer Heinrich Hertz Institute HHI

The following pertains to the use of this website. As the party responsible for data processing (controller), we process your personal data collected via our website and store them for the period necessary to achieve the specified purposes and to comply with statutory requirements. In the following, we inform you about the data we collect and the way we process them. Furthermore, we inform you about your data privacy rights pertaining to the use of this website.

Personal data, as defined by Article 4(1) General Data Protection Regulation (GDPR) includes any information relating to an identified or identifiable natural person.

1. Name and contact information of the person who signs responsible for the data processing (controller) and of the society’s data protection officer

This data protection information shall apply to the processing of data on our Institute’s website www.hhi.fraunhofer.de by the controller, the:

Fraunhofer Society for the Advancement of Applied Research
Fraunhofer Gesellschaft zur Förderung der angewandten Forschung e.V.
Hansastraße 27 c,
D-80686 München (Munich, Germany)

On behalf of your Fraunhofer Heinrich Hertz Institute HHI
(in the following referred to as ‘Fraunhofer Institute’)

Email: info@hhi.fraunhofer.de
Telephone: +49 30 31002-0

You can reach the Data Protection Officer of the Fraunhofer Institute at the above address c/o Data Protection Officer or at datenschutz@zv.fraunhofer.de.

Please do not hesitate to contact the Data Protection Officer directly at any time in case of any questions concerning your data protection rights and/or your rights as data subject.

2. Processing of Personal Data and Purposes of the Data Processing

a) When visiting the website

You may access our website without having to disclose any details of your identity. The browser installed on your terminal device automatically transmits information to the server of our website (e.g. browser type and version, date and time of access) to enable connection with the website, including the IP address of your requesting terminal device. This information is temporarily stored in a so-called log file and deleted after 30 days.

Your IP address is processed for technical and administrative purposes regarding connection set-up and stability, to guarantee the security and functioning of our website and to be able to track any illegal attacks on the website, if required.

The legal basis for processing the IP address is Art. 6 (1) lit. f GDPR. Our legitimate interest ensues from said security interest and the necessity of the unobstructed availability of our website.

We cannot draw any direct conclusions about your identity from processing the IP address and other information in the log file.

Moreover, we use cookies and analytics services when you visit our website. Further details can be found further below in this data protection information.

a) When registering for events

We offer a variety of events through our website on a regular basis, for which you may register online.

In order to register online, our website’s visitors have to provide some mandatory data, which generally include:

  • First and last name
  • Address
  • Email address
  • Payment information (only for events that require payment and depending on the selected method of payment)

Any other mandatory data are marked as such (e.g. with *). Further information can often be provided voluntarily.

The purpose of processing the mandatory data is to identify you as event participant, to reserve a spot for your participation, to establish a contractual relationship with you, to provide you before, during and after the event with information that will optimize your participation, and to help us plan and ensure a smooth event experience. If we collect your payment information for events that require payment, the data are needed to process the participation fee. Voluntary data allow us to plan and conduct the event based on participant interest.

We process data at your request and for the purposes described by Article 6 (1) lit. b GDPR to fulfill the obligations of the participation agreement and precontractual conditions.

We store the data we collect in the context of event registrations for 6 months unless you have consented to a longer storage period under Art. 6 (1) lit. a GDPR.

Photos and videos will be taken to document the event in pictures. Since you can possibly be identified in these images, either directly or indirectly, they represent personal data.

The images are created for Fraunhofer and will be used for news reporting directly associated with the event as well as for internal and external reporting by Fraunhofer.

Furthermore, the images will be published for the purpose of subsequent news reporting on our social-media platforms or our website. This processing is required in particular to document our event and promote future events.

The legal basis for data processing is Art. 6 (1) lit. f GDPR. The purposes mentioned are legitimate interests within the meaning of the aforementioned provision.

3. Transfer of Personal Data to Third Parties

If we forward personal data collected through websites to processors, we will notify you in this data protection information regarding the respective data processing operation, citing the specific recipient.

Aside from that, we will only forward your personal data if

  • you have given consent pursuant to Art. 6 (1) lit. a GDPR;
  • this is required pursuant to Article 6 (1) lit. b GDPR for the performance of a contract with you (for example forwarding to shipping companies for the purpose of delivering goods ordered by you, or forwarding payment information to payment service providers or credit institutions in order to process a payment transaction);
  • there is a legal obligation for disclosure pursuant to Art. 6 (1) lit. c GDPR.

The recipients may use the transferred data for the above-mentioned purposes only.

4. Cookies

This website uses cookies. Cookies are small files that your browser automatically generates and stores on your device (laptop, tablet, smartphone, etc.) when you visit our site. Cookies do not harm your device nor do they contain viruses, Trojans or other malware.

Cookies store information associated with the specific device used. That does not mean that we can directly identify you.

We use cookies for the purpose of making the use of our offers more convenient and pleasant for you. For example, we use so-called session cookies to allow session controls or to save data entries in forms or shopping carts during the session. At the latest, session cookies are deleted when you close your browser.

 

On the other hand, we use cookies to statistically record the use of our website for the purpose of optimizing our offers for you (see Point ‎4). When you visit our site again, these cookies make it possible for us to automatically recognize that you have already visited our site before. These cookies are deleted after 90 days.

The data processed by the cookies are necessary for the above-mentioned purposes to protect our legitimate interests and those of third parties pursuant to Art. 6 (1) lit. f GDPR.

Most browsers automatically accept cookies. However, you can configure your browser to not save any cookies on your computer or to display a notice before new cookies are saved. Completely disabling cookies may mean that you cannot fully use all functions of our website.

5. Web analysis/Tracking using LeadLab (wiredminds GmbH)

Our website uses the Leadlab service by Wiredminds GmbH and its tracking pixel technology to analyze user behavior and optimize our site accordingly. The service particularly allows us to identify which companies have visited our site. In so doing we do not obtain any information that may identify you directly.

The use of Leadlab involves cookies and tracking pixels which allow statistical analysis of the use of this website based on your visits. Information, including personal information, about your visiting behavior is stored in the cookie and sent to Wiredminds or is directly obtained by Wiredminds. Wiredminds uses a pseudonym to process the information in a usage profile for the purpose of analysis. The data are anonymized to the extent possible.

Without your specific permission, we neither use the data collected to identify you personally nor will we match the data with personal data pertaining to the pseudonym associated with you.

If IP addresses are collected, they are immediately anonymized after collection by deleting the last number block.

For more information about data protection at Wiredminds, please visit the company’s website.

We process statistical data based on our legitimate interest pursuant to Article 6 (1) lit. f GDPR for optimizing our online offering and our web presence. Wiredminds processes the data on our behalf based on a data processing agreement between us and Wiredminds. This agreement ensures that the data processing on our behalf is consistent with the General Data Protection Regulation and guarantees the protection of the data subjects’ rights.

If you do not want your usage behavior to be recorded and analyzed, you may object by means of an opt-out cookie. It will be set to prevent the future collection of your data when you visit this website. The opt-out cookie works only in this browser and only for our website. It is stored on your device. If you delete the cookies for this browser, you will have to set the opt-out cookie again.

6. Social Plugins

We use so-called social media buttons (also called social media plug-ins) on our website. These are small icons which you can use to share the contents of our website in your profile on social networks.

If you activate such an icon, a connection is established between our website and the social network. In addition to the contents in question, the operator of the social network obtains further, partly personal information. For example, this includes the fact that you are currently visiting our site.

The social media buttons are integrated using the so-called Shariff solution. This solution prevents your device from establishing a link to the social network merely because you visit a website featuring a social plugin button without clicking on it. This means that information is only transmitted to the social network when you activate the button.

We integrate the following social plug-ins on our website:

 

a)   Facebook Ireland Limited: Sharing on Facebook

Information is partly transmitted to the parent company Facebook Inc., headquartered in the USA. This company complies with the data protection regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Commerce.

For the purpose and scope of data collection, further processing and use of data by Facebook as well as your related rights and configuration options for protecting your privacy, please refer to Facebook’s privacy policy.

 

b)   Twitter International Company: Sharing on Twitter

Information is partly transmitted to the parent company Twitter Inc., headquartered in the USA. This company complies with the data protection regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Commerce.

Further information on data protection on Twitter can be found in Twitter’s privacy policy.

 

c)   XING SE: Sharing on XING

Further information on data protection on XING can be found in XING’s privacy policy.

 

d)   LinkedIn Corporation: Sharing on LinkedIn

Information is partly transmitted to the parent company LinkedIn Corporation, headquartered in the USA. This company complies with the data protection regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Commerce. Further information on data protection on LinkedIn can be found in the company’s privacy policy.

7. YouTube

We use components (videos) of YouTube, LLC, 901 Cherry Ave., 94066 San Bruno, CA, USA (hereinafter “YouTube”), a company of Google Inc., Amphitheatre Parkway, Mountain View CA 94043, USA, (hereinafter “Google”) in our websites. The implementation is based on Art. 6 (1) lit. f GDPR; our legitimate interest in that case is the smooth integration of the videos and the attractive design of our website.

We use the “privacy-enhanced mode” option provided by YouTube.

When you access a page containing an embedded video, a connection to the YouTube servers is established and the contents are displayed on the Internet page through a notification to your browser.

Pursuant to YouTube specifications, in the “privacy-enhanced mode” your data - especially which of our website pages you visited as well as device-specific information including the IP address - is sent to the YouTube servers in the US only if you view the video.

If you are simultaneously logged into YouTube, this information is assigned to your YouTube member account. You may prevent this by logging out of your member account before visiting our website.

Google complies with the Data Protection Regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Trade.

Further information on data protection in connection with YouTube can be found in Google’s privacy policy.

8. Your Rights as Affected Person

You have the following rights:

 

  • Pursuant to Article 7(3) GDPR, you have the right to withdraw at any time any consent you may have given to us before.  Consequently, we may no longer continue the respective activity.
  • Pursuant to Article 15 GDPR, you have the right to obtain information on your personal data which we have processed. In particular, you have the right to information on the following:
    • Purposes of the data processing
    • The category of personal data,
    • The categories of recipients to which we disclosed or will disclose your data,
    • The planned storage periods of data,
    • The existence of the right to correction, deletion, restriction of processing and objection,
    • The right to appeal,
    • The right to know the origin of your data in the event that we did not collect these data,
    • The right to meaningful and detailed information on the existence of automated decision-making including profiling and, if applicable, relevant information on the details thereof;
  • Pursuant to Article 16 GDPR, you have the right to obtain without undue delay  the rectification of inaccurate personal data and/or the completion of incomplete personal data in storage at the Fraunhofer-Gesellschaft,
  • Pursuant to Article 17 GDPR, you have the right to the erasure of your personal data unless the erasure interferes with the execution of the right to the free expression of opinions and to information, with the compliance with legal obligations, is necessary in the public interest or for establishing, exercising or defending legal claims,
  • Pursuant to Article 18 GDPR, you have the right to restriction of processing of your personal data if you contest or challenge the accuracy of these data, the processing of the data is unlawful but you oppose the erasure of these data and we no longer need the data while you still need the data to establish, exercise or defend legal claims or you have raised an objection against the data processing pursuant to Article 21 GDPR,
  • Pursuant to Article 20 GDPR, you have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format or to demand the transmit to another controller and
  • Pursuant to Article 77 GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you may find such authority at your habitual residence, your workplace or our company domicile.

Information on your right to object pursuant to Article 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data pursuant to Article 6(1), point (f) GDPR (data processing for the purposes of the legitimate interests) and Article 6,(1), point (e) GDPR (data processing for the performance of a task carried out in the public interest). This shall also apply to profiling as prescribed by Article 4 No. 4 GDPR, which is based on this provision.

Once you file an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.

To the extent that your objection addresses the processing of data for direct advertising, we will stop the processing immediately. In this case, citing a special situation is not required. This shall also apply to profiling in as far as it relates to such direct advertising.

If you would like to assert your right to object, an email to datenschutz@zv.fraunhofer.de will suffice.

9. Data Security

We transmit all your personal data using the widely used and secure TLS (Transport Layer Security) encryption standard. The TLS protocol is a proven and secure standard that is also used in online banking transactions. You will recognise a secure TLS connection by the “s” following the http (https://...) in your browser URL or by the lock symbol in the lower section of your browser.

Moreover, we use suitable technical and organisational safety procedures to protect your data against accidental or wilful manipulation, partial or complete loss, destruction or against the unauthorised access by third parties. We constantly improve these security measures as the technology advances.

10. Timeliness of the Data and Amendments to this Data Protection Information

This data protection information as amended on May 2018 is currently applicable.

Due to improvements of our website and website offers or by virtue of amended statutory or administrative standards, it may become necessary to amend this data protection information. You may find the latest data protection information by clicking the link on this website: https://www.hhi.fraunhofer.de/en/data-protection-policy. You may read or print this updated and amended version at any time.

11. Severability

Should individual provisions of this data protection declaration be or become invalid either in part or in their entirety or prove infeasible at any time, this shall not affect the remaining provisions. This shall apply accordingly to gaps in this declaration.