Privacy Policy

We are pleased that you are interested in our company. Data protection is a particularly high priority for the management of KIT Campus Transfer GmbH. Our website can generally be used without providing any personal data. However, if a data subject wishes to use specific services offered by our company through our website, processing personal data may become necessary. If such processing is necessary and there is no statutory basis for it, we generally obtain the data subject’s consent.

Personal data, such as a data subject’s name, address, email address or telephone number, is always processed in accordance with the General Data Protection Regulation (GDPR) and the country-specific data protection provisions applicable to KIT Campus Transfer GmbH. Through this privacy policy, our company wishes to inform the public about the nature, scope and purpose of the personal data we collect, use and process. This privacy policy also informs data subjects about their rights.

As the controller, KIT Campus Transfer GmbH has implemented numerous technical and organisational measures to ensure the most comprehensive protection possible for personal data processed through this website. Nevertheless, internet-based data transmissions may have security vulnerabilities, meaning that absolute protection cannot be guaranteed. For this reason, data subjects may also provide personal data to us through alternative channels, such as by telephone.

 

1. Definitions

The privacy policy of KIT Campus Transfer GmbH is based on the terminology used by the European legislator when adopting the General Data Protection Regulation (GDPR). Our privacy policy should be easy to read and understand for the public, our customers and our business partners. To ensure this, we would first like to explain the terminology used.

 

We use the following terms, among others, in this privacy policy:

 

a) Personal data

Personal data means any information relating to an identified or identifiable natural person, hereinafter referred to as the “data subject”. An identifiable natural person is someone who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.

 

b) Data subject

A data subject is any identified or identifiable natural person whose personal data is processed by the controller.

 

c) Processing

Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

 

d) Restriction of processing

Restriction of processing means marking stored personal data with the aim of limiting its future processing.

 

e) Profiling

Profiling means any form of automated processing of personal data that involves using personal data to evaluate certain personal aspects relating to a natural person, particularly to analyse or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

 

f) Pseudonymisation

Pseudonymisation means processing personal data in such a way that it can no longer be attributed to a specific data subject without additional information, provided that this additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data is not attributed to an identified or identifiable natural person.

 

g) Controller

The controller is the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be provided for by Union or Member State law.

 

h) Processor

A processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.

 

i) Recipient

A recipient is a natural or legal person, public authority, agency or other body to which personal data is disclosed, whether or not it is a third party. However, public authorities that may receive personal data in the context of a particular investigation under Union or Member State law are not considered recipients.

 

j) Third party

A third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and persons authorised to process personal data under the direct authority of the controller or processor.

 

k) Consent

Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of their personal data through a statement or a clear affirmative action.

 

2. Name and Address of the Controller

The controller for the purposes of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union, and other provisions relating to data protection is:

 

Short Course & TFT Forum

 

Organiser:


KIT Campus Transfer GmbH
Haid-und-Neu-Straße 7
76131 Karlsruhe
Germany

Telephone: +49 162 8449570

Email: info@course-forum.de

Website: www.course-forum.de

 

3. Cookies

The websites of KIT Campus Transfer GmbH use cookies. Cookies are text files placed and stored on a computer system through an internet browser.

 

Many websites and servers use cookies. Many cookies contain a cookie ID, which is a unique identifier consisting of a string of characters. This allows websites and servers to identify the specific internet browser in which the cookie has been stored. It enables visited websites and servers to distinguish the data subject’s individual browser from other browsers containing different cookies. A particular internet browser can be recognised and identified through its unique cookie ID.

By using cookies, KIT Campus Transfer GmbH can provide users of this website with more user-friendly services that would not be possible without cookies.

 

Cookies allow us to optimise the information and services on our website for users. As mentioned above, cookies enable us to recognise users of our website. The purpose of this recognition is to make the website easier to use. For example, users of a website that uses cookies do not need to re-enter their login details each time they visit, because the website and the cookie stored on their computer system perform this function. Another example is a shopping cart cookie in an online shop. The online shop uses a cookie to remember the items a customer has placed in their virtual shopping cart.

 

Data subjects can prevent our website from placing cookies at any time by adjusting the settings of their internet browser, thereby permanently rejecting cookies. Cookies that have already been placed can also be deleted at any time through an internet browser or other software. This is possible in all commonly used internet browsers. If a data subject disables cookies in their browser, some functions of our website may not be fully available.

 

4. Collection of General Data and Information

The website of KIT Campus Transfer GmbH collects a range of general data and information whenever a data subject or an automated system accesses it. This general data and information is stored in the server’s log files. The information collected may include:

  1. The browser types and versions used.
  2. The operating system used by the accessing system.
  3. The website from which the accessing system reaches our website, known as the referrer.
  4. The subpages accessed on our website.
  5. The date and time of access.
  6. An Internet Protocol address (IP address).
  7. The internet service provider of the accessing system.
  8. Other similar data and information used to protect against attacks on our information technology systems.

When using this general data and information, KIT Campus Transfer GmbH does not draw conclusions about the data subject. Rather, this information is required to:

  1. Deliver the content of our website correctly.
  2. Optimise our website content and its advertising.
  3. Ensure the continued functionality of our information technology systems and website technology.
  4. Provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack.

KIT Campus Transfer GmbH therefore analyses this anonymously collected data and information for statistical purposes and to improve data protection and data security within our company, with the ultimate aim of ensuring an optimal level of protection for the personal data we process. Anonymous server log file data is stored separately from all personal data provided by a data subject.

 

5. Registration on Our Website

Data subjects can register on the controller’s website by providing personal data. The personal data transmitted to the controller is determined by the registration form used. Personal data entered by a data subject is collected and stored exclusively for the controller’s internal use and its own purposes. The controller may arrange for this data to be transferred to one or more processors, such as a parcel delivery service, which also uses the personal data exclusively for internal purposes attributable to the controller.

 

When a data subject registers on the controller’s website, the IP address assigned by their internet service provider (ISP), together with the date and time of registration, is also stored. This information is stored to prevent misuse of our services and, where necessary, to enable criminal offences to be investigated. Storing this data is therefore necessary to safeguard the controller. As a rule, this data is not disclosed to third parties unless there is a legal obligation to disclose it or disclosure serves law enforcement purposes.

Registration involving the voluntary provision of personal data enables the controller to offer the data subject content or services that, by their nature, can only be offered to registered users. Registered users may change the personal data provided during registration at any time or have it completely deleted from the controller’s records.

 

Upon request, the controller will inform any data subject at any time about the personal data stored about them. The controller will also rectify or erase personal data at the data subject’s request or notification, provided that no statutory retention obligations prevent this. All employees of the controller are available as contacts for this purpose.

 

6. Contact Through the Website

In accordance with statutory requirements, the website of KIT Campus Transfer GmbH contains information enabling rapid electronic contact and direct communication with our company, including a general email address. If a data subject contacts the controller by email or through a contact form, the personal data they provide is automatically stored. Personal data voluntarily transmitted to the controller in this way is stored for the purpose of handling the enquiry or contacting the data subject. This personal data is not disclosed to third parties.

 

7. Routine Erasure and Blocking of Personal Data

The controller processes and stores a data subject’s personal data only for the period necessary to fulfil the purpose of storage, or for the period required by the European legislator or another legislator under laws or regulations to which the controller is subject.

If the purpose of storage no longer applies, or a retention period prescribed by the European legislator or another competent legislator expires, personal data is routinely blocked or erased in accordance with statutory requirements.

 

8. Rights of the Data Subject

a) Right to confirmation

Every data subject has the right granted by the European legislator to obtain confirmation from the controller as to whether personal data concerning them is being processed. Data subjects wishing to exercise this right may contact an employee of the controller at any time.

b) Right of access

Every data subject whose personal data is processed has the right granted by the European legislator to obtain information about their stored personal data from the controller, free of charge, at any time, and to receive a copy of that information. The European legislator also grants data subjects access to the following information:

  • The purposes of processing.
  • The categories of personal data being processed.
  • The recipients or categories of recipients to whom the personal data has been or will be disclosed, particularly recipients in third countries or international organisations.
  • Where possible, the intended period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period.
  • The existence of a right to request rectification or erasure of personal data, restriction of processing by the controller, or to object to such processing.
  • The right to lodge a complaint with a supervisory authority.
  • Where the personal data was not collected from the data subject, any available information about its source.
  • The existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.

Data subjects also have the right to obtain information about whether their personal data has been transferred to a third country or an international organisation. Where this is the case, they have the right to be informed about the appropriate safeguards relating to the transfer.

 

Data subjects wishing to exercise their right of access may contact an employee of the controller at any time.

 

c) Right to rectification

Every data subject whose personal data is processed has the right granted by the European legislator to obtain the rectification of inaccurate personal data concerning them without undue delay. Taking into account the purposes of processing, data subjects also have the right to have incomplete personal data completed, including by providing a supplementary statement.

Data subjects wishing to exercise this right may contact an employee of the controller at any time.

 

d) Right to erasure (“right to be forgotten”)

Every data subject whose personal data is processed has the right granted by the European legislator to request that the controller erase personal data concerning them without undue delay where one of the following grounds applies and insofar as processing is not necessary:

  • The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
  • The data subject withdraws the consent on which processing was based under Article 6(1)(a) or Article 9(2)(a) GDPR, and there is no other legal basis for processing.
  • The data subject objects to processing under Article 21(1) GDPR and there are no overriding legitimate grounds for processing, or the data subject objects to processing under Article 21(2) GDPR.
  • The personal data has been unlawfully processed.
  • The personal data must be erased to comply with a legal obligation under Union or Member State law to which the controller is subject.
  • The personal data was collected in connection with the provision of information society services referred to in Article 8(1) GDPR.

If one of these grounds applies and a data subject wishes to request the erasure of personal data stored by KIT Campus Transfer GmbH, they may contact an employee of the controller at any time. The employee of KIT Campus Transfer GmbH will arrange for the erasure request to be fulfilled without undue delay.

 

Where KIT Campus Transfer GmbH has made personal data public and, as the controller, is obliged to erase it under Article 17(1) GDPR, the company will take reasonable steps, including technical measures, taking into account the available technology and implementation costs, to inform other controllers processing the published personal data that the data subject has requested the erasure of any links to, or copies or replications of, that personal data, insofar as processing is not necessary. The employee of KIT Campus Transfer GmbH will take the necessary steps in each individual case.

 

e) Right to restriction of processing

Every data subject whose personal data is processed has the right granted by the European legislator to obtain restriction of processing from the controller where one of the following conditions applies:

  • The data subject contests the accuracy of the personal data, for a period allowing the controller to verify its accuracy.
  • Processing is unlawful, and the data subject opposes erasure of the personal data and requests restriction of its use instead.
  • The controller no longer needs the personal data for processing purposes, but the data subject requires it to establish, exercise or defend legal claims.
  • The data subject has objected to processing under Article 21(1) GDPR, and verification of whether the controller’s legitimate grounds override those of the data subject is pending.

f) Right to data portability

Every data subject whose personal data is processed has the right granted by the European legislator to receive the personal data concerning them that they have provided to a controller in a structured, commonly used and machine-readable format. They also have the right to transmit this data to another controller without hindrance from the controller to which it was provided, where processing is based on consent under Article 6(1)(a) or Article 9(2)(a) GDPR, or on a contract under Article 6(1)(b) GDPR, and is carried out by automated means, provided that processing is not necessary for performing a task carried out in the public interest or in the exercise of official authority vested in the controller.

 

When exercising their right to data portability under Article 20(1) GDPR, data subjects also have the right to have their personal data transmitted directly from one controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.

 

Data subjects wishing to exercise their right to data portability may contact an employee of KIT Campus Transfer GmbH at any time.

 

g) Right to object

Every data subject whose personal data is processed has the right granted by the European legislator to object at any time, on grounds relating to their particular situation, to processing of their personal data based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on these provisions.

 

If a data subject objects, KIT Campus Transfer GmbH will no longer process their personal data unless we can demonstrate compelling legitimate grounds for processing that override the data subject’s interests, rights and freedoms, or unless processing serves the establishment, exercise or defence of legal claims.

 

Where KIT Campus Transfer GmbH processes personal data for direct marketing purposes, data subjects have the right to object at any time to processing of their personal data for such marketing. This also applies to profiling insofar as it is related to direct marketing. If a data subject objects to KIT Campus Transfer GmbH processing their personal data for direct marketing purposes, KIT Campus Transfer GmbH will no longer process it for those purposes.

 

Data subjects also have the right, on grounds relating to their particular situation, to object to processing of their personal data by KIT Campus Transfer GmbH for scientific or historical research purposes or statistical purposes under Article 89(1) GDPR, unless processing is necessary to perform a task carried out in the public interest.

To exercise their right to object, data subjects may contact any employee of KIT Campus Transfer GmbH or another employee directly. In the context of using information society services, and notwithstanding Directive 2002/58/EC, data subjects may also exercise their right to object by automated means using technical specifications.

 

h) Automated individual decision-making, including profiling

Every data subject whose personal data is processed has the right granted by the European legislator not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them, provided that the decision:

  1. Is not necessary for entering into or performing a contract between the data subject and the controller; or
  2. Is not authorised by Union or Member State law to which the controller is subject and which provides appropriate measures to safeguard the data subject’s rights, freedoms and legitimate interests; or
  3. Is not based on the data subject’s explicit consent.

Where the decision is necessary for entering into or performing a contract between the data subject and the controller, or is based on the data subject’s explicit consent, KIT Campus Transfer GmbH will implement appropriate measures to safeguard the data subject’s rights, freedoms and legitimate interests. These include, at a minimum, the right to obtain human intervention on the controller’s part, express their point of view and contest the decision.

 

Data subjects wishing to exercise rights relating to automated decisions may contact an employee of the controller at any time.

 

i) Right to withdraw consent to data processing

Every data subject whose personal data is processed has the right granted by the European legislator to withdraw their consent to processing of their personal data at any time.

Data subjects wishing to exercise this right may contact an employee of the controller at any time.

 

9. Legal Basis for Processing

Article 6(1)(a) GDPR serves as the legal basis for processing operations for which our company obtains consent for a specific processing purpose.

 

Where processing personal data is necessary to perform a contract to which the data subject is a party, for example when processing is necessary to supply goods or provide another service or consideration, processing is based on Article 6(1)(b) GDPR. The same applies to processing necessary to take steps prior to entering into a contract, such as handling enquiries about our products or services.

Where our company is subject to a legal obligation requiring the processing of personal data, such as compliance with tax obligations, processing is based on Article 6(1)(c) GDPR.

 

In rare cases, processing personal data may be necessary to protect the vital interests of the data subject or another natural person. This could occur, for example, if a visitor were injured on our premises and their name, age, health insurance information or other vital information needed to be passed to a doctor, hospital or another third party. In this case, processing would be based on Article 6(1)(d) GDPR.

 

Finally, processing operations may be based on Article 6(1)(f) GDPR. This legal basis applies to processing not covered by any of the preceding legal bases where processing is necessary to pursue a legitimate interest of our company or a third party, provided that the data subject’s interests, fundamental rights and freedoms do not override that interest. Such processing is permitted particularly because it was expressly recognised by the European legislator, which considered that a legitimate interest could exist where the data subject is a customer of the controller (Recital 47, second sentence, GDPR).

 

10. Legitimate Interests Pursued by the Controller or a Third Party

Where processing personal data is based on Article 6(1)(f) GDPR, our legitimate interest is conducting our business activities for the benefit of all our employees and shareholders.

 

11. Period for Which Personal Data Is Stored

The applicable statutory retention period determines how long personal data is stored. Once this period expires, the corresponding data is routinely erased, provided that it is no longer required to perform or initiate a contract.

 

12. Statutory or Contractual Requirements to Provide Personal Data; Necessity for Entering into a Contract; Obligation to Provide Personal Data; Possible Consequences of Failure to Provide It

Providing personal data may be required by law, for example under tax regulations, or may arise from contractual provisions, such as requirements to provide information about a contracting party.

 

In some cases, entering into a contract may require a data subject to provide personal data that we must subsequently process. For example, a data subject is obliged to provide personal data when our company enters into a contract with them. Failure to provide this personal data would mean that the contract could not be concluded.

 

Before providing personal data, the data subject must contact one of our employees. The employee will explain, on a case-by-case basis, whether providing the personal data is required by law or contract, or is necessary to enter into a contract; whether there is an obligation to provide it; and what consequences would follow if it were not provided.

Information icon

Wir benötigen Ihre Zustimmung zum Laden der Übersetzungen

Wir nutzen einen Drittanbieter-Service, um den Inhalt der Website zu übersetzen, der möglicherweise Daten über Ihre Aktivitäten sammelt. Bitte überprüfen Sie die Details in der Datenschutzerklärung und akzeptieren Sie den Dienst, um die Übersetzungen zu sehen.