Privacy policy

Information on the handling of personal data

We are very pleased about your interest in our website - and thus in our company. The protection of your private rights and freedoms is very important to us; we only use your data for the purposes intended. Since it is important to us that you are aware at all times of the extent to which we collect, use and, if necessary, transfer your data to third parties, we will provide you with the following comprehensive information on the processing of your personal data collected by us or stored by us.

Visiting our website is generally possible without providing (personal) data; if there are exceptions to this for selected services, we will explain these in the following chapters. When processing personal data, we strictly adhere to the requirements of the EU General Data Protection Regulation (GDPR) and any other data protection regulations.

Name and address of the controller

Technische Hochschule Georg Agricola (THGA), staatlich anerkannte Hochschule der DMT-Gesellschaft für Lehre und Bildung mbH (DMT-LB)
Prof. Susanne Lengyel, Prof. Dr. Sunhild Kleingärtner, Ulrich Wessel
Herner Straße 45
44787 Bochum
Germany

Phone: +49 (0)234 – 968-02
E-mail: info@thga.de
Website: https://moodle.thga.de/

Name and address of the data protection officer

Martina Brinkmann
Cortina Consult GmbH
Hafenweg 24
48155 Münster
Germany

E-mail: dsb.dmt@cortina-consult.de
Website: https://www.cortina-consult.de

Actuality of the privacy policy

To ensure that we always have up-to-date data protection information in connection with the services of our website, we use the CLOUD DSE service of Cortina Consult GmbH, Hafenweg 24 in 48155 Münster. In this process, the contents of our privacy policy are hosted on the servers at Cortina Consult and managed centrally. Necessary changes are implemented promptly by Cortina Consult and immediately displayed via direct integration on our website.

Rights of data subjects

The EU General Data Protection Regulation (GDPR) provides for extensive rights for data subjects in Chapter III, which we explain to you accordingly below with regard to the processing of your personal data:

Right to information

This requirement concerns in particular information on the following details of data processing:

  • Processing purposes
  • Data categories
  • Recipients or categories of recipients, if applicable
  • If applicable, the planned storage duration or the criteria for determining this duration.
  • Note on the respective right of correction, deletion, restriction or objection
  • Existence of the right to complain to a supervisory authority
  • If applicable, origin of the data (if not collected from you)
  • If applicable, existence of automated decision-making including profiling, including meaningful information about the logic involved, the scope and the effects to be expected
  • If applicable, (planned) transfer to a third country or international organization
Right to rectification

We will correct any erroneous data immediately, provided that you inform us of the circumstance accordingly.

Right to erasure (right to be forgotten)

Provided that the processing is no longer necessary and one of the following conditions is met:

  • Discontinuation of the purpose of processing
  • Withdrawal of their consent and absence of any other legal basis for processing
  • Objection to processing without an important reason to the contrary
  • Unlawful processing
  • Required to fulfill a legal obligation
  • Data collection was carried out in accordance with Art. 8 (1) GDPR
Right to restriction of processing

Provided that one of the following conditions is met:

  • You dispute the accuracy of your data (restriction can be made for the duration of the review on our side)
  • In the event of unlawful processing and if the data is not to be deleted, restriction of processing shall take the place of deletion
  • If the processing purposes cease to apply, at the same time you need your data for the assertion, exercise or defense of legal claims
  • After you have lodged an objection pursuant to Art. 21 (1) GDPR and for the duration of the examination as to whether our legitimate reasons outweigh yours.
Right to data portability

If it is technically possible and does not affect the rights and freedoms of other persons, we will - at your request - transfer your data to another recipient (responsible party).

Right to object

If we collect or have collected and process personal data from you (on the basis of Art. 6 (1) e or f or Art. 9 (2) a GDPR), you have the right to object to the data processing (including profiling) at any time (with effect for the future). In exceptional cases, the objection may be ineffective, e.g. if we can demonstrate compelling interests worthy of protection for the processing that outweigh your interests or processing serves the assertion, exercise or defense of legal claims. If we process your personal data for the purpose of direct marketing, you have the right to object to such processing at any time. This also applies to profiling, insofar as it is related to such direct advertising. You also have the right to object to processing of your data concerning you which is carried out by us for scientific or historical research purposes or for statistical purposes pursuant to Article 89 (1) GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.

Automated decisions in individual cases including profiling

If we collect or have collected and process personal data from you, you have the right not to be subject to any decision based solely on automated processing - including profiling - which produces legal effects concerning you or similarly significantly affects you. Exceptions to this requirement apply if the decision is necessary for the conclusion or performance of a contract between you and us or you have expressly consented to the processing. In any case, we will take reasonable steps to safeguard your rights and freedoms and legitimate interests, including at least the right to obtain the intervention of a person on our part, to express our own point of view and to contest the decision.

Right to complain to a supervisory authority

A list of the supervisory authorities responsible in Germany can be found on the website of the Federal Commissioner for Data Protection or at the following link: https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-node.html.

General information on data processing on the website

The following information applies to the data processing on our website in general. If there are exceptions or additions to this information, these are described in detail in the relevant sections.

Data security information

We secure our website and other systems through technical and organizational measures against loss, destruction, access, modification or distribution of your data by unauthorized persons. In addition, we have implemented SSL encryption (SHA256) on our website to protect your data. However, despite regular checks, complete protection against all dangers is not possible.

Our legitimate interest

Our legitimate interest, as defined in Article 6 (1) f GDPR, is based on the performance of our business activities in order to maintain our ability to operate and secure the employment of our employees.

General deadlines for data deletion

After the purpose of storage has ceased, the retention periods are generally at least six or ten years. As a rule, data is deleted immediately in accordance with our deletion concept, provided that this does not conflict with any retention obligation, necessity for contract fulfillment or a legitimate interest.

Deletion or blocking of personal data

We store your personal data only for the period required to fulfill the specified purpose. After the purpose no longer applies and after expiration of any existing retention periods, your data will be deleted immediately. If deletion is not possible, the data will be blocked instead.

Collection of general data and information

As soon as you visit our website, our web server collects some general data and technical information - as shown in the table below:

Data collected

Purpose of the survey

browser types and versions usedcorrect display of the page content
Operating system used, visitor origin (referrer, e.g. Google), subpages clicked onOptimization of our website content as well as our advertising
Date and time of access to the website as well as IP address and internet service provider of the visitorEnsuring the permanent functionality of our IT systems (for the operation of the website) and prevention of misuse

Other data and information for security in the event of attacks

Providing relevant information to law enforcement agencies in the event of a cyberattack

Obligation to provide personal data

Under certain circumstances (e.g. due to legal or contractual regulations), an obligation arises for you to provide us with your personal data. Examples of such processing as follows:

Nature or purpose of the processing

Need

Conclusion of a sales contract (e.g. your address)Fulfillment of the contractual obligation (e.g. delivery of the goods to your address)
In the employee context (e.g. transmission of data to the tax office)Compliance with legal requirements (e.g. tax regulations)

Information about specific data processing on the website

If applicable, in deviation from or in addition to the above-mentioned general information, you will find details of the individual data processing on our website below.

Cookies

On this website we use cookies; these are small text files that are placed or stored on your computer via your internet browser (e.g. Google Chrome, Safari, Firefox, Edge). These cookies are used for various purposes: many cookies are technically necessary to provide you with certain website functions (e.g. shopping cart functions, saving your login information), other cookies are used to ensure the security of your data or the website and some cookies can be used to analyze your user behavior. The latter cookies may contain a so-called cookie ID - a unique identifier consisting of a string of characters that allows Internet pages and servers to be assigned to the storing browser.
Cookies that are necessary to carry out the transmission of a message via a public telecommunications network and cookies that are absolutely necessary to provide you with an expressly requested function are referred to as "technically necessary cookies" and may be set without your explicit consent (Section 25 (2) TTDSG). All other cookies are subject to consent (§ 25 para. 1 TTDSG); if applicable, regulated by our Consent Management Platform.
We use cookies partly only for the duration of your stay on the website, partly for a predefined period and partly permanently. You can delete all these cookies manually or automatically at any time via your web browser.
It is possible to use our offers (although possibly not to the full extent of their functions) without cookies. Most browsers are set to accept cookies automatically. However, you can deactivate the storage of cookies or set your browser to notify you as soon as cookies are sent.

User profile - employees
Purpose of the processing of general data
Data typePurpose of the survey
First name, last name, e-mail address, LoginIDCreating a Moodle account, providing access, verification, assigning roles to uniquely identifiable natural persons, communicating by email via learning platform.
Legal basis (according to Art. 6 / 9 DSGVO)
  • Fulfillment of a contract (Art. 6 para. 1 b)
  • Recipient (if applicable)none
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessityThe data is mandatory under the underlying contract.
    Consequences of non-compliance (in case of failure to provide the required data)Without the data, the user profile cannot be created and it is therefore not possible to use Moodle.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data is automatically provided via the directory service of all user accounts for the THGA network.
    Change of purpose, if applicablenone
    Deletion of the user profileAfter termination of the employment relationship, the user profile will be deleted together with all data. For security and maintenance reasons, the deletion period can be up to six months.
    User profile - Teachers
    Purpose of the processing of general data
    Data typePurpose of the survey
    First name, last name, e-mail address, LoginIDCreating a Moodle account, providing access, verification, assigning roles to uniquely identifiable natural persons, communicating by email via learning platform.
    Legal basis (according to Art. 6 / 9 DSGVO)
  • Informed consent (Art. 6 para. 1 a)
  • Recipient (if applicable)none
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessityThere is no obligation to provide the data. According to the principle of "freedom of research and teaching" (cf. Art. (3) GG), the teacher is free to use the learning platform in the context of your teaching.
    Consequences of non-compliance (in case of failure to provide the required data)Without the data, the user profile cannot be created and it is therefore not possible to use Moodle.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data is automatically provided via the directory service of all user accounts for the THGA network.
    Change of purpose, if applicablenone
    Deletion of the user profileAfter termination of the employment relationship or if consent is revoked, the user profile will be deleted together with all data. For security and maintenance reasons, the deletion period can be up to six months.
    User profile - Students
    Purpose of the processing of general data
    Data typePurpose of the survey
    First name, last name, e-mail address, LoginIDCreating a Moodle account, providing access, verification, assigning roles to uniquely identifiable natural persons, communicating by email via learning platform.
    Martikell numberUnique identification of students, filling attendance or registration lists as appropriate.
    Science area, study programCreation and management of user groups, organizational purpose
    Library numberCompleteness, easy to find
    current course enrollmentAssignment of roles and permissions
    Legal basis (according to Art. 6 / 9 DSGVO)
  • Protection of public interests (Art. 6 para. 1 e)
  • Recipient (if applicable)none
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessityThe provision of personal data is mandatory for the use of the learning platform.
    Consequences of non-compliance (in case of failure to provide the required data)Without the data, the user profile cannot be created and it is therefore not possible to use Moodle.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data is provided automatically via the HISinOne administration software (also: https://meine.thga.de/, "My THGA").
    Change of purpose, if applicablenone
    Deletion of the user profileAfter de-registration, the user profile is deleted along with all data. The deletion period can be up to six months for security and maintenance reasons.
    User profile - non-university members
    Purpose of the processing of general data
    Data typePurpose of the survey
    First name, last name, e-mail address, LoginIDCreating a Moodle account, providing access, verification, assigning roles to uniquely identifiable natural persons, communicating by email via learning platform.
    Legal basis (according to Art. 6 / 9 DSGVO)
  • Informed consent (Art. 6 para. 1 a)
  • Recipient (if applicable)none
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessityThere is no obligation.
    Consequences of non-compliance (in case of failure to provide the required data)Without the data, the user profile cannot be created and it is therefore not possible to use Moodle.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data comes from the data subject himself.
    Change of purpose, if applicablenone
    Deletion of the user profileThe user accounts will be deleted upon request (informally to moodle@thga.de or by using the "Delete my account" function). The deletion period may be up to six months for security and maintenance reasons.
    Usage data - all users
    Purpose of the processing of general data
    Data typePurpose of the survey
    Time of the first access to the learning platform, time of the last access to the learning platform, time of the last access to a courseClean up, delete or block inactive or orphaned user accounts for security, privacy and other reasons. Data protection and other reasons, deregistration and identification of students no longer actively participating in courses.
    Legal basis (according to Art. 6 / 9 DSGVO)
  • Safeguarding legitimate interests (Art. 6 para. 1 f)
  • Recipient (if applicable)Date of last course access: Visible for users with role "Lecturer" or "Staff member
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessityThe data collected automatically during use.
    Consequences of non-compliance (in case of failure to provide the required data)The data collected automatically during use.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data collected automatically during use.
    Change of purpose if necessarynone
    Other voluntary profile data
    Purpose of the processing of general data
    Data typePurpose of the survey
    User picture, city, country, description of own person, interests, other information (e.g..: Website, phone number(s), office hours, address, instant messenger, social network profiles).Indication of further information (e.g. contact data, office hours of teachers, social media profiles), advertisements in user profiles
    Legal basis (according to Art. 6 / 9 DSGVO)
  • Informed consent (Art. 6 para. 1 a)
  • Recipient (if applicable)The data is visible to authenticated users if they have access to the affected user profile
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessitynone
    Consequences of non-compliance (in case of failure to provide the required data)none
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data comes from the data subject himself.
    Change of purpose if necessarynone
    Individual contents of the Moodle courses

    If applicable, further data processing takes place through the embedding of various services within the courses. Since the learning platform has various input options, including source code and HTML code, the responsibility for this lies with the respective course provider and we cannot list or inform about this integration in its entirety.

    Price history data
    Purpose of the processing of general data
    Data typePurpose of the survey
    Course history, votes, uploaded files or text submissions, chat and forum posts, answers to questions, glossary and wiki posts, comments and ratings.Assignment of messages, forum posts etc. to user accounts, assignment of course activities to user accounts
    Legal basis (according to Art. 6 / 9 GDPR)
  • For employees: Fulfillment of a contract (Art. 6 para. 1 b)
  • For students: Protection of public interests (Art. 6 para. 1 e)
  • For teachers and non-university staff: Informed consent (Art. 6 para. 1 a)
  • Recipient (if applicable)The data is visible to administrators and persons assigned to the respective courses with the role "instructor" or "staff member" and is also deleted when the user deregisters from a course, but at the latest when the course is deleted or reset. Data in connection with online activities aimed at collaborative learning are partly also visible to other users (mostly participants in the same courses).In some cases, data can survive the deletion of the person concerned from a course or even the deletion of a user account if it is necessary to maintain a function of a course component (e.g., forum posts are sometimes retained even after deletion from the course or after deletion of a user account if replies to this post exist which would be taken out of context without the post).
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessitynone
    Consequences of non-compliance (in case of failure to provide the required data)Without the data, the described data processing cannot take place.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data is created and stored by the Moodle software underlying the learning platform based on user activity.
    Authentication and authorization infrastructure for Sciebo
    Purpose of the processing of general data
    Data typePurpose of the survey
    First Name, Last Name, Display Name, Affiliation, Personal ID, Email AddressLogin to Sciebo via THGA user account, authentication, authorization
    Legal basis (according to Art. 6 / 9 DSGVO)
  • Informed consent (Art. 6 para. 1 a)
  • Recipient (if applicable)Hochschulcloud.NRW; Westfälische Wilhelms-Universität Münster, Schlossplatz 2, 48148 Münster
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessitynone
    Consequences of non-compliance (in case of failure to provide the required data)Without the data the registration can not take place.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data usually originates from the data subject, but may also originate from third parties.
    Change of purpose, if applicablenone
    Google reCaptcha
    Purpose of processingAnalysis, bot protection
    Legal basis (according to Art. 6 / 9 DSGVO)
  • Informed consent (Art. 6 para. 1 a)
  • Recipient (if applicable)Google LCC, Alphabet Inc, Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)America, Google
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessitynone
    Consequences of non-compliance (in case of failure to provide the required data)none
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data usually originates from the data subject, but may also originate from third parties.
    Where applicable, categories of personal data (if not collected directly from the data subject).Screen resolution, date and time of visit, IP address, browser language, mouse movements, visitor behavior, responses and forms.
    Change of purpose, if applicablenone
    Privacy info of the addinhttps://policies.google.com/privacy?hl=en
    Data protection officer of the addinhttps://support.google.com/policies/troubleshooter/7575787?hl=en
    Adobe Connect
    Purpose of the processing of general data
    Data typePurpose of the survey
    First name, last name, e-mail addressParticipation in web conference, creation of a temporary user account on the servers of DFN
    Legal basis (according to Art. 6 / 9 DSGVO)
  • Protection of public interests (Art. 6 para. 1 e)
  • Recipient (if applicable)Association for the Promotion of a German Research Network; Alexanderplatz 1, 10178 Berlin, e-mail: info@dfn.de, phone: 49 30 884299 0
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessitynone
    Consequences of non-compliance (in case of failure to provide the required data)Without the data, participation in the conference is not possible.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data is automatically shared via the user account.
    Change of purpose, if applicablenone
    Zoom
    Purpose of processingProvide service, provide support, display user avatar, send marketing messages, provide announcements, conduct promotional activities, provide event information, create account, respond to inquiries, service optimization, monitor data center performance, provide account dashboards, maintain security, manage disaster recovery plans and policies, fraud and abuse detection, meet legal obligations
    Legal basis (according to Art. 6 / 9 GDPR)
  • Fulfillment of a contract (Art. 6 para. 1 b)
  • Recipient (if applicable)Zoom Video Communications Inc; 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, United States
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)United States of America
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessityThe provision of data is mandatory based on the underlying contract.
    Consequences of non-compliance (in case of failure to provide the required data)The provision of data is mandatory based on the underlying contract.
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data usually originates from the data subject, but may also originate from third parties.
    Where applicable, categories of personal data (if not collected directly from the data subject).Date of birth, name, phone number, email address, language preference, user ID, password, profile picture, session schedule, configuration data, session metadata, feature usage data, performance data, service logs, billing information, location, IP address, browser type, ISP, referrer URL, operating system, date/time stamp
    Change of purpose if necessarynone
    Panopto
    Purpose of the processing of general data
    Data typePurpose of the survey
    User settingsSaving user settings for language, subtitles and playback position of videos that users interact with
    Legal basis (according to Art. 6 / 9 GDPR)
  • Performance of a contract (Art. 6 para. 1 b)
  • Recipient (if applicable)none
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)Data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessitynone
    Consequences of non-compliance (in case of failure to provide the required data)none
    If applicable, existence of an automated decision-making processIn this context, we do not use automated decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data usually originates from the data subject, but may also come from third parties.
    Matomo (self-hosted)
    Purpose of processingThis is an open source web analytics service used to analyze user behavior and optimize the website.
    Recipient (if applicable)

    none

    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessitynone
    Consequences of non-compliance (in case of failure to provide the required data)none
    If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data usually originates from the data subject, but may also originate from third parties.
    Where applicable, categories of personal data (if not collected directly from the data subject).

    Browser language, Browser type, Device operating system, Device type, Geographic location, IP address, Number of visits, Referrer URL, Screen resolution, Usage data, Subpages visited.

    Change of purpose if necessarynone