Data Protection
Here you will find information on data protection, such as the data protection declaration and the data protection declaration for order processing.
Data protection declaration for order processing
You can download the data protection declaration for order processing here.
Data protection declaration for order processingResponsible for data processing
The responsible party within the meaning of the EU General Data Protection Regulation and other national data protection laws of the member states as well as other data protection regulations is the
Gesellschaft für wissenschaftliche Datenverarbeitung mbH Göttingen Burckhardtweg 4 37077 Göttingen Germany
Tel.: +49 551 39-30001 E-Mail: support@gwdg.de Website: https://www.gwdg.de
represented by the managing director
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of the processing of personal data.
HPC.NDS Operators
Furthermore, the operators of HPC.NDS are active in data processing to the extent necessary for the provision of their respective services. The operators are:
- Gesellschaft für wissenschaftliche Datenverarbeitung mbH Göttingen
- Technische Universität Braunschweig
- Gottfried Wilhelm Leibniz Universität Hannover
Please contact the data protection officer of the relevant institution accordingly.
Contact person / Data protection officer
You can contact the data protection officer for the GWDG and this website as follows:
Gesellschaft für wissenschaftliche Datenverarbeitung mbH Göttingen Datenschutzbeauftragter Burckhardtweg 4 37077 Göttingen Germany
Tel.: +49 551 39-30001 E-Mail: datenschutz@gwdg.de
General information on data processing
Scope of processing of personal data
We generally process personal data of our users only to the extent necessary for providing a functional website as well as our content and services.
The processing of personal data of our users generally takes place only after the user’s consent (Art. 6 Para. 1 lit. a GDPR).
When processing personal data required for the fulfillment of a contract of which the data subject is a party, Art. 6 Para. 1 lit. b GDPR serves as the legal basis. This also applies to processing operations required for the execution of pre-contractual measures.
Insofar as the processing of personal data is required for the fulfillment of a legal obligation to which our company is subject, Art. 6 Para. 1 lit. c GDPR serves as the legal basis.
Provision of the website and creation of log files
Description and scope of data processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing computer. The following data are collected:
- Date of access
- Client IP address
- End of server processing time
- HTTP request (e.g. GET including GET variables)
- Status code sent to the client
- Size of data sent to the client, without HTTP header
- Requested URL path
- Browser information sent by the client
- Referer sent by the client
Legal basis for data processing
The legal basis for the temporary storage of data and log files is Art. 6 Para. 1 lit. f GDPR.
Purpose of data processing
The temporary storage of the IP address by the system is necessary to enable the delivery of the website to the user’s computer and its correct display. For this purpose, the user’s IP address must remain stored for the duration of the session.
In addition, the data serve to optimize the website and ensure the security of the information technology systems. An analysis of the data for other purposes does not take place in this context.
Since HPC.NDS is a third-party funded research project, we must provide information on usage for the funding organization as part of the usage verification and will therefore generate anonymized statistical data (and, for example, graphics) on the accesses and use them in external representation (also for marketing purposes). We will also exchange the information within the consortium.
There is a legitimate interest in data processing according to Art. 6 Para. 1 lit. f GDPR.
Duration of storage
The data are deleted as soon as they are no longer required for achieving the purpose of their collection. In the case of data collection for providing the website, this is the case when the respective session is ended.
In the case of storage of data in log files, this is the case after at most seven days. Further storage is possible. In this case, the IP addresses of the users are deleted or anonymized so that assignment to the accessing client is no longer possible.
Right to object and removal
The collection of data for providing the website and the storage of data in log files is absolutely necessary for the operation of the website. The possibility of objection is taken into account insofar as this is technically and organizationally feasible by the responsible party and no contractual or legal obligation for collection, storage and processing exists.
Support form and e-mail contact
Description and scope of data processing
A form is available on the website which can be used for electronic support requests. If a user makes use of this possibility to make contact, the data entered in the input mask are transmitted and stored in a purposeful manner.
These data are:
- First and last name
- E-mail address
- Contact request or other voluntarily transmitted data
Alternatively, contact can be made via the provided e-mail address. In this case, the personal data of the user provided and transmitted with the e-mail itself are stored and transmitted in encrypted form.
The data can be transmitted to the members of the consortium for processing your request.
Since HPC.NDS is a third-party funded research project, we must provide information on usage for the funding organization as part of the usage verification and will therefore generate anonymized statistical data (and, for example, graphics) on the requests and use them in external representation (also for marketing purposes).
Legal basis for data processing
The legal basis for processing the data is Art. 6 Para. 1 lit. a GDPR if the user’s consent is present.
The legal basis for processing the data transmitted in the course of sending an e-mail is Art. 6 Para. 1 lit. f GDPR. If the e-mail contact aims at concluding a contract, Art. 6 Para. 1 lit. b GDPR is the additional legal basis for the processing.
Purpose of data processing
The processing of personal data from the input mask serves to process the contact.
The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems.
Duration of storage
The transmitted data are deleted 1 year after they are no longer required for achieving the purpose of their collection.
For the personal data from the input mask of the contact form and those sent by e-mail, the purpose is fulfilled when the respective conversation with the user is ended. The conversation is ended when the circumstances indicate that the relevant matter has been finally clarified.
The personal data additionally collected during the sending process are deleted after a period of seven days at the latest.
Further storage is possible. In this case, the personal data of the users are deleted or anonymized so that an assignment of the request and communication to the person is no longer possible.
Right to object and removal
The user has the possibility at any time to revoke his consent to the processing of personal data. If the user makes contact by e-mail, he can object to the storage of his personal data at any time. In such a case, an active conversation cannot then be continued. All personal data stored in the course of the contact are deleted in this case.
Rights of the data subject
You have various rights regarding the processing of your personal data. These are listed below.
Right to information (GDPR Art. 15)
You can request confirmation from the responsible party whether personal data concerning you are being processed. This includes the right to request information on whether the personal data concerning you are transmitted to a third country or to an international organization.
Right to rectification (GDPR Art. 16)
You have the right to rectification and/or completion vis-à-vis the responsible party, insofar as the processed personal data concerning you are incorrect or incomplete. The responsible party must carry out the rectification without delay. Right to deletion / “right to be forgotten” / right to restriction of processing (GDPR Art. 17, 18).
You have the right to request the immediate deletion of your personal data from the responsible party. Alternatively, you can request the restriction of processing from the responsible party.
Restrictions are mentioned in the GDPR under the mentioned articles or paragraphs.
Right to information (GDPR Art. 19)
If you have asserted the right to rectification, deletion or restriction of processing against the responsible party, this party is obliged to inform all recipients to whom the personal data concerning you have been disclosed of this rectification or deletion of data or restriction of processing, unless this proves impossible or involves disproportionate effort.
You have the right vis-à-vis the responsible party to be informed about these recipients.
Right to data portability (GDPR Art. 20)
You have the right to receive the personal data concerning you which you have provided to the responsible party in a structured, common and machine-readable format.
In addition to the GDPR, it should be noted that data portability for mass data / user data is limited to technical readability only. The right to data portability does not include that data created by the user in a proprietary format is converted by the responsible party into a “common”, i.e. standardized format.
Right to object (GDPR Art. 21)
You have the right to object to the processing if this is done exclusively on the basis of a balancing by the responsible party (cf. GDPR Art. 6 Para. 1 lit f). Right to revocation of the data protection consent declaration (GDPR Art. 7 Para. 3)
Right to revocation of the data protection consent declaration (GDPR Art. 7 Para. 3)
You have the right to revoke your data protection consent declaration at any time. The revocation of the consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 EU-GDPR), in particular in the member state of your place of residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
The competent supervisory authority is:
Die Landesbeauftragte für den Datenschutz Niedersachsen Prinzenstraße 5 30159 Hannover Telefon: 0511 120 45 00 Telefax: 0511 120 45 99 E-Mail: poststelle@lfd.niedersachsen.de