Support

Lorem ipsum dolor sit amet:

24h / 365days

We offer support for our customers

Mon - Fri 8:00am - 5:00pm (GMT +1)

Get in touch

Cybersteel Inc.
376-293 City Road, Suite 600
San Francisco, CA 94102

Have any questions?
+44 1234 567 890

Drop us a line
info@yourdomain.com

About us

Lorem ipsum dolor sit amet, consectetuer adipiscing elit.

Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Donec quam felis, ultricies nec.

Datenschutzerklärung

Privacy Statement

We appreciate your interest in our institution. Data privacy has a high priority for the management of the Brandenburg Medical School Theodor Fontane. You can basically use the website of the Brandenburg Medical School without leaving personal data. Processing of personal data may, however, become necessary if a data subject wishes to utilize specific services via our website. Where such processing becomes necessary and in the absence of a legal basis, we generally seek consent from the data subject.

Processing a data subject’s personal data such as name, address, email address or phone number always complies with the General Data Protection Regulation and the country-specific regulations applying to the Brandenburg Medical School Theodor Fontane. This Privacy Statement serves to inform the public of type, scope and purpose of data gathered, used and processed by our institution. It also informs data subjects about their rights.

The Brandenburg Medical School Theodor Fontane as the responsible party has implemented numerous technical and organizational measures to ensure complete protection of personal data processed via these internet sites. Nevertheless, internet-based data transfer in general may involve security gaps, so that absolute protection cannot be guaranteed. Every data subject is therefore free to transfer personal data to us via alternatives, for example by phone.  

1. Definitions

The Privacy Statement of the Brandenburg Medical School Theodor Fontane is based on the terminology used by the European Regulatory Authorities in issuing the General Data Protection Regulation (German abbreviation: DS-GVO). Our Privacy Statement is meant to be easy to read and understand for the general public as well as our clients and business partners. It is therefore necessary to define a number of terms used below.

The Privacy Statement uses, amongst others, the following terms:

  • a) Personal data

Personal data means any information referring to an identified or identifiable natural person (in the following: “data subject”). An individual is considered as identifiable if this person can be directly or indirectly associated with an identifier such as a name, identification code, location data, online ID, or one or several specific characteristics which express this person’s physical, physiological, genetic, mental, economic, cultural or social identity.

  • b) Data subject

A data subject is any identified or identifiable natural person whose personal data is processed by those responsible for data processing.

  • c) Processing

Processing describes every procedure performed with or without automated methods in connection with personal data, i.e. procedures to collect, enter, organize, sort, store, adapt or modify, read, query, use, disclose via transmission, dissemination or otherwise making available, match or link, restrict, delete or destroy data.    

  • d) Referencing

Referencing means the marking of stored personal data with the aim of limiting their processing in future.

  • e) Profiling

Profiling means any kind of automated processing of personal data for the use of such data to assess certain personal characteristics referring to a natural person; specifically, to analyze or predict aspects such as work performance, economic situation, state of health, personal preferences, interests, reliability, behavior, abode or change of location.

  • f) Pseudonymization

Pseudonymization describes the processing of personal data in a way that personal data can no longer be assigned to a specific data subject without consulting additional information, provided that this additional information is stored separately and subject to organizational measures which ensure that the personal data cannot be associated with an identified or identifiable natural person.

  • g) Data controller

The data controller, i.e. the party responsible for data handling or processing, is the natural person or legal entity, authority, institution or other body with the right to decide either alone or together with others on the purposes and means of processing personal data. Where purposes and means of this processing are given by Union law or national law, the data controller or the specific appointment criteria may be determined by Union or national law.

  • h) Processors

Processors are natural persons or legal entities, authorities, institutions or other bodies who process personal data on behalf of the data controller.

  • i) Recipient

Data recipients are natural persons or legal entities, authorities, institutions or other bodies to whom or which personal data are revealed, whether or not they are third parties. Authorities receiving personal data in the context of a specific request under Union or national law are not considered recipients.

  • j) Third parties

Third parties are natural persons or legal entities, authorities, institutions or other bodies other than the data subject, the data controller, the processor and the persons authorized to process personal data under the direct authority of the data controller or the processor.

  • k) Consent

Consent is any informed, free and unequivocal expression of will from the data subject in the given case, in the form of an explanation or other explicit confirmation, to say that the data subject agrees to the processing of his or her personal data.  

 2. Name and address of the institution responsible for data handling

Responsible institution within the meaning of the DS-GVO, other data protection regulations valid in the EU member states and other pertinent regulations:

Medizinische Hochschule Brandenburg Theodor Fontane (Brandenburg Medical School)
Fehrbelliner Straße 38
16816 Neuruppin
Germany

Phone: 03391 39-14110
E-Mail:
info@mhb-fontane.de
Website:
www.mhb-fontane.de

3. Name and address of the data protection officer

Data protection officer of the above institution:

Claus Wüstenhagen
Brünhildestraße 25
14542 Werder (Havel)
Germany

E-Mail: dsb@mhb-fontane.de.

Every data subject may contact our data protection officer for all questions and suggestions concerning data protection at any time.

4. Cookies

The Brandenburg Medical School Theodor Fontane uses cookies on its websites. Cookies are text files stored on a computer system via an internet browser.

Numerous internet sites and servers use cookies. Many cookies contain a so called cookie ID, an unequivocal identification of the cookie. It consists of a string of characters which permits a matching of internet sites and servers with the specific internet browser where the cookie is stored. In this way, the visited internet sites and servers can distinguish a person’s individual browser from other internet browsers with other cookies. The unequivocal cookie ID serves to recognize and identify a specific internet browser.

Cookies allow the Brandenburg Medical School Theodor Fontane to make the user experience as convenient as possible and optimize information and services for website visitors. As mentioned above, cookies serve to recognize website visitors and thus to facilitate their use of our websites. Users of a website with cookies need not enter their access data every time they visit that site, because this task is taken over by the website and the cookie stored on users’ computer systems. Another example is the cookie of a shopping cart in the online shop. The online shop uses a cookie to memorize the items a customer has placed in the virtual shopping cart.   

The data subject can avoid the installation of cookies via our websites at any time by the appropriate setting of a browser and thus permanently refuse to accept cookies. Cookies that have already been set can be deleted any time via all common internet browsers or other software programs. If data subjects deactivate the setting of cookies, they may not be able to fully use all functions otherwise offered by our websites.

5. Collection of general data and information

Whenever a data subject or automated system visits the website of the Brandenburg Medical School Theodor Fontane, the website collects a number of general data and information which are stored in the server logfiles. Details collected can be (1) the browser types and versions, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so called referrer), (4) the sub-sites accessed via an accessing system on our website, (5) date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information which serve to protect our information technology systems from attacks. The Brandenburg Medical School Theodor Fontane does not draw conclusions about the data subject from such general data and information. These are required to (1) correctly provide the website contents, (2) optimize the content and promotion of our website, (3) ensure the permanent functional capacity of our IT systems and the technology of our website, and (4) make necessary information for prosecution available to law enforcement authorities in case of cyber-attacks. The Brandenburg Medical School Theodor Fontane evaluates such anonymously collected data and information statistically and with the objective of increased data protection and data security in our institution and ultimately an optimum level of protection for the personal data we process. Anonymous data from server logfiles are stored separately from all personal data provided by data subjects.

6. Registration on our website

Data subjects may enter personal data to register on the website of the data controller. The input mask used for registration indicates the personal data to be transmitted to the data controller. Personal data entered by the data subject will be used and stored exclusively for internal purposes. The data controller may cause further transmission to one or several processors such as parcel services, who will also use the personal data exclusively for internal purposes on behalf of the data controller.

Registration on the website of the data controller means that the IP address assigned to the data subject by the internet service provider (ISP) and the time of registration are stored. Storage of this data is the only way to avoid misuse of our services, facilitates the investigation of offences when required, and is therefore necessary to protect the data controller. Personal data will in principle not be passed on to third parties unless required by law or for law enforcement purposes.

Registration of data subjects with voluntary input of personal data enables the data controller to offer contents or services that can be made available to registered users exclusively. Registered persons are free at any time to amend the personal data entered upon registration or demand complete deletion from the database of the data controller.

The data controller informs the data subject about personal data stored for that person at any time and upon request. The data controller will also amend or delete personal data upon request or notice from the data subject if there are no legal retention obligations. All employees of the data controller are available to the data subject as contacts in this context.

7. Subscription to our newsletter

The website of the Brandenburg Medical School Theodor Fontane invites users to subscribe to the newsletter of our institution. The input mask indicates the data transmitted to the data controller.  

The Brandenburg Medical School Theodor Fontane periodically sends a newsletter to inform customers and business partners of services offered. In principle, data subjects can receive our newsletter only if (1) the data subject has a valid email address and (2) has registered for newsletter distribution. For legal reasons we rely on the double opt-in procedure to send a confirmation email to the first email address provided by the data subject for newsletter dispatch. This confirmation email serves to check whether the owner of the email address has authorized receipt of the newsletter as the data subject.

Upon registration for the newsletter, we also store the IP address assigned by the ISP to the data subject’s computer system at the time of registration, as well as date and time of registration. Collection of this information is required to trace a (possible) misuse of a data subject’s email address at a later time and therefore serves as legal protection to the data controller.

Personal data collected for registration for the newsletter is exclusively used for newsletter dispatch. Subscribers may also be informed via email if this is required for the newsletter service or a possible registration in case of changes in newsletter services or changes in technical conditions. Personal data collected in the context of newsletter services will not be passed on to third parties. Data subjects may cancel their subscription of our newsletter and revoke their consent to the storing of personal data provided for newsletter dispatch at any time. Every newsletter contains a link to withdrawal of consent. Newsletter subscription may alternatively be cancelled directly on the website of the data controller or be notified to the data controller in other forms. If you register for virtual information events and further on-site events, we reserve the right to send you pertinent information concerning our programs and the MHB. You may sign out at any time.

8. Newsletter Tracking

The newsletters of the Brandenburg Medical School Theodor Fontane contain so called tracking pixels. A tracking pixel is a miniature graphic embedded in emails which are sent in HTML format to permit logfile recording and logfile analysis. In this way, online marketing campaigns can be statistically evaluated for success or failure, for example. The embedded tracking pixel enables the Brandenburg Medical School Theodor Fontane to see whether and when a data subject opened an email and which links contained in that email were followed.

The data controller records and evaluates the personal data collected via the tracking pixels in the newsletters in order to optimize the newsletter dispatch and adapt the content of future newsletters to the data subject’s interests. Personal data of this kind is not passed on to third parties. Data subjects may withdraw their respective separate consent given in the context of the double-opt-in procedure at any time. The data controller will delete this personal data upon withdrawal. The Brandenburg Medical School Theodor Fontane will automatically consider cancellation of the newsletter as withdrawal of consent.

9. Contact via the website

In accordance with statutory provisions, the website of the Brandenburg Medical School Theodor Fontane contains elements which permit easy electronic contact and immediate communication with our institution, including a general email address. When a data subject contacts the data controller via email or via contact form, the personal data transferred by the data subject will be automatically recorded. Such personal data transmitted voluntarily by a data subject to the data controller are recorded for the purposes of processing, or for contacting the data subject, and will not be passed on to third parties.

10. Routine collection and deletion of personal data

The data controller processes and saves personal data of a data subject exclusively for the period required to achieve the storage purpose, or as far as stipulated by European directives and regulations or other laws and regulations applying to the data controller.

When the storage purpose does no longer apply or a retention period stipulated by European or other directives or regulations expires, the personal data will be routinely blocked or deleted pursuant to legal requirements.

11. Rights of data subjects

  • a) Right to obtain confirmation

All data subjects have the right to request confirmation from the data controller whether their personal data is being processed, in accordance with European directives and guidelines. To claim this right, a data subject may contact an employee of the data controller at any time.

  • b) Right to be informed

According to European directives and guidelines, every data subject affected by the processing of personal data has the right to request from the data controller free-of-charge information on the personal data recorded for that person and a copy of such information. Moreover, European directives and guidelines grant all data subjects the right to be informed about:

    • the processing purposes
    • the categories of personal data that are processed
    • the recipients or categories of recipients to whom the personal data has been or will be revealed, specifically in case of recipients in third countries or international organizations
    • where possible, the planned storage duration or, if this is not possible, the criteria for determining such duration
    • a right to amendment or deletion of their personal data, or to restriction of processing by the data controller, or to revocation of such processing
    • the right to appeal to a competent authority
    • if personal data are not collected from the data subject: all available information on their origin
    • automated decision making including profiling pursuant to Article 22(1;4) DS-GVO and — at least in these cases — meaningful information on the rationale, scope and intended implications of such processing for the data subject

Moreover, the data subject is entitled to request information whether personal data was passed on to a third country or international organization. In this case the data subject is entitled to information on suitable guarantees in connection with the data transfer.

A data subject wishing to claim this right may contact an employee of the data controller at any time.

  • c) Right of correction

European guidelines and directives give all data subjects affected by the processing of personal data the right to demand immediate correction of incorrect personal data concerning them. Data subjects are also entitled to demand the completion of incomplete personal data – also via supplemental explanation, in consideration of the purposes of the processing concerned.

A data subject wishing to claim this right may contact an employee of the data controller at any time.

  • d) Right to demand cancellation (“right to be forgotten”)

Pursuant to European guidelines and directives, all data subjects affected by the processing of personal data are entitled to demand from the data controller that personal data concerning them be deleted without delay if one of the following reasons applies and as far as processing is not required:

    • Personal data were collected or otherwise processed for purposes for which they are no longer required.
    • The data subject revokes consent as the basis for processing according to Art. 6(1a) or Art. 9(2a) DS-GVO, and there is no other legal basis for processing.
    • The data subject files an objection against processing pursuant to Art. 21(1) DS-GVO and there are no other reasons to justify processing, or the data subject files an objection against processing pursuant to Art. 21(2) DS-GVO.
    • Processing of personal data was unlawful.
    • Deletion of personal data is required to meet a legal obligation pursuant to European or national law applying to the data controller.
    • Personal data were collected in connection with information society services in accordance with Art. 8(1) DS-GVO.

If one of the above reasons applies and a data subject wishes personal data stored with the Brandenburg Medical School Theodor Fontane to be deleted, that person may contact an employee of the data controller at any time. The employee will ensure deletion without delay.

In case the Brandenburg Medical School Theodor Fontane has made personal data publicly available and our institution as the responsible party is obliged to arrange for deletion pursuant to Art. 17(1) DS-GVO, the Brandenburg Medical School Theodor Fontane will take appropriate measures including those of a technical nature to inform other parties responsible for the processing of such personal data of the data subject’s request: i.e. to delete all links to the personal data in question, or copies or replications of these, unless processing is required. The employee of the Brandenburg Medical School Theodor Fontane will take the necessary steps on a case-by-case basis.

  • e) Right to demand restriction on data processing

Pursuant to European guidelines and directives, all data subjects affected by the processing of personal data are entitled to request the data controller to restrict processing in either of the following circumstances:

    • The data subject contests the accuracy of personal data for a period of time which enables the data controller to check the accuracy of the personal data in question.
    • Processing of personal data is unlawful, and the data subject opposes erasure and instead demands the use of such data to be restricted.
    • Personal data is no longer required by the data controller for processing purposes, but by the data subject for the assertion, exercise or defense of legal claims.
    • The data subject has filed an objection against the processing, pursuant to Art. 21(1) DS-GVO, and it is not yet certain whether the justified reasons of the data controller outweigh those of the data subject.  

If one of the above circumstances applies, and a data subject wishes to demand restriction of personal data stored with the Brandenburg Medical School Theodor Fontane, this person may contact an employee of the data controller at any time. The employee of the Brandenburg Medical School Theodor Fontane will arrange the required restriction.

  • f) Right to data portability

Pursuant to European guidelines and directives, all data subjects affected by the processing of personal data are entitled to receiving a structured, conventional and machine readable version of the personal data they made available to the data controller. Data subjects also have the right to transfer such data to a different data controller without interference from the data controller to whom they had been made available, provided that processing is based on consent according to Art. 6(1a) DS-GVO or Art. 9(2a) DS-GVO or on an contract according to Art. 6(1b) DS-GVO and processing is performed via automated procedures, or that processing is not required for an assignment in the public interest or for the exercise of official authority transferred to the data controller.

In exercise of the right to data portability pursuant to Art. 20(1) DS-GVO, data subjects have the right to insist that one data controller transmits personal data directly to another data controller as far as this is technically feasible and does not affect the rights and freedoms of others.  

To exercise the right to data portability, a data subject may contact an employee of the Brandenburg Medical School at any time.

  • g) Right to object

Pursuant to European guidelines and directives, all data subjects affected by the processing of personal data have the right to object at any time – for reasons relating to their individual situation – to the processing of their personal data on the basis of Art. 6(1e or f) DS-GVO. The same applies to profiling on that basis.  

In case of objection, personal data will no longer be processed by the Brandenburg Medical School Theodor Fontane, unless we provide compelling legitimate grounds for processing that outweigh a data subject’s interests, rights and freedoms, or processing serves to assert, exercise or defend legal claims.

Where the Brandenburg Medical School Theodor Fontane processes personal data for purposes of direct marketing, the data subject is entitled to object to the processing of personal data for such purposes at any time. The same applies to profiling in connection with such direct marketing. If the data subject objects to the processing by the Brandenburg Medical School Theodor Fontane for direct marketing, the Brandenburg Medical School Theodor Fontane will refrain from processing personal data for that purpose.

For reasons resulting from their specific circumstances, data subjects are moreover entitled to raise objections against the processing of their personal data at the Brandenburg Medical School for purposes of academic or historical research or for statistical purposes pursuant to Art. 89(1) DS-GVO, unless such processing is required to carry out a task in the public interest.

To exercise the right to object, a data subject may directly contact any employee or other staff of the Brandenburg Medical School Theodor Fontane. Data subjects are moreover free to exercise their right to object via automated procedures with technical specifications, in connection with the use of information society services, notwithstanding Directive 2002/58/EG.

  • h) Automated decisions in the individual case, including profiling

Pursuant to European guidelines and directives, all data subjects affected by the processing of personal data are entitled not to be subject to a decision made exclusively based on automated processing, including profiling, which produces legal effects or significantly affects them, as far as the decision (1) is not required to conclude or execute a contract between the data subject and the data controller, or (2) is permitted by Union or member state laws applicable to the data controller and these laws contain suitable steps to ensure the data subject’s rights, freedoms and legitimate interests, or (3) is taken with the data subject’s explicit consent.

If the decision is required (1) to conclude or execute a contract between the data subject and the data controller, or (2) is taken with the data subject’s explicit consent, then the Brandenburg Medical School Theodor Fontane will take appropriate steps to safeguard the data subject’s rights, freedoms and legitimate interests, which include at least the right to procure the intervention of a person representing the data controller, to present their own position, and to contest the decision.

If data subjects wish to assert rights in connection with automated decisions, they may contact an employee of the data controller at any time.

  • i) Right to cancel consent to data processing

Pursuant to European guidelines and directives, all data subjects affected by the processing of personal data have the right to cancel their consent to the processing of personal data at any time.

If data subjects wish to exercise that right, they may contact an employee of the data controller at any time.

12. Data protection in applications and application procedures

The data controller gathers and processes applicants’ personal data for application procedure purposes. Processing may also be carried out electronically, which occurs specifically in cases where applicants send their application documents electronically to the data controller, e.g. via email or a web form to be found on the website. If the data controller concludes an employment contract with an applicant, the data transferred will be stored for the purposes of the employment relation, subject to statutory provisions. If the data controller does not conclude an employment contract with the applicant, application documents are automatically deleted two months after notification, unless other legitimate interests of the data controller prevent deletion. Other legitimate interests to this effect can, for example, be burden of proof in a lawsuit concerning the General Equal Treatment Act (GETA).

13. Data protection regulations covering the use of Facebook

The data controller has integrated components of the social network Facebook on this website.

A social network is a social meeting point on the internet, an online community where, as a rule, users can communicate and interact in virtual space. A social network can serve as a platform for exchanging opinions and experiences or can enable the internet community to provide personal or business-related information. Facebook allows users to create their own profiles, to upload photos and link up via friend requests.

The operating company of Facebook is Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. The data controller for personal data of data subjects living outside the US or Canada is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

With every access to a single page of this website, which is operated by the data controller and contains an integrated Facebook component (Facebook plug-in), the respective Facebook component automatically causes the internet browser of the data subject’s information technology system to download and illustrate the respective Facebook plug-in. An overview of all Facebook plug-ins may be downloaded from https://developers.facebook.com/docs/plugins/?locale=de_DE. This technical process notifies Facebook of the specific single page on our website accessed by the data subject.

If the data subject is simultaneously logged into Facebook, Facebook will register with each access to our website by the data subject and during the navigation of our website which specific single page on our website the data subject calls up. This information is collected via the Facebook component and assigned to the Facebook account of the data subject. If the data subject clicks one of the integrated Facebook buttons on our website, for example the “Like” button, or enters a comment, Facebook assigns this information to the data subject’s personal Facebook user account and stores such personal data.

Facebook is always notified that a data subject has accessed our website whenever the data subject is logged into Facebook while accessing our website; this occurs irrespective of whether the data subject clicks the Facebook component or not. If a data subject objects to such transfer of information to Facebook, transmission can be prevented by logging out from the Facebook account prior to accessing our website.  

The data guideline published by Facebook and available at https://de-de.facebook.com/about/privacy/ contains information about the collection, processing and use of personal data by Facebook. It also describes the settings offered by Facebook to protect a data subject’s privacy. Further, it contains various applications to oppress data transfer to Facebook which a data subject may use.

 14. Newsletter dispatch via CleverReach

We use CleverReach, a service of CleverReach GmbH & Co.KG, Schafjückenweg2,26180Rastede, Germany, for the dispatch of our newsletter. The basis is an order processing contract pursuant to Art.28DS-GVO. CleverReach processes your data entered in the context of newsletter registration (e.g. email address, name if applicable) exclusively on our behalf and according to our instructions.

Purpose and legal basis of data processing

Data processing serves to distribute our newsletter and measure performance (e.g. open and click rates). The legal basis is your consent pursuant to Art.
6(1/1lit.a)DS-GVO in connection with Art.7DS-GVO. We rely on the so called double opt-in procedure for proof of consent.


Recipient and transmission to third countries

CleverReach does not transmit personal data to third parties but stores and processes data exclusively on servers within the European Union.

Storage period

Your data will be retained for as long as your newsletter subscription is valid and will be deleted from the distribution list upon cancellation. Backups will be deleted on a regular basis unless longer retention is legally required.

Revocation of consent

You may revoke your consent to receiving the newsletter with future effect at any time, e.g. via the unsubscribe link at the bottom of each newsletter or a notification to the contact address given in the imprint. Revocation does not affect the legitimacy of processing prior to revocation.  

15. Use of HubSpot

For our marketing activities we use the services of HubSpot Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA, respectively of HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin (in the following: “HubSpot”). HubSpot is an integrated software solution that covers various aspects of our online marketing – among other things, email marketing (e.g. newsletter dispatch), social media publishing and reporting, contact management (e.g. user segmentation and CRM), landing pages and contact forms.

Processed data and purposes of the processing

The use of HubSpot involves the processing of the following personal data in particular:
•    contact data (e.g. name, email address, phone number, company),
  information on interactions with our emails or the website (e.g. pages called up, length of stay on the website, submit form actions),
   technical data (e.g. IP address, type of browser, operating system).
We process these data in order to analyze and optimize our marketing activities, to address interested parties, to distribute content and for CRM.


Legal basis of processing

The processing of personal data is based on your consent pursuant to Art.
6(1 lit.a) DS-GVO, if such consent has been requested (e.g. for newsletter subscription). In other cases, processing is based on our legitimate interest, pursuant to Art.6(1 lit.f) DS-GVO, in the analysis, optimization and cost-effective operation of our marketing efforts and website.

Data transfer to third countries

HubSpot processes data, to some extent on servers in the US. We concluded an agreement on order processing with HubSpot pursuant to Art.
28 DS-GVO. Data transmissions to the US are based on an adequacy decision adopted by the European Commission (EU-U.S. Data Privacy Framework, DPF) pursuant to Art.45 DS-GVO. HubSpot Inc. is certified to the DPF and thus guarantees a level of data privacy corresponding to that of the European Union. Where no certification according to DPF applies in individual cases or data is transmitted to other affiliates in third countries, transmission takes place on the basis of appropriate guarantees pursuant to Art.46 DS-GVO, specifically: the EU standard contractual clauses. For more information see: https://legal.hubspot.com/de/dpa.

Storage period

Personal data is retained for as long as is necessary for the purpose in question, or until you revoke your consent.

Possibilities of objection and revocation

You may object to your personal data being processed with future effect at any time. If processing is based on consent, you may withdraw your consent at any time. Please use the contact data given in our imprint.

16. Privacy terms on the use and application of Google AdSense

The data controller has integrated Google AdSense on this website. Google AdSense is an online service which provides advertising services on third-party websites. Google AdSense is based on an algorithm that selects the adverts shown on third-party sites to match the respective content on these sites. Google AdSense permits an interest-related targeting of internet users via creation of individual user profiles.

The operating company of the Google AdSense component is Alphabet Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of the Google AdSense component is to incorporate advertisements on our website. Google AdSense places a cookie on the data subject’s IT system. For definition of cookie see above. Placing the cookie enables Alphabet Inc. to analyze the use of our website. Every visit to a single page of the website operated by the data controller and containing a Google AdSense component will automatically cause the internet browser of the data subject’s IT system to transmit data to Alphabet Inc. for the purposes of online advertising and settlement of commissions. In the context of this technical procedure, Alphabet Inc. receives information on personal data such as the data subject’s IP address and may thus track the origin of visitors and clicks for subsequent calculation of commissions.

As explained above, the data subject may prevent the placing of cookies via our website at any time by means of the setting of the internet browser and thus permanently reject the placing of cookies. A pertinent setting of the browser would moreover prevent Alphabet Inc. from placing a cookie on the data subject’s IT system. In addition, a cookie already installed by Alphabet Inc. can be deleted at any time via the internet browser or other software programs.

Moreover, Google AdSense uses so called tracking pixels. A tracking pixel is a miniature graphic embedded in websites to permit logfile recording and logfile analysis for the purpose of statistical evaluation. The embedded tracking pixel enables Alphabet Inc. to see whether and when a data subject visited a website and which links were followed. Tracking pixels serve, for example, to assess visitor flows on a website.

Personal data and information are transmitted to Alphabet Inc. in the United States via Google AdSense, which includes the IP address and is necessary for the recording and invoicing of adverts. This personal data, collected via the described technical procedure, is stored and processed in the United States and is potentially passed on to third parties by Alphabet Inc.

For more detailed information on Google-AdSense see this link: https://www.google.de/intl/de/adsense/start/.

17. Privacy terms on the use and application of Google Analytics (with anonymization function)

The data controller has integrated the component Google Analytics (with anonymization function) on this website. Google Analytics is a web analysis service. Web analysis describes the collection and evaluation of data about visitors viewing websites. A web analysis service gathers, e.g., information about the website from which a data subject has reached another website (so called referrer), which single page of the website was accessed, or how often and for how long a single page was accessed. Web analyses are mainly used for website optimization and for cost-effectiveness analyses of online advertising.

The operating company of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The data controller uses the addition "gat._anonymizeIp" for the web analysis via Google Analytics. This addition serves to shorten and anonymize the data subject’s IP address when our website is accessed from a member state of the European Union or another signatory state to the EEA treaty.

The purpose of the Google Analytics component is to analyze visitor flows on our website. Google uses the data and information gathered in this way to evaluate the use of our website for online reports on the activities on our website, and for other services in connection with the use of our website.

Google Analytics places a cookie on the data subject’s IT system. For definition of cookie see above. Placing the cookie enables Google to analyze the use of our website. Every visit to a single page of the website operated by the data controller and containing a Google Analytics component will automatically cause the internet browser of the data subject’s IT system to transmit data to Google for the purpose of online analysis. In the context of this technical procedure, Google receives information on personal data such as the data subject’s IP address and may thus track the origin of visitors and clicks for subsequent calculation of commissions.

The cookie serves to store personal information such as a data subject’s access time, the site from which access occurred, and the frequency of visits to our website. For each access to our website, such personal information including the IP address of the data subject’s internet connection is passed on to Google in the United States and stored there and is potentially passed on to third parties.

As explained above, the data subject may prevent the placing of cookies via our website at any time by means of the setting of the internet browser and thus permanently reject the placing of cookies. A pertinent setting of the browser would moreover prevent Google from placing a cookie on the data subject’s IT system. In addition, a cookie already installed by Google Analytics can be deleted at any time via the internet browser or other software programs.

Moreover, the data subject has the option of rejecting and preventing the collection of data generated by Google Analytics in connection with the use of this website, and of objecting to and thus preventing the processing of such data by Google. To that end, the data subject needs to download and install a browser add-on via the link https://tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via JavaScript that no data and information on visits to websites must be transmitted to Google Analytics. Google will treat the installation of the browser add-on as objection. When the data subject’s IT system is deleted, formatted or newly installed at a later time, the data subject must reinstall the browser add-on in order to deactivate Google Analytics. If the data subject or another person attributable to the data subject’s sphere of influence deinstalls or deactivates the browser add-on, there is the option of reinstalment or reactivation of the browser add-on.

For further information and currently valid privacy policies of Google see https://www.google.de/intl/de/policies/privacy/ and http://www.google.com/analytics/terms/de.html. For more detailed information on Google Analytics see this link https://www.google.com/intl/de_de/analytics/.

18. Privacy terms on the use and application of TikTok

Legal basis

The personalized advertising displayed to you by TikTok is based on your consent. Apart from that, TikTok processes user data on the basis of a contract (Art. 6(1/1b) DS-GVO), a balance of interests (Art. 6(1/1f) DS-GVO) or in compliance with legal obligations (Art. 6(1/1c) DS-GVO). Users have the option of revoking consent and objecting to processing based on a balance of interests pursuant to Art. 21 DS-GVO. For details see the privacy statement and terms of use of TikTok (link see below).

Purpose

TikTok processes personal data for various purposes, e.g. to supply services, to notify users of changes in services, to offer support to users, to enable users to share user information with other users, to develop new services or to comply with legal obligations.

TikTok collects the following user data, among others: profile data, user content and usage data, location data, information on contacts / friends.

For more details on how your data are used and which data and information are processed see the TikTok privacy statement and terms of use (link see below).

Duration of data retention

TikTok retains user data for as long as necessary to supply services to users, to comply with contractual obligations and exercise their rights with regard to the information in question. If user information is not required to supply the service, TikTok retains user data only for as long as TikTok can pursue legitimate business purposes with such retention.

If a user requests deletion of his or her TikTok account, the account will first be deactivated for several weeks and deleted subsequently. In the course of this procedure, user data in connection with the in-app message function will also be deleted.

Messages sent by you to other users of the TikTok service remain stored on their devices.

The TikTok privacy statement (ink see below) draws attention to potentially longer deletion and retention periods.

Objection, revocation and termination of processing

TikTok offers users the option of controlling and managing their own user data (personal data) via configuration options. In addition, TikTok offers automated information services on how your data is processed. Pursuant to statutory requirements you have the right to demand erasure and correction of data, to object to your data being used, to demand restricted use and to withdraw your declared consent at any time.

Additional advice

Please note that TikTok may change their terms of use and privacy policy at any time. You should therefore check at regular intervals whether these texts are still valid. The DSV Group assumes no responsibility for the actuality, accuracy or completeness of information relating to the terms of use and privacy policy of TikTok. The privacy policy available to us complies with information required in accordance with Articles 12 ff. DS-GOV to the extent that the DSV Group’s companies use TikTok services for embedding videos on one of our websites or our staff use TikTok for the benefit of customers.

Terms of use - TikTok:
https://www.tiktok.com/legal/terms-of-use?lang=de

Privacy policy:
https://www.tiktok.com/legal/privacy-policy?lang=de#section-1

Questions on TikTok privacy policy:
TikTok offers a contact form linked to the privacy policy to users who have questions concerning TikTok’s privacy policy or wish to contact TikTok’s privacy officer.

19. Privacy terms on the use and application of Google AdWords

The data controller has integrated Google AdWords on this website. Google AdWords is a service for internet advertising and permits advertisers to place ads in search engine results of Google as well as in Google advertising networks. Google AdWords enables an advertiser to specify certain key words in advance through which an ad in the Google search engine results will be displayed only if the user calls up a key word-relevant result via the search engine. Within the Google advertising network, ads are distributed over topically relevant websites via an automated algorithm and under consideration of the key words specified in advance.

The operating company of the services of Google AdWords is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of Google AdWords is the promotion of our website via display of ads of specific interest on the website of third-party businesses and in search engine results of the Google search engine and via display of third-party advertisements on our website.

When a data subject visits our website via a Google ad, Google places information in the form of a so called conversion cookie on that data subject’s IT system. For definition of cookie see above. A conversion cookie ceases to be valid after thirty days and does not allow identification of the data subject. During its period of validity, the conversion cookie makes it possible to track whether certain single pages, such as the shopping cart of an online shop, have been called up on our website. The conversion cookie enables us as well as Google to track whether a data subject reaching our website via an AdWords advertisement has generated turnover, i.e. completed or aborted the purchase of goods.  

Google uses the data and information gathered via the use of the conversion cookie to compile visitor statistics for our website. We use these visitor statistics to obtain the total number of users referred to us via AdWords ads, i.e. to determine success or failure of the respective AdWords ads and to optimize our AdWords ads in future. Neither our institution nor other advertising clients of Google AdWords receive information from Google that would permit identification of the data subject in question.

Personal data, such as the websites visited by the data subject, are stored by means of the conversion cookie. This means that personal data including the IP address of the internet connection used by the data subject are transmitted to Google in the United States with each visit to our websites, stored there and potentially passed on to third parties.  

As explained above, the data subject may prevent the placing of cookies via our website at any time by means of the setting of the internet browser and thus permanently reject the placing of cookies. A pertinent setting of the browser would moreover prevent Google from placing a conversion cookie on the data subject’s IT system. In addition, a cookie already installed by Google AdWords can be deleted at any time via the internet browser or other software programs.

Moreover, the data subject has the option of objecting to interest-specific advertising from Google. For this purpose, the data subject must call up the link  www.google.de/settings/ads from each of the browsers used, and enter the desired settings.

For more information and the currently valid privacy policy of Google see:

 https://www.google.de/intl/de/policies/privacy/.

20. Privacy terms on the use and application of Instagram

The data controller has installed components of the service Instagram on this website. Instagram is to be qualified as an audiovisual platform and enables users to share photos and videos and further disseminate such data in other social networks.

The operating company of Instagram services is Instagram LLC, 1 Hacker Way, Building 14 First Floor, Menlo Park, CA, USA.

With each visit to a single page of this website operated by the data controller and containing an integrated Instagram component (Insta button), the respective Instagram component automatically causes the internet browser on the data subject’s IT system to download a display of that Instagram component. In the context of this technical procedure, Instagram receives information which specific single page of our website the data subject has accessed.

If a data subject is simultaneously logged in to Instagram, Instagram can see from each visit of that person to our website and for the entire duration of that visit which specific single page the data subject has accessed. The Instagram component gathers this information and associates it with the data subject’s Instagram account. A click on one of the Instagram buttons integrated in our website enables Instagram to associate the data and information transmitted in this way with the data subject’s personal Instagram user account and to store and process such data.

The Instagram component always notifies Instagram that the data subject has accessed our website whenever that person is simultaneously logged in to Instagram at the time of access; this happens whether a data subject clicks an Instagram component or not. If data subjects do not agree to the transfer of this information to Instagram, they may prevent the transfer by logging out of their Instagram account prior to accessing our website.

For more information and the currently valid privacy policy of Instagram see:  https://help.instagram.com/155833707900388 and https://www.instagram.com/about/legal/privacy/.

21. Privacy terms on the use and application of YouTube

The data controller has installed components of YouTube on this website. YouTube is an internet video portal that permits users to put video clips on the net free of charge, and other users to view, assess and comment on these clips, also free of charge. YouTube permits the publication of all kinds of videos, so that complete movies and TV programs, music videos, trailers or self-produced videos can be accessed via the internet portal.

The operating company of YouTube is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

With each visit to a single page of this website operated by the data controller and containing an integrated YouTube component (YouTube video), the respective YouTube component automatically causes the internet browser on the data subject’s IT system to download a display of that YouTube component. Further information on YouTube is available at https://www.youtube.com/yt/about/de/. In the context of this technical procedure, YouTube and Google receive information which specific single page of our website the data subject has accessed.

If a data subject is simultaneously logged into YouTube, access to a single page containing a YouTube video will show to YouTube the specific single page of our website visited by the data subject. YouTube and Google store that information and associate it with the data subject’s respective YouTube account.

The YouTube component always notifies YouTube and Google that the data subject has accessed our website whenever that person is simultaneously logged in to YouTube at the time of access; this happens whether a data subject clicks a YouTube video or not. If data subjects do not agree to the transfer of this information to YouTube and Google, they may prevent the transfer by logging out of their YouTube account prior to accessing our website.

The privacy policy published by YouTube, available at https://www.google.de/intl/de/policies/privacy/, offers information about the collection, processing and usage of personal data by YouTube and Google.

22. Tool: Heyflow

At some points we use the interactive tool “Heyflow”, a product of Heyflow GmbH, Jungfernstieg 49, 20354 Hamburg, Germany, to answer and process your enquiries. Processing is based on your consent (Art. 6(1 lit. a) DS-GVO) or respectively our legitimate interest (Art. 6(1 lit. f) DS-GVO). Heyflow processes your data as a processor (Art. 28 DS-GVO) and upon our instructions exclusively, and stores that data on EU servers. We have concluded an order processing contract with Heyflow.

23. Mode of payment: Privacy terms concerning Klarna as mode of payment

The data controller has integrated components of Klarna on this website. Klarna is an online payment service provider for purchase on account or flexible installment payments. Klarna offers further services such as buyer protection or identity and solvency check.

The operating company of Klarna is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden.

When data subjects select “purchase on account” or “installment purchase” from the payment options in our online shop during the order transaction, their data are automatically transmitted to Klarna. Selecting one of these payment options, the data subject consents to personal data being transmitted as necessary for purposes of the payment option or for an identity or solvency check.  

As a rule, personal data passed on to Klarna are: first name, last name, address, date of birth, gender, email address, IP address, phone number, mobile number and other data required for a purchase on account or by installments. A purchase contract may also require personal data in connection with the respective order. This can mean an exchange of payment details like bank account, card number, expiry date and CVC code, number of articles, item number, data on goods and services, prices and taxation, details about former purchasing habits or a data subject’s financial state.

Communication of data primarily fulfills purposes of identity check, payment administration and prevention of fraud. The data controller will transmit personal data to Klarna specifically in cases where legitimate interest can be demonstrated. Klarna passes personal data exchanged between Klarna and the data controller on to credit agencies for identity and solvency checks.

Moreover, Klarna transmits personal data to associated enterprises (Klarna Group) and service providers or subcontractors in so far as this is necessary to meet contractual obligations or to process the data on behalf of the consignor.

For the purpose of deciding whether to establish, conduct or terminate a contractual relationship, Klarna collects and uses data and information on a data subject’s payment history and probability values for future payment behavior (so called scoring). Scoring is calculated on the basis of scientifically approved mathematical-statistical methods.

The data subject may withdraw consent to the handling of personal data by Klarna at any time. Withdrawal has no effect on personal data, the processing, use or transmission of which is essential for the (contractually agreed) payment procedure.

For the currently valid privacy policy of Klarna see https://cdn.klarna.com/1.0/shared/content/policy/data/de_de/data_protection.pdf.

24. Mode of payment: Privacy terms concerning PayPal as mode of payment

The data controller has integrated components of PayPal on this website. PayPal is an online payment service provider. Payments are settled via so called PayPal accounts which represent virtual private or business accounts. PayPal offers the further option of making virtual payments via credit card in case a user has no PayPal account. A PayPal account is kept via an email address so that there is no account number in the classic sense. PayPal permits to initiate online payments to third parties or receive payments. Moreover, PayPal assumes trustee functions and provides buyer protection.

The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.

When data subjects select “PayPal” from the payment options in our online shop during the order transaction, their data are automatically transmitted to PayPal. Selecting this payment option, a data subject consents to personal data being transmitted as required for payment handling.   

As a rule, personal data passed on to PayPal are: first name, last name, address, email address, IP address, phone number, mobile number and other data required for payment handling. A purchase contract may also require personal data in connection with the respective order.

The purpose of this data transmission is payment handling and prevention of fraud. The data controller will transmit personal data to PayPal specifically in cases where legitimate interest can be demonstrated. PayPal may pass personal data exchanged between PayPal and the data controller on to credit agencies for identity and solvency checks.

PayPal may transmit personal data to associated enterprises and service providers or subcontractors in so far as this is necessary to meet contractual obligations or to process the data on behalf of the consignor.

The data subject may withdraw consent to the handling of personal data by PayPal at any time. Withdrawal has no effect on personal data the processing, use or transmission of which is essential for the (contractually agreed) payment procedure.

For the currently valid privacy policy of PayPal see: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

25. Mode of payment: Privacy terms concerning Sofortüberweisung as mode of payment

The data controller has integrated components of Sofortüberweisung on this website. Sofortüberweisung is a payment service provider for cashless payment of products and services on the internet. Sofortüberweisung uses a technical procedure to give online traders immediate confirmation of payment, so that they can supply goods or render services or downloads to customers immediately upon receipt of the order.

The operating company of Sofortüberweisung is SOFORT GmbH, Fußbergstraße 1, 82131 Gauting, Germany.

When data subjects select “Sofortüberweisung” from the payment options in our online shop during the order transaction, their data are automatically transmitted to Sofortüberweisung. Selecting this payment option, a data subject consents to personal data being transmitted as required for payment handling.   

In the purchase transaction via Sofortüberweisung, the buyer communicates PIN and TAN to Sofort GmbH. After technical verification of the account balance and account coverage, Sofortüberweisung executes the transfer to the online trader who receives automated confirmation of the transaction.

Personal data passed on to Sofortüberweisung are: first name, last name, address, email address, IP address, phone number, mobile number and other data required for the payment transaction. The purpose of this data transmission is payment handling and prevention of fraud. The data controller will transmit further personal data to Sofortüberweisung in cases where legitimate interest can be demonstrated. Sofortüberweisung may pass personal data exchanged between Sofortüberweisung and the data controller on to credit agencies for identity and solvency checks.

Sofortüberweisung may transmit personal data to associated enterprises and service providers or subcontractors in so far as this is necessary to meet contractual obligations or to process the data on behalf of the consignor.

The data subject may withdraw consent to the handling of personal data by Sofortüberweisung at any time. Withdrawal has no effect on personal data the processing, use or transmission of which is essential for the (contractually agreed) payment procedure.

For the currently valid privacy policy of Sofortüberweisung see here.

26. Online donations

The website of the Brandenburg Medical School Theodor Fontane offers supporters the opportunity to make online donations. We have integrated the donation form “Fundraisingbox” of the service provider Wikando GmbH, Schießgrabenstr. 32, 86150 Augsburg, on our website. Wikando GmbH has made contractual arrangements with us to maintain data protection and use personal data exclusively for the agreed purpose, i.e. the proper processing of your donation.

Session cookies required for technical reasons are set when the donation form is called up and will be automatically deleted when you leave the website.

When you make an online donation, your personal data is transmitted to us via a connection secured by SSL. We forward your encrypted payment data to the respective payment provider (see below). The donation form requests the following data: first name, last name, for corporate donations the name of the company, address in case a donation receipt is requested, your email for making contact and confirming the donation (transaction-related contact). Depending on the payment provider (see below), we ask for further data if required for the handling of your donation. For further information see the privacy terms of
Fundraising Box at:
https://www.fundraisingbox.com/datenschutz/.
For further information see: https://www.fundraisingbox.com/datensicherheit/

Please note that we are required by law to retain your donation data (i.e. name, address, bank details, date and amount of the donation) for a ten-year period.

Payment provider: Direct debit
In case of donation via direct debit, the servers of the Wikando GmbH store the data so that the Medizinische Hochschule Brandenburg CAMPUS GmbH can execute the direct debit transaction. We transmit name and IBAN of the account holder to the credit institution we have appointed to carry out the transaction, i.e. Sparkasse Ostprignitz-Ruppin.

Payment provider: PayPal
You may make online donations to us via the payment provider PayPal. If you select PayPal as the payment provider, your data are passed on to PayPal Europe S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, Luxembourg. Data transmission is carried out pursuant to Art. 6(1 lit. a) EU DS-GVO (consent) and based on Art. 6(1 lit. b) EU DS-GVO (processing in fulfillment of contract).
Only data required for payment handling will be transmitted. As a rule, these are: first name, last name, email address, IP address, phone or mobile number, or other details required for the payment transaction.

The purpose of this data transmission is payment handling and prevention of fraud. Pursuant to Art. 6(1 lit.f) EU DS-GVO (legitimate interest), PayPal may pass on your payment details to credit agencies for identity and solvency checks. Where necessary to fulfil contractual obligations or for contract data processing, PayPal may pass on your data to subcontractors and other contract partners. You are entirely free to object to the processing of your personal data by PayPal. This does not affect data required for the payment transaction or data processing in the past. For further information see the PayPal privacy policy at:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

Payment provider: Stripe
You may make online donations to us via credit card. We will pass on your payment-relevant data to Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Data transmission is carried out pursuant to Art. 6(1 lit. a) EU DS-GVO (consent) and Art. 6(1 lit. b) EU DS-GVO (processing in fulfillment of contract). As a rule, these are: first name, last name, address, phone number (land line and/or mobile), email address, IP address, credit card provider, credit card number, check digits and expiry date, and possibly further details required for the payment transaction.

Pursuant to Art. 6(1 lit. f) EU DS-GVO (legitimate interest), Stripe may pass on your payment details to credit agencies for identity and solvency checks. Where necessary to fulfil contractual obligations or for contract data processing, Stripe may pass on your data to subcontractors or other contract partners. You may withdraw your consent to data processing by Stripe at any time; withdrawal does not affect past instances of data processing. For more information see the Stripe privacy policy at:  https://stripe.com/de/privacy#translation

27. Legal basis of processing

Art. 6(1 lit. a) DS-GVO is the legal basis for processing operations where our institution seeks consent for specific processing purposes. If the processing of personal data is required to fulfill a contract with the data subject as a contracting party, as for example in processing activities required for the delivery of goods or other services or counter services, then the processing is based on Art. 6(1 lit. b) DS-GVO. The same applies to processing activities required to perform pre-contractual measures, for example in response to inquiries about our products and services. In case of legal obligations that require the processing of personal data, for example tax obligations, processing is based on Art. 6(1 lit. c) DS-GVO. On rare occasions the processing of personal data may become necessary to protect vital interests of the data subject or another natural person. That would be the case if a visitor to our institution was injured, and that person’s name, age, health insurance details or other vital information would have to be revealed to a doctor, a hospital or other third parties. In that case, processing would be based on Art. 6(1 lit. d) DS-GVO. Processing operations may ultimately be based on Art. 6(1 lit. f) DS-GVO. This is the legal basis of other processing operations not covered by the before-mentioned legal grounds, where processing is necessary to safeguard a legitimate interest of our institution or of a third party, unless the interests, fundamental rights and freedoms of the data subject prevail. We are entitled to such processing operations particularly since European lawmakers mention them explicitly and take the view that a legitimate interest might be assumed if the data subject is a client of the data controller (recital 47/2 DS-GVO).

28. Legitimate interests in processing pursued by the data controller or a third party

Insofar as the processing of personal data is based on Article 6(1 lit. f) DS-GVO, it is our legitimate interest to conduct our business activities for the benefit of all our employees and shareholders.    

29. Duration of storage of personal data

The criterion for the duration of storage of personal data is the respective statutory retention period. The data in question will be routinely deleted upon expiry of that period unless required to meet or initiate a contract.

30. Statutory or contractual regulations on the provision of personal data; necessity for contract conclusion; obligation of data subject to provide personal data; possible consequences of failure to provide data

Please be aware that the provision of personal data is partly prescribed by law (e.g. tax legislation) or may result from contractual provisions (e.g. information on contracting partners). In some cases, a contract conclusion may require a data subject to provide personal data which we need to process subsequently. A data subject is, e.g., obliged to make personal data available to us when concluding a contract with our institution. Failure to do so would make a contract impossible. Prior to the provision of personal data, the data subject must contact one of our employees. Our employee will inform the data subject whether the provision of personal data is required by law or contract in that individual case, or required for contract conclusion, whether there is an obligation to provide personal data, and what the consequences of failure to do so would be.

31. Automated decision making

As a responsible institution we abstain from automated decision making or profiling.

Th original German-language version of this privacy statement was generated by the privacy policy generator of DGD Deutsche Gesellschaft für Datenschutz GmbH which acts as external data protection adviser (Datenschutzbeauftragter), in collaboration with RC GmbH (recyclers of used computers: gebrauchte Computer), and the law firm WILDE BEUGER SOLMECKE | Rechtsanwälte.

 

© 2026 MEDIZINISCHE HOCHSCHULE BRANDENBURG Theodor Fontane
Settings saved
Privacy Settings

In order to be able to offer you a personalized and optimized user experience, we use optional, statistical cookies and localStorage entries for technical functions.

Technically required cookies are always loaded.

We use localStorage entries for technical functions that are necessary for a smooth and effective use of our website.

Our optional statistical cookies are used to collect information about the use of our website. These cookies help us understand how you, for example, access our website, how long you stay, and which pages you visit.

user_privacy_settings

Domain name: mhb-fontane.de
Expiration: 30 days
Storage location: Localstorage
Description: Stores the privacy level settings from the cookie consent tool "Privacy Manager".

user_privacy_settings_expires

Domain name: mhb-fontane.de
Expiration: 30 days
Storage location: Localstorage
Description: Stores the storage duration of the privacy level settings from the cookie consent tool "Privacy Manager".

ce_popup_isClosed

Domain name: mhb-fontane.de
Expiration: 30 days
Storage location: Localstorage
Description: Stores that the popup (content element - popup) has been closed by user click.

onepage_animate

Domain name: mhb-fontane.de
Expiration: 30 days
Storage location: Localstorage
Description: Stores that the scroll script for the onepage navigation has been initiated.

onepage_position

Domain name: mhb-fontane.de
Expiration: 30 days
Storage location: Localstorage
Description: Stores the offset position for the onepage navigation.

onepage_active

Domain name: mhb-fontane.de
Expiration: 30 days
Storage location: Localstorage
Description: Stores that the current page is an "Onepage" page.

view_isGrid

Domain name: mhb-fontane.de
Expiration: 30 days
Storage location: Localstorage
Description: Stores the current view mode of a grid layout on the website.

portfolio_MODULE_ID

Domain Name: mhb-fontane.de
Expiration: 30 days
Storage Location: Localstorage
Description: Stores the selected filter of the portfolio filter.

Eclipse.outdated-browser: "confirmed"

Domain Name: mhb-fontane.de
Expiration: 30 days
Storage Location: Localstorage
Description: Stores the state of the "Outdated Browser" notice bar.

PHPSESSID

Domain Name: mhb-fontane.de
Expiration: Session
Storage Location: Cookie (required)
Description: The "PHPSESSID" cookie is used by PHP applications to maintain the session state of a user across multiple page requests. It contains a unique identifier for the current session and allows the website to store information such as login status, settings, and other session data.

csrf_https-contao_csrf_token

Domain Name: mhb-fontane.de
Expiration: Session
Storage Location: Cookie (required)
Description: The "csrf_https-contao_csrf_token" cookie is used by the Contao web application to prevent cross-site request forgery attacks. It contains a randomly generated token used in form submissions to ensure that the request comes from the correct user and not from a malicious source.

_ga_L1WJ29L4GT

Domain Name: .mhb-fontane.de
Expiration: 400 days
Storage Location: Cookie (Statistics)
Description: This cookie is used by Google Analytics to distinguish users. It contains a randomly generated unique identifier.

_ga

Domain Name: .mhb-fontane.de
Expiration: 400 days
Storage Location: Cookie (Statistics)
Description: This cookie is used by Google Analytics to distinguish users. It contains a randomly generated unique identifier. It is typically used for analyzing website visits and can capture information such as the number of visits, duration of the visit, and pages visited.

_gid

Domain name: .mhb-fontane.de
Expiration: 24 hours
Location: Cookie (Statistics)
Description: This cookie is used by Google Analytics to distinguish users. It contains a randomly generated unique identifier. It is used for analyzing website visits, similar to the "_ga" cookie, but it has a shorter expiration time.

NAP

Domain name: .bing.com
Expiration: Session
Location: Cookie (Statistics)
Description: This cookie contains information about the user's activities and settings on the Bing website.

WLS

Domain name: .bing.com
Expiration: Session
Location: Cookie (Statistics)
Description: This cookie stores certain information about the user's settings on the Bing website.

_EDGE_S

Domain name: .bing.com
Expiration: Session
Location: Cookie (Statistics)
Description: This cookie contains a unique session ID and additional information for tracking the user session on the Bing website.

OIDI

Domain name: .bing.com
Expiration: 35 days
Location: Cookie (Statistics)
Description: This cookie is used to store user identification information on the Bing website.

_clck

Domain name: .bing.com
Expiration: 8 months
Location: Cookie (Statistics)
Description: This cookie stores a unique identifier for the user and is used for tracking and analyzing user activities on the Bing website.

OID

Here is the translation of the text values in the code:

Domain name: .bing.com
Expiration: 35 days
Location: Cookie (Statistics)
Description: This cookie contains user identification information and is used for various purposes on the Bing website.

SRCHHPGUSR

Domain Name: .bing.com
Expiration: 11 months
Location: Cookie (Statistics)
Description: This cookie stores information about user settings and preferences on the Bing homepage.

ABDEF

Domain Name: .bing.com
Expiration: 9 months
Location: Cookie (Statistics)
Description: This cookie contains information about A/B tests and experiments that the user has participated in on Bing search.

BCP

Domain Name: .bing.com
Expiration: 8 months
Location: Cookie (Statistics)
Description: This cookie stores information about the user's display settings on the Bing website.

BFB

Domain Name: .bing.com
Expiration: 9 months
Location: Cookie (Statistics)
Description: This cookie contains information about user activities and settings on the Bing website.

BFBUSR

Domain Name: .bing.com
Expiration: 9 months
Location: Cookie (Statistics)
Description: This cookie contains information about user activities and settings on the Bing website.

SRCHD

Domain Name: .bing.com
Expiration: 9 months
Location: Cookie (Statistics)
Description: This cookie stores information about user settings and preferences on the Bing website.

_SS

Here is the translation of the text values into English: ```plaintext

Domain Name: .bing.com
Expiration: Session
Location: Cookie (Statistics)
Description: This cookie contains a unique session ID and is used for tracking and analyzing user activities on the Bing website.

SRCHUID

Domain Name: .bing.com
Expiration: 9 months
Location: Cookie (Statistics)
Description: This cookie contains a unique user ID and is used for tracking and analyzing user activities on the Bing website.

dsc

Domain Name: .bing.com
Expiration: Session
Location: Cookie (Statistics)
Description: This cookie stores information about the user's activities and settings on the Bing website.

_HPVN

Domain Name: .bing.com
Expiration: 9 months
Location: Cookie (Statistics)
Description: This cookie stores various information about the user's status and is used for tracking and analyzing user activities on the Bing website.

SRCHUSR

Domain Name: .bing.com
Expiration: 11 months
Location: Cookie (Statistics)
Description: This cookie stores information about the user's status and is used for tracking and analyzing user activities on the Bing website.

_UR

Domain Name: .bing.com
Expiration: 9 months
Location: Cookie (Statistics)
Description: This cookie contains various information about the user's status and is used for tracking and analyzing user activities on the Bing website.

ipv6

Domain Name: .bing.com
Expiration: 2024-05-26T13:33:37.738Z
Location: Cookie (Statistics)
Description: This cookie stores information about the user's IP version and is used for tracking and analyzing user activities on the Bing website.

MUID

Domain name: .bing.com
Expiration: 400 days
Location: Cookie (Statistics)
Description: This cookie contains a unique user ID and is used for tracking and analyzing user activities on the Bing website.

_uetvid

Domain name: .mhb-fontane.de
Expiration: 24 hours
Location: Cookie (Statistics)
Description: This cookie contains a unique visitor ID and is used for tracking and analyzing user activities on the website.

_uetsid

Domain name: .mhb-fontane.de
Expiration: 24 hours
Location: Cookie (Statistics)
Description: This cookie contains a unique session ID and is used for tracking and analyzing user activities on the website.

_clsk

Domain name: .mhb-fontane.de
Expiration: 24 hours
Location: Cookie (Statistics)
Description: This cookie stores information about the visitor's status and is used for tracking and analyzing user activities on the website.

CLID

Domain name: www.clarity.ms
Expiration: 365 days
Location: Cookie (Statistics)
Description: This cookie contains a unique user ID and is used for tracking and analyzing user activities on the Clarity website.

xs

Domain name: .facebook.com
Expiration: 360 days
Location: Cookie (Statistics)
Description: This cookie is used by Facebook to maintain a user's session and verify their identity.

oo

Domain name: .facebook.com
Expiration: 360 days
Location: Cookie (Statistics)
Description: This cookie is used by Facebook to store information about the user, such as their language settings.

usida

Domain name: .facebook.com
Expiration: Session
Location: Cookie (Statistics)
Description: This cookie contains an encrypted user ID and is used by Facebook to store user information.

presence

Domain name: .facebook.com
Expiration: Session
Location: Cookie (Statistics)
Description: This cookie is used by Facebook to track a user's presence status, such as whether they are online.

sb

Domain name: .facebook.com
Expiration: 8 months
Location: Cookie (Statistics)
Description: This cookie is used by Facebook to store information about the user to ensure the security and integrity of the website.

datr

Domain name: .facebook.com
Expiration: 135 days
Location: Cookie (Statistics)
Description: This cookie is used by Facebook to identify users and detect security risks.

c_user

Domain name: .facebook.com
Expiration: 360 days
Location: Cookie (Statistics)
Description: This cookie stores the user ID of the Facebook user.

wd

Domain name: .facebook.com
Expiration: 4 days
Location: Cookie (Statistics)
Description: This cookie stores the device's screen size to adjust the layout of the Facebook page.

dpr

Domain name: .facebook.com
Expiration: 4 days
Location: Cookie (Statistics)
Description: This cookie stores the device's screen resolution to adjust the layout of the Facebook page.

_fbp

Domain name: .mhb-font ane.de
Expiration: 90 days
Location: Cookie (Statistics)
Description: This cookie is used by Facebook for tracking advertising activities.

 


You are using an outdated browser. The website may not be displayed correctly.