Data protection and data security are of great importance to RefCare and to our organization. Transparency regarding the processing of your personal data, as well as the protection of your data, are therefore particularly important to us.
With this statement, we provide you with an overview of how personal data is collected and processed when you use our websites and what you can do yourself to better protect your data.
Controller for data processing
Universitätsklinikum Heidelberg
Im Neuenheimer Feld 672
69120 Heidelberg
Public law institution represented by the Executive Board of the University Hospital
Phone: +49 6221 56-0
Fax: +49 6221 56-5999
Email: klinikumsvorstand@med.uni-heidelberg.de
Data protection officer
Universitätsklinikum Heidelberg
Data Protection Officer
Im Neuenheimer Feld 672
69120 Heidelberg
Phone: +49 6221 56 7036
Email: datenschutz@med.uni-heidelberg.de
Personal data are all information relating to an identified or identifiable natural person. The decisive factor is whether it is possible to establish a personal reference based on the collected data. This includes information such as your name, address, telephone number, or email address. Information that cannot be linked directly to your actual identity – such as preferred websites or the number of users visiting a page – is not considered personal data.
When you visit our websites, our web servers temporarily store connection data of the requesting computer, the pages you visit, the date and duration of your visit, the identification data of the browser and operating system used, and the website from which you accessed ours.
Further personal data, such as your name, address, telephone number, or email address, are only collected if you voluntarily provide them – for example, as part of a registration, survey, competition, contract execution, or information request.
Where the website allows you to enter personal or business data (such as email addresses, names, or postal addresses), the disclosure of such data by the user is expressly voluntary. Emails are transmitted via a contact form. If you send us such a message, your personal data will only be collected to the extent necessary to respond. Emails are transmitted unencrypted.
The personal data you provide will be used solely for the technical administration of the websites and to fulfill your wishes and requirements – generally, to process a contract concluded with you or to respond to your inquiry.
Only where you have given prior consent – or if statutory provisions permit – will we also use these data for product-related surveys, marketing purposes, or statistical evaluations.
Your personal data will not be passed on, sold, or otherwise transmitted to third parties unless this is necessary for contract performance or you have expressly consented.
You may withdraw your consent at any time with effect for the future.
We generally store all information you transmit to us until the respective purpose (e.g. contract performance) is fulfilled. For example, inquiries are stored until completion, and newsletter data until you unsubscribe. Where longer retention is required by law, data will be stored accordingly.
If you no longer wish us to use your data, we will of course comply with your request immediately (please contact us at the address listed under “Contact”).
Stored personal data will be deleted when you withdraw your consent, when knowledge of the data is no longer required for the purpose pursued, or when storage is otherwise unlawful. Data required for billing or accounting purposes are not affected by a deletion request.
During your visit to our website, we use so-called cookies — small text files stored on your computer. Cookies help us determine usage frequency and the number of users, and make our website as convenient and efficient as possible for you.
We use “session cookies”, which are temporarily stored during your visit, and “permanent cookies” to recognize returning visitors. Permanent cookies serve to provide optimal user guidance and to present you with varied content. The content of a permanent cookie is limited to an identification number. Personal data such as name or IP address are not stored. No individual usage profiles are created.
Our website can also be used without cookies. You can disable cookie storage in your browser, restrict it to certain websites, or set your browser to notify you when a cookie is sent. Please note that deactivating cookies may limit the website’s functionality and usability.
Cookies required for the electronic communication process or the provision of specific functions (e.g. shopping cart) are stored based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically correct and optimized provision of services. Other cookies (e.g. those used for analysis purposes) are addressed separately in this privacy statement.
Web analytics with Matomo (without cookies)
This website uses Matomo, an open-source web analytics software, for statistical analysis of visitor access. The analysis is carried out entirely without cookies. IP addresses are anonymized before storage, preventing any link to individuals. Data processing is based on our legitimate interest in optimizing our website in accordance with Art. 6(1)(f) GDPR. Since all data are processed exclusively on our own servers and not shared with third parties, maximum protection of your personal data is ensured.
Your visit is currently being recorded. Click here to opt out of tracking.
We take all necessary technical and organizational security measures to protect your personal data from loss and misuse. Your data are stored in a secure operating environment not accessible to the public.
In certain cases, personal data are encrypted during transmission using Secure Socket Layer (SSL) technology. This means that communication between your computer and our servers takes place using a recognized encryption method, provided your browser supports SSL.
Where we obtain consent for processing personal data, Art. 6(1)(a) GDPR serves as the legal basis. When processing is necessary for the performance of a contract with the data subject, Art. 6(1)(b) GDPR applies. If processing is required to fulfill a legal obligation, Art. 6(1)(c) GDPR applies. If processing is necessary to protect vital interests of the data subject or another person, Art. 6(1)(d) GDPR applies. Where processing is necessary to safeguard a legitimate interest of our company or a third party and this interest outweighs the rights and freedoms of the data subject, Art. 6(1)(f) GDPR serves as the legal basis. Legitimate interests include ensuring website operation and security, analyzing website usage, and simplifying website acce
Under applicable law, you have the right at any time to obtain free information about your stored personal data, their origin, recipients, and the purpose of processing (Art. 15 GDPR), as well as the right to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), objection (Art. 21 GDPR), and data portability (Art. 20 GDPR).
For the right of access and erasure, the limitations of §§34 and 35 of the German Federal Data Protection Act (BDSG) apply.
You also have the right to lodge a complaint with the competent supervisory authority (Art. 77 GDPR in conjunction with §19 BDSG). The competent authority is the data protection officer of the federal state in which our company is based.
A list of data protection officers and their contact details can be found at:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
Many data processing operations are only possible with your express consent. You may withdraw any consent already given at any time by sending us an informal email. The legality of processing carried out prior to withdrawal remains unaffected.
We may amend this privacy policy from time to time. Any changes will be announced on this page in due course.
Stand: 18.05.2018