Data Protection Information
- Fordatis - Research Data Repository of the Fraunhofer-Gesellschaft -
When you use this website, we process your personal data as data controllers and save them for the duration required to fulfill the defined purposes and legal obligations. The sections below provide further details about the data this involves, how they will be processed and which rights you have in this regard.
Personal data, as defined by Article 4 (1) General Data Protection Regulation (GDPR) include all information related to an identified or identifiable natural person.
1. Name and Contact Information of Controller and Corporate Data Protection Officer
This data protection information applies to data processing on our Research Data Repository Fordatis (fordatis.fraunhofer.de) by the controller:
zur Förderung der angewandten Forschung e.V.
Hansastraße 27 c,
Telephone: [+49 89 1205-0]
Fax: [+49 89 1205-7531]
The corporate data protection officer at Fraunhofer can be reached at the above-mentioned address, c/o Data Protection Officer or at email@example.com.
Please feel free to contact the data protection officer directly at any time with your questions concerning your data protection rights and/or your rights as data subject.
2. Personal Data Processing and Purposes of Data Processing
a) When creating user accounts
The Research Data Repository “Fordatis” automatically creates user accounts if an entry exists in the corporate directory (Shibboleth). This involves the following mandatory information:
- Email address
- First and last Name
- Institutional affiliation
The information will be erased automatically as soon as the entry in the corporate directory is erased.
In Fordatis the role “Admin” has user accounts by function and the passwords of these accounts are also stored in the Fordatis system.
b) When visiting the repository
Every time you visit our web pages, our website servers save a protocol of your device accessing our website. This storage is temporary and lasts only until the automated deletion. Our website server saves the following access data until their automated deletion:
- The IP address of the requesting device
- Access date and time
- Name and URL of the accessed data
- The transmitted data volume
- The message whether the access was successful
- The used browser and operating system
- Name of the Internet Provider (ISP)
- The referring website (referring URL)
- Triggered actions in the Repository
- The user's login
The server processes these data for the following purposes:
- To enable the use of the website (link connection [forward setup])
- Administration of the network infrastructure
- Appropriate technical and organisational measures to ensure IT systems and data security commensurate with the available state of the art technology
- To offer user-friendly service
- To optimize the Internet offering
Legal foundations for the above processing purposes:
- Processing in response to a website visitor according to numbers 1-2 Article 6 para. 1, page1, lit. b (Requirement for compliance with provisions of the website user contract)
- Processing pursuant to numbers 3, Article 6 para. 1, page 1, lit. c GDPR (legal obligation to implement technical and organisational measures to ensure secure data processing according to Article 32 GDPR and Article 6 para. 1, page 1, lit. f GDPR (legitimate interests in data processing for the network and information security) as well as
- Data processing pursuant to numbers 4 – 5, Article 6 para. 1, page1 lit. f GDPR (legitimate interests) - our legitimate interests in the processing of data are based in our desire to offer user-friendly optimised web pagesDarüber hinaus setzen wir beim Besuch unserer Website Cookies ein. Nähere Erläuterungen dazu erhalten Sie unter den Ziffer 4 dieser Datenschutzinformation.
c) When using contact forms
We offer the option to contact us via a contact form provided on the website. This involves the following mandatory information:
- Date and page from which the message was sent
- Timestamp of the login
We require your data to determine who sent the inquiry and to be able to answer and process it.
This data processing in response to your inquiry is necessary for the purposes of our legitimate interests pursuant to Art. 6 (1) lit. f GDPR.
We will delete the personal data collected by us using the contact form after your inquiry has been processed.
3. Transfer of Data
If we forward personal data collected through websites to processors, we will notify you in this data protection information regarding the respective data processing operation, citing the specific recipient.
Aside from that, we will only forward your personal data if
- you have given consent pursuant to Art. 6 (1) lit. a GDPR;
- this is required pursuant to Article 6 (1) lit. b GDPR for the performance of a contract with you (for example forwarding to shipping companies for the purpose of delivering goods ordered by you, or forwarding payment information to payment service providers or credit institutions in order to process a payment transaction);
- there is a legal obligation for disclosure pursuant to Art. 6 (1) lit. c GDPR.
The recipients may use the transferred data for the above-mentioned purposes only.
According to Article 28 GDPR, our websites are hosted on our own servers located in Germany exclusively.
The transfer/transmission of personal data to countries outside the EU or an international organisation shall be excluded.
Cookies store information associated with the specific device used. That does not mean that we can directly identify you.
We also use temporary cookies to optimize user-friendliness; these cookies are stored on your device for 30 days. When you visit our site again to use our services, these cookies will automatically detect that you have visited in the past and will reapply your previous entries and settings so that you do not have to enter them again.
The data processed by the cookies are necessary for the above-mentioned purposes to protect our legitimate interests and those of third parties pursuant to Art. 6 (1) lit. f GDPR.
Most browsers automatically accept cookies. However, you can configure your browser to not save any cookies on your computer or to display a notice before new cookies are saved. Completely disabling cookies may mean that you cannot fully use all functions of our website.
5. Rights of the Data Subject
You have the following rights:
- pursuant to Art. 7(3) GDPR, to withdraw your consent at any time. This means that we may not continue the data processing based on this consent in the future;
- pursuant to Art. 15 GDPR, to obtain access to your personal data processed by us. In particular, you may request information about the purposes of the processing, the categories of personal data concerned, the categories of recipients to whom the personal data have been or will be disclosed, and the envisaged period for which the data will be stored. Moreover, you have the right to request rectification, erasure, or restriction of processing, to object to processing, the right to lodge a complaint, and to obtain information about the source of your data if they were not collected by us, as well as about the existence of automated decision-making, including profiling, and, if applicable, meaningful information about the logic involved;
- pursuant to Art. 16 GDPR, to obtain the rectification of inaccurate data or the completion of your personal data without undue delay;
- pursuant to Art. 17 GDPR, to obtain the erasure of personal data saved by us unless processing is necessary to exercise the right of freedom of expression and information, to comply with a legal obligation, for reasons of public interest, or to establish, exercise or defend legal claims;
- pursuant to Art. 18 GDPR, to obtain restriction of processing of your personal data if you contest the accuracy of the data, the processing is unlawful but you oppose the erasure of the personal data, or if we no longer need the personal data while you still require it for establishing, exercising or defending legal claims, or if you have filed an objection to the processing pursuant to Art. 21 GDPR;
- pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us, in a structured, commonly used and machine-readable format or to transmit those data to another controller and
- pursuant to Art. 77 GDPR, the right to lodge a complaint with a supervisory authority. Generally, you may contact the supervisory authority of your habitual residence, place of work or the registered offices of our organization.
Information on your right to object pursuant to Art. 21 GDPR
You have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data pursuant to Art. 6 (1) lit. e GDPR (data processing carried out in the public interest) and Art. 6 (1) lit. f GDPR (data processing for purposes of legitimate interests).
If you file an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defense of legal claims.
If your objection is directed against the processing of data for the purpose of direct marketing, we will stop the processing immediately. In this case, citing a special situation is not necessary. This includes profiling to the extent that it is related to such direct marketing.
If you would like to assert your right to object, please send an email to firstname.lastname@example.org.
6. Data Security
All your personal data are transmitted in encrypted format, using the widely used and secure TLS (Transport Layer Security) standard. TLS is a secure and proven standard that is also used, for instance, in online banking. You will recognize a secure TLS connection by the additional s after http (i.e., https://..) in the address bar of your browser or by the lock icon in the lower part of your browser.
In all other regards, we use suitable technical and organizational security measures to protect your data against accidental or intentional manipulations, partial or complete loss, destruction, or the unauthorized access of third parties. We continuously improve our security measures in accordance with the state of the art.
7. Timeliness and Amendments to this Data Protection Information
The further development of our website and the products and services offered or changed due to statutory or regulatory requirements, respectively, may make it necessary to amend this data protection information. You may access and print out the latest data protection information at any time from our website.