WhatDoUC Logo WhatDoUC

Privacy Statement

I. Name and address of the Data Controller:

The Data Controller for the purposes of the General Data Protection Regulation (hereinafter: GDPR) and other national data privacy laws and regulations is defined as follows:

Hochschule Aalen, Technik- und Wirtschaft,
Aalen University - Technology and Economics (hereinafter: HS Aalen)
represented by its Rector
Beethovenstraße 1
73430 Aalen
E-Mail: info@hs-aalen.de
Phone: +49 7361 576-0

Hochschule Aalen
Fakultät Wirtschaft und Gesundheit - Sekretariat WIB/CSC/DSB
Beethovenstraße 1
73430 Aalen
E-Mail: WIB.Sekretariat@hs-aalen.de

II. Contact details of the Data Protection Officer:

Hochschule Aalen
Beethovenstraße 1
73430 Aalen
E-Mail: datenschutz@hs-aalen.de

III. Scope of processing Personal Data (hereinafter: Personal Data):

This application consists of two components: the website und the mobile application (iOS & Android). In this section the processing of information will be presented separately for both:.

1. Website:

Each time our website is accessed, our system automatically collects Personal Data and information from the computer system of the accessing computer. The following Personal Data are collected:

The temporary storage of the Personal Data is necessary to enable the delivery of the website to the Subject’s computer and to ensure the functionality of the website. In addition, this information helps to optimize the website and ensure the security of our IT systems. An evaluation of the Personal Data for marketing purposes does not take place in this context.

Additionally, the website collects and saves the following information if a user logs in with password. This part of the website is used for administrative tasks of WhatDoUC application:

This personnel data is necessary for managing the restricted access to the administrative functions of WhatDoUC application.

Cookies (Website):

Cookies are small text files that are used by websites for an effective user experience. The related laws allow us to save cookies on your device, if this is absolute necessary for the correct functionality of the website. Other types of cookies except the technical necessary ones are not used on this website. Through the usage of this website, you are accepting to save cookies.

This website saves cookies only if a user logs in with password to the web application. This part of the website serves only for administrative functions. Usage without login sets no cookies.

Required cookies (only after login):
Required cookies are used for restricting access to the protected parts of the website. Authentication on the website can’t operate without these cookies.

Name Provider Reason Max. Age Type
selectedInstitution whatdouc.hs-aalen.de Saving the last selected institution for login n/a Local Storage
_shibsession_<a random string with 92 characters> whatdouc.hs-aalen.de Saving the session id for SSO login. End of session HTTP-Cookie
token-refresh whatdouc.hs-aalen.de Saving the security token for API communication. 4 hours HTTP-Cookie

2. Mobile application:

The mobile application collects and saves the following information only if a user logs in with password:

This information is necessary for identifying the users personally, so that a compensation for the work, i.e. annotating the images, can be offered.

IV. Legal background for processing Personal Data:

V. Empfänger der personenbezogenen Daten:

Die personenbezogenen Daten werden nur von den intern zuständigen Stellen zu den o.g. Zwecken verarbeitet. Nur die Organisationen, die an einem Annotationsprojekt teilnehmen, bekommen die Nutzerdaten der eigenen Organisation. Eine Weitergabe an dritten Personen oder nicht beteiligten Institutionen sind ausgeschlossen.

VI. Transfer of Personal Data to a third country

None of the Personal Data is transferred to a third country or an international organisation.

VII. Duration of storage:

In the case of processing Personal Data in log files, deletion shall be due after fourteen (14) days at the latest.

The information which is collected during a user login on the web application or the mobile application is anonymized after a year of last login date.

VIII. Subject rights:

The regulatory authority over Aalen University is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, poststelle@lfdi.bwl.de.