Data Protection
Privacy Policy
1. Introduction With the following information, we wish to provide you—as the "data subject"—with an overview of how we process your personal data and to inform you of your rights under data protection laws. In principle, it is possible to use our websites without entering any personal data. However, if you wish to make use of specific services offered by our company via our website, the processing of personal data may become necessary. If the processing of personal data is required and there is no statutory basis for such processing, we generally obtain your consent. The processing of personal data—such as your name, address, or e-mail address—is always carried out in accordance with the General Data Protection Regulation (GDPR) and the state-specific data protection regulations applicable to the "Technische Universität Ilmenau." With this privacy policy, we wish to inform you about the scope and purpose of the personal data we collect, use, and process.
As the data controller, we have implemented numerous technical and organizational measures to ensure the most comprehensive protection possible for the personal data processed via this website. However, internet-based data transmissions can inherently have security gaps, meaning that absolute protection cannot be guaranteed. For this reason, you are free to transmit personal data to us via alternative means, such as by telephone or by mail.
You, too, can take simple and easily implementable measures to protect yourself against unauthorized access to your data by third parties. We would therefore like to offer you some advice here on the secure handling of your data:
Protect your account (login, user account, or customer account) and your IT system (computer, laptop, tablet, or mobile device) with secure passwords. l Only you should have access to the passwords.
Ensure that you use each of your passwords for only one account (login, user account, or customer account).
Do not use the same password for different websites, applications, or online services. When using IT systems that are publicly accessible or shared with others, it is essential to log out after every session on a website, application, or online service.
Passwords should consist of at least 12 characters and be chosen so that they cannot be easily guessed. Therefore, they should not contain common everyday words or the names of yourself or your relatives; instead, they should include a mix of uppercase and lowercase letters, numbers, and special characters.
2. Controller
The controller within the meaning of the GDPR is:
Technische Universität Ilmenau
Ehrenbergstr. 29, 98693 Ilmenau
Germany Phone: +49 3677 69-0
Fax: +49 3677 69-5009
E-mail: praesident@tu-ilmenau.de
Representative of the controller: Univ.-Prof. Dr.-Ing. habil. Kai-Uwe Sattler
3. Data Protection Officer
You can contact the Data Protection Officer as follows:
Martin Neldner
Phone: +49 3677 69-2524
Fax: +49 3677 69-5009
E-mail: datenschutz@tu-ilmenau.de
You may contact our Data Protection Officer directly at any time with any questions or suggestions regarding data protection.
4. Legal basis for processing
Article 6(1)(a) of the GDPR (in conjunction with Section 25(1) of the TTDSG) serves as the legal basis for our company for processing operations where we obtain consent for a specific processing purpose.
If the processing of personal data is necessary for the performance of a contract to which you are a party—such as in processing operations required for the delivery of goods or the provision of another service or counter-performance—the processing is based on Article 6(1)(b) of the GDPR. The same applies to processing operations required to carry out pre-contractual measures, for instance, in cases of inquiries regarding our products or services.
If our company is subject to a legal obligation requiring the processing of personal data—such as for the fulfillment of tax obligations—the processing is based on Article 6(1)(c) of the GDPR.
In rare cases, the processing of personal data might become necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were injured on our premises and their name, age, health insurance details, or other vital information had to be passed on to a doctor, hospital, or other third party. In such an instance, the processing would be based on Article 6(1)(d) of the GDPR.
Finally, processing operations may be based on Article 6(1)(f) of the GDPR.This legal basis applies to processing operations not covered by any of the aforementioned legal bases if the processing is necessary to safeguard a legitimate interest of our company or a third party, provided that the interests, fundamental rights, and fundamental freedoms of the data subject do not override such interest. Such processing operations are permitted, in particular, because they have been specifically mentioned by the European legislator. In this regard, he took the view that a legitimate interest could be assumed if you are a customer of our company (Recital 47, Sentence 2 of the GDPR).
Our services are generally directed at adults. Persons under the age of 16 may not transmit personal data to us without the consent of their parents or legal guardians. We do not request, collect, or disclose to third parties any personal data concerning children or adolescents.
5. Technology
5.1 SSL/TLS Encryption This site uses SSL or TLS encryption to ensure secure data processing and to protect the transmission of confidential content—such as orders, login details, or contact inquiries—that you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser's address bar displays "https://" instead of "http://" and by the padlock symbol in your browser bar.
We employ this technology to protect the data you transmit.
6. Cookies
6.1 Information on avoiding cookies in common browsers
You can delete cookies, allow only selected cookies, or disable cookies entirely at any time via your browser settings. Further information is available on the support pages of the respective providers:
Chrome: https://support.google.com/chrome/answer/95647?tid=311178978.
Safari: https://support.apple.com/de-at/guide/safari/sfri11471/mac?tid=311178978
Firefox: support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-l%C3%B6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
6.2 No cookies are used
We do not use technically necessary cookies or any other forms of cookies on our website. Consequently, you will not see a cookie notice, and no consent for the use of cookies is obtained.
7. Content of our website
7.1 Contacting us / Contact form
Personal data is collected when you contact us (e.g., via contact form or email). The data collected when using a contact form is evident from the respective form. This data is stored and used exclusively for the purpose of responding to your inquiry or for establishing contact and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your inquiry pursuant to Art. 6(1)(f) GDPR. If your contact aims to conclude a contract, an additional legal basis for processing is Art. 6(1)(b) GDPR. Your data will be deleted after your inquiry has been fully processed; this occurs when the circumstances indicate that the matter in question has been conclusively resolved and there are no statutory retention obligations preventing deletion.
8. Your rights as a data subject
8.1 Right of access (Art. 15 GDPR)
You have the right to obtain information from us at any time, free of charge, regarding the personal data stored about you, as well as a copy of this data, in accordance with statutory provisions.
8.2 Complaint to a supervisory authority
You have the right to lodge a complaint with a supervisory authority responsible for data protection regarding our processing of personal data.
9. Currency and amendment of the privacy policy
This privacy policy is currently valid and is dated January 2023.
It may become necessary to amend this privacy policy due to the further development of our websites and services or due to changes in legal or regulatory requirements. The currently applicable privacy policy can be accessed and printed by you at any time on the website at "www.mobilitaet-thueringen.de/datenschutz". This privacy policy was created with the assistance of the data protection software audatis MANAGER.

