Skip to main content
MEDAL

Data Protection Information

Controller

The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection regulations is

German Cancer Research Center - Foundation under Public Law
Im Neuenheimer Feld 280, 69120 Heidelberg, Germany
Phone: +49 (0)6221 420
Email: kontakt(at)dkfz.de
Website: www.dkfz.de

Data Protection Officer

German Cancer Research Center - Foundation under Public Law
Im Neuenheimer Feld 280, 69120 Heidelberg, Germany
Phone: +49 (0)6221 420
Email: datenschutz(at)dkfz.de

1. General Information on the Processing of Personal Data

1.1 Scope of processing

We process our user's personal data only insofar as this is necessary to provide a functional website and our content and services. Processing generally takes place only with the user's consent. An exception applies where prior consent cannot be obtained for factual reasons and the processing is otherwise permitted by law.

1.2 Legal basis

Where we obtain the data subject's consent for processing, Art. 6 para. 1 lit. a GDPR serves as the legal basis.

Where processing is necessary for the performance of a contract to which the data subject is a party, including pre-contractual measures, Art. 6 para. 1 lit. b GDPR applies.

Where processing is necessary to fulfil a legal obligation to which we are subject, Art. 6 para. 1 lit. c GDPR applies.

Where processing is necessary to protect the vital interests of the data subject or another natural person, Art. 6 para. 1 lit. d GDPR applies.

Where processing is necessary to safeguard a legitimate interest of ours or of a third party, and the data subject's interests, fundamental rights and freedoms do not override that interest, Art. 6 para. 1 lit. f GDPR applies.

1.3 Erasure and storage duration

Personal data is erased or blocked as soon as the purpose of storage no longer applies. Data may be retained longer where required by EU or national law. It is blocked or erased once any prescribed retention period expires, unless further storage is needed for the conclusion or fulfilment of a contract.

2. Provision of the Website and Creation of Log Files

2.1 Description and scope

Each time our website is accessed, our system automatically collects data from the accessing computer, including:

  • Browser type and version
  • Operating system
  • Internet service provider
  • IP address
  • Date and time of access
  • The website from which the user's system accessed ours

2.2 Legal basis

Art. 6 para. 1 lit. f GDPR.

2.3. Purpose

Temporary storage of the IP address is necessary to deliver the website to the user's computer, and the address must remain stored for the duration of the session. Log files help ensure the website's functionality and the security of our IT systems; this data is not analyzed for marketing purposes. These purposes constitute our legitimate interest under Art. 6 para. 1 lit. f GDPR.

2.4 Duration of storage

Session data is deleted once the session ends. Data stored in log files is deleted after seven days at the latest, though longer storage is possible if IP addresses are deleted or anonymized so the accessing client can no longer be identified.

2.5 Right to object

Collecting this data is essential to operating the website, so users cannot object to it.