Data protection
In accordance with the duty to inform
when collecting personal data (Art. 13 and Art.14 DSGVO)
1. Designation of the Processing Activity
Webshop THD
2. Name and Contact Details of the Responsible Person
The Deggendorf Institute of Technology is a corporation under public law. It is represented by the president Prof. Dr. rer. nat. Peter Sperber.
Deggendorf Institute of Technology
Dieter-Görlitz-Platz 1
94469 Deggendorf
3. Contact Details of the Data Protection Officer
Data Protection Officer of the Deggendorf Institute of Technology:
Prof. Dr. Herbert Fischer
Deggendorf Institute of Technology
Dieter-Görlitz-Platz 1
94469 Deggendorf
e-mail: datenschutz@th-deg.de
4. Purposes and Legal Bases of Processing
4.a) Purposes of Processing:
Collection, registration and storage of customer data to process for being able to process orders from the shop.
For the administration of products, product categories, prices, stock, product groups including product images.
4.b) Legal Bases of Processing
The necessity for the execution of a contract is given, for the execution of the purchase contract Art. 4 para. 1b DGSVO
The permission of the users is existent, storage of data for the customer’s account Art. 6 para. 1a DSGVO
The processing due to legal obligation is possible, Art. 6 para 1 lit. c DSGVO in combination with Art. 5 para. 1 f DSGVO / Art. 32 DSGVO Guarantee of the System’s Security, Error Diagnostics and Fault Repair, Concerning Log Data
The permission of the user is existent, for personalised product images Art. 4 para. 1a) DSGVO
5. Recipient or Categories of Recipients of Personal Data
Your personal data will be disclosed to the following bodies, in so far as the disclosure is necessary in the respective case:
Internal bodies: Communication and Marketing, Finances, IT Service
External bodies: State Office of Finances
6. Forwarding of Personal Data to a Third Country
A forwarding to a third country does not occur.
7. Duration of the Storage of Personal Data
After collection, your data will be stored as long as necessary for the respective accomplishment of the task – if applicable, in compliance with the statutory retention period. The individual periods are defined and constituted in the DIT’s data privacy management system.
Contact details:
The contact details/customer data of the person concerned will be deleted from the shop’s customer database upon revocation of the consent for the collection of data.
Log data:
The log data will be deleted from the system after a period of 30 days.
Billing information:
Concerning the contact details on invoices for procurements from third-party funds:
Invoices for procurements from third-party funds are subject to a statutory retention period of 30 years.
Concerning contact details on invoices:
Invoices are subject to a statutory retention period of 10 years.
Image/video and audio data:
Personalised product images of the person concerned will be deleted from the system upon revocation of the consent.
8. Rights of the Concerned
According to the General Data Protection Regulation, you are entitled with the following rights:
If your personal data is processed, you have the right to receive information about the data stored about your person (Art. 15 DSGVO).
If incorrect personal data is processed, you have a right to rectification (Art. 16 DSGVO).
If the statutory requirements are given, you may request the deletion or restriction of processing as well as object to the processing of personal data (Art. 17,18 and 21 DSGVO)
If you have agreed to the data processing or if a contract for data processing exists and the processing of data is carried out with the help of automated procedures, you may have a right to data portability (Art. 20 DSGVO).
Should you make use of your above-mentioned rights, a public authority will examine whether the legal requirements are fulfilled for doing so.
Furthermore, there is a right of complaint to the
Bayerische Landesbeauftragte für den Datenschutz
Wagmüllerstraße 18
80538 München
phone: 089 212672-0
e-mail: poststelle@datenschutz-bayern.de
9. Right of Revocation of Consent
If you have agreed to the processing by the Deggendorf Institute of Technology via respective declaration, you can revoke this consent at any time for the future. The lawfulness of the data processing carried out on the basis of the consent until its revocation is not affected by the revocation.
10. Obligation to Provide Data
You are not obliged to provide your data. The collection is carried out on a voluntary basis. However, your data is needed to process your application for the order in the DIT shop. If you do not provide the required data, your application cannot be processed.
11. Data that Is Not Collected Directly from You
Personalised product images: Image data is used on the basis of signed consent forms.
12. Cookies
Partly, web pages use so-called Cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies make our service more user-friendly, effective and safe. Cookies are small text files which are stored on your computer and saved by your browser.
Most of the Cookies used by us are so-called “Session-Cookies”. They are automatically deleted after the end of your visit. Other Cookies are saved on your end device until you delete them. Those Cookies allow us to recognize your browser the next time you visit.
You can set your browser so that you are informed about the setting of Cookies and only allow Cookies in individual cases, exclude the acceptance of Cookies for certain cases or in general, and activate the automatic deletion of Cookies when closing the browser. If Cookies are deactivated, the functionality of this website may be limited.
The following Cookies are used by our shop:
Name of the Cookie |
Function |
Storage Duration |
__csrf_token-1 |
Is needed for the validation of customer data. |
Is bound to the browser session. |
session-1 |
Identifies the current session, browser and its shopping cart. |
Is bound to the browser session. |
cookiePreferences |
The information about which Cookies the customer wants are stored in a serial string. |
The information is stored for half a year. |
slt |
Enables us to recognize the customer when he returns to the shop, even if the session is expired. |
Is stored for one year or is deleted manually via logout by the customer. |
sUniqueID |
Is responsible for the assignment of the note list and is used when using the note list. |
Is stored for one year. |
x-ua-device |
Is used for the identification of the end device used, e. g. for the correct display of the shop. |
Is bound to the browser session. |
allowCookie |
Saves the Cookie settings of the shop customer. |
Does not expire. |
timezone |
The time zone is saved, e. g. for time specifications in e-mails. |
|
PHPSESSID |
PHP sessions that are used to assign the current session (shopping cart, etc.). |
Is bound to the browser session. |
csrf |
All CSRF Cookies are used to validate the form entries in order to prevent XSS attacks. |
Is bound to the browser session. |
sw-cache-hash |
Technical Cookie for the cache functionality. |
|
cookie-preference |
For the customer’s Cookie preferences if they are configurated in the offcanvas. |
The information is stored for half a year. |
sw-states |
Technical Cookie for the cache functionality. |
|
Status as of 16 September 2021