KKS Heidelberg Account Support

Data protection statement

December 18, 2023

Data protection and data security for clients and partners of our company as well as interested parties and users of our web presence is valued greatly by our company. Transparency regarding the processing of your personal data as well as the protection of your data are therefore of particular importance to us.

With this statement, we provide you with an overview of how data is collected and processed when using our webpages and what you yourself can do to improve the protection of your data, if applicable.

Controller

Universitätsklinikum Heidelberg AöR [University Hospital Heidelberg Public Body]
Koordinierungszentrum für klinische Studien (KKS) [Coordination Center for Clinical Trials]
Dr. med. Steffen P. Luntz
Berliner Straße 10
69120 Heidelberg [Germany]

Tel.: +49 6221 56 34502
E-Mail:Sekretariat.KKS@med.uni-heidelberg.de

Company data protection officer

Data protection officer of the hospital:
Universitätsklinikum Heidelberg [University Hospital Heidelberg]
Datenschutzbeauftragte [Data protection officer]
Im Neuenheimer Feld 672
69120 Heidelberg [Germany]

Telephone: +49 6221 56 7036
E-Mail:datenschutz@med.uni-heidelberg.de

Contact in case of questions, complaints, assertion of your rights

In case there are questions about the system, the registration and matters other than data protection, you can contact us at any time using the following address:

Universitätsklinikum Heidelberg [University Hospital Heidelberg]
Koordinierungszentrum für klinische Studien (KKS) [Coordination Center for Clinical Trials]
eCRF Account-Support
Berliner Straße 10
69120 Heidelberg [Germany]

Telephone: +49 6221 56 36824
E-mail: Account-Support.KKS@med.uni-heidelberg.de


In case of questions on data protection, complaints or assertion of your data protection rights, you can
contact us at any time using the following address:

Universitätsklinikum Heidelberg [University Hospital Heidelberg]
Datenschutzbeauftragte [Data protection officer]
Im Neuenheimer Feld 672
69120 Heidelberg [Germany]
Telephone: +49 6221 56 7036

E-mail: datenschutz@med.uni-heidelberg.de

What is personal data

Personal data includes all information that refers to an identified or identifiable natural person. This means that it is crucial whether the collected data can be used to establish a link to your person. This includes information such as your name, address, telephone number and e-mail address. Information that cannot be connected directly with your proper identity, - such as favorite websites or the number of users of a site - does not constitute personal data.

How do we collect and process data about your person

When you visit our websites, our webservers by default temporarily store the following information for the purpose of system safety: the connection data of the inquiring computer, our websites you are visiting, the date and duration of the visit, the identification data of the browser used the type of operating system, as well as the website your visiting us from. Personal data beyond this, such as your name, address, telephone number or e-mail address is not collected, unless you provide this information voluntarily, e.g. in line with a registration, survey, competition, complete a contract or request for information.

How do we use data about your person, how do we forward it

If the internet offer provides the possibility of entering personal or business data (e-mail addresses, names, addresses), the disclosure of this data on the part of the user takes place on an explicitly voluntary basis. E-mails are transmitted with a contact form. When you send us this type of message, your personal data will only be collected to the extent necessary for a response. The e-mail is transmitted in encoded form.

We will use the personal data you provided for purposes of the technical administration of websites and to meet your wishes and requirements, in other words, usually to finalize the contract concluded with you or to answer your inquiry. At the end of the study, this data will furthermore be passed on to the respective sponsor together with the study data.


Your personal data will not be transmitted, sold or otherwise passed on to third parties, unless this is necessary for the purposes of finalizing the contract, or you gave your explicit consent.

Once a consent has been given, it can be withdrawn at any time with effect for the future.

How long will your data remain stored

In principle, we store all information you pass on to us until the respective, e.g. contractual purpose has been fulfilled. E-mail correspondence with the account support will be stored until the end of the study and beyond, depending on the legally stipulated duration.

When is your data deleted

The deletion of the stored personal data takes place in case you withdraw your consent to storage, once the knowledge of the data is no longer needed to fulfill the purpose pursued by the storage or if the storage is inadmissible because of other legal reasons. Data for billing and accounting purposes and data associated with our RDE system will be deleted after the legal obligation to keep and retain records has expired.

What steps do we take to make processing safe

Our company takes all necessary technical and organizational safety measures to protect your personal data from loss and misuse. Thus, your data will be stored in a secure operating environment that is not accessible to the public.

SSL and TLS encoding

For safety purposes and for to protect the transmission of confidential contents, such as orders or inquiries you send to us as site operators, this page uses SSL or TLS encoding. You can recognize an encrypted connection from a change in the address line of the browser from „http://“ to „https://“ and the padlock icon in your browser line.

When the SSL or TLS encoding is activated, the data you are transmitting to us cannot be read by third parties.

If you would like to contact our company by means of e-mail, we would like to point out that the confidentiality of the transmitted information is not ensured. The content of e-mails can be viewed by third parties. We therefore recommend that you send us confidential information only by postal route.

Legal bases for data processing

If we obtain consent from the data subject for processing operations of personal data, § 6 (1a) EU General Data Protection Regulation (GDPR) serves as legal basis.

When processing personal data that is necessary for fulfilling a contract and the party to the contract is the data subject, § 6 (1b) GDPR serves as legal basis. This also applies to processing operations that are necessary for carrying out pre-contractual measures.

If personal data must be processed to fulfill a legal obligation our company is subject to, § 6 (1c) GDPR serves as legal basis.

In case vital interests of the data subject or another natural person necessitates the processing of personal data, § 6 (1d) GDPR serves as legal basis.

If the processing is necessary to protect a legitimate interest of our company or a third party and if the interests, fundamental rights and fundamental freedoms of the affected persons do not outweigh the first interest, § 6 (1f) GDPR serves as legal basis for the processing. Legitimate interests are most notably the securing of the operation and safety of the website, the investigation of the way the website is used by visitors and the simplification of the use of the website.

These are your data protection rights

Within the scope of the applicable legal regulations, you, at any time, have the right to free-of-charge information about your personal data, its origin and potential recipients and the purpose of data processing (§ 15 GDPR), and, if applicable, the right to revision of incorrect data § 16 GDPR), deletion of this data (§ 17 GDPR), the right to limit the processing in accordance with § 18 GDPR, to objection (§ 21 GDPR) as well as the right to data portability of the data you provided in accordance with § 20 GDPR). With regard to the right to information and the right to cancellation, the limitations according to §§ 34 and 35 of the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) apply. In addition, in case of violations of the data protection act, you are entitled to the right of appeal with the competent regulatory authority (§ 77 GDPR in conjunction with § 19 BDSG). The foreign regulatory authority in matters of data protection is the state data protection officer of the federal state our company is located in. A list of data protection officers as well as their contact data can be accessed with the following link:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

How you can withdraw consent to data processing once it has been provided

A number of data processing operations are only possible with your express consent. You can withdraw an already provided consent at any time. An informal communication per e-mail is sufficient for this purpose. The lawfulness of the data processing remains unaffected from the withdrawal until the time of withdrawal.

Informational e-mails

As part of setting up access to our RDE system (e.g. clincase), you will receive e-mails for your information at irregular intervals (e.g. about system failures, access information, changes of eCRFs of the relevant databases/studies, etc.). It is mandatory that these e-mails are linked to the access to our RDE system and serve the data safety of the respective databases/studies. If you do not agree with receiving these e-mails, we will not be able to set up access to our RDE system for you or we have to deactivate your access to our RDE system.

Registration

The data subject has the option of registering on the website of the controller by providing personal data. Which personal data will hereby be transmitted to the controller, is a result of the respective input mask that is used for the registration. The personal data entered by the data subject will be collected and stored only for internal use with the controller and for own purposes. The controller can initiate the transmission to one or several processors, such as a parcel service, who will also use the personal data only for internal use that is attributed to the controller.

By registering on the website of the controller, the IP address assigned by the Internet Service Provider (ISP) of the data subject, the data as the well as the time of registration is stored. Storage of this data takes place in view of the fact that this is the only way to prevent the misuse of our services, and this data makes it possible, when needed, to clarify offenses and copyright infringements. In this respect, storage of this data is necessary as a safeguard for the controller. The transmission of this data to third parties generally does not take place if there is no legal obligation for transmission or the transmission serves criminal or legal prosecution.

Upon request, the controller provides information to all data subjects at any time as to which personal data of the data subject is stored. Furthermore, the controller revises or deletes personal data upon request or instructions of the data subject, if this is not contrary to the legal obligation to keep and retain records. The data protection officer specified by name in the data protection statement and the total number of employees of the controller are available as contact persons for the data subject in this context.

Changes to the data protection statement

Changes to this information on data protection can be made that will be announced on this page in due time.