Applicant management as part of the allocation of study places

Data protection information in accordance with Article 13 (1) and (2) of the General Data Protection Regulation (GDPR ) on the processing of personal data in the context of the application for and allocation of study places at the Zittau/Görlitz University of Applied Sciences (HSZG).

Person responsible for data processing

Zittau/Görlitz University of Applied Sciences
Theodor-Körner-Allee 16
02763 Zittau

Please send inquiries regarding data processing to
Your request will be forwarded to the responsible department and processed promptly.

Data protection officer of the controller

The data protection officer can be contacted at

DID Dresdner Institut für Datenschutz
Hospitalstraße 4
01097 Dresden

Web.: www.dids.de
Phone: +49 (0)351 / 655 772 - 0
E-mail:

Purposes of data processing

The HSZG processes your personal data as part of your application for a study place for the purposes of admission, enrolment and further teaching and study organization.

Legal basis

The data in connection with an application is processed on the basis of § 15 Para. 1 No. 1 SächsHSG in conjunction with § 2 SächsHSPersDatVO.
§ 2 SächsHSPersDatVO processed.

The processing of personal data for the provision and improvement of the website (application portal) as well as for the detection and correction of errors is based on Art. 6 para. 1 lit. e GDPR.

Anyone who uses the login area is assigned a user account. The processing of personal data takes place on the basis of the user relationship and the existing contractual relationships in accordance with
Art. 6 para. 1 sentence 1 lit. b) GDPR.

Categories of personal data

In addition to the data entered into the applicant portal by your applicants for the award decision, the HSZG processes the following personal data for the provision of its website (applicant portal).

 

Processing of log data (access data)

When using the website, the following information is collected to detect errors

  • access to pages
  • whether the access was successful
  • the time
  • the volume of data transferred
  • the IP address of the requesting computer

The IP address is stored in abbreviated form so that identification is not possible or only possible with an effort that is disproportionate to the gain in knowledge of the requesting connection.

 

Account

In order to use non-public areas of the website, such as applicant and alumni management, you must have a user account. The following personal data is required to create an account: Title, surname, first name, e-mail address and a password of your choice.

Without providing this data in full, no user account can be assigned and therefore the non-public areas of the website cannot be used. The processing is carried out on the basis of Art. 6 para. 1 e) GDPR for the purpose of restricting access to non-public, protected parts of the Zittau/Görlitz University of Applied Sciences website to registered users. The account data will not be transmitted to third parties. The deletion takes place automatically upon explicit deletion request of the user at the latest upon exmatriculation/leaving the university or if misuse is detected.

 

Automatic login for smartphones

When using the website with an account, it is possible to remain logged in with a smartphone. For this purpose, a cookie with the encrypted access data is stored on the end device. At the same time, a digital fingerprint of the end device is stored on the server. The digital fingerprint is calculated from several parameters. The following information is evaluated for this purpose.

  • SCREEN_SIZE_AND_COLOR_DEPTH (screen size and color depth)
  • DEVICE_ATTRIBUTES: id, model, vendor, build, device_os_version (attributes of the end device used: model number [not IMEI], model name, manufacturer, series, version of the operating system used)
  • ACCEPT_LANGUAGE (language setting)
  • TIME_ZONE (time zone)
  • DEVICE_TYPE (device type)
  • BROWSER_TYPE (program used for Internet access)

 

Cookies

This application uses cookies, i.e. small files with short texts for technical processing. Without cookies, for example if they have been deactivated in the browser, it is not possible to use this application in full. Only essential cookies are used. Essential cookies enable basic functions and are necessary for the proper functioning of the website. They cannot be deselected and are listed below.

 

Cookie name Content (example) Purpose Valid until
JSESSIONID R5E0F8CC126518A2FF92F4614XYZABC Identification of the user's current session At the end of the session
lastRefresh 1406342235039 Stamp of the last update or the last call of this application At the end of the session
sessionRefresh 0 Enables the client-side display of the (remaining) runtime of the current user session At the end of the session
download-complete The presence of the cookie indicates to the browser that an (internal) file download has been completed. At the end of the session
cs.sys.hisinoneAutoLogin abc1234___::___def5678 If automatic login is active, an access key is saved here. For logging out on the respective device. The server-side data can also be deleted for other devices in the device management.
cs.sys.requestPerformance a4d76e62-eb45-44df-ad7e-19b612f36956 If the performance analysis is active, an assignment is made here between the server-side and client-side processing of the same browser request. At the end of the session

 

Processing of log data for the analysis of user behavior

In order to optimize the website, the HSZG automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. The following data is processed

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with data from other sources.

Receiver

Log data, account data and data from automatic logins from smartphones are not transmitted.

Storage duration

The stored log data is automatically deleted after 7 calendar days.
If the applicant identity (account data) is not used for the application, if the application is unsuccessful or if no enrolment takes place for any other reason, the data will be deleted 9 weeks after the start of the semester as part of the semester clean-up. Account data will be deleted automatically upon the user's express request for deletion, at the latest upon exmatriculation/leaving the university or if misuse is detected. If the automatic login with smartphone is no longer used for 4 weeks, it is automatically deleted. In addition, the user can revoke the automatic login at any time via the settings in his/her account, e.g. if the smartphone has been lost. By storing the above data for the respective end device, the user can also keep several of his/her end devices separate in his/her account and, if necessary, deactivate the automatic login for individual end devices.

Rights of the data subjects

As a person affected by the processing of your personal data, you have the following rights if the legal requirements are met.

  • You have the right to information about the processing of your personal data(Art. 15 GDPR).
  • You have the right to rectification of inaccurate personal data concerning you (Art.16 GDPR)
  • You have the right to erasure of your personal data (Art.17 GDPR).
  • You have the right to request the restriction of the processing of your personal data (Art.18 GDPR)
  • You have the right to data portability of your personal data (Art.20 GDPR)
  • You have the right to object to the processing of your personal data at any time (Art.21 GDPR)
  • You have the right to withdraw your consent to data processing at any time. The lawfulness of the data processing carried out on the basis of your consent until revocation remains unaffected(Art. 13 para. 2 lit. c GDPR).
  • You have the right to lodge a complaint with the Saxon data protection officer
    (for contact details, see https://www.saechsdsb.de/kontakt).

Provision of personal data

According to Art. 13 (2) lit. e GDPR, the provision of personal data of applicants is not required by law.

However, without the complete provision of the account data, no user account can be assigned and thus the non-public areas of the website cannot be used. Without the complete provision of the personal data required for admission and enrolment, an applicant cannot be considered for the allocation of a study place.

Decision-making and profiling

No automated decision-making or profiling in accordance with Art. 22 GDPR is carried out when allocating study places.