Privacy Policy

WHU - Otto Beisheim School of Management, Burgplatz 2, 56179 Vallendar ("WHU") is happy to welcome you on our website.

With this privacy policy, WHU fulfils its existing legal obligation to provide information in accordance with Art. 13 of the General Data Protection Regulation ("GDPR") with regard to the processing of personal data on our website. In the following, we therefore explain which of your personal data we process and in what way. Please contact us if you have any further questions. You will find our contact details below and at the end of this page.

General information about the processing of personal data

Responsible according to Art. 4 (7) of the EU General Data Protection Regulation ("GDPR") is WHU - Otto Beisheim School of Management, Burgplatz 2, 56179 Vallendar (see our imprint, e-mail: datenschutz(at)whu.edu).

You can contact our data protection officer with the data provided at the end of this Privacy Policy.

Personal data

Personal data is any information that relates to an identified or identifiable natural person. A natural person is considered to be identifiable if, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special features, that expresses the physical, physiological, genetic, mental, economic, cultural or social identity of this natural person, can be identified. This includes, for example, information such as your name, address, telephone number, language, location, e-mail address, bank details and date of birth.

Processing of personal data

A processing of personal data applies to any operation performed with or without the aid of automated procedures or in any series of procedures related to personal data. In particular, data processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

We process personal data in accordance with the specifications and conditions described below within the framework of automated processing based on a relevant legal authorisation. The scope of the processing of your personal data is limited by the purposes described in each case.

Automated decision-making in individual cases including profiling according to Art. 22 GDPR does not take place.

If we use a processor for the processing of your personal data, we conclude a data processing contract with them, which fulfills all the requirements of Art. 28 GDPR.

Purpose of processing personal data when visiting our website

In the case of merely informative use of the website, for example, if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you visit our website, we collect the following data that is technically necessary for us to show you our website and to ensure the stability and security (legal basis is Art. 6 para. 1 sentence 1 lt. f GDPR):

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the requirement (concrete page)
  • Access Status / HTTP status code
  • Transmitted amount of data
  • Website that the request comes from
  • Browser
  • Operating system and its interface
  • Language and version of the browser software.

In addition to the purely informative use of our website, we offer various services which you can use if you are interested. For this purpose, you will generally have to provide additional personal data which we use to provide the respective service and to which the aforementioned data processing principles apply. We present these to you in this privacy policy.

Use of Cookies

In addition to the above-mentioned data, cookies are stored on your computer when you use our website, if you give us your consent.

Cookies are small text files that are stored on your hard drive in accordance with the browser you are using and through which certain information flows to the site that sets the cookie. Cookies cannot execute programs or transfer viruses to your computer. They serve to make the Internet offer altogether more user-friendly and effective.

On the one hand we use technically necessary cookies. These cookies are necessary for a good functionality of our website and cannot be switched off in our system. The legal basis is Art. 6 para. 1 sentence 1 lt. f GDPR ("legitimate interest"). However, you can of course configure your browser settings according to your wishes and also reject such technically necessary cookies. Please note that you will not be able to use our website in that case.

Otherwise, Art. 6 para. 1 sentence 1 lt. a GDPR is the legal basis for the use of cookies ("consent"). You can differentiate whether you give us consent for all cookies, only for certain types of cookies (e.g. functional cookies, performance cookies, advertising/tracking cookies) or no consent at all.

This consent is voluntary. You can refuse it without giving reasons and without having to fear any disadvantages. You can also revoke this consent at any time with future effect here, without having to fear any disadvantages. However, we would like to point out that if you do not give your consent or if you revoke it, you may not be able to use all the functions of this website to their full extent.

We will also provide you with further information on the use of cookies in the following sections if cookies are used.

You will also find detailed information in our cookie policy, which you can access via the following link.

Integration of Google Maps

On this website we use Google Maps. This allows us to show you interactive maps directly on the website and enable you to conveniently use the map feature.

By visiting the website, Google receives the information that you have accessed the corresponding subpage of our website. Furthermore, the data mentioned above in this declaration under "Purpose of processing personal data when visiting our website" will be transmitted. This is done regardless of whether Google provides a user account that you are logged in to, or if there is no user account. When you're logged in to Google, your data will be assigned directly to your account. If you do not wish to be associated with your profile on Google, you must log out before activating the button. Google stores your data as user profiles and uses them for the purposes of advertising, market research, and / or tailor-made website design. Such an evaluation is done (even for users who are not logged in) to provide appropriate advertising and to inform other users of the social network about their activities on our website. You have the right to object to the formation of these user profiles, whereby you must contact respective provider to exercise this right.

Google also processes your personal data in the USA. Before giving your consent in accordance with Art. 49 para. 1 a GDPR, we would like to point out in particular that in the USA there may not be an adequate level of data protection without a decision on appropriateness and without suitable guarantees, as data protection laws do not comply with the provisions of the GDPR and in particular the rights of data subjects may not be enforceable.

The above will only take place if you give us your consent. The legal basis is Art. 6 para. 1 sentence 1 lt. a GDPR ("Consent"). This consent is voluntary. You can refuse it without giving reasons and without having to fear any disadvantages. You can also revoke this consent at any time with future effect here, without having to fear any disadvantages.

Further information on the purpose and scope of data collection and processing can be found in the provider's data protection declarations. There you will also find further information on your rights in this regard and setting options to protect your privacy: www.google.de/intl/de/policies/privacy.

Contact form

When you contact us by e-mail or through a contact form, we will collect the personal information you provide (e-mail address, first name, last name and, if applicable, your telephone number) to answer your questions. We will delete data for these purposes after storage is no longer required, or limit the processing if there are statutory retention requirements.

The legal basis is Art. 6 para. 1 sentence 1 lt. f GDPR.

Use of Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies", text files that are stored on your computer and that allow an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted and stored at a Google server in the USA. However, if IP address anonymization is activated on this website, your IP address will be shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. It is only in exceptional cases that the full IP address will be sent to a Google server in the US and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website usage and internet usage to the website operator. 

The IP address provided by Google Analytics as part of Google Analytics will not be merged with other Google data.

This website uses Google Analytics with the extension "_anonymizeIp()". This allows IP addresses to be further processed in a shortened form, thus excluding the possibility of personal references. If the data collected about you contains a personal reference, this is immediately excluded and the personal data is immediately deleted.

Google also processes your personal data in the USA. Before you give your consent in accordance with Art. 49 para. 1 a GDPR, we would like to point out in particular that in the USA there may not be an adequate level of data protection without a decision on appropriateness and without suitable guarantees, as data protection laws do not comply with the provisions of the GDPR and in particular the rights of data subjects may not be enforceable.

The above will only take place if you give us your consent. The legal basis is Art. 6 para. 1 sentence 1 lt. a GDPR ("Consent"). This consent is voluntary. You can refuse it without giving reasons and without having to fear any disadvantages. You can also revoke this consent at any time with future effect here, without having to fear any disadvantages.

We use Google Analytics to analyse and regularly improve the use of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user.

Third Party Information: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001, Terms of Use: www.google.com/analytics/terms/de.html, Privacy Policy: www.google.com/intl/de/analytics/learn/privacy.html, and the Privacy Policy: www.google.de/intl/de/policies/privacy.

Duration of data processing

The maximum duration of storage depends on the purpose of the data processing. The duration of storage depends in particular on the period for which the processing is necessary to fulfil the purpose or to comply with legal obligations. The statutory storage obligations, in particular in accordance with § 257 HGB and § 147 AO (6 or 10 years), remain unaffected.

Recipient of personal data

We transmit your data to the specialist departments within WHU, as far as this is necessary and legally permissible.

If we use a commissioned processor to process your personal data, we conclude a commissioned processing contract with this processor, which fulfils all the requirements of Art. 28 GDPR.

Your personal data will not be transferred beyond this, unless this is expressly stated in this document.

Place of data processing

The processing of your personal data by us takes place in Germany or in member states of the European Union, unless a transfer of your personal data to states outside the member states of the European Union (so-called third countries) or to other international organisations has been described in the cases listed above, in which case the necessary requirements under Art. 44 ff. GDPR are observed. 

Safety / Technical and organizational measures

We take all necessary technical and organizational measures in accordance with the provisions of Articles 24, 25 and 32 GDPR in order to protect your personal data from misuse and loss, destruction, access, modification or disclosure by unauthorized persons.

In this way, we comply with the legal requirements for pseudonymizing and encrypting personal data, the confidentiality, integrity, availability and resilience of systems and services related to processing, the availability of personal data and the ability to rapidly restore them in the event of a physical or technical incident as well as the establishment of procedures for periodic tests, assessment and evaluation of the effectiveness of technical and organizational measures to ensure the safety of processing.

Furthermore, we also follow the requirements of Art. 25 GDPR with regard to the principles of "privacy by design" (data protection by means of technical design) and "privacy by default" (data protection by means of privacy-friendly default settings).

Your rights

You have a right to free information (right of access) about your personal data as well as, subject to the relevant conditions, a right to rectification, blocking and eraser of your data, to the restriction of processing, to data portability as well as a right of objection.

Insofar as we base the processing of your personal data on the weighing of interests, you can object to the processing. This is the case if the processing is in particular not necessary for the fulfilment of a contract with you. If you do so, please explain why we should not process your personal data as we have done. In the event of your justified objection, we will examine the facts of the case and will either stop or adapt the data processing or show you our compelling reasons worthy of protection on the basis of which we will continue the processing.

You also have the opportunity to complain to a competent supervisory authority (e.g. Landesbeauftragter für den Datenschutz und Informationsfreiheit Rheinland-Pfalz, Prof. Dr. Kugelmann, Hintere Bleiche 34, 55116 Mainz, Germany).

Please contact us or our external data protection officer if you have any questions regarding the processing of your personal data, as well as questions relating to the above-mentioned rights and their assertion, or if you have any suggestions:

Frau Susanne Kamm
Dr. Dornbach Consulting GmbH
Anton-Jordan-Straße 1 
56070 Koblenz
E-Mail: datenschutz(at)whu.edu
Tel.: 0261 9431-434

As of: July 2020

The English version only serves informational purposes. The German version is legally binding.