We take data protection seriously

Protecting your privacy when processing personal data is a matter of great importance to us. When you visit our website, our web servers automatically record your IP address, the website from which you are visiting us, the pages you view on our site, and the date and duration of your visit. This information is strictly necessary for the technical transmission of the web pages and for secure server operation. This data is not analysed on a personalised basis.

The processing of personal data – such as a data subject’s name, address, email address or telephone number – is always carried out in accordance with the General Data Protection Regulation and in compliance with the state-specific data protection regulations applicable to the Ostbayerische Technische Hochschule Regensburg. Through this privacy policy, the University aims to inform the public about the nature, scope and purpose of the personal data we collect, use and process. Furthermore, this privacy policy informs data subjects of their rights.

As the data controller, the Ostbayerische Technische Hochschule Regensburg has implemented numerous technical and organisational measures to ensure the most comprehensive possible protection of the personal data processed via this website. Nevertheless, internet-based data transmissions may, in principle, be subject to security vulnerabilities, meaning that absolute protection cannot be guaranteed. For this reason, any data subject is free to provide us with personal data via alternative means, such as by telephone.

Definitions

“Personal data”

This refers to any information relating to an identified or identifiable natural person (hereinafter referred to as the ‘data subject’); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

‘Processing’

This includes any operation or set of operations which is carried out on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or any other form of making available, the alignment or combination, the restriction, erasure or destruction;

Further definitions are set out in Article 4 of the GDPR.

The party responsible for data collection on this website is:

Ostbayerische Technische Hochschule Regensburg
Seybothstraße 2
93053 Regensburg
Telephone +49 (0) 941 943 02
Email: praesident(at)oth-regensburg.de

The Ostbayerische Technische Hochschule Regensburg is a public-law body pursuant to Article 1(1), first sentence, of the Bavarian Higher Education Innovation Act (BayHIG).
The Ostbayerische Technische Hochschule Regensburg is legally represented by the Chair of the University Executive Board, President Prof. Dr Ralph Schneider.
Further details and information on the supervisory authority can be found in the imprint.

The data protection officer of the data controller is:

Projekt 29 GmbH & Co. KG
Ostengasse 14
93047 Regensburg
Tel. 0941-2986930
E-Mail:datenschutz(at)oth-regensburg.de

Please note that emails sent to this address are processed in a ticketing system operated by Projekt29 GmbH to ensure prompt handling.

Any data subject may contact our Data Protection Officer directly at any time with any questions or suggestions regarding data protection.

When you visit our website, the following information is stored in the server log files by default:

  • the page from which the file was requested – Referrer URL
  • the name of the file
  • the date and time of the request
  • a description of the type of web browser used / browser version
  • the operating system installed, the operating system’s language and the screen resolution
  • the hostname of the accessing computer
  • the amount of data transferred in each instance
  • the access status / HTTP status code (i.e. whether the file was transferred or could not be found, etc.)
  • the IP address used and its location.

The stored data is analysed solely to ensure the proper operation and security of the website. This data is not combined with other data sources, nor is it analysed for the purpose of drawing conclusions about your identity.

We process the data mentioned for the following purposes:

  • To ensure that the website connects properly and without disruption,
  • Ensuring the website can be used,
  • Evaluating system security and stability

The legal basis for the processing is Article 6(1), first subparagraph, point (e) GDPR in conjunction with Article 4(1) of the Bavarian Data Protection Act (BayDSG). The processing is necessary in order to fulfil the public service mandate entrusted to us to operate a secure website. You may visit our website without providing any personal details. Under no circumstances do we use the data collected for the purpose of identifying you personally. The server log files collected in connection with the use of the website are stored for a period of 7 days for reasons of IT security, in particular to defend against attempted attacks, and are subsequently deleted automatically.

Cookies

The website of the Ostbayerische Technische Hochschule Regensburg uses cookies.

Cookies are small text files that your browser automatically creates and stores on your device (laptop, tablet, smartphone, etc.) when you visit our website.

Cookies do not cause any damage to your device and do not contain any viruses, Trojans or other malware. The cookie stores information relating to the specific device being used. However, this does not mean that we thereby gain direct knowledge of your identity.

By using session cookies, the data controller can provide users of this website with a user-friendly service that would not be possible without setting cookies.

Without your consent, we use only technically necessary cookies. The storage of these cookies on your device is permitted without consent under Section 25(2)(2) of the TDDDG, as it is absolutely necessary for the provision of the service you have expressly requested. The subsequent processing of the data is based on Article 6(1), first subparagraph, point (e) GDPR in conjunction with Article 4(1) of the Bavarian Data Protection Act (BayDSG).

We only use personal data cookies to improve our website, provide additional services or for marketing/advertising purposes with your consent. On your first visit, you may voluntarily consent to tracking or analytics via the cookie banner that appears on the screen. Where applicable, your data may be passed on to partners or third-party providers. These cookies will only be stored if you explicitly consent to this; the legal basis in such cases is your consent in accordance with Section 25(1) of the German Telemedia Act (TDDDG) and Article 6(1), first subparagraph, point (a) GDPR.

You can change your cookie settings at any time here:

Change cookie settings

Contact form

If you send us enquiries via the contact form, the details you provide in the enquiry form – including the contact details you have provided there – will be stored by us for the purpose of processing your enquiry and in the event of any follow-up questions. We will not pass on this data without your consent.

The legal basis for the processing is Article 6(1), first subparagraph, point (e) GDPR in conjunction with Article 4(1) of the Bavarian Data Protection Act (BayDSG); the processing of enquiries forms part of the university’s duties. If your enquiry is aimed at initiating or fulfilling a contract, Article 6(1), first subparagraph, point (b) GDPR applies. You may object to the processing pursuant to Article 21 of the GDPR; an informal message to datenschutz@oth-regensburg.de is sufficient. In this case, we may not be able to process your enquiry further.

The data you enter in the contact form will remain with us until you request its deletion or the purpose for storing the data no longer applies (e.g. once your enquiry has been fully processed). Mandatory legal provisions – in particular retention periods – remain unaffected.

Communication by email

At your request, we will also communicate with you via email. The legal basis for this is Article 6(1), first subparagraph, point (e) GDPR in conjunction with Article 4(1) of the Bavarian Data Protection Act (BayDSG). Please note that emails sent via the internet are generally unencrypted and third parties may, under certain circumstances, gain access to them. Upon request, we will provide you with an encrypted transmission channel for the transmission of confidential content. Emails may form part of an administrative procedure. In this case, they will be retained – including the email address – in accordance with the retention and disposal regulations applicable to the university, in particular in accordance with budgetary and administrative law provisions and the Bavarian Archives Act.

Once the retention period has expired, a review is carried out towards the end of the calendar year to determine whether there is still a need for the data to be processed. If this is not the case, the data will be deleted.

Newsletters and mailing lists

On various pages of our website, we offer you the opportunity to subscribe to a newsletter or a topic-specific mailing list.
To subscribe, we require your email address and, where applicable, further information. Any data that is not strictly necessary is clearly marked as such on the registration forms and is provided on a voluntary basis.
Please refer to the relevant registration form for details of which specific details are collected and which of these are mandatory.

Registration takes place via the so-called double opt-in procedure. After submitting the form, you will receive an email asking you to confirm your registration. Only after this confirmation will we add you to the mailing list. If no confirmation is received, we will automatically delete your registration details after 30 days at the latest. As proof of your registration, we store the time of registration and confirmation, the IP address used, and the wording of the declaration of consent you provided.
We process your data in order to send you the information you have requested. The legal basis for this is your consent pursuant to Article 6(1), first subparagraph, point (a) GDPR. You may withdraw your consent at any time with effect for the future. To do so, simply click the unsubscribe link at the end of each newsletter email or send an informal message to the contact address provided in the newsletter. The lawfulness of the processing carried out up to the point of withdrawal remains unaffected.

Job application portal

If you send us your application documents, we will use them solely for the purpose of assessing your application and will not pass your data on to third parties.

As an application usually contains sensitive personal data, we would like to point out that you are responsible for ensuring the data is encrypted if you send applications directly to us by email. For applications submitted via our careers portal, encryption is implemented and guaranteed by the system.

Application data is stored and managed separately from other data records and is used exclusively for the purpose of selecting candidates. If an employment contract is concluded, the necessary data from the application process is transferred to the personnel file.

If no employment contract is concluded, the application documents will be automatically deleted no later than six months after notification of the rejection decision, provided that no other legitimate interests of the data controller preclude such deletion or the applicant has expressly consented to the extended storage and retention of their application (applicant pool).

The legal basis for the processing is Article 6(1), first subparagraph, point (b) GDPR in conjunction with Section 26(1), first sentence, of the BDSG (decision on the establishment of an employment relationship). Insofar as your application contains information relating to special categories of personal data – such as a severe disability – the processing is based on Article 9(2)(b) of the GDPR in conjunction with Section 26(3) of the BDSG. The retention of data following a rejection serves to defend against potential claims under the General Equal Treatment Act and is based on Article 6(1), first subparagraph, point (c) GDPR in conjunction with Section 15(4) of the AGG. Inclusion in the candidate pool takes place exclusively with your consent in accordance with Article 6(1), first subparagraph, point (a) GDPR.

Plugins and tools

Matomo

We use the open-source software Matomo to analyse and statistically evaluate website usage. Cookies are used for this purpose. The information generated by the cookie regarding website usage is transmitted to our servers and compiled into pseudonymous usage profiles. The information is used to analyse website usage and to enable us to design our website in line with user needs. The information is not passed on to third parties. Under no circumstances is the IP address linked to other data relating to the user. IP addresses are anonymised so that they cannot be traced back to an individual (IP masking).

Use of Meta Pixel (formerly Facebook Pixel)

We use the Meta Pixel on our website, provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (‘Meta’).
This enables us to track the behaviour of website visitors after they have been redirected to our website by clicking on a Facebook or Instagram advert. This allows us to evaluate the effectiveness of the adverts for statistical and market research purposes and to optimise future advertising campaigns.

The processing of data takes place exclusively on the basis of your consent in accordance with Section 25(1) of the TDDDG and Article 6(1), first subparagraph, point (a) GDPR. You may withdraw your consent at any time via our consent banner tool with effect for the future.

When collecting and transferring data to Meta, we are jointly responsible for the processing with Meta within the meaning of Article 26 of the GDPR. We have concluded an agreement with Meta regarding joint responsibility; the key provisions of this agreement are available at www.facebook.com/legal/controller_addendum. Under this agreement, Meta is responsible for ensuring that data subjects’ rights are upheld in relation to the data stored by Meta. You may, however, also exercise your rights by contacting us. The data is stored and processed by Meta in such a way that a link to the relevant user profile is possible and Meta can use the data for its own advertising purposes in accordance with the Meta Data Use Policy. This may enable Meta and its partners to display advertisements on and outside of Facebook or Instagram.

The information collected may also be transferred to Meta’s servers in the USA. For data transfers to the USA, Meta relies on its certification under the EU-US Data Privacy Framework, for which the European Commission, by decision of 10 July 2023, has determined that an adequate level of protection is provided, as well as, in addition, on the European Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR.

Further information on data processing by Meta can be found at:
https://www.facebook.com/privacy/policy/

Embedding YouTube videos

This website embeds videos from the YouTube platform. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

We use YouTube in enhanced privacy mode. According to YouTube, this mode ensures that YouTube does not store any information about visitors to this website before they watch the video. However, the enhanced privacy mode does not necessarily prevent data from being shared with YouTube partners. YouTube therefore establishes a connection to the Google DoubleClick network, regardless of whether you watch a video or not.

As soon as you play a YouTube video on this website, a connection is established with YouTube’s servers. In doing so, the YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you allow YouTube to link your browsing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.

Furthermore, after you start a video, YouTube may store various cookies on your device or use similar recognition technologies (e.g. device fingerprinting). In this way, YouTube may obtain information about visitors to this website. This information is used, amongst other things, to collect video statistics, improve user experience and prevent fraud.

Where applicable, further data processing operations may be triggered after a YouTube video has been played, over which we have no control. As the relevant consent has been obtained, processing takes place exclusively on the basis of Article 6(1), first subparagraph, point (a) GDPR and Section 25(1) of the TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.

Further information on data protection at YouTube can be found in their privacy policy at: https://policies.google.com/privacy?hl=de.

Google Maps

This site uses the Google Maps map service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

In order to use the functions of Google Maps, it is necessary to store your IP address. This

information is usually transmitted to a Google server in the USA and stored there. The provider of this website has no influence over this data transmission. When Google Maps is activated, Google may use Google Web Fonts to ensure consistent font display. When you access Google Maps, your browser loads the required web fonts into its cache to display text and fonts correctly.

The use of Google Maps is in the interests of presenting our online services in an appealing manner and ensuring that the locations specified on our website can be easily found. As the relevant consent has been obtained, processing is carried out exclusively on the basis of Article 6(1), first subparagraph, point (a) GDPR and Section 25(1) of the TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.

Further information on the handling of user data can be found in Google’s privacy policy: https://policies.google.com/privacy?hl=de.

Online presence on Facebook, Instagram, LinkedIn, Spotify, TikTok and WhatsApp

Facebook, Instagram, LinkedIn, Spotify, TikTok and WhatsApp are not integrated into the website, and we do not collect any data. If you click on the link, you will be redirected to the relevant website, where the privacy policy published there will apply. Of course, you can also access our online presence directly.

Insofar as you have given your consent to the respective social media operator in accordance with Article 6(1), first subparagraph, point (a) GDPR, when you visit our online presence on the social media platforms mentioned above, your data will be automatically collected and stored for market research and advertising purposes, from which usage profiles are created using pseudonyms. These may be used, for example, to display adverts within and outside the platforms that are presumed to match your interests. Cookies are generally used for this purpose. For detailed information on the processing and use of data by the relevant social media operator, as well as contact details, your rights in this regard and the settings available to protect your privacy, please refer to the providers’ privacy policies linked below. Should you nevertheless require assistance in this matter, please do not hesitate to contact us.

Facebook: https://www.facebook.com/policy.php

Instagram: https://instagram.com/about/legal/privacy/

LinkedIn: https://www.linkedin.com/legal/privacy-policy

Spotify: https://www.spotify.com/de/legal/privacy-policy/

TikTok: https://www.tiktok.com/legal/page/eea/privacy-policy/de

WhatsApp: https://www.whatsapp.com/legal/privacy-policy?lang=de

Friendly Captcha (bot/spam protection)

Our website uses the ‘Friendly Captcha’ service (www.friendlycaptcha.com). This service is provided by Friendly Captcha GmbH, Am Anger 3–5, 82237 Wörthsee, Germany. Friendly Captcha is a security solution designed to prevent automated programmes and scripts (so-called ‘bots’) from using our website.

Friendly Captcha does not set or read any cookies on the visitor’s device. IP addresses are stored only in hashed (one-way encrypted) form and do not allow us or Friendly Captcha to identify any individual. Where personal data is collected, it is deleted after 30 days at the latest.

The legal basis for the processing is Article 6(1), first subparagraph, point (e) GDPR in conjunction with Article 4(1) of the Bavarian Data Protection Act (BayDSG). Protecting our website against unauthorised access by bots, in particular against spam and bulk enquiries, is necessary for the proper operation of our website. Further information on data protection when using Friendly Captcha can be found at: https://friendlycaptcha.com/legal/privacy-end-users/

The FriendlyCaptcha tool is integrated into the contact form on our website. This is used to verify whether the entries on the contact form are actually made by a user or by mechanical or automated programmes (so-called ‘bots’). For this purpose, the provider of Friendly Captcha, Friendly Captcha GmbH (Am Anger 3–5, 82237 Wörthsee), collects your IP address, technical details of the web browser and, where applicable, the operating system you are using, the section of our website you have accessed, the date and time of your visit, and any information you are asked to provide by Friendly Captcha. No cookies are set or used for this purpose. Friendlycaptcha only receives the data once you click on the button to start the ‘anti-bot verification’. The legal basis for the data processing is our legitimate interest pursuant to Article 6(1), first subparagraph, point (f) GDPR.

Events

The university organises or co-organises events. If you register yourself, we process your data on the basis of your consent (Article 6(1), first subparagraph, point (a) GDPR); if we invite you directly, the legal basis for the processing is the performance of a task carried out in the public interest (Article 6(1), first subparagraph, point (e) GDPR in conjunction with Art. 4(1) of the Bavarian Data Protection Act (BayDSG)).

We collect the data from publicly available sources (e.g. newspapers or online publications), directly from event participants (e.g. by providing a form, via email or by telephone), or receive it from other public or non-public bodies.

The data is processed for the purpose of preparing and organising the respective events (e.g. compiling guest lists and facilitating access control). Depending on the type of event, the university acts as a co-organiser alongside another partner organisation. In such cases, the data collected is transferred to this partner organisation or, where applicable, to an external service provider; these parties are also permitted to use the data solely for the proper organisation of the event.

Photographs and video recordings at events

Photographs and, where applicable, videos are taken at our events and used for the University’s public relations work; the legal basis for this is Article 6(1), first subparagraph, point (e) GDPR in conjunction with Article 4(1) of the Bavarian Data Protection Act (BayDSG) and Sections 22 and 23 of the German Act on Copyright in Works of Art and Photography (KUG); public relations work forms part of the university’s remit. If you do not wish your personal data to be processed in this way, please inform us accordingly.

What do we use your data for?

We use your data to fulfil our statutory duties in teaching, study, research, continuing professional development and knowledge and technology transfer, to provide our online services and – where you have given your consent – to analyse visitor and traffic figures and to optimise our website. We use the data you have entered yourself to respond to your contact enquiry or message.

Disclosure of data

Your personal data will not be disclosed to third parties for any purposes other than those set out below.
We will only disclose your personal data to third parties if:

  • you have given your explicit consent in accordance with Article 6(1), first subparagraph, point (a) GDPR,
  • the disclosure is necessary, in accordance with Article 6(1), first subparagraph, point (b) GDPR, for the performance of a contract to which you are a party, or for the implementation of pre-contractual measures taken in response to your enquiry;
  • where there is a legal obligation to disclose the data pursuant to Article 6(1), first subparagraph, point (c) GDPR, or where processing is necessary to comply with a legal obligation to which the controller is subject.
  • where, in accordance with Article 6(1), first subparagraph, point (d) GDPR, the processing is necessary to protect the vital interests of the data subject or of another natural person;
  • where, in accordance with Article 6(1), first subparagraph, point (e) GDPR, processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Restricted areas on the website

Students and staff can log in to restricted areas via the OTH website.

The following personal data is collected in the process: username, password.

You undertake to treat your personal login details as confidential and not to disclose them to any unauthorised third party. We cannot accept any liability for the misuse of passwords, unless we are responsible for such misuse.

Rights of those affected

You have the right:

  • pursuant to Article 7(3) of the GDPR, to withdraw your consent at any time. As a result, we shall no longer be permitted to continue processing data on the basis of that consent in the future;
  • pursuant to Article 15 of the GDPR, to request information about your personal data processed by us. In particular, you may request information regarding the purposes of processing, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the intended period of storage, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data where it was not collected by us, and the existence of automated decision-making, including profiling, and, where applicable, meaningful information regarding the details thereof;
  • to request, in accordance with Article 16 of the GDPR, the rectification of inaccurate personal data or the completion of your personal data stored by us without undue delay;
  • in accordance with Article 17 of the GDPR, to request the erasure of your personal data stored by us, unless processing is necessary for the exercise of the right to freedom of expression and information, to comply with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims;
  • in accordance with Article 18 of the GDPR, to request the restriction of the processing of your personal data, provided that you contest the accuracy of the data, the processing is unlawful but you oppose its erasure, and we no longer require the data but you require it for the establishment, exercise or defence of legal claims, or where you have objected to the processing in accordance with Article 21 of the GDPR;
  • in accordance with Article 20 of the GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another data controller;
  • pursuant to Article 21 of the GDPR, to object at any time to the processing of your personal data on grounds relating to your particular situation, insofar as such processing is based on Article 6(1), first subparagraph, point (e) GDPR;
  • to lodge a complaint with a supervisory authority in accordance with Article 77 of the GDPR. As a rule, you may contact the supervisory authority for your usual place of residence, your place of work or our registered office.

The supervisory authority responsible for us is: The Bavarian State Commissioner for Data Protection, Wagmüllerstraße 18, 80538 Munich, telephone 089 212672-0, email: poststelle(at)datenschutz-bayern.de.

Right to object

Where your personal data is processed on the basis of Article 6(1), first subparagraph, point (e) GDPR, you have the right to object to the processing of your personal data in accordance with Article 21 of the GDPR. The controller will then no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Where your data is processed for the purposes of direct marketing, you have a general right to object, which we will honour without you needing to specify a particular situation. (Article 21(2) of the GDPR)

If you wish to exercise your right to withdraw consent or your right to object, you may do so informally. For example, simply sending us an email is sufficient. (datenschutz(at)oth-regensburg.de)

Period for which personal data is stored

The data controller processes and stores the data subject’s personal data only for the period necessary to fulfil the purpose of storage and/or insofar as this is required or prescribed by relevant legal provisions.

Once the retention obligation has expired, a review is carried out towards the end of the calendar year to determine whether there is still a need for processing. If this is not the case, the data will be deleted.

Data security

Our website uses state-of-the-art encryption (Transport Layer Security, TLS). You can tell whether a particular page on our website is being transmitted in an encrypted form by the closed key or padlock symbol displayed in the browser’s address bar. We also implement appropriate technical and organisational measures to protect your data against accidental or deliberate manipulation, partial or complete loss, destruction or unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.

 

Changes to this Privacy Policy – Effective 21 August 2026

Due to the further development of our website and the services offered via it, or as a result of changes to legal or regulatory requirements, it may become necessary to amend this Privacy Policy. You can view and print the latest version of the Privacy Policy at any time on the website under ‘Privacy’.