Privacy Policy
1. Introduction
This privacy policy explains the reason for the collection and processing of your personal data, the way we protect the data provided and what rights you may exercise in relation to your data. We are committed to safeguarding the privacy of our website visitors.
2. The data controller
Responsible for data processing are the members of the TEF Health Consortium who act as joint controllers
Details of the respective parties / controllers and the data processing can be found in the Joint Controller Agreement here: TEF-Health Joint Controller Agreement
Please find the Data Subject information here: TEF-Health Data Subject Information
TEF-Health Project Coordinator (CHARITE):
Berlin Institute of Health, Brain Simulation SectionRobert-Koch-Platz 4
Prof Dr Petra Ritter
petra.ritter@charite.de; +49-30-450 560005
3. What categories of data do we collect?
We save and process the data of the visitors only to the extent necessary to ensure the functionality and administration of this website. Every time you visit our website, your IP address and other pieces of information are saved in anonymized form. These data are not being evaluated for the purpose of marketing.
3.1. Server log files
Whenever you visit our website, we automatically store certain data. This includes your IP address, type and version of the browser you use, time, date, website from which you come to our site. Your IP address is pseudonymised that means you can no longer be identified. All data stored in the log files will be deleted after 7 days.
The legal basis for this data process is Art. 6 (1) lit. f GDPR.
3.2. Cookies
Our website uses a small number of technically necessary cookies to ensure secure access, correct language display, and smooth user sessions. These cookies are essential for the operation of the site and do not require your consent under the GDPR and the ePrivacy Directive. These cookies do not track your behavior and are not shared with third parties for marketing purposes.
3.3. Contact
When you send a message we save your name and email address. We use these data only for the purpose of communication with you. After the communication is completed, these saved data will be deleted. The legal basis for this data processing is Art. 6 (1) lit. a GDPR.
3.4. Third party websites
This website contains links to other websites. We are not responsible for the privacy policies or practices of third party websites.
3.5. Online presence on social media
We maintain online presence on social networks and platforms in order to communicate with interested parties and users and to inform them about our project. When visiting each of these platforms, you as a user agree to the terms and conditions and the data processing guidelines of the corresponding operator. We provide links to twitter, linkedin, youtube via external links, we do not keep track of how you interact with links and do not exchange any information.
3.6. Education programme usage
When you are signed in and watch a recording in our Education programme (/education), we record how far you get through each lesson: the furthest position reached, the time watched, and whether you completed it, together with your account, organisation and country. We use this to maintain your learning progress so you can resume where you left off and to issue completion certificates, and - reported in aggregate - to see which material is used and completed so we can improve the training. Aggregate reporting is the default; named per-learner records are accessible only to the TEF-Health programme coordinators. We do not use this data for advertising and do not share it with third parties.
When you take a module quiz or exam, we record your answers, your score and whether you passed, together with any comment you leave on a question. Comments are read by the programme coordinators to correct the questions, so please do not put personal details in them.
On completing a module we issue a certificate naming you, the module and the date, and we e-mail it to you as a PDF. Each certificate carries a code. Anyone who holds both that code and your surname can confirm the certificate at /certificate, which then shows your name, what you completed and when. The code alone discloses nothing, so it is you who decides who can check it, by passing on both parts.
We keep these records for as long as you hold a TEF-Health account, so that your progress and certificates remain available. When your account is deleted, the records are deleted or anonymised, unless a longer period is required by law or to keep an issued certificate valid. If you ask us to erase a certificate, we erase it and it stops verifying.
The legal basis for this data processing is Art. 6 (1) lit. b GDPR (performance of the educational service you requested, meaning your progress and your certificates) and Art. 6 (1) lit. f GDPR (our legitimate interest in improving the training programme through aggregate usage analysis).
3.7. Pitching session recordings
Pitching sessions of a TEF-Health panel, such as the TEF-Health Hospital Network, are video calls in which a company presents its needs. We record the session as video with picture and sound, together with the presenter's name, their organisation and what they present. The recording is made only where the company has given its consent beforehand, on the booking page where it chooses its time.
The recording is shared with the member institutions of that panel, so that an institution that could not attend live can still answer the company's needs. This is internal sharing within the TEF-Health consortium: the recording is not published and it is not passed to anyone outside the consortium. All institutions that receive it are established in the European Union, and no transfer to a third country is intended.
The recording is deleted at the end of the sharing window the company agreed to, which is 30 days after the session for the TEF-Health Hospital Network. That window is fixed at the moment consent is given, so a later change to our settings never extends a consent already collected.
Access to a recording requires an authenticated account on this platform and is restricted to the designated member institutions of the panel. Transmission and storage are encrypted, the recording is held on servers within the European Union, and access expires automatically at the end of the sharing window.
Consent can be withdrawn in whole or in part at any time with effect for the future, without any disadvantage, by writing to the controller named in the consent the company received.
The legal basis for this data processing is Art. 6 (1) lit. a GDPR.
4. Your rights as a "data subject"
Under the General Data Protection Regulation, you have the right to access, modify or delete your data. You have the right to information about your personal data that we process. Furthermore, you have a right to rectification or deletion or restriction of processing, as it is applicable to you under the law. You have the right to lodge a complaint about the processing of your personal data by us to a supervisory authority for data protection.