Data Protection Information
When you use this website, we process your personal data as data controllers and save them for the duration required to fulfill the defined purposes and legal obligations. The sections below provide further details about the data this involves, how they will be processed and which rights you have in this regard.
Personal data, as defined by Article 4 (1) General Data Protection Regulation (GDPR) include all information related to an identified or identifiable natural person.
1. Scope of Application
This data protection information applies to data processing on the project website located at https://www.codeinspect.de and all services we offer in context with this project as web services or mobile app providing we refer to this data protection information.
2. Name and Contact Information of Controller and Corporate Data Protection Officer
Controller within the meaning of Art. 4 (7) GDPR:
Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V.
Hansastraße 27 c
80686 München
Germany
on behalf of its Fraunhofer Institute for Secure Information Technology, Rheinstraße 75, 64295 Darmstadt (in the following referred to as 'Fraunhofer SIT')
Email: info@sit.fraunhofer.de
Telephone: +49 6151 869-399
Fax: +49 6151 869-224
You can reach the Data Protection Officer at Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V., z.H. Datenschutzbeauftragter, Hansastraße 27 c, 80686 Munich or at datenschutz@zv.fraunhofer.de.
Please feel free to contact the data protection officer directly at any time with your questions concerning your data protection rights and/or your rights as data subject.
3. Personal Data Processing and Purposes of Data Processing
a) When visiting the website
You may access our website without having to disclose any details of your identity. The browser installed on your terminal device automatically transmits information to the server of our website (e.g. browser type and version, date and time of access) to enable connection with the website, including the IP address of your requesting terminal device. This information is temporarily stored in a so-called log file and deleted after no more than 30 days.
Your IP address is processed for technical and administrative purposes regarding connection set-up and stability, to guarantee the security and functioning of our website and to be able to track any illegal attacks on the website, if required.
The legal basis for processing the IP address is Art. 6 (1) lit. f GDPR. Our legitimate interest ensues from said security interest and the necessity of the unobstructed availability of our website.
We cannot draw any direct conclusions about your identity from processing the IP address and other information in the log file.
Moreover, we use cookies when you visit our website. Further details can be found further below in this data protection information.
b) When using contact forms
Some of our websites offer the option to contact us via a contact form provided on the website. This involves some mandatory information (title, if applicable, first and last name, email address). We require your data to determine who sent the inquiry and to be able to answer and process it.
This data processing in response to your inquiry is necessary for the purposes of our legitimate interests pursuant to Art. 6 (1) lit. f GDPR.
We will automatically delete the personal data collected by us using the contact form after your inquiry has been processed, unless statutory retention periods prohibit the erasure of your data.
c) Subscription to our Newsletter
If you have expressly given your consent pursuant to point (a) of the first sentence of Article 6(1) GDPR, we use your email address to send you our regular newsletter . The newsletter contains information regarding the work at our institute and other facilities and events of Fraunhofer e.V.
After subscribing to our newsletter, you will receive a registration notification by email, which will you need to confirm to be able to receive the newsletter (so-called double opt-in). This serves as a verification that the registration has actually been initiated by you.
Unsubscribing is possible at any time, e.g. via a link at the end of each newsletter. Alternatively, you may also unsubscribe by email abmeldung@sit.fraunhofer.de or use the following link: www.fraunhofer.de/de/fraunhofer-newsletter-abmeldung.html.
After revoking your consent for sending the newsletter, your email address will be deleted immediately from our newsletter distribution list.
d) Use of “CodeInspect”
CodeInspect is a tool for analysing Android applications. As part of the performance of a license agreement and in order to take steps to entering into a license agreement (this includes making use of our free demo), we collect the following data:
- Title
- First and last name
- E-Mail-Address
- Address
- Telephone number (optional)
- Confirmation of academic activity (optional)
- Payment data
- Signed license agreements (including the contract period which is necessary for the license verification while using “CodeInspect”)
- Bug reports (=reports on software errors that occur while using „CodeInspect“)
- Payment information, e.g. credit card details (only if you enter into a license agreement with costs).
The collecting and processing of these data have the following purposes:
- To identify you as our contract partner
- To complete the payment process
- To provide and improve the service you require
- To contact you by phone to get a feedback on your experience with our free demo version.
We are processing your phone number to contact you by phone in order to get a feedback on your experience with our free demo version. We do so in accordance with Article 6, para. 1 page 1 lit. f GDPR based on our legitimate interests in improving our service “CodeInspect” and to find out the needs of potential customers of “CodeInspect”. We are processing all other above mentioned personal data according to Article 6, para. 1, page 1 lit. b GDPR. We only store the personal data until the termination of the license agreement, unless fiscal safekeeping and documentation laws require a longer storage time according to Article 6 para. 1 lit. c GDPR and in particular according to § 147 AO [German Fiscal Code]).
4. Transfer of Data
We will only disclose your personal data to third parties if:
- You have given consent pursuant to Art. 6 (1) lit. a GDPR,
- There is a legal obligation for disclosure pursuant to Art. 6 (1) lit. c GDPR,
-
We contracted a processor in accordance to Article 28 GDPR; our processors are:
- Eigenbetrieb Darmstädter Werkstätten, Darmstadt
Processor for the Erasure of Personal Data.
- 4wd media GmbH & Co.KG, Darmstadt
Processor for the Maintenance of our Website.
Third parties may use the transferred data for the above-mentioned purposes only.
5. Cookies
This website uses cookies. Cookies are small files that your browser automatically generates and stores on your device (laptop, tablet, smartphone, etc.) when you visit our site. Cookies do not harm your device nor do they contain viruses, Trojans or other malware.
Cookies store information associated with the specific device used. That does not mean that we can directly identify you.
We use cookies for the purpose of making the use of our offers more convenient and pleasant for you. For example, we use so-called session cookies to detect that you have previously visited various pages of our website.
We also use temporary cookies to optimize user-friendliness; these cookies are stored on your device for a specific fixed time interval. When you visit our site again to use our services, these cookies will automatically detect that you have visited in the past and will reapply your previous entries and settings so that you do not have to enter them again.
The data processed by the cookies are necessary for the above-mentioned purposes to protect our legitimate interests and those of third parties pursuant to Art. 6 (1) lit. f GDPR.
Most browsers automatically accept cookies. However, you can configure your browser to not save any cookies on your computer or to display a notice before new cookies are saved. Completely disabling cookies may mean that you cannot fully use all functions of our website.
6. Social Media Plug-ins
We may use social media buttons (also called social media plug-ins) on our website. These are small icons which you can use to share the contents of our website in your profile on social networks.If you activate such an icon, a connection is established between our website and the social network. In addition to the contents in question, the operator of the social network obtains further, partly personal information. For example, this includes the fact that you are currently visiting our site.
The social media buttons are integrated using the so-called Shariff solution. This solution prevents your device from establishing a link to the social network merely because you visit a website featuring a social plug-in button without clicking on it. This means that information is only transmitted to the social network when you actually click the button.
The following social media plug-ins may be used on our sites:
a) Facebook Ireland Limited: Sharing on Facebook
Information is partly transmitted to the parent company Facebook Inc., headquartered in the USA. This company complies with the data protection regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Commerce.
Further information on data protection on Facebook can be found in Facebook’s privacy policy at https://www.facebook.com/about/privacy/.
b) Twitter International Company: Sharing on Twitter
Information is partly transmitted to the parent company Twitter Inc., headquartered in the USA. This company complies with the data protection regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Commerce.
Further information on data protection on Twitter can be found in Twitter’s privacy policy at https://twitter.com/privacy.
c) XING SE: Sharing on XING
Further information on data protection on XING can be found in XING’s privacy policy at https://www.xing.com/privacy.
d) LinkedIn Corporation: Sharing on LinkedIn
Information is partly transmitted to the parent company LinkedIn Corporation, headquartered in the USA. This company complies with the data protection regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Commerce.
Further information on data protection on LinkedIn can be found in the company’s privacy policy at https://www.linkedin.com/legal/privacy-policy.
e) Pinterest Europe Ltd.: Sharing on Pinterest
Further information on data protection on Pinterest can be found in Pinterest’s privacy policy at https://policy.pinterest.com/de/privacy-policy.
f) Facebook Ireland Limited: Sharing on Instagram
Information is partly transmitted to the parent company Facebook Inc., headquartered in the USA. This company complies with the data protection regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Commerce.
For the purpose and scope of data collection, further processing and use of data by Facebook as well as your related rights and configuration options for protecting your privacy, please refer to Instagram’s privacy policy at https://help.instagram.com/519522125107875.
7. YouTube
We use components (videos) of YouTube, LLC, 901 Cherry Ave., 94066 San Bruno, CA, USA (hereinafter “YouTube”), a company of Google Inc., Amphitheatre Parkway, Mountain View CA 94043, USA, (hereinafter “Google”) in our websites. The implementation is based on Art. 6 (1) lit. f GDPR; our legitimate interest in that case is the smooth integration of the videos and the attractive design of our website.
We use the “privacy-enhanced mode” option provided by YouTube.
When you access a page containing an embedded video, a connection to the YouTube servers is established and the contents are displayed on the Internet page through a notification to your browser.
Pursuant to YouTube specifications, in the “privacy-enhanced mode” your data - especially which of our website pages you visited as well as device-specific information including the IP address - is sent to the YouTube servers in the US only if you view the video.
If you are simultaneously logged into YouTube, this information is assigned to your YouTube member account. You may prevent this by logging out of your member account before visiting our website.
Google complies with the Data Protection Regulations of the U.S. Privacy Shield and is registered with the U.S. Privacy Shield Program of the U.S. Department of Trade.
Further information on data protection in connection with YouTube can be found in Google’s privacy policy at https://www.google.de/intl/de/policies/privacy/.
8. Rights of the Data Subject
You have the following rights:
- pursuant to Art. 7 (3) GDPR, to withdraw your consent at any time. This means that we may not continue the data processing based on this consent in the future;
- pursuant to Art. 15 GDPR, to obtain access to your personal data processed by us. In particular, you may request information about the purposes of the processing, the categories of personal data concerned, the categories of recipients to whom the personal data have been or will be disclosed, and the envisaged period for which the data will be stored. Moreover, you have the right to request rectification, erasure, or restriction of processing, to object to processing, the right to lodge a complaint, and to obtain information about the source of your data if they were not collected by us, as well as about the existence of automated decision-making, including profiling, and, if applicable, meaningful information about the logic involved;
- pursuant to Art. 16 GDPR, to obtain the rectification of inaccurate data or the completion of your personal data without undue delay;
- pursuant to Art. 17 GDPR, to obtain the erasure of personal data saved by us unless processing is necessary to exercise the right of freedom of expression and information, to comply with a legal obligation, for reasons of public interest, or to establish, exercise or defend legal claims;
- pursuant to Art. 18 GDPR, to obtain restriction of processing of your personal data if you contest the accuracy of the data, the processing is unlawful but you oppose the erasure of the personal data, or if we no longer need the personal data while you still require it for establishing, exercising or defending legal claims, or if you have filed an objection to the processing pursuant to Art. 21 GDPR;
- pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us, in a structured, commonly used and machine-readable format or to transmit those data to another controller and
- pursuant to Art. 77 GDPR, the right to lodge a complaint with a supervisory authority. Generally, you may contact the supervisory authority of your habitual residence, place of work or the registered offices of our organization.
Information on your right to object pursuant to Art. 21 GDPR
You have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data pursuant to Art. 6 (1) lit. e GDPR (data processing carried out in the public interest) and Art. 6 (1) lit. f GDPR (data processing for purposes of legitimate interests).
If you file an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defense of legal claims.
If your objection is directed against the processing of data for the purpose of direct marketing, we will stop the processing immediately. In this case, citing a special situation is not necessary. This includes profiling to the extent that it is related to such direct marketing.
If you would like to assert your right to object, please send an email to datenschutzkoordination@zv.fraunhofer.de.
9. Data Security
All your personal data are transmitted in encrypted format, using the widely used and secure TLS (Transport Layer Security) standard. TLS is a secure and proven standard that is also used, for instance, in online banking. You will recognize a secure TLS connection by the additional s after http (i.e., "https://..") in the address bar of your browser or by the lock icon in the lower part of your browser.
In all other regards, we use suitable technical and organizational security measures to protect your data against accidental or intentional manipulations, partial or complete loss, destruction, or the unauthorized access of third parties. We continuously improve our security measures in accordance with the state of the art.
10. Timeliness and Amendments to this Data Protection Information
The further development of our website and the products and services offered or changed due to statutory or regulatory requirements, respectively, may make it necessary to amend this data protection information. You may access and print out the latest data protection information at any time from our website.