Privacy Policy

Data protection at a glance

Privacy Policy

Data protection at a glance

Background

This privacy policy informs you about the nature, scope and purpose of the processing of your personal data by the data protection controllers pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR).

Scope and responsibility

This privacy policy applies to the online offering of Steinbeis University of Applied Sciences.

The controller responsible for data processing on this website is:

Steinbeis‑Hochschule GmbH
Filderhauptstraße 142
70599 Stuttgart
Tel.: +49 30 47 39 14‑500
Email: info@steinbeis‑hochschule.de

Data Protection Officer

We have appointed a Data Protection Officer for our university. You can reach them at the following email address: dsb-shb@steinbeis.de

Processing of your data on our website

How is your data processed in detail?
Below, we inform you about the individual processing operations, the scope and purpose of data processing, the legal basis, the obligation to provide your data and the respective storage period. No automated decision-making in individual cases, including profiling, takes place.

Provision of the website

Purpose
To provide and display the website and to ensure its stability and security, technically required data is processed.

Categories of data processed
In particular, your IP address, browser type and browser version, operating system used, referrer URL, date and time of access, and the pages accessed are processed.

Recipients
The data may be transmitted to employees of the web hosting provider insofar as this is necessary for the provision and operation of the website.

Third-country data transfer
No third-country transfer takes place.

Storage period
In principle, the data is stored only for as long as is necessary to provide the website and ensure stability and security.

Legal basis
Processing is carried out on the basis of Art. 6(1) lit. b GDPR.

Contact form

Purpose
The contact form is used to process and respond to your enquiries. The data you enter is used to contact you and handle your request.

Categories of data processed
When using the contact form, the following personal data is processed in particular: first name, last name, email address, telephone number if applicable, the content of your message, and technical metadata, e.g. time of the enquiry and IP address.

Recipients
The recipient of the data is Steinbeis University of Applied Sciences. Data is only passed on to third parties if this is necessary to process your enquiry or if there is a legal obligation to do so.

Third-country data transfer
No third-country transfer takes place.

Storage period
The data transmitted via the contact form is deleted as soon as your enquiry has been conclusively processed and no statutory retention obligations prevent deletion.

Legal basis
Processing is carried out on the basis of Art. 6(1) lit. b GDPR.

Contact by email or telephone

Purpose
If you contact us by email or telephone, we process the personal data you provide in order to handle your enquiry and communicate with you.

Categories of data processed
Depending on the content of the enquiry, we process contact and communication data in particular, e.g. name, email address, telephone number, as well as the information contained in the enquiry.

Recipients
The recipient of the data is Steinbeis University of Applied Sciences. Data is only passed on to third parties if this is necessary for processing or if there is a legal obligation to do so.

Third-country data transfer
No third-country transfer takes place.

Storage period
The data is deleted as soon as your enquiry has been conclusively processed and no statutory retention obligations prevent deletion.

Legal basis
Depending on the type of enquiry, processing is carried out on the basis of Art. 6(1) lit. b GDPR.

Password-protected areas

Purpose
We may provide certain content or pages of the website with password protection in order to restrict access to specific content.

Categories of data processed
As part of password protection, we process the password you enter as well as technical usage data, e.g. IP address, time of access, browser or device information. Depending on the configuration, a cookie may be set to maintain access status.

Recipients
The recipient of the data is Steinbeis University of Applied Sciences. If service providers are used for hosting or technical support, they may have access as processors.

Third-country data transfer
No third-country transfer takes place.

Storage period
Technical log data is deleted in accordance with the server log file retention periods. Any access cookie that may be set is stored for the duration of the session or, depending on the configuration, in accordance with the cookie lifetime specified in the consent tool.

Legal basis
Processing is carried out on the basis of Art. 6(1) lit. f GDPR.

TOOLS & PLUGINS

Consent Management: Complianz

Purpose
The Complianz consent management tool is used to obtain, document and manage your consent to data processing and the use of cookies and comparable technologies in compliance with data protection law. The aim is to enable you to make an informed decision about the use of services on our website that require consent.

Categories of data processed
As part of consent management, the following personal data is processed in particular:
Information about your consent behaviour, IP address, date and time of consent, consent ID, and technical information about the browser and device used.

Recipients
The recipient of the data is
Complianz B.V.
Kalmarweg 14-5
9723JG Groningen
Netherlands
which acts as a processor within the scope of consent management.

Third-country data transfer
A transfer of data to third countries cannot be ruled out. If data is transferred, this is done on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular through the use of the European Commission’s standard contractual clauses.

Storage period
Consent data is stored for as long as is necessary to provide evidence of the consent given. As a rule, it is deleted after consent is withdrawn or after the intended storage period of the cookies has expired.

Legal basis
The use of technically non-essential cookies and comparable technologies is carried out exclusively on the basis of your consent pursuant to Art. 6(1) lit. a GDPR. Technically necessary cookies are used on the basis of Art. 6(1) lit. f GDPR.

Web analytics with Google Analytics

Purpose
We use Google Analytics to evaluate the use of our website and obtain information about user behaviour. This helps us to improve the website technically, in terms of content and structure, and to analyse the reach of our offerings.

Categories of data processed
When using Google Analytics, the following personal data may be processed in particular:
  • technical usage data (e.g. IP address in truncated form, device and browser information),
  • usage data (e.g. pages visited, time spent on site, interactions),
  • timestamps and approximate location data (region/country),
  • pseudonymous identifiers (e.g. cookie or device IDs).

Processing is carried out using cookies or comparable technologies.

Recipients
The recipients of the data are
  • Cybot A/S, Denmark (Cookiebot), and
  • Usercentrics GmbH, Germany, which act as processors within the scope of consent management.
Third-country data transfer
A transfer of data to third countries cannot be ruled out. Data is transferred on the basis of the European Commission’s standard contractual clauses pursuant to Art. 46 GDPR.

Storage period
Consent data is stored for as long as is necessary to provide evidence of the consent given. As a rule, it is deleted after consent is withdrawn or after the intended storage period of the cookies has expired.

Legal basis
The use of technically non-essential cookies and comparable technologies is carried out exclusively on the basis of your consent pursuant to Art. 6(1) lit. a GDPR. Technically necessary cookies are used on the basis of Art. 6(1) lit. f GDPR.

Multilingualism

Purpose
We provide the website in various languages and store your selected language setting to make it easier to use the website.

Categories of data processed
When using the multilingual function, technical usage data may be processed, e.g. IP address, browser or device information, date and time of access, as well as information about the selected language setting, e.g. via cookies or comparable technologies.

Recipients
The recipient of the data is Steinbeis University of Applied Sciences. If service providers are used for hosting or technical support, they may have access as processors.

Third-country data transfer
No third-country transfer takes place.

Storage period
Information about the language setting is stored for the duration of the session or, if stored in cookies, in accordance with the cookie lifetime specified in the consent tool. Log data is deleted after the retention periods specified for server log files.

Legal basis
Processing is carried out on the basis of Art. 6(1) lit. f GDPR.

SOCIAL & MEDIA

Vimeo

Purpose
Vimeo is used to provide videos on the website and display them in an appealing way.

Categories of data processed
When playing a Vimeo video, the following data may be processed in particular:
IP address, information about the device and browser used, date and time of access, and, where applicable, technical usage data (e.g. referrer URL).

Recipients
The recipient of the data is Vimeo, Inc., USA. Vimeo processes the data as an independent controller.

Third-country data transfer
A transfer of data to the USA cannot be ruled out. Data is transferred on the basis of the European Commission’s standard contractual clauses pursuant to Art. 46 GDPR.

Storage period
The storage period is based on Vimeo’s specifications. We have no influence on the specific duration of storage.

Legal basis
Processing is carried out on the basis of your consent pursuant to Art. 6(1) lit. a GDPR.

Social media channels

Purpose
We maintain presences on various social media channels to provide information about our offerings and activities, give insights into our work, and communicate with interested parties. The respective platforms also provide the option to contact us, for example via comments, posts or direct messages.

Categories of data processed
When using our social media channels, we process the personal data that you actively provide to us via the respective platform, e.g. your name or username, profile information, message content, comments or reactions.

Recipients
Within Steinbeis University of Applied Sciences, only authorised employees have access to the content addressed to us via social media channels.

Third-country data transfer
A transfer of data to third countries, in particular to the USA, cannot be ruled out. Data is transferred on the basis of the European Commission’s standard contractual clauses pursuant to Art. 46 GDPR.

Storage period
We store the data we process as part of communication via social media channels only for as long as is necessary to handle your request.

Legal basis
Your personal data is processed on the basis of our legitimate interest in contemporary public relations and communication pursuant to Art. 6(1) lit. f GDPR.
If you contact us specifically via social media channels, processing of your data may also be necessary to carry out pre-contractual measures or to respond to your enquiry pursuant to Art. 6(1) lit. b GDPR.

Data processing by the platform operators
When using our social media channels, the respective platform operators process personal data under their own responsibility. This includes, in particular, technical data (e.g. IP address, device information), usage and interaction data and—if you have a user account and are logged in—additional profile data. Processing may also be carried out for the platform operators’ own purposes, for example to provide the services, analyse user behaviour or deliver personalised content and advertising. We have no influence on the nature and scope of this data processing. Further information can be found in the privacy policies of the respective platform operators.

Rights of data subjects

Under the General Data Protection Regulation (GDPR), you have the following rights:
  • Right of access to information about the processing of your personal data (Art. 15 GDPR),
  • Right to rectification of inaccurate or incomplete data (Art. 16 GDPR),
  • Right to erasure of your personal data, provided the legal requirements are met (Art. 17 GDPR),
  • Right to restriction of processing (Art. 18 GDPR),
  • Right to data portability, where applicable (Art. 20 GDPR),
  • Right to object to processing based on Art. 6(1) lit. f GDPR (Art. 21 GDPR),
  • Right to withdraw consent given, with effect for the future (Art. 7(3) GDPR),
  • Right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
Last updated: January 2026

Background

This privacy policy informs you about the nature, scope and purpose of the processing of your personal data by the data protection controllers pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR).

Scope and responsibility

This privacy policy applies to the online offering of Steinbeis University of Applied Sciences.

The controller responsible for data processing on this website is:

Steinbeis‑Hochschule GmbH
Filderhauptstraße 142
70599 Stuttgart
Tel.: +49 30 47 39 14‑500
Email: info@steinbeis‑hochschule.de

Data Protection Officer

We have appointed a Data Protection Officer for our university. You can reach them at the following email address: dsb-shb@steinbeis.de

Processing of your data on our website

How is your data processed in detail?
Below, we inform you about the individual processing operations, the scope and purpose of data processing, the legal basis, the obligation to provide your data and the respective storage period. No automated decision-making in individual cases, including profiling, takes place.

Provision of the website

Purpose
To provide and display the website and to ensure its stability and security, technically required data is processed.

Categories of data processed
In particular, your IP address, browser type and browser version, operating system used, referrer URL, date and time of access, and the pages accessed are processed.

Recipients
The data may be transmitted to employees of the web hosting provider insofar as this is necessary for the provision and operation of the website.

Third-country data transfer
No third-country transfer takes place.

Storage period
In principle, the data is stored only for as long as is necessary to provide the website and ensure stability and security.

Legal basis
Processing is carried out on the basis of Art. 6(1) lit. b GDPR.

Contact form

Purpose
The contact form is used to process and respond to your enquiries. The data you enter is used to contact you and handle your request.

Categories of data processed
When using the contact form, the following personal data is processed in particular: first name, last name, email address, telephone number if applicable, the content of your message, and technical metadata, e.g. time of the enquiry and IP address.

Recipients
The recipient of the data is Steinbeis University of Applied Sciences. Data is only passed on to third parties if this is necessary to process your enquiry or if there is a legal obligation to do so.

Third-country data transfer
No third-country transfer takes place.

Storage period
The data transmitted via the contact form is deleted as soon as your enquiry has been conclusively processed and no statutory retention obligations prevent deletion.

Legal basis
Processing is carried out on the basis of Art. 6(1) lit. b GDPR.

Contact by email or telephone

Purpose
If you contact us by email or telephone, we process the personal data you provide in order to handle your enquiry and communicate with you.

Categories of data processed
Depending on the content of the enquiry, we process contact and communication data in particular, e.g. name, email address, telephone number, as well as the information contained in the enquiry.

Recipients
The recipient of the data is Steinbeis University of Applied Sciences. Data is only passed on to third parties if this is necessary for processing or if there is a legal obligation to do so.

Third-country data transfer
No third-country transfer takes place.

Storage period
The data is deleted as soon as your enquiry has been conclusively processed and no statutory retention obligations prevent deletion.

Legal basis
Depending on the type of enquiry, processing is carried out on the basis of Art. 6(1) lit. b GDPR.

Password-protected areas

Purpose
We may provide certain content or pages of the website with password protection in order to restrict access to specific content.

Categories of data processed
As part of password protection, we process the password you enter as well as technical usage data, e.g. IP address, time of access, browser or device information. Depending on the configuration, a cookie may be set to maintain access status.

Recipients
The recipient of the data is Steinbeis University of Applied Sciences. If service providers are used for hosting or technical support, they may have access as processors.

Third-country data transfer
No third-country transfer takes place.

Storage period
Technical log data is deleted in accordance with the server log file retention periods. Any access cookie that may be set is stored for the duration of the session or, depending on the configuration, in accordance with the cookie lifetime specified in the consent tool.

Legal basis
Processing is carried out on the basis of Art. 6(1) lit. f GDPR.

TOOLS & PLUGINS

Consent Management: Complianz

Purpose
The Complianz consent management tool is used to obtain, document and manage your consent to data processing and the use of cookies and comparable technologies in compliance with data protection law. The aim is to enable you to make an informed decision about the use of services on our website that require consent.

Categories of data processed
As part of consent management, the following personal data is processed in particular:
Information about your consent behaviour, IP address, date and time of consent, consent ID, and technical information about the browser and device used.
Recipients
The recipient of the data is
Complianz B.V.
Kalmarweg 14-5
9723JG Groningen
Netherlands
which acts as a processor within the scope of consent management.
Third-country data transfer
A transfer of data to third countries cannot be ruled out. If data is transferred, this is done on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular through the use of the European Commission’s standard contractual clauses.
Storage period
Consent data is stored for as long as is necessary to provide evidence of the consent given. As a rule, it is deleted after consent is withdrawn or after the intended storage period of the cookies has expired.
Legal basis
The use of technically non-essential cookies and comparable technologies is carried out exclusively on the basis of your consent pursuant to Art. 6(1) lit. a GDPR. Technically necessary cookies are used on the basis of Art. 6(1) lit. f GDPR.

Web analytics with Google Analytics

Purpose
We use Google Analytics to evaluate the use of our website and obtain information about user behaviour. This helps us to improve the website technically, in terms of content and structure, and to analyse the reach of our offerings.

Categories of data processed
When using Google Analytics, the following personal data may be processed in particular:
  • technical usage data (e.g. IP address in truncated form, device and browser information),
  • usage data (e.g. pages visited, time spent on site, interactions),
  • timestamps and approximate location data (region/country),
  • pseudonymous identifiers (e.g. cookie or device IDs).

Processing is carried out using cookies or comparable technologies.

Recipients
The recipients of the data are
  • Cybot A/S, Denmark (Cookiebot), and
  • Usercentrics GmbH, Germany, which act as processors within the scope of consent management.
Third-country data transfer
A transfer of data to third countries cannot be ruled out. Data is transferred on the basis of the European Commission’s standard contractual clauses pursuant to Art. 46 GDPR.
Storage period
Consent data is stored for as long as is necessary to provide evidence of the consent given. As a rule, it is deleted after consent is withdrawn or after the intended storage period of the cookies has expired.
Legal basis
The use of technically non-essential cookies and comparable technologies is carried out exclusively on the basis of your consent pursuant to Art. 6(1) lit. a GDPR. Technically necessary cookies are used on the basis of Art. 6(1) lit. f GDPR.

Multilingualism

Purpose
We provide the website in various languages and store your selected language setting to make it easier to use the website.

Categories of data processed
When using the multilingual function, technical usage data may be processed, e.g. IP address, browser or device information, date and time of access, as well as information about the selected language setting, e.g. via cookies or comparable technologies.
Recipients
The recipient of the data is Steinbeis University of Applied Sciences. If service providers are used for hosting or technical support, they may have access as processors.
Third-country data transfer
No third-country transfer takes place.
Storage period
Information about the language setting is stored for the duration of the session or, if stored in cookies, in accordance with the cookie lifetime specified in the consent tool. Log data is deleted after the retention periods specified for server log files.
Legal basis
Processing is carried out on the basis of Art. 6(1) lit. f GDPR.

SOCIAL & MEDIA

Vimeo

Purpose
Vimeo is used to provide videos on the website and display them in an appealing way.

Categories of data processed
When playing a Vimeo video, the following data may be processed in particular:
IP address, information about the device and browser used, date and time of access, and, where applicable, technical usage data (e.g. referrer URL).

Recipients
The recipient of the data is Vimeo, Inc., USA. Vimeo processes the data as an independent controller.

Third-country data transfer
A transfer of data to the USA cannot be ruled out. Data is transferred on the basis of the European Commission’s standard contractual clauses pursuant to Art. 46 GDPR.

Storage period
The storage period is based on Vimeo’s specifications. We have no influence on the specific duration of storage.

Legal basis
Processing is carried out on the basis of your consent pursuant to Art. 6(1) lit. a GDPR.

Social media channels

Purpose
We maintain presences on various social media channels to provide information about our offerings and activities, give insights into our work, and communicate with interested parties. The respective platforms also provide the option to contact us, for example via comments, posts or direct messages.

Categories of data processed
When using our social media channels, we process the personal data that you actively provide to us via the respective platform, e.g. your name or username, profile information, message content, comments or reactions.

Recipients
Within Steinbeis University of Applied Sciences, only authorised employees have access to the content addressed to us via social media channels.

Third-country data transfer
A transfer of data to third countries, in particular to the USA, cannot be ruled out. Data is transferred on the basis of the European Commission’s standard contractual clauses pursuant to Art. 46 GDPR.

Storage period
We store the data we process as part of communication via social media channels only for as long as is necessary to handle your request.

Legal basis
Your personal data is processed on the basis of our legitimate interest in contemporary public relations and communication pursuant to Art. 6(1) lit. f GDPR.
If you contact us specifically via social media channels, processing of your data may also be necessary to carry out pre-contractual measures or to respond to your enquiry pursuant to Art. 6(1) lit. b GDPR.

Data processing by the platform operators
When using our social media channels, the respective platform operators process personal data under their own responsibility. This includes, in particular, technical data (e.g. IP address, device information), usage and interaction data and—if you have a user account and are logged in—additional profile data. Processing may also be carried out for the platform operators’ own purposes, for example to provide the services, analyse user behaviour or deliver personalised content and advertising. We have no influence on the nature and scope of this data processing. Further information can be found in the privacy policies of the respective platform operators.

Rights of data subjects

Under the General Data Protection Regulation (GDPR), you have the following rights:
  • Right of access to information about the processing of your personal data (Art. 15 GDPR),
  • Right to rectification of inaccurate or incomplete data (Art. 16 GDPR),
  • Right to erasure of your personal data, provided the legal requirements are met (Art. 17 GDPR),
  • Right to restriction of processing (Art. 18 GDPR),
  • Right to data portability, where applicable (Art. 20 GDPR),
  • Right to object to processing based on Art. 6(1) lit. f GDPR (Art. 21 GDPR),
  • Right to withdraw consent given, with effect for the future (Art. 7(3) GDPR),
  • Right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
Last updated: January 2026