Privacy Policy

WHU – Otto Beisheim School of Management, Burgplatz 2, 56179 Vallendar ("WHU") is happy to welcome you on our website.

General information about the processing of personal data

Below we inform you about the processing of your personal data when visiting our website.

Responsible according to Art. 4 (7) of the EU General Data Protection Regulation ("GDPR") is WHU - Otto Beisheim School of Management, Burgplatz 2, 56179 Vallendar (see our imprint, e-mail: datenschutz@whu.edu).

You can contact our data protection officer with the data provided at the end of this Privacy Policy.

If we use contracted service providers for specific offerings or would like to use your data for advertising purposes, we will inform you in detail below about the respective procedures. In doing so, we also name the specified criteria for the storage duration.

Personal data

Personal data is any information that relates to an identified or identifiable natural person. A natural person is considered to be identifiable if, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special features, that expresses the physical, physiological, genetic, mental, economic, cultural or social identity of this natural person, can be identified.

This includes, for example, information such as your name, address, telephone number, language, location, e-mail address, bank details and date of birth.

Processing of personal data

When processing data, we handle your personal data responsibly and confidentially. Therefore, your personal data will of course be processed in compliance with the applicable national (in particular BDSG) and European data protection regulations (in particular GDPR), as described below.

Such processing of personal data applies to any operation performed with or without the aid of automated procedures or in any series of procedures related to personal data. In particular, data processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction

If we use a processor for the processing of your personal data, we conclude a data processing contract with them, which fulfills all the requirements of Art. 28 GDPR.

Automated decision-making in individual cases including profiling according to Art. 22 GDPR does not take place.

Purpose of processing personal data when visiting our website

We process personal data in accordance with the requirements and conditions set out below in the context of automated processing. The purpose of processing your personal data is limited to the respective purposes.

In the case of merely informative use of the website, for example, if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you visit our website, we collect the following data that is technically necessary for us to show you our website and to ensure the stability and security (legal basis is Art. 6 para. 1 sentence 1 lt. f GDPR):

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the requirement (concrete page)
  • Access Status / HTTP status code
  • Transmitted amount of data
  • Website that the request comes from
  • Browser
  • Operating system and its interface
  • Language and version of the browser software.

In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive assigned to the browser you are using and by which the place/site that sets the cookie (here us) receives certain information. Cookies can not run programs or transmit viruses to your computer. They generally serve by making the internet offerings more user-friendly and effective. The use of cookies is described below under the heading "Use of cookies".

Use of Cookies

This website uses the following types of cookies, their scope and operation are explained below:

  • Transient cookies
  • Persistent cookies

Transient cookies are automatically deleted once you close the browser. In particular these include the session cookies. These store a session ID, with which various requests from your browser can be allocated to a common session. This will allow your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.

Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie. You can delete the cookies in the security settings of your browser at any time.

You can configure your browser settings according to your wishes and, for example, refuse to accept third-party cookies or all cookies. Please be aware that you may not be able to use all features of this site in that case.

We use cookies to identify you for follow-up visits if you have an account with us. Otherwise you would have to log in again for each visit.

Duration of data processing

The maximum duration of storage depends on the purpose of the respective data processing. The duration of the storage depends on the time required for the processing to fulfill the respective purpose or to fulfill legal obligations. The statutory storage obligations according to sec. 257 German Commerical Code (“HGB”) and sec. 147 German Tax Code (“AO”) (6 or 10 years) remain unaffected.

Recipient of personal data

If we use a processor for the processing of your personal data, we conclude a contract processing contract with the processor, which fulfills all the requirements of Art. 28 GDPR. The individual data processing versions are shown below.

Any further transmission of your personal data will not take place unless explicitly stated below.

Use of Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies", text files that are stored on your computer and that allow an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted and stored at a Google server in the USA. However, if IP address anonymization is activated on this website, your IP address will be shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. It is only in exceptional cases that the full IP address will be sent to a Google server in the US and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website usage and internet usage to the website operator. A data processing contract according to Art. 28 GDPR has been established.

The IP address provided by Google Analytics as part of Google Analytics will not be merged with other Google data.

You can prevent the storage of cookies by a corresponding setting of your browser software; however, please note that if you do this, you may not be able to use all the features of this website fully. You may also prevent the collection by Google of the data generated by the cookie and related to your use of the website (including your IP address), as well as the processing of this data by Google by using the browser plug-in available under the following link to download and install: http://tools.google.com/dlpage/gaoptout?hl=de.

The legal basis is Art. 6 para. 1 sentence 1 lt. f GDPR.

Integration of YouTube Videos

We have included YouTube videos in our online offering, which are saved on www.YouTube.com and are directly playable on our website. These are all incorporated in the "extended privacy mode", which means that none of your user data is transferred to YouTube if you are not playing the videos. Only when you play the videos, the above data will be transmitted. We don't have any influence on this data transfer.

By visiting the website, YouTube receives the information that you have accessed the corresponding sub-page of our website. In addition, the data mentioned above in this statement will be transmitted. This happens regardless of whether YouTube provides a user account that you are logged in to, or if there is no user account. When you're logged in to Google, your data will be assigned directly to your account. If you do not wish to be associated with your profile on YouTube, you must log out before activating the button. YouTube saves your data as usage profiles and uses them for advertising, market research and / or custom design of its website. Such an evaluation is done in particular (even for users who are not logged in) to provide appropriate advertising and to inform other users of the social network about their activities on our website. You have a right to object to the creation of these usage profiles, but you need to get in touch with YouTube in order to do so.

For more information on the purpose and scope of your data collection and processing through YouTube, please read the respective privacy policy. You'll also get more information about your rights and privacy settings here: www.google.com/intl/en/policies/privacy. Google also processes your personal information in the US and has submitted to the EU-US Privacy Shield, www.privacyshield.gov/EU-US-Framework.

Place of data processing

The processing of your personal data by us takes place in principle in Germany or in member states of the European Union, so long as a transfer of your personal data to states outside the member states of the European Union (third states) or other international organizations has not been presented in the aforementioned cases.

Safety / Technical and organizational measures

We take all necessary technical and organizational measures in accordance with the provisions of Articles 24, 25 and 32 GDPR in order to protect your personal data from misuse and loss, destruction, access, modification or disclosure by unauthorized persons.

In this way, we comply with the legal requirements for pseudonymizing and encrypting personal data, the confidentiality, integrity, availability and resilience of systems and services related to processing, the availability of personal data and the ability to rapidly restore them in the event of a physical or technical incident as well as the establishment of procedures for periodic tests, assessment and evaluation of the effectiveness of technical and organizational measures to ensure the safety of processing.

Furthermore, we also follow the requirements of Art. 25 GDPR with regard to the principles of "privacy by design" (data protection by means of technical design) and "privacy by default" (data protection by means of privacy-friendly default settings).

Your rights

You have a right to free information (right of access) about your personal data as well as, subject to the relevant conditions, a right to rectification, blocking and eraser of your data, to the restriction of processing, to data portability as well as a right of objection.

You also have the opportunity to complain to the relevant regulatory authority.

If you have any questions regarding the processing of your personal data or questions related to the aforementioned rights as well as suggestions, please contact our external data protection officer:

Dr. Dornbach Consulting GmbH
Anton-Jordan-Straße 1
56070 Koblenz
Tel .: +49 (0) 261 9431-442
Fax: +49 (0) 261 9431-445
E-Mail: datenschutz@whu.edu 

As of: May 2018

The English version only serves informational purposes. The German version is legally binding. 

  • AACSB Logo
  • AMBA Logo
  • Equis Logo
  • European Business Schools