Privacy Policy

Last Updated: November 2025

1. Introduction

CRC 1550 “Molecular Circuits of Heart Disease” (“we”, “our”, “us”, or “the Centre”) operates the website crc1550.com (hereinafter referred to as the “Website”).

This Privacy Policy explains our practices regarding the collection, use, disclosure, and protection of personal data when you use the Website and interact with our services. We are committed to protecting your privacy and ensuring a transparent, trustworthy relationship with all users.

If you have questions about this Privacy Policy or our privacy practices, please contact us using the information provided in Section 14 of this policy.

2. Data Controller and Contact Information

Organisation: CRC 1550 – Molecular Circuits of Heart Disease Website: crc1550.com Data Controller: University of Heidelberg (Ruprecht-Karls-Universität Heidelberg)

Contact Details:

For privacy-related inquiries, please contact us using the above details.

3. Personal Data We Collect

3.1 Data from Contact Forms

When you use our contact form or send inquiries, we collect:

3.2 Data from Job Applications

If you apply for positions through “Work With Us” section, we collect:

3.3 Data from Newsletter Subscriptions

If you subscribe to our newsletter or mailing lists, we collect:

3.4 Automatically Collected Data

When you visit the Website, we automatically collect:

3.5 Data from Third-Party Integrations

The Website may include embedded content from third parties (YouTube videos, social media feeds, etc.). These providers may collect data about you according to their own privacy policies.

3.6 Event Registration Data

If you register for our conferences, seminars, or events, we collect:

4. Legal Basis for Data Processing

We process your personal data under the following legal bases in accordance with the GDPR:

5. Purpose of Data Processing

We use collected personal data for:

  1. Communication: Responding to inquiries, providing information, and establishing contact
  2. Job Applications: Processing applications and recruitment activities
  3. Event Management: Registering participants, sending event information, and post-event follow-up
  4. Newsletter Distribution: Sending research updates, news, and information you subscribed to receive
  5. Website Functionality: Ensuring the Website operates properly and securely
  6. Analytics: Understanding visitor behavior and improving Website experience
  7. Research: Using data in accordance with research protocols and ethical guidelines
  8. Regulatory Compliance: Meeting legal and funding requirements
  9. Security: Protecting the Website from unauthorized access and malicious activities
  10. Statistical Analysis: Creating anonymized, aggregated statistics for reporting

6. Data Sharing

We do not sell or rent personal data to third parties for commercial purposes.

We may share your data with:

  1. Service Providers: Third-party vendors assisting with Website operations, email delivery, analytics, and hosting. These providers are contractually bound to maintain data confidentiality.
  2. University Partners: Other departments and institutions within the University of Heidelberg may receive data if relevant to ongoing research or administrative functions.
  3. Consortium Partners: Partner institutions within CRC 1550 may receive data regarding joint research activities or collaboration, with your consent.
  4. Funding Agencies: The German Research Foundation (DFG) and other funding bodies may receive anonymized information required for reporting purposes.
  5. Legal Requirements: When required by law, court order, or regulatory authority.
  6. Third-Party Platforms: If you interact with embedded content (YouTube, social media), these platforms receive data according to their privacy policies.
  7. Research Collaborators: Anonymized data may be shared with collaborating research institutions for scientific purposes.

7. International Data Transfers

Our Website is hosted within the European Union. We comply with GDPR requirements for any international data transfers. If your data is transferred outside the EU/EEA, we implement appropriate safeguards such as Standard Contractual Clauses.

8. Data Retention

You may request data deletion at any time, subject to legal retention requirements.

9. Your Rights Under the GDPR

You have the following rights regarding your personal data:

9.1 Right of Access

You may request a copy of your personal data in a structured, commonly used, and machine-readable format.

9.2 Right to Rectification

You may request that we correct inaccurate or incomplete personal data.

9.3 Right to Erasure

You may request deletion of your personal data, subject to legal exceptions.

9.4 Right to Restrict Processing

You may request that we limit how we use your personal data.

9.5 Right to Data Portability

You may request your data in a portable format for transfer to another organization.

9.6 Right to Object

You may object to certain types of processing, including direct marketing and automated decision-making.

9.7 Right to Withdraw Consent

If we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

9.8 Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing that has legal effects.

To exercise any of these rights, please contact us using the details in Section 2. We will respond within 30 days.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

However, no method of transmission over the Internet is entirely secure. While we take reasonable precautions, we cannot guarantee absolute security.

11. Cookies and Similar Technologies

For detailed information about cookies used on the Website, please refer to our Cookie Policy. In summary:

You can manage cookies through our cookie consent tool or your browser settings.

12. Children’s Privacy

The Website is not intentionally directed to children under 16 years of age. We do not knowingly collect personal data from children without parental consent. If we become aware that a child has provided us with personal data, we will take steps to delete it and terminate the child’s interaction with the Website.

13. Third-Party Links and Services

The Website may contain links to external websites and embedded services that are not operated by us. This Privacy Policy applies only to the Website. We are not responsible for third-party privacy practices. We encourage you to review their privacy policies before providing personal data.

14. Contacting Us

For questions about this Privacy Policy, to exercise your GDPR rights, or to report privacy concerns:

Email: CRC1550@uni-heidelberg.de

Mailing Address: CRC 1550 Project Office Eppelheimer Strasse 8 69115 Heidelberg Germany

Phone: +49 (6221) 56-36113

Data Protection Authority Complaint: If you believe we have violated your privacy rights, you may lodge a complaint with the German data protection authority (Landesbeauftragte für Datenschutz Baden-Württemberg) or your local supervisory authority.

15. Policy Updates

We may update this Privacy Policy periodically to reflect:

Material changes will be communicated via email notification and by updating the “Last Updated” date at the top of this page.

16. Legal Compliance

This Privacy Policy complies with:


Legal Notice: This policy is provided for informational purposes. For specific legal advice regarding data protection, please consult with a qualified legal professional specializing in privacy and data protection law.

Last Updated: November 2025 Version: 1.0 Language: English