Privacy Policy
Last Updated: November 2025
1. Introduction
CRC 1550 “Molecular Circuits of Heart Disease” (“we”, “our”, “us”, or “the Centre”) operates the website crc1550.com (hereinafter referred to as the “Website”).
This Privacy Policy explains our practices regarding the collection, use, disclosure, and protection of personal data when you use the Website and interact with our services. We are committed to protecting your privacy and ensuring a transparent, trustworthy relationship with all users.
If you have questions about this Privacy Policy or our privacy practices, please contact us using the information provided in Section 14 of this policy.
2. Data Controller and Contact Information
Organisation: CRC 1550 – Molecular Circuits of Heart Disease Website: crc1550.com Data Controller: University of Heidelberg (Ruprecht-Karls-Universität Heidelberg)
Contact Details:
- Address: Eppelheimer Strasse 8, 69115 Heidelberg, Germany
- Phone: +49 (6221) 56-36113
- Email: CRC1550@uni-heidelberg.de
For privacy-related inquiries, please contact us using the above details.
3. Personal Data We Collect
3.1 Data from Contact Forms
When you use our contact form or send inquiries, we collect:
- Full name
- Email address
- Organization/Institution
- Phone number (optional)
- Subject of inquiry
- Message content
- Any additional information you voluntarily provide
3.2 Data from Job Applications
If you apply for positions through “Work With Us” section, we collect:
- Full name
- Email address
- Current position/institution
- Research interests and expertise
- Curriculum Vitae or resume
- Contact information
- Cover letter or motivation statement
- Educational background
3.3 Data from Newsletter Subscriptions
If you subscribe to our newsletter or mailing lists, we collect:
- Email address
- Full name
- Organization/Institution
- Research interests
- Preferred communication frequency
3.4 Automatically Collected Data
When you visit the Website, we automatically collect:
- Internet Protocol (IP) address
- Browser type and version
- Operating system
- Pages visited and time spent on each page
- Referring/exit pages
- Device type and screen resolution
- Geographic location (approximate)
- Clickstream data
- Cookies and similar tracking technologies (see Cookie Policy)
3.5 Data from Third-Party Integrations
The Website may include embedded content from third parties (YouTube videos, social media feeds, etc.). These providers may collect data about you according to their own privacy policies.
3.6 Event Registration Data
If you register for our conferences, seminars, or events, we collect:
- Full name
- Email address
- Affiliation/Institution
- Research field
- Dietary requirements (if applicable)
- Accessibility needs (if applicable)
- Any additional relevant information
4. Legal Basis for Data Processing
We process your personal data under the following legal bases in accordance with the GDPR:
- Consent: For newsletter subscriptions, non-essential cookies, and optional services
- Contract Fulfillment: To respond to inquiries, process job applications, and manage event registrations
- Legitimate Interests: To maintain Website functionality, conduct analytics, improve user experience, and conduct research
- Legal Obligation: To comply with applicable laws and regulatory requirements
- Public Task: As a research institution funded by the German Research Foundation (DFG)
5. Purpose of Data Processing
We use collected personal data for:
- Communication: Responding to inquiries, providing information, and establishing contact
- Job Applications: Processing applications and recruitment activities
- Event Management: Registering participants, sending event information, and post-event follow-up
- Newsletter Distribution: Sending research updates, news, and information you subscribed to receive
- Website Functionality: Ensuring the Website operates properly and securely
- Analytics: Understanding visitor behavior and improving Website experience
- Research: Using data in accordance with research protocols and ethical guidelines
- Regulatory Compliance: Meeting legal and funding requirements
- Security: Protecting the Website from unauthorized access and malicious activities
- Statistical Analysis: Creating anonymized, aggregated statistics for reporting
6. Data Sharing
We do not sell or rent personal data to third parties for commercial purposes.
We may share your data with:
- Service Providers: Third-party vendors assisting with Website operations, email delivery, analytics, and hosting. These providers are contractually bound to maintain data confidentiality.
- University Partners: Other departments and institutions within the University of Heidelberg may receive data if relevant to ongoing research or administrative functions.
- Consortium Partners: Partner institutions within CRC 1550 may receive data regarding joint research activities or collaboration, with your consent.
- Funding Agencies: The German Research Foundation (DFG) and other funding bodies may receive anonymized information required for reporting purposes.
- Legal Requirements: When required by law, court order, or regulatory authority.
- Third-Party Platforms: If you interact with embedded content (YouTube, social media), these platforms receive data according to their privacy policies.
- Research Collaborators: Anonymized data may be shared with collaborating research institutions for scientific purposes.
7. International Data Transfers
Our Website is hosted within the European Union. We comply with GDPR requirements for any international data transfers. If your data is transferred outside the EU/EEA, we implement appropriate safeguards such as Standard Contractual Clauses.
8. Data Retention
- Contact Form Submissions: Retained for 24 months or until you request deletion
- Job Applications: Retained for 12 months after application decision; unsuccessful applicants’ data is deleted unless consent is given for future opportunities
- Newsletter Subscriber Data: Retained while you remain subscribed; you may unsubscribe at any time
- Event Registration Data: Retained for 12 months after the event
- Website Analytics Data: Retained for up to 26 months
- Server Logs: Retained for up to 90 days for security purposes
- Email Communications: Retained for 12 months for service and compliance purposes
You may request data deletion at any time, subject to legal retention requirements.
9. Your Rights Under the GDPR
You have the following rights regarding your personal data:
9.1 Right of Access
You may request a copy of your personal data in a structured, commonly used, and machine-readable format.
9.2 Right to Rectification
You may request that we correct inaccurate or incomplete personal data.
9.3 Right to Erasure
You may request deletion of your personal data, subject to legal exceptions.
9.4 Right to Restrict Processing
You may request that we limit how we use your personal data.
9.5 Right to Data Portability
You may request your data in a portable format for transfer to another organization.
9.6 Right to Object
You may object to certain types of processing, including direct marketing and automated decision-making.
9.7 Right to Withdraw Consent
If we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
9.8 Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that has legal effects.
To exercise any of these rights, please contact us using the details in Section 2. We will respond within 30 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Secure HTTPS encryption for data transmission
- Regular security updates and patches
- Access controls and authentication mechanisms
- Employee data protection training
- Incident response and breach notification procedures
- Regular security audits
However, no method of transmission over the Internet is entirely secure. While we take reasonable precautions, we cannot guarantee absolute security.
11. Cookies and Similar Technologies
For detailed information about cookies used on the Website, please refer to our Cookie Policy. In summary:
- Essential Cookies: Required for Website functionality
- Functional Cookies: Enable additional features and social sharing
- Analytical Cookies: Help us understand visitor behavior
- Preference Cookies: Remember your choices
- Third-Party Cookies: From embedded services (YouTube, social media)
You can manage cookies through our cookie consent tool or your browser settings.
12. Children’s Privacy
The Website is not intentionally directed to children under 16 years of age. We do not knowingly collect personal data from children without parental consent. If we become aware that a child has provided us with personal data, we will take steps to delete it and terminate the child’s interaction with the Website.
13. Third-Party Links and Services
The Website may contain links to external websites and embedded services that are not operated by us. This Privacy Policy applies only to the Website. We are not responsible for third-party privacy practices. We encourage you to review their privacy policies before providing personal data.
14. Contacting Us
For questions about this Privacy Policy, to exercise your GDPR rights, or to report privacy concerns:
Email: CRC1550@uni-heidelberg.de
Mailing Address: CRC 1550 Project Office Eppelheimer Strasse 8 69115 Heidelberg Germany
Phone: +49 (6221) 56-36113
Data Protection Authority Complaint: If you believe we have violated your privacy rights, you may lodge a complaint with the German data protection authority (Landesbeauftragte für Datenschutz Baden-Württemberg) or your local supervisory authority.
15. Policy Updates
We may update this Privacy Policy periodically to reflect:
- Changes in our practices
- Legal requirements
- Technological advances
- Other relevant factors
Material changes will be communicated via email notification and by updating the “Last Updated” date at the top of this page.
16. Legal Compliance
This Privacy Policy complies with:
- General Data Protection Regulation (GDPR) – EU Regulation 2016/679
- German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG)
- Other applicable privacy and data protection legislation
Legal Notice: This policy is provided for informational purposes. For specific legal advice regarding data protection, please consult with a qualified legal professional specializing in privacy and data protection law.
Last Updated: November 2025 Version: 1.0 Language: English