Auslandssemester Bali

Privacy Policy

Preamble

With the following privacy policy, we would like to inform you about the types of personal data (hereinafter also referred to simply as ‘data’) that we process, the purposes for which we do so, and the extent of such processing. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”).

The terms used are gender-neutral.

As at 5 October 2026

Table of Contents

Person in charge

First name, Surname / Company
Street, house number
Postcode, town, country

Email address: [email protected]

Overview of the treatments

The following overview summarises the types of data processed and the purposes for which they are processed, and refers to the data subjects.

Types of data processed

  • Property details.
  • Employee details.
  • Contact details.
  • Table of contents.
  • Contract details.
  • Usage data.
  • Meta, communication and procedural data.
  • Log data.

Categories of data subjects

  • Service recipients and clients.
  • Staff.
  • Prospective students.
  • Communication partner.
  • Users.
  • Third persons.
  • Tip-off.

Purposes of processing

  • Communication.
  • Security measures.
  • Audience reach measurement.
  • Tracking.
  • Target audience definition.
  • Affiliate tracking.
  • Organisational and administrative procedures.
  • Feedback.
  • Marketing.
  • Profile with user-specific information.
  • Provision of our online services and user-friendliness.
  • IT infrastructure.
  • Whistleblower protection.
  • Public relations.

Relevant legal provisions

Relevant legal bases under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country of residence or our country of incorporation. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.

  • Consent (Article 6(1), first sentence, point (a) of the GDPR) - The data subject has given their consent to the processing of their personal data for a specific purpose or for several specific purposes.
  • Fulfilment of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) - The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
  • Legal obligation (Article 6(1), first sentence, point (c) of the GDPR) - The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR) - processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests, fundamental rights and freedoms of the data subject which require the protection of personal data.

National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains, in particular, specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.

Note regarding the applicability of the GDPR and the Swiss Data Protection Act (DSG): This privacy notice serves to provide information in accordance with both the Swiss Data Protection Act (DSG) and the General Data Protection Regulation (GDPR). For this reason, please note that, due to the GDPR’s broader geographical scope and greater clarity, the terms used in the GDPR are employed here. In particular, instead of the terms ‘processing’ of ‘personal data’ used in the Swiss Data Protection Act (DSG), “overriding interest” and “personal data requiring special protection”, the terms used in the GDPR – “processing” of “personal data”, as well as “legitimate interest” and “special categories of data” – are used. However, the legal meaning of these terms continues to be determined in accordance with the Swiss Data Protection Act (DSG) within the scope of its application.

Application of data protection regulations in the country of incorporation: In the country where the controller is based, national data protection regulations apply in addition to the General Data Protection Regulation (GDPR).

Security measures

In accordance with legal requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihoods and severity of the threat to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and safeguarding the availability and segregation of the data. Furthermore, we have put procedures in place to ensure that data subjects’ rights are upheld, that data is deleted and that appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and through privacy-friendly default settings.

Securing online connections using TLS/SSL encryption technology (HTTPS): To protect users’ data transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the presence of ‘HTTPS’ in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.

Transfer of personal data

As part of our processing of personal data, it may happen that this data is transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.

International data transfers

Data processing in third countries: Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to other individuals, bodies or organisations (which can be identified by the postal address of the respective provider or if the privacy policy expressly refers to data transfers to third countries), this is always carried out in accordance with legal requirements.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the European Commission dated 10 July 2023. In addition, we have entered into standard contractual clauses with the relevant providers, which comply with the European Commission’s requirements and set out contractual obligations to protect your data.

This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, whilst the Standard Contractual Clauses serve as an additional safeguard. Should any changes arise in relation to the DPF, the Standard Contractual Clauses will act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of any political or legal changes.

For each service provider, we’ll let you know whether they’re DPF-certified and whether standard contractual clauses are in place. You can find further information on the DPF and a list of certified companies on the US Department of Commerce’s website at https://www.dataprivacyframework.gov/ (in English).

Appropriate security measures apply to data transfers to other third countries, in particular standard contractual clauses, explicit consent or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=des.

General information on data storage and deletion

We delete personal data that we process in accordance with legal requirements as soon as the underlying consents are withdrawn or there are no longer any legal grounds for processing. This applies to cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule apply where legal obligations or specific interests require the data to be retained or archived for a longer period.

In particular, data which must be retained for commercial or tax law reasons, or where storage is necessary for the purposes of legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.

Our privacy policy contains additional information on the storage and deletion of data, which applies specifically to certain data processing operations.

Where there are several specifications regarding retention periods or data erasure deadlines, the longest period shall always apply. We process data that is no longer retained for its originally intended purpose, but rather due to legal requirements or other reasons, exclusively for the purposes that justify its retention.

Start of a time limit at the end of the year: If a time limit does not expressly commence on a specific date and lasts for at least one year, it automatically begins at the end of the calendar year in which the event triggering the time limit occurred. In the case of ongoing contractual relationships under which data is stored, the event triggering the limitation period is the date on which the notice of termination or other termination of the legal relationship takes effect.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
  • Right to information: You have the right to request confirmation as to whether your personal data is being processed, as well as access to this data, further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: In accordance with legal requirements, you have the right to request that your personal data be completed or that any inaccurate personal data concerning you be corrected.
  • Right to erasure and restriction of processing: In accordance with the relevant legal provisions, you have the right to request that data relating to you be deleted without delay, or, alternatively, in accordance with the relevant legal provisions, to request a restriction on the processing of such data.
  • Right to data portability: You have the right to receive the personal data concerning you that you have provided to us, in accordance with the statutory requirements, in a structured, commonly used and machine-readable format, or to request that it be transferred to another data controller.
  • Complaint to the supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. In particular, you may lodge a complaint with a supervisory authority in the Member State of your habitual residence, your place of work or the place where the alleged infringement occurred.

Provision of the online service and web hosting

We process users’ data in order to provide them with our online services. To this end, we process the user’s IP address, which is necessary to deliver the content and functions of our online services to the user’s browser or device.

  • Types of data processed: Usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved). Log data (e.g. log files relating to logins, data retrieval or access times).
  • Target audience: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
  • Retention and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’.
  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Provision of an online service on rented server space: To provide our online services, we use storage space, computing capacity and software that we rent or otherwise obtain from a relevant server provider (also known as a ‘web host’); Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
  • Collection of access data and log files: Access to our website is logged in the form of so-called ‘server log files’. Server log files may include the address and name of the web pages and files accessed, the date and time of the request, the amount of data transferred, confirmation of a successful request, browser type and version, the user’s operating system, the referrer URL (the page visited previously) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks), and, on the other hand, to ensure server capacity utilisation and stability; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Data deletion: Log file information is stored for a maximum of 30 days and is then deleted or anonymised. Data that needs to be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.

Use of cookies

The term ‘cookies’ refers to functions that store and retrieve information on users’ devices. Cookies may also be used for various purposes, such as ensuring the functionality, security and convenience of online services, as well as analysing visitor traffic. We use cookies in accordance with legal requirements. To this end, we obtain users’ consent in advance where necessary. Where consent is not required, we rely on our legitimate interests. This applies where the storage and retrieval of information is essential to provide explicitly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online services. Consent may be withdrawn at any time. We provide clear information on the scope of this and which cookies are used.

Notes on the legal basis for data protection: Whether we process personal data using cookies depends on consent. Where consent has been given, this serves as the legal basis. Where consent has not been given, we rely on our legitimate interests, which are explained earlier in this section and in the context of the relevant services and procedures.

Retention period: With regard to storage duration, the following types of cookies are distinguished:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left an online service and closed their device (e.g. browser or mobile app).
  • Persistent cookies: Persistent cookies remain stored even after the device is switched off. This allows, for example, the user’s logged-in status to be saved and their preferred content to be displayed immediately when they visit the website again. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information on the type and storage duration of cookies (e.g. when seeking consent), they should assume that these are persistent and may be stored for up to two years.

General information on withdrawal and opting out: Users may withdraw the consents they have given at any time and may also object to the processing of their data in accordance with legal requirements, including via their browser’s privacy settings.

  • Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
  • Target audience: Users (e.g. website visitors, users of online services).
  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Consent (Article 6(1), first sentence, point (a) of the GDPR).

Further information on processing procedures, methods and services:

  • Processing of cookie data on the basis of consent: We use a consent management solution to obtain users’ consent to the use of cookies or to the procedures and providers specified within the consent management solution. This procedure serves to obtain, log, manage and revoke consents, in particular with regard to the use of cookies and similar technologies used to store, read and process information on users’ devices. As part of this procedure, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers mentioned in the consent management procedure. Users also have the option to manage and withdraw their consents. The declarations of consent are stored in order to avoid repeated requests and to be able to provide evidence of consent in accordance with legal requirements. Storage takes place on the server and/or in a cookie (known as an ‘opt-in cookie’) or by means of comparable technologies, in order to be able to associate the consent with a specific user or their device. Unless specific details regarding the providers of consent management services are available, the following general information applies: Consent is stored for up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, details of the scope of consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, the system and the end device used; Legal basis: Consent (Art. 6(1), first sentence, point (a) of the GDPR).

Contact and enquiry management

When you contact us (e.g. by post, via the contact form, by email, by telephone or via social media), and in the context of existing user and business relationships, the details provided by enquirers will be processed to the extent necessary to respond to enquiries and carry out any requested actions.

  • Types of data processed: Contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship or the time of creation). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
  • Target audience: Communication partner.
  • Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online services and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’.
  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).

Further information on processing procedures, methods and services:

  • Contact form: When you get in touch via our contact form, by email or through other communication channels, we process the personal data you provide in order to respond to and deal with your enquiry. This usually includes details such as your name, contact details and, where applicable, any further information provided to us that is necessary for us to deal with your enquiry appropriately. We use this data exclusively for the stated purpose of establishing contact and communication; Legal basis: Fulfilment of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Web analytics, monitoring and optimisation

Web analytics (also known as ‘reach measurement’) is used to analyse visitor traffic to our online platform and may include pseudonymised data on visitor behaviour, interests or demographic information, such as age or gender. With the help of reach analysis, we can, for example, identify at what times our online platform or its functions and content are used most frequently, or encourage repeat use. It also enables us to identify which areas require optimisation.

As well as web analytics, we can also use testing methods to, for example, test and optimise different versions of our online offering or its individual components.

Unless otherwise stated below, profiles – that is, data aggregated to reflect a usage session – may be created for these purposes, and information may be stored in a browser or on a device and subsequently retrieved. The data collected includes, in particular, websites visited and the features used on them, as well as technical information such as the browser used, the computer system used and details of usage times. Where users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.

In addition, users’ IP addresses are stored. However, we use an IP masking process (i.e. pseudonymisation by truncating the IP address) to protect users. Generally speaking, no personally identifiable data (such as email addresses or names) is stored as part of web analytics, A/B testing and optimisation; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.

Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
  • Target audience: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Audience measurement (e.g. traffic statistics, identification of returning visitors); profiles containing user-related information (creation of user profiles). Provision of our online services and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’. Cookies may be stored for up to two years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Google Analytics: We use Google Analytics to measure and analyse the use of our online service on the basis of a pseudonymous user identification number. This identification number does not contain any personally identifiable data, such as names or email addresses. It serves to associate analytical information with a device in order to identify which content users have accessed during one or more sessions, which search terms they have used, whether they have revisited the content, or how they have interacted with our online service. The time of use and its duration are also stored, as well as the sources from which users have accessed our online service and technical details of their devices and browsers.
    In doing so, pseudonymous user profiles are created using information gathered from the use of various devices, which may involve the use of cookies. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based equivalents). For EU data traffic, IP address data is used exclusively for this derivation of geolocation data before being deleted immediately. It is not logged, is not accessible and is not used for any other purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymisation of the IP address); Privacy Policy: https://business.safety.google/privacy/; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying adverts: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (Types of processing and the data processed).

Affiliate programmes and affiliate links

We incorporate so-called affiliate links or other references (which may include, for example, search boxes, widgets or discount codes) to the offers and services of third-party providers (collectively referred to as ‘affiliate links’) into our online platform. If users follow the affiliate links or subsequently take up the offers, we may receive a commission or other benefits from these third-party providers (collectively referred to as ‘commission’).

In order to track whether users have taken up offers via an affiliate link we have used, it is necessary for the relevant third-party providers to know that users have followed an affiliate link included within our online offering. The linking of affiliate links to the relevant transactions or other actions (e.g. purchases) serves solely the purpose of commission settlement and is deleted as soon as it is no longer required for that purpose.

For the purposes of the aforementioned allocation of affiliate links, the affiliate links may be supplemented with certain values which form part of the link or may be stored elsewhere, e.g. in a cookie. These values may include, in particular, the referring website (referrer), the time, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the relevant offer, the type of link used, the type of offer and an online identifier of the user.

Notes on legal basis: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
  • Target audience: Prospective customers. Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Affiliate tracking.
  • Retention and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’.
  • Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Social media presence

We maintain an online presence on social media platforms and, in this context, process user data in order to communicate with users active on these platforms or to provide information about us.

Please note that user data may be processed outside the European Union. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights.

Furthermore, users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on users’ behaviour and the resulting interests. These profiles may in turn be used, for instance, to display adverts both within and outside the networks that are presumed to match users’ interests. Consequently, cookies are usually stored on users’ computers, in which their usage behaviour and interests are recorded. In addition, data may also be stored in the usage profiles regardless of the devices used by users (particularly if they are members of the respective platforms and are logged in there).

For a detailed description of the respective processing methods and opt-out options, please refer to the privacy policies and information provided by the operators of the respective networks.

We would also like to point out that, in the case of requests for information and the exercise of data subjects’ rights, these can most effectively be raised with the providers themselves. Only the providers themselves have access to user data and can take appropriate action and provide information directly. Should you nevertheless require assistance, please do not hesitate to contact us.

  • Types of data processed: Contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation). Usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions).
  • Target audience: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Communication; feedback (e.g. collecting feedback via an online form). Public relations.
  • Retention and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’.
  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Instagram: A social network that allows users to share photos and videos, comment on and like posts, send messages, and follow profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://www.instagram.com; Privacy Policy: https://privacycenter.instagram.com/policy/. Basis for transfers to third countries: Data Privacy Framework (DPF).
  • Facebook pages: Profiles on the social network Facebook – The data controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data relating to visitors to our Facebook page (‘fan page’). This includes, in particular, information about user behaviour (e.g. content viewed or interacted with, actions taken) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details can be found in Facebook’s Data Policy: https://www.facebook.com/privacy/policy/s. Facebook also uses this data to provide us with statistical analyses via the ‘Page Insights’ service, which give us an insight into how people interact with our page and its content. This is based on an agreement with Facebook (‘Information about Page Insights’: https://www.facebook.com/legal/terms/page_controller_addendum), which, amongst other things, sets out security measures and the rights of data subjects. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_datas. Users can therefore submit requests for access or erasure directly to Facebook. Users’ rights (in particular the right to access, erasure, objection and the right to lodge a complaint with a supervisory authority) remain unaffected by this. Joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for any further processing, including any possible transfer to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website:https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/. Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).

Plug-ins, embedded features and content

We incorporate functional and content elements into our online offering that are sourced from the servers of their respective providers (hereinafter referred to as ‘third-party providers’). These may include, for example, graphics, videos or city maps (hereinafter collectively referred to as ‘content’).

The integration always requires that the third-party providers of this content process users’ IP addresses, as they would be unable to send the content to users’ browsers without them. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only content where the respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as ‘web beacons’) for statistical or marketing purposes. These ‘pixel tags’ enable information, such as visitor traffic on the pages of this website, to be analysed. This pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical details about the browser and operating system, referring websites, the time of the visit and further details regarding the use of our online service; it may also be linked to such information from other sources.

Notes on legal basis: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is that consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
  • Target audience: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; audience measurement (e.g. traffic statistics, identification of returning visitors); tracking (e.g. interest-based/behavioural profiling, use of cookies); target group segmentation. Marketing.
  • Retention and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’. Cookies may be stored for up to two years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
  • Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

Privacy information for whistleblowers

In this section, you will find information on how we handle data relating to individuals who make reports (whistleblowers), as well as data relating to affected and involved parties, as part of our whistleblowing procedure.

  • Types of data processed: Personal details (e.g. full name, home address, contact details, customer number, - This text area must be unlocked with a Premium licence. - premiumtext premiumtext premiumtext ); Employee details (information about staff and other individuals within an organisation – This text section must be unlocked with a Premium licence. – premiumtext premiumtext premiumtext ); Contact details (e.g. postal and email addresses or – This text section must be unlocked with a Premium licence. – premiumtext premiumtext premiumtext ); Content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship – This text section must be unlocked with a Premium licence. – premiumtext premiumtext premiumtext premiumtext premiumtext premiumtext). Usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency, device types and operating systems used, interactions with – This text section must be unlocked with a Premium licence. - premiumtext premiumtext premiumtext premiumtext premiumtext ).
  • Target audience: Beneficiaries and clients; employees (e.g. staff, applicants, temporary staff and others – This section of text must be unlocked with a Premium licence. – premiumtext premiumtext premiumtext); third parties. Whistleblowers.
  • Purposes of processing and legitimate interests: Whistleblower protection.
  • Retention and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’.
  • Legal basis: Consent (Art. 6(1), first sentence, point (a) of the GDPR); Legal obligation (Art. 6(1), first sentence, point (c) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Legal basis (Germany): Insofar as we process data to fulfil our legal obligations under the Whistleblower Protection Act (HinSchG), the legal basis for the processing is Article 6(1), first sentence, point (c) of the GDPR and, in the case of special categories of personal data, Article 9(2)(g) of the GDPR and Section 22 of the Federal Data Protection Act (BDSG), in each case in conjunction with Section 10 of the HinSchG.
  • Types of data processed: We may collect various types of data in the course of receiving and processing reports, as well as during the subsequent whistleblower procedure. This includes, in particular, the data provided by a whistleblower, such as:
    Name, contact details and location of the person providing the information,
    Names and details of potential witnesses or people affected by the report,
    Names and details of the people the message is addressed to,
    Information regarding the alleged misconduct,
    - We may collect various types of data in connection with the receipt and processing of reports, as well as during the subsequent whistleblower procedure. This includes, in particular, the data provided by a whistleblower, such as: the name, contact details and location of the person making the report; the names and details of any witnesses or individuals affected by the report; the names and details of the individuals against whom the report is directed; details of the alleged misconduct; and any other relevant details, provided that - This section of text must be unlocked with a Premium licence.
  • Special categories of personal data: We may, in the course of our activities, collect certain types of personal data, particularly where this is provided by a whistleblower.
  • Using our online forms: Please note that it is possible to submit feedback anonymously. To ensure the security of your data when using our online forms, we recommend accessing them in your browser’s ‘incognito mode’. Here’s how to open an incognito window: a) On a Windows PC: Open your browser and press Ctrl+Shift+N; b) On a Mac: Open your browser and press Command+Shift+N; c) On mobile devices: Switch to private mode via the tab menu.

     Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
  • Names to be included: You have the option to submit reports anonymously. However, unless prohibited by national legislation, we recommend that you provide your name and contact details. This enables us to investigate the report more effectively and, if necessary, to contact you directly.
    If you provide your name and contact details, your identity will be treated as strictly confidential
  • Provision of data to third parties: We will only pass on data relating to the information you have provided to third parties under certain circumstances. This will occur either a) if you have given us your express consent to do so, or b) if there is a legal obligation to pass on the data. Potential third parties include public authorities, government bodies, regulatory bodies or tax authorities, where disclosure is necessary to fulfil a legal or regulatory obligation. Furthermore, we may engage solicitors and other specialist advisers in accordance with legal provisions. They are authorised to investigate alleged misconduct and to take necessary measures following an investigation, such as initiating disciplinary or legal proceedings. Furthermore, service providers carefully selected and monitored by us may receive data for these purposes (for example, operators of a web-based reporting system). However, these service providers are contractually obliged, within the framework of a data processing agreement, to comply with the applicable data protection regulations.
  • Data retention and deletion: Personal data will only be processed for as long as is necessary to fulfil the processing purposes described above. Once this data is no longer required for the stated purposes, it will be deleted.
  • Technical and organisational measures: We have implemented the necessary contractual, technical and organisational measures to ensure the security of all data we process. Amendments and updates

We ask that you check the content of our privacy policy regularly. We will update the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.

Where we provide addresses and contact details for companies and organisations in this privacy policy, please note that these details may change over time, so please check them before getting in touch.

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Where these terms are defined by law, their statutory definitions apply. The explanations below, however, are primarily intended to aid understanding.

  • Affiliate tracking: As part of affiliate tracking, links are logged which are used by linking websites to direct users to websites offering products or other services. The operators of the respective linking websites may receive a commission if users follow these so-called affiliate links and subsequently take advantage of the offers (e.g. by purchasing goods or using services). For this to happen, it is necessary for the providers to be able to track whether users who are interested in specific offers subsequently take advantage of them as a result of the affiliate links. Consequently, for affiliate links to function properly, they must be supplemented with certain values which either form part of the link or are stored elsewhere, for example in a cookie. These values include, in particular, the referring website (referrer), the time, an online identifier for the operator of the website on which the affiliate link was located, an online identifier for the relevant offer, an online identifier for the user, as well as tracking-specific values such as, for example, advertising material ID, partner ID and categorisations
  • Staff: The term ‘employees’ refers to people who are in an employment relationship, whether as staff members, employees or in similar roles. An employment relationship is a legal relationship between an employer and an employee, established by an employment contract or agreement. It involves the employer’s obligation to pay the employee remuneration in return for the employee’s work. The employment relationship comprises various phases, including the establishment phase, during which the employment contract is concluded; the performance phase, during which the employee carries out their work; and the termination phase, when the employment relationship ends, whether through dismissal, a mutual termination agreement or otherwise. Employee data refers to all information relating to these individuals and arising in the context of their employment. This includes aspects such as personal identification details, identification numbers, salary and bank details, working hours, holiday entitlements, health data and performance appraisals.
  • Key details: Master data comprises essential information required for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include, amongst other things, personal and demographic details such as names, contact details (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between individuals and services, organisations or systems by enabling unique identification and communication.
  • Content details: Content data comprises information generated during the creation, editing and publication of all types of content. This category of data may include text, images, videos, audio files and other multimedia content published across various platforms and media. Content data is not limited to the actual content itself, but also includes metadata that provides information about the content, such as tags, descriptions, author details and publication dates.
  • Contact details: Contact details are essential pieces of information that enable communication with individuals or organisations. They include, amongst other things, telephone numbers, postal addresses and email addresses, as well as communication channels such as social media handles and instant messaging identifiers.
  • Meta, communication and procedural data: Meta, communication and procedural data are categories that contain information about how data is processed, transmitted and managed. Meta-data, also known as ‘data about data’, comprises information that describes the context, origin and structure of other data. It may include details such as file size, creation date, the author of a document and revision histories. Communication data records the exchange of information between users via various channels, such as email correspondence, call logs, social media messages and chat histories, including the individuals involved, timestamps and transmission routes. Process data describes the processes and procedures within systems or organisations, including workflow documentation, transaction and activity logs, and audit logs used to track and verify operations.
  • Usage data: Usage data refers to information that tracks how users interact with digital products, services or platforms. This data encompasses a wide range of information that reveals how users utilise applications, which features they prefer, how long they spend on specific pages, and the paths they take when navigating through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Furthermore, usage data plays a crucial role in identifying trends, preferences and potential problem areas within digital offerings
  • Personal data: ‘Personal data’ means any information relating to an identified or identifiable natural person (hereinafter referred to as the ‘data subject’); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profile with user-related information: The processing of ‘profiles containing user-related information’, or ‘profiles’ for short, encompasses any form of automated processing of personal data that involves using such personal data to identify certain personal characteristics relating to a natural person (depending on the type of profiling, this may include various information relating to demographics, behaviour and interests, such as interaction with websites and their content, etc.), or to predict them (e.g. interests in specific content or products, clicking behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
  • Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used to analyse system issues, for security monitoring or to generate performance reports.
  • Reach measurement: Audience measurement (also known as web analytics) is used to analyse visitor traffic to an online platform and can include the behaviour or interests of visitors in relation to specific information, such as website content. With the help of reach analysis, operators of online services can, for example, identify at what times users visit their websites and what content they are interested in. This enables them, for example, to better tailor the content of their websites to the needs of their visitors.
  • Tracking: The term ‘tracking’ refers to the ability to monitor users’ behaviour across multiple online platforms. As a rule, information about behaviour and interests relating to the online platforms used is stored in cookies or on the servers of the providers of tracking technologies (known as ‘profiling’). This information can then be used, for example, to show users adverts that are likely to match their interests.
  • Person in charge: The term ‘controller’ refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Production: ‘Processing’ means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, be it collection, analysis, storage, transmission or erasure.
  • Contract details: Contractual data is specific information relating to the formalisation of an agreement between two or more parties. It documents the terms under which services or products are provided, exchanged or sold. This data category is essential for the management and fulfilment of contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include the start and end dates of the contract, the nature of the agreed services or products, pricing arrangements, payment terms, termination rights, renewal options and any special conditions or clauses. It serves as the legal basis for the relationship between the parties and is crucial for clarifying rights and obligations, enforcing claims and resolving disputes.
  • Target audience: The term ‘Custom Audiences’ is used when target groups are defined for advertising purposes, such as displaying adverts. For example, based on a user’s interest in specific products or topics online, it can be inferred that this user might be interested in adverts for similar products or the online shop where they viewed those products. The term ‘Lookalike Audiences’ (or similar target groups) is used, on the other hand, when content deemed suitable is displayed to users whose profiles or interests are presumed to correspond to those of the users on whose profiles the audience was based. Cookies and web beacons are generally used for the purpose of creating Custom Audiences and Lookalike Audiences.


Privacy Policy | Study in Bali