Privacy Policy
This notice explains how your personal data is processed when you use the enquiry and contact forms on professionals.uni-munich.de (the MUDT Professional Centers), in accordance with Regulation (EU) 2016/679 (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG).
This page is a technically separate offering from the MUDT main website at uni-munich.de. The processing on the main website is governed by its own privacy notice, available at uni-munich.de/privacy-policy.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Eduvest GmbH
operating Munich University of Digital Technologies & Applied Sciences (MUDT)
Otto-Hahn-Ring 6, Building 75
81739 Munich, Germany
Phone: +49 160 590 07 70
Email: info@uni-munich.de
Represented by the Managing Directors Dirk Lamottke and Tarek Kallel. Further details are set out in the Imprint.
2. Data protection contact
For all questions concerning the processing of your personal data, please contact dataprivacy@uni-munich.de (postal address as above, marked "Data Protection").
MUDT has not appointed a Data Protection Officer, as it is below the threshold for a mandatory appointment under Section 38(1) BDSG. Data protection matters are overseen internally and reachable via the contact above.
3. What data we process
When you submit one of the enquiry forms, we process:
- The details you enter: name, work email, company, and depending on the form your role, area of interest, number of participants and your message.
- Technical data recorded automatically with your submission: your IP address, browser identifier (user agent), the referring page, and the date and time. This is used to handle the request and to detect and prevent misuse of the form.
You decide which details to provide. Only an email address or a message is technically required to send an enquiry.
4. Purpose and legal basis
- Handling your enquiry and taking steps at your request prior to a possible contract - Art. 6(1)(b) GDPR.
- Our legitimate interest in receiving, documenting and responding to enquiries and in keeping the form secure against spam and abuse - Art. 6(1)(f) GDPR.
5. Email notification
When a form is submitted, our server sends the content of your submission by email to the MUDT mailbox that handles Professional Centers enquiries, so that we notice your request quickly and can reply to it. This email contains the details you entered together with the technical data listed in section 3. If you provided an email address, it is also set as the reply address so that our answer reaches you directly.
The message is transmitted over an encrypted connection (TLS). Where the receiving mailbox is operated by a provider other than our hosting provider, that provider processes the message on our behalf as described in section 6.
6. Hosting, content delivery and recipients
Your submission is stored as an entry in a protected log file and, as described in section 5, delivered to our enquiry mailbox. Both are accessible only to the MUDT team handling Professional Centers enquiries. Our website and this log are hosted by Contabo GmbH (Aschauer Strasse 32a, 81549 Munich, Germany) on servers located within the European Union. Contabo processes data on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
The enquiry mailbox is operated on Microsoft 365, provided by Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland), acting as our processor under the Microsoft Products and Services Data Protection Addendum pursuant to Art. 28 GDPR. Mailbox content is stored within the European Union under Microsoft's EU Data Boundary commitment. Access by Microsoft personnel outside the EU for support purposes cannot be fully excluded; such transfers are covered by the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (under which Microsoft is certified) and by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
The site is delivered through the content delivery network of Cloudflare, Inc., acting as our processor. To deliver, cache and secure the site, Cloudflare processes connection data such as your IP address (Art. 6(1)(f) GDPR) and may set a strictly necessary security cookie. As Cloudflare, Inc. is based in the United States, a transfer of connection data to a third country cannot be fully excluded; such transfers are covered by the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (under which Cloudflare is certified) and by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. We do not sell your data and do not use it for advertising.
7. Retention
We keep your enquiry and any related correspondence only for as long as needed to handle your request and any resulting engagement, and delete it afterwards, unless statutory retention periods apply - for example commercial or tax retention obligations of up to 10 years under the German Commercial Code (HGB) and Fiscal Code (AO), where an enquiry leads to a contract or commercial correspondence. Technical log entries (including the IP address) are routinely deleted after 90 days; the same applies to the notification emails described in section 5, which contain the same technical data.
8. Cookies, tracking and external links
This website itself sets no cookies and uses no analytics, advertising or cross-site tracking. Its fonts are served locally, so no third-party font or script requests are made while you browse. Our content delivery provider (Cloudflare) may set a strictly necessary security cookie to protect the site; this does not track you across other websites and requires no consent under Section 25(2) TDDDG.
The social media links in the footer (Facebook, Instagram, YouTube, LinkedIn, TikTok) are plain hyperlinks. Simply visiting this site transfers no data to those platforms; data is exchanged with them only once you click a link and leave our site.
9. Security of processing
We apply appropriate technical and organisational measures (Art. 32 GDPR), including transport encryption (TLS) both for all data exchanged with the site and for the internal transmission of the notification emails, access on a need-to-know basis, protection of the enquiry log and the enquiry mailbox against direct access, and staff confidentiality.
10. Your rights
Under the GDPR you have the right to:
- access to your personal data (Art. 15);
- rectification (Art. 16) and erasure (Art. 17);
- restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21).
To exercise these rights, contact dataprivacy@uni-munich.de. We will respond within one month of receipt (Art. 12(3) GDPR); this period may be extended by up to two further months for complex requests, in which case we will inform you.
11. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the EU member state of your residence, place of work or the place of the alleged infringement. The authority responsible for us is:
Bayerisches Landesamt fuer Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
Phone: +49 981 180093-0
www.lda.bayern.de
12. Changes to this policy
We may update this notice as our services or the legal requirements change. The current version always applies.
Last updated: July 2026