Privacy Policy
1. Controller responsible for data processing
Students’ Union of the University of Münster,
represented by the General Students’ Committee (AStA)
Scharnhorststraße 48
48151 Münster
Email: asta.vorsitz@uni-muenster.de
2. Purpose of data processing
We process your personal data exclusively for the purpose of social counseling and the processing of your application for financial support.
This includes information about your financial situation, personal data, as well as other relevant information required to process your application.
The Office for University Funding of the University of Münster receives access to your address data, bank details, and the justification of your emergency situation prepared by us, insofar as this is necessary for the administration of funding, the review of funding allocation, and budgetary documentation. Your personal data is processed by the AStA and stored in systems operated by Hetzner Online GmbH.
A data processing agreement pursuant to Art. 28 GDPR has been concluded with Hetzner.
3. Legal basis of processing
The processing of your personal data is based on the following legal grounds:
Art. 6(1)(e) GDPR – in conjunction with § 3 of the North Rhine-Westphalia Data Protection Act (DSG NRW) – for the performance of a task carried out in the public interest within the scope of social and financial counseling of the student body,
Art. 6(1)(b) GDPR – insofar as, in individual cases, a contractual agreement (e.g. loan or repayment agreement) is concluded with you,
Art. 6(1)(a) GDPR – insofar as you voluntarily provide additional information.
You may withdraw your consent at any time with effect for the future, without affecting the lawfulness of processing carried out prior to the withdrawal.
4. Categories of data collected:
Name, email address, telephone number
University, matriculation number, course of study
Financial information (e.g. income, debts)
Additional personal information (e.g. date of birth, marital status)
Voluntarily provided personal data (e.g. additional information on social or financial circumstances)
5. Storage period and deletion
Personal data collected as part of the ticket and application process will only be stored for as long as necessary to process the respective case and to fulfill the associated legal obligations.
After completion of the application process and fulfillment of all legal and administrative requirements, the data will generally be retained for up to three years. This period is based on the regular limitation period pursuant to § 195 German Civil Code (BGB) and serves to document proper processing and to defend against possible legal claims. Deletion currently takes place manually at defined intervals.
An automated deletion procedure is planned in the near future to ensure timely and data protection-compliant removal of data without manual intervention. If statutory retention obligations (e.g. tax or budgetary regulations) require longer storage, the relevant data will be restricted until the expiration of these periods and then deleted.
6. Recipients and hosting / data processing
Processing is primarily carried out by the responsible teams within the AStA.
Our systems are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, as a processor.
A data processing agreement pursuant to Art. 28 GDPR has been concluded with Hetzner. Hetzner processes data exclusively on instructions from the AStA and based on documented technical and organizational measures (TOMs). Data will only be disclosed to other third parties if required by law or if you have consented.
7. Data transfer to third countries
Storage and processing take place in data centers within Germany. No transfer to third countries occurs. Should this change in exceptional cases (e.g. selection of a non-EU location), this will only take place in compliance with Art. 44 et seq. GDPR (in particular standard contractual clauses/adequacy decisions). You will be informed in advance.
8. Rights of data subjects
You have the right to:
Access to the data stored about you (Art. 15 GDPR)
Rectification of inaccurate or incomplete data (Art. 16 GDPR)
Erasure of your personal data, provided no legal retention obligations apply (Art. 17 GDPR)
Restriction of processing (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Object to processing (Art. 21 GDPR)
Lodge a complaint with a supervisory authority (Art. 77 GDPR)
9. Data protection officer
The General Students’ Committee (AStA) of the University of Münster is a legally capable partial public-law entity pursuant to § 53 of the Higher Education Act NRW. A data protection officer has not been appointed. An internal data protection contact point has been established to coordinate compliance with data protection requirements:
Data protection contact point
AStA of the University of Münster
Data Protection
Schlossplatz 1
48149 Münster
Email: asta.vorsitz@uni-muenster.de
For general data protection inquiries, you may also contact the Data Protection Officer of the University of Münster:
University of Münster
Data Protection Officer
Schlossplatz 2
48149 Münster
Email: datenschutz@uni-muenster.de
10. Supervisory authority
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Email: poststelle@ldi.nrw.de
Web: https://www.ldi.nrw.de
11. Contact information
For questions or concerns regarding your personal data, you may contact us at any time, quoting your ticket number.
AStA of the University of Münster
AStA Social Counseling
Schlossplatz 1
48149 Münster
asta.soziales@uni-muenster.de
02518322281
12. Provision of data
The provision of data is required for processing your application. Without this data, the application cannot be processed.
13. Automated decision-making
No automated decision-making, including profiling, takes place.
Each application is reviewed and assessed personally by a member of the social counseling team.
14. Cookies and tracking
Technically necessary cookies:
Our ticket system uses only technically necessary cookies required for operation and provision of functions.
Consent is not required for this (§ 25(2) No. 2 TTDSG).
Use of Matomo (local web analytics)
To anonymously evaluate the use of our online services, we operate our own instance of the open-source web analytics software Matomo on the same server environment at Hetzner Online GmbH.
Matomo is configured in a privacy-friendly manner:
No use of cookies (“enforce tracking without cookies”)
IP address anonymization: the last two bytes of the IP address are removed (e.g. 192.168.xxx.xxx)
Pseudonymization of user IDs, no cross-session profiling
Browser Do-Not-Track signals are respected
No transmission to third parties or third countries
Regular deletion or anonymization of older data at defined intervals
Only pseudonymized usage data is processed.
The analysis serves exclusively for statistical improvement and system security of our online offering.
Processing is based on Art. 6(1)(e) GDPR in conjunction with § 3 DSG NRW, as it serves the performance of a task in the public interest (optimization and accessible provision of the service). No data is shared with third parties.
15. Updates to this privacy policy
This privacy policy is regularly reviewed and updated if necessary. The current version can always be found on this page.