Privacy Policy
1. Controller
The controller within the meaning of Article 4(7) of the General Data Protection Regulation (“GDPR”) is:
European Science Communication Institute (ESCI) gGmbH, Lindenstraße 87
26123 Oldenburg, Germany, Phone: +49 441 779 222 80
Email: info@esci.eu
3. General information on the processing of personal data
We process personal data to the extent necessary to provide and secure this website, respond to enquiries and – after obtaining the relevant consent – carry out statistical website analytics.
The applicable legal framework includes, in particular, the General Data Protection Regulation, the German Federal Data Protection Act (BDSG) and Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).
Personal data is deleted or anonymised once the relevant processing purpose no longer applies, unless statutory retention obligations, the establishment or defence of legal claims or overriding legitimate grounds justify further storage. The applicable principle of storage limitation is set out in Article 5(1)(e) GDPR.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. We also do not carry out profiling within the meaning of Articles 4(4) and 22 GDPR.
4. Hosting and server log files
The website is hosted by:
Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp
Germany
Mittwald processes personal data generated in connection with hosting on our behalf. This processing is governed by a data processing agreement pursuant to Article 28 GDPR.
When the website is accessed, technically necessary connection and access data is processed. This may include: IP address; date and time of access; requested page or URL; requested hostname; referrer URL; browser type and user agent; operating system; protocol used; HTTP status code; and amount of data transferred.
The processing is necessary to deliver the website and ensure its functionality, stability and security. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our website and the detection and prevention of technical attacks.
According to the hosting provider, IP addresses are stored in anonymised form in the access logs. The anonymised access logs are retained for 60 days. Error logs may contain the accessing IP address and, depending on the error, the requested page. Error logs are deleted after seven days.
5.1 Cookies and comparable technologies
Our website uses cookies and, where applicable, comparable technologies through which information is stored on a user’s terminal equipment or information already stored on that equipment is accessed.
Where such storage or access is strictly necessary to provide the website or a function expressly requested by you, it is based on Section 25(2) no. 2 TDDDG. Depending on the relevant purpose, the associated processing of personal data is based on Article 6(1)(f) or Article 6(1)(c) GDPR.
Non-essential cookies and comparable technologies are used only after you have given your consent. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future pursuant to Article 7(3) GDPR. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. You may review and change your selection at any time via the “Cookie Settings” link in the footer of our website.
5.2 Real Cookie Banner
We use the WordPress plugin “Real Cookie Banner Pro” to obtain, manage and document your consent choices.
The plugin is operated locally within our WordPress installation. According to the plugin provider, consent choices are stored in the database of our WordPress installation and are generally not transmitted to the plugin provider.
The following information may be processed to document your selection: a pseudonymous consent ID or UUID; a shortened and hashed IP-related value; the services and service groups selected; the version of the cookie banner used; the date and time of the decision; the page on which the decision was made; the button selected and technical information relating to the display of and interaction with the banner.
The consent choice is documented to comply with our accountability and evidential obligations under Articles 5(2) and 7(1) GDPR. The legal basis for the associated processing is Article 6(1)(c) GDPR.
The cookie or information used to remember your selection is stored on the basis of Section 25(2) no. 2 TDDDG because it is necessary to provide your selected privacy settings.
Your selection is stored until the validity period of the relevant cookie expires, you change your selection or a change to the cookie banner requires your selection to be requested again. Server-side consent records are retained for as long as necessary to comply with the evidential obligation under Article 7(1) GDPR and to defend against possible legal claims. They are subsequently deleted or anonymised.
6. Privacy-friendly website analytics using Matomo
We use Matomo Cloud to statistically analyse the use of our website. Matomo Cloud is provided by InnoCraft Ltd., 7 Waterloo Quay, PO Box 625, 6140 Wellington, New Zealand (“InnoCraft”). Our Matomo Cloud instance is available at esci.matomo.cloud.
When Matomo is activated, your browser establishes a connection to our Matomo Cloud instance. Depending on the content accessed and the configuration of the service, the following information may be processed: the page and page title accessed; the date and time of the page view; the previously visited page or referrer; general technical information concerning the browser, operating system and device; language and screen resolution; downloads and outbound links; and the IP address technically transmitted when the connection is established.
We have configured Matomo not to set analytics cookies. The absence of analytics cookies does not prevent the processing of the analytics information described above.
We have enabled IP anonymisation. The IP address is anonymised before it is stored in the analytics database. The full IP address is not stored permanently and is not used by us for precise geolocation or the long-term recognition of individual website visitors. We do not use Matomo User IDs or use the analytics data to create cross-website or cross-device user profiles.
InnoCraft processes the analytics data on our behalf. We have concluded a data processing agreement with InnoCraft pursuant to Article 28 GDPR. According to InnoCraft’s current information, customer data in Matomo Cloud is hosted using Amazon Web Services in Frankfurt, Germany, with backups stored in Dublin, Ireland.
InnoCraft is established in New Zealand. Personal data may therefore be transferred to or accessed from New Zealand. The European Commission has recognised New Zealand as providing an adequate level of data protection. The transfer is therefore based on the adequacy decision pursuant to Article 45 GDPR.
We use Matomo to understand the general use and reach of our website and to improve the content offered.
Matomo is activated only after you have consented to the “Statistics” category in our consent banner. Before consent is given, no analytics data is transmitted to Matomo Cloud. The legal basis for the processing of personal data is Article 6(1)(a) GDPR. Where information is stored on or accessed from your terminal equipment as part of the technical measurement, the additional legal basis is Section 25(1) TDDDG.
You may withdraw your consent at any time with effect for the future pursuant to Article 7(3) GDPR by changing your selection via the “Cookie Settings” link. Following withdrawal, Matomo will no longer be activated during future visits.
Detailed visitor data is automatically deleted after 90 days. Aggregated statistical reports that no longer permit individual website visits or visitors to be identified may be retained for as long as they are required for project evaluation and reporting purposes.
Further information is available in InnoCraft’s Matomo Cloud Privacy Policy:
https://matomo.org/matomo-cloud-privacy-policy/
7. Security and Login Protection (Kadence Security)
We use the WordPress plugin “Kadence Security” (formerly “Solid Security”) to protect our website against unauthorised access, malicious requests and brute-force attacks. The enabled security functions include local brute-force protection, firewall rules, the blocking of suspicious or abusive access, two-factor authentication for authorised WordPress user accounts, security logging, lockout notifications and the enforcement of encrypted HTTPS connections.
When a security-relevant event occurs, the following data may be processed: IP address; date and time; requested URL; user agent; referrer and other request-header information; the username or user ID used in a login attempt, where applicable; login success or failure; the security rule or module triggered; and information concerning a lockout or ban. Normal page views are not entered in the plugin’s security logs unless they trigger a security rule or another security-relevant event.
Local brute-force protection and the firewall rules are used to identify and block repeated failed login attempts and suspicious requests. Depending on the number and type of security events, access associated with an IP address or username may be temporarily blocked. IP addresses or user-agent strings may also be added to a ban list, including for a longer period in the case of repeated security events.
Two-factor authentication applies only to persons with an authorised WordPress user account. When authentication through a time-based one-time password is used, the authentication code is generated by the user’s authenticator application. The corresponding authentication secret is stored in encrypted form in our WordPress database. Depending on the authentication methods enabled for the relevant account, authentication codes sent by email or backup codes may also be used.
Security log entries are stored in the database of our WordPress installation. According to the current configuration, these log entries are automatically deleted after 60 days. Information relating to a temporary lockout is retained until the lockout expires. Entries in the ban list are retained for as long as necessary to maintain the relevant ban and are deleted when the ban is lifted or is no longer required. The continued necessity of longer-term bans is reviewed periodically. Two-factor authentication data is retained for as long as two-factor authentication remains active for the relevant account and is deleted when two-factor authentication is disabled or the account is deleted, unless further retention is required by law.
If a user account or IP address is blocked for security reasons, designated website administrators may receive an email notification. Such notifications are processed through the email service used by us. Further information about the recipients of personal data is provided in Section 10 of this Privacy Policy.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interests are protecting the confidentiality, integrity and availability of our website and IT systems, preventing unauthorised access and detecting and defending against attacks and misuse. These measures also support compliance with the security requirements set out in Article 32 GDPR.
Security logs are stored within our WordPress installation hosted by Mittwald. Access is restricted to authorised administrators and the service providers identified in this Privacy Policy. Information about data subject rights, including the right to object under Article 21 GDPR, is provided in Section 13.
8. Contact by email
If you contact us by email, we process the data you provide. This may include, in particular, your email address, name, message content and associated communications and metadata. The purpose of the processing is to deal with and respond to your enquiry.
Where the enquiry concerns the conclusion or performance of a contract, the legal basis is Article 6(1)(b) GDPR.
In other cases, the processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to respond appropriately to enquiries received.
Hosting, email and IT service providers engaged by us may have access to communications data for technical processing purposes. Where these service providers act exclusively on our instructions, they are engaged on the basis of a data processing agreement pursuant to Article 28 GDPR.
We generally delete the data once your enquiry has been finally dealt with and further storage is no longer required. Statutory retention duties, in particular under Section 257 of the German Commercial Code (HGB) or Section 147 of the German Fiscal Code (AO), remain unaffected where they apply to the particular communication.
9. Locally hosted fonts
This website uses locally hosted fonts. The font files are loaded exclusively from our own server. When the fonts are loaded, no connection is established to servers operated by Google or other external font providers.
10. Recipients of personal data
Within ESCI, access to personal data is restricted to authorised persons who require the data for the purposes described in this Privacy Policy.
Depending on the relevant processing activity, external recipients or processors may include:
- Mittwald CM Service GmbH & Co. KG as our hosting provider;
- email service providers used for communication and security notifications; and
- IT service providers engaged to maintain, support and secure the website.
Where these service providers process personal data exclusively on our instructions, they are engaged on the basis of a data processing agreement pursuant to Article 28 GDPR.
Personal data may also be disclosed to public authorities, courts or other recipients where this is required by law, necessary for the establishment, exercise or defence of legal claims, or otherwise permitted under applicable data protection law.
11. International data transfers
According to the current technical configuration, personal data processed in connection with the operation of this website is not transferred to recipients in countries outside the European Union or the European Economic Area.
Should we introduce a service that involves the transfer of personal data to a third country, such transfers will take place only in accordance with Articles 44 et seq. GDPR. Where required, we will provide information about the relevant recipient, the third country concerned and the applicable transfer mechanism before the service is used
12. Retention periods
Where no specific retention period is stated in this Privacy Policy, we retain personal data only for as long as necessary for the relevant processing purpose.
The data is subsequently deleted or anonymised unless statutory retention obligations, the establishment, exercise or defence of legal claims or other overriding legitimate grounds justify further storage. Articles 5(1)(e) and 17 GDPR apply.
13. Rights of data subjects
Subject to the statutory requirements, you have the following rights in particular:
- the right of access under Article 15 GDPR;
- the right to rectification under Article 16 GDPR;
- the right to erasure under Article 17 GDPR;
- the right to restriction of processing under Article 18 GDPR;
- the right to data portability under Article 20 GDPR;
- the right to object under Article 21 GDPR; and
- the right to withdraw consent with effect for the future under Article 7(3) GDPR.
Where you object, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or Article 6(1)(f) GDPR, we will generally cease processing the personal data concerned. Further processing is permissible only where we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or where processing is necessary for the establishment, exercise or defence of legal claims. This follows from Article 21(1) GDPR.
You may exercise your rights by contacting us using the contact details provided in Section 1 or Section 2.
14. Right to lodge a complaint
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. This right may be exercised, in particular, in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
The supervisory authority with local jurisdiction over ESCI is:
The State Commissioner for Data Protection of Lower Saxony
(Der Landesbeauftragte für den Datenschutz Niedersachsen)
Prinzenstraße 5
30159 Hannover
Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: https://www.lfd.niedersachsen.de
15. Requirement to provide data
The transmission of technical connection data is necessary for the website to be provided. Without this data, the website cannot be delivered.
When contacting us, you generally decide which information to provide. Without the information required to deal with your enquiry, we may be unable to respond.
This information is provided pursuant to Article 13(2)(e) GDPR.
16. Amendments to this Privacy Policy
We will update this Privacy Policy if the website, the services used, the technical configuration or the applicable legal requirements change.
Last updated: 31 July 2026.