Privacy Policy for Our Website
We place a high priority on the responsible handling of personal data. Protecting your privacy and safeguarding the confidentiality and integrity of your personal data are of paramount importance to us. We process personal data exclusively with due care, for specific purposes, and in accordance with applicable data protection regulations. To this end, we have implemented appropriate technical and organizational measures to ensure an adequate level of protection when processing personal data.
In this Privacy Notice, we explain what personal data we process, for what purposes, and on what legal basis, as well as what rights you have in connection with the processing of your personal data.
Name and Address of the Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:
Doggenriedstraße 70
88250 Weingarten
Germany
Phone: +49 (0) 751/501-9344
Email: info@rwu.de
Contact Information for the Data Protection Officer
You can contact the data protection officer of the data controller using the following contact information:
Benedict Lenz
EXACON Prüf- und Sachverständigengesellschaft mbH
Untere Gallusstraße 34
88677 Markdorf
Phone: +49 (0) 7544 912982
Email: dsb@rwu.de
General Information on Data Processing
Legal Bases for the Processing of Personal Data
In accordance with Article 13 of the GDPR, we hereby inform you of the legal bases for our data processing activities. Unless the legal basis is expressly stated in the respective privacy notices, the following applies: The legal basis for processing based on consent is Article 6(1)(a) of the GDPR in conjunction with Article 7 of the GDPR. The legal basis for processing necessary to fulfill a contract or to take steps prior to entering into a contract is Article 6(1)(b) of the GDPR. This applies in particular where processing is necessary to provide our services or to process related inquiries. The legal basis for processing necessary to comply with a legal obligation is Article 6(1)(c) of the GDPR. To the extent that the vital interests of the data subject or another natural person necessitate the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis. To the extent that public authorities process personal data to perform a task carried out in the public interest or in the exercise of official authority, the legal basis is generally Article 6(1)(e) of the GDPR in conjunction with the relevant statutory basis. To the extent that processing is necessary to protect our legitimate interests or those of a third party, and the interests, fundamental rights, and fundamental freedoms of the data subjects do not override those interests, Article 6(1)(f) of the GDPR serves as the legal basis. This does not apply to processing carried out by public authorities in the performance of their duties.
Data Erasure and Retention Period
We adhere to the principles of data minimization pursuant to Article 5(1)(c) of the GDPR and storage limitation pursuant to Article 5(1)(e) of the GDPR. We store your personal data only for as long as is necessary to achieve the purposes stated here or as required by the retention periods prescribed by law. Once the respective purpose no longer applies or once these retention periods have expired, the corresponding data will be deleted as soon as possible.
External Links
This website may contain links to third-party websites or to other websites under our control. If you follow a link to a website outside our control, please note that these websites have their own privacy policies. We assume no responsibility or liability for these external websites or their privacy policies. Therefore, before using these websites, please check whether you agree with their privacy policies.
You can recognize external links either by their color, which is slightly different from the rest of the text, or by the fact that they are underlined. Your cursor will highlight external links when you move it over them. Your personal data is only transmitted to the link’s destination once you click on an external link. In doing so, the operator of the other website receives, in particular, your IP address, the time at which you clicked the link, the page on which you clicked the link, and additional information that you can find in the privacy policy of the respective provider.
Please also note that certain links may result in data being transferred outside the European Economic Area. This could allow foreign authorities to gain access to your data. You may not have any legal recourse against such access to your data. If you do not want your personal data to be transmitted to the link’s destination—or, worse still, to be exposed to unauthorized access by foreign authorities—please do not click on any links.
Your Rights as a Data Subject
Data subjects may contact the data controller or the data protection officer directly with any questions regarding data protection and the processing of their personal data.
Right of Access (Art. 15 GDPR)
You may request information about your stored data.
Right to Rectification (Art. 16 GDPR)
You may request that inaccurate data be corrected.
Right to erasure (Art. 17 GDPR)
You may request that we erase your data, provided that the legal requirements for doing so are met.
Right to Restriction of Processing (Art. 18 GDPR)
You may request that we restrict the processing of your data, provided the legal requirements are met.
Right to Data Portability (Art. 20 GDPR)
To the extent technically feasible, you have the right to receive your data in a structured, machine-readable format.
Right to Object (Art. 21 GDPR)
You may object at any time to the processing of your data for reasons arising from your particular situation, provided that the processing is based on Art. 6(1)(e) or (f) GDPR.
Right to Withdraw Consent (Art. 7(3) GDPR)
If you have given your consent todata processing, you may withdraw it at any time with future effect. Withdrawal does not affect the lawfulness of processing carried out on the basis of your consent prior to the withdrawal. Please direct your withdrawal to the contact information provided for the Data Protection Officer or the data controller.
Timeframes for Complying with Data Subjects’ Rights
We generally strive to respond to all requests within 30 days. However, this timeframe may be extended for reasons related to the specific right of the data subject or the complexity of your request.
Website Hosting (Web Host)
Our website is hosted by:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
When you visit our website, we automatically collect and store information in so-called server log files. Your browser automatically transmits this information to our server or to the server of our hosting provider.
This includes:
- The IP address of the website visitor’s device
- Device used
- Hostname of the accessing computer
- The visitor’s operating system
- Browser type and version
- Name of the file accessed
- Time of the server request
- Amount of data
- Information on whether the data retrieval was successful
This data is not combined with other data sources.
Instead of hosting this website on our own server, we may also have it hosted on the server of an external service provider (hosting company), which we have listed above in this case. The personal data collected by this website is then stored on the hosting company’s servers. In addition to the data mentioned above, the web host also stores on our behalf, for example, contact inquiries, contact information, names, website access data, metadata and communication data, contractual data, and other data generated through the website.
The legal basis for processing this data is Article 6(1)(f) of the GDPR. Our legitimate interest is the technically error-free display and optimization of this website. If the website is accessed for the purpose of entering into contract negotiations with us or concluding a contract, this serves as an additional legal basis (Article 6(1)(b) of the GDPR). In the event that we have engaged a hosting provider, a data processing agreement is in place with this service provider.
Use of Local Storage Items, Session Storage Items, and Cookies
Our website uses local storage items, session storage items, and/or cookies. Local storage is a mechanism that enables data to be stored within the browser on your device. This data typically includes user preferences, such as a website’s “day” or “night mode,” and remains stored until you manually delete it. Session storage is very similar to local storage, except that the data is stored only for the duration of the current session—that is, until you close the current tab. After that, the session storage items are deleted from your device. Cookies are pieces of information that a web server (a server that provides web content) stores on your device to identify that device. They are either stored temporarily for the duration of a session (session cookies) and deleted after you leave a website, or stored permanently (permanent cookies) on your device until you delete them yourself or your web browser deletes them automatically.
These objects may also be stored on your device by third-party companies when you visit our site (third-party requests). This enables us, as the operator, and you, as a visitor to this website, to use certain third-party services that are integrated into this website. Examples include the processing of payment services or the display of videos.
These mechanisms have a wide range of applications. They can improve a website’s functionality, manage shopping cart features, enhance the security and convenience of website use, and perform analyses of visitor traffic and behavior. Depending on the specific functions, these must be classified in accordance with data protection laws. If they are necessary for the operation of the website and intended to provide specific functions (such as the shopping cart feature) or serve to optimize the website (e.g., cookies to measure visitor behavior), their use is based on Article 6(1)(f) of the GDPR. As the website operator, we have a legitimate interest in storing local storage items, session storage items, and cookies to ensure the technically flawless and optimized provision of our services. In all other cases, local storage items, session storage items, and cookies are stored only with your explicit consent (Article 6(1)(a) of the GDPR).
To the extent that local storage items, session storage, or cookies are used by third-party companies or for analytical purposes, we will inform you of this separately within this Privacy Notice. Your required consent will be requested and may be revoked at any time.
Use of External Services
External services are used on our website. External services are third-party services that are integrated into our website. This may be done for various reasons, such as embedding videos or ensuring the security of the website. When using these services, personal data is also transferred to the respective providers of these external services. If we do not have a legitimate interest in using these services, we will obtain your consent—which you may revoke at any time—as a visitor to our website prior to their use (Art. 6(1)(a) GDPR).
Web Analytics and Audience Measurement
Nature and Purpose of Processing
To analyze the use of our website, we process—subject to your consent—personal data from website visitors. The purpose of the processing is to gather information about the use and reach of our website in order to improve its technical functionality, stability, security, and user-friendliness, and to further develop its content in line with user needs.
Processing generally takes place in aggregated and statistical form. In particular, we evaluate information regarding which areas of our website are accessed and how frequently, which pages users enter from, how long individual pieces of content are viewed, and how users navigate within the website. The purpose of this processing is not to conduct a targeted analysis aimed at directly identifying individual persons.
The information obtained through web analytics is not used to target individuals for advertising purposes and is not used to create independent personality profiles. To the extent that analytics tools provide technical functions for recognizing end devices, this is done exclusively for the statistical analysis of recurring usage and not for the creation of personalized profiles.
Legal Basis
The processing of personal data in the context of web analytics and audience measurement is based exclusively on consent pursuant to Art. 6(1)(a) of the GDPR. Without such consent, no processing for the stated purposes will take place. Consent may be revoked at any time with future effect. Consent may be revoked by changing your consent or cookie settings on this website. To do so, you may access and adjust the relevant settings at any time. Revoking consent prevents further processing of personal data for the purposes of web analytics and audience measurement. The lawfulness of the processing carried out up to the time of revocation remains unaffected.
Consequences of Withholding Consent
The provision of personal data for the purposes of web analytics and audience measurement is voluntary. Without your consent, no processing for these purposes will take place. Use of the website is generally possible even without consent to web analytics; however, certain functions or displays may be limited if they rely on aggregated analyses for the purpose of optimizing the website.
Automated Decision-Making
We do not use any automated decision-making processes within the scope of web analytics and audience measurement as defined in Article 22 of the GDPR. We do not automatically make decisions that have legal effects or similarly significant adverse effects on data subjects.
Please note that the analytics tools used for web analytics may involve automated processing, particularly for the statistical analysis of usage data or the compilation of aggregated reports on the use of our website. These automated processing activities serve exclusively for analysis and evaluation purposes and do not result in automated decisions with legal effects on individual persons. We have no direct influence over the specific processing procedures of the respective providers. Further information on this can be found in the privacy policies of the respective analytics tools used.
Sentry
We use the Sentry service on our website. The provider of this service is Functional Software, Inc., 45 Fremont Street, 8th Floor, CA 94105, San Francisco, USA.
Use of the service may result in data being transferred to a third country (the U.S.). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.
Further information can be found in the provider’s privacy policy at the following URL: https://sentry.io/privacy/.
Consent Management
To comply with data protection requirements, we use a consent management tool on our website. We use this tool to obtain the necessary consent for setting cookies or using external services. The consents are stored.
The processing is necessary for compliance with a legal obligation to which the controller (website operator) is subject. Therefore, the legal basis for the processing is Article 6(1)(c) of the GDPR.
Cookiebot
We use the Cookiebot service on our website. The service provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. Further information can be found in the provider’s privacy policy at the following URL: https://www.cookiebot.com/de/privacy-policy/.
Content Management System
A content management system enables the creation, editing, organization, and presentation of digital content. We use a content management system to create content for our website. This allows us to design a more appealing website.
We base this processing on a legitimate interest (Art. 6(1)(f) GDPR).
Our legitimate interest lies in the technically flawless presentation and optimization of the website.
Storyblok
We use the Storyblok service on our website. The service provider is Storyblok GmbH, Peter-Behrens-Platz 2, Linz, AT 4020, Austria. Further information can be found in the provider’s privacy policy at the following URL: https://www.storyblok.com/legal/privacy-policy.
Job Portal
To publish job postings or link to them, we have integrated elements from job portals into our website.
Data processing will only take place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6(1)(a) GDPR). Without your consent, data processing as described above will not take place. If you withdraw your consent (e.g., via the consent banner or other options provided on this website), we will cease this data processing. The lawfulness of the processing carried out up to the time of withdrawal remains unaffected.
BITE Applicant Manager
We use the BITE Applicant Manager service on our website. The provider of this service is BITE GmbH, Filchnerstraße 16, 89231 Neu-Ulm, Germany.
Further information can be found in the provider’s privacy policy at the following URL: https://www.b-ite.de/legal-notice.html.
Automated Decision-Making
Automated decision-making within the meaning of Art. 22 of the GDPR does not take place. Should we use automated decision-making procedures in individual cases in the future, we will provide separate notice of this to the extent required by law.
Competent Supervisory Authority: LfDI BW
We take your concerns and rights very seriously. However, if you believe that we have not adequately addressed your complaints or concerns, you have the right to file a complaint with a competent data protection authority.
The State Commissioner for Data Protection and Freedom of Information
P.O. Box 10 29 32
70025 Stuttgart
Phone: 07 11/61 55 41-0
Fax: 07 11/61 55 41-15
Additional Privacy Notices
Here you will find a clear and organized overview of the privacy notices regarding data processing at Ravensburg-Weingarten University of Applied Sciences.
Aktuelles
Benachrichtigung über eine Datenschutzverletzung gemäß Art. 34DSGVO
Kompromittierte E-Mail-Postfächernach Phishing-Angriff vom 04.09.2026 | CaseID#576689
Am 04.09.2026 20:50 wurde uns folgende Datenschutzverletzung bekannt, über welche wir Sie fristgerechtinformieren.
Art der Verletzung
Im Rahmen eines mutmaßlichen Phishing-Angriffs auf E-Mail-Konten von Hochschulangehörigen haben sich unberechtigte Dritte Zugriff auf mehrere E-Mail-Postfächer der Hochschule Ravensburg-Weingarten verschafft. Die erlangten Zugangsdaten wurden unter anderem dazu genutzt, über die betroffenen Konten Phishing- bzw. Spam-E-Mails zu versenden. Durch den unberechtigten Zugriffauf die E-Mail-Postfächer kann nicht ausgeschlossen werden, dass personenbezogene Daten, die im Rahmen der E-Mail-Kommunikation verarbeitet wurden, von den Angreifern eingesehen oder gesichert wurden. Typischerweise können dabei insbesondere folgende Datenarten betroffen sein:
- Persönliche Identifikationsdaten (z. B. Namen, Funktionsbezeichnungen)
- Kommunikationsdaten (E-Mail-Adressen)
- Inhalte der E-Mail-Kommunikation einschließlich projekt- oder studienbezogener Informationen
- E-Mail-Anhänge, die organisatorische, verwaltungsbezogene oder projektbezogene Inhalteenthalten
Potentiell betroffene Personen:
- Mitglieder und Angehörige der Hochschule
- Externe Personen, mit denen über das betroffene E-Mail-Konto kommuniziert wurde
- Externe Empfänger der versandten Phishing-/Spam-E-Mails
Name und Kontaktdaten des Verantwortlichen
Rektor Professor Dr.-Ing. Thomas Spägele
Hochschule Ravensburg-Weingarten
Doggenriedstraße 70
88250 Weingarten
E-Mail: info@rwu.de
Telefon: +49 (0) 751/501-9344
Name und Kontaktdaten des Datenschutzbeauftragten
Benedict Lenz
EXACON Prüf- und Sachverständigengesellschaft mbH
Untere Gallusstraße 34
D - 88677 Markdorf
E-Mail: dsb@rwu.de
Telefon: +49 (0) 7544 912982
Folgende Maßnahmen wurden zur Abmilderung bzw. Behebung der Datenschutzverletzung gesetzt
Benachrichtigung der Betroffenen
Die betroffenen Personen werden über den Datenschutzvorfallinformiert. Zudem erfolgt eine Sensibilisierung derHochschulangehörigen für Phishing- und Social-Engineering-Angriffesowie Hinweise zu sicheren Verhaltensweisen im E-Mail-Verkehr, ummögliche Folgerisiken zu reduzieren.
Meldung des Vorfalls an diezuständigeDatenschutzaufsichtsbehörde
Der Datenschutzvorfall wurde an die zuständigeDatenschutzaufsichtsbehörde gemeldet. Dadurch wurdesichergestellt, dass der Vorfall transparent dokumentiert ist unddurch die Aufsichtsbehörde geprüft werden kann.
Sperrung des kompromittierten E-Mail-Kontos und Vergabe neuerZugangsdaten
Das Passwort des kompromittierten E-Mail-Kontos wurde geändert,um einen weiteren Zugriff auf dieses durch die Hacker zuverhindern.
Technische Analyse desbetroffenen E-Mail-Postfachs
Das betroffene E-Mail-Postfach wurde technisch überprüft, um denUmfang des Vorfalls besser einschätzen zu können und festzustellen, ob und in welchem Umfang unberechtigte Zugriffe erfolgt sind. Die Analyse diente zudem dazu, weitere Sicherheitsrisiken auszuschließen.
Eine Analyse hat ergeben, dass voraussichtlich ein hohes Risiko für die persönlichen Rechte undFreiheiten natürlicher Personen besteht:
- Risiko Identitätsdiebstahl oder -betrug
- Risiko Rufschädigung
- Risiko Berufsgeheimnis
- Risiko Kontrollverlust
Mögliche Folgen für betroffene Personen
Es kann nicht ausgeschlossen werden, dass unberechtigte Dritte vor der Unterbindung des Zugriffs Inhalte der kompromittierten E-Mail-Postfächer eingesehen oder gesichert haben. Dadurch besteht die Möglichkeit, dass personenbezogene Daten, vertrauliche Kommunikationsinhalte oder Dokumente weiterhin unbefugt verwendet werden.
Ein wesentliches Risiko besteht insbesondere darin, dass die erlangten Informationen für weitere gezielte Angriffe genutzt werden. Denkbar sind etwa täuschend echt wirkende Phishing-E-Mails, die an frühere Kommunikation, bekannte Ansprechpartner oder persönliche bzw. organisatorische Kontexte anknüpfen. Da die kompromittierten Konten zudem zum Versand von Phishing- bzw. Spam-Nachrichten über legitime Hochschul-E-Mail-Adressen genutzt wurden, können solche Nachrichten bei den Empfängern einen erhöhten Vertrauensgrad entfalten.
Dadurch besteht insbesondere das Risiko, dass weitere Personen auf entsprechende Nachrichten hereinfallen, schädliche Links aufrufen, Dateianhänge öffnen oder Zugangsdaten bzw. Passwörter gegenüber Dritten preisgeben. In der Folge können weitere Benutzerkonten kompromittiert und wiederum für neue Phishing- oder Betrugsversuche genutzt werden.
Diese Risiken können insbesondere dann erhöht sein, wenn betroffene Personen
- schadhafte Links oder Dateianhänge in E-Mails öffnen,
- Zugangsdaten oder Passwörter ungewollt gegenüber Dritten preisgeben oder
- auf echt wirkende Nachrichten reagieren, die unter Verwendung legitimer Hochschul-E-Mail-Adressenversandt wurden.
Sonstige Informationen für Betroffene
Betroffenen wird empfohlen, im täglichen E-Mail-Verkehr erhöhte Wachsamkeit walten zu lassen. Insbesondere sollte auf ungewöhnliche oder unerwartete Nachrichten, abweichende Absenderadressen sowie auf ungewohnte Formulierungen oder Inhalte geachtet werden.
Bei Unsicherheiten sollte stets geprüft werden, ob der angezeigte Name des Absenders zur tatsächlichen Absender-E-Mail-Adresse passt. Abweichungen oder unplausible Kombinationen können ein Hinweis aufeinen betrügerischen Versand sein. Auch E-Mails, die einen ungewöhnlichen Kontext haben oder sich nichteindeutig einer bekannten Kommunikation zuordnen lassen, sollten kritisch hinterfragt werden.
Typische Merkmale von Phishing- oder Social-Engineering-Angriffen sind unter anderem:
- Aufforderungen zu sofortigem Handeln („Bitte klicken Sie umgehend…“, „Ihr Konto wird gesperrt…“),
- das Erzeugen von Zeitdruck oder Dringlichkeit,
- die Aufforderung, Links zu öffnen, Dateien herunterzuladen oder Zugangsdaten preiszugeben.
Links oder Dateianhänge aus verdächtigen E-Mails sollten nicht geöffnet werden. Zugangsdaten, Passwörter oder sonstige vertrauliche Informationen sollten grundsätzlich nicht per E-Mail weitergegeben werden.
Sofern Zweifel an der Echtheit einer Nachricht bestehen oder Auffälligkeiten festgestellt werden, wirdempfohlen, die E-Mail nicht zu beantworten und den Vorfall an die zuständigen Stellen der Hochschule zu melden.
Diese Hinweise dienen der Sensibilisierung für Phishing- und Social-Engineering-Angriffe sowie der Reduzierung möglicher Folgerisiken im Zusammenhang mit dem beschriebenen Vorfall.
Contact & People
Responsible Authorities
Ravensburg-Weingarten University of Applied Sciences
Represented by the Rector, Prof. Dr.-Ing. Thomas Spägele
Doggenriedstraße
88250 Weingarten
Tel. +49 751 501-9344
Email: info@rwu.de
Website: www.rwu.de
DATA PROTECTION OFFICER
Benedict Lenz
EXACON Prüf- und Sachverständigengesellschaft GmbH
Untere Gallusstraße 34
88677 Markdorf
Email: dsb@rwu.de
Data Protection Coordination at RWU