Home/Privacy Policy

Privacy Policy

Information about how we handle your data.

Privacy Policy / Data Protection Declaration

Last updated: 27/02/2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

CISPA Helmholtz-Zentrum für Informationssicherheit gGmbH
Stuhlsatzenhaus 5
66123 Saarbrücken
Germany

Email: info@cispa.de

This platform is operated on behalf of the Helmholtz project "KI in der Verwaltung" and serves the entire Helmholtz Association. CISPA acts as the legally responsible controller for the purposes of data protection law.

2. Data Protection Officer

The Data Protection Officer of CISPA Helmholtz-Zentrum für Informationssicherheit gGmbH can be contacted at:

Data Protection Officer
CISPA Helmholtz-Zentrum für Informationssicherheit gGmbH
Stuhlsatzenhaus 5
66123 Saarbrücken
Germany

Email: datenschutz@cispa.de

3. Purpose and Nature of This Platform

HAIFlow (haiflow.de) is a community-driven knowledge and information platform for the Helmholtz Association. It provides information, references to external resources, and is accessible exclusively to registered members of the Helmholtz community.

Key characteristics of this platform:

  • No tracking or profiling
  • No web analytics tools
  • No marketing or advertising
  • No processing of personal data for third-party commercial purposes
  • Authentication via Helmholtz AAI (federated identity management)

4. Hosting and Data Processing Agreement

This platform is hosted by an external service provider on the basis of a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR:

netcup GmbH
Emmy-Noether-Str. 10
76131 Karlsruhe
Germany

netcup GmbH processes personal data exclusively on documented instructions from the controller (CISPA) and within the European Union. The company holds ISO 9001, ISO 27001, and ISO 27701 certifications. A valid DPA is in place.

When accessing the platform, the following data is automatically recorded in server log files:

  • Browser type and version
  • Operating system
  • Referrer URL
  • Hostname or IP address of the requesting device
  • Date and time of access

Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in technical security and stable operation)
Retention period: Server log data is retained for a maximum of 30 days and then deleted automatically, unless a longer retention period is required for the investigation of a specific security incident.

5. Authentication via Helmholtz AAI

Access to this platform requires authentication via Helmholtz AAI, which uses the OpenID Connect (OIDC) / OAuth2 protocol. During the login process, the following personal data is transmitted from your home organisation to this platform:

A. Data received from your home organisation (required for service provision):

  • Unique persistent user identifier (OIDC sub claim, scope: openid)
  • Name / display name (scope: profile)
  • Email address (scope: email)
  • Group memberships and access entitlements (eduperson_entitlement), used exclusively for authorisation decisions

All four attributes are technically required to provide the service: the persistent identifier and entitlements for authentication and authorisation, name and email address for user account management.

Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract / provision of the service); Art. 6 (1) lit. f GDPR (legitimate interest in secure and authenticated access)
Retention period: User account data is retained for as long as the account is active. Accounts are deleted upon request or after 18 months of inactivity.

To rectify personal data transmitted by your home organisation (e.g. name or email address), please contact your home organisation's IT helpdesk directly. This data is outside the scope of this platform's control.

6. Session Cookies

This platform uses technically necessary session cookies solely for the purpose of maintaining an authenticated session after login via Helmholtz AAI. These cookies:

  • Do not track behaviour across sessions
  • Are not shared with third parties
  • Are deleted automatically upon logout or expiry of the session token

Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in secure session management). No consent is required for technically necessary cookies (§ 25 (2) No. 2 TDDDG).

7. External Links

This platform contains links to external websites. We have no influence over the content or data processing practices of these external websites. Responsibility for data protection lies solely with the respective website operators.

8. Rights of Data Subjects

Under the GDPR, you have the following rights with respect to personal data processed by this platform:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing based on legitimate interests (Art. 21 GDPR)

To exercise any of these rights, please contact the controller or the Data Protection Officer at the addresses provided in Section 1 and 2.

You also have the right to lodge a complaint with a supervisory authority. The competent authority for CISPA is:

Unabhängiges Datenschutzzentrum Saarland
Fritz-Dobisch-Str. 12
66111 Saarbrücken
Germany
www.datenschutz.saarland.de