Techno Heritage Network Techno Heritage Network

Privacy Policy

Last updated: August 12, 2026

This privacy policy explains how personal data is processed when you use www.technoheritage.com and its services.

1. Controller and Contact

Dematon | Medienbüro
Mathias Brösicke
Waldstraße 2
69168 Wiesloch
Germany
Email: mail@dematon.de

Dematon | Medienbüro is responsible for the technical operation of this website and the processing of personal data described in this policy. The Techno Heritage Network is an initiative involving Heidelberg University and the Berlin University of the Arts. Questions about data processing through the website may be sent to the controller at the address above.

2. Website Access, Hosting and Server Logs

The website and its email infrastructure are hosted by IONOS SE. When the website is accessed, technically necessary connection data may be processed, including the requested page or file, date and time, browser and operating-system information, referrer information, device type, and an Internet Protocol (IP) address in anonymised form.

The processing is necessary to deliver the website and to maintain its security and stability. It is based on Art. 6(1)(f) of the General Data Protection Regulation (GDPR). According to the information provided by the hosting provider for its web-hosting products, visitor data is retained for eight weeks.

3. Technically Necessary Session Cookie

This website uses a technically necessary session cookie, normally named PHPSESSID. It supports login sessions, protection of forms against unauthorised requests, and the secure newsletter subscription, confirmation, and unsubscribe processes.

The cookie is not used for analytics, advertising, tracking, or user profiling and is normally deleted when the browser session ends. Its use is based on Art. 6(1)(f) GDPR and, insofar as information is stored on or read from the user's device, Section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG).

4. Consent Management with CCM19

This website uses the consent-management service CCM19, provided by Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn, Germany. The CCM19 script is obtained from cloud.ccm19.de. When it is loaded, technically necessary connection data, including the visitor's IP address, may be transmitted to the provider.

CCM19 is used to display the consent interface, manage the visitor's choices, control services that require consent, and document those choices. For this purpose, CCM19 may store a consent identifier and the selected settings in a cookie, local storage, or session storage and may process the time and technical circumstances of the decision. The storage period is governed by the settings configured in CCM19. Visitors can reopen the consent interface at any time and change or withdraw their choices with effect for the future.

The use of the consent-management service is based on Art. 6(1)(c) GDPR insofar as it is required to comply with legal obligations, and otherwise on Art. 6(1)(f) GDPR. Our legitimate interest is to manage services in a privacy-compliant manner and to be able to demonstrate consent. Technically necessary storage on or access to the visitor's device is based on Section 25(2)(2) TDDDG.

Bootstrap, Bootstrap Icons, and jQuery are hosted locally on this website. Loading these libraries therefore does not establish a connection to jsDelivr, code.jquery.com, or another library CDN.

5. Bibliographic Data from Zotero

The bibliography may retrieve publicly available bibliographic records from the Zotero Application Programming Interface (API). This request is made by the website server. The visitor's IP address is therefore not intentionally transmitted to Zotero through the API request. A direct connection to Zotero is established only if a visitor follows an external Zotero link.

6. Newsletter

If you subscribe to the newsletter, we process your name, email address, consent status and time, technical confirmation and unsubscribe tokens, and the relevant creation and confirmation dates. Subscription uses a double-opt-in procedure: the subscription becomes active only after the confirmation link in the email has been deliberately confirmed.

Confirmation links expire after 24 hours. Confirmed subscriber data is retained until consent is withdrawn or the subscription is cancelled. Unsubscribing deletes the subscriber record. Newsletter emails are sent through IONOS mail infrastructure. Mailing records may contain the subject, content, recipient email address, sending status, and sending time for operational verification.

The legal basis for sending the newsletter is your consent under Art. 6(1)(a) GDPR. Consent may be withdrawn at any time by using the unsubscribe link in a newsletter. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

7. Protection Against Automated Subscriptions

To protect the newsletter form against flooding and automated abuse, the website temporarily processes the visitor's IP address and email address. These values are stored only as keyed cryptographic hash values in the rate-limit table. Accepted attempts and their times are retained for up to two days and are then deleted automatically.

This processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the newsletter service and the prevention of misuse.

8. User Accounts and Administration

User accounts are provided only to authorised editorial and administrative users. The system processes account information such as username, email address, password hash, authorisation status, and technically necessary session data. Passwords are not stored in plain text. The data is processed to operate and secure the editorial backend on the basis of Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on the user's relationship with the project and duties.

To protect the editorial login against automated password guessing and other misuse, failed login attempts are recorded temporarily. The IP address and the username or email address entered during the attempt are stored only as keyed cryptographic hash values, together with the time of the attempt. The plain IP address and the plain login identifier are not stored in this rate-limit record. Excessive failed attempts may result in the login being temporarily rejected. These security records are retained for no longer than two days and are then deleted automatically.

Password-reset requests are protected by comparable security limits. For this purpose, keyed cryptographic hash values derived from the IP address, the submitted login identifier and, for an existing account, its email address are stored together with the time and technical result of the request. This prevents repeated reset emails without storing these values in plain text. Excessive requests may be rejected temporarily. The rate-limit records are deleted automatically after no more than two days.

This security processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to protect editorial accounts, website data, and the technical infrastructure against unauthorised access and automated attacks.

Account data is retained for as long as the account is required and is deleted or anonymised when the authorisation ends, unless statutory or security-related retention obligations apply.

9. Submissions and Editorial Content

When information is submitted for collections, activities, publications, blog posts, or related editorial records, the website processes the information entered in the relevant form. This may include names, institutional affiliations, contact details, descriptive texts, web and social-media links, images, image credits, and other content supplied for publication.

Information identified as publication content may be displayed publicly after editorial review and activation. Contact details used solely for communication or confirmation are not intended for publication unless this is apparent from the form or has been agreed. Pending submissions may use confirmation and deletion links. Editorial data is retained for the duration of the documentation and research purpose; deletion requests are assessed against legal, academic, archival, and documentation requirements.

10. Recipients and External Links

Personal data may be processed by the hosting and email provider, the consent-management provider described in Section 4, and authorised members of the editorial team where necessary for the purposes described above.

Ordinary external links to third-party websites, including social-media platforms, YouTube, Digital Object Identifier (DOI) services, and Zotero, do not by themselves establish a connection to those providers. A connection is established only when the link is followed. The CCM19 consent-management script described in Section 4 is loaded automatically when the page is displayed. The privacy rules of the respective third party apply to subsequent processing by that provider.

11. Retention

Personal data is retained only for as long as required for the relevant purpose or by law. The specific periods described above apply where available. Where no fixed period has been defined, necessity is reviewed according to the purpose, contractual or institutional requirements, security needs, and applicable statutory retention obligations.

12. Legal Bases

Depending on the processing activity, the legal bases are consent under Art. 6(1)(a) GDPR, contractual or pre-contractual necessity under Art. 6(1)(b) GDPR, compliance with legal obligations under Art. 6(1)(c) GDPR, and legitimate interests under Art. 6(1)(f) GDPR. The applicable basis is specified in the relevant sections above.

13. Your Rights

Subject to the applicable legal requirements, you have the right to request access to and rectification or erasure of your personal data, restriction of processing, data portability, and to object to processing. Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

You also have the right to lodge a complaint with a data-protection supervisory authority. The supervisory authority responsible for the controller is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.

14. Automated Decision-Making

No automated decision-making or personal profiling within the meaning of Art. 22 GDPR takes place. Automated security limits may temporarily reject excessive newsletter requests, login attempts, or password-reset requests but do not produce legal or similarly significant effects.

15. Changes to This Policy

This privacy policy may be updated when the website, its services, or the applicable legal requirements change. The current version is published on this page.

Initiated by
Berlin University of the Arts Heidelberg University
© 2026 Techno Heritage Network. All rights reserved.