Privacy notice
Last updated: 21 September 2026
With this notice, Bielefeld University fulfils its duties under Articles 13 and 14 of the General Data Protection Regulation (GDPR) for the website sp-szenarien.de: which personal data is processed when you visit the pages and when you subscribe to the newsletter, for what purpose, on which legal basis, for how long, and which rights you have. The terms “personal data”, “processing”, “controller” and “processor” are used as defined in Article 4 GDPR.
It applies to the public website at sp-szenarien.de in both languages and to its preview at stage.sp-szenarien.de. It does not apply to the editorial area that authors use after signing in at sp-szenarien.de/intern; that area has its own privacy policy, which you will find there.
1. Controller
The controller within the meaning of the GDPR is Bielefeld University, a public-law corporation with legal capacity maintained by the State of North Rhine-Westphalia, represented by its Rector.
Universität Bielefeld
Universitätsstraße 25
33615 Bielefeld, Germany
Phone: +49 521 106-00
E-mail: post@uni-bielefeld.de
Responsible unit
Medizinische Fakultät OWL, Referat Studium und Lehre
Dr. phil. Tim Peters, MME
E-mail: tim.peters@uni-bielefeld.de
Phone: +49 521 106-67431
Data protection officer
Data Protection Officer of Bielefeld University
By post via the university address
Phone: +49 521 106-5225
E-mail: datenschutzbeauftragte@uni-bielefeld.de
2. Principles
This website presents the E-SPARRING project of the Medical School OWL, the standard for role scripts of simulated persons, and the catalogue of scenarios written to it. For providing the pages, the legal basis is Article 6 (1) (e) GDPR in conjunction with Section 3 (1) of the North Rhine-Westphalia Data Protection Act (DSG NRW) and Section 3 of the North Rhine-Westphalia Higher Education Act (HG NRW): informing the public about the university’s research and teaching. You receive the newsletter only with your consent.
The website uses no analytics, tracking or advertising services and loads no third-party content: no fonts, scripts, maps or videos from other servers. The pages are generated when the website is built and can be read without JavaScript. There is no contact form and no registration. No profiling takes place, and no automated decisions within the meaning of Article 22 GDPR are made. Data is passed on only to the service providers named below, and only as described there.
3. Visiting the website
Access data
Each time a page is requested, the server necessarily processes connection data: the IP address of your device, date and time, the address requested, the address of the page you came from if your browser sends it (referrer), your browser identifier (user agent), the status code of the response, the amount of data transferred and the processing time. This information is kept in the server’s system log and serves operational security, troubleshooting and the defence against attacks. It is not evaluated to trace your behaviour and is deleted after 14 days at the latest. The legal basis is Article 6 (1) (e) GDPR in conjunction with Section 3 DSG NRW and the duty to ensure the security of processing under Article 32 GDPR.
To protect against overload, the server counts requests per IP address in memory for a short time; for newsletter subscriptions, this means at most one subscription per address and minute. Nothing of this count is stored.
Cookie and local storage
The website sets no cookie for reading its pages. If you choose a colour scheme in the footer (light, dark, as the system), your browser remembers this choice in local storage under the name “vsp-theme”; the entry never leaves your device. The language is part of the page address and is not stored.
This website sets no further cookie. The colour scheme is strictly necessary for the function you explicitly requested (Section 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG); no consent is required, which is why there is no cookie banner.
4. Newsletter
On the home page you can subscribe to our newsletter. It reports on the progress of the project, on changes to the standard for role scripts and on new scenarios in the catalogue. The only data processed for this is your e-mail address; we do not ask for a name and do not need one.
Subscription uses double opt-in: after your entry we send a message with a confirmation link to the address you gave. Only when you open it do we add you to the list. The link works once and expires after seven days; only a checksum of it is stored, from which the link cannot be reconstructed. If you do not confirm, the subscription is deleted once that period has passed. This makes sure that nobody can enter someone else’s address.
The legal basis is your consent (Article 6 (1) (a) GDPR). We store your e-mail address, the time of the subscription, the time of the confirmation and which page you subscribed from; the two times are the record of consent required by Article 7 (1) GDPR. The data is kept until you unsubscribe.
You can withdraw your consent at any time with effect for the future (Article 7 (3) GDPR). Every newsletter message contains an unsubscribe link for this; it leads to a page where you enter your address, and you then receive a message with a confirmation link. This second step is the same as when subscribing and is there for the same reason: otherwise somebody else could unsubscribe you. You can also simply write to us. After unsubscribing you receive no further messages; your address remains on record as unsubscribed, so that we can show that and when you withdrew, and so that it is not entered again by mistake.
The subscription field contains a field that is invisible to you and that people cannot fill in. If it is filled in nonetheless, we discard the subscription without sending any mail; this detects automated submissions without our passing data to a third-party service. The website’s reply is always the same — it does not reveal whether an address is already on our list.
5. Contact by e-mail
The website lists the e-mail addresses of its contact persons. If you write to us directly, your address, the content of your message and the time are processed in Bielefeld University’s e-mail system in order to answer your enquiry. The legal basis is Article 6 (1) (e) GDPR in conjunction with Section 3 DSG NRW and Section 3 HG NRW. Messages are kept for as long as necessary to deal with your enquiry and are deleted in accordance with the university’s retention rules.
6. Links to other websites and information about persons
The pages link to third-party services, such as the university’s directory of persons and publications via doi.org. Nothing is loaded from them while you read. If you follow a link, the destination learns at most that you came from sp-szenarien.de, not from which page; the privacy notice of the respective provider then applies.
The “Team” page and the footer show the name, function, work e-mail address and phone number of staff members, with a portrait where available. This information comes from the university’s directory of persons, is maintained there by the persons themselves and is copied when the website is built; a portrait appears only if the person has released it in the directory. The legal basis is Article 6 (1) (e) GDPR in conjunction with Section 3 DSG NRW and Section 18 DSG NRW.
The “Involvement” page lists the names and institutions of the members of the student advisory board and the expert panel. They are named with their consent (Article 6 (1) (a) GDPR); no contact details and no portraits are shown. Consent can be withdrawn at any time with effect for the future; the name is then removed the next time the website is built.
7. Service providers and recipients
Hosting
The website and its server run on a virtual machine of IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, in the Berlin data centre. The database is reachable only from the machine itself; all external connections are encrypted. A backup of the database, and thus of the newsletter list, is made daily and kept for seven days. A data processing agreement under Article 28 GDPR is in place with IONOS.
Mail delivery
We send the mail of this website through AhaSend, a service of Aha Labs Inc. with servers in the European Union. Transmitted are the recipient address, the subject and the content of the message as well as technical delivery reports; AhaSend processes them solely in order to deliver the mail. A data processing agreement under Article 28 GDPR is in place with the provider. We delete the content of a sent message from our outbox after delivery; what remains is the note that and when it was delivered.
Other recipients
Data is not disclosed to any other third parties unless we are legally obliged to do so.
8. Your rights
Towards Bielefeld University you have the right of access to the data stored about you (Article 15 GDPR), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18) and to data portability (Article 20). Where processing is based on Article 6 (1) (e) GDPR, you may object to it at any time on grounds relating to your particular situation (Article 21 GDPR). You may withdraw any consent given at any time with effect for the future (Article 7 (3) GDPR). To do so, contact the responsible unit or the data protection officer, both named above.
When you merely visit the website, we store nothing that identifies you as a person: the access data carries only an IP address and is deleted after 14 days. We cannot identify you in it (Article 11 GDPR); if you nevertheless wish to exercise your rights, tell us what allows an attribution, for example your IP address and the time of your visit. If you have subscribed to the newsletter, your e-mail address is enough.
You also have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The authority responsible for Bielefeld University is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
(State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
Phone: +49 211 38424-0
E-mail: poststelle@ldi.nrw.de
Web: www.ldi.nrw.de
9. Changes to this notice
This notice describes the state of the website as of the date given above. When functions that process personal data are added, it will be updated before they are enabled. The current version is always available at this place.