Privacy Policy

Effective: 26/06/2022

1. Controller

The party responsible (“controller”) for data processing is:
Deutscher Akademischer Austauschdienst e.V.
(German Academic Exchange Service)
Kennedyallee 50
53175 Bonn
Contact: datenschutz@daad.de

2. Data Protection Officer

You can reach our data protection officer at:
Dr Gregor Scheja
Scheja & Partners GmbH & Co. KG
Adenauerallee 136
D-53113 Bonn
Telephone: +49 (0)228 2272260
Contact: https://www.scheja-partner.de/en/contact/contact.html

3. Your Rights as a Data Subject

As a data subject, you have the following rights under the General Data Protection Regulation (GDPR) insofar as the relevant statutory requirements are met:

Access: You are entitled to receive information about processed data concerning you.

Rectification: You can request that incorrect data concerning you be corrected. Furthermore, you can request that incomplete data be completed.

Erasure: In certain cases, you may request that your personal data be deleted.

Restriction of processing: In certain cases, you may request that the processing of your data be restricted.

Data portability: If you have provided us with data on the basis of a contract or a declaration of consent, you can request that you receive the data you provided in a structured, commonly-used and machine-readable format or that this information be sent to a different controller.

Right to Object

Case-specific right to object

You have the right to object at any time – on grounds relating to your particular situation – to the processing of personal data concerning you which is carried out on the basis of Art. 6, section 1 (e) of the GDPR or Art. 6, section 1 (f) of the GDPR; this also applies to profiling based on this provision. These personal data will then no longer be processed for these purposes unless it can be demonstrated that compelling, legitimate grounds exist for such processing which override your interests, rights and freedoms, or if such processing is required for the raising, exercise or defense of legal claims. To make use of your right to object, please use the contact details specified in clause 2.

Right to object to data processing for the purposes of direct marketing

In certain individual cases, your data may be processed for direct marketing purposes. You have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising. This also applies to profiling to the extent that it is related to such direct marketing. Where you object to data processing for the purposes of direct marketing, your personal data will no longer be processed for these purposes.

Withdrawal of consent: If you have given your consent to the processing of your data, you can withdraw this consent at any time with future effect. However, this does not affect the lawfulness of any processing of your data conducted prior to your withdrawal of consent. In addition to the procedures detailed under “Asserting your rights”, you can also declare your withdrawal under the terms of the relevant information in “Exercise of withdrawal” in the “Services & cookies” section.

Asserting your rights: In order to exercise any of the rights specified above, please send an email to datenschutz@daad.de or get in contact by post using the address specified above under Point 1. When you do so, please make sure that we can clearly identify you.

Right to appeal: You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your usual residence, place of work or place of the alleged infringement if you believe that the processing of your personal data is unlawful.

4. Automated Individual Decision-Making, Including Profiling

Automated individual decision-making, including profiling as defined by Article 22 of the GDPR do not take place in connection with the use of our service.

5. Details on Services, Cookies, etc.

5.1 Our Services

5.1.1 General

  1. a) Description of service:
  • Data categories: Date and time of access, length of visit, type of device, operating system used, functions used, volume of data sent, type of event, IP address, domain name
  • Purpose(s): Provision of service
  • Legal basis/bases: Article 6, section 1 (b and f) of the GDPR
  • Legitimate interests pursued if applicable: Technical operability
  • Recipients or categories of recipients: Internal departments, hosting provider, external service provider for technical support
  • Third-country transfers, adequacy decision (yes/no): yes – USA
  • Safeguards and access possibilities to those: AWS complies with GDPR requirements through EU Standard Contractual Clauses and appropriate technical and organizational measures; AWS is certified under the Data Privacy Framework
  • Storage periods or criteria for their determination: Immediately following delivery by web server
  • Duty to provide personal data and potential consequences of failure to provide: No obligation to provide, automated collection by calling up the service
  • Exercising the right to object:
  • Data sources: Direct collection when calling up the website/service
  1. b) Log files:
  • Data categories: Accessed URL, IP address of user, time and date of access, volume of data transmitted, website from which the user accesses the requested page (referrer), websites accessed by the user’s system through our website, http status, information about browser type and version used, user’s operating system, user’s Internet service provider
  • Purpose(s): Statistical analyses, website improvement, system security (e.g. preventing misuse), error diagnosis
  • Legal basis/bases: Article 6, section 1 of the GDPR
  • Legitimate interests pursued if applicable: See purposes
  • Recipients or categories of recipients: Internal departments, hosting provider, external service provider for technical support, government agencies on request
  • Third-country transfers, adequacy decision (yes/no): yes – USA
  • Safeguards and access possibilities to those: AWS complies with GDPR requirements through EU Standard Contractual Clauses and appropriate technical and organizational measures; AWS is certified under the Data Privacy Framework
  • Storage periods or criteria for their determination: 7 days after creation
  • Duty to provide personal data and potential consequences of failure to provide: No obligation to provide, automated collection by calling up the service
  • Exercising the right to object:
  • Data sources: Direct collection when calling up the website/service

5.1.2 Personalized Use of ConnectING Portal

  1. a) Registration for ConnectING portal:
  • Data categories: First name, last name, email address, password, user ID
  • Purpose(s): Registration for ConnectING portal, user authentication, account management and communication with the DWIH New Delhi team specifically for the use of the portal
  • Legal basis/bases: Article 6, section 1 (b) of the GDPR
  • Legitimate interests pursued if applicable:
  • Recipients or categories of recipients: Internal departments, hosting provider, external service provider for technical support
  • Third-country transfers, adequacy decision (yes/no): yes – USA
  • Safeguards and access possibilities to those: AWS complies with GDPR requirements through EU Standard Contractual Clauses and appropriate technical and organizational measures; AWS is certified under the Data Privacy Framework
  • Storage periods or criteria for their determination: After the user has deleted their account and a DAAD employee has carried out a manual check to ensure that no further DAAD services are linked to the account
  • Duty to provide personal data and potential consequences of failure to provide: Registration is not possible without providing the data
  • Exercising the right to object:
  • Data sources: Direct collection upon registration
  1. b) ConnectING – Submission of cooperation projects and funding programmes:
  • Data categories:
    • Funding programmes:
      • Funded by (selection: European/EU organisation, German and Indian organisation, German organisation, Indian organisation)
      • Programme title
      • Funding Organisation 1 – mandatory (name, external link, logo)
      • Funding Organisation 2 – optional (name, external link, logo)
      • Research field (selection from predefined list)
      • Brief description of the programme and its objectives
      • Eligibility of the institution
      • What can be funded
      • Beneficiary (selection: Undergraduate, Graduate, Postgraduate, PhD scholars, Faculty/Academicians, Administrative staff)
      • Funding duration (selection: Under 3 months, 3-6 months, 6-12 months, 1-3 years, 3-5 years)
      • Grant amount with currency selection (EUR/USD/INR)
      • Application deadline
      • Application link
      • Contact information (title, first name, family name, designation, institution, email address)
    • Cooperation Projects:
      • Name of the research project
      • Project/reference website
      • Project logo
      • Areas of research project (selection from predefined list)
      • Leading institution of the cooperation project (institution name, external link, address, country, city)
      • Cooperation partner institutions – Partner institution 1 – mandatory (institution name, external link, address, country, city – multiple partners can be added)
      • Short description of the project
      • Project duration (selection: Under 3 months, 3-6 months, 6-12 months, 1-3 years, 3-5 years)
      • Total grant received with currency selection (EUR/USD/INR)
      • Grant-awarding institution (multiple institutions can be added)
      • Contact information (title, first name, family name, designation, institution, email address)
  • Purpose(s): Offering of public information about research collaborations and funding opportunities; administrative review and approval before publication
  • Legal basis/bases: Article 6, section 1 (b) of the GDPR
  • Legitimate interests pursued if applicable:
  • Recipients or categories of recipients: Internal departments (including administrators for review), hosting provider (Amazon Web Services – AWS), external service provider for technical support, all public visitors of the portal (including unregistered users) after approval — specifically, the contact information including email address provided in the submission will be publicly visible.
  • Third-country transfers, adequacy decision (yes/no): yes – USA
  • Safeguards and access possibilities to those: AWS complies with GDPR requirements through EU Standard Contractual Clauses; AWS is certified under the Data Privacy Framework
  • Storage periods or criteria for their determination: In principle, deletion after the user has removed the data or deleted the account. Approved projects and programmes remain publicly visible until removed by the submitter or administrator.
  • Duty to provide personal data and potential consequences of failure to provide: Mandatory fields marked with “*” are required for submission. Without this information, the submission cannot be processed. Please note that contact information provided in submissions, including your email address, will be publicly visible to all website visitors once the submission is approved. By submitting, you acknowledge and consent to this public display of your contact details.
  • Exercising the right to object:
  • Data sources: Direct collection in user profile submission forms

Note: All submitted research projects and funding programmes are subject to administrative review and approval before being published on the portal. Once approved, this information becomes publicly visible to all portal visitors without the need for registration. This includes the contact person’s name, designation, and email address, which will be displayed publicly so that any visitor can directly contact the person who submitted the project or funding programmes without requiring a portal account.

5.2 Cookies

We use cookies on ConnectING to provide you with an extensive range of functions, to make our portal more user-friendly and to optimise our platform. Cookies are small text files that are generated by a web server and stored on your computer by the web browser used during your online session.

We use what are known as session cookies. These are automatically deleted when you terminate your browser session.

We also use persistent cookies for the primary purpose of being able to provide permanent, recurring settings to you as a visitor to our website. This allows us to customize our website in accordance with your individual preferences. Persistent cookies also permit us to perform analyses of a visitor’s usage behaviour, but only for as long as the cookie remains valid.

This website uses Google Analytics with the extension “_anonymizeIp()”. This has the effect of truncating IP addresses before further processing.

In addition, other cookies (third-party cookies) may be stored in connection with your use of specific third-party services by the providers of those services.

You can configure the browser settings on your device to prevent the storage of cookies if you do not want them to be used. Please be aware that the functionality and functional scope of our platform may be restricted as a result. Furthermore, we will then only use certain cookies after obtaining your prior consent (see below). You may also avail yourself of special options to opt out of the use of certain cookies (see below). Please refer to the information contained in the following tables for extensive details on the type, scope, purposes, legal bases and opt-out options with regard to data processing in connection with these cookies.

This website uses social plug-ins from LinkedIn. A Shariff solution has been implemented on our website. When you call up our website, data is not automatically sent to the relevant social media. When you click on a social media button, your browser connects to the server of the relevant social network. We have no influence on the scope of data collected by the social media operators.

Further information about data protection policies:

LinkedIn: https://www.linkedin.com/legal/privacy-policy

If you do not want social media to collect data via our website, do not click on the relevant buttons. You can also block social plug-ins via browser add-ons.

5.4 Map Service

This website uses the map service Google Maps, operated by Google Inc. When you access a page that includes Google Maps, your browser connects directly with the Google servers. If you do not wish Google to collect, process or use data about you via our website, you can disable JavaScript in your browser settings. However, you will not be able to use the map display. Further details can be found in the Google Privacy Policy.

5.5 Links to Third-Party Websites

Websites and services by other site owners linked to this website are designed and supplied by third parties. We have no influence on the design, content or function of third-party services. Third-party sites may have their own cookies and data collection practices. We have no influence over this. You may wish to obtain more information directly from the owners of third-party websites.

6. Recipients of Personal Data

Internal recipients: Within the DAAD, access is limited to persons requiring it for the purposes specified under clause 5.

External recipients: We only share your personal data with external recipients outside the DAAD if this is required for managing or processing your request, if there is some different legitimate permission or if you have given us your consent for this purpose.

  1. a) Processors
    External service providers we use for the provision of services.
  2. b) Public bodies
    Public authorities and state institutions to which we need to send personal data for mandatory legal reasons.
  3. c) Private bodies
    Cooperation partners and assistants, to whom data is transmitted on the basis of consent or a mandatory requirement.

7. Data Processing in Third Countries

If data is transmitted to bodies that have their head offices or data-processing locations outside EU member states and outside states forming part of the EEA, we ensure before disclosure that those bodies either have your adequate consent or they provide an adequate level of data protection (for instance, through an adequacy decision taken by the European Commission, through suitable guarantees such as the agreement of standard EU contractual clauses with the recipient). You can request from us a list of recipients in third countries and a copy of the provisions that have been agreed in each case. To do so, please use the contact details given in clause 1.

8. Retention Period

You will find the retention period for personal data in the relevant chapter on data processing. We generally apply the rule whereby we only save your personal data for as long as they are required to fulfil their purposes or – if you have given your consent – until you withdraw your consent. If you withdraw your consent, we erase your personal data, unless further processing is permitted under the relevant applicable statutory provisions. We also erase your personal data if we are under an obligation to do so on legal grounds.

9. Update Status

The latest version of this data protection statement shall be applicable. Last updated: 4th September 2026