This privacy policy applies to Discovery, the University of Erfurt’s search portal for academic literature (https://discovery.uni-erfurt.de).
The data controller within the meaning of the General Data Protection Regulation and other national data protection laws of the Member States, as well as other data protection provisions, is the University of Erfurt, represented by:
As a general rule, we process our users’ personal data only to the extent necessary to provide a fully functional website and to make our content and services available. The processing of our users’ personal data is permitted under statutory provisions (terms of use); by registering to use the library, users consent to the processing of their personal data. Users may correct or delete their data at any time (upon deregistration or termination of their user status).
The legal basis for the processing of the data is Article 6(1)(c) of the GDPR in conjunction with the Terms of Use of the Erfurt University Library dated 28 February 2018. The legal basis for the temporary storage of data in the case of anonymous use, as well as for the storage of log files, is Article 6(1)(f) of the GDPR.
The Discovery search portal gives you access to a wide range of digital resources hosted on third-party platforms. These include databases, publisher platforms and aggregators providing access to digital journals and books (e.g. ProQuest Ebook Central, SpringerLink and EBSCO). All providers are subject to the GDPR. Please check what data these third-party providers store and process before using their digital services.
Privacy policies of selected third-party providers (selection):
ReDi links (link resolver)
If an electronic full text is available, an additional button labelled ‘Go to electronic full text (ReDi)’ will appear in the search results for a title. This links to an available electronic text or a page containing further information from the service provider (ReDI, Freiburg University Library). For security reasons and to diagnose errors, the service provider stores the IP addresses and other details transmitted by the browser (Apache log files) for 7 days; otherwise, the service does not hold any personal data. Statistics on the use of the link resolver are anonymised.
scanning service For part of the collection, an additional “Scanning service” button is displayed in the search results for a title, which allows members of the University of Erfurt to request scans of parts of the work from the library. The files are made available on an internal platform (VZG Göttingen). Personal data (provided upon logging into Discovery; name, user number and email address) is transferred via an encrypted connection to a processing platform as part of the procedure and stored digitally. It is not passed on to third parties and is used solely to notify the person placing the order (order confirmation, delivery email, rejection of orders or other enquiries). The data is deleted once the process is complete.
The data subject’s personal data will also be erased or restricted as soon as the purpose for which it was stored no longer applies. Data will also be blocked or deleted when a retention period prescribed by the aforementioned standards expires, unless there is a need to continue storing the data for the purpose of concluding or fulfilling a contract.
Under the terms of the data processing agreement in accordance with Article 28 of the EU GDPR, the Joint Library Network’s central office automatically collects and stores in its server log files the information that your browser transmits when you access Discovery. This includes:
This data cannot be linked to specific individuals. It is used to analyse system security and stability, to investigate misuse and to ensure a user-friendly experience on our website. This data is not combined with other data sources; furthermore, following statistical analysis, the data is deleted regularly (after a period of 5 days). It is not passed on to third parties.
This site uses SSL encryption for security reasons and to protect the transmission of all content.
You can recognise an encrypted connection by the fact that the address bar in your browser changes from ‘http://’ to ‘https://’, and by the padlock icon in your browser’s address bar.
Cookies are small text files generated by the web server and sent to your internet browser, where they are stored or saved. Cookies are used to improve the functionality and user-friendliness of the website for you. A session cookie is created whilst you are using our website. This contains settings (e.g. language or layout selection) and titles saved to your wishlist, and is deleted when you close your browser completely. Alternatively, users can also delete these cookies themselves via their browser.
Discovery uses a proprietary system to analyse visitor traffic and activity. No personal data is stored at any time; the data is analysed solely in anonymised form. Access to this analytical data is password-protected and available to the library’s administrators. Discovery does not contain any trackers.
On the Discovery website, we offer users the option to log in by providing personal data, to manage their personal user account (OPAC), and to place orders and make reservations. The details required to log in to the user account (library card number / student identity card (thoska) number and the corresponding password) are entered into a form and stored in the browser for the duration of the session. The data is not passed on to third parties.
The user account (OPAC) contains the following personal data:
as well as details of loans, orders, reservations and fees.
Personal data is recorded in the library system (LBS) when you register as a library user (via the form) and is stored for the duration of the process. It is required for the library to provide its services. When orders and/or reservations are submitted, the relevant details are sent to us, printed on order slips and stored in the library system for the duration of the process, as well as in physical form as an insert in the relevant item.
If the option to store data on the server is selected in the ‘Settings’ tab for favourites, search history or profiles, the library card number is stored on the server in pseudonymised form. The retention period for this data is one year after the last login. The data can also be irrevocably deleted at any time by the user themselves using the ‘Delete’ button.
On the Discovery information page, as well as whenever you click the ‘i’ icon labelled ‘Questions?/Errors?’, you can contact us via the email address provided. In this case, the user’s personal data transmitted with the email will be stored. In this context, the data will not be passed on to third parties. The processing of personal data serves solely to handle the enquiry. The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected. For personal data sent by email, this is the case once the relevant correspondence with the user has been concluded. The correspondence is deemed to have been concluded when it is clear from the circumstances that the matter in question has been definitively resolved.