Privacy Policy

Data Privacy Statement

Our data privacy statement, sets out how we handle personal data. We are aware of the importance to users of how personal data are handled and we assure you that we observe all relevant legal requirements. We consider the protection of your privacy to be of paramount importance. For this reason, compliance with the legal requirements on data privacy is, for us, a matter of course.

HSBA Hamburg School of Business Administration gGmbH
Willy-Brandt-Straße 75, 20459 Hamburg

Data Protection Commissioner
You can contact our data protection officer at datacontrol(at)

Personal Data
Personal data refers to any information about personal or factual circumstances of an identified or identifiable person. This includes information and details such as your name, home address or other postal address, telephone number and also your e-mail address.

Legal Basis
Your data are handled according to the following legal provisions:
– With regard to data communicated in forms, etc. with your consent, Art. 6(1) (a) GDPR
– With regard to services you use for the performance of a contract , Art. 6(1)(b) GDPR
– Otherwise, with particular regard to statistical data and online identifiers based on legitimate interests, Art 6(1)(f) GDPR (see below)

Legitimate Interests
When handling your data, we pursue the following legitimate interests:
– Improving our service
– Protecting against misuse
– Statistics

Data Sources
Unless otherwise specified, we obtain the data from you (including via devices used by you).

Data Transfer to Third Countries
Data are transferred to third countries outside the European Union. This is done on the basis of contractual regulations stipulated by law that ensure appropriate protection of your data and that are available for you to view on request.

Retention Period
We retain your data,
– if you have consented to this as part of processing, until such time as you withdraw your consent,
– if we need the data to undertake an agreement, until such time as the contractual relationship with you ceases or legal retention periods expire,
– if we use the data on the basis of a legitimate interest, until such time as your overriding interest obliges us to delete or anonymise them.

Purposes of Use
Personal data will only be collected by us to the extent and for the purpose for which you provide the data to us, e.g. for registration.  

We use and store your personal data as part of our services for the following purposes only if you have provided us with your express consent:

Sending of Newsletters, Access to the Study Place Exchange and Mailings
In individual cases, you will also be asked for an informed declaration of consent, e.g. if you need the following personal information:
Customer surveys, customer care, offering new products, generating customized customer information, creating customer profiles

We create user profiles based on your login data and use these profiles and the information they contain, provided by you, also for the following purposes:

To communicate with customers about orders, products, services, and marketing offerings, to update records, maintain customer accounts, to recommend products or services that customers might be interested in, others

Further Information on Newsletters and the Study Place Exchange
Users can register on the website for subscription to various newsletters and for the Study Place Exchange. We store salutation, first name, surname, e-mail address, possibly company, browser information (referring domain, URL, country of the visitor, mobile use, website language, browser language, pagefunnel) and interests in products such as degree programmes incl. academic year or Executive Education offerings. Specifically for the use of the Study Place Exchange credentials (email address, password, creation date, last login) are stored. Registration is only possible after acceptance of the data protection regulations of HSBA. The data is recorded in the CRM system of the HSBA.

Registration for the newsletter and the Study Place Exchange take place with the double-opt-in procedure. Each newsletter contains an unsubscribe link. Cancellations and deletion requests can be sent to datacontrol(at)

Further information on the HSBA Talent Finder
The HSBA Talent Finder is a tool for matching Job & Master prospects with potential employers. When registering for the tool, the following user data is stored on the website and transferred to a CRM system: title, first name, last name, email address, company name, consent to privacy policy. The tool may only be used by partner companies of the HSBA and prospective students who have already applied to a HSBA study programme. The prospective students can independently determine which information they want to make available to potential employers. The potential employers commit themselves to a careful handling of the personal data of the prospective students. In particular, the potential employers agree not to disclose personal information to third parties.

Further Information on Events
When registering for an event, the following user data are stored on the website and transferred to a CRM system: title, first name, last name, email address, number of registrations, consent to the privacy policy, and optional remarks, title, company, position and Sign up for the newsletter. If the event is subject to a charge, the address, student status and a declaration of commitment are also recorded.

Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on our websites. This service is provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Irland („Google“).
reCAPTCHA is used to check whether the data entered on our website (such as on a contact form) has been entered by a human or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, how long the visitor has been on the website). Data processing is based on Art. 6 (1) (f) DSGVO. The website operator has a legitimate interest in protecting its site from abusive automated crawling and spam. As part of the use of Google reCAPTCHA, personal data can also be transmitted to the servers of Google LLC. in the US.
In the event of the transfer of personal data to Google LLC. based in the United States, Google LLC. certified for the US-European data protection convention "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. A current certificate can be viewed here:
For more information about Google reCAPTCHA and Google’s privacy policy, please visit the following link:

Further Information on Mailings
We regularly inform interested parties, students, companies and other groups about our products, offers and services by post or email. In doing so, we store the information provided to us (business card, binder), publicly available information, date and reason for consent to be included in our distribution lists, as well as usage data of our products. The persons can be removed by email to datacontrol(at) from the corresponding distributors.

Intranet Offer Myhsba
HSBA provides access to "Myhsba" offers for certain groups of people (students, staff, teachers). Use is based on an additional myhsba privacy statement and special myhsba terms of use.

Data Protection
We have taken extensive technical and organisational measures to secure your data against potential risks, such as unauthorised login or access, unauthorised perusal, amendment or distribution, as well as against loss, deletion or misuse.

In order to protect your personal data against unauthorised access by third parties when being transmitted, we secure data transmissions, if necessary, using SSL encryption. This is a standard encryption procedure for online services, particularly for the Internet.

Every time you access our web pages, usage data are transferred through your specific web browser and stored in the form of protocol files (known as server log files). The datasets stored in this way contain the following data
• The domain from which the user is accessing the website
• Date and time of access
• IP address of the accessing computer
• Website(s) which the user is visiting in the context of the offering
• Amount of data transferred; browser type and version
• Operating system used; name of internet service provider
• Indication of whether access was successful

These logfile datasets are analysed in anonymised form, to improve the offering and make it more user-friendly, to identify and resolve errors, and to control server workloads.

Cookies are small files that your browser stores on your PC in a directory designated specifically for this purpose. These cookies can be used e.g. to find out whether you have already visited a website. Most browsers accept cookies automatically. Nevertheless, you can change the settings in your browser, so that no cookies can be stored or so that your explicit agreement is required before any cookies are stored. You can also delete previously set cookies at any time. Please note that disabling cookies may result in your use of our website being restricted.
Information about our use of cookies
We need cookies for the following purposes: Anmeldung Studienplatzbörse, Facebook Tracking, Cookie Info, Google analytics.

Web Analysis
Like almost all website operators, we use analytical tools in the form of tracking software to ascertain the number of users using our website and how frequently they visit.

To enable us to optimise our website and our service, we use Google Analytics, which is a web analysis service provided by Google Inc. (“Google”). Google Analytics uses what are known as “cookies”: these are text files stored on your computer and used to analyse your website usage. The information generated by the cookie about your use of this website (including your IP address) will be sent to a Google server in the USA and stored there. However, if IP anonymisation is enabled on this website, within member states of the European Union, or in other states that are party to the agreement on the European Economic Area Google first abbreviates your IP address. The full IP address will only be transmitted in exceptional circumstances to one of Google's servers in the USA, where it will then be abbreviated. Google will use this information on behalf of our website operator to analyse your use of the website in order to compile reports about website activities for the website operator and to perform other services connected with the use of the website and of the Internet. The IP address transmitted by your browser as part of Google Analytics will not be merged or combined with other data by Google. You can prevent cookies from being stored by applying the appropriate settings in your browser software; please note, however, that in this case you may not be able to use all of the functions of this website to their full extent.

You may also prevent Google from collecting data generated by the cookie referring to your website usage (including your IP address), and from processing these data by downloading and installing the browser plug-in available from the following link As an alternative to the browser add-on or within browsers on mobile devices, please click on this link to prevent Google Analytics from collecting data in this website in future (the opt-out only works in this browser, and only for this domain). This stores an opt-out cookie on your device. If you delete your cookies in this browser, you need to click on this link again. Further information is available at or at (general information on Google Analytics and data protection).

Please note that on this website, Google Analytics has been extended by the code “gat._anonymizeIp();”, to ensure anonymised collection of IP addresses (known as IP masking).

Social Networks

Facebook is operated by Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA and is available online at Individual social media plugins feature one of the Facebook logos or the extension ‘Facebook Social Plugin’. A list of the visuals and functions of the individual plugins can be seen here: Whenever you visit a page on our website which contains one of these social media plugins, your browser will establish a direct connection with the Facebook servers. The content of the social media plugins are transferred from Facebook to your browser, which incorporates them into the website. We therefore have no influence over the scope of the data which Facebook collects using its social media plugins, and are able to provide information to you about this only to the best of our knowledge: Because the social media plugin is embedded, Facebook is informed that you have visited the page of our website in question, even if you are not a registered user of Facebook or are not logged into Facebook at the time. This information is transferred from your browser along with your IP address to a Facebook server in the USA and stored there. According to information provided by Facebook, only an anonymised IP address is stored for non-registered users in Germany. If you are logged into Facebook, Facebook can directly attribute it to your Facebook account whenever you visit our website. Facebook receives information about your visit to our website, regardless of whether you interact with the social media plugins. If you interact with the social media plugins (for example, click the ‘Like’ button or leave a comment), the relevant information is transferred by your browser directly to Facebook and stored there. Additionally, the information is published on Facebook and displayed to your Facebook friends. To find out about the purpose and scope of this data gathering, further processing and use of the data by Facebook, as well as your rights and options for protecting your privacy, please review the Facebook privacy policy at If you are a registered Facebook user, and prefer Facebook not to collect data about you via our website and connect it with your membership data stored at Facebook, you must log out of Facebook before visiting our website. It is also possible to block the social media plugins using add-ons for your browser, such as the Facebook Blocker: 

Our web pages incorporate the functions provided by the service Instagram, as operated by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. If you are logged into your Instagram account, by clicking the Instagram button you can link content from our pages with your Instagram profile. This enables Instagram to attribute your visit to our web page to your user account. Please note that we as the content provider of these pages do not have knowledge of the information contained in the data transferred or of its usage on the part of Instagram.

Additional information on this subject is available in Instagram’s data privacy notice at

The ‘+1’ plugin from Google Inc. (1600 Amphitheater Parkway, Mountain View, CA 94043, USA) is integrated into our website, identifiable from the ‘+1’ symbol on a white or coloured background. Whenever you visit a page on our site which includes this plugin, your browser establishes a direct connection with the Google servers. The content of the plugin is then transferred to your browser, which integrates the content into the website. We have no influence over the scope and/or content of the data collected by Google via this plugin. According to information provided by Google, no personal data are collected unless you click on the plugin. Such data are only collected and processed if you are a Google+ member and you are logged in to your Google+ account. If you are logged into your personal user account with Google/Google+ when you visit our website, Google can trace your website visit to your specific account. By interacting with plugins (for example, by clicking the button or leaving a comment), the relevant information is transferred directly to Google and stored there. Furthermore, we cannot guarantee that other Google services embedded in our website will not associate data with your Google profile. If you wish to prevent such data transfer, you must log out of your Google/Google+ account before visiting our website. Google users can find out about the purpose and scope of this data gathering, further processing and use of the data by Google, as well as their rights and options for protecting their privacy, by reviewing the privacy policy with regard to the ‘+1’ plugin at and the FAQ at   

This website uses plugins from which is operated by Youtube, LLC (901 Cherry Avenue, San Bruno, CA 94066, USA). If you visit a website that contains such a plugin, your browser establishes a direct connection with the YouTube servers. These plugins transfer data to the YouTube servers about which websites you have visited. If you are logged in as a member of YouTube, YouTube attributes this information to each of your personal user accounts on these platforms. When using these plugins (for example, clicking the ‘Play’ button on a video or leaving a comment), this information is attributed to your YouTube user account, which you can prevent by logging out of your account before using the plugin. For more information, please review the privacy policy: 

This website uses buttons for the Twitter service which is offered by Twitter Inc. (1355 Market St., Suite 900, San Francisco, CA, 94103, USA). These plugins can be identified by terms such as ‘Twitter’, ‘tweet’ and/or the Twitter logo. They make it possible, among other things, to share a comment or a page of this website via Twitter. When you visit a website which contains such a button, your browser establishes a direct connection with the Twitter servers. The content of the Twitter button is transferred directly from Twitter to your browser. We therefore have no influence over the scope of the data collected by Twitter via this plugin, and can only provide information on this to you to the best of our knowledge. Log data (for example, the user’s IP address and previously visited websites, etc.) are transferred to Twitter. For more information, please review the Twitter privacy policy: 

The “XING Share Button” is installed on this website. When accessing this site, your browser will briefly connect to the servers of XING AG, Dammtorstraße 29-32, 20354 Hamburg (“XING”), which establishes the “XING Share Button” functions (in particular the calculation/display of the counter value). XING does not store any of your personal data regarding access to this website. XING in particular does not store any IP addresses. No analysis will be made of your browsing behaviour using cookies in connection with the “XING Share Button”. Current data protection information on the “XING Share Button” and additional information can be found here 

Plug-ins from LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (LinkedIn) are incorporated in this website. The LinkedIn plug-ins are identifiable from the LinkedIn logo or the “Share Button” on this website. If you visit this website, a direct connection will be generated between your browser and the LinkedIn server through the plug-in. In this way, LinkedIn receives information on the fact that you visited this website with your IP address. If you click on the LinkedIn “Share Button” while you are logged in to your LinkedIn account, you can link the contents of this web page to your LinkedIn profile. In this way, LinkedIn can allocate the visit to this website to your user account. Please note that we as website operators receive no knowledge of the content of the data transferred or their use by LinkedIn. You can find details on data collection (its purpose, extent, further processing and use) as well as on your rights and the possibility to amend settings in LinkedIn’s privacy policy. The LinkedIn policy can be found at

Third-Party Services
We use third-party services for various functions on our website.

Addsearch SiteSearch
Our websites use Addsearch SiteSearch via Java Script code. If you use the search box on this website, data will be passed to Addesarch using Addsearch's privacy policy ( In order to prevent execution of the Java Script code used, you can install a Java Script Blocker (eg

We use Hotjar to better understand the needs of our users and to optimize this website. With Hotjar's technology, we get a better understanding of our users' experiences (e.g. how much time users spend on which pages, which links they click on, what they like and what they don't like etc.) and this helps us to improve our offer of user feedback align. Hotjar works with cookies and other technologies to collect information about the behavior of our users and their end devices (in particular the IP address of the device (is only recorded and saved in anonymized form), screen size, device type (Unique Device Identifiers), information about the browser used, location (country only), preferred language for displaying our website). Hotjar stores this information in a pseudonymized user profile. The information is neither used by Hotjar nor by us to identify individual users or combined with other data about individual users. The legal basis is Art. 6 para. 1 p. 1 lit. f GDPR. For more information, see Hotjar's privacy policy: 

You can object to the storage of a user profile and information about your visit to our website by Hotjar and the setting of Hotjar tracking cookies on other websites via this link:

Rights of the Data Subject
Right to access, rectification, right to object, to complaint, erasure and blockage.
• You have the right to request information about whether and which personal data is processed by our company. You also have the right to demand that your personal data is rectified or amended.
• Under certain circumstances, you have the right to request that your personal data should be deleted.
• Under certain circumstances, you have the right to demand that the processing of your personal data should be restricted.
• You can withdraw your consent to the processing and use of your data completely or partially at any time with future application.
• You have the right to obtain your personal data in a common, structured and mechanically readable format.
• If you have any questions, comments, complaints or requests in connection with our statement on data protection and the processing of your personal data, you can also contact our data protection officer in detail.
• You also have the right to complain to the responsible supervisory authority if you believe that the processing of your personal data is in violation of the legislation.

Contacts Possibility
You can reach us as follows:
Prof. Dr. Christoph Bauer, ePrivacy GmbH, Große Bleichen 21, 20354 Hamburg

Inquiries are received by the data protection officer and processed by the staff department.

Requirement or Obligation to Provide Data
Insofar as this is not explicitly stated, when data are collected, the provision of data is neither required nor obligatory.

Date of Issue of this Data Privacy Statement

We reserve the right to make amendments at any time to this data privacy statement for future effect.

This data privacy statement has been compiled with the assistance of the ePrivacy GmbH data privacy statement generator.