Data Protection Statement
Data Protection Statement (Privacy Policy)
Version: 0.1 | Effective Date: September 7, 2026 | Last Updated: September 7, 2026
This Data Protection Statement explains how Pfiffner Research IT, based at Njalsgade 205, 2300 Copenhagen, Denmark — operating the Platform as "Datadonationmodule.com" and referred to below as "we," "us," or "our" — collects, uses, and protects your personal data when you use our website and data donation platform (the "Platform").
This statement applies to personal data we control (your account information, billing data, etc.), including billing data we may generate or process manually outside the Platform (e.g., for invoicing). For personal data of research participants that we process on behalf of research clients, please refer to the privacy notice provided by the specific research project.
Platform Status. The Platform is currently in a preliminary/testing phase. As we continue development, the features available and the processing activities described in this Statement may change. Any change affecting how we collect or process your personal data will be reflected in an update to this Statement in accordance with Section 10 (Changes to This Statement).
1. Scope of this Statement
This statement covers personal data we process as a data controller, including:
- Account Data: Information about you and your organization when you register and use the Platform
- Usage Data: How you interact with the Platform
- Communications: Emails and support interactions
- Marketing Data: Newsletter subscriptions and preferences (if applicable)
What this statement does not cover:
- Personal data of research participants donated through projects (we process this as a data processor on behalf of research clients; see their privacy notices)
- Third-party websites linked from our Platform
- Services provided by our sub-processors (though we ensure they meet data protection standards)
Use by Minors
The Platform is intended for use by researchers, institutions, and other professional account holders, and is not directed at or intended for use by individuals under the age of 18. Research projects created on the Platform may involve minors as research participants; the collection and processing of a minor participant's personal data in that context is carried out on behalf of the research client and is governed by that project's own privacy notice, not by this Statement (see the introduction above).
2. Data We Collect
2.1 Information You Provide Directly
- Account & Contact: Name, email, phone, institutional affiliation, job title, country, account credentials
- Billing: Invoicing and billing details, where generated or processed manually outside the Platform
- Projects: Configuration details for research projects you create
- Communications: Support messages, feedback, survey responses
2.2 Information We Collect Automatically
- Technical: IP address, browser/device type, access times, cookies
- Usage: Features used, navigation patterns, performance metrics
- Security: Login attempts, access logs, API calls
2.3 Information from Third Parties
We do not currently receive personal data about you from third-party sources. If this changes in the future, we will update this Statement accordingly and, where required, notify you.
2.4 Special Data & Automated Processing
We do not process special categories of data (health, biometric, etc.) about account holders, nor do we use automated decision-making that significantly affects you.
2.5 Basis for Providing Data
Providing certain information — such as your name, email address, and institutional affiliation at registration — is necessary to enter into and perform our contract with you. If you do not provide this information, we will not be able to create or maintain your account or provide the Platform to you. Other information (e.g., optional profile details or marketing preferences) is provided voluntarily, and declining to provide it will not affect your ability to use the core Platform.
3. How We Use Your Data
We process your personal data for the following purposes, each with its own legal basis under GDPR/nFADP:
Service Delivery - Create and manage your account — Contract Performance - Enable research project creation and management — Contract Performance - Provide customer support — Contract Performance; Legitimate Interests
Security & Compliance - Protect against fraud, abuse, and security threats — Legitimate Interests - Monitor for suspicious activity and enforce our Terms — Legitimate Interests; Contract Performance - Comply with legal and regulatory requirements (e.g., tax, accounting) — Legal Compliance
Improvement & Communications - Analyze usage to improve the Platform — Legitimate Interests - Fix bugs and develop features — Legitimate Interests - Send service notifications and respond to inquiries — Contract Performance; Legitimate Interests - Send marketing communications — Consent (where required; you may withdraw at any time)
4. Data Sharing and Disclosure
We do not sell your personal data. We may share data in the following circumstances:
4.1 Service Providers (Sub-processors)
We engage third parties to help operate the Platform:
- Infrastructure hosting (Hetzner, Germany)
- Email delivery (Proton)
All sub-processors:
- Meet our security and privacy standards
- Are listed in our DPA (available upon request)
We provide 30 days' notice before adding new sub-processors.
4.2 Legal Requirements
We may disclose data when legally required (court orders, regulatory investigations, law enforcement requests). We will:
- Notify you unless prohibited by law
- Challenge overbroad requests
- Disclose only the minimum required
4.3 Research and Aggregate Data
We do not share, sell, or otherwise disclose data collected through your research projects, or any aggregated data derived from it, with third parties other than the sub-processors listed in Section 4.1 and as otherwise described in this Statement.
4.4 With Your Consent
We may share data for other purposes with your explicit consent.
5. Data Storage Location
Your data is stored on servers in Germany (EEA), providing strong GDPR protection. We do not transfer data outside the EEA or Switzerland. All sub-processors are required to store data within the EEA or Switzerland.
6. Data Retention
Active Accounts - Account & usage data: Duration of account - Logs: retained for a maximum of 24 months
Closed Accounts - Account data: Deleted within 90 days - Backups: Data removed within 90 days
We retain data only as long as necessary for service provision, legal compliance, or legitimate business purposes. When retention periods expire, data is securely deleted or anonymized.
7. Data Security
7.1 Security Measures
We implement industry-standard security including:
- Technical: Encryption in transit (TLS) and at rest (AES-256), and multi-factor authentication
- Organizational: Role-based access, background checks, incident response plans, and regular security audits
- Physical: Secure data centers with redundant systems
For detailed security information, contact us.
7.2 Your Security Responsibilities
You must:
- Use strong, unique passwords
- Enable multi-factor authentication
- Keep credentials confidential
- Log out on shared devices
- Report security concerns promptly
- Review account activity regularly
7.3 Limitations
No system is 100% secure. Despite our efforts, unauthorized access, hardware/software failure, or other factors may compromise security. Use the Platform at your own risk, subject to our liability limitations in the Terms of Service.
8. Your Data Protection Rights
Under GDPR, nFADP, and applicable laws, you have the following rights:
- Access: Request confirmation of processing and a copy of your data
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion when data is no longer necessary, you withdraw consent, or processing is unlawful (exceptions apply for legal obligations)
- Restriction: Limit processing during accuracy disputes or when you object to processing
- Portability: Receive your data in machine-readable format (JSON/CSV) to transfer to another service
- Object: Object to processing based on legitimate interests or for direct marketing
- Withdraw Consent: Withdraw consent at any time (doesn't affect prior lawful processing)
- Lodge a Complaint: Lodge a complaint with a data protection supervisory authority
How to Exercise Your Rights
- Email: info@datadonationmodule.com
- Account Settings: Use export/delete functions where available
- Response Time: Within one month (may extend by two months for complex requests, with notice)
- Cost: Free (reasonable fees for excessive/repetitive requests)
- Identity Verification: We may request proof of identity for security
We will assist you in exercising your rights in an accessible manner.
Lodging a Complaint
If you believe our processing of your personal data infringes GDPR, nFADP, or other applicable law, you have the right to lodge a complaint with a supervisory authority — in particular, the authority in the EU/EEA member state of your habitual residence, place of work, or the place of the alleged infringement.
Swiss residents may also contact the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch.
9. Cookies and Tracking
9.1 What Are Cookies
Cookies are small text files stored on your device by websites you visit. They help websites remember information about your visit.
9.2 Cookies We Use
- Essential (Always Active): Session management, security, load balancing
- Functional (Optional): Preferences, language, UI customization
A detailed cookie list is available through the link in our website footer.
9.3 Managing Cookies
Browser Settings - You can block or delete cookies through browser settings - This may affect Platform functionality
Our Cookie Preferences - You can view and adjust your functional cookie preferences at any time using the cookie settings link in the website footer - There is no separate account-level cookie setting; the footer link is the single point of control
9.4 Other Tracking Technologies
Local Storage - Used to store preferences and cache data - Persists across sessions - Can be cleared through browser settings
10. Changes to This Statement
10.1 Updates
We may update this statement to reflect:
- Changes in our practices
- Legal or regulatory changes
- New features or services
- Feedback and improvements
10.2 Notice of Changes
We will notify you of material changes by:
- Email to registered address (30 days before effective date)
- Prominent notice on Platform
- Update to "Last Updated" date
Minor changes (typos, clarifications, formatting) may not trigger notification.
10.3 Your Options
If you disagree with changes:
- You may object or raise concerns
- You may delete your account before changes take effect
- Continued use after the effective date constitutes acceptance
10.4 Version History
Previous versions are available by emailing info@datadonationmodule.com.
11. Contact Us
Controller: Pfiffner Research IT
Address: Njalsgade 205, 2300 Copenhagen, Denmark
Email: info@datadonationmodule.com
Web: datadonationmodule.com / ddmodule.com
Data Protection Officer: We have not appointed a Data Protection Officer,
as we are not required to under Art. 37 GDPR.