Privacy Policy
Privacy Policy for the Medical Report Access Service
In addition, the General Privacy Policy of Ludwig-Maximilians-Universität München (LMU Munich) applies. There you will find, in particular, information about the data controller, the data protection officer, and your rights as a data subject (access, rectification, erasure, restriction of processing, objection, and the right to lodge a complaint with a supervisory authority).
Accessing Medical Reports with an Access Code
This platform enables the retrieval of medical report documents using a personal access code. When you enter an access code and when you download a report document, we process the following data:
– a pseudonymised form of your IP address (cryptographic hash; the IP address itself is not stored)
– where available, a pseudonymised session hash
– browser and user agent information
– the type of event (e.g. valid or invalid code entry, document download) and a timestamp
– a truncated, non-reversible fragment of the entered access code
Access codes themselves are stored exclusively as cryptographic hashes; they are never stored in plain text.
Purposes of Processing
This data is processed to securely provide the report access service, to prevent misuse (e.g. by limiting failed code entry attempts and the number of downloads per access code), to enforce rate limiting, and to ensure the traceability of security-relevant events.
Legal Basis
The legal basis for processing is the provision of the report access service to you (Art. 6 (1) (b) GDPR) and our legitimate interest in the secure and abuse-free operation of the platform (Art. 6 (1) (f) GDPR); insofar as the service is operated in the performance of a public task of LMU Munich, additionally Art. 6 (1) (e) GDPR.
Retention Period
Access logs are stored only for as long as is necessary for the security of the service, the prevention of misuse, and the traceability of security-relevant events, and are deleted thereafter.
Technically Necessary Cookies
The application sets the following technically necessary cookies:
sessionid – session identifier. Purpose: session management and maintaining the logged-in state. Retention period: approx. 14 days (Django default). Security attributes: HttpOnly, SameSite=Lax, Secure over HTTPS.
csrftoken – protection against cross-site request forgery in forms. Retention period: approx. 1 year (Django default). Security attributes: SameSite=Lax, Secure over HTTPS.
clinical_report_optional_tracking – stores your choice in the privacy banner. Retention period: 12 months. Security attributes: HttpOnly, SameSite=Lax.
django_language – stores your language selection (German/English). Retention period: until the end of the browser session. Security attributes: SameSite=Lax.
Legal basis: Art. 6 (1) (b) and (f) GDPR. No third-party cookies and no advertising or analytics cookies are set.
Optional Statistics (Only with Your Consent)
If you give your consent via the privacy banner, we record a statistics event for page views consisting of a pseudonymised IP hash, where available a session hash, the browser user agent, the page visited, and a timestamp. Raw IP addresses are not stored for this purpose. The legal basis is your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). You can withdraw your consent at any time with effect for the future via the privacy settings.
Data Transfer from the Study System
Access codes are generated within the respective study and exchanged between the study data system (REDCap) and this platform via a secured interface. In this process, study-internal record identifiers are transferred to this platform, but no names or contact details of the data subjects.