This privacy policy covers the use of the Copenhagen Research Platform (CARP) Services as provided and hosted by the Technical University of Denmark (DTU). In practice, this typically covers researchers who use the CARP services via the CARP Study Portal.
Who we are
“We” are the Department of Health Technology at the Technical University of Denmark (DTU Health Tech). DTU Health Tech is a public research department for health technology.
Our website address is: https://www.healthtech.dtu.dk/
This is the Privacy Policy for the Copenhagen Research Platform (CARP). CARP is used by researchers at DTU to collect, store, manage, and analyze data for research purposes.
CARP is operated by the Technical University of Denmark (DTU) at the Department of Health Technology, which is the data controller for CARP. CARP complies with the privacy policy of DTU.
The legal entity responsible for processing your personal data is:
Technical University of Denmark (DTU)
Department of Health Technology
Ørsteds Plads
Building 345C
2800 Kongens Lyngby
Contact details for DTU’s data protection officer are:
DTU
Attn. DPO
Anker Engelunds Vej 1
Building 101A
2800 Kongens Lyngby
Email: dpo@dtu.dk
Tel.: +45 25 25 25 25
As a data controller, DTU is committed to giving the utmost attention to the security and protection of your privacy. DTU processes your personal data in compliance with applicable privacy and personal data laws according to the European General Data Protection Regulation (GDPR).
This Privacy Policy explains how we process your personal data when you use CARP as a researcher (“Researcher”). As a Researcher, you access the CARP services (“Services”) via various software applications (“Applications”) (including web applications) or software scripts (“Scripts) (including Python or REST-based Application Programming Interfaces (APIs)).
All data collection in CARP is done as part of a Research Study (“Study”). A Study will always have a Researcher who is responsible for the Study.
What data do we collect?
As a Researcher using the CARP Services, we collect the following types of data from you:
- Identity data that can directly identify you, such as your email address, username, name, picture, phone number, and work affiliation and address.
- Technical data such as technical logs, debug technical information, and website cookies.
How do we use data?
The data collected through the CARP Services is processed by DTU for the following specific purposes.
- Conduct Research. Personal data processed by DTU is used to identify and contact the Researcher conducting a Study with a specific purpose.
- Improving the CARP Applications and Services. We may use your personal data to improve our Applications and Services and to correct or modify software settings.
Who do we share your data with?
We do not share your personal data with anyone unless you permit us to do so.
In the case that a Study wants to share your data with another organization outside DTU – for example, another university or a hospital – an agreement about data sharing or disclosure will be made with this organization. You will be part of such a data sharing or disclosure agreement.
How do we publish your data?
Your personal data will not be published.
As part of our research, your data will be subject to data processing and analysis, and the result of such analysis will be part of scientific dissemination in academic journals, conferences, blogs, or public data sets.
However, any such results will only be published in anonymized formats with no person-identifiable data. Anonymization will be done by statistical aggregation and by removing all person-identifiable data from such research dissemination.
How long will we retain your data?
We will keep your data as long as it is relevant for the research purpose of the Study from which it was obtained.
What rights do you have over your data?
You can request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
How do we process your data?
CARP Services processes data in two places:
- In web applications (e.g., the CARP Web Portal)
- On the CARP server
All communication between the web browser running the CARP web application and the CARP server is encrypted.
All CARP services, including web applications, are subject to user authentication and authorization.
All data is encrypted on the CARP server.
The CARP server is hosted within the EU.