← Back to RadScore

Privacy Policy for RadScore

Version 1.0 · Last updated: 11 July 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation for the general operation of RadScore is:

Torsten DiekhoffProf. Dr. med.Debussystraße 5a13158 BerlinDeutschland

Email: info@radscore.de

The controller currently operates RadScore as an individual. RadScore is not a separate legal entity.

A data protection officer has not currently been appointed. Data protection enquiries may be sent to info@radscore.de.

2. Purpose of the platform

RadScore is an access-restricted research platform for the structured conduct of medical imaging and assessment projects.

In particular, the platform enables:

  • the administration of scientific projects,
  • the provision of pseudonymised medical imaging data,
  • the conduct of structured assessments,
  • the documentation of training and test phases,
  • consensus and adjudication procedures, and
  • the export of pseudonymised research data.

RadScore is not intended for primary clinical diagnosis or the direct treatment of patients.

3. Responsibility for research projects

Responsibility for the technical operation of RadScore must be distinguished from responsibility for individual research projects.

Where a hospital, university, research institution or other institution determines the purposes and essential means of a research project, that institution is the controller for the project-related processing.

In this situation, the operator of RadScore generally processes project-related data as a processor on behalf of the controller. A data processing agreement pursuant to Article 28 GDPR must be concluded before processing begins.

Where Torsten Diekhoff himself determines the purposes and essential means of a project, he is also the controller for the project-related processing.

Where the operator and one or more institutions jointly determine the purposes and essential means, joint controllership pursuant to Article 26 GDPR may exist.

The specific allocation of roles is determined and documented separately before each research project begins.

4. Accessing the website and technical log data

When RadScore is accessed, technically necessary data may be processed, in particular:

  • IP address,
  • date and time of access,
  • resource accessed,
  • HTTP status code,
  • browser type and browser version,
  • operating system,
  • amount of data transferred,
  • referrer information, where transmitted,
  • technical error and security information.

Processing serves to provide the platform, analyse errors, defend against abusive access and ensure IT security.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure and reliable operation of the platform.

5. Registration and user account

The following data in particular are processed when registering and using a user account:

  • name or display name,
  • email address,
  • cryptographically secured password verifier,
  • preferred language,
  • user status,
  • global and project-specific roles,
  • project memberships,
  • times of registration, approval and amendment,
  • two-factor authentication status,
  • security-relevant account and session information.

Processing serves to establish and administer the user account, control access, allocate permissions and attribute activities.

The legal basis is Article 6(1)(b) GDPR where a user relationship exists, and Article 6(1)(f) GDPR. The legitimate interest is the controlled conduct of scientific projects and protection against unauthorised use.

6. Authentication, auditing and IT security

To secure the platform, the following data in particular may be processed:

  • login times,
  • failed login attempts,
  • IP addresses or security characteristics derived from them,
  • browser and device information,
  • session identifiers,
  • blocking and rate-limit information,
  • use of two-factor authentication,
  • times of security-relevant account changes,
  • entries in security and audit logs.

Processing serves to prevent, detect and investigate unauthorised access and to ensure the traceability of security-relevant and project-related activities.

The legal basis is Article 6(1)(f) GDPR.

7. Project, imaging and assessment data

Depending on the research project, the following data in particular may be processed:

  • project names and project descriptions,
  • project roles and permissions,
  • pseudonymised case numbers,
  • age or age group,
  • sex,
  • project-specific clinical or demographic characteristics,
  • medical imaging data,
  • DICOM metadata and technical acquisition parameters,
  • structured assessments,
  • free-text comments,
  • annotations,
  • processing status,
  • times of processing and submission,
  • pseudonymised reader codes,
  • consensus and adjudication results.

Pseudonymised data must not be equated with anonymous data. As long as attribution to a person is possible with the aid of additional information, they remain personal data.

Directly identifying patient data should be removed or replaced with project-specific pseudonyms before import in regular study operations.

RadScore's technical import check does not replace the data-providing party's responsibility for proper pseudonymisation.

8. Legal bases for research and health data

The specific legal basis for research data and special categories of personal data, in particular health data, is determined separately for each research project.

Depending on the project, the following may apply in particular:

  • Article 6(1)(a) GDPR in conjunction with Article 9(2)(a) GDPR,
  • Article 6(1)(e) or (f) GDPR in conjunction with Article 9(2)(j) GDPR,
  • Section 27 BDSG,
  • applicable federal-state or sector-specific research provisions.

The specific legal basis, research purpose and retention period are described in the project-specific privacy information.

9. Cookies and local storage technologies

RadScore uses only technically necessary cookies and comparable storage mechanisms.

In particular, these serve:

  • secure login,
  • maintenance of an authenticated session,
  • protection of two-factor authentication,
  • attribution of security processes,
  • storage of the selected language.

Technically necessary storage mechanisms are used on the basis of Section 25(2) TDDDG.

RadScore currently does not use cookies for advertising, reach measurement or behavioural analysis.

10. Recipients and persons authorised to access data

Personal data are made accessible only to persons and bodies that need them for their respective tasks.

These may include:

  • system administrators,
  • project administrators,
  • authorised readers,
  • adjudicators and consensus moderators,
  • project staff authorised to conduct analyses,
  • participating research institutions,
  • data protection and information security units,
  • technical service providers,
  • legally authorised public authorities and courts.

Access within RadScore is role-based and project-based.

11. Hosting

RadScore is operated on infrastructure provided by the following company:

Hetzner Online GmbHIndustriestr. 2591710 GunzenhausenDeutschland

Depending on the specific service purchased, Hetzner is used in particular for:

  • hosting the platform,
  • providing the email mailbox,
  • technical infrastructure and backups for the web-hosting product purchased.

Hetzner processes the data required for these services as a processor on behalf of the operator. A data processing agreement pursuant to Article 28 GDPR must be concluded for this purpose.

12. Communication by email

When a person contacts RadScore by email, the contact details provided, the content of the message and the technical metadata required to process the enquiry are processed.

The email address info@radscore.de is used for communication. The associated mailbox is operated using infrastructure provided by Hetzner Online GmbH.

Directly identifying patient data, medical imaging data, passwords, authenticator codes or other particularly sensitive information must not be transmitted by unencrypted email.

Depending on the subject of the enquiry, the legal basis is Article 6(1)(b) or Article 6(1)(f) GDPR.

Where an enquiry relates to a specific research project, it may be forwarded to the institution responsible for that project.

13. AI-assisted functions

AI-assisted functions are disabled in the currently intended production operation.

Accordingly, no user input, project information or medical data from RadScore are currently transmitted to an external provider of generative AI.

This privacy policy must be updated before AI functions are activated in production. In particular, providers, processing purposes, categories of data transmitted, retention periods and possible transfers to third countries must be described.

14. Transfers to third countries

The regular hosting of RadScore and the email mailbox are operated through Hetzner. No transfer of project-related research data to a third country is envisaged in regular operation.

Transfers to third countries must be described and assessed again if external services such as OpenAI, analytics providers or other international service providers are activated in the future.

15. Retention period

Personal data are stored only for as long as necessary for the respective purpose or for as long as statutory, contractual or scientific retention obligations apply.

In particular, the following criteria apply:

  • User accounts are stored for the duration of the authorisation to use the platform.
  • After the authorisation to use the platform ends, account data are erased or anonymised unless continued attribution to audit or research data is required.
  • Project-related research and assessment data are stored in accordance with the study protocol, ethics approval and project-specific retention concept.
  • Medical imaging data are erased or anonymised in accordance with the periods defined for the respective project.
  • Security and audit logs are stored for as long as necessary for traceability, IT security or scientific integrity.
  • Temporary import and export files are erased as soon as they are no longer required for technical processing.
  • Data in backups may persist until the backup is next overwritten in the regular cycle.

16. Automated decisions

RadScore does not make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR.

Automated or AI-assisted functions, if activated in the future, serve solely to support professionally responsible users.

17. Rights of data subjects

Subject to the statutory requirements, data subjects have in particular the right to:

  • access,
  • rectification,
  • erasure,
  • restriction of processing,
  • data portability,
  • object,
  • withdraw consent with effect for the future.

Requests to exercise these rights may be sent to info@radscore.de.

In scientific research projects, individual rights may be restricted under the statutory conditions where their exercise would render the research purpose impossible or seriously impair it.

Project-related enquiries may be forwarded to the institution responsible for the respective research project.

18. Right to lodge a complaint

Data subjects have the right to lodge a complaint with a data protection supervisory authority.

The authority generally competent for the operation of the platform is:

Berliner Beauftragte für Datenschutz und InformationsfreiheitAlt-Moabit 59-6110555 BerlinDeutschlandEmail: mailbox@datenschutz-berlin.de

19. Security of processing

The operator implements technical and organisational measures to protect personal data against loss, alteration, unauthorised disclosure and unauthorised access.

Depending on the respective configuration, these include in particular:

  • encrypted transmission,
  • role-based and project-based access rights,
  • secure password storage,
  • two-factor authentication,
  • time-limited sessions,
  • protection against repeated login attempts,
  • logging of security-relevant activities,
  • separation of import, imaging and export areas,
  • backups,
  • update and patch management.

Potential personal data breaches may be reported via info@radscore.de.

20. Changes to this privacy policy

This privacy policy is amended when functions, legal bases, service providers or processing procedures change.

The current version is publicly accessible through RadScore.

© 2026 RadScore·Legal Notice·Privacy·Terms··