Privacy policy
As of: 29 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is the Förderverein der KiTa Unter'm Regenbogen Stockelsdorf (in Gründung / being founded), represented by its board (§ 26 BGB, see legal notice), c/o Johannes Möllerherm, Heinrichstraße 10F, 23617 Stockelsdorf, Germany, email: vorstand@foerderverein-regenbogen-stockelsdorf.de
No data protection officer has been appointed, as there is no legal obligation to do so.
2. Principles
We process personal data only to the extent necessary to operate this website and to carry out the association's work. This website uses no tracking, no analytics services, no advertising networks and no social media embeds. Fonts and all other resources are served from our own server; visiting this website establishes no connections to third parties.
3. Hosting and server log files
This website is hosted on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner; data is processed in data centres in Germany.
When you visit the website, the server automatically processes technical access data (IP address, date and time, page accessed, referrer, browser type and operating system). This log data is required to provide, stabilise and secure the website (legal basis: Art. 6 (1) (f) GDPR). It is not combined with other data and is deleted after 7 days at the latest, unless a security incident requires longer retention.
4. Cookies and local storage
This website uses no cookies for advertising or analytics purposes and therefore shows no cookie banner. Only technically required mechanisms are used (§ 25 (2) no. 2 TDDDG):
- a session cookie and a CSRF protection cookie for form security (deleted when the browser is closed or after a short time),
- a cookie storing your language choice (German/English),
- local storage of your chosen appearance (light/dark mode) on your device.
These serve exclusively the function you requested.
5. Encryption
The website is available exclusively via HTTPS (TLS encryption).
6. Contact
If you contact us by email, we process the data you provide (name, email address, content of the message) to handle your enquiry. The legal basis is Art. 6 (1) (b) GDPR where the enquiry relates to a contract (e.g. a membership), otherwise Art. 6 (1) (f) GDPR. We delete the correspondence once it is settled and no statutory retention obligations apply.
7. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may object to processing based on Art. 6 (1) (f) GDPR with effect for the future (Art. 21); consent you have given may be withdrawn at any time without affecting the lawfulness of prior processing.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany, https://www.datenschutzzentrum.de.
No automated decision-making, including profiling (Art. 22 GDPR), takes place.
8. Membership application via this website
Through our membership form we process the data required to establish and manage your membership: name, address, email address, date of birth or confirmation of legal age, the contribution amount and payment interval you have chosen, and your bank details (IBAN, account holder) including the SEPA direct debit mandate. The legal basis is Art. 6 (1) (b) GDPR (establishing and performing the membership) and Art. 6 (1) (c) GDPR for obligations under tax and payment law. If you provide it voluntarily, we also process your phone number for queries about your application and for membership administration (Art. 6 (1) (b) GDPR); providing it is not required to join, and the number is never shown publicly.
We use a double-opt-in procedure to confirm your email address. Confirmation and system emails are sent via the email infrastructure of our hosting provider Hetzner. As proof of the electronically issued SEPA mandate we store the time, IP address and technical characteristics of the mandate declaration (Art. 6 (1) (f) GDPR; evidence towards banks and payment service providers).
Membership administration, the collection of contributions and the issuing of donation receipts are carried out with the association management software easyVerein of SD Software-Design GmbH, Freiburg, Germany; your application data is transferred there. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider; processing takes place in Germany.
Fixed deletion periods apply on the website itself: applications whose email address is not confirmed within 14 days are deleted automatically together with the mandate data. Applications rejected by the board are deleted 90 days after the rejection. After successful transfer to easyVerein, we automatically reduce the application within 30 days to the evidence data of the mandate (mandate reference, mandate text, time, IP address, technical characteristics and the mandate document); name, address, date of birth, phone number and bank details then remain only in the membership administration.
Retention periods: membership data until the end of the membership and beyond, to the extent statutory retention periods apply (in particular §§ 147 AO, up to ten years for accounting-relevant records); mandate evidence at least for the duration of the chargeback periods in direct debit transactions (up to 13 months after the last debit).
9. Recurring donations by direct debit
If you set up a yearly recurring donation by SEPA direct debit, we process your name, address, email address, the donation amount, your bank details (IBAN, account holder) and the direct debit mandate; a phone number only if you provide it voluntarily. For a company donation we additionally process the company name and the confirmation of the authorised representative. Legal basis is Art. 6 (1) (b) GDPR (execution of the donation agreement) and Art. 6 (1) (c) GDPR for tax and payment obligations (donation receipts).
We confirm your email address by double opt-in. To prove the electronically granted mandate we store the time, IP address and technical characteristics of the declaration (Art. 6 (1) (f) GDPR). Before every debit we send you a notice by email 7 days in advance; every email contains a link to end the donation at any time. The donation is transferred to our association management software easyVerein (see section 8) as a contact without membership; the treasurer sets up the yearly debit there.
Deletion periods: recurring donations whose email address is not confirmed within 14 days are deleted automatically together with the mandate data. After you end the donation, the data on this website is kept for 14 months (chargeback period of up to 13 months after the last debit) and then automatically reduced to the evidence data of the mandate; name, address and bank details then remain only in the association management software for as long as statutory retention periods apply (§§ 147 AO).