Legal
Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the provision of our services and, in particular, on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: 23 July 2026
Table of contents
- Preamble
- Controller
- Overview of processing activities
- Relevant legal bases
- Security measures
- Transmission of personal data
- International data transfers
- Service providers used
- General information on data storage and deletion
- Rights of data subjects
- Provision of the online offering and web hosting
- Audience measurement
- Source from campaign links
- Contact and enquiry management
- Newsletter and electronic notifications
- Changes and updates
- Definitions of terms
Controller
Justin Koecke
Meiderdorfstraße 19
35066 Frankenberg (Eder), Germany
Email address: contact.ifpaa@gmail.com
Overview of processing activities
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
- Contact data.
- Content data.
- Usage data.
- Meta, communication, and procedural data.
- Log data.
Categories of data subjects
- Communication partners.
- Users.
- Third parties.
Purposes of processing
- Communication.
- Security measures.
- Direct marketing.
- Audience measurement.
- Organisational and administrative procedures.
- Feedback.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
Relevant legal bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(1)(a) GDPR) - the data subject has given consent to the processing of personal data relating to them for one or more specific purposes.
- Legitimate interests (Art. 6(1)(1)(f) GDPR) - processing is necessary to protect the legitimate interests of the controller or a third party, provided that the interests, fundamental rights, and freedoms of the data subject that require the protection of personal data do not override those interests.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains special provisions, in particular on the right to access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, the data protection laws of the individual federal states may apply.
Security measures
In accordance with legal requirements and taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as the access, input, transfer, availability, and separation of the data concerned. Furthermore, we have established procedures that ensure the exercise of data subjects' rights, the deletion of data, and responses to threats to the data. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorised access. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL.
Transmission of personal data
In the course of our processing of personal data, it may happen that the data is transmitted to or disclosed to other bodies, companies, legally independent organisational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the legal requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.
International data transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transferring data to other persons, bodies, or companies, this always takes place in accordance with the legal requirements. The services we use (Supabase, Resend, and Vercel) are based in the USA.
For data transfers to the USA, we rely — insofar as the respective providers are certified under it — on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission on 10 July 2023. In addition, or otherwise, we rely on the standard contractual clauses agreed with the providers, which comply with the requirements of the EU Commission and establish contractual obligations to protect your data.
Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). Information on third-country transfers and applicable adequacy decisions can also be found in the information provided by the EU Commission.
Service providers used
The following service providers process personal data on our behalf. A data processing agreement is in place with all three. They are based in the USA; the safeguards named in the "International data transfers" section apply to the transfer.
- Supabase Inc. (San Francisco, USA) — storage of the form and registration data in a database. Privacy policy
- Resend (San Francisco, USA) — sending the confirmation and notification emails. Privacy policy
- Vercel Inc. (Walnut, CA, USA) — hosting, delivery via a content delivery network, and audience measurement. Privacy policy
General information on data storage and deletion
We delete personal data that we process in accordance with the legal provisions as soon as the underlying consents are withdrawn or there is no further legal basis for the processing. This applies to cases in which the original purpose of the processing no longer applies or the data is no longer required. Exceptions to this rule exist where statutory obligations or special interests require longer retention or archiving of the data.
Where several statements on the retention period or deletion deadlines for a piece of data exist, the longest period is always decisive. Where a period does not expressly begin on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the triggering event occurred.
Specific information on individual processing activities (for example on the deletion of unconfirmed registrations or the newsletter data) can be found in the respective sections of this privacy policy.
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is connected with such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to obtain information about this data, as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without delay, or alternatively to request a restriction of the processing of the data in accordance with the legal requirements.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used, and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the requirements of the GDPR.
Provision of the online offering and web hosting
We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
- Types of data processed: Usage data (e.g. pages accessed, device types and operating systems used); meta, communication, and procedural data (e.g. IP addresses, time stamps); log data (e.g. log files relating to the retrieval of data or access times).
- Data subjects: Users (e.g. website visitors).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; information technology infrastructure; security measures.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing activities, procedures, and services:
- Provision of the online offering on rented storage space: For the provision of our online offering, we use storage space, computing capacity, and software that we obtain from the provider Vercel Inc. (Walnut, CA, USA); legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful access, the browser type and version, the user's operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes, e.g. to avoid overloading the servers, and, on the other hand, to ensure the utilisation and stability of the servers; legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised.
- Content delivery network: We use a "content delivery network" (CDN, provided by Vercel). A CDN is a service with the help of which the content of an online offering, in particular large media files such as graphics or program scripts, can be delivered faster and more securely with the help of regionally distributed servers connected via the internet; legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
Audience measurement
We use a privacy-friendly service to measure reach, in order to evaluate visitor and page-view numbers in aggregated form. The service uses no cookies and stores no IP addresses. Visitors are distinguished solely by a hash derived from the server request, which is discarded after 24 hours. Only anonymous, aggregated statistics are produced, which cannot be assigned to any particular person. No access to the user's device takes place, which is why no consent is required for this.
- Types of data processed: Usage data (e.g. pages accessed, referrer, location limited to country/region level, device type and browser in aggregated form).
- Data subjects: Users (e.g. website visitors).
- Purposes of processing: Audience measurement; provision of our online offering and user-friendliness.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
- Service provider: Vercel Inc. (Walnut, CA, USA).
Source from campaign links
If you access our online offering via a campaign link (e.g. with a parameter such as ?ref= or utm_source), we store the source identifier it contains together with your registration. This serves solely to evaluate through which channels interested parties become aware of the project. Only the name of the source is stored, not your other browsing behaviour.
- Types of data processed: Usage data (name of the access source).
- Data subjects: Users.
- Purposes of processing: Audience measurement; organisational and administrative procedures.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
Contact and enquiry management
When contacting us (e.g. by post, contact form, email, telephone, or via social media) as well as in the context of existing user and business relationships, the information of the enquiring persons is processed insofar as this is necessary to respond to the contact enquiries and any requested measures.
- Types of data processed: Contact data (e.g. email addresses); content data (e.g. answers to the questions about the IFPAA concept); meta, communication, and procedural data (e.g. IP addresses, time stamps).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form); provision of our online offering and user-friendliness.
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing activities, procedures, and services:
- Survey and registration form: Via the form on this page, we process the information you voluntarily provide about the IFPAA concept as well as your email address. The information serves to gauge interest in the project idea (market validation). No IP address is stored alongside these answers; legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
- Storage in a database (Supabase): The information submitted via the form is stored in a database of the provider Supabase Inc. (San Francisco, USA), which processes the data on our behalf; legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
Newsletter and electronic notifications
We send newsletters, emails, and other electronic notifications (hereinafter "newsletter") only with the consent of the recipients or on the basis of a legal permission. Providing your email address is sufficient to register. Registration takes place using the so-called double opt-in procedure: after submitting, you receive an email containing a confirmation link, and your consent counts as given only once you confirm. This ensures that nobody can register using someone else's email address. If you do not confirm, your registration is deleted automatically after 30 days.
Deletion: If you withdraw your consent or unsubscribe, we delete your registration including your email address completely.
The logging of the registration procedure is based on our legitimate interests for the purpose of demonstrating that it was carried out properly. As part of this logging, we store the time and the IP address of your confirmation as evidence of consent. Insofar as we commission a service provider to send emails, this is based on our legitimate interests in an efficient and secure dispatch system.
Content: Information on the progress of the IFPAA, on new cases, and on the launch of the Institute.
- Types of data processed: Contact data (email address); meta, communication, and procedural data (e.g. IP address and time of confirmation).
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing (by email).
- Legal bases: Consent (Art. 6(1)(1)(a) GDPR); for logging the evidence: legitimate interests (Art. 6(1)(1)(f) GDPR).
- Objection option (opt-out): You can cancel receipt at any time, i.e. withdraw your consent. You will find an unsubscribe link at the end of every message; alternatively, you can use one of the contact options given above.
Further information on processing activities, procedures, and services:
- Dispatch via Resend: Emails are sent via the service provider Resend (San Francisco, USA), which processes the email address and the technical dispatch data on our behalf. We do not use open or click tracking (e.g. via tracking pixels); legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
Changes and updates
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and we ask you to check the details before contacting them.
Definitions of terms
In this section you will find an overview of the terms used in this privacy policy. Insofar as the terms are legally defined, their legal definitions apply. The following explanations, on the other hand, are intended primarily to aid understanding.
- Content data: Content data comprises information generated in the course of creating, editing, and publishing content of all kinds. This category of data can include texts, images, videos, audio files, and other multimedia content. Content data is not limited to the actual content but also includes metadata that provides information about the content itself.
- Contact data: Contact data is essential information that enables communication with persons or organisations. It includes, among other things, telephone numbers, postal addresses, and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Inventory data: Inventory data comprises essential information necessary for the identification and management of contractual partners, user accounts, profiles, and similar assignments. This data may include personal and demographic details such as names, contact information, dates of birth, and specific identifiers (user IDs).
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as time stamps, IP addresses, user actions, error messages, and other details about the use or operation of a system.
- Meta, communication, and procedural data: Meta, communication, and procedural data are categories that contain information about how data is processed, transmitted, and managed. Metadata describes the context, origin, and structure of other data. Communication data captures the exchange of information between users via various channels. Procedural data describes the processes and workflows within systems or organisations.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more special characteristics.
- Usage data: Usage data refers to information that captures how users interact with digital products, services, or platforms. This data includes, for example, pages accessed, referrer, details about the device and browser, and time stamps. It is particularly valuable for analysing user behaviour in aggregated form.
- Controller: The "controller" is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" is any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collecting, evaluating, storing, transmitting, or deleting.
Created with the free privacy policy generator by Dr. Thomas Schwenke
← Back to home