Privacy Policy

The following information is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) regarding the processing of personal data in connection with visiting and using this website. The German Federal Data Protection Act (BDSG) applies in addition, as does the German Telecommunications Digital Services Data Protection Act (TDDDG) for access to terminal equipment. This English text is a courtesy translation; the German version is the binding one.

Placeholder — replace before publishing

This page is scaffolding, not a legally effective document. Every entry in square brackets is a placeholder and must be replaced with the actual company data; sections that do not apply must be deleted. The draft deliberately contains no company, address, register or tax data — an imprint with incorrect details is legally worse than none. Have it reviewed by a lawyer before publishing.

1. Controller

The controller within the meaning of Article 4(7) GDPR for the processing of personal data on this website is:

[Full company name including legal form] [Street and number] [Postcode, city] [Country]

Represented by: [name of authorised representative(s)] Telephone: [telephone number] Email: [email address]

[All of the above are placeholders and must be replaced with the actual details. They must match the mandatory legal notice details required under section 5 DDG (German Digital Services Act). Invented or incomplete details expose the operator to cease-and-desist claims.]

2. Data Protection Officer

[First check whether an appointment is required at all: under Article 37(1) GDPR and section 38(1) BDSG, in particular where at least 20 persons are regularly and permanently engaged in the automated processing of personal data, where processing operations are subject to a data protection impact assessment under Article 35 GDPR, or where personal data is processed commercially for the purpose of transfer or of market and opinion research.]

[If a data protection officer has been appointed (whether mandatory or voluntary), insert their name, address and contact details here. If no data protection officer has been appointed, delete this section in full — a non-existent data protection officer must never be named.]

3. Legal Bases and General Information

We process personal data only where a legal basis permits it. The relevant bases are in particular: Article 6(1) subparagraph 1(a) GDPR (consent), (b) (performance of a contract or pre-contractual measures), (c) (compliance with a legal obligation) and (f) (legitimate interests). The applicable legal basis is stated separately for each processing operation below.

Where information is stored on or read from your terminal equipment, admissibility is additionally governed by section 25 TDDDG.

Providing your data is generally neither required by law nor by contract. However, without the data marked as mandatory we cannot process a contact enquiry or a newsletter subscription.

Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place on this website. [Verify before publication and delete if such procedures are in fact used.]

4. Server Log Files When Visiting the Website

Each time this website is accessed, your browser transmits data for technical reasons, which our web server records in what are known as log files. The following are recorded: the IP address of the requesting device, the date and time of access, the resource requested (URL), the HTTP status code, the volume of data transferred, the previously visited page (referrer, where transmitted), and the browser type, browser version and operating system.

The legal basis is Article 6(1) subparagraph 1(f) GDPR. Our legitimate interest is specifically: to technically enable the connection and delivery of the website, to monitor system stability and load, to detect and remedy malfunctions, and to detect, defend against and, where necessary, evidence to law enforcement authorities any attacks on our infrastructure — in particular denial-of-service attacks, automated login attempts and form abuse.

Log files are deleted after [insert retention period, e.g. in days — ask the hosting provider for the value actually configured and enter it here; the period must be limited to what is necessary for the purposes stated]. This data is not combined with other data sources to identify individual users; this does not apply where there are concrete indications of unlawful use.

5. Hosting and Processing on Our Behalf

This website is operated by an external service provider. The personal data collected on the website is stored on that provider's servers.

[Insert the name, legal form and full address of the hosting provider. State the server location. No name may be stated here without reliable knowledge of the provider actually used.]

The provider processes the data solely on our instructions and for the purposes we specify. A data processing agreement pursuant to Article 28(3) GDPR is in place with the provider. The legal basis for using the provider is Article 6(1) subparagraph 1(f) GDPR; our legitimate interest lies in the secure, performant and professionally administered operation of the website.

[Add any further processors here — for example for email delivery, newsletters, ticketing, backups or content delivery. A contract under Article 28 GDPR is required for each processor; the list must be completed before publication on the basis of the record of processing activities under Article 30 GDPR.]

6. Cookies and Consent Management

This website uses cookies and comparable technologies (e.g. local storage).

No consent is required under section 25(2) no. 2 TDDDG for technically necessary cookies that are strictly required to provide the digital service you have expressly requested. We base the associated data processing on Article 6(1) subparagraph 1(f) GDPR; our legitimate interest is the technically correct and secure provision of the website.

All other cookies and all other access to your terminal equipment — in particular for analytics, audience measurement or marketing purposes — are used exclusively with your prior consent under section 25(1) TDDDG; the subsequent processing of the data collected in this way is based on Article 6(1) subparagraph 1(a) GDPR. You may withdraw your consent at any time with effect for the future (Article 7(3) GDPR), without affecting the lawfulness of processing carried out before withdrawal.

[Add here: the consent management tool used, how to withdraw consent or change the selection later, and a list of the cookies actually set, with purpose, provider and storage period. This list must be compiled from a technical inspection of the live website.]

7. Contact Form and Contact by Email

You can send us a message using the contact form on this website. We process the data you enter [list the form's mandatory and optional fields specifically here, e.g. name, email address, club/organisation, message text] together with the time of submission and the technical data required to prevent abuse.

If your enquiry relates to entering into or performing a contract — for example a product demonstration or a quotation — the legal basis is Article 6(1) subparagraph 1(b) GDPR. In all other cases the legal basis is Article 6(1) subparagraph 1(f) GDPR; our legitimate interest is the prompt and traceable handling of enquiries. Where you have expressly consented to any further use, Article 6(1) subparagraph 1(a) GDPR applies.

We delete the data as soon as your enquiry has been conclusively dealt with and no statutory retention obligations prevent deletion (see section 11). The same applies to the content of your message if you contact us by email.

[If the form is protected by a spam-protection, captcha or anti-bot service, that service must be described separately here, with provider, purpose, legal basis and any third-country transfer.]

8. Newsletter with Double Opt-In

To receive our newsletter we need your email address [add any further mandatory details here, e.g. form of address, name, club]. Registration uses the double opt-in procedure: after you sign up, we send you an email containing a confirmation link. You are added to the distribution list only once you have clicked that link. If confirmation is not given, the registration is deleted automatically after [insert period, e.g. in days].

The legal basis is your consent under Article 6(1) subparagraph 1(a) GDPR; section 7(2) no. 2 UWG (German Act against Unfair Competition) applies in addition to advertising by email. To evidence consent as required by Article 7(1) GDPR, we log the time of registration and confirmation and the IP address used; the legal basis for this is Article 6(1) subparagraph 1(c) and (f) GDPR (accountability and evidence obligations, mitigation of abuse and liability risks).

You may withdraw your consent at any time with effect for the future (Article 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out up to that point. Please use the unsubscribe link at the end of each newsletter or send an informal message to the address given in section 1. Following withdrawal we delete your data from the distribution list; your email address may be retained on a suppression list to prevent future mailings (Article 6(1) subparagraph 1(c) and (f) GDPR).

[If the newsletter is sent via a service provider, that provider must be named here with its name, address and server location; a processing agreement under Article 28 GDPR is required, as are the details in section 10 where a third-country transfer is involved. If performance is measured (open and click rates, tracking pixels), this must be described separately and expressly covered by the consent obtained.]

9. Web Analytics, Audience Measurement and Embedded Third-Party Services

[This section must either be completed in full or deleted. No statement can be made here without a technical inspection of the live website — in particular, no analytics, tracking, mapping, video, font or payment service may be named whose actual use has not been verified.]

[For each service actually used, state: the provider's name and address, the purpose of processing, the categories of data processed, the legal basis (for non-essential services usually Article 6(1) subparagraph 1(a) GDPR in conjunction with section 25(1) TDDDG), the retention period, recipients, any third-country transfer, and how to withdraw consent or object.]

[Note: where fonts, icons, maps or videos are loaded from external servers, the user's IP address is transmitted to the respective provider. Such requests must also be declared here.]

10. Transfers to Third Countries

Personal data is transferred to a country outside the European Economic Area or to an international organisation only where the conditions of Articles 44 et seq. GDPR are met — in particular on the basis of an adequacy decision of the European Commission (Article 45 GDPR), appropriate safeguards such as the standard contractual clauses (Article 46(2)(c) GDPR) or, only by way of exception, a derogation under Article 49 GDPR.

[For each service provider involving a third country, state: the recipient, the recipient country, the transfer mechanism and, where standard contractual clauses are used, a reference to supplementary measures and to the transfer impact assessment carried out. If no third-country transfer takes place, shorten this section accordingly — but that statement may only be made once it has been verified for every service used.]

[Status note, to be re-checked before publication: as far as we are aware, the 2023 adequacy decision on the EU-US Data Privacy Framework remains in force for the United States; the General Court of the European Union upheld it in Case T-553/23 (Latombe) on 3 September 2025, and an appeal is pending before the Court of Justice of the European Union. The decision's continued validity is therefore not conclusively settled. Verify the current position before publication, and refer to US recipients only where their Data Privacy Framework certification has actually been checked.]

11. Retention and Erasure

We process and store personal data only for as long as is necessary for the purposes stated. Once the purpose ceases to apply, or if you withdraw a consent, the data is deleted unless a statutory retention obligation prevents this.

Statutory retention periods take precedence over erasure. The relevant provisions are in particular section 147 AO (German Fiscal Code) and section 257 HGB (German Commercial Code). For accounting vouchers and for commercial and business letters received and sent, the periods were partly shortened with effect from 1 January 2025 by the Fourth Bureaucracy Relief Act; accounting vouchers must now be retained for eight years, whereas annual financial statements, commercial books and inventories remain subject to a ten-year period. [The period applicable in each case must be checked from a tax perspective; it may be extended for as long as the assessment period under section 169 AO has not yet expired.]

In addition, data may be retained until the expiry of the standard limitation period of three years under sections 195 and 199 BGB (German Civil Code), where necessary to establish, exercise or defend legal claims (Article 6(1) subparagraph 1(f) GDPR). During such retention, processing is restricted to that purpose.

[Specific erasure periods for each processing operation — log files, contact enquiries, newsletter list, suppression list — must be taken from the erasure policy and entered here or in the relevant sections.]

12. Your Rights as a Data Subject

You have the following rights in relation to personal data concerning you:

Right of access under Article 15 GDPR to the data processed, the purposes, the recipients, the envisaged retention period and the origin of the data, and to a copy of the data.

Right to rectification of inaccurate data and completion of incomplete data under Article 16 GDPR.

Right to erasure under Article 17 GDPR, unless processing is necessary to comply with a legal obligation or to establish, exercise or defend legal claims.

Right to restriction of processing under Article 18 GDPR.

Right to data portability under Article 20 GDPR, i.e. to receive the data you have provided in a structured, commonly used and machine-readable format, where processing is based on consent or a contract and is carried out by automated means.

Right to object under Article 21 GDPR (see the separate section 13).

In addition, we communicate rectifications, erasures and restrictions to all recipients pursuant to Article 19 GDPR, unless this proves impossible or involves disproportionate effort.

Where processing is based on your consent, you may withdraw it at any time under Article 7(3) GDPR with effect for the future; the lawfulness of processing carried out before withdrawal remains unaffected.

An informal message to the contact details given in section 1 is sufficient to exercise these rights.

Without prejudice to any other remedy, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing infringes the GDPR.

[The competent supervisory authority is the data protection authority of the federal state in which the company has its registered office. Insert the authority's name, address and website only once the registered office has been determined — no authority may be guessed here.]

13. Right to Object under Article 21 GDPR

This notice is presented separately as required by Article 21(4) GDPR.

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1) subparagraph 1(e) or (f) GDPR; this also applies to profiling based on those provisions. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Where personal data concerning you is processed for direct marketing purposes, you have the right under Article 21(2) GDPR to object at any time to such processing; this also applies to related profiling. If you object to processing for direct marketing purposes, your data will no longer be processed for those purposes. No particular form is required for the objection, which may be sent to the contact details given in section 1.

14. Data Security, Currency and Governing Language Version

We take technical and organisational measures pursuant to Article 32 GDPR to protect data against loss, destruction, access, alteration or dissemination by unauthorised persons. The website is delivered over an encrypted connection (TLS). [Verify technically before publication; do not include any further security assurances that are not actually implemented.]

This privacy notice is dated [insert publication date]. We will update it where changes to our processing operations or to the law make this necessary. The current version is available on this website.

Only the German version of this privacy notice is authoritative. The English version is a non-binding translation provided for ease of understanding; in the event of discrepancies, the German version prevails.

Draft as of 25 August 2026. The German version is the binding one.