Privacy Policy

Table of Contents

  1. Introduction
  2. Privacy Overview
  3. General Information
  4. Information About the Controller
  5. Hosting
  6. SSL and TLS Encryption
  7. Data Collection on This Website
  8. Plugins and Tools
  9. Your Rights

 


 

1. Introduction

The operators of this website take the protection of your personal data very seriously. We handle your personal data confidentially and in compliance with legal data protection regulations as well as this privacy policy.

When you use this website, various personal data are collected. Personal data refers to information that can be used to identify you personally. This privacy policy explains which data we collect and how we use it. It also explains the purposes for which the data is processed and how this is done.

Please note that data transmission over the internet (e.g., when communicating via email) may have security vulnerabilities. Complete protection of data against access from third parties is not possible.



2. Privacy Overview

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to any information that can be used to identify you. For detailed information on data protection, please refer to our privacy policy provided below this text.

 

Data Collection on This Website

Who is responsible for data collection on this Website?

Data processing on this website is carried out by the website operator. You can find the contact details of the operator in the section "Information About the Controller" in this privacy policy.

How do we collect your data?

Some of your data is collected when you provide it to us. For example, this may include data you enter into a contact form.

Other data is collected automatically or with your consent through our IT systems when you visit the website. This primarily includes technical data (e.g., IP address, internet browser, operating system, or time of page access). This data is collected automatically as soon as you access this website.

What Do We Use Your Data For?

Some of the data is collected to ensure the error-free provision of the website (e.g., technical data such as IP address). Data that could be used to analyze your user behavior is not collected. Data that you voluntarily provide to us through the contact form will only be used to process your inquiry.

What are your rights regarding your data?

You have the right to obtain information about the origin, recipients, and purpose of your stored personal data at any time and free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time with future effect. Additionally, under certain circumstances, you have the right to request the restriction of the processing of your personal data. Furthermore, you have the right to file a complaint with the competent supervisory authority.

For this and any further questions regarding data protection, you can contact us at any time.



3. General Information

Retention Period

Unless a specific retention period is mentioned within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you request the deletion of your data or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g., tax or commercial law retention periods); in such cases, deletion occurs after these grounds no longer apply.

 

General Information on the Legal Grounds for Data Processing on This Website

If you have given your consent to data processing, we process your personal data based on Article 6(1)(a) GDPR or, if special categories of data as defined in Article 9(1) GDPR are processed, based on Article 9(2)(a) GDPR. In the case of explicit consent to the transfer of personal data to third countries, the processing is additionally based on Article 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., via device fingerprinting), data processing is additionally based on Section 25(1) of the German TDDDG. Consent can be withdrawn at any time. If your data is required to fulfill a contract or to carry out pre-contractual measures, we process your data based on Article 6(1)(b) GDPR. Additionally, if data processing is necessary to fulfill a legal obligation, we process your data based on Article 6(1)(c) GDPR. Data processing may also occur based on our legitimate interest under Article 6(1)(f) GDPR. The applicable legal basis for specific cases is provided in the following sections of this privacy policy.

 

Recipients of Personal Data

As part of our association‘s activities, we work with various external parties. In some cases, this requires the transfer of personal data to these external parties. Personal data is only shared with external parties if this is necessary for contract fulfillment, if we are legally obligated to do so (e.g., sharing data with tax authorities), if we have a legitimate interest in the transfer under Article 6(1)(f) GDPR, or if another legal basis permits the data transfer. When using data processors, we only share personal data of our website visitors based on a valid Data Processing Agreement (DPA). In the case of joint processing, a Joint Processing Agreement is concluded.



4. Information About the Controller

The controller responsible for data processing on this website is:

St. Andreas Gemeinde e. V.
Rankestraße 14
76137 Karlsruhe
Germany

Phone: +49 (0) 7251 3225037
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).



5. Hosting

We host the content of our website with the following provider:

Alfahosting

The provider is Alfahosting GmbH, Edmund-von-Lippmann-Straße 13-15, 06112 Halle (Saale), Germany (hereinafter referred to as Alfahosting). When you visit our website, Alfahosting collects various personal data, including your IP address, and stores this data in an anonymized form in the server log files.

For more details, please refer to Alfahosting's privacy policy: https://alfahosting.de/datenschutz/.

The use of Alfahosting is based on Article 6(1)(f) of the GDPR. We have a legitimate interest in ensuring the most reliable presentation of our website.

Data Processing Agreement

We have entered into a Data Processing Agreement (DPA) with the provider mentioned above. This is a contract required under data protection law to ensure that Alfahosting processes the personal data of our website visitors solely in accordance with our instructions and in compliance with the GDPR.



6. SSL and TLS Encryption

For security reasons and to protect the transmission of confidential content and personal data, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the change in the browser's address bar from "http://" to "https://" and by the lock symbol in your browser's address bar.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.



7. Data Collection on This Website

Cookies

General Information

Our website uses so called "cookies". Cookies are small data packets that do not cause any harm to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after your visit ends. Permanent cookies remain stored on your device until you delete them manually or they are automatically deleted by your web browser.

Cookies serve various purposes. Many cookies are technically necessary as certain website functions would not work without them (e.g., the shopping cart function or video displays). Other cookies may be used to analyze user behavior or for advertising purposes.

You can configure your browser to inform you about the use of cookies, to allow cookies only in individual cases, to exclude the acceptance of cookies for specific cases or in general, and to automatically delete cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

Cookies in Use

This website uses two cookies, both of which are technically necessary to ensure the proper functioning of the website and to display the site as previously configured during your next visit.

  • Session Cookie: This stores only the session ID and is deleted no later than when you close your browser.
  • Language Cookie: This stores only the language you selected for the website. It is automatically deleted one year after your last visit to the website, but you can delete it manually at any time.

The use of these cookies is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in ensuring the optimal functionality of the website and providing a user-friendly and efficient experience during visits.

 

Server Log Files

The provider of these sites automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This includes:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Access to this website, including subpages
  • Date and time of the server request
  • IP address
  • Internet service provider used
  • Other similar data and information used for threat prevention in the event of attacks on our IT systems

This data is not merged with other data sources. Additionally, the data is not shared with third parties or used to draw conclusions about the data subject.

The collection of this data is carried out on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in ensuring the technically error-free presentation and optimization of their website, for which the server log files must be recorded.

 

Contact Form

You can send general inquiries to us via the contact form. The information you provide, including your contact details, is used exclusively to process your inquiry and for potential follow-up questions. Your data will not be shared with third parties without your explicit consent.

The processing of this data is based on our legitimate interest in effectively managing inquiries addressed to us (Art. 6(1)(f) GDPR).

The data you enter in the contact form will be stored only as long as is necessary to process your request. Mandatory legal provisions—especially retention periods—remain unaffected.

 

Inquiries via Email or Phone

If you contact us via email or phone, your inquiry, including all resulting personal data (e.g., name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not share this data without your consent.

The processing of this data is based on Art. 6(1)(b) GDPR if your inquiry is related to the fulfillment of a contract or is necessary for pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), if such consent was obtained. Consent can be revoked at any time.

The data you send to us as part of contact inquiries will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions—especially legal retention periods—remain unaffected.



8. Plugins and Tools

PDF Viewer (Local Hosting)

Our website embeds PDF documents. To display these PDF documents, we use PDF.js by Mozilla.

Both the PDF documents themselves and all necessary components for displaying the PDFs on the website are hosted directly on our server and provided from there. Therefore, no personal data is transmitted to third parties.

 

SmartMaps Map Service

On this website we use the “SmartMaps” map platform of YellowMap AG, CAS-Weg 1-5, 76131 Karlsruhe, Germany, which enables us to display map services directly on the website.

When you access the SmartMaps service, your browser transmits technically necessary data to the YellowMap AG servers in order to provide the service. This data is processed in compliance with the GDPR and is not stored permanently.

When using the location map, no cookies are set by the map service provider.

Further information can be found at htts://www.smartmaps.net/gdpr.

You can prevent the future transmission of technically necessary data to the servers of YellowMap AG by disabling JavaScript in your browser. However, please note that this will disable not only the SmartMaps mapping service but also all other website functionalities that rely on JavaScript.

The use of SmartMaps is based on our legitimate interest in ensuring a user-friendly design of our online services and facilitating the accessibility of our physical location. This constitutes a legitimate interest under Art. 6(1)(f) GDPR.

Data Processing Agreement

We have entered into a data processing agreement (DPA) for the use of the mapping service mentioned above. This legally required agreement ensures that YellowMap AG processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

 

Button “Navigate to the Chapel” – Navigation App

On our website, we offer you the option to access the navigation service of your device by using the “Navigate to the Chapel” button. Depending on your operating system, either the Apple Maps app (for iOS devices) or the Google Maps app (for Android devices) will be opened. If neither operating system is detected, a new browser tab with the Google Maps website will be opened.

When you click the button, you are redirected to either the Apple Maps app, the Google Maps app, or the Google Maps website. Please note that in this context, personal data such as your IP address, location data (if enabled on your device), and potentially other data may be transmitted to the respective providers (Apple or Google) according to their privacy policies.

By clicking the button and using the respective mapping or navigation services, data is transmitted to the respective provider (Apple or Google), who is independently responsible for processing your data. As the website operator, we have no influence over the collection and processing of data by these external services.

For details on the personal data collected by the service providers and further information on data processing when using Apple Maps or Google Maps, please refer to their respective privacy policies:



9. Your Rights

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You may withdraw any previously given consent at any time. The withdrawal of consent does not affect the lawfulness of data processing carried out prior to the withdrawal.

 

Right to Object to Data Collection in Special Cases (Art. 21 GDPR)

If data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right, at any time, to object to the processing of your personal data for reasons arising from your particular situation; this also applies to profiling based on these provisions. The legal basis for processing can be found in this privacy policy. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims (objection pursuant to Art. 21(1) GDPR).

 

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of a breach of the GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or the location of the alleged infringement. This right is without prejudice to any other administrative or judicial remedies.

 

Right to Data Portability

You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done where it is technically feasible.

 

Access, Rectification, and Erasure

You have the right, within the scope of applicable legal provisions, to access your stored personal data, its origin, its recipients, and the purpose of its processing, at any time and free of charge. You also have the right to request that your data be rectified or erased. For these and any other inquiries regarding personal data, you may contact us at any time.

 

Right to Restrict Processing

You have the right to request the restriction of processing of your personal data. You can contact us at any time to exercise this right. The right to restriction of processing applies in the following cases:

  • If you contest the accuracy of your personal data stored with us, we will need time to verify this. During the verification period, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you may request the restriction of data processing instead of erasure.
  • If we no longer need your personal data but you require it for the establishment, exercise, or defense of legal claims, you have the right to request the restriction of processing instead of erasure.
  • If you have objected to processing pursuant to Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. Until it is determined whose interests prevail, you have the right to request the restriction of processing of your personal data.

If you have restricted the processing of your personal data, such data—apart from being stored—may only be processed with your consent or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.