Skip to main content
Transparency & Data Protection

Privacy Policy

Information regarding the processing of personal data in accordance with Articles 13 & 14 of the General Data Protection Regulation (GDPR / DSGVO) and the German TDDDG.

1. Data Controller

The controller for data processing on this website under the GDPR is:

SprachCafé Polnisch e.V.

Schulzestr. 1, D-13187 Berlin (Germany)

Represented by the Board: Agata Koch (President & Chairwoman)

Email: kontakt@sprachcafe-polnisch.org

Phone: +49 (0)160 9968 0059

2. Privacy by Design: Modern, Secure Architecture

Our web portal has been engineered following the principles of data minimization (Art. 5(1)(c) GDPR) and privacy by default (Art. 25 GDPR) as a modern static site (Astro SSG):

🚫 100% Tracker-Free & Ad-Free (No Annoying Cookie Banners)

We do not use any tracking cookies, ad networks, behavioral profiling, or external analytics scripts (such as Google Analytics or Meta Pixel). Because we do not deploy technologies requiring consent, no cookie banner is required on our website.

🔤 Self-Hosted Fonts & Assets

All typography (Inter and Roboto) and icons are hosted directly on our own server in modern WOFF2 format. No connection is made to third-party CDNs (such as Google Fonts). Your IP address is never shared with Google or third parties during your visit.

3. Hosting & Server Log Files

Hosting in AWS (Frankfurt Region / Germany)

Our web server and reverse proxy (Caddy v2) are deployed on cloud infrastructure provided by Amazon Web Services EMEA SARL in Frankfurt am Main (`eu-central-1`), Germany. All data processing occurs strictly within the European Union.

Server Logs

When you access our pages, our server records only technically necessary connection data (IP address, date/timestamp, requested URI, HTTP status code, transferred bytes, and user agent string).

Purpose and Legal Basis: Ensuring technical stability, performance, and defense against malicious attacks (DDoS). Legal basis: legitimate interest pursuant to Art. 6(1)(f) GDPR. Logs are purged on a rolling cycle within 7 to 14 days.

4. Contact Form and Membership Applications

Online Membership Application (`/en/mitmachen/mitglied-werden/`)

Personal details submitted in the membership application are processed solely to establish and manage your association membership (Art. 6(1)(b) GDPR) and comply with statutory bookkeeping obligations (Art. 6(1)(c) GDPR).

Contact Form (`/en/kontakt/`)

Information submitted via our contact forms is transmitted directly to our secure email inbox and is used exclusively to answer your inquiry.

5. Member App, Digital Membership Card & Google Wallet

To facilitate statutory membership rights, verify digital membership passes, and manage membership benefits (such as annual free coffee quotas, event discounts, and free library access), the association provides a web portal (team.sprachcafe-polnisch.org/member/activate) and the dedicated Android application „SprachCafé Mitglied“ (org.sprachcafe.member).

  • Categories of Processed Data: First and last name, email address, phone number (if provided), member number (e.g. SCP-10001), membership tier (Silver, Gold, Platinum, Company), contribution status, free coffee quota allocation/redemptions, and dynamic QR verification tokens.
  • Legal Basis: Fulfillment of membership contract and rights (Art. 6(1)(b) GDPR) and statutory financial recordkeeping obligations (Art. 6(1)(c) GDPR).
  • On-Device Local Storage: The Android app stores pass data locally and encrypted (Android SharedPreferences) to allow offline pass presentation and scanning.
  • Optional Google Wallet Integration: Exporting the pass to Google Wallet is entirely voluntary and only initiated upon explicit user interaction (Art. 6(1)(a) GDPR).

6. Board Administration & POS Operations (`team.sprachcafe-polnisch.org`)

Administrative access to membership rosters, financial records, and POS audits is restricted and passwordlessly protected using Microsoft Entra ID (Single Sign-On) for authorized board members only.

  • Legal Basis: IT security and data protection under Art. 32 GDPR as well as legitimate organizational interests under Art. 6(1)(f) GDPR.

7. House Library (`hausbibliothek.org`)

The House Library platform at hausbibliothek.org manages book loans and reader accounts. Reader accounts inactive for more than 24 months are routinely deleted in accordance with data erasure obligations (Art. 17 GDPR).

8. Your Rights Under GDPR

You have the right to access (Art. 15 GDPR), rectify (Art. 16 GDPR), erase (Art. 17 GDPR), restrict processing (Art. 18 GDPR), receive data portability (Art. 20 GDPR), and object to processing (Art. 21 GDPR).

To exercise your rights, simply send an email to: kontakt@sprachcafe-polnisch.org.

Competent Data Protection Supervisory Authority:

Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Email: mailbox@datenschutz-berlin.de

Last updated: September 2026