Privacy Policy
Courtesy translation. The German version is the legally binding one.
We are delighted by your interest in our work. Data protection is a particularly high priority for Tales&Legends gemeinnützige UG (haftungsbeschränkt). Our website can generally be used without providing any personal data. However, if a data subject wishes to use special services offered through our website, processing of personal data may become necessary. Where such processing is necessary and there is no statutory basis for it, we generally obtain the data subject's consent.
The processing of personal data is always carried out in compliance with the General Data Protection Regulation (GDPR) and the country-specific data protection provisions applicable to us. Through this privacy policy, we inform the public about the nature, scope, and purpose of the personal data we collect, use, and process, and about the rights to which data subjects are entitled.
1. Definitions
This privacy policy is based on the terminology used in the GDPR. We use, among others, the following terms:
- Personal data: any information relating to an identified or identifiable natural person (the "data subject").
- Processing: any operation performed on personal data, whether or not by automated means (collection, recording, storage, alteration, retrieval, use, disclosure, erasure, etc.).
- Restriction of processing: the marking of stored personal data with the aim of limiting its processing in the future.
- Pseudonymization: the processing of personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional, separately held information.
- Controller: the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processor: a natural or legal person which processes personal data on behalf of the controller.
- Consent: any freely given, informed, and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of personal data relating to them.
2. Name and address of the controller
The controller within the meaning of the GDPR is:
Tales&Legends gemeinnützige UG (haftungsbeschränkt)
Reiboldschachtring 28
01705 Freital
Germany
Phone: 01522 2584587
Email: nils@talesandlegends.org
Website: https://talesandlegends.org
3. Cookies
Our website uses cookies — text files stored on the data subject's computer system via their browser. Cookies help us make our website more user-friendly and recognize returning visitors.
Non-essential cookies (e.g., for Google Analytics) are only set once the data subject has given consent via our website's cookie-consent banner. Data subjects can prevent cookies from being set at any time via their browser settings and can delete cookies already stored. Disabling cookies may mean not all features of our website are fully usable.
4. Collection of general data and information (server log files)
Our website collects a range of general data and information with every access, stored in the server's log files: browser type and version used, operating system, referrer URL, subpages accessed, date and time of access, IP address, and the internet service provider of the accessing system.
We draw no conclusions about the data subject from this data. It is needed to correctly deliver the content of our website, ensure the continued functionality of our IT systems, and to provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack.
5. Newsletter
Our website offers the option to subscribe to our newsletter. Which personal data is transmitted when ordering the newsletter is apparent from the input form used for this purpose. We use EmailOctopus (EmailOctopus Ltd.) as a processor for sending and managing the newsletter.
Sending follows the double opt-in procedure: a confirmation email is sent to the email address entered for the first time, verifying that the holder of that address has authorized receipt of the newsletter. We also store the IP address assigned by the internet service provider and the date and time of registration, to be able to trace any possible later misuse of the email address.
Data collected as part of newsletter registration is used exclusively to send the newsletter and is not passed on to third parties outside of EmailOctopus. The subscription can be cancelled at any time via the unsubscribe link in every newsletter or by contacting us.
6. Newsletter tracking
Our newsletters, sent via EmailOctopus, may contain what are known as tracking pixels — miniature graphics embedded in the email that enable a log file to be recorded and analyzed. This allows us to determine statistically whether and when an email was opened and which links it contains were clicked, in order to optimize our newsletter distribution. This data is not passed on to third parties outside of EmailOctopus. We treat an unsubscribe from the newsletter as an automatic withdrawal of this consent.
7. Contact options via the website
Due to legal requirements, our website contains information that enables quick electronic contact with us and direct communication, including a general email address. If a data subject contacts us by email or via our contact form, the personal data transmitted is automatically stored and used exclusively to process the inquiry or to make contact with the data subject. This personal data is not passed on to third parties.
8. Routine erasure and blocking of personal data
We process and store personal data only for the period necessary to achieve the storage purpose, or as provided for by law. If the storage purpose no longer applies, or a statutory retention period expires, the personal data is routinely blocked or erased in accordance with statutory provisions.
9. Rights of the data subject
- Right of confirmation and access: you may, at any time, request free confirmation and information about the personal data stored about you, including a copy of that data, as well as information about processing purposes, categories of data, recipients, and the intended storage period.
- Right to rectification: you may request the immediate correction of inaccurate personal data, or the completion of incomplete personal data.
- Right to erasure ("right to be forgotten"): you may request the erasure of your personal data where one of the grounds listed in Art. 17 GDPR applies (e.g., the data is no longer necessary, consent is withdrawn, or the data was processed unlawfully).
- Right to restriction of processing: you may request restriction of processing, e.g. if you contest the accuracy of the data or oppose erasure and request restricted use instead.
- Right to data portability: you may receive personal data concerning you that you have provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller, provided the processing is based on consent or a contract and is carried out by automated means.
- Right to object: on grounds relating to your particular situation, you may object at any time to processing of your personal data based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions.
- Automated individual decision-making: you have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you.
- Right to withdraw consent: you may withdraw any consent given to us at any time, with effect for the future.
- Right to lodge a complaint with a supervisory authority: without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement.
To exercise these rights, you may contact us at any time using the contact details given in section 2.
10. Google Analytics (GA4)
We use Google Analytics 4 (GA4) on our website, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland. GA4 collects, among other things, data on which website a data subject came from (referrer), which subpages were accessed, and how long they were viewed, in order to optimize our website.
GA4 truncates and anonymizes IP addresses by default and without any separate configuration, before they are stored — unlike older versions of Google Analytics, no additional flag is required for this. GA4 is only loaded after the data subject has given consent via our cookie-consent banner.
The data subject can object to collection by GA4 by declining in the consent banner, or by installing the browser add-on provided by Google at https://tools.google.com/dlpage/gaoptout. Further information on Google's privacy policy is available at https://policies.google.com/privacy.
11. Cloudflare Turnstile
We use the Cloudflare Turnstile service on our website to protect forms (donations, contact) from automated access (bots) — a privacy-friendly alternative to classic CAPTCHAs that generally does not require solving a puzzle.
The operating company is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA; for users in the European Economic Area, Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, is additionally named as a contact. When Turnstile is embedded, data such as IP address, browser and operating system information, the subpage accessed, date/time, and interaction data from the verification process may be transmitted to Cloudflare; this data may be stored in a cookie.
Processing is based on Art. 6(1)(f) GDPR — our legitimate interest is protecting our forms from abuse and spam. Transfer to the USA is based on the Standard Contractual Clauses approved by the European Commission; Cloudflare has also joined the EU-U.S. Data Privacy Framework. Cloudflare's privacy policy is available at https://www.cloudflare.com/de-de/privacypolicy/, and the Turnstile Privacy Addendum at https://www.cloudflare.com/turnstile-privacy-policy/.
12. PayPal as a payment method
We offer PayPal as a payment option for donations. The European operating company is PayPal (Europe) S.Ã .r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. If the data subject selects PayPal as the payment method, the data necessary for payment processing (e.g., name, address, email address, IP address) is automatically transmitted to PayPal. By selecting this payment option, the data subject consents to this transmission.
The transmission serves payment processing and fraud prevention. Withdrawing consent with PayPal does not affect data already processed for the contractual payment transaction. PayPal's privacy policy is available at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
13. Azure Communication Services (email delivery)
We send automated emails (donation confirmation, donation receipt, payment reminder, forwarding of contact form inquiries) via Azure Communication Services, a service of Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. This processes the data necessary for the respective email (including email address, name, and the subject/content of the relevant message).
The legal basis is Art. 6(1)(b) GDPR (fulfillment of the donation/contractual relationship) or Art. 6(1)(f) GDPR (legitimate interest in responding to contact inquiries). A data processing agreement is in place with Microsoft. Further information on Microsoft Azure's privacy policy is available at https://privacy.microsoft.com/de-de/privacystatement.
14. Storage of donation and contact data
To process donations (including donation receipts) and handle contact inquiries, we store personal data in a Microsoft Azure database (Cosmos DB), and generated donation receipts as PDFs in a Microsoft Azure storage account (Blob Storage). A data processing agreement with Microsoft applies here too; data is stored only as long as necessary to process the donation and to satisfy statutory retention obligations (in particular tax-related retention periods for donation receipts).
15. Legal basis for processing
Where we obtain consent for a specific processing purpose, Art. 6(1)(a) GDPR serves as the legal basis for our processing. Where processing is necessary for the performance of a contract to which the data subject is party (e.g., processing a donation), the processing is based on Art. 6(1)(b) GDPR; the same applies to processing required to carry out pre-contractual measures. Where we are subject to a legal obligation that requires processing (e.g., tax retention obligations), processing is based on Art. 6(1)(c) GDPR. Otherwise, processing may be based on Art. 6(1)(f) GDPR, provided it is necessary to safeguard a legitimate interest and the data subject's interests, fundamental rights, and freedoms do not override it.
16. Legitimate interests pursued in the processing
Where processing is based on Art. 6(1)(f) GDPR, our legitimate interest lies in fulfilling our non-profit purpose — running and safeguarding our LARP events, processing donations, and providing our website securely and reliably.
17. Duration of storage
The criterion for the duration of storage of personal data is the applicable statutory retention period (in particular commercial and tax law retention periods for donation receipts). Once the period expires, the corresponding data is routinely erased, provided it is no longer needed for the performance or initiation of a contract.
18. Provision of personal data
We advise that the provision of personal data is partly required by law (e.g., tax regulations for donation receipts) or may arise from contractual arrangements. Without certain data (e.g., a valid email address), a donation, newsletter registration, or the handling of a contact inquiry may not be possible.
19. Automated decision-making
We do not use automated decision-making or profiling.