Skip to main content

Version from 18 October 2026

Legal

Privacy Policy

Last updated: September 2026

DSV Version 1.9

This version takes effect on 18 October 2026. The currently applicable privacy policy remains at jetztangeln.de/privacy.

1. General Information and Controller

The protection of your personal data is a central concern for us. This privacy policy transparently informs you about which data we collect in the context of using our website and app, for what purpose we process it, and which rights you have as a data subject.

Controller within the meaning of the General Data Protection Regulation (GDPR) is: JetztAngeln UG (haftungsbeschränkt) Birnbaumweg 9, 37176 Nörten-Hardenberg Email: [email protected]

For data protection inquiries and to exercise your data subject rights, please contact us at: [email protected]

2. Data Security and Access Control

All data transmissions between your end device and our servers are exclusively encrypted via HTTPS using current TLS protocols. Administrative access to our servers and to all processed data is exclusively possible via our own secured VPN network based on WireGuard. Access from outside this network is technically excluded. These measures serve to implement a level of protection appropriate to the risk pursuant to Art. 32 GDPR.

3. Hosting, Infrastructure and DNS

Our website and all backend systems are operated on our own servers within Germany. The technical infrastructure is based on container technology (Docker) and includes the components PostgreSQL, MariaDB, Redis, Minio, and Traefik. For support and sales we also operate self-hosted applications (Chatwoot for contact and live chat, Calnode for appointment booking, Twenty as CRM) on the same infrastructure in Germany. Transmission of personal data to third parties occurs exclusively on a legal basis.

External Resources

Our website uses a Markdown editor that automatically loads several JavaScript libraries and CSS files from the CDN service unpkg.com upon page access. These are the libraries highlight.js, KaTeX, Mermaid, ECharts, Cropper.js, Prettier, and Screenfull. With each of these loading processes, the user's IP address is transmitted to the servers of unpkg.com. unpkg.com is operated by Cloudflare, Inc., so the same safeguards apply to these transmissions as for our other Cloudflare usage (Standard Contractual Clauses of the EU Commission pursuant to Art. 46 GDPR). We have no influence on this behavior, as it is technically conditioned by the editor used. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in operating the website).

4. Data Collection on the Website

Cookies and Local Storage

For the technically sound operation of the website, we use essential cookies that may be set without consent because they are strictly necessary for basic functionality. In addition, we use non-essential cookies exclusively after your explicit consent, which you can give via our consent banner. The legal basis for this is Art. 6(1)(a) GDPR.

Contact Form and Live Chat

Inquiries via our contact form and the live chat on the website are processed via the self-hosted Chatwoot solution on our servers in Germany. Your inquiry or chat data is not shared with external third-party providers. Processing may include in particular name, email address, message content, and technical metadata for delivery. Processing is carried out on the basis of Art. 6(1)(b) GDPR to handle your request or Art. 6(1)(f) GDPR (legitimate interest in efficient customer communication).

Appointment Booking (Calnode) and Google Meet

For scheduling appointments (e.g. product demos or support calls) we use the self-hosted scheduling solution Calnode on our servers in Germany. Name, email address, the requested appointment time, and any other information you provide may be processed. For the video conference Calnode typically creates a Google Meet link (Google Ireland Limited / Google LLC). To organize and run the video meeting, name, email address, appointment time, and technical connection data may in particular be transmitted to Google. The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR (legitimate interest in organizing and conducting consultation appointments). For transfers to third countries (in particular the USA), Google relies on Standard Contractual Clauses pursuant to Art. 46 GDPR. Further information: https://policies.google.com/privacy

CRM (Twenty)

To handle inquiries, prospects, and existing contacts we use the self-hosted CRM solution Twenty on our servers in Germany. Contact data and communication history from the contact form, live chat, and appointment booking may be consolidated there and accessed by authorized staff of JetztAngeln UG. Data is not shared with external third-party providers. The legal basis is Art. 6(1)(b) or (f) GDPR (pre-contractual steps or legitimate interest in structured customer support).

Microsoft Clarity

If you have consented via our consent banner, we use Microsoft Clarity, a web analytics service of Microsoft Corporation (One Microsoft Way, Redmond, WA 98052, USA). Clarity records interactions on our website (e.g. clicks, scroll behavior, mouse movements) and creates aggregated heatmaps and session recordings to improve our website. IP address, device and browser information, and pseudonymized usage data may be transmitted to Microsoft. Without your consent, the Clarity script is not loaded. Processing is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time by reopening the consent dialog via the “Cookie settings” link in the footer. For transfers to the USA, Microsoft relies on the Standard Contractual Clauses of the EU Commission pursuant to Art. 46 GDPR. Further information is available in Microsoft's privacy statement: https://privacy.microsoft.com/privacystatement

Remote Config and Product Experiments

To control product features, we load our own feature flags (remote config) from our servers in Germany. Delivering default values is required for operation and takes place without a personal identifier (Art. 6(1)(f) GDPR or as technically necessary processing). If you consent to the “Product experiments” category, we store a random first-party identifier (cookie/local storage) to assign you consistently to an A/B variant. This identifier is not shared with third parties and is used solely for variant assignment. Without this consent you always receive the default value. The legal basis for the identifier and A/B assignment is Art. 6(1)(a) GDPR. You may withdraw consent at any time via the consent dialog; the identifier is then deleted.

5. Data Collection and Functions in the App

In the context of using our app, we process personal data to the following extent:

Account Data

When registering and using your account, we collect your name, email address, and telephone number. In addition, we store relevant timestamps (account creation, last change, last login), your profile picture, and your club role.

Social Profile and Mentions

For the community we store a social profile with a unique mention slug (@name) and an option to hide your civil name in posts, comments, and feeds. In that case the mention slug or a display name is shown instead of your name. Mentions and user search may resolve the slug. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in a usable community).

Community, Posts and Blocks

Content that you publish within the app - including posts, comments, replies, and likes - is stored and processed. Feed notifications may store the display name of acting persons and be delivered by push or in-app. You can block other users; interactions and notifications are then filtered accordingly. If you report a violation of our terms of use, this process is documented and may be reviewed by staff of JetztAngeln UG (platform moderation).

Club Data

For managing club profiles, we process information such as name, address, telephone number, contact person, website, and description of the club as well as uploaded club documents, statutes, and regulations. Where clubs act as providers within the meaning of PStTG/DAC7, we also process tax identification and register data of the club, in particular tax number, issuing country, VAT ID (if available), club/register number, register court, legal form, and, where applicable, a financial account identifier where this is available to us through payment service providers such as Mollie.

Member Master Data (Club)

Where the club maintains memberships on the platform, additional member master data provided or managed by the club may be processed, in particular salutation, title, gender, date of birth, address, membership number, status, start/end of membership, club role, custom club attributes, and payment data such as IBAN and SEPA mandate reference. Where the club allows it, members can complete or correct selected master data and custom club attributes themselves in the app. For youth management, the club may configure an age limit in years and optional automation to adjust membership status and notify authorized administrators when a youth member reaches that age limit; the stored date of birth may be evaluated for this purpose. The controller for this club membership data is regularly the club; JetztAngeln UG acts in this respect as a processor pursuant to Art. 28 GDPR.

Club Messages

Club administrators can send targeted messages to members or selected recipient groups (in-app and/or email, possibly with attachments). Recipients may have delivery preferences. In addition, push notifications may be triggered via Firebase Cloud Messaging. The legal basis is Art. 6(1)(b) or (f) GDPR in the context of club communication; the club is responsible for content and recipient circle.

Work Services

Clubs can create work services (title, locations as free text, description, time range, and optional helper count as a guideline). Linked club members can sign up in the app and optionally choose tasks if the club has defined tasks. Task occupancy (who took which task) is visible to club members. After the event, members can enter hours worked themselves; club administrators confirm or lock the entries. Reminders may be sent by email and push where user preferences allow. For settlement, required hours and an hourly rate may be configured; club administrators can generate a SEPA debit export for unpaid hours. The controller for this club data is regularly the club; JetztAngeln UG acts in this respect as a processor pursuant to Art. 28 GDPR. The legal basis is Art. 6(1)(b) or (f) GDPR in the context of club administration.

Events

Clubs can create events (title, type, location as free text, description, time range, and optional participant count as a guideline). This includes youth group meetings. For those, an audience by membership status and additionally invited club members outside the selected status groups may also be stored. Linked or invited club members can RSVP or cancel in the app. Reminders (including the day before and about one week beforehand) may be sent by email and push where user preferences allow. The club may configure a minimum attendance at youth group meetings per calendar year; if attendance falls short, warnings may be sent to affected members and the attendance overview may be highlighted for authorized roles. An event can be linked to multiple work services (and vice versa). Access and editing are limited to authorized club roles (in particular type-specific rights, youth management, or administrator rights). The controller for this club data is regularly the club; JetztAngeln UG acts in this respect as a processor pursuant to Art. 28 GDPR. The legal basis is Art. 6(1)(b) or (f) GDPR in the context of club administration.

Meeting Minutes

Clubs can maintain meetings and related minutes on the platform. This may include title, meeting type, location, time range, and status (draft or completed). Attendance lists with linked club members and/or guest names (also without an app account) and participant roles may be recorded, as well as agenda items, resolutions (text, votes, acceptance or rejection), and the minutes as free text. On completion, the time and the completing person may be documented. Access and editing are limited to authorized club roles (in particular with meeting-minutes permission or administrator rights). The controller for this club data is regularly the club; JetztAngeln UG acts in this respect as a processor pursuant to Art. 28 GDPR. The legal basis is Art. 6(1)(b) or (f) GDPR in the context of club administration.

Stocking Measures

Clubs can record stocking measures on the platform (water body, fish species, amount in kg, stocking date, optional cost and notes) and store yearly stocking plans per water and species. Evaluations show the biomass balance of target stocking, actually stocked amounts, and harvested catch data. Warning thresholds for the success rate are configurable per club. Access and editing are limited to authorized club roles (in particular with stocking permission or administrator rights). The controller for this club data is regularly the club; JetztAngeln UG acts in this respect as a processor pursuant to Art. 28 GDPR. The legal basis is Art. 6(1)(b) or (f) GDPR in the context of club administration.

Annual Catch Lists and Document Analysis

Clubs may upload annual catch lists (e.g. PDF or scan) and optionally have them analyzed automatically via Microsoft Azure Document Intelligence. Details about members and catches may be extracted from the documents and taken over in structured form. This function is only used if the club actively enables it. The club is responsible for ensuring that processing of the uploaded documents is lawful and that data subjects have been informed. Azure may process data as a processor; details follow from section 9 and the DPA.

Catch Reports and Fishing Days

Catch reports include time, location, and optionally a photo of the catch. Optionally, you may link a catch report to a bait previously stored in your personal bait catalog. In addition, results of automated rule checks may be stored with a catch report (e.g. closed season, minimum/maximum length, minimum/maximum weight, and catch limits at club, water, or guest-ticket product level) where corresponding rules are configured. If you assign a catch position to a catch report, we store the coordinates you set together with the report. For fishing day reports, a timestamp is stored. Club administrators may also enter fishing days and catches for members or guests (with guest display name and capture source). Your device's live GPS location is used to display your position on the water map and is not stored permanently as a tracking history.

Baits (Personal Catalog)

In the app you can create a personal catalog of your fishing baits. We store details you enter such as name, bait type, brand or model, and size or weight, and optionally a photo. You may optionally link a stored bait to a catch report. The bait catalog belongs to your user account and is not available to club administrators as a club catalog. On account deletion, your baits including any related optional photos are deleted; references on existing catch reports are removed. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

Offline Use and Local Caching

To enable fishing, maps, and inspections without a stable internet connection, the app stores selected data locally on your device. This may include in particular: digital guest tickets and membership indicators, water and regulation information, catch limits, local fishing days and catch reports (including optional photos and catch positions), your local bait catalog (including optional photos), pending sync jobs (outbox), downloaded map tiles, and cryptographically signed offline inspection grants for fisheries wardens. In addition, devices of authorized fisheries wardens (supervisor_mode permission) may store inspection data for club guest tickets that are valid, within 24 hours before start, or within 24 hours after expiry (including buyer name, ticket details, catches, catch limits, and security-related information) so that offline inspection is also possible via guest ticket code (manual entry, physical ticket QR, or wallet QR). These snapshots are removed from the device at the latest 24 hours after the respective guest ticket expires (valid_until), on logout, or when supervisor permission is lost. When connectivity is restored, pending operations are synchronized with our servers. The legal basis is Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in usable offline functionality and enforcement of fishing rules). Local caches can be removed on logout, account deletion, or via corresponding app functions; until then the data remains on your device.

Water Information

Water information including associated images is maintained both by JetztAngeln UG and by the clubs themselves. Where clubs edit this content, they act as data controllers for the content they post; JetztAngeln UG only provides the technical platform in this regard. To publish a water, the club may upload proof of ownership or lease. These document images are stored on servers in Germany and reviewed manually by staff of JetztAngeln UG. After approval the files are kept until the expiry date plus 30 days, after rejection for 24 hours, otherwise until club use of the service ends. A later rejection returns the water to draft.

Legitimation (Fishing License)

To verify your fishing entitlement, you can upload your fishing license. The document images are stored on servers in Germany and reviewed manually by staff of JetztAngeln UG (approval or rejection with reasons). An approved fishing license may be a prerequisite for purchasing digital guest tickets. After approval the images are kept until the expiry date plus 30 days, after rejection for 24 hours, otherwise until account deletion. Review status metadata may be kept longer. We may send expiry notices by email. If the display name in the buyer profile or relevant name data changes, a new review may be required or an existing approval may become invalid. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in preventing abuse).

Club Join via QR Code

Clubs can provide a QR code via which users can submit a join application. In the course of this process, the name, profile picture, email address, and time of last activity of the joining user are displayed to the club administrator for review so that they can accept or reject the application. Processing of this data is carried out on the basis of Art. 6(1)(b) GDPR in the context of preparing a contractual relationship between the user and the club.

Buyer Profile (Guest Tickets)

For purchasing digital guest tickets, we collect a buyer profile with display name, date of birth, and postal address (street, postal code, city, country). These details serve contract performance, age verification (including separate notices/consents for minors), and invoice/proof documentation. Whether a buyer was a minor at the time of purchase may be stored with the order. Processing is based on Art. 6(1)(b) GDPR (performance of a contract) and, where tax or reporting retention is required, Art. 6(1)(c) GDPR. Club administrators do not generally receive the postal address from the buyer profile, but only under the conditions set out in section 6 (catch-limit exceedance, documented rule violation on a catch report, or review of a security case).

Digital Wallet Passes

After purchasing a guest ticket, we may provide links to digital wallet passes (Apple Wallet / Google Wallet). The passes may contain buyer and ticket data. For Google Wallet, corresponding data may be transmitted to Google for pass generation. The legal basis is Art. 6(1)(b) GDPR.

Security Violations and Bans

Fisheries wardens may report violations at the water in the app (type, severity, note, reference to fishing day/water/club), including where a report is first captured offline and synchronized later. Authorized club administrators with review permission (e.g. the board) are notified of new reports by email and - unless disabled in the app settings - by push notification so they can promptly verify or reject the report. Verified violations are made available in the platform network to other clubs for risk-based inspection and guest ticket sales. This may result in club-specific bans, purchase approvals, or a platform-wide exclusion. Affected users are notified by email. The legal basis is Art. 6(1)(f) GDPR (legitimate interest of clubs and the platform in enforcing fishing rules and protecting waters) or Art. 6(1)(b) GDPR where this serves contract performance.

6. Visibility and Roles

Club administrators have access within their administrative function at any time to the following data of their members and of app users linked to the club: name, email address, profile picture, club role, time of last activity, and catch reports and fishing days. In addition, administrators can change a member's club role. In the QR code-based join procedure, administrators see the name, profile picture, email address, and time of last activity of a prospective member to decide on admission to the club. Authorized roles with meeting-minutes permission or administrator rights may view and edit meeting minutes including attendance, agenda, resolutions, and transcript. Authorized roles with stocking permission or administrator rights may view and edit stocking entries and yearly stocking plans and related catch aggregations (water body, species, time range) for the biomass balance. Authorized roles with youth management may view and manage youth members as well as youth group meetings including RSVPs, invitations, and attendance overviews, and may maintain the club's youth management settings. Postal addresses from the buyer profile (address for guest ticket purchases) and - where available - postal addresses from club membership master data are not freely visible to club administrators. They are disclosed exclusively and only after server-side validation when, within the selected period, a configured catch limit was exceeded, a documented rule violation was recorded for a catch (e.g. closed season, minimum/maximum length, or minimum/maximum weight), or authorized administrators review a reported security case (permission to review security cases). In those cases, administrators may view the name and postal address of the person concerned where this is necessary to enforce club and water rules and to communicate with fisheries authorities. The legal basis is Art. 6(1)(f) GDPR (legitimate interest of the club in enforcing its rules) or, where the club is the controller for that processing, the legal bases relied on by the club. The fisheries authority can temporarily access relevant member data via a QR code-based inspection process. This access is limited in time to the end of the respective fishing day, but no more than 30 minutes. Where offline inspections are used, the check relies on locally held, time-limited digital grants (signed angler QR) or on pre-synced inspection data for valid guest tickets for ticket-code checks (including physical ticket or wallet QR); those snapshots remain on the warden device at most until 24 hours after the respective guest ticket expires. Final server-side documentation may occur with delay after synchronization. In this relationship, the respective fishing club acts as the data controller for the usual admin visibility (member data, catch reports, fishing days, meeting minutes, youth management, and events); JetztAngeln UG acts as the technical processor pursuant to Art. 28 GDPR. Disclosure of postal addresses from the buyer profile is instead a disclosure between controllers and is not covered by that processor relationship.

7. App Permissions

Depending on the functions used, the app requires the following device accesses: access to camera and photo library for uploading profile pictures, posts, bait photos, and the fishing license as well as for QR code-based inspection by fisheries authorities; access to location data (GPS) to display your position on the water map and - where you set it - to store a catch position; and permission to receive push notifications (Firebase Cloud Messaging) for club information, club messages, feed activity, fishing day reminders, status messages, and security-related notices (e.g. new violation reports for authorized administrators). For offline maps, map tiles may be cached locally. All permissions are activated only after your explicit consent. For collecting crash reports, technical device information such as device model and operating system version is also collected and transmitted to Firebase Crashlytics. For feature flags we load our own remote-config values from our servers; default values without A/B assignment are required for operation. If you consent to the “Product experiments” category in the privacy dialog, we store a random first-party identifier locally for consistent A/B assignment (not shared with third parties). Security-critical data - such as authentication tokens and offline inspection grants - are stored encrypted or otherwise protected in device storage.

8. Registration via Third Parties

You have the option to register via Google Sign-In or Apple Sign-In. In that case, name and email address are transmitted to us by the respective provider. Passwords remain exclusively with the selected provider and are not stored or processed by us at any time.

9. Third-Party Providers, SDKs and Processing

For specific functions of our app and website, we use specialized third-party providers. In detail these are: Mollie B.V. for secure payment processing and payouts to clubs; Google Ireland Limited / Firebase for Crashlytics (crash reports, device information) and Firebase Cloud Messaging (push notifications, device push tokens); Microsoft Corporation for Clarity (web analytics, only after consent) and optionally Azure Document Intelligence (analysis of annual catch lists on club initiative); CARTO (Basemaps CDN) and Esri ArcGIS World Imagery for map tiles or satellite maps; the public OpenStreetMap Nominatim instance (nominatim.openstreetmap.org) for address geocoding (your IP address may be transmitted to the OpenStreetMap Foundation); where applicable Google for Google Wallet passes; Google Ireland Limited / Google LLC typically for Google Meet in connection with video appointments booked via Calnode (name, email, appointment metadata, and connection data); and Cloudflare for DNS resolution, DDoS protection, and other security functions. MapLibre serves as a client-side map rendering library and does not itself receive personal server data from us; map tiles are loaded via the named tile providers. When using these services, IP addresses and technical metadata may be transmitted to the respective providers. Chatwoot (contact and live chat), Calnode (appointment booking), and Twenty (CRM) are operated by us on our servers in Germany; they are not external third-party providers within the meaning of this section (see the Hosting section and the sections on contact, appointment booking, and CRM). For video appointments via Calnode, Google Meet is typically used in addition (see above). Where third parties process personal data on our behalf, they are classified as processors pursuant to Art. 28 GDPR. The necessary processor terms are in each case part of the general terms of use or the Data Processing Agreements provided by the providers used, which we have accepted in the course of using these services. For data transfers to third countries - in particular to the USA - we base the transfer on the Standard Contractual Clauses approved by the EU Commission pursuant to Art. 46(2)(c) GDPR.

10. Privacy Notes for Minors

Our app is generally aimed at all age groups, as fishing is an accessible and widespread leisure activity for minors. Full identity or age verification does not currently take place. When purchasing guest tickets we collect the date of birth in the buyer profile and may derive from it whether the buyer is a minor; in that case separate notices and consents may be required at checkout. Where the club uses youth management, the date of birth stored for a member may be evaluated for the age limit, status changes, and notifications to authorized administrators; youth group meetings and attendance overviews may also concern data of minors. The controller for that processing is regularly the club. For users under 16 years of age, we expressly recommend registering and using the app together with a parent or guardian. Parents or guardians have the right to request information about stored data on behalf of minor children as well as their rectification or deletion. Please send corresponding requests to [email protected].

11. Email and Push Communication

For operating our services we send system emails, for example to confirm your registration, for account and fishing license status messages, purchase confirmations, expiry notices, and security-relevant notices, including notifications to authorized club administrators about new violation reports and purchase approval requests. Where used by the club and allowed by user preferences, this also includes event reminders (including the day before and about one week beforehand), warnings when club-configured minimum attendance at youth group meetings is not met, and notices to authorized administrators when a youth member reaches the configured age limit. Push notifications may concern club messages, feed activity (likes/comments), fishing day reminders, event reminders, security notices, and purchase approval requests and are delivered via Firebase Cloud Messaging. Newsletters are sent exclusively on the basis of your explicit and separate consent pursuant to Art. 6(1)(a) GDPR. Product updates are a separate purpose. They require their own double opt-in, are not tied to the contract, and can be withdrawn just as easily in the account, in the app, or through the link in the email.

12. Data Storage and Deletion

Personal data is deleted as soon as the purpose of its processing ceases or your account is terminated at your request. For data with tax, commercial law, or reporting relevance - in particular invoice, payment, tax, register, and PStTG/DAC7 reporting data - the statutory retention periods of up to ten years apply pursuant to § 147 AO and § 257 HGB as well as applicable tax documentation obligations. This data is deleted without delay after expiry of the period. Fishing license scans are kept after approval until the expiry date plus 30 days, after rejection for 24 hours, and are removed at the latest on account deletion. Club-uploaded ownership or lease proofs for waters are kept after approval until the expiry date plus 30 days, after rejection for 24 hours, and are removed when club use of the service ends. Review status and expiry dates may remain as metadata for longer. Active club members are generally shown by name to club administrators. One year after leaving a club, expiry of a guest ticket, or account deletion treated as leaving a club, the relevant personal references in catch reports and fishing days are anonymized. On account deletion, existing fishing days and related catch reports are unlinked from the user account and initially kept as guest entries under the former display name; after one year that guest display name is anonymized. Your personal bait catalog including optional bait photos is deleted on account deletion; references on catch reports are removed. Club catch facts remain as statistical and fisheries records; ticket-related financial data is retained in anonymized form where legal retention obligations apply. Meeting minutes remain with the club until deleted by the club or the club stops using the service, unless separate club or statutory retention obligations require otherwise. Event participation, invitation, and reminder data as well as records of youth attendance warnings and age-status changes likewise remain with the club until deleted by the club or the club stops using the service. On account deletion, snapshots of selected buyer details on existing ticket orders (e.g. email and display-name snapshot) may remain for statutory proof and retention purposes where necessary. Local offline caches and pending sync jobs on the device are removed on logout, account deletion, or via corresponding app functions where technically possible. Until deletion or successful synchronization, the data remains on your device. Where club administrators may view name and postal address for catch-limit exceedances, documented rule violations, or security case review (see section 6), that access remains bound to those conditions and does not amount to a general disclosure of buyer-profile addresses. For technical purposes of system stability and error diagnosis, server and application logs are stored. These logs may contain personal data such as IP addresses or internal user identifiers. Application logs at container level are limited to a maximum of 7 days and a file size of 10 MB per file with a maximum of 3 files per service. System and server logs are automatically deleted after at most 7 days. Data backups are kept for a period of 7 days and then irrevocably deleted. The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest in system security and error diagnosis).

13. Your Rights as a Data Subject

Pursuant to the GDPR you have the following rights: the right of access to the data stored about you (Art. 15 GDPR), the right to rectification of inaccurate data (Art. 16 GDPR), the right to erasure or restriction of processing (Art. 17, 18 GDPR), the right to data portability (Art. 20 GDPR), the right to withdraw consents given with effect for the future, and the right to lodge a complaint with the competent data protection supervisory authority. In the app you can initiate a data access request (email to us). On the platform side, access requests may be processed and - where provided - made available as a PDF. To exercise your rights, please contact: [email protected] The competent supervisory authority is: State Commissioner for Data Protection Lower Saxony (LfD Lower Saxony) Prinzenstraße 5, 30159 Hanover www.lfd.niedersachsen.de

14. Changes to This Privacy Policy

We reserve the right to adapt this privacy policy if legal requirements change, new functions are introduced, or we use new third-party providers. The date at the beginning of the document indicates the status of the current version in each case. In the event of significant changes - in particular if new data processing operations are added, new third parties receive data, or the purposes of processing change - we will inform you in advance by email or via an in-app notification. The notification is given with reasonable advance notice so that you have the opportunity to review the changes and delete your account if necessary. For editorial adjustments without substantive effects - such as refinements of wording or updates of contact data - no separate notification takes place. We recommend reading this privacy policy regularly to always be informed of the current status.