Skip to main content
Transparency & Data Protection

Privacy Policy

Information regarding the processing of personal data in accordance with Articles 13 & 14 of the General Data Protection Regulation (GDPR / DSGVO) and the German TDDDG.

1. Data Controller

The controller for data processing on this website under the GDPR is:

SprachCafé Polnisch e.V.

Schulzestr. 1, D-13187 Berlin (Germany)

Represented by the Board: Agata Koch (President & Chairwoman)

Email: [email protected]

Phone: +49 (0)160 9968 0059

2. Privacy by Design: Modern, Secure Architecture

Our web portal has been engineered following the principles of data minimization (Art. 5(1)(c) GDPR) and privacy by default (Art. 25 GDPR) as a modern static site (Astro SSG):

🚫 100% Tracker-Free & Ad-Free (No Annoying Cookie Banners)

We do not use any tracking cookies, ad networks, behavioral profiling, or external analytics scripts (such as Google Analytics or Meta Pixel). Because we do not deploy technologies requiring consent, no cookie banner is required on our website.

🔤 Self-Hosted Fonts & Assets

All typography (Inter and Roboto) and icons are hosted directly on our own server in modern WOFF2 format. No connection is made to third-party CDNs (such as Google Fonts). Your IP address is never shared with Google or third parties during your visit.

3. Hosting, Cloudflare Edge Protection & Server Logs

Hosting in Amazon Web Services (AWS EC2 Frankfurt am Main)

Our web servers, databases, and application services are operated on dedicated cloud instances (Amazon EC2) provided by Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855 Luxembourg). The physical server location is Frankfurt am Main (`eu-central-1`), Germany. All data processing strictly resides within the European Union under a binding Data Processing Addendum (Art. 28 GDPR).

Cloudflare Anycast DNS & Edge Protection

To ensure rapid worldwide DNS resolution, DDoS mitigation, and robust network availability, we use the global infrastructure of Cloudflare (Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA / Cloudflare Germany GmbH). Our domains' name servers are provided via Cloudflare Anycast DNS. Network traffic is routed through Cloudflare edge nodes located within the European Union pursuant to EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and an executed DPA (Art. 28 GDPR).

Server Logs (Caddy Reverse Proxy)

When you access our pages, our Caddy web server records only technically necessary connection data (IP address, date/timestamp, requested URI, HTTP status code, transferred bytes, and user agent string).

Purpose and Legal Basis: Ensuring technical stability, performance, and defense against malicious attacks (DDoS). Legal basis: legitimate interest pursuant to Art. 6(1)(f) GDPR and § 25(2)(2) TDDDG. Logs are purged on a rolling cycle within 7 to 14 days.

4. Contact Form and Membership Applications

Online Membership Application (`/en/mitmachen/mitglied-werden/`)

Personal details submitted in the membership application are processed solely to establish and manage your association membership (Art. 6(1)(b) GDPR) and comply with statutory bookkeeping obligations (Art. 6(1)(c) GDPR).

Contact Form (`/en/kontakt/`)

Information submitted via our contact forms is transmitted directly to our secure email inbox and is used exclusively to answer your inquiry.

5. Newsletter Subscription & Double Opt-In

You may subscribe to our free association newsletters covering upcoming cultural events, SprachCafé for kids and families, and multilingual programs.

  • Double Opt-In Procedure: Registration utilizes a confirmed opt-in procedure. After submitting your request, you will receive an activation email with a confirmation link. The subscription becomes active only once you click this link (Art. 6(1)(a) GDPR).
  • Delivery Infrastructure: Newsletters are primarily distributed through our self-hosted Listmonk platform (newsletter.sprachcafe-polnisch.org) on our AWS server in Frankfurt, and secondarily via Mailchimp (Intuit Inc., USA; under EU Standard Contractual Clauses).
  • Unsubscribe Anytime: You can withdraw your consent to receive newsletters at any time by clicking the unsubscribe link present in every newsletter footer or by emailing [email protected].

6. Member App, Digital Membership Card & Google Wallet

To facilitate statutory membership rights, verify digital membership passes, and manage membership benefits (such as annual free coffee quotas, event discounts, and free library access), the association provides a web portal (team.sprachcafe-polnisch.org/member/activate) and the dedicated Android application „SprachCafé Mitglied“ (org.sprachcafe.member).

  • Categories of Processed Data: First and last name, email address, phone number (if provided), member number (e.g. SCP-10001), membership tier (Silver, Gold, Platinum, Company), contribution status, free coffee quota allocation/redemptions, and dynamic QR verification tokens.
  • Legal Basis: Fulfillment of membership contract and rights (Art. 6(1)(b) GDPR) and statutory financial recordkeeping obligations (Art. 6(1)(c) GDPR).
  • On-Device Local Storage: The Android app stores pass data locally and encrypted (Android SharedPreferences) to allow offline pass presentation and scanning.
  • Optional Google Wallet Integration: Exporting the pass to Google Wallet is entirely voluntary and only initiated upon explicit user interaction (Art. 6(1)(a) GDPR).

7. Board Administration & POS Operations (`team.sprachcafe-polnisch.org`)

Administrative access to membership rosters, financial records, and POS audits is restricted and passwordlessly protected using Microsoft Entra ID (Single Sign-On) for authorized board members only.

  • Legal Basis: IT security and data protection under Art. 32 GDPR as well as legitimate organizational interests under Art. 6(1)(f) GDPR.

8. House Library (`hausbibliothek.org`)

The House Library platform at hausbibliothek.org manages book loans and reader accounts. Reader accounts inactive for more than 24 months are routinely deleted in accordance with data erasure obligations (Art. 17 GDPR).

9. Your Rights Under GDPR

You have the right to access (Art. 15 GDPR), rectify (Art. 16 GDPR), erase (Art. 17 GDPR), restrict processing (Art. 18 GDPR), receive data portability (Art. 20 GDPR), and object to processing (Art. 21 GDPR).

To exercise your rights, simply send an email to: [email protected].

Competent Data Protection Supervisory Authority:

Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Email: [email protected]

Last updated: October 2026