Skip to main content

Privacy Policy

How we process your personal data across all supodo services

1. Scope

supodo is a platform for disability, inclusion and senior sport, made up of several services all operated by the same controller. This document applies to all supodo services. The individual services publish no legal notice and no privacy policy of their own but point to these pages instead.

Including:

Beyond these, this document applies to any further publicly offered supodo service reachable at supodo.com and its subdomains, or at supodo.link.

Internal test and development environments are not covered. Where they are publicly reachable, they publish their own details for that environment.

Sections 6 to 11 are organised by service. Section 6 applies to all of them; each following section applies only to the service named in its heading. Internal test and development environments are not covered.

2. Controller

The controller for the processing on all of the services listed above, within the meaning of Art. 4(7) GDPR, is:

supodo
Marib Aldoais
Leimbergerstraße 43a
91052 Erlangen
Germany

Email: kontakt@supodo.com
Phone: +49 170 9000109

Data protection officer

We have not appointed a data protection officer, and we are not required to. Section 38(1) of the German Federal Data Protection Act (BDSG) requires an appointment only where at least 20 people are constantly engaged in automated processing, or where a data protection impact assessment is required. For any data protection question, please use the contact details above.

3. The legal bases we rely on

We process personal data only where a legal basis exists, and this policy names the applicable basis at each processing activity. Four bases occur:

Contract or pre-contractual steps (Art. 6(1)(b) GDPR)

We process data that is necessary to provide a service you have asked for — for example your user account, your sign-in, or the content you create.

Legitimate interests (Art. 6(1)(f) GDPR)

We process data where we have a legitimate interest in doing so and your interests do not override it. We name the specific interest at every point where we rely on this basis, so that you can assess it. You may object to processing on this basis — see section 15.

Consent (Art. 6(1)(a) GDPR)

We process data on the basis of your consent where we have expressly asked for it — for the newsletter, for example. You can withdraw consent at any time, without that making the processing carried out until then unlawful.

Legal obligation (Art. 6(1)(c) GDPR)

We process data where a law requires us to, for instance where statutory retention periods apply to correspondence.

Wherever we rely on legitimate interests, we have carried out a balancing exercise against your rights and freedoms. We will tell you its outcome on request.

4. Health and disability data

This is the most important section for a platform like ours. Please read it even if you skip the rest.

Why this matters here

We never ask you about your health, a diagnosis or a disability, and we store no such information. Even so, your data can reveal something about your health: if you belong to an organisation, or take part in an event, whose purpose is disability or inclusion sport, a disability can be inferred from that. For individual activities there is a sharper level: an activity can be linked to a target audience — for example blind sport, wheelchair sport or dwarf sport. If you take part in an activity labelled that way, the inference is far more specific than the general purpose of a whole organisation. The Court of Justice of the European Union has held that for Art. 9 GDPR it is enough that information follows indirectly from data — it does not have to be collected explicitly (judgments of 1 August 2022, C-184/20, and of 4 October 2024, C-21/23).

Where no such inference is possible

Not every affiliation supports such an inference, and we do not want to claim more here than is the case. In senior sport, taking part indicates age only — which is not health information. For mixed-ability and generally inclusive activities there is no inference to draw; that is the point of inclusion. How precisely we can distinguish depends on the level: for individual activities we can, because a target audience may be recorded there; for whole organisations and events we cannot, because the inference follows only from their general purpose. Where there is doubt, we treat all role, membership and participation data as specially protected.

How we handle this data

We therefore treat role, membership and participation data as specially protected throughout:

  • We do not pass it on, other than to the organisation or event you joined yourself, and to co-organising organisations where that is necessary to run the event.
  • We do not publish it. What is publicly visible is the activities themselves — organisations and events with the status "published" — never the people behind them.
  • Access is enforced in the database itself, not only in the application, and is tied to your account.
  • We do not use it for advertising, for profiling, or for any analysis of individual people.

What is still open

We are completing the data protection assessment of this inference. We say so openly rather than leaving it out: the role and participation records themselves are processed under Art. 6(1)(b) GDPR where you create them yourself, and under Art. 6(1)(f) where an organisation enters you — its legitimate interest being the running of its own sports programme. We will update this section as soon as the assessment is complete. Until then: you can end any role, membership or participation at any time, and we delete the corresponding record when you do.

5. Children and young people

In youth sport, minors use our services too. Where we rely on your consent, that consent is valid under Art. 8(1) GDPR only from the age of 16. Germany has not used the option in that article to set a lower age limit, so 16 applies. Below the age of 16, consent must be given or authorised by a parent or other holder of parental responsibility. There is more to it: an activity can state a minimum and a maximum age. If you take part in one aimed explicitly at children or young people, your approximate age can be inferred from that — even though you never told us your date of birth. We do not collect an age and we do not check it technically.

This age limit applies only to processing based on consent. Processing that is necessary to perform a contract, or that rests on legitimate interests, is not governed by Art. 8 GDPR.

Our newsletter is addressed to adults. We do not knowingly enrol anyone under 16. If we learn that a sign-up was made without the required consent of a parent or guardian, we delete it.

Where an organisation enters a minor as a member or participant, it is the organisation — not us — that obtains the required consent from the parent or guardian. We have no contact with the parent or guardian and cannot obtain that consent. The organisation remains responsible for the lawfulness of the data it enters.

If you hold parental responsibility and have a question about a child's data, or want it deleted, please use the contact details in section 2. We treat such requests as a priority.

6. Common to all services

This section applies regardless of which of our services you use.

Hosting

All of our services run on servers we operate with a provider in Germany. All personal data arising from your use is stored there.

We use the following hosting provider:
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany

The legal basis is Art. 6(1)(b) GDPR where hosting serves to provide a service you have asked for, and Art. 6(1)(f) GDPR for our interest in secure, fast and reliable operation by a competent provider.

We have a data processing agreement with the hosting provider under Art. 28 GDPR. It processes data only on our instructions. Both servers are located in Nuremberg, and the agreement confines processing to the EU and the EEA. No transfer to a third country takes place through the hosting provider.

Log data

Operating our services produces technical log data. Requests to our database and sign-in interface — which sits behind the management console, the app and the short links — are recorded in a log store on the same servers. This records:

  • the time of the request
  • the interface called
  • the HTTP method used
  • the response status
  • your IP address
  • your browser identifier (user agent)

We do not combine this data with other sources and do not build user profiles from it.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the technically faultless operation of our services, fault-finding, and defending against attacks and misuse. For the same reason we briefly count how often a form is submitted from one IP address, and refuse further submissions once a limit is reached. These counters are held in memory only; they are not stored permanently and are discarded after a short time.

We have not yet set a fixed deletion period for these logs. What determines it is how long the data remains necessary for the purposes named above: fault-finding in day-to-day operation, and investigating and defending against attacks and misuse, including pursuing or defending any claims arising from them. Once we have determined a fixed period, we will state it here.

Cookies and storage on your device

We use strictly necessary cookies only, in particular for sign-in and sessions in the management console and the app. No consent is required for these under section 25(2) no. 2 of the German TDDDG, because they are strictly necessary to provide the service you have expressly requested. We use no cookies for analytics, advertising or audience measurement, no analytics tools, and no embedded external fonts, maps or videos. That is why our services carry no cookie banner.

We store three further items on your device, likewise without consent under section 25(2) no. 2 of the German TDDDG: on the website, in the management console and in the app, a cookie remembers the language version you chose, so that a visit without a language in the address appears in that language; this cookie is a session cookie and is deleted when you close the browser. In the management console, your browser additionally remembers in local storage whether you collapsed the side bar. Also in the management console, a cookie remembers up to twelve organisations you administer and most recently opened, so that the side bar offers you those first; we delete this cookie after 30 days. It is part of the navigation inside the management console you deliberately opened, and therefore necessary for the service you requested. All three serve only the presentation you asked for; we do not evaluate them and do not combine them with anything. The short-link service stores nothing on your device (see section 10).

Security

We transmit all pages over encrypted HTTPS only, and take technical and organisational measures under Art. 32 GDPR to protect your data against loss, alteration and unauthorised access. Access to other users' data is enforced in the database itself, not only in the application.

Links to external websites

Our services contain links to third-party websites. We are not responsible for their content or their data protection practices. Please check their privacy information before entering personal data there.

Data is transmitted to the link target only once you click an external link. This is technically necessary because of the protocol underlying the internet (TCP/IP). What is transmitted includes your IP address, the time you clicked, and the operating system and browser version of your device.

7. Website (supodo.com)

On this website you can write to us through a form and subscribe to our newsletter. There is no user account here.

Contact form, and enquiries by email or phone

When you write to us through the contact form, we process your email address, the subject and your message, in order to handle your enquiry and in case of follow-up questions. You receive a confirmation at the address you gave, which reproduces your message. If you contact us by email or phone, the same applies to the data arising there.

The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract or its preparation. In all other cases it is Art. 6(1)(f) GDPR — our legitimate interest in answering enquiries addressed to us — or your consent under Art. 6(1)(a) GDPR where you volunteer additional information.

Your email address is required so that we can reply; without it we cannot handle your enquiry. The form does not ask for your name. There is no statutory or contractual obligation to provide it.

We delete your enquiry once it has been dealt with conclusively, unless a statutory retention period applies.

Newsletter

For the newsletter we process your email address and the language you chose. We do not ask for your name when you sign up; you can add it yourself later in your newsletter preferences. Sign-up uses the double opt-in procedure: after signing up you receive an email in which you have to confirm. We store the time of sign-up and of confirmation in order to be able to demonstrate consent, together with delivery and bounce information so that we stop sending to invalid addresses.

The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time, using the unsubscribe link in every newsletter or by messaging us. Withdrawal takes effect for the future only.

We run delivery ourselves, using the Listmonk software on the servers we rent, described in section 6 (see also section 11). No external mailing service is involved.

We store your data until you unsubscribe. After that we retain the record of your consent and its withdrawal for as long as is necessary to defend against claims.

Protecting the forms against abuse

To protect the contact form, the newsletter sign-up and the reporting form against automated abuse, our server sets your browser a computation which it solves in the background. It only starts once you tick the box below the form — nothing is loaded and nothing is computed for it before that. You do not have to solve a picture puzzle. The mechanism runs entirely on our own servers; no third-party service is involved.

Once you tick the box, your browser fetches the task from our server and computes the answer on your device. Only the task and its answer are transmitted. We process your IP address as we do on any other request to our servers, in order to limit the number of requests (section 6). We do not evaluate information about your browser or your device for this mechanism, and no data is passed to third parties in the process.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is protecting our forms against spam, against bulk sending, and against our confirmation email being used to write to arbitrary third parties.

8. Management console for clubs and events (manager.supodo.com)

The management console is used by people who maintain activities and events on behalf of an organisation. It requires a user account.

Sign-in goes through our central sign-in service; section 11 sets out what data arises there. Within the console itself we additionally store which roles your account holds in which organisations and events, and who created a record. For organisations, contact details, images and short links we also record who last changed them.

For organisations and events we process the information the people responsible enter there: name, description, type of organisation, sports, target groups, times, places and addresses, costs, images, links to social networks, and contact details such as email address, telephone and fax number. Contact details are often personal data, even where they belong to an organisation.

About people we process roles: administrator, member and follower at organisation level; event manager, participant, support and follower at event level. Technically, a role consists only of a reference to your account, a reference to the organisation or event, and the kind of role. What can nevertheless follow from that is set out in section 4.

Where an organisation enters data about a person who does not hold the account themselves, we receive that data not from the data subject but from the organisation. We provide this information here in accordance with Art. 14 GDPR. The organisation is responsible for the lawfulness of that entry and for informing the person concerned.

Organisations and events become publicly visible once the organisation sets them to "published". Before that they are visible only to the accounts entitled to see them. Roles, memberships and participation are never publicly visible.

The legal basis is Art. 6(1)(b) GDPR for the account, sign-in and the maintenance of one's own content. For the public visibility of published activities it is Art. 6(1)(f) GDPR — the organisation's legitimate interest, and our own, in making disability, inclusion and senior sport activities findable; that is precisely what these services exist for.

Content remains stored until the organisation deletes it. Roles remain stored until they are ended. If you delete your account, your roles are deleted with it.

9. App (app.supodo.com)

In the app you can search for and view activities without signing in, and follow organisations and events.

No sign-in is needed to search and view published activities. Only the data described in section 6 arises, in particular the server log files.

The first time you do something that has to be stored — following an organisation, for instance — we automatically set up an anonymous account for your device. That account holds no name, no email address and no password; it consists only of an identifier stored in your browser, and serves solely to find your list of followed activities again. We cannot link an anonymous account to a person known by name. It is nonetheless personal data within the meaning of Art. 4(1) GDPR, because it amounts to an online identifier.

When you follow an organisation or an event, we store a follower role for it — the reference to your account, the reference to the activity, and the time. That list is visible only to you. Please note section 4, which applies even if you only follow.

The legal basis is Art. 6(1)(b) GDPR: without this anonymous account a list of followed activities cannot technically be kept, and that list is the very function you asked for.

If you clear your browser data, your anonymous account is no longer reachable by you. Anonymous accounts that never followed anything are deleted automatically after 30 days. For anonymous accounts that do have followed activities we have not yet set a fixed period; we will delete them once we have determined one, and will state it here. On request we delete your anonymous account at any time.

10. Short links (supodo.link)

The short-link service resolves a short address and forwards you to its target. There is no sign-in, and no content of yours is stored.

When you open a short link, we determine its target and forward you there. The target may be a supodo page or an external website.

This service sets no cookies. It stores nothing on your device, uses no analytics or tracking tools, and builds no user profiles.

The server log files described in section 6 arise. In addition we limit the number of requests per IP address in order to protect the service against automated abuse. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the stable, abuse-free operation of the service.

As soon as we forward you, data is transmitted to the target — including where the target is somebody else's website. This is technically necessary because of the TCP/IP protocol. What is transmitted includes your IP address, the time of the request, and the operating system and browser version of your device. For processing on a third-party target page, its operator is responsible.

11. Sign-in, user accounts and email delivery (auth.supodo.com, mail.supodo.com)

Sign-in and newsletter delivery run on two pieces of software that we operate ourselves, on the rented servers described in section 6.

For your user account we process your username, email address, first and last name, your password exclusively as a hash that cannot be reversed, any passkeys you have registered, the status of email verification, linked external identities, and session data: sign-in times, session and access tokens, and counters of failed sign-in attempts. We also record when you accepted our terms of use — we have to be able to demonstrate that.

Our sign-in service additionally writes a log event for security-relevant activity around your account, in particular signing in, signing out, a failed sign-in, registration, confirmation of your e-mail address, and a change of your password. It records the time, the type of event, your account identifier and your IP address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the security of accounts and the investigation of misuse. We delete these log events automatically after 90 days.

When you register, we send an email to the address you gave, which you have to confirm. Without confirmation the account cannot be used. We send that email through a mailbox at our hosting provider; no further service provider is involved.

You can alternatively sign in with a Google account. If you do, Google transmits your email address, your name and an identifier to us, and we create an account here from that. We adopt the email address Google has already verified as confirmed, so no further confirmation email is needed. Google is the controller for the processing of your data at Google; the transmission is triggered by your decision to sign in that way. If you would rather not, register with an email address and a password.

For the newsletter we manage subscription status, your email address, your name where given, and delivery and bounce information in our self-operated mailing software. The substantive information is in section 7.

The legal basis is Art. 6(1)(b) GDPR for the account and sign-in, Art. 6(1)(f) GDPR for email verification and the counters of failed sign-in attempts — our legitimate interest being account security — and Art. 6(1)(a) GDPR for the newsletter.

We store account data until you delete your account or ask for its deletion. Session data is deleted shortly after it arises, and the sign-in service's log events automatically after 90 days.

12. Recipients and processors

We do not pass personal data to third parties except in the cases named in this policy, where you have agreed, or where we are legally required to. Two companies are involved — one as a processor acting on our instructions and, if you choose it, one as an independent controller:

Hetzner Online GmbH, Nuremberg, Germany

Operator of the servers on which all our services run — a processor under Art. 28 GDPR. The data processing agreement in its version of 16 February 2026 was concluded on 7 August 2026 and confines processing to the EU and the EEA. In it we expressly declared that the platform may process special categories of personal data under Art. 9(1) GDPR — health and disability data — because these can be inferred from affiliation and participation.

Google Ireland Limited, Dublin, Ireland

Provider of the sign-in with a Google account (section 11) — not a processor, but an independent controller. If you use it, you sign in with Google directly; Google then passes us your email address, your name and an identifier. For users in the European Economic Area and Switzerland, Google's privacy policy names Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland as the controller, so our counterpart is established in the EEA. What Google does with your data beyond that — including passing it within its own group to the United States — Google decides and answers for itself; the details are in Google's privacy policy. Signing in with Google is optional: you can create an account with an email address and a password instead.

What are not processors

The sign-in service, the database, the mailing software and the operations console are software that we run ourselves on the servers named above. There is no further company behind them that receives your data. Our newsletter delivery in particular is not a service booked from a provider: we run the mailing software ourselves on the servers we rent; outbound email goes through a mailbox at our hosting provider.

Beyond that, data can reach organisations you have joined yourself — these are not processors but are themselves controllers for the processing within their own area. And we may be obliged to disclose data to public authorities or courts; we do so only to the extent we are legally required to.

13. Transfers to third countries

All data stored on our servers stays in Germany. No transfer by us to a country outside the EU and the EEA takes place. If you sign in with a Google account, our counterpart is Google Ireland Limited in Ireland and therefore within the EEA; whether and how Google passes data on to the United States beyond that is Google's own decision and responsibility as an independent controller (sections 11 and 12).

14. Retention periods

We store personal data only for as long as it is necessary for the relevant purpose. Where we can state a specific period, we state it; where none has been set yet, we say so explicitly rather than talking around it.

  • Log data from our database and sign-in interface: we have not yet set a fixed period. What determines it is how long the data remains necessary for fault-finding and for investigating and defending against attacks and misuse (see section 6).
  • Enquiries by contact form, email or phone: until the enquiry has been dealt with conclusively, then deleted, unless a statutory retention period applies.
  • Newsletter: until you unsubscribe. We keep the record of your consent and its withdrawal beyond that, for as long as necessary to defend against claims.
  • User account and sign-in data: until you delete the account or ask for its deletion. Session data is deleted shortly after it arises; the sign-in service's log events after 90 days.
  • Roles, memberships and participation: until they are ended, or the account is deleted.
  • Content in the management console, including uploaded images: until the organisation concerned deletes it.
  • Anonymous app accounts that follow no organisation and no event at all: 30 days, then deleted automatically by a process that runs daily.
  • Anonymous app accounts that do follow activities: we have not yet set a period for these. What governs it is how long the followed list still serves its purpose. We will set the period and state it at this point; on request we delete such an account immediately at any time.

Where deletion is not possible because the data is still needed for other permissible purposes, we restrict the processing instead: the data is then processed for that purpose only and not used further.

15. Your rights

You have the following rights in relation to us. Exercising them is free of charge, and you do not have to give reasons — with the exception of objection.

  • Access (Art. 15 GDPR): you can find out whether and what data we process about you, for what purposes, for how long, who we pass it to and where we got it, and obtain a copy of it.
  • Rectification (Art. 16 GDPR): you can have inaccurate data corrected and incomplete data completed.
  • Erasure (Art. 17 GDPR): you can ask us to delete your data, to the extent we no longer need it and are not legally required to keep it.
  • Restriction of processing (Art. 18 GDPR): you can require us to store data only, for the time being, and not use it further — for instance while we check a rectification.
  • Data portability (Art. 20 GDPR): you can receive the data you provided to us on the basis of consent or a contract in a common, machine-readable format, or have it transmitted to another controller.
  • Withdrawal of consent (Art. 7(3) GDPR): you can withdraw consent you have given at any time, as easily as you gave it. Processing carried out before the withdrawal remains lawful.

Right to object

Where we process data on the basis of legitimate interests under Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR). If you object, we will stop processing the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. This policy names the interest we pursue at every processing activity on that basis — so that you are able to ground an objection.

How to exercise your rights

A message to the contact details in section 2 is enough; no particular form is required. We reply without undue delay and at the latest within one month of receipt. Where a request is complex we may extend that period by up to two further months, and will tell you if we do. To prevent us handing data to the wrong person, we may have to ask a question to verify your identity; we will not ask for more information than necessary.

Complaining to a supervisory authority

If you are not satisfied with our answer, please write to us again — we review every complaint ourselves and respond to it. Independently of that, you have the right under Art. 77 GDPR to complain to a data protection supervisory authority, in particular in the Member State of your residence, your place of work, or the place of the alleged infringement. The authority responsible for us is:

Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany

16. No automated decision-making

We take no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). We carry out no profiling, no scoring or rating of people, and no ad targeting. The bot check on the forms described in section 7 assesses a single form submission, not you as a person; if a submission is rejected you can try again or email us directly.

17. Information for users outside the EU

supodo is aimed at sports communities in Germany and Europe. Our services are reachable from anywhere, but we do not offer them into other markets on purpose. Foreign data protection law generally attaches to whether a service targets a market, not to whether a page can be opened there. What governs us is therefore the GDPR and German law. The following notes are added so that you can place your own situation.

Australia

We do not carry on business in Australia within the meaning of section 5B of the Privacy Act 1988 (Cth), and so we are not currently subject to that Act or to the Australian Privacy Principles. We nonetheless follow the substance of APP 1 — a clearly expressed, up-to-date privacy policy — and add the two items APP 1.4 requires beyond Art. 13 GDPR.

Overseas recipients and their countries: your data is stored in Germany. A single recipient is located outside Germany, and only if you sign in with a Google account: Google Ireland Limited in Ireland, which may pass data on to the United States within its own responsibility (sections 11, 12 and 13).

How complaints are handled: write to us using the contact details in section 2. We acknowledge receipt, review the matter ourselves, reply within one month, and give you the outcome with our reasons. If you disagree with it, you can approach the supervisory authority named in section 15.

United States of America

We do not do business in California and fall below every threshold of the California Consumer Privacy Act: our annual revenue is far below US$26,625,000, we process the data of fewer than 100,000 California residents or households, and we derive no revenue from selling or sharing personal information. We do not sell personal data at all. The Children's Online Privacy Protection Act does not apply to us, because our services are not directed to children in the USA.

Canada

We carry on no commercial activity with a real and substantial connection to Canada and are therefore not subject to the Personal Information Protection and Electronic Documents Act. Our newsletter nevertheless meets what Canada's Anti-Spam Legislation requires of commercial email: we send only after an express sign-up with confirmation, we identify the sender in every email, and every email carries a working unsubscribe link.

Other countries

We give no separate information here for the United Kingdom, Switzerland, Brazil, China or the individual further US states, because we do not target those markets. Should that change, we will extend this policy before any such service launches.

18. Reports about illegal content and breaches of the Terms of Use

When you report content to us through the reporting form, we process the kind of report you chose, the exact address of the content, your description and — where you provide them — your name and email address. The report therefore also contains personal data about the person whose content you are reporting. We use this information solely to review the report, to confirm receipt and communicate our decision to you, and to give a statement of reasons to the person affected.

For reports about illegal content the legal basis is Art. 6(1)(c) GDPR: handling them is required of us by Art. 16 of Regulation (EU) 2022/2065. Where you report a breach of our Terms of Use, no such legal obligation exists. That processing rests on Art. 6(1)(b) GDPR as far as it serves the performance of the terms agreed with the person concerned, and otherwise on Art. 6(1)(f) GDPR — our legitimate interest in keeping our services free of content that breaks our own rules. If you do not state the kind of report you are making, we classify it ourselves; until then we process it on the basis of Art. 6(1)(f) GDPR.

Without the exact address and a description we cannot act on a report. For reports about illegal content your contact details are required by law, unless the report concerns content involving the sexual abuse of children — in that case you may report without them. For reports about a breach of the Terms of Use there is no legal duty to give them; we ask for them because we otherwise cannot settle the report with you. Without contact details we can tell you neither that the report arrived nor what we decided.

We do not pass your contact details to the person whose content you reported. What we must give that person is the reasoning behind our decision — not the identity of whoever reported it.

We keep reports and the related correspondence for three years from the final decision. That period follows the standard limitation period of §§ 195, 199 BGB: both the person reporting and the person affected can challenge our decision within it, and we have to be able to substantiate it.

19. Changes to this privacy policy

We adapt this policy when our services or the legal requirements change. The version published on this page is the one that applies; the date below shows its status. Where a change materially affects you, we additionally give notice at a suitable place within the service concerned. If a processing activity based on your consent changes, we obtain fresh consent beforehand.

Last updated: 14 August 2026