08.04.2026

Datenschutz

1. Overview and Controller

We take the protection of your personal data seriously. We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG).
This policy explains what personal data we collect when you visit our website or interact with us, how we use it, and what rights you have.

Controller responsible for data processing on this website:

[Foundation Legal Name, e.g. “One Nation Foundation gemeinnützige GmbH” or “… e.V.”]
[Street and Number]
[Postal Code, City]
Germany

Represented by: [Name(s) of the legal representative(s), e.g. Vorstand / Geschäftsführung]
Email: [contact@yourdomain.org]
Phone: [optional]

Note: the controller details should match your Impressum/legal notice.

2. Data Protection Officer (Optional)

[We have appointed a Data Protection Officer (DPO). You can reach our DPO at:]
[Name / Company]
[Address or email]

Note: A DPO is mandatory only under the conditions of Art. 37 GDPR / § 38 BDSG (e.g. where ≥ 20 persons are constantly engaged in automated processing, or where core activities involve large-scale processing of special-category data). If you are not required to have one, delete this section entirely.

3. Your Rights as a Data Subject

    You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) — to obtain confirmation of whether we process your data and to receive a copy.
  • Right to rectification (Art. 16 GDPR) — to have inaccurate data corrected and incomplete data completed.
  • Right to erasure (Art. 17 GDPR) — to have your data deleted where the legal conditions are met.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR) — to receive data you provided in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21 GDPR) — see the separate notice in Section 4 below.
  • Right to withdraw consent (Art. 7(3) GDPR) — where processing is based on consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.

To exercise any of these rights, contact us using the details in Section 1.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany [https://www.lda.bayern.de]

Note: BayLDA is the competent authority for non-public (private-sector) bodies based in Bavaria. Adjust if your registered seat is in another federal state.

4. Right to Object — Important Notice

Where we process your personal data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to such processing (Art. 21(1) GDPR).

If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.

Where we process personal data for direct marketing purposes, you have the right to object at any time (Art. 21(2) GDPR). If you object to processing for direct marketing, we will no longer process your data for those purposes.

To exercise your right to object, contact us using the details in Section 1.

5. How We Protect Your Data

This website uses SSL/TLS encryption for security and to protect the transmission of confidential content. You can recognise an encrypted connection by the “https://” prefix and the lock symbol in your browser’s address bar. When SSL/TLS encryption is active, the data you transmit to us cannot be read by third parties.

In addition, we take appropriate technical and organisational measures to protect your personal data against accidental or intentional manipulation, loss, destruction, or access by unauthorised persons. Our security measures are continuously reviewed and improved in line with technological developments.

6. Hosting and Server Log Files

Our website is hosted by GoDaddy. The responsible entity for customers in the EU/EEA is:
GoDaddy c/o WeWork
Friesenplatz 4
50672 Köln, Germany
(Attn: Legal, Office of the Data Privacy Officer)
The operating company is GoDaddy.com, LLC (USA / GoDaddy group).

7. Cookies and Consent Management

Our website uses cookies and comparable technologies (e.g. local storage). Cookies are small text files stored on your device that do not cause any harm.
We distinguish between:

Strictly necessary cookies, required for the basic functioning of the website. These are set on the basis of Art. 6(1)(f) GDPR (and § 25(2) TDDDG), as we have a legitimate interest in providing a functional website.
Optional cookies (e.g. for analytics, marketing, or embedded media), which we set only with your prior consent in accordance with Art. 6(1)(a) GDPR and § 25(1) TDDDG.

When you first visit our website, our consent banner allows you to accept or decline optional cookies. You can change or withdraw your selection at any time via [link to “Cookie Settings” / the banner trigger].
Note: This section must match the cookies your site actually sets. If you use a consent management tool (e.g. Borlabs Cookie, Complianz, Real Cookie Banner), name it and describe it here.

8. Contacting Us

If you contact us by email, telephone, or via any contact form, your details (including the personal data you provide) will be stored and processed by us in order to handle your enquiry and any follow-up questions.
The legal basis for processing this data is:

Art. 6(1)(b) GDPR where your request relates to the performance of a contract or pre-contractual measures;
otherwise Art. 6(1)(f) GDPR, based on our legitimate interest in effectively handling enquiries directed to us.

We retain this data until the purpose for storing it ceases (e.g. once your enquiry is fully resolved), unless statutory retention periods require otherwise.

9. Newsletter and "Notify Me" Sign-Up

If you sign up to be notified about our offerings (for example, the availability of our products) or to receive our newsletter, we collect your email address and the data required to verify it.
We use the double opt-in procedure: after you submit your email address, we send you a confirmation email and only add you to the list once you confirm via the link it contains. This allows us to verify that the owner of the email address consented. We log the registration, the confirmation, and the time, together with the IP address used, in order to demonstrate the sign-up process.
The legal basis is your consent under Art. 6(1)(a) GDPR. You may withdraw your consent and unsubscribe at any time, for example via the unsubscribe link in every message. The withdrawal does not affect the lawfulness of processing carried out before it.
We store your email address for this purpose until you unsubscribe; after unsubscribing, it is deleted or stored on a blocklist solely to prevent future mailings.
Note: If you use an email service provider (e.g. Brevo, Mailchimp, CleverReach, rapidmail), name it here, describe the data transfer, confirm a DPA under Art. 28 GDPR is in place, and — for providers outside the EU/EEA — add the third-country transfer note from Section 12.

10. Donations

When you make a donation through our website, we collect the data necessary to process the donation. Depending on the payment method and form fields, this may include your name, email address, postal address, donation amount, and payment data.
We process this data to carry out the donation, to issue donation receipts, and to comply with statutory obligations (in particular tax and accounting law). The legal bases are:

Art. 6(1)(b) GDPR for processing the donation you initiated;
Art. 6(1)(c) GDPR for processing required to meet legal retention and tax obligations.

Donation and payment records are retained for the statutory periods (generally [6 / 10] years under German commercial and tax law).
Payment processing: Payments are processed by the following payment service provider(s):
[e.g. Stripe Payments Europe, Ltd. / PayPal (Europe) S.à r.l. et Cie, S.C.A. — add the legal entity and address of each provider you use]
When you choose a payment method, the data required for processing the payment is transmitted to the relevant provider, which acts as an independent controller and/or processor for that purpose. Please also consult the privacy policy of the respective provider. The legal basis is Art. 6(1)(b) GDPR.
Note: Our donation forms are managed via the GiveWP plugin. Confirm which payment gateways are active and list each provider’s legal entity and privacy policy link. Several common providers are based in the USA — apply Section 12 accordingly.

11. Online Shop (Optional — activate when the shop goes live)

When you place an order in our online shop, we collect the data necessary to perform the contract — in particular your name, billing and delivery address, email address, and payment data. This data is processed to perform the purchase contract on the basis of Art. 6(1)(b) GDPR and to comply with commercial and tax retention obligations on the basis of Art. 6(1)(c) GDPR.
[If the shop is operated via Shopify: describe the data transfer to Shopify as a processor/controller, reference the data processing terms, and — as Shopify is based outside the EU — apply the third-country transfer safeguards in Section 12.]
Note: This section is a placeholder. Complete it only once the shop is operational, and have it reviewed specifically, as e-commerce adds further obligations (e.g. order processing, returns, accessibility under the BFSG).

12. Data Transfers to Third Countries

Some of the service providers we use may be based in, or process data in, countries outside the European Union / European Economic Area (in particular the USA).
Where we transfer data to such third countries, we ensure an adequate level of data protection through appropriate safeguards under Art. 44 ff. GDPR — in particular the EU Standard Contractual Clauses (SCCs), an applicable adequacy decision of the European Commission (e.g. certification under the EU–US Data Privacy Framework), and/or your explicit consent under Art. 49(1)(a) GDPR.
You can request a copy of the specific safeguards in place by contacting us at the address in Section 1.
Note: List the specific third-country providers (payment, email, shop, fonts, analytics) and the mechanism each relies on. This section is a frequent source of formal complaints, so it warrants careful legal review.

13. Fonts

This website uses self-hosted fonts. The font files are loaded from our own server, so no connection to a third-party font provider is established and no personal data (such as your IP address) is transmitted to such a provider when loading the website.
Note: This reflects a self-hosted/local font setup. If any font, icon set, or stylesheet is loaded from an external CDN, that transfer must be disclosed here instead.

14. Changes to This Privacy Policy

We may update this privacy policy to reflect changes in our services or in the legal requirements. The version published on this website applies. The “Last updated” date at the top indicates the current version.