Technical data-protection measures
A clear overview of which data we store, how we protect it and what rights you have.
🔒
Encryption of sensitive data
Particularly sensitive details are stored encrypted, not in plain text:
- •Health information (allergies and medical notes)
- •Contact data such as address and IBAN
🩺
Health data
Special rules apply to health information:
- •It is stored encrypted only.
- •It is visible only to the relevant teams (kitchen and first aid).
- •Every access by the team is logged and visible in your data export in the profile.
- •30 days after the event it is deleted automatically and permanently, not just hidden.
✅
Consents
Consents you give are documented verifiably:
- •privacy policy, terms, liability and age confirmation
- •each with timestamp and document version
🙋
Your rights
You stay in control of your data:
- •On request you can get access to the data stored about you.
- •You can delete or anonymize your account.
- •With the “anonymize after event” option this happens automatically.
📨
Protected data export
A data export bundles your most sensitive data and is therefore specially secured:
- •The export is not downloaded directly in the browser but provided through a one-time download link.
- •We send this link out-of-band to your registered channel (email or Telegram) and it can be used exactly once.
- •If you have both channels on file, two-factor protection applies automatically: the link arrives by email and the PIN by Telegram. Only both together release the export.
- •A request is possible at most once per day.
- •The export is locked if your contact details (email or Telegram) were changed in the last 14 days.
- •Every change to your contact details is additionally reported to your previous contact details, so you notice an unexpected takeover immediately.
🗺️
Map privacy
On the member map:
- •Only an approximate location is shown, never your exact address.
- •The display can be turned off at any time.
- •On request you do not appear in public lists either.
👁️
Access and accountability
Access to data is controlled:
- •When an administrator accesses private data, it is logged.
- •Booking and finance data are linked in a tamper-evident chain.
🧾
Bookkeeping
Payment-related data (fees, donations, transfers):
- •It is retained for the legal periods, usually 6 to 10 years.
- •It is stored revision-safe and therefore cannot be freely deleted.
🪪
Profile data
Address, phone and similar details:
- •On request they are anonymized after the event, once bookkeeping is complete.
📜
Log data
Technical logs are used for error analysis:
- •They are deleted after 90 days.
- •Audit and finance logs are tamper-evident.
Your settings: Profile ·
Delete or anonymize account