GitCover Commons gUG (hereinafter referred to as "we" or "GCC") takes the protection of your personal data very seriously. This statement describes the data we collect, how we use it, and the rights you have.

1. Data Controller

GitCover Commons gUG (limited liability)
Talstraße 2, 61381 Friedrichsdorf
Represented by Managing Director Axel Druschel
E-Mail: info@gitcover.org

We have not appointed a data protection officer, as there is no statutory obligation to do so (Section 38 BDSG). Please direct data protection requests to the address above.

2. Data We Collect

a) When Visiting This Website

When merely visiting this website, no personal data is collected via tracking, cookies, or analytics services. We do not use analytics tools (no Google Analytics, no Plausible, no Matomo). The page only loads external fonts (Google Fonts) and the diagram library Mermaid.js (loaded via the jsDelivr CDN; license: MIT). When accessing these resources, your IP address and browser headers are transmitted to the respective providers (jsDelivr/Cloudflare or Google). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a technically reliable, appealing presentation). You can prevent this transmission by using local fonts and self-hosting Mermaid — a corresponding extension is in development. For license notices of third-party components, see the Licenses page.

b) Server Logfiles

When retrieving the website, the web server or our hosting service provider processes technically necessary access data (IP address in shortened/temporary form, date and time, requested resource, referrer, user-agent) for delivery of the page and to ensure IT security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation). Log data is deleted or anonymized after [7] days.

c) Via Email Contact

If you contact us via email (e.g., for an official donation receipt), we store the data you provide (name, address, email address, donation details) to process your request. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and/or Art. 6(1)(f) GDPR (legitimate interest).

d) Registration for Training (B2B)

If you register for a training course, we process the data required for execution (name, business contact details, company, if applicable participation/payment data). The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (tax and commercial law retention). Our offers are directed exclusively at entrepreneurs (see GTC).

e) Official Donation Receipts

To issue official donation receipts pursuant to Section 50(1) EStDV, we store the name, address, donation amount, donation date, and purpose. Legal basis: Section 147 AO (10-year retention obligation), Art. 6(1)(c) GDPR (legal obligation). After the retention period expires, the data will be deleted.

3. Disclosure to Third Parties

We do not disclose your personal data to third parties, unless:

4. Data Processing on Behalf

Where we use service providers who process personal data on our behalf (e.g., hosting/server operation), this is based on a contract for data processing pursuant to Art. 28 GDPR. Beyond that, we do not use any data processors (no newsletter tool, no CRM, no cloud storage with personal data).

5. Transfer to Third Countries

By loading external resources (Google Fonts; Mermaid.js via jsDelivr CDN), a transmission of IP address and browser headers to providers may occur, who may operate servers also outside the EU/EEA. The legal basis is Art. 6(1)(f) GDPR; where required, safeguarding is provided via EU Standard Contractual Clauses (Art. 46 GDPR). You can avoid this by self-hosting the resources (in planning).

6. Retention Period

7. Your Rights

You have the right at any time to:

Please direct requests in writing to info@gitcover.org.

8. Right to Complain

You have the right to lodge a complaint with the competent data protection supervisory authority. For us, this is the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 31 63, 65021 Wiesbaden (datenschutz.hessen.de).

9. SSL/TLS Encryption

This website is served via HTTPS (TLS 1.2/1.3). The connection between your browser and the server is encrypted.

10. Email Encryption

Emails to us can be encrypted with PGP. Our PGP key is available upon request. Please send sensitive data (address for official donation receipts) encrypted or by mail.

11. Changes to This Statement

We will update this privacy statement if our practices or the law change. The current version is always available on this page.