Legal
Datenschutzerklärung
GitCover Commons gUG (hereinafter referred to as "we" or "GCC") takes the protection of your personal data very seriously. This statement describes the data we collect, how we use it, and the rights you have.
1. Data Controller
GitCover Commons gUG (limited liability)
Talstraße 2, 61381 Friedrichsdorf
Represented by Managing Director Axel Druschel
E-Mail: info@gitcover.org
We have not appointed a data protection officer, as there is no statutory obligation to do so (Section 38 BDSG). Please direct data protection requests to the address above.
2. Data We Collect
a) When Visiting This Website
When merely visiting this website, no personal data is collected via tracking, cookies, or analytics services. We do not use analytics tools (no Google Analytics, no Plausible, no Matomo). The page only loads external fonts (Google Fonts) and the diagram library Mermaid.js (loaded via the jsDelivr CDN; license: MIT). When accessing these resources, your IP address and browser headers are transmitted to the respective providers (jsDelivr/Cloudflare or Google). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a technically reliable, appealing presentation). You can prevent this transmission by using local fonts and self-hosting Mermaid — a corresponding extension is in development. For license notices of third-party components, see the Licenses page.
b) Server Logfiles
When retrieving the website, the web server or our hosting service provider processes technically necessary access data (IP address in shortened/temporary form, date and time, requested resource, referrer, user-agent) for delivery of the page and to ensure IT security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation). Log data is deleted or anonymized after [7] days.
c) Via Email Contact
If you contact us via email (e.g., for an official donation receipt), we store the data you provide (name, address, email address, donation details) to process your request. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and/or Art. 6(1)(f) GDPR (legitimate interest).
d) Registration for Training (B2B)
If you register for a training course, we process the data required for execution (name, business contact details, company, if applicable participation/payment data). The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (tax and commercial law retention). Our offers are directed exclusively at entrepreneurs (see GTC).
e) Official Donation Receipts
To issue official donation receipts pursuant to Section 50(1) EStDV, we store the name, address, donation amount, donation date, and purpose. Legal basis: Section 147 AO (10-year retention obligation), Art. 6(1)(c) GDPR (legal obligation). After the retention period expires, the data will be deleted.
3. Disclosure to Third Parties
We do not disclose your personal data to third parties, unless:
- You have explicitly consented (Art. 6(1)(a) GDPR)
- A legal obligation exists (e.g., disclosure to tax authorities, Section 147 AO)
- It is necessary for contract fulfillment (e.g., bank for donation processing)
4. Data Processing on Behalf
Where we use service providers who process personal data on our behalf (e.g., hosting/server operation), this is based on a contract for data processing pursuant to Art. 28 GDPR. Beyond that, we do not use any data processors (no newsletter tool, no CRM, no cloud storage with personal data).
5. Transfer to Third Countries
By loading external resources (Google Fonts; Mermaid.js via jsDelivr CDN), a transmission of IP address and browser headers to providers may occur, who may operate servers also outside the EU/EEA. The legal basis is Art. 6(1)(f) GDPR; where required, safeguarding is provided via EU Standard Contractual Clauses (Art. 46 GDPR). You can avoid this by self-hosting the resources (in planning).
6. Retention Period
- Server logfiles: [7] days
- Email correspondence: until fully processed + 2 years retention
- Training/contract data: 6 or 10 years (Section 257 HGB, Section 147 AO)
- Donation receipts and booking records: 10 years (Section 147 AO)
7. Your Rights
You have the right at any time to:
- Access to data stored about you (Art. 15 GDPR)
- Rectification of incorrect data (Art. 16 GDPR)
- Erasure of your data, provided no retention obligations apply (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent granted, with effect for the future (Art. 7(3) GDPR)
Please direct requests in writing to info@gitcover.org.
8. Right to Complain
You have the right to lodge a complaint with the competent data protection supervisory authority. For us, this is the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 31 63, 65021 Wiesbaden (datenschutz.hessen.de).
9. SSL/TLS Encryption
This website is served via HTTPS (TLS 1.2/1.3). The connection between your browser and the server is encrypted.
10. Email Encryption
Emails to us can be encrypted with PGP. Our PGP key is available upon request. Please send sensitive data (address for official donation receipts) encrypted or by mail.
11. Changes to This Statement
We will update this privacy statement if our practices or the law change. The current version is always available on this page.