Privacy policy

Contents

1. Introduction & Responsible Party

  • Website Operator
  • Responsible for Content & Data Processing
  • Data Protection Officer
  • Who is the ICF Movement?
  • Legal Basis

2. Principles of Data Processing

  • βœ… Transparency
  • 🎯 Purpose Limitation
  • βž– Data Minimization
  • πŸ” Security
  • πŸ• Storage Limitation
  • 🌍 Lawfulness

3. Collection & Use of Personal Data

  • πŸ“¬Contact & Forms
  • πŸ’Œ Newsletter & Communication
  • πŸ’³Donations
  • πŸ“ˆ Website Usage & Tracking
  • πŸ’» Server Logs & IT Security

4. Einsatz von Cookies & Tracking Technologien

  • πŸͺWhat are Cookies?
  • πŸͺ Consent Management (CookieHub)
  • βš™οΈ Consent-Based Cookies
  • πŸ›  Management via Google Tag Manager

5. Use of Tools & Third-Party Providers

  • πŸ“ˆ Analytics & Performance Tools
  • πŸ“‹ Forms, Newsletter & Communication
  • πŸŽ₯ Media Embeds
  • βš™οΈAdditional Tools

6. Your Rights

  • πŸ“‹ Right to Information
  • ✏️ Right to Rectification
  • ❌Right to Erasure
  • 🧯 Right to Restriction
  • 🚫 Right to Object
  • πŸ“€ Right to Data Portability
  • πŸ›‘Right to Withdraw Consent
  • πŸ§‘β€βš–οΈ Right to Lodge a Complaint with a Supervisory Authority

7. Data Transfer & Data Processing Agreements

  • 🀝 Cooperation with Service Providers (Data Processing)
  • 🌍 Transfer to Third Countries

8. Retention Period

  • πŸ”„ General Principles
  • πŸ“Œ What does this mean for you?

9. International Data Transfer

  • 🌍 What does this mean specifically?
  • πŸ‡ΊπŸ‡Έ Example: USA

10. Security

  • πŸ” Technical & Organizational Measures
  • πŸ›‘οΈWhat You Should Know

11. Legal Basis for Data Processing & Scope

  • Switzerland
  • European Union

12. Legal Basis for Data Processing & Scope

13. Changes

Introduction & Responsible Party

For us, data protection isn’t just a legal formality – it’s an expression of responsibility. As ICF Hamburg, we’re committed to treating your data with care and respect.

This privacy policy informs you about which personal data we process on our website, for what purpose we do so, and what rights you have in this regard.

It applies to the domain https://icf.church/in all its language versions, as well as to all the following legal entities, and to any future companies operating under the ICF (International Christian Fellowship) brand or in which one of the named organizations holds a stake.

  • ICF Movement (Association)
  • ICF Movement Deutschland e.V. (Association)
  • ICF Hamburg
  • ICF Startup LΓΌbeck

Wherever this privacy policy refers to “ICF” or “we,” this means – depending on the context – one or more of these organizations.

Website Operator

ICF Hamburg e.V.
Merlinweg 2
25436 Tornesch
Germany
[email protected]

Responsible for Content & Data Processing

ICF Hamburg e.V.
Merlinweg 2
25436 Tornesch
Germany
[email protected]

Board:
1. Vorsitzender: Andreas Pantli
2. Vorsitzende: Anna Kristina Pantli
Kassenwart: Christopher KΓΆhler

The responsible party is authorized to act with at least two of the persons named above, and thereby decides on the purposes and means of processing personal data (e.g. names, contact details, etc.).

Data Protection Officer

ICF Hamburg e.V. currently has no legally required data protection officer appointed. The board is responsible for data protection matters. If you have any questions or concerns regarding data protection, you can reach us at:

[email protected]

Who is the ICF Movement?

ICF is a Christian church on a biblical foundation. We were born from the dream of making church dynamic, relatable, and relevant for people.

The ICF Movement is an organization that promotes the founding of churches primarily in Europe, and selectively in the rest of the world, with the goal of helping people become more like Jesus Christ, live fearlessly, and positively change the world around them. We understand the founding of new churches as a missionary mandate that is a fundamental part of our DNA.

Alongside founding ICF churches, the ICF Movement is committed to renewing and strengthening the existing church landscape in Europe and beyond. To this end, resources, conferences, courses (ICF College), leadership development, and coaching are offered.

Together, we believe that Europe and the world can be awakened through healthy, socially relevant local churches. It is our deepest conviction that the local church is the hope of the world!

Learn more about this https://icf.church/movement

Legal Basis

The respective information provided for the various tools in this privacy policy is used exclusively to process your respective request. You can find more information in the section β€žLegal Basis for Data Processingβ€œ.

Principles of Data Processing

We process personal data with a clear purpose and only to the extent necessary for that purpose. In doing so, we adhere to the following principles:

βœ… Transparency

We want you to be able to understand at any time what happens to your data. That’s why we openly describe in this policy which tools we use and why.

🎯 Purpose Limitation

We collect and use personal data only for the purpose intended – for example, to get in touch with you, for newsletter sign-up, to analyze website usage, or to process donations.

βž– Data Minimization

We collect and process only as much data as necessary. Where anonymous or pseudonymous use is possible, we use it.

πŸ” Security

Your data is protected with us. We implement technical and organizational measures to safeguard it against loss, misuse, or unauthorized access.

πŸ• Storage Limitation

We store personal data only for as long as it is needed for the respective purpose, or as required by legal retention obligations.

🌍 Lawfulness

Our data processing is based on a valid legal basis: whether that’s your consent, a legitimate interest, or a legal obligation. We do not make any decisions with legal or similarly significant effects on a purely automated basis (no “profiling” within the meaning of Art. 22 GDPR).

Note: For certain data processing operations involving increased risk (e.g. processing of sensitive data), we conduct a Data Protection Impact Assessment (DPIA) in accordance with Art. 35 GDPR or Art. 22 revFADP, as needed.

Collection & Use of Personal Data

We collect personal data when you actively provide it to us (e.g. via a form) or when it’s technically necessary – for example, through a form, your IP address when visiting a page, when making a donation, or when using our website.

Here’s when this happens and how we use this data:

πŸ“¬Contact & Forms

For example, if you write to us via a contact form or sign up for an event, we process the data you enter (e.g. name, email, your inquiry, etc.) in order to respond to your request or provide the desired service.

πŸ’Œ Newsletter & Communication

If you sign up for our newsletter or stay in touch with us (e.g. by showing interest in resources or offerings), we store and use your contact details to send you regular emails, inspiration, and updates.

You can unsubscribe from the newsletter at any time via the unsubscribe link in every email.

πŸ’³Donations

Donations to the ICF Movement can be made via our own platform, https://give.icf.church This platform is operated by us, the ICF Movement, in collaboration with ICF ZΓΌrich, and falls under our responsibility with regard to data protection.

Payment processing is handled through external providers such as Stripe, PayPal, and TWINT. As soon as you choose one of these payment services, you will be redirected to their platform. From that point on, the respective providers’ own privacy policies will also apply to the further processing of your data.

Alternatively, you can also send a monetary donation directly to ICF Hamburg e.V. via bank transfer. The personal data transmitted in this process (e.g. name, address if needed for the donation receipt, purpose of use) is processed by us on the basis of your consent (Art. 6(1)(a) GDPR) as well as to fulfill tax-law obligations (Art. 6(1)(c) GDPR). This data is not passed on to third parties.

We process the data you provide (e.g. name, email, amount, payment method) to process your donation and for documentation purposes (e.g. issuing donation receipts). Donations to church organizations may, under certain circumstances, allow conclusions to be drawn about your religious beliefs (a special category of personal data considered particularly sensitive under Art. 9 GDPR). This processing takes place only with your explicit consent or where legally permitted.

πŸ™ŒTeam Involvement

If you decide to volunteer on one of ICF Hamburg’s teams, we collect personal data (e.g. name, contact details, team affiliation, and where relevant, skills or availability) in order to coordinate assignments, communicate internally, and organize events, workshops, courses, and conferences.

This processing is based on your consent (Art. 6(1)(a) GDPR). Your data is not passed on to third parties without your explicit consent – with the exception of our data processor Elvanto (servers in the EU: Ireland and Frankfurt), where this data is stored. You can withdraw your consent at any time; until then, your data remains stored.

πŸ“ˆ Website Usage & Tracking

When you visit our website, certain technical information is automatically processed, such as:

  • IP address (truncated/pseudonymized)
  • Browsertyp und -version
  • IP address (truncated/pseudonymized)
  • Operating system Date and time of access
  • Pages visited / time spent

This data helps us keep our website technically stable and continuously improve it (see section β€žCookies & Trackingβ€œ)

πŸ’» Server Logs & IT Security

When you visit our pages, our hosting automatically processes server logs (e.g. IP address, date/time, requested URL, referrer, user agent). This serves the technical delivery of our website and IT security.

Use of Cookies & Tracking Technologies

Our website uses cookies and similar technologies to – with your consent – provide content in a user-friendly way, analyze performance, and enable certain features (e.g. forms or videos).

πŸͺWhat are Cookies?

Cookies are small text files that your browser automatically creates and stores on your device. They don’t contain any malware; instead, they help us, for example:

  • Run the website technically (essential cookies)
  • Create visitor statistics
  • Evaluate marketing campaigns

πŸͺ Consent Management (CookieHub)

Our website uses CookieHub to manage consent for cookies and third-party services. This tool displays a consent banner when you visit and stores your approval or refusal via a technically necessary cookie.

βš™οΈ Consent-Based Cookies

Not all cookies are necessary. Those used, for example, for statistics or marketing purposes, we only set with your explicit consent (Β§ 25 TTDSG / ePrivacy).

That’s why, on your first visit to our website, we show you a cookie banner where you can individually decide which cookies to allow. You can change your selection at any time via the cookie banner.

We use the following cookie categories:

  • Essential cookies: Necessary for technical operation.
  • Functional cookies: Enhance user-friendliness.
  • Analytics cookies: Help us improve the website.
  • Marketing cookies: Support targeted advertising.

πŸ›  Management via Google Tag Manager

We use Google Tag Manager to control certain services in a data-protection-compliant and efficient way – for example, Google Analytics, Facebook Pixel, or other analytics tools. Tag Manager itself does not store personal data; it merely loads configurable scripts.

Tools & Third-Party Providers Used

We use selected third-party providers to make our website user-friendly, secure, and modern. Below, we explain which tools we use, what data is processed in the process, and why.

πŸ“ˆ Analytics & Performance Tools

Google Analytics

We use this to understand how visitors use our website. The data collected (e.g. page views, time spent, device used) is analyzed anonymously.

Google Tag Manager

Used to manage tracking tags and cookies. Tag Manager itself does not store any personal data.

Meta Pixel

We use this to measure marketing campaigns and display relevant content.

Google Ads

Used for campaign tracking and conversion measurement, to analyze the effectiveness of our advertising.

Microsoft Clarity

Used to analyze user behavior (e.g. click paths, heatmaps). The data is analyzed anonymously.

Gleap

We use Gleap as a support and communication platform. It’s used to process support requests, display help resources (e.g. help articles), evaluate user feedback, and show targeted chat messages, notifications, or banners.

Pulsetic

Monitors the availability and performance of the website. No personal data is stored.

Sentry

Records error messages (bugs) and technical data to improve stability.

πŸ“‹ Forms, Newsletter & Communication

MailGun

We use MailGun as an SMTP service to ensure emails are delivered reliably (e.g. confirmations, newsletters).

Google reCAPTCHA

To protect our forms from misuse and spam, we use Google reCAPTCHA (versions 2 & 3). This service checks whether the input comes from a human or a bot. In doing so, information such as your IP address, time spent on the page, and mouse movements are analyzed and transmitted to Google.

Salesforce Account Engagement (Pardot)

Our marketing automation platform, through which we manage newsletters and campaigns. Pardot tracks which content is relevant to you, in order to send you suitable information.

πŸ‘₯ Mitglieder- & Kontaktverwaltung

Elvanto (Church Management)

We use Elvanto (Elvanto Pty Ltd, A.C.N. 400 371 668) as an internal church management tool. Through Elvanto, we manage contact and member data, organize teams and services, and communicate internally. Data from our contact forms (e.g. “Find a Team,” “Find a Small Group,” general inquiries) as well as from team volunteer sign-ups flows into Elvanto.

The data is processed on Elvanto’s servers within the European Union (Ireland and Frankfurt). A data processing agreement in accordance with Art. 28 GDPR is in place with Elvanto. You can find Elvanto’s privacy policy at https://www.elvanto.com/gdpr/.

πŸŽ₯ Media Embeds

YouTube & Vimeo

Videos from YouTube and Vimeo are embedded on our website. In doing so, these providers may set cookies and collect usage data (e.g. which videos are watched).

Spotify

Audio files and videos from Spotify are embedded on our website. In doing so, Spotify may set cookies and collect usage data (e.g. which podcasts are listened to).

ICF Hub

Sermons, offerings, services, and certain organizational data such as social media links, address, or contact details are transmitted to the website from our own internal ICF platform via an API, and this is technically necessary for the core functionalities to work.

βš™οΈAdditional Tools

  • Google Maps: For interactive maps on the website
  • Algolia: For the internal search function for offerings, sermons & locations
  • Shortpixel: Image optimization
  • Zapier: Automation (e.g. transferring data between tools).
  • WPML (Translation): Manages the multilingual display of content

Your Rights

Protecting your personal data matters to us. You have the right to know what happens to your data, and we want to show you transparently what options are available to you. Here’s an overview of your rights:

πŸ“‹ Right to Information

You can ask at any time whether we have stored personal data about you, and if so, what data.

✏️ Right to Rectification

Wenn etwas nicht (mehr) stimmt, kannst du die Korrektur deiner Daten verlangen.

❌Right to Erasure

You have the right to have your data deleted – for example, if it’s no longer needed for its original purpose, or if you’ve withdrawn your consent.

🧯 Right to Restriction

You can request that we restrict the processing of your data – for example, while a review is being carried out, or in the event of an objection.

🚫 Right to Object

You can object to the processing of your personal data at any time – particularly if this processing is based on a legitimate interest (Art. 6(1)(f) GDPR). For direct marketing (e.g. newsletters), you can object at any time and without giving any reason.

πŸ“€ Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, or to have it transmitted directly to another controller – to the extent this is technically feasible.

πŸ›‘Right to Withdraw Consent

If you have given your consent to a data processing operation, you can withdraw that consent at any time, with effect for the future. An informal email is sufficient for this. The lawfulness of any data processing carried out up until the withdrawal remains unaffected.

πŸ§‘β€βš–οΈ Right to Lodge a Complaint with a Supervisory Authority

If you believe your data protection concerns have not been adequately addressed, you have the right to contact the competent supervisory authority.

The competent authority is generally:

  • For Germany: Since the registered office of ICF Hamburg e.V. is in Tornesch (Schleswig-Holstein), the primary competent authority is the UnabhΓ€ngige Landeszentrum fΓΌr Datenschutz Schleswig-Holstein (ULD) (datenschutzzentrum.de). For activities within the city of Hamburg, the Hamburgische Beauftragte fΓΌr Datenschutz und Informationsfreiheit (HmbBfDI) may also be relevant (datenschutz-hamburg.de).
  • For Austria: Austrian Data Protection Authority (dsb.gv.at)
  • For Switzerland: Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch)

Data Transfer & Data Processing Agreements

As a general rule, we do not pass your personal data on to third parties, unless it is:

  • Necessary to fulfill a purpose that you’re aware of and want (e.g. processing a donation),
  • Legally required,
  • Covered by valid consent,
  • Or takes place as part of a data processing arrangement.

🀝 Cooperation with Service Providers (Data Processing)

For certain technical, administrative, and communication processes, we work with selected service providers. These so-called “data processors” act on our behalf and according to our instructions – for example, when:

  • Hosting and operation of the website (e.g. DigitalOcean, Xano, Imgix)
  • Sending emails (e.g. MailGun, Salesforce Account Engagement)
  • Analyse- und Trackingtools (z.β€―B. Google Analytics, Clarity, Sentry)
  • Forms (z.β€―B. Gravity Forms)

We have concluded data-protection-compliant contracts with all our data processors, to ensure that your data is protected and not used for their own purposes.

🌍 Transfer to Third Countries

Some of our service providers are based outside Switzerland or the EU (e.g. in the USA). In such cases, we make sure that an adequate level of data protection is in place – for example, through:

  • Standard contractual clauses of the EU Commission,
  • Adequacy decisions (for countries such as Switzerland),
  • Or additional technical protective measures

Retention Period

We retain personal data for as long as necessary for the respective purpose – or as required by law.

πŸ”„ General Principles

  • Contact inquiries are stored for a maximum of 2 years (for the purpose of follow-up and internal analysis), provided no deletion request is received, no legitimate interest in deletion exists, and no legal retention obligations apply.
  • We store newsletter data until you unsubscribe or withdraw your consent.
  • Donor data is subject to tax-law retention obligations in Switzerland and the EU (usually 10 years).
  • Tracking data (e.g. via Google Analytics) is stored anonymously and retained in order to track longer-term trends, so we can improve the ICF website.

πŸ“Œ What does this mean for you?

We comply with legal deadlines and regularly review which data can be deleted or anonymized.

International Data Transfer

Some of the services we use (e.g. for hosting, newsletters, analytics) are based in, or process data in, countries outside Switzerland, Germany, or Austria – particularly in the USA.

🌍 What does this mean specifically?

When personal data is transferred to countries that don’t have an equivalent level of data protection to Switzerland or the EU, we make sure that your data is nevertheless well protected.

We achieve this, for example, through:

  • EU Standard Contractual Clauses (SCCs) from the EU Commission
  • Adequacy decisions (including the EU/CH-US Data Privacy Framework)

Additional technical/organizational measures, such as encryption or strict access restrictions

πŸ‡ΊπŸ‡Έ Example: USA

Some of our service providers (e.g. Google, Meta, MailGun, Vimeo) are headquartered in the USA. Some of these providers have joined the Data Privacy Framework (DPF), which aims to ensure a comparable level of data protection between the EU/Switzerland and the USA.

Where this does not apply, we use the EU Standard Contractual Clauses as the legal basis.

Security

Protecting your data matters to us. That’s why we implement comprehensive security measures to reliably protect it against loss, misuse, or unauthorized access.

πŸ” Technical & Organizational Measures

We implement technical and organizational security measures to protect your data from loss, misuse, unauthorized access, or disclosure. These include, among others:

  • Careful selection and monitoring of service providers
  • Encryption of connections (SSL/TLS), recognizable by the “https://” in your browser’s address bar
  • Access restrictions on our systems
  • Regular security and software updates
  • Secure password policies & two-factor authentication (internal)

πŸ›‘οΈWhat You Should Know

No digital system is 100% secure. But we do our best to ensure a high level of protection – and respond immediately if there’s any cause for concern. If you notice anything, please reach out to us. We take your feedback seriously. Despite careful technical and organizational measures, a residual risk can never be fully ruled out when transmitting data over the internet (e.g. when using third-party services).

Legal Basis for Data Processing & Scope

This privacy policy is based on the requirements of the General Data Protection Regulation (GDPR), the Swiss Data Protection Act (revFADP), and Austrian data protection law.

Our data processing is based on the applicable legal grounds in each case. Depending on the country from which you access our offerings, different legal standards apply.

πŸ‡¨πŸ‡­ Switzerland

Processing takes place in accordance with the principle of good faith under Art. 31(1) revFADP, and in observance of the principles of proportionality, purpose limitation, and data security (Art. 6 revFADP).

πŸ‡ͺπŸ‡Ί European Union

Data processing is based on the relevant legal grounds under the GDPR, in particular:

  • Art. 6(1)(a) GDPR – Consent
  • Art. 6(1)(b) GDPR – Performance of a contract, or implementation of pre-contractual measures
  • Art. 6(1)(c) GDPR – Legal obligation
  • Art. 6(1)(f) GDPR – Legitimate interest (e.g. our interest in analyzing user behavior to improve our website, or in ensuring IT security)
  • Art. 9(2) GDPR – Processing of special categories of personal data (e.g. in the context of donations)

The relevant legal basis is stated in the respective sections where necessary, or depends on the specific purpose of the processing.

For users outside these legal jurisdictions – for example, the USA (CCPA), Brazil (LGPD), or the UK – additional rights may apply. If you access our offerings from another country, we recommend familiarizing yourself with the local data protection regulations.

Contact for Data Protection Concerns

If you have any questions about data protection, or would like to exercise your rights (e.g. information, deletion, withdrawal of consent), feel free to reach out to us.

Contact

ICF Hamburg e.V.
Merlinweg 2
25436 Tornesch
Germany

datenschutz@icf-hamburg.de

We will respond to your request as quickly as possible – and in any case within the legally required deadline (reporting and notification obligations under Art. 33/34 GDPR or revFADP).

Changes

We review our privacy policy regularly and, where necessary, adapt it to new legal requirements (e.g. rulings by the CJEU, new laws such as the AI Act, or changes to the revFADP) or technical developments. You can find the current version at any time on our website.

Last Updated: Version 2.0 – May 2026