Privacy policy

Protecting your data matters to us. We handle personal data responsibly and comply with applicable data protection laws, in particular the EU General Data Protection Regulation (GDPR).

CONTENTS

1. Introduction & Responsible Entity

๐Ÿข Responsible for Content & Data

๐Ÿ–ฅ๏ธ Technical Operation of the Website

๐Ÿค Responsibilities

๐Ÿ“ฎ Data protection contact

๐ŸŒŽ Who is the ICF Movement?

๐Ÿ“– How this policy is structured

2. Principles of Data Processing

โœ… Transparency

๐ŸŽฏ Purpose Limitation

โž– Data Minimization

๐Ÿ” Security

๐Ÿ• Storage Limitation

๐ŸŒ Lawfulness

3. Collection & Use of Personal Data

๐Ÿ“ฌ Contact & Forms

๐Ÿ™ When you entrust us with personal information

๐Ÿ’Œ Newsletter & Communication

๐Ÿ’ณ Donations

๐Ÿ“ˆ Server Logs & Tracking Data

4. Use of Cookies & Tracking Technologies

๐Ÿช What are Cookies?

๐Ÿช Consent Management (CookieHub)

โš™๏ธ When we need your consent

5. Tools & Third-Party Providers Used

๐Ÿ“ˆ Analytics and Performance Tools

๐Ÿ“‹ Forms, Newsletter & Communication

๐ŸŽฅ Media Embeds

๐Ÿ›ก๏ธ Technical Operations and Security

6. Use of AI

๐Ÿค– AI-powered Chat & Support

โœ๏ธ AI-generated Content

๐Ÿง  No automated decisions about you

๐Ÿ“‹ Our Framework

7. Your Rights

๐Ÿ“‹ Right to Access

โœ๏ธ Right to Rectification

โŒ Right to Erasure

๐Ÿงฏ Right to Restriction

๐Ÿšซ Right to Object

๐Ÿ“ค Right to Data Portability

๐Ÿ›‘ Right to Withdraw Consent

๐Ÿง‘โ€โš–๏ธ Right to Lodge a Complaint with a Supervisory Authority

โฑ๏ธ How quickly we respond

8. Data Transfer & Processing on our Behalf

๐Ÿค Joint Responsibility

๐Ÿค Collaboration with Service Providers (Data Processing)

9. Storage Period

๐Ÿ’พ And what about backups?

10. International Data Transfer

๐ŸŒ How we protect your data in the process

11. Security

๐Ÿ” Technical & Organizational Measures

๐Ÿ›ก๏ธ What you should know

12. Legal Bases for Data Processing & Scope

๐Ÿ‡จ๐Ÿ‡ญ Switzerland

๐Ÿ‡ช๐Ÿ‡บ European Union

13. Contact for data protection matters

14. Changes

1. Introduction & Responsible Entity

For us, data protection isnโ€™t just a legal checkboxโ€”itโ€™s an expression of responsibility. As the ICF Movement, weโ€™re committed to treating your data with care and respect.

This privacy policy tells you what personal data we process on our website, why we do so, and what rights you have.

This privacy policy applies to the domain https://icf.church/muenchen in all language versions, as well as to all of the following legal entities and any future companies operating under the ICF (International Christian Fellowship) brand or in which one of the listed Organizations is involved.

  • ICF Munich
  • ICF Freising
  • ICF Augsburg
  • ICF Passau
  • ICF Starnberg
  • the Micro Churches connected with ICF Munich

Wherever this privacy policy refers to “ICF” or “We,” it means โ€“ depending on the context โ€“ one or more of these Organizations.

๐Ÿข Responsible for Content & Data

Responsible in the sense of Art. 4 No. 7 GDPR and Art. 5 lit. j revDSG for the content, forms, and Events on these pages is:

ICF Munich e. V.
ArnulfstraรŸe 34
80335 Munich
Germany
[email protected]


๐Ÿ–ฅ๏ธ Technical Operation of the Website

The technical platform, hosting, and security of this website are the responsibility of:

ICF Movement
Zรผrichstrasse 131
8600 Dรผbendorf
Switzerland
[email protected]


๐Ÿค Responsibilities

The ICF Location mentioned above is responsible for the content, forms, and Events on these pages. The ICF Movement is responsible for the platform, hosting, and security. The Location does not have a say in this. For analyzing website usage and measuring campaigns, the ICF Movement and the Location jointly decide on purposes and means. To that extent, they are joint controllers under Art. 26 GDPR.

The essence of the agreement according to Art. 26 GDPR: The ICF Movement fulfills the information obligations via this declaration, operates the technical systems, and answers inquiries regarding analysis and campaign data. The ICF Location answers inquiries regarding content, forms, and Events. You can assert your rights with both โ€“ we will forward your request internally so you only have to contact us once.


๐Ÿ“ฎ Contact Person for Data Protection

Felix Hiesinger, Data Protection Officer, [email protected]


๐ŸŒŽ Who is the ICF Movement?

ICF is a Christian church based on biblical principles.

We were born from the dream of making church dynamic, relevant, and contemporary for people.

The ICF Movement is an Organization that promotes the founding of churches primarily in Europe and selectively in the rest of the world, with the goal of helping people become more like Jesus Christ, live fearlessly, and positively change their environment. We understand the founding of new churches as a missionary mandate, which is a fundamental part of our DNA.

In addition to planting ICF Churches, the ICF Movement is committed to renewing and strengthening the existing church landscape in Europe and beyond. To this end, resources, conferences, programs (ICF College), leadership, and coaching are offered.

Together, we believe that Europe and the world can be awakened through healthy and socially relevant local churches. It is our deepest conviction that the local church is the hope of the world!

Learn more at https://icf.church/movement/


๐Ÿ“– How this policy is structured

For each processing activity, you will find what data we use, on what legal basis, and how long we store it. The overview of all legal bases can be found in the section “Legal Bases for Data Processing & Scope.”

Do you have to provide us with data?

No. The information in our forms is voluntary. However, without the information marked as mandatory, we cannot process your request (Art. 13 para. 2 lit. e GDPR).

2. Principles of Data Processing

We process personal data with a clear purpose and only to the extent necessary for that purpose. We adhere to these principles:

โœ… Transparency

We want you to be able to understand what happens with your data at any time. That’s why we openly describe in this statement which tools we use and why.

๐ŸŽฏ Purpose Limitation

We collect and use personal data for the respective intended purpose โ€“ e.g., for contacting us, newsletter registration, website usage analysis, or processing donations.

โž– Data Minimization

We only collect & process the data necessary to handle your request. If anonymous or pseudonymous use is possible, we implement it.

๐Ÿ” Security

We protect your data with technical and organizational measures โ€” details are provided further below in the dedicated section “Security.”

๐Ÿ• Storage Limitation

We store personal data for as long as it is needed for the respective purpose or as required by legal retention obligations.

๐ŸŒ Lawfulness

Every processing is based on a legal ground: your consent, the fulfillment of a contract, a legal obligation, or a legitimate interest. Which one applies is stated for each individual processing activity.

3. Collection & Use of Personal Data

We collect personal data when you actively submit it to us or when it is technically necessary โ€“ e.g., via a form, your IP address when a page is accessed, when donating, or when using our website. Here you can find out in which situations this happens and how we use this data:

๐Ÿ“ฌ Contact & Forms

When you write to us via a form or register for an event, we process the information you enterโ€”typically your name, email address, and your requestโ€”so we can reply to you or provide the service.

Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) or legitimate interest in responding to your inquiry (Art. 6(1)(f) GDPR)

๐Ÿ“ธ Photos, videos & audio recordings at events

At our eventsโ€”for example, celebrations, camps, seminars, workshops, or hangoutsโ€”we take photos, video recordings, and audio recordings. These events are generally open to the public; we inform you about recordings in advance (e.g., during registration) and on site.

We use these recordings to document and share our workโ€”for example in annual and activity reports, on our website, on social media, and in print media (flyers, brochures). We only share them with third parties where they are service providers commissioned by us (e.g., agencies, print shops) who process the data on our behalf.

We handle recordings carefully and make sure that the legitimate interests of the people shown are not violated. If you are affected for particularly compelling reasons, please contact usโ€”we will then review appropriate measures.

Legal basis: Legitimate interest in public relations and documenting our activities (Art. 6(1)(f) GDPR)

Your right to object:
You can object to the processing of your image at any time without formalities (Art. 21(1) GDPR), for example by emailing us ([email protected]). We will review your objection and stop further publication within the limits of what is technically possible. We cannot recall print media that has already been distributed.

๐Ÿง’ Photos & data of children and young people

For Events for children and young peopleโ€”for example ICF Kids, camps, or youth eventsโ€”we sometimes process data of minors, such as during registration or in photo and video recordings.

For children under 16, we obtain the consent of their legal guardians before publishing photos or videos in which the child is identifiable (Art. 8 GDPR). For registration forms for childrenโ€™s and youth Events, we point this out separately and explicitly ask the legal guardians.

Legal basis: Consent of the legal guardians (Art. 6(1)(a) in conjunction with Art. 8 GDPR)

๐Ÿ™ When you share something personal with us

Some people write to us about a prayer request, a crisis, or a question they wouldnโ€™t ask anyone else. That matters to us, and we handle these messages differently from a normal inquiry:

  • They are only read by the people responsible for them.
  • They do not flow into our CRM or marketing analyses.
  • We only store them for as long as support is needed, and then delete them.

Such information may include specially protected dataโ€”for example about your health or your faith. We process it only because you intentionally share it with us, and we rely on your explicit consent (Art. 9(2)(a) GDPR, Art. 6(7)(a) revDSG).

๐Ÿ’Œ Newsletter & communication

When you sign up for our newsletter, we store your email address,

your name (if provided), and your language setting so we can regularly send you

inspiration, updates, and information about Events.

You can unsubscribe from the newsletter at any time via the unsubscribe link in every email. After you unsubscribe, we only keep your address on a suppression list so you donโ€™t receive any further emails.

Legal basis: Consent (Art. 6(1)(a) GDPR, Art. 6(6) revDSG); to prove registration, legal obligation and legitimate interest (Art. 6(1)(c) and (f) GDPR)

๐Ÿ’ณ Donations

You can donate to ICF Munich directly via a form on this website. Payment processing is handled by the following external payment service providers:

  • Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland)
    If you choose to pay via Stripe, the payment data you enter will be transmitted to Stripe.
    Your data is transmitted to Stripe on the basis of Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (processing to perform a contract). You can withdraw your consent to data processing at any time. A withdrawal does not affect the lawfulness of processing carried out in the past. All data required for payment processing is used exclusively to carry out the payments and is transmitted via โ€œSSLโ€. Stripe is PCI DSS certified. Stripe may transfer, process, and store personal data outside the EU. Stripe is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply.

They process your payment data and check whether a payment is fraudulent. They use their own cookies for this. Your card details are processed exclusively thereโ€”we do not see or store them.

We process the remaining detailsโ€”name, email address, amount, and payment methodโ€”to process your donation, send you a confirmation, and record it properly. We are legally required to retain the related receipts; how long is stated below under โ€œRetention period.โ€

A donation to a church says something about your faith. Such information is specially protected (Art. 9 GDPR, Art. 5 lit. c no. 1 revDSG). Thatโ€™s why we explicitly ask in the donation form whether you agreeโ€”including that our payment service provider and our donation administration process this information. Without this consent, we cannot accept a donation via this website.

What if you withdraw your consent?
You can do that at any time. From then on, we wonโ€™t use your donation data for anything else: no thank-you letters, no analyses, no donation history. What we are not allowed to delete are the booking receipts themselvesโ€”they are subject to statutory retention obligations. Instead, we restrict them: they remain stored until the above period expires, but are only used if an authority needs to see them. After that, we delete them.

Legal basis: Processing your donation: performance of a contract (Art. 6(1)(b) GDPR); in Switzerland, our overriding interest in processing the contract (Art. 31(2)(a) revDSG). Retaining receipts: legal obligation (Art. 6(1)(c) GDPR); in Switzerland, statutory justification (Art. 31(1) revDSG). Information that reveals your faith, and sharing it with our service providers: your explicit consent (Art. 9(2)(a) GDPR, Art. 6(7)(a) revDSG). Your withdrawal applies going forward (Art. 7(3) GDPR); it does not override statutory retention obligations (Art. 17(3)(b) GDPR).

Retention period: in Switzerland 10 years (Art. 958f OR), in Germany 8 years for booking receipts and 10 years for annual financial statements (ยง 147 AO).

๐Ÿ“ˆ Server logs & tracking data

As soon as you access our website, we automatically process technical information. We distinguish between two levelsโ€”the difference is important:

Server logs (always, even without consent):

Our hosting logs every access with the full IP address, date and time, requested URL, referrer, and user agent. Without this, we can neither operate the website nor protect it from attacks.

Legal basis: Legitimate interest in providing the service and IT security (Art. 6(1)(f) GDPR)

Traffic analysis (only with your consent):

If you have consented, we also measure which pages are accessed, how long visits last, and how someone finds us. Your IP address is shortened before it is stored.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG)

4. Use of Cookies & Tracking Technologies

Our website uses cookies and similar technologies. Some of these are necessary for the operation of the site; all others are only used if you have consented.

๐Ÿช What are cookies?

Cookies are small text files that your browser stores on your device. Similar technologies like local storage or pixels work similarly. They help us to,

  • to operate the website technically,
  • to understand how it is used,
  • and to evaluate campaigns.

๐Ÿช Consent management (CookieHub)

CookieHub โ€” CookieHub ehf., Reykjanesbรฆr, Iceland (EEA)

We log the time of your decision, the categories selected, technical details about your browser, and a random identifier that allows your decision to be retrievedโ€”this is required as proof under Art. 7(1) GDPR.

Legal basis: Legal obligation and legitimate interest (Art. 6(1)(c) and (f) GDPR)
Retention period: 12 months

โš™๏ธ When we need your consent

For cookies that are not necessary to operate the websiteโ€”i.e., statistics, marketing, and embedded contentโ€”we need a legal basis. Which one applies depends on which country you are coming from:

  • Germany: ยง 25(1) TDDDG. A legitimate interest is explicitly not sufficient here for access to your device.
  • Austria: ยง 165(3) TKG 2021. The same applies here: your consent must be activeโ€”scrolling on or a pre-ticked box is not enough.
  • Switzerland: For access to your device, Art. 45c lit. b FMG applies. It requires us to inform you about the processing and its purpose and to point out that you can refuse it. If you are coming from Switzerland or Liechtenstein, we implement this as follows: our banner informs you on your first visit and you can reject each category. Until you reject, analytics and marketing cookies are activeโ€”this is the opt-out model permitted in Switzerland. Your rejection takes effect immediately and applies to all future visits. If you are coming from the EU or the EEA, we obtain your consent beforehand: without your active โ€œyes,โ€ nothing that isnโ€™t technically necessary will be loaded. In both cases, โ€œAcceptโ€ and โ€œRejectโ€ are equally easy to access.

Our cookie categories:

  • Essential โ€” indispensable for technical operation. This includes storing your cookie decision, your language selection, search on our website, securing our forms, and protection against attacks. Without consent.
  • Functional โ€” remembers settings that make it easier for you to use the site and runs our support chat. Only with consent.
  • Analytics โ€” measures how our website is used. Only with consent.
  • Marketing โ€” measures our campaigns, enables advertising, and loads embedded third-party content: maps, videos, podcasts, and our radio. This content comes from providers who also evaluate it for their own advertising purposesโ€”thatโ€™s why it falls into this category. Only with consent.
  • Other cookies โ€” cookies we have not yet been able to assign to a category. They are treated as non-essential cookies and are only set with your consent.

5. Tools & Third-Party Providers Used

We use selected third-party providers to make our website user-friendly, secure, and modern. Below, we explain which tools we use, what data is processed, and why.

๐Ÿ“ˆ Analytics and Performance Tools

Google Analyticsโ€”Google Ireland Limited, Dublin, Ireland

Shows us how our website is used: which pages are accessed, how long visits last, and how someone finds us. We also measure which forms are opened and submitted โ€“ this shows us where people drop off while filling them out. The content of your entries is not transmitted.

The data is pseudonymous: it is not assigned to a person by name, but can be assigned to a device via a random identifier (client ID). Your IP address is shortened before it is stored.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG)

Retention period: 14 months

Third country: USA, Google LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply

Google Tag Manager โ€” Google Ireland Limited, Dublin, Ireland

The Tag Manager is the tool we use to control which analytics and marketing services are loaded. It does not analyze anything itself, but when the container is loaded, your IP address is transmitted to Googleโ€”thatโ€™s why we only load it once you have consented.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG)
Retention period: 25 months

Third country: USA, Google LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply

Meta Pixel โ€” Meta Platforms Ireland Limited, Dublin, Ireland
Measures our campaigns on Facebook and Instagram and enables us to show you relevant content there. Meta processes the data for its own purposes as well and is jointly responsible with usโ€”see the section โ€œJoint controllershipโ€ for more.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG); in Switzerland, additionally explicit consent under Art. 6(7)(b) revDSG
Retention period: The cookies on your device expire 13 months after last use. How long Meta stores the transmitted data on its own systems is determined by Metaโ€”see Metaโ€™s privacy policy for details.
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework (if and as long as the provider is certified); Standard Contractual Clauses also apply

TikTok Pixel โ€” TikTok Technology Limited, Dublin, Ireland
Measures whether our campaigns on TikTok are effectiveโ€”i.e., whether someone does something with us after clicking an ad. For this purpose, your visit to our website is transmitted to TikTok and linked there to your TikTok account or your device. TikTok also uses this data for its own purposes, including ad delivery. Thatโ€™s why we are jointly responsible with TikTok (Art. 26 GDPR)โ€”see the section โ€œJoint controllershipโ€ for more.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG); in Switzerland, additionally explicit consent under Art. 6(7)(b) revDSG
Retention period: The cookies on your device expire 13 months after last use. How long TikTok stores the transmitted data on its own systems is determined by TikTokโ€”see TikTokโ€™s privacy policy for details.
Third country: According to TikTok, it stores data from the European Economic Area in data centers in Norway, Ireland, and the USA. Access from China, where the parent company ByteDance is based, cannot be ruled out based on current information. For transfers outside the EEA, TikTok relies on Standard Contractual Clauses.

Google Ads โ€” Google Ireland Limited, Dublin, Ireland
Measures whether our advertising is effectiveโ€”i.e., whether someone does something with us after clicking an ad. This creates pseudonymous profiles of your behavior on our website.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG)
Retention period: 3 years
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply

Microsoft Clarity โ€” Microsoft Ireland Operations Limited, Dublin, Ireland & Microsoft Corporation, USA
Clarity helps us see where people get stuck on our website. To do this, Clarity records sessions: mouse movements, scrolling, clicks, and page changes are stored as a playable recording and summarized into heatmaps. Entries in form fields are masked. This data is pseudonymous, not anonymous. Microsoft sets an identifier that applies not only to Clarity but to Microsoft services in generalโ€”including Microsoftโ€™s advertising network. Thatโ€™s why we donโ€™t treat Clarity as a purely analytics tool and explicitly point this out here.

Legal basis: Consent (Art. 6 para. 1 lit. a GDPR, ยง 25 para. 1 TDDDG)
Storage period: 9 months
Third country: USA, certified for the EU-US and Swiss-US Data Privacy Framework; Standard Contractual Clauses also apply

๐Ÿ“‹ Forms, Newsletters & Communication

Gravity Forms
Our forms run via Gravity Forms. The data is initially stored in our own database. Depending on the form, we forward it to the following recipients:

The technical transfer to these recipients happens directly from our server. We use extensions for this (Gravity Forms Webhooks, Gravity Wiz API Alchemist) that do not store any data themselves and do not receive a copy.

Email verification: To make sure confirmations actually reach you, we check when you submit whether the address entered is deliverable. For this, your email address is transmitted to ZeroBounce (ZeroBounce, USA) and verified there.

Legal basis: Legitimate interest in deliverable confirmations (Art. 6(1)(f) GDPR)
Retention period: Zapier (69 days), ZeroBounce (30 days), Gravity Forms (30 days), Salesforce (until withdrawal)
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply

MailGun โ€” Mailgun Technologies, Inc. (Sinch Group)Ensures our emails arrive reliably from a technical perspectiveโ€”confirmations, notifications, newsletters. We send form confirmations and system emails via MailGun.

Before an email is sent there, it passes through a sending component on our own server. This records who received which email and when, and whether it could be delivered. We need this to be able to trace delivery issues. MailGun also logs sending on its side.

Legal basis: Performance of a contract and legitimate interest in reliable delivery (Art. 6(1)(b) and (f) GDPR)
Retention period: 30 days
Third country: USA, certified under the EU-U.S. Data Privacy Framework, but not under the Swiss-U.S. Data Privacy Framework. For disclosures from Switzerland, we rely on the standard data protection clauses recognized by the FDPIC.

Google reCAPTCHAโ€” Google Ireland Limited, Ireland & Google LLC, USAProtects our forms from automated attacks. For this purpose, Google evaluates, among other things, your IP address, how long you stay on the page, and your mouse movements to determine whether you are a human. The protection is loaded when you access pages with forms.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG)
Third country: USA, Google LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply

Fillout โ€” Fillout Inc., USA
For certain formsโ€”for example event registrations or surveysโ€”we use Fillout. From some pages, you are redirected directly there, or you see the form embedded directly on the page.

Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Retention period: Until withdrawal
Third country: USA, Fillout Inc. is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clausesโ€”for Switzerland, on the version recognized by the FDPIC.

Marketing Cloud Engagement (Pardot) โ€” Salesforce, Inc.We use this platform to send our newsletter. In doing so, we measure whether and when you open an email and which links you click. This information creates an interest profile that helps us send you more relevant content. We only do this if you have consented.

Legal basis: Consent (Art. 6(1)(a) GDPR)
Retention period: until you unsubscribe, if that was the only purpose
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply

Elvanto โ€” Elvanto Pty Ltd, Australia (EU server location: Ireland and Frankfurt)

Elvanto is our personal data system (CRM). Among other things, we manage registrations for events and groups as well as contact details of members and interested people.

Legal basis: Performance of a contract or legitimate interest in managing our Events (Art. 6(1)(b) and (f) GDPR)
Retention period: until withdrawal
Third country: The data is stored on servers in the EU (Ireland, Frankfurt). Since Elvanto Pty Ltd is based in Australia, access from a third country cannot be completely ruled out; we rely on Standard Contractual Clauses for this.

Billetto โ€” Billetto ApS, Copenhagen, Denmark (EU)

For ticketing for certain events, we sometimes use Billetto. If you book tickets via our website, you will be redirected to Billettoโ€™s website; their own privacy policy also applies there. We also transmit the data you enter to ICF Mรผnchen e. V. for processing to enable your participation in the event, and store it in Elvanto.

Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Retention period: until statutory retention obligations expire after the event
Third country: Billetto is a company based in the EU; according to its own information, data may in individual cases also be processed outside the EU.

Freshdesk โ€” Freshworks Inc., San Mateo, California, USA (stored on servers in the EU)

We use the Freshdesk ticketing system to handle support and contact requests. When you contact us, your detailsโ€”for example your name, email address, and the content of your requestโ€”are stored in the ticketing system so we can track and respond to your request.

Legal basis: Contract performance or pre-contractual measures, or legitimate interest in efficient processing of your inquiries (Art. 6(1)(b) or (f) GDPR)
Retention period: until revoked
Third country: Your Freshdesk data is stored on servers in the EU. Since Freshworks Inc., as the parent company, is based in the USA, access from a third country cannot be completely ruled out. Freshworks is certified under the EU-U.S. Data Privacy Framework and additionally concludes Standard Contractual Clauses through its own data processing agreement. Freshworks is also ISO-27001 and SOC-2 certified.

๐ŸŽฅ Media Embeds

YouTube โ€” Google Ireland Limited & Vimeo Vimeo.com, Inc., USA
We embed videos. Videos only load once you’ve given consent. After that, the respective provider receives your IP address and can set cookies; if you’re logged in there, they can associate the video view with your account.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG)
Third country: USA, certified under the EU-US and Swiss-US Data Privacy Framework; Standard Contractual Clauses additionally apply

Spotify โ€” Spotify AB, SwedenFor embedded podcasts and audio content โ€” under the same conditions as above.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG)

Google Maps โ€” Google Ireland Limited, Dublin, Ireland
Shows you where to find us. As soon as a map loads, your browser transmits your IP address to Google, and Google can set cookies. If you’re logged into Google, Google can associate the map view with your account. That’s why we only load maps once you’ve given consent.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG)
Retention period: 12 MONTHS
Third country: USA, certified under the EU-US and Swiss-US Data Privacy Framework; Standard Contractual Clauses additionally apply

ICF Radio โ€” SAM Cloud and Triton Digital, USAOur radio player retrieves the program and live stream from two external services. The player only starts once you’ve given consent. After that, your device establishes a direct connection to the streaming provider; your IP address and technical information about your device are transmitted.

Legal basis: Consent (Art. 6 para. 1 lit. a GDPR, ยง 25 para. 1 TDDDG)
Third country: USA, Triton Digital is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses โ€“ for Switzerland, on the version recognized by the FDPIC.

๐Ÿ›ก๏ธ Technical Operation and Security

DigitalOcean โ€” DigitalOcean LLC, USA (Server Region Frankfurt)

Operates the servers on which this website (main installation) runs, as well as the regular backup of our systems using the Snapshooter tool. Backups also contain personal data and are automatically overwritten.

Legal basis: Legitimate interest in failover security and legal obligations (Art. 6(1)(f) and (c) GDPR)
Third country: USA, DigitalOcean LLC is certified under the EU-US and Swiss-US Data Privacy Framework; Standard Contractual Clauses additionally apply

Cloudflare โ€” Cloudflare, Inc., USA

Delivers our website faster and protects it from attacks. Every request to our website runs through Cloudflare; IP address, requested URL, and browser data are processed.

Additionally, Cloudflare measures in your browser how quickly our pages load (“Browser Insights”). Technical information about your device and the page accessed is transmitted. We use this exclusively to identify slow pages โ€” no profile is created about you.

Legal basis: Legitimate interest in availability and IT security (Art. 6(1)(f) GDPR)

Retention period: 7 days (logs), 30 days (analytics)

Third country: USA, certified under the EU-US and Swiss-US Data Privacy Framework; Standard Contractual Clauses additionally apply

Wordfence โ€” Defiant, Inc., USA

Detects and blocks attacks on our website. For this purpose, IP addresses, access patterns, and failed login attempts are analyzed and partially transmitted to Wordfence.

Legal basis: Legitimate interest in IT security (Art. 6(1)(f) GDPR)

Retention period: 20 days (logs)

Third country: USA, Defiant, Inc. is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses โ€” for Switzerland in the version recognized by the FDPIC.

Sentry โ€” Functional Software, Inc., USA โ€” (Server Region EU)

Reports technical errors to us so we can fix them. Error reports may contain IP addresses, accessed URLs including parameters, and browser data โ€” information that may relate to you.

Legal basis: Legitimate interest in a functioning website (Art. 6(1)(f) GDPR)

Retention period: 90 days

Third country: We use Sentry’s EU region โ€” error reports are stored in Frankfurt and do not leave the EU in regular operation. Management of our Sentry account runs through systems in the USA, so access from there cannot be completely ruled out. Functional Software, Inc. (Sentry) is certified under the EU-US and Swiss-US Data Privacy Framework; Standard Contractual Clauses additionally apply

Pulsetic โ€” Designmodo, Inc., USA

Regularly accesses our website from outside to check whether it’s reachable. These requests come from Pulsetic itself, not from you โ€” no data about you is generated.

Legal basis: Legitimate interest in availability (Art. 6(1)(f) GDPR)
Retention period: 5 years
Third country: USA, Designmodo, Inc. is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses โ€” for Switzerland in the version recognized by the FDPIC.

ShortPixel โ€” ID SCOUT SRL, Bucharest, Romania

Reduces the size of image files on our website so pages load faster. Our server transfers the images to ShortPixel and plays back the optimized version โ€” your browser has no contact with ShortPixel, your IP address is not transmitted. Additionally, we have image descriptions (alt texts) automatically generated with AI so our content is accessible with a screen reader. For this, our server passes the image to ShortPixel, which uses an AI service โ€” currently OpenAI or Anthropic, both in the USA. This also applies to images showing people. These are exclusively images we publish on this website anyway. We use the result only as an image description.

Legal basis: Legitimate interest in a fast and accessible website (Art. 6(1)(f) GDPR)

Retention period: Images are deleted from ShortPixel’s servers after optimization (according to the provider, within approximately 30 minutes)
Third country: USA. Neither OpenAI nor Anthropic is certified under the Data Privacy Framework. ShortPixel bases the transfer on Standard Contractual Clauses (Module 3, processor to sub-processor) โ€” for Switzerland in the version recognized by the FDPIC.

Imgix โ€” Zebrafish Labs, Inc, USA

Delivers images in the appropriate size and quality so pages load quickly. Your browser loads these images directly from Imgix โ€” your IP address, browser, and the page accessed are transmitted. When cropping, Imgix automatically detects where faces are in an image so the crop is correct โ€” no person is identified.

Legal basis: Legitimate interest in a fast website (Art. 6(1)(f) GDPR)

Third country: USA, Zebrafish Labs, Inc. is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses โ€” for Switzerland in the version recognized by the FDPIC.

WPML โ€” OnTheGoSystems Limited, Hong Kong

Language selection (local function on our server): Our content is available in multiple languages. We store your chosen language in a technically necessary cookie on your device. Translation management runs entirely on our own server โ€” no data about you is transmitted to the manufacturer or other third parties.

Legal basis: Legitimate interest in a functioning website (Art. 6(1)(f) GDPR); for storage on your device, technical necessity (ยง 25(2) No. 2 TDDDG)

Algolia โ€” Algolia SAS, France (Server Region EU)

Operates the search on our website. Your search query runs through a cache in our own infrastructure and from there to Algolia โ€” your IP address typically does not reach Algolia. Only if this cache fails does your browser query Algolia directly; then search term and IP address are transmitted. We know: What people search for on a church website can be very personal. We therefore only analyze search queries in aggregate to improve the search โ€” we do not associate them with any person and do not link them to other data about you.

Legal basis: Legitimate interest in a functioning search (Art. 6(1)(f) GDPR)

Retention period: 90 days

Third country: Our search data is located in Algolia’s EU region. According to Algolia, logs of individual search queries may also be processed outside the EU; Standard Contractual Clauses apply โ€” for Switzerland in the version recognized by the FDPIC.

MainWP (Central Website Management) โ€” YellowTree GmbH, Germany

Our websites are managed centrally from a dashboard โ€” for updates, security checks, and backups. This dashboard is operated by YellowTree GmbH, our technical service provider, on its own infrastructure. The software manufacturer does not receive any content from our website.

This connection is an administrative access. Through it, everything that is also accessible through the website’s own administration is fundamentally reachable โ€” including form submissions. YellowTree uses it exclusively on our behalf for maintenance and security; the details are regulated in a data processing agreement.

Legal basis: Legitimate interest in secure and up-to-date operation of our websites (Art. 6(1)(f) GDPR)

ICF Hub โ€” operated by ICF Movement, technical platform: Xano, Inc., USAEvents, celebrations, and organizational data such as address, social media links, and contact information come to this website from ICF Hub via an interface. Without this connection, the core functions of the site would not work. This query runs through our server, not through your browser โ€” your IP address is not transmitted. When contact details of individuals are published โ€” such as contact persons for a location โ€” these come from our internal administration. We inform the affected individuals separately in accordance with Art. 14 GDPR

Legal basis: Legitimate interest in presenting our events (Art. 6(1)(f) GDPR)
Third country: USA, Xano, Inc. is certified under the EU-US Data Privacy Framework, but not under the Swiss-US Data Privacy Framework. For disclosures from Switzerland, we rely on the standard data protection clauses recognized by the FDPIC.

Hetzner โ€” Hetzner Online GmbH, Gunzenhausen, Germany
For hosting domains and individual web installations, we use the infrastructure of Hetzner Online GmbH. When accessing and operating these websites, technical connection data (e.g., IP address, server log files) is processed on Hetzner’s servers.

Legal basis: Legitimate interest in a secure, stable, and technically flawless operation of our web offerings (Art. 6 para. 1 lit. f GDPR).
Storage period: Server log files are automatically deleted or anonymized after 7 to 14 days.

Strato โ€” STRATO AG, Berlin, Germany
We operate a virtual server environment (VM) at STRATO AG, on which our internal accounting and billing software runs. In this context, personal and financial data (master and contact data, invoice and payment data, as well as booking receipts from members, donations, and services) are processed.

Legal basis: Fulfillment of contract and implementation of pre-contractual measures (Art. 6 para. 1 lit. b GDPR), fulfillment of legal and tax obligations (Art. 6 para. 1 lit. c GDPR in conjunction with ยง 147 AO), and our legitimate interest in proper financial and association administration (Art. 6 para. 1 lit. f GDPR).
Storage period: Data is stored in accordance with statutory commercial and tax retention periods (in Germany, 8 to 10 years according to ยง 147 AO / ยง 257 HGB).

6. Use of AI

In some places, Artificial Intelligence (AI) helps us to assist you faster. We use it consciously in a limited way โ€“ and you should always be able to recognize whether you are speaking with a machine or a human.

๐Ÿค– AI-powered Chat & Support

Gleap โ€” Gleap GmbH, Austria

An AI-powered chat assistant may be integrated into our website to help you with questions and suggest relevant help articles. It runs via our support platform Gleap and uses an AI model for this purpose.

Gleap is also our support platform outside of AI chat: for help articles, user feedback, and targeted hints in the widget. For the widget to start at all, Gleap stores a basic technical configuration in your browser. Everything else โ€” the chat session itself and your messages โ€” only happens once you’ve given consent.

The assistant identifies itself as AI at first contact. Art. 50(1) of the EU AI Regulation requires this from providers of such systems โ€” we think it’s right anyway and look for this when selecting tools. You can request to speak with a person from our team at any time.

When you use the chat, we process your messages and technical metadata to respond to you. Please do not enter particularly sensitive information in the chat.

Legal basis: Consent (Art. 6(1)(a) GDPR, ยง 25(1) TDDDG) ยท Retention period: 14 months
Third country: Gleap in Austria;
Transfer to various AI providers

โœ๏ธ AI-generated Content

Where we create or process texts, images, or subtitles with AI, we review them editorially. Image, audio, and video content that appears real but is AI-generated or AI-altered is visibly labeled. This is required of us as operators by Art. 50 para. 4 of the EU AI Regulation.

For texts, this obligation does not apply to us because we editorially review every published text and take responsibility for it. Nevertheless, we voluntarily indicate where AI played a significant role in the result โ€“ we believe this is appropriate.

๐Ÿง  No automated decisions about you

We do not make decisions with legal or similarly significant effects exclusively automatically (Art. 22 GDPR). According to Art. 21 revDSG, we would also inform you if this were ever the case. AI helps us with formulating, sorting, and answering โ€“ decisions that affect you are made by people.

๐Ÿ“‹ Our Framework

We do not enter personal data into systems that are not approved for it, we train our employees in dealing with AI (Art. 4 EU AI Regulation), and we review every system before use.

7. Your Rights

The protection of your personal data is important to us. You have the right to know what happens to your data, and we transparently show you what options are available to you. Here is an overview of your rights:

๐Ÿ“‹ Right of Access

You can find out at any time whether and which personal data we process about you โ€“ and request a copy thereof (Art. 15 GDPR, Art. 25 revDSG).

โœ๏ธ Right to Rectification

If something is no longer correct, you can request the correction of your data (Art. 16 GDPR, Art. 32 para. 1 revDSG).

โŒ Right to Erasure

You have the right to have your data deleted โ€“ for example, if it is no longer needed for the original purpose or you have withdrawn your consent (Art. 17 GDPR). In Switzerland, we destroy or anonymize personal data as soon as it is no longer needed for the purpose (Art. 6 para. 4 revDSG); furthermore, you can legally demand deletion (Art. 32 para. 2 lit. c revDSG). Where we are legally obliged to retain data โ€“ for example, for donation receipts โ€“ we restrict processing instead of deleting.

๐Ÿงฏ Right to Restriction of Processing

You can request that we only process your data in a restricted manner โ€“ e.g., during an examination or in case of an objection (Art. 18 GDPR).

๐Ÿšซ Right to Object

You can object to advertising at any time and without giving reasons โ€“ then we will no longer process your data for this purpose (Art. 21 para. 2 and 3 GDPR). A short message to us is sufficient.

Furthermore, you can object to the processing of your data for reasons arising from your particular situation โ€“ especially for processing based on a legitimate interest (Art. 21 para. 1 GDPR).

๐Ÿ“ค Right to Data Portability

You have the right to receive data that we process automatically based on your consent or for contract performance in a common format and โ€” if technically feasible โ€” to have it transferred to third parties (Art. 20 GDPR, Art. 28 revDSG).

๐Ÿ›‘ Right to Withdraw Consent

If you have given us consent for certain purposes (e.g., newsletter), you can withdraw it at any time. The withdrawal takes effect for the future โ€” the fact that we processed your data until then remains lawful (Art. 7(3) GDPR).

๐Ÿง‘โ€โš–๏ธ Right to Lodge a Complaint with a Supervisory Authority

If you think we’re not handling your data properly, please talk to us first โ€” most of the time it can be resolved quickly. Independently, you can contact our Clearing Office or a supervisory authority.

In the EU you have the right to lodge a complaint with the supervisory authority of your residence, workplace, or the place of the alleged infringement (Art. 77 GDPR):

  • Germany: State Commissioner for Data Protection and Freedom of Information of the respective federal state
  • Austria: Austrian Data Protection Authority, Vienna
  • In Switzerland you can contact the Federal Data Protection and Information Commissioner (FDPIC). They can open an investigation (Art. 49 revDSG).

In Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC). They can open an investigation (Art. 49 revDSG).

โฑ๏ธ How quickly we respond

We respond to your request within one month (Art. 12 para. 3 GDPR; in Switzerland Art. 25 para. 7 revDSG). If it becomes more complex, we may extend by up to two months โ€“ then we will inform you within the first month with justification. To ensure that the request truly comes from you, we may need to ask you for proof of identity.

8. Data Transfer & Processing on our Behalf

We generally do not disclose your personal data to third parties, unless it is:

  • necessary to fulfill a purpose you know and want (e.g., donation processing),
  • legally required,
  • covered by valid consent,
  • or occurs within the framework of data processing.

๐Ÿค Joint Controllership

For some services, we don’t decide alone what happens to your data โ€” the provider also uses it for their own purposes. In these cases, we are jointly responsible under Art. 26 GDPR:

  • Meta Pixel and our pages on Facebook and Instagram: Meta also analyzes usage data for its own analytics and advertising. We have concluded the agreement provided for this purpose with Meta. Meta fulfills the information obligations for its own processing, we for the collection on our website.
  • YouTube channel and other social media presences: Here too we receive statistical evaluations (“Insights”) based on the processing of usage data.
  • TikTok Pixel and our TikTok channel: TikTok also analyzes usage data for its own analytics and advertising. We have concluded the agreement provided for this purpose with TikTok.

You can assert your rights with any of the joint controllers. The providers themselves make the full text of the agreements available; we’ll send it to you upon request.

๐Ÿค Collaboration with Service Providers (Data Processing)

For technical, administrative, and communication tasks, we work with selected service providers โ€” for hosting and security, for sending emails, for forms, search, and support. Which ones specifically are listed in the section “Tools & Third-Party Providers Used.”

Before we engage a service provider, we review them and conclude the necessary contracts. Where someone processes data on our behalf, this is a data processing agreement under Art. 28 GDPR or Art. 9 revDSG. It stipulates that they only use your data for the agreed purpose and protect it appropriately.

For some services โ€“ especially Google, Meta, and Microsoft โ€“ the providers also process data for their own purposes. In such cases, they are not only processors. Where this is the case, we state it for the respective service and in the section “Joint Responsibility.”

We review this list semi-annually. If you notice that something is missing or no longer correct, please write to us โ€“ we will correct it.

9. Storage Period

We retain personal data for as long as necessary for the respective purpose โ€“ or as long as required by law.

  • Server logs: 14 days โ†’ IT security and error analysis
  • Contact inquiries: until final processing, then at most 24 months โ†’ follow-up questions and traceability
  • Newsletter data: until unsubscription, then only on the suppression list โ†’ consent
  • Email delivery logs: 12 months โ†’ traceability of delivery issues
  • Backups: 24 months โ†’ then automatically overwritten

How long individual services store data on their own systems is stated directly for each service in the section “Tools & Third-Party Providers Used.”

๐Ÿ’พ And what about backups?

If you request deletion, we remove your data from our active systems. In our backups, it may still be present for up to 12 months until these are automatically overwritten. We do not restore deleted data from backups.

10. International Data Transfer

Some of our service providers process data outside Switzerland and the EU. According to Art. 19(4) revDSG, we tell you which countries are involved and what we base this on:

  • Ireland (EU): Google Ireland, Meta Platforms Ireland, Microsoft Ireland, TikTok Technology Limited โ€” EU/EEA, no additional measures required
  • Iceland (EEA): CookieHub ehf.
  • Austria (EU): Gleap GmbH
  • Sweden (EU): Spotify AB
  • Romania (EU): ID SCOUT SRL (ShortPixel)
  • France (EU): Algolia SAS
  • Denmark (EU): Billetto ApS
  • Australia (Standard Contractual Clauses; server location EU): > Elvanto Pty Ltd
  • USA (Data Privacy Framework and Standard Contractual Clauses):
    Google LLC, Meta Platforms Inc., Microsoft Corp., Cloudflare Inc., Vimeo.com Inc., Salesforce Inc., Zapier Inc., DigitalOcean LLC (incl. SnapShooter), ZeroBounce, Stripe LLC, Functional Software Inc. (Sentry), Freshworks Inc. (Freshdesk; data storage on > EU servers)
  • USA (EU-US DPF; standard data protection clauses recognized by the FDPIC for Switzerland):
    Mailgun Technologies Inc., Xano Inc.
  • USA (Standard Contractual Clauses only, in the version recognized by the FDPIC for Switzerland):
    Fillout Inc., Defiant Inc. (Wordfence), Zebrafish Labs Inc. (imgix), Triton Digital, Designmodo Inc. (Pulsetic), OpenAI and Anthropic (AI image descriptions via ShortPixel)
  • Norway (EEA) and USA: TikTok โ€” EEA or Standard Contractual Clauses; access from China cannot be ruled out as of today

๐ŸŒ How we protect your data in the process

Within the EU and the EEA, the same level of data protection applies as here โ€” no additional measures are necessary there. For transfers to the USA, we rely on two foundations simultaneously:

  • the EU-US Data Privacy Framework or the Swiss-US Data Privacy Framework, provided the provider is certified there. For the EU, this is based on an adequacy decision by the EU Commission dated July 10, 2023; for Switzerland, on a decision by the Federal Council dated August 14, 2024;
  • additionally, the Standard Contractual Clauses โ€” for the EU, those of the EU Commission; for Switzerland, the version recognized by the FDPIC.

We deliberately conclude the Standard Contractual Clauses additionally because the legal situation regarding adequacy decisions can change. This ensures your data remains protected even if a basis is removed.

In addition, technical and organizational measures such as encryption and strict access restrictions are in place.

11. Security

๐Ÿ” Technical & Organizational Measures

We protect your data with technical and organizational measures against loss, misuse, and unauthorized access (Art. 32 GDPR, Art. 8 revDSG). These include:

  • encrypted connections (SSL/TLS), recognizable by the “https://” in the address bar
  • access restrictions to our systems
  • regular security and software updates
  • secure password policies and internal two-factor authentication
  • careful selection and monitoring of our service providers
  • regular backup copies

๐Ÿ›ก๏ธ What you should know

No digital system is completely secure. Even with careful measures, a residual risk remains when transmitting data over the internet. We work to keep it as small as possible โ€“ and react immediately if there is cause for concern. If you notice anything, please contact us. We take every hint seriously.

12. Legal Bases for Data Processing & Scope

This privacy policy is based on the General Data Protection Regulation (GDPR) and the Swiss Data Protection Act (revDSG). For access to your device, depending on the country, the German TDDDG, the Austrian TKG 2021, and the Swiss Telecommunications Act also apply; for the use of AI, the EU AI Regulation.

Our data processing is based on the respective applicable legal bases. Depending on the country from which you access our services, different legal norms apply.

๐Ÿ‡จ๐Ÿ‡ญSwitzerland

We process personal data lawfully, in good faith, and proportionately (Art. 6 para. 1 and 2 revDSG), for a purpose recognizable to you (Art. 6 para. 3 revDSG). We destroy or anonymize data as soon as it is no longer necessary for the purpose (Art. 6 para. 4 revDSG), and protect it through appropriate measures (Art. 8 revDSG).

Where we need your consent, we obtain it voluntarily and after providing appropriate information (Art. 6 para. 6 revDSG). We will explicitly ask you if we process particularly sensitive personal data โ€” this includes information about religious views and activities (Art. 5 lit. c no. 1 revDSG, Art. 6 para. 7 lit. a revDSG). This is the case, for example, with a donation or if you entrust us with something personal. In these cases, we ask you explicitly in the form.

For analysis and marketing on this website, we follow the path provided by Art. 45c lit. b TCA for Switzerland: we inform you and you can object at any time. How this works in detail is described in the section “Use of Cookies & Tracking Technologies.”

If we disclose personal data abroad, we rely on an adequacy decision by the Federal Council (Art. 16 para. 1 revDSG) or on standard data protection clauses recognized by the FDPIC (Art. 16 para. 2 lit. d revDSG).

๐Ÿ‡ช๐Ÿ‡บ European Union

For processing subject to the GDPR, we rely on the legal bases of Art. 6 para. 1 GDPR โ€” depending on the processing, on your consent, the fulfillment of a contract, a legal obligation, or a legitimate interest. If special categories of personal data are involved โ€” for example, in the case of donations or if you entrust us with personal matters โ€” Art. 9 para. 2 GDPR is also applied. Which basis applies in each individual case is always stated directly with the respective processing.

If you access our services from another country, additional rights may apply there. In that case, please feel free to contact us โ€“ we will look into it.

13. Contact for data protection matters

If you have any questions about data protection or would like to exercise your rights (e.g., access, deletion, withdrawal of consent), feel free to contact us.

Contact:
ICF Munich e. V.
Felix Hiesinger
ArnulfstraรŸe 34
80335 Munich
Germany
[email protected]

Weโ€™ll get back to you as quickly as possible โ€” more on this under “How quickly we respond”

14. Changes

We review this privacy policy at least every six months and adapt it if legal requirements (e.g., new laws, court rulings, or changes in the revDSG, the GDPR, or the EU AI Act) or the tools we use change. You can always find the current version here on our website.

Last update: Version 2.0 โ€” 2026-09-13