Data protection
Protecting your data matters to us. We handle personal data responsibly and comply with applicable data protection laws, in particular the EU General Data Protection Regulation (GDPR).
CONTENTS
1. Introduction & Responsible Entity
🏢 Responsible for content & data
🖥️ Technical Operation of the Website
🤝 Responsibilities
📮 Contact Person for Data Protection
🌎 Who is the ICF Movement?
📖 How this policy is structured
2. Principles of Data Processing
✅ Transparency
🎯 Purpose Limitation
➖ Data Minimization
🔐 Security
🕐 Storage Limitation
🌍 Lawfulness
3. Collection & Use of Personal Data
📬 Contact & Forms
🙏 When you entrust us with personal matters
💌 Newsletter & communication
💳 Donations
📈 Server logs & tracking data
4. Use of Cookies & Tracking Technologies
🍪 What are cookies?
🍪 Consent management (CookieHub)
⚙️ When we need your consent
5. Tools & Third-Party Providers Used
📈 Analytics and performance tools
📋 Forms, Newsletters & Communication
🎥 Media embeds
🛡️ Technical Operation and Security
🤖 AI-powered chat & support
✍️ AI-generated Content
🧠 No automated decisions about you
📋 Our framework
📋 Right of access
✏️ Right to rectification
❌ Right to erasure
🧯 Right to restriction
🚫 Right to object
📤 Right to data portability
🛑 Right to withdraw consent
🧑⚖️ Right to lodge a complaint with a supervisory authority
⏱️ How quickly we respond
8. Data Transfer & Processing on our Behalf
🤝 Joint responsibility
🤝 Working with service providers (data processing on behalf / processor arrangement)
💾 And what about backups?
10. International Data Transfer
🌍 How we protect your data in the process
🔐 Technical & organizational measures
🛡️ What you should know
12. Legal Bases for Data Processing & Scope
🇨🇭Switzerland
🇪🇺 European Union
13. Contact for data protection matters
14. Changes
1. Introduction & Responsible Entity
For us, data protection isn’t just a legal box-ticking exercise—it’s an expression of responsibility. As the ICF Movement, we are committed to ensuring your data is handled with care and respect.
This privacy policy informs you about which personal data we process on our website, for what purpose we do so, and what rights you have in this context.
This privacy policy applies to the domain https://icf.church/muenchen in all language versions, as well as to all of the following legal entities and to future companies operating under the ICF (International Christian Fellowship) brand or in which one of the listed Organizations is involved.
- ICF Munich
- ICF Freising
- ICF Augsburg
- ICF Passau
- ICF Starnberg
- Micro Churches connected with ICF Munich
Where this privacy policy refers to “ICF” or “we,” this means—depending on the context—one or more of these Organizations.
🏢 Responsible for content & data
Responsible in the sense of Art. 4 No. 7 GDPR and Art. 5 lit. j revDSG for the content, forms, and Events on these pages is:
ICF Munich e. V.
Arnulfstraße 34
80335 Munich
Germany
[email protected]
🖥️ Technical Operation of the Website
The technical platform, hosting, and security of this website are the responsibility of:
ICF Movement
Zürichstrasse 131
8600 Dübendorf
Switzerland
[email protected]
🤝 Responsibilities
The ICF Location mentioned above is responsible for the content, forms, and Events on these pages. The ICF Movement is responsible for the platform, hosting, and security. The Location does not have a say in this. For analyzing website usage and measuring campaigns, the ICF Movement and the Location jointly decide on purposes and means. To that extent, they are joint controllers under Art. 26 GDPR.
The essence of the agreement according to Art. 26 GDPR: The ICF Movement fulfills the information obligations via this declaration, operates the technical systems, and answers inquiries regarding analysis and campaign data. The ICF Location answers inquiries regarding content, forms, and Events. You can assert your rights with both – we will forward your request internally so you only have to contact us once.
📮 Contact Person for Data Protection
Felix Hiesinger, Data Protection Officer, [email protected]
🌎 Who is the ICF Movement?
ICF is a Christian church based on biblical principles.
We were born out of a dream to make church dynamic, relevant to everyday life, and contemporary for people.
The ICF Movement is an organization that supports church planting primarily in Europe and, in some cases, in the rest of the world, with the goal of helping people become more like Jesus Christ, live fearlessly, and positively impact their environment. We see planting new churches as a mission mandate that is a core part of our DNA.
In addition to planting ICF Churches, the ICF Movement is committed to renewing and strengthening the existing church landscape in Europe and beyond. To this end, resources, conferences, programs (ICF College), leadership, and coaching are offered.
Together, we believe that Europe and the world can be awakened through healthy, socially relevant local churches. It is our deepest conviction that the local church is the hope of the world!
Learn more at https://icf.church/movement/
📖 How this policy is structured
For each type of processing, you’ll find what we use data for, the legal basis, and how long we store it. An overview of all legal bases can be found in the section “Legal bases for data processing & scope.”
Do you have to provide us with data?
No. The information in our forms is voluntary. However, without the information marked as required fields, we cannot process your request (Art. 13(2)(e) GDPR).
2. Principles of Data Processing
We process personal data with a clear purpose and only to the extent necessary for that purpose. We adhere to these principles:
✅ Transparency
We want you to be able to understand what happens with your data at any time. That’s why we openly describe in this statement which tools we use and why.
🎯 Purpose Limitation
We collect and use personal data for the respective intended purpose – e.g., for contacting us, newsletter registration, website usage analysis, or processing donations.
➖ Data Minimization
We only collect & process the data necessary to handle your request. If anonymous or pseudonymous use is possible, we implement it.
🔐 Security
We protect your data with technical and organizational measures — details are provided further below in the dedicated section “Security.”
🕐 Storage Limitation
We store personal data for as long as it is needed for the respective purpose or as required by legal retention obligations.
🌍 Lawfulness
Every processing is based on a legal ground: your consent, the fulfillment of a contract, a legal obligation, or a legitimate interest. Which one applies is stated for each individual processing activity.
3. Collection & Use of Personal Data
We collect personal data when you actively submit it to us or when it is technically necessary – e.g., via a form, your IP address when a page is accessed, when donating, or when using our website. Here you can find out in which situations this happens and how we use this data:
📬 Contact & Forms
If you write to us via a form or register for an event, we process the information you enter—typically your name, email address, and your request—in order to respond to you or provide the service.
Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) or legitimate interest in responding to your inquiry (Art. 6(1)(f) GDPR)
📸 Photos, videos & audio recordings at events
At our events—for example, celebrations, camps, seminars, workshops, or hangouts—we take photos, video recordings, and audio recordings. These events are generally open to the public; we inform you about recordings in advance (e.g., during registration) and on site.
We use these recordings to document and share our work—for example in annual and activity reports, on our website, on social media, and in print media (flyers, brochures). We only share them with third parties where they are service providers commissioned by us (e.g., agencies, print shops) who process the data on our behalf.
We handle recordings with care and ensure that the legitimate interests of people depicted are not violated. If you are affected for particularly compelling reasons, please contact us—we will then review appropriate measures.
Legal basis: Legitimate interest in public relations and documenting our activities (Art. 6(1)(f) GDPR)
Your right to object:
You can object to the processing of your image at any time without formalities (Art. 21(1) GDPR), for example by email ([email protected]). We will review your objection and stop further publication to the extent technically possible. We cannot recall printed materials that have already been distributed.
🧒 Photos & data of children and young people
For Events for children and young people—e.g., ICF Kids, camps, or youth events—we sometimes process data of minors, for example during registration or for photo and video recordings.
For those under 16, we obtain the consent of the legal guardians before publishing photos or videos in which the child is identifiable (Art. 8 GDPR). For registration forms for children’s and youth Events, we point this out separately and explicitly ask the legal guardians.
Legal basis: Consent of the legal guardians (Art. 6(1)(a) in conjunction with Art. 8 GDPR)
🙏 When you entrust us with personal matters
Some people write to us about a prayer request, a crisis, or a question they wouldn’t ask anyone else. That matters to us, and we handle such messages differently from a normal inquiry:
- They are only read by the people responsible for them
- They do not flow into our CRM or marketing analyses.
- We only store them for as long as support is needed, and delete them afterwards.
Such information may include specially protected data—for example about your health or your faith. We process it only because you deliberately share it with us, and we rely on your explicit consent (Art. 9(2)(a) GDPR, Art. 6(7)(a) revFADP).
💌 Newsletter & communication
If you sign up for our newsletter, we store your email address,
your name (if provided) and your language setting, so we can regularly send you
inspiration, updates, and information about Events.
You can unsubscribe from the newsletter at any time via the unsubscribe link in every email. After you unsubscribe, we only keep your address on a suppression list so you don’t receive any further emails.
Legal basis: Consent (Art. 6(1)(a) GDPR, Art. 6(6) revFADP); for proof of registration, legal obligation and legitimate interest (Art. 6(1)(c) and (f) GDPR)
💳 Donations
You can make donations to ICF Munich directly via a form on this website. Payment processing is handled by the following external payment service providers:
- Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland)
If you choose to pay via Stripe, the payment data you enter will be transmitted to Stripe.
Your data is transmitted to Stripe on the basis of Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (processing to perform a contract). You can withdraw your consent to data processing at any time. A withdrawal does not affect the lawfulness of processing operations carried out in the past. All data required for payment processing is used exclusively to carry out the payments and is transmitted via the “SSL” procedure. Stripe is PCI DSS certified. Stripe may transfer, process, and store personal data outside the EU. Stripe is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply.
They process your payment data and check whether a payment is fraudulent. They use their own cookies for this. Your card details are processed exclusively there—we do not see or store them.
We process the remaining details—name, email address, amount, and payment method—to process your donation, send you a confirmation, and record it properly. We are legally required to retain the related receipts; how long is stated below under “Retention period.”
A donation to a church says something about your faith. Such information is specially protected (Art. 9 GDPR, Art. 5 lit. c no. 1 revDSG). That’s why we explicitly ask in the donation form whether you agree—including that our payment service provider and our donation administration process this information. Without this consent, we cannot accept a donation via this website.
And what if you withdraw your consent?
You can do that at any time. From then on, we won’t use your donation data for anything else: no thank-you letters, no analyses, no donation history. What we are not allowed to delete are the booking receipts themselves—they are subject to statutory retention obligations. Instead, we restrict them: they remain stored until the above period expires, but are only used if an authority needs to see them. After that, we delete them.
Legal basis: Processing your donation: performance of a contract (Art. 6(1)(b) GDPR); in Switzerland, our overriding interest in processing the contract (Art. 31(2)(a) revDSG). Retaining receipts: legal obligation (Art. 6(1)(c) GDPR); in Switzerland, statutory justification (Art. 31(1) revDSG). Information that reveals your faith, and sharing it with our service providers: your explicit consent (Art. 9(2)(a) GDPR, Art. 6(7)(a) revDSG). Your withdrawal applies going forward (Art. 7(3) GDPR); it does not override statutory retention obligations (Art. 17(3)(b) GDPR).
Retention period: In Switzerland, 10 years (Art. 958f CO); in Germany, 8 years for booking receipts and 10 years for annual financial statements (§ 147 AO).
📈 Server logs & tracking data
As soon as you visit our website, we automatically process technical information. We distinguish between two levels—the difference is important:
Server logs (always, even without consent):
Our hosting logs every visit with the full IP address, date and time, requested URL, referrer, and user agent. Without this, we can neither operate the website nor protect it from attacks.
Legal basis: Legitimate interest in provision and IT security (Art. 6(1)(f) GDPR)
Traffic analysis (only with your consent):
If you have consented, we also measure which pages are accessed, how long visits last, and how someone finds us. Your IP address is truncated before it is stored.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
4. Use of Cookies & Tracking Technologies
Our website uses cookies and similar technologies. Some are necessary for operating the site; we only use all others if you have consented.
🍪 What are cookies?
Cookies are small text files that your browser stores on your device. Comparable technologies such as local storage or pixels work similarly. They help us to
- operate the website technically,
- understand how it is used,
- and evaluate campaigns.
🍪 Consent management (CookieHub)
CookieHub — CookieHub ehf., Reykjanesbær, Iceland (EEA)
We log the time of your decision, the categories selected, technical information about your browser, and a random identifier that allows your decision to be retrieved—this is required as proof under Art. 7(1) GDPR.
Legal basis: Legal obligation and legitimate interest (Art. 6(1)(c) and (f) GDPR)
Retention period: 12 months
⚙️ When we need your consent
For cookies that are not necessary to operate the website—i.e., statistics, marketing, and embedded content—we need a legal basis. Which one applies depends on which country you are coming from:
- Germany: § 25(1) TDDDG. Legitimate interest is explicitly not sufficient here for access to your device.
- Austria: § 165(3) TKG 2021. The same applies here: your consent must be actively given—scrolling on or a pre-ticked box is not enough.
- Switzerland: For access to your device, Art. 45c lit. b TCA applies. It requires us to inform you about the processing and its purpose and to point out that you can refuse it. If you are coming from Switzerland or Liechtenstein, we implement this as follows: our banner informs you on your first visit and you can reject each category. Until you reject, analytics and marketing cookies are active—this is the opt-out model permitted in Switzerland. Your rejection takes effect immediately and applies to all future visits. If you are coming from the EU or the EEA, we obtain your consent beforehand: without your active “yes,” nothing that isn’t technically necessary will be loaded. In both cases, “Accept” and “Reject” are equally easy to access.
Our cookie categories:
- Essential — indispensable for technical operation. This includes storing your cookie decision, your language selection, search on our website, securing our forms, and protection against attacks. Without consent.
- Functional — remembers settings that make it easier for you to use the site and runs our support chat. Only with consent.
- Analytics — measures how our website is used. Only with consent.
- Marketing — measures our campaigns, enables advertising, and loads embedded third-party content: maps, videos, podcasts, and our radio. This content comes from providers who also evaluate it for their own advertising purposes—this is why it falls into this category. Only with consent.
- Other cookies — cookies we have not yet been able to assign to a category. They are treated like non-essential cookies and are only set with your consent.
5. Tools & Third-Party Providers Used
We use selected third-party providers to make our website user-friendly, secure, and modern. Below, we explain which tools we use, which data is processed, and why.
📈 Analytics and performance tools
Google Analytics—Google Ireland Limited, Dublin, Ireland
Shows us how our website is used: which pages are accessed, how long visits last, and how someone gets to us. We also measure which forms are opened and submitted—this shows us where people drop off while filling them out. The content of your entries is not transmitted.
The data is pseudonymous: it is not assigned to a person by name, but can be assigned to a device via a random identifier (client ID). Your IP address is shortened before it is stored.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
Retention period: 14 months
Third country: USA, Google LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Google Tag Manager — Google Ireland Limited, Dublin, Ireland
Tag Manager is the tool we use to control which analytics and marketing services are loaded. It doesn’t analyze anything itself, but when the container is loaded, your IP address is transmitted to Google—that’s why we only load it once you have consented.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
Retention period: 25 months
Third country: USA, Google LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Meta Pixel — Meta Platforms Ireland Limited, Dublin, Ireland
Measures our campaigns on Facebook and Instagram and enables us to show you relevant content there. Meta processes the data for its own purposes as well and is jointly responsible with us—see the section “Joint controllership” for more.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); in Switzerland, additionally explicit consent under Art. 6(7)(b) revDSG
Retention period: The cookies on your device expire 13 months after last use. How long Meta stores the transmitted data on its own systems is determined by Meta—see Meta’s privacy policy for details.
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework (if and as long as the provider is certified); Standard Contractual Clauses also apply
TikTok Pixel — TikTok Technology Limited, Dublin, Ireland
Measures whether our campaigns on TikTok are effective—i.e., whether someone does something with us after clicking an ad. For this purpose, your visit to our website is transmitted to TikTok and linked there to your TikTok account or your device. TikTok also uses this data for its own purposes, including ad delivery. That’s why we are jointly responsible with TikTok (Art. 26 GDPR)—see the section “Joint controllership” for more.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); in Switzerland, additionally explicit consent under Art. 6(7)(b) revDSG
Retention period: The cookies on your device expire 13 months after last use. How long TikTok stores the transmitted data on its own systems is determined by TikTok—see TikTok’s privacy policy for details.
Third country: According to TikTok, it stores data from the European Economic Area in data centers in Norway, Ireland, and the USA. Access from China, where the parent company ByteDance is based, cannot be ruled out based on current information. For transfers outside the EEA, TikTok relies on Standard Contractual Clauses.
Google Ads — Google Ireland Limited, Dublin, Ireland
Measures whether our advertising is effective—i.e., whether someone does something with us after clicking an ad. This creates pseudonymous profiles of your behavior on our website.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
Retention period: 3 years
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Microsoft Clarity — Microsoft Ireland Operations Limited, Dublin, Ireland & Microsoft Corporation, USA
Clarity helps us see where people get stuck on our website. To do this, Clarity records sessions: mouse movements, scrolling, clicks, and page changes are stored as a playable recording and summarized into heatmaps. Entries in form fields are masked. This data is pseudonymous, not anonymous. Microsoft sets an identifier that applies not only to Clarity but to Microsoft services in general—including Microsoft’s advertising network. That’s why we don’t treat Clarity as a purely analytics tool and explicitly point this out here.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR, § 25 para. 1 TDDDG)
Storage period: 9 months
Third country: USA, certified for the EU-US and Swiss-US Data Privacy Framework; Standard Contractual Clauses also apply
📋 Forms, Newsletters & Communication
Gravity Forms
Our forms run via Gravity Forms. The data is initially stored in our own database. Depending on the form, we forward it to the following recipients:
- Salesforce (Salesforce, Inc., USA) — our CRM and Marketing Cloud Account Engagement
- Google Sheets (Google Ireland Limited) — so our team can evaluate registrations together
- Zapier (Zapier Inc., USA) — connects forms with other systems; the data passes through Zapier’s systems
- Google Places (Google Ireland Limited)— suggests addresses as you type. Your input is transmitted to Google while you are typing, not only when you submit
The technical transfer to these recipients happens directly from our server. We use extensions for this (Gravity Forms Webhooks, Gravity Wiz API Alchemist) that do not store any data themselves and do not receive a copy.
Email verification: To make sure confirmations actually reach you, we check when you submit whether the address entered is deliverable. For this, your email address is transmitted to ZeroBounce (ZeroBounce, USA) and verified there.
Legal basis: Legitimate interest in deliverable confirmations (Art. 6(1)(f) GDPR)
Retention period: Zapier (69 days), ZeroBounce (30 days), Gravity Forms (30 days), Salesforce (until withdrawal)
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
MailGun — Mailgun Technologies, Inc. (Sinch Group) Ensures our emails are delivered reliably from a technical standpoint—confirmations, notifications, newsletters. We send form confirmations and system emails via MailGun.
Before an email is sent there, it passes through a sending component on our own server. This records who received which email and when, and whether it could be delivered. We need this to be able to trace delivery issues. MailGun also logs sending on its side.
Legal basis: Performance of a contract and legitimate interest in reliable delivery (Art. 6(1)(b) and (f) GDPR)
Retention period: 30 days
Third country: USA, certified under the EU-U.S. Data Privacy Framework, but not under the Swiss-U.S. Data Privacy Framework. For disclosures from Switzerland, we rely on the Standard Data Protection Clauses recognized by the FDPIC.
Google reCAPTCHA— Google Ireland Limited, Ireland & Google LLC, USAProtects our forms from automated attacks. For this purpose, Google evaluates, among other things, your IP address, how long you stay on the page, and your mouse movements to determine whether you are a human. The protection is loaded when you access pages with forms.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
Third country: USA, Google LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Fillout — Fillout Inc., USA
For certain forms—for example event registrations or surveys—we use Fillout. From some pages, you are redirected directly there, or you see the form embedded directly on the page.
Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Retention period: Until revoked
Third country: USA, Fillout Inc. is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses—for Switzerland, the version recognized by the FDPIC.
Marketing Cloud Engagement (Pardot) — Salesforce, Inc.We use this platform to send our newsletter. In doing so, we measure whether and when you open an email and which links you click. This information creates an interest profile that helps us send you more relevant content. We only do this if you have consented.
Legal basis: Consent (Art. 6(1)(a) GDPR)
Retention period: until you unsubscribe, if that was the only purpose
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Elvanto — Elvanto Pty Ltd, Australia (EU server location: Ireland and Frankfurt)
Elvanto is our personal data system (CRM). Among other things, we manage registrations for events and groups, as well as contact details of members and interested parties.
Legal basis: Performance of a contract or legitimate interest in managing our Events (Art. 6(1)(b) and (f) GDPR)
Retention period: until revoked
Third country: The data is stored on servers in the EU (Ireland, Frankfurt). Since Elvanto Pty Ltd is based in Australia, access from a third country cannot be completely ruled out; we rely on Standard Contractual Clauses for this.
Billetto — Billetto ApS, Copenhagen, Denmark (EU)
For ticketing for certain events, we sometimes use Billetto. If you book tickets via our website, you will be redirected to Billetto’s website; their own privacy policy also applies there. We also transmit the data you enter to ICF Munich e. V. for processing to enable your participation in the event, and store it in Elvanto.
Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Retention period: until statutory retention obligations expire after the event
Third country: Billetto is a company based in the EU; according to its own information, data may in individual cases also be processed outside the EU.
Freshdesk — Freshworks Inc., San Mateo, California, USA (stored on servers in the EU)
We use the Freshdesk ticketing system to handle support and contact inquiries. If you contact us, your details—e.g., name, email address, and the content of your inquiry—are stored in the ticketing system so we can track and respond to your request.
Legal basis: Performance of a contract or pre-contractual measures, or legitimate interest in efficiently handling your inquiries (Art. 6(1)(b) or (f) GDPR)
Retention period: until revoked
Third country: Your Freshdesk data is stored on servers in the EU. Since Freshworks Inc., as the parent company, is based in the USA, access from a third country cannot be completely ruled out. Freshworks is certified under the EU-U.S. Data Privacy Framework and also concludes Standard Contractual Clauses via its own data processing agreement Freshworks is also ISO 27001 and SOC 2 certified.
🎥 Media embeds
YouTube — Google Ireland Limited & Vimeo Vimeo.com, Inc., USA
We embed videos. Videos only load once you’ve given consent. After that, the respective provider receives your IP address and can set cookies; if you’re logged in there, they can associate the video view with your account.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Spotify — Spotify AB, SwedenFor embedded podcasts and audio content—under the same conditions as above.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
Google Maps — Google Ireland Limited, Dublin, Ireland
Shows you where to find us. As soon as a map is loaded, your browser transmits your IP address to Google, and Google can set cookies. If you are logged in to Google, Google can associate the map view with your account. That’s why we only load maps once you have consented.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
Retention period: 12 MONTHS
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
ICF Radio — SAM Cloud and Triton Digital, USAOur radio player retrieves the program and live stream from two external services. The player only starts once you’ve given consent. After that, your device establishes a direct connection to the streaming provider; your IP address and technical information about your device are transmitted.
Legal basis: Consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG)
Third country: USA, Triton Digital is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses—for Switzerland, the version recognized by the FDPIC.
🛡️ Technical Operation and Security
DigitalOcean — DigitalOcean LLC, USA (server region Frankfurt)
Operates the servers on which this website (main installation) runs, as well as the regular backup of our systems via the Snapshooter tool. Backups also contain personal data and are automatically overwritten.
Legal basis: Legitimate interest in failover reliability and legal obligations (Art. 6(1)(f) and (c) GDPR)
Third country: USA, DigitalOcean LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Cloudflare — Cloudflare, Inc., USA
Delivers our website faster and protects it from attacks. Every request to our website goes through Cloudflare; in the process, IP address, requested URL, and browser data are processed.
In addition, Cloudflare measures in your browser how quickly our pages load (“Browser Insights”). Technical information about your device and the page accessed is transmitted. We use this exclusively to find slow pages—no profile about you is created.
Legal basis: Legitimate interest in availability and IT security (Art. 6(1)(f) GDPR)
Retention period: 7 days (logs), 30 days (analytics)
Third country: USA, certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Wordfence — Defiant, Inc., USA
Detects and blocks attacks on our website. For this purpose, IP addresses, access patterns, and failed login attempts are analyzed and in some cases transmitted to Wordfence.
Legal basis: Legitimate interest in IT security (Art. 6(1)(f) GDPR)
Retention period: 20 days (logs)
Third country: USA, Defiant, Inc. is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses—for Switzerland, the version recognized by the FDPIC.
Sentry — Functional Software, Inc., USA — (server region EU)
Reports technical errors to us so we can fix them. Error reports may contain IP addresses, accessed URLs including parameters, and browser data—i.e., information that may relate to you.
Legal basis: Legitimate interest in a functioning website (Art. 6(1)(f) GDPR)
Retention period: 90 days
Third country: We use Sentry’s EU region—error reports are stored in Frankfurt and do not leave the EU during normal operations. Administration of our Sentry account runs via systems in the USA, so access from there cannot be completely ruled out. Functional Software, Inc. (Sentry) is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework; Standard Contractual Clauses also apply
Pulsetic — Designmodo, Inc., USA
Regularly accesses our website from the outside to check whether it is reachable. These requests come from Pulsetic itself, not from you—no data about you is generated.
Legal basis: Legitimate interest in availability (Art. 6(1)(f) GDPR)
Retention period: 5 years
Third country: USA, Designmodo, Inc. is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses—for Switzerland, the version recognized by the FDPIC.
ShortPixel — ID SCOUT SRL, Bucharest, Romania
Reduces the size of image files on our website so pages load faster. Our server transfers the images to ShortPixel and plays back the optimized version — your browser has no contact with ShortPixel, your IP address is not transmitted. Additionally, we have image descriptions (alt texts) automatically generated with AI so our content is accessible with a screen reader. For this, our server passes the image to ShortPixel, which uses an AI service — currently OpenAI or Anthropic, both in the USA. This also applies to images showing people. These are exclusively images we publish on this website anyway. We use the result only as an image description.
Legal basis: Legitimate interest in a fast and accessible website (Art. 6(1)(f) GDPR)
Retention period: The images are deleted from ShortPixel’s servers after optimization (according to the provider, within about 30 minutes).
Third country: USA. Neither OpenAI nor Anthropic is certified under the Data Privacy Framework. ShortPixel bases the transfer on Standard Contractual Clauses (Module 3, processor to sub-processor)—for Switzerland, the version recognized by the FDPIC.
Imgix — Zebrafish Labs, Inc, USA
Delivers images in the right size and quality so pages load quickly. Your browser loads these images directly from Imgix—your IP address, your browser, and the page accessed are transmitted. When cropping, Imgix automatically detects where faces are in an image so the crop is correct—no person is identified.
Legal basis: Legitimate interest in a fast website (Art. 6(1)(f) GDPR)
Third country: USA, Zebrafish Labs, Inc. is not certified under the Data Privacy Framework. The transfer is based on Standard Contractual Clauses—for Switzerland, the version recognized by the FDPIC.
WPML — OnTheGoSystems Limited, Hong Kong
Language selection (local function on our server): Our content is available in multiple languages. We store the language you selected in a technically necessary cookie on your device. Translation management runs entirely on our own server—no data about you is transmitted to the manufacturer or other third parties.
Legal basis: Legitimate interest in a functioning website (Art. 6(1)(f) GDPR); for storage on your device, technical necessity (§ 25(2) no. 2 TDDDG)
Algolia — Algolia SAS, France (server region EU)
Operates the search on our website. Your search query runs through a cache in our own infrastructure and from there to Algolia — your IP address typically does not reach Algolia. Only if this cache fails does your browser query Algolia directly; then search term and IP address are transmitted. We know: What people search for on a church website can be very personal. We therefore only analyze search queries in aggregate to improve the search — we do not associate them with any person and do not link them to other data about you.
Legal basis: Legitimate interest in a functioning search (Art. 6(1)(f) GDPR)
Retention period: 90 days
Third country: Our search data is stored in Algolia’s EU region. According to Algolia, logs of individual search queries may also be processed outside the EU; Standard Contractual Clauses apply—for Switzerland, the version recognized by the FDPIC.
MainWP (central website management) — YellowTree GmbH, Germany
Our websites are managed centrally from a dashboard—for updates, security checks, and backups. This dashboard is operated by YellowTree GmbH, our technical service provider, on its own infrastructure. The software manufacturer does not receive any content from our website.
This connection is an administrative access. In principle, it can reach everything that can also be reached via the website administration itself—including form entries. YellowTree uses it exclusively on our behalf for maintenance and security; the details are governed by a data processing agreement.
Legal basis: Legitimate interest in the secure and up-to-date operation of our websites (Art. 6 para. 1 lit. f GDPR)
ICF Hub — operated by ICF Movement, technical platform: Xano, Inc., USAEvents, celebrations, and organizational data such as address, social media links, and contact information come to this website from ICF Hub via an interface. Without this connection, the core functions of the site would not work. This query runs through our server, not through your browser — your IP address is not transmitted. When contact details of individuals are published — such as contact persons for a location — these come from our internal administration. We inform the affected individuals separately in accordance with Art. 14 GDPR
Legal basis: Legitimate interest in the presentation of our Events (Art. 6 para. 1 lit. f GDPR)
Third country: USA, Xano, Inc. is certified for the EU-US Data Privacy Framework, but not for the Swiss-US Data Privacy Framework. For disclosures from Switzerland, we rely on the standard data protection clauses recognized by the FDPIC.
Hetzner — Hetzner Online GmbH, Gunzenhausen, Germany
For hosting domains and individual web installations, we use the infrastructure of Hetzner Online GmbH. When accessing and operating these websites, technical connection data (e.g., IP address, server log files) is processed on Hetzner’s servers.
Legal basis: Legitimate interest in a secure, stable, and technically flawless operation of our web offerings (Art. 6 para. 1 lit. f GDPR).
Storage period: Server log files are automatically deleted or anonymized after 7 to 14 days.
Strato — STRATO AG, Berlin, Germany
We operate a virtual server environment (VM) at STRATO AG, on which our internal accounting and billing software runs. In this context, personal and financial data (master and contact data, invoice and payment data, as well as booking receipts from members, donations, and services) are processed.
Legal basis: Fulfillment of contract and implementation of pre-contractual measures (Art. 6 para. 1 lit. b GDPR), fulfillment of legal and tax obligations (Art. 6 para. 1 lit. c GDPR in conjunction with § 147 AO), and our legitimate interest in proper financial and association administration (Art. 6 para. 1 lit. f GDPR).
Storage period: Data is stored in accordance with statutory commercial and tax retention periods (in Germany, 8 to 10 years according to § 147 AO / § 257 HGB).
6. Use of AI
In some places, Artificial Intelligence (AI) helps us to assist you faster. We use it deliberately and in a limited way — and you should be able to tell at any time whether you are speaking with a machine or a human.
🤖 AI-powered Chat & Support
Gleap — Gleap GmbH, Austria
An AI-powered chat assistant may be integrated into our website to help you with questions and suggest relevant help articles. It runs via our support platform Gleap and uses an AI model for this purpose.
Gleap is also our support platform outside of AI chat: for help articles, user feedback, and targeted hints in the widget. For the widget to start at all, Gleap stores a basic technical configuration in your browser. Everything else — the chat session itself and your messages — only happens once you’ve given consent.
The assistant identifies itself as AI upon first contact. Art. 50 para. 1 of the EU AI Act requires this from providers of such systems — we believe it is the right thing to do anyway and pay attention to this when selecting tools. You can request to speak with a person from our team at any time.
When you use the chat, we process your messages and technical metadata to respond to you. Please do not enter any particularly sensitive information in the chat.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR, § 25 para. 1 TDDDG) · Storage period: 14 months
Third country: Gleap in Austria; Transfer to various AI providers
✍️ AI-generated Content
Where we create or process texts, images, or subtitles with AI, we review them editorially. Image, audio, and video content that appears real but is AI-generated or AI-altered is visibly labeled. This is required of us as operators by Art. 50 para. 4 of the EU AI Regulation.
For texts, this obligation does not apply to us because we editorially review every published text and take responsibility for it. Nevertheless, we voluntarily indicate where AI played a significant role in the result – we believe this is appropriate.
🧠 No automated decisions about you
We do not make decisions with legal or similarly significant effects exclusively through automated means (Art. 22 GDPR). According to Art. 21 revDSG, we would also inform you if this were ever the case. AI helps us with phrasing, sorting, and answering — decisions that affect you are made by humans.
📋 Our Framework
We do not enter personal data into systems that are not approved for it, we train our employees in handling AI (Art. 4 EU AI Act), and we check every system before use.
7. Your Rights
The protection of your personal data is important to us. You have the right to know what happens to your data, and we show you transparently what options are available to you. Here is an overview of your rights:
📋 Right of Access
You can find out at any time whether and which personal data we process about you — and request a copy of it (Art. 15 GDPR, Art. 25 revDSG).
✏️ Right to Rectification
If something is no longer correct, you can request the correction of your data (Art. 16 GDPR, Art. 32 para. 1 revDSG).
❌ Right to Erasure
You have the right to have your data deleted — for example, if it is no longer needed for the original purpose or if you have withdrawn your consent (Art. 17 GDPR). In Switzerland, we destroy or anonymize personal data as soon as it is no longer necessary for the purpose (Art. 6 para. 4 revDSG); furthermore, you can request erasure through the courts (Art. 32 para. 2 lit. c revDSG). Where we are legally required to retain data — such as for donation receipts — we restrict processing instead of deleting it.
🧯 Right to Restriction of Processing
You can request that we process your data only to a limited extent – e.g., during a review or in the event of an objection (Art. 18 GDPR).
🚫 Right to Object
You can object to advertising at any time and without giving reasons — we will then no longer process your data for this purpose (Art. 21 para. 2 and 3 GDPR). A short message to us is sufficient.
Furthermore, you can object to the processing of your data for reasons arising from your particular situation — especially for processing based on a legitimate interest (Art. 21 para. 1 GDPR).
📤 Right to Data Portability
You have the right to receive data that we process automatically on the basis of your consent or for the performance of a contract in a common format and – if technically feasible – to have it transferred to third parties (Art. 20 GDPR, Art. 28 revDSG).
🛑 Right to Withdraw Consent
If you have given us your consent for specific purposes (e.g., newsletter), you can withdraw it at any time. The withdrawal applies to the future — the fact that we processed your data until then remains lawful (Art. 7 para. 3 GDPR).
🧑⚖️ Right to lodge a complaint with a supervisory authority
If you feel that we are not handling your data correctly, please contact us first — usually, this can be resolved quickly. Regardless of this, you can contact our Clearing Office or a supervisory authority.
In the EU, you have the right to lodge a complaint with the supervisory authority of your place of residence, your workplace, or the place of the alleged infringement (Art. 77 GDPR):
- Germany: State Commissioner for Data Protection and Freedom of Information of the respective federal state
- Austria: Austrian Data Protection Authority, Vienna
- In Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC). He can open an investigation (Art. 49 revDSG).
In Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC). He can open an investigation (Art. 49 revDSG).
⏱️ How quickly we respond
We respond to your request within one month (Art. 12 para. 3 GDPR; in Switzerland Art. 25 para. 7 revDSG). If things get more complicated, we may extend this by up to two months — in which case we will tell you within the first month, providing reasons. To ensure that the request really comes from you, we may need to ask you for proof of identity.
8. Data Transfer & Processing on our Behalf
We generally do not disclose your personal data to third parties, unless it is:
- necessary to fulfill a purpose that you know and want (e.g., donation processing),
- required by law,
- covered by valid consent,
- or takes place within the framework of commissioned processing.
🤝 Joint Controllership
For some services, we don’t decide alone what happens to your data — the provider also uses it for their own purposes. In these cases, we are jointly responsible under Art. 26 GDPR:
- Meta Pixel and our pages on Facebook and Instagram: Meta also evaluates usage data for its own analyses and advertising. We have concluded the intended agreement with Meta. Meta fulfills the information obligations for its own processing, we for the collection on our website.
- YouTube channel and other social media presences: Here, too, we receive statistical evaluations (“Insights”) based on the processing of usage data.
- TikTok Pixel and our TikTok channel: TikTok also evaluates usage data for its own analyses and advertising. We have concluded the intended agreement with TikTok.
You can assert your rights with any of the joint controllers. The providers themselves provide the full text of the agreements; we will send it to you upon request.
🤝 Cooperation with Service Providers (Data Processing)
For technical, administrative, and communicative tasks, we work with selected service providers — for hosting and security, for sending emails, for forms, search, and support. Which ones these are in detail can be found in the section “Tools Used & Third-Party Providers”.
Before we engage a service provider, we review them and conclude the necessary contracts. Where someone processes data on our behalf, this is a data processing agreement under Art. 28 GDPR or Art. 9 revDSG. It stipulates that they only use your data for the agreed purpose and protect it appropriately.
For some services — especially Google, Meta, and Microsoft — the providers also process data for their own purposes. They are then not just processors. Where this is the case, we mention it for the respective service and in the “Joint Controllership” section.
We review this list every six months. If you notice that something is missing or no longer correct here, please write to us — we will correct it.
9. Storage Period
We retain personal data for as long as necessary for the respective purpose – or as long as required by law.
- Server logs: 14 days → IT security and error analysis
- Contact requests: until final processing, thereafter for a maximum of 24 months → follow-up questions and traceability
- Newsletter data: until unsubscription, thereafter only on the blocklist → consent
- Email delivery logs: 12 months → traceability of delivery problems
- Backup copies: 24 months → automatically overwritten thereafter
How long the individual services store data on their own systems is stated directly for each service in the “Tools Used & Third-Party Providers” section.
💾 And what about backups?
If you request erasure, we remove your data from our active systems. In our backup copies, it may still be present for up to 12 months until these are automatically overwritten. We do not restore deleted data from backups.
10. International Data Transfer
Some of our service providers process data outside Switzerland and the EU. According to Art. 19(4) revDSG, we tell you which countries are involved and what we base this on:
- Ireland (EU): Google Ireland, Meta Platforms Ireland, Microsoft Ireland, TikTok Technology Limited — EU/EEA, no additional measures necessary
- Iceland (EEA): CookieHub ehf.
- Austria (EU): Gleap GmbH
- Sweden (EU): Spotify AB
- Romania (EU): ID SCOUT SRL (ShortPixel)
- France (EU): Algolia SAS
- Denmark (EU): Billetto ApS
- Australia (Standard Contractual Clauses; server location EU): > Elvanto Pty Ltd
- USA (Data Privacy Framework and Standard Contractual Clauses):
Google LLC, Meta Platforms Inc., Microsoft Corp., Cloudflare Inc., Vimeo.com Inc., Salesforce Inc., Zapier Inc., DigitalOcean LLC (incl. SnapShooter), ZeroBounce, Stripe LLC, Functional Software Inc. (Sentry), Freshworks Inc. (Freshdesk; data storage on > EU servers) - USA (EU-US DPF; standard data protection clauses recognized by the FDPIC for Switzerland):
Mailgun Technologies Inc., Xano Inc. - USA (Standard Contractual Clauses only, in the version recognized by the FDPIC for Switzerland):
Fillout Inc., Defiant Inc. (Wordfence), Zebrafish Labs Inc. (imgix), Triton Digital, Designmodo Inc. (Pulsetic), OpenAI and Anthropic (AI image descriptions via ShortPixel) - Norway (EEA) and USA: TikTok — EEA or Standard Contractual Clauses; access from China cannot be ruled out as of today
🌍 How we protect your data in the process
Within the EU and the EEA, the same level of data protection applies as here — no additional measures are necessary there. For transfers to the USA, we rely on two bases simultaneously:
- the EU-US Data Privacy Framework or the Swiss-US Data Privacy Framework, provided the provider is certified there. For the EU, this is based on an adequacy decision by the EU Commission of July 10, 2023; for Switzerland, on a decision by the Federal Council of August 14, 2024;
- additionally, the Standard Contractual Clauses — for the EU those of the EU Commission, for Switzerland the version recognized by the FDPIC.
We deliberately conclude the Standard Contractual Clauses additionally because the legal situation regarding adequacy decisions can change. This way, your data remains protected even if one basis ceases to apply.
In addition, there are technical and organizational measures such as encryption and strict access restrictions.
11. Security
🔐 Technical & Organizational Measures
We protect your data with technical and organizational measures against loss, misuse, and unauthorized access (Art. 32 GDPR, Art. 8 revDSG). These include:
- encrypted connections (SSL/TLS), recognizable by the “https://” in the address bar
- access restrictions to our systems
- regular security and software updates
- secure password policies and internal two-factor authentication
- careful selection and monitoring of our service providers
- regular backup copies
🛡️ What you should know
No digital system is completely secure. Even with careful measures, a residual risk remains when transmitting data over the internet. We work to keep it as small as possible – and react immediately if there is cause for concern. If you notice anything, please contact us. We take every hint seriously.
12. Legal Bases for Data Processing & Scope
This privacy policy is based on the General Data Protection Regulation (GDPR) and the Swiss Data Protection Act (revDSG). For access to your end device, the German TDDDG, the Austrian TKG 2021, and the Swiss Telecommunications Act also apply depending on the country; for the use of AI, the EU AI Act applies.
Our data processing is based on the respective applicable legal foundations. Depending on the country in which you access our Events, different legal norms apply.
🇨🇭Switzerland
We process personal data lawfully, in good faith, and proportionately (Art. 6 para. 1 and 2 revDSG), for a purpose recognizable to you (Art. 6 para. 3 revDSG). We destroy or anonymize data as soon as it is no longer necessary for the purpose (Art. 6 para. 4 revDSG), and protect it through appropriate measures (Art. 8 revDSG).
Where we need your consent, we obtain it voluntarily and after providing appropriate information (Art. 6 para. 6 revDSG). We will explicitly ask you if we process particularly sensitive personal data — this includes information about religious views and activities (Art. 5 lit. c no. 1 revDSG, Art. 6 para. 7 lit. a revDSG). This is the case, for example, with a donation or if you entrust us with something personal. In these cases, we ask you explicitly in the form.
For analysis and marketing on this website, we follow the path provided by Art. 45c lit. b TCA for Switzerland: we inform you and you can object at any time. How this works in detail is described in the section “Use of Cookies & Tracking Technologies.”
If we disclose personal data abroad, we rely on an adequacy decision by the Federal Council (Art. 16 para. 1 revDSG) or on standard data protection clauses recognized by the FDPIC (Art. 16 para. 2 lit. d revDSG).
🇪🇺 European Union
For processing subject to the GDPR, we rely on the legal bases of Art. 6 para. 1 GDPR — depending on the processing, on your consent, the fulfillment of a contract, a legal obligation, or a legitimate interest. If special categories of personal data are involved — for example, in the case of donations or if you entrust us with personal matters — Art. 9 para. 2 GDPR is also applied. Which basis applies in each individual case is always stated directly with the respective processing.
If you access our services from another country, additional rights may apply there. In that case, please feel free to contact us – we will look into it.
13. Contact for data protection matters
If you have questions about data protection or would like to exercise your rights (e.g., access, erasure, withdrawal), please feel free to contact us.
Contact:
ICF Munich e. V.
Felix Hiesinger
Arnulfstraße 34
80335 Munich
Germany
[email protected]
We’ll get back to you as quickly as possible — more on this under “How quickly we respond”
14. Changes
We review this privacy policy at least every six months and adapt it if legal requirements (e.g., new laws, court rulings, or changes in the revDSG, the GDPR, or the EU AI Act) or the tools we use change. You can always find the current version here on our website.
Last update: Version 2.0 — 2026-09-13