Privacy Policy
Contents
1. Introduction & Data Controller
- Website Operator
- Responsible for Content & Data Processing
- Data Protection Officer
- What Is the ICF Movement?
- Legal Basis
2. Principles of Data Processing
- ✅ Transparency
- 🎯 Purpose Limitation
- ➖ Data Minimisation
- 🔐 Security
- 🕐 Storage Limitation
- 🌍 Lawfulness
3. Collection & Use of Personal Data
- 📬 Contact Requests & Forms
- 💌 Newsletters & Communication
- 💳 Donations
- 📈 Website Usage & Tracking
- 💻 Server Logs & IT Security
4. Use of Cookies & Tracking Technologies
- 🍪 What Are Cookies?
- 🍪 Consent Management — CookieHub
- ⚙️ Consent-Based Cookies
- 🛠 Management via Google Tag Manager
5. Tools & Third-Party Providers
- 📈 Analytics & Performance Tools
- 📋 Forms, Newsletters & Communication
- 🎥 Embedded Media
- ⚙️ Other Tools
6. Your Rights
- 📋 Right of Access
- ✏️ Right to Rectification
- ❌ Right to Erasure
- 🧯 Right to Restriction of Processing
- 🚫 Right to Object
- 📤 Right to Data Portability
- 🛑 Right to Withdraw Consent
- 🧑⚖️ Right to Lodge a Complaint with a Supervisory Authority
7. Data Disclosure & Data Processing Agreements
- 🤝 Cooperation with Service Providers — Data Processing
- 🌍 Transfers to Third Countries
8. Data Retention Period
- 🔄 General Principles
- 📌 What Does This Mean for You?
9. International Data Transfers
- 🌍 What Does This Mean in Practice?
- 🇺🇸 Example: United States
10. Security
- 🔐 Technical & Organisational Measures
- 🛡️ What You Should Know
11. Legal Bases for Data Processing & Scope of Application
- Switzerland
- European Union
12. Contact Regarding Data Protection Matters
13. Changes
Introduction & Data Controller
For us, data protection is not merely a legal obligation, but an expression of responsibility. As ICF Tel Aviv, we are committed to ensuring that your data is handled with care and respect.
This Privacy Policy explains what personal data we process through our website, the purposes for which we process it, and the rights you have in relation to your data.
It applies to the domain https://icf.church/telaviv in all available language versions, as well as to all of the following legal entities and any future organisations operating under the ICF — International Christian Fellowship — brand or in which one of the listed organisations holds an interest:
- ICF Movement — Association
- ICF Movement Deutschland e.V. — Registered Association
- ICF Tel Aviv
Whenever the terms “ICF” or “we” are used in this Privacy Policy, they refer, depending on the context, to one or more of these organisations.
Website Operator
ICF Tel Aviv
Menachem Begin Road 116
6701310 Tel Aviv-Yafo
Israel
[email protected]
Responsible for Content & Data Processing
ICF Tel Aviv
Menachem Begin Road 116
6701310 Tel Aviv-Yafo
Israel
[email protected]
What Is the ICF Movement?
ICF is a Christian church founded on biblical principles. It was born out of a dream to create a church experience that is dynamic, relevant to everyday life, and contemporary.
The ICF Movement is an organisation that supports the planting of churches, primarily in Europe and selectively in other parts of the world. Its goal is to help people become more like Jesus Christ, live fearlessly, and make a positive difference in their communities. We understand church planting as part of the Great Commission and as a fundamental part of our DNA.
In addition to planting ICF churches, the ICF Movement is committed to renewing and strengthening the existing church landscape in Europe and beyond. For this purpose, it provides resources, conferences, training programmes through ICF College, leadership development, and coaching.
Together, we believe that Europe and the world can experience spiritual renewal through healthy and socially relevant local churches. It is our deepest conviction that the local church is the hope of the world!
Learn more at https://icf.church/movement
Legal Basis
The information you provide through the various tools described in this Privacy Policy will be used exclusively to process your specific request. Further information can be found in the section “Legal Bases for Data Processing.”
Principles of Data Processing
We process personal data for clearly defined purposes and only to the extent necessary for those purposes. In doing so, we follow these principles:
✅ Transparency
We want you to be able to understand at any time what happens to your data. Therefore, this Privacy Policy openly explains which tools we use and why we use them.
🎯 Purpose Limitation
We collect and use personal data only for its intended purpose—for example, to respond to contact requests, manage newsletter subscriptions, analyse website usage, or process donations.
➖ Data Minimisation
We collect and process only the data that is necessary. Whenever anonymous or pseudonymous use is possible, we make use of these options.
🔐 Security
Your data is protected. We use appropriate technical and organisational measures to protect it against loss, misuse, and unauthorised access.
🕐 Storage Limitation
We retain personal data only for as long as it is required for the relevant purpose or as long as statutory retention obligations apply.
🌍 Lawfulness
Our processing of personal data is based on a valid legal basis, such as your consent, a legitimate interest, or a legal obligation.
We do not make decisions that have legal or similarly significant effects based solely on automated processing. This means that we do not carry out “profiling” within the meaning of Article 22 of the General Data Protection Regulation—GDPR.
Please note: Where certain data-processing activities involve an increased level of risk—for example, the processing of sensitive personal data—we conduct a Data Protection Impact Assessment where necessary, in accordance with Article 35 of the GDPR or Article 22 of the revised Swiss Federal Act on Data Protection.
Collection & Use of Personal Data
We collect personal data when you actively provide it to us, for example through a form, or when the processing is technically necessary—for example, your IP address when you visit a page, make a donation, or use our website.
Below, you can find information about the situations in which this occurs and how we use your data.
📬 Contact Requests & Forms
When you contact us through a contact form or register for an event, we process the information you provide, such as your name, email address, and message, in order to respond to your request or provide the requested service.
💌 Newsletters & Communication
When you subscribe to our newsletter or remain in contact with us—for example, because you are interested in our resources or activities—we store and use your contact details to send you regular emails, inspiration, and updates.
You can unsubscribe from the newsletter at any time by using the unsubscribe link included in every email.
💳 Donations
Donations to the ICF Movement can be made through our own platform: https://icf.church/telaviv/en/give/ This platform is operated by the ICF Movement in cooperation with ICF Zurich and forms part of our responsibility under applicable data protection laws.
Payments are processed through external providers such as Stripe, PayPal, and TWINT. Once you select one of these payment services, you will be redirected to the provider’s platform. The provider’s own privacy policy will then also apply to the further processing of your data.
We process the information you provide, such as your name, email address, donation amount, and payment method, in order to process and document your donation, including the issuance of donation receipts.
Donations to religious organisations may, in certain circumstances, reveal information about a person’s religious beliefs. Such information may constitute a special category of personal data and is considered particularly sensitive under Article 9 of the GDPR. We process this information only with your explicit consent or where the processing is permitted by law.
📈 Website Usage & Tracking
When you visit our website, certain technical information is automatically processed, including:
- IP address, shortened or pseudonymised
- Browser type and version
- Operating system
- Date and time of access
- Pages visited and time spent on the website
This information helps us operate our website reliably and continuously improve it. Please also refer to the section “Cookies & Tracking.”
💻 Server Logs & IT Security
When you visit our website, our hosting provider automatically processes server log information, such as your IP address, the date and time of access, the requested URL, referrer information, and user agent.
This processing is necessary for the technical operation of the website and for IT security.
Tools & Third-Party Providers
We use selected third-party providers to make our website user-friendly, secure, and modern.
Below, we explain which tools we use, which data may be processed, and why these tools are used.
📈 Analytics & Performance Tools
Google Analytics
We use Google Analytics to understand how visitors use our website.
Collected information, such as page views, time spent on the website, and the type of device used, is evaluated in an anonymised or pseudonymised form.
Google Tag Manager
Google Tag Manager is used to manage tracking tags and cookies. Google Tag Manager does not itself store personal data.
Meta Pixel
We use Meta Pixel to measure the performance of marketing campaigns and display relevant content.
Google Ads
Google Ads is used for campaign tracking and conversion measurement so that we can evaluate the effectiveness of our advertising.
Microsoft Clarity
Microsoft Clarity is used to analyse user behaviour, such as click paths and heatmaps.
The collected data is evaluated in an anonymised or pseudonymised form.
Gleap
We use Gleap as a support and communication platform.
Gleap is used to process support requests, display assistance such as help articles, evaluate user feedback, and display targeted chat messages, notifications, or banners.
Pulsetic
Pulsetic monitors the availability and performance of our website.
No personal data is stored by this service.
Sentry
Sentry records error messages, software bugs, and technical information in order to improve the stability and performance of the website.
📋 Forms, Newsletters & Communication
MailGun
We use Mailgun as an SMTP service to ensure the reliable technical delivery of emails, including confirmations and newsletters.
Google reCAPTCHA
We use Google reCAPTCHA versions 2 and 3 to protect our forms against misuse, spam, and automated submissions.
The service checks whether information has been entered by a person or an automated bot.
For this purpose, information such as the IP address, time spent on the page, and mouse movements may be analysed and transmitted to Google.
Salesforce Account Engagement (Pardot)
Salesforce Account Engagement, also known as Pardot, is our marketing automation platform.
We use it to manage newsletters and campaigns. Pardot may record which content is relevant to you so that we can send you appropriate information.
🎥 Embedded Media
Spotify
Audio files and videos from Spotify may be embedded on our website.
Spotify may place cookies and collect usage information, such as information about which podcasts are played.
ICF Hub
Sermons, activities, church services, and certain organisational information—such as social media links, addresses, and contact details—are transferred to the website through an API from our own internal ICF platform.
This transfer is technically necessary for the website’s core features to function.
⚙️ Other Tools
- Google Maps: Used to display interactive maps on the website.
- Algolia: Used for the internal search function for activities, sermons, and locations.
- ShortPixel: Used to optimise images.
- Zapier: Used for automation, including the transfer of data between different tools.
- WPML: Used to manage the multilingual presentation of website content.
Your Rights
The protection of your personal data is important to us.
You have the right to understand what happens to your data, and we aim to explain transparently which options are available to you. Below is an overview of your rights.
📋 Right of Access
You may ask us at any time whether we store personal data about you and request information about which personal data we process.
✏️ Right to Rectification
When your personal data is incorrect or no longer accurate, you may ask us to correct it.
❌ Right to Erasure
You may request the deletion of your personal data, for example when the data is no longer required for the purpose for which it was originally collected or when you withdraw your consent.
🧯 Right to Restriction of Processing
You may request that we restrict the processing of your personal data, for example while the accuracy of the data is being reviewed or while an objection is being considered.
🚫 Right to Object
You may object to the processing of your personal data where the processing is based on our legitimate interests or where another applicable legal basis gives you the right to object.
📤 Right to Data Portability
Where the applicable legal requirements are met, you may request to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format.
You may also request that the data be transferred to another controller where this is technically possible.
🛑 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw your consent at any time.
The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
🧑⚖️ Right to Lodge a Complaint with a Supervisory Authority
If you believe that your data protection concerns have not been adequately addressed, you have the right to contact the competent data protection supervisory authority.
Depending on the applicable jurisdiction, the competent authority may include:
- For Austria: the Austrian Data Protection Authority
- For Switzerland: the Federal Data Protection and Information Commissioner — FDPIC
- For Germany: the data protection authority of the relevant federal state
Data Disclosure & Data Processing
As a general rule, we do not disclose your personal data to third parties unless the disclosure:
- is necessary to fulfil a purpose that you know about and have requested, such as processing a donation;
- is required by law;
- is covered by valid consent;
- or takes place as part of processing carried out on our behalf.
🤝 Cooperation with Service Providers
We work with selected service providers for certain technical, administrative, and communication-related processes.
These service providers act on our behalf and in accordance with our instructions. They may support us with:
- hosting and operating the website, including providers such as DigitalOcean, Xano, and Imgix;
- sending emails, including providers such as Mailgun and Salesforce Account Engagement;
- analytics and tracking, including Google Analytics, Microsoft Clarity, and Sentry;
- forms, including Gravity Forms.
Where required, we conclude appropriate data processing agreements with these service providers to ensure that your data is protected and is not used for the providers’ own purposes.
🌍 Transfers to Third Countries
Some of our service providers are located outside Switzerland or the European Union, including in the United States.
In these cases, we take steps to ensure an appropriate level of data protection, for example through:
- Standard Contractual Clauses approved by the European Commission;
- adequacy decisions concerning countries recognised as providing an appropriate level of data protection;
- additional technical and organisational safeguards.
Data Retention Period
We retain personal data for as long as it is necessary for the relevant purpose or for as long as required by law.
🔄 General Principles
- Contact requests are generally stored for no longer than two years for follow-up and internal analysis, unless you request deletion, there is another legitimate reason for deletion, or statutory retention obligations require longer storage.
- Newsletter information is stored until you unsubscribe or withdraw your consent.
- Donor information may be subject to tax and accounting retention obligations. In Switzerland and the European Union, the applicable retention period is often ten years.
- Tracking information, such as information collected through Google Analytics, may be stored in an anonymised form so that we can understand long-term developments and improve the ICF website.
📌 What Does This Mean for You?
We comply with applicable statutory retention periods and regularly review which information can be deleted or anonymised.
International Data Transfers
Some of the services we use for hosting, newsletters, and analytics are located in or process data in countries outside Switzerland, Germany, or Austria, particularly in the United States.
🌍 What Does This Mean in Practice?
When personal data is transferred to countries that do not provide a level of data protection equivalent to that in Switzerland or the European Union, we take steps to ensure that your data remains appropriately protected.
These safeguards may include:
- Standard Contractual Clauses — SCCs — approved by the European Commission;
- adequacy decisions, including the EU-US and Swiss-US Data Privacy Frameworks;
- additional technical and organisational safeguards, such as encryption and strict access controls.
🇺🇸 Example: United States
Some of our service providers, including Google, Meta, Mailgun, and Vimeo, have their main offices in the United States.
Some of these providers participate in the Data Privacy Framework, which is intended to provide an appropriate level of protection for data transferred between the European Union or Switzerland and the United States.
Where the Data Privacy Framework does not apply, we may use the European Commission’s Standard Contractual Clauses as the legal basis for the transfer.
Security
Protecting your personal data is important to us.
We therefore use comprehensive security measures to protect it against loss, misuse, and unauthorised access.
🔐 Technical & Organisational Measures
We use technical and organisational security measures to protect your personal data against loss, misuse, unauthorised access, or disclosure.
These measures include:
- careful selection and monitoring of service providers;
- encryption of connections through SSL/TLS, identifiable by “https://” in the browser’s address bar;
- access restrictions for our systems;
- regular security and software updates;
- secure password policies and internal two-factor authentication.
🛡️ What You Should Know
No digital system can be guaranteed to be completely secure.
However, we do everything reasonably possible to maintain a high level of protection and respond promptly when there is cause for concern.
Please contact us if you notice anything unusual. We take reports and concerns seriously.
Despite careful technical and organisational measures, residual risks associated with the transmission of information over the internet—for example, when using third-party services—cannot be completely excluded.
Legal Bases for Data Processing & Scope of Application
This Privacy Policy is based on the principles of the General Data Protection Regulation — GDPR — the revised Swiss Federal Act on Data Protection — revFADP — and applicable Austrian data protection law.
Our processing of personal data is based on the relevant applicable legal provisions.
Different legal requirements may apply depending on the country from which you access our services.
🇮🇱 Israel
In Israel, the processing of personal data is governed, among other things, by:
- the Privacy Protection Law, 5741–1981;
- the Privacy Protection Regulations (Data Security), 5777–2017;
- applicable amendments, regulations, and guidance issued by the Israeli Privacy Protection Authority.
Amendment No. 13 to the Privacy Protection Law updated key definitions, strengthened the enforcement powers of the regulator, and introduced additional requirements for certain organisations. It entered into force in August 2025.
Depending on the circumstances, personal data may be processed:
- on the basis of consent;
- in order to provide a requested service;
- to comply with a legal obligation;
- to protect a legitimate interest;
- to ensure the security of the website and information systems;
- on another legal basis permitted by applicable law.
🇨🇭 Switzerland
Personal data is processed in accordance with the principle of good faith under Article 31(1) of the revised Swiss Federal Act on Data Protection and in accordance with the principles of proportionality, purpose limitation, and data security under Article 6.
🇪🇺 European Union
Where the GDPR applies, the processing of personal data is based in particular on the following legal grounds:
- Article 6(1)(a) GDPR: Consent
- Article 6(1)(b) GDPR: Performance of a contract or steps taken before entering into a contract
- Article 6(1)(c) GDPR: Compliance with a legal obligation
- Article 6(1)(f) GDPR: Legitimate interests, including our interest in analysing website usage to improve our website and maintaining IT security
- Article 9(2) GDPR: Processing of special categories of personal data, including information that may be processed in connection with donations
The applicable legal basis is specified in the relevant section where necessary or is determined according to the specific purpose of the processing.
Users outside these jurisdictions—for example, in the United States under the CCPA, Brazil under the LGPD, or the United Kingdom—may have additional rights.
When you access our services from another country, we recommend familiarising yourself with the data protection laws applicable in your place of residence.
Contact Regarding Data Protection Matters
If you have questions about data protection or wish to exercise your rights—for example, to request access, deletion, or withdrawal of consent—please contact us.
Contact
ICF Tel Aviv
Menachem Begin Road 116
6701310 Tel Aviv-Yafo
Israel
[email protected]
We will respond to your request as quickly as possible and, in all cases, within the period required by applicable law.
Where relevant, this includes notification and reporting obligations under Articles 33 and 34 of the GDPR or the revised Swiss Federal Act on Data Protection.
Changes
We regularly review this Privacy Policy and update it where necessary to reflect new legal requirements, court decisions, new legislation such as the AI Act, changes to the revised Swiss Federal Act on Data Protection, or technical developments.
The current version of this Privacy Policy is always available on our website.
Last updated: August 2026