termin-umfrage.de

Privacy at termin-umfrage.de

Privacy policy

This policy explains which personal data are processed when a date poll is created or used and which rights data subjects have.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Dennis BrunerEmil-Warburg-Weg 2095447 BayreuthGermanyEmail: dennis@bruner.email

2. Purpose and operation of the service

termin-umfrage.de lets groups suggest whole days and answer yes, maybe, or no. There are no user accounts. A poll is accessed through a random link that must be kept secret.

Anyone with the link can see the title, proposed dates, participant names, and answer matrix. Share it only with the intended group.

3. Polls and answers

Creating a poll processes its title, proposed dates, expiry, and technical timestamps. Participating processes the chosen name, answers, timestamps, and association with the poll.

The processing is necessary to provide the expressly requested service under Article 6(1)(b) GDPR. Secure group access and abuse prevention are additionally based on the legitimate interest in a functional and secure service under Article 6(1)(f) GDPR.

  • The poll capability and participant token are stored on the server only as SHA-256 hashes.
  • The raw participant token remains in the browser so the participant can edit or remove their own answers.
  • Participants may use a pseudonym instead of their real name.

4. Connection, log, and security data

When the service is accessed, the server processes technically necessary data such as IP address, time, requested address, HTTP method, status code, referrer, and browser identifier. These data are required for delivery, troubleshooting, attack prevention, and abuse protection.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure, stable, and low-abuse operation of the service. IP-based rate-limit keys are hashed before storage.

5. Cookies and local browser storage

Only technically necessary storage technologies are used. Consent is not required under section 25(2)(2) TDDDG because they are necessary to provide the service expressly requested by the user. There are no analytics, advertising, or third-party cookies.

  • An encrypted, HTTP-only, SameSite=Lax session cookie stores language, CSRF protection, and short-lived form state. It expires 120 minutes after the last activity.
  • The XSRF-TOKEN cookie protects forms and data-changing requests from third-party websites.
  • datefind:participant:* stores the participant token together with the poll expiry and is automatically removed afterwards.
  • datefind:theme stores an expressly selected appearance locally until it is changed or browser data are cleared. It is not transmitted to the server.

6. Hosting by Hetzner

The application, database, and encrypted backups are processed by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, on servers in Falkenstein, Germany. A data processing agreement under Article 28 GDPR is in place with Hetzner.

No transfer outside the EU or EEA is intended for hosting.

7. Contact and Proton Mail

The contact form processes name, email address, subject, message, and the poll link for deletion requests. The message is sent to the controller through Proton Mail without permanent storage in the application. The provider is Proton AG in Switzerland.

Switzerland benefits from an adequacy decision by the European Commission under Article 45 GDPR. The legal bases are Article 6(1)(b) GDPR for service-related or pre-contractual requests, Article 6(1)(c) GDPR for privacy requests, and Article 6(1)(f) GDPR for general communication. The legitimate interest is responding to incoming requests.

8. Recipients

Recipients are Hetzner as the hosting processor, Proton for email communication, and the people to whom a poll link is made available. Data are not shared for advertising purposes.

9. Retention and deletion

Personal data are deleted or anonymized under the following rules unless a legal obligation or the necessary establishment, exercise, or defense of legal claims requires otherwise:

  • Polls expire after three months by default. A shorter period or a maximum of twelve months can be selected when creating one. Expired polls and all associated data are permanently removed from the active database each day.
  • Participants may remove their own information earlier with the token stored in their browser.
  • Session data expire 120 minutes after the last activity. Rate-limit data expire after the relevant window of no more than ten minutes; physically expired database records are removed every minute.
  • Application and web-server logs are retained for no more than 14 days.
  • Encrypted backups are created daily and overwritten after 30 days. Deleted data may therefore remain in backups for up to 30 days.
  • Ordinary contact correspondence is deleted no later than 90 days after final resolution. Individual messages may be kept longer when required by law or for specific legal claims.

10. Data-subject rights

Subject to Articles 15 to 21 GDPR, you have rights including access, rectification, erasure, restriction, portability, and objection to processing under Article 6(1)(f) GDPR. Core processing is not based on consent, so there is no corresponding consent to withdraw. Rights may be exercised through the contact form or by emailing dennis@bruner.email.

You may also complain to the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, or another competent supervisory authority.

11. Identification for privacy requests

The service is intentionally account-free and pseudonymous. Under Article 11 GDPR, no additional identity data are collected solely for later requests. Include the poll link, the name used, and the participant token where available.

If the record cannot be linked safely, no additional poll data will be disclosed. A complete poll is deleted only after manual review of the link and credible creation details. Identity documents are not routinely requested.

12. Security

Poll and participant tokens are randomly generated and stored on the server only as hashes. Poll pages are delivered with noindex, no referrer forwarding, and no public caching. Production traffic is encrypted using HTTPS.

Despite these measures, the poll link is an access capability. Anyone who obtains it can see the poll. Do not publish it or send it to unrelated people.

13. Minors and special-category data

The service is intended for people aged 16 or over. Use pseudonyms where a real name is unnecessary, and do not enter health data, religious beliefs, political opinions, or other sensitive information in poll titles, names, or messages.

14. Automated decision-making

There is no automated decision-making, including profiling, within the meaning of Article 22 GDPR. The date ranking is merely a mathematical display of answers and produces no legal or similarly significant effects.

15. Requirement to provide data

Providing personal data is not required by law or contract. However, the relevant function cannot be provided without a title, proposed dates, and the information necessary to participate.

16. Changes to this policy

This policy will be updated if functions, providers, or the legal situation change materially. The current version and its update date remain available from the site footer.

The German version is authoritative. This English translation is provided for convenience.