DRAFT. This template must be reviewed by a German lawyer (and against actual data flows) before launch. GDPR / DSGVO non-compliance is fineable. Verify every claim below matches what the codebase actually does.

Legal

Privacy Policy

Pursuant to Art. 13 GDPR.

1. Data controller

{{Full legal name}} {{Address}} Email: hello@deutschland4u.com

2. What we collect and why

When you visit our site or subscribe to the newsletter, we process the following data:

  • Server logs: IP address, user agent, requested URL, response status, timestamp. Stored for {{N days, e.g. 14}}. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the site securely).
  • Newsletter: email address you enter in the form. Used solely to send periodic updates about Deutschland4U. Legal basis: Art. 6(1)(a) GDPR (your consent).
  • Telegram bot: if you message our bot, we store your chat id, first name, and the message content to operate the bot. Legal basis: Art. 6(1)(b) GDPR (contract performance — providing the bot service you requested).

3. Cookies

We use only strictly necessary cookies (session, theme preference). We do not use analytics, advertising, or third-party tracking cookies. {{Update this section if you add Plausible, GA4, Meta Pixel, etc. and add a cookie consent banner per TTDSG §25.}}

4. Third-party services

  • Hosting: {{Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA — adjust to actual provider}}. Data transfer to the US under EU-US Data Privacy Framework.
  • Database: {{Neon, Inc., San Francisco, USA — adjust if different}}. Region: {{EU Frankfurt or as configured}}.
  • Image CDN: Pexels (Berlin, Germany).
  • Instagram publishing: Meta Platforms Ireland Ltd, when we publish a reel through the Meta Graph API.

5. Your rights

Under the GDPR you have the right to (a) access your data, (b) request rectification, (c) request erasure, (d) restrict processing, (e) data portability, (f) object to processing, (g) withdraw consent at any time, and (h) lodge a complaint with a supervisory authority ({{e.g. Hamburgischer Beauftragter für Datenschutz}}). To exercise these rights, write to hello@deutschland4u.com.

6. Newsletter unsubscribe

Every newsletter we send contains a one-click unsubscribe link. You can also write to us at any time to be removed.

7. Data retention

Newsletter email: kept until you unsubscribe. Telegram bot conversations: {{N months}}. Server logs: see section 2. After these periods, data is deleted or fully anonymized.

Last updated: {{YYYY-MM-DD}}.