Preamble #
With this privacy policy, UA-DE e.V. informs you about which categories of personal data (hereinafter referred to briefly as “data”) are processed within the scope of providing our application and our online services, for what purposes this is done, and to what extent. All terms used are expressly to be understood as gender-neutral.
Our Promise on Data Protection: UA-DE e.V. is particularly committed to the principle of data minimization. For this reason, we use neither cookies nor trackers or other behavioral analysis tools on our website and in our application. The processing of information regarding our donors takes place exclusively within the strict framework of legal requirements for the proper retention of donation certificates.
As of: May 25, 2026
Table of Contents #
- Preamble
- Data Controller
- Overview of Processing Activities
- Applicable Legal Bases
- Security Measures
- General Information on Data Storage and Deletion
- Rights of the Data Subjects
- Performance of Tasks according to Articles of Association or Rules of Procedure
- Payment Procedures
- Provision of the Online Offer and Web Hosting
- Newsletter and Electronic Notifications
- Presences in Social Networks (Social Media)
- Definitions of Terms
Data Controller #
UA-DE e.V. Tannenstraße 5 40476 Düsseldorf Germany
Persons Authorized to Represent: Maryna Schiefer, Tobias Juderjahn, Vadym Dudukal
Email Address: webmaster@ua-de.info
Signal: https://signal.me/#eu/eZo8Ilu6Mc51r5JOwYu7R1Po7oid11auuR8OnY4YSEGm7Y21rVtNhqqyOH2oVYR3
Overview of Processing Activities #
The following overview summarizes the types of data processed by UA-DE e.V., the purposes of the processing, and the categories of data subjects concerned.
Types of Processed Data #
- Master and contact data.
- Payment and contract data.
- Content, usage, and log data.
- Meta, communication, and procedural data.
- Specific member data.
Categories of Data Subjects #
- Beneficiaries, clients, and interested parties.
- Communication partners and users of the online offer.
- Members, donors, business and contractual partners, as well as involved third parties.
Purposes of Processing #
- Fulfillment of contractual and statutory obligations as well as general communication.
- Execution of organizational, administrative, and business processes.
- Provision of information technology infrastructure and ensuring security measures.
- Fundraising, public relations, and informational purposes.
- Direct marketing and gathering feedback.
Applicable Legal Bases #
The processing of personal data by UA-DE e.V. is carried out on the basis of the regulations of the General Data Protection Regulation (GDPR). In addition, national regulations apply, in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG) in Germany and any state data protection laws.
- Consent: Art. 6 (1) (a) GDPR.
- Performance of a contract & pre-contractual inquiries: Art. 6 (1) (b) GDPR.
- Legal obligation: Art. 6 (1) (c) GDPR.
- Legitimate interests: Art. 6 (1) (f) GDPR.
- Membership contract (Articles of Association): Art. 6 (1) (b) GDPR.
The BDSG additionally regulates specific special cases such as the right to information, erasure, objection, as well as the processing of special categories of data.
Security Measures #
UA-DE e.V. takes appropriate technical and organizational measures (TOM) in accordance with legal requirements and taking into account the state of the art to ensure a level of data protection appropriate to the risk.
Data Integrity: Physical and electronic access controls secure confidentiality and availability.
Data Subject Rights: Established processes are in place for the deletion of data and the safeguarding of user rights.
Privacy by Design: Privacy-friendly default settings are already considered when selecting software and hardware.
Encryption: All data transmissions via our online services are encrypted using TLS/SSL technology (HTTPS).
General Information on Data Storage and Deletion #
Personal data will be deleted as soon as the underlying consent is revoked or the legal basis ceases to apply (e.g., if the purpose no longer exists). Exceptions to this are statutory retention obligations or vital interests in legal enforcement.
The following general retention periods apply under German law:
| Period | Affected Documents / Data | Legal Basis |
|---|---|---|
| 10 years | Books, records, annual financial statements, inventories, management reports, organizational documents | Sec. 147 (1) No. 1 AO (German Fiscal Code), Sec. 257 (1) No. 1 HGB (German Commercial Code) |
| 8 years | Accounting vouchers such as invoices and expense receipts | Sec. 147 (1) No. 4 AO, Sec. 257 (1) No. 4 HGB |
| 6 years | Commercial and business letters, tax-relevant documents (e.g., payroll slips) | Sec. 147 (1) No. 2, 3, 5 AO, Sec. 257 (1) No. 2 & 3 HGB |
| 3 years | Data for processing warranty, damage compensation, or similar contractual claims | Regular limitation period under Sec. 195, 199 BGB (German Civil Code) |
For ongoing contracts, the reasons for retention periods shift to the date of effective termination or conclusion. Unless agreed otherwise, a one-year period begins at the end of the respective calendar year.
Rights of the Data Subjects #
As a data subject affected by data processing, you have comprehensive rights against UA-DE e.V. under the GDPR. You can assert these rights at any time informally (e.g., via email to webmaster@ua-de.info).
-
Right of Access (Art. 15 GDPR): You have the right to obtain confirmation as to whether or not we process personal data concerning you. If this is the case, you can request access to this data as well as further information (e.g., processing purposes, categories of recipients, and the planned storage period).
-
Right to Rectification (Art. 16 GDPR): If the data processed by us is inaccurate or incomplete, you can request immediate rectification or completion.
-
Right to Erasure (“Right to be Forgotten”) (Art. 17 GDPR): You can request the erasure of your data if the purpose of the processing no longer applies, you withdraw consent, or the data has been unlawfully processed. The right to erasure does not apply if statutory retention obligations (e.g., tax law periods for donation certificates) prevent erasure.
-
Right to Restriction of Processing (Art. 18 GDPR): You have the right to request the restriction of the processing of your data if you contest the accuracy of the data, the processing is unlawful, or you have objected to the processing while the verification is pending.
-
Right to Data Portability (Art. 20 GDPR): You can request that we provide you with the data you have provided to us in a structured, commonly used, and machine-readable format, or transmit it to another controller, provided that the processing is based on consent or a contract.
-
Right to Withdraw Consent (Art. 7 (3) GDPR): You can withdraw consent once given (e.g., for receiving our newsletter) at any time with effect for the future. The lawfulness of the processing carried out up until the withdrawal remains unaffected.
-
Important Right: Right to Object (Art. 21 GDPR)
If we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation. This also applies to direct marketing based on these grounds. We will then cease processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests.
Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR):
If you believe that the processing of your data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority. For this purpose, you may contact the authority responsible for us:Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
GermanyEmail: poststelle@ldi.nrw.de
Website: www.ldi.nrw.de
Performance of Tasks according to Articles of Association or Rules of Procedure #
UA-DE e.V. processes data of members, supporters, interested parties, and donors to fulfill the association’s purpose as well as on the basis of legitimate interests (e.g., for administrative tasks or public relations). The necessity of data storage is reviewed regularly.
Specific Processes:
- Member Administration & Fee Management: Recording of master data, management of membership fees, invoicing, and dunning procedures. (Legal basis: Art. 6 (1) (b), (c) & (f) GDPR).
- Events: Logistical planning, registration, attendance recording, and follow-up of association activities. (Legal basis: Art. 6 (1) (b) & (f) GDPR).
- Public Relations: Distribution of informational materials and maintenance of press contacts. (Legal basis: Art. 6 (1) (b) & (f) GDPR).
- Fundraising: Implementation of donation campaigns and stewardship of supporters. (Legal basis: Art. 6 (1) (b) & (f) GDPR).
Payment Procedures #
To process membership fees and donations, UA-DE e.V. uses secure and encrypted payment methods via certified payment service providers. The association itself does not receive sensitive account or credit card data, but merely a status confirmation of the transaction.
Legal Basis: Performance of a contract (Art. 6 (1) (b) GDPR) as well as legitimate interests (Art. 6 (1) (f) GDPR).
Service Providers Used:
- Google Pay: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. (Privacy Policy: https://business.safety.google/privacy/).
- PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. (Privacy Policy: https://www.paypal.com/de/legalhub/paypal/privacy-full).
- Stripe: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA (Transfers secured via the Data Privacy Framework). (Privacy Policy: https://stripe.com/de/privacy).
Provision of the Online Offer and Web Hosting #
For the secure and stable delivery of our website, UA-DE e.V. processes technical usage and log data (e.g., IP addresses).
- Server Log Files: Accesses are automatically logged to maintain server stability and defend against DDoS attacks. Log files are deleted or anonymized after a maximum of 30 days, unless they serve evidentiary purposes.
- Content Delivery Network (CDN): A CDN is used for the accelerated and protected provision of large media files.
- Legal Basis: Legitimate interests (Art. 6 (1) (f) GDPR).
Newsletter and Electronic Notifications #
Newsletters containing information about association projects and campaigns are sent strictly on the basis of voluntary consent.
- Registration: Providing an email address is sufficient for registration.
- Opt-Out: Withdrawal of consent is possible at any time via the unsubscribe link at the end of each newsletter or by email.
- Obligation to Provide Proof: Unsubscribed email addresses may be stored in a blocklist for up to three years to legally prove former consent in the event of a dispute.
- Legal Basis: Consent pursuant to Art. 6 (1) (a) GDPR.
Presences in Social Networks (Social Media) #
UA-DE e.V. maintains profiles in social networks to communicate with users active there. We point out that providers may process data outside the EU and create usage profiles (e.g., via cookies set there) for advertising purposes. Data subject rights should preferably be asserted directly with the respective platform operator.
- Legal Basis: Legitimate interests (Art. 6 (1) (f) GDPR).
- Networks Used & Joint Responsibilities:
- Bluesky: Bluesky, PBLLC, Seattle, USA. (Privacy Policy: https://bsky.social/about/support/privacy-policy).
- Instagram / Facebook Pages: Meta Platforms Ireland Limited, Dublin, Ireland. There is a joint responsibility with Meta for collecting visitor data to create “Page Insights”. (Privacy Policy: https://privacycenter.instagram.com/policy/ and https://www.facebook.com/privacy/policy/).
- LinkedIn: LinkedIn Ireland Unlimited Company, Dublin, Ireland. Joint responsibility for collecting data to create “Page Insights”. (Privacy Policy: https://www.linkedin.com/legal/privacy-policy).
- X: X Internet Unlimited Company, Dublin, Ireland. (Privacy Policy: https://x.com/de/privacy).
Definitions of Terms #
The following definitions are based on the legal provisions of the GDPR and serve to provide a better understanding of the terms used:
- Master Data: Basic identification data such as name, postal address, date of birth, and user IDs.
- Content Data: Multi-media data such as texts, images, videos, or associated metadata (e.g., time of creation).
- Contact Data: Communication channels such as phone numbers, email addresses, and social media handles.
- Member Data: Specific information for managing memberships, status, fees, and activity within the association.
- Usage Data: Interaction data such as duration of visits, click paths, types of devices used, and IP addresses.
- Personal Data: Any information relating to an identified or identifiable natural person, directly or indirectly.
- Data Controller: The natural or legal person who determines the purposes and means of the processing of personal data (in this context, UA-DE e.V.).
- Processing: Any operation or set of operations performed on data, whether or not by automated means (such as collection, storage, transmission, or erasure).
- Contract Data: Contractual framework conditions such as terms, service descriptions, prices, and termination rights.
- Payment Data: Information required for financial transactions, such as bank details, amounts, and verification status.