Skip to content

Legal

Privacy policy

This privacy policy explains how W3ltfrieden e.V. (“we”, “us”, “our”) processes your personal data when you visit our platform or contact us. It also explains your rights.

Important, before you post:

Missions, logbook posts, comments and profiles are publicly visible on the internet, registration or not. That goes for people, organisations, search engines and AI applications. Content on this platform allows conclusions to be drawn about political opinions or philosophical beliefs. So before you publish anything, think about which details you want to make public. Registering under a pseudonym is possible.

As of 27.09.2026

Name and contact details of the controller

The controller for your personal data under the EU General Data Protection Regulation (GDPR) is:

W3ltfrieden e.V.c/o ATG Rechtsanwaltsgesellschaft mbHNeuer Wall 920354 HamburgGermany

represented by Fabian Friedrich and Sönke Mißfeld as joint authorised representatives

Email: info@w3ltfrieden.de

Recipients of the personal data and transfers to third countries

Service providers help us run our platform, and we transfer personal data to them. We have concluded data processing agreements (DPAs) with these service providers.

Some service providers may be based outside the European Union or the European Economic Area – in what are known as third countries. Section 3 explains which service providers we use, where they are headquartered and whether the European Commission has recognised an adequate level of data protection for the country in question (an adequacy decision).

An adequacy decision is a formal recognition by the European Commission that a country ensures an adequate level of data protection. For the USA, the EU-US Data Privacy Framework (DPF) is such an adequacy decision for certified companies. Where we transfer data to US service providers certified under the DPF, the transfer relies on that decision. For countries or service providers without an adequacy decision (Singapore or non-certified US providers, for example), we make sure your data stays protected by concluding standard contractual clauses (SCCs) with the service providers. SCCs are standardised legal contracts approved by the European Commission.

Section 3 of this privacy policy also lists the further recipients of your personal data.

How your personal data is processed

Personal data is any information that can be related to you directly or indirectly.

Which details we need for your account

You are not legally or contractually required to provide us with your personal data. However, we need certain details, such as your email address and chosen username, to conclude the user agreement and set up your account.

Without these details, you cannot create a profile or submit a mission. You can read published content without providing them.

You can also develop a first mission draft without an account.

Accounts and publishing from age 18

Under our terms of use, you must be at least 18 to create an account and publish content such as missions or comments.

Children's ideas can become missions too: as a parent, you can develop a mission together with your child and manage it through your own account. You remain responsible for the mission, its content and communication. Please do not publish details that could identify your child.

We do not knowingly collect personal data from minors. If we learn that a registered person is under 18, we will close their account and delete the associated data.

Your personal data is processed as follows:

Providing the platform

Personal data

Your IP address, the web address you visit (URL), and information about your browser and operating system.

Purpose

To allow your device to communicate with our platform and load the content you request.

Legal basis

Legitimate interest (under Art. 6(1)(f) GDPR): providing the platform.

Duration

Our service providers store your personal data for as long as they need it to deliver their service. Where necessary it is kept longer in order to assert legal claims.

Service providers (recipients) and third parties

Frontend hosting: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. We have concluded a DPA with our service provider.

Backend hosting: Render Services, Inc., 525 Brannan Street, Suite 300, San Francisco, CA 94107, USA. Processing takes place on servers in Frankfurt, Germany. We have concluded a DPA with our service provider.

Both service providers are certified under the EU-US Data Privacy Framework (DPF). The transfer of data to the USA relies on the European Commission’s adequacy decision.

Downloading materials

Personal data

Your IP address, the web address you visit (URL), and information about your browser and operating system.

Purpose

To let you download our materials. The files are stored on GitHub. When you download a file, your browser is redirected to GitHub and loads it directly from there.

Legal basis

Legitimate interest (under Art. 6(1)(f) GDPR): providing our materials.

Duration

Our service provider stores your personal data for as long as it needs it to deliver its service. Where necessary it is kept longer in order to assert legal claims.

Service providers (recipients) and third parties

File hosting: GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. We have concluded a DPA with our service provider.

GitHub, Inc. is certified under the EU-US Data Privacy Framework (DPF). The transfer of data to the USA relies on the European Commission’s adequacy decision.

Your account and public profile

Sign-in details

Your username, email address and password in hashed form, rather than plain text.

Public profile data

Username, display name, location, joining date, profile picture, short bio, links to social networks, your own missions, mission memberships and logbook entries.

Purpose

Your account lets you submit and manage missions, join mission teams, and write comments and logbook entries. You can edit your profile and details yourself in your account.

Your preferred username

Your username is unique on W3ltfrieden and forms part of your public profile address. You can claim your preferred username when you register, as long as it is still available. Pseudonyms are welcome.

Legal basis

Processing for the performance of a contract under Art. 6(1)(b) GDPR

Storage and deletion

Your public profile data and sign-in details remain stored until you change them or your account is deleted.

As soon as you request account deletion, your profile is no longer publicly visible and you are signed out on all devices. Your public profile data and sign-in details are automatically deleted after 30 days. You receive a reminder three days beforehand.

You can also trigger immediate deletion through a confirmation link. Backups are kept for up to seven days.

Service providers (recipients) and third parties

Authentication and storage provider: Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Processing takes place on servers in Frankfurt, Germany.

There is no adequacy decision by the European Commission for Singapore. The cooperation with our service provider is based on SCCs.

Creating, reviewing and publishing missions

Personal data

Mission data: your display name together with the title and the description of the mission

Moderation notes and decisions, and assessments by the ethics bot

Record of consent (consisting of: what you consented to, in which version, when and by which route, plus your IP address in encrypted form and browser data)

Purpose

You can create, submit and manage missions. They become publicly visible only once the moderation team approves them.

The ethics bot supports the moderation team with an initial check. It compares your mission description against a list of terms and criteria that we maintain and provides notes for the review. A human member of the moderation team always decides whether to publish the mission.

Data source for user content (Art. 14 GDPR): where users publish personal data about you, we do not collect that personal data directly from you but from a third party (the person publishing it).

Legal basis

Mission data is processed for the performance of a contract (under Art. 6(1)(b) GDPR).

For the submission and review phase, Art. 6(1)(b) GDPR applies in conjunction with your consent under Art. 9(2)(a) GDPR.

For the phase after submission and review, that is once missions have been published, Art. 6(1)(b) GDPR applies in conjunction with Art. 9(2)(e) GDPR, personal data manifestly made public.

The pre-check and the use of the ethics bot rely on our legitimate interest (under Art. 6(1)(f) GDPR): identifying content that is unlawful or breaks the rules, in conjunction with Art. 9(2)(e) GDPR, personal data manifestly made public.

The processing of your personal data by third parties (people publishing it) relies on our legitimate interest (under Art. 6(1)(f) GDPR) in conjunction with the performance of a contract (under Art. 6(1)(b) GDPR, see also Section 10.6(b) and Section 10.7 of the terms of use).

We process your record of consent on the basis of our legitimate interest (under Art. 6(1)(f) GDPR): our legitimate interest in keeping records of consent after a withdrawal lies in being able to show that your consent was obtained properly. This serves to defend against possible liability and damages claims and to evidence our accountability under data protection law.

Storage and deletion

Before publication, you can edit or delete your mission. You can archive a published mission. It is then no longer publicly visible.

If you delete your account, your missions are automatically deleted after 30 days. Backups are kept for up to seven days.

Record of consent: After you deregister or withdraw your consent, we store the bare evidence of your original consent for a further three years, until the end of the calendar year.

Review records

We automatically delete the ethics bot's review data – your mission description and the review result – 90 days after the review.

We keep the moderation decision for three years. It documents why content was approved or removed. These retention periods also apply if you delete your account before they expire.

Service providers (recipients) and third parties

Storage provider: Supabase Pte. Ltd (see details above)

AI model routing: EUrouter B.V., Jacob van Lennepstraat 78H, 1053 HM Amsterdam, Netherlands. We have concluded a DPA with our service provider. As a router, the service passes the description of the mission on to model providers. You find the list of model providers here.

Use of the Peace Mission Bot

Personal data

Your answers to the Peace Mission Bot's questions and a record of your consent.

This record contains what you consented to, in which version, when and through which process. It also includes your IP address in encrypted form and information about your browser.

Purpose

The Peace Mission Bot helps you turn your answers into a mission draft. Using it is optional: you can also write your mission yourself, without AI assistance.

Legal basis

Your answers to the Peace Mission Bot's questions are processed on the basis of your consent under Art. 6(1)(a) GDPR in conjunction with your consent under Art. 9(2)(a) GDPR. You can withdraw your consent at any time in your profile settings.

For as long as your consent is in place, you can use the Peace Mission Bot.

We process your record of consent on the basis of our legitimate interest (under Art. 6(1)(f) GDPR): our legitimate interest in keeping records of consent after a withdrawal lies in being able to show that your consent was obtained properly. This serves to defend against possible liability and damages claims and to evidence our accountability under data protection law.

Duration

Your answers to the Peace Mission Bot's questions and the draft produced from them are stored for 90 days and then deleted automatically. If you delete your account before then, they stay until the 90 days are up; after that there is no link to your account any more.

Record of consent: After you deregister or withdraw your consent, we store the bare evidence of your original consent for a further three years, until the end of the calendar year.

Service providers (recipients) and third parties

AI model routing: EUrouter B.V. (see details above)

Storage provider: Supabase Pte. Ltd (see details above)

Mission logbook and comments

Personal data

Your logbook entries, including images where applicable, and your comments, each linked to your display name.

Purpose

To make your published logbook entries and comments publicly visible on the platform.

Legal basis

The processing is carried out for the performance of a contract (under Art. 6(1)(b) GDPR) in conjunction with Art. 9(2)(e) GDPR, personal data manifestly made public.

Storage and deletion

You can delete your logbook entries and the content of your comments yourself at any time. If you delete your account, this content is automatically deleted after 30 days.

Deleted comments leave an empty placeholder so that other people's replies remain readable. Backups are kept for up to seven days.

Service providers (recipients) and third parties

Authentication and storage provider: Supabase Pte. Ltd. (see details above)

Joining a mission and offering help

Personal data

Your team membership, display name, username and the link to your profile.

Purpose

When you join a mission team, your team membership is displayed publicly.

When you confirm an offer of support via “I can help”, the mission lead receives your display name, username and profile link. Under our terms of use, they may use these details only to respond to your offer.

Your details are shared as soon as you confirm. We cannot take back information that has already been shared.

Legal basis

The processing is carried out for the performance of a contract (under Art. 6(1)(b) GDPR) in conjunction with Art. 9(2)(e) GDPR, personal data manifestly made public.

Duration

Your team membership is deleted as soon as you remove yourself from the team, or when the mission lead removes you from the team or deletes the mission. If you delete your account, your team membership is deleted automatically after 30 days. Backups are kept for up to seven days.

Service providers (recipients) and third parties

Authentication and storage provider: Supabase Pte. Ltd. (see details above)

Further recipients: The lead of the mission you support.

Security and technical operation

Personal data

Your IP address, the web address you access (URL), and details about your browser and operating system.

Purpose

We use this data to protect the platform, fight fraud and abuse, fix technical errors and make technical improvements to the platform.

Legal basis

We process your technical usage data on the basis of our legitimate interest (under Art. 6(1)(f) GDPR): keeping the platform secure, technically correct in its display, and optimised.

Storage and deletion

We do not store log files containing this technical usage data ourselves. Our hosting and security service providers produce access logs containing your IP address. These logs are deleted there within 14 days.

Service providers (recipients) and third parties

Captcha and bot protection services: Cloudflare, Inc., 701 Townsend St., San Francisco, CA 94107, USA. We have concluded a DPA with our service provider.

Cloudflare, Inc. is certified under the EU-US Data Privacy Framework (DPF). The transfer of data to the USA relies on the European Commission’s adequacy decision.

Authentication and storage provider: Supabase Pte. Ltd. (see details above)

Frontend hosting: Vercel Inc., (see details above)

Backend hosting: Render Services, Inc., (see details above)

Emails about your account and your missions

Personal data

Your email address.

Purpose

We use your email address for essential account functions and communication on the platform. You receive confirmation emails when you register, change your password or delete your account, as well as notifications about the status of missions you have submitted and offers of support.

We also send you important account security notices and inform you about material changes to platform functions or our terms of use.

Legal basis

The processing is carried out for the performance of a contract (under Art. 6(1)(b) GDPR)

Storage and deletion

We store your email address for as long as your account exists. We keep no copy of the message sent. The send job is deleted after seven days. Delivery logs at the mail service provider are deleted after 30 days.

Service providers (recipients) and third parties

Mail service provider (Brevo): SENDINBLUE, 17 rue de Salneuve, 75017, Paris, France.

We have concluded a DPA with our service provider.

Reports and moderation

Personal data

Name and email address of the reporting person (except where the law provides otherwise, as with reports about certain criminal offences), identifying data of the reported person (username, user ID for example), the content concerned, and the communication exchanged during the reporting and appeal procedure.

Purpose

We process this data to review reported content for possible breaches of the law or our rules, communicate moderation decisions, handle appeals and meet legal requirements.

If you are the reported person, information about the allegation and the context of the report comes from third parties, such as the reporting person or the relevant authorities. This explains the source of the data under Art. 14 GDPR.

To protect the reporting person, we disclose their identity to you only when we are legally required to do so.

Legal basis

The processing relies on our legitimate interest (under Art. 6(1)(f) GDPR): keeping the platform safe and in line with the terms of use. Where the review concerns special categories of personal data, we rely on Art. 9(2)(e) GDPR (personal data manifestly made public).

Duration

The data is stored until the reporting and moderation procedure is finally concluded.

Once an investigation or a measure is concluded, we keep the data until the appeal period (six months from receipt of the reasons) has expired and no further legal claims can be brought.

Service providers (recipients) and third parties

Mail service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. We have concluded a DPA with our service provider.

This service provider is certified under the EU-US Data Privacy Framework (DPF). The transfer of data to the USA relies on the European Commission’s adequacy decision.

Further recipients: Where serious criminal offences are suspected (danger to life and limb, for example), we are legally obliged to pass certain data on to the competent law enforcement authorities.

Your email enquiries

Personal data

Your email address, your first and last name, the subject and the other information in your message.

Purpose

We use this information to handle your enquiry and reply to you by email.

Legal basis

The processing relies on our legitimate interest (under Art. 6(1)(f) GDPR): answering your questions.

Storage and deletion

We store this data for up to 12 months. We keep it longer only when required by tax or commercial law or because of a legal dispute.

Service providers (recipients) and third parties

Mail service provider: Google Ireland Limited (see details above).

Statistics on platform use

Personal data

Pseudonymised usage data (hashed IP address, URL and user agent)

Purpose

We compile summary statistics about our platform's reach and how it is used. This helps us improve its functions and services.

We do not use cookies for this. Individual visitors are not tracked, and no persistent identifiers are created.

Legal basis

The processing relies on our legitimate interest (under Art. 6(1)(f) GDPR): to gain insights for improving functions and services and to evaluate how people use the platform.

Anonymisation

After 24 hours, the usage data is fully anonymised.

Service providers (recipients) and third parties

Web analytics: Plausible Insights OÜ, Västriku tn 2, 50403, Tartu, Estonia.

We have concluded a DPA with our service provider. The following links have more about Plausible’s data protection practices, security measures and a legal assessment of GDPR compliance.

Our newsletter

Personal data

Your email address.

Purpose

We use your email address to send you our newsletter.

After signing up, you receive an email with a confirmation link. Your sign-up is complete only once you click this link. This process is called double opt-in and protects against unwanted sign-ups by others.

Legal basis

Your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time, for example through the unsubscribe link in our newsletter emails.

Duration

Email address: For as long as your consent is in place; deletion once the contract with the service provider ends.

Service providers (recipients) and third parties

Mail service provider (Brevo): SENDINBLUE, 17 rue de Salneuve, 75017, Paris, France.

We have concluded a DPA with our service provider.

Receiving and processing donations and supporting memberships

Personal data

Personal details: data fields including name, postal address, email address

Payment data: the data needed to process the payment (depending on the payment method you choose, e.g. IBAN and BIC for payments by direct debit)

Technical usage data: When you open our support page, your browser loads the forms directly from Twingle. Twingle receives your IP address, the web address you visit (URL), and information about your browser and operating system, even if you do not donate. The legal basis for this is our legitimate interest (under Art. 6(1)(f) GDPR): providing the forms.

Purposes

The processing serves to handle your donation technically, to book the incoming payment and, where applicable, to issue you a donation receipt (Zuwendungsbestätigung).

Legal basis

The processing is based on our legal obligation under Art. 6(1)(c) GDPR to store donation data relevant for accounting.

Duration

For as long as needed to carry out and complete the donation. Once the donation is fully processed, the data is stored for the statutory retention periods, in particular the ten-year limitation period under tax law.

Service providers (recipients) and third parties

Online donation platform provider: twingle GmbH, Prinzenallee 74, 13357 Berlin, Germany. We have concluded a DPA with our service provider.

Third parties

Depending on the payment method you choose, Twingle passes the payment data on to the relevant payment service provider to carry out the transaction (e.g. banks for SEPA direct debit, PayPal, credit card providers, Stripe Payments Europe, Limited (SPEL)). These are independent controllers within the meaning of data protection law. The privacy notices of the relevant payment service provider also apply to the payment processing: PayPal privacy statement, Stripe privacy policy.

Cookies and browser storage

Cookies are small files that store information in your browser. They can help a website recognise your browser and adapt its content. Cookies can come from the website you visit or from third-party services included on that website.

Your browser's local storage and session storage serve similar purposes. When we refer to cookies here, we also mean these forms of storage.

Our platform uses cookies. Our cookie policy explains which ones we use, what we use them for, and how you can block or delete them.

Automated decision-making including profiling

No automated decision-making, including profiling, takes place.

Your rights

The GDPR gives you the following rights. If you want to exercise them or have questions about them, email us at info@w3ltfrieden.de. An informal message is enough.

Right to withdraw consent (Art. 7(3) GDPR)

Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Your right to withdraw does not affect the lawfulness of the processing carried out up to your withdrawal.

Right of access (Art. 15 GDPR)

You have the right to ask us to confirm whether personal data concerning you is being processed; where it is, you have a right of access to that personal data and to the information set out in Art. 15 GDPR.

Right to rectification (Art. 16 GDPR)

You have the right to ask for inaccurate personal data about you to be corrected without delay. You also have the right to have incomplete personal data about you completed.

Right to erasure (Art. 17 GDPR)

You have the right to ask us to erase your personal data without delay, where the legal conditions under Art. 17 GDPR are met.

Right to restriction of processing (Art. 18 GDPR)

You have the right to ask for the processing of your personal data to be restricted, where the legal conditions under Art. 18 GDPR are met.

Right to data portability (Art. 20 GDPR)

If our automated processing is based on your consent or a contract with you, you have the right to receive the personal data you have provided to us about yourself in a structured, commonly used and machine-readable format. You also have the right to transmit that data to another controller without hindrance.

Right to object (Art. 21 GDPR)

On grounds relating to your particular situation, you have the right to object at any time to the processing of your personal data where that processing relies on legitimate interests (Art. 6(1)(f) GDPR). If you object, we will stop processing your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Right to lodge a complaint (Art. 77 GDPR)

You have the right to lodge a complaint with the competent supervisory authority if you believe that we process your personal data in a way that does not comply with data protection law. You can lodge the complaint in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement.

The supervisory authority primarily competent for us is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit,Ludwig-Erhard-Str. 22,20459 Hamburg,Germany

Questions

If you have questions about this privacy policy, please send an email to info@w3ltfrieden.de.

Changes to this privacy policy

This privacy policy is updated from time to time. The date of the last change is at the top of the privacy policy.