Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to as “data”) we process, for which purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and especially on our websites, in mobile applications, as well as within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offering”).
The terms used are not gender-specific.
Status: June 20, 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing
- Relevant Legal Bases
- Security Measures
- Use of Cookies
- Plugins and Embedded Functions and Content
Controller
Boedeker Foundation
Rietzer Siedlung 11
14797 Kloster Lehnin
Germany
Email address: mail@margarites.info
Imprint: https://www.margarites.info/imprint/
Overview of Processing
The following overview summarizes the types of data processed, the purposes of their processing, and the categories of data subjects.
Types of Data Processed
- Location data.
- Usage data.
- Meta, communication, and procedural data.
Categories of Data Subjects
- Users.
Purposes of Processing
- Provision of our online offering and user-friendliness.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the GDPR regulations, national data protection provisions may apply in your or our country of residence. If more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6(1)(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Legitimate Interests (Art. 6(1)(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, provided that the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data do not override those interests.
National data protection regulations in Germany: In addition to the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. State data protection laws of the individual federal states may also apply.
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, input, transfer, availability, and separation of the data. We have also implemented procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data threats. Furthermore, we consider the protection of personal data during the development or selection of hardware, software, and procedures according to the principle of data protection by design and by default.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and encrypted.
Use of Cookies
The term “cookies” refers to functions that store and read information on users’ devices. Cookies may be used for various purposes, such as ensuring the functionality, security, and convenience of online offerings, as well as analyzing visitor flows. We use cookies in accordance with legal requirements. Where necessary, we obtain prior consent from users. If consent is not required, we rely on our legitimate interests. This applies when storing and reading information is essential to provide explicitly requested content and functions. This includes storing settings and ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We provide clear information about the scope and types of cookies used.
Notes on legal bases: Whether we process personal data using cookies depends on whether consent has been given. If consent is given, it serves as the legal basis. Without consent, we rely on our legitimate interests, as explained above and in the context of the respective services and procedures.
Storage duration: Regarding storage duration, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user leaves an online offering and closes their device (e.g., browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device is closed. For example, login status can be saved, and preferred content can be displayed directly when the user revisits a website. Data collected via cookies may also be used for reach measurement. Unless we provide explicit information about the type and duration of cookies (e.g., when obtaining consent), users should assume that cookies are permanent and may be stored for up to two years.
General notes on withdrawal and objection (opt-out): Users may withdraw their consent at any time and may also object to processing in accordance with legal requirements, including via their browser’s privacy settings.
- Types of data processed: Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
- Data subjects: Users (e.g., website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR). Consent (Art. 6(1)(1)(a) GDPR).
Further notes on processing operations, procedures, and services:
- Processing of cookie data based on consent: We use a consent management solution to obtain user consent for the use of cookies or the procedures and providers listed within the consent management solution. This procedure serves to obtain, record, manage, and withdraw consent, particularly regarding the use of cookies and comparable technologies used to store, read, and process information on users’ devices. User consent for the use of cookies and related processing operations, including specific processing and providers listed in the consent management procedure, is obtained. Users can also manage and withdraw their consent. Consent declarations are stored to avoid repeated requests and to provide proof of consent in accordance with legal requirements. Storage occurs server-side and/or in a cookie (so-called opt-in cookie) or via comparable technologies to assign consent to a specific user or device. Unless specific information about consent management providers is given, the following general notes apply: The storage duration of consent is up to two years. A pseudonymous user identifier is created, stored together with the time of consent, the scope of consent (e.g., categories of cookies and/or service providers), and information about the browser, system, and device used; Legal basis: Consent (Art. 6(1)(1)(a) GDPR).
Plugins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include graphics, videos, or maps (hereinafter collectively referred to as “content”).
Integration always requires that the third-party providers of this content process the users’ IP addresses, as they cannot send the content to the users’ browsers without the IP address. The IP address is therefore required to display this content or functionality. We strive to use only content whose providers use the IP address solely to deliver the content. Third-party providers may also use pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Pixel tags can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on users’ devices and may contain technical information about the browser and operating system, referring websites, visit times, and other information about the use of our online offering, and may also be combined with such information from other sources.
Notes on legal bases: If we ask users for consent to use third-party providers, the legal basis for processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we also refer to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons); location data (information on the geographical position of a device or person).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion according to the information in the section “General information on data storage and deletion.” Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for up to two years).
- Legal bases: Consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further notes on processing operations, procedures, and services:
- Integration of third-party software, scripts, or frameworks (e.g., jQuery): We integrate software into our online offering that we retrieve from the servers of other providers (e.g., function libraries used for displaying or improving user-friendliness of our online offering). The respective providers collect the users’ IP addresses and may process them for the purpose of transmitting the software to the users’ browsers, as well as for security, evaluation, and optimization of their offering; Legal basis: Legitimate interests (Art. 6(1)(1)(f) GDPR).
- Font Awesome (provided on our own server): Display of fonts and icons; Service provider: The Font Awesome icons are hosted on our server; no data is transmitted to the Font Awesome provider; Legal basis: Legitimate interests (Art. 6(1)(1)(f) GDPR).
- Google Maps: We integrate the maps of the “Google Maps” service provided by Google. The data processed may include IP addresses and location data of users; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal basis: Consent (Art. 6(1)(1)(a) GDPR); Website: https://mapsplatform.google.com/; Privacy Policy: https://business.safety.google/privacy/. Basis for third-country transfers: Data Privacy Framework (DPF).
Created with the free privacy policy generator by Dr. Thomas Schwenke