Choirspace
Menu

Legal information

Privacy notice

Scope

This privacy notice applies only to the public marketing website at choirspace.de. A separate privacy notice applies to the Choirspace application at app.choirspace.de.

Controller and privacy contact

Daniel Hey

Wolziger Zeile 30a

12307 Berlin

Privacy enquiries: support [at] choirspace.de

Contact form

When you contact us, we process your selected enquiry type, name, and email address, plus any optional choir or ensemble, choir size, and message you provide. We also process technical data needed for delivery and abuse prevention. The enquiry is sent server-side to the configured contact recipient.

The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries), or Art. 6(1)(b) GDPR where the inquiry serves to initiate a contract. To send the inquiry, we use the email service Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). A data processing agreement pursuant to Art. 28 GDPR is in place with Resend. As this processing involves a transfer of data to the United States, it is based on the EU Standard Contractual Clauses (SCCs) as well as, additionally, Resend's certification under the EU-U.S. Data Privacy Framework (DPF). The recipient of the inquiry is Daniel Hey (${obfuscatedContactEmail}). Data submitted via the form is deleted once it is no longer required to process the inquiry, and no later than [e.g., 6 months], unless a longer retention period is required by law.

Server logs and abuse prevention

Servers and security functions may process technical data such as time, requested address, status code, and shortened or technical network identifiers.

Our hosting provider, Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA), automatically processes technical information with each page request, such as IP address, date and time of the request, the requested address (URL), status code, amount of data transferred, referrer, and browser type (server log files). To protect against abuse and overload, we use the security features provided by Vercel (including automatic DDoS protection). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in ensuring the secure and uninterrupted operation of the website). Log files are automatically deleted after 1 hour, unless longer retention is necessary to investigate a specific security incident. A data processing agreement pursuant to Art. 28 GDPR is in place with Vercel; the transfer of data to the United States is based on the EU Standard Contractual Clauses.

Data subject rights

Depending on applicable law, rights may include access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and a complaint to a supervisory authority.

The competent supervisory authority is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, BlnBDI), Alt-Moabit 59–61, 10555 Berlin, Germany, email: mailbox@datenschutz-berlin.de, phone: +49 30 13889-0. To exercise your rights, you may contact us at [your email address]. The right to erasure does not apply where, for example, processing is required to comply with a legal obligation, or where the data is needed to establish, exercise, or defend legal claims. You may object at any time to processing based on Art. 6(1)(f) GDPR; in that case, we will no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests.

Language Version

This privacy policy is provided in both German and English. In case of any discrepancies or ambiguities between the language versions, the German version shall prevail.