1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Ivo Arndt
Merseburger Straße 138, 04177 Leipzig, Germany
Contact: via the contact form of this website; no e-mail address is published on purpose.
The German-Furs Network is a private, non-commercial project. No Data Protection Officer has been appointed, as the statutory thresholds under Art. 37 GDPR / § 38 BDSG (German Federal Data Protection Act) are not met.
2. General information on data processing
Personal data is processed only to the extent necessary to provide a functioning platform and the content and services offered here, or where explicit consent has been given. Processing regularly takes place only with consent (Art. 6(1)(a) GDPR), for the performance of or entering into a contract (Art. 6(1)(b) GDPR), or on the basis of a legitimate interest (Art. 6(1)(f) GDPR), to the extent legally permissible. The applicable legal basis is stated for each processing activity below.
No tracking, no third-party analysis of usage behavior, and no profiling take place. No external resources such as fonts, scripts, images, or web fonts from third-party providers are loaded — all content is served exclusively from this site's own server. Personal data is only transferred to third parties where expressly described in this policy (see section 14).
Unless stated otherwise, the retention period depends on how long the respective data is required for the stated purpose; an overview table is provided in section 16.
3. Hosting, server, and application logs
When this website is accessed, the web server processes technically necessary connection data (e.g. the page accessed, timestamp, browser type used) to provide the website reliably and securely (Art. 6(1)(f) GDPR).
- Application log: contains no e-mail addresses; IP addresses are anonymized before storage (IPv4: last octet removed; IPv6: truncated to /64). Retained for at most 30 days, then automatically deleted.
- Web server access log and monthly report: the web server additionally logs, for this domain, the IP address (anonymized the same way as the application log), HTTP method, the address requested (without query parameters; security tokens contained in addresses are masked), timestamp, status code, amount of data sent, response time, referrer (likewise without query parameters), and browser identifier (Art. 6(1)(f) GDPR). Other domains operated on the same infrastructure are pure redirects with no application behind them and generate no log data of their own. Raw data is retained for at most 40 days, then automatically deleted. Once a month, a purely local aggregated statistics report is generated from it — without any third party and without location lookup — covering figures such as request counts, referrers, and browser/OS distribution; it no longer contains individual requests and cannot be attributed to any person. These reports serve exclusively for technical operations analysis; no profiling and no linkage to user accounts takes place. Reports are retained for at most 12 months on a rolling basis, then automatically deleted.
- Status page (
status.german-furs.net): it shows whether this website is reachable. On each request the status page's web server processes the IP address, time, HTTP method, requested path (without query parameters), status code, amount of data sent and browser identifier (Art. 6(1)(f) GDPR, secure and stable operation); no referrer is stored. The IP address is shortened before it is written to the access log (IPv4: last octet removed; IPv6: last 64 bits removed); that log is deleted after 14 days at the latest. For abuse handling and troubleshooting the web server additionally keeps an error log with the full IP address, the requested address (including any query parameters) and the referrer; it is deleted after 7 days at the latest. Security and system logs of the server (for example block lists against repeated failed accesses, system messages) may contain the full IP address and are deleted after 30 days at the latest. The status page sets no cookies, loads no third-party resources and uses no analytics; three to four display settings (colour theme, appearance of the status bars and times, page language) are kept in your browser's local storage and are not transmitted. It is operated in the EU by netcup GmbH (see section 14), with which a data processing agreement pursuant to Art. 28 GDPR has been concluded. - Server error and system logs: for troubleshooting and abuse handling the web server keeps an error log with the full IP address, the requested address (including any query parameters) and the referrer (Art. 6(1)(f) GDPR); retained for at most 7 days. Other system logs of the server (block lists against repeated failed accesses, system messages, login and audit logs of the administration) may contain the full IP address, and so may the submission log of the system mailer, which can hold the recipient addresses of e-mails that are not sent directly through the mail server; retained for at most 30 days. The logs of the database (error log and slow-query log, the latter can contain the text of a slow query and thus stored values) and of the PHP runtime are retained for at most 28 days.
- Security log (failed login attempts, password resets, role changes): recorded to detect and prevent abuse and may include the full IP address (Art. 6(1)(f) GDPR). Retained for at most 7 days, then automatically deleted.
- Request limiting by the web server: to protect against overload and abuse the web server limits the number of requests and simultaneous connections per IP address (Art. 6(1)(f) GDPR). For this the full IP address is held only in working memory while the access is active and is not written to disk; it is gone after a restart of the server.
- Login lockout on repeated failures (brute-force protection): after several failed login attempts, an increasing wait time is temporarily stored per account and per IP address (Art. 6(1)(f) GDPR). Storage expires automatically; no longer-term retention takes place.
4. Cookies and sessions
This website uses only technically necessary cookies:
- a session cookie required for signing in and using the protected area (automatically deleted after one hour of inactivity), and
- optionally, after selecting the "stay signed in" feature, a login cookie valid for up to 30 days.
Both cookies are strictly necessary for operating the website (§ 25(2) No. 2 TDDDG) and are therefore exempt from the consent requirement under § 25(1) TDDDG. No tracking, marketing, or analytics cookies are set; a cookie consent banner is therefore not required and is not shown.
5. Registration and user account
Registration collects an e-mail address, an internal username, and a publicly visible display name (Art. 6(1)(b) GDPR, pre-contractual measures). Registration requires self-declaring to be at least 16 years old (Art. 8 GDPR); no separate parental-consent path is offered, and registration under 16 is technically blocked. The e-mail address is additionally checked against a local list of known disposable e-mail domains to prevent abuse — no request is made to any third party for this purpose.
Sign-in is available via passkeys (WebAuthn) or a time-limited login link sent by e-mail (valid for 15 minutes, stored only as a hash). A traditional password is not used for signing in.
Failed and successful login attempts are stored with a timestamp, a coarse device class (browser/OS family only, not a full identifier), and status for 30 days (Art. 6(1)(f) GDPR), so account holders can be shown suspicious activity.
Further account logs and block lists (Art. 6(1)(f) GDPR, accountability and abuse prevention): changes to an account's rights and ranks (time, affected account, granting party, old/new value, reason) and operations around address data (creation, sharing, viewing, deletion — never the address content itself) are logged and deleted with the account. If an account is permanently banned and deleted, only an irreversible hash (HMAC-SHA-256) of the e-mail address and, if linked, the Telegram ID is kept on a block list so the person cannot simply re-register with the same details; no plaintext is retained. To limit abuse (sign-in attempts, forms, uploads), short-lived counters keyed by your IP address or account identifier are kept in memory (Redis) and expire automatically. When you change your e-mail address, the previous address receives a security notice; the new address only takes effect after confirmation.
6. Address data and verification
For certain features (e.g. proof of legal age, sharing with event organizers or moderators they have appointed), name, date of birth, and address can be provided. This data is stored encrypted and only transiently decrypted for display while a share is actively being used; shares are time-limited to 15 minutes and viewable only once (Art. 6(1)(a) or (b) GDPR, depending on context). The date of birth is additionally displayed unencrypted on the public profile only if this has been explicitly consented to; consent can be withdrawn at any time in the control center, upon which the public display is removed immediately.
Only members holding the Administration or Moderation administrative rank review addresses (for Level 2). So that these people can be reached in person, a dedicated public page ("Team") shows the display name of every member holding an administrative rank (Administration, Moderation, Event/ Carpool/Lodging management), each linked to their public profile (Art. 6(1)(f) GDPR, legitimate interest in these role-holders being reachable). The listing ends automatically once the rank is revoked or the account is deleted.
7. Profile picture and uploaded files
Uploaded images (profile picture, preview images for events, carpools, and lodging listings) are re-encoded server-side; all metadata (including EXIF and GPS data) is completely removed in the process. Files are stored under a random technical identifier; the original file name is not retained (Art. 6(1)(b) GDPR).
8. Events, carpools, and lodging (BnB)
Participating in an event, carpool, or lodging listing processes the data required for that purpose (e.g. participation status, and any answers to participation questions defined by the listing's creator) (Art. 6(1)(b) GDPR). By default, only the participant count is publicly visible, not the names of individual participants — those are otherwise accessible only to the listing's creator and the responsible moderators. Withdrawing from participation deletes the associated record.
The listing's creator can optionally turn on a public participant list (Art. 6(1)(f) GDPR, legitimate interest). When on, the event's, carpool's, or lodging listing's public page shows, for every approved participation, only the display name, linked to the public profile — nothing else (no status, no answers, no guests). A registering participant is shown a notice about this and can hide themselves from that list at any time, without affecting their participation itself (withdrawal of consent, Art. 6(1)(a) GDPR). An archived event no longer shows such a list.
For events, the creator and responsible moderators can additionally record whether a confirmed participant actually showed up on-site, and check off optional, self-defined tracking points per participation option (e.g. "attended", "paid") — a purely internal, reversible observation by the event's own staff, visible only to that group (Art. 6(1)(f) GDPR). They can also download the participant list of an event, carpool, or lodging listing (name, status, answers to participation questions, and for events the tracking notes above) as a CSV file; the file is generated on demand and not stored on the server.
For events that allow it, a registered participant may add up to a maximum set by the event's creator of additional guests accompanying them (called "guests" of the event participation in the application — not to be confused with the lodging guests described further below in this section). These accompanying guests are tracked purely anonymously as a running position (e.g. "Guest 1", "Guest 2"); no name or other identifying feature is ever collected. Only the count, any answers to participation questions the creator has enabled for guests, and an optional on-site attendance mark by the event staff are processed — each visible only to the group named in the first paragraph above, and counting toward the event's own participant limit. The legal basis is legitimate interest (Art. 6(1)(f) GDPR); the registering participant actively confirms via a checkbox, at the time guests are added, that they are authorized to do so and vouch for the accuracy of the information submitted. Because no name or other identifying feature is stored, guests have no data-subject rights of their own beyond those of the registering participant; their data is automatically deleted together with the associated participation record or the event itself.
The creator (or an appointed moderator and the administration) can add people who turn up on site and have no account, or cannot register, by name alone — as a participant of an event, carpool or lodging listing and, for events, additionally on participation options (e.g. a sleeping place, even without taking part). Only the name entered by the creator (free text, at most 100 characters), a running number and, for events, an attendance mark and the lists the person was put on are processed. Such entries are marked "added on site" for the team and are visible only on the management page and in the team's CSV download — never in the public participant list, the history log, notifications or application logs; the public participant count includes them. The legal basis is the organiser's legitimate interest in running the event on site (Art. 6(1)(f) GDPR). Because the people concerned have no account there is no self-service for them; they can contact the creator or us at any time and ask for their entry to be removed. The entries are deleted automatically together with the event, carpool or lodging listing; when an event is archived only the name remains as an entry of the archive count, without any link to an account, and the entries on participation options are deleted.
For events where the creator allows it, people can take part without an account. For this, a display name, an e-mail address and a language as well as the answers to the participation questions (including the choice of places) are entered; guests cannot be brought along. The participation is only requested after the person has clicked a confirmation link (valid for 24 hours) sent to their address (double opt-in). The legal basis is the performance of the requested participation (Art. 6(1)(b) GDPR); the voluntary answers to participation questions are based on your consent (Art. 6(1)(a) GDPR), which you give by submitting them and can withdraw by changing the answers or withdrawing the participation. To protect the form against abuse, the shortened IP address and a hash of the e-mail address are held as counters in the in-memory service (Redis) and expire automatically after one hour (Art. 6(1)(f) GDPR); disposable addresses, addresses of accounts and banned addresses are rejected. For this a technical account without any way to sign in is stored (only name, address, language and the participation itself). The details are visible only to the creator, moderators they appointed and the administration on the event's management page (the e-mail address only to this group, never in the CSV download), marked "Ohne Konto" ("without account") — never in the public participant list and never publicly; the participant count includes them. Messages about this participation (confirmation, approval, rejection, moving up from the waitlist, cancellation and important changes to the event) are sent by e-mail in the language of your request — without a separate setting, because they are part of the requested service, and never via Telegram. With the personal link in the confirmation e-mail (or a new link requested via "send the link to my participation again", which invalidates the old one) you can see your status, change your answers and withdraw the participation; withdrawing deletes your data at once. The link is an access key to exactly this participation: do not pass it on. It is part of the address line and can therefore appear in the web server's access log (at most 40 days, shortened IP address) and in the browser history; the pages are excluded from search engines and intermediate caches and do not hand the link on to other websites. Deletion: an unconfirmed request after 24 hours, a confirmed participation on withdrawal, on removal by the creator or with the event (at the latest in the daily cleanup), otherwise when the event is archived (30 days after it ends) — then the e-mail address and the answers are deleted and only the name remains in the archive count, without any link to an account. In the event's change log such people only appear as "Person ohne Konto" ("person without account"), never by name. If you later register with the same e-mail address, this participation is assigned to your new account once your registration is confirmed, and the personal link becomes invalid.
For carpools, the vehicle's license plate is visible only to confirmed passengers, the offering user, and moderation staff; publicly, only the vehicle's make, model, and color are shown. For lodging listings, the exact location is shown only to confirmed guests, the offering user, and moderation staff; publicly, only an approximate location rounded to two decimal places (roughly 1.1 km precision) or the distance to the associated event is shown.
Feedback on events, carpools, and lodging listings is moderated before public display; for carpools and lodging listings, the consent of the person named in the feedback is additionally required before it is displayed with a name.
Bookmark list and contact list: users can put events, carpools, and lodging listings on a private bookmark list (Art. 6(1)(b) GDPR, providing the requested function) and add other users to a private contact list from their public profile page (consent, Art. 6(1)(a) GDPR — adding is an explicit action). Only the reference between your account and the entry or the other account is stored. Both lists are visible to their owner only; the person added is not informed and cannot query who has them as a contact. The contact list is capped at 500 entries, is part of the data access export (your own list only), and is deleted as soon as either account is deleted.
9. Messages: tickets and inquiries
Tickets are messages to staff (Administrators and Moderators) — e.g. bug reports, criticism, suggestions, or reports about rule-violating content. They are stored permanently for as long as the associated account exists and are deleted together with the account (Art. 6(1)(f) GDPR).
Inquiries are private messages between a user and the creator of an event, carpool, or lodging listing. They are visible only to the two parties involved — staff has no access to them. Inquiries are deleted as soon as the associated listing or either of the two involved accounts is deleted. When ownership of a listing is transferred, the new responsible person gains access to the prior message history for that listing.
10. Contact form and partnerships
Messages submitted via the contact form (name, e-mail address, subject, message) are delivered exclusively by e-mail and are not stored in the database (Art. 6(1)(b) or (f) GDPR).
To defend against automated advertising and abuse, every submission is checked by a content filter, and its outcome is recorded in a log: whether the message was delivered or discarded, the short technical reason (e.g. the matched rule, the number of links or the bot-protection trigger), the domain part of the sender's e-mail address, and the shortened IP address (IPv4: last octet set to 0; IPv6: truncated to /64). Name, full e-mail address, subject and message text are not part of this log. The log is visible to the administrators only and is deleted automatically after 30 days (legitimate interest, Art. 6(1)(f) GDPR, in keeping the contact form and the e-mail inbox free of abuse). Advertising messages are not wanted and are discarded.
Partnership details (name, linked website address, image) are stored for as long as the partnership exists, and are removed at the latest 30 days after rejection or termination, or when the associated account is deleted.
11. Visitor statistics
To anonymously determine page views, a hash is formed from the IP address, browser identifier, and a daily-rotating random value, which is kept only in a temporary store (Redis) for 24 hours to prevent counting the same visit twice on the same day (Art. 6(1)(f) GDPR). Only the aggregated number of views per day is stored permanently — without any personal reference. No cookie is set for this purpose; known automated accesses (bots) are excluded from the count.
12. Notifications and Telegram integration
Notifications: You decide in the control center which events you want to be told about (e.g. decisions on your participations, changes and cancellations of events, taxis or BnBs you are involved in, new events and articles, replies to your tickets). No category is preselected — every notification is sent solely on the basis of your explicit consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by switching the category off. Your choice per category is stored, as well as — until it is sent, at most 7 days — the message to be sent. If your Telegram account is linked and reachable, you receive the messages exclusively there, otherwise by e-mail; never on both. Sign-in, confirmation and security e-mails (login link, confirmation of registration and e-mail change, data-password reset) are independent of this and are always sent by e-mail (Art. 6(1)(b) GDPR).
Telegram link: This website optionally offers linking the user account with a Telegram account to receive notifications (e.g. ticket replies, status changes on one's own listings) via the Telegram messenger service. Linking only ever happens on the user's own initiative and with consent (Art. 6(1)(a) GDPR).
While the link is active, the Telegram user ID, Telegram username, first name as stored with Telegram and — if Telegram can no longer be reached (bot blocked, chat deleted) — the point in time from which e-mail is used instead are processed. For every interaction with the Telegram bot, the action performed and its outcome are logged — never the content of any message sent — with a retention period of at most 30 days. The link can be removed independently at any time in the control center.
Important note on third-country transfer: Telegram is operated by Telegram FZ-LLC, headquartered outside the European Union. Using the Telegram link therefore transfers the data named above to a third country. Telegram's own privacy policy additionally applies in this respect. Anyone wishing to avoid this can use every feature of this website without linking Telegram.
To help prevent fraud, a list of known Telegram scam accounts provided by a third party is also checked against (Art. 6(1)(f) GDPR); this does not concern data of this website's own users. No automated objection process exists for an entry in this external list; please direct any questions via the contact form.
Security bot for Telegram groups: a second bot protects connected Telegram groups. When someone joins a group, their Telegram ID, username and the group context are processed and checked against the scam list and the block list; matches are removed from the group automatically (Art. 6(1)(f) GDPR, protecting the group from fraud). This also affects people who have no account on this website; only Telegram ID, username and group context are stored, for at most 30 days, never message contents. You can object via the contact form.
13. Announcements on Bluesky and Mastodon
When an event is approved, a short announcement is automatically posted to Bluesky and Mastodon. It contains only already-public, non-personal information about the event itself (name, date, location, participant limit if set, link) — the name of the event's creator or of any participant is never included. This feature therefore does not involve any personal data.
The website also links, in its navigation, to the network's own channels on Telegram, Mastodon, Bluesky and Facebook. These are plain links without embedded content or plugins: visiting this website transmits no data to those platforms. Only when you click one of these links do you leave this website, and the respective platform's own privacy policy applies.
14. Processors and service providers
- Server hosting: the website and its database run on a rented server of netcup GmbH (Emmy-Noether-Str. 10, 76131 Karlsruhe, Germany; data centre in the EU). A data processing agreement under Art. 28 GDPR has been concluded with this provider.
- E-mail delivery: system e-mails (e.g. login links, notifications) are sent via the mail server of the provider united-domains AG (Germany). A data processing agreement under Art. 28 GDPR has been concluded with this provider.
- Telegram (Telegram FZ-LLC, third country): only when an account is linked or through the security bot, see section 12.
- Bluesky/Mastodon: receive only public information about events and articles, no personal data.
- Uptime monitoring: the website's availability is monitored using a self-hosted monitoring solution (Uptime Kuma); no data is transferred to third parties in the process. The alert e-mails of this solution to the administration (only the name of the monitored site, status, time and error text) are sent through the same mail server as the system e-mails (see above); the public status page is described in section 3.
No further external services (e.g. analytics tools, external fonts, Gravatar, or comparable services) are integrated.
15. Backups
For resilience, the database and uploaded files are backed up daily. Backups are asymmetrically encrypted before leaving the server; the corresponding private key is kept exclusively offline, outside the server. Backups are automatically deleted after 30 days; the same period applies to any copy additionally transferred to another system. A backup is also taken before a database update.
16. Retention periods at a glance
| Data | Retention |
|---|---|
| Application log | 30 days |
| Web server access log (raw data) | 40 days |
| Web server error log (full IP) | 7 days |
| Server security and system logs (block lists, system messages, login and audit logs; full IP where recorded) | 30 days |
| Database and PHP runtime logs (including the slow-query log) | 28 days |
| Monthly statistics reports (aggregated) | 12 months (rolling) |
| Security log | 7 days |
| Status page: access log (shortened IP) / error log (full IP) / security and system logs (full IP where recorded) | at most 14 days / 7 days / 30 days |
| Login lockout (brute-force) | automatic expiry, no long-term retention |
| Login history | 30 days |
| Counters for abuse limiting (IP/account) | expire automatically within the respective time window |
| Role and address-access log | until the account is deleted |
| Block list (hashes only) | permanent, only after a permanent ban |
| Session (inactivity) | 1 hour |
| "Stay signed in" | 30 days |
| E-mail login link | 15 minutes, single use |
| Confirmation link (registration / e-mail change) | 24 hours |
| Password reset link | 1 hour |
| One-time address data share | 15 minutes, viewable once |
| Unconfirmed registration | automatically deleted after 7 days |
| Participation without an account: unconfirmed request (name, e-mail address, answers) | automatic deletion after 24 hours |
| Participation without an account: confirmed participation (name, e-mail address, answers) and personal link | until withdrawal, removal or deletion of the event (at once, or in the daily cleanup), at the latest when the event is archived (30 days after it ends); only the name remains in the archive |
| Telegram interaction log | 30 days |
| Contact form log (outcome, reason, sender domain, shortened IP) | 30 days |
| Notifications waiting to be sent (queue) | until sent, at most 7 days |
| Bookmark list, contact list | until you remove them, at the latest when one of the accounts involved is deleted |
| Public participant list (display name) | until withdrawal, until you hide yourself, or until the entry or account is deleted |
| Backups | 30 days |
| Account deletion: removal from all systems incl. logs/backups | within 30 days |
Processing not listed in this table is retained for as long as its purpose continues to apply (e.g. participations, tickets, inquiries — see the respective sections above), and is removed at the latest when the associated account or listing is deleted.
17. Rights of data subjects
You have the right to access the data stored about you (Art. 15 GDPR), to have inaccurate data corrected (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR), to data portability (Art. 20 GDPR), and to object to processing based on legitimate interest (Art. 21 GDPR). Any consent given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR).
Self-service tools are available in your account's control center for this purpose: a complete data export in JSON format (access), the ability to correct your own details, and complete deletion of your account including all personal data. The export covers account data, passkeys (without key material), sign-in history, tickets and inquiries including your own messages, participations, bookmarks, feedback (written and received), your own listings, moderator roles, pending ownership transfers, partnerships, badges, flags, counters, the role and address-access log, address shares you created, the Telegram interaction log, "stay signed in" details, and your address (only after entering your data password, since only it can decrypt it). After account deletion, data is removed from all systems, including logs and backups, within 30 days.
Exception: published content you authored remains — articles, approved experience reports (event, taxi, BnB) and archive snapshots of past events — together with the display name shown with it, which you chose yourself as the author attribution (Art. 6(1)(f) GDPR: continuity of editorial content). The link to your account is removed on deletion. If you want the name removed as well, an informal message is sufficient (Art. 17 GDPR); we then replace it with "Deleted account" and keep only the text. Experience reports that were not yet approved are deleted with the account. Likewise, frozen display names without any link in change logs remain, since they can no longer be attributed to an account after deletion; messages you wrote in other people's threads remain with the author shown as "Deleted account"; in tickets that reported you, your frozen name is replaced by a placeholder.
People who take part in an event without an account have no control center: they can change their answers and withdraw the participation — which deletes their data at once — themselves via their personal link (rectification, erasure, withdrawal of consent). Access, restriction and all other rights are granted on an informal request (see below), the access including the participations stored for their e-mail address; we check that the request comes from the address concerned.
For any request that cannot be handled through the self-service tools, an informal message via the contact form, or to the postal address given above, is sufficient.
18. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. The competent authority is generally the supervisory authority of the German federal state in which the controller is based:
Sächsische Datenschutz- und Transparenzbeauftragte (Saxon Data Protection
and Transparency Commissioner)
Maternistraße 17, 01067 Dresden, Germany
Postal address: Postfach 11 01 32, 01330 Dresden, Germany
Phone: +49 351 85471-101
E-mail: post@sdtb.sachsen.de
Website: https://www.datenschutz.sachsen.de
19. Changes to this privacy policy
This privacy policy is updated as needed, for example as the platform is further developed or the legal situation changes. The version available on this page at the time of your visit applies.