Skip to content
VielRespektZentrum VielRespektZentrum Essen · seit 2019
Rooms The House Events About Funding Join in Request a room DE

Privacy policy

Protecting your data matters to us. This website is deliberately built to be data-minimal: no external trackers, no advertising, no social-media plugins.

This is a translation for convenience. In case of doubt, the German version prevails.

Controller

VielRespektStiftung, Rottstr. 24–26, 45127 Essen, Germany, info@vielrespektstiftung.de

Hosting

This website runs on a server in Germany (Hetzner Online GmbH, Nuremberg). No data is transferred to third countries as part of website operation.

Server log files

When the website is accessed, technical access data is processed automatically (IP address, date and time, page accessed, referrer, browser type). This data serves secure, stable operation and anonymous statistics, is not merged with other data sources and is deleted after a short time. The legal basis is our legitimate interest (Art. 6 (1) (f) GDPR).

Cookies

For website visitors we set no cookies and use no analytics or tracking tools. Only if you actively sign in do you receive a technically necessary session cookie: in the internal editorial area (login at /admin) and in the booking portal for registered organisations. These cookies solely enable the login and protect forms (CSRF protection), contain no tracking functionality and expire when you sign out or the session ends. Legal basis: provision of the service you use (Art. 6 (1) (b) GDPR) and § 25 (2) no. 2 of the German TDDDG.

Fonts

All fonts are stored locally on our server and delivered from there. No Google Fonts or other external font services are loaded; visiting a page creates no connection to third parties.

No external services

This website uses no Google Maps, no Google reCAPTCHA and no plugins or buttons from Facebook, Instagram, X/Twitter or other networks. No data is transmitted to such providers.

Room inquiry form

If you use the inquiry form, we process the data you provide (name, email address and optionally association/initiative, preferred room, preferred date, number of people, equipment needed, message) solely to handle your request. The data is stored in our database and sent by email to the foundation as well as to you as a confirmation of receipt. Email is sent via our mailbox provider united-domains AG (Starnberg, Germany). No transfer to other third parties takes place. The legal basis is the handling of your request and our legitimate interest (Art. 6 (1) (b) and (f) GDPR). To protect against automated spam we use a field invisible to you (honeypot) and a short timing check – no external captcha service.

E-mail correspondence and matching to a file

When you write to us or we reply to you, we process the content of those e-mails (sender and recipient address, subject, message text, timestamp) in order to handle your request and keep the exchange traceable. Our mailbox is hosted by united-domains AG (Starnberg, Germany).

So that correspondence remains findable alongside an inquiry or a using organisation, our system transfers e-mails from that mailbox into our administration software automatically and matches them to the corresponding inquiry or organisation by e-mail address. In doing so:

  • No attachments are transferred and there is no full-text evaluation or content analysis – matching is based solely on the e-mail address.
  • If an e-mail cannot be matched to any inquiry or organisation, it remains unmatched and our team can assign it manually. A new record for a person or organisation is never created automatically.
  • There is no automated decision-making within the meaning of Art. 22 GDPR: matching changes neither the processing status of your request nor triggers any measure. The only thing recorded is when we first replied – as an internal measure of our response time.

Legal basis: handling of your request or performance of the usage relationship, and our legitimate interest in orderly case handling (Art. 6 (1) (b) and (f) GDPR). No data is passed on to third parties.

Organisation accounts and booking portal

Organisations that use our rooms regularly can receive an account for our booking portal. For this we process: the organisation's name, e-mail address and name of the contact person(s), login credentials (passwords are stored exclusively as a cryptographic hash), and the bookings created via the portal (room, time period, number of people, purpose) including their history with on-site check-in and check-out. We use this data to manage room usage, coordinate with the organisation and – for paid usage – for billing. Legal basis: performance of the usage relationship (Art. 6 (1) (b) GDPR). No data is passed on to third parties.

Photo documentation at check-out

At the check-out of a room booking, the condition of the room may be documented with photos. The photos show the room, not the people present, and serve exclusively to document the handover condition (e.g. damage or cleaning issues). They are stored on our server in Germany and automatically deleted after 90 days. Legal basis: our legitimate interest in a traceable room handover (Art. 6 (1) (f) GDPR).

Sign-in to the internal area (Google)

Our team signs in to the internal administration area using our organisation's Google accounts (Google Workspace, provider: Google Ireland Limited, Dublin). During sign-in, credentials data (team account e-mail address, time of login) is exchanged between our website and Google. This concerns only staff and appointees of the foundation – not website visitors and not users of the booking portal. A transfer to third countries by Google cannot be ruled out; Google is certified under the EU-US Data Privacy Framework.

Retention periods

We store personal data only as long as necessary for the respective purpose:

  • Room inquiries: 24 months after receipt, after which personal details are anonymised (statistical key data is retained without personal reference)
  • E-mail correspondence transferred into the administration software: 24 months after the e-mail was received or sent; addresses, subject and message text are then removed
  • Booking data: personal plain-text data 24 months after use
  • Check-out photo documentation: 90 days
  • Issue reports (tickets): 24 months after resolution
  • Technical change logs of the system: 36 months
  • Data subject to statutory retention obligations (e.g. billing records) remains unaffected and is retained in our accounting according to the statutory periods

Backups

Our systems are backed up regularly. Backup copies are encrypted and automatically rotated. When data is deleted or anonymised, deletion may take up to 14 days to propagate to backup copies; restores are performed only to remedy technical failures, and any restored data that had been deleted is deleted again.

Your rights

You have the right to information, correction, deletion, restriction of processing, data portability and objection. Please contact info@vielrespektstiftung.de. You also have the right to lodge a complaint with the supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit NRW, www.ldi.nrw.de.

Last updated: 12 August 2026