Scope
This privacy notice applies only to the public marketing website at choirspace.de. A separate privacy notice applies to the Choirspace application at app.choirspace.de.
Legal information
This privacy notice applies only to the public marketing website at choirspace.de. A separate privacy notice applies to the Choirspace application at app.choirspace.de.
When you contact us, we process your selected enquiry type, name, and email address, plus any optional choir or ensemble, choir size, and message you provide. We also process technical data needed for delivery and abuse prevention. The enquiry is sent server-side to the configured contact recipient.
The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries), or Art. 6(1)(b) GDPR where the inquiry serves to initiate a contract. To send the inquiry, we use the email service Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). A data processing agreement pursuant to Art. 28 GDPR is in place with Resend. As this processing involves a transfer of data to the United States, it is based on the EU Standard Contractual Clauses (SCCs) as well as, additionally, Resend's certification under the EU-U.S. Data Privacy Framework (DPF). The recipient of the inquiry is Daniel Hey (support@choirspace.de). Data submitted via the form is deleted once it is no longer required to process the inquiry, and no later than 6 months, unless a longer retention period is required by law.
To protect against automated submissions (spam), we additionally use ALTCHA, an open-source, self-hosted mechanism. Before a message is sent, the browser solves a brief computational task (proof-of-work); no personal data is processed, no cookies are set, and no data is transmitted to third parties — the task is created and checked entirely on our own server. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in protecting against abuse and automated requests).
Servers and security functions may process technical data such as time, requested address, status code, and shortened or technical network identifiers.
Our hosting provider, Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA), automatically processes technical information with each page request, such as IP address, date and time of the request, the requested address (URL), status code, amount of data transferred, referrer, and browser type (server log files). To protect against abuse and overload, we use the security features provided by Vercel (including automatic DDoS protection). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in ensuring the secure and uninterrupted operation of the website). Log files are automatically deleted after 1 hour, unless longer retention is necessary to investigate a specific security incident. A data processing agreement pursuant to Art. 28 GDPR is in place with Vercel; the transfer of data to the United States is based on the EU Standard Contractual Clauses.
This app uses Vercel Web Analytics to evaluate page views and basic usage statistics in aggregated form. Vercel Web Analytics does not use cookies. Visitors are distinguished using a hash generated from the incoming request and renewed daily. Data that may be processed includes the visited URL, referrer, approximate region, browser, operating system, device type, and timestamp. The data is used only for aggregated statistics and no custom analytics events are currently tracked.
The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest in the statistical evaluation of how our website is used). The provider is Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA); a data processing agreement pursuant to Art. 28 GDPR is in place with Vercel, and the transfer of data to the United States is based on the EU Standard Contractual Clauses (SCCs).
This website does not use cookies and does not store data in your browser's local storage. The evaluation described in the “Web Analytics” section above is cookieless.
Depending on applicable law, rights may include access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and a complaint to a supervisory authority.
The competent supervisory authority is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, BlnBDI), Alt-Moabit 59–61, 10555 Berlin, Germany, email: mailbox@datenschutz-berlin.de, phone: +49 30 13889-0. To exercise your rights, you may contact us at support@choirspace.de. The right to erasure does not apply where, for example, processing is required to comply with a legal obligation, or where the data is needed to establish, exercise, or defend legal claims. You may object at any time to processing based on Art. 6(1)(f) GDPR; in that case, we will no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests.
This privacy policy is provided in both German and English. In case of any discrepancies or ambiguities between the language versions, the German version shall prevail.