1. Service Provider
Hamburg Space Team e.V.
c/o E-EXK3
Am Schwarzenberg-Campus 3 (E)
21073 Hamburg
Germany
2. Purposes and Legal Bases for Processing
We process personal data for the operation and provision of this website (https://hamburgspace.de), to communicate with you, and to ensure the security and stability of the service. The legal bases are Art. 6(1)(f) GDPR (legitimate interest in secure, stable website operation), Art. 6(1)(b) GDPR (contract/pre-contractual steps, e.g., in response to inquiries), and, where applicable, Art. 6(1)(c) GDPR (legal obligations).
3. Hosting (Cloudflare) and Server Log Files
This website is hosted via Cloudflare Pages and uses the infrastructure of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (including a content delivery network, edge caching, DDoS protection, and a web application firewall). When you visit our pages, Cloudflare processes, among other things, your IP address, date/time, accessed URL/request path, referrer, user agent, HTTP headers, error/status codes, and a Ray ID (request identifier), and logs security-related events in server logs. This processing is carried out for the purposes of technical provision, delivery acceleration, network security (defense against attacks/bot traffic), and service stability. The legal basis is Article 6(1)(f) of the GDPR.
Cloudflare maintains security and operational logs. These are generally retained for a short period and then deleted or anonymized; longer retention may occur in individual cases to preserve evidence in specific incidents. Further information can be found in the Cloudflare Privacy Policy and the Data Processing Addendum.
4. Cookies
We do not use tracking or analytics cookies. Technically necessary cookies may be set via Cloudflare, e.g., __cf_bm (bot management) and cf_clearance (proof of challenge completion), to protect our website from malicious traffic and ensure availability. These cookies do not contain any tracking information used by us.
5. Communication
If you contact us, for example via email, we process the information you provide (e.g., name, email address, message content) to handle your inquiry (Art. 6(1)(b) GDPR). Data will be deleted as soon as it is no longer required for processing and there are no legal retention obligations.
6. Embedded Content and External Links
On our website, we may link to external sites (e.g., Instagram). No third-party content is embedded that transmits data to third parties when loaded. When accessing external links, the privacy policies of the respective providers apply.
7. Recipients and Transfers to Third Countries
Recipients of personal data include, in particular, technical service providers, notably Cloudflare (website hosting/security). This may involve a transfer to the United States. We have a data processing agreement with Cloudflare pursuant to Art. 28 GDPR; international transfers are based on Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR. Additionally, Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF). Further information: Cloudflare DPA (incl. SCC), Cloudflare DPF entry.
8. Retention Period
We process personal data only for as long as necessary for the stated purposes or as required by statutory retention obligations. The data is subsequently deleted or anonymized.
9. Your Rights
You have the rights to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR). In addition, you have the right to withdraw your consent at any time with future effect (Art. 7(3) GDPR). You have the right to lodge a complaint with a data protection supervisory authority. The competent authority includes the Hamburg Commissioner for Data Protection and Freedom of Information Ludwig-Erhard-Str. 22, 20459 Hamburg Tel.: 040 428 54-4040, Email: [email protected]
10. Obligation to Provide Data
The provision of personal data is not required by law. It may be necessary for certain functions (e.g., contacting us); without the relevant information, processing may not be possible.
11. Security
We take technical and organizational measures to protect personal data from loss, destruction, unauthorized access, alteration, or disclosure by unauthorized persons, and we adapt these measures to the state of the art.
12. Web Analytics (Cloudflare Web Analytics)
We use Cloudflare Web Analytics, a privacy-friendly analytics service provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. The JavaScript beacon operates without cookies and collects only anonymized usage data (e.g., pages visited, referrer, device type, browser/operating system information, time of visit). This data is not combined with personal data to create user profiles.
Processing is based on Art. 6(1)(f) GDPR (legitimate interest in statistical analysis to improve our offering). Cloudflare processes data as a data processor; a data processing agreement is in place with Cloudflare, and appropriate safeguards apply for transfers to third countries (Standard Contractual Clauses, EU-U.S. Data Privacy Framework).
Further information can be found in the Cloudflare Web Analytics documentation and in the Cloudflare Data Processing Addendum.
Retention Period / Sampling: The metrics collected by Cloudflare are stored for the periods specified by us in the Cloudflare configuration; the display may be based on a sample. If you have any questions, please contact us at [email protected].