Privacy Policy

 

Website and Services of Swing in Konstanz e. V.
Last updated: 10 May 2026

  1. General Information

The protection of personal data is important to us. This Privacy Policy explains which personal data we process in connection with our website, our internal members’ area and our digital association services, for what purposes this data is processed, and what rights data subjects have.

Personal data means any information relating to an identified or identifiable natural person, for example a name, email address, IP address, booking data or communication data.

Our publicly accessible website can generally be used without providing personal data. Where personal data is collected, this is done only to the extent necessary to provide the relevant function, enable communication, organise association activities, manage bookings or comply with legal obligations.

  1. Controller

The controller responsible for data processing is:

Swing in Konstanz e. V.
Zollernstraße 9
78462 Konstanz
Germany

Email: info@swinginkonstanz.de

Represented by the Board:

Jens Weber, Chair
Lara Pfost, Deputy Chair

Further members of the Board:
Daniela Mink, Treasurer
Nadia Stüssi, Secretary
Annika Schreiber, Board Member
Theresa Deifel, Board Member

Further contact details can be found in the Legal Notice.

  1. Hosting and Server Log Files

When our website is accessed, the technical provider or host of the website automatically processes information transmitted by the browser used. This may include, in particular:

  • IP address

  • date and time of access

  • page or file accessed

  • amount of data transferred

  • notification of successful access

  • browser type and browser version

  • operating system used

  • referrer URL

  • hostname of the accessing device

This data is processed in order to technically provide the website, ensure its stability and security, analyse errors and prevent misuse.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and error-free operation of our website.

This data is not combined with other data sources unless this is exceptionally necessary to investigate unlawful use.

Server log files are stored only for as long as necessary for the purposes stated above.

  1. Contact

If you contact us by email or by other means, we process the data you provide, in particular your name, email address, the content of your message and any other information voluntarily provided.

This data is processed in order to handle your request and any follow-up questions.

The legal basis is Art. 6(1)(b) GDPR where the request relates to membership, a booking, an event or another association-related service. In all other cases, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in properly handling requests.

The data will be deleted once it is no longer required to handle the request, unless statutory retention obligations apply or legitimate interests justify further storage.

  1. Internal Members’ Area

We provide members and authorised users with an internal members’ area. The internal members’ area is used, in particular, to organise association activities, inform members and provide access to internal digital association services.

When using the internal members’ area, the following personal data may be processed, in particular:

  • name

  • email address

  • membership status or user authorisation

  • login data

  • technical usage data

  • date and time of access

  • any content voluntarily entered or uploaded by users

This data is processed in order to provide the internal members’ area, authenticate authorised users, manage internal association services, ensure technical security and prevent misuse.

The legal basis is Art. 6(1)(b) GDPR where the processing is necessary for the performance of membership obligations or the provision of agreed association services. Where the processing serves security, error analysis or organisational administration, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable provision of the internal members’ area.

  1. Booking Tool in the Internal Members’ Area

We provide a booking tool in the internal members’ area. The booking tool may be used to book, manage or cancel appointments, classes, training sessions, events or other association activities.

When using the booking tool, the following personal data may be processed, in particular:

  • name

  • email address

  • membership status or authorisation to use the booking tool

  • booked appointments, classes, training sessions or events

  • time of booking, modification or cancellation

  • any voluntary information provided in connection with the booking

  • login and usage data

  • technical data, in particular IP address, browser information, device information, referrer URL, date and time of access

This data is processed in order to provide the booking tool, manage bookings, organise association activities, communicate about booked activities, prevent double bookings, ensure technical security and analyse errors.

The legal basis is Art. 6(1)(b) GDPR where the processing is necessary for the performance of membership obligations, the provision of agreed association services or pre-contractual measures.

Where the processing serves technical security, the prevention of misuse, error analysis or the organisational administration of association activities, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and efficient provision of the booking tool.

Where processing is based on consent, the legal basis is Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.

Data stored in the booking tool will only be stored for as long as necessary for the purposes stated above. Booking data may be stored for a longer period where statutory retention obligations apply or where storage is necessary to document association-related processes.

  1. Use of Google Services in Connection with the Booking Tool

Google services may be used for the operation or organisation of the booking tool. Depending on the technical implementation, this may include, in particular, Google Calendar, Google Forms, Google Sheets, Google Drive, Google Apps Script or comparable Google services.

The provider for users in the European Union is generally:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Processing by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, cannot be excluded.

When accessing or using the booking tool, technical data may be transmitted to Google. This may include, in particular, the IP address of the internet connection used. Depending on the technical integration, browser and device information, the date and time of access, the referrer URL and other technical usage data may also be transmitted to Google.

If users are logged into a Google account while using the booking tool, Google may be able to associate the use of the booking tool with that Google account.

Google services are integrated in order to technically provide the booking tool, manage bookings and organise association activities.

The legal basis is Art. 6(1)(b) GDPR where the use of Google services is necessary to provide the booked or agreed association service. Otherwise, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the functional, efficient and reliable organisation of association activities and booking management.

Where personal data is transferred to the United States or other third countries, this is carried out in accordance with the applicable data protection requirements. Google refers, among other things, to the EU-U.S. Data Privacy Framework and Standard Contractual Clauses for data transfers.

Further information on Google’s processing of personal data can be found in Google’s Privacy Policy:
https://policies.google.com/privacy

Information on Google’s data transfer mechanisms can be found at:
https://policies.google.com/privacy/frameworks

  1. Cookies and Similar Technologies

Our website and internal members’ area may use cookies or similar technologies. Cookies are small text files stored on the device used. Similar technologies may include, for example, local storage or session storage.

We use such technologies where they are technically necessary for the operation of the website, the internal members’ area or the booking tool. This applies, in particular, to functions such as login, session management, security settings or the technical provision of individual functions.

The legal basis for the processing of personal data in connection with technically necessary cookies is Art. 6(1)(f) GDPR. Our legitimate interest lies in the functional, secure and user-friendly provision of our digital services.

Where cookies or similar technologies are used that are not technically necessary, this is done only on the basis of consent. The legal basis is then Art. 6(1)(a) GDPR and Section 25 TDDDG. Consent may be withdrawn at any time with effect for the future.

As of the date of this Privacy Policy, we do not use Google Analytics, Google Ads or other marketing or tracking cookies.

  1. Newsletter

If you subscribe to our newsletter, we process your email address and any other data voluntarily provided in order to send you the newsletter.

Subscription to the newsletter takes place only with your consent. The legal basis is Art. 6(1)(a) GDPR.

You may withdraw your consent at any time with effect for the future, in particular via the unsubscribe link in the newsletter or by contacting us.

After you unsubscribe from the newsletter, your email address will be deleted from the newsletter mailing list unless statutory retention obligations apply or another legal basis permits further storage.

  1. Email Communication and Service Notifications

We may contact users, members or persons who have made a booking by email where this is necessary to organise association activities, perform membership-related services, manage a booking, inform users about changes or handle a request.

Such messages are not promotional newsletters but relate to the respective membership, booking, event or request.

The legal basis is Art. 6(1)(b) GDPR where the communication is necessary for the performance of membership obligations, a booking or an association service. Otherwise, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper organisation and communication of association activities.

  1. Recipients of Personal Data

Within the association, personal data is made accessible only to those persons who need it for the respective purposes.

Data is transferred to third parties only where this is necessary to provide our website, internal members’ area, booking tool or association-related services, where there is a legal obligation, where consent has been given or where another legal basis permits this.

Recipients may include, in particular:

  • technical service providers

  • hosting providers

  • email service providers

  • providers of booking, form, calendar or storage solutions

  • Google, where Google services are used in connection with the booking tool or other functions

  • tax or legal advisers, where necessary

  • authorities, where there is a legal obligation

Where service providers process personal data on our behalf, we conclude data processing agreements pursuant to Art. 28 GDPR where required.

  1. Data Transfers to Third Countries

Personal data may be transferred to countries outside the European Union or the European Economic Area, in particular where services provided by international providers are used, for example Google services.

Where such a transfer takes place, it is carried out only in accordance with the applicable data protection requirements, in particular on the basis of an adequacy decision, appropriate safeguards such as Standard Contractual Clauses, or another permissible basis under the GDPR.

  1. Storage Period

We store personal data only for as long as necessary for the respective purposes.

Longer storage may take place where statutory retention obligations exist, where the data is required for the establishment, exercise or defence of legal claims, or where another legal basis permits further storage.

Once the respective purpose no longer applies and there are no retention obligations or other reasons for further storage, the data will be deleted or anonymised.

  1. Data Security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure.

Please note that data transmission over the internet, especially communication by email, may have security vulnerabilities. Complete protection against access by third parties is not possible.

  1. Rights of Data Subjects

Data subjects have the following rights under the GDPR, in particular:

  • right of access to the personal data processed

  • right to rectification of inaccurate data

  • right to erasure of personal data

  • right to restriction of processing

  • right to data portability

  • right to object to certain processing activities

  • right to withdraw consent with effect for the future

You may contact us at any time to exercise these rights.

  1. Right to Object

Where we process personal data on the basis of Art. 6(1)(f) GDPR, data subjects have the right to object to such processing at any time on grounds relating to their particular situation.

We will then no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing serves the establishment, exercise or defence of legal claims.

  1. Withdrawal of Consent

Where processing is based on consent, that consent may be withdrawn at any time with effect for the future.

The lawfulness of processing carried out on the basis of consent before its withdrawal remains unaffected.

  1. Right to Lodge a Complaint with a Supervisory Authority

Data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data violates data protection law.

For Baden-Württemberg, the competent authority is, in particular:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany

Email: poststelle@lfdi.bwl.de
Website: https://www.baden-wuerttemberg.datenschutz.de

  1. Changes to this Privacy Policy

We may amend this Privacy Policy if our services, the technologies used, legal requirements or actual data processing change.

The current version published on our website applies.