Privacy policy
Information under Art. 13 and 14 GDPR · as at 11.08.2026
This translation is part of the information, not a decoration — Art. 12(1) GDPR requires us to inform you in clear and plain language, and for many of our members that language is not German. Should this text and the German version nevertheless differ, the German wording governs. You may of course write to us in English; we answer in the language you wrote in.
The short version does not replace the policy — every point is set out below, with its purpose, legal basis and storage period.
1. Controller
The controller for the data processing on this website is:
ICD360S e.V.c/o Ionut-Claudiu Duinea
Elsa-Brandström-Straße 13
89231 Neu-Ulm
E-mail: datenschutz@icd360s.de
No data protection officer has been appointed. The conditions of § 38 (1) BDSG (as a rule at least 20 persons constantly engaged in automated processing) are not met. Please address data protection enquiries to the address above. It reaches the same mailbox as kontakt@icd360s.de; the separate address exists so that requests for access or erasure do not get lost among general enquiries — those requests are subject to deadlines.
2. What happens when you visit this website
When you call up a page, your browser transmits technically necessary data to our server, which are stored there in log files:
- IP address of the requesting device
- date and time of access
- name and path of the file retrieved
- volume of data transferred and status message
- browser and operating system used (user agent)
- the page visited before (referrer), where transmitted
Purpose: delivering the page, operational security and
defence against attacks.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies
in the trouble-free and secure operation of the site.
Storage period: the logs are deleted automatically after
14 days at the latest. Where they are needed to investigate a specific
security incident, the entries concerned are kept until the matter has been
finally clarified.
These data are not combined with other data sources, and they are not evaluated for advertising or analytical purposes.
3. No analytics, no external services
This website uses neither analytics nor tracking tools. No fonts, maps, videos, scripts or other content are loaded from third-party servers; merely looking at the site therefore transmits your IP address to no one but us. There are no social media buttons and no profiling.
The only script
The page runs a single short script. It comes from us, sits inside the page itself and is not loaded from anywhere. Its entire task: to hide the floating symbols at the edge of the screen while you scroll, and to show them again as soon as you stop.
It establishes no network connection, stores nothing on your device and reads nothing from it. It therefore processes no personal data, and § 25 TDDDG is not engaged — that provision concerns the storing of information on, and the reading of information from, terminal equipment, and neither takes place. If JavaScript is switched off in your browser, the symbols simply stay put; nothing else changes.
Cookies for your display settings
Using the symbol at the right-hand edge of the screen you can adapt the presentation to your needs: text size and typeface, line, paragraph and letter spacing, line length, contrast, colour scheme, the emphasis of links and headings, the strength of the keyboard focus outline, and motion effects. Only once you click one of these settings do we store it in a cookie — so that the page looks the way you set it up next time you come.
Without such a click, nothing is stored. The presentation then follows the settings of your device, which are not transmitted to us.
- Names
thema,schrift,schriftart,kontrast,zeilen,absatz,abstand,breite,links,titel,fokus,bewegung,stimme— one per setting, and only for those you have actually changed- Content
- nothing but the keyword chosen, such as
dunkel,grossorhoch. No identifier, no marker, no serial number, no link to you as a person - Storage period
- one year. „Reset everything" in the same panel deletes them all at once; in your browser you can remove them yourself at any time
- Legal basis
- § 25 (2) no. 2 TDDDG — the storage is strictly necessary in order to provide the function you have expressly asked for. No consent is required for it, which is why this site shows no consent banner.
Because these cookies work without any link to a person, no processing of
personal data under the GDPR takes place in that respect. They are set as
Secure, HttpOnly and SameSite=Lax: they
are transmitted only in encrypted form, cannot be read by scripts and do not
leave this website.
One cookie for your draft application
When you call up the membership application, we set one further cookie. It contains nothing but a random number. That number is the key with which the application you have begun is found again on your next visit — which is why you can stop half-way through filling it in and carry on later, without an account and without a password.
- Name
icd_antrag- Content
- 32 random characters, nothing else. Your entries are not in the cookie but on our server — otherwise they would travel across the network with every single page view, including every one that has nothing to do with the application
- Storage period
- 30 days. After that it expires, and the draft is deleted
- Legal basis
- § 25 (2) no. 2 TDDDG — without this cookie we could not find the application you have begun, that is, we could not provide the function you expressly asked for. No consent is required for this either
There are no other cookies — in particular none for analytics, reach measurement or advertising.
Why this site shows no cookie banner
You are not asked for your consent on these pages. That is not an omission but the consequence of there being nothing you would have to consent to.
A consent banner is required under § 25 (1) TDDDG where a website stores information on your device, or reads information from it, that is not strictly necessary — that is, above all for counting pixels, reach measurement, advertising and recognition cookies. None of that happens here.
Only two things are stored: what you have set yourself — text size, contrast, colour scheme and the other presentation preferences — and, if you start an application for membership, the random number with which your draft is found again. Both are exempt from the consent requirement under § 25 (2) no. 2 TDDDG, because they are strictly necessary in order to provide precisely the function you expressly asked for. Anyone who does not start an application never gets that second cookie at all.
This statement holds as long as the site stays as it is. If a map, an embedded video or a visitor statistic were added later, a banner would be needed — and this section would have to be the first thing to go.
4. Encryption
The site is served exclusively over a TLS-encrypted connection (HTTPS). Requests over unencrypted HTTP are redirected to HTTPS automatically.
5. Contact form
If you use the contact form, you transmit to us your name, your e-mail address and your text. The message is delivered to our mailbox as an e-mail and dealt with there; there is no database and no ticket system.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in
answering enquiries; for contract-related matters Art. 6(1)(b) GDPR.
Storage period: until the matter has been finally dealt with,
then erasure, unless statutory retention periods stand in the way.
No captcha, no external service. Against automated
submissions we use an additional field invisible to you and a signed timestamp
in the form. Both stay on our server; nothing is transmitted to third parties
and nothing is stored on your device.
5a. Withdrawal form
If you withdraw from your membership using the withdrawal form, we process your name, your e-mail address and — in so far as you give them — membership number, address, date of joining and your remark. In addition we record the time of receipt.
Purpose: to receive your withdrawal, to act on it and to be
able to show that it arrived in time.
Legal basis: Art. 6(1)(b) GDPR — the processing is necessary
in order to deal with your withdrawal; as regards the time of receipt
additionally Art. 6(1)(c) and (f) GDPR (being able to prove a declaration
bound by a deadline).
Recipients: no one outside the association. The information
goes to our mailbox and is additionally transferred into the association's
application on the same server, so that the board can deal with the matter.
Storage period: until the matter is settled, then for as long
as statutory retention periods require. A withdrawal is a record — we do not
delete it straight away, because it proves that you were in time.
Confirmation: you will receive an acknowledgement of receipt
by e-mail without delay. It contains the time of receipt and is your proof.
No login is needed for this, and we do not check your identity automatically. The form is only a more convenient route — an informal e-mail or a letter is just as effective.
5b. Membership application
When you fill in the membership application, we process the details you give there: first name and surname, where applicable middle name and name at birth, date and place of birth, gender, marital status, nationality, residence status, mother tongue, address, mobile number and e-mail address, as well as the type and start of the membership you want. If you are not yet of age, the name and telephone number of a person with parental responsibility are added.
We ask about your financial situation only because § 6 (4) of the statutes ties a reduction of the fee to it. Giving it is voluntary: anyone who would rather not chooses „none of the above" and pays the full fee. Evidence is submitted only later, and you do not upload any files through this form.
Purpose: to decide on your application for admission (§ 6 (2)
of the statutes) and, if you are admitted, to establish and administer the
membership.
Legal basis: Art. 6(1)(b) GDPR — the processing takes place
at your request and is necessary in order to enter into and carry out the
membership.
Recipients: no one outside the association. The information
goes to our mailbox and is transferred into the association's application on
the same server, so that the board can examine it.
Interim state: while you are still filling it in, your draft
sits on our server and is found again by way of the icd_antrag
cookie. If you do not touch it for 30 days it is
deleted automatically — including where you never sent it.
Storage period after sending: if you are admitted, for as long
as the membership lasts, thereafter in accordance with statutory retention
periods; if the application is rejected or withdrawn, we delete the details as
soon as the matter is closed.
Confirmation: you receive an acknowledgement of receipt by
e-mail immediately; a second message goes to the board.
You can withdraw the application at any time — simply reply to the confirmation e-mail and we will delete it. And you do not have to use this form: an informal application by e-mail or letter is just as effective.
6. Contacting us by e-mail
If you write to us, we process your details exclusively in order to deal with
your enquiry.
Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries,
otherwise Art. 6(1)(f) GDPR (interest in answering enquiries).
Storage period: until the matter has been finally dealt with,
then erasure, unless statutory retention periods stand in the way.
7. Hosting
The website runs on a server operated by the association itself. The server hardware is provided by OVH GmbH (St.-Johanner-Straße 41–43, 66111 Saarbrücken). A contract for processing on behalf of a controller under Art. 28 GDPR is in place with the provider. The processing takes place within the European Union.
8. Your rights
As against us you have the right to
Art. 15 GDPR
Art. 16 GDPR
Art. 17 GDPR
Art. 18 GDPR
Art. 20 GDPR
Art. 21 GDPR
In so far as processing is based on consent, you may withdraw that consent at any time with effect for the future; the lawfulness of the processing carried out up to that point remains unaffected.
Where to send it: for everything in this section an informal e-mail to datenschutz@icd360s.de is enough — there is no form for it, and proof of your identity is asked for only where there are reasonable doubts about it (Art. 12(6) GDPR). We answer without undue delay, at the latest within one month.
Right to lodge a complaint with a supervisory authority
Independently of this, you may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)Promenade 18
91522 Ansbach
poststelle@lda.bayern.de
9. Changes to this policy
We adapt this policy as soon as the data processing on this website changes. The version available here is the one that applies; its date is given at the top.