Privacy
Privacy policy
Last updated: 26 September 2026
This is a courtesy translation. In the event of any discrepancy, the German version is the legally binding one.
This website works without cookies, without visitor statistics and without advertising networks. The only data processed is what is technically required to serve the site — and whatever you send us yourself through the reservation form.
1. Controller
The controller within the meaning of the GDPR is:
[Full legal name of the organisation][if applicable, represented by: first and last name]
Kurze Straße 2
[postcode] Göttingen
Germany
Phone: [phone number]
Email: kontakt@inanna-kulturtreff.de
We have not appointed a data protection officer. Under § 38 of the German Federal Data Protection Act this only becomes mandatory once twenty or more people are permanently engaged in automated processing of personal data. [Please check whether this applies to you.]
2. Your rights
You have the following rights in relation to us:
- Access (Art. 15 GDPR) — whether and what data we hold about you.
- Rectification (Art. 16 GDPR) — if something is wrong or incomplete.
- Erasure (Art. 17 GDPR) — unless a retention obligation applies.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) — in a commonly used format.
- Objection (Art. 21 GDPR) — against processing based on a legitimate interest.
Where you have given consent, you may withdraw it at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal.
An informal message to kontakt@inanna-kulturtreff.de is enough for any of these.
Right to lodge a complaint
You may also complain to a data protection supervisory authority, in particular in the member state of your residence, place of work or of the alleged infringement. The authority responsible for us is:
Die Landesbeauftragte für den Datenschutz NiedersachsenPrinzenstraße 5
30159 Hannover, Germany
[Verify current contact details at lfd.niedersachsen.de before publishing.]
3. Visiting the site: server logs
Each time a page is requested, your browser transmits technically necessary information which our hosting provider records in log files:
- IP address of the requesting device
- date and time of the request
- name and path of the file retrieved
- amount of data transferred and whether the request succeeded
- browser type and version, operating system
- previously visited page (referrer), if your browser sends it
Purpose: delivering the website, keeping the server stable and
secure, tracing attacks.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in
operating the site securely and without faults.
Retention: [Ask the hosting provider and
enter the period — seven days is common.]
This data is not merged with other sources and is not used to identify you personally.
Processor: hosting
The website is hosted by ALL-INKL.COM — Neue Medien Münnich, proprietor René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. The servers are located in Germany. A data processing agreement under Art. 28 GDPR is in place. [Conclude the agreement in the KAS customer area if you have not already, and verify the provider details.]
4. Reservation form
The “Reserve a spot” form lets you send us a request. In doing so we process:
- Required: name and email address
- Optional: phone number, number of people, chosen event, your message
- Added automatically: the language of the page and the time of receipt
Purpose: handling and answering your request, planning seating.
Legal basis: Art. 6(1)(b) GDPR, as the processing serves
pre-contractual steps taken at your request; additionally Art. 6(1)(a) GDPR
based on the consent you give in the form.
Retention: until your request has been dealt with and no
follow-up is to be expected, at most
[define a period, e.g. twelve months after the event].
Statutory retention obligations remain unaffected.
Your details are used solely to handle the request and are not passed on to third parties. You can always write to us informally by email instead — the form is not the only way.
Protection against automated submissions
The form contains a field invisible to visitors and measures the time between the page loading and the form being submitted. Both serve solely to deter automated submissions. No additional personal data is collected and nothing is transmitted to third parties. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest lies in protection against misuse.
Processor: database
[This section only applies once the database is connected. Until then the form merely opens a prepared email and no data is stored in a database — remove this subsection until that changes.]
Incoming reservations are stored in a database at Supabase, operated by Supabase, Inc., 970 Toa Payoh North, Singapore. The server region we use is [enter region, recommended: eu-central-1, Frankfurt]. A data processing agreement under Art. 28 GDPR is in place. [Conclude the agreement and verify the provider details. If the server region lies outside the EU, the basis for the international transfer under Art. 44 et seq. GDPR must additionally be described here — usually standard contractual clauses.]
5. Contact by email
If you write to us directly, we process your email address and the content of your message in order to reply.
Legal basis: Art. 6(1)(b) GDPR where your message concerns the
initiation or performance of a contract, otherwise Art. 6(1)(f) GDPR based on
our legitimate interest in answering enquiries.
Retention: until the matter has been conclusively settled.
6. What this site does not do
The following is not a statement of intent but a description of how the site is actually built:
- No cookies. The site sets none. That is also why there is no consent banner — there would be nothing to consent to.
- No analytics, no tracking. Neither Google Analytics nor any comparable tool is embedded. We do not know how many people visit this site.
- No advertising networks, no profiling.
- Fonts are served from our own server. The typefaces used (Playfair Display, Bodoni Moda, Space Grotesk) are not loaded from Google but delivered by us. Opening the site establishes no connection to Google and transmits no IP address there.
- The video is on our own server. No YouTube or Vimeo player is embedded, and the video only loads once you play it.
- No social media plugins. The icons in the footer are ordinary links, not embedded content. No connection to Instagram or Facebook is made unless you click them.
- No embedded map. The “Open in maps” link leads to Google Maps but loads nothing into this page. Only when you click it do you leave our site, and Google’s privacy policy then applies.
7. Browser storage
After a successful login, the editorial area of this site
(/admin.html) stores a session token in the browser’s
localStorage so that the logged-in person does not have to re-enter
their password on every page. That area is intended for staff only and is not
linked from the website.
Nothing is stored in the browser for ordinary visitors. Access to local storage is exempt from consent under § 25(2) no. 2 TDDDG, as it is strictly necessary for the login the user has expressly requested.
8. Data security
[This section only becomes accurate once an SSL certificate is active for the domain. While the site is reachable over http:// only, the statement below would be untrue and must be removed — or the certificate set up.]
This website uses TLS encryption (recognisable by https:// in the
address bar and the padlock symbol). This means data you send us — for example
through the reservation form — cannot be read by third parties in transit.
In addition, access to the editorial area is protected by password, and write access to the database is restricted to explicitly authorised accounts.
9. Changes to this policy
We adapt this policy when the legal situation or the technology of the site changes. The version published here is the one that applies; the date above shows when it was last updated.