Privacy Policy
Deutsch-Irakisches Forum für Zusammenarbeit und nachhaltige Entwicklung e.V. i.G.
Click here
Non-binding translation. This English version is provided for information only. The legally binding text is the German original. In the event of any discrepancy, the German version prevails.
Controller
Deutsch-Irakisches Forum für Zusammenarbeit und nachhaltige Entwicklung e.V. i.G.
c/o Dr. Mohammed Al-Fakhri
Fregestraße 38b
12161 Berlin
E-Mail: [email protected]
1. General information on data processing
We process personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the applicable statutory requirements. This policy provides information on the nature, scope and purpose of the processing of personal data on our website.
2. Visiting the website (server log files)
When you access our website, data is collected automatically (in particular IP address, date and time of access, browser used, referrer URL). These server log files serve the security and technical operation of the website, are not merged with other personal data, and are deleted after no more than 14 days.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure operation).
3. Hosting (netcup)
Our website is hosted by netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. netcup processes the data arising via the website (in particular server log files) on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. The servers are located in Germany.
Legal basis: Art. 6 (1) (f) GDPR.
4. Contact form
When you send us an enquiry via the contact form, we process the data you provide in order to handle and respond to your enquiry. We collect:
- First and last name
- Email address
- Company / organisation (if provided)
- Country / region and type of enquiry (for routing)
- The content of your message
Legal basis: Art. 6 (1) (a) GDPR (your consent), as well as Art. 6 (1) (b) and (f) GDPR (handling the enquiry). The data is deleted once your enquiry has been conclusively handled and no statutory retention obligations apply. You may withdraw your consent at any time with effect for the future.
To protect against automated misuse (spam), we use a captcha or honeypot solution on the form (Friendly Captcha, provider: Friendly Captcha GmbH, Germany). This solution is data-minimising and does not set cookies for marketing purposes.
5. Membership application and member administration
When you apply for membership via our online form or the PDF form, we process the data you provide in order to decide on your admission and — in the event of admission — to administer the membership. In particular, we collect:
- Type of membership (full, supporting or institutional)
- First and last name
- Email address and, where applicable, telephone number
- Postal address (street, postal code, city, country)
- For institutional membership: name of the organisation, authorised representative and position
- Where applicable, your additional information in the message field
Purpose and legal basis: Processing takes place to review your application for admission and to establish and carry out the membership relationship. The legal basis is Art. 6 (1) (b) GDPR (initiation and performance of the membership relationship) and, insofar as you have consented, Art. 6 (1) (a) GDPR.
Recipients: Your information is forwarded exclusively to the responsible members of the Executive Board, who decide on admission. No disclosure to third parties takes place.
Storage period: If your application is rejected or you withdraw it, your data is deleted once it is no longer required and no statutory retention obligations apply. In the event of membership, your data is stored for the duration of the membership; after it ends, it is deleted in compliance with the statutory retention periods (in particular under tax and commercial law).
Payment data: Bank and payment data (e.g. for a SEPA direct debit mandate) is not collected via the online form, but exclusively via a separate, signed form. It is treated confidentially and used only for the purpose of collecting membership fees.
6. Sending emails (SMTP)
For the reliable sending of emails (e.g. replies to enquiries, system notifications), we use an SMTP service via Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The data required for sending (sender, recipient, content) is processed in the course of this. A data processing agreement pursuant to Art. 28 GDPR is in place with Google.
Legal basis: Art. 6 (1) (f) GDPR.
7. Cookies and consent
Insofar as our website uses cookies that are not technically necessary, this is done only on the basis of your consent. To manage your consent, we use the consent tool Complianz. When you enter the website, a consent banner is displayed through which you can select the desired categories (opt-in). Your selection is documented and can be changed or withdrawn at any time via the “Cookie settings” link in the footer.
Legal basis: Art. 6 (1) (a) GDPR (consent) and § 25 TDDDG.
8. Multilingualism (Polylang)
To provide the website in several languages, we use the Polylang plugin. In doing so, a technically necessary cookie may be set that stores your language selection. No personal data is processed for marketing purposes.
Legal basis: Art. 6 (1) (f) GDPR.
9. Social media links
Our website links to our profiles on Instagram (Meta Platforms Inc., USA), YouTube (Google LLC, USA) and Facebook (Meta Platforms Inc., USA). These are simple links, not embedded plugins; data is transmitted to these services only once you actively click the respective link and visit the provider’s page. The privacy policies of the respective providers apply to the data processing there.
10. Data subject rights
You have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent given (Art. 7 (3) GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
11. Transfer to third countries
We do not transfer personal data to countries outside the EU/EEA, except as otherwise described in this policy. Should you access linked services of US providers, the processing there takes place under their responsibility; the basis is regularly the European Commission’s Standard Contractual Clauses (SCC).
12. Storage period
Personal data is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations exist.
13. Data security
We use SSL/TLS encryption and take technical and organisational measures to protect your data against unauthorised access.
14. Data protection officer
The association is not required to appoint a data protection officer, as fewer than 20 people are permanently engaged in the automated processing of personal data.
As of: June 2026 | Version 1.0
