Legal information

Privacy policy

Privacy

Preamble

This privacy policy explains which personal data we process, for what purposes and to what extent. It applies to the public website of the Bundesarbeitsgemeinschaft Preußen, the newsletter archive, the digital handbook, digital forms on this website and the associated internal administrative processes insofar as personal data is processed.

The terms used are gender-neutral.

As of: 20 September 2026

Controller

Controller responsible for data protection

The controller within the meaning of the General Data Protection Regulation is the Bundesarbeitsgemeinschaft Preußen für Philatelie und Postgeschichte e. V., represented by its executive board.

Postal address
Bundesarbeitsgemeinschaft Preußen
c/o Udo Becker, 1. Vorsitzender
Böttcherstr. 5
28816 Stuhr

Contact
Data protection enquiries and general matters:
Kontakt@arge-preussen.de

Further information about the website provider is available in our legal notice.

The postal address care of the chairperson is used solely to receive postal correspondence for the association. The association, represented by its executive board, remains the controller.

Overview

Overview of processing

We process personal data primarily to provide our website, communicate, administer membership, handle membership applications, carry out registrations and logins, enable use of the newsletter archive and digital handbook, send electronic messages, provide a voluntary membership directory and handle membership fees and SEPA-related processes.

  • Basic data, such as name, address, membership number and similar master data
  • Contact data, such as email address and telephone number
  • Membership data, such as membership details, group affiliation and internal administration
  • Payment data, such as IBAN, BIC and fee-related information
  • Contract and procedural data, such as registration, confirmation and processing status
  • Usage and log data, such as IP address, login times and technical access
Legal bases

Relevant legal bases

We process personal data on the basis of the General Data Protection Regulation (GDPR) and applicable national legislation. The main legal bases are:

  • Article 6(1)(a) GDPR – consent
  • Article 6(1)(b) GDPR – performance of a contract and steps prior to entering into a contract
  • Article 6(1)(c) GDPR – legal obligation
  • Article 6(1)(f) GDPR – legitimate interests

Where data is processed in connection with membership, this is primarily for managing the membership relationship, administering membership data and handling membership fees.

Security

Security measures

We take technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unauthorised disclosure or unauthorised alteration.

Data transmitted through our website is encrypted using HTTPS or TLS. This applies in particular to registrations, logins, membership applications, direct debit forms and other forms submitted through the website.

Our internal online membership administration is also password-protected. Only authorised persons have access. Personal data is processed there solely for association administration and the organisational procedures required for this purpose.

Storage and erasure

General information on data storage and erasure

We erase personal data as soon as the purpose of processing no longer applies and there are no statutory retention obligations or other legitimate reasons for continued storage.

Where commercial or tax law requires retention, or data is needed to establish, exercise or defend legal claims, erasure takes place only after the relevant periods have expired.

  • Up to 10 years for documents relevant under tax or commercial law
  • Up to 6 years for other business documents where required by law
  • Generally 3 years to pursue or defend civil claims
Data subject rights

Rights of data subjects

Subject to the applicable legal provisions, you have in particular the following rights:

  • Right of access to the personal data being processed
  • Right to rectification of inaccurate data or completion of incomplete data
  • Right to erasure where no statutory retention obligations prevent it
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on legitimate interests
  • Right to withdraw consent with effect for the future
  • Right to lodge a complaint with a data protection supervisory authority
Membership and administration

Membership administration and association activities

We process personal data of members, interested persons and communication partners insofar as necessary to perform our statutory tasks, administer membership and fees, organise association activities and communicate.

This includes in particular basic data, contact data, membership numbers, membership details, fee-related information and association administration data.

Membership administration is carried out online and is password-protected. Only authorised persons have access where necessary for association administration.

Where editorial content, images, event information or details of office holders are maintained on the website or in protected work areas, this takes place as part of association activities and the public presentation of our statutory tasks.

Membership directory

Voluntary membership directory

An internal membership directory may be provided to members. A member is included only if they expressly confirm this and accept the privacy policy. Without this approval, the member is not included in the directory.

To check and confirm approval, we process in particular membership number, surname, email address, confirmation code, approval status, time of confirmation and the details selected for the directory. First name, surname, place of residence and email address are included as standard details. Telephone number, date of birth and full address are included only if the member additionally approves these details.

Approval is secured by a personal confirmation code sent to the confirmed email address. If no email address is on file, the member can confirm an email address during this process. The email service can also be activated on request, but is not required for inclusion in the directory. Members without a confirmed email address are not listed in the digital directory.

The directory can be generated as a PDF from the approved data and used within the association. The PDF header may contain statistical information, such as the number of active members, the number of listed members and information about members without an email address or without active use of the email service.

Approval can be changed or withdrawn with effect for the future. The legal basis is Article 6(1)(a) GDPR where inclusion in the directory is based on consent, and Article 6(1)(f) GDPR for secure technical processing, documentation and internal association organisation.

Membership application

Membership applications through the website

You can submit a digital membership application through our website. We process the data entered in the form, in particular salutation, title, first name, surname, date of birth, address, country, email address, telephone number, BDPh number, details of philatelic associations, collecting interests, comments and voluntary details about the email service and the requested payment of membership fees by SEPA direct debit.

Form data is transmitted in encrypted form. A personal confirmation link is sent by email to confirm the application. The application is processed further as a binding application only after this digital confirmation.

A PDF may be generated from the application data during processing. It serves internal documentation, further processing of the application and the provision of a document for the member.

The legal basis is primarily Article 6(1)(b) GDPR (steps prior to entering into a contract or performance of the membership relationship) and Article 6(1)(f) GDPR for organisational and administrative processes.

SEPA

SEPA direct debit mandate

If a SEPA direct debit mandate is granted in connection with a membership application or later, we process the necessary payment data, in particular IBAN and BIC, together with the associated membership and contact data.

Data is also transmitted through encrypted connections in this case. The mandate is additionally confirmed through a personal confirmation link sent by email. A PDF of the mandate may be generated during processing for internal handling and documentation for the member.

The legal basis is Article 6(1)(b) GDPR for managing the membership relationship and membership fees, and Article 6(1)(c) GDPR where statutory retention obligations apply.

Registration and login

Registration, login and user accounts

User accounts may be created for certain areas, in particular the newsletter archive, the digital handbook and internal administrative functions. We process in particular username, email address, password hashes, group and access approval information, and log data relating to registrations, invitations, logins and password procedures.

For security reasons, we store in particular registration and login times and technical access data insofar as necessary to prevent misuse and ensure secure operation.

Profiles and accounts in non-public areas are not publicly visible.

Contact form

Contacting us through the website

When you use our German or English contact form, we process the details you enter. These include your name, email address, subject and message. Your email address is required so that we can respond to your enquiry.

We process this data to handle and respond to your enquiry. If your message relates to an existing or prospective membership or another contractual relationship, the legal basis is Article 6(1)(b) GDPR. For general enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is appropriate communication with interested persons, collectors, researchers and members.

Form data is transmitted through an encrypted connection and forwarded by email to the responsible contact mailbox belonging to the association. Only persons entrusted with handling the enquiry have access. Data is disclosed to third parties only where necessary to handle the enquiry or required by law.

To prevent automated messages, we use an invisible form field, a minimum form completion time, a technically necessary session token and a time-based limit on submissions. We do not use external CAPTCHA or analytics services for this purpose.

We erase the submitted details once the enquiry has been fully handled and there are no statutory retention obligations or legitimate reasons for continued storage. If the enquiry contains information relevant under commercial or tax law, the corresponding statutory retention periods apply.

Email communication

Sending emails and electronic notifications

We process personal data to communicate by email, in particular for confirmation messages, password procedures and notifications relating to membership applications, SEPA procedures, registrations and organisational processes.

Technical and organisational emails are sent from email addresses belonging to the association. The data necessary for delivery and documentation is processed for this purpose.

Where a separate email service or newsletter is used, this is based on the relevant registration or consent, or within existing association relationships insofar as permitted by law.

Confirmation codes may also be used to secure individual procedures, such as registration for the email service or confirmation of an email address in connection with the voluntary membership directory.

PDF generation

Generation of PDF documents

In connection with digital membership applications, SEPA direct debit mandates and the voluntary membership directory, PDFs may be generated from data that has been entered, confirmed or approved. These PDFs serve internal documentation, further processing within the association, provision of documents to the persons concerned and, for the membership directory, internal association information based on the approvals granted.

Webhosting

Provision of the website and webhosting

We use a webhosting provider to make this website available. Data necessary to operate the website is processed, in particular technical access data, IP addresses, access times, information about the browser and system used, and server log files.

Server log files are processed primarily to ensure technical operation, analyse errors and maintain security.

Our hosting provider is:

ALL-INKL.COM – Neue Medien Münnich
Hauptstraße 68
02742 Friedersdorf
Germany

Further information: all-inkl.com
Provider’s privacy information: all-inkl.com/datenschutzinformationen

Statistics

Data-minimising audience measurement

For editorial evaluation, we record how often public pages on the website are accessed. This helps us identify interest in topics, structure content more effectively and develop frequently read areas.

Audience measurement uses no statistics cookies, visitor profiles or user IDs, and does not store IP addresses or full browser identifiers in plain text. To reduce repeated counts caused by refreshing the same page, a temporary, non-reversible hash is generated from the IP address and page path. A separate temporary hash is also generated from the IP address to estimate overall website reach, so that repeat visits within 24 hours are not counted as additional visitors. These hashes are retained for no more than 24 hours and then deleted. Apart from these hashes, only aggregated daily values per page path are stored, such as date, page address, page title, topic area, views and 24-hour page visits with repeat counts reduced, together with a daily website-wide count of 24-hour visitors with repeat counts reduced.

To improve the technical presentation, we also evaluate broad technical categories across the website that browsers transmit when accessing pages. Only aggregated daily values for device type, browser family and operating system family are stored permanently, for example mobile device, desktop, Chrome, Safari, Firefox, iOS, Android, Windows or macOS. The full user agent is not stored permanently for this purpose.

The statistics are evaluated internally and are not combined with other data sources. The legal basis is our legitimate interest in maintaining and improving our website to meet users’ needs under Article 6(1)(f) GDPR.

Cookies

Use of cookies

Our website may use technically necessary cookies or comparable storage mechanisms. These serve in particular to operate the website securely, manage sessions, enable login to protected areas and store technically necessary settings.

Where only technically necessary cookies are used, this is based on our legitimate interests in a secure and functional website.

If additional services or content requiring consent are integrated in future, we will update this privacy policy accordingly and provide an appropriate consent procedure.

Data disclosure

Disclosure of personal data

Personal data is disclosed to third parties only where permitted by law or necessary to perform our tasks and processes. This may include in particular technical service providers, hosting providers or internal association office holders insofar as they need the data to perform their respective tasks.

Where external service providers are used, we comply with data protection requirements and, where necessary, enter into a data processing agreement.

Transfers to third countries

International data transfers

Personal data is transferred to countries outside the European Union or the European Economic Area only where legally permissible in the individual case or where appropriate safeguards exist.

Under the current setup of this website, personal data is generally processed primarily within the European Union or in Germany.

Updates

Changes and updates

We adapt this privacy policy whenever changes to our processing activities or the legal framework make this necessary.

Existing confirmations remain valid for purely editorial or clarifying changes. If processing purposes, the scope of consent-based processing or other material content changes, we assign a new version to the policy and ask the persons concerned to acknowledge it again or provide any required consent again.

Note

Preparation and adaptation

This privacy policy is based on a legal text from Datenschutz-Generator.de by Dr Thomas Schwenke, individually adapted for the website of the Bundesarbeitsgemeinschaft Preußen and revised to reflect the functions actually used.