PRIVACY POLICY (GDPR-COMPLIANT)
Version: 2025 – for the Lemuria Bay website, operated by a private individual until association registration
1. Controller
The controller responsible for processing your personal data within the meaning of Art. 4(7) GDPR is:
Veit Jürgens
Dietrich-Bonhoeffer-Str. 11
10407 Berlin
Germany
E-Mail: info@lemuriabay.org
This website is currently operated as a private initiative.
The non-profit association “Lemuria Bay e. V.” is in formation and not yet legally registered.
Once the association is registered, this Privacy Policy will be updated accordingly.
2. Personal Data Collected
We collect personal data in the following situations:
2.1 When visiting the website
Technical data is collected automatically by the hosting provider (“server log files”):
- IP address
- date and time of access
- browser type and version
- operating system
- referrer URL
- pages viewed
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure website).
2.2 When contacting us (email, contact form)
We process:
- name
- email address
- phone number (optional)
- content of your message
Purpose: Responding to inquiries and communication.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures), Art. 6(1)(f) GDPR.
2.3 When applying for the Volunteer Programme
We may process:
- personal and contact details
- motivation letter, experience, qualifications
- preferred travel period
- emergency contacts
- health information (optional, only with consent)
- passport information (if required for local authorities)
Purpose: participation assessment, organisation, safety.
Legal basis: Art. 6(1)(b) GDPR,
for health data: Art. 9(2)(a) GDPR (explicit consent).
2.4 Payments & participation fees
Since the association is not yet registered, participation fees are held in trust by:
Veit Jürgens (as a private organiser)
We process:
- name
- amount paid
- payment date
- payment method
- purpose of payment
Legal basis: Art. 6(1)(b) GDPR (contract fulfilment).
No donation receipts are issued. Payments are not considered donations.
3. Use of Cookies
If your website uses no cookies except technically necessary ones, use this:
This website uses only technically necessary cookies. No tracking, analytics, or marketing cookies are used.
If you plan to use Google Analytics, Meta Pixel, YouTube embeds etc. → sag Bescheid, dann integriere ich die entsprechenden Module.
4. Purpose of Data Processing
Your data may be used for:
- communication and responding to inquiries
- processing volunteer applications
- organising the volunteer programme
- safety and emergency procedures
- accounting for participation fees
- improving the website
- fulfilling legal obligations
5. Sharing of Data
Personal data is only shared when necessary and lawful:
5.1 Service providers (processors)
Such as:
- website hosting
- email service providers
- cloud services (if used)
5.2 Partners in Madagascar
Only when required for:
- accommodation
- programme coordination
- safety procedures
- emergency response
Madagascar is not an EU country with an adequacy decision.
Therefore the legal basis for transfers is:
- Art. 49(1)(b) GDPR (necessary for contract execution)
- or Art. 49(1)(a) GDPR (explicit consent)
5.3 Legal authorities
Only if required by law.
No data is shared for advertising.
6. Data Retention
Data is retained only as long as necessary:
- General inquiries: up to 12 months
- Programme participation: 6–10 years (legal retention)
- Health data: deleted immediately after programme completion unless required for safety
- Payment data: according to tax laws
7. Your Rights (Art. 12–23 GDPR)
You have the following rights:
- access (Art. 15)
- rectification (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- objection (Art. 21)
- withdrawal of consent (Art. 7(3))
To exercise your rights, contact:
info@lemuriabay.org
8. Right to Lodge a Complaint
You may lodge a complaint with your local data protection authority or with:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Website: https://www.datenschutz-berlin.de
9. Security Measures
We implement technical and organisational measures to protect your data, including:
- encrypted communication (SSL/TLS)
- access control
- limited personal data collection
- secure storage and deletion policies
10. Third-Country Transfers (Madagascar)
Since Madagascar is outside the EU/EEA, and no adequacy decision exists:
- Transfers occur only when necessary for performance of the volunteer agreement (Art. 49(1)(b) GDPR)
- or based on explicit consent (Art. 49(1)(a) GDPR)
You will be informed in advance if such transfers take place.
11. Changes to This Privacy Policy
This Privacy Policy may be updated if:
- the association becomes officially registered
- the website functionality expands
- new tools or services are introduced
- legal requirements change
The latest version will always be published on this page.
12. Contact
If you have questions regarding data protection, please contact:
info@lemuriabay.org
