Privacy policy
This website loads nothing from third parties, sets no non-essential cookies and measures no behaviour. That is why there is no cookie banner here. It is intended, not an omission.
1. Controller
Universal Peace Foundation Europe e.V., Mondstrasse 10, 85609 Aschheim, Germany. Register of associations VR 211356, Amtsgericht München. Email: info@upfeurope.org.
No data protection officer is appointed by law. Please direct enquiries to the address above.
2. Principle: no third parties
All fonts, images, style declarations and scripts are served from our own domain. The site loads no Google Fonts, no font or script CDN, no maps, no YouTube or Vimeo video, no reCAPTCHA, no social media widgets and no advertising or tracking pixels.
Visiting this website therefore transmits no personal data to third parties.
3. No cookie banner
We set no cookies at all, and we store nothing in your browser's local or session storage — neither for analytics, marketing or profiling, nor for convenience settings. Language is handled purely through separate URLs for the German and English pages. Because no information is stored on your device within the meaning of section 25 TDDDG, no consent is required, and there is no banner for a consent we do not need.
4. Server log files
On each request the web server processes: shortened IP address, date and time, requested resource, status code, volume of data transferred, referrer and browser identification.
Purpose: operation, security and fault diagnosis. Legal basis: Art. 6(1)(f) GDPR, legitimate interest in secure operation. Retention: seven days, then automatic deletion. No merging with other data takes place.
5. Contact form
Data processed: name, email address, message and, if you provide it, telephone number.
Purpose: answering your enquiry. Legal basis: Art. 6(1)(b) GDPR for enquiries relating to a contract, otherwise Art. 6(1)(a) GDPR on the basis of your consent. Retention: until the enquiry is settled, at most six months; statutory retention periods remain unaffected.
Spam protection uses a hidden field and a check on submission time — no third-party captcha and no further evaluation. You may withdraw your consent at any time by email to info@upfeurope.org; the lawfulness of processing carried out until then remains unaffected.
6. Newsletter
Sending is by double opt-in only: after signing up you receive an email with a confirmation link. Only then do we add you. We log the time of sign-up, the time of confirmation and the email address used as evidence of consent.
Legal basis: Art. 6(1)(a) GDPR. Every message contains an unsubscribe link; after unsubscribing we delete the address, except for the record of consent given and withdrawn. Nothing is pre-ticked and no open or click tracking takes place.
7. Membership and SEPA direct debit
For membership we process name, address, date of birth, email address and bank details. Legal basis: Art. 6(1)(b) GDPR for performing the membership relationship and Art. 6(1)(c) GDPR for tax and commercial obligations.
Bank details are transmitted solely to our bank in order to collect the fee. Retention: for the duration of the membership, then ten years under tax retention periods.
8. Photographs
Identifiable people appear on this website only where consent under Art. 6(1)(a) GDPR is on file; for minors the guardians give that consent. Consent can be withdrawn at any time.
This is enforced technically: every photograph of an identifiable person passes through a consent list in the source code. Without consent the image is not served. See the image rights page for detail.
9. Hosting and processing agreement
The website runs with a provider whose servers are located in the European Union. A processing agreement under Art. 28 GDPR is in place with that provider. No transfer to third countries takes place.
Transmission is encrypted with TLS only. The server sends a strict Content-Security-Policy permitting content from its own domain only, plus HSTS, X-Content-Type-Options, Referrer-Policy strict-origin-when-cross-origin and a Permissions-Policy denying geolocation, camera and microphone.
10. Audience measurement
No audience measurement takes place. Should evaluation become necessary, it will use self-hosted Matomo in cookieless mode with IP anonymisation only. Google Analytics will not be used under any circumstances.
11. The 11:11 display
The time remaining until the next peace minute is calculated entirely in your browser from your device clock. No location request, no IP lookup and no network request take place.
12. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and the right to withdraw consent at any time (Art. 7(3) GDPR).
Right to lodge a complaint with the supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
13. Version
This policy is updated when processing changes.