Privacy Policy
Last updated: 30 September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
World Human Rights Defenders e.V.
Behrenstr. 29
10117 Berlin
Germany
Chairman of the Board: Hüseyin Demir
Phone: +49 30 45086778
Email: [email protected]
2. Contact for Data Protection Enquiries
If you have any questions regarding the processing of your personal data or wish to exercise your data protection rights, you may contact us at any time:
World Human Rights Defenders e.V.
Behrenstr. 29
10117 Berlin
Germany
Phone: +49 30 45086778
Email: [email protected]
3. General Principles of Data Processing
We process personal data only where there is a legal basis for doing so and where the processing is necessary for a specified purpose.
Depending on the processing activity, processing is carried out in particular on the basis of:
- Art. 6(1)(a) GDPR – consent,
- Art. 6(1)(b) GDPR – performance of a contract or steps taken prior to entering into a contract,
- Art. 6(1)(c) GDPR – compliance with a legal obligation,
- Art. 6(1)(f) GDPR – legitimate interests.
Where special categories of personal data within the meaning of Art. 9 GDPR are processed, such processing takes place only where one of the conditions set out in Art. 9(2) GDPR is also met.
As a general rule, we retain personal data only for as long as necessary for the respective purpose or for as long as statutory retention, documentation or evidentiary obligations apply.
4. Provision of the Website and Server Log Files
When you access our website, technically necessary information is processed. This may include in particular:
- IP address,
- date and time of access,
- pages or files accessed,
- referrer URL,
- browser type and browser version,
- operating system,
- technical status and error information.
The processing is carried out for the technical provision of the website, to ensure stability and security, and to detect and prevent abusive or unlawful access.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and uninterrupted provision of our website.
Server log data is retained only for as long as necessary for secure operation, troubleshooting and the prevention or investigation of security incidents, unless statutory obligations require longer storage.
5. Hosting by Hostinger
Our website and the associated technical systems are hosted by Hostinger.
The hosting infrastructure we use is located in Lithuania and therefore within the European Union.
As part of the hosting services, IP addresses, server log data, technical connection data and data submitted by users through our website may in particular be processed.
The processing is carried out for the secure, stable and efficient provision of our website.
The legal basis is Art. 6(1)(f) GDPR.
Where Hostinger processes personal data on our behalf, such processing is carried out on the basis of data processing agreements pursuant to Art. 28 GDPR.
Our email infrastructure is also provided through our hosting provider.
6. Cloudflare
We use services provided by Cloudflare to improve the security, availability and performance of our website.
Traffic between your device and our website may be routed through Cloudflare’s infrastructure.
Cloudflare may in particular process:
- IP addresses,
- technical connection data,
- HTTP headers,
- browser and device information,
- requested resources,
- information used to identify security-related or abusive access.
The processing serves in particular to prevent attacks, protect against abusive access, ensure the availability of our website and optimise the delivery of content.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the security, stability and performance of our website.
Cloudflare may use technically necessary security information or cookies, for example in connection with a security check. Where storing or accessing such information on the end device is strictly necessary, this is carried out on the basis of Section 25(2) No. 2 TDDDG.
In connection with Cloudflare’s global infrastructure, personal data may be processed outside the European Economic Area, in particular in the United States.
For transfers to the United States, Cloudflare relies, among other mechanisms, on its certification under the EU-U.S. Data Privacy Framework. Where this does not apply, Standard Contractual Clauses approved by the European Commission may in particular be used.
7. Cookies and Similar Technologies
Our website uses cookies and comparable technical storage mechanisms.
Some of these are technically necessary in order to provide the website and functions expressly requested by you.
For technically necessary cookies, consent is not required where the conditions of Section 25(2) TDDDG are met.
Non-essential cookies or comparable technologies, in particular those used for statistical purposes, are used only after you have given your prior consent.
You may change or withdraw your consent at any time with effect for the future using the consent management function provided on our website.
8. Consent Management with Complianz
We use Complianz to manage your cookie and privacy settings.
Information is stored regarding which data processing activities you have consented to or objected to. This is necessary so that we can respect your choices and document the granting or refusal of consent.
For this purpose, cookies with names such as cmplz_* may in particular be used.
According to our current configuration, consent preferences stored by Complianz are retained for up to 365 days.
The processing is carried out for the purpose of managing and documenting your privacy choices.
Where technically necessary information is stored on your device for this purpose, this is carried out in accordance with Section 25(2) TDDDG.
You may change your choices at any time using the consent management function.
9. Language Selection
Our website is multilingual and uses a technical function provided by Polylang to store the selected language.
For this purpose, the pll_language cookie may in particular be used.
This cookie contains the language selected by you and enables the website to display the corresponding language version during subsequent visits.
According to our current configuration, the retention period is up to 365 days.
The storage is necessary to provide the language version of the website selected by you.
10. Google Analytics
We use Google Analytics 4 for statistical analysis of the use of our website.
Google Analytics is activated only after you have expressly consented to statistical data processing through our consent management system.
The service is provided by Google. For users within the European Economic Area, Google Ireland Limited is involved in particular; other companies within the Google group may also process personal data as part of Google’s global infrastructure.
The following data may in particular be processed:
- information about pages accessed,
- time and duration of visits,
- device and browser information,
- approximate location information,
- technical usage and event data.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.
Where information is stored on or accessed from your device, this is based on your consent pursuant to Section 25(1) TDDDG.
The retention period for user and event data in Google Analytics is set to two months. The retention period for user data is not reset upon new user activity.
This retention setting applies in particular to user-level and event-level data; aggregated standard reports in Google Analytics may remain unaffected.
You may withdraw your consent at any time with effect for the future through our cookie and privacy settings.
In connection with the use of Google services, data may be transferred to the United States or other countries outside the European Economic Area.
Google LLC is certified under the EU-U.S. Data Privacy Framework. Where necessary, additional safeguards, in particular Standard Contractual Clauses, may also be used.
11. Google Tag Manager
We use Google Tag Manager for the technical management of website tags and to control services such as Google Analytics.
In our configuration, Google Tag Manager is used in such a way that services requiring consent are activated only after the corresponding consent has been granted.
Google Tag Manager is used in particular to manage the tags deployed on the website. The actual data processing is governed by the respective service integrated through Tag Manager.
12. Locally Hosted Web Fonts
The web fonts used on our website are hosted locally through our own website infrastructure.
When these fonts are loaded, no connection is established to Google Fonts servers.
Accordingly, your IP address is not transmitted to Google solely for the purpose of displaying fonts on our website.
13. Contact by Email
If you contact us by email, we process the data you provide, in particular:
- email address,
- where applicable, your name,
- the content of your message,
- any other information you voluntarily provide.
The processing is carried out for the purpose of handling and responding to your enquiry.
Where your enquiry relates to the initiation or performance of a contractual, membership or other legal relationship, the processing is carried out on the basis of Art. 6(1)(b) GDPR.
In other cases, the processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the appropriate handling of incoming enquiries.
The data is deleted as soon as it is no longer required for handling the enquiry and there are no statutory retention obligations or other legitimate grounds requiring further storage.
14. Forms on Our Website
We provide various forms on our website.
If you submit personal data to us through a form, we process the information you enter for the purpose stated in the respective form.
Depending on the form, this may include in particular:
- name and contact details,
- email address,
- telephone number,
- communication preferences,
- information about qualifications and professional experience,
- language skills,
- information relating to voluntary engagement,
- membership information,
- other information provided voluntarily.
According to our current technical configuration, data submitted through our WordPress forms is stored in the WordPress database of our website.
Mandatory fields are marked accordingly. If the information requested in a mandatory field is not provided, the respective enquiry or application may not be processed.
Voluntary information is not required in order to submit the form unless expressly stated otherwise.
15. Newsletter and Brevo
We offer a newsletter through which we provide information about the activities of World Human Rights Defenders e.V., human rights developments, reports, publications, events and related topics.
For the technical administration and delivery of our newsletter, we use Brevo, a service provided by Brevo/Sendinblue SAS, France.
If you subscribe to our newsletter, we process in particular:
- your email address,
- your first name, if voluntarily provided,
- your newsletter consent,
- information relating to the subscription and confirmation process,
- technical information required to document the registration.
The processing is carried out exclusively for the purpose of sending and administering the newsletter.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.
Your consent is voluntary. You may withdraw it at any time with effect for the future, in particular by using the unsubscribe link included in each newsletter.
Double Opt-In
We use a Double Opt-In procedure for newsletter registrations.
After submitting the registration form, you receive an email asking you to confirm your subscription. Your newsletter subscription is completed only after you confirm the registration.
The confirmation process may be documented in order to demonstrate that valid consent has been obtained.
Brevo supports Double Opt-In and maintains corresponding registration and confirmation information for signup forms. Brevo Help
Processing by Brevo
Brevo processes newsletter data on our behalf as a processor within the meaning of Art. 28 GDPR.
A Data Processing Agreement forms part of Brevo’s contractual framework. Brevo Help
According to Brevo, the hosting servers used to process and store its databases are located within the European Union, including infrastructure in France, Germany and Belgium. Brevo Help
Newsletter data is retained for as long as the newsletter subscription remains active or as long as retention is necessary to demonstrate consent or comply with statutory obligations.
After unsubscribing, your email address will no longer be used to send the newsletter. Where necessary, limited information may be retained for the purpose of documenting the withdrawal or preventing further newsletter delivery.
16. Spam Protection with Google reCAPTCHA
To protect our newsletter form against automated submissions, spam and abuse, we use Google reCAPTCHA.
reCAPTCHA analyses technical information and interactions in order to distinguish legitimate users from automated or abusive access.
In this context, Google may process in particular:
- IP address,
- browser and device information,
- operating system information,
- technical interaction and usage data,
- information required to evaluate whether a submission is automated or abusive.
Google states that information processed in connection with reCAPTCHA is used for the provision and maintenance of the security service and for fraud and abuse protection. Google Cloud
The purpose of the processing is to protect our forms and technical infrastructure against spam, automated submissions and misuse.
The legal basis for processing personal data is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, forms and communication systems against automated abuse and security threats.
Where information is stored on or accessed from your device and such access is strictly necessary for the security function requested in connection with the form, the processing may be based on Section 25(2) No. 2 TDDDG. Where consent is legally required for a particular storage or access operation, such processing takes place only on the basis of the applicable consent requirements.
Google may process data through infrastructure outside the European Economic Area, including in the United States.
Where applicable, transfers to Google LLC in the United States may be based on the EU-U.S. Data Privacy Framework or other safeguards permitted under Art. 44 et seq. GDPR.
17. Applications for Voluntary Engagement
If you apply through our website for voluntary engagement with World Human Rights Defenders e.V., we process the personal data you provide for the purposes of:
- assessing your application,
- communicating with you in connection with your application,
- selecting and assigning suitable areas of activity,
- preparing and, if you are accepted, organising your voluntary engagement.
This may include in particular contact details, qualifications, language skills, professional or volunteering experience, availability, preferred areas of activity and other information provided voluntarily.
Where the processing is aimed at establishing a voluntary engagement relationship, it is carried out on the basis of Art. 6(1)(b) GDPR.
Additional organisational processing may be based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper organisation and implementation of our non-profit activities.
Voluntary Information on Accessibility and Support Needs
Where you voluntarily provide information about accessibility or support needs and such information may reveal information concerning your health or a disability, this may constitute special categories of personal data within the meaning of Art. 9 GDPR.
Where the processing is based on your explicit consent, it is carried out pursuant to Art. 9(2)(a) GDPR.
Providing such information is voluntary.
You may withdraw your consent at any time with effect for the future.
Retention Period for Unsuccessful Applications
If an application for voluntary engagement is unsuccessful or withdrawn by you, we generally delete the personal data collected during the application process no later than six months after completion of the application process, unless statutory obligations or other legally permissible grounds require a longer retention period.
If a person is accepted as a volunteer, the data required for carrying out the voluntary engagement is retained for the duration of the engagement and thereafter only to the extent required by statutory retention obligations or other legally permissible purposes.
18. Voluntary Consent to Publications
Where, in connection with voluntary engagement, we obtain separate consent for the publication of personal information, photographs or other content on our website, on social media or in printed publications, such processing is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR.
Giving such consent is voluntary.
Refusing such consent generally has no effect on the assessment of an application for voluntary engagement.
Consent that has been granted may be withdrawn at any time with effect for the future.
19. Membership
If you apply for membership in World Human Rights Defenders e.V. or are a member of our association, we process the personal data required for:
- processing your membership application,
- administering the membership,
- communicating with members,
- fulfilling association-related and statutory obligations,
- where applicable, processing membership fees.
The legal basis is in particular Art. 6(1)(b) GDPR and, where legal obligations must be fulfilled, Art. 6(1)(c) GDPR.
Due to the nature of our association’s activities, membership may in certain circumstances allow conclusions to be drawn about special categories of personal data, in particular political or philosophical beliefs.
Where this results in the processing of special categories of personal data within the meaning of Art. 9 GDPR, such processing takes place only if the requirements of Art. 9(2) GDPR are met.
Where the statutory requirements are satisfied, processing in the course of the legitimate activities of a not-for-profit organisation may be based on Art. 9(2)(d) GDPR. Where these requirements are not satisfied and the processing is based on explicit consent, Art. 9(2)(a) GDPR applies.
We limit the processing to data required for association and membership administration.
20. Online Donations via FundraisingBox
For the technical provision and processing of our online donations, we use FundraisingBox, a service provided by:
Wikando GmbH
Schießgrabenstraße 32
86150 Augsburg
Germany
When you complete a donation form, the following data may in particular be processed:
- name,
- contact details,
- where applicable, address,
- donation amount,
- payment method,
- transaction data,
- other information provided voluntarily.
The processing is carried out for the purpose of handling, processing and documenting your donation.
The legal basis is generally Art. 6(1)(b) GDPR.
Where data must be retained due to statutory obligations, in particular tax or commercial-law retention requirements, further processing is carried out on the basis of Art. 6(1)(c) GDPR.
Wikando GmbH processes personal data through FundraisingBox as a processor pursuant to Art. 28 GDPR.
Depending on the payment method you select, additional payment service providers may be involved in processing the payment.
21. Credit Card Payments via Stripe
If you select credit card as the payment method for an online donation, the payment is processed through Stripe.
In this context, the following data may in particular be processed:
- name and contact details,
- payment amount,
- payment and credit card information,
- transaction data,
- IP address,
- technical information required for authentication and fraud prevention.
The legal basis for processing required to carry out the payment is Art. 6(1)(b) GDPR.
Stripe Payments Europe, Limited and other companies within the Stripe group may be involved in processing the payment.
Stripe may also process personal data outside the European Economic Area as part of its international infrastructure.
For relevant transfers to the United States, the EU-U.S. Data Privacy Framework may in particular apply. Stripe LLC is certified under this framework. Where necessary, Standard Contractual Clauses or other appropriate safeguards may additionally be used.
Where Stripe processes data for its own legally required purposes, for example fraud prevention, payment processing or compliance with regulatory obligations, Stripe may act as an independent controller in this respect.
22. Payments via PayPal
If you select PayPal as your payment method, the data required to carry out the payment is transmitted to PayPal.
The provider for users in Germany and the European Economic Area is in particular:
PayPal (Europe) S.Ã r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
Luxembourg
The following data may in particular be processed:
- name,
- email address,
- payment amount,
- account and transaction information,
- technical data.
The legal basis for processing necessary to carry out the payment is Art. 6(1)(b) GDPR.
As part of its payment services, PayPal is generally independently responsible for the processing carried out by PayPal.
Within the global PayPal group, personal data may also be processed outside the European Economic Area. PayPal uses, among other safeguards, approved Binding Corporate Rules (BCRs) for intra-group transfers.
23. Payment by SEPA Direct Debit
If you select SEPA direct debit as your payment method, we process the data required to carry out the direct debit.
This may include in particular:
- name,
- IBAN,
- donation amount,
- mandate information,
- transaction and payment information.
The data is processed through FundraisingBox and, to the extent necessary to execute the direct debit, transmitted to the financial institutions involved.
The legal basis is Art. 6(1)(b) GDPR.
Where payment or mandate data must continue to be stored due to statutory retention and evidentiary obligations, such processing is carried out on the basis of Art. 6(1)(c) GDPR.
24. Social Media Links
Our website may contain links to profiles or services offered by social networks.
These are generally ordinary links and not automatically embedded social media content.
Therefore, merely accessing our website does not generally establish a connection to the relevant social network as a result of such a link.
Only when you click the respective link do you leave our website, and the privacy rules of the respective provider then apply.
25. Recipients of Personal Data
Personal data is transferred to third parties only where:
- this is necessary for the respective purpose,
- there is a legal obligation to do so,
- corresponding consent has been given, or
- another legal basis permits the transfer.
Potential recipients may include in particular:
- hosting and IT service providers,
- security and infrastructure providers,
- analytics providers,
- newsletter and communication service providers,
- payment service providers,
- banks and financial institutions,
- processors,
- public authorities where disclosure is required by law.
Where service providers process personal data exclusively on our behalf, the requirements for processing pursuant to Art. 28 GDPR are observed.
26. Transfers of Personal Data to Third Countries
Some of the service providers we use belong to internationally operating corporate groups or use infrastructure outside the European Economic Area.
Personal data is transferred to a third country only in accordance with the requirements of Art. 44 et seq. GDPR.
Where the European Commission has adopted an adequacy decision for a third country or a particular transfer mechanism, the transfer may be based on that decision.
For appropriately certified companies in the United States, the EU-U.S. Data Privacy Framework may in particular serve as the basis for the transfer.
Where no applicable adequacy decision exists, Standard Contractual Clauses approved by the European Commission or other safeguards permitted under the GDPR may in particular be used.
For intra-group transfers involving PayPal, approved Binding Corporate Rules may also apply.
Brevo states that its database hosting infrastructure is located within the European Union. Brevo Help
27. Retention Period
Unless a more specific retention period is stated in this Privacy Policy, we retain personal data only for as long as necessary for the respective processing purpose.
Data may be retained for longer only where:
- statutory retention or documentation requirements apply,
- the data is required for the establishment, exercise or defence of legal claims, or
- another legal basis permits continued retention.
Once the purpose no longer applies and any statutory retention periods have expired, the data is deleted or, where immediate deletion is technically or legally impossible, restricted until deletion.
28. Your Rights
Subject to the applicable statutory requirements, you have in particular the following rights:
Right of Access – Art. 15 GDPR
You may request information as to whether and which personal data concerning you we process.
Right to Rectification – Art. 16 GDPR
You may request the correction of inaccurate personal data or the completion of incomplete data.
Right to Erasure – Art. 17 GDPR
You may request the deletion of your personal data where the statutory requirements are met.
Right to Restriction of Processing – Art. 18 GDPR
You may request restriction of processing where the statutory requirements are met.
Right to Data Portability – Art. 20 GDPR
Where the statutory requirements are met, you may receive personal data in a structured, commonly used and machine-readable format or request its transmission to another controller.
Right to Object – Art. 21 GDPR
Where processing is based on Art. 6(1)(e) or (f) GDPR, you may object to the processing on grounds relating to your particular situation.
Withdrawal of Consent – Art. 7(3) GDPR
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
To exercise your rights, you may contact us at:
World Human Rights Defenders e.V.
Phone: +49 30 45086778
Email: [email protected]
29. Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority.
Due to the registered office of World Human Rights Defenders e.V. in Berlin, the competent supervisory authority is in particular:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany
Email: [email protected]
30. Automated Decision-Making and Profiling
We do not use decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
31. Technical and Organisational Measures
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Depending on the respective level of protection required, these measures include in particular:
- access and authorisation controls,
- multi-factor authentication for administrative access,
- secure transmission of data,
- protection of IT infrastructure,
- web application firewall and bot protection,
- data backups,
- security and activity logging,
- malware monitoring,
- updating and maintenance of the systems used,
- protection against unauthorised access.
The measures are reviewed and adapted in accordance with the level of protection required and the state of the art.
32. Amendments and Review of this Privacy Policy
We update this Privacy Policy whenever our data processing activities, services used or legal requirements change.
We review this Privacy Policy regularly and, as a general rule, at least once per year to ensure that it remains up to date.
The current version published on our website applies.
Last updated: 30 September 2026
