Privacy Policy
In short
This website has no contact form, no audience measurement and embeds nothing from third parties. It sets exactly one cookie, and that one remembers your choice of language.
Everything beyond that belongs to the SuperKarl donation form. That form is not on this website but on the websites of the organisations that use it — and there I do not process donation data for myself, but on behalf of the organisation in question. The two are kept apart below.
Personal data means any information relating to you — your name, for instance, your email address or your IP address. For every activity, this policy states which of it is involved, why, who else receives it and how long it is kept.
Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Andreas KleinSuperKarl
Alteburgerstraße 32
50678 Köln
Germany
- Phone+49 173 8888987
- Emailandy@superkarl.io
For any question about data protection, and to exercise the rights described below, please use the contact details given above.
I am not required to appoint a data protection officer and have not appointed one: the conditions of § 38 of the German Federal Data Protection Act (BDSG) are not met.
When you visit this website
This website runs on Google Cloud Run in the europe-west1 region (Belgium). As with any web server, access data is generated in the process: your IP address, the date and time of the request, the address requested, the HTTP status code, the volume of data transferred, the identifier your browser reports (user agent) and, if your browser sends it, the page you came from.
I need this data to deliver the website, to find faults and to fend off attacks. The legal basis is Art. 6 (1) (f) GDPR; my legitimate interest is the secure and functioning operation of this service.
The logs are held in the log storage of my Google Cloud project and are deleted there automatically after 30 days. They are not combined with other data and are not used to analyse your behaviour.
The connection to this website is encrypted with TLS throughout.
The cookie this website sets
This website exists in German and in English. So that the choice is not lost with every click, it stores the language you requested in a cookie:
| Name | Purpose | Retention |
|---|---|---|
| NEXT_LOCALE | Remembers which language you are reading this website in. Its content is “de” or “en” — nothing else. | Until you close your browser (session cookie) |
The cookie is only set when the language you requested differs from the one your browser prefers — anyone with a German browser opening the German home page never receives it at all. It is limited to the path “/”, set with SameSite=Lax, and contains no identifier by which you could be recognised.
Because this cookie is strictly necessary in order to provide you with the service you have expressly requested — the page in the language you chose — no consent is required for it under § 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). That is also why you will find no cookie banner here.
What this website does not do
There is no audience measurement here, no analytics tool, no advertising network and no social media button. Fonts, images, scripts and sounds are served by this server itself; while you read these pages your browser opens no connection to any external provider.
There is also no form. If you would like to write or call, please use the ways given above — I then process what you tell me in order to answer your enquiry (Art. 6 (1) (f) GDPR, or Art. 6 (1) (b) GDPR for contractual matters) and keep your message for as long as it is needed to answer it and to deal with follow-up questions.
The SuperKarl donation form on other websites
The actual service is a donation form that non-profit organisations embed in their own website. If you are reading this section, you most likely arrived here from such a form.
This matters for who is responsible: the organisation you are donating to decides on the purposes and means of processing your donation. It is the controller within the meaning of Art. 4 (7) GDPR, I process the data on its behalf under Art. 28 GDPR, and a contract covering that instruction is in place. You therefore exercise your rights as a data subject with the organisation; if you contact me instead, I will pass your request on to them and reply to you.
This policy nevertheless describes the process in full, because the form links to it and because you should know what happens on your device and who gets to see what you enter.
When you fill the form in, the following is transmitted: your name and your email address — both are mandatory — the amount, the payment method you chose and whether you are giving once or monthly. Depending on how the organisation has set up its form and on what you enter, the following may be added: telephone number, street, postcode, town and country, a donation purpose, a free-text comment, whether you are donating as a company and if so the company name, whether you are covering the transaction fee, whether you wish to donate anonymously, and whether you would like a donation receipt. After paying, you can add your postal address for the receipt.
The purpose is to carry out your donation and, if you ask for one, to issue a donation receipt. The legal basis is Art. 6 (1) (b) GDPR (performing the process you initiated); for retention under tax law it is Art. 6 (1) (c) GDPR.
If you submit without a name or without an email address, the form stops: without those two the payment cannot be attributed and no confirmation can be sent. Everything else is optional — although without a postal address you will not receive a donation receipt.
When the donation page is loaded, your IP address and the address requested are also recorded in the server logs, as described in the section on this website; the same retention period of 30 days applies to the donation servers. In addition, the server counts requests per IP address for one minute at a time in order to stop automated attacks on the payment interface. That count is kept in memory only and expires with the time window. The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest is the prevention of abuse.
Cookies and storage in the donation form
The donation form itself sets no cookie and measures nothing. What is stored on your device comes from two sources: from Stripe, the payment service provider, and from resuming a payment that briefly takes you to your bank or payment provider.
| Name | Set by | Purpose | Retention |
|---|---|---|---|
| __stripe_mid | Stripe | Fraud prevention. Recognises the device a payment is made from. | 1 year |
| __stripe_sid | Stripe | Fraud prevention within an ongoing payment. | 30 minutes |
| sk_pending_donation:<form ID> | SuperKarl | Holds what you entered and the proof of your payment while you switch to your bank or payment provider, so that afterwards you see the confirmation page and not an empty form. Not a cookie but an entry in the browser’s session storage. | Until the browser tab is closed, at most 30 minutes |
The two Stripe cookies are placed by Stripe’s script on the domain of the organisation on whose page you are donating, with SameSite=Strict and only over encrypted connections. The script is loaded as soon as the form appears on the page, because it provides the payment fields themselves.
All three entries serve solely to carry out and secure the payment that you set in motion by opening the donation form. They are therefore strictly necessary under § 25 (2) no. 2 TDDDG and are set without separate consent. They are not used for audience measurement or advertising.
Payment processing by Stripe
The payment itself is handled by Stripe Payments Europe, Limited (Ireland). You enter your payment details — card number, IBAN or the credentials of your payment provider — in fields provided by Stripe. They go straight to Stripe and never reach my servers; afterwards I only see which payment method was used and, for card payments, the card brand, the issuing country and the last four digits.
So that Stripe can attribute the payment to the right transaction and detect fraud, what you entered in the form is transmitted to Stripe as additional information: name, email address and, where given, telephone number and postal address, along with the details of the donation itself. Stripe also receives technical data from your browser, including your IP address.
Stripe is certified to PCI DSS Level 1, the highest standard of the card industry.
The legal basis for the transmission to Stripe is Art. 6 (1) (b) GDPR insofar as it is necessary to carry out your donation, and Art. 6 (1) (f) GDPR for fraud prevention. Towards me, Stripe is a processor; for its own purposes — in particular fraud prevention and meeting its own obligations as a payment service provider — Stripe acts as a controller in its own right. How Stripe handles this is set out in Stripe’s own privacy policy.
- Stripestripe.com/privacy
Emails you receive from SuperKarl
After a donation you receive a confirmation by email; the same applies when you set up or end a monthly donation. The organisation you donated to is notified of your donation. These messages are part of carrying out the donation — they are not marketing emails, and there is no newsletter.
They are sent via Scaleway TEM, a service of Scaleway SAS in France; delivery runs through their data centre region in Paris. For this, Scaleway receives your email address, your name and the content of the message, and processes both solely in order to deliver the message and not for purposes of its own. The legal basis is Art. 6 (1) (b) GDPR.
Accounts for organisations
This section concerns only staff of organisations that use SuperKarl and log into the administration interface. As a donor you have no account, and you will never receive the cookies named here.
For an account I process the email address, the name, the role within the organisation’s account and the times of creation and modification. Signing in works with a one-time code sent to the email address on file; there is no password. The legal basis is Art. 6 (1) (b) GDPR — without an account the service cannot be provided.
After signing in, the administration interface sets the cookies “sAccessToken”, “sRefreshToken”, “sFrontToken”, “sAntiCsrf” and “st-last-access-token-update”. They keep the session alive and protect against attacks in which a foreign page triggers actions in a signed-in account. The access cookie expires after one hour, the others after 100 days at the latest; all of them are deleted on sign-out. These, too, are strictly necessary under § 25 (2) no. 2 TDDDG.
Account credentials are managed by SuperTokens, run as self-hosted software in the same Google Cloud environment as the rest of the service. Nothing is transmitted to its vendor.
Who else receives the data
I pass data on only where it is necessary for the purposes described or where I am legally obliged to. Nothing is sold, and nothing is passed on for advertising.
| Recipient | What for | Place of processing |
|---|---|---|
| Google Cloud EMEA Limited | Operating the servers, the database and the logs for the website, the donation form and the administration interface | europe-west1 region, Belgium |
| Stripe Payments Europe, Limited | Payment processing and fraud prevention | Ireland |
| Scaleway SAS | Sending the emails | France |
| The organisation you donate to | It is the controller for your donation and sees what you entered in its own administration interface | Depends on the organisation |
Google and Stripe incorporate their terms for processing on behalf of a controller under Art. 28 GDPR into their service agreements, so those terms apply to this service. Tax advisers, public authorities and courts may be added where I am legally obliged to provide information.
Transfers to countries outside the EU
The recipients named above process within the European Union. With Scaleway it stays that way: the provider states that it runs the entire technical stack of its email service itself and within the EU, with no sub-processor outside it.
Google and Stripe belong to corporate groups with companies outside the EU that may have access in the course of maintenance and support. For such cases their terms provide for a valid transfer mechanism — the European Commission’s standard contractual clauses under Implementing Decision (EU) 2021/914 or, where a recipient in the United States participates in it, the EU-US Data Privacy Framework. For the United States, the European Commission determined in its adequacy decision of 10 July 2023 that certified companies offer an adequate level of protection.
A copy of the relevant agreement is available on request using the contact details given above.
How long the data is kept
Server logs are deleted automatically after 30 days. Cookies and the session-storage entry expire according to the periods given in the tables above.
Donation records are accounting documents. They are subject to the retention periods of German commercial and tax law — under § 147 of the Fiscal Code (AO) and § 257 of the Commercial Code (HGB) generally ten years, counted from the end of the year in which the donation was booked. That period is an obligation and not a choice; while it runs, erasure cannot be required, but restriction of processing under Art. 18 GDPR can.
Account data of an organisation’s staff is deleted when the account is closed or the person is removed from it.
How long the organisation you donated to keeps your data in its own systems is for that organisation to decide.
Your rights
You have the following rights against the controller. For donations that is the organisation you donated to; for this website and for accounts in the administration interface it is me.
| Right | What you can ask for | GDPR |
|---|---|---|
| Access | Whether and which data about you is being processed — and a copy of it | Art. 15 |
| Rectification | That what is wrong is corrected and what is incomplete is completed | Art. 16 |
| Erasure | That your data is erased, unless a statutory retention obligation stands in the way | Art. 17 |
| Restriction | That your data is blocked rather than erased — for instance while its accuracy is being checked | Art. 18 |
| Data portability | What you provided yourself, in a common machine-readable format — or transmitted directly to another body | Art. 20 |
| Objection | That processing based on a legitimate interest ends — see the separate section below | Art. 21 |
| Withdrawal of consent | That consent you gave ends with effect for the future; what happened before remains lawful | Art. 7 (3) |
Access, rectification and erasure are free of charge for you.
Your right to object under Art. 21 GDPR
Where I process data on the basis of a legitimate interest under Art. 6 (1) (f) GDPR — this concerns the server logs, the prevention of abuse and fraud prevention — you have the right to object to that processing at any time on grounds relating to your particular situation.
If you object, I will stop processing the data concerned unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
An objection requires no particular form. A message to the email address given above is enough.
Complaint to a supervisory authority
Independently of everything else, under Art. 77 GDPR you may lodge a complaint with a supervisory authority if you consider that the processing of your data infringes the GDPR. The competent authority is the one of your place of residence, your place of work or the place of the alleged infringement. For me as a controller based in Cologne it is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–4
40213 Düsseldorf
Germany
- Phone+49 211 38424-0
- Emailpoststelle@ldi.nrw.de
Security
All transmissions are encrypted with TLS. Access to the administration interface is limited to the account of the respective organisation: one organisation’s data is not reachable from another. This is enforced on every single database query rather than in the interface — a query that would touch another organisation’s record does not return it. Card numbers and bank details are never stored on my servers.
Changes to this privacy policy
This policy describes the service as it stands today. If what is processed or who receives it changes, this text changes too. The version currently in force is always the one on this page.
Last updated: 23 August 2026.