Privacy Policy
The protection of your personal data is important to us. This website is operated by FINDER e.V. in Berlin, Germany. All data processing is governed by the EU General Data Protection Regulation (GDPR). Key points: we use no tracking cookies, our analytics is self-hosted and cookieless, all data is stored on our own servers in Germany, and we do not share data with third parties.
1. Data Controller
The party responsible for data processing on this website is:
FINDER e.V.
Schützenstraße 6A
10117 Berlin, Germany
Email: info@finder-akademie.de
Phone: +49 (0)30 754 395 750
2. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
You also have the right to lodge a complaint with a supervisory authority. The competent authority is the Berlin Commissioner for Data Protection and Freedom of Information.
3. Data Processing When Visiting the Website
When you visit our website, the following data is processed automatically:
Server Logs
Our server temporarily stores the following data in log files:
- IP address of the requesting device
- Date and time of access
- Name and URL of the requested file
- Amount of data transferred
- Notification of successful retrieval
- Browser type and version
- Operating system
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and stability of the website).
Cookies
We only use technically necessary cookies required for the operation of the website. These cookies do not store personal data and are deleted when you close your browser.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in session management).
Contact Form
When you submit an inquiry via our contact form or book a consultation, the data you provide is used to process your request.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).
Newsletter
If you subscribe to our newsletter, we store your email address to send you regular information about our programme and training offers. You can unsubscribe at any time via the link in each email.
Legal basis: Art. 6(1)(a) GDPR (consent).
Appointment Booking
For booking consultations, we use a self-hosted scheduling solution (Cal.com) on our own servers. The data you enter (name, email, message) is processed exclusively on our servers and is not shared with third parties.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures).
4. Web Analytics (Umami)
We use Umami, a privacy-friendly analytics tool that we self-host on our own servers in Germany. Umami helps us understand and improve website usage.
Privacy-Friendly Configuration
We operate Umami in "cookieless mode", which means:
- No cookies: No tracking cookies are stored on your device
- No persistent identification: Visitors are not tracked across sessions
- No IP storage: Your IP address is not stored
- No third parties: All data remains on our own servers
Data Collected
For statistical purposes, we collect the following anonymised information:
- Pages visited and time spent
- Device type (desktop, tablet, mobile) and browser
- Approximate geographic origin (country/region, no more precise)
- Referring website (referrer)
This data cannot be attributed to any individual person.
Right to Object (Opt-out)
You can opt out of data collection at any time. Your preference is stored locally in your browser and applies to all future visits on this device.
Web analytics enabled
Anonymous usage statistics are collected.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in optimising our website). When opt-out is enabled, no data is collected.
5. Data Processing for Registered Users
When you register for the protected area of our website, additional data is processed:
| Data Type | Purpose | Retention |
|---|---|---|
| Email address, password | Authentication | Until account deletion |
| Name, institution | Personalisation | Until account deletion |
| Region, role | Content adaptation | Until account deletion |
| Course customisations | Storing individual modifications | Until account deletion |
| Shared units | Collaboration between users | Until revocation |
Storage: Data is stored in a self-hosted PostgreSQL database on our own servers in Germany. No data is shared with third parties.
Deletion: You can delete your account at any time in your account settings. All your personal data will be permanently removed.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) for providing the service.
Usage Statistics
With your consent, we collect additional usage statistics for registered users to help us improve the platform:
- Which units and methods you access
- Which materials you download
- Which videos you play
This data is linked to your user account but is only evaluated in anonymised and aggregated form. The analysis helps us understand which content is most helpful. Data is not shared with third parties.
Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time.
6. Encryption of Course Notes
REBOUND offers optional client-side encryption for course notes. This feature was designed for educators who may include personal information about students in their notes.
What Is Encrypted?
When encryption is enabled, your notes for individual course units are encrypted before being sent to our servers. Metadata such as course names, timestamps, and unit numbers are not encrypted.
How Does Encryption Work?
- Client-side encryption: Your notes are encrypted on your device before they reach our servers.
- AES-256-GCM: We use AES-256-GCM, an industry standard for secure encryption.
- Key derivation: The encryption key is derived from your personal password (PBKDF2).
- Zero-knowledge: Neither REBOUND staff nor administrators can read encrypted notes.
Recovery Key
When you activate encryption, you receive a 12-word recovery key. This allows you to recover your notes if you forget your password.
Important: The recovery key is not stored on our servers. If you lose both your password and your recovery key, your encrypted notes are permanently lost.
Note: Encryption is optional. You can continue to use unencrypted notes. The choice is yours.
7. My REBOUND — Anonymous Access for Young People
Via my-rebound.de, young people can participate anonymously in the REBOUND programme. Access is via a QR code shown by the teacher in class. Students choose a nickname and join anonymously — no name, no email, no date of birth. No registration or user account is required.
Data Processed
| Data Type | Purpose | Retention |
|---|---|---|
| Pseudonymous ID (UUID) | Attribution of responses | Until programme end (automatic) |
| Self-chosen nickname | Display within the group | Until programme end |
| Responses to self-assessment questions | Comparison with group | Until programme end, then aggregated only |
| Last activity (timestamp) | Session management | Until programme end |
No personal identification: No data is collected that would allow identification of individuals. Neither IP addresses nor device information are stored.
No web analytics: No Umami or other analytics tools are used on my-rebound.de.
Comparison data: Responses are only shown in aggregated form (averages) when at least 20 people in a group have responded (k-anonymity).
Free-text responses: Only visible to the person themselves, not aggregated, and deleted at programme end.
Automatic deletion: All individual data is automatically deleted at the end of the school year. Only anonymous, aggregated statistics remain.
No access for supervisors: Teachers and facilitators only see summarised group results, never individual responses.
Legal basis: Art. 6(1)(e) GDPR (performance of a task in the public interest — educational purposes). No consent required as no personal data is processed.
8. Hosting and Data Processing
All services of this website are operated on FINDER e.V.'s own servers in Germany. This includes:
- The website and all content
- The database for user accounts and course content
- The appointment booking system
- Authentication services
No personal data is transmitted to third-party providers or servers outside our infrastructure.
9. Changes to This Privacy Policy
We reserve the right to update this privacy policy to comply with current legal requirements or to reflect changes in our services. The updated policy will apply to your next visit.
Last updated: February 2026