Privacy policy

This is a translation. Only the German version is legally binding. Read the German version

1. Controller

Türkische Studenten Gesellschaft Aachen e.V.
Jülicher Straße 209 q/s, 52070 Aachen, Germany
Represented by the board (Vorstand): Mehmet Alagül, Bahri Berkay Bayrak, Emir Pisirici, Oğuzhan Ünal
Email: kommunikation@tsg.rwth-aachen.de

We are not required to appoint a data protection officer. For any data protection questions, contact the board at the email address above.

2. Hosting and delivery of the website

Our website is run on Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA), on servers in the EU (Dublin, Ireland). The database and sign-in run on Supabase Inc. ([TODO: copy the address from the Supabase DPA]); server location: EU (Ireland, eu-west-1). When you visit the website, these providers process technically necessary data, especially your IP address, date and time, the page you requested and browser details. The providers keep this data in their logs only for a short time.

We have a data processing agreement under Art. 28 GDPR with both providers [TODO: sign the Supabase DPA in the dashboard, then remove this note]. Transfers to the USA or other third countries cannot be ruled out. They are based on the EU-US Data Privacy Framework (Art. 45 GDPR) where the provider is certified, and otherwise on Standard Contractual Clauses (Art. 46(2)(c) GDPR).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working website).

The domain is registered with INWX GmbH & Co. KG. INWX does not process data of website visitors.

3. Protection against abuse

To stop attacks such as automated sign-in attempts, we limit the number of requests. For this we do not store your IP address in plain text, only as an encrypted hash value (HMAC). These entries are deleted automatically after 24 hours at the latest.

Legal basis: Art. 6(1)(f) GDPR (protecting the website and accounts against abuse).

4. Visitor statistics

On the public information pages (not in the forum or the account, contact or admin areas) we use Vercel Web Analytics to understand which pages are visited and how often. Vercel Web Analytics sets no cookies and stores nothing on your device. Visits are only grouped using a hash of the request that is discarded after 24 hours; no profile of you is created.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a website that meets visitors' needs).

5. Cookies

We only use technically necessary cookies, for example to keep you signed in. These do not need consent (Section 25(2) no. 2 TDDDG). We do not use tracking or advertising cookies, and we do not load content from third parties such as Google servers or social networks.

6. User account

When you create an account, we process: your name, email address, field of study, semester, age and password (stored only in encrypted form). We need this data to provide your account and to identify you as a member of the community. You must be at least 16 years old to have an account.

When you sign up, you confirm the forum rules and the notice on anonymous posting. We store that you confirmed them and which version you confirmed. A new display name is first stored as a request; it only becomes visible once an admin approves it.

Legal basis: Art. 6(1)(b) GDPR (user relationship).
Retention: until you delete your account. You can delete your account at any time in the account settings.

If you are part of the TSG team (admins and owners), we also send your notifications by email to your account address. The email only contains the type of notification, where relevant the title of a forum question, and a link; never the contents of contact messages or IP addresses.

For sign-in, confirmation and notification emails we use [TODO: enter the email provider, e.g. Supabase Auth or your own SMTP service].

[TODO: If community applications, team memberships or notifications collect further data, add a separate section here.]

7. Forum

The forum is public. Anyone can read questions and answers, including through a public interface (API), and third parties can copy and share them. Posts under your name show your display name. New questions and every anonymous post are only published after an admin approves them; until then only you and the admins can see them. Please do not post sensitive personal details.

Legal basis: Art. 6(1)(b) GDPR.
Retention: until you delete the post or your account, or the post is removed.

8. Anonymous posts

For anonymous questions and replies, your name is shown to nobody, not even to the TSG team, and we store no IP address.

  • Before publication: every anonymous post is checked by an admin. Until the admin decides, we store which account it came from (pseudonymisation) so that you can edit or delete the pending post and see the outcome. Admins see the post but not this link; only the software uses it.
  • At publication: the link to your account is deleted permanently. From then on nobody, including TSG, can trace the post back to you. You can therefore no longer edit or delete it yourself; write to us if it has to go. It also stays if you delete your account.
  • Rejected posts are not published. The text and the link are deleted when the review ends, or after 30 days at the latest.
  • Consequences: moderators can remove published anonymous posts. Warnings, suspensions and bans can only be tied to posts under your name or to anonymous posts that are still waiting for approval.
  • Legal basis: Art. 6(1)(b) GDPR (forum rules) and Art. 6(1)(f) GDPR. Our legitimate interest is protecting the forum against insults, hate, spam and sabotage. The processing is not based on consent. Your confirmation at sign-up or before your first post serves to inform you and to record that you accepted the forum rules.

9. Moderation, reports and suspensions

When a post is reported, we store the report, the moderator who reported it, the reason and a copy of the reported text as evidence. The copy and the report are kept even if the public post is deleted, so that the decision can be reviewed.

For a warning or suspension, we store the type of measure, the reason, its length and a hash value (SHA-256) of your email address. Through this hash, a suspension still applies if the account is deleted and created again with the same email address. Minor violations lead to phased bans (1 day, 3 days, 1 week, then permanent); all earlier phases count. For serious violations an immediate permanent ban is also possible. If an account is deleted for serious violations, its email address is blocked from the forum for 2 years. You can see your moderation history in your profile at any time.

Members can report posts. We store the report, the reason and the reporting account; admins are not shown who reported a post.

All decisions are made by people. There is no automated decision-making within the meaning of Art. 22 GDPR. You can see the measure and the reason for it on the forum pages (Art. 17 Digital Services Act). You can appeal within 14 days by emailing kommunikation@tsg.rwth-aachen.de.

Legal basis: Art. 6(1)(b) and (f) GDPR.
Retention: ban phases and permanent bans are kept without a time limit, because each later phase builds on the earlier ones; a ban can be lifted early after a successful appeal. Reports, evidence, lookup logs and other suspension records are deleted automatically 2 years after the case is closed or the suspension ends.

10. Disclosure to authorities

We do not pass data to the police, the university or other bodies on our own initiative. However, we are legally required:

  • to provide information when a court or competent authority lawfully orders it (e.g. Section 21 TDDDG), and
  • to inform law enforcement if we become aware of information giving rise to a suspicion of a crime that threatens someone's life or safety (Art. 18 Digital Services Act).

Legal basis: Art. 6(1)(c) GDPR (legal obligation).

11. Contact form

When you write to us through the contact form, we store your message, the subject and the category you chose. If you are signed in and do not write anonymously, we also see your name and email address so we can reply. Such a signed message becomes a conversation: the team's replies and your follow-ups are stored with the message and shown to you in your account under "Messages to TSG". For anonymous contact messages we store neither a link to your account nor an IP address; they cannot be traced back to you.

Legal basis: Art. 6(1)(f) GDPR (handling your request), or Art. 6(1)(b) GDPR if it concerns your account.
Retention: 12 months from receipt; contact messages and the replies exchanged about them are then deleted automatically.

12. Recipients

Your data is only available to the people in TSG responsible for the task in question and to our processors Vercel and Supabase [TODO: and the email provider, if any]. Data is only disclosed to authorities as described in section 10. We do not sell data or share it for advertising.

13. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR).

Right to object (Art. 21 GDPR): Where we process data based on Art. 6(1)(f) GDPR, you can object at any time on grounds relating to your particular situation. We will then stop, unless we can show compelling legitimate grounds, or the processing is needed to establish, exercise or defend legal claims. This includes enforcing an ongoing suspension.

To exercise your rights, simply email kommunikation@tsg.rwth-aachen.de. We reply within one month.

Right to complain: You can complain to a data protection supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.

14. Changes

We update this privacy policy when the website or the law changes.

Last updated: September 2026