Privacy Policy

Protecting your personal data is important to us. Below we explain which personal data we process when you visit this website and use our community features, for what purpose and on what legal basis this happens, and which rights you have. The German version of this policy is legally authoritative; this English text is provided for your convenience.

1. Controller

The controller responsible for data processing on this website is:

[Name / operator(s) or company]
[Street and number]
[Postal code, City]
Germany

Email: [contact@bookdragons-den.com]
Phone: [optional: phone number]

The “controller” is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data. This website is jointly operated by two persons; both can be reached via the contact details above.

A data protection officer is not legally required and has therefore not been appointed. For any questions regarding data protection, please contact us using the details above.

2. General Information

Legal bases for processing

We process personal data only in accordance with the applicable laws (GDPR, German Federal Data Protection Act). Depending on the processing, we rely on:

  • Consent (Art. 6(1)(a) GDPR) – e.g. the newsletter or setting non-essential cookies.
  • Contract / user relationship (Art. 6(1)(b) GDPR) – e.g. providing your user account and the community features.
  • Legal obligation (Art. 6(1)(c) GDPR).
  • Legitimate interest (Art. 6(1)(f) GDPR) – e.g. the secure and reliable operation of the website.

Storage period

We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention periods. If the purpose no longer applies or you withdraw a consent, the data will be deleted unless statutory retention obligations prevent this.

Recipients and processors

We only share your data where this is legally permitted. Where we use service providers who process data on our behalf (e.g. hosting, email delivery), this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Transfer to third countries

A transfer to countries outside the EU/EEA only takes place where legally permitted and where appropriate safeguards (e.g. EU standard contractual clauses) are in place. Where individual services may process data outside the EU, we point this out separately below.

3. Your Rights

With regard to your personal data, you have the following rights towards us:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Withdrawal of a given consent with effect for the future (Art. 7(3) GDPR)

To exercise your rights, an informal message to the contact details above is sufficient.

Right to lodge a complaint with a supervisory authority: Regardless of the above, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence or of the alleged infringement.

4. Hosting

This website is hosted by an external service provider (host). The personal data collected on this website is stored on the host’s servers. This may include, among other things, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access data and other data generated via a website.

Our host is:

Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany

The servers are located in Germany. Hosting is carried out for the purpose of fulfilling our obligations towards our users and in the interest of a secure, fast and efficient provision of our online offering (Art. 6(1)(b) and (f) GDPR). A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with the host.

5. Server Log Files

When you access this website, the host automatically collects and stores information that your browser transmits in so-called server log files. These are in particular:

  • browser type and version
  • operating system used
  • referrer URL (previously visited page)
  • host name of the accessing computer
  • time of the server request
  • IP address

This data is not merged with other data sources. It is collected on the basis of Art. 6(1)(f) GDPR; we have a legitimate interest in the technically error-free presentation and the security of our website. The log files are automatically deleted after a short time.

6. SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser’s address bar starts with “https://”.

7. Cookies and Consent Management

Our website uses cookies and comparable technologies (e.g. your browser’s local storage). Cookies are small text files that are stored on your device and cause no harm.

Technically necessary cookies are required for basic functions to work – for example logging in to your user account, security features or the language selection. They are set on the basis of Art. 6(1)(f) GDPR and § 25(2) TDDDG.

For all non-essential cookies we obtain your consent via a consent tool (cookie banner, § 25(1) TDDDG, Art. 6(1)(a) GDPR). Your choice is stored so that it does not have to be requested again on your next visit. You can change or withdraw your consent at any time via the cookie settings with effect for the future.

8. Contacting Us by Email

If you contact us by email, we process the data you provide (e.g. your name, your email address and the content of your message) in order to handle your request. We do not use a contact form on this website. The legal basis is – where initiating or performing a user relationship – Art. 6(1)(b) GDPR, otherwise our legitimate interest in responding to your request (Art. 6(1)(f) GDPR).

The data remains with us until the purpose of storage no longer applies (e.g. once your request has been handled) or until you ask us to delete it and no statutory retention obligations prevent this.

9. Registration and User Account (Magic-Link Login)

To take part in the community, you can create a free user account. During registration we collect:

  • username
  • first and last name
  • email address
  • your confirmation of the privacy policy and terms of use, and where applicable the age confirmation

Login is passwordless: after you enter your email address, we send you a one-time login link (“magic link”). We do not store a password. These emails are sent via our own mail server (see the section “Email Delivery”).

This processing serves to provide your account and the community features and is based on Art. 6(1)(b) GDPR (user relationship). We store your account data for as long as your account exists. You can delete your account at any time via the profile settings; the associated personal data will then be deleted unless statutory retention obligations prevent this.

10. Community Features (Profile, Wall, Ratings, Likes)

As a logged-in user you can maintain a public profile, publish posts and comments (e.g. on the wall/timeline), rate books and posts (star/“spice” rating) and mark content with a “like”.

Please note: content you publish in public areas (e.g. your displayed name, profile details, posts, comments and ratings) is visible to other visitors. Do not publish any data there whose public visibility you do not want. The legal basis is Art. 6(1)(b) GDPR (user relationship) or your consent by actively publishing the content (Art. 6(1)(a) GDPR). As a rule, you can remove content you have posted yourself.

11. Fan Art Competition / Image Uploads

As part of the fan art competition you can upload your own image files. In doing so we process the uploaded image, the associated displayed name/username and additional details (e.g. title/book reference and your confirmations regarding the terms of participation, age statement and AI labelling).

Once approved, submitted images are displayed publicly on the website and may be put up for voting. The processing is based on your consent given when uploading and confirming the terms of participation (Art. 6(1)(a) GDPR). You can withdraw your consent with effect for the future; we will then remove the entry from public display.

Please only upload images to which you hold the necessary rights and that do not infringe the rights of third parties. Note that uploaded files may contain additional technical information (e.g. EXIF metadata).

12. Newsletter (MailerLite)

If you subscribe to our newsletter, we process the email address you provide and, where applicable, further voluntary details in order to send you the newsletter. The legal basis is your consent (Art. 6(1)(a) GDPR).

The newsletter sign-up form is technically provided via Elementor Forms and passes the email address you enter (and any further details) to MailerLite. For sending we use the service MailerLite (MailerLite / UAB “MailerLite” or MailerLite Limited). Registration uses a double opt-in procedure: after you sign up, you receive an email asking you to confirm the subscription. This ensures that no one is subscribed using someone else’s email address.

MailerLite processes the newsletter data on our behalf; a data processing agreement pursuant to Art. 28 GDPR is in place. Where processing takes place outside the EU/EEA, it is safeguarded by appropriate measures (e.g. EU standard contractual clauses). MailerLite also analyses statistically whether newsletters are opened and links are clicked, in order to evaluate and improve the mailing technically.

You can unsubscribe from the newsletter and withdraw your consent at any time – for example via the unsubscribe link at the end of every newsletter email. The withdrawal does not affect the lawfulness of the processing carried out up to that point. After unsubscribing, your data will be removed from the distribution list.

Further information: MailerLite’s privacy notice at https://www.mailerlite.com/legal/privacy-policy.

13. Email Delivery (WP Mail SMTP)

System and notification emails (e.g. the login link for the passwordless login or replies to contact requests) are sent via our own mail server. To ensure reliable delivery we use the “WP Mail SMTP” plugin, which handles delivery via an authenticated SMTP connection. The legal basis is Art. 6(1)(b) and (f) GDPR (contract/user relationship and legitimate interest in reliable email delivery).

14. Services and Plugins Used

Elementor / Elementor Pro

The website is built with the Elementor / Elementor Pro page builder. The resources required for display are delivered from our own server. The only form used on the website is the newsletter sign-up (Elementor Forms); the data processed in this context is described in the section “Newsletter (MailerLite)”. The legal basis for using Elementor is our legitimate interest in an appealing and functional website (Art. 6(1)(f) GDPR).

WPML (multilingual)

To provide the website in several languages we use WPML. WPML does not process any personal visitor data for its own purposes; only technical information about the selected language is stored. The legal basis is Art. 6(1)(f) GDPR.

Self-hosted fonts

To display fonts consistently we use fonts stored locally on our server. When the pages are loaded, the fonts are loaded directly from our server; no connection to third-party servers (such as Google Fonts) is established in the process.

15. Minors / Age Notice

Some content of this community is intended for an adult audience and is labelled accordingly (e.g. age and content notices). Persons below the required minimum age may not use the features concerned. We do not knowingly process any data of children; should we become aware of such processing, we will delete the data.

16. Validity and Changes to This Privacy Policy

This privacy policy is dated [date]. As our website develops, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. You can access the current version on this page at any time.