Privacy policy
As at: 05/2026
Note on language version: Only the German version of this page is authoritative and legally binding. Versions in other languages are machine-generated translations and serve solely to improve comprehension. In the event of discrepancies or questions of interpretation, the German text shall prevail.
A. Privacy Policy for the Website
B. Privacy Policy for Social Media Presences
A. Privacy Policy for the Website
We process personal data (hereinafter “data”) of users only to the extent necessary to provide a functional and comfortable website as well as our content and services.
“Processing” means the collection, use, disclosure and/or storage. According to the General Data Protection Regulation (hereinafter “GDPR”), “personal data” generally means all data by which a natural person can be identified. The exact definitions of the terms are set out in Art. 4 GDPR.
The following explanations inform you in particular about the type, scope, purpose, duration and legal basis of the processing of personal data, about the purposes and means of processing for which we alone or jointly with others decide, as well as about any third-party components we may use.
I. Information about the controller
II. Rights of the user
III. Information on data processing
I. Information about the controller
The controller (hereinafter “controller”) within the meaning of the GDPR and other national data protection laws of the member states as well as other data protection provisions is:
Marcel Habeck
Törnfinder
Schaphusenweg 10
59494 Soest
Telephone: +49 / (0)2921 / 344 378
E-mail: info@toernfinder.de
II. Rights of the user
With regard to the processing of his/her personal data described below, the user has the right
1. to demand confirmation as to whether data concerning him/her is being processed, as well as access to this data and further information and copies of the data in accordance with Art. 15 GDPR;
2. to demand the immediate rectification of incorrect data concerning him/her or the completion of this data pursuant to Art. 16 GDPR;
3. to demand that data concerning him be erased without delay in accordance with Art. 17 GDPR, or – if further processing is required pursuant to Art. 17(3) GDPR – to demand a restriction of processing in accordance with Art. 18 GDPR;
4. to receive the data concerning him that he has provided, in accordance with Art. 20 GDPR, and to demand that it be transferred to other controllers;
5. to lodge a complaint with the supervisory authority pursuant to Art. 77 GDPR, if the user is of the opinion that the processing of his data violates the GDPR.
Right to object: The user may object at any time, in accordance with Art. 21 GDPR, to the future processing of data concerning him that takes place on the basis of Art. 6(1)(f) GDPR. The objection may in particular be raised against processing for the purposes of direct marketing.
The controller is also obliged to notify all recipients to whom the personal data has been disclosed of any rectification or erasure of the data or any restriction of processing carried out pursuant to Art. 16, Art. 17(1) and Art. 18 GDPR, unless this proves impossible or involves disproportionate effort. The user has the right to be informed of these recipients.
III. Information on data processing
Insofar as no detailed information is provided below regarding the individual data processing operations, the processed data of the user will be erased or blocked as soon as the purpose of storage no longer applies and no statutory retention obligations prevent erasure.
Server data
For communication and security reasons, the following data is collected during a visit to the website, which is transmitted by the user's internet browser to the controller or to its hosting provider (so-called server log files):
- Browser type and version;
- operating system used;
- Website from which the user came to the website (referrer URL);
- page accessed;
- date and time of access;
- internet protocol (IP) address of the user.
The legal basis for the temporary storage is Art. 6(1)(f) GDPR on the basis of the legitimate interest in improving the stability, functionality and security of the website. The data is anonymised after seven days at the latest. Data whose further storage is required for evidentiary purposes is excluded from anonymisation until the respective incident has been finally clarified.
Hosting
The website is hosted by an external service provider (host). The personal data collected on this website is stored on the host's servers. This may include, in particular, IP addresses, contact enquiries, meta and communication data, contract data, contact details and other data generated via the website.
The host is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in the most reliable and secure provision of our website possible. If corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
The host is Raidboxes GmbH, Hafenstraße 32, 48153 Münster, Germany. A contract for data processing in accordance with Art. 28 GDPR has been concluded with the host.
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from „http://“ to „https://“ and by the padlock symbol in the browser line. When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Cookies and consent management (Borlabs Cookie)
The controller uses cookies on its website. Cookies are small text files or other storage technologies that the internet browser used by the user places and stores on the end device. These cookies process certain user information to an individual extent.
Technically necessary cookies, which are required for the operation of the website, are used on the basis of Art. 6(1)(f) GDPR and § 25(2) TDDDG. Cookies and services that are not technically necessary are only used with the consent of the user pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG.
To manage consents, the controller uses the consent management tool "Borlabs Cookie" from Borlabs GmbH, Rübenkamp 32, 22305 Hamburg. Borlabs Cookie stores the consent decision made by the user in a technically necessary cookie or in the browser's local storage, in order to be able to retrieve it on subsequent visits to the site. This data is not transmitted to Borlabs. The legal basis is Art. 6(1)(f) GDPR and § 25(2) TDDDG; the legitimate interest lies in the lawful management of consents given.
"Session" cookies are deleted when the user closes their browser. "Persistent" cookies are automatically deleted after a period that depends on the respective cookie, but which does not exceed one year. The user can prevent or restrict the installation of cookies by setting their browser accordingly and can delete cookies already stored at any time. Once given, consent can be withdrawn by the user at any time with effect for the future via the cookie settings on the website. If cookies are restricted, this may mean that not all functions of the website can be used to their full extent.
Registration and contract processing
Users can register on the portal in order to create and publish, as an advertiser, listings for sailing trips, courses and seminars, as an advertising partner, adverts, or as an author, trip reports. The data entered during registration (e.g. name, address, e-mail address, indication of commercial/private) is collected and stored for the establishment, performance and administration of the user relationship as well as for the processing of any subscriptions. Upon registration, the IP address as well as the date and time of registration are also stored.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract or implementation of pre-contractual measures). Data is not passed on to third parties outside the scope of contract processing; excepted from this is the disclosure to processors (e.g. hosting, e-mail dispatch) within the scope of the processing described below.
Contract and billing data is deleted upon expiry of the statutory retention periods under tax and commercial law. An account that has been inactive for more than one year and for which no valid subscription exists may be deleted by the controller; the associated data is deleted insofar as no statutory retention obligations apply.
Publication of listings, adverts and provider and partner pages
The content provided by advertisers and advertising partners (in particular texts, images, contact and profile details) is published on the portal, including the display on the provider or partner overview page and the respective individual page. Publication takes place for the performance of the user contract on the basis of Art. 6(1)(b) GDPR. Insofar as the advertiser has provided its own legal notice and its own privacy policy on its provider page, it is solely responsible for their content.
Uploaded images (metadata)
If images are uploaded to the portal – for example for listings, adverts, the provider or partner page, or for trip reports – these image files may contain metadata (e.g. time of capture, camera or device information as well as location data/EXIF data). This metadata may be accessible to third parties upon publication. The uploading user should remove any unwanted metadata prior to uploading. The respective uploading user is responsible for the uploaded content and the data contained therein.
Uploaded images are stored in the website's media library and, for technical reasons, are accessible via a direct, publicly retrievable internet address (URL). This means they can also be accessed independently of the respective content page – for example by directly calling up the address – and can be indexed by search engines. Users should therefore not upload any images whose public accessibility is not desired.
REVIEWS
The controller may enable users to rate providers. In doing so, the content of the rating, the time it was submitted, and the name or chosen pseudonym provided by the user are stored and published – in particular on the respective provider page. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in operating a meaningful rating system and in informing other users. The controller is entitled to remove ratings in accordance with the terms of use.
Trip reports
Registered users (authors) may submit and publish trip reports. In doing so, the submitted content, including at least one image, as well as the name provided, are published. This processing is based on the author's consent pursuant to Art. 6(1)(a) GDPR, which is granted by submitting and publishing the content and may be withdrawn at any time with effect for the future.
Contact
If the user contacts the controller or a provider (e.g. via a contact form or by e-mail), the personal data entered in doing so is used to process the enquiry. The provision of the data is required in order to answer the enquiry.
If the contact enquiry serves to fulfil a contract or to initiate a contract, the legal basis is Art. 6(1)(b) GDPR. Otherwise, the legal basis is the legitimate interest in processing the enquiry pursuant to Art. 6(1)(f) GDPR or consent pursuant to Art. 6(1)(a) GDPR, which may be withdrawn at any time pursuant to Art. 7(3) GDPR. The data will be deleted as soon as the enquiry has been conclusively answered and no statutory retention obligations apply.
Sending of automated e-mails (Brevo)
For the reliable delivery of automated or transactional e-mails (e.g. confirmations of registration and subscription, notifications), the controller uses an external dispatch service provider. In doing so, in particular the recipient's e-mail address and the content of the respective message are processed.
The provider is Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany (server location EU).
The legal basis is Art. 6(1)(b) GDPR, insofar as the dispatch serves to fulfil the contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in reliable and secure e-mail delivery). A data processing agreement pursuant to Art. 28 GDPR has been concluded with the service provider.
Invoicing and accounting (sevDesk)
For the creation of invoices and for bookkeeping purposes, the controller uses the cloud-based accounting software „sevDesk“. The provider is sevDesk GmbH, Im Unteren Angel 1, 77652 Offenburg, Germany. In this context, the data of the customer required for invoicing is processed, in particular name, address, invoice items and, where applicable, the VAT identification number.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (fulfilment of tax and commercial law obligations). The data is stored for the duration of the statutory retention periods. A data processing agreement pursuant to Art. 28 GDPR has been concluded with the provider.
Direct marketing
The controller reserves the right to use the data collected in the context of a contractual relationship for direct advertising by e-mail or post pursuant to § 7 Abs. 3 UWG, unless the user objects to this use. The direct advertising exclusively comprises offers for similar services to those already used. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the economic interest in sales as well as the improvement of services. The user may object to this use at any time.
Comment function for blog posts
For the comment function on this website, in addition to the comment itself, the time of creation, the e-mail address and – unless the comment is made anonymously – the chosen name are stored. As comments are not necessarily checked before publication, we also store the author's IP address so that we can take action against the author in the event of legal infringements (e.g. insults). The comments remain on the website until the commented content has been deleted or the comments have to be removed for legal reasons. The legal basis for the publication of the comment is consent pursuant to Art. 6(1)(a) GDPR, which can be withdrawn at any time with effect for the future. The storage of the IP address is based on the legitimate interest pursuant to Art. 6(1)(f) GDPR in pursuing any legal infringements.
Shortlist / favourites function
The website offers a shortlist or favourites function that makes it possible to temporarily save individual content. No personal data is stored and no cookies are set; the storage takes place locally in the browser and is deleted as soon as the page is left or the browser is closed. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in user-friendly functionality).
Google Maps
This website uses – only with the prior consent of the user – the map service „Google Maps“. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, USA. When activated, in particular the IP address and, where applicable, location data of the user are processed and transmitted to Google; transmission to the USA is possible.
Google Maps is used exclusively on the basis of the user's consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent can be withdrawn at any time with effect for the future via the cookie settings. The transfer of data to the USA is based on the adequacy decision of the EU Commission (EU–US Data Privacy Framework) and, additionally, on the standard contractual clauses. Further information: https://policies.google.com/privacy
Web analytics with Trackboxx
This website uses the privacy-friendly web analytics service Trackboxx, provided by Trackboxx, Dorfstr. 12, 22956 Grönwohld, Germany. Trackboxx allows us to analyse user behaviour in order to improve the website, without setting cookies. No personal data is stored permanently: a hash value is generated from the visitor's IP address and further parameters, which recognises the visitor only for the duration of their visit to the website and is automatically deleted after 24 hours at the latest. Subsequent identification of individual visitors, or reconstruction of the IP address from the hash value, is not possible. Processing takes place on servers in Germany; the data is not passed on to third parties. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a data-protection-compliant analysis of site usage). Further information: https://trackboxx.com/datenschutzerklaerung/
Integration of social media links
The controller uses links to social networks on the website. The integration takes place via a linked graphic. Only by clicking on the corresponding graphic is the user forwarded to the service of the respective network. A transfer of personal data to the networks does not take place before clicking.
After forwarding, information about the user is collected by the respective network (e.g. IP address, date, time and page visited). If the user is logged into their user account of the respective network during this process, the network operator can assign the information to the personal account. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in external representation and the improvement of usage quality.
The following social networks are linked:
- Facebook and Instagram – Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Private policy: https://www.facebook.com/privacy/policy
- X – Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland. Privacy policy: https://x.com/de/privacy
- LinkedIn – LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. Privacy policy: https://www.linkedin.com/legal/privacy-policy
B. Privacy policy for social media presences
To promote our services and to communicate with interested parties or customers, we use so-called social media platforms. The following information informs you about the processing of personal data when you visit one of our company presences on a social media platform or get in touch with us via it.
I. Information on the joint controllers
For the social media platforms named below,
Marcel Habeck
Törnfinder
Schaphusenweg 10
59494 Soest
Telephone: +49 / (0)2921 / 344 378
E-mail: info@toernfinder.de
is jointly responsible with the respective platform operator named within the meaning of Art. 26 GDPR. Insofar as the respective platform operator provides an agreement on joint responsibility, it is linked below; this sets out who fulfils which obligations under the GDPR – in particular with regard to the exercise of data subjects' rights and the information obligations.
- Facebook and Instagram Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Joint controller arrangement (Page Controller Addendum): https://www.facebook.com/legal/terms/page_controller_addendum
- LinkedIn – LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. Joint controller arrangement (Page Insights Joint Controller Addendum): https://legal.linkedin.com/pages-joint-controller-addendum. LinkedIn bases the transfer of personal data to the USA on the European Commission's standard contractual clauses.
- X – Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland; parent company X Corp., USA. In this respect, too, joint responsibility exists with regard to the statistical data of the company page; a transfer of personal data to the USA is possible. Further information can be found in X's privacy policy: https://x.com/de/privacy
II. Rights of the user
Irrespective of the details of the agreement, you can assert your rights under the GDPR with and against each individual controller. The user is entitled to the rights specified under Section A.II (Art. 15 to 18, 20, 21 and 77 GDPR).
III. Information on data processing
When accessing the respective company presence (Facebook, Instagram, X and LinkedIn), the respective platform operator processes user data (e.g. personal information, IP address). From this data, the platform operators create aggregated, statistical information for the controller on the use of the company presence (so-called insights or statistics); the controller does not thereby receive access to the underlying personal data of individuals. The platform operators also use the data in particular for market research and advertising purposes and for creating usage profiles. If the user is logged into their account when accessing the page, the platform operator can link the data to the respective user account.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the analysis, communication and promotion of the services. The legal basis may also be consent pursuant to Art. 6(1)(a) GDPR given to the respective platform operator, which can be withdrawn from that operator at any time. Further details on the respective processing activities can be found in the data protection notices and agreements of the platform operators linked under Section B.I.
