Data protection

Privacy policy

How Founderland collects, uses, protects, and shares personal data—and the choices available to you.

Updated September 4, 2026
01

Controller and contact

Founderland gUG (haftungsbeschränkt) is responsible for data processing described here. Contact hello@founderland.org for general questions or dpo@founderland.org for data-protection requests. Registered office: c/o Factory Works GmbH, Rheinsberger Str. 76/77, 10115 Berlin.

02

Your rights

  • Access your personal data and information about its processing (Art. 15 GDPR).
  • Correct inaccurate data (Art. 16).
  • Request deletion where applicable (Art. 17).
  • Restrict processing where applicable (Art. 18).
  • Object to processing based on legitimate interests (Art. 21).
  • Receive portable data where processing is based on consent or contract (Art. 20).
  • Withdraw consent at any time for future processing.
  • Complain to the competent data-protection supervisory authority.
03

Data we process

  • Basic technical request and security data when the website is visited.
  • Contact details and message content when you contact Founderland.
  • Membership, authentication, profile, directory, and consent records for the private member portal.
  • Separate public founder or speaker profile information where explicit public-listing consent exists.
  • Grant application and administration data.
  • Email addresses submitted to access an impact report; this does not create marketing consent.
04

Purposes and legal bases

Founderland processes data to operate and secure the site and member community, answer enquiries, administer membership and grants, honour visibility choices, provide requested resources, meet legal obligations, and improve services. Depending on the activity, the basis is consent (Art. 6(1)(a)), contract or pre-contractual steps (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)), or legitimate interests (Art. 6(1)(f)).

05

Member and public profiles

Private member-directory information is available only to approved authenticated members and is protected by database access policies. Public founder and speaker listings require separate consent. Withdrawing public-listing or directory consent must remove the relevant visibility without cancelling membership.

06

Recipients and external services

Data may be processed by contracted providers necessary to run the service, such as hosting, Supabase authentication/database services, form or grant tools, email delivery, file hosting, and payment providers. External links—including Typeform, Google Drive, Stripe, social networks, and community tools—apply their own privacy terms when visited. Founderland does not sell personal data.

07

Retention

Contact-form or enquiry data is generally removed no later than 24 months after the matter is resolved unless a contract or legal retention obligation requires longer storage. Membership, consent, grant, and financial records are retained only for their documented operational or legal purpose. Withdrawal, correction, export, and deletion requests are handled subject to applicable obligations.

08

International transfers and security

Where a provider processes data outside the EEA, Founderland must use an applicable GDPR transfer mechanism and document it before launch. Data in transit is protected with HTTPS in production. Access is limited according to role and purpose; no online system can guarantee absolute security.

09

Cookies and analytics

Founderland uses only browser storage necessary for core functions such as authentication and security. Google Analytics and Hotjar are not currently used. Any future non-essential analytics or marketing technology will require appropriate notice and consent. See the Cookies page.

10

Changes and questions

Founderland may update this policy when its services, providers, or legal duties change. The version published when you next visit applies. Questions and rights requests may be sent to dpo@founderland.org.

11

Hinweise auf Deutsch

Founderland nimmt Datenschutz ernst und verarbeitet personenbezogene Daten nach der DSGVO und dem Bundesdatenschutzgesetz. Sie haben insbesondere Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Widerspruch und Datenübertragbarkeit. Eine erteilte Einwilligung kann jederzeit mit Wirkung für die Zukunft widerrufen werden. Für Datenschutzanfragen kontaktieren Sie dpo@founderland.org. Diese deutsche Kurzfassung wird vor Veröffentlichung mit der vollständigen Datenschutzerklärung abgestimmt.