Privacy
Your data is safe with us
We take the protection of your personal data seriously. We process your data confidentially in accordance with the GDPR and this privacy policy. This notice describes what we process on www.wunder.charity based on the current state of our website and extensions.
Data controller
WUNDER - Joline Schöngen Foundation
Am Mittelberg 31
51375 Leverkusen-Schlebusch, Germany
Email: datenschutz@wunder.charity
What data do we collect?
When you donate:
• Name and address (for donation receipts)
• Email address
• Donation amount, date and chosen project/purpose
• Payment data is processed directly by Stripe - we do not store full card details
• Optional: postcode/city lookup via address assist - sends a request to OpenStreetMap/Nominatim only when you use this feature
• Optional when bank connection is enabled: when matching incoming transfers, counterparty name, IBAN and remittance text from the bank transaction may be processed and linked to the donation
When you subscribe to our newsletter:
• Email address
• First name (optional)
• Timestamp and proof of double opt-in consent
• Newsletter language
For newsletters we send, we measure clicks pseudonymously: links route via our own server; we store the campaign, the clicked link and a random recipient token - no IP address and no open tracking (no tracking pixel). The legal basis is your newsletter consent (Art. 6(1)(a) GDPR); the association ends when you unsubscribe.
When you visit the website (technical):
• IP address (security and abuse prevention)
• Date and time of access
• Page requested and HTTP status
• Browser type, operating system and device type (from user agent)
• Referrer URL (source page, if transmitted)
This data appears in server logs and rate limiting. We do not use third-party marketing or reach trackers (e.g. Google Analytics or Meta Pixel).
For fallback/placeholder images (e.g. story pages, About us), images may be loaded from the Unsplash CDN; your IP address may then be transmitted to Unsplash.
When you enter an email address in public forms (contact, donate, newsletter, project subscribe), we check the domain via Google Public DNS (MX/A lookup); only the email domain is sent to Google.
Optional with “Wunder Insights” enabled: anonymised first-party web analytics (page views, click heatmaps, scroll depth, and a coarse, IP-derived approximate location: country, region/state and city; the IP address itself is not stored) without marketing cookies. The coarse location is derived server-side via our hosting/CDN provider and is not shared with third parties for advertising. Legal basis: Art. 6(1)(f) GDPR. You may opt out via “Decline web analytics” in the footer.
In “My Account” (after donor login):
• Email address and donor profile (name, address, newsletter preference)
• Donation history, badges and optional birthday campaign metadata
• Session cookie after magic-link login (max. 24 hours, technically necessary)
Why do we use your data?
• Donation data: receipts, tax retention, donor communication
• Newsletter: information about projects and our work (consent only)
• Website technical data: operation, stability and abuse prevention
• My Account: providing the donor portal
• Optional AI chatbot: answering your questions when you voluntarily use the chat
• Optional bank connection: automatically matching incoming donation transfers to open donations (read-only account information)
Legal basis
Processing is based on:
• Art. 6(1)(a) GDPR (consent) - newsletter, optional AI chat; for the bank connection also the account holder’s explicit, revocable Open Banking/PSD2 consent to account information
• Art. 6(1)(b) GDPR (contract) - donations and donor portal, matching incoming payments
• Art. 6(1)(c) GDPR (legal obligation) - tax retention
• Art. 6(1)(f) GDPR (legitimate interest) - technical logs, security and abuse prevention; email domain checks to reduce invalid addresses; efficient matching of bank transactions to donations; delivery of fallback images
How long do we keep your data?
• Donation data: 10 years (tax law)
• Newsletter: until you withdraw consent; unconfirmed double opt-in signups are deleted automatically after the reminder
• Server logs: approx. 7 days
• Rate-limit entries: minutes to a few hours
• Donor session: max. 24 hours
• AI chat history: per internal retention rules (only if chatbot is used)
• Bank transactions (if connection enabled): as long as needed for matching and traceability of donation processing, consistent with tax retention duties; retention at Enable Banking per their processor agreement / DPA
Cookies and local storage
We do not use third-party marketing or tracking cookies. A cookie consent banner is therefore not required for normal browsing.
Technically necessary storage only when you use specific features:
• Donor login: session cookie after magic-link sign-in (24 h)
• Optional AI chatbot: chat session ID in your browser’s local storage, only when you open the chat
• Optional Wunder Insights: anonymous session ID in sessionStorage (no cookie) and opt-out flag in localStorage if you decline
Fonts are served locally via Next.js (no Google Fonts loaded in the browser). You can delete local storage and cookies in your browser settings at any time.
Sharing of data
We only share your data if:
• you have given consent
• it is required to perform a contract
• we are legally obliged to do so
Processors (Art. 28 GDPR):
• Hetzner Online GmbH, Gunzenhausen, Germany - hosting, servers and email delivery (SMTP) (hetzner.com/legal/privacy-policy)
• Stripe Payments Europe Ltd., Dublin, Ireland - payment processing (stripe.com/privacy)
Other recipients for specific features (no marketing tracking):
• Google LLC, USA (dns.google / Google Public DNS) - when validating email addresses on public forms (contact, donate, newsletter, project subscribe), the domain of the entered email address is sent to Google for an MX/A lookup. No other form data. (developers.google.com/speed/public-dns/privacy)
• Unsplash, Inc. (images.unsplash.com) - fallback/placeholder images (e.g. story pages, About us); loading may transmit the visitor’s IP address to Unsplash (unsplash.com/privacy)
When optional extensions are enabled:
• Enable Banking Oy, Otakaari 5, 02150 Espoo, Finland (EU) - licensed account information service (AISP) under PSD2, supervised by FIN-FSA. Read-only retrieval of balances and transactions of the foundation account (including counterparty name, amount, remittance text) to automatically match incoming donations. No payment initiation (no PIS), no access to bank logins/PIN/TAN. Processing in the EU (enablebanking.com/privacy). A GDPR processor agreement (DPA) with Enable Banking should be in place.
• Anthropic PBC, USA - AI chatbot and personalised impact reports (anthropic.com/privacy). EU Standard Contractual Clauses. Anthropic is the only AI provider we use.
• OpenStreetMap Foundation / Nominatim - address suggestions when donating, only if postcode lookup is used (openstreetmap.org/privacy)
Using the AI chatbot is voluntary. Donations, newsletter and information work without it.
Your rights
You have the right to:
• Access (Art. 15 GDPR)
• Rectification (Art. 16 GDPR)
• Erasure (Art. 17 GDPR)
• Restriction (Art. 18 GDPR)
• Data portability (Art. 20 GDPR)
• Object (Art. 21 GDPR)
• Withdraw consent (Art. 7(3) GDPR)
Contact: datenschutz@wunder.charity
Right to lodge a complaint
You may lodge a complaint with a supervisory authority.
Competent authority (Germany):
State Commissioner for Data Protection and Freedom of Information NRW
Kavalleriestraße 2-4
40213 Düsseldorf, Germany
www.ldi.nrw.de
TLS encryption
This website uses TLS encryption (HTTPS). You can recognise a secure connection by “https://” in the address bar and the lock icon in your browser.