Legal
Privacy Policy
Last updated: 21 August 2026
1. Controller
Notice regarding the controller
The controller responsible for data processing on this website is:
FAL-Freude am Leben e.V.
Gesundheitsverein (health association)
Beatrice Kapek
Friedrich-Wilhelm-Str. 38
12103 Berlin, Germany
Phone: +49 (0)163 987 10 31
E-mail:
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data. Further details can be found in our imprint.
We have not appointed a data protection officer, as the legal requirements for doing so do not apply. If you have any questions about data protection, please contact the address above.
2. Hosting
This website is hosted by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The data is processed in a data centre in Helsinki (Finland) and therefore within the European Union.
We use this hosting provider on the basis of our legitimate interest in providing our online offering securely, reliably and efficiently (Art. 6 (1) (f) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
3. Server log files
When you access this website, the web server automatically processes information transmitted by your browser (so-called server log files):
- the page or file requested
- date and time of access
- amount of data transferred and notification of successful retrieval
- browser type and version
- operating system used
- referrer URL (the page visited previously)
- IP address
This data is not merged with other data sources and is not used to identify individuals. We do not keep a permanent access log: the server's technical logs are automatically overwritten at regular intervals and are generally no longer available after 30 days at the latest. They are kept longer only if they are needed to investigate a specific security incident. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the technically faultless operation and the security of the website.
4. Cookies
This website does not use any marketing, advertising or statistics cookies. The only cookie set is a technically necessary session cookie of the content management system, plus a token protecting the forms against cross-site request forgery. The legal basis is § 25 (2) no. 2 TDDDG in conjunction with Art. 6 (1) (f) GDPR.
These cookies contain no profiling data, are not used to recognise you across several websites and expire when you close your browser at the latest. As we do not use any cookies requiring consent, this website does not need a cookie consent banner either.
5. Forms on this website
We provide three forms. Each of them processes only the details you enter yourself:
- Contact form: name, e-mail address, phone number (optional) and your message.
- Supporting membership: company or organisation (optional), name, street, postcode and town, e-mail address, website and phone number (optional) as well as your message.
- Exhibitor enquiry: company or offering, contact person, e-mail address, phone number (optional), preferred date and your description of what you would like to present.
Mandatory fields are marked with an asterisk. Before submitting, you must explicitly consent to the processing of your details. The legal basis is Art. 6 (1) (a) GDPR (your consent) as well as Art. 6 (1) (b) and (f) GDPR insofar as your enquiry concerns the establishment or performance of a membership or an exhibitor participation. You may withdraw your consent at any time with effect for the future.
Your entries are transmitted to the association by e-mail and additionally stored in the form database of this website. We do not store your IP address in the process. Stored submissions are deleted automatically after twelve months at the latest, and earlier if your enquiry has been dealt with and no statutory retention obligations apply.
6. Spam protection with ALTCHA
To protect our forms against automated submissions we use ALTCHA. ALTCHA sets your browser a small computing task (proof of work) that is solved in the background – you do not have to solve a picture puzzle.
ALTCHA runs entirely on our own server. No data is transmitted to third-party providers, no cookies are set and no user tracking takes place. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in protection against spam and misuse.
7. Newsletter
If you would like to subscribe to our newsletter, we need your e-mail address. We do not ask for any further details.
Subscription uses the double opt-in procedure: after submitting the form you receive an e-mail in which you must confirm your subscription. Only then do we add you to the mailing list. As proof of the subscription we store the time of the subscription, the time of the confirmation and the IP address used. The legal basis is Art. 6 (1) (a) GDPR.
You can unsubscribe at any time using the unsubscribe link in every newsletter
or by sending an informal message to
8. Contacting us by e-mail or telephone
If you contact us by e-mail or telephone, we process your details solely in order to deal with your request. The legal basis is Art. 6 (1) (b) GDPR for enquiries about a membership or an exhibitor participation, otherwise Art. 6 (1) (f) GDPR. Here too: we delete the data as soon as the matter has been dealt with and no retention obligations apply.
9. No web analytics, no tracking
No reach measurement and no analysis of your usage behaviour takes place on this website. We use neither Google Analytics nor any comparable analytics, advertising or tracking service. No usage profiles are created, no cross-site tracking takes place and no automated decision-making occurs.
Should we introduce anonymous reach measurement in the future, we will amend this privacy policy accordingly beforehand.
10. No social media plugins
No social media plugins are embedded on this website. References to profiles on social networks would be plain links: only when you click such a link is a connection to the respective provider established and does the provider receive data about your visit. The respective provider is responsible for the processing on those platforms.
11. Fonts
The fonts used on this website are delivered locally from our own server. There is no connection to third-party servers, in particular not to Google Fonts; no data is transmitted to third parties. Likewise, no map services, video platforms or other third-party content are embedded.
12. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the browser address bar starting with “https://” and by the padlock symbol. As long as encryption is active, the data you transmit to us cannot be read by third parties.
13. Recipients and transfers to third countries
We only pass on your data insofar as this is necessary to fulfil our contractual or legal obligations. Recipients are:
- our hosting provider Hetzner Online GmbH as a processor (see section 2),
- the operator of our e-mail dispatch, ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf (Germany), through which the form and newsletter e-mails are sent,
- SiteGround Spain S.L., Calle de Prim 19, 28004 Madrid, Spain, which hosts the association’s e-mail account (
This email address is being protected from spambots. You need JavaScript enabled to view it. ) where your enquiries arrive and are stored; processing takes place on servers within the European Union, - our technical service provider for the support and maintenance of this website as a processor pursuant to Art. 28 GDPR.
No further transfer to countries outside the European Union takes place.
14. Your rights as a data subject
You have the following rights towards us with regard to your personal data:
- access to the data we process (Art. 15 GDPR)
- rectification of incorrect or incomplete data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability in a common, machine-readable format (Art. 20 GDPR)
- objection to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR)
- withdrawal of consent given, with effect for the future (Art. 7 (3) GDPR)
An informal message to
15. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin, Germany
Internet: www.datenschutz-berlin.de
16. Changes to this privacy policy
We adapt this privacy policy as soon as changes to our website or to the legal situation make this necessary. The version published here applies in each case.