Legal
Privacy
How personal data is handled.
1. Privacy at a glance
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You will find their contact details in the section “Information about the controller” in this privacy policy.
How do we collect your data?
Some of your data is collected because you give it to us, for example when you send us an email.
Other data is collected automatically by our IT systems when you visit the website. This is mainly technical data (e.g., web browser, operating system, or time of the page request). This data is collected automatically as soon as you enter this website.
What do we use your data for?
The data is collected to ensure that the website is provided without errors and to answer your inquiries. We do not use any analytics, tracking, or advertising tools.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time about this and any other questions on the subject of data protection.
2. Hosting and storage
Hosting at netcup
We host our website at netcup GmbH. The provider is
netcup GmbH
Daimlerstraße 25
76185 Karlsruhe
Germany
For details, please see netcup’s privacy policy: https://www.netcup.com/de/kontakt/datenschutzerklaerung
netcup is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible.
Data processing agreement
We have concluded a data processing agreement (DPA) with netcup. This is a contract required by data protection law which ensures that netcup processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Storage of images and videos (Cloudflare R2)
We store the images, videos, and other files of this website in the R2 storage service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, in a data center within the European Union. The files are delivered through our own server: your browser does not connect to Cloudflare, and Cloudflare receives no data about your visit.
This is based on Art. 6(1)(f) GDPR; our legitimate interest is the reliable and secure storage of the content of our website. A data processing agreement is in place with Cloudflare; Cloudflare is certified under the EU-US Data Privacy Framework.
3. General information and mandatory information
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the internet (e.g., when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Information about the controller
The controller responsible for data processing on this website is:
Freiluft GmbH
Mühlenstraße 1
24143 Kiel
Germany
Phone +49(0)431-98279-15
Fax +49(0)431-98279-29
Email: ✉ Email address
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Storage period
Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for which it was processed no longer applies. If you assert a justified request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., retention periods under tax or commercial law); in the latter case, the data will be deleted once these reasons no longer apply.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out until the withdrawal remains unaffected by the withdrawal.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
If the data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right at any time to object to the processing of your personal data on grounds relating to your particular situation; this also applies to profiling based on these provisions. The respective legal basis on which a processing operation is based can be found in this privacy policy. If you object, we will no longer process your personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims (objection under Art. 21(1) GDPR).
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is connected with such direct marketing. If you object, your personal data will subsequently no longer be used for direct marketing purposes (objection under Art. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, their place of work, or the place of the alleged breach. The right to lodge a complaint is without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Information, deletion, and correction
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction or deletion of this data. You can contact us at any time about this and any other questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us about this at any time. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we usually need time to check this. For the duration of the check, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection under Art. 21(1) GDPR, your interests and ours must be weighed against each other. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data – apart from its storage – may only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a member state.
Objection to advertising emails
We hereby object to the use of contact data published as part of the legal notice obligation for sending unsolicited advertising and information material. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, for example by spam emails.
4. Data collection on this website
Server log files
Our server automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- time of the server request
- IP address
This data is not merged with other data sources.
This data is collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, the server log files must be recorded.
Consents and storage in your browser
If we embed content that may only be loaded after your consent (see section 5), a notice asks for your consent. We store your choice exclusively in your browser (in the so-called local storage under the name “freiluft-consent-v2”); it is not transmitted to us. You can change or withdraw your choice at any time via “Cookie settings” at the bottom of the page. If no such content is embedded, no notice appears and nothing is stored.
The legal bases for processing personal data in this context are Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR in conjunction with Section 25(2) no. 2 TDDDG. Our legitimate interest is the management of the technologies used and the related consents.
The provision of the personal data is neither required by contract nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we cannot manage your consents.
We do not use cookies for analytics or advertising purposes. Fonts are loaded from our own server; no connection to third parties is established.
Strictly necessary
What the website needs in order to work. This needs no consent (Section 25(2) No. 2 TDDDG) – here is what it is, what for and for how long.
Your cookie settings
Stores what you allowed or refused here, so the website sticks to it and does not ask again on every page.
- Type
- Browser storage (localStorage)
- Name
freiluft-consent-v2- Storage period
- 1 year, then the website asks again
- Provider
- This website
Place on the page
Remembers how far down a page you scrolled, so a reload brings you back to the same place.
- Type
- Storage of this tab (sessionStorage)
- Name
fl-scroll:…- Storage period
- until you close the tab
- Provider
- This website
Access to protected pages
Remembers for each password-protected page that you entered its password, and shows a notice after a wrong password.
- Type
- Cookie
- Name
page_access_…page_access_error- Storage period
- page_access_…: 7 dayspage_access_error: 30 seconds, only after a wrong password
- Provider
- This website
For editors only – visitors to the website never get these:
Editor sign-in
Keeps editors signed in to the admin and remembers the festival, language and color scheme there. These cookies only exist on the admin’s address – visitors to this website never get them.
- Type
- Cookie
- Name
payload-tokenpayload-tenant · payload-lng · payload-theme- Storage period
- payload-token: 2 hourspayload-tenant · payload-lng · payload-theme: 1 year
- Provider
- This website
Editor preview
Shows editors unpublished drafts of this website. Only a preview link from the admin creates it.
- Type
- Cookie
- Name
__prerender_bypass- Storage period
- until you close the browser or leave the preview
- Provider
- This website
External content
Videos, maps and pages from other providers, e.g. a ticket shop in a window. They load only with your consent; the provider then receives your IP address and technical details about your device.
Weeztix
Ticket shop · shop.weeztix.com
Provider: Weeztix B.V., Netherlands. The Weeztix ticket shop in a window on this website. Loading it sends your IP address and technical details about your device to Weeztix. The cart and payment are handled by Weeztix; for this the shop may set cookies of its own, store details in your browser and bring in further services (e.g. a waiting queue or statistics) – under the responsibility of Weeztix.
Privacy policy of the provider (opens in a new tab)
Inquiries by email, telephone, or fax
If you contact us by email, telephone, or fax, your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this was requested.
The data you send us via contact inquiries will remain with us until you ask us to delete it, withdraw your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Forms
If we offer a form on a page (e.g., for contact, registrations, or applications as an exhibitor), we store the information you enter in our system at netcup (see section 2) in order to handle your request, and send it to ourselves by email. To send these emails we use an email service, currently Resend (Resend, Inc., USA). The legal basis is Art. 6(1)(b) GDPR insofar as your request is related to a contract or its initiation, otherwise our legitimate interest in handling your request (Art. 6(1)(f) GDPR). The information remains with us until your request has been dealt with and no statutory retention periods prevent its deletion.
Newsletter
If you subscribe to a newsletter, we use your email address and, if provided, your name to send you the newsletter. Subscription uses the double opt-in procedure: you receive an email in which you confirm your subscription; only then are you added. We store the time of subscription and confirmation as proof. For sending and administration we use, depending on the newsletter, the service Brevo (Sendinblue SAS, Paris, France) or Mailchimp (The Rocket Science Group LLC, USA). The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the unsubscribe link in every newsletter; your data will then be deleted from the list.
Spam protection for forms (Cloudflare Turnstile)
If spam protection is switched on for a form on this website (e.g., for contact or the newsletter), the Turnstile service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, checks whether the entry comes from a human. For this purpose, the page loads a script from Cloudflare; your IP address and technical data about your browser and device are transmitted to Cloudflare. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protecting our forms against misuse and spam. Cloudflare is certified under the EU-US Data Privacy Framework. Further information: cloudflare.com/privacypolicy.
Search
We process search queries on our server in order to show you the results. We do not store them and do not pass them on to third parties.
Password-protected pages
If a page or the entire website is protected by a password, after you enter the correct password we set a technically necessary cookie (“site_access” or “page_access_…”, valid for 30 days) so that you are not asked again on every visit. The legal basis is Section 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(f) GDPR.
Notice windows
If a notice window opens by itself, we remember in your browser (session or local storage, name “modal-gesehen-…”) that you have seen it, so that it does not appear again on every page view. This information does not leave your browser. The legal basis is Section 25(2) no. 2 TDDDG.
Error monitoring
If a technical error occurs on our server, an error report may be sent to the service Sentry (Functional Software, Inc., USA) so that we can fix the error. The report contains technical information about the error; personal data such as your IP address is removed beforehand. The legal basis is our legitimate interest in an error-free website (Art. 6(1)(f) GDPR).
Posts from our Instagram account
When we show posts from our Instagram account on this website, our server fetches them through Instagram’s official interface (Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, D04 X2K5, Ireland) — the pictures (all pictures of an album), their captions, the date, and the links to the posts, every few hours. We store the pictures as copies with our storage service (see “Hosting and storage”) and deliver them from there.
What happens when you visit: nothing that involves Instagram. Your browser loads the posts from our server, not from Instagram; no data is transferred to Instagram or Meta, no cookies are set, and no scripts from Instagram are loaded. Clicking a post opens it on our website, also from our server. Only when you click “View on Instagram,” a hashtag or a profile in a caption, or the link to our profile does Instagram open in a new tab; from then on, Instagram’s privacy policy applies.
Purpose and legal basis: We want to show our Instagram account on our website without passing your data to Instagram for it. The legal basis is our legitimate interest in presenting our own posts in a data-minimizing way (Art. 6(1)(f) GDPR).
Storage period: We keep only the newest posts. Older posts, and posts we delete on Instagram, are removed from our server as well at the next fetch, picture included.
More: Instagram’s privacy policy.
Maps
When we show a map on this website, its pictures (map tiles) come from the OpenStreetMap project (OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom). Our server fetches each tile there the first time it is needed, stores it as a copy with our storage service (see “Hosting and storage”) and delivers it from there. In doing so, our server only tells OpenStreetMap which tile it needs and the address of our website — no data about you.
What happens when you visit: nothing that involves OpenStreetMap. Your browser loads the map and its tiles from our server, not from OpenStreetMap; no data is transferred to OpenStreetMap, no cookies are set and no third-party scripts are loaded. Only when you click “Get directions” does Apple Maps (on an iPhone or iPad) or Google Maps open in a new tab; from then on, Apple’s or Google’s privacy policy applies.
Purpose and legal basis: We want to show you where the festival takes place and how to get there without passing your data to a map provider for it. The legal basis is our legitimate interest in providing directions in a data-minimizing way (Art. 6(1)(f) GDPR).
Storage period: Map tiles are pictures of the map, not data about you. We keep them as long as the map provider allows, at least seven days, and then check whether they have changed.
More: the OpenStreetMap Foundation’s privacy policy.
Links to social networks
We link to our profiles on social networks such as Instagram, Facebook, and TikTok. These are simple links: only when you click on them is the page of the respective network opened, and only then do its privacy provisions apply. Before that, no data is transmitted to these providers.
5. Content embedded from other providers
Some content may come from other providers, such as videos, maps, or a ticket shop. It is only loaded once you have agreed via the notice or clicked “Load content”. Only then does your browser connect to the respective provider, who receives your IP address and technical data and may set its own cookies. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); you can withdraw it at any time via “Cookie settings”. The notice names the providers that are currently embedded. Possible providers are:
- YouTube videos: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. We use the privacy-enhanced mode (youtube-nocookie.com). Privacy policy: policies.google.com/privacy
- Vimeo videos: Vimeo Inc., USA. Privacy policy: vimeo.com/privacy
- Google Maps: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: policies.google.com/privacy
- OpenStreetMap maps: OpenStreetMap Foundation, United Kingdom. Privacy policy: osmfoundation.org/wiki/Privacy_Policy
- Ticket shop: Weeztix (Netherlands). The purchase itself is subject to the terms and privacy policy of Weeztix, which are linked in the shop.
Insofar as data is transferred to the USA in the process, this is done on the basis of the EU-US Data Privacy Framework if the provider is certified under it, and otherwise on the basis of the European Commission’s standard contractual clauses.
Accommodation
Sleep where the festival is
Campsites right behind the dike: two minutes to the water, no early morning drive, and in the evening you just stay where you are. Tents, vans, and everything in between.
