This Privacy Policy is published for the Action Network Worldwide platform and also covers the academy. For academy.actionnetwork.world and the academy signup, the additional information at the end of this page takes precedence. Read the additional information for the academy
- Signing up for the academy happens on a Google Form; how those answers are handled is set out in the additional information below.
- academy.actionnetwork.world uses no analytics and sets no cookies of its own; its one cookie is listed in our own Cookie Policy, not in the tables below.
- This site is hosted and delivered by different providers than actionnetwork.world.
Privacy Policy
Last Updated: 8 October 2026
1. Controller
The controller responsible for the processing of your personal data is:
Weltweit – Gesellschaft zur Förderung lokaler Initiativen e.V.
Talstr. 1
65812 Bad Soden
Germany
Registered at Amtsgericht Königstein im Taunus, VR 1327
Representatives: Kajo Stelter, Frank Müller, Marie Wellenbeck
For privacy-related inquiries, please use our support contact form.
Supervisory Authority:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Germany
Email: poststelle@datenschutz.hessen.de
2. Overview
This Privacy Policy explains how Weltweit – Gesellschaft zur Förderung lokaler Initiativen e.V. (“we”, “us”, “our”) collects, uses, stores, and shares your personal data when you use the Action Network platform (“Platform”, “Service”) at actionnetwork.world.
We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG), and the Telecommunications-Telemedia Data Protection Act (Telekommunikation-Telemedien-Datenschutz-Gesetz, TDDDG).
This Privacy Policy should be read in conjunction with our Terms of Service.
3. Legal Bases for Processing
We process your personal data only where we have a legal basis to do so under Article 6(1) GDPR:
- Article 6(1)(a) GDPR – Consent: You have given clear, affirmative consent to the processing of your personal data for one or more specific purposes (e.g., analytics, optional Google Drive integration).
- Article 6(1)(b) GDPR – Contract Performance: Processing is necessary for the performance of a contract to which you are a party (e.g., providing Platform services, managing your account, processing subscriptions and payments).
- Article 6(1)(c) GDPR – Legal Obligation: Processing is necessary for compliance with a legal obligation to which we are subject (e.g., retention of invoices and accounting records under German tax and commercial law).
- Article 6(1)(f) GDPR – Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided that your interests and fundamental rights do not override those interests (e.g., error logging, security, fraud prevention).
Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
4. Data We Collect
4.1 Authentication Data
When you register for an account, we collect the following data via our self-hosted Keycloak identity provider:
- Email address
- Name (first name, last name)
- Password (stored as a cryptographic hash; we never store plaintext passwords)
- Keycloak subject ID (unique identifier)
- Realm access roles (user permissions)
- Preferred username
Legal basis: Article 6(1)(b) GDPR (contract performance).
Authentication protocol: We use OAuth 2.0 with PKCE (Proof Key for Code Exchange, S256) for secure authentication. Access and refresh tokens are issued by Keycloak and validated server-side using the jose library.
4.2 Profile Data
During onboarding and when you edit your profile, we collect:
- First name, last name
- Bio / specialty (optional)
- Interests (tags, optional)
- Match tags (tags for matching purposes, optional)
- Location (latitude/longitude coordinates, optional)
- Avatar image (optional)
Legal basis: Article 6(1)(b) GDPR (contract performance).
4.3 Organization Data
If you create or join an organization, we collect:
- Organization name
- Organization alias (URL-friendly slug)
- Organization type (e.g., NGO, social enterprise)
- Organization description
- Organization logo (optional)
- Organization membership roles (admin, editor, member, viewer)
- Organization verification status and documentation (if you apply for verification)
Legal basis: Article 6(1)(b) GDPR (contract performance).
4.4 User Settings
We store your preferences and settings, including:
- Locale (language preference)
- Timezone
- Notification preferences (email digest, match alerts, connection alerts, opportunity alerts, workspace alerts)
- Privacy settings (profile visibility, show email, show location)
Legal basis: Article 6(1)(b) GDPR (contract performance).
4.5 Subscription and Payment Data (Paid Plans Only)
If you subscribe to a paid Solo or Org plan, we process the following data:
- Stripe customer ID and subscription ID (generated by Stripe)
- Subscription plan (Solo or Org), tier (including NGO discount tier), billing cycle (monthly or annual)
- Subscription status (active, trialing, past_due, canceled, etc.)
- Trial allotment (whether you have used your one trial per email address)
- Current period end date, cancel-at-period-end flag
- Billing name and address
- VAT identification number (VAT-ID, for Org customers subject to reverse charge)
- Invoice records (invoice number, amount, date, status, line items)
- Early-start consent and withdrawal acknowledgement records (for Solo consumers, per § 356 BGB)
Payment card data: Your credit or debit card number, CVV, and expiry date are collected and stored by Stripe (our payment processor), not by us. We never receive or store your full card number. Stripe processes payment card data under its own PCI-DSS certification and privacy terms.
Legal basis:
- Article 6(1)(b) GDPR (contract performance) for payment processing, subscription management, and billing.
- Article 6(1)(c) GDPR (legal obligation) for retention of invoices and accounting records under German tax law (§ 147 Abgabenordnung, 10 years) and commercial law (§ 257 Handelsgesetzbuch, 6–10 years).
Note: Free-tier users have no payment data processed. Subscription and payment data applies only to users on a paid plan or trial.
Note (subject to legal/finance review): the VAT-ID / reverse-charge processing described above is contingent on Stripe Tax, OSS registration, and VIES validation being configured in the billing system. Confirm the actual configuration before publishing, and describe only the processing that genuinely occurs.
4.6 Workspace Data
If you create or participate in workspaces, we collect:
- Workspace title, slug, and mode (task-mode or project-mode)
- Workspace member and coordinator roles
- Deliverables (tasks, documents, milestones scoped to the workspace)
- Activity logs (changes, updates, and actions within the workspace)
Legal basis: Article 6(1)(b) GDPR (contract performance).
4.7 Google Drive Integration (Optional)
If you choose to connect your Google Drive account to a workspace, we collect and store:
- Google OAuth access and refresh tokens (stored server-side; never exposed to your browser)
- Google account email address
- Selected root folder ID
- Connection capabilities (permissions granted)
- Token expiry timestamp
Files and documents remain stored on your own Google Drive account, not on our servers. The Platform acts solely as an interface to access and manage your Google Drive files.
You may disconnect your Google Drive account at any time through workspace settings, which immediately revokes the Platform’s access to your Google Drive.
Legal basis: Article 6(1)(a) GDPR (consent, given when you authorize the Google Drive connection).
4.8 API Access Tokens
If you generate personal API access tokens to grant external services (e.g., AI agents) access to your Platform data, we store:
- Token hash (the unhashed token is shown to you once and never stored)
- Token name (optional label)
- Creation timestamp
- Last-used timestamp
Legal basis: Article 6(1)(b) GDPR (contract performance).
4.9 Contact Form Data
When you submit a support inquiry via our contact form, we collect:
- First name, last name
- Email address
- Subject and message
This data is transmitted via Brevo’s transactional email API to our support team. We also implement bot protection (honeypot field and 3-second timing check) and rate limiting (5 submissions per IP address per hour, stored in-memory only).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in providing customer support).
4.10 Feedback Data
When you submit feedback via our GitHub-based feedback system, we collect:
- Feedback type (bug, feature request, question, other)
- Title and description
- Email address (optional)
- Page URL, user agent, timestamp
Feedback is posted as a public GitHub issue in our repository (welt-weit/anw-portal). Same bot protection and rate limiting as contact form applies.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in improving the Platform).
4.11 File Uploads
When you upload images (avatar, organization logo), we:
- Process the image server-side (resize, format conversion to WebP, EXIF metadata removal)
- Sanitize SVG files (for logos) to remove potentially harmful code
- Store the processed image on our content delivery network (DigitalOcean Spaces, EU Frankfurt region)
- Make the image publicly accessible via CDN URL
Legal basis: Article 6(1)(b) GDPR (contract performance).
4.12 Error Logging Data
When an error occurs on the Platform, we may log the following data to Better Stack (Logtail) for debugging and monitoring purposes:
- Error message and stack trace
- Page URL
- User agent string
- HTTP status code
- Timestamp
- Ticket ID (unique error identifier)
We do not log passwords, authentication tokens, or other sensitive credentials.
Error logging is optional and only active if the VITE_LOGTAIL_SOURCE_TOKEN environment variable is configured.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in maintaining Platform security and reliability).
4.13 IP Addresses
We collect IP addresses only for the following limited purposes:
- Rate limiting (contact form and feedback submissions): IP addresses are stored in-memory only and purged within 1 hour. They are not persisted to disk or logs.
- Country lookup for analytics (only if you have consented to analytics, see section 5.3): when an analytics event is received, your IP address is used transiently to determine your country. Only the country is kept; the IP address itself is not stored in our analytics data.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in preventing abuse) for rate limiting; Article 6(1)(a) GDPR (consent) for the analytics country lookup.
4.14 Map Data
When you use the interactive map feature (powered by Mapbox), the following data may be transmitted to Mapbox (based in the United States):
- Latitude and longitude coordinates (approximate location)
- Location search queries (if you use the location picker)
We do not send your name, email, or other personally identifiable information to Mapbox.
Legal basis: Article 6(1)(b) GDPR (contract performance – providing map functionality).
4.15 Mobile App – Camera and Receipt Scanning
The NGOstack mobile app lets you photograph expense receipts and capture photos as project evidence. When you scan a receipt, the image is transmitted to our servers and processed by an AI provider (see section 6) to extract text and pre-fill the expense form. The image and the extracted text are stored with the resulting expense or evidence record.
When your device is offline, text extraction runs entirely on the device and no image is transmitted until the record syncs. Camera access is requested only when you begin a capture, and can be revoked at any time in your device settings.
Legal basis: Article 6(1)(b) GDPR (contract performance – providing expense and evidence capture).
4.16 Mobile App – Device Location
When you tap the location control on an evidence or project-update form, the app reads your device’s current coordinates and attaches them to that record. This is precise location data, collected only at that moment and only on your explicit action.
The app does not collect location in the background, or at any time when you are not actively using it. The field is optional and records save without it.
Legal basis: Article 6(1)(a) GDPR (consent – given by the explicit action of tapping the control).
4.17 Mobile App – Push Notifications
With your permission, the app receives notifications about your projects and workspaces. Delivery requires sharing a device push token with Google (on Android) or Apple (on iOS) – see section 6. The token identifies the device installation, not you personally.
Notification permission can be declined or revoked at any time; the app remains fully usable without it.
Legal basis: Article 6(1)(a) GDPR (consent – given via the operating system permission prompt).
4.18 Mobile App – Biometric Unlock
You may protect access to the app with Face ID, Touch ID, or Android biometric authentication. Biometric data is held exclusively by your device’s operating system and is never transmitted to us, stored by us, or accessible to the app – the app receives only a pass or fail result.
We therefore process no biometric data within the meaning of Article 9 GDPR.
Legal basis: Article 6(1)(b) GDPR (contract performance – providing optional app-lock security).
4.19 Mobile App – Data Stored on Your Device
So that the app works without connectivity, it stores a local database of the records you have opened and any changes you have not yet synced. Authentication tokens are held in the iOS Keychain or the Android Keystore, hardware-backed on devices that support it.
All of this data is removed when you sign out or uninstall the app.
Legal basis: Article 6(1)(b) GDPR (contract performance – providing offline access).
5. Cookies and Local Storage
Note (subject to legal review): this section was updated for the opt-in analytics model. Confirm the storage categorisation, the analytics legal basis and the retention wording before publishing.
We use cookies and browser storage (localStorage, sessionStorage) to provide and improve the Platform. You can control your cookie preferences via our cookie consent banner, managed by vanilla-cookieconsent.
5.1 Cookies
| Cookie Name | Purpose | Duration | httpOnly | Category |
|---|---|---|---|---|
access_token |
JWT access token for authentication (the token itself is valid for 15 minutes and is renewed automatically) | 60 days, or until logout | Yes | Necessary |
refresh_token |
JWT refresh token for session renewal | 60 days, or until logout | Yes | Necessary |
cc_cookie |
Cookie consent preferences (vanilla-cookieconsent) | 365 days | No | Necessary |
onboarded |
Remembers that the signed-in account has completed onboarding, so you are not sent back into the setup flow (contains your account ID) | 365 days, or until logout | No | Necessary |
anw_in_app |
Set only when the Platform is opened inside the NGOstack mobile app; keeps the in-app layout for the rest of that visit | Browser session | Yes | Necessary |
All cookies use Secure and SameSite=Lax attributes for security.
5.2 Browser Storage
Entries in the Analytics category are written only after you have consented to analytics. Necessary entries carry a step you started (such as signup or accepting an invitation) or are needed for the Platform to work. Functional entries only remember choices you made in the interface; they stay in your browser and are not sent to us.
| Key | Storage Type | Purpose | Duration | Category |
|---|---|---|---|---|
anw:analytics-sid |
sessionStorage | Random analytics session ID for this browser tab (first-party only). Written only after you consent to analytics | Browser tab session; replaced after 30 minutes of inactivity | Analytics |
anw:analytics-utm |
sessionStorage | UTM campaign parameters of the link you arrived through. Written only after you consent to analytics | Browser session | Analytics |
anw:analytics-attr |
sessionStorage | The website hostname that referred you and the page you landed on (first-party only). Written only after you consent to analytics | Browser session | Analytics |
anw:analytics-last |
sessionStorage | Time of your last activity, used to start a new analytics session after 30 minutes of inactivity. Written only after you consent to analytics | Browser session | Analytics |
anw:oid |
localStorage | Active organization ID | Until changed | Necessary |
anw:signup-intent |
sessionStorage | User’s stated intent during signup (org vs. network) | Browser session | Necessary |
anw:build-id |
localStorage | Deployed version tracking for update notifications | Until cleared | Necessary |
anw:pending-invite |
sessionStorage | The invitation you followed, kept until you have signed in so it can be accepted | Browser session | Necessary |
anw:space-invite |
sessionStorage | The community space invitation from a join link, kept until signup is complete | Browser session | Necessary |
anw:referral-token |
sessionStorage | The referral link you arrived through, kept until signup is complete | Browser session | Necessary |
anw:post-onboarding-redirect |
sessionStorage | The page to return you to after onboarding | Browser session | Necessary |
anw:account-deleted-email |
sessionStorage | Your email address after you delete your account, so the confirmation page can name it | Browser session | Necessary |
anw:wid |
localStorage | Active workspace | Until changed | Functional |
anw:ws-scope |
localStorage | Whether you last viewed your personal or shared workspaces | Until changed | Functional |
anw:color-mode |
localStorage | Light or dark display preference | Until changed | Functional |
anw:announcement-dismissed |
localStorage | Remembers that you closed the announcement bar | Until cleared | Functional |
anw:match-tags-alert-dismissed |
sessionStorage | Remembers that you closed the match-tags reminder | Browser session | Functional |
anw:trial-banner-dismissed |
sessionStorage | Remembers that you closed the trial banner | Browser session | Functional |
anw:referral-prompt-shown-at |
localStorage | When the referral prompt was last shown, so it is not repeated too often | Until cleared | Functional |
anw:featured-carousel-open |
localStorage | Whether the featured opportunities carousel is expanded | Until changed | Functional |
anw:proposal-draft-wizard-v1 |
localStorage | Unsaved progress in the proposal draft wizard | Until the draft is created or cleared | Functional |
5.3 Analytics
We use first-party analytics only. We do not use Google Analytics or any third-party tracking services.
Only with your consent. Analytics is off until you accept the analytics category in the cookie consent banner. Until then, nothing is sent to us for analytics and nothing is stored in your browser for analytics. If you are signed in, we collect analytics only when you have explicitly agreed, and that choice is stored on your account.
Analytics events are sent from your browser to our own API and stored in a ClickHouse database that we run ourselves on our hosting infrastructure (see section 6). No third-party analytics provider receives them.
For each event we collect:
- A random session ID (generated in your browser, stored in sessionStorage per tab, and replaced after 30 minutes of inactivity)
- Your account ID, if you are signed in and have consented
- The page path (query strings are removed and secret tokens in the path are masked) and the page title
- The event name and category, for example a page view, a feature you used, a search, whether you started and completed sign-up, a click on a link that leaves our site (the destination hostname only) or a file download (the file name only)
- Device type, browser and operating system, derived from your browser’s User-Agent
- Your country, derived from your IP address. The IP address is used only for this lookup and is not stored in our analytics data
- The referring website (the hostname only, for example google.com — never the full address or its query string) and the page you landed on
- UTM campaign parameters (if present in the link you followed), and the traffic channel derived from them (for example “Email” or “Organic Search”)
How you first found us. If you have consented to analytics when you create your account, we save on your account a single record of how you first arrived: the UTM campaign parameters of the link you clicked, the referring website’s hostname, the page you landed on, and the resulting traffic channel (for example “Email” or “Organic Search”). We use it only to understand which outreach reaches people. It is written once and never updated, it never contains an IP address, a full web address or a query string, it is included in your data export (Article 20 GDPR) and it is deleted with your account. Without that consent, no such record is created.
Retention. Raw analytics events are deleted automatically after 90 days. Aggregated statistics (for example daily page-view counts) may be kept for longer.
Legal basis: Article 6(1)(a) GDPR together with § 25(1) TDDDG (consent). You can withdraw your consent at any time in the cookie settings or in your account’s privacy settings. From then on, no further analytics data is collected. Withdrawal does not affect processing that took place before it.
6. Third-Party Service Providers
We engage the following third-party processors to provide Platform services. Each processor is bound by a data processing agreement (DPA) or contractual terms that ensure GDPR compliance.
| Provider | Purpose | Data Processed | Location | Transfer Basis |
|---|---|---|---|---|
| Keycloak (self-hosted) | Authentication, identity management | Email, name, password hash, subject ID, roles | EU (self-hosted) | N/A (EU-hosted) |
| DigitalOcean | Hosting, storage (Spaces CDN) | All Platform data, uploaded images | EU (Frankfurt) | N/A (EU-hosted) |
| Stripe Payments Europe, Ltd. | Payment processing (paid plans only) | Billing name/address, VAT-ID (Org), email, card data (stored by Stripe), subscription & invoice records | EU (Ireland) + USA sub-processing | EU-US Data Privacy Framework + SCCs (Art. 46(2)(c) GDPR) |
| Brevo (Sendinblue) | Transactional email (contact form, notifications) | Name, email, message content | EU | N/A (EU-hosted) |
| Better Stack (Logtail) | Error logging and monitoring | Error messages, stack traces, page URL, user agent, timestamp | EU | N/A (EU-hosted) |
| GitHub (Microsoft) | Feedback system (issue tracking) | Feedback text, email (optional), page URL, user agent, timestamp | USA | EU-US Data Privacy Framework + SCCs (Art. 46(2)(c) GDPR) |
| Mapbox | Interactive map | Coordinates (lat/lng), location search queries | USA | EU-US Data Privacy Framework + SCCs (Art. 46(2)(c) GDPR) |
| Drive integration (optional) | OAuth tokens, account email, folder IDs, file metadata | USA | EU-US Data Privacy Framework + SCCs (Art. 46(2)(c) GDPR) | |
| OpenRouter (AI gateway) | AI text extraction and document OCR (mobile receipt scanning) | Receipt and document images, extracted text | USA | Standard Contractual Clauses, Module 2 (Art. 46(2)(c) GDPR) |
| AI model providers engaged by the gateway as sub-processors (currently including Google, OpenAI, Anthropic and Meta; the gateway publishes its current sub-processor list at trust.openrouter.ai) | Model inference for extraction and OCR | Receipt and document images, extracted text | USA | Standard Contractual Clauses, Module 2 (Art. 46(2)(c) GDPR) |
| Google Firebase Cloud Messaging | Push notification delivery (Android) | Device push token | USA | EU-US Data Privacy Framework + SCCs (Art. 46(2)(c) GDPR) |
| Apple Push Notification service | Push notification delivery (iOS) | Device push token | USA | EU-US Data Privacy Framework + SCCs (Art. 46(2)(c) GDPR) |
Data transfers to the USA: Where a processor is based in the United States or uses USA-based sub-processors, data transfers are covered by:
- The EU-US Data Privacy Framework (adequacy decision under Article 45 GDPR), and/or
- Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR.
You may request copies of the applicable SCCs by contacting us via our support contact form.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or to comply with legal obligations.
| Data Category | Retention Period | Legal Basis for Retention |
|---|---|---|
| Account and profile data | Until account deletion | Contract performance |
| Authentication tokens (access/refresh) | 60 days (session cookies), or until logout | Contract performance |
| Subscription metadata (status, plan, period) | Until account deletion | Contract performance |
| Invoices and accounting records | 10 years (German tax law, § 147 AO) | Legal obligation (Art. 6(1)(c) GDPR) |
| API access tokens | Until manually revoked or account deletion | Contract performance |
| Google Drive connection data | Until manually disconnected or account deletion | Consent |
| Contact form / feedback submissions | As long as necessary to respond + 1 year (archive) | Legitimate interest |
| Error logs (Logtail) | 90 days (Better Stack retention policy) | Legitimate interest |
| IP addresses (rate limiting) | In-memory only; purged within 1 hour | Legitimate interest |
| Analytics data (first-party) | Raw events: 90 days; aggregated statistics may be kept longer | Consent |
| How you first found us (account record) | Until your account is deleted | Consent |
| Receipt and evidence images (mobile) | Until the associated record or the account is deleted | Contract performance |
| AI extraction requests | Not separately retained by us; retained by the AI gateway only as long as necessary for the processing, under its data processing agreement | Contract performance |
| Device push tokens | Until notifications are disabled or account deletion | Consent |
| Mobile diagnostic logs (Better Stack) | 90 days (Better Stack retention policy) | Legitimate interest |
Account deletion: When you delete your account, we delete all personal data except for:
- Invoices and accounting records (retained for 10 years as required by German tax and commercial law).
- Data required to comply with legal obligations or to establish, exercise, or defend legal claims.
8. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
8.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether or not we process your personal data, and, where that is the case, access to the personal data and information about the processing.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to obtain the rectification of inaccurate personal data concerning you. You can update most of your data directly via your account settings.
8.3 Right to Erasure (“Right to be Forgotten”) (Article 17 GDPR)
You have the right to request the erasure of your personal data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
You can delete your account at any time via account settings. Note that invoices and accounting records will be retained for 10 years as required by law.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request restriction of processing under certain conditions, such as when you contest the accuracy of the data or object to processing.
8.5 Right to Data Portability (Article 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON), and to transmit that data to another controller.
8.6 Right to Object (Article 21 GDPR)
You have the right to object, on grounds relating to your particular situation, to processing of your personal data which is based on Article 6(1)(f) GDPR (legitimate interests). We will cease processing unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms.
You have an absolute right to object to processing for direct marketing purposes at any time.
8.7 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent (e.g., analytics, Google Drive integration), you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
8.8 Right to Lodge a Complaint (Article 77 GDPR)
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
Our supervisory authority is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Germany
Email: poststelle@datenschutz.hessen.de
8.9 Exercising Your Rights
To exercise any of these rights, please contact us via our support contact form. We will respond to your request without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Passwords are hashed using industry-standard algorithms (bcrypt/Argon2). API access tokens are hashed before storage.
- Authentication: OAuth 2.0 with PKCE (S256) for secure user authentication. JWT tokens validated server-side using jose library.
- Access control: Role-based access control (RBAC) for Platform features. Database access restricted to authorized personnel only.
- Secure cookies: Authentication tokens stored in httpOnly, Secure, SameSite=Lax cookies to prevent client-side access and CSRF attacks.
- EXIF stripping: Image uploads processed to remove EXIF metadata (which may contain geolocation or device information).
- SVG sanitization: SVG files sanitized to remove potentially harmful code (XSS attacks).
- Rate limiting: Contact form and feedback submissions rate-limited to prevent abuse.
- Bot protection: Honeypot fields and timing checks on form submissions.
- Regular security updates: We keep our software dependencies and infrastructure up to date with the latest security patches.
Despite these measures, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your data.
10. Automated Decision-Making and Profiling
We use a tag-based matching system to suggest potential connections and opportunities based on the tags in your profile (interests, match tags) and the tags in other users’ profiles and organization opportunities.
This matching is fully automated but does not constitute automated decision-making with legal or similarly significant effects under Article 22 GDPR. The matching system provides suggestions only and does not make binding decisions about you. You remain in full control of whether to act on any suggestion.
We do not engage in profiling for marketing, behavioral analysis, or other purposes beyond the tag-based matching described above.
11. Children’s Data
The Platform is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that data as soon as possible.
If you believe we have collected data from a child under 16, please contact us via our support contact form.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons.
We will notify you of any material changes by posting a notice on the Platform or by sending you an email. The “Last Updated” date at the top of this Privacy Policy indicates when it was last revised.
Your continued use of the Platform after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. If you do not agree to the revised Privacy Policy, you must stop using the Platform and delete your account.
13. Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Weltweit – Gesellschaft zur Förderung lokaler Initiativen e.V.
Talstr. 1
65812 Bad Soden
Germany
Support contact form: /support
Supervisory Authority:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Germany
Email: poststelle@datenschutz.hessen.de
Additional information for the academy
The Action Network Worldwide Academy is operated by Weltweit – Gesellschaft zur Förderung lokaler Initiativen e. V., the controller named in this Privacy Policy. Where this section and the rest of the policy differ, this section applies to academy.actionnetwork.world and to the academy signup.
Signing up for the academy
Signing up takes you to a form hosted by Google Forms. The answers you give there, including your name, email address, organisation, country and role, are collected through Google Forms and stored in a Google Sheet held by the operator. We use them to plan the academy and its first cohort and to contact you about it. Nothing you enter there is added to a newsletter.
Legal basis: your consent, Art. 6(1)(a) GDPR, given in the form. You can withdraw it at any time by writing to support@actionnetwork.world; we then delete your answers.
Google's role and the transfer of the data: The form and its response sheet belong to our organisation's Google Workspace account. For customers in the European Economic Area, Google's contracting party is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which processes the answers on our behalf as a processor under Google's data processing terms (Article 28 GDPR). Google may also process data in the United States; those transfers are covered by the EU-US Data Privacy Framework (Article 45 GDPR) and the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR).
How long we keep your answers: 24 months after you register, or until you withdraw your consent, whichever comes first. Then your answers are deleted.
Hosting and content delivery
academy.actionnetwork.world runs on DigitalOcean App Platform, provided by DigitalOcean LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA, which processes every request to this site on our behalf as a processor under Art. 28 GDPR, including the IP address the request carries, the page requested, the time and your browser's user agent. App Platform delivers the site through Cloudflare, Inc. as its own sub-processor; we have no separate contract with Cloudflare.
That edge sets one cookie, __cf_bm, on every request in order to tell human visitors from automated traffic. It is described in our Cookie Policy. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in keeping the service available and defending it against abuse.
Cookies and analytics
academy.actionnetwork.world uses no analytics and sets no cookies of its own. The cookie and browser-storage tables and the description of the consent banner elsewhere in this policy describe actionnetwork.world; this site's one cookie is listed in our Cookie Policy at academy.actionnetwork.world/cookie.