Back to homepage

Privacy Policy

Last updated: 15.06.2026

Thank you for visiting our website and web application allgroups.chat, including the related dashboard and administration areas. Protecting your personal data is important to us. Below, we explain which personal data we process, for what purposes, on which legal basis and which rights you have.

1. Controller

The controller responsible for data processing is:

Semesterkur UG (haftungsbeschraenkt)
Ernst-Weyden-Strasse 15
51105 Cologne
Germany
Email: kontakt@semesterkur.de

2. Subject Matter of This Privacy Policy

This Privacy Policy applies to the use of our website, our web application and the related features, in particular to:

  • purely informational visits to the website,
  • use of the dashboard and other application areas,
  • registrations and user accounts,
  • login methods via third-party providers,
  • submission, review, moderation, publication and management of group and platform content,
  • contacting us,
  • technically necessary storage and security features,
  • internal processing and organizational workflows.

3. General Information on the Processing of Personal Data

We process personal data only to the extent necessary to provide a functional website and web application, to provide our services, to secure our systems, to communicate with users and to carry out internal processing and organizational workflows.

Personal data means any information relating to an identified or identifiable natural person.

4. Accessing the Website and Server Log Files

When you access our website or web application, the browser on your device automatically transmits information to our servers or to upstream security and delivery systems. In particular, we process the following data:

  • IP address
  • date and time of access
  • requested URL
  • referrer URL
  • browser type and browser version
  • operating system
  • HTTP status code
  • technical request, header and connection data

Processing is carried out for the following purposes:

  • providing the website and web application,
  • ensuring stability and system security,
  • detecting misuse, attacks and bots,
  • error analysis and technical administration.

The legal basis is Art. 6(1)(f) GDPR.

Our legitimate interest lies in the secure, stable and misuse-free provision of our online services.

Server log files are generally deleted after 14 days unless they are exceptionally needed for a longer period to investigate specific security incidents, cases of misuse or legal violations. In such cases, storage may take place for up to 90 days where this is necessary to clarify the facts, preserve evidence or defend legal claims.

5. Hosting, Infrastructure and Cloudflare

Our website and web application are hosted on servers operated by us or for us in Germany.

To deliver, secure and optimize the availability of our website and web application, we also use services from Cloudflare, Inc. or affiliated companies, in particular for:

  • DNS
  • reverse proxy / content delivery
  • caching
  • firewall and security features
  • bot and misuse protection

In this context, IP addresses, request data, header information, security characteristics, connection metadata and technical diagnostic data may be processed where this is necessary for secure and stable provision.

The legal bases are:

  • Art. 6(1)(f) GDPR
  • Section 25(2) TDDDG, insofar as access to information on the end device or storage is strictly technically necessary

Our legitimate interest lies in the secure, performant and reliable provision of our online services and in defending against abusive access.

Cloudflare Web Analytics (Reach Measurement)

For statistical analysis of access to our website and web application, we additionally use Cloudflare Web Analytics, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare Web Analytics operates without cookies and without fingerprinting: no cookies are set and no cross-device identifiers are created. Only aggregated metrics are collected, such as the number of page views, viewed pages, referrers, approximate country of origin and browser and device types used. This does not allow individual visitors to be identified.

The legal basis is our legitimate interest in statistically analyzing website usage for reach measurement and improving our offering (Art. 6(1)(f) GDPR). Because no information is stored on or read from your end device, consent under Section 25 TDDDG is not required for this.

When Cloudflare is used, data may be transferred to the USA. Cloudflare is certified under the EU-US Data Privacy Framework; EU Commission standard contractual clauses are used additionally.

Anonymous Analytics with PostHog (EU)

For anonymous analysis of the use of our website and web application, we use PostHog in the EU-hosted version (PostHog EU Cloud, data center in Frankfurt am Main; provider: PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA). The analytics data is processed exclusively on servers within the EU. We operate PostHog in anonymous mode: no cookies are set, no cross-device identifiers or personal user profiles are created, and IP addresses are not stored. Only aggregated, anonymous usage data is collected, such as page views, events, approximate country of origin and browser and device types used.

The legal basis is our legitimate interest in statistically analyzing website usage for reach measurement and improving our offering (Art. 6(1)(f) GDPR). Because no information is stored on or read from your end device, consent under Section 25 TDDDG is not required for this. No transfer to a third country outside the EU takes place in this context.

6. Technically Necessary Cookies, Local Storage and Similar Technologies

We use cookies, local storage, session storage and comparable technologies where this is technically necessary to provide our website and web application. This concerns in particular:

  • storage of session and login states,
  • security and protection features,
  • user-specific display and language settings,
  • state information within the web application.

Where the use of these technologies is strictly technically necessary, it is based on Section 25(2) TDDDG.

Subsequent processing of personal data is carried out, depending on the feature, on the basis of Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.

If non-technically necessary technologies are used in the future, they will be used only on the basis of your consent.

7. Use of the Web Application and Dashboard

Our website includes interactive features and dashboard areas. When these are used, we additionally process technically necessary application data, in particular:

  • session and status data,
  • technical authentication data,
  • security and verification characteristics,
  • error and diagnostic data,
  • settings within the application,
  • interaction and control data within the web application.

Processing is carried out to provide the respective features, maintain the integrity and security of the application and troubleshoot errors.

The legal bases are:

  • Art. 6(1)(b) GDPR, insofar as use takes place within a usage relationship,
  • Art. 6(1)(f) GDPR to ensure stable and secure operation.

Our legitimate interest lies in the technical functionality, stability and security of the web application.

8. Registration and User Account

Where user accounts can be created or managed on our platform, we process the data required for this, in particular:

  • name or display name,
  • email address,
  • internal user ID,
  • time of registration,
  • login times,
  • account settings,
  • technical security and authentication data.

Processing is carried out to set up, operate and manage the user account and to provide the requested features.

The legal basis is Art. 6(1)(b) GDPR.

Without providing the account data requested as mandatory information, a user account cannot be created or maintained.

After deletion of the user account, we store account-related data only to the extent necessary to comply with legal obligations or to defend against or assert legal claims. Otherwise, productive account data is deleted or anonymized within 30 days after deletion becomes effective. Backup copies and recovery data are overwritten or deleted within our technical backup cycles no later than within 90 days.

9. Login via Google

You can log in via Google. If you use this feature, we receive from Google the data required for authentication, account assignment and login. This includes in particular:

  • a provider-specific identifier,
  • your email address,
  • any basic profile data you have released.

Processing is carried out for login, authentication, account assignment, account security and misuse prevention.

The legal basis is Art. 6(1)(b) GDPR.

Please note that when you use this login method, additional personal data is processed by Google under Google's own responsibility under data protection law.

10. Login via Apple

You can also log in via Sign in with Apple. If you use this feature, we receive from Apple the data required for authentication, account assignment and login. This includes in particular:

  • a provider-specific identifier,
  • your email address or a relay email address provided by Apple,
  • any further information you have released.

Processing is carried out for login, authentication, account assignment, account security and misuse prevention.

The legal basis is Art. 6(1)(b) GDPR.

Please note that when you use this login method, additional personal data is processed by Apple under Apple's own responsibility under data protection law.

11. Platform Features, Group Content and User-Generated Data

Our platform is used in particular for submitting, reviewing, managing, moderating, verifying, displaying and publishing group-related content. In this context, we process the data required for this, in particular:

  • group name,
  • group description,
  • category,
  • city, region and other assignments,
  • invitation links,
  • group-related metadata,
  • information about the submitting or responsible person,
  • moderation, review and status information,
  • communication content in connection with submissions, reviews, queries or reports.

Processing is carried out for the following purposes:

  • carrying out platform features,
  • processing and reviewing submissions,
  • quality assurance and moderation,
  • misuse and fraud prevention,
  • publication of permissible content,
  • processing reports and objections.

The legal bases are:

  • Art. 6(1)(b) GDPR, insofar as processing is necessary to use the platform features,
  • Art. 6(1)(f) GDPR for quality assurance, misuse prevention, platform integrity and legal defense.

Our legitimate interest lies in functional, reliable platform operation with low levels of misuse.

12. Data About Third Parties in Submissions or Group Contexts

Where personal data about persons who have not contacted us directly is transmitted to us as part of submissions, reviews, reports or group-related processes, we process this data only to the extent necessary for the respective platform features, review processes, moderation decisions, security purposes or the handling of objections.

In these cases, the data may originate in particular from:

  • the submitting person,
  • group-related information within the platform feature,
  • communications in connection with the respective group or report.

In particular, the following may be processed:

  • names,
  • function or role references,
  • contact details,
  • group-related assignments,
  • communication and review notes.

The legal basis is Art. 6(1)(f) GDPR.

Our legitimate interest lies in processing and reviewing platform content, preventing misuse, moderating permissible content and preserving our rights.

13. WhatsApp-Related Features and Interfaces

Where our services use WhatsApp-related features, links or technical interfaces, we process WhatsApp-related data to the required extent. Depending on the specific feature, this concerns in particular:

  • phone numbers,
  • WhatsApp IDs, chat IDs or group IDs,
  • invitation links,
  • status and delivery information,
  • timestamps,
  • technical responses and webhook data,
  • content data where technically necessary for the respective feature.

Processing is carried out in particular for the technical integration of WhatsApp-related features, for assigning and processing group-related workflows, for session and status processing, for system administration and for troubleshooting.

The legal bases are:

  • Art. 6(1)(b) GDPR, insofar as processing is necessary to provide the requested feature,
  • Art. 6(1)(f) GDPR for technical administration, system stability, misuse prevention and error analysis.

Our legitimate interest lies in the secure and functional integration of the respective communication and group features.

Where you interact with WhatsApp services via links or technical features, additional data processing is carried out by WhatsApp Ireland Limited, WhatsApp LLC and/or companies of the Meta group of companies under their own responsibility under data protection law.

14. Internal Technical Systems and Automations

To technically provide and internally process our services, we use self-hosted internal systems for workflow automation, process control, integrations, moderation, status processing and technical message processing.

In this context, in particular the following may be processed:

  • form and input data,
  • status information,
  • approvals and review steps,
  • moderation data,
  • technical events,
  • process-related metadata.

Processing is carried out for efficient handling of processes, technical integration of our systems, quality assurance and secure and scalable provision of our services.

The legal bases are:

  • Art. 6(1)(b) GDPR,
  • Art. 6(1)(f) GDPR.

Our legitimate interest lies in efficient, reliable and traceable internal workflows.

15. Processing via Google Services for File and Spreadsheet Management

Where necessary for internal organization, review, documentation and processing workflows, we use Google services for file and spreadsheet management.

Personal data may be processed where it is contained in files, spreadsheets, entries or linked processing workflows. Processing may include in particular creating, reading, updating, assigning, storing and deleting data records.

The legal bases are:

  • Art. 6(1)(b) GDPR,
  • Art. 6(1)(f) GDPR.

Our legitimate interest lies in efficient internal organization, documentation and process handling.

16. Contacting Us

If you contact us, for example by email or via a form, we process the data you provide to handle your inquiry. This includes in particular:

  • name,
  • email address,
  • message text,
  • other voluntarily provided information.

The legal bases are:

  • Art. 6(1)(b) GDPR, insofar as your inquiry concerns pre-contractual or contractual measures,
  • Art. 6(1)(f) GDPR in other cases.

Our legitimate interest lies in the appropriate handling of inquiries, support cases and other communications.

Contact inquiries are generally deleted after the relevant process has been completed, unless statutory retention obligations or legitimate interests in further storage exist. The regular deletion period is 3 years from the end of the calendar year in which the inquiry was finally processed.

17. Recipients of Data

Personal data is disclosed only where this is legally permissible and necessary for the respective purposes. Recipients may include in particular:

  • hosting and server service providers,
  • Cloudflare,
  • Google,
  • Apple,
  • WhatsApp-/Meta-related services,
  • technical administrators and development service providers,
  • internal or external bodies for processing support, security, review or moderation matters,
  • authorities, courts or other public bodies where there is a legal obligation.

Where external service providers act as processors, they are engaged on the basis of Art. 28 GDPR.

18. Transfers to Third Countries

Despite hosting and internal system use in Germany, it cannot be excluded that, in connection with individual services, personal data may be transferred to or processed by recipients in countries outside the European Union or the European Economic Area, in particular when Cloudflare, Google, Apple or WhatsApp-/Meta services are used.

Where a transfer to a third country takes place, it is carried out only in compliance with the legal requirements. Depending on the provider and data flow, the transfer may in particular be based on:

  • an adequacy decision under Art. 45 GDPR,
  • standard contractual clauses under Art. 46 GDPR,
  • other legally permissible safeguards.

Where a transfer to recipients in the USA takes place, it may, depending on the recipient, in particular be based on the EU-US Data Privacy Framework if the respective recipient is certified under it. Otherwise, we base the transfer on other permissible safeguards, in particular standard contractual clauses.

Information on the relevant safeguards can be requested using the contact details above.

19. Storage Period

We store personal data only for as long as necessary for the respective purposes or as long as statutory retention obligations exist.

Unless a more specific period is stated in this Privacy Policy, the following principles apply in particular:

  • server and security logs: deletion after 14 days, subject to longer storage of up to 90 days in the event of security incidents, cases of misuse or for legal defense,
  • session and technical state data: generally until the end of the session or until the technically intended session expires,
  • account data: for the duration of the user account; after account deletion, productive account data is deleted or anonymized within 30 days unless statutory retention obligations or legitimate reasons prevent this; backup copies are overwritten or deleted within 90 days at the latest,
  • support and contact inquiries: deletion 3 years from the end of the calendar year in which processing was completed, unless statutory or legal reasons prevent this,
  • moderation, review and process data: storage for 3 years after completion of the respective process where further storage is necessary for documentation, misuse prevention or legal defense.

20. Obligation to Provide Data

Providing certain personal data is necessary to use individual features.

This applies in particular to:

  • technical connection data when accessing the website and web application,
  • account data for registration and user accounts,
  • authentication data for social login methods,
  • content information in submissions, reports or group-related features,
  • communication data when contacting us.

Without this data, the affected features cannot be provided in whole or in part.

21. Your Rights

In accordance with statutory provisions, you have the right:

  • to access under Art. 15 GDPR,
  • to rectification under Art. 16 GDPR,
  • to erasure under Art. 17 GDPR,
  • to restriction of processing under Art. 18 GDPR,
  • to data portability under Art. 20 GDPR,
  • to object under Art. 21 GDPR to processing based on Art. 6(1)(f) GDPR,
  • to withdraw consent you have given with effect for the future.

To exercise your rights, you can contact us at any time using the contact details above.

22. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.

23. Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy with effect for the future, in particular if our website or web application is further developed, new features are introduced, the services used change or the legal situation changes.