Privacy Policy

Information on the processing of personal data in accordance with the General Data Protection Regulation (GDPR).

1Controller

Responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

4VisionGlobal
Institute for connecting people to support their strengths and visions

Registered office:
Lederergasse 28-20
1080 Vienna
Austria

Delivery address / Branch office:
Mühlenbergstraße 9
18461 Richtenberg
Germany

ZVR number: 1225874555

Email: 4visionglobal.faireint@gmail.com

Represented by the Executive Board: Lars Gutknecht (President), Sascha Gladbach (Vice President), Tilo Juncken (Vice President). For details on representation rules, see Imprint.

2General Information on Data Processing

We process personal data of our users fundamentally only to the extent necessary to provide a functional website as well as our content and services. Processing regularly occurs only with the user's consent or to the extent required for the performance of a contract or pre-contractual measures.

Processing of personal data beyond the actual extent required to fulfill the purpose does not take place.

3Hosting and Content Delivery (Vercel)

This website is hosted by Vercel Inc. Vercel is a cloud hosting provider supplying the technical infrastructure for operating the website.

Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA.

Processed data: For technical reasons, access data (IP address, date and time of access, requested URL, browser type and version, referrer URL if applicable) are processed in server log files with each access to the website. Runtime logs of serverless functions have been sanitized and do not contain personal data (no email addresses, names, member IDs, or full Stripe reference IDs).

Purpose: Provision of the website, ensuring infrastructure security and stability, error diagnosis.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical provision and security of the website).

Storage duration: Server log files are stored for a limited period and subsequently erased. The exact storage duration follows Vercel's specifications.

Third-country transfer: Vercel Inc. is a US company. Transfer of personal data to the USA cannot be excluded. Vercel offers a Data Processing Addendum (DPA) and uses Standard Contractual Clauses (SCCs) for data transfers. For further information, visit vercel.com/legal/dpa.

4Backend and Database (Base44)

The backend infrastructure and database of this website are provided via Base44 (Base44, Inc.). Base44 acts as a data processor (Art. 28 GDPR) for storing and processing member and contribution data.

Provider: Base44, Inc. (belongs to Wix.com Ltd.).

Processed data: Member data (first and last name, email address, phone number, address, member number, membership status, contribution amount, payment interval, join date), contribution data (contributor's name and email address, amount, project, reference number, Stripe transaction IDs), and configuration data for contribution logic.

Purpose: Management of supporting memberships, recording project contributions, provision of member portal, sending transactional emails.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures) for member and contribution data; Art. 6(1)(f) GDPR for technically necessary data storage.

Server location: Base44 by default uses a US data region. Whether a different region is configured for this project is currently unverified.

Base44 states that all providers receiving personal data from Base44 are bound by data processing agreements, and transfers are covered by Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework, or other appropriate safeguards. Base44 also publishes a subprocessor list and provides a Data Processing Addendum (DPA).

Details regarding Base44's Data Processing Addendum (DPA) can be reviewed at base44.com/dpa.

Storage duration: Member data are stored for the duration of membership. Contribution data are stored for at least the legally mandated period for accounting records.

5Payment Processing (Stripe)

For payment processing (supporting memberships and project contributions), we use the payment service provider Stripe.

Provider: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland (for European customers).

Data transmitted to Stripe: During payment processing, data necessary for the transaction are transmitted to Stripe. This includes data provided by the user in Stripe Checkout (name, email address) and payment data (credit card details or bank account details). Input of payment data occurs exclusively on the Stripe Checkout page, not on our website.

Data received from Stripe and stored by us: We store exclusively Stripe reference IDs (Customer ID, Subscription ID, Price ID, Product ID, Session ID, Payment Intent ID) and metadata provided by the user (name, email address, chosen contribution, project).

Not stored by us: We do not store credit card numbers, CVV/CVC codes, expiration dates, or bank account details. Complete payment details are processed exclusively by Stripe.

Purpose: Processing supporting memberships and project contributions.

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in secure payment processing).

Storage duration: The storage duration of payment data depends on Stripe's terms and statutory retention requirements.

Third-country transfer: Stripe may process data outside the EU. However, Stripe Payments Europe Ltd. is subject to GDPR requirements. For further information, see Stripe's privacy policy: stripe.com/privacy.

6Email Dispatch

For sending transactional emails (welcome emails, contribution confirmations), we use the email features of the Base44 platform. Emails are sent via Base44 Backend Functions, not through direct integration of an email provider in our website.

Data flow: Email dispatch is executed by Base44 backend infrastructure. Base44 states that emails from apps built on the Base44 platform use the domain base44-apps.com.

Processed data: Email address, name, and content data required for the respective email (member number, contribution information, reference number, project name).

Purpose: Sending confirmation and information emails to supporting members and contributors.

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in communication).

Subprocessor note: Base44 publishes subprocessor information for certain communication services. Which specific email provider Base44 uses internally cannot be directly verified from the application perspective. Base44 may provide further information upon request.

7Fonts

This website uses the fonts "Inter" and "Plus Jakarta Sans". These are loaded via Next.js Font Optimization (next/font/google). Font files are downloaded during the build process and hosted locally on the web server. No direct call to Google servers is made by the browser when rendering fonts. No data are transferred to Google LLC in connection with fonts.

8Member Portal and Authentication

Supporting members can log in via a member portal. Authentication occurs via a technically necessary httpOnly cookie (4vg_member_token) containing a cryptographically signed JWT (JSON Web Token).

Processed data: Email address, member number (for login), as well as member ID, first name, and expiration timestamp in the JWT.

Purpose: Authentication and access control for the member portal.

Legal basis: Art. 6(1)(b) GDPR (contract performance — provision of the member portal).

Cookie properties: httpOnly (inaccessible via JavaScript), secure (HTTPS only), sameSite=lax, validity 30 days.

Storage duration: The cookie is valid for 30 days and automatically deleted upon expiration. Upon logout, the cookie is deleted immediately.

No further tracking cookies, analytics cookies, or marketing cookies are set. No local storage or session storage is used for personal data.

9Supporting Membership

When concluding a supporting membership, the following personal data are collected and processed:

  • First and last name
  • Email address
  • Address (street, house number, zip code, city, country) — if provided in the form
  • Phone number — if provided in the form
  • Selected membership contribution and payment interval (monthly/annual)
  • Stripe Customer ID and Stripe Subscription ID
  • Member number (automatically generated)
  • Join date

Purpose: Management of membership, debiting membership contributions, provision of member portal, sending informational emails.

Legal basis: Art. 6(1)(b) GDPR (contract performance) for contractual data; consents granted (statutes, contribution regulations, privacy policy) are based on Art. 6(1)(a) GDPR.

Storage duration: Member data are stored for the duration of membership. After resignation or cancellation, data are deleted unless statutory retention requirements (in particular tax and commercial law) apply.

10Project Contributions

When making a project contribution via the website, the following personal data are processed:

  • Name (provided in Stripe Checkout)
  • Email address (provided in Stripe Checkout)
  • Contribution amount and selected project
  • Stripe transaction IDs (Session ID, Payment Intent, Customer ID)
  • Reference number (automatically generated)

Purpose: Recording and allocating project contributions, confirmation email, traceability of fund usage.

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in transparent fund usage).

Storage duration: Contribution data are stored for the duration of statutory retention obligations.

11Partnership Inquiries

Via the contact form on page /mitmachen/partnerschaft , interested parties can direct a partnership inquiry to the association. The following personal data are processed:

  • First and last name (required)
  • Email address (required)
  • Company / Organization (required)
  • Type of partnership (required)
  • Message (required)
  • Website (optional)
  • Phone number (optional)

Purpose: Processing partnership inquiry and personal contact by the association. Processing occurs exclusively based on consent granted by the interested party (privacy checkbox in form).

Legal basis: Art. 6(1)(a) GDPR (consent). Consent relates exclusively to processing the specific inquiry and can be revoked at any time.

Transmission: Inquiry is processed via Base44 backend infrastructure and forwarded to the association via email. No permanent storage of inquiry data occurs in a database. Email transmission occurs via the email infrastructure described in Section 6.

Confirmation email: Interested party receives an automatic confirmation email regarding receipt of inquiry. This email is also sent via Base44 backend infrastructure.

Storage duration: [Retention period to be specified by association]

No further processing: Data collected via the form will not be used for marketing purposes, profiling, tracking, or newsletter dispatch. No disclosure to third parties for advertising purposes occurs.

13External Image Sources

This website uses imagery from external sources. When displaying these images, a connection to the respective provider's servers may be established, processing the user's IP address.

Unsplash (images.unsplash.com): Stock photography provider, Unsplash Inc., USA. Images are loaded via Next.js Image Optimization system.

Base44 Media CDN: Own image material and project uploads, provided via the Base44 platform.

13Social Media Links

The website contains links to social media profiles (Instagram, TikTok). These links lead to external platforms. When accessing these links, no data are transmitted to social media platforms unless the user clicks the link.

Upon clicking a social media link, the user leaves our website and enters the domain of the respective platform operator. Data processing there is exclusively the responsibility of the respective platform operator.

14Your Rights as a Data Subject

You have the following rights under the GDPR:

  • Access (Art. 15 GDPR): You can request access to your personal data being processed.
  • Rectification (Art. 16 GDPR): You can request rectification of inaccurate personal data.
  • Erasure (Art. 17 GDPR): You can request erasure of your personal data, provided no statutory retention obligations prevent it.
  • Restriction (Art. 18 GDPR): You can request restriction of processing.
  • Data Portability (Art. 20 GDPR): You can request receipt of your data in a structured, commonly used, and machine-readable format.
  • Objection (Art. 21 GDPR): You can object to processing based on legitimate interests.
  • Withdrawal of Consent (Art. 7(3) GDPR): You can withdraw consent granted at any time.

To exercise your rights, please contact: 4visionglobal.faireint@gmail.com

15Responsible Supervisory Authority

If you have complaints, you can contact the responsible data protection supervisory authority:

The State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Barichgasse 40-42
1030 Vienna
Austria
www.dsb.gv.at

16SSL Encryption

For security reasons and to protect the transmission of confidential content, such as login data in the member portal, this website uses SSL/TLS encryption. You can recognize an encrypted connection by the browser address line changing from "http://" to "https://" and by the lock symbol in your browser line.

17No Tracking, No Analytics Tools

We do not use any tracking. There arenothird-party cookies, no advertising tracking tools, and no hidden analytics services.

The only cookies set are technically necessary cookies for authentication in the member portal.