Privacy Policy
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Simon Maximilian Heistermann
Mutter-Teresa-Weg 6
46325 Borken
Germany
Email: hello@daretogether.net
2. Data Protection Officer
We are not legally required to appoint a data protection officer pursuant to § 38 of the German Federal Data Protection Act (BDSG). For any data protection inquiries, please contact us directly at hello@daretogether.net.
3. Data We Collect
We process personal data that you provide to us or that is automatically collected when you use our website and services.
3.1 Waitlist Data
When you join one of our waitlists (the Cape Town trip or the general community list), we process:
- First name and email address
- Which lists you are on (Cape Town waitlist, community list or both)
- Age bracket (a range, not a date of birth)
- Occupation as a selection (self-employed, employed with remote option, studying, other) plus an optional free-text field if you choose “other”
- Budget bracket as a range, never a specific amount
- The website language at the time you signed up
- Where your visit came from: UTM parameters in the URL you opened and the referring page
- As proof of your consent: the consent text exactly as it was shown to you, plus the status and timestamp of your confirmation (double opt-in)
Your entry only becomes active once you confirm it via the link in the confirmation email. We do not collect a postal address, phone number or payment details.
A Cape Town sign-up creates two entries: one on the Cape Town waitlist and one on the community list. Both purposes are named explicitly in the consent text under the form and are given with one consent. You can withdraw them separately: the unsubscribe link in a community email ends the community emails only, the unsubscribe link in a Cape Town email stops all emails for both lists.
3.2 Internal Handling of Your Entry
For each waitlist entry we keep an internal status (new, contacted, place confirmed, withdrawn) and a notes field. In it we record what is relevant for planning the trip, for example the outcome of the personal call. These notes are accessible only to us, and you can request access to them at any time (see section 9).
3.3 Technical Data
When you visit our website, our hosting provider automatically processes server log data: IP address, browser type and version, operating system, date and time of access, referring URL and pages visited. We do not store this data in our own database.
To protect against automated mass sign-ups we apply rate limiting. This briefly processes your IP address in order to count requests per time window.
3.4 Usage Measurement
We measure how our website is used, to understand which content gets read and where visitors drop off. We use PostHog on servers within the European Union. This processes page views, click events, approximate location at country level, and device and browser details. The measurement runs without cookies: no data is stored on your device, and the association ends when you close the browser tab.
3.5 Email Log and Suppression List
We log the emails we send you (confirmation email, welcome email, broadcasts). Recorded are the recipient address, the type of email, an identifier from the sending provider, and the timestamp.
If you unsubscribe, we store your email address together with the reason and the timestamp on a suppression list. This is necessary so that your unsubscribe is respected permanently - without that list you would be contacted again on the next send.
4. Purposes and Legal Basis
We process your personal data for the following purposes and on the following legal bases:
Joining the waitlist
Purpose: adding you to the list you chose and sending the confirmation and welcome emails.
Legal basis: Art. 6(1)(a) GDPR — your consent via double opt-in. You can withdraw it at any time using the unsubscribe link in every email.
Emails to the lists
Purpose: information about the Cape Town workation (how it works, selection, programme, the offer to participate) and news from the community.
Legal basis: Art. 6(1)(a) GDPR together with § 7(2) no. 2 of the German Act Against Unfair Competition, that is your consent. Every one of these emails carries an unsubscribe link; in addition we set the List-Unsubscribe header so your email program can offer the unsubscribe directly. Unsubscribing takes effect immediately.
Planning the trip
Purpose: contacting you personally, working out whether the trip is right for you, and putting the group together. This includes the internal status and notes.
Legal basis: Art. 6(1)(b) GDPR — pre-contractual measures taken at your request.
Proof of consent and suppression list
Purpose: being able to demonstrate that you consented and with what wording, and respecting your unsubscribe permanently.
Legal basis: Art. 5(2) in conjunction with Art. 6(1)(c) GDPR — accountability; for the suppression list additionally Art. 6(1)(f) GDPR — legitimate interest in not contacting you again.
Usage measurement
Purpose: understanding which content gets read and where visitors drop off.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in a comprehensible website. See section 7.
Where your visit came from
Purpose: understanding which channel brings interested people to us (UTM parameters and referring page).
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in assessing our reach.
Protecting the form
Purpose: defending against automated mass sign-ups through rate limiting.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure operation.
5. Third-Party Processors
We use the following third-party service providers to run our website and our emails. Each processor has entered into a Data Processing Agreement (DPA) with us in accordance with Art. 28 GDPR.
Vercel Inc.
San Francisco, California, USA
Purpose: Website hosting, content delivery network (CDN), and serverless function execution.
Data processed: Technical access data (IP address, request logs).
Supabase Inc.
Servers in Frankfurt am Main, Germany
Purpose: Database hosting.
Data processed: all waitlist entries including internal handling notes, the email log and the suppression list.
Resend
San Francisco, California, USA
Purpose: sending our emails.
Data processed: recipient address, email content, delivery metadata.
PostHog
EU instance (Frankfurt, Germany)
Purpose: usage measurement and analysis of website use.
Data processed: page views, click events, device and browser details, approximate location at country level – without cookies and without storing anything on your device.
Upstash
Purpose: rate limiting, protecting the form against automated mass sign-ups.
Data processed: IP address and number of requests per time window, stored briefly.
6. International Data Transfers
Our third-party processors are based in the United States. Data transfers to the US are conducted on the following legal bases:
- EU-US Data Privacy Framework (DPF): The European Commission has adopted an adequacy decision for the EU-US Data Privacy Framework (Commission Implementing Decision of 10 July 2023). Our processors are certified under the DPF, which ensures an adequate level of data protection.
- Standard Contractual Clauses (SCCs): As an additional safeguard, we have entered into Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR with our processors.
8. Retention Periods
We store your personal data only for as long as it is necessary for the purposes it was collected for, or as long as the law requires.
| Data category | Retention period |
|---|---|
| Unconfirmed waitlist entries | 30 days after sign-up, then deleted automatically |
| Confirmed waitlist entries | until you withdraw, at the latest 24 months after the last contact |
| Internal handling notes | together with the entry they belong to |
| Proof of consent | together with the entry it belongs to |
| Email log | 12 months |
| Suppression list | permanently – it is the only way to honour your unsubscribe |
| Usage measurement | 12 months |
9. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — You may request confirmation of whether we process your personal data and, if so, obtain a copy of that data.
- Right to rectification (Art. 16 GDPR) — You may request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR) — You may request deletion of your data, subject to legal retention obligations.
- Right to restriction (Art. 18 GDPR) — You may request restriction of processing in certain circumstances.
- Right to data portability (Art. 20 GDPR) — You may request your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR) — You may object to processing based on legitimate interests (Art. 6(1)(f) GDPR) at any time, for reasons related to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3) GDPR) — Where processing is based on your consent (e.g., your waitlist entry), you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact us at hello@daretogether.net. We will respond within one month of receiving your request.
11. Automated Decision-Making
We do not use fully automated decision-making, including profiling, within the meaning of Art. 22 GDPR. Who gets a place on the trip is decided after a personal call, not by an algorithm.
12. Obligation to Provide Data
Waitlist: We need your first name and email address to add you to the list and to reach you. Occupation, budget bracket and age bracket help us plan; without them we cannot judge whether the trip is a fit for you.
Community list: First name and email address are enough.
13. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons.
For material changes (e.g., new data processing purposes, new processors, changes to retention periods), we will notify everyone on our lists via email at least 30 days before the changes take effect and update the “Last updated” date below.
You have the right to object to new processing activities by contacting us at hello@daretogether.net. If you do not wish to accept changes to our data processing, you may request deletion of your data without penalty.
Minor corrections, clarifications, or formatting changes that do not expand the scope of our data processing may take effect immediately.
14. Severability
Should any provision of this privacy policy be held invalid or unenforceable, the remaining provisions shall remain in full force and effect. Any invalid provision shall be replaced by a valid provision that comes closest to the intent of the original.
Last updated: September 2026