Privacy Policy
Transparent information about what data Ehemalige processes, why we need it and what control you have over your data.
What matters on this page?
Ehemalige only processes necessary data for the alumni network, uses no tracking/ads and gives you control over visibility, export and deletion.
Data minimization
Only data needed for login, cohort rooms and communication.
No tracking
No ads, no profiling, only technically necessary cookies.
Your control
Export data, control visibility and delete account.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Today is LifeGuido [NACHNAME]
[STRASSE UND HAUSNUMMER]
[PLZ ORT]
Deutschland
E-Mail: [E-MAIL-ADRESSE]
Telefon: [TELEFONNUMMER]
2. What data we collect
Ehemalige only collects data that is actually necessary to operate an alumni network. We follow the principle of data minimization (Art. 5(1)(c) GDPR).
2.1 During registration
- Email address -- for magic-link sign-in
- Name -- so former classmates can recognize you
2.2 Optional profile details
You decide which of these details to provide and who can see them:
- City / place of residence
- Occupation
- School affiliation (school, class, period)
- Graduation year / cohort
- Profile picture
2.3 Usage content
- Posts in cohort rooms
- Stories
- Messages to other members
- Photos and files you upload
- Events you create or participate in
2.4 Technical data
When accessing Ehemalige, technical data is collected automatically for secure operation:
- IP address (not stored permanently, only in server logs for max. 7 days)
- Browser type and version
- Date and time of access
3. Legal basis
We process your data on the following legal bases:
| Processing | Legal basis |
|---|---|
| Registration, profile, platform use | Art. 6(1)(b) GDPR (contract performance) |
| Security, abuse prevention, server logs | Art. 6(1)(f) GDPR (legitimate interest) |
| Optional profile fields (city, occupation etc.) | Art. 6(1)(a) GDPR (consent) |
4. Purpose of processing
We process your data exclusively for:
- Alumni network: finding and reconnecting with former classmates
- Reunions: organizing events and coordinating participants
- Communication: enabling messages between members
- Cohort rooms: sharing memories together
- Platform operation: technical delivery and security
Ehemalige uses no advertising and no tracking. Your data is not used for profiling, scoring or personalized ads.
5. Retention and deletion periods
| Data | Retention period |
|---|---|
| Account data (name, email) | Until you delete the account |
| Profile details | Until deleted by you or with account deletion |
| Posts, messages, photos | Until deleted by you or with account deletion |
| Server logs (IP addresses) | Maximum 7 days |
| Session cookies | Until end of browser session or max. 24 hours |
After account deletion, all personal data is permanently deleted within 30 days. Posts in cohort rooms are anonymized.
6. Magic link authentication
Ehemalige uses no passwords. Sign-in works exclusively via so-called magic links:
- You enter your email address.
- You receive a one-time sign-in link via email.
- The link is time-limited (max. 15 minutes) and can only be used once.
Because we do not store passwords, the risk of a password leak is eliminated. Your email address is used only to deliver the magic link and important platform notifications.
7. Cookies
Ehemalige uses only technically necessary cookies. They are required for operating the platform and therefore do not require separate consent (Art. 6(1)(f) GDPR, § 25(2) TDDDG).
| Cookie | Purpose | Duration |
|---|---|---|
ehemalige_session |
Session handling after sign-in | End of session / max. 24 h |
XSRF-TOKEN |
Protection against cross-site request forgery | End of session |
There are no tracking cookies, analytics cookies or advertising cookies. Therefore, no cookie banner is required.
8. Real-time communication (WebSockets)
For real-time features (e.g. chat messages), Ehemalige uses WebSocket connections via Laravel Reverb. These connections are:
- Encrypted (WSS/TLS)
- Authenticated -- only signed-in users can open a connection
- Short-lived -- the connection exists only during active use
No data is permanently stored via WebSockets beyond the data already listed in section 2.
9. Disclosure to third parties
Your data is not shared with third parties, sold or used for advertising purposes.
Data is only shared if:
- you have explicitly consented (Art. 6(1)(a) GDPR), or
- there is a legal obligation (Art. 6(1)(c) GDPR, e.g. by court order).
10. Transfers to third countries
Ehemalige stores and processes all data exclusively on servers in Germany. Personal data is not transferred to third countries (outside the EEA).
11. Your rights
You have the following rights at any time regarding your personal data:
- Access (Art. 15 GDPR) -- what data we store about you
- Rectification (Art. 16 GDPR) -- correction of inaccurate data
- Erasure (Art. 17 GDPR) -- deletion of your data ("right to be forgotten")
- Restriction (Art. 18 GDPR) -- restriction of processing
- Data portability (Art. 20 GDPR) -- receive your data in a common format
- Objection (Art. 21 GDPR) -- object to processing
To exercise your rights, an informal message to the email address listed above is sufficient. You can also exercise many of these rights directly in your profile settings (e.g. change data, export data or delete your account).
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority depends on your place of residence. A list can be found at bfdi.bund.de.
12. Account deletion
You can delete your account yourself at any time:
- Go to your profile settings
- Click "Delete account"
- Confirm deletion
After deletion, all your personal data will be permanently removed within 30 days. Posts in cohort rooms are anonymized. A data export is possible in the settings before deletion.
13. Data protection officer
As a sole proprietorship, we are currently not required to appoint a data protection officer (Art. 37 GDPR, § 38 BDSG), and none is currently appointed. For privacy-related questions, please contact:
Guido [NACHNAME]E-Mail: [E-MAIL-ADRESSE]
14. Changes to this privacy policy
We reserve the right to update this privacy policy when necessary, e.g. due to legal changes or when platform features are expanded. The current version is always available on this page.
If material changes affect your rights, you will be informed by email.
Related pages
For rules, contact and responsibilities, use these pages.