Skip to content
English
English

Privacy notice

1. Services covered by this notice

This privacy notice explains how personal data is processed on the marketing website at buergerportal.de and www.buergerportal.de. It also applies to corresponding test and preview versions where they offer the same features. Personal data is information relating to an identified or identifiable person.

Separate privacy notices apply to registration and use of the application at app.buergerportal.de and to the processing of your requests by a connected organisation. The marketing website does not accept residents’ applications or documents for processing by organisations.

Privacy notice for your Bürgerportal account and the app (external link)

2. Controller and privacy contact

TEC2DATE GmbH
Hermann-Steinhäuser-Straße 43-47
63065 Offenbach am Main
Represented by Managing Director Christoph Schneider
Phone: +49 69 99 99 279 0
Email: kontakt@buergerportal.de
Privacy contact: datenschutz@buergerportal.de

If you have questions about privacy or wish to exercise your rights, please contact our privacy contact.

3. Visiting the website, hosting and security

We operate the website and our self-hosted analytics platform on systems at Hetzner in Germany. Our hosting provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. We have a data processing agreement with Hetzner under Article 28 GDPR.

Each visit involves the technical processing of, in particular, your IP address, the requested path including any URL parameters transmitted, the date and time, browser and operating system information, the previously visited page where applicable, and connection and response information. This is necessary to deliver the requested content to your browser, identify errors and protect the website against attacks.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to provide the website securely and reliably. The website cannot be delivered without the technically necessary processing of connection data.

The container serving the website does not write regular access logs. This is distinct from upstream web servers, the web application firewall and technical error and security logs. Such logs are used solely for operation, troubleshooting and preventing abuse. They are not combined with Umami to create visitor profiles. WAF logs are retained for 30 days and then deleted. Retention of other logs depends on the relevant technical purpose, investigation of specific security incidents and, where applicable, safeguarding legal claims. The data must be deleted once it is no longer needed for those purposes.

Protected test and preview versions may require sign-in using HTTP Basic Auth. The credentials entered are processed to control access. Your browser may retain them until the session ends. This access control is not a sign-in to Bürgerportal. The legal basis is Article 6(1)(f) GDPR: our interest in protecting content that is not yet public.

4. Contact forms, recommendations and personal contact

If you contact us using a form, by email or by phone, we process your details to handle your enquiry, ask follow-up questions and prepare for possible cooperation. Consent to website analytics is not required.

The forms at /support and /kontakt require your name, email address and message. Support enquiries are sent to support@buergerportal.de. General enquiries are sent to kontakt@buergerportal.de. We use your details to handle your enquiry and reply by email. The form cannot be submitted without these details. Alternatively, you can contact us by email or phone.

The recommendation form at /institution-empfehlen requires your name and email address and the organisation’s name and email address. You may provide the work email address of a personal contact or the organisation’s general contact address. We use these details to process your recommendation and ask you follow-up questions if necessary. The form cannot be submitted without these details.

Your recommendation is sent to the responsible team at TEC2DATE. We review the suggestion and contact the organisation personally. In doing so, we share your name and email address, together with your wish for the organisation to offer its own portal, with the organisation you specified. The proposed message is visible in the form before submission. You receive an acknowledgement. No automatic email is sent to the organisation. Please do not provide details of personal matters or proceedings.

The contact form for organisations requires a name, organisation, email address and enquiry. Your role and phone number are optional. The enquiry is sent to kontakt@buergerportal.de. This form cannot be submitted without the required details. You can still contact us using the other methods listed.

Where the pilot participation form is offered, the organisation, contact person and work email address are required. Details of organisation type, German federal state, role, size or caseload, phone number, existing portal, portal solution used, planned replacement or addition, specialist applications, document management system and further comments are optional. If “in Planung” (planned) is selected for an existing portal, we also ask for the planned implementation period on an optional basis. “Noch nicht festgelegt” (not yet decided) is also available. Pilot participation enquiries are sent to pilotbewerbung@buergerportal.de. These are requests to participate in a pilot phase, not job applications.

When you contact us by email, we also process sender, recipient and sending information transmitted by your email system, and any attached files. When you contact us by phone, we process the contact details and conversation content provided insofar as necessary to handle the enquiry. Please do not send residents’ case files, health data or confidential documents about other people through the marketing contact channels.

Where your enquiry concerns a contract with you or steps taken at your request before entering into a contract, the legal basis is Article 6(1)(b) GDPR. For general enquiries or where you represent an organisation, we process your business contact details under Article 6(1)(f) GDPR. Our legitimate interest is to answer enquiries and enable communication with interested parties and their contacts.

The forms send your entries to our own email service, which checks them and forwards them through our SMTP connection at Hetzner. It does not maintain a permanent form database or its own queue. The entries are processed temporarily in memory for transmission. Once your enquiry has been sent successfully, you will generally receive a confirmation email containing your details. An error in sending the confirmation does not necessarily mean that we have not received your enquiry. Processing in the email systems involved continues independently of this.

Enquiries are accessible to the people responsible for handling them. Mailboxes under buergerportal.de are hosted at Hetzner in Germany, covered by a data processing agreement. Contact and support enquiries are forwarded to TEC2DATE mailboxes. These operate in Microsoft 365 with data stored in the European Union or EFTA. A data processing agreement for Microsoft 365 is in place with a German or European contracting company. Enquiries addressed directly to TEC2DATE are also processed there. Technical email providers are therefore involved in transmission, delivery and storage. The details are not used for a newsletter or passed to external analytics services.

Email enquiries and related correspondence currently remain stored in our mailboxes after processing is complete. A fixed deletion period has not yet been implemented. Statutory retention obligations and your rights, in particular the right to erasure where the legal requirements are met, remain unaffected. Section 12 explains how to exercise your rights.

5. Newsletters and press mailing lists

With your consent, we send you information from the mailing lists you select. Subscription is voluntary and requires your email address. We also store your mailing list selection, subscription source and evidence of your consent, including its wording, version and the times of subscription, confirmation and unsubscription. You verify your email address using a link sent by email.

The legal basis for sending emails is Article 6(1)(a) GDPR. You can withdraw your consent at any time using the links in each newsletter email or by contacting news@buergerportal.de. This does not affect the lawfulness of processing carried out previously. We store evidence of consent under Article 6(1)(c) in conjunction with Article 7(1) GDPR and, to defend legal claims, under Article 6(1)(f) GDPR.

We operate our newsletter system at Hetzner in Germany. For email delivery, we use Mailjet, a service of the Sinch Group, as a processor. Mailjet processes recipient addresses, email content and delivery information. For possible transfers outside the European Economic Area, the data processing agreement provides in particular for EU standard contractual clauses. Information and a copy of the applicable safeguards are available from datenschutz@buergerportal.de.

Data processing at Mailjet (external link)

We do not analyse opens or clicks at an individual level. We store delivery failure and spam complaint reports for 30 days and remove them in the daily deletion run. We block permanently undeliverable addresses and addresses associated with spam complaints from further newsletters. The basis is Article 6(1)(f) GDPR. Our interest is reliable delivery without unwanted emails.

We delete unconfirmed subscriptions no later than eight days after the last request. Data for other existing subscriptions or blocks remains in place. We store confirmed subscriptions until unsubscription. After unsubscription through newsletter management, we retain evidence of consent for a further three years, after which it is removed in the daily deletion run. A minimal suppression record is retained for as long as necessary to respect your unsubscription or a delivery block. We review this annually. The legal basis is Article 6(1)(f) GDPR. Section 11 applies to backups.

When you subscribe to a newsletter in Bürgerportal, our newsletter system receives your email address, evidence of consent, subscription source, technical request identifiers and timestamps from the portal. We process these details in a technical transfer log to transmit the subscription reliably and prevent duplicate requests. If you delete your Bürgerportal account, we remove your newsletter recipient record, including all subscriptions and evidence of consent, from the newsletter system. If a global delivery block is in place, the blocked recipient record is retained. We unsubscribe the portal subscription and remove its evidence of consent. A new express subscription after account deletion requires email confirmation again. Global delivery blocks remain in place.

We remove the transmitted data from the technical transfer log seven days after completion. Pseudonymised technical records of completed requests are deleted after 1,095 days during ongoing cleanup. They prevent delayed old requests from triggering a new subscription. If the delivery outcome is unresolved, we also remove the transmitted data after seven days. The technical record remains until manual clarification. No fixed automatic deletion period has been set for such unresolved records. Withdrawals not yet completed remain stored until successfully processed and are retried in the event of a temporary disruption. The legal basis for the technical records is Article 6(1)(f) GDPR. Our interest is to reliably respect your subscriptions, unsubscriptions and delivery blocks.

6. Protecting forms against abuse

All public contact, support, recommendation, application and newsletter subscription forms also use self-hosted ALTCHA. Your browser solves a short computational challenge. Our form server verifies the proof before sending. The widget and verification run on our own infrastructure. No cookies are set and no data is transferred to the ALTCHA provider. Challenges are tied to the respective form, valid for ten minutes and usable only once. The limited pool of challenges in memory contains no form entries or IP addresses. Used challenges are removed immediately, expired ones at the next verification or challenge generation, and all challenges upon restart. The security check requires JavaScript. Alternatively, you can contact us by email or phone.

We use our own safeguards against automated or excessive form requests. These include rate limits, a check field that ordinary visitors should not fill in and checks of technical timestamps. We do not integrate an external CAPTCHA service for this.

For rate limiting, the delivery service processes a truncated IP network range and attempt timestamps in memory. This also includes failed form submission attempts. The limit uses a one-hour window. Entries no longer needed are removed no later than the next hourly cleanup or upon restart. Technical delivery and error logs may also contain the form type and truncated network range. Upstream infrastructure may process further connection data to prevent abuse.

For newsletter subscription rate limits, we use pseudonymised check values derived from the truncated IP network range and email address. For changes to mailing list selections, a check value is derived from the recipient identifier. These values, generated using a secret key, are held exclusively in memory alongside counters and the start of the relevant time window. The window is one hour. Expired entries are removed when the relevant rate limiter is next called or upon restart.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to protect our forms, mailboxes and infrastructure against spam, overload and misuse. A temporary technical rejection of a form request is not an automated decision about your enquiry or participation in the pilot phase.

7. Settings and storage in your browser

The website uses local browser storage for the settings described below. These features are separate from optional website analytics and do not create advertising profiles. We do not set analytics cookies.

SettingPurpose and storageDuration
AppearanceYour chosen light, dark or system-based appearance is saved in local storage under buergerportal-theme.Until you change the setting or clear your browser storage. There is no automatic expiry.
Navigation for organisationsbuergerportal-institutionen-themen-gewaehlt in session storage remembers whether you have already selected a topic, keeping the topic overview compact on subsequent page visits.For the session in the relevant browser tab. You can clear the storage earlier. Entering through the header resets the selection.
Analytics choicebuergerportal-analyse-v1 in local storage contains your consent or refusal, a timestamp and the information version.Valid for a maximum of 180 days. After expiry, the choice is discarded on the next access. You can delete or change it earlier.

Storing explicitly selected appearance and navigation settings serves the requested interface function and takes place under section 25(2), point 2 TDDDG. Where personal data is processed, the legal basis is Article 6(1)(f) GDPR. Our interest is to provide your settings in a user-friendly way. Storing your analytics choice serves to respect and document your decision under Article 6(1)(c) in conjunction with Article 7(1) and (3) GDPR. The necessary access to your device takes place under section 25(2), point 2 TDDDG.

You can delete or block this storage in your browser settings. Settings may then be lost or requested again. If your analytics choice cannot be saved, analytics stays disabled. We cannot remotely delete data already stored on a device you no longer use.

8. Optional website analytics with Umami

With your consent, we, TEC2DATE GmbH, analyse page views and selected clicks to improve this website. We run analytics ourselves on our systems at Hetzner in Germany. We do not transmit analytics data to external analytics services. You can use everything without analytics. You can withdraw your consent at any time using the “Analytics settings” button at the bottom of the page. Select “Decline” there.

We use the self-hosted software Umami for this. The analytics script is loaded only after express consent. Earlier page views or clicks are not reported retrospectively. No measurement takes place unless the analytics configuration has also been actively enabled. The legal basis is Article 6(1)(a) GDPR. Where information on your device is accessed, section 25(1) TDDDG also applies.

We collect visits to known content pages without URL parameters or fragments, timestamps and predefined event names, such as clicks on registration, sign-in, demo or app store links, and designated form events. We also collect the website hostname, a language value fixed to German, and browser, operating system and device categories derived from the browser identifier. A registration click does not establish that registration in Bürgerportal was completed.

Our proxy does not pass visitor IP addresses or location headers to Umami. Independently of this, the IP address is technically processed when connecting to the website. Umami uses the internal gateway address and browser characteristics to generate a session identifier that changes daily. As a precaution, we treat these identifiers as pseudonymous data. Visitors with the same browser characteristics may be grouped together. The analysis is therefore not an exact count of individual people.

We do not transmit form entries, names, email addresses, documents, user account IDs, referrer addresses, advertising identifiers or freely defined user properties to Umami. We do not use session recordings, heatmaps or cross-device identification. Umami telemetry and external update checks are disabled. Authorised people at TEC2DATE GmbH can access the analysis. Hetzner is involved as our hosting processor. No transfer to third countries is planned for this analytics service.

Analytics data is removed after 90 days in the daily deletion run, meaning no later than 91 days in normal operation. The analytics choice is valid in the browser for a maximum of 180 days. We also respect the browser signals Do Not Track and Global Privacy Control and keep analytics disabled when these signals are present.

You can withdraw your consent at any time by selecting “Decline” under “Analytics settings” in the footer. No further analytics events will then be sent. The decision is also respected in other open tabs of the same website. This does not affect the lawfulness of processing before withdrawal. Withdrawal does not automatically delete analytics data already collected. To request erasure, contact our privacy contact. As we do not link data to names or accounts, individual records may not be attributable to you. We do not collect additional identification data solely for this purpose.

We serve fonts, logos, images, graphics and app store badges ourselves. Displaying them does not load font or image files from external providers. This website does not contain external video, map, advertising or social media embeds.

Links may lead to the Bürgerportal application, a demo service, app stores or other websites. Your browser connects to the respective provider only when you open such a destination. The relevant privacy notices apply there. Opening an email link uses your email program. A phone link may use your phone application. In test and preview versions, links may temporarily lead to test destinations.

10. Recipients, service providers and processing abroad

Within our company, only people who need the data for their respective tasks can access it. Where we engage service providers to process data on our instructions, this is based on Article 28 GDPR. Other recipients may be involved where disclosure is legally required or necessary to pursue legal claims, such as competent authorities, courts or advisers bound by professional confidentiality.

Hosting and Umami analytics take place in Germany under the configuration described here. The statement that no data is transmitted to external analytics services refers to website analytics. It does not mean that no other providers are involved when you initiate email communication or open external links. Any transfer of personal data that we initiate to countries outside the European Economic Area must also meet the requirements of Articles 44 et seq. GDPR. European data storage for Microsoft 365 does not entirely rule out individual processing operations outside this region, for example for support or security. Such transfers are subject to the specifically applicable safeguards under Articles 44 et seq. GDPR. You can request further information and, where applicable, a copy of the safeguards from our privacy contact.

11. General retention periods and data protection

Retention periods are described under the respective processing activities. Email enquiries are subject to the current arrangements described in section 4. Statutory retention obligations must be observed independently of this.

The website is intended to be accessed using HTTPS encryption. We use access restrictions and separate the website, form delivery service and analytics database. Encryption and other safeguards reduce risks but cannot guarantee absolute security. In particular, ordinary email is not automatically end-to-end encrypted. For confidential content, please agree a suitable transmission method with us first.

Where data is included in backups, these are used for recovery after technical disruptions. Backups are stored exclusively in Germany. Only TEC2DATE has access. They are retained for a maximum of six months from creation and then deleted. Data already deleted from live systems may remain in backups until then. Following recovery, deletions made in the meantime must be applied again. The deletion period for the live Umami database is not a commitment about the retention period of all infrastructure backups.

12. Your rights

Where the legal requirements are met, you have the right to access your personal data, including a copy (Article 15 GDPR), rectification of inaccurate data (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). The right to data portability applies in particular to data you have provided that we process by automated means on the basis of consent or a contract.

You can withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. To exercise your rights, simply email datenschutz@buergerportal.de. To prevent disclosure to unauthorised people, we may need reasonable additional information to verify your identity if we have justified doubts.

13. Your right to object

Where we process data under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You may object to processing for direct marketing at any time without giving particular reasons. Send your objection to datenschutz@buergerportal.de.

14. Complaints to a supervisory authority

You may lodge a complaint with a data protection supervisory authority, particularly in the member state of your habitual residence, place of work or the alleged infringement. The authority responsible for our registered office is the Hessian Commissioner for Data Protection and Freedom of Information. Information and contact details are available at datenschutz.hessen.de.

15. Automated decisions and changes

On the marketing website, we do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Enquiries or pilot participation requests are not decided solely on the basis of website analytics.

We update this notice when the website or its data processing changes. If purposes requiring consent or the scope of data change significantly, we obtain renewed consent where necessary. This version: 18 September 2026.