
Legal
Pursuant to GDPR, TTDSG and TMG · Last updated: March 2026
The protection of your personal data is of particular importance to us. We therefore process your data exclusively on the basis of statutory provisions (GDPR, TTDSG, TMG). In this privacy policy, we inform you about the most important aspects of data processing in connection with our website.
The controller pursuant to Art. 4 No. 7 GDPR is:
Verein für Afghanistan-Förderung e.V. (Bright Afghan)
Alaunbachweg 12, 53229 Bonn, Germany
Phone: +49 (0) 228 481077
Email: info@brightafghan.org
Represented by: Abdul Jalil Hekmat (Chairman)
As a small non-profit association, we are not legally required to appoint a data protection officer pursuant to Art. 37 GDPR. For any data protection queries, please contact us directly at the address above.
This website is hosted by Vercel Inc., 340 Pine Street, Suite 900, San Francisco, CA 94104, USA. Each time our website is accessed, Vercel automatically records the following data in server log files: anonymised IP address, date and time of request, URL, referrer URL, browser type/version, operating system, HTTP status code.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in the secure provision of the website). Log files are deleted after 30 days. Data transfer to the USA is based on EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR). Vercel participates in the EU–US Data Privacy Framework. Details: vercel.com/legal/privacy-policy
We use Vercel Analytics, a privacy-friendly web analytics service by Vercel Inc. Vercel Analytics collects anonymised usage data such as page views, time on page, and device types. No cookies are set and no personal data (such as IP addresses) is stored or shared with third parties.
Vercel Analytics is only activated after you have given consent via our cookie consent banner. Legal basis: Art. 6 (1)(a) GDPR (consent). You may withdraw your consent at any time via the cookie settings.
More information: vercel.com/docs/analytics/privacy-policy
We use strictly necessary cookies without which the website cannot function. These do not require consent (§ 25 (2) No. 2 TTDSG): language preference, session cookie (for secure login), CSRF protection token.
On your first visit, a cookie consent banner is displayed at the bottom of the page. You can accept all cookies, allow only essential cookies, or make a granular selection. Your consent decision is stored in your browser (localStorage) and can be withdrawn at any time via the cookie settings in the website footer.
Legal basis: § 25 (1) TTDSG (consent for non-essential cookies) and Art. 6 (1)(a) GDPR (consent). The storage of the consent decision itself is technically necessary (§ 25 (2) No. 2 TTDSG).
For any optional cookies, we obtain your explicit consent in advance pursuant to § 25 (1) TTDSG and Art. 6 (1)(a) GDPR. You may withdraw this consent at any time. We currently use the following optional services:
When you contact us via our contact form or by email, the data you provide (name, email address, subject, message) is stored solely for the purpose of handling your enquiry and is not shared with third parties. Legal basis: Art. 6 (1)(b) GDPR or Art. 6 (1)(f) GDPR. Data is deleted after your enquiry has been fully resolved.
Form data is transmitted via TLS encryption. Emails are sent via Resend (Resend Inc., San Francisco, CA, USA, privacy policy). Data transfer to the USA is based on EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR) and a Data Processing Agreement (Art. 28 GDPR). Only the data necessary for email delivery (recipient email address, subject, message content) is transmitted.
Donations are processed via Twingle (Twingle GmbH, Franklinstraße 27, 10587 Berlin, privacy policy). Data transmitted includes name, email, postal address (for donation receipt), donation amount/frequency, and payment data. Processing is based on a Data Processing Agreement (Art. 28 GDPR). Legal basis: Art. 6 (1)(b) GDPR; for donation receipts Art. 6 (1)(c) GDPR. Donor data is retained for 10 years pursuant to German tax law.
Twingle operates its servers in Germany and is fully GDPR-compliant. All donor data is exclusively processed and stored on German servers.
Twingle facilitates payments via third-party providers such as PayPal, Stripe, or SEPA. The respective privacy policies of these providers apply to their processing.
If you subscribe to our newsletter, we process your email address based on your consent (Art. 6 (1)(a) GDPR) via a double opt-in procedure.
Newsletter emails are sent via Resend (Resend Inc., San Francisco, CA, USA, privacy policy). Data transfer to the USA is based on EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR) and a Data Processing Agreement (Art. 28 GDPR).
Newsletter subscriber data (email address, subscription timestamp, confirmation status) is managed and stored via Supabase (Supabase Inc., San Francisco, CA, USA, privacy policy). Data transfer to the USA is based on EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR) and a Data Processing Agreement (Art. 28 GDPR). Data is stored in a secured database and used exclusively for newsletter delivery.
You may unsubscribe at any time via the unsubscribe link in any newsletter email or by contacting us at info@brightafghan.org. After withdrawal of consent, your data will be removed from the mailing list.
We use Sanity (Sanity AS, Stortorvet 7, 0155 Oslo, Norway, privacy policy) to manage website content. Sanity does not process personal data of website visitors.
The member dashboard is restricted to authorised staff. Login data (email/password or Google OAuth 2.0) is processed on the basis of Art. 6 (1)(b) GDPR. Google OAuth is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ( Google Privacy Policy).
Under the GDPR you have the following rights:
To exercise your rights, contact us at: info@brightafghan.org
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority (Art. 77 GDPR). The supervisory authority for North Rhine-Westphalia is:
Landesbeauftragte für Datenschutz und Informationsfreiheit NRW (LDI NRW)This website uses TLS/SSL encryption for all data transmission. We implement appropriate technical and organisational security measures pursuant to Art. 32 GDPR to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorised access by third parties.
We reserve the right to update this privacy policy when the legal framework or our data processing practices change. The current version is always available on this page. We will notify you of material changes in an appropriate manner.
Last updated: March 2026