Privacy Notice

1. Controller

The controller responsible for the processing of personal data on this website is:

TONALi gGmbH
Kleiner Kielort 8
20144 Hamburg, Germany

Phone: +49 40 53 26 62 71
E-mail: info@tonali.de

Managing directors: Amadeus Templeton, Boris Matchin

Register court: Amtsgericht Hamburg, HRB 113743
VAT identification number: DE274969618

2. Data protection officer

You can reach our external data protection officer at:

Arne Platzbecker
HABEWI GmbH & Co. KG
Palmaille 96
22767 Hamburg, Germany

Phone: +49 40 46008966
E-mail: platzbecker@habewi.de

You may contact him directly about any data protection matter at any time; you do not need to give a reason.

3. Scope of this notice

This privacy notice applies to the website tonali.de including all its subpages and its English-language version. It does not apply to third-party services we link to — such as our social media profiles, our newsletter system or external ticketing and donation platforms. Those services are governed by the privacy notices of their respective providers; we point this out separately in the relevant sections.

Personal data means any information relating to an identified or identifiable natural person — for example your name, your e-mail address or your IP address. Processing means any handling of such data, from collection through storage to erasure.

4. Overview of the technology used

This website has been rebuilt and deliberately designed to minimise data collection. In concrete terms:

  • We do not use web analytics or tracking. There is no audience measurement, no profiling and no advertising cookies.
  • Simply visiting the website does not set any cookies that would require consent. A cookie banner is therefore not necessary.
  • Fonts, images and scripts are served from our own servers. No content is retrieved from Google Fonts or comparable services.
  • All application servers and the database are located in the European Union (Frankfurt am Main).

Where data is nevertheless passed to third parties — for instance when you submit the contact form or make a donation — we describe this individually in the sections below.

5. Provision of the website and server log files

When you access our website, your browser transmits technically necessary data to the server delivering the page. Without this data the page cannot be displayed to you. The following is processed:

  • your IP address
  • date and time of the request
  • the address requested (URL) and the HTTP status code
  • the volume of data transferred
  • the previously visited page (referrer), if your browser transmits it
  • browser type, browser version and operating system

The purpose of this processing is to deliver the website, to ensure the security of our systems and to investigate faults and attempted attacks. The legal basis is our legitimate interest in a functioning and secure web presence, Art. 6(1)(f) GDPR.

The hosting infrastructure is operated by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA, acting as our processor. The application servers that answer your requests are pinned to the Frankfurt am Main region (eu-central-1). Static content is delivered through a global content delivery network, which means a request may be served from a location outside the EU. On transfers to third countries see section 19.

Server-side access logs are deleted or anonymised regularly, as soon as they are no longer required for the operation and security of the website.

6. Content, images and database

The texts, images and event listings on this website are stored in a database and a media store operated by Supabase (Supabase Inc., 970 Toa Payoh North, Singapore, with European processing located in the Frankfurt am Main region). Supabase acts as our processor.

Merely reading the website does not cause any personal data about you to be stored there. Personal data only arises once you actively send us something — for example through the contact form (section 8).

7. Cookies and storage on your device

A cookie is a small text file that a website places on your device. Storing information on your device and accessing information already stored there is only permitted with your consent, unless it is strictly necessary for a service you have expressly requested (section 25 TDDDG).

An ordinary visit to this website sets no cookies. There are no analytics, marketing or personalisation cookies, and we do not embed any service that would set such cookies.

There are two cases in which something may nevertheless be stored on your device:

  • If you use the donation form on our donations page, its provider may set its own cookies which are necessary to process the donation (section 11).
  • On non-public preview versions of this website, which are accessible only with a password, a technically necessary cookie is set after a successful sign-in to remember it. This cookie never reaches you as an ordinary visitor to the published website.

You can delete cookies at any time in your browser settings or prevent them from being stored in the first place.

8. Contact form

This website offers a form through which you can reach us. It collects:

  • name (required)
  • e-mail address (required)
  • telephone number (optional)
  • your message (optional)
  • your confirmation that you have read this privacy notice and agree to be contacted (required)

We additionally store the time of submission and the address of the page from which you sent the form. To protect against automated bulk submissions we also store a checksum of your IP address computed with a secret addition. The IP address itself is not stored, and the checksum cannot be converted back into the IP address.

The purpose of this processing is to handle your enquiry and to communicate with you about it. The legal basis is your consent under Art. 6(1)(a) GDPR and — insofar as your enquiry concerns the conclusion or performance of a contract — Art. 6(1)(b) GDPR. You may withdraw your consent at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected.

After submitting, you automatically receive a confirmation of receipt by e-mail. Your enquiry is at the same time forwarded to the responsible team and stored in our internal system so that we can handle it and trace its history.

We erase your enquiry once it has been dealt with conclusively and no statutory retention obligations apply.

9. Contact by e-mail, telephone or post

If you write to us or call us outside the form, we process the data that arises — in particular your name, your contact details and the content of your enquiry — solely in order to handle your request.

The legal basis is Art. 6(1)(b) GDPR where your enquiry serves the initiation or performance of a contract, and otherwise our legitimate interest in answering enquiries under Art. 6(1)(f) GDPR.

Please note that unencrypted e-mail may be read by third parties in transit. For confidential matters we are happy to offer you another channel.

10. Newsletter

We send our newsletter through CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany, acting as our processor. You sign up through a form provided by them, where your data is collected and stored.

We use the double opt-in procedure: after signing up you receive an e-mail in which you confirm your registration. Only then do we add you to the distribution list. On registration we additionally store the time and the technical details of the confirmation in order to be able to demonstrate your consent.

The legal basis is your consent under Art. 6(1)(a) GDPR. You can unsubscribe at any time; every issue contains an unsubscribe link. After you unsubscribe we delete your data from the distribution list; we retain the record of your consent for as long as we need it to defend against claims.

11. Donations

On our donations page we embed a donation form provided by twingle GmbH (Tiniusstrasse 9–11, 13089 Berlin, Germany). When you open that page, a script is loaded from the provider's servers, which transmits your IP address to the provider. The provider may set its own cookies in this context.

When you donate, you enter your details directly into the provider's form. The data processed there includes in particular your name, your contact details, the donation amount and the payment details you choose. Payment itself is handled by the respective payment service providers; we do not receive complete payment data.

The legal basis for processing your donation is Art. 6(1)(b) GDPR, and for embedding the form our legitimate interest in offering a simple and secure way to donate under Art. 6(1)(f) GDPR. For tax purposes and to issue donation receipts we process donation data on the basis of Art. 6(1)(c) GDPR and retain it in line with commercial and tax law retention periods.

12. Events and dates

We publish our events and dates on this website. Viewing these pages requires no registration and no personal data.

Tickets are not sold through this website. To buy a ticket we link you to the relevant advance booking system, where that provider's privacy notice applies.

13. Error logging and security

So that we can notice and fix technical faults, we use the Sentry service (Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA). The service runs in the EU region; the data is stored in the European Union.

If an error occurs in your browser or on our server, an error report is generated. It contains technical details such as the error message, the address requested, the time as well as details of the browser and operating system, and it may contain the IP address. Before it is sent, we automatically remove known confidential fields such as cookies and credentials.

Your session is not recorded (no session replay). We have expressly disabled that feature. In addition, only a sample of requests is evaluated to measure response times.

The legal basis is our legitimate interest in the error-free and secure operation of this website, Art. 6(1)(f) GDPR.

14. Operational logs

For technical operations we evaluate structured log data. It is forwarded by the host to the Axiom service (Axiom, Inc., USA), which runs in the EU region. The logs contain technical details about how a request was handled; credentials and fields identified as confidential are removed automatically before they are written.

The legal basis is our legitimate interest in stable and traceable operations, Art. 6(1)(f) GDPR.

15. Protection against abusive use

The forms and programming interfaces of this website are protected against automated bulk requests. To that end we count requests per sender within a time window. For this counting we use a short-term caching service (Upstash, Inc., USA). The counters expire automatically after a short time.

The legal basis is our legitimate interest in protecting our systems against abuse and overload, Art. 6(1)(f) GDPR.

16. Sending e-mail

Automated e-mails from this website — such as the confirmation of receipt for your form enquiry — are sent via the service provider Resend (Resend, Inc., USA), which acts as our processor. The data transmitted includes your e-mail address as well as the subject and content of the message.

The legal basis is Art. 6(1)(b) GDPR, or our legitimate interest in reliable delivery under Art. 6(1)(f) GDPR.

17. Links to social networks

We link to our profiles on Instagram and Facebook (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland) and on YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). These are plain links, not embedded buttons or tracking pixels. Data is only transmitted to the respective network once you click such a link; from that moment its privacy notice applies.

For the processing of your data on the platforms themselves we are joint controllers with the respective provider insofar as statistics about the use of our profiles are concerned. We have only limited influence on the processing carried out there.

18. Recipients of your data

Within our organisation only those units receive access to your data that need it to perform their tasks. Beyond that we engage service providers acting as our processors under Art. 28 GDPR and bound by our instructions:

  • our IT service provider for the development, operation and maintenance of this website
  • Vercel Inc., USA: hosting and delivery of the website, application servers in Frankfurt am Main
  • Supabase Inc.: database and media store, Frankfurt am Main region
  • Functional Software, Inc. (Sentry), EU region: error logging
  • Axiom, Inc., EU region: operational logs
  • Upstash, Inc.: protection against abusive use
  • Resend, Inc.: sending automated e-mails
  • CleverReach GmbH & Co. KG, Rastede: sending the newsletter
  • twingle GmbH, Berlin: donation form and donation processing

Data is disclosed to other recipients only if you have consented, if we are legally obliged to do so, or if it is necessary to enforce our rights. Your data is not sold.

19. Transfers to third countries

We have chosen our infrastructure so that your data is processed within the European Union. Transfers to countries outside the EU or the EEA may nevertheless occur, in particular because some of the service providers named above are established in the United States and may access the systems from there for maintenance and support.

We base such transfers on the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR and, where the provider concerned is certified, on the adequacy decision for the EU-U.S. Data Privacy Framework under Art. 45 GDPR. You can obtain a copy of the relevant safeguards on request using the contact details in section 1.

20. Retention periods

We store personal data only for as long as it is necessary for the respective purposes or as required by statutory retention periods. After that the data is deleted or anonymised.

  • server log files: until they are no longer required for the operation and security of the website
  • error reports and operational logs: until the purpose of the evaluation ceases to apply
  • form enquiries: until the matter is concluded, beyond that only where statutory retention obligations exist
  • newsletter data: until you withdraw your consent
  • donation and accounting data: in line with commercial and tax law periods, as a rule up to ten years

21. Security measures

We take technical and organisational measures in line with the state of the art to protect your data against loss, alteration and unauthorised access. These include in particular:

  • encrypted transmission of all pages and forms via HTTPS
  • browser-side security directives (including Content Security Policy, Referrer Policy and Permissions Policy) that restrict the loading of third-party content
  • tenant-separated data storage with access rules enforced directly in the database, so that one organisation's content is not reachable by another
  • a role and permission model for editorial access as well as logged sign-ins
  • automatic removal of confidential fields from logs and error reports
  • regular updates of the software components in use

22. Your rights

You have the following rights in relation to the personal data concerning you:

  • access to whether and which data we process about you (Art. 15 GDPR)
  • rectification of inaccurate and completion of incomplete data (Art. 16 GDPR)
  • erasure of your data, unless a retention obligation applies (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • receipt of the data you provided in a common format and its transfer to another controller (Art. 20 GDPR)
  • withdrawal of a consent given, with effect for the future (Art. 7(3) GDPR)

An informal message to the contact details in section 1 or 2 is enough to exercise your rights.

23. Right to object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of data concerning you which we base on Art. 6(1)(f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or unless the processing serves to establish, exercise or defend legal claims.

Where your data is processed for direct marketing purposes, you may object at any time without giving reasons; processing for that purpose will then cease.

24. Complaint to a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement (Art. 77 GDPR).

The authority responsible for us is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Strasse 22, 20459 Hamburg, Germany
Phone: +49 40 428544040
E-mail: mailbox@datenschutz.hamburg.de

25. No automated decision-making

Automated decision-making including profiling under Art. 22 GDPR does not take place. We do not evaluate you automatically and we do not take decisions concerning you based solely on automated processing.

26. Changes to this privacy notice

We adapt this privacy notice when the legal situation, our services or the technology in use changes. The version published on this page applies in each case.

Last updated: 8 September 2026