Legal

Privacy

What happens with your data when you visit hey.forum and when you post.

Controller

The controller for the processing of personal data on this website is hey.business GmbH, Salzburger Straße 15, 83329 Waging am See, Germany.

Contact: info@hey.business, phone +49 8681 8589852. Further details are in the imprint.

Hosting

The web application and its database (PostgreSQL) run on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in the Falkenstein data centre in Germany.

Hetzner processes the data generated by operating the server on our behalf under a data processing agreement pursuant to Art. 28 GDPR.

Access data and server logs

hey.forum is a web application built on Next.js (Node.js) with the Payload content system. The application itself keeps no access log of its own and does not store visitors' IP addresses in its database. The runtime writes its operational and error messages to the container output.

The reverse proxy (Traefik) on the server does not write access logs either; we checked this on 29 September 2026.

The server keeps the container output in at most three files of 10 MB each. When the last file is full, the oldest entries are overwritten. Whenever the website is deployed anew, the container is replaced and its logs are deleted. How long an entry survives therefore depends on traffic and on how often the website is redeployed; there is no fixed number of days. We do not analyse this data ourselves.

The legal basis is our legitimate interest in delivering the website securely and reliably (Art. 6(1)(f) GDPR).

Cloudflare

Cloudflare, Inc. (USA) operates in front of the website as a reverse proxy and content delivery network (CDN). Every request passes through Cloudflare first. Cloudflare processes your IP address and the request data (for example the requested address, time and browser identifier) to deliver the pages and protect them from attacks.

Cloudflare processes this data as a processor under Art. 28 GDPR on our behalf, on the basis of the Cloudflare Data Processing Addendum (version 6.4, effective 3 April 2026). According to Cloudflare's privacy policy (effective 4 November 2025, section 6), Cloudflare acts as a processor for these request logs ("Customer Logs").

The legal basis is our legitimate interest in delivering the website securely and reliably (Art. 6(1)(f) GDPR).

Retention: Cloudflare stores this data until the end of our contract with Cloudflare or until it is no longer needed to provide the service, whichever comes first. At the end of the contract Cloudflare deletes or returns the data.

Data may be transferred to the USA in the process. The basis is the EU Commission's standard contractual clauses (Art. 46(2)(c) GDPR), which are part of the data processing addendum, alternatively the EU Commission's adequacy decision on the EU-US Data Privacy Framework. You can obtain a copy of the standard contractual clauses on request to info@hey.business; they are also part of the publicly available Cloudflare Data Processing Addendum.

When we checked on 29 September 2026, Cloudflare set no cookies and injected no scripts on these pages.

Cookies and local storage

These pages use no analytics, statistics or tracking services and no advertising cookies. There are four technical stores:

The public pages embed no content from third-party servers. The fonts (Instrument Serif, Geist, Geist Mono) are served by this server.

1. Visitor identifier "hey_forum_visitor_id" (cookie): This cookie is set only when, as a visitor without an account, you support an idea or submit a comment, not merely when you read. It contains a random identifier, cannot be read by scripts in the browser (HttpOnly), is sent only over secure connections (Secure, SameSite=Lax) and lasts one year. It prevents repeated support of the same idea from the same browser and attributes your own comments and supports to the same identifier. The identifier is stored in our database together with every comment and every support. Signed-in team members do not receive this cookie; their account identifier is stored instead. The cookie is not a prerequisite for supporting or commenting: if your browser rejects it, the action still goes through, and the server generates a new random identifier for it, which is stored with the entry. Because the browser does not keep it, each such action has a different identifier; repeated support then cannot be prevented, and entries cannot be attributed to the same person. If you delete the cookie, comments and supports already stored remain, but the browser can no longer recognise them as yours; afterwards you count as a new visitor. The legal basis is Art. 6(1)(f) GDPR; for access to your device we rely on § 25(2) no. 2 TDDDG. You can delete the cookie in your browser settings at any time.

2. Sign-in cookie "payload-token" (team members only): the Payload content system sets it when a team member signs in at /admin; visitors without an account do not receive it. Its content is a signed token (JWT) with the account identifier, the email address, the roles of the account and the session identifier, plus issue and expiry time. It lasts 2 hours (7200 seconds, Payload's default; we set no other value), cannot be read by scripts in the browser (HttpOnly), applies to the whole site (path "/") and is sent with SameSite=Lax. In production it carries the "Secure" attribute and is sent only over secure connections. The purpose is signing the team in for moderation; without the cookie sign-in is not possible. The legal basis is Art. 6(1)(f) GDPR (secure moderation) or, where a team member works for us, Art. 6(1)(b) GDPR; for access to the device we rely on § 25(2) no. 2 TDDDG.

3. Interface cookies of the content system (team members only, and only when they change the setting): "payload-theme" (value "light" or "dark", one year, readable by scripts, path "/") stores the colour choice of the Payload interface, "payload-lng" (language code, one year, path "/") its language. Neither contains an identifier and neither is transmitted to third parties. Visitors without an account do not receive them. The legal basis is Art. 6(1)(f) GDPR; for access to the device we rely on § 25(2) no. 2 TDDDG.

4. Colour mode (localStorage): When you change the colour mode, your browser stores this choice locally (entry "hey-theme-mode"). When a page loads, it also reads the older entry "ghdr.theme" if it is still present in your browser from an earlier service, and uses it only if "hey-theme-mode" is missing. This older entry is only read, not changed, migrated or deleted. Neither entry is transmitted to us; access is necessary for the appearance you chose (§ 25(2) no. 2 TDDDG). You can delete them at any time in your browser settings.

When we checked on 29 September 2026, none of the pages we tested (home, regions, topics, moderation, sign-in) set a cookie on a plain visit. A consent prompt is therefore not needed.

Team area (/admin): the content system uses no Gravatar and sends no usage statistics to its vendor (both are switched off). There is one exception: when a team member opens a record with a JSON field, the content system's editor component loads the library "Monaco" from cdn.jsdelivr.net (jsDelivr); the provider thereby receives the IP address and the usual request data of the team member's browser. This affects team members only, never visitors. The legal basis is Art. 6(1)(f) GDPR.

Search, filters and region selection

When you search or filter ideas, the search term and filters go to our server as address parameters. When you pick a region in the region navigator, your browser asks our server for the sub-regions (country identifier, parent region and language). Our server uses these details only to build the response; the application does not store them. Like every requested address, however, they pass through Cloudflare (see the Cloudflare section).

Visitor data: ideas, comments, supports

On hey.forum you can submit ideas, support ideas and comment on ideas. No account is needed.

Idea: title, summary, text, optionally a freely chosen display name ("Bürgerin/Bürger" if left empty), optionally a location hint and optionally an identifier of a directory entry, plus region, topics, processing status, support and comment counters, and creation and modification time. An idea becomes publicly visible only after moderation has approved it.

Stored is the address derived from the title or name of an idea, discussion, initiative or volunteer request (part of the web address, "slug"); if the title contains a name, it therefore also appears in the address. This address is shown publicly and stored in the database.

In addition, moderation can store an attachment (reference data in JSON format) and a summary written by moderation (free text) with an idea. Only moderation fills both fields, by hand; the application calls no AI service for this, transmits nothing to third parties for it, and does not fill the fields itself. They may contain details about persons and are publicly retrievable for published ideas through the application's interface (API).

Comment: text, display name, identifier of the commented item, visitor identifier from the cookie (or the account identifier of a signed-in team member), moderation status (for example "visible", "hidden"), where applicable a moderation reason, and creation and modification time. Comments appear publicly at once and can be hidden or removed by moderation.

Support: visitor identifier (or account identifier), identifier of the supported idea, vote type ("support"), a derived key that prevents repeated support, and creation and modification time. Supports cannot be viewed publicly; only the counter on the idea is shown.

Title, summary, text, display name and location hint are visible to everyone once published. Please do not include personal data of third parties, and do not choose a display name that identifies you if you do not want that. The application stores neither IP address nor browser identifier (user agent) with ideas, comments or supports.

The purpose is running and moderating the participation platform. The legal basis is our legitimate interest in doing so (Art. 6(1)(f) GDPR). No automatic deletion period is in place: we keep posts as long as the platform shows them or moderation needs them. On request to info@hey.business we delete posts and the associated visitor identifier as far as they can be attributed to you.

Team account data (moderation and administration)

Accounts for the team are created only by an administrator; there is no registration and no sign-in for visitors. Stored are: email address, roles, the password only as a salted hash (never in plain text), the password reset token with expiry time and the time of the last request, the counter of failed sign-ins and a lock time, the sessions (identifier, creation and expiry time), and the creation and modification time of the account.

In addition there are administration data of the Payload content system that are tied to an account: interface settings and editing locks (which account is currently editing which entry). For moderation decisions we store the identifier and email address of the reviewing person, decision note, decision time and audit trail in the moderation entry.

For sign-in Payload sets the cookie "payload-token". No email sending is set up: if the system still triggers an email (for example "forgot password"), it is not sent; only the recipient address and subject are written to the container output (retention as in the server logs section).

The purpose is secure sign-in and moderation. The legal basis is our legitimate interest in secure moderation of the platform (Art. 6(1)(f) GDPR). Access: account holders to their own account, moderation to the account list, administrators to all accounts. Only an administrator deletes accounts; we keep them as long as the person works in the team. Sessions and tokens carry an expiry time.

Details entered by moderation: initiatives, volunteer requests, discussions, directory references

Initiatives and volunteer requests are created only by team members; visitors cannot submit them. In doing so, moderation enters details about third parties (associations, initiatives, contact persons) who do not enter them themselves through this portal.

Initiative: name, description, mission statement, contact email address, website, social media links, addresses of logo and cover image, link to a directory entry, topics, region, status, and creation and modification time. Volunteer request: title, description, type of need, required number, time commitment, time information, location, start and end, contact method, status, link to an initiative, and creation and modification time. Contact email address and contact method are shown on the public pages (as a button to write an email, or as text).

The purpose is to make volunteering offers and needs, discussions and references to places and events visible. The legal basis is our legitimate interest in doing so (Art. 6(1)(f) GDPR). No automatic deletion period is in place: entries stay as long as they are published or the initiative needs them.

Discussion: title and text of the discussion, display name of the author, forum area, region, topics, status, counters and timestamps. Only team members create discussions (not the website); title and text can contain details about named persons. Directory references: name, address and web address of a place or event, taken from the HEY directory (Foundry); for sole traders, associations or private persons as providers they can be traceable to a person.

For references to places and events, coordinates (places only), region details and a checksum of the imported content are also stored; for sole traders, associations or private persons as providers, address and coordinates can locate a person.

Description texts of regions, topics and forum areas are free text written by the team; they are not meant for details about persons, but are technically not limited to that, and are publicly visible. For initiatives the addresses of logo and cover image are also stored; the images themselves are not stored with us.

If you are affected by such a detail, you can request access, rectification and erasure and object to the processing (see Right to object). Write to info@hey.business and name the entry; moderation then changes or deletes it. Access: public on the pages, editing only by moderation and administrators.

Data sets without details about visitors

Regions, topics and forum areas consist of identifiers and settings; their description texts are described in the previous section. The HEY Foundry delivery logs contain only counters and machine markers (readable only by administrators). Payload also keeps internal tables for key-value data and the state of database changes without personal reference.

Overview: which data is stored where

Data setStored detailsPurposeLegal basisRetentionAccess
IdeasTitle, summary, text, display name, location hint, directory links, region, topics, status, counters, timestamps, attachment and summary written by moderation (free text, filled by moderation only), address derived from the titleParticipationArt. 6(1)(f)No automatic deletion; deletion on requestPublic after approval; moderation, administrators
CommentsText, display name, visitor identifier, item identifier, moderation status, moderation reason, timestampsParticipation, moderationArt. 6(1)(f)No automatic deletion; deletion on requestPublic while visible; moderation, administrators
SupportsVisitor identifier, idea identifier, vote type, derived key, timestampsPrevent repeated support, counterArt. 6(1)(f)No automatic deletion; deletion on requestModeration, administrators (publicly only the counter)
Moderation entriesTitle of the reviewed item, status, identifier and email address of the reviewing person, decision note, decision time, audit trailModerationArt. 6(1)(f)No automatic deletionModeration, administrators
Team accountsEmail address, roles, salted password hash, password reset token with expiry and request time, counter of failed sign-ins, lock time, sessions, timestampsSign-in, securityArt. 6(1)(f)As long as the person works in the team; sessions and tokens carry an expiry timeOwn account; moderation (account list); administrators
Account administration dataInterface settings, editing locksOperating the content systemArt. 6(1)(f)No automatic deletionOwn account; administrators
InitiativesName, description, mission statement, contact email address, website, social media links, image addresses, status, timestampsMake volunteering offers visibleArt. 6(1)(f)No automatic deletion; deletion on requestPublic; editing by moderation, administrators
Volunteer requestsTitle, description, type, number, time commitment, time information, location, start and end, contact method, status, timestampsMake needs visibleArt. 6(1)(f)No automatic deletion; deletion on requestPublic; editing by moderation, administrators
Discussions (created by the team)Title and text of the discussion, display name of the author, forum area, topics, status, counters, timestampsMake discussions visibleArt. 6(1)(f)No automatic deletion; deletion on requestPublic; editing by moderation, administrators
Directory referencesName, address and web address of places and events from the HEY directory, coordinates, region details, checksumLink to directory entriesArt. 6(1)(f)No automatic deletion; deletion on requestModeration, administrators; public only once resolved
Description texts (regions, topics, forum areas)Free text written by the teamExplain contentArt. 6(1)(f)No automatic deletion; deletion on requestPublic; editing by moderation, administrators
Other data setsIdentifiers and settings of regions, topics, forum areas; Foundry delivery logsContent and operationno personal reference–Public or administrators

Newsletter and forms

A newsletter is planned but not yet available. The sign-up field in the footer sends nothing and stores no addresses. There is no contact form.

If you email or call us, we process your details (for a call, what you tell us on the phone, and your phone number where it is shown to us) to handle your enquiry. The legal basis for emails and calls is Art. 6(1)(b) GDPR where your enquiry concerns a contract or pre-contractual measures, otherwise our legitimate interest in answering it (Art. 6(1)(f) GDPR).

Retention and rights

We keep details from emails and calls to us as long as needed to handle your enquiry or as statutory retention duties require. For server logs the deletion criteria above apply (at most three files of 10 MB each, deletion when the container is replaced), for Cloudflare the criteria in the Cloudflare section, for all other data the details in the sections on the individual data and in the overview.

You can exercise the rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20). Write to the email address above. The right to object is set out in the next section.

Right to object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data that is based on Art. 6(1)(f) GDPR (Art. 21(1) GDPR). This covers every processing in this notice for which we rely on our legitimate interest.

After an objection we no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

You can send the objection to info@hey.business without any formalities.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA) in Ansbach.

As of September 2026.

Back to home