Privacy policy

Last updated: 2026-07-24

With the following privacy policy we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes and to what extent, within the scope of the online offering crisisplan.eu.

The most important thing first: crisisplan.eu is deliberately built so that your personal crisis plans never leave your device. There are no user accounts, no registration and no email requirement, and no cookies are set. Your plans — including notes and emergency contacts — are stored exclusively locally in your browser (IndexedDB or local storage) and are never transmitted to a server. The entire offering can be used without providing any personal data.

The terms used are not gender-specific.

This English version is provided for your convenience. In the event of any discrepancy, the German version of this privacy policy prevails.

Controller

Christian GötzeRathenaustr. 316761 HennigsdorfGermanyEmail: contact@crisisplan.euLegal notice (Impressum): https://crisisplan.eu/impressumA data protection officer is not required by law (Section 38 BDSG).

Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects.

Your crisis plans themselves are not part of it: they are stored exclusively locally in your browser and never reach our servers (see the section "Local storage of your crisis plans").

Types of data processed:

  • Meta, communication and procedural data (e.g. IP addresses, access times, browser type)
  • Usage data (aggregated, anonymised audience statistics)
  • Content data only when you actively contact us (your message to us)

Categories of data subjects:

  • Users (visitors to the online offering)
  • Communication partners (when contacting us)

Purposes of processing:

  • Provision of the online offering and web hosting
  • Security measures
  • Audience measurement / web analytics
  • Responding to contact requests

Relevant legal bases

Below we share the legal bases of the General Data Protection Regulation (GDPR) on which we process personal data. In addition, the national data protection requirements in Germany apply, in particular the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).

  • Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary to safeguard our legitimate interests, provided that the interests or fundamental rights and freedoms of the data subject do not override them. This applies in particular to the secure and stable operation of the online offering and to statistical audience measurement.

Your crisis plans are stored in your browser’s local storage because you expressly wish to use this function; the storage is strictly necessary for the service you have requested (Section 25(2)(2) TDDDG). We do not process this content, as the data never reaches our servers.

The location-based function (see below) runs exclusively in your browser; no personal location data is transmitted to us or stored by us, so no processing by us within the meaning of the GDPR takes place in this respect.

Security measures

We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, in order to ensure a level of protection appropriate to the risk. These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling access to the data as well as its input and disclosure.

TLS encryption (https): To protect the data transmitted via our online offering, we use TLS encryption. You can recognise encrypted connections by the prefix "https://" in the address bar of your browser.

Data minimisation by architecture: The most effective security measure of this offering is that your crisis plans never reach our systems in the first place — what is not stored with us cannot be compromised at our end.

Collection from the data subject: We collect personal data exclusively directly from the data subjects.

Automated decision-making: Automated decision-making or profiling within the meaning of Art. 22 GDPR does not take place.

Transfer to recipients and processors

To operate this online offering we use the following service providers, who act for us within the scope of processing on our behalf (Art. 28 GDPR): our hosting provider (Hetzner Online GmbH, see section "Provision of the online offering and web hosting") and — solely for delivering messages from the contact form — the email delivery service rapidmail GmbH (Augustinerplatz 2, 79098 Freiburg im Breisgau, Germany). Corresponding data processing agreements have been concluded. The mailbox in which contact emails arrive is operated by Proton AG (Geneva, Switzerland); Switzerland is covered by an adequacy decision of the EU Commission (Art. 45 GDPR). Beyond that, no transfer to third countries outside the European Economic Area (EEA) takes place. Your crisis plans never reach any of these service providers — they remain exclusively in your browser.

Provision of the online offering and web hosting

We operate this online offering on a server in a data centre in Germany. As our web host we use Hetzner Online GmbH, which acts as a processor for us.

Collection of access data and log files: When our online offering is accessed, access data is recorded on the server side in so-called server log files. This regularly includes: IP address, date and time of access, requested URL, HTTP method, amount of data transferred, status message, browser type and version (user agent), and referrer URL. The storage serves to ensure operation, IT security (in particular the detection and prevention of attacks) and error analysis. The log files are stored on our own server in Germany and — apart from the reporting of attacker IP addresses described below — are not transmitted to any external service provider. They are deleted as soon as they are no longer required for the stated purposes, as a rule after 30 days. If log data continues to be required to investigate a specific security incident, storage is restricted until the matter has been finally clarified.

Attack detection (CrowdSec): To defend against attacks, the server log files are automatically analysed on our own server with the open-source security software CrowdSec. If an attack is detected (e.g. repeated intrusion or abuse attempts), the attacker's IP address may be reported to CrowdSec SAS (France, EU) for collective abuse prevention. Only IP addresses from which attacks originate are reported; normal use of the offering is never reported. Legal basis: legitimate interests (Art. 6(1)(f) GDPR – IT security).

  • Types of data processed: Meta, communication and procedural data (e.g. IP addresses, access times, browser type).
  • Data subjects: Users (visitors to the online offering).
  • Purposes of processing: Provision of the online offering, IT security, error analysis.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR – interest in secure and stable operation).

Hosting provider used:

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; website: https://www.hetzner.com; privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz. The server locations are in Germany.

Local storage of your crisis plans (in your browser)

You can create and save personal crisis plans without having an account. Such a plan may contain in particular the following information: a freely chosen title, the selected scenarios, the progress on associated checklists, the selected country or region, emergency contacts, and free-text notes.

This information is stored exclusively locally in your browser (IndexedDB) and is never transmitted to our server. We have no access to your crisis plans and do not process this data within the meaning of the GDPR — any special categories of personal data (Art. 9 GDPR, e.g. health details in your notes) never reach us either. You retain full control over your data.

When you open a saved plan, only its random technical identifier appears in your browser's address bar; it is therefore part of the requested URL (see the section "Provision of the online offering and web hosting" on server log files), but contains none of your plan's content and is not linked by us to any other data. In the audience measurement (Matomo), this identifier is removed from the URL before anything is recorded.

Storing this data on your device is strictly necessary for the function you expressly wish to use (creating and managing crisis plans) and is therefore exempt from consent pursuant to Section 25(2)(2) TDDDG.

Please note the consequences of local storage:

  • If you delete this offering’s site data in your browser (or uninstall the browser), your plans are irretrievably gone. Therefore export a backup regularly (page "Your data") and print your plan — in a crisis, paper is the most reliable medium anyway.
  • The export creates a file on your device; nothing is transmitted to us in the process.
  • On a shared device, other people with access to the same browser can view your saved plans. On shared devices, consider using a separate browser profile.

You can view and individually delete your plans yourself at any time (page "My plans"), and export, import or completely remove them from the browser (page "Your data").

Cookies and local storage

Our online offering does not use any cookies at all — neither for tracking or advertising purposes nor for sessions. A consent banner is therefore not required.

Local browser storage: To store interface settings we use your browser’s local storage, in particular for the chosen appearance (theme), the selected country, the dismissal of the safety-notice banner, the dismissal of the shared-device notice and a not-yet-saved draft of a crisis plan; your saved crisis plans are kept in the browser database IndexedDB (see the previous section). In addition, we use short-lived technical markers in your browser's session storage (sessionStorage) — for example for status messages after saving and for recovery after updates — and a local marker recording whether you have already exported or printed a plan. All of this information remains exclusively in your browser and is not transmitted to us. The storage is strictly necessary for the functions you have requested (Section 25(2)(2) TDDDG). You can delete the local storage at any time via your browser settings.

Audience measurement is carried out without cookies (see section "Web analytics (Matomo)").

Location-based function

Our online offering provides the option of using your location in order to suggest region-relevant scenarios. This function is optional. If it is used, your browser first asks you for permission to access your location (browser prompt).

The coordinates determined by your device are processed exclusively locally in your browser in order to determine the corresponding country or region. The coordinates are never transmitted to our server and are not stored by us. No processing of personal location data by us therefore takes place.

You decide on location access yourself via your browser prompt; you can revoke a permission you have granted at any time in your browser settings.

Web analytics (Matomo)

Self-hosted audience measurement with Matomo: To statistically analyse how our online offering is used, we use Matomo, an open-source web analytics tool. Matomo runs exclusively on our own infrastructure at https://matomo.cgoetze.de; the collected data is processed solely on our own server in Germany and is not shared with any third party — in particular not with the makers of Matomo (InnoCraft Ltd.). No transfer to third countries outside the EEA takes place.

Cookieless processing without consent: Matomo is configured in a privacy-friendly way. It sets no cookies and does not access information already stored on your device. The active detection of device and browser characteristics (such as screen resolution and installed browser features) is disabled, so nothing is accessed on your device in that respect either. Because no information within the meaning of Section 25(1) TDDDG is stored on or read from your device, neither consent nor a consent banner is required. Your IP address is anonymised (the final bytes are truncated) before any storage; any geolocation is derived only from the already-anonymised IP address. There is no cross-site tracking, no individual user profiles are built and no User ID is used; the resulting statistics are aggregated and do not allow any conclusions about individual persons.

Objection and "Do Not Track": Our Matomo installation respects your browser’s "Do Not Track" setting. If your browser sends a "Do Not Track" signal, you are not included in the audience measurement. You may also object to this processing at any time with effect for the future (Art. 21 GDPR).

Aggregate scenario and usage counters: In addition, our server counts in purely aggregate form (without IP addresses, without identifiers and without any personal reference) views of the individual scenario pages (one counter per scenario) as well as selected plan lifecycle events (e.g. plan created, printed, backup exported/imported, storage persistence requested — counters only, without plan content and without plan ID). This counting is also skipped if your browser sends a "Do Not Track" signal.

  • Types of data processed: Meta, communication and procedural data (e.g. shortened/anonymised IP addresses, access times, pages viewed, anonymised referrer URL, approximate region, device and browser type, language setting).
  • Data subjects: Users (visitors to the online offering).
  • Purposes of processing: Audience measurement / web analytics; needs-based, statistically sound optimisation of the online offering.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR – interest in the statistical analysis and optimisation of the online offering); Section 25(1) TDDDG does not apply, as nothing is stored on or read from the device.

Contact and email communication

When you contact us (e.g. via the contact page or by email), the information you provide is processed insofar as this is necessary to respond to your request and any follow-up questions. The information is deleted as soon as it is no longer required for the purpose, as a rule no later than 6 months after the request has been finally processed, unless statutory retention obligations apply.

Delivery: Messages from the contact form are delivered via the email delivery service rapidmail GmbH (Germany), acting as a processor, and arrive in our mailbox operated by Proton AG (Switzerland; EU Commission adequacy decision).

Spam protection (ALTCHA): To protect the contact form against automated requests we use the self-hosted security solution ALTCHA. Your browser solves a small computational task (proof of work) in the background. No cookies are set, no data is transmitted to third parties, and no information is stored on or read from your device.

We do not send an email newsletter; there are also no account- or registration-related emails, as the offering works without user accounts.

  • Types of data processed: Contact data (e.g. email address), content data (text entries).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact requests and communication.
  • Recipients: rapidmail GmbH (email delivery), Proton AG (email mailbox).
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR – responding to requests).

Deletion of data

The data processed by us is deleted in accordance with the legal requirements as soon as the consents permitted for processing are revoked or other permissions cease to apply (e.g. if the purpose of processing this data no longer applies or it is no longer required for the purpose). If the data is not deleted because it is required for other and legally permissible purposes, its processing is restricted to those purposes.

In addition, the following deletion periods and principles apply:

  • Server log files: deletion as a rule after 30 days (see section "Provision of the online offering and web hosting").
  • Locally stored crisis plans: reside exclusively in your browser and are under your sole control; you can delete them yourself at any time in the app (page "Your data") or via your browser settings.
  • Audience measurement (Matomo): deletion of the raw data (visitor logs) after 90 days; aggregated, anonymous reports are deleted after 12 months.

Rights of data subjects

Right to object (Art. 21 GDPR): You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR.

For your crisis plans: since this data resides exclusively locally in your browser, you can exercise the corresponding rights (viewing, exporting, rectifying, deleting) yourself directly in the app at any time — a request to us is not necessary for this, nor would it be possible, as we do not hold this data.

As a data subject, you are also entitled to further rights under the GDPR, which arise in particular from Art. 15 to 18 and 20 GDPR:

  • Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether data concerning you is being processed and to obtain information about this data as well as further information and a copy of the data.
  • Right to rectification (Art. 16 GDPR): You have the right to request the completion or rectification of data concerning you.
  • Right to erasure (Art. 17 GDPR): You have the right to request the erasure of data concerning you.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of the processing of your data.
  • Right to data portability (Art. 20 GDPR): You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format or to request its transmission to another controller.
  • Withdrawal of consent (Art. 7(3) GDPR): Insofar as processing is based on consent, you have the right to withdraw it at any time with effect for the future.
  • Complaint to the supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow; phone: +49 33203 356-0; email: poststelle@lda.brandenburg.de.

Amendment and updating of the privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing carried out by us make this necessary. The date given above indicates when the privacy policy was last updated.

Definitions of terms

In this section you will find an overview of the terms used in this privacy policy. Many of the terms are taken from the law and defined primarily in Art. 4 GDPR. The legal definitions are binding.

  • Personal data: Any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier.
  • Controller: The natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: Any operation or set of operations performed on personal data, whether or not by automated means. The term covers practically any handling of data, be it collection, analysis, storage, transmission or erasure.
  • Processor: A natural or legal person that processes personal data on behalf of the controller (e.g. a hosting provider).