← Back to homepage

Privacy Policy

This English translation is provided for convenience only; the legally binding version is the German one.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Doppelweiss GmbH
Meddenwarf 1
22457 Hamburg
Germany
Managing Director: Kian Asnaashari
Phone: +49 40 309 28884
Email: campus@doppelweiss.com

2. Your Rights

You have the following rights regarding your personal data: the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21). Where you have given consent, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR). Please contact us at the address above.

You also have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.

3. Hosting and Delivery of the Website

This website consists of static pages and is provided on a server we rent from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Nuremberg, Germany. Hetzner processes the resulting data exclusively on our behalf and in accordance with our instructions (Art. 28 GDPR).

The website is delivered through the content delivery and security network of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare serves the page content from a data centre near you and protects the website against attacks. In doing so, Cloudflare processes your IP address and technical connection data. The legal basis is our legitimate interest in the secure, fast and stable provision of the website (Art. 6(1)(f) GDPR). A transfer to the USA cannot be ruled out; such transfers are based on the European Commission’s Standard Contractual Clauses or on the EU-US Data Privacy Framework.

4. Server Log Files

When you access the website, information transmitted by your browser is automatically stored in server log files. This is typically: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request, and the IP address. This data serves the technical delivery of the site and the detection of faults and attacks. It is not merged with other data sources and is not used to identify you personally. The legal basis is Art. 6(1)(f) GDPR.

5. Contacting Us

If you contact us by email or telephone, we store your details in order to handle your enquiry and in case of follow-up questions. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or (f) (legitimate interest in responding). The data is deleted as soon as it is no longer necessary for that purpose and no statutory retention obligations prevent deletion.

The same applies if you choose “Get contacted instead” on the booking page: we then store the details you entered (first and last name, email address, telephone number, year of birth, playing position and your message) in order to contact you about your enquiry. No contract is concluded by this. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures). You may object to further contact at any time without formality, and we will delete your details. If you submit the booking form, we also store the same details even if you do not go on to complete the payment — so that we can trace your enquiry and reach you.

6. Booking and Payment Processing (Stripe)

When you book through this website, we process the data you provide — first and last name, email address, telephone number, year of birth, playing position and your message — together with the billing details, in order to conclude and perform the contract. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

Payment is processed by the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). You enter your payment data, such as your card number, directly on Stripe’s payment page; we do not receive this data. Stripe processes the data in order to carry out the payment and to meet its own legal obligations, in particular fraud and money laundering prevention. This may involve a transfer to third countries, including the USA; Stripe bases such transfers on the European Commission’s Standard Contractual Clauses. Further information is available in Stripe’s privacy policy at stripe.com/privacy.

The booking data from the form is passed to Stripe via an interface operated by us at Cloudflare. We retain booking and billing data in accordance with statutory commercial and tax retention periods of up to ten years (Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB).

7. Photography and Filming During the Event

Photographs and video recordings are made during the campus. We only use these for our public relations work if you have given us separate consent to do so (Art. 6(1)(a) GDPR). This consent is voluntary, is not required in order to take part, and may be withdrawn at any time with effect for the future.

8. Fonts

This website uses fonts (Oswald, Hanken Grotesk) that are hosted locally on our server. When you access the site, no connection is made to third-party servers such as Google Fonts, and no personal data is transmitted to third parties.

9. Cookies and Analytics

This website does not set any cookies. There is no analytics, no tracking and no profiling, and no third-party content (such as maps, videos or social media plugins) is embedded. A consent banner is therefore not required. On Stripe’s payment page, Stripe’s own information applies.

10. Currency of This Policy

This privacy policy will be updated whenever changes to our data processing make this necessary. Last updated: August 2026.