mifem e.V. · Kassel
Privacy policy
How we handle your personal data. Version: September 2026. The legally binding version of this privacy policy is the German one.
1. Privacy at a glance
General information
The following information provides an overview of what happens to your personal data when you visit this website. Personal data is any information by which you can be personally identified.
Detailed information on data protection can be found in the following sections of this privacy policy.
Data collection on this website
Data processing on this website is carried out by the operator of the website. You will find the contact details of the controller in the following section.
Some of the data is collected automatically or with your consent by the website's IT systems. This is in particular technical data such as the browser used, the operating system, the time of the page visit and the IP address.
Other data is processed when you provide it to us voluntarily, for example when you contact us by e-mail.
2. Controller
The controller for data processing on this website is:
Migrantische Frauenemanzipation (mifem) e.V.
Treppenstraße 4
34117 Kassel
Germany
Represented by the authorised board pursuant to § 26 BGB:
Chair: Dr Melehat Kutun
Deputy chair: Eda Kara
E-mail: info@mifem.de
Pursuant to § 6 (2) of the statutes, the association is represented in and out of court by the chair or the deputy chair. Each of them is authorised to represent the association individually.
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
3. Hosting with Netlify
This website is hosted by the following provider:
Netlify, Inc.
101 2nd Street
San Francisco, CA 94105
USA
When our website is accessed, the hosting provider processes technically necessary information. This may include in particular the following data:
- IP address or anonymised IP address,
- date and time of access,
- page or file accessed,
- amount of data transferred,
- browser type and browser version,
- operating system used,
- referrer URL,
- requesting internet provider,
- notification of successful retrieval.
The processing serves to provide the website technically, to ensure its security and stability and to be able to detect possible abusive access. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure and reliable operation of this website.
The data is deleted as soon as it is no longer required for the purposes stated, unless statutory retention obligations or legitimate security interests prevent deletion.
A data processing agreement under Art. 28 GDPR is in place with Netlify; it is incorporated into their terms of service. Processing also takes place in the United States. Netlify, Inc. is certified under the EU-U.S. Data Privacy Framework, so the transfer is based on the European Commission's adequacy decision of 10 July 2023. Further information: netlify.com/privacy
4. SSL and TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption.
You can recognise an encrypted connection by the fact that the browser's address bar begins with "https://" and a padlock symbol is displayed.
5. Contact form and contact by email
When you fill in the contact form, the details you enter there – name, email address and your message – are processed through the Netlify Forms service, stored at Netlify, Inc. and forwarded from there by email to info@mifem.de. What is said about hosting above also applies, including the processing in the United States. The form contains a field that is invisible to you and that rejects automated submissions; it processes no personal data.
If you contact us by e-mail, we process the information you send us, including your contact details, in order to handle your enquiry and to answer any follow-up questions.
If your enquiry serves to initiate or perform a contract or membership, the processing is based on Art. 6 (1) (b) GDPR. In all other cases, the processing is based on our legitimate interest in handling enquiries addressed to us pursuant to Art. 6 (1) (f) GDPR. Where you have expressly consented, the processing is based on Art. 6 (1) (a) GDPR.
The data you have sent will be deleted once your enquiry has been dealt with conclusively and no statutory retention obligations or other legitimate reasons for further storage exist.
6. Cookies and storage on your device
To show our Instagram posts on the home page, we embed an external service. That service and Meta place cookies and comparable technologies on your device.
This happens only with your express consent. The legal bases are § 25 (1) TDDDG and Art. 6 (1) (a) GDPR. As long as you do not consent, the service is not loaded and no request is sent to it.
We store your decision in your browser's local storage for six months – as a plain yes or no with a date, without an identifier and without a cookie. We use no third-party service for the consent itself.
You can change your decision at any time with effect for the future, via the “Cookie settings” link at the foot of every page. We use no analytics, statistics or advertising services; there are no tracking pixels and no cross-device recognition.
7. Instagram posts on this website
On the home page we show our latest posts in a frame that Instagram itself provides for this purpose. It is loaded directly from Instagram. The recipient of the data is therefore:
- Recipient of the data
- Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland
- Instagram's privacy policy
- privacycenter.instagram.com/policy
If you consent, your browser connects to Instagram. In particular your IP address, details of your browser and device, the date and time and the page you visited may be transmitted. If you are logged in to Instagram, Meta can link the visit to your account. We have no influence on any further processing.
Without your consent the frame is not loaded – it sits in the page without an address, so no request goes out to Instagram. You can withdraw your consent at any time via “Cookie settings” at the foot of the page; the section is then locked again.
8. External links to Instagram
Our website also contains simple links to our Instagram profile. As long as you do not click such a link, no connection to Instagram is established by the link alone.
If you click the link, you leave our website. The respective platform provider is generally responsible for the subsequent data processing on Instagram.
9. No use of further analytics or map services
As things currently stand, we use neither Google Analytics nor embedded Google Maps or YouTube videos on this website. Fonts are also not loaded from external servers but are held on our own web space.
This section is to be adapted if one of these services or another statistics, analytics or marketing tool is used at a later date.
10. Storage period
Unless a specific storage period is stated in this privacy policy, we store personal data only for as long as is necessary for the respective purpose of processing.
Statutory retention periods remain unaffected. If you request effective deletion or withdraw consent, the data concerned will be deleted unless there are legal or other permissible grounds for further storage.
11. Your rights
Within the scope of the statutory requirements, you have in particular the following rights:
- right of access pursuant to Art. 15 GDPR,
- right to rectification pursuant to Art. 16 GDPR,
- right to erasure pursuant to Art. 17 GDPR,
- right to restriction of processing pursuant to Art. 18 GDPR,
- right to data portability pursuant to Art. 20 GDPR,
- right to object pursuant to Art. 21 GDPR,
- right to withdraw consent given pursuant to Art. 7 (3) GDPR.
The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the withdrawal.
To exercise your rights you can contact info@mifem.de .
12. Right to object
If data processing is based on Art. 6 (1) (e) or (f) GDPR, you have the right at any time to object to the processing of your personal data for reasons arising from your particular situation.
We will then no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
13. Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority. The authority responsible for us is:
The Hessian Commissioner for Data Protection and Freedom of Information
Wilhelmstraße 7
Wiesbaden 65185
Germany
Telephone: +49 611 1408-0
E-mail: poststelle@datenschutz.hessen.de
Website: datenschutz.hessen.de
14. Changes to this privacy policy
We reserve the right to adapt this privacy policy if the functions of our website, the services used or the legal requirements change.
Version: September 2026