Privacy Policy
Datenschutzerklärung / Privacy Policy
Last updated: March 17, 2026
Forest4Future (“we,” “us,” or “our”) is a United States 501(c)(3) nonprofit organization (EIN: 41-3975881) committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you visit our websites (forest4future.eu, forest4future.net) or interact with our services. Because we operate a .eu domain and serve users in the European Union, we comply with both the EU General Data Protection Regulation (GDPR) and applicable US privacy laws.
1. Data Controller
The data controller responsible for processing your personal data is:
501(c)(3) Nonprofit Organization
EIN: 41-3975881
Responsible person: Johannes zu Eltz
Email: info@forest4future.eu
Verantwortlicher gem. Art. 4 Abs. 7 DSGVO: Forest4Future, vertreten durch Johannes zu Eltz. Kontakt: info@forest4future.eu.
2. Data We Collect
We collect personal data only when necessary to fulfill our nonprofit mission. Depending on how you interact with us, this may include:
2.1 Donations & Sponsorships
- Full name, email address
- Billing address (required for tax receipts and payment processing)
- Donation amount and transaction details
- Payment method (processed by PayPal; we never see your full card number)
2.2 Gift Certificates
- Purchaser name and email
- Recipient name (as entered for the certificate)
- Personal message (optional)
2.3 Contact Forms & Email
- Name, email address, message content
2.4 Automatically Collected Data
- IP address (anonymized in server logs)
- Browser type, operating system, device type
- Pages visited, date and time of access
We do not use analytics or tracking tools such as Google Analytics. We do not collect data for advertising purposes.
3. Legal Basis for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
- Contract performance (Art. 6(1)(b)): Processing donations, issuing tax receipts, and fulfilling gift certificate orders.
- Legitimate interest (Art. 6(1)(f)): Operating our website, ensuring security, and improving our services.
- Legal obligation (Art. 6(1)(c)): Retaining financial records as required by tax law (US IRS regulations for 501(c)(3) organizations).
- Consent (Art. 6(1)(a)): Where you explicitly consent, for example when subscribing to updates. You may withdraw consent at any time.
4. Payment Processing
All payments (donations, tree sponsorships, gift certificates) are processed through PayPal, Inc. (San Jose, USA). PayPal is PCI DSS Level 1 certified. When you make a payment, your payment details are handled directly by PayPal via their secure API. We never store or have access to your full payment information.
PayPal processes your data in accordance with their Privacy Statement. Data may be transferred to the United States. PayPal participates in the EU-US Data Privacy Framework.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO (Vertragserfuellung). PayPal ist PCI-DSS Level 1 zertifiziert und nimmt am EU-US Data Privacy Framework teil.
5. Hosting & Infrastructure
Our website and backend services are hosted on Hetzner Cloud (Hetzner Online GmbH, Gunzenhauser Str. 1, 91710 Gunzenhausen, Germany). All servers are located in Germany (EU), ensuring that your data remains within the European Union. Hetzner is ISO 27001 certified.
Server access logs containing IP addresses are retained for a maximum of 7 days for security purposes and then automatically deleted.
Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an sicherem und stabilem Betrieb der Website). Alle Server befinden sich in Deutschland.
6. Email Communication
We use SMTP-based email delivery (via Nodemailer) for transactional emails such as donation confirmations, tax receipts, and gift certificate delivery. We send emails only when necessary for completing transactions you initiate or when you have explicitly consented to receive updates.
We do not sell, rent, or share your email address with third parties for marketing purposes.
8. Third-Party Services
We use the following third-party services:
| Service | Purpose | Data Location |
|---|---|---|
| Hetzner Cloud | Website hosting, database | Germany (EU) |
| PayPal | Payment processing | USA (EU-US DPF) |
| SMTP Provider | Transactional email delivery | EU |
We do not use Google Analytics, Facebook Pixel, or any other tracking or advertising services.
9. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy:
- Donation records: Retained for 7 years as required by US tax law (IRS regulations for 501(c)(3) organizations).
- Contact form submissions: Deleted after 12 months unless an ongoing relationship exists.
- Server logs: Automatically deleted after 7 days.
- Gift certificate data: Retained for 3 years after issuance.
10. Your Rights (GDPR Art. 15–21)
If you are located in the European Economic Area (EEA), you have the following rights under the GDPR:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate data.
- Right to erasure (Art. 17): Request deletion of your data, subject to legal retention requirements.
- Right to restrict processing (Art. 18): Request that we limit how we use your data.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interest.
- Right to withdraw consent: Where processing is based on consent, you may withdraw at any time without affecting prior processing.
To exercise any of these rights, please contact us at info@forest4future.eu. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. If you are in Germany, this is the relevant state data protection authority (Landesdatenschutzbeauftragte).
Sie haben das Recht auf Auskunft, Berichtigung, Loeschung, Einschraenkung der Verarbeitung, Datenuebertragbarkeit und Widerspruch. Kontaktieren Sie uns unter info@forest4future.eu. Beschwerderecht bei der zustaendigen Aufsichtsbehoerde.
11. Children's Privacy
Our services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated “Last updated” date. We encourage you to review this page periodically.
13. Contact
For any questions regarding this Privacy Policy or your personal data, please contact us:
Email: info@forest4future.eu