top of page

Privacy Policy

Privacy Policy of The Million Project

​

1. Introduction

Protecting personal data is not merely a legal obligation for The Million Project gUG. It is an essential part of our commitment to transparency, trust and responsible participation.

The Million Project is built on democratic engagement and collective decision making. This requires digital infrastructure and communication tools. Wherever personal data is processed, we do so with care, proportionality and in accordance with the General Data Protection Regulation (GDPR).

This Privacy Policy explains how we collect, process and protect personal data when you use our website, subscribe to our newsletter, contact us, donate or participate in our memberspace.

​

2. Controller

The controller responsible for data processing within the meaning of the GDPR is:

The Million Project gUG
Klosterstraße 4
76726 Germersheim
Germany

Registered at: Registergericht Landau
Commercial Register No.: HRB 34487

Email: connect@themillionproject.org

​

3. Principles of Data Processing

We process personal data based on the following principles:

  • Lawfulness, fairness and transparency

  • Purpose limitation

  • Data minimization

  • Accuracy

  • Storage limitation

  • Integrity and confidentiality

We only collect data that is necessary to provide our services, enable participation, communicate with you or comply with legal obligations.

​

4. Hosting and Technical Infrastructure (Wix)

Our website is hosted and technically operated via Wix.com Ltd.

Wix processes certain data on our behalf as a data processor. This may include hosting data, form submissions and technical usage information. Wix may store data on servers located inside or outside the European Union. In such cases, appropriate safeguards are in place in accordance with GDPR requirements.

The legal basis for hosting is Art. 6 para. 1 lit. f GDPR, as we have a legitimate interest in secure and reliable website operation.

​

5. Website Access Data

When you access our website, technical information is automatically collected:

  • IP address

  • Date and time of request

  • Browser type and version

  • Operating system

  • Referrer URL

  • Pages visited

This data is used exclusively to ensure technical stability, prevent misuse and maintain system security.

Legal basis: Art. 6 para. 1 lit. f GDPR.

​

6. Contact Forms and General Communication

If you contact us via contact form or email, we process the data you provide, such as:

  • Name

  • Email address

  • Message content

  • Any additional voluntary information

This data is used solely to respond to your request, evaluate potential volunteer engagement or address inquiries.

Legal basis:
Art. 6 para. 1 lit. b GDPR (pre-contractual communication)
Art. 6 para. 1 lit. f GDPR (legitimate interest in communication)

We do not share this data with third parties unless legally required.

​

7. Newsletter

If you subscribe to our newsletter, we process your email address and, where provided, your name.

The newsletter is currently managed through Wix.com. Subscription is based on explicit consent via a double opt-in process.

Legal basis: Art. 6 para. 1 lit. a GDPR.

You may withdraw your consent at any time by clicking the unsubscribe link in any newsletter or contacting us directly.

​

8. Donations

a) Bank Transfers

If you donate via bank transfer, we receive personal data transmitted by your bank, such as your name, IBAN and donation amount.

This data is processed to allocate your donation, issue receipts where applicable and comply with tax regulations.

Legal basis: Art. 6 para. 1 lit. b and lit. c GDPR.

b) Stripe

Online donations are processed via Stripe Payments Europe Ltd.

Stripe acts as an independent controller and processes payment-related data such as name, payment information and transaction details. We do not store full payment card information on our servers.

For further details, please consult Stripe’s privacy policy.

​

9. Memberspace and Login Area

The Million Project provides a protected memberspace intended for participatory engagement, voting processes and internal collaboration.

In this context, we process:

  • Name

  • Email address

  • Login credentials

  • Participation data

  • Activity within the memberspace

This processing is necessary to ensure secure access, protect voting integrity and maintain transparent documentation of participation processes.

Legal basis:
Art. 6 para. 1 lit. b GDPR
Art. 6 para. 1 lit. f GDPR

Access is restricted to registered members.

​

10. Google Analytics

We use Google Analytics, provided by Google Ireland Ltd., to analyze website usage and improve functionality.

Google Analytics uses cookies and processes usage data. IP anonymization is activated.

The use of Google Analytics is based solely on your consent via our cookie banner.

Legal basis: Art. 6 para. 1 lit. a GDPR.

You may withdraw your consent at any time through the cookie settings.

​

11. Cookies

Our website uses cookies for technical functionality and analytics.

Essential cookies are required for website and memberspace functionality.
Analytics cookies are only activated after your explicit consent.

Further details are provided in our Cookie Policy.

​

12. Data Retention

We store personal data only as long as necessary for the respective purpose or as required by statutory retention obligations under German law.

Donation-related data may be stored in accordance with tax retention periods.

​

13. Your Rights Under GDPR

You have the right to:

  • Access your personal data

  • Rectify inaccurate data

  • Request erasure

  • Restrict processing

  • Data portability

  • Withdraw consent at any time

  • Object to processing

  • Lodge a complaint with a supervisory authority

Supervisory authority in Rhineland-Palatinate:
Landesbeauftragter für den Datenschutz Rheinland-Pfalz

​

14. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, loss or misuse.

Access to personal data is limited to individuals who require it for legitimate operational purposes.

​

15. Changes to this Privacy Policy

We may update this Privacy Policy to reflect legal developments or changes in our services. The most current version is always available on our website.

​​

16. Contacting Us

If you have any questions about this Cookie Policy, please contact us at Connect@themillionproject.com.

​

Last Updated: 2nd March 2026

bottom of page