Information on data processing under Article 13 GDPR
Privacy Policy
This policy explains how Nova Exchange Workshop processes personal data when you use this website and its member area. Last updated: 24 August 2026.
1. Controller and contact
The controller for the processing described in this policy is Thomas Müller, Domplatz 5, 38100 Braunschweig, Germany.
Email: neworkshop.bs@gmail.com. You can also use the contact form on this website.
2. Data protection officer
No data protection officer has been appointed for the current operation of this website.
3. Hosting, delivery and server logs
The production setup uses Vercel for application hosting and Neon PostgreSQL for the database. When the website is requested, those providers can process technically necessary connection data, such as IP address, date and time, requested page or file, HTTP status, browser or device information, referrer information where sent, and security-related log data.
We process this data to deliver the website, maintain reliability, prevent abuse, analyse errors and protect the service. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the website. Where necessary device storage or access is required to provide an expressly requested service, Section 25(2) no. 2 TDDDG may also apply.
We do not independently retain server logs. Vercel and other infrastructure providers retain technical data only under their own documented retention rules and for the time necessary for their operational and security purposes.
4. Cookies and language preference
The current code uses only functional cookies: `club_session` for authenticated member sessions and `club_locale` to remember the selected English or German language. The session cookie is HTTP-only, uses SameSite=Lax, and is marked Secure in production. The language cookie is functional, uses SameSite=Lax, and is marked Secure in production.
No analytics, advertising, social-media tracking, or other non-essential cookies are implemented. No local-storage use was identified in the application code. The legal basis is Article 6(1)(b) GDPR where required for the member service and Article 6(1)(f) GDPR for secure operation; for necessary device storage or access, Section 25(2) no. 2 TDDDG applies.
The language preference can remain for up to one year. Authenticated sessions expire after the configured session duration, which is 14 days by default, or on logout.
5. Member area, authentication and administration
The member area processes account and access data for authorised members: email address, optional name, role, optional biography, password hash, password-setup token hash, session-token hash, token and session timestamps, and content entered by authorised members or administrators. Passwords and raw session or setup tokens are not stored in plaintext by the application.
We process this data for member authentication, access control, account security, administration of the club website, and management or publication of club content. The legal basis is Article 6(1)(b) GDPR where necessary for membership or requested access, and Article 6(1)(f) GDPR for security, abuse prevention and administration.
Recipients are authorised club administrators, Vercel as hosting provider and Neon as database provider. Account and access data are kept while the member account is active. They are deleted or anonymised when the account is removed, unless statutory retention duties or legal claims require longer retention. Password-setup links are valid for 48 hours; sessions are valid for the configured duration.
6. Contact form and email correspondence
When you use the contact form, the application processes your name, email address and message. A hidden honeypot field is used only to identify likely automated submissions. The server sends the message to the club's configured recipient mailbox through Resend; the contact form does not write messages to PostgreSQL.
We process this data to respond to your enquiry and protect the form from misuse. The legal basis is Article 6(1)(b) GDPR where the enquiry relates to a requested service or pre-contractual communication, otherwise Article 6(1)(f) GDPR based on our legitimate interest in responding to communications and preventing abuse.
Recipients are Resend as email-delivery provider, the configured recipient mailbox and authorised club contacts. Contact correspondence is deleted no later than 12 months after the enquiry has been conclusively handled, unless statutory retention duties or legal claims require longer retention.
7. Server-side market data
The investment section retrieves current index data server-side from Yahoo Finance. Your browser calls this website's API; the request to Yahoo is made by the application server. This feature does not intentionally send your account, contact-form or member-profile data to Yahoo Finance.
Yahoo Finance can process connection data from the application server. The legal basis is Article 6(1)(f) GDPR based on our legitimate interest in providing current educational market data. This application does not save live market data in its database for this feature.
8. Fonts, social links and third-party content
The website uses Manrope and Fraunces through Next.js font handling. In the current implementation, the fonts are fetched during the build process and served with the application; visitors are not intended to load the fonts directly from Google when viewing the website.
Instagram, LinkedIn and YouTube are opened only when you select an external link. The website does not embed YouTube players, social-media feeds or tracking pixels. After you open an external link, that provider's privacy policy applies to its processing.
9. Recipients and international transfers
Depending on the service used, recipients or processors may include Vercel for hosting, Neon for the database, Resend for email delivery, the club's recipient-mailbox provider, and Yahoo Finance for server-side market-data retrieval. Personal data is disclosed only where necessary for the purposes described in this policy, to authorised club personnel, or where legally required.
Some providers may process data outside the European Economic Area. Where that occurs, the provider's applicable contractual and legal safeguards under Articles 44 et seq. GDPR, such as an adequacy decision or Standard Contractual Clauses, apply. Details are available in the providers' privacy and data-processing documentation linked in this policy.
10. Retention and deletion
We retain personal data only for as long as necessary for the relevant purpose, to meet statutory retention duties, or to establish, exercise or defend legal claims. The concrete periods are stated above where they are determined by the application or club process: up to one year for language preferences, 14 days by default for sessions, 48 hours for password-setup links, for the active life of a member account for account data, and no later than 12 months after a contact enquiry has been resolved for contact correspondence.
Technical server-log data is not independently retained by the club and is handled under the relevant provider's retention rules.
11. Your rights
Subject to the statutory conditions, you have the right to request access to your personal data, rectification, erasure, restriction of processing, data portability, and to object to processing based on Article 6(1)(e) or (f) GDPR. Where processing is based on consent, you may withdraw that consent at any time with future effect.
To exercise your rights, contact us at neworkshop.bs@gmail.com. Please include enough information for us to identify the relevant processing safely.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU or EEA Member State of your habitual residence, workplace or the place of the alleged infringement.
The competent supervisory authority for the controller's establishment is: Der Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany. Email: poststelle@lfd.niedersachsen.de.
13. Automated decisions and profiling
The current implementation does not use automated decision-making or profiling that produces legal effects or similarly significant effects within the meaning of Article 22 GDPR. The member database check is a technical access-control step for existing authorised accounts.
14. Security and changes to this policy
The production site is delivered over HTTPS/TLS. The application uses access controls, HTTP-only session cookies in production and hashed authentication tokens. We review technical and organisational security measures as necessary for the service.
We may update this policy when processing changes or legal requirements require it. The latest version is published on this page.
