Privacy Policy

Language: English | Deutsch

Last updated: 2026-08-30

This Privacy Policy explains how WAYF Journal processes personal data when you use this website.

1. Controllers (Art. 4(7) GDPR)

The joint controllers for data processing on this website are:

Sahra Malin
Suad Kamardeen
Boxhagener Str. 81
10245 Berlin
Germany
Email: wayfjournal@gmail.com

As joint controllers we have agreed that WAYF Journal answers all requests from data subjects and provides the information required under Articles 13 and 14 GDPR. You may exercise your rights against either of us using the contact details above, and we will respond jointly. The essence of this arrangement is summarised here in line with Art. 26(2) GDPR.

2. Data we process and why

a) Website access / hosting logs

When you visit this website, technical log data (for example IP address, date/time, requested URL, user agent) may be processed by our hosting provider to ensure security and stability.

Legal basis: Art. 6(1)(f) GDPR (legitimate interests in secure operation).

b) Contact, partnerships and other forms

If you submit a form (for example contact, partnerships, newsletter), we process the data you provide (name, email and your message) to handle your request.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures/request handling) and Art. 6(1)(f) GDPR (communication).

c) Newsletter signups

We process newsletter signup data to provide updates and communications you requested.

Legal basis: Art. 6(1)(a) GDPR (consent), where applicable.

You can withdraw your consent at any time with effect for the future, either by using the unsubscribe option in any newsletter or by emailing us. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal (Art. 7(3) GDPR).

d) Orders and payments (Stripe)

For purchases in our shop, payment and order data is processed by Stripe to complete payment and prevent fraud. We also process limited order details to fulfill your purchase.

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (fraud prevention, secure operations).

e) Transactional emails (Resend)

After successful orders, we send transactional emails (for example order confirmations and digital download information where applicable).

Legal basis: Art. 6(1)(b) GDPR (contract performance).

f) Web fonts and externally hosted images

Our pages currently load the Inter and Playfair Display typefaces from Google Fonts, and our logo image from a Squarespace content delivery network. When a page loads, your browser requests these files directly from those providers, which means your IP address and browser information are transmitted to them. No cookies are set by this and we receive no data from it ourselves.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in consistent presentation and reliable delivery).

We intend to serve these files from our own domain so that this transfer no longer takes place. This section will be updated when that change is made.

g) Digital download files (Google Drive)

Digital editions are stored on Google Drive and delivered as an unlisted share link, which anyone holding the link can open. Opening the link means your request, and any Google account you are signed into, is processed by Google under its own terms. We do not track who opens a download link.

Legal basis: Art. 6(1)(b) GDPR (delivery of the purchased edition).

3. Processors and recipients

We use service providers (processors) for technical operations. These currently include:

  • Netlify (hosting, and storage of submissions from the forms on this site)
  • Stripe (payment processing)
  • Resend (transactional email delivery)
  • Google Drive (storage and delivery of digital edition PDFs)
  • Google Fonts (delivery of the typefaces used on this site)
  • Squarespace (content delivery network for our logo image)

4. International data transfers

Netlify, Stripe, Resend, Google and Squarespace are based in or have parent companies in the United States, so data may be processed outside the EU/EEA and the UK. These transfers rely on the EU–US Data Protection Framework where the provider is certified under it, and otherwise on EU Standard Contractual Clauses together with the UK International Data Transfer Addendum. You can request details of the safeguards that apply to a particular provider using the contact details below.

5. Retention periods

Form submissions, newsletter data and general correspondence are retained for up to 3 years, or until you withdraw consent or ask us to delete them, whichever comes first.

Order and payment records are kept for longer because tax and accounting law requires it: up to 10 years under German retention rules and at least 6 years under UK rules. We keep these records for the longer of the periods that applies to a given order, and then delete them.

6. Cookies and analytics

We set no cookies of our own and run no analytics or tracking tools on this website. Your cart is stored locally in your own browser and is never sent to us except when you check out. Stripe may set cookies on its own checkout pages, which are governed by Stripe's privacy notice.

Reminder for future update: if analytics are introduced later, this section must be updated before activation.

7. Your rights under GDPR

You have the right to access, rectify, erase, restrict processing, object to processing, and data portability, where applicable. Where processing is based on consent, you may withdraw that consent at any time (Art. 7(3) GDPR).

You may also lodge a complaint with a supervisory authority, especially in the EU member state of your habitual residence, place of work, or alleged infringement. For our Berlin activities this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit; in the United Kingdom it is the Information Commissioner's Office (ICO).

8. Contact for privacy requests

For all privacy-related requests, contact: wayfjournal@gmail.com