Chorga
Back to home

Privacy policy

Last updated: July 2026

1. Controller

The controller responsible for data processing on this website is: Ole Pahlkötter, Brunnenstraße 11, 56355 Weidenbach, Germany. Email: ole.pahlkoetter@t-online.de.

2. Hosting and server logs

This website is hosted by Vercel Inc. (San Francisco, USA). When you access our pages, Vercel processes technically necessary server log data (including IP address, time of access and page requested) to deliver the website and keep it secure. To protect the site, your browser also participates in a Content Security Policy; technical violation reports (page visited, blocked resource, browser type — without names or account data) may be transmitted to us and stored briefly in server logs. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in reliable and secure operation). A data processing agreement including EU standard contractual clauses is in place with Vercel.

3. Account, choir data and files

When you create an account, we process the data you provide (first and last name, email address, password in encrypted form, chosen language, optionally a profile picture) as well as the content you create in Chorga (e.g. choirs, memberships, roles and functions, events, participation and repertoire data, and uploaded files such as sheet music and audio recordings). This data is stored in a database operated by our processor Supabase in the EU (Frankfurt am Main region); a data processing agreement is in place with Supabase. The legal basis is Art. 6(1)(b) GDPR (performance of contract). Your choir's internal data is only visible to members of your choir; files are delivered via short-lived signed links.

4. Email delivery

We send system emails via Resend (Resend Inc., USA; data processing agreement including EU standard contractual clauses). These include confirmation emails on registration, sign-in links for passwordless login, password reset links, notifications to choir administrators about new inquiries (can be disabled in the choir settings), notices before long-unused choirs are archived, and internal notifications to our moderation team. For this purpose, the email address and the respective occasion are processed. The legal basis is Art. 6(1)(b) GDPR; for operational and moderation emails Art. 6(1)(f) GDPR.

5. Public choir profiles and performances

Choirs decide for themselves whether to publish a public profile (public by choice). Only once the choir administration publishes it do the approved details (e.g. choir name, description, location, rehearsal times at the chosen level of detail, logo/banner, the choir's contact details, shared performances) become publicly visible — on the choir profile, in the choir directory, in the concert calendar and potentially to search engines. Publication can be revoked at any time, after which the profile is no longer publicly accessible. The legal basis towards the choir is Art. 6(1)(b) GDPR; for personal details of individual people in the profile, the choir must have an appropriate arrangement with those people.

6. Choir map and geocoding (OpenStreetMap)

For the optional map view of the choir directory, your browser loads map tiles from servers of the OpenStreetMap Foundation (St. John's Innovation Centre, Cambridge, United Kingdom); your IP address is transmitted there. The map is only loaded when you open the map view. An EU Commission adequacy decision is in place for the United Kingdom. In addition, to determine a choir's map position we transmit its location details (city and country, no personal data) to the Nominatim geocoding service of the OpenStreetMap Foundation. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a location-based presentation of the directory).

7. Contact and join inquiries to choirs

Via public choir profiles you can send inquiries to a choir (e.g. joining, booking, press, cooperation). We process the data you provide: name, email address, optionally phone number and voice part, and your message, together with the time of your consent. These details are visible only to the administration of the choir you contacted, which handles your inquiry there (including status, assignment and internal note). The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw with effect for the future. 90 days after processing is completed, name, contact details and message are anonymised automatically.

8. Spam protection with Cloudflare Turnstile

We protect public forms (inquiries and reports) with Cloudflare Turnstile (Cloudflare Inc., USA). Turnstile checks without picture puzzles whether an input comes from a human and processes technical browser and connection data for this purpose (including IP address and device information). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in protection against spam and abuse). A data processing agreement including EU standard contractual clauses is in place with Cloudflare.

9. Reports and moderation

Public content (profiles, performances) and received inquiries can be reported. We process the reason for the report, an optional description and, if you wish, your email address for follow-up questions. Reports are reviewed by our moderation team; processing steps are recorded in an internal, immutable log. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a safe, compliant platform). Closed reports are deleted automatically 365 days after closure.

10. Product telemetry

To understand which features are used and where choirs drop off, we store a small, fixed set of usage events (e.g. choir created, first event created, profile published) with a timestamp and an association with the account or choir. We do not track page views, do not use advertising or third-party tools and do not build usage profiles; analysis is carried out in aggregated form. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in improving the product). Telemetry events are deleted automatically after 730 days; when an account or choir is deleted, the association is removed.

11. Abuse protection (rate limiting)

To protect public forms against abuse, we limit the number of submissions per sender. For this purpose we briefly store a cryptographically hashed value of your IP address (SHA-256) with a counter — the IP address itself is not stored. These counters are deleted after 24 hours at the latest. The legal basis is Art. 6(1)(f) GDPR.

12. Calendar subscriptions

Choir members can subscribe to their choir's events as a calendar. The subscription link contains a personal, random access key and delivers the choir's event data (90 days back and all future events) to your calendar application — for technical reasons without additional login. Treat the link like a password; you can regenerate it at any time, which invalidates the old link. When your membership ends or the choir is archived, access is blocked automatically. The legal basis is Art. 6(1)(b) GDPR.

13. Cookies

Chorga uses only technically necessary cookies: for your login (session) and, where applicable, for your language preference. No tracking, advertising or analytics cookies are used. The legal basis is Art. 6(1)(b) GDPR and Section 25(2) of the German TDDDG.

14. Storage periods

We store account and choir data for as long as your account or the choir exists. If you delete your account, your personal data is deleted unless statutory retention obligations apply. In addition, the automatic periods described above apply: inquiries are anonymised 90 days after completion, closed reports are deleted after 365 days, telemetry events are deleted after 730 days, and rate-limit counters are removed after 24 hours at the latest.

15. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR). You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). For any requests, simply contact the email address given above.