Privacy notice

As of 22 September 2026

1. Controller

The controller responsible for processing data on this website is Divyanand Spiritual Foundation e.V., Sägestraße 37, 79737 Herrischried, Germany, represented by the Chair of the Board, Dr. Angelika Glöckner, telephone +49 7764 93970.

For any question about data protection, and to exercise your rights, an informal message to info@dsf-germany.org is enough.

2. In brief

  • You can use the website without signing in. Without signing in, the website sets no cookie.
  • We use no analytics, tracking or advertising tools. The website loads no content, fonts or scripts from third parties.
  • Because we do not track you across websites, a "Do Not Track" signal from your browser changes nothing here.
  • Signing in is optional and works only with a Google account. We receive your email address, your name and a Google identifier.
  • While you are signed in, we store where you stopped in a satsang, and which satsangs and passages you have saved.
  • We do not pass your data on, sell it or use it for advertising.

3. Visiting the website and server logs

Whenever you open the website, your browser necessarily sends data to our server. This includes in particular your IP address, the date and time of the request, the address requested, the response status, the amount of data transferred, the page you came from (referrer), and your browser and operating system.

The server stores this data in log files. We use it to deliver the website, to keep it secure, to fend off attacks and to find faults. We do not combine it with other data and do not build usage profiles from it.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is operating the website securely and without faults. The logs are deleted automatically after 14 days.

4. Cookie

As long as you do not sign in, the website sets no cookie. Only when you choose "Sign in" do we set a single cookie, the session cookie "dsf_session". It holds only a random identifier by which our server recognises your session. The cookie is sent only over encrypted connections, cannot be read by scripts, and is not sent to other websites.

While you are signing in, the session holds only a check value that makes sure the return from Google belongs to your own sign-in. During this step the cookie lasts no more than 10 minutes; if the sign-in fails or you decline it at Google, we delete it at once. Once you are signed in, the session records which account is signed in, when you signed in and when you were last active.

A sign-in ends after 30 days without activity, at the latest 180 days after signing in, and immediately when you sign out; the cookie is then deleted. While you are signed in, each visit extends it by 30 days, up to that limit.

The legal basis for storing the cookie is § 25(2) no. 2 TDDDG, because it is strictly necessary for the sign-in you asked for; for the processing, Art. 6(1)(b) GDPR. We use no other cookies, no third-party cookies and no other storage in your browser.

5. Signing in with Google

Signing in is optional. When you choose "Sign in", you are sent to Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google checks your sign-in; we never learn your password.

With your agreement at Google, Google sends us your Google account identifier, your email address and your name as it appears in your Google account. We get no access to your Google account and store neither access tokens nor your profile picture.

Google also processes data in the USA. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision under Art. 45 GDPR. For how Google processes data, see Google's privacy policy.

The legal basis is Art. 6(1)(b) GDPR: we need these details to provide the account you create.

To protect sign-in against automated attacks, we count sign-in attempts per IP address. For this we store not the IP address itself but only a check value formed with a secret key, and delete the count after 30 minutes at the latest. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the security of the accounts.

6. Your account and what you save

When you sign in, we store your email address, your name, your Google identifier, and when the account was created and last changed. Your account applies to the websites of Divyanand Spiritual Foundation in Germany, India and the USA; saved content stays with the website on which you saved it.

For signed-in users we store listening progress and saved satsangs and passages, so that you can resume playback and find content again; we also show you a verse of the day of your own, for which nothing additional is stored. The legal basis is Art. 6(1)(b) GDPR. We do not analyse your listening and take no automated decisions.

The data remains stored until you remove it yourself or ask for your account to be deleted. When your account is deleted, we delete it together with its content and end active sessions on all three websites. A message to info@dsf-germany.org is enough.

7. Contact by email or telephone

When you contact us by email or telephone, we process your details to answer your enquiry. The legal basis is Art. 6(1)(f) GDPR, and Art. 6(1)(b) GDPR for enquiries about your account. We delete the details once your enquiry is settled, unless statutory retention obligations apply.

8. Recipients

The website, the database and the server logs are held by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, which processes this data on our behalf and on our instructions under a data processing agreement (Art. 28 GDPR). The servers are in Germany. Google is also involved in signing in, as described above. Beyond that, we pass your data on to no one.

Apart from signing in with Google, we transfer no data to countries outside the European Union or the European Economic Area.

9. Your rights

You have the right of access to the data we hold about you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20). A message to us is enough.

Right to object: where we process data on the basis of Art. 6(1)(f) GDPR, you may object to that processing at any time on grounds relating to your particular situation (Art. 21 GDPR).

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany, www.baden-wuerttemberg.datenschutz.de.

10. Whether you must provide data

You are under no legal or contractual obligation to provide data. Without the connection data your browser sends, the website cannot be delivered. The website can be used without signing in; we then process only the connection data described above.

11. Security

Every connection to this website is encrypted (TLS). Access to the stored data is limited to the people who maintain the website.

12. Changes

We update this privacy notice when the website or the law changes. The version published here applies.