Privacy Policy
(Effective as of October 6, 2025 – replaces all previous versions)
1. Data Controller
Rebuilding Syria Platform / 2x Next UG (haftungsbeschränkt)
Managing Director: Maher Daboul
Fössestraße 38, 30451 Hannover, Germany
Tel.: +49 155 606 222 00
E-Mail: info@rebuilding-syria.com
2. Hosting & Content Delivery Network
This website is hosted by Webflow Inc., 398 11th St, San Francisco, CA 94103, USA.
Webflow uses global CDNs such as AWS CloudFront and Fastly to ensure fast and secure content delivery.
In doing so, personal data (e.g., IP addresses in server logs) may be transferred to servers in the United States.
Webflow relies on the EU Commission’s Standard Contractual Clauses and, for certified companies, the EU-US Data Privacy Framework to safeguard data transfers.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing a secure and efficient website).
3. Server Log Files
When you visit our website, Webflow automatically stores technical information, including:
- IP address (anonymized after 24 hours)
- Date and time of access
- Requested URL
- Referrer URL
- Browser and device information
These logs are used solely to ensure the technical operation of the website and are deleted after a maximum of 30 days.
4. Cookies & Consent
We only use technically necessary cookies, such as:
- Session cookies from Webflow
- Authentication and language cookies from Outseta (for login and localization purposes)
No analytics, marketing, or tracking cookies are used.
Therefore, no cookie consent banner is required under §25(2) No. 2 TTDSG.
If additional or optional cookies are introduced in the future, we will obtain explicit consent beforehand.
5. User Accounts & Authentication (Outseta)
We use Outseta Inc., Dover, New Hampshire, USA to manage user registrations, logins, and membership accounts.
Outseta stores only the information necessary to create and maintain user accounts (e.g., name, email address, password hash).
Session cookies are used to enable login functionality and expire automatically upon logout.
Data transfers to the United States are safeguarded by Standard Contractual Clauses under Art. 46(2)(c) GDPR.
Data Processing Agreement with Outseta
Rebuilding Syria operates under a formal Data Processing Agreement (DPA) with Outseta LLC, ensuring full compliance with the EU General Data Protection Regulation (GDPR).
Under this DPA, Outseta acts as a certified Data Processor and is committed to protecting user data, maintaining strict confidentiality, and processing information only in accordance with our documented instructions.
The agreement outlines Outseta’s security measures, breach notification procedures, and obligations related to user rights and data deletion.
You can review the full Outseta Data Processing Agreement here:
https://drive.google.com/file/d/1zMMTmpW7vTkm0flIvrVPf_3Q7AXKMbEY/view?usp=sharing
For more information on Outseta’s privacy practices, please refer to their official Privacy Policy:
https://www.outseta.com/privacy-policy
6. Contact Forms
Mandatory fields: name/company, email address, and message.
Submitted data are transmitted securely via Webflow, temporarily stored, and then forwarded to us through Outseta or email.
Purpose: Processing your inquiry
Legal basis: Art. 6(1)(b) GDPR (pre-contractual communication)
Retention period: Data are deleted no later than six months after the inquiry has been resolved.
6a. Newsletter (Outseta Email Lists)
If you subscribe to our newsletter, we use the integrated email service provided by Outseta Inc., Dover, NH, USA.
Your name and email address are stored to send you updates about projects, partnerships, and platform activities.
Subscription is handled through a double opt-in process to confirm your consent.
You may unsubscribe at any time by clicking the unsubscribe link in any email.
After unsubscribing, your data will be deleted within 30 days.
Legal basis: Art. 6(1)(a) GDPR (consent).
6b. Data Processing via n8n & Airtable
Form submissions on the Rebuilding Syria platform are securely transferred through n8n.io, an automation service hosted within the European Union, to Airtable Inc., 799 Market Street, San Francisco, CA 94103, USA, where they are organized and stored for internal use.
This process ensures efficient handling of registration and partnership requests.
Data transfers to Airtable are protected by the EU Standard Contractual Clauses to ensure GDPR compliance.
Legal basis: Art. 6(1)(b) GDPR (performance of pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in efficient data management).
7. Interactive Maps (Mapbox)
We use Mapbox Inc., 740 15th Street NW, Washington, D.C. 20005, USA to display interactive maps.
When you access a map, your browser connects to Mapbox servers and transmits technical data (e.g., IP address, browser type, geographic region).
This data is used solely to provide and display the map properly.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a visually appealing presentation).
More information: https://www.mapbox.com/legal/privacy
8. Google Search Console
We use Google Search Console to monitor and improve our website’s visibility in Google search results.
No tracking code is embedded, and no personal data are collected or stored.
Google only receives aggregated performance data for the domain, without personal identifiers.
9. Rights of Data Subjects
RightDescriptionAccess (Art. 15)Obtain confirmation and a copy of your personal data being processed.Rectification (Art. 16)Request correction of inaccurate or incomplete data.Erasure (Art. 17)Request deletion (“right to be forgotten”).Restriction (Art. 18)Limit processing to specific purposes.Data Portability (Art. 20)Receive your data in a machine-readable format.Objection (Art. 21)Object to processing based on legitimate interests.
You also have the right to file a complaint with a data protection supervisory authority.
10. Data Processing Agreements
Data processing agreements under Art. 28 GDPR are in place with Webflow, Outseta, n8n, and Airtable.
11. Data Protection Officer
Our organization employs fewer than 20 individuals who regularly handle automated data processing.
According to §38 BDSG, we are therefore not required to appoint a Data Protection Officer.
12. Updates & Amendments
This privacy policy is effective as of October 6, 2025.
We may update this policy to reflect technical developments or changes in legal requirements.
The current version is always available at:
https://www.rebuilding-syria.com/privacy-policy