Legal information
Privacy policy
Last updated: September 2026
1. Controller
2. Data we process
When you access the website, the server processes technically necessary connection data, in particular the IP address, time, requested page, transferred data volume, browser and system information. Registration stores your display name, email address, password in hashed form, home region, experience level, profile description and email-confirmation status. You may also voluntarily store a profile picture, tours, locations, times, tour partners, reports, photos, GPS tracks, visibility settings, mountain-friend connections and notice-board posts.
3. Purposes and legal bases
Account data and voluntarily submitted content are processed to provide the tour log, selected sharing options and community functions (Article 6(1)(b) GDPR). Technical logs and security measures support stable and secure operation and prevent misuse (Article 6(1)(f) GDPR). Processing required by law is based on Article 6(1)(c) GDPR.
4. Visibility, photos and reports
Profile name, profile picture, home region and experience level may be visible to other visitors. For tours, members choose between “Everyone”, “registered members only”, “mountain friends only” and “private”. Notice-board posts are publicly visible. Mountain-friend requests and connection status are intended only for the members involved. Please do not publish another person’s data without their permission.
For new photo uploads, we record when the uploading member confirmed their authorisation and, where applicable, the consent of identifiable people. When a photo is reported, the photo, reason, explanation, name and email address of the reporting person, and processing status are stored. This information is used solely to review and handle possible infringements.
5. Session and cookies
The application uses only a technically necessary session cookie for login, language selection and form protection. No advertising, analytics or tracking cookies are used.
6. OpenStreetMap maps
When a map is displayed, the browser loads map tiles from the OpenStreetMap Foundation. In particular, your IP address, browser information, referrer, time and requested tiles are transmitted to the OpenStreetMap Foundation. Map servers may be located in the United Kingdom and the Netherlands, among other places. OpenStreetMap Foundation privacy policy.
7. Google Photos
The connection to Google Photos is made only when a signed-in member explicitly starts this function. Google handles sign-in and image selection. Bergerlebnisse temporarily receives the permission required for the selection and downloads only the images expressly selected. They are reduced in size and then stored as tour photos. Google is responsible for processing within the Google account. Google Privacy Policy.
8. Email delivery and hosting
Confirmation messages are sent through the operator’s mail server. The website and its database are operated on a commissioned server. The hosting provider processes technical data as a processor where necessary for provision, maintenance and security.
9. Retention
Account data and stored content are generally retained until deleted by the member or until a deletion request is made, unless legal obligations require otherwise. Email confirmation links are valid for 24 hours. Notice-board posts are hidden after the planned date or, without a date, after 90 days; authors may remove them earlier. Photo-report information is retained until review is complete and thereafter only as long as necessary to document the handling of the report or defend legal claims. Security and server logs are retained only as long as necessary for operation, troubleshooting and prevention of misuse.
10. Your rights
Subject to the GDPR, you have rights including access, rectification, erasure, restriction of processing, data portability and objection. Consent may be withdrawn with effect for the future. Requests can be sent to the email address above.
You also have the right to lodge a complaint with a data-protection supervisory authority. The Bavarian State Office for Data Protection Supervision (BayLDA) is generally responsible for non-public bodies in Bavaria. www.lda.bayern.de.