Privacy policy
This English version is provided for your convenience. In case of any discrepancy, the German version is legally binding.
1. Controller
Marco Kälz
Am Rasen 1
37441 Bad Sachsa
Germany
Email: info@funktech.de
2. Summary
- No advertising, no tracking, no analytics or marketing services.
- Only technically necessary cookies are used; therefore no consent banner is required.
- No external fonts, scripts or content from third-party servers are loaded into your browser.
- Email address, name, credentials for third-party services, station data, uploaded images, profile details, messages and names, places, addresses and remarks in the logbook are stored encrypted (XChaCha20-Poly1305). Passwords are stored only as an Argon2id hash.
- You can export your data and delete your account with all data yourself at any time.
3. Hosting and server logs
The application is hosted by:
[Hosting-Anbieter (Name, Anschrift) – in der Verwaltung eintragen]
When pages are accessed, the web server processes technically necessary data (IP address, time, requested page, browser identification). The legal basis is Art. 6 (1) (f) GDPR (secure operation). A data processing agreement pursuant to Art. 28 GDPR has been concluded with the hosting provider. The retention period of server logs is determined by the hosting provider.
4. Cookies and browser storage
We only use technically necessary cookies (§ 25 (2) no. 2 TDDDG, Art. 6 (1) (f) GDPR). No consent is required for this. There are no analytics, marketing or third-party cookies and no permanent storage in the browser (local storage).
- Session cookie (“__Host-funklog” or “funklog”): contains only a random identifier, keeps you signed in and protects forms against cross-site requests. Valid until you close the browser or sign out; after 60 minutes of inactivity you are signed out automatically.
- Notice cookie (“fl_hinweis”): remembers that you have read the cookie notice. Content “1”, lifetime 12 months.
- Device cookie (“fl_geraet”, only after signing in): a random identifier so that we can warn you when someone signs in to your account from a new device. The server only stores an irreversible hash. Lifetime 400 days.
- Session storage (“sessionStorage”, only for signed-in members): remembers the scroll position, expanded sections and unsent text drafts in the current browser tab. The data does not leave your browser and is deleted when you close the tab or sign out. If your session expires while you are writing, unsent drafts are kept and only shown again to the same member after signing in.
5. Registration and user account
For the account we process your email address, password (only as a hash), optionally callsign or radio name and name, as well as the time of acceptance of the terms of use. To confirm, you receive an email with a link. The legal basis is Art. 6 (1) (b) GDPR (contract of use). Unconfirmed registrations are deleted automatically after 7 days.
Depending on the operator's setting, your account is activated automatically once your email address is confirmed, or manually by the team. With manual activation, authorised team members see your email address, your callsign or radio name and the time of registration; you are informed by email when your account is activated. Before activation we check whether the data is on the block list (see section 6a).
Optionally you can set up two-factor authentication with an authenticator app. The required secret is stored encrypted; the QR code is generated exclusively in your browser.
6. Protection against misuse
To fend off password attacks we store failed sign-in attempts with an irreversible, daily changing hash of the IP address for a maximum of 24 hours. Security-relevant events (sign-in, password change, administrative actions) are logged with a shortened IP address (last block removed) for 90 days. After several failed attempts, sign-in is temporarily blocked (longer with each further block) and you are informed by email; likewise when someone signs in from a new device.
To prevent the use of passwords that have already leaked, we check new passwords and occasionally passwords at sign-in against the “Pwned Passwords” database (Have I Been Pwned, operated via Cloudflare). Neither the password nor a complete hash is transmitted, only the first 5 characters of a SHA-1 hash (k-anonymity); the comparison takes place on our server. The operator can switch this check off. The legal basis is Art. 6 (1) (f) GDPR (protection of accounts).
6a. Moderation, blocking and exclusion from re-registration
To protect the community areas from misuse, moderators and administrators with the “Users” permission can:
- Mute: The member can still read everything but cannot publish posts, messages, ads, photos or profile texts for 24 hours, 7 days, 30 days or indefinitely. We store the end of the mute and the reason (encrypted); both are removed automatically when it expires.
- Lock: Signing in is no longer possible and existing sessions are ended.
- Exclude from re-registration (block list): So that locked or deleted members cannot sign up again with the same data, an entry can be added to the block list. We store only a non-reversible check value (HMAC-SHA-256) of the email address – normalised so that variants such as “name+tag@…” are recognised –, a shortened hint of the address (e.g. “ma*@ex*.de”), the callsign or radio name, the reason (encrypted), the date and the duration. The full email address is not stored for this purpose. Anyone on the block list cannot register again with this data or transfer it to another account; on an attempt, only the owner of the email address receives a notice.
You are informed of a mute or lock by email, stating the reason. All measures are recorded in the administration log (90 days). Block list entries are deleted automatically when the chosen duration (1 or 2 years) ends; indefinite entries as soon as they are no longer necessary – at the latest following your justified objection, unless overriding reasons prevail. You can request information and object to the measure at any time (email to info@funktech.de or, when muted, via “Help & support”).
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in protecting members and orderly operation) and Art. 6 (1) (b) GDPR (enforcement of the terms of use). There is no automated decision: every measure is taken by a human.
7. Logbook data
In the logbook you record radio contacts. These also contain data of your contact partners (e.g. callsign, radio name, first name, place, locator, possibly the address for QSL cards). We process this data exclusively on your behalf and to provide the logbook (Art. 6 (1) (b) GDPR towards you; Art. 6 (1) (f) GDPR towards the contact partners – legitimate interest in documenting contacts as is customary in radio operation and confirming them by QSL card). The data is only visible to your account; administrators have no access to other users' logbooks in the application.
7a. Calendar, news and internal messages
- Calendar: Title, description and location of your appointments are stored encrypted. Only you can see private appointments. With “busy”, other members only see the period and your callsign. With “selected members”, only the people you entered can see the appointment; they are informed by email. All members can see public appointments. For the calendar subscription you receive a secret link that can be renewed at any time. Reminders are sent by email on request.
- News: Published articles show your callsign or first name and are visible to members or publicly depending on the setting. When you delete your account, published articles remain without your name.
- Internal messages: Subject and text are stored encrypted and can only be read by sender and recipient – administrators have no access. Only if you report a message is its content passed on to the administrators. The email notification does not contain the message content; you can switch it off or mute individual members. Messages are deleted as soon as both sides have deleted them, at the latest when one of the two accounts is deleted.
- Blocking: You can block other members. The list of blocked members is only visible to you. Blocked members can no longer send you messages, you receive no notifications triggered by them, and they can no longer see your profile.
- Spam: If you mark a message as spam, further messages from this sender go to your spam folder without an email notification. If several members mark the same sender, the moderators only learn the sender and the number of marks – not the content (Art. 6 (1) (f) GDPR, protection against misuse).
The legal basis in each case is Art. 6 (1) (b) GDPR (provision of the functions you use).
7a2. Member chat and chat bot
In the chat we process your messages (stored encrypted), the time and your callsign or display name. Messages are visible to everyone with access to the respective room. They are deleted automatically after the period set by the operator (default: 30 days); you can delete your own messages at any time. Under “Here now”, others in the room see who was in the chat during the last two minutes – you can switch this off in the chat settings. For each room we store up to which message you have read.
Room access and callsign check: Rooms can be restricted to members with certain identifiers in their profile. If a confirmed amateur radio callsign is required, our server looks up your callsign in the public callsign list of the Bundesnetzagentur (see section 8) and compares the published holder with the name in your profile or account; the name does not have to be shown publicly. The result (callsign, name according to the list, match) is visible only to you and to team members with the “Users” or “Chat” permission. Alternatively you can confirm your callsign via LoTW: on your click our server signs in once with the LoTW credentials you stored; we only store that and when the confirmation took place. If you request access, the moderators see your name, your reason, the identifiers in your profile and the result of the callsign check. The legal basis is Art. 6 (1) (b) and (f) GDPR (protecting rooms against unauthorised access).
Chat bot (automatic moderation): A program on our server checks chat messages for insults, threats, hate speech and spam before they are published. No texts are transferred to other providers. If the bot detects a violation, the message is not published but held back for moderation; repeated violations lead to a temporary chat mute (10 minutes, 1 hour or 24 hours), serious cases are reported to the team. For this we store the incident (time, rule, excerpt of the message – encrypted) for 90 days. From messages deleted by moderation or reported, the bot collects word suggestions that are only used after confirmation by the moderation (unless the operator enables automatic adoption). Further measures (locking, exclusion) are always taken by a human. If you address the bot (e.g. “!hilfe”, “!termine”), it replies in the room with fixed texts, calculations or information from the site; personal replies (e.g. your logbook statistics with “!log”) are only visible to you. Reminders (“!erinnere”) are stored encrypted until due and deleted afterwards. Moderation can release held messages; you can object at any time via “Help & support”.
The legal basis is Art. 6 (1) (b) GDPR (chat) and Art. 6 (1) (f) GDPR (protecting members from insults and misuse).
7a3. QRV spots
If you mark yourself as “QRV”, we show your callsign or display name, radio service, frequency/channel, mode, optionally your locator and your note – depending on the operator's setting for members or also for visitors. Spots expire after the chosen time (at most 4 hours) and are deleted at the latest one day later (Art. 6 (1) (b) GDPR).
7a4. Mutual QSO confirmation
If two members have logged the same contact (the other's callsign or radio name, same service, time ±30 minutes, same band or channel), we mark it as “confirmed by member” for both. Only this mark is set; no further logbook data is shown to the other member. You can switch this off under “My account” (Art. 6 (1) (b) GDPR).
7b. Events and calendar export
If you register for an event, we store your acceptance or cancellation and an optional remark (encrypted). Your callsign or first name is visible to other registered members in the participant list, the remark only to the organiser. The organiser can send emails about the event to all registered participants and download the participant list. You can change your registration at any time; it is removed when the event or your account is deleted.
“Add to my calendar” downloads a calendar file directly from our server. Only if you explicitly click “Google Calendar” or “Outlook” are the title, time, place and description of the appointment passed to the respective provider (Google or Microsoft).
The legal basis is Art. 6 (1) (b) GDPR.
7b2. Member profile
The member profile is voluntary (Art. 6 (1) (a) GDPR). It is hidden by default; you decide yourself whether it is visible to signed-in members or – if the site allows it – also to visitors, and which details (name, place of residence, age, locator) are shown. Of the date of birth, at most the age is shown. Name, place of residence, date of birth and texts are stored encrypted. Photos are reduced in size, stripped of metadata (e.g. GPS position, camera data) and stored encrypted; they are only delivered to people who are allowed to see the profile. Please only upload images to which you hold the rights and to which the people shown have agreed. You can change or completely delete the profile at any time; it is removed automatically when the account is deleted.
7b2a. Station, member map and messages
In the “My station” section you can present your radio equipment with text and up to three photos (same visibility as the profile). You only appear on the member map if you explicitly switch it on (consent, Art. 6 (1) (a) GDPR); only the centre of your locator field (e.g. JO51, about 110 × 185 km) is shown, never your exact position – to everyone allowed to see your profile. You can withdraw consent in your profile at any time.
When writing a message you can search members by callsign, display name or radio name; only members who receive messages and have not blocked you are shown, and the search is not stored. Team members with the corresponding permission can publish announcements to all or to groups of members; we store whether you have read or hidden an announcement. Announcements are deleted after one year. Votes in forum polls are stored per member to prevent double voting; only totals are shown, never who voted for what.
7b3. Forum
For forum posts we process your callsign or display name, the text and the time (Art. 6 (1) (b) GDPR). Posts are visible to everyone allowed to see the forum (operator setting: members only or also visitors). If you subscribe to a topic or a board, you receive emails about new replies or topics; you can unsubscribe in the topic, in the board or under “My account”. For the unread marker we store when you last read a topic. If your session expires while writing, your unsent text is temporarily stored in your server session (at most 6 hours) and inserted again after you sign in. When you delete your account, posts remain without your name so that discussions stay understandable – on request they are deleted as well. Reported posts are checked by the moderators.
7b4. Radio flea market
For ads we process the details you enter, photos (without metadata) and your display name (Art. 6 (1) (b) GDPR). Please do not state your full address; contact is made via internal messages. Ads expire after 60 days and are deleted automatically 90 days after expiry or completion; you can delete them yourself at any time. Watch lists are only visible to you. The operator is not a contracting party to purchases between members.
7b4b. Photo gallery
In albums (e.g. of field days, meetings or regulars' tables) we process the uploaded photos, captions, the date taken and the name of the uploader (Art. 6 (1) (b) and (f) GDPR). Photos are reduced in size, stripped of camera data such as the GPS position and stored encrypted; depending on the album setting they are visible to members or publicly. People recognisable in photos should agree to publication. If you appear in a photo and do not want this, use “Report photo” or write to us – we will remove it immediately (Art. 17, 21 GDPR). When you delete your account, the photos you uploaded are deleted.
7b4a. Support requests
If you submit a support request, we process subject, topic and messages (stored encrypted) to handle your request (Art. 6 (1) (b) GDPR). Only you and team members with the “Support” permission can read them. By email you only receive a notice with a link, not the content. Requests are deleted together with your account.
7b5. Backups
To protect against data loss, encrypted backup copies of the database and the images are created regularly (Art. 6 (1) (f) and Art. 32 GDPR). Only a few backups are kept (by default the last 7); older ones are deleted automatically. Deleted data may therefore still be contained in them until the last backup is overwritten and will only be restored in the event of a recovery.
7c. Mailing list and newsletters
For the mailing list we process your email address (encrypted) on the basis of your consent (Art. 6 (1) (a) GDPR). Registration takes place using the double opt-in procedure: you are only added after clicking the confirmation link. As proof of consent we store the time and the shortened IP address. Unconfirmed registrations are deleted after 7 days. You can withdraw your consent at any time via the link in every newsletter (also via your email program's one-click unsubscribe) or under “My account”; the address is then completely deleted after 30 days. Regardless of this, registered members receive notifications that are necessary for using the service (Art. 6 (1) (b) GDPR). For sending, address and content are briefly stored in a queue and deleted after sending.
7d. Support for the site
If the “Support us” page is active, it contains links to payment services (e.g. PayPal) and possibly bank details. Only when you click such a link do you leave our website; the privacy policy of the respective provider then applies to the payment. We only receive the information customary for the payment from there.
8. Lookups with external services
So that names and places can be completed automatically, our server (not your browser) sends requests to the following services. Only the searched callsign or radio name is transmitted, not your IP address:
- Bundesnetzagentur – public callsign list of the amateur radio service (https://ans.bundesnetzagentur.de). To relieve the service, results are cached for up to 90 days (encrypted).
- Hotel November DX Group – publicly accessible member list (hndx.de), loaded weekly.
- RadioID.net (USA) – public DMR ID database.
- HamQTH.com (Czech Republic) and QRZ.com (USA) – only if you store your own account there and the source is switched on in your search settings.
- Country detection from the callsign prefix runs on our server without any external request (country list by AD1C, country-files.com).
You choose which sources are used yourself in the logbook under *Settings › Search & lookups*. The operator can switch off any external service. Results are cached so that the same request is not made several times.
The legal basis is Art. 6 (1) (f) GDPR (completion of logbook entries from publicly accessible directories).
9. Online logbooks (eQSL, LoTW, QRZ.com)
Only if you store credentials in your account and start a sync does our server transmit your amateur radio contacts to eQSL.cc or QRZ.com and retrieve confirmations from eQSL.cc, LoTW (ARRL) and QRZ.com. These providers are based in the USA. The transfer takes place at your express request to fulfil the service you want (Art. 6 (1) (b), Art. 49 (1) (b) GDPR). The privacy policies of these providers also apply. Your credentials are kept in your personal vault: they are additionally encrypted with a key derived from your login password (Argon2id) that is only available during your signed-in session. Without your password nobody – not even the operator – can read them, not even from a backup. They are used exclusively for syncs and lookups you trigger, never displayed and not exported; every use is logged in your security log. If you reset your password via “Forgot password”, they are deleted. You can delete them yourself at any time.
10. Sending emails
For confirmation and password emails we use the mail server of our hosting provider. Email address and message content are processed (Art. 6 (1) (b) GDPR).
11. Retention period
We store account data and logbook until you delete your account. On deletion, all associated data including uploaded images is removed immediately and permanently (database pages and image files are overwritten). The only exception is any block list entry (section 6a), which remains for the duration stated there. Backups of the hosting provider are overwritten on a regular basis.
12. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). You can carry out export and deletion yourself under “My account”. For anything else an email to info@funktech.de is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
https://www.lfd.niedersachsen.de
13. No automated decisions
There is no automated decision-making, including profiling. Technical protective measures (e.g. a temporary sign-in lock after failed attempts, the spam folder, a short chat mute by the chat bot) only apply temporarily or only for you and can be lifted by moderation; measures such as muting, locking or the block list are always taken by a human.
Last updated: 08.10.2026