Last updated: September 17, 2026
1. Who is responsible
Pulse Ministries gemeinnützige GmbH
Am Pfarracker 23, 64395 Brensbach, Germany
Represented by the managing director Andreas Fronius
Amtsgericht Darmstadt, HRB 109816
Email: team@thepulse.org
We are the controller within the meaning of the General Data Protection Regulation (GDPR) for all language versions of thepulse.org. We are not required to appoint a data protection officer; we answer your questions about data protection directly at the address above.
2. Hosting, server logs and protection against attacks
The website and our dashboard are operated for us by Magic Pages (Jannis Fedoruk-Betschki, Wiesingerstraße 2, 4820 Bad Ischl, Austria) on servers of Hetzner Online GmbH in Germany. Magic Pages works as a processor under Art. 28 GDPR on our instructions; all data is stored in the EU, the disks are encrypted, backups are made daily, stored encrypted and deleted after three months. When you open a page, the server automatically processes: IP address, date and time, the address requested, the amount of data transferred, the page you came from, and your browser and operating system. These server logs serve only the secure and smooth operation of the site, are not combined with other data and are kept only as long as necessary for that purpose. The legal basis is our legitimate interest in secure operation (Art. 6 (1) (f) GDPR).
In front of the website sits the network of Cloudflare, Inc., 101 Townsend St, San Francisco, USA, as protection against attacks and for faster delivery. In doing so, Cloudflare sees your IP address and technical connection data. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, the EU standard contractual clauses apply. More in the Cloudflare privacy policy. The legal basis is our legitimate interest in security and availability (Art. 6 (1) (f) GDPR).
3. Cookies and browser storage
We only set what the site needs to work. Details are in our cookie policy. In brief:
- Necessary: a login cookie when you sign in as a member (“ghost-members-ssr”), and a cookie that stores your decision in the cookie notice (“cc_cookie”, six months).
- Browser storage (not a cookie): your saved items in the finder, a cache of the finder data for ten minutes, the page through which you came to sign up, and a random session ID for our visitor statistics (section 4). Saved items, cache and origin page stay in your browser; we store the origin page only if you sign up, as a signup statistic.
- No analytics or marketing cookies. Our audience measurement works without cookies (section 4).
You can reopen the cookie notice at any time via the “Cookies” link in the footer and change your choice. The legal basis for necessary cookies is § 25 (2) of the German TDDDG in conjunction with Art. 6 (1) (f) GDPR.
4. Visitor statistics
To see which posts are read, we use the statistics built into Ghost. When you open a page, your browser sends to our own server: the page requested, the page you came from, browser type, language, the country derived from your browser’s time zone, whether you are signed in as a member, and a random session ID that your browser stores temporarily. No cookies are set for this, and your IP address is not stored. Our server forwards this data to an analytics instance (Tinybird) that Magic Pages operates for us on its own servers at Hetzner in Germany; no external analytics service is involved. We only see totals: page views, countries of origin, device types, referrers, and whether readers are members. The legal basis is our legitimate interest in improving our service (Art. 6 (1) (f) GDPR).
5. Free membership and newsletter
Pulse runs on the Ghost platform. When you sign up, we create a free member account. For this we store your email address, your name if you choose to give it, the newsletters you selected, the time of signup and the page through which you signed up. There is no password: to sign in, you receive a link by email. By clicking this link you confirm that the address belongs to you.
With your signup you receive the newsletter you selected, usually “Pulse” with new posts. Every newsletter contains an unsubscribe link; you can also change your selection at any time under “Newsletter settings” or have your account deleted entirely.
We can see whether an email was opened and which link was clicked. We use this only to learn which content is helpful, not for advertising. At the end of every email you can also tell us with one click whether it helped you.
We send the emails through the service Mailgun (Mailgun Technologies, Inc., a Sinch company), which processes and stores the messages in the EU; the processing is based on a data processing agreement and the EU standard contractual clauses.
The legal basis is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time with effect for the future. Your data remains stored as long as your account exists. After you unsubscribe, we keep your address on a suppression list so that you don’t receive any more emails; on request we delete it completely.
6. Contact form and email
Through the contact form, your name, email address and message are sent to us. The form runs on our own system (dashboard.thepulse.org, also hosted by Magic Pages on servers in Germany). We use your details only to answer your request and delete them as soon as the matter is settled and no statutory retention period applies, at the latest after twelve months. The same applies to emails you send us. The legal basis is the handling of your request (Art. 6 (1) (b) GDPR) and our legitimate interest in communication (Art. 6 (1) (f) GDPR).
7. Comments
As a member you can comment on posts. Your name and your comment are published; your email address stays internal. We reserve the right to moderate and delete comments that violate our terms of use. The legal basis is your consent given by submitting (Art. 6 (1) (a) GDPR). Comments remain until you delete them or your account is deleted.
8. Reviews
Reviews are testimonials that readers send us through our form. We store the details you provide there (name, rating, text and the information about yourself that you add voluntarily) on our own system (dashboard.thepulse.org) and show the testimonial on the website and in newsletters as you approved it. You can have your testimonial changed or removed at any time via team@thepulse.org. The legal basis is your consent (Art. 6 (1) (a) GDPR).
9. Live trainings
You register for live trainings through our newsletter “Pulse Trainings”; participation runs through Zoom (Zoom Video Communications, Inc., San Jose, USA, with EU standard contractual clauses and certification under the EU-US Data Privacy Framework). When you join, Zoom sees your name, email address, IP address and device data; the Zoom privacy statement applies. We record the input and make it available as a replay; we say so at the start. Participants are not seen or heard in the recording unless they turn on their camera or microphone themselves. The legal basis is the delivery of the training (Art. 6 (1) (b) GDPR).
10. Embedded content
Some posts contain videos from YouTube (Google Ireland Limited, Dublin) or Vimeo (Vimeo.com, Inc., New York) as well as images loaded directly from Unsplash. When you open such a page, your browser connects to these providers, which see your IP address and, in the case of YouTube and Vimeo, may set their own cookies. We have no control over this. We load the scripts for signup and the announcement bar through the content delivery network jsDelivr (Prospect One, Kraków, Poland), which also sees your IP address. The legal basis is our legitimate interest in an appealing and working presentation (Art. 6 (1) (f) GDPR). For YouTube, the Google privacy policy applies; for Vimeo, the Vimeo privacy policy.
11. Support and donations
We do not process any payment data on our website itself. Those who support Pulse transfer money to Vereinigte Deutsche Missionshilfe e. V. (VDM) or use its donation page; the VDM privacy policy applies. The VDM informs us of a donation with name and amount so that we can say thank you.
12. Links to social networks
In the footer we link to our profiles. These are plain links, not embedded plugins: when you open our site, no data is transferred to these networks. Only when you click a link do the rules of the respective provider apply.
13. Your rights
You have the right of access to the data stored about you (Art. 15 GDPR), to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing that we base on a legitimate interest (Art. 21). You can withdraw any consent you have given at any time; the lawfulness of the processing carried out until then remains unaffected. Write to us at team@thepulse.org.
If you believe that we are not processing your data lawfully, you can lodge a complaint with a supervisory authority. The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, datenschutz.hessen.de. You can also contact the authority where you live.
14. Data security
All connections to our website are encrypted (TLS). Only the people on the team who need it for their work have access to member data. We pass data on only to the service providers named in this policy and only as far as necessary for the respective purpose. Data is never passed on to third parties for advertising purposes.
15. Children and young people
Pulse is aimed at adults who walk alongside young people. We do not knowingly collect data from persons under 16. If we become aware of it, we delete the data.
16. Changes
We adapt this policy when our website or the legal situation changes. The version published here applies.
