privacy policy | Datenschutz

Privacy Notice
Creative Space

lovrika gUG (haftungsbeschränkt

(OPERATIONAL DRAFT)

Purpose. Part A is written as website publication text. Part B is an internal launch and legal-review checklist and must not be published with the privacy notice.

Prepared: 4 August 2026

Controller: lovrika gUG (haftungsbeschränkt), Hamburg

Public-facing initiative: Creative Space

Legal status: Operational draft pending final review by a German data-protection lawyer

This draft intentionally contains no private telephone number or private email address. Until a business contact address is activated, privacy requests are directed to the company’s postal address.

The draft reflects the tools and practices confirmed as at the preparation date. It must be updated before any material new tool, application form, CRM, youth programme, tracking tag, advertising pixel, AI transcription service, or additional data use is introduced.

CREATIVE SPACE | PRIVACY NOTICE

Privacy Notice for Creative Space

Last updated: 4 August 2026

This Privacy Notice explains how lovrika gUG (haftungsbeschränkt), operating publicly as Creative Space, processes personal data in connection with the Creative Space website, online community, memberships, donations, newsletters, events, workshops and related activities. It also explains the choices and rights available to individuals under the General Data Protection Regulation (GDPR) and other applicable data-protection law.

1. Controller and contact

The controller responsible for the processing described in this Notice is:

lovrika gUG (haftungsbeschränkt)
Creative Space
Billgrabendeich 15
c/o Ruth Nelson-Andorf
21035 Hamburg
Germany
Registered with Amtsgericht Hamburg, HRB 200615
Managing Director: Ruth Nelson-Andorf

Until a dedicated business email address is activated, please send privacy enquiries or requests by post to the address above. No telephone contact is offered for privacy matters at present. Electronic contact details will be added when a business address is available.

2. Data Protection Officer

lovrika gUG (haftungsbeschränkt) has not appointed a formal Data Protection Officer. Privacy enquiries should be directed to the controller using the contact details above.

3. Scope and basic principles

We process only personal data that is necessary for defined purposes. Depending on the activity, processing is based on one or more of the following legal bases:

Article 6(1)(b) GDPR, where processing is necessary to take steps at your request or to perform a membership, event or other contract;

Article 6(1)(c) GDPR, where processing is necessary to comply with a legal obligation, including accounting and tax duties;

Article 6(1)(f) GDPR, where processing is necessary for a legitimate interest such as secure website operation, answering enquiries, administering the community, preventing misuse or maintaining useful community discussions, and those interests are not overridden by your rights;

Article 6(1)(a) GDPR, where you have given consent, including for newsletters, optional cookies, recordings, public stories, testimonials or photographs; and

Section 25 TDDDG, where consent or an exception is required for storing information on, or accessing information from, your device.

Where providing data is required to conclude or perform a contract, we identify the relevant fields as required. Other profile, onboarding, event and feedback information is voluntary. If required data is not provided, the relevant service may not be available.

4. Website hosting and technical access data

4.1 Squarespace hosting

The public website is hosted and operated using Squarespace. The service provider is Squarespace Ireland Limited, Le Pole House, Ship Street Great, Dublin 8, Ireland, together with affiliated service providers including Squarespace, Inc. in the United States where applicable.

When you access the website, Squarespace may process technical data such as IP address, date and time of access, requested page, referrer URL, browser and operating-system information, device information, language settings, security events and similar log data. This processing is necessary to deliver the website, maintain security, prevent misuse and diagnose errors. The legal basis is Article 6(1)(f) GDPR. Essential access to information on your device is based on Section 25(2) TDDDG where applicable.

Squarespace may process data outside the European Economic Area. Transfers are addressed through the safeguards described in Squarespace’s Data Processing Addendum, including relevant Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

4.2 Activity log and server records

Squarespace provides administrators with a limited activity log showing recent visits and associated technical information. We use this only for website operation, security, troubleshooting and aggregated understanding of website use. Squarespace currently makes the activity log available to us for seven days. Other provider-controlled security and infrastructure logs are retained according to Squarespace’s documented retention rules and legal obligations.

5. Cookies and consent management

The website uses technically necessary cookies and similar technologies so that pages, forms, consent choices and checkout functions work securely. Necessary technologies are used on the basis of Article 6(1)(f) GDPR and Section 25(2) TDDDG where applicable.

Analytics, embedded media and other non-essential technologies are used only after consent where consent is required. The Squarespace cookie banner provides separate options to accept or reject non-essential cookies. Consent is voluntary and may be withdrawn for the future by reopening the cookie settings where available, or by clearing this site’s cookies and revisiting the site. Withholding or withdrawing consent does not affect essential website use, although optional media or features may be unavailable.

6. Website analytics

6.1 Squarespace Analytics

We use Squarespace Analytics to understand, in aggregated form, how visitors find and use the website and to improve its content. Depending on consent and configuration, Squarespace Analytics may process page views, visits, approximate location, referrer, device and browser information and unique browser identifiers. Squarespace uses cookies to distinguish unique visitors and browsing sessions.

Where analytics cookies or similar device access are used, the legal bases are your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may reject or withdraw consent as described above.

6.2 Google Analytics 4

With your consent, the website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with possible processing by Google LLC and other affiliates outside the European Economic Area.

Google Analytics may process information about website and app interactions, pages viewed, approximate location, device and browser characteristics, referrer information, consent status and pseudonymous identifiers. Google states that for users in the EU, EEA, Switzerland and the United Kingdom, individual IP addresses are used for coarse geolocation and discarded before logging.

Google Analytics is activated only after analytics consent. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. Google acts as a processor for Google Analytics under its data-processing terms. International transfers are protected using applicable contractual and statutory transfer mechanisms. You may withdraw consent through the site’s cookie controls or use Google’s browser opt-out tools.

7. Contact and other website forms

When you contact us or submit a Squarespace form, we process the information you enter, such as your name, email address, organisation, subject, message and any other information you choose to provide. Squarespace stores form submissions and makes them available to authorised site administrators.

We use the data to answer the enquiry and manage any requested follow-up. The legal basis is Article 6(1)(b) GDPR where the enquiry concerns a contract or pre-contractual steps, and otherwise Article 6(1)(f) GDPR based on our legitimate interest in responding to enquiries. Optional information is processed on the basis of your voluntary submission and, where specifically requested, consent.

We normally delete routine contact enquiries within twelve months after the matter is closed, unless the information is needed for an ongoing relationship, legal obligation or the establishment, exercise or defence of legal claims.

8. Newsletter subscription forms and communications

A person is added to a Creative Space mailing list only after a separate, explicit subscription. Membership, a donation, an event registration or a general enquiry does not by itself constitute newsletter consent.

For the newsletter subscription form on the Squarespace website, Squarespace processes the email address and subscription record on our behalf. We use the information to send the content described at the point of subscription, including Creative Space news, SDG- and IDG-related information, events, opportunities to support our work and invitations to join or contribute to the community. The legal basis is Article 6(1)(a) GDPR. Subscribers may unsubscribe at any time using the link in a message or the relevant subscription settings.

Where a person separately subscribes through Substack, Substack, Inc. processes subscription, account, device, usage and communication data. Substack acts partly as our processor for publication data and partly as an independent controller for its own platform purposes, as explained in its privacy policy. A Squarespace subscription, a Substack subscription and Circle community communications are separate choices and are not automatically combined.

We retain active subscription data until unsubscribe or withdrawal of consent. We may retain a minimal suppression record after unsubscribe where necessary to ensure that no further marketing is sent and to demonstrate compliance. Service, security and membership administration messages that are necessary to operate an account or contract may still be sent independently of newsletter consent.

9. Embedded videos and external media

Some pages may contain videos or other media embedded from an external provider, including YouTube where indicated. Loading or playing such content may transmit IP address, page URL, browser and device information, cookie identifiers, interaction data and, if you are logged in to the provider, account-related information to that provider.

External video content is treated as non-essential and should be blocked until media consent where technically required. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. If you do not consent, the media may not load. The provider’s own privacy policy applies to its independent processing after the connection is established.

10. Spam and abuse protection

Squarespace may use Google reCAPTCHA Enterprise or comparable automated anti-abuse measures when a visitor submits a protected form. Such services may process IP address, device and browser data, interaction patterns, security signals and the page from which the request was made in order to distinguish legitimate submissions from automated misuse. Donation CAPTCHA is not currently enabled.

The purpose is to protect forms and systems from spam, fraud and technical abuse. The legal basis is Article 6(1)(f) GDPR and, where the technology is strictly necessary for the requested form and security function, Section 25(2) TDDDG; consent is obtained where required by the technology’s actual configuration. Google’s privacy terms also apply to its independent processing.

11. Links to social networks and external websites

The website contains ordinary links to external services such as LinkedIn and Substack. A normal link does not create an advertising or analytics tag on our website. Data is transmitted to the external service only when you choose to follow the link, at which point the external provider is responsible for its own processing. We do not currently use the LinkedIn Insight Tag, Meta Pixel or another advertising pixel. A LinkedIn profile link is not a LinkedIn Insight Tag.

12. Creative Space community on Circle

12.1 Roles of lovrika and Circle

The Creative Space member community is hosted on Circle. CircleCo, Inc., 228 Park Ave S, PMB 52933, New York, NY 10003, USA, generally processes community data as a processor on our instructions under its Data Processing Addendum. Circle also processes certain account, usage, feedback, security and service data for its own purposes as an independent controller, as described in Circle’s privacy notices.

Circle’s privacy notice does not replace this Notice. Circle expressly states that data processed inside an individual community is governed by the community owner’s privacy notice. International transfers are addressed through Circle’s Data Processing Addendum and the EU Standard Contractual Clauses, including controller-to-processor Module Two.

12.2 Registration, membership and account data

There is currently no separate membership application form. When a person creates or activates a Circle account and membership, we and Circle may process name, email address, password or authentication data, membership plan and status, account identifiers, notification preferences, profile information, security and access data, technical usage information and transaction metadata. Required account and membership data is processed under Article 6(1)(b) GDPR. Security, moderation and platform administration are also based on Article 6(1)(f) GDPR.

Membership is available only to adults aged 18 or over. We do not knowingly create community accounts for minors.

12.3 Member profiles and introductions

Members may voluntarily complete a profile and introduction so that other members can find and understand their work. Depending on what a member chooses to add, this may include a name, photograph, professional role, organisation or business, location, biography, skills, interests, Sustainable Development Goal focus, website and social links, asks, offers and collaboration interests.

Profile information and introductions are visible to other authorised community members according to the relevant space and profile settings. Members choose how much optional information to provide and may edit or remove it through their account where the platform permits.

12.4 Posts, comments, direct messages and files

Circle processes content that members create or share, including posts, comments, reactions, direct messages, event interactions, images, videos, audio, links and uploaded files. This content is processed to provide the community, facilitate connection and collaboration, moderate the space and enforce community rules. The legal bases are Article 6(1)(b) and Article 6(1)(f) GDPR.

Content is visible to the members who have access to the relevant space or conversation. Other members may download presentations, images and other files that a member intentionally shares. Members should upload only material they are entitled to share and should understand that copies downloaded by other members cannot always be recalled or technically deleted by lovrika.

12.5 Voluntary onboarding, event and workshop forms

We may use voluntary forms within Circle to understand a member’s onboarding needs, interests, event preferences, feedback or workshop goals. Completion is optional, although providing relevant information may help a member participate fully. We do not ask for medical, mental-health, disability or other special-category information in these forms. The legal basis is Article 6(1)(b), Article 6(1)(f) or, where specifically requested, Article 6(1)(a) GDPR.

12.6 Notifications, broadcasts and marketing

Circle sends account, access, security, event and community notifications that are necessary to operate the service or that the member selects through notification preferences. Members may adjust available notification settings. Promotional or movement-building broadcasts from Creative Space are sent only where an appropriate consent or other lawful basis exists, and recipients may unsubscribe from marketing without ending their membership. Ending marketing messages does not prevent necessary contractual or service communications.

12.7 End of membership and deletion

When paid or granted access ends, a workflow may remove the member from paid access groups and spaces and deactivate the account. Deactivation removes access and hides the profile, but Circle does not automatically delete the member’s posts, comments, direct messages or uploaded files. These items may remain in the community unless the member deletes them before departure where possible, or requests erasure from lovrika.

A full Circle account and content deletion must currently be carried out manually by an administrator. If you want your account and associated content permanently deleted, please contact lovrika before or after membership ends. We will assess and action a valid erasure request in accordance with Article 17 GDPR. Certain data or content may be retained where necessary to comply with law, resolve disputes, establish or defend legal claims, protect other people’s rights, or preserve a community discussion where retention is justified and proportionate. Where possible, retained contributions will be anonymised or separated from the former member’s profile.

12.8 Special-category and highly sensitive data

Creative Space supports reflective conversations about sustainable work, confidence, wellbeing and the realities of changemaking. However, Circle’s Data Processing Addendum treats GDPR Article 9 special-category data as prohibited customer data. Members must therefore not upload, post, store or intentionally transmit medical diagnoses, detailed mental-health or disability information, biometric data, political opinions, religious or philosophical beliefs, trade-union membership, sexual-life or sexual-orientation data, racial or ethnic origin, genetic data, government identification numbers or similar highly sensitive material through Circle.

We do not ask members to disclose such information. If sensitive information is disclosed unexpectedly, we do not document or record it and will take reasonable steps to minimise or remove it. General discussion of wellbeing is not intended to create a health record or provide medical services. A suitable alternative process and provider must be agreed before any programme intentionally collects special-category data.

13. Membership payments through Circle and Stripe

Paid memberships are offered through Circle’s checkout using Stripe. Depending on the selected payment method, the checkout may process email address, name, country, billing address, optional business name, membership plan and cadence, transaction amount and currency, payment status, Stripe customer or transaction identifiers, payment method tokens and limited card metadata such as brand and last four digits. Card numbers and security codes are entered directly into Stripe-controlled payment fields and are not stored by lovrika.

The processing is necessary to establish and perform the membership contract under Article 6(1)(b) GDPR and to meet accounting and tax obligations under Article 6(1)(c) GDPR. Fraud prevention and payment security may also be based on legitimate interests under Article 6(1)(f) GDPR. Stripe may act as a processor for payment services and as an independent controller where it processes data for its own regulatory, fraud-prevention and legal obligations. Circle receives and stores transaction and billing metadata required to administer access, invoices and support.

14. Website donations, Squarespace, Stripe and Qonto

Donations made through the website are initiated through a Squarespace donation block and processed financially through Stripe. Squarespace operates the checkout, creates a donor profile and transaction record, makes donation details available to authorised administrators and sends an automated donation confirmation email. Stripe processes the payment credentials and payment transaction.

Depending on the donation configuration, we, Squarespace and Stripe may process donor name, email address, telephone number where requested, billing address, donation amount and currency, fund or purpose, recurring donation frequency, fee-cover choice, order number, payment type and status, transaction identifiers, limited payment-method metadata and any information voluntarily entered into a donation or checkout form.

The legal bases are Article 6(1)(b) GDPR for carrying out the donation and any recurring instruction, Article 6(1)(c) GDPR for accounting and tax duties, and Article 6(1)(f) GDPR for fraud prevention, payment support and administration. A separate mailing-list subscription at checkout is optional and based on Article 6(1)(a) GDPR.

Qonto is used as lovrika’s business bank account. There is currently no direct website-to-Qonto integration. Qonto receives settlement and banking information arising from payment transfers and processes it under banking, contractual and statutory obligations. Qonto does not receive full payment-card details from lovrika.

Financial, accounting and donation documentation is retained for the applicable statutory period. Depending on the type of record, German commercial and tax retention obligations may require retention for several years after the transaction or financial year ends.

15. Events, workshops and online meetings

Creative Space events and workshops may be organised through Circle Events and delivered in a Circle live room or through another platform identified in the event information, such as Zoom, Google Meet or Microsoft Teams. Member facilitators may also select an appropriate platform under Creative Space event and workshop guidelines.

We may process registration information, event choice, participant name, contact details, attendance status, accessibility or participation preferences that the person voluntarily provides, chat contributions and technical connection data. The legal basis is Article 6(1)(b) GDPR where participation is contractual, Article 6(1)(f) GDPR for organising and securing the event, or consent where participation or a feature is optional.

The specific platform and its privacy information will be identified with the event where it is not Circle. If a member independently organises an event and determines how participant data is used, that member may be an independent controller and must provide appropriate privacy information.

Events are not recorded by default. Audio, video, screenshots, chat logs, attendance lists or transcripts are saved or shared beyond what is necessary to run the event only after participants have received clear information and, where required, each participant has given separate consent. A participant may keep camera and microphone off where the event format permits. AI transcription or automated meeting-summary tools are not used without prior notice, a lawful basis and an update to the relevant privacy information.

16. Coaching and individual development support

Coaching services made available through Creative Space are delivered only by appropriately certified coaches who are expected to follow the ICF, EMCC or an equivalent recognised professional code of ethics. A coach who determines the purpose and means of coaching records is independently responsible for providing a privacy notice and protecting any client information.

Creative Space does not routinely receive or keep coaching notes, individual development records or health information. A coach may share information with lovrika only where the client has specifically agreed, or where another clear legal basis applies, and only to the minimum extent necessary. Coaching sessions are not recorded by default.

17. Research, anonymised stories, testimonials and public content

Creative Space may conduct surveys, interviews or qualitative learning activities to understand the realities of SDG- and IDG-aligned solopreneurs and improve support systems. The information notice and legal basis for each research activity will be provided at collection. Participation is voluntary unless a limited item is genuinely necessary to deliver a commissioned programme.

We do not publish an identifiable story, quotation, testimonial, photograph, screenshot, podcast or interview merely because someone is a member or attended an event. Identifiable or potentially identifiable public content is used only under a specific written or electronic permission that describes the content, purpose, audience and publication channels. Consent can be withdrawn for future use, although it may not be possible to retrieve copies already lawfully published or downloaded by others.

A story described as anonymous must be altered sufficiently that the person cannot reasonably be identified from the story alone or in combination with other available information. Until that threshold is reached, the material remains personal data and is treated as confidential or pseudonymised. Source recordings, notes and consent records are access-restricted and retained only for the period stated for the activity. Genuinely anonymised statistical or narrative insights may be retained and used for research, impact reporting and education because they are no longer personal data.

18. Recipients and access

Personal data is disclosed only where needed for the purposes described above. Recipients may include:

authorised Creative Space administrators and team members whose role requires access;

other authorised community members for profile and content information shared in member spaces;

service providers such as Squarespace, Circle, Stripe, Google Analytics, Substack and the platform selected for a specific event;

professional advisers, auditors, insurers or public authorities where required for legal, tax, governance or claims purposes; and

project or organisational partners where this is necessary for a disclosed programme and an appropriate legal basis or permission exists.

We do not sell personal data. Access to administrative back ends is restricted by role. Former team members’ access is removed when their role ends. Members and facilitators may access only the spaces and information made available to them through their role and community permissions.

19. International data transfers

Several service providers are headquartered in the United States or use sub-processors in other countries. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision such as the EU–US Data Privacy Framework where applicable, the European Commission’s Standard Contractual Clauses, and supplementary contractual, organisational or technical measures as required. Provider privacy notices and data-processing addenda contain further information about their transfer mechanisms.

20. Retention

We keep personal data only for as long as necessary for the stated purpose, to comply with law or to establish, exercise or defend legal claims. More specific criteria include:

contact enquiries: normally up to twelve months after closure, unless connected to an ongoing relationship or legal matter;

newsletter subscriptions: until unsubscribe or withdrawal, plus a minimal suppression and consent record where necessary;

active member account data: for the membership period; after access ends, the Circle account may be deactivated while content remains as described in section 12.7;

event registration data: normally up to six months after the event unless needed for certificates, payment records, follow-up requested by the participant or legal claims;

recordings: only for the period stated when consent is obtained and normally no longer than twelve months unless a different period is expressly agreed;

research source material: for the period stated to participants and normally no longer than twenty-four months after the relevant project ends, unless renewed permission or a legal need applies;

payment, donation, invoice and accounting records: for applicable German commercial and tax retention periods; and

consent records: for as long as needed to demonstrate the permission and address related legal claims.

When a purpose ends, data is deleted, anonymised or access-restricted unless another lawful retention ground applies. Provider backups may be overwritten according to the provider’s documented cycle rather than deleted immediately from every backup copy.

21. Security

We use proportionate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access. Measures include role-based access, limiting administrative privileges, removing access when a role ends, password-protected accounts and devices, encrypted connections, appropriate updates, confidentiality expectations, provider security controls and incident-response procedures. Two-factor authentication is used where available and should be enabled by every administrator.

Circle states in its Data Processing Addendum that it uses access controls, multi-factor authentication, encryption using AES-256 at rest and TLS 1.2 or higher in transit, regular backups, vulnerability management and incident-response measures. Squarespace, Stripe and other processors maintain their own security measures under their contractual and legal obligations. No internet transmission or storage method can guarantee absolute security.

22. Automated decision-making and AI

lovrika does not use solely automated decision-making that produces legal or similarly significant effects for members, donors or participants. Membership and moderation decisions are made by authorised people. If an AI-enabled provider feature is introduced in a way that materially changes the processing of member or participant data, we will assess it and update the relevant privacy information before use.

23. Adults only and future youth programmes

The current public community and membership are intended only for people aged 18 or over. Individuals under 18 may not become members. We do not presently collect personal data directly from minors through a Creative Space youth programme.

Before any future youth programme collects data from a person under 18, Creative Space will introduce a programme-specific privacy notice, age-appropriate information, data-minimisation rules, safeguarding measures, suitable provider contracts and, where required, a verifiable parent or guardian consent process. The general community privacy notice will not be treated as sufficient for that future processing.

24. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

receive information about our processing and obtain access to your personal data;

have inaccurate data corrected and incomplete data completed;

request erasure of personal data;

request restriction of processing;

receive data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller;

object, on grounds relating to your situation, to processing based on Article 6(1)(f) GDPR;

object at any time to processing for direct marketing; and

withdraw consent at any time for the future without affecting processing that was lawful before withdrawal.

To exercise a right, please contact the controller by post using the address in section 1. We may need to verify identity before acting on a request. We normally respond within one month; the period may be extended by up to two further months where permitted for complex or numerous requests, and we will explain any extension.

25. Right to complain

You have the right to lodge a complaint with a data-protection supervisory authority, particularly in the EU Member State of your habitual residence, place of work or the place of the alleged infringement. The supervisory authority responsible for lovrika’s registered office is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22
20459 Hamburg
Germany
https://datenschutz-hamburg.de/

26. Changes to this Notice

We may update this Notice when our activities, service providers or legal requirements change. The current version and update date will be published on the Creative Space website. Where a change materially affects members or requires new consent, we will provide additional notice or request consent as appropriate.