Legal

Your data. Clearly explained.

This policy explains what data is processed across the public website, Discord services and protected team areas — and why.

No advertising tracking Encrypted transmission Clear retention rules
Transparency

PRIVACY POLICY

Last updated: 31 August 2026

Controller

The controller responsible for the processing of personal data on this website is:

Jens Shimpf
Project: Die Kochshow
Herdweg 16
71254 Ditzingen
Germany

Email: post@diekochshow.com
Website: https://diekochshow.com

Please send privacy enquiries to the email address above.

Scope and sources of data

This privacy policy applies to the entire diekochshow.com website. It covers the public pages, recipes and media, contact form, newsletter, winner area, application centre, team centre and the non-public administration, task, stream planning, calendar and accounting areas.

We receive personal data mainly from you directly, from authorised team members in the course of administration, from your Discord account after a connection initiated by you and automatically in the form of technically necessary connection and security data. Personal data is processed only where this is necessary to provide the website, perform the function you requested, communicate with you, meet legal obligations or protect the service.

Hosting and server log data

This website is hosted by:

STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany

When the website is accessed, technically necessary connection data is processed. This may include the page or file requested, date and time, transferred data volume, browser type and version, operating system, referring URL, host name and IP address. Processing is necessary to deliver the website, identify errors, defend against attacks and maintain secure operation.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and error-free provision of our website. Where processing is necessary for a contract or pre-contractual steps, Article 6(1)(b) GDPR also applies. STRATO generally acts as our processor for hosting. Further information: https://www.strato.de/datenschutz/

Encrypted transmission

The website is provided over HTTPS. This protects transmitted content, in particular form entries, session identifiers and login data, against unauthorised access by third parties while in transit. Absolute security of electronic communication cannot, however, be guaranteed.

Cookies and sessions

We do not use advertising, analytics or tracking cookies. Only technically necessary cookies or cookies expressly requested by you are used:

  • DKSSESSID: a random session identifier for security functions, forms, Discord connections and protected areas. It does not contain login details in plain text and is normally deleted when the browser is closed.
  • dks_lang: stores the selected website language for up to one year.
  • dks_winner_lang: stores the selected language in the winner area for up to one year.

The legal basis for related processing is Article 6(1)(f) GDPR or Article 6(1)(b) GDPR where the cookie is needed for a function requested by you. Access to terminal equipment is permitted under section 25(2)(2) TDDDG where it is strictly necessary to provide the digital service expressly requested by you. Language cookies are set when you choose a language.

You can delete or block cookies in your browser. Without the session cookie, forms, Discord logins and protected areas may not function correctly.

No audience measurement, advertising or profiling

No external analytics, advertising or profiling services are currently used on this website. We do not create advertising profiles, conduct cross-site tracking or sell personal data.

Twitch and YouTube live status

The website may use the official Twitch and YouTube interfaces from our server to check whether Die Kochshow is currently live. The request is made by our web server. IP addresses, cookies and other identifiers of individual website visitors are not transmitted to Twitch or YouTube through this live-status request. Results may be cached briefly on our server.

If you click a Twitch or YouTube link, you leave our website. The platform provider will then process connection and usage data under its own responsibility.

Privacy information:
Twitch: https://www.twitch.tv/p/de-de/legal/privacy-notice/
Google/YouTube: https://policies.google.com/privacy?hl=en

Embedded YouTube videos

YouTube videos are not loaded automatically. A local notice is displayed first. A player from youtube-nocookie.com is loaded only after you actively select “Watch video”.

For users in the European Economic Area, the provider is generally Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When the player is loaded, Google or YouTube necessarily receives information such as your IP address, browser and device details, the time and the page viewed. If you are signed in to Google, Google may associate the view with your account. Even in enhanced privacy mode, YouTube may store information in your browser or use existing identifiers during playback.

The player is loaded only with your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Consent applies to the video actively loaded and is not stored permanently by our website. Reloading the page displays the local notice again. Further information: https://policies.google.com/privacy?hl=en

External links and social media

The website contains links to third-party services, particularly Twitch, YouTube, TikTok, Instagram and Discord. Merely displaying our page does not establish a connection to a target provider through a normal link. The external service opens only after your click. The provider may then process connection, device and usage data under its own terms. We have no control over that processing.

Contact by email and contact form

If you contact us by email, we process in particular your email address, time, message content and, where provided, your name and attachments. The contact form in the imprint processes your name, email address, category, subject, message and choice of an optional confirmation. The enquiry is sent through STRATO's mail servers directly to post@diekochshow.com.

The contact form message is not additionally stored in the website database. To prevent spam and abuse, only a contact ID, non-reversible checksums derived from IP and email details, the recipient, a limited delivery status and a technical error code are stored. These technical records are deleted after no more than 90 days. If you select “Send me a copy”, you receive an automatically generated confirmation containing the contact ID and submitted details.

Processing is carried out to handle and answer the enquiry. Article 6(1)(b) GDPR applies where the message concerns a contract or pre-contractual measures. In all other cases, Article 6(1)(f) GDPR applies; our legitimate interests are proper communication and prevention of abuse. Confirming the privacy notice records that you were informed about the processing.

General enquiries are normally retained in the email inbox for no more than six months after completion, unless legal obligations, contracts or legal claims require longer retention.

Winner area and prize fulfilment

Winners receive a personal, time-limited link. Its code is stored as a cryptographic hash and, where needed for later issue, additionally in encrypted form. The winner area is not publicly listed and is blocked from search engines.

Depending on the prize, the following data may be processed:

  • name, Discord name and email address,
  • shipping address and other information required for the prize,
  • answers in individually configured form fields,
  • submission time, processing, email and shipping status,
  • internal notes required for fulfilment,
  • non-reversible checksums derived from IP address and browser identifier to detect abuse.

The data is used to associate the submission with the authorised winner, handle questions, prepare and hand over or ship the prize, prevent repeated redemption and document fulfilment. The legal basis is Article 6(1)(b) GDPR. Optional processing may be based on Article 6(1)(a), security measures on Article 6(1)(f) and statutory retention on Article 6(1)(c) GDPR.

Where necessary, relevant information may be shared with a shipping provider, competition partner or sponsor. Winner data is normally deleted no later than 90 days after fulfilment has been marked complete, unless legal obligations or claims require otherwise. If a winner link is deleted, the same contact details may be entered again for a later, separate prize.

Application centre and Discord login

An email address is generally not required for applications. Secure association and later access to the application centre use the applicant's Discord account. Application categories can be publicly visible or displayed only after Discord login and successful verification of a configured server role.

The Discord connection processes, depending on the function:

  • unique Discord user ID,
  • Discord username, display name and avatar,
  • server membership and Discord roles needed for access checks,
  • OAuth consent, connection and verification time.

The OAuth2 `identify` scope is used for identification. If an expressly offered automatic server join is enabled, `guilds.join` may also be requested. An access token is used only for connection and, where applicable, the server join, then revoked and not retained as a permanent access token in the website database. The website session is time-limited.

The application process may additionally process:

  • application category, age where requested and answers to configurable questions,
  • application reference, submission time and processing status,
  • responsible team members, internal notes and reviews,
  • interview time, location, acceptance or decline and a request for another appointment,
  • messages between applicant and team in the protected centre,
  • status and processing history,
  • Discord notifications, delivery status and technical errors,
  • pseudonymised security values to limit abuse and repeated applications,
  • time and version of the confirmed privacy notice.

Processing is required for identification, review and handling of the application, appointment coordination, communication, status display, abuse prevention and documentation. Decisions are taken by authorised team members. There is no solely automated application decision.

Section 26(1) BDSG applies to an application for employment. Article 6(1)(b) GDPR applies to pre-contractual measures for other forms of participation. Voluntary Discord features and an optional server join may be based on Article 6(1)(a) GDPR. Security and documentation measures are based on Article 6(1)(f) GDPR.

Rejected or withdrawn applications are generally deleted no later than six months after completion unless pending claims, statutory duties or separate consent require otherwise. For accepted applications, only data still needed for team or contract administration is transferred.

Discord notifications and applicant communication

After receipt of an application and for selected status changes, the Kochshow bot may send designed Discord direct messages containing a link to the application centre. Team messages and interview invitations can also trigger a notification. Applicants do not need to reply to bot messages; communication with the team takes place through the protected application centre.

For this purpose, the Discord user ID, necessary notification content, technical message identifiers, delivery time, delivery status and, where relevant, a limited error message are processed. The personal link alone does not grant access; the connected Discord account must also be signed in. After acceptance, rejection or withdrawal, the centre may be closed for new submissions.

Newsletter by email and Discord

For the newsletter, you first select the desired topics—new streams, new recipes or both—and then the delivery route: email, Discord or both. Only fields required for the selected delivery routes are displayed and processed.

Depending on your choice, we process:

  • email address and normalised email address,
  • Discord user ID, username, display name and avatar,
  • topic and delivery channel selections,
  • registration, confirmation and unsubscribe status,
  • consent time and consent version,
  • hashed confirmation and management tokens and the protected personal management access,
  • delivery times, delivery status, limited attempt count and technical errors.

If email is selected, a confirmation message is sent before final activation. If Discord is selected, you must expressly connect your Discord account. You can change or unsubscribe from the newsletter through the personal management link. Emails contain an unsubscribe link; Discord messages include a corresponding management button where technically available. Discord direct messages can be blocked by Discord or your privacy settings.

The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw it at any time with future effect through the management link or by emailing post@diekochshow.com. No new newsletter is scheduled after unsubscribing. Necessary consent and delivery evidence may be retained in restricted form for an appropriate period to meet legal obligations and defend against claims.

Team centre and Discord role verification

The non-public team centre brings together links and access to tasks, stream plans, calendar and personal accounting. Access uses Discord. The unique Discord user ID, username, display name, avatar, server membership, required roles and verification times are processed. Roles are checked again against the Discord server at login or when synchronisation is triggered.

Which areas and people are selectable or visible is determined by Discord roles configured in the admin area. Role verification is used only for access and permissions management. The legal basis is Article 6(1)(b) GDPR or section 26 BDSG where use forms part of a working relationship, and Article 6(1)(f) GDPR for secure permission management.

Tasks, stream plan and team calendar

The task system may process title, description, deadline, status, priority, checklist items, comments, assigned Discord users, responsible roles, participants and processing history. Depending on the selected setting, tasks are published as a Discord direct message or an updated embed in a selected server channel. Names or Discord display names of responsible people may be visible there. Technical message and channel IDs prevent duplicates and allow updates.

The stream plan processes date, day, freely configurable positions such as camera, Twitch or YouTube administration, permitted roles and assigned team members. Current Discord members and roles can be retrieved when a new plan is created or manual synchronisation is performed.

The team calendar processes title, category, description, start and end time, visibility roles and assigned people. Team members can accept or decline. A reason is required for a decline and is visible to responsible administrators or authorised organisers. A meeting summary may be added later to the fixed or freely entered “Team Meeting” category and read by authorised team members.

This processing supports internal organisation, task allocation, scheduling, accountability and communication. The legal basis is Article 6(1)(b) GDPR, section 26 BDSG or Article 6(1)(f) GDPR. Data is deleted when it is no longer needed for organisation, accounting or evidence and there are no statutory obligations or claims requiring retention.

Team accounting and main account

The website provides internal team accounting. It may process Discord user ID, display name, role, entry title and reason, date, amount, type of transaction, payout or return status, link to the main account and processing history. Team members see only their own total and history. Administrators and expressly authorised accounting users can manage the overall view and main account.

The main account records manual income, expenses, donations and team-related entries. Crediting an amount to a team member can create a corresponding debit in the main account. When the amount is paid out or returned to Die Kochshow, this status is documented in the internal record. The system does not execute bank, card or PayPal payments and does not replace external bookkeeping; it documents only the entries made in it.

The legal basis is Article 6(1)(b) GDPR, section 26 BDSG, Article 6(1)(c) GDPR for statutory documentation obligations and Article 6(1)(f) GDPR for transparent internal accounting. Retention is determined by applicable contract, tax and commercial law and the need to defend against claims.

Donations and donation receipts

The optional public donation portal initially collects the donor's name, requested amount and email address. We additionally process a reference number, an access key stored only as a hash, language, processing and email status, and shortened or hashed technical characteristics for abuse prevention. Messages, payment approvals, a report that a payment has been made and, voluntarily, an address may be stored in the protected donation centre. The personal access link must be kept confidential.

Payment details are displayed only after personal approval. For bank transfers, the configured account data and a reference number are shown. For PayPal, the website merely opens an external PayPal link; PayPal processes the data entered there under its own responsibility. The website cannot access the PayPal or bank account and does not automatically detect receipt of payment. A payment reported by a donor is therefore recorded as received only after manual verification.

For a main-account entry marked as a donation, the system may additionally process the donor's name, full address, email address, donation amount, date, purpose or reason, receipt number, processing status and email or error status. The amount of a donation is not technically limited to EUR 250. A designed PDF donation receipt can be generated from these details. Outgoing messages are sent through the SMTP mailbox actually configured; spende@diekochshow.com is used only as a forwarding and archive address. A cancellation records the status, time and authorised processor, and the donor receives a designed cancellation message.

Processing is carried out to handle the request and communication, document support actually received and, where applicable, issue or cancel a receipt on the basis of Article 6(1)(a), (b), (c) and (f) GDPR where the respective basis applies. Open requests are deleted when no longer required. Accounting and receipt data is retained for statutory retention periods. Messages already delivered, recipient inboxes and backup copies remain unaffected until their applicable periods or backup rotations expire. The technical description as a donation receipt does not guarantee tax recognition in an individual case.

Team profiles, images and published content

The public website may publish names or stage names, tasks, descriptions, profile pictures, favourite dishes and social-media links of team members. Recipes, streams and other content may identify authors or contributors. Uploaded images are stored in optimised variants; file type, paths, dimensions, alternative text, crop and uploading user are processed for this purpose.

The legal basis is an agreement under Article 6(1)(b) GDPR, consent under Article 6(1)(a) GDPR or our legitimate interest in presenting the team under Article 6(1)(f) GDPR. Public information can be accessed worldwide and stored by search engines or third parties. Profiles and media no longer required are removed after participation ends or following an effective withdrawal, unless rights or legal duties prevent this.

Administration accounts, two-factor and USB login

For authorised administrators, editors and accounting users, we process in particular username, email address, password hash, role, additional permissions, account status, login times, failed attempts and lockout times. Passwords are not stored in plain text.

When authenticator login is configured, the necessary TOTP secret is stored in encrypted form. Up to five USB key files can be configured for each account. The server stores in particular a random key ID, label, cryptographic verifier, creation time, last-used time and revocation time. The secret key file remains with the user. Modified, revoked or deleted keys are rejected. If several login methods are configured, users can choose between the available methods after password login; an authorised USB key may additionally allow direct login.

For security-relevant administration actions, the user, time, IP address, action, affected object and limited technical details are recorded in audit logs. Processing is necessary for user administration, permissions, system security and accountability. The legal basis is Article 6(1)(b) GDPR, section 26 BDSG and Article 6(1)(f) GDPR.

Login logs are generally deleted after 90 days and general administration audit logs after twelve months unless a security incident, statutory duty or legal claim requires longer retention. Account data is deleted or anonymised when authorisation ends and it is no longer needed.

Discord as an external service and Kochshow bots

The provider for people in the European Economic Area is:

Discord Netherlands B.V.
Schiphol Boulevard 195
1118 BG Schiphol
Netherlands

Discord is used for login, role and membership checks, optional server joins, avatars, direct messages, task and status notifications and selected channel embeds. Depending on the function, Discord user ID, username and display name, avatar, roles, membership, message content, channel and message ID, delivery time and technical status are transferred to or retrieved from Discord.

The website uses configured applications and bots managed and synchronised in the admin area under “Die Kochshow Bot” or function-specific settings. A bot does not have to appear online continuously if the action is performed server-side through the Discord interface. Discord may reject direct messages under its own rules, where there is no communication route, or because of your privacy settings.

During Discord login, retrieval of an avatar from cdn.discordapp.com and message delivery, Discord processes data under its own responsibility. Discord may process data in the United States and other countries and refers, among other safeguards, to adequacy decisions and standard contractual clauses. Further information: https://discord.com/privacy

Consent can be withdrawn for the future by emailing post@diekochshow.com. Where Discord is required for unique identification or access to a protected area, that service may then become unavailable or restricted. Permissions can also be managed in your Discord account.

Email delivery

System, contact, winner, newsletter, donation and cancellation emails are sent through STRATO's SMTP servers. Depending on the message, recipient address, sender alias, subject, content, delivery time, status and a limited error message are processed. The website may use post@diekochshow.com, newsletter@diekochshow.com and spenden@diekochshow.com as function-specific senders. Some messages are automated system messages; a notice in the email explains whether replies are monitored.

Database backups

Access-protected database backups are created on the hosting storage to recover from errors, accidental changes or security incidents. The system retains no more than eight backup generations; older backups are deleted during rotation. Data deleted from the active system may therefore remain in a backup until the last affected generation is replaced. Backups are used only for recovery, error analysis and availability of the service. The legal basis is Article 6(1)(f) GDPR.

Recipients of personal data

Within Die Kochshow, access is limited to people who need the respective data for their work. Depending on the function used, the following recipients or recipient categories may also receive data:

  • STRATO GmbH as hosting, database and email provider,
  • Discord Netherlands B.V. for Discord login, role checks, profile display, bots and messages,
  • Google Ireland Limited or YouTube after a video is actively loaded,
  • Twitch after an external Twitch service is opened,
  • shipping providers, competition partners or sponsors where required for prize fulfilment,
  • advisers, technical providers, courts, authorities or other bodies where there is a legal obligation or disclosure is necessary to establish, exercise or defend legal claims.

Any additional transfer takes place only with consent or another legal basis.

Transfers to third countries

The core website is hosted by STRATO. Voluntary use of external platforms such as Discord, YouTube, Twitch, Instagram or TikTok may involve processing outside the European Union and European Economic Area, particularly in the United States. For external links this begins after they are opened, and for embedded YouTube videos after active loading. Discord is involved when you start a login, when avatars are retrieved and when bot messages are sent.

Where we are responsible for a transfer, we rely on an adequacy decision under Article 45 GDPR, appropriate safeguards such as standard contractual clauses under Article 46 GDPR or a statutory exception under Article 49 GDPR. A different level of data protection may apply in third countries despite these mechanisms.

Overview of legal bases

We process personal data mainly under:

  • Article 6(1)(a) GDPR – consent,
  • Article 6(1)(b) GDPR – contract and pre-contractual measures,
  • Article 6(1)(c) GDPR – legal obligation,
  • Article 6(1)(f) GDPR – legitimate interests,
  • section 26 BDSG – processing connected with employment or another working relationship,
  • section 25 TDDDG – storage of or access to information on terminal equipment.

Our legitimate interests include secure and economic operation, prevention of abuse, proper communication, team organisation, permissions management, documentation of administration actions and defence of legal claims.

Retention periods

We store personal data only for as long as it is needed for the relevant purpose. It is then deleted or anonymised unless statutory retention duties, ongoing contractual relationships, consent evidence, security incidents or legal claims require otherwise. The main standard periods are:

  • technical contact-form records: no more than 90 days,
  • completed general email enquiries: normally no more than six months,
  • completed winner data: normally no more than 90 days after fulfilment,
  • rejected or withdrawn applications: normally no more than six months after completion,
  • newsletter subscriber data: until unsubscribe, with necessary consent evidence potentially retained longer,
  • login logs: normally 90 days,
  • general admin audit logs: normally twelve months,
  • task, calendar, stream plan, accounting, donation and receipt data: according to organisational, contractual and legal necessity,
  • backups: until automatic rotation within no more than eight backup generations.

Data relevant under tax, commercial, employment or evidence laws may be retained for the applicable statutory period and restricted against use for other purposes.

Your rights

Where the legal requirements are met, you have in particular the following rights:

  • access under Article 15 GDPR,
  • rectification under Article 16 GDPR,
  • erasure under Article 17 GDPR,
  • restriction under Article 18 GDPR,
  • data portability under Article 20 GDPR,
  • objection under Article 21 GDPR,
  • withdrawal of consent with future effect under Article 7(3) GDPR,
  • complaint to a supervisory authority under Article 77 GDPR.

To exercise your rights, email post@diekochshow.com. We may ask for additional information where this is necessary to verify your identity securely. For Discord-based areas, the unique Discord user ID may be used for matching. The rights of other people and statutory retention duties remain unaffected.

Specific information on the right to object

Where processing is based on Article 6(1)(f) GDPR, you may object at any time for reasons arising from your particular situation. We will then no longer process the affected data unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or processing is needed to establish, exercise or defend legal claims.

Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority, particularly in the place of your habitual residence, workplace or the alleged infringement. The supervisory authority generally responsible for the controller's location is:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany

Email: poststelle@lfdi.bwl.de
Complaint information: https://www.baden-wuerttemberg.datenschutz.de/beschwerde/

Requirement to provide data

You do not have to provide information actively to browse the public website, although technical connection data is required to deliver it. Mandatory fields are marked in forms and protected areas. Without the required winner data, a prize cannot be fulfilled. Without a Discord connection, Discord newsletters, the application centre and team areas cannot be used. Without required accounting or donor data, the transaction cannot be documented or a receipt produced. Optional information and delivery channels are identified as such.

No automated individual decision-making

We do not make decisions based solely on automated processing within the meaning of Article 22 GDPR that have legal or similarly significant effects on you. Role checks control only technical visibility and access. Automatically sent registration, status, task, newsletter or appointment messages reflect content and states previously configured or handled by authorised people.

Security

The website uses technical and organisational safeguards. These include HTTPS, secure session cookies, CSRF protection, strict security headers, role and permission checks, password hashing, encrypted secrets, TOTP or USB keys, limits on failed logins, pseudonymised abuse checks, logs of security-relevant actions, access-protected areas and regular backups. Safeguards are reviewed and adjusted according to risk and technical development.

Changes to this privacy policy

We update this privacy policy when functions, providers or legal requirements change. The current version published on the website applies. The date of the last change appears at the beginning. Where required, material changes will also be highlighted within the affected function.