Transparent, data-minimal, no advertising tracking

Privacy notice

This notice explains what data Roses of Zikr processes, why, on which legal basis, and for how long. The service is private and free of charge. It accepts no donations and uses no advertising, affiliate links, sales, personalised user profiles, or Google Analytics.

Last updated: 2 September 2026

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Roses of Zikr
München, Deutschland
info@rosesofzikr.com

1. Website access and hosting

When you open the site, your browser sends technically necessary data to the web server. This may include IP address, date and time, requested URL, volume transferred, referrer, browser, operating system and error status. The host uses this to deliver the site securely, prevent abuse and investigate faults.

The legal basis is Article 6(1)(f) GDPR: the legitimate interest in a secure and stable service. Server logs are erased after the period stated below unless a security incident or legal duty exceptionally requires longer retention.

ALL-INKL.COM – Neue Medien Münnich
Inhaber: René Münnich
Hauptstraße 68
02742 Friedersdorf
Deutschland

Server-log retention
14 days

Full IP addresses are recorded in access logs.

The access logs are also used to create an internal Webalizer access report. The site embeds no external analytics script for this purpose.

2. Data-minimal visitor count

The server IP address is briefly normalised in memory and immediately pseudonymised with an HMAC and a secret server key. The application does not store the raw IP. Only the pseudonymous hash and first visit date/time are stored.

A code is counted once within 13 months and then automatically erased. Anonymous daily totals remain as historical statistics. Shared or changing public IP addresses can make the count imprecise. Recognisable bots and signed-in administrators are excluded.

The basis is Article 6(1)(f) GDPR, the legitimate interest in data-minimal reach measurement. You may object for reasons arising from your particular situation under Article 21 GDPR.

3. Cookies, local storage and offline use

There are no advertising, tracking or social-media cookies. Functional storage includes:

  • Session cookie for admin login, CSRF protection and one-time notices; erased when the browser closes.
  • Language cookie after an explicit language choice; one year.
  • Group cookies for the last group and requested automatic reopening; one year.
  • Local browser storage for appearance, personal dhikr counters, goals, streaks, custom dhikr and prayer-time method; it stays on your device.
  • Service worker/cache storage for the expressly offered offline function.

The subsequent personal-data basis is Article 6(1)(b) or (f) GDPR. Device storage is limited to requested or strictly necessary functions under section 25(2) no. 2 TDDDG. You can erase it in browser settings.

4. Qur’an and hadith content

Embedded Qur’anEnc and HadeethEnc content is retrieved through the Roses of Zikr server, so those sources receive the site server’s address rather than automatically receiving your visitor IP. Responses are not linked to a user profile.

If you choose an external original-source link, your browser connects directly to that provider, which may receive your IP address, browser data and access time. Its own privacy terms then apply.

5. Prayer times and location

Location access begins only after your click and browser permission. Approximate coordinates rounded to about 100 metres, or a voluntarily entered city and country, are sent with the date and calculation method to this server and then to the AlAdhan API operated by Islamic Network. Roses of Zikr does not store the location in its database.

The basis is your consent under Article 6(1)(a) GDPR. A possible transfer outside the EEA, where protection and enforceable rights may be weaker, additionally relies on Article 49(1)(a) GDPR where no adequacy decision applies. You can revoke browser access for future requests or not use the function; city and country are voluntary alternatives.

6. Dhikr and groups

Personal counters stay on your device. Public groups process a group name, dhikr title, count, approval status and creation time. Approved names and counts are public; do not enter real names or other personal information.

Random device identifiers and operations support reliable offline synchronisation. Operations and rejected or unapproved groups are erased after 90 days. Approved groups remain until administrative deletion or the purpose ends. The basis is Article 6(1)(b) GDPR for the requested group feature, otherwise Article 6(1)(f) GDPR for secure moderation.

7. Feedback

The feedback form stores rating, category, message, page language and time. It asks for no name or email and the app does not add an IP address to the feedback record. Do not enter personal or sensitive information. Feedback is automatically erased after 12 months. The basis is Article 6(1)(f) GDPR, the legitimate interest in improving the site.

8. Recipients and international transfers

Recipients may be the host below as processor and, only when the prayer-time feature is actively used, Islamic Network/AlAdhan. Opening an external source sends data directly to that selected site. Data is not sold and no personalised advertising takes place.

9. Retention and provision

The relevant periods are stated above. Otherwise, data is erased when the purpose ends unless legal obligations or overriding grounds require retention. Data is required only where technically necessary for delivery or a feature you select; without it that feature cannot be provided.

10. Your rights

Where the legal conditions are met, you have rights of access, rectification, erasure, restriction, portability and objection under Articles 15–21 GDPR. You may withdraw consent at any time for the future and lodge a complaint under Article 77 GDPR, in particular with the authority competent for your residence, workplace or the controller’s establishment.

Privacy contact: info@rosesofzikr.com

Competent data protection authority: Directory of German supervisory authorities ↗

11. Security and automated decisions

The site uses HTTPS. Session cookies are configured as Secure, HttpOnly and SameSite=Lax where technically possible, and security policies limit browser capabilities. There is no automated decision-making or profiling under Article 22 GDPR.

12. Changes

This notice will be updated if functions, recipients or the law change. Translations are provided for understanding; the German version governs in case of legal differences.