# Legal — imprint, privacy, photos Not legal advice — but the points where school sites regularly get flagged. The actual imprint and privacy texts are `pages` records in PocketBase (slugs `imprint` and `privacy`), edited in the admin UI — see `redaktion.md`. Filling them in with released, real data before go-live is tracked as a Gitea issue (milestone „Elternbeirat-Website"). ## Imprint (§ 5 DDG) If the Elternbeirat has no legal form of its own, the operator is listed personally in the imprint with name and a valid postal address for service. This is a decision, not a formality — the private address becomes public. Alternative: the school's address, but only with its explicit consent and if the school is a co-operator. ## Privacy policy With the move, Tom becomes the controller in the sense of the GDPR. Name the server logs with IP addresses, define the legal basis and the deletion period. ## No external resources Google Fonts, Maps, YouTube embeds, and CDN scripts transmit visitors' IPs to third parties. Fonts are served by ourselves. This is the reason behind the "no external resources" rule in `CLAUDE.md` — data protection, not taste. ## Photos of children Only with the consent of the legal guardians — by far the most common mistake on school sites. When in doubt, no photos of people. Note: the old WordPress backup contained no own images anyway (only URLs in the database), so any photo used is a fresh, consciously released one. ## Hosting on a private connection The public IP of the private connection appears in the DNS of a school site. A deliberate decision, not a side effect.