Privacy policy
Last reviewed: September 19, 2026
imami brings religious professionals and institutions together. That takes data — but only the data without which there is no match to make. This page says which data that is, what we use it for, and who sees it besides us.
Controller
imamiRedouane Dali
Bakusbrink 43a
32120 Hiddenhausen
Deutschland
Email: redouane.dali@outlook.com
What happens when you open this site
For your browser to receive a page, it has to tell our server where to send it. That leaves log data: IP address, date and time, the address requested, the browser and operating system identifier and — if your browser sends it — the page you came from.
We need this to deliver the site, to find faults and to fend off attacks. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is secure operation. We do not merge the logs with other data, we build no profiles from them, and we keep them no longer than operation and abuse prevention require.
Cookies and local storage
This site sets no advertising or analytics cookies. It embeds no analytics service and no ad network, and the fonts sit on our own server — your browser does not fetch them from third parties. That is also why we do not ask for consent: what is stored is technically necessary and stays with you.
Two things your browser remembers:
- NEXT_LOCALE — a cookie holding the language you picked, so the next page arrives in the same one. It lasts a year.
- imami-theme — your choice between light and dark, in your browser's local storage. It never leaves your device, and if you follow the system setting we store nothing at all.
Search
You can search in your own words — “imam for a wedding in Cologne, Arabic”. To turn that into filters, we interpret the sentence: place, specialty, language. Part of that is our own code; for the rest we pass the text you typed to a language-model service whose servers are in the European Union. Only that text is passed on — not your IP address, and nothing that identifies you.
We neither log nor store the search text. So that individual visitors cannot abuse the interpreter at our expense, we count for ten minutes how many requests come from one IP address. That count lives in memory only and disappears with the window.
Places are looked up in our own gazetteer; it sits in our database and is built from freely licensed GeoNames data. Your place entry therefore goes to no external address service. The legal basis is Art. 6(1)(f) GDPR: a search should find something even when it is phrased as a sentence rather than as a form.
The map on the results page
Next to the result list there is a map. The map images are not ours; they come from an external map service, and your browser loads them there directly. That service learns your IP address and which section of the map you are looking at. Which results you are shown it does not learn — those come from us.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is showing results where they are. The same results sit beside the map as a list, which stays complete even when the map does not load.
Account, profiles and needs
You can read the public site without an account. Anyone creating a profile, posting a need or answering one needs an account. Sign-in and password are handled by our own identity service; the same account works for imami and for our sister product amana.
What professionals write in their profile — name, specialties, languages, place, availability — is there to be found: it is publicly visible and may be picked up by search engines. Needs posted by institutions are public as well. Needs posted by private individuals are not; they appear neither in our sitemap nor in search engines. A need posted as private is visible only to the people invited to it.
The legal basis is Art. 6(1)(b) GDPR: without these details there is no match to make, which is the point of the service.
Contact between professionals and institutions
When a professional answers a need or an institution approaches a professional, the other side sees what the decision requires: who is asking, what it is about, and what the profile says. Everything after that runs through the inbox inside imami.
We notify you by email about open requests and replies. For that, your email address goes to the service that delivers the message. The email itself carries the pointer, not the conversation — it says something is waiting for you, not what is in it.
Verification and the seal
Anyone who wants the seal submits evidence. Those documents sit in storage on servers in the European Union, are not publicly retrievable, and are reviewed by us to decide on the seal. Only the outcome becomes public: the seal on the profile, never the document behind it.
Paid packages
Packages are bought by institutions; professionals and private individuals never go through checkout. Payment runs through our payment provider Stripe. The checkout page belongs to Stripe, as does the portal where invoices, payment methods and cancellation are managed: you enter your card details there, and they never reach us.
To Stripe we pass the institution's name and email address plus an identifier, so that an incoming payment can be assigned to the right account. Back we get whether a package is paid for and until when. The legal basis is Art. 6(1)(b) GDPR.
Stripe belongs to a group headquartered in the United States. For transfers there, Stripe relies on the European Commission's standard contractual clauses.
Where the data sits
imami runs on servers in France, operated by a provider acting for us as a processor under Art. 28 GDPR. The language-model service behind the search, the storage holding the verification documents and the service delivering our email stand in the same role.
How long we keep it
Account, profile and needs stay as long as the account does. Delete it and we remove them — except for what we have to keep for tax and commercial law, above all the records of paid packages with their statutory retention periods.
Log data and the count of search requests are short-lived; how long they stay is written above, in the sections where they arise.
Your rights
You have the right to information about your data, to rectification, to erasure, to restriction of processing and to data portability. You may object at any time to processing based on a legitimate interest, and you may withdraw consent at any time with effect for the future.
Write to us at the address above. Independently of that, you may lodge a complaint with a data protection supervisory authority; the competent one is the authority of the German federal state we are based in.
Changes
When what we process changes, we change this policy. The date above says when it was last reviewed.