Privacy policy
Privacy policy
Note: replace every placeholder in [square brackets] with your real details and have these texts reviewed by a lawyer before you start selling. You can delete this line afterwards. The German version is authoritative.
1. Controller
The controller for data processing on this website is:
[Name / company] [Address] Email: the address given in the legal notice
[If a data protection officer has been appointed, add their contact details here. Most sole traders are not required to appoint one.]
2. Principles
We process personal data only to the extent necessary to provide the course platform. This site uses no third-party advertising or tracking services, embeds no external fonts and sets only strictly necessary cookies. Reach measurement is cookieless and stored in our own database without any IP addresses or device identifiers.
The legal bases for processing are - depending on the purpose - Art. 6 (1) (b) GDPR (performance of a contract and pre-contractual steps), Art. 6 (1) (f) GDPR (legitimate interest in a secure, functioning service) and Art. 6 (1) (a) GDPR (consent) where consent is obtained. For payments, processing additionally serves compliance with legal obligations (Art. 6 (1) (c) GDPR, in particular commercial and tax retention duties).
3. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). You may withdraw any consent given at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority, for example the authority responsible for [federal state].
An informal message to the email address in the legal notice is enough to exercise your rights.
4. Hosting
The website runs on a server operated by [hosting provider, e.g. IONOS SE, Elgendorfer Str. 57, 56410 Montabaur]. The server location is [Germany]. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. Processing is based on Art. 6 (1) (f) GDPR (secure and efficient provision of the service).
5. Server log files
The hosting provider automatically collects and stores information that your browser transmits in server log files (browser type and version, operating system, referrer URL, host name, time of the request, IP address). This data is used for technical delivery, stability and security and is not merged with other data sources. The legal basis is Art. 6 (1) (f) GDPR. The retention period follows the hosting provider's specifications (usually a few days to weeks).
6. Cookies
This website sets two cookies, both strictly necessary:
- mm_session - keeps you signed in. Set only after login, httpOnly, expires after 30 days. It contains only a random session token; the session data is held server-side.
- mm_locale - stores your language choice (German or English), lifetime up to one year.
No cookies are set for analytics or marketing. The legal basis for storing information on your device is § 25 (2) no. 2 TDDDG (strictly necessary); for the subsequent processing, Art. 6 (1) (b) and (f) GDPR. No consent is required for this; the cookie notice serves transparency only.
7. Registration and user account
For an account we process your name, email address, a password you choose (stored only as a cryptographic hash, never in plain text) and your language choice. On registration we send you an email to confirm your address; confirmation is useful for account recovery but is not a precondition for use. The legal basis is Art. 6 (1) (b) GDPR. The data is stored until you delete your account.
8. Course use and learning progress
While you use the course we store which lessons you have opened and completed and - for video lessons - the last playback position reached. This lets us show your progress and resume the last lesson. The legal basis is Art. 6 (1) (b) GDPR. The data is stored until you delete your account.
9. Payment processing via Stripe
Payments are handled by the payment service provider Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). The actual payment takes place on a page hosted by Stripe; you enter card or bank details directly with Stripe, not with us, and we do not store them. Data transmitted to or processed by Stripe includes name, email address, amount, currency and payment method. We receive from Stripe a payment confirmation, a customer and transaction identifier and the payment status. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). A transfer to the USA may take place; it is safeguarded by the European Commission's adequacy decision on the EU-US Data Privacy Framework or by standard contractual clauses. Details: https://stripe.com/privacy .
10. Sending email
For transactional email (address confirmation, password reset, purchase confirmation, payment notices) we use [SMTP provider, address, server location]. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. Your email address and the content of the respective message are processed. The legal basis is Art. 6 (1) (b) GDPR (registration and purchase) or Art. 6 (1) (f) GDPR (account security). No marketing newsletters are sent.
11. Reach measurement
We measure use of our service exclusively with our own cookieless event log in our database. Recorded are an event name (e.g. "landing page viewed", "purchase completed"), possibly your account identifier, the path requested and the language. Not recorded are IP address, user agent or other device characteristics; there is no combination into a user profile and no transfer to third parties. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in improving the service). You may object to this processing at any time (see section 3).
12. Contacting us
If you contact us by email we process your details to handle the enquiry. The legal basis is Art. 6 (1) (b) GDPR where the enquiry concerns a contract, otherwise Art. 6 (1) (f) GDPR. We delete enquiries once they are no longer needed and no retention obligations apply.
13. Retention
We store account data and learning progress until you delete your account. Information we need for orders and invoices is retained for up to ten years due to commercial and tax obligations (§ 257 HGB, § 147 AO); otherwise such records are anonymised as far as possible after account deletion.
14. Data security
Transmission is encrypted via TLS (https). Passwords are stored only as a bcrypt hash. Access to course content and administration functions is checked server-side. Security-relevant endpoints are rate-limited against automated attacks.
15. Changes to this policy
We adjust this privacy policy whenever changes to processing require it. The version published on this page applies.