Privacy Policy / Datenschutzerklärung
Template version: 2 September 2026
Template requiring completion: Replace the controller details and verify the actual Vercel region, Stripe account configuration, retention periods, and any additional tools before launch.
1. Controller
[FULL LEGAL NAME / COMPANY]
[POSTAL ADDRESS]
Email: [PRIVACY EMAIL]
Data protection officer, if appointed: [CONTACT]
2. Hosting and server logs
This website is hosted by Vercel Inc. Technical request data, such as IP address, timestamp, requested URL, browser information, and security events, may be processed to deliver and protect the website. The legal basis is Art. 6(1)(b) GDPR where processing is necessary to provide requested content and Art. 6(1)(f) GDPR for the legitimate interests of secure, reliable operation. Configure the Vercel project and data-processing agreement for the operator's actual jurisdiction.
3. Vercel Web Analytics
We use Vercel Web Analytics to understand aggregated usage such as page views, referring pages, country, device type, browser, and operating system. According to Vercel, Web Analytics does not use third-party cookies and reports anonymized, aggregated data. We do not send names, email addresses, recovery keys, VIP codes, or payment details as analytics events. The intended legal basis is Art. 6(1)(f) GDPR (legitimate interest in improving the course); verify whether local law or the final configuration requires consent.
4. Payments via Stripe
When you choose to purchase access, payment and contact data are processed by Stripe Payments Europe, Limited and/or the Stripe entity applicable to your location. Stripe receives the information required to create and complete Checkout, prevent fraud, issue receipts, and meet legal obligations. We receive transaction identifiers, payment status, customer email, and limited billing information, but not full card details. Processing is based on Art. 6(1)(b) GDPR for contract performance and Art. 6(1)(c) GDPR for legal retention obligations. Stripe may process data outside the EEA under applicable transfer safeguards; consult Stripe's current privacy documentation for details.
5. Access cookies and local progress
After a paid or VIP unlock, the website sets a strictly necessary, signed, HTTP-only access cookie. It contains an access status and, for purchases, pseudonymous purchase references; it does not contain payment-card data. The cookie is designed for long-term lifetime access and may remain for up to ten years unless deleted. Course progress and completed exercises are stored locally in your browser and are not transmitted to our server.
6. Recovery
If you restore a purchase, the purchase email and signed recovery key are sent to our server and checked against Stripe. They are used only to verify the purchase and issue a new access cookie. Do not share the recovery key.
7. Recipients and international transfers
Data may be received by Vercel as hosting/analytics provider and Stripe as payment provider. Depending on configuration, processing may occur in third countries including the United States. Appropriate safeguards may include an adequacy decision, the EU–US Data Privacy Framework, and/or Standard Contractual Clauses. The operator must document the safeguards actually relied upon.
8. Retention
Payment and contract records are retained for the periods required by commercial and tax law. Security logs are retained only as long as required for operational security under the provider configuration. Access-cookie and local-progress data remain until expiry or deletion by the user. Replace this paragraph with the operator's verified retention schedule.
9. Your rights
Subject to the GDPR's conditions, you may request access, correction, deletion, restriction, portability, or object to processing. You may also lodge a complaint with a competent data protection supervisory authority. Contact [PRIVACY EMAIL] to exercise these rights.
10. Required and voluntary data
No account is required for the two free lessons. Payment information is required only if you buy full access. A VIP code is voluntary and is checked server-side. Without required payment or recovery data, the corresponding access cannot be provided.