We place particular importance on protecting your data. Therefore, when processing your personal data (e.g. master data), we comply with the applicable data protection regulations, especially the GDPR and the Austrian Data Protection Act (DSG).
Below you will find detailed information about the data processing activities we carry out:
Contents
No phone support
Please note that we do not offer telephone customer support. Inquiries are processed exclusively in writing via email at support@bogneracademy.com. This is for documentation and quality assurance purposes.
As we are not legally required to do so, we have not appointed or registered a data protection officer with the data protection authority.
If the processing of your personal data is based on a balancing of interests (Art. 6 para. 1 lit. f GDPR: legitimate interests), you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data.
When exercising your right to object, we kindly ask you to explain your reasons why you believe we should not process your personal data as we do. We will examine the situation and either cease or adapt the data processing, or demonstrate our compelling legitimate grounds and continue processing.
We will also continue processing your data if it is required for the establishment, exercise, or defense of legal claims.
You may object to the processing of your personal data for direct marketing and data analysis purposes at any time. In this case, we will stop the data processing.
To exercise any of the above rights, please contact us personally, by telephone, or in writing:
Bogner Academy GmbH
Peter-Behrens-Platz 10
4020 Linz
Phone: +43 677 6436 5253
Phone:
Email: support@bogneracademy.com
Please note that we can only provide information if you are able to identify yourself.
2.2. If you believe that the processing of your data violates applicable data protection law or that your data protection rights have been infringed, you also have the right to lodge a complaint with the supervisory authority in the Member State of your residence, workplace, or the place of the alleged infringement.
If you wish to file your complaint with the supervisory authority in Austria, please direct it to:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Website, browser, operating system and interface, language and version of browser software
3.2. Electronic Contact Inquiries via the Website
3.3. Cookies / Web Analytics Service
3.4. Use of Google Services
This website uses various services of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”).
For data processing concerning residents of the European Union, the European Economic Area, and Switzerland, the responsible entity is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Below, we explain in detail which services are used on this website.
Further information about Google services and the privacy policy can be found at:
https://policies.google.com/privacy?hl=en
Information about transfers to countries outside the EU / EEA:
When using Google services, Google—as an active participant in the EU-U.S. Data Privacy Framework—also processes your data in the United States.
Companies that have successfully completed the Data Privacy Framework program are considered to have an adequate level of data protection under the provisions of the EU-U.S. and Swiss-U.S. Data Privacy Frameworks.
The Data Privacy Framework ensures secure data transfers of EU citizens’ data to the U.S.
Further information about the EU-U.S. Data Privacy Framework can be found at:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
3.4.1 Google Tag Manager
This website uses Google Tag Manager, a tool for technically integrating and managing applications on the website.
3.4.2 Google Fonts
This website uses external fonts known as “Google Fonts.” These web fonts are integrated by a server call, typically to a Google server in Ireland.
3.4.3 Google Analytics
This website uses cookies from Google to analyze the use of the website.
3.5. User Account
To use the app and the web platform, a user account must be created. For this, users must register with an email address and password and subsequently receive a profile account.
You can delete your user account at any time. In the navigation area of the customer account, the function “Delete user account” is available. After confirming the email sent to you, the user account will be deleted.
3.6. Customer Management, Accounting, Logistics and Bookkeeping
Providing your personal data is necessary for the performance of a contract or for the implementation of pre-contractual measures. Without this data, we cannot conclude a contract with you.
3.7. Customer Support and Marketing for Own Purposes
3.7.1. Customer Referrals (“Referral Partnerships”)
As part of our “Referral Partnerships,” we offer existing customers the opportunity to refer new customers to our products. Typically, we provide registered users with vouchers or discount codes that they can forward to new customers. If a new customer places an order, the referral partner also receives corresponding benefits. We process personal data to ensure smooth handling, transparent cooperation, and to measure the success of these activities.
3.8. Payment Systems
3.8.1. PayPal
PayPal is an online payment service for which you need a personal PayPal account. The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.
Further information about this online payment service provider can be found here:
https://www.paypal.com/de/legalhub/paypal/privacy-full
3.8.2. Stripe Payments
Stripe is an online payment service that requires you to have a personal Stripe account. The European operating company of Stripe is Stripe Payments Europe (Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland).
Further information about this online payment service provider can be found here:
https://stripe.com/en-de/privacy
3.8.3. Coinbase
Coinbase is an online payment service that requires you to have a personal Coinbase account. The European operating companies of Coinbase are Coinbase Ireland Limited (70 Sir John Rogerson’s Quay, Dublin 2, 662881, Ireland), Coinbase Europe Limited (70 Sir John Rogerson’s Quay, Dublin 2, 662881, Ireland), and Coinbase Germany GmbH (Kurfürstendamm 12, 10719 Berlin, Germany).
Further information about this online payment service provider can be found here:
https://www.coinbase.com/de/legal/privacy
3.9. Applicant Management
3.10. Social Media
3.10.1 YouTube (Google LLC)
YouTube is part of the Google LLC group. The controller for the processing of personal data in connection with YouTube usage is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
3.10.2 Facebook, Instagram (Meta Inc.)
Facebook and Instagram are part of Meta Inc. These services are operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, which is the controller for the processing of personal data through Facebook and Instagram.
Details on data collection and processing by the respective platform can be found at:
Facebook:
https://de-de.facebook.com/about/privacy/ (general privacy policy)
and
https://www.facebook.com/legal/terms/page_controller_addendum# (specific data collection for page insights)
Instagram:
https://help.instagram.com/155833707900388
Meta Platforms Inc., the parent company of Facebook and Instagram, has committed to complying with the requirements of the EU-U.S. and Swiss-U.S. Data Privacy Frameworks by certifying under the Data Privacy Framework Program.
Information on participation can be found by searching “Meta Platforms, Inc.” at:
https://www.dataprivacyframework.gov/s/participant-search
3.10.3. LinkedIn (Microsoft Corporation)
LinkedIn is part of the Microsoft Corporation group. The controller responsible for processing personal data in connection with the use of LinkedIn services is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
3.10.4. X (formerly Twitter)
X is operated by X Corp. The controller responsible for the service in the European region is Twitter International Unlimited Company, Fenian Street, D02 F663 Dublin, Ireland.
3.10.5. TikTok (Bytedance Ltd.)
TikTok is operated by Bytedance Ltd. and its European branch, TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. The controller for data processing in connection with TikTok use is TikTok Technology Limited.
3.10.6. Threads (Meta Platforms Ireland Limited)
Threads is a service of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, and part of the Meta group (Facebook, Instagram).
3.11. Website Shop System: WooCommerce
The integration of the webshop on this website is done using the WooCommerce plugin for WordPress, an open-source solution provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.
Automattic Inc., the parent company of the WooCommerce platform, has committed to complying with the requirements of the EU-U.S. and Swiss-U.S. Data Privacy Frameworks by certifying under the Data Privacy Framework Program. Information on participation can be found by searching “Automattic, Inc.” at:
https://www.dataprivacyframework.gov/s/participant-search
Further information on WooCommerce’s privacy policy can be found at:
https://automattic.com/privacy/
3.12. Images and Learning Content
3.12.1. Vimeo
The controller for Vimeo is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.
3.12.2. LearnDash
The controller for LearnDash is LearnDash, 2531 Jackson Avenue, Ann Arbor, MI 48103, USA.
3.12.3. YouTube (Google LLC)
YouTube videos are embedded in LearnDash for the presentation of video content. When an embedded YouTube video is started, a connection to YouTube’s servers is established. YouTube is then informed which page you are visiting. Additionally, when a video is played, cookies are used to collect information about user behavior – unless cookies are blocked in your browser.
For more information, see section 3.10.1 and YouTube’s privacy policy:
https://policies.google.com/privacy?hl=de&gl=de
4.Information on Data Transfers to Third Countries or International Organizations
The data we process is not transferred to recipients in third countries or to international organizations.
5.Change Management
This privacy policy is available in its current version on our website.
If you have questions about a previous version, please contact the entity listed in section 1.
Version 1.1, as of November/2025
Protecting your data is a matter of particular concern to us, which is why we comply with the applicable data protection regulations, in particular the GDPR and the DSG, when processing your personal data (e.g. master data).
Below you will find more detailed information about the data processing activities we carry out:
Table of Contents
1. Controller – 1 –
2. Data subject rights / Right to object and right of withdrawal / Right to lodge a complaint – 1 –
3. Information on the processing of your personal data – 2 –
3.1. Website visit – 2 –
3.2. Electronic contact requests via the website – 3 –
3.3. Cookies / Web analysis service – 3 –
3.4. Use of Google services – 4 –
3.5. User account – 5 –
3.6. Customer management, accounting, logistics and bookkeeping – 6 –
3.7. Customer care and marketing for own purposes – 7 –
3.8. Payment systems – 8 –
3.9. Applicant management – 11 –
3.10. Social media – 11 –
3.11. Website shop system: WooCommerce – 14 –
3.12. Images and learning content – 15 –
4. Information on data transfers to third countries or international organisations – 16 –
5. Change management – 16 –
1. Controller
Bogner Academy GmbH
Peter-Behrens-Platz 10
4020 Linz
Telephone:
E-mail: support@bogneradvisory.com
As we are not legally obliged to do so, we have not appointed/nominated a data protection officer to the data protection authority.
2. Data subject rights / Right to object and right of withdrawal / Right to lodge a complaint
2.1. You have the following rights vis-à-vis us with regard to your personal data:
Right of access (Art 15 GDPR),
Right to rectification (Art 16 GDPR) or erasure (Art 17 GDPR),
Restriction of processing (Art 18 GDPR),
Right to data portability (Art 20 GDPR),
Right to object to processing (Art 21 GDPR),
If the processing of your personal data is based on a balancing of interests (Art 6(1)(f) GDPR: legitimate interests), you have the right to object to the processing at any time for reasons arising from your particular situation. When exercising your right to object, we ask you to explain the reasons why we should not process your personal data as we have done. We will review the situation and either stop the data processing or adapt it, or show you our compelling legitimate grounds and continue the data processing. We will also continue the data processing if it serves the establishment, exercise or defence of legal claims.
You can object to data processing for the purposes of direct marketing and data analysis at any time. In this case, we will stop the data processing.
Right to withdraw consent (Art 7(3) GDPR).
If you have given us your consent to process your personal data, you can withdraw this consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
To exercise the aforementioned rights, you must inform us in person, by telephone or in writing:
Bogner Academy GmbH
Peter-Behrens-Platz 10
4020 Linz
Telephone:
E-mail: support@bogneradvisory.com
Please note that we can only provide information if you can identify yourself.
2.2. If you believe that the data processing violates applicable data protection law or that we have infringed your data protection rights, you also have the right to lodge a complaint with the supervisory authority in the Member State of your residence, place of work or the place of the alleged infringement.
If you wish to lodge your complaint with the supervisory authority in Austria, please address it to:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Wien
3. Information on the processing of your personal data
3.1. Website visit
Purpose: If our website is used only for information purposes (no registration and no transmission of other information), personal data is collected that is transmitted from your browser to our server. This is technically necessary in order to display our website to you and to ensure the stability and security of the website.
Data subjects: Website visitors
Legal basis: Legitimate interest (Art 6(1)(f) GDPR), Section 165(3) TKG 2021
Legitimate interests: Provision of a stable, secure and user-friendly information society service (website, online shop, appointment scheduling) for information about our company, to raise awareness of our company and our services and products;
The following data is processed: IP address, date and time of the request, time zone difference to GMT, content of the request (specific page), access status/HTTP status code, amount of data transferred in each case, requesting website, browser, operating system and interface, language and version of the browser software
Storage period: As long as you use our website.
Recipients / Recipient categories: Processors
3.2. Electronic contact requests via the website
Purpose: Processing of contact requests via e-mail or the website contact form.
Data subjects: Website visitors who use the contact form
Legal basis: Performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR), legitimate interest (Art 6(1)(f) GDPR), Section 165(3) TKG 2021
Legitimate interests: Provision of a stable and user-friendly information society service (website, online shop, appointment scheduling) for receiving and responding to inquiries
The following data is processed: Master data, content data of the request
Storage period: Until the request has been answered. If legal retention obligations exist, processing will be restricted until then.
Recipients / Recipient categories: Processors
3.3. Cookies / Web analysis service
Purpose: Improvement of the service offering, website appearance and direct advertising
Data subjects: Website visitors
Legal basis: Consent (Art 6(1)(a) GDPR), performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR), legitimate interest (Art 6(1)(f) GDPR), Section 165(3) TKG 2021
Legitimate interests: Improvement of own services, technical stability, plausibility check of billing from the use of cookies and web analysis services.
The following data is processed: IP address
Storage period: See cookie banner
Recipients / Recipient categories: Company of the analysis service / service provider
3.4. Use of Google services
This website uses various services of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”). For the data processing of residents of the European Union, the European Economic Area and Switzerland, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland is responsible. Below you will find a detailed explanation of which services this website uses.
Further information on Google services and the privacy policy can be found at https://policies.google.com/privacy?hl=en.
Information on transfers to countries outside the EU / EEA:
When using Google services, Google, as an active participant in the EU-US Data Privacy Framework, also processes your data in the USA. Companies that have successfully completed the Data Privacy Framework Program are considered entities with an adequate level of protection under the provisions of the EU-US and Swiss-US Data Privacy Frameworks.
The Data Privacy Framework ensures secure data transfer for data of EU citizens to the USA. Further information on the EU-US Data Privacy Framework can be found at: https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
3.4.1 Google Tag Manager
This website uses Google Tag Manager, a program for the technical integration and management of applications on the website.
Purpose: Recording of interactions on the website and forwarding to the connected service program; management and modification of service programs for website analysis without programming effort.
Data subjects: Website visitors
Legal basis: Consent (Art 6(1)(a) GDPR)
The following data is processed: IP address
Storage period: During the visit to the website
Transfer to countries outside the EU / EEA: possibly USA (details in point 3.4)
3.4.2 Google Fonts
This website uses external fonts, so-called “Google Fonts”. These web fonts are integrated by a server call, usually a Google server in Ireland.
Purpose: Platform-independent uniform display of our web content.
Data subjects: Website visitors
Legal basis: Legitimate interest (Art 6(1)(f) GDPR)
Legitimate interests: Improvement of own services, technical stability, uniform display, fast loading times of the website.
The following data is processed: IP address
Storage period: During the visit to the website
Transfer to countries outside the EU / EEA: possibly USA (details in point 3.4)
3.4.3. Google Analytics
This website uses Google cookies to analyse website usage.
Purpose: Improvement of the service offering, website appearance and direct advertising. We use the analysis of user behaviour to optimise both our web offering and our advertising.
Data subjects: Website visitors who have given their consent
Legal basis: Consent (Art 6(1)(a) GDPR), explicit consent (Art 49(1)(a) GDPR)
The following data is processed: IP address, number of sessions and visits, click behaviour, duration of stay on the website, rough location (country, city)
Storage period: see cookie banner
Recipients / Recipient categories: Processors
Transfer to countries outside the EU/EEA: possibly USA (details in point 3.4)
3.5. User account
To use the app and the web platform, a user account must be created. Users must register with their e-mail address and password and then receive a profile account.
Purpose: Creation and management of the user profile created
Data subjects: Persons who create a user account
Legal basis: Consent (Art 6(1)(a) GDPR), legitimate interest (Art 6(1)(f) GDPR)
Legitimate interests: Defence, exercise and enforcement of legal claims; security applications, in particular defence against unauthorised access to the user account.
The following data is processed: Salutation, title, first name, last name, address data, e-mail address, date of birth, payment preferences, in the case of purchases additionally contract data, duration of access authorisation to certain digital products […].
Storage period: The data may be stored until the expiry of the seventh year after the last contact with the client, unless longer contractual or legal retention periods exist.
Recipients / Recipient categories: Processors
You can delete your user account yourself at any time. The “Delete user account” function is available in the navigation area of the customer account. After confirmation of the e-mail sent to you, the user account will be deleted.
3.6. Customer management, accounting, logistics and bookkeeping
Purpose: Processing of personal data in the context of any business relationships with customers and suppliers in the course of a commercial activity, including systematic recording of all business transactions concerning income and expenses.
Data subjects: Customers, suppliers, employees
Legal basis: Consent (Art 6(1)(a) GDPR), performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR), compliance with a legal obligation (Art 6(1)(c) GDPR), legitimate interest (Art 6(1)(f) GDPR).
Legitimate interests: Defence, exercise and enforcement of legal claims, evaluation of customer relationships (in particular duration of the business relationship, number of complaints).
The following data is processed: Master data, VAT ID number
Storage period: Until termination of the business relationship or until expiry of the warranty, guarantee, limitation and legal retention periods applicable to the controller (in particular BAO); beyond that until termination of any legal disputes in which the data is required as evidence.
Recipients / Recipient categories: Tax office, courts and authorities, suppliers, debt collection companies for debt collection, banks tasked with payments to the data subject or third parties, legal representatives, tax advisors, payroll accountants.
The provision of your personal data is necessary for the performance of the contract or steps prior to entering into a contract. Without this data, we cannot conclude a contract with you.
3.7. Customer care and marketing for own purposes
Purpose: Processing of own or purchased customer and prospect data for the initiation of business concerning the own supply or service offering as well as for the implementation of advertising measures and newsletter dispatch; Customer Relationship Management.
Data subjects: Suppliers, customers
Legal basis: Consent (Art 6(1)(a) GDPR), performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR), compliance with a legal obligation (Art 6(1)(c) GDPR), legitimate interest (Art 6(1)(f) GDPR)
Legitimate interests: Defence, exercise and enforcement of legal claims; evaluation of opening rates and statistics on the success of our campaigns to optimise customer communication; economic interest in customer and supplier retention.
The following data is processed for newsletter dispatch via our website: Master data
Storage period: The data may be stored until the expiry of the third year after the last contact with the client, unless longer contractual or legal retention periods exist.
Recipients / Recipient categories: Company of the analysis service / service provider
3.8. Payment systems
3.8.1. PayPal
PayPal is an online payment service for which you need your own PayPal account. The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.
Purpose: Processing of online payments
Data subjects: Users who order chargeable content and select this payment service provider
Legal basis: Consent (Art 6(1)(a) GDPR), performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR), legitimate interest (Art 6(1)(f) GDPR), Section 165(3) TKG 2021.
Legitimate interests: Integration and offering of different payment systems, display and forwarding of requests to payment service providers, analysis of abandoned transactions to optimise processes, defence, exercise and enforcement of legal claims.
The following data is processed: PayPal ID, master data, contract data, IP address, device data for the establishment and technical processing of the payment, in particular IP address, date and time of the request, time zone difference to GMT, content of the request (specific page), access status/HTTP status code, amount of data transferred in each case, requesting website, browser, operating system and interface, language and version of the browser software.
Storage period: Until completion of the payment processing including the period for processing a refund. Certain invoice data is also stored for the duration of the legal retention period of seven years.
Recipients / Recipient categories: Online payment service provider and the sub-payment service provider selected by the user, processors
Further information on the online payment service provider can be found here: https://www.paypal.com/de/legalhub/paypal/privacy-full
3.8.2. Stripe Payments
Stripe is an online payment service for which you need your own Stripe account. The European operating company of Stripe is Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
Purpose: Processing of online payments
Data subjects: Users who order chargeable content and select this payment service provider
Legal basis: Consent (Art 6(1)(a) GDPR), performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR), legitimate interest (Art 6(1)(f) GDPR), Section 165(3) TKG 2021.
Legitimate interests: Integration and offering of different payment systems; display and forwarding of requests to payment service providers; analysis of abandoned transactions to optimise processes, defence, exercise and enforcement of legal claims.
The following data is processed: First and last name, address, e-mail address, contract data, device data for the establishment and technical processing of the payment, in particular IP address, date and time of the request, time zone difference to GMT, content of the request (specific page), access status/HTTP status code, amount of data transferred in each case, requesting website, browser, operating system and interface, language and version of the browser software.
Storage period: Until completion of the payment processing including the period for processing a refund. Certain invoice data is also stored for the duration of the legal retention period of seven years.
Recipients / Recipient categories: Online payment service provider and the sub-payment service provider selected by the user, processors
Further information on the online payment service provider can be found here: https://stripe.com/en-de/privacy
3.8.3. Coinbase
Coinbase is an online payment service for which you need your own Coinbase account. The European operating companies of Coinbase are Coinbase Ireland Limited (70 Sir John Rogerson’s Quay, Dublin 2, 662881, Ireland), Coinbase Europe Limited (70 Sir John Rogerson’s Quay, Dublin 2, 662881, Ireland) and Coinbase Germany GmbH (Kurfürstendamm 12, 10719 Berlin, Germany).
Purpose: Processing of online payments
Data subjects: Users who order chargeable content and select this payment service provider
Legal basis: Consent (Art 6(1)(a) GDPR), performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR), legitimate interest (Art 6(1)(f) GDPR), Section 165(3) TKG 2021.
Legitimate interests: Integration and offering of different payment systems; display and forwarding of requests to payment service providers; analysis of abandoned transactions to optimise processes; defence, exercise and enforcement of legal claims.
The following data is processed: Transaction data, contract data, master data, device data for the establishment and technical processing of the payment, in particular IP address, date and time of the request, time zone difference to GMT, content of the request (specific page), access status/HTTP status code, amount of data transferred in each case, requesting website, browser, operating system and interface, language and version of the browser software.
Storage period: Until completion of the payment processing including the period for processing a refund. Certain invoice data is also stored for the duration of the legal retention period of seven years.
Recipients / Recipient categories: Online payment service provider, processors
Further information on the online payment service provider can be found here: https://www.coinbase.com/de/legal/privacy
3.9. Applicant management
Purpose: Use and retention of personal data provided by applicants if this data has been provided by the data subject.
Data subjects: Applicants, interested parties
Legal basis: Consent (Art 6(1)(a) GDPR), explicit consent (Art 9(2)(a) GDPR) as well as establishment, exercise and defence of legal claims (Art 9(2)(f) GDPR) and legitimate interest (Art 6(1)(f) GDPR; Art 10 GDPR in conjunction with Section 4(3)(2) DSG)
Legitimate interests: Defence, exercise and enforcement of legal claims; documentation of the selection process, including evaluations and interview notes.
The following data is processed: Master data, CV, voluntarily provided data
Storage period: Applicant data is deleted immediately after the advertised position has been filled or after the expiry of the limitation period under the Equal Treatment Act (7 months), unless consent for retention has been given. Unsolicited applications are kept on file as appropriate, namely until withdrawal by the data subject.
Recipients / Recipient categories: Applicant data is not passed on.
3.10. Social media
Purpose: In addition to our website, we are also present on social networks, in particular YouTube, Instagram, LinkedIn and X (formerly Twitter) to increase awareness of our company and for marketing purposes. If you visit one of our online presences, personal data may be transmitted to the operator of the social network. The operator may also link your profile with ours if you are logged in to the respective network.
Legal basis: Consent (Art 6(1)(a) GDPR), explicit consent (Art 49(1)(a) GDPR)
Data subjects: Visitors to our presences on social media
The following data is processed: Date and time of the actions performed, user ID (only for logged-in users), location data (country/city), language setting, age/gender group (for logged-in users from the user profile), previously visited website, determination of the hardware (computer/mobile device)
Storage period: If a person contacts us on social media, the messages are treated like electronic contact requests via the website (point 3.2). The data is stored until the request has been answered. If legal retention obligations exist, processing will be restricted until then.
Recipients / Recipient categories: Operator of the visited social media platform
3.10.1 YouTube (Google LLC)
YouTube is part of the Google LLC group of companies. The controller for the processing of personal data in the context of using YouTube is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Transfer to the following third countries from a data protection perspective:
USA: Companies that have successfully completed the Data Privacy Framework Program are considered entities with an adequate level of protection under the provisions of the EU-US and Swiss-US Data Privacy Frameworks. It is permissible under data protection law to transfer information to these companies within the framework of the Data Privacy Framework.
Details on the specific data collection and processing by the respective operator can be found under the following links:
https://www.youtube.com/static?gl=DE&template=terms&hl=de and https://policies.google.com/privacy.
Google LLC, the parent company of the YouTube platform, has committed to complying with the requirements of the EU-US and Swiss-US Data Privacy Frameworks by certifying itself for the Data Privacy Framework Program. Information on participation can be found under the search term “Google LLC.” here: https://www.dataprivacyframework.gov/s/participant-search
3.10.2 Facebook, Instagram (Meta Inc.)
Facebook and Instagram belong to Meta Inc. The services are operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, which is the controller for the processing of personal data through the use of Facebook and Instagram.
Details on the specific data collection and processing by the respective operator can be found in the following links:
Facebook: https://de-de.facebook.com/about/privacy/ (general privacy policy) and https://www.facebook.com/legal/terms/page_controller_addendum# (specific data collection for Page Insights)
Instagram: https://help.instagram.com/155833707900388
Transfer to the following third countries from a data protection perspective:
USA: Companies that have successfully completed the Data Privacy Framework Program are considered entities with an adequate level of protection under the provisions of the EU-US and Swiss-US Data Privacy Frameworks. It is permissible under data protection law to transfer information to these companies within the framework of the Data Privacy Framework.
Meta Platforms Inc, the parent company of the Facebook and Instagram platforms, has committed to complying with the requirements of the EU-US and Swiss-US Data Privacy Frameworks by certifying itself for the Data Privacy Framework Program. Information on participation can be found under the search term “Meta Platforms, Inc.” here: https://www.dataprivacyframework.gov/s/participant-search.
3.10.3. LinkedIn (Microsoft Corporation)
LinkedIn is part of the Microsoft Corporation group of companies. The controller for the processing of personal data in the context of using LinkedIn services is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
Transfer to the following third countries from a data protection perspective:
USA: For companies that have not completed the Data Privacy Framework Program, an adequate level of protection cannot be guaranteed under the legal requirements.
Details on the specific data collection and processing by the respective operator can be found here:
LinkedIn: https://www.linkedin.com/legal/privacy-policy
LinkedIn relies on the standard contractual clauses issued by the European Commission for international data transfers (SCC). Details can be found here: https://www.linkedin.com/help/linkedin/answer/a1343190?trk=microsites-frontend_legal_privacy-policy&lang=en-us&intendedLocale=en
3.10.4. X (formerly Twitter)
X belongs to the company X Corp. The data protection controller for the operation of the service in the European area is Twitter International Unlimited Company, Fenian Street, D02 F663 Dublin, Ireland.
Transfer to the following third countries from a data protection perspective:
USA: For companies that have not completed the Data Privacy Framework Program, an adequate level of protection cannot be guaranteed under the legal requirements.
Details on the specific data collection and processing by the respective operator can be found in the following links: https://twitter.com/en/privacy
X relies on the standard contractual clauses issued by the European Commission for international data transfers (SCC). Details can be found here:
https://gdpr.x.com/en/controller-to-controller-transfers.html
3.11. Website shop system: WooCommerce
The integration of the webshop on this website is done by means of a plug-in of the open source solution WooCommerce for WordPress. It is provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.
Purpose: Provision of our products and services, processing and handling of orders, transmission of important communications and information about your account or your purchase
Data subjects: Visitors to the website
Legal basis: Consent (Art 6(1)(a) GDPR), legitimate interest (Art 6(1)(f) GDPR)
Legitimate interests: Defence, exercise and enforcement of legal claims; optimisation of our website
The following data is processed: Master data, voluntarily provided data
Storage period: We store your personal data only as long as necessary to fulfil the purposes for which it was collected. If your data is no longer needed, it will be securely deleted or anonymised.
Recipients / Recipient categories: Shipping service providers
Transfer to third countries from a data protection perspective: Yes, USA.
Companies that have successfully completed the Data Privacy Framework Program are considered entities with an adequate level of protection under the provisions of the EU-US and Swiss-US Data Privacy Frameworks. It is permissible under data protection law to transfer information to these companies within the framework of the Data Privacy Framework.
Automattic Inc, the parent company of the webshop platform WooCommerce, has committed to complying with the requirements of the EU-US and Swiss-US Data Privacy Frameworks by certifying itself for the Data Privacy Framework Program. Information on participation can be found under the search term “Automattic, Inc.” here: https://www.dataprivacyframework.gov/s/participant-search.
Further information on the privacy policy of WooCommerce can be found at: https://automattic.com/privacy/
3.12. Images and learning content
3.12.1. Vimeo
The controller for Vimeo is Vimeo Inc, 555 West 18th Street, New York, New York 10011, USA.
Purpose: Preparation and presentation of course content in the member area
Data subjects: Users who use Vimeo
Legal basis: Consent (Art 6(1)(a) GDPR), legitimate interest (Art 6(1)(f) GDPR), performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR)
Legitimate interests: Defence, exercise and enforcement of legal claims
The following data is processed: Usage data, content data
Storage period: We store your personal data only as long as necessary to fulfil the purposes for which it was collected. If your data is no longer needed, it will be securely deleted or anonymised.
Further information on the privacy policy can be found here: https://vimeo.com/privacy
3.12.2. LearnDash
The controller for LearnDash is LearnDash, 2531 Jackson Avenue, Ann Arbor, MI 48103, USA.
Purpose: Preparation and presentation of course content in the member area
Data subjects: Users who use LearnDash
Legal basis: Consent (Art 6(1)(a) GDPR), legitimate interest (Art 6(1)(f) GDPR), performance of a contract or steps prior to entering into a contract (Art 6(1)(b) GDPR)
Legitimate interests: Defence, exercise and enforcement of legal claims
The following data is processed: Usage data
Storage period: We store your personal data only as long as necessary to fulfil the purposes for which it was collected. If your data is no longer needed, it will be securely deleted or anonymised.
Further information on the privacy policy can be found here: https://www.learndash.com/privacy-policy/
3.12.3. YouTube (Google LLC)
YouTube videos are embedded on LearnDash for the presentation of video content. When an embedded YouTube video is started, a connection is established to YouTube servers. This informs YouTube which page you are visiting. In addition, when a video is started, information about user behaviour is collected using cookies – unless cookies are blocked in the browser.
Further information can be found in point 3.10.1. as well as in the YouTube privacy policy: https://policies.google.com/privacy?hl=en&gl=en
4. Information on data transfers to third countries or international organisations
The data processed by us is not transferred to recipients in third countries or international organisations.
5. Change management
This privacy policy is available in its current version on our website. If you have any questions about a previous version, please contact the entity named in point 1.