Privacy Policy

Table of Contents

  • Responsible Party
  • Overview of Processing
  • Legal Bases
  • Security Measures
  • Data Transfer
  • International Data Transfers
  • Rights of Data Subjects
  • Use of Cookies
  • Online Services and Web Hosting
  • Payment Processing
  • Contact and Inquiry Management

Responsible Party

Christian Engelhard

Kreuthof 1

91719 Heidenheim

[email protected]

Overview of Processing

The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects.

Types of Processed Data

  • Contact Data.
  • Content Data.
  • Usage Data.
  • Meta-, Communication- and Process Data.
  • Contract Data.

Categories of Data Subjects

  • Communication Partners.
  • Users.

Purposes of Processing

  • Providing our services.
  • Providing our online offer.
  • User Friendliness.
  • Information Technology Infrastructure.
  • Payment Processing and Contract Fulfillment.

Legal Bases

In the following, we inform you about the legal basis of our data processing operations.

  • Consent (Art. 6(1)(a) GDPR).
  • Contractual Performance and Prior Requests (Art. 6(1)(b) GDPR).
  • Legitimate Interests (Art. 6(1)(f) GDPR).

National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations apply to data protection in Germany. This includes in particular the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). The BDSG contains, inter alia, provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, data processing for other purposes and transmission as well as automated individual decision-making.

Note on the basis of our data protection declaration: The GDPR has a direct effect in the member states of the European Union. The DSGVO is therefore applicable in the member states.

Security Measures

We take appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk.

The measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input, disclosure, ensuring availability and separation of data.

Data Transfer

As part of our processing of personal data, it may happen that the data is transferred to other bodies, companies or persons or that it is disclosed to them. The recipients of this data may include, for example, payment institutions within the framework of order processing, IT service providers or providers of services and content that are integrated into a website.

International Data Transfers

In the course of our processing of personal data, it may happen that the data is transferred to other bodies, companies or persons or that it is disclosed to them in a third country i.e. outside the European Union (EU), the European Economic Area (EEA) or the Swiss Confederation.

The recipients of this data may include, for example, international IT service providers or providers of services and content that are integrated into a website.

EU-US Trans-Atlantic Data Privacy Framework

The EU-US Trans-Atlantic Data Privacy Framework is an intergovernmental agreement between the United States of America and the European Union on the basis of which the European Commission has issued an adequacy decision for the United States. The framework provides that the data protection standards of the GDPR are essentially reflected in the United States, which is why the United States is considered a secure third country for data transfers from the EU.

Rights of Data Subjects

You have the following rights, which you can exercise at any time by contacting the responsible party mentioned at the beginning of this privacy policy:

  • Right of objection: You have the right to object to the processing of your personal data at any time.
  • Right to rectification: You have the right to request the rectification of inaccurate personal data concerning you without undue delay.
  • Right to erasure: You have the right to request the erasure of personal data concerning you without undue delay.
  • Right to restriction of processing: You have the right to request the restriction of processing of your personal data.
  • Right to data portability: You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller.
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR.

Use of Cookies

This Website doesn't use any cookies.

Provision of Online Services and Web Hosting

We process user data in order to provide them with our online services...

  • Processed data types: Usage data...
  • Data subjects: Users...
  • Purposes of processing: Provision of our online services...
  • Legal bases: Legitimate interests...

Further Information on Processing Procedures

Collection of access data and log files: Access to our online service is logged in the form of so-called "server log files"...

Payment Processing

As part of contractual and business relationships, we process data for payment processing. The processing is carried out to fulfill contractual obligations and due to legal requirements.

Payment Service Providers Used

Whop Shop

When paying via Whop Shop, your payment data will be transmitted to Whop Shop as part of the payment processing. The data processing is carried out on the basis of Art. 6(1)(b) GDPR (contractual performance).

PayPal

When paying via PayPal, your data will be transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. The data transfer takes place in accordance with Art. 6(1)(b) GDPR.

Stripe

When using Stripe as a payment method, your data will be forwarded to Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The transfer takes place in accordance with Art. 6(1)(b) GDPR exclusively for payment processing.

Processed Data

  • Inventory data (e.g., names, addresses)
  • Payment data (e.g., bank details, invoices)
  • Contract data (e.g., subject matter of contract, term)
  • Usage data (e.g., access times, visited websites)
  • Communication data (e.g., device information, IP addresses)

Legal bases: Contractual performance and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legal obligation (Art. 6(1)(c) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).

Contact and Inquiry Management

When contacting us and within the framework of existing user and business relationships, the information of the inquiring persons is processed...

  • Processed data types: Contact data...
  • Data subjects: Communication partners.
  • Purposes of processing: Contact requests and communication...
  • Legal bases: Legitimate interests...

Further Information on Processing Procedures

Contact form: When users contact us via our contact form, email, or other communication channels...