Privacy Policy
How we collect, use, retain, and protect personal data.
1. Data protection at a glance
General information
This policy explains what happens to personal data when you use this website. Personal data is any information that can identify you directly or indirectly.
How data is collected
We receive data that you provide, for example when you create or use an account, book training, complete a form, or contact us. Our systems also record technical data such as browser type, operating system, IP address, and access time when you visit the website.
Why data is processed
Some data is necessary to operate the website reliably and securely. Other data is used to provide training and account services, process contracts and payments, answer enquiries, or understand how the website is used.
2. Controller and general information
Controller
thePHP.cc OHGPoignring 24
82515 Wolfratshausen
Germany
Phone: +49.8171.428058
Email: privacy@thephp.cc
The controller determines the purposes and means of processing personal data. We treat your information confidentially and in accordance with applicable data protection law. Internet communication, including email, can nevertheless have security gaps and cannot be protected completely against third-party access.
Legal bases
Depending on the purpose, processing is based on your consent (Article 6(1)(a) GDPR), performance of a contract or pre-contractual steps (Article 6(1)(b) GDPR), a legal obligation (Article 6(1)(c) GDPR), or our legitimate interests (Article 6(1)(f) GDPR). Where special categories of data or transfers to third countries require consent, Articles 9(2)(a) and 49(1)(a) GDPR may also apply. Access to or storage of information on your device is based on Section 25 TDDDG where applicable.
Recipients and retention
Personal data is shared with external parties only where this is required for a contract, permitted by a legal basis, or required by law. Processors act under an appropriate data processing agreement. We retain data until its purpose no longer applies, unless statutory retention duties or another lawful reason require longer storage.
Your data protection rights
You may request information about your stored data, its origin, recipients, and purpose. You may also request correction, deletion, restriction of processing, or delivery of eligible data in a commonly used machine-readable format. Consent can be withdrawn at any time for future processing.
Where processing relies on Article 6(1)(e) or (f) GDPR, you may object for reasons arising from your particular situation. You may object to direct marketing at any time. You also have the right to lodge a complaint with a competent supervisory authority. Contact privacy@thephp.cc to exercise these rights.
Encryption
This website uses SSL or TLS encryption to protect confidential information in transit. An encrypted connection is indicated by an HTTPS address and the lock symbol in your browser.
3. Data recorded by this website
Cookies
Cookies are small data packages stored temporarily for a session or for a longer period. Essential cookies support functions such as authentication and secure account use. They are used on the basis of our legitimate interest in providing a reliable service, unless consent is required. You can restrict or delete cookies in your browser; doing so may limit website functionality.
Server log files
Our provider automatically records browser type and version, operating system, referrer URL, host name, request time, and IP address. These records are not merged with other sources and are processed under Article 6(1)(f) GDPR to operate, secure, and optimise the website.
Academy page visits
The Academy records the page address, including its query parameters, and the access time when a page is displayed. For a session associated with an account, the visit is associated with that account. Otherwise, the session identifier, IP address, and browser user-agent information are recorded with the visit. This information is used to understand how the Academy is used.
Accounts, bookings, and contact requests
Information submitted through accounts, booking workflows, forms, email, or telephone is processed to provide the requested service and handle follow-up questions. The basis is Article 6(1)(b) GDPR for contractual matters and otherwise consent or our legitimate interest in responding effectively. The information is retained until you request deletion, withdraw consent, or its purpose ends, subject to mandatory retention periods.
4. Analytics and external services
Plausible Analytics
We may use Plausible Analytics to evaluate website usage. It processes information such as page and referrer URLs, browser, operating system, device type, request data, and IP address. Request and IP information may be hashed temporarily. Processing is based on consent where requested, or otherwise on our legitimate interest in understanding website use.
Forms and appointment booking
Forms may be provided through Jotform Inc., and appointment scheduling may use Zeeg GmbH. These services process the entries and booking details you provide, together with necessary technical metadata. Where data is transferred outside the European Economic Area, appropriate safeguards such as standard contractual clauses or participation in the EU-US Data Privacy Framework are used.
Video services
Embedded YouTube or Vimeo videos can establish a connection to the provider after activation. The provider may receive the page visited, IP address, and technical information. We use privacy-enhanced or do-not-track modes where available. The legal basis is consent where requested and otherwise our legitimate interest in presenting useful media content.
5. Newsletter
Newsletter subscriptions require an email address and information needed to confirm ownership and consent. This data is used only to send the requested information. You can unsubscribe at any time. After unsubscribing, the address may be retained on a suppression list where necessary to prevent further mailings.
6. Contracts and payments
Customer and contract data is processed to establish, perform, and change contractual relationships. It is deleted after the relationship ends and statutory retention periods expire. Data is disclosed to payment providers only as needed to process a transaction. Payment services may include PayPal and Stripe; their own contractual and privacy terms also apply.
7. Online conferences
We may use conference services such as Zoom to communicate and deliver services. The providers process account and contact details, meeting metadata, technical device and connection data, and any content shared during a meeting. The legal basis is performance of a contract, consent where requested, or our legitimate interest in efficient communication. Data controlled by us is deleted when its purpose ends unless a retention duty applies; provider retention is governed by the provider's own policy.
Adapted for this website from the thePHP.cc Privacy Policy.