Privacy Policy

Note on the current status: This policy reflects the currently known technical configuration of German Pro Academy. Google Analytics, Meta Pixel, and other marketing or tracking services requiring consent are not activated as of the date of this version and are therefore not described as active processing. Prior to their activation, this policy and the consent management system must be updated.

Privacy Policy German Pro Academy for the Website, Online Training, Purchase, and Use of the Learning Platform Effective as of August 4, 2026

Contents

1. Data Controller and Contact Information

2. Scope and Principles

3. Legal Basis

4. Provision of the Framer Website

5. Framer Analytics

6. Provision of the Learning Platform via Replit

7. Server Logs and Security

8. Purchases and Payment Processing via Stripe

9. Activation Code and Device Activation

10. AI-powered learning feedback

11. Module feedback

12. Contact and Google Workspace

13. Cookies and Similar Technologies

14. Recipients and Data Processors

15. Transfers to Third Countries

16. Retention Period and Deletion

17. Obligation to Provide Data

18. Automated Decision-Making

19. Rights of Data Subjects

20. Right to File a Complaint

21. Data Security

22. Changes to This Statement

Appendix: Overview of Processing Activities Appendix: Provider Information

1. Data Controller and Contact Information

The data controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection regulations is:

German Pro Academy

Inhaber: Jens Steckler

c/o PostCloud 93824

Otto-Kraus-Straße 10

90411 Nürnberg

Deutschland

E-Mail: hello@germanproacademy.com

A Data Protection Officer has not yet been appointed. Data protection inquiries may be directed directly to the email address provided above.

2. Scope and Principles

This Privacy Policy provides information about the processing of personal data when using the germanproacademy.com website, when accessing and using the learning platform provided via Replit, when making purchases via Stripe, when activating purchased training courses, when using the AI-powered feedback feature, as well as when submitting voluntary module evaluations and contacting us via email.

We process personal data in accordance with the principles of lawfulness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. No user accounts are created. Names, email addresses, or passwords are not stored as user profiles on the learning platform.

Personal data is any information relating to an identified or identifiable natural person. This may include, in particular, names, email addresses, IP addresses, payment information, technical identifiers, and the contents of free-text fields.

3. Legal Bases

We process personal data in particular on the following legal bases:

• Contract performance: Article 6(1)(b) GDPR. • Legal obligations: Article 6(1)(c) GDPR. • Legitimate interests, including secure operation: Article 6(1)(f) GDPR. • Consent, where expressly obtained: Article 6(1)(a) GDPR.

4. Provision of the Framer Website

The public landing page is provided using Framer. The provider is Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands. When you access the website, technically necessary connection data is processed. This may include, in particular, the IP address, the date and time of access, the resource accessed, the amount of data transferred, the referrer URL, the browser type, the operating system, and error or security information.

This processing serves to deliver the website, ensure stability and security, and detect abusive or malicious access attempts. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure and functional provision of our online services.

Framer processes data as a data processor in accordance with its contractual data protection terms. According to the published security information, Framer uses infrastructure in the United States for its services. Section 15 contains further details on international transfers.

5. Framer Analytics

For the landing page, the privacy-focused visitor statistics integrated into Framer may be used. According to Framer, these statistics do not use cookies or persistent identifiers and are not intended to collect data that identifies individual website visitors. Aggregated usage metrics, such as page views or general access statistics, are displayed.

To the extent that any personal data is involved at all, processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the purely aggregated evaluation of the reach and technical usage of our website. Google Analytics, Meta Pixel, and comparable third-party tracking services are not activated as of the date of this statement.

6. Provision of LernplaNorm via Replit

The interactive learning platform, including the front end, API server, and PostgreSQL database, is hosted via Replit. The provider is Replit, Inc., United States. The production deployment was published in the Europe (EU) region; according to the current configuration, computing power and the production database are located in this region.

When you access the learning platform, Replit, as the infrastructure and hosting provider, processes technically necessary data, including, in particular, your IP address, the time and destination of your access, browser and device information, as well as server-side log and security data. This processing is necessary to deliver the learning platform, detect attacks and technical malfunctions, and ensure secure operation. The legal basis is Article 6(1)(f) of the GDPR.

According to the current implementation, the following data records are stored in the Replit PostgreSQL database:

indirectly linked to a transaction or a device and are therefore treated as pseudonymous personal data as a precaution.

Replit manages automatic database backups within its infrastructure. The specific retention period depends on the Replit plan subscribed to and the applicable backup and deletion periods for that plan. We do not store separate backup copies of users’ personal data that are independent of Replit.

7. Server Logs and Security

The API server uses structured technical logging. According to the current configuration, query parameters and request bodies are not included in the application logs. Due to infrastructure requirements, Replit and, where applicable, other technical subcontractors may process connection and security data. The retention of these platform logs is governed by the hosting provider’s specifications and settings.

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in error diagnosis, IT security, attack detection, and maintaining availability.

8. Purchases and Payment Processing via Stripe

For one-time purchases of training access, we use Stripe Checkout. The payment page is provided by Stripe. Depending on the country and the selected payment method, Stripe may directly collect and process, in particular, your name, email address, billing address, payment information, card details, transaction data, IP address, and fraud prevention data.

Complete card or account details are not transmitted to our server and are not stored by us.

Our application receives and stores only technical payment references, specifically the Stripe session ID and the Payment Intent ID, as well as the activation code generated from a successful payment.

This processing is necessary for the performance of the sales contract and for payment processing. The legal basis is Article 6(1)(b) of the GDPR. To the extent that data must be retained to fulfill tax or commercial law obligations, the processing is based on Article 6(1)(c) of the GDPR. Stripe also processes certain data under its own responsibility, for example, to comply with regulatory obligations, prevent fraud, and ensure security.

Activation is triggered on the server side via a signed Stripe webhook event of the type “checkout.session.completed.” This verifies whether the payment was successfully completed before an activation code is generated.

9. Activation Code and Device Activation

After a successful payment, an activation code is generated. This code can be activated on up to two different devices according to the specified product logic. For each activated device, a randomly generated UUID device token is stored. By design, the device token does not contain any directly identifying information such as a name or email address.

The “mad_device” cookie is set in the browser. It contains the random device token and serves solely to recognize the already activated device and provide the purchased access without requiring re-login. The cookie is configured as HttpOnly, is transmitted via secure connections in the production environment, uses SameSite=Lax, and has an intended lifetime of one year.

This processing is necessary to provide the purchased digital content. The legal basis is Article 6(1)(b) of the GDPR. Setting the cookie is absolutely necessary to provide the expressly requested access permanently on the activated device; therefore, consent is not required under Section 25(2)(2) of the TDDDG.

The user can delete the cookie in the browser settings. In this case, reactivation may be necessary; depending on the number of device slots already used, activation may be restricted. In justified support cases, we can perform a technical check and, if necessary, reset the cookie.

10. AI-Powered Learning Feedback

In selected exercises, users can enter their own free-text responses and request AI- powered feedback on grammar, naturalness, and business communication. This feature uses the OpenAI Chat Completions API via the Replit AI Integrations Proxy. Replit acts as a technical intermediary; the actual model processing is performed by OpenAI.

• The specified system prompt regarding the desired feedback. • The predefined context of the fictional meeting scenario. • The selected, predefined response option. • The free-text response entered by the user.

The following information is transmitted to the AI processing system:

To the extent that the feature is part of the purchased training, processing is carried out for the purpose of fulfilling the contract in accordance with Article 6(1)(b) of the GDPR. For exercises provided free of charge, processing is based on Article 6(1)(f) of the GDPR; our legitimate interest lies in providing an interactive learning feature actively requested by the user. Users decide for themselves whether to submit a free-text response.

11. Module Feedback

At the end of a module, users may voluntarily submit feedback. The following information is stored: the module ID, a star rating from 1 to 5, an optional recommendation checkbox, an optional free-text comment, and the time of submission. The feedback is not linked to a user account, email address, activation code, device token, or payment information.

Since the comment field is open-ended, users may voluntarily enter personal information there. We ask that you do not include names, contact information, or any other personal or confidential information in the comment field.

Processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in quality control and the further development of learning content. Participation is voluntary. Free- text comments are deleted or anonymized when they are no longer needed for evaluation and product improvement or when a valid request for deletion is received, provided there are no overriding legal grounds to the contrary.

12. Contact and Google Workspace

When you contact us viahello@germanproacademy.com or another business email address, we process the data you provide, including, in particular, your email address, name, message content, attachments, and communication and time-stamp data. Email communication is provided via Google Workspace. For users in the European Economic Area, the service provider is typically Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Processing is based on Article 6(1)(b) of the GDPR for contract-related inquiries and on Article 6(1)(f) of the GDPR for general inquiries. Our legitimate interest lies in the proper handling of inquiries and business communication.

Emails are deleted as soon as they are no longer needed for processing and documentation, provided there are no legal retention requirements or legitimate interests in storing them for a longer period. Business and tax-related correspondence may be stored in accordance with statutory retention periods.

13. Cookies and Similar Technologies

As of the date of this statement, the learning platform uses only the technically necessary cookie “mad_device” described in Section 9. According to the latest code review, the application does not use localStorage, sessionStorage, IndexedDB, Service Workers, or any other persistent browser-side storage.

According to Framer’s specifications for Framer Analytics, the landing page does not use cookies or persistent identifiers. External Google fonts are not loaded; the Inter font is bundled and delivered locally within the learning application.

Google Analytics, Meta Pixel, and other non-essential tracking or marketing technologies are currently inactive. Before activating them, we will set up an appropriate consent management system that blocks non-essential technologies until consent is given, allows for an equivalent opt-out, offers granular settings, and refers to an updated cookie policy or privacy policy.

14. Recipients and Processors

Personal data is disclosed to recipients only to the extent necessary to provide the respective service, fulfill contractual obligations, comply with legal obligations, or protect legitimate interests. The service providers used include, in particular:

15. Transfers to Third Countries

Some of the service providers we use, or their subprocessors, are based or have technical infrastructure outside the European Economic Area, particularly in the United States. This applies in particular to certain aspects of processing carried out by Framer, Replit, Stripe, OpenAI, and Google.

Transfers to third countries take place only to the extent that the requirements of Articles 44 et seq. of the GDPR are met. Depending on the provider and the nature of the processing, measures such as adequacy decisions by the European Commission, certification under the EU-US Data Privacy Framework, standard contractual clauses of the European Commission, and supplementary technical and organizational measures may be employed. Details can be found in the privacy policies and data processing terms of the respective provider.

According to the current configuration, the production Replit deployment and the associated database are located in the Europe (EU) region. This does not preclude the possibility that Replit, as a U.S.

company or its subcontractors may process data outside the EEA in certain support, security, or service situations.

16. Retention Period and Deletion

We store personal data only for as long as is necessary for the respective purpose or as required by statutory retention obligations. Relevant criteria include, in particular, the duration of the contractual relationship, the usability of purchased accesses, the need to defend against or enforce claims, technical security requirements, and commercial and tax law provisions.

In particular, the following principles apply:

17. Obligation to Provide Data

The provision of certain data is required if you wish to complete a purchase, make a payment, activate training access, or receive AI feedback you have requested. Without the required data in each case, the relevant function cannot be provided.

Providing module feedback and entering a free-text comment are voluntary. Contacting us via email is also voluntary; however, we cannot respond without your contact information.

18. Automated Decisions

We do not make any decisions within the meaning of Article 22 of the GDPR that are based solely on automated processing and that produce legal effects on you or similarly significantly affect you.

The AI-powered feedback is intended solely for learning and practice purposes. It does not constitute a binding evaluation, examination, personnel decision, or any other decision with legal or similarly significant effects.

• Access to personal data. • Rectification of inaccurate data. • Erasure and restriction of processing. • Data portability. • Objection to processing. • Withdrawal of consent. • Protection against solely automated decisions.

19. Rights of Data Subjects

Provided that the legal requirements are met, data subjects have the following rights in particular:

20. Right to object under Article 21 of the GDPR

To the extent that we process personal data on the basis of Article 6(1)(f) of the GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation. We will then no longer process the data in question unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

21. Right to File a Complaint

Under Article 77 of the GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law. In particular, you may contact the supervisory authority of your usual place of residence, your place of work, or the location of the alleged violation.

Depending on administrative jurisdiction, the competent Bavarian data protection supervisory authority may be the relevant authority for the data controller. However, you may contact any supervisory authority competent under Article 77 of the GDPR, regardless of this.

22. Data Security

We take appropriate technical and organizational measures to protect personal data from loss, manipulation, unauthorized access, and other unlawful processing. These include, in particular, encrypted transmission, access restrictions, server-side secret management, separate production and development environments, secure webhook verification, HttpOnly and Secure cookie settings, data minimization, the absence of user accounts, and the limitation of request content logging.

Despite appropriate measures, data transmission over the Internet cannot be made completely risk-free. We review our security measures on a risk-based basis and adjust them as needed.

23. Changes to This Privacy Policy

We update this Privacy Policy when the services we use, data flows, legal requirements, or our offerings change. The version published on the website is authoritative. In the event of significant changes, we may also provide additional notice in an appropriate manner.

Before activating Google Analytics, Meta Pixel, newsletter services, externally embedded media, or other tracking or marketing technologies, this Privacy Policy will be supplemented and—where necessary—prior consent will be obtained via a consent management solution.

Appendix 2: Provider Information and Additional Notes

Framer B.V.: Rozengracht 207B, 1016 LZ Amsterdam, Netherlands Data Protection: https://www.framer.com/legal/privacy-statement Contract/DPA Information: https://www.framer.com/legal/data-processing-addendum/2.0 Replit, Inc.: United States; production deployment by German Pro Academy: Europe (EU) Privacy Policy: https://replit.com/privacy-policy Contract/DPA Information: https://replit.com/site/dpa/ Stripe: The applicable Stripe entity, depending on the contract and payment service Data protection: https://stripe.com/de/privacy Contract/DPA Information: https://stripe.com/legal/dpa OpenAI: For EEA-related services, specifically OpenAI Ireland Limited, Dublin, Ireland Data Protection: https://openai.com/de-DE/policies/eu-privacy-policy/ Contract/DPA Information: https://openai.com/de-DE/enterprise-privacy/ Google Workspace: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Privacy Policy: https://policies.google.com/privacy Contract/DPA Information: https://workspace.google.com/terms/dpa_terms.html

Document Status

Version 1.0 - Effective August 4, 2026

This version reflects the current status as documented at the time of creation. It must be reviewed and updated prior to the use of any additional services, in particular Google Analytics, Google Tag Manager, Meta Pixel, newsletter, CRM, video, or appointment booking services, whenever such services are activated.