1. Overview
This Privacy Policy explains how SmarterGerman ("we," "our," "us") collects, uses, and protects your personal information when you use our website (smartergerman.com) and online German language courses.
We are committed to protecting your privacy and complying with:
- The EU General Data Protection Regulation (GDPR)
- German Federal Data Protection Act (BDSG)
- German Telecommunications-Telemedia Data Protection Act (TTDSG)
- California Consumer Privacy Act (CCPA/CPRA)
- Strato AG – Datenschutzerklärung
- Amazon Web Services (SES) – Data Privacy
- CCM19 – Datenschutzerklärung
2. Data Controller
Friedelstraße 38
12047 Berlin, Germany
Email: privacy@smartergerman.com
Phone: +49 15167318894
VAT ID: DE288541978
For any privacy-related questions or to exercise your rights, please contact us using the information above.
3. What Data We Collect
We collect different types of data depending on how you interact with our services:
3.1 Data You Provide Directly
- Account Information: Name, email address, password (encrypted)
- Course Enrollment: Course selections, progress data, completion status
- Payment Information: Processed by our payment providers (Teachable, LemonSqueezy) - we never store credit card details
- Communications: Messages sent via contact forms, support requests, newsletter subscriptions
3.2 Data Collected Automatically
- Technical Data: IP address (anonymized), browser type, operating system, device information
- Usage Data: Pages visited, time spent, referring website, course interaction data
- Cookies: Session cookies, preference cookies, analytics cookies (with consent)
3.3 Data from Third Parties
- Teachable: Course enrollment confirmations, completion status
- Payment Processors: Transaction confirmations (no payment details)
- Analytics Providers: Aggregated usage statistics (with consent)
4. How We Use Your Data
Purpose | Data Types | Legal Basis |
---|---|---|
Provide course access | Account data, enrollment data | Contract fulfillment |
Process payments | Transaction data | Contract fulfillment |
Send course updates | Email, enrollment data | Legitimate interest |
Marketing (newsletter) | Email, preferences | Consent |
Website security | Technical data, logs | Legitimate interest |
Analytics | Usage data | Consent |
Legal compliance | Billing records | Legal obligation |
5. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
5.1 Contract Performance (Art. 6(1)(b) GDPR)
To provide access to courses you've enrolled in and process your registration.
5.2 Consent (Art. 6(1)(a) GDPR)
For marketing emails, analytics cookies, and optional tracking. You can withdraw consent anytime.
5.3 Legal Obligations (Art. 6(1)(c) GDPR)
To comply with German tax law and maintain required business records.
5.4 Legitimate Interests (Art. 6(1)(f) GDPR)
For website security, fraud prevention, and essential service communications. We've conducted a balancing test to ensure our interests don't override your rights.
6. Who We Share Data With
We only share your data with carefully selected service providers who help us deliver our services:
6.1 Service Providers (Data Processors)
- Teachable, Inc. (USA) - Course platform and hosting
Privacy Policy: https://teachable.com/privacy-policy - LemonSqueezy (Netherlands/USA) - Payment processing
Privacy Policy: https://www.lemonsqueezy.com/privacy - Strato AG (Germany) - Website hosting and email services
- Amazon SES (Germany/EU) - Email delivery
- CCM19 (Germany) - Cookie consent management
6.2 Analytics and Marketing (with consent)
- Google Ireland Limited - Google Analytics, Google Ads
Privacy Policy: https://policies.google.com/privacy - Meta Platforms Ireland - Facebook Pixel
Privacy Policy: https://www.facebook.com/privacy/policy
We never sell your personal data to third parties.
7. How Long We Keep Your Data
Data Type | Retention Period | Reason |
---|---|---|
Course access data | Duration of enrollment + 1 year | Service provision |
Payment/billing records | 8 years (German tax law) | Legal requirement |
Customer support emails | 6 years | German commercial law |
Newsletter data | Until unsubscribe | Consent-based |
Server logs | 90 days | Security monitoring |
Analytics data | 14 months | Service improvement |
Note: Unsubscribe records are kept indefinitely to prevent re-enrollment through automated systems.
8. Your Privacy Rights
Under GDPR, you have the following rights:
8.1 Right to Access (Art. 15 GDPR)
Request a copy of your personal data and information about how we process it.
8.2 Right to Rectification (Art. 16 GDPR)
Request correction of inaccurate or incomplete personal data.
8.3 Right to Erasure (Art. 17 GDPR)
Request deletion of your data, subject to legal retention requirements.
8.4 Right to Restriction (Art. 18 GDPR)
Request we limit processing while disputes are resolved.
8.5 Right to Data Portability (Art. 20 GDPR)
Receive your data in a structured, machine-readable format.
8.6 Right to Object (Art. 21 GDPR)
Object to processing based on legitimate interests or for direct marketing.
8.7 Right to Withdraw Consent
Withdraw consent for consent-based processing at any time.
8.8 Right to Complain
Lodge a complaint with your local data protection authority.
9. International Data Transfers
Some of our service providers are located outside the EU. We ensure adequate protection through:
9.1 Standard Contractual Clauses (SCCs)
We have EU Commission-approved SCCs in place with:
- Teachable, Inc. (USA)
- Google LLC (for Analytics and Ads)
- Meta Platforms, Inc. (for Facebook services)
9.2 Additional Safeguards
- Data encryption in transit and at rest
- Limited access on a need-to-know basis
- Regular security assessments
For transparency, we acknowledge that US authorities may access data stored by US providers under US law. We minimize this risk through technical and contractual measures.
10. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption: SSL/TLS for all data transmissions
- Access Control: Role-based access, strong authentication
- Regular Updates: Security patches and system updates
- Incident Response: Procedures for breach detection and notification
- Staff Training: Regular privacy and security training
As part of our efforts to protect this website and our users from abuse and automated spam, we temporarily log the IP addresses of form submissions and check them against the public threat database AbuseIPDB. This processing is based on our legitimate interest in ensuring platform security (Art. 6(1)(f) GDPR). These IP addresses are stored securely and deleted automatically after 7 days. They are not used for profiling or marketing purposes.
Despite our measures, no internet transmission is 100% secure. We'll notify you and authorities of any breach as required by law.
11. Cookies and Tracking Technologies
We use cookies and similar technologies to improve your experience. You control which cookies we use through our consent tool.
11.1 Essential Cookies (No consent required)
- Session management
- Security features
- Load balancing
11.2 Analytics Cookies (Consent required)
Opt-Out Options:
- Google Analytics: Browser add-on
- Google Ads (personalised ads): Ads Settings
- Facebook / Meta ads: Ad Preferences or the DAA opt-out (DAA, DAAC-CA, EDAA)
- Google Analytics (anonymized IP)
- Usage patterns and popular content
11.3 Marketing Cookies (Consent required)
- Google Ads remarketing
- Facebook Pixel
11.4 Do Not Track
We respect Global Privacy Control (GPC) signals and Do Not Track browser settings.
11.5 Other Third-Party Cookies
YouTube Videos: We embed YouTube videos on our website. When a YouTube video is loaded or played, YouTube may set cookies or run scripts to track video playback, analyze usage data, and personalize content. This may involve collecting your IP address and browser information. For more information, please visit YouTube’s Privacy Policy.
Amazon Advertising: Our site displays Amazon advertising content, which may set cookies or run scripts to serve personalized ads, track ad impressions, and measure campaign effectiveness. Data such as your IP address, device type, and browsing activity may be processed by Amazon. For details, see the Amazon Privacy Notice.
Twitter: Embedded Twitter widgets (such as timelines, tweets, or share buttons) may set cookies or run scripts to enhance functionality and collect data about your interactions. This may include your IP address, device details, and user interactions. See the Twitter Privacy Policy for more information.
Vimeo: When you interact with Vimeo videos embedded on our site, Vimeo may set cookies or run scripts to enable video playback and collect analytics on viewing behavior. Information such as your IP address and device/browser information may be collected. Further information is available in the Vimeo Privacy Policy.
12. Children's Privacy
Our services are not directed to children under 16. We do not knowingly collect personal data from children under 16 without parental consent.
If you believe we've collected data from a child under 16, please contact us immediately at privacy@smartergerman.com for deletion.
13. California Privacy Rights (CCPA/CPRA)
This section applies only to California residents.
13.1 Personal Information We Collect
In the last 12 months, we've collected these categories:
- Identifiers: Name, email, IP address
- Commercial Information: Course purchases, transaction history
- Internet Activity: Browsing history on our site, interaction with courses
- Education Information: Course progress and completion
13.2 How We Use Personal Information
- Providing and personalizing our services
- Processing transactions
- Communicating with you
- Improving our services
- Legal compliance
13.3 Your California Rights
- Right to Know: Request categories and specific pieces of personal information
- Right to Delete: Request deletion (subject to exceptions)
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: We do not sell or share personal information
- Non-Discrimination: We won't discriminate for exercising rights
13.4 Exercising Your Rights
California residents can submit requests:
- Email: privacy@smartergerman.com
- Include "California Privacy Request" in subject
- We'll verify your identity before processing
13.5 Do Not Sell or Share
We do not “sell” personal information for money. We do, however, disclose certain identifiers (IP address, cookie ID) to Google and Meta to show you personalised advertising. Under the CPRA this constitutes “sharing”. You may opt-out at any time by clicking the “Do Not Sell or Share My Personal Information” link in the footer or by enabling the Global Privacy Control (GPC) signal in your browser. We honour both mechanisms.
13.6 Sensitive Personal Information
We do not collect sensitive personal information as defined by CPRA.
14. Changes to This Policy
We may update this policy to reflect changes in law or our practices. We'll notify you of material changes by:
- Posting a prominent notice on our website
- Sending an email to registered users
- Updating the "Last Updated" date
Continued use after changes constitutes acceptance of the updated policy.
15. Contact Information
For Privacy Inquiries:
Email: privacy@smartergerman.comPhone: +49 15167318894
Mail: Michael Schmitz, Friedelstraße 38, 12047 Berlin, Germany
Supervisory Authorities:
Germany: Berliner Beauftragte für Datenschutz und Informationsfreiheit
Website: www.datenschutz-berlin.de
EU: You may also contact your local data protection authority.
Thank you for taking the time to read our privacy policy. Your privacy matters to us, and we're committed to protecting your personal data while providing excellent German language education.