Data Protection

Privacy Policy

This Privacy Policy explains which personal data Gizuskin processes when you use the academy, for which purposes, on which legal basis, and what rights you have under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

Last updated: 2026-06-24

1. Controller and contact

The controller responsible for the processing of personal data on this website within the meaning of the EU General Data Protection Regulation (GDPR) is Gizuskin ("Gizuskin", "we", "us"). You can reach us using the contact details published in our Imprint. Gizuskin acts as data controller for the personal data processed in connection with your account and your use of the academy.

2. Categories of personal data processed

We process the following categories of personal data: account data (name, email address, password hash, language preference), profile data (professional background you choose to provide), course usage data (lessons viewed, quiz answers, progress, certificates), support communications, technical data (IP address, browser, device identifiers, log files), and cookie/analytics data as described below. Payment-related data is collected and processed by our Merchant of Record Paddle.com and is governed by Paddle's own privacy notice.

3. Purposes and legal basis

We process your personal data for the following purposes and on the following legal bases: (a) creating and operating your account and providing the courses, certificates and downloads you purchased, Art. 6(1)(b) GDPR (performance of contract); (b) responding to support requests, Art. 6(1)(b) and (f) GDPR (contract and legitimate interest); (c) ensuring the security, integrity and abuse prevention of the platform, Art. 6(1)(f) GDPR (legitimate interest); (d) complying with statutory obligations such as tax, accounting and consumer-protection record keeping, Art. 6(1)(c) GDPR; (e) improving the academy on the basis of aggregated usage data, Art. 6(1)(f) GDPR; and (f) sending direct marketing or using analytics/marketing cookies only with your consent, Art. 6(1)(a) GDPR.

4. Recipients and processors

We share personal data only with carefully selected recipients on a need-to-know basis: hosting and infrastructure providers; authentication, database and storage providers; analytics and error-reporting providers used to operate the platform; Paddle.com Inc. and its affiliates, who act as Merchant of Record for all sales and handle payments, billing, tax, invoicing, subscription management and refund processing; email and transactional messaging providers used to deliver receipts, access details and certificates; professional advisers such as lawyers and accountants; and public authorities where we are required to do so by law. Where these recipients act on our behalf, they do so under data processing agreements that comply with Art. 28 GDPR.

5. International data transfers

Some of our service providers, including Paddle, may process personal data outside the European Economic Area, in particular in the United Kingdom and the United States. Where data is transferred to a country without an adequacy decision of the European Commission, we rely on appropriate safeguards within the meaning of Art. 46 GDPR, in particular the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures.

6. Storage period

We keep personal data only as long as necessary for the purposes for which it was collected. Account data is kept for the duration of the account and is deleted on closure, unless statutory retention obligations (e.g. tax and commercial law, typically 6 to 10 years in Germany) require longer retention. Course progress data is kept while your access is active so that you can resume where you left off; aggregated and anonymised data may be kept longer for product improvement. Server log files are kept for a short technical period and then deleted or anonymised. Personal data that is no longer required and not subject to a statutory retention obligation is deleted or anonymised.

7. Your rights (Art. 15 to 22 GDPR)

You have the right to request access to your personal data (Art. 15), rectification of inaccurate data (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw that consent at any time with effect for the future (Art. 7(3)). To exercise these rights, contact us using the details in our Imprint. We will respond within one month in accordance with Art. 12(3) GDPR.

8. Cookies and tracking

We use cookies and similar technologies that are strictly necessary to operate the academy (for example to keep you signed in and to remember your language). Cookies and similar technologies for analytics or marketing are only set with your consent, which you can give or withdraw at any time. You can also manage cookies via your browser settings; disabling strictly necessary cookies may prevent the academy from functioning correctly.

9. Security and right to lodge a complaint

We apply appropriate technical and organisational measures to protect your personal data, in particular transport encryption (TLS), encrypted storage, access controls, role-based permissions, audit logging and regular review of our security posture. Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR).