Privacy policy
This privacy policy applies to the website certification-course.com and to the
course area of the CertPath app.
1. Controller
Ralf EisendReschstr. 2a
81825 München
Germany
For data protection enquiries, contact us at
support@certification-course.com. No data protection officer has been
appointed, as the statutory conditions for a mandatory appointment are not met.
2. Overview and principles
We process personal data only to the extent necessary to provide the website, the courses and the services connected with them (data minimisation). The legal bases are Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interest, e.g. secure operation) and Art. 6(1)(a) GDPR (consent, e.g. statistics). Where a provider processes personal data on our behalf, a data processing agreement under Art. 28 GDPR is in place; for providers outside the EU we base transfers on EU standard contractual clauses or the EU-US Data Privacy Framework (details in section 7).
In short: without an account, visiting this website only involves technically necessary connection data plus, where applicable, our reach measurement (Google Analytics). In the EEA, the United Kingdom and Switzerland that measurement runs only after you consent; elsewhere it is on by default and you can switch it off at any time — section 6 explains both cases. With an account, the data needed for your purchase and for running the course is added.
3. Hosting and delivery
- Cloudflare (Cloudflare, Inc., USA): hosting of this website (Cloudflare Pages), DNS and content delivery network. When you access the site, Cloudflare processes technically necessary connection data (IP address, time, requested resource) for delivery and to defend against attacks. Legal basis: Art. 6(1)(f) GDPR.
- Fly.io (Fly.io, Inc., USA): hosting of the course area and of the database in the Frankfurt (EU) region. Legal basis: Art. 6(1)(b) GDPR.
4. Account, purchase and running the course
These processing activities concern you once you buy a course or an account is created for you (legal basis in each case Art. 6(1)(b) GDPR unless stated otherwise):
- Clerk (Clerk, Inc., USA): creation, sign-in and management of your user account (email address, sign-in data). Accounts are passwordless — you sign in with your email address.
- Stripe (Stripe Payments Europe, Ltd., Ireland): payment processing and invoicing for the one-time course purchase. To do this, Stripe collects your email address and billing address, and a VAT ID if you provide one. Stripe processes some of this data under its own responsibility; invoice data is subject to statutory retention duties.
- Purchase records: we store the purchase event we receive from Stripe. It contains your email address, your billing address and, if provided, your VAT ID, together with the timestamp of your acceptance of our terms — which is what documents the conclusion of the contract.
- Resend (Resend, Inc., USA — processing in the EU region): sending the two emails we send ourselves — the purchase receipt confirming that your access is unlocked, and, if you withdraw, the confirmation that we received your withdrawal (see below). Your invoice comes from Stripe. No marketing is sent through this channel.
- Withdrawal notices: if you use our withdrawal form, we store what you declare — the email address you give, the order reference and message if you add them, and the time your declaration reached us. We need this to identify your purchase, to refund you, and because the law requires us to confirm the time of receipt to you; the record also evidences that you withdrew in time. Legal bases: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR (our legal obligation under § 356a BGB). You do not need an account to withdraw, so this may be the only data we hold about you.
- Learning and progress data: in the course area we store your quiz, drill and exam attempts, your answers and your results, in order to provide what the contract owes you (evaluations, attempt history, progress). If you enter an exam date for the countdown, we store that too.
- AI assistant — Anthropic (Anthropic, PBC, USA): to answer you, the message you type and the conversation currently open in your browser are transmitted to the Anthropic API and processed there. We do not store the conversation on our servers — it exists only in your browser and is gone when you reload or close the page. We do not transmit your name, your email address or your account ID to Anthropic. Anthropic does not use API data to train its models. The assistant is available to buyers of a course only. Legal basis: Art. 6(1)(b) GDPR.
- Operational logs: to keep the service running and to protect it against abuse, we process technically necessary data such as your IP address for rate limiting (held in memory only, for a rolling period, and not stored permanently). Legal basis: Art. 6(1)(f) GDPR.
5. Recipients (processors at a glance)
| Provider | Purpose | Location / processing region |
|---|---|---|
| Cloudflare, Inc. | Website hosting (Pages), DNS/CDN | USA |
| Fly.io, Inc. | App and database hosting | USA / Frankfurt region (EU) |
| Clerk, Inc. | Account and sign-in | USA |
| Stripe Payments Europe, Ltd. | Payment (one-time purchase), invoices | Ireland (EU) |
| Resend, Inc. | Transactional email (purchase receipt, withdrawal confirmation) | USA / EU region |
| Anthropic, PBC | AI assistant (course area, buyers only) | USA |
| Google Ireland Ltd. | Google Analytics 4 statistics and Google Ads conversion measurement (whether a visit from a Google ad led to a purchase). Inside the EEA/UK/Switzerland only with your consent; elsewhere enabled by default with an opt-out — see section 6 | Ireland / USA |
Beyond measuring whether our own ads led to a purchase, we do not pass data to third parties for advertising purposes, and we do not run remarketing or build advertising profiles about you. Section 6 explains when that measurement is based on your consent and when it is on by default with an opt-out.
6. Cookies, local storage and analytics
Where you are decides how this works. We apply two different regimes:
- If you are in the EEA, the United Kingdom or Switzerland — or if we cannot tell where you are — nothing happens until you choose. Our privacy banner offers two separate, independent choices, Analytics and Ads & marketing, and both are strictly opt-in: no request is sent to Google before you decide, and declining is just as easy as accepting.
- Everywhere else, we load Google Analytics with measurement enabled by default when you open the site, without showing a banner first. You can switch it off at any time via "Privacy settings" in the footer (and on the purchase pages); your choice then applies from that point on. Even in this case we never grant the ad-personalisation signal — see below.
We use Google's Consent Mode v2. The starting point is always denied for all four consent signals (analytics storage and the three advertising signals); signals are then granted either because you chose them, or — outside the regions named above — because measurement is on by default.
Analytics. If you accept Analytics, we load Google Analytics 4 to understand
how our site is used, with IP anonymisation (anonymize_ip) enabled. This grants
the analytics-storage signal only. Google Analytics then sets its own cookies
(_ga) in your browser.
Ads & marketing. With this category we grant advertising signals
(ad_storage, ad_user_data) so that Google can measure whether a visit that
arrived from one of our Google ads led to a purchase (conversion measurement).
We use this only to measure the effectiveness of our own advertising.
ad_personalization is only ever granted if you actively choose the Ads &
marketing category yourself. Where measurement is on by default (outside the
EEA/UK/Switzerland), that signal stays denied — so no advertising profiles are
built about you and no remarketing takes place. Legal basis inside the EEA/UK/CH:
Art. 6(1)(a) GDPR and § 25(1) TDDDG (your consent); outside: our legitimate
interest in measuring our own advertising, Art. 6(1)(f) GDPR, with the opt-out
described above. You can change your choice at any time via "Privacy settings" in
the footer (and on the purchase pages), with effect for the future.
How we recognise your region. When you open our website, our content
delivery network (Cloudflare) tells us the country your request comes from. We
store only that two-letter country code in a temporary cookie on our domain
(certpath-geo, deleted when you close your browser) so that both our marketing
website and the purchase pages apply the same rules. We do not store your IP
address for this and cannot identify you from it. Legal basis: § 25(2) TDDDG and
Art. 6(1)(f) GDPR (applying the correct privacy regime).
Measuring which ad led to a purchase. If — and only if — advertising signals
are granted (see above), we store the click identifier Google appends to our ad
links (gclid) and, where present, the utm_source parameter in a cookie on our
domain (certpath-gclid, up to 30 days). If you then buy, we pass that
identifier plus a coarse channel label (for example "google-cpc") to our payment
provider Stripe as part of the order data, so that we can see which advertising
channel a purchase came from. Nothing else is passed. Declining Ads & marketing
deletes this cookie, and no such data is attached to your order.
Your consent decision is stored in a cookie on our domain
(certpath-consent, your decision plus a timestamp), so that a single choice
applies across both our marketing website and the purchase pages of the app and
you are not asked twice. Where measurement is on by default, no such cookie is
written until you actually make a choice — the default is not treated as your
consent, and any choice you make always overrides it. It stays until you decide
again or clear your browser
storage. Legal basis: § 25(2) TDDDG (strictly necessary to honour your choice).
Practice progress without an account. If you try practice questions without an account, your progress is stored in your browser's local storage only. It is not transmitted to us. If you later buy the course, that progress is imported into your account so it is not lost. Legal basis: § 25(2) TDDDG and, for the import, Art. 6(1)(b) GDPR.
The course area itself uses cookies that are strictly necessary for signing in and keeping you signed in (Clerk). With the sole exception of the purchase pages (the buy and order-confirmation pages), which are part of the same funnel as the marketing website and, only with your consent, use the analytics and ads tools described above, there is no tracking in the course area.
7. Transfers to third countries
Some of the providers named above are based in the USA. Where data is transferred there, we base this on adequacy decisions (EU-US Data Privacy Framework, where the provider is certified) and/or EU standard contractual clauses (Art. 44 et seq. GDPR). Where a provider offers an EU processing region, we use it (Fly.io: Frankfurt · Resend: EU region).
8. Storage duration and deleting your account
We store personal data only for as long as the purpose we collected it for lasts, or as long as statutory retention duties require. This table is the full picture:
| Data | How long we keep it | Why |
|---|---|---|
| Your account, your course access and your learning progress (practice attempts and answers) | For as long as you keep the account. Access to a purchased course is permanent, and we never delete a paid account because you have not used it | Performing our contract with you (Art. 6(1)(b) GDPR) — this is the lifetime access you bought |
| Free accounts that never bought anything | Deleted after 24 months without any activity — no sign-in and no practice in that time. Accounts with a purchased course, or one we granted you ourselves, are never affected | Our legitimate interest in not keeping data nobody uses (Art. 6(1)(f) GDPR) |
| Purchase and settlement records: the purchase event we receive from Stripe (including the timestamp at which you accepted our terms) and any refund | For the statutory retention periods | Legal obligation (Art. 6(1)(c) GDPR) — these records document the conclusion of the contract and how it was settled |
| Payment and invoice data | Kept by Stripe for the statutory commercial and tax retention periods (for example ten years, § 147 AO) | Legal obligation (Art. 6(1)(c) GDPR); this data sits with Stripe, not with us |
| Server and access logs | 30 days | Operating and securing the service (Art. 6(1)(f) GDPR) |
| Your conversations with the AI assistant | Not stored at all | — |
| Analytics and ad-conversion measurement on the marketing website and the purchase pages (Google Analytics 4 and Google Ads conversion measurement) | 2 months in Google Analytics; ad-conversion data at Google per its retention; the advertising click identifier in your browser up to 30 days | Your consent (Art. 6(1)(a) GDPR) inside the EEA/UK/Switzerland; outside, our legitimate interest with an opt-out (Art. 6(1)(f) GDPR) — see section 6 |
If you declare a withdrawal, we keep the record of it — what you declared and the time it reached us — as evidence that you withdrew in time and that we confirmed receipt to you, and for as long as the statutory retention duties for the related payment require.
You can ask us to delete your account at any time — write to
support@certification-course.com. We will delete your account, your course
access and your learning data. If you bought a course, deleting your account
ends that access permanently and we cannot restore it, so we will ask you to
confirm once before we go ahead. The purchase and settlement records listed
above, and the invoice data held by Stripe, are kept for as long as statutory
retention duties require.
9. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). You can withdraw any consent you have given at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority — for example the authority responsible for your place of residence, or the authority responsible for us: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.