Privacy Policy

1. Responsible for this website and the privacy policy

Tycho Pfäfflin (address, phone number, email address as stated in the Legal Notice)

2. General Information

I process personal data exclusively in accordance with the GDPR and the German Federal Data Protection Act (BDSG).

3. Hosting

This website is hosted by Domainfactory GmbH. For operational purposes, Domainfactory may process connection data (e.g., IP addresses in server log files). Legal basis: Art. 6 (1) lit. f GDPR.

4. SSL Encryption

Access is provided exclusively via SSL-encrypted connection (https://tychopfaefflin.de/).

5. Google Fonts

For consistent presentation, I use Google Fonts. When accessed, data (IP address) is transmitted to Google. Provider: Google Ireland Ltd., Dublin, parent company Google LLC, USA. Legal basis: Art. 6 (1) lit. f GDPR.

6. Online Courses via Zoom

I use Zoom Video Communications, Inc. (USA) to conduct online courses. The data processed may include name, email address, IP address, and communication content. Legal basis: Art. 6 (1) lit. b GDPR. Data may be transferred to the USA; Zoom relies on EU Standard Contractual Clauses.

7. Participant Management & Invoices

I store names, email addresses, phone numbers (if provided), and billing addresses locally on a password-protected computer for course administration, accounting, and to maintain a participation history. Legal basis: Art. 6 (1) lit. b GDPR (contract), Art. 6 (1) lit. c GDPR (legal obligations), and Art. 6 (1) lit. f GDPR (legitimate interest in orderly participant management). Participants may object to further storage or request deletion at any time.

8. Payment Processing

Payments are made via bank transfer or PayPal. Payment data is processed solely by the respective payment service provider. I do not store account data.

9. Newsletter via MailerLite

I use MailerLite for my newsletter. Stored data includes name and email address. Registration is carried out via double opt-in. Unsubscribing is possible at any time. Legal basis: Art. 6 (1) lit. a GDPR (consent). MailerLite may use servers in the USA, secured via Standard Contractual Clauses.

10. Social Media Links

My website contains links to social media profiles. No data is transferred unless you click on the links.

11. Data Retention

12. Rights of Data Subjects