Privacy Policy
Protecting your personal data matters to us. Below we explain which data we process when you use gypsyguitaracademy.com, for what purpose and on what legal basis – and what rights you have.
1. Controller & contact
The controller responsible for the processing of data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Dizzy Fingers Academy GmbH
Represented by its Managing Director Malte Weber
Hövelstraße 4, 59439 Holzwickede, Germany
Telephone: +49 1525 4569703
Email: mail@gypsyguitaracademy.com
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
2. Your rights as a data subject
In relation to the personal data concerning you, you have the following rights against us:
- Access (Article 15 GDPR) to the data we process;
- Rectification of inaccurate data, or completion of incomplete data (Article 16 GDPR);
- Erasure (Article 17 GDPR), provided that no statutory retention obligations or other grounds prevent this;
- Restriction of processing (Article 18 GDPR);
- Data portability (Article 20 GDPR) in a structured, commonly used, machine-readable format;
- Withdrawal of a consent you have given (Article 7(3) GDPR), with effect for the future.
Right to object (Article 21 GDPR)
Where we process personal data on the basis of our legitimate interests (Article 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation. Where your data are processed for direct marketing purposes, you may object at any time without giving reasons.
Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authorities with jurisdiction include the supervisory authority of the federal state in which we are established. A list of the supervisory authorities is available at bfdi.bund.de.
3. Legal bases & withdrawal of consent
We process personal data on the basis of the relevant provisions of the GDPR and of the German Telecommunications and Digital Services Data Protection Act (TDDDG). The legal bases that may apply are, in particular: your consent (Article 6(1)(a) GDPR, Section 25(1) TDDDG); performance of a contract or steps taken before entering into a contract (Article 6(1)(b) GDPR); compliance with legal obligations (Article 6(1)(c) GDPR); and our legitimate interests (Article 6(1)(f) GDPR).
Where information is stored on, or accessed from, your device (for example cookies used for analytics or marketing purposes), this is done solely on the basis of your consent under Section 25(1) TDDDG – unless such storage or access is strictly necessary in order to provide a service you have expressly requested (Section 25(2) no. 2 TDDDG), for example when you sign in to your user account. You may withdraw a consent you have given at any time with effect for the future, for example through the settings of our cookie banner. The lawfulness of processing carried out up to the point of withdrawal is unaffected.
4. Hosting, content delivery & server logs
Hosting
We host our website with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; the servers are located in Germany. The personal data processed in this context (in particular technical access data) are stored on that provider’s servers. The processing serves the secure, fast and stable provision of our online offering (Article 6(1)(f) GDPR) and the performance of the contract (Article 6(1)(b) GDPR). A data processing agreement under Article 28 GDPR is in place with Hetzner. The video content shown on the platform is very largely not stored with Hetzner but made available through external video services (see section 10).
Cloudflare (content delivery network)
To deliver our website securely and efficiently, we use a content delivery network and security services provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare processes technical connection data (including your IP address) as our processor in order to route requests, filter traffic and defend against attacks. The legal basis is our legitimate interest in secure and efficient operation (Article 6(1)(f) GDPR). Data may be transferred to the USA in this context; see section 11. Further information: cloudflare.com/privacypolicy.
Server log files
The provider of these pages automatically collects and stores information in server log files that your browser transmits automatically: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and IP address. These data are not combined with other data sources. The legal basis is Article 6(1)(f) GDPR; we have a legitimate interest in the technically faultless presentation and the security of our website.
5. Cookies & consent management
Our website uses cookies and similar technologies. We use technically necessary cookies, which enable the operation of the site and functions you have requested (for example login and shopping basket), on the basis of Article 6(1)(f) or (b) GDPR and Section 25(2) TDDDG. We only set cookies that are not necessary (analytics, marketing, third-party services embedded on public pages) with your consent.
Real Cookie Banner
To manage the cookies we use and the associated consents, we use the consent tool “Real Cookie Banner” provided by devowl.io GmbH. It documents consents given and withdrawn. The legal basis is Article 6(1)(c) GDPR (the legal obligation to demonstrate consent) and Article 6(1)(f) GDPR. You can change your settings at any time using the banner. Details: devowl.io/rcb/data-processing.
6. Contacting us, customer account & contract handling
Contact form & email
If you contact us using the contact form or by email, we process the details you provide in order to deal with your enquiry and any follow-up questions. The legal basis is Article 6(1)(b) GDPR (for contract-related enquiries) or Article 6(1)(f) GDPR (our interest in responding). We store these data until the purpose no longer applies or you ask us to erase them; statutory retention periods are unaffected.
Guitar enquiries (referral to the guitar maker)
Using the contact form on our website, you can register your interest in handmade guitars. In such cases the contract of sale for a guitar is concluded directly between you and the guitar maker (Jozsi Lak); we pass on the details of your enquiry (name, contact details, content of the enquiry) so that he can contact you and prepare a quotation. The legal basis is Article 6(1)(b) GDPR (steps taken at your request before entering into a contract).
Customer account & members’ area
To use the members’ area you create a customer account. Mandatory details must be complete; otherwise we may refuse the registration. The processing serves the establishment and performance of the user relationship (Article 6(1)(b) GDPR). We will inform you of important changes using the email address you have provided.
Orders & contract handling (WooCommerce)
To handle orders and subscriptions, we process customer and contract data (for example name, address, email address, payment and subscription details). This processing is necessary for the performance of the contract (Article 6(1)(b) GDPR). Data are only passed to third parties where this is necessary in order to perform the contract (for example to payment service providers, see section 7) or where there is a legal obligation to do so (Article 6(1)(c) GDPR). Once the contract has been completed, or the business relationship has ended, the data are erased unless statutory retention periods (for example under commercial or tax law) prevent this.
Evidence of the place of supply for VAT purposes
When you place an order, we also store the IP address from which the order was placed. Together with the billing address you provide and the details we receive from the payment service provider used (in particular as to the origin of the payment), it serves to determine the country in which the service is deemed to be supplied for VAT purposes. We are required by law to determine that country on the basis of items of evidence that are independent of one another, and to retain that evidence. The legal basis is compliance with a legal obligation (Article 6(1)(c) GDPR) in conjunction with the applicable VAT legislation. These details form part of our accounting records; the statutory retention periods therefore apply to them (see section 12), rather than the shorter periods that apply to the usage logs.
Tax obligations, tax advisers and public authorities
We pass invoices and the associated accounting records to our tax advisers and submit them to the tax authorities where we are required or requested to do so. Our tax advisers do not act as our processor; they are an independent recipient in their own right and are themselves bound by professional confidentiality. The platform of DATEV eG, Paumgartnerstraße 6–14, 90429 Nuremberg, Germany, is used to transmit and process these records. The legal basis is compliance with legal obligations (Article 6(1)(c) GDPR) and our legitimate interest in proper bookkeeping (Article 6(1)(f) GDPR).
Sending email
To send our emails – for example order confirmations and acknowledgements of receipt, replies to enquiries and internal system notifications – we use the email service of Zoho Corporation B.V., Beneluxlaan 4B, 3527 HK Utrecht, Netherlands. In doing so, the sender and recipient details and the content of the message concerned are processed. The provider acts as our processor; a data processing agreement under Article 28 GDPR is in place. The legal basis is performance of the contract (Article 6(1)(b) GDPR) or our legitimate interest in reliable email communication (Article 6(1)(f) GDPR). Our newsletter is sent separately, using the service named in section 8.
Usage logs in the members’ area
Within the members’ area we log the use of the content. Only signed-in members are recorded; visitors who are not signed in do not generate any log entry.
The data processed are the identifier of the user account, details of which content was used, when and to what extent, details of sign-ins to the user account, and summary metrics about the use of the account. As part of this logging, the IP address is at no point stored in plain text, but only in hashed form and solely for the purpose of distinguishing between access from the same and from a different origin. This does not affect the IP address stored in connection with an order (see “Evidence of the place of supply for VAT purposes” above). This is a data minimisation measure and not anonymisation: the data remain linked to the user account and therefore remain personal data.
Purposes and legal bases:
- Detecting misuse on the basis of unusual usage patterns. Nothing is blocked automatically; every individual case is assessed by a person. The sign-in log serves the same purpose and supports the security of user accounts. The legal basis is our legitimate interest in protecting copyright-protected content and in enforcing the contractual restrictions on use (Article 6(1)(f) GDPR).
- The “Continue learning” feature: displaying the lesson you last started in the members’ area. The legal basis is performance of the user contract (Article 6(1)(b) GDPR).
- Internal analysis of how the service is used. Access is available to administrators only. The legal basis is our legitimate interest in assessing and developing our offering (Article 6(1)(f) GDPR).
No automated decision-making in individual cases, including profiling, within the meaning of Article 22 GDPR takes place.
Retention: The log entries are condensed and erased automatically at regular intervals. Individual entries relating to media use are erased after 90 days, and entries relating to sign-ins after 30 days. The summary metrics exist for as long as the user account exists. Beyond that, we retain only aggregated analyses that no longer contain any personal reference. If a user account is deleted, we remove all personal log data belonging to that account.
Recipients and cookies: The log data themselves are not passed to third parties and do not leave our server. The only exception is the internal notification about unusual use: it is sent by email to ourselves, contains the display name and email address of the account concerned, and is sent through our email service provider (see section 6, “Sending email”). We, as the operator, are the sole recipients of that message. No cookies are set beyond the cookie required in order to sign in; the processing takes place on the server. This logging is to be distinguished from the embedding of the video service, on which we provide separate information in section 10.
You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR (Article 21 GDPR).
Advertising to existing customers
Where we obtain your email address in connection with the purchase of goods or a service, we reserve the right to send you offers for similar products of our own by email, on the basis of Section 7(3) of the German Act against Unfair Competition (UWG). You may object at any time, and doing so will incur no costs other than the transmission costs at base rates.
7. Payment service providers
We use external payment service providers to handle payments. When you choose a payment method, the data required for it are transmitted to the provider concerned. The legal basis is Article 6(1)(b) GDPR (performance of the contract) and, where consent is required for the payment process, Article 6(1)(a) GDPR.
Stripe
Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Privacy information: stripe.com/privacy.
PayPal
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Privacy information: paypal.com.
Amazon Pay
Provider: Amazon Payments Europe S.C.A., 38 avenue John F. Kennedy, L-1855 Luxembourg. When you pay using Amazon Pay, the necessary payment and order data are transmitted to Amazon. Privacy information: pay.amazon.eu.
8. Newsletter
To send you our newsletter we need your email address and your consent to receive it (double opt-in). The processing takes place solely on the basis of your consent (Article 6(1)(a) GDPR). You can unsubscribe from the newsletter at any time, for example using the “unsubscribe” link. The lawfulness of processing already carried out is unaffected.
Mailchimp
The newsletter is sent using “Mailchimp”, a service of Intuit Inc. / The Rocket Science Group LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA. Mailchimp makes it possible to organise and analyse the sending of the newsletter (for example whether a message has been opened and which links have been clicked). A data processing agreement is in place with Mailchimp. Transfers to the USA are based on the provider’s certification under the EU-US Data Privacy Framework (DPF) or on EU standard contractual clauses (see section 11). The DPF certification is listed under the parent company “Intuit Inc.” at dataprivacyframework.gov. Privacy information: intuit.com/privacy.
9. Web analytics & advertising
We use the following services for audience measurement and advertising. We only use the marketing services (Google Ads, Meta Pixel) once you have given consent through our cookie banner (Article 6(1)(a) GDPR, Section 25(1) TDDDG); that consent is voluntary and can be withdrawn at any time. Our self-hosted, cookie-free audience measurement with Matomo is operated on the basis of our legitimate interest (Article 6(1)(f) GDPR) and does not require consent.
Matomo (self-hosted, cookie-free)
We use the open-source web analytics service Matomo in order to evaluate the use of our website statistically and to improve what we offer. We run Matomo ourselves, on our own servers, without cookies and with the IP address anonymised. The data collected (for example pages viewed, time spent, approximate location, technical details) remain with us; they are not passed to third parties and are not transferred to third countries. Identifying an individual person is therefore not possible. The legal basis is our legitimate interest in audience measurement that minimises data (Article 6(1)(f) GDPR); a “do not track” setting in your browser is respected. You have the right to object to this processing on grounds relating to your particular situation (Article 21 GDPR).
Google Ads & conversion tracking
We use Google Ads provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, including conversion tracking, in order to measure how successful our advertisements are. A cookie is set when you click on an advertisement; if you then visit certain pages, Google and we are able to recognise that you were referred to our site. No personal identification takes place. Privacy information: policies.google.com/privacy.
Meta Pixel (Facebook/Instagram Ads)
To measure and optimise our advertising on Facebook and Instagram, we use the “Meta Pixel” provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. It makes it possible to follow the behaviour of users after they have clicked on a Meta advertisement, so that effectiveness can be evaluated and audiences defined. In this respect we and Meta are joint controllers in part (Article 26 GDPR). The controller addendum provided by Meta, which forms part of the terms of use of the Meta business tools, applies to that joint controllership. Privacy information: facebook.com/privacy/policy.
10. Embedded services & plugins
Google reCAPTCHA
To protect our forms against automated misuse and spam, we use “Google reCAPTCHA” provided by Google Ireland Limited. reCAPTCHA analyses various pieces of information for this purpose (for example IP address, time spent, mouse movements). The form is only loaded once you have given consent through the cookie banner. The legal basis is your consent (Article 6(1)(a) GDPR, Section 25(1) TDDDG); in addition, we have a legitimate interest in protection against misuse. Privacy information: policies.google.com/privacy.
Vimeo
Both on the publicly accessible pages of our website and in the members’ area, we embed videos of Vimeo Inc. (330 West 34th Street, New York, New York 10001, USA). When you play a video, its video file is loaded from there, and Vimeo receives your IP address in the process. No information is stored on, or read from, your device in this context; in particular, no cookies are set and no local storage is used. A connection to Vimeo is only established when you actually play a video, and not when a page is opened.
In the members’ area the legal basis is performance of the user contract (Article 6(1)(b) GDPR), because making the videos available is the main service we owe. On freely accessible pages we base playback on our legitimate interest in presenting our content (Article 6(1)(f) GDPR). We do not obtain consent for this, because no information is stored on or accessed from your device and Section 25 TDDDG therefore does not apply. On the transfer of your IP address to the USA, see section 11. Privacy information: vimeo.com/privacy.
This is to be distinguished from the embedding by way of a preview described below, in which a window of the video provider concerned is loaded.
Embedded videos with click-to-load (YouTube and Vimeo)
In editorial articles we embed videos of YouTube LLC (901 Cherry Ave., San Bruno, CA 94066, USA; Google Ireland Limited) and of Vimeo Inc. by way of a preview. The preview image is loaded from our own server; only when you actively start a video does a window of the provider concerned open, a connection to that provider is established and data – including your IP address – are transmitted. Only in this case can the provider concerned also store information on your device or read information from it. The legal basis is your consent (Article 6(1)(a) GDPR, Section 25(1) TDDDG), which you give by starting the video and which you may withdraw at any time with effect for the future. Privacy information: policies.google.com/privacy and vimeo.com/privacy.
Videos may also be embedded through YouTube in the members’ area. Where overviews of such videos are shown there, our server retrieves the associated details; no data from your device are transmitted to YouTube in the process. Here too, a connection to YouTube is only established when playback starts.
11. Transfers to third countries
Some of the services we use (for example Cloudflare, Mailchimp, Google, Meta, Vimeo) may transfer personal data to the USA or to other third countries. The USA does not have a level of data protection equivalent to that of EU law. Where a transfer takes place, we base it on:
- the certification of the recipient concerned under the EU-US Data Privacy Framework (DPF), where such certification exists (adequacy decision of the European Commission of 10 July 2023); and/or
- the standard contractual clauses (SCCs) issued by the European Commission, together with supplementary safeguards; and/or
- your explicit consent (Article 49(1)(a) GDPR).
Despite these measures, access to the data by US authorities, among others, cannot be entirely ruled out. Further information can be found in the privacy notices of the providers concerned, which are linked above.
12. Storage periods
The periods stated in section 6 apply to the usage logs in the members’ area. Where no more specific storage period is stated in this policy, your personal data remain with us until the purpose of the processing no longer applies. If you exercise a right to erasure or withdraw your consent, your data will be erased unless there are other legally permissible grounds for storing them (for example the statutory retention periods under the German Commercial Code and the German Fiscal Code, as a rule between 6 and 10 years). In the latter case, erasure takes place once those grounds no longer apply.
13. Currency & changes to this policy
This privacy policy is currently in force and has the version status stated above. As our website and our offering develop further, or as a result of changed statutory or regulatory requirements, it may become necessary to amend this privacy policy. The current version can be viewed on this page at any time.