Privacy Policy

1. Controller

Marcus Rother

Martin-Albert-Str. 8

90491 Nürnberg

Germany

E-Mail: hello@marcusrother.de

2. Hosting

This website is hosted by Host Europe GmbH.

A data processing agreement pursuant to Art. 28 GDPR has been concluded with the hosting provider.

3. Server Log Files

When visiting this website, the following data is automatically collected:

  • IP address
  • Date and time of access
  • Browser type and version
  • Operating system
  • Referrer URL
  • Accessed pages

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and technical stability).

Retention period: Maximum 14 days.

4. Cookies and Cookie Management

This website uses cookies.

Consent for cookies is managed via the GDPR Cookie Compliance plugin.

Cookies are small text files that are stored on a user’s device when visiting a website.

The following categories of cookies may be used on this website:

Technically necessary cookies

These cookies are required for the operation of the website and cannot be disabled through the consent tool. They include functions such as:

• login functionality

• shopping cart features (WooCommerce)

• language switching via TranslatePress

• security functions

Legal basis:

Art. 6 (1) lit. f GDPR (legitimate interest in the technically secure operation of the website).

Analytics and marketing cookies

Analytics and marketing cookies are only activated after the user has given explicit consent through the cookie consent banner.

These cookies may include services such as:

• Google Analytics

• Google Ads conversion tracking

• Jetpack statistics

Legal basis:

Art. 6 (1) lit. a GDPR (consent).

Users may withdraw or change their consent at any time via the cookie settings on this website.

5. WooCommerce (Online Shop)

When purchasing digital products, the following data is processed:

  • First and last name
  • Billing address
  • Email address
  • IP address
  • Order details
  • Payment information

Purpose:

  • Contract processing
  • Invoicing
  • Creation of user accounts
  • Compliance with tax retention obligations

Legal basis: Art. 6(1)(b) GDPR.

Retention in accordance with German tax and commercial law (§ 147 AO, § 257 HGB – 10 years).

6. User Accounts and LearnPress

Customers receive individual login credentials for access to online courses.

Processed data:

  • Username
  • Password (stored in encrypted form)
  • Course progress
  • Login timestamps
  • Interactions within the course

Legal basis: Art. 6(1)(b) GDPR.

Within the course platform, learning progress and interactions may be recorded.

This may include:

• completed lessons

• course progress

• quiz results

• timestamps of course activity

This processing is necessary to provide the digital learning environment and track course completion.

Legal basis:

Art. 6 (1) lit. b GDPR (performance of the contract).

7. Payment Providers

Stripe

Provider: Stripe Payments Europe Ltd.

Payment and transaction data are processed.

Legal basis: Art. 6(1)(b) GDPR.


PayPal

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A.

PayPal may be used for both shop purchases and bookings via Calendly.

When selecting PayPal, users are redirected to PayPal. Data processing is carried out independently by PayPal.

Legal basis: Art. 6(1)(b) GDPR.

8. Appointment Booking and Payment via Calendly

Provider: Calendly LLC, USA.

Processed data:

  • Name
  • Email address
  • Appointment details
  • Payment data (if integrated payment function is used)

Purpose:

  • Appointment management
  • Contract fulfillment
  • Payment processing

Legal basis:

  • Art. 6(1)(b) GDPR
  • Art. 6(1)(f) GDPR

Data transfer to the United States is based on Standard Contractual Clauses.

9. Live Online Courses via Zoom

Provider: Zoom Video Communications Inc., USA.

When participating in live online courses, the following data may be processed:

  • Name or displayed username
  • Email address
  • IP address
  • Audio and video data (if activated)
  • Chat content
  • Session metadata

Purpose:

  • Conducting the event
  • Communication
  • Technical provision of the session

Legal basis: Art. 6(1)(b) GDPR.

If camera or microphone are activated voluntarily:

Art. 6(1)(a) GDPR (consent).

Data transfer to the United States cannot be excluded.

Zoom uses Standard Contractual Clauses pursuant to Art. 46 GDPR.

Live sessions within the “Science of Being Human” courses may be recorded and made available to participants as streaming content within the course platform.

Participants may choose to deactivate their camera and microphone during the session.

10. WhatsApp Community

This website contains references to a WhatsApp community.

Provider: WhatsApp Ireland Limited.

If users join the community via a link or reserve sessions via WhatsApp, data processing takes place within the WhatsApp platform.

Data that may be processed:

  • Phone number
  • Profile name
  • Communication content

Legal basis: Art. 6(1)(a) GDPR (voluntary contact).

Data transfer to third countries cannot be excluded.

11. Yoast SEO

This website uses the Yoast SEO plugin for technical search engine optimization.

Provider: Yoast B.V., Netherlands.

Yoast SEO itself does not process personal data of website visitors.

The plugin is used solely for optimizing metadata, content structure, and search engine visibility.

Further information: https://yoast.com/privacy-policy/

12. Jetpack (WordPress.com)

This website uses features of the Jetpack plugin.

Provider: Automattic Inc., USA.

Jetpack may provide functions such as:

• website statistics

• security monitoring

• spam protection

• performance optimization

In this context, the following data may be processed:

• IP address

• browser information

• website usage data

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website security and optimization).

Further information: https://automattic.com/privacy/

13. Google Search Console

This website uses Google Search Console.

Provider: Google Ireland Limited.

Google Search Console is used to analyze and improve the visibility of the website in Google Search.

No direct processing of personal data of website visitors takes place through this tool.

Further information: https://policies.google.com/privacy

14. Google Analytics

This website uses Google Search Console.

Provider: Google Ireland Limited.

Google Analytics uses cookies that allow analysis of how visitors use the website.

The following data may be processed:

• IP address (anonymized)

• device information

• usage behavior

• page views

• interaction with the website

Processing takes place only on the basis of user consent via the cookie consent tool.

Legal basis: Art. 6(1)(a) GDPR.

Further information: https://policies.google.com/privacy

IP anonymization is activated on this website.

This means that the IP address of users is shortened by Google within member states of the European Union or in other contracting states of the European Economic Area before being transmitted to the United States.

Google Analytics is only activated after the user has given consent through the cookie consent tool.

15. Google Ads

This website plans to use Google Ads for online advertising.

Provider: Google Ireland Limited.

Google Ads may use conversion tracking.

The following data may be processed:

• IP address

• cookie information

• interaction data

• device information

Processing takes place only on the basis of user consent via the cookie consent tool.

Legal basis: Art. 6(1)(a) GDPR.

Further information: https://policies.google.com/privacy

Google Ads services are only activated after the user has given consent through the cookie consent tool.

16. Google reCAPTCHA

Used to protect against spam.

Processed data:

  • IP address
  • Mouse movements
  • Device information
  • Time spent on page

Legal basis:

or Art. 6(1)(a) GDPR (consent).

Art. 6(1)(f) GDPR

17. WP Mail SMTP

Emails are sent via an SMTP system.

Processed data:

  • Email address
  • Email content

Legal basis: Art. 6(1)(b) GDPR.

18. Data Retention

Personal data is stored:

until consent is withdrawn

for the duration of a contractual relationship

in accordance with statutory retention periods

19. International Data Transfers

Some services used on this website are provided by companies located in the United States.

Where personal data is transferred to the United States, this transfer is based on:

• the EU-US Data Privacy Framework, or

• Standard Contractual Clauses pursuant to Art. 46 GDPR.

These safeguards are intended to ensure an adequate level of data protection.

20. Data Subject Rights

You have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)

You also have the right to lodge a complaint with a supervisory authority.

21. SSL Encryption

This website uses SSL/TLS encryption to ensure secure transmission of confidential content.