Privacy Policy

Introduction

This privacy policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as “data”) in the context of our services, our website and its associated functions and content, as well as our external online presences such as social media profiles (hereinafter collectively referred to as “online offer”). With regard to the terms used, such as “processing” or “controller”, we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

 

Controller and contact details

darive
Owner: Thomas Gerstmann
Urbanstr. 71
10967 Berlin
Germany

Phone: +49 241 89439009
E-mail: [email protected]

Contact for data protection matters: Thomas Gerstmann, [email protected]

We have not appointed a data protection officer, as we are not required to do so under Art. 37 GDPR and § 38 BDSG.

 

General information

As a user of our website, this privacy policy gives you all necessary information about how, to what extent and for what purpose we or third-party providers collect and use your data. The collection and use of your data takes place strictly in accordance with the GDPR and the German Federal Data Protection Act (BDSG), and, where cookies and similar technologies are concerned, the German Digital Services Data Protection Act (TDDDG). We are committed to the confidentiality of your personal data and work strictly within the limits set by law.

Where possible, the collection of personal data takes place on a voluntary basis. We only pass data on to third parties where we are legally permitted to do so, where it is necessary to perform a contract, or where you have consented. We secure the transmission of confidential data using TLS encryption. We would nevertheless point out the general risks of internet use over which we have no control. In e-mail traffic in particular, your data is not secure without further precautions and may potentially be intercepted by third parties.

 

Processing purposes

  • Provision of our online offer, its functions and contents
  • Responding to contact requests and communicating with users
  • Scheduling and managing appointments
  • Delivery of our newsletter and related communications
  • Conclusion and performance of contracts, including payment processing
  • Provision of our course content and our application
  • Security measures
  • Reach measurement and marketing

 

Legal basis for data processing

Where you have given your consent, the legal basis for processing is Art. 6 (1)(a) GDPR, and, for the storage of or access to information on your device, § 25 (1) TDDDG.

Where processing is necessary for the performance of a contract with you or for pre-contractual measures, the legal basis is Art. 6 (1)(b) GDPR.

Where processing is necessary to comply with a legal obligation, the legal basis is Art. 6 (1)(c) GDPR.

Where processing is necessary to protect our legitimate interests, the legal basis is Art. 6 (1)(f) GDPR. Our legitimate interests are set out in the relevant sections below.

 

Contact form and e-mail contact

If you use a contact form on this website, the data entered in the input mask is transmitted to us and stored, together with your IP address and the date and time of submission. Alternatively, you can contact us using the e-mail address provided; in that case the personal data transmitted with your e-mail will be stored.

The data is used exclusively to process your enquiry and any follow-up questions. The additional technical data processed during submission serves to prevent misuse of the contact form and to ensure the security of our systems.

The legal basis is Art. 6 (1)(b) GDPR where your enquiry relates to a contract or pre-contractual measures, and otherwise Art. 6 (1)(f) GDPR based on our legitimate interest in responding to enquiries.

Enquiries that do not lead to a contract are deleted six months after your request has been dealt with.

 

Appointment booking

You can book an appointment with us on this website. For this purpose we operate our own instance of the open source software Cal.com. There is no contractual relationship with Cal.com, Inc., and no data is transmitted to that company.

The instance is hosted for us by Peakford Ltd., 86 “The Office” Leli Falzon Street, Naxxar NXR 2609, Malta (service name: PikaPods). Processing takes place within the European Union.

When you book an appointment, we process the data you provide: your name, e-mail address, the requested appointment and time zone, and any information you enter in the message field. Technical access data is also collected.

The legal basis is Art. 6 (1)(b) GDPR where the appointment serves the initiation or performance of a contract, and otherwise Art. 6 (1)(f) GDPR based on our legitimate interest in straightforward appointment scheduling.

Booking data is deleted 12 months after the appointment.

We have concluded a data processing agreement with Peakford Ltd. in accordance with Art. 28 GDPR.

 

Calendar

To manage our appointments we operate our own instance of the open source software Nextcloud. There is no contractual relationship with Nextcloud GmbH, and no data is transmitted to that company.

The instance is hosted for us by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in Germany.

When you book an appointment through us, a corresponding calendar entry is created in this instance. It contains your name, e-mail address, the agreed time and, where applicable, the information you entered in the message field.

The legal basis is Art. 6 (1)(b) GDPR where the appointment serves the initiation or performance of a contract, and otherwise Art. 6 (1)(f) GDPR based on our legitimate interest in orderly appointment management.

Calendar entries are deleted 12 months after the appointment.

We have concluded a data processing agreement with Hetzner Online GmbH in accordance with Art. 28 GDPR.

 

Newsletter

If you wish to receive the newsletter offered on this website, we require your e-mail address as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. Further data is not collected, or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.

The processing of the data entered in the newsletter registration form is based exclusively on your consent (Art. 6 (1)(a) GDPR). You can revoke your consent to the storage of the data, the e-mail address and their use for sending the newsletter at any time, for example via the “unsubscribe” link in the newsletter. The lawfulness of the processing already carried out remains unaffected by the revocation.

The data you provide for the purpose of receiving the newsletter will be stored until you unsubscribe and will then be deleted from the distribution list. Data stored for other purposes remains unaffected.

After you have unsubscribed, your e-mail address may be stored in a blocklist to prevent future mailings. Data in the blocklist is used only for this purpose and is not merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 (1)(f) GDPR). Storage in the blocklist is not limited in time.

You can object to this storage if your interests outweigh our legitimate interest.

 

Customer accounts and course access

If you purchase one of our products, we create a customer account for you. We process your name, e-mail address, billing details, purchase history, access credentials, your progress within the course, contact tags and any comments you post in the member area. 

The legal basis is Art. 6 (1)(b) GDPR. Data required for accounting purposes is additionally retained on the basis of Art. 6 (1)(c) GDPR in conjunction with statutory retention obligations.

Access to the course is provided via Kajabi (see “Services used” below). Course access data is deleted 12 months after your access ends, subject to statutory retention obligations.

 

Embedded content from other websites

Pages on this website may contain embedded content (e.g. videos, images, articles). Embedded content from other websites behaves exactly as if the visitor had visited the other website.

These websites may collect information about you, use cookies, embed additional third-party tracking services, and record your interaction with that embedded content — including your interaction with it if you have an account and are logged in to that website.

 

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

The legal basis is Art. 6 (1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of our website. Log files are deleted according to the specifications of our hosting provider.

 

Cooperation with processors and third parties

If, in the course of our processing, we disclose data to other persons and companies, transmit it to them or otherwise grant them access, this is only done on the basis of a legal permission (for example where transmission is necessary for the performance of a contract), where you have consented, where a legal obligation provides for this, or on the basis of our legitimate interests.

Where we engage processors, we do so on the basis of a data processing agreement in accordance with Art. 28 GDPR. The processors we use are listed under “Services used” below.

 

Transfers to third countries

Some of the providers we use are based in the United States. Where personal data is transferred to a third country, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR — either an adequacy decision such as the EU-US Data Privacy Framework, or the Standard Contractual Clauses adopted by the European Commission. The specific safeguard applicable to each provider is stated in the relevant section below.

 

How long we store your data

We store personal data only for as long as necessary for the purposes described in this privacy policy, unless longer retention is required by law. In particular:

  • Contact enquiries that do not lead to a contract: 6 months after the enquiry has been dealt with
  • Appointment bookings and calendar entries: 12 months after the appointment
  • Newsletter data: until you unsubscribe; blocklist entries are stored indefinitely
  • Course access data: 12 months after your access ends
  • Data in the darive application: 12 months after the end of the contract term and of access
  • Analytics data: as stated in the respective sections below
  • Data subject to statutory retention obligations: for the duration of those obligations

 

Rights of data subjects

You have the right to request confirmation as to whether data concerning you is being processed, and to obtain information about that data as well as further information and a copy of the data in accordance with the legal requirements.

You have the right to request that data concerning you be completed or that inaccurate data concerning you be corrected.

You have the right to demand that the data concerned be deleted without undue delay or, alternatively, to demand restriction of processing in accordance with the statutory provisions.

You have the right to receive the data concerning you that you have provided to us in a structured, commonly used format and to request that it be transmitted to other controllers.

You also have the right to lodge a complaint with the competent supervisory authority.

 

Right of withdrawal

You have the right to revoke consents you have given with effect for the future.

 

Right of objection

You may object to the future processing of data relating to you at any time in accordance with the statutory provisions. An objection may in particular be made against processing for the purposes of direct marketing.

 

Objection to advertising e-mails

The use of contact data published within the scope of the imprint obligation for the transmission of advertising and information material that has not been expressly requested is hereby prohibited. We expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.

 

Information, deletion, blocking

You can obtain information free of charge at any time about the personal data we have stored about you, and about the origin, recipients and purpose of the data collection and processing. You also have the right to request the correction, blocking or deletion of your data. Excluded from this is data that is retained due to legal regulations or is required for proper business processing. If data is not covered by a legal archiving obligation, we will delete your data at your request. If an archiving obligation applies, we will block your data. For all questions and concerns regarding the correction, blocking or deletion of personal data, please contact us using the contact details in this privacy policy or at the address given in the imprint.

 

Changes and updates to this privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We will adapt it as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.

 

TLS encryption

Our website uses TLS encryption (also referred to as SSL) when transmitting confidential or personal content. You can recognise an encrypted connection by the fact that the address in your browser bar begins with “https://”. Data encrypted in this way cannot be read by third parties. Please only transmit confidential information when encryption is active, and contact us if in doubt.

 

Services used

 

Kajabi

Our website, blog, landing pages, newsletter, member area and payment processing are provided via the Kajabi platform. The provider is Kajabi, LLC, USA. Kajabi acts as our processor.

When you access our pages, Kajabi processes server log data: IP address, browser type and version, operating system, referrer URL, host name and the time of access. When you register, submit a form or make a purchase, Kajabi additionally processes the data you provide — in particular your name, e-mail address, billing details and purchase history — as well as your interaction with our e-mails.

The legal basis is Art. 6 (1)(b) GDPR for contractual relationships and Art. 6 (1)(f) GDPR for the technical operation and security of our online offer.

Kajabi uses the following cookies on this site:

Cookie Name Purpose
_kjb_session Kajabi session cookie Tracks your active session so you do not need to log in again
kjba Kajabi affiliate token Tracks which affiliate has referred an offer purchase
_abv Admin bar hidden Tracks whether the user wishes their admin preview bar to be hidden

A data processing agreement in accordance with Art. 28 GDPR forms part of Kajabi’s terms of service and has been in effect since 27 September 2021. Transfers to the United States are based on the EU Standard Contractual Clauses.

Further information: https://legal.kajabi.com/policies/privacy

 

Piwik PRO & Piwik PRO Tag Manager

We use the Piwik PRO Analytics Suite from Piwik PRO GmbH (Kurfürstendamm 21, 10719 Berlin, Germany, “Piwik PRO”), our processor, as our website and app analytics software. We collect data about website visitors.

Piwik PRO collects data about your operating system, your browser, browsing activities and other information. We calculate metrics such as bounce rate, page views and sessions to understand how our website is used. Your IP address is immediately anonymised and shortened: the last bytes of the IP address are replaced by zeros. Furthermore, no data about your screen resolution or your browser plug-ins is recorded.

Piwik PRO distinguishes in terms of its functionality whether a user has consented to data processing by Piwik PRO and the use of cookies or not.

If you do not consent, data is only collected without cookies. In this way, new and returning visitors are not recognised, and so-called “device fingerprinting” does not take place. The purpose of processing to this extent is the legitimate interest of the controller. Legal basis: Art. 6 (1)(f) GDPR.

If you consent to data processing by Piwik PRO and cookies, we can also create a visitor profile based on the browsing history, analyse visitor behaviour, display personalised content and carry out online campaigns. The purpose of the processing is then analytics and conversion tracking based on your consent. Legal basis: Art. 6 (1)(a) GDPR and § 25 (1) TDDDG.

Here you can view the scope of the data collected by Piwik PRO in detail.

Piwik PRO is hosted on Microsoft Azure in Germany. The data is stored for 12 months. Piwik PRO does not share data about you with other sub-processors or third parties and does not use it for its own purposes. You can find more information in the Piwik PRO privacy policy, and you can opt out of Piwik PRO tracking at any time.

 

Microsoft Clarity

We use Microsoft Clarity web analytics software for our website. The provider is Microsoft Corporation (One Microsoft Way, Redmond, WA 98052-6399, USA). Data is transferred to Microsoft Ireland Operations Ltd. (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). Interactions on our website (e.g. mouse movements, clicks, scrolling) as well as session recordings and heat maps are created in order to improve usability and better detect errors.

Clarity’s masking is set to “Balanced”, which means that entries in form fields are masked and are not visible in the recordings.

Recordings are retained for 30 days. Click data, heat map data and any sessions we label are retained for 13 months. After the retention period, the data is deleted from Clarity’s servers, including backups, and cannot be recovered.

Microsoft also processes your data in the USA, among other places. Clarity and Microsoft are active participants in the EU-US Data Privacy Framework, which regulates the transfer of personal data from EU citizens to the USA. For more information, please visit the European Commission’s adequacy decision.

In addition, Microsoft uses Standard Contractual Clauses (Art. 46 (2) and (3) GDPR). These are templates provided by the EU Commission intended to ensure that your data complies with European data protection standards even if it is transferred to and stored in third countries such as the USA. You can find the implementing decision and the corresponding clauses here. For more information on Microsoft’s Standard Contractual Clauses, please visit Microsoft’s documentation.

The use of this service is based on your consent in accordance with Art. 6 (1)(a) GDPR and § 25 (1) TDDDG. Consent can be revoked at any time.

To contact the data protection officer at Microsoft Ireland Operations Ltd. by e-mail: https://www.microsoft.com/de-at/concern/privacy. The privacy policy of Microsoft Ireland Operations Ltd.: https://privacy.microsoft.com/de-de/privacystatement.

 

The darive application


For customers of our programmes we provide a web application at app.darive.com. It contains your individual learning path and the working tools of the darive Outcomes Engine.

In the application we process: your name, e-mail address, the organisation you belong to, your role, your Kajabi contact ID, the status of your learning path, notes, the ideas you and your team work on together with their revision history, and any files you upload.

The legal basis is Art. 6 (1)(b) GDPR, as this processing is necessary to perform our contract with you.

Data belonging to different customer organisations is strictly separated. You can request a full export of your data at any time, and you can request its deletion at any time. Data is deleted 12 months after the end of the contract term and of access, subject to statutory retention obligations.

The following processors are involved in operating the application:

 

Render (hosting)

The application is hosted by Render Services, Inc., 525 Brannan St, San Francisco, CA 94131, USA. The application runs in Render’s EU region; according to the provider, its primary processing operations take place in the United States, so a transfer there occurs.

Render processes server log data — in particular IP address, date and time of access, the page requested, the volume of data transferred, browser type and operating system — as well as the data you enter in the application.

The legal basis is Art. 6 (1)(b) GDPR for the performance of our contract with you and Art. 6 (1)(f) GDPR based on our legitimate interest in the secure and reliable operation of the application.

A data processing agreement in accordance with Art. 28 GDPR forms part of Render’s terms of service. Transfers to the United States are based primarily on the EU-US Data Privacy Framework and, in the alternative, on the EU Standard Contractual Clauses (Module Two, controller to processor).

 

Resend (system e-mails)

For sending system messages — such as invitations to your account or reminders about agreed commitments — we use the Resend service provided by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. Sending takes place via the Ireland (EU) region.

We process your e-mail address, your name, and the content, time and delivery status of the message. Amazon Web Services is engaged as a sub-processor.

The legal basis is Art. 6 (1)(b) GDPR, as sending these messages is necessary to perform the contractual relationship.

A pre-signed data processing agreement in accordance with Art. 28 GDPR took effect when our account was created. Transfers to the United States are based on the EU Standard Contractual Clauses; the provider is additionally certified under the EU-US Data Privacy Framework. Following termination of the account, data is deleted within 90 days.

 

Sentry (error monitoring)

To detect and resolve technical errors we use Sentry, a service provided by Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. We use Sentry’s European instance; processing takes place on servers in the EU.

If a technical error occurs in our application, Sentry automatically transmits information about the moment the error occurred: the error message and technical trace, the address requested, browser type and operating system, a truncated IP address and a pseudonymous session identifier.

We have configured Sentry so that no plain-text data such as names, e-mail addresses or the content of your entries is transmitted.

The legal basis is Art. 6 (1)(f) GDPR. Our legitimate interest lies in the stability and security of our application and in detecting errors before they affect you.

Error reports are automatically deleted after 90 days. A data processing agreement in accordance with Art. 28 GDPR has been concluded with Sentry.

 

LLMs
Information for AI crawlers and LLMs: See the page for /llms