Privacy Policy
This is a courtesy English translation — the German version (Datenschutzerklärung) is legally binding.
1) Controller and Contact Details
We are delighted that you are visiting our website. In the following, we explain how we process your personal data in the course of your use of our website. Personal data is any information that allows you to be personally identified.
The controller for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Daniel Dörr – Boulderwald
In der Grafschaft 16, 35102 Lohra, Germany
Phone: 0160 6356390
Email: [email protected]
To protect your data and to securely transmit confidential content, our website uses SSL/TLS encryption (recognisable by “https://” and the padlock symbol in your browser’s address bar).
2) Hosting and Server Log Files
Our website is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). On each access, the server automatically collects data that your browser transmits (“server log files”): the page accessed, date and time, volume of data transferred, source/referrer, the browser and operating system used, and the (anonymised where possible) IP address. This data is technically necessary to display the website and to ensure its stability and security. The legal basis is our legitimate interest in a stable and secure provision (Art. 6(1)(f) GDPR). A data processing agreement is in place with Vercel; any transfer to the USA takes place on the basis of the EU Standard Contractual Clauses.
3) Cookies and Consent Management
Cookies are small text files that are stored on your device. We use only technically necessary cookies as well as — subject to your consent — cookies for optional services. Where personal data is processed through cookies, this is done to perform the contract (Art. 6(1)(b) GDPR), on the basis of your consent (Art. 6(1)(a) GDPR) or to safeguard our legitimate interests (Art. 6(1)(f) GDPR).
To manage your consent, we use the consent management tool CCM19 provided by Papoo Software & Media GmbH (Auguststraße 4, 53229 Bonn, Germany). You can withdraw or adjust your consent at any time with effect for the future via the cookie notice. You can also control the storage of cookies via your browser settings; deactivation may restrict the functionality of the website.
4) Reach Measurement
For the statistical analysis of the use of our website (e.g. page views), we use a data-minimising, cookieless reach measurement provided by Münz Media GmbH (base.muenzmedia.de). No cookies are set and no cross-device profiles are created; the processing is carried out in an anonymised or pseudonymised form. The legal basis is our legitimate interest in the needs-based design and optimisation of our website (Art. 6(1)(f) GDPR). Münz Media GmbH acts as a processor on our behalf.
5) Contacting Us
When you contact us (e.g. by email or contact form), the personal data you provide is processed to handle your enquiry and the associated technical administration. The legal basis is our legitimate interest in processing your enquiry (Art. 6(1)(f) GDPR); if the enquiry is aimed at concluding a contract, Art. 6(1)(b) GDPR additionally applies. For storage and delivery we use the service providers named under section 8. Your data will be deleted once your matter has been conclusively dealt with and no statutory retention obligations prevent this.
6) Online Appointment Booking and Payment Processing
In the course of the online booking of courses and trips, we process the data you provide in the booking form (e.g. name, contact details, participant information). The processing is carried out to perform the contract (Art. 6(1)(b) GDPR). Booking data is stored in a database of our service provider Supabase (processing on our behalf).
Payments are processed via the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). The data required for payment is transmitted directly to Stripe; the legal basis is Art. 6(1)(b) GDPR. Stripe’s privacy policy additionally applies (https://stripe.com/de/privacy).
7) Email Newsletter
If you sign up for our newsletter, we process your email address to send you information about our offers. Dispatch takes place using the double opt-in procedure: you will only receive the newsletter once you have actively verified your registration via a confirmation link. The legal basis is your consent (Art. 6(1)(a) GDPR). To prevent misuse, we store the IP address and time of registration. You can unsubscribe at any time via the unsubscribe link or by notifying us; your address will then be deleted from the newsletter distribution list.
As an existing customer, we may send you offers for similar services on the basis of Art. 6(1)(f) GDPR in conjunction with Section 7(3) of the German Act Against Unfair Competition (UWG); you may object to this at any time.
8) Service Providers Used (Processing on Our Behalf)
For sending emails (e.g. booking/contact confirmations, newsletters) we use the service Twilio SendGrid (Twilio Inc., USA). For hosting (Vercel), database (Supabase), payment processing (Stripe), consent management (CCM19) and reach measurement (Münz Media GmbH), the details stated above apply. Where necessary, data processing agreements are in place with these service providers; in the case of transfers to third countries (e.g. the USA), these are safeguarded by the EU Standard Contractual Clauses.
9) Your Rights
Under the GDPR, you have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of a consent granted (Art. 7(3) GDPR)
- Lodging a complaint with a data protection supervisory authority (Art. 77 GDPR)
Right to object (Art. 21 GDPR): You have the right, on grounds relating to your particular situation, to object at any time to the processing of your data where it is based on a legitimate interest. You may object to processing for direct marketing purposes at any time without giving reasons.
10) Storage Period
The duration of storage depends on the respective legal basis and the purpose of processing. Data processed on the basis of consent is stored until consent is withdrawn. Data subject to statutory retention periods (e.g. under commercial or tax law) is deleted once these periods have expired.