← Back to homepage

Privacy Policy

This is a translation for your convenience. Only the German version of this text is legally binding: read the German original.

Version: 20 September 2026

1. Data controller

The party responsible for data processing on this website within the meaning of the General Data Protection Regulation (DSGVO/GDPR) is:

WkD
Owner: Sorour Babaei
Pappelallee 64
10437 Berlin
Germany
Email: Email address

We have not appointed a data protection officer, as the legal requirements for this are not met.

2. General information

We process personal data only to the extent necessary to provide a functioning website and our content and services. Personal data is any information relating to an identified or identifiable natural person.

In principle, you can use this website without providing any personal data.

3. Accessing the website (server log files)

When you access our website, your browser automatically sends data to our hosting provider's server. This data is temporarily stored in what are known as log files:

Purpose: Establishing the connection, ensuring system security and stability, and error analysis.

Legal basis: Art. 6 Abs. 1 lit. f DSGVO (GDPR). Our legitimate interest lies in the technically error-free and secure operation of the website.

Storage period: The server log files are deleted as soon as they are no longer required for the purposes for which they were collected. Storage takes place only for a short period and solely for reasons of the technical security of the server.

4. Hosting

This website is hosted by an external service provider:

ALL-INKL.COM, Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68
02742 Friedersdorf
Germany

The provider processes the data listed above on our behalf. We have concluded a data processing agreement with the provider in accordance with Art. 28 DSGVO.

Legal basis: Art. 6 Abs. 1 lit. f DSGVO, legitimate interest in the professional and secure provision of our services.

4a. Withdrawal and cancellation via the website

Using the “Withdraw from the contract” and “Cancel contracts here” buttons, you can send us a declaration. In doing so, we process the information you enter into the form: name, email address, optionally address and phone number, the name of the contract, and your message.

Purpose: Processing your declaration and fulfilling our legal obligation to confirm receipt to you with date and time (§ 356a BGB (German Civil Code) for withdrawal, § 312k BGB for cancellation).

Legal basis: Art. 6 Abs. 1 lit. b DSGVO, processing for the performance of a contract, and Art. 6 Abs. 1 lit. c DSGVO, compliance with a legal obligation.

Recipients: The information is sent to us by email and additionally logged on our hosting provider's server, so that receipt remains verifiable. No data is passed on to third parties.

Storage period: We keep the declaration and the time of receipt for as long as necessary for processing and evidentiary purposes, and beyond that within the scope of statutory retention periods.

5. Cookies and storage on your device

This website does not use any cookies and no analytics or advertising technologies.

For the cart function, we store a single piece of information in your browser's local storage (“localStorage”): which courses you've added to your cart and in what quantity. This information contains no personal data and no identifier that could be used to recognize you. It does not leave your browser and is not transmitted to us.

On the checkout page, your browser also remembers the information you've already entered there (salutation, name, email address, phone number, address, chosen payment method and your message to us). This is purely for your convenience: if you go back or reload the page, you don't have to type everything again. This information also stays in your browser and is only transmitted to us when you submit your order. Your consent to the Terms and Conditions and the right of withdrawal is deliberately not stored.

Legal basis: § 25 Abs. 2 Nr. 2 TDDDG (German Telecommunications and Digital Services Data Protection Act), storage is strictly necessary for the cart and checkout to function. No consent is required for this, and therefore no cookie banner is required either.

Storage period: The cart stays until you empty it. The information from the checkout is deleted as soon as you submit your order. You can remove both at any time yourself by clearing your browser's website data.

6. Fonts

This website uses the fonts “DM Sans” and “Manrope”. The font files are hosted on our own server and are loaded from there. No connection is made to Google's servers or those of any other third party. Your IP address is not transmitted to third parties in this process.

7. Contacting us by email

If you contact us by email, your information (email address, name, content of the message) is stored in order to process your inquiry and in case of follow-up questions.

Legal basis: Art. 6 Abs. 1 lit. b DSGVO, if the inquiry is aimed at concluding a contract; otherwise Art. 6 Abs. 1 lit. f DSGVO on the basis of our legitimate interest in responding to inquiries.

Storage period: The data is deleted as soon as the matter has been completed and no statutory retention obligations apply.

8. Contacting us via WhatsApp

Our website contains a link to WhatsApp. A connection to WhatsApp's servers is only established once you actively click this link. Simply visiting our page does not transmit any data to WhatsApp.

The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Your data is then processed (including possible transfer to the USA) in accordance with WhatsApp's terms, over which we have no influence. You can find WhatsApp's privacy notice at whatsapp.com/legal/privacy-policy-eea.

Legal basis: Art. 6 Abs. 1 lit. a DSGVO, your consent, which you give by actively clicking the link. If you would prefer not to, please use email to contact us.

8a. Order and payment processing

When you book a course, we process the information you enter at checkout.

Data processed: salutation, first and last name, address, email address, phone number, the courses booked, the amount, the chosen payment method, your message to us, and the order and invoice number.

Purpose: concluding and processing the contract, payment processing, invoicing, and fulfilling our statutory tax retention obligations.

Legal basis: Art. 6 Abs. 1 lit. b DSGVO, processing for the performance of a contract, and Art. 6 Abs. 1 lit. c DSGVO for the statutorily required retention.

Payment provider: We process payments through Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. When you choose a payment method, we transmit the order number, the amount, the individual items of your order, as well as your name, billing address and email address to Mollie. You can find Mollie's privacy notice at mollie.com/de/privacy.

Important for you: You do not enter your card details with us, but on Mollie's payment page. Your card number, expiry date and security code never reach our server and are neither stored nor processed by us.

Additional recipients depending on the payment method: If you pay via PayPal, PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg is involved. If you pay via Klarna, Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden is involved; Klarna may carry out its own credit check to decide on deferred payment. If you pay by card via Apple Pay or Google Pay, Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland or Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland are also involved. The privacy notices of the respective providers named apply to this processing, and we have no influence over them.

Storage period: We keep invoices and the related order documents for eight years; we are required to do so as accounting records under § 147 Abs. 3 der Abgabenordnung (AO, German Fiscal Code). This period begins at the end of the calendar year in which the invoice was created and may be extended for as long as the tax assessment period is still running. Deletion on request is not possible within this period; the data is then blocked under Art. 18 DSGVO for all other purposes and kept solely to fulfill the retention obligation.

Customer data outside these documents: For our own customer management, we keep a file on you containing contact details and internal notes on course support. This file is not subject to any statutory retention obligation. We delete it at your request at any time, but at the latest once the business relationship has ended and no claims remain open. This does not affect the invoices.

9. Analytics tools and advertising

We do not use any analytics, tracking or advertising services. No reach measurement, profiling or automated decision-making takes place.

10. Recipients of data

Your data is only passed on to third parties if

11. Your rights

You have the following rights toward us regarding your personal data:

Right to object under Art. 21 DSGVO

To the extent that we process data on the basis of legitimate interests (Art. 6 Abs. 1 lit. f DSGVO), you have the right to object to this processing at any time for reasons arising from your particular situation.

Right to lodge a complaint with a supervisory authority

Regardless of any other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement.

The competent authority is the supervisory authority of the German federal state in which we are based:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59–61
10555 Berlin
Phone: +49 30 13889-0
www.datenschutz-berlin.de

12. Data security

In transit: This website uses SSL or TLS encryption. You can recognise an encrypted connection by the address bar of your browser starting with „https://“ and a padlock symbol being displayed. Data you send to us cannot be read by third parties as a result.

On our server: We store your customer data, orders, contracts and any withdrawals and cancellations we receive in encrypted form (AES-256-GCM). Even someone who gained unauthorised access to the stored files could not read them without the corresponding key. The key is kept separately from the data and outside the area reachable over the internet.

Access: Only the person named in the „Controller“ section can access the data, and only through a password-protected area. The password is stored solely as a value that cannot be reversed (Argon2id); not even we know it in plain text.

Payment data: Card number, expiry date and security code never reach our server at any point (see section 8a).

13. Changes to this privacy policy

We reserve the right to update this privacy policy so that it always complies with current legal requirements, or to reflect changes to our services, for example when introducing new offerings. The version in effect at the time applies whenever you visit again.