Privacy Policy
Nexa Consulting GmbH
1. Introduction and Data Controller
We appreciate your interest in our online academy. Protecting your personal data is of particular importance to us. We treat your personal data confidentially and in accordance with the applicable data protection laws (GDPR, BDSG) as well as this Privacy Policy.
Data Controller pursuant to the GDPR:
Nexa Consulting GmbH
Hünefeldstraße 56,
42285 Wuppertal, Germany
Email: info@nexa-bildung.de
Managing Director: Ribal Dib
2. Data Collection on Our Website
Server Log Files:
When you visit our website, the hosting provider automatically collects information such as your IP address, browser type, referrer URL, and timestamp. This data is used to ensure the security and proper functionality of the website (legal basis: Art. 6 para. 1 lit. f GDPR).
Contact Form:
Data submitted through inquiries is stored for processing the request and handling any follow-up questions. Your data will not be shared without your consent (legal basis: Art. 6 para. 1 lit. b GDPR).
Cookies:
We use necessary cookies for the login area. Analytical cookies (e.g., Google Analytics) are only placed after your explicit consent via our cookie banner.
3. Registration and Use of the Learning Platform (LMS)
Registration is required to participate in our courses.
Scope of Data:
Name, email address, billing address, as well as usage-related data (course progress, test results, log times).
Purpose:
Provision of learning content, issuance of certificates, and management of your customer account.
Legal Basis:
Art. 6 para. 1 lit. b GDPR (performance of a contract).
4. Payment Processing
To process payments, we use external payment service providers (e.g., Stripe, PayPal, or Klarna).
Data Sharing:
Your payment data is transmitted directly to the respective provider. We do not store credit card details on our own servers.
Legal Basis:
Art. 6 para. 1 lit. b GDPR.
5. Third-Party Providers and Tools of the Academy
To provide our courses digitally, we use specialized tools:
Video Conferences (e.g., Zoom/Teams):
Used to conduct live webinars. During these sessions, metadata as well as audio and video data may be processed.
Email Marketing:
If you have subscribed to our newsletter, we use Mailchimp. You can unsubscribe at any time via the link provided in the email.
Hosting:
Our website and LMS data are stored with a certified hosting provider (e.g., Hetzner or AWS Frankfurt).
6. Data Transfers to Third Countries
If tools from providers outside the European Union are used (e.g., providers based in the USA), we ensure that an adequate level of data protection is maintained (e.g., through the EU-U.S. Data Privacy Framework or Standard Contractual Clauses of the European Commission).
7. Storage Period
We delete your data as soon as it is no longer required to fulfill the purpose for which it was collected.
Important:
Legal retention periods (especially tax-related documents, which must be retained for 10 years according to § 147 AO) remain unaffected.
8. Your Rights as a Data Subject
You have the right at any time to:
- Access your personal data stored by us (Art. 15 GDPR).
- Request correction of inaccurate data (Art. 16 GDPR).
- Request deletion of your data (“Right to be Forgotten”, Art. 17 GDPR).
- Request restriction of processing (Art. 18 GDPR).
- Request data portability (Art. 20 GDPR).
- Object to the processing of your data (Art. 21 GDPR).
To exercise these rights, please contact us using the email address mentioned above. You also have the right to lodge a complaint with the competent data protection supervisory authority.
9. Data Security
We use the widely adopted SSL (Secure Socket Layer) encryption protocol in combination with the highest level of encryption supported by your browser.