Legal

ISBC Privacy Policy

Comprehensive policy for ISBC and its associated websites

Version: 15 July 2026

This is an English translation of the German privacy policy for international visitors. The legal framework referenced is primarily the GDPR and German data protection law.

1. Controller and scope

The controller within the meaning of the GDPR and other applicable data protection provisions is ISBC โ€“ Int. Sport Business Coaching & Consulting, Faulenbruchstr. 102, 52159 Roetgen, Germany, phone +49 157 858 30 215, email contact@impactful-change.de. This policy applies to the ISBC domains listed in the German policy and their subdomains, including landing pages, booking, registration, event, shop and information services.

2. Terms and principles

Personal data means information relating to an identified or identifiable natural person. Processing includes collecting, storing, using, transmitting, restricting or deleting such data. We follow purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality and accountability.

3. Legal bases

Depending on the processing activity, we rely in particular on Art. 6(1)(a), (b), (c) and (f) GDPR, Art. 9(2) GDPR where special categories are exceptionally processed, and ยง 25 TDDDG for storage of or access to information on end devices.

4. Hosting, content delivery and server logs

Technical data such as IP address, date and time, requested address, referrer, browser, operating system, device, transferred data volume, status and error data may be processed to deliver the website, ensure stability and security, defend against attacks and analyze errors. Server logs are typically stored for seven to thirty days unless a security incident requires longer retention.

5. Encryption and technical security

We use TLS/SSL encryption and appropriate technical and organizational safeguards, including access controls, strong passwords, multi-factor authentication, updates, backups, logging, encryption and system separation where appropriate.

6. Cookies, local storage and consent management

Strictly necessary cookies and similar technologies may be used where required for the requested service. Non-essential analytics, convenience, media and marketing technologies are activated only after consent. Consent can be changed or withdrawn through the cookie settings.

7. Contact

When you contact us by email, phone, contact form, chat or comparable means, we process the information you provide and technical metadata to handle the request, communicate, document and prevent misuse. Requests are generally deleted six to twenty-four months after completion unless contractual or statutory obligations require longer storage.

8. Newsletter and promotional communication

Newsletters are generally sent only after explicit consent using double opt-in. Where reach measurement, open or click tracking is used, it is based on consent unless anonymous or technically necessary. Consent can be withdrawn at any time.

9. Registration, booking, coaching, consulting, workshops and events

Depending on the service, we may process name, contact details, billing address, company, role, booked service, date, event, participant data, communication, status, contract and payment information for contract initiation, performance, organization, communication, billing and follow-up.

10. Ticket shop, orders and digital services

For orders and ticket purchases, we process order, participant, billing, payment, communication and delivery data. Personalized tickets may include name, event, ticket number, category and QR or barcodes.

11. Payment processing via Stripe

We use Stripe Payments Europe Ltd. and related entities, financial partners, banks, payment networks, card schemes and subprocessors. Data may include name, email, billing and delivery address, payment method, truncated card details, account information, amount, currency, transaction number, device and browser data, IP address, fraud-prevention data, refunds and disputes. International transfers are handled in accordance with Arts. 44 et seq. GDPR.

12. Accounting, tax advice and receivables

Invoice, booking, contract and payment data may be shared with tax advisers, accounting providers, banks, payment providers, legal advisers, debt collection services and authorities where necessary or legally required.

13. Instagram and other social media links

Normal external links generally connect to the external provider only when clicked. Social network providers may then process IP address, device information, referrer, usage data and, where logged in, account information.

14. Embedded Instagram, LinkedIn, YouTube and other content

Embedded posts, videos, feeds, maps or plugins can transmit data and set cookies when loaded. Such content is generally activated only after consent unless technically necessary.

15. Web analytics

If tools such as Google Analytics or comparable services are used, they support reach measurement, error analysis and optimization and are generally activated only after consent. Data may include cookie IDs, pseudonymous identifiers, IP and device information, page views, interactions, source and approximate region.

16. Marketing, conversion measurement and remarketing

Meta Pixel, Google Ads, LinkedIn Insight Tag or similar technologies are activated only after consent. They may process interactions, page views, orders, campaign attribution, device and cookie identifiers and may create audiences.

17. External fonts, videos, maps and media

External content is integrated locally or in a data-minimizing manner where possible. Where a connection to a third-party provider is required, it is generally established only after consent unless technically necessary.

18. Email and transactional delivery

Email and delivery providers may be used for confirmations, tickets, invoices, appointments and service messages. Data may include name, email address, message content, sending time, delivery status and required booking or order information.

19. Central processing across domains and subdomains

Data collected across the listed ISBC domains and their subdomains may be processed in shared customer, communication, booking, newsletter, analytics, security or billing systems where purposes are compatible and processing is necessary for the relevant relationship.

20. Recipients and categories of recipients

  • Hosting, domain, IT and security providers
  • Email, newsletter, CRM and communication providers
  • Stripe, banks, payment networks and payment providers
  • Tax, accounting, legal advisers and authorities
  • Event, ticketing, printing, shipping and cooperation partners where required
  • Analytics, media and marketing providers only within the scope of consent

21. Processing on behalf and joint controllership

Processors acting only on our instructions are contractually bound under Art. 28 GDPR. Where purposes and means are jointly determined with a partner, responsibilities are regulated under Art. 26 GDPR.

22. Transfers to third countries

Some providers or subprocessors may process data outside the EU/EEA. Transfers take place only under Arts. 44 et seq. GDPR, using mechanisms such as adequacy decisions, the EU-US Data Privacy Framework for certified US organizations, Standard Contractual Clauses and supplementary safeguards.

23. Retention periods

Typical guidance values are: server logs 7โ€“30 days; contact requests 12โ€“36 months after completion; newsletter data until withdrawal with consent evidence usually retained up to three years thereafter; contract, invoice and booking data according to statutory commercial and tax retention periods; application data, where applicable, generally six months after completion; consent records according to evidentiary requirements.

24. Obligation to provide data

Certain data is contractually or legally required. Without necessary master, contact, booking, billing or payment data, contracts, orders, events or payments may not be possible.

25. Automated decisions

We generally do not make decisions with legal or similarly significant effects solely by automated means. Payment providers may perform automated risk and fraud checks.

26. Minors

Our business services are generally intended for adults. Data relating to minors is processed only where required for a specifically intended service and where a valid legal basis exists.

27. Your rights

  • Access under Art. 15 GDPR
  • Rectification under Art. 16 GDPR
  • Erasure under Art. 17 GDPR
  • Restriction under Art. 18 GDPR
  • Data portability under Art. 20 GDPR
  • Objection under Art. 21 GDPR
  • Withdrawal of consent under Art. 7(3) GDPR
  • Complaint to a supervisory authority under Art. 77 GDPR

To exercise your rights, contact contact@impactful-change.de.

28. Objection to direct marketing and legitimate interests

You may object to processing for direct marketing at any time. You may also object to processing based on legitimate interests for reasons arising from your particular situation.

29. Right to lodge a complaint

You may in particular contact the supervisory authority responsible for North Rhine-Westphalia: the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, or any supervisory authority competent under Art. 77 GDPR.

30. Changes to this Privacy Policy

We update this policy when the legal situation, services, data flows or technical procedures change. The version published on the relevant website is authoritative.

Back to homepage