Legal
ISBC Privacy Policy
Comprehensive policy for ISBC and its associated websites
Version: 15 July 2026
1. Controller and scope
The controller within the meaning of the GDPR and other applicable data protection provisions is ISBC โ Int. Sport Business Coaching & Consulting, Faulenbruchstr. 102, 52159 Roetgen, Germany, phone +49 157 858 30 215, email contact@impactful-change.de. This policy applies to the ISBC domains listed in the German policy and their subdomains, including landing pages, booking, registration, event, shop and information services.
2. Terms and principles
Personal data means information relating to an identified or identifiable natural person. Processing includes collecting, storing, using, transmitting, restricting or deleting such data. We follow purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality and accountability.
3. Legal bases
Depending on the processing activity, we rely in particular on Art. 6(1)(a), (b), (c) and (f) GDPR, Art. 9(2) GDPR where special categories are exceptionally processed, and ยง 25 TDDDG for storage of or access to information on end devices.
4. Hosting, content delivery and server logs
Technical data such as IP address, date and time, requested address, referrer, browser, operating system, device, transferred data volume, status and error data may be processed to deliver the website, ensure stability and security, defend against attacks and analyze errors. Server logs are typically stored for seven to thirty days unless a security incident requires longer retention.
5. Encryption and technical security
We use TLS/SSL encryption and appropriate technical and organizational safeguards, including access controls, strong passwords, multi-factor authentication, updates, backups, logging, encryption and system separation where appropriate.
6. Cookies, local storage and consent management
Strictly necessary cookies and similar technologies may be used where required for the requested service. Non-essential analytics, convenience, media and marketing technologies are activated only after consent. Consent can be changed or withdrawn through the cookie settings.
7. Contact
When you contact us by email, phone, contact form, chat or comparable means, we process the information you provide and technical metadata to handle the request, communicate, document and prevent misuse. Requests are generally deleted six to twenty-four months after completion unless contractual or statutory obligations require longer storage.
8. Newsletter and promotional communication
Newsletters are generally sent only after explicit consent using double opt-in. Where reach measurement, open or click tracking is used, it is based on consent unless anonymous or technically necessary. Consent can be withdrawn at any time.
9. Registration, booking, coaching, consulting, workshops and events
Depending on the service, we may process name, contact details, billing address, company, role, booked service, date, event, participant data, communication, status, contract and payment information for contract initiation, performance, organization, communication, billing and follow-up.
10. Ticket shop, orders and digital services
For orders and ticket purchases, we process order, participant, billing, payment, communication and delivery data. Personalized tickets may include name, event, ticket number, category and QR or barcodes.
11. Payment processing via Stripe
We use Stripe Payments Europe Ltd. and related entities, financial partners, banks, payment networks, card schemes and subprocessors. Data may include name, email, billing and delivery address, payment method, truncated card details, account information, amount, currency, transaction number, device and browser data, IP address, fraud-prevention data, refunds and disputes. International transfers are handled in accordance with Arts. 44 et seq. GDPR.
12. Accounting, tax advice and receivables
Invoice, booking, contract and payment data may be shared with tax advisers, accounting providers, banks, payment providers, legal advisers, debt collection services and authorities where necessary or legally required.
13. Instagram and other social media links
Normal external links generally connect to the external provider only when clicked. Social network providers may then process IP address, device information, referrer, usage data and, where logged in, account information.
14. Embedded Instagram, LinkedIn, YouTube and other content
Embedded posts, videos, feeds, maps or plugins can transmit data and set cookies when loaded. Such content is generally activated only after consent unless technically necessary.
15. Web analytics
If tools such as Google Analytics or comparable services are used, they support reach measurement, error analysis and optimization and are generally activated only after consent. Data may include cookie IDs, pseudonymous identifiers, IP and device information, page views, interactions, source and approximate region.
16. Marketing, conversion measurement and remarketing
Meta Pixel, Google Ads, LinkedIn Insight Tag or similar technologies are activated only after consent. They may process interactions, page views, orders, campaign attribution, device and cookie identifiers and may create audiences.
17. External fonts, videos, maps and media
External content is integrated locally or in a data-minimizing manner where possible. Where a connection to a third-party provider is required, it is generally established only after consent unless technically necessary.
18. Email and transactional delivery
Email and delivery providers may be used for confirmations, tickets, invoices, appointments and service messages. Data may include name, email address, message content, sending time, delivery status and required booking or order information.
19. Central processing across domains and subdomains
Data collected across the listed ISBC domains and their subdomains may be processed in shared customer, communication, booking, newsletter, analytics, security or billing systems where purposes are compatible and processing is necessary for the relevant relationship.
20. Recipients and categories of recipients
- Hosting, domain, IT and security providers
- Email, newsletter, CRM and communication providers
- Stripe, banks, payment networks and payment providers
- Tax, accounting, legal advisers and authorities
- Event, ticketing, printing, shipping and cooperation partners where required
- Analytics, media and marketing providers only within the scope of consent
21. Processing on behalf and joint controllership
Processors acting only on our instructions are contractually bound under Art. 28 GDPR. Where purposes and means are jointly determined with a partner, responsibilities are regulated under Art. 26 GDPR.
22. Transfers to third countries
Some providers or subprocessors may process data outside the EU/EEA. Transfers take place only under Arts. 44 et seq. GDPR, using mechanisms such as adequacy decisions, the EU-US Data Privacy Framework for certified US organizations, Standard Contractual Clauses and supplementary safeguards.
23. Retention periods
Typical guidance values are: server logs 7โ30 days; contact requests 12โ36 months after completion; newsletter data until withdrawal with consent evidence usually retained up to three years thereafter; contract, invoice and booking data according to statutory commercial and tax retention periods; application data, where applicable, generally six months after completion; consent records according to evidentiary requirements.
24. Obligation to provide data
Certain data is contractually or legally required. Without necessary master, contact, booking, billing or payment data, contracts, orders, events or payments may not be possible.
25. Automated decisions
We generally do not make decisions with legal or similarly significant effects solely by automated means. Payment providers may perform automated risk and fraud checks.
26. Minors
Our business services are generally intended for adults. Data relating to minors is processed only where required for a specifically intended service and where a valid legal basis exists.
27. Your rights
- Access under Art. 15 GDPR
- Rectification under Art. 16 GDPR
- Erasure under Art. 17 GDPR
- Restriction under Art. 18 GDPR
- Data portability under Art. 20 GDPR
- Objection under Art. 21 GDPR
- Withdrawal of consent under Art. 7(3) GDPR
- Complaint to a supervisory authority under Art. 77 GDPR
To exercise your rights, contact contact@impactful-change.de.
28. Objection to direct marketing and legitimate interests
You may object to processing for direct marketing at any time. You may also object to processing based on legitimate interests for reasons arising from your particular situation.
29. Right to lodge a complaint
You may in particular contact the supervisory authority responsible for North Rhine-Westphalia: the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, or any supervisory authority competent under Art. 77 GDPR.
30. Changes to this Privacy Policy
We update this policy when the legal situation, services, data flows or technical procedures change. The version published on the relevant website is authoritative.