Privacy Policy
We (How To Study German LLC) take data protection seriously. This notice explains what personal data we process when you use our website, on which legal bases (GDPR), for which purposes, and how you can exercise your rights.
1) Controller & Contact
Controller:
How To Study German LLC
30 N Gould St Ste N, Sheridan, WY 82801, United States
Email: in**@**************an.com
EU Representative (Art. 27 GDPR):
EXCHANGENB OÜ, Männimäe 1, Pudisoo küla, 74626 Kuusalu vald, Harju maakond, Estonia
Email: in**@**************an.com
Appointed as our official EU Representative under Article 27 GDPR, acting as the contact point for supervisory authorities and data subjects in the European Union on all data-protection matters relating to this website.
Data Protection Officer:
We have not appointed a Data Protection Officer, as the criteria of Art. 37 GDPR are not met (no large-scale monitoring, no large-scale processing of special categories of data).
2) Legal Bases
- Art. 6(1)(b) GDPR – performance of a contract or steps prior to entering into a contract.
- Art. 6(1)(a) GDPR – consent (e.g. analytics, advertising, newsletters, social login, embedded media).
- Art. 6(1)(f) GDPR – legitimate interests (security, fraud prevention, website operation).
- Art. 6(1)(c) GDPR – legal obligations (tax and accounting).
3) What We Process & Why
- Server access data (IP address, timestamp, referrer, user agent) for security and stability.
- Contact data (name, email, message) when you contact us by form or email.
- Order and payment data for digital products (see Paddle).
- Newsletter data (email address, first name) if you subscribe.
- Account data (name, email address, provider user ID) if you register or log in via social login.
- Security logs of logged-in users to prevent unauthorized access.
- Cookies and Local Storage as described below.
Quizzes and interactive tools:
Our quizzes and interactive grammar tools (e.g. the Article Trainer) are evaluated exclusively client-side in your browser. Your answers and results are not stored on our servers, not linked to your person, and not transmitted to third parties. Accordingly, no personal data is processed when you use these tools.
4) Cookies, Local Storage & Consent
Real Cookie Banner:
We use Real Cookie Banner (provided by devowl.io GmbH, Germany) to manage consent for cookies and external services. Essential cookies are required for the operation and security of the website. Non-essential cookies (e.g. analytics, marketing, social login, embedded media) are used only after consent. Your consent decision is stored so that we can document it, and you can change or withdraw it at any time via the cookie settings link on our website, with effect for the future.
Retention of consent records: until withdrawal or re-consent (max. 12 months).
Local Storage (Functional Elements):
We use the so-called “Local Storage” of your browser to save technical status information (e.g., whether you have already seen or closed a promotional popup/sticky bar). This ensures that popups are not displayed to you repeatedly within a certain timeframe.
This data is stored locally on your device, contains no personal identifiers, and is not transferred to third parties.
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in usability) and § 25(2) No. 2 TDDDG (technical necessity; TDDDG is the German law formerly known as TTDSG).
5) Third-Party Services & Plugins
5.1 Security & Bot Protection – Cloudflare
We use Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA) as a security and performance service to protect our website against malicious traffic, bots, and attacks (e.g. DDoS).
Cloudflare processes technical connection data such as IP addresses, request metadata, and security-related information.
This processing is essential to protect the website and is based on Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention). Data may be transferred to the USA; Cloudflare provides appropriate safeguards through the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (SCCs).
Privacy policy: https://www.cloudflare.com/privacypolicy/
5.2 Bot Protection on Forms – Cloudflare Turnstile
We use Cloudflare Turnstile (Cloudflare, Inc., USA) as a CAPTCHA-free bot protection tool to secure our forms against automated abuse. Turnstile analyses browser signals and interaction patterns to distinguish between humans and automated bots. No personal profiling is performed. Technical data (e.g. IP address, browser information) may be transmitted to Cloudflare, including to servers in the USA, where appropriate safeguards are provided through the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (SCCs).
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in preventing spam and abuse).
Privacy policy: https://www.cloudflare.com/privacypolicy/
5.3 Payments – Paddle (Merchant of Record)
Payments for digital products are handled by Paddle as Merchant of Record.
Paddle processes payment and billing data independently as controller. Your payment card details are never transmitted to, or stored by, us.
Legal basis: Art. 6(1)(b) (performance of a contract) and Art. 6(1)(c) GDPR (tax and accounting obligations). Where data is transferred outside the EU/EEA, appropriate safeguards are provided through EU Standard Contractual Clauses (SCCs).
Retention: order and payment records are retained for up to 10 years in compliance with tax and accounting obligations.
https://www.paddle.com/legal/privacy
5.4 Anti-Spam – CleanTalk
We use CleanTalk Anti-Spam and CleanTalk Security to protect forms, logins, and the website from spam and attacks.
Technical data such as IP addresses and request patterns may be processed. Where data is transferred to the USA, appropriate safeguards are provided through EU Standard Contractual Clauses (SCCs).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in spam and abuse prevention).
5.5 Security – Wordfence
We use the security plugin Wordfence, provided by Defiant, Inc. (1700 Westlake Ave N Ste 200, Seattle, WA 98109, USA), to protect our website against cyberattacks, malicious traffic, and brute-force logins. For this purpose, your IP address and website activity data are processed.
The legal basis for this processing is our legitimate interest in maintaining the security and integrity of our website according to Art. 6(1)(f) GDPR.
Since data is transferred to the USA, the provider guarantees an adequate level of data protection by using EU Standard Contractual Clauses (SCCs). For more information, please refer to the Wordfence Privacy Policy: https://www.wordfence.com/privacy-policy/
5.6 Tag Management – Google Tag Manager (GTM4WP)
We use Google Tag Manager, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), to manage and deploy marketing and analytics tags on our website. The plugin GTM4WP (Google Tag Manager for WordPress) is used to integrate the GTM container into WordPress.
Google Tag Manager itself does not set cookies or collect personal data independently. It acts solely as a container that controls which other tags (e.g. Google Analytics, Google Ads) are loaded – and only after the visitor has given their consent via our cookie banner.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient tag management); marketing tags within GTM are loaded only on the basis of Art. 6(1)(a) GDPR (consent).
Privacy policy: https://policies.google.com/privacy
5.7 Analytics – Google Analytics
If enabled and after your consent, we use Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to analyse website usage. Data collected may include page views, session duration, device information, and approximate location. Google Analytics is deployed via Google Tag Manager and only activated after consent.
IP addresses are anonymised before storage. Data may be transferred to Google servers in the USA; Google provides appropriate safeguards through the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs).
Legal basis: Art. 6(1)(a) GDPR (consent).
Retention: up to 14 months (Google Analytics data-retention setting).
Privacy policy: https://policies.google.com/privacy
5.8 Advertising – Google Ads (Remarketing & Conversion Tracking)
We use Google Ads (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for online advertising and to measure the effectiveness of our ads. This includes:
- Remarketing: Visitors to our website may be shown personalised ads on Google Search or other websites within the Google Display Network.
- Conversion Tracking: We track whether users who clicked on one of our ads subsequently completed a desired action (e.g. booking a lesson or purchasing a product).
For these purposes, Google places a cookie or uses similar technologies on your device. A pseudonymous ID is used to recognise returning visitors. No personally identifiable information is collected or linked to your identity by us.
Google Ads tags are deployed via Google Tag Manager and are only activated after your consent. Data may be transferred to Google servers in the USA; Google provides appropriate safeguards through the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs).
Legal basis: Art. 6(1)(a) GDPR (consent).
You can opt out of personalised advertising at any time at: https://adssettings.google.com
Privacy policy: https://policies.google.com/privacy
5.9 Advertising – Microsoft Advertising (Bing UET: Remarketing & Conversion Tracking)
We use Microsoft Advertising (operated by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA; in the EU represented by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland), including its Universal Event Tracking (UET) technology, for online advertising and to measure the effectiveness of our ads. This includes:
- Remarketing: Visitors to our website may be shown personalised ads on Bing and other partners within the Microsoft Advertising Network.
- Conversion Tracking: We track whether users who clicked on one of our ads subsequently completed a desired action (e.g. purchasing a product or subscribing to our newsletter).
For these purposes, Microsoft places cookies (e.g. _uetsid, _uetvid, MUID) or uses similar technologies on your device. A pseudonymous ID is used to recognise returning visitors. No personally identifiable information is collected or linked to your identity by us.
The Microsoft UET tag is integrated and managed via our consent manager (Real Cookie Banner) and is only activated after your consent. Data may be transferred to Microsoft servers in the USA; Microsoft is certified under the EU-US Data Privacy Framework and additionally provides appropriate safeguards through Standard Contractual Clauses (SCCs).
Legal basis: Art. 6(1)(a) GDPR (consent).
You can manage your advertising preferences at any time at: https://account.microsoft.com/privacy/ad-settings
Privacy policy: https://privacy.microsoft.com/en-us/privacystatement
5.10 Forms – WPForms & Contact Form 7
When you submit a contact form, we process the data you enter (e.g. name, email address, message) together with technical submission metadata (IP address, timestamp) in order to handle your request. Form submissions are stored on our hosting infrastructure and forwarded to our mailbox (see Section 5.13).
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps) and Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
5.11 Newsletter (MailerLite)
We use MailerLite (UAB “MailerLite”, J. Basanavičiaus 15, LT-03108 Vilnius, Lithuania) to manage our subscriber list and send emails.
Registration & Double Opt-In:
If you subscribe to our newsletter, we process your email address and name. Registration takes place via a so-called double opt-in procedure (you will receive a confirmation email asking you to confirm your registration). This prevents misuse of your email address.
Legal Basis:
- The sending of the newsletter is based on your consent (Art. 6(1)(a) GDPR).
- The technical provision of the sign-up form and the processing of data to ensure the security of our system (spam protection) is based on our legitimate interest (Art. 6(1)(f) GDPR) in offering a secure and user-friendly newsletter system.
Data Processing:
MailerLite is based in the EU (Lithuania) and processes data in compliance with the GDPR. Where sub-processors outside the EU/EEA are used, MailerLite ensures appropriate safeguards through Standard Contractual Clauses (SCCs).
You can unsubscribe at any time via the link in every email. Your data is retained until you unsubscribe.
Privacy Policy MailerLite: https://www.mailerlite.com/legal/privacy-policy
5.12 Social Login – Nextend Social Login (Google, Facebook, X)
We offer the option to register and log in to our website using an existing account with Google (Google Ireland Limited, Dublin, Ireland), Facebook (Meta Platforms Ireland Ltd., Dublin, Ireland) or X instead of creating a separate password. This function is provided by the plugin Nextend Social Login, which runs on our own server.
A connection to the respective provider is established only when you actively click the corresponding login button. You are then redirected to the provider, where you log in and authorise the transfer of data. We receive only the profile data you have expressly authorised – typically your name, email address and the provider’s user ID. We do not receive your password, and we do not access your contacts, posts or other profile content.
The providers may process your data as independent controllers and may transfer it to the USA; appropriate safeguards are provided through the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs). Please refer to the providers’ own privacy policies for details.
Legal basis: Art. 6(1)(a) GDPR (consent – you decide actively whether to use social login) and Art. 6(1)(b) GDPR (creation and operation of your user account).
Retention: account data is stored until you delete your user account. You can revoke our app’s access at any time in the settings of the respective provider.
Privacy policies: Google · Meta/Facebook
5.13 Email Communication – Zoho
Our email inbox (in**@**************an.com) is operated with Zoho Mail (Zoho Corporation), which acts as our processor under a data processing agreement pursuant to Art. 28 GDPR. When you contact us by email – or when a contact form submission is forwarded to us – Zoho processes your name, email address, the content of your message and technical email metadata on our behalf.
Data is processed within the EU/EEA (EU data center). Where sub-processors outside the EU/EEA are used, appropriate safeguards are provided through Standard Contractual Clauses (SCCs).
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps and contract performance) and Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
Retention: until your enquiry has been resolved and any statutory retention periods have expired.
5.14 Hosting & Page Builder – Elementor Cloud
Our website is hosted via Elementor Cloud Hosting (Elementor Ltd.).
Technical and usage data – in particular server access data such as IP address, timestamp, referrer, user agent and requested URL – may be processed on Elementor servers under a GDPR-compliant DPA. Elementor Cloud runs on Google Cloud infrastructure; where data is hosted in the USA, appropriate safeguards are provided through Standard Contractual Clauses (SCCs).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable operation of the website).
Retention: server access logs are typically deleted within 30 days.
https://elementor.com/dpa
5.15 Fonts – Local Google Fonts
We use the plugin Local Google Fonts to host all Google Fonts used on this website on our own server. As a result, no font requests – and therefore no IP addresses – are transmitted to Google when you visit our pages.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly and performant font delivery).
5.16 Embedded Videos (YouTube)
Embedded YouTube videos (Google Ireland Limited / YouTube, Google LLC) are loaded only after your consent via our cookie banner. Once loaded, Google may receive technical data such as your IP address, device and browser information, and may set cookies on your device. Data may be transferred to the USA; appropriate safeguards are provided through the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs).
Legal basis: Art. 6(1)(a) GDPR (consent).
Privacy policy: https://policies.google.com/privacy
5.17 Security Activity Logs
To ensure the security of our website and defend against bot attacks or unauthorized access, we log administrative actions and login attempts of logged-in users.
Data processed includes IP address, username (public display name), timestamp, and the specific action performed. These logs are stored locally in our WordPress database and are not transmitted to third parties.
Retention: These logs are automatically deleted after 3 months.
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in website security and error diagnosis).
5.18 Other Operational Plugins
We use further plugins purely for the technical operation, performance, structure and search-engine optimisation of the website – for example caching, code snippets, custom CSS/JS, redirects, table of contents, structured data and SEO tools. These plugins run server-side within our own WordPress installation and do not transmit personal data to third parties. Where redirect management temporarily logs error pages (404) including the IP address for diagnostic purposes, these entries are typically deleted within 30 days.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating, maintaining and securing the website).
6) Retention
We store personal data only as long as necessary for the stated purposes or as required by law. In particular:
- Server and access logs: typically deleted within 30 days.
- Security logs (Wordfence, CleanTalk): deleted within 30 days.
- Security activity logs (logged-in users): deleted after 3 months.
- Consent records (Real Cookie Banner): until withdrawal or re-consent (max. 12 months).
- Order and payment records (Paddle): up to 10 years (tax and accounting obligations).
- Newsletter data (MailerLite): until you unsubscribe.
- Email correspondence (Zoho): until your enquiry is resolved and any statutory retention periods expire.
- Analytics data (Google Analytics): up to 14 months.
- Advertising cookies (Google Ads, Microsoft UET): cookie lifetime as set by the respective provider.
- Account data (social login): until the user account is deleted.
- Quiz and tool usage: not stored – evaluated client-side in your browser only.
7) International Transfers
Where data are transferred outside the EU/EEA – in particular to the USA – appropriate safeguards are used, namely certification under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (SCCs). The specific safeguard applicable to each service is stated in Section 5.
8) Security
We apply technical and organizational security measures such as SSL/TLS encryption, a web application firewall, malware and brute-force protection, role-based access controls, and regular backups to protect your data against unauthorized access, loss, or misuse.
9) Your Rights
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR), with effect for the future
- Right to lodge a complaint with a supervisory authority
To exercise your rights, contact us at in**@**************an.com, or contact our EU Representative (EXCHANGENB OÜ, see Section 1).
10) Changes to This Policy
We may update this Privacy Policy to reflect legal or technical changes. The current version is always available on this page.
Last updated: 14 July 2026