Legal

Privacy Policy

Information pursuant to Art. 13 and 14 GDPR about the processing of your data on studienkolleg.org.

Updated: Aug 8, 2026

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) is:

Henry van de Vorming
c/o AutorenServices.de
Birkenallee 24
36037 Fulda
Germany

Email: hello@arrimundo.com

2. Overview of Data Processing

Studienkolleg.org is an information portal. We process personal data to operate and secure the website, for reach and usage analytics, and for the marketing of advertising space – partly on the basis of legitimate interests, partly on the basis of your consent (see Sections 8–10 for details). The following types of data may be affected:

  • Usage data – pages visited, access times, referrer URLs
  • Meta/communication data – IP addresses (anonymised), device and browser information
  • Analytics and advertising data – pseudonymous identifiers as well as interaction and device information from the analytics and advertising services used
  • Contact data – email address, if you contact us

There is no registration and no login on this website. This website is financed by advertising: Mediavine's advertising and audience-engagement scripts are embedded on every page (Section 10). They are loaded automatically when the page is opened so that the consent window (CMP) can appear; cookies, unique identifiers and the sharing of data with advertising partners are then governed by the choice you make there. Google Analytics (Section 9) is only loaded after you have given consent. Data is transferred to third countries outside the EU/EEA only where explicitly stated below.

3. Legal Bases

We process personal data on the basis of the following legal grounds under the GDPR:

  • Art. 6(1)(a) GDPR – Consent of the data subject
  • Art. 6(1)(b) GDPR – Performance of a contract or pre-contractual measures
  • Art. 6(1)(f) GDPR – Legitimate interests (e.g. security and optimisation of the website)

Where cookies or comparable technologies are used, their permissibility is additionally governed by § 25 TDDDG (German Telecommunications Digital Services Data Protection Act, formerly TTDSG).

4. Security Measures

We implement technical and organisational measures in accordance with Art. 32 GDPR to ensure a level of protection appropriate to the risk. These include in particular:

  • Encrypted data transmission via HTTPS/TLS
  • Regular review of security measures
  • Access control and minimisation of processed data

5. Hosting

This website is hosted by Netlify, Inc. (44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA). When you visit our website, connection data (e.g. IP address, time of access) is automatically collected by Netlify and stored in server log files.

Netlify is certified under the EU-U.S. Data Privacy Framework, ensuring an adequate level of data protection. For more information, please see the Netlify Privacy Policy.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the reliable provision of the website).

6. Access Data & Server Log Files

Each time you access our website, the following data is automatically collected and temporarily stored in server log files:

  • IP address of the requesting device
  • Date and time of access
  • Requested URL and HTTP status code
  • Amount of data transferred
  • Referrer URL (previously visited page)
  • Browser type and version, operating system

This data is used exclusively to ensure smooth operation and to improve our services, and is deleted after no more than 30 days. No identification of individual persons takes place.

Legal basis: Art. 6(1)(f) GDPR.

7. Cookies & Storage Technologies

For our own features we use no tracking cookies and only employ technically necessary storage technologies:

  • Local Storage – To save user preferences (e.g. dark mode setting, language preference)
  • Service Worker Cache – For offline functionality and faster page loading

These technologies are strictly necessary for the functionality of the website and are not used for tracking. Consent is not required for these pursuant to § 25(2)(2) TDDDG.

An exception are consent-based third-party services: Google Analytics (see Section 9) is only loaded after you have given consent. The advertising and Grow scripts from Mediavine (see Section 10), by contrast, are embedded on every page and are loaded automatically because they bring the consent window with them; they set cookies, unique identifiers and comparable storage technologies in accordance with the choice you make in that window. For technical reasons, your IP address is already transmitted to Mediavine's and Grow's servers when these scripts are loaded (details in Section 10).

Legal basis: § 25(2)(2) TDDDG in conjunction with Art. 6(1)(f) GDPR.

8. Web Analytics Tools

To analyse website usage and improve our services, we use the following privacy-friendly analytics tools:

a) Plausible Analytics

We use Plausible Analytics (Plausible Insights OÜ, Tallinn, Estonia). Plausible is a privacy-friendly analytics tool that uses no cookies and collects no personal data. No IP addresses are stored or shared with third parties. All data is processed on servers within the EU.

Plausible only collects aggregated, anonymous usage statistics (page views, referrers, device type, country). It is not possible to identify individual users.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analysing website usage). Consent is not required as no personal data is processed.

More information: plausible.io/data-policy

b) PostHog

We use PostHog (PostHog, Inc.) for product analytics. PostHog helps us understand how the website is used and improve the user experience. The following data may be collected:

  • Anonymised usage data (page views, click paths, time on site)
  • Device information (browser type, screen size, operating system)
  • Approximate location (country level, based on anonymised IP)

We have configured PostHog so that IP addresses are not stored in full. No tracking cookies are set. Data is processed on servers within the EU (Frankfurt).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the analysis and optimisation of the website).

More information: posthog.com/privacy

9. Google Analytics

With your consent, we use Google Analytics, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, USA). Google Analytics helps us understand how the website is used and improve our services.

For this purpose, cookies and comparable technologies are used and, among others, the following data is processed:

  • truncated (anonymised) IP address as well as device and browser information
  • usage data (pages visited, time on site, interactions, referrer)
  • a pseudonymous identifier (Client ID) to recognise the device
  • approximate location (city/country level)

Google Analytics is loaded via the Cloudflare Zaraz consent management only after you have given consent. Your consent is voluntary and can be withdrawn at any time with effect for the future (e.g. via the cookie settings).

Transfer to the USA: data may be transferred to Google LLC in the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework; EU Standard Contractual Clauses are additionally in place.

Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TDDDG.

More information: Google Privacy Policy.

10. Advertising: Mediavine & Grow

This website is financed by advertising. The advertising space is marketed by Mediavine, Inc. (8 The Green, #20971, Dover, DE 19901, USA) — under the brand name "Journey by Mediavine". For this purpose, two Mediavine scripts are embedded on every page, which are loaded automatically when the page is opened:

  • Advertising script (scripts.scriptwrapper.com) – controls the delivery of the advertisements, the auction for advertising space (header bidding/Prebid) and brings along Mediavine's consent window (consent management platform, CMP).
  • Grow (faves.grow.me) – provides audience-engagement and audience features (e.g. saving articles as "Faves", following our content, an optional reader account) and works together with the consent management.

In connection with these services, the following data may be processed:

  • IP address as well as device and browser information
  • Usage data (pages visited, time on site, interactions with advertisements and Grow features)
  • Cookie and device identifiers (unique identifiers)
  • Approximate location (at country/region level, derived from the IP address)
  • The choice you make in the consent window (consent signal under the TCF standard)

a) What happens before you give your consent

We state this openly: both scripts are loaded irrespective of your consent, because the consent window itself is part of the Mediavine script. In doing so, your IP address is technically transmitted to Mediavine's and Grow's servers. For this purpose, Grow calls the endpoint api.grow.me/location-privacy-info and uses the IP address to determine your approximate location in order to establish which data protection regime applies to you and whether — and which — consent window has to be displayed. This initial transmission is technically necessary so that the consent request can be presented in a legally compliant manner in the first place.

Legal basis for this: Art. 6(1)(f) GDPR (legitimate interest in providing a functioning consent management system and in the advertising-financed provision of this service).

b) What happens only after you have given your consent

The setting of cookies and comparable storage technologies, the assignment of unique identifiers, the delivery of personalised advertising and the sharing of data with the integrated programmatic third-party providers (advertising networks, demand-side platforms and measurement service providers) are governed by the choice you make in the consent window. These third-party providers are integrated via the framework of the IAB Europe Transparency & Consent Framework (TCF); you can view the complete, up-to-date list of providers as well as the purposes they pursue in the consent window. These providers are separate controllers or process the data under their own responsibility.

Legal basis for this: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act).

c) Withdrawal

Your consent is voluntary and can be withdrawn or changed at any time with effect for the future: to do so, open the settings window of the Mediavine CMP via the "Privacy settings" or "Consent settings" link that Mediavine displays at the bottom of the page, and adjust your choice. Withdrawal does not affect the lawfulness of the processing carried out up to that point.

d) Transfer to the USA

Mediavine, Grow and some of the advertising partners integrated via the TCF process data in the United States and, where applicable, in further third countries. There is no level of data protection there comparable to that in the EU; in particular, access to this data by US authorities cannot be ruled out and legal remedies may be limited. The transfer is based on appropriate safeguards within the meaning of Art. 44 et seq. GDPR (in particular EU Standard Contractual Clauses as well as – where the respective provider is certified – the EU-U.S. Data Privacy Framework); insofar as the transfer is based on your consent, additionally on Art. 49(1)(a) GDPR.

More information on data processing by Mediavine: Mediavine Privacy Policy.

11. Contact

If you contact us by email, the data you provide (email address, possibly your name, message content) will be stored by us in order to respond to your enquiry. We delete the data collected in this context once storage is no longer necessary, or restrict processing where statutory retention obligations apply.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).

12. Rights of Data Subjects

As a data subject, you have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR) – You may request information about the data we process about you.
  • Right to rectification (Art. 16 GDPR) – You may request the correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) – You may request the deletion of your data, provided no statutory retention obligations apply.
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR) – You may object at any time to the processing of your data based on Art. 6(1)(f) GDPR.
  • Right to withdraw consent (Art. 7(3) GDPR) – Any consent given may be withdrawn at any time with effect for the future.

To exercise your rights, please contact: hello@arrimundo.com

Right to lodge a complaint with a supervisory authority

If you believe that the processing of your personal data infringes the GDPR, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority. You may contact the supervisory authority of your place of residence, your workplace, or the place of the alleged infringement.

13. Changes to This Privacy Policy

We reserve the right to amend this privacy policy to ensure it always complies with current legal requirements or to reflect changes to our services. The new privacy policy will apply to any subsequent visit.