Privacy Policy
Last Updated: March 8, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how innoventra (“we”, “us”, or “our”) collects, uses, and protects personal data when you visit our website and when you contact us about online courses, live webinars, masterclasses, intensives, or educational programs. Our goal is plain-language transparency: what we collect, why we need it, how long we keep it, and how you can exercise your rights.
Data Controller (GDPR): Innoventra Learning GmbH, Theresienhöhe 12, Schwanthalerhöhe, 80339 Munich, Germany. Contact email for privacy matters: [email protected]. If you contact us through our forms, by email, or by phone, we will process your personal data as described in this Policy.
We do not appoint a Data Protection Officer (DPO) because we do not conduct large-scale processing of special-category data. If this changes, we will update this Policy and provide dedicated DPO contact details.
Effective Date: March 8, 2026.
2. Personal Data We Collect
We collect personal data in three main ways: (a) when you provide it directly (for example through a contact form), (b) automatically when you use the site (technical and usage data), and (c) through cookies and similar technologies (subject to your choices).
- Identity & contact details: name, email address, and optionally phone number if you provide it by email.
- Form content: the program you select (course/webinar/masterclass/intensive) and any message you write (starting level, goals, preferred dates, or other details).
- Technical data: IP address, browser type and version, device/OS information, language settings, approximate location derived from IP (city/region level), and timestamps.
- Usage data: pages viewed, time spent, navigation paths, referring pages, and interaction events (for example, button clicks), where you have consented to analytics cookies.
- Cookies & identifiers: identifiers stored in cookies (see Section 4), including consent status, and (after consent) analytics and marketing identifiers.
- Conversion events: events that indicate a form submission or a completed inquiry flow, which may be measured for advertising attribution after you give marketing consent.
We do not intentionally collect special-category data (such as health data, religion, political opinions), financial account details, payment card numbers, or government identification numbers through our website contact forms. Please do not include such information in your message.
3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)
We process personal data only when we have a lawful basis. The specific basis depends on the context and your choices in the cookie preferences panel.
Contact and enrollment requests
- Purpose: to respond to your inquiry, recommend a program, clarify schedules and formats, and provide registration and purchase details.
- Legal basis: GDPR Art. 6(1)(b) (steps prior to entering into a contract) and, where required, Art. 6(1)(a) (consent), for example when you explicitly consent to be contacted.
Analytics (only after consent)
- Purpose: to understand how visitors use the site so we can improve content structure, navigation, and clarity of course information.
- Legal basis: GDPR Art. 6(1)(a) (consent).
Marketing and advertising measurement (only after consent)
- Purpose: remarketing, audience building (including custom and lookalike audiences), and conversion attribution for advertising campaigns.
- Legal basis: GDPR Art. 6(1)(a) (consent).
Security and fraud prevention
- Purpose: protect the website and forms, reduce spam and abusive traffic, maintain availability, and investigate suspicious activity.
- Legal basis: GDPR Art. 6(1)(f) (legitimate interests). Our legitimate interest is maintaining a secure, reliable service and protecting users from malicious activity.
Legal obligations
- Purpose: comply with applicable laws, respond to lawful requests, and maintain records where required.
- Legal basis: GDPR Art. 6(1)(c) (legal obligation).
Automated Decision-Making (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
4. Cookies & Tracking Technologies
Cookies are small text files stored on your device. We also use similar technologies such as pixel tags and server-side event forwarding. We categorize cookies and related technologies into three groups: Essential, Analytics, and Marketing.
Essential (always active)
Essential cookies are required for the site to function. They support basic features such as session continuity and saving your cookie preferences. These cookies do not require consent. Examples include _site_session and cookie_consent. Retention ranges from session to 12 months.
Analytics (only after consent)
Analytics cookies help us measure site usage and improve content. Where used, we configure analytics to reduce data where possible (for example, IP anonymization where available). Example cookies include _ga and _ga_XXXXXXXXXX (GA4). We use a typical analytics data retention window of 14 months.
Marketing (only after consent)
Marketing cookies and related identifiers support advertising measurement and remarketing. Example cookies include _gcl_au (Google Ads), _fbp and _fbc (Meta). These may be used to measure conversions, build audiences, and limit ad repetition.
If you would like more detail on cookie names, purposes, and retention periods, please see our Cookie Policy at /cookie-policy/.
5. Consent (EEA/UK)
Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Consent status is stored in the cookie_consent cookie (12 months).
You may withdraw or update your consent at any time using “Manage cookie preferences” in the site footer or by clearing cookies in your browser settings. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
6. Sharing With Advertising & Service Partners
We share data with carefully selected service providers and advertising partners when needed to operate the site, measure performance, or (after consent) run marketing campaigns. We do not sell personal data.
- Google LLC (GA4, Google Ads, Tag Manager, remarketing): cookie identifiers, usage data, and conversion events (after consent).
- Meta Platforms (Pixel, Custom/Lookalike Audiences, Conversion API): page view signals, conversions, and audience membership (after consent), sometimes including hashed identifiers for matching.
- Cloudflare (CDN and security): IP-based threat detection and performance optimization to keep the site reliable and protected.
We do not permit these providers to use site data for their own independent commercial purposes. Provider processing is governed by their agreements with us and their own privacy documentation.
7. International Transfers
Some service providers and advertising partners may process data outside the EEA/UK, including in the United States. Where transfers occur, we rely on appropriate safeguards, such as: the EU-US Data Privacy Framework (where applicable), the UK Extension to the DPF, the Swiss-US DPF (where applicable), and Standard Contractual Clauses (EU 2021/914) as a fallback. For UK transfers where needed, we may use the UK International Data Transfer Agreement (IDTA) as a fallback.
You can request additional information about transfer safeguards by emailing [email protected].
8. Retention
We keep personal data only as long as needed for the purposes described in this Policy. Typical retention periods are:
- Contact submissions and inquiries: up to 2 years from the last interaction, unless you request deletion sooner.
- Analytics data: typically 14 months (where consented).
- Marketing cookies: per cookie lifetime (for example, 90 days for certain marketing identifiers), where consented.
- Email correspondence: for the duration of the relationship plus 1 year, unless legal obligations require longer retention.
- Server security logs: typically 90 days for security monitoring and investigation.
- Cookie consent records: up to 3 years for audit and accountability purposes.
- Legal and tax records: as required by law (often 6–10 years for certain business records).
If you request deletion, we will delete or anonymize your data where possible, subject to any legal retention obligations.
9. Your Rights (GDPR & UK GDPR)
Depending on your location, you may have the right to access, correct, or delete your personal data, as well as other rights under GDPR/UK GDPR:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent at any time (Art. 7(3))
- Right to lodge a complaint with a supervisory authority (Art. 77)
To exercise your rights, email [email protected]. We respond within 30 days; in complex cases, this may be extended by up to 60 additional days as permitted by law. We may request information to verify your identity before completing a request.
Supervisory authority references: EU guidance via the European Data Protection Board (EDPB) and, for the UK, the Information Commissioner’s Office (ICO). For Germany, you may contact the relevant German data protection authority for your region.
10. Children
This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided us personal data without verifiable parental consent, contact us and we will delete the information promptly.
11. Do Not Track
This website does not respond to “Do Not Track” (DNT) browser signals. Third-party providers may have their own DNT handling and opt-out mechanisms.
12. Data Deletion Requests
You may request deletion of your personal data by emailing [email protected] with the subject line “Data Deletion Request”. We aim to complete deletion within 30 days after identity verification, except where we must retain certain records to comply with legal obligations or to establish, exercise, or defend legal claims.
13. Business Transfers
In the event of a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity. If such a transfer materially changes how personal data is used, we will provide notice on the site.
14. California (CCPA / CPRA)
This section applies to California residents where the California Consumer Privacy Act (CCPA) as amended by the CPRA applies. In the last 12 months, we may have collected the categories of personal information listed below, and disclosed them to service providers and advertising partners for business purposes:
- Identifiers (name, email, IP address, cookie IDs) for responding to requests and, after consent, for advertising measurement.
- Internet/network activity (pages viewed, interactions) for analytics and site improvement after consent.
- Inferences (interests or preferences derived from interactions) to support advertising relevance after consent.
We do not sell personal information as defined by CCPA. We may share personal information for cross-context behavioral advertising when marketing cookies are enabled. California residents may opt out of sharing by disabling marketing cookies via “Manage cookie preferences” in the footer.
California rights may include: Right to Know, Right to Delete, Right to Correct, Right to Opt Out of sale/sharing, and the right to non-discrimination. To submit a request, email [email protected] with the subject “California Privacy Request”. We will verify your identity before responding. Authorized agents may submit requests with appropriate written proof of authorization.
15. Virginia (VCDPA)
If you are a Virginia resident and the Virginia Consumer Data Protection Act (VCDPA) applies, you may have rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject “Virginia Privacy Request”. If we decline to act on your request, you may appeal by emailing the subject “Appeal of Refusal — Privacy Request”. We respond to appeals within 60 days.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide a prominent notice on the homepage at least 14 days before the changes take effect, where reasonably practicable. The “Last Updated” date at the top of this page indicates when the Policy was most recently revised.
18. Contact
If you have questions about this Privacy Policy or how we handle personal data, contact:
- Legal entity: Innoventra Learning GmbH
- Address: Theresienhöhe 12, Schwanthalerhöhe, 80339 Munich, Germany
- Email: [email protected]
- Phone: +49 89 2555 1607