Privacy · last changed 28 September 2026
What this site knows about you
As a visitor, almost nothing until you say otherwise. As a member of the course, what it takes to give you the course: your email address, your purchase, your timezone, and which lessons you have watched and completed. There is no advertising pixel and nothing is sold on. How the site is used is measured, and the part of that which would recognise you waits for your yes. Below is the whole of it.
Responsible
Valerian Happe, Sander Str. 28, 33129 Delbrück, Germany. Email: happe.digital.solutions@gmail.com.
No data protection officer has been appointed; a one-person operation of this size is not required to have one.
Opening a page
The site runs on Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Like every web server, theirs records each request: IP address, time, the page requested, the referring page, and browser and operating system versions. That is what makes delivery and defence against attacks possible, and it is the legitimate interest we rely on (Art. 6 (1)(f) GDPR). Cloudflare holds those records for at most seven days and then deletes them. We do not export them, and they are joined to nothing else.
Cloudflare processes this for us under a data processing agreement. Requests are answered from the data centre nearest to you, which may be outside the EU; transfers rest on the EU standard contractual clauses and Cloudflare's certification under the EU–US Data Privacy Framework.
What is kept in your browser
Visitors get no cookies. One small entry is written into your browser's local storage, stays on your device and is sent nowhere: tmh.found.v1, which of the seven places you have already lit, so the room remembers where you have been.
Members who sign in get the cookies the sign-in needs (sb-…-auth-token), and a session-only note of your timezone (tmh.tz). Without them the members area cannot work, so they are strictly necessary (§ 25 (2) no. 2 TDDDG). The sign-in cookies stay for up to 400 days, so that the course is one click away on the device you used, unless you untick the box at sign-in — then they last until you close the browser, which is also what tmh.session-only notes. Signing out clears them either way.
Your answer to the banner is remembered in local storage (tmh.consent.v1). If it was yes, PostHog keeps its own identifier there and in a cookie (ph_…); if it was no or you withdrew it, they are not set and an existing one is discarded.
Measuring what works
Two counts run here, and they are not the same thing. The first is Cloudflare Web Analytics: it counts page views, the pages themselves and the site that linked to you. It sets nothing on your device, reads nothing from it and cannot recognise you on a second visit, so it runs for everyone on our legitimate interest in knowing whether this site is read at all (Art. 6 (1)(f) GDPR).
The second only runs if you allowed it in the banner. PostHog (PostHog, Inc., in their European cloud, hosted in Frankfurt, Germany) follows a visit through the site: the pages, the buttons and links clicked, how far into a video you got, and whether the address you left later became a purchase. It keeps an identifier in your browser so those steps form one path rather than a dozen strangers, records a replay of the pages with everything you type masked out, and, once you sign in, files that path under your account id — never your address. Its requests go through /ph on this domain so that a blocker does not decide our numbers for us. This is consent, and only consent (Art. 6 (1)(a) GDPR; § 25 (1) TDDDG). Withdraw it at the bottom of any page, and nothing more is sent; PostHog processes for us under a data processing agreement, and we keep what is collected for twelve months.
Separately, and without either of them, we note with a free-lesson signup which campaign link you came from and which site linked to you, if the address you arrived on says so. That stays in our own database and tells us which channel the course reaches people through (Art. 6 (1)(f) GDPR).
The checkout
The course is sold by Paddle (Paddle.com Market Limited, Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom), which acts as merchant of record. Their payment window is their software, not ours. It is loaded only when you click the buy button — never on page load — from cdn.paddle.com, buy.paddle.com, *.paddle.com, and those requests tell them your IP address, your browser and which page you were on. You have asked for exactly that service with the click, which is the basis (§ 25 (2) no. 2 TDDDG; Art. 6 (1)(b) GDPR).
Everything you type into that window — name, address, payment details — goes to Paddle and never passes through this site. For that part they are the responsible party, under their own privacy policy. Paddle sits in the United Kingdom, outside the EU. Transfers there rest on the European Commission's adequacy decision of 19 December 2025, which holds until 27 December 2031 and finds that UK law protects your data to an equivalent standard. Once the payment is through, Paddle tells us your email address, your country, the transaction number and the amount, so we can open the course for you (Art. 6 (1)(b) GDPR).
Your course account
Accounts live with Supabase (Supabase, Inc., hosted for us in Frankfurt, Germany, AWS region eu-central-1). We store your email address, your purchase, your timezone and the hour you want course mails, and your progress: when you opened, started and finished each lesson and practice video, and when you clicked “Complete this lesson”. The course opens lessons and sends its practice mails from these times — that is the purpose, and it is part of the contract you bought (Art. 6 (1)(b) GDPR).
Your timezone is first guessed from your billing country and then taken from your browser when you sign in; you can change it on your account page. Supabase processes all of this for us under a data processing agreement with EU standard contractual clauses.
We keep the account as long as you have access to the course. If you ask us to delete it, we do, except for the purchase records we are obliged to keep for tax purposes (up to ten years, § 147 AO, § 257 HGB).
The videos
Lesson videos are streamed by Bunny Stream (BunnyWay d.o.o., Cesta komandanta Staneta 4a, 1215 Medvode, Slovenia), from servers in Europe. When you play a video, their player receives your IP address and browser details, and each video link carries a signed token that expires after a few hours, so the videos cannot be passed on. Bunny processes this for us under a data processing agreement (Art. 6 (1)(b) GDPR). The player reports to us — not to Bunny or anyone else — when you start a video and how far you got.
The sign-in links and the course mails (practice reminders on the days the course plans them) are sent through Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany) under a data processing agreement. Brevo receives your email address and the content of the mail. Course mails are part of the course (Art. 6 (1)(b) GDPR). Mails beyond that only go to people who asked for the free lesson and confirmed their address (see below). If you would rather not receive them, one line to us is enough.
One week after you finish the course, we ask you once for a few lines about it: in the members area, and by mail if you agreed to hear from us by confirming your address for the free lesson (Art. 6 (1)(a) GDPR). Your answer and its wording are stored with the time; the course and its mails do not depend on it. The mail has a link to switch it off, and it is not sent if you already wrote to us. What you write is stored with your account; it appears on the website only if you tick the box that allows it, signed the way you chose, and you can withdraw that at any time.
The free first lesson
If you enter your email address for the free first lesson (on the home page, on /free-lesson or in the footer), we store the address, where you entered it, the time, and the exact consent wording shown next to the button, in our database at Supabase (Frankfurt), and send you one mail through Brevo asking you to confirm it (double opt-in). Nothing else is sent to an unconfirmed address, and we delete it after 30 days.
The link in that mail confirms the address and opens your own members area, where lesson 00 is free. For that we create an account for your address, as for a purchase, and sign you in with the same sign-in cookies described under "What is kept in your browser" above. While you watch, the player reports to us when you started and how far you got, as it does for the course.
With the confirmation we also add you to our mailing list at Brevo and write to you again, about the course and new lessons, not often (Art. 6 (1)(a) GDPR, your consent). Every one of those mails has an unsubscribe link, and one line to us is just as good; you can withdraw your consent at any time with effect for the future. Your account is deleted on request.
What is not here
No Google Analytics. No Meta pixel, no advertising, no tag manager, no fonts from somewhere else — the typefaces are served from this domain. What is measured is described above and stays with us and our processors; nothing about you is sold on, and no profile of you is built for anyone else.
Nothing here decides anything about you on its own. There is no automated decision-making and no profiling within the meaning of Art. 22 GDPR: no score is kept on you, no price moves with who you are, and access to the course follows from your purchase and nothing besides.
Your rights
Under the GDPR you may ask us for a copy of what we hold about you (Art. 15), have it corrected (Art. 16) or erased (Art. 17), have its use restricted (Art. 18), receive it in a portable form (Art. 20), and object to processing based on legitimate interest (Art. 21 (1)).
Against mail about the course and new lessons you may object at any time and without giving a reason, and we stop (Art. 21 (2) GDPR). The unsubscribe link in any of those mails does exactly that. Where we asked for your consent — the measurement banner, the mailing list — you can withdraw it just as freely, and what was done before the withdrawal stays lawful.
One email to happe.digital.solutions@gmail.com is enough. You can also complain to a supervisory authority — the one for your place of residence, or ours: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Changes
When something here changes, the date at the top says so.
Who runs this site is on the legal notice; the rules for the course are in the terms of use and the refund policy.