1. Overview#
This Privacy Policy applies to the website tra-mada.de, the app app.tra-mada.de and the associated booking, payment, learning, community, support and communication functions of traMADA GmbH.
traMADA processes personal data to provide the website and app, manage user accounts, enable access to digital services, process payments, provide support and live formats, operate community functions, comply with legal obligations, protect rights and keep the services technically secure.
traMADA does not sell personal data. Data is shared only where this is necessary for the relevant service, required by law, based on consent or necessary following a balancing of interests and permissible under data protection law.
2. Controller and Contact#
traMADA GmbH
Große Gallusstraße 14, 60313 Frankfurt am Main, Germany
Email: info@tra-mada.de
Telephone and WhatsApp: +49 170 7850 550
Legally represented by its managing directors Daniel Kahlig and Marco Bösing.
Please direct privacy inquiries and requests to exercise your rights to info@tra-mada.de.
3. Legal Bases and Data Sources#
Depending on the function, traMADA processes data on the following legal bases:
- Art. 6(1)(b) GDPR for registration, contract formation, digital access, customer support, payment, support and billing,
- Art. 6(1)(c) GDPR for legal obligations, in particular commercial, tax, consumer protection, data protection and documentation obligations,
- Art. 6(1)(a) GDPR for consent, for example newsletters, non-essential tracking, recordings or publications,
- Art. 6(1)(f) GDPR for legitimate interests such as IT security, prevention of misuse, error analysis, product improvement, permissible direct advertising, enforcement of rights and defense against claims,
- Section 25 TDDDG for storing information on terminal devices or accessing it, for example through cookies, local storage or comparable technologies.
Required data may be necessary by law or contract, or may be needed for contract formation, service provision, payment, security, support or documentation. Without required data, traMADA cannot provide the affected function or service, or can provide it only to a limited extent. Voluntary information and consent may be withdrawn with effect for the future in accordance with legal requirements.
Data may come directly from you or, where necessary, from login providers, payment providers, scheduling and live-tool providers, communication and support service providers, partner or lead sources, app and community functions, public authorities, advisers or publicly accessible sources.
4. Website and Tracking#
When you access the website, technical access data is processed, such as IP address, date and time, URL accessed, referrer, browser, operating system, volume of data transferred and status codes. This data is used for delivery, stability, security and error analysis. The website and app may use technically necessary cookies, local storage, session IDs or similar storage mechanisms, particularly for login, security, preferences, forms and contract functions.
Non-essential analytics, attribution, marketing, A/B testing, recognition or product analysis functions are used only where valid consent has been given or a statutory exception applies; they are not necessary merely to access the website or for strictly necessary contract functions. For this purpose, traMADA may use PostHog via EU endpoints and a local relay path; the data processed may include event data, page views, campaign parameters, referrers, device and browser data, technical identifiers and linked booking events.
Attribution and funnel data such as UTM parameters, referrer, landing page, time, funnel variant, Facebook click ID and PostHog identifier may be stored in local storage or in a first-party cookie for up to 30 days, provided that the specific storage is permissible under Section 25 TDDDG, particularly on the basis of valid consent or a narrowly applicable statutory exception.
The website may link to external platforms such as WhatsApp, YouTube, Instagram, Google Reviews or other profiles. The respective provider processes data under its own terms only when you open an external link.
5. App and Learning Platform#
For user accounts, traMADA processes in particular names, email addresses, password data in protected form, session data, roles, product and feature assignments, contract status, consent, technical account data and security events. This may include email verification, password resets, two-factor authentication, passkeys, device sessions and rights management. If you sign in with Google, traMADA processes the login data provided by Google, in particular your unique user ID, email address and name. Google additionally processes data under its own responsibility.
The app may process course progress, unlocked content, video and audio access, bookmarks, comments, messages, reactions, survey and quiz data, attachments, images, support messages and error reports. This data is used for the learning platform, customer support, community, security, support and improvement of the training. Content published or provided by customers through community, chat, comment, upload, live or feedback functions may, in accordance with the Terms and Conditions, also be processed for references, testimonials, social media posts, excerpts, screenshots or other external presentations by traMADA. Private support content, account data, payment data and confidential individual communications are not included. Please do not transmit any special categories of personal data under Art. 9 GDPR through these functions. traMADA does not request such data; if it is nevertheless disclosed voluntarily, traMADA processes it only where an exception under Art. 9 GDPR applies, for example for explicit consent, content manifestly made public, legal claims, or for deletion or restriction.
In the event of reports, moderation, security vulnerabilities, malfunctions, misuse or data protection incidents, traMADA may process the content, location, identity, contact, account, device, log, communication, review, action and documentation data necessary for these purposes. Paid services are not directed at minors. If traMADA receives indications that a minor is using them, data may be processed to clarify the validity of the contract, consent of legal representatives, access restrictions, reversal, security and legal defense. Consent-based online or advertising functions are likewise not directed at children under the age of 16; where legally required in an individual case, consent by the holder of parental responsibility or given with their authorization is decisive.
External market, news, calendar, heatmap, country flag or comparable widget and media services may be integrated into the app. When such content is loaded, the respective provider or its infrastructure may process technical data such as IP address, browser data, time, referrer and usage events under its own terms.
6. Contract, Payment and Communication#
For paid services, traMADA processes contract, invoice, payment, tax, product, price, refund, withdrawal and termination data as well as supporting records. Payments may be made using the methods specified in the relevant checkout, contract, customer account or invoice, particularly through Stripe, PayPal, subscription functions, tax calculation, payment management or SEPA bank transfer. In doing so, traMADA processes the bank, payment service provider, communication, review and documentation data required for allocation, billing, refunds, dispute handling, prevention of misuse and enforcement of rights.
traMADA uses email for system messages and registration, verification, security, contract, payment, withdrawal, termination and support communications. If you contact traMADA by email, telephone, WhatsApp, form, messenger or through social networks, traMADA processes contact data, message content, technical metadata and subsequent communication data.
When communicating through external messengers, social networks, telephony, scheduling or video services, the respective provider may also process data under its own responsibility and terms. If you do not wish to use these channels, you can contact traMADA by email.
traMADA may use Calendly for bookings. For live sessions, webinars or support, participant data, chat data, recordings and technical connection data may be processed via Zoom or comparable providers. Recordings and promotional publications of names, likenesses, voices, chat messages, questions, screenshots, reviews, testimonials or recording excerpts are made only with an appropriate legal basis.
Where you activate push or in-app notifications, traMADA processes technical subscription data, device permissions, notification types, delivery status and preferences. Promotional push or in-app notifications are used only where valid consent has been given or a statutory exception applies.
7. Newsletters and Advertising#
If you subscribe to newsletters or promotional updates, traMADA processes your email address, consent status, time and technical delivery, bounce, unsubscribe and documentation data where this is necessary for delivery or documentation. You may withdraw consent at any time, for example through an unsubscribe link or by sending a message to info@tra-mada.de. Personal opening, click or comparable analyses are used only where valid consent has been given or a statutory exception applies.
As a rule, traMADA sends promotional emails only with prior consent or within the legally permissible scope of advertising to existing customers for its own similar services, where traMADA obtained the email address in connection with a sale, you have not objected and you are clearly informed of the right to object both when the address is collected and each time it is used. Telephone advertising to consumers takes place only with prior express consent; telephone advertising to other market participants only where at least presumed consent exists. Advertising by SMS, WhatsApp, messenger or comparable direct messages takes place only with prior express consent. Records of consumer consent to telephone advertising are retained for five years from the time consent is given and after each use.
8. Service Providers, Recipients and Transfers#
Depending on the function used, the following categories of service providers and recipients in particular may be involved:
- hosting, security, CDN, frontend delivery, file, video, audio and learning-platform infrastructure,
- product analytics, attribution, error analysis, and consent or preference management,
- appointment booking, live formats, email, telephony, messengers, support and system communications, as well as internal text drafting, AI, support and administration tools,
- payment processing, invoicing, tax calculation, refunds and payment management,
- authentication, security functions, web push, in-app notifications and community functions,
- external market, news, calendar, widget, media and asset services, where integrated into the website or app,
- tax advisers, legal advisers, public authorities, courts and other bodies receiving documentation, where necessary.
Where required, processors are used only on the basis of a contract pursuant to Art. 28 GDPR. Where providers independently determine the purposes and means, they act as independent controllers or, if expressly agreed, as joint controllers.
Some providers may process data outside the European Union or the European Economic Area. In these cases, where required, traMADA uses adequacy decisions, the EU-US Data Privacy Framework for appropriately certified US providers, standard contractual clauses, supplementary safeguards or, in exceptional cases, Art. 49 GDPR.
You may request information on the applicable transfer bases and, where provided for by the GDPR, a copy or information about the availability of appropriate or suitable safeguards via info@tra-mada.de. Trade secrets, security information and third-party rights may be appropriately redacted.
9. Retention and Security#
Data is deleted as soon as it is no longer required for the stated purposes and no statutory retention periods or legitimate reasons for retention prevent deletion. Commercial and business correspondence is generally retained for six years, accounting vouchers and invoices generally for eight years, and books, records, inventories, opening balance sheets, annual financial statements and organizational documents generally for ten years. The period generally begins at the end of the calendar year in which the relevant transaction arose.
Contract, payment, withdrawal, termination, support, moderation and documentation data may also be stored until the expiry of applicable limitation periods. Server, security and error logs are stored only for as long as necessary for operation, security, investigation of misuse or legal documentation.
traMADA implements risk-based technical and organizational measures pursuant to Art. 32 GDPR. These may include role and access controls, encryption or pseudonymization, backups, logging, separation of production and test data, service-provider reviews, security updates, incident processes and deletion processes.
10. Your Rights#
In accordance with the GDPR, you have the following rights in particular:
- access pursuant to Art. 15 GDPR
- rectification pursuant to Art. 16 GDPR
- erasure pursuant to Art. 17 GDPR
- restriction of processing pursuant to Art. 18 GDPR
- notification regarding recipients pursuant to Art. 19 GDPR
- data portability pursuant to Art. 20 GDPR
- objection pursuant to Art. 21 GDPR
- withdrawal of consent pursuant to Art. 7(3) GDPR
- rights relating to solely automated decisions, including profiling, pursuant to Art. 22 GDPR
- lodging a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR
The Hessian Commissioner for Data Protection and Freedom of Information is generally responsible for traMADA as a company based in Hesse. Current contact information is available at datenschutz.hessen.de. You may also contact any other competent data protection supervisory authority.
For privacy inquiries, please use info@tra-mada.de. traMADA may request proof of identity when this is necessary to protect your data.
traMADA responds to requests under Arts. 15 to 22 GDPR without undue delay and generally within one month of receipt. In cases permitted by law, this period may be extended by up to two further months due to the complexity or number of requests; traMADA will inform you of an extension and the reasons for it within one month.
Where personal data is processed on the basis of legitimate interests, you may object on grounds relating to your particular situation in accordance with Art. 21 GDPR. You may object to direct advertising at any time; this also applies to profiling to the extent that it is related to such direct advertising. The affected data will then no longer be processed for these purposes.
11. Automated Decision-Making#
Based on its current business operations, traMADA does not make any decisions based solely on automated processing that produce legal effects or similarly significantly affect you within the meaning of Art. 22 GDPR. Analytics, attribution or segmentation data may be used only where there is a legal basis for doing so and required access to terminal devices is permissible under Section 25 TDDDG.
