Privacy Policy
Last updated: September 2026
1. Controller
The controller within the meaning of the GDPR is:
training.dental
Owner: Martina Hondong-Kulik
Tönges Feld 55
51371 Leverkusen, Germany
Email: [email protected]
Phone: +49 2173 9403664
2. General information on data processing
We process personal data only to the extent necessary to provide a functioning website and to deliver our services. As a rule, processing takes place only with the consent of the data subject. An exception applies where the processing is permitted by law.
3. Cookies and consent
Our website uses cookies. Technically necessary cookies (for example to protect forms via Cloudflare Turnstile) are set without consent. Analytics cookies (Google Analytics) are loaded only after your express consent given through our cookie banner (Section 25 TDDDG, the German Digital Services Data Protection Act). You may withdraw your consent at any time via the „Cookie-Einstellungen“ (cookie settings) link in the footer.
4. Cloudflare (CDN & WAF)
To protect and deliver our website we use services of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. In doing so, Cloudflare processes IP addresses, HTTP requests and device data. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in security and performance). Transfer to a third country: USA – EU-US Data Privacy Framework. Privacy policy: cloudflare.com/privacypolicy
5. Cloudflare Turnstile (CAPTCHA alternative)
To protect our forms against automated access we use Cloudflare Turnstile. This processes IP address, browser characteristics, time spent on the page and mouse movements. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing misuse). Turnstile is technically necessary and does not require cookie consent. Privacy policy: cloudflare.com/privacypolicy
6. Contact form
On the „Kontakt“ (contact) page you can send us an enquiry using a form. Only the three entries you fill in yourself are processed: name, email address and the free text of your message. There are no further fields — we ask for neither a telephone number nor a postal address or practice details.
Purpose: handling and answering your enquiry.
Legal basis: Art. 6(1)(b) GDPR where your enquiry is directed at entering into or performing a contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
Recipient: exclusively our own mailbox [email protected] on our own mail server. Your enquiry is not passed on to third parties, and no further recipient is involved.
Storage: the application does not store your message. It receives it, validates the entries and delivers it — the only copy resides in the mailbox named above. Retention period: twelve months from receipt, after which the message is deleted.
Protection against automated submissions: the form contains a field invisible to you that only automated scripts fill in, and it limits the number of submissions per sender. Your IP address is held briefly in memory for this purpose and is not stored. No third-party service is involved, so no data is passed to third parties for this purpose.
Please do not enter any patient or health data in the message field. The contact form is not intended for such information. In that case, please contact us by telephone instead.
7. Google Analytics 4
With your consent given through the cookie banner we use Google Analytics 4 (GA4) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. GA4 processes anonymised IP addresses, page views, device data and usage behaviour. Legal basis: Art. 6(1)(a) GDPR (consent). GA4 may only be loaded after your active opt-in (Section 25 TDDDG). Transfer to a third country: USA – standard contractual clauses and the EU-US Data Privacy Framework. Retention period: 14 months (configured in GA4). You may object to data collection at any time: withdraw cookies via „Cookie-Einstellungen“ (cookie settings) in the footer, or use the browser add-on: tools.google.com/dlpage/gaoptout. Privacy policy: policies.google.com/privacy
8. Stripe (payment processing)
For payment processing we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe processes name, email, billing address, payment data, IP address and transaction data. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Transmitting your payment data to Stripe is strictly necessary in order to carry out the payment. Transfer to a third country: possible (Stripe Inc., USA) – standard contractual clauses. Retention period: transaction data 7 years (statutory tax retention obligation). Privacy policy: stripe.com/de/privacy
9. AI chatbot (OpenAI)
A chatbot is available across our site to answer questions about our offering. In order for it to answer, your input is transmitted to OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, where it is processed by a language model. Use is voluntary — our website is fully available to you without the chatbot.
What is transmitted: the text you enter and the preceding messages of the same conversation. Your question is additionally converted into a sequence of numbers so that we can find the matching entries in our knowledge base — that conversion also takes place at OpenAI.
If you are signed in, we additionally transmit your display name, an internal user identifier, and your subscription status, payment status, minute balance and point total, so that the chatbot can answer questions about your account. Your email address and postal address are not transmitted. If you are not signed in, no account data is transmitted.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in giving immediate information about our offering); for the account data of signed-in users, Art. 6(1)(b) GDPR (performance of a contract). Transfer to a third country: USA – Standard Contractual Clauses, which form part of the data processing agreement concluded with OpenAI.
Retention: We do not store your conversations. The history exists only while the chat window is open and is discarded when the page is reloaded. According to OpenAI, inputs and outputs are retained for up to 30 days for abuse detection and are not used to train its models. Please do not enter any patient or health data into the chat. Privacy policy: openai.com/policies/privacy-policy
10. Retention periods
Personal data is deleted as soon as the purpose of the processing ceases to apply:
- Usage data (page views, sessions): 14 months (GA4)
- Customer data (portal): 1 year after the end of the contract (Section 9 of our Terms)
- Payment data: 10 years (Section 147 of the German Fiscal Code, principles of proper accounting)
- Server log files: max. 7 days
- Chat conversations (AI chatbot): not stored by us; up to 30 days at OpenAI
- Contact enquiries (mailbox): 12 months from receipt
11. Your rights as a data subject
You have the following rights vis-à-vis us (Art. 15–21 GDPR):
- Access (Art. 15): which data we hold about you
- Rectification (Art. 16): correction of inaccurate data
- Erasure (Art. 17): deletion of your data, unless a retention obligation applies
- Restriction (Art. 18): restriction of processing
- Data portability (Art. 20): receipt of your data in a machine-readable format
- Objection (Art. 21): objection to processing based on legitimate interests
To exercise your rights, please contact: [email protected]
12. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with the competent data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit NRW (LDI NRW)
Postfach 20 04 44, 40102 Düsseldorf, Germany
www.ldi.nrw.de