Legal information
Privacy Policy
Last updated: July 2026
This Privacy Policy explains how personal data is processed on the public website, in the protected student area, for course bookings, in the shop, through file uploads and during individual or group online lessons using Zoom.
1. Controller
The controller is CroLangSchule, proprietor Marija Ilicic Mikulic, Biberacher Straße 6, 88471 Laupheim, Germany. Phone: +49 (0) 163 9645964. Email: info@crolangschule.com. No data protection officer has currently been appointed. If a statutory appointment obligation arises, the relevant contact details will be published here.
2. Legal bases and purposes
Personal data is processed to provide the website and student portal, answer enquiries, enter into and perform course and purchase contracts, provide learning materials, conduct online lessons, tests and homework, and meet legal duties. Depending on the activity, processing is based on Article 6(1)(a), (b), (c) or (f) GDPR. Where minors participate, any required declarations from a parent or legal guardian are obtained.
3. Website access, hosting and server logs
When the website is accessed, the IP address, date and time, requested URL, referrer, browser, operating system, transferred data volume and technical error information may be processed. This supports secure and reliable operation, abuse prevention and troubleshooting. The actual hosting provider, server location and any processing agreement must be added before launch.
4. Cookies and consent management
Essential cookies or similar storage technologies may be used without separate consent where they are necessary for login, the shopping basket, language selection, security or another function expressly requested by the user. Non-essential analytics, convenience or marketing technologies are activated only after valid consent. Consent can be withdrawn at any time through the cookie settings.
5. Contact requests
When you contact us by form, email or telephone, we process the contact details and message content you provide. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual matters and otherwise Article 6(1)(f) GDPR based on our legitimate interest in answering enquiries.
6. Registration and student account
A student account may include first and last name, address, date of birth, telephone number, email address, learning objective, language level, booked courses, payment status, user ID and a securely stored password hash. Login credentials must be kept confidential and may not be shared. Accounts and access rights are managed according to role.
7. Protected student area and learning materials
Approved students can access Croatian learning documents, PDFs, exercises, audio and video files, lesson links and other course content. Course allocation, access rights, access time and download status may be logged. Materials are provided only for personal learning. A student’s private profile, address, payment, assessment and administration data is not made visible to other participants.
8. Course booking and contract performance
For course bookings, we process identity, contact, course, schedule, participant, price, payment and booking data. This is necessary to enter into and perform the contract. Booking confirmations, contractual information and legally required notices may be sent by email.
9. Online lessons via Zoom
Zoom is used for online lessons. Depending on the settings, display name, email address, IP address, device and connection data, meeting ID, attendance times, audio, video, chat, reactions, screen sharing and transmitted files may be processed. Camera and microphone are used only where enabled by the participant or where this is required for the agreed lesson format and clearly announced. Lessons are not recorded without prior notice and, where required, consent. The relevant Zoom contracting entity, enabled functions, retention periods and privacy configuration must be documented before launch.
10. Group courses and visibility of other participants
In group courses, participants must be able to see the display names and, where camera or microphone is enabled, the image and voice of other group members. Chat messages, reactions and voluntarily shared screen content may also be visible within the group. This internal visibility cannot be fully avoided in interactive group teaching and forms part of the booked format. Participants may not use, disclose, photograph, film or record another person’s name, image, voice, chat contribution or other information outside the course. A neutral display name may be permitted where reliable identification for teaching remains possible.
11. Homework, uploads, tests and assessments
Students may submit text, photographs, PDFs, audio or other permitted files as homework or tests. The account, course, lesson, submission time, processing time, answers, points, assessments, corrections and feedback may be processed. Access is limited to responsible teachers, administrators and specifically authorised staff. Students should not upload unnecessary third-party data or particularly sensitive content.
12. Shop, payments, invoices and shipping
For shop orders, we process the name, billing and shipping address, email address, products ordered, price, payment method and status, invoice number, shipping and download information. For bank transfers, participating banks process payment information under their own responsibility. If PayPal or another payment service is activated, the required order and payment information is sent to that service; the specific provider must be identified before activation. Shipping providers receive only the data necessary for delivery.
13. Recipients and processors
Recipients may include responsible teachers, authorised staff, hosting, maintenance, email, video-conferencing, payment and shipping providers, tax advisers, accountants and public authorities. Providers processing personal data solely on our instructions are bound by a data-processing agreement under Article 28 GDPR.
14. International transfers
International providers, particularly Zoom or payment and cloud services, may process data outside the European Economic Area. Transfers take place only on a lawful basis, such as an adequacy decision or appropriate safeguards including standard contractual clauses. Even with such safeguards, official access under the law of the recipient country cannot always be fully excluded.
15. Retention periods
Data is retained only as long as necessary for its purpose. Enquiries are deleted after completion unless retention is required. Account, course, homework and test data is deleted or anonymised after the contract ends once it is no longer required for teaching, evidence or legal claims. Accounting and invoice records are kept for statutory retention periods. Security logs are deleted after an appropriate period unless an incident requires longer retention.
16. Data security
Appropriate technical and organisational measures are used, including HTTPS, secure password hashes, role-based permissions, access restrictions, logging of security-relevant actions, backups and regular updates. Participants must keep passwords, course links and meeting links confidential and may not share accounts.
17. Data-subject rights
Subject to the statutory conditions, individuals have rights of access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn at any time for the future. Proof of identity may be requested to prevent unauthorised disclosure.
18. Withdrawal and objection
Consent may be withdrawn at any time with future effect. Processing based on legitimate interests may be objected to for reasons relating to the individual situation. Compelling legitimate grounds or the establishment, exercise or defence of legal claims may justify continued processing.
19. Right to lodge a complaint
Complaints may be lodged with a data protection supervisory authority. For a business based in Baden-Württemberg, the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg is generally competent. The right to contact any other authority competent under Article 77 GDPR remains unaffected.
20. Changes to this Policy
This Privacy Policy is updated when functions, providers, processing activities or legal requirements change. The version published on the website applies.
Datenverarbeitung im Online-Shop
Bei Bestellungen verarbeiten wir Kontaktdaten, Rechnungs- und Lieferanschrift, bestellte Artikel, Zahlungsart, Bestellstatus, Gutscheincodes und bei digitalen Produkten Downloadprotokolle. Die Verarbeitung erfolgt zur Vertragsanbahnung und Vertragserfüllung sowie zur Erfüllung gesetzlicher Aufbewahrungspflichten. Lieferdaten können an eingesetzte Versanddienstleister und Zahlungsdaten an den ausgewählten Zahlungsdienstleister übermittelt werden. Zustimmungen zu AGB, Datenschutz, Widerruf und zur vorzeitigen Bereitstellung digitaler Inhalte werden mit Zeitpunkt, IP-Adresse und Browserinformationen dokumentiert.
