Privacy Policy
Effective: 13 August 2026
Table of Contents
- Controller
- Contact Data Protection Officer
- Overview of Processing
- Relevant Legal Bases
- Security Measures
- Transfer of Personal Data
- International Data Transfers
- Rights of Data Subjects
- Use of Cookies
- Online Appointment Booking
- Online Meetings (Zoom)
- Calendar Synchronisation (Microsoft 365/Outlook)
- Provision of Online Services and Web Hosting
- Contact and Inquiry Management
- Application Form
- Chatbot
- Reviews (Google)
- Web Analytics, Monitoring and Optimisation
- Plugins and Embedded Functions and Content
- Consent Declaration for Social Media
Controller
ZeBuS e.V.
Elif Yagbasan (Board)
Richardstr. 66
12055 Berlin
Germany
Email: info@zebus-ev.de
Data Protection Officer
dsb@zebus-ev.de
Overview of Processing
The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects.
Types of data processed
- Inventory data.
- Location data.
- Contact data.
- Content data.
- Usage data.
- Meta, communication and procedural data.
Categories of data subjects
- Communication partners.
- Users.
- Customers and interested parties.
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations.
- Contact requests and communication.
- Security measures.
- Reach measurement.
- Administration and answering of inquiries.
- Feedback.
- Provision of our online services and user-friendliness.
- Information technology infrastructure.
- Appointment management and appointment reminders.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will receive an overview of the legal bases of the GDPR on the basis of which we process personal data.
- Consent (Art. 6 (1) (a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR) – Processing is necessary for the performance of a contract or for the implementation of pre-contractual measures.
- Legitimate interests (Art. 6 (1) (f) GDPR) – Processing is necessary for the purposes of the legitimate interests of the controller or a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection in Germany apply. This includes in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG).
Note on the applicability of the GDPR and the Swiss FADP: These privacy notices serve both to provide information under the Swiss Federal Act on Data Protection (FADP) and under the General Data Protection Regulation (GDPR).
Security Measures
We implement appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of processing.
IP address truncation: If IP addresses are processed and the processing of a complete IP address is not required, the IP address is truncated (IP masking).
TLS/SSL encryption (https): To protect user data transmitted via our online services, we use TLS/SSL encryption.
Transfer of Personal Data
In the course of our processing of personal data, it may happen that the data is transferred to other bodies, companies or persons. Recipients of this data may include IT service providers or providers of services and content integrated into a website.
International Data Transfers
If we process data in a third country (outside the European Union (EU), the European Economic Area (EEA)), this is done only in accordance with the legal requirements. Data transfers only take place if the data protection level is otherwise secured, in particular through standard contractual clauses (Art. 46 (2) (c) GDPR), express consent or in the case of contractually or legally required transfer.
EU-US Trans-Atlantic Data Privacy Framework: The EU Commission has recognised the data protection level for certain US companies as safe under the adequacy decision of 10 July 2023. Information: https://www.dataprivacyframework.gov/.
Rights of Data Subjects
Right to object: You have the right to object at any time to the processing of your personal data based on Art. 6 (1) (e) or (f) GDPR.
Right to withdraw consent: You have the right to withdraw given consent at any time. Please write "Withdrawal of consent" in the subject line and send the withdrawal by post or email to qm@zebus-ev.de.
Right of access: You have the right to obtain confirmation as to whether data concerning you is being processed and to receive information about this data.
Right to rectification: You have the right to request the completion or correction of inaccurate data concerning you.
Right to erasure and restriction of processing: You have the right to request that data concerning you be deleted immediately or, alternatively, to request restriction of processing.
Right to data portability: You have the right to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format.
Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR.
Use of Cookies
Cookies are small text files or other storage notes that store information on end devices and read information from end devices.
Information on consent: We use cookies in accordance with legal regulations. We obtain prior consent from users unless this is not legally required. We use our own consent banner with the categories "Statistics" and "Marketing".
Cookies used by us: We only use the following first-party cookies: a session cookie (zebus_ev_session, technically required), a CSRF protection cookie (XSRF-TOKEN, technically required), a language preference cookie (locale, technically required), a cookie storing your consent (cookie_consent, technically required for the consent banner), and a cookie for landing page attribution (lp_landing, 30 days, see the section "Web Analytics, Monitoring and Optimisation"). The technically required cookies do not require consent (Art. 6 (1) (f) GDPR, § 25 (2) No. 2 TTDSG).
Storage duration: Temporary cookies (session cookies) are deleted at the latest after a user leaves our online service and closes their device. Permanent cookies remain stored even after closing the device.
Opt-Out: Users can restrict the use of cookies in their browser settings. Objection to the use of cookies for online marketing purposes can also be declared via https://optout.aboutads.info and https://www.youronlinechoices.com/.
Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR). Consent (Art. 6 (1) (a) GDPR) and § 25 (1) TTDSG.
Online Appointment Booking
Data use: The personal data collected in the online appointment booking process is necessary for the consultation at ZeBuS e.V. and is used exclusively for appointment processing.
Data collected: Name, email address, telephone number (optional), preferred language, any further information you voluntarily provide in the booking form (e.g. a message), and the time of your consent declaration for data processing. For online appointments, we create a video conference link (see the section "Online Meetings (Zoom)").
Access to your appointments: You will receive a confirmation by email as well as a personal link through which you can view, reschedule or cancel your appointments. For this purpose, a one-time, time-limited access link (magic link) is sent. You will also receive automatic appointment reminders by email.
Data processing is based on Art. 6 (1) (b) GDPR, as it is necessary for contract processing. If staff calendars are synchronised with Microsoft 365, the section "Calendar Synchronisation (Microsoft 365/Outlook)" also applies.
Online Meetings (Zoom)
If you book an online appointment, the appointment is conducted via the video conferencing service "Zoom". The provider is Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For this purpose, we transmit to Zoom the data required for conducting the meeting: the meeting topic (which contains your name) as well as the date and duration of the meeting. Please note that Zoom may process personal data, in particular connection and metadata as well as technical data about your device. Processing is carried out in accordance with Zoom's Privacy Policy at https://zoom.us/privacy.
Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR). Third country transfer basis: EU-US Data Privacy Framework (DPF); Zoom Video Communications, Inc. is DPF certified.
Calendar Synchronisation (Microsoft 365/Outlook)
If the employees of ZeBuS e.V. use the calendar synchronisation service, appointments are synchronised between our appointment management and the Microsoft 365 calendar of the respective employee via the Microsoft Graph API. For this purpose, the customer's name, the appointment time and the type of appointment are transmitted to Microsoft and entered into the employee's calendar.
Provider: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; further information: https://privacy.microsoft.com/en-us/privacystatement. Third country transfer basis: EU-US Data Privacy Framework (DPF); Microsoft Corporation is DPF certified.
Legal basis: Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR) as well as legitimate interests in efficient appointment management (Art. 6 (1) (f) GDPR).
Provision of Online Services and Web Hosting
We process user data to provide our online services. We process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
Collection of access data and log files: Access to our online service is logged in the form of server log files. Log file information is stored for a maximum of 30 days and then deleted or anonymised.
Siteground: SiteGround Spain S.L., Calle de Prim 19, 28004 Madrid, Spain. Privacy policy.
Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR).
Contact and Inquiry Management
When contacting us (e.g. by post, contact form, email, telephone or via social media), the details of the enquirer are processed insofar as this is necessary to answer the contact enquiry.
Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR). Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR).
Application Form
When contacting us via the application form, the details of the enquirer are processed to the extent necessary to answer the contact enquiry and to carry out any requested measures.
Types of data processed: Contact data (e.g. name, email), content data (e.g. entries in online forms, uploaded files such as CV and cover letter), usage data, meta, communication and procedural data.
Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR). Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR).
Chatbot
We offer a chatbot ("Lia") on our website that answers questions about our courses and offers. The chatbot is operated exclusively on our own servers; no data is transmitted to third parties or to providers of artificial intelligence. Your entered questions are stored in an internal database for quality assurance purposes and can be viewed in our administration area. Please do not enter special categories of personal data (e.g. health data) in chat conversations. The chat history is additionally stored in the local storage of your browser.
Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR) – providing and improving our information offering.
Reviews (Google)
We integrate customer reviews of our company from Google on our website. For this purpose, publicly submitted reviews, including the reviewer's name and the review text, are automatically retrieved via the Google Places API and published on our website. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Third country transfer basis: EU-US Data Privacy Framework (DPF).
Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR) – presenting the quality and reputation of our offering.
Web Analytics, Monitoring and Optimisation
Web analysis (also referred to as "reach measurement") is used to evaluate visitor traffic to our online service and may include behaviour, interests or demographic information about visitors as pseudonymous values.
Google Analytics 4: We use Google Analytics to measure and analyse the use of our online service on the basis of a pseudonymous user identification number. Google Analytics does not log or store individual IP addresses for EU users. Google Analytics is only loaded after your explicit consent, which you grant via our consent banner (category "Statistics"). You can withdraw your consent at any time via the consent banner.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://policies.google.com/privacy. Third country transfer basis: EU-US Data Privacy Framework (DPF), standard contractual clauses. Opt-Out: https://tools.google.com/dlpage/gaoptout.
Legal basis: Consent (Art. 6 (1) (a) GDPR) and § 25 (1) TTDSG. Security measures: IP masking.
Internal Conversion Measurement (Landing Page Attribution): To determine how many visitors to our blog subsequently book an appointment via our online booking system, we store the entry page (URL path) of a visitor's first visit server-side, in a technically necessary first-party cookie and in an internal database table. If an appointment is subsequently booked, the stored entry page is linked to that appointment. This processing is independent of consent to Google Analytics, no data is shared with third parties, and no cross-session user profiling takes place; evaluation is aggregate only (number of entries per page versus number of bookings).
Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR) – measuring the effectiveness of our editorial content.
Plugins and Embedded Functions and Content
We integrate functional and content elements into our online service that are obtained from the servers of their respective providers. Unless stated otherwise below, these elements are only loaded after your consent via our consent banner.
Google Maps: We integrate maps from the Google Maps service. The maps are only loaded after your consent via our consent banner (category "Marketing"). Processed data may include IP addresses and location data. Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. Third country transfer basis: EU-US Data Privacy Framework (DPF).
YouTube: On our "Job-BSK" course page, we integrate videos from the "YouTube" platform by Google. The videos are only loaded after your consent via our consent banner (category "Marketing"). Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Third country transfer basis: EU-US Data Privacy Framework (DPF).
Own fonts: The fonts used on our website are hosted on our own servers and delivered directly. No connection to Google servers (Google Fonts) takes place.
Legal bases: Consent (Art. 6 (1) (a) GDPR) and § 25 (1) TTDSG.
Consent Declaration for Social Media
Categories of personal data: We process image, video or audio recordings of events and everyday school life at ZeBuS e.V. These recordings may show your ethnic origin, religion or health.
Purposes of data processing: ZeBuS e.V. makes image, video and audio recordings for documentation, information, advertising and illustrative material on events, websites, social media channels and in print media.
Legal basis: We process personal data in accordance with Art. 4 GDPR in compliance with the GDPR and the Bundesdatenschutzgesetz (BDSG). ZeBuS e.V. records and publishes image, video and audio material based on your consent (Art. 6 (1) (a) GDPR). Consent can be revoked at any time.
Recipients: Your data is processed internally only by the relevant administrative staff at ZeBuS e.V. When ZeBuS e.V. publishes recordings on social media channels, the operators of the social media platforms also receive and process your data.
Storage period: Recordings are stored until the purpose is fulfilled. If consent is revoked, ZeBuS e.V. deletes the material.
Data Protection for Medical FSP Exams and Private Courses
This supplement applies to registrations for Medical FSP exams and private language courses at ZeBuS e.V.
Controller
ZeBuS e.V., Richardstr. 66, 12055 Berlin, Germany, Email: info@zebus-ev.de
Purpose of Data Processing
Personal data collected in the context of inquiries and bookings for FSP exams and private courses (name, email address, telephone number, payment information, B2 certificate) is processed exclusively for handling your inquiry, contract performance, and billing of the booked service.
Legal Basis
Processing is based on Art. 6 (1) (b) GDPR (contract performance and pre-contractual measures) and Art. 6 (1) (c) GDPR (legal obligation, e.g. retention obligations).
Payment Processing
Payment processing is carried out via Stripe Payments Europe Ltd. Necessary payment data is transmitted to Stripe. Stripe processes your data in accordance with the Stripe Privacy Policy (https://stripe.com/privacy). We do not store complete credit card data.
Retention Period
Your data is stored for the duration of the contractual relationship and thereafter in accordance with statutory retention periods (in particular tax recording obligations pursuant to AO, max. 10 years).
Your Rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing at any time. Please contact dsb@zebus-ev.de for this purpose.