Privacy Policy

Last updated: [REVIEW — insert date]

1. Data Controller

The data controller responsible for the processing of your personal data on this website is:

[REVIEW — Company name]
[REVIEW — Street address]
[REVIEW — City, postal code, Germany]
Email: [REVIEW — privacy@studynow.example.com]

2. What Data We Collect

2.1 Account Data

When you create an account, we collect your email address, name, and password (stored as a cryptographic hash). If you sign in via a third-party provider (e.g. Google), we receive your name and email from that provider.

2.2 Profile & Preference Data

During onboarding and in your account settings, you may provide your nationality, current country of residence, study level, and subject interests. This data is used to personalise your experience.

2.3 Usage Data

We collect information about how you interact with our website, including pages visited, courses and universities viewed, search queries, and clicks. This data is collected via server-side logging and, where you have given cookie consent, client-side analytics.

2.4 Technical Data

When you visit our website, your browser automatically transmits certain technical data, including your IP address, browser type, operating system, and referring URL. This data is processed for security purposes and to ensure the functionality of our services.

3. Legal Bases for Processing (Art. 6 GDPR)

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide our services — account management, personalisation, and course/university search.
  • Consent (Art. 6(1)(a)): Where you have opted in to share your profile with universities for lead matching, or consented to marketing cookies.
  • Legitimate interest (Art. 6(1)(f)): Security, fraud prevention, and aggregated analytics to improve our services.

4. Data Sharing with Universities

If you consent to lead sharing (offered during onboarding or in your account privacy settings), we may share your name, email, nationality, study level, and subject interests with universities that offer programs matching your profile. Universities may use this information to contact you with relevant course information.

You can withdraw this consent at any time in your Account > Privacy settings. Upon withdrawal, we will stop sharing your data with new universities. Data already shared with universities is subject to their own privacy policies.

5. Cookies & Tracking

We use strictly necessary cookies (e.g. session authentication, onboarding state) that do not require consent. For analytics and marketing cookies, we request your consent via our cookie banner before any such cookies are set.

[REVIEW — List specific cookies and their purposes, retention periods, and any third-party analytics providers (e.g. Plausible, PostHog).]

6. Your Rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (“right to be forgotten”, Art. 17)
  • Restrict processing (Art. 18)
  • Data portability — receive your data in a machine-readable format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3))

To exercise any of these rights, contact us at [REVIEW — privacy@studynow.example.com].

7. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will erase your personal data within 30 days, except where retention is required by law. Consent records are retained for documentation purposes as required by Art. 7(1) GDPR.

8. Data Security

We implement appropriate technical and organisational measures to protect your data, including encrypted connections (TLS), hashed passwords, and access controls.

9. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for us is:

[REVIEW — Insert relevant German state data protection authority, e.g. “Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg”]

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of material changes via email. The current version is always available at this URL.