Skip to main content

Privacy Policy

Status: May 2026

Note: This is a convenience translation. In the event of any discrepancy or conflict between the German and English versions, the German version shall prevail and be legally binding.

1. Data Protection at a Glance

General Information

The following information provides a concise overview of what happens to your personal data when you visit this website. Personal data means any data by which you can be personally identified. Detailed information on data protection can be found in the full Privacy Policy set out below.

Data Collection on This Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. The operator's contact details can be found in the section "Information on the Data Controller" in this Privacy Policy.

How do we collect your data?

Your data is collected, on the one hand, when you provide it to us. This may include, for example, data you enter into a contact form.

Other data is collected automatically or after your consent when you visit the website through our IT systems. This mainly includes technical data (e.g. internet browser, operating system, or time of page access). Such data is collected automatically as soon as you enter this website.

What do we use your data for?

Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyse your user behaviour. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other service inquiries.

What rights do you have regarding your data?

You have the right at any time to obtain, free of charge, information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the rectification or erasure of such data. If you have given consent to data processing, you may withdraw this consent at any time with effect for the future. Furthermore, you have the right, under certain circumstances, to request the restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority.

For these purposes, as well as for any further questions regarding data protection, you may contact us at any time.

Analytics Tools and Third-Party Tools

When visiting this website, your browsing behaviour may be statistically analysed. This is mainly carried out using so-called analytics programs. We also offer Google Login as an optional third-party login method for registration and sign-in. Detailed information on these services can be found in the following Privacy Policy.

2. Hosting and Content Delivery Networks (CDN)

We host the content of our website with the following provider:

External Hosting

This website is hosted externally. Personal data collected on this website is stored on the servers of the hosting provider(s). This may include, in particular, IP addresses, contact requests, metadata and communication data, contract data, contact details, names, website access data, and other data generated via a website.

External hosting is carried out for the purpose of fulfilling contractual obligations towards our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online services by a professional provider (Art. 6(1)(f) GDPR). Where corresponding consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.

Our hosting provider(s) will process your data only to the extent necessary to fulfil their performance obligations and in accordance with our instructions.

We use the following hosting provider:
Name: OVH GmbH
Address: Christophstraße 19, 50670 Cologne, Germany

Data Processing Agreement

We have concluded a Data Processing Agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law, ensuring that the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Use of Cloudflare (CDN)

We use Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA; German subsidiary: Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich) as a content delivery network (CDN) and security service (reverse proxy via Cloudflare DNS) to deliver our website faster and more resiliently against attacks. In doing so, Cloudflare processes in particular IP addresses and technical access and log data (request metadata); where Cloudflare makes such data available via the dashboard, it is referred to as "Customer Logs".

In addition, we may use Cloudflare's built-in "Zone Analytics" / "HTTP Traffic" reporting to analyze aggregated metrics such as the number of requests, bandwidth, "Unique Visitors", and traffic by country/region.

The use of Cloudflare is based on our legitimate interest in the most error-free and secure provision of our website (Art. 6(1)(f) GDPR).

When providing the services, Cloudflare typically acts as a data processor under a Data Processing Addendum (DPA): https://www.cloudflare.com/cloudflare-customer-dpa/

Information about Cloudflare's sub-processors is available at: https://www.cloudflare.com/gdpr/subprocessors/

Further information can be found in Cloudflare's Privacy Policy: https://www.cloudflare.com/privacypolicy/

3. General Information and Mandatory Disclosures

Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this Privacy Policy.

When you use this website, various personal data are collected. Personal data means data by which you can be personally identified. This Privacy Policy explains which data we collect and for what purposes we use it. It also explains how and for what purpose this is done.

Technical and Organisational Measures (TOM)

We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect personal data (risk-based approach).

At Network Level:

  • Transport encryption: HTTPS/TLS (current versions)
  • DDoS/Network protection: OVH standard protection mechanisms

At Application Level:

  • Password requirements: Min. 8 characters, complexity rules
  • Authentication: Session-based (cookies), password hashing
  • Access protection for administrative interfaces

At Infrastructure Level:

  • Logging: Recording of system/access events, retention typically 90 days
  • Access protection: Administrative access only for authorised persons (currently: Philipp Manhart & Christoph Manhart)
  • Updates: Regular system updates; security-relevant updates are applied promptly
  • Backups: Daily backups, 30-day retention, separate storage (planned)

Governance & Audits:

  • Security review/audit: planned for Q2 2026
  • Penetration test: planned

Known Limits:

  • No redundancy (single point of failure)
  • No geographic distribution (data location Frankfurt)

Complete protection cannot be guaranteed despite all measures. Please note that data transmission over the internet (e.g. communication by email) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.

Data Breaches and Security Incidents

What is a data breach?

An unauthorised processing or disclosure of personal data (e.g. through hacking, malware, insider threat).

Our measures in the event of a data breach:

  1. We notify the supervisory authority (BayLDA) within 72 hours of discovery at the latest
  2. Affected users will be promptly informed by email if there is a high risk to their rights/freedoms
  3. We take immediate technical measures to limit the damage

Contact in case of security incidents:

If you suspect a security breach, please contact us immediately:
Email: philipp-manhart [at] outlook.de

We will then inform you about possible next steps.

Information on the Data Controller

The data controller responsible for data processing on this website is:

Name: Philipp Manhart
Address: Jasminstraße 9, 80939 Munich, Germany
Telephone: +49 160 1713651
Email: philipp-manhart [at] outlook.de

The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g. names, email addresses, etc.).

Contact for Data Protection Inquiries and Data Protection Officer

Contact person for data protection matters:

Philipp Manhart
Jasminstraße 9
80939 Munich, Germany
Email: philipp-manhart [at] outlook.de
Telephone: +49 160-1713651

Note: We have not appointed a separate Data Protection Officer.

For data protection inquiries, please send an email with the subject "Data Protection Inquiry" to the email address above.

Response Time: We will respond to inquiries within 30 days (statutory deadline pursuant to Art. 12 GDPR).

Data Protection Complaint: The competent supervisory authority is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA).
Contact: https://www.lda.bayern.de

Storage Period

Unless a more specific storage period has been specified in this Privacy Policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you assert a legitimate request for erasure or withdraw your consent to data processing, your data will be erased unless we have other legally permissible reasons for storing your personal data (e.g. statutory retention periods under tax or commercial law); in the latter case, erasure will take place after these reasons cease to apply.

General Information on the Legal Bases for Data Processing on This Website

If you have given consent to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR where special categories of personal data pursuant to Art. 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is also based on Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your end device (e.g. via device fingerprinting), data processing is additionally based on Section 25(1) TDDDG. Consent may be withdrawn at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data where necessary to comply with a legal obligation on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. Information on the relevant legal basis in each individual case is provided in the following sections of this Privacy Policy.

Recipients of Personal Data

In the course of our business activities, we cooperate with various external parties. In some cases, this also requires the transfer of personal data to such external parties. We only disclose personal data to external parties if this is necessary for the performance of a contract, if we are legally obliged to do so (e.g. disclosure to tax authorities), if we have a legitimate interest pursuant to Art. 6(1)(f) GDPR, or if another legal basis permits the disclosure of data. When using processors, we only disclose personal data of our customers on the basis of a valid Data Processing Agreement. In the case of joint processing, a joint processing agreement is concluded.

Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You may withdraw consent already given at any time. The lawfulness of the data processing carried out up to the time of withdrawal remains unaffected by the withdrawal.

Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)

WHERE DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. This right is without prejudice to any other administrative or judicial remedies.

Right to Data Portability

You have the right to receive data that we process on the basis of your consent or in performance of a contract in a commonly used, machine-readable format, and to have it transmitted to you or to a third party. If you request the direct transfer of data to another controller, this will only be done insofar as it is technically feasible.

Right of Access, Rectification, and Erasure

Within the scope of the applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients, and the purpose of data processing, as well as, if applicable, a right to rectification or erasure of such data. For this purpose, and for further questions regarding personal data, you may contact us at any time.

Right to Restriction of Processing

You have the right to request the restriction of processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing exists in the following cases:

  • If you contest the accuracy of your personal data stored by us, we generally require time to verify this. For the duration of the verification, you have the right to request restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you may request restriction of processing instead of erasure.
  • If we no longer need your personal data, but you require it for the establishment, exercise, or defence of legal claims, you have the right to request restriction of processing instead of erasure.
  • If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your interests and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request restriction of processing of your personal data.

Where processing has been restricted, such personal data may — with the exception of storage — only be processed with your consent or for the establishment, exercise, or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.

SSL / TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the website operator, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the change in the browser address line from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Objection to Promotional Emails

The use of contact data published within the scope of the Legal Notice (Imprint) obligation for the purpose of sending unsolicited advertising and information materials is hereby expressly objected to. The operators of this website expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam emails.

4. Data Collection on This Website

Registration on This Website

You may register on this website in order to use additional features (e.g. saving learning progress and creating your own decks). Registration and sign-in are possible with an email address and password or, optionally, through a supported third-party login method. We currently offer Google Login for this purpose. The data entered or transmitted for this purpose is used exclusively for the use of the respective offer or service for which you have registered. Mandatory information requested during registration must be provided in full; otherwise, we will reject the registration.

For important changes, such as changes to the scope of services or technically necessary modifications, we will use the email address provided during registration to inform you accordingly.

The processing of data entered during registration is carried out for the purpose of performing the user relationship established by the registration and, if applicable, for the initiation of further contracts (Art. 6(1)(b) GDPR).

The data collected during registration will be stored by us for as long as you are registered on this website and will be deleted thereafter. Statutory retention periods remain unaffected.

Sign-In with Google

If you use Sign-In with Google, you will be redirected to Google for authentication. For users in the European Economic Area and Switzerland, the provider of the Google service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google also processes data in connection with sign-in as an independent controller under Google's Privacy Policy. We remain responsible for the account data stored by SpaceRep.

We only request the Google permissions necessary for registration, sign-in, and account creation. These are currently the OAuth scopes openid, email, and profile. Depending on the data released by Google, we receive and store in particular your Google account ID, your email address, your name, where applicable your profile picture, and technical authentication data such as provider ID, OAuth tokens, ID token, scope information, and expiry times. We use this data for account creation, authentication, session management, and protection against misuse.

Limited Use: We do not use data received through Google Login for advertising, advertising profiling, credit scoring, selling data, disclosure to data brokers, or other purposes not disclosed in this Privacy Policy.

The legal basis is Art. 6(1)(b) GDPR insofar as the processing is necessary to provide your user account and perform the user relationship. Where we process the data for secure authentication and misuse prevention, this is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.

As part of providing Google services, processing in third countries, in particular by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, may also take place. Google provides information about international data transfers and transfer mechanisms at: https://policies.google.com/privacy/frameworks

Google Login is optional. You may continue to use registration and sign-in with an email address and password instead. Minors may use Google Login only if they are legally permitted to do so under applicable law or if the required consent of their legal representatives has been obtained. If you use Google Login, Google's Privacy Policy and Terms of Service also apply: https://policies.google.com/

You can revoke the connection to SpaceRep in your Google account. Such revocation only ends access via Google and does not automatically delete your SpaceRep account or the data stored by SpaceRep. You can request deletion of your SpaceRep account separately using the rights and contact channels described in this Privacy Policy.

We store the data received through Google Login for as long as your user account exists or until the user account is deleted. Statutory retention periods remain unaffected.

Server Log Files

The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This information includes:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Host name of the accessing device
  • Time of the server request
  • IP address

This data is not merged with other data sources.

The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website — for this purpose, the collection of server log files is necessary.

Inquiries by Email, Telephone, or Fax

If you contact us by email, telephone, or fax, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.

Processing of this data is based on Art. 6(1)(b) GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), if such consent has been requested; consent may be withdrawn at any time.

The data you send to us via inquiries will remain with us until you request deletion, withdraw your consent to storage, or the purpose for data storage ceases to apply (e.g. after completion of your request). Mandatory statutory provisions — in particular statutory retention periods — remain unaffected.