Privacy policy
Information on the processing of personal data on fahrschuldaten.de.
Version: 2026-07-24
1. Controller
The controller responsible for processing personal data on this website and within the platform is:
VEHI Digital UG (haftungsbeschränkt) Am Pichelssee 58 13595 Berlin Germany Email: info@fahrschuldaten.de
2. Definitions and user groups
Personal data means any information relating to an identified or identifiable natural person. Processing means any operation performed on personal data (e.g. collection, storage, transmission, deletion).
We distinguish in particular the following areas and user groups:
- website visitors (public pages without an account)
- registered users (driving school and team accounts)
- publicly displayed driving school, location and price data
Legal bases for processing include in particular Art. 6(1)(a) GDPR for consent, Art. 6(1)(b) GDPR for contract performance and pre-contractual measures, Art. 6(1)(c) GDPR for legal obligations, and Art. 6(1)(f) GDPR for legitimate interests.
Information obligations arise in particular from Art. 13 GDPR where data is collected directly from the data subject.
3. Website access and server log files
When you access our website, technically necessary data is processed. This may include:
- IP address
- date and time of access
- page / URL accessed
- referrer URL
- browser type and version
- operating system
- amount of data transferred
- status codes
- technical security information
Purposes: providing the website, security, stability, error analysis, and detecting misuse or attacks.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of the website.
Server log data is generally stored for 14 days and then deleted or anonymised. In security-relevant cases (e.g. attack detection, ongoing investigation), longer retention may be required.
4. Hosting and technical infrastructure
4.1 Operation of the web application and database (netcup)
We operate the website, application and database (PostgreSQL) on infrastructure of netcup GmbH, Dexheimer Str. 4–6, 55246 Mainz-Kastel, Germany (VPS in Germany / EU). We also use a reverse proxy (Caddy) for TLS and delivery.
Purposes: platform operation, account handling, technical administration.
Legal bases: Art. 6(1)(b) GDPR (use / pre-contractual steps) and Art. 6(1)(f) GDPR (security, misuse prevention, system operation).
4.2 Data processing agreements
Where service providers process personal data on our behalf, we conclude data processing agreements pursuant to Art. 28 GDPR as required.
5. Contact by email
When users contact us by email or via the contact or Enterprise form, we process the information submitted to handle the request.
This may include:
- name
- email address
- company or driving school
- phone number, if provided
- message content
- technical metadata
The legal basis is Art. 6(1)(b) GDPR where the request relates to a contract or pre-contractual measures. In all other cases, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in handling enquiries.
Appointments booked via Google Calendar are processed on systems of Google Ireland Limited. Google's privacy policy applies to the booking.
6. Cookies, local storage and consent tool
6.1 General
We use cookies and similar technologies (e.g. sessionStorage) to operate the website technically and – only after consent – to measure reach and marketing.
You can change or withdraw consent at any time via "Cookie settings" (footer link).
6.2 Categories
Our consent tool controls three categories:
- Necessary (technically required, e.g. login, security, consent storage) – no consent required
- Statistics (Google Analytics) – only after consent
- Marketing (Google Ads) – only after consent
Legal bases: necessary technologies Art. 6(1)(b) and/or (f) GDPR and Section 25(2) no. 2 TDDDG. Statistics/marketing: Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Examples of necessary cookies: cookie_consent (1 year), authjs.session-token, authjs.csrf-token. Additional technically necessary geo/probe cookies (is_eu, cc, typically 30 days) may be set to support regional settings.
To deduplicate marketing events after consent, we store short-lived sessionStorage entries (prefix tracked:). They last until the end of the browser session and contain no plain-text email, only technical event keys.
6.3 Consent logging (Art. 7 GDPR)
Consents to the privacy policy, terms of service and double opt-in, as well as cookie banner choices, are logged server-side. The consent log may store: timestamp (UTC), status per category (statistics/marketing), privacy policy / consent banner version, locale, IP address and user agent, and where applicable an email hash. Log data is generally retained for 3 years and serves as proof of consent.
Withdrawal takes effect from the time it is declared and does not affect the lawfulness of processing carried out before withdrawal.
7. Registration and user account
When registering and using a user account, we process the data required for account creation and management.
This may include:
- name
- email address
- password (hashed, not in plain text)
- company or driving school
- role within the company
- location assignment
- login timestamps
- security and verification data
- usage and account status
Purposes: account creation, login, account management, security and misuse prevention.
The legal basis is Art. 6(1)(b) GDPR. Where security data is processed, Art. 6(1)(f) GDPR also applies.
Transparency: At registration, your contact details are not automatically shared with external data or product partners. You control later sharing of location data in the account.
8. Driving school, location and price data
Driving schools can enter data about their business, locations, licence classes, prices and price list versions via the platform.
This data is predominantly business and factual data. Personal data may be affected where contact persons, owners, managing directors or personal email addresses are stored.
Processing is carried out to provide, manage, review and – where released – publish or share platform data with partners.
The legal basis is Art. 6(1)(b) GDPR where processing is necessary to use the platform. Where data is displayed publicly or processed for quality assurance, Art. 6(1)(f) GDPR may also apply.
9. Data quality, public display and internal processing area
We may automatically and manually check submitted data for completeness, plausibility, contradictions or quality issues. This may involve user activity, price list versions, change histories and audit logs.
Where data is intended for publication, the driving school name, location, contact details, classes, prices and price list versions may in particular be shown publicly.
Some processes are supported in an internal processing area. It is not intended for external third parties, but only for authorised internal users of VEHI Digital / fahrschuldaten.de (role-based access for support, quality assurance and operations).
Legal bases: Art. 6(1)(b) and (f) GDPR.
10. Payment processing via Stripe
For paid plans we use Stripe Payments Europe, Limited (Ireland) and/or affiliated Stripe, Inc. entities (USA).
This may include transmission of:
- name
- email address
- billing address
- payment data
- tax data
- plan information
- transaction data
Purpose: handling paid services and invoicing.
Legal basis: Art. 6(1)(b) GDPR; where tax and commercial retention obligations apply, Art. 6(1)(c) GDPR.
Stripe may process data in the USA. Where required, this is based on the EU-US Data Privacy Framework and/or standard contractual clauses (Art. 46(2)(c) GDPR). Details: https://stripe.com/privacy
11. Email delivery via Postmark
For transactional emails we use Postmark (AC PM, LLC, 222 N LaSalle St, Chicago, IL 60601, USA) as a processor (DPA under Art. 28 GDPR).
Transactional emails may in particular include:
- registration and verification emails
- password reset emails
- security information
- data quality notices
- contract and system notifications
This may involve processing email address, name, technical delivery data and message content.
Legal bases: Art. 6(1)(b) GDPR (service/process emails) and Art. 6(1)(f) GDPR (reliable operation).
Third country USA: EU-US Data Privacy Framework (DPF) – Postmark is DPF-certified; supplemented by standard contractual clauses under Art. 46(2)(c) GDPR. Despite DPF certification, a residual risk of government access under US law remains; based on our assessment, the residual risk is appropriate given the nature of the data.
Provider retention: delivery logs typically 45 days (Postmark default).
12. Newsletter and promotional communication
We do not currently offer a separate email newsletter.
If we offer newsletters or similar promotional series in the future, this will only happen with separate consent (Art. 6(1)(a) GDPR). Consent may be withdrawn at any time with effect for the future.
Service and process emails (e.g. verification, security, contract) are not covered by this.
13. Online marketing (consent only)
The following services are activated only after your express consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG). Withdraw consent at any time via cookie settings.
13.1 Google Tag Manager (GTM) Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland / Google LLC, USA. Role: processor (technical container). Purpose: managing and delivering tracking tags (e.g. GA4, Google Ads) — GTM itself does not store standalone usage profiles. Legal basis: Art. 6(1)(a) GDPR; Section 25(1) TDDDG. Third country USA: EU-US Data Privacy Framework (DPF) and standard contractual clauses (SCCs). The container is loaded with Consent Mode v2 (defaults denied until you consent).
13.2 Google Analytics 4 (GA4) Delivered via Google Tag Manager. Provider: Google Ireland Limited / Google LLC, USA. Purpose: reach measurement, page views, selected events (e.g. sign_up, first_location_published, purchase). Cookies include _ga, _ga_*, _gid. Third country USA: DPF and SCCs. Event data is stored at Google according to the retention period configured in GA4.
13.3 Google Ads (conversion tracking & remarketing) Where configured in GTM. Provider: Google Ireland Limited / Google LLC. Purpose: conversion measurement and remarketing. Cookies include _gcl_au, IDE, test_cookie. Third country USA: DPF and SCCs.
13.4 Meta Pixel Where configured in GTM. Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. Purpose: conversion measurement and remarketing via Meta platforms. Cookies include _fbp, _fbc. Third country USA: SCCs and, where applicable, DPF. Event data at Meta typically up to 180 days.
No parallel direct gtag.js / Meta Pixel script is loaded alongside the GTM container, to avoid double counting.
14. Other services (geocoding)
For location entry we use OpenStreetMap/Nominatim server-side for geocoding. Address data and technical request data may be transmitted to the respective Nominatim/OSM service.
Purpose: mapping and validating location addresses.
Legal basis: Art. 6(1)(b) GDPR (platform feature) or Art. 6(1)(f) GDPR (correct location assignment).
Fonts are embedded locally via next/font; end users do not directly access Google servers.
15. Recipients and transfers to third countries
Personal data may be transmitted to the following categories of recipients:
- hosting and infrastructure providers (netcup)
- email service providers (Postmark)
- payment service providers (Stripe)
- analytics and marketing providers (only after consent: Google, Meta)
- geocoding services (OpenStreetMap/Nominatim)
- support and IT service providers
- tax advisors and accounting
- authorities, where legally required
- data partners, where a driving school actively grants access to location data in the account
Data is shared only where a legal basis exists.
Where personal data is processed outside the EU/EEA (in particular the USA for Postmark, Stripe, Google, Meta), this occurs only where GDPR requirements are met, in particular an adequacy decision (e.g. EU-US DPF) and/or standard contractual clauses.
16. Storage period and deletion
We store personal data only as long as necessary for the respective purposes.
16.1 Legacy waitlist entries We no longer offer a public waitlist. Any remaining legacy waitlist entries without a converted customer account are deleted upon withdrawal or at the latest after 24 months without relevant interaction (inactivity).
16.2 Consent and proof logs Records of consent (including cookie banner logging) are generally retained for 3 years to meet our accountability obligations.
16.3 Customer account Account data remains stored while the account exists. After active account deletion, pure account data is deleted or anonymised within 30 days unless retention obligations prevent this. Consent records may be retained longer in anonymised form (see 16.2).
16.4 Billing and evidence data Billing, contract and accounting data may be stored longer due to statutory retention obligations.
16.5 Server logs See section 3 (generally 14 days).
17. Rights of data subjects
Data subjects have the following rights under the GDPR in particular:
- right of access (Art. 15 GDPR)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object (Art. 21 GDPR)
- right to withdraw consent (Art. 7(3) GDPR)
- right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Please send requests to: info@fahrschuldaten.de
Withdraw cookie consent at any time via "Cookie settings" in the footer. Registered users can also see consent status under account settings (Privacy & consents).
18. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates data protection law.
The supervisory authority of the federal state where you reside or where our company is established (Berlin) may in particular be competent.
19. Data security
We implement technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure.
These may in particular include access restrictions, encryption, logging, rights and role concepts, backups and security reviews.
20. Changes to this privacy policy
We may update this privacy policy when the legal situation, platform features or services used change. The current version published on fahrschuldaten.de applies.