Privacy Policy
1. Controller
The controller responsible for data processing is:
NH Creative Hub
Owner:Nadine Hager
Lauerhöferstraße 9
67697 Otterberg
Email: NHCreativeInsights@gmail.com
2. General Information
We process personal data in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection laws.
Personal data means any information relating to an identified or identifiable natural person.
3. Data We Collect
We may process the following categories of personal data:
Name
Email address
Billing information
Account information
Transaction data
IP address
Usage data within digital tools
Communication data (emails, messages)
The specific data processed depends on the services used.
4. Purpose of Processing
We process personal data for the following purposes:
Contract fulfillment (Art. 6(1)(b) GDPR)
Account creation and access management
Payment processing
Providing digital content and subscriptions
Customer support
Legal compliance (Art. 6(1)(c) GDPR)
Protection of legitimate business interests (Art. 6(1)(f) GDPR)
5. Payments and Third-Party Platforms
Payments and subscription management may be processed via third-party platforms such as Whop or other payment service providers.
These providers process data under their own privacy policies.
We only receive the data necessary for contract fulfillment.
6. Hosting
Our website may be hosted by an external hosting provider.
In this case, personal data collected on this website is processed on the servers of the hosting provider under a data processing agreement pursuant to Art. 28 GDPR.
7. Email Communication
If you contact us by email, your data will be stored for the purpose of processing your inquiry.
The legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR.
8. Use of Digital Tools
When using our digital tools, usage-related data may be processed to ensure functionality, performance, and security.
No automated decision-making within the meaning of Art. 22 GDPR takes place.
9. Data Retention
We retain personal data only as long as necessary for:
Contract fulfillment
Legal obligations (e.g., tax retention periods)
Legitimate business interests
After expiry of statutory retention periods, data is deleted.
10. International Data Transfers
If data is processed outside the European Union, this is done only where appropriate safeguards are in place (e.g., Standard Contractual Clauses).
11. Your Rights
Under the GDPR, you have the right to:
Access your stored data (Art. 15 GDPR)
Rectification (Art. 16 GDPR)
Erasure (Art. 17 GDPR)
Restriction of processing (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Object to processing (Art. 21 GDPR)
You also have the right to lodge a complaint with a supervisory authority.
12. Mandatory Provision of Data
The provision of personal data may be required for contract conclusion.
Without required data, a contract cannot be concluded.
13. Updates to This Privacy Policy
We reserve the right to update this Privacy Policy to comply with legal requirements or changes in our services.
🔹 Newsletter / Email Marketing
Email Marketing and Newsletter
If you subscribe to our newsletter or provide your email address for marketing purposes, we process:
Email address
Name (if provided)
Interaction data (e.g., open and click behavior)
The legal basis is:
Art. 6(1)(a) GDPR (consent)
You may withdraw your consent at any time by clicking the unsubscribe link in any email or by contacting us.
We may use third-party email service providers to manage and send emails.
Such providers process data on our behalf under data processing agreements pursuant to Art. 28 GDPR.
🔹 Affiliate Tracking
Affiliate Links and Tracking
Our services may contain affiliate links.
If you click on an affiliate link, the respective provider may process:
IP address
Browser information
Referrer URL
Transaction-related data
Affiliate tracking may use cookies or similar technologies.
The legal basis is:
Art. 6(1)(f) GDPR (legitimate interest in monetization and performance measurement)
The data processing is carried out by the respective affiliate partner under their own privacy policies.
🔹 External APIs
Use of External APIs and Data Providers
We may integrate external APIs and third-party data providers in order to provide market data, analytics, calculations, or other functionality within our tools.
When using such integrations, certain technical data (e.g., IP address or usage data) may be transmitted to the respective provider.
Processing is based on:
Art. 6(1)(b) GDPR (contract fulfillment), or
Art. 6(1)(f) GDPR (legitimate interest in service functionality)
We select providers carefully and ensure appropriate safeguards for international data transfers where applicable.
