Privacy Policy

This Privacy Policy explains how GoethéB1 ("we", "us", the "Service", at b1goethe.com) collects and uses your personal data when you use our website and practice app for preparing the Goethe-Zertifikat B1 exam. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) and applicable data-protection laws.

1. Who is responsible for your data

The controller responsible for your personal data is:

As the operator is established outside the EU/EEA, our representative in the EU under Art. 27 GDPR is: [EU REPRESENTATIVE, to appoint; name & EU address].

2. What data we collect

We do not collect special-category data (e.g., health, ethnicity), and we do not knowingly collect data from children (see Section 9).

3. Why we use your data, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Create and run your account; sign-inPerformance of a contract (Art. 6(1)(b))
Save and sync your learning progressPerformance of a contract (Art. 6(1)(b))
Generate automated feedback on the writing you submitPerformance of a contract (Art. 6(1)(b))
Keep the Service secure; prevent abuseLegitimate interests (Art. 6(1)(f))
Send study reminders / notifications (if you enable them)Your consent (Art. 6(1)(a))
Website analytics (Google Analytics via Google Tag Manager)Your consent (Art. 6(1)(a))
Product analytics & session replay (Amplitude)Your consent (Art. 6(1)(a))
Send you study-tips / newsletter emails (only if you opt in)Your consent (Art. 6(1)(a))

You can withdraw any consent at any time (e.g., turn off reminders, unsubscribe) without affecting processing already carried out.

Marketing emails (newsletter)

If you tick the optional box when you create your account (it is never pre-ticked), or switch on “Study tips & news by email” in your settings, we will send you occasional study tips and product news. We rely on your consent (Art. 6(1)(a) GDPR), and we record the fact and time you gave it as proof of consent. You can withdraw your consent at any time, and withdrawing is as easy as giving it: use the unsubscribe link in any email, or the toggle in your account settings. We keep your subscription status until you unsubscribe or delete your account. We do not share your email address with our analytics providers.

4. Cookies

We use a strictly-necessary session cookie to keep you logged in; this is essential to provide the Service and does not require consent. We also use analytics tools that are not strictly necessary and therefore require your prior consent (which we ask for through our cookie-consent banner; you can accept or decline, and change your choice at any time):

Declining does not affect your use of the Service. We do not use advertising cookies.

5. Who we share data with

We do not sell your personal data. We share it only with service providers ("processors") who help us run the Service, under data-processing agreements:

We may also disclose data where required by law.

6. International data transfers

Some of the providers we use are located outside the European Economic Area (EEA) — including Google, Amplitude, and Resend in the USA — and our operating entity is based outside the EEA. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework. You may contact us for more information about these safeguards.

7. How long we keep your data

We keep your account and progress data for as long as your account is active. When you delete your account, we delete your personal data from our active systems promptly and from backups within our normal backup-rotation cycle. Server logs are kept only for a short period for security and troubleshooting.

8. Your rights

Under the GDPR (and similar laws) you have the right to:

To exercise any right, email hello [at] b1goethe.com. We respond within one month.

9. Children

The Service is intended for users aged 16 and over (the digital-consent age in Germany and several EU countries). We do not knowingly collect data from children under this age. If you believe a child has provided us data, contact us and we will delete it.

10. How we protect your data

We use appropriate security measures, including password hashing (Argon2id), encryption in transit (HTTPS/TLS), access controls, and encryption at rest where applicable. In the event of a personal-data breach that is likely to put your rights at risk, we will notify the relevant authority and, where required, affected users.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new "Last updated" date and, for material changes, notify you where appropriate.

12. Contact

Questions about your privacy? Email hello [at] b1goethe.com or write to Elif Yılmaz, Abide Bayram Sk 19, Gazimağusa 99450, North Cyprus (TRNC).