Privacy
Deutsch: DatenschutzPrivacy Policy
This policy explains how personal data is processed when you visit this website, make an inquiry, register, pay for, or participate in an offering.
This is an English translation for convenience. The German privacy policy is the authoritative legal version.
Controller
Who is responsible
Falk Scissek
Biblical Risk Academy
An der Stockwiese 6
38536 Meinersen
Germany
Email: falk@biblical-risk-academy.com
No data protection officer has been appointed.
Website
Hosting and server logs
When you visit this website, the hosting provider processes technically necessary data. This may include your IP address, the date and time of access, requested pages or files, transferred data volume, browser, operating system, referrer URL, and status messages.
Processing is necessary to provide the website and protect its security and stability. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure and functional provision of this website.
The website is hosted on servers in Germany by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp, Germany. Log data is deleted or anonymized once it is no longer required for operation and security, unless a legal obligation or a specific security incident requires longer retention.
Contact
Email and contact forms
When you contact me, I process your name, email address, message, and any other details you voluntarily provide. General contact forms request only the data needed to respond.
Processing is necessary to handle your inquiry. The legal basis is Article 6(1)(b) GDPR where the request concerns pre-contractual or contractual steps, and otherwise Article 6(1)(f) GDPR. The legitimate interest is responding appropriately to inquiries.
Email is also provided through Mittwald, which processes technical connection and log data. According to the provider, mail-server sending logs are deleted after four weeks. Logs for email sent from the web environment are anonymized after one day and then retained for 60 days.
Please do not use contact forms or email to send confidential operational information or medical, pastoral, or other particularly sensitive personal data.
Forms
Microsoft Forms only after your choice
Microsoft Forms may be used for contact and workshop forms. An embedded Microsoft form is not loaded automatically when you open a page. A connection to Microsoft is established only after you select the relevant button. Microsoft may then process technical access and device data and use cookies or similar technologies.
Where consent is required to load the embedded form, the legal basis is Article 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). The subsequent processing of your form responses is based on Article 6(1)(b) or (f) GDPR, depending on your inquiry. You may always use the stated email address instead.
The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft or affiliated companies may also process data outside the EU or EEA. Microsoft identifies adequacy decisions and standard contractual clauses among the safeguards it uses. See the Microsoft Privacy Statement.
When registration takes place through an external organizer or partner, you leave this website and that provider is responsible for its data processing.
Offerings
Registration, contracts, and participation
For workshops, training, and development programs, I process the data needed to prepare and deliver the service. This may include contact and organization details, the selected offering, appointments, communications, attendance information, and agreed development goals. The legal basis is Article 6(1)(b) GDPR.
Personal conversations, self-reflection, and development work are treated confidentially. Please share particularly sensitive data only where it is necessary and has been agreed in advance. Where special categories of personal data are intentionally processed, this occurs only on an appropriate legal basis, particularly explicit consent under Article 9(2)(a) GDPR. Consent may be withdrawn for the future at any time.
Information is not shared with a sponsoring organization unless the participant expressly agrees or disclosure is legally required.
Payment
Invoices, bank transfers, and PayPal
For proposals and invoices, I process details such as your name, billing address, organization, service, and payment information. The legal bases are Article 6(1)(b) GDPR for contract performance and Article 6(1)(c) GDPR for statutory accounting and retention obligations.
For bank transfers, the participating banks process the account data needed for payment. If you choose PayPal, the payment data required is shared with PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. PayPal also processes data under its own responsibility. See the PayPal Privacy Statement.
Online meetings
Delivery through Zoom
Online workshops and one-on-one meetings may take place through Zoom. This may involve your display name, email address, meeting and connection data, and any audio, video, or chat content you choose to share. Processing is necessary to deliver the booked service under Article 6(1)(b) GDPR.
Sessions are not normally recorded. If recording is planned in an exceptional case, you will be informed in advance and a separate appropriate legal basis will be used.
The provider is Zoom Communications, Inc., United States. Data may be processed outside the EU or EEA. Zoom states that it uses contractual and other legally recognized safeguards. See the Zoom Privacy Statement.
Retention
Recipients and retention periods
Data is provided only to service providers and bodies needed for hosting, communication, forms, workshop delivery, payment, or legal obligations. Where providers act as processors, processing is based on an appropriate data processing agreement.
Inquiries are deleted once they have been fully handled unless contractual or legal reasons require retention. Contract-related correspondence is retained for statutory periods; accounting records and invoices are generally kept for eight years. Working notes, self-assessments, and development materials are deleted once they are no longer needed for the agreed work and no legal obligation or legal defense requires continued retention.
Transfers outside the EU or EEA use the safeguards required by law, particularly adequacy decisions or standard contractual clauses, unless a statutory exception applies.
Cookies
No analytics or advertising
This website does not use analytics, advertising, or profiling services and does not set its own cookies for those purposes. External fonts, maps, and videos are not loaded automatically. A Microsoft form is loaded only after your selection; possible storage or access to information is explained in the Microsoft Forms section.
Rights
Your privacy rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction, data portability, and objection to certain processing. Where processing is based on consent, you may withdraw that consent at any time for the future. This does not affect processing that occurred before withdrawal.
You may also lodge a complaint with a data protection authority, particularly in your habitual residence, place of work, or the place of the alleged infringement. In Lower Saxony, the competent authority is the State Commissioner for Data Protection of Lower Saxony.
Last updated: September 2026