Information pursuant to Art. 13 GDPR
Privacy Policy
Last updated: 2026-10-01
This policy applies to the Meritlume websites. You can change your choice anytime via cookie settings.
Controller
Teachlume GmbH i.G.
Friedrichstraße 155, 10117 Berlin, Deutschland
Email: privacy@meritlume.com
For data-protection enquiries, contact us at the email address above.
Principles & legal bases
We process personal data only insofar as necessary to provide a functional website and our services. Legal bases are in particular Art. 6(1)(b) GDPR (contract/pre-contractual steps), (f) (legitimate interest), (c) (legal obligation) and (a) (consent).
Hosting & delivery
The website is delivered via the content delivery network of Cloudflare, Inc. (USA); application data (database, authentication, file storage) is processed at Supabase, Inc. (USA). Application data is stored and processed in the Frankfurt am Main region (AWS eu-central-1, EU); for CDN delivery, connection data is processed at the Cloudflare location closest to you. Both act as processors for us (Art. 28 GDPR). As both providers are US companies, a third-country element cannot be fully excluded; transfers are safeguarded via the adequacy decision for the EU-US Data Privacy Framework (Cloudflare is certified) and EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). On access, server log data is generated (e.g. truncated IP, timestamp, requested resource, referrer, user agent) — Art. 6(1)(f) GDPR, stored only briefly for security and troubleshooting. To defend against automated access (bot detection), Cloudflare may additionally set the technically necessary security cookie "__cf_bm" (lifetime approx. 30 minutes; § 25(2) TDDDG, Art. 6(1)(f) GDPR).
For reach measurement we evaluate aggregated access statistics that Cloudflare collects server-side at the edge while delivering the website (page views, countries of origin, status codes); no cookies are set and no information is read from your device. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in needs-based, stable provision). We do not currently use the client-side "Cloudflare Web Analytics" measurement script.
Cookies & consent
Technically necessary cookies (e.g. to store your cookie choice and for login) are set on the basis of § 25(2) TDDDG or Art. 6(1)(f) GDPR. All other cookies/technologies are set only after your consent via our consent tool. You can change your choice anytime via Cookie settings .
Your choice is stored under the name "cb_consent" in your browser local storage and as a first-party cookie of the same name (lifetime 180 days) so your decision persists across visits (§ 25(2) TDDDG).
This consent requirement applies to visitors from the European Economic Area, the United Kingdom and Switzerland — and, in case of doubt, also where your location cannot be determined. For visitors from other countries whose law does not require prior agreement (such as the USA), statistics and marketing start enabled; a clearly visible notice says so and offers an opt-out at any time ("Do Not Sell or Share My Personal Information"). Once declared, an opt-out is stored and applies on every further visit.
For Google services we use Google Consent Mode in its advanced implementation: Google tags load before your consent decision, but without consent they run with a "denied" status and neither set nor read cookies. In this state, cookieless aggregated status signals ("pings") may be transmitted to Google — including the IP address technically transmitted with any request, the page visited and the consent status; no user-level profiling takes place. Only after you consent do the respective services measure fully (including cookies).
Registration & account
To use the platform you create an account (email, name, organisation data). Processing is for contract performance (Art. 6(1)(b) GDPR). Course, progress and certificate data are processed to provide the training service.
Learning groups and community
Courses can have a learning group with a community space. There we store your membership and role (participant or moderator), your published posts and replies including titles, the “This helped me” reaction, reports to moderators and moderation notes, your read status and a level derived from your course points and participation. Private reflection answers are stored separately.
Who sees what: published posts and replies are visible to the members of the same learning group or alumni space, with your name and level — others do not see your points. The coach or the organisation’s administrators and the moderators additionally see reports and an overview of participation. Private reflection answers are visible only to the person who writes them — not to the coach, the moderators or the organisation. Withdrawn and hidden posts are no longer displayed.
The controller is whoever is responsible for the course: where an organisation (such as your employer, or a coach for their participants) provides the course, we process the data as its processor; where you bought the course from us, we are the controller and the legal basis is Art. 6(1)(b) GDPR. Deletion: there is currently no time-based deletion of learning-group content. Posts, replies, reactions and private reflections are deleted when your account is deleted, when the learning group or the organisation is deleted — at the latest after the end of the contract under the data processing agreement — or earlier at your request (Art. 17 GDPR). Withdrawn and hidden posts remain stored until then but are no longer displayed.
AI assistant and dashboard copilot
When you use the AI assistant or dashboard copilot, we send your chat input and the product or dashboard information required for the response, limited by your existing permissions, to OpenAI Ireland Ltd. (Ireland). The feature is optional and read-only in the dashboard; it does not change your data. OpenAI processes this data as a processor on our behalf; where we act as a processor for customers, OpenAI is engaged as a subprocessor. With store=false, model outputs are not stored as API resources available for later retrieval. OpenAI may retain inputs and outputs in abuse-monitoring logs for up to 30 days by default; longer retention is possible where required by law or reasonably necessary to protect its services or third parties. Processing in or onward transfer to the United States is possible; third-country transfers are subject to the agreed data-protection safeguards, in particular an adequacy decision or EU Standard Contractual Clauses. Please do not enter unnecessary sensitive personal data into the chat.
OpenAI Data Processing Addendum
Other AI-assisted features (e.g. the training-needs analysis and course generation) process the input you provide for them (such as a company description) via Google’s Gemini API (Google Ireland Limited) as processor. Inputs are not used for advertising or to train third-party models; processing in third countries is possible and safeguarded via EU Standard Contractual Clauses. Here too, please do not enter personal data that is not required for the feature.
We evaluate feedback on course content with a language model from Anthropic (Anthropic PBC, USA); if it is unavailable, Google’s Gemini API takes over. The free texts are transmitted without real names and attributed via pseudonyms. With the phishing simulation activated, the same model creates template texts from campaign briefings. None of these services uses the data for training; transfers to the US are safeguarded by EU Standard Contractual Clauses or the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(b) or (f) GDPR; where we act as processor for customer organisations, these services are sub-processors under Annex 2 of the data processing agreement. We produce voices, images and videos for course content with further AI services; they receive narration texts and image descriptions only, no personal data, and do not use them for training.
Contact, newsletter & email delivery
When you contact us or sign up for the newsletter, we process your data to handle the request (Art. 6(1)(b)/(f) GDPR) or based on your consent (Art. 6(1)(a) GDPR). Delivery is handled via Brevo (Brevo GmbH, formerly Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin) as processor; processing takes place in the EU. You can withdraw newsletter consent anytime via the unsubscribe link.
We hand out our white papers in exchange for this consent: requesting a paper also signs you up for the newsletter and a short topical follow-up series — this is stated at the form’s checkbox, the box is not pre-ticked, and without your tick we do not send the paper. The papers are free and there is no entitlement to them; you can withdraw at any time via the unsubscribe link without any disadvantage. Some papers are handed out without this coupling — the form says what you receive instead.
We keep prospect and sales contacts in a CRM: HubSpot (HubSpot Ireland Limited) acting as processor. This involves business contact data (name, email address, company, role) and the status of the contact. Legal basis is Art. 6(1)(f) GDPR (our legitimate interest in traceable sales work) or Art. 6(1)(b) GDPR for contracts under negotiation. Processing takes place with EU data residency. Learner data from customer organisations does NOT enter the CRM.
For cold outreach by email we use Instantly (Instantly.ai, USA) as processor; transfers are safeguarded by EU Standard Contractual Clauses. Details — including the right to object under Art. 21 GDPR — are set out in the privacy statement of the respective sending domain.
Transactional platform emails (e.g. invitations, training reminders, system notifications) are sent via the processor Brevo (Brevo GmbH, Berlin); processing takes place in the European Union. This involves name, email address and the respective training context. Where we send such emails to a customer organisation’s users on its behalf, we act as processor under the data processing agreement (Art. 28 GDPR); otherwise the legal basis is Art. 6(1)(b) GDPR.
To support trial and customer accounts, we also maintain a contact profile for administrator contacts in our CRM at Brevo (name, email, organisation, plan and usage status) and send product-related onboarding and account notification emails — Art. 6(1)(b) and (f) GDPR (contract performance, customer care). You can object to these emails at any time.
Compliance Radar and radar widget
The Compliance Radar (conformbase.com/en/compliance-radar, German original at conformbase.com/compliance-radar) shows published decisions of authorities and courts. Where these name natural persons — for example responsible executives — we only take over what the official source itself has published and refer to that source. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in information about the enforcement of compliance obligations). Data subjects can object under Art. 21 GDPR; contact the address above or use "report an error" on the respective case.
Error reports on a case are anonymous: we only store the text entered and the time, no contact details. Your IP address is not stored; it only enters an abuse limiter in a daily-rotating encrypted form (HMAC), which expires after the time window (Art. 6(1)(f) GDPR).
The radar widget, which third parties can embed on their websites, sets no cookies, stores nothing in visitors’ browsers, contains no trackers and loads no third-party content. Its requests to conformbase.com transmit no referrer and no credentials. We do not log which websites embed the widget and do not evaluate the requests. For technical reasons our delivery provider Cloudflare processes connection data on retrieval (see "Hosting & delivery"); we are not a processor for the embedding website because we do not process personal data on its behalf there.
Course offers on partner websites
Coaches and partners can show our course offer on their own website with an embedded block. The block is loaded from our domain — immediately or, if the partner has set it up that way, only after your click. It sets no cookies, stores nothing in your browser, does not recognise you on later visits and transmits no referrer; we do not log on which pages it appears. For technical reasons our delivery provider Cloudflare processes connection data on retrieval (see "Hosting & delivery"). We only count how many enquiries, registrations and bookings arise via a block — without any data about you (Art. 6(1)(f) GDPR).
If you send an enquiry via the block, we process your name, email address, optionally your company and your message to answer it; for a coach offer it goes to the respective coach (Art. 6(1)(b) GDPR). If you register or book via the block, we note which partner you came from — solely from the address of the button, not from your browser — in order to remunerate the partner under the programme terms (Art. 6(1)(f) GDPR).
Payment processing
Paid bookings are processed via Stripe (Stripe Payments Europe, Ltd.). Stripe processes the data required for payment on its own responsibility; we receive payment status and invoice data for contract performance (Art. 6(1)(b) GDPR).
Purchase via a coach’s course page: sharing with the coach
If you buy a course via a coach’s course page (Coachweave brand), we are your contracting party and process your order data as controller to perform the contract (Art. 6(1)(b) GDPR). We pass your name, email address, the course purchased and the purchase date to the coach whose course you bought. The only recipient is that coach; who that is is stated on the course page.
Purpose: the coach supports you within the purchased course and may inform you about their own offers to the extent permitted by law. The legal basis is Art. 6(1)(b) GDPR insofar as the coach’s support is part of the purchased course, and otherwise Art. 6(1)(f) GDPR (the coach’s legitimate interest and our legitimate interest in a direct relationship between you and the coach whose method you bought). From the transfer onwards the coach is an independent controller for this data; the coach is contractually obliged to use it only for these purposes, not to pass it on and to delete it once it is no longer needed.
Objection: you can object to the transfer and to the use of your data for advertising at any time (Art. 21 GDPR) — to us at the address above or directly to the coach. An objection to advertising must be followed without any balancing of interests. For courses of the Tribelume brand no such transfer takes place: creators there only receive aggregated sales figures without personal reference.
Referral and partner programmes
Coaches can recommend Coachweave to other coaches, and partners can recommend ConformBase to companies — each via a personal link or code. If you open coachweave.com or conformbase.com via such a link, we store the code and the time of the visit under the name "cw-empfehlung" in your browser session storage (deleted when you close the tab). Only with your consent to marketing services do we also store it in local storage, for at most 90 days (Art. 6(1)(a) GDPR together with § 25(1) TDDDG); withdrawing your consent deletes this entry. We count visits via a link only as a number per day, without any data about you.
If you register with a referral code or via such a link, we assign your account or organisation to the recommending partner; for ConformBase this also applies to organisations a partner creates for you and to enquiries carrying the code. For Coachweave: That coach sees your name (or only "Recommended coach no. X" if you object to your name being shown in your account), the date you registered, your status and your progress towards the revenue threshold in broad steps — never revenue, prices, customers or learners. The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in rewarding referrals correctly); you can object to your name being shown at any time (Art. 21 GDPR).
To pay out rewards we process the recommending coach's invoicing, tax and bank details to perform the contract (Art. 6(1)(b) GDPR) and keep credit notes for the statutory periods (Art. 6(1)(c) GDPR). To prevent abuse we compare company, address, bank account, tax number and email domain of partner and recommended coach (Art. 6(1)(f) GDPR).
Reviews via ProvenExpert
At the end of a course we offer a link to a review on ProvenExpert (Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin, Germany). As long as you do not click, no data flows there. Only when you actively choose the link do we pass your name and email address to ProvenExpert so that your review invitation can be matched; the legal basis is Art. 6(1)(b) GDPR (your request) or (f) (our legitimate interest in customer reviews). We act under our own responsibility here; no learner data is transmitted automatically. Processing takes place in the EU.
Web analytics & reach measurement
All analytics services listed here — including cookieless ones — load only after you consent to the "Statistics" category via our consent tool (Art. 6(1)(a) GDPR; together with § 25(1) TDDDG where cookies or comparable identifiers are used). You can adjust or withdraw your consent anytime via the cookie settings.
The following services run on the public pages of this website and in the sign-in, registration and onboarding area of the dashboard on the main domain. On customer-specific subdomains and the learning-platform domain (courses.conformbase.com) none of these services are used; learning-progress, training or course-content data is never transmitted to or evaluated by the providers listed.
Cloudflare Web Analytics
Cookieless aggregate traffic measurement (page views, referrers) with no personal profiles.
Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Cookies/identifiers:
Sets no cookies (cookieless).
Third-country transfer: Possible transfer to the USA; safeguarded via EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Retention: aggregated, no personal raw data · Provider's privacy policy
Ahrefs Web Analytics
Cookieless reach measurement for SEO analysis (page views, sources) without cross-site tracking.
Provider: Ahrefs Pte. Ltd., 16 Raffles Quay, #33-03 Hong Leong Building, Singapur 048581
Cookies/identifiers:
Sets no cookies (cookieless).
Third-country transfer: Processing outside the EU (Singapore); safeguarded via EU Standard Contractual Clauses.
Retention: aggregated · Provider's privacy policy
Google Analytics 4
Analysis of usage behaviour (pages, sessions, events) for reach measurement and optimisation; with IP truncation and Google Consent Mode.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland
Cookies/identifiers:
_ga— Distinguishes users (2 years)_ga_<ID>— Session state (GA4) (2 years)
Third-country transfer: Possible transfer to the USA; safeguarded via EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Retention: up to 14 months (event data) · Provider's privacy policy
Marketing & conversion measurement
These services measure advertising conversions and deliver relevant ads; conversion measurement is partly performed server-side (Conversions API). The sole legal basis is your consent (Art. 6(1)(a) GDPR together with § 25(1) TDDDG), which you can withdraw at any time.
Meta-Pixel (Facebook/Instagram)
Measurement of ad conversions and remarketing on Facebook/Instagram; complemented by the Conversions API (server-side).
Provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Irland
Cookies/identifiers:
_fbp— Browser identifier for advertising (90 days)
Third-country transfer: Possible transfer to the USA; safeguarded via EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Retention: up to 90 days (cookie); server-side per Meta · Provider's privacy policy
OpenAI Ads Pixel
Measurement of ad conversions for ads shown in ChatGPT (attributing an ad click to a registration or purchase).
Provider: OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Irland
Cookies/identifiers:
Sets no cookies (cookieless).
Third-country transfer: Possible transfer to the USA; safeguarded via EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Retention: per OpenAI's privacy policy · Provider's privacy policy
Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw a given consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority.
Contact for data-subject rights: privacy@meritlume.com