1. Scope of this Privacy Policy
This Privacy Policy explains how TemplinTech processes personal data when you use our websites, digital platforms, customer and educational services, and our official communication channels.
Processing is carried out in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), applicable German data protection law, including the Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG), and other applicable legal requirements.
This Privacy Policy applies to templintech.com and its subdomains, including go.templintech.com with TemplinTech Connect and academy.templintech.com with TemplinTech Academy.
It also applies to other websites, digital services, or projects operated under the TemplinTech name where they refer to this Privacy Policy and no separate privacy information is provided.
This Privacy Policy also covers personal data processed by us in connection with TemplinTech's official profiles and channels on LinkedIn, Instagram, and YouTube.
2. Controller
The controller within the meaning of Article 4(7) GDPR is:
Dr. Yordan Balabanov
Frankfurter Str. 37
70376 Stuttgart
Germany
Phone: +49 176 376 708 10
Email:
The controller determines the purposes and means of processing personal data in connection with TemplinTech's activities, websites, and digital services unless otherwise stated for a specific processing activity.
3. Legal bases, retention periods, and recipients
Legal bases for processing
We process personal data only for specified and lawful purposes and where an applicable legal basis exists.
Depending on the circumstances, processing may be based on:
- Article 6(1)(a) GDPR – where you have given consent to a specific processing activity;
- Article 6(1)(b) GDPR – where processing is necessary for the performance of a contract or in order to take steps at your request prior to entering into a contract;
- Article 6(1)(c) GDPR – where processing is necessary for compliance with a legal obligation;
- Article 6(1)(f) GDPR – where processing is necessary for the purposes of our legitimate interests or those of a third party and those interests are not overridden by your interests, fundamental rights, and freedoms.
Where a technology stores information on a user's terminal device or accesses information already stored there, Section 25 TDDDG also applies.
Where such storage or access is strictly necessary to provide a digital service expressly requested by the user, prior consent is not required under Section 25(2)(2) TDDDG.
Retention periods
Personal data is retained only for as long as necessary to fulfill the purpose for which it is processed.
Once the relevant purpose no longer applies, the data is deleted or anonymized unless further retention is required by applicable law or is necessary for the establishment, exercise, or defense of legal claims.
Statutory retention periods may apply to contractual, accounting, tax, and commercial records and may take precedence over the general principle of deletion once the original purpose no longer applies.
Recipients of personal data
Personal data is disclosed to external recipients only where this is necessary and there is a valid legal basis.
Depending on the relevant process, recipients may include hosting and technical service providers, payment service providers, competent public authorities, tax or accounting advisers, and other parties whose involvement is necessary to provide the relevant service, perform a contract, or comply with a legal obligation.
Where an external organization processes personal data on our behalf and in accordance with our instructions, the processing is governed in accordance with Article 28 GDPR where those requirements apply.
Transfers outside the European Economic Area
When certain international services are used, such as Stripe, WhatsApp, or social media platforms, personal data may also be processed in countries outside the European Union and the European Economic Area.
Where additional safeguards are required for such transfers, the mechanisms permitted under the GDPR are used, such as an adequacy decision of the European Commission, the EU-U.S. Data Privacy Framework for participating certified organizations, Standard Contractual Clauses, or another applicable legal mechanism.
4. Visiting our websites and hosting
STRATO
The technical infrastructure for our websites and platforms is hosted by:
STRATO AG
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
When a website is loaded, technical data is exchanged between your device and the hosting infrastructure in order to establish the connection and deliver the requested content.
The data processed in this context may include, in particular:
- IP address;
- date and time of the request;
- requested page, file, or resource;
- browser type and version;
- operating system used;
- referrer URL, where transmitted;
- technical information concerning the request and the server response.
This data is used to technically provide the services, maintain system stability, diagnose technical problems, and protect against misuse and attacks.
The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest is the provision of secure, reliable, and technically functioning infrastructure.
STRATO states that full visitor IP addresses processed for the detection and prevention of attacks are retained for up to seven days. Log files provided to STRATO customers for hosting analysis and administration contain anonymized IP addresses.
Further information about data protection at STRATO: https://www.strato.de/datenschutz/
5. Cookies and technical storage in the browser
TemplinTech follows the principle of minimizing the use of cookies and comparable technologies.
templintech.com and Joomla
During a standard visit to templintech.com, Joomla uses a first-party session cookie to manage the current technical session and related website functionality.
It is set by our own domain, is limited to the current browser session, and is not used by TemplinTech for advertising, marketing, behavioral analysis, creation of advertising profiles, or tracking across different websites.
Language functionality may use information within the current session where this is necessary to provide the language version selected by the user.
go.templintech.com and TemplinTech Connect
When using go.templintech.com, user accounts, and TemplinTech Connect, additional technically necessary session and authentication mechanisms may be used where required to provide secure login and the requested customer functionality.
If a user expressly activates a feature that keeps them signed in, such as “Remember Me,” a persistent authentication cookie may be used where necessary to provide that specifically requested functionality.
academy.templintech.com and Moodle
When academy.templintech.com is used, the Moodle platform uses the technical session cookie MoodleSession.
MoodleSession maintains the current session and enables the platform to recognize that session when the user moves between different pages. When a user signs in to an account, it is required to maintain the authenticated session.
MoodleSession is not used by TemplinTech for advertising, marketing, or tracking user behavior across different websites.
Moodle's feature for persistently remembering the username has been disabled. Accordingly, TemplinTech does not use the persistent MoodleID cookie for remembering the username.
Other technical mechanisms
Depending on the specific service, technical browser mechanisms such as caching, session storage, or web application functionality may be used where necessary for the technical delivery or optimization of the relevant service.
TemplinTech does not use these mechanisms for advertising tracking or for creating behavioral profiles.
Detailed information about the cookies used and the applicable rules is available at: https://templintech.com/cookie-consent.
6. Communication with TemplinTech
Contact forms
If you send us a message using a form on one of our websites, we process the information you provide in order to review your inquiry, respond to you, and conduct any necessary follow-up communication.
Depending on the specific form, the data processed may include your name, email address, telephone number, organization, and the content of your message.
Where the inquiry relates to a contract or steps taken prior to entering into a contract, the legal basis is Article 6(1)(b) GDPR.
For other inquiries, processing is based on Article 6(1)(f) GDPR and our legitimate interest in communicating effectively with persons who contact us.
Email and telephone
When you contact us by email or telephone, we process the data you voluntarily provide as well as the information necessary to review and follow up on your inquiry.
Contractual and pre-contractual communications are processed on the basis of Article 6(1)(b) GDPR. In other cases, processing is generally based on Article 6(1)(f) GDPR.
Standard email is generally not an end-to-end encrypted communication channel. We therefore recommend that particularly sensitive data not be sent by ordinary email unless appropriate additional protective measures have been taken.
TemplinTech also offers the option of communicating via WhatsApp. For users in the European Region, the service is provided by:
WhatsApp Ireland Limited
Merrion Road
Dublin 4
D04 X2K5
Ireland
If you choose to contact us via WhatsApp, we may process your telephone number, name or profile information, the content of your messages, files you send, and other information you voluntarily provide as part of the communication.
WhatsApp states that personal messages and calls are protected by end-to-end encryption. However, the service provider itself processes certain account, technical, and communication metadata in accordance with its own policies.
Where the communication relates to a contract or preparations for entering into a contract, our processing is based on Article 6(1)(b) GDPR.
In other cases, the legal basis is Article 6(1)(f) GDPR and our legitimate interest in providing a convenient and efficient communication channel.
Use of WhatsApp is optional. You may contact us by email or telephone instead.
Further information: https://www.whatsapp.com/legal/privacy-policy-eea/
7. User accounts and TemplinTech Connect
Customer accounts and access to TemplinTech Connect and other related digital services are or may be provided through go.templintech.com.
When registering for and managing an account, the following data may be processed, for example:
- first and last name;
- email address;
- username;
- company or organization;
- contact and billing information;
- selected services or subscriptions;
- information concerning orders and payments;
- status of contractual relationships;
- settings and actions required to manage the account.
Mandatory fields are limited to the data required to create the account, securely identify the user, or provide the relevant service.
Passwords are not stored as readable plain text but are protected using appropriate cryptographic mechanisms for credential storage.
Processing required for registration, account administration, and provision of contracted services is based on Article 6(1)(b) GDPR.
Data required to protect accounts, prevent and detect misuse, diagnose technical problems, and maintain system security may be processed on the basis of Article 6(1)(f) GDPR.
Where consent is required for a particular feature, information about the consent given and the time at which it was provided may be retained where necessary to demonstrate the lawfulness of the processing.
After an account is closed, associated data is deleted when it is no longer required unless statutory retention periods, ongoing contractual relationships, or the need to establish, exercise, or defend legal claims require longer retention.
8. TemplinTech Academy and Moodle
At academy.templintech.com, we operate TemplinTech Academy using the Moodle learning management platform.
Moodle is used to provide and manage online courses, educational content, user accounts, course enrollments, learning activities, and related functionality.
Personal data processed through TemplinTech Academy is used to provide, administer, secure, and document the relevant educational services.
TemplinTech Academy account
A user account is required to use certain courses and features within TemplinTech Academy.
Depending on the functionality used, the following data may be processed in particular:
- first and last name;
- email address;
- username;
- language and other account settings;
- course enrollment information;
- role and access permissions;
- information concerning creation and use of the account;
- technical data relating to login and use of the platform.
The data is processed to the extent necessary to create and administer the account and provide the selected educational services.
Where TemplinTech Academy is used as part of a contractual or pre-contractual service, the legal basis is Article 6(1)(b) GDPR.
Processing required to protect the platform, prevent misuse, and ensure information security may be based on Article 6(1)(f) GDPR.
Learning activity and progress
When participating in a course, Moodle may process information concerning course use and learning progress.
Depending on the structure and functionality of the specific course, this may include:
- course enrollment and participation;
- access to learning resources and activities;
- completion status of activities and courses;
- date and time of actions performed;
- submitted assignments, text, or files;
- answers to quizzes, assignments, or other forms of assessment;
- results, scores, and grades where used;
- feedback from an instructor or assessor;
- posts and interactions in forums or other communication features where enabled;
- information concerning course completion and issued confirmations or certificates where such functionality is used.
This data is processed to provide the relevant course, track learning progress, conduct the intended learning and assessment activities, document completion, and provide course-related services.
Where the course is provided as part of a contractual service, the primary legal basis is Article 6(1)(b) GDPR.
Technical and activity logs
Moodle records certain technical and user actions required for the operation, administration, security, and, where applicable, documentation of platform use.
These records may include, for example:
- user identifier;
- IP address;
- date and time of the action;
- type of action performed or resource accessed;
- information concerning the course, activity, or component in which the action occurred;
- other technical data required to trace system events.
Technical and activity logs may be used for administration and diagnostics, protection of user accounts and the platform, detection and prevention of misuse, and, where necessary for the relevant course, documentation of learning activities performed.
Where processing is necessary to provide and document the contracted educational service, the legal basis is Article 6(1)(b) GDPR.
Where the data is processed for technical and information security purposes, the legal basis is Article 6(1)(f) GDPR and our legitimate interest in protecting the platform and its users.
Assignments and uploaded files
Where a course permits the submission of assignments, documents, or other files, the submitted content is stored within the learning platform and processed for the performance and assessment of the relevant learning activity.
We recommend that users provide only information necessary for the relevant course and avoid including personal data relating to third parties or particularly sensitive information unless this is expressly required for the relevant assignment and an applicable legal basis exists.
Communication within the Academy
Where Moodle features for messages, forums, comments, or communication between participants and instructors are used, we process the relevant content and associated data required to provide the communication functionality.
The legal basis is generally Article 6(1)(b) GDPR where the communication forms part of the educational service, or Article 6(1)(f) GDPR where processing is necessary for the administration and normal operation of the platform.
Retention of data in TemplinTech Academy
Data within TemplinTech Academy is retained for as long as necessary to provide and administer the relevant course, manage the user account, and fulfill associated contractual and legal obligations.
Different categories of educational data may be subject to different retention periods.
Information required to demonstrate participation, course completion, achieved results, issued confirmations or certificates, or provision of a service may be retained for longer than ordinary technical data where this is necessary to document the education provided, comply with a legal obligation, or defend legal claims.
Once the relevant purpose no longer applies, the data is deleted or anonymized unless applicable law or another permissible legal basis requires further retention.
Rights concerning Academy data
The data subject rights described later in this Privacy Policy also apply to personal data processed through TemplinTech Academy.
Moodle provides technical mechanisms for identifying and exporting personal data relating to a specific user and for deleting such data where the applicable legal and technical conditions permit.
Requests concerning data in TemplinTech Academy may be sent to:
9. Customer, order, and contractual data
If you express an interest in a paid service, place an order, or become a TemplinTech customer, we process the data required to prepare, enter into, administer, and perform the contractual relationship.
This may include:
- identification and contact details;
- company or organizational information;
- address and billing details;
- information concerning ordered services, subscriptions, or digital content;
- contractual status;
- correspondence;
- information concerning payments made.
The primary legal basis is Article 6(1)(b) GDPR.
Where certain information must be retained to comply with accounting, tax, commercial, or other statutory requirements, processing is additionally based on Article 6(1)(c) GDPR.
If mandatory information required for performance of a contract is not provided, the relevant order or service may not be capable of being performed.
Services, subscriptions, and digital content
When you order a service, subscription, digital product, or digital content, we use the contractual data required to process the order, activate or provide access, perform the service, issue invoices, communicate with the customer, and provide support.
10. Payments via Stripe Checkout
TemplinTech uses Stripe Checkout for electronic payments.
When a payment process is initiated through Stripe Checkout, your browser establishes a connection with Stripe's payment infrastructure. Information required to perform and secure the payment is provided to and processed within Stripe's systems.
For the European Economic Area, depending on the specific payment product and the role involved in processing, different entities within the Stripe group may participate, including:
- Stripe Payments Europe, Limited;
- Stripe Technology Company, Limited;
- Stripe Technology Europe, Limited, where the relevant regulated payment services are provided.
These entities are established in Ireland. The specific Stripe entity and its role depend on the product used and the particular processing activity.
For a payment transaction, Stripe may process, for example:
- name;
- email address;
- billing address;
- payment method information;
- payment amount and currency;
- transaction and merchant information;
- IP address;
- browser and device information;
- information required to authenticate the payment, prevent fraud, and manage risk.
Depending on the specific operation, Stripe may act as a processor on our behalf and/or as an independent controller for certain purposes of its own, particularly in relation to security, fraud prevention, and compliance with financial and regulatory obligations.
Where payment card details are entered directly through Stripe Checkout, TemplinTech does not receive or store the full payment card number.
We receive the information required to determine the outcome of the payment, fulfill the order, issue invoices, process any applicable refund, and administer the contractual relationship.
Our processing required for payment and performance of the contract is based on Article 6(1)(b) GDPR.
Processing and retention required to comply with accounting, tax, or other legal obligations is based on Article 6(1)(c) GDPR.
Stripe may use its own cookies and comparable technologies on its pages and within its infrastructure in accordance with Stripe's policies, including for security, fraud prevention, and proper performance of the payment process.
Further information: https://stripe.com/privacy
Protection of payment traffic
Communication between the browser and the participating web and payment systems takes place through encrypted HTTPS/TLS connections.
This is intended to protect transmitted data against unauthorized reading or modification while in transit, within the technical capabilities of the cryptographic protocols used.
11. Newsletter
AcyMailing
We use AcyMailing to organize and send newsletters. The component is installed within TemplinTech's Joomla environment, and subscriber data is managed within the hosting infrastructure used by us.
An email address is required to subscribe. Where the form contains additional fields, such as a name, providing this information is voluntary unless expressly indicated otherwise.
Processing for newsletter purposes is based on your consent pursuant to Article 6(1)(a) GDPR.
To demonstrate registration and the consent provided, technical information concerning the registration and its confirmation may be retained, such as the date and time and, where the system records it for this purpose, the IP address.
Where a double opt-in procedure is used, the newsletter subscription is activated only after additional confirmation by the holder of the relevant email address.
Under the current configuration, TemplinTech does not use Google Analytics in connection with the newsletter and does not use AcyMailing to create individualized behavioral or marketing profiles of recipients.
You may unsubscribe from the newsletter at any time with effect for the future, for example by using the unsubscribe link included in each message.
After unsubscribing, the email address is removed from the active mailing list.
Where necessary, minimal information may be retained in a suppression list to ensure that the unsubscribe request is respected and that no further unsolicited newsletters are sent to the relevant address.
For this limited purpose, processing is based on Article 6(1)(f) GDPR and our legitimate interest in implementing and documenting the requested unsubscribe.
If the same email address is processed independently for another lawful purpose, such as an existing customer or contractual relationship, unsubscribing from the newsletter does not affect that separate processing.
12. Official social media profiles
TemplinTech maintains the following official profiles and channels:
LinkedIn: https://www.linkedin.com/company/templintech
Instagram: https://www.instagram.com/templintech
YouTube: https://www.youtube.com/@templintech
These platforms are linked from our websites using ordinary hyperlinks. During a standard visit to templintech.com, we do not automatically load embedded LinkedIn, Instagram, or YouTube components that establish a connection with the respective platform.
A connection with the relevant external platform occurs when you voluntarily follow the relevant link or use the social media platform itself.
When you visit a TemplinTech profile on a social media platform, the operator of the respective platform processes personal data in accordance with its own policies. We do not have full control over processing independently carried out by the platform for its own purposes.
When you interact directly with TemplinTech through a platform, for example by commenting or sending a message, we process the information available to us for communication, profile administration, and responding to your inquiry.
Our processing is generally based on Article 6(1)(f) GDPR and our legitimate interest in maintaining a professional presence and communicating through the relevant platform.
Where the interaction relates to a contract or pre-contractual relationship, Article 6(1)(b) GDPR applies.
For users and organizations in the European Union, European Economic Area, and Switzerland, the relevant LinkedIn entity is:
LinkedIn Ireland Unlimited Company
Gardner House, Wilton Plaza
Wilton Place
Dublin 2
Ireland
LinkedIn provides corporate page administrators with statistical information through Page Insights.
For the processing of personal data used to generate Page Insights concerning members in the European Economic Area or Switzerland, LinkedIn and the administrator of the relevant page act as joint controllers in accordance with LinkedIn's Page Insights Joint Controller Addendum.
The Page Insights provided by LinkedIn to TemplinTech are aggregated and do not allow us to associate the statistical metrics with a specific LinkedIn member.
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
Page Insights Joint Controller Addendum: https://www.linkedin.com/legal/l/page-joint-controller-addendum
For users in the European Region, Instagram is provided by:
Meta Platforms Ireland Limited
Merrion Road
Dublin 4
D04 X2K5
Ireland
When you visit or interact with our Instagram profile, Meta processes information in accordance with its own policies.
TemplinTech may have access to publicly posted information, comments, direct messages, reactions, and statistical information provided for the professional profile.
Further information: https://www.facebook.com/privacy/policy/
YouTube
YouTube is a Google service. For users in the European Economic Area, the relevant consumer services of Google are generally provided by Google Ireland Limited.
When you visit our YouTube channel or interact with content directly on YouTube, Google processes data in accordance with its own policies.
TemplinTech may receive information concerning public interactions and aggregated statistics relating to the channel.
This processing takes place within the YouTube platform. TemplinTech does not automatically load YouTube content on its own websites during a standard visit.
Google Privacy Policy: https://policies.google.com/privacy?hl=en
13. No advertising or behavioral tracking on our websites
TemplinTech does not use Google Analytics, Meta Pixel, or other systems on its own websites for advertising or marketing tracking, retargeting, or creating behavioral advertising profiles of visitors.
We do not use advertising or analytics cookies to monitor visitor behavior across different websites.
Technical testing of the current TemplinTech Academy configuration has not identified Google Analytics, Google Fonts, or Google reCAPTCHA as part of the platform's standard page loading.
The mere existence of a user account, customer profile, or learning profile in TemplinTech Connect or TemplinTech Academy does not in itself constitute behavioral profiling within the meaning of the GDPR.
14. Locally provided fonts and icons
Font Awesome
We use Font Awesome to display certain icons.
The required files are hosted locally within the infrastructure used by us. During standard loading of these files, no connection is established with servers operated by Fonticons, Inc., and no visitor IP address is transmitted to Fonticons solely as a result of using Font Awesome.
15. Protection of data in transit and information security
Our websites and platforms use HTTPS and SSL/TLS encryption.
This protects information transmitted between your browser and the relevant server against unauthorized reading or modification while in transit, within the technical capabilities of the cryptographic protocols used.
In addition to protecting data in transit, we apply appropriate technical and organizational measures taking into account the nature, scope, context, and risk of the relevant processing.
Despite the measures taken, absolute security of information systems cannot be guaranteed.
16. Automated decision-making and profiling
TemplinTech does not use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
We do not use personal data relating to visitors to our own websites for advertising or marketing-related behavioral profiling.
The administration of user, customer, or learning accounts and the retention of information required to provide a contracted service or course do not in themselves constitute automated profiling within the meaning of Article 22 GDPR.
17. Your rights regarding personal data
Subject to the conditions set out in the GDPR, you have the following rights:
- right of access to personal data processed concerning you – Article 15 GDPR;
- right to rectification of inaccurate or incomplete data – Article 16 GDPR;
- right to erasure where the statutory conditions are met – Article 17 GDPR;
- right to restriction of processing – Article 18 GDPR;
- right to data portability under the conditions of Article 20 GDPR;
- right to object to certain processing activities – Article 21 GDPR;
- right to withdraw consent at any time with effect for the future where processing is based on consent;
- right to lodge a complaint with a competent supervisory authority – Article 77 GDPR.
Withdrawal of consent
Where processing is based on your consent, you may withdraw that consent at any time.
Withdrawal takes effect for the future and does not affect the lawfulness of processing carried out before the withdrawal.
Objection to processing based on legitimate interests
Where we process your personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation.
Following a justified objection, we will cease the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defense of legal claims.
Direct marketing
Where personal data is processed by us for direct marketing purposes, you have the right to object to such processing at any time.
Once you exercise your right to object, we will no longer use the relevant personal data for direct marketing.
How to exercise your rights
You may submit a request or ask a question concerning data protection at:
Where necessary to protect personal data against unauthorized disclosure, we may request additional information required to verify the identity of the person exercising the relevant right.
18. Right to Lodge a Complaint with a Supervisory Authority
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
The supervisory authority responsible for our establishment in Baden-Württemberg is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW) .
The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
19. Unsolicited advertising communications
Contact details published in the Imprint and other legally required pages do not constitute consent to receive unsolicited advertising communications.
We object to the use of this information for sending unsolicited advertising or informational materials and reserve the right to take legally available action in the event of unlawful or abusive use of the relevant contact details.
20. Changes to this Privacy Policy
This Privacy Policy may be updated when our services, technical infrastructure, service providers, processing activities, or applicable legal requirements change.
The current version is published on templintech.com.
Additional privacy information may be provided for individual services or projects involving specific processing activities and will supplement this Privacy Policy.
Last updated: August 31, 2026