Privacy Policy
Last updated: 30 July 2026 · pursuant to GDPR & BDSG
1. Controller
The controller responsible for data processing within the meaning of the GDPR is:
NexstoryaInnstr. 69b
94032 Passau
Deutschland
E-Mail: welcome@nexstorya.de
Tel.: +49 8544 919727
2. Collection and Processing of Personal Data
We collect personal data only to the extent necessary for the provision of our services or where you have voluntarily provided it to us.
When you visit our website we automatically process the following data:
- IP address (stored in server log files, automatically deleted after 14 days at the latest)
- Date and time of access
- Pages accessed and time spent
- Browser type and operating system
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically error-free provision of the website).
3. Contact Form and Email Contact
When you contact us via the contact form or by email, we process the following data:
- Name
- Email address
- Phone number (optional)
- Message and enquiry details
- Requested package (if specified)
Purpose: Processing your enquiry and getting in touch with you.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and your consent pursuant to Art. 6(1)(a) GDPR.
Storage period: Your enquiry data will be stored for the duration of the business relationship and for 3 years after its end, unless statutory retention obligations require a longer storage period.
Email dispatch: We use our own mail infrastructure to process your enquiry and send confirmation messages. Your data will not be passed on to third parties for advertising purposes.
Live chat: If you use our live chat, we process your chat messages, a session identifier, the page you visited and your IP address in order to answer your enquiry and prevent abuse. Legal basis: Art. 6 (1) (b) and (f) GDPR. Chat histories are deleted as soon as they are no longer required to handle your enquiry.
4. Online Booking and Payment Processing (Stripe)
For booking and payment processing we use the service Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (hereinafter Stripe).
When making a booking, Stripe processes the following data:
- First and last name
- Email address
- Payment data (credit card data is processed exclusively by Stripe)
- IP address and device information
Purpose: Processing payments and fraud prevention.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
Data transfer: Stripe may transfer data to the USA. The transfer is based on EU standard contractual clauses pursuant to Art. 46 GDPR.
For more information, please refer to Stripe's privacy policy: stripe.com/de/privacy
5. Recipients of Data
Your personal data will generally not be passed on to third parties, except where this is required by law or necessary for the fulfilment of the contract. In connection with the operation of our website, we use the following service providers:
- Hosting provider (servers located in the EU)
- Email provider IONOS SE, Berlin (processing on German servers)
- Stripe Payments Europe, Ltd., Dublin (payment processing – see Section 4)
All service providers are contractually obliged to comply with the GDPR (data processing agreements pursuant to Art. 28 GDPR).
6. Cookies, Tracking and Third-Party Services
Our website uses technically necessary cookies for the secure operation of the website (e.g. session management). These cookies are essential for operation and cannot be deactivated.
Google Analytics 4
With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies to analyse the use of our website (e.g. page views, time spent, scroll depth).
- Purpose: analysis and optimisation of our website
- Legal basis: Art. 6(1)(a) GDPR (your consent)
- Data transfer: Google LLC, USA (standard contractual clauses pursuant to Art. 46 GDPR)
- Storage period: 14 months (Google default)
Further information: policies.google.com/privacy
Google Ads (conversion measurement)
With your consent we use Google Ads conversion tracking, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It allows us to measure whether visitors reached our website via a Google ad and submitted an enquiry.
- Purpose: measuring the effectiveness of our advertising
- Legal basis: Art. 6 (1) (a) GDPR (your consent), § 25 (1) TDDDG
- Data transfer: Google LLC, USA (EU standard contractual clauses pursuant to Art. 46 GDPR)
Google reCAPTCHA
To protect our forms against spam and automated abuse we use Google reCAPTCHA (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The service is only loaded once you interact with the contact form, and as part of a security check in case of suspicious access patterns. IP address, device and browser information as well as interaction behaviour may be transmitted to Google.
- Purpose: protection against spam, bots and abusive requests
- Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the security of our website)
- Data transfer: Google LLC, USA (EU standard contractual clauses pursuant to Art. 46 GDPR)
ProvenExpert (Review Widget)
Our website displays ratings from the review service provider ProvenExpert (Expert Systems AG, Charlottenstraße 4, 10969 Berlin). The rating data is retrieved by our server — no data is transmitted from your browser to ProvenExpert when you visit our website. Only when you click the link to our ProvenExpert profile does the ProvenExpert privacy policy apply.
- Purpose: display of verified customer reviews
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
Further information: provenexpert.com/datenschutzerklaerung
7. Personal Client Area (my.nexstorya.de)
If, after a booked consultation, you are given access to our personal client area (my.nexstorya.de), we additionally process the following data there to provide you with the tools enabled for your account (e.g. University Finder, Cost of Living Calculator, Recognition Assistant, Kita Finder, Chat):
- Email address (used as login) and a password stored only as a hash
- Preferred language and account/login activity (e.g. time of last login)
- Timestamp and IP address of registration, and the version of the T&Cs and Privacy Policy accepted at that time
- Optionally, a secret key for two-factor authentication (2FA), if you enable it
- The access rights assigned to you (which tools are enabled for your account)
If you use the chat in the client area, we process your messages. If your IP address matches a recent conversation in our website's live chat, your client-area chat is automatically linked to that existing conversation so our team doesn't lose context; otherwise a new, independent conversation begins.
Purpose: Performance of the consultation contract in place with you, by providing the booked tools, and account security.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (IT security, abuse prevention, logging of security-relevant events per point 9.7).
Storage period and deletion: Account data is stored for as long as your account exists. You may remove your account and all associated data at any time yourself under "Settings → Delete account"; for security reasons this requires confirming a code sent to your email address. Excluded are data we are legally required to retain (e.g. invoice and payment data under § 257 HGB / § 147 AO), which is kept separately in the booking system (see point 4) and is not part of the client area.
8. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR): You may request information about the data stored about you.
- Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You may request the deletion of your data, provided no retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR): You may under certain circumstances request a restriction of processing.
- Right to data portability (Art. 20 GDPR): You have the right to receive your data in a commonly used format.
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests.
- Withdrawal of consent (Art. 7(3) GDPR): You may withdraw any consent given at any time with effect for the future.
To exercise your rights, please contact: welcome@nexstorya.de
9. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The competent supervisory authority for Bavaria is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)Promenade 18
91522 Ansbach
Deutschland
www.lda.bayern.de
10. Data Security
We use technical and organisational security measures to protect your data against accidental or deliberate manipulation, loss, destruction or access by unauthorised persons. In detail:
- Transport encryption: All data transfers are made exclusively via HTTPS with TLS 1.2/1.3. Unencrypted HTTP requests are automatically redirected to HTTPS.
- Encryption of stored booking data: Booking data (name, email, phone, appointment details) is stored in a database reachable only through the VPN described in point 9.3 and is not publicly accessible. The connection to it is encrypted (see point 9.1).
- Access control: The administration area is accessible exclusively via an encrypted VPN (WireGuard). Direct access from the internet is technically prevented.
- Consent documentation: For online bookings, the timestamp (ISO), IP address and the version of the Privacy Policy and T&Cs in force at the time are stored together with the booking. This serves as proof of consent pursuant to Art. 7(1) GDPR and § 312g BGB.
- Automatic data deletion: Completed and cancelled bookings are automatically deleted from the system after 3 years, unless statutory retention obligations (e.g. under HGB, AO) require otherwise.
- Security log: Security-relevant events (e.g. failed reCAPTCHA checks, exceeding request limits) are recorded in an internal log that is not publicly accessible.
- Client area account and security log: Security-relevant actions in the personal client area (registration including acceptance of the T&Cs/Privacy Policy, sign-ins and sign-outs, password and 2FA changes, account deletion) are logged with timestamp and IP address for a maximum of 12 months and then automatically deleted. Legal basis: Art. 6(1)(f) GDPR.
11. Currency and Amendments to this Privacy Policy
This Privacy Policy is currently valid and was last updated in May 2026. Due to the further development of our website or due to changes in legal or regulatory requirements, it may be necessary to amend this Privacy Policy.
