Nexstorya – Visa Services
Legal

Privacy Policy

Last updated: 19 August 2026 · pursuant to GDPR & BDSG

1. Controller

The controller responsible for data processing within the meaning of the GDPR is:

Nexstorya
Innstr. 69b
94032 Passau
Deutschland

E-Mail: welcome@nexstorya.de
Tel.: +49 8544 919727

2. Collection and Processing of Personal Data

We collect personal data only to the extent necessary for the provision of our services or where you have voluntarily provided it to us.

When you visit our website we automatically process the following data:

  • IP address (stored in server log files, automatically deleted after 14 days at the latest)
  • Date and time of access
  • Pages accessed and time spent
  • Browser type and operating system

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically error-free provision of the website).

3. Contact Form and Email Contact

When you contact us via the contact form or by email, we process the following data:

  • Name
  • Email address
  • Phone number (optional)
  • Message and enquiry details
  • Requested package (if specified)

Purpose: Processing your enquiry and getting in touch with you.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and your consent pursuant to Art. 6(1)(a) GDPR.

Storage period: Your enquiry data will be stored for the duration of the business relationship and for 3 years after its end, unless statutory retention obligations require a longer storage period.

Email dispatch: We use our own mail infrastructure to process your enquiry and send confirmation messages. Your data will not be passed on to third parties for advertising purposes.

Live chat: If you use our live chat, we process your chat messages, a session identifier, the page you are on and your IP address in order to answer your enquiry and prevent misuse. So that our team can reply promptly, messages are forwarded to our internal working group on the Telegram messenger service (Telegram FZ-LLC, Dubai, UAE). There is no EU adequacy decision for the UAE; the transfer is based on Art. 49(1)(b) GDPR. Please do not send identity documents or health data via the chat. Legal basis: Art. 6(1)(b) and (f) GDPR. We delete chat histories as soon as they are no longer needed to handle your enquiry, and after 36 months at the latest.

4. Online Booking and Payment Processing (Stripe)

For booking and payment processing we use the service Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (hereinafter Stripe).

When making a booking, Stripe processes the following data:

  • First and last name
  • Email address
  • Payment data (credit card data is processed exclusively by Stripe)
  • IP address and device information

Purpose: Processing payments and fraud prevention.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

Data transfer: Stripe may transfer data to the USA. The transfer is based on EU standard contractual clauses pursuant to Art. 46 GDPR.

For more information, please refer to Stripe's privacy policy: stripe.com/de/privacy

5. Recipients of Data

Your personal data will generally not be passed on to third parties, except where this is required by law or necessary for the fulfilment of the contract. In connection with the operation of our website, we use the following service providers:

  • Hosting provider (servers located in the EU)
  • Email provider IONOS SE, Berlin (processing on German servers)
  • Stripe Payments Europe, Ltd., Dublin (payment processing – see Section 4)
  • Telegram FZ-LLC, Dubai (UAE) — delivery of live chat messages to our team; see Section 3

All service providers are contractually obliged to comply with the GDPR (data processing agreements pursuant to Art. 28 GDPR).

6. Cookies, Tracking and Third-Party Services

Our website uses technically necessary cookies for the secure operation of the website (e.g. session management). These cookies are essential for operation and cannot be deactivated.

Google Analytics 4

With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies to analyse the use of our website (e.g. page views, time spent, scroll depth).

  • Purpose: analysis and optimisation of our website
  • Legal basis: Art. 6(1)(a) GDPR (your consent)
  • Data transfer: Google LLC, USA (standard contractual clauses pursuant to Art. 46 GDPR)
  • Storage period: 14 months (Google default)

Further information: policies.google.com/privacy

Google Ads (conversion measurement)

With your consent we use Google Ads conversion tracking, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It allows us to measure whether visitors reached our website via a Google ad and submitted an enquiry.

  • Purpose: measuring the effectiveness of our advertising
  • Legal basis: Art. 6 (1) (a) GDPR (your consent), § 25 (1) TDDDG
  • Data transfer: Google LLC, USA (EU standard contractual clauses pursuant to Art. 46 GDPR)

Google reCAPTCHA

To protect our forms against spam and automated abuse we use Google reCAPTCHA (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The service is only loaded once you interact with the contact form, and as part of a security check in case of suspicious access patterns. IP address, device and browser information as well as interaction behaviour may be transmitted to Google.

  • Purpose: protection against spam, bots and abusive requests
  • Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the security of our website)
  • Data transfer: Google LLC, USA (EU standard contractual clauses pursuant to Art. 46 GDPR)

ProvenExpert (Review Widget)

Our website displays ratings from the review service provider ProvenExpert (Expert Systems AG, Charlottenstraße 4, 10969 Berlin). The rating data is retrieved by our server — no data is transmitted from your browser to ProvenExpert when you visit our website. Only when you click the link to our ProvenExpert profile does the ProvenExpert privacy policy apply.

  • Purpose: display of verified customer reviews
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest)

Further information: provenexpert.com/datenschutzerklaerung

7. Personal Client Area (my.nexstorya.de)

After booking a consultation you receive access to our personal client area at my.nexstorya.de. What we process there is considerably more, and more sensitive, than on this website — in particular your answers to the intake questionnaire and the identity and education documents you upload. Those processing activities are described in the client area's own detailed privacy policy; in outline they are:

  • Account data: email address as login, password stored only as a hash, language, sign-in and sign-out times, optional two-factor authentication
  • Intake questionnaire: name, date of birth, nationality, place of residence, contact details, goals and language levels (deleted after 36 months)
  • Uploaded documents: e.g. passport, residence permit, certificates, proof of funding — stored encrypted (AES-256-GCM), scanned for malware, deleted after 24 months with advance notice
  • Client-area chat, and the time and IP address of security-relevant account events (security log, 12 months)
  • Your appointments and confirmed package purchases, shown there read-only from the booking system

In the client area you can export all of your stored data yourself at any time, and delete your account together with all documents yourself.

Purpose: Performance of your consulting contract by providing the tools you booked, and account security.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (IT security, prevention of misuse, logging of security-relevant events pursuant to point 9.7).

Storage period and deletion: The periods stated in the client area apply: questionnaire 36 months, uploaded documents 24 months (extendable), chat 36 months, security log 12 months. Account data is kept for as long as your account exists. Excluded is data subject to statutory retention obligations (e.g. invoicing and payment data under § 257 HGB / § 147 AO), which is kept separately (see point 4).

Full information about the client area: Client area privacy policy (my.nexstorya.de)

8. Your Rights as a Data Subject

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR): You may request information about the data stored about you.
  • Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR): You may request the deletion of your data, provided no retention obligations apply.
  • Right to restriction of processing (Art. 18 GDPR): You may under certain circumstances request a restriction of processing.
  • Right to data portability (Art. 20 GDPR): You have the right to receive your data in a commonly used format.
  • Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3) GDPR): You may withdraw any consent given at any time with effect for the future.

To exercise your rights, please contact: welcome@nexstorya.de

9. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The competent supervisory authority for Bavaria is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Deutschland
www.lda.bayern.de

10. Data Security

We use technical and organisational security measures to protect your data against accidental or deliberate manipulation, loss, destruction or access by unauthorised persons. In detail:

  • Transport encryption: All data transfers are made exclusively via HTTPS with TLS 1.2/1.3. Unencrypted HTTP requests are automatically redirected to HTTPS.
  • Encryption of stored booking data: Booking data (name, email, phone, appointment details) is stored in a database reachable only through the VPN described in point 9.3 and is not publicly accessible. The connection to it is encrypted (see point 9.1).
  • Access control: The administration area of our website (content management system, analytics dashboard, server administration) is accessible exclusively via an encrypted VPN (WireGuard); direct access from the internet is technically prevented there. The personal client area (my.nexstorya.de), by contrast, is deliberately reachable from the internet — it is meant for you — and is protected by password sign-in, optional two-factor authentication, lockouts after failed attempts and request rate limiting.
  • Consent documentation: For online bookings, the timestamp (ISO), IP address and the version of the Privacy Policy and T&Cs in force at the time are stored together with the booking. This serves as proof of consent pursuant to Art. 7(1) GDPR and § 312g BGB.
  • Automatic data deletion: Completed and cancelled bookings are automatically deleted from the system after 3 years, unless statutory retention obligations (e.g. under HGB, AO) require otherwise.
  • Security log: Security-relevant events (e.g. failed reCAPTCHA checks, exceeding request limits) are recorded in an internal log that is not publicly accessible.
  • Client area account and security log: Security-relevant actions in the personal client area (registration including acceptance of the T&Cs/Privacy Policy, sign-ins and sign-outs, password and 2FA changes, account deletion) are logged with timestamp and IP address for a maximum of 12 months and then automatically deleted. Legal basis: Art. 6(1)(f) GDPR.

11. Currency and Amendments to this Privacy Policy

This Privacy Policy applies in the version stated above. Due to the further development of our website or changes in legal or regulatory requirements, it may become necessary to amend it.