Privacy notice
Information on the processing of personal data on this website. The German version is decisive for legal interpretation.
1. Controller
Oleg Fallmann, trading as “EnergoInformatics”
Danziger Str. 9, 66121 Saarbrücken, Germany
Phone: +49 152 23157980
Email: info@energoinformatics.com
2. Scope and sources
This privacy notice applies to energoinformatics.com, the connected booking and administration backend at admin.energoinformatics.com and the forms and functions offered there. We usually obtain personal data directly from you when you visit the website, make a booking or payment, subscribe to the email course, submit a review or contact us. We also receive payment status and transaction identifiers from Stripe.
3. Hosting and server logs
The website, backend and database are hosted on infrastructure provided by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. Technical connection data may include IP address, date/time, requested URL, referrer, browser and operating system information, transferred data volume and status/error codes. Processing is based on Article 6(1)(f) GDPR for secure and stable operation, troubleshooting and abuse prevention. Logs are deleted or anonymised when no longer required, unless an incident or legal duty requires longer retention. IONOS privacy information.
4. Public API and back office
The public website retrieves offers, dates, prices, availability, books and published reviews through the backend API. Apart from technical connection data, no personal data are required unless you submit your own information. The back office is restricted to authorised users and uses a necessary protected session cookie. Administrative and security-relevant actions may be logged with user, time and IP address under Article 6(1)(f) GDPR for access protection, traceability and abuse prevention.
5. Language choice and local storage
If you choose a language manually, eiLanguageManual is stored locally in your browser until you delete it. It contains only the chosen language and is required for the language function you requested (§ 25(2) no. 2 TDDDG). It is not used for advertising or profiling.
6. First-party funnel and campaign measurement
On the Energy Ball landing page we measure page views and selected clicks within our own system, such as clicks to books, workshops, the intensive seminar and the main website. A random visitor identifier is transmitted for the page view but is not persistently stored in a cookie or Local Storage. Campaign information contained in the link, such as source, campaign and content identifier (UTM parameters), may also be stored server-side.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is privacy-conscious measurement of the effectiveness of our own information and marketing content so that we can improve landing pages, content and campaigns. We do not use an external analytics or advertising provider for this measurement and do not create cross-platform user profiles.
7. Workshop and seminar bookings
Depending on your entries, we process title, first and last name, email address, optional phone/company/address supplement, billing address and country, optional message, language and selected event, payment plan, booking number, amounts and booking/payment status, as well as the version and time of acceptance of participation/cancellation terms and withdrawal information. Processing necessary for booking and contract performance is based on Article 6(1)(b) GDPR; invoicing, accounting and tax records are additionally based on Article 6(1)(c) GDPR.
If you use the electronic cancellation or withdrawal function, we additionally process the type and time of the declaration, booking data used for identification, the calculated cancellation rate, refund and outstanding amounts, and the technical processing status with Stripe and Lexware. No user account is required. Secure booking links contain a non-guessable cryptographically signed booking reference.
8. Payments with Stripe
Online payments are processed through Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. You are redirected to Stripe Checkout. Email, booking number, event, amount, currency, language and necessary billing/technical information are provided to Stripe. Card or bank data are entered directly with Stripe and are not stored on our server. We store transaction, Checkout and Payment Intent identifiers, payment method, amount, currency and status for reconciliation, remaining payments and invoices. Legal bases are Article 6(1)(b) and, where required, Article 6(1)(c) GDPR. Stripe may process data outside the EEA using mechanisms it describes such as the EU-US Data Privacy Framework and Standard Contractual Clauses. Stripe privacy.
9. Invoicing with Lexware Office
Data needed for contacts, invoices and accounting are provided to Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany. This can include name, company, email, billing address, booking number, service, date, payment method, invoice amount, deposit, remaining amount and payment status. If a cancellation or withdrawal results in a refund, our system may also transmit a credit note linked to the original invoice to Lexware. Legal bases are Article 6(1)(b) and (c) GDPR. Lexware privacy and security.
10. Email delivery
Booking/payment confirmations, payment links, organisational information and invoices are sent by email. The configured mail provider processes name, email, booking/payment data and, where applicable, invoice PDFs. Production server and email services use IONOS unless another SMTP provider is configured. Legal bases are Article 6(1)(b), (c) and, for necessary technical delivery logs, (f) GDPR.
11. Energy Ball email course and newsletter
For the free email course we process your email address, optional first name, language, consent text and timestamp, confirmation/unsubscribe status and, where available, campaign source, campaign, content identifier and landing page. We also store the delivery status of scheduled emails. Registration uses double opt-in. The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw consent at any time for the future using the unsubscribe link. A minimal suppression and consent record may be retained where necessary to honour the withdrawal and demonstrate the prior consent.
12. Customer reviews and personal testimonials
When you submit a review through the website, we process the full name you enter, your chosen public name format, star rating, optional workshop/seminar reference, review text, language, consent timestamp and moderation status. Your entered full name remains visible in the protected back office even if you choose “Anonymous” or “first name + initial” for public display. Website reviews are manually checked and are never published automatically.
Publication of the review, chosen name display and translations is based on your consent under Article 6(1)(a) GDPR. If your voluntary text contains health information, religious or philosophical beliefs or other special categories of personal data, the consent request explicitly also covers publication and translation of those data under Article 9(2)(a) GDPR. Please do not include sensitive information about other people unless you are entitled to do so.
Testimonials, names, photographs or experience reports provided separately are likewise published and translated only on the basis of documented consent. Consent can be withdrawn at any time for the future. After withdrawal we stop further publication and delete the data and translations where no other legal ground or retention duty applies.
To protect the review form from automated abuse, an HMAC value is derived from the IP address or, as a fallback, browser information. No raw IP address is stored in the rate-limit table. This processing is based on Article 6(1)(f) GDPR for spam and abuse prevention. Rate-limit values are automatically removed after two days; maintenance runs hourly.
13. Review translation with Amazon Bedrock and Amazon Nova Micro
For automatic customer-review translations we use Amazon Bedrock from Amazon Web Services (AWS) with the Amazon Nova Micro model. Only the review text itself together with the source and target language is transmitted to Amazon Bedrock. The name stored separately in the back office, email address, booking data and other profile data are not intentionally included by the translation function. Personal data or special categories of personal data may nevertheless be contained in the review text written by you.
The transmission is used exclusively for the translation permitted by the person whose review is to be published and is based on the consent described in section 12. The technical configuration uses the EU Geo inference identifier eu.amazon.nova-micro-v1:0 with eu-central-1 (Frankfurt) as the default source region. According to AWS documentation, model inference with this EU Geo profile is routed within the designated European AWS Regions.
Before every automatic translation, our back office additionally checks the data-retention mode configured for the Amazon Bedrock account used. Translation is performed only when Zero Data Retention with mode none is active. AWS describes this mode as one in which request and response data are not written to durable AWS storage and are not shared with the model provider. Customer-data processing is covered by the AWS Data Processing Addendum (DPA), which AWS states is incorporated into the AWS Service Terms and applies automatically when customer data are processed. More information: AWS Privacy · AWS GDPR Center.
14. Google Maps – only after your choice
Google Maps by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland is loaded only after you select “Show map”. Google may then receive IP address, device/browser information, time and the map request and may use storage technologies. The legal basis is consent under Article 6(1)(a) GDPR and § 25(1) TDDDG. Google privacy.
15. External communication, social-media and shop links
The website contains external links including WhatsApp, Telegram, LinkedIn, Facebook, Instagram, YouTube, TikTok, X, VK, Google Maps and external bookshops. A normal link does not establish a connection to the provider merely when our page loads. Once you click it, you leave our site or open that service; from that point the provider processes data under its own responsibility. If you contact us through a messenger or social network, we process the communication to handle your request under Article 6(1)(b) GDPR for contractual/pre-contractual communication or otherwise Article 6(1)(f) GDPR. Email is available as an alternative.
16. Cookies, analytics and advertising
The public website does not use external analytics/marketing services, advertising trackers or externally hosted fonts. The only first-party campaign measurement is described in section 6. Functional storage consists of the language preference and, only in the protected back office, the necessary session cookie. Stripe and Google Maps may use their own cookies or similar technologies once their services are actively opened.
17. Recipients and processors
Recipients may include hosting and email providers, Stripe/payment parties, Lexware Office, Amazon Web Services (AWS) for an authorised customer-review translation through Amazon Bedrock, tax/legal advisers and authorities where required. Google, messenger, social-media and shop providers generally receive data through our site only after you actively use the external service. We do not sell personal data or disclose them for unrelated third-party advertising.
18. Transfers outside the EEA
Stripe, Google/YouTube, Meta, LinkedIn, WhatsApp, Telegram, TikTok, X, VK and their providers may process data outside the EU/EEA. Where required, providers describe safeguards such as adequacy decisions, the EU-US Data Privacy Framework or Standard Contractual Clauses.
For the AI inference used to translate customer reviews, we use only the EU Geo profile described above in Amazon Bedrock. AWS is a global provider. Where AWS transfers customer data to a third country in the course of providing its services, the AWS Data Processing Addendum states that, where applicable, the European Commission's Standard Contractual Clauses are used as a transfer mechanism unless another recognised transfer mechanism applies.
19. Retention
- Enquiries: until resolved and thereafter only as required for documentation or legal claims.
- Booking/payment/contract data: for contract performance and applicable limitation and statutory retention periods.
- Invoices/accounting records: generally eight years under German tax rules; business correspondence may be retained for six years.
- Backups: until routine overwriting unless longer retention is required.
- Language preference: until you delete it in the browser.
- Newsletter: until withdrawal/unsubscription; necessary suppression and proof records may be kept longer where required.
- Funnel events: only while pseudonymous campaign events are needed for effectiveness measurement and optimisation, then deleted or anonymised.
- Reviews: published reviews and translations until consent is withdrawn or publication is no longer needed. Unpublished submissions remain until moderation and thereafter only as long as necessary for questions, proof of consent or legal claims.
- Review rate limit: HMAC values are automatically cleaned up after two days; maintenance runs hourly.
20. Your rights and withdrawal of consent
Subject to the GDPR, you have rights including access, rectification, erasure, restriction, portability and objection to processing based on legitimate interests. Consent – for example for newsletters, Google Maps or publication of a review – may be withdrawn at any time for the future without affecting prior lawful processing. Contact info@energoinformatics.com.
21. Complaint
You may lodge a complaint with a data protection supervisory authority. For our establishment, in particular: Unabhängiges Datenschutzzentrum Saarland, Fritz-Dobisch-Str. 12, 66111 Saarbrücken, Germany, poststelle@datenschutz.saarland.de.
22. Automated decisions
We do not make solely automated decisions with legal or similarly significant effects within Article 22 GDPR. Stripe may carry out its own automated security and fraud checks. Website reviews are checked by a person before publication.
23. Security
Transmission is protected by TLS/HTTPS. Back-office access is authenticated and role-based. Databases, invoice files and backups are protected within the server environment. No internet transmission can be guaranteed absolutely secure.
24. Version
Last updated: 14 August 2026. This English translation is provided for convenience; the German version is decisive for legal interpretation.
Ready for the next step?
Write to me about a workshop, the intensive seminar, the EnergoInfoClub, or for a short recommendation on which entry point suits you.