Skip to content
Back to home page

Privacy policy

Information pursuant to Art. 13 and 14 GDPR

This is a translation for convenience. Projection-X is based in Germany; the German version of these terms is the binding one. Questions? Write to us via the support page.

Controller

Nicolas BauerPaullinerstr. 179848 Bonndorf im SchwarzwaldDeutschlandE-Mail: connect@projection-x.de

A data protection officer has not been appointed, as this is not required by law; please address enquiries directly to the address given above.

What happens when you merely visit

When you call up the site, your browser transmits technically necessary data to our hosting provider: IP address, time, the address called up, and browser and operating system identifiers. This is necessary in order to operate the site (Art. 6(1)(f) GDPR — our legitimate interest in a functioning, secure service). This data is not combined with other sources.

Account and sign-in

For an account we need your email address and a password; you may voluntarily provide a name, a short description, a profile picture and a location. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).

For accounts with elevated rights, and on request for all others, we send a six-digit code by email when you sign in. We log sign-in times and security events in order to detect misuse.

Instead of waiting for the code you may register a passkey. For this we store your device’s public key, an identifier, a signature counter, the name you choose yourself and the times of creation and last use. The private key never leaves your device and never reaches our servers; we do not process biometric data — your fingerprint or face stays on your device. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR). You can remove a passkey in your settings at any time; changing your password removes every passkey on your account.

Purchases, licences and tokens

When you make a purchase we process order data, the payment status and the entitlements arising from it. The payment itself is handled by Stripe; full card details do not reach our servers. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and, for the retention of accounting records, compliance with obligations under tax law (Art. 6(1)(c) GDPR).

Licence keys are bound to the devices on which you activate them. For this purpose we store a device identifier and the time of activation — necessary in order to enforce the agreed number of devices.

Purchase recommendations in the cart

When there are products in your cart, we show further products under the heading “Customers also bought” that other customers bought together with one of these products. To do this we evaluate the orders stored with us in aggregated form: we count how many different customer accounts bought a product in your cart and another product. Only paid and non-refunded purchases are taken into account; test purchases, credits, gifts and accounts of our team do not count.

A product only appears there once at least three different people have bought it together with the product concerned. Names, email addresses or other details of these people are neither read nor shown; who bought a product cannot be seen from the recommendation. We do not store the result permanently but recalculate it regularly; interim results remain in our server’s working memory for at most one hour.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to show you products that suit your purchase. Using your order data for this purpose is compatible with the original purpose (processing your purchase) (Art. 6(4) GDPR): only counts are formed, the threshold of three people prevents conclusions about individual purchases, and no profiles about you are created.

You may object to your purchases being taken into account at any time (Art. 21 GDPR), informally by email to the address given above. Your purchases will then no longer be counted from that point on.

Trial versions (launcher)

If you start the 60-minute trial of an effect in the launcher, we store a device identifier permanently so that the trial runs only once per device. The legal basis is our legitimate interest in limiting the free trial version to one run per device (Art. 6(1)(f) GDPR).

Coaching: live sessions and recordings

One-to-one coaching sessions take place as a video call directly on the platform (camera, microphone and, if you wish, screen sharing). Your browser asks for the permissions itself; without your permission nothing is transmitted. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). Files that you share in a session are accessible only to you and the coach.

For as long as the platform’s own video room has not been enabled, a session may alternatively take place via an external meeting service — you will receive the link in advance; the privacy policy of the provider concerned then additionally applies to that call. No recording takes place by this route.

A recording of the session (picture, sound and shared screen) is made solely where you have expressly consented beforehand (Art. 6(1)(a) GDPR) — we ask for that consent before the session, and you may change it at any time up to the start of a recording. The recording is stored privately (Cloudflare R2), can be accessed only by you and the coach and is streamed exclusively on the platform — it is not made publicly available. If you decline, the session simply takes place without a recording.

Community

Posts, comments, likes and the indication of whom you follow are visible to signed-in users. Your profile is public only if you have set it to be; the display of the effects you have purchased and of the courses you are taking can also be switched off individually.

If you place yourself on the creator globe, we store rounded coordinates (accurate to about 11 kilometres) and a place designation made up of town and country — deliberately not your address. You can remove yourself again at any time.

Posts by other users may embed images from third-party servers. When you view such a post, your browser retrieves the image directly from the server concerned — that server thereby sees your IP address and browser identifier. Which servers this applies to is determined by the person who wrote the post.

Reviews

You can write a review of the launcher and of products you have bought or hold a valid licence for. For this we store the star rating, an optional title, your text, the time of creation and of the last change, the kind of verification (purchase, licence or paired launcher) and the link to your account.

You can also review courses you have bought and paid for, and the coaching once you have booked and paid for a coaching session. In both cases we store “purchase” as the kind of verification.

Before publishing and on every change, we use data we already hold (orders, unlocks and licences, or launcher sign-ins and pairings) to check whether your account owns the product or has paired the launcher. Only the result of this check is stored.

For a course we use your orders and unlocks to check whether your account bought and paid for exactly this course. Single modules or episodes, a subscription or an unlock by us are not enough. For the coaching we check whether your account has booked and paid for a coaching session.

Your review is visible to every visitor of the page concerned — with star rating, title, text, date, the note “edited” after a change, the kind of verification and your display name. As the name we show your display name or username; if your profile is not public, only your initials; if no name is set, “Verified user”. Your email address never appears. You see which name will appear before submitting and can change it in the settings. From the reviews we calculate the average rating, which may appear on the page and in structured data for search engines.

We also show the average rating and the number of reviews on the tiles of the overviews in the shop and for courses. If you sort the shop by “Top rated”, we order the products by these two values. For this we only use the star ratings that are stored anyway.

We also show the most recently written reviews on the start page: with star rating, title, an excerpt of the text, date, the kind of verification and your display name, and a link to the page of the reviewed item.

The legal basis for storing and publishing is Art. 6(1)(b) GDPR (you use a platform feature you choose yourself). We base the authenticity check and the review of reported reviews on Art. 6(1)(f) GDPR; our legitimate interest is to show only genuine customer reviews and to remove illegal content. The statement of reasons we send you when deleting a review is based on Art. 6(1)(c) GDPR in conjunction with Art. 17 DSA.

You can edit or delete your review at any time while the reviewed product is offered in the shop. Deleting your account also deletes your reviews. If we take a product out of the shop, we stop showing its reviews; they remain stored until you delete your account or ask us to delete them, and they reappear if the product is offered again. If a review breaks our review rules, we delete it completely and tell you the reason by email. For such a deletion we keep a log entry (time, reason, star rating, kind of verification and internal IDs, not the text) as evidence of our decision.

The same applies to courses: while a course is offered, you can edit or delete your review. If we take a course off the offer, we stop showing its reviews; they remain stored as described and reappear if the course is offered again.

Where we rely on Art. 6(1)(f) GDPR, you can object (Art. 21 GDPR). Since a review cannot be published without the check, an objection will usually lead to the review being deleted.

Emails

Contract-related messages (purchase confirmation, licence key, password, support) are sent by us on the basis of performance of the contract. You receive notifications about posts by people you follow only because you follow those people — the legal bases are the performance of the user agreement and our legitimate interest in a functioning community (Art. 6(1)(b) and (f) GDPR). Every such email contains a way to unsubscribe, and you can change the setting at any time.

We send a newsletter solely after express consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.

Cookies and local storage

We use technically necessary cookies for signing in (session), for your choice of language and for your choice of navigation layout (sidebar or header bar, entry “px_nav”). They are required in order to operate the service and do not require consent (Section 25(2) TDDDG (German Digital Services Data Protection Act)).

Before launch and when you register, four further necessary cookies are added. “px_hub” lets team members and testers into the hub before launch; it is valid for 12 hours, signed and holds the account ID. “px_ref” remembers the invitation code you register with until your account is created; “px_absicht” remembers that you chose to register with your Patreon email. Both last only for the session and are created only when you click “Register” or that option; opening an invitation link sets no cookie. “px_google_start” remembers for up to ten minutes that the security check was passed before signing up with Google; it contains no personal data and is deleted after returning from Google.

We store your choice in the cookie dialog for 12 months in the cookie “px_consent”. It holds no identifier, only the version, a checksum of the texts, the day of your decision and your choice — so that we can prove what you consented to (Art. 7(1) GDPR). You can change your choice at any time via “Cookie settings”.

Only after your decision in the cookie dialog do we store, in your browser’s local storage, settings you make yourself (for example display and subtitles), your notes on lessons and your cart (at most 30 days after the last change). Which notices you have dismissed and the progress of the initial tour (entry “px_wt_step”) are kept beyond the session only if you allow this in the cookie dialog. Likewise, only with your permission do we set up a service worker that makes the hub installable as an app and shows an offline page without a connection. These entries do not leave your device; you only transmit the cart when you go to checkout.

We deliver files from our storage — images, videos and uploaded media — via our own domain. Only when you download purchased files or files shared in coaching, and when you upload files in coaching or in the operator area, does your browser connect directly to our storage provider Cloudflare (R2) via a time-limited address; Cloudflare then sees your IP address.

The sounds of the card pick in Early Access come from our own server (hosted by Vercel). They load only after your click on the card page and only while the “Sound” switch is on; nothing is stored on your device in the process.

Anything beyond that — in particular the loading of external videos — happens only with your consent, which you give via the cookie dialog and can change at any time. We do not use any counting, analytics or advertising services.

Recipients and processors

We use the following service providers. In so far as they process personal data on our behalf, we conclude processing agreements with them pursuant to Art. 28 GDPR. We keep a record of the status of those agreements internally; on request we will provide information on an individual service provider.

Vercel

Vercel Inc., USA

Operation and delivery of the website (hosting).

Data: IP address, date and time, the address accessed, browser identifier.

Supabase

Supabase Inc., USA — database in the EU (Ireland)

Accounts, sign-in and database.

Data: Email address, encrypted password, sign-in times, your content.

Google (sign-in)

Google Ireland Ltd., Ireland / Google LLC, USA

Only if you choose “Continue with Google”: sign-in via your Google account. We do not load or display your Google profile picture.

Data: Email address and name from your Google account. We do not take the address of your profile picture, which Google also transmits, into your profile.

Stripe

Stripe Payments Europe Ltd., Ireland

Payment processing, invoices, subscriptions.

Data: Name, email, payment data, billing address, purchase history.

Cloudflare R2

Cloudflare Inc., USA

Storage of files: effects, images, uploaded media.

Data: The files themselves, access times.

Cloudflare Turnstile

Cloudflare Inc., USA

Protection against automated requests in forms, for example when registering and signing in, when resetting your password, for support, coaching and newsletter requests, community posts and the card pick in Early Access. The script loads only in forms that need it and only after your decision in the cookie dialog; according to Cloudflare, it sets no cookies on this website. The legal basis is our legitimate interest in protection against abuse (Art. 6(1)(f) GDPR); access to your device is strictly necessary for this (Section 25(2) no. 2 TDDDG). To improve its bot detection, Cloudflare also processes the data as an independent controller.

Data: IP address and the browser and device characteristics that the script collects in order to tell people from programs.

Resend

Resend Inc., USA

Sending of emails (sign-in, licence keys, support, notifications).

Data: Email address, content of the message, delivery status.

Mux

Mux Inc., USA

Delivery of the course and preview videos. They load only once you allow Mux in the cookie dialog or at the video’s placeholder; you can withdraw this at any time via “Cookie settings”.

Data: IP address, playback times, device type.

LiveKit

LiveKit Inc., USA — media server in the EU region chosen by us

Live video room for one-to-one coaching sessions (camera, microphone, screen sharing) — only if you join a session. The connection is encrypted; a recording takes place solely after your express consent.

Data: IP address, connection data, and during the session picture and sound streams.

YouTube

Google Ireland Ltd., Ireland / Google LLC, USA

Embedded videos in enhanced privacy mode (youtube-nocookie.com). The player and thumbnails (i.ytimg.com, img.youtube.com) load only once you allow YouTube in the cookie dialog or at the placeholder; a click on “Play” does not replace this permission.

Data: IP address, device data, playback behaviour (by YouTube).

Vimeo

Vimeo Inc., USA

Embedded videos with a “Do Not Track” parameter (player.vimeo.com). The player and thumbnails (vimeocdn.com) load only once you allow Vimeo in the cookie dialog or at the placeholder; a click on “Play” does not replace this permission.

Data: IP address, device data, playback behaviour (by Vimeo).

Instagram (Meta)

Meta Platforms Ireland Ltd., Ireland / Meta Platforms Inc., USA

Instagram posts and reels embedded in community posts. The thumbnail and the post load only once you allow Instagram in the cookie dialog or at the placeholder, and the post itself even then only on your click; before that there is only a placeholder from us. For the embedding, we and Meta are joint controllers (Art. 26 GDPR).

Data: IP address, device data, playback and interaction behaviour (by Meta).

VirusTotal

Chronicle LLC (Google), USA

Malware scanning of the download files we provide (plugins) before they are delivered. Only our own files are scanned — no user data.

Data: Only the program files themselves and their checksums.

OpenStreetMap (Nominatim)

OpenStreetMap Foundation, United Kingdom

Resolution of the location you enter yourself for the creator globe.

Data: Only the search term entered — the request is made by our server, your IP address is not passed on.

Google Maps Geocoding

Google Ireland Ltd., Ireland / Google LLC, USA

Resolution of the location you enter yourself for the creator globe — as an alternative to OpenStreetMap.

Data: Only the search term entered — the request is made by our server, your IP address is not passed on.

In so far as service providers process data outside the EU — in particular in the USA — we base the transfer for each service on the adequacy decision on the EU-U.S. Data Privacy Framework (DPF) and/or on the EU standard contractual clauses (SCC): for Vercel, Supabase, Google (sign-in, YouTube, Maps Geocoding, VirusTotal), Stripe, Cloudflare, Resend, Mux, LiveKit, Vimeo and Meta (Instagram), DPF and/or SCC apply in each case under the data processing agreement (DPA) which the provider concerned offers to its customers. Which of the two mechanisms applies in an individual case, and where the provider publishes the safeguards, we will tell you on request in relation to an individual service provider.

Retention periods

We store account data for as long as your account exists. After deletion we remove it — with two exceptions, which we name here expressly instead of hiding them behind a general formula.

  • Statutory retention obligations: we keep invoices and accounting records for ten years (Section 147 AO (German Fiscal Code)). This also includes the token bookings and any remaining token balance: purchased tokens are credit paid in advance and are carried as a liability in the accounts; the booking lines bear the payment or order number to which they belong. Records of purchase consent, of account deletion and of the account recovery route are kept by us for three years (Section 195 BGB (German Civil Code)), as is the record of your newsletter consent.
  • Prevention of misuse: the identifier of the device on which a free trial has been used up is kept by us permanently — otherwise the same trial could be repeated at will with a new account. Likewise a deletion marker for your account, so that it cannot be created again via the launcher. If you take part in the referral programme, an outstanding, uncollected chargeback debt together with a blocking flag also remains; the note we have written on the matter falls away upon deletion. These are technical identifiers and amounts, not master data; your name and your address are not among them.

We keep records of consent for the newsletter for as long as the consent applies and, in addition, for three years as evidence (Section 195 BGB); after that we delete them.

We delete technical logs automatically after fixed periods: security events after 180 days — with the exception of records of purchase consent, of account deletion and of the account recovery route, which we keep for three years for the defence of legal claims (Section 195 BGB) —, licence-check and download logs after 90 days, used sign-in codes after 30 days. The cache of the location search (search terms only, no personal data) is cleared after 90 days.

In addition: we delete unconfirmed newsletter sign-ups after 30 days, records relating to cancellation procedures after 3 years, coaching recordings after 12 months, and IP addresses from licence events and activations after 90 days.

Purchase recommendations: no separate storage; interim results for at most one hour in the server’s working memory.

Reviews: until you delete them, delete your account or we remove them for breaking the rules — also when the product is no longer in the shop (hidden, but stored); the log entry about such a removal remains as evidence (see “Reviews”).

Your rights

You have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). Consent you have given may be withdrawn at any time with effect for the future.

Please contact connect@projection-x.de for this purpose. Irrespective of this, you have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.

Clicks on product links in the community

Posts in the community may refer to products from our range. If you call up such a link, we log your account, the post, the item and the time.

Purpose: to establish whether a later purchase came about via a community post, and to settle the share due to the person who wrote it. Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement including the referral programme) and Art. 6(1)(f) GDPR (legitimate interest in detecting abusive settlement).

Retention period: clicks not followed by a purchase are deleted after 45 days. If a click leads to a share, it is retained as part of the settlement record for as long as retention periods under commercial and tax law are running.

No cookies are set in the process and no information is read out from your device. Attribution takes place exclusively via your signed-in account; without signing in, nothing is logged.

Last updated: 3 October 2026 · Version 1.11.0

Cancel contracts here

Cookies and content

What this site may load

What is necessary always runs: sign-in, language, cart and the protection of forms. Everything else is your choice.

  • Remember hints: dismissed hints and your step in the tour stay stored beyond the session.
  • App & offline: the hub becomes installable as an app and shows an offline page without a connection.
  • Videos & 3D: moving images and the 3D stage from our own server. This is not consent but your preference on data usage.
  • External media: videos and images from Mux, YouTube, Vimeo and Instagram. 3 further controllers (Google, Vimeo, Meta) receive data such as your IP address, also in the USA (EU-US Data Privacy Framework).

Both buttons take you to the site. You can change your choice at any time at the bottom of every page under “Cookie settings”. Withdrawal takes effect from then on, not retroactively.

ImprintPrivacyCancel contracts here

All categories and providers in detail

Everything is off by default. A switch takes effect only with “Save choice”.

Necessary

Always on

Without these entries, sign-in, cart, checkout and security do not work. They cannot be switched off.

Entries (22)
  • sb-<ref>-auth-token

    Type
    Cookie
    Purpose
    Keeps you signed in. Only created when you sign in.
    Duration
    up to 400 days (default of the sign-in library); ends when you sign out
    Provider
    Projection-X with Supabase (processor)
    Role
    Processor
    Third country
    USA possible (Supabase Inc.; EU-US Data Privacy Framework, standard contractual clauses)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • sb-<ref>-auth-token-code-verifier

    Type
    Cookie
    Purpose
    Secures the return from Google sign-in. Only created after “Sign in with Google”.
    Duration
    short, until sign-in is complete
    Provider
    Projection-X with Supabase (processor)
    Role
    Processor
    Third country
    USA possible (Supabase Inc.; EU-US Data Privacy Framework, standard contractual clauses)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • px2fa_ok

    Type
    Cookie
    Purpose
    Remembers that the second factor was confirmed on this device.
    Duration
    30 days
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR (protection against abuse)
  • pxag_ok

    Type
    Cookie
    Purpose
    Remembers the passed extra check for the admin area (team only).
    Duration
    12 hours
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR (protection against abuse)
  • px_next

    Type
    Cookie
    Purpose
    Remembers your destination when you sign in with Google, so you land there afterwards.
    Duration
    10 minutes
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • px_aktion_<id>

    Type
    Cookie
    Purpose
    Remembers that you entered the access word of a promotion.
    Duration
    until you close the browser
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • px_hub

    Type
    Cookie
    Purpose
    Lets team members and testers into the hub before launch (after approval or the correct tester PIN). Signed, holds the account ID and only valid for that account; only created then.
    Duration
    12 hours
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR (access protection)
  • px_absicht

    Type
    Cookie
    Purpose
    Remembers that you chose “With Patreon” when registering, so your new account is assigned to it. Not a proof of entitlement. Only created when you click.
    Duration
    Session (until you close the browser); only created when you click and deleted once your account is created or you continue without Patreon
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • px_ref

    Type
    Cookie
    Purpose
    Remembers the invitation code you register with until your account is created. Only created when you click “Register”; opening an invitation link sets no cookie.
    Duration
    Session (until you close the browser); only created when you click
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • px_patreon_state

    Type
    Cookie
    Purpose
    Operator area only: secures connecting the operator’s Patreon account (signed check value with the operator’s account ID). Only valid on the way back from Patreon.
    Duration
    10 minutes
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR (protection against abuse)
  • px_google_start

    Type
    Cookie
    Purpose
    Remembers for up to ten minutes that the security check was passed before signing up with Google. Only needed for new accounts; deleted after returning from Google. Contains no personal data.
    Duration
    10 minutes
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR (protection against abuse)
  • px-cart

    Type
    Browser storage
    Purpose
    Your cart, only the product identifiers. Only after “Add to cart”.
    Duration
    at most 30 days
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • px-cart-checkout

    Type
    Browser storage
    Purpose
    Remembers the items that just went to checkout until you return.
    Duration
    until you close the tab
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • px-lesson-notes:*

    Type
    Browser storage
    Purpose
    Your own notes on a lesson. Only when you write them.
    Duration
    until you delete them
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • Page structure and images

    Type
    Service
    Purpose
    Page structure, fonts and images of this website from our own server.
    Duration
    usual browser caching
    Provider
    Projection-X, hosted by Vercel (processor)
    Role
    own service
    Third country
    USA (Vercel Inc.; EU-US Data Privacy Framework)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • Card pick sounds

    Type
    Service
    Purpose
    Short sounds of the card pick from our own server (/media/praeregistrierung/sfx). They only load after your click on the card page; the “Sound” switch turns them off. Nothing is stored on your device.
    Duration
    nothing stored on your device
    Provider
    Projection-X, hosted by Vercel (processor)
    Role
    own service
    Third country
    USA (Vercel Inc.; EU-US Data Privacy Framework)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • Supabase

    Type
    Service
    Purpose
    Sign-in, registration and password reset. Only when you use one of them.
    Duration
    no storage of its own in your browser
    Provider
    Supabase Inc. (processor)
    Role
    Processor
    Third country
    USA possible (Supabase Inc.; EU-US Data Privacy Framework, standard contractual clauses)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • Stripe

    Type
    Service
    Purpose
    Payment: we forward you to Stripe’s checkout. No Stripe script loads on this website.
    Duration
    no storage on this website; Stripe sets its own cookies on its checkout page
    Provider
    Stripe (partly an independent controller)
    Role
    Controller
    Third country
    USA (Stripe, Inc.; EU-US Data Privacy Framework)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • LiveKit

    Type
    Service
    Purpose
    Video coaching in the live room. Only when you enter a coaching room.
    Duration
    no storage of its own in your browser
    Provider
    LiveKit Inc. (processor)
    Role
    Processor
    Third country
    USA (LiveKit Inc.; standard contractual clauses)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
  • Cloudflare Turnstile

    Type
    Service
    Purpose
    Protection against automated registrations and sign-ins. Loads only in forms that need it, and only after your choice.
    Duration
    no cookies on this website (according to Cloudflare)
    Provider
    Cloudflare, Inc. (processor; independent controller for improving bot detection)
    Role
    Processor
    Third country
    USA (Cloudflare, Inc.; EU-US Data Privacy Framework)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR (protection against abuse)
  • Cloudflare R2 (direct upload)

    Type
    Service
    Purpose
    Direct uploads of large files in the admin and studio area and in coaching.
    Duration
    no storage of its own in your browser
    Provider
    Cloudflare, Inc. (processor)
    Role
    Processor
    Third country
    USA (Cloudflare, Inc.; EU-US Data Privacy Framework)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR

Necessary, by your own choice

Settings you make yourself, without an identifier. They are stored only once you change them.

Entries (5)
  • px_locale

    Type
    Cookie
    Purpose
    Your language. Only when you switch it yourself.
    Duration
    12 months
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG (a setting you chose); Art. 6(1)(f) GDPR
  • px_nav

    Type
    Cookie
    Purpose
    Sidebar or top bar. Only when you switch the layout yourself.
    Duration
    12 months
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG (a setting you chose); Art. 6(1)(f) GDPR
  • px-display

    Type
    Browser storage
    Purpose
    Your display settings: motion off, 3D, smooth scrolling, cursor. Only when you switch them yourself.
    Duration
    until you reset the setting
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG (a setting you chose); Art. 6(1)(f) GDPR
  • px-fuer-dich

    Type
    Browser storage
    Purpose
    Hides the “For you” block if you chose so yourself.
    Duration
    until you show the block again
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG (a setting you chose); Art. 6(1)(f) GDPR
  • px-player-subtitles

    Type
    Browser storage
    Purpose
    Your subtitle choice in the course player.
    Duration
    until you change it
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Sec. 25(2) no. 2 TDDDG (a setting you chose); Art. 6(1)(f) GDPR

Only during an attack

During an attack on the website, the firewall of our host checks that a real browser is asking.

Entries (1)
  • _vcrcs

    Type
    Cookie
    Purpose
    Only during an attack on the website: the firewall checks that a real browser is asking and remembers the passed check.
    Duration
    1 hour
    Provider
    Vercel Inc. (processor)
    Role
    Processor
    Third country
    USA (Vercel Inc.; EU-US Data Privacy Framework)
    Legal basis
    Sec. 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR (protection against abuse)

Remember hints

Dismissed hints, promotions and pop-ups as well as your step in the introductory tour stay stored. Without this choice they last only until you close the tab.

Entries (4)
  • px_wt_step:<Konto>

    Type
    Browser storage
    Purpose
    Remembers at which step you left the introductory tour. The name contains your account identifier.
    Duration
    until the end of the tour
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR
  • px_install_dismissed

    Type
    Browser storage
    Purpose
    Remembers that you dismissed the app installation hint.
    Duration
    until you withdraw consent or clear the site data
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR
  • px_promo_dismissed

    Type
    Browser storage
    Purpose
    Remembers which promotions you dismissed (at most 40).
    Duration
    until you withdraw consent or clear the site data
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR
  • px_popup_<id>_<v>

    Type
    Browser storage
    Purpose
    Remembers which notice windows you dismissed.
    Duration
    until you withdraw consent or clear the site data
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR

App & offline

A service worker makes the hub installable and shows an offline page without a connection. Without this choice it is unregistered.

Entries (2)
  • Service Worker /sw.js

    Type
    Browser storage
    Purpose
    Makes the hub installable as an app and shows an offline page without a connection.
    Duration
    until you withdraw consent; it is then unregistered
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR
  • Cache px-hub-*

    Type
    Browser storage
    Purpose
    Stores the offline page and the app icons in your browser.
    Duration
    until you withdraw consent; it is then deleted
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    no transfer
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR

Videos & 3D

Preference, not consent

Moving images and 3D from our own server. No third party, no consent; saves data.

Entries (2)
  • Videos from our own server

    Type
    Service
    Purpose
    Loops, films, tile, feed and course videos, clips and coaching recordings from our own server.
    Duration
    usual browser caching
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    USA (Vercel Inc. and Cloudflare, Inc. as processors; EU-US Data Privacy Framework)
    Legal basis
    no consent required (own server); your preference on data usage
  • 3D stage and demo data

    Type
    Service
    Purpose
    3D stage with model, textures and program code (about 3.6 MB) and the demo data of the stages.
    Duration
    usual browser caching
    Provider
    Projection-X (own server)
    Role
    own service
    Third country
    USA (Vercel Inc. as processor; EU-US Data Privacy Framework)
    Legal basis
    no consent required (own server); your preference on data usage

External media

Videos and images from other providers. Each provider sees your IP address when content loads; each can be switched on its own.

  • Type
    Service
    Purpose
    Streaming of course and product videos. Your browser loads the videos directly from Mux; Mux sees your IP address.
    Duration
    no storage of its own in your browser
    Provider
    Mux, Inc. (processor)
    Role
    Processor
    Third country
    USA (Mux, Inc.; EU-US Data Privacy Framework)
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR
  • Type
    Service
    Purpose
    Embedded YouTube videos (www.youtube-nocookie.com) and their thumbnails. Google sees your IP address.
    Duration
    set by Google; this website cannot delete cookies on Google’s own domains
    Provider
    Google Ireland Limited (controller)
    Role
    Controller
    Third country
    USA (Google LLC; EU-US Data Privacy Framework)
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR
  • Type
    Service
    Purpose
    Embedded Vimeo videos (player.vimeo.com, with “Do Not Track”) and their thumbnails. Vimeo sees your IP address.
    Duration
    set by Vimeo; this website cannot delete cookies on Vimeo’s own domains
    Provider
    Vimeo.com, Inc. (controller)
    Role
    Controller
    Third country
    USA (Vimeo.com, Inc.)
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR
  • Type
    Service
    Purpose
    Embedded Instagram posts and their thumbnails. Meta sees your IP address.
    Duration
    set by Meta; this website cannot delete cookies on Meta’s own domains
    Provider
    Meta Platforms Ireland Limited (joint controller under Art. 26 GDPR)
    Role
    Joint controller
    Third country
    USA (Meta Platforms, Inc.; EU-US Data Privacy Framework)
    Legal basis
    Consent, Sec. 25(1) TDDDG; Art. 6(1)(a) GDPR; joint controllership under Art. 26 GDPR (CJEU C-40/17)

This website cannot delete cookies that YouTube, Vimeo or Instagram set on their own domains. You can do that in your browser settings.

Choose individually