Privacy policy

Last updated: August 2026

1. Controller

The controller for data processing on this website within the meaning of the GDPR is:

Andres Vargas
AmigoSAP – Nachhilfe
Pützbruchstr. 6
52477 Alsdorf, Germany
Phone: +49 163 4824433
Email: info@amigosap.com

We act as controller for the processing described on this website. For payment processing, Paddle.com is an independent controller as Merchant of Record.

2. What data we process and why

Account and sign-in

Data: email address, password (stored encrypted), and where applicable name and profile data when signing in with Google. Purpose: creating and managing your account and access to your hour balance. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Bookings and hour credits

Data: name, email, selected module, appointment, booking messages, purchased and used hours. Purpose: delivering the coaching and managing your credit balance. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Contact requests

Data: name, email address, content of your message. Purpose: handling your enquiry. Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) or our legitimate interest in communication (Art. 6(1)(f) GDPR).

Purchase and order data

Data: order reference, purchased package, purchase status. Purpose: unlocking your credits and evidencing the order. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and legal obligations (Art. 6(1)(c) GDPR). We do not collect payment details such as card data; these are processed exclusively by Paddle.

Server and usage data

Data: IP address, date and time of access, page requested, browser type and device information, error logs. Purpose: providing and stabilising the website, security and abuse prevention. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

3. Recipients and processors

  • Hosting and backend providers for operating the website, database and authentication.
  • Paddle.com Market Ltd. as Merchant of Record for sales, payment processing, invoicing, tax compliance and refunds.
  • Google, if you voluntarily sign in with your Google account.
  • Professional advisers (e.g. tax advisers) and public authorities, where legally required.

We do not pass data to third parties for advertising purposes. Contracts pursuant to Art. 28 GDPR are in place with our processors.

4. Transfers to third countries

Individual service providers may process data outside the EEA, in particular in the USA. In such cases the transfer is based on an adequacy decision of the EU Commission or on EU Standard Contractual Clauses together with supplementary safeguards.

5. Retention

We store account and booking data for the duration of the business relationship. Afterwards it is deleted or anonymised unless statutory retention periods apply (usually 6 to 10 years under commercial and tax law). Contact requests are deleted no later than 12 months after final processing. Server logs are deleted shortly, usually within 30 days.

6. Cookies and local storage

We only use technically necessary cookies and local storage, e.g. for your login session, language selection and checkout handling. Legal basis: § 25(2) TDDDG and legitimate interest (Art. 6(1)(f) GDPR). We do not use tracking or marketing cookies. You can delete or block cookies in your browser settings at any time; sign-in may then no longer work.

7. Your rights

Under the GDPR you have the right to:

  • access to the data stored about you (Art. 15)
  • rectification of inaccurate data (Art. 16)
  • erasure (Art. 17)
  • restriction of processing (Art. 18)
  • data portability (Art. 20)
  • object to processing based on legitimate interests (Art. 21)
  • withdraw consent with effect for the future (Art. 7(3))

A message to info@amigosap.com is sufficient to exercise these rights. We generally respond within one month. You may also lodge a complaint with a data protection supervisory authority, e.g. the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Germany.

8. Data security

We take appropriate technical and organisational measures to protect your data, in particular TLS-encrypted transmission, access restrictions at database level and encrypted storage of passwords.

9. Changes

We update this privacy policy when our services or the legal situation change. The version published on this page applies.