Privacy Policy

Last updated: August 2026 · Draft, pending legal review.

This is a translation provided for convenience. In case of any discrepancy, the German version is the legally authoritative text.

1. Controller

The controller for data processing on this website is:

Train the Future UG (haftungsbeschränkt)
Prenzlauer Allee 186
10405 Berlin
Germany

Represented by the managing director: Sama Tanveer
Phone: +49 176 72134293
Email: info@trainthefuture.com

2. Data protection officer

Whether we are required to appoint a data protection officer is determined by § 38 BDSG (generally from 20 people permanently engaged in automated processing). This assessment is still outstanding and will be completed before this policy is published. Until then, please use the contact details above for any data protection question.

3. Hosting and server log files

This website is hosted by Cloudflare. When you access it, access data transmitted by your browser is processed automatically: IP address, date and time, the address requested, referrer, browser and operating system details.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and uninterrupted operation of the website and the prevention of attacks. The specific retention period for these log entries will be added before publication.

4. Contacting us

If you contact us by email, phone or WhatsApp, we process your details in order to handle your enquiry.

The legal basis is Art. 6(1)(b) GDPR where your enquiry is directed at entering into a contract (for example requesting a trial lesson), and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries.

For WhatsApp messages, the operator of that service also processes your data under its own terms. If you would prefer to avoid this, please use email or phone.

5. Trial lesson enquiries

To arrange a trial lesson we need the child’s age, the preferred location and a way to contact you. The enquiry is always made by a parent or guardian; the contracting party is the guardian, not the child.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures).

6. Appointment booking (planned)

Calendly, a service based in the USA, is intended for online appointment booking. The data you enter in the booking form would be transmitted to it. This service is not currently integrated. Before it is activated, the legal basis, the transfer mechanism for the third-country transfer and the scope of the data transmitted will be added here.

7. Customer management (planned)

The Kommo CRM system is intended for managing enquiries and enrolments. This service is also not currently integrated. Before it is activated, the scope of the data stored, the retention period and the legal basis will be added here.

8. Learning platform

Accounts are created for participating children on the learning platform of our licensor, Algorithmics. The child’s first name and age and a contact detail for the guardian are transmitted for this purpose. The licensor is based in Cyprus (EU).

The legal basis is Art. 6(1)(b) GDPR, as use of the platform forms part of the course. The contractual classification of this transfer — processing under Art. 28 GDPR or joint controllership under Art. 26 GDPR — is currently being reviewed against the licence agreement.

9. Course booking via third parties

Some camps are booked through the Kindaling platform. Kindaling is an independent controller for the data collected there, not our processor. As soon as you follow a booking link, Kindaling’s own privacy policy applies. We receive only the information required to deliver the booked course.

10. Analytics and cookies

We use Google Tag Manager (container GTM-WT4JJSHK) and Google Analytics 4. These services are loaded only after your explicit consent; without consent, no data is transmitted to Google. We use Google Consent Mode v2.

The legal basis is Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. You can withdraw your consent at any time, with effect for the future, via the cookie settings in the footer.

The individual cookies that may be set, with provider, purpose and duration, are listed in our cookie policy.

11. Protection against misuse

Cloudflare Turnstile is intended to protect our forms against automated access. Turnstile operates without profiling user behaviour across websites. The legal basis is Art. 6(1)(f) GDPR.

12. Email delivery

A service provider processing data within the EU is intended for confirmation and notification emails. The specific provider will be added before publication.

13. Reviews and maps

Reviews from the Google Business Profile are retrieved at the time the page is built and delivered as static text. Map extracts are embedded as static images. In both cases, no connection is made from your browser to Google when you visit this website.

14. Social media profiles

We link to our profiles on external platforms in the footer. These are plain links: data is only transmitted to the platform concerned once you click one of them.

15. Photographs and video

We publish photographs of events, courses and camps on this website in which children are identifiable. The sole basis for this is the prior written consent of the guardians under Art. 6(1)(a) in conjunction with Art. 7 GDPR.

That consent can be withdrawn at any time. On notification to the address above, we will remove the image in question. The reconciliation of the consents held against every currently published image has not yet been completed.

16. Third-country transfers

Where data is transferred to recipients outside the EU/EEA, this takes place only on the basis of an adequacy decision, certification under the EU-US Data Privacy Framework, or standard contractual clauses. The assignment per service provider will be added before publication.

17. Retention

We store personal data only for as long as is necessary for the relevant purpose or as required by statutory retention obligations — in particular the commercial and tax law periods under § 257 HGB and § 147 AO. Enquiries that do not lead to an enrolment are deleted after a defined period. The specific periods per data category will be added before publication.

18. Your rights

You have the right at any time to:

  • Access the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Withdraw consent with effect for the future (Art. 7(3) GDPR)

An informal message to the contact details above is sufficient to exercise these rights.

19. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany

Book a Trial LessonWhatsApp (opens in a new tab)