Privacy Policy — Lapicida Latinus

*As of August 2026*

1. Data Controller

Andreas Blankestein
Riederhöhe 12a
28279 Bremen
Germany

Email: andreas@lapicida-latinus.de
Website: https://lapicida-latinus.de

2. General

We process personal data only to the extent necessary for the operation of this website, the app, and the services offered. Processing is carried out in accordance with the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).

3. Hosting

This website is hosted by:

Hostinger International Ltd.

61 Lordou Vironos Street, 6023 Larnaca, Cyprus

When you visit the website, the server automatically stores so-called server log files that your browser transmits. These include: IP address, date and time of the request, URL accessed, browser type and version, operating system, and referrer URL.

This data is technically necessary to deliver the website and is not combined with other data sources.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: operation and security of the website)

Retention period: 30 days, followed by automatic deletion

A Data Processing Agreement (DPA) has been concluded with Hostinger.

4. Cookies and Cookie Settings

This website uses cookies. Technically necessary cookies are set without consent. All other cookies (e.g., for analytics or marketing) are only activated after you give your consent via the cookie banner.

You can change or revoke your cookie settings at any time via the “Cookie Settings” link in the footer of this website.

We use Real Cookie Banner to record and document your consents in compliance with the GDPR.

5. Contact Form

When you send us a message via the contact form on this website, the following data is collected and stored in the WordPress database:

– Name
– Email address
– Your message
– Time of submission

We store your message in the database (and not just via email) to ensure reliable processing and traceability.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: responding to your inquiry); for purchase-related inquiries, Art. 6(1)(b) GDPR

Retention period: Until your inquiry has been fully processed, followed by a maximum of 3 months, unless statutory retention periods apply

6. Registration and User Account

When you create a user account, we process:

– Email address
– Password (stored in encrypted form)
– Name
(if applicable) – Date of registration
– License status and purchase history

Legal basis: Article 6(1)(b) of the GDPR (performance of a contract or pre-contractual measures)

Retention period: For the duration of the contractual relationship; data relevant for tax purposes is retained for 10 years (Section 147 of the German Fiscal Code (AO))

7. Purchase and Payment Processing

7.1 WooCommerce

We use WooCommerce (Automattic Inc., USA) to process purchases. When a purchase is made, the following data is processed: name, address, email address, selected payment method, and order details. This data is necessary for the performance of the contract.

Legal basis: Art. 6(1)(b) GDPR

Retention period: 10 years (tax-related retention requirement pursuant to § 147 AO)

7.2 PayPal

If you select PayPal as your payment method, the necessary data will be transmitted to PayPal to process the payment:

PayPal (Europe) S.à.r.l. et Cie, S.C.A.

22-24 Boulevard Royal, 2449 Luxembourg

PayPal may transfer data to the United States. This is based on standard contractual clauses pursuant to Art. 46(2)(c) of the GDPR.

PayPal Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

Legal basis:** Article 6(1)(b) of the GDPR

7.3 Stripe

If you select credit card as your payment method, the necessary payment data will be transmitted to Stripe:

Stripe Payments Europe, Ltd.

1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland

Stripe may transfer data to the United States. This is based on standard contractual clauses pursuant to Art. 46(2)(c) of the GDPR and the EU-U.S. Data Privacy Framework.

Stripe Privacy Policy: https://stripe.com/de/privacy

Legal basis: Article 6(1)(b) of the GDPR

8. Newsletter “Letters from the Officina”

What we collect. For the “Letters from the Officina” newsletter we process your email address. In addition, we store the time of your signup, your IP address and your browser identifier, as well as the route by which you signed up.

What for. We use your email address solely to send you the newsletter. The time of signup, IP address and browser identifier are not stored for the purpose of sending, but as evidence that the signup genuinely came from you — we are legally required to keep such a record.

Legal basis. The newsletter is sent on the basis of your consent (Art. 6(1)(a) GDPR). We store the evidence data on the basis of our legitimate interest in being able to demonstrate a legally valid signup (Art. 6(1)(f) GDPR).

How signing up works. After you submit the form, we send you an email containing a confirmation link. You are only added to the list once you click that link. If you sign up via a personal link from an email we had previously sent to that exact address, the additional confirmation step is omitted — clicking the personal link already proves that the address is yours.

Who receives the data. We do not pass your address on to third parties and do not use it for advertising outside this newsletter. Subscriber data is held on our own server. For the technical dispatch and for server operation we use Hostinger International Ltd. as a processor; a data processing agreement is in place.

No performance tracking. We do not measure whether you have opened an email or clicked a link. There are no tracking pixels and no click tracking.

How long. We store your data until you unsubscribe. After you unsubscribe, we retain your address and the record of your consent in order to ensure that you receive no further emails and to be able to demonstrate that consent was given. You may request complete erasure at any time.

Your withdrawal. You may withdraw your consent at any time, without giving reasons. Every email contains an unsubscribe link for this purpose; one click is enough. Alternatively, an informal message to andreas@lapicida-latinus.de will suffice. The lawfulness of the processing carried out up to that point remains unaffected.

9. Google Services

We use various services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may transfer data to servers in the United States. This is based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR as well as the EU-U.S. Data Privacy Framework.

9.1 Google Analytics (via Google Site Kit)

With your consent, we use Google Analytics to statistically analyze the use of our website. In doing so, pseudonymous user profiles are created. IP addresses are anonymized before being transmitted to Google (IP anonymization enabled).

Legal basis: Article 6(1)(a) of the GDPR (consent via cookie banner)

You can prevent data collection by Google Analytics by rejecting the corresponding category in the cookie banner or by installing the browser add-on at https://tools.google.com/dlpage/gaoptout.

9.2 Google Tag Manager

Google Tag Manager itself does not store any cookies and does not collect any personal data. It is used solely to manage the integrated tags (e.g., Google Analytics). It only becomes active once you have accepted the relevant cookies.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: efficient tag management)

9.3 Google Search Console

We use Google Search Console to monitor our website’s search performance. No individual user data is processed in this process; only aggregated, non-personal statistics are analyzed.

Legal basis: Art. 6(1)(f) GDPR

9.4 Google Ads (planned)

We plan to use Google Ads for advertising purposes. As soon as Google Ads is active, this privacy policy will be updated accordingly. Processing is based exclusively on your consent via the cookie banner.

10. Spam Protection (Friendly Captcha)

To protect our forms from spam and misuse, we use Friendly Captcha:

Friendly Captcha GmbH

Tal 8, 80331 Munich, Germany

Friendly Captcha does not set cookies, does not create user profiles, and does not perform cross-site tracking. To solve the captcha, technical device data (browser information) is temporarily processed. Personal data is not stored permanently.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: protection against misuse)

Friendly Captcha Privacy Policy: https://friendlycaptcha.com/legal/privacy-end-users/

11. Lapicida Latinus App

11.1 App Download (Google Play)

The Lapicida Latinus Android app can be downloaded from the Google Play Store. During the download and installation, Google processes its own data in accordance with the Google Privacy Policy. We have no influence over this processing.

11.2 App Use Without an Account (Offline)

The app can be used entirely offline and without a user account. In this case, no personal data is transmitted to us.

11.3 App Notifications (Device ID)

In order to deliver system notifications to you within the app (e.g., notifications about updates or new content), an anonymous device ID is generated and stored on our server. This ID does not allow any identification of you personally and is not linked to your user account (if you do not have an account).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract: provision of app functionality)

Retention period: Until the app is uninstalled or upon request

11.4 Telemetry (Usage Statistics)

With your consent, we collect anonymous usage data (e.g., which exercise types are used, number of sessions). This data does not contain any personally identifiable information and cannot be attributed to a specific individual.

Telemetry can be disabled at any time in the app settings.

Legal basis: Art. 6(1)(a) GDPR (consent)

11.5 Bug Reports

If an error occurs in the app, you can submit a bug report. This report contains technical information about the error (e.g., app version, device type, error description). All reports are transmitted without personal data, unless you voluntarily provide your contact information.

If you provide contact information, it will be used exclusively to process your bug report.

Legal basis: Art. 6(1)(f) GDPR (without contact information) / Art. 6(1)(a) GDPR (with contact information)

Retention period: Until the error is resolved, up to a maximum of 6 months

11.6 DeepL API (optional feature)

The app offers optional integration with DeepL for translation assistance. If you wish to use this feature, you must enter your own DeepL API key in the app settings. The connection to DeepL is then established directly between your device and DeepL—we, as the operator, do not receive any data in this process.

DeepL’s Privacy Policy applies: https://www.deepl.com/de/privacy

11.7 Vocabulary Scan (Photo Recognition)

Purpose and scope. The app offers an optional feature that lets you take a photo of a vocabulary list or textbook page. The image is used solely to automatically recognise the vocabulary it contains (Latin word, part of speech and meaning) and add it to your vocabulary list. No further analysis of the image takes place – in particular, no person or facial recognition.

Processing. For text recognition, the photo is transmitted to our service provider Anthropic (Anthropic PBC, USA) and processed there by an AI model (Claude). The photo is not stored permanently; it is only processed for the duration of the recognition and then discarded. The recognised vocabulary meanings may additionally be transmitted to DeepL SE (Germany) for translation (see section 11.6).

No AI training. The transmitted content is not used by the service providers to train their AI models.

Legal basis. Art. 6(1)(b) GDPR (provision of the feature you actively requested).

Third-country transfer. The transfer to Anthropic (USA) takes place on the basis of the EU Standard Contractual Clauses (see also section 12).

Voluntary. Use of the vocabulary scan is voluntary. Without using this feature, no photo is transmitted.

12. Data Transfer to Third Countries

Some of the services we use transfer data to countries outside the EU/EEA (particularly the U.S.). Where this is the case, the transfer is based on appropriate safeguards pursuant to Art. 46 of the GDPR (Standard Contractual Clauses) or on the EU-U.S. Data Privacy Framework. For details, please refer to the privacy policies of the respective providers.

13. Retention Period

Personal data will be deleted or blocked as soon as the purpose for which it was stored no longer applies. In addition, data may be retained if statutory retention obligations apply (e.g., tax-related retention periods: 10 years pursuant to Section 147 of the German Fiscal Code (AO)).

14. Your Rights

You have the following rights with respect to your personal data:

Right of access (Art. 15 GDPR): You may request information about the data we have stored.

Rectification (Art. 16 GDPR): You may request the correction of inaccurate data.

Erasure (Art. 17 GDPR): You may request the erasure of your data, provided that no statutory retention obligations prevent this.

Restriction of processing (Art. 18 GDPR)

Data portability (Art. 20 GDPR): You may receive your data in a machine-readable format.

Objection (Art. 21 GDPR): You may object to the processing of your data based on legitimate interests.

Withdrawal of Consent (Art. 7(3) GDPR): You may withdraw any consent you have given at any time, effective for the future.

To exercise your rights, please contact: andreas@lapicida-latinus.de

15. Right to File a Complaint with the Supervisory Authority

You have the right to lodge a complaint with the competent data protection supervisory authority:

The State Commissioner for Data Protection and Freedom of Information in Bremen (LfDI Bremen)

Arndtstraße 1
27570 Bremerhaven
Phone: +49 421 361-2010
Email: office@datenschutz.bremen.de
Website: https://www.datenschutz.bremen.de

16. Data Security

We implement technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our security measures are continuously improved in line with technological developments. Data transmission on our website is encrypted (TLS/HTTPS).

17. Validity of This Privacy Policy

This Privacy Policy is current as of August 2026. We reserve the right to update it in the event of changes to the legal landscape or to our services. The most current version is available at https://lapicida-latinus.com/en/privacy-policy/.