Privacy Policy for tennisgate.com
Last updated: 26 July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data-protection laws is:
TennisGate GmbH
Eupener Straße 60
50933 Köln
Germany
Represented by the Managing Directors Oliver Heuft and Lars Bischoff
Phone: +49 (0)761 15664488
Email: office@tennisgate.com
You may send privacy-related enquiries to the contact details above.
2. Subject matter and scope
This Privacy Policy explains how we process personal data when you visit tennisgate.com, register or sign in, purchase or use digital content, memberships, courses or webinars, use partner access portals, contact TennisGate, submit a withdrawal or cancellation, or otherwise interact with our platform.
Personal data means any information relating to an identified or identifiable natural person. This may include contact, account, contract, payment, usage, device, security and communication data.
3. Legal bases for processing
We process personal data only where a legal basis applies. Depending on the processing activity, the principal legal bases are:
- Article 6(1)(a) GDPR: processing based on your consent;
- Article 6(1)(b) GDPR: processing necessary for the performance of a contract or to take steps at your request before entering into a contract;
- Article 6(1)(c) GDPR: processing necessary for compliance with a legal obligation;
- Article 6(1)(f) GDPR: processing necessary for our legitimate interests or those of a third party, provided that your interests or fundamental rights do not override those interests.
The storage of information on your device, or access to information already stored there, is additionally governed by Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG). Technologies that are not strictly necessary are generally used only after consent.
4. Hosting and server log data
Our website is hosted by HostPress GmbH, Bahnhofstraße 34, 66571 Eppelborn, Germany. We have concluded a data-processing agreement with HostPress.
When the website is accessed, technically necessary data may be processed and stored in server log files. This may include the IP address, date and time, requested URL, referrer URL, transferred data volume, HTTP status code, browser type and version, operating system and internet service provider.
This processing is necessary to provide the website securely and reliably, defend against attacks and diagnose technical errors. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of our digital services.
Log data is deleted when it is no longer needed for these purposes. If a specific security incident occurs, relevant data may be retained until the incident has been fully investigated and, where necessary, legal claims have been pursued or defended.
5. Cookies, similar technologies and Real Cookie Banner
We use cookies and similar technologies, such as local storage, to provide functions that are technically necessary and, with your consent, to enable analytics, marketing or embedded-media services.
We use the WordPress plugin Real Cookie Banner to obtain, manage and document your choices. The plugin runs on our own webspace. It may store a pseudonymous consent identifier, your selections, the banner version, date and time, the page accessed and technical information required to display the consent interface.
Strictly necessary storage or access on your device is based on Section 25(2) TDDDG. Processing required to obtain, manage and document consent is based on Article 6(1)(c) GDPR and, additionally, Article 6(1)(f) GDPR.
You can change or withdraw your choices at any time with effect for the future through the privacy settings provided in the website footer. This does not affect the lawfulness of processing carried out before withdrawal.
Details of the services used, technologies, purposes and storage periods are shown in the privacy settings or cookie information. Consent records are retained for as long as reasonably necessary to comply with statutory accountability requirements or to establish, exercise or defend legal claims.
6. Contacting us
When you contact us by email, telephone or contact form, we process the information you provide, including your name, contact details, the content of your enquiry, communication metadata and, where applicable, contract or order information.
Where the enquiry relates to a contract or pre-contractual steps, the legal basis is Article 6(1)(b) GDPR. In other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to respond appropriately and document the communication.
Enquiries are deleted once they have been finally dealt with, unless statutory retention duties or legitimate reasons require longer storage.
7. Registration, customer account, sign-in and security
A customer account is required for certain functions and paid offers. During registration and account use, we may process your name, email address, username, billing and contact data, contractual or membership status, and the dates, times and technical details of registration, sign-in and account actions.
Passwords are not stored in plain text but as cryptographically secured verification values. We may also process failed sign-in attempts, IP addresses, device and browser information and security events to protect accounts, prevent misuse and detect unauthorised sharing or use.
The legal basis for providing the account and contractual functions is Article 6(1)(b) GDPR. Security logging is based on Article 6(1)(f) GDPR. Our legitimate interest is to protect the platform, its content and user accounts.
Account data is generally stored for the duration of the user relationship. After deletion or termination, data is removed unless it remains necessary to perform an existing contract, comply with legal retention duties, prevent misuse or establish, exercise or defend legal claims.
8. Orders, contracts, memberships and Paddle
When you order a membership, category, course, webinar or other digital offer, we process the information required to handle the order and provide access. This may include your name, email address, billing address, telephone number where supplied, product, price, currency, order and contract identifiers, term, renewal or cancellation status, tax information, communications and payment status.
The TennisGate platform and access management use WordPress and WooCommerce. Where the checkout is processed by Paddle, Paddle acts as the authorised reseller and Merchant of Record for the payment transaction. Depending on your location, the relevant Paddle entity is identified during checkout and in Paddle’s contractual documents. Paddle processes order, payment, tax, invoicing, fraud-prevention and refund data under its own responsibility and in accordance with its privacy notice.
For transactions processed by Paddle, TennisGate generally receives the information required to create and manage access, such as customer and order identifiers, contact details, product, subscription status, transaction status, currency and tax or invoice references. TennisGate does not receive or store full payment-card details entered in Paddle’s checkout.
Processing by TennisGate for access and contract administration is based on Article 6(1)(b) GDPR. Processing required for invoicing, accounting, taxation or statutory records is additionally based on Article 6(1)(c) GDPR. Paddle’s own processing is governed by the legal bases and notices stated by Paddle.
Further information is available in Paddle’s Privacy Policy.
9. Use of digital content and platform functions
When protected content or membership functions are used, we process data necessary to deliver the service, control licences, troubleshoot issues, improve the platform and maintain security. This may include account and membership identifiers, content accessed, access times, session data, browser and device information, playback or progress information and security-relevant usage patterns.
Processing necessary to provide purchased functions is based on Article 6(1)(b) GDPR. Processing for technical security and the prevention of account sharing, unauthorised recording, automated access or other misuse is based on Article 6(1)(f) GDPR.
Where the platform offers personal lists, favourites, playlists, learning progress, test results, certificates or competence records, we process the account, content and result data necessary to provide these functions. Public validation pages for badges or certificates are made available only to the intended extent. Users decide whether to publish or share a validation link.
10. Withdrawal, cancellation and other contractual declarations
When you submit a withdrawal, cancellation or another contractual declaration through our website, we may process your name, email address, order or contract identifier, selected order items, the content of the declaration, date and time, and technical evidence required to document the submission.
We use the EU Order Withdrawal Button for WooCommerce plugin provided by vendidero to receive and document electronic withdrawal requests. The data is processed on the systems used for the TennisGate website and may be transmitted to Paddle where necessary to identify a Paddle transaction, stop a subscription or arrange a refund.
Processing is necessary to receive, assess, document and implement your declaration and is based on Article 6(1)(b) and Article 6(1)(c) GDPR. Relevant data is retained in accordance with statutory retention duties for contractual and business records and for the establishment, exercise or defence of legal claims.
11. Online courses, webinars and events
When you register for or participate in an online course, webinar or event, we may process your name, contact details, booking and participation data, communications, technical connection data and, where applicable, learning or test results.
Processing is necessary to organise and deliver the booked offer and is based on Article 6(1)(b) GDPR. If an external webinar, video-conferencing or event service is used, the relevant provider and processing will be described during registration or in supplementary privacy information.
12. Partner portals, membership checks and single sign-on
Access may be provided through a partner organisation, a membership check or single sign-on. In this case, TennisGate may receive only the data or technical authorisation evidence required to verify eligibility and provide access. Depending on the implementation, this may include a name, email address, partner identifier, membership or package status, start and end dates and authentication tokens.
Processing required to provide the authorised access is based on Article 6(1)(b) GDPR or, where the partner arranges access for its members, Article 6(1)(f) GDPR. Additional data-protection arrangements may apply between TennisGate and the partner. Passwords managed by a partner organisation are not requested by TennisGate.
13. Newsletter and promotional communications
When you subscribe to a newsletter, we process your email address, where supplied your name, and logging data relating to registration and confirmation. Registration generally uses a double opt-in process. We record the time and technical evidence of registration and confirmation in order to demonstrate valid consent.
The legal basis for sending the newsletter is Article 6(1)(a) GDPR. Documentation of consent is based on Article 6(1)(c) and Article 6(1)(f) GDPR. Our legitimate interest is to demonstrate compliant registration.
Opening and click measurement is used only where you have consented and in accordance with the settings of the mailing service. You may withdraw consent at any time through the unsubscribe link in each message or by contacting us. After withdrawal, your data is removed from the active mailing list; evidence required for compliance may be retained until relevant limitation periods expire.
We may use a newsletter or email service provider as a processor. The specific provider is identified in the subscription form, privacy settings or supplementary privacy information.
14. Embedded Vimeo videos
We embed videos from Vimeo.com, Inc., USA. When an embedded video is loaded or played, Vimeo may receive data including the IP address, device and browser information, the page viewed, playback information and cookie or similar identifiers.
Vimeo content is generally loaded only after consent through our consent-management system. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time through the privacy settings.
Processing in the United States or other third countries cannot be ruled out. Vimeo states that it uses appropriate mechanisms for international data transfers. Further information is available in Vimeo’s privacy information.
15. Google Analytics 4
Where you have consented, we use Google Analytics 4 to analyse and improve the website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by affiliated companies, including in the United States, may occur.
Google Analytics may use cookies or similar technologies and process a pseudonymous client ID, session and event data, approximate location, device and browser information, referrer, pages accessed and interactions. Google states that individual IP addresses of users in the EU are not logged or stored; an IP address may be processed briefly to derive approximate location and then discarded.
Google Analytics is used only on the basis of consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Where Google Consent Mode is used, Google services are controlled according to the choices made in the consent-management interface.
The retention period for user and event data in our analytics configuration is no more than 14 months. Aggregated reports may remain available for longer. Consent can be withdrawn at any time through the privacy settings.
16. Google Ads and conversion measurement
Where you have consented, we use Google Ads to measure the success of advertising and to display relevant advertisements. The provider is Google Ireland Limited; processing by affiliated companies, including in the United States, may occur.
When you arrive through a Google advertisement or perform a defined action, cookies or comparable identifiers, device and browser data, IP-related information, pages visited, interactions, order or conversion events and pseudonymous advertising identifiers may be processed.
The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. Personalised advertising and remarketing are used only in accordance with your consent. The specific technologies and storage periods are shown in the privacy settings, where consent can also be withdrawn.
17. Locally hosted fonts
Fonts used on the website are generally delivered locally from our own server. Merely loading these fonts therefore does not establish a connection to Google Fonts or another external font provider.
18. External links and social-media profiles
The website may contain links to external websites and social-media profiles. Displaying a normal link does not generally transmit data to the provider. Data is processed under the external provider’s responsibility only after you follow the link.
Where social-media content, feeds or comparable external functions are embedded directly, they are generally blocked by our consent-management system and loaded only after consent. The external provider’s privacy information then applies in addition.
19. Recipients, processors and international transfers
We disclose personal data only where permitted or required by law. Recipients may include hosting and IT service providers, Paddle and other payment or transaction providers, banks, accounting and tax advisers, communication and newsletter providers, video and analytics providers, cooperation partners where required to perform a contract, and public authorities where legally required.
Service providers that process personal data solely on our instructions are engaged under Article 28 GDPR. Other providers, particularly payment, platform or network operators, may process data as independent controllers for their own statutory or operational purposes.
For transfers outside the European Union or European Economic Area, we ensure that an appropriate transfer mechanism applies. This may include an adequacy decision of the European Commission, participation by a US organisation in the EU–US Data Privacy Framework, EU Standard Contractual Clauses or a statutory derogation.
20. Storage periods
We retain personal data only for as long as necessary for the relevant purpose or as required by statutory retention periods. It is then deleted or anonymised unless another legal basis permits further storage.
Depending on the type of document, tax and commercial records may be subject to retention periods of six, eight or ten years. Contract, order and invoice data may therefore be retained after an account or membership ends. Data necessary to establish, exercise or defend legal claims may be retained until the applicable limitation periods expire.
21. Your data-protection rights
Subject to the statutory conditions, you have the following rights:
- access to your personal data under Article 15 GDPR;
- rectification of inaccurate data and completion of incomplete data under Article 16 GDPR;
- erasure under Article 17 GDPR;
- restriction of processing under Article 18 GDPR;
- data portability under Article 20 GDPR;
- objection to processing based on Article 6(1)(e) or (f) GDPR under Article 21 GDPR;
- withdrawal of consent at any time with effect for the future under Article 7(3) GDPR;
- the right not to be subject to a decision based solely on automated processing where Article 22 GDPR applies.
To exercise your rights, contact us using the details in section 1. We may need to verify your identity before responding.
22. Right to lodge a complaint
You have the right to lodge a complaint with a data-protection supervisory authority. In particular, you may contact the authority responsible for your habitual residence, place of work or the place of the alleged infringement.
The supervisory authority responsible for TennisGate is generally:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
23. Automated decision-making
TennisGate does not use solely automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Payment and fraud-prevention providers may carry out automated risk checks under their own responsibility; further information is available in their privacy notices.
24. Data security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures are reviewed and adapted to risk, technical development and the nature of the processing.
No internet transmission or storage system can provide absolute security. Please keep your access credentials confidential and notify us promptly if you suspect unauthorised use.
25. Changes to this Privacy Policy
We may update this Privacy Policy where processing activities, services, legal requirements or technical circumstances change. The current version is published on tennisgate.com. Where required by law, we will provide additional notice or obtain consent.