Privacy Policy
Privacy Policy
This English version is a courtesy translation. In the event of discrepancies, the German version prevails.
1. Controller for the processing of data (hereinafter "we")
Julia Kalder
c/o Autorenglück #80461
Albert-Einstein-Str. 47
02977 Hoyerswerda
Germany
Phone: +49 2173 2954754
Email: info@bold-bloom.com
Further details about us can be found in our imprint.
2. Personal data, purposes of processing and legal bases
Personal data is any information relating to an identified or identifiable natural person (hereinafter "data subject"). A natural person is regarded as identifiable where they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to that person's identity.
The purpose of processing data is the operation of this website with information about our services and contact options, as well as the provision of our software service Bold Bloom.
Personal data is collected on our website only where this is necessary for the use of the website (Art. 6(1)(a) and/or Art. 6(1)(b) GDPR), to safeguard our interest in improving the user experience and maintaining the security of use (Art. 6(1)(f) GDPR), for the use of the services offered on the website and pre-contractual measures such as form entries (Art. 6(1)(a) and/or Art. 6(1)(b) GDPR), or for the conclusion and performance of a contract (Art. 6(1)(a) and (b) GDPR). Further details are set out under the headings below.
3. Hosting, database and access data
For hosting and providing our website, operating our database and storing user and application data we use the services of Hostinger International, Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, with the server located in Frankfurt am Main. Hostinger processes personal data on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
When our website is accessed, technically necessary connection data is processed. This may include the IP address, date and time of access, the page or file requested, the volume of data transferred, HTTP status codes, referrer URL, browser type and version, operating system and information about the internet service provider. No complete access log of all page views is kept. To a limited extent, technical error and security logs may arise. These may contain the data listed above insofar as this is necessary for error analysis, for detecting and averting abusive access and for ensuring the security and stability of our IT systems.
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional provision of our website and in averting attacks and misuse.
4. Cookies
Our website uses cookies. Cookies are small files stored on your device that enable the provision and user-friendly use of the website, for example to manage sessions, store login data, language settings and privacy settings, and to protect against unauthorised requests.
Where cookies are strictly necessary to provide a telemedia service you have expressly requested, storage of or access to information on your device is based on § 25(2) no. 2 TDDDG. Where you consent to the use of non-essential cookies or services, the legal basis is § 25(1) TDDDG together with Art. 6(1)(a) GDPR. To obtain, manage and document your consents we use a consent management tool. That processing serves to fulfil our accountability obligations under Art. 5(2) and Art. 7(1) GDPR and rests on our legitimate interest in transparent and lawful consent management under Art. 6(1)(f) GDPR.
To evaluate the use of our publicly accessible website statistically we operate a self-hosted reach measurement on our own servers. No analytics cookies are set and no third-party analytics services are embedded. Visits are stitched using a daily-rotating, non-reversible checksum; IP addresses are not stored. No information is stored on or read from your device. Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the data-minimising evaluation and needs-based development of our website. You may object to the reach measurement at any time via the privacy settings; where the "Analytics" category is rejected or the browser signals "Do Not Track" or "Global Privacy Control" are present, no reach measurement takes place.
Details of the cookies used can be found in our cookie policy.
5. Contact by email and contact form
If you contact us by email or through the contact form, we process the personal data you transmit. This includes in particular your email address, your name where provided, the content of your message and any further details you supply.
Processing serves to handle your enquiry, to communicate with you and to deal with follow-up questions. Insofar as your enquiry concerns the conclusion or performance of a contract, the legal basis is Art. 6(1)(b) GDPR. Otherwise processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in handling enquiries appropriately, efficiently and traceably.
For sending emails we use, depending on the technical configuration, the Postmark service of Wildbit LLC, 2400 Market Street, No. 200, Suite 235B, Philadelphia, PA 19103, USA, or Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, USA. We process in particular the recipient address, subject, message content, any attachments, dispatch and delivery status and technical delivery information. The respective providers process personal data on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Insofar as personal data is transferred to the USA when using Postmark or Amazon Web Services, the transfer is based on the European Commission's adequacy decision for the EU–US Data Privacy Framework under Art. 45 GDPR. Wildbit LLC and Amazon Web Services, Inc. are each certified under the EU–US Data Privacy Framework.
Processing is based on Art. 6(1)(b) GDPR insofar as the respective email is necessary for initiating, performing or terminating the contract. Insofar as dispatch is necessary to fulfil statutory obligations, in particular for invoicing and tax-relevant documents, processing is based on Art. 6(1)(c) GDPR.
6. Customer account
As a coach or company you can create a customer account with us. In the course of registration and subsequent use of the customer account we process in particular your name, email address, role, language settings, access credentials in the form of a password hash, authentication and session identifiers, the selected plan and information on the status of email verification, the account and security. Where provided during booking, we also process company and billing data, in particular company or business name, business address, contact person details and VAT identification number. Through the protected customer portal you can manage your subscription, initiate a cancellation and retrieve billing information and invoices. After successful registration and acceptance of the contract you gain access to the software features of Bold Bloom.
Processing is necessary for pre-contractual measures and performance of the contract and is based on Art. 6(1)(b) GDPR. The processing of technical and security-related data, in particular IP addresses, session identifiers and account or security status, is otherwise based on Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring IT security, preventing abusive registrations and use, and documenting and enforcing our contractual rights.
7. Login, sessions and account security
For sign-in, provision of the platform and protection of user accounts we process in particular account data, authentication and session identifiers, IP address, information on the device and browser used, the time and status of sign-in processes and security-relevant events. We process this data to enable sign-ins, manage sessions, detect and avert unauthorised access and prevent misuse and fraud attempts.
Insofar as necessary for providing the user account and performing the contract, processing is based on Art. 6(1)(b) GDPR. Insofar as processing serves IT and system security and the detection, prevention and investigation of misuse or fraud, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and contractually compliant use of the platform and in protecting user accounts and data.
Where you have expressly consented, an approximate location may be determined from your IP address during sign-in in order to detect unusual sign-in attempts. For this we use the ip-api.com service of Kloudend Ltd., United Kingdom. Use takes place exclusively after your prior explicit consent; processing is based on Art. 6(1)(a) GDPR. Consent can be withdrawn at any time in the account settings with effect for the future; stored location data is then deleted.
8. Plans, subscription and invoices
For use of the free Solo plan, the conclusion and management of subscriptions and for billing, we process in particular the selected plan, price, any discounts or voucher codes, term and payment and cancellation status. To allocate and manage payment transactions we also process the transaction and reference data supplied by the payment service providers used and, where available, details of the payment method and payment status.
Payment is processed via Stripe Payments Europe Ltd. and, where selected in the German checkout, via PayPal (Europe) S.à r.l. et Cie, S.C.A. Further information can be found in sections 9 and 10 of this privacy policy. To create and provide invoices and any correction or cancellation invoices, we process invoice data, service period, amounts, tax details, payment date and the respective invoice file.
Processing for the performance of the contract and payment handling is based on Art. 6(1)(b) GDPR. Insofar as processing is necessary to fulfil statutory invoicing and retention obligations, it is based on Art. 6(1)(c) GDPR.
9. Stripe
On our website you can make payments by credit card. If you pay using these methods, payment is processed via the payment provider "Stripe". The provider is Stripe Payments Europe Ltd., Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland. The data required for this (card number, validity and check digit) is forwarded to the payment provider in encrypted form and is not visible to the website operator. The payment provider may transfer, process and store personal data necessary for handling the payment outside the EU. The transfer of the data necessary for payment processing to Stripe takes place for the performance of the contract on the basis of Art. 6(1)(b) GDPR. Stripe processes data in the context of payment handling in accordance with its own privacy provisions and may, where necessary, act as an independent controller. Further information on data processing by Stripe is available at stripe.com/privacy.
10. PayPal
On our website you can make payments via the payment service provider PayPal. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. If you select PayPal as the payment method, the data necessary for payment processing is transmitted to PayPal in encrypted form. This may include name, email address, billing data, payment amount, currency, transaction data and the details required for the selected payment method. Payment data such as access credentials to your PayPal account or complete payment instrument data is generally not visible to us. PayPal processes the data in accordance with its own privacy provisions and may, where necessary, act as an independent controller.
The transfer of the data necessary for payment processing to PayPal takes place for the performance of the contract on the basis of Art. 6(1)(b) GDPR. Further information on data processing by PayPal is available at paypal.com.
11. Special categories of personal data (health data)
In the course of using the Bold Bloom platform, information on physical or mental condition, emotions, personal thoughts or health conditions may be processed, in particular in coaching notes, session notes and mood and wellbeing surveys. Such information may constitute special categories of personal data, in particular health data, within the meaning of Art. 9(1) GDPR. The content is processed within the Bold Bloom platform and protected by additional technical and organisational measures. These include in particular application-side field encryption, role- and permission-based access controls and data isolation per coach. Access is limited to the respective authorised persons.
The processing of special categories of personal data takes place exclusively on the basis of explicit consent under Art. 9(2)(a) GDPR. Insofar as coaching-related content that may contain special categories of personal data is transmitted for the optional AI feature, that transfer likewise takes place only after prior explicit consent under Art. 9(2)(a) GDPR.
You can withdraw your consent at any time with effect for the future, using the corresponding settings in your account or by contacting us at info@bold-bloom.com. The lawfulness of processing carried out on the basis of consent up to the withdrawal remains unaffected.
This processing has been subjected to a Data Protection Impact Assessment (DPIA) under Article 35 GDPR. The DPIA documents the legal basis, risk and mitigation assessment, and the review schedule; it is made available on request to the controller contact listed above.
12. Bug reports, error telemetry and support
In the case of technical errors, support requests and use of the platform, we may process in particular account data, the time and type of the request or error report, details of the browser or device used, technical log data, information on the features concerned and the descriptions and attachments you voluntarily submit. Depending on the content of a support request or error report, personal data may also be included. To detect, analyse and remedy technical errors we use the Sentry service of Functional Software, Inc. dba Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, for error tracking, and Better Stack (Logtail) for aggregating technical log data. Sentry processes personal data on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Insofar as personal data is transferred to Functional Software, Inc. dba Sentry in the USA, the transfer is based on the European Commission's adequacy decision for the EU–US Data Privacy Framework under Art. 45 GDPR. Functional Software, Inc. participates in the EU–US Data Privacy Framework. Personal data is pseudonymised or masked before transmission where technically possible.
Insofar as processing is necessary for providing support, handling reported errors and providing the platform in accordance with the contract, it is based on Art. 6(1)(b) GDPR. Insofar as processing serves to ensure IT security, stability and the further development of the platform, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, error-free and reliable provision of the platform.
13. AI features
For the provision of the optional AI-assisted features, in particular "AI Session Proposal", the AI-assisted team analysis and the Coaching Toolkit evaluations, the content selected or entered by the coach for that purpose, including technical context data, is transmitted to Mistral AI SAS, 15 Rue des Halles, 75001 Paris, France. Processing takes place within the European Union.
Processing for the provision of the AI feature requested by the coach is based on Art. 6(1)(b) GDPR. Insofar as coaching-related content is processed in the context of the feature that may contain special categories of personal data within the meaning of Art. 9 GDPR, the transfer takes place exclusively after prior explicit consent under Art. 9(2)(a) GDPR. Insofar as processing serves IT and system security, the detection and prevention of misuse or error analysis, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, performant and contractually compliant provision of the platform.
14. Google OAuth and Google Calendar integration
Where you activate the optional sign-in via your Google account or the optional Google Calendar integration, we process the data necessary for authentication and the respective integration. This may include name, email address, Google account ID, OAuth access and refresh tokens and — where the calendar integration is active — the calendar data necessary to display or manage calendar appointments. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The connection can be disconnected at any time in the account settings or in the settings of your Google account.
Processing for the provision of the sign-in or calendar feature actively requested by you is based on Art. 6(1)(b) GDPR. Google processes personal data on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Insofar as personal data is transferred to the USA, the transfer is based on the European Commission's adequacy decision for the EU–US Data Privacy Framework under Art. 45 GDPR, as Google LLC participates in the EU–US Data Privacy Framework.
15. Slack and Microsoft Teams webhooks
You can optionally have notifications from the Bold Bloom platform delivered to a Slack or Microsoft Teams workspace you have set up. The information necessary for the respective notification — in particular details of the triggering event, any names or designations and the content you selected in the integration — is transmitted to the connected service. Transmission takes place exclusively where you have actively set up the respective integration. The providers are Slack Technologies, LLC, 500 Howard Street, San Francisco, CA 94105, USA, and Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA.
Processing for the provision of the integration feature you have activated is based on Art. 6(1)(b) GDPR. Slack and Microsoft process personal data in the context of the respective integration on the basis of suitable contractual data protection safeguards. Insofar as personal data is transferred to the USA, the transfer takes place — where the conditions are met in the individual case — on the basis of the EU–US Data Privacy Framework under Art. 45 GDPR; in addition or where necessary, the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR are used. Microsoft participates in the EU–US Data Privacy Framework. According to its own information, Slack participates in the EU–US Data Privacy Framework via Salesforce, Inc., 415 Mission Street, 3rd Floor, San Francisco, CA 94105, USA.
16. Better Stack (Logtail)
For aggregating, evaluating and storing technical log data we use Better Stack (formerly Logtail). The provider is Better Stack, Inc., 651 N Broad St, Suite 206, Middletown, DE 19709-6402, USA. This may involve technical log data, timestamps, IP addresses, error and status information and other metadata necessary for the analysis, stability and security of the platform. Personal data is pseudonymised or masked before transmission where technically possible.
Insofar as processing is necessary to ensure the stability, security and error analysis of the platform, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and error-free provision of the platform. Better Stack processes personal data on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Insofar as personal data is transferred to Better Stack, the transfer is based on the European Commission's adequacy decision for the EU–US Data Privacy Framework under Art. 45 GDPR. Better Stack participates in the EU–US Data Privacy Framework.
17. Recipients of personal data
Beyond the sections above, personal data is passed on only to our staff.
Otherwise your personal data is not passed on to third parties without your express consent, unless we are legally obliged to do so within the meaning of Art. 6(1)(c) GDPR or the disclosure is strictly necessary for the performance of a contractual relationship under Art. 6(1)(b) GDPR.
Bold Bloom maintains a Record of Processing Activities (ROPA) under Art. 30 GDPR documenting all processing purposes, data categories, recipients, third-country transfers, and retention periods. The ROPA is reviewed at least annually and is available on request to the controller contact listed above.
A written engagement under Art. 28(3) GDPR exists with every processor named here. The contractual evidence (the vendor's standard DPA URL, the DPA acceptance date, the DPA version, the internal contract owner and the next review date) is maintained in an internal Sub-Processor DPA Register and reviewed at least annually. The register is made available for inspection on a justified request.
18. Storage periods
We delete your data as follows:
- Technical application and error logs: 14 days — error analysis, stability and IT security
- App activity logs: 30 days — usage analysis and error resolution
- Session data and session identifiers: 30 days — management and protection of sessions
- Login activity logs including IP address and device information: 90 days — detection and investigation of unusual sign-ins and account security
- Fraud signals and misuse indicators: 90 days — misuse and fraud prevention
- Audit and administration logs: 365 days — traceability of security-relevant and administrative operations
- Account, registration, contract and usage data as well as coaching notes, session notes, mood and wellbeing surveys and other platform content: for the duration of the contractual relationship, thereafter generally at the latest 30 days after the end of the contract — subject to statutory retention obligations or a differing instruction from the controller
- Guest identities in retrospectives, in particular display name and figure: 30 days — conduct and provision of retrospectives
- OAuth and calendar connection data: until the respective connection is disconnected, the token expires or is revoked, or the account is deleted
- Support requests and support communication: 365 days — handling enquiries, resolving errors and evidencing the communication
- Email delivery events, in particular dispatch and delivery status: 90 days — ensuring and evidencing the delivery of system emails
- Invoicing, payment and billing data as well as invoice files: up to 8 years — fulfilment of commercial and tax retention obligations
- Payment instrument data, in particular complete card or PayPal credentials: not stored by us — processing takes place at Stripe or PayPal under their own retention periods
- Voucher redemptions: anonymised after 730 days — management and evaluation of vouchers
- Files from Article 20 GDPR data exports: 30 days — provision of data exports
- Backups: 7 days — data backup and restoration in the event of a fault
- Cookie, language and consent settings: until the respective cookie expires, the setting is changed or it is deleted manually in the browser
Statutory commercial and tax retention duties differ by record type: booking vouchers and invoices generally eight years, commercial and business letters generally six years, annual financial statements, inventories and comparable records generally ten years.
Beyond that, we review annually whether the data stored about you can be deleted. Commercial and tax retention obligations remain unaffected.
19. Rights of data subjects
You are not legally obliged to provide your personal data. Provision may, however, be necessary for concluding a contract or for functions of the website. If data is not provided, a contract or a function on the website may not be available.
There is no automated decision-making on the website, and no profiling takes place.
The rights of data subjects follow in particular from Articles 15 to 23 and Article 77 GDPR and from §§ 32 to 37 of the German Federal Data Protection Act (BDSG). In relation to your personal data you have the right to
- information, Art. 15 GDPR
- rectification, Art. 16 GDPR
- erasure, Art. 17 GDPR
- restriction of processing, Art. 18 GDPR
- portability, Art. 20 GDPR
If you have given consent to the processing of personal data, you have the right of withdrawal under Art. 7 GDPR with effect for the future.
You further have the right to object to the processing of personal data under Art. 21 GDPR:
1. You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR (processing based on a balancing of interests). If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
2. In individual cases we process personal data for direct marketing. Where this applies to you, you have the right to object at any time to processing of data concerning you for such marketing. If you object to processing for direct marketing purposes, we will no longer process your personal data for those purposes.
The objection is not subject to any particular form and should preferably be addressed to the contact details given in section 1.
If you consider that the processing of personal data concerning you infringes data protection law, you always have the right to lodge a complaint with the competent supervisory authority under Art. 77 GDPR. Without prejudice to any other administrative or judicial remedy, this right applies in particular in the Member State of your residence, place of work or the place of the alleged infringement.
The contact details of the supervisory authorities can be found in the BfDI list of addresses.
The supervisory authority competent for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Version: 2026-09-12