Privacy Policy
Update cookies preferences
Privacy Policy – Psytrance Blueprint
Privacy Policy – Psytrance Blueprint
Privacy Policy
Effective date: 9 July 2026
Important: This Privacy Policy applies only to customers and users outside of Germany .
For customers in Germany, please refer to the separate German Datenschutzerklärung (DSGVO) .
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our websites, purchase our products, or use our services (collectively, the “Services”).
By using the Services, you acknowledge this Policy. If you do not agree, please do not use the Services.
1) Controller / Contact
Controller: Andreas Geißinger, Schumannstr. 9, 81679 Munich, Germany
Email: psiger.records@gmail.com | Phone: +49 176 52477009
No statutory data protection officer is required. For privacy questions, contact us via the email above.
2) Scope
This Policy applies to our websites and online offerings related to “Psytrance Blueprint”, including live Zoom sessions, optional video feedback, and community features (e.g., Discord).
Third-party sites linked from our Services are governed by their own privacy notices.
3) Categories of Data We Process
Account & Contact Data: name, email address, billing address (if provided).
Contract & Payment Data: plan purchased, subscription status, invoices, transaction IDs (card details are handled by payment providers).
Communications: emails/support requests; optional community interactions (e.g., Discord username, messages you post).
Service Usage & Tech Data: IP address, timestamps, pages visited, referrer, device/browser type, session IDs, essential cookies.
Learning-Related (optional): materials you submit for feedback (e.g., audio/project files), participation info for live sessions (display name, chat posts).
4) Purposes and Legal Bases
Provide & operate the Services (incl. live sessions, account admin, optional feedback) — GDPR Art. 6(1)(b) (contract).
Payments, invoicing, tax/audit — Art. 6(1)(b) & (c) (contract & legal obligation).
Support & communications — Art. 6(1)(b) or (f) (contract or legitimate interest in effective communication).
Security, fraud prevention, abuse monitoring — Art. 6(1)(f) (legitimate interests).
Analytics (Google Analytics) — Art. 6(1)(a) (consent via cookie banner; IP anonymisation enabled).
Marketing & advertising (e.g., Meta, TikTok, Reddit) — Art. 6(1)(a) (consent via cookie banner).
Compliance & legal claims — Art. 6(1)(c) & (f) .
5) Cookies & Consent
We use essential cookies for core functionality (e.g., login, CSRF protection). These are strictly necessary.
Non-essential cookies (analytics/advertising) are used only with your prior consent through our cookie/consent banner. You can withdraw consent at any time with future effect.
You can also control cookies via your browser settings; disabling essential cookies may impair functionality.
6) Processors / Recipients
Hosting & delivery: Cloudflare, Inc. (USA) — site hosting (Cloudflare Pages/Workers), CDN, server logs, attack mitigation. Cloudflare is certified under the EU-US Data Privacy Framework; SCCs apply additionally.
Bot protection: Cloudflare Turnstile — verifies that opt-in form submissions come from a real person and sets strictly necessary cookies for this (__cf_bm, _cfuvid). Legal basis: legitimate interest (Art. 6(1)(f) GDPR, security); no consent required for strictly necessary cookies.
Email delivery: Amazon Web Services EMEA SARL — Amazon SES, EU region (Frankfurt); transactional emails and, only with your consent, newsletter/marketing emails. Every email contains an unsubscribe link.
Video Conferencing: Zoom Video Communications, Inc. (USA) — live sessions; SCCs.
Community: Discord, Inc. (USA) — optional community access; own terms/privacy apply; SCCs.
Payments: Stripe — processes payments as an independent controller for card data; we receive transaction metadata (status/IDs).
Analytics (consent-based, withdrawable at any time): PostHog Inc. — EU-hosted (Frankfurt) product analytics; session replay only with separate consent, with form inputs masked. Microsoft Clarity — heatmaps and interaction recordings for usability research; US transfer under the EU-US Data Privacy Framework.
Advertising (separate consent): Google Analytics and the Meta Pixel for campaign measurement; these tags never load without consent and stay inactive unless a campaign is configured.
Video embeds: YouTube in privacy-enhanced mode (youtube-nocookie.com); the player loads only after you click. Your IP address is transmitted to Google when the preview image and the video load.
Advisors/Authorities: legal, accounting, tax advisors; law enforcement/regulators where legally required.
7) International Data Transfers
Where data is transferred outside the EU/EEA/UK (e.g., to the USA), we rely on appropriate safeguards such as the EU Commission’s Standard Contractual Clauses (SCCs) and additional measures (data minimisation, encryption where feasible).
Copies of the relevant SCCs can be requested via the contact above.
8) Retention
We retain personal data only as long as necessary for the stated purposes, to comply with legal obligations, or to establish/exercise/defend legal claims.
Typical periods: contract/account data for the term of the subscription plus statutory retention (usually 6–10 years for tax); server logs 7–30 days (longer if needed for security); cookies per your consent settings.
9) Your Rights
EU/UK residents (GDPR/UK GDPR): right of access, rectification, erasure, restriction, portability, and objection; right to withdraw consent at any time with future effect.
You also have the right to lodge a complaint with a supervisory authority, e.g., in Germany: Bavarian DPA (BayLDA), Promenade 18, 91522 Ansbach, https://www.lda.bayern.de .
Other regions: depending on your location, you may have additional rights under local laws. We will honour applicable legal rights upon request.
To exercise your rights, contact: psiger.records@gmail.com .
10) Children
Our Services are not directed to individuals under 18. We do not knowingly collect personal data from minors. If we learn that we have collected such data, we will delete it.
11) Security
We implement appropriate technical and organisational measures to protect personal data. No method of transmission over the Internet or electronic storage is completely secure.
12) “Do Not Track”
Some browsers offer a “Do Not Track” (DNT) signal. Our Services do not currently respond to DNT signals.
13) Changes to This Policy
We may update this Policy from time to time. The current version is indicated by the “Effective date” above.
14) Contact
Questions or requests? Email us at psiger.records@gmail.com or write to: Andreas Geißinger, Schumannstr. 9, 81679 Munich, Germany.