Skip to content
Die Ausbilder Ghribi & Werner
Operator cardBriefingFor employers
DEEN
Get the app
Last updated: 27 September 2026

Privacy policy

This is a courtesy translation. Only the German version is legally binding.

This page explains which personal data we process when you use the "Die Ausbilder" app (iOS and Android) or the website dieausbilderapp.com, why we need it, who else gets to see it and when we delete it.

In short: the app contains no advertising trackers, no audience measurement and no crash reporting to third parties. The website sets no cookies.

Contents
  1. Controller
  2. Website dieausbilderapp.com
  3. Account and sign-in
  4. Profile and digital operator card
  5. Verification by QR code
  6. Bookings, payments and invoices
  7. Annual safety briefing in the app
  8. Documents and uploaded files
  9. Reminders and push notifications
  10. Sending emails
  11. Servers, database and logs
  12. What the app stores on your phone
  13. App permissions
  14. Who else sees your data
  15. How long we keep data
  16. Your rights
  17. Required information and changes

Controller

Die Ausbilder Ghribi & Werner GbR
Butzweilerstraße 35-39
50829 Köln
Germany

Email: info@die-ausbilderkoeln.de · Phone: +49 178 1147496

We have not appointed a data protection officer as we are not legally required to. Please send any privacy question directly to the address above.

Website dieausbilderapp.com

The website is delivered via Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). When you open it, Cloudflare processes technically necessary connection data such as IP address, time, requested address and browser identifier to deliver the page and protect it against attacks. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).

To show the next training dates, course photos and trainer portraits, the page queries our server api.dieausbilderapp.com, which also receives your IP address. No cookies are set, nothing is stored in your browser and no usage statistics are collected. We serve fonts ourselves; there is no connection to Google Fonts.

Account and sign-in

You do not need an account to browse courses and dates. For bookings, your digital operator card and the safety briefing you create an account. Sign-in runs through Firebase Authentication by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). You can choose:

  • Email and password: Firebase stores your email address and your password in encrypted form and sends the email to confirm your address.
  • Sign in with Google: Google gives us your email address, your name and an identifier of your Google account.
  • Sign in with Apple (iPhone only): Apple gives us an identifier and an email address (if you wish, an anonymous relay address from Apple) and, the first time, your name.

We store your email address, whether it is confirmed, the sign-in methods you use and the Firebase identifiers. After sign-in our server issues its own access keys. So that the app does not keep signing you out, the key that renews your session is valid for 365 days and is renewed with every use. We also store when you last used the app.

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR). Google may also process data in the USA; Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR).

Profile and digital operator card

For your operator card and certificates we need: first and last name, date of birth, a passport photo and, if you provide them, company, phone number, address, driving licence classes and qualifications. For the card itself we store type and class, card number, issuer, issue and expiry date, the equipment you were trained on, the training dates and the status of your annual briefing.

Name, date of birth and photo are printed on the card. So that it stays meaningful, you cannot change them yourself once saved; write to us if something is wrong.

You can add licences from other providers yourself and back them up with a photo or PDF. We review the proof and mark the card as "External".

The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and, where we must retain training records, compliance with a legal obligation (Art. 6(1)(c) GDPR).

Verification by QR code

Every card has a QR code containing a random, unguessable link. Anyone who scans it sees, without the app and without signing in: your name, card number, type and class, issue and validity date, the equipment and the briefing status. The certificate can be downloaded as a PDF from the same page; it also shows your date of birth.

That is what the card is for: so that employers, supervisors or inspectors can quickly check that you may operate the equipment. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). Only show or send the code to people who are meant to check your qualification. Once the card or your account is deleted, the link stops working.

Bookings, payments and invoices

When you book a course, we store the booking with the participant details (name, date of birth, company, email and phone for confirmation and reminders), the payment method and the amount. On the training day we record that you attended and whether you passed the exam. If you are on a waiting list, we store the entry and whether a seat was offered to you.

Payments: for bank transfer and company invoice we process the details needed for matching (payment reference) and for the invoice (recipient, address, email). For company codes we store which code was redeemed for which booking so that the company’s contingent can be settled.

If the app offers "Pay now", the payment is handled by Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). You enter your payment details (e.g. card number) directly with Stripe; we never see them. We receive the payment status and create a Stripe customer record with your email address. Which payment methods Stripe shows depends on your device (e.g. card, Apple Pay, Google Pay). Stripe also processes data in the USA; Stripe, Inc. is certified under the EU-US Data Privacy Framework. For some purposes, such as fraud prevention, Stripe is a controller in its own right: https://stripe.com/privacy

The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). We retain invoices and accounting records for as long as commercial and tax law requires (§ 147 AO, § 257 HGB, currently up to ten years; Art. 6(1)(c) GDPR).

Annual safety briefing in the app

For every briefing attempt we store the questions drawn, your answers, start and end time, the score and whether you passed. The result is evaluated automatically (passed from 80 % correct answers). You can retake the briefing as often as you like. A passed attempt is noted on your card and stored as a record in your profile.

So that your answers are not lost without signal, they are also kept on your device until you submit. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

Documents and uploaded files

You can upload photos and PDFs, such as your passport photo, proof of licences or briefings from elsewhere and other documents (e.g. a driving licence or first-aid certificate). The files are stored on our server in Frankfurt am Main and can only be retrieved through time-limited, signed links our server creates for you or our staff. We look at uploaded proof in order to approve or reject it.

Please do not upload health data that the training does not require. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

Reminders and push notifications

So that no deadline slips, we remind you by email and push notification of your annual briefing (30 days, 7 days and 1 day before, on the due date and when overdue) and of booked dates (7 days and 1 day before). We also inform you about booking confirmations, received payments, date changes, seats freed up from the waiting list and the result of reviewed proof.

Occasionally we also send push notifications about courses and offers.

The app asks for your permission for push notifications on first start. If you agree, we store a push key for your device, the operating system and the device name. Notifications are delivered through the Expo push service (650 Industries, Inc., USA), which passes them on to Apple (APNs) or Google (Firebase Cloud Messaging). Transfers to the USA are based on EU standard contractual clauses (Art. 46(2)(c) GDPR). Notifications contain only a short text, no card or payment data.

Legal bases: for reminders and booking messages the performance of the contract (Art. 6(1)(b) GDPR); for push notifications and information on offers your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can switch push notifications off at any time in your phone’s settings.

Sending emails

We send our emails through the delivery service Resend (Resend, Inc., 2261 Market Street, San Francisco, CA 94114, USA) with servers in the EU (Ireland). Your email address and the content of the email are processed. Resend acts on our behalf (Art. 28 GDPR); any access from the USA is covered by EU standard contractual clauses (Art. 46(2)(c) GDPR).

The email confirming your address is sent by Firebase (Google), see "Account and sign-in".

Servers, database and logs

Our server runs at Render (Render Services, Inc., 525 Brannan St, San Francisco, CA 94107, USA) in its Frankfurt am Main data centre. The database is operated by MongoDB Atlas (MongoDB Ltd., Ballsbridge, Dublin 4, Ireland) in Frankfurt am Main. Cloudflare sits in front of the server as a protection and delivery network. All three act on our behalf (Art. 28 GDPR); any access from the USA is covered by EU standard contractual clauses or the EU-US Data Privacy Framework.

Every request to our server produces technical logs with IP address, time, requested address and device identifier (user agent). We need them to find errors and fend off attacks (e.g. by limiting requests per IP address) and delete them after a short time.

We also keep a change log recording who changed what and when on bookings, payments, cards and accounts, with IP address and device identifier. It serves as evidence towards participants, employers and authorities and protects against manipulation. When your account is deleted, we remove IP address and device identifier from your entries; the entry itself remains as a record.

The legal basis is our legitimate interest in secure and traceable operation (Art. 6(1)(f) GDPR).

What the app stores on your phone

So that your card works without signal, the app stores a copy of your profile, cards, bookings and payments as well as your passport photo on the device, plus your sign-in keys. This is technically necessary for the app to work as you expect (§ 25(2) no. 2 TDDDG). The app removes this data from the device when you sign out or delete your account.

App permissions

  • Camera and photos: only when you add a passport photo or a document. The app only accesses the image you choose or take.
  • Notifications: for reminders and information, see above.

The app does not use location, contacts or advertising IDs.

Who else sees your data

Within our company, only the people who need your data for booking, training, exams and billing see it, plus the service providers named above. Your card is also seen by anyone you show the QR code to. If you booked with a company code or your employer pays the invoice, the company learns that you used the seat. We do not sell data or pass it on for advertising.

How long we keep data

We keep your account data, cards, bookings, briefings and documents for as long as your account exists and remove them when you delete it. Exceptions are payments and invoices we must retain for tax and commercial reasons, and claims that are still open. How deletion works and exactly what remains is described at https://dieausbilderapp.com/en/delete-account

Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future, for example by switching off push notifications in your phone’s settings.

Just write to info@die-ausbilderkoeln.de.

You can also lodge a complaint with a data protection supervisory authority. Ours is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, https://www.ldi.nrw.de

Required information and changes

Without an account, name, date of birth and passport photo we cannot issue a card, and without contact details we cannot confirm a booking. All other information is voluntary.

We update this policy when the app or the law changes. The date at the top shows the current version.

Back to home

Die Ausbilder Ghribi & Werner
Die Ausbilder Ghribi & Werner GbR
Butzweilerstraße 35–39
50829 Köln
Legal
Legal noticePrivacyTermsWithdrawalDelete account
Contact
info@die-ausbilderkoeln.de0178 1147496 (Mourad Ghribi)0177 8024828 (Sascha Werner)die-ausbilderkoeln.de
© 2026 Die Ausbilder Ghribi & Werner GbR