Privacy Policy
Last updated: 03.07.2026
1. General Information
This Privacy Policy explains how Varhor collects, uses, discloses and protects personal data when you visit our public website or access the member area after subscribing to our services.We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable German data protection laws (such as the Bundesdatenschutzgesetz – BDSG).
By using our website or creating a member account, you acknowledge that your personal data will be processed as described in this Privacy Policy.
2. Data controller
The data controller for the processing activities described in this Privacy Policy is:
info@varhor.com
Bismarckstraße 19A
32756 Detmold
Germany
3. Categories of personal data
We may process the following categories of personal data:
- Identification data
Name, email address, company, role, country or region and other information you provide during registration or communication. - Account and membership data
Username, encrypted password, membership level, subscription status, plan details, renewal dates and internal member ID. - Billing and payment data
Billing address, VAT or tax number where applicable, limited payment details (e.g. last 4 digits of card, transaction IDs).
Full payment card details are processed by our payment providers and are not stored by us. - Usage data and logs
IP address, device and browser type, operating system, access times, pages viewed, reports or areas accessed, search queries, click events, and general activity in the member area. - Communication data
Content of enquiries sent via contact forms or email, support tickets, and other correspondence with us. - Cookie and tracking data
Cookie identifiers, preferences, and aggregated analytics data as described in the “Cookies and tracking” section.
4. Sources of data
We obtain personal data:
Directly from you
When you register, subscribe, login, request information, contact support or otherwise use our services.Automatically
When you visit our public website or member area, certain data is automatically collected via log files, cookies, scripts and similar technologies.From service providers
Certain data elements (e.g. payment status, customer ID) may be provided by our integrated third‑party services.
5. Purposes and legal bases of processing
We process personal data for the following purposes and on the following legal bases under Article 6 GDPR:
- Provision of website and member area
- Purpose: To operate our public site, provide secure login, manage member accounts and deliver subscribed content.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) and legitimate interests (Art. 6(1)(f) GDPR) in operating a secure and functional platform.
- Subscription management, billing and payments
- Purpose: To manage subscriptions, process payments, handle invoices and account-related communication.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR), including tax and accounting rules.
- Analytics, service improvement and security
- Purpose: To analyse usage patterns, fix issues, improve performance and prevent misuse or attacks.
- Legal basis: Legitimate interests (Art. 6(1)(f) GDPR) in improving and securing our services.
- Communication and support
- Purpose: To respond to enquiries, provide member support, and handle requests.
- Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
- Marketing communications (optional)
- Purpose: To send newsletters or marketing information, where permitted.
- Legal basis: Consent (Art. 6(1)(a) GDPR) or legitimate interests (Art. 6(1)(f) GDPR), in accordance with applicable e‑privacy rules. You may opt‑out at any time.
- Legal compliance and enforcement
- Purpose: To comply with statutory obligations, respond to lawful requests, assert or defend legal claims.
- Legal basis: Compliance with legal obligations (Art. 6(1)(c) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
6. Cookies and tracking technologies
We use cookies and similar technologies on our website and member area. These may be:
- Essential cookies
Required for basic site functionality, login sessions, security and remembering mandatory preferences.
Legal basis: Performance of a contract and legitimate interests (Art. 6(1)(b) and (f) GDPR). - Functional and preference cookies
Used to remember region, language or display options.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR) and/or consent (Art. 6(1)(a) GDPR), depending on jurisdiction. - Analytics cookies
Used to collect aggregated statistics on usage and performance.
Legal basis: Consent (Art. 6(1)(a) GDPR), where required by law.
Where necessary, we display a cookie notice that allows you to accept or decline non‑essential cookies. You can also manage cookies through your browser settings, though disabling certain cookies may affect the functionality of our services.
7. Use of Memberstack
To provide secure access control, authentication and membership management, we integrate a third‑party service called Memberstack.
- Purpose
Memberstack is used to create and manage user accounts, handle login sessions, restrict access to member‑only content, and support subscription functionality. - Data processed via Memberstack
Memberstack may process your name, email address, encrypted password, membership level, internal user IDs, and data relating to login, session status and membership state. - Role of Memberstack
Memberstack acts as our service provider and processes personal data on our behalf under a data processing agreement. - International transfers
According to Memberstack’s documentation, data may be stored or processed in the United States or other countries. Where personal data is transferred outside the European Economic Area, appropriate safeguards, such as standard contractual clauses, are implemented to protect your data in line with GDPR requirements.
Further details can be found in Memberstack’s own privacy and legal documentation.
8.Other recipients of personal data
In addition to Memberstack, we may share personal data with:
- Payment service providers
For example: [Stripe, PayPal, other], to process transactions securely. - Hosting and infrastructure providers
For example: [your host / cloud provider], which operates servers and storage used by our website and member area. - Email and communication services
For example: [email provider, transactional email service], to send account‑related messages or support replies. - Professional advisers
Lawyers, tax advisers, auditors or other professionals, where necessary to protect our business and comply with law. - Authorities and regulators
Where required by law or to protect rights, safety and property.
All such recipients are carefully selected and bound by contractual obligations to protect personal data and comply with applicable data protection standards.
We do not sell personal data to third parties.
9.International transfers
Because we serve members worldwide and use global service providers, personal data may be processed in countries outside the European Union/EEA.
If data is transferred to a country without an EU adequacy decision, we implement appropriate safeguards in line with Articles 44–49 GDPR, such as:
- standard contractual clauses approved by the European Commission,
- additional technical and organisational measures where appropriate.
You may request further information about these safeguards using the contact details below.
10.Data retention
We retain personal data only for as long as necessary to achieve the purposes described in this Privacy Policy or as required by law.
Examples:
- Account and membership data
Stored for the duration of your membership and for a reasonable period thereafter, e.g. to manage reactivation or resolve disputes. - Billing and payment data
Stored in accordance with statutory retention periods under tax and commercial law (typically 6–10 years). - Logs and analytics data
Stored only as long as necessary for security, performance and service improvement, then deleted or anonymised.
Once data is no longer needed, we delete or anonymise it, subject to technical and legal constraints.
11.Your rights under GDPR
As a data subject, you have the following rights, subject to the conditions and limitations in the GDPR and national law:
- Right of access (Art. 15 GDPR)
To obtain confirmation as to whether we process personal data about you and to receive a copy of such data. - Right to rectification (Art. 16 GDPR)
To have inaccurate or incomplete personal data corrected. - Right to erasure (Art. 17 GDPR)
To request deletion of personal data in certain circumstances, for example where it is no longer necessary or processing is unlawful. - Right to restriction of processing (Art. 18 GDPR)
To request that we limit processing in specific situations. - Right to data portability (Art. 20 GDPR)
To receive personal data you provided to us in a structured, commonly used and machine‑readable format and to transmit it to another controller, where technically feasible. - Right to object (Art. 21 GDPR)
To object, on grounds relating to your particular situation, to processing based on legitimate interests, including profiling. You also have the right to object to direct marketing. - Right to withdraw consent (Art. 7(3) GDPR)
If processing is based on consent, you may withdraw it at any time with effect for the future.
To exercise these rights, please contact us using the details in the “Contact” section below. We may need to verify your identity before fulfilling your request.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement. In Germany, this is typically the competent data protection authority of your federal state.
12.Security measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including:
- encrypted transmission (e.g. HTTPS/TLS),
- access controls and role‑based permissions,
- regular updates and monitoring of our systems,
- internal policies and awareness measures.
Despite these measures, no online system can guarantee absolute security. We continuously review and improve our safeguards to reduce risk.
13.Member accounts and responsibility
If you hold a member account:
- You are responsible for keeping your login credentials confidential.
- You should choose a strong password and not reuse it across other services.
- You must inform us promptly if you suspect unauthorised access or misuse of your account.
We reserve the right to suspend or terminate accounts that pose a security risk or violate our terms.
14.Third‑party websites
Our website or reports may contain links to third‑party websites or services.We are not responsible for the privacy practices or content of such third parties. We recommend that you review their privacy policies before providing any personal data.
15.Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example to reflect changes in our services, legal requirements or guidance.The “Last updated” date at the top of this page indicates the most recent revision. Material changes may be communicated via the website, member area or email.
16.Contact
If you have questions about this Privacy Policy or how we handle personal data, please contact:
info@varhor.com
Bismarckstraße 19A
32756 Detmold
Germany