Last updated: July 27, 2026
This Privacy Policy explains how V‑IZ (“we”, “us”) collects, uses and discloses your personal data when you visit our website (v-iz.de) or web application (v-iz.de/app/), use our mobile app (iOS/Android) or use our services. For the purposes of the General Data Protection Regulation (GDPR), V‑IZ is the controller.
Responsible person within the meaning of the GDPR:
V‑IZ Video-Integrationszentrum
Owner: Fuat Karacocuk
S3 2A
68161 Mannheim
Germany
Telephone: 07131 8882719
WhatsApp: 01523 2756171
Email: info@v-iz.de
1. WHAT DATA WE COLLECT
Depending on how you use our services (website or app), we collect different types of data.
1.0 Free use without an account
You can use the free part of V‑IZ at v-iz.de/app/ without logging in and without creating an account. The following applies:
- We will not create an account for you. We do not ask for your name or email address.
- Your learning progress (e.g. vocabulary learned, exercises completed, daily portion of AI exercises) is saved only locally on your device, i.e. in local storage in the browser. This data is not on our servers. If you delete the browser data, the progress is gone.
- If you start an AI exercise, your input will be sent to our AI service provider for processing (see section 5.2). In order to limit the free daily amount and prevent misuse, we process your IP address only as a hash value.
- As with every website visit, technical data is generated when you access the page (see section 1.2).
Legal basis: The free functions are provided in accordance with Article 6 Paragraph 1 Letter b GDPR. Saving your progress on your own device is absolutely necessary for the service you want and therefore does not require consent in accordance with Section 25 Paragraph 2 No. 2 TDDDG. We base the processing of the IP hash value to prevent misuse on our legitimate interest (Art. 6 Para. 1 lit. f GDPR).
As soon as you create an account, sections 1.1 to 1.3 also apply.
1.1 Information you provide to us
- Account Information & Order details: Name, email address, password and billing address. The paid services are provided digitally.
- Communication: Content of support requests or feedback.
- Exercise data (AI): Texts that you enter for correction, audio recordings for pronunciation exercises and photos of handwritten letters (at Premium).
1.2 Automatically collected data (app & website)
- Usage data: Learning progress, lessons completed, exam results, token status.
- Device Information & Logs: Device model, operating system, IP address, time zone, unique device identifiers (device IDs) and crash logs. This data is technically necessary to provide the app in a stable manner and to prevent misuse (e.g. account sharing).
- Transaction data: Purchase history, subscription status or booked product (Premium or video course with level), billing period and expiration date of access.
1.3 Data from payments & In-app purchases
Website (v-iz.de): When you order through our website (Premium or a video course, as a subscription or a one-time purchase), V‑IZ does not store your credit card, Apple Pay or Google Pay details. They are processed directly by our payment service provider Stripe (Stripe Payments Europe Limited, Ireland). This also applies to recurring subscription payments. Stripe sends us only the information required to perform the contract, such as payment confirmation, the activation signal, the product booked and the invoice data needed to issue your receipt.
Mobile app (iOS / Android): If you make an in-app purchase, we do not process the payment data. Apple (App Store) or Google (Play Store) handles it directly as an independent controller. We receive only technical confirmation via RevenueCat (see Section 5.2) so that we can synchronize your account status.
1.4 Minors
Our services are generally aimed at people aged 18 and over. For minors, we require the consent of their legal guardians.
1.5 Reviews (ratings)
If you submit a review on v-iz.de, we process the following information: star rating, review title and text, display name and email address, together with your IP address and the time of submission. After review, we publish only the star rating, title, text and display name and, where applicable, the label “Verified purchase”. We do not publish your email address or IP address; we use them internally only to verify a purchase and prevent misuse or spam. The legal basis is your consent (Article 6(1)(a) GDPR), which you give when submitting the review. You may withdraw this consent at any time by emailing info@v-iz.de; we will then remove the review promptly.
2. ACCESS TO DEVICE FUNCTIONS (AUTHORIZATIONS)
In order for the app to function fully, we need access to certain hardware components. You can manage these permissions in your device's settings.
- Microphone: Required for pronunciation training and dialogue simulations. Audio recordings are transmitted to our AI service providers (see section 5.2) for speech analysis. We do not store the recordings permanently; only the analysis result (e.g. pronunciation assessment, correction notes) is assigned to your learning progress and stored in our database. The audio data can remain with the AI provider for a short time to detect misuse (see section 5.2).
- Camera/Photo Gallery: Required (at Premium) to upload photos of handwritten letters for correction. The images are stored in our Supabase database and sent to our AI service provider (Google Vertex AI, see section 5.2) for content analysis. The images will remain associated with your account until you delete them or delete your account.
3. COOKIES AND TRACKING
3.1 On the website: We differentiate between three categories:
- Necessary: We need these technologies for the website and web application to function at all (e.g. login, session management, security, saving your cookie decision). According to Section 25 Paragraph 2 No. 2 TDDDG, you do not require consent.
- Statistics: Google Analytics 4 and Microsoft Clarity. These services are loaded only after you consent to the Statistics category.
- Marketing: Google Ads and the Meta Pixel. These services are loaded only after you consent to the Marketing category.
No transmission will take place to Google, Meta or Microsoft without your consent. The corresponding scripts are then not even loaded, so no request is sent to these providers.
Click identifiers from advertisements: If you come to us via an ad, the advertising provider appends an identifier to the address (e.g. "gclid" on Google, "fbclid" on Meta). We store this identifier only after your consent to the marketing category in your browser for 90 days. It is used to assign a later purchase to the correct ad. It will not be stored without marketing consent.
3.2 In the mobile app: We use technology to monitor app stability and store your learning progress. Tracking for advertising purposes only takes place if you have expressly agreed to this (e.g. via App Tracking Transparency on iOS).
3.3 Revocation: You can revoke or change your consent at any time via the “Cookie Settings” link in the footer of the website or via the system settings of your device. A revocation has effect for the future.
4. HOW WE USE YOUR DATA (PURPOSE & LEGAL BASIS)
We process your data on the basis of the GDPR for the following purposes:
- Fulfillment of the contract (Art. 6 Para. 1 lit. b GDPR): Providing the free and paid functions, sending the digital book codes by email, synchronizing learning progress, making AI corrections, managing your subscription or one-time purchase and processing payments.
- Legitimate interest (Art. 6 Para. 1 lit. f GDPR): Preventing fraud and account sharing (device tracking), improving app stability (error logs), IT security.
- Consent (Art. 6 Para. 1 lit. a GDPR): For optional marketing newsletters, reach analysis and advertising tracking (see section 5.2) as well as specific device access.
- Legal obligation (Art. 6 Para. 1 lit. c GDPR): Storage of tax data (invoices).
You do not have to provide us with any data to use it free of charge. Account and login details as well as billing details are required for paid services. Without this data we cannot provide paid access, send the book codes or issue an invoice.
5. DISCLOSURE TO THIRD PARTIES & TECHNICAL INFRASTRUCTURE
We use specialised service providers. Where they process personal data on our behalf, we have concluded data processing agreements pursuant to Article 28 GDPR.
5.1 Recipient categories
Recipients of your data include, in particular, hosting providers, payment providers, database services, AI providers, analysis and advertising services as well as email sending services.
5.2 Specific Services
- Payment service provider (Stripe): Stripe Payments Europe Limited (Ireland) processes card payments and wallet payments (Apple Pay, Google Pay) for us. Stripe is independently responsible for the payment data; we receive technical confirmations, the purchase/activation signal and billing data. Data protection information from Stripe: https://stripe.com/de/privacy.
- Database & Authentication (Supabase): Supabase Inc. (USA) provides our backend for user accounts, password-based login and learning progress.
- Hosting (Netlify): Netlify Inc. (USA) hosts our website and web application.
- In-app subscription management (RevenueCat): RevenueCat Inc. (US) manages the synchronization of in-app subscriptions purchased through the Apple App Store and Google Play Store with your V‑IZ account. In particular, app store transaction IDs, subscription status and device identifiers are processed.
- Email sending (Resend): Resend (Resend Inc., USA) sends transactional emails such as order confirmations, registration links, invoices and reminders on our behalf. Your email address, your name and, if applicable, order information will be processed.
- AI services (Google Vertex AI): For text and speech analysis in our AI trainer functions, we use Google Vertex AI (Google Cloud EMEA Limited, Ireland), including models from the Gemini family and Google Cloud speech synthesis. Your input (text entered, audio recordings and uploaded photos) is sent to Vertex AI for processing. Processing takes place in Google Cloud’s EU multi-region, so your input is processed and stored within the European Union. Google processes this data on our instructions as a processor. Under the terms applicable to Vertex AI, customer data is not used to train the models. Short-term caching may be used to detect misuse. More information: https://cloud.google.com/terms/data-processing-addendum
- Automation (Zapier): Zapier Inc. (USA) connects individual systems for us and automates internal processes relating to orders and support. The data required for the respective process is processed, in particular email address, name and order information. Zapier acts as a processor for us. Data protection information: https://zapier.com/privacy
- Microsoft Clarity (analysis): We use Microsoft Clarity (Microsoft Ireland Operations Limited) to analyze user behavior and improve our website. Clarity creates session recordings (mouse movements, clicks and scrolling behavior) and heatmaps. Sensitive input fields are automatically masked. Clarity is loaded only after you consent to the Statistics category (Art. 6(1)(a) GDPR). Nothing is transmitted to Microsoft without this consent. More information: https://privacy.microsoft.com/de-de/privacystatement
- Google Ads & conversion tracking: We use Google Ads (Google Ireland Limited) to advertise our offers and measure conversions. Google Ads is loaded only after you consent to the Marketing category (Art. 6(1)(a) GDPR). Only then is a conversion measurement cookie set, the click identifier “gclid” stored (for 90 days; see Section 3.1), and information about click and conversion events and your device and browser environment transmitted to Google. No request is sent to Google Ads without marketing consent. More information: https://policies.google.com/privacy
- Google Analytics 4 (Firebase): To measure reach and analyze website usage, we use Google Analytics 4 (Google Ireland Limited), which is technically part of our Firebase/Google Analytics project. The pages accessed, approximate origin, device and browser environment as well as interaction events (e.g. page view, checkout start, purchase completion) are recorded in a pseudonymized form. Google Analytics 4 is loaded only after you have consented to the Statistics category (Art. 6 Para. 1 lit. a GDPR). Without this consent, nothing will be transmitted to Google, including no cookieless or aggregated signals. More information: https://policies.google.com/privacy
- Meta Pixel (Facebook/Instagram): We use the Meta Pixel (Meta Platforms Ireland Limited) to measure the effectiveness of our advertising campaigns on Facebook and Instagram and for remarketing. The pixel transfers information about your visit and interactions (e.g. registrations) to Meta. Meta and V‑IZ are jointly responsible for the collection and transmission of this data within the meaning of Art. 26 GDPR. The Meta Pixel is loaded only after you have consented to the Marketing category (Art. 6 Para. 1 lit. a GDPR). Only then is the click identifier “fbclid” saved (90 days, see section 3.1). No request is sent to Meta without marketing consent. More information: https://www.facebook.com/privacy/policy
6. INTERNATIONAL DATA TRANSFERS
Some of our service providers (e.g. Supabase, Netlify, Resend, RevenueCat, Zapier, Google, Meta, Microsoft) are based in the USA or operate servers there. Stripe processes personal payment data primarily within the EU/EEA; however, individual processing steps can also rely on US servers.
AI processing: Our AI capabilities run through Google Vertex AI. The contractual partner is Google Cloud EMEA Limited based in Ireland. We have configured Vertex AI to process in the EU multiregion. Your input into the AI trainers will therefore be processed and stored within the European Union. If a transfer to a third country occurs as part of operation and support, the following guarantees apply.
- If the provider is certified under the EU-US Data Privacy Framework (DPF), we base the transmission on this adequacy decision.
- Otherwise, we use the Standard Contractual Clauses (SCCs) of the EU Commission and take additional security measures if necessary.
7. STORAGE PERIOD
We only store data for as long as is necessary for the respective purpose:
- Purchase receipts & Invoices: 10 years (legal retention period).
- Account details: Until you delete the account.
- Security logs (IP/Device IDs): Are usually deleted or anonymized after 30 days. If there is a legitimate suspicion of misuse (e.g. unauthorized access, fraud), we store the affected logs for a maximum of another 90 days to clarify the matter; then deletion or anonymization takes place.
- Audio recordings (pronunciation): We do not store them permanently; only the analysis result remains.
- Photo uploads (letter corrections): Remain assigned to your account until deleted by you or when the account is deleted.
- Click identifiers from advertisements (gclid, fbclid and similar): 90 days in your browser’s local storage, and only if marketing consent has been given. They are then automatically deleted. How long Google or Meta stores the data they generate depends on the specifications of these providers.
8. YOUR RIGHTS
You have the following rights according to the GDPR:
- Access (Article 15), rectification (Article 16), erasure (Article 17).
- Restriction of processing (Article 18) and data portability (Article 20).
- Right to object (Article 21): You can object to processing at any time based on legitimate interests.
- Right to complain: You have the right to complain to a data protection supervisory authority (Article 77 GDPR).
- Automated decisions (Article 22 GDPR): We use automated procedures only to detect account sharing, for example an unusually large number of devices used at the same time or geographically implausible login patterns. If misuse is suspected, the account may be blocked temporarily. You may request a manual review by our support team, present your point of view and challenge the decision at any time. We do not currently make decisions based solely on automated processing within the meaning of Article 22 GDPR, such as a decision on eligibility to enter into a contract.
- Revocation of consent: If we process data based on your consent, you can revoke it at any time with future effect.
Account deletion: You can delete your account yourself at any time in your account area (v-iz.de/app/konto), in our mobile app under "Profile > Delete account" or by email to info@v-iz.de. After deletion, personal data will be treated in accordance with Section 7; invoices are subject to the statutory retention requirement.
9. CONTACT
Responsible person within the meaning of the GDPR:
V‑IZ Video-Integrationszentrum
Owner: Fuat Karacocuk
S3 2A
68161 Mannheim
Germany
Telephone: 07131 8882719
WhatsApp: 01523 2756171
Email: info@v-iz.de
No data protection officer has been appointed because V‑IZ is not currently required to appoint one under Section 38 BDSG.