Privacy Policy

Inhaltsverzeichnis

1. Data Controller

The controller responsible for processing personal data in connection with this website and our consulting, training, and coaching services is:

Arabia Interculture
Ahmed Hussein
Zu den Mühlen 4
53783 Eitorf
Germany

Telephone: +49 (0) 2243 916 28 28
Email: info@arabia-interculture.com
Website: https://www.arabia-interculture.com/

This Privacy Policy explains how we process personal data when you use our website, contact us, initiate a business relationship, or participate in our services.

2. General Principles of Data Processing

We process personal data only to the extent necessary to operate our website, communicate with individuals and organizations, deliver our services, comply with legal obligations, or pursue legitimate interests.

Depending on the processing activity, the following legal bases may apply:

  • Article 6(1)(a) GDPR: Consent of the data subject.

  • Article 6(1)(b) GDPR: Performance of a contract with the data subject or steps taken at their request before entering into a contract.

  • Article 6(1)(c) GDPR: Compliance with a legal obligation.

  • Article 6(1)(f) GDPR: Pursuit of legitimate interests, provided these are not overridden by the interests or fundamental rights and freedoms of the data subject.

Where special categories of personal data within the meaning of Article 9 GDPR are processed, an additional condition under Article 9(2) GDPR must be satisfied.

When organizations commission services for their employees, the processing of participants’ personal data is not automatically based on Article 6(1)(b) GDPR. Article 6(1)(f) GDPR may apply, provided its legal requirements are met.

Providing personal data is generally not required by law. However, without certain information, particularly names and contact details, we may be unable to respond to enquiries or deliver agreed services.

3. Website Hosting and Server Log Files

Our website is hosted by an external hosting provider using servers located in Germany.

When you visit our website, the following technical information may be processed automatically:

  • IP address of the accessing device

  • Date and time of access

  • Pages and files requested

  • Browser type and version

  • Operating system and device information

  • Referrer URL, where transmitted

  • Technical status and error messages

This processing is necessary to provide a secure and reliable website, maintain system stability, identify technical errors, and prevent misuse.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our website.

Server log files are automatically deleted after seven days. Any additional processing in connection with specific security incidents is subject to the applicable legal requirements.

4. Cookies and Similar Technologies

Our website uses cookies and similar technologies.

Some are necessary for essential website functions, language preferences, security, and consent management. Other technologies, particularly Google Analytics, are used only with the appropriate consent.

The storage of information on your device and access to such information are governed by Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).

For technologies that are not strictly necessary, we obtain consent under Section 25(1) TDDDG. The exemption under Section 25(2), No. 2 TDDDG applies to strictly necessary technologies where its conditions are met.

Real Cookie Banner

We use Real Cookie Banner to manage and document your consent choices.

The information processed may include a pseudonymous user identifier, the time and content of your decision, technical information, and your selected preferences.

The validity period of cookie consent is set to 365 days. Documented consent records are automatically deleted after 12 months.

Storage of IP addresses as part of consent documentation is disabled.

You can change or withdraw your consent at any time, with effect for the future, through the privacy settings on our website.

The legal basis for documenting consent is, in particular, Article 6(1)(c) GDPR in conjunction with the accountability requirement under Article 7(1) GDPR.

Further information about the cookies and services used is available in our website’s privacy settings.

5. Google Analytics

We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics helps us evaluate website usage statistically and improve our website’s content and functionality.

The information processed may include page views, interactions, session duration, technical browser and device characteristics, and approximate geographical information.

Google Analytics is controlled through our consent management system and is activated only after the relevant consent has been given.

The legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Consent may be withdrawn at any time with effect for the future.

The following retention settings are configured in Google Analytics:

  • Event data: two months

  • User data: 14 months

The setting to reset the retention period upon renewed user activity is enabled.

These retention periods apply to the corresponding user-level and event-level data. Aggregated statistical reports may remain available for longer.

Personal data may also be processed in the United States in connection with Google Analytics. The applicable data protection safeguards govern such transfers.

Further information:

https://business.safety.google/privacy/
https://policies.google.com/privacy

6. Cloudflare Turnstile

We use Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, to protect our contact forms against automated submissions, spam, and misuse.

Turnstile is used on pages containing the relevant forms.

The information processed may include:

  • IP address

  • Browser and device information

  • Technical connection data

  • Information used to detect automated access

The purpose of this processing is to protect our forms and technical systems.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is preventing abusive access and automated form submissions.

Where Cloudflare Turnstile stores information on or accesses information from users’ devices, Section 25 TDDDG also applies.

We use the service as a security function. The exemption under Section 25(2), No. 2 TDDDG applies where the relevant technical processing is strictly necessary to provide the expressly requested form functionality.

Personal data may be transferred to Cloudflare in the United States. The applicable data protection safeguards govern such transfers.

Further information: https://www.cloudflare.com/privacypolicy/

7. Elementor and WPML

We use the WordPress plugins Elementor and WPML to design and operate our website.

Elementor supports the presentation and functionality of website elements and the processing of contact forms.

WPML enables the multilingual presentation of our website and may store information about the language selected by visitors.

This processing serves the provision of a functional, multilingual website.

The legal basis is Article 6(1)(f) GDPR.

Where information is stored on or accessed from users’ devices and is strictly necessary, Section 25(2), No. 2 TDDDG applies, provided its conditions are met.

The processing of contact form submissions is explained separately in Section 9.

8. Fonts

The fonts used on our website are hosted locally on our web server.

Loading these fonts does not establish a connection to Google Fonts or other external font providers.

9. Contact and Contact Forms

If you contact us by email, telephone, or through a contact form, we process the information you provide.

This may include:

  • Name

  • Organization and professional position

  • Email address and telephone number

  • Content of your enquiry

  • Additional information provided voluntarily

We use this information to respond to your enquiry, communicate with you, and, where applicable, prepare or carry out a business relationship.

The legal basis is Article 6(1)(b) GDPR where processing is necessary for pre-contractual measures taken at your request or for the performance of a contract with you.

For business enquiries submitted on behalf of an organization, Article 6(1)(f) GDPR may apply. Our legitimate interest is responding to business enquiries and communicating with professional contacts.

Storage of Contact Form Submissions

Information submitted through our contact forms is sent to us by email and is additionally stored in the WordPress database through Elementor Submissions.

These stored form submissions are manually deleted once they are no longer required to process the relevant enquiry.

Statutory retention obligations and other legal grounds for continued storage remain unaffected.

10. Email Communication via Microsoft 365

We use Microsoft 365 and Outlook for business email communication.

The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

The information processed may include names, email addresses, message contents, attachments, communication metadata, and technical connection information.

Processing serves the handling of enquiries, business communication, and the delivery of our services.

Depending on the circumstances, the legal basis is Article 6(1)(b), (c), or (f) GDPR.

Processing outside the European Economic Area cannot be excluded in connection with Microsoft services. The applicable legal requirements and contractual safeguards govern such transfers.

Further information: https://www.microsoft.com/privacy/privacystatement

11. Communication via WhatsApp

At the request of our contacts, we occasionally communicate through WhatsApp, a service provided by WhatsApp Ireland Limited, Ireland.

We use this communication channel particularly when you contact us through WhatsApp or when communication through this channel has been agreed.

The information processed may include telephone numbers, profile information, message contents, transmitted files, and communication metadata.

Depending on the circumstances, the legal basis is Article 6(1)(b) or (f) GDPR.

Confidential coaching content and special categories of personal data are not exchanged through WhatsApp.

You may request at any time that communication continue through another channel.

Further information: https://www.whatsapp.com/legal/privacy-policy-eea

12. Appointment Scheduling via Calendly and Cal.com

We use Calendly (Calendly LLC, USA) and Cal.com (Cal.com, Inc., USA) for online appointment scheduling.

The booking functions are not embedded directly into our website. Only when you click the relevant link are you redirected to the website of the respective provider.

The following information may be processed when booking an appointment:

  • Name

  • Email address

  • Selected appointment

  • Additional information voluntarily provided in the booking form

The information is used to organize and conduct the scheduled meeting and, where necessary, for related follow-up communication.

Depending on the circumstances, the legal basis is Article 6(1)(b) or (f) GDPR.

Booking data is manually deleted from the respective scheduling platform after the appointment has taken place and the associated follow-up communication has been completed, once the information is no longer required for these purposes.

Statutory retention obligations remain unaffected.

Further information:

https://calendly.com/privacy
https://cal.com/privacy

13. Business Enquiries, Proposals, and Contract Management

In the course of our business activities, we process personal data relating to contacts at companies, public institutions, educational organizations, and other entities.

This may include:

  • Names and professional contact details

  • Organization and professional position

  • Business correspondence

  • Information relating to enquiries and proposals

  • Contractual and organizational information

  • Billing-related information

Processing serves the initiation, organization, delivery, and invoicing of our services.

Depending on the circumstances, the legal basis is Article 6(1)(b), (c), or (f) GDPR.

Our legitimate interest includes conducting our business activities and communicating with professional contacts.

14. Participant Data in Training, Consulting, and Coaching

We process personal data relating to participants in our services.

We receive this information either directly from the individuals concerned or from the organization commissioning the relevant service.

The information processed may include:

  • Name

  • Professional contact details

  • Organization and professional position

  • Organizational information relating to participation

  • Information required for scheduling and delivering the service

Processing serves the preparation, organization, and delivery of the agreed services.

Where an organization commissions a service for its employees, Article 6(1)(f) GDPR may apply, provided its legal requirements are met.

Participant data is not used for newsletters or general advertising.

Assignment-related participant data is deleted after completion of the relevant assignment, unless statutory retention obligations or other legal grounds require continued storage.

Where participant data is not collected directly from the individuals concerned, we take account of the information obligations under Article 14 GDPR.

15. Confidentiality and Data Protection in Coaching

Individual coaching services may involve processing personal information relating to professional challenges, leadership behavior, personal development goals, and individual experiences.

Confidentiality and data protection are addressed in the relevant coaching agreement.

Information discussed during coaching is treated confidentially and processed exclusively within the scope of the agreed service.

Confidential coaching content is generally not disclosed to commissioning organizations or other third parties unless the individual concerned has validly agreed to a specific disclosure or another legal basis applies.

Where handwritten coaching notes are taken, they are used exclusively to support the coaching process. They are destroyed immediately after completion of the assignment.

Processing is based on the applicable legal basis under Article 6 GDPR.

Where special categories of personal data are involved, the requirements of Article 9 GDPR must also be satisfied. Any explicit consent required for such processing is obtained separately.

16. Online Training, Consulting, and Coaching via Zoom and Microsoft Teams

We use Zoom (Zoom Communications, Inc., USA) and Microsoft Teams (Microsoft Ireland Operations Limited, Ireland) for online sessions.

Sessions are conducted either through our own accounts or through videoconferencing systems provided by our clients.

The information processed may include:

  • Names and, where applicable, email addresses

  • IP addresses

  • Device and connection information

  • Meeting metadata

  • Audio and video data

  • Chat messages

  • Content shared during sessions

Processing serves the delivery of the agreed online session.

Depending on the circumstances, the legal basis is Article 6(1)(b) or (f) GDPR.

Responsibility under data protection law depends on how the session is organized and on the parties’ actual responsibilities.

Where sessions take place through a client’s systems, the client’s privacy information must also be taken into account.

Recordings

Online training and coaching sessions are generally not recorded.

Recordings are made only at the express request of the client and in accordance with the applicable data protection requirements.

Participants are informed before a planned recording begins. Where consent is required, it is obtained in advance.

Recordings may be made through the client’s videoconferencing systems or through Arabia Interculture’s own Zoom or Microsoft Teams accounts.

Where recordings are made through Arabia Interculture’s accounts, the respective provider’s cloud recording function is used.

Recorded audio, video, and, where applicable, presentation and chat content are initially stored on the provider’s systems.

Recordings are provided exclusively to the respective client for the agreed purpose.

Immediately after successful transfer, Arabia Interculture deletes the recordings from its own Zoom or Microsoft Teams cloud recording areas.

Any technical backup copies maintained by the videoconferencing provider are subject to that provider’s storage and deletion procedures.

Responsibility under data protection law and the legal basis for a recording depend on the actual responsibilities and the relevant contractual arrangements.

17. Personality Assessments and Diagnostic Instruments

As part of coaching, leadership development, and consulting services, diagnostic instruments may be used by agreement, including personality, leadership, and strengths assessments.

Assessments are administered through the platforms of the respective assessment providers. Their privacy policies apply additionally to the processing carried out through those platforms.

Participants generally receive their individual results directly from the respective provider.

Where participants voluntarily share their results during coaching or consulting, we process them only to the extent necessary for the agreed service and on an applicable legal basis.

Where special categories of personal data are involved, the additional requirements of Article 9 GDPR are observed.

Individual assessment results are not disclosed to commissioning organizations without an appropriate legal basis.

Our own working copies are deleted or destroyed after completion of the relevant assignment.

18. Cooperation with External Trainers, Coaches, and Consultants

Arabia Interculture works with qualified external professionals to deliver training, coaching, and consulting services.

These professionals provide their services within the objectives, content requirements, and organizational arrangements established by Arabia Interculture.

They retain a degree of professional and methodological independence in delivering their services.

Where necessary to prepare or carry out an assignment, Arabia Interculture provides the commissioned professionals with relevant participant information.

This generally includes:

  • Names

  • Professional positions

  • Professional contact details

Disclosure is limited to information required for the respective assignment.

Written confidentiality and data protection agreements are concluded with external professionals.

They are required to treat the participant information received as confidential, use it exclusively for the respective assignment, and delete it after completion, unless statutory retention obligations apply.

The classification of the relationship under data protection law depends on the parties’ actual tasks and responsibilities.

Where processing on behalf of a controller within the meaning of Article 28 GDPR takes place, the necessary agreements are concluded.

Additional requirements for transfers to professionals outside the European Economic Area are addressed in the following section.

19. International Cooperation and Data Transfers

Arabia Interculture works with international clients and external trainers, coaches, and consultants in various countries, particularly in the MENA region.

Where necessary to carry out an assignment, personal data may be transferred to the professionals involved. This generally consists of names, professional positions, and contact details.

The information is used exclusively to carry out the respective assignment.

The professionals involved are contractually required to maintain confidentiality, comply with data protection obligations, and delete participant information received after completion of the assignment.

Transfers of personal data outside the European Economic Area are subject to the requirements of Articles 44 et seq. GDPR.

For transfers to countries without an adequacy decision by the European Commission, appropriate safeguards under Article 46 GDPR are generally required, unless a statutory derogation under Article 49 GDPR applies in the specific circumstances.

Information about the safeguards applicable to a particular transfer may be requested at info@arabia-interculture.com.

20. Business Communications

We contact professional contacts in connection with existing business relationships, specific enquiries, and individual business communications.

We do not currently operate an automated newsletter.

We send promotional emails only where a legal basis exists and the requirements of Section 7 of the German Act Against Unfair Competition (UWG) are met.

Depending on the circumstances, personal data is processed on the basis of Article 6(1)(a), (b), or (f) GDPR.

You may object at any time to the use of your personal data for direct marketing.

21. External Links and Social Networks

Our website contains links to LinkedIn and X.

These are ordinary external links rather than embedded social media content.

Simply visiting our website does not establish a connection to these social networks through the links.

Only when you click a link are you redirected to the respective provider. The provider’s privacy policy then applies.

LinkedIn: https://www.linkedin.com/legal/privacy-policy
X: https://x.com/en/privacy

Where we operate business profiles on social networks, joint controllership with the respective platform provider may exist in connection with the provision of page statistics.

Information about the relevant LinkedIn arrangement is available at:

https://legal.linkedin.com/pages-joint-controller-addendum

22. External Videos and Media

We currently provide access to videos and other third-party media exclusively through external links.

We do not use embedded video players.

Only when you click a relevant link are you redirected to the third-party provider, whose privacy policy then applies.

23. Recipients of Personal Data

Where necessary, personal data may be disclosed to the following categories of recipients:

  • Website hosting and IT service providers

  • Communication and videoconferencing providers

  • Appointment scheduling providers

  • Assessment and diagnostic instrument providers

  • External trainers, coaches, and consultants

  • Clients, where agreed and legally permitted

  • Tax advisers, banks, and other parties involved in business administration

  • Public authorities or other authorized recipients where disclosure is legally required

Where service providers process personal data on our behalf as processors, the requirements of Article 28 GDPR apply.

Personal data is disclosed only where necessary for the relevant purpose and legally permitted.

24. Data Retention and Deletion

We generally retain personal data only for as long as necessary for the relevant processing purpose or as required by law.

The following retention periods and deletion procedures apply in particular:

Data categoryRetention period or deletion procedure
Server log filesAutomatically deleted after seven days
Cookie consent recordsAutomatically deleted after twelve months
Cookie consent validity365 days
Google Analytics event dataTwo months
Google Analytics user data14 months; reset upon renewed user activity enabled
Elementor form submissionsManually deleted once the enquiry has been processed and the information is no longer required
Calendly and Cal.com booking dataManually deleted after the appointment and associated follow-up communication have been completed
Assignment-related participant dataDeleted after completion of the assignment
Participant data held by external professionalsDeleted after completion of the respective assignment in accordance with contractual obligations
Handwritten coaching notesDestroyed immediately after completion of the assignment
Working copies of assessment resultsDeleted or destroyed after completion of the assignment
Our own cloud recordings of online sessionsDeleted immediately after successful transfer to the client
Project-related working documentsDeleted after completion of the assignment unless further retention is necessary

Business records may be subject to statutory retention periods.

These include documents relevant to commercial and tax law. The applicable retention periods are determined by the relevant legal provisions, particularly Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO).

Where statutory retention obligations apply, the relevant data is deleted after the applicable periods expire, unless other legal grounds justify continued retention.

External platforms may apply additional technical storage and deletion procedures.

25. Your Rights

Subject to the applicable legal requirements, you have the following rights:

  • Right of access (Article 15 GDPR): To obtain information about the processing of your personal data.

  • Right to rectification (Article 16 GDPR): To request correction of inaccurate data or completion of incomplete data.

  • Right to erasure (Article 17 GDPR): To request deletion of personal data under the applicable conditions.

  • Right to restriction of processing (Article 18 GDPR): To request restriction of processing in certain circumstances.

  • Right to data portability (Article 20 GDPR): To receive certain personal data in a structured, commonly used, and machine-readable format.

  • Right to withdraw consent (Article 7(3) GDPR): To withdraw consent at any time with effect for the future.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise your rights, you may contact us informally at:

info@arabia-interculture.com

26. Right to Object under Article 21 GDPR

Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.

We will then cease processing the relevant data unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

Objection to direct marketing: Where personal data is processed for direct marketing purposes, you may object at any time without giving reasons. The relevant data will then no longer be used for that purpose.

An informal objection sent to info@arabia-interculture.com is sufficient.

27. Right to Lodge a Complaint

Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.

Our competent supervisory authority is:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW)

https://www.ldi.nrw.de/

You may also contact another competent data protection supervisory authority, particularly in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement.

28. Automated Decision-Making

We do not make decisions based solely on automated processing within the meaning of Article 22 GDPR that produce legal effects concerning you or similarly significantly affect you.

29. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, and unlawful disclosure.

These measures include access restrictions, encrypted communication, and contractual confidentiality obligations.

Our website uses HTTPS encryption to protect data transmitted between your browser and our web server.

30. Updates to This Privacy Policy

We update this Privacy Policy when our services, the technologies we use, or the applicable legal requirements change.

The version published on our website at the relevant time applies.

Last updated: 9 October 2026