Skip to main content

Privacy Policy

Last updated: July 23, 2026

This Privacy Policy explains what personal data GradGermany collects when you use our website and services, why we collect it, who we share it with, how long we keep it, and the rights you have. It is written to be read alongside our Terms & Conditions and our Imprint.

1. Who We Are

GradGermany (“we”, “us”, “our”) is an education consultancy that helps international students apply to universities in Germany. Because we operate across Germany and India and serve students in both regions, we treat your data in line with both the EU General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act, 2023 (DPDP Act).

This policy applies to our website at gradgermany.com, the student portal, the German-learning area, and any related services (together, the “Platform”).

2. Data Controller & How to Reach Us

The data controller responsible for your personal data is GradGermany, contactable at [email protected].

For any data-protection matter, including requests to access, correct, or delete your data, or to withdraw consent, you can reach our Grievance Officer:

Shikha Gupta
E-Mail: [email protected]
Phone: +91 879 9797 088

3. What Data We Collect

We collect only the data we need to run the Platform and deliver our services.

Account data. Your name, email address, phone number, date of birth, nationality, current education level, and target intake. Your password is stored in a securely hashed form and is never visible to us. If you sign in with Google, we store a Google account identifier instead of a password.

Profile-evaluation data. When you request a (free) profile evaluation, we collect the details you enter: your academic background (institution, field of study, grades and grading system, degree type and duration, anabin status), your target programme and intake, your language levels and test scores (German, TestDaF, English, IELTS), and any notes you add. We also store the documents you choose to upload.

Documents you upload. These can include transcripts, degree and school certificates, CVs, motivation and recommendation letters, language and medium-of-instruction certificates, work-experience certificates, portfolios, and, where you provide them, your passport, national ID (for example an Aadhaar card), and financial-proof documents. Some of these are sensitive documents; we ask you to upload only what is necessary, and we describe below how they are used and protected.

Contact and enquiry data. If you submit a contact form, service enquiry, review, Ausbildung enquiry, or job application, we collect the details on that form, which may include your name, email, phone, the message or notes you write, service interests, salary expectations, and any file (such as a résumé) you attach. You do not need an account to contact us.

Communication data. Messages you exchange with your consultant or tutor through the Platform, and appointment details you book.

Technical data. Your IP address, browser type, and the essential cookies needed for the Platform to work, collected automatically when you visit.

Account-activity data. If you have an account, we keep a limited record of your sign-ins and of which areas of the portal you use (the feature name and time only, never page or message content), so we can keep your account secure and improve the service. These activity records are deleted automatically after 12 months.

We do not collect payment-card data. See section 7 for how any future payments are handled.

4. Why We Use Your Data, and Our Legal Basis

Under the GDPR we must have a legal basis for each use of your data. The table below explains what we do and why we are allowed to do it. Where we rely on consent, you can withdraw it at any time (section 12).

  • Provide our services (evaluate your profile, manage your application, coordinate with universities, communicate with you): performance of our contract with you, GDPR Article 6(1)(b). Under the DPDP Act this is processing for the purpose for which you provided the data.
  • Process the sensitive documents you upload (passport, national ID such as Aadhaar, financial proof): your explicit consent, GDPR Article 9(2)(a). You choose whether to upload these; we do not require them to submit an evaluation.
  • AI-assisted evaluation (section 6): your separate, explicit consent, GDPR Article 6(1)(a) and, for any sensitive documents, Article 9(2)(a).
  • Send service notifications (status updates, document feedback, appointment reminders, new messages): performance of our contract, Article 6(1)(b).
  • Send marketing emails (news, tips, offers): your consent, Article 6(1)(a). You opt in separately and can unsubscribe at any time (section 9).
  • Analytics and advertising cookies (section 8): your consent, Article 6(1)(a).
  • Keep the Platform secure and prevent abuse (bot protection, sign-in logging, fraud prevention): our legitimate interests, Article 6(1)(f).
  • Meet legal obligations (for example commercial and tax record-keeping, responding to lawful requests): legal obligation, Article 6(1)(c).

5. AI-Assisted Evaluation & International Transfers

Your profile evaluation can be prepared with the help of automated tools. This only happens if you tick the dedicated AI-consent box on the evaluation form. It is separate from accepting our Terms, it is optional, and if you do not consent your evaluation is prepared manually by a consultant instead.

When you consent, the details you entered and the documents you uploaded (which may include transcripts, certificates, your passport, a national ID such as an Aadhaar card, and financial proof) are sent to OpenAI and/or Google Gemini in the United States. These providers read the documents (including reading text from scans and images) and help produce a draft assessment and programme suggestions. This is assistance only: a human consultant reviews, and may adjust, the result before it is shared with you, and you can ask us to redo the assessment without AI.

Because these providers are outside the EU/EEA, using them involves an international transfer of your data. We rely on the providers’ data-processing terms and on standard contractual clauses as the safeguard for that transfer. You can withdraw AI consent at any time by contacting our Grievance Officer (section 2), after which we stop any further AI processing of your data.

6. Who We Share Your Data With

We share your data only where it is needed to deliver our services, to keep the site running, or, for optional cookies, to measure and advertise with your consent. We do not sell your personal data or share it with data brokers.

  • Universities and educational bodies: when we submit or support your application on your behalf.
  • Hosting provider (Hetzner, Germany): our servers and database are located in Germany. Your account data and uploaded documents are stored there on private storage, not publicly accessible.
  • Email providers (Resend, with Mailjet as a fallback): to send you service and, where you opted in, marketing emails.
  • Network and security (Cloudflare): Cloudflare delivers and protects the site (HTTPS, firewall, bot protection). Cloudflare also provides a cookieless, aggregate visitor count (see section 8).
  • AI providers (OpenAI and Google Gemini, USA): only for AI-assisted evaluation, and only with your explicit consent, as described in section 5.
  • Google (Analytics) and Microsoft (Clarity): site-usage analytics, only if you accept analytics cookies. Clarity masks text content in the page before it leaves your browser.
  • Meta (Facebook Pixel) and Google (AdSense): to measure advertising and to serve third-party display ads on our blog pages, only if you accept marketing cookies.
  • Legal authorities: only where required by law.

7. Payments

We do not collect or store payment-card details. If you purchase a paid service, payment is handled entirely on the secure hosted page of a third-party payment provider (Razorpay); we receive only a confirmation of the outcome (for example the plan and status), never your card data.

8. Cookies & Similar Technologies

Strictly necessary (always active, required for the Platform to function, no consent needed):

  • Session cookie: keeps you logged in.
  • CSRF token: protects forms against cross-site request forgery.
  • Consent preference: remembers whether you accepted or declined optional cookies.
  • Bot protection (Cloudflare Turnstile): a privacy-friendly challenge on some forms to block automated abuse.

First-party usage insights (no cookie, no consent required). Separately from the cookie-based analytics below, we run our own fully anonymous measurement on our own servers to understand which parts of the site are useful and improve them. It records only the page address, where clicks land and how far the page is scrolled, and your screen size. It uses no cookies and stores no IP address, no account link, and no cross-site identifier, so it cannot identify you or build a profile of you. Because it processes no personal data and stores nothing on your device, it operates without requiring consent. We honour your browser's Do Not Track setting and record nothing when it is switched on. The data is aggregated into heatmaps and automatically deleted after 90 days.

Analytics (loaded only after you accept analytics on our cookie banner). Nothing in this category measures you until you opt in:

  • Google Analytics 4: page-view and visitor measurement, including which pages and buttons are used and how visitors reached us.
  • Microsoft Clarity: session replays and heatmaps with page text masked, to spot usability issues.
  • Cloudflare Web Analytics: an aggregate page-view count. It is cookieless and does not track you across sites or build a profile of you; even so, we load it only after you accept analytics, so nothing measures you before you opt in.

Marketing cookies (loaded only after you accept them on our cookie banner):

  • Meta Pixel: measures the effectiveness of our ads on Facebook and Instagram.
  • Google AdSense: serves third-party display ads on our blog pages and sets advertising identifiers.

Both optional categories are off by default. If you decline, none of the analytics or marketing tools above are loaded. Rejecting is as easy as accepting: the banner gives “Reject all”, “Save my choices”, and “Accept all” equal weight. You can change or withdraw your choice at any time using the “Cookie Settings” link in the footer of every page, and we ask you to reconfirm about once a year.

Consent records. To meet our legal duty to show that valid consent was given (GDPR Article 7; DPDP Act), we log each cookie, AI, terms, and marketing consent decision. For each decision we store: a randomly generated consent ID kept in your browser (a pseudonymous identifier not linked to your name, used to match a later withdrawal to the original choice), the date and time, what you accepted or declined, the version of the banner and of this policy shown to you, your browser language and type, and a truncated IP address (the final part is removed so you cannot be identified from it). These consent records are kept for up to 36 months and then automatically deleted.

9. Marketing Emails & Unsubscribe

We send marketing or informational email sequences only where you have opted in. Every marketing email includes an unsubscribe link, and unsubscribing takes effect immediately and permanently for that address. Service emails that are necessary to your case (for example application-status updates and appointment reminders) are not marketing and are sent as part of providing the service.

10. Data Retention

  • Account data: kept while your account is in use. You can request deletion at any time.
  • Inactive accounts: if you do not log in or use your account for 4 months, we email you a warning; if there is still no activity 14 days later, your account and its data are deleted automatically. Simply logging in (or emailing us to keep your data) resets this.
  • Uploaded documents: stored on private storage and deleted when your account or evaluation is deleted.
  • Contact and enquiry submissions: kept for up to 2 years, then deleted.
  • Application records: kept for up to 6 years after completion of services where required by German commercial and tax law.
  • Activity logs: deleted automatically after 12 months.
  • Consent records: kept for up to 36 months to demonstrate valid consent, then automatically deleted.

11. Data Security

  • HTTPS encryption on all connections (via Cloudflare).
  • Passwords stored using strong one-way hashing (bcrypt); two-factor secrets stored encrypted.
  • Uploaded documents held on private storage that is not publicly accessible.
  • Role-based access: students, consultants, and admins each see only what they need.
  • Servers hosted in Germany (Hetzner), under EU data-protection standards.

12. Your Rights in the EU/EEA (GDPR)

If the GDPR applies to you, you have the right to:

  • Access your data and receive a copy. Logged-in users can download their data as a file directly from the student portal.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”), subject to records we must keep by law.
  • Restrict or object to certain processing, including processing based on our legitimate interests.
  • Data portability, to receive your data in a structured, machine-readable format.
  • Withdraw consent at any time (for AI processing, marketing, and analytics/marketing cookies), without affecting processing already carried out.
  • Lodge a complaint with a supervisory authority (in Germany, the data-protection authority of the relevant federal state).

13. Your Rights in India (DPDP Act 2023)

If the DPDP Act applies to you, you have the right to:

  • Access a summary of your personal data and how we process it.
  • Correct, complete, update, or erase your personal data.
  • Grievance redressal through our Grievance Officer (section 2).
  • Nominate another person to exercise your rights in the event of death or incapacity.
  • Withdraw consent as easily as it was given.

14. How to Exercise Your Rights

  • Self-service: logged-in users can download their data and delete their account from the student portal.
  • Registered users: email [email protected] from your registered address with your request (for example “Data Deletion Request”).
  • Non-registered visitors: email the same address with the details you used when contacting us.

We acknowledge requests within 48 hours and resolve them within 30 days. Some data may be retained where the law requires it (for example tax or accounting records).

15. Children

Our services are directed to adults aged 18 and over, and our evaluation and enquiry forms enforce a minimum age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact our Grievance Officer and we will delete it.

16. Changes to This Policy

We may update this policy from time to time. Changes are posted here with an updated date, and we notify registered users by email of any material change.

17. Contact Us

GradGermany — Data Protection
Grievance Officer: Shikha Gupta
Email: [email protected]
Phone: +91 879 9797 088
Website: gradgermany.com