Privacy Policy
This privacy policy explains which personal data is processed when you visit this website or send an enquiry to LevelUp English — and which is not. In short: this website works without tracking and without analytics services, and therefore without a general cookie banner. Cookies are only set if you actively choose a country and language (section 8). We essentially only process data about you when you send us an enquiry.
1. Controller
LevelUp English GmbH i.G., represented by the managing director Felix Kellaway c/o Cambridge Innovation Campus, Lohmühlenstraße 65, 12435 Berlin, Germany Phone: +49 30 2359 1386 Email: info@levelupenglish.de
2. Hosting and server logs
This website is hosted by Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). When you access our pages, Cloudflare processes technically necessary connection data, in particular your IP address, to deliver the content, and keeps short-term server logs to defend against attacks and analyze errors. The legal basis is our legitimate interest in a secure and reliable operation of the website (Art. 6(1)(f) GDPR). Cloudflare acts as our processor; for transfers to the USA see section 13.
3. Contact form
When you use our contact form, we process the information you enter: name, school and location, email address, optionally a phone number, your message, the name of the camp for camp enquiries, and how you heard about us.
The purpose is handling and answering your enquiry and preparing an offer. The legal bases are your consent given via the checkbox in the form (Art. 6(1)(a) GDPR) and the performance of pre-contractual steps (Art. 6(1)(b) GDPR). Depending on the topic, your enquiry is routed internally to the responsible inbox (schools, camps, or the general office inbox).
Together with the enquiry, we record which page of our website it was sent from (including address parameters such as campaign tags) and where the visit came from — for external sources only the name of the referring website, for our own pages only the path. No cookie or local storage is used for this, and no IP address is stored.
After submitting, you receive an automatic confirmation email at the address you provided (sender: noreply@webform.levelupenglish.de).
Notification of new dates: If you ask to be notified on the page of a camp whose next dates are not yet fixed, we store your name, email address and the camp concerned for that purpose and send you a single email once the new dates are published. The legal basis is your request (Art. 6(1)(b) GDPR). The address is not used for anything else, in particular not for a newsletter. The entry is deleted six months after the notification and in any case no later than 24 months after your request.
You can revoke your consent at any time with effect for the future (informally, to info@levelupenglish.de); this does not affect the lawfulness of processing carried out before the revocation.
4. Storage of enquiries
We additionally store incoming enquiries in a database at Cloudflare (the same processor as for hosting): reference number, name, school, email address, phone number, topic, market, camp name where applicable, the origin details described in section 3 and, where applicable, the click identifier of a Google or Meta ad (section 9). The text of your message is expressly not stored in the database; it remains solely in the email inbox. The purpose of this storage is a monthly internal evaluation report (e.g. how many enquiries reach us and about what). No profiling takes place and no data is shared with third parties.
Submissions rejected by the spam filter are logged without any personal fields — only the rejection reason, topic, market, page path, and time (legal basis: Art. 6(1)(f) GDPR, protection against abuse).
Retention: Enquiries that do not lead to a booking are deleted after 24 months — in the database as well as in the email inboxes. Log rows of rejected submissions are deleted after 6 months. For technical reasons, the database keeps automatic restore points covering the last 7 days; a deletion therefore becomes final at most one week later.
5. Spam protection
To protect the contact form against automated abuse, we first use checks that work without personal data (hidden form fields and timing). In addition, we use Cloudflare Turnstile: on pages with a form, a script is loaded from challenges.cloudflare.com which processes, among other things, your IP address and device information to distinguish humans from bots. The legal basis is our legitimate interest in protection against spam and abuse (Art. 6(1)(f) GDPR); as a pure security measure, this does not require consent under § 25 TDDDG.
6. Email delivery (Resend)
For sending the enquiry emails and the confirmation email we use the service Resend (Resend, Inc., USA) as a processor. Sending is handled via the service’s EU region (Ireland); Resend may also process account and diagnostic data in the USA — see section 13.
7. Maps (OpenFreeMap)
On pages with a location map, map tiles are loaded from tiles.openfreemap.org. The operator is Hyperknot Software Kft. (Hungary, EU). Your IP address is technically transmitted to this provider when the tiles load; according to its published privacy statement, IP addresses are not logged. The legal basis is our legitimate interest in presenting our locations (Art. 6(1)(f) GDPR).
8. Country and language choice (cookie)
If you actively choose a country or language on this website, or dismiss the
country suggestion, we store that choice in cookies (lu_site,
lu_geohint) with a lifetime of 12 months. The cookies contain only your
choice and are read only by our website. The suggestion of a matching country
happens entirely in your browser (based on time zone and language setting);
no data is transmitted to us or to third parties for this. As a setting you
explicitly requested, the cookie is exempt from consent under § 25(2) no. 2
TDDDG. You can delete it in your browser at any time.
9. Measuring our ads (Google Ads, Meta)
We occasionally run ads on Google Ads and on Meta (Instagram, Facebook). If
you reach us via such an ad, the address contains a click identifier (gclid
for Google, fbclid for Meta). Two things then happen — both without a cookie
and without any script from these providers:
Counting the landing. Our server counts that a page was opened with such an identifier — with date, page, market and the country the request came from. The identifier itself is not stored, nor is an IP address. This count contains no personal data and serves to measure the reach of our ads (Art. 6(1)(f) GDPR).
Carrying the identifier through your visit. While you stay on our website, we append the identifier to the addresses of our internal links. Nothing is stored on your device; the identifier only appears in the address of the page you are currently viewing and is gone when your visit ends. If you submit the contact form during this visit, the identifier is stored together with your enquiry in our database (section 4) so that we can see which ad led to an enquiry. The legal basis is our legitimate interest in measuring the success of our advertising (Art. 6(1)(f) GDPR); you may object to this processing (section 15). An enquiry on a later day is no longer attributed to any ad — that would require storing the identifier in a cookie, which we deliberately do not do.
No Google or Meta script runs on this website and your browser sends no data to these providers. We may transmit the click identifiers collected for Google from our server to Google Ads so that Google can attribute the enquiry to the ad; only the identifier that Google itself assigned on the click, and the time, would be transmitted — no name, no email address, no IP address. No such transmission currently takes place. We transmit no data to Meta. Google Ads is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; ads on Instagram and Facebook are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. For a possible transfer to the USA see section 13.
10. Customer reviews (ProvenExpert)
The reviews shown on this website are taken from the public feed of our ProvenExpert profile when the website is built and are embedded statically. No connection to ProvenExpert is made when you visit the website.
11. Videos, fonts, no analytics
Videos and fonts are hosted on our own servers; no third-party content such as YouTube or Google Fonts is loaded. We do not use any web analytics or tracking services; how we measure our Google and Meta ads is described in section 9.
12. External links
Our pages link to external services, such as booking pages of the German Youth Hostel Association (DJH), our job listings on join.com, WhatsApp, and our social media profiles. Data is only transmitted once you click such a link; the privacy policy of the respective provider then applies.
13. Processors and transfers to third countries
We use the following processors under Art. 28 GDPR: Cloudflare (hosting, database, spam protection) and Resend (email delivery). Both companies are based in the USA. Transfers rely on the adequacy decision for the EU-US Data Privacy Framework and, additionally, on EU standard contractual clauses (Art. 46(2)(c) GDPR).
Google Ireland Limited (section 9) is not our processor but an independent controller for the Google Ads service; Google may transfer the click identifier to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework.
Meta Platforms Ireland Limited (section 9) is likewise an independent controller for the ad service on Instagram and Facebook. We transmit no data to Meta; what Meta itself processes when you click an ad is governed by Meta’s privacy policy.
14. Job applications
On our careers page you can apply for an advertised role directly through a form. We then process the details you enter — name, email address, optionally phone number, where you are based, your availability, your answers to role-specific questions and your message — together with the documents you upload (your CV and, optionally, one further document, each as a PDF).
The purpose is to carry out the application procedure and decide on a cooperation. The legal basis is Art. 6(1)(b) GDPR, for employment relationships in conjunction with § 26(1) BDSG. The application is delivered as an email via our service provider Resend (section 6) to our applications mailbox; neither the form nor the documents are stored on our servers or in our database. You receive an automatic confirmation of receipt at the email address you provided. The form is protected against automated abuse by the same measures as the contact form (section 5).
Applications you send us by email are processed on the same basis. If no cooperation results, we delete the documents at the latest 6 months after the procedure ends; longer storage only happens with your consent. For roles that are additionally advertised via the join.com platform, join.com’s privacy policy applies to the application process there.
15. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20), as well as the right to revoke any consent at any time.
Right to object (Art. 21 GDPR): Where we process data based on our legitimate interest, you may object to that processing at any time on grounds relating to your particular situation.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — for example with the Berlin Commissioner for Data Protection and Freedom of Information, which is responsible for us, or with the authority where you live.
16. No automated decision-making
No automated decision-making, including profiling, takes place.
17. Whether you must provide data
You can use this website without providing personal data. We need the fields marked as required in the contact form to answer your enquiry; without them the enquiry cannot be sent. The same applies to the required fields of the application form (name, email address, CV). There is no statutory or contractual obligation to provide them.
Information for persons in Switzerland
For visitors from Switzerland, the information duties of the Swiss Data Protection Act (FADP) additionally apply. The controller is the entity named in section 1. The data described in this policy is processed in Germany and the EU and — through the service providers Cloudflare and Resend — in the USA. Transfers to the USA rely on the Swiss-U.S. Data Privacy Framework or on standard contractual clauses with the adaptations required under the FADP. You have the rights provided by the FADP, in particular access (Art. 25 FADP), rectification, and erasure; the competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
18. Changes
We update this policy when the website or the legal situation changes. The version published here applies.
Last updated: September 2026
