Privacy Policy
This privacy policy is written to the standard of the General Data Protection Regulation (GDPR) and is addressed to users in the EU.
1. At a glance
General information. The following provides a simple overview of what happens to your personal data when you visit this website.
Who is responsible? Data processing is carried out by the website operator (WORLDSHAPER DF LLC, represented by Daniel Förster; contact details under section 3).
How do we collect your data? Some data you provide to us (e.g. by e-mail). Other data is collected automatically or with your consent when you visit the website (technical data such as browser, operating system, time of access).
What do we use your data for? To provide the website without errors, to handle your enquiries, and — if you become a member — to provide and operate the membership service.
Your rights. Access, rectification, erasure, withdrawal of consent, and the right to lodge a complaint with the competent supervisory authority.
2. Hosting
We host the content of our website with All-Inkl (ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany). The provider records log files including your IP address, on the basis of our legitimate interest in secure and efficient provision (Art. 6(1)(f) GDPR). A data processing agreement is in place with the provider.
3. General information and mandatory disclosures
Controller. WORLDSHAPER DF LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States of America, represented by Daniel Förster. E-mail: daniel.foerster@thanealaric.com.
Storage period. Your data remains with us until the purpose of processing no longer applies, or until you make a legitimate request for erasure or withdraw your consent, unless statutory retention periods apply.
International data transfers. We are established in the United States, and some of the services we use are provided by companies in the United States. Data may therefore be transferred to the USA.
Any such transfer takes place only on a permissible basis under Chapter V GDPR — that is, on the basis of an adequacy decision (the EU-US Data Privacy Framework, where the recipient is certified under it), EU Standard Contractual Clauses, or your consent. Where a provider is certified under the Data Privacy Framework, that certification is the basis relied on; where it is not, Standard Contractual Clauses apply.
You can request a copy of the safeguards in place by contacting us at the address in this section.
Your rights. You have the right at any time to access, rectification, erasure and restriction of processing, the right to data portability, the right to withdraw consent, the right to object (Art. 21 GDPR), and the right to lodge a complaint with a supervisory authority.
SSL/TLS encryption. For security reasons, this site uses SSL/TLS encryption, recognisable by “https://” and the padlock symbol in your browser’s address bar.
4. Data collection on this website
Cookies and consent. Non-essential and consent-requiring services load only after your consent, which we obtain through a consent banner. This consent requirement follows from Section 25(1) TDDDG together with Art. 6(1)(a) GDPR. Technically necessary cookies are set on the basis of Section 25(2) TDDDG or Art. 6(1)(f) GDPR. You can withdraw or adjust your consent at any time via the banner.
Consent management (CookieYes). The consent banner is provided by CookieYes Limited, 3 Warren Yard, Warren Park, Wolverton Mill, Milton Keynes MK12 5NW, United Kingdom. When you visit the site, the banner is loaded from CookieYes’s servers and your consent decision is recorded there together with technical data such as your IP address, so that we can demonstrate the consent given.
Legal basis: our legal obligation to obtain and document consent (Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR) and our legitimate interest in a functioning, verifiable consent mechanism (Art. 6(1)(f) GDPR). The consent tool necessarily loads before you make a choice, because it is the mechanism by which the choice is offered.
Transfer: CookieYes is established in the United Kingdom. The United Kingdom is the subject of an adequacy decision of the European Commission, most recently renewed on 19 December 2025, so the transfer takes place on the basis of Art. 45 GDPR. A data processing agreement is in place with CookieYes.
Server log files. The provider automatically records information in server log files (browser type, operating system, referrer URL, hostname, time of access, IP address) on the basis of Art. 6(1)(f) GDPR.
Contact by e-mail. If you contact us by e-mail, your details are stored to handle your enquiry (Art. 6(1)(b) or (f) GDPR). A contact form is not currently used.
5. Membership and member area
Platform. The membership, its content and the community are provided through the Circle platform (Circle.so, Inc., United States).
What is processed. When you register and use the member area, the following are processed: account data (name, e-mail address), usage data (progress, activity, membership level) and content data (posts, messages, uploads).
Purpose and legal basis. Performance of the membership contract (Art. 6(1)(b) GDPR) and our legitimate interest in the secure and efficient operation of the platform (Art. 6(1)(f) GDPR).
Third-country transfer. Circle is a US provider; processing takes place in the USA. Circle is not certified under the EU-US Data Privacy Framework; the transfer is therefore based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) as agreed in Circle’s data processing terms.
No disclosure to third parties. We do not pass on usage or progress data to third parties. This applies in particular to employers, including where a company has purchased seats for its staff.
Your content. You retain the rights in the contributions you post. We display them within the platform to other members so that the community can function; we do not publish them outside the platform without your separate consent. See Clause 6 of our Terms of Service.
Storage period. Account and content data are stored for the duration of the membership. After the membership ends they are deleted, unless statutory retention periods apply — in particular tax and commercial retention obligations for billing data.
6. Payment processing
Provider. Payments are processed through Stripe (Stripe, LLC, South San Francisco, California, United States). Under the Stripe Services Agreement the contracting entity is determined by the account country of the business — which for us is the United States — and Stripe, LLC is in any event a party for the purposes of processing personal data.
Third-country transfer. Processing takes place in the USA. Stripe, LLC is certified under the EU-US Data Privacy Framework (EU-U.S., Swiss-U.S. and UK Extension, all active as at 1 September 2026). The transfer is therefore based on the European Commission’s adequacy decision (Art. 45 GDPR).
What is processed. The data required to process the payment (name, e-mail address, billing data, payment details). Full card numbers are processed by the payment service provider and are not accessible to us.
Purpose and legal basis. Performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in secure and efficient payment processing (Art. 6(1)(f) GDPR).
VAT identification number. If you provide a VAT identification number, we validate it and retain the validation record. This is a legal obligation in connection with the correct tax treatment of the transaction (Art. 6(1)(c) GDPR).
Storage period. Billing data is retained for the statutory retention periods.
7. Newsletter
We do not currently offer a newsletter. If one is introduced, it will be sent only with your consent (double opt-in, Art. 6(1)(a) GDPR), and this policy will be updated accordingly.
8. Embedded services
Web fonts. Fonts used on this website are hosted locally on our own server. They are not retrieved from an external provider, so no data is transmitted to a font provider and no consent is required for them.
Calendly (appointment booking). For online appointment booking we use Calendly (Calendly LLC, USA). When you book, the data you provide (name, e-mail, requested time) is transmitted to Calendly; a transfer to the USA is possible, based on the EU-US Data Privacy Framework or EU Standard Contractual Clauses. The basis is your consent or the performance of the appointment (Art. 6(1)(a) or (b) GDPR).
Web analytics (Google Analytics 4). This website uses Google Analytics 4, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and comparable technologies that allow us to analyse how the website is used.
Legal basis: your consent only (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You may withdraw your consent at any time via the consent banner, with effect for the future.
Without your consent, no analytics data is collected. Until you consent, Google’s consent mode is set to “denied” for analytics purposes: no analytics cookies are set and no measurement data is transmitted.
What is processed with your consent: pages viewed, time of access, approximate location derived from the IP address, referrer, and technical data about the browser and device. According to Google, IP addresses are used to derive approximate location and are not stored in Google Analytics 4.
Transfer: data may be transmitted to Google LLC in the United States. Google LLC is certified under the EU-US Data Privacy Framework, so the transfer rests on the European Commission’s adequacy decision (Art. 45 GDPR). A data processing agreement with Google is in place.
Google Search Console. We additionally use Google Search Console to review how the site performs in Google search. It provides us with aggregated search statistics only, gives us no personal data about individual visitors, and sets no cookies on your device.
Version 3.0 · 2 September 2026.
