Privacy


Privacy Policy rmp.eu (New Version - Release Version)

As of: July 1, 2026

1. Controller

Responsible for data processing on rmp.eu (including the integrated area rmp.eu/login) is:

RMP Germany GmbH
Schelder Au 1
35687 Dillenburg
Telephone: +49 175 5823304
Email: [email protected]

Management: Daniele Gianella

Data protection officer (external):
Thomas Heimhalt
DATENSCHUTZ perfect GmbH
Wilhelm-Kolb-Str. 1a
76187 Karlsruhe
Email: [email protected]

Regional license partners (e.g. for Austria, Switzerland and Nordics) can act as independent controllers in downstream business processes if personal data is transferred to their own contractual/support context. The above-mentioned responsible body is responsible for direct purchase, registration and contract processes that are processed directly via rmp.eu. Access and use of the rmp.eu/login dashboard are also the responsibility of RMP germany GmbH, even if a profile was previously created in the country partner context. For independent processes in the respective country partner context outside the rmp.eu/login area, the area of ​​​​responsibility of the partner in question applies.

2. General information on data processing

We only process personal data to the extent permitted by law. Depending on the process, processing is carried out in particular on the basis of:

     
  • Art. 6 Paragraph 1 Letter a GDPR (consent)
  • Art. 6 Paragraph 1 Letter b GDPR (contract and pre-contractual measures)
  • Art. 6 Paragraph 1 Letter c GDPR (legal obligation)
  • Art. 6 Paragraph 1 Letter f GDPR (legitimate interests)
  • Paragraph 25 Paragraph 1 TDDDG (consent for non-essential end device access, e.g. cookies/tracking)
  • Paragraph 25 Paragraph 2 TDDDG (Exceptions for technically necessary terminal device access)
  •  

If consent is the legal basis, it can be revoked at any time with future effect. The lawfulness of the processing carried out until the revocation remains unaffected.

We only pass on personal data if there is a legal basis (e.g. to fulfill a contract, based on consent, due to legal obligations or based on an Data Processing Agreement (DPA)).

If providers are used outside the EU/EEA, we observe the requirements of Art. 44 ff. GDPR. Further information on recipients, third country references and guarantees can be found in the relevant sections of this Privacy Policy.

In this new version, the specific processing operations are presented separately by area:

     
  • Homepage on rmp.eu (public area)
  • Login/customer dashboard on rmp.eu/login (integrated area)
  •  

Note on RMP e-Academy: The RMP e-Academy, operated at rmp-academy.thinkific.com, is accessible via rmp.eu. The Academy is operated by Reiss Motivation Profile Switzerland GmbH (RMP Swiss), Schwyz, Switzerland. The processing of personal data on the Academy platform is governed by the separate Privacy Policy of the RMP e-Academy (available at rmp-academy.thinkific.com/pages/privacy). This Privacy Policy does not apply to the Academy platform.

To the extent that personal data is collected directly from data subjects, the provision of certain data is necessary for contract fulfillment, support or security-relevant platform functions. Without this data, individual services may not be provided or may only be provided to a limited extent.

Exclusively automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR does not currently take place within the web/dashboard processing described here.

3. Hosting and server log files

We use hosting and infrastructure services for the technical provision of rmp.eu and rmp.eu/login.

3.1 Hosting

The productive hosting path for the website, TYPO3 frontend and associated email services is carried out via ALL-INKL.COM (Neue Medien Münnich GmbH), Friedersdorf on the basis of a Data Processing Agreement (DPA). The RMP platform backend (API, authentication, profile data storage) runs on dedicated server infrastructure of Hetzner Online GmbH, Gunzenhausen (data centre Falkenstein, Germany) – likewise on the basis of a Data Processing Agreement pursuant to Art. 28 GDPR (DPA v1.2, concluded 23 Jun 2026).

The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR (secure and stable operation of the website) and - where relevant - Art. 6 Para. 1 lit. b GDPR (contractually required provision). Order processing contracts exist with the service providers used.

3.2 Server log files

When you access our pages, technically necessary connection data is processed in server log files. These include in particular:

     
  • Browser type and browser version
  • Operating system
  • Referrer URL
  • Host name of the accessing computer
  • Time of request
  • IP address
  •  

The processing is carried out to ensure IT security, stability, error analysis and misuse detection on the basis of Art. 6 Para. 1 lit. f GDPR.

This log data will not be merged with other data sources without a separate legal basis.

3.3 Storage period (hosting/logs)

Server log data is only stored for as long as necessary for the stated purposes. They will then be deleted or - if necessary and legally permissible - pseudonymized or anonymized, unless longer storage is necessary for legal prosecution, defense against attacks or due to legal obligations.

4. Contact us

If you contact us (e.g. via form, email or telephone), we will process your information to process your request. For telephone contact, an AI-supported telephone assistant (fonio.ai) can be used; Appointments can be made via Cal.com. The operational operation of this telephone/appointment path takes place in the RMP network via Reiss Motivation Profile Switzerland GmbH (Switzerland).

4.1 Processed data

     
  • Master data and contact details (e.g. name, email address, telephone number)
  • Content data of the request (message, subject, attachment)
  • Technical metadata (e.g. time, IP address, channel)
  •  

4.2 Purposes

     
  • Processing and answering inquiries
  • Contract initiation and contract execution
  • Quality assurance and traceability of communication processes
  •  

4.3 Legal basis

     
  • Art. 6 Paragraph 1 Letter b GDPR, insofar as the request is directed to a contract or pre-contractual measures
  • Art. 6 Para. 1 lit. f GDPR for efficient and secure communication processes
  • Art. 6 Para. 1 lit. a GDPR, insofar as consent was obtained in individual cases
  •  

4.4 Recipients

     
  • Internal responsible departments (e.g. support, sales, specialist department)
  • Communication channels used (e.g. email, telephone and internal processing processes)
  • fonio.ai (AI telephone assistant), Cal.com (appointment booking) and Acuity Scheduling / Squarespace (online appointment booking), if used (see section 4.6)
  • Zoom (video calls, webinars), if used (see section 4.8)
  •  

4.5 Storage period

Inquiry data is only stored for as long as is necessary for processing and post-processing. The data will then be deleted, provided that there are no legal retention requirements or legitimate interests in providing evidence.

4.6 Telephone contact, appointment booking and online booking (fonio.ai, Cal.com, Acuity Scheduling)

If you contact us by telephone, your call can be answered and processed by an AI-powered telephone assistant from fonio.ai (fonio). Upon request or during the course of the conversation, appointments can be made via Cal.com. In addition, we use Acuity Scheduling (Squarespace Inc.) as an independent online booking system for appointment scheduling. This telephone and appointment path is operated in the RMP network via Reiss Motivation Profile Switzerland GmbH (Switzerland).

4.6.1 Processed data

     
  • Phone number and call metadata (e.g. time, duration, call status)
  • Speech and conversation data (audio) as well as transcripts/summaries of the conversation
  • Contact and content data you provided in the conversation (e.g. name, request, appointment request)
  • After the call: automatically generated email summary and transcript sent to the responsible RMP contact (internal recipient)
  • When booking an appointment via Cal.com: booking data (e.g. name, email address, telephone number, desired date, calendar reference)
  • When booking an appointment via Acuity Scheduling: booking data (name, email address, telephone number, desired appointment, message/request if provided)
  •  

4.6.2 Purposes

     
  • Receiving and processing telephone inquiries
  • Forwarding, callback organization or appointment scheduling
  • Quality assurance and traceability of telephone contact
  •  

4.6.3 Legal basis

     
  • Art. 6 Paragraph 1 Letter b GDPR, insofar as the call serves to initiate or execute a contract
  • Art. 6 Para. 1 lit. f GDPR for efficient, accessible communication by telephone
  • Art. 6 Para. 1 lit. a GDPR, insofar as consent is required in individual cases (e.g. optional additional processing)
  •  

4.6.4 Recipient/processor

     
  • Reiss Motivation Profile Switzerland GmbH as an operating point in the RMP network for the telephone/appointment process
  • fonio (fonio.ai) as processor for the AI telephone assistant
  • Cal.com, Inc. as processor for appointment booking via Cal.com, if used in the process
  • Squarespace Inc. (Acuity Scheduling) as processor for online appointment bookings via Acuity Scheduling, if used
  • Internal responsible positions at RMP germany GmbH
  •  

Fonio processes in the RMP telephone process based on the fonio AVV (Article 28 GDPR); According to the provider, servers are in Nuernberg (Germany). For the automated post-call email dispatch, fonio uses the sub-processor Sinch AB / Mailgun (email infrastructure; parent company: Sinch AB, Stockholm, Sweden); transfer protection via EU-US Data Privacy Framework and Standard Contractual Clauses. The transfer bases documented in the fonio appendix (SCC and/or EU-US Data Privacy Framework) apply to further sub-processors used (including telephony, LLM, logging). Cal.com is used for appointment bookings based on a countersigned DPA; possible third country references (especially the USA) are contractually addressed there. Acuity Scheduling (Squarespace Inc., USA) is used as an independent parallel online booking system; processing is based on the data processing agreement (DPA) incorporated into Squarespace's Terms of Service (effective 31 Jan 2025); transfer protection via EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCC); account managed by Reiss Motivation Profile Switzerland GmbH (RMP Swiss) as the responsible controller. For details see section 10.

4.6.5 Storage duration

Conversation and booking data are only stored for as long as is necessary to process the request, arrange appointments and provide evidence. Specific deadlines are based on the contractual requirements with fonio, Cal.com and Acuity Scheduling (Squarespace) as well as our internal deletion rules (typically analogous to contact/support data, unless longer legally required).

If calling people do not agree to the recording, the conversation will be ended; the affected call is deleted according to the process instructions.

4.6.6 Note on AI processing

The telephone assistant processes entries automatically. The operating process includes a non-skippable announcement that it is a telephone AI and the conversation is being recorded. You can request forwarding to a natural contact person at any time, if provided for in the company.

4.7 Email marketing and newsletter (Mailchimp / Intuit Inc.)

We use the Mailchimp service of Intuit Inc., 2700 Coast Ave., Mountain View, CA 94043, USA, for sending newsletters and contract-essential onboarding communications. RMP germany GmbH operates and manages a central Mailchimp account through which all four country entities (Germany, Austria, Switzerland, Nordics) communicate.

4.7.1 Newsletter (prospects and customers)

If you sign up for our newsletter through our website, we process your data solely on the basis of your explicit consent (Art. 6(1)(a) GDPR). Sign-up uses a double opt-in procedure: you will receive a confirmation email, and the newsletter is only sent after you click the confirmation link. You may withdraw your consent at any time with future effect – via the unsubscribe link in every newsletter email or by contacting our data protection team.

Data processed: First name, last name, email address, country, and optionally an interest or audience tag (e.g. seminar participant)

4.7.2 RMP Master onboarding and contract communications

RMP Masters are added to our Mailchimp communication list upon conclusion of the contract (admission as a licensed RMP coach) in order to receive contract-essential information (e.g. platform updates, professional notices, training announcements). Processing is based on Art. 6(1)(b) GDPR (performance of contract). Unsubscribing is possible to the extent the communication does not include contractually required mandatory information.

Data processed: First name, last name, email address, country, tag "RMP Master"

4.7.3 Performance measurement (click tracking)

Our emails use active click tracking: links are routed through Mailchimp servers so that clicks are recorded. This allows us to identify relevant content and improve our communications. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in effective, targeted communication). You may object to tracking by unsubscribing from the newsletter or by contacting us.

4.7.4 Data processing and third-country transfer

Intuit Inc. processes data as a data processor pursuant to Art. 28 GDPR on the basis of the Mailchimp Data Processing Addendum (DPA). Intuit Inc. is headquartered in the USA; the data transfer is safeguarded by Intuit Inc.'s participation in the EU-US Data Privacy Framework (DPF) (pursuant to the European Commission's adequacy decision).

4.7.5 Storage period

Newsletter subscriber data is stored until consent is withdrawn; following unsubscription, data is deleted or anonymised within 30 days. RMP Master data is stored for the duration of the active contractual relationship and deleted in line with general retention periods (Section 11) after contract termination.

4.8 Video communication (Zoom)

For video calls and webinars (e.g. client calls, RMP Master onboarding, online seminars, Daylite calendar integrations), we use the Zoom service of Zoom Video Communications, Inc., 55 Almaden Blvd, San Jose, CA 95113, USA. The Zoom account is managed by Polygen Schwyz AG.

4.8.1 Processed data

     
  • Connection data (IP address, device, operating system, client version)
  • Meeting metadata (time, duration, meeting ID, room name)
  • Communication content (audio, video, chat messages, shared screens), as activated in the meeting
  • Username and email address (for registered participants)
  •  

4.8.2 Purposes

     
  • Conducting video consultations, onboarding sessions and webinars
  • Coordination and communication with RMP Masters and prospective customers
  •  

4.8.3 Legal basis

     
  • Art. 6(1)(b) GDPR, insofar as the call serves to initiate or execute a contract
  • Art. 6(1)(f) GDPR for efficient digital communication and collaboration
  • Art. 6(1)(a) GDPR, insofar as consent is required in individual cases
  •  

4.8.4 Recipients / processors and third-country transfer

Zoom Video Communications, Inc. (USA) processes data as a processor pursuant to Art. 28 GDPR. The data processing agreement (DPA) is incorporated into Zoom's Terms of Service. The transfer of data to the USA is safeguarded by Zoom's participation in the EU-US Data Privacy Framework (DPF) as well as Standard Contractual Clauses (SCC) as a fallback.

Privacy configuration: The Zoom account in use is configured to use EU-only data centres (Germany, Netherlands, Sweden) for data storage and processing; EEA data residency is activated. AI Companion functions (automatic transcription, meeting summaries, AI analytics) are fully disabled.

4.8.5 Storage period

Meeting metadata and connection data are processed at Zoom in accordance with Zoom's privacy policies and our account configuration; meeting recordings (if created) are deleted after the purpose has been fulfilled.

5. Cookies and consent management

Our website uses cookies and similar technologies. We differentiate between technically necessary technologies and technologies that require consent.

5.1 Technically Required Technologies

Technically necessary cookies/device access are used to provide core functions of the website and the integrated login/dashboard area (e.g. session, security, consent status, page delivery).

Legal basis:

     
  • Art. 6 Paragraph 1 Letter f GDPR
  • Paragraph 25 Paragraph 2 TDDDG
  •  

5.2 Technologies requiring consent

Analysis, marketing and third-party content will only be loaded with effective consent.

Legal basis:

     
  • Art. 6 Paragraph 1 Letter a GDPR
  • Paragraph 25 Paragraph 1 TDDDG
  •  

5.3 Consent Tool

A consent management tool is used to obtain, manage and document consent (currently Cookiebot/Cybot). Consent can be granted, rejected and revoked using this tool.

5.4 Revocation and change

Consent can be changed or revoked at any time with future effect. The legality of the processing carried out up to that point remains unaffected.

5.5 Evidence and runtime comparison

The technical effectiveness of the consent logic is secured via web reports and proof of runtime. For authenticated dashboard innerflows, an additional comparison of the actually loaded scripts and interfaces is carried out.

6. Analytics and Tracking Services

We use services for analysis, reach measurement and marketing control. Unless technically necessary, these are only activated after consent.

6.1 Typical Service Categories

     
  • Tag and script management (e.g. Google Tag Manager)
  • Web analysis and conversion measurement (e.g. Google and Meta services)
  • Marketing/retargeting tags and pixels (additional tags can be reloaded via tag management; a fixed meta pixel is no longer stored in the current productive code)
  • Third-party content and external scripts related to marketing (e.g. Stripe script for certain flows)
  •  

Additional proof of runtime (Cloudflare script list, as of 2026-04-23):

     
  • Cookiebot (uc.js, cd.js, cdreport.js, widgetIcon.min.js, state.js)
  • Google Tag Manager (gtm.js)
  • Google Analytics 4 (analytics.js, gtag/js, region1.analytics.google.com); GA4 sends audience signals to Google Ads (google.ch/ads/ga-audiences, stats.g.doubleclick.net) after consent if Google Signals is enabled - no separate Google Ads Conversion Tag
  • Meta/Facebook Pixel (fbevents.js) after consent
  • LinkedIn Insight Tag (snap.licdn.com) after consent
  • Stripe (js.stripe.com) for payment-related flows
  • Cloudflare Utility Script (cdn-cgi/.../email-decode.min.js)
  • local TYPO3 merge script (typo3temp/assets/compressed/...)
  •  

6.2 Processed data

     
  • Usage data (page views, events, interactions)
  • Online identifiers (cookie IDs, pixel IDs, advertising IDs)
  • Device/browser data, IP address, referrer, timestamp
  •  

6.3 Purposes

     
  • Reach measurement and improvement of content
  • Campaign management and success measurement
  • Target group formation, retargeting and marketing optimization
  •  

6.4 Legal basis

     
  • Article 6 Paragraph 1 Letter a GDPR and Paragraph 25 Paragraph 1 TDDDG for analysis/marketing technologies that require consent
  • Art. 6 Para. 1 lit. f GDPR only where individual technical components are classified as absolutely necessary
  •  

6.5 Third country reference

For individual analysis/marketing services, a transfer to third countries (particularly the USA) cannot be ruled out. Such transfers only take place under the conditions of Art. 44 ff. GDPR (e.g. adequacy decision or suitable guarantees).

6.6 Evidence and runtime comparison

The named analysis/tracking processing is regularly compared with the actual runtime behavior (public areas via web/cookie scans; authenticated dashboard innerflows via separate runtime checks). Differences between the term and the legal text are updated and corrected internally.

7. Homepage on rmp.eu (public area)

The publicly accessible pages of rmp.eu are managed as a separate processing area. This area includes in particular information pages, contact channels, marketing/analysis integrations and pre-contractual purchase initiations.

7.1 Purpose

     
  • Provision and technical delivery of the website
  • Presentation of content, services and contact options
  • Processing inquiries and pre-contractual communication
  • Reach measurement and optimization of the website (if permitted or consented)
  • Marketing and campaign management (if consented)
  • Misuse detection, availability and IT security
  •  

7.2 Data Categories

     
  • Connection and device data: IP address, user agent, date/time, referrer, requested URL
  • Usage data: page views, interactions, event data (depending on activated services)
  • Cookie and consent data: consent status, technical cookie IDs, preferences
  • Communication data: Information from contact forms, emails, telephone calls (including transcripts) or other inquiries
  • Purchase initiation/shop reference: product-related entries and interactions before the contract is concluded
  •  

7.3 Legal basis

     
  • Art. 6 Para. 1 lit. f GDPR for operation, stability, security and optimization of the website
  • Art. 6 Paragraph 1 Letter b GDPR for pre-contractual inquiries and contractually induced communication
  • Art. 6 Paragraph 1 Letter a GDPR i. V. m. Paragraph 25 Paragraph 1 TDDDG for cookies/technologies requiring consent
  • Art. 6 Para. 1 lit. c GDPR, insofar as there are legal retention or proof obligations
  •  

7.4 Recipients

     
  • Internal positions with responsible functions (operations, marketing, support)
  • Hosting and infrastructure provider according to AVV
  • Technical service providers for consent, analysis, marketing and integrations (depending on active configuration)
  • Communication and shipping services for contact or campaign processes (including fonio.ai, Cal.com for telephone/appointment processes)
  •  

7.5 Third country transfer

     
  • If services are used by providers outside the EU/EEA, transmission will only take place under the conditions of Art. 44 ff. GDPR
  • Appropriateness decisions or suitable guarantees (e.g. standard contractual clauses) can be considered as transfer mechanisms
  • Service-specific third country information is specified in the respective provider sections
  •  

7.6 Storage period

     
  • Server and security logs are only retained for the period necessary to ensure operation and security
  • Consent information is stored in accordance with applicable proof and revocation requirements
  • Communication data is deleted or archived according to the purpose, processing time and legal deadlines
  • Raw marketing/analytics data is processed according to the respective configuration and deletion rules
  •  

7.7 Rights of those affected

Data subjects have the same rights in the homepage area as in all other processing areas (in particular information, correction, deletion, restriction, data portability, objection and revocation of consent given).

7.8 Technical integration / consent

     
  • Technically necessary functions are operated without separate consent, if legally permissible
  • Optional analysis, marketing and third-party content will only be loaded after effective consent
  • Consent can be adjusted or revoked at any time using the consent tool
  • Cloudflare geoblocking/VPN blocking is used in the homepage context exclusively as a protective measure for purchase-related paths
  • In productive operation, Cloudflare on rmp.eu is also used for WAF/OWASP protection, selective login exceptions to avoid false positives and brute force defense on login POST paths
  •  

8. Login/customer dashboard on rmp.eu/login (integrated area)

The login and dashboard area is technically integrated into rmp.eu, but contains independent processing (authentication, session management, profile functions, assessment, sharing and payment processes). Therefore, this area is described separately within this joint Privacy Policy.

8.1 Purpose

     
  • Registration and authentication of users
  • Providing dashboard functionality and personalized content
  • Carrying out and evaluating assessments
  • Sharing and revoking profile shares
  • Processing of purchase processes (e.g. profile purchase/additional modules)
  • Sending transaction-related emails (e.g. registration or gift process)
  • Processing and documentation of upstream confirmations in the purchase/registration process (e.g. approval of general terms and conditions, declaration of early start of services, confirmation of residence)
  • Plausibility and access checks in the registration process (e.g. adulthood check via age validation)
  •  

8.2 Data Categories

     
  • Login and contact details: email address, password (entered when logging in), name if applicable
  • Session and access data: session information, login status, API token
  • Account and profile data: user master data, assessment IDs, profile and evaluation data
  • Interaction data: answers entered in the assessment, share/unshare actions
  • Purchase and transaction data: checkout-related data, tax information, transaction status
  • Communication data: transaction-related email content and shipping metadata
  • Operational and log data: technical request/response metadata for error analysis and system security
  • Questionnaire entry data:
  • as mandatory information in the entry shown: gender, age, country of residence
  • as optional statistical information: function, career level, size of the company, industry, years in the company
  • Consent/confirmation data before the start of the questionnaire (e.g. checkboxes set including time/status reference)
  • Purchase/contract confirmation data (e.g. checkboxes set for general terms and conditions, early start of service, residence information/country context)
  • Validation data in the registration flow (e.g. age check rule with minimum age >=18 in the runtime example shown)
  • Consent data for copyright terms of use (IDS notices), if actively requested in the respective runtime flow
  •  

Note on technical implementation:

To stabilize the session, a login context (e.g. email and password) can be temporarily processed in the frontend session in the login/dashboard context in order to re-authenticate if the token is invalid. This mechanism is limited to the functional purpose and is further minimized in the hardening track.

8.3 Legal basis

     
  • Art. 6 Para. 1 lit. b GDPR (contract execution and pre-contractual measures), in particular for login, profile provision, assessment and payment processing
  • Art. 6 Para. 1 lit. c GDPR (legal obligations), insofar as retention and proof obligations exist
  • Art. 6 Para. 1 lit. f GDPR (legitimate interests), in particular for abuse prevention, system security, error analysis and stable provision of platform functions
  • Art. 6 Paragraph 1 Letter a GDPR i. In accordance with Section 25 Paragraph 1 TDDDG, insofar as optional consent-based technologies are used in the dashboard
  • Art. 6 Para. 1 lit. a GDPR, insofar as additional consents/confirmations are actively given and documented before the start of the questionnaire
  • Art. 6 Para. 1 lit. c GDPR, insofar as there are proof/documentation obligations for contractual declarations (e.g. confirmations relating to revocation/start of service).
  •  

8.4 Recipients

     
  • Internal positions with responsible functions (e.g. operations, support, billing)
  • RMP API, operated by POLYGEN Schwyz AG, Gartenlaubenstrasse 17, 6430 Schwyz, Switzerland, as a processor (Art. 28 GDPR) for authentication and the processing of login/account/assessment/profile/sharing and checkout-related data
  • Payment service provider Stripe for technical payment processing
  • Email infrastructure for transactional messages
  • Processor for hosting and technical operations in accordance with Data Processing Agreement (DPA)s
  •  

8.5 Third country transfer

     
  • If data is processed as part of payment, tracking or platform services outside the EU/EEA, this will only be done on the basis of the legal requirements of Art. 44 ff. GDPR (in particular an adequacy decision or suitable guarantees such as standard contractual clauses)
  • Details on individual third-country transfers are supplemented in the respective service sections of this Privacy Policy
  •  

8.6 Storage period

     
  • Session data is only stored for as long as is necessary for the respective session and function provision
  • Login context data for token revalidation is only retained for the ongoing session logic and is removed upon logout or session end
  • Account, profile and assessment data are stored in accordance with the contractual purpose and operational deletion concepts
  • Transaction and billing-relevant data will be stored in accordance with the applicable commercial and tax deadlines
  • Protocol and operational data are earmarked, minimized and deleted after defined deadlines or - where necessary and legally permissible - pseudonymized or anonymized
  •  

8.7 Rights of those affected

The same data subject rights apply to the login/dashboard area as to the rest of the website (in particular information, correction, deletion, restriction, data portability, objection and revocation of consent given).

8.8 Technical integration / consent

     
  • Login, session, security and core dashboard features are treated as technically required
  • Optional analysis/marketing technologies will only be activated after effective consent
  • Consent settings can be adjusted or revoked via the consent tool
  • In integrated purchasing processes, only the data required for payment processing is transmitted to the payment service provider
  • Security and error logging will be limited to necessary technical content; Access and retention are role-based based on the need-to-know principle
  • Cloudflare security features are currently used on rmp.eu for login/auth operations (including WAF rules, brute force protection and risk-based access checks); The live server platform-auth.rmp-online.com has not yet been switched to Cloudflare.
  • The AI ​​chatbot RMP Buddy is integrated into the dashboard context on rmp.eu/login.
  • After explicit consent, the personalized dashboard chatbot (f85e5bfbcb17430897c8309f06486d6a) transfers the following data to GPT Trainer (POLYGEN Inc., USA): evaluation type, gender, evaluation date, and 16 life-motive values (numeric). Name, email address, and other direct identifiers are not transferred.
  • The legal basis for this profile transfer is Art. 6 Para. 1 lit. a GDPR (consent). Consent can be withdrawn at any time in the dashboard via the Profile Consent link with future effect; after withdrawal, no further profile data is transferred for the dashboard chatbot.
  • Storage period for the chatbot path: on logout, the active chat session is deleted immediately; regardless of logout, chat sessions are deleted automatically after no later than 90 days.
  • In the questionnaire flow, an upstream confirmation/consent step is provided via checkboxes before the start (including Privacy Policy, data processing/disclosure, copyright terms of use).
  • Additional checkbox and plausibility steps are visible in the purchase/registration flow shown (terms and conditions/revocation/residence confirmations as well as minimum age validation >=18); these are processed as upstream contract/compliance steps before the actual service is provided.
  •  

8.9 Profiling/assessment transparency

     
  • Assessment answers are processed into profile and result presentations in order to provide contractually agreed evaluations in the user account.
  • An external evaluation service from IDS Publishing Corporation (USA) is used for the technical scoring/norm evaluation. Only a minimized field set is transmitted (including age, gender, country, response values, technical test ID). No clear data (first name, last name, email) is transmitted. For details on third country transfers see Section 10; the copyright IDS usage consent is requested separately in the respective runtime flow.
  • The evaluation is used to display and interpret motif/profile characteristics in the dashboard; it is not used for an exclusively automated decision with legal or similarly significant effects on data subjects.
  • If users revoke any consent they may have given for optional components, this will have effect for the future; Contractually required processing steps already carried out on a different legal basis remain unaffected.
  • Profile/assessment data is generally stored until the account is deleted, provided there are no conflicting legal obligations; Those affected can assert their legal rights to information, correction, deletion, restriction and objection.
  •  

8.10 Mobile apps (iOS/Android) in the user context

     
  • For mobile applications in the user context (iOS/Android, including app store entry Reiss Motivation Profile® and Google Play entry RMP), the same assignment of responsibility applies as for the direct purchase/dashboard context on rmp.eu and rmp.eu/login (RMP germany GmbH).
  • The mobile functions for profile purchase, profile creation, profile viewing and profile sharing are treated from a data protection perspective as mobile access to the same technical processing context.
  • The technical development and operation of the mobile apps (iOS and Android) are carried out by 247GRAD GmbH, Im Metternicher Feld 30c, 56072 Koblenz, Germany (processor; DPA pursuant to Art. 28 GDPR concluded 09.06.2026). 247GRAD operates the app within their Microsoft Azure MPN tenant (Tenant ID 9823e47d-e1dc-4b79-b9e3-0a98a9b45e11, Subscription RMP). Named sub-processor pursuant to DPA Annex 4: Microsoft Ireland Operations Limited (Dublin, Ireland).
  • In the mobile channel, third-party providers are also used for app operation/communication, in particular:
  • Microsoft Application Insights (crash reporting, diagnostics, app performance and interaction analysis),
  • GPT Trainer (AI-supported chatbot, processing user-generated chat content).
  • For Microsoft Application Insights, DPF/SCC/DPA basics are publicly verifiable; The specific app/tenant/region configuration must be documented in the evidence base.
  • The following applies to GPT Trainer: operation and provision are carried out by POLYGEN Schwyz AG; within the subprocessor/transfer chain, different LLM providers may be used (currently in particular OpenAI/ChatGPT models and Google/Gemini models; optionally Anthropic/Claude models, where activated). DeepSeek is not used in the current RMP operation. Contractual coverage is provided via the documented DPA/transfer path (including POLYGEN confirmation May 21, 2026). Chat data is deleted on the controller side with 90-day automation; data subject rights are documented in the runbook.
  • If data is processed outside the EU/EEA in connection with these services, the transfer will only take place under the conditions of Art. 44 ff. GDPR (in particular suitable safeguards such as SCC and/or an adequacy decision, where applicable).
  • App-specific mandatory information in the stores (Apple App Privacy Label / Google Play Data Safety) must be kept consistent with this Privacy Policy and the app SDKs actually used.
  • If there are discrepancies between store information and actual runtime/SDK usage, the information and this Privacy Policy will be updated.
  •  

9. Recipients and processors

We only transfer personal data if this is necessary for the respective purposes and legally permissible.

9.1 Recipient categories

     
  • Internal positions within the responsible organization (e.g. operations, support, sales, billing)
  • IT and hosting service provider for operation, maintenance and security
  • Communication, analysis, marketing and payment service providers depending on the functions activated
  • Regional license partners (e.g. for Austria, Switzerland, Nordics), insofar as data for the specific contract initiation, contract execution or support is required in the respective country context
  • Public bodies and authorities, insofar as there is a legal obligation
  •  

9.2 Processor

If service providers process data on our behalf, this is done on the basis of Art. 28 GDPR with a corresponding Data Processing Agreement (DPA) (AVV/DPA). The service providers are bound to our instructions and are not allowed to process data for their own, non-agreed purposes.

9.3 Contract and evidence bases

     
  • Hosting/Infra: ALL-INKL.COM (Neue Medien Münnich GmbH), Friedersdorf (web frontend/TYPO3/email, DPA); Hetzner Online GmbH, Gunzenhausen (API backend/dedicated server, Falkenstein data centre, Germany; GDPR DPA Art. 28 v1.2, concluded 23 Jun 2026)
  • Platform/API: POLYGEN Schwyz AG as processor for RMP API and platform functions
  • In productive operation (depending on configuration): Cookiebot, Google Tag Manager, Google Analytics, LinkedIn Tag, Stripe, Cloudflare, fonio.ai (telephone AI), Cal.com (appointment booking), IDS Publishing Corporation (scoring/evaluation)
  • App channel:247GRAD GmbH (app development and operation iOS/Android; processor, DPA Art. 28 GDPR, concluded 09.06.2026); Microsoft Application Insights (app telemetry, West Europe region, via 247GRAD Azure tenant); GPT Trainer (AI chatbot, via POLYGEN; DPA and 90-day deletion automation documented)
  • Contract, subprocessor and transfer records (DPA/AVV/SCC per service) are kept internally for each processing path and are regularly compared with the technical runtime
  •  

9.4 Classification of regional license partners

Regional license partners (e.g. in Austria, Switzerland and the Nordics) are not generally joint controllers for all processing on rmp.eu/rmp.eu/login. Direct purchase and contract processes processed directly via rmp.eu as well as access and use of the rmp.eu/login dashboard are the responsibility of RMP germany GmbH. If data is transferred to an independent regional contract or support process outside the rmp.eu/login area (e.g. invitation/support by a country partner), further processing takes place in the respective area of ​​responsibility of the partner in question.

10. Third country transfers

Personal data will only be transferred to countries outside the EU/EEA if the requirements of Article 44 ff. GDPR are met.

10.1 Legal Mechanisms

The following are particularly suitable bases for transmission:

     
  • Appropriateness decision by the EU Commission
  • Standard contractual clauses (SCC) including any necessary additional measures
  • in exceptional cases, express consent in accordance with Art. 49 GDPR
  •  

10.2 Practical relevance in the web/dashboard context

Individual analysis, marketing, communication or payment services may have a third country connection (particularly the USA). The specific basis is documented for each provider (DPF and/or SCC) and regularly checked to ensure that it is up to date.

The service-specific assignment of recipient roles and transfer mechanics is documented internally and regularly compared with the technical runtime.

This particularly affects the following services:

     
  • Cookiebot (consent management): Third country reference possible per provider structure; Transfer protection via DPF and/or SCC
  • Google Tag Manager, Google Analytics, Google Ads/DoubleClick: USA/third country reference possible; Transfer protection via DPF and/or SCC
  • Meta/Facebook services: only with active integration via tag management; no fixed pixel is stored in the current productive code; When activated, USA/third country reference possible with transfer protection via DPF and/or SCC
  • LinkedIn Tag: Third country reference possible; Transfer protection via DPF and/or SCC
  • Stripe (payment processing): third country purchase possible; Transfer protection via DPF and/or SCC; Payment services role must be classified separately for each process
  • Cloudflare (security/utility functions currently on rmp.eu; platform-auth.rmp-online.com not yet converted): Third country reference possible; Transfer protection via DPF and SCC
  • Microsoft Application Insights (app channel, iOS/Android): processing by Microsoft Ireland Operations Limited (Dublin, Ireland; sub-processor pursuant to 247GRAD DPA Annex 4) in Azure region West Europe (EU, Netherlands). Intra-group transfer to Microsoft Corporation (USA) possible; transfer safeguarded via EU-U.S. Data Privacy Framework (DPF) and Microsoft Products and Services Data Protection Addendum (DPA) with EU SCC fallback. Configuration confirmed: resource rmp-platform, DPA receipt 09 Jun 2026.
  • GPT Trainer/Paladin Max (app chatbot): third country reference possible; operation/provision via POLYGEN; within this path, models from OpenAI (ChatGPT), Google (Gemini), and optionally Anthropic (Claude) may be used; DeepSeek is not used in the current RMP operation; subprocessor/transfer chain documented (DPA signed, SCC/DPF per provider path); 90-day deletion automation for chat sessions
  • IDS Publishing Corporation (scoring/evaluation in the assessment path, USA): transmission of only minimized fields without real names; Transfer protection via SCC and contractual obligations; Hosting subprocessor GoDaddy (USA)
  • fonio.ai (AI telephone assistant): Operation in the RMP network via Reiss Motivation Profile Switzerland GmbH; Order processing based on the fonio-AVV (contractual partner RMP Germany GmbH); Server according to provider in Germany (Nuernberg); for automated post-call email dispatch, fonio uses sub-processor Sinch AB / Mailgun (email infrastructure, Sweden/USA), secured via EU-US DPF and Standard Contractual Clauses; further sub-processors (including LLM/telephony/logging services) with transfer protection via SCC and/or EU-US DPF; sub-processor and TOM information contractually regulated and documented internally
  • Cal.com (appointment booking): USA/third country reference possible; Data Processing Agreement signed and countersigned with Cal.com (proof May 20, 2026); Transfer protection via DPA/SCC (and if necessary DPF)
  • Acuity Scheduling / Squarespace Inc. (online appointment booking): USA; DPA automatically incorporated into Squarespace Terms of Service (effective Jan 31, 2025); account holder Reiss Motivation Profile Switzerland GmbH; transfer protection via EU-US DPF and SCC
  • Zoom Video Communications, Inc. (video calls, webinars): USA; DPA incorporated into Zoom Terms of Service (November 2024); account holder Polygen Schwyz AG; EU-only data centres (DE/NL/SE) configured; EEA data residency activated; AI Companion functions disabled; transfer protection via EU-US DPF and SCC
  •  

10.3 Obligation to be transparent and audit

We carry out an ongoing comparison between the technical term, contractual basis and text representation. Deviations are tracked, corrected and documented internally.

11. Storage period

Unless a more specific period is specified in this Privacy Policy, we only store personal data for as long as is necessary for the respective processing purpose.

11.1 General delete logic

     
  • Loss of purpose: Data will be deleted or - if necessary and legally permissible - pseudonymized or anonymized as soon as it is no longer needed for the original purpose
  • Revocation of consent: Processing based on consent will be terminated in the future
  • Legal obligations: Storage takes place if commercial, tax or other legal requirements require this
  •  

11.2 Typical storage classes

     
  • Server/security logs: typically 30 days; In the case of security-relevant incidents, exceptionally up to 90 days
  • Consent/cookie proof: usually 12 months
  • Contact/support data: usually 12 months after completion of the process; in legal cases longer to the extent required by law
  • Telephone transcripts/call metadata (fonio), appointment booking data (Cal.com, Acuity Scheduling) and video meeting metadata (Zoom): analogous to contact/support data, unless otherwise contractually or legally
  • Session and dashboard data: until logout/end of session; For login session contexts, storage longer than the session lifetime does not apply
  • GPT Trainer/Paladin Max chat conversations (if used in the login/app context): deletion is automated after 90 days via the operational process
  • Proof of consent for chat use: separate in your own system, not part of the external chat conversation deletion
  • API operation/error logs: typically 30 days; In the case of security-relevant incidents, exceptionally up to 90 days
  • Assessment and profile data: in principle until the account is deleted by the user, provided there are no conflicting legal obligations
  • Contract/billing data: according to statutory retention periods (regularly in the corridor 6 to 10 years, if relevant)
  •  

11.3 Documentation status

The deadlines mentioned are continuously compared with technical runtimes, operational processes and legal reviews. Deviations are tracked, corrected and documented in the verification documentation. For external AI provider paths, it is documented that there are no fixed standard deadlines on the provider side and that deletion is request-based; That's why the controller-side extinguishing automation is managed as a binding operational measure and checked regularly.

12. Children and young people

Our offers on rmp.eu and in the rmp.eu/login area are generally aimed at users of legal age or at people who are able to act effectively contractually in the respective context of use.

We do not consciously process personal data of children and young people for independent contract conclusions without the necessary legal requirements. If consent in accordance with Art. 8 GDPR would be required in individual cases, this may only be given under the applicable legal conditions (including the necessary consent of the legal guardian).

If it becomes known that data was transmitted without the necessary requirements, the data in question will be checked and deleted or blocked to the extent legally required.

13. Rights of data subjects

Affected persons have the following rights in particular within the framework of the legal requirements:

     
  • Information (Article 15 GDPR)
  • Correction of incorrect data (Article 16 GDPR)
  • Deletion (Article 17 GDPR)
  • Restriction of processing (Article 18 GDPR)
  • Data portability (Article 20 GDPR)
  • Objection to certain processing operations (Article 21 GDPR)
  • Revocation of consent given with effect for the future (Art. 7 Para. 3 GDPR)
  •  

To exercise your rights, you can use the contact channels listed in section Controller.

If you believe that the processing of your data violates data protection law, you also have the right to complain to a supervisory authority.

14. Right to complain to the supervisory authority

Without prejudice to any other administrative or judicial remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular:

     
  • in the Member State of your habitual residence,
  • in the Member State of your place of work, or
  • at the location of the alleged violation.
  •  

The responsible supervisory authority for the responsible body in Hesse is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI):

Hessischer Beauftragter für Datenschutz und Informationsfreiheit (HBDI)
Postfach 31 63
65021 Wiesbaden
https://datenschutz.hessen.de/

15. Updates to this Privacy Policy

We will adapt this Privacy Policy as soon as this is necessary due to technical, organizational, legal or regulatory changes.

The current version is published on rmp.eu.

Key updates to this version (as of 01 Jul 2026):

     
  • Structured new version of the data protection information for rmp.eu including the integrated area rmp.eu/login (03 Jun 2026).
  • Clarification of the distribution of roles between RMP germany GmbH, country partners and deployed service providers.
  • 247GRAD GmbH added as app processor (§8.10, §9.3, 23 Jun 2026); Hetzner Online GmbH documented as active API backend provider (§3.1, §9.3, 23 Jun 2026).
  • HBDI postal address added (§14, 25 Jun 2026).
  • Mailchimp / Intuit Inc. added as processor for newsletter and RMP Master onboarding communications (§4.7, 26 Jun 2026).
  • Acuity Scheduling (Squarespace Inc.) added as parallel online booking system (§4.6, 27 Jun 2026).
  • Zoom (Zoom Video Communications, Inc.) added as processor for video calls and webinars (§4.8 new, 27 Jun 2026).
  • §6.1 runtime verification updated (01 Jul 2026): Google Ads Conversion Tag (viewthroughconversion) removed (tag was deactivated in Jun 2026); Google Analytics 4 with Google Signals / remarketing audiences (ga-audiences, after consent only) correctly described; Facebook Pixel, LinkedIn Insight Tag and Stripe explicitly listed.
  •  

If there are significant changes, we will also provide information via suitable channels (e.g. notices on the website and/or in the user context of the dashboard).

Cookies (Declaration)