Privacy Policy
1. Controller within the meaning of the GDPR
Die verantwortliche Stelle für die Datenverarbeitung auf dieser Website ist:
Sarah Tabola
Am Schafsteg
64569 Nauheim
Deutschland
Phone: 0176 675 306 85
Mail: hello@sarahtabola.com
Website: www.sarahtabola.com
2. General information on data processing
We take the protection of your personal data very seriously. Personal data is processed confidentially and in accordance with the applicable data protection regulations and this privacy policy.
When you use this website, various personal data are collected. This privacy policy explains what data we collect, what we use it for, and the legal basis for doing so.
3. Access Data and Hosting (United Domains)
Our website is hosted by united-domains AG (Gautinger Straße 10, 82319 Starnberg, Germany).
When you visit our website, certain data is automatically collected and stored in so-called server log files, including:
- IP address (anonymized or truncated)
- Date and time of request
- Browser type and version, as well as the operating system used
- Referrer URL (the previously visited page)
- Name of the retrieved file and target domain
This data serves the purposes of technical security, error analysis, and website stability. Processing is based on Art. 6(1)(f) GDPR (legitimate interest in the error-free and secure operation of our website). We have entered into a data processing agreement (DPA) with united-domains in accordance with Art. 28 GDPR.
4. Consent management (Borlabs cookie)
Our website uses the consent management technology of Borlabs Cookie to obtain your consent for the storage of certain cookies in your browser or the use of certain technologies and to document this in a manner compliant with data protection regulations.
When you visit our website, a Borlabs cookie is stored in your browser to record the consents you have granted or the withdrawal of such consents. This data is not shared with the provider of Borlabs Cookie but remains on our server. Processing is carried out to fulfill our legal obligation to obtain consent in accordance with Art. 6(1)(c) GDPR.
5. Online Shop (WooCommerce & Registration)
We operate an online shop on our website based on the system WooCommerce.
Customer Account and Registration
To make purchases in our online shop (e.g., digital products, bookings for sessions, seminars, or events), registration and the creation of a customer account are required. The data you enter (name, address, email address, and—if applicable—telephone number) is processed during this process. This processing is carried out for the purpose of fulfilling the contract or taking steps prior to entering into a contract, based on Article 6(1)(b) of the GDPR.
Payment processing
We use the payment service provider PayPal to process payments. When you make a purchase or book an appointment, your payment details (e.g., name, purchase amount, bank or credit card details) are transmitted to PayPal to process the payment.
PayPal: The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. Data is transmitted on the basis of Art. 6(1)(b) GDPR (performance of a contract). Details regarding data processing can be found in PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
6. Appointment Management and Bookings
On our website, we offer the option to book online sessions, in-person appointments, seminars, and events directly.
Appointment booking software (Amelia)
For online appointment booking and management, we use the WordPress plugin Amelia (developed by TMS-Plugins / TMS Solutions LLC).
The plugin is hosted and operated locally on our own server. The data you enter when booking an appointment (e.g., name, email address, phone number, selected appointment, and any comments) is processed directly on our server and is not transmitted to TMS Solutions servers.
To manage and coordinate appointments, booking data may be synchronized with our external calendar service (e.g., Google Calendar or Apple iCloud) to avoid scheduling conflicts.
The legal basis for the processing of data in the context of appointment booking is the performance of a contract with you or the taking of steps prior to entering into a contract pursuant to Art. 6(1)(b) GDPR.
7. Contact options
Contact Form (WS Form) & Email
If you send us inquiries via the contact form (provided by the WS Form plugin) or directly by email, your details—including the contact information you provide—will be stored by us for the purpose of processing the inquiry and handling any follow-up questions.
The data entered via the contact form remains on our web server (stored in our database within the WordPress installation) and is additionally forwarded to us via email.
The legal basis for this processing is our legitimate interest in effectively handling inquiries addressed to us (Art. 6(1)(f) GDPR) or, if the inquiry aims at concluding a contract (e.g., booking a session or a seminar), Art. 6(1)(b) GDPR.
The data remains with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions—particularly statutory retention periods—remain unaffected.
Contact via WhatsApp
If you contact us via the WhatsApp messaging service, this takes place using the private version of the messenger. The provider is WhatsApp Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland).
Contact is initiated solely at your own discretion. If you send us a message, we process your telephone number, your name (to the extent shared via WhatsApp), and the content of your message in order to handle your inquiry. The legal basis for this processing is your express consent pursuant to Art. 6(1)(a) GDPR, which you provide by actively sending the message. If the message aims to conclude a contract (e.g., booking a session or a seminar), an additional legal basis is Art. 6(1)(b) GDPR.
Please note that WhatsApp transfers personal data to its parent company, Meta Platforms, Inc., in the USA. Meta is certified under the EU-US Data Privacy Framework, ensuring an adequate level of data protection for the data exchanged within the chat.
8. Newsletter (Brevo)
If you wish to subscribe to the newsletter offered on the website, we require an email address from you. The newsletter is sent via the service provider Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany).
Double opt-in process
We use a so-called double opt-in procedure for newsletter subscriptions. This means that after signing up, you will receive an email asking you to confirm your subscription. This confirmation is necessary to prevent anyone from signing up using someone else's email address. Processing is based on your consent in accordance with Art. 6(1)(a) GDPR.
Performance Measurement (Tracking)
Our newsletters contain a so-called "web beacon"—a pixel-sized file that is retrieved from the Brevo server when the newsletter is opened. This retrieval process involves collecting technical information (e.g., regarding the browser, your system, your IP address, and the time of access) as well as information on whether and when the newsletter was opened and which links were clicked. This analysis helps us understand our users' reading habits and tailor our content accordingly. This tracking is also carried out based on your consent in accordance with Art. 6(1)(a) GDPR. You may withdraw this consent at any time by unsubscribing from the newsletter.
We have entered into a data processing agreement (DPA) with Sendinblue GmbH (Brevo).
9. Analysis and tracking tools
The tools mentioned in this section are activated only after your explicit consent via our consent management system (Borlabs Cookie).
Google Analytics 4 (GA4)
Subject to your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland).
GA4 uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). IP anonymization is enabled by default in Google Analytics 4, meaning your IP address is truncated by Google within European Union member states before being transmitted to the USA. Data processing takes place exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). Google is certified under the EU-US Data Privacy Framework.
Meta Pixel
Subject to your consent, we use the Meta Pixel from Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland).
The Meta Pixel enables Meta to identify visitors to our online services as a target audience for displaying advertisements (so-called “Facebook Ads” or “Instagram Ads”). We use the Meta Pixel to ensure that the Meta ads we run are displayed only to users who have shown an interest in our online services. Processing takes place solely on the basis of your consent (Art. 6 para. 1 lit. a GDPR). Meta Platforms, Inc. (USA) is certified under the EU-US Data Privacy Framework.
10. Social Media (Instagram)
We maintain a public Instagram page at: www.instagram.com/sarah.tabola
Instagram is a service provided by Meta Platforms Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland).
When you visit our Instagram page, Meta processes users' personal data. We are jointly responsible with Meta for the processing of so-called "Insights data" (page statistics) in accordance with Article 26 of the GDPR. You can find the relevant agreement with Meta here: Facebook Page Insights Supplement.
Further information on data processing by Instagram can be found in the Meta Privacy Center.
11. No external third-party embeds
We do not embed external third-party content (such as YouTube videos, Vimeo, Google Maps, or external Instagram feeds) on our website. All fonts used (Google Fonts: Montserrat, Merriweather) are installed locally on our server, ensuring that no data is transmitted to Google when the page loads.
12. Retention period
Unless a specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted, unless we have other legally permissible grounds for retaining it (e.g., statutory retention periods under tax or commercial law, such as Section 257 of the German Commercial Code [HGB] or Section 147 of the German Fiscal Code [AO]).
13. Your rights under the GDPR
As the data subject, you have the right at any time to:
- Information (Art. 15 GDPR) regarding your data stored by us
- Rectification (Art. 16 GDPR) of inaccurate data
- Erasure (Art. 17 GDPR) of your data (“right to be forgotten”)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR) to processing based on a legitimate interest
- Revocation of consents granted (Art. 7(3) GDPR) with effect for the future
To exercise these rights, an informal notification via email to hello@sarahtabola.com is sufficient.
14. Right to lodge a complaint with the supervisory authority
In accordance with Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. The competent authority is generally the supervisory authority at your habitual residence, your place of work, or the place where our company is based (The Hessian Commissioner for Data Protection and Freedom of Information).
Last updated: 09.07.2026