Last updated: August 2026
We take the protection of your personal data seriously. This Privacy Policy explains how personal data is processed when you visit the LSPnext website, register for the LSPnext Community, use your community account or purchase services through LSPnext.
1. Controller
The controller responsible for the processing of personal data on this website and within the LSPnext Community is:
Leadership Campus GmbH
[full postal address]
Germany
Email: [privacy/contact email]
LSPnext is a project operated by Leadership Campus GmbH.
Further legal information can be found in our Imprint.
2. General Information on Data Processing
We process personal data only where this is necessary to provide our website, community, services and contractual offerings, where we are legally required to do so, where we have a legitimate interest in the processing, or where you have given us your consent.
Depending on the processing activity, the legal basis may in particular be:
- Art. 6(1)(a) GDPR – consent;
- Art. 6(1)(b) GDPR – performance of a contract or steps taken prior to entering into a contract;
- Art. 6(1)(c) GDPR – compliance with a legal obligation;
- Art. 6(1)(f) GDPR – our legitimate interests or those of a third party.
Where processing is based on consent, you may withdraw your consent at any time with effect for the future.
3. Website Hosting and Server Log Files
When you access our website, technical information is automatically transmitted by your browser to the server on which the website is hosted.
This may include:
- IP address;
- date and time of access;
- requested page or file;
- referring website;
- browser type and version;
- operating system;
- device information;
- HTTP status code.
This information is required to technically deliver the website, ensure system security, identify technical problems and protect the website against misuse and attacks.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our website and community platform.
Our hosting provider is:
[name and address of hosting provider]
Where the hosting provider processes personal data on our behalf, this processing takes place on the basis of a data processing agreement in accordance with Art. 28 GDPR.
4. Registration for the LSPnext Community
To use the registered areas of the LSPnext Community, you must create a personal account.
During registration, we process the information provided in the registration form. Depending on the information requested, this may include:
- first name;
- last name;
- email address;
- username;
- password or encrypted password information;
- professional information;
- profile information;
- date and time of registration;
- IP address;
- confirmation of the Terms of Use;
- information relating to your membership status.
We process this information to:
- create and administer your LSPnext account;
- provide access to the appropriate community areas;
- identify you within the community;
- manage your membership;
- communicate with you regarding your account and membership;
- document acceptance of our Terms of Use;
- protect the community against misuse.
The legal basis for account creation and administration is Art. 6(1)(b) GDPR.
Where processing is required for platform security, abuse prevention or the documentation of legally relevant actions, processing may additionally be based on Art. 6(1)(f) GDPR.
Your registration data is generally stored for as long as your account exists. Following account deletion, data will be deleted unless continued storage is required for legal, contractual or security reasons.
5. Registration Forms – Fluent Forms
We use the WordPress plugin Fluent Forms to provide registration and other forms on our website.
Information entered into a form is processed within our WordPress installation and stored in accordance with the configuration of the respective form.
Depending on the form, this may include:
- name;
- email address;
- profile or professional information;
- form responses;
- date and time of submission;
- IP address;
- consent declarations;
- acceptance of Terms of Use.
The purpose and legal basis depend on the respective form.
For community registration, processing is generally based on Art. 6(1)(b) GDPR.
Where you provide a separate consent, processing is based on Art. 6(1)(a) GDPR.
We only request information that is required for the respective purpose.
6. LSPnext Community – FluentCommunity
The LSPnext Community is operated using the WordPress community software FluentCommunity.
When using the community, we may process information including:
- profile data;
- profile image;
- professional headline and biography;
- posts;
- comments and replies;
- reactions;
- uploaded files or images;
- group and community memberships;
- activity information;
- communication with administrators or moderators;
- reports concerning content or behaviour.
Information you publish within community areas is visible to other users who have access to the respective area.
Please therefore carefully consider which personal or confidential information you publish.
The processing of community data is necessary to provide the LSPnext Community and its communication and collaboration functions.
The legal basis is Art. 6(1)(b) GDPR.
Processing required for moderation, prevention of misuse, enforcement of our Terms of Use and protection of members may also be based on Art. 6(1)(f) GDPR.
Our legitimate interests include maintaining a safe, professional and functional community environment.
7. Public Profile Information
Depending on your membership settings, parts of your profile may be visible to other members.
This may include, for example:
- name;
- profile image;
- professional headline;
- biography;
- country or region;
- social media links;
- professional interests.
Please only provide information that you wish to make available to other authorised members of the community.
You can edit many elements of your profile yourself through your LSPnext account.
8. Posts, Comments and User-Generated Content
When you publish posts, comments, replies, images, documents or other content within LSPnext, we process this content together with information linking it to your user account.
The purpose is to enable professional communication and exchange within the community.
The legal basis is Art. 6(1)(b) GDPR.
Where content is reviewed or processed for moderation, security, prevention of misuse or enforcement of community standards, the legal basis may also be Art. 6(1)(f) GDPR.
If you delete your account, certain contributions may remain within existing discussions where this is necessary to maintain the integrity and context of the conversation. Where appropriate, such content may be anonymised.
9. FluentCRM
We use FluentCRM within our WordPress environment to organise member and customer information and to manage communication relating to LSPnext.
Depending on your relationship with LSPnext, we may process information including:
- name;
- email address;
- membership status;
- tags or categories;
- registration information;
- purchases;
- participation in programmes or activities;
- communication history.
We use this information to administer memberships, provide relevant account and service information and organise communication with members.
For contractual and membership-related communication, the legal basis is Art. 6(1)(b) GDPR.
Where communication is based on a separate consent, the legal basis is Art. 6(1)(a) GDPR.
10. Email Communication and Transactional Emails
We send emails where necessary to operate your account and provide our services.
These may include:
- registration confirmations;
- account notifications;
- password reset emails;
- membership information;
- booking or payment confirmations;
- important information relating to the operation of LSPnext.
For these purposes, we process your name, email address and information necessary for the relevant communication.
Transactional and account-related communication is generally based on Art. 6(1)(b) GDPR.
Emails are technically transmitted via:
[name of email/SMTP provider]
Where this provider processes data on our behalf, appropriate contractual data protection arrangements are used.
11. Newsletters and Marketing Emails
Where we offer newsletters or marketing communication, such emails will only be sent where there is an appropriate legal basis.
Where your consent is required, the legal basis is Art. 6(1)(a) GDPR.
You may withdraw your consent at any time, for example by using the unsubscribe function contained in the respective email.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Account-related and contractual communications are not marketing communications and may still be sent where they are necessary to provide your membership or services.
12. Purchases and WooCommerce
We use WooCommerce to manage purchases, memberships, courses and other paid services offered through LSPnext.
When you make a purchase, we may process information including:
- name;
- billing address;
- email address;
- company information;
- tax information where required;
- products or services purchased;
- order date;
- order status;
- payment status;
- transaction information.
This information is processed for order administration, performance of the contract, invoicing, accounting and fulfilment of legal obligations.
The legal basis is Art. 6(1)(b) GDPR for contractual processing and Art. 6(1)(c) GDPR where information must be retained to comply with statutory accounting or tax obligations.
Payment information may be transmitted to the selected payment service provider.
We do not require access to full credit card details where these are processed directly by the payment service provider.
13. Payments via Stripe
We use Stripe to process electronic payments.
When you select a payment method provided through Stripe, information required for payment processing is transmitted to Stripe.
This may include:
- name;
- email address;
- billing information;
- payment information;
- transaction amount;
- currency;
- transaction identifiers;
- technical information required to prevent fraud and process the payment.
For users in the European Economic Area, Stripe services may involve Stripe Payments Europe Limited, Ireland, as well as other Stripe entities and service providers depending on the payment method and processing involved.
The purpose of processing is to process payments, prevent fraud and manage payment-related transactions.
The legal basis for the transmission of information required to process your payment is Art. 6(1)(b) GDPR.
Where Stripe carries out processing for its own legally defined purposes, Stripe may act as an independent controller for those processing activities.
Further information on Stripe’s processing of personal data can be found in Stripe’s Privacy Policy.
14. Cookies and Similar Technologies
Our website uses cookies and similar technologies.
Cookies are small pieces of information stored on your device or accessed through your browser.
Technically necessary cookies
Some cookies or similar storage mechanisms are necessary to provide functions expressly requested by you.
These may be required, for example, for:
- user login;
- account authentication;
- session management;
- security;
- shopping cart functionality;
- payment processes;
- remembering technically necessary settings.
Where storage or access to information on your device is strictly necessary to provide the service requested by you, consent is not required under § 25(2) TDDDG.
Where personal data is processed in connection with such technologies, the processing is based on the applicable provision of Art. 6(1) GDPR.
Optional cookies and technologies
Where we use cookies or technologies that are not technically necessary, particularly for analytics, marketing or tracking, they will only be activated where legally required after you have given your consent.
The legal basis for the storage of or access to information on your device is § 25(1) TDDDG in conjunction with your consent.
Where personal data is subsequently processed, the legal basis is generally Art. 6(1)(a) GDPR.
You can withdraw or change your consent at any time through the cookie settings available on our website.
15. Embedded Content and External Services
Pages within LSPnext may contain content from external providers, for example videos, maps, social media content or other embedded services.
If external content is loaded, the relevant provider may receive technical information such as your IP address and browser information.
Where such services are not technically necessary, they will only be loaded where required after consent has been obtained.
Details of the services actually used and the respective providers should be displayed through our consent management system or described in this Privacy Policy where applicable.
16. Recipients of Personal Data
Personal data may be disclosed to external recipients where this is necessary for the purposes described in this Privacy Policy.
These recipients may include:
- website and server hosting providers;
- email and communication service providers;
- payment service providers;
- IT and technical service providers;
- professional advisers such as tax advisers or accountants;
- public authorities where disclosure is legally required.
Where service providers process personal data on our behalf, we conclude data processing agreements where required by Art. 28 GDPR.
We do not sell personal data to third parties.
17. International Data Transfers
Some service providers may process personal data outside the European Economic Area.
Where personal data is transferred to a country outside the European Economic Area, we ensure that the requirements of Chapter V GDPR are met.
Depending on the provider and destination country, this may include:
- an adequacy decision by the European Commission;
- the EU-U.S. Data Privacy Framework where applicable;
- Standard Contractual Clauses approved by the European Commission;
- other legally recognised safeguards.
Information about specific international transfers is provided in the relevant sections of this Privacy Policy where applicable.
18. Storage Periods
We store personal data only for as long as necessary for the respective processing purpose.
The actual retention period depends on the type of data and the purpose for which it is processed.
In particular:
- account information is generally stored for the duration of your membership;
- community content may be retained where necessary to preserve the context of discussions;
- form submissions are stored only for as long as they are required for the relevant purpose;
- contractual, invoicing and payment information may be retained for statutory accounting and tax retention periods;
- security and technical data is retained only for the period necessary for security and system administration unless longer retention is required in a specific case.
After the applicable retention period expires, personal data is deleted or anonymised unless further processing is legally permitted or required.
19. Your Data Protection Rights
Subject to the applicable legal requirements, you have the right to:
- obtain information about the personal data we process about you;
- request correction of inaccurate personal data;
- request deletion of your personal data;
- request restriction of processing;
- receive personal data you have provided to us in a structured, commonly used and machine-readable format where the legal requirements for data portability are met;
- object to certain processing based on legitimate interests;
- withdraw consent at any time with effect for the future.
To exercise your rights, please contact:
[privacy/contact email]
You also have the right to lodge a complaint with a competent data protection supervisory authority.
20. Data Security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures are reviewed and adapted where appropriate in light of technical developments and the nature of the processing.
However, no internet-based transmission or storage system can guarantee absolute security.
21. Automated Decision-Making
We do not currently use automated decision-making within the meaning of Art. 22 GDPR to make decisions that produce legal effects concerning members or similarly significantly affect them.
If this changes, this Privacy Policy will be updated accordingly.
22. Changes to this Privacy Policy
We may update this Privacy Policy where our services, technical systems or legal requirements change.
The current version is always available on the LSPnext website.
Where changes materially affect the processing of member data, we will provide appropriate information to affected users.
Leadership Campus GmbH – LSPnext
Privacy Policy – Version August 2026
