Workshop privacy policy — Professional & partner courses
Translation for convenience — the German original is legally binding.
Privacy Policy
Last updated: July 2026
Goodsmith GmbH (hereinafter "Goodsmith", "we" or "us") operates the online shop at goodsmith.eu as well as the partner dashboard with all associated information, content, features, tools, products and services (the "Services"). Our Services include the online sale of our hoof protection products, the booking and conduct of our certification workshops, and the management of our partner community.
This Privacy Policy describes how we collect, process and share personal data when you visit our website, make a purchase or workshop booking, attend one of our certification workshops, or otherwise communicate with us. Please read this Privacy Policy carefully before using our Services.
In addition to this Privacy Policy, our General Terms and Conditions (for the sale of goods) and our Terms of Participation for Certification Workshops apply. In the event of a conflict between the aforementioned terms and this Privacy Policy, this Privacy Policy shall take precedence with regard to the collection, processing and sharing of personal data.
1. Controller
The controller within the meaning of Art. 4 No. 7 DSGVO is:
Goodsmith GmbH
Robert-Koch-Straße 1, Haus 1
82152 Planegg
Deutschland
E-Mail: bennet.klein@good-smith.com
2. What personal data we process
Depending on how you interact with us, we may process the following categories of personal data:
- Contact data: Name, postal address, billing address, delivery address, telephone number, e-mail address.
- Financial and payment data: Payment card information, bank details, transaction details, payment confirmations.
- Contractual and account information: Username, password, security questions, configurations, discount group assignments, order history.
- Profession-related data (for workshop bookings): Details of business registration, tax number, professional liability insurer and insurance policy number.
- Workshop data: Format, location and date of the booking, attendance and certification status, photographic documentation of work results, certificate number.
- Communication data: Contents of your messages to our customer support, feedback on workshops.
- Device and usage data: IP address, browser and device information, pages visited, access times, interactions with the Services.
3. Sources of personal data
We receive your personal data from the following sources:
- Directly from you, when you create an account, place an order or workshop booking, communicate with us, or otherwise provide data to us.
- Automatically via the Services, in particular through your end device and your use of our website (cookies and similar technologies).
- From our service providers and processors, who carry out certain processing operations on our behalf (see Section 5).
- From partners and other third parties on the basis of legitimate interests or on the basis of your consent.
4. Purposes and Legal Bases of Processing
We process your personal data for the following purposes:
4.1 Performance of a Contract (Art. 6 Abs. 1 lit. b DSGVO)
For the processing of orders in the online shop, for the organisation and handling of workshop bookings, for the issuance of certificates, for the provision of the partner dashboard, and for communication within the context of existing contractual relationships.
4.2 Legal Obligations (Art. 6 Abs. 1 lit. c DSGVO)
For compliance with statutory retention obligations under tax and commercial law (generally ten years pursuant to §§ 147 AO, 257 HGB), for responding to enquiries from supervisory or law enforcement authorities, and for the fulfilment of other statutory obligations.
4.3 Legitimate Interests (Art. 6 Abs. 1 lit. f DSGVO)
For ensuring IT security, for fraud prevention, for customer relationship management and segmentation within the CRM, for reach measurement and improvement of our services, for the public verifiability of our certifications, and for direct marketing within the limits prescribed by law.
4.4 Consent (Art. 6 Abs. 1 lit. a DSGVO, § 25 Abs. 1 TDDDG)
For cookies and tracking that are not technically necessary, for marketing communications by e-mail outside of an ongoing business relationship, and for participation in the partner WhatsApp group. You may withdraw any consent given at any time with effect for the future.
5. Specific Processing Operations
5.1 Use of the Online Shop (Sale of Goods)
The processing of your data in connection with orders is carried out for the purpose of contract performance. Contact, payment and order data are processed. Payment processing is handled by the payment service providers you select during checkout; reference is made to their respective privacy notices in our General Terms and Conditions.
5.2 Certification Workshops
5.2.1 Booking and Contract Processing
Contact and billing data, information regarding the selected workshop format, location and date, information regarding business registration and professional liability insurance, as well as payment data are processed. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Retention period: for the duration of the contractual relationship plus the statutory retention periods.
5.2.2 Photographic Documentation of Work Results
To ensure the quality of the certification, the workshop instructor takes photographs of the work results (hooves, applied shoeing, application on the horse) and uploads these to a central folder, where they are assigned to your participant profile. Only work results are photographed; portrait or personal photographs are taken only with explicit separate consent.
Purpose: Internal quality assurance, issuance of the Postal Certificate.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract — photographic documentation is a necessary prerequisite for the issuance of the certificate).
Recipients: Exclusively internally responsible employees of Goodsmith GmbH.
Retention period: For the duration of the certification assessment and for retention of the certificate file, but no longer than 10 years after the issuance of the certificate.
Use of the photographic documentation for marketing, advertising or public presentation purposes takes place exclusively on the basis of a separate explicit consent.
5.2.3 Public Verification Page
To enable end customers and third parties to verify our certifications, we publish the following data on a verification page at goodsmith.eu upon entry of a valid certificate number: first name, first letter of the surname, certificate number, workshop format and date of issuance, as well as the active status of the certificate.
Purpose: Public verifiability of the qualification of certified partners.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). The balancing of interests takes into account, on the one hand, the considerable interest in the verifiability of our certificates and, on the other hand, the minimal scope of the data published (no full surname, no searchable directory, findability only upon knowledge of the certificate number).
Retention period: For as long as the certification is active. Following invalidation or revocation: designation as "no longer active" for a further 24 months, followed by deletion.
You may object to the listing on the verification page at any time with effect for the future; the certificate itself remains unaffected thereby.
5.2.4 Certificate Printing and Postal Dispatch
For the physical printing and postal dispatch of the certificate, we process your first and last name as well as your postal address, certificate number and workshop details. Printing and dispatch are carried out internally by Goodsmith; no engagement of external processors takes place.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
5.2.5 Anonymous Feedback Survey
Following each workshop, participants receive a link to an anonymous feedback survey. The survey is technically designed in such a way that no tracing back to the individual person is possible; exclusively rating data without personal attribution are stored.
Purpose: Evaluation of workshop quality, improvement of our offerings.
Legal basis: Not applicable in the case of genuinely anonymous data.
5.2.6 Administration in the Partner Health System (HubSpot)
For the purposes of customer relationship management and segmentation, we use the Partner Health System (HubSpot). Contract data, order history, workshop history, feedback scores and the assignment to partner segments derived therefrom are processed.
Purpose: Customer relationship management, targeted communication, evaluation of partner performance.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in structured customer management).
Processor: HubSpot Ireland Limited, 2 Dockland Central, Guild Street, Dublin 1, Ireland. A data processing agreement pursuant to Art. 28 GDPR is in place.
Data transfer to the USA: HubSpot processes data, inter alia, in the USA. The transfer is carried out on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR) and additionally on the basis of standard contractual clauses (Art. 46(2)(c) GDPR).
Segmentation is carried out on a rule-based basis and serves exclusively for communication management. No automated decisions within the meaning of Art. 22 GDPR with legal effect vis-à-vis you take place.
5.2.7 Partner WhatsApp Group
Certified partners may join the Partner WhatsApp Group on a voluntary basis. Your mobile phone number as well as the details stored in your WhatsApp profile (name, profile picture) are processed.
Purpose: Professional exchange within the partner community.
Legal basis: Art. 6(1)(a) GDPR (consent by means of the active act of joining).
Data recipients: Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, D04 X2K5, Ireland and its affiliated companies.
Data transfer to the USA: Meta processes data, inter alia, in the USA. The transfer is carried out on the basis of the EU-US Data Privacy Framework and additionally on the basis of standard contractual clauses.
Participation is voluntary and is not a prerequisite for certification. You may terminate the processing at any time by leaving the group.
5.3 Meta Pixel and Meta Conversions API (Facebook and Instagram)
We use the Meta Pixel and the Conversions API of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland ("Meta") on our website.
Purpose of processing. By means of the Meta Pixel and the Conversions API, Meta enables us to identify visitors to our online offering as a target audience for the display of advertisements on Facebook and Instagram ("Custom Audiences") and to measure the effectiveness of our advertisements (conversion tracking) for statistical purposes.
Data processed. IP address, browser and device information, pages visited and actions taken (page views, product views, shopping cart, purchases), time of access, referral URL and — where available — your Meta user ID. Via the Conversions API, additionally pseudonymised (hashed) event data are transmitted server-side (including hashed e-mail address, telephone number, name, address components as well as order and event data).
Legal basis. Your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may withdraw your consent at any time with effect for the future by adjusting your cookie settings.
Joint controllership. In respect of the collection and transmission of the data, we and Meta are joint controllers within the meaning of Art. 26 GDPR. Joint controllership is limited to collection and onward transmission. The subsequent processing by Meta is the sole responsibility of Meta. The obligations agreed between us and Meta can be found at https://www.facebook.com/legal/controller_addendum.
Data transfer to the USA. Meta is certified under the EU-US Data Privacy Framework; in addition, standard contractual clauses pursuant to Art. 46(2)(c) GDPR are used.
Objection and withdrawal. You may object to the processing at any time by withdrawing your consent via our cookie banner or by adjusting the advertising settings in your Meta account (https://www.facebook.com/settings?tab=ads).
5.4 Shopify as Hosting and Service Provider
Our website and our online shop are hosted by Shopify International Limited (Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland). Shopify collects and processes personal data on our behalf regarding your access to and use of the services. To improve our offering, we use certain advanced Shopify features, which may incorporate data from your interactions with our shop as well as across shops.
The privacy notices of Shopify apply to the data collected and used by Shopify: https://www.shopify.com/legal/privacy/app-users. Further information on exercising your rights vis-à-vis Shopify: https://privacy.shopify.com/en.
6. Disclosure of Personal Data to Third Parties
We disclose your personal data to third parties where this is necessary for the aforementioned purposes. Recipients include in particular:
- Processors, who provide services on our behalf (IT management, payment processing, data analysis, cloud storage, fulfilment and shipping, HubSpot CRM).
- Business and marketing partners, who provide marketing services on our behalf.
- Meta Platforms, in the context of the use of the Meta Pixel and the Conversions API (see Section 5.3) as well as the partner WhatsApp group (see Section 5.2.7).
- Authorities and courts, where we are required to do so by law or where this is necessary to safeguard legitimate interests.
- Corporate group, in the context of a business transaction (merger, restructuring, insolvency).
Any disclosure beyond this takes place only with your express consent.
7. Retention Periods
We store personal data only for as long as is necessary for the respective purpose or as required by statutory retention obligations. Specific retention periods are stated for the individual processing operations in Section 5. Documents relevant under commercial and tax law are retained by us as a rule for ten years (§§ 147 AO, 257 HGB).
8. International Transfers
We transfer personal data outside the European Economic Area only where an adequate level of data protection is ensured. This takes place in particular on the basis of adequacy decisions of the European Commission (such as the EU-US Data Privacy Framework) or on the basis of standard contractual clauses pursuant to Art. 46 Abs. 2 lit. c DSGVO. The specific legal bases for individual recipients are identified in Section 5.
9. Your Rights
Under the DSGVO, you have the following rights:
- Right of access (Art. 15 DSGVO): You may request information about which data we process about you.
- Right to rectification (Art. 16 DSGVO): You may request the rectification of inaccurate or incomplete data.
- Right to erasure (Art. 17 DSGVO): You may, under certain conditions, request the erasure of your data.
- Right to restriction of processing (Art. 18 DSGVO): You may, under certain conditions, request the restriction of processing.
- Right to data portability (Art. 20 DSGVO): You may receive your data in a structured, commonly used and machine-readable format.
- Right to object (Art. 21 DSGVO): You may object at any time to the processing of your data on grounds relating to your particular situation. In the case of direct marketing, an absolute right to object exists.
- Withdrawal of consent (Art. 7 Abs. 3 DSGVO): Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of the processing carried out up to that point remains unaffected.
- Right to lodge a complaint (Art. 77 DSGVO): You may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence. The authority responsible for our registered seat is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
To exercise your rights, please contact the details set out in Section 12. In order to verify your identity, we may request additional information from you. The exercise of your rights shall not result in any disadvantage to you.
10. Security
We protect your personal data by means of technical and organisational measures in accordance with the current state of the art. Please note, however, that the transmission of data via the internet is not in every case entirely free of risk. We recommend transmitting sensitive information to us exclusively via secure channels.
11. Data of Children
Our services are not directed at children. We do not knowingly collect personal data from children under the age of 16. Should we become aware that we have collected data from persons under the age of 16, such data will be deleted without delay. Parents or guardians who suspect that their child has transmitted personal data to us may contact us using the contact details provided in Section 12.
12. Contact
For questions regarding this Privacy Policy, to exercise your rights, or for any other data protection-related concerns, please contact:
Goodsmith GmbH
Robert-Koch-Straße 1, Haus 1
82152 Planegg
E-Mail: bennet.klein@good-smith.com
13. Changes to this Privacy Policy
We update this Privacy Policy from time to time in order to reflect changes to our processing operations or for operational, legal, or regulatory reasons. The currently applicable version can be found on this page. The date of the most recent update is indicated at the beginning of this Privacy Policy.
Last updated: 28 July 2026






