Privacy Policy

Preamble

The Project Business Foundation as an independent thinktank is a brand of Oliver F. Lehmann. Protecting your personal data is a high priority for us. This policy explains what personal data we collect, why, on what legal basis, how long we keep it, and who we share it with, in line with the EU General Data Protection Regulation (GDPR).

This policy covers both of our web properties:

1. Controller

The controller responsible for processing your personal data is:

Oliver F. Lehmann
Project Business Training
Trollblumenstr. 39g
80995 Munich, Germany
E-mail: oliver@oliverlehmann.com

Website: https://OliverLehmann.com

You can exercise any of the rights described in section 9 by contacting us at the address above.

2. Definitions

The pivacy declaration of the Project Business Foundation is based on the terms used by the European Data Protection Supervisor when adopting the General Data Protection Regulation (GDPR). Our data protection declaration should be easy to read and understand for the public as well as for our customers and business partners. To ensure this, we would like to explain in advance the terminology used.

We use the following terms, among others, in this privacy statement:

Where we refer to a legal basis (e.g. “Art. 6(1)(b)”), we mean the corresponding provision of the GDPR.

3.  Access data and server logs

When you visit our websites, our hosting infrastructure automatically records technical data needed to deliver and secure the service: browser type/version, operating system, referring page, the pages you access, date and time, IP address, and your internet service provider. We use this data to serve content correctly, to maintain stability and security, and to investigate misuse or attacks. The legal basis is our legitimate interest in a secure, functioning website (Art. 6(1)(f)). Access logs are retained for a short period (see section 8) and are not used to identify you personally except where necessary to defend against an attack.

4. Cookies and consent

Our website uses cookies and similar technologies. Strictly necessary cookies are set to operate the site; all non-essential cookies and third-party scripts (including analytics — see section 5) are loaded only after you consent. We manage consent with the WPConsent cookie-consent tool, which lets you accept or reject cookie categories and change your choice at any time via the consent banner. You can also block or delete cookies in your browser settings; some site features may then not work fully.

For further details, please see our Cookie Note at https://project-business.org/about/cookie-policy/.

5. Website services and third-party plugins

WordPress

Our project-business.org website is built on WordPress and uses the components listed below.

The privacy policy of WordPress can be found at https://wordpress.org/about/privacy/

Plugins

Each is listed with its purpose and any data it processes or transfers to a third party.

Service / pluginPurposePersonal data & recipient
Google Analytics (via MonsterInsights)Website usage statistics — how visitors find and use the site.Sets analytics cookies and transmits usage data (pages viewed, device/browser, truncated/anonymised IP to Google (Google Ireland Ltd; Google LLC, USA). Loaded only with your consent. Legal basis: consent (Art. 6(1)(a)). You can withdraw consent at any time via the cookie banner.
WPConsentCookie-consent banner and script blocking.Stores your consent choices (locally / in a consent record). Legal basis: legal obligation and legitimate interest in demonstrating consent (Art. 6(1)(c)/(f)).
Everest FormsContact, registration and event forms.Processes and stores the data you submit in a form (e.g. name, e-mail, message) to respond to your request. Legal basis: your request / (pre-)contract or consent (Art. 6(1)(b)/(a)).
Sucuri SecuritySecurity auditing and malware scanning.Activity logs may record IP addresses; remote scans transmit site data to Sucuri Inc. (USA). Legal basis: legitimate interest in security (Art. 6(1)(f)).
RedirectionManages URL redirects and logs 404 (not-found) errors.May log request URL, referrer and IP address to diagnose broken links. Processed locally; retained briefly. Legal basis: legitimate interest (Art. 6(1)(f)).
All in One SEOSearch-engine metadata and sitemaps.Operates on page content/metadata; does not, by itself, transfer visitor personal data to third parties.
CoBlocks (by GoDaddy)Page-building content blocks for the editor.Renders page content; no visitor personal data transferred by the plugin.
WPCodeInserts site-wide code snippets (e.g. the analytics tag).A tool for administrators; any third-party script it loads is disclosed separately (e.g. Google Analytics, above) and gated by consent.
PBP Foundation Pages (Project Business Foundation)Surfaces the certification portal’s scholarship application and Foundation workshops as in-theme pages.These pages collect data on behalf of, and route it to, our certification platform (section 6). Processing there is described in that section.
WP File ManagerAdministrative file management.Used by administrators only; does not process visitor personal data.

6. The certification platform (cert.project-business.org)

Our certification platform processes personal data to register exam candidates, deliver and grade the PBP exam, issue and verify certificates, and operate the related community, provider (AEP), corporate and scholarship services.

6.1 Data we process

6.2 Sub-processors of the certification platform

ProviderRoleLocation / transfer safeguard
SupabaseDatabase and file storage for all platform data.Processing under a DPA, with EU Standard Contractual Clauses where data leaves the EU.
ResendDelivery of transactional and information e-mails.USA; DPA + Standard Contractual Clauses.
VercelApplication hosting and server logs.USA / global edge; DPA + Standard Contractual Clauses.
Anthropic (Claude)AI-assisted assessment of scholarship applications; drafting of our own LinkedIn content (section 7).USA; DPA + Standard Contractual Clauses.
Google (Drive)Storage of media used in our LinkedIn content.USA; DPA + Standard Contractual Clauses.
WooCommerce store (OliverLehmann.com)Look-up of voucher purchasers (name, e-mail) to link purchases to accounts.Operated by the controller.

7. Automated processing in the scholarship programme

For applications to the PBP scholarship programme, we use an automated analysis to help assess applications. The information you enter in the application form is processed by our AI sub-processor (Anthropic) to produce a written assessment and a suitability indication. This is a decision-support tool only — every scholarship decision is made by a human reviewer, and the automated output does not by itself produce a legal or similarly significant effect within the meaning of Article 22 GDPR. Uploaded supporting documents are not sent to the AI. The legal basis is your explicit consent, given when you submit the application; you may withdraw it at any time, and you may request human review of, and contest, any assessment. Outside the scholarship programme we do not use automated decision-making that produces legal or similarly significant effects.

8. Retention periods

We keep personal data only as long as necessary for the purpose it was collected for, or as required by law. Our standard periods are:

CategoryRetention
Certification records (name, credential, award date, certificate ID, city/country)For the life of the credential (the PBP certification is granted for life); retained indefinitely for verification, subject to registry opt-out.
Information/marketing contacts (subscribers)Until you opt out. On opt-out we keep only a minimal suppression record so we do not contact you again.
Candidate postal addressDeleted approx. 12 months after the certificate is issued (no longer needed; the registry uses only city/country).
Exam operational detail (individual answers, failed-attempt sessions)Approx. 24 months, then deleted; the passing result underlying a certificate is retained as part of the credential.
Non-certified / abandoned accountsDeleted after approx. 24–36 months of inactivity where no credential was earned.
Scholarship application content and uploaded documentsVery short-lived: erased shortly after the decision and any appeal window; only the minimal outcome record is retained to administer the programme.
AEP and corporate accountsDuration of the relationship plus 24 months after expiry/termination; API keys are revoked immediately on termination.
Community content (posts, comments, attachments)Kept while the account is active; deleted or anonymised when the account is closed.
Security and audit logs (session IP/user-agent, login and admin logs)Access/server logs approx. 30–90 days; security-audit records approx. 12 months.
Website analytics data (Google Analytics)Per our configured Google Analytics retention setting.
Financial / billing records (voucher purchases, invoices)Retained for the statutory period under German tax and commercial law (currently 8–10 years).

When we delete data from our live systems, it is also removed from backups on the next backup-rotation cycle. Where we no longer need to identify you but still need the data for statistics (e.g. pass rates by country), we anonymise it rather than keep it in identifiable form.

9. Your rights

Under the GDPR you have the right to: confirmation and access to your data; a copy of it; rectification of inaccurate data; erasure (“right to be forgotten”); restriction of processing; data portability; and to object to processing based on legitimate interest or to direct marketing. Where processing is based on consent, you may withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at info@project-bussines.org. Certified members can additionally manage registry visibility and communication opt-outs from their account, and scholarship applicants can erase their application data from the application status page.

LinkedIn’s applicable privacy policy is available at https://www.linkedin.com/legal/privacy-policy.

LinkedIn’s cookie policy is available at https://www.linkedin.com/legal/cookie-policy.

10. International data transfers

Some of our processors are located in the United States or operate globally (see sections 5 and 6). Where personal data is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses and any applicable adequacy framework to safeguard your data.

11. Legal bases (summary)

Performance of a contract or pre-contractual steps — Art. 6(1)(b) (e.g. registering for and taking the exam, issuing certificates, AEP/corporate services).

Consent — Art. 6(1)(a) (e.g. non-essential cookies and analytics, marketing e-mails, registry publication of optional fields, the scholarship AI assessment).

Legal obligation — Art. 6(1)(c) (e.g. statutory retention of billing records).

Legitimate interests — Art. 6(1)(f) (e.g. security, fraud prevention, maintaining the integrity of the credential registry).

12. Legitimate interests in processing pursued by the controller or a third party

If the processing of personal data is based on Article 6 I lit. f DS-GVO, our legitimate interest is the performance of our business activities for the benefit of the well-being of all our employees and our shareholders.

13. Supervisory authority

Our competent supervisory authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Ansbach, Germany. You may also contact the authority in your country of residence.

Version of this privacy policy: 14 August 2025