
Privacy Policy
Preamble
The Project Business Foundation as an independent thinktank is a brand of Oliver F. Lehmann. Protecting your personal data is a high priority for us. This policy explains what personal data we collect, why, on what legal basis, how long we keep it, and who we share it with, in line with the EU General Data Protection Regulation (GDPR).
This policy covers both of our web properties:
- our informational website at project-business.org; and
- our certification and community platform at cert.project-business.org, where exam candidates, community members, accredited exam providers (AEPs), corporate clients, and scholarship applicants register and manage their credentials.
1. Controller
The controller responsible for processing your personal data is:
Oliver F. Lehmann
Project Business Training
Trollblumenstr. 39g
80995 Munich, Germany
E-mail: oliver@oliverlehmann.com
Website: https://OliverLehmann.com
You can exercise any of the rights described in section 9 by contacting us at the address above.
2. Definitions
The pivacy declaration of the Project Business Foundation is based on the terms used by the European Data Protection Supervisor when adopting the General Data Protection Regulation (GDPR). Our data protection declaration should be easy to read and understand for the public as well as for our customers and business partners. To ensure this, we would like to explain in advance the terminology used.
We use the following terms, among others, in this privacy statement:
- Personal data
Personal data is any information relating to an identified or identifiable natural person (hereinafter “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. - Data subject
A data subject is any identified or identifiable natural person whose personal data are processed by the controller. - Processing
Processing is any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, filing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. - Restriction of processing
Restriction of processing is the marking of stored personal data with the aim of limiting their future processing. - Profiling
Profiling is any type of automated processing of personal data which consists of using such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects relating to that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or change of location. - Pseudonymization
Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separate and is subject to technical and organizational measures to ensure that the personal data relating to the data subject are not disclosed to any third party. - Controller or responsible person
Controller or responsible person is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for under Union or Member State law. - Processor
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. - Recipient
Recipient means a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether or not a third party. However, public authorities that may receive personal data in the context of a specific investigative task under Union or Member State law shall not be considered as recipients. - Third party
Third party means a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons who are authorized to process the personal data under the direct responsibility of the controller or the processor. - Consent
Consent is any indication of intention given voluntarily by the data subject for the specific case in an informed manner and unambiguously in the form of a statement or other unambiguous affirmative act by which the data subject indicates that he or she consents to the processing of personal data relating to him or her.
Where we refer to a legal basis (e.g. “Art. 6(1)(b)”), we mean the corresponding provision of the GDPR.
3. Access data and server logs
When you visit our websites, our hosting infrastructure automatically records technical data needed to deliver and secure the service: browser type/version, operating system, referring page, the pages you access, date and time, IP address, and your internet service provider. We use this data to serve content correctly, to maintain stability and security, and to investigate misuse or attacks. The legal basis is our legitimate interest in a secure, functioning website (Art. 6(1)(f)). Access logs are retained for a short period (see section 8) and are not used to identify you personally except where necessary to defend against an attack.
4. Cookies and consent
Our website uses cookies and similar technologies. Strictly necessary cookies are set to operate the site; all non-essential cookies and third-party scripts (including analytics — see section 5) are loaded only after you consent. We manage consent with the WPConsent cookie-consent tool, which lets you accept or reject cookie categories and change your choice at any time via the consent banner. You can also block or delete cookies in your browser settings; some site features may then not work fully.
For further details, please see our Cookie Note at https://project-business.org/about/cookie-policy/.
5. Website services and third-party plugins
WordPress
Our project-business.org website is built on WordPress and uses the components listed below.
The privacy policy of WordPress can be found at https://wordpress.org/about/privacy/
Plugins
Each is listed with its purpose and any data it processes or transfers to a third party.
| Service / plugin | Purpose | Personal data & recipient |
|---|---|---|
| Google Analytics (via MonsterInsights) | Website usage statistics — how visitors find and use the site. | Sets analytics cookies and transmits usage data (pages viewed, device/browser, truncated/anonymised IP to Google (Google Ireland Ltd; Google LLC, USA). Loaded only with your consent. Legal basis: consent (Art. 6(1)(a)). You can withdraw consent at any time via the cookie banner. |
| WPConsent | Cookie-consent banner and script blocking. | Stores your consent choices (locally / in a consent record). Legal basis: legal obligation and legitimate interest in demonstrating consent (Art. 6(1)(c)/(f)). |
| Everest Forms | Contact, registration and event forms. | Processes and stores the data you submit in a form (e.g. name, e-mail, message) to respond to your request. Legal basis: your request / (pre-)contract or consent (Art. 6(1)(b)/(a)). |
| Sucuri Security | Security auditing and malware scanning. | Activity logs may record IP addresses; remote scans transmit site data to Sucuri Inc. (USA). Legal basis: legitimate interest in security (Art. 6(1)(f)). |
| Redirection | Manages URL redirects and logs 404 (not-found) errors. | May log request URL, referrer and IP address to diagnose broken links. Processed locally; retained briefly. Legal basis: legitimate interest (Art. 6(1)(f)). |
| All in One SEO | Search-engine metadata and sitemaps. | Operates on page content/metadata; does not, by itself, transfer visitor personal data to third parties. |
| CoBlocks (by GoDaddy) | Page-building content blocks for the editor. | Renders page content; no visitor personal data transferred by the plugin. |
| WPCode | Inserts site-wide code snippets (e.g. the analytics tag). | A tool for administrators; any third-party script it loads is disclosed separately (e.g. Google Analytics, above) and gated by consent. |
| PBP Foundation Pages (Project Business Foundation) | Surfaces the certification portal’s scholarship application and Foundation workshops as in-theme pages. | These pages collect data on behalf of, and route it to, our certification platform (section 6). Processing there is described in that section. |
| WP File Manager | Administrative file management. | Used by administrators only; does not process visitor personal data. |
6. The certification platform (cert.project-business.org)
Our certification platform processes personal data to register exam candidates, deliver and grade the PBP exam, issue and verify certificates, and operate the related community, provider (AEP), corporate and scholarship services.
6.1 Data we process
- Exam candidates: name, the name to appear on the certificate, employer, e-mail, postal address, city, country, an optional LinkedIn URL, a password (stored only as a secure hash), exam sessions and answers, scores, pass/fail results and certificate identifiers.
- Public credential registry: for holders of a valid credential we publish, at cert.project-business.org/verify, the person’s name, city, country, credential(s) and award date, and — only where the holder has not opted out — their LinkedIn URL and a contact e-mail. You can opt out of the registry entirely, or of the LinkedIn/e-mail fields individually, at any time.
- Accredited Exam Providers (AEP): organisation and contact details, address, LinkedIn, DUNS/procurement identifiers, a password hash and an API key.
- Corporate clients: company and contact details and seat allocations.
- Scholarship applicants: name, e-mail, country, employment status, professional history, motivation, a description of financial hardship, and up to three uploaded supporting documents. This is sensitive information; it is stored in a private repository, access is limited to authorised reviewers under a confidentiality commitment, it is not sent to any AI system as a document, and it is erased on a short schedule (section 8).
- Community members: the posts, comments and attachments you create.
- Technical/security data: for security and abuse prevention we log IP address and browser/user-agent on administrative and authentication events.
6.2 Sub-processors of the certification platform
| Provider | Role | Location / transfer safeguard |
|---|---|---|
| Supabase | Database and file storage for all platform data. | Processing under a DPA, with EU Standard Contractual Clauses where data leaves the EU. |
| Resend | Delivery of transactional and information e-mails. | USA; DPA + Standard Contractual Clauses. |
| Vercel | Application hosting and server logs. | USA / global edge; DPA + Standard Contractual Clauses. |
| Anthropic (Claude) | AI-assisted assessment of scholarship applications; drafting of our own LinkedIn content (section 7). | USA; DPA + Standard Contractual Clauses. |
| Google (Drive) | Storage of media used in our LinkedIn content. | USA; DPA + Standard Contractual Clauses. |
| WooCommerce store (OliverLehmann.com) | Look-up of voucher purchasers (name, e-mail) to link purchases to accounts. | Operated by the controller. |
7. Automated processing in the scholarship programme
For applications to the PBP scholarship programme, we use an automated analysis to help assess applications. The information you enter in the application form is processed by our AI sub-processor (Anthropic) to produce a written assessment and a suitability indication. This is a decision-support tool only — every scholarship decision is made by a human reviewer, and the automated output does not by itself produce a legal or similarly significant effect within the meaning of Article 22 GDPR. Uploaded supporting documents are not sent to the AI. The legal basis is your explicit consent, given when you submit the application; you may withdraw it at any time, and you may request human review of, and contest, any assessment. Outside the scholarship programme we do not use automated decision-making that produces legal or similarly significant effects.
8. Retention periods
We keep personal data only as long as necessary for the purpose it was collected for, or as required by law. Our standard periods are:
| Category | Retention |
|---|---|
| Certification records (name, credential, award date, certificate ID, city/country) | For the life of the credential (the PBP certification is granted for life); retained indefinitely for verification, subject to registry opt-out. |
| Information/marketing contacts (subscribers) | Until you opt out. On opt-out we keep only a minimal suppression record so we do not contact you again. |
| Candidate postal address | Deleted approx. 12 months after the certificate is issued (no longer needed; the registry uses only city/country). |
| Exam operational detail (individual answers, failed-attempt sessions) | Approx. 24 months, then deleted; the passing result underlying a certificate is retained as part of the credential. |
| Non-certified / abandoned accounts | Deleted after approx. 24–36 months of inactivity where no credential was earned. |
| Scholarship application content and uploaded documents | Very short-lived: erased shortly after the decision and any appeal window; only the minimal outcome record is retained to administer the programme. |
| AEP and corporate accounts | Duration of the relationship plus 24 months after expiry/termination; API keys are revoked immediately on termination. |
| Community content (posts, comments, attachments) | Kept while the account is active; deleted or anonymised when the account is closed. |
| Security and audit logs (session IP/user-agent, login and admin logs) | Access/server logs approx. 30–90 days; security-audit records approx. 12 months. |
| Website analytics data (Google Analytics) | Per our configured Google Analytics retention setting. |
| Financial / billing records (voucher purchases, invoices) | Retained for the statutory period under German tax and commercial law (currently 8–10 years). |
When we delete data from our live systems, it is also removed from backups on the next backup-rotation cycle. Where we no longer need to identify you but still need the data for statistics (e.g. pass rates by country), we anonymise it rather than keep it in identifiable form.
9. Your rights
Under the GDPR you have the right to: confirmation and access to your data; a copy of it; rectification of inaccurate data; erasure (“right to be forgotten”); restriction of processing; data portability; and to object to processing based on legitimate interest or to direct marketing. Where processing is based on consent, you may withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at info@project-bussines.org. Certified members can additionally manage registry visibility and communication opt-outs from their account, and scholarship applicants can erase their application data from the application status page.
LinkedIn’s applicable privacy policy is available at https://www.linkedin.com/legal/privacy-policy.
LinkedIn’s cookie policy is available at https://www.linkedin.com/legal/cookie-policy.
10. International data transfers
Some of our processors are located in the United States or operate globally (see sections 5 and 6). Where personal data is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses and any applicable adequacy framework to safeguard your data.
11. Legal bases (summary)
Performance of a contract or pre-contractual steps — Art. 6(1)(b) (e.g. registering for and taking the exam, issuing certificates, AEP/corporate services).
Consent — Art. 6(1)(a) (e.g. non-essential cookies and analytics, marketing e-mails, registry publication of optional fields, the scholarship AI assessment).
Legal obligation — Art. 6(1)(c) (e.g. statutory retention of billing records).
Legitimate interests — Art. 6(1)(f) (e.g. security, fraud prevention, maintaining the integrity of the credential registry).
12. Legitimate interests in processing pursued by the controller or a third party
If the processing of personal data is based on Article 6 I lit. f DS-GVO, our legitimate interest is the performance of our business activities for the benefit of the well-being of all our employees and our shareholders.
13. Supervisory authority
Our competent supervisory authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Ansbach, Germany. You may also contact the authority in your country of residence.
Version of this privacy policy: 14 August 2025
