Privacy
Privacy policy
What we collect, why, which tools we use, and how you stay in control.
Version 1.2 · Last updated 29 September 2026
The short version. This site is run by Jonas Lang Image Expert (owner: Jonas Lang), Blütenstraße 4, 86438 Kissing, Germany (hello@frameeconomics.com). In the EU, the UK and Switzerland, nothing for ads or analytics runs until you say yes in the cookie banner. Everywhere else, including Australia, it runs unless you switch it off there. Either way you can change your choice at any time under “Cookie settings” at the bottom of every page. The tag container that holds those tools does load on every page, but it stores nothing on your device and collects nothing by itself (section 8.1). We use your details to answer you, to run what you sign up for, to send the emails you asked for, and to measure and improve our ads. Sometimes we write to a business first about our services, using contact details the business published itself (section 10.8). We never sell your personal information. Your rights are in section 11. People in Australia, see section 13. People in the USA, see section 14.
- Who is responsible
- What we collect, in brief
- Legal bases
- Recipients and transfers outside the EU
- How long we keep data
- Hosting, security and email
- Cookies and your consent choices
- Advertising and analytics
- Forms, applications, bookings and calls
- Emails and newsletter
- Your rights
- All tools at a glance
- People in Australia
- People in the USA
- Children
- Changes to this policy
1. Who is responsible
The controller responsible for data processing on this website under the EU General Data Protection Regulation (GDPR) is:
Jonas Lang Image Expert (sole trader)
Owner: Jonas Lang
Blütenstraße 4
86438 Kissing
Germany
Email: hello@frameeconomics.com
Contact form: frameeconomics.com/contact
The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (for example names or email addresses). More details are in our Impressum.
We have not appointed a data protection officer, because the law does not require one for a business of our size (§ 38 BDSG). You can reach us about anything in this policy at the address above.
2. What we collect, in brief
- When you visit: technical data such as your IP address, browser, operating system, the page you came from, the pages you open and the time. We need this to deliver the site and keep it secure.
- Only if you choose: data from cookies, pixels and tags for analytics, advertising and embedded videos. In the EU, the UK and Switzerland these run only after you accept them in the cookie banner. Everywhere else they run until you switch them off there.
- When you write to us or fill in a form: what you enter, for example your name, email address, YouTube channel link, your answers and your message.
- When you sign up for emails: your email address, name, the answers you gave and the record of your consent, plus whether you open our emails and click their links.
- When you book or buy: contract, booking, invoice and payment data.
- When you take part in the Free Channel Deep-Dive: your public channel, your application answers and, only with your consent, a recording of the deep-dive.
- When we write to you first: your name, your business email address or public profile, your YouTube channel and what you publish about your offer, taken from pages you made public yourself (section 10.8).
Some of this data is collected automatically by our IT systems when you visit. Everything else you give us yourself, or it reaches us from a platform you used to contact us, such as a Meta lead form or Skool. The one exception is business outreach, where we take business contact details from pages the business published itself (section 10.8).
3. Legal bases
We only process personal data where a legal basis applies:
- Consent (Art. 6(1)(a) GDPR). Where we store information on your device or read it from your device (cookies, pixels, local storage) and this is not strictly necessary, this is also based on your consent under § 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). You can withdraw consent at any time with effect for the future.
- Contract and pre-contract steps (Art. 6(1)(b) GDPR), for example when you apply, book, buy or ask us something before a contract.
- Legal obligations (Art. 6(1)(c) GDPR), for example tax and accounting retention duties.
- Legitimate interests (Art. 6(1)(f) GDPR), for example running a secure website, answering enquiries efficiently, measuring our emails and writing to businesses about our services. You can object to processing based on legitimate interests (see section 11).
- Strictly necessary device access (§ 25(2) no. 2 TDDDG), for example storing your cookie choice.
Each section below names the legal basis that applies.
4. Recipients and transfers outside the EU
We use service providers to run this business. Where they process data on our behalf, we use their data processing terms (Art. 28 GDPR) wherever the provider offers them, and they may only use the data on our instructions. Some providers act as independent controllers (for example payment providers, and Skool for its own platform), and for the Meta Pixel we and Meta are joint controllers (see section 8.4). We only pass data on where the law allows it: with your consent, to perform a contract, because we are legally required to, or where we have a legitimate interest.
Some providers are based in, or process data in, the USA or other countries outside the EU/EEA. For the USA, the European Commission has adopted an adequacy decision for companies certified under the EU–US Data Privacy Framework (DPF). Where a provider is certified, transfers are based on that decision (Art. 45 GDPR). Otherwise they are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) or, where no such clauses are in place, on Art. 49(1)(b) GDPR, because the transfer is necessary to deal with the request you send us or to perform our contract with you. Please note that in the USA and other third countries, public authorities may be able to access data and you may not have the same legal remedies as in the EU.
Every provider we use is listed with its country and transfer basis in section 12.
5. How long we keep data
Unless a more specific period is named in this policy, we keep personal data until the purpose it was collected for no longer applies. If you ask us to delete it, or you withdraw your consent, we delete it unless another legal reason lets us or requires us to keep it. Typical reasons are tax and commercial retention periods: invoices and booking records 8 years, business letters and emails about a contract 6 years, account books 10 years (§ 147 German Fiscal Code, § 257 German Commercial Code, § 14b German VAT Act). In that case we delete the data once the reason no longer applies.
6. Hosting, security and email
6.1 Cloudflare (hosting, content delivery, security)
This website is hosted and delivered by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (Cloudflare Workers and Cloudflare's content delivery network). Every request to this site passes through Cloudflare's servers. Cloudflare processes your IP address, the time, the requested URL, the referring page, your browser and operating system, and technical data needed to deliver the page and to block attacks and abuse. Cloudflare keeps this data only for short periods under its own retention rules. The legal basis is our legitimate interest in a fast, reliable and secure website (Art. 6(1)(f) GDPR). We have a data processing agreement with Cloudflare. Cloudflare is certified under the DPF; the Standard Contractual Clauses apply as a fallback. Details: cloudflare.com/privacypolicy.
6.2 Server log files
When you visit, the servers automatically collect and store information your browser sends: browser type and version, operating system, referrer URL, host name of the accessing computer, time of the request and IP address. This data is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR: we have a legitimate interest in a technically error-free and secure website, and log files are needed for that.
6.3 Encryption
This site uses TLS encryption (https) to protect what you send us, for example through a form. You can tell by the “https://” and the lock icon in your browser's address bar.
6.4 Emails you send us (Cloudflare Email Routing and Gmail)
Emails to addresses at frameeconomics.com and image-expert.com are received by Cloudflare Email Routing (Cloudflare, Inc., see 6.1) and forwarded to our mailbox at Gmail, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may process data in the USA (Google LLC is certified under the DPF). We store your email, your address and the details you give us to answer you. The legal basis is Art. 6(1)(b) GDPR where your email relates to a contract or pre-contract steps, and otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). We delete your email once your request is dealt with, unless retention periods apply (section 5).
7. Cookies and your consent choices
7.1 What cookies are
Cookies are small data files stored on your device. Similar technologies, such as pixels, tags and your browser's local storage, work in a comparable way. Session cookies are deleted when you close your browser; persistent cookies stay until they expire or you delete them. First-party cookies are set by this site; third-party cookies are set by other companies, for example Meta or Google.
7.2 Our consent banner
We ask for your consent with our own banner, built with the open-source tool CookieConsent and hosted on our own server, so no data goes to an outside consent provider. It stores your choice, a random consent ID, the date and the version of the banner in the cookie cc_cookie for 6 months, so we can respect your choice and prove your consent. The legal basis is Art. 6(1)(c) GDPR in connection with Art. 7(1) GDPR, and § 25(2) no. 2 TDDDG. You can change or withdraw your choice at any time under “Cookie settings” at the bottom of every page. When you withdraw a category, we delete its cookies and reload the page.
7.3 Strictly necessary storage
cc_cookie: your cookie choice (6 months).- Local storage on the application page: a draft of the answers you are typing, so you can come back to them. It stays on your device until you send the form or clear your browser data.
- Local storage on the masterclass page (
mc_signed): remembers that you signed up, so the video stays unlocked on your device.
These are necessary to provide what you asked for (§ 25(2) no. 2 TDDDG; Art. 6(1)(b) and (f) GDPR). They stay on your device and are not sent to anyone.
7.4 What you can switch on
- Analytics: Google Analytics (section 8.2).
- Marketing: Meta Pixel (including advanced matching), Meta Conversions API and Custom Audiences, Google Ads conversion tracking, remarketing and enhanced conversions (sections 8.3 and 8.4).
- External media: YouTube and Vimeo videos and YouTube thumbnails (section 8.7).
Consent is voluntary, and the site works without it. The legal basis for these tools is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
8. Advertising and analytics
We advertise on Meta (Facebook, Instagram) and Google (including YouTube). To see which ads work and to show our ads to the right people, we use the tools below, but only if you accept “Analytics” or “Marketing” in the cookie banner. Before that, none of them load. The one exception is the Google Tag Manager container in 8.1: it is the box the other tools sit in, it loads on every page, and it collects nothing by itself.
8.1 Google Tag Manager
Google Tag Manager, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, loads on every page. It is only a container: it sets no cookies of its own, reads no information from your device, creates no user profiles, and sends nothing to any analytics or advertising service by itself. Every analytics and advertising tag inside it stays blocked until you consent. Loading the file means Google Ireland Limited receives your IP address, browser type and the page you are on, and may transfer that to Google LLC in the USA. The legal basis is our legitimate interest in running a consent-aware tag layer (Art. 6(1)(f) GDPR). Because the container stores nothing on and reads nothing from your device, § 25(1) TDDDG does not apply to it. Google is certified under the DPF. You can object to this processing at any time under section 11.
8.2 Google Analytics 4
With your consent (“Analytics”), we use Google Analytics 4, a service of Google Ireland Limited, to understand how visitors use the site: pages viewed, time on page, the source of a visit (for example an ad or a search), device and browser, approximate location, and interactions such as form sends. Google Analytics uses cookies (_ga, _ga_*, up to 2 years) and does not log or store full IP addresses. Google may process the data in the USA. We keep Analytics data for up to 14 months and use Google's data processing terms for Analytics. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Google is certified under the DPF. More: policies.google.com/privacy.
8.3 Google Ads
With your consent (“Marketing”), we use Google Ads, a service of Google Ireland Limited, in these ways:
- Conversion tracking: if you reach our site through a Google or YouTube ad, Google sets a cookie (
_gcl_*, up to 90 days) and tells us, in aggregated form, whether the click led to a visit or a form. We do not see who you are. - Remarketing: Google can show our ads to people who visited this site, on Google, YouTube and partner sites, and can build audiences of people with similar characteristics. If you are signed in to Google, Google may link this across your devices.
- Enhanced conversions: when you send a form, your email address is hashed (turned into an unreadable code) in your browser and sent to Google so the send can be matched to an ad click.
- Customer Match: we only upload the email addresses of people who separately agreed to this. They are hashed before upload, and Google deletes addresses it cannot match.
- YouTube audiences: Google may show our ads to people who watched our YouTube channel. This happens inside Google's systems under YouTube's own terms; no data from this website is involved.
We use Google Consent Mode in its basic setting: the advertising and analytics tags themselves do not load or run at all without the matching consent, and your choice is passed to Google. In the EU, the UK and Switzerland that means they stay off until you accept them. Everywhere else they start on and stop as soon as you switch them off. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Google may transfer data to Google LLC in the USA, which is certified under the DPF. More: policies.google.com/technologies/ads and your ad settings at adssettings.google.com.
8.4 Meta Pixel, Conversions API and Custom Audiences
With your consent (“Marketing”), we use the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”). The pixel tells us whether people who saw or clicked our ads on Facebook or Instagram came to this site and sent a form. It lets us show our ads again to people who visited this site (Custom Audiences from website visitors) and to people with similar characteristics (lookalike audiences). The pixel sets cookies (_fbp, _fbc, up to 90 days) and sends Meta your IP address, browser data, the pages you visit and the actions you take. If you are logged in to Facebook or Instagram, Meta can link this to your account.
Advanced matching. With the same consent, the pixel also reads contact details you enter in a form — for example your name, your email address and any other contact details the form asks for — turns each value into an irreversible code (a hash) inside your browser, and sends that code to Meta so Meta can tell whether you are one of its users and match your visit to an ad. Only the code is sent, and we do not see these values ourselves through this feature. Meta's software decides which fields it recognises, so we cannot list every case in advance. Nothing is read or sent unless you accepted “Marketing”, and you can switch it off again at any time under “Cookie settings”.
Conversions API. Events the pixel sends from your browser are also copied to Meta through its Conversions API, which Meta runs on its own servers. Separately, when you send a form after accepting “Marketing”, we (through our automation tool Zapier) may send Meta the event (for example “Lead”), a random event ID, the Meta click and browser IDs, and your email address in hashed form. Both routes let Meta match the event to an ad and avoid counting it twice. Neither runs without your consent: if you have not accepted “Marketing” the pixel never loads, so there is nothing to copy, and we send nothing ourselves.
Joint controllership. For collecting your data through the pixel and transmitting it to Meta, we and Meta are joint controllers (Art. 26 GDPR). Our agreement is Meta's Controller Addendum (facebook.com/legal/controller_addendum). We are responsible for your consent and for informing you. Meta is responsible for the security of its tools and for its further processing, and you can exercise your rights directly with Meta. For matching and measurement, Meta acts as our processor under its Data Processing Terms.
We do not upload our email or customer lists to Meta. The legal basis for the pixel and the Conversions API is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Meta may transfer data to Meta Platforms, Inc. in the USA, which is certified under the DPF. More: facebook.com/privacy/policy. You can manage the ads Meta shows you in your Facebook and Instagram ad settings.
8.5 Meta lead ads (Instant Forms)
Some of our ads on Facebook and Instagram contain a form (a Meta Instant Form). If you fill it in, Meta collects the details you enter on its platform (your name, email address, YouTube channel link, your answer to our question and the consent box you ticked), together with the form version, the time and Meta's lead ID, and makes them available to us. We are the controller for these lead details. Meta processes your use of its platform under its own terms and privacy policy. Meta keeps the leads available to us for 90 days, and we copy them automatically, through Zapier, into our email tool Brevo (section 10). The legal basis is your consent to our emails (Art. 6(1)(a) GDPR) and, for the application, Art. 6(1)(b) GDPR.
8.6 Our social media profiles
We have profiles on YouTube, Facebook and Instagram. When you visit them, the platform processes your data under its own privacy policy: Google Ireland Limited for YouTube, Meta Platforms Ireland Limited for Facebook and Instagram. For the page statistics Meta provides to us (Page Insights), we and Meta are joint controllers (Art. 26 GDPR) under Meta's Page Insights Controller Addendum; Meta handles the main obligations and you can exercise your rights with Meta. Our legal basis is our legitimate interest in being present where our audience is (Art. 6(1)(f) GDPR).
8.7 Embedded videos: YouTube and Vimeo
Our pages can show videos from YouTube (Google Ireland Limited) and Vimeo (Vimeo.com, Inc., 330 West 34th Street, 10th Floor, New York, NY 10001, USA), including the masterclass video, our portfolio and the page with the recorded Free Channel Deep-Dives. We use YouTube's privacy-enhanced mode (youtube-nocookie.com) and Vimeo's Do-Not-Track setting. Videos and YouTube thumbnails load once “External media” is on, or as soon as you press play. In the EU, the UK and Switzerland you have to switch it on first; everywhere else it starts on and you can switch it off. At that point the provider receives your IP address and the page you are on and may set cookies or similar identifiers, and if you are logged in, link the view to your account. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Google and Vimeo are certified under the DPF.
8.8 Fonts
The fonts on this site are hosted on our own server. No connection to Google or another font provider is made when you load a page.
8.9 Our community on Skool
Our paid community is hosted on Skool, a platform of Skool.com, Inc., 111 Main St., El Segundo, CA 90245, USA. When you visit or join it, you use Skool under Skool's own terms and privacy policy, and Skool handles sign-up, login and membership payments as the seller of record. We see what Skool shows group owners: your name, profile, email address, your answers to our membership questions, your activity and posts in the community, and whether your membership is active. We do not see your full card details. We use this to run the community, to answer you and to suggest next steps, including our paid programmes. The legal basis is Art. 6(1)(b) GDPR (your membership) and our legitimate interest in running and growing the community (Art. 6(1)(f) GDPR).
We have connected our Meta Pixel and the Meta Conversions API to our Skool community through Skool's own integration. Skool can then tell Meta when someone views our community page, starts a trial or pays, so we can measure and improve our ads. Skool does not show a separate cookie banner for this. The pixel's advanced matching (section 8.4) applies on Skool as well: contact details you enter when you sign up for or manage your membership there are turned into an irreversible code in your browser and sent to Meta for the same matching purpose. Only the code is sent, and we do not see these values ourselves through this feature. The legal basis we rely on is our legitimate interest in measuring which ads lead to members (Art. 6(1)(f) GDPR). You can object at any time by emailing us, block the pixel with your browser's privacy settings, and manage ads in your Meta ad settings. Skool is not certified under the DPF; your data reaches Skool in the USA because you sign up with Skool yourself (Art. 49(1)(b) GDPR).
9. Forms, applications, bookings and calls
9.1 Contact form (Formspree)
If you send us a message through the contact form, we receive what you enter (name, email address, your YouTube channel link and your message) and technical data about the send (time, page, and whether you allowed marketing cookies). Our forms are processed by Formspree, Inc., San Antonio, Texas, USA, which forwards the message to us and stores it in its system. We use your details to answer you and to handle follow-up questions. The legal basis is Art. 6(1)(b) GDPR where your message relates to a contract or pre-contract steps, and otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR) or your consent, if you gave it. Formspree processes the data in the USA and is not certified under the DPF; the transfer is based on Art. 49(1)(b) GDPR (see section 4). We keep your message until your request is dealt with, you ask us to delete it, or you withdraw consent, and then delete it unless retention periods apply.
9.2 Applications, reservations and sign-ups on this site
Our application page (for the Accelerator and founding spots), the Channel Deep-Dive reservation form and the masterclass sign-up are also processed by Formspree (see 9.1). We receive what you enter, for example your name, email, YouTube channel, topic, audience, the channels you admire, how you make money, your goals and your notes. We use this to assess your application or reservation, to contact you about it, to deliver the masterclass and, where you ticked the box, to send you our emails (section 10). The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(a) GDPR for the emails. If no contract follows, we delete applications and reservations 12 months after our last contact with you.
9.3 The Free Channel Deep-Dive
Applying. If you apply, we receive your answers (your channel, topic, audience, the channels you admire, your offer and its price, how many calls you booked last month) and your tick boxes. They are stored as fields on your contact record in Brevo (section 10) and in our pick sheet in Google Sheets (section 9.8). We use them to pick the three channels, to prepare the deep-dives and to make the emails you signed up for more relevant. The legal basis is Art. 6(1)(b) GDPR for taking part and Art. 6(1)(a) GDPR for the emails. The rules are in the application terms.
If you are picked. We record a walkthrough of your public channel (a screen recording with our commentary), write an action plan and hold a 45-minute call with you. The recording goes to everyone on our newsletter and onto an unlisted page of this website (embedded through YouTube), and parts of it may be used in our marketing. This only happens with your consent, given step by step: the tick box on the application, your reply when you are picked, and a second yes on the finished recording before it goes out. A paid ad using it needs a separate written yes. We keep your name or channel off screen if you ask. You can withdraw your consent at any time: we then take the page and the video down within 7 days. Emails already sent cannot be recalled. The legal basis is your consent (Art. 6(1)(a) GDPR; for images of you also § 22 of the German Art Copyright Act, KUG).
Testimonials. If you give us a testimonial, we only publish it with your consent, and wherever we show it we say that you received the deep-dive for free.
How long. We delete the pick sheet entries of applicants who were not picked 12 months after applications close. The answers on your Brevo record stay while you are subscribed and are deleted when you unsubscribe (section 10.5). Recordings stay published until you withdraw your consent or we take them down.
9.4 Booking calls: Calendly and Google Calendar
You can book calls with us through Calendly, a service of Calendly LLC, 115 E Main St, Ste A1B, Buford, GA 30518, USA. Calendly processes your name, email address, the time you choose, your answers to the booking questions and technical data, and syncs the appointment with our Google Calendar (Google Ireland Limited). The legal basis is Art. 6(1)(b) GDPR and our legitimate interest in easy scheduling (Art. 6(1)(f) GDPR). Calendly processes the data under its data processing agreement. Calendly and Google are certified under the DPF.
9.5 Video calls: Zoom and Google Meet
We hold calls on Zoom (Zoom Communications, Inc., 55 Almaden Blvd, Suite 600, San Jose, CA 95113, USA) or Google Meet (Google Ireland Limited). When you join, the provider processes your name, email address, meeting data (time, duration, IP address, device), and the audio, video, screen sharing and chat of the call. We do not record calls unless everyone on the call agrees beforehand. The legal basis is Art. 6(1)(b) GDPR, and otherwise our legitimate interest in effective communication (Art. 6(1)(f) GDPR). Zoom processes the data under its data processing terms. Zoom and Google are certified under the DPF.
9.6 AI tools: Claude and ChatGPT
We use the AI tools Claude (Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland) and ChatGPT (OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland) to analyse applications and public channel content, to prepare deep-dives and action plans, and to draft replies. Before we enter anything, we remove email addresses and other contact details. What goes in is your public channel content and your answers. We use the providers' settings that stop our inputs from being used to train their models. The providers may process data in the USA on the basis of the Standard Contractual Clauses. Every decision, including who is picked, is made by a person; we do not make decisions based solely on automated processing (Art. 22 GDPR). The legal basis is our legitimate interest in preparing our work efficiently (Art. 6(1)(f) GDPR) and, for services you booked, Art. 6(1)(b) GDPR.
9.7 Automation: Zapier
We use Zapier (Zapier, Inc., 548 Market St #62411, San Francisco, CA 94104, USA) to move data between our tools, for example lead form details from Meta into Brevo, form sends into Brevo and Google Sheets, and, only where you accepted “Marketing”, form events to Meta and Google (sections 8.3 and 8.4). Zapier only handles the data needed for each step. The legal basis is the one that applies to the underlying processing. Zapier processes the data under its data processing addendum and is certified under the DPF.
9.8 Notes, documents and files: Notion and Google Workspace tools
We keep notes, plans and work documents in Notion (Notion Labs, Inc., San Francisco, USA) and in Google Drive, Docs and Sheets (Google Ireland Limited). This can include notes on applications and client work, our pick sheet for the Free Channel Deep-Dive, and the documents we share with you, such as your action plan. The legal basis is Art. 6(1)(b) GDPR and our legitimate interest in organised work (Art. 6(1)(f) GDPR). Notion and Google are certified under the DPF.
9.9 Payments and invoices: PayPal, Stripe, bank transfer
If you buy a paid service outside Skool, for example the Channel Deep-Dive, we process your name, address, email, what you bought, the price and the payment status to invoice you and deliver the service (Art. 6(1)(b) GDPR) and to meet our tax and accounting duties (Art. 6(1)(c) GDPR). You can pay:
- By PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. PayPal processes your payment data under its own privacy policy and may check your identity and creditworthiness for some payment methods.
- By card or other methods through Stripe: Stripe Payments Europe, Ltd., Dublin, Ireland. Stripe processes your payment data and may transfer data to Stripe, LLC in the USA, which is certified under the DPF.
- By bank transfer: your bank and ours process the transfer details.
Payment providers act as independent controllers for the payment itself. We keep invoices and booking records for 8 years (section 5).
9.10 Spam protection: Google reCAPTCHA
Our forms are protected against spam and abuse by Google reCAPTCHA (version 3), a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA only loads once you start filling in one of our forms, not when you just visit a page. It then checks whether the form is being used by a person or by an automated program, using information such as your IP address, browser and device data, how long you spend on the page and your mouse and keyboard activity, and it may set cookies. Google may transfer this data to Google LLC in the USA, which is certified under the DPF. The legal basis is our legitimate interest in protecting our forms from spam and abuse (Art. 6(1)(f) GDPR); where reCAPTCHA stores or reads information on your device, this is necessary for the form you chose to use (§ 25(2) no. 2 TDDDG). If you prefer not to use it, email us instead at hello@frameeconomics.com. More: policies.google.com/privacy.
10. Emails and newsletter
10.1 What you sign up for
You can sign up for our emails through a Meta lead form, the application page, the masterclass sign-up and the tick boxes on our other forms. You then get the emails described where you signed up, for example the three recorded channel deep-dives and Jonas Lang's emails about YouTube for coaches, including news about our programmes and our community.
10.2 Your consent and our record of it
You sign up by ticking an unticked box. We keep a record of your consent: the time, the form and its version, the wording shown and the ticked box, taken from Meta's lead record or from our form. The legal basis for sending is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time.
10.3 Brevo
We send our emails with Brevo, a service of Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany, part of Sendinblue SAS, Paris, France. Brevo stores your email address, name, the fields we keep about you (for example your channel link, your answers and tags such as “applied”) and the send and delivery data of our emails. Brevo stores the data on servers in the EU. We have a data processing agreement with Brevo. More: brevo.com/legal/privacypolicy.
10.4 Measuring opens and clicks
Our emails contain a small invisible image, and their links pass through Brevo. This lets us see whether and when you opened an email and which links you clicked. We use this to tell engaged readers apart, to send the right follow-up (for example a reminder only to people who have not yet opened the application), and to improve our emails. The legal basis is our legitimate interest in measuring and targeting our emails (Art. 6(1)(f) GDPR). You can object at any time by unsubscribing, and you can block the invisible image by turning off automatic image loading in your email app.
10.5 Unsubscribing
Every email has a one-click unsubscribe link, and you can also just reply or write to us. We then stop all emails to you. We keep your email address on a blocklist so we do not email you again by mistake (Art. 6(1)(f) GDPR), and we keep the record of your consent for up to 3 years after you unsubscribe so we can prove it if needed (Art. 6(1)(c) and (f) GDPR). Your other data is deleted when you unsubscribe, unless retention periods apply.
10.6 Emails to customers
If you bought a service from us and gave us your email address for it, we may send you emails about our own similar services without asking again (§ 7(3) of the German Act against Unfair Competition). You can object at any time, at no cost other than your usual transmission costs, through the link in every email or by writing to us. The legal basis is our legitimate interest in direct marketing (Art. 6(1)(f) GDPR).
10.7 Australian and US recipients
Our newsletter and our other marketing emails go only to people in Australia who have consented. Every email identifies us and contains a working unsubscribe link, and we act on unsubscribe requests within 5 business days (Spam Act 2003). For people in the USA, our emails follow the CAN-SPAM Act. A first personal message to a business is covered in section 10.8.
10.8 When we write to you first (business outreach)
Sometimes we write a personal first message to a coach, a consultant or another expert whose YouTube channel we think we can help. We do this by email or by a direct message on a social network, one person at a time and never in bulk.
Where your details come from. We take your name, your business email address or profile, your YouTube channel and what you publish about your offer from pages you made public yourself: your YouTube channel page, your own website or your own video descriptions. We do not buy contact lists and we do not take addresses from directories or databases. We note the page where we found your details and the date.
Who we do not write to. We do not write first to people in the European Union, the United Kingdom or Switzerland, and we do not write to anyone whose pages say they do not want unsolicited offers.
What we use it for, and the legal basis. We use these details only to offer you our services and to keep a record of where we found them. The legal basis is our legitimate interest in winning new business clients (Art. 6(1)(f) GDPR). In Australia, New Zealand and Canada we rely on the consent the law infers from a business address that was published without a no-contact notice, and our message is about the work you do in that business (Spam Act 2003, Schedule 2; Unsolicited Electronic Messages Act 2007; Canada's anti-spam legislation, section 10(9)). In the USA these messages follow the CAN-SPAM Act. They contain no tracking: we do not measure whether you open them.
Who receives it. We send and receive these messages through our own mailbox (section 6.4) and keep our notes in the planning tools listed in section 12. Nobody else receives your details.
How to stop it. Every message says who we are and how to stop. Reply “no” and we will not contact you again, on any channel. We act on it the same day. We then keep only your email address or profile name on a do-not-contact list, so we do not write to you again by mistake (Art. 6(1)(f) GDPR).
How long we keep it. If we do not end up working together, we delete your details 6 months after our last message. Two things stay: your entry on the do-not-contact list, and, for up to 3 years, the note of where and when we found your published address, so we can show that we were allowed to write to you (Art. 6(1)(f) and Art. 17(3)(e) GDPR).
Your rights. You can object at any time (section 11), and you can ask us what we hold about you and where we got it.
11. Your rights
Under the GDPR you have the right, free of charge, to:
- get information about the data we hold about you, where it came from, who received it and why we process it (Art. 15);
- have incorrect data corrected (Art. 16) and have data deleted (Art. 17);
- have processing restricted (Art. 18), for example while we check a dispute about accuracy;
- receive the data you gave us in a common machine-readable format, or have it sent to someone else (Art. 20);
- withdraw a consent you gave, with effect for the future (Art. 7(3));
- complain to a data protection supervisory authority (Art. 77).
Right to object (Art. 21 GDPR): where we process your data based on Art. 6(1)(e) or (f) GDPR, you have the right to object at any time on grounds relating to your particular situation, including to profiling based on those provisions. We will then stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. Where we process your data for direct marketing, you may object at any time to processing for that purpose, including profiling related to it. Your data will then no longer be used for direct marketing.
Supervisory authority. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, poststelle@lda.bayern.de, www.lda.bayern.de. You can also complain to the authority where you live or work.
Objection to advertising emails. We object to the use of the contact details published in our Impressum for sending advertising and information material we did not ask for. We reserve the right to take legal action if unsolicited advertising is sent, for example spam emails.
To use any of your rights, write to hello@frameeconomics.com. We may ask you to confirm your identity.
12. All tools at a glance
| Tool | Provider | What we use it for | Where, transfer basis | When it runs |
|---|---|---|---|---|
| Cloudflare | Cloudflare, Inc., USA | Hosting, content delivery, security, email forwarding | Worldwide network, USA: DPF, SCCs as fallback | Always |
| Google reCAPTCHA | Google Ireland Ltd, Ireland | Spam protection on our forms | Ireland, USA: DPF | Once you start filling in a form |
| Formspree | Formspree, Inc., USA | Website forms | USA: Art. 49(1)(b) GDPR | When you send a form |
| Brevo | Brevo GmbH, Germany (Sendinblue SAS, France) | Emails, contact records, open and click statistics | EU | When you sign up |
| Meta Instant Forms | Meta Platforms Ireland Ltd, Ireland | Lead forms in our ads | Ireland, USA: DPF | When you use one of our ad forms |
| Meta Pixel (incl. advanced matching), Conversions API, Custom Audiences | Meta Platforms Ireland Ltd, Ireland | Ad measurement, remarketing, lookalike audiences | Ireland, USA: DPF | Only with “Marketing” consent (on Skool: section 8.9) |
| Google Ads (conversion tracking, remarketing, enhanced conversions, Customer Match, YouTube audiences) | Google Ireland Ltd, Ireland | Ad measurement, remarketing | Ireland, USA: DPF | Only with “Marketing” consent; Customer Match only with separate consent |
| Google Analytics 4 | Google Ireland Ltd, Ireland | Site statistics | Ireland, USA: DPF | Only with “Analytics” consent |
| Google Tag Manager | Google Ireland Ltd, Ireland | Loading the analytics and advertising tags | Ireland, USA: DPF | On every page (container only; every tag inside needs consent) |
| YouTube (privacy-enhanced mode) | Google Ireland Ltd, Ireland | Videos, thumbnails, the deep-dive recordings | Ireland, USA: DPF | Only with “External media” consent or when you press play |
| Vimeo (Do Not Track) | Vimeo.com, Inc., USA | Videos | USA: DPF | Only with “External media” consent |
| Skool | Skool.com, Inc., USA | Our community, membership payments, Meta Pixel integration | USA: Art. 49(1)(b) GDPR | When you visit or join our community |
| Calendly | Calendly LLC, USA | Booking calls | USA: DPF | When you book |
| Google Calendar | Google Ireland Ltd, Ireland | Appointments | Ireland, USA: DPF | When you book |
| Zoom | Zoom Communications, Inc., USA | Video calls | USA: DPF | During calls |
| Google Meet | Google Ireland Ltd, Ireland | Video calls | Ireland, USA: DPF | During calls |
| Gmail | Google Ireland Ltd, Ireland | Our mailbox | Ireland, USA: DPF | When you email us |
| Google Drive, Docs, Sheets | Google Ireland Ltd, Ireland | Documents, the deep-dive pick sheet | Ireland, USA: DPF | Applications, client work |
| Notion | Notion Labs, Inc., USA | Notes and planning | USA: DPF | Internal work |
| Zapier | Zapier, Inc., USA | Moving data between our tools | USA: DPF | When data moves between tools |
| Claude | Anthropic Ireland, Limited, Ireland | Analysing applications, drafting | Ireland, USA: SCCs | Preparation work |
| ChatGPT | OpenAI Ireland Ltd, Ireland | Analysing applications, drafting | Ireland, USA: SCCs | Preparation work |
| PayPal | PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg | Payments | EU | If you pay with PayPal |
| Stripe | Stripe Payments Europe, Ltd., Ireland | Card payments, invoices | Ireland, USA: DPF | If you pay through Stripe |
| Bank transfer | Your bank and ours | Payments | Depends on the banks | If you pay by transfer |
| CookieConsent | Open source, hosted by us | Your cookie choice | Our server (Cloudflare) | Always |
13. Information for people in Australia
We handle personal information of people in Australia in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). This section summarises how. The rest of this policy gives the details.
13.1 What we collect and hold
Identity and contact details (name, email address), your YouTube channel and business details (your offer, price, calls booked), what you tell us in forms, emails and calls, your email engagement (opens and clicks), technical and usage data about your visit (IP address, device, pages), ad interaction data, contact details you enter in a form passed to Meta in coded (hashed) form so it can match you to an ad (sections 8.4 and 8.9), booking and transaction details (not your full card number, which our payment providers handle), and recordings of a Free Channel Deep-Dive where you agreed to it. We do not ask for sensitive information (such as health information), and please don't send it to us.
13.2 How we collect and hold it
Mostly directly from you: through our website forms, Meta lead forms, emails, calls, Calendly and Skool. When we write to a business first, we take its business contact details from pages the business published itself (section 10.8). Some is collected automatically. On this website, the cookie banner in Australia is an opt-out one: cookies, pixels and the analytics and advertising tags run from the moment you arrive and keep running until you switch them off in the banner or under “Cookie settings”. (In the EU, the UK and Switzerland they run only after you accept them.) Our tag container itself loads on every page and stores nothing on your device (section 8.1). In our Skool community, which shows no banner of its own, the Meta Pixel runs as described in section 8.9. Some comes from Meta and Google as ad reports and lead details. We hold it in the cloud services listed in section 12, protected by access controls and encrypted connections.
13.3 Why we collect, hold, use and disclose it
To answer you, to run our services and the Free Channel Deep-Dive, to send the emails you asked for, for direct marketing about our own services, to measure and improve our ads, and to meet our legal, tax and accounting obligations (sections 6 to 10).
13.4 Direct marketing
You can opt out of our marketing at any time with the unsubscribe link in our emails, by replying “no” to a personal message from us, or by writing to us. We act on your request within 5 business days and free of charge. You can also opt out of ad tracking on this site at any time under “Cookie settings”. In our Skool community there is no banner, so email us to object and we will switch the pixel off for you (section 8.9). If you ask, we will tell you where we got your details.
13.5 Disclosure overseas
We are based in Germany, so your information is held and used there. It is also disclosed to our service providers, located in Germany, France, Ireland, Luxembourg and other EU countries, and in the USA (section 12), and it may be processed in other countries where these providers operate.
13.6 Anonymity
You can browse this site without telling us who you are, and ask a general question without giving your full name. To apply, book or buy, we need your details.
13.7 Accessing and correcting your information
Email hello@frameeconomics.com to ask for a copy of the information we hold about you or to correct it. We respond within 30 days, free of charge, and may ask you to confirm your identity. If we can't give you access or make a correction, we will tell you why in writing and how you can complain.
13.8 Complaints
If you think we have mishandled your personal information, contact us first at hello@frameeconomics.com. We will reply within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC): online at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5288, Sydney NSW 2001.
13.9 Automated decisions
We do not use computer programs to make decisions that could significantly affect your rights or interests. AI tools help us prepare our work (section 9.6), but a person makes every decision, including who is picked for the Free Channel Deep-Dive.
13.10 Security
We take reasonable steps to protect your information from misuse, loss and unauthorised access, and to delete or de-identify it when we no longer need it.
14. Information for people in the USA
We collect the categories of personal information described in sections 2 and 13.1: identifiers (such as name and email), commercial information (what you booked or bought), internet activity on this site (only with your consent for analytics and ads), and information you give us about your business. We use it for the purposes in sections 6 to 10 and share it with the service providers in section 12.
We do not sell your personal information for money. With your consent, advertising platforms (Meta, Google) receive information about your visit to show you ads (“targeted advertising”); you can refuse or withdraw this at any time under “Cookie settings”. When you accept Analytics or Marketing, these third parties may collect information about your online activities over time and across different websites.
Do Not Track. We do not respond to browser Do Not Track signals, because there is no common standard for them. Our cookie banner lets you refuse tracking instead.
You can ask us what personal information we hold about you, and ask us to correct or delete it, by writing to hello@frameeconomics.com. We will tell you about changes to this policy by updating this page and its date.
15. Children
Our services are for adults running a business. They are not directed at anyone under 18, and we do not knowingly collect personal information from children.
16. Changes to this policy
We update this policy when our services, our tools or the law change. The version and date at the top show the current version. If a change affects something you consented to, we will ask again.