Language

We are delighted that you are visiting our website www.gymaesthetics.com and are interested in our company. We attach a great deal of importance to protecting your personal data. Personal data is information about an identified or identifiable natural person’s personal or factual circumstances. This includes details such as the person’s real name, address, phone number and date of birth, as well as all other data which may refer to an identifiable person.
Because personal data is afforded special legal protection, we only collect it insofar as doing so is necessary to making our website available and providing our service. Below, we have provided an outline of what personal information we collect about you during your visit to our website and how we use it.
Our data protection practices comply with legal regulations, particularly those set down in the German Federal Data Protection Act (BDSG), the German Telemedia Act (TMG) and the EU’s General Data Protection Regulation (GDPR). We will only collect, process and store your personal data insofar as doing so is necessary to making this website and our contents and services functionally available, as well as for the purpose of processing enquiries and, if necessary, handling orders / contracts, but only if there is a legitimate interest for doing so under the terms of Art. 6, Para. 1, Clause 1, lit. f of the GDPR or other statutory permission. Your data will also be used for further purposes precisely defined in your consent, e.g. to send advertising information by newsletter, only if you have separately given your consent beforehand.

 

1. Controller under the terms of Art. 4, Para. 7 of the GDPR

The controller under the terms of the GDPR, other national data protection legislation of the member states and other provisions under data protection legislation is:

Gym Aesthetics GmbH
Königstraße 56
70173 Stuttgart

Email: service@gymaesthetics.com
Tel.: +49 (0)711 25517317

 

2. Providing the website and creating log files

Each time our website is accessed, our system automatically records data and information from the accessing computer’s computer system. The following data is collected in this regard:

Extent of data processing

(1) Information about the browser type and the version used
(2) The accessing device’s operating system
(3) The accessing device’s IP address
(4) Date and time of access
(5) Websites and resources (images, files, other page contents) which were accessed on our website
(6) Websites from which the user’s system accessed our website (referrer tracking)

This data is stored in our system’s log files. This data is not stored together with personal data belonging to a specific user, so individual site visitors are not identified.

Legal basis for personal data processing

Art. 6, Para. 1, lit. f of the GDPR (legitimate interest). Our legitimate interest is to guarantee achievement of the purpose outlined below.

Purpose of data processing

Logging is carried out to maintain our website’s compatibility for all visitors where possible and to combat misuse and eliminate faults. To this end, it is necessary to log the accessing computer’s technical data, so that we can respond to display errors, attacks on our IT systems and/or functionality errors on our website as early as possible. Additionally, we also use the data to optimise the website and to ensure the general security of our IT systems.

Duration of storage

The above technical data is deleted as soon as it is no longer needed to guarantee the website’s compatibility for all visitors, but at the latest within three months of our website being accessed.

Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

3. Special features of the website

Our site offers you a variety of features which, when used by us, serve to collect, process and store personal data. We have provided an explanation of what happens to this data below:

Form for subscribing to the newsletter:

    • Extent of personal data processing

The data you entered when subscribing to the newsletter.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (implicit consent)

    • Purpose of data processing

Data captured on our newsletter’s sign-up screen is used by us for the sole purpose of sending our newsletter, in which we provide information about all our services and our news. Once you have signed up, we will send you a confirmation email containing a link you have to click on to complete the process of signing up to our newsletter (double opt-in).

    • Duration of storage

You can unsubscribe from our newsletter at any time by clicking on the Unsubscribe link, which is also included in every newsletter. We will delete your data immediately after you cancel your subscription. We will also delete your data immediately if you do not complete the sign-up process. We reserve the right to delete the same without any need to provide justification or to provide any prior or subsequent information.

    • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

Contact form(s):

    • Extent of personal data processing

The data you entered in our contact forms.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (implicit consent)

    • Purpose of data processing

We will use the data captured by means of our contact form(s) only to process the specific contact request received through the contact form(s).

    • Duration of storage

The data captured is deleted immediately after your request has been processed, provided that there are no statutory retention periods.

    • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

Login area:

    • Extent of personal data processing

The registration and login data you entered on our site.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (implicit consent)

    • Purpose of data processing

You can use a separate login area on our website. If you have forgotten your password or username for this area, you can request to have this data sent to you again after firstly entering your contact details (email address). Any usage data incoming within the context of using the login area is collected, saved and processed by us for the sole purpose of tackling misuse, troubleshooting and maintaining functionality. This data is not used for any other purposes or transferred to third parties.

    • Duration of storage

Data collected within the context of the ‘Forgotten your username or password?’ function is only used to re-send forgotten login data.

    • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

4. Automatic credit check / scoring

If we deliver any goods or services prior to receiving payment, we reserve the right to obtain an automatic credit report based on mathematical / statistical methods from the following company (companies) so as to protect our legitimate interests. We receive information from the following service provider regarding the statistical probability of default. The credit report may include probability values (score values), which are calculated based on scientifically recognised mathematical / statistical methods. Conclusions are thereby drawn as to the customer’s future risk of payment default using a wide range of features, such as income, address data, occupation, marital status and previous payment history. The result is expressed in the form of a payment value (“score”). The information obtained in this way forms the basis of our decision on whether to establish, execute or terminate a contractual relationship. However, selection of one of the payment methods offered does not depend on such information. The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy. Specific details:

 

  • Automatic identity and credit check when the “PayPal” payment method is selected:
    • Extent of personal data processing

If you have selected “PayPal” as your chosen payment method, we will forward your personal customer data collected within the context of the order process to PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as “PayPal”) within the context of payment handling. If you give your consent, the following data is affected by the data transfer: First name and surname, street, house number, postcode, town / city, date of birth, phone number and the data provided in connection with your order.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. b of the GDPR (implementation of pre-contractual measures)

    • Purpose of data processing

PayPal performs a credit check when you select “PayPal” as the payment method. During this process, mathematical and statistical procedures are used to calculate a rating with respect to the probability of default (calculate a so-called scoring value). PayPal uses the calculated scoring value as the basis for its decision on whether or not to provide the respective payment methods. A scoring value is calculated according to recognised scientific procedures. Reference is also made to the PayPal privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

    • Duration of storage

We will store the relevant data for processing the payment as long as doing so is necessary for the execution of the transaction. If the data is subject to the legal retention requirements, deletion shall take place once the retention requirement has expired. The duration of PayPal’s data storage is determined by PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

    • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

5. Statistical evaluation of visits to this website – web trackers

When this website or individual files on the website is / are accessed, we collect, process and store the following data: IP address, web page from which the file was retrieved, name of the file, the retrieval date and time, the data volume transmitted and the retrieval success notification (so-called web log). We only use this access data in a non-personalised form with a view to continuously improving our website and for statistical purposes.
We also use the following web trackers to evaluate visits to our website:

 

  • Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing

We use a web tracking service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing”) on our website. In the context of web tracking, Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing privacy policy: https://www.google.de/intl/de/policies/privacy/. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

 

  • Google AdSense

We use a web tracking service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google AdSense”) on our website. In the context of web tracking, Google AdSense uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Google AdSense tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Google AdSense servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Google AdSense has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Google AdSense privacy policy: https://www.google.de/intl/de/policies/privacy/. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

 

  • Google Analytics
    • Extent of personal data processing

We use the web tracking service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google Analytics”) on our site. In the context of web tracking, Google Analytics uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Google Analytics tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Google LLC servers and is processed and stored outside of the European Union, e.g. in the US.
The European Commission has noted that an appropriate data protection level can exist in the US if the data processing company is subject to the EU/US Privacy Shield Agreement and if the data export to the US was designed to be permissible in this way. Google will anonymise your IP address before transmission if you activate IP anonymisation within this website’s Google Analytics tracking code. This website uses a Google Analytics tracking code expanded to include the gat._anonymizeIp(); operator so as to enable only anonymised collection of IP addresses (so-called IP masking).

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (consent), either in the context of registration with Google (opening a Google account and accepting the privacy notice implemented there) or, if you have not registered with Google, through explicit consent when you call up our site.

    • Purpose of data processing

On our behalf, Google will use this information for the purpose of evaluating your visit to this website, compiling reports on website activities and providing us with other services relating to website and Internet use. The IP address transmitted by your browser in the context of Google Analytics is not associated with the other data held by Google LLC.

    • Duration of storage

Personalized data will be deleted or anonymized after a period of 14months.

    • Opportunity to object and remove

You can prevent personal data (particularly your IP address) from being collected and disclosed to Google and Google’s processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find atwww.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting. Furthermore, you can prevent Google’s collection and processing of the data generated by the Google cookie and related to your use of the website (including your IP address) by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de). You can find Google Analytics’ security and privacy policy at http://www.google.com/intl/de/analytics/learn/privacy.html

Click here to opt-out of the Google Analytics tracking.

 

  • Facebook Connect / Login

We use a web tracking service provided by Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94024, USA (hereinafter referred to as “Facebook Connect / Login”) on our website. In the context of web tracking, Facebook Connect / Login uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Facebook Connect / Login tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Facebook Connect / Login servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Facebook Connect / Login has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Facebook Connect / Login privacy policy: https://www.facebook.com/privacy/explanation. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

 

  • Facebook Custom Audience

We use a web tracking service provided by Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94024, USA (hereinafter referred to as “Facebook Custom Audience”) on our website. In the context of web tracking, Facebook Custom Audience uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Facebook Custom Audience tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Facebook Custom Audience servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Facebook Custom Audience has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Facebook Custom Audience privacy policy: https://www.facebook.com/privacy/explanation. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

 

  • Facebook Exchange (FBX)

We use a web tracking service provided by Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94024, USA (hereinafter referred to as “Facebook Exchange (FBX)” on our website. In the context of web tracking, Facebook Exchange (FBX) uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Facebook Exchange (FBX) tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Facebook Exchange (FBX) servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Facebook Exchange (FBX) has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Facebook Exchange (FBX) privacy policy: https://www.facebook.com/privacy/explanation. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

 

  • MailChimp

We use the MailChimp service from The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, 30308 Atlanta, United States of America, email: dpo@mailchimp.com, website: https: // mailchimp. com /. The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

We use the service to be able to show the newsletter used and a registration option on our site.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://mailchimp.com/legal/.

The provider also offers an opt-out option at https://mailchimp.com/legal/.

 

  • Hotjar

We use the Hotjar service from Hotjar Ltd., 20 Bisazza Street, 1640 Sliema, Malta on our site. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

Via Hotjar, we conduct a behavioral analysis of the use of our websites and evaluate feedback using tools such as heat maps, session recordings and surveys.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.hotjar.com/privacy.

 

  • Moat Analytics / Moat Ads

We use the Moat Analytics / Moat Ads service from Oracle America, Inc., 500 Oracle Parkway, CA 94065 Redwood Shores, United States of America, email: mail@legislator.de, website: https: // www.oracle.com/.The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

Through the MediaMath service, we can collect and evaluate data from you on the site in order to be able to show you individual advertising.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.oracle.com/legal/privacy/privacy-policy.html.

The provider also offers an opt-out option at https://www.oracle.com/legal/privacy/privacy-policy.html.

 

6. Integration of external web services and data processing outside the EU

We use active JavaScript contents from external providers (“web services”) on our website. When you access our website, these external providers may receive personal information about your visit to our website. Data may be processed outside the EU in this regard. You can prevent this from happening by installing a JavaScript blocker, such as the ‘NoScript’ browser plugin (www.noscript.net), or by disabling JavaScript in your browser. This can lead to functional restrictions on websites you visit.
We use the following external web services:

  • Google

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Google in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. Google has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in Google’s privacy policy: https://www.google.com/intl/de/policies/privacy/. You can prevent Google from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

 

  • Google Video

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google Video”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Google Video in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. Google Video has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Google Video privacy policy: https://www.google.com/intl/de/policies/privacy/. You can prevent Google Video from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

 

  • Google APIs

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google APIs”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Google APIs in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. Google APIs has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Google APIs privacy policy: https://www.google.com/intl/de/policies/privacy/. You can prevent Google APIs from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

 

  • Googletagmanager.com

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Googletagmanager.com”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Googletagmanager.com in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. Googletagmanager.com has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Googletagmanager.com privacy policy: https://www.google.com/intl/de/policies/privacy/. You can prevent Googletagmanager.com from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

 

  • Google Fonts

We use the Google Fonts service from Google LLC, 1600 Amphitheater Parkway, 94043 Mountain View, United States of America, email: support-de@google.com, website: http://www.google.com /. The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

Fonts are reloaded on our site via the Google Fonts service in order to be able to display the site in a visually better version.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://policies.google.com/privacy.

 

  • Google Maps
    • Which personal data are collected and to what extent are they processed?

On our site we use the map service of the company Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: Google Maps). Google Maps is integrated into the website via the Google API in order to visualize location information and display it in the form of a map. The processing of the IP address by Google Maps is technically necessary to display the map. With regard to the other web services integrated via Google APIs, the regulations in the respective section of this data protection declaration on Google APIs apply.

    • Legal basis for the processing of personal data

Art. 6 lit.f GDPR (legitimate interest). Our legitimate interest lies in being able to visualize the usual presentation of location information on the Internet.

    • Purpose of data processing

On our behalf, Google will use the information obtained from Google Maps to show you the map. You can find us faster and more precisely using Google Maps than with a simple, non-interactive route map.

    • Duration of storage

Google will save the data relevant for the function of Google Maps for as long as it is necessary to fulfill the booked web service. The data is collected and saved anonymously. If there is a personal reference, the data will be deleted immediately, provided that it is not subject to any statutory retention requirements. In any case, the deletion takes place after the retention period expires.

    • Opposition and cancellation option

You can prevent the collection and forwarding of personal data to Google (especially your IP address) and the processing of this data by Google by deactivating the execution of script code in your browser, installing a script blocker in your browser or Activate the "Do Not Track" setting in your browser. You can find Google's security and data protection principles at https://policies.google.com/privacy.

    • Joint processing

We have concluded a joint processing agreement with Google with regard to Google Maps. You can find the content at https://privacy.google.com/intl/de/businesses/mapscontrollerterms/.

 

  • Gstatic

We use the Gstatic service from Google LLC, 1600 Amphitheater Parkway, 94043 Mointain View, United States of America, email: support-de@google.com, website: http://www.google.com/. The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

Gstatic is a service used by Google to retrieve static content in order to reduce bandwidth usage and to preload required catalog files.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://policies.google.com/privacy.

 

  • Paypal

We use the PayPal service from PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is the contract that has already been concluded or is yet to be concluded between you and us in accordance with Art. 6 Paragraph 1 lit.

The service is integrated by us in order to be able to show you the PayPal button on every subpage in our online shop so that you know which payment method you can use to shop with us.

You can find out which rights you have with regard to processing at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE.

 

  • Paypal Objects

We use the PayPal service from PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is the contract that has already been concluded or is yet to be concluded between you and us in accordance with Art. 6 Paragraph 1 lit.

The service is integrated by us in order to be able to show you the PayPal button on every subpage in our online shop so that you know which payment method you can use to shop with us.

You can find out which rights you have with regard to processing at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE.

 

  • Trusted Shops

We use the Trusted Shops service from Trusted Shops GmbH, Subbelrather Straße 15c, 50823 Cologne, Germany on our website. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is our legitimate interest in processing in accordance with Article 6 (1) (f) GDPR.

Reviews from other buyers or the Trusted Shop seal are displayed on our website via Trusted Shops.

With regard to the processing, you have the right of objection listed in Art. 21. You can find more information at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.trustedshops.de/impressum/.

The provider also offers an opt-out option at https://www.trustedshops.de/impressum/.

 

  • Zdassets

We use the Zdassets service from Zendesk, Inc., 1019 Market Street, 94103 San Francisco, United States of America, email: jrobman@zendesk.com, website: https://www.zendesk.com/. The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

 

  • Zopim

We use the Zopim service from Zendesk, Inc., 1019 Market Street, 94103 San Francisco, United States of America, email: jrobman@zendesk.com, website: https://www.zendesk.com/.The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

The service is a plug-in that we need in order to be able to display all of the contents of our website to you. The plugin makes our website more attractive and easier to experience for our site visitors.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.zendesk.de/company/customers-partners/privacy-policy/.

 

  • veinteractive.com

We use the veinteractive.comservice provided by Ve Global UK Limited, White Collar Factory, Old Street Yard, EC1Y 8AF London, United Kingdom. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

The service is a plug-in that we need in order to be able to display all of the contents of our website to you. The plugin makes our website more attractive and easier to experience for our site visitors.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.ve.com/de/datenschutzerklaerung.

 

  • Google reCaptcha

We use the Google reCaptcha service from Google LLC, 1600 Amphitheater Parkway, 9403 Mountain View, United States of America, email: support-de@google.com, website: http://www.google.com on our website /. The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

We use the Google Re-Captcha service to protect our website and forms from automated attacks and spam.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://policies.google.com/privacy.

 

  • Veinteractive

We use the Veinteractive service of Ve Global UK Limited, 77 Leadenhall Street, EC3A 3DE London, United Kingdom, email: info@ve.com, website: https://www.ve.com/ on our site. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

The service is a plug-in that we need in order to be able to display all of the contents of our website to you. The plugin makes our website more attractive and easier to experience for our site visitors.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.ve.com/privacy-policy.

 

  • Gym Aesthetics

We use the GymAesthetics service from Gym Aesthetics GmbH, Königstraße 56, 70173 Stuttgart, Germany, email: business@gymaesthetics.com, website: https://www.gymaesthetics.com/de/de/. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

The service is a plug-in that we need in order to be able to display all of the contents of our website to you. The plugin makes our website more attractive and easier to experience for our site visitors.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.gymaesthetics.com/de/de/privacy-policy?___store=German.

 

  • www.gymaesthetics.com

We use the GymAesthetics service from Gym Aesthetics GmbH, Königstraße 56, 70173 Stuttgart, Germany, email: business@gymaesthetics.com, website: https://www.gymaesthetics.com/de/de/. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

The service is a plug-in that we need in order to be able to display all of the contents of our website to you. The plugin makes our website more attractive and easier to experience for our site visitors.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.gymaesthetics.com/de/de/privacy-policy?___store=German.

 

  • Website-Check Siegel

We use the Website-Check Siegel service of the company Website-Check GmbH, Beethovenstraße 24, 66111 Saarbrücken, Germany, email: support@website-check.de, website: http://www.website-check.de/.The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is our legitimate interest in processing in accordance with Article 6 (1) (f) GDPR.

With regard to the processing, you have the right of objection listed in Art. 21. You can find more information at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.website-check.de/datenschutzerklaerung/.

 

  • chimpstatic.com

We use the chimpstatic.comservice provided by Gandi International, 23, route d'Arlon, 8009 Strassen, Luxembourg on our website. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

The service is a plug-in that we need in order to be able to display all of the contents of our website to you. The plugin makes our website more attractive and easier to experience for our site visitors.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://www.gandi.net/en/contracts/terms-of-service.

 

  • qlzn6i1l.com

We use the service qlzn6i1l.com of the company qlzn6i1l.com., United States of America on our site.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

The service is a plug-in that we need in order to be able to display all of the contents of our website to you. The plugin makes our website more attractive and easier to experience for our site visitors.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

 

  • Yahoo Ad Exchange (Right Media)

A web service provided by Oath (EMEA), Ltd., 5-7 Point Square, North Wall Quay, Dublin 1 (hereinafter referred to as “Yahoo Ad Exchange (Right Media)”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Yahoo Ad Exchange (Right Media) in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. The data is deleted as soon as the purpose of its collection has been fulfilled.  You will find further information about how the transferred data is handled in the Yahoo Ad Exchange (Right Media) privacy policy: https://policies.yahoo.com/ie/de/yahoo/privacy/index.htm. You can prevent Yahoo Ad Exchange (Right Media) from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

 

  • YouTube

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “YouTube”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to YouTube in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. YouTube has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in YouTube’s privacy policy: https://www.google.de/intl/de/policies/privacy/. You can prevent YouTube from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

 

  • Social plugin – “Twitter”
    • Extent of personal data processing

We have integrated a social plugin provided by the social network “Twitter”, which is operated by Twitter, Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA (hereinafter referred to as “Twitter”), on our website. If you access a page featuring such a plugin, your browser automatically establishes a background connection to Twitter’s servers. The content of the plugin is transferred directly to your browser by Twitter and is only integrated in our page. Through this integration, Twitter receives the information that your browser has loaded a specific page on our website. This also applies if you do not have a Twitter profile or are not logged into Twitter at present. This information (including your IP address) is transmitted by your browser directly to a Twitter server in the US and stored there. If you are logged into Twitter, Twitter can directly assign your visit to our website to your Twitter profile. If you interact with the plugins – for example, click the “Like” button or post a comment – this information is also transferred directly to a Twitter server and stored there. The information is also published on your Twitter profile and made accessible to your Twitter contacts who you have enabled for this.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (if you are registered with “Twitter”) and Art. 6, Para. 1. lit. f of the GDPR (if you are not registered with Twitter). Insofar as processing is carried out based on Art. 6, Para. 1, Clause 1, lit. f of the GDPR, the site operator’s legitimate interest lies in enabling user interaction with the site operator’s contents on Twitter. .

    • Purpose of data processing

The primary purpose of data collection is to offer you an opportunity for social interaction networked with Twitter and to design our website in an interactive way. Please refer to Twitter’s privacy policy (https://twitter.com/de/privacy) to find out about the extent of data collection and Twitter’s further processing and use of the data you provided, as well as your rights in this regard and the settings available to protect your privacy.

    • Duration of storage

Twitter will store the data which is relevant to the provision of the web service for as long as is necessary. If the data is subject to the legal retention requirements, deletion shall take place once the retention requirement has expired.

    • Opportunity to object and remove

If you do not want Twitter’s social plugin to be executed, you can block such execution by installing a so-called script blocker such as “NoScript”, for example. If you do not want Twitter to assign the data collected via our website to your Twitter profile, you must log out of Twitter before visiting our website. You can also prevent loading of the Twitter plugin in a targeted manner by using add-ons for your browser. For Mozilla Firefox: https://addons.mozilla.org/de/firefox/addon/Twitter-blocker/. For Opera: https://addons.opera.com/de/extensions/details/Twitter-blocker/?display=en. For Chrome: https://chrome.google.com/webstore/detail/Twitter-blocker/pjaajgndmkdhodnaeeflmchheijfjnhf. The opportunities to object and remove are additionally based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

  • Social plugin – “Pinterest”
    • Extent of personal data processing

We have integrated a social plugin provided by the social network “Pinterest”, which is operated by Pinterest Inc., 808 Brannan St., San Francisco, CA 94103, USA (hereinafter referred to as “Pinterest”), on our website. If you access a page featuring such a plugin, your browser automatically establishes a background connection to Pinterest’s servers. The content of the plugin is transferred directly to your browser by Pinterest and is only integrated in our page. Through this integration, Pinterest receives the information that your browser has loaded a specific page on our website. This also applies if you do not have a Pinterest profile or are not logged into Pinterest at present. This information (including your IP address) is transmitted by your browser directly to a Pinterest server in the US and stored there. If you are logged into Pinterest, Pinterest can directly assign your visit to our website to your Pinterest profile. If you interact with the plugins – for example, click the “Like” button or post a comment – this information is also transferred directly to a Pinterest server and stored there. The information is also published on your Pinterest profile and made accessible to your Pinterest contacts who you have enabled for this.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (if you are registered with “Pinterest”) and Art. 6, Para. 1. lit. f of the GDPR (if you are not registered with Pinterest). Insofar as processing is carried out based on Art. 6, Para. 1, Clause 1, lit. f of the GDPR, the site operator’s legitimate interest lies in enabling user interaction with the site operator’s contents on Pinterest. .

    • Purpose of data processing

The primary purpose of data collection is to offer you an opportunity for social interaction networked with Pinterest and to design our website in an interactive way. Please refer to Pinterest’s privacy policy (https://policy.pinterest.com/de/privacy-policy) to find out about the extent of data collection and Pinterest’s further processing and use of the data you provided, as well as your rights in this regard and the settings available to protect your privacy.

    • Duration of storage

Pinterest will store the data which is relevant to the provision of the web service for as long as is necessary. If the data is subject to the legal retention requirements, deletion shall take place once the retention requirement has expired.

    • Opportunity to object and remove

If you do not want Pinterest’s social plugin to be executed, you can block such execution by installing a so-called script blocker such as “NoScript”, for example. If you do not want Pinterest to assign the data collected via our website to your Pinterest profile, you must log out of Pinterest before visiting our website. You can also prevent loading of the Pinterest plugin in a targeted manner by using add-ons for your browser. For Mozilla Firefox: https://addons.mozilla.org/de/firefox/addon/Pinterest-blocker/. For Opera:https://addons.opera.com/de/extensions/details/Pinterest-blocker/?display=en. For Chrome: https://chrome.google.com/webstore/detail/Pinterest-blocker/pjaajgndmkdhodnaeeflmchheijfjnhf. The opportunities to object and remove are additionally based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

  • Social plugin – “Google+”
    • Extent of personal data processing

We have integrated a social plugin provided by the social network “Google+”, which is operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, CA, USA (hereinafter referred to as “Google+”), on our website. If you access a page featuring such a plugin, your browser automatically establishes a background connection to Google+’s servers. The content of the plugin is transferred directly to your browser by Google+ and is only integrated in our page. Through this integration, Google+ receives the information that your browser has loaded a specific page on our website. This also applies if you do not have a Google+ profile or are not logged into Google+ at present. This information (including your IP address) is transmitted by your browser directly to a Google+ server in the US and stored there. If you are logged into Google+, Google+ can directly assign your visit to our website to your Google+ profile. If you interact with the plugins – for example, click the “Like” button or post a comment – this information is also transferred directly to a Google+ server and stored there. The information is also published on your Google+ profile and made accessible to your Google+ contacts who you have enabled for this.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (if you are registered with “Google+”) and Art. 6, Para. 1. lit. f of the GDPR (if you are not registered Google+). Insofar as processing is carried out based on Art. 6, Para. 1, Clause 1, lit. f of the GDPR, the site operator’s legitimate interest lies in enabling user interaction with the site operator’s contents on Google+. .

    • Purpose of data processing

The primary purpose of data collection is to offer you an opportunity for social interaction networked with Google+ and to design our website in an interactive way. Please refer to Google+’s privacy policy (google.com/privacy) to find out about the extent of data collection and Google+’s further processing and use of the data you provided, as well as your rights in this regard and the settings available to protect your privacy.

    • Duration of storage

Google+ will store the data which is relevant to the provision of the web service for as long as is necessary. If the data is subject to the legal retention requirements, deletion shall take place once the retention requirement has expired.

    • Opportunity to object and remove

If you do not want Google+’s social plugin to be executed, you can block such execution by installing a so-called script blocker such as “NoScript”, for example. If you do not want Google+ to assign the data collected via our website to your Google+ profile, you must log out of Google+ before visiting our website. You can also prevent loading of the Google+ plugin in a targeted manner by using add-ons for your browser. For Mozilla Firefox: https://addons.mozilla.org/de/firefox/addon/Google +-blocker/. For Opera: https://addons.opera.com/de/extensions/details/Google+-blocker/?display=en. For Chrome: https://chrome.google.com/webstore/detail/Google +-blocker/pjaajgndmkdhodnaeeflmchheijfjnhf. The opportunities to object and remove are additionally based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

  • AddThis

We use the AddThis service from Oracle America, Inc., 500 Oracle Parkway, 94065 Redwood Shores, California, United States of America, email: info_de@oracle.com, website: https://www.oracle.com/de/. The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

Via AddThis, advertising from the Addthis advertising network is displayed on our website.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at http://www.addthis.com/privacy.

The provider also offers an opt-out option at http://www.addthis.com/privacy/opt-out.

 

  • Doubleclick

We use the Doubleclick service from Google LLC, 1600 Amphitheater Parkway, 94043 Mountain View, United States of America, e-mail: support-de@google.com, website: http://www.google.com/onoursite.. The processing also takes place in a third country for which there is no adequacy decision by the Commission. Therefore, the level of protection customary for the GDPR cannot be guaranteed during transmission, as it cannot be ruled out that in third countries, e.g. authorities, can gain access to the data collected.

The legal basis for the transmission of personal data is your consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, which you have given on our website.

DoubleClick is a Google service that offers and delivers digital advertising on the Internet. It is used to be able to display individual advertising to the site users.

You can revoke your consent at any time. You can find more detailed information on withdrawing your consent either with the consent itself or at the end of this data protection declaration.

Further information on the handling of the transferred data can be found in the provider's data protection declaration at https://policies.google.com/privacy.

 

7. Information about the use of cookies

  • Extent of personal data processing

We use cookies on various pages to enable the use of certain functions on our website. The so-called ‘cookies’ are small text files which your browser can save on your computer. These text files contain a characteristic character string which enables unique identification of the browser the next time our website is called up. The process of saving a cookie file is also known as ‘setting a cookie’.

  • Legal basis for personal data processing

Art. 6, Para. 1, lit. f of the GDPR. (legitimate interest). Our legitimate interest is to maintain the full functionality of our website, to increase usability and to enable more individual customer contact. We can only identify individual site visitors using the cookie technology if said site visitors sent us corresponding personal data based on separate consent beforehand.

  • Purpose of data processing

The cookies are set by our website to maintain the full functionality of our website and to improve usability. The cookie technology also enables us to recognise individual visitors using pseudonyms, e.g. an individual, arbitrary ID, so we can offer more individual services.

  • Duration of storage

Our cookies are stored until they are deleted from your browser or, if the cookie is a session cookie, until the session is ended.

  • Opportunity to object and remove

According to your requirements, you can make settings in your browser so that you generally prevent cookies from being set, are only informed of them, can decide on whether to accept cookies on a case-by-case basis or categorically accept the setting of cookies. Cookies can be used for different purposes, e.g. to identify that your PC has previously connected to our website (permanent cookies) or to save your most recently viewed websites (session cookies). We use cookies to offer you increased user comfort. We advise that you accept cookies for our website to use our convenience functions. The opportunities to object and remove are additionally based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

 

8. Data security and data protection, communication by email

When it is collected, stored and processed, your personal data is protected by means of technical and organisational measures to ensure that it is inaccessible to third parties. Since we cannot guarantee complete data security on the transmission path to our IT systems during unencrypted communication by email, we advise sending highly confidential information using encrypted communication or by post.

 

9. Revocation of consent – data information and change requests – deleting and blocking data

Right to information

You have the right to request confirmation as to whether we are processing your personal data. If this is the case, you have a right to information about the information named in Art. 15 Paragraph 1 GDPR, provided that the rights and freedoms of other persons are not impaired (see Art. 15 Paragraph 4 GDPR). We would be happy to provide you with a copy of the data.

Right to correction

According to Art. 16 GDPR, you have the right to have incorrectly stored personal data (such as address, name, etc.) corrected at any time. You can also request that the data stored by us be completed at any time. A corresponding adjustment will be made immediately.

Right to cancellation

According to Art. 17 Para. 1 GDPR, you have the right to have us delete the personal data collected about you

  • if the data is either no longer required;
  • due to the revocation of your consent, the legal basis for the processing no longer applies;
  • You have objected to the processing and there are no legitimate reasons for the processing;
  • Your data is being processed unlawfully;
  • a legal obligation requires this or a survey according to Art. 8 Para. 1 GDPR has taken place.

According to Art. 17 Paragraph 3 GDPR, the right does not exist if

  • the processing is necessary to exercise the right to freedom of expression and information;
  • Your data has been collected on the basis of a legal obligation;
  • the processing is necessary for reasons of public interest;
  • the data is required to assert, exercise or defend legal claims.

According to the German Federal Data Protection Act, you have a right to obtain free information concerning the data stored about you and, if necessary, a right to correct, block or delete such data. Your data is then deleted unless statutory regulations to the contrary exist. You can revoke the permission you granted us to use your personal data at any time. You are more than welcome to send any information, deletion and correction requests concerning your data, as well as any suggestions, to the following address at any time:

Gym Aesthetics GmbH
Stuttgarter Str. 116
70469 Stuttgart

Email: service@gymaesthetics.com
Tel.: +49 (0)711 25517317

 

10. Right to data portability

According to Art. 20 GDPR, you have the right to have your personal data transmitted. We provide the data in a structured, common and machine-readable format. The data can either be sent to you or to a person in charge named by you.

Upon request, we will provide you with the following data in accordance with Art. 20 Paragraph 1 GDPR:

  • Data that has been collected on the basis of an express consent in accordance with Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR;
  • Data that we have received from you in accordance with Article 6 (1) (b) GDPR as part of existing contracts;
  • Data that has been processed as part of an automated procedure.

We will transfer the personal data directly to a person in charge of your choice, insofar as this is technically feasible. Please note that we are not allowed to transfer data that encroach on the freedoms and rights of other persons in accordance with Article 20 (4) GDPR.

 

11. Right to lodge a complaint with the supervisory authority according to Art. 77 I of the GDPR

If you suspect that your data is being processed unlawfully on our site, you can naturally obtain judicial clarification of the issue at any time. Regardless of this, you have the option of contacting a supervisory authority. You have a right to lodge a complaint in the EU member state of your place of residence, your workplace and/or the place of the suspected violation, i.e. you can choose the supervisory authority you wish to contact from the aforementioned locations. The supervisory authority with whom the complaint was lodged then informs you of the status and results of your petition, including the possibility of a judicial legal remedy according to Art. 78 of the GDPR.

Created by:
© IT law firm DURY – www.dury.de
© Website-Check GmbH – www.website-check.de