GYMTASTIC® UG, Domainweg 1C, 31171 Nordstemmen (hereinafter referred to as “Provider” or “we”) is the developer and operator of “GYMTASTIC®”. We take the protection of your personal data very seriously and observe the requirements of the European General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and the Telemedia Act (TMG) when collecting, processing and using your data. The following statement gives you an overview of how we ensure data protection and what type of data is collected and for what purpose.
1. COLLECTION, PROCESSING AND USE OF PERSONAL DATA
“Personal data” is all individual information about your personal or factual circumstances. This includes all information that allows a conclusion to be drawn about your identity (e.g. name, address, email address, bank details, etc.).
The collection, storage and processing of personal data is governed exclusively by applicable law. We are committed to handling the data you provide responsibly and with the greatest care.
The “GYMTASTIC®” website and our systems are protected by technical and organizational measures against loss, destruction, access, alteration or distribution of your data by unauthorized persons. Despite regular checks, complete protection against all dangers is not possible.
2. PURPOSES OF PROCESSING YOUR PERSONAL INFORMATION
We process personal information to operate, provide and improve the offerings we offer to our customers. We use the data we receive from you to:
- Provide you with our services, including giving you access to your profile and our website,
- Identify you as a registered user when you log in to our website and visit it again,
- process payments,
- offer logistics services including shipment tracking,
- improve the website and our services,
- Answer your questions and provide appropriate customer service,
- Send you our newsletters,
- Recommend personalized offers to you on the website,
- enable our social sharing features; This also includes providing you with the option to connect with members of your network who are both customers of GYMTASTIC and one or more social networks,
- carry out various internal business measures, e.g. B. data analysis, controls, monitoring and preventive measures to protect against attempted fraud, developing new products and services, improving or revising the website or our services, identifying usage trends, determining the effectiveness of our advertising campaigns and conducting and expanding our business activities,
- ensure compliance with legal regulations and procedures as well as the requirements of public and government authorities, applicable industry standards and our internal policies,
- enforce our general terms and conditions,
- to protect our business activities or those of our affiliated companies,
- protect our rights, privacy, safety or property and/or those of our affiliates, you or others,
- to allow us to seek possible legal remedies and limit any damages that we may incur.
We will also use this information in other ways for which we will provide separate information at the time of collection.
3. DATA COLLECTION WHEN VISITING OUR WEBSITE
When using our website for purely informational purposes, i.e. if the user does not register or otherwise provide us with information, we only collect data that the browser transmits to our server (so-called “server log files”). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the time of access
- Amount of data sent in bytes
- Source/reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if necessary: in anonymized form)
Processing is carried out in accordance with Article 6 Paragraph 1 Letter f of the GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to subsequently check the server log files if there are concrete indications of illegal use.
4. NEWSLETTER / REVOCATION OF CONSENT FOR NEWSLETTER
On the GYMTASTIC® website, users are given the opportunity to subscribe to our company's newsletter. Which personal data is transmitted to the person responsible for processing when ordering the newsletter is determined by the input mask used for this purpose.
GYMTASTIC® regularly informs its customers about the company's offers by means of a newsletter. Our company's newsletter can generally only be received by the data subject if
a) the data subject has a valid email address and
b) the data subject registers to receive the newsletter.
For legal reasons, a confirmation email will be sent using the double opt-in procedure to the email address entered by a data subject for the first time to receive the newsletter. This confirmation email is used to check whether the owner of the email address as the data subject has authorized receipt of the newsletter.
When registering for the newsletter, we also store the IP address assigned by the Internet service provider (ISP) of the computer system used by the data subject at the time of registration as well as the date and time of registration. The collection of this data is necessary in order to be able to understand the (possible) misuse of the email address of a data subject at a later point in time and therefore serves to provide legal protection for the person responsible for processing.
The personal data collected when registering for the newsletter is used exclusively to send our newsletter. Furthermore, subscribers to the newsletter could be informed by email if this is necessary for the operation of the newsletter service or a related registration, as could be the case in the event of changes to the newsletter offer or a change in technical circumstances. The personal data collected as part of the newsletter service will not be passed on to third parties. The data subject can cancel the subscription to our newsletter at any time. The consent to the storage of personal data that the data subject has given us for sending the newsletter can be revoked at any time. For the purpose of revoking your consent, there is a corresponding link in every newsletter. It is also possible to unsubscribe from the newsletter at any time directly on the website of the controller or to communicate this to the controller in another way.
You can revoke your consent to receive the newsletter at any time with effect for the future by declaring your revocation to the provider using the following contact details:
GYMTASTIC® UG, Domainweg 1C, 31171 Nordstemmen
You will not incur any costs for revoking your consent to receive the newsletter, apart from the transmission costs according to the respective basic tariff of your telephone/internet provider.
5. DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING
In accordance with Article 6 Paragraph 1 Letter b GDPR, personal data will continue to be collected and processed if you provide it to us to execute a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. It is possible to delete your customer account at any time and can be done by sending a message to kundenservice @gymtastic.de take place. We store and use the data you provide to process the contract. After the contract has been fully processed or your customer account has been deleted, your data will be blocked in consideration of tax and commercial law retention periods and deleted after these periods have expired, unless you have expressly consented to further use of your data or have reserved the right to further use of your data as permitted by law on our part which we will inform you about below.
To process your order, we work with service providers who support us in whole or in part in the implementation of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information. The personal data we collect will be passed on to the transport company commissioned with the delivery as part of the contract processing, to the extent that this is necessary to deliver the goods. As part of the payment processing, we pass on your payment data to the commissioned credit institution if this is necessary for the payment processing. The legal basis for passing on the data is Article 6 Paragraph 1 Letter b GDPR.
6. INTEGRATION OF FACEBOOK
We offer you the opportunity to recommend offers, products, promotions and messages via Facebook. For this we use social plugins from Facebook. These services are offered by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (Facebook).
If you are logged in to Facebook during your visit to smilesecret.de, Facebook can assign the pages you visit to your Facebook account. By interacting with the social plugins (clicking, etc.), the information generated by the interaction is transmitted to Facebook and stored there. You can prevent this by logging out of Facebook before visiting our website.
It is also possible to have social plugins generally blocked by Facebook. There are extensions for the respective browser (e.g. the Facebook Blocker ), which you must install and activate for your respective browser.
Facebook's data protection information and other setting options to protect privacy can be found here at Facebook can be accessed (http://de-de.facebook.com/about/privacy/).
7. YOUTUBE PLUGIN
This website uses plugins from YouTube. These services are provided by YouTube, LLC, Cherry Ave., United States (Youtube), represented by Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, United States (Google).
When the website is created in your browser, the code of the "Youtube" button is queried directly from a YouTube/Google server by your browser and integrated into the "GYMTASTIC®" website that appears in your browser. We therefore have no influence on the extent of data accessed by YouTube/Google.
According to its own information, Google collects information about the page that you viewed when you clicked on the YouTube button, i.e. the Internet address, your IP address and other browser-related information. Google standardized its data protection policies on March 1, 2012. The current data protection declaration no longer contains any information about the use of the YouTube button.
If you are logged in to your YouTube account, the information collected will be assigned to your account/Google account. By interacting with the YouTube plugins (clicking, etc.), the information resulting from the interaction is transmitted to YouTube/Google and stored there. You can prevent this by logging out of YouTube before visiting our website.
According to its own information, Google does not record your visits to the Internet or your browser history permanently and does not evaluate your visit to a page with a YouTube button in any other way. However, Google stores some data about your visit for a short period of time, usually around two weeks, for system maintenance and troubleshooting purposes. However, this data is not structured according to individual profiles, usernames or URLs .
Further information on the purpose and scope of the collection, storage and processing of your data by YouTube/Google as well as settings can be found here: https://policies.google.com/privacy?hl=de&gl=de .
Please inform yourself there as well, as the data protection regulations of Google products are regularly updated and adapted due to expanded functionalities.
8. INSTAGRAM PLUGIN
This website uses plugins from Instagram. These services are provided by Instagram, LLC, 1601 Willow Rd. Menlo Park, CA 94025, United States.
When the website is set up in your browser, the code of the Instagram plugin is queried directly from an Instagram server by your browser and integrated into the “GYMTASTIC” website that appears in your browser. We therefore have no influence on the amount of data retrieved by Instagram.
Further information on the purpose and scope of Instagram's collection, storage and processing of your data and settings can be found here: https://help.instagram.com/519522125107875?helpref=page_content .
Please inform yourself there as well, as the data protection regulations for Instagram products are regularly updated and adapted due to expanded functionalities.
9. GOOGLE ANALYTICS
This website uses Google Analytics, a web analysis service provided by Google Inc. (“Google”). Google Analytics uses so-called “cookies”, text files that are stored on your computer and that enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. The IP address is anonymized by us (anonymi-zeIp() so-called IP masking), which is why your IP address is shortened by Google within the member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the provider, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website and internet use to the provider. We do not combine the IP address transmitted by your browser as part of Google Analytics with other Google data.
You can prevent the storage of cookies by setting your browser software accordingly; However, we would like to point out that in this case you may not be able to fully use all of the functions on this website. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google using the following link (http:// tools.google.com/dlpage/gaoptout?hl=de) download and install the available browser plugin.
Further information about Google Analytics can be found here provided: https://support.google.com/analytics/answer/6004245?hl=de.
10. USE OF GOOGLE ADWORDS
The "GYMTASTIC®" website uses the online advertising program "Google AdWords" and, within the framework of Google AdWords, the conversion tracking of Google LLC., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google"). We use Google Adwords to draw attention to our attractive offers on external websites using advertising materials (so-called Google Adwords). We can determine how successful the individual advertising measures are in relation to the data from the advertising campaigns. Our interest is to show you advertising that is of interest to you, to make our website more interesting for you and to achieve a fair calculation of advertising costs.
The conversion tracking cookie is set when a user clicks on an ad placed by Google. Cookies are small text files that are stored on your computer system. These cookies expire after 30 days and are not used for personal identification. If the user visits certain pages on this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google AdWords customer receives a different cookie. Cookies cannot therefore be tracked via the websites of AdWords customers. The information collected using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, you will not receive any information that can be used to personally identify users. If you do not want to participate in tracking, you can object to this use by easily deactivating the Google Conversion Tracking cookie via your Internet browser under user settings. You will then not be included in the conversion tracking statistics.
You can find further information about Google's data protection regulations at the following internet address: https://policies.google.com/privacy?gl=de.
Cookies are small pieces of information that the website stores on the hard drive of your computer, tablet or smartphone. Please note that HTML5 introduced the Web Storage feature, which is similar to cookies and for this reason we refer to it as a cookie below.
Cookies contain information that the website uses to improve the efficiency of communication between you and your web browser. Cookies identify your computer or device and not you as a specific user.
We set session cookies, permanent cookies, session cookies for HTML5 sessionStorage and HTML5 localStorage as well as HTML5 sessionStorage objects, which are temporary and are deleted after you close your internet browser. Persistent cookies are stored for a longer period of time and remain on your computer until they are deleted. Persistent cookies expire or self-delete after a period of time, as determined by the cookie, but are renewed each time you visit the website. HTML5 localStorage objects are persistent and remain on your computer until deleted.
You can prevent cookies from being set by setting your internet browser so that all cookies are deleted when you close the browser window. You can also delete the cookies stored on your computer at any time. Further information about cookies, including the question of how dangerous cookies are, can be found at the following link on the website of the Federal Office for Information Security.
Cookies are used for the following purposes:
Generating statistics: for measuring website traffic, such as the number of website visitors, which domain the visitors come from, which pages they visit on the website and in which geographical areas the visitors are located.
Monitoring website performance and your use of our website: for monitoring website performance, our applications and infrastructure and how you use our website.
Login process and improving the functionality of our website: to optimize the user experience on the website, which includes remembering your username and password when you visit the website again, as well as remembering your browser and preferred settings (e.g. your preferred language).
12. LEGAL BASIS OF PROCESSING
Art. 6 Paragraph 1 Letter a) GDPR serves our company as the legal basis for processing operations in which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, as is the case, for example, with processing operations that are necessary for the delivery of goods or the provision of any other service or consideration, the processing is based on Art. 6 Paragraph 1 Letter b) GDPR. The same applies to processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If our company is subject to a legal obligation that requires the processing of personal data, such as to fulfill tax obligations, the processing is based on Art. 6 Para. 1 Letter c) GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. Then the processing would be based on Article 6 Paragraph 1 Letter d) GDPR. Ultimately, processing operations could be based on Article 6 Paragraph 1 Letter f) GDPR. Processing operations that are not covered by any of the above-mentioned legal bases are based on this legal basis if the processing is necessary to protect a legitimate interest of our company or a third party, provided that the interests, fundamental rights and freedoms of the data subject do not prevail. We are permitted to carry out such processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, he was of the opinion that a legitimate interest could be assumed if the data subject is a customer of the controller (Recital 47 Sentence 2 GDPR).
13. LEGAL OBLIGATION TO TRANSFER PERSONAL DATA TO THIRD PARTIES
We would like to point out that we are legally obliged to pass on your personal data to third parties in certain cases (e.g. in the event of criminal prosecution).
14. YOUR RIGHTS
We would like to briefly inform you about the data protection rights that you can exercise towards us:
Right to information and information
You have the right to receive information about the personal data we store at any time. Please send us an email to email@example.com.
Right to rectification
GYMTASTIC® may only process relevant data about you. If you discover - for example by exercising your right to information - that a date about you is incorrect or has become incorrect, we are generally obliged to correct it immediately.
Right of deletion
If you would like to delete your account, send us an email to firstname.lastname@example.org from the email address with which you registered with us. Please also tell us your full name.
Right to object
If you have a legal right to object to the data processing described in this data protection notice, we will inform you of this at the relevant point. You also have the opportunity to conveniently exercise your objection at the appropriate points.
You generally have the right to object to (further) data processing when processing is based on the legal basis of “legitimate interest” and when processing is based on consent.
Right to lodge a complaint with the supervisory authorities
You have the right to lodge a complaint with a data protection authority. To do this, you can, for example, contact the data protection authority responsible for your place of residence or your federal state or the data protection authority responsible for us. This is the Berlin Commissioner for Data Protection and Freedom of Information.
You also have the right to receive data that you have provided to us in a structured, common and machine-readable format or - if technically feasible - to request that the data be transmitted to a third party.
15. FURTHER INFORMATION ON DATA PROTECTION AT “GYMTASTIC®”
Your trust in the protection of your personal data when you visit our websites is very important to us. We are therefore available to answer any questions you may have regarding the collection, storage and processing of your personal data at any time. If you have any questions that this data protection declaration could not answer, you can contact us at any time at customer service @gymtastic.de to contact.
16. Messenger people
By sending a start message, I agree to the validity of Gymtastic 's internal data protection regulations.
In particular, in accordance with Art. 6 Para. 1 lit. processed and used to transmit messages to me. To use the messenger service, an active account with the respective provider is required.
I am also aware that Gymtastic uses MessengerPeople GmbH, Seidlstraße 8, 80335 Munich as a technical service provider and processor to provide this service.
My consent to the processing of personal data can always be freely revoked; To do this, please send a corresponding notification to ( Gymtastic) . Further information can be found in the respective data protection policies of Gymtastic, the messenger services and MessengerPeople GmbH.