
Privacy Policy
This privacy policy applies to https://www.boxverein-berlin.de/ and https://www.isi-gym.de/
The basics
This website uses no tracking mechanisms to follow you around the internet, no Facebook pixel, no Google tags, no YouTube cookies or any similar rubbish.
Controller
Cookies
This website uses only functional cookies that are needed to display the pages.
Types of data we process
Users of this website — The server log files record every access to this website in anonymous form.
Users of the training programme — We only collect data about your health and fitness as far as it is needed for your sporting success.
Purpose of the data processing
Data is processed only in order to run our website, for security measures, for marketing and to provide contractually agreed services.
Legal basis of the data processing
Unless a specific legal basis is named further below, the following apply.
For obtaining consent — Art. 6 (1) (a) and Art. 7 GDPR. Processing in order to provide our services, carry out contractual measures and answer enquiries — Art. 6 (1) (b) GDPR. Processing in order to meet our legal obligations — Art. 6 (1) (c) GDPR. Processing in order to safeguard our legitimate interests — Art. 6 (1) (f) GDPR. In the event that the vital interests of the data subject or of another natural person make the processing of personal data necessary — Art. 6 (1) (d) GDPR is the legal basis.
Server log files
Our website is looked after technically by the digital agency Reuther Media; they are our processor under Art. 28 GDPR. The server is located at Hetzner Online GmbH in Helsinki (Finland). Access data is collected and stored there in server log files that your browser transmits automatically. This data consists of browser type and browser version, the operating system of the user, the referrer URL of the calling page, if you clicked a link to our site, the host name of the accessing computer, the time of the server request, the IP address, the volume of data transferred, http response codes, that is, messages about a successful request.
This data cannot be assigned to specific people. It is not combined with other sources of data. We reserve the right to check this data retrospectively if we become aware of concrete evidence of unlawful use. The processing of this data is limited to the purpose of pursuing unlawful use.
It is stored on the basis of our legitimate interests and also in your interest in being protected against misuse and other unauthorised use. As a rule this data is not passed on to third parties, unless doing so is necessary to pursue our claims or there is a legal obligation to do so.
Log files are deleted after 30 days, except for data whose further retention is needed as evidence until the incident in question has been finally resolved.
Getting in touch by form, email or telephone
In order to deal with your enquiries by contact form, telephone or email, we store the contact details you send us so that we can handle and process the enquiry and answer any follow-up questions.
Unless statutory retention obligations require us to keep it longer, we delete this data after no more than 12 months.
Right to information, deletion and rectification
You have the right at any time to free information about the personal data we hold about you and about the purpose of the data processing, as well as a right to have this data corrected or deleted.
In particular this covers the following rights:
Information on whether data concerning you is being processed, on its origin and its recipients, and a copy of the data — Art. 15 GDPR
Completion or rectification of incorrect data concerning you — Art. 16 GDPR
Immediate deletion of your data — Art. 16 GDPR
Restriction of the processing of the data — Art. 16 GDPR
Transfer of the data concerning you to other controllers — Art. 20 GDPR
To lodge a complaint with the competent supervisory authority — Art. 77 GDPR
To withdraw consent you have given, with effect for the future — Art. 7 (3) GDPR
To object to the future processing of your data as provided for by law — Art. 21 GDPR
Retention and deletion of data
The data we process is deleted, or its processing is restricted, in accordance with Art. 17 and 18 GDPR as soon as it is no longer needed for the purpose it was collected for and no statutory retention obligations stand in the way of deletion.
Data that is not deleted because it has to be kept for commercial or tax law reasons is blocked from further processing and is not processed for other purposes.
Processing on the basis of contractual services
The data processed includes master data such as name, address, email address and telephone numbers, contract data such as the services used, contract contents, contractual communication and the names of contact persons, and payment data such as bank details and payment history.
We process data that is needed to establish and fulfil the contractual services. It is disclosed to external people or companies only where this is necessary within the scope of a contract. When processing data entrusted to us as part of an order, we act in line with the instructions of the client and with the statutory requirements.
Processing as part of running the organisation
We also process the data named in the previous section for administrative tasks, for organising our operations, for financial accounting and in order to comply with legal obligations.
The purpose of, and our interest in, this processing lies in administration, financial accounting, office organisation and the archiving of data — that is, in tasks that serve to maintain our activities, carry out our duties and provide our services. In doing so we pass data on to the tax authorities, to tax advisers or auditors and to fee offices and payment service providers.
The data is deleted once it is no longer needed to fulfil contractual or statutory duties of care or to deal with any warranty and comparable obligations; whether the data still needs to be kept is reviewed every two years. Otherwise the statutory retention obligations apply.
Data on suppliers, event organisers and training courses is generally stored permanently.
Transfer to processors and to others
Data is transferred to processors or to third parties exclusively on the basis of a statutory permission, for example when account details have to be passed to a payment service provider in order to fulfil a contract, or when you have consented to the transfer, or because of a legal obligation, or on the basis of our legitimate interest, for example when we use agents or technical service providers.
Processing by third parties is only ever carried out on the basis of a data processing agreement — Art. 28 GDPR.
